Files
BFM-decomp/cookbook/C0360.md
T

2.4 KiB

§322 — A PROBE THAT ANSWERS A NECESSARY BUT NOT SUFFICIENT QUESTION WILL PRICE BLOCKED WORK AS FREE: RUN THE REAL PLANNER WHEN THE PLANNER IS PURE (P31 S67; measured, 96 of 159 open jtbl functions)

THE SHAPE. jtbl_carve --probe called only island_probe, which answers where does this table live — a table in the data tail returns tail — standard §8a carve at gate time, and that reads as "carveable". It is necessary and not sufficient: build_carve, the real planner, ALSO refuses a plan whose two same-subseg .rodata carves would be non-contiguous, because one object cannot leave a hole for an uncarved neighbour's table. island_probe cannot see that — it looks at one function, and the refusal is a property of the SUBSEG's whole carve set.

WHAT IT COST. The S66 free-wins audit priced 32 jtbl functions as "free now, run them through the serial gate" on this probe. Re-probed with the planner: ov_SC03_010:func_8017F6C0 probes a clean tail and the gate books CARVE-REFUSED; ov_SC02_000:func_8017F950, explicitly on that free list, refuses too. Fleet-wide the honest numbers are 159 open functions reference a jtbl (30% of the 530 frontier, 57 binaries, 72 (binary,subseg) hosts) → 96 plan-refused · 43 carveable · 16 main curated-name ERR · 4 main-manual, with 75 of the refusals non-main across 38 subsegs. A whole session's lane was scoped off a probe that had never been asked the blocking question.

THE FIX, AND WHEN IT IS AVAILABLE. build_carve is a PURE planner — it reads the config and the payload and writes nothing (verified: no open(...,'w'), no subprocess, no os.rename in its body), and it signals refusal by sys.exit(msg). So the probe can simply CALL it inside try/except SystemExit and report the message as plan-refused. Cost: nothing. Blast radius: none. Generalise: whenever a cheap probe and an expensive applier disagree about feasibility, check whether the applier's DECISION half is separable from its MUTATION half. If it is, the probe must call it. A probe that models the applier loosely is a second oracle that silently disagrees (R34), and the direction of its error — optimistic — is the expensive one, because optimistic probes create work plans, and pessimistic ones only lose opportunities.

THE TELL THAT YOU HAVE ONE. A batch whose verdicts are uniform (13 of 13 near) is a harness smell, not a subject signal. Real codegen residuals scatter.