Files
BFM-decomp/docs/cookbook-index.md
T
Drew T 895bb6a239 feat(phase-30 S50): clear the func_801EDC18 carry blocker — 4/4 banked, and re-priced
- The blocker was carried as "one missing file-scope extern gates 83 PURE members". Both
  halves were wrong (R14): corpus.stubs says 4 open members, and D_801ED98C is a DEFINED
  const Blk8 whose rodata lives inside the member's own nonmatchings .s — replacing the stub
  deletes the data with it. gather_externs can carry an extern DECL, never a DEFINITION,
  which is why it reported "no file-scope decl" for a symbol md_SC05_023 defines on line 114.
- Fix: paste typedef + const definition + body per sibling (data bytes verified identical
  across md_SC05_024/025/028/029). 4/4 banked.
- aprop_symfix: new `local-only` class — draft-DEFINED identifiers that merely carry a
  vram-looking suffix (Blk8_…, S8_…, L_call_…) are not stale symbols. Measured: that is every
  non-clean case in the whole wave-7a/7b stored-draft residue, which holds ZERO stale-symbol
  recoveries (a clean negative result — the defect was A-prop-specific).
- cookbook index regenerated (tools-health fails closed on a stale index — it caught §171).
- R22 clean rebuild: check-all 213 passed, 0 failed of 213. Stubs 12,445 -> 12,441.
2026-08-14 00:23:32 -06:00

1315 lines
160 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# Cookbook index — find the entry by the SYMPTOM you are looking at
> **Generated by `tools/cookbook_index.py` — do not hand-edit** (R33). Regenerate after adding a cookbook section.
>
> `docs/matching-cookbook.md` is ~716 KB / 512 sections. Grepping it blind is how three P30 wave-1 agents each "discovered" an idiom that was already written down. **Start here, then read the section.** A section appears under every symptom it addresses.
**How to use:** name what you SEE in the diff (a stolen delay slot, an extra `la`, a swapped register pair, a `conflicting types` error), find that symptom below, read those sections first. If nothing fits, THEN grind — and add a section when you win.
## Start here — the symptoms that come up most, with the section that fixes them
> Hand-curated from what agents actually hit and, in several cases, RE-DERIVED because keyword matching alone did not surface the entry (P30 wave-2 feedback). If your symptom is here, read the named section before anything else.
- **wrong branch sense / arms swapped / `beq` where the target has `bne` (match_one prints this class as **BRANCH-POLARITY**)** → **§3-T4** (invert the source condition) + **§32**.2; for a trailing `return 0` vs an early return see the shared-ret0 note (cookbook L1344)
- **`conflicting types` on YOUR OWN function's definition, where the fleet canon is `(void)`** → **§73** (the PARAMS axis) + **§42** — keep the `(void)` signature and read the incoming arg via `register s32 a0v __asm__("$4")`; §42 is otherwise indexed only under regalloc
- **a shared global declared at a conflicting type (u8 vs s32, signedness) blocking your draft** → **§37** asm-label alias `extern T X __asm__("D_x")` — beats `*(T*)&X`, whose address-of perturbs regalloc. Works for FUNCTION definitions too (P30 wave 2)
- **target reuses ONE address register across two different offsets of the same global** → **§20** (the pointer-var-to-the-global bullet, cookbook L1907-1918) — take `T *p = &D_x;` and index off `p`, never the bare symbol twice
- **an extra `la` / the address hoisted into a callee-saved register across calls** → **§20** + `gcc-2.7.2-map/cse_expr.md` §H — `*(T*)&sym` force_regs the address; the asm-label alias (§37) keeps the direct `%lo` mem form
- **`andi $x,0xFF` folded away in your output but present in the target** → **§1/I2** + **§12** name the family; if the prescribed `& 0xff` at the use folds, hold the masked byte in a **u16** local so only a QI->HI extend survives (P30 wave 2, byte-tested)
- **`slti` where the target has `sltiu` (or vice versa)** → **§35** — a separate SIGNED int copy of an unsigned load keeps `slti`; chained bounds get range-folded, so write each bound as its own `if`/`goto` (**§21**)
- **you are about to hand-derive a body that some overlay already matched** → **§71** — grep the callees/globals for an already-matched SIBLING first; in wave 2 this alone produced iteration-1 MATCHes on 4 of 19 targets
- **gcc stole an instruction into a branch delay slot that the target leaves as `nop`** → **§5a** + the zero-byte `__asm__("")` fence (**§34** toolkit) — `reorg.c stop_search_p` halts the eager filler on an asm insn
- **`void` vs `s32` return — is promoting it byte-neutral?** → **NO, not always: §41d** (byte-proven; a `void` body with no `return` gains an instruction). P30 adds a second mechanism: an `s32` return keeps `$v0` live-out and blocks dbr from filling a loop-back delay slot
- **`match_one` says **SIZE-MISMATCH/short** and the target has a frame-pointer prologue (`addu $fp,$sp,$zero` / `21F0A003`)** → **The target is -O0.** Pass `--o0` to `match_one`/`rtu_match` — nothing else will ever match (§116: opt level is a property of the FILE). Known -O0 regions: boot, `ov_SC01_077_o0*`, the whale `_o0b`, and 0x8013B568..0x8013C98C — a target outside all four still needs checking
- **same instruction multiset, one contiguous window, loads/registers ROTATED inside it** → pure sched1 statement-order (`gcc-2.7.2-map/sched.md` §S1/§S4). **Cheapest lever: brute-force it** — N independent statements, script all N! orders through `match_one` (24 runs ≈ 2 min) instead of reasoning about `rank_for_schedule`
- **a two-constant `if/else` or `?:` result lands in **$v1** where the target reuses the condition's **$v0**** → **§76** — fold the condition into a NAMED local and overwrite that SAME variable with the two constants (an s16 temp, a fresh temp, an inner scope, and both ternary polarities all stay $v1; only reusing one `s32` local coalesces onto $v0). §76 reads as behemoth-only; it is not
- **a load HOISTED above a store (match_one may call it a WIDTH class)** → usually **§76 regalloc**, not a width bug: a missing WAR dependency lets sched2 hoist it. Same fix — one variable for the compare temp and the result
- **`ori $v0,0xffd8` in yours vs `addiu $v0,-0x28` in the target** → a NEGATIVE constant stored into an **unsigned** narrow local materialises via zero-extended `ori`; make the local **signed** to get `addiu`. It does NOT cost you the `lhu` on readback — gcc-2.7.2 emits `lhu` for any plain HImode load feeding an `sh` (P30 wave 4, byte-tested)
- **LENGTH-DRIFT −1 and the missing instruction is a reg-to-reg COPY in a `jal` delay slot** → a narrow **prototyped** param (plain ANSI `s16 arg3`) — §43 is indexed as the K&R-definition lever, but the ANSI form is the fix as often
- **your narrow load lost its load-delay `nop` right after an inline block move** → an `lwl/lwr`+`swl/swr` pair is a delay-slot **SPONGE** for the following load — the inverse of the §5a/§34 fence case. Align-1 4×u8 struct assign emits the inline form (§38 covers only the -O0 memcpy-call form)
- **your `e = param_1` copy VANISHED (target addresses every field off a copy at a join block)** → cse.c `make_regs_eqv` keeps a param copy only when the new pseudo's live range escapes the cse block AND outlives the param's last mention — reach that by REUSING the same variable in a later block. Copy-in-the-arms gets hoisted into the delay slot; copy-assigned-in-an-arm goes global allocno → callee-saved + 2 prologue insns
- **⚠️ the `.run/ghidra_c/<fn>.c` seed looks like a DIFFERENT function entirely** → it may be — overlays share VAs, so a seed can be decompiled from another overlay mapped at the same address. Trust the target `.s`, not the seed (P30 wave 4)
## By symptom
### delay slots & branches (6)
- **§3-T4** — Branch polarity: invert the source condition to flip gcc's chosen branch <sub>L90</sub>
- **§5a** — Cross-jump tail-merge — gcc collapses two byte-identical blocks the original kept separate (FIX FOUND) <sub>L211</sub>
- **§3-D.** — THE CROSS-JUMP RATCHET (the sharpest new trap — `func_80131340` L-C) <sub>L3508</sub>
- **§3-C.** — Inner-block declaration does NOT delay slot allocation — BYTE-REFUTED <sub>L10065</sub>
- **§162** — CROSS-JUMP DIRECTION: the surviving copy is always the LATER one, so a BACKWARD `j` into a sibling arm is a source `goto` (P30 S48) <sub>L11263</sub>
- **§162** — The cross-jump "CALL veto" is a COUNT law, not a CALL law (BOUNDS §88a; P30 S48, `func_80189540`) <sub>L11299</sub>
### instruction scheduling (19)
- **§3-T2** — Source statement order drives instruction scheduling <sub>L78</sub>
- **§3** — When a diff is pure scheduling → decomp-permuter (harness built, Phase 6) <sub>L107</sub>
- **§10** — Closing the regalloc/scheduling hard tail by hand (LZSS, Phase 7 session F — the full close) <sub>L835</sub>
- **§25** — The "schedule" class is mostly COALESCING (pin-crackable), not scheduling; + the gate two-stage + h_exact over-counts ×134 (Phase 21, cont.6) <sub>L2132</sub>
- **§3-The** — crack: the residual was gcc-2.7.2 COPY-COALESCING, not the instruction scheduler <sub>L2144</sub>
- **§3-The** — genuine scheduler — `rank_for_schedule` (sched.c), for when it IS scheduling <sub>L2160</sub>
- **§3-The** — genuine schedule WALLS (do NOT re-grind — stub) <sub>L2169</sub>
- **§32** — The region-a CAMERA-GIANT idiom set: struct-base hoisting + 4 sibling levers (Phase 24 T7, Fable5-cracked on `func_80129CF8` 191 ins, match_one MATCH; transferable to the 6 sibling giants) <sub>L2422</sub>
- **§34** — The `func_80138ED0` giant crack: gcc-2.7.2's **3-qty sort bug** + the **zero-byte asm allocation toolkit** + the **giv-init fence** (Phase 24 T5; Opus→close=21, Fable5→MATCH ×134) <sub>L2454</sub>
- **§35** — The region-a sibling-giant harvest: difficulty ≠ $s-reg count (it's global-array hoisting) + the banking recipe + new loop idioms (Phase 24 T7, 5 parallel Opus-Max agents) <sub>L2471</sub>
- **§3-A4** — SINK THE CONSUMER CALL INTO THE ARMS (the inverse of A1; `func_8016AB6C`, byte-proven) <sub>L3444</sub>
- **§49** — The LUID DIAL: a zero-byte SCHEDULING dial (the sched.c analogue of §47) — `func_8017A4AC` (536 ins ×134), Phase 26 session 8 <sub>L3527</sub>
- **§66d-5** — `residual_class`'s "structural ⇒ permuter CPU is waste" is WRONG for schedule permutations (measured, Phase 29 SESSION-18) <sub>L5491</sub>
- **§3-The** — attribution primitive (use this before calling anything a scheduling residual) <sub>L6057</sub>
- **§3-The** — scheduling rules (refining §135-2 and §135-4) <sub>L8909</sub>
- **Consequence** — for the family (a real scheduling decision) <sub>L10092</sub>
- **§148** — The loop.c hoisting THRESHOLD is arithmetic you can compute, and the `?:` clamp that folds to MIN_EXPR (P30 S42, `func_8017C6F4`, 947 ins) <sub>L10142</sub>
- **§3-A.** — `move_movables` hoists iff `threshold × savings × lifetime ≥ insn_count` — and you can read it <sub>L10148</sub>
- **§16Z** — SHARPENS *(sharpens §37 "the /s-DEP LATTICE", §136-13, §136-14, §16Xy, §162q, `gcc-2.7.2-map/sched.md` §64)* <sub>L14337</sub>
### register allocation & pins (42)
- **§10** — Closing the regalloc/scheduling hard tail by hand (LZSS, Phase 7 session F — the full close) <sub>L835</sub>
- **Residual** — A — commutative `|`/`&`/`+` result lands in the wrong source-operand register <sub>L856</sub>
- **Register-allocation** — ORDER (call-crossing $s0/$s1 swap) → FORCE it with register pins (byte-proven) <sub>L1384</sub>
- **§3-The** — LOOSE-TYPING wall is real for narrow params (Phase 16, reconfirmed) <sub>L1428</sub>
- **§3-THE** — CAP: at this tail the match_one→gate gap is the LOOSE-TYPING CALL-GRAPH wall (not cheap plumbing) <sub>L1637</sub>
- **§22** — DEF-side loose-typing recovery + grinder blacklist (Phase 21) <sub>L2005</sub>
- **§24** — The `ov_SC01_077_a.c` split-file vein: split-aware propagation, but loose-typing-gated (Phase 21) <sub>L2085</sub>
- **§25** — The "schedule" class is mostly COALESCING (pin-crackable), not scheduling; + the gate two-stage + h_exact over-counts ×134 (Phase 21, cont.6) <sub>L2132</sub>
- **§42** — The F-band ≤28 regalloc crack wave: register-pin/DENSITY levers beat the permuter (Phase 25 T7 F-band, 2026-07-10; Ultracode 9-worker wave, 4/9 banked byte-identical, 266 swept ×134) <sub>L2900</sub>
- **§43** — The K&R s16-param definition DISSOLVES the "narrow-param wall" for by-value register args (Phase 25 task A, Fable5 crack of the 369-ins giant `func_80166994` ×134, 2026-07-11) <sub>L3195</sub>
- **§45** — The flagship `func_80133CD4` crack (399 ins ×134): the merged-variable permutation-breaker + the 1-death local-alloc gate (Phase 25 task A giant escalation, Fable5 gdb-on-cc1, 2026-07-11) <sub>L3298</sub>
- **§47** — The live-length SLIDER: splitting a global.c allocno-priority TIE with one zero-byte asm (Phase 26 session 8, Fable5 Max, byte-proven on `func_8017BEBC` 952 ins ×113) <sub>L3365</sub>
- **§48** — The 12-core jr crack wave: the ALLOCNO-PRICING dials and the EBB rule (Phase 26 session 8, Ultracode, 9/12 MATCH first pass) <sub>L3405</sub>
- **§3-A.** — ALLOCNO-PRICING DIALS — move a value into the register you want, byte-neutrally <sub>L3413</sub>
- **§52** — The WALKER-FAMILY skeleton: 6 regalloc-order levers + a deeply-characterized intrinsic wall (`func_80178004`, 165 ins ×134; Phase 26, Fable5, 2026-07-15) <sub>L3913</sub>
- **§52a** — The regalloc sibling wave: new levers + two new wall classes (cheap-Opus applying §52, 2026-07-15) <sub>L3959</sub>
- **§52b** — Sibling wave 2: more de-pin levers, a third wall class, and the match_one→whole-binary gap at scale (2026-07-15) <sub>L3997</sub>
- **§66d-1** — What transfers between giants is the LOOP, not the PIN <sub>L5280</sub>
- **§70** — The giv-init base register: walk the PARAMETER, not a copy of it (Phase 29 SESSION-18, `func_801777BC`) <sub>L5619</sub>
- **§71** — Before mapping a giant, look for an already-matched SIBLING beside it (Phase 29 SESSION-18, `func_8017D960`, 3,338 ins) <sub>L5660</sub>
- **§72** — A `register __asm__` pin is a PREFERENCE, not a reservation (Phase 29 SESSION-18, `func_8017F510`) <sub>L5726</sub>
- **§74** — Auditing a pinned draft: the §72 hazard is CALLER-SAVED pins spanning a call, and only the disassembly can tell you (Phase 29 SESSION-19, `func_8017D960` b2, 5 pins) <sub>L5822</sub>
- **§76** — The allocno CLASS (local vs global) is the dominant regalloc lever, and C reaches it ONLY through declaration scope and variable reuse (Phase 29 SESSION-19, behemoth #3 `func_8017F510` 1,511 ins, 97 → MATCH, pin-free) <sub>L6028</sub>
- **§78** — A LENGTH drift can be a register grant in disguise; and `fold` never leaves a literal first in an `|` chain (Phase 29 SESSION-19, behemoth #2 `func_8017D960` 3,338 ins, 1806 → 0, pin-free) <sub>L6174</sub>
- **§76** — confirmed at scale, and a pin nuance <sub>L6251</sub>
- **§80** — A do-not-re-buy entry is scoped to its BASE, not to the function; and the pin's hidden cost is an unconditional `qty_phys_sugg` (Phase 29 SESSION-19, `func_8017BF14` 45 → 0) <sub>L6270</sub>
- **§3-The** — pin's hidden cost, with the citation <sub>L6291</sub>
- **§83** — The parameterised-repeat law, the spill-area trap, and why a per-case edit cannot move a per-case symptom (Phase 29 SESSION-20, `func_80183814` 5,122 ins, cold-ish start → 36 structural / 99.3%) <sub>L6412</sub>
- **§83c** — TRAP: a "dead local" in a prior draft may be gcc's OWN spill area <sub>L6445</sub>
- **§86** — Pinned-exemplar templatability is a PER-FAMILY property, not a per-member rate; and the §42e pin guard is now over-conservative (Phase 29 SESSION-20) <sub>L6589</sub>
- **§3-Two** — further notes worth keeping <sub>L8248</sub>
- **§137** — REGALLOC-PERM is a TWO-COMPILE ARITHMETIC PROBLEM, not a permuter job <sub>L9341</sub>
- **§3-The** — same swallow, twice more, in the integration spine <sub>L9706</sub>
- **§3-B.** — A `?:` on MEMORY operands costs ~16 bytes of invisible frame; on REGISTER operands, zero <sub>L10054</sub>
- **§3-D.** — A lone `$t8`/`$t9` in the target is RELOAD SCRATCH — reproduce the spill, don't pin the register <sub>L10070</sub>
- **§3-C.** — A zero-byte ALLOCNO-PRIORITY slider <sub>L10181</sub>
- **§150** — A register ROTATION across symmetric blocks is VARIABLE-IDENTITY evidence, not an allocator tie (P30 S43, `func_8017C6F4`, 947 ins ×4) <sub>L10309</sub>
- **§152** — BYTE SIZE is the family key that name- and h_seq-grouping both miss (P30 S43, the 0xECC family: 1 crack → 12 overlays → 11,364 ins) <sub>L10415</sub>
- **§155** — hi/lo literal scanning MUST track base registers (S45) <sub>L10555</sub>
- **§158** — The RANGE-EXTENDER: a fourth zero-emission asm lever completes the allocno toolkit (P30 S46 tier-3, `func_8017CE58`, 733 ins) <sub>L10709</sub>
- **Bonus** — facts worth keeping <sub>L10754</sub>
- **§156** — THE PREFERENCE-DONOR MERGE: cross-region variable reuse is what fills a0-a3, and a call-arg use in ONE region steers the fill in ALL of them (P30 S46 tier-3, `func_80186E24`, 611 ins: 236-off "S11 regalloc-order" → MATCH, zero new pins) <sub>L10769</sub>
### CSE / redundancy / rematerialization (3)
- **§46** — The `func_80178D40` crack (890 ins ×134, the heaviest core in the game): four LOOP-STRUCTURE levers cheap-Opus found by reading loop.c/jump.c/cse.c (Phase 26 session 8, 2026-07-13) <sub>L3313</sub>
- **§83d** — CSE's quantity budget is WHOLE-FUNCTION, so a local rewrite cannot fix a local symptom <sub>L6452</sub>
- **§153** — THE ADDRESS-REMATERIALISATION LAUNDER: a third zero-emission asm lever (P30 S43, `func_8018D98C`, 710 ins) <sub>L10463</sub>
### loops & induction variables (9)
- **§3-T1** — Loop pointer: top-of-body for `addu` induction, not constant-folded `addiu` <sub>L71</sub>
- **§34** — The `func_80138ED0` giant crack: gcc-2.7.2's **3-qty sort bug** + the **zero-byte asm allocation toolkit** + the **giv-init fence** (Phase 24 T5; Opus→close=21, Fable5→MATCH ×134) <sub>L2454</sub>
- **§35** — The region-a sibling-giant harvest: difficulty ≠ $s-reg count (it's global-array hoisting) + the banking recipe + new loop idioms (Phase 24 T7, 5 parallel Opus-Max agents) <sub>L2471</sub>
- **§46** — The `func_80178D40` crack (890 ins ×134, the heaviest core in the game): four LOOP-STRUCTURE levers cheap-Opus found by reading loop.c/jump.c/cse.c (Phase 26 session 8, 2026-07-13) <sub>L3313</sub>
- **§66d** — The permuter⇄reader loop: alternate a random search with a byte-verified idiom, and let `residual_class` decide whose turn it is (Phase 29 SESSION-17) <sub>L5245</sub>
- **§66d-1** — What transfers between giants is the LOOP, not the PIN <sub>L5280</sub>
- **§70** — The giv-init base register: walk the PARAMETER, not a copy of it (Phase 29 SESSION-18, `func_801777BC`) <sub>L5619</sub>
- **§145** — Three loop/combine levers from the S40 wave-2 drafters (16/16 match_one) <sub>L9924</sub>
- **§148** — The loop.c hoisting THRESHOLD is arithmetic you can compute, and the `?:` clamp that folds to MIN_EXPR (P30 S42, `func_8017C6F4`, 947 ins) <sub>L10142</sub>
### structs, block moves & memcpy (35)
- **§3-T2** — Source statement order drives instruction scheduling <sub>L78</sub>
- **§5** — Known hard-residual classes (instruction-identical, one byte-exact blocker) <sub>L199</sub>
- **§13** — Add a location overlay — the canonical runbook (Phase 13; the Phase-15 fleet recipe) <sub>L1056</sub>
- **§15** — Struct-heavy shared-core pipeline (Phase 16) — empirical determinations (S0) <sub>L1313</sub>
- **§16** — Guided hand-matching the struct-heavy core (Phase 17 — beats the §15 brute-force) <sub>L1335</sub>
- **§3-The** — crack: the residual was gcc-2.7.2 COPY-COALESCING, not the instruction scheduler <sub>L2144</sub>
- **§28** — Banking a "close=0 gate-rejected" giant: the canonical-extern recovery (Phase 22 T1, byte-proven on func_8015126C ×134) <sub>L2325</sub>
- **§28b** — The struct-walled close=0 giant (§28 case #3) IS bankable: the engine_types.h type-lift (Phase 22 T2, byte-proven on func_80156B74 ×134) <sub>L2357</sub>
