5.7 KiB
§308a — A TWO-INSTRUCTION ARM STUB LAID BEFORE THE OTHER ARM AND REACHED ONLY BY A TRAILING j SURVIVES ONLY BEHIND A SHORT-CIRCUIT && GUARD PLUS A SEPARATE RE-TEST; EVERY PLAIN if/else-if, GOTO-LADDER, NESTED-INVERTED-if AND 1-/2-NODE switch LETS jump1 INLINE IT (−2 ins) (P31 S63 t5e-t5i; byte-proven func_80180808)
(BOUNDS §256 — its flat goto-in-target-block-order dispatch is the right family and the WRONG spelling here (closeness 2, never 0); supplies the first byte-measured instance of §195-G BOUND 5's "put a surviving CODE_LABEL in the way and the two spellings are no longer guaranteed equal" — measured price 2 instructions, where §195-G's ⚠ headline says the branch sense is free; complements §164-46/§165-03, which license the surviving RANGE re-test but never say it must be PAIRED with the guard that already decided it; sits beside §199-G, whose 2-node-switch and nested-inverted-if rows were both probed and refuted for this shape.)
TARGET SHAPE / THE TELL. A three-way dispatch on one call result where the target lays the SHORT arm first:
bne $v1,$v0,.default <- the "not the special constant" exit
nop
sh $v0,0x70($a0) <- armA: a 1-2 instruction self-terminating stub…
j .common <- …ending in its own `j`
nop
j .armB <- and a LONE `j` immediately before armB's own body
i.e. a 2-instruction armA block placed BEFORE armB and reached only by a trailing unconditional j. On the naive draft match_one files this as BRANCH-POLARITY / beq!=bne at closeness 2 with nins EXACT (64/64) — a near-match. The index (L14) routes that class to §3-T4 "invert the source condition". Do not. Inverting that one branch's sense collapses nins 64 → 62 and closeness 2 → 40: gcc's jump1 deletes the stub's j+nop, inlines the block and folds the guard. A count-EXACT BRANCH-POLARITY residual sitting on a short stub is a structure diagnosis, not a polarity one (same trap family as §165-23, §167-27 and §164-55's S63 addendum).
THE C SHAPE THAT MATCHES — the guard's range conjunct is written TWICE: once inside the short-circuit &&, once as the standalone dispatch test.
if (v1 >= 5 && v1 != 0x294) goto skip; /* union guard: leave for the default */
if (v1 < 5) goto armA; /* re-test the SAME range the guard already decided */
goto armB;
armA: *(s16 *)(a0 + 0x70) = 1; goto common;
armB: /* the long, call-bearing arm */ …
common: /* shared tail */ …
skip: *(u16 *)(a0 + 2) += 1;
MECHANISM — INFERRED, NOT TRACED. Cite it as a place to look, never as a proven pass behaviour (§164z's standard). The reading is jump.c:1737-1747's invert-a-cond-jump-that-jumps-over-an-uncond-jump (invert_jump/delete_jump) plus the swapped-inequality fold at :1540-1640: any single-test spelling leaves the stub as a lone self-terminating block landing right after an unconditional jump, which jump1 then inlines. The && form is claimed to survive because do_jump's TRUTH_ANDIF codegen (expr.c:8970-8990, §194-M/L19957) aims the positive branch at the drop-through and thread_jumps folds the duplicated slti into it, leaving the j armB un-collapsed. Not verified against an RTL dump — the "what" is byte-proven, the "why" is a hypothesis.
BYTE EVIDENCE. func_80180808 (ov_SC01_005, 64 ins, target asm/ov_SC01_005/nonmatchings/ov_SC01_005_jr_8017ED5C/func_80180808.s), banked at src/ov_SC01_005/ov_SC01_005_jr_8017ED5C.c:3515 (commit 9b9385afd, wave t5i, whole-binary gate green). Ladder on the pinned triple: v0 = §256's flat goto ladder (if(v1<5) goto body0; if(v1==0x294) goto body1; goto skip;) → near, nins 64, closeness 2, residual = target 10620005 beq v1,v0,+0x68 vs mine bne $v1,$v0, and target 08000035 j +0xd4 vs mine j .L80180870. v1 = §3-T4 applied literally, single-axis from v0 (second test's sense inverted, the two goto targets swapped — exactly §195-G ⚠'s "free" pair) → near, nins 62, closeness 40; the j/nop pair is gone. v2 = full if/else restructure → 63 ins, closeness 38. Nine further hand-probed spellings via direct cc1 .s dumps (v4, v6-early, v8, sw1-sw4 switch forms, w1-w4, y1-y4 with __asm__("") fences per §42/§73/§37/§5a/§34/§194-H, z1/z4/z5) all either kept the wrong beq/bne at 64 or collapsed to 62/63 — none reached 0. Winner = the z1 shape above (.run/t5i/opus/scratch_func_80180808/v6.c, submitted verbatim as .run/t5i/opus/func_80180808.c): MATCH, closeness 0, nins 64/64, residual [].
BOUNDS. (1) n = 1 function. The refuted-alternative list is broad (13 spellings) but all inside one body — treat the &&+re-test prescription as a first thing to try on this tell, not a proven universal. (2) The re-test here is a RANGE compare, which §164-46 says survives free; an EQUALITY re-test in the same position would additionally need §165-03's zero-byte __asm__("" : "=r"(t) : "0"(t)) tie, untested here. (3) §199-G's 2-node-switch tell does not fire — this header leads with a bne to the default, not the all-positive beq header — so the switch probes failing is consistent with §199-G, not evidence against it. (4) Do not read this as "always duplicate the guard": the extra conjunct costs nothing only because the guard and the dispatch test are the same range on the same value.
INDEX DELTA. cookbook-index.md L14 (BRANCH-POLARITY → §3-T4) needs the exception: count-EXACT BRANCH-POLARITY where the disputed branch is followed by a 1-2 instruction stub that ends in its own j ⇒ read §308a before inverting anything; the invert costs 2 instructions.