Files
BFM-decomp/docs/cookbook-index.md
T
Drew T 3e8138819a docs(cookbook): §431 — splitting a 27k-line TU at its original boundaries
Where to split: the jtbl spans (tables pack tight within a TU, separated across TUs), and
that is also the MINIMUM — a TU with no switch emits no table and is invisible, so what
you recover is a lower bound on the original structure, not the structure.

What crosses: ask the compiler. 2,318 externs is the scary number and the wrong one; only
57 of 1,247 declared names cross a boundary, 19 of them typedefs with one definition each
and zero shape conflicts. Fix TYPES first — a missing typedef cascades into dozens of
parse errors that all evaporate at once.

Plus the general defect it exposed (a typedef stripper must read the destination's
includes) and the operational rule it cost twice (gate_main reverts src/*.c first, so
commit alignment edits before gating).
2026-09-02 13:37:11 -06:00

3907 lines
518 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# Cookbook index — find the entry by the SYMPTOM you are looking at
> **Generated by `tools/cookbook_index.py` — do not hand-edit** (R33). Regenerate after adding a cookbook section.
>
> `docs/matching-cookbook.md` is ~716 KB / 1099 sections. Grepping it blind is how three P30 wave-1 agents each "discovered" an idiom that was already written down. **Start here, then read the section.** A section appears under every symptom it addresses.
**How to use:** name what you SEE in the diff (a stolen delay slot, an extra `la`, a swapped register pair, a `conflicting types` error), find that symptom below, read those sections first. If nothing fits, THEN grind — and add a section when you win.
## Start here — the symptoms that come up most, with the section that fixes them
> Hand-curated from what agents actually hit and, in several cases, RE-DERIVED because keyword matching alone did not surface the entry (P30 wave-2 feedback). If your symptom is here, read the named section before anything else.
- **wrong branch sense / arms swapped / `beq` where the target has `bne` (match_one prints this class as **BRANCH-POLARITY**)** → **§3-T4** (invert the source condition) + **§32**.2; for a trailing `return 0` vs an early return see the shared-ret0 note (cookbook L1344)
- **`conflicting types` on YOUR OWN function's definition, where the fleet canon is `(void)`** → **§73** (the PARAMS axis) + **§42** — keep the `(void)` signature and read the incoming arg via `register s32 a0v __asm__("$4")`; §42 is otherwise indexed only under regalloc
- **a shared global declared at a conflicting type (u8 vs s32, signedness) blocking your draft** → **§37** asm-label alias `extern T X __asm__("D_x")` — beats `*(T*)&X`, whose address-of perturbs regalloc. Works for FUNCTION definitions too (P30 wave 2)
- **target reuses ONE address register across two different offsets of the same global** → **§20** (the pointer-var-to-the-global bullet, cookbook L1907-1918) — take `T *p = &D_x;` and index off `p`, never the bare symbol twice
- **an extra `la` / the address hoisted into a callee-saved register across calls** → **§20** + `gcc-2.7.2-map/cse_expr.md` §H — `*(T*)&sym` force_regs the address; the asm-label alias (§37) keeps the direct `%lo` mem form
- **`andi $x,0xFF` folded away in your output but present in the target** → **§1/I2** + **§12** name the family; if the prescribed `& 0xff` at the use folds, hold the masked byte in a **u16** local so only a QI->HI extend survives (P30 wave 2, byte-tested)
- **`slti` where the target has `sltiu` (or vice versa)** → **§35** — a separate SIGNED int copy of an unsigned load keeps `slti`; chained bounds get range-folded, so write each bound as its own `if`/`goto` (**§21**)
- **you are about to hand-derive a body that some overlay already matched** → **§71** — grep the callees/globals for an already-matched SIBLING first; in wave 2 this alone produced iteration-1 MATCHes on 4 of 19 targets
- **gcc stole an instruction into a branch delay slot that the target leaves as `nop`** → **§5a** + the zero-byte `__asm__("")` fence (**§34** toolkit) — `reorg.c stop_search_p` halts the eager filler on an asm insn
- **`void` vs `s32` return — is promoting it byte-neutral?** → **NO, not always: §41d** (byte-proven; a `void` body with no `return` gains an instruction). P30 adds a second mechanism: an `s32` return keeps `$v0` live-out and blocks dbr from filling a loop-back delay slot
- **`match_one` says **SIZE-MISMATCH/short** and the target has a frame-pointer prologue (`addu $fp,$sp,$zero` / `21F0A003`)** → **The target is -O0.** Pass `--o0` to `match_one`/`rtu_match` — nothing else will ever match (§116: opt level is a property of the FILE). Known -O0 regions: boot, `ov_SC01_077_o0*`, the whale `_o0b`, and 0x8013B568..0x8013C98C — a target outside all four still needs checking
- **same instruction multiset, one contiguous window, loads/registers ROTATED inside it** → pure sched1 statement-order (`gcc-2.7.2-map/sched.md` §S1/§S4). **Cheapest lever: brute-force it** — N independent statements, script all N! orders through `match_one` (24 runs ≈ 2 min) instead of reasoning about `rank_for_schedule`
- **a two-constant `if/else` or `?:` result lands in **$v1** where the target reuses the condition's **$v0**** → **§76** — fold the condition into a NAMED local and overwrite that SAME variable with the two constants (an s16 temp, a fresh temp, an inner scope, and both ternary polarities all stay $v1; only reusing one `s32` local coalesces onto $v0). §76 reads as behemoth-only; it is not
- **a load HOISTED above a store (match_one may call it a WIDTH class)** → usually **§76 regalloc**, not a width bug: a missing WAR dependency lets sched2 hoist it. Same fix — one variable for the compare temp and the result
- **`ori $v0,0xffd8` in yours vs `addiu $v0,-0x28` in the target** → a NEGATIVE constant stored into an **unsigned** narrow local materialises via zero-extended `ori`; make the local **signed** to get `addiu`. It does NOT cost you the `lhu` on readback — gcc-2.7.2 emits `lhu` for any plain HImode load feeding an `sh` (P30 wave 4, byte-tested)
- **LENGTH-DRIFT −1 and the missing instruction is a reg-to-reg COPY in a `jal` delay slot** → a narrow **prototyped** param (plain ANSI `s16 arg3`) — §43 is indexed as the K&R-definition lever, but the ANSI form is the fix as often
- **your narrow load lost its load-delay `nop` right after an inline block move** → an `lwl/lwr`+`swl/swr` pair is a delay-slot **SPONGE** for the following load — the inverse of the §5a/§34 fence case. Align-1 4×u8 struct assign emits the inline form (§38 covers only the -O0 memcpy-call form)
- **your `e = param_1` copy VANISHED (target addresses every field off a copy at a join block)** → cse.c `make_regs_eqv` keeps a param copy only when the new pseudo's live range escapes the cse block AND outlives the param's last mention — reach that by REUSING the same variable in a later block. Copy-in-the-arms gets hoisted into the delay slot; copy-assigned-in-an-arm goes global allocno → callee-saved + 2 prologue insns
- **⚠️ the `.run/ghidra_c/<fn>.c` seed looks like a DIFFERENT function entirely** → it may be — overlays share VAs, so a seed can be decompiled from another overlay mapped at the same address. Trust the target `.s`, not the seed (P30 wave 4)
## By symptom
### delay slots & branches (67)
- **§3-T4** — Branch polarity: invert the source condition to flip gcc's chosen branch <sub>L90</sub>
- **§5a** — Cross-jump tail-merge — gcc collapses two byte-identical blocks the original kept separate (FIX FOUND) <sub>L211</sub>
- **§3-D.** — THE CROSS-JUMP RATCHET (the sharpest new trap — `func_80131340` L-C) <sub>L3542</sub>
- **§3-C.** — Inner-block declaration does NOT delay slot allocation — BYTE-REFUTED <sub>L10102</sub>
- **§162** — CROSS-JUMP DIRECTION: the surviving copy is always the LATER one, so a BACKWARD `j` into a sibling arm is a source `goto` (P30 S48) <sub>L11300</sub>
- **§162** — The cross-jump "CALL veto" is a COUNT law, not a CALL law (BOUNDS §88a; P30 S48, `func_80189540`) <sub>L11336</sub>
- **§177** — 🔴 THE EPILOGUE RETURN-DELAY SLOT IS DECIDED BY YOUR SAVED-REGISTER SET, NOT BY SCHEDULING <sub>L17223</sub>
- **§176-A** — "SCHEDULE / DELAY-SLOT / LENGTH-DRIFT ±1" ⇒ check STATEMENT ORDER around the call first <sub>L17680</sub>
- **§186** — CROSS-JUMPING RUNS **AFTER** SCHEDULING, SO NO C-LEVEL BARRIER CAN STEER IT <sub>L18133</sub>
- **§194-H** — §164-29's WAR fence runs again at SCHED2 ON HARD REGISTERS: an in-place `v &= K` before a branch fences the store that reads v, and when TWO independent stores compete for the one delay slot the fence picks the winner at ZERO length drift (a WIDTH/sh!=sw swap, not a nop). Corrects §167-42's reconstruction (pseudo arm → hard-reg arm) and supplies its first re-runnable A/B. <sub>L19352</sub>
- **§194-M** — A STORE in a CONDITIONAL branch's delay slot proves its C statement DOMINATES the branch — reorg can never pull a store out of either thread (gcc-2.7.2, -mips1) <sub>L19611</sub>
- **§195-D** — §195 — `masked_diff.mask_for` returns 0 for EVERY `j`/`jal` word, so an internal `j` destination is invisible to match_one, the permuter scorer AND every similarity tier: a control-flow semantic error (which calls execute) surfaces as a 1-instruction residual mislabelled `DELAY-SLOT / profile=schedule`, or as an outright false MATCH <sub>L19925</sub>
- **§195-E** — A 0/1 materialised at a JOIN immediately before the controlling `beqz`/`bnez` proves the source NAMED the condition — a truth expression in an `if`'s controlling position reaches `do_jump`, which has no value path <sub>L19993</sub>
- **§195-F** — fold-const.c:4825 canonicalises a `?:` whose THEN arm is zero (or constant against a non-constant ELSE) by inverting the condition and swapping the arms — so a ternary's written arm order is byte-inert there, and `c ? 0 : X` is unspellable: it always compiles as `!c ? X : 0` <sub>L20051</sub>
- **§195-G** — §NEW — TWO ARMS CALLING THE SAME CALLEE MERGE INTO ONE `jal` UNLESS EACH ARM'S OWN CODE CONSUMES THE RESULT: the C dial that keeps two call sites apart is WHERE the consumer test lives, and the branch SENSE you spell it with is byte-inert (jump.c:1737 canonicalises it) <sub>L20103</sub>
- **§195-J** — GTE / PsyQ op CALL-vs-INLINE is a PER-SITE SOURCE FACT, not a TU style — both forms coexist in one TU (measured in 2 TUs), and the tell is the target's own opcodes (`lwc2`/`sqr`/`swc2` vs `jal`), not the sibling. Costs -8 ins on func_8018505C. Corollary: the game's inline `sqr` macro emits TWO hazard nops, the SDK's `Square0` body emits ONE — so the inline form is provably not `Square0` inlined (a second instance of §187's SDK-vs-game GTE nop divergence). <sub>L20263</sub>
- **§195-N** — In a call-bearing chain of N≥2 `if (f(...)) return 1;` tests closed by `return 0;`, the LAST test must stay in STATEMENT form — the value form (`return f() != 0;` / `? 1 : 0` / `!!f()`) costs +1 `j` and empties the other N−1 delay slots. The cause is REORG block placement, not jump.c's `delete_jump`. <sub>L20460</sub>
- **§197-B** — A REPEATED COMPARE OF ONE VALUE AGAINST ONE CONSTANT IS DELETED BY cse's `qty_comparison_code` CHANNEL (the non-EQ complement of §165-03) — and a front-end-opaque mask on EITHER compare is a pure-C dial that keeps the target's second branch <sub>L20660</sub>
- **§199-F** — §164-36b — THE TARGET-HEAD FENCE IS A DELAY-SLOT THREAD SELECTOR, AND IT ONLY FIRES WHEN `mostly_true_jump > 0` (amendment to §164-36; its "−1 instruction" tell is falsified) <sub>L21020</sub>
- **§199-G** — At TWO case nodes the switch-vs-if oracle is not blind — but the tell is ALL tests positive + a trailing `j default`, NOT the first test's polarity <sub>L21074</sub>
- **§201-C** — §X — A CALL'S OWN DELAY SLOT AND THE UPSTREAM CONDITIONAL BRANCH'S SLOT COMPETE FOR ONE INSN (the call's argument copy), AND ONE STATEMENT'S POSITION RELATIVE TO THE CALL DECIDES BOTH — the residual is visible at the BRANCH, not at the call <sub>L21311</sub>
- **§204-A** — A COMPARE THAT APPEARS BOTH IN A BRANCH'S DELAY SLOT AND AGAIN ON THE FALL-THROUGH IS A JOIN WITH TWO INCOMING EDGES: THE TWO GUARDS ARE SEQUENTIAL `if`s, NEVER `if/else if` <sub>L21607</sub>
- **§211** — HOIST THE LOOP INIT ABOVE THE DOMINATING GUARD: it fills the guard's delay slot AND flips the counter/pointer register pair (P31 S58) <sub>L22415</sub>
- **§221** — A CONSTANT SHARED BY TWO STORES DIES AT THE CALL WHOSE DELAY SLOT REFILLS ITS REGISTER **(single observation — not yet cross-confirmed)** (P31 S58) <sub>L22819</sub>
- **§223** — READING A `jal` DELAY SLOT: the value in it was produced BEFORE the call, so it is NEVER that call's return (P31 S58) <sub>L22877</sub>
- **§224** — CROSS-JUMP: WRITE THE DUPLICATE, AND READ A SHARED DELAY SLOT AS THE MERGE SIGNATURE (P31 S58) <sub>L22939</sub>
- **§232** — WHEN THE `jr` DELAY SLOT'S STORE STORES THE RETURN VALUE, TIE THEM WITH ONE PSEUDO **(single observation — not yet cross-confirmed)** (P31 S58) <sub>L23221</sub>
- **§243** — SPELL THE CSE BARRIER AS A REASSIGNED POINTER; AND THE `nop`-AFTER-EVERY-`lh` SIGNATURE (P31 S58b) <sub>L23721</sub>
- **§247** — TWO BRANCHES TO **ONE** LABEL MEANS THE SOURCE CONDITION IS NEGATED (P31 S58b) <sub>L23873</sub>
- **§224** — addendum (P31 S58b) — CROSS-JUMP MERGES *CALLS*, AND THE DELAY SLOT IS THE DISCRIMINATOR <sub>L24560</sub>
- **§263** — A STOLEN DELAY SLOT WHOSE INSTRUCTION IS AN ARG-REGISTER COPY IS AN ARITY ERROR, NOT A SCHEDULE (P31 S59, byte-proven) <sub>L24927</sub>
- **ADD-4** — → §225-3/-4 addendum — THE MIRROR ROW: VALUE-RETURN IN THE *TAKEN* ARM + TRAILING BARE `return 0` <sub>L25159</sub>
- **ADD-5** — → §1/I1 addendum — THE INVERTED RANGE TEST: `(u32)(x-lo) >= N` WITH THE ZERO-ARM AS THE TRAILING `else` <sub>L25173</sub>
- **ADD-5** — → §267-ADD-6 / §172b-1 addendum — THE SIGN-TEST FACE: `(s16)v < 0` IS `sll 16` + `bgez` ON THE SHIFTED COPY, RAW STAYS LIVE — AND THE HALFWORD-ABS SHAPE NEEDS NO RITUAL <sub>L25411</sub>
- **ADDENDUM** — to §224 — CROSS-JUMP: THE DUPLICATE CAN BE A PLAIN STORE, NOT ONLY A CALL <sub>L26004</sub>
- **ADDENDUM** — to §172a — RE-READING MEMORY (NOT NAMING A TEMP) IS WHAT KEEPS AN INCREMENT'S DELAY-SLOT FILL ALIVE <sub>L26304</sub>
- **ADDENDUM** — to §225 / §256 — A GOTO TO A SHARED SET-POINT PREVENTS IF-CONVERSION FROM COLLAPSING A LATER BRANCH TEST <sub>L26335</sub>
- **§277** — RETURN-TAIL C SPELLING PICKS THE DELAY-SLOT-FILL vs TRAILING-MOVE TOPOLOGY, AND A NARROWER SECOND VARIABLE KEEPS TWO PSEUDOS INSTEAD OF ONE (P31 S60; `func_801846F0` ov_SC03_104, `func_801A44C4` md_SC07_004, both byte-proven) <sub>L26561</sub>
- **ADDENDUM** — to §22 (`volatile`-qualified-global reload lever, cookbook ~L1922) — for a NON-constant, same-address double RMW, a plain memory clobber beats `volatile`, and `volatile` actively breaks a delay-slot fill <sub>L27226</sub>
- **ADDENDUM** — to §220 — REFERENCING THE RAW PARAMETER (NO NAMED COPY, NOT EVEN A PIN) LETS THE CALLEE-SAVED SPILL LAND IN THE FIRST CALL'S OWN DELAY SLOT <sub>L27480</sub>
- **ADDENDUM** — to §252 — a `>=0`/`<0` split on an unconditionally-decremented value needs the POSTFIX operator INSIDE the branch condition, not a prior statement <sub>L27538</sub>
- **ADDENDUM** — to §20's cross-jump EXPLOIT bullet (func_8017E360, ov_SC05_007 — wave dg) <sub>L27832</sub>
- **ADDENDUM** — §NNN — sharpens §55a / §164-37 / §165-28 (switch-vs-tree cluster): A SHAPE THAT LOOKS LIKE A SWITCH DISPATCH CAN BE PLAIN NESTED `if`s WHOSE SHARED BODY WAS TRIPLICATED BY THE SOURCE AND THEN CROSS-JUMP-MERGED BACK DOWN <sub>L28223</sub>
- **§285** — PRE-INITIALIZING A VARIABLE WITH A SHARED CONSTANT BEFORE A BRANCH MAKES BOTH ARMS OF THE FOLLOWING if/else DESTRUCTIVELY REUSE THE SAME DESTINATION REGISTER FOR THEIR BITWISE RESULT (byte-proven; `func_801811F0`, ov_SC03_102, independently rediscovered across waves di/dj) (P31 S60; waves #, byte-proven) <sub>L29078</sub>
- **§286** — FOLD A STATEMENT'S SIDE EFFECT INTO A COMMA-EXPRESSION IN AN ARGUMENT POSITION TO PLACE ITS RTL RELATIVE TO A CALL'S OWN DELAY SLOT (P31 S60/dj; `func_80180A88`, ov_SC06_010, byte-proven 411/411) (P31 S60; waves #, byte-proven) <sub>L29082</sub>
- **§291** — THE DELAY-SLOT FALSE-VALUE: A CONDITIONAL BRANCH'S ZERO ARM MUST BE A FALL-THROUGH-ADJACENT BLOCK ENDING IN AN EXPLICIT JUMP, OR REORG CANNOT MATERIALIZE IT INSIDE THE BRANCH'S OWN DELAY SLOT (P31 S60; waves #, byte-proven) <sub>L29102</sub>
- **ADDENDUM** — to §253 — SECOND byte-proven card (upgrade from single-observation), and the placement face: postfix-in-condition parks the RMW store in the branch delay slot <sub>L29336</sub>
- **§306** — A HAZARD `nop` IN FRONT OF A DIV-RESULT STORE IS A STATEMENT-ORDER DEFECT: THE INDEPENDENT TRAILING STATEMENT MUST BE WRITTEN *BEFORE* THE DIVISION-CONSUMING ONE (P31 S62 T4; byte-proven func_8017E7D0) <sub>L29874</sub>
- **§308** — A NAIVE FINAL `goto` DELETES THE TARGET'S `j`+`nop`: SPELL THAT EDGE AS A TAUTOLOGICAL `if` SO cse FOLDS IT TO AN UNCONDITIONAL JUMP *AFTER* jump1's WINDOW HAS CLOSED (P31 S63 t5e-t5i; byte-proven func_80180808) <sub>L29983</sub>
- **§308a** — A TWO-INSTRUCTION ARM STUB LAID *BEFORE* THE OTHER ARM AND REACHED ONLY BY A TRAILING `j` SURVIVES ONLY BEHIND A SHORT-CIRCUIT `&&` GUARD PLUS A SEPARATE RE-TEST; EVERY PLAIN if/else-if, GOTO-LADDER, NESTED-INVERTED-if AND 1-/2-NODE switch LETS jump1 INLINE IT (−2 ins) (P31 S63 t5e-t5i; byte-proven func_80180808) <sub>L30012</sub>
- **§309** — A FRAME-ADDRESS EQUIVALENCE RIDES *THROUGH* A SKIPPABLE CONDITIONAL: POST-`if` STORES FOLD ONTO `$sp` UNLESS THE `if` SURVIVES jump1 AS A BARRIER-PRECEDED DIAMOND (P31 S63 t5e-t5i; byte-proven func_801812AC) <sub>L30046</sub>
- **§311** — A JOIN-BLOCK STORE CAN SWALLOW AN ARM'S LOAD-DELAY `nop`: WHEN ONE ARM'S VALUE COMES FROM A LOAD, DUPLICATE THE STORE INTO BOTH ARMS (P31 S64 t5j-t5m; byte-proven func_8017D7E0) <sub>L30117</sub>
- **§314** — AN IF/ELSE-IF ABS-RANGE CHECK'S C SPELLING IS INERT: FOUR STRUCTURALLY DIFFERENT REWRITES ALL COMPILE BYTE-IDENTICAL, AND NONE REACHES A TARGET THAT SINKS THE NEGATIVE ARM INTO AN OUT-OF-LINE BLOCK (P31 S65; UNPROVEN, gate-refused draft func_80181720) <sub>L30241</sub>
- **Addendum** — A §5a BARRIER SITS IN REORG'S FILL WINDOW TOO, SO ITS SIDE OF THE INNER `goto` IS CHOSEN P (func_80181D08) <sub>L30489</sub>
- **§NNN** — REFUTED: A `sw %lo(SYM)($at)` IN A JUMP'S DELAY SLOT WITH ITS `lui $at` STRANDED ABOVE THE JUMP IS **ASSEMBLER** MACRO-EXPANSION, NOT A cse SPLIT — OUR PIPELINE CANNOT EMIT IT FROM ANY C, AND THE +1 IS A `maspsx` GAP (P31 S66 round2, `func_8005DBD8`, byte-probed) <sub>L30591</sub>
- **Addendum** — REGALLOC-PERM store in a cross-jump shared tail defeats §137's barrier (func_8017EDE8) <sub>L30630</sub>
- **Addendum** — LENGTH-DRIFT nop clears when offset math precedes the symbol launder (func_80039B20) <sub>L30634</sub>
- **Addendum** — Return-0 statement order: extra j+move vs delay-slot fusion (func_8018BB50) <sub>L30721</sub>
- **§331** — OPEN GAP: NO LEVER ELIMINATES AN *UNWANTED DUPLICATE* COPY AT A BRANCH-TARGET BLOCK HEAD (P31 S67; main/func_80013154, closeness 12, NOT solved) <sub>L31059</sub>
- **§332** — THE maspsx `la`-IN-A-DELAY-SLOT GAP: gcc EMITS A SYMBOLIC ADDRESS LOAD AS ONE ATOMIC length-2 INSN, SO IT CAN NEVER FILL A JUMP DELAY SLOT — 6 FUNCTIONS FLEET-WIDE, NONE BANKABLE FROM C (P31 S67; byte-traced main/func_80062144, func_8005DBD8) <sub>L31071</sub>
- **§336** — THE §5a CROSS-JUMP BARRIER GOES AT THE *BOTTOM* OF THE TWIN, NOT THE TOP: `find_cross_jump` WALKS BACKWARD FROM THE CONVERGING JUMP (P31 S67; byte-proven ov_SC05_001/func_80183C9C) <sub>L31149</sub>
- **§339** — A 2-CASE SWITCH OMITS THE LOW-BOUND RANGE TEST, SO THE PRESENCE OF `slti/bnez` BETWEEN THE `beq`s IS A **COUNT TELL** FOR A THIRD CASE NODE (P31 S67; byte-proven ov_SC02_005/func_80190538, 197 ins) <sub>L31181</sub>
- **§346** — `c ? X : -X` TAKES expand_expr's COND_EXPR **SINGLETON** PATH (copy, then negate IN PLACE) — AN if/else STATEMENT GIVES THE TWO-ARM FORM (P31 S67; byte-proven ov_SC03_102/func_80180C38, closed the last instruction) <sub>L31322</sub>
- **§370** — ★★ — A **HARD BOUND** FROM sched.c, AND THE reorg SLOT-STEAL DIAGNOSTIC (P31 S68; main/func_8001BC6C, 69 ins, NOT closed — 33 → 28 over ~45 measured compiles) <sub>L31838</sub>
- **§396g** — ★★ — A GUARD LADDER'S RUNGS MUST STAY SYMMETRIC OR `reorg.c` LOSES ITS BRANCH REDIRECT (P31 S69; byte-proven ov_SC03_028/func_80184C90, 92 ins) <sub>L32818</sub>
- **§428** — ★★★ — A ZERO-BYTE CROSS-JUMP BARRIER: ADVANCE THE POINTER INSIDE EACH SWITCH ARM (P31 S72; `main/func_80026D64`, 218 ins, MATCH in 2 compiles) <sub>L33950</sub>
- **§430** — ★★★ — A SHARED TAIL IS A LATE CROSS-JUMP MERGE, NOT A SOURCE `goto` — AND SPELLING IT AS ONE CAN INVALIDATE A LOOP (P31 S72; `main/CdReadSectorReadyCB`, 422/424 ins, verified with `cc1 -dL`) <sub>L34023</sub>
### instruction scheduling (88)
- **§3-T2** — Source statement order drives instruction scheduling <sub>L78</sub>
- **§3** — When a diff is pure scheduling → decomp-permuter (harness built, Phase 6) <sub>L107</sub>
- **§10** — Closing the regalloc/scheduling hard tail by hand (LZSS, Phase 7 session F — the full close) <sub>L854</sub>
- **§25** — The "schedule" class is mostly COALESCING (pin-crackable), not scheduling; + the gate two-stage + h_exact over-counts ×134 (Phase 21, cont.6) <sub>L2151</sub>
- **§3-The** — crack: the residual was gcc-2.7.2 COPY-COALESCING, not the instruction scheduler <sub>L2163</sub>
- **§3-The** — genuine scheduler — `rank_for_schedule` (sched.c), for when it IS scheduling <sub>L2179</sub>
- **§3-The** — genuine schedule WALLS (do NOT re-grind — stub) <sub>L2188</sub>
- **§32** — The region-a CAMERA-GIANT idiom set: struct-base hoisting + 4 sibling levers (Phase 24 T7, Fable5-cracked on `func_80129CF8` 191 ins, match_one MATCH; transferable to the 6 sibling giants) <sub>L2441</sub>
- **§34** — The `func_80138ED0` giant crack: gcc-2.7.2's **3-qty sort bug** + the **zero-byte asm allocation toolkit** + the **giv-init fence** (Phase 24 T5; Opus→close=21, Fable5→MATCH ×134) <sub>L2473</sub>
- **§35** — The region-a sibling-giant harvest: difficulty ≠ $s-reg count (it's global-array hoisting) + the banking recipe + new loop idioms (Phase 24 T7, 5 parallel Opus-Max agents) <sub>L2490</sub>
- **§3-A4** — SINK THE CONSUMER CALL INTO THE ARMS (the inverse of A1; `func_8016AB6C`, byte-proven) <sub>L3478</sub>
- **§49** — The LUID DIAL: a zero-byte SCHEDULING dial (the sched.c analogue of §47) — `func_8017A4AC` (536 ins ×134), Phase 26 session 8 <sub>L3561</sub>
- **§66d-5** — `residual_class`'s "structural ⇒ permuter CPU is waste" is WRONG for schedule permutations (measured, Phase 29 SESSION-18) <sub>L5525</sub>
- **§3-The** — attribution primitive (use this before calling anything a scheduling residual) <sub>L6091</sub>
- **§3-The** — scheduling rules (refining §135-2 and §135-4) <sub>L8946</sub>
- **Consequence** — for the family (a real scheduling decision) <sub>L10129</sub>
- **§148** — The loop.c hoisting THRESHOLD is arithmetic you can compute, and the `?:` clamp that folds to MIN_EXPR (P30 S42, `func_8017C6F4`, 947 ins) <sub>L10179</sub>
- **§3-A.** — `move_movables` hoists iff `threshold × savings × lifetime ≥ insn_count` — and you can read it <sub>L10185</sub>
- **§16Z** — SHARPENS *(sharpens §37 "the /s-DEP LATTICE", §136-13, §136-14, §16Xy, §162q, `gcc-2.7.2-map/sched.md` §64)* <sub>L14394</sub>
- **§175** — A CALLER-SAVED REGISTER PIN CAN BE A CORRECTNESS BUG, NOT JUST A SCHEDULING CHOICE (P31 wave H, 2026-08-15) <sub>L16776</sub>
- **§177** — 🔴 THE EPILOGUE RETURN-DELAY SLOT IS DECIDED BY YOUR SAVED-REGISTER SET, NOT BY SCHEDULING <sub>L17223</sub>
- **§3-B.** — A `return <const>` IS A PRIORITY-1 HARD-REG SET THE SCHEDULER PLACES FIRST (func_8001BE30, 92 ins) <sub>L17308</sub>
- **§176-A** — "SCHEDULE / DELAY-SLOT / LENGTH-DRIFT ±1" ⇒ check STATEMENT ORDER around the call first <sub>L17680</sub>
- **§176-C** — 🔴 WALL REFUTATION: a hard-register pin CANNOT schedule around a call, because of a genuine gcc-2.7.2 bug <sub>L17750</sub>
- **§186** — CROSS-JUMPING RUNS **AFTER** SCHEDULING, SO NO C-LEVEL BARRIER CAN STEER IT <sub>L18133</sub>
- **§193-C** — gcc-2.7.2 cross_jump merges the SCHEDULED common SUFFIX only — there is no prefix/head merge, so §8/§48-A1's "duplicate into both arms and cross_jump refunds it" is a TAIL-only lever <sub>L18588</sub>
- **§193-D** — A COMPILER-GENERATED ARGUMENT COPY IS A `optimize_reg_copy_1` TRIGGER: when the pointer's LAST use in a block precedes a call that takes the pointer *as a register*, sched1 hoists the implicit `move $aN,$sN` to the block top and local-alloc re-bases the WHOLE block's memory operands onto `$aN`. The only C dial is a label (the §165-24 goto-join) between the block and the call. <sub>L18622</sub>
- **§193-F** — §148-A2 — The `threshold -= 3` STAIRCASE: `move_movables` admits a COUNT of invariants, not a boolean — two identical merged constants split hoisted/not-hoisted by LIST ORDER, and `insn_count` picks the rank cutoff <sub>L18723</sub>
- **§194-A** — A zero-byte scheduling fence goes AFTER the defining statement to make that computation emit FIRST in its block — and the barrier predicate is `volatile`-or-colon-less, not the `"memory"` clobber (COMPLEMENTS §165-40; does not refute it) <sub>L18991</sub>
- **§194-D** — Declared width of a computed-value local is a sched1 dial (count-neutral) — a replication + attribution correction of §165-17, NOT a new argument-register law <sub>L19158</sub>
- **§194-H** — §164-29's WAR fence runs again at SCHED2 ON HARD REGISTERS: an in-place `v &= K` before a branch fences the store that reads v, and when TWO independent stores compete for the one delay slot the fence picks the winner at ZERO length drift (a WIDTH/sh!=sw swap, not a nop). Corrects §167-42's reconstruction (pseudo arm → hard-reg arm) and supplies its first re-runnable A/B. <sub>L19352</sub>
- **§194-K** — Blind sched1's alias oracle with a second SET of a pointer pseudo — the first zero-byte, non-volatile, dependence-CREATING lever (corrects §167-05's "volatile is the only door"; fourth consumer of reg_n_sets) <sub>L19485</sub>
- **§194-N** — §193-D's C dial is misstated: the lever is a SURVIVING CODE_LABEL (a label with a real incoming edge), not "a label between the block and the call" — a bare label, or a `goto L; L:` pair whose target is the next active insn, is deleted by jump1 (jump.c:663-669 → delete_insn → jump.c:3458-3461, and jump.c:243 for the bare case) long before sched1/local-alloc, and costs exactly zero bytes <sub>L19669</sub>
- **§195-D** — §195 — `masked_diff.mask_for` returns 0 for EVERY `j`/`jal` word, so an internal `j` destination is invisible to match_one, the permuter scorer AND every similarity tier: a control-flow semantic error (which calls execute) surfaces as a 1-instruction residual mislabelled `DELAY-SLOT / profile=schedule`, or as an outright false MATCH <sub>L19925</sub>
- **§199-A** — §189-A's asm→source inference is byte-FALSE: an interloper between a split constant's `lui`/`ori` is a SCHEDULE fact, not a source fact — and the separator is the BIRTHING BOOST, not a "priority floor" (§189-A's split-timing half survives; its "no statement order / no pin" absolute and the candidate's own forward-scheduler narrative both fall) <sub>L20759</sub>
- **§199-F** — §164-36b — THE TARGET-HEAD FENCE IS A DELAY-SLOT THREAD SELECTOR, AND IT ONLY FIRES WHEN `mostly_true_jump > 0` (amendment to §164-36; its "−1 instruction" tell is falsified) <sub>L21020</sub>
- **§205** — THE CHAINED ASSIGNMENT IS ITS OWN SCHEDULING DIAL: `*b = *a = v;` moves an argument copy that no local, no pin and no statement reorder will move (P31 S56) <sub>L22098</sub>
- **§211** — HOIST THE LOOP INIT ABOVE THE DOMINATING GUARD: it fills the guard's delay slot AND flips the counter/pointer register pair (P31 S58) <sub>L22415</sub>
- **§219** — COMPOUND `+=`, FULL ASSIGNMENT, AND AN EXPLICIT TEMP ARE THREE DIFFERENT SCHEDULES OF ONE READ-MODIFY-WRITE (P31 S58) <sub>L22752</sub>
- **§30** — addendum (P31 S58) — the `/s` grant closes a SCHEDULING residual and a REGISTER residual with one edit <sub>L23257</sub>
- **§165-40** — addendum (P31 S58) — the barrier goes at the COPY SITE, not inside the region it protects <sub>L23289</sub>
- **§239** — TWO-STATEMENT INTEGER-SPACE MATERIALISATION REORDERS `la` vs `sll`; AND THE PLUS-TREE OPERAND ORDER (P31 S58b) <sub>L23601</sub>
- **§243** — SPELL THE CSE BARRIER AS A REASSIGNED POINTER; AND THE `nop`-AFTER-EVERY-`lh` SIGNATURE (P31 S58b) <sub>L23721</sub>
- **§245** — THE CALL'S ARGUMENT LIST IS A SCHEDULING SLOT (P31 S58b) <sub>L23786</sub>
- **§211** — addendum (P31 S58b) — INIT PLACEMENT: FIVE MORE DIALS BEYOND THE GUARD HOIST <sub>L24316</sub>
- **§263** — A STOLEN DELAY SLOT WHOSE INSTRUCTION IS AN ARG-REGISTER COPY IS AN ARITY ERROR, NOT A SCHEDULE (P31 S59, byte-proven) <sub>L24927</sub>
- **ADD-8** — → §245 addendum — THE RE-TIE BARRIER PINS CALL-ARG SETUP TO SOURCE ORDER (construct 6) <sub>L25203</sub>
- **ADDENDUM** — to §244 — THE COMPILER BARRIER, NOT `volatile`, BLOCKS A STORE→LOAD HOIST THROUGH A POINTER-OFFSET FIELD <sub>L26069</sub>
- **§281** — GROUP COPY-THEN-RMW BY OPERATION KIND, NOT FIELD BY FIELD: sched1 does the interleaving, the source must not (P31 S60; wave cf, func_80180FB4, ov_SC03_111, byte-proven) <sub>L26990</sub>
- **§NNN** — A DEPENDENT COPY-THEN-RMW BLOCK MUST BE SOURCE-GROUPED BY OPERATION KIND, NOT BY FIELD, AND SCHED1 DOES THE INTERLEAVING (P31 S60; `func_80180FB4`, ov_SC03_111, byte-proven) <sub>L26991</sub>
- **§282** — gcc's OWN LOOP REVERSAL PUTS THE COUNTER INIT AFTER THE HOISTED MOVABLES — a position no hand-written down-count can reach (P31 S60; wave cf, func_80180DD8, ov_SC04_005, byte-proven) <sub>L27036</sub>
- **§NNN** — WRITE THE UP-COUNT LOOP: gcc's OWN REVERSAL PRODUCES A COUNTER-INIT INSTRUCTION THAT LANDS AFTER HOISTED MOVABLES, WHICH A HAND-WRITTEN DOWN-COUNT LOOP CANNOT REPRODUCE (P31 S60; `func_80180DD8`, ov_SC04_005, byte-proven) <sub>L27037</sub>
- **ADDENDUM** — to §195-N — a GNU statement-expression slider must sit INSIDE the conditional arm's value position, not as a post-hoc barrier, to block the store-flag transform on a ternary chain <sub>L27307</sub>
- **ADDENDUM** — §NNN — sharpens §167-13's boundary: CHAINING TWO IDENTICAL SIDE-BY-SIDE STORES INTO ONE C ASSIGNMENT STATEMENT IS A MID-BLOCK SCHEDULING-PRIORITY DIAL, NOT ONLY A STORE-ORDER SPELLING <sub>L28260</sub>
- **§284** — COMBINE CAN REASSOCIATE TWO SEQUENTIAL BITWISE-AND MASKS INTO ONE AGAINST THE PRE-MASK VALUE; AN ASM IN/OUT FENCE RIGHT AFTER THE FIRST MASK BLOCKS IT (P31, wave dd, `func_8018087C`, ov_SC04_020, byte-proven) (P31 S60; waves #, byte-proven) <sub>L29074</sub>
- **§298** — THE SHARED-TAIL POSITION DIAGNOSTIC: A FOLDED TAIL *BETWEEN* SWITCH ARMS MEANS PER-ARM DUPLICATED STATEMENTS, NOT A HOISTED POST-SWITCH STATEMENT (P31 S61; waves g0e/g0f, `func_80181B68`, ov_SC06_016, byte-proven 68/68) <sub>L29542</sub>
- **§299** — TWO INDEPENDENT EXTRACTION CHAINS EMIT CONTIGUOUSLY INSIDE ONE EXPRESSION; ONLY A STATEMENT BOUNDARY MAKES THE SCHEDULER INTERLEAVE THEM (P31 S61; wave m0a, `func_8003A404`, main, byte-proven 8/8) <sub>L29567</sub>
- **§307** — THE BRUTE-FORCE-THE-STATEMENT-ORDERS LEVER HAS A BOUND: A FAN-OUT COPY'S PRIORITY IS SCHEDULER-INTERNAL, AND NO SOURCE ORDER REACHES IT (P31 S63; byte-evidenced NEGATIVE result, main wave) <sub>L29939</sub>
- **§309** — A FRAME-ADDRESS EQUIVALENCE RIDES *THROUGH* A SKIPPABLE CONDITIONAL: POST-`if` STORES FOLD ONTO `$sp` UNLESS THE `if` SURVIVES jump1 AS A BARRIER-PRECEDED DIAMOND (P31 S63 t5e-t5i; byte-proven func_801812AC) <sub>L30046</sub>
- **§314** — AN IF/ELSE-IF ABS-RANGE CHECK'S C SPELLING IS INERT: FOUR STRUCTURALLY DIFFERENT REWRITES ALL COMPILE BYTE-IDENTICAL, AND NONE REACHES A TARGET THAT SINKS THE NEGATIVE ARM INTO AN OUT-OF-LINE BLOCK (P31 S65; UNPROVEN, gate-refused draft func_80181720) <sub>L30241</sub>
- **Addendum** — A §5a BARRIER SITS IN REORG'S FILL WINDOW TOO, SO ITS SIDE OF THE INNER `goto` IS CHOSEN P (func_80181D08) <sub>L30489</sub>
- **Addendum** — Loop sentinel wrongly hoisted out of a call-containing loop (func_801835B0) <sub>L30493</sub>
- **Addendum** — REGALLOC-PERM: one memory-clobber barrier insufficient — stack two (func_80182D1C) <sub>L30523</sub>
- **Addendum** — A plain global-RMW triplet is a fillable scheduling window too — zero drift, and the fille (func_800CB058) <sub>L30533</sub>
- **Addendum** — Shared arithmetic that CONSUMES the selected value cannot be hoisted above the `if` — narr (func_80183DA0) <sub>L30537</sub>
- **Addendum** — Truncating assign must be the lazy `||` operand, not hoisted (func_80012B58) <sub>L30560</sub>
- **Addendum** — WIDTH sh!=lhu residual: hoist a sibling field's load first (func_80182538) <sub>L30572</sub>
- **Addendum** — REGALLOC-PERM store in a cross-jump shared tail defeats §137's barrier (func_8017EDE8) <sub>L30630</sub>
- **Addendum** — Volatile zero-byte asm slider scrambles the prologue schedule (func_801814B0) <sub>L30747</sub>
- **Addendum** — §194-A addendum — the bare/colon-less fence measured NULL and only the "memory"-clobber fo (func_8017E464) <sub>L30761</sub>
- **§336** — THE §5a CROSS-JUMP BARRIER GOES AT THE *BOTTOM* OF THE TWIN, NOT THE TOP: `find_cross_jump` WALKS BACKWARD FROM THE CONVERGING JUMP (P31 S67; byte-proven ov_SC05_001/func_80183C9C) <sub>L31149</sub>
- **§340** — §194-K COROLLARY: **FLIP THE FALSE EDGE YOU CANNOT DELETE.** A "scheduler" residual can be sched.c's ALIAS ORACLE emitting a FALSE true-dependence; source order chooses its DIRECTION (P31 S67; byte-proven ov_SC03_107/func_8017CF48, 10 -> 0 in one compile, zero bytes) <sub>L31209</sub>
- **§341** — AN HImode STORE TEMP REWEIGHTS A sched2 TIE-BREAK THAT NO STATEMENT ORDER CAN REACH (P31 S67; byte-proven ov_SC03_006/func_801823B8, last 4 ins) <sub>L31243</sub>
- **§349** — RE-ASSIGN A BASE POINTER AT THE END OF THE LOOP BODY TO MAKE `n_times_set > 1` — THAT KILLS BOTH loop.c's INVARIANT HOIST **AND** THE ADDRESS GIV, REPRODUCING A REMATERIALISED `addiu $aN,$sp,K` (P31 S67; byte-proven ov_SC06_029/func_801804C8, 255 ins) <sub>L31414</sub>
- **§350** — A ZERO-BYTE RE-TIE SETS `reg_n_sets=2`, WHICH KILLS sched1's `birthing_insn_p` LAUNCH_PRIORITY BOOST — THE MECHANISM BEHIND "MY ADDS ARE GLUED TO THEIR STORES" (P31 S67; byte-proven ov_SC04_011/func_80180B24, 215 ins) <sub>L31435</sub>
- **§352** — ⚠ TWO IDENTICAL `__asm__ __volatile__("")` BARRIERS **MERGE WITH EACH OTHER** — SPELL THE SECOND ONE DIFFERENTLY (P31 S67; byte-proven resident/func_800D128C, measured closeness 105 when they merged) <sub>L31486</sub>
- **§361** — ★ — A LOOP-TAIL BYTE SIGNATURE THAT NAMES ITS SOURCE SHAPE — AND THE LAW THAT A "SCHEDULING TIE" MAY BE YOUR OWN EARLIER LEVER (P31 S68; byte-proven main/func_800241C0, fable escalation, 19 → 0 in 3 iterations) <sub>L31637</sub>
- **§370** — ★★ — A **HARD BOUND** FROM sched.c, AND THE reorg SLOT-STEAL DIAGNOSTIC (P31 S68; main/func_8001BC6C, 69 ins, NOT closed — 33 → 28 over ~45 measured compiles) <sub>L31838</sub>
- **§373** — ★★★ — THE **DEAD-RESET CSE-BREAKER**, THE PIN THAT BREAKS A sched2 ANTI-DEP, AND WHY AN `asm` CAN NEVER RAISE PRIORITY (P31 S68; byte-proven ov_SC06_010/func_8017E764, 438 ins, fable escalation closed 8 → 0) <sub>L31977</sub>
- **§3-2.** — A REGISTER PIN THAT DELETES A sched2 ANTI-DEPENDENCE <sub>L31997</sub>
- **§3-3.** — HARD FACT FOR THE SCHEDULING MAP — an `asm` ALWAYS has priority 1 <sub>L32010</sub>
- **§379** — ★★★ — **MEM_IN_STRUCT_P**: THE SAME LOAD, WRITTEN AS A STRUCT MEMBER, SCHEDULES WHERE A CAST CANNOT (P31 S69; byte-proven main/func_80021284 220 ins and main/func_8002D904 217 ins, found INDEPENDENTLY by two agents) <sub>L32164</sub>
- **§381** — THE `insn_count` HOIST THRESHOLD IS A DIAL YOU CAN READ WITH `cc1 -dL` (P31 S69; four independent uses in one wave) <sub>L32216</sub>
- **§385** — ★★★ — THE **SCHED2 PRIORITY-DONOR ASM**: closing the "hoisted-invariant vs IV-init preheader swap" class (P31 S69; byte-proven main/func_80038A58, 347 ins, fable escalation 2 → 0) <sub>L32309</sub>
- **§393** — ★★ — THE **BIRTHING BOOST**: A SINGLE-SET LOCAL IS SCHEDULED LAST; GIVE IT A SECOND SET (P31 S69; byte-proven ov_SC02_017/func_8017FCFC) <sub>L32543</sub>
- **§3-B.** — THE SCHEDULER DIALS (the dominant residual family this wave) <sub>L33108</sub>
- **§424** — ★★★ — EQUAL-PRIORITY STORES COME OUT **REVERSED**: sched1's LUID tie picks the LAST statement first (P31 S71; byte-proven `ov_SC07_006/func_801890FC`, 387 ins) <sub>L33807</sub>
- **§428** — ★★★ — A ZERO-BYTE CROSS-JUMP BARRIER: ADVANCE THE POINTER INSIDE EACH SWITCH ARM (P31 S72; `main/func_80026D64`, 218 ins, MATCH in 2 compiles) <sub>L33950</sub>
### register allocation & pins (131)
- **§10** — Closing the regalloc/scheduling hard tail by hand (LZSS, Phase 7 session F — the full close) <sub>L854</sub>
- **Residual** — A — commutative `|`/`&`/`+` result lands in the wrong source-operand register <sub>L875</sub>
- **Register-allocation** — ORDER (call-crossing $s0/$s1 swap) → FORCE it with register pins (byte-proven) <sub>L1403</sub>
- **§3-The** — LOOSE-TYPING wall is real for narrow params (Phase 16, reconfirmed) <sub>L1447</sub>
- **§3-THE** — CAP: at this tail the match_one→gate gap is the LOOSE-TYPING CALL-GRAPH wall (not cheap plumbing) <sub>L1656</sub>
- **§22** — DEF-side loose-typing recovery + grinder blacklist (Phase 21) <sub>L2024</sub>
- **§24** — The `ov_SC01_077_a.c` split-file vein: split-aware propagation, but loose-typing-gated (Phase 21) <sub>L2104</sub>
- **§25** — The "schedule" class is mostly COALESCING (pin-crackable), not scheduling; + the gate two-stage + h_exact over-counts ×134 (Phase 21, cont.6) <sub>L2151</sub>
- **§42** — The F-band ≤28 regalloc crack wave: register-pin/DENSITY levers beat the permuter (Phase 25 T7 F-band, 2026-07-10; Ultracode 9-worker wave, 4/9 banked byte-identical, 266 swept ×134) <sub>L2934</sub>
- **§43** — The K&R s16-param definition DISSOLVES the "narrow-param wall" for by-value register args (Phase 25 task A, Fable5 crack of the 369-ins giant `func_80166994` ×134, 2026-07-11) <sub>L3229</sub>
- **§45** — The flagship `func_80133CD4` crack (399 ins ×134): the merged-variable permutation-breaker + the 1-death local-alloc gate (Phase 25 task A giant escalation, Fable5 gdb-on-cc1, 2026-07-11) <sub>L3332</sub>
- **§47** — The live-length SLIDER: splitting a global.c allocno-priority TIE with one zero-byte asm (Phase 26 session 8, Fable5 Max, byte-proven on `func_8017BEBC` 952 ins ×113) <sub>L3399</sub>
- **§48** — The 12-core jr crack wave: the ALLOCNO-PRICING dials and the EBB rule (Phase 26 session 8, Ultracode, 9/12 MATCH first pass) <sub>L3439</sub>
- **§3-A.** — ALLOCNO-PRICING DIALS — move a value into the register you want, byte-neutrally <sub>L3447</sub>
- **§52** — The WALKER-FAMILY skeleton: 6 regalloc-order levers + a deeply-characterized intrinsic wall (`func_80178004`, 165 ins ×134; Phase 26, Fable5, 2026-07-15) <sub>L3947</sub>
- **§52a** — The regalloc sibling wave: new levers + two new wall classes (cheap-Opus applying §52, 2026-07-15) <sub>L3993</sub>
- **§52b** — Sibling wave 2: more de-pin levers, a third wall class, and the match_one→whole-binary gap at scale (2026-07-15) <sub>L4031</sub>
- **§66d-1** — What transfers between giants is the LOOP, not the PIN <sub>L5314</sub>
- **§70** — The giv-init base register: walk the PARAMETER, not a copy of it (Phase 29 SESSION-18, `func_801777BC`) <sub>L5653</sub>
- **§71** — Before mapping a giant, look for an already-matched SIBLING beside it (Phase 29 SESSION-18, `func_8017D960`, 3,338 ins) <sub>L5694</sub>
- **§72** — A `register __asm__` pin is a PREFERENCE, not a reservation (Phase 29 SESSION-18, `func_8017F510`) <sub>L5760</sub>
- **§74** — Auditing a pinned draft: the §72 hazard is CALLER-SAVED pins spanning a call, and only the disassembly can tell you (Phase 29 SESSION-19, `func_8017D960` b2, 5 pins) <sub>L5856</sub>
- **§76** — The allocno CLASS (local vs global) is the dominant regalloc lever, and C reaches it ONLY through declaration scope and variable reuse (Phase 29 SESSION-19, behemoth #3 `func_8017F510` 1,511 ins, 97 → MATCH, pin-free) <sub>L6062</sub>
- **§78** — A LENGTH drift can be a register grant in disguise; and `fold` never leaves a literal first in an `|` chain (Phase 29 SESSION-19, behemoth #2 `func_8017D960` 3,338 ins, 1806 → 0, pin-free) <sub>L6208</sub>
- **§76** — confirmed at scale, and a pin nuance <sub>L6285</sub>
- **§80** — A do-not-re-buy entry is scoped to its BASE, not to the function; and the pin's hidden cost is an unconditional `qty_phys_sugg` (Phase 29 SESSION-19, `func_8017BF14` 45 → 0) <sub>L6304</sub>
- **§3-The** — pin's hidden cost, with the citation <sub>L6325</sub>
- **§83** — The parameterised-repeat law, the spill-area trap, and why a per-case edit cannot move a per-case symptom (Phase 29 SESSION-20, `func_80183814` 5,122 ins, cold-ish start → 36 structural / 99.3%) <sub>L6446</sub>
- **§83c** — TRAP: a "dead local" in a prior draft may be gcc's OWN spill area <sub>L6479</sub>
- **§86** — Pinned-exemplar templatability is a PER-FAMILY property, not a per-member rate; and the §42e pin guard is now over-conservative (Phase 29 SESSION-20) <sub>L6623</sub>
- **§3-Two** — further notes worth keeping <sub>L8282</sub>
- **§137** — REGALLOC-PERM is a TWO-COMPILE ARITHMETIC PROBLEM, not a permuter job <sub>L9378</sub>
- **§3-The** — same swallow, twice more, in the integration spine <sub>L9743</sub>
- **§3-B.** — A `?:` on MEMORY operands costs ~16 bytes of invisible frame; on REGISTER operands, zero <sub>L10091</sub>
- **§3-D.** — A lone `$t8`/`$t9` in the target is RELOAD SCRATCH — reproduce the spill, don't pin the register <sub>L10107</sub>
- **§3-C.** — A zero-byte ALLOCNO-PRIORITY slider <sub>L10218</sub>
- **§150** — A register ROTATION across symmetric blocks is VARIABLE-IDENTITY evidence, not an allocator tie (P30 S43, `func_8017C6F4`, 947 ins ×4) <sub>L10346</sub>
- **§152** — BYTE SIZE is the family key that name- and h_seq-grouping both miss (P30 S43, the 0xECC family: 1 crack → 12 overlays → 11,364 ins) <sub>L10452</sub>
- **§155** — hi/lo literal scanning MUST track base registers (S45) <sub>L10592</sub>
- **§158** — The RANGE-EXTENDER: a fourth zero-emission asm lever completes the allocno toolkit (P30 S46 tier-3, `func_8017CE58`, 733 ins) <sub>L10746</sub>
- **Bonus** — facts worth keeping <sub>L10791</sub>
- **§156** — THE PREFERENCE-DONOR MERGE: cross-region variable reuse is what fills a0-a3, and a call-arg use in ONE region steers the fill in ALL of them (P30 S46 tier-3, `func_80186E24`, 611 ins: 236-off "S11 regalloc-order" → MATCH, zero new pins) <sub>L10806</sub>
- **§175** — A CALLER-SAVED REGISTER PIN CAN BE A CORRECTNESS BUG, NOT JUST A SCHEDULING CHOICE (P31 wave H, 2026-08-15) <sub>L16776</sub>
- **§176j** — STOPPING A WAVE MID-FLIGHT COSTS THE IN-FLIGHT TAIL (and how much is recoverable) <sub>L17160</sub>
- **§177** — 🔴 THE EPILOGUE RETURN-DELAY SLOT IS DECIDED BY YOUR SAVED-REGISTER SET, NOT BY SCHEDULING <sub>L17223</sub>
- **§179-A** — 🔴 A LOOP-WALKED POINTER **PARAMETER** HANDS ITS ARGUMENT REGISTER TO THE GIV (9 byte-proofs) <sub>L17377</sub>
- **§179-F** — PINNING A LOOP-WALKED POINTER IS A TOTAL OFF-SWITCH FOR STRENGTH REDUCTION <sub>L17573</sub>
- **§179-G** — 🟡 A PIN CAN **CREATE** A COMBINE `LOG_LINK` AND DELETE AN `andi` (sixth RC-5 channel, n=1) <sub>L17596</sub>
- **§176** — SEVEN LEVERS FROM THE P31 OVERNIGHT WAVES (2026-08-15): statement order, false regalloc, and the pin that fights back <sub>L17674</sub>
- **§176-B** — "REGALLOC-PERM, 1-4 instructions off" ⇒ it is usually NOT register allocation <sub>L17704</sub>
- **§176-C** — 🔴 WALL REFUTATION: a hard-register pin CANNOT schedule around a call, because of a genuine gcc-2.7.2 bug <sub>L17750</sub>
- **§3-18** — of 20 reconciled while keeping the match. The two that did not are mechanism, not effort. <sub>L18003</sub>
- **§186** — CROSS-JUMPING RUNS **AFTER** SCHEDULING, SO NO C-LEVEL BARRIER CAN STEER IT <sub>L18133</sub>
- **§186c** — WHERE A VALUE IS LOADED DECIDES WHICH ALLOCATOR OWNS IT, AND THEREFORE ITS REGISTER <sub>L18162</sub>
- **§193-B** — A NARROW CAST OF A WIDE PARAMETER COSTS ONE EXTRA INSTRUCTION WHEN ITS STATEMENT SITS AFTER AN INTERVENING `jal` — AND THE DECIDER IS `combine.c:929`'s CROSS-CALL GUARD, NOT REGISTER ALLOCATION <sub>L18550</sub>
- **§193-D** — A COMPILER-GENERATED ARGUMENT COPY IS A `optimize_reg_copy_1` TRIGGER: when the pointer's LAST use in a block precedes a call that takes the pointer *as a register*, sched1 hoists the implicit `move $aN,$sN` to the block top and local-alloc re-bases the WHOLE block's memory operands onto `$aN`. The only C dial is a label (the §165-24 goto-join) between the block and the call. <sub>L18622</sub>
- **§194-B** — A `addu $rA,$rB,$zero` copy feeding ≥2 `sh` stores is a SECOND, 16-BIT-DECLARED local — the width, not the clamp or the join liveness, is what keeps the copy (and func_80183094's pin + `"memory"` clobber are both provably inert) <sub>L19057</sub>
- **§194-C** — A CALLER-SAVED loop counter proves its live range crosses ZERO calls — so it cannot share a pseudo with any value LIVE ACROSS a call (but it may freely share one with values that merely sit between calls) <sub>L19095</sub>
- **§194-D** — Declared width of a computed-value local is a sched1 dial (count-neutral) — a replication + attribution correction of §165-17, NOT a new argument-register law <sub>L19158</sub>
- **§194-G** — Reading the integer half of a 16.16 stack aggregate: REGISTER-LIVENESS, not the C spelling, decides `sra` vs `lhu` — and the break is count-neutral <sub>L19309</sub>
- **§194-H** — §164-29's WAR fence runs again at SCHED2 ON HARD REGISTERS: an in-place `v &= K` before a branch fences the store that reads v, and when TWO independent stores compete for the one delay slot the fence picks the winner at ZERO length drift (a WIDTH/sh!=sw swap, not a nop). Corrects §167-42's reconstruction (pseudo arm → hard-reg arm) and supplies its first re-runnable A/B. <sub>L19352</sub>
- **§194-N** — §193-D's C dial is misstated: the lever is a SURVIVING CODE_LABEL (a label with a real incoming edge), not "a label between the block and the call" — a bare label, or a `goto L; L:` pair whose target is the next active insn, is deleted by jump1 (jump.c:663-669 → delete_insn → jump.c:3458-3461, and jump.c:243 for the bare case) long before sched1/local-alloc, and costs exactly zero bytes <sub>L19669</sub>
- **§195-B** — A CALL_INSN does not start a basic block in gcc-2.7.2 — so a call-crossing temp can be a LOCAL-alloc quantity (the missing precondition under §48-A2 / §52 / regalloc.md K8) <sub>L19835</sub>
- **§195-F** — fold-const.c:4825 canonicalises a `?:` whose THEN arm is zero (or constant against a non-constant ELSE) by inverting the condition and swapping the arms — so a ternary's written arm order is byte-inert there, and `c ? 0 : X` is unspellable: it always compiles as `!c ? X : 0` <sub>L20051</sub>
- **§197-C** — Fix A1 (operand order) cannot move a commutative destination whose .greg conflict set already contains BOTH operand hard registers — split the accumulate so the destination IS the load's pseudo <sub>L20688</sub>
- **§199-A** — §189-A's asm→source inference is byte-FALSE: an interloper between a split constant's `lui`/`ori` is a SCHEDULE fact, not a source fact — and the separator is the BIRTHING BOOST, not a "priority floor" (§189-A's split-timing half survives; its "no statement order / no pin" absolute and the candidate's own forward-scheduler narrative both fall) <sub>L20759</sub>
- **§199-B** — A permutation sweep that holds ANY statement fixed is not a sweep: the statement an agent pins as "obviously load-bearing" is the one carrying the signal, and the partial sweep returns a FLAT residual that reads as proof of order-invariance <sub>L20808</sub>
- **§199-E** — §189-A BOUNDED AND CORRECTED — the discriminator is INSN_PRIORITY, not "is the interloper a constant": an insn between a `lui`/`ori` pair proves NOTHING about the source spelling unless it TIES the `ori` on priority, and on the pinned `-mcpu=3000` triple a dependent load never does <sub>L20961</sub>
- **§205** — THE CHAINED ASSIGNMENT IS ITS OWN SCHEDULING DIAL: `*b = *a = v;` moves an argument copy that no local, no pin and no statement reorder will move (P31 S56) <sub>L22098</sub>
- **§208** — TWO NAMED LOCALS FOR ONE RELOADED EXPRESSION BUY TWO ALLOCNOS — the naming granularity owns the REGISTER SPLIT, not just the load count (P31 S58) <sub>L22243</sub>