- **§30** — Fable5Max cracks §20/§10 "unsteerable" from the gcc SOURCE: store-vs-load is a `/s` aliasing flag, the def-side wall has a macro escape, + the birthing-boost (Phase 23, byte-proven on giant `func_8014EE14` 248 ins ×134) <sub>L2382</sub>
- **§32** — The region-a CAMERA-GIANT idiom set: struct-base hoisting + 4 sibling levers (Phase 24 T7, Fable5-cracked on `func_80129CF8` 191 ins, match_one MATCH; transferable to the 6 sibling giants) <sub>L2422</sub>
- **§38** — The WHALE `func_80144B9C` (770 ins): the -O0 struct-assign memcpy idiom + the -O0 reach-134 ×134 rollout (Phase 24 T7 §G, cheap Opus — no Fable5, no calls.c) <sub>L2527</sub>
- **§40** — Structural families: the MECHANICAL symbol-remap (crack one exemplar → remap the rest, ~0 tokens) (Phase 25 T3/T7, 2026-07-08) <sub>L2553</sub>
- **§41** — The DEF-SIDE canonical-sig wall: mechanically banking a drafted giant past `conflicting types` (Phase 25 T5b batch-2, 2026-07-09; `tools/canon_sig_reconcile.py`, byte-proven on `func_8013B274`) <sub>L2710</sub>
- **§42a** — addendum — wave 2 (residuals + 29-100 band): iso-MATCH ≠ real-TU bank, the memcpy→struct-assign fix, +5 levers (2026-07-10b) <sub>L2953</sub>
- **§44** — The Phase-25 cheap-Opus giant batch: 5 structural levers + the §43 extension (2026-07-11, 6 crackers over the frontier giants) <sub>L3242</sub>
- **§46** — The `func_80178D40` crack (890 ins ×134, the heaviest core in the game): four LOOP-STRUCTURE levers cheap-Opus found by reading loop.c/jump.c/cse.c (Phase 26 session 8, 2026-07-13) <sub>L3313</sub>
- **§3-Why** — 0/8 was structural, and predictable from two words <sub>L4045</sub>
- **§54** — `--fix-def-sig`: the member's CANONICAL DECLARATION is a build step too (tiny-IMM mega-pools, +4,801, Phase 29 T6, 2026-07-16) <sub>L4163</sub>
- **§56b** — PROPAGATING an h_seq giant: the exemplar's externs MUST be fleet-canonical, not the draft's types <sub>L4232</sub>
- **§65a** — The blast-radius taxonomy (makes §61's law structural instead of remembered) <sub>L5030</sub>
- **§66d-5** — `residual_class`'s "structural ⇒ permuter CPU is waste" is WRONG for schedule permutations (measured, Phase 29 SESSION-18) <sub>L5491</sub>
- **§83** — The parameterised-repeat law, the spill-area trap, and why a per-case edit cannot move a per-case symptom (Phase 29 SESSION-20, `func_80183814` 5,122 ins, cold-ish start → 36 structural / 99.3%) <sub>L6412</sub>
- **§84** — The DERIVED-OFFSET remap bug: a hand-computed literal that encodes the DISTANCE between two per-overlay symbols, and why `match_one` is structurally blind to it (Phase 29 SESSION-20, `func_8013D53C`) <sub>L6472</sub>
- **§3-The** — construct <sub>L6477</sub>
- **§91** — A structure-TRANSFER is only valid where the structure corresponds: the `--like` role trap (Phase 29 SESSION-21, `func_8012AAAC` ×137) <sub>L6842</sub>
- **§3-The** — three-hypothesis trail, because two of them were wrong and the wrongness is instructive <sub>L6871</sub>
- **§129** — Post-carve, `rtu_match`/`match_one` COUNT THE JUMP TABLE AS INSTRUCTIONS; and a carve must never be committed without its owner (P30 S28, `func_8013BD74`) <sub>L8437</sub>
- **§129a** — the target instruction count is INFLATED after a carve <sub>L8441</sub>
- **§3-The** — DEFINITION-side alias is the only escape when the fleet canon disagrees on a promoting param <sub>L9470</sub>
- **§3-Two** — errors of mine, both instructive <sub>L10006</sub>
- **§160** — THE REACH-15 WAVE HARVEST: an align-1 block move, and the instrument that called it a wall (P30 S47) <sub>L10890</sub>
- **§16Xy** — SHARPENS *(sharpens §136d-3, §37 /s-DEP LATTICE, §135-2, §136-13, §162q)* <sub>L12297</sub>
- **§3-The** — `/s` drop clause is in ALL THREE dependence predicates, so the FIXED-ADDRESS STORE is what floats (P30 S48, `func_8017CA18`, ov_MAIN_012) <sub>L12299</sub>
- **§16Z** — SHARPENS *(sharpens §37 "the /s-DEP LATTICE", §136-13, §136-14, §16Xy, §162q, `gcc-2.7.2-map/sched.md` §64)* <sub>L14337</sub>
- **§3-The** — ADDRESS-CLASS TABLE: which load/store pairs even REACH the `/s` clause (P30 S48 wave 4, `func_80185B44`, ov_SC03_014) <sub>L14339</sub>
### types, signedness & load/store width (34)
- **§3-I1** — Unsigned range check: `(x - lo) < (hi-lo)` → `addiu`+`sltiu` <sub>L41</sub>
- **§3-I2** — Byte mask forces `andi` even after `lbu` <sub>L47</sub>
- **§3-T3** — Types <sub>L85</sub>
- **§7** — PsyQ SDK types & symbols (the library-call prerequisite) <sub>L303</sub>
- **§14c** — Callee-signature-aware harvest — breaking the extern-type-conflict wall (Phase 15, T6) <sub>L1213</sub>
- **Phase-20** — RESOLUTION — `tools/cast_call_sites.py` BUILT + the cap re-diagnosed (R14, byte-proven) <sub>L1701</sub>
- **§23** — Giant `func_80153E00` cracked (scalar-data CAST); BUT most giant drafts are STALE+INCOMPLETE, and a diag MUST remove artifacts (Phase 21 — byte-proven + a self-correction) <sub>L2032</sub>
- **§28b** — The struct-walled close=0 giant (§28 case #3) IS bankable: the engine_types.h type-lift (Phase 22 T2, byte-proven on func_80156B74 ×134) <sub>L2357</sub>
- **§33** — Automating the giant decl-reconcile: `tools/reconcile_decls.py` (the DATA analog of §20's `cast_call_sites`) + a fleet-majority type oracle (Phase 24 T7b, byte-proven on `func_80129CF8`) <sub>L2434</sub>
- **§40a** — The DECL-RECONCILE pass (type-lift so remapped drafts compile in the sibling TU) (Phase 25 T7.2, 2026-07-08) <sub>L2601</sub>
- **§41** — The DEF-SIDE canonical-sig wall: mechanically banking a drafted giant past `conflicting types` (Phase 25 T5b batch-2, 2026-07-09; `tools/canon_sig_reconcile.py`, byte-proven on `func_8013B274`) <sub>L2710</sub>
- **§41d** — `void`→`s32` is NOT always byte-neutral: gate the RAW draft FIRST (Phase 26 session 6, byte-proven) <sub>L2878</sub>
- **§42b** — addendum — wave 3 (Max, 2026-07-10c): THE STALE-OBJECT GATE TRAP + the read-global `&`-cast drift + fix <sub>L2994</sub>
- **§43** — The K&R s16-param definition DISSOLVES the "narrow-param wall" for by-value register args (Phase 25 task A, Fable5 crack of the 369-ins giant `func_80166994` ×134, 2026-07-11) <sub>L3195</sub>
- **§3-C.** — TYPE- AND SHAPE-DRIVEN CODEGEN (the C type literally selects the addressing mode) <sub>L3484</sub>
- **§56b** — PROPAGATING an h_seq giant: the exemplar's externs MUST be fleet-canonical, not the draft's types <sub>L4232</sub>
- **§64** — The §20 type-lift's three laws: fold the tagged typedef, check VISIBILITY, and strip only what is TEXTUALLY IDENTICAL (`lift_types.py`, Phase 29 SESSION-14, 2026-07-23) <sub>L4908</sub>
- **§64a** — VARIANT types: UNIQUIFY the camps, do not reconcile them (`uniquify_type.py`, Phase 29 SESSION-14) <sub>L4957</sub>
- **§65g** — Where the cheap levers STOP: the local-type and in-TU-self-decl classes did not yield <sub>L5139</sub>
- **§68** — A comment-only line halted the extern scan, and the skip label blamed the type cap (Phase 29 SESSION-18) <sub>L5524</sub>
- **§73** — A def-side self-decl conflict has TWO axes: RETURN (fleet widen, T2) and PARAMS (casts at each use, T0). Diagnose which before paying for the expensive one (Phase 29 SESSION-19, `func_8014F3E8` + `func_8014D4C0`) <sub>L5783</sub>
- **§75c** — Class-B's remedy is the FULL §17a-1 PAIR (decl **and** call-site cast); a decl-only fix moves the error and looks like a new wall (Phase 29 SESSION-19, `func_8012F14C`) <sub>L5997</sub>
- **§3-The** — defect this exposed: a shared type that is present but invisible <sub>L6354</sub>
- **§92** — Conforming a DECLARATION: pointer changes are caller-neutral, scalar-WIDTH changes are not (Phase 29 SESSION-21, `tools/conform_decls.py`) <sub>L6891</sub>
- **§94** — A family sweep's `0/N` is a TYPE-CARRY failure until proven otherwise: lift the exemplar's local types, ALL of them, transitively (Phase 29 SESSION-21, `func_8016B6BC` 0/137 → 137/137) <sub>L6947</sub>
- **§100** — Prefer the DRAFT-LOCAL fix: a type only one function uses belongs in its BODY, not in a shared header (Phase 29 SESSION-22, `func_80175DA8` 0/137 → 137/137) <sub>L7216</sub>
- **§120** — Uniquify draft-defined TYPE names; and check which of N staging sites you actually patched (Phase 29 T93) <sub>L8026</sub>
- **§3-Do** — NOT "strip the duplicate typedef" — it breaks the extern that uses it <sub>L8037</sub>
- **§3-The** — type-form rules <sub>L8879</sub>
- **§143** — `cast_call_sites` read a RETURN STATEMENT as a prototype and deleted it. A 0/39 sweep became 18/39. (P30 S40) <sub>L9831</sub>
- **Then** — propagation returned 0/137 TWICE — both times a missing TYPE <sub>L9997</sub>
- **§154** — Reading a disc payload: the module-id word, static base derivation, and "type 1 = uncompressed overlay" (P30 S44) <sub>L10519</sub>
- **§3-C.** — PAC type 1 = the same payload class as type 4, just NOT compressed <sub>L10545</sub>
- **§155b** — check the TYPE your oracle returns before comparing against it (S45 p5) <sub>L10584</sub>
### declarations, prototypes & K&R (57)
- **§3-T4** — Branch polarity: invert the source condition to flip gcc's chosen branch <sub>L90</sub>
- **§8c** — Splitting a TU means rebuilding its DECLARATION ENVIRONMENT, not moving text (Phase 26 session 6) <sub>L437</sub>
- **§8d** — Templating a body INTO a TU must not CHANGE its declaration environment — demote the carried data externs (Phase 26 session 8, byte-proven on `func_8015AE2C` ×133) <sub>L483</sub>
- **§13** — Add a location overlay — the canonical runbook (Phase 13; the Phase-15 fleet recipe) <sub>L1056</sub>
- **§14c** — Callee-signature-aware harvest — breaking the extern-type-conflict wall (Phase 15, T6) <sub>L1213</sub>
- **§3-The** — pipeline gotcha — match_one ≠ the gate; `sig_unify` is MANDATORY <sub>L1421</sub>
- **§3-The** — gate two-stage — sig_unify is a FALLBACK, not unconditional (`gate_stage.py`, §19 folded in) <sub>L2189</sub>
- **§28** — Banking a "close=0 gate-rejected" giant: the canonical-extern recovery (Phase 22 T1, byte-proven on func_8015126C ×134) <sub>L2325</sub>
- **§28d** — The "macro-extern-injection" lever: freeing reach-134 inline matches dedup_propagate skips as "not self-contained" (Phase 23, `tools/inject_capped_externs.py`) <sub>L2366</sub>
- **§33** — Automating the giant decl-reconcile: `tools/reconcile_decls.py` (the DATA analog of §20's `cast_call_sites`) + a fleet-majority type oracle (Phase 24 T7b, byte-proven on `func_80129CF8`) <sub>L2434</sub>
- **§40a** — The DECL-RECONCILE pass (type-lift so remapped drafts compile in the sibling TU) (Phase 25 T7.2, 2026-07-08) <sub>L2601</sub>
- **§41** — The DEF-SIDE canonical-sig wall: mechanically banking a drafted giant past `conflicting types` (Phase 25 T5b batch-2, 2026-07-09; `tools/canon_sig_reconcile.py`, byte-proven on `func_8013B274`) <sub>L2710</sub>
- **§41b** — addendum — M4 "reconcile_decls" tier is ALSO a probe over-count: 0/8 mechanical (Phase 25 T7-M4, 2026-07-10) <sub>L2858</sub>
- **§41d** — `void`→`s32` is NOT always byte-neutral: gate the RAW draft FIRST (Phase 26 session 6, byte-proven) <sub>L2878</sub>
- **§43** — The K&R s16-param definition DISSOLVES the "narrow-param wall" for by-value register args (Phase 25 task A, Fable5 crack of the 369-ins giant `func_80166994` ×134, 2026-07-11) <sub>L3195</sub>
- **§51g** — When the thing you are scanning has a GRAMMAR, parse the grammar (`tools/cdecl.py`) <sub>L3769</sub>
- **§54** — `--fix-def-sig`: the member's CANONICAL DECLARATION is a build step too (tiny-IMM mega-pools, +4,801, Phase 29 T6, 2026-07-16) <sub>L4163</sub>
- **§56** — Banking a hand-drafted GIANT into its exemplar TU: self-contained draft vs live-TU decls, 4 reconciliation tactics (`func_8013FAF8`, 312 ins ×138, Phase 29 T4, 2026-07-17) <sub>L4187</sub>
- **§56b** — PROPAGATING an h_seq giant: the exemplar's externs MUST be fleet-canonical, not the draft's types <sub>L4232</sub>
- **§57** — The SELF-decl normalize: the sibling's OWN caller declares the templated fn divergently (the third §17a-1 direction; `tools/normalize_self_decls.py`, func_801670E4 ×137, Phase 29, 2026-07-18) <sub>L4256</sub>
- **§61** — Task 14: the gate ladder's missing stage is the ARITY pre-pass, and it is TU-side not draft-side (Phase 29, 2026-07-21) <sub>L4545</sub>
- **§63** — The fresh-138 DEF-SIDE blocker: fix the HEADER decl, not the draft (`fix_header_decl.py`, Phase 29 SESSION-13, 2026-07-23) <sub>L4877</sub>
- **§63** — UPDATE (Phase 29 SESSION-14) — `fix_header_decl`'s "SAFE" verdict is FLEET-BLIND; it MUST be R22-validated <sub>L5000</sub>
- **§65c** — `rtu_match` MATCH → bank held 13/13 on self-decl, but broke on the FIRST callee-decl case <sub>L5081</sub>
- **§65g** — Where the cheap levers STOP: the local-type and in-TU-self-decl classes did not yield <sub>L5139</sub>
- **§66a** — The widest write in a pipeline is the one most likely to be UNDECLARED <sub>L5181</sub>
- **§68** — A comment-only line halted the extern scan, and the skip label blamed the type cap (Phase 29 SESSION-18) <sub>L5524</sub>
- **§73** — A def-side self-decl conflict has TWO axes: RETURN (fleet widen, T2) and PARAMS (casts at each use, T0). Diagnose which before paying for the expensive one (Phase 29 SESSION-19, `func_8014F3E8` + `func_8014D4C0`) <sub>L5783</sub>
- **§75** — A propagation cap is usually a MINORITY-SPELLING SOURCE OVERLAY, not a wall: census the carried extern before believing the exclusion message (Phase 29 SESSION-19, `func_8014F3E8` ×4 → ×138) <sub>L5866</sub>
- **§75b** — A body's preamble can carry `#define`s, not just `extern`s; extraction lifts only the externs (Phase 29 SESSION-19, `func_80165CA0` ×3 → fleet) <sub>L5948</sub>
- **§75c** — Class-B's remedy is the FULL §17a-1 PAIR (decl **and** call-site cast); a decl-only fix moves the error and looks like a new wall (Phase 29 SESSION-19, `func_8012F14C`) <sub>L5997</sub>
- **§76** — The allocno CLASS (local vs global) is the dominant regalloc lever, and C reaches it ONLY through declaration scope and variable reuse (Phase 29 SESSION-19, behemoth #3 `func_8017F510` 1,511 ins, 97 → MATCH, pin-free) <sub>L6028</sub>
- **§79** — For a 0-callee giant, fingerprint by DATA symbols (§71 cannot fire); and the STACK-SLOT ORDER is a declaration-order oracle (Phase 29 SESSION-19, `func_8017BF14` 4,763 ins, cold start → 45/4763) <sub>L6220</sub>
- **§3-NEW** — LEVER — the frame layout reads back the original declaration order <sub>L6240</sub>
- **§3-1.** — The inlined-helper signature <sub>L6375</sub>
- **§92** — Conforming a DECLARATION: pointer changes are caller-neutral, scalar-WIDTH changes are not (Phase 29 SESSION-21, `tools/conform_decls.py`) <sub>L6891</sub>
- **§95** — `reconcile_tu` dropped the SIBLING declarators of a multi-symbol `extern` line (Phase 29 SESSION-21, `func_80176218`) <sub>L6983</sub>
- **§96** — The same rewrite, one shape down: `reconcile_tu` matched statements to lines by TEXT, so every COMMENTED declaration was silently skipped (Phase 29 SESSION-22, `func_80176218` banked) <sub>L7018</sub>
- **§98** — `conform_decls` had three defects, and only the third needed R22 to find (Phase 29 SESSION-22, `func_8014CF04`) <sub>L7113</sub>
- **§99** — The narrow-param wall is a DEF-side problem with a ZERO-blast-radius fix: convert the definition to K&R (Phase 29 SESSION-22, `func_80175AB8` + `func_80175DA8`) <sub>L7167</sub>
- **§102** — A PLUMBING verdict can MASK a DIFF; and K&R is not always a codegen change (Phase 29 SESSION-22, `func_8016EC0C`) <sub>L7272</sub>
- **§103** — A FILE-scope `extern` in a shared overlay TU is a GLOBAL constraint on every LATER function; move the DECL, not the draft (Phase 29 T48/T51, `func_80135260` — the fleet-wide half) <sub>L7307</sub>
- **§104** — Two silent-skip defects in one scan: match on MASKED text, emit from the ORIGINAL (Phase 29 T53, `gather_externs`) <sub>L7395</sub>
- **§112** — A macro-scoped declaration only collides where the macro is INSTANTIATED (Phase 29 T67/T69, `audit_header_sigs.py`) <sub>L7730</sub>
- **§113** — An ARITY blocker only exists if the macro CALLS the function; an address-taken use has no call site (Phase 29 T72) <sub>L7776</sub>
- **§114** — The THIRD decl axis: a CALLEE the draft declares differently from the target TU (Phase 29 T76/T77) <sub>L7808</sub>
- **§3-Do** — NOT "strip the duplicate typedef" — it breaks the extern that uses it <sub>L8037</sub>
- **§121** — Synthesise externs for macro-DEFINED callees from the macro's own definition head (Phase 29 T95) <sub>L8061</sub>
- **§3-The** — declaration surface (integration, not codegen) <sub>L8938</sub>
- **§136f** — Two declaration sub-cases the reconcile lane surfaced (lane now 15/15 lifetime) <sub>L9183</sub>
- **§138** — The propagation lanes: a gate refusal is a DECLARATION, and which lever you owe depends on blast radius <sub>L9412</sub>
- **Reconciling** — a gate-refused draft: which way you edit depends on WHERE the TU's decl is <sub>L9562</sub>
- **§141** — The §134 class is CLOSED: every line-shape decision now routes through `cdecl._mask` (P30 S39) <sub>L9737</sub>
- **§143** — `cast_call_sites` read a RETURN STATEMENT as a prototype and deleted it. A 0/39 sweep became 18/39. (P30 S40) <sub>L9831</sub>
- **§3-C.** — Inner-block declaration does NOT delay slot allocation — BYTE-REFUTED <sub>L10065</sub>
- **§159** — THE DECLARATION AXIS: conform to byte-truth, and make every guard state its COVERAGE (P30 S47; ~10,930 sites across 8 axes, fleet byte-identical) <sub>L10825</sub>
- **§168** — THE COUSIN TIER (P30 S49, 2026-08-12): h_seq's exact-hash brittleness, measured — and the similarity map above it <sub>L16208</sub>
### jump tables & switches (27)
- **§8** — rodata island (compiler jump tables) — the `.data→.rodata→.data` sandwich (Phase 7) <sub>L320</sub>
- **§8a** — rodata island in a flat OVERLAY — the tail sandwich, per matched jr-function (Phase 26 — PoC PROVEN) <sub>L342</sub>
- **§8a-pad** — a trailing `.word 0x00000000` under a jtbl dlabel is `.align` PAD, not an entry (Phase 26 session 6, byte-proven) <sub>L380</sub>
- **§8b** — MULTI-jtbl per overlay — the `ld_interleave --order` sandwich + the same-subseg cases (Phase 26 session 4) <sub>L404</sub>
- **§8e** — The jtbl ALIGNMENT LAW + the pad-spec filter — multi-table .rodata spans (Phase 29, byte-proven; `.run/probe_jtbl/verdict.md`) <sub>L530</sub>
- **§3-The** — clean object-level metric (use this, not the permuter score, for jtbl/rodata functions) <sub>L844</sub>
- **§41b** — T7 execution: the object-only probe OVER-counts BANKABLE by two link/rodata classes (Phase 25 T7-M1, 2026-07-10) <sub>L2809</sub>
- **§48** — The 12-core jr crack wave: the ALLOCNO-PRICING dials and the EBB rule (Phase 26 session 8, Ultracode, 9/12 MATCH first pass) <sub>L3405</sub>
- **§53** — SWEEP A FAMILY WITH THE TOOL ITS EXEMPLAR NEEDED: the jr/switch carve, and how omitting it manufactured the "families don't template" doctrine (Phase 28 T1, 2026-07-15) <sub>L4028</sub>
- **§61b** — The jtbl gate stage: built, and the ORDERING law it exposed (Phase 29 Task-14 stage 4, 2026-07-21) <sub>L4658</sub>
- **§61c** — The jtbl bank is INCREMENTALLY valid and CLEAN-INVALID (Phase 29, 2026-07-21) — the blocking finding <sub>L4713</sub>
- **§62** — The jtbl RECONCILE must also follow the carve: the post-carve draft reconcile (`harvest_verify._jtbl_reconcile`, Phase 29 SESSION-11, 2026-07-22) <sub>L4833</sub>
- **§81** — Banking a jr (jump-table) function: the 3-step carve chain, and why `match_one` cannot see the problem (Phase 29 SESSION-19, `func_8017C954`) <sub>L6323</sub>
- **§88d** — BANKING ORDER: run the §81 carve chain BEFORE banking, never after <sub>L6701</sub>
- **§97** — The gate's own tree hygiene: a refused carve, an unchecked recovery, and a snapshot that captured a dirty tree (Phase 29 SESSION-22) <sub>L7066</sub>
- **§105** — A gate's revert must survive an EXCEPTION, not just a failure (Phase 29 T53, `jtbl_family_bank`) <sub>L7431</sub>
