Files
BFM-decomp/tools
Drew T 758c4365b6 feat(phase-28 T7): make audit-binaries — the R36 citizenship gate (R32 enforcement)
R36: a newly-discovered binary is not real until every consumer knows it. Onboarding produces a
byte-CLEAN binary (check-all green) that is not yet a CITIZEN — the tools that enumerate binaries
can each be silently unaware of it, and the byte-gate is structurally blind to that (R34).

Not hypothetical: P27 onboarded 4 SC07 overlays byte-clean; P28 found FOUR consumers silently
ignoring them (family_remap.img_path, .run/family_hseq.json, config/dedup.us.yaml, and the overlays'
own .c), hiding ~6,400 already-matched bodies. Every failure was silent.

- tools/audit_binaries.py asserts, coverage-checked BOTH directions (R32), against the config the
  BUILD reads (R33 — onboarded = main + resident + every config/splat.ov_*.yaml):
    1. dup_report.BINARIES (what corpus/family_hseq/progress all derive from) EXACTLY equals the
       onboarded set — a missing binary is invisible to every derived tool; a phantom is invented.
    2. every onboarded binary has a byte-derived sig.
    3. THE LOAD-BEARING SC07 CHECK: every onboarded OVERLAY's .c includes ../shared/engine_core.h,
       or no shared body can ever reach it (main/resident have their own bodies, exempt).
    4. every onboarded overlay is represented in the family map (warn — regenerable/may post-date).
  INFO: dedup-group membership (0 = onboarded-but-un-harvested, a dedup_extend candidate).
- NEGATIVE CONTROL: stripping the shared include from ov_SC07_006.c makes the gate FAIL loudly and
  exit 1 — it catches the exact bug that hid 6,400 bodies for a month. Restored clean.
- Wired into `make tools-health` (the pre-matching ritual) — cheap (config + text scans, no build),
  so it sits in the fast lane. Passes today: 140 onboarded, all full citizens.
- Reads config/dedup.us.yaml as TEXT (never a YAML round-trip — the H5 lesson from T4).
2026-07-16 01:56:26 -06:00
..