- **§211** — HOIST THE LOOP INIT ABOVE THE DOMINATING GUARD: it fills the guard's delay slot AND flips the counter/pointer register pair (P31 S58) <sub>L22415</sub>
- **§215** — PIN ECONOMY: the twin's pins are NOT part of the shape, and §17's "pin every call-crossing value" is over-broad (P31 S58) <sub>L22601</sub>
- **§220** — THE PARAMETER ITSELF IS A REGALLOC DIAL: use it directly, prefer `s32` to `void*`, and place the save-copy AFTER the first call (P31 S58) <sub>L22779</sub>
- **§221** — A CONSTANT SHARED BY TWO STORES DIES AT THE CALL WHOSE DELAY SLOT REFILLS ITS REGISTER **(single observation — not yet cross-confirmed)** (P31 S58) <sub>L22819</sub>
- **§30** — addendum (P31 S58) — the `/s` grant closes a SCHEDULING residual and a REGISTER residual with one edit <sub>L23257</sub>
- **§244** — `volatile` IS A COUNTING INSTRUMENT, A STORE-ORDER PIN, AND MUST SOMETIMES BE ASYMMETRIC (P31 S58b) <sub>L23751</sub>
- **§248** — SPLIT THE LOAD FROM THE ARITHMETIC: A FUSED `g + K` DENIES THE CALLEE-SAVED REGISTER ITS DIRECT HOME (P31 S58b) <sub>L23907</sub>
- **§253** — POSTFIX `++` vs `+= 1` PICKS A DIFFERENT SCRATCH REGISTER **(single observation — not yet cross-confirmed)** (P31 S58b) <sub>L24053</sub>
- **§254** — THE DEAD PARAMETER IS A REGISTER-PLACEMENT TOOL **(single observation — not yet cross-confirmed)** (P31 S58b) <sub>L24067</sub>
- **§215** — addendum (P31 S58b) — PIN ECONOMY, PART 2: NINE REFINEMENTS <sub>L24424</sub>
- **§223** — addendum (P31 S58b) — FIVE MORE CONFIRMATIONS, AND THE CONSTANT-IN-`$v0` CASE <sub>L24536</sub>
- **§263** — A STOLEN DELAY SLOT WHOSE INSTRUCTION IS AN ARG-REGISTER COPY IS AN ARITY ERROR, NOT A SCHEDULE (P31 S59, byte-proven) <sub>L24927</sub>
- **ADD-8** — → §245 addendum — THE RE-TIE BARRIER PINS CALL-ARG SETUP TO SOURCE ORDER (construct 6) <sub>L25203</sub>
- **§268** — A `register __asm__` PIN ON A CALL-CLOBBERED REGISTER IS HONORED EXACTLY WHEN THE PINNED RANGE CROSSES NO CALL (P31 S59c; three A/B'd cards, unifying §257-2's two) <sub>L25285</sub>
- **ADD-6** — → §220-addendum — THE FOURTH FACE: WHEN THE NAMED COPY ITSELF BUYS THE EXTRA CALLEE-SAVED, PIN THE COPY TO `$16` <sub>L25427</sub>
- **ADD-7** — → §229 addendum — THE VALUE FACE: A LOOP-STORE CONSTANT SPELLED AS A LITERAL HAS NO SOURCE POSITION; NAME IT TO PIN THE PROLOGUE INIT ORDER <sub>L25443</sub>
- **ADDENDUM** — to §82 — struct copies must stay MEMBER-WISE, not block-moved, to match a spill-slot save <sub>L25743</sub>
- **ADDENDUM** — to §136d-1 (RC-12, the `$0`-add / opaque-copy family) — two symptoms beyond "compare reads the wrong register" <sub>L25781</sub>
- **ADDENDUM** — to §164-64 — AN EMPTY CLOBBER ON AN ARGUMENT REGISTER CAN BE THE DELIBERATE FIX, NOT JUST THE ACCIDENTAL BUG <sub>L26038</sub>
- **§275** — THE LEFTOVER-REGISTER READ <sub>L26412</sub>
- **§NNN** — A DO-WHILE'S GUARD AND LATCH MUST REPEAT THE SAME BOUND EXPRESSION, NOT SHARE ONE LOCAL: THE REPETITION IS WHAT BUYS THE CSE'D COPY INTO A SECOND REGISTER (P31 S60; `func_8017F2A4`, ov_SC03_096, byte-proven 25/25) <sub>L26923</sub>
- **ADDENDUM** — to §176-B2 — in a micro-function with no long/short lifetime asymmetry, BOTH contending pseudos need their own hard-register pin <sub>L27364</sub>
- **ADDENDUM** — to §220 — REFERENCING THE RAW PARAMETER (NO NAMED COPY, NOT EVEN A PIN) LETS THE CALLEE-SAVED SPILL LAND IN THE FIRST CALL'S OWN DELAY SLOT <sub>L27480</sub>
- **ADDENDUM** — to §215 — FIFTH SHAPE: reused mask constants across two call-free merge sites each get their own whole-function hard-register pin, and a shared sub-expression at the second site must be its own statement <sub>L27565</sub>
- **ADDENDUM** — to §194-B (func_8017EB34, ov_SC03_117 — wave dk; distinct from the §74 co-pinning finding on the SAME function below) <sub>L27973</sub>
- **ADDENDUM** — §NNN — sharpens §162a3/§60b: A `sll $v0,16 / sltiu $v0,1` ZERO-TEST OF A JUST-DECREMENTED HALFWORD IS A SIGNED-TEMP WIDTH TELL OUTSIDE ANY SWITCH/RANGE-TEST CONTEXT <sub>L28293</sub>
- **§285** — PRE-INITIALIZING A VARIABLE WITH A SHARED CONSTANT BEFORE A BRANCH MAKES BOTH ARMS OF THE FOLLOWING if/else DESTRUCTIVELY REUSE THE SAME DESTINATION REGISTER FOR THEIR BITWISE RESULT (byte-proven; `func_801811F0`, ov_SC03_102, independently rediscovered across waves di/dj) (P31 S60; waves #, byte-proven) <sub>L29078</sub>
- **§287** — A STACK-FRAME HOLE BELOW TWO ADDRESS-TAKEN AGGREGATE LOCALS IS A LEADING PAD MEMBER OF ONE COMBINED STRUCT, NOT SEPARATE LOCALS OR A REGISTER PIN (P31 S60/dj; `func_8017D104`, ov_SC06_027, byte-proven 47/47) (P31 S60; waves #, byte-proven) <sub>L29086</sub>
- **§288** — A REGISTER PIN DECLARED UNINITIALIZED AND ASSIGNED ONLY AT ITS LATE, SOLE USE STILL FORCES THE FIXED REGISTER'S SAVE/RESTORE, AND THE ASSIGNMENT'S SOURCE POSITION CONTROLS WHERE THE VALUE MATERIALIZES (P31; `func_80186530`, ov_SC02_017, byte-proven, match_one MATCH re-verified) (P31 S60; waves #, byte-proven) <sub>L29090</sub>
- **§290** — A SINGLE STRENGTH-REDUCED GIV CAN DRIVE STORES TO SEVERAL DISTINCT RELOCATABLE SYMBOLS, EACH KEEPING ITS OWN `%hi`/`%lo` ANCHOR (P31 S60; waves #, byte-proven) <sub>L29098</sub>
- **ADDENDUM** — to §172b-1 (counter-type dial) — the sll's SOURCE REGISTER is the placement discriminator <sub>L29268</sub>
- **ADDENDUM** — to §282 — the ADDRESS-GIV face: write the walked address INLINE so strength reduction births the induction register at loop.c's own insertion point <sub>L29313</sub>
- **§310** — A TWO-OPERAND `subu`'s DESTINATION TIES ONLY TO THE OPERAND THAT IS BLOCK-LOCAL: SHARE *ONE* SIDE ACROSS BLOCKS TO CHOOSE WHICH OPERAND'S REGISTER IT LANDS IN (P31 S64 t5j-t5m; byte-proven func_8017F578) <sub>L30086</sub>
- **§312** — A BARE RELATIONAL IN AN `if` GIVES THE `slt` NO TARGET: ASSIGN THE COMPARISON INTO THE ALREADY-ALLOCATED VARIABLE TO CHOOSE ITS DESTINATION REGISTER, AT ZERO INSTRUCTION COST (P31 S64 t5o-t5r; byte-proven func_80180DCC) <sub>L30159</sub>
- **Addendum** — §312 addendum — naming the compare's dest is the vehicle, the hard-reg pin on that name is (func_80184A68) <sub>L30461</sub>
- **Addendum** — subu/sh dest reuses a pinned operand's dying register (func_8017F498) <sub>L30465</sub>
- **Addendum** — Addendum to §312 — the compare's named destination must itself carry a hard register: nami (func_80184A68) <sub>L30481</sub>
- **Addendum** — REGALLOC-PERM: one memory-clobber barrier insufficient — stack two (func_80182D1C) <sub>L30523</sub>
- **REFUTED** — claim — Dead call-arg register address-fold: no C-level lever found (func_8017ECAC) <sub>L30541</sub>
- **Addendum** — REGALLOC-PERM: the store reads the narrow copy's register — split the one narrow local by (func_801838CC) <sub>L30626</sub>
- **Addendum** — REGALLOC-PERM store in a cross-jump shared tail defeats §137's barrier (func_8017EDE8) <sub>L30630</sub>
- **§319** — N TEXTUALLY DUPLICATED `return v;` TAILS PUT THE LAST `or` AND THE RETURN-REGISTER MOVE IN ONE BASIC BLOCK, SO combine FOLDS THEM AND YOU ARE EXACTLY −1; A `goto done;` JOIN WITH REAL INCOMING EDGES RESTORES THE SEPARATE `addu $v0,$a0,$zero` (P31 S66 round4; byte-proven func_801809F0) <sub>L30671</sub>
- **Addendum** — LENGTH-DRIFT −1 on a coalesced-away copy: a CALLER-SAVED SOURCE pin can resurrect it, boun (func_8017D72C) <sub>L30714</sub>
- **Addendum** — The dying-pinned-register reuse on a sign-extend chain: route every later read through a s (func_80186868) <sub>L30743</sub>
- **Addendum** — Register-pinned helper pointer local regresses closeness; use plain local (func_80013CFC) <sub>L30757</sub>
- **§325** — REGALLOC: A SHARED SMALL CONSTANT STORED TWICE IN THE PRE-LOOP BLOCK IS A *local-alloc* $s-OCCUPANT THAT STEALS THE ARGUMENT ALLOCNO'S REGISTER — PIN THE ARGUMENT-DERIVED LOCAL, NOT THE CONSTANT (P31 S67; byte-proven ov_SC03_119/func_80184F18, 153 ins) <sub>L30987</sub>
- **§329** — fold-const NARROWS `(int)s16_var & 0xFFF` ONTO THE *RAW HImode PSEUDO*, BREAKING THE SIGN-EXTEND/MASK REGISTER TIE — A ZERO-BYTE WIDENING TEMP RESTORES IT (P31 S67; byte-proven ov_SC01_084/func_80183244, 157 ins) <sub>L31034</sub>
- **§334** — A RELOAD SPILL SLOT IS ROUNDED TO `BIGGEST_ALIGNMENT` (8B), SO ONE SPILLED 4-BYTE PSEUDO CAN GROW THE FRAME BY 16 (P31 S67; byte-proven ov_SC05_008/func_8017DF68, 82 -> 53 residual) <sub>L31129</sub>
- **§342** — A `void *` PARAMETER CAST TO ITS REAL TYPE IN A LOCAL IS **NOT** BYTE-NEUTRAL WHEN A LATER PARAMETER ALSO NEEDS A CALLEE-SAVED REGISTER (P31 S67; byte-proven ov_SC07_002/func_80181394, NEW LAW) <sub>L31257</sub>
- **§344** — RAISE A BIV'S global_alloc PRIORITY WITH A ZERO-BYTE REFERENCE INSTEAD OF PINNING IT; PINNING THE COUNTER KILLS LSR ENTIRELY (P31 S67; byte-proven ov_SC03_121/func_80180E64, 222 ins) <sub>L31296</sub>
- **§347** — LOOP REGISTER ASSIGNMENT IS A **DECLARATION-ORDER + LIVE-RANGE** DIAL: FIVE COMPOSABLE LEVERS, 178 -> 0 (P31 S67; byte-proven ov_SC06_029/func_8017EF34, 243 ins) <sub>L31342</sub>
- **§365** — PIN **BOTH** MASKS OR NEITHER (P31 S68; ov_SC01_000/func_8017E594, 357 ins) <sub>L31748</sub>
- **§368** — ★★★ — THE **RELOAD-REMAT CONSTANT**: REACH A REGISTER NO PIN CAN REACH (P31 S68; ov_SC03_105/func_80187A30, 339 ins, fable escalation closed 8 → 0 in ONE edit) <sub>L31792</sub>
- **§373** — ★★★ — THE **DEAD-RESET CSE-BREAKER**, THE PIN THAT BREAKS A sched2 ANTI-DEP, AND WHY AN `asm` CAN NEVER RAISE PRIORITY (P31 S68; byte-proven ov_SC06_010/func_8017E764, 438 ins, fable escalation closed 8 → 0) <sub>L31977</sub>
- **§3-2.** — A REGISTER PIN THAT DELETES A sched2 ANTI-DEPENDENCE <sub>L31997</sub>
- **§374** — A `register … __asm__("$30")` RESERVATION IS **NOT HONOURED** BY `move_movables` (P31 S68; main/func_80015608, 86 ins) <sub>L32026</sub>
- **§375** — AN `$a0`-`$a3` PIN USED LATE RELOCATES AN **EARLIER** OUTGOING-CALL USE OF THAT REGISTER (P31 S68; main/func_8005F0C8, 88 ins) <sub>L32042</sub>
- **§3-C.** — REGISTER ALLOCATION FROM C, WITHOUT PINS <sub>L33124</sub>
- **§410** — ★★★ — COPY THEN ACCUMULATE ON THE COPY: resolving the birthing-boost vs register-allocation dilemma (P31 S71; byte-proven `ov_SC04_015/func_8017EB78`, 98 ins) <sub>L33353</sub>
- **§417** — ★★★ — A REGISTER PIN CAN BLOCK `jump.c`'s SELECT COLLAPSE, AND UNPINNING THEN EXPOSES A `cse` SKIP-BLOCKS MERGE (P31 S71; byte-proven `ov_SC03_013/func_8017E6F4`, 182 ins) <sub>L33605</sub>
- **§419** — ★★★ — WHEN A PIN IS IMPOSSIBLE, WIN THE local-alloc DENSITY CONTEST INSTEAD (P31 S71; byte-proven `ov_SC01_000/func_8017DD04`, 297 ins) <sub>L33658</sub>
### CSE / redundancy / rematerialization (45)
- **§46** — The `func_80178D40` crack (890 ins ×134, the heaviest core in the game): four LOOP-STRUCTURE levers cheap-Opus found by reading loop.c/jump.c/cse.c (Phase 26 session 8, 2026-07-13) <sub>L3347</sub>
- **§83d** — CSE's quantity budget is WHOLE-FUNCTION, so a local rewrite cannot fix a local symptom <sub>L6486</sub>
- **§153** — THE ADDRESS-REMATERIALISATION LAUNDER: a third zero-emission asm lever (P30 S43, `func_8018D98C`, 710 ins) <sub>L10500</sub>
- **§176-D** — CSE-class levers used in reverse (two sharpenings of §153 and cse_expr §2) <sub>L17776</sub>
- **§193-E** — A varying-address (pointer) load is re-emitted once per CSE-LIVE INTERVAL, and naming it in a C local is the only C-level lever over that count — no store SPELLING has any reach <sub>L18693</sub>
- **§193-F** — §148-A2 — The `threshold -= 3` STAIRCASE: `move_movables` admits a COUNT of invariants, not a boolean — two identical merged constants split hoisted/not-hoisted by LIST ORDER, and `insn_count` picks the rank cutoff <sub>L18723</sub>
- **§193-H** — A pointer-derived base load `*(s32*)(p+K)` is uncacheable across ANY memory write or call (cse's third kill disjunct) — so the target emits one `lw` per store-separated RUN of spellings, and a run of stores sharing one `lw` is a C local you must declare <sub>L18848</sub>
- **§194-A** — A zero-byte scheduling fence goes AFTER the defining statement to make that computation emit FIRST in its block — and the barrier predicate is `volatile`-or-colon-less, not the `"memory"` clobber (COMPLEMENTS §165-40; does not refute it) <sub>L18991</sub>
- **§194-J** — Back-to-back identical stores: flow.c's `last_mem_set` deletes the first, and only `volatile` saves it <sub>L19433</sub>
- **§194-K** — Blind sched1's alias oracle with a second SET of a pointer pseudo — the first zero-byte, non-volatile, dependence-CREATING lever (corrects §167-05's "volatile is the only door"; fourth consumer of reg_n_sets) <sub>L19485</sub>
- **§195-H** — §165-27g — ON A FIXED-SYMBOL GLOBAL, `extern T D[];` + `D[0]` IS THE CSE RELOAD DIAL, AT ZERO ADDRESSING COST, AND THE ELEMENT COUNT IS INERT (§165-27's `T v[2]` CAVEAT IS A LOCAL-FRAME FACT AND DOES NOT TRANSFER) <sub>L20151</sub>
- **§195-I** — §145(b) AMENDED — the pointer-bump `addiu` is saved by cse, not combine: ANY second SET of a pseudo in the address's equivalence chain (in-place `p += K`, §145(b)'s `p = r;` copy, or an asm re-tie) kills the fold; the pass is cse and the gate is `invalidate`'s `reg_tick++` <sub>L20198</sub>
- **§195-L** — The cse store-re-seed does not cross a JOIN LABEL: per-arm stores + a join read keep the reload that one join store deletes (bounds §193-E BOUND 1/BOUND 3 with §48-B's EBB boundary) <sub>L20359</sub>
- **§197-A** — A NARROW SIGNED MEMORY READ FEEDING A CONSTANT `>>` LOSES ITS `lh`, AND THE CURE IS AN ASM RE-TIE (attribution CONTESTED: cse vs combine) <sub>L20622</sub>
- **§197-B** — A REPEATED COMPARE OF ONE VALUE AGAINST ONE CONSTANT IS DELETED BY cse's `qty_comparison_code` CHANNEL (the non-EQ complement of §165-03) — and a front-end-opaque mask on EITHER compare is a pure-C dial that keeps the target's second branch <sub>L20660</sub>
- **§199-D** — A narrow UNSIGNED value compared in an ordered `if` emits `sltiu`/`sltu`; the only dial is the WIDTH of a real object, and a widening `(s32)` cast is inert — AMENDS §35 (whose stated "only CSE-reuse canonicalizes" mechanism is byte-wrong) and does NOT apply inside a `switch` <sub>L20901</sub>
- **§201-E** — §194-J-2 — The `last_mem_set` deletion window is measured in SOURCE/expand order, not in the printed stream; a foreign store moved between the pair in C source is a real lever, and `volatile` is not always the better one <sub>L21409</sub>
- **§204-D** — A LOOP-INVARIANT LOAD IS ADMITTED AS A MOVABLE ONLY IF ITS ADDRESS CANNOT TRAP: `local.field` PASSES, THE SAME READ THROUGH A POINTER LOCAL IS REFUSED <sub>L21804</sub>
- **§243** — SPELL THE CSE BARRIER AS A REASSIGNED POINTER; AND THE `nop`-AFTER-EVERY-`lh` SIGNATURE (P31 S58b) <sub>L23721</sub>
- **§244** — `volatile` IS A COUNTING INSTRUMENT, A STORE-ORDER PIN, AND MUST SOMETIMES BE ASYMMETRIC (P31 S58b) <sub>L23751</sub>
- **ADD-1** — → §257-8 addendum — THE INTERPOSED ASM'S `__volatile__` IS A PER-SHAPE DIAL, AND THE "NO-OUTPUT ASM IS IMPLICITLY VOLATILE" LORE IS BYTE-FALSE IN gcc-2.7.2 <sub>L25354</sub>
- **ADDENDUM** — to §244 — THE COMPILER BARRIER, NOT `volatile`, BLOCKS A STORE→LOAD HOIST THROUGH A POINTER-OFFSET FIELD <sub>L26069</sub>
- **ADDENDUM** — to §211 — AN IN-LOOP ACCUMULATOR WANTS A CLOSED-FORM EXPRESSION WHEN THE TARGET REMATERIALISES ITS CONSTANT AFTER EVERY CALL <sub>L26377</sub>
- **§276** — MIXED ADDRESS-EXPRESSION SPELLING FOR ADJACENT RELOCATABLE SYMBOLS IS A CSE-UNIFICATION DIAL, NOT JUST A BYTE-ENCODING CHOICE (P31 S60; `func_80180FE8`, ov_SC06_006, byte-proven) <sub>L26452</sub>
- **§NNN** — A DO-WHILE'S GUARD AND LATCH MUST REPEAT THE SAME BOUND EXPRESSION, NOT SHARE ONE LOCAL: THE REPETITION IS WHAT BUYS THE CSE'D COPY INTO A SECOND REGISTER (P31 S60; `func_8017F2A4`, ov_SC03_096, byte-proven 25/25) <sub>L26923</sub>
- **ADDENDUM** — to §22 (`volatile`-qualified-global reload lever, cookbook ~L1922) — for a NON-constant, same-address double RMW, a plain memory clobber beats `volatile`, and `volatile` actively breaks a delay-slot fill <sub>L27226</sub>
- **§302** — A RED BINARY IS A DRIFTED SPEC, NOT A MYSTERY: THE THREE CARVE-STATE INVARIANTS AND HOW TO DERIVE EACH FROM THE BYTES (P31 S62 T2; five reds healed in one session, 5/5, +39 held banks) <sub>L29719</sub>
- **§308** — A NAIVE FINAL `goto` DELETES THE TARGET'S `j`+`nop`: SPELL THAT EDGE AS A TAUTOLOGICAL `if` SO cse FOLDS IT TO AN UNCONDITIONAL JUMP *AFTER* jump1's WINDOW HAS CLOSED (P31 S63 t5e-t5i; byte-proven func_80180808) <sub>L29983</sub>
- **§317** — A NARROW STRUCT-FIELD STORE TURNS A *LIVE SImode VARIABLE* INTO A `li`: convert.c's TRUNCATION-DISTRIBUTION MINTS A HImode COPY, AND cse REWRITES THAT COPY'S SOURCE TO THE EQUIVALENT CONSTANT (P31 S66; byte-proven func_8017EF94) <sub>L30344</sub>
- **Addendum** — Addendum to §167-12 — the single-operand volatile keepalive, re-confirmed at a gated MATCH (func_8017F498) <sub>L30485</sub>
- **REFUTED** — claim — REFUTED — the `j`-slot store is an ASPSX macro-expansion hop, not a cse split; maspsx hard (func_8005DBD8) <sub>L30589</sub>
- **§NNN** — REFUTED: A `sw %lo(SYM)($at)` IN A JUMP'S DELAY SLOT WITH ITS `lui $at` STRANDED ABOVE THE JUMP IS **ASSEMBLER** MACRO-EXPANSION, NOT A cse SPLIT — OUR PIPELINE CANNOT EMIT IT FROM ANY C, AND THE +1 IS A `maspsx` GAP (P31 S66 round2, `func_8005DBD8`, byte-probed) <sub>L30591</sub>
- **Addendum** — Volatile zero-byte asm slider scrambles the prologue schedule (func_801814B0) <sub>L30747</sub>
- **§326** — DEFEATING ADDRESS-CSE: SPELL TWO READS OF THE SAME HALFWORD DIFFERENTLY AND GCC CANNOT SHARE THE ADDRESS (P31 S67; byte-proven ov_SC01_077/func_8017FAAC, 154 ins) <sub>L31000</sub>
- **§327** — A RANGE TEST MUST BE HImode: WITH `s32` + A `(u16)` CAST GCC *PROVES* THE MASK REDUNDANT AND DROPS THE `andi` (P31 S67; byte-proven ov_SC02_039/func_8017EC34, 154 ins) <sub>L31009</sub>
- **§328** — THE VOLATILE ALIAS MUST BE AN *OBJECT*, NOT A CAST: `*(volatile s32*)&sym` UNFOLDS %lo INTO A SEPARATE `addiu` (P31 S67; byte-proven ov_SC07_007/func_80181B8C, 156 ins, NEW LAW) <sub>L31024</sub>
- **§345** — A VOLATILE **STORE** EVICTS THE MEM FROM cse AND KEEPS `sh`; A VOLATILE **LOAD** BLOCKS combine AND DEGRADES `lh` INTO `lhu+sll+sra` (P31 S67; byte-proven ov_SC01_084/func_80181A7C) <sub>L31312</sub>
- **§349** — RE-ASSIGN A BASE POINTER AT THE END OF THE LOOP BODY TO MAKE `n_times_set > 1` — THAT KILLS BOTH loop.c's INVARIANT HOIST **AND** THE ADDRESS GIV, REPRODUCING A REMATERIALISED `addiu $aN,$sp,K` (P31 S67; byte-proven ov_SC06_029/func_801804C8, 255 ins) <sub>L31414</sub>
- **§351** — `/s` (MEM_IN_STRUCT_P) IS A DIAL YOU CHOOSE PER ACCESS: A COMPONENT_REF GRANTS IT AND LETS cse KEEP AN INDEX ACROSS THE STORE; A PLAIN CAST DENIES IT (P31 S67; ov_SC01_000/func_8017DD04, 186 -> 5) <sub>L31456</sub>
- **§352** — ⚠ TWO IDENTICAL `__asm__ __volatile__("")` BARRIERS **MERGE WITH EACH OTHER** — SPELL THE SECOND ONE DIFFERENTLY (P31 S67; byte-proven resident/func_800D128C, measured closeness 105 when they merged) <sub>L31486</sub>
- **§368** — ★★★ — THE **RELOAD-REMAT CONSTANT**: REACH A REGISTER NO PIN CAN REACH (P31 S68; ov_SC03_105/func_80187A30, 339 ins, fable escalation closed 8 → 0 in ONE edit) <sub>L31792</sub>
- **§373** — ★★★ — THE **DEAD-RESET CSE-BREAKER**, THE PIN THAT BREAKS A sched2 ANTI-DEP, AND WHY AN `asm` CAN NEVER RAISE PRIORITY (P31 S68; byte-proven ov_SC06_010/func_8017E764, 438 ins, fable escalation closed 8 → 0) <sub>L31977</sub>
- **§3-1.** — DEAD-RESET CSE-BREAKER — the zero-footprint replacement for a §195-I asm re-tie <sub>L31979</sub>
- **§385** — ★★★ — THE **SCHED2 PRIORITY-DONOR ASM**: closing the "hoisted-invariant vs IV-init preheader swap" class (P31 S69; byte-proven main/func_80038A58, 347 ins, fable escalation 2 → 0) <sub>L32309</sub>
- **§417** — ★★★ — A REGISTER PIN CAN BLOCK `jump.c`'s SELECT COLLAPSE, AND UNPINNING THEN EXPOSES A `cse` SKIP-BLOCKS MERGE (P31 S71; byte-proven `ov_SC03_013/func_8017E6F4`, 182 ins) <sub>L33605</sub>
### loops & induction variables (48)
- **§3-T1** — Loop pointer: top-of-body for `addu` induction, not constant-folded `addiu` <sub>L71</sub>
- **§34** — The `func_80138ED0` giant crack: gcc-2.7.2's **3-qty sort bug** + the **zero-byte asm allocation toolkit** + the **giv-init fence** (Phase 24 T5; Opus→close=21, Fable5→MATCH ×134) <sub>L2473</sub>
- **§35** — The region-a sibling-giant harvest: difficulty ≠ $s-reg count (it's global-array hoisting) + the banking recipe + new loop idioms (Phase 24 T7, 5 parallel Opus-Max agents) <sub>L2490</sub>
- **§46** — The `func_80178D40` crack (890 ins ×134, the heaviest core in the game): four LOOP-STRUCTURE levers cheap-Opus found by reading loop.c/jump.c/cse.c (Phase 26 session 8, 2026-07-13) <sub>L3347</sub>
- **§66d** — The permuter⇄reader loop: alternate a random search with a byte-verified idiom, and let `residual_class` decide whose turn it is (Phase 29 SESSION-17) <sub>L5279</sub>
- **§66d-1** — What transfers between giants is the LOOP, not the PIN <sub>L5314</sub>
- **§70** — The giv-init base register: walk the PARAMETER, not a copy of it (Phase 29 SESSION-18, `func_801777BC`) <sub>L5653</sub>
- **§145** — Three loop/combine levers from the S40 wave-2 drafters (16/16 match_one) <sub>L9961</sub>
- **§148** — The loop.c hoisting THRESHOLD is arithmetic you can compute, and the `?:` clamp that folds to MIN_EXPR (P30 S42, `func_8017C6F4`, 947 ins) <sub>L10179</sub>
- **§171a** — THE MECHANICAL A-PROP DRAFT (P30 S50): 256 members banked with no agent in the loop <sub>L16474</sub>
- **§179-A** — 🔴 A LOOP-WALKED POINTER **PARAMETER** HANDS ITS ARGUMENT REGISTER TO THE GIV (9 byte-proofs) <sub>L17377</sub>
- **§179-E** — A `>2*MAX_MOVE_BYTES` BLOCK COPY IS A **STRUCT ASSIGNMENT**, NOT A HAND LOOP <sub>L17547</sub>
- **§179-F** — PINNING A LOOP-WALKED POINTER IS A TOTAL OFF-SWITCH FOR STRENGTH REDUCTION <sub>L17573</sub>
- **§194-C** — A CALLER-SAVED loop counter proves its live range crosses ZERO calls — so it cannot share a pseudo with any value LIVE ACROSS a call (but it may freely share one with values that merely sit between calls) <sub>L19095</sub>
- **§204-B** — A LOOP COUNT THAT ARRIVES ON THE STACK IS DECREMENTED IN PLACE: a fresh counter local can cost a real `move` AND permute the whole callee-saved file <sub>L21682</sub>
- **§204-D** — A LOOP-INVARIANT LOAD IS ADMITTED AS A MOVABLE ONLY IF ITS ADDRESS CANNOT TRAP: `local.field` PASSES, THE SAME READ THROUGH A POINTER LOCAL IS REFUSED <sub>L21804</sub>
- **§211** — HOIST THE LOOP INIT ABOVE THE DOMINATING GUARD: it fills the guard's delay slot AND flips the counter/pointer register pair (P31 S58) <sub>L22415</sub>
- **§246** — THREE-LIVE-VALUE SCAN LOOPS WANT ADDRESS-FROM-INDEX; AND TWO SYMBOLS CAN SHARE ONE giv (P31 S58b) <sub>L23833</sub>
- **ADD-7** — → §229 addendum — THE VALUE FACE: A LOOP-STORE CONSTANT SPELLED AS A LITERAL HAS NO SOURCE POSITION; NAME IT TO PIN THE PROLOGUE INIT ORDER <sub>L25443</sub>
- **ADD-8** — → §30a addendum — THE THIRD COLUMN: `*p++` IS ALSO SERIALIZED BUT BURNS `addiu`; ONLY CAST-PLUS GIVES SERIALIZATION *AND* DISPLACEMENT FOLDING <sub>L25456</sub>
- **ADDENDUM** — to §172b-1 — TWO PLACEMENT DIALS THE PROMOTION LAW DOESN'T NAME: NARROW THE COUNTER'S DECLARED TYPE, AND MOVE THE CAST INTO THE LOOP BODY <sub>L26100</sub>
- **ADDENDUM** — to §211 — AN IN-LOOP ACCUMULATOR WANTS A CLOSED-FORM EXPRESSION WHEN THE TARGET REMATERIALISES ITS CONSTANT AFTER EVERY CALL <sub>L26377</sub>
- **§279** — A `do/while (p < end)` LOOP UNDER AN ENTRY GUARD: the guard decides the compare, not the loop (P31 S60; wave cf, func_8017F2A4, ov_SC03_096, byte-proven) <sub>L26922</sub>
- **§NNN** — A DO-WHILE'S GUARD AND LATCH MUST REPEAT THE SAME BOUND EXPRESSION, NOT SHARE ONE LOCAL: THE REPETITION IS WHAT BUYS THE CSE'D COPY INTO A SECOND REGISTER (P31 S60; `func_8017F2A4`, ov_SC03_096, byte-proven 25/25) <sub>L26923</sub>
- **§NNN** — A LOOP CURSOR'S C TYPE (POINTER vs PLAIN INTEGER) SELECTS `sltu` vs `slt` FOR ITS BOUND TEST, INDEPENDENT OF THE VALUES INVOLVED (P31 S60; `func_800CAE74`, md_MAIN_031, byte-proven; cross-confirmed same wave by `func_8017F2A4`, ov_SC03_096) <sub>L26957</sub>
- **§282** — gcc's OWN LOOP REVERSAL PUTS THE COUNTER INIT AFTER THE HOISTED MOVABLES — a position no hand-written down-count can reach (P31 S60; wave cf, func_80180DD8, ov_SC04_005, byte-proven) <sub>L27036</sub>
- **§NNN** — WRITE THE UP-COUNT LOOP: gcc's OWN REVERSAL PRODUCES A COUNTER-INIT INSTRUCTION THAT LANDS AFTER HOISTED MOVABLES, WHICH A HAND-WRITTEN DOWN-COUNT LOOP CANNOT REPRODUCE (P31 S60; `func_80180DD8`, ov_SC04_005, byte-proven) <sub>L27037</sub>
- **§290** — A SINGLE STRENGTH-REDUCED GIV CAN DRIVE STORES TO SEVERAL DISTINCT RELOCATABLE SYMBOLS, EACH KEEPING ITS OWN `%hi`/`%lo` ANCHOR (P31 S60; waves #, byte-proven) <sub>L29098</sub>
- **ADDENDUM** — to §282 — the ADDRESS-GIV face: write the walked address INLINE so strength reduction births the induction register at loop.c's own insertion point <sub>L29313</sub>
- **ADDENDUM** — to the L1800 anchor-steer bullet — a DERIVED-POINTER local silently flips the merged giv's anchor END <sub>L29357</sub>
- **§297** — ONE GIV SERVING MIXED-WIDTH LOADS *AND* A STORE NEEDS STRUCT-MEMBER SPELLING; CAST/INDEX SPELLINGS RE-SPLIT THE PSEUDO (P31 S61; wave m0a, `func_800347C8`, main, byte-proven 31/31) <sub>L29499</sub>
- **§312** — A BARE RELATIONAL IN AN `if` GIVES THE `slt` NO TARGET: ASSIGN THE COMPARISON INTO THE ALREADY-ALLOCATED VARIABLE TO CHOOSE ITS DESTINATION REGISTER, AT ZERO INSTRUCTION COST (P31 S64 t5o-t5r; byte-proven func_80180DCC) <sub>L30159</sub>
- **Addendum** — Loop sentinel wrongly hoisted out of a call-containing loop (func_801835B0) <sub>L30493</sub>
- **§325** — REGALLOC: A SHARED SMALL CONSTANT STORED TWICE IN THE PRE-LOOP BLOCK IS A *local-alloc* $s-OCCUPANT THAT STEALS THE ARGUMENT ALLOCNO'S REGISTER — PIN THE ARGUMENT-DERIVED LOCAL, NOT THE CONSTANT (P31 S67; byte-proven ov_SC03_119/func_80184F18, 153 ins) <sub>L30987</sub>
- **§344** — RAISE A BIV'S global_alloc PRIORITY WITH A ZERO-BYTE REFERENCE INSTEAD OF PINNING IT; PINNING THE COUNTER KILLS LSR ENTIRELY (P31 S67; byte-proven ov_SC03_121/func_80180E64, 222 ins) <sub>L31296</sub>
- **§346** — `c ? X : -X` TAKES expand_expr's COND_EXPR **SINGLETON** PATH (copy, then negate IN PLACE) — AN if/else STATEMENT GIVES THE TWO-ARM FORM (P31 S67; byte-proven ov_SC03_102/func_80180C38, closed the last instruction) <sub>L31322</sub>
- **§347** — LOOP REGISTER ASSIGNMENT IS A **DECLARATION-ORDER + LIVE-RANGE** DIAL: FIVE COMPOSABLE LEVERS, 178 -> 0 (P31 S67; byte-proven ov_SC06_029/func_8017EF34, 243 ins) <sub>L31342</sub>
- **§348** — THE BASE SPELLING PICKS THE ADDRESSING MODE: A SYMBOL GIVES THE 3-INSN `lui/%lo` FORM, A POINTER VARIABLE GIVES THE 2-INSN `addu/lw` FORM (P31 S67; byte-proven ov_SC07_007/func_80182184, 264 -> 30 on this row alone) <sub>L31397</sub>
- **§349** — RE-ASSIGN A BASE POINTER AT THE END OF THE LOOP BODY TO MAKE `n_times_set > 1` — THAT KILLS BOTH loop.c's INVARIANT HOIST **AND** THE ADDRESS GIV, REPRODUCING A REMATERIALISED `addiu $aN,$sp,K` (P31 S67; byte-proven ov_SC06_029/func_801804C8, 255 ins) <sub>L31414</sub>
- **§354** — THE giv **WORTH-WHILE TEST** IS A DIAL: RE-ASSOCIATE THE ADDEND INTO THE INDEX TERM AND `strength_reduce` DECLINES (P31 S68; byte-proven ov_SC03_105/func_801824CC, 320 ins, 201 → 5 → 0) <sub>L31542</sub>
- **§357** — ONE STRUCT POINTER, NOT TWO: A SECOND SOURCE VARIABLE BUILDS A THIRD IV (P31 S68; byte-proven ov_SC06_029/func_80181DF8, 335 ins, 330 → 13) <sub>L31589</sub>
- **§361** — ★ — A LOOP-TAIL BYTE SIGNATURE THAT NAMES ITS SOURCE SHAPE — AND THE LAW THAT A "SCHEDULING TIE" MAY BE YOUR OWN EARLIER LEVER (P31 S68; byte-proven main/func_800241C0, fable escalation, 19 → 0 in 3 iterations) <sub>L31637</sub>
- **§366** — ★★ — `group_case_nodes` MERGES **STACKED CONSECUTIVE** CASE LABELS: GIVE EVERY CASE ITS OWN BODY (P31 S68; ov_SC01_001/func_8017EC28, **first-try MATCH 360/360**, 96/96 relocs audited) <sub>L31757</sub>
- **§385** — ★★★ — THE **SCHED2 PRIORITY-DONOR ASM**: closing the "hoisted-invariant vs IV-init preheader swap" class (P31 S69; byte-proven main/func_80038A58, 347 ins, fable escalation 2 → 0) <sub>L32309</sub>
- **§386** — ★★★ — A BYTE LOAD ON THE **BIV** BASE WAS BORN IN THE COMBINE PASS: SPELL IT AS A SHIFT-MASK, NEVER A DEREF (P31 S69; byte-proven main/func_80020598, 292 ins, escalation 1 → 0) <sub>L32335</sub>
- **§393** — ★★ — THE **BIRTHING BOOST**: A SINGLE-SET LOCAL IS SCHEDULED LAST; GIVE IT A SECOND SET (P31 S69; byte-proven ov_SC02_017/func_8017FCFC) <sub>L32543</sub>
- **§418** — ★★★ — TWO LOOP-STRUCTURE LEVERS: MAKE THE SECOND INDEX A GIV, AND KEEP A TABLE ADDRESS UNFOLDED (P31 S71; byte-proven `ov_SC04_016/func_8017DF8C`, 184 ins, 32 → 0 in seven compiles) <sub>L33632</sub>
- **§430** — ★★★ — A SHARED TAIL IS A LATE CROSS-JUMP MERGE, NOT A SOURCE `goto` — AND SPELLING IT AS ONE CAN INVALIDATE A LOOP (P31 S72; `main/CdReadSectorReadyCB`, 422/424 ins, verified with `cc1 -dL`) <sub>L34023</sub>
### structs, block moves & memcpy (88)
- **§3-T2** — Source statement order drives instruction scheduling <sub>L78</sub>
- **§5** — Known hard-residual classes (instruction-identical, one byte-exact blocker) <sub>L199</sub>
- **§13** — Add a location overlay — the canonical runbook (Phase 13; the Phase-15 fleet recipe) <sub>L1075</sub>
- **§15** — Struct-heavy shared-core pipeline (Phase 16) — empirical determinations (S0) <sub>L1332</sub>
- **§16** — Guided hand-matching the struct-heavy core (Phase 17 — beats the §15 brute-force) <sub>L1354</sub>
- **§3-The** — crack: the residual was gcc-2.7.2 COPY-COALESCING, not the instruction scheduler <sub>L2163</sub>
- **§28** — Banking a "close=0 gate-rejected" giant: the canonical-extern recovery (Phase 22 T1, byte-proven on func_8015126C ×134) <sub>L2344</sub>
- **§28b** — The struct-walled close=0 giant (§28 case #3) IS bankable: the engine_types.h type-lift (Phase 22 T2, byte-proven on func_80156B74 ×134) <sub>L2376</sub>
- **§30** — Fable5Max cracks §20/§10 "unsteerable" from the gcc SOURCE: store-vs-load is a `/s` aliasing flag, the def-side wall has a macro escape, + the birthing-boost (Phase 23, byte-proven on giant `func_8014EE14` 248 ins ×134) <sub>L2401</sub>
- **§32** — The region-a CAMERA-GIANT idiom set: struct-base hoisting + 4 sibling levers (Phase 24 T7, Fable5-cracked on `func_80129CF8` 191 ins, match_one MATCH; transferable to the 6 sibling giants) <sub>L2441</sub>
- **§38** — The WHALE `func_80144B9C` (770 ins): the -O0 struct-assign memcpy idiom + the -O0 reach-134 ×134 rollout (Phase 24 T7 §G, cheap Opus — no Fable5, no calls.c) <sub>L2546</sub>
- **§40** — Structural families: the MECHANICAL symbol-remap (crack one exemplar → remap the rest, ~0 tokens) (Phase 25 T3/T7, 2026-07-08) <sub>L2572</sub>
- **§41** — The DEF-SIDE canonical-sig wall: mechanically banking a drafted giant past `conflicting types` (Phase 25 T5b batch-2, 2026-07-09; `tools/canon_sig_reconcile.py`, byte-proven on `func_8013B274`) <sub>L2729</sub>
- **§42a** — addendum — wave 2 (residuals + 29-100 band): iso-MATCH ≠ real-TU bank, the memcpy→struct-assign fix, +5 levers (2026-07-10b) <sub>L2987</sub>
- **§44** — The Phase-25 cheap-Opus giant batch: 5 structural levers + the §43 extension (2026-07-11, 6 crackers over the frontier giants) <sub>L3276</sub>
- **§46** — The `func_80178D40` crack (890 ins ×134, the heaviest core in the game): four LOOP-STRUCTURE levers cheap-Opus found by reading loop.c/jump.c/cse.c (Phase 26 session 8, 2026-07-13) <sub>L3347</sub>
- **§3-Why** — 0/8 was structural, and predictable from two words <sub>L4079</sub>
- **§54** — `--fix-def-sig`: the member's CANONICAL DECLARATION is a build step too (tiny-IMM mega-pools, +4,801, Phase 29 T6, 2026-07-16) <sub>L4197</sub>
- **§56b** — PROPAGATING an h_seq giant: the exemplar's externs MUST be fleet-canonical, not the draft's types <sub>L4266</sub>
- **§65a** — The blast-radius taxonomy (makes §61's law structural instead of remembered) <sub>L5064</sub>
- **§66d-5** — `residual_class`'s "structural ⇒ permuter CPU is waste" is WRONG for schedule permutations (measured, Phase 29 SESSION-18) <sub>L5525</sub>
- **§83** — The parameterised-repeat law, the spill-area trap, and why a per-case edit cannot move a per-case symptom (Phase 29 SESSION-20, `func_80183814` 5,122 ins, cold-ish start → 36 structural / 99.3%) <sub>L6446</sub>
- **§84** — The DERIVED-OFFSET remap bug: a hand-computed literal that encodes the DISTANCE between two per-overlay symbols, and why `match_one` is structurally blind to it (Phase 29 SESSION-20, `func_8013D53C`) <sub>L6506</sub>
- **§3-The** — construct <sub>L6511</sub>
- **§91** — A structure-TRANSFER is only valid where the structure corresponds: the `--like` role trap (Phase 29 SESSION-21, `func_8012AAAC` ×137) <sub>L6876</sub>
- **§3-The** — three-hypothesis trail, because two of them were wrong and the wrongness is instructive <sub>L6905</sub>
- **§129** — Post-carve, `rtu_match`/`match_one` COUNT THE JUMP TABLE AS INSTRUCTIONS; and a carve must never be committed without its owner (P30 S28, `func_8013BD74`) <sub>L8471</sub>
- **§129a** — the target instruction count is INFLATED after a carve <sub>L8475</sub>
- **§3-The** — DEFINITION-side alias is the only escape when the fleet canon disagrees on a promoting param <sub>L9507</sub>
- **§3-Two** — errors of mine, both instructive <sub>L10043</sub>
- **§160** — THE REACH-15 WAVE HARVEST: an align-1 block move, and the instrument that called it a wall (P30 S47) <sub>L10927</sub>
- **§16Xy** — SHARPENS *(sharpens §136d-3, §37 /s-DEP LATTICE, §135-2, §136-13, §162q)* <sub>L12334</sub>
- **§3-The** — `/s` drop clause is in ALL THREE dependence predicates, so the FIXED-ADDRESS STORE is what floats (P30 S48, `func_8017CA18`, ov_MAIN_012) <sub>L12336</sub>
- **§16Z** — SHARPENS *(sharpens §37 "the /s-DEP LATTICE", §136-13, §136-14, §16Xy, §162q, `gcc-2.7.2-map/sched.md` §64)* <sub>L14394</sub>
- **§3-The** — ADDRESS-CLASS TABLE: which load/store pairs even REACH the `/s` clause (P30 S48 wave 4, `func_80185B44`, ov_SC03_014) <sub>L14396</sub>
- **§176g** — SIZE A WAVE BY INSTRUCTIONS, NOT BY CARDS (P31 S52 — the adopted doctrine) <sub>L16994</sub>
- **§3-F.** — `MEM_IN_STRUCT_P` ASYMMETRY IN `true_dependence` (func_80037144, 124 ins) <sub>L17345</sub>
- **§179-E** — A `>2*MAX_MOVE_BYTES` BLOCK COPY IS A **STRUCT ASSIGNMENT**, NOT A HAND LOOP <sub>L17547</sub>
- **§176-B** — "REGALLOC-PERM, 1-4 instructions off" ⇒ it is usually NOT register allocation <sub>L17704</sub>
- **§189** — FIVE COMPILER LAWS MINED FROM THE WAVE R/S JOURNALS (P31 S53), each source-cited and re-derived by a second agent <sub>L18267</sub>
- **§193-A** — The wave card ships only OPEN-set pointers and discards the atlas's BANKED one — `exemplar`/`sibs` are stubs 100% by construction (tools/atlas.py:96/657), while `seed.ref` (matched pool, atlas.py:505-536) is dropped at build_wave_atlas.py:143 <sub>L18483</sub>
- **§193-B** — A NARROW CAST OF A WIDE PARAMETER COSTS ONE EXTRA INSTRUCTION WHEN ITS STATEMENT SITS AFTER AN INTERVENING `jal` — AND THE DECIDER IS `combine.c:929`'s CROSS-CALL GUARD, NOT REGISTER ALLOCATION <sub>L18550</sub>
- **§193-I** — A DECLARED AGGREGATE LOCAL HAS AN 8-BYTE FRAME STRIDE — CEIL(size,8), NOT size. N ARRAYS THEREFORE COST 8·k MORE THAN ONE HAND-LAID STRUCT (k = how many of them have size mod 8 ≠ 0), AND THE TELL IS IDENTICAL INSTRUCTION COUNT WITH EVERY $sp DISPLACEMENT SHIFTED BY THE SAME CONSTANT. <sub>L18888</sub>
- **§194-E** — The wave card's `exemplar` is the TARGET ITSELF on 42/73 wave-U and 36/71 wave-T cards — a construction consequence of `atlas.py:657` (exemplar = max-nins OPEN member) meeting `build_wave_atlas.py:166` (one card per gid); and the shipped §193-A `seed_ref` is same-binary on 0/51, so no card field can ever name a destination-TU sibling <sub>L19199</sub>
- **§194-H** — §164-29's WAR fence runs again at SCHED2 ON HARD REGISTERS: an in-place `v &= K` before a branch fences the store that reads v, and when TWO independent stores compete for the one delay slot the fence picks the winner at ZERO length drift (a WIDTH/sh!=sw swap, not a nop). Corrects §167-42's reconstruction (pseudo arm → hard-reg arm) and supplies its first re-runnable A/B. <sub>L19352</sub>
- **§195-D** — §195 — `masked_diff.mask_for` returns 0 for EVERY `j`/`jal` word, so an internal `j` destination is invisible to match_one, the permuter scorer AND every similarity tier: a control-flow semantic error (which calls execute) surfaces as a 1-instruction residual mislabelled `DELAY-SLOT / profile=schedule`, or as an outright false MATCH <sub>L19925</sub>
- **§195-F** — fold-const.c:4825 canonicalises a `?:` whose THEN arm is zero (or constant against a non-constant ELSE) by inverting the condition and swapping the arms — so a ternary's written arm order is byte-inert there, and `c ? 0 : X` is unspellable: it always compiles as `!c ? X : 0` <sub>L20051</sub>
- **§195-G** — §NEW — TWO ARMS CALLING THE SAME CALLEE MERGE INTO ONE `jal` UNLESS EACH ARM'S OWN CODE CONSUMES THE RESULT: the C dial that keeps two call sites apart is WHERE the consumer test lives, and the branch SENSE you spell it with is byte-inert (jump.c:1737 canonicalises it) <sub>L20103</sub>
- **§195-K** — At -O2 the §18 array-of-struct lever is a FRAME lever, not a length lever — but only when the N reads carry DISTINCT index expressions; with a SHARED index §18's +2-instruction residual is still alive at -O2 (the submitted "memory-loaded narrow index" precondition and unconditional length-neutrality are both falsified) <sub>L20307</sub>
- **§199-D** — A narrow UNSIGNED value compared in an ordered `if` emits `sltiu`/`sltu`; the only dial is the WIDTH of a real object, and a widening `(s32)` cast is inert — AMENDS §35 (whose stated "only CSE-reuse canonicalizes" mechanism is byte-wrong) and does NOT apply inside a `switch` <sub>L20901</sub>
- **§199-F** — §164-36b — THE TARGET-HEAD FENCE IS A DELAY-SLOT THREAD SELECTOR, AND IT ONLY FIRES WHEN `mostly_true_jump > 0` (amendment to §164-36; its "−1 instruction" tell is falsified) <sub>L21020</sub>
- **§204-D** — A LOOP-INVARIANT LOAD IS ADMITTED AS A MOVABLE ONLY IF ITS ADDRESS CANNOT TRAP: `local.field` PASSES, THE SAME READ THROUGH A POINTER LOCAL IS REFUSED <sub>L21804</sub>
- **§225** — THREE CONTROL-FLOW SHAPES NO STRUCTURED SPELLING REACHES (P31 S58) <sub>L22975</sub>
- **§30** — addendum (P31 S58) — the `/s` grant closes a SCHEDULING residual and a REGISTER residual with one edit <sub>L23257</sub>
- **§249** — THE SELF-ASSIGN, THE DEAD RE-ASSIGN, AND THE `+ zr` COPY: THREE WAYS TO MAKE A DELETED INSTRUCTION REAL (P31 S58b) <sub>L23931</sub>
- **§30** — addendum (P31 S58b) — THE ANONYMOUS STRUCT MEMBER REF GRANTS `/s`, AND THAT IS A TWO-FOR-ONE <sub>L24199</sub>
- **§263** — A STOLEN DELAY SLOT WHOSE INSTRUCTION IS AN ARG-REGISTER COPY IS AN ARITY ERROR, NOT A SCHEDULE (P31 S59, byte-proven) <sub>L24927</sub>
- **ADD-8** — → §245 addendum — THE RE-TIE BARRIER PINS CALL-ARG SETUP TO SOURCE ORDER (construct 6) <sub>L25203</sub>
- **ADD-11** — → Cross-confirmation card block (per §259's standing instruction: confirmation, not news) <sub>L25234</sub>
- **ADD-4** — → §167-37 addendum — THE FIFTH PRECONDITION, NOW MEASURED: DOWNSTREAM FIELD RE-READS ⇒ NAME IT **AND** STORE **INSIDE** THE ARM <sub>L25394</sub>
- **ADD-10** — → Cross-confirmation card block (per §259's standing instruction: confirmation, not news) <sub>L25485</sub>
- **ADDENDUM** — to §82 — struct copies must stay MEMBER-WISE, not block-moved, to match a spill-slot save <sub>L25743</sub>
- **ADDENDUM** — to §244 — THE COMPILER BARRIER, NOT `volatile`, BLOCKS A STORE→LOAD HOIST THROUGH A POINTER-OFFSET FIELD <sub>L26069</sub>
- **§281** — GROUP COPY-THEN-RMW BY OPERATION KIND, NOT FIELD BY FIELD: sched1 does the interleaving, the source must not (P31 S60; wave cf, func_80180FB4, ov_SC03_111, byte-proven) <sub>L26990</sub>
- **§NNN** — A DEPENDENT COPY-THEN-RMW BLOCK MUST BE SOURCE-GROUPED BY OPERATION KIND, NOT BY FIELD, AND SCHED1 DOES THE INTERLEAVING (P31 S60; `func_80180FB4`, ov_SC03_111, byte-proven) <sub>L26991</sub>
- **§NNN** — WRITE THE UP-COUNT LOOP: gcc's OWN REVERSAL PRODUCES A COUNTER-INIT INSTRUCTION THAT LANDS AFTER HOISTED MOVABLES, WHICH A HAND-WRITTEN DOWN-COUNT LOOP CANNOT REPRODUCE (P31 S60; `func_80180DD8`, ov_SC04_005, byte-proven) <sub>L27037</sub>
- **§285** — PRE-INITIALIZING A VARIABLE WITH A SHARED CONSTANT BEFORE A BRANCH MAKES BOTH ARMS OF THE FOLLOWING if/else DESTRUCTIVELY REUSE THE SAME DESTINATION REGISTER FOR THEIR BITWISE RESULT (byte-proven; `func_801811F0`, ov_SC03_102, independently rediscovered across waves di/dj) (P31 S60; waves #, byte-proven) <sub>L29078</sub>
- **§287** — A STACK-FRAME HOLE BELOW TWO ADDRESS-TAKEN AGGREGATE LOCALS IS A LEADING PAD MEMBER OF ONE COMBINED STRUCT, NOT SEPARATE LOCALS OR A REGISTER PIN (P31 S60/dj; `func_8017D104`, ov_SC06_027, byte-proven 47/47) (P31 S60; waves #, byte-proven) <sub>L29086</sub>
- **§297** — ONE GIV SERVING MIXED-WIDTH LOADS *AND* A STORE NEEDS STRUCT-MEMBER SPELLING; CAST/INDEX SPELLINGS RE-SPLIT THE PSEUDO (P31 S61; wave m0a, `func_800347C8`, main, byte-proven 31/31) <sub>L29499</sub>
- **§308a** — A TWO-INSTRUCTION ARM STUB LAID *BEFORE* THE OTHER ARM AND REACHED ONLY BY A TRAILING `j` SURVIVES ONLY BEHIND A SHORT-CIRCUIT `&&` GUARD PLUS A SEPARATE RE-TEST; EVERY PLAIN if/else-if, GOTO-LADDER, NESTED-INVERTED-if AND 1-/2-NODE switch LETS jump1 INLINE IT (−2 ins) (P31 S63 t5e-t5i; byte-proven func_80180808) <sub>L30012</sub>
- **§312** — A BARE RELATIONAL IN AN `if` GIVES THE `slt` NO TARGET: ASSIGN THE COMPARISON INTO THE ALREADY-ALLOCATED VARIABLE TO CHOOSE ITS DESTINATION REGISTER, AT ZERO INSTRUCTION COST (P31 S64 t5o-t5r; byte-proven func_80180DCC) <sub>L30159</sub>
- **§314** — AN IF/ELSE-IF ABS-RANGE CHECK'S C SPELLING IS INERT: FOUR STRUCTURALLY DIFFERENT REWRITES ALL COMPILE BYTE-IDENTICAL, AND NONE REACHES A TARGET THAT SINKS THE NEGATIVE ARM INTO AN OUT-OF-LINE BLOCK (P31 S65; UNPROVEN, gate-refused draft func_80181720) <sub>L30241</sub>
- **§315** — ALL-CONSTANT AGGREGATE FILL: THE EMISSION ORDER IS SHARED-LITERAL GROUPS × DESCENDING INDEX, WITH PAIRED SUB-FIELDS INTERLEAVED (P31 S66; ⚠ **UNPROVEN** — `func_80185214`, gate-REFUSED draft, closeness 32→5, never MATCHed) <sub>L30273</sub>
- **§316** — A GUARD CHAIN THAT GATES A SUCCESS BLOCK ROUTES ITS FAILING GUARDS TO A LABEL **BEFORE** THE FLAG TEST, NOT TO THE EPILOGUE: THE RESIDUAL IS IMM-OFFSET-ONLY AT AN EXACTLY EQUAL INSTRUCTION COUNT (P31 S66; byte-proven func_80180284) <sub>L30310</sub>
- **§317** — A NARROW STRUCT-FIELD STORE TURNS A *LIVE SImode VARIABLE* INTO A `li`: convert.c's TRUNCATION-DISTRIBUTION MINTS A HImode COPY, AND cse REWRITES THAT COPY'S SOURCE TO THE EQUIVALENT CONSTANT (P31 S66; byte-proven func_8017EF94) <sub>L30344</sub>
- **Addendum** — WIDTH sh!=lhu residual: hoist a sibling field's load first (func_80182538) <sub>L30572</sub>
- **Addendum** — Masked-OR field-merge plateaus at close=10; bitfield store clears it (func_8017FD64) <sub>L30700</sub>
- **§321** — FILE-SCOPE DUPLICATE ANONYMOUS-STRUCT TYPEDEFS ARE A HARD ERROR; THE SAME TEXT AT BLOCK SCOPE IS A WARNING (P31 S66; byte-proven func_80180728, func_8017F9F8, func_8017E07C) <sub>L30845</sub>
- **§335** — AN `extern u16 A[]` READ AT A VARIABLE SUBSCRIPT ALLOCATES DEAD STACK TEMPS (~8B PER ACCESS) THAT INFLATE THE FRAME WHILE EMITTING ZERO EXTRA INSTRUCTIONS (P31 S67; byte-proven ov_SC06_025/func_8017EA74, closeness 141 -> 20) <sub>L31140</sub>
- **§346** — `c ? X : -X` TAKES expand_expr's COND_EXPR **SINGLETON** PATH (copy, then negate IN PLACE) — AN if/else STATEMENT GIVES THE TWO-ARM FORM (P31 S67; byte-proven ov_SC03_102/func_80180C38, closed the last instruction) <sub>L31322</sub>
- **§351** — `/s` (MEM_IN_STRUCT_P) IS A DIAL YOU CHOOSE PER ACCESS: A COMPONENT_REF GRANTS IT AND LETS cse KEEP AN INDEX ACROSS THE STORE; A PLAIN CAST DENIES IT (P31 S67; ov_SC01_000/func_8017DD04, 186 -> 5) <sub>L31456</sub>
- **§357** — ONE STRUCT POINTER, NOT TWO: A SECOND SOURCE VARIABLE BUILDS A THIRD IV (P31 S68; byte-proven ov_SC06_029/func_80181DF8, 335 ins, 330 → 13) <sub>L31589</sub>
- **§364** — ★ — THE libgpu `P_TAG` BITFIELD SPELLING IS **OPT-LEVEL DEPENDENT** (P31 S68; two functions, opposite verdicts, same session) <sub>L31734</sub>
- **§379** — ★★★ — **MEM_IN_STRUCT_P**: THE SAME LOAD, WRITTEN AS A STRUCT MEMBER, SCHEDULES WHERE A CAST CANNOT (P31 S69; byte-proven main/func_80021284 220 ins and main/func_8002D904 217 ins, found INDEPENDENTLY by two agents) <sub>L32164</sub>
- **§391** — ★★ — A BYTE-ALIGNED STRUCT COPIES IN FOUR INSTRUCTIONS, A WORD-ALIGNED ONE IN TWO (P31 S69) <sub>L32488</sub>
- **§395** — ★★★ — FIVE NARROWING/PLACEMENT LEVERS FROM ONE 91-INSTRUCTION CRACK (P31 S69; byte-proven ov_SC06_018/func_80189E60, warm start 32 off → MATCH 91/91) <sub>L32611</sub>
- **§418** — ★★★ — TWO LOOP-STRUCTURE LEVERS: MAKE THE SECOND INDEX A GIV, AND KEEP A TABLE ADDRESS UNFOLDED (P31 S71; byte-proven `ov_SC04_016/func_8017DF8C`, 184 ins, 32 → 0 in seven compiles) <sub>L33632</sub>
- **§425** — ★★★ — `sb` ALIASES SCALAR GLOBALS WHILE `sh`/`sw` STRUCT STORES DO NOT, AND TWO MORE ALIAS/BOOST RULES (P31 S71; `md_MAIN_003/func_800CF3E8`, 467 of 469 ins, all four byte-verified from `-dS`/`-dR`/`-dl`/`-dr`) <sub>L33829</sub>
### types, signedness & load/store width (95)
- **§3-I1** — Unsigned range check: `(x - lo) < (hi-lo)` → `addiu`+`sltiu` <sub>L41</sub>
- **§3-I2** — Byte mask forces `andi` even after `lbu` <sub>L47</sub>
- **§3-T3** — Types <sub>L85</sub>
- **§7** — PsyQ SDK types & symbols (the library-call prerequisite) <sub>L322</sub>
- **§14c** — Callee-signature-aware harvest — breaking the extern-type-conflict wall (Phase 15, T6) <sub>L1232</sub>
- **Phase-20** — RESOLUTION — `tools/cast_call_sites.py` BUILT + the cap re-diagnosed (R14, byte-proven) <sub>L1720</sub>
- **§23** — Giant `func_80153E00` cracked (scalar-data CAST); BUT most giant drafts are STALE+INCOMPLETE, and a diag MUST remove artifacts (Phase 21 — byte-proven + a self-correction) <sub>L2051</sub>
- **§28b** — The struct-walled close=0 giant (§28 case #3) IS bankable: the engine_types.h type-lift (Phase 22 T2, byte-proven on func_80156B74 ×134) <sub>L2376</sub>
- **§33** — Automating the giant decl-reconcile: `tools/reconcile_decls.py` (the DATA analog of §20's `cast_call_sites`) + a fleet-majority type oracle (Phase 24 T7b, byte-proven on `func_80129CF8`) <sub>L2453</sub>
- **§40a** — The DECL-RECONCILE pass (type-lift so remapped drafts compile in the sibling TU) (Phase 25 T7.2, 2026-07-08) <sub>L2620</sub>
- **§41** — The DEF-SIDE canonical-sig wall: mechanically banking a drafted giant past `conflicting types` (Phase 25 T5b batch-2, 2026-07-09; `tools/canon_sig_reconcile.py`, byte-proven on `func_8013B274`) <sub>L2729</sub>
- **§41d** — `void`→`s32` is NOT always byte-neutral: gate the RAW draft FIRST (Phase 26 session 6, byte-proven) <sub>L2912</sub>
- **§42b** — addendum — wave 3 (Max, 2026-07-10c): THE STALE-OBJECT GATE TRAP + the read-global `&`-cast drift + fix <sub>L3028</sub>
- **§43** — The K&R s16-param definition DISSOLVES the "narrow-param wall" for by-value register args (Phase 25 task A, Fable5 crack of the 369-ins giant `func_80166994` ×134, 2026-07-11) <sub>L3229</sub>
- **§3-C.** — TYPE- AND SHAPE-DRIVEN CODEGEN (the C type literally selects the addressing mode) <sub>L3518</sub>
- **§56b** — PROPAGATING an h_seq giant: the exemplar's externs MUST be fleet-canonical, not the draft's types <sub>L4266</sub>
- **§64** — The §20 type-lift's three laws: fold the tagged typedef, check VISIBILITY, and strip only what is TEXTUALLY IDENTICAL (`lift_types.py`, Phase 29 SESSION-14, 2026-07-23) <sub>L4942</sub>
- **§64a** — VARIANT types: UNIQUIFY the camps, do not reconcile them (`uniquify_type.py`, Phase 29 SESSION-14) <sub>L4991</sub>
- **§65g** — Where the cheap levers STOP: the local-type and in-TU-self-decl classes did not yield <sub>L5173</sub>
- **§68** — A comment-only line halted the extern scan, and the skip label blamed the type cap (Phase 29 SESSION-18) <sub>L5558</sub>
- **§73** — A def-side self-decl conflict has TWO axes: RETURN (fleet widen, T2) and PARAMS (casts at each use, T0). Diagnose which before paying for the expensive one (Phase 29 SESSION-19, `func_8014F3E8` + `func_8014D4C0`) <sub>L5817</sub>
- **§75c** — Class-B's remedy is the FULL §17a-1 PAIR (decl **and** call-site cast); a decl-only fix moves the error and looks like a new wall (Phase 29 SESSION-19, `func_8012F14C`) <sub>L6031</sub>
- **§3-The** — defect this exposed: a shared type that is present but invisible <sub>L6388</sub>
- **§92** — Conforming a DECLARATION: pointer changes are caller-neutral, scalar-WIDTH changes are not (Phase 29 SESSION-21, `tools/conform_decls.py`) <sub>L6925</sub>