- **§125** — Split the CARVE from the BODY before calling a jr residue a wall — and measure it by SHA from a CLEAN tree (P30 SESSION-28; **this section's first draft was WRONG and the method caught it**) <sub>L8206</sub>
- **§126** — The carve-within-a-carve: an ADDRESS RANGE is not an OPTIMIZATION REGION (P30 T2, byte-proven end-to-end) <sub>L8264</sub>
- **§129** — Post-carve, `rtu_match`/`match_one` COUNT THE JUMP TABLE AS INSTRUCTIONS; and a carve must never be committed without its owner (P30 S28, `func_8013BD74`) <sub>L8437</sub>
- **§129a** — the target instruction count is INFLATED after a carve <sub>L8441</sub>
- **§129b** — never commit a carve whose owner is still a stub (it strands the carve) <sub>L8462</sub>
- **§130** — An INCREMENTAL build can report BYTE-IDENTICAL for a change the CLEAN build cannot even LINK (P30 S28, the jr pair) <sub>L8486</sub>
- **§131** — The jtbl OVER-SPAN: `sltiu N` is ground truth in BOTH directions, and the zero-word rule only guards one (P30 S28, `func_80191C50`) <sub>L8533</sub>
- **§132** — The `JR-PAIR-IN-ONE-O0-OBJECT` "wall" was TWO instrument defects: a merged-double span the carve could not see, and a truncated object no rule deleted (P30 S29, `func_8013B83C` + `func_8013BD74`) <sub>L8570</sub>
- **§132b** — When the span's already-matched owner is ITSELF multi-switch: `--span-rel` (P30 S1, `func_8014032C`) <sub>L8660</sub>
- **§139** — A GATE THAT GREPS FOR VERDICTS MUST ASSERT 1:1 ACCOUNTING; and a `--src` filter must not survive a carve (P30 S38, wave 6: 10 of 16 drafts vanished) <sub>L9591</sub>
- **§161** — THE RETRY-WAVE HARVEST: a jump table indexed from zero, and two allocator traps (P30 S47) <sub>L10966</sub>
### optimisation level (-O0/-O2) (12)
- **§6** — Per-module optimization mixing — the -O0 boot module (Phase 7) <sub>L246</sub>
- **Detecting** — the opt level (do this first) <sub>L254</sub>
- **Build** — mechanism — per-file opt override (splat resegmentation) <sub>L288</sub>
- **§18** — Per-file `-O0` split inside an overlay/blob (Phase 19 T1) <sub>L1519</sub>
- **§38** — The WHALE `func_80144B9C` (770 ins): the -O0 struct-assign memcpy idiom + the -O0 reach-134 ×134 rollout (Phase 24 T7 §G, cheap Opus — no Fable5, no calls.c) <sub>L2527</sub>
- **§39** — The ×1→×134 giant-endgame: propagate a matched **-O2** giant via the NATIVE DEFINE-macro path (Phase 24 T7 §G close, 2026-07-08) <sub>L2537</sub>
- **§116** — Optimization level is a property of the FILE, not the function: read a family 0/N against the member's stub HOME (Phase 29 T79) <sub>L7877</sub>
- **§3-The** — finding: opt level is per FILE, so the file's contents must be opt-HOMOGENEOUS <sub>L8279</sub>
- **§127** — The `-O0` regime: the CONSTANT-OFFSET FOLD, and why `-O0` needs its own idiom set (P30 T3 wave, 15 targets) <sub>L8349</sub>
- **§3-The** — rest of the `-O0` regime (write PLAIN C, and mean it) <sub>L8367</sub>
- **§127a** — §71 (sibling-first) is the strongest `-O0` lever, and it beats the index <sub>L8377</sub>
- **§132** — The `JR-PAIR-IN-ONE-O0-OBJECT` "wall" was TWO instrument defects: a merged-double span the carve could not see, and a truncated object no rule deleted (P30 S29, `func_8013B83C` + `func_8013BD74`) <sub>L8570</sub>
### family propagation & sweeps (84)
- **§8d** — Templating a body INTO a TU must not CHANGE its declaration environment — demote the carried data externs (Phase 26 session 8, byte-proven on `func_8015AE2C` ×133) <sub>L483</sub>
- **§11** — Cross-binary dedup & code-sharing (Phase 11 — "one match unlocks many") <sub>L908</sub>
- **§3-The** — mechanism: game-code dedup is SOURCE-LEVEL, not an object swap (R-D1, the key lesson) <sub>L926</sub>
- **§3-The** — flat-blob overlay config (what the template encodes) <sub>L1071</sub>
- **§3-THE** — NON-4-ALIGNED-OVERLAY GOTCHA (≈75% of the fleet; fixed in the template + Makefile, automatic) <sub>L1079</sub>
- **§14** — Propagate a matched function across the fleet — `tools/dedup_propagate.py` (Phase 15) <sub>L1126</sub>
- **§19** — Scaling the toolkit waves — the recovery PIPELINE + the propagation CAP (Phase 19 T3) <sub>L1597</sub>
- **§24** — The `ov_SC01_077_a.c` split-file vein: split-aware propagation, but loose-typing-gated (Phase 21) <sub>L2085</sub>
- **§25** — The "schedule" class is mostly COALESCING (pin-crackable), not scheduling; + the gate two-stage + h_exact over-counts ×134 (Phase 21, cont.6) <sub>L2132</sub>
- **§3-h** — _exact OVER-COUNTS ×134 — verify shareability before crediting a class's "reach-134" (R14) <sub>L2177</sub>
- **Where** — this leaves the reach-134 tail (cont.6 option-3, now CONFIRMED byte-backed) <sub>L2233</sub>
- **§28** — Banking a "close=0 gate-rejected" giant: the canonical-extern recovery (Phase 22 T1, byte-proven on func_8015126C ×134) <sub>L2325</sub>
- **§28c** — The close=0 recovery is NOT fully exhausted (§26 corrected, R14); + the dedup_propagate registry-skip recovery (Phase 22 T2) <sub>L2352</sub>
- **§28b** — The struct-walled close=0 giant (§28 case #3) IS bankable: the engine_types.h type-lift (Phase 22 T2, byte-proven on func_80156B74 ×134) <sub>L2357</sub>
- **§28d** — The "macro-extern-injection" lever: freeing reach-134 inline matches dedup_propagate skips as "not self-contained" (Phase 23, `tools/inject_capped_externs.py`) <sub>L2366</sub>
- **§30** — Fable5Max cracks §20/§10 "unsteerable" from the gcc SOURCE: store-vs-load is a `/s` aliasing flag, the def-side wall has a macro escape, + the birthing-boost (Phase 23, byte-proven on giant `func_8014EE14` 248 ins ×134) <sub>L2382</sub>
- **§34** — The `func_80138ED0` giant crack: gcc-2.7.2's **3-qty sort bug** + the **zero-byte asm allocation toolkit** + the **giv-init fence** (Phase 24 T5; Opus→close=21, Fable5→MATCH ×134) <sub>L2454</sub>
- **§38** — The WHALE `func_80144B9C` (770 ins): the -O0 struct-assign memcpy idiom + the -O0 reach-134 ×134 rollout (Phase 24 T7 §G, cheap Opus — no Fable5, no calls.c) <sub>L2527</sub>
- **§39** — The ×1→×134 giant-endgame: propagate a matched **-O2** giant via the NATIVE DEFINE-macro path (Phase 24 T7 §G close, 2026-07-08) <sub>L2537</sub>
- **§40** — Structural families: the MECHANICAL symbol-remap (crack one exemplar → remap the rest, ~0 tokens) (Phase 25 T3/T7, 2026-07-08) <sub>L2553</sub>
- **§40a** — The DECL-RECONCILE pass (type-lift so remapped drafts compile in the sibling TU) (Phase 25 T7.2, 2026-07-08) <sub>L2601</sub>
- **§40b** — The reloc-tracker blind spot: the indexed-global idiom that hid the "reach-1 tail" (Phase 26 Task 1, 2026-07-11, byte-verified V0/V1) <sub>L2634</sub>
- **§40c** — The h_seq per-sibling reconcile: templating a reconcile-class crack ×134 (Phase 26 Task 8, 2026-07-12, byte-proven) <sub>L2676</sub>
- **§41c** — T7-M2: the ×134 def-side-wall sweep via per-sibling RE-reconcile (Phase 25, 2026-07-10; 4,389 banks, ~0 agent tokens) <sub>L2839</sub>
- **§42** — The F-band ≤28 regalloc crack wave: register-pin/DENSITY levers beat the permuter (Phase 25 T7 F-band, 2026-07-10; Ultracode 9-worker wave, 4/9 banked byte-identical, 266 swept ×134) <sub>L2900</sub>
- **§42e** — propagating a CRACK ×134: the def-finder bug + the byte-drift residual (the "remap-fail" misdiagnosis) <sub>L3121</sub>
- **§43** — The K&R s16-param definition DISSOLVES the "narrow-param wall" for by-value register args (Phase 25 task A, Fable5 crack of the 369-ins giant `func_80166994` ×134, 2026-07-11) <sub>L3195</sub>
- **§45** — The flagship `func_80133CD4` crack (399 ins ×134): the merged-variable permutation-breaker + the 1-death local-alloc gate (Phase 25 task A giant escalation, Fable5 gdb-on-cc1, 2026-07-11) <sub>L3298</sub>
- **§46** — The `func_80178D40` crack (890 ins ×134, the heaviest core in the game): four LOOP-STRUCTURE levers cheap-Opus found by reading loop.c/jump.c/cse.c (Phase 26 session 8, 2026-07-13) <sub>L3313</sub>
- **§47** — The live-length SLIDER: splitting a global.c allocno-priority TIE with one zero-byte asm (Phase 26 session 8, Fable5 Max, byte-proven on `func_8017BEBC` 952 ins ×113) <sub>L3365</sub>
- **§49** — The LUID DIAL: a zero-byte SCHEDULING dial (the sched.c analogue of §47) — `func_8017A4AC` (536 ins ×134), Phase 26 session 8 <sub>L3527</sub>
- **§52** — The WALKER-FAMILY skeleton: 6 regalloc-order levers + a deeply-characterized intrinsic wall (`func_80178004`, 165 ins ×134; Phase 26, Fable5, 2026-07-15) <sub>L3913</sub>
- **§3-The** — 6 levers (the "walker-family skeleton" — apply to the 12 siblings; levers 1-5 retire ~half the residual) <sub>L3924</sub>
- **§53** — SWEEP A FAMILY WITH THE TOOL ITS EXEMPLAR NEEDED: the jr/switch carve, and how omitting it manufactured the "families don't template" doctrine (Phase 28 T1, 2026-07-15) <sub>L4028</sub>
- **§55c** — Sizing the propagate: a TARGETED propagate is ~4 min/core, and "it's slow" was a BROKEN-TREE ARTIFACT <sub>L4141</sub>
- **§54** — `--fix-def-sig`: the member's CANONICAL DECLARATION is a build step too (tiny-IMM mega-pools, +4,801, Phase 29 T6, 2026-07-16) <sub>L4163</sub>
- **§56** — Banking a hand-drafted GIANT into its exemplar TU: self-contained draft vs live-TU decls, 4 reconciliation tactics (`func_8013FAF8`, 312 ins ×138, Phase 29 T4, 2026-07-17) <sub>L4187</sub>
- **§56b** — PROPAGATING an h_seq giant: the exemplar's externs MUST be fleet-canonical, not the draft's types <sub>L4232</sub>
- **§57** — The SELF-decl normalize: the sibling's OWN caller declares the templated fn divergently (the third §17a-1 direction; `tools/normalize_self_decls.py`, func_801670E4 ×137, Phase 29, 2026-07-18) <sub>L4256</sub>
- **§57a** — Two NSD corrections + the SURGICAL-ONLY law + the honest broad-sweep yield (Phase 29, 2026-07-18) <sub>L4303</sub>
- **§59** — Three h_seq sweep-residual classes match_one/the-exemplar-bank don't reveal (Phase 29 crack-wave close, 2026-07-18) <sub>L4377</sub>
- **§3-Two** — corollaries worth remembering <sub>L4450</sub>
- **§65a** — The blast-radius taxonomy (makes §61's law structural instead of remembered) <sub>L5030</sub>
- **§3-Giv** — record order (the §70 family) <sub>L5760</sub>
- **§75** — A propagation cap is usually a MINORITY-SPELLING SOURCE OVERLAY, not a wall: census the carried extern before believing the exclusion message (Phase 29 SESSION-19, `func_8014F3E8` ×4 → ×138) <sub>L5866</sub>
- **§75a** — The exclusion classes, enumerated with named causes (Phase 29 SESSION-19, the 134-binary `dedup_extend` sweep) <sub>L5925</sub>
- **§75b** — A body's preamble can carry `#define`s, not just `extern`s; extraction lifts only the externs (Phase 29 SESSION-19, `func_80165CA0` ×3 → fleet) <sub>L5948</sub>
- **§76** — The allocno CLASS (local vs global) is the dominant regalloc lever, and C reaches it ONLY through declaration scope and variable reuse (Phase 29 SESSION-19, behemoth #3 `func_8017F510` 1,511 ins, 97 → MATCH, pin-free) <sub>L6028</sub>
- **§77** — Every extraction tool carries a NARROW hard-coded preamble set; anything outside it silently caps the body's reach. Diff the preamble before you gate. (Phase 29 SESSION-19 — three variants in one session, two different tools) <sub>L6084</sub>
- **§84** — The DERIVED-OFFSET remap bug: a hand-computed literal that encodes the DISTANCE between two per-overlay symbols, and why `match_one` is structurally blind to it (Phase 29 SESSION-20, `func_8013D53C`) <sub>L6472</sub>
- **§86** — Pinned-exemplar templatability is a PER-FAMILY property, not a per-member rate; and the §42e pin guard is now over-conservative (Phase 29 SESSION-20) <sub>L6589</sub>
- **§3-THE** — LAW: all-or-nothing PER FAMILY <sub>L6600</sub>
- **§3-Why** — the two live families differ from the three dead ones — the open question <sub>L6627</sub>
- **§3-The** — cheap discriminator, before spending a sweep <sub>L6666</sub>
- **§89b** — the parallel gate farm existed; the family path could not reach it (`tools/sweep_parallel.py`) <sub>L6745</sub>
- **§91** — A structure-TRANSFER is only valid where the structure corresponds: the `--like` role trap (Phase 29 SESSION-21, `func_8012AAAC` ×137) <sub>L6842</sub>
- **§94** — A family sweep's `0/N` is a TYPE-CARRY failure until proven otherwise: lift the exemplar's local types, ALL of them, transitively (Phase 29 SESSION-21, `func_8016B6BC` 0/137 → 137/137) <sub>L6947</sub>
- **§105** — A gate's revert must survive an EXCEPTION, not just a failure (Phase 29 T53, `jtbl_family_bank`) <sub>L7431</sub>
- **§107** — A lever wired into ONE gate path is a lever most families cannot reach (Phase 29 T56, `func_80144090` 0/136 → 136/136) <sub>L7513</sub>
- **§108** — Diagnosing a family `0/N`: the four causes, and the third opt-in lever (Phase 29 T59) <sub>L7551</sub>
- **§111** — The distinct-code metric is not noisy: a family pays it only if its members are byte-VARIANT (Phase 29 T66) <sub>L7681</sub>
- **§116** — Optimization level is a property of the FILE, not the function: read a family 0/N against the member's stub HOME (Phase 29 T79) <sub>L7877</sub>
- **§123** — PROPAGATE A FAMILY WITH THE TOOL ITS TIER NEEDS: `dedup_propagate` is h_exact-only; its refusals are statements about the TOOL (P30 wave 1, 2026-07-30) <sub>L8116</sub>
- **§124** — A "not matched" verdict can mean the definition is there under a DIFFERENT C NAME: the asm-label alias blind spot (P30 SESSION-28, `func_8016191C` ×137) <sub>L8153</sub>
- **§124a** — a family sweep's `0 matched-exemplar families` may be a FILTER, not a wall <sub>L8198</sub>
- **§134** — MULTI-LINE BLINDNESS: one root cause, four faces, in `family_remap`'s preamble scanner (P30 S6, 190 zero-crack families) <sub>L8711</sub>
- **§136c** — SIBLING-FIRST is a DERIVATION shortcut, not just a conflict fix (the fastest route in a family wave) <sub>L9066</sub>
- **§138** — The propagation lanes: a gate refusal is a DECLARATION, and which lever you owe depends on blast radius <sub>L9412</sub>
- **§142** — An open stub whose `h_exact` class is MATCHED elsewhere is FREE. Propagate the body; do not gate a draft. (P30 S39, +7,710 ins in two commands) <sub>L9775</sub>
- **§143** — `cast_call_sites` read a RETURN STATEMENT as a prototype and deleted it. A 0/39 sweep became 18/39. (P30 S40) <sub>L9831</sub>
- **Then** — propagation returned 0/137 TWICE — both times a missing TYPE <sub>L9997</sub>
- **§3-A.** — The frame has THREE strata, and stratum 3 is unreachable from C <sub>L10038</sub>
- **§3-E.** — A `qty_compare` TIE is not spelling-reachable — recognise it and stop <sub>L10080</sub>
- **Consequence** — for the family (a real scheduling decision) <sub>L10092</sub>
- **§150** — A register ROTATION across symmetric blocks is VARIABLE-IDENTITY evidence, not an allocator tie (P30 S43, `func_8017C6F4`, 947 ins ×4) <sub>L10309</sub>
- **§151** — THE GHOST WEDGE: when a load-before-store transposition is unreachable by ANY statement order (P30 S43, `func_8017EF68`, 969 ins) <sub>L10364</sub>
- **When** — to reach for it <sub>L10404</sub>
- **§152** — BYTE SIZE is the family key that name- and h_seq-grouping both miss (P30 S43, the 0xECC family: 1 crack → 12 overlays → 11,364 ins) <sub>L10415</sub>
- **§156** — an ORPHANED reconcile poisons the fleet: `dedup_propagate`'s kept edit (S45 p6/p7) <sub>L10637</sub>
- **§160** — THE REACH-15 WAVE HARVEST: an align-1 block move, and the instrument that called it a wall (P30 S47) <sub>L10890</sub>
- **§162** — S48 WAVE-1 HARVEST (P30, 2026-08-11): the reach-ordered sibling campaign's first 12 targets <sub>L11011</sub>
- **§163z** — THE UNVETTED REMAINDER (do not cite as law; each needs a dedupe pass) <sub>L11825</sub>
- **§3-The** — ADDRESS-CLASS TABLE: which load/store pairs even REACH the `/s` clause (P30 S48 wave 4, `func_80185B44`, ov_SC03_014) <sub>L14339</sub>
- **§168** — THE COUSIN TIER (P30 S49, 2026-08-12): h_seq's exact-hash brittleness, measured — and the similarity map above it <sub>L16208</sub>
### integration / TU plumbing (39)
- **§8c** — Splitting a TU means rebuilding its DECLARATION ENVIRONMENT, not moving text (Phase 26 session 6) <sub>L437</sub>
- **§8d** — Templating a body INTO a TU must not CHANGE its declaration environment — demote the carried data externs (Phase 26 session 8, byte-proven on `func_8015AE2C` ×133) <sub>L483</sub>
- **§9.3** — Make it the build: resegment + swap + resolve (`tools/psyq_integrate.py`, libcd DONE) <sub>L685</sub>
- **§9.4** — Integrating a SECOND library (libgs block 6 after libcd) — multi-library gotchas <sub>L712</sub>
- **§9.5** — Integrating a WHOLE multi-block library in one call (full libgs — Phase 7 session G) <sub>L740</sub>
- **§17a** — The TOOLKIT at WAVE scale (Phase-18 Step-3b/Step-1 — measured) + the pipeline-integration gotchas <sub>L1445</sub>
- **§3-THE** — CAP: at this tail the match_one→gate gap is the LOOSE-TYPING CALL-GRAPH wall (not cheap plumbing) <sub>L1637</sub>
- **Diagnostic** — lesson: a failed in-TU build leaves a STALE `.o` <sub>L1654</sub>
- **§28d** — The "macro-extern-injection" lever: freeing reach-134 inline matches dedup_propagate skips as "not self-contained" (Phase 23, `tools/inject_capped_externs.py`) <sub>L2366</sub>
- **§30a** — §30 generalizes to the FULL near-miss backlog (via STANDARD Opus agents, not just Fable5) + 2 more steer levers + the mechanical-integration throughput unlock (Phase 23 (a)) <sub>L2394</sub>
- **§40a** — The DECL-RECONCILE pass (type-lift so remapped drafts compile in the sibling TU) (Phase 25 T7.2, 2026-07-08) <sub>L2601</sub>
- **§42a** — addendum — wave 2 (residuals + 29-100 band): iso-MATCH ≠ real-TU bank, the memcpy→struct-assign fix, +5 levers (2026-07-10b) <sub>L2953</sub>
- **§42c** — addendum — wave 3 (Max orchestrator + CORRECTED Ultracode fan-out, 2026-07-10c): the real-TU-faithful parallel harness (rtu_match) + 7/9 crack, ZERO iso-drift <sub>L3033</sub>
- **§56** — Banking a hand-drafted GIANT into its exemplar TU: self-contained draft vs live-TU decls, 4 reconciliation tactics (`func_8013FAF8`, 312 ins ×138, Phase 29 T4, 2026-07-17) <sub>L4187</sub>
- **§61** — Task 14: the gate ladder's missing stage is the ARITY pre-pass, and it is TU-side not draft-side (Phase 29, 2026-07-21) <sub>L4545</sub>
- **§61a** — The Task-5 wave: 11/12 MATCH, 0 banked — three DISTINCT integration walls, each now named (Phase 29, 2026-07-21) <sub>L4606</sub>
- **§63** — The fresh-138 DEF-SIDE blocker: fix the HEADER decl, not the draft (`fix_header_decl.py`, Phase 29 SESSION-13, 2026-07-23) <sub>L4877</sub>
- **§63** — UPDATE (Phase 29 SESSION-14) — `fix_header_decl`'s "SAFE" verdict is FLEET-BLIND; it MUST be R22-validated <sub>L5000</sub>
- **§65** — The stranded-draft recovery: BLAST-RADIUS TIERS, and the per-overlay de-macroize that refutes §20's DEF-conflict wall (`tools/demacroize.py` + `tools/blocker_probe.py`, Phase 29 SESSION-16, 2026-07-24) <sub>L5015</sub>
- **§65b** — The escape: de-macroize the instantiation, don't touch the shared header <sub>L5045</sub>
- **§65f** — The de-macroize lever's BOUNDARY, measured: byte-neutral 14 times of 15, and the 15th is why the gate exists <sub>L5118</sub>
- **§65g** — Where the cheap levers STOP: the local-type and in-TU-self-decl classes did not yield <sub>L5139</sub>
- **§85** — The RETURN-axis fleet widen is ALL-OR-NOTHING: widening the shared header alone guarantees a conflict in the source overlay (Phase 29 SESSION-20, `func_8012CC88` / `func_8014D12C`) <sub>L6539</sub>
- **§95** — `reconcile_tu` dropped the SIBLING declarators of a multi-symbol `extern` line (Phase 29 SESSION-21, `func_80176218`) <sub>L6983</sub>
- **§96** — The same rewrite, one shape down: `reconcile_tu` matched statements to lines by TEXT, so every COMMENTED declaration was silently skipped (Phase 29 SESSION-22, `func_80176218` banked) <sub>L7018</sub>
- **§3-Two** — `reconcile_tu` bugs found underneath, one introduced while fixing the other <sub>L7190</sub>
- **§100** — Prefer the DRAFT-LOCAL fix: a type only one function uses belongs in its BODY, not in a shared header (Phase 29 SESSION-22, `func_80175DA8` 0/137 → 137/137) <sub>L7216</sub>
