mirror of
https://github.com/Druthulu/BFM-decomp
synced 2026-10-03 00:05:11 -04:00
4fbe768798
The crack was NOT achieved; the wall is now mechanism-complete instead of inferred: - caller-save.c setup_save_areas DISCOVERED as a second never-referenced-slot producer: eager 4-byte areas per call-clobbered hard reg carrying a call-crossing pseudo at ANY reload iteration (-fcaller-saves is on at -O2), emitted code or not. - Alignment math corrected: alter_reg slots 8B (align -1), save areas 4B (align 0). - The whole-binary gate run on v_best/v_dialfree for the FIRST time: both rejected — the standalone NEAR-2/NEAR-25 verdicts are faithful, no TU-state leak. - 200-variant randomized structural sweep: swapped-arm recomputes are the ONE dimension that moves vars upward (cse does not merge the swapped select) at ~1:1 real-code cost; four coincidental vars=256 hits, all heavy-drift. - Proof: cross-jump cannot delete slot-bearing code (identical-offset requirement) — the last no-residue mechanism branch closed by argument, not probe. - Inline forms collapse the chain 246->209 ins: the bytes REQUIRE textual macro repeats. - cc1 flag axis (-fforce-addr/-fno-force-mem/-fno-caller-saves/-fno-schedule-insns): vars=224 invariant. Idioms delivered (Drew's second ask): §172 v2 (complete frame-residue model: producers, alignment, orphan rule, the three-layer canonicalization wall with its honest bound) + §172a (the lhu/lh typing tell: movhi=lhu copy vs extendhisi2=lh promotion, the double-load signature; the macro-vs-inline tell: re-evaluated compares in arms = textually repeating macros, load-bearing redundancy). The 0x801F1CD8/0x8017D290 family idioms were §171a/b. Floor stays NEAR 2/246. Parked for P32 with the siege kit: tools/cc1_dumps.sh, the §172-v2 model, sweep_gen.py, the swaprepeat lead. ~240 cumulative refutations, each byte-grounded.