- **§94** — A family sweep's `0/N` is a TYPE-CARRY failure until proven otherwise: lift the exemplar's local types, ALL of them, transitively (Phase 29 SESSION-21, `func_8016B6BC` 0/137 → 137/137) <sub>L6981</sub>
- **§100** — Prefer the DRAFT-LOCAL fix: a type only one function uses belongs in its BODY, not in a shared header (Phase 29 SESSION-22, `func_80175DA8` 0/137 → 137/137) <sub>L7250</sub>
- **§120** — Uniquify draft-defined TYPE names; and check which of N staging sites you actually patched (Phase 29 T93) <sub>L8060</sub>
- **§3-Do** — NOT "strip the duplicate typedef" — it breaks the extern that uses it <sub>L8071</sub>
- **§3-The** — type-form rules <sub>L8913</sub>
- **§143** — `cast_call_sites` read a RETURN STATEMENT as a prototype and deleted it. A 0/39 sweep became 18/39. (P30 S40) <sub>L9868</sub>
- **Then** — propagation returned 0/137 TWICE — both times a missing TYPE <sub>L10034</sub>
- **§154** — Reading a disc payload: the module-id word, static base derivation, and "type 1 = uncompressed overlay" (P30 S44) <sub>L10556</sub>
- **§3-C.** — PAC type 1 = the same payload class as type 4, just NOT compressed <sub>L10582</sub>
- **§155b** — check the TYPE your oracle returns before comparing against it (S45 p5) <sub>L10621</sub>
- **§3-B.** — Typedef handling — the only strategy that survives contact <sub>L17058</sub>
- **§3-D.** — A NARROW TYPE BLOCKS COPY ELISION (func_8001D3FC — new idiom) <sub>L17329</sub>
- **§185** — EDIT THE SIDE THAT IS CHEAP TO VERIFY, AND CHECK A TU RETYPE AT ITS USE SITES <sub>L18101</sub>
- **§186b** — A NO-SAVE 16-BYTE FRAME IN A LEAF FUNCTION MEANS `s16` LOCALS, NOT A HIDDEN CALL <sub>L18154</sub>
- **§193-B** — A NARROW CAST OF A WIDE PARAMETER COSTS ONE EXTRA INSTRUCTION WHEN ITS STATEMENT SITS AFTER AN INTERVENING `jal` — AND THE DECIDER IS `combine.c:929`'s CROSS-CALL GUARD, NOT REGISTER ALLOCATION <sub>L18550</sub>
- **§193-G** — §164-54's "scope to ≥4 arms" bound is byte-wrong — the dispatch-topology oracle goes live at THREE case nodes (`balance_case_nodes` splits at `i > 2`), but only for a signed-after-promotion index <sub>L18787</sub>
- **§193-H** — A pointer-derived base load `*(s32*)(p+K)` is uncacheable across ANY memory write or call (cse's third kill disjunct) — so the target emits one `lw` per store-separated RUN of spellings, and a run of stores sharing one `lw` is a C local you must declare <sub>L18848</sub>
- **§194-B** — A `addu $rA,$rB,$zero` copy feeding ≥2 `sh` stores is a SECOND, 16-BIT-DECLARED local — the width, not the clamp or the join liveness, is what keeps the copy (and func_80183094's pin + `"memory"` clobber are both provably inert) <sub>L19057</sub>
- **§194-D** — Declared width of a computed-value local is a sched1 dial (count-neutral) — a replication + attribution correction of §165-17, NOT a new argument-register law <sub>L19158</sub>
- **§194-G** — Reading the integer half of a 16.16 stack aggregate: REGISTER-LIVENESS, not the C spelling, decides `sra` vs `lhu` — and the break is count-neutral <sub>L19309</sub>
- **§194-H** — §164-29's WAR fence runs again at SCHED2 ON HARD REGISTERS: an in-place `v &= K` before a branch fences the store that reads v, and when TWO independent stores compete for the one delay slot the fence picks the winner at ZERO length drift (a WIDTH/sh!=sw swap, not a nop). Corrects §167-42's reconstruction (pseudo arm → hard-reg arm) and supplies its first re-runnable A/B. <sub>L19352</sub>
- **§194-I** — §16N+2's magic-per-odd-part ladder has exactly one broken row — read the divisor arithmetically instead: d = round(2^(32 + post_shift) / magic_read_as_unsigned) <sub>L19390</sub>
- **§197-A** — A NARROW SIGNED MEMORY READ FEEDING A CONSTANT `>>` LOSES ITS `lh`, AND THE CURE IS AN ASM RE-TIE (attribution CONTESTED: cse vs combine) <sub>L20622</sub>
- **§199-D** — A narrow UNSIGNED value compared in an ordered `if` emits `sltiu`/`sltu`; the only dial is the WIDTH of a real object, and a widening `(s32)` cast is inert — AMENDS §35 (whose stated "only CSE-reuse canonicalizes" mechanism is byte-wrong) and does NOT apply inside a `switch` <sub>L20901</sub>
- **§201-D** — THE SIGNEDNESS OF A div/mod MAGIC IS DECIDED BY THE STATIC TYPE OF THE DIVIDEND TREE AFTER `get_narrower` STRIPS WIDENING CONVERSIONS — NEVER BY A PROVABLE RANGE. AN `& 0xFF` IS NOT A CONVERSION, SO IT NEVER FLIPS THE MAGIC; A DECLARED-UNSIGNED LOCAL *OR* A NARROWING CAST WRITTEN AT THE DIVIDE BOTH DO. <sub>L21362</sub>
- **§203** — A DEDUPED TYPEDEF MUST PRECEDE EVERY SPLICE POINT, NOT JUST ITS OWN (P31 S56) <sub>L21527</sub>
- **§204-E** — `decl_prior`'s `%hi/%lo` ARM HAS NEVER FIRED: the card's promised GLOBAL-TYPE row is 0 of 1,210 <sub>L21879</sub>
- **§218** — A NARROW TYPE AT THE ABI BOUNDARY COSTS AN IN-PLACE `sll/sra` PAIR — on the RETURN as well as on the PARAMETER (P31 S58) <sub>L22723</sub>
- **§220** — THE PARAMETER ITSELF IS A REGALLOC DIAL: use it directly, prefer `s32` to `void*`, and place the save-copy AFTER the first call (P31 S58) <sub>L22779</sub>
- **§227** — TYPE THE SOURCE BY THE **LOAD** WIDTH, NOT BY THE STORE WIDTH (P31 S58) <sub>L23059</sub>
- **§234** — CONSTANT MATERIALISATION: THE STORE LVALUE'S SIGNEDNESS PICKS `addiu` vs `li`/`ori` (P31 S58b) <sub>L23357</sub>
- **§237** — THE CAST-AT-CALL-SITE DECISION TABLE: WHAT §17a-1 FIXES, WHAT IT CANNOT, AND THE FOUR ESCAPES (P31 S58b) <sub>L23506</sub>
- **§242** — `*k` vs `<<n`, AND `/2^n` vs `>>n`: EXPRESSION SPELLING OWNS THE LOAD WIDTH AND THE ROUNDING CHAIN (P31 S58b) <sub>L23693</sub>
- **§243** — SPELL THE CSE BARRIER AS A REASSIGNED POINTER; AND THE `nop`-AFTER-EVERY-`lh` SIGNATURE (P31 S58b) <sub>L23721</sub>
- **§251** — IMMEDIATE-SPELLING TRIGGERS: `+= 0xFF`, FULL-WIDTH `~K`, AND THE TWO-OR SPLIT (P31 S58b) <sub>L24010</sub>
- **ADD-5** — → §1/I1 addendum — THE INVERTED RANGE TEST: `(u32)(x-lo) >= N` WITH THE ZERO-ARM AS THE TRAILING `else` <sub>L25173</sub>
- **ADD-2** — → §236 addendum (item 1 corollary) — THE SILENT-SPLICE DECLARATION LADDER: WHERE THE TU HAS NO SPELLING, UNPROTOTYPED `()` BEATS THE FLEET VOTE <sub>L25367</sub>
- **ADD-5** — → §267-ADD-6 / §172b-1 addendum — THE SIGN-TEST FACE: `(s16)v < 0` IS `sll 16` + `bgez` ON THE SHIFTED COPY, RAW STAYS LIVE — AND THE HALFWORD-ABS SHAPE NEEDS NO RITUAL <sub>L25411</sub>
- **ADD-8** — → §30a addendum — THE THIRD COLUMN: `*p++` IS ALSO SERIALIZED BUT BURNS `addiu`; ONLY CAST-PLUS GIVES SERIALIZATION *AND* DISPLACEMENT FOLDING <sub>L25456</sub>
- **ADDENDUM** — to §179-C — the `.type NAME, @function` requirement <sub>L25640</sub>
- **ADDENDUM** — to §134 — a typedef defined BELOW the splice point is stripped anyway <sub>L25687</sub>
- **ADDENDUM** — to §172b-1 — TWO PLACEMENT DIALS THE PROMOTION LAW DOESN'T NAME: NARROW THE COUNTER'S DECLARED TYPE, AND MOVE THE CAST INTO THE LOOP BODY <sub>L26100</sub>
- **ADDENDUM** — to §172b-4 — THE PLAIN CAST-DIVISION ALREADY PRODUCES THE PATTERN; DON'T HAND-ROLL THE BIAS, AND KEEP THE OPERAND WIDE <sub>L26192</sub>
- **§280** — THE CURSOR'S DECLARED TYPE PICKS `sltu` vs `slt`: a `T*` bound test is UNSIGNED by C rule, an integer cursor is signed (P31 S60; wave cf, func_800CAE74, md_MAIN_031, byte-proven) <sub>L26956</sub>
- **§NNN** — A LOOP CURSOR'S C TYPE (POINTER vs PLAIN INTEGER) SELECTS `sltu` vs `slt` FOR ITS BOUND TEST, INDEPENDENT OF THE VALUES INVOLVED (P31 S60; `func_800CAE74`, md_MAIN_031, byte-proven; cross-confirmed same wave by `func_8017F2A4`, ov_SC03_096) <sub>L26957</sub>
- **ADDENDUM** — to §21 — the `bltz`+`slti` (or N-separate-compares) signed-range-split bullet is now CONFIRMED on three independent functions, and generalizes beyond `lbu`/u8 <sub>L27157</sub>
- **ADDENDUM** — to §202 — the DEF-SIDE ALIAS also resolves a function-vs-DATA-symbol identifier clash, not only a function-vs-function prototype clash <sub>L27203</sub>
- **ADDENDUM** — §NNN — sharpens §162a3/§60b: A `sll $v0,16 / sltiu $v0,1` ZERO-TEST OF A JUST-DECREMENTED HALFWORD IS A SIGNED-TEMP WIDTH TELL OUTSIDE ANY SWITCH/RANGE-TEST CONTEXT <sub>L28293</sub>
- **§288** — A REGISTER PIN DECLARED UNINITIALIZED AND ASSIGNED ONLY AT ITS LATE, SOLE USE STILL FORCES THE FIXED REGISTER'S SAVE/RESTORE, AND THE ASSIGNMENT'S SOURCE POSITION CONTROLS WHERE THE VALUE MATERIALIZES (P31; `func_80186530`, ov_SC02_017, byte-proven, match_one MATCH re-verified) (P31 S60; waves #, byte-proven) <sub>L29090</sub>
- **§292** — DECLARING A SYMBOL UPSTREAM OF AN ALREADY-BANKED SIBLING THAT RELIES ON THAT SYMBOL'S IMPLICIT (K&R) DECLARATION CAN SILENTLY REPROTOTYPE THE SIBLING'S OWN CALL SITE (P31 S60; waves #, byte-proven) <sub>L29106</sub>
- **ADDENDUM** — to §172b-1 (counter-type dial) — the sll's SOURCE REGISTER is the placement discriminator <sub>L29268</sub>
- **ADDENDUM** — to §31's asm→layout inference — TWO WIDTH-PAIR DISCRIMINATORS (same offset, different widths) <sub>L29380</sub>
- **§297** — ONE GIV SERVING MIXED-WIDTH LOADS *AND* A STORE NEEDS STRUCT-MEMBER SPELLING; CAST/INDEX SPELLINGS RE-SPLIT THE PSEUDO (P31 S61; wave m0a, `func_800347C8`, main, byte-proven 31/31) <sub>L29499</sub>
- **§318** — A UNARY MINUS STORED BACK INTO THE SAME HALFWORD IS COMPUTED IN HImode, SO ITS LOAD IS `lhu`; AN INLINE `(s32)` CAST IS PROVABLY INERT AND ONLY A NAMED SImode LOCAL BUYS `lh` (P31 S66; `func_8018568C`, ov_SC03_028 — **`match_one`-only, NOT byte-gated**) <sub>L30378</sub>
- **Addendum** — Reversed-operand sltu then xori 1 means unsigned less-or-equal (func_8017D948) <sub>L30505</sub>
- **Addendum** — WIDTH sh!=lhu residual: hoist a sibling field's load first (func_80182538) <sub>L30572</sub>
- **Addendum** — Static local_type blocker survives typedef removal — it's textual (func_801588CC) <sub>L30615</sub>
- **§320** — THE §43 "RETURN-TYPE FLIP PAIR" IS **NOT** TU-EDIT-REQUIRED: THREE DRAFT-ONLY ESCAPES (P31 S66; byte-proven func_800CCBC0, func_800D30D0, func_800D2A24) <sub>L30786</sub>
- **§321** — FILE-SCOPE DUPLICATE ANONYMOUS-STRUCT TYPEDEFS ARE A HARD ERROR; THE SAME TEXT AT BLOCK SCOPE IS A WARNING (P31 S66; byte-proven func_80180728, func_8017F9F8, func_8017E07C) <sub>L30845</sub>
- **§323** — CARRYING FILE-SCOPE TYPES BETWEEN SPLIT TUs: DEDUPE BY NAME, SKIP HEADER-PROVIDED, AND THE GUARD TRAVELS WITH THE BLOCK (P31 S67; ov_SC02_000, two defects fixed, one open) <sub>L30896</sub>
- **§327** — A RANGE TEST MUST BE HImode: WITH `s32` + A `(u16)` CAST GCC *PROVES* THE MASK REDUNDANT AND DROPS THE `andi` (P31 S67; byte-proven ov_SC02_039/func_8017EC34, 154 ins) <sub>L31009</sub>
- **§328** — THE VOLATILE ALIAS MUST BE AN *OBJECT*, NOT A CAST: `*(volatile s32*)&sym` UNFOLDS %lo INTO A SEPARATE `addiu` (P31 S67; byte-proven ov_SC07_007/func_80181B8C, 156 ins, NEW LAW) <sub>L31024</sub>
- **§335** — AN `extern u16 A[]` READ AT A VARIABLE SUBSCRIPT ALLOCATES DEAD STACK TEMPS (~8B PER ACCESS) THAT INFLATE THE FRAME WHILE EMITTING ZERO EXTRA INSTRUCTIONS (P31 S67; byte-proven ov_SC06_025/func_8017EA74, closeness 141 -> 20) <sub>L31140</sub>
- **§342** — A `void *` PARAMETER CAST TO ITS REAL TYPE IN A LOCAL IS **NOT** BYTE-NEUTRAL WHEN A LATER PARAMETER ALSO NEEDS A CALLEE-SAVED REGISTER (P31 S67; byte-proven ov_SC07_002/func_80181394, NEW LAW) <sub>L31257</sub>
- **§345** — A VOLATILE **STORE** EVICTS THE MEM FROM cse AND KEEPS `sh`; A VOLATILE **LOAD** BLOCKS combine AND DEGRADES `lh` INTO `lhu+sll+sra` (P31 S67; byte-proven ov_SC01_084/func_80181A7C) <sub>L31312</sub>
- **§351** — `/s` (MEM_IN_STRUCT_P) IS A DIAL YOU CHOOSE PER ACCESS: A COMPONENT_REF GRANTS IT AND LETS cse KEEP AN INDEX ACROSS THE STORE; A PLAIN CAST DENIES IT (P31 S67; ov_SC01_000/func_8017DD04, 186 -> 5) <sub>L31456</sub>
- **§378** — ★★★ — THE **SELF-CALLER CAST**: LET A TU KEEP CALLING THE FUNCTION IT IS ABOUT TO DEFINE (P31 S69; byte-proven ov_SC04_010/func_8017D6CC) <sub>L32114</sub>
- **§379** — ★★★ — **MEM_IN_STRUCT_P**: THE SAME LOAD, WRITTEN AS A STRUCT MEMBER, SCHEDULES WHERE A CAST CANNOT (P31 S69; byte-proven main/func_80021284 220 ins and main/func_8002D904 217 ins, found INDEPENDENTLY by two agents) <sub>L32164</sub>
- **§392** — ★★★ — THE SONNET-WAVE HARVEST (P31 S69): SEVEN TYPE/ORDER LEVERS THAT EACH CLOSED A MATCH <sub>L32502</sub>
- **§422** — ★★ — QImode ARITHMETIC VIA `(u8)(x - K)`, AND `flag ^ 1` NEEDS ITS OWN TEMP (P31 S71; byte-proven `resident/func_800D06E8`, 344 ins) <sub>L33760</sub>
- **§423** — ★★★ — "MATCH IN ISOLATION + GATE REJECTS + CAUSE NOT DETERMINED" ⇒ GREP THE TU FOR A FILE-SCOPE TYPEDEF THE DRAFT ALSO CARRIES (P31 S71; byte-proven `ov_SC03_092/func_8017FA74`) <sub>L33780</sub>
### declarations, prototypes & K&R (114)
- **§3-T4** — Branch polarity: invert the source condition to flip gcc's chosen branch <sub>L90</sub>
- **§8c** — Splitting a TU means rebuilding its DECLARATION ENVIRONMENT, not moving text (Phase 26 session 6) <sub>L456</sub>
- **§8d** — Templating a body INTO a TU must not CHANGE its declaration environment — demote the carried data externs (Phase 26 session 8, byte-proven on `func_8015AE2C` ×133) <sub>L502</sub>
- **§13** — Add a location overlay — the canonical runbook (Phase 13; the Phase-15 fleet recipe) <sub>L1075</sub>
- **§14c** — Callee-signature-aware harvest — breaking the extern-type-conflict wall (Phase 15, T6) <sub>L1232</sub>
- **§3-The** — pipeline gotcha — match_one ≠ the gate; `sig_unify` is MANDATORY <sub>L1440</sub>
- **§3-The** — gate two-stage — sig_unify is a FALLBACK, not unconditional (`gate_stage.py`, §19 folded in) <sub>L2208</sub>
- **§28** — Banking a "close=0 gate-rejected" giant: the canonical-extern recovery (Phase 22 T1, byte-proven on func_8015126C ×134) <sub>L2344</sub>
- **§28d** — The "macro-extern-injection" lever: freeing reach-134 inline matches dedup_propagate skips as "not self-contained" (Phase 23, `tools/inject_capped_externs.py`) <sub>L2385</sub>
- **§33** — Automating the giant decl-reconcile: `tools/reconcile_decls.py` (the DATA analog of §20's `cast_call_sites`) + a fleet-majority type oracle (Phase 24 T7b, byte-proven on `func_80129CF8`) <sub>L2453</sub>
- **§40a** — The DECL-RECONCILE pass (type-lift so remapped drafts compile in the sibling TU) (Phase 25 T7.2, 2026-07-08) <sub>L2620</sub>
- **§41** — The DEF-SIDE canonical-sig wall: mechanically banking a drafted giant past `conflicting types` (Phase 25 T5b batch-2, 2026-07-09; `tools/canon_sig_reconcile.py`, byte-proven on `func_8013B274`) <sub>L2729</sub>
- **§41b** — addendum — M4 "reconcile_decls" tier is ALSO a probe over-count: 0/8 mechanical (Phase 25 T7-M4, 2026-07-10) <sub>L2892</sub>
- **§41d** — `void`→`s32` is NOT always byte-neutral: gate the RAW draft FIRST (Phase 26 session 6, byte-proven) <sub>L2912</sub>
- **§43** — The K&R s16-param definition DISSOLVES the "narrow-param wall" for by-value register args (Phase 25 task A, Fable5 crack of the 369-ins giant `func_80166994` ×134, 2026-07-11) <sub>L3229</sub>
- **§51g** — When the thing you are scanning has a GRAMMAR, parse the grammar (`tools/cdecl.py`) <sub>L3803</sub>
- **§54** — `--fix-def-sig`: the member's CANONICAL DECLARATION is a build step too (tiny-IMM mega-pools, +4,801, Phase 29 T6, 2026-07-16) <sub>L4197</sub>
- **§56** — Banking a hand-drafted GIANT into its exemplar TU: self-contained draft vs live-TU decls, 4 reconciliation tactics (`func_8013FAF8`, 312 ins ×138, Phase 29 T4, 2026-07-17) <sub>L4221</sub>
- **§56b** — PROPAGATING an h_seq giant: the exemplar's externs MUST be fleet-canonical, not the draft's types <sub>L4266</sub>
- **§57** — The SELF-decl normalize: the sibling's OWN caller declares the templated fn divergently (the third §17a-1 direction; `tools/normalize_self_decls.py`, func_801670E4 ×137, Phase 29, 2026-07-18) <sub>L4290</sub>
- **§61** — Task 14: the gate ladder's missing stage is the ARITY pre-pass, and it is TU-side not draft-side (Phase 29, 2026-07-21) <sub>L4579</sub>
- **§63** — The fresh-138 DEF-SIDE blocker: fix the HEADER decl, not the draft (`fix_header_decl.py`, Phase 29 SESSION-13, 2026-07-23) <sub>L4911</sub>
- **§63** — UPDATE (Phase 29 SESSION-14) — `fix_header_decl`'s "SAFE" verdict is FLEET-BLIND; it MUST be R22-validated <sub>L5034</sub>
- **§65c** — `rtu_match` MATCH → bank held 13/13 on self-decl, but broke on the FIRST callee-decl case <sub>L5115</sub>
- **§65g** — Where the cheap levers STOP: the local-type and in-TU-self-decl classes did not yield <sub>L5173</sub>
- **§66a** — The widest write in a pipeline is the one most likely to be UNDECLARED <sub>L5215</sub>
- **§68** — A comment-only line halted the extern scan, and the skip label blamed the type cap (Phase 29 SESSION-18) <sub>L5558</sub>
- **§73** — A def-side self-decl conflict has TWO axes: RETURN (fleet widen, T2) and PARAMS (casts at each use, T0). Diagnose which before paying for the expensive one (Phase 29 SESSION-19, `func_8014F3E8` + `func_8014D4C0`) <sub>L5817</sub>
- **§75** — A propagation cap is usually a MINORITY-SPELLING SOURCE OVERLAY, not a wall: census the carried extern before believing the exclusion message (Phase 29 SESSION-19, `func_8014F3E8` ×4 → ×138) <sub>L5900</sub>
- **§75b** — A body's preamble can carry `#define`s, not just `extern`s; extraction lifts only the externs (Phase 29 SESSION-19, `func_80165CA0` ×3 → fleet) <sub>L5982</sub>
- **§75c** — Class-B's remedy is the FULL §17a-1 PAIR (decl **and** call-site cast); a decl-only fix moves the error and looks like a new wall (Phase 29 SESSION-19, `func_8012F14C`) <sub>L6031</sub>
- **§76** — The allocno CLASS (local vs global) is the dominant regalloc lever, and C reaches it ONLY through declaration scope and variable reuse (Phase 29 SESSION-19, behemoth #3 `func_8017F510` 1,511 ins, 97 → MATCH, pin-free) <sub>L6062</sub>
- **§79** — For a 0-callee giant, fingerprint by DATA symbols (§71 cannot fire); and the STACK-SLOT ORDER is a declaration-order oracle (Phase 29 SESSION-19, `func_8017BF14` 4,763 ins, cold start → 45/4763) <sub>L6254</sub>
- **§3-NEW** — LEVER — the frame layout reads back the original declaration order <sub>L6274</sub>
- **§3-1.** — The inlined-helper signature <sub>L6409</sub>
- **§92** — Conforming a DECLARATION: pointer changes are caller-neutral, scalar-WIDTH changes are not (Phase 29 SESSION-21, `tools/conform_decls.py`) <sub>L6925</sub>
- **§95** — `reconcile_tu` dropped the SIBLING declarators of a multi-symbol `extern` line (Phase 29 SESSION-21, `func_80176218`) <sub>L7017</sub>
- **§96** — The same rewrite, one shape down: `reconcile_tu` matched statements to lines by TEXT, so every COMMENTED declaration was silently skipped (Phase 29 SESSION-22, `func_80176218` banked) <sub>L7052</sub>
- **§98** — `conform_decls` had three defects, and only the third needed R22 to find (Phase 29 SESSION-22, `func_8014CF04`) <sub>L7147</sub>
- **§99** — The narrow-param wall is a DEF-side problem with a ZERO-blast-radius fix: convert the definition to K&R (Phase 29 SESSION-22, `func_80175AB8` + `func_80175DA8`) <sub>L7201</sub>
- **§102** — A PLUMBING verdict can MASK a DIFF; and K&R is not always a codegen change (Phase 29 SESSION-22, `func_8016EC0C`) <sub>L7306</sub>
- **§103** — A FILE-scope `extern` in a shared overlay TU is a GLOBAL constraint on every LATER function; move the DECL, not the draft (Phase 29 T48/T51, `func_80135260` — the fleet-wide half) <sub>L7341</sub>
- **§104** — Two silent-skip defects in one scan: match on MASKED text, emit from the ORIGINAL (Phase 29 T53, `gather_externs`) <sub>L7429</sub>
- **§112** — A macro-scoped declaration only collides where the macro is INSTANTIATED (Phase 29 T67/T69, `audit_header_sigs.py`) <sub>L7764</sub>
- **§113** — An ARITY blocker only exists if the macro CALLS the function; an address-taken use has no call site (Phase 29 T72) <sub>L7810</sub>
- **§114** — The THIRD decl axis: a CALLEE the draft declares differently from the target TU (Phase 29 T76/T77) <sub>L7842</sub>
- **§3-Do** — NOT "strip the duplicate typedef" — it breaks the extern that uses it <sub>L8071</sub>
- **§121** — Synthesise externs for macro-DEFINED callees from the macro's own definition head (Phase 29 T95) <sub>L8095</sub>
- **§3-The** — declaration surface (integration, not codegen) <sub>L8975</sub>
- **§136f** — Two declaration sub-cases the reconcile lane surfaced (lane now 15/15 lifetime) <sub>L9220</sub>
- **§138** — The propagation lanes: a gate refusal is a DECLARATION, and which lever you owe depends on blast radius <sub>L9449</sub>
- **Reconciling** — a gate-refused draft: which way you edit depends on WHERE the TU's decl is <sub>L9599</sub>
- **§141** — The §134 class is CLOSED: every line-shape decision now routes through `cdecl._mask` (P30 S39) <sub>L9774</sub>
- **§143** — `cast_call_sites` read a RETURN STATEMENT as a prototype and deleted it. A 0/39 sweep became 18/39. (P30 S40) <sub>L9868</sub>
- **§3-C.** — Inner-block declaration does NOT delay slot allocation — BYTE-REFUTED <sub>L10102</sub>
- **§159** — THE DECLARATION AXIS: conform to byte-truth, and make every guard state its COVERAGE (P30 S47; ~10,930 sites across 8 axes, fleet byte-identical) <sub>L10862</sub>
- **§168** — THE COUSIN TIER (P30 S49, 2026-08-12): h_seq's exact-hash brittleness, measured — and the similarity map above it <sub>L16265</sub>
- **§176f** — THE DECLARATION FORM IS A MATCHING LEVER, SO RECONCILE TOWARD THE FORM THE MATCH NEEDS (P31 S52) <sub>L16963</sub>
- **§183** — THE DECLARATION-RECONCILIATION PLAYBOOK (P31 S53, measured on 20 byte-verified drafts) <sub>L18002</sub>
- **§193-H** — A pointer-derived base load `*(s32*)(p+K)` is uncacheable across ANY memory write or call (cse's third kill disjunct) — so the target emits one `lw` per store-separated RUN of spellings, and a run of stores sharing one `lw` is a C local you must declare <sub>L18848</sub>
- **§193-I** — A DECLARED AGGREGATE LOCAL HAS AN 8-BYTE FRAME STRIDE — CEIL(size,8), NOT size. N ARRAYS THEREFORE COST 8·k MORE THAN ONE HAND-LAID STRUCT (k = how many of them have size mod 8 ≠ 0), AND THE TELL IS IDENTICAL INSTRUCTION COUNT WITH EVERY $sp DISPLACEMENT SHIFTED BY THE SAME CONSTANT. <sub>L18888</sub>
- **§194-B** — A `addu $rA,$rB,$zero` copy feeding ≥2 `sh` stores is a SECOND, 16-BIT-DECLARED local — the width, not the clamp or the join liveness, is what keeps the copy (and func_80183094's pin + `"memory"` clobber are both provably inert) <sub>L19057</sub>
- **§194-D** — Declared width of a computed-value local is a sched1 dial (count-neutral) — a replication + attribution correction of §165-17, NOT a new argument-register law <sub>L19158</sub>
- **§195-A** — §167-08's "an $aN READ before the jal is scratch" has a byte-proven FALSE-NEGATIVE class: an argument that DIES at the call is allocated straight into $aN, so its only def is a plain load far above the jal and every intervening use reads $aN — there is no positive tell in either direction, only the two-arity A/B <sub>L19764</sub>
- **§195-C** — A call-argument `%hi/%lo` pair sitting at the block head, far above its `jal`, is a load-delay-gap filler chosen by SOURCE STATEMENT ORDER — swap the two independent statements nearest the call; a single-use `void *p = &SYM;` call-arg temp is OUTPUT-inert against it (but NOT expand-stream-inert) <sub>L19877</sub>
- **§195-D** — §195 — `masked_diff.mask_for` returns 0 for EVERY `j`/`jal` word, so an internal `j` destination is invisible to match_one, the permuter scorer AND every similarity tier: a control-flow semantic error (which calls execute) surfaces as a 1-instruction residual mislabelled `DELAY-SLOT / profile=schedule`, or as an outright false MATCH <sub>L19925</sub>
- **§195-F** — fold-const.c:4825 canonicalises a `?:` whose THEN arm is zero (or constant against a non-constant ELSE) by inverting the condition and swapping the arms — so a ternary's written arm order is byte-inert there, and `c ? 0 : X` is unspellable: it always compiles as `!c ? X : 0` <sub>L20051</sub>
- **§195-G** — §NEW — TWO ARMS CALLING THE SAME CALLEE MERGE INTO ONE `jal` UNLESS EACH ARM'S OWN CODE CONSUMES THE RESULT: the C dial that keeps two call sites apart is WHERE the consumer test lives, and the branch SENSE you spell it with is byte-inert (jump.c:1737 canonicalises it) <sub>L20103</sub>
- **§195-H** — §165-27g — ON A FIXED-SYMBOL GLOBAL, `extern T D[];` + `D[0]` IS THE CSE RELOAD DIAL, AT ZERO ADDRESSING COST, AND THE ELEMENT COUNT IS INERT (§165-27's `T v[2]` CAVEAT IS A LOCAL-FRAME FACT AND DOES NOT TRANSFER) <sub>L20151</sub>
- **§196** — PUT ON THE CARD WHAT THE TREE ALREADY KNOWS: the fleet's declaration consensus (P31 S54) <sub>L20553</sub>
- **§199-D** — A narrow UNSIGNED value compared in an ordered `if` emits `sltiu`/`sltu`; the only dial is the WIDTH of a real object, and a widening `(s32)` cast is inert — AMENDS §35 (whose stated "only CSE-reuse canonicalizes" mechanism is byte-wrong) and does NOT apply inside a `switch` <sub>L20901</sub>
- **§199-G** — At TWO case nodes the switch-vs-if oracle is not blind — but the tell is ALL tests positive + a trailing `j default`, NOT the first test's polarity <sub>L21074</sub>
- **§200** — THE ALIAS IS THE UNIVERSAL DECLARATION ESCAPE: stop negotiating with the TU's spelling (P31 S55) <sub>L21140</sub>
- **§201-A** — §150-B applies to `decl_prior`'s DEF row: for an overlay-window symbol the banked "definition" is usually another overlay's function, and the card ranks it ABOVE the destination TU <sub>L21199</sub>
- **§201-D** — THE SIGNEDNESS OF A div/mod MAGIC IS DECIDED BY THE STATIC TYPE OF THE DIVIDEND TREE AFTER `get_narrower` STRIPS WIDENING CONVERSIONS — NEVER BY A PROVABLE RANGE. AN `& 0xFF` IS NOT A CONVERSION, SO IT NEVER FLIPS THE MAGIC; A DECLARED-UNSIGNED LOCAL *OR* A NARROWING CAST WRITTEN AT THE DIVIDE BOTH DO. <sub>L21362</sub>
- **§202** — THE ALIAS CARRIES A DEFINITION, NOT JUST A DECLARATION: the DEF-SIDE-RETURN wall (P31 S56) <sub>L21490</sub>
- **§204-C** — WHEN A LOCAL BUFFER'S ADDRESS IS PASSED TO A CALL, ITS SIZE IS A FACT ABOUT THE CALLEE'S BODY, NOT ABOUT THE CALL SITE: grep the callee's proven definition and count the stores through the pointer parameter before you declare the local <sub>L21746</sub>
- **§204-E** — `decl_prior`'s `%hi/%lo` ARM HAS NEVER FIRED: the card's promised GLOBAL-TYPE row is 0 of 1,210 <sub>L21879</sub>
- **§208** — TWO NAMED LOCALS FOR ONE RELOADED EXPRESSION BUY TWO ALLOCNOS — the naming granularity owns the REGISTER SPLIT, not just the load count (P31 S58) <sub>L22243</sub>
- **§214** — THE BANKED TWIN MAY BE A MACRO, A DELETED `.s`, OR A SEMANTIC INVERSE — six ways a ≥0.9 similarity lies (P31 S58) <sub>L22555</sub>
- **§216** — DISTINCT ADJACENT SCALARS vs ONE ARRAY: one `lui` per access is the tell, and the array decl is UNUSABLE (P31 S58) <sub>L22657</sub>
- **§220** — THE PARAMETER ITSELF IS A REGALLOC DIAL: use it directly, prefer `s32` to `void*`, and place the save-copy AFTER the first call (P31 S58) <sub>L22779</sub>
- **§224** — CROSS-JUMP: WRITE THE DUPLICATE, AND READ A SHARED DELAY SLOT AS THE MERGE SIGNATURE (P31 S58) <sub>L22939</sub>
- **§236** — THE DECLARATION LAYER IS THE DOMINANT BANK-BLOCKER: NINE WAYS A BYTE-PERFECT BODY FAILS THE GATE (P31 S58b) <sub>L23427</sub>
- **§243** — SPELL THE CSE BARRIER AS A REASSIGNED POINTER; AND THE `nop`-AFTER-EVERY-`lh` SIGNATURE (P31 S58b) <sub>L23721</sub>
- **§250** — `%hi/%lo` vs `lw`: THE EXTERN'S ARRAY-vs-SCALAR SHAPE DECIDES ADDRESS MATERIALISATION (P31 S58b) <sub>L23973</sub>
- **§214** — addendum (P31 S58b) — FOUR MORE WAYS A HIGH-SIMILARITY TWIN LIES <sub>L24388</sub>
- **§226** — addendum (P31 S58b) — THE FRAME CATALOGUE: SEVEN MORE LEVERS, AND SLOT ORDER IS DECLARATION ORDER <sub>L24617</sub>
- **§263** — A STOLEN DELAY SLOT WHOSE INSTRUCTION IS AN ARG-REGISTER COPY IS AN ARITY ERROR, NOT A SCHEDULE (P31 S59, byte-proven) <sub>L24927</sub>
- **ADD-10** — → §237 addendum (arity-evidence paragraph) — AN `la` PAIR ABOVE THE PROLOGUE `sw $ra` IS AN OUTGOING-ARGUMENT MATERIALISATION <sub>L25225</sub>
- **ADD-2** — → §236 addendum (item 1 corollary) — THE SILENT-SPLICE DECLARATION LADDER: WHERE THE TU HAS NO SPELLING, UNPROTOTYPED `()` BEATS THE FLEET VOTE <sub>L25367</sub>
- **§272** — The `(void)`-decl + empty-call wall: K&R the DEFINITION, not just the decls (P31 S59) <sub>L25599</sub>
- **ADDENDUM** — to §20 — a global declared as `T *` may itself BE the array base, not a pointer to dereference <sub>L25820</sub>
- **ADDENDUM** — to §172b-1 — TWO PLACEMENT DIALS THE PROMOTION LAW DOESN'T NAME: NARROW THE COUNTER'S DECLARED TYPE, AND MOVE THE CAST INTO THE LOOP BODY <sub>L26100</sub>
- **§280** — THE CURSOR'S DECLARED TYPE PICKS `sltu` vs `slt`: a `T*` bound test is UNSIGNED by C rule, an integer cursor is signed (P31 S60; wave cf, func_800CAE74, md_MAIN_031, byte-proven) <sub>L26956</sub>
- **ADDENDUM** — to §202 — the DEF-SIDE ALIAS also resolves a function-vs-DATA-symbol identifier clash, not only a function-vs-function prototype clash <sub>L27203</sub>
- **ADDENDUM** — §NNN — sharpens §37/§124 (unspecified-parameter-list family): DERIVE A CALLEE'S ARITY LOWER BOUND FROM ITS OWN `.s` STACK-ARGUMENT READS, NOT FROM ANY SINGLE CALL SITE <sub>L28326</sub>
- **§288** — A REGISTER PIN DECLARED UNINITIALIZED AND ASSIGNED ONLY AT ITS LATE, SOLE USE STILL FORCES THE FIXED REGISTER'S SAVE/RESTORE, AND THE ASSIGNMENT'S SOURCE POSITION CONTROLS WHERE THE VALUE MATERIALIZES (P31; `func_80186530`, ov_SC02_017, byte-proven, match_one MATCH re-verified) (P31 S60; waves #, byte-proven) <sub>L29090</sub>
- **§292** — DECLARING A SYMBOL UPSTREAM OF AN ALREADY-BANKED SIBLING THAT RELIES ON THAT SYMBOL'S IMPLICIT (K&R) DECLARATION CAN SILENTLY REPROTOTYPE THE SIBLING'S OWN CALL SITE (P31 S60; waves #, byte-proven) <sub>L29106</sub>
- **Addendum** — Counter zero in the DECLARATION slot, empty for-init — the prologue SHIFT-DRIFT/+K face of (func_8018275C) <sub>L30725</sub>
- **§324** — THE ARITY-SELF WALL NEEDS *BOTH* HALVES: A K&R DEFINITION **AND** A NO-PROTO TU DECL; EITHER ALONE STILL FAILS (P31 S67; rtu-proven ov_SC01_005/func_8017FBCC, 14 instances measured) <sub>L30949</sub>
- **§333** — FRAME SIZE IS SET BY *DECLARED* AGGREGATES, NOT USED ONES: AN UNREFERENCED TRAILING LOCAL IS A REAL DIAL (P31 S67; three independent byte-proven instances in one wave) <sub>L31115</sub>
- **§335** — AN `extern u16 A[]` READ AT A VARIABLE SUBSCRIPT ALLOCATES DEAD STACK TEMPS (~8B PER ACCESS) THAT INFLATE THE FRAME WHILE EMITTING ZERO EXTRA INSTRUCTIONS (P31 S67; byte-proven ov_SC06_025/func_8017EA74, closeness 141 -> 20) <sub>L31140</sub>
- **§342** — A `void *` PARAMETER CAST TO ITS REAL TYPE IN A LOCAL IS **NOT** BYTE-NEUTRAL WHEN A LATER PARAMETER ALSO NEEDS A CALLEE-SAVED REGISTER (P31 S67; byte-proven ov_SC07_002/func_80181394, NEW LAW) <sub>L31257</sub>
- **§343** — `decl_prior`'s FLEET MAJORITY CAN BE WRONG ABOUT THE TRUE SIGNATURE — READ THE RIVALS, NOT JUST THE WINNER (P31 S67; measured on func_8012BD14 / func_8012D624 / func_80143C74) <sub>L31274</sub>
- **§347** — LOOP REGISTER ASSIGNMENT IS A **DECLARATION-ORDER + LIVE-RANGE** DIAL: FIVE COMPOSABLE LEVERS, 178 -> 0 (P31 S67; byte-proven ov_SC06_029/func_8017EF34, 243 ins) <sub>L31342</sub>
- **§343-addendum** — SECOND INSTANCE OF THE WRONG-MAJORITY DECL (same function) <sub>L31390</sub>
- **§354** — THE giv **WORTH-WHILE TEST** IS A DIAL: RE-ASSOCIATE THE ADDEND INTO THE INDEX TERM AND `strength_reduce` DECLINES (P31 S68; byte-proven ov_SC03_105/func_801824CC, 320 ins, 201 → 5 → 0) <sub>L31542</sub>
- **§361** — ★ — A LOOP-TAIL BYTE SIGNATURE THAT NAMES ITS SOURCE SHAPE — AND THE LAW THAT A "SCHEDULING TIE" MAY BE YOUR OWN EARLIER LEVER (P31 S68; byte-proven main/func_800241C0, fable escalation, 19 → 0 in 3 iterations) <sub>L31637</sub>
- **§367** — RECONCILING A DECL CONFLICT BETWEEN TWO DRAFTS FOR THE SAME TU (P31 S68; main) <sub>L31777</sub>
- **§378b** — ★★★ — THE FOUR VARIANTS OF THE DECL BLOCKER, AND THE TWO PLACES §378 DOES **NOT** APPLY (P31 S69, all four measured the same day) <sub>L32572</sub>
- **§378c** — ★★ — THE FIFTH DECL-BLOCKER VARIANT: THE DRAFT REDECLARES WHAT THE TU ALREADY OWNS (P31 S69) <sub>L32722</sub>
- **§398** — ★★★ — `family_remap` CARRIES THE **SOURCE** TU's DECL ENVIRONMENT INTO A DESTINATION THAT ALREADY OWNS THOSE NAMES (P31 S69; measured 3 banked of 22) <sub>L32835</sub>
- **§415** — ★★ — A FILE-SCOPE DECL MAKES gcc-2.7.2 MERGE THE TU'S LATER *BLOCK-SCOPE* EXTERNS INTO IT (P31 S71; byte-proven `ov_SC04_011/func_80180B24`, 215 ins) <sub>L33547</sub>
### jump tables & switches (61)
- **§8** — rodata island (compiler jump tables) — the `.data→.rodata→.data` sandwich (Phase 7) <sub>L339</sub>
- **§8a** — rodata island in a flat OVERLAY — the tail sandwich, per matched jr-function (Phase 26 — PoC PROVEN) <sub>L361</sub>
- **§8a-pad** — a trailing `.word 0x00000000` under a jtbl dlabel is `.align` PAD, not an entry (Phase 26 session 6, byte-proven) <sub>L399</sub>
- **§8b** — MULTI-jtbl per overlay — the `ld_interleave --order` sandwich + the same-subseg cases (Phase 26 session 4) <sub>L423</sub>
- **§8e** — The jtbl ALIGNMENT LAW + the pad-spec filter — multi-table .rodata spans (Phase 29, byte-proven; `.run/probe_jtbl/verdict.md`) <sub>L549</sub>
- **§3-The** — clean object-level metric (use this, not the permuter score, for jtbl/rodata functions) <sub>L863</sub>
- **§41b** — T7 execution: the object-only probe OVER-counts BANKABLE by two link/rodata classes (Phase 25 T7-M1, 2026-07-10) <sub>L2843</sub>
- **§48** — The 12-core jr crack wave: the ALLOCNO-PRICING dials and the EBB rule (Phase 26 session 8, Ultracode, 9/12 MATCH first pass) <sub>L3439</sub>
- **§53** — SWEEP A FAMILY WITH THE TOOL ITS EXEMPLAR NEEDED: the jr/switch carve, and how omitting it manufactured the "families don't template" doctrine (Phase 28 T1, 2026-07-15) <sub>L4062</sub>
- **§61b** — The jtbl gate stage: built, and the ORDERING law it exposed (Phase 29 Task-14 stage 4, 2026-07-21) <sub>L4692</sub>
- **§61c** — The jtbl bank is INCREMENTALLY valid and CLEAN-INVALID (Phase 29, 2026-07-21) — the blocking finding <sub>L4747</sub>
- **§62** — The jtbl RECONCILE must also follow the carve: the post-carve draft reconcile (`harvest_verify._jtbl_reconcile`, Phase 29 SESSION-11, 2026-07-22) <sub>L4867</sub>
- **§81** — Banking a jr (jump-table) function: the 3-step carve chain, and why `match_one` cannot see the problem (Phase 29 SESSION-19, `func_8017C954`) <sub>L6357</sub>
- **§88d** — BANKING ORDER: run the §81 carve chain BEFORE banking, never after <sub>L6735</sub>
- **§97** — The gate's own tree hygiene: a refused carve, an unchecked recovery, and a snapshot that captured a dirty tree (Phase 29 SESSION-22) <sub>L7100</sub>
- **§105** — A gate's revert must survive an EXCEPTION, not just a failure (Phase 29 T53, `jtbl_family_bank`) <sub>L7465</sub>
- **§125** — Split the CARVE from the BODY before calling a jr residue a wall — and measure it by SHA from a CLEAN tree (P30 SESSION-28; **this section's first draft was WRONG and the method caught it**) <sub>L8240</sub>
- **§126** — The carve-within-a-carve: an ADDRESS RANGE is not an OPTIMIZATION REGION (P30 T2, byte-proven end-to-end) <sub>L8298</sub>
- **§129** — Post-carve, `rtu_match`/`match_one` COUNT THE JUMP TABLE AS INSTRUCTIONS; and a carve must never be committed without its owner (P30 S28, `func_8013BD74`) <sub>L8471</sub>
- **§129a** — the target instruction count is INFLATED after a carve <sub>L8475</sub>
- **§129b** — never commit a carve whose owner is still a stub (it strands the carve) <sub>L8496</sub>
- **§130** — An INCREMENTAL build can report BYTE-IDENTICAL for a change the CLEAN build cannot even LINK (P30 S28, the jr pair) <sub>L8520</sub>
- **§131** — The jtbl OVER-SPAN: `sltiu N` is ground truth in BOTH directions, and the zero-word rule only guards one (P30 S28, `func_80191C50`) <sub>L8567</sub>
- **§132** — The `JR-PAIR-IN-ONE-O0-OBJECT` "wall" was TWO instrument defects: a merged-double span the carve could not see, and a truncated object no rule deleted (P30 S29, `func_8013B83C` + `func_8013BD74`) <sub>L8604</sub>
- **§132b** — When the span's already-matched owner is ITSELF multi-switch: `--span-rel` (P30 S1, `func_8014032C`) <sub>L8694</sub>
- **§139** — A GATE THAT GREPS FOR VERDICTS MUST ASSERT 1:1 ACCOUNTING; and a `--src` filter must not survive a carve (P30 S38, wave 6: 10 of 16 drafts vanished) <sub>L9628</sub>
- **§161** — THE RETRY-WAVE HARVEST: a jump table indexed from zero, and two allocator traps (P30 S47) <sub>L11003</sub>
- **§179-F** — PINNING A LOOP-WALKED POINTER IS A TOTAL OFF-SWITCH FOR STRENGTH REDUCTION <sub>L17573</sub>
- **§188** — 🔴 THE `jr $ra` + `addiu $sp` TAIL IS AN **ASSEMBLER** ARTIFACT, NOT A FRAME SHAPE <sub>L18217</sub>
- **§199-D** — A narrow UNSIGNED value compared in an ordered `if` emits `sltiu`/`sltu`; the only dial is the WIDTH of a real object, and a widening `(s32)` cast is inert — AMENDS §35 (whose stated "only CSE-reuse canonicalizes" mechanism is byte-wrong) and does NOT apply inside a `switch` <sub>L20901</sub>
- **§199-G** — At TWO case nodes the switch-vs-if oracle is not blind — but the tell is ALL tests positive + a trailing `j default`, NOT the first test's polarity <sub>L21074</sub>
- **§206** — THE JTBL-CARVE DRAFTING IDIOM: the bounds check is the entry count, and an EMPTY case owns a slot (P31 S56) <sub>L22153</sub>
- **§222** — SWITCH vs IF-CHAIN, PART 3: source arm order IS emission order, a leading EMPTY case buys the median split, and a 2-way dispatch with a shared post-block is a `switch` (P31 S58) <sub>L22835</sub>
- **§232** — WHEN THE `jr` DELAY SLOT'S STORE STORES THE RETURN VALUE, TIE THEM WITH ONE PSEUDO **(single observation — not yet cross-confirmed)** (P31 S58) <sub>L23221</sub>
- **§256** — GOTOS IN THE TARGET'S BLOCK ORDER REPRODUCE SWITCH PLACEMENT WITHOUT SWITCH'S SIDE EFFECTS (P31 S58b) <sub>L24114</sub>
- **§222** — addendum (P31 S58b) — IF-CHAIN vs SWITCH: THREE MORE DISCRIMINATORS <sub>L24518</sub>
- **§260-A** — STAGE 2 IS PROVEN, AND THE WHOLE jtbl PIPELINE IS AUTOMATED AT THE GATE (P31 S59, same day) <sub>L24813</sub>
- **ADDENDUM** — to §8 — WHEN `INCLUDE_RODATA` NEEDS A STANDALONE `.s` YOU CAN'T CREATE, CARRY THE FRAGMENT AS A FILE-SCOPE `__asm__` BLOB <sub>L26222</sub>
- **ADDENDUM** — §NNN — sharpens §55a / §164-37 / §165-28 (switch-vs-tree cluster): A SHAPE THAT LOOKS LIKE A SWITCH DISPATCH CAN BE PLAIN NESTED `if`s WHOSE SHARED BODY WAS TRIPLICATED BY THE SOURCE AND THEN CROSS-JUMP-MERGED BACK DOWN <sub>L28223</sub>
- **ADDENDUM** — §NNN — sharpens §162a3/§60b: A `sll $v0,16 / sltiu $v0,1` ZERO-TEST OF A JUST-DECREMENTED HALFWORD IS A SIGNED-TEMP WIDTH TELL OUTSIDE ANY SWITCH/RANGE-TEST CONTEXT <sub>L28293</sub>
- **§295** — THE KERNEL-TRAP STUB: §81's jr-DETECTOR WITHOUT A TABLE IS A PsyQ SYSCALL TRAMPOLINE — ROUTE TO §265, NEVER INTO THE CARVE CHAIN (P31 S61; wave m0a, 9 cards byte-proven; resolves §182's held cluster) <sub>L29401</sub>
- **§298** — THE SHARED-TAIL POSITION DIAGNOSTIC: A FOLDED TAIL *BETWEEN* SWITCH ARMS MEANS PER-ARM DUPLICATED STATEMENTS, NOT A HOISTED POST-SWITCH STATEMENT (P31 S61; waves g0e/g0f, `func_80181B68`, ov_SC06_016, byte-proven 68/68) <sub>L29542</sub>
- **§302** — A RED BINARY IS A DRIFTED SPEC, NOT A MYSTERY: THE THREE CARVE-STATE INVARIANTS AND HOW TO DERIVE EACH FROM THE BYTES (P31 S62 T2; five reds healed in one session, 5/5, +39 held banks) <sub>L29719</sub>
- **§304** — SELF-DEFINING RODATA: WHEN A FUNCTION'S `.s` IS THE ONLY OWNER OF THE DATA IT REFERENCES, THE C BODY MUST DEFINE IT (P31 S62 T3; byte-proven md_MAIN_011/func_800D04F4) <sub>L29799</sub>
- **§305** — "CARVE-REFUSED" AT GATE TIME IS THREE NAMED, DETERMINISTIC CLASSES — NONE OF THEM A CARVE (P31 S62 T3; 28 resolver drafts autopsied 28/28) <sub>L29822</sub>
- **§308a** — A TWO-INSTRUCTION ARM STUB LAID *BEFORE* THE OTHER ARM AND REACHED ONLY BY A TRAILING `j` SURVIVES ONLY BEHIND A SHORT-CIRCUIT `&&` GUARD PLUS A SEPARATE RE-TEST; EVERY PLAIN if/else-if, GOTO-LADDER, NESTED-INVERTED-if AND 1-/2-NODE switch LETS jump1 INLINE IT (−2 ins) (P31 S63 t5e-t5i; byte-proven func_80180808) <sub>L30012</sub>
- **REFUTED** — claim — REFUTED: a block shared across TWO switch statements is ordinary forward cross_jump, not a (func_8001B0D4) <sub>L30638</sub>
- **§NNN** — REFUTED: A CODE BLOCK SHARED BY TWO *DIFFERENT* SWITCH STATEMENTS IS ORDINARY FORWARD `cross_jump`, NOT A SHAPE C CANNOT REACH — §164-11 ALREADY BANKS IT FROM PLAIN NESTED SWITCHES (P31 S66 round3, `func_8001B0D4`; ⚠ **UNPROVEN** — gate-REFUSED draft, closeness 68→45, never MATCHed) <sub>L30640</sub>
- **§322** — A PROBE THAT ANSWERS A *NECESSARY BUT NOT SUFFICIENT* QUESTION WILL PRICE BLOCKED WORK AS FREE: RUN THE REAL PLANNER WHEN THE PLANNER IS PURE (P31 S67; measured, 96 of 159 open jtbl functions) <sub>L30866</sub>
- **§338** — `jtbl_carve._sltiu_bounds` MISREADS A NON-SWITCH `sltiu` AS A BOUNDS CHECK, OVER-SPANNING THE TABLE (P31 S67; ov_SC06_022/func_80185B80, byte-diagnosed) <sub>L31171</sub>
- **§339** — A 2-CASE SWITCH OMITS THE LOW-BOUND RANGE TEST, SO THE PRESENCE OF `slti/bnez` BETWEEN THE `beq`s IS A **COUNT TELL** FOR A THIRD CASE NODE (P31 S67; byte-proven ov_SC02_005/func_80190538, 197 ins) <sub>L31181</sub>
- **§362** — TWO TRAPS WHEN A CARVE MOVES A STUB INTO THE `-O0` TU (P31 S68; byte-proven, 6 fns / 2,547 ins across ov_MAIN_012 / ov_SC02_037 / ov_SC03_107) <sub>L31682</sub>
- **§371** — ★★ — CARVING A **SINGLE-OBJECT MODULE BINARY**, AND THE spimdisasm RODATA-MIGRATION TRAP THAT FOLLOWS (P31 S68; byte-proven md_MAIN_003, func_800D0D6C 345 ins) <sub>L31890</sub>
- **§384** — ★★★ — A CARVE-CONFIG BANK IS RED UNTIL YOU RE-EXTRACT, AND THAT LOOKS EXACTLY LIKE A FALSE BANK (P31 S69; measured twice, cost one destroyed match) <sub>L32259</sub>
- **§387** — ★★ — **SPLIT-FOLD DISPATCH CLOBBER**: one switch case needs a reload, another must keep the fold (P31 S69; byte-proven main/func_80030F80, 343 ins, escalation 3 → 0) <sub>L32361</sub>
- **§322b** — ★★★ — THE CARVE CLASS IS COMPLETABLE, AND EVERY WORKTREE `CARVE-REFUSED` WAS AN INSTRUMENT VERDICT (P31 S69, Fable-3 audit; byte-proven end-to-end) <sub>L32667</sub>
- **§3-A.** — THE ORACLE HAS A HOLE: match_one cannot see a jump table (§405-A) <sub>L33098</sub>
- **§412** — ★★★ — §323 CARVE BLOCKER 2 WAS A REGEX THAT COULD NOT SEE PAST `__attribute__` (P31 S71) <sub>L33424</sub>
- **§426** — ★★★ — main's SWITCH FUNCTIONS WERE NEVER A CODEGEN WALL: ONE RODATA CARVE HAD BEEN MISSING SINCE PHASE 7 (P31 S72; 3 of the 11 "PROVEN gate-rejects" banked byte-identical in 14 s) <sub>L33855</sub>
- **§428** — ★★★ — A ZERO-BYTE CROSS-JUMP BARRIER: ADVANCE THE POINTER INSIDE EACH SWITCH ARM (P31 S72; `main/func_80026D64`, 218 ins, MATCH in 2 compiles) <sub>L33950</sub>
- **§431** — ★★★ — SPLITTING A 27,000-LINE TU AT ITS ORIGINAL BOUNDARIES: THE JTBL SPANS TELL YOU WHERE, AND THE COMPILER TELLS YOU WHAT CROSSES (P31 S72; `src/800.c` -> `800.c`/`800_b.c`/`800_c.c`, byte-identical with nothing banked) <sub>L34061</sub>
### optimisation level (-O0/-O2) (22)
- **§6** — Per-module optimization mixing — the -O0 boot module (Phase 7) <sub>L265</sub>
- **Detecting** — the opt level (do this first) <sub>L273</sub>
- **Build** — mechanism — per-file opt override (splat resegmentation) <sub>L307</sub>
- **§18** — Per-file `-O0` split inside an overlay/blob (Phase 19 T1) <sub>L1538</sub>
- **§38** — The WHALE `func_80144B9C` (770 ins): the -O0 struct-assign memcpy idiom + the -O0 reach-134 ×134 rollout (Phase 24 T7 §G, cheap Opus — no Fable5, no calls.c) <sub>L2546</sub>
- **§39** — The ×1→×134 giant-endgame: propagate a matched **-O2** giant via the NATIVE DEFINE-macro path (Phase 24 T7 §G close, 2026-07-08) <sub>L2556</sub>
- **§116** — Optimization level is a property of the FILE, not the function: read a family 0/N against the member's stub HOME (Phase 29 T79) <sub>L7911</sub>
- **§3-The** — finding: opt level is per FILE, so the file's contents must be opt-HOMOGENEOUS <sub>L8313</sub>
- **§127** — The `-O0` regime: the CONSTANT-OFFSET FOLD, and why `-O0` needs its own idiom set (P30 T3 wave, 15 targets) <sub>L8383</sub>
- **§3-The** — rest of the `-O0` regime (write PLAIN C, and mean it) <sub>L8401</sub>
- **§127a** — §71 (sibling-first) is the strongest `-O0` lever, and it beats the index <sub>L8411</sub>
- **§132** — The `JR-PAIR-IN-ONE-O0-OBJECT` "wall" was TWO instrument defects: a merged-double span the carve could not see, and a truncated object no rule deleted (P30 S29, `func_8013B83C` + `func_8013BD74`) <sub>L8604</sub>
- **§195-K** — At -O2 the §18 array-of-struct lever is a FRAME lever, not a length lever — but only when the N reads carry DISTINCT index expressions; with a SHARED index §18's +2-instruction residual is still alive at -O2 (the submitted "memory-loaded narrow index" precondition and unconditional length-neutrality are both falsified) <sub>L20307</sub>
- **§261** — THE -O0 ORACLE: DERIVE THE OPT LEVEL FROM THE TARGET, AND `$fp` IS NOT THE TELL (P31 S59) <sub>L24849</sub>
- **§261a** — THE -O0 FRAME-RELOAD GRAMMAR: reload COUNT disambiguates the C spelling (P31 S59, byte-proven) <sub>L24875</sub>
- **§265** — THE VERBATIM-ASM BANK LANE: A FUNCTION NO -O2 C CAN EVER MATCH BANKS AS A RAW `__asm__` BODY (P31 S59b; two banked cards, two in-tree precedents) <sub>L25018</sub>
- **ADDENDUM** — to §127 — the -O0 constant-offset fold keys on the MEMBER-ACCESS tree shape, not on the index being constant <sub>L29170</sub>
- **ADDENDUM** — to §261a — FOUR MORE -O0 DIALS BEYOND THE RELOAD COUNT (boot.c + md_MAIN_011/003, wave m0a/g0a/g0f, byte-proven) <sub>L29198</sub>
- **Addendum** — Addendum to §261a — the -O0 increment-operator copy also fires on the POINTER LOCAL itself (func_8001212C) <sub>L30473</sub>
- **Addendum** — Addendum to §164-XX/§165-06 — at -O0 a bare local IS a memory lvalue, so the increment ope (func_8001212C) <sub>L30477</sub>
- **§362** — TWO TRAPS WHEN A CARVE MOVES A STUB INTO THE `-O0` TU (P31 S68; byte-proven, 6 fns / 2,547 ins across ov_MAIN_012 / ov_SC02_037 / ov_SC03_107) <sub>L31682</sub>
- **§388** — ★★★ — THE **-O0 COLOURING ORACLE**: simulate `stupid.c` instead of grinding spellings (P31 S69; main/func_80011380 proved a C-level WALL at 6) <sub>L32384</sub>
### family propagation & sweeps (122)
- **§8d** — Templating a body INTO a TU must not CHANGE its declaration environment — demote the carried data externs (Phase 26 session 8, byte-proven on `func_8015AE2C` ×133) <sub>L502</sub>
- **§11** — Cross-binary dedup & code-sharing (Phase 11 — "one match unlocks many") <sub>L927</sub>
- **§3-The** — mechanism: game-code dedup is SOURCE-LEVEL, not an object swap (R-D1, the key lesson) <sub>L945</sub>
- **§3-The** — flat-blob overlay config (what the template encodes) <sub>L1090</sub>
- **§3-THE** — NON-4-ALIGNED-OVERLAY GOTCHA (≈75% of the fleet; fixed in the template + Makefile, automatic) <sub>L1098</sub>
- **§14** — Propagate a matched function across the fleet — `tools/dedup_propagate.py` (Phase 15) <sub>L1145</sub>
- **§19** — Scaling the toolkit waves — the recovery PIPELINE + the propagation CAP (Phase 19 T3) <sub>L1616</sub>
- **§24** — The `ov_SC01_077_a.c` split-file vein: split-aware propagation, but loose-typing-gated (Phase 21) <sub>L2104</sub>
- **§25** — The "schedule" class is mostly COALESCING (pin-crackable), not scheduling; + the gate two-stage + h_exact over-counts ×134 (Phase 21, cont.6) <sub>L2151</sub>
- **§3-h** — _exact OVER-COUNTS ×134 — verify shareability before crediting a class's "reach-134" (R14) <sub>L2196</sub>
- **Where** — this leaves the reach-134 tail (cont.6 option-3, now CONFIRMED byte-backed) <sub>L2252</sub>
- **§28** — Banking a "close=0 gate-rejected" giant: the canonical-extern recovery (Phase 22 T1, byte-proven on func_8015126C ×134) <sub>L2344</sub>
- **§28c** — The close=0 recovery is NOT fully exhausted (§26 corrected, R14); + the dedup_propagate registry-skip recovery (Phase 22 T2) <sub>L2371</sub>
- **§28b** — The struct-walled close=0 giant (§28 case #3) IS bankable: the engine_types.h type-lift (Phase 22 T2, byte-proven on func_80156B74 ×134) <sub>L2376</sub>
- **§28d** — The "macro-extern-injection" lever: freeing reach-134 inline matches dedup_propagate skips as "not self-contained" (Phase 23, `tools/inject_capped_externs.py`) <sub>L2385</sub>
- **§30** — Fable5Max cracks §20/§10 "unsteerable" from the gcc SOURCE: store-vs-load is a `/s` aliasing flag, the def-side wall has a macro escape, + the birthing-boost (Phase 23, byte-proven on giant `func_8014EE14` 248 ins ×134) <sub>L2401</sub>
- **§34** — The `func_80138ED0` giant crack: gcc-2.7.2's **3-qty sort bug** + the **zero-byte asm allocation toolkit** + the **giv-init fence** (Phase 24 T5; Opus→close=21, Fable5→MATCH ×134) <sub>L2473</sub>
- **§38** — The WHALE `func_80144B9C` (770 ins): the -O0 struct-assign memcpy idiom + the -O0 reach-134 ×134 rollout (Phase 24 T7 §G, cheap Opus — no Fable5, no calls.c) <sub>L2546</sub>