- **§102** — A PLUMBING verdict can MASK a DIFF; and K&R is not always a codegen change (Phase 29 SESSION-22, `func_8016EC0C`) <sub>L7272</sub>
- **§103** — A FILE-scope `extern` in a shared overlay TU is a GLOBAL constraint on every LATER function; move the DECL, not the draft (Phase 29 T48/T51, `func_80135260` — the fleet-wide half) <sub>L7307</sub>
- **§109** — Conforming a definition to a shared header: fix the NAMES, then check the RETURN precondition (Phase 29 T60) <sub>L7600</sub>
- **§112** — A macro-scoped declaration only collides where the macro is INSTANTIATED (Phase 29 T67/T69, `audit_header_sigs.py`) <sub>L7730</sub>
- **§114** — The THIRD decl axis: a CALLEE the draft declares differently from the target TU (Phase 29 T76/T77) <sub>L7808</sub>
- **§3-The** — integration idioms (these decide whether a byte-correct draft BANKS) <sub>L8804</sub>
- **§3-The** — declaration surface (integration, not codegen) <sub>L8938</sub>
- **Reconciling** — a gate-refused draft: which way you edit depends on WHERE the TU's decl is <sub>L9562</sub>
- **§3-The** — same swallow, twice more, in the integration spine <sub>L9706</sub>
- **§3-A.** — Payload word0 is a global MODULE ID; code starts after the header <sub>L10524</sub>
- **§162** — THE LICM PAIR: what makes an address a movable AT ALL, and why the preheader order is the body order (P30 S47, `ov_MAIN_012`) <sub>L11140</sub>
- **§166** — THE DESTINATION-TU ORACLE (P30 S48): the seven-attempt bug that was never codegen <sub>L14899</sub>
### build graph, splat & the harness (109)
- **§4** — Flag/toolchain gotchas <sub>L190</sub>
- **Build** — mechanism — per-file opt override (splat resegmentation) <sub>L288</sub>
- **§8c** — Splitting a TU means rebuilding its DECLARATION ENVIRONMENT, not moving text (Phase 26 session 6) <sub>L437</sub>
- **§9** — Link real PsyQ library objects byte-exact (Phase 7 — GO proven) <sub>L613</sub>
- **§9.1** — Generalised per-object linker — `tools/psyq_link.py` (+ `psyq_link_lib.py`), 18/18 libcd byte-exact <sub>L642</sub>
- **§9.2** — Wire a library region into the build with NOLOAD — no data carving (`tools/psyq_link_region.py`) <sub>L666</sub>
- **§9.3** — Make it the build: resegment + swap + resolve (`tools/psyq_integrate.py`, libcd DONE) <sub>L685</sub>
- **§9.6** — Scaling library linking to the whole EXE (Phase 8 — 8 libs linked, 20%→50% byte-identical) <sub>L766</sub>
- **§9.7** — Binary-agnostic toolchain refactor (Phase 9) — the reusable pattern for Gen2 <sub>L802</sub>
- **§3-The** — clean object-level metric (use this, not the permuter score, for jtbl/rodata functions) <sub>L844</sub>
- **§3-The** — mechanism: game-code dedup is SOURCE-LEVEL, not an object swap (R-D1, the key lesson) <sub>L926</sub>
- **Per-binary** — toolchain provenance (R24) <sub>L959</sub>
- **§12** — Ultracode harvest — parallel-draft + byte-gate at scale (Phase 12, resident: 1.4%→71.7% in one session) <sub>L964</sub>
- **One-command** — onboarding — `tools/new_overlay.sh <SCxx> <FILE_nnn>` <sub>L1062</sub>
- **§3-THE** — NON-4-ALIGNED-OVERLAY GOTCHA (≈75% of the fleet; fixed in the template + Makefile, automatic) <sub>L1079</sub>
- **Fleet** — build — `make build-all` / `make check-all` <sub>L1120</sub>
- **§14** — Propagate a matched function across the fleet — `tools/dedup_propagate.py` (Phase 15) <sub>L1126</sub>
- **§14b** — Harvesting the UNMATCHED shared core — the match_one wall (Phase 15) <sub>L1192</sub>
- **§14c** — Callee-signature-aware harvest — breaking the extern-type-conflict wall (Phase 15, T6) <sub>L1213</sub>
- **§17** — The compiler-quirk wall — the matching TOOLKIT (Phase 18; gcc-2.7.2 source + byte-gated) <sub>L1376</sub>
- **§3-The** — pipeline gotcha — match_one ≠ the gate; `sig_unify` is MANDATORY <sub>L1421</sub>
- **§17a** — The TOOLKIT at WAVE scale (Phase-18 Step-3b/Step-1 — measured) + the pipeline-integration gotchas <sub>L1445</sub>
- **§19** — Scaling the toolkit waves — the recovery PIPELINE + the propagation CAP (Phase 19 T3) <sub>L1597</sub>
- **§20** — The wave-at-scale GATE CAP + residual-class verdicts (Phase 20) <sub>L1632</sub>
- **§3-THE** — CAP: at this tail the match_one→gate gap is the LOOSE-TYPING CALL-GRAPH wall (not cheap plumbing) <sub>L1637</sub>
- **Diagnostic** — lesson: a failed in-TU build leaves a STALE `.o` <sub>L1654</sub>
- **Phase-20** — RESOLUTION — `tools/cast_call_sites.py` BUILT + the cap re-diagnosed (R14, byte-proven) <sub>L1701</sub>
- **§24** — The `ov_SC01_077_a.c` split-file vein: split-aware propagation, but loose-typing-gated (Phase 21) <sub>L2085</sub>
- **§25** — The "schedule" class is mostly COALESCING (pin-crackable), not scheduling; + the gate two-stage + h_exact over-counts ×134 (Phase 21, cont.6) <sub>L2132</sub>
- **§3-The** — gate two-stage — sig_unify is a FALLBACK, not unconditional (`gate_stage.py`, §19 folded in) <sub>L2189</sub>
- **§28** — Banking a "close=0 gate-rejected" giant: the canonical-extern recovery (Phase 22 T1, byte-proven on func_8015126C ×134) <sub>L2325</sub>
- **§28c** — The close=0 recovery is NOT fully exhausted (§26 corrected, R14); + the dedup_propagate registry-skip recovery (Phase 22 T2) <sub>L2352</sub>
- **§28d** — The "macro-extern-injection" lever: freeing reach-134 inline matches dedup_propagate skips as "not self-contained" (Phase 23, `tools/inject_capped_externs.py`) <sub>L2366</sub>
- **§29** — Reasoning-model (GLM5.2) DEF-side reconciliation idioms + the wall's hard limit (Phase 23 T10.7, `tools/glm_reconcile.py`) <sub>L2374</sub>
- **§33** — Automating the giant decl-reconcile: `tools/reconcile_decls.py` (the DATA analog of §20's `cast_call_sites`) + a fleet-majority type oracle (Phase 24 T7b, byte-proven on `func_80129CF8`) <sub>L2434</sub>
- **§34** — The `func_80138ED0` giant crack: gcc-2.7.2's **3-qty sort bug** + the **zero-byte asm allocation toolkit** + the **giv-init fence** (Phase 24 T5; Opus→close=21, Fable5→MATCH ×134) <sub>L2454</sub>
- **§35** — The region-a sibling-giant harvest: difficulty ≠ $s-reg count (it's global-array hoisting) + the banking recipe + new loop idioms (Phase 24 T7, 5 parallel Opus-Max agents) <sub>L2471</sub>
- **§37** — The T7 §G giant endgame: 6/8 cracked, meta-laws + transferable levers (Phase 24, 2026-07-07; FULL byte-verified detail + gcc-2.7.2 line cites in `docs/gcc-2.7.2-map/t7g-giant-harvest.md`) <sub>L2506</sub>
- **§39** — The ×1→×134 giant-endgame: propagate a matched **-O2** giant via the NATIVE DEFINE-macro path (Phase 24 T7 §G close, 2026-07-08) <sub>L2537</sub>
- **§41** — The DEF-SIDE canonical-sig wall: mechanically banking a drafted giant past `conflicting types` (Phase 25 T5b batch-2, 2026-07-09; `tools/canon_sig_reconcile.py`, byte-proven on `func_8013B274`) <sub>L2710</sub>
- **§41a** — v3.1: the def-side wall was ~71% TOOL-shaped — the five measured defects + the laws that dissolve them (Phase 25 T6, Fable5, 2026-07-09) <sub>L2754</sub>
- **§41b** — T7 execution: the object-only probe OVER-counts BANKABLE by two link/rodata classes (Phase 25 T7-M1, 2026-07-10) <sub>L2809</sub>
- **§41d** — `void`→`s32` is NOT always byte-neutral: gate the RAW draft FIRST (Phase 26 session 6, byte-proven) <sub>L2878</sub>
- **§42b** — addendum — wave 3 (Max, 2026-07-10c): THE STALE-OBJECT GATE TRAP + the read-global `&`-cast drift + fix <sub>L2994</sub>
- **§45** — The flagship `func_80133CD4` crack (399 ins ×134): the merged-variable permutation-breaker + the 1-death local-alloc gate (Phase 25 task A giant escalation, Fable5 gdb-on-cc1, 2026-07-11) <sub>L3298</sub>
- **§51** — TOOLING INTEGRITY: the silent skip, and how to hunt it <sub>L3630</sub>
- **§51b** — Why the byte-gate cannot save you <sub>L3652</sub>
- **§51f** — Checklist for any new corpus-scanning tool <sub>L3755</sub>
- **§51g** — When the thing you are scanning has a GRAMMAR, parse the grammar (`tools/cdecl.py`) <sub>L3769</sub>
- **§53** — SWEEP A FAMILY WITH THE TOOL ITS EXEMPLAR NEEDED: the jr/switch carve, and how omitting it manufactured the "families don't template" doctrine (Phase 28 T1, 2026-07-15) <sub>L4028</sub>
- **§55** — Core-crack wave levers + the GATE-ORCHESTRATION law (Phase 29 T3, 13-agent ultracode wave, 2026-07-17) <sub>L4093</sub>
- **§55b** — THE GATE-ORCHESTRATION LAW (3 traps, ~3.5h lost; all recovered, 0 data lost) <sub>L4122</sub>
- **§55c** — Sizing the propagate: a TARGETED propagate is ~4 min/core, and "it's slow" was a BROKEN-TREE ARTIFACT <sub>L4141</sub>
- **§54** — `--fix-def-sig`: the member's CANONICAL DECLARATION is a build step too (tiny-IMM mega-pools, +4,801, Phase 29 T6, 2026-07-16) <sub>L4163</sub>
- **§57** — The SELF-decl normalize: the sibling's OWN caller declares the templated fn divergently (the third §17a-1 direction; `tools/normalize_self_decls.py`, func_801670E4 ×137, Phase 29, 2026-07-18) <sub>L4256</sub>
- **§61** — Task 14: the gate ladder's missing stage is the ARITY pre-pass, and it is TU-side not draft-side (Phase 29, 2026-07-21) <sub>L4545</sub>
- **§61b** — The jtbl gate stage: built, and the ORDERING law it exposed (Phase 29 Task-14 stage 4, 2026-07-21) <sub>L4658</sub>
- **§61d** — The undo was eating the tree: two tools, one defect, invisible to the byte-gate (Phase 29, 2026-07-22) <sub>L4779</sub>
- **§62** — The jtbl RECONCILE must also follow the carve: the post-carve draft reconcile (`harvest_verify._jtbl_reconcile`, Phase 29 SESSION-11, 2026-07-22) <sub>L4833</sub>
- **§65** — The stranded-draft recovery: BLAST-RADIUS TIERS, and the per-overlay de-macroize that refutes §20's DEF-conflict wall (`tools/demacroize.py` + `tools/blocker_probe.py`, Phase 29 SESSION-16, 2026-07-24) <sub>L5015</sub>
- **§65d** — Existing-ladder baseline, measured (do this before building a recovery stage) <sub>L5091</sub>
- **§65e** — Two oracles, and the disagreement is the finding (R34 in practice) <sub>L5101</sub>
- **§65f** — The de-macroize lever's BOUNDARY, measured: byte-neutral 14 times of 15, and the 15th is why the gate exists <sub>L5118</sub>
- **§66b** — A metric parsed out of another tool's prose goes NULL silently when the label changes <sub>L5200</sub>
- **§67a** — Run the symbol-set guard BEFORE you pay for a gate (`tools/symcheck.py`, Phase 29 SESSION-18) <sub>L5405</sub>
- **§77** — Every extraction tool carries a NARROW hard-coded preamble set; anything outside it silently caps the body's reach. Diff the preamble before you gate. (Phase 29 SESSION-19 — three variants in one session, two different tools) <sub>L6084</sub>
- **§3-The** — CANDIDATE gate and the REAL gate need DIFFERENT preambles — keep the difference out of the bank <sub>L6124</sub>
- **§79** — For a 0-callee giant, fingerprint by DATA symbols (§71 cannot fire); and the STACK-SLOT ORDER is a declaration-order oracle (Phase 29 SESSION-19, `func_8017BF14` 4,763 ins, cold start → 45/4763) <sub>L6220</sub>
- **§82** — Two source-shape oracles from behemoth #6: a duplicated `addiu $aN,$sp,K` across a `jal` means the block was INLINED, and scalar-vs-aggregate decides WHEN a stack slot is allocated (Phase 29 SESSION-19, `func_8017C730` 1,061 ins) <sub>L6370</sub>
- **§3-2.** — Scalar vs aggregate decides *when* the slot is allocated <sub>L6389</sub>
- **§3-Why** — it survived every candidate gate <sub>L6495</sub>
- **§3-THE** — FIX IS MECHANICAL — the tool already holds the answer <sub>L6510</sub>
- **§87** — `match_one` COMPILES but never LINKS, so an unresolvable data symbol reads as MATCH; and stored drafts go STALE against the tree (Phase 29 SESSION-20) <sub>L6633</sub>
- **§88f** — the missing rung: a RELOCATION gate between `match_one` and the binary <sub>L6718</sub>
- **§89a** — MEASURE the write set; do not assert its tier (`tools/blast_radius.py`) <sub>L6732</sub>
- **§89b** — the parallel gate farm existed; the family path could not reach it (`tools/sweep_parallel.py`) <sub>L6745</sub>
- **§90** — Five tool-integrity laws from one session, each of which changed an answer (Phase 29 SESSION-21, 2026-07-27) <sub>L6766</sub>
- **§90a** — A comparison tool MUST share its reference oracle's index space, exactly <sub>L6772</sub>
- **§92** — Conforming a DECLARATION: pointer changes are caller-neutral, scalar-WIDTH changes are not (Phase 29 SESSION-21, `tools/conform_decls.py`) <sub>L6891</sub>
- **§97** — The gate's own tree hygiene: a refused carve, an unchecked recovery, and a snapshot that captured a dirty tree (Phase 29 SESSION-22) <sub>L7066</sub>
- **§105** — A gate's revert must survive an EXCEPTION, not just a failure (Phase 29 T53, `jtbl_family_bank`) <sub>L7431</sub>
- **§107** — A lever wired into ONE gate path is a lever most families cannot reach (Phase 29 T56, `func_80144090` 0/136 → 136/136) <sub>L7513</sub>
- **§3-Why** — it survived so long: a MASKED oracle will MATCH a wrong symbol <sub>L7953</sub>
- **§122** — GATE RAW BEFORE TRANSFORMING; the undo belongs to the WRITER, as a per-edit journal (P30 T0a, 2026-07-30) <sub>L8084</sub>
- **§123** — PROPAGATE A FAMILY WITH THE TOOL ITS TIER NEEDS: `dedup_propagate` is h_exact-only; its refusals are statements about the TOOL (P30 wave 1, 2026-07-30) <sub>L8116</sub>
- **§126a** — a bare `except: continue` around a coverage-asserting oracle re-creates the silent skip (P30 S28) <sub>L8317</sub>
- **§130** — An INCREMENTAL build can report BYTE-IDENTICAL for a change the CLEAN build cannot even LINK (P30 S28, the jr pair) <sub>L8486</sub>
- **§132** — The `JR-PAIR-IN-ONE-O0-OBJECT` "wall" was TWO instrument defects: a merged-double span the carve could not see, and a truncated object no rule deleted (P30 S29, `func_8013B83C` + `func_8013BD74`) <sub>L8570</sub>
- **§133** — The DEFAULT-FILTER class: three times in one session, a tool silently answered a narrower question than the one asked (P30 S1–S3) <sub>L8685</sub>
- **§134** — MULTI-LINE BLINDNESS: one root cause, four faces, in `family_remap`'s preamble scanner (P30 S6, 190 zero-crack families) <sub>L8711</sub>
- **§3-The** — splitting/merging rules (each closed a residual, byte-gated) <sub>L8853</sub>
- **§137a** — A gate verdict has a TIMESTAMP; re-check it against the draft's mtime <sub>L9383</sub>
- **§138** — The propagation lanes: a gate refusal is a DECLARATION, and which lever you owe depends on blast radius <sub>L9412</sub>
- **§134** — again, in a second tool — and the waiter rule corrected <sub>L9523</sub>
- **Reconciling** — a gate-refused draft: which way you edit depends on WHERE the TU's decl is <sub>L9562</sub>
- **§139** — A GATE THAT GREPS FOR VERDICTS MUST ASSERT 1:1 ACCOUNTING; and a `--src` filter must not survive a carve (P30 S38, wave 6: 10 of 16 drafts vanished) <sub>L9591</sub>
- **§140** — A METRIC IS NOT A MEASUREMENT UNTIL IT IS REPRODUCIBLE FROM THE COMMITTED TREE (P30 S1e: a phantom regression that gated the session's best lever) <sub>L9657</sub>
- **§142** — An open stub whose `h_exact` class is MATCHED elsewhere is FREE. Propagate the body; do not gate a draft. (P30 S39, +7,710 ins in two commands) <sub>L9775</sub>
- **§3-The** — measurement (do this before any wave; it is ~20 lines and needs no builds) <sub>L9787</sub>
- **§155b** — check the TYPE your oracle returns before comparing against it (S45 p5) <sub>L10584</sub>
- **§156** — an ORPHANED reconcile poisons the fleet: `dedup_propagate`'s kept edit (S45 p6/p7) <sub>L10637</sub>
- **§158** — The RANGE-EXTENDER: a fourth zero-emission asm lever completes the allocno toolkit (P30 S46 tier-3, `func_8017CE58`, 733 ins) <sub>L10709</sub>
- **§160** — THE REACH-15 WAVE HARVEST: an align-1 block move, and the instrument that called it a wall (P30 S47) <sub>L10890</sub>
- **§161** — THE RETRY-WAVE HARVEST: a jump table indexed from zero, and two allocator traps (P30 S47) <sub>L10966</sub>
- **§162** — S48 WAVE-1 HARVEST (P30, 2026-08-11): the reach-ordered sibling campaign's first 12 targets <sub>L11011</sub>
- **§163** — S48 WAVES 2-3 HARVEST (P30, 2026-08-11/12): the five that were byte-probed and are actionable <sub>L11757</sub>
- **§165** — S48 WAVE-4 HARVEST (P30, 2026-08-12): banked the same day the wave landed <sub>L13686</sub>
- **§166** — THE DESTINATION-TU ORACLE (P30 S48): the seven-attempt bug that was never codegen <sub>L14899</sub>
- **§167** — S48 WAVE-5/6 HARVEST (P30, 2026-08-12): the saturation point <sub>L14955</sub>
### process, measurement & doctrine (73)
- **§8e** — The jtbl ALIGNMENT LAW + the pad-spec filter — multi-table .rodata spans (Phase 29, byte-proven; `.run/probe_jtbl/verdict.md`) <sub>L530</sub>
- **§3-The** — mechanism: game-code dedup is SOURCE-LEVEL, not an object swap (R-D1, the key lesson) <sub>L926</sub>
- **Per-binary** — toolchain provenance (R24) <sub>L959</sub>
- **§17a** — The TOOLKIT at WAVE scale (Phase-18 Step-3b/Step-1 — measured) + the pipeline-integration gotchas <sub>L1445</sub>
- **Diagnostic** — lesson: a failed in-TU build leaves a STALE `.o` <sub>L1654</sub>
- **Phase-20** — RESOLUTION — `tools/cast_call_sites.py` BUILT + the cap re-diagnosed (R14, byte-proven) <sub>L1701</sub>
- **§23** — Giant `func_80153E00` cracked (scalar-data CAST); BUT most giant drafts are STALE+INCOMPLETE, and a diag MUST remove artifacts (Phase 21 — byte-proven + a self-correction) <sub>L2032</sub>
- **§3-h** — _exact OVER-COUNTS ×134 — verify shareability before crediting a class's "reach-134" (R14) <sub>L2177</sub>
- **§28c** — The close=0 recovery is NOT fully exhausted (§26 corrected, R14); + the dedup_propagate registry-skip recovery (Phase 22 T2) <sub>L2352</sub>
- **§31-triage** — R17 applies to CODEGEN residuals, never to a compile ERROR (Phase 26 session 7, Drew asked) <sub>L2693</sub>
- **§41a** — v3.1: the def-side wall was ~71% TOOL-shaped — the five measured defects + the laws that dissolve them (Phase 25 T6, Fable5, 2026-07-09) <sub>L2754</sub>
- **§41b** — T7 execution: the object-only probe OVER-counts BANKABLE by two link/rodata classes (Phase 25 T7-M1, 2026-07-10) <sub>L2809</sub>
- **§41b** — addendum — M4 "reconcile_decls" tier is ALSO a probe over-count: 0/8 mechanical (Phase 25 T7-M4, 2026-07-10) <sub>L2858</sub>
- **§53** — SWEEP A FAMILY WITH THE TOOL ITS EXEMPLAR NEEDED: the jr/switch carve, and how omitting it manufactured the "families don't template" doctrine (Phase 28 T1, 2026-07-15) <sub>L4028</sub>
- **§3-The** — meta-lesson (R35, and why this one is expensive) <sub>L4078</sub>
- **§55** — Core-crack wave levers + the GATE-ORCHESTRATION law (Phase 29 T3, 13-agent ultracode wave, 2026-07-17) <sub>L4093</sub>
- **§55b** — THE GATE-ORCHESTRATION LAW (3 traps, ~3.5h lost; all recovered, 0 data lost) <sub>L4122</sub>
- **§57a** — Two NSD corrections + the SURGICAL-ONLY law + the honest broad-sweep yield (Phase 29, 2026-07-18) <sub>L4303</sub>
- **§58** — match_one MATCH ≠ BANK: the four blind spots + the crack-wave reconcile-before-bank law (Phase 29 crack-wave, 2026-07-18) <sub>L4343</sub>
- **§60** — Classify the residual, don't rank it: the deterministic residual→class classifier and what it measured about the backlog (Phase 29 Task-13A, 2026-07-21) <sub>L4407</sub>
- **What** — it measured — the whole open backlog, byte-grounded <sub>L4431</sub>
- **§3-The** — parallel-probe race this surfaced <sub>L4463</sub>
- **§61b** — The jtbl gate stage: built, and the ORDERING law it exposed (Phase 29 Task-14 stage 4, 2026-07-21) <sub>L4658</sub>
- **§62** — The jtbl RECONCILE must also follow the carve: the post-carve draft reconcile (`harvest_verify._jtbl_reconcile`, Phase 29 SESSION-11, 2026-07-22) <sub>L4833</sub>
- **§63** — UPDATE (Phase 29 SESSION-14) — `fix_header_decl`'s "SAFE" verdict is FLEET-BLIND; it MUST be R22-validated <sub>L5000</sub>
- **§65** — The stranded-draft recovery: BLAST-RADIUS TIERS, and the per-overlay de-macroize that refutes §20's DEF-conflict wall (`tools/demacroize.py` + `tools/blocker_probe.py`, Phase 29 SESSION-16, 2026-07-24) <sub>L5015</sub>
- **§65a** — The blast-radius taxonomy (makes §61's law structural instead of remembered) <sub>L5030</sub>