- **§39** — The ×1→×134 giant-endgame: propagate a matched **-O2** giant via the NATIVE DEFINE-macro path (Phase 24 T7 §G close, 2026-07-08) <sub>L2556</sub>
- **§40** — Structural families: the MECHANICAL symbol-remap (crack one exemplar → remap the rest, ~0 tokens) (Phase 25 T3/T7, 2026-07-08) <sub>L2572</sub>
- **§40a** — The DECL-RECONCILE pass (type-lift so remapped drafts compile in the sibling TU) (Phase 25 T7.2, 2026-07-08) <sub>L2620</sub>
- **§40b** — The reloc-tracker blind spot: the indexed-global idiom that hid the "reach-1 tail" (Phase 26 Task 1, 2026-07-11, byte-verified V0/V1) <sub>L2653</sub>
- **§40c** — The h_seq per-sibling reconcile: templating a reconcile-class crack ×134 (Phase 26 Task 8, 2026-07-12, byte-proven) <sub>L2695</sub>
- **§41c** — T7-M2: the ×134 def-side-wall sweep via per-sibling RE-reconcile (Phase 25, 2026-07-10; 4,389 banks, ~0 agent tokens) <sub>L2873</sub>
- **§42** — The F-band ≤28 regalloc crack wave: register-pin/DENSITY levers beat the permuter (Phase 25 T7 F-band, 2026-07-10; Ultracode 9-worker wave, 4/9 banked byte-identical, 266 swept ×134) <sub>L2934</sub>
- **§42e** — propagating a CRACK ×134: the def-finder bug + the byte-drift residual (the "remap-fail" misdiagnosis) <sub>L3155</sub>
- **§43** — The K&R s16-param definition DISSOLVES the "narrow-param wall" for by-value register args (Phase 25 task A, Fable5 crack of the 369-ins giant `func_80166994` ×134, 2026-07-11) <sub>L3229</sub>
- **§45** — The flagship `func_80133CD4` crack (399 ins ×134): the merged-variable permutation-breaker + the 1-death local-alloc gate (Phase 25 task A giant escalation, Fable5 gdb-on-cc1, 2026-07-11) <sub>L3332</sub>
- **§46** — The `func_80178D40` crack (890 ins ×134, the heaviest core in the game): four LOOP-STRUCTURE levers cheap-Opus found by reading loop.c/jump.c/cse.c (Phase 26 session 8, 2026-07-13) <sub>L3347</sub>
- **§47** — The live-length SLIDER: splitting a global.c allocno-priority TIE with one zero-byte asm (Phase 26 session 8, Fable5 Max, byte-proven on `func_8017BEBC` 952 ins ×113) <sub>L3399</sub>
- **§49** — The LUID DIAL: a zero-byte SCHEDULING dial (the sched.c analogue of §47) — `func_8017A4AC` (536 ins ×134), Phase 26 session 8 <sub>L3561</sub>
- **§52** — The WALKER-FAMILY skeleton: 6 regalloc-order levers + a deeply-characterized intrinsic wall (`func_80178004`, 165 ins ×134; Phase 26, Fable5, 2026-07-15) <sub>L3947</sub>
- **§3-The** — 6 levers (the "walker-family skeleton" — apply to the 12 siblings; levers 1-5 retire ~half the residual) <sub>L3958</sub>
- **§53** — SWEEP A FAMILY WITH THE TOOL ITS EXEMPLAR NEEDED: the jr/switch carve, and how omitting it manufactured the "families don't template" doctrine (Phase 28 T1, 2026-07-15) <sub>L4062</sub>
- **§55c** — Sizing the propagate: a TARGETED propagate is ~4 min/core, and "it's slow" was a BROKEN-TREE ARTIFACT <sub>L4175</sub>
- **§54** — `--fix-def-sig`: the member's CANONICAL DECLARATION is a build step too (tiny-IMM mega-pools, +4,801, Phase 29 T6, 2026-07-16) <sub>L4197</sub>
- **§56** — Banking a hand-drafted GIANT into its exemplar TU: self-contained draft vs live-TU decls, 4 reconciliation tactics (`func_8013FAF8`, 312 ins ×138, Phase 29 T4, 2026-07-17) <sub>L4221</sub>
- **§56b** — PROPAGATING an h_seq giant: the exemplar's externs MUST be fleet-canonical, not the draft's types <sub>L4266</sub>
- **§57** — The SELF-decl normalize: the sibling's OWN caller declares the templated fn divergently (the third §17a-1 direction; `tools/normalize_self_decls.py`, func_801670E4 ×137, Phase 29, 2026-07-18) <sub>L4290</sub>
- **§57a** — Two NSD corrections + the SURGICAL-ONLY law + the honest broad-sweep yield (Phase 29, 2026-07-18) <sub>L4337</sub>
- **§59** — Three h_seq sweep-residual classes match_one/the-exemplar-bank don't reveal (Phase 29 crack-wave close, 2026-07-18) <sub>L4411</sub>
- **§3-Two** — corollaries worth remembering <sub>L4484</sub>
- **§65a** — The blast-radius taxonomy (makes §61's law structural instead of remembered) <sub>L5064</sub>
- **§3-Giv** — record order (the §70 family) <sub>L5794</sub>
- **§75** — A propagation cap is usually a MINORITY-SPELLING SOURCE OVERLAY, not a wall: census the carried extern before believing the exclusion message (Phase 29 SESSION-19, `func_8014F3E8` ×4 → ×138) <sub>L5900</sub>
- **§75a** — The exclusion classes, enumerated with named causes (Phase 29 SESSION-19, the 134-binary `dedup_extend` sweep) <sub>L5959</sub>
- **§75b** — A body's preamble can carry `#define`s, not just `extern`s; extraction lifts only the externs (Phase 29 SESSION-19, `func_80165CA0` ×3 → fleet) <sub>L5982</sub>
- **§76** — The allocno CLASS (local vs global) is the dominant regalloc lever, and C reaches it ONLY through declaration scope and variable reuse (Phase 29 SESSION-19, behemoth #3 `func_8017F510` 1,511 ins, 97 → MATCH, pin-free) <sub>L6062</sub>
- **§77** — Every extraction tool carries a NARROW hard-coded preamble set; anything outside it silently caps the body's reach. Diff the preamble before you gate. (Phase 29 SESSION-19 — three variants in one session, two different tools) <sub>L6118</sub>
- **§84** — The DERIVED-OFFSET remap bug: a hand-computed literal that encodes the DISTANCE between two per-overlay symbols, and why `match_one` is structurally blind to it (Phase 29 SESSION-20, `func_8013D53C`) <sub>L6506</sub>
- **§86** — Pinned-exemplar templatability is a PER-FAMILY property, not a per-member rate; and the §42e pin guard is now over-conservative (Phase 29 SESSION-20) <sub>L6623</sub>
- **§3-THE** — LAW: all-or-nothing PER FAMILY <sub>L6634</sub>
- **§3-Why** — the two live families differ from the three dead ones — the open question <sub>L6661</sub>
- **§3-The** — cheap discriminator, before spending a sweep <sub>L6700</sub>
- **§89b** — the parallel gate farm existed; the family path could not reach it (`tools/sweep_parallel.py`) <sub>L6779</sub>
- **§91** — A structure-TRANSFER is only valid where the structure corresponds: the `--like` role trap (Phase 29 SESSION-21, `func_8012AAAC` ×137) <sub>L6876</sub>
- **§94** — A family sweep's `0/N` is a TYPE-CARRY failure until proven otherwise: lift the exemplar's local types, ALL of them, transitively (Phase 29 SESSION-21, `func_8016B6BC` 0/137 → 137/137) <sub>L6981</sub>
- **§105** — A gate's revert must survive an EXCEPTION, not just a failure (Phase 29 T53, `jtbl_family_bank`) <sub>L7465</sub>
- **§107** — A lever wired into ONE gate path is a lever most families cannot reach (Phase 29 T56, `func_80144090` 0/136 → 136/136) <sub>L7547</sub>
- **§108** — Diagnosing a family `0/N`: the four causes, and the third opt-in lever (Phase 29 T59) <sub>L7585</sub>
- **§111** — The distinct-code metric is not noisy: a family pays it only if its members are byte-VARIANT (Phase 29 T66) <sub>L7715</sub>
- **§116** — Optimization level is a property of the FILE, not the function: read a family 0/N against the member's stub HOME (Phase 29 T79) <sub>L7911</sub>
- **§123** — PROPAGATE A FAMILY WITH THE TOOL ITS TIER NEEDS: `dedup_propagate` is h_exact-only; its refusals are statements about the TOOL (P30 wave 1, 2026-07-30) <sub>L8150</sub>
- **§124** — A "not matched" verdict can mean the definition is there under a DIFFERENT C NAME: the asm-label alias blind spot (P30 SESSION-28, `func_8016191C` ×137) <sub>L8187</sub>
- **§124a** — a family sweep's `0 matched-exemplar families` may be a FILTER, not a wall <sub>L8232</sub>
- **§134** — MULTI-LINE BLINDNESS: one root cause, four faces, in `family_remap`'s preamble scanner (P30 S6, 190 zero-crack families) <sub>L8745</sub>
- **§136c** — SIBLING-FIRST is a DERIVATION shortcut, not just a conflict fix (the fastest route in a family wave) <sub>L9103</sub>
- **§138** — The propagation lanes: a gate refusal is a DECLARATION, and which lever you owe depends on blast radius <sub>L9449</sub>
- **§142** — An open stub whose `h_exact` class is MATCHED elsewhere is FREE. Propagate the body; do not gate a draft. (P30 S39, +7,710 ins in two commands) <sub>L9812</sub>
- **§143** — `cast_call_sites` read a RETURN STATEMENT as a prototype and deleted it. A 0/39 sweep became 18/39. (P30 S40) <sub>L9868</sub>
- **Then** — propagation returned 0/137 TWICE — both times a missing TYPE <sub>L10034</sub>
- **§3-A.** — The frame has THREE strata, and stratum 3 is unreachable from C <sub>L10075</sub>
- **§3-E.** — A `qty_compare` TIE is not spelling-reachable — recognise it and stop <sub>L10117</sub>
- **Consequence** — for the family (a real scheduling decision) <sub>L10129</sub>
- **§150** — A register ROTATION across symmetric blocks is VARIABLE-IDENTITY evidence, not an allocator tie (P30 S43, `func_8017C6F4`, 947 ins ×4) <sub>L10346</sub>
- **§151** — THE GHOST WEDGE: when a load-before-store transposition is unreachable by ANY statement order (P30 S43, `func_8017EF68`, 969 ins) <sub>L10401</sub>
- **When** — to reach for it <sub>L10441</sub>
- **§152** — BYTE SIZE is the family key that name- and h_seq-grouping both miss (P30 S43, the 0xECC family: 1 crack → 12 overlays → 11,364 ins) <sub>L10452</sub>
- **§156** — an ORPHANED reconcile poisons the fleet: `dedup_propagate`'s kept edit (S45 p6/p7) <sub>L10674</sub>
- **§160** — THE REACH-15 WAVE HARVEST: an align-1 block move, and the instrument that called it a wall (P30 S47) <sub>L10927</sub>
- **§162** — S48 WAVE-1 HARVEST (P30, 2026-08-11): the reach-ordered sibling campaign's first 12 targets <sub>L11048</sub>
- **§163z** — THE UNVETTED REMAINDER (do not cite as law; each needs a dedupe pass) <sub>L11862</sub>
- **§3-The** — ADDRESS-CLASS TABLE: which load/store pairs even REACH the `/s` clause (P30 S48 wave 4, `func_80185B44`, ov_SC03_014) <sub>L14396</sub>
- **§168** — THE COUSIN TIER (P30 S49, 2026-08-12): h_seq's exact-hash brittleness, measured — and the similarity map above it <sub>L16265</sub>
- **§171a** — THE MECHANICAL A-PROP DRAFT (P30 S50): 256 members banked with no agent in the loop <sub>L16474</sub>
- **§171b** — THREE CARRIES THE MECHANICAL DRAFT NEEDS (P30 S50, banking the top-reach families) <sub>L16524</sub>
- **§3-G.** — TWO MODELLING TRAPS THAT COST THESE AGENTS SWEEPS OF HUNDREDS OF COMPILES <sub>L17351</sub>
- **§193-E** — A varying-address (pointer) load is re-emitted once per CSE-LIVE INTERVAL, and naming it in a C local is the only C-level lever over that count — no store SPELLING has any reach <sub>L18693</sub>
- **§194-E** — The wave card's `exemplar` is the TARGET ITSELF on 42/73 wave-U and 36/71 wave-T cards — a construction consequence of `atlas.py:657` (exemplar = max-nins OPEN member) meeting `build_wave_atlas.py:166` (one card per gid); and the shipped §193-A `seed_ref` is same-binary on 0/51, so no card field can ever name a destination-TU sibling <sub>L19199</sub>
- **§195-E** — A 0/1 materialised at a JOIN immediately before the controlling `beqz`/`bnez` proves the source NAMED the condition — a truth expression in an `if`'s controlling position reaches `do_jump`, which has no value path <sub>L19993</sub>
- **§199-B** — A permutation sweep that holds ANY statement fixed is not a sweep: the statement an agent pins as "obviously load-bearing" is the one carrying the signal, and the partial sweep returns a FLAT residual that reads as proof of order-invariance <sub>L20808</sub>
- **§203** — A DEDUPED TYPEDEF MUST PRECEDE EVERY SPLICE POINT, NOT JUST ITS OWN (P31 S56) <sub>L21527</sub>
- **§225** — THREE CONTROL-FLOW SHAPES NO STRUCTURED SPELLING REACHES (P31 S58) <sub>L22975</sub>
- **§30** — addendum (P31 S58b) — THE ANONYMOUS STRUCT MEMBER REF GRANTS `/s`, AND THAT IS A TWO-FOR-ONE <sub>L24199</sub>
- **§3-1a.** — The §266 sweep — every solo-lever A/B run for this batch <sub>L25526</sub>
- **ADDENDUM** — to §179-D (GTE macro reference family) — `gte_SetRotMatrix`/`gte_SetTransMatrix` bodies <sub>L25717</sub>
- **ADDENDUM** — to §82 — struct copies must stay MEMBER-WISE, not block-moved, to match a spill-slot save <sub>L25743</sub>
- **ADDENDUM** — to §136d-1 (RC-12, the `$0`-add / opaque-copy family) — two symptoms beyond "compare reads the wrong register" <sub>L25781</sub>
- **§282** — gcc's OWN LOOP REVERSAL PUTS THE COUNTER INIT AFTER THE HOISTED MOVABLES — a position no hand-written down-count can reach (P31 S60; wave cf, func_80180DD8, ov_SC04_005, byte-proven) <sub>L27036</sub>
- **ADDENDUM** — to the zero-byte-asm-slider family (§47 / §148-C / §153) (func_800CB874, md_MAIN_040 — wave dj; open tension with a more cautious dm-wave card — see closing) <sub>L27955</sub>
- **ADDENDUM** — the zero-emission-asm family gains a REF-SLIDER PLACEMENT LAW and a paired RESTORER (func_800CB900, md_MAIN_026) <sub>L28165</sub>
- **ADDENDUM** — §NNN — sharpens §37/§124 (unspecified-parameter-list family): DERIVE A CALLEE'S ARITY LOWER BOUND FROM ITS OWN `.s` STACK-ARGUMENT READS, NOT FROM ANY SINGLE CALL SITE <sub>L28326</sub>
- **ADDENDUM** — to §199-F family (func_8017EFB0, ov_SC02_021, wave cu) <sub>L28478</sub>
- **§287** — A STACK-FRAME HOLE BELOW TWO ADDRESS-TAKEN AGGREGATE LOCALS IS A LEADING PAD MEMBER OF ONE COMBINED STRUCT, NOT SEPARATE LOCALS OR A REGISTER PIN (P31 S60/dj; `func_8017D104`, ov_SC06_027, byte-proven 47/47) (P31 S60; waves #, byte-proven) <sub>L29086</sub>
- **ADDENDUM** — to §127 — the -O0 constant-offset fold keys on the MEMBER-ACCESS tree shape, not on the index being constant <sub>L29170</sub>
- **§296** — THE FRAME CHECK OUTRANKS THE ATLAS LEVER: READ PROLOGUE/EPILOGUE BEFORE DRAFTING ANY C — A REAL TELL CAN LIVE INSIDE AN UNREACHABLE FRAGMENT (P31 S61; wave m0a, 16 cards byte-proven; extends §179-C) <sub>L29456</sub>
- **§297** — ONE GIV SERVING MIXED-WIDTH LOADS *AND* A STORE NEEDS STRUCT-MEMBER SPELLING; CAST/INDEX SPELLINGS RE-SPLIT THE PSEUDO (P31 S61; wave m0a, `func_800347C8`, main, byte-proven 31/31) <sub>L29499</sub>
- **§307** — THE BRUTE-FORCE-THE-STATEMENT-ORDERS LEVER HAS A BOUND: A FAN-OUT COPY'S PRIORITY IS SCHEDULER-INTERNAL, AND NO SOURCE ORDER REACHES IT (P31 S63; byte-evidenced NEGATIVE result, main wave) <sub>L29939</sub>
- **§308a** — A TWO-INSTRUCTION ARM STUB LAID *BEFORE* THE OTHER ARM AND REACHED ONLY BY A TRAILING `j` SURVIVES ONLY BEHIND A SHORT-CIRCUIT `&&` GUARD PLUS A SEPARATE RE-TEST; EVERY PLAIN if/else-if, GOTO-LADDER, NESTED-INVERTED-if AND 1-/2-NODE switch LETS jump1 INLINE IT (−2 ins) (P31 S63 t5e-t5i; byte-proven func_80180808) <sub>L30012</sub>
- **§314** — AN IF/ELSE-IF ABS-RANGE CHECK'S C SPELLING IS INERT: FOUR STRUCTURALLY DIFFERENT REWRITES ALL COMPILE BYTE-IDENTICAL, AND NONE REACHES A TARGET THAT SINKS THE NEGATIVE ARM INTO AN OUT-OF-LINE BLOCK (P31 S65; UNPROVEN, gate-refused draft func_80181720) <sub>L30241</sub>
- **§NNN** — REFUTED: A CODE BLOCK SHARED BY TWO *DIFFERENT* SWITCH STATEMENTS IS ORDINARY FORWARD `cross_jump`, NOT A SHAPE C CANNOT REACH — §164-11 ALREADY BANKS IT FROM PLAIN NESTED SWITCHES (P31 S66 round3, `func_8001B0D4`; ⚠ **UNPROVEN** — gate-REFUSED draft, closeness 68→45, never MATCHed) <sub>L30640</sub>
- **§323** — CARRYING FILE-SCOPE TYPES BETWEEN SPLIT TUs: DEDUPE BY NAME, SKIP HEADER-PROVIDED, AND THE GUARD TRAVELS WITH THE BLOCK (P31 S67; ov_SC02_000, two defects fixed, one open) <sub>L30896</sub>
- **§341** — AN HImode STORE TEMP REWEIGHTS A sched2 TIE-BREAK THAT NO STATEMENT ORDER CAN REACH (P31 S67; byte-proven ov_SC03_006/func_801823B8, last 4 ins) <sub>L31243</sub>
- **§355** — A REMAPPED SIBLING'S **SOURCE BIAS IS NOT ITS EMITTED BIAS** — DO NOT HAND-SHIFT OFFSETS TO MATCH THE ASM (P31 S68; byte-proven ov_SC07_007/func_8013DD68, 187/187 in 2 iterations) <sub>L31560</sub>
- **§368** — ★★★ — THE **RELOAD-REMAT CONSTANT**: REACH A REGISTER NO PIN CAN REACH (P31 S68; ov_SC03_105/func_80187A30, 339 ins, fable escalation closed 8 → 0 in ONE edit) <sub>L31792</sub>
- **§379** — ★★★ — **MEM_IN_STRUCT_P**: THE SAME LOAD, WRITTEN AS A STRUCT MEMBER, SCHEDULES WHERE A CAST CANNOT (P31 S69; byte-proven main/func_80021284 220 ins and main/func_8002D904 217 ins, found INDEPENDENTLY by two agents) <sub>L32164</sub>
- **§396** — ★★★ — SIX LEVERS FROM THE S69 SINGLETON ROUND, INCLUDING ONE THAT ONLY A `COND_EXPR` REACHES (P31 S69) <sub>L32737</sub>
- **§398** — ★★★ — `family_remap` CARRIES THE **SOURCE** TU's DECL ENVIRONMENT INTO A DESTINATION THAT ALREADY OWNS THOSE NAMES (P31 S69; measured 3 banked of 22) <sub>L32835</sub>
- **§3-B.** — THE SCHEDULER DIALS (the dominant residual family this wave) <sub>L33108</sub>
- **§408** — ★★★ — §406 REFUTED AS A SWEEP: THE SHAPE IS THE FAMILY, THE DISAGREEMENT IS THE DEFECT (P31 S71; 0 MATCH / 14 applied, 0 / 210) <sub>L33209</sub>
- **§420** — ★★★ — A MULTI-CLUSTER SYMBOL REBASE, AND THE BARE-NAME DEDUP THAT HID THREE QUARTERS OF IT (P31 S71; 4 banked in 57 s) <sub>L33692</sub>
- **§421** — ★★★ — A `la $tN` + `addiu` PAIR CAN BE A **RELOAD** ARTIFACT THAT NO C SPELLING REACHES (P31 S71; byte-proven `md_SC07_003/func_801A293C`, 313 ins, 6 → 0) <sub>L33729</sub>
### integration / TU plumbing (78)
- **§8c** — Splitting a TU means rebuilding its DECLARATION ENVIRONMENT, not moving text (Phase 26 session 6) <sub>L456</sub>
- **§8d** — Templating a body INTO a TU must not CHANGE its declaration environment — demote the carried data externs (Phase 26 session 8, byte-proven on `func_8015AE2C` ×133) <sub>L502</sub>
- **§9.3** — Make it the build: resegment + swap + resolve (`tools/psyq_integrate.py`, libcd DONE) <sub>L704</sub>
- **§9.4** — Integrating a SECOND library (libgs block 6 after libcd) — multi-library gotchas <sub>L731</sub>
- **§9.5** — Integrating a WHOLE multi-block library in one call (full libgs — Phase 7 session G) <sub>L759</sub>
- **§17a** — The TOOLKIT at WAVE scale (Phase-18 Step-3b/Step-1 — measured) + the pipeline-integration gotchas <sub>L1464</sub>
- **§3-THE** — CAP: at this tail the match_one→gate gap is the LOOSE-TYPING CALL-GRAPH wall (not cheap plumbing) <sub>L1656</sub>
- **Diagnostic** — lesson: a failed in-TU build leaves a STALE `.o` <sub>L1673</sub>
- **§28d** — The "macro-extern-injection" lever: freeing reach-134 inline matches dedup_propagate skips as "not self-contained" (Phase 23, `tools/inject_capped_externs.py`) <sub>L2385</sub>
- **§30a** — §30 generalizes to the FULL near-miss backlog (via STANDARD Opus agents, not just Fable5) + 2 more steer levers + the mechanical-integration throughput unlock (Phase 23 (a)) <sub>L2413</sub>
- **§40a** — The DECL-RECONCILE pass (type-lift so remapped drafts compile in the sibling TU) (Phase 25 T7.2, 2026-07-08) <sub>L2620</sub>
- **§42a** — addendum — wave 2 (residuals + 29-100 band): iso-MATCH ≠ real-TU bank, the memcpy→struct-assign fix, +5 levers (2026-07-10b) <sub>L2987</sub>
- **§42c** — addendum — wave 3 (Max orchestrator + CORRECTED Ultracode fan-out, 2026-07-10c): the real-TU-faithful parallel harness (rtu_match) + 7/9 crack, ZERO iso-drift <sub>L3067</sub>
- **§56** — Banking a hand-drafted GIANT into its exemplar TU: self-contained draft vs live-TU decls, 4 reconciliation tactics (`func_8013FAF8`, 312 ins ×138, Phase 29 T4, 2026-07-17) <sub>L4221</sub>
- **§61** — Task 14: the gate ladder's missing stage is the ARITY pre-pass, and it is TU-side not draft-side (Phase 29, 2026-07-21) <sub>L4579</sub>
- **§61a** — The Task-5 wave: 11/12 MATCH, 0 banked — three DISTINCT integration walls, each now named (Phase 29, 2026-07-21) <sub>L4640</sub>
- **§63** — The fresh-138 DEF-SIDE blocker: fix the HEADER decl, not the draft (`fix_header_decl.py`, Phase 29 SESSION-13, 2026-07-23) <sub>L4911</sub>
- **§63** — UPDATE (Phase 29 SESSION-14) — `fix_header_decl`'s "SAFE" verdict is FLEET-BLIND; it MUST be R22-validated <sub>L5034</sub>
- **§65** — The stranded-draft recovery: BLAST-RADIUS TIERS, and the per-overlay de-macroize that refutes §20's DEF-conflict wall (`tools/demacroize.py` + `tools/blocker_probe.py`, Phase 29 SESSION-16, 2026-07-24) <sub>L5049</sub>
- **§65b** — The escape: de-macroize the instantiation, don't touch the shared header <sub>L5079</sub>
- **§65f** — The de-macroize lever's BOUNDARY, measured: byte-neutral 14 times of 15, and the 15th is why the gate exists <sub>L5152</sub>
- **§65g** — Where the cheap levers STOP: the local-type and in-TU-self-decl classes did not yield <sub>L5173</sub>
- **§85** — The RETURN-axis fleet widen is ALL-OR-NOTHING: widening the shared header alone guarantees a conflict in the source overlay (Phase 29 SESSION-20, `func_8012CC88` / `func_8014D12C`) <sub>L6573</sub>
- **§95** — `reconcile_tu` dropped the SIBLING declarators of a multi-symbol `extern` line (Phase 29 SESSION-21, `func_80176218`) <sub>L7017</sub>
- **§96** — The same rewrite, one shape down: `reconcile_tu` matched statements to lines by TEXT, so every COMMENTED declaration was silently skipped (Phase 29 SESSION-22, `func_80176218` banked) <sub>L7052</sub>
- **§3-Two** — `reconcile_tu` bugs found underneath, one introduced while fixing the other <sub>L7224</sub>
- **§100** — Prefer the DRAFT-LOCAL fix: a type only one function uses belongs in its BODY, not in a shared header (Phase 29 SESSION-22, `func_80175DA8` 0/137 → 137/137) <sub>L7250</sub>
- **§102** — A PLUMBING verdict can MASK a DIFF; and K&R is not always a codegen change (Phase 29 SESSION-22, `func_8016EC0C`) <sub>L7306</sub>
- **§103** — A FILE-scope `extern` in a shared overlay TU is a GLOBAL constraint on every LATER function; move the DECL, not the draft (Phase 29 T48/T51, `func_80135260` — the fleet-wide half) <sub>L7341</sub>
- **§109** — Conforming a definition to a shared header: fix the NAMES, then check the RETURN precondition (Phase 29 T60) <sub>L7634</sub>
- **§112** — A macro-scoped declaration only collides where the macro is INSTANTIATED (Phase 29 T67/T69, `audit_header_sigs.py`) <sub>L7764</sub>
- **§114** — The THIRD decl axis: a CALLEE the draft declares differently from the target TU (Phase 29 T76/T77) <sub>L7842</sub>
- **§3-The** — integration idioms (these decide whether a byte-correct draft BANKS) <sub>L8838</sub>
- **§3-The** — declaration surface (integration, not codegen) <sub>L8975</sub>
- **Reconciling** — a gate-refused draft: which way you edit depends on WHERE the TU's decl is <sub>L9599</sub>
- **§3-The** — same swallow, twice more, in the integration spine <sub>L9743</sub>
- **§3-A.** — Payload word0 is a global MODULE ID; code starts after the header <sub>L10561</sub>
- **§162** — THE LICM PAIR: what makes an address a movable AT ALL, and why the preheader order is the body order (P30 S47, `ov_MAIN_012`) <sub>L11177</sub>
- **§166** — THE DESTINATION-TU ORACLE (P30 S48): the seven-attempt bug that was never codegen <sub>L14956</sub>
- **§173** — THE STORED-PLUMBING RECOVERY RECIPE (P31 T6): symfix-first, per-group isolation, and where the verdicts have no drafts <sub>L16670</sub>
- **§176d** — THE CONFLICT TABLE MUST BE SEEDED FROM THE TU, AND KEYED PER FILE (P31 S52, 2026-08-15) <sub>L16867</sub>
- **§180b** — WHAT THE PRE-GATE LADDER ACTUALLY FINDS IN A COLD PILE (the shape of integration debt) <sub>L17883</sub>
- **§185** — EDIT THE SIDE THAT IS CHEAP TO VERIFY, AND CHECK A TU RETYPE AT ITS USE SITES <sub>L18101</sub>
- **§194-E** — The wave card's `exemplar` is the TARGET ITSELF on 42/73 wave-U and 36/71 wave-T cards — a construction consequence of `atlas.py:657` (exemplar = max-nins OPEN member) meeting `build_wave_atlas.py:166` (one card per gid); and the shipped §193-A `seed_ref` is same-binary on 0/51, so no card field can ever name a destination-TU sibling <sub>L19199</sub>
- **§195-J** — GTE / PsyQ op CALL-vs-INLINE is a PER-SITE SOURCE FACT, not a TU style — both forms coexist in one TU (measured in 2 TUs), and the tell is the target's own opcodes (`lwc2`/`sqr`/`swc2` vs `jal`), not the sibling. Costs -8 ins on func_8018505C. Corollary: the game's inline `sqr` macro emits TWO hazard nops, the SDK's `Square0` body emits ONE — so the inline form is provably not `Square0` inlined (a second instance of §187's SDK-vs-game GTE nop divergence). <sub>L20263</sub>
- **§199-D** — A narrow UNSIGNED value compared in an ordered `if` emits `sltiu`/`sltu`; the only dial is the WIDTH of a real object, and a widening `(s32)` cast is inert — AMENDS §35 (whose stated "only CSE-reuse canonicalizes" mechanism is byte-wrong) and does NOT apply inside a `switch` <sub>L20901</sub>
- **§200** — THE ALIAS IS THE UNIVERSAL DECLARATION ESCAPE: stop negotiating with the TU's spelling (P31 S55) <sub>L21140</sub>
- **§201-A** — §150-B applies to `decl_prior`'s DEF row: for an overlay-window symbol the banked "definition" is usually another overlay's function, and the card ranks it ABOVE the destination TU <sub>L21199</sub>
- **§203** — A DEDUPED TYPEDEF MUST PRECEDE EVERY SPLICE POINT, NOT JUST ITS OWN (P31 S56) <sub>L21527</sub>
- **§210** — THE SINGLE-BIT MASK IN A BOOLEAN TAIL: `andi K ; sltu $zero,v` vs `srl n ; andi 1` is a STATEMENT-SHAPE dial, not an operator choice (P31 S58) <sub>L22369</sub>
- **ADD-2** — → §42a addendum — A SHARED CONSTANT *NAMED IN A LOCAL* ACROSS A `jal` IS AN ISO→TU DRIFT HAZARD; WRITE BARE LITERALS <sub>L25137</sub>
- **ADD-3** — → §236, item 10 — THE UN-DELETED `INCLUDE_ASM` STUB IS A DUPLICATE DEFINITION <sub>L25149</sub>
- **ADD-2** — → §236 addendum (item 1 corollary) — THE SILENT-SPLICE DECLARATION LADDER: WHERE THE TU HAS NO SPELLING, UNPROTOTYPED `()` BEATS THE FLEET VOTE <sub>L25367</sub>
- **§273** — A standalone compile is the WRONG oracle for a TU-destined draft (P31 S59) <sub>L25619</sub>
- **ADDENDUM** — to §134 — a typedef defined BELOW the splice point is stripped anyway <sub>L25687</sub>
- **ADDENDUM** — to §8 — WHEN `INCLUDE_RODATA` NEEDS A STANDALONE `.s` YOU CAN'T CREATE, CARRY THE FRAGMENT AS A FILE-SCOPE `__asm__` BLOB <sub>L26222</sub>
- **§280** — THE CURSOR'S DECLARED TYPE PICKS `sltu` vs `slt`: a `T*` bound test is UNSIGNED by C rule, an integer cursor is signed (P31 S60; wave cf, func_800CAE74, md_MAIN_031, byte-proven) <sub>L26956</sub>
- **§NNN** — A LOOP CURSOR'S C TYPE (POINTER vs PLAIN INTEGER) SELECTS `sltu` vs `slt` FOR ITS BOUND TEST, INDEPENDENT OF THE VALUES INVOLVED (P31 S60; `func_800CAE74`, md_MAIN_031, byte-proven; cross-confirmed same wave by `func_8017F2A4`, ov_SC03_096) <sub>L26957</sub>
- **ADDENDUM** — to §199-G — A `default:` LABEL GROUPED ONTO THE LAST CASE REMOVES THE `j default` TAIL, EVEN THOUGH THE 2-NODE HEADER STAYS ALL-POSITIVE <sub>L27411</sub>
- **§301** — AN INTERNAL `j` CARRIES `R_MIPS_26 .text`: rtu/match_one "MATCH" COULD NOT SEE WHICH LABEL A `j` TAKES — FIXED (`jrel`), AND THE TWO DRAFT SHAPES IT HID (P31 S62 T1; byte-proven 2/2, negative-controlled over 3,297 stubs) <sub>L29671</sub>
- **Addendum** — Reversed-operand sltu then xori 1 means unsigned less-or-equal (func_8017D948) <sub>L30505</sub>
- **§NNN** — REFUTED: A `sw %lo(SYM)($at)` IN A JUMP'S DELAY SLOT WITH ITS `lui $at` STRANDED ABOVE THE JUMP IS **ASSEMBLER** MACRO-EXPANSION, NOT A cse SPLIT — OUR PIPELINE CANNOT EMIT IT FROM ANY C, AND THE +1 IS A `maspsx` GAP (P31 S66 round2, `func_8005DBD8`, byte-probed) <sub>L30591</sub>
- **§320** — THE §43 "RETURN-TYPE FLIP PAIR" IS **NOT** TU-EDIT-REQUIRED: THREE DRAFT-ONLY ESCAPES (P31 S66; byte-proven func_800CCBC0, func_800D30D0, func_800D2A24) <sub>L30786</sub>
- **§323** — CARRYING FILE-SCOPE TYPES BETWEEN SPLIT TUs: DEDUPE BY NAME, SKIP HEADER-PROVIDED, AND THE GUARD TRAVELS WITH THE BLOCK (P31 S67; ov_SC02_000, two defects fixed, one open) <sub>L30896</sub>
- **§324** — THE ARITY-SELF WALL NEEDS *BOTH* HALVES: A K&R DEFINITION **AND** A NO-PROTO TU DECL; EITHER ALONE STILL FAILS (P31 S67; rtu-proven ov_SC01_005/func_8017FBCC, 14 instances measured) <sub>L30949</sub>
- **§337** — THE CC1-ONLY BLOCKER CLASS: `blocker_probe`'s STATIC ORACLE REPORTS "none" AND THE WHOLE-TU COMPILE STILL FAILS (P31 S67; ov_SC04_011/func_801827DC, md_MAIN_027/func_800CB4A4) <sub>L31157</sub>
- **§356** — MEASURE A DRAFT IN THE TU IT WILL LIVE IN, NOT IN THE STANDALONE PROBE (P31 S68; measured over 47 stored drafts) <sub>L31574</sub>
- **§362** — TWO TRAPS WHEN A CARVE MOVES A STUB INTO THE `-O0` TU (P31 S68; byte-proven, 6 fns / 2,547 ins across ov_MAIN_012 / ov_SC02_037 / ov_SC03_107) <sub>L31682</sub>
- **§367** — RECONCILING A DECL CONFLICT BETWEEN TWO DRAFTS FOR THE SAME TU (P31 S68; main) <sub>L31777</sub>
- **§376** — ★★★ — A STANDALONE `match_one` CLOSENESS OF 0 IS A CLAIM ABOUT THE **BODY**, NEVER ABOUT THE **TU** (P31 S69; measured 0/28) <sub>L32055</sub>
- **§378** — ★★★ — THE **SELF-CALLER CAST**: LET A TU KEEP CALLING THE FUNCTION IT IS ABOUT TO DEFINE (P31 S69; byte-proven ov_SC04_010/func_8017D6CC) <sub>L32114</sub>
- **§385** — ★★★ — THE **SCHED2 PRIORITY-DONOR ASM**: closing the "hoisted-invariant vs IV-init preheader swap" class (P31 S69; byte-proven main/func_80038A58, 347 ins, fable escalation 2 → 0) <sub>L32309</sub>
- **§378c** — ★★ — THE FIFTH DECL-BLOCKER VARIANT: THE DRAFT REDECLARES WHAT THE TU ALREADY OWNS (P31 S69) <sub>L32722</sub>
- **§398** — ★★★ — `family_remap` CARRIES THE **SOURCE** TU's DECL ENVIRONMENT INTO A DESTINATION THAT ALREADY OWNS THOSE NAMES (P31 S69; measured 3 banked of 22) <sub>L32835</sub>
- **§3-D.** — INTEGRATION IS STILL THE BOTTLENECK, AND THE TU IS THE AUTHORITY <sub>L33140</sub>
- **§415** — ★★ — A FILE-SCOPE DECL MAKES gcc-2.7.2 MERGE THE TU'S LATER *BLOCK-SCOPE* EXTERNS INTO IT (P31 S71; byte-proven `ov_SC04_011/func_80180B24`, 215 ins) <sub>L33547</sub>
- **§423** — ★★★ — "MATCH IN ISOLATION + GATE REJECTS + CAUSE NOT DETERMINED" ⇒ GREP THE TU FOR A FILE-SCOPE TYPEDEF THE DRAFT ALSO CARRIES (P31 S71; byte-proven `ov_SC03_092/func_8017FA74`) <sub>L33780</sub>
- **§431** — ★★★ — SPLITTING A 27,000-LINE TU AT ITS ORIGINAL BOUNDARIES: THE JTBL SPANS TELL YOU WHERE, AND THE COMPILER TELLS YOU WHAT CROSSES (P31 S72; `src/800.c` -> `800.c`/`800_b.c`/`800_c.c`, byte-identical with nothing banked) <sub>L34061</sub>
### build graph, splat & the harness (195)
- **§4** — Flag/toolchain gotchas <sub>L190</sub>
- **Build** — mechanism — per-file opt override (splat resegmentation) <sub>L307</sub>
- **§8c** — Splitting a TU means rebuilding its DECLARATION ENVIRONMENT, not moving text (Phase 26 session 6) <sub>L456</sub>
- **§9** — Link real PsyQ library objects byte-exact (Phase 7 — GO proven) <sub>L632</sub>
- **§9.1** — Generalised per-object linker — `tools/psyq_link.py` (+ `psyq_link_lib.py`), 18/18 libcd byte-exact <sub>L661</sub>
- **§9.2** — Wire a library region into the build with NOLOAD — no data carving (`tools/psyq_link_region.py`) <sub>L685</sub>
- **§9.3** — Make it the build: resegment + swap + resolve (`tools/psyq_integrate.py`, libcd DONE) <sub>L704</sub>
- **§9.6** — Scaling library linking to the whole EXE (Phase 8 — 8 libs linked, 20%→50% byte-identical) <sub>L785</sub>
- **§9.7** — Binary-agnostic toolchain refactor (Phase 9) — the reusable pattern for Gen2 <sub>L821</sub>
- **§3-The** — clean object-level metric (use this, not the permuter score, for jtbl/rodata functions) <sub>L863</sub>
- **§3-The** — mechanism: game-code dedup is SOURCE-LEVEL, not an object swap (R-D1, the key lesson) <sub>L945</sub>
- **Per-binary** — toolchain provenance (R24) <sub>L978</sub>
- **§12** — Ultracode harvest — parallel-draft + byte-gate at scale (Phase 12, resident: 1.4%→71.7% in one session) <sub>L983</sub>
- **One-command** — onboarding — `tools/new_overlay.sh <SCxx> <FILE_nnn>` <sub>L1081</sub>
- **§3-THE** — NON-4-ALIGNED-OVERLAY GOTCHA (≈75% of the fleet; fixed in the template + Makefile, automatic) <sub>L1098</sub>
- **Fleet** — build — `make build-all` / `make check-all` <sub>L1139</sub>
- **§14** — Propagate a matched function across the fleet — `tools/dedup_propagate.py` (Phase 15) <sub>L1145</sub>
- **§14b** — Harvesting the UNMATCHED shared core — the match_one wall (Phase 15) <sub>L1211</sub>
- **§14c** — Callee-signature-aware harvest — breaking the extern-type-conflict wall (Phase 15, T6) <sub>L1232</sub>
- **§17** — The compiler-quirk wall — the matching TOOLKIT (Phase 18; gcc-2.7.2 source + byte-gated) <sub>L1395</sub>
- **§3-The** — pipeline gotcha — match_one ≠ the gate; `sig_unify` is MANDATORY <sub>L1440</sub>
- **§17a** — The TOOLKIT at WAVE scale (Phase-18 Step-3b/Step-1 — measured) + the pipeline-integration gotchas <sub>L1464</sub>
- **§19** — Scaling the toolkit waves — the recovery PIPELINE + the propagation CAP (Phase 19 T3) <sub>L1616</sub>
- **§20** — The wave-at-scale GATE CAP + residual-class verdicts (Phase 20) <sub>L1651</sub>
- **§3-THE** — CAP: at this tail the match_one→gate gap is the LOOSE-TYPING CALL-GRAPH wall (not cheap plumbing) <sub>L1656</sub>
- **Diagnostic** — lesson: a failed in-TU build leaves a STALE `.o` <sub>L1673</sub>
- **Phase-20** — RESOLUTION — `tools/cast_call_sites.py` BUILT + the cap re-diagnosed (R14, byte-proven) <sub>L1720</sub>
- **§24** — The `ov_SC01_077_a.c` split-file vein: split-aware propagation, but loose-typing-gated (Phase 21) <sub>L2104</sub>
- **§25** — The "schedule" class is mostly COALESCING (pin-crackable), not scheduling; + the gate two-stage + h_exact over-counts ×134 (Phase 21, cont.6) <sub>L2151</sub>
- **§3-The** — gate two-stage — sig_unify is a FALLBACK, not unconditional (`gate_stage.py`, §19 folded in) <sub>L2208</sub>
- **§28** — Banking a "close=0 gate-rejected" giant: the canonical-extern recovery (Phase 22 T1, byte-proven on func_8015126C ×134) <sub>L2344</sub>
- **§28c** — The close=0 recovery is NOT fully exhausted (§26 corrected, R14); + the dedup_propagate registry-skip recovery (Phase 22 T2) <sub>L2371</sub>
- **§28d** — The "macro-extern-injection" lever: freeing reach-134 inline matches dedup_propagate skips as "not self-contained" (Phase 23, `tools/inject_capped_externs.py`) <sub>L2385</sub>
- **§29** — Reasoning-model (GLM5.2) DEF-side reconciliation idioms + the wall's hard limit (Phase 23 T10.7, `tools/glm_reconcile.py`) <sub>L2393</sub>
- **§33** — Automating the giant decl-reconcile: `tools/reconcile_decls.py` (the DATA analog of §20's `cast_call_sites`) + a fleet-majority type oracle (Phase 24 T7b, byte-proven on `func_80129CF8`) <sub>L2453</sub>
- **§34** — The `func_80138ED0` giant crack: gcc-2.7.2's **3-qty sort bug** + the **zero-byte asm allocation toolkit** + the **giv-init fence** (Phase 24 T5; Opus→close=21, Fable5→MATCH ×134) <sub>L2473</sub>
- **§35** — The region-a sibling-giant harvest: difficulty ≠ $s-reg count (it's global-array hoisting) + the banking recipe + new loop idioms (Phase 24 T7, 5 parallel Opus-Max agents) <sub>L2490</sub>
- **§37** — The T7 §G giant endgame: 6/8 cracked, meta-laws + transferable levers (Phase 24, 2026-07-07; FULL byte-verified detail + gcc-2.7.2 line cites in `docs/gcc-2.7.2-map/t7g-giant-harvest.md`) <sub>L2525</sub>
- **§39** — The ×1→×134 giant-endgame: propagate a matched **-O2** giant via the NATIVE DEFINE-macro path (Phase 24 T7 §G close, 2026-07-08) <sub>L2556</sub>
- **§41** — The DEF-SIDE canonical-sig wall: mechanically banking a drafted giant past `conflicting types` (Phase 25 T5b batch-2, 2026-07-09; `tools/canon_sig_reconcile.py`, byte-proven on `func_8013B274`) <sub>L2729</sub>
- **§41a** — v3.1: the def-side wall was ~71% TOOL-shaped — the five measured defects + the laws that dissolve them (Phase 25 T6, Fable5, 2026-07-09) <sub>L2788</sub>
- **§41b** — T7 execution: the object-only probe OVER-counts BANKABLE by two link/rodata classes (Phase 25 T7-M1, 2026-07-10) <sub>L2843</sub>
- **§41d** — `void`→`s32` is NOT always byte-neutral: gate the RAW draft FIRST (Phase 26 session 6, byte-proven) <sub>L2912</sub>
- **§42b** — addendum — wave 3 (Max, 2026-07-10c): THE STALE-OBJECT GATE TRAP + the read-global `&`-cast drift + fix <sub>L3028</sub>
- **§45** — The flagship `func_80133CD4` crack (399 ins ×134): the merged-variable permutation-breaker + the 1-death local-alloc gate (Phase 25 task A giant escalation, Fable5 gdb-on-cc1, 2026-07-11) <sub>L3332</sub>
- **§51** — TOOLING INTEGRITY: the silent skip, and how to hunt it <sub>L3664</sub>
- **§51b** — Why the byte-gate cannot save you <sub>L3686</sub>
- **§51f** — Checklist for any new corpus-scanning tool <sub>L3789</sub>
- **§51g** — When the thing you are scanning has a GRAMMAR, parse the grammar (`tools/cdecl.py`) <sub>L3803</sub>
- **§53** — SWEEP A FAMILY WITH THE TOOL ITS EXEMPLAR NEEDED: the jr/switch carve, and how omitting it manufactured the "families don't template" doctrine (Phase 28 T1, 2026-07-15) <sub>L4062</sub>
- **§55** — Core-crack wave levers + the GATE-ORCHESTRATION law (Phase 29 T3, 13-agent ultracode wave, 2026-07-17) <sub>L4127</sub>
- **§55b** — THE GATE-ORCHESTRATION LAW (3 traps, ~3.5h lost; all recovered, 0 data lost) <sub>L4156</sub>
- **§55c** — Sizing the propagate: a TARGETED propagate is ~4 min/core, and "it's slow" was a BROKEN-TREE ARTIFACT <sub>L4175</sub>
- **§54** — `--fix-def-sig`: the member's CANONICAL DECLARATION is a build step too (tiny-IMM mega-pools, +4,801, Phase 29 T6, 2026-07-16) <sub>L4197</sub>
- **§57** — The SELF-decl normalize: the sibling's OWN caller declares the templated fn divergently (the third §17a-1 direction; `tools/normalize_self_decls.py`, func_801670E4 ×137, Phase 29, 2026-07-18) <sub>L4290</sub>
- **§61** — Task 14: the gate ladder's missing stage is the ARITY pre-pass, and it is TU-side not draft-side (Phase 29, 2026-07-21) <sub>L4579</sub>
- **§61b** — The jtbl gate stage: built, and the ORDERING law it exposed (Phase 29 Task-14 stage 4, 2026-07-21) <sub>L4692</sub>
- **§61d** — The undo was eating the tree: two tools, one defect, invisible to the byte-gate (Phase 29, 2026-07-22) <sub>L4813</sub>
- **§62** — The jtbl RECONCILE must also follow the carve: the post-carve draft reconcile (`harvest_verify._jtbl_reconcile`, Phase 29 SESSION-11, 2026-07-22) <sub>L4867</sub>
- **§65** — The stranded-draft recovery: BLAST-RADIUS TIERS, and the per-overlay de-macroize that refutes §20's DEF-conflict wall (`tools/demacroize.py` + `tools/blocker_probe.py`, Phase 29 SESSION-16, 2026-07-24) <sub>L5049</sub>
- **§65d** — Existing-ladder baseline, measured (do this before building a recovery stage) <sub>L5125</sub>
- **§65e** — Two oracles, and the disagreement is the finding (R34 in practice) <sub>L5135</sub>
- **§65f** — The de-macroize lever's BOUNDARY, measured: byte-neutral 14 times of 15, and the 15th is why the gate exists <sub>L5152</sub>
- **§66b** — A metric parsed out of another tool's prose goes NULL silently when the label changes <sub>L5234</sub>
- **§67a** — Run the symbol-set guard BEFORE you pay for a gate (`tools/symcheck.py`, Phase 29 SESSION-18) <sub>L5439</sub>
- **§77** — Every extraction tool carries a NARROW hard-coded preamble set; anything outside it silently caps the body's reach. Diff the preamble before you gate. (Phase 29 SESSION-19 — three variants in one session, two different tools) <sub>L6118</sub>
- **§3-The** — CANDIDATE gate and the REAL gate need DIFFERENT preambles — keep the difference out of the bank <sub>L6158</sub>
- **§79** — For a 0-callee giant, fingerprint by DATA symbols (§71 cannot fire); and the STACK-SLOT ORDER is a declaration-order oracle (Phase 29 SESSION-19, `func_8017BF14` 4,763 ins, cold start → 45/4763) <sub>L6254</sub>
- **§82** — Two source-shape oracles from behemoth #6: a duplicated `addiu $aN,$sp,K` across a `jal` means the block was INLINED, and scalar-vs-aggregate decides WHEN a stack slot is allocated (Phase 29 SESSION-19, `func_8017C730` 1,061 ins) <sub>L6404</sub>
- **§3-2.** — Scalar vs aggregate decides *when* the slot is allocated <sub>L6423</sub>
- **§3-Why** — it survived every candidate gate <sub>L6529</sub>
- **§3-THE** — FIX IS MECHANICAL — the tool already holds the answer <sub>L6544</sub>
- **§87** — `match_one` COMPILES but never LINKS, so an unresolvable data symbol reads as MATCH; and stored drafts go STALE against the tree (Phase 29 SESSION-20) <sub>L6667</sub>
- **§88f** — the missing rung: a RELOCATION gate between `match_one` and the binary <sub>L6752</sub>
- **§89a** — MEASURE the write set; do not assert its tier (`tools/blast_radius.py`) <sub>L6766</sub>
- **§89b** — the parallel gate farm existed; the family path could not reach it (`tools/sweep_parallel.py`) <sub>L6779</sub>
- **§90** — Five tool-integrity laws from one session, each of which changed an answer (Phase 29 SESSION-21, 2026-07-27) <sub>L6800</sub>
- **§90a** — A comparison tool MUST share its reference oracle's index space, exactly <sub>L6806</sub>
- **§92** — Conforming a DECLARATION: pointer changes are caller-neutral, scalar-WIDTH changes are not (Phase 29 SESSION-21, `tools/conform_decls.py`) <sub>L6925</sub>
- **§97** — The gate's own tree hygiene: a refused carve, an unchecked recovery, and a snapshot that captured a dirty tree (Phase 29 SESSION-22) <sub>L7100</sub>
- **§105** — A gate's revert must survive an EXCEPTION, not just a failure (Phase 29 T53, `jtbl_family_bank`) <sub>L7465</sub>
- **§107** — A lever wired into ONE gate path is a lever most families cannot reach (Phase 29 T56, `func_80144090` 0/136 → 136/136) <sub>L7547</sub>
- **§3-Why** — it survived so long: a MASKED oracle will MATCH a wrong symbol <sub>L7987</sub>
- **§122** — GATE RAW BEFORE TRANSFORMING; the undo belongs to the WRITER, as a per-edit journal (P30 T0a, 2026-07-30) <sub>L8118</sub>
- **§123** — PROPAGATE A FAMILY WITH THE TOOL ITS TIER NEEDS: `dedup_propagate` is h_exact-only; its refusals are statements about the TOOL (P30 wave 1, 2026-07-30) <sub>L8150</sub>
- **§126a** — a bare `except: continue` around a coverage-asserting oracle re-creates the silent skip (P30 S28) <sub>L8351</sub>
- **§130** — An INCREMENTAL build can report BYTE-IDENTICAL for a change the CLEAN build cannot even LINK (P30 S28, the jr pair) <sub>L8520</sub>
- **§132** — The `JR-PAIR-IN-ONE-O0-OBJECT` "wall" was TWO instrument defects: a merged-double span the carve could not see, and a truncated object no rule deleted (P30 S29, `func_8013B83C` + `func_8013BD74`) <sub>L8604</sub>
- **§133** — The DEFAULT-FILTER class: three times in one session, a tool silently answered a narrower question than the one asked (P30 S1–S3) <sub>L8719</sub>
- **§134** — MULTI-LINE BLINDNESS: one root cause, four faces, in `family_remap`'s preamble scanner (P30 S6, 190 zero-crack families) <sub>L8745</sub>
- **§3-The** — splitting/merging rules (each closed a residual, byte-gated) <sub>L8887</sub>
- **§137a** — A gate verdict has a TIMESTAMP; re-check it against the draft's mtime <sub>L9420</sub>
- **§138** — The propagation lanes: a gate refusal is a DECLARATION, and which lever you owe depends on blast radius <sub>L9449</sub>
- **§134** — again, in a second tool — and the waiter rule corrected <sub>L9560</sub>
- **Reconciling** — a gate-refused draft: which way you edit depends on WHERE the TU's decl is <sub>L9599</sub>
- **§139** — A GATE THAT GREPS FOR VERDICTS MUST ASSERT 1:1 ACCOUNTING; and a `--src` filter must not survive a carve (P30 S38, wave 6: 10 of 16 drafts vanished) <sub>L9628</sub>
- **§140** — A METRIC IS NOT A MEASUREMENT UNTIL IT IS REPRODUCIBLE FROM THE COMMITTED TREE (P30 S1e: a phantom regression that gated the session's best lever) <sub>L9694</sub>
- **§142** — An open stub whose `h_exact` class is MATCHED elsewhere is FREE. Propagate the body; do not gate a draft. (P30 S39, +7,710 ins in two commands) <sub>L9812</sub>
- **§3-The** — measurement (do this before any wave; it is ~20 lines and needs no builds) <sub>L9824</sub>
- **§155b** — check the TYPE your oracle returns before comparing against it (S45 p5) <sub>L10621</sub>
- **§156** — an ORPHANED reconcile poisons the fleet: `dedup_propagate`'s kept edit (S45 p6/p7) <sub>L10674</sub>
- **§158** — The RANGE-EXTENDER: a fourth zero-emission asm lever completes the allocno toolkit (P30 S46 tier-3, `func_8017CE58`, 733 ins) <sub>L10746</sub>
- **§160** — THE REACH-15 WAVE HARVEST: an align-1 block move, and the instrument that called it a wall (P30 S47) <sub>L10927</sub>
- **§161** — THE RETRY-WAVE HARVEST: a jump table indexed from zero, and two allocator traps (P30 S47) <sub>L11003</sub>
- **§162** — S48 WAVE-1 HARVEST (P30, 2026-08-11): the reach-ordered sibling campaign's first 12 targets <sub>L11048</sub>
- **§163** — S48 WAVES 2-3 HARVEST (P30, 2026-08-11/12): the five that were byte-probed and are actionable <sub>L11794</sub>
- **§165** — S48 WAVE-4 HARVEST (P30, 2026-08-12): banked the same day the wave landed <sub>L13736</sub>
- **§166** — THE DESTINATION-TU ORACLE (P30 S48): the seven-attempt bug that was never codegen <sub>L14956</sub>
- **§167** — S48 WAVE-5/6 HARVEST (P30, 2026-08-12): the saturation point <sub>L15012</sub>
- **§176e** — SYMBOL IDENTITY IS COMPUTABLE OFFLINE (P31 S52): `tools/reloc_identity.py` <sub>L16906</sub>
- **§3-A.** — The seven under-reporting holes (all in `gate_main`, all the same shape) <sub>L17040</sub>
- **§3-C2.** — RECONCILE BEFORE THE FIRST GATE — a parked draft gets HARDER to bank, not easier <sub>L17087</sub>
- **§3-D.** — The measured cost shape, and what to build next <sub>L17110</sub>
- **§176i** — WHAT A STATIC PRE-GATE CHECK CAN AND CANNOT PROVE (P31 S52, wave Q) <sub>L17128</sub>
- **§179** — IDIOMS MINED FROM THE WAVE P/Q JOURNALS (P31 S52, harvest pass) <sub>L17367</sub>
- **§179-G** — 🟡 A PIN CAN **CREATE** A COMBINE `LOG_LINK` AND DELETE AN `andi` (sixth RC-5 channel, n=1) <sub>L17596</sub>
- **§176c** — MAIN (SLUS_007.26) CANNOT BE GATED INCREMENTALLY <sub>L17663</sub>
- **§180** — THE LEFTOVER-DRAFT HARVEST: RE-VERIFY WHAT YOU ALREADY HAVE BEFORE DRAFTING ANYTHING NEW <sub>L17854</sub>
- **§180b** — WHAT THE PRE-GATE LADDER ACTUALLY FINDS IN A COLD PILE (the shape of integration debt) <sub>L17883</sub>
- **§181** — WHAT A WAVE'S GATE ACTUALLY REJECTS (P31 S53, measured on wave R's 45-draft main pile) <sub>L17920</sub>
- **§184** — COMMENT-BLINDNESS IS A DEFECT CLASS, NOT A BUG (P31 S53: three tools, one root cause, one session) <sub>L18073</sub>
- **§187** — 🔴 "SAME SOURCE" IS NOT "SAME OBJECT": THE SDK BUILD AND THE GAME BUILD DISAGREE ON GTE NOPS <sub>L18179</sub>
- **§190** — THREE PRESCRIPTIONS FROM THE SAME HARVEST (weaker evidence than §189, honestly labelled) <sub>L18342</sub>
- **§191** — WHAT THIS HARVEST DID **NOT** BANK (4 rejected, 4 narrowed) — recorded so it is not re-derived <sub>L18379</sub>
- **§192** — THE PRE-GATE LADDER WAS MAIN-ONLY, AND NOBODY COULD SEE IT (P31 S54) <sub>L18401</sub>
- **§193** — THE WAVE-T HARVEST (P31 S54): 71 index_gap reports -> 9 laws, 5 rejected, 61 already-covered <sub>L18466</sub>
- **§193-A** — The wave card ships only OPEN-set pointers and discards the atlas's BANKED one — `exemplar`/`sibs` are stubs 100% by construction (tools/atlas.py:96/657), while `seed.ref` (matched pool, atlas.py:505-536) is dropped at build_wave_atlas.py:143 <sub>L18483</sub>
- **§193-G** — §164-54's "scope to ≥4 arms" bound is byte-wrong — the dispatch-topology oracle goes live at THREE case nodes (`balance_case_nodes` splits at `i > 2`), but only for a signed-after-promotion index <sub>L18787</sub>
- **§193-I** — A DECLARED AGGREGATE LOCAL HAS AN 8-BYTE FRAME STRIDE — CEIL(size,8), NOT size. N ARRAYS THEREFORE COST 8·k MORE THAN ONE HAND-LAID STRUCT (k = how many of them have size mod 8 ≠ 0), AND THE TELL IS IDENTICAL INSTRUCTION COUNT WITH EVERY $sp DISPLACEMENT SHIFTED BY THE SAME CONSTANT. <sub>L18888</sub>
- **§193-REJECTED** — what this harvest did NOT bank (recorded so it is not re-derived) <sub>L18947</sub>
- **§194** — THE WAVE-U HARVEST (P31 S54): 64 index_gap reports -> 14 laws, 5 rejected, 44 already-covered <sub>L18974</sub>
- **§194-E** — The wave card's `exemplar` is the TARGET ITSELF on 42/73 wave-U and 36/71 wave-T cards — a construction consequence of `atlas.py:657` (exemplar = max-nins OPEN member) meeting `build_wave_atlas.py:166` (one card per gid); and the shipped §193-A `seed_ref` is same-binary on 0/51, so no card field can ever name a destination-TU sibling <sub>L19199</sub>
- **§194-G** — Reading the integer half of a 16.16 stack aggregate: REGISTER-LIVENESS, not the C spelling, decides `sra` vs `lhu` — and the break is count-neutral <sub>L19309</sub>
- **§194-K** — Blind sched1's alias oracle with a second SET of a pointer pseudo — the first zero-byte, non-volatile, dependence-CREATING lever (corrects §167-05's "volatile is the only door"; fourth consumer of reg_n_sets) <sub>L19485</sub>
- **§194-REJECTED** — what this harvest did NOT bank (recorded so it is not re-derived) <sub>L19729</sub>
- **§195** — THE WAVE-V HARVEST (P31 S54): 67 index_gap reports -> 14 laws, 9 rejected, 76 already-covered <sub>L19750</sub>
- **§195-I** — §145(b) AMENDED — the pointer-bump `addiu` is saved by cse, not combine: ANY second SET of a pseudo in the address's equivalence chain (in-place `p += K`, §145(b)'s `p = r;` copy, or an asm re-tie) kills the fold; the pass is cse and the gate is `invalidate`'s `reg_tick++` <sub>L20198</sub>
- **§195-M** — Frame `vars` is a SEQUENTIAL bump-allocation, not a flat sum: §193-I's CEIL(aggregate,8) term and §165-03/§167-06's 8×orphan term are the SAME frame_offset walk at two different compiler stages, and each stage re-CEILs frame_offset to 8 before it allocates <sub>L20411</sub>
- **§195-REJECTED** — what this harvest did NOT bank (recorded so it is not re-derived) <sub>L20507</sub>
- **§197** — THE WAVE-W HARVEST (P31 S54): 68 index_gap reports -> 4 laws, 3 rejected, 41 already-covered <sub>L20608</sub>
- **§199** — THE WAVE-X HARVEST (P31 S54/S55): 63 index_gap reports -> 7 laws, 2 rejected, 56 already-covered <sub>L20748</sub>
- **§199-C** — A NEGATIVE CONSTANT MULTIPLY ALWAYS TAKES expmed's negate_variant — but whether you ever SEE the neg is decided by COMBINE, and for an EVEN |K| it never disappears <sub>L20853</sub>
- **§199-D** — A narrow UNSIGNED value compared in an ordered `if` emits `sltiu`/`sltu`; the only dial is the WIDTH of a real object, and a widening `(s32)` cast is inert — AMENDS §35 (whose stated "only CSE-reuse canonicalizes" mechanism is byte-wrong) and does NOT apply inside a `switch` <sub>L20901</sub>
- **§199-G** — At TWO case nodes the switch-vs-if oracle is not blind — but the tell is ALL tests positive + a trailing `j default`, NOT the first test's polarity <sub>L21074</sub>
- **§201** — THE WAVE-Y HARVEST (P31 S55): 67 gap reports -> 5 laws, 8 rejected, 53 already-covered <sub>L21189</sub>
- **§204** — THE WAVE-Z HARVEST (P31 S56): 82 gap reports -> 5 laws, 16 rejected, 30 already-covered <sub>L21588</sub>
- **§207** — THE WAVE ab–ag HARVEST (P31 S58): 278 byte-banked notes → 25 laws, 103 self-reported no-gap <sub>L22222</sub>
- **§233** — THE WAVE aa–bg HARVEST (P31 S58b): 1,101 byte-banked notes → 24 new laws, 21 addenda, ~700 already-covered <sub>L23313</sub>
- **§236** — THE DECLARATION LAYER IS THE DOMINANT BANK-BLOCKER: NINE WAYS A BYTE-PERFECT BODY FAILS THE GATE (P31 S58b) <sub>L23427</sub>
- **§247** — TWO BRANCHES TO **ONE** LABEL MEANS THE SOURCE CONDITION IS NEGATED (P31 S58b) <sub>L23873</sub>
- **§254** — THE DEAD PARAMETER IS A REGISTER-PLACEMENT TOOL **(single observation — not yet cross-confirmed)** (P31 S58b) <sub>L24067</sub>
- **§259** — THE DISCARD LEDGER FOR THE aa–bg HARVEST (P31 S58b): WHAT WAS MINED AND REJECTED, AND WHY <sub>L24724</sub>
- **§260-A** — STAGE 2 IS PROVEN, AND THE WHOLE jtbl PIPELINE IS AUTOMATED AT THE GATE (P31 S59, same day) <sub>L24813</sub>
- **§261** — THE -O0 ORACLE: DERIVE THE OPT LEVEL FROM THE TARGET, AND `$fp` IS NOT THE TELL (P31 S59) <sub>L24849</sub>
- **§267** — ADDENDA HARVESTED FROM WAVES at/bh/bk/bl (P31 S59b) <sub>L25120</sub>
- **ADD-9** — → §213-3 / §217 addendum — ADJACENT PRE-CALL FRAME STORES ARE ONE AGGREGATE; THE UNESCAPED SCALAR NEIGHBOR IS DEAD-STORED <sub>L25215</sub>
- **§269** — ADDENDA HARVESTED FROM WAVES ax/bm (P31 S59c) <sub>L25339</sub>
- **§271** — Ordinal IMM pairing: text order is NOT emission order; emit CANDIDATES, let the oracle pick (P31 S59) <sub>L25577</sub>
- **§273** — A standalone compile is the WRONG oracle for a TU-destined draft (P31 S59) <sub>L25619</sub>
- **§274** — ADDENDA HARVESTED FROM 18 WAVES (P31 S60): 315 candidates, 255 already covered, 21 sharpenings, 3 new laws <sub>L25634</sub>
- **§278** — ADDENDA HARVESTED FROM WAVE cf (P31 S60): 34 candidates, 13 already covered, 8 sharpenings, 4 new laws <sub>L26625</sub>
- **§283** — ADDENDA HARVESTED FROM THE 36-WAVE BATCH (P31 S60): 1,216 candidates, 859 already covered, 46 sharpenings, 9 new laws <sub>L27121</sub>
- **§287** — A STACK-FRAME HOLE BELOW TWO ADDRESS-TAKEN AGGREGATE LOCALS IS A LEADING PAD MEMBER OF ONE COMBINED STRUCT, NOT SEPARATE LOCALS OR A REGISTER PIN (P31 S60/dj; `func_8017D104`, ov_SC06_027, byte-proven 47/47) (P31 S60; waves #, byte-proven) <sub>L29086</sub>
- **§293** — THE "WHOLE-OBJECT GATE NEEDS EVERY SIBLING" LAW, WRITTEN PROPERLY: IT IS THREE LAWS, AND THE LOAD-BEARING ONE IS "THE BASELINE, NOT THE SIBLINGS" (P31 S61; byte-proven on 15 binaries in one night) <sub>L29109</sub>
- **§294** — ADDENDA HARVESTED FROM THE S61 GEN0/MAXTOK/MAIN/DEEPSEEK BATCH (waves ab8/ab16/ab24/ab32 · g0a–g0f · m0a · ds1/ds2): 99 candidates, 52 covered, 15 notes → 10 addenda, 29 notes → 5 new laws (§295–§299), 3 refuted <sub>L29159</sub>
- **§303** — MODULE ISLAND TABLES: DERIVE THE PADS AT BUILD TIME, PEEL NOTHING — THE §154-A/§260 "island-pads"/"island-blocked" WALLS DISSOLVE (P31 S62 T3a; byte-proven md_SC03_076 func_801F0A9C + func_801F0F28, sha 9a165e36…) <sub>L29763</sub>
- **§305** — "CARVE-REFUSED" AT GATE TIME IS THREE NAMED, DETERMINISTIC CLASSES — NONE OF THEM A CARVE (P31 S62 T3; 28 resolver drafts autopsied 28/28) <sub>L29822</sub>
- **§313** — A RECOVERY STAGE THAT REWRITES THE DRAFT IS PART OF THE MEASUREMENT: GATE THE RAW DRAFT FIRST, THE REWRITE ONLY AS A FALLBACK (P31 S65 t5r-recovery; byte-proven func_8017BEBC, 246 ins) <sub>L30185</sub>
- **§314** — AN IF/ELSE-IF ABS-RANGE CHECK'S C SPELLING IS INERT: FOUR STRUCTURALLY DIFFERENT REWRITES ALL COMPILE BYTE-IDENTICAL, AND NONE REACHES A TARGET THAT SINKS THE NEGATIVE ARM INTO AN OUT-OF-LINE BLOCK (P31 S65; UNPROVEN, gate-refused draft func_80181720) <sub>L30241</sub>
- **§315** — ALL-CONSTANT AGGREGATE FILL: THE EMISSION ORDER IS SHARED-LITERAL GROUPS × DESCENDING INDEX, WITH PAIRED SUB-FIELDS INTERLEAVED (P31 S66; ⚠ **UNPROVEN** — `func_80185214`, gate-REFUSED draft, closeness 32→5, never MATCHed) <sub>L30273</sub>
- **§316** — A GUARD CHAIN THAT GATES A SUCCESS BLOCK ROUTES ITS FAILING GUARDS TO A LABEL **BEFORE** THE FLAG TEST, NOT TO THE EPILOGUE: THE RESIDUAL IS IMM-OFFSET-ONLY AT AN EXACTLY EQUAL INSTRUCTION COUNT (P31 S66; byte-proven func_80180284) <sub>L30310</sub>
- **§318** — A UNARY MINUS STORED BACK INTO THE SAME HALFWORD IS COMPUTED IN HImode, SO ITS LOAD IS `lhu`; AN INLINE `(s32)` CAST IS PROVABLY INERT AND ONLY A NAMED SImode LOCAL BUYS `lh` (P31 S66; `func_8018568C`, ov_SC03_028 — **`match_one`-only, NOT byte-gated**) <sub>L30378</sub>
- **Addendum** — Addendum to §167-12 — the single-operand volatile keepalive, re-confirmed at a gated MATCH (func_8017F498) <sub>L30485</sub>
- **§NNN** — REFUTED: A CODE BLOCK SHARED BY TWO *DIFFERENT* SWITCH STATEMENTS IS ORDINARY FORWARD `cross_jump`, NOT A SHAPE C CANNOT REACH — §164-11 ALREADY BANKS IT FROM PLAIN NESTED SWITCHES (P31 S66 round3, `func_8001B0D4`; ⚠ **UNPROVEN** — gate-REFUSED draft, closeness 68→45, never MATCHed) <sub>L30640</sub>
- **§323a** — R53, TWICE IN ONE HOUR: A FAILED BUILD LEAVES THE PREVIOUS BINARY, AND `sha1sum` READS GREEN (P31 S67) <sub>L30926</sub>
- **§328** — THE VOLATILE ALIAS MUST BE AN *OBJECT*, NOT A CAST: `*(volatile s32*)&sym` UNFOLDS %lo INTO A SEPARATE `addiu` (P31 S67; byte-proven ov_SC07_007/func_80181B8C, 156 ins, NEW LAW) <sub>L31024</sub>
- **§332a** — MAIN'S RESIDUAL FRONTIER IS CONTAMINATED WITH TOOLCHAIN WALLS: 4 OF 7 IN ONE WAVE (P31 S67, measured) <sub>L31096</sub>
- **§333** — FRAME SIZE IS SET BY *DECLARED* AGGREGATES, NOT USED ONES: AN UNREFERENCED TRAILING LOCAL IS A REAL DIAL (P31 S67; three independent byte-proven instances in one wave) <sub>L31115</sub>
- **§337** — THE CC1-ONLY BLOCKER CLASS: `blocker_probe`'s STATIC ORACLE REPORTS "none" AND THE WHOLE-TU COMPILE STILL FAILS (P31 S67; ov_SC04_011/func_801827DC, md_MAIN_027/func_800CB4A4) <sub>L31157</sub>
- **§340** — §194-K COROLLARY: **FLIP THE FALSE EDGE YOU CANNOT DELETE.** A "scheduler" residual can be sched.c's ALIAS ORACLE emitting a FALSE true-dependence; source order chooses its DIRECTION (P31 S67; byte-proven ov_SC03_107/func_8017CF48, 10 -> 0 in one compile, zero bytes) <sub>L31209</sub>
- **§346** — `c ? X : -X` TAKES expand_expr's COND_EXPR **SINGLETON** PATH (copy, then negate IN PLACE) — AN if/else STATEMENT GIVES THE TWO-ARM FORM (P31 S67; byte-proven ov_SC03_102/func_80180C38, closed the last instruction) <sub>L31322</sub>
- **§353** — USE `-fno-thread-jumps` AS AN **ORACLE** TO PROVE A RESIDUAL IS thread_jumps, THEN LAUNDER THE *VALUE* TO KEEP A DEAD RE-TEST (P31 S67; byte-proven ov_SC01_008/func_8017EC68, 279 ins) <sub>L31519</sub>
- **§357** — ONE STRUCT POINTER, NOT TWO: A SECOND SOURCE VARIABLE BUILDS A THIRD IV (P31 S68; byte-proven ov_SC06_029/func_80181DF8, 335 ins, 330 → 13) <sub>L31589</sub>
- **§358** — (sharpens §333) — AN **UNREFERENCED** FIXED-SIZE AGGREGATE LOCAL IS LOAD-BEARING (P31 S68; same function) <sub>L31598</sub>
- **§371** — ★★ — CARVING A **SINGLE-OBJECT MODULE BINARY**, AND THE spimdisasm RODATA-MIGRATION TRAP THAT FOLLOWS (P31 S68; byte-proven md_MAIN_003, func_800D0D6C 345 ins) <sub>L31890</sub>
- **§383** — TWO TOOLCHAIN FACTS THE PACKS DID NOT CARRY (P31 S69) <sub>L32244</sub>
- **§388** — ★★★ — THE **-O0 COLOURING ORACLE**: simulate `stupid.c` instead of grinding spellings (P31 S69; main/func_80011380 proved a C-level WALL at 6) <sub>L32384</sub>
- **§392** — ★★★ — THE SONNET-WAVE HARVEST (P31 S69): SEVEN TYPE/ORDER LEVERS THAT EACH CLOSED A MATCH <sub>L32502</sub>
- **§332b** — ★★★ — THE §332 "WALLS" ARE A PER-OBJECT ASSEMBLER MODE, NOT A C LIMIT — 6 CLOSE AS REAL C (P31 S69, Fable-3) <sub>L32702</sub>
- **§405** — ★★★ — THE S70 WAVE HARVEST: 130 agents, 113 MATCH, and the laws they brought back <sub>L33092</sub>
- **§3-A.** — THE ORACLE HAS A HOLE: match_one cannot see a jump table (§405-A) <sub>L33098</sub>
- **§414** — ★★★ — `parallel_gate` ON `main` IS A FALSE PASS, AND THE RULE WAS ALREADY WRITTEN DOWN (P31 S71) <sub>L33510</sub>
- **§423** — ★★★ — "MATCH IN ISOLATION + GATE REJECTS + CAUSE NOT DETERMINED" ⇒ GREP THE TU FOR A FILE-SCOPE TYPEDEF THE DRAFT ALSO CARRIES (P31 S71; byte-proven `ov_SC03_092/func_8017FA74`) <sub>L33780</sub>
- **§426** — ★★★ — main's SWITCH FUNCTIONS WERE NEVER A CODEGEN WALL: ONE RODATA CARVE HAD BEEN MISSING SINCE PHASE 7 (P31 S72; 3 of the 11 "PROVEN gate-rejects" banked byte-identical in 14 s) <sub>L33855</sub>
- **§427** — ★★ — A HASH IS A CORRECTNESS ORACLE WITH ZERO DIAGNOSTIC CONTENT; PRESERVE THE RED ARTIFACT BEFORE ANYTHING REBUILDS OVER IT (P31 S72) <sub>L33931</sub>
### process, measurement & doctrine (133)
- **§8e** — The jtbl ALIGNMENT LAW + the pad-spec filter — multi-table .rodata spans (Phase 29, byte-proven; `.run/probe_jtbl/verdict.md`) <sub>L549</sub>
- **§3-The** — mechanism: game-code dedup is SOURCE-LEVEL, not an object swap (R-D1, the key lesson) <sub>L945</sub>
- **Per-binary** — toolchain provenance (R24) <sub>L978</sub>
- **§17a** — The TOOLKIT at WAVE scale (Phase-18 Step-3b/Step-1 — measured) + the pipeline-integration gotchas <sub>L1464</sub>
- **Diagnostic** — lesson: a failed in-TU build leaves a STALE `.o` <sub>L1673</sub>
- **Phase-20** — RESOLUTION — `tools/cast_call_sites.py` BUILT + the cap re-diagnosed (R14, byte-proven) <sub>L1720</sub>
- **§23** — Giant `func_80153E00` cracked (scalar-data CAST); BUT most giant drafts are STALE+INCOMPLETE, and a diag MUST remove artifacts (Phase 21 — byte-proven + a self-correction) <sub>L2051</sub>
- **§3-h** — _exact OVER-COUNTS ×134 — verify shareability before crediting a class's "reach-134" (R14) <sub>L2196</sub>
- **§28c** — The close=0 recovery is NOT fully exhausted (§26 corrected, R14); + the dedup_propagate registry-skip recovery (Phase 22 T2) <sub>L2371</sub>
- **§31-triage** — R17 applies to CODEGEN residuals, never to a compile ERROR (Phase 26 session 7, Drew asked) <sub>L2712</sub>
- **§41a** — v3.1: the def-side wall was ~71% TOOL-shaped — the five measured defects + the laws that dissolve them (Phase 25 T6, Fable5, 2026-07-09) <sub>L2788</sub>
- **§41b** — T7 execution: the object-only probe OVER-counts BANKABLE by two link/rodata classes (Phase 25 T7-M1, 2026-07-10) <sub>L2843</sub>
- **§41b** — addendum — M4 "reconcile_decls" tier is ALSO a probe over-count: 0/8 mechanical (Phase 25 T7-M4, 2026-07-10) <sub>L2892</sub>
- **§53** — SWEEP A FAMILY WITH THE TOOL ITS EXEMPLAR NEEDED: the jr/switch carve, and how omitting it manufactured the "families don't template" doctrine (Phase 28 T1, 2026-07-15) <sub>L4062</sub>
- **§3-The** — meta-lesson (R35, and why this one is expensive) <sub>L4112</sub>
- **§55** — Core-crack wave levers + the GATE-ORCHESTRATION law (Phase 29 T3, 13-agent ultracode wave, 2026-07-17) <sub>L4127</sub>
- **§55b** — THE GATE-ORCHESTRATION LAW (3 traps, ~3.5h lost; all recovered, 0 data lost) <sub>L4156</sub>
- **§57a** — Two NSD corrections + the SURGICAL-ONLY law + the honest broad-sweep yield (Phase 29, 2026-07-18) <sub>L4337</sub>
- **§58** — match_one MATCH ≠ BANK: the four blind spots + the crack-wave reconcile-before-bank law (Phase 29 crack-wave, 2026-07-18) <sub>L4377</sub>
- **§60** — Classify the residual, don't rank it: the deterministic residual→class classifier and what it measured about the backlog (Phase 29 Task-13A, 2026-07-21) <sub>L4441</sub>
- **What** — it measured — the whole open backlog, byte-grounded <sub>L4465</sub>
- **§3-The** — parallel-probe race this surfaced <sub>L4497</sub>
- **§61b** — The jtbl gate stage: built, and the ORDERING law it exposed (Phase 29 Task-14 stage 4, 2026-07-21) <sub>L4692</sub>
- **§62** — The jtbl RECONCILE must also follow the carve: the post-carve draft reconcile (`harvest_verify._jtbl_reconcile`, Phase 29 SESSION-11, 2026-07-22) <sub>L4867</sub>
- **§63** — UPDATE (Phase 29 SESSION-14) — `fix_header_decl`'s "SAFE" verdict is FLEET-BLIND; it MUST be R22-validated <sub>L5034</sub>
- **§65** — The stranded-draft recovery: BLAST-RADIUS TIERS, and the per-overlay de-macroize that refutes §20's DEF-conflict wall (`tools/demacroize.py` + `tools/blocker_probe.py`, Phase 29 SESSION-16, 2026-07-24) <sub>L5049</sub>
- **§65a** — The blast-radius taxonomy (makes §61's law structural instead of remembered) <sub>L5064</sub>
- **§65d** — Existing-ladder baseline, measured (do this before building a recovery stage) <sub>L5125</sub>
- **§65e** — Two oracles, and the disagreement is the finding (R34 in practice) <sub>L5135</sub>
- **§65f** — The de-macroize lever's BOUNDARY, measured: byte-neutral 14 times of 15, and the 15th is why the gate exists <sub>L5152</sub>
- **§66c** — Before a wave, verify the FUEL exists; an "already attempted" set built from the wrong directory lies in BOTH directions <sub>L5251</sub>
- **§66d-5** — `residual_class`'s "structural ⇒ permuter CPU is waste" is WRONG for schedule permutations (measured, Phase 29 SESSION-18) <sub>L5525</sub>
- **§3-The** — honest fix was source-level and cheap <sub>L5784</sub>
- **§3-The** — residual, and the honest read <sub>L6294</sub>
- **§83** — The parameterised-repeat law, the spill-area trap, and why a per-case edit cannot move a per-case symptom (Phase 29 SESSION-20, `func_80183814` 5,122 ins, cold-ish start → 36 structural / 99.3%) <sub>L6446</sub>
- **Scope** — , measured (do not over-generalise — §80) <sub>L6552</sub>
- **§3-Two** — ladder lessons banked with it <sub>L6562</sub>
- **§3-Do** — the WHOLE axis in one edit, then R22 once <sub>L6601</sub>
- **§3-THE** — LAW: all-or-nothing PER FAMILY <sub>L6634</sub>
- **§88b** — the `slti` literal-position law (extends §78 to comparisons) <sub>L6720</sub>
- **§88e** — a wrong diagnosis, refuted properly (the model for how to treat an inherited lever) <sub>L6742</sub>
- **§89a** — MEASURE the write set; do not assert its tier (`tools/blast_radius.py`) <sub>L6766</sub>
- **§90d** — Do not measure a live wave's drafts (§87 in real time) <sub>L6844</sub>
- **§98** — `conform_decls` had three defects, and only the third needed R22 to find (Phase 29 SESSION-22, `func_8014CF04`) <sub>L7147</sub>
- **§106** — Persist the MEASUREMENT, derive the POLICY: a stored route let a stale file out-vote the live table (Phase 29 T54, `residual_class._ROUTE`) <sub>L7504</sub>
- **§125** — Split the CARVE from the BODY before calling a jr residue a wall — and measure it by SHA from a CLEAN tree (P30 SESSION-28; **this section's first draft was WRONG and the method caught it**) <sub>L8240</sub>
- **§3-The** — meta-lesson <sub>L8291</sub>
- **Wave** — economics (measured, for the next batch's sizing) <sub>L8987</sub>
- **§136b** — A prior wave's "genuine byte-DIFF" verdict is NOT reliable evidence (4 of 4 refuted) <sub>L9067</sub>
- **§136g** — When the index points at the WRONG lever: two byte-refuted routings (func_801863B4) <sub>L9245</sub>
- **§136h** — CORRECTION: the zero-crack pool does NOT "refill with cheap work" (my error, byte-measured) <sub>L9274</sub>
- **§136j** — The failure MIX flips with function size (measured across four bands, one session) <sub>L9336</sub>
- **Rank** — the lane by measured concentration, not by class count <sub>L9515</sub>
- **§140** — A METRIC IS NOT A MEASUREMENT UNTIL IT IS REPRODUCIBLE FROM THE COMMITTED TREE (P30 S1e: a phantom regression that gated the session's best lever) <sub>L9694</sub>
- **§3-The** — measurement (do this before any wave; it is ~20 lines and needs no builds) <sub>L9824</sub>
- **§3-And** — the report-vs-bytes lesson attached to it <sub>L9856</sub>
- **§146** — RE-MEASURE A WALL BEFORE YOU RESPECT IT. Both "permanent" giants fell to drafts already on disk. (P30 S6, +50,094 ins) <sub>L10011</sub>
- **§147** — The three-stratum FRAME LAW, and four "stop searching" verdicts (P30 S42, `func_8017C294`, serial run) <sub>L10070</sub>
- **§3-C.** — Inner-block declaration does NOT delay slot allocation — BYTE-REFUTED <sub>L10102</sub>
- **§3-D.** — "Cheap fuel" that was never probed: 0 of 31 templatable <sub>L10327</sub>
- **§3-Two** — corrections to the record <sub>L10379</sub>
- **§3-The** — two fallouts, and how to close them (both measured, in order) <sub>L10429</sub>
- **What** — does NOT work (14 byte-measured probes) <sub>L10520</sub>
- **§157** — the cheap-tier size cliff, measured (S45 p6) <sub>L10721</sub>
- **§162** — The cross-jump "CALL veto" is a COUNT law, not a CALL law (BOUNDS §88a; P30 S48, `func_80189540`) <sub>L11336</sub>
- **§3-The** — law <sub>L11583</sub>
- **DIAGNOSTIC** — TELL — two faces, one law <sub>L11625</sub>
- **§163** — S48 WAVES 2-3 HARVEST (P30, 2026-08-11/12): the five that were byte-probed and are actionable <sub>L11794</sub>
- **§163z** — THE UNVETTED REMAINDER (do not cite as law; each needs a dedupe pass) <sub>L11862</sub>
- **§164z** — REFUTED CLAIMS: do NOT re-derive these <sub>L13670</sub>
- **§165z** — REFUTED THIS WAVE: do NOT re-derive <sub>L14912</sub>
- **§167z** — REFUTED IN WAVES 5/6: do NOT re-derive <sub>L16208</sub>
- **§168** — THE COUSIN TIER (P30 S49, 2026-08-12): h_seq's exact-hash brittleness, measured — and the similarity map above it <sub>L16265</sub>
- **§176g** — SIZE A WAVE BY INSTRUCTIONS, NOT BY CARDS (P31 S52 — the adopted doctrine) <sub>L16994</sub>
- **§176h** — THE BATCH-SUBSTITUTION HAZARD MAP (P31 S52): seven holes, three wrong fixes, one law <sub>L17032</sub>
- **§3-D.** — The measured cost shape, and what to build next <sub>L17110</sub>
- **§176j-2** — THE REPAIR PASS, MEASURED (do this instead of resuming) <sub>L17186</sub>
- **§176-C** — 🔴 WALL REFUTATION: a hard-register pin CANNOT schedule around a call, because of a genuine gcc-2.7.2 bug <sub>L17750</sub>
- **§176-E** — Two cheap source spellings, both cc1-probed <sub>L17802</sub>
- **§180** — THE LEFTOVER-DRAFT HARVEST: RE-VERIFY WHAT YOU ALREADY HAVE BEFORE DRAFTING ANYTHING NEW <sub>L17854</sub>
- **§181** — WHAT A WAVE'S GATE ACTUALLY REJECTS (P31 S53, measured on wave R's 45-draft main pile) <sub>L17920</sub>
- **§182** — §177's HONEST NEGATIVE: the epilogue lever cracked 4 of 16, and the `800c3` cluster held <sub>L17976</sub>
- **§183** — THE DECLARATION-RECONCILIATION PLAYBOOK (P31 S53, measured on 20 byte-verified drafts) <sub>L18002</sub>
- **§185** — EDIT THE SIDE THAT IS CHEAP TO VERIFY, AND CHECK A TU RETYPE AT ITS USE SITES <sub>L18101</sub>
- **§190** — THREE PRESCRIPTIONS FROM THE SAME HARVEST (weaker evidence than §189, honestly labelled) <sub>L18342</sub>
- **§194-A** — A zero-byte scheduling fence goes AFTER the defining statement to make that computation emit FIRST in its block — and the barrier predicate is `volatile`-or-colon-less, not the `"memory"` clobber (COMPLEMENTS §165-40; does not refute it) <sub>L18991</sub>
- **§194-D** — Declared width of a computed-value local is a sched1 dial (count-neutral) — a replication + attribution correction of §165-17, NOT a new argument-register law <sub>L19158</sub>
- **§195-J** — GTE / PsyQ op CALL-vs-INLINE is a PER-SITE SOURCE FACT, not a TU style — both forms coexist in one TU (measured in 2 TUs), and the tell is the target's own opcodes (`lwc2`/`sqr`/`swc2` vs `jal`), not the sibling. Costs -8 ins on func_8018505C. Corollary: the game's inline `sqr` macro emits TWO hazard nops, the SDK's `Square0` body emits ONE — so the inline form is provably not `Square0` inlined (a second instance of §187's SDK-vs-game GTE nop divergence). <sub>L20263</sub>
- **§201-E** — §194-J-2 — The `last_mem_set` deletion window is measured in SOURCE/expand order, not in the printed stream; a foreign store moved between the pair in C source is a real lever, and `volatile` is not always the better one <sub>L21409</sub>
- **§230** — THE ANCHOR PROBE: with `%hi`/`%lo` masked, the surviving `addiu` deltas tell you which assignment was written first **(single observation — not yet cross-confirmed)** (P31 S58) <sub>L23165</sub>
- **§257** — THE DEAD-END LEDGER (P31 S58b): ELEVEN LEVERS THAT MEASURED NULL OR BACKFIRED <sub>L24151</sub>
- **§194-B** — / §209 addendum (P31 S58b) — TWO MORE INSTANCES, AND THE BOUND IS NOW REFUTED FOUR WAYS <sub>L24220</sub>
- **§266** — THE INERT-RIDER LAW: A LEVER IS ONLY CITABLE WHEN ITS SOLO REMOVAL BREAKS THE MATCH (P31 S59b; measured 4-of-8 on this batch) <sub>L25080</sub>
- **ADD-4** — → §167-37 addendum — THE FIFTH PRECONDITION, NOW MEASURED: DOWNSTREAM FIELD RE-READS ⇒ NAME IT **AND** STORE **INSIDE** THE ARM <sub>L25394</sub>
- **ADD-9** — → §255 "AND CASE-BODY PLACEMENT" bound / §222-addendum-3 — ON A LARGE SPARSE TREE, BODIES FOLLOW **SOURCE** ORDER (measured by a one-word probe) <sub>L25471</sub>
- **ADDENDUM** — to §172b-1 — TWO PLACEMENT DIALS THE PROMOTION LAW DOESN'T NAME: NARROW THE COUNTER'S DECLARED TYPE, AND MOVE THE CAST INTO THE LOOP BODY <sub>L26100</sub>
- **What** — I could not verify <sub>L27074</sub>
- **ADDENDUM** — to §164-75 — the fold-reassociation law also fires at a variable's INITIALIZER, not only a later expression <sub>L27131</sub>
- **What** — I could not verify <sub>L27648</sub>
- **ADDENDUM** — to §153 / §236-5 (func_801A419C, md_SC07_003 — waves di and dl, corroborating; refutes a contradicted dj-wave card) <sub>L27865</sub>
- **What** — I could not verify <sub>L28105</sub>
- **ADDENDUM** — to §174 Law 4 (func_8017E9A8, ov_SC06_015) <sub>L28125</sub>
- **ADDENDUM** — the zero-emission-asm family gains a REF-SLIDER PLACEMENT LAW and a paired RESTORER (func_800CB900, md_MAIN_026) <sub>L28165</sub>
- **What** — I could not verify <sub>L28663</sub>
- **What** — I could not verify <sub>L28969</sub>
- **§293** — THE "WHOLE-OBJECT GATE NEEDS EVERY SIBLING" LAW, WRITTEN PROPERLY: IT IS THREE LAWS, AND THE LOAD-BEARING ONE IS "THE BASELINE, NOT THE SIBLINGS" (P31 S61; byte-proven on 15 binaries in one night) <sub>L29109</sub>
- **§294** — ADDENDA HARVESTED FROM THE S61 GEN0/MAXTOK/MAIN/DEEPSEEK BATCH (waves ab8/ab16/ab24/ab32 · g0a–g0f · m0a · ds1/ds2): 99 candidates, 52 covered, 15 notes → 10 addenda, 29 notes → 5 new laws (§295–§299), 3 refuted <sub>L29159</sub>
- **§313** — A RECOVERY STAGE THAT REWRITES THE DRAFT IS PART OF THE MEASUREMENT: GATE THE RAW DRAFT FIRST, THE REWRITE ONLY AS A FALLBACK (P31 S65 t5r-recovery; byte-proven func_8017BEBC, 246 ins) <sub>L30185</sub>
- **REFUTED** — claim — REFUTED — the `j`-slot store is an ASPSX macro-expansion hop, not a cse split; maspsx hard (func_8005DBD8) <sub>L30589</sub>
- **§NNN** — REFUTED: A `sw %lo(SYM)($at)` IN A JUMP'S DELAY SLOT WITH ITS `lui $at` STRANDED ABOVE THE JUMP IS **ASSEMBLER** MACRO-EXPANSION, NOT A cse SPLIT — OUR PIPELINE CANNOT EMIT IT FROM ANY C, AND THE +1 IS A `maspsx` GAP (P31 S66 round2, `func_8005DBD8`, byte-probed) <sub>L30591</sub>
- **REFUTED** — claim — REFUTED: a block shared across TWO switch statements is ordinary forward cross_jump, not a (func_8001B0D4) <sub>L30638</sub>
- **§NNN** — REFUTED: A CODE BLOCK SHARED BY TWO *DIFFERENT* SWITCH STATEMENTS IS ORDINARY FORWARD `cross_jump`, NOT A SHAPE C CANNOT REACH — §164-11 ALREADY BANKS IT FROM PLAIN NESTED SWITCHES (P31 S66 round3, `func_8001B0D4`; ⚠ **UNPROVEN** — gate-REFUSED draft, closeness 68→45, never MATCHed) <sub>L30640</sub>
- **Addendum** — §194-A addendum — the bare/colon-less fence measured NULL and only the "memory"-clobber fo (func_8017E464) <sub>L30761</sub>
- **§322** — A PROBE THAT ANSWERS A *NECESSARY BUT NOT SUFFICIENT* QUESTION WILL PRICE BLOCKED WORK AS FREE: RUN THE REAL PLANNER WHEN THE PLANNER IS PURE (P31 S67; measured, 96 of 159 open jtbl functions) <sub>L30866</sub>
- **§323a** — R53, TWICE IN ONE HOUR: A FAILED BUILD LEAVES THE PREVIOUS BINARY, AND `sha1sum` READS GREEN (P31 S67) <sub>L30926</sub>
- **§324** — THE ARITY-SELF WALL NEEDS *BOTH* HALVES: A K&R DEFINITION **AND** A NO-PROTO TU DECL; EITHER ALONE STILL FAILS (P31 S67; rtu-proven ov_SC01_005/func_8017FBCC, 14 instances measured) <sub>L30949</sub>
- **§328** — THE VOLATILE ALIAS MUST BE AN *OBJECT*, NOT A CAST: `*(volatile s32*)&sym` UNFOLDS %lo INTO A SEPARATE `addiu` (P31 S67; byte-proven ov_SC07_007/func_80181B8C, 156 ins, NEW LAW) <sub>L31024</sub>
- **§332a** — MAIN'S RESIDUAL FRONTIER IS CONTAMINATED WITH TOOLCHAIN WALLS: 4 OF 7 IN ONE WAVE (P31 S67, measured) <sub>L31096</sub>
- **§337** — THE CC1-ONLY BLOCKER CLASS: `blocker_probe`'s STATIC ORACLE REPORTS "none" AND THE WHOLE-TU COMPILE STILL FAILS (P31 S67; ov_SC04_011/func_801827DC, md_MAIN_027/func_800CB4A4) <sub>L31157</sub>
- **§342** — A `void *` PARAMETER CAST TO ITS REAL TYPE IN A LOCAL IS **NOT** BYTE-NEUTRAL WHEN A LATER PARAMETER ALSO NEEDS A CALLEE-SAVED REGISTER (P31 S67; byte-proven ov_SC07_002/func_80181394, NEW LAW) <sub>L31257</sub>
- **§343** — `decl_prior`'s FLEET MAJORITY CAN BE WRONG ABOUT THE TRUE SIGNATURE — READ THE RIVALS, NOT JUST THE WINNER (P31 S67; measured on func_8012BD14 / func_8012D624 / func_80143C74) <sub>L31274</sub>
- **§352** — ⚠ TWO IDENTICAL `__asm__ __volatile__("")` BARRIERS **MERGE WITH EACH OTHER** — SPELL THE SECOND ONE DIFFERENTLY (P31 S67; byte-proven resident/func_800D128C, measured closeness 105 when they merged) <sub>L31486</sub>
- **§356** — MEASURE A DRAFT IN THE TU IT WILL LIVE IN, NOT IN THE STANDALONE PROBE (P31 S68; measured over 47 stored drafts) <sub>L31574</sub>
- **§361** — ★ — A LOOP-TAIL BYTE SIGNATURE THAT NAMES ITS SOURCE SHAPE — AND THE LAW THAT A "SCHEDULING TIE" MAY BE YOUR OWN EARLIER LEVER (P31 S68; byte-proven main/func_800241C0, fable escalation, 19 → 0 in 3 iterations) <sub>L31637</sub>
- **§370** — ★★ — A **HARD BOUND** FROM sched.c, AND THE reorg SLOT-STEAL DIAGNOSTIC (P31 S68; main/func_8001BC6C, 69 ins, NOT closed — 33 → 28 over ~45 measured compiles) <sub>L31838</sub>
- **§376** — ★★★ — A STANDALONE `match_one` CLOSENESS OF 0 IS A CLAIM ABOUT THE **BODY**, NEVER ABOUT THE **TU** (P31 S69; measured 0/28) <sub>L32055</sub>
- **§384** — ★★★ — A CARVE-CONFIG BANK IS RED UNTIL YOU RE-EXTRACT, AND THAT LOOKS EXACTLY LIKE A FALSE BANK (P31 S69; measured twice, cost one destroyed match) <sub>L32259</sub>
- **§378b** — ★★★ — THE FOUR VARIANTS OF THE DECL BLOCKER, AND THE TWO PLACES §378 DOES **NOT** APPLY (P31 S69, all four measured the same day) <sub>L32572</sub>
- **§398** — ★★★ — `family_remap` CARRIES THE **SOURCE** TU's DECL ENVIRONMENT INTO A DESTINATION THAT ALREADY OWNS THOSE NAMES (P31 S69; measured 3 banked of 22) <sub>L32835</sub>
- **§3-E.** — WHAT THE AGENTS REFUTED <sub>L33148</sub>
- **§408** — ★★★ — §406 REFUTED AS A SWEEP: THE SHAPE IS THE FAMILY, THE DISAGREEMENT IS THE DEFECT (P31 S71; 0 MATCH / 14 applied, 0 / 210) <sub>L33209</sub>
- **§411** — ★★★ — THE PACK MUST CARRY THAT FUNCTION'S OWN HISTORY (P31 S71; measured 38/39 vs 124/131) <sub>L33386</sub>
- **§428a** — ★★★ — TWO RESIDUALS THAT MOVE IN OPPOSITE DIRECTIONS UNDER EVERY LEVER USUALLY SHARE ONE CAUSE (P31 S72; `main/func_8001B0D4`, NEAR/53 -> MATCH; **my first answer here was WRONG and is kept below as the refutation**) <sub>L33988</sub>
### (unbucketed — title matched no symptom vocabulary) (325)
- **§3-How** — to use this <sub>L30</sub>
- **§1** — Idiom catalog (asm pattern → C that produces it) <sub>L39</sub>
- **§3-I3** — Division by a constant → magic multiply <sub>L54</sub>
- **§3-I4** — Runtime (variable) division → `divu` + zero-check `break` (NEEDS `--expand-div`) <sub>L60</sub>
- **§2** — Writing matching C (what makes gcc emit X) <sub>L69</sub>
- **§3a** — Escalation TIER above the permuter — web-research the compiler internals (HIGH VALUE, proven) <sub>L128</sub>
- **§3b** — §31-directed permuter mutation — bias the search over the class's levers (Phase 24 T5) <sub>L147</sub>
- **Residual** — B — a `return <const>` materialised late / merged instead of distributed per-site <sub>L886</sub>
- **§3-The** — A→B→C per-overlay workflow <sub>L1110</sub>
- **Dedup-credit** — (§11) for overlays — two shapes <sub>L1127</sub>
- **§14a** — The fleet bulk run (Phase 15 — `--auto-from`, 947 REAL → 74,527; 3.82% → 22.14% in one pass) <sub>L1188</sub>
- **§14d** — Deterministic recovery beats agent waves on the hard tail (Phase 15, the final-session finding) <sub>L1288</sub>
- **§14e** — Two hard-tail dead-ends (Phase 15 — documented so they aren't re-attempted) <sub>L1317</sub>
- **§3-The** — STEERABLE idioms (byte-confirmed this phase) <sub>L1423</sub>
- **Strategic** — conclusion — the match-% lever post-research <sub>L1454</sub>
- **§3-NEW** — / CONFIRMED residual classes (this session) <sub>L1679</sub>
- **Operational** — gotchas (cost real time) <sub>L1700</sub>
- **What** — WORKED — the Phase-20 reusable wins <sub>L1708</sub>
- **§21** — wave-distilled idioms (Phase 21) <sub>L1771</sub>
- **§26** — The cheap close=0 recovery lever is EXHAUSTED; `idiom_loop --assess` was DOUBLY inflated (Phase 21, cont.7) <sub>L2218</sub>
- **§3-The** — `_a` close=0 recovery banks 0/20 — same def-side wall as MAIN (0/40) <sub>L2224</sub>
- **§27** — Giant matching recipe (Phase 21 cont.7b — validated on func_80176D94, 152 ins) <sub>L2278</sub>
- **§28a** — decomp.wiki GCC patterns worth trying on BFM giants (decomp.wiki/compilers/GCC, raw at decompals/decompedia; PS1-applicable subset) <sub>L2364</sub>
- **§31** — THE gcc-2.7.2 CODEGEN MAP: pass → residual → C-lever catalog (Phase 23; 4 Fable5 agents read the compiler source) <sub>L2421</sub>
- **§36** — Fable5 giant-crack levers (Phase 24 T7 Fable5 batch; accumulates as each lands — full RTL dumps in `.run/t7/fable/`) <sub>L2506</sub>
- **§42d** — addendum — wave 4 (rtu_match fan-out over the mapped frontier, 2026-07-10c): 24/26 MATCH, +5 durable levers <sub>L3116</sub>
- **§3-B.** — THE EBB RULE — the general form of §46-L2 <sub>L3502</sub>
- **§3-E.** — Meta <sub>L3552</sub>
- **§50** — Refinements that BOUND §47/§48 (from the `func_80135EB0` wall, 21→6; Phase 26 session 8) <sub>L3610</sub>
- **§51a** — The bug class <sub>L3670</sub>
- **§51c** — THE METHOD (do not audit by reading the regex) <sub>L3696</sub>
- **§51d** — THE LAWS <sub>L3711</sub>
- **§51e** — The false-wall pipeline (why this is not just hygiene) <sub>L3773</sub>
- **§3-Why** — the wall is (probably) intrinsic <sub>L3979</sub>
- **§3-The** — case <sub>L4067</sub>
- **§3-The** — rule <sub>L4096</sub>
- **§55a** — New byte-proven levers (each from a banked or near draft) <sub>L4132</sub>
- **§60a** — What the first DIRECTED grinder run exposed (Phase 29 Task-13B, 2026-07-21) <sub>L4506</sub>
- **§60b** — The plateau autopsy's verdict: a `partial` drift is a WRONG DRAFT, not a missing transform (Phase 29 Task-13B close, 2026-07-21) <sub>L4544</sub>
- **§66** — Exercise a banking driver's SUCCESS path before pointing it at a wave: the free re-bank test (Phase 29 SESSION-17, 2026-07-24) <sub>L5193</sub>
- **§66d-2** — Two operational sharp edges <sub>L5323</sub>
- **§66d-3** — Read the ILS per-cycle SERIES, not its final best: a repeated score and a still-falling one look identical in a summary line and mean opposite things <sub>L5334</sub>
- **§67** — The arg-copy PLACEMENT lever: launder a parameter into a fresh pseudo AT the statement where the target's copy lands (Phase 29 SESSION-18, `func_8014D820` 25 → 16) <sub>L5349</sub>
- **§66d-4** — "ILS converged" means converged FOR THAT WEIGHT PROFILE, not a floor (amends §66d-3; Phase 29 SESSION-18) <sub>L5472</sub>
- **§69** — How to attack a behemoth: map it, don't draft it (Phase 29 SESSION-18, `func_80183814`, 5,122 ins) <sub>L5603</sub>
- **What** — is left, and what is byte-recorded as SPENT <sub>L5800</sub>
- **§3-The** — mechanism, with citations <sub>L6071</sub>
- **§3-Two** — diagnosis traps this function proved <sub>L6098</sub>
- **Practice** — Practice <sub>L6108</sub>
- **§3-The** — drift was an allocation decision, not missing code <sub>L6214</sub>
- **§3-The** — economics <sub>L6245</sub>
- **§71** — has a blind spot, and this is it <sub>L6260</sub>
- **§3-The** — flagged "#1 move" LOST — and why the failure is informative <sub>L6336</sub>
- **§78** — 's attribution primitive, run and reproduced <sub>L6346</sub>
- **Cold-start** — economics, now complete <sub>L6352</sub>
- **Also** — reproduced on this function <sub>L6435</sub>
- **§3-And** — the banking footnote (§75a class A, one line) <sub>L6439</sub>
- **§83a** — READ THE HEADLINE NUMBER CORRECTLY: a LENGTH drift makes `match_one`'s count meaningless <sub>L6453</sub>
- **§83b** — THE LEVER: find the parameterised REPEAT before decoding case-by-case <sub>L6461</sub>
- **§83e** — §80 vindicated again, on the same day it was written <sub>L6500</sub>
- **§3-The** — conflict <sub>L6578</sub>
- **§3-THE** — FAILURE MODE — widening only `engine_core.h` is worse than not starting <sub>L6586</sub>
- **§3-The** — precondition, and how to check it in one grep <sub>L6593</sub>
- **Reading** — , for the next person <sub>L6610</sub>
- **§3-The** — guard refuses a class that largely works <sub>L6625</sub>
- **§3-The** — blindness ladder, now complete — FOUR classes `match_one` cannot see <sub>L6683</sub>
- **Consequence** — for the backlog ledger <sub>L6693</sub>
- **§88** — `cross_jump` will not merge a common suffix containing a CALL; and §78 is scoped to ORDERED comparisons only (Phase 29 SESSION-20, the behemoth close-out) <sub>L6708</sub>
- **§88a** — repeated CALL-shaped blocks are left UNMERGED; call-free tails are merged for you <sub>L6713</sub>
- **§89** — Two throughput rules the project already had written down and was not following (Phase 29 SESSION-20) <sub>L6760</sub>
- **§3-The** — standing sequence <sub>L6792</sub>
- **§90b** — "Byte-neutral" is not "wanted": undo on the SUCCESS path too <sub>L6823</sub>
- **§90c** — A library-callable function must FAIL CLOSED on an unconfigured module <sub>L6833</sub>
- **§90e** — An agent's CONCLUSION and its EVIDENCE fail independently — re-derive the premise, not the fix <sub>L6852</sub>
- **§93** — `set -o pipefail` attributes a pipeline failure to the LAST stage, not the failing one (Phase 29 SESSION-21, `func_8014D820`) <sub>L6956</sub>
- **§101** — The STALE DEFAULT class: a guard whose cause was removed is a silent skip wearing a safety label (Phase 29 SESSION-22, three instances in one session) <sub>L7279</sub>
- **§110** — A unit must define exactly ONE function, and "ends in `;`" does not tell you which line defines it (Phase 29 T65) <sub>L7674</sub>
- **§115** — A `func_XXXXXXXX` predicate rots by design: the same name-form assumption in THREE places (Phase 29 T78) <sub>L7884</sub>
- **§3-The** — fix moves the DEFINITION, not the stub — and here is why the obvious shortcut fails <sub>L7929</sub>
- **§117** — Spell the sibling's symbol from the SIBLING's address, not the exemplar's kind (Phase 29 T82) <sub>L7960</sub>
- **§118** — Ordinal (positional) immediate resolution: compare C tokens to the DIFFERING asm uses (Phase 29 T87) <sub>L7997</sub>
- **§119** — Two levers on the SAME axis, opposite directions: test the off-diagonal (Phase 29 T89) <sub>L8031</sub>
- **§3-The** — wiring trap that cost two attempts <sub>L8077</sub>
- **§3-The** — method (keep this) <sub>L8247</sub>
- **§3-The** — instrument rules that make its answer trustworthy (this is where I failed) <sub>L8257</sub>
- **§3-The** — corrected results (each SHA-verified, from a clean tree, restore re-verified) <sub>L8272</sub>
- **§3-The** — instrument trap that hid it (and it is §124's shape again) <sub>L8324</sub>
- **§3-The** — mechanics <sub>L8333</sub>
- **§3-The** — idiom they kept re-deriving: the constant-offset fold <sub>L8390</sub>
- **§127b** — the knowledge was in a SOURCE COMMENT, not the cookbook <sub>L8420</sub>
- **§128** — A raw NUL in C source makes grep SILENTLY SKIP the file (P30 S28, 137 files) <sub>L8427</sub>
- **§128a** — a negative control must corrupt a SCRATCH COPY, never the tracked file <sub>L8459</sub>
- **§3-The** — real blocker underneath, for the record <sub>L8511</sub>
- **§3-The** — diagnostic ladder that finally located it (reusable) <sub>L8557</sub>
- **Defect** — 1 — a pre-§8e MERGED DOUBLE is not a single-table predecessor <sub>L8613</sub>
- **Defect** — 2 — `as` writes a corpse and nothing deletes it <sub>L8631</sub>
- **§3-The** — fingerprint, and the 30-second ladder that found it <sub>L8641</sub>
- **§3-The** — transferable rule <sub>L8662</sub>
- **§132a** — `--like` is for a sibling with NO record; against one that HAS a record it over-derives (P30 S29, `ov_SC07_010`) <sub>L8669</sub>
- **§135** — Six byte-verified gcc-2.7.2 idioms from the P30 S6f-h waves (and the two-lane wave shape that found them) <sub>L8799</sub>
- **§3-The** — codegen idioms <sub>L8804</sub>
- **§3-The** — wave shape that produced these <sub>L8853</sub>
- **§136** — The LOCAL-VARIABLE lever: how many C locals, at what scope (P30 wave 4a, 25 byte-verified banks) <sub>L8871</sub>
- **§136a** — Blocker capture: classify on the OUTPUT, never on the exit status <sub>L9010</sub>
- **§136d** — Four gcc-2.7.2 levers the redraft lane found (each closed a residual no other lever moved) <sub>L9128</sub>
- **§136e** — §136c's PRECONDITION, and two more symptom keys (wave 4b batch 3) <sub>L9172</sub>
- **§136i** — The drafter model LADDER: Haiku → **Sonnet** → Opus → Fable5 (Drew, 2026-08-03) <sub>L9304</sub>
- **§3-The** — triage, cheapest first <sub>L9455</sub>
- **THREE** — carry variants hide in one "CARRY-FIXABLE" bucket — and they need different fixes <sub>L9524</sub>
- **STEP** — 0 of sibling-first: grep `src/` for a distinctive LITERAL from the `.s` <sub>L9580</sub>
- **§3-The** — generalisation — three corollaries worth more than the bug <sub>L9660</sub>
- **§3-And** — the inverse-lookup trap, same session <sub>L9677</sub>
- **§3-The** — three-line proof (do this before diagnosing any metric movement) <sub>L9714</sub>
- **§3-The** — two instrument defects it exposed <sub>L9723</sub>
- **§3-Two** — wrong mechanisms I chased first, and why they were wrong <sub>L9754</sub>
- **§3-The** — trap that hid it — SAME FUNCTION, TWO ROUTES, ONLY ONE IS FREE <sub>L9839</sub>
- **Route** — selection (why `--addr` sometimes says "nothing changed") <sub>L9848</sub>
- **§144** — THE LITERAL'S SPELLING PICKS THE IMMEDIATE ENCODING (P30 S40 wave 1, `func_801822E0`) <sub>L9922</sub>
- **§3-Why** — a correct draft can read as an intrinsic wall <sub>L10022</sub>
- **§3-The** — rule <sub>L10057</sub>
- **§3-B.** — `(v < 0x40) ? v : 0x3F` is folded to `MIN_EXPR` and expands to the WRONG SHAPE <sub>L10204</sub>
- **§3-D.** — Reproduce the original's BUGS verbatim <sub>L10228</sub>
- **§149** — Four instrument defects in one session, and the two questions they were hiding (P30 S43) <sub>L10277</sub>
- **§3-A.** — A prep step that returns its input on failure is indistinguishable from a search that found nothing <sub>L10283</sub>
- **§3-B.** — Same address + same name ≠ same body — and the ledger keys on address <sub>L10301</sub>
- **§3-C.** — `make: *** [...] Error N` is a summary, never a diagnosis <sub>L10317</sub>
- **§3-The** — fix <sub>L10353</sub>
- **§3-The** — method that found it (this is the transferable part) <sub>L10363</sub>
- **Diagnostic** — order (adopt this) <sub>L10390</sub>
- **§3-The** — mechanism (read from cc1's own `-dR` trace, not inferred) <sub>L10406</sub>
- **§3-The** — lever — a zero-emission insn that absorbs the blocked tick <sub>L10421</sub>
- **§3-The** — finding <sub>L10457</sub>
- **§3-The** — key <sub>L10466</sub>
- **§3-Two** — cautions that must travel with this technique <sub>L10477</sub>
- **§3-The** — companion defect (open) <sub>L10488</sub>
- **Symptom** — Symptom <sub>L10508</sub>
- **Mechanism** — (gcc source + RTL dumps, not inferred) <sub>L10513</sub>
- **§3-The** — cure — a fresh launder per site, each in its own block <sub>L10526</sub>
- **Companion** — levers from the same function <sub>L10536</sub>
- **§3-B.** — Two static base-derivation methods that must AGREE (use both) <sub>L10570</sub>
- **§155a** — the same failure class, one level up: SHAPE-blind table scanning (S45 p5) <sub>L10601</sub>
- **§155c** — the ZERO-REFERENCE trap: gcc splits a global-array address across the `lui` and the LOAD (S46) <sub>L10644</sub>
- **Symptom** — Symptom <sub>L10755</sub>
- **§3-Why** — the fork is chained (gcc source, validated insn-by-insn against -dS/-dR dumps) <sub>L10761</sub>
- **§3-The** — method (dump-arithmetic first, then place — no probing) <sub>L10774</sub>
- **§162a** — SHARPENS *(sharpens §161a, §131, §8a-pad, §129a)* <sub>L11075</sub>
- **§162b** — SHARPENS *(sharpens §48-A3, §156, §150, §76)* <sub>L11104</sub>
- **§162d** — SHARPENS *(sharpens §31, §21, §30, §55a)* <sub>L11133</sub>
- **§162e** — NEW <sub>L11175</sub>
- **§162f** — SHARPENS *(sharpens §42d, §41d, §73, §10)* <sub>L11243</sub>
- **§162g** — NEW <sub>L11298</sub>
- **§162h** — SHARPENS *(sharpens §88, §88a, §50-B, §8)* <sub>L11334</sub>
- **§162i** — SHARPENS *(sharpens §135, §21, §42, §32)* <sub>L11402</sub>
- **§162j** — SHARPENS *(sharpens §25, §136d-1, §48-B, §46-L2)* <sub>L11427</sub>
- **§162k** — SHARPENS *(sharpens §1-I2, §12, §160d, §21)* <sub>L11456</sub>
- **§162l** — SHARPENS *(sharpens §48-B, §48-C1, §20, §21)* <sub>L11519</sub>
- **§162m** — SHARPENS *(sharpens §36, §158, §148, §153)* <sub>L11574</sub>
- **§158a** — THE FIFTH LEVER IS NOT AN ASM: `do { } while (0)` is a REGION ref-multiplier you MINT (P30 S48, `func_8017CBC8`, ov_MAIN_012 / jr_801789AC, 188 ins → MATCH) <sub>L11576</sub>
- **Size** — it before you write it (§158 step 1-2, applied) <sub>L11594</sub>
- **§3-The** — wrap BOUNDARY is the dial — and it is indiscriminate <sub>L11615</sub>
- **§3-Not** — a pure dial <sub>L11621</sub>
- **§162n** — NEW <sub>L11647</sub>
- **§162o** — SHARPENS *(sharpens §158, §136-1, §136-6, §79)* <sub>L11680</sub>
- **§162p** — SHARPENS *(sharpens §48-B, §46-L2, §156, §136d-1)* <sub>L11739</sub>
- **§162q** — SHARPENS *(sharpens §30, §30a, §135-2, §136-13)* <sub>L11756</sub>
- **§164** — S48 §163z SKEPTIC PASS (P30, 2026-08-12): 190 claims vetted, 82 banked <sub>L11882</sub>
- **§169** — THE MICRO-ADAPT LANE (P30 S49): edit a proven body, don't crack a new one <sub>L16317</sub>
- **§170** — THE A-PROP WORD-DIFF CARD (P30 S49): the lane that had no owner <sub>L16364</sub>
- **§171** — THE STALE SEED SYMBOL (P30 S50, 2026-08-13): why §170's 91%→57% was never codegen <sub>L16408</sub>
- **§172** — THE ORPHAN-SLOT MECHANISM v2 (P30 S50-Max): the complete frame-residue model for gcc-2.7.2 MIPS <sub>L16557</sub>
- **§172a** — TWO DECOMPILATION TELLS FROM THE SAME DIG (P30 S50-Max) <sub>L16611</sub>
- **§172b** — THREE MORE TELLS FROM THE GCC READ (P30 S50-Max, banked on Drew's ask) <sub>L16627</sub>
- **§174** — THE ADAPT-CARD WAVE RECIPE (P31 waves A/B, 2026-08-14): prevention beats recovery <sub>L16706</sub>
- **§176a** — THE VERIFICATION-LAYER LAWS (P31 overnight, 2026-08-15). What each check can and cannot prove. <sub>L16801</sub>
- **§176b** — BATCH-GATING MECHANICS (P31): what changes when N drafts land in ONE .c <sub>L16841</sub>
- **§3-C.** — The limit that remains (recorded, not solved) <sub>L17080</sub>
- **§176k** — TWO SELECTOR BUGS THAT SILENTLY SHRINK A WAVE <sub>L17206</sub>
- **§178** — SIX LEVERS MINED FROM THE WAVE-P JOURNALS (P31 S52), each byte-proven and source-cited <sub>L17280</sub>
- **§3-A.** — THE `$0`-ADD OPAQUE COPY defeats `make_regs_eqv` (func_80033398, 93 ins) <sub>L17292</sub>
- **§3-C.** — SINGLE-SET TEMPS GET THE BIRTHING BOOST (func_8001D3FC, 196 ins) <sub>L17321</sub>
- **§3-E.** — THE ZERO-OFFSET ALIAS HOLE (func_80037028, 71 ins) <sub>L17336</sub>
- **§179-B** — 🔴 THE HAND-WRITTEN-ASM TRANSCRIPTION CHECKLIST (maspsx + masked_diff; 10 byte-proofs) <sub>L17426</sub>
- **§179-C** — 🔴 A FUNCTION WITH NO EPILOGUE (falls into a sibling's shared tail) MUST BE FILE-SCOPE `__asm__` <sub>L17476</sub>
- **§179-D** — `gte_stflg` MUST CLOBBER `"$12"` OR THE WHOLE TEMP FILE ROTATES BY ONE <sub>L17527</sub>
- **§179-H** — A MID-BODY `.global LABEL` PAIR SLICES A BYTE-COMPARABLE FRAGMENT OUT OF A LARGER ROUTINE <sub>L17623</sub>
- **Considered** — and NOT banked <sub>L17646</sub>
- **§176-F** — Misdiagnosis triage: four residual verdicts that were lying <sub>L17824</sub>
- **What** — is NOT banked here <sub>L17841</sub>
- **§180c** — WHEN A BINARY'S MASS BAND IS SPENT, THE FLEET-WIDE DRAW IS STRICTLY BETTER <sub>L17902</sub>
- **Only** — ONE of 27 blocked drafts was wrong. The other 26 were correct and unbankable. <sub>L17921</sub>
- **§180d** — THE `pgrep` BRACKET TRICK PROTECTS THE PATTERN, NOT THE COMMAND LINE <sub>L17990</sub>
- **Three** — defects in one call path; the overlay slates that carry most of the wave work were being waved through <sub>L18402</sub>
- **§194-F** — `if ((*p = v = f()) == 0)` is an expand-time pseudo SPLITTER (store_expr's `want_value && MEM` path), not a fold — it partitions one value between local_alloc and global_alloc. BOUNDS §21's L1872 bullet, whose stated direction is byte-wrong on 3 of 4 instances, and CLOSES the control §167-37 asked for. <sub>L19236</sub>
- **§194-L** — §88b and §189-E are BOTH half-wrong, but not the way the candidate says: the compare-constant shape is a 2-D lookup (cmp_info ROW × constant-in-window), and naming matters on OPPOSITE sides of the window for the GE/LT rows vs the GT/LE rows <sub>L19563</sub>
- **§197-REJECTED** — §197-REJECTED <sub>L20733</sub>
- **§199-REJECTED** — §199-REJECTED <sub>L21129</sub>
- **§201-B** — In a narrowed PLUS/MINUS/AND/IOR/XOR expression the destination pointee is INERT — the sign of the materialized constant is decided by an OR over the UNWIDENED operands (convert.c trunc1), which bounds §1841 to direct constant stores <sub>L21231</sub>
- **§201-REJECTED** — eight, the session's highest <sub>L21465</sub>
- **§204-CONFIRMED** — 30 reports that the index already answered <sub>L21931</sub>
- **§204-REJECTED** — sixteen, twice the previous record <sub>L22025</sub>
- **§209** — THE NARROW LOCAL IS A DIAL IN TWO OPPOSITE DIRECTIONS, AND §194-B's "≥2 `sh` STORES" BOUND IS BYTE-WRONG (P31 S58) <sub>L22292</sub>
- **§212** — THE WALKING CURSOR IS COUNTABLE: `*wp++` emits one `addiu` PER STORE, `wp[0..2]` emits one (P31 S58) <sub>L22474</sub>
- **§213** — INDEPENDENT SAME-BASE STORES: THE EMISSION ORDER IS A PERMUTATION OF SOURCE ORDER, AND THE PERMUTATION IS NOT ALWAYS THE IDENTITY (P31 S58) <sub>L22519</sub>
- **§217** — DECODING A CALL'S STACK ARGUMENT SLOTS: `sw` at `0x10`/`0x14`/`0x18` are params 5/6/7 **(single observation — not yet cross-confirmed)** (P31 S58) <sub>L22697</sub>
- **§226** — FRAME PADS: FOUR WAYS §162i1/§2429's DEAD-LOCAL LEVER MISFIRES (P31 S58) <sub>L23018</sub>
- **§228** — READING THE DIVIDE, PART N: the off-by-one compare is `% K == 1`, and three more discriminators (P31 S58) <sub>L23079</sub>
- **§229** — THE ADDRESS IS A VALUE: NAMING IT MOVES THE `lui`/`addiu` PAIR — AND §L14410 SAYS THE OPPOSITE FOR A REASON (P31 S58) <sub>L23116</sub>
- **§231** — TRANSCRIPTION AND SEMANTIC-READ HYGIENE: six ways the listing misleads (P31 S58) <sub>L23180</sub>
- **§194-B** — addendum (P31 S58) — BOUND 2 is byte-wrong; see §209 Direction A <sub>L23277</sub>
- **§176-B** — addendum (P31 S58) — the misdiagnosis direction <sub>L23283</sub>
- **§164-63** — addendum (P31 S58) — the interposed asm works when the SECOND value is an ordinary assignment <sub>L23298</sub>
- **§193-A** — / §194-E addendum (P31 S58) — where the twin's body actually lives <sub>L23307</sub>
- **§235** — THE PHANTOM SYMBOL: A MASKED `MATCH` CAN CARRY A RELOCATION THAT DOES NOT EXIST (P31 S58b) <sub>L23398</sub>