- **§65d** — Existing-ladder baseline, measured (do this before building a recovery stage) <sub>L5091</sub>
- **§65e** — Two oracles, and the disagreement is the finding (R34 in practice) <sub>L5101</sub>
- **§65f** — The de-macroize lever's BOUNDARY, measured: byte-neutral 14 times of 15, and the 15th is why the gate exists <sub>L5118</sub>
- **§66c** — Before a wave, verify the FUEL exists; an "already attempted" set built from the wrong directory lies in BOTH directions <sub>L5217</sub>
- **§66d-5** — `residual_class`'s "structural ⇒ permuter CPU is waste" is WRONG for schedule permutations (measured, Phase 29 SESSION-18) <sub>L5491</sub>
- **§3-The** — honest fix was source-level and cheap <sub>L5750</sub>
- **§3-The** — residual, and the honest read <sub>L6260</sub>
- **§83** — The parameterised-repeat law, the spill-area trap, and why a per-case edit cannot move a per-case symptom (Phase 29 SESSION-20, `func_80183814` 5,122 ins, cold-ish start → 36 structural / 99.3%) <sub>L6412</sub>
- **Scope** — , measured (do not over-generalise — §80) <sub>L6518</sub>
- **§3-Two** — ladder lessons banked with it <sub>L6528</sub>
- **§3-Do** — the WHOLE axis in one edit, then R22 once <sub>L6567</sub>
- **§3-THE** — LAW: all-or-nothing PER FAMILY <sub>L6600</sub>
- **§88b** — the `slti` literal-position law (extends §78 to comparisons) <sub>L6686</sub>
- **§88e** — a wrong diagnosis, refuted properly (the model for how to treat an inherited lever) <sub>L6708</sub>
- **§89a** — MEASURE the write set; do not assert its tier (`tools/blast_radius.py`) <sub>L6732</sub>
- **§90d** — Do not measure a live wave's drafts (§87 in real time) <sub>L6810</sub>
- **§98** — `conform_decls` had three defects, and only the third needed R22 to find (Phase 29 SESSION-22, `func_8014CF04`) <sub>L7113</sub>
- **§106** — Persist the MEASUREMENT, derive the POLICY: a stored route let a stale file out-vote the live table (Phase 29 T54, `residual_class._ROUTE`) <sub>L7470</sub>
- **§125** — Split the CARVE from the BODY before calling a jr residue a wall — and measure it by SHA from a CLEAN tree (P30 SESSION-28; **this section's first draft was WRONG and the method caught it**) <sub>L8206</sub>
- **§3-The** — meta-lesson <sub>L8257</sub>
- **Wave** — economics (measured, for the next batch's sizing) <sub>L8950</sub>
- **§136b** — A prior wave's "genuine byte-DIFF" verdict is NOT reliable evidence (4 of 4 refuted) <sub>L9030</sub>
- **§136g** — When the index points at the WRONG lever: two byte-refuted routings (func_801863B4) <sub>L9208</sub>
- **§136h** — CORRECTION: the zero-crack pool does NOT "refill with cheap work" (my error, byte-measured) <sub>L9237</sub>
- **§136j** — The failure MIX flips with function size (measured across four bands, one session) <sub>L9299</sub>
- **Rank** — the lane by measured concentration, not by class count <sub>L9478</sub>
- **§140** — A METRIC IS NOT A MEASUREMENT UNTIL IT IS REPRODUCIBLE FROM THE COMMITTED TREE (P30 S1e: a phantom regression that gated the session's best lever) <sub>L9657</sub>
- **§3-The** — measurement (do this before any wave; it is ~20 lines and needs no builds) <sub>L9787</sub>
- **§3-And** — the report-vs-bytes lesson attached to it <sub>L9819</sub>
- **§146** — RE-MEASURE A WALL BEFORE YOU RESPECT IT. Both "permanent" giants fell to drafts already on disk. (P30 S6, +50,094 ins) <sub>L9974</sub>
- **§147** — The three-stratum FRAME LAW, and four "stop searching" verdicts (P30 S42, `func_8017C294`, serial run) <sub>L10033</sub>
- **§3-C.** — Inner-block declaration does NOT delay slot allocation — BYTE-REFUTED <sub>L10065</sub>
- **§3-D.** — "Cheap fuel" that was never probed: 0 of 31 templatable <sub>L10290</sub>
- **§3-Two** — corrections to the record <sub>L10342</sub>
- **§3-The** — two fallouts, and how to close them (both measured, in order) <sub>L10392</sub>
- **What** — does NOT work (14 byte-measured probes) <sub>L10483</sub>
- **§157** — the cheap-tier size cliff, measured (S45 p6) <sub>L10684</sub>
- **§162** — The cross-jump "CALL veto" is a COUNT law, not a CALL law (BOUNDS §88a; P30 S48, `func_80189540`) <sub>L11299</sub>
- **§3-The** — law <sub>L11546</sub>
- **DIAGNOSTIC** — TELL — two faces, one law <sub>L11588</sub>
- **§163** — S48 WAVES 2-3 HARVEST (P30, 2026-08-11/12): the five that were byte-probed and are actionable <sub>L11757</sub>
- **§163z** — THE UNVETTED REMAINDER (do not cite as law; each needs a dedupe pass) <sub>L11825</sub>
- **§164z** — REFUTED CLAIMS: do NOT re-derive these <sub>L13620</sub>
- **§165z** — REFUTED THIS WAVE: do NOT re-derive <sub>L14855</sub>
- **§167z** — REFUTED IN WAVES 5/6: do NOT re-derive <sub>L16151</sub>
- **§168** — THE COUSIN TIER (P30 S49, 2026-08-12): h_seq's exact-hash brittleness, measured — and the similarity map above it <sub>L16208</sub>
### (unbucketed — title matched no symptom vocabulary) (169)
- **§3-How** — to use this <sub>L30</sub>
- **§1** — Idiom catalog (asm pattern → C that produces it) <sub>L39</sub>
- **§3-I3** — Division by a constant → magic multiply <sub>L54</sub>
- **§3-I4** — Runtime (variable) division → `divu` + zero-check `break` (NEEDS `--expand-div`) <sub>L60</sub>
- **§2** — Writing matching C (what makes gcc emit X) <sub>L69</sub>
- **§3a** — Escalation TIER above the permuter — web-research the compiler internals (HIGH VALUE, proven) <sub>L128</sub>
- **§3b** — §31-directed permuter mutation — bias the search over the class's levers (Phase 24 T5) <sub>L147</sub>
- **Residual** — B — a `return <const>` materialised late / merged instead of distributed per-site <sub>L867</sub>
- **§3-The** — A→B→C per-overlay workflow <sub>L1091</sub>
- **Dedup-credit** — (§11) for overlays — two shapes <sub>L1108</sub>
- **§14a** — The fleet bulk run (Phase 15 — `--auto-from`, 947 REAL → 74,527; 3.82% → 22.14% in one pass) <sub>L1169</sub>
- **§14d** — Deterministic recovery beats agent waves on the hard tail (Phase 15, the final-session finding) <sub>L1269</sub>
- **§14e** — Two hard-tail dead-ends (Phase 15 — documented so they aren't re-attempted) <sub>L1298</sub>
- **§3-The** — STEERABLE idioms (byte-confirmed this phase) <sub>L1404</sub>
- **Strategic** — conclusion — the match-% lever post-research <sub>L1435</sub>
- **§3-NEW** — / CONFIRMED residual classes (this session) <sub>L1660</sub>
- **Operational** — gotchas (cost real time) <sub>L1681</sub>
- **What** — WORKED — the Phase-20 reusable wins <sub>L1689</sub>
- **§21** — wave-distilled idioms (Phase 21) <sub>L1752</sub>
- **§26** — The cheap close=0 recovery lever is EXHAUSTED; `idiom_loop --assess` was DOUBLY inflated (Phase 21, cont.7) <sub>L2199</sub>
- **§3-The** — `_a` close=0 recovery banks 0/20 — same def-side wall as MAIN (0/40) <sub>L2205</sub>
- **§27** — Giant matching recipe (Phase 21 cont.7b — validated on func_80176D94, 152 ins) <sub>L2259</sub>
- **§28a** — decomp.wiki GCC patterns worth trying on BFM giants (decomp.wiki/compilers/GCC, raw at decompals/decompedia; PS1-applicable subset) <sub>L2345</sub>
- **§31** — THE gcc-2.7.2 CODEGEN MAP: pass → residual → C-lever catalog (Phase 23; 4 Fable5 agents read the compiler source) <sub>L2402</sub>
- **§36** — Fable5 giant-crack levers (Phase 24 T7 Fable5 batch; accumulates as each lands — full RTL dumps in `.run/t7/fable/`) <sub>L2487</sub>
- **§42d** — addendum — wave 4 (rtu_match fan-out over the mapped frontier, 2026-07-10c): 24/26 MATCH, +5 durable levers <sub>L3082</sub>
- **§3-B.** — THE EBB RULE — the general form of §46-L2 <sub>L3468</sub>
- **§3-E.** — Meta <sub>L3518</sub>
- **§50** — Refinements that BOUND §47/§48 (from the `func_80135EB0` wall, 21→6; Phase 26 session 8) <sub>L3576</sub>
- **§51a** — The bug class <sub>L3636</sub>
- **§51c** — THE METHOD (do not audit by reading the regex) <sub>L3662</sub>
- **§51d** — THE LAWS <sub>L3677</sub>
- **§51e** — The false-wall pipeline (why this is not just hygiene) <sub>L3739</sub>
- **§3-Why** — the wall is (probably) intrinsic <sub>L3945</sub>
- **§3-The** — case <sub>L4033</sub>
- **§3-The** — rule <sub>L4062</sub>
- **§55a** — New byte-proven levers (each from a banked or near draft) <sub>L4098</sub>
- **§60a** — What the first DIRECTED grinder run exposed (Phase 29 Task-13B, 2026-07-21) <sub>L4472</sub>
- **§60b** — The plateau autopsy's verdict: a `partial` drift is a WRONG DRAFT, not a missing transform (Phase 29 Task-13B close, 2026-07-21) <sub>L4510</sub>
- **§66** — Exercise a banking driver's SUCCESS path before pointing it at a wave: the free re-bank test (Phase 29 SESSION-17, 2026-07-24) <sub>L5159</sub>
- **§66d-2** — Two operational sharp edges <sub>L5289</sub>
- **§66d-3** — Read the ILS per-cycle SERIES, not its final best: a repeated score and a still-falling one look identical in a summary line and mean opposite things <sub>L5300</sub>
- **§67** — The arg-copy PLACEMENT lever: launder a parameter into a fresh pseudo AT the statement where the target's copy lands (Phase 29 SESSION-18, `func_8014D820` 25 → 16) <sub>L5315</sub>
- **§66d-4** — "ILS converged" means converged FOR THAT WEIGHT PROFILE, not a floor (amends §66d-3; Phase 29 SESSION-18) <sub>L5438</sub>
- **§69** — How to attack a behemoth: map it, don't draft it (Phase 29 SESSION-18, `func_80183814`, 5,122 ins) <sub>L5569</sub>
- **What** — is left, and what is byte-recorded as SPENT <sub>L5766</sub>
- **§3-The** — mechanism, with citations <sub>L6037</sub>
- **§3-Two** — diagnosis traps this function proved <sub>L6064</sub>
- **Practice** — Practice <sub>L6074</sub>
- **§3-The** — drift was an allocation decision, not missing code <sub>L6180</sub>
- **§3-The** — economics <sub>L6211</sub>
- **§71** — has a blind spot, and this is it <sub>L6226</sub>
- **§3-The** — flagged "#1 move" LOST — and why the failure is informative <sub>L6302</sub>
- **§78** — 's attribution primitive, run and reproduced <sub>L6312</sub>
- **Cold-start** — economics, now complete <sub>L6318</sub>
- **Also** — reproduced on this function <sub>L6401</sub>
- **§3-And** — the banking footnote (§75a class A, one line) <sub>L6405</sub>
- **§83a** — READ THE HEADLINE NUMBER CORRECTLY: a LENGTH drift makes `match_one`'s count meaningless <sub>L6419</sub>
- **§83b** — THE LEVER: find the parameterised REPEAT before decoding case-by-case <sub>L6427</sub>
- **§83e** — §80 vindicated again, on the same day it was written <sub>L6466</sub>
- **§3-The** — conflict <sub>L6544</sub>
- **§3-THE** — FAILURE MODE — widening only `engine_core.h` is worse than not starting <sub>L6552</sub>
- **§3-The** — precondition, and how to check it in one grep <sub>L6559</sub>
- **Reading** — , for the next person <sub>L6576</sub>
- **§3-The** — guard refuses a class that largely works <sub>L6591</sub>
- **§3-The** — blindness ladder, now complete — FOUR classes `match_one` cannot see <sub>L6649</sub>
- **Consequence** — for the backlog ledger <sub>L6659</sub>
- **§88** — `cross_jump` will not merge a common suffix containing a CALL; and §78 is scoped to ORDERED comparisons only (Phase 29 SESSION-20, the behemoth close-out) <sub>L6674</sub>
- **§88a** — repeated CALL-shaped blocks are left UNMERGED; call-free tails are merged for you <sub>L6679</sub>
- **§89** — Two throughput rules the project already had written down and was not following (Phase 29 SESSION-20) <sub>L6726</sub>
- **§3-The** — standing sequence <sub>L6758</sub>
- **§90b** — "Byte-neutral" is not "wanted": undo on the SUCCESS path too <sub>L6789</sub>
- **§90c** — A library-callable function must FAIL CLOSED on an unconfigured module <sub>L6799</sub>
- **§90e** — An agent's CONCLUSION and its EVIDENCE fail independently — re-derive the premise, not the fix <sub>L6818</sub>
- **§93** — `set -o pipefail` attributes a pipeline failure to the LAST stage, not the failing one (Phase 29 SESSION-21, `func_8014D820`) <sub>L6922</sub>
- **§101** — The STALE DEFAULT class: a guard whose cause was removed is a silent skip wearing a safety label (Phase 29 SESSION-22, three instances in one session) <sub>L7245</sub>
- **§110** — A unit must define exactly ONE function, and "ends in `;`" does not tell you which line defines it (Phase 29 T65) <sub>L7640</sub>
- **§115** — A `func_XXXXXXXX` predicate rots by design: the same name-form assumption in THREE places (Phase 29 T78) <sub>L7850</sub>
- **§3-The** — fix moves the DEFINITION, not the stub — and here is why the obvious shortcut fails <sub>L7895</sub>
- **§117** — Spell the sibling's symbol from the SIBLING's address, not the exemplar's kind (Phase 29 T82) <sub>L7926</sub>
- **§118** — Ordinal (positional) immediate resolution: compare C tokens to the DIFFERING asm uses (Phase 29 T87) <sub>L7963</sub>
- **§119** — Two levers on the SAME axis, opposite directions: test the off-diagonal (Phase 29 T89) <sub>L7997</sub>
- **§3-The** — wiring trap that cost two attempts <sub>L8043</sub>
- **§3-The** — method (keep this) <sub>L8213</sub>
- **§3-The** — instrument rules that make its answer trustworthy (this is where I failed) <sub>L8223</sub>
- **§3-The** — corrected results (each SHA-verified, from a clean tree, restore re-verified) <sub>L8238</sub>
- **§3-The** — instrument trap that hid it (and it is §124's shape again) <sub>L8290</sub>
- **§3-The** — mechanics <sub>L8299</sub>
- **§3-The** — idiom they kept re-deriving: the constant-offset fold <sub>L8356</sub>
- **§127b** — the knowledge was in a SOURCE COMMENT, not the cookbook <sub>L8386</sub>
- **§128** — A raw NUL in C source makes grep SILENTLY SKIP the file (P30 S28, 137 files) <sub>L8393</sub>
- **§128a** — a negative control must corrupt a SCRATCH COPY, never the tracked file <sub>L8425</sub>
- **§3-The** — real blocker underneath, for the record <sub>L8477</sub>
- **§3-The** — diagnostic ladder that finally located it (reusable) <sub>L8523</sub>
- **Defect** — 1 — a pre-§8e MERGED DOUBLE is not a single-table predecessor <sub>L8579</sub>
- **Defect** — 2 — `as` writes a corpse and nothing deletes it <sub>L8597</sub>
- **§3-The** — fingerprint, and the 30-second ladder that found it <sub>L8607</sub>
- **§3-The** — transferable rule <sub>L8628</sub>
- **§132a** — `--like` is for a sibling with NO record; against one that HAS a record it over-derives (P30 S29, `ov_SC07_010`) <sub>L8635</sub>
- **§135** — Six byte-verified gcc-2.7.2 idioms from the P30 S6f-h waves (and the two-lane wave shape that found them) <sub>L8765</sub>
- **§3-The** — codegen idioms <sub>L8770</sub>
- **§3-The** — wave shape that produced these <sub>L8819</sub>
- **§136** — The LOCAL-VARIABLE lever: how many C locals, at what scope (P30 wave 4a, 25 byte-verified banks) <sub>L8837</sub>
- **§136a** — Blocker capture: classify on the OUTPUT, never on the exit status <sub>L8973</sub>
- **§136d** — Four gcc-2.7.2 levers the redraft lane found (each closed a residual no other lever moved) <sub>L9091</sub>
- **§136e** — §136c's PRECONDITION, and two more symptom keys (wave 4b batch 3) <sub>L9135</sub>
- **§136i** — The drafter model LADDER: Haiku → **Sonnet** → Opus → Fable5 (Drew, 2026-08-03) <sub>L9267</sub>
- **§3-The** — triage, cheapest first <sub>L9418</sub>
- **THREE** — carry variants hide in one "CARRY-FIXABLE" bucket — and they need different fixes <sub>L9487</sub>
- **STEP** — 0 of sibling-first: grep `src/` for a distinctive LITERAL from the `.s` <sub>L9543</sub>
- **§3-The** — generalisation — three corollaries worth more than the bug <sub>L9623</sub>
- **§3-And** — the inverse-lookup trap, same session <sub>L9640</sub>
- **§3-The** — three-line proof (do this before diagnosing any metric movement) <sub>L9677</sub>
- **§3-The** — two instrument defects it exposed <sub>L9686</sub>
- **§3-Two** — wrong mechanisms I chased first, and why they were wrong <sub>L9717</sub>
- **§3-The** — trap that hid it — SAME FUNCTION, TWO ROUTES, ONLY ONE IS FREE <sub>L9802</sub>
- **Route** — selection (why `--addr` sometimes says "nothing changed") <sub>L9811</sub>
- **§144** — THE LITERAL'S SPELLING PICKS THE IMMEDIATE ENCODING (P30 S40 wave 1, `func_801822E0`) <sub>L9885</sub>
- **§3-Why** — a correct draft can read as an intrinsic wall <sub>L9985</sub>
- **§3-The** — rule <sub>L10020</sub>
- **§3-B.** — `(v < 0x40) ? v : 0x3F` is folded to `MIN_EXPR` and expands to the WRONG SHAPE <sub>L10167</sub>
- **§3-D.** — Reproduce the original's BUGS verbatim <sub>L10191</sub>
- **§149** — Four instrument defects in one session, and the two questions they were hiding (P30 S43) <sub>L10240</sub>
- **§3-A.** — A prep step that returns its input on failure is indistinguishable from a search that found nothing <sub>L10246</sub>
- **§3-B.** — Same address + same name ≠ same body — and the ledger keys on address <sub>L10264</sub>
- **§3-C.** — `make: *** [...] Error N` is a summary, never a diagnosis <sub>L10280</sub>
- **§3-The** — fix <sub>L10316</sub>
- **§3-The** — method that found it (this is the transferable part) <sub>L10326</sub>
- **Diagnostic** — order (adopt this) <sub>L10353</sub>
- **§3-The** — mechanism (read from cc1's own `-dR` trace, not inferred) <sub>L10369</sub>
- **§3-The** — lever — a zero-emission insn that absorbs the blocked tick <sub>L10384</sub>
- **§3-The** — finding <sub>L10420</sub>
- **§3-The** — key <sub>L10429</sub>
- **§3-Two** — cautions that must travel with this technique <sub>L10440</sub>
- **§3-The** — companion defect (open) <sub>L10451</sub>
- **Symptom** — Symptom <sub>L10471</sub>
- **Mechanism** — (gcc source + RTL dumps, not inferred) <sub>L10476</sub>
- **§3-The** — cure — a fresh launder per site, each in its own block <sub>L10489</sub>
- **Companion** — levers from the same function <sub>L10499</sub>
- **§3-B.** — Two static base-derivation methods that must AGREE (use both) <sub>L10533</sub>
- **§155a** — the same failure class, one level up: SHAPE-blind table scanning (S45 p5) <sub>L10564</sub>
- **§155c** — the ZERO-REFERENCE trap: gcc splits a global-array address across the `lui` and the LOAD (S46) <sub>L10607</sub>
- **Symptom** — Symptom <sub>L10718</sub>
- **§3-Why** — the fork is chained (gcc source, validated insn-by-insn against -dS/-dR dumps) <sub>L10724</sub>
- **§3-The** — method (dump-arithmetic first, then place — no probing) <sub>L10737</sub>
- **§162a** — SHARPENS *(sharpens §161a, §131, §8a-pad, §129a)* <sub>L11038</sub>
- **§162b** — SHARPENS *(sharpens §48-A3, §156, §150, §76)* <sub>L11067</sub>
- **§162d** — SHARPENS *(sharpens §31, §21, §30, §55a)* <sub>L11096</sub>
- **§162e** — NEW <sub>L11138</sub>
- **§162f** — SHARPENS *(sharpens §42d, §41d, §73, §10)* <sub>L11206</sub>
- **§162g** — NEW <sub>L11261</sub>
- **§162h** — SHARPENS *(sharpens §88, §88a, §50-B, §8)* <sub>L11297</sub>
- **§162i** — SHARPENS *(sharpens §135, §21, §42, §32)* <sub>L11365</sub>
- **§162j** — SHARPENS *(sharpens §25, §136d-1, §48-B, §46-L2)* <sub>L11390</sub>
- **§162k** — SHARPENS *(sharpens §1-I2, §12, §160d, §21)* <sub>L11419</sub>
- **§162l** — SHARPENS *(sharpens §48-B, §48-C1, §20, §21)* <sub>L11482</sub>
- **§162m** — SHARPENS *(sharpens §36, §158, §148, §153)* <sub>L11537</sub>
- **§158a** — THE FIFTH LEVER IS NOT AN ASM: `do { } while (0)` is a REGION ref-multiplier you MINT (P30 S48, `func_8017CBC8`, ov_MAIN_012 / jr_801789AC, 188 ins → MATCH) <sub>L11539</sub>
- **Size** — it before you write it (§158 step 1-2, applied) <sub>L11557</sub>
- **§3-The** — wrap BOUNDARY is the dial — and it is indiscriminate <sub>L11578</sub>
- **§3-Not** — a pure dial <sub>L11584</sub>
- **§162n** — NEW <sub>L11610</sub>
- **§162o** — SHARPENS *(sharpens §158, §136-1, §136-6, §79)* <sub>L11643</sub>
- **§162p** — SHARPENS *(sharpens §48-B, §46-L2, §156, §136d-1)* <sub>L11702</sub>
- **§162q** — SHARPENS *(sharpens §30, §30a, §135-2, §136-13)* <sub>L11719</sub>
- **§164** — S48 §163z SKEPTIC PASS (P30, 2026-08-12): 190 claims vetted, 82 banked <sub>L11845</sub>
- **§169** — THE MICRO-ADAPT LANE (P30 S49): edit a proven body, don't crack a new one <sub>L16260</sub>