- **§238** — SAME NAME, DIFFERENT FUNCTION: THE OVERLAY-HOMONYM TRAP (P31 S58b) <sub>L23561</sub>
- **§240** — `A + K + B`: WRITE THE CONSTANT **BETWEEN** THE TWO RUNTIME TERMS (P31 S58b) <sub>L23635</sub>
- **§241** — THE FOLDED SIGN-EXTEND-AND-SCALE: `sll 16 ; sra (16 − log2 scale)` (P31 S58b) <sub>L23664</sub>
- **§252** — THE GUARDED PRE-DECREMENT: `(x != 0) && (--x == 0)` (P31 S58b) <sub>L24032</sub>
- **§255** — THE EMPTY CASE, PART 2: FOUR TREE SHAPES IT BUYS (P31 S58b) <sub>L24079</sub>
- **§258** — ADDENDA TO EXISTING SECTIONS (P31 S58b) <sub>L24194</sub>
- **§202** — addendum (P31 S58b) — THE DEF-SIDE ALIAS ALSO CLEARS A RETURN+PARAM DOUBLE CONFLICT <sub>L24243</sub>
- **§205** — addendum (P31 S58b) — CHAINED ASSIGNMENT: N≥3 IS INNERMOST-FIRST, AND THE TEXT MIRRORS EMISSION <sub>L24254</sub>
- **§208** — addendum (P31 S58b) — IT SCALES TO SIX SITES, AND IT HAS AN EXACT INVERSE <sub>L24271</sub>
- **§210** — addendum (P31 S58b) — THREE CONFIRMED SPELLINGS OF THE BOOLEAN TAIL <sub>L24300</sub>
- **§213** — addendum (P31 S58b) — THREE MORE PERMUTATION LAWS FOR INDEPENDENT SAME-BASE STORES <sub>L24359</sub>
- **§217** — CROSS-CONFIRMED (P31 S58b) — AND THE INCOMING HOME SLOT IS THE MIRROR <sub>L24476</sub>
- **§220** — addendum (P31 S58b) — THE PARAMETER, NOT A COPY (SEVEN CARDS) <sub>L24493</sub>
- **§225** — addendum (P31 S58b) — THE GUARD-CLAUSE FINGERPRINT, AND THREE MORE SHAPES <sub>L24590</sub>
- **§229** — addendum (P31 S58b) — NAME IT **INSIDE** THE ARM <sub>L24662</sub>
- **§230** — CROSS-CONFIRMED (P31 S58b) <sub>L24673</sub>
- **§231** — addendum (P31 S58b) — FOUR MORE WAYS THE LISTING MISLEADS <sub>L24682</sub>
- **§232** — CROSS-CONFIRMED (P31 S58b) <sub>L24713</sub>
- **§260** — THE §154-A LEADING-ISLAND SPLIT: ONE CONFIG LINE, AND THE ISLAND PEELS FROM THE END (P31 S59, byte-proven) <sub>L24763</sub>
- **§262** — A LANE'S YIELD IS ONLY A LANE FACT IF IT IS SIZE-MATCHED (P31 S59) <sub>L24897</sub>
- **§264** — FOUR TELLS-LANE C RECIPES, EACH DRIVEN TO MATCH (P31 S59) <sub>L24968</sub>
- **ADD-1** — → §231 addendum (also cross-ref from §195-D) — THE MASKED-`jal` "MISSING CALL" ILLUSION <sub>L25128</sub>
- **ADD-6** — → §172b-1 / §264 addendum — SHIFT-AS-TEST: `(x << 16) != 0` TESTS THE LOW HALF WITHOUT TRUNCATING THE PSEUDO <sub>L25182</sub>
- **ADD-7** — → §256 addendum — THE SINGLE-GUARD GOTO: THEN-BLOCK OUT OF LINE AT THE TAIL <sub>L25191</sub>
- **ADD-3** — → §238 addendum — TWO BINARIES CAN EACH DEFINE THE SAME `func_` NAME WITH DIFFERENT BYTES, AND NO GENERATED REPORT SHOWS IT <sub>L25381</sub>
- **§270** — The A-prop 0-bank anatomy: a byte-correct body still needs FOUR layers to agree (P31 S59) <sub>L25559</sub>
- **ADDENDUM** — to §1-I5 <sub>L25849</sub>
- **ADDENDUM** — to §164-51 <sub>L25914</sub>
- **ADDENDUM** — to §176-F5 <sub>L25930</sub>
- **ADDENDUM** — to §225 <sub>L25959</sub>
- **ADDENDUM** — to §229 — A POINTER'S NUMBER OF USES DECIDES WHETHER ITS ADDRESS FOLDS OR SURVIVES A CALL <sub>L26147</sub>
- **ADDENDUM** — to §226 — A DEAD LOCAL SCOPED TO A NESTED BLOCK BUYS A MID-FUNCTION `addiu sp` PAIR, NOT A FRAME-SIZE CHANGE <sub>L26265</sub>
- **ADDENDUM** — to §74 (func_800D0E30, resident) <sub>L26633</sub>
- **ADDENDUM** — to §172b-4 (func_80185054, ov_SC03_097) <sub>L26669</sub>
- **ADDENDUM** — to §265 (func_8017DC80, ov_SC07_002) <sub>L26707</sub>
- **ADDENDUM** — to §17 (func_800CB794, md_MAIN_036) <sub>L26746</sub>
- **ADDENDUM** — to §162p (func_8017C120, ov_MAIN_012) <sub>L26794</sub>
- **ADDENDUM** — to §20 (~L1947) (func_80186AD0, ov_SC06_032) <sub>L26828</sub>
- **ADDENDUM** — to §164-56 (func_8017F644, ov_SC04_005) <sub>L26858</sub>
- **ADDENDUM** — to §237 (func_8017F7FC, ov_SC03_092) <sub>L26893</sub>
- **ADDENDUM** — to §195-E — a goto-ladder's STORES must sit AT the labels, after the gotos, not inline before them <sub>L27245</sub>
- **Harness-defect** — flags <sub>L27719</sub>
- **ADDENDUM** — to §167-40 (func_8017E2CC, ov_SC04_015 — wave dg) <sub>L27812</sub>
- **ADDENDUM** — to §87 (func_801815F4 ov_SC06_032; corroborating func_801840DC ov_SC05_017, func_80189C68 ov_SC03_006 — wave dg) <sub>L27846</sub>
- **ADDENDUM** — to §263 (func_801E83AC, md_SC04_029 — wave dj) <sub>L27885</sub>
- **ADDENDUM** — to §265 (func_8017D878, ov_SC03_107 — wave dj; corroborated by a REJECTED, contradicted card in wave dm — see closing) <sub>L27899</sub>
- **ADDENDUM** — to §6 (func_801811F0, ov_SC03_102 — waves dj and dl, corroborated by a self-reported "nothing new" dm-wave card) <sub>L27913</sub>
- **ADDENDUM** — to §195-G (func_80183BB0, ov_SC05_001 — wave dj) <sub>L27927</sub>
- **ADDENDUM** — to §74 (func_8017EB34, ov_SC03_117 — counter/clamp variant; wave dj, corroborated by dk/dl/dm cards on the same function) <sub>L28005</sub>
- **ADDENDUM** — §37 — merged into the §153/§236-5 entry above (func_801A419C, wave dl) <sub>L28025</sub>
- **ADDENDUM** — §6 — merged into the §6 entry above (func_801811F0, wave dl) <sub>L28033</sub>
- **ADDENDUM** — to §238 (func_80182CB4, ov_SC02_000 — wave dl) <sub>L28041</sub>
- **ADDENDUM** — to §137a (func_801684B4, ov_MAIN_012; corroborated independently by func_80189E68, func_8017FF9C, func_801822B4, func_8018DA8C — wave dl) <sub>L28059</sub>
- **ADDENDUM** — to §8c / §88d (func_8016AB6C, ov_MAIN_012 — wave dm) <sub>L28075</sub>
- **ADDENDUM** — to §73 / §30#2 (func_800D1984, resident — wave dm) <sub>L28089</sub>
- **From** — ck + cl + cm <sub>L28217</sub>
- **ADDENDUM** — to §5a (func_80181F74, ov_SC03_112, wave cn) <sub>L28359</sub>
- **ADDENDUM** — to §265 (func_8017E26C, ov_SC04_016, wave cn) <sub>L28409</sub>
- **ADDENDUM** — to §42b (func_8018247C, ov_SC07_002, waves cu + cw) <sub>L28447</sub>
- **ADDENDUM** — to §195-E (func_800CFC1C, md_MAIN_003, wave cv) <sub>L28533</sub>
- **ADDENDUM** — to §215 addendum (func_800CB2C8, md_MAIN_033, waves cv + cw) <sub>L28578</sub>
- **ADDENDUM** — to §236 item 4 (func_8017D268, ov_SC04_006, wave cw) <sub>L28634</sub>
- **Harness-defect** — flags (not idioms — flagged for the operator) <sub>L28695</sub>
- **ADDENDUM** — to §250 (func_8017D7CC, ov_SC03_115 — cx/cy/cz/dr) <sub>L28736</sub>
- **ADDENDUM** — to §225 (func_8017E190, ov_SC03_115 — cx/cy/cz) <sub>L28781</sub>
- **ADDENDUM** — to §45-A (func_8017F6A4, ov_SC02_016 — cy/cz) <sub>L28834</sub>
- **ADDENDUM** — to §249 (func_80182ED4, ov_SC04_004 — dp/dr/dt) <sub>L28878</sub>
- **ADDENDUM** — to §199-A (func_801816FC, ov_SC02_005 — dp/dr/dt) <sub>L28923</sub>
- **Harness-defect** — flags <sub>L29012</sub>
- **§289** — an array local's address-taken base keeps every element's store alive, even though only one pointer escapes (`func_80189EFC`, ov_SC04_011) (P31 S60; waves #, byte-proven) <sub>L29094</sub>
- **ADDENDUM** — to §264-3 — the explicit entry copy's BOUND: required exactly when the RAW value must outlive the call that consumes only the PROMOTED value <sub>L29248</sub>
- **ADDENDUM** — to §276 — the SHARE direction: spell the second adjacent symbol RELATIVE to force ONE anchor <sub>L29280</sub>
- **ADDENDUM** — to §31's density-dummy dial (L2460/L2497) — the dose is TWO refs, and the dummy must sit where the loser is live-through <sub>L29296</sub>
- **§300** — S61 DISTILL BATCH NOTES (waves ab8/ab16/ab24/ab32 · g0a–g0f · m0a · ds1/ds2 · m0b) <sub>L29602</sub>
- **§306a** — T4 DISTILL ADDENDA (P31 S62; four byte-proven refinements to existing laws, verified against the book by an independent verifier; each names its parent §) <sub>L29901</sub>
- **Addendum** — §148-A2 addendum — the empty-asm insn_count dial (N bare `__asm__("")` = exactly +N real i (func_801835B0) <sub>L30453</sub>
- **Addendum** — Chained *2*2 array index folds to one copy;sll, not two (func_80011380) <sub>L30509</sub>
- **Addendum** — Last if-arm's nested if un-fuses the whole preceding chain (func_8017FE88) <sub>L30529</sub>
- **Addendum** — Orphan sh triplet to $sp is a write-only local array (func_8017F274) <sub>L30622</sub>
- **RETRIEVAL** — FAILURES this round (not new knowledge — a RETRIEVAL defect) <sub>L30656</sub>
- **Addendum** — Integer-space address arithmetic is a THIRD no-movable spelling, and a distant `SYM[0]` re (func_8017D89C) <sub>L30704</sub>
- **RETRIEVAL** — FAILURES this round <sub>L30765</sub>
- **§323b** — A SCRIPT THAT PARSES argv AT IMPORT CANNOT BE SHARED; EXTRACT THE PREDICATE, DO NOT COPY IT (P31 S67) <sub>L30935</sub>
- **§330** — THE NEIGHBOUR-SHAPE LEVER IS THE CHEAPEST FIRST MOVE, AND IT IS UNDER-USED (P31 S67; four independent instances in one 20-function wave) <sub>L31042</sub>
- **§347-addendum** — A THIRD INSTANCE, AND THE SHARPEST STATEMENT OF THE RULE (md_MAIN_025/func_800CB300, 243 ins) <sub>L31372</sub>
- **§359** — (§43-adjacent) — SPELL A SIGN-WIDEN AS AN EXPLICIT TWO-STEP, FUNCTION-SCOPED TEMP (P31 S68; byte-proven main/func_80012B58, 69 ins, 58 → 3 → 0) <sub>L31608</sub>
- **§360** — THE "COMPILER FOUND A SHORTER EQUIVALENT THAN THE TARGET" PAIR (P31 S68; main/func_800241C0, 68 ins, 68 → 19) <sub>L31621</sub>
- **§363** — ★★ — THE OVERLAY-LAYOUT ASSUMPTION IS A SYSTEMIC BUG CLASS, AND `main` IS THE EXCEPTION THAT FINDS IT (P31 S68; six instances, four of them in one session) <sub>L31705</sub>
- **§369** — REUSE THE **COMPARE CONSTANT'S OWN VARIABLE** FOR A MASK THAT KEEPS COALESCING (P31 S68; md_SC07_004/func_801AEC38, 365 ins) <sub>L31822</sub>
- **§372** — ★★★ — THE **COPY-CAPTURE PAIR**, AND THE ONE ZERO-BYTE EDIT THAT DEFEATS BOTH (P31 S68; byte-proven main/func_8003491C, 78 ins, fable escalation closed 5 → 0) <sub>L31939</sub>
- **CROSS-REFERENCE** — TO §370 — checked and found INAPPLICABLE here, which is the point <sub>L32018</sub>
- **§377** — THREE HARNESS DEFECTS FOUND IN ONE GATING SESSION, ALL "A CONFIDENT NUMBER ABOUT A SMALLER WORLD" (P31 S69) <sub>L32097</sub>
- **§380** — ★★★ — **A SECOND SET OF A PSEUDO DISQUALIFIES IT FROM `move_movables`** (P31 S69; main/func_800215F4, 465 ins, closeness 106 → 59 → 39) <sub>L32195</sub>
- **§382** — TWO FOLD REASSOCIATIONS THAT NEED THEIR OWN STATEMENT (P31 S69) <sub>L32232</sub>
- **§389** — ★★★ — `h_norm` IS BLIND TO INDEXED-GLOBAL RELOCS, SO FREE WORK BECOMES AN INVISIBLE SINGLETON (P31 S69; 31 stubs / 4,811 ins recovered, 8 banked same day) <sub>L32409</sub>
- **§390** — ★★★ — MINIMUM DISTANCE IS NOT MINIMUM WORK; RANK TWIN CANDIDATES BY EFFORT, AND FILTER LOOKALIKES BY RATIO (P31 S69; byte-proven ov_SC01_077/func_80184D50, banked) <sub>L32450</sub>
- **§394** — ★★ — TWO ALIGN-1 ACCESSES IN ONE FUNCTION RESERVE A PHANTOM STACK SLOT (P31 S69; ov_SC02_005/func_80180610) <sub>L32560</sub>
- **§314b** — ★★ — TWO ABS-RANGE GUARDS IN ONE FUNCTION NEED **DIFFERENT SPELLINGS** (P31 S69; byte-proven ov_SC04_002/func_8018691C, 111 ins) <sub>L32645</sub>
- **§397** — ★★★ — RE-RUN THE TWIN SCAN AFTER EVERY EXEMPLAR BANK; A CLUSTER SIBLING IS FREE THE MOMENT ITS EXEMPLAR LANDS (P31 S69; ~250k tokens spent proving it the expensive way) <sub>L32785</sub>
- **§398b** — ★★ — NAMING A SUB-EXPRESSION IN A LOCAL CHANGES WHICH PSEUDO SURVIVES; INLINE IT AT BOTH USE SITES (P31 S69; byte-proven ov_SC03_028/func_80183264, 93 ins) <sub>L32865</sub>
- **§399** — ★★★ — FOUR LEVERS FROM THE FINAL S69 ROUND (P31 S69; each byte-proven, none previously in the cookbook) <sub>L32892</sub>
- **§400** — ★★ — A BASELINE CHECK THAT CONFLATES "ABSENT EVERYWHERE" WITH "CHANGED UNDER US" SILENTLY DROPS NEW FILES (P31 S69; 8 files, one session) <sub>L32932</sub>
- **§401** — §401 <sub>L32967</sub>
- **§402** — §402 <sub>L33000</sub>
- **§403** — §403 <sub>L33024</sub>
- **§404** — §404 <sub>L33056</sub>
- **§406** — ★★ — THE PROLOGUE-WEAVE CLASS IS MECHANICAL AND LARGE (134 open stubs) <sub>L33158</sub>
- **§407** — ★★ — LATE-WAVE ADDENDA TO §405 (the last agents in) <sub>L33180</sub>
- **§409** — ★★★ — THE S71 JOURNAL-FUELLED WAVE: 100% FIRST-PASS MATCH, AND THE NINE LAWS IT BROUGHT BACK (P31 S71) <sub>L33261</sub>
- **§3-The** — nine laws this wave produced <sub>L33288</sub>
- **§413** — ★★★ — DIFFICULTY IS THE RESIDUAL CLASS, NOT `nins` — ROUTE THE MODEL TIER OFF HISTORY (P31 S71, Drew) <sub>L33473</sub>
- **§416** — ★★ — FOUR LEVERS FROM THE S71 OVERNIGHT LANE, none of which the cookbook held (P31 S71) <sub>L33572</sub>
## All sections, in order
- **§3-How** — to use this <sub>L30</sub>
- **§1** — Idiom catalog (asm pattern → C that produces it) <sub>L39</sub>
- **§3-I1** — Unsigned range check: `(x - lo) < (hi-lo)` → `addiu`+`sltiu` <sub>L41</sub>
- **§3-I2** — Byte mask forces `andi` even after `lbu` <sub>L47</sub>
- **§3-I3** — Division by a constant → magic multiply <sub>L54</sub>
- **§3-I4** — Runtime (variable) division → `divu` + zero-check `break` (NEEDS `--expand-div`) <sub>L60</sub>
- **§2** — Writing matching C (what makes gcc emit X) <sub>L69</sub>
- **§3-T1** — Loop pointer: top-of-body for `addu` induction, not constant-folded `addiu` <sub>L71</sub>
- **§3-T2** — Source statement order drives instruction scheduling <sub>L78</sub>
- **§3-T3** — Types <sub>L85</sub>
- **§3-T4** — Branch polarity: invert the source condition to flip gcc's chosen branch <sub>L90</sub>
- **§3** — When a diff is pure scheduling → decomp-permuter (harness built, Phase 6) <sub>L107</sub>
- **§3a** — Escalation TIER above the permuter — web-research the compiler internals (HIGH VALUE, proven) <sub>L128</sub>
- **§3b** — §31-directed permuter mutation — bias the search over the class's levers (Phase 24 T5) <sub>L147</sub>
- **§4** — Flag/toolchain gotchas <sub>L190</sub>
- **§5** — Known hard-residual classes (instruction-identical, one byte-exact blocker) <sub>L199</sub>
- **§5a** — Cross-jump tail-merge — gcc collapses two byte-identical blocks the original kept separate (FIX FOUND) <sub>L211</sub>
- **§6** — Per-module optimization mixing — the -O0 boot module (Phase 7) <sub>L265</sub>
- **Detecting** — the opt level (do this first) <sub>L273</sub>
- **Build** — mechanism — per-file opt override (splat resegmentation) <sub>L307</sub>
- **§7** — PsyQ SDK types & symbols (the library-call prerequisite) <sub>L322</sub>
- **§8** — rodata island (compiler jump tables) — the `.data→.rodata→.data` sandwich (Phase 7) <sub>L339</sub>
- **§8a** — rodata island in a flat OVERLAY — the tail sandwich, per matched jr-function (Phase 26 — PoC PROVEN) <sub>L361</sub>
- **§8a-pad** — a trailing `.word 0x00000000` under a jtbl dlabel is `.align` PAD, not an entry (Phase 26 session 6, byte-proven) <sub>L399</sub>
- **§8b** — MULTI-jtbl per overlay — the `ld_interleave --order` sandwich + the same-subseg cases (Phase 26 session 4) <sub>L423</sub>
- **§8c** — Splitting a TU means rebuilding its DECLARATION ENVIRONMENT, not moving text (Phase 26 session 6) <sub>L456</sub>
- **§8d** — Templating a body INTO a TU must not CHANGE its declaration environment — demote the carried data externs (Phase 26 session 8, byte-proven on `func_8015AE2C` ×133) <sub>L502</sub>
- **§8e** — The jtbl ALIGNMENT LAW + the pad-spec filter — multi-table .rodata spans (Phase 29, byte-proven; `.run/probe_jtbl/verdict.md`) <sub>L549</sub>
- **§9** — Link real PsyQ library objects byte-exact (Phase 7 — GO proven) <sub>L632</sub>
- **§9.1** — Generalised per-object linker — `tools/psyq_link.py` (+ `psyq_link_lib.py`), 18/18 libcd byte-exact <sub>L661</sub>
- **§9.2** — Wire a library region into the build with NOLOAD — no data carving (`tools/psyq_link_region.py`) <sub>L685</sub>
- **§9.3** — Make it the build: resegment + swap + resolve (`tools/psyq_integrate.py`, libcd DONE) <sub>L704</sub>
- **§9.4** — Integrating a SECOND library (libgs block 6 after libcd) — multi-library gotchas <sub>L731</sub>
- **§9.5** — Integrating a WHOLE multi-block library in one call (full libgs — Phase 7 session G) <sub>L759</sub>
- **§9.6** — Scaling library linking to the whole EXE (Phase 8 — 8 libs linked, 20%→50% byte-identical) <sub>L785</sub>
- **§9.7** — Binary-agnostic toolchain refactor (Phase 9) — the reusable pattern for Gen2 <sub>L821</sub>
- **§10** — Closing the regalloc/scheduling hard tail by hand (LZSS, Phase 7 session F — the full close) <sub>L854</sub>
- **§3-The** — clean object-level metric (use this, not the permuter score, for jtbl/rodata functions) <sub>L863</sub>
- **Residual** — A — commutative `|`/`&`/`+` result lands in the wrong source-operand register <sub>L875</sub>
- **Residual** — B — a `return <const>` materialised late / merged instead of distributed per-site <sub>L886</sub>
- **§11** — Cross-binary dedup & code-sharing (Phase 11 — "one match unlocks many") <sub>L927</sub>
- **§3-The** — mechanism: game-code dedup is SOURCE-LEVEL, not an object swap (R-D1, the key lesson) <sub>L945</sub>
- **Per-binary** — toolchain provenance (R24) <sub>L978</sub>
- **§12** — Ultracode harvest — parallel-draft + byte-gate at scale (Phase 12, resident: 1.4%→71.7% in one session) <sub>L983</sub>
- **§13** — Add a location overlay — the canonical runbook (Phase 13; the Phase-15 fleet recipe) <sub>L1075</sub>
- **One-command** — onboarding — `tools/new_overlay.sh <SCxx> <FILE_nnn>` <sub>L1081</sub>
- **§3-The** — flat-blob overlay config (what the template encodes) <sub>L1090</sub>
- **§3-THE** — NON-4-ALIGNED-OVERLAY GOTCHA (≈75% of the fleet; fixed in the template + Makefile, automatic) <sub>L1098</sub>
- **§3-The** — A→B→C per-overlay workflow <sub>L1110</sub>
- **Dedup-credit** — (§11) for overlays — two shapes <sub>L1127</sub>
- **Fleet** — build — `make build-all` / `make check-all` <sub>L1139</sub>
- **§14** — Propagate a matched function across the fleet — `tools/dedup_propagate.py` (Phase 15) <sub>L1145</sub>
- **§14a** — The fleet bulk run (Phase 15 — `--auto-from`, 947 REAL → 74,527; 3.82% → 22.14% in one pass) <sub>L1188</sub>
- **§14b** — Harvesting the UNMATCHED shared core — the match_one wall (Phase 15) <sub>L1211</sub>
- **§14c** — Callee-signature-aware harvest — breaking the extern-type-conflict wall (Phase 15, T6) <sub>L1232</sub>
- **§14d** — Deterministic recovery beats agent waves on the hard tail (Phase 15, the final-session finding) <sub>L1288</sub>
- **§14e** — Two hard-tail dead-ends (Phase 15 — documented so they aren't re-attempted) <sub>L1317</sub>
- **§15** — Struct-heavy shared-core pipeline (Phase 16) — empirical determinations (S0) <sub>L1332</sub>
- **§16** — Guided hand-matching the struct-heavy core (Phase 17 — beats the §15 brute-force) <sub>L1354</sub>
- **§17** — The compiler-quirk wall — the matching TOOLKIT (Phase 18; gcc-2.7.2 source + byte-gated) <sub>L1395</sub>
- **Register-allocation** — ORDER (call-crossing $s0/$s1 swap) → FORCE it with register pins (byte-proven) <sub>L1403</sub>
- **§3-The** — STEERABLE idioms (byte-confirmed this phase) <sub>L1423</sub>
- **§3-The** — pipeline gotcha — match_one ≠ the gate; `sig_unify` is MANDATORY <sub>L1440</sub>
- **§3-The** — LOOSE-TYPING wall is real for narrow params (Phase 16, reconfirmed) <sub>L1447</sub>
- **Strategic** — conclusion — the match-% lever post-research <sub>L1454</sub>
- **§17a** — The TOOLKIT at WAVE scale (Phase-18 Step-3b/Step-1 — measured) + the pipeline-integration gotchas <sub>L1464</sub>
- **§18** — Per-file `-O0` split inside an overlay/blob (Phase 19 T1) <sub>L1538</sub>
- **§19** — Scaling the toolkit waves — the recovery PIPELINE + the propagation CAP (Phase 19 T3) <sub>L1616</sub>
- **§20** — The wave-at-scale GATE CAP + residual-class verdicts (Phase 20) <sub>L1651</sub>
- **§3-THE** — CAP: at this tail the match_one→gate gap is the LOOSE-TYPING CALL-GRAPH wall (not cheap plumbing) <sub>L1656</sub>
- **Diagnostic** — lesson: a failed in-TU build leaves a STALE `.o` <sub>L1673</sub>
- **§3-NEW** — / CONFIRMED residual classes (this session) <sub>L1679</sub>
- **Operational** — gotchas (cost real time) <sub>L1700</sub>
- **What** — WORKED — the Phase-20 reusable wins <sub>L1708</sub>
- **Phase-20** — RESOLUTION — `tools/cast_call_sites.py` BUILT + the cap re-diagnosed (R14, byte-proven) <sub>L1720</sub>
- **§21** — wave-distilled idioms (Phase 21) <sub>L1771</sub>
- **§22** — DEF-side loose-typing recovery + grinder blacklist (Phase 21) <sub>L2024</sub>
- **§23** — Giant `func_80153E00` cracked (scalar-data CAST); BUT most giant drafts are STALE+INCOMPLETE, and a diag MUST remove artifacts (Phase 21 — byte-proven + a self-correction) <sub>L2051</sub>
- **§24** — The `ov_SC01_077_a.c` split-file vein: split-aware propagation, but loose-typing-gated (Phase 21) <sub>L2104</sub>
- **§25** — The "schedule" class is mostly COALESCING (pin-crackable), not scheduling; + the gate two-stage + h_exact over-counts ×134 (Phase 21, cont.6) <sub>L2151</sub>
- **§3-The** — crack: the residual was gcc-2.7.2 COPY-COALESCING, not the instruction scheduler <sub>L2163</sub>
- **§3-The** — genuine scheduler — `rank_for_schedule` (sched.c), for when it IS scheduling <sub>L2179</sub>
- **§3-The** — genuine schedule WALLS (do NOT re-grind — stub) <sub>L2188</sub>
- **§3-h** — _exact OVER-COUNTS ×134 — verify shareability before crediting a class's "reach-134" (R14) <sub>L2196</sub>
- **§3-The** — gate two-stage — sig_unify is a FALLBACK, not unconditional (`gate_stage.py`, §19 folded in) <sub>L2208</sub>
- **§26** — The cheap close=0 recovery lever is EXHAUSTED; `idiom_loop --assess` was DOUBLY inflated (Phase 21, cont.7) <sub>L2218</sub>
- **§3-The** — `_a` close=0 recovery banks 0/20 — same def-side wall as MAIN (0/40) <sub>L2224</sub>
- **Where** — this leaves the reach-134 tail (cont.6 option-3, now CONFIRMED byte-backed) <sub>L2252</sub>
- **§27** — Giant matching recipe (Phase 21 cont.7b — validated on func_80176D94, 152 ins) <sub>L2278</sub>
- **§28** — Banking a "close=0 gate-rejected" giant: the canonical-extern recovery (Phase 22 T1, byte-proven on func_8015126C ×134) <sub>L2344</sub>
- **§28a** — decomp.wiki GCC patterns worth trying on BFM giants (decomp.wiki/compilers/GCC, raw at decompals/decompedia; PS1-applicable subset) <sub>L2364</sub>
- **§28c** — The close=0 recovery is NOT fully exhausted (§26 corrected, R14); + the dedup_propagate registry-skip recovery (Phase 22 T2) <sub>L2371</sub>
- **§28b** — The struct-walled close=0 giant (§28 case #3) IS bankable: the engine_types.h type-lift (Phase 22 T2, byte-proven on func_80156B74 ×134) <sub>L2376</sub>
- **§28d** — The "macro-extern-injection" lever: freeing reach-134 inline matches dedup_propagate skips as "not self-contained" (Phase 23, `tools/inject_capped_externs.py`) <sub>L2385</sub>
- **§29** — Reasoning-model (GLM5.2) DEF-side reconciliation idioms + the wall's hard limit (Phase 23 T10.7, `tools/glm_reconcile.py`) <sub>L2393</sub>
- **§30** — Fable5Max cracks §20/§10 "unsteerable" from the gcc SOURCE: store-vs-load is a `/s` aliasing flag, the def-side wall has a macro escape, + the birthing-boost (Phase 23, byte-proven on giant `func_8014EE14` 248 ins ×134) <sub>L2401</sub>
- **§30a** — §30 generalizes to the FULL near-miss backlog (via STANDARD Opus agents, not just Fable5) + 2 more steer levers + the mechanical-integration throughput unlock (Phase 23 (a)) <sub>L2413</sub>
- **§31** — THE gcc-2.7.2 CODEGEN MAP: pass → residual → C-lever catalog (Phase 23; 4 Fable5 agents read the compiler source) <sub>L2421</sub>
- **§32** — The region-a CAMERA-GIANT idiom set: struct-base hoisting + 4 sibling levers (Phase 24 T7, Fable5-cracked on `func_80129CF8` 191 ins, match_one MATCH; transferable to the 6 sibling giants) <sub>L2441</sub>
- **§33** — Automating the giant decl-reconcile: `tools/reconcile_decls.py` (the DATA analog of §20's `cast_call_sites`) + a fleet-majority type oracle (Phase 24 T7b, byte-proven on `func_80129CF8`) <sub>L2453</sub>
- **§34** — The `func_80138ED0` giant crack: gcc-2.7.2's **3-qty sort bug** + the **zero-byte asm allocation toolkit** + the **giv-init fence** (Phase 24 T5; Opus→close=21, Fable5→MATCH ×134) <sub>L2473</sub>
- **§35** — The region-a sibling-giant harvest: difficulty ≠ $s-reg count (it's global-array hoisting) + the banking recipe + new loop idioms (Phase 24 T7, 5 parallel Opus-Max agents) <sub>L2490</sub>
- **§36** — Fable5 giant-crack levers (Phase 24 T7 Fable5 batch; accumulates as each lands — full RTL dumps in `.run/t7/fable/`) <sub>L2506</sub>
- **§37** — The T7 §G giant endgame: 6/8 cracked, meta-laws + transferable levers (Phase 24, 2026-07-07; FULL byte-verified detail + gcc-2.7.2 line cites in `docs/gcc-2.7.2-map/t7g-giant-harvest.md`) <sub>L2525</sub>
- **§38** — The WHALE `func_80144B9C` (770 ins): the -O0 struct-assign memcpy idiom + the -O0 reach-134 ×134 rollout (Phase 24 T7 §G, cheap Opus — no Fable5, no calls.c) <sub>L2546</sub>
- **§39** — The ×1→×134 giant-endgame: propagate a matched **-O2** giant via the NATIVE DEFINE-macro path (Phase 24 T7 §G close, 2026-07-08) <sub>L2556</sub>
- **§40** — Structural families: the MECHANICAL symbol-remap (crack one exemplar → remap the rest, ~0 tokens) (Phase 25 T3/T7, 2026-07-08) <sub>L2572</sub>
- **§40a** — The DECL-RECONCILE pass (type-lift so remapped drafts compile in the sibling TU) (Phase 25 T7.2, 2026-07-08) <sub>L2620</sub>
- **§40b** — The reloc-tracker blind spot: the indexed-global idiom that hid the "reach-1 tail" (Phase 26 Task 1, 2026-07-11, byte-verified V0/V1) <sub>L2653</sub>
- **§40c** — The h_seq per-sibling reconcile: templating a reconcile-class crack ×134 (Phase 26 Task 8, 2026-07-12, byte-proven) <sub>L2695</sub>
- **§31-triage** — R17 applies to CODEGEN residuals, never to a compile ERROR (Phase 26 session 7, Drew asked) <sub>L2712</sub>
- **§41** — The DEF-SIDE canonical-sig wall: mechanically banking a drafted giant past `conflicting types` (Phase 25 T5b batch-2, 2026-07-09; `tools/canon_sig_reconcile.py`, byte-proven on `func_8013B274`) <sub>L2729</sub>
- **§41a** — v3.1: the def-side wall was ~71% TOOL-shaped — the five measured defects + the laws that dissolve them (Phase 25 T6, Fable5, 2026-07-09) <sub>L2788</sub>
- **§41b** — T7 execution: the object-only probe OVER-counts BANKABLE by two link/rodata classes (Phase 25 T7-M1, 2026-07-10) <sub>L2843</sub>
- **§41c** — T7-M2: the ×134 def-side-wall sweep via per-sibling RE-reconcile (Phase 25, 2026-07-10; 4,389 banks, ~0 agent tokens) <sub>L2873</sub>
- **§41b** — addendum — M4 "reconcile_decls" tier is ALSO a probe over-count: 0/8 mechanical (Phase 25 T7-M4, 2026-07-10) <sub>L2892</sub>
- **§41d** — `void`→`s32` is NOT always byte-neutral: gate the RAW draft FIRST (Phase 26 session 6, byte-proven) <sub>L2912</sub>
- **§42** — The F-band ≤28 regalloc crack wave: register-pin/DENSITY levers beat the permuter (Phase 25 T7 F-band, 2026-07-10; Ultracode 9-worker wave, 4/9 banked byte-identical, 266 swept ×134) <sub>L2934</sub>
- **§42a** — addendum — wave 2 (residuals + 29-100 band): iso-MATCH ≠ real-TU bank, the memcpy→struct-assign fix, +5 levers (2026-07-10b) <sub>L2987</sub>
- **§42b** — addendum — wave 3 (Max, 2026-07-10c): THE STALE-OBJECT GATE TRAP + the read-global `&`-cast drift + fix <sub>L3028</sub>
- **§42c** — addendum — wave 3 (Max orchestrator + CORRECTED Ultracode fan-out, 2026-07-10c): the real-TU-faithful parallel harness (rtu_match) + 7/9 crack, ZERO iso-drift <sub>L3067</sub>
- **§42d** — addendum — wave 4 (rtu_match fan-out over the mapped frontier, 2026-07-10c): 24/26 MATCH, +5 durable levers <sub>L3116</sub>
- **§42e** — propagating a CRACK ×134: the def-finder bug + the byte-drift residual (the "remap-fail" misdiagnosis) <sub>L3155</sub>
- **§43** — The K&R s16-param definition DISSOLVES the "narrow-param wall" for by-value register args (Phase 25 task A, Fable5 crack of the 369-ins giant `func_80166994` ×134, 2026-07-11) <sub>L3229</sub>
- **§44** — The Phase-25 cheap-Opus giant batch: 5 structural levers + the §43 extension (2026-07-11, 6 crackers over the frontier giants) <sub>L3276</sub>
- **§45** — The flagship `func_80133CD4` crack (399 ins ×134): the merged-variable permutation-breaker + the 1-death local-alloc gate (Phase 25 task A giant escalation, Fable5 gdb-on-cc1, 2026-07-11) <sub>L3332</sub>
- **§46** — The `func_80178D40` crack (890 ins ×134, the heaviest core in the game): four LOOP-STRUCTURE levers cheap-Opus found by reading loop.c/jump.c/cse.c (Phase 26 session 8, 2026-07-13) <sub>L3347</sub>
- **§47** — The live-length SLIDER: splitting a global.c allocno-priority TIE with one zero-byte asm (Phase 26 session 8, Fable5 Max, byte-proven on `func_8017BEBC` 952 ins ×113) <sub>L3399</sub>
- **§48** — The 12-core jr crack wave: the ALLOCNO-PRICING dials and the EBB rule (Phase 26 session 8, Ultracode, 9/12 MATCH first pass) <sub>L3439</sub>
- **§3-A.** — ALLOCNO-PRICING DIALS — move a value into the register you want, byte-neutrally <sub>L3447</sub>
- **§3-A4** — SINK THE CONSUMER CALL INTO THE ARMS (the inverse of A1; `func_8016AB6C`, byte-proven) <sub>L3478</sub>
- **§3-B.** — THE EBB RULE — the general form of §46-L2 <sub>L3502</sub>
- **§3-C.** — TYPE- AND SHAPE-DRIVEN CODEGEN (the C type literally selects the addressing mode) <sub>L3518</sub>
- **§3-D.** — THE CROSS-JUMP RATCHET (the sharpest new trap — `func_80131340` L-C) <sub>L3542</sub>
- **§3-E.** — Meta <sub>L3552</sub>
- **§49** — The LUID DIAL: a zero-byte SCHEDULING dial (the sched.c analogue of §47) — `func_8017A4AC` (536 ins ×134), Phase 26 session 8 <sub>L3561</sub>
- **§50** — Refinements that BOUND §47/§48 (from the `func_80135EB0` wall, 21→6; Phase 26 session 8) <sub>L3610</sub>
- **§51** — TOOLING INTEGRITY: the silent skip, and how to hunt it <sub>L3664</sub>
- **§51a** — The bug class <sub>L3670</sub>
- **§51b** — Why the byte-gate cannot save you <sub>L3686</sub>
- **§51c** — THE METHOD (do not audit by reading the regex) <sub>L3696</sub>
- **§51d** — THE LAWS <sub>L3711</sub>
- **§51e** — The false-wall pipeline (why this is not just hygiene) <sub>L3773</sub>
- **§51f** — Checklist for any new corpus-scanning tool <sub>L3789</sub>
- **§51g** — When the thing you are scanning has a GRAMMAR, parse the grammar (`tools/cdecl.py`) <sub>L3803</sub>
- **§52** — The WALKER-FAMILY skeleton: 6 regalloc-order levers + a deeply-characterized intrinsic wall (`func_80178004`, 165 ins ×134; Phase 26, Fable5, 2026-07-15) <sub>L3947</sub>
- **§3-The** — 6 levers (the "walker-family skeleton" — apply to the 12 siblings; levers 1-5 retire ~half the residual) <sub>L3958</sub>
- **§3-Why** — the wall is (probably) intrinsic <sub>L3979</sub>
- **§52a** — The regalloc sibling wave: new levers + two new wall classes (cheap-Opus applying §52, 2026-07-15) <sub>L3993</sub>
- **§52b** — Sibling wave 2: more de-pin levers, a third wall class, and the match_one→whole-binary gap at scale (2026-07-15) <sub>L4031</sub>
- **§53** — SWEEP A FAMILY WITH THE TOOL ITS EXEMPLAR NEEDED: the jr/switch carve, and how omitting it manufactured the "families don't template" doctrine (Phase 28 T1, 2026-07-15) <sub>L4062</sub>
- **§3-The** — case <sub>L4067</sub>
- **§3-Why** — 0/8 was structural, and predictable from two words <sub>L4079</sub>
- **§3-The** — rule <sub>L4096</sub>
- **§3-The** — meta-lesson (R35, and why this one is expensive) <sub>L4112</sub>
- **§55** — Core-crack wave levers + the GATE-ORCHESTRATION law (Phase 29 T3, 13-agent ultracode wave, 2026-07-17) <sub>L4127</sub>
- **§55a** — New byte-proven levers (each from a banked or near draft) <sub>L4132</sub>
- **§55b** — THE GATE-ORCHESTRATION LAW (3 traps, ~3.5h lost; all recovered, 0 data lost) <sub>L4156</sub>
- **§55c** — Sizing the propagate: a TARGETED propagate is ~4 min/core, and "it's slow" was a BROKEN-TREE ARTIFACT <sub>L4175</sub>
- **§54** — `--fix-def-sig`: the member's CANONICAL DECLARATION is a build step too (tiny-IMM mega-pools, +4,801, Phase 29 T6, 2026-07-16) <sub>L4197</sub>
- **§56** — Banking a hand-drafted GIANT into its exemplar TU: self-contained draft vs live-TU decls, 4 reconciliation tactics (`func_8013FAF8`, 312 ins ×138, Phase 29 T4, 2026-07-17) <sub>L4221</sub>
- **§56b** — PROPAGATING an h_seq giant: the exemplar's externs MUST be fleet-canonical, not the draft's types <sub>L4266</sub>
- **§57** — The SELF-decl normalize: the sibling's OWN caller declares the templated fn divergently (the third §17a-1 direction; `tools/normalize_self_decls.py`, func_801670E4 ×137, Phase 29, 2026-07-18) <sub>L4290</sub>
- **§57a** — Two NSD corrections + the SURGICAL-ONLY law + the honest broad-sweep yield (Phase 29, 2026-07-18) <sub>L4337</sub>
- **§58** — match_one MATCH ≠ BANK: the four blind spots + the crack-wave reconcile-before-bank law (Phase 29 crack-wave, 2026-07-18) <sub>L4377</sub>
- **§59** — Three h_seq sweep-residual classes match_one/the-exemplar-bank don't reveal (Phase 29 crack-wave close, 2026-07-18) <sub>L4411</sub>
- **§60** — Classify the residual, don't rank it: the deterministic residual→class classifier and what it measured about the backlog (Phase 29 Task-13A, 2026-07-21) <sub>L4441</sub>
- **What** — it measured — the whole open backlog, byte-grounded <sub>L4465</sub>
- **§3-Two** — corollaries worth remembering <sub>L4484</sub>
- **§3-The** — parallel-probe race this surfaced <sub>L4497</sub>
- **§60a** — What the first DIRECTED grinder run exposed (Phase 29 Task-13B, 2026-07-21) <sub>L4506</sub>
- **§60b** — The plateau autopsy's verdict: a `partial` drift is a WRONG DRAFT, not a missing transform (Phase 29 Task-13B close, 2026-07-21) <sub>L4544</sub>
- **§61** — Task 14: the gate ladder's missing stage is the ARITY pre-pass, and it is TU-side not draft-side (Phase 29, 2026-07-21) <sub>L4579</sub>
- **§61a** — The Task-5 wave: 11/12 MATCH, 0 banked — three DISTINCT integration walls, each now named (Phase 29, 2026-07-21) <sub>L4640</sub>
- **§61b** — The jtbl gate stage: built, and the ORDERING law it exposed (Phase 29 Task-14 stage 4, 2026-07-21) <sub>L4692</sub>
- **§61c** — The jtbl bank is INCREMENTALLY valid and CLEAN-INVALID (Phase 29, 2026-07-21) — the blocking finding <sub>L4747</sub>
- **§61d** — The undo was eating the tree: two tools, one defect, invisible to the byte-gate (Phase 29, 2026-07-22) <sub>L4813</sub>
- **§62** — The jtbl RECONCILE must also follow the carve: the post-carve draft reconcile (`harvest_verify._jtbl_reconcile`, Phase 29 SESSION-11, 2026-07-22) <sub>L4867</sub>
- **§63** — The fresh-138 DEF-SIDE blocker: fix the HEADER decl, not the draft (`fix_header_decl.py`, Phase 29 SESSION-13, 2026-07-23) <sub>L4911</sub>
- **§64** — The §20 type-lift's three laws: fold the tagged typedef, check VISIBILITY, and strip only what is TEXTUALLY IDENTICAL (`lift_types.py`, Phase 29 SESSION-14, 2026-07-23) <sub>L4942</sub>
- **§64a** — VARIANT types: UNIQUIFY the camps, do not reconcile them (`uniquify_type.py`, Phase 29 SESSION-14) <sub>L4991</sub>
- **§63** — UPDATE (Phase 29 SESSION-14) — `fix_header_decl`'s "SAFE" verdict is FLEET-BLIND; it MUST be R22-validated <sub>L5034</sub>
- **§65** — The stranded-draft recovery: BLAST-RADIUS TIERS, and the per-overlay de-macroize that refutes §20's DEF-conflict wall (`tools/demacroize.py` + `tools/blocker_probe.py`, Phase 29 SESSION-16, 2026-07-24) <sub>L5049</sub>
- **§65a** — The blast-radius taxonomy (makes §61's law structural instead of remembered) <sub>L5064</sub>
- **§65b** — The escape: de-macroize the instantiation, don't touch the shared header <sub>L5079</sub>
- **§65c** — `rtu_match` MATCH → bank held 13/13 on self-decl, but broke on the FIRST callee-decl case <sub>L5115</sub>
- **§65d** — Existing-ladder baseline, measured (do this before building a recovery stage) <sub>L5125</sub>
- **§65e** — Two oracles, and the disagreement is the finding (R34 in practice) <sub>L5135</sub>
- **§65f** — The de-macroize lever's BOUNDARY, measured: byte-neutral 14 times of 15, and the 15th is why the gate exists <sub>L5152</sub>
- **§65g** — Where the cheap levers STOP: the local-type and in-TU-self-decl classes did not yield <sub>L5173</sub>
- **§66** — Exercise a banking driver's SUCCESS path before pointing it at a wave: the free re-bank test (Phase 29 SESSION-17, 2026-07-24) <sub>L5193</sub>
- **§66a** — The widest write in a pipeline is the one most likely to be UNDECLARED <sub>L5215</sub>
- **§66b** — A metric parsed out of another tool's prose goes NULL silently when the label changes <sub>L5234</sub>
- **§66c** — Before a wave, verify the FUEL exists; an "already attempted" set built from the wrong directory lies in BOTH directions <sub>L5251</sub>
- **§66d** — The permuter⇄reader loop: alternate a random search with a byte-verified idiom, and let `residual_class` decide whose turn it is (Phase 29 SESSION-17) <sub>L5279</sub>
- **§66d-1** — What transfers between giants is the LOOP, not the PIN <sub>L5314</sub>
- **§66d-2** — Two operational sharp edges <sub>L5323</sub>
- **§66d-3** — Read the ILS per-cycle SERIES, not its final best: a repeated score and a still-falling one look identical in a summary line and mean opposite things <sub>L5334</sub>
- **§67** — The arg-copy PLACEMENT lever: launder a parameter into a fresh pseudo AT the statement where the target's copy lands (Phase 29 SESSION-18, `func_8014D820` 25 → 16) <sub>L5349</sub>
- **§67a** — Run the symbol-set guard BEFORE you pay for a gate (`tools/symcheck.py`, Phase 29 SESSION-18) <sub>L5439</sub>
- **§66d-4** — "ILS converged" means converged FOR THAT WEIGHT PROFILE, not a floor (amends §66d-3; Phase 29 SESSION-18) <sub>L5472</sub>
- **§66d-5** — `residual_class`'s "structural ⇒ permuter CPU is waste" is WRONG for schedule permutations (measured, Phase 29 SESSION-18) <sub>L5525</sub>
- **§68** — A comment-only line halted the extern scan, and the skip label blamed the type cap (Phase 29 SESSION-18) <sub>L5558</sub>
- **§69** — How to attack a behemoth: map it, don't draft it (Phase 29 SESSION-18, `func_80183814`, 5,122 ins) <sub>L5603</sub>
- **§70** — The giv-init base register: walk the PARAMETER, not a copy of it (Phase 29 SESSION-18, `func_801777BC`) <sub>L5653</sub>
- **§71** — Before mapping a giant, look for an already-matched SIBLING beside it (Phase 29 SESSION-18, `func_8017D960`, 3,338 ins) <sub>L5694</sub>
- **§72** — A `register __asm__` pin is a PREFERENCE, not a reservation (Phase 29 SESSION-18, `func_8017F510`) <sub>L5760</sub>
- **§3-The** — honest fix was source-level and cheap <sub>L5784</sub>
- **§3-Giv** — record order (the §70 family) <sub>L5794</sub>
- **What** — is left, and what is byte-recorded as SPENT <sub>L5800</sub>
- **§73** — A def-side self-decl conflict has TWO axes: RETURN (fleet widen, T2) and PARAMS (casts at each use, T0). Diagnose which before paying for the expensive one (Phase 29 SESSION-19, `func_8014F3E8` + `func_8014D4C0`) <sub>L5817</sub>
- **§74** — Auditing a pinned draft: the §72 hazard is CALLER-SAVED pins spanning a call, and only the disassembly can tell you (Phase 29 SESSION-19, `func_8017D960` b2, 5 pins) <sub>L5856</sub>
- **§75** — A propagation cap is usually a MINORITY-SPELLING SOURCE OVERLAY, not a wall: census the carried extern before believing the exclusion message (Phase 29 SESSION-19, `func_8014F3E8` ×4 → ×138) <sub>L5900</sub>
- **§75a** — The exclusion classes, enumerated with named causes (Phase 29 SESSION-19, the 134-binary `dedup_extend` sweep) <sub>L5959</sub>
- **§75b** — A body's preamble can carry `#define`s, not just `extern`s; extraction lifts only the externs (Phase 29 SESSION-19, `func_80165CA0` ×3 → fleet) <sub>L5982</sub>
- **§75c** — Class-B's remedy is the FULL §17a-1 PAIR (decl **and** call-site cast); a decl-only fix moves the error and looks like a new wall (Phase 29 SESSION-19, `func_8012F14C`) <sub>L6031</sub>
- **§76** — The allocno CLASS (local vs global) is the dominant regalloc lever, and C reaches it ONLY through declaration scope and variable reuse (Phase 29 SESSION-19, behemoth #3 `func_8017F510` 1,511 ins, 97 → MATCH, pin-free) <sub>L6062</sub>
- **§3-The** — mechanism, with citations <sub>L6071</sub>
- **§3-The** — attribution primitive (use this before calling anything a scheduling residual) <sub>L6091</sub>
- **§3-Two** — diagnosis traps this function proved <sub>L6098</sub>
- **Practice** — Practice <sub>L6108</sub>
- **§77** — Every extraction tool carries a NARROW hard-coded preamble set; anything outside it silently caps the body's reach. Diff the preamble before you gate. (Phase 29 SESSION-19 — three variants in one session, two different tools) <sub>L6118</sub>
- **§3-The** — CANDIDATE gate and the REAL gate need DIFFERENT preambles — keep the difference out of the bank <sub>L6158</sub>
- **§78** — A LENGTH drift can be a register grant in disguise; and `fold` never leaves a literal first in an `|` chain (Phase 29 SESSION-19, behemoth #2 `func_8017D960` 3,338 ins, 1806 → 0, pin-free) <sub>L6208</sub>
- **§3-The** — drift was an allocation decision, not missing code <sub>L6214</sub>
- **§3-The** — economics <sub>L6245</sub>
- **§79** — For a 0-callee giant, fingerprint by DATA symbols (§71 cannot fire); and the STACK-SLOT ORDER is a declaration-order oracle (Phase 29 SESSION-19, `func_8017BF14` 4,763 ins, cold start → 45/4763) <sub>L6254</sub>
- **§71** — has a blind spot, and this is it <sub>L6260</sub>
- **§3-NEW** — LEVER — the frame layout reads back the original declaration order <sub>L6274</sub>
- **§76** — confirmed at scale, and a pin nuance <sub>L6285</sub>
- **§3-The** — residual, and the honest read <sub>L6294</sub>
- **§80** — A do-not-re-buy entry is scoped to its BASE, not to the function; and the pin's hidden cost is an unconditional `qty_phys_sugg` (Phase 29 SESSION-19, `func_8017BF14` 45 → 0) <sub>L6304</sub>
- **§3-The** — pin's hidden cost, with the citation <sub>L6325</sub>
- **§3-The** — flagged "#1 move" LOST — and why the failure is informative <sub>L6336</sub>
- **§78** — 's attribution primitive, run and reproduced <sub>L6346</sub>
- **Cold-start** — economics, now complete <sub>L6352</sub>
- **§81** — Banking a jr (jump-table) function: the 3-step carve chain, and why `match_one` cannot see the problem (Phase 29 SESSION-19, `func_8017C954`) <sub>L6357</sub>
- **§3-The** — defect this exposed: a shared type that is present but invisible <sub>L6388</sub>
- **§82** — Two source-shape oracles from behemoth #6: a duplicated `addiu $aN,$sp,K` across a `jal` means the block was INLINED, and scalar-vs-aggregate decides WHEN a stack slot is allocated (Phase 29 SESSION-19, `func_8017C730` 1,061 ins) <sub>L6404</sub>
- **§3-1.** — The inlined-helper signature <sub>L6409</sub>
- **§3-2.** — Scalar vs aggregate decides *when* the slot is allocated <sub>L6423</sub>
- **Also** — reproduced on this function <sub>L6435</sub>
- **§3-And** — the banking footnote (§75a class A, one line) <sub>L6439</sub>
- **§83** — The parameterised-repeat law, the spill-area trap, and why a per-case edit cannot move a per-case symptom (Phase 29 SESSION-20, `func_80183814` 5,122 ins, cold-ish start → 36 structural / 99.3%) <sub>L6446</sub>
- **§83a** — READ THE HEADLINE NUMBER CORRECTLY: a LENGTH drift makes `match_one`'s count meaningless <sub>L6453</sub>
- **§83b** — THE LEVER: find the parameterised REPEAT before decoding case-by-case <sub>L6461</sub>
- **§83c** — TRAP: a "dead local" in a prior draft may be gcc's OWN spill area <sub>L6479</sub>
- **§83d** — CSE's quantity budget is WHOLE-FUNCTION, so a local rewrite cannot fix a local symptom <sub>L6486</sub>
- **§83e** — §80 vindicated again, on the same day it was written <sub>L6500</sub>
- **§84** — The DERIVED-OFFSET remap bug: a hand-computed literal that encodes the DISTANCE between two per-overlay symbols, and why `match_one` is structurally blind to it (Phase 29 SESSION-20, `func_8013D53C`) <sub>L6506</sub>
- **§3-The** — construct <sub>L6511</sub>
- **§3-Why** — it survived every candidate gate <sub>L6529</sub>
- **§3-THE** — FIX IS MECHANICAL — the tool already holds the answer <sub>L6544</sub>
- **Scope** — , measured (do not over-generalise — §80) <sub>L6552</sub>
- **§3-Two** — ladder lessons banked with it <sub>L6562</sub>
- **§85** — The RETURN-axis fleet widen is ALL-OR-NOTHING: widening the shared header alone guarantees a conflict in the source overlay (Phase 29 SESSION-20, `func_8012CC88` / `func_8014D12C`) <sub>L6573</sub>
- **§3-The** — conflict <sub>L6578</sub>
- **§3-THE** — FAILURE MODE — widening only `engine_core.h` is worse than not starting <sub>L6586</sub>
- **§3-The** — precondition, and how to check it in one grep <sub>L6593</sub>
- **§3-Do** — the WHOLE axis in one edit, then R22 once <sub>L6601</sub>
- **Reading** — , for the next person <sub>L6610</sub>
- **§86** — Pinned-exemplar templatability is a PER-FAMILY property, not a per-member rate; and the §42e pin guard is now over-conservative (Phase 29 SESSION-20) <sub>L6623</sub>
- **§3-The** — guard refuses a class that largely works <sub>L6625</sub>
- **§3-THE** — LAW: all-or-nothing PER FAMILY <sub>L6634</sub>
- **§3-Why** — the two live families differ from the three dead ones — the open question <sub>L6661</sub>
- **§87** — `match_one` COMPILES but never LINKS, so an unresolvable data symbol reads as MATCH; and stored drafts go STALE against the tree (Phase 29 SESSION-20) <sub>L6667</sub>
- **§3-The** — blindness ladder, now complete — FOUR classes `match_one` cannot see <sub>L6683</sub>
- **Consequence** — for the backlog ledger <sub>L6693</sub>
- **§3-The** — cheap discriminator, before spending a sweep <sub>L6700</sub>
- **§88** — `cross_jump` will not merge a common suffix containing a CALL; and §78 is scoped to ORDERED comparisons only (Phase 29 SESSION-20, the behemoth close-out) <sub>L6708</sub>
- **§88a** — repeated CALL-shaped blocks are left UNMERGED; call-free tails are merged for you <sub>L6713</sub>
- **§88b** — the `slti` literal-position law (extends §78 to comparisons) <sub>L6720</sub>
- **§88d** — BANKING ORDER: run the §81 carve chain BEFORE banking, never after <sub>L6735</sub>
- **§88e** — a wrong diagnosis, refuted properly (the model for how to treat an inherited lever) <sub>L6742</sub>
- **§88f** — the missing rung: a RELOCATION gate between `match_one` and the binary <sub>L6752</sub>
- **§89** — Two throughput rules the project already had written down and was not following (Phase 29 SESSION-20) <sub>L6760</sub>
- **§89a** — MEASURE the write set; do not assert its tier (`tools/blast_radius.py`) <sub>L6766</sub>
- **§89b** — the parallel gate farm existed; the family path could not reach it (`tools/sweep_parallel.py`) <sub>L6779</sub>
- **§3-The** — standing sequence <sub>L6792</sub>
- **§90** — Five tool-integrity laws from one session, each of which changed an answer (Phase 29 SESSION-21, 2026-07-27) <sub>L6800</sub>
- **§90a** — A comparison tool MUST share its reference oracle's index space, exactly <sub>L6806</sub>
- **§90b** — "Byte-neutral" is not "wanted": undo on the SUCCESS path too <sub>L6823</sub>
- **§90c** — A library-callable function must FAIL CLOSED on an unconfigured module <sub>L6833</sub>
- **§90d** — Do not measure a live wave's drafts (§87 in real time) <sub>L6844</sub>
- **§90e** — An agent's CONCLUSION and its EVIDENCE fail independently — re-derive the premise, not the fix <sub>L6852</sub>
- **§91** — A structure-TRANSFER is only valid where the structure corresponds: the `--like` role trap (Phase 29 SESSION-21, `func_8012AAAC` ×137) <sub>L6876</sub>
- **§3-The** — three-hypothesis trail, because two of them were wrong and the wrongness is instructive <sub>L6905</sub>
- **§92** — Conforming a DECLARATION: pointer changes are caller-neutral, scalar-WIDTH changes are not (Phase 29 SESSION-21, `tools/conform_decls.py`) <sub>L6925</sub>
- **§93** — `set -o pipefail` attributes a pipeline failure to the LAST stage, not the failing one (Phase 29 SESSION-21, `func_8014D820`) <sub>L6956</sub>
- **§94** — A family sweep's `0/N` is a TYPE-CARRY failure until proven otherwise: lift the exemplar's local types, ALL of them, transitively (Phase 29 SESSION-21, `func_8016B6BC` 0/137 → 137/137) <sub>L6981</sub>
- **§95** — `reconcile_tu` dropped the SIBLING declarators of a multi-symbol `extern` line (Phase 29 SESSION-21, `func_80176218`) <sub>L7017</sub>
- **§96** — The same rewrite, one shape down: `reconcile_tu` matched statements to lines by TEXT, so every COMMENTED declaration was silently skipped (Phase 29 SESSION-22, `func_80176218` banked) <sub>L7052</sub>
- **§97** — The gate's own tree hygiene: a refused carve, an unchecked recovery, and a snapshot that captured a dirty tree (Phase 29 SESSION-22) <sub>L7100</sub>
- **§98** — `conform_decls` had three defects, and only the third needed R22 to find (Phase 29 SESSION-22, `func_8014CF04`) <sub>L7147</sub>
- **§99** — The narrow-param wall is a DEF-side problem with a ZERO-blast-radius fix: convert the definition to K&R (Phase 29 SESSION-22, `func_80175AB8` + `func_80175DA8`) <sub>L7201</sub>
- **§3-Two** — `reconcile_tu` bugs found underneath, one introduced while fixing the other <sub>L7224</sub>
- **§100** — Prefer the DRAFT-LOCAL fix: a type only one function uses belongs in its BODY, not in a shared header (Phase 29 SESSION-22, `func_80175DA8` 0/137 → 137/137) <sub>L7250</sub>
- **§101** — The STALE DEFAULT class: a guard whose cause was removed is a silent skip wearing a safety label (Phase 29 SESSION-22, three instances in one session) <sub>L7279</sub>
- **§102** — A PLUMBING verdict can MASK a DIFF; and K&R is not always a codegen change (Phase 29 SESSION-22, `func_8016EC0C`) <sub>L7306</sub>
- **§103** — A FILE-scope `extern` in a shared overlay TU is a GLOBAL constraint on every LATER function; move the DECL, not the draft (Phase 29 T48/T51, `func_80135260` — the fleet-wide half) <sub>L7341</sub>
- **§104** — Two silent-skip defects in one scan: match on MASKED text, emit from the ORIGINAL (Phase 29 T53, `gather_externs`) <sub>L7429</sub>
- **§105** — A gate's revert must survive an EXCEPTION, not just a failure (Phase 29 T53, `jtbl_family_bank`) <sub>L7465</sub>
- **§106** — Persist the MEASUREMENT, derive the POLICY: a stored route let a stale file out-vote the live table (Phase 29 T54, `residual_class._ROUTE`) <sub>L7504</sub>
- **§107** — A lever wired into ONE gate path is a lever most families cannot reach (Phase 29 T56, `func_80144090` 0/136 → 136/136) <sub>L7547</sub>
- **§108** — Diagnosing a family `0/N`: the four causes, and the third opt-in lever (Phase 29 T59) <sub>L7585</sub>
- **§109** — Conforming a definition to a shared header: fix the NAMES, then check the RETURN precondition (Phase 29 T60) <sub>L7634</sub>
- **§110** — A unit must define exactly ONE function, and "ends in `;`" does not tell you which line defines it (Phase 29 T65) <sub>L7674</sub>
- **§111** — The distinct-code metric is not noisy: a family pays it only if its members are byte-VARIANT (Phase 29 T66) <sub>L7715</sub>
- **§112** — A macro-scoped declaration only collides where the macro is INSTANTIATED (Phase 29 T67/T69, `audit_header_sigs.py`) <sub>L7764</sub>
- **§113** — An ARITY blocker only exists if the macro CALLS the function; an address-taken use has no call site (Phase 29 T72) <sub>L7810</sub>
- **§114** — The THIRD decl axis: a CALLEE the draft declares differently from the target TU (Phase 29 T76/T77) <sub>L7842</sub>
- **§115** — A `func_XXXXXXXX` predicate rots by design: the same name-form assumption in THREE places (Phase 29 T78) <sub>L7884</sub>
- **§116** — Optimization level is a property of the FILE, not the function: read a family 0/N against the member's stub HOME (Phase 29 T79) <sub>L7911</sub>
- **§3-The** — fix moves the DEFINITION, not the stub — and here is why the obvious shortcut fails <sub>L7929</sub>
- **§117** — Spell the sibling's symbol from the SIBLING's address, not the exemplar's kind (Phase 29 T82) <sub>L7960</sub>
- **§3-Why** — it survived so long: a MASKED oracle will MATCH a wrong symbol <sub>L7987</sub>
- **§118** — Ordinal (positional) immediate resolution: compare C tokens to the DIFFERING asm uses (Phase 29 T87) <sub>L7997</sub>
- **§119** — Two levers on the SAME axis, opposite directions: test the off-diagonal (Phase 29 T89) <sub>L8031</sub>
- **§120** — Uniquify draft-defined TYPE names; and check which of N staging sites you actually patched (Phase 29 T93) <sub>L8060</sub>
- **§3-Do** — NOT "strip the duplicate typedef" — it breaks the extern that uses it <sub>L8071</sub>
- **§3-The** — wiring trap that cost two attempts <sub>L8077</sub>
- **§121** — Synthesise externs for macro-DEFINED callees from the macro's own definition head (Phase 29 T95) <sub>L8095</sub>
- **§122** — GATE RAW BEFORE TRANSFORMING; the undo belongs to the WRITER, as a per-edit journal (P30 T0a, 2026-07-30) <sub>L8118</sub>
- **§123** — PROPAGATE A FAMILY WITH THE TOOL ITS TIER NEEDS: `dedup_propagate` is h_exact-only; its refusals are statements about the TOOL (P30 wave 1, 2026-07-30) <sub>L8150</sub>
- **§124** — A "not matched" verdict can mean the definition is there under a DIFFERENT C NAME: the asm-label alias blind spot (P30 SESSION-28, `func_8016191C` ×137) <sub>L8187</sub>
- **§124a** — a family sweep's `0 matched-exemplar families` may be a FILTER, not a wall <sub>L8232</sub>
- **§125** — Split the CARVE from the BODY before calling a jr residue a wall — and measure it by SHA from a CLEAN tree (P30 SESSION-28; **this section's first draft was WRONG and the method caught it**) <sub>L8240</sub>
- **§3-The** — method (keep this) <sub>L8247</sub>
- **§3-The** — instrument rules that make its answer trustworthy (this is where I failed) <sub>L8257</sub>
- **§3-The** — corrected results (each SHA-verified, from a clean tree, restore re-verified) <sub>L8272</sub>
- **§3-Two** — further notes worth keeping <sub>L8282</sub>
- **§3-The** — meta-lesson <sub>L8291</sub>
- **§126** — The carve-within-a-carve: an ADDRESS RANGE is not an OPTIMIZATION REGION (P30 T2, byte-proven end-to-end) <sub>L8298</sub>
- **§3-The** — finding: opt level is per FILE, so the file's contents must be opt-HOMOGENEOUS <sub>L8313</sub>
- **§3-The** — instrument trap that hid it (and it is §124's shape again) <sub>L8324</sub>
- **§3-The** — mechanics <sub>L8333</sub>
- **§126a** — a bare `except: continue` around a coverage-asserting oracle re-creates the silent skip (P30 S28) <sub>L8351</sub>
- **§127** — The `-O0` regime: the CONSTANT-OFFSET FOLD, and why `-O0` needs its own idiom set (P30 T3 wave, 15 targets) <sub>L8383</sub>
- **§3-The** — idiom they kept re-deriving: the constant-offset fold <sub>L8390</sub>
- **§3-The** — rest of the `-O0` regime (write PLAIN C, and mean it) <sub>L8401</sub>
- **§127a** — §71 (sibling-first) is the strongest `-O0` lever, and it beats the index <sub>L8411</sub>
- **§127b** — the knowledge was in a SOURCE COMMENT, not the cookbook <sub>L8420</sub>
- **§128** — A raw NUL in C source makes grep SILENTLY SKIP the file (P30 S28, 137 files) <sub>L8427</sub>
- **§128a** — a negative control must corrupt a SCRATCH COPY, never the tracked file <sub>L8459</sub>
- **§129** — Post-carve, `rtu_match`/`match_one` COUNT THE JUMP TABLE AS INSTRUCTIONS; and a carve must never be committed without its owner (P30 S28, `func_8013BD74`) <sub>L8471</sub>
- **§129a** — the target instruction count is INFLATED after a carve <sub>L8475</sub>
- **§129b** — never commit a carve whose owner is still a stub (it strands the carve) <sub>L8496</sub>
- **§3-The** — real blocker underneath, for the record <sub>L8511</sub>
- **§130** — An INCREMENTAL build can report BYTE-IDENTICAL for a change the CLEAN build cannot even LINK (P30 S28, the jr pair) <sub>L8520</sub>
- **§3-The** — diagnostic ladder that finally located it (reusable) <sub>L8557</sub>
- **§131** — The jtbl OVER-SPAN: `sltiu N` is ground truth in BOTH directions, and the zero-word rule only guards one (P30 S28, `func_80191C50`) <sub>L8567</sub>
- **§132** — The `JR-PAIR-IN-ONE-O0-OBJECT` "wall" was TWO instrument defects: a merged-double span the carve could not see, and a truncated object no rule deleted (P30 S29, `func_8013B83C` + `func_8013BD74`) <sub>L8604</sub>
- **Defect** — 1 — a pre-§8e MERGED DOUBLE is not a single-table predecessor <sub>L8613</sub>
- **Defect** — 2 — `as` writes a corpse and nothing deletes it <sub>L8631</sub>
- **§3-The** — fingerprint, and the 30-second ladder that found it <sub>L8641</sub>
- **§3-The** — transferable rule <sub>L8662</sub>
- **§132a** — `--like` is for a sibling with NO record; against one that HAS a record it over-derives (P30 S29, `ov_SC07_010`) <sub>L8669</sub>
- **§132b** — When the span's already-matched owner is ITSELF multi-switch: `--span-rel` (P30 S1, `func_8014032C`) <sub>L8694</sub>
- **§133** — The DEFAULT-FILTER class: three times in one session, a tool silently answered a narrower question than the one asked (P30 S1–S3) <sub>L8719</sub>
- **§134** — MULTI-LINE BLINDNESS: one root cause, four faces, in `family_remap`'s preamble scanner (P30 S6, 190 zero-crack families) <sub>L8745</sub>
- **§135** — Six byte-verified gcc-2.7.2 idioms from the P30 S6f-h waves (and the two-lane wave shape that found them) <sub>L8799</sub>
- **§3-The** — codegen idioms <sub>L8804</sub>
- **§3-The** — integration idioms (these decide whether a byte-correct draft BANKS) <sub>L8838</sub>
- **§3-The** — wave shape that produced these <sub>L8853</sub>
- **§136** — The LOCAL-VARIABLE lever: how many C locals, at what scope (P30 wave 4a, 25 byte-verified banks) <sub>L8871</sub>
- **§3-The** — splitting/merging rules (each closed a residual, byte-gated) <sub>L8887</sub>
- **§3-The** — type-form rules <sub>L8913</sub>
- **§3-The** — scheduling rules (refining §135-2 and §135-4) <sub>L8946</sub>
- **§3-The** — declaration surface (integration, not codegen) <sub>L8975</sub>
- **Wave** — economics (measured, for the next batch's sizing) <sub>L8987</sub>
- **§136a** — Blocker capture: classify on the OUTPUT, never on the exit status <sub>L9010</sub>
- **§136b** — A prior wave's "genuine byte-DIFF" verdict is NOT reliable evidence (4 of 4 refuted) <sub>L9067</sub>
- **§136c** — SIBLING-FIRST is a DERIVATION shortcut, not just a conflict fix (the fastest route in a family wave) <sub>L9103</sub>
- **§136d** — Four gcc-2.7.2 levers the redraft lane found (each closed a residual no other lever moved) <sub>L9128</sub>
- **§136e** — §136c's PRECONDITION, and two more symptom keys (wave 4b batch 3) <sub>L9172</sub>
- **§136f** — Two declaration sub-cases the reconcile lane surfaced (lane now 15/15 lifetime) <sub>L9220</sub>
- **§136g** — When the index points at the WRONG lever: two byte-refuted routings (func_801863B4) <sub>L9245</sub>
- **§136h** — CORRECTION: the zero-crack pool does NOT "refill with cheap work" (my error, byte-measured) <sub>L9274</sub>
- **§136i** — The drafter model LADDER: Haiku → **Sonnet** → Opus → Fable5 (Drew, 2026-08-03) <sub>L9304</sub>
- **§136j** — The failure MIX flips with function size (measured across four bands, one session) <sub>L9336</sub>
- **§137** — REGALLOC-PERM is a TWO-COMPILE ARITHMETIC PROBLEM, not a permuter job <sub>L9378</sub>
- **§137a** — A gate verdict has a TIMESTAMP; re-check it against the draft's mtime <sub>L9420</sub>
- **§138** — The propagation lanes: a gate refusal is a DECLARATION, and which lever you owe depends on blast radius <sub>L9449</sub>
- **§3-The** — triage, cheapest first <sub>L9455</sub>
- **§3-The** — DEFINITION-side alias is the only escape when the fleet canon disagrees on a promoting param <sub>L9507</sub>
- **Rank** — the lane by measured concentration, not by class count <sub>L9515</sub>
- **THREE** — carry variants hide in one "CARRY-FIXABLE" bucket — and they need different fixes <sub>L9524</sub>
- **§134** — again, in a second tool — and the waiter rule corrected <sub>L9560</sub>
- **STEP** — 0 of sibling-first: grep `src/` for a distinctive LITERAL from the `.s` <sub>L9580</sub>
- **Reconciling** — a gate-refused draft: which way you edit depends on WHERE the TU's decl is <sub>L9599</sub>
- **§139** — A GATE THAT GREPS FOR VERDICTS MUST ASSERT 1:1 ACCOUNTING; and a `--src` filter must not survive a carve (P30 S38, wave 6: 10 of 16 drafts vanished) <sub>L9628</sub>
- **§3-The** — generalisation — three corollaries worth more than the bug <sub>L9660</sub>
- **§3-And** — the inverse-lookup trap, same session <sub>L9677</sub>
- **§140** — A METRIC IS NOT A MEASUREMENT UNTIL IT IS REPRODUCIBLE FROM THE COMMITTED TREE (P30 S1e: a phantom regression that gated the session's best lever) <sub>L9694</sub>
- **§3-The** — three-line proof (do this before diagnosing any metric movement) <sub>L9714</sub>
- **§3-The** — two instrument defects it exposed <sub>L9723</sub>
- **§3-The** — same swallow, twice more, in the integration spine <sub>L9743</sub>
- **§3-Two** — wrong mechanisms I chased first, and why they were wrong <sub>L9754</sub>
- **§141** — The §134 class is CLOSED: every line-shape decision now routes through `cdecl._mask` (P30 S39) <sub>L9774</sub>
- **§142** — An open stub whose `h_exact` class is MATCHED elsewhere is FREE. Propagate the body; do not gate a draft. (P30 S39, +7,710 ins in two commands) <sub>L9812</sub>
- **§3-The** — measurement (do this before any wave; it is ~20 lines and needs no builds) <sub>L9824</sub>
- **§3-The** — trap that hid it — SAME FUNCTION, TWO ROUTES, ONLY ONE IS FREE <sub>L9839</sub>
- **Route** — selection (why `--addr` sometimes says "nothing changed") <sub>L9848</sub>
- **§3-And** — the report-vs-bytes lesson attached to it <sub>L9856</sub>
- **§143** — `cast_call_sites` read a RETURN STATEMENT as a prototype and deleted it. A 0/39 sweep became 18/39. (P30 S40) <sub>L9868</sub>
- **§144** — THE LITERAL'S SPELLING PICKS THE IMMEDIATE ENCODING (P30 S40 wave 1, `func_801822E0`) <sub>L9922</sub>
- **§145** — Three loop/combine levers from the S40 wave-2 drafters (16/16 match_one) <sub>L9961</sub>
- **§146** — RE-MEASURE A WALL BEFORE YOU RESPECT IT. Both "permanent" giants fell to drafts already on disk. (P30 S6, +50,094 ins) <sub>L10011</sub>
- **§3-Why** — a correct draft can read as an intrinsic wall <sub>L10022</sub>
- **Then** — propagation returned 0/137 TWICE — both times a missing TYPE <sub>L10034</sub>
- **§3-Two** — errors of mine, both instructive <sub>L10043</sub>
- **§3-The** — rule <sub>L10057</sub>
- **§147** — The three-stratum FRAME LAW, and four "stop searching" verdicts (P30 S42, `func_8017C294`, serial run) <sub>L10070</sub>
- **§3-A.** — The frame has THREE strata, and stratum 3 is unreachable from C <sub>L10075</sub>
- **§3-B.** — A `?:` on MEMORY operands costs ~16 bytes of invisible frame; on REGISTER operands, zero <sub>L10091</sub>
- **§3-C.** — Inner-block declaration does NOT delay slot allocation — BYTE-REFUTED <sub>L10102</sub>
- **§3-D.** — A lone `$t8`/`$t9` in the target is RELOAD SCRATCH — reproduce the spill, don't pin the register <sub>L10107</sub>
- **§3-E.** — A `qty_compare` TIE is not spelling-reachable — recognise it and stop <sub>L10117</sub>
- **Consequence** — for the family (a real scheduling decision) <sub>L10129</sub>
- **§148** — The loop.c hoisting THRESHOLD is arithmetic you can compute, and the `?:` clamp that folds to MIN_EXPR (P30 S42, `func_8017C6F4`, 947 ins) <sub>L10179</sub>
- **§3-A.** — `move_movables` hoists iff `threshold × savings × lifetime ≥ insn_count` — and you can read it <sub>L10185</sub>
- **§3-B.** — `(v < 0x40) ? v : 0x3F` is folded to `MIN_EXPR` and expands to the WRONG SHAPE <sub>L10204</sub>
- **§3-C.** — A zero-byte ALLOCNO-PRIORITY slider <sub>L10218</sub>
- **§3-D.** — Reproduce the original's BUGS verbatim <sub>L10228</sub>
- **§149** — Four instrument defects in one session, and the two questions they were hiding (P30 S43) <sub>L10277</sub>
- **§3-A.** — A prep step that returns its input on failure is indistinguishable from a search that found nothing <sub>L10283</sub>
- **§3-B.** — Same address + same name ≠ same body — and the ledger keys on address <sub>L10301</sub>
- **§3-C.** — `make: *** [...] Error N` is a summary, never a diagnosis <sub>L10317</sub>
- **§3-D.** — "Cheap fuel" that was never probed: 0 of 31 templatable <sub>L10327</sub>
- **§150** — A register ROTATION across symmetric blocks is VARIABLE-IDENTITY evidence, not an allocator tie (P30 S43, `func_8017C6F4`, 947 ins ×4) <sub>L10346</sub>
- **§3-The** — fix <sub>L10353</sub>
- **§3-The** — method that found it (this is the transferable part) <sub>L10363</sub>
- **§3-Two** — corrections to the record <sub>L10379</sub>
- **Diagnostic** — order (adopt this) <sub>L10390</sub>
- **§151** — THE GHOST WEDGE: when a load-before-store transposition is unreachable by ANY statement order (P30 S43, `func_8017EF68`, 969 ins) <sub>L10401</sub>
- **§3-The** — mechanism (read from cc1's own `-dR` trace, not inferred) <sub>L10406</sub>
- **§3-The** — lever — a zero-emission insn that absorbs the blocked tick <sub>L10421</sub>
- **§3-The** — two fallouts, and how to close them (both measured, in order) <sub>L10429</sub>
- **When** — to reach for it <sub>L10441</sub>
- **§152** — BYTE SIZE is the family key that name- and h_seq-grouping both miss (P30 S43, the 0xECC family: 1 crack → 12 overlays → 11,364 ins) <sub>L10452</sub>
- **§3-The** — finding <sub>L10457</sub>
- **§3-The** — key <sub>L10466</sub>
- **§3-Two** — cautions that must travel with this technique <sub>L10477</sub>
- **§3-The** — companion defect (open) <sub>L10488</sub>
- **§153** — THE ADDRESS-REMATERIALISATION LAUNDER: a third zero-emission asm lever (P30 S43, `func_8018D98C`, 710 ins) <sub>L10500</sub>
- **Symptom** — Symptom <sub>L10508</sub>
- **Mechanism** — (gcc source + RTL dumps, not inferred) <sub>L10513</sub>
- **What** — does NOT work (14 byte-measured probes) <sub>L10520</sub>
- **§3-The** — cure — a fresh launder per site, each in its own block <sub>L10526</sub>
- **Companion** — levers from the same function <sub>L10536</sub>
- **§154** — Reading a disc payload: the module-id word, static base derivation, and "type 1 = uncompressed overlay" (P30 S44) <sub>L10556</sub>
- **§3-A.** — Payload word0 is a global MODULE ID; code starts after the header <sub>L10561</sub>
- **§3-B.** — Two static base-derivation methods that must AGREE (use both) <sub>L10570</sub>
- **§3-C.** — PAC type 1 = the same payload class as type 4, just NOT compressed <sub>L10582</sub>
- **§155** — hi/lo literal scanning MUST track base registers (S45) <sub>L10592</sub>
- **§155a** — the same failure class, one level up: SHAPE-blind table scanning (S45 p5) <sub>L10601</sub>
- **§155b** — check the TYPE your oracle returns before comparing against it (S45 p5) <sub>L10621</sub>
- **§155c** — the ZERO-REFERENCE trap: gcc splits a global-array address across the `lui` and the LOAD (S46) <sub>L10644</sub>
- **§156** — an ORPHANED reconcile poisons the fleet: `dedup_propagate`'s kept edit (S45 p6/p7) <sub>L10674</sub>
- **§157** — the cheap-tier size cliff, measured (S45 p6) <sub>L10721</sub>
- **§158** — The RANGE-EXTENDER: a fourth zero-emission asm lever completes the allocno toolkit (P30 S46 tier-3, `func_8017CE58`, 733 ins) <sub>L10746</sub>
- **Symptom** — Symptom <sub>L10755</sub>
- **§3-Why** — the fork is chained (gcc source, validated insn-by-insn against -dS/-dR dumps) <sub>L10761</sub>
- **§3-The** — method (dump-arithmetic first, then place — no probing) <sub>L10774</sub>
- **Bonus** — facts worth keeping <sub>L10791</sub>
- **§156** — THE PREFERENCE-DONOR MERGE: cross-region variable reuse is what fills a0-a3, and a call-arg use in ONE region steers the fill in ALL of them (P30 S46 tier-3, `func_80186E24`, 611 ins: 236-off "S11 regalloc-order" → MATCH, zero new pins) <sub>L10806</sub>
- **§159** — THE DECLARATION AXIS: conform to byte-truth, and make every guard state its COVERAGE (P30 S47; ~10,930 sites across 8 axes, fleet byte-identical) <sub>L10862</sub>
- **§160** — THE REACH-15 WAVE HARVEST: an align-1 block move, and the instrument that called it a wall (P30 S47) <sub>L10927</sub>
- **§161** — THE RETRY-WAVE HARVEST: a jump table indexed from zero, and two allocator traps (P30 S47) <sub>L11003</sub>
- **§162** — S48 WAVE-1 HARVEST (P30, 2026-08-11): the reach-ordered sibling campaign's first 12 targets <sub>L11048</sub>
- **§162a** — SHARPENS *(sharpens §161a, §131, §8a-pad, §129a)* <sub>L11075</sub>
- **§162b** — SHARPENS *(sharpens §48-A3, §156, §150, §76)* <sub>L11104</sub>
- **§162d** — SHARPENS *(sharpens §31, §21, §30, §55a)* <sub>L11133</sub>
- **§162e** — NEW <sub>L11175</sub>
- **§162** — THE LICM PAIR: what makes an address a movable AT ALL, and why the preheader order is the body order (P30 S47, `ov_MAIN_012`) <sub>L11177</sub>
- **§162f** — SHARPENS *(sharpens §42d, §41d, §73, §10)* <sub>L11243</sub>
- **§162g** — NEW <sub>L11298</sub>
- **§162** — CROSS-JUMP DIRECTION: the surviving copy is always the LATER one, so a BACKWARD `j` into a sibling arm is a source `goto` (P30 S48) <sub>L11300</sub>
- **§162h** — SHARPENS *(sharpens §88, §88a, §50-B, §8)* <sub>L11334</sub>
- **§162** — The cross-jump "CALL veto" is a COUNT law, not a CALL law (BOUNDS §88a; P30 S48, `func_80189540`) <sub>L11336</sub>
- **§162i** — SHARPENS *(sharpens §135, §21, §42, §32)* <sub>L11402</sub>
- **§162j** — SHARPENS *(sharpens §25, §136d-1, §48-B, §46-L2)* <sub>L11427</sub>
- **§162k** — SHARPENS *(sharpens §1-I2, §12, §160d, §21)* <sub>L11456</sub>
- **§162l** — SHARPENS *(sharpens §48-B, §48-C1, §20, §21)* <sub>L11519</sub>
- **§162m** — SHARPENS *(sharpens §36, §158, §148, §153)* <sub>L11574</sub>
- **§158a** — THE FIFTH LEVER IS NOT AN ASM: `do { } while (0)` is a REGION ref-multiplier you MINT (P30 S48, `func_8017CBC8`, ov_MAIN_012 / jr_801789AC, 188 ins → MATCH) <sub>L11576</sub>
- **§3-The** — law <sub>L11583</sub>
- **Size** — it before you write it (§158 step 1-2, applied) <sub>L11594</sub>
- **§3-The** — wrap BOUNDARY is the dial — and it is indiscriminate <sub>L11615</sub>
- **§3-Not** — a pure dial <sub>L11621</sub>
- **DIAGNOSTIC** — TELL — two faces, one law <sub>L11625</sub>
- **§162n** — NEW <sub>L11647</sub>
- **§162o** — SHARPENS *(sharpens §158, §136-1, §136-6, §79)* <sub>L11680</sub>
- **§162p** — SHARPENS *(sharpens §48-B, §46-L2, §156, §136d-1)* <sub>L11739</sub>
- **§162q** — SHARPENS *(sharpens §30, §30a, §135-2, §136-13)* <sub>L11756</sub>
- **§163** — S48 WAVES 2-3 HARVEST (P30, 2026-08-11/12): the five that were byte-probed and are actionable <sub>L11794</sub>
- **§163z** — THE UNVETTED REMAINDER (do not cite as law; each needs a dedupe pass) <sub>L11862</sub>
- **§164** — S48 §163z SKEPTIC PASS (P30, 2026-08-12): 190 claims vetted, 82 banked <sub>L11882</sub>
- **§16Xy** — SHARPENS *(sharpens §136d-3, §37 /s-DEP LATTICE, §135-2, §136-13, §162q)* <sub>L12334</sub>
- **§3-The** — `/s` drop clause is in ALL THREE dependence predicates, so the FIXED-ADDRESS STORE is what floats (P30 S48, `func_8017CA18`, ov_MAIN_012) <sub>L12336</sub>
- **§164z** — REFUTED CLAIMS: do NOT re-derive these <sub>L13670</sub>
- **§165** — S48 WAVE-4 HARVEST (P30, 2026-08-12): banked the same day the wave landed <sub>L13736</sub>
- **§16Z** — SHARPENS *(sharpens §37 "the /s-DEP LATTICE", §136-13, §136-14, §16Xy, §162q, `gcc-2.7.2-map/sched.md` §64)* <sub>L14394</sub>
- **§3-The** — ADDRESS-CLASS TABLE: which load/store pairs even REACH the `/s` clause (P30 S48 wave 4, `func_80185B44`, ov_SC03_014) <sub>L14396</sub>
- **§165z** — REFUTED THIS WAVE: do NOT re-derive <sub>L14912</sub>
- **§166** — THE DESTINATION-TU ORACLE (P30 S48): the seven-attempt bug that was never codegen <sub>L14956</sub>
- **§167** — S48 WAVE-5/6 HARVEST (P30, 2026-08-12): the saturation point <sub>L15012</sub>
- **§167z** — REFUTED IN WAVES 5/6: do NOT re-derive <sub>L16208</sub>
- **§168** — THE COUSIN TIER (P30 S49, 2026-08-12): h_seq's exact-hash brittleness, measured — and the similarity map above it <sub>L16265</sub>
- **§169** — THE MICRO-ADAPT LANE (P30 S49): edit a proven body, don't crack a new one <sub>L16317</sub>
- **§170** — THE A-PROP WORD-DIFF CARD (P30 S49): the lane that had no owner <sub>L16364</sub>
- **§171** — THE STALE SEED SYMBOL (P30 S50, 2026-08-13): why §170's 91%→57% was never codegen <sub>L16408</sub>
- **§171a** — THE MECHANICAL A-PROP DRAFT (P30 S50): 256 members banked with no agent in the loop <sub>L16474</sub>
- **§171b** — THREE CARRIES THE MECHANICAL DRAFT NEEDS (P30 S50, banking the top-reach families) <sub>L16524</sub>
- **§172** — THE ORPHAN-SLOT MECHANISM v2 (P30 S50-Max): the complete frame-residue model for gcc-2.7.2 MIPS <sub>L16557</sub>
- **§172a** — TWO DECOMPILATION TELLS FROM THE SAME DIG (P30 S50-Max) <sub>L16611</sub>
- **§172b** — THREE MORE TELLS FROM THE GCC READ (P30 S50-Max, banked on Drew's ask) <sub>L16627</sub>
- **§173** — THE STORED-PLUMBING RECOVERY RECIPE (P31 T6): symfix-first, per-group isolation, and where the verdicts have no drafts <sub>L16670</sub>
- **§174** — THE ADAPT-CARD WAVE RECIPE (P31 waves A/B, 2026-08-14): prevention beats recovery <sub>L16706</sub>
- **§175** — A CALLER-SAVED REGISTER PIN CAN BE A CORRECTNESS BUG, NOT JUST A SCHEDULING CHOICE (P31 wave H, 2026-08-15) <sub>L16776</sub>
- **§176a** — THE VERIFICATION-LAYER LAWS (P31 overnight, 2026-08-15). What each check can and cannot prove. <sub>L16801</sub>
- **§176b** — BATCH-GATING MECHANICS (P31): what changes when N drafts land in ONE .c <sub>L16841</sub>
- **§176d** — THE CONFLICT TABLE MUST BE SEEDED FROM THE TU, AND KEYED PER FILE (P31 S52, 2026-08-15) <sub>L16867</sub>
- **§176e** — SYMBOL IDENTITY IS COMPUTABLE OFFLINE (P31 S52): `tools/reloc_identity.py` <sub>L16906</sub>
- **§176f** — THE DECLARATION FORM IS A MATCHING LEVER, SO RECONCILE TOWARD THE FORM THE MATCH NEEDS (P31 S52) <sub>L16963</sub>
- **§176g** — SIZE A WAVE BY INSTRUCTIONS, NOT BY CARDS (P31 S52 — the adopted doctrine) <sub>L16994</sub>
- **§176h** — THE BATCH-SUBSTITUTION HAZARD MAP (P31 S52): seven holes, three wrong fixes, one law <sub>L17032</sub>
- **§3-A.** — The seven under-reporting holes (all in `gate_main`, all the same shape) <sub>L17040</sub>
- **§3-B.** — Typedef handling — the only strategy that survives contact <sub>L17058</sub>
- **§3-C.** — The limit that remains (recorded, not solved) <sub>L17080</sub>
- **§3-C2.** — RECONCILE BEFORE THE FIRST GATE — a parked draft gets HARDER to bank, not easier <sub>L17087</sub>
- **§3-D.** — The measured cost shape, and what to build next <sub>L17110</sub>
- **§176i** — WHAT A STATIC PRE-GATE CHECK CAN AND CANNOT PROVE (P31 S52, wave Q) <sub>L17128</sub>
- **§176j** — STOPPING A WAVE MID-FLIGHT COSTS THE IN-FLIGHT TAIL (and how much is recoverable) <sub>L17160</sub>
- **§176j-2** — THE REPAIR PASS, MEASURED (do this instead of resuming) <sub>L17186</sub>
- **§176k** — TWO SELECTOR BUGS THAT SILENTLY SHRINK A WAVE <sub>L17206</sub>
- **§177** — 🔴 THE EPILOGUE RETURN-DELAY SLOT IS DECIDED BY YOUR SAVED-REGISTER SET, NOT BY SCHEDULING <sub>L17223</sub>
- **§178** — SIX LEVERS MINED FROM THE WAVE-P JOURNALS (P31 S52), each byte-proven and source-cited <sub>L17280</sub>
- **§3-A.** — THE `$0`-ADD OPAQUE COPY defeats `make_regs_eqv` (func_80033398, 93 ins) <sub>L17292</sub>
- **§3-B.** — A `return <const>` IS A PRIORITY-1 HARD-REG SET THE SCHEDULER PLACES FIRST (func_8001BE30, 92 ins) <sub>L17308</sub>
- **§3-C.** — SINGLE-SET TEMPS GET THE BIRTHING BOOST (func_8001D3FC, 196 ins) <sub>L17321</sub>
- **§3-D.** — A NARROW TYPE BLOCKS COPY ELISION (func_8001D3FC — new idiom) <sub>L17329</sub>
- **§3-E.** — THE ZERO-OFFSET ALIAS HOLE (func_80037028, 71 ins) <sub>L17336</sub>
- **§3-F.** — `MEM_IN_STRUCT_P` ASYMMETRY IN `true_dependence` (func_80037144, 124 ins) <sub>L17345</sub>
- **§3-G.** — TWO MODELLING TRAPS THAT COST THESE AGENTS SWEEPS OF HUNDREDS OF COMPILES <sub>L17351</sub>
- **§179** — IDIOMS MINED FROM THE WAVE P/Q JOURNALS (P31 S52, harvest pass) <sub>L17367</sub>
- **§179-A** — 🔴 A LOOP-WALKED POINTER **PARAMETER** HANDS ITS ARGUMENT REGISTER TO THE GIV (9 byte-proofs) <sub>L17377</sub>
- **§179-B** — 🔴 THE HAND-WRITTEN-ASM TRANSCRIPTION CHECKLIST (maspsx + masked_diff; 10 byte-proofs) <sub>L17426</sub>
- **§179-C** — 🔴 A FUNCTION WITH NO EPILOGUE (falls into a sibling's shared tail) MUST BE FILE-SCOPE `__asm__` <sub>L17476</sub>
- **§179-D** — `gte_stflg` MUST CLOBBER `"$12"` OR THE WHOLE TEMP FILE ROTATES BY ONE <sub>L17527</sub>
- **§179-E** — A `>2*MAX_MOVE_BYTES` BLOCK COPY IS A **STRUCT ASSIGNMENT**, NOT A HAND LOOP <sub>L17547</sub>
- **§179-F** — PINNING A LOOP-WALKED POINTER IS A TOTAL OFF-SWITCH FOR STRENGTH REDUCTION <sub>L17573</sub>
- **§179-G** — 🟡 A PIN CAN **CREATE** A COMBINE `LOG_LINK` AND DELETE AN `andi` (sixth RC-5 channel, n=1) <sub>L17596</sub>
- **§179-H** — A MID-BODY `.global LABEL` PAIR SLICES A BYTE-COMPARABLE FRAGMENT OUT OF A LARGER ROUTINE <sub>L17623</sub>
- **Considered** — and NOT banked <sub>L17646</sub>
- **§176c** — MAIN (SLUS_007.26) CANNOT BE GATED INCREMENTALLY <sub>L17663</sub>
- **§176** — SEVEN LEVERS FROM THE P31 OVERNIGHT WAVES (2026-08-15): statement order, false regalloc, and the pin that fights back <sub>L17674</sub>
- **§176-A** — "SCHEDULE / DELAY-SLOT / LENGTH-DRIFT ±1" ⇒ check STATEMENT ORDER around the call first <sub>L17680</sub>
- **§176-B** — "REGALLOC-PERM, 1-4 instructions off" ⇒ it is usually NOT register allocation <sub>L17704</sub>
- **§176-C** — 🔴 WALL REFUTATION: a hard-register pin CANNOT schedule around a call, because of a genuine gcc-2.7.2 bug <sub>L17750</sub>
- **§176-D** — CSE-class levers used in reverse (two sharpenings of §153 and cse_expr §2) <sub>L17776</sub>
- **§176-E** — Two cheap source spellings, both cc1-probed <sub>L17802</sub>
- **§176-F** — Misdiagnosis triage: four residual verdicts that were lying <sub>L17824</sub>
- **What** — is NOT banked here <sub>L17841</sub>
- **§180** — THE LEFTOVER-DRAFT HARVEST: RE-VERIFY WHAT YOU ALREADY HAVE BEFORE DRAFTING ANYTHING NEW <sub>L17854</sub>
- **§180b** — WHAT THE PRE-GATE LADDER ACTUALLY FINDS IN A COLD PILE (the shape of integration debt) <sub>L17883</sub>
- **§180c** — WHEN A BINARY'S MASS BAND IS SPENT, THE FLEET-WIDE DRAW IS STRICTLY BETTER <sub>L17902</sub>
- **§181** — WHAT A WAVE'S GATE ACTUALLY REJECTS (P31 S53, measured on wave R's 45-draft main pile) <sub>L17920</sub>
- **Only** — ONE of 27 blocked drafts was wrong. The other 26 were correct and unbankable. <sub>L17921</sub>
- **§182** — §177's HONEST NEGATIVE: the epilogue lever cracked 4 of 16, and the `800c3` cluster held <sub>L17976</sub>
- **§180d** — THE `pgrep` BRACKET TRICK PROTECTS THE PATTERN, NOT THE COMMAND LINE <sub>L17990</sub>
- **§183** — THE DECLARATION-RECONCILIATION PLAYBOOK (P31 S53, measured on 20 byte-verified drafts) <sub>L18002</sub>
- **§3-18** — of 20 reconciled while keeping the match. The two that did not are mechanism, not effort. <sub>L18003</sub>
- **§184** — COMMENT-BLINDNESS IS A DEFECT CLASS, NOT A BUG (P31 S53: three tools, one root cause, one session) <sub>L18073</sub>
- **§185** — EDIT THE SIDE THAT IS CHEAP TO VERIFY, AND CHECK A TU RETYPE AT ITS USE SITES <sub>L18101</sub>
- **§186** — CROSS-JUMPING RUNS **AFTER** SCHEDULING, SO NO C-LEVEL BARRIER CAN STEER IT <sub>L18133</sub>
- **§186b** — A NO-SAVE 16-BYTE FRAME IN A LEAF FUNCTION MEANS `s16` LOCALS, NOT A HIDDEN CALL <sub>L18154</sub>
- **§186c** — WHERE A VALUE IS LOADED DECIDES WHICH ALLOCATOR OWNS IT, AND THEREFORE ITS REGISTER <sub>L18162</sub>
- **§187** — 🔴 "SAME SOURCE" IS NOT "SAME OBJECT": THE SDK BUILD AND THE GAME BUILD DISAGREE ON GTE NOPS <sub>L18179</sub>
- **§188** — 🔴 THE `jr $ra` + `addiu $sp` TAIL IS AN **ASSEMBLER** ARTIFACT, NOT A FRAME SHAPE <sub>L18217</sub>
- **§189** — FIVE COMPILER LAWS MINED FROM THE WAVE R/S JOURNALS (P31 S53), each source-cited and re-derived by a second agent <sub>L18267</sub>
- **§190** — THREE PRESCRIPTIONS FROM THE SAME HARVEST (weaker evidence than §189, honestly labelled) <sub>L18342</sub>
- **§191** — WHAT THIS HARVEST DID **NOT** BANK (4 rejected, 4 narrowed) — recorded so it is not re-derived <sub>L18379</sub>
- **§192** — THE PRE-GATE LADDER WAS MAIN-ONLY, AND NOBODY COULD SEE IT (P31 S54) <sub>L18401</sub>
- **Three** — defects in one call path; the overlay slates that carry most of the wave work were being waved through <sub>L18402</sub>
- **§193** — THE WAVE-T HARVEST (P31 S54): 71 index_gap reports -> 9 laws, 5 rejected, 61 already-covered <sub>L18466</sub>
- **§193-A** — The wave card ships only OPEN-set pointers and discards the atlas's BANKED one — `exemplar`/`sibs` are stubs 100% by construction (tools/atlas.py:96/657), while `seed.ref` (matched pool, atlas.py:505-536) is dropped at build_wave_atlas.py:143 <sub>L18483</sub>
- **§193-B** — A NARROW CAST OF A WIDE PARAMETER COSTS ONE EXTRA INSTRUCTION WHEN ITS STATEMENT SITS AFTER AN INTERVENING `jal` — AND THE DECIDER IS `combine.c:929`'s CROSS-CALL GUARD, NOT REGISTER ALLOCATION <sub>L18550</sub>
- **§193-C** — gcc-2.7.2 cross_jump merges the SCHEDULED common SUFFIX only — there is no prefix/head merge, so §8/§48-A1's "duplicate into both arms and cross_jump refunds it" is a TAIL-only lever <sub>L18588</sub>
- **§193-D** — A COMPILER-GENERATED ARGUMENT COPY IS A `optimize_reg_copy_1` TRIGGER: when the pointer's LAST use in a block precedes a call that takes the pointer *as a register*, sched1 hoists the implicit `move $aN,$sN` to the block top and local-alloc re-bases the WHOLE block's memory operands onto `$aN`. The only C dial is a label (the §165-24 goto-join) between the block and the call. <sub>L18622</sub>
- **§193-E** — A varying-address (pointer) load is re-emitted once per CSE-LIVE INTERVAL, and naming it in a C local is the only C-level lever over that count — no store SPELLING has any reach <sub>L18693</sub>
- **§193-F** — §148-A2 — The `threshold -= 3` STAIRCASE: `move_movables` admits a COUNT of invariants, not a boolean — two identical merged constants split hoisted/not-hoisted by LIST ORDER, and `insn_count` picks the rank cutoff <sub>L18723</sub>
- **§193-G** — §164-54's "scope to ≥4 arms" bound is byte-wrong — the dispatch-topology oracle goes live at THREE case nodes (`balance_case_nodes` splits at `i > 2`), but only for a signed-after-promotion index <sub>L18787</sub>
- **§193-H** — A pointer-derived base load `*(s32*)(p+K)` is uncacheable across ANY memory write or call (cse's third kill disjunct) — so the target emits one `lw` per store-separated RUN of spellings, and a run of stores sharing one `lw` is a C local you must declare <sub>L18848</sub>
- **§193-I** — A DECLARED AGGREGATE LOCAL HAS AN 8-BYTE FRAME STRIDE — CEIL(size,8), NOT size. N ARRAYS THEREFORE COST 8·k MORE THAN ONE HAND-LAID STRUCT (k = how many of them have size mod 8 ≠ 0), AND THE TELL IS IDENTICAL INSTRUCTION COUNT WITH EVERY $sp DISPLACEMENT SHIFTED BY THE SAME CONSTANT. <sub>L18888</sub>
- **§193-REJECTED** — what this harvest did NOT bank (recorded so it is not re-derived) <sub>L18947</sub>
- **§194** — THE WAVE-U HARVEST (P31 S54): 64 index_gap reports -> 14 laws, 5 rejected, 44 already-covered <sub>L18974</sub>
- **§194-A** — A zero-byte scheduling fence goes AFTER the defining statement to make that computation emit FIRST in its block — and the barrier predicate is `volatile`-or-colon-less, not the `"memory"` clobber (COMPLEMENTS §165-40; does not refute it) <sub>L18991</sub>
- **§194-B** — A `addu $rA,$rB,$zero` copy feeding ≥2 `sh` stores is a SECOND, 16-BIT-DECLARED local — the width, not the clamp or the join liveness, is what keeps the copy (and func_80183094's pin + `"memory"` clobber are both provably inert) <sub>L19057</sub>
- **§194-C** — A CALLER-SAVED loop counter proves its live range crosses ZERO calls — so it cannot share a pseudo with any value LIVE ACROSS a call (but it may freely share one with values that merely sit between calls) <sub>L19095</sub>
- **§194-D** — Declared width of a computed-value local is a sched1 dial (count-neutral) — a replication + attribution correction of §165-17, NOT a new argument-register law <sub>L19158</sub>
- **§194-E** — The wave card's `exemplar` is the TARGET ITSELF on 42/73 wave-U and 36/71 wave-T cards — a construction consequence of `atlas.py:657` (exemplar = max-nins OPEN member) meeting `build_wave_atlas.py:166` (one card per gid); and the shipped §193-A `seed_ref` is same-binary on 0/51, so no card field can ever name a destination-TU sibling <sub>L19199</sub>
- **§194-F** — `if ((*p = v = f()) == 0)` is an expand-time pseudo SPLITTER (store_expr's `want_value && MEM` path), not a fold — it partitions one value between local_alloc and global_alloc. BOUNDS §21's L1872 bullet, whose stated direction is byte-wrong on 3 of 4 instances, and CLOSES the control §167-37 asked for. <sub>L19236</sub>
- **§194-G** — Reading the integer half of a 16.16 stack aggregate: REGISTER-LIVENESS, not the C spelling, decides `sra` vs `lhu` — and the break is count-neutral <sub>L19309</sub>
- **§194-H** — §164-29's WAR fence runs again at SCHED2 ON HARD REGISTERS: an in-place `v &= K` before a branch fences the store that reads v, and when TWO independent stores compete for the one delay slot the fence picks the winner at ZERO length drift (a WIDTH/sh!=sw swap, not a nop). Corrects §167-42's reconstruction (pseudo arm → hard-reg arm) and supplies its first re-runnable A/B. <sub>L19352</sub>
- **§194-I** — §16N+2's magic-per-odd-part ladder has exactly one broken row — read the divisor arithmetically instead: d = round(2^(32 + post_shift) / magic_read_as_unsigned) <sub>L19390</sub>
- **§194-J** — Back-to-back identical stores: flow.c's `last_mem_set` deletes the first, and only `volatile` saves it <sub>L19433</sub>
- **§194-K** — Blind sched1's alias oracle with a second SET of a pointer pseudo — the first zero-byte, non-volatile, dependence-CREATING lever (corrects §167-05's "volatile is the only door"; fourth consumer of reg_n_sets) <sub>L19485</sub>
- **§194-L** — §88b and §189-E are BOTH half-wrong, but not the way the candidate says: the compare-constant shape is a 2-D lookup (cmp_info ROW × constant-in-window), and naming matters on OPPOSITE sides of the window for the GE/LT rows vs the GT/LE rows <sub>L19563</sub>
- **§194-M** — A STORE in a CONDITIONAL branch's delay slot proves its C statement DOMINATES the branch — reorg can never pull a store out of either thread (gcc-2.7.2, -mips1) <sub>L19611</sub>
- **§194-N** — §193-D's C dial is misstated: the lever is a SURVIVING CODE_LABEL (a label with a real incoming edge), not "a label between the block and the call" — a bare label, or a `goto L; L:` pair whose target is the next active insn, is deleted by jump1 (jump.c:663-669 → delete_insn → jump.c:3458-3461, and jump.c:243 for the bare case) long before sched1/local-alloc, and costs exactly zero bytes <sub>L19669</sub>
- **§194-REJECTED** — what this harvest did NOT bank (recorded so it is not re-derived) <sub>L19729</sub>
- **§195** — THE WAVE-V HARVEST (P31 S54): 67 index_gap reports -> 14 laws, 9 rejected, 76 already-covered <sub>L19750</sub>
- **§195-A** — §167-08's "an $aN READ before the jal is scratch" has a byte-proven FALSE-NEGATIVE class: an argument that DIES at the call is allocated straight into $aN, so its only def is a plain load far above the jal and every intervening use reads $aN — there is no positive tell in either direction, only the two-arity A/B <sub>L19764</sub>
- **§195-B** — A CALL_INSN does not start a basic block in gcc-2.7.2 — so a call-crossing temp can be a LOCAL-alloc quantity (the missing precondition under §48-A2 / §52 / regalloc.md K8) <sub>L19835</sub>
- **§195-C** — A call-argument `%hi/%lo` pair sitting at the block head, far above its `jal`, is a load-delay-gap filler chosen by SOURCE STATEMENT ORDER — swap the two independent statements nearest the call; a single-use `void *p = &SYM;` call-arg temp is OUTPUT-inert against it (but NOT expand-stream-inert) <sub>L19877</sub>
- **§195-D** — §195 — `masked_diff.mask_for` returns 0 for EVERY `j`/`jal` word, so an internal `j` destination is invisible to match_one, the permuter scorer AND every similarity tier: a control-flow semantic error (which calls execute) surfaces as a 1-instruction residual mislabelled `DELAY-SLOT / profile=schedule`, or as an outright false MATCH <sub>L19925</sub>
- **§195-E** — A 0/1 materialised at a JOIN immediately before the controlling `beqz`/`bnez` proves the source NAMED the condition — a truth expression in an `if`'s controlling position reaches `do_jump`, which has no value path <sub>L19993</sub>
- **§195-F** — fold-const.c:4825 canonicalises a `?:` whose THEN arm is zero (or constant against a non-constant ELSE) by inverting the condition and swapping the arms — so a ternary's written arm order is byte-inert there, and `c ? 0 : X` is unspellable: it always compiles as `!c ? X : 0` <sub>L20051</sub>
- **§195-G** — §NEW — TWO ARMS CALLING THE SAME CALLEE MERGE INTO ONE `jal` UNLESS EACH ARM'S OWN CODE CONSUMES THE RESULT: the C dial that keeps two call sites apart is WHERE the consumer test lives, and the branch SENSE you spell it with is byte-inert (jump.c:1737 canonicalises it) <sub>L20103</sub>
- **§195-H** — §165-27g — ON A FIXED-SYMBOL GLOBAL, `extern T D[];` + `D[0]` IS THE CSE RELOAD DIAL, AT ZERO ADDRESSING COST, AND THE ELEMENT COUNT IS INERT (§165-27's `T v[2]` CAVEAT IS A LOCAL-FRAME FACT AND DOES NOT TRANSFER) <sub>L20151</sub>
- **§195-I** — §145(b) AMENDED — the pointer-bump `addiu` is saved by cse, not combine: ANY second SET of a pseudo in the address's equivalence chain (in-place `p += K`, §145(b)'s `p = r;` copy, or an asm re-tie) kills the fold; the pass is cse and the gate is `invalidate`'s `reg_tick++` <sub>L20198</sub>
- **§195-J** — GTE / PsyQ op CALL-vs-INLINE is a PER-SITE SOURCE FACT, not a TU style — both forms coexist in one TU (measured in 2 TUs), and the tell is the target's own opcodes (`lwc2`/`sqr`/`swc2` vs `jal`), not the sibling. Costs -8 ins on func_8018505C. Corollary: the game's inline `sqr` macro emits TWO hazard nops, the SDK's `Square0` body emits ONE — so the inline form is provably not `Square0` inlined (a second instance of §187's SDK-vs-game GTE nop divergence). <sub>L20263</sub>
- **§195-K** — At -O2 the §18 array-of-struct lever is a FRAME lever, not a length lever — but only when the N reads carry DISTINCT index expressions; with a SHARED index §18's +2-instruction residual is still alive at -O2 (the submitted "memory-loaded narrow index" precondition and unconditional length-neutrality are both falsified) <sub>L20307</sub>
- **§195-L** — The cse store-re-seed does not cross a JOIN LABEL: per-arm stores + a join read keep the reload that one join store deletes (bounds §193-E BOUND 1/BOUND 3 with §48-B's EBB boundary) <sub>L20359</sub>
- **§195-M** — Frame `vars` is a SEQUENTIAL bump-allocation, not a flat sum: §193-I's CEIL(aggregate,8) term and §165-03/§167-06's 8×orphan term are the SAME frame_offset walk at two different compiler stages, and each stage re-CEILs frame_offset to 8 before it allocates <sub>L20411</sub>
- **§195-N** — In a call-bearing chain of N≥2 `if (f(...)) return 1;` tests closed by `return 0;`, the LAST test must stay in STATEMENT form — the value form (`return f() != 0;` / `? 1 : 0` / `!!f()`) costs +1 `j` and empties the other N−1 delay slots. The cause is REORG block placement, not jump.c's `delete_jump`. <sub>L20460</sub>
- **§195-REJECTED** — what this harvest did NOT bank (recorded so it is not re-derived) <sub>L20507</sub>
- **§196** — PUT ON THE CARD WHAT THE TREE ALREADY KNOWS: the fleet's declaration consensus (P31 S54) <sub>L20553</sub>
- **§197** — THE WAVE-W HARVEST (P31 S54): 68 index_gap reports -> 4 laws, 3 rejected, 41 already-covered <sub>L20608</sub>
- **§197-A** — A NARROW SIGNED MEMORY READ FEEDING A CONSTANT `>>` LOSES ITS `lh`, AND THE CURE IS AN ASM RE-TIE (attribution CONTESTED: cse vs combine) <sub>L20622</sub>
- **§197-B** — A REPEATED COMPARE OF ONE VALUE AGAINST ONE CONSTANT IS DELETED BY cse's `qty_comparison_code` CHANNEL (the non-EQ complement of §165-03) — and a front-end-opaque mask on EITHER compare is a pure-C dial that keeps the target's second branch <sub>L20660</sub>
- **§197-C** — Fix A1 (operand order) cannot move a commutative destination whose .greg conflict set already contains BOTH operand hard registers — split the accumulate so the destination IS the load's pseudo <sub>L20688</sub>
- **§197-REJECTED** — §197-REJECTED <sub>L20733</sub>
- **§199** — THE WAVE-X HARVEST (P31 S54/S55): 63 index_gap reports -> 7 laws, 2 rejected, 56 already-covered <sub>L20748</sub>
- **§199-A** — §189-A's asm→source inference is byte-FALSE: an interloper between a split constant's `lui`/`ori` is a SCHEDULE fact, not a source fact — and the separator is the BIRTHING BOOST, not a "priority floor" (§189-A's split-timing half survives; its "no statement order / no pin" absolute and the candidate's own forward-scheduler narrative both fall) <sub>L20759</sub>
- **§199-B** — A permutation sweep that holds ANY statement fixed is not a sweep: the statement an agent pins as "obviously load-bearing" is the one carrying the signal, and the partial sweep returns a FLAT residual that reads as proof of order-invariance <sub>L20808</sub>
- **§199-C** — A NEGATIVE CONSTANT MULTIPLY ALWAYS TAKES expmed's negate_variant — but whether you ever SEE the neg is decided by COMBINE, and for an EVEN |K| it never disappears <sub>L20853</sub>
- **§199-D** — A narrow UNSIGNED value compared in an ordered `if` emits `sltiu`/`sltu`; the only dial is the WIDTH of a real object, and a widening `(s32)` cast is inert — AMENDS §35 (whose stated "only CSE-reuse canonicalizes" mechanism is byte-wrong) and does NOT apply inside a `switch` <sub>L20901</sub>
- **§199-E** — §189-A BOUNDED AND CORRECTED — the discriminator is INSN_PRIORITY, not "is the interloper a constant": an insn between a `lui`/`ori` pair proves NOTHING about the source spelling unless it TIES the `ori` on priority, and on the pinned `-mcpu=3000` triple a dependent load never does <sub>L20961</sub>
- **§199-F** — §164-36b — THE TARGET-HEAD FENCE IS A DELAY-SLOT THREAD SELECTOR, AND IT ONLY FIRES WHEN `mostly_true_jump > 0` (amendment to §164-36; its "−1 instruction" tell is falsified) <sub>L21020</sub>
- **§199-G** — At TWO case nodes the switch-vs-if oracle is not blind — but the tell is ALL tests positive + a trailing `j default`, NOT the first test's polarity <sub>L21074</sub>
- **§199-REJECTED** — §199-REJECTED <sub>L21129</sub>
- **§200** — THE ALIAS IS THE UNIVERSAL DECLARATION ESCAPE: stop negotiating with the TU's spelling (P31 S55) <sub>L21140</sub>
- **§201** — THE WAVE-Y HARVEST (P31 S55): 67 gap reports -> 5 laws, 8 rejected, 53 already-covered <sub>L21189</sub>
- **§201-A** — §150-B applies to `decl_prior`'s DEF row: for an overlay-window symbol the banked "definition" is usually another overlay's function, and the card ranks it ABOVE the destination TU <sub>L21199</sub>
- **§201-B** — In a narrowed PLUS/MINUS/AND/IOR/XOR expression the destination pointee is INERT — the sign of the materialized constant is decided by an OR over the UNWIDENED operands (convert.c trunc1), which bounds §1841 to direct constant stores <sub>L21231</sub>
- **§201-C** — §X — A CALL'S OWN DELAY SLOT AND THE UPSTREAM CONDITIONAL BRANCH'S SLOT COMPETE FOR ONE INSN (the call's argument copy), AND ONE STATEMENT'S POSITION RELATIVE TO THE CALL DECIDES BOTH — the residual is visible at the BRANCH, not at the call <sub>L21311</sub>
- **§201-D** — THE SIGNEDNESS OF A div/mod MAGIC IS DECIDED BY THE STATIC TYPE OF THE DIVIDEND TREE AFTER `get_narrower` STRIPS WIDENING CONVERSIONS — NEVER BY A PROVABLE RANGE. AN `& 0xFF` IS NOT A CONVERSION, SO IT NEVER FLIPS THE MAGIC; A DECLARED-UNSIGNED LOCAL *OR* A NARROWING CAST WRITTEN AT THE DIVIDE BOTH DO. <sub>L21362</sub>
- **§201-E** — §194-J-2 — The `last_mem_set` deletion window is measured in SOURCE/expand order, not in the printed stream; a foreign store moved between the pair in C source is a real lever, and `volatile` is not always the better one <sub>L21409</sub>
- **§201-REJECTED** — eight, the session's highest <sub>L21465</sub>
- **§202** — THE ALIAS CARRIES A DEFINITION, NOT JUST A DECLARATION: the DEF-SIDE-RETURN wall (P31 S56) <sub>L21490</sub>
- **§203** — A DEDUPED TYPEDEF MUST PRECEDE EVERY SPLICE POINT, NOT JUST ITS OWN (P31 S56) <sub>L21527</sub>
- **§204** — THE WAVE-Z HARVEST (P31 S56): 82 gap reports -> 5 laws, 16 rejected, 30 already-covered <sub>L21588</sub>
- **§204-A** — A COMPARE THAT APPEARS BOTH IN A BRANCH'S DELAY SLOT AND AGAIN ON THE FALL-THROUGH IS A JOIN WITH TWO INCOMING EDGES: THE TWO GUARDS ARE SEQUENTIAL `if`s, NEVER `if/else if` <sub>L21607</sub>
- **§204-B** — A LOOP COUNT THAT ARRIVES ON THE STACK IS DECREMENTED IN PLACE: a fresh counter local can cost a real `move` AND permute the whole callee-saved file <sub>L21682</sub>
- **§204-C** — WHEN A LOCAL BUFFER'S ADDRESS IS PASSED TO A CALL, ITS SIZE IS A FACT ABOUT THE CALLEE'S BODY, NOT ABOUT THE CALL SITE: grep the callee's proven definition and count the stores through the pointer parameter before you declare the local <sub>L21746</sub>
- **§204-D** — A LOOP-INVARIANT LOAD IS ADMITTED AS A MOVABLE ONLY IF ITS ADDRESS CANNOT TRAP: `local.field` PASSES, THE SAME READ THROUGH A POINTER LOCAL IS REFUSED <sub>L21804</sub>
- **§204-E** — `decl_prior`'s `%hi/%lo` ARM HAS NEVER FIRED: the card's promised GLOBAL-TYPE row is 0 of 1,210 <sub>L21879</sub>
- **§204-CONFIRMED** — 30 reports that the index already answered <sub>L21931</sub>
- **§204-REJECTED** — sixteen, twice the previous record <sub>L22025</sub>
- **§205** — THE CHAINED ASSIGNMENT IS ITS OWN SCHEDULING DIAL: `*b = *a = v;` moves an argument copy that no local, no pin and no statement reorder will move (P31 S56) <sub>L22098</sub>
- **§206** — THE JTBL-CARVE DRAFTING IDIOM: the bounds check is the entry count, and an EMPTY case owns a slot (P31 S56) <sub>L22153</sub>
- **§207** — THE WAVE ab–ag HARVEST (P31 S58): 278 byte-banked notes → 25 laws, 103 self-reported no-gap <sub>L22222</sub>