- **§170** — THE A-PROP WORD-DIFF CARD (P30 S49): the lane that had no owner <sub>L16307</sub>
- **§171** — THE STALE SEED SYMBOL (P30 S50, 2026-08-13): why §170's 91%→57% was never codegen <sub>L16351</sub>
## All sections, in order
- **§3-How** — to use this <sub>L30</sub>
- **§1** — Idiom catalog (asm pattern → C that produces it) <sub>L39</sub>
- **§3-I1** — Unsigned range check: `(x - lo) < (hi-lo)` → `addiu`+`sltiu` <sub>L41</sub>
- **§3-I2** — Byte mask forces `andi` even after `lbu` <sub>L47</sub>
- **§3-I3** — Division by a constant → magic multiply <sub>L54</sub>
- **§3-I4** — Runtime (variable) division → `divu` + zero-check `break` (NEEDS `--expand-div`) <sub>L60</sub>
- **§2** — Writing matching C (what makes gcc emit X) <sub>L69</sub>
- **§3-T1** — Loop pointer: top-of-body for `addu` induction, not constant-folded `addiu` <sub>L71</sub>
- **§3-T2** — Source statement order drives instruction scheduling <sub>L78</sub>
- **§3-T3** — Types <sub>L85</sub>
- **§3-T4** — Branch polarity: invert the source condition to flip gcc's chosen branch <sub>L90</sub>
- **§3** — When a diff is pure scheduling → decomp-permuter (harness built, Phase 6) <sub>L107</sub>
- **§3a** — Escalation TIER above the permuter — web-research the compiler internals (HIGH VALUE, proven) <sub>L128</sub>
- **§3b** — §31-directed permuter mutation — bias the search over the class's levers (Phase 24 T5) <sub>L147</sub>
- **§4** — Flag/toolchain gotchas <sub>L190</sub>
- **§5** — Known hard-residual classes (instruction-identical, one byte-exact blocker) <sub>L199</sub>
- **§5a** — Cross-jump tail-merge — gcc collapses two byte-identical blocks the original kept separate (FIX FOUND) <sub>L211</sub>
- **§6** — Per-module optimization mixing — the -O0 boot module (Phase 7) <sub>L246</sub>
- **Detecting** — the opt level (do this first) <sub>L254</sub>
- **Build** — mechanism — per-file opt override (splat resegmentation) <sub>L288</sub>
- **§7** — PsyQ SDK types & symbols (the library-call prerequisite) <sub>L303</sub>
- **§8** — rodata island (compiler jump tables) — the `.data→.rodata→.data` sandwich (Phase 7) <sub>L320</sub>
- **§8a** — rodata island in a flat OVERLAY — the tail sandwich, per matched jr-function (Phase 26 — PoC PROVEN) <sub>L342</sub>
- **§8a-pad** — a trailing `.word 0x00000000` under a jtbl dlabel is `.align` PAD, not an entry (Phase 26 session 6, byte-proven) <sub>L380</sub>
- **§8b** — MULTI-jtbl per overlay — the `ld_interleave --order` sandwich + the same-subseg cases (Phase 26 session 4) <sub>L404</sub>
- **§8c** — Splitting a TU means rebuilding its DECLARATION ENVIRONMENT, not moving text (Phase 26 session 6) <sub>L437</sub>
- **§8d** — Templating a body INTO a TU must not CHANGE its declaration environment — demote the carried data externs (Phase 26 session 8, byte-proven on `func_8015AE2C` ×133) <sub>L483</sub>
- **§8e** — The jtbl ALIGNMENT LAW + the pad-spec filter — multi-table .rodata spans (Phase 29, byte-proven; `.run/probe_jtbl/verdict.md`) <sub>L530</sub>
- **§9** — Link real PsyQ library objects byte-exact (Phase 7 — GO proven) <sub>L613</sub>
- **§9.1** — Generalised per-object linker — `tools/psyq_link.py` (+ `psyq_link_lib.py`), 18/18 libcd byte-exact <sub>L642</sub>
- **§9.2** — Wire a library region into the build with NOLOAD — no data carving (`tools/psyq_link_region.py`) <sub>L666</sub>
- **§9.3** — Make it the build: resegment + swap + resolve (`tools/psyq_integrate.py`, libcd DONE) <sub>L685</sub>
- **§9.4** — Integrating a SECOND library (libgs block 6 after libcd) — multi-library gotchas <sub>L712</sub>
- **§9.5** — Integrating a WHOLE multi-block library in one call (full libgs — Phase 7 session G) <sub>L740</sub>
- **§9.6** — Scaling library linking to the whole EXE (Phase 8 — 8 libs linked, 20%→50% byte-identical) <sub>L766</sub>
- **§9.7** — Binary-agnostic toolchain refactor (Phase 9) — the reusable pattern for Gen2 <sub>L802</sub>
- **§10** — Closing the regalloc/scheduling hard tail by hand (LZSS, Phase 7 session F — the full close) <sub>L835</sub>
- **§3-The** — clean object-level metric (use this, not the permuter score, for jtbl/rodata functions) <sub>L844</sub>
- **Residual** — A — commutative `|`/`&`/`+` result lands in the wrong source-operand register <sub>L856</sub>
- **Residual** — B — a `return <const>` materialised late / merged instead of distributed per-site <sub>L867</sub>
- **§11** — Cross-binary dedup & code-sharing (Phase 11 — "one match unlocks many") <sub>L908</sub>
- **§3-The** — mechanism: game-code dedup is SOURCE-LEVEL, not an object swap (R-D1, the key lesson) <sub>L926</sub>
- **Per-binary** — toolchain provenance (R24) <sub>L959</sub>
- **§12** — Ultracode harvest — parallel-draft + byte-gate at scale (Phase 12, resident: 1.4%→71.7% in one session) <sub>L964</sub>
- **§13** — Add a location overlay — the canonical runbook (Phase 13; the Phase-15 fleet recipe) <sub>L1056</sub>
- **One-command** — onboarding — `tools/new_overlay.sh <SCxx> <FILE_nnn>` <sub>L1062</sub>
- **§3-The** — flat-blob overlay config (what the template encodes) <sub>L1071</sub>
- **§3-THE** — NON-4-ALIGNED-OVERLAY GOTCHA (≈75% of the fleet; fixed in the template + Makefile, automatic) <sub>L1079</sub>
- **§3-The** — A→B→C per-overlay workflow <sub>L1091</sub>
- **Dedup-credit** — (§11) for overlays — two shapes <sub>L1108</sub>
- **Fleet** — build — `make build-all` / `make check-all` <sub>L1120</sub>
- **§14** — Propagate a matched function across the fleet — `tools/dedup_propagate.py` (Phase 15) <sub>L1126</sub>
- **§14a** — The fleet bulk run (Phase 15 — `--auto-from`, 947 REAL → 74,527; 3.82% → 22.14% in one pass) <sub>L1169</sub>
- **§14b** — Harvesting the UNMATCHED shared core — the match_one wall (Phase 15) <sub>L1192</sub>
- **§14c** — Callee-signature-aware harvest — breaking the extern-type-conflict wall (Phase 15, T6) <sub>L1213</sub>
- **§14d** — Deterministic recovery beats agent waves on the hard tail (Phase 15, the final-session finding) <sub>L1269</sub>
- **§14e** — Two hard-tail dead-ends (Phase 15 — documented so they aren't re-attempted) <sub>L1298</sub>
- **§15** — Struct-heavy shared-core pipeline (Phase 16) — empirical determinations (S0) <sub>L1313</sub>
- **§16** — Guided hand-matching the struct-heavy core (Phase 17 — beats the §15 brute-force) <sub>L1335</sub>
- **§17** — The compiler-quirk wall — the matching TOOLKIT (Phase 18; gcc-2.7.2 source + byte-gated) <sub>L1376</sub>
- **Register-allocation** — ORDER (call-crossing $s0/$s1 swap) → FORCE it with register pins (byte-proven) <sub>L1384</sub>
- **§3-The** — STEERABLE idioms (byte-confirmed this phase) <sub>L1404</sub>
- **§3-The** — pipeline gotcha — match_one ≠ the gate; `sig_unify` is MANDATORY <sub>L1421</sub>
- **§3-The** — LOOSE-TYPING wall is real for narrow params (Phase 16, reconfirmed) <sub>L1428</sub>
- **Strategic** — conclusion — the match-% lever post-research <sub>L1435</sub>
- **§17a** — The TOOLKIT at WAVE scale (Phase-18 Step-3b/Step-1 — measured) + the pipeline-integration gotchas <sub>L1445</sub>
- **§18** — Per-file `-O0` split inside an overlay/blob (Phase 19 T1) <sub>L1519</sub>
- **§19** — Scaling the toolkit waves — the recovery PIPELINE + the propagation CAP (Phase 19 T3) <sub>L1597</sub>
- **§20** — The wave-at-scale GATE CAP + residual-class verdicts (Phase 20) <sub>L1632</sub>
- **§3-THE** — CAP: at this tail the match_one→gate gap is the LOOSE-TYPING CALL-GRAPH wall (not cheap plumbing) <sub>L1637</sub>
- **Diagnostic** — lesson: a failed in-TU build leaves a STALE `.o` <sub>L1654</sub>
- **§3-NEW** — / CONFIRMED residual classes (this session) <sub>L1660</sub>
- **Operational** — gotchas (cost real time) <sub>L1681</sub>
- **What** — WORKED — the Phase-20 reusable wins <sub>L1689</sub>
- **Phase-20** — RESOLUTION — `tools/cast_call_sites.py` BUILT + the cap re-diagnosed (R14, byte-proven) <sub>L1701</sub>
- **§21** — wave-distilled idioms (Phase 21) <sub>L1752</sub>
- **§22** — DEF-side loose-typing recovery + grinder blacklist (Phase 21) <sub>L2005</sub>
- **§23** — Giant `func_80153E00` cracked (scalar-data CAST); BUT most giant drafts are STALE+INCOMPLETE, and a diag MUST remove artifacts (Phase 21 — byte-proven + a self-correction) <sub>L2032</sub>
- **§24** — The `ov_SC01_077_a.c` split-file vein: split-aware propagation, but loose-typing-gated (Phase 21) <sub>L2085</sub>
- **§25** — The "schedule" class is mostly COALESCING (pin-crackable), not scheduling; + the gate two-stage + h_exact over-counts ×134 (Phase 21, cont.6) <sub>L2132</sub>
- **§3-The** — crack: the residual was gcc-2.7.2 COPY-COALESCING, not the instruction scheduler <sub>L2144</sub>
- **§3-The** — genuine scheduler — `rank_for_schedule` (sched.c), for when it IS scheduling <sub>L2160</sub>
- **§3-The** — genuine schedule WALLS (do NOT re-grind — stub) <sub>L2169</sub>
- **§3-h** — _exact OVER-COUNTS ×134 — verify shareability before crediting a class's "reach-134" (R14) <sub>L2177</sub>
- **§3-The** — gate two-stage — sig_unify is a FALLBACK, not unconditional (`gate_stage.py`, §19 folded in) <sub>L2189</sub>
- **§26** — The cheap close=0 recovery lever is EXHAUSTED; `idiom_loop --assess` was DOUBLY inflated (Phase 21, cont.7) <sub>L2199</sub>
- **§3-The** — `_a` close=0 recovery banks 0/20 — same def-side wall as MAIN (0/40) <sub>L2205</sub>
- **Where** — this leaves the reach-134 tail (cont.6 option-3, now CONFIRMED byte-backed) <sub>L2233</sub>
- **§27** — Giant matching recipe (Phase 21 cont.7b — validated on func_80176D94, 152 ins) <sub>L2259</sub>
- **§28** — Banking a "close=0 gate-rejected" giant: the canonical-extern recovery (Phase 22 T1, byte-proven on func_8015126C ×134) <sub>L2325</sub>
- **§28a** — decomp.wiki GCC patterns worth trying on BFM giants (decomp.wiki/compilers/GCC, raw at decompals/decompedia; PS1-applicable subset) <sub>L2345</sub>
- **§28c** — The close=0 recovery is NOT fully exhausted (§26 corrected, R14); + the dedup_propagate registry-skip recovery (Phase 22 T2) <sub>L2352</sub>
- **§28b** — The struct-walled close=0 giant (§28 case #3) IS bankable: the engine_types.h type-lift (Phase 22 T2, byte-proven on func_80156B74 ×134) <sub>L2357</sub>
- **§28d** — The "macro-extern-injection" lever: freeing reach-134 inline matches dedup_propagate skips as "not self-contained" (Phase 23, `tools/inject_capped_externs.py`) <sub>L2366</sub>
- **§29** — Reasoning-model (GLM5.2) DEF-side reconciliation idioms + the wall's hard limit (Phase 23 T10.7, `tools/glm_reconcile.py`) <sub>L2374</sub>
- **§30** — Fable5Max cracks §20/§10 "unsteerable" from the gcc SOURCE: store-vs-load is a `/s` aliasing flag, the def-side wall has a macro escape, + the birthing-boost (Phase 23, byte-proven on giant `func_8014EE14` 248 ins ×134) <sub>L2382</sub>
- **§30a** — §30 generalizes to the FULL near-miss backlog (via STANDARD Opus agents, not just Fable5) + 2 more steer levers + the mechanical-integration throughput unlock (Phase 23 (a)) <sub>L2394</sub>
- **§31** — THE gcc-2.7.2 CODEGEN MAP: pass → residual → C-lever catalog (Phase 23; 4 Fable5 agents read the compiler source) <sub>L2402</sub>
- **§32** — The region-a CAMERA-GIANT idiom set: struct-base hoisting + 4 sibling levers (Phase 24 T7, Fable5-cracked on `func_80129CF8` 191 ins, match_one MATCH; transferable to the 6 sibling giants) <sub>L2422</sub>
- **§33** — Automating the giant decl-reconcile: `tools/reconcile_decls.py` (the DATA analog of §20's `cast_call_sites`) + a fleet-majority type oracle (Phase 24 T7b, byte-proven on `func_80129CF8`) <sub>L2434</sub>
- **§34** — The `func_80138ED0` giant crack: gcc-2.7.2's **3-qty sort bug** + the **zero-byte asm allocation toolkit** + the **giv-init fence** (Phase 24 T5; Opus→close=21, Fable5→MATCH ×134) <sub>L2454</sub>
- **§35** — The region-a sibling-giant harvest: difficulty ≠ $s-reg count (it's global-array hoisting) + the banking recipe + new loop idioms (Phase 24 T7, 5 parallel Opus-Max agents) <sub>L2471</sub>
- **§36** — Fable5 giant-crack levers (Phase 24 T7 Fable5 batch; accumulates as each lands — full RTL dumps in `.run/t7/fable/`) <sub>L2487</sub>
- **§37** — The T7 §G giant endgame: 6/8 cracked, meta-laws + transferable levers (Phase 24, 2026-07-07; FULL byte-verified detail + gcc-2.7.2 line cites in `docs/gcc-2.7.2-map/t7g-giant-harvest.md`) <sub>L2506</sub>
- **§38** — The WHALE `func_80144B9C` (770 ins): the -O0 struct-assign memcpy idiom + the -O0 reach-134 ×134 rollout (Phase 24 T7 §G, cheap Opus — no Fable5, no calls.c) <sub>L2527</sub>
- **§39** — The ×1→×134 giant-endgame: propagate a matched **-O2** giant via the NATIVE DEFINE-macro path (Phase 24 T7 §G close, 2026-07-08) <sub>L2537</sub>
- **§40** — Structural families: the MECHANICAL symbol-remap (crack one exemplar → remap the rest, ~0 tokens) (Phase 25 T3/T7, 2026-07-08) <sub>L2553</sub>
- **§40a** — The DECL-RECONCILE pass (type-lift so remapped drafts compile in the sibling TU) (Phase 25 T7.2, 2026-07-08) <sub>L2601</sub>
- **§40b** — The reloc-tracker blind spot: the indexed-global idiom that hid the "reach-1 tail" (Phase 26 Task 1, 2026-07-11, byte-verified V0/V1) <sub>L2634</sub>
- **§40c** — The h_seq per-sibling reconcile: templating a reconcile-class crack ×134 (Phase 26 Task 8, 2026-07-12, byte-proven) <sub>L2676</sub>
- **§31-triage** — R17 applies to CODEGEN residuals, never to a compile ERROR (Phase 26 session 7, Drew asked) <sub>L2693</sub>
- **§41** — The DEF-SIDE canonical-sig wall: mechanically banking a drafted giant past `conflicting types` (Phase 25 T5b batch-2, 2026-07-09; `tools/canon_sig_reconcile.py`, byte-proven on `func_8013B274`) <sub>L2710</sub>
- **§41a** — v3.1: the def-side wall was ~71% TOOL-shaped — the five measured defects + the laws that dissolve them (Phase 25 T6, Fable5, 2026-07-09) <sub>L2754</sub>
- **§41b** — T7 execution: the object-only probe OVER-counts BANKABLE by two link/rodata classes (Phase 25 T7-M1, 2026-07-10) <sub>L2809</sub>
- **§41c** — T7-M2: the ×134 def-side-wall sweep via per-sibling RE-reconcile (Phase 25, 2026-07-10; 4,389 banks, ~0 agent tokens) <sub>L2839</sub>
- **§41b** — addendum — M4 "reconcile_decls" tier is ALSO a probe over-count: 0/8 mechanical (Phase 25 T7-M4, 2026-07-10) <sub>L2858</sub>
- **§41d** — `void`→`s32` is NOT always byte-neutral: gate the RAW draft FIRST (Phase 26 session 6, byte-proven) <sub>L2878</sub>
- **§42** — The F-band ≤28 regalloc crack wave: register-pin/DENSITY levers beat the permuter (Phase 25 T7 F-band, 2026-07-10; Ultracode 9-worker wave, 4/9 banked byte-identical, 266 swept ×134) <sub>L2900</sub>
- **§42a** — addendum — wave 2 (residuals + 29-100 band): iso-MATCH ≠ real-TU bank, the memcpy→struct-assign fix, +5 levers (2026-07-10b) <sub>L2953</sub>
- **§42b** — addendum — wave 3 (Max, 2026-07-10c): THE STALE-OBJECT GATE TRAP + the read-global `&`-cast drift + fix <sub>L2994</sub>
- **§42c** — addendum — wave 3 (Max orchestrator + CORRECTED Ultracode fan-out, 2026-07-10c): the real-TU-faithful parallel harness (rtu_match) + 7/9 crack, ZERO iso-drift <sub>L3033</sub>
- **§42d** — addendum — wave 4 (rtu_match fan-out over the mapped frontier, 2026-07-10c): 24/26 MATCH, +5 durable levers <sub>L3082</sub>
- **§42e** — propagating a CRACK ×134: the def-finder bug + the byte-drift residual (the "remap-fail" misdiagnosis) <sub>L3121</sub>
- **§43** — The K&R s16-param definition DISSOLVES the "narrow-param wall" for by-value register args (Phase 25 task A, Fable5 crack of the 369-ins giant `func_80166994` ×134, 2026-07-11) <sub>L3195</sub>
- **§44** — The Phase-25 cheap-Opus giant batch: 5 structural levers + the §43 extension (2026-07-11, 6 crackers over the frontier giants) <sub>L3242</sub>
- **§45** — The flagship `func_80133CD4` crack (399 ins ×134): the merged-variable permutation-breaker + the 1-death local-alloc gate (Phase 25 task A giant escalation, Fable5 gdb-on-cc1, 2026-07-11) <sub>L3298</sub>
- **§46** — The `func_80178D40` crack (890 ins ×134, the heaviest core in the game): four LOOP-STRUCTURE levers cheap-Opus found by reading loop.c/jump.c/cse.c (Phase 26 session 8, 2026-07-13) <sub>L3313</sub>
- **§47** — The live-length SLIDER: splitting a global.c allocno-priority TIE with one zero-byte asm (Phase 26 session 8, Fable5 Max, byte-proven on `func_8017BEBC` 952 ins ×113) <sub>L3365</sub>
- **§48** — The 12-core jr crack wave: the ALLOCNO-PRICING dials and the EBB rule (Phase 26 session 8, Ultracode, 9/12 MATCH first pass) <sub>L3405</sub>
- **§3-A.** — ALLOCNO-PRICING DIALS — move a value into the register you want, byte-neutrally <sub>L3413</sub>
- **§3-A4** — SINK THE CONSUMER CALL INTO THE ARMS (the inverse of A1; `func_8016AB6C`, byte-proven) <sub>L3444</sub>
- **§3-B.** — THE EBB RULE — the general form of §46-L2 <sub>L3468</sub>
- **§3-C.** — TYPE- AND SHAPE-DRIVEN CODEGEN (the C type literally selects the addressing mode) <sub>L3484</sub>
- **§3-D.** — THE CROSS-JUMP RATCHET (the sharpest new trap — `func_80131340` L-C) <sub>L3508</sub>
- **§3-E.** — Meta <sub>L3518</sub>
- **§49** — The LUID DIAL: a zero-byte SCHEDULING dial (the sched.c analogue of §47) — `func_8017A4AC` (536 ins ×134), Phase 26 session 8 <sub>L3527</sub>
- **§50** — Refinements that BOUND §47/§48 (from the `func_80135EB0` wall, 21→6; Phase 26 session 8) <sub>L3576</sub>
- **§51** — TOOLING INTEGRITY: the silent skip, and how to hunt it <sub>L3630</sub>
- **§51a** — The bug class <sub>L3636</sub>
- **§51b** — Why the byte-gate cannot save you <sub>L3652</sub>
- **§51c** — THE METHOD (do not audit by reading the regex) <sub>L3662</sub>
- **§51d** — THE LAWS <sub>L3677</sub>
- **§51e** — The false-wall pipeline (why this is not just hygiene) <sub>L3739</sub>
- **§51f** — Checklist for any new corpus-scanning tool <sub>L3755</sub>
- **§51g** — When the thing you are scanning has a GRAMMAR, parse the grammar (`tools/cdecl.py`) <sub>L3769</sub>
- **§52** — The WALKER-FAMILY skeleton: 6 regalloc-order levers + a deeply-characterized intrinsic wall (`func_80178004`, 165 ins ×134; Phase 26, Fable5, 2026-07-15) <sub>L3913</sub>
- **§3-The** — 6 levers (the "walker-family skeleton" — apply to the 12 siblings; levers 1-5 retire ~half the residual) <sub>L3924</sub>
- **§3-Why** — the wall is (probably) intrinsic <sub>L3945</sub>
- **§52a** — The regalloc sibling wave: new levers + two new wall classes (cheap-Opus applying §52, 2026-07-15) <sub>L3959</sub>
- **§52b** — Sibling wave 2: more de-pin levers, a third wall class, and the match_one→whole-binary gap at scale (2026-07-15) <sub>L3997</sub>
- **§53** — SWEEP A FAMILY WITH THE TOOL ITS EXEMPLAR NEEDED: the jr/switch carve, and how omitting it manufactured the "families don't template" doctrine (Phase 28 T1, 2026-07-15) <sub>L4028</sub>
- **§3-The** — case <sub>L4033</sub>
- **§3-Why** — 0/8 was structural, and predictable from two words <sub>L4045</sub>
- **§3-The** — rule <sub>L4062</sub>
- **§3-The** — meta-lesson (R35, and why this one is expensive) <sub>L4078</sub>
- **§55** — Core-crack wave levers + the GATE-ORCHESTRATION law (Phase 29 T3, 13-agent ultracode wave, 2026-07-17) <sub>L4093</sub>
- **§55a** — New byte-proven levers (each from a banked or near draft) <sub>L4098</sub>
- **§55b** — THE GATE-ORCHESTRATION LAW (3 traps, ~3.5h lost; all recovered, 0 data lost) <sub>L4122</sub>
- **§55c** — Sizing the propagate: a TARGETED propagate is ~4 min/core, and "it's slow" was a BROKEN-TREE ARTIFACT <sub>L4141</sub>
- **§54** — `--fix-def-sig`: the member's CANONICAL DECLARATION is a build step too (tiny-IMM mega-pools, +4,801, Phase 29 T6, 2026-07-16) <sub>L4163</sub>
- **§56** — Banking a hand-drafted GIANT into its exemplar TU: self-contained draft vs live-TU decls, 4 reconciliation tactics (`func_8013FAF8`, 312 ins ×138, Phase 29 T4, 2026-07-17) <sub>L4187</sub>
- **§56b** — PROPAGATING an h_seq giant: the exemplar's externs MUST be fleet-canonical, not the draft's types <sub>L4232</sub>