- **§208** — TWO NAMED LOCALS FOR ONE RELOADED EXPRESSION BUY TWO ALLOCNOS — the naming granularity owns the REGISTER SPLIT, not just the load count (P31 S58) <sub>L22243</sub>
- **§209** — THE NARROW LOCAL IS A DIAL IN TWO OPPOSITE DIRECTIONS, AND §194-B's "≥2 `sh` STORES" BOUND IS BYTE-WRONG (P31 S58) <sub>L22292</sub>
- **§210** — THE SINGLE-BIT MASK IN A BOOLEAN TAIL: `andi K ; sltu $zero,v` vs `srl n ; andi 1` is a STATEMENT-SHAPE dial, not an operator choice (P31 S58) <sub>L22369</sub>
- **§211** — HOIST THE LOOP INIT ABOVE THE DOMINATING GUARD: it fills the guard's delay slot AND flips the counter/pointer register pair (P31 S58) <sub>L22415</sub>
- **§212** — THE WALKING CURSOR IS COUNTABLE: `*wp++` emits one `addiu` PER STORE, `wp[0..2]` emits one (P31 S58) <sub>L22474</sub>
- **§213** — INDEPENDENT SAME-BASE STORES: THE EMISSION ORDER IS A PERMUTATION OF SOURCE ORDER, AND THE PERMUTATION IS NOT ALWAYS THE IDENTITY (P31 S58) <sub>L22519</sub>
- **§214** — THE BANKED TWIN MAY BE A MACRO, A DELETED `.s`, OR A SEMANTIC INVERSE — six ways a ≥0.9 similarity lies (P31 S58) <sub>L22555</sub>
- **§215** — PIN ECONOMY: the twin's pins are NOT part of the shape, and §17's "pin every call-crossing value" is over-broad (P31 S58) <sub>L22601</sub>
- **§216** — DISTINCT ADJACENT SCALARS vs ONE ARRAY: one `lui` per access is the tell, and the array decl is UNUSABLE (P31 S58) <sub>L22657</sub>
- **§217** — DECODING A CALL'S STACK ARGUMENT SLOTS: `sw` at `0x10`/`0x14`/`0x18` are params 5/6/7 **(single observation — not yet cross-confirmed)** (P31 S58) <sub>L22697</sub>
- **§218** — A NARROW TYPE AT THE ABI BOUNDARY COSTS AN IN-PLACE `sll/sra` PAIR — on the RETURN as well as on the PARAMETER (P31 S58) <sub>L22723</sub>
- **§219** — COMPOUND `+=`, FULL ASSIGNMENT, AND AN EXPLICIT TEMP ARE THREE DIFFERENT SCHEDULES OF ONE READ-MODIFY-WRITE (P31 S58) <sub>L22752</sub>
- **§220** — THE PARAMETER ITSELF IS A REGALLOC DIAL: use it directly, prefer `s32` to `void*`, and place the save-copy AFTER the first call (P31 S58) <sub>L22779</sub>
- **§221** — A CONSTANT SHARED BY TWO STORES DIES AT THE CALL WHOSE DELAY SLOT REFILLS ITS REGISTER **(single observation — not yet cross-confirmed)** (P31 S58) <sub>L22819</sub>
- **§222** — SWITCH vs IF-CHAIN, PART 3: source arm order IS emission order, a leading EMPTY case buys the median split, and a 2-way dispatch with a shared post-block is a `switch` (P31 S58) <sub>L22835</sub>
- **§223** — READING A `jal` DELAY SLOT: the value in it was produced BEFORE the call, so it is NEVER that call's return (P31 S58) <sub>L22877</sub>
- **§224** — CROSS-JUMP: WRITE THE DUPLICATE, AND READ A SHARED DELAY SLOT AS THE MERGE SIGNATURE (P31 S58) <sub>L22939</sub>
- **§225** — THREE CONTROL-FLOW SHAPES NO STRUCTURED SPELLING REACHES (P31 S58) <sub>L22975</sub>
- **§226** — FRAME PADS: FOUR WAYS §162i1/§2429's DEAD-LOCAL LEVER MISFIRES (P31 S58) <sub>L23018</sub>
- **§227** — TYPE THE SOURCE BY THE **LOAD** WIDTH, NOT BY THE STORE WIDTH (P31 S58) <sub>L23059</sub>
- **§228** — READING THE DIVIDE, PART N: the off-by-one compare is `% K == 1`, and three more discriminators (P31 S58) <sub>L23079</sub>
- **§229** — THE ADDRESS IS A VALUE: NAMING IT MOVES THE `lui`/`addiu` PAIR — AND §L14410 SAYS THE OPPOSITE FOR A REASON (P31 S58) <sub>L23116</sub>
- **§230** — THE ANCHOR PROBE: with `%hi`/`%lo` masked, the surviving `addiu` deltas tell you which assignment was written first **(single observation — not yet cross-confirmed)** (P31 S58) <sub>L23165</sub>
- **§231** — TRANSCRIPTION AND SEMANTIC-READ HYGIENE: six ways the listing misleads (P31 S58) <sub>L23180</sub>
- **§232** — WHEN THE `jr` DELAY SLOT'S STORE STORES THE RETURN VALUE, TIE THEM WITH ONE PSEUDO **(single observation — not yet cross-confirmed)** (P31 S58) <sub>L23221</sub>
- **§30** — addendum (P31 S58) — the `/s` grant closes a SCHEDULING residual and a REGISTER residual with one edit <sub>L23257</sub>
- **§194-B** — addendum (P31 S58) — BOUND 2 is byte-wrong; see §209 Direction A <sub>L23277</sub>
- **§176-B** — addendum (P31 S58) — the misdiagnosis direction <sub>L23283</sub>
- **§165-40** — addendum (P31 S58) — the barrier goes at the COPY SITE, not inside the region it protects <sub>L23289</sub>
- **§164-63** — addendum (P31 S58) — the interposed asm works when the SECOND value is an ordinary assignment <sub>L23298</sub>
- **§193-A** — / §194-E addendum (P31 S58) — where the twin's body actually lives <sub>L23307</sub>
- **§233** — THE WAVE aa–bg HARVEST (P31 S58b): 1,101 byte-banked notes → 24 new laws, 21 addenda, ~700 already-covered <sub>L23313</sub>
- **§234** — CONSTANT MATERIALISATION: THE STORE LVALUE'S SIGNEDNESS PICKS `addiu` vs `li`/`ori` (P31 S58b) <sub>L23357</sub>
- **§235** — THE PHANTOM SYMBOL: A MASKED `MATCH` CAN CARRY A RELOCATION THAT DOES NOT EXIST (P31 S58b) <sub>L23398</sub>
- **§236** — THE DECLARATION LAYER IS THE DOMINANT BANK-BLOCKER: NINE WAYS A BYTE-PERFECT BODY FAILS THE GATE (P31 S58b) <sub>L23427</sub>
- **§237** — THE CAST-AT-CALL-SITE DECISION TABLE: WHAT §17a-1 FIXES, WHAT IT CANNOT, AND THE FOUR ESCAPES (P31 S58b) <sub>L23506</sub>
- **§238** — SAME NAME, DIFFERENT FUNCTION: THE OVERLAY-HOMONYM TRAP (P31 S58b) <sub>L23561</sub>
- **§239** — TWO-STATEMENT INTEGER-SPACE MATERIALISATION REORDERS `la` vs `sll`; AND THE PLUS-TREE OPERAND ORDER (P31 S58b) <sub>L23601</sub>
- **§240** — `A + K + B`: WRITE THE CONSTANT **BETWEEN** THE TWO RUNTIME TERMS (P31 S58b) <sub>L23635</sub>
- **§241** — THE FOLDED SIGN-EXTEND-AND-SCALE: `sll 16 ; sra (16 − log2 scale)` (P31 S58b) <sub>L23664</sub>
- **§242** — `*k` vs `<<n`, AND `/2^n` vs `>>n`: EXPRESSION SPELLING OWNS THE LOAD WIDTH AND THE ROUNDING CHAIN (P31 S58b) <sub>L23693</sub>
- **§243** — SPELL THE CSE BARRIER AS A REASSIGNED POINTER; AND THE `nop`-AFTER-EVERY-`lh` SIGNATURE (P31 S58b) <sub>L23721</sub>
- **§244** — `volatile` IS A COUNTING INSTRUMENT, A STORE-ORDER PIN, AND MUST SOMETIMES BE ASYMMETRIC (P31 S58b) <sub>L23751</sub>
- **§245** — THE CALL'S ARGUMENT LIST IS A SCHEDULING SLOT (P31 S58b) <sub>L23786</sub>
- **§246** — THREE-LIVE-VALUE SCAN LOOPS WANT ADDRESS-FROM-INDEX; AND TWO SYMBOLS CAN SHARE ONE giv (P31 S58b) <sub>L23833</sub>
- **§247** — TWO BRANCHES TO **ONE** LABEL MEANS THE SOURCE CONDITION IS NEGATED (P31 S58b) <sub>L23873</sub>
- **§248** — SPLIT THE LOAD FROM THE ARITHMETIC: A FUSED `g + K` DENIES THE CALLEE-SAVED REGISTER ITS DIRECT HOME (P31 S58b) <sub>L23907</sub>
- **§249** — THE SELF-ASSIGN, THE DEAD RE-ASSIGN, AND THE `+ zr` COPY: THREE WAYS TO MAKE A DELETED INSTRUCTION REAL (P31 S58b) <sub>L23931</sub>
- **§250** — `%hi/%lo` vs `lw`: THE EXTERN'S ARRAY-vs-SCALAR SHAPE DECIDES ADDRESS MATERIALISATION (P31 S58b) <sub>L23973</sub>
- **§251** — IMMEDIATE-SPELLING TRIGGERS: `+= 0xFF`, FULL-WIDTH `~K`, AND THE TWO-OR SPLIT (P31 S58b) <sub>L24010</sub>
- **§252** — THE GUARDED PRE-DECREMENT: `(x != 0) && (--x == 0)` (P31 S58b) <sub>L24032</sub>
- **§253** — POSTFIX `++` vs `+= 1` PICKS A DIFFERENT SCRATCH REGISTER **(single observation — not yet cross-confirmed)** (P31 S58b) <sub>L24053</sub>
- **§254** — THE DEAD PARAMETER IS A REGISTER-PLACEMENT TOOL **(single observation — not yet cross-confirmed)** (P31 S58b) <sub>L24067</sub>
- **§255** — THE EMPTY CASE, PART 2: FOUR TREE SHAPES IT BUYS (P31 S58b) <sub>L24079</sub>
- **§256** — GOTOS IN THE TARGET'S BLOCK ORDER REPRODUCE SWITCH PLACEMENT WITHOUT SWITCH'S SIDE EFFECTS (P31 S58b) <sub>L24114</sub>
- **§257** — THE DEAD-END LEDGER (P31 S58b): ELEVEN LEVERS THAT MEASURED NULL OR BACKFIRED <sub>L24151</sub>
- **§258** — ADDENDA TO EXISTING SECTIONS (P31 S58b) <sub>L24194</sub>
- **§30** — addendum (P31 S58b) — THE ANONYMOUS STRUCT MEMBER REF GRANTS `/s`, AND THAT IS A TWO-FOR-ONE <sub>L24199</sub>
- **§194-B** — / §209 addendum (P31 S58b) — TWO MORE INSTANCES, AND THE BOUND IS NOW REFUTED FOUR WAYS <sub>L24220</sub>
- **§202** — addendum (P31 S58b) — THE DEF-SIDE ALIAS ALSO CLEARS A RETURN+PARAM DOUBLE CONFLICT <sub>L24243</sub>
- **§205** — addendum (P31 S58b) — CHAINED ASSIGNMENT: N≥3 IS INNERMOST-FIRST, AND THE TEXT MIRRORS EMISSION <sub>L24254</sub>
- **§208** — addendum (P31 S58b) — IT SCALES TO SIX SITES, AND IT HAS AN EXACT INVERSE <sub>L24271</sub>
- **§210** — addendum (P31 S58b) — THREE CONFIRMED SPELLINGS OF THE BOOLEAN TAIL <sub>L24300</sub>
- **§211** — addendum (P31 S58b) — INIT PLACEMENT: FIVE MORE DIALS BEYOND THE GUARD HOIST <sub>L24316</sub>
- **§213** — addendum (P31 S58b) — THREE MORE PERMUTATION LAWS FOR INDEPENDENT SAME-BASE STORES <sub>L24359</sub>
- **§214** — addendum (P31 S58b) — FOUR MORE WAYS A HIGH-SIMILARITY TWIN LIES <sub>L24388</sub>
- **§215** — addendum (P31 S58b) — PIN ECONOMY, PART 2: NINE REFINEMENTS <sub>L24424</sub>
- **§217** — CROSS-CONFIRMED (P31 S58b) — AND THE INCOMING HOME SLOT IS THE MIRROR <sub>L24476</sub>
- **§220** — addendum (P31 S58b) — THE PARAMETER, NOT A COPY (SEVEN CARDS) <sub>L24493</sub>
- **§222** — addendum (P31 S58b) — IF-CHAIN vs SWITCH: THREE MORE DISCRIMINATORS <sub>L24518</sub>
- **§223** — addendum (P31 S58b) — FIVE MORE CONFIRMATIONS, AND THE CONSTANT-IN-`$v0` CASE <sub>L24536</sub>
- **§224** — addendum (P31 S58b) — CROSS-JUMP MERGES *CALLS*, AND THE DELAY SLOT IS THE DISCRIMINATOR <sub>L24560</sub>
- **§225** — addendum (P31 S58b) — THE GUARD-CLAUSE FINGERPRINT, AND THREE MORE SHAPES <sub>L24590</sub>
- **§226** — addendum (P31 S58b) — THE FRAME CATALOGUE: SEVEN MORE LEVERS, AND SLOT ORDER IS DECLARATION ORDER <sub>L24617</sub>
- **§229** — addendum (P31 S58b) — NAME IT **INSIDE** THE ARM <sub>L24662</sub>
- **§230** — CROSS-CONFIRMED (P31 S58b) <sub>L24673</sub>
- **§231** — addendum (P31 S58b) — FOUR MORE WAYS THE LISTING MISLEADS <sub>L24682</sub>
- **§232** — CROSS-CONFIRMED (P31 S58b) <sub>L24713</sub>
- **§259** — THE DISCARD LEDGER FOR THE aa–bg HARVEST (P31 S58b): WHAT WAS MINED AND REJECTED, AND WHY <sub>L24724</sub>
- **§260** — THE §154-A LEADING-ISLAND SPLIT: ONE CONFIG LINE, AND THE ISLAND PEELS FROM THE END (P31 S59, byte-proven) <sub>L24763</sub>
- **§260-A** — STAGE 2 IS PROVEN, AND THE WHOLE jtbl PIPELINE IS AUTOMATED AT THE GATE (P31 S59, same day) <sub>L24813</sub>
- **§261** — THE -O0 ORACLE: DERIVE THE OPT LEVEL FROM THE TARGET, AND `$fp` IS NOT THE TELL (P31 S59) <sub>L24849</sub>
- **§261a** — THE -O0 FRAME-RELOAD GRAMMAR: reload COUNT disambiguates the C spelling (P31 S59, byte-proven) <sub>L24875</sub>
- **§262** — A LANE'S YIELD IS ONLY A LANE FACT IF IT IS SIZE-MATCHED (P31 S59) <sub>L24897</sub>
- **§263** — A STOLEN DELAY SLOT WHOSE INSTRUCTION IS AN ARG-REGISTER COPY IS AN ARITY ERROR, NOT A SCHEDULE (P31 S59, byte-proven) <sub>L24927</sub>
- **§264** — FOUR TELLS-LANE C RECIPES, EACH DRIVEN TO MATCH (P31 S59) <sub>L24968</sub>
- **§265** — THE VERBATIM-ASM BANK LANE: A FUNCTION NO -O2 C CAN EVER MATCH BANKS AS A RAW `__asm__` BODY (P31 S59b; two banked cards, two in-tree precedents) <sub>L25018</sub>
- **§266** — THE INERT-RIDER LAW: A LEVER IS ONLY CITABLE WHEN ITS SOLO REMOVAL BREAKS THE MATCH (P31 S59b; measured 4-of-8 on this batch) <sub>L25080</sub>
- **§267** — ADDENDA HARVESTED FROM WAVES at/bh/bk/bl (P31 S59b) <sub>L25120</sub>
- **ADD-1** — → §231 addendum (also cross-ref from §195-D) — THE MASKED-`jal` "MISSING CALL" ILLUSION <sub>L25128</sub>
- **ADD-2** — → §42a addendum — A SHARED CONSTANT *NAMED IN A LOCAL* ACROSS A `jal` IS AN ISO→TU DRIFT HAZARD; WRITE BARE LITERALS <sub>L25137</sub>
- **ADD-3** — → §236, item 10 — THE UN-DELETED `INCLUDE_ASM` STUB IS A DUPLICATE DEFINITION <sub>L25149</sub>
- **ADD-4** — → §225-3/-4 addendum — THE MIRROR ROW: VALUE-RETURN IN THE *TAKEN* ARM + TRAILING BARE `return 0` <sub>L25159</sub>
- **ADD-5** — → §1/I1 addendum — THE INVERTED RANGE TEST: `(u32)(x-lo) >= N` WITH THE ZERO-ARM AS THE TRAILING `else` <sub>L25173</sub>
- **ADD-6** — → §172b-1 / §264 addendum — SHIFT-AS-TEST: `(x << 16) != 0` TESTS THE LOW HALF WITHOUT TRUNCATING THE PSEUDO <sub>L25182</sub>
- **ADD-7** — → §256 addendum — THE SINGLE-GUARD GOTO: THEN-BLOCK OUT OF LINE AT THE TAIL <sub>L25191</sub>
- **ADD-8** — → §245 addendum — THE RE-TIE BARRIER PINS CALL-ARG SETUP TO SOURCE ORDER (construct 6) <sub>L25203</sub>
- **ADD-9** — → §213-3 / §217 addendum — ADJACENT PRE-CALL FRAME STORES ARE ONE AGGREGATE; THE UNESCAPED SCALAR NEIGHBOR IS DEAD-STORED <sub>L25215</sub>
- **ADD-10** — → §237 addendum (arity-evidence paragraph) — AN `la` PAIR ABOVE THE PROLOGUE `sw $ra` IS AN OUTGOING-ARGUMENT MATERIALISATION <sub>L25225</sub>
- **ADD-11** — → Cross-confirmation card block (per §259's standing instruction: confirmation, not news) <sub>L25234</sub>
- **§268** — A `register __asm__` PIN ON A CALL-CLOBBERED REGISTER IS HONORED EXACTLY WHEN THE PINNED RANGE CROSSES NO CALL (P31 S59c; three A/B'd cards, unifying §257-2's two) <sub>L25285</sub>
- **§269** — ADDENDA HARVESTED FROM WAVES ax/bm (P31 S59c) <sub>L25339</sub>
- **ADD-1** — → §257-8 addendum — THE INTERPOSED ASM'S `__volatile__` IS A PER-SHAPE DIAL, AND THE "NO-OUTPUT ASM IS IMPLICITLY VOLATILE" LORE IS BYTE-FALSE IN gcc-2.7.2 <sub>L25354</sub>
- **ADD-2** — → §236 addendum (item 1 corollary) — THE SILENT-SPLICE DECLARATION LADDER: WHERE THE TU HAS NO SPELLING, UNPROTOTYPED `()` BEATS THE FLEET VOTE <sub>L25367</sub>
- **ADD-3** — → §238 addendum — TWO BINARIES CAN EACH DEFINE THE SAME `func_` NAME WITH DIFFERENT BYTES, AND NO GENERATED REPORT SHOWS IT <sub>L25381</sub>
- **ADD-4** — → §167-37 addendum — THE FIFTH PRECONDITION, NOW MEASURED: DOWNSTREAM FIELD RE-READS ⇒ NAME IT **AND** STORE **INSIDE** THE ARM <sub>L25394</sub>
- **ADD-5** — → §267-ADD-6 / §172b-1 addendum — THE SIGN-TEST FACE: `(s16)v < 0` IS `sll 16` + `bgez` ON THE SHIFTED COPY, RAW STAYS LIVE — AND THE HALFWORD-ABS SHAPE NEEDS NO RITUAL <sub>L25411</sub>
- **ADD-6** — → §220-addendum — THE FOURTH FACE: WHEN THE NAMED COPY ITSELF BUYS THE EXTRA CALLEE-SAVED, PIN THE COPY TO `$16` <sub>L25427</sub>
- **ADD-7** — → §229 addendum — THE VALUE FACE: A LOOP-STORE CONSTANT SPELLED AS A LITERAL HAS NO SOURCE POSITION; NAME IT TO PIN THE PROLOGUE INIT ORDER <sub>L25443</sub>
- **ADD-8** — → §30a addendum — THE THIRD COLUMN: `*p++` IS ALSO SERIALIZED BUT BURNS `addiu`; ONLY CAST-PLUS GIVES SERIALIZATION *AND* DISPLACEMENT FOLDING <sub>L25456</sub>
- **ADD-9** — → §255 "AND CASE-BODY PLACEMENT" bound / §222-addendum-3 — ON A LARGE SPARSE TREE, BODIES FOLLOW **SOURCE** ORDER (measured by a one-word probe) <sub>L25471</sub>
- **ADD-10** — → Cross-confirmation card block (per §259's standing instruction: confirmation, not news) <sub>L25485</sub>
- **§3-1a.** — The §266 sweep — every solo-lever A/B run for this batch <sub>L25526</sub>
- **§270** — The A-prop 0-bank anatomy: a byte-correct body still needs FOUR layers to agree (P31 S59) <sub>L25559</sub>
- **§271** — Ordinal IMM pairing: text order is NOT emission order; emit CANDIDATES, let the oracle pick (P31 S59) <sub>L25577</sub>
- **§272** — The `(void)`-decl + empty-call wall: K&R the DEFINITION, not just the decls (P31 S59) <sub>L25599</sub>
- **§273** — A standalone compile is the WRONG oracle for a TU-destined draft (P31 S59) <sub>L25619</sub>
- **§274** — ADDENDA HARVESTED FROM 18 WAVES (P31 S60): 315 candidates, 255 already covered, 21 sharpenings, 3 new laws <sub>L25634</sub>
- **ADDENDUM** — to §179-C — the `.type NAME, @function` requirement <sub>L25640</sub>
- **ADDENDUM** — to §134 — a typedef defined BELOW the splice point is stripped anyway <sub>L25687</sub>
- **ADDENDUM** — to §179-D (GTE macro reference family) — `gte_SetRotMatrix`/`gte_SetTransMatrix` bodies <sub>L25717</sub>
- **ADDENDUM** — to §82 — struct copies must stay MEMBER-WISE, not block-moved, to match a spill-slot save <sub>L25743</sub>
- **ADDENDUM** — to §136d-1 (RC-12, the `$0`-add / opaque-copy family) — two symptoms beyond "compare reads the wrong register" <sub>L25781</sub>
- **ADDENDUM** — to §20 — a global declared as `T *` may itself BE the array base, not a pointer to dereference <sub>L25820</sub>
- **ADDENDUM** — to §1-I5 <sub>L25849</sub>
- **ADDENDUM** — to §164-51 <sub>L25914</sub>
- **ADDENDUM** — to §176-F5 <sub>L25930</sub>
- **ADDENDUM** — to §225 <sub>L25959</sub>
- **ADDENDUM** — to §224 — CROSS-JUMP: THE DUPLICATE CAN BE A PLAIN STORE, NOT ONLY A CALL <sub>L26004</sub>
- **ADDENDUM** — to §164-64 — AN EMPTY CLOBBER ON AN ARGUMENT REGISTER CAN BE THE DELIBERATE FIX, NOT JUST THE ACCIDENTAL BUG <sub>L26038</sub>
- **ADDENDUM** — to §244 — THE COMPILER BARRIER, NOT `volatile`, BLOCKS A STORE→LOAD HOIST THROUGH A POINTER-OFFSET FIELD <sub>L26069</sub>
- **ADDENDUM** — to §172b-1 — TWO PLACEMENT DIALS THE PROMOTION LAW DOESN'T NAME: NARROW THE COUNTER'S DECLARED TYPE, AND MOVE THE CAST INTO THE LOOP BODY <sub>L26100</sub>
- **ADDENDUM** — to §229 — A POINTER'S NUMBER OF USES DECIDES WHETHER ITS ADDRESS FOLDS OR SURVIVES A CALL <sub>L26147</sub>
- **ADDENDUM** — to §172b-4 — THE PLAIN CAST-DIVISION ALREADY PRODUCES THE PATTERN; DON'T HAND-ROLL THE BIAS, AND KEEP THE OPERAND WIDE <sub>L26192</sub>
- **ADDENDUM** — to §8 — WHEN `INCLUDE_RODATA` NEEDS A STANDALONE `.s` YOU CAN'T CREATE, CARRY THE FRAGMENT AS A FILE-SCOPE `__asm__` BLOB <sub>L26222</sub>
- **ADDENDUM** — to §226 — A DEAD LOCAL SCOPED TO A NESTED BLOCK BUYS A MID-FUNCTION `addiu sp` PAIR, NOT A FRAME-SIZE CHANGE <sub>L26265</sub>
- **ADDENDUM** — to §172a — RE-READING MEMORY (NOT NAMING A TEMP) IS WHAT KEEPS AN INCREMENT'S DELAY-SLOT FILL ALIVE <sub>L26304</sub>
- **ADDENDUM** — to §225 / §256 — A GOTO TO A SHARED SET-POINT PREVENTS IF-CONVERSION FROM COLLAPSING A LATER BRANCH TEST <sub>L26335</sub>
- **ADDENDUM** — to §211 — AN IN-LOOP ACCUMULATOR WANTS A CLOSED-FORM EXPRESSION WHEN THE TARGET REMATERIALISES ITS CONSTANT AFTER EVERY CALL <sub>L26377</sub>
- **§275** — THE LEFTOVER-REGISTER READ <sub>L26412</sub>
- **§276** — MIXED ADDRESS-EXPRESSION SPELLING FOR ADJACENT RELOCATABLE SYMBOLS IS A CSE-UNIFICATION DIAL, NOT JUST A BYTE-ENCODING CHOICE (P31 S60; `func_80180FE8`, ov_SC06_006, byte-proven) <sub>L26452</sub>
- **§277** — RETURN-TAIL C SPELLING PICKS THE DELAY-SLOT-FILL vs TRAILING-MOVE TOPOLOGY, AND A NARROWER SECOND VARIABLE KEEPS TWO PSEUDOS INSTEAD OF ONE (P31 S60; `func_801846F0` ov_SC03_104, `func_801A44C4` md_SC07_004, both byte-proven) <sub>L26561</sub>
- **§278** — ADDENDA HARVESTED FROM WAVE cf (P31 S60): 34 candidates, 13 already covered, 8 sharpenings, 4 new laws <sub>L26625</sub>
- **ADDENDUM** — to §74 (func_800D0E30, resident) <sub>L26633</sub>
- **ADDENDUM** — to §172b-4 (func_80185054, ov_SC03_097) <sub>L26669</sub>
- **ADDENDUM** — to §265 (func_8017DC80, ov_SC07_002) <sub>L26707</sub>
- **ADDENDUM** — to §17 (func_800CB794, md_MAIN_036) <sub>L26746</sub>
- **ADDENDUM** — to §162p (func_8017C120, ov_MAIN_012) <sub>L26794</sub>
- **ADDENDUM** — to §20 (~L1947) (func_80186AD0, ov_SC06_032) <sub>L26828</sub>
- **ADDENDUM** — to §164-56 (func_8017F644, ov_SC04_005) <sub>L26858</sub>
- **ADDENDUM** — to §237 (func_8017F7FC, ov_SC03_092) <sub>L26893</sub>
- **§279** — A `do/while (p < end)` LOOP UNDER AN ENTRY GUARD: the guard decides the compare, not the loop (P31 S60; wave cf, func_8017F2A4, ov_SC03_096, byte-proven) <sub>L26922</sub>
- **§NNN** — A DO-WHILE'S GUARD AND LATCH MUST REPEAT THE SAME BOUND EXPRESSION, NOT SHARE ONE LOCAL: THE REPETITION IS WHAT BUYS THE CSE'D COPY INTO A SECOND REGISTER (P31 S60; `func_8017F2A4`, ov_SC03_096, byte-proven 25/25) <sub>L26923</sub>
- **§280** — THE CURSOR'S DECLARED TYPE PICKS `sltu` vs `slt`: a `T*` bound test is UNSIGNED by C rule, an integer cursor is signed (P31 S60; wave cf, func_800CAE74, md_MAIN_031, byte-proven) <sub>L26956</sub>
- **§NNN** — A LOOP CURSOR'S C TYPE (POINTER vs PLAIN INTEGER) SELECTS `sltu` vs `slt` FOR ITS BOUND TEST, INDEPENDENT OF THE VALUES INVOLVED (P31 S60; `func_800CAE74`, md_MAIN_031, byte-proven; cross-confirmed same wave by `func_8017F2A4`, ov_SC03_096) <sub>L26957</sub>
- **§281** — GROUP COPY-THEN-RMW BY OPERATION KIND, NOT FIELD BY FIELD: sched1 does the interleaving, the source must not (P31 S60; wave cf, func_80180FB4, ov_SC03_111, byte-proven) <sub>L26990</sub>
- **§NNN** — A DEPENDENT COPY-THEN-RMW BLOCK MUST BE SOURCE-GROUPED BY OPERATION KIND, NOT BY FIELD, AND SCHED1 DOES THE INTERLEAVING (P31 S60; `func_80180FB4`, ov_SC03_111, byte-proven) <sub>L26991</sub>
- **§282** — gcc's OWN LOOP REVERSAL PUTS THE COUNTER INIT AFTER THE HOISTED MOVABLES — a position no hand-written down-count can reach (P31 S60; wave cf, func_80180DD8, ov_SC04_005, byte-proven) <sub>L27036</sub>
- **§NNN** — WRITE THE UP-COUNT LOOP: gcc's OWN REVERSAL PRODUCES A COUNTER-INIT INSTRUCTION THAT LANDS AFTER HOISTED MOVABLES, WHICH A HAND-WRITTEN DOWN-COUNT LOOP CANNOT REPRODUCE (P31 S60; `func_80180DD8`, ov_SC04_005, byte-proven) <sub>L27037</sub>
- **What** — I could not verify <sub>L27074</sub>
- **§283** — ADDENDA HARVESTED FROM THE 36-WAVE BATCH (P31 S60): 1,216 candidates, 859 already covered, 46 sharpenings, 9 new laws <sub>L27121</sub>
- **ADDENDUM** — to §164-75 — the fold-reassociation law also fires at a variable's INITIALIZER, not only a later expression <sub>L27131</sub>
- **ADDENDUM** — to §21 — the `bltz`+`slti` (or N-separate-compares) signed-range-split bullet is now CONFIRMED on three independent functions, and generalizes beyond `lbu`/u8 <sub>L27157</sub>
- **ADDENDUM** — to §202 — the DEF-SIDE ALIAS also resolves a function-vs-DATA-symbol identifier clash, not only a function-vs-function prototype clash <sub>L27203</sub>
- **ADDENDUM** — to §22 (`volatile`-qualified-global reload lever, cookbook ~L1922) — for a NON-constant, same-address double RMW, a plain memory clobber beats `volatile`, and `volatile` actively breaks a delay-slot fill <sub>L27226</sub>
- **ADDENDUM** — to §195-E — a goto-ladder's STORES must sit AT the labels, after the gotos, not inline before them <sub>L27245</sub>
- **ADDENDUM** — to §195-N — a GNU statement-expression slider must sit INSIDE the conditional arm's value position, not as a post-hoc barrier, to block the store-flag transform on a ternary chain <sub>L27307</sub>
- **ADDENDUM** — to §176-B2 — in a micro-function with no long/short lifetime asymmetry, BOTH contending pseudos need their own hard-register pin <sub>L27364</sub>
- **ADDENDUM** — to §199-G — A `default:` LABEL GROUPED ONTO THE LAST CASE REMOVES THE `j default` TAIL, EVEN THOUGH THE 2-NODE HEADER STAYS ALL-POSITIVE <sub>L27411</sub>
- **ADDENDUM** — to §220 — REFERENCING THE RAW PARAMETER (NO NAMED COPY, NOT EVEN A PIN) LETS THE CALLEE-SAVED SPILL LAND IN THE FIRST CALL'S OWN DELAY SLOT <sub>L27480</sub>
- **ADDENDUM** — to §252 — a `>=0`/`<0` split on an unconditionally-decremented value needs the POSTFIX operator INSIDE the branch condition, not a prior statement <sub>L27538</sub>
- **ADDENDUM** — to §215 — FIFTH SHAPE: reused mask constants across two call-free merge sites each get their own whole-function hard-register pin, and a shared sub-expression at the second site must be its own statement <sub>L27565</sub>
- **What** — I could not verify <sub>L27648</sub>
- **Harness-defect** — flags <sub>L27719</sub>
- **ADDENDUM** — to §167-40 (func_8017E2CC, ov_SC04_015 — wave dg) <sub>L27812</sub>
- **ADDENDUM** — to §20's cross-jump EXPLOIT bullet (func_8017E360, ov_SC05_007 — wave dg) <sub>L27832</sub>
- **ADDENDUM** — to §87 (func_801815F4 ov_SC06_032; corroborating func_801840DC ov_SC05_017, func_80189C68 ov_SC03_006 — wave dg) <sub>L27846</sub>
- **ADDENDUM** — to §153 / §236-5 (func_801A419C, md_SC07_003 — waves di and dl, corroborating; refutes a contradicted dj-wave card) <sub>L27865</sub>
- **ADDENDUM** — to §263 (func_801E83AC, md_SC04_029 — wave dj) <sub>L27885</sub>
- **ADDENDUM** — to §265 (func_8017D878, ov_SC03_107 — wave dj; corroborated by a REJECTED, contradicted card in wave dm — see closing) <sub>L27899</sub>
- **ADDENDUM** — to §6 (func_801811F0, ov_SC03_102 — waves dj and dl, corroborated by a self-reported "nothing new" dm-wave card) <sub>L27913</sub>
- **ADDENDUM** — to §195-G (func_80183BB0, ov_SC05_001 — wave dj) <sub>L27927</sub>
- **ADDENDUM** — to the zero-byte-asm-slider family (§47 / §148-C / §153) (func_800CB874, md_MAIN_040 — wave dj; open tension with a more cautious dm-wave card — see closing) <sub>L27955</sub>
- **ADDENDUM** — to §194-B (func_8017EB34, ov_SC03_117 — wave dk; distinct from the §74 co-pinning finding on the SAME function below) <sub>L27973</sub>
- **ADDENDUM** — to §74 (func_8017EB34, ov_SC03_117 — counter/clamp variant; wave dj, corroborated by dk/dl/dm cards on the same function) <sub>L28005</sub>
- **ADDENDUM** — §37 — merged into the §153/§236-5 entry above (func_801A419C, wave dl) <sub>L28025</sub>
- **ADDENDUM** — §6 — merged into the §6 entry above (func_801811F0, wave dl) <sub>L28033</sub>
- **ADDENDUM** — to §238 (func_80182CB4, ov_SC02_000 — wave dl) <sub>L28041</sub>
- **ADDENDUM** — to §137a (func_801684B4, ov_MAIN_012; corroborated independently by func_80189E68, func_8017FF9C, func_801822B4, func_8018DA8C — wave dl) <sub>L28059</sub>
- **ADDENDUM** — to §8c / §88d (func_8016AB6C, ov_MAIN_012 — wave dm) <sub>L28075</sub>
- **ADDENDUM** — to §73 / §30#2 (func_800D1984, resident — wave dm) <sub>L28089</sub>
- **What** — I could not verify <sub>L28105</sub>
- **ADDENDUM** — to §174 Law 4 (func_8017E9A8, ov_SC06_015) <sub>L28125</sub>
- **ADDENDUM** — the zero-emission-asm family gains a REF-SLIDER PLACEMENT LAW and a paired RESTORER (func_800CB900, md_MAIN_026) <sub>L28165</sub>
- **From** — ck + cl + cm <sub>L28217</sub>
- **ADDENDUM** — §NNN — sharpens §55a / §164-37 / §165-28 (switch-vs-tree cluster): A SHAPE THAT LOOKS LIKE A SWITCH DISPATCH CAN BE PLAIN NESTED `if`s WHOSE SHARED BODY WAS TRIPLICATED BY THE SOURCE AND THEN CROSS-JUMP-MERGED BACK DOWN <sub>L28223</sub>
- **ADDENDUM** — §NNN — sharpens §167-13's boundary: CHAINING TWO IDENTICAL SIDE-BY-SIDE STORES INTO ONE C ASSIGNMENT STATEMENT IS A MID-BLOCK SCHEDULING-PRIORITY DIAL, NOT ONLY A STORE-ORDER SPELLING <sub>L28260</sub>
- **ADDENDUM** — §NNN — sharpens §162a3/§60b: A `sll $v0,16 / sltiu $v0,1` ZERO-TEST OF A JUST-DECREMENTED HALFWORD IS A SIGNED-TEMP WIDTH TELL OUTSIDE ANY SWITCH/RANGE-TEST CONTEXT <sub>L28293</sub>
- **ADDENDUM** — §NNN — sharpens §37/§124 (unspecified-parameter-list family): DERIVE A CALLEE'S ARITY LOWER BOUND FROM ITS OWN `.s` STACK-ARGUMENT READS, NOT FROM ANY SINGLE CALL SITE <sub>L28326</sub>
- **ADDENDUM** — to §5a (func_80181F74, ov_SC03_112, wave cn) <sub>L28359</sub>
- **ADDENDUM** — to §265 (func_8017E26C, ov_SC04_016, wave cn) <sub>L28409</sub>
- **ADDENDUM** — to §42b (func_8018247C, ov_SC07_002, waves cu + cw) <sub>L28447</sub>
- **ADDENDUM** — to §199-F family (func_8017EFB0, ov_SC02_021, wave cu) <sub>L28478</sub>
- **ADDENDUM** — to §195-E (func_800CFC1C, md_MAIN_003, wave cv) <sub>L28533</sub>
- **ADDENDUM** — to §215 addendum (func_800CB2C8, md_MAIN_033, waves cv + cw) <sub>L28578</sub>
- **ADDENDUM** — to §236 item 4 (func_8017D268, ov_SC04_006, wave cw) <sub>L28634</sub>
- **What** — I could not verify <sub>L28663</sub>
- **Harness-defect** — flags (not idioms — flagged for the operator) <sub>L28695</sub>
- **ADDENDUM** — to §250 (func_8017D7CC, ov_SC03_115 — cx/cy/cz/dr) <sub>L28736</sub>
- **ADDENDUM** — to §225 (func_8017E190, ov_SC03_115 — cx/cy/cz) <sub>L28781</sub>
- **ADDENDUM** — to §45-A (func_8017F6A4, ov_SC02_016 — cy/cz) <sub>L28834</sub>
- **ADDENDUM** — to §249 (func_80182ED4, ov_SC04_004 — dp/dr/dt) <sub>L28878</sub>
- **ADDENDUM** — to §199-A (func_801816FC, ov_SC02_005 — dp/dr/dt) <sub>L28923</sub>
- **What** — I could not verify <sub>L28969</sub>
- **Harness-defect** — flags <sub>L29012</sub>
- **§284** — COMBINE CAN REASSOCIATE TWO SEQUENTIAL BITWISE-AND MASKS INTO ONE AGAINST THE PRE-MASK VALUE; AN ASM IN/OUT FENCE RIGHT AFTER THE FIRST MASK BLOCKS IT (P31, wave dd, `func_8018087C`, ov_SC04_020, byte-proven) (P31 S60; waves #, byte-proven) <sub>L29074</sub>
- **§285** — PRE-INITIALIZING A VARIABLE WITH A SHARED CONSTANT BEFORE A BRANCH MAKES BOTH ARMS OF THE FOLLOWING if/else DESTRUCTIVELY REUSE THE SAME DESTINATION REGISTER FOR THEIR BITWISE RESULT (byte-proven; `func_801811F0`, ov_SC03_102, independently rediscovered across waves di/dj) (P31 S60; waves #, byte-proven) <sub>L29078</sub>
- **§286** — FOLD A STATEMENT'S SIDE EFFECT INTO A COMMA-EXPRESSION IN AN ARGUMENT POSITION TO PLACE ITS RTL RELATIVE TO A CALL'S OWN DELAY SLOT (P31 S60/dj; `func_80180A88`, ov_SC06_010, byte-proven 411/411) (P31 S60; waves #, byte-proven) <sub>L29082</sub>
- **§287** — A STACK-FRAME HOLE BELOW TWO ADDRESS-TAKEN AGGREGATE LOCALS IS A LEADING PAD MEMBER OF ONE COMBINED STRUCT, NOT SEPARATE LOCALS OR A REGISTER PIN (P31 S60/dj; `func_8017D104`, ov_SC06_027, byte-proven 47/47) (P31 S60; waves #, byte-proven) <sub>L29086</sub>
- **§288** — A REGISTER PIN DECLARED UNINITIALIZED AND ASSIGNED ONLY AT ITS LATE, SOLE USE STILL FORCES THE FIXED REGISTER'S SAVE/RESTORE, AND THE ASSIGNMENT'S SOURCE POSITION CONTROLS WHERE THE VALUE MATERIALIZES (P31; `func_80186530`, ov_SC02_017, byte-proven, match_one MATCH re-verified) (P31 S60; waves #, byte-proven) <sub>L29090</sub>
- **§289** — an array local's address-taken base keeps every element's store alive, even though only one pointer escapes (`func_80189EFC`, ov_SC04_011) (P31 S60; waves #, byte-proven) <sub>L29094</sub>
- **§290** — A SINGLE STRENGTH-REDUCED GIV CAN DRIVE STORES TO SEVERAL DISTINCT RELOCATABLE SYMBOLS, EACH KEEPING ITS OWN `%hi`/`%lo` ANCHOR (P31 S60; waves #, byte-proven) <sub>L29098</sub>
- **§291** — THE DELAY-SLOT FALSE-VALUE: A CONDITIONAL BRANCH'S ZERO ARM MUST BE A FALL-THROUGH-ADJACENT BLOCK ENDING IN AN EXPLICIT JUMP, OR REORG CANNOT MATERIALIZE IT INSIDE THE BRANCH'S OWN DELAY SLOT (P31 S60; waves #, byte-proven) <sub>L29102</sub>
- **§292** — DECLARING A SYMBOL UPSTREAM OF AN ALREADY-BANKED SIBLING THAT RELIES ON THAT SYMBOL'S IMPLICIT (K&R) DECLARATION CAN SILENTLY REPROTOTYPE THE SIBLING'S OWN CALL SITE (P31 S60; waves #, byte-proven) <sub>L29106</sub>
- **§293** — THE "WHOLE-OBJECT GATE NEEDS EVERY SIBLING" LAW, WRITTEN PROPERLY: IT IS THREE LAWS, AND THE LOAD-BEARING ONE IS "THE BASELINE, NOT THE SIBLINGS" (P31 S61; byte-proven on 15 binaries in one night) <sub>L29109</sub>
- **§294** — ADDENDA HARVESTED FROM THE S61 GEN0/MAXTOK/MAIN/DEEPSEEK BATCH (waves ab8/ab16/ab24/ab32 · g0a–g0f · m0a · ds1/ds2): 99 candidates, 52 covered, 15 notes → 10 addenda, 29 notes → 5 new laws (§295–§299), 3 refuted <sub>L29159</sub>
- **ADDENDUM** — to §127 — the -O0 constant-offset fold keys on the MEMBER-ACCESS tree shape, not on the index being constant <sub>L29170</sub>
- **ADDENDUM** — to §261a — FOUR MORE -O0 DIALS BEYOND THE RELOAD COUNT (boot.c + md_MAIN_011/003, wave m0a/g0a/g0f, byte-proven) <sub>L29198</sub>
- **ADDENDUM** — to §264-3 — the explicit entry copy's BOUND: required exactly when the RAW value must outlive the call that consumes only the PROMOTED value <sub>L29248</sub>
- **ADDENDUM** — to §172b-1 (counter-type dial) — the sll's SOURCE REGISTER is the placement discriminator <sub>L29268</sub>
- **ADDENDUM** — to §276 — the SHARE direction: spell the second adjacent symbol RELATIVE to force ONE anchor <sub>L29280</sub>
- **ADDENDUM** — to §31's density-dummy dial (L2460/L2497) — the dose is TWO refs, and the dummy must sit where the loser is live-through <sub>L29296</sub>
- **ADDENDUM** — to §282 — the ADDRESS-GIV face: write the walked address INLINE so strength reduction births the induction register at loop.c's own insertion point <sub>L29313</sub>
- **ADDENDUM** — to §253 — SECOND byte-proven card (upgrade from single-observation), and the placement face: postfix-in-condition parks the RMW store in the branch delay slot <sub>L29336</sub>
- **ADDENDUM** — to the L1800 anchor-steer bullet — a DERIVED-POINTER local silently flips the merged giv's anchor END <sub>L29357</sub>
- **ADDENDUM** — to §31's asm→layout inference — TWO WIDTH-PAIR DISCRIMINATORS (same offset, different widths) <sub>L29380</sub>
- **§295** — THE KERNEL-TRAP STUB: §81's jr-DETECTOR WITHOUT A TABLE IS A PsyQ SYSCALL TRAMPOLINE — ROUTE TO §265, NEVER INTO THE CARVE CHAIN (P31 S61; wave m0a, 9 cards byte-proven; resolves §182's held cluster) <sub>L29401</sub>
- **§296** — THE FRAME CHECK OUTRANKS THE ATLAS LEVER: READ PROLOGUE/EPILOGUE BEFORE DRAFTING ANY C — A REAL TELL CAN LIVE INSIDE AN UNREACHABLE FRAGMENT (P31 S61; wave m0a, 16 cards byte-proven; extends §179-C) <sub>L29456</sub>
- **§297** — ONE GIV SERVING MIXED-WIDTH LOADS *AND* A STORE NEEDS STRUCT-MEMBER SPELLING; CAST/INDEX SPELLINGS RE-SPLIT THE PSEUDO (P31 S61; wave m0a, `func_800347C8`, main, byte-proven 31/31) <sub>L29499</sub>
- **§298** — THE SHARED-TAIL POSITION DIAGNOSTIC: A FOLDED TAIL *BETWEEN* SWITCH ARMS MEANS PER-ARM DUPLICATED STATEMENTS, NOT A HOISTED POST-SWITCH STATEMENT (P31 S61; waves g0e/g0f, `func_80181B68`, ov_SC06_016, byte-proven 68/68) <sub>L29542</sub>
- **§299** — TWO INDEPENDENT EXTRACTION CHAINS EMIT CONTIGUOUSLY INSIDE ONE EXPRESSION; ONLY A STATEMENT BOUNDARY MAKES THE SCHEDULER INTERLEAVE THEM (P31 S61; wave m0a, `func_8003A404`, main, byte-proven 8/8) <sub>L29567</sub>
- **§300** — S61 DISTILL BATCH NOTES (waves ab8/ab16/ab24/ab32 · g0a–g0f · m0a · ds1/ds2 · m0b) <sub>L29602</sub>
- **§301** — AN INTERNAL `j` CARRIES `R_MIPS_26 .text`: rtu/match_one "MATCH" COULD NOT SEE WHICH LABEL A `j` TAKES — FIXED (`jrel`), AND THE TWO DRAFT SHAPES IT HID (P31 S62 T1; byte-proven 2/2, negative-controlled over 3,297 stubs) <sub>L29671</sub>
- **§302** — A RED BINARY IS A DRIFTED SPEC, NOT A MYSTERY: THE THREE CARVE-STATE INVARIANTS AND HOW TO DERIVE EACH FROM THE BYTES (P31 S62 T2; five reds healed in one session, 5/5, +39 held banks) <sub>L29719</sub>
- **§303** — MODULE ISLAND TABLES: DERIVE THE PADS AT BUILD TIME, PEEL NOTHING — THE §154-A/§260 "island-pads"/"island-blocked" WALLS DISSOLVE (P31 S62 T3a; byte-proven md_SC03_076 func_801F0A9C + func_801F0F28, sha 9a165e36…) <sub>L29763</sub>
- **§304** — SELF-DEFINING RODATA: WHEN A FUNCTION'S `.s` IS THE ONLY OWNER OF THE DATA IT REFERENCES, THE C BODY MUST DEFINE IT (P31 S62 T3; byte-proven md_MAIN_011/func_800D04F4) <sub>L29799</sub>
- **§305** — "CARVE-REFUSED" AT GATE TIME IS THREE NAMED, DETERMINISTIC CLASSES — NONE OF THEM A CARVE (P31 S62 T3; 28 resolver drafts autopsied 28/28) <sub>L29822</sub>
- **§306** — A HAZARD `nop` IN FRONT OF A DIV-RESULT STORE IS A STATEMENT-ORDER DEFECT: THE INDEPENDENT TRAILING STATEMENT MUST BE WRITTEN *BEFORE* THE DIVISION-CONSUMING ONE (P31 S62 T4; byte-proven func_8017E7D0) <sub>L29874</sub>
- **§306a** — T4 DISTILL ADDENDA (P31 S62; four byte-proven refinements to existing laws, verified against the book by an independent verifier; each names its parent §) <sub>L29901</sub>
- **§307** — THE BRUTE-FORCE-THE-STATEMENT-ORDERS LEVER HAS A BOUND: A FAN-OUT COPY'S PRIORITY IS SCHEDULER-INTERNAL, AND NO SOURCE ORDER REACHES IT (P31 S63; byte-evidenced NEGATIVE result, main wave) <sub>L29939</sub>
- **§308** — A NAIVE FINAL `goto` DELETES THE TARGET'S `j`+`nop`: SPELL THAT EDGE AS A TAUTOLOGICAL `if` SO cse FOLDS IT TO AN UNCONDITIONAL JUMP *AFTER* jump1's WINDOW HAS CLOSED (P31 S63 t5e-t5i; byte-proven func_80180808) <sub>L29983</sub>
- **§308a** — A TWO-INSTRUCTION ARM STUB LAID *BEFORE* THE OTHER ARM AND REACHED ONLY BY A TRAILING `j` SURVIVES ONLY BEHIND A SHORT-CIRCUIT `&&` GUARD PLUS A SEPARATE RE-TEST; EVERY PLAIN if/else-if, GOTO-LADDER, NESTED-INVERTED-if AND 1-/2-NODE switch LETS jump1 INLINE IT (−2 ins) (P31 S63 t5e-t5i; byte-proven func_80180808) <sub>L30012</sub>
- **§309** — A FRAME-ADDRESS EQUIVALENCE RIDES *THROUGH* A SKIPPABLE CONDITIONAL: POST-`if` STORES FOLD ONTO `$sp` UNLESS THE `if` SURVIVES jump1 AS A BARRIER-PRECEDED DIAMOND (P31 S63 t5e-t5i; byte-proven func_801812AC) <sub>L30046</sub>
- **§310** — A TWO-OPERAND `subu`'s DESTINATION TIES ONLY TO THE OPERAND THAT IS BLOCK-LOCAL: SHARE *ONE* SIDE ACROSS BLOCKS TO CHOOSE WHICH OPERAND'S REGISTER IT LANDS IN (P31 S64 t5j-t5m; byte-proven func_8017F578) <sub>L30086</sub>
- **§311** — A JOIN-BLOCK STORE CAN SWALLOW AN ARM'S LOAD-DELAY `nop`: WHEN ONE ARM'S VALUE COMES FROM A LOAD, DUPLICATE THE STORE INTO BOTH ARMS (P31 S64 t5j-t5m; byte-proven func_8017D7E0) <sub>L30117</sub>
- **§312** — A BARE RELATIONAL IN AN `if` GIVES THE `slt` NO TARGET: ASSIGN THE COMPARISON INTO THE ALREADY-ALLOCATED VARIABLE TO CHOOSE ITS DESTINATION REGISTER, AT ZERO INSTRUCTION COST (P31 S64 t5o-t5r; byte-proven func_80180DCC) <sub>L30159</sub>
- **§313** — A RECOVERY STAGE THAT REWRITES THE DRAFT IS PART OF THE MEASUREMENT: GATE THE RAW DRAFT FIRST, THE REWRITE ONLY AS A FALLBACK (P31 S65 t5r-recovery; byte-proven func_8017BEBC, 246 ins) <sub>L30185</sub>
- **§314** — AN IF/ELSE-IF ABS-RANGE CHECK'S C SPELLING IS INERT: FOUR STRUCTURALLY DIFFERENT REWRITES ALL COMPILE BYTE-IDENTICAL, AND NONE REACHES A TARGET THAT SINKS THE NEGATIVE ARM INTO AN OUT-OF-LINE BLOCK (P31 S65; UNPROVEN, gate-refused draft func_80181720) <sub>L30241</sub>
- **§315** — ALL-CONSTANT AGGREGATE FILL: THE EMISSION ORDER IS SHARED-LITERAL GROUPS × DESCENDING INDEX, WITH PAIRED SUB-FIELDS INTERLEAVED (P31 S66; ⚠ **UNPROVEN** — `func_80185214`, gate-REFUSED draft, closeness 32→5, never MATCHed) <sub>L30273</sub>
- **§316** — A GUARD CHAIN THAT GATES A SUCCESS BLOCK ROUTES ITS FAILING GUARDS TO A LABEL **BEFORE** THE FLAG TEST, NOT TO THE EPILOGUE: THE RESIDUAL IS IMM-OFFSET-ONLY AT AN EXACTLY EQUAL INSTRUCTION COUNT (P31 S66; byte-proven func_80180284) <sub>L30310</sub>
- **§317** — A NARROW STRUCT-FIELD STORE TURNS A *LIVE SImode VARIABLE* INTO A `li`: convert.c's TRUNCATION-DISTRIBUTION MINTS A HImode COPY, AND cse REWRITES THAT COPY'S SOURCE TO THE EQUIVALENT CONSTANT (P31 S66; byte-proven func_8017EF94) <sub>L30344</sub>
- **§318** — A UNARY MINUS STORED BACK INTO THE SAME HALFWORD IS COMPUTED IN HImode, SO ITS LOAD IS `lhu`; AN INLINE `(s32)` CAST IS PROVABLY INERT AND ONLY A NAMED SImode LOCAL BUYS `lh` (P31 S66; `func_8018568C`, ov_SC03_028 — **`match_one`-only, NOT byte-gated**) <sub>L30378</sub>
- **Addendum** — §148-A2 addendum — the empty-asm insn_count dial (N bare `__asm__("")` = exactly +N real i (func_801835B0) <sub>L30453</sub>
- **Addendum** — §312 addendum — naming the compare's dest is the vehicle, the hard-reg pin on that name is (func_80184A68) <sub>L30461</sub>
- **Addendum** — subu/sh dest reuses a pinned operand's dying register (func_8017F498) <sub>L30465</sub>
- **Addendum** — Addendum to §261a — the -O0 increment-operator copy also fires on the POINTER LOCAL itself (func_8001212C) <sub>L30473</sub>
- **Addendum** — Addendum to §164-XX/§165-06 — at -O0 a bare local IS a memory lvalue, so the increment ope (func_8001212C) <sub>L30477</sub>
- **Addendum** — Addendum to §312 — the compare's named destination must itself carry a hard register: nami (func_80184A68) <sub>L30481</sub>
- **Addendum** — Addendum to §167-12 — the single-operand volatile keepalive, re-confirmed at a gated MATCH (func_8017F498) <sub>L30485</sub>
- **Addendum** — A §5a BARRIER SITS IN REORG'S FILL WINDOW TOO, SO ITS SIDE OF THE INNER `goto` IS CHOSEN P (func_80181D08) <sub>L30489</sub>
- **Addendum** — Loop sentinel wrongly hoisted out of a call-containing loop (func_801835B0) <sub>L30493</sub>
- **Addendum** — Reversed-operand sltu then xori 1 means unsigned less-or-equal (func_8017D948) <sub>L30505</sub>
- **Addendum** — Chained *2*2 array index folds to one copy;sll, not two (func_80011380) <sub>L30509</sub>
- **Addendum** — REGALLOC-PERM: one memory-clobber barrier insufficient — stack two (func_80182D1C) <sub>L30523</sub>
- **Addendum** — Last if-arm's nested if un-fuses the whole preceding chain (func_8017FE88) <sub>L30529</sub>
- **Addendum** — A plain global-RMW triplet is a fillable scheduling window too — zero drift, and the fille (func_800CB058) <sub>L30533</sub>
- **Addendum** — Shared arithmetic that CONSUMES the selected value cannot be hoisted above the `if` — narr (func_80183DA0) <sub>L30537</sub>
- **REFUTED** — claim — Dead call-arg register address-fold: no C-level lever found (func_8017ECAC) <sub>L30541</sub>
- **Addendum** — Truncating assign must be the lazy `||` operand, not hoisted (func_80012B58) <sub>L30560</sub>
- **Addendum** — WIDTH sh!=lhu residual: hoist a sibling field's load first (func_80182538) <sub>L30572</sub>
- **REFUTED** — claim — REFUTED — the `j`-slot store is an ASPSX macro-expansion hop, not a cse split; maspsx hard (func_8005DBD8) <sub>L30589</sub>
- **§NNN** — REFUTED: A `sw %lo(SYM)($at)` IN A JUMP'S DELAY SLOT WITH ITS `lui $at` STRANDED ABOVE THE JUMP IS **ASSEMBLER** MACRO-EXPANSION, NOT A cse SPLIT — OUR PIPELINE CANNOT EMIT IT FROM ANY C, AND THE +1 IS A `maspsx` GAP (P31 S66 round2, `func_8005DBD8`, byte-probed) <sub>L30591</sub>
- **Addendum** — Static local_type blocker survives typedef removal — it's textual (func_801588CC) <sub>L30615</sub>
- **Addendum** — Orphan sh triplet to $sp is a write-only local array (func_8017F274) <sub>L30622</sub>
- **Addendum** — REGALLOC-PERM: the store reads the narrow copy's register — split the one narrow local by (func_801838CC) <sub>L30626</sub>
- **Addendum** — REGALLOC-PERM store in a cross-jump shared tail defeats §137's barrier (func_8017EDE8) <sub>L30630</sub>
- **Addendum** — LENGTH-DRIFT nop clears when offset math precedes the symbol launder (func_80039B20) <sub>L30634</sub>
- **REFUTED** — claim — REFUTED: a block shared across TWO switch statements is ordinary forward cross_jump, not a (func_8001B0D4) <sub>L30638</sub>
- **§NNN** — REFUTED: A CODE BLOCK SHARED BY TWO *DIFFERENT* SWITCH STATEMENTS IS ORDINARY FORWARD `cross_jump`, NOT A SHAPE C CANNOT REACH — §164-11 ALREADY BANKS IT FROM PLAIN NESTED SWITCHES (P31 S66 round3, `func_8001B0D4`; ⚠ **UNPROVEN** — gate-REFUSED draft, closeness 68→45, never MATCHed) <sub>L30640</sub>
- **RETRIEVAL** — FAILURES this round (not new knowledge — a RETRIEVAL defect) <sub>L30656</sub>
- **§319** — N TEXTUALLY DUPLICATED `return v;` TAILS PUT THE LAST `or` AND THE RETURN-REGISTER MOVE IN ONE BASIC BLOCK, SO combine FOLDS THEM AND YOU ARE EXACTLY −1; A `goto done;` JOIN WITH REAL INCOMING EDGES RESTORES THE SEPARATE `addu $v0,$a0,$zero` (P31 S66 round4; byte-proven func_801809F0) <sub>L30671</sub>
- **Addendum** — Masked-OR field-merge plateaus at close=10; bitfield store clears it (func_8017FD64) <sub>L30700</sub>
- **Addendum** — Integer-space address arithmetic is a THIRD no-movable spelling, and a distant `SYM[0]` re (func_8017D89C) <sub>L30704</sub>
- **Addendum** — LENGTH-DRIFT −1 on a coalesced-away copy: a CALLER-SAVED SOURCE pin can resurrect it, boun (func_8017D72C) <sub>L30714</sub>
- **Addendum** — Return-0 statement order: extra j+move vs delay-slot fusion (func_8018BB50) <sub>L30721</sub>
- **Addendum** — Counter zero in the DECLARATION slot, empty for-init — the prologue SHIFT-DRIFT/+K face of (func_8018275C) <sub>L30725</sub>
- **Addendum** — The dying-pinned-register reuse on a sign-extend chain: route every later read through a s (func_80186868) <sub>L30743</sub>
- **Addendum** — Volatile zero-byte asm slider scrambles the prologue schedule (func_801814B0) <sub>L30747</sub>
- **Addendum** — Register-pinned helper pointer local regresses closeness; use plain local (func_80013CFC) <sub>L30757</sub>
- **Addendum** — §194-A addendum — the bare/colon-less fence measured NULL and only the "memory"-clobber fo (func_8017E464) <sub>L30761</sub>
- **RETRIEVAL** — FAILURES this round <sub>L30765</sub>
- **§320** — THE §43 "RETURN-TYPE FLIP PAIR" IS **NOT** TU-EDIT-REQUIRED: THREE DRAFT-ONLY ESCAPES (P31 S66; byte-proven func_800CCBC0, func_800D30D0, func_800D2A24) <sub>L30786</sub>
- **§321** — FILE-SCOPE DUPLICATE ANONYMOUS-STRUCT TYPEDEFS ARE A HARD ERROR; THE SAME TEXT AT BLOCK SCOPE IS A WARNING (P31 S66; byte-proven func_80180728, func_8017F9F8, func_8017E07C) <sub>L30845</sub>
- **§322** — A PROBE THAT ANSWERS A *NECESSARY BUT NOT SUFFICIENT* QUESTION WILL PRICE BLOCKED WORK AS FREE: RUN THE REAL PLANNER WHEN THE PLANNER IS PURE (P31 S67; measured, 96 of 159 open jtbl functions) <sub>L30866</sub>
- **§323** — CARRYING FILE-SCOPE TYPES BETWEEN SPLIT TUs: DEDUPE BY NAME, SKIP HEADER-PROVIDED, AND THE GUARD TRAVELS WITH THE BLOCK (P31 S67; ov_SC02_000, two defects fixed, one open) <sub>L30896</sub>
- **§323a** — R53, TWICE IN ONE HOUR: A FAILED BUILD LEAVES THE PREVIOUS BINARY, AND `sha1sum` READS GREEN (P31 S67) <sub>L30926</sub>
- **§323b** — A SCRIPT THAT PARSES argv AT IMPORT CANNOT BE SHARED; EXTRACT THE PREDICATE, DO NOT COPY IT (P31 S67) <sub>L30935</sub>
- **§324** — THE ARITY-SELF WALL NEEDS *BOTH* HALVES: A K&R DEFINITION **AND** A NO-PROTO TU DECL; EITHER ALONE STILL FAILS (P31 S67; rtu-proven ov_SC01_005/func_8017FBCC, 14 instances measured) <sub>L30949</sub>
- **§325** — REGALLOC: A SHARED SMALL CONSTANT STORED TWICE IN THE PRE-LOOP BLOCK IS A *local-alloc* $s-OCCUPANT THAT STEALS THE ARGUMENT ALLOCNO'S REGISTER — PIN THE ARGUMENT-DERIVED LOCAL, NOT THE CONSTANT (P31 S67; byte-proven ov_SC03_119/func_80184F18, 153 ins) <sub>L30987</sub>
- **§326** — DEFEATING ADDRESS-CSE: SPELL TWO READS OF THE SAME HALFWORD DIFFERENTLY AND GCC CANNOT SHARE THE ADDRESS (P31 S67; byte-proven ov_SC01_077/func_8017FAAC, 154 ins) <sub>L31000</sub>
- **§327** — A RANGE TEST MUST BE HImode: WITH `s32` + A `(u16)` CAST GCC *PROVES* THE MASK REDUNDANT AND DROPS THE `andi` (P31 S67; byte-proven ov_SC02_039/func_8017EC34, 154 ins) <sub>L31009</sub>
- **§328** — THE VOLATILE ALIAS MUST BE AN *OBJECT*, NOT A CAST: `*(volatile s32*)&sym` UNFOLDS %lo INTO A SEPARATE `addiu` (P31 S67; byte-proven ov_SC07_007/func_80181B8C, 156 ins, NEW LAW) <sub>L31024</sub>
- **§329** — fold-const NARROWS `(int)s16_var & 0xFFF` ONTO THE *RAW HImode PSEUDO*, BREAKING THE SIGN-EXTEND/MASK REGISTER TIE — A ZERO-BYTE WIDENING TEMP RESTORES IT (P31 S67; byte-proven ov_SC01_084/func_80183244, 157 ins) <sub>L31034</sub>
- **§330** — THE NEIGHBOUR-SHAPE LEVER IS THE CHEAPEST FIRST MOVE, AND IT IS UNDER-USED (P31 S67; four independent instances in one 20-function wave) <sub>L31042</sub>
- **§331** — OPEN GAP: NO LEVER ELIMINATES AN *UNWANTED DUPLICATE* COPY AT A BRANCH-TARGET BLOCK HEAD (P31 S67; main/func_80013154, closeness 12, NOT solved) <sub>L31059</sub>
- **§332** — THE maspsx `la`-IN-A-DELAY-SLOT GAP: gcc EMITS A SYMBOLIC ADDRESS LOAD AS ONE ATOMIC length-2 INSN, SO IT CAN NEVER FILL A JUMP DELAY SLOT — 6 FUNCTIONS FLEET-WIDE, NONE BANKABLE FROM C (P31 S67; byte-traced main/func_80062144, func_8005DBD8) <sub>L31071</sub>
- **§332a** — MAIN'S RESIDUAL FRONTIER IS CONTAMINATED WITH TOOLCHAIN WALLS: 4 OF 7 IN ONE WAVE (P31 S67, measured) <sub>L31096</sub>
- **§333** — FRAME SIZE IS SET BY *DECLARED* AGGREGATES, NOT USED ONES: AN UNREFERENCED TRAILING LOCAL IS A REAL DIAL (P31 S67; three independent byte-proven instances in one wave) <sub>L31115</sub>
- **§334** — A RELOAD SPILL SLOT IS ROUNDED TO `BIGGEST_ALIGNMENT` (8B), SO ONE SPILLED 4-BYTE PSEUDO CAN GROW THE FRAME BY 16 (P31 S67; byte-proven ov_SC05_008/func_8017DF68, 82 -> 53 residual) <sub>L31129</sub>
- **§335** — AN `extern u16 A[]` READ AT A VARIABLE SUBSCRIPT ALLOCATES DEAD STACK TEMPS (~8B PER ACCESS) THAT INFLATE THE FRAME WHILE EMITTING ZERO EXTRA INSTRUCTIONS (P31 S67; byte-proven ov_SC06_025/func_8017EA74, closeness 141 -> 20) <sub>L31140</sub>
- **§336** — THE §5a CROSS-JUMP BARRIER GOES AT THE *BOTTOM* OF THE TWIN, NOT THE TOP: `find_cross_jump` WALKS BACKWARD FROM THE CONVERGING JUMP (P31 S67; byte-proven ov_SC05_001/func_80183C9C) <sub>L31149</sub>
- **§337** — THE CC1-ONLY BLOCKER CLASS: `blocker_probe`'s STATIC ORACLE REPORTS "none" AND THE WHOLE-TU COMPILE STILL FAILS (P31 S67; ov_SC04_011/func_801827DC, md_MAIN_027/func_800CB4A4) <sub>L31157</sub>
- **§338** — `jtbl_carve._sltiu_bounds` MISREADS A NON-SWITCH `sltiu` AS A BOUNDS CHECK, OVER-SPANNING THE TABLE (P31 S67; ov_SC06_022/func_80185B80, byte-diagnosed) <sub>L31171</sub>
- **§339** — A 2-CASE SWITCH OMITS THE LOW-BOUND RANGE TEST, SO THE PRESENCE OF `slti/bnez` BETWEEN THE `beq`s IS A **COUNT TELL** FOR A THIRD CASE NODE (P31 S67; byte-proven ov_SC02_005/func_80190538, 197 ins) <sub>L31181</sub>
- **§340** — §194-K COROLLARY: **FLIP THE FALSE EDGE YOU CANNOT DELETE.** A "scheduler" residual can be sched.c's ALIAS ORACLE emitting a FALSE true-dependence; source order chooses its DIRECTION (P31 S67; byte-proven ov_SC03_107/func_8017CF48, 10 -> 0 in one compile, zero bytes) <sub>L31209</sub>
- **§341** — AN HImode STORE TEMP REWEIGHTS A sched2 TIE-BREAK THAT NO STATEMENT ORDER CAN REACH (P31 S67; byte-proven ov_SC03_006/func_801823B8, last 4 ins) <sub>L31243</sub>
- **§342** — A `void *` PARAMETER CAST TO ITS REAL TYPE IN A LOCAL