- **§57** — The SELF-decl normalize: the sibling's OWN caller declares the templated fn divergently (the third §17a-1 direction; `tools/normalize_self_decls.py`, func_801670E4 ×137, Phase 29, 2026-07-18) <sub>L4256</sub>
- **§57a** — Two NSD corrections + the SURGICAL-ONLY law + the honest broad-sweep yield (Phase 29, 2026-07-18) <sub>L4303</sub>
- **§58** — match_one MATCH ≠ BANK: the four blind spots + the crack-wave reconcile-before-bank law (Phase 29 crack-wave, 2026-07-18) <sub>L4343</sub>
- **§59** — Three h_seq sweep-residual classes match_one/the-exemplar-bank don't reveal (Phase 29 crack-wave close, 2026-07-18) <sub>L4377</sub>
- **§60** — Classify the residual, don't rank it: the deterministic residual→class classifier and what it measured about the backlog (Phase 29 Task-13A, 2026-07-21) <sub>L4407</sub>
- **What** — it measured — the whole open backlog, byte-grounded <sub>L4431</sub>
- **§3-Two** — corollaries worth remembering <sub>L4450</sub>
- **§3-The** — parallel-probe race this surfaced <sub>L4463</sub>
- **§60a** — What the first DIRECTED grinder run exposed (Phase 29 Task-13B, 2026-07-21) <sub>L4472</sub>
- **§60b** — The plateau autopsy's verdict: a `partial` drift is a WRONG DRAFT, not a missing transform (Phase 29 Task-13B close, 2026-07-21) <sub>L4510</sub>
- **§61** — Task 14: the gate ladder's missing stage is the ARITY pre-pass, and it is TU-side not draft-side (Phase 29, 2026-07-21) <sub>L4545</sub>
- **§61a** — The Task-5 wave: 11/12 MATCH, 0 banked — three DISTINCT integration walls, each now named (Phase 29, 2026-07-21) <sub>L4606</sub>
- **§61b** — The jtbl gate stage: built, and the ORDERING law it exposed (Phase 29 Task-14 stage 4, 2026-07-21) <sub>L4658</sub>
- **§61c** — The jtbl bank is INCREMENTALLY valid and CLEAN-INVALID (Phase 29, 2026-07-21) — the blocking finding <sub>L4713</sub>
- **§61d** — The undo was eating the tree: two tools, one defect, invisible to the byte-gate (Phase 29, 2026-07-22) <sub>L4779</sub>
- **§62** — The jtbl RECONCILE must also follow the carve: the post-carve draft reconcile (`harvest_verify._jtbl_reconcile`, Phase 29 SESSION-11, 2026-07-22) <sub>L4833</sub>
- **§63** — The fresh-138 DEF-SIDE blocker: fix the HEADER decl, not the draft (`fix_header_decl.py`, Phase 29 SESSION-13, 2026-07-23) <sub>L4877</sub>
- **§64** — The §20 type-lift's three laws: fold the tagged typedef, check VISIBILITY, and strip only what is TEXTUALLY IDENTICAL (`lift_types.py`, Phase 29 SESSION-14, 2026-07-23) <sub>L4908</sub>
- **§64a** — VARIANT types: UNIQUIFY the camps, do not reconcile them (`uniquify_type.py`, Phase 29 SESSION-14) <sub>L4957</sub>
- **§63** — UPDATE (Phase 29 SESSION-14) — `fix_header_decl`'s "SAFE" verdict is FLEET-BLIND; it MUST be R22-validated <sub>L5000</sub>
- **§65** — The stranded-draft recovery: BLAST-RADIUS TIERS, and the per-overlay de-macroize that refutes §20's DEF-conflict wall (`tools/demacroize.py` + `tools/blocker_probe.py`, Phase 29 SESSION-16, 2026-07-24) <sub>L5015</sub>
- **§65a** — The blast-radius taxonomy (makes §61's law structural instead of remembered) <sub>L5030</sub>
- **§65b** — The escape: de-macroize the instantiation, don't touch the shared header <sub>L5045</sub>
- **§65c** — `rtu_match` MATCH → bank held 13/13 on self-decl, but broke on the FIRST callee-decl case <sub>L5081</sub>
- **§65d** — Existing-ladder baseline, measured (do this before building a recovery stage) <sub>L5091</sub>
- **§65e** — Two oracles, and the disagreement is the finding (R34 in practice) <sub>L5101</sub>
- **§65f** — The de-macroize lever's BOUNDARY, measured: byte-neutral 14 times of 15, and the 15th is why the gate exists <sub>L5118</sub>
- **§65g** — Where the cheap levers STOP: the local-type and in-TU-self-decl classes did not yield <sub>L5139</sub>
- **§66** — Exercise a banking driver's SUCCESS path before pointing it at a wave: the free re-bank test (Phase 29 SESSION-17, 2026-07-24) <sub>L5159</sub>
- **§66a** — The widest write in a pipeline is the one most likely to be UNDECLARED <sub>L5181</sub>
- **§66b** — A metric parsed out of another tool's prose goes NULL silently when the label changes <sub>L5200</sub>
- **§66c** — Before a wave, verify the FUEL exists; an "already attempted" set built from the wrong directory lies in BOTH directions <sub>L5217</sub>
- **§66d** — The permuter⇄reader loop: alternate a random search with a byte-verified idiom, and let `residual_class` decide whose turn it is (Phase 29 SESSION-17) <sub>L5245</sub>
- **§66d-1** — What transfers between giants is the LOOP, not the PIN <sub>L5280</sub>
- **§66d-2** — Two operational sharp edges <sub>L5289</sub>
- **§66d-3** — Read the ILS per-cycle SERIES, not its final best: a repeated score and a still-falling one look identical in a summary line and mean opposite things <sub>L5300</sub>
- **§67** — The arg-copy PLACEMENT lever: launder a parameter into a fresh pseudo AT the statement where the target's copy lands (Phase 29 SESSION-18, `func_8014D820` 25 → 16) <sub>L5315</sub>
- **§67a** — Run the symbol-set guard BEFORE you pay for a gate (`tools/symcheck.py`, Phase 29 SESSION-18) <sub>L5405</sub>
- **§66d-4** — "ILS converged" means converged FOR THAT WEIGHT PROFILE, not a floor (amends §66d-3; Phase 29 SESSION-18) <sub>L5438</sub>
- **§66d-5** — `residual_class`'s "structural ⇒ permuter CPU is waste" is WRONG for schedule permutations (measured, Phase 29 SESSION-18) <sub>L5491</sub>
- **§68** — A comment-only line halted the extern scan, and the skip label blamed the type cap (Phase 29 SESSION-18) <sub>L5524</sub>
- **§69** — How to attack a behemoth: map it, don't draft it (Phase 29 SESSION-18, `func_80183814`, 5,122 ins) <sub>L5569</sub>
- **§70** — The giv-init base register: walk the PARAMETER, not a copy of it (Phase 29 SESSION-18, `func_801777BC`) <sub>L5619</sub>
- **§71** — Before mapping a giant, look for an already-matched SIBLING beside it (Phase 29 SESSION-18, `func_8017D960`, 3,338 ins) <sub>L5660</sub>
- **§72** — A `register __asm__` pin is a PREFERENCE, not a reservation (Phase 29 SESSION-18, `func_8017F510`) <sub>L5726</sub>
- **§3-The** — honest fix was source-level and cheap <sub>L5750</sub>
- **§3-Giv** — record order (the §70 family) <sub>L5760</sub>
- **What** — is left, and what is byte-recorded as SPENT <sub>L5766</sub>
- **§73** — A def-side self-decl conflict has TWO axes: RETURN (fleet widen, T2) and PARAMS (casts at each use, T0). Diagnose which before paying for the expensive one (Phase 29 SESSION-19, `func_8014F3E8` + `func_8014D4C0`) <sub>L5783</sub>
- **§74** — Auditing a pinned draft: the §72 hazard is CALLER-SAVED pins spanning a call, and only the disassembly can tell you (Phase 29 SESSION-19, `func_8017D960` b2, 5 pins) <sub>L5822</sub>
- **§75** — A propagation cap is usually a MINORITY-SPELLING SOURCE OVERLAY, not a wall: census the carried extern before believing the exclusion message (Phase 29 SESSION-19, `func_8014F3E8` ×4 → ×138) <sub>L5866</sub>
- **§75a** — The exclusion classes, enumerated with named causes (Phase 29 SESSION-19, the 134-binary `dedup_extend` sweep) <sub>L5925</sub>
- **§75b** — A body's preamble can carry `#define`s, not just `extern`s; extraction lifts only the externs (Phase 29 SESSION-19, `func_80165CA0` ×3 → fleet) <sub>L5948</sub>
- **§75c** — Class-B's remedy is the FULL §17a-1 PAIR (decl **and** call-site cast); a decl-only fix moves the error and looks like a new wall (Phase 29 SESSION-19, `func_8012F14C`) <sub>L5997</sub>
- **§76** — The allocno CLASS (local vs global) is the dominant regalloc lever, and C reaches it ONLY through declaration scope and variable reuse (Phase 29 SESSION-19, behemoth #3 `func_8017F510` 1,511 ins, 97 → MATCH, pin-free) <sub>L6028</sub>
- **§3-The** — mechanism, with citations <sub>L6037</sub>
- **§3-The** — attribution primitive (use this before calling anything a scheduling residual) <sub>L6057</sub>
- **§3-Two** — diagnosis traps this function proved <sub>L6064</sub>
- **Practice** — Practice <sub>L6074</sub>
- **§77** — Every extraction tool carries a NARROW hard-coded preamble set; anything outside it silently caps the body's reach. Diff the preamble before you gate. (Phase 29 SESSION-19 — three variants in one session, two different tools) <sub>L6084</sub>
- **§3-The** — CANDIDATE gate and the REAL gate need DIFFERENT preambles — keep the difference out of the bank <sub>L6124</sub>
- **§78** — A LENGTH drift can be a register grant in disguise; and `fold` never leaves a literal first in an `|` chain (Phase 29 SESSION-19, behemoth #2 `func_8017D960` 3,338 ins, 1806 → 0, pin-free) <sub>L6174</sub>
- **§3-The** — drift was an allocation decision, not missing code <sub>L6180</sub>
- **§3-The** — economics <sub>L6211</sub>
- **§79** — For a 0-callee giant, fingerprint by DATA symbols (§71 cannot fire); and the STACK-SLOT ORDER is a declaration-order oracle (Phase 29 SESSION-19, `func_8017BF14` 4,763 ins, cold start → 45/4763) <sub>L6220</sub>
- **§71** — has a blind spot, and this is it <sub>L6226</sub>
- **§3-NEW** — LEVER — the frame layout reads back the original declaration order <sub>L6240</sub>
- **§76** — confirmed at scale, and a pin nuance <sub>L6251</sub>
- **§3-The** — residual, and the honest read <sub>L6260</sub>
- **§80** — A do-not-re-buy entry is scoped to its BASE, not to the function; and the pin's hidden cost is an unconditional `qty_phys_sugg` (Phase 29 SESSION-19, `func_8017BF14` 45 → 0) <sub>L6270</sub>
- **§3-The** — pin's hidden cost, with the citation <sub>L6291</sub>
- **§3-The** — flagged "#1 move" LOST — and why the failure is informative <sub>L6302</sub>
- **§78** — 's attribution primitive, run and reproduced <sub>L6312</sub>
- **Cold-start** — economics, now complete <sub>L6318</sub>
- **§81** — Banking a jr (jump-table) function: the 3-step carve chain, and why `match_one` cannot see the problem (Phase 29 SESSION-19, `func_8017C954`) <sub>L6323</sub>
- **§3-The** — defect this exposed: a shared type that is present but invisible <sub>L6354</sub>
- **§82** — Two source-shape oracles from behemoth #6: a duplicated `addiu $aN,$sp,K` across a `jal` means the block was INLINED, and scalar-vs-aggregate decides WHEN a stack slot is allocated (Phase 29 SESSION-19, `func_8017C730` 1,061 ins) <sub>L6370</sub>
- **§3-1.** — The inlined-helper signature <sub>L6375</sub>
- **§3-2.** — Scalar vs aggregate decides *when* the slot is allocated <sub>L6389</sub>
- **Also** — reproduced on this function <sub>L6401</sub>
- **§3-And** — the banking footnote (§75a class A, one line) <sub>L6405</sub>
- **§83** — The parameterised-repeat law, the spill-area trap, and why a per-case edit cannot move a per-case symptom (Phase 29 SESSION-20, `func_80183814` 5,122 ins, cold-ish start → 36 structural / 99.3%) <sub>L6412</sub>
- **§83a** — READ THE HEADLINE NUMBER CORRECTLY: a LENGTH drift makes `match_one`'s count meaningless <sub>L6419</sub>
- **§83b** — THE LEVER: find the parameterised REPEAT before decoding case-by-case <sub>L6427</sub>
- **§83c** — TRAP: a "dead local" in a prior draft may be gcc's OWN spill area <sub>L6445</sub>
- **§83d** — CSE's quantity budget is WHOLE-FUNCTION, so a local rewrite cannot fix a local symptom <sub>L6452</sub>
- **§83e** — §80 vindicated again, on the same day it was written <sub>L6466</sub>
- **§84** — The DERIVED-OFFSET remap bug: a hand-computed literal that encodes the DISTANCE between two per-overlay symbols, and why `match_one` is structurally blind to it (Phase 29 SESSION-20, `func_8013D53C`) <sub>L6472</sub>
- **§3-The** — construct <sub>L6477</sub>
- **§3-Why** — it survived every candidate gate <sub>L6495</sub>
- **§3-THE** — FIX IS MECHANICAL — the tool already holds the answer <sub>L6510</sub>
- **Scope** — , measured (do not over-generalise — §80) <sub>L6518</sub>
- **§3-Two** — ladder lessons banked with it <sub>L6528</sub>
- **§85** — The RETURN-axis fleet widen is ALL-OR-NOTHING: widening the shared header alone guarantees a conflict in the source overlay (Phase 29 SESSION-20, `func_8012CC88` / `func_8014D12C`) <sub>L6539</sub>
- **§3-The** — conflict <sub>L6544</sub>
- **§3-THE** — FAILURE MODE — widening only `engine_core.h` is worse than not starting <sub>L6552</sub>
- **§3-The** — precondition, and how to check it in one grep <sub>L6559</sub>
- **§3-Do** — the WHOLE axis in one edit, then R22 once <sub>L6567</sub>
- **Reading** — , for the next person <sub>L6576</sub>
- **§86** — Pinned-exemplar templatability is a PER-FAMILY property, not a per-member rate; and the §42e pin guard is now over-conservative (Phase 29 SESSION-20) <sub>L6589</sub>
- **§3-The** — guard refuses a class that largely works <sub>L6591</sub>
- **§3-THE** — LAW: all-or-nothing PER FAMILY <sub>L6600</sub>
- **§3-Why** — the two live families differ from the three dead ones — the open question <sub>L6627</sub>
- **§87** — `match_one` COMPILES but never LINKS, so an unresolvable data symbol reads as MATCH; and stored drafts go STALE against the tree (Phase 29 SESSION-20) <sub>L6633</sub>
- **§3-The** — blindness ladder, now complete — FOUR classes `match_one` cannot see <sub>L6649</sub>
- **Consequence** — for the backlog ledger <sub>L6659</sub>
- **§3-The** — cheap discriminator, before spending a sweep <sub>L6666</sub>
- **§88** — `cross_jump` will not merge a common suffix containing a CALL; and §78 is scoped to ORDERED comparisons only (Phase 29 SESSION-20, the behemoth close-out) <sub>L6674</sub>
- **§88a** — repeated CALL-shaped blocks are left UNMERGED; call-free tails are merged for you <sub>L6679</sub>
- **§88b** — the `slti` literal-position law (extends §78 to comparisons) <sub>L6686</sub>
- **§88d** — BANKING ORDER: run the §81 carve chain BEFORE banking, never after <sub>L6701</sub>
- **§88e** — a wrong diagnosis, refuted properly (the model for how to treat an inherited lever) <sub>L6708</sub>
- **§88f** — the missing rung: a RELOCATION gate between `match_one` and the binary <sub>L6718</sub>
- **§89** — Two throughput rules the project already had written down and was not following (Phase 29 SESSION-20) <sub>L6726</sub>
- **§89a** — MEASURE the write set; do not assert its tier (`tools/blast_radius.py`) <sub>L6732</sub>
- **§89b** — the parallel gate farm existed; the family path could not reach it (`tools/sweep_parallel.py`) <sub>L6745</sub>
- **§3-The** — standing sequence <sub>L6758</sub>
- **§90** — Five tool-integrity laws from one session, each of which changed an answer (Phase 29 SESSION-21, 2026-07-27) <sub>L6766</sub>
- **§90a** — A comparison tool MUST share its reference oracle's index space, exactly <sub>L6772</sub>
- **§90b** — "Byte-neutral" is not "wanted": undo on the SUCCESS path too <sub>L6789</sub>
- **§90c** — A library-callable function must FAIL CLOSED on an unconfigured module <sub>L6799</sub>
- **§90d** — Do not measure a live wave's drafts (§87 in real time) <sub>L6810</sub>
- **§90e** — An agent's CONCLUSION and its EVIDENCE fail independently — re-derive the premise, not the fix <sub>L6818</sub>
- **§91** — A structure-TRANSFER is only valid where the structure corresponds: the `--like` role trap (Phase 29 SESSION-21, `func_8012AAAC` ×137) <sub>L6842</sub>
- **§3-The** — three-hypothesis trail, because two of them were wrong and the wrongness is instructive <sub>L6871</sub>
- **§92** — Conforming a DECLARATION: pointer changes are caller-neutral, scalar-WIDTH changes are not (Phase 29 SESSION-21, `tools/conform_decls.py`) <sub>L6891</sub>
- **§93** — `set -o pipefail` attributes a pipeline failure to the LAST stage, not the failing one (Phase 29 SESSION-21, `func_8014D820`) <sub>L6922</sub>
- **§94** — A family sweep's `0/N` is a TYPE-CARRY failure until proven otherwise: lift the exemplar's local types, ALL of them, transitively (Phase 29 SESSION-21, `func_8016B6BC` 0/137 → 137/137) <sub>L6947</sub>
- **§95** — `reconcile_tu` dropped the SIBLING declarators of a multi-symbol `extern` line (Phase 29 SESSION-21, `func_80176218`) <sub>L6983</sub>
- **§96** — The same rewrite, one shape down: `reconcile_tu` matched statements to lines by TEXT, so every COMMENTED declaration was silently skipped (Phase 29 SESSION-22, `func_80176218` banked) <sub>L7018</sub>
- **§97** — The gate's own tree hygiene: a refused carve, an unchecked recovery, and a snapshot that captured a dirty tree (Phase 29 SESSION-22) <sub>L7066</sub>
- **§98** — `conform_decls` had three defects, and only the third needed R22 to find (Phase 29 SESSION-22, `func_8014CF04`) <sub>L7113</sub>
- **§99** — The narrow-param wall is a DEF-side problem with a ZERO-blast-radius fix: convert the definition to K&R (Phase 29 SESSION-22, `func_80175AB8` + `func_80175DA8`) <sub>L7167</sub>
- **§3-Two** — `reconcile_tu` bugs found underneath, one introduced while fixing the other <sub>L7190</sub>
- **§100** — Prefer the DRAFT-LOCAL fix: a type only one function uses belongs in its BODY, not in a shared header (Phase 29 SESSION-22, `func_80175DA8` 0/137 → 137/137) <sub>L7216</sub>
- **§101** — The STALE DEFAULT class: a guard whose cause was removed is a silent skip wearing a safety label (Phase 29 SESSION-22, three instances in one session) <sub>L7245</sub>
- **§102** — A PLUMBING verdict can MASK a DIFF; and K&R is not always a codegen change (Phase 29 SESSION-22, `func_8016EC0C`) <sub>L7272</sub>
- **§103** — A FILE-scope `extern` in a shared overlay TU is a GLOBAL constraint on every LATER function; move the DECL, not the draft (Phase 29 T48/T51, `func_80135260` — the fleet-wide half) <sub>L7307</sub>
- **§104** — Two silent-skip defects in one scan: match on MASKED text, emit from the ORIGINAL (Phase 29 T53, `gather_externs`) <sub>L7395</sub>
- **§105** — A gate's revert must survive an EXCEPTION, not just a failure (Phase 29 T53, `jtbl_family_bank`) <sub>L7431</sub>
- **§106** — Persist the MEASUREMENT, derive the POLICY: a stored route let a stale file out-vote the live table (Phase 29 T54, `residual_class._ROUTE`) <sub>L7470</sub>
- **§107** — A lever wired into ONE gate path is a lever most families cannot reach (Phase 29 T56, `func_80144090` 0/136 → 136/136) <sub>L7513</sub>
- **§108** — Diagnosing a family `0/N`: the four causes, and the third opt-in lever (Phase 29 T59) <sub>L7551</sub>
- **§109** — Conforming a definition to a shared header: fix the NAMES, then check the RETURN precondition (Phase 29 T60) <sub>L7600</sub>
- **§110** — A unit must define exactly ONE function, and "ends in `;`" does not tell you which line defines it (Phase 29 T65) <sub>L7640</sub>
- **§111** — The distinct-code metric is not noisy: a family pays it only if its members are byte-VARIANT (Phase 29 T66) <sub>L7681</sub>
- **§112** — A macro-scoped declaration only collides where the macro is INSTANTIATED (Phase 29 T67/T69, `audit_header_sigs.py`) <sub>L7730</sub>
- **§113** — An ARITY blocker only exists if the macro CALLS the function; an address-taken use has no call site (Phase 29 T72) <sub>L7776</sub>
- **§114** — The THIRD decl axis: a CALLEE the draft declares differently from the target TU (Phase 29 T76/T77) <sub>L7808</sub>
- **§115** — A `func_XXXXXXXX` predicate rots by design: the same name-form assumption in THREE places (Phase 29 T78) <sub>L7850</sub>
- **§116** — Optimization level is a property of the FILE, not the function: read a family 0/N against the member's stub HOME (Phase 29 T79) <sub>L7877</sub>
- **§3-The** — fix moves the DEFINITION, not the stub — and here is why the obvious shortcut fails <sub>L7895</sub>
- **§117** — Spell the sibling's symbol from the SIBLING's address, not the exemplar's kind (Phase 29 T82) <sub>L7926</sub>
- **§3-Why** — it survived so long: a MASKED oracle will MATCH a wrong symbol <sub>L7953</sub>
- **§118** — Ordinal (positional) immediate resolution: compare C tokens to the DIFFERING asm uses (Phase 29 T87) <sub>L7963</sub>
- **§119** — Two levers on the SAME axis, opposite directions: test the off-diagonal (Phase 29 T89) <sub>L7997</sub>
- **§120** — Uniquify draft-defined TYPE names; and check which of N staging sites you actually patched (Phase 29 T93) <sub>L8026</sub>
- **§3-Do** — NOT "strip the duplicate typedef" — it breaks the extern that uses it <sub>L8037</sub>
- **§3-The** — wiring trap that cost two attempts <sub>L8043</sub>
- **§121** — Synthesise externs for macro-DEFINED callees from the macro's own definition head (Phase 29 T95) <sub>L8061</sub>
- **§122** — GATE RAW BEFORE TRANSFORMING; the undo belongs to the WRITER, as a per-edit journal (P30 T0a, 2026-07-30) <sub>L8084</sub>
- **§123** — PROPAGATE A FAMILY WITH THE TOOL ITS TIER NEEDS: `dedup_propagate` is h_exact-only; its refusals are statements about the TOOL (P30 wave 1, 2026-07-30) <sub>L8116</sub>
- **§124** — A "not matched" verdict can mean the definition is there under a DIFFERENT C NAME: the asm-label alias blind spot (P30 SESSION-28, `func_8016191C` ×137) <sub>L8153</sub>
- **§124a** — a family sweep's `0 matched-exemplar families` may be a FILTER, not a wall <sub>L8198</sub>
- **§125** — Split the CARVE from the BODY before calling a jr residue a wall — and measure it by SHA from a CLEAN tree (P30 SESSION-28; **this section's first draft was WRONG and the method caught it**) <sub>L8206</sub>
- **§3-The** — method (keep this) <sub>L8213</sub>
- **§3-The** — instrument rules that make its answer trustworthy (this is where I failed) <sub>L8223</sub>
- **§3-The** — corrected results (each SHA-verified, from a clean tree, restore re-verified) <sub>L8238</sub>
- **§3-Two** — further notes worth keeping <sub>L8248</sub>
- **§3-The** — meta-lesson <sub>L8257</sub>
- **§126** — The carve-within-a-carve: an ADDRESS RANGE is not an OPTIMIZATION REGION (P30 T2, byte-proven end-to-end) <sub>L8264</sub>
- **§3-The** — finding: opt level is per FILE, so the file's contents must be opt-HOMOGENEOUS <sub>L8279</sub>
- **§3-The** — instrument trap that hid it (and it is §124's shape again) <sub>L8290</sub>
- **§3-The** — mechanics <sub>L8299</sub>
- **§126a** — a bare `except: continue` around a coverage-asserting oracle re-creates the silent skip (P30 S28) <sub>L8317</sub>
- **§127** — The `-O0` regime: the CONSTANT-OFFSET FOLD, and why `-O0` needs its own idiom set (P30 T3 wave, 15 targets) <sub>L8349</sub>
- **§3-The** — idiom they kept re-deriving: the constant-offset fold <sub>L8356</sub>
- **§3-The** — rest of the `-O0` regime (write PLAIN C, and mean it) <sub>L8367</sub>
- **§127a** — §71 (sibling-first) is the strongest `-O0` lever, and it beats the index <sub>L8377</sub>
- **§127b** — the knowledge was in a SOURCE COMMENT, not the cookbook <sub>L8386</sub>
- **§128** — A raw NUL in C source makes grep SILENTLY SKIP the file (P30 S28, 137 files) <sub>L8393</sub>
- **§128a** — a negative control must corrupt a SCRATCH COPY, never the tracked file <sub>L8425</sub>
- **§129** — Post-carve, `rtu_match`/`match_one` COUNT THE JUMP TABLE AS INSTRUCTIONS; and a carve must never be committed without its owner (P30 S28, `func_8013BD74`) <sub>L8437</sub>
- **§129a** — the target instruction count is INFLATED after a carve <sub>L8441</sub>
- **§129b** — never commit a carve whose owner is still a stub (it strands the carve) <sub>L8462</sub>
- **§3-The** — real blocker underneath, for the record <sub>L8477</sub>
- **§130** — An INCREMENTAL build can report BYTE-IDENTICAL for a change the CLEAN build cannot even LINK (P30 S28, the jr pair) <sub>L8486</sub>
- **§3-The** — diagnostic ladder that finally located it (reusable) <sub>L8523</sub>
- **§131** — The jtbl OVER-SPAN: `sltiu N` is ground truth in BOTH directions, and the zero-word rule only guards one (P30 S28, `func_80191C50`) <sub>L8533</sub>
- **§132** — The `JR-PAIR-IN-ONE-O0-OBJECT` "wall" was TWO instrument defects: a merged-double span the carve could not see, and a truncated object no rule deleted (P30 S29, `func_8013B83C` + `func_8013BD74`) <sub>L8570</sub>
- **Defect** — 1 — a pre-§8e MERGED DOUBLE is not a single-table predecessor <sub>L8579</sub>
- **Defect** — 2 — `as` writes a corpse and nothing deletes it <sub>L8597</sub>
- **§3-The** — fingerprint, and the 30-second ladder that found it <sub>L8607</sub>
- **§3-The** — transferable rule <sub>L8628</sub>
- **§132a** — `--like` is for a sibling with NO record; against one that HAS a record it over-derives (P30 S29, `ov_SC07_010`) <sub>L8635</sub>
- **§132b** — When the span's already-matched owner is ITSELF multi-switch: `--span-rel` (P30 S1, `func_8014032C`) <sub>L8660</sub>
- **§133** — The DEFAULT-FILTER class: three times in one session, a tool silently answered a narrower question than the one asked (P30 S1–S3) <sub>L8685</sub>
- **§134** — MULTI-LINE BLINDNESS: one root cause, four faces, in `family_remap`'s preamble scanner (P30 S6, 190 zero-crack families) <sub>L8711</sub>
- **§135** — Six byte-verified gcc-2.7.2 idioms from the P30 S6f-h waves (and the two-lane wave shape that found them) <sub>L8765</sub>
- **§3-The** — codegen idioms <sub>L8770</sub>
- **§3-The** — integration idioms (these decide whether a byte-correct draft BANKS) <sub>L8804</sub>
- **§3-The** — wave shape that produced these <sub>L8819</sub>
- **§136** — The LOCAL-VARIABLE lever: how many C locals, at what scope (P30 wave 4a, 25 byte-verified banks) <sub>L8837</sub>
- **§3-The** — splitting/merging rules (each closed a residual, byte-gated) <sub>L8853</sub>
- **§3-The** — type-form rules <sub>L8879</sub>
- **§3-The** — scheduling rules (refining §135-2 and §135-4) <sub>L8909</sub>
- **§3-The** — declaration surface (integration, not codegen) <sub>L8938</sub>
- **Wave** — economics (measured, for the next batch's sizing) <sub>L8950</sub>
- **§136a** — Blocker capture: classify on the OUTPUT, never on the exit status <sub>L8973</sub>
- **§136b** — A prior wave's "genuine byte-DIFF" verdict is NOT reliable evidence (4 of 4 refuted) <sub>L9030</sub>
- **§136c** — SIBLING-FIRST is a DERIVATION shortcut, not just a conflict fix (the fastest route in a family wave) <sub>L9066</sub>
- **§136d** — Four gcc-2.7.2 levers the redraft lane found (each closed a residual no other lever moved) <sub>L9091</sub>
- **§136e** — §136c's PRECONDITION, and two more symptom keys (wave 4b batch 3) <sub>L9135</sub>
- **§136f** — Two declaration sub-cases the reconcile lane surfaced (lane now 15/15 lifetime) <sub>L9183</sub>
- **§136g** — When the index points at the WRONG lever: two byte-refuted routings (func_801863B4) <sub>L9208</sub>
- **§136h** — CORRECTION: the zero-crack pool does NOT "refill with cheap work" (my error, byte-measured) <sub>L9237</sub>
- **§136i** — The drafter model LADDER: Haiku → **Sonnet** → Opus → Fable5 (Drew, 2026-08-03) <sub>L9267</sub>
- **§136j** — The failure MIX flips with function size (measured across four bands, one session) <sub>L9299</sub>
- **§137** — REGALLOC-PERM is a TWO-COMPILE ARITHMETIC PROBLEM, not a permuter job <sub>L9341</sub>
- **§137a** — A gate verdict has a TIMESTAMP; re-check it against the draft's mtime <sub>L9383</sub>
- **§138** — The propagation lanes: a gate refusal is a DECLARATION, and which lever you owe depends on blast radius <sub>L9412</sub>
- **§3-The** — triage, cheapest first <sub>L9418</sub>
- **§3-The** — DEFINITION-side alias is the only escape when the fleet canon disagrees on a promoting param <sub>L9470</sub>
- **Rank** — the lane by measured concentration, not by class count <sub>L9478</sub>
- **THREE** — carry variants hide in one "CARRY-FIXABLE" bucket — and they need different fixes <sub>L9487</sub>
- **§134** — again, in a second tool — and the waiter rule corrected <sub>L9523</sub>
- **STEP** — 0 of sibling-first: grep `src/` for a distinctive LITERAL from the `.s` <sub>L9543</sub>
- **Reconciling** — a gate-refused draft: which way you edit depends on WHERE the TU's decl is <sub>L9562</sub>
- **§139** — A GATE THAT GREPS FOR VERDICTS MUST ASSERT 1:1 ACCOUNTING; and a `--src` filter must not survive a carve (P30 S38, wave 6: 10 of 16 drafts vanished) <sub>L9591</sub>
- **§3-The** — generalisation — three corollaries worth more than the bug <sub>L9623</sub>
- **§3-And** — the inverse-lookup trap, same session <sub>L9640</sub>
- **§140** — A METRIC IS NOT A MEASUREMENT UNTIL IT IS REPRODUCIBLE FROM THE COMMITTED TREE (P30 S1e: a phantom regression that gated the session's best lever) <sub>L9657</sub>
- **§3-The** — three-line proof (do this before diagnosing any metric movement) <sub>L9677</sub>
- **§3-The** — two instrument defects it exposed <sub>L9686</sub>
- **§3-The** — same swallow, twice more, in the integration spine <sub>L9706</sub>
- **§3-Two** — wrong mechanisms I chased first, and why they were wrong <sub>L9717</sub>
- **§141** — The §134 class is CLOSED: every line-shape decision now routes through `cdecl._mask` (P30 S39) <sub>L9737</sub>
- **§142** — An open stub whose `h_exact` class is MATCHED elsewhere is FREE. Propagate the body; do not gate a draft. (P30 S39, +7,710 ins in two commands) <sub>L9775</sub>
- **§3-The** — measurement (do this before any wave; it is ~20 lines and needs no builds) <sub>L9787</sub>
- **§3-The** — trap that hid it — SAME FUNCTION, TWO ROUTES, ONLY ONE IS FREE <sub>L9802</sub>
- **Route** — selection (why `--addr` sometimes says "nothing changed") <sub>L9811</sub>
- **§3-And** — the report-vs-bytes lesson attached to it <sub>L9819</sub>
- **§143** — `cast_call_sites` read a RETURN STATEMENT as a prototype and deleted it. A 0/39 sweep became 18/39. (P30 S40) <sub>L9831</sub>
- **§144** — THE LITERAL'S SPELLING PICKS THE IMMEDIATE ENCODING (P30 S40 wave 1, `func_801822E0`) <sub>L9885</sub>
- **§145** — Three loop/combine levers from the S40 wave-2 drafters (16/16 match_one) <sub>L9924</sub>
- **§146** — RE-MEASURE A WALL BEFORE YOU RESPECT IT. Both "permanent" giants fell to drafts already on disk. (P30 S6, +50,094 ins) <sub>L9974</sub>
- **§3-Why** — a correct draft can read as an intrinsic wall <sub>L9985</sub>
- **Then** — propagation returned 0/137 TWICE — both times a missing TYPE <sub>L9997</sub>
- **§3-Two** — errors of mine, both instructive <sub>L10006</sub>
- **§3-The** — rule <sub>L10020</sub>
- **§147** — The three-stratum FRAME LAW, and four "stop searching" verdicts (P30 S42, `func_8017C294`, serial run) <sub>L10033</sub>
- **§3-A.** — The frame has THREE strata, and stratum 3 is unreachable from C <sub>L10038</sub>
- **§3-B.** — A `?:` on MEMORY operands costs ~16 bytes of invisible frame; on REGISTER operands, zero <sub>L10054</sub>
- **§3-C.** — Inner-block declaration does NOT delay slot allocation — BYTE-REFUTED <sub>L10065</sub>
- **§3-D.** — A lone `$t8`/`$t9` in the target is RELOAD SCRATCH — reproduce the spill, don't pin the register <sub>L10070</sub>
- **§3-E.** — A `qty_compare` TIE is not spelling-reachable — recognise it and stop <sub>L10080</sub>
- **Consequence** — for the family (a real scheduling decision) <sub>L10092</sub>
- **§148** — The loop.c hoisting THRESHOLD is arithmetic you can compute, and the `?:` clamp that folds to MIN_EXPR (P30 S42, `func_8017C6F4`, 947 ins) <sub>L10142</sub>
- **§3-A.** — `move_movables` hoists iff `threshold × savings × lifetime ≥ insn_count` — and you can read it <sub>L10148</sub>
- **§3-B.** — `(v < 0x40) ? v : 0x3F` is folded to `MIN_EXPR` and expands to the WRONG SHAPE <sub>L10167</sub>
- **§3-C.** — A zero-byte ALLOCNO-PRIORITY slider <sub>L10181</sub>
- **§3-D.** — Reproduce the original's BUGS verbatim <sub>L10191</sub>
- **§149** — Four instrument defects in one session, and the two questions they were hiding (P30 S43) <sub>L10240</sub>
- **§3-A.** — A prep step that returns its input on failure is indistinguishable from a search that found nothing <sub>L10246</sub>
- **§3-B.** — Same address + same name ≠ same body — and the ledger keys on address <sub>L10264</sub>
- **§3-C.** — `make: *** [...] Error N` is a summary, never a diagnosis <sub>L10280</sub>
- **§3-D.** — "Cheap fuel" that was never probed: 0 of 31 templatable <sub>L10290</sub>
- **§150** — A register ROTATION across symmetric blocks is VARIABLE-IDENTITY evidence, not an allocator tie (P30 S43, `func_8017C6F4`, 947 ins ×4) <sub>L10309</sub>
- **§3-The** — fix <sub>L10316</sub>
- **§3-The** — method that found it (this is the transferable part) <sub>L10326</sub>
- **§3-Two** — corrections to the record <sub>L10342</sub>
- **Diagnostic** — order (adopt this) <sub>L10353</sub>
- **§151** — THE GHOST WEDGE: when a load-before-store transposition is unreachable by ANY statement order (P30 S43, `func_8017EF68`, 969 ins) <sub>L10364</sub>
- **§3-The** — mechanism (read from cc1's own `-dR` trace, not inferred) <sub>L10369</sub>
- **§3-The** — lever — a zero-emission insn that absorbs the blocked tick <sub>L10384</sub>
- **§3-The** — two fallouts, and how to close them (both measured, in order) <sub>L10392</sub>
- **When** — to reach for it <sub>L10404</sub>
- **§152** — BYTE SIZE is the family key that name- and h_seq-grouping both miss (P30 S43, the 0xECC family: 1 crack → 12 overlays → 11,364 ins) <sub>L10415</sub>
- **§3-The** — finding <sub>L10420</sub>
- **§3-The** — key <sub>L10429</sub>
- **§3-Two** — cautions that must travel with this technique <sub>L10440</sub>
- **§3-The** — companion defect (open) <sub>L10451</sub>
- **§153** — THE ADDRESS-REMATERIALISATION LAUNDER: a third zero-emission asm lever (P30 S43, `func_8018D98C`, 710 ins) <sub>L10463</sub>
- **Symptom** — Symptom <sub>L10471</sub>
- **Mechanism** — (gcc source + RTL dumps, not inferred) <sub>L10476</sub>
- **What** — does NOT work (14 byte-measured probes) <sub>L10483</sub>
- **§3-The** — cure — a fresh launder per site, each in its own block <sub>L10489</sub>
- **Companion** — levers from the same function <sub>L10499</sub>
- **§154** — Reading a disc payload: the module-id word, static base derivation, and "type 1 = uncompressed overlay" (P30 S44) <sub>L10519</sub>
- **§3-A.** — Payload word0 is a global MODULE ID; code starts after the header <sub>L10524</sub>
- **§3-B.** — Two static base-derivation methods that must AGREE (use both) <sub>L10533</sub>
- **§3-C.** — PAC type 1 = the same payload class as type 4, just NOT compressed <sub>L10545</sub>
- **§155** — hi/lo literal scanning MUST track base registers (S45) <sub>L10555</sub>
- **§155a** — the same failure class, one level up: SHAPE-blind table scanning (S45 p5) <sub>L10564</sub>
- **§155b** — check the TYPE your oracle returns before comparing against it (S45 p5) <sub>L10584</sub>
- **§155c** — the ZERO-REFERENCE trap: gcc splits a global-array address across the `lui` and the LOAD (S46) <sub>L10607</sub>
- **§156** — an ORPHANED reconcile poisons the fleet: `dedup_propagate`'s kept edit (S45 p6/p7) <sub>L10637</sub>
- **§157** — the cheap-tier size cliff, measured (S45 p6) <sub>L10684</sub>
- **§158** — The RANGE-EXTENDER: a fourth zero-emission asm lever completes the allocno toolkit (P30 S46 tier-3, `func_8017CE58`, 733 ins) <sub>L10709</sub>
- **Symptom** — Symptom <sub>L10718</sub>
- **§3-Why** — the fork is chained (gcc source, validated insn-by-insn against -dS/-dR dumps) <sub>L10724</sub>
- **§3-The** — method (dump-arithmetic first, then place — no probing) <sub>L10737</sub>
- **Bonus** — facts worth keeping <sub>L10754</sub>
- **§156** — THE PREFERENCE-DONOR MERGE: cross-region variable reuse is what fills a0-a3, and a call-arg use in ONE region steers the fill in ALL of them (P30 S46 tier-3, `func_80186E24`, 611 ins: 236-off "S11 regalloc-order" → MATCH, zero new pins) <sub>L10769</sub>
- **§159** — THE DECLARATION AXIS: conform to byte-truth, and make every guard state its COVERAGE (P30 S47; ~10,930 sites across 8 axes, fleet byte-identical) <sub>L10825</sub>
- **§160** — THE REACH-15 WAVE HARVEST: an align-1 block move, and the instrument that called it a wall (P30 S47) <sub>L10890</sub>
- **§161** — THE RETRY-WAVE HARVEST: a jump table indexed from zero, and two allocator traps (P30 S47) <sub>L10966</sub>
- **§162** — S48 WAVE-1 HARVEST (P30, 2026-08-11): the reach-ordered sibling campaign's first 12 targets <sub>L11011</sub>
- **§162a** — SHARPENS *(sharpens §161a, §131, §8a-pad, §129a)* <sub>L11038</sub>
- **§162b** — SHARPENS *(sharpens §48-A3, §156, §150, §76)* <sub>L11067</sub>
- **§162d** — SHARPENS *(sharpens §31, §21, §30, §55a)* <sub>L11096</sub>
- **§162e** — NEW <sub>L11138</sub>
- **§162** — THE LICM PAIR: what makes an address a movable AT ALL, and why the preheader order is the body order (P30 S47, `ov_MAIN_012`) <sub>L11140</sub>
- **§162f** — SHARPENS *(sharpens §42d, §41d, §73, §10)* <sub>L11206</sub>
- **§162g** — NEW <sub>L11261</sub>
- **§162** — CROSS-JUMP DIRECTION: the surviving copy is always the LATER one, so a BACKWARD `j` into a sibling arm is a source `goto` (P30 S48) <sub>L11263</sub>
- **§162h** — SHARPENS *(sharpens §88, §88a, §50-B, §8)* <sub>L11297</sub>
- **§162** — The cross-jump "CALL veto" is a COUNT law, not a CALL law (BOUNDS §88a; P30 S48, `func_80189540`) <sub>L11299</sub>
- **§162i** — SHARPENS *(sharpens §135, §21, §42, §32)* <sub>L11365</sub>
- **§162j** — SHARPENS *(sharpens §25, §136d-1, §48-B, §46-L2)* <sub>L11390</sub>
- **§162k** — SHARPENS *(sharpens §1-I2, §12, §160d, §21)* <sub>L11419</sub>
- **§162l** — SHARPENS *(sharpens §48-B, §48-C1, §20, §21)* <sub>L11482</sub>
- **§162m** — SHARPENS *(sharpens §36, §158, §148, §153)* <sub>L11537</sub>
- **§158a** — THE FIFTH LEVER IS NOT AN ASM: `do { } while (0)` is a REGION ref-multiplier you MINT (P30 S48, `func_8017CBC8`, ov_MAIN_012 / jr_801789AC, 188 ins → MATCH) <sub>L11539</sub>
- **§3-The** — law <sub>L11546</sub>
- **Size** — it before you write it (§158 step 1-2, applied) <sub>L11557</sub>
- **§3-The** — wrap BOUNDARY is the dial — and it is indiscriminate <sub>L11578</sub>
- **§3-Not** — a pure dial <sub>L11584</sub>
- **DIAGNOSTIC** — TELL — two faces, one law <sub>L11588</sub>
- **§162n** — NEW <sub>L11610</sub>
- **§162o** — SHARPENS *(sharpens §158, §136-1, §136-6, §79)* <sub>L11643</sub>
- **§162p** — SHARPENS *(sharpens §48-B, §46-L2, §156, §136d-1)* <sub>L11702</sub>
- **§162q** — SHARPENS *(sharpens §30, §30a, §135-2, §136-13)* <sub>L11719</sub>
- **§163** — S48 WAVES 2-3 HARVEST (P30, 2026-08-11/12): the five that were byte-probed and are actionable <sub>L11757</sub>
- **§163z** — THE UNVETTED REMAINDER (do not cite as law; each needs a dedupe pass) <sub>L11825</sub>
- **§164** — S48 §163z SKEPTIC PASS (P30, 2026-08-12): 190 claims vetted, 82 banked <sub>L11845</sub>
- **§16Xy** — SHARPENS *(sharpens §136d-3, §37 /s-DEP LATTICE, §135-2, §136-13, §162q)* <sub>L12297</sub>
- **§3-The** — `/s` drop clause is in ALL THREE dependence predicates, so the FIXED-ADDRESS STORE is what floats (P30 S48, `func_8017CA18`, ov_MAIN_012) <sub>L12299</sub>
- **§164z** — REFUTED CLAIMS: do NOT re-derive these <sub>L13620</sub>
- **§165** — S48 WAVE-4 HARVEST (P30, 2026-08-12): banked the same day the wave landed <sub>L13686</sub>
- **§16Z** — SHARPENS *(sharpens §37 "the /s-DEP LATTICE", §136-13, §136-14, §16Xy, §162q, `gcc-2.7.2-map/sched.md` §64)* <sub>L14337</sub>
- **§3-The** — ADDRESS-CLASS TABLE: which load/store pairs even REACH the `/s` clause (P30 S48 wave 4, `func_80185B44`, ov_SC03_014) <sub>L14339</sub>
- **§165z** — REFUTED THIS WAVE: do NOT re-derive <sub>L14855</sub>
- **§166** — THE DESTINATION-TU ORACLE (P30 S48): the seven-attempt bug that was never codegen <sub>L14899</sub>
- **§167** — S48 WAVE-5/6 HARVEST (P30, 2026-08-12): the saturation point <sub>L14955</sub>
- **§167z** — REFUTED IN WAVES 5/6: do NOT re-derive <sub>L16151</sub>
- **§168** — THE COUSIN TIER (P30 S49, 2026-08-12): h_seq's exact-hash brittleness, measured — and the similarity map above it <sub>L16208</sub>
- **§169** — THE MICRO-ADAPT LANE (P30 S49): edit a proven body, don't crack a new one <sub>L16260</sub>
- **§170** — THE A-PROP WORD-DIFF CARD (P30 S49): the lane that had no owner <sub>L16307</sub>
- **§171** — THE STALE SEED SYMBOL (P30 S50, 2026-08-13): why §170's 91%→57% was never codegen <sub>L16351</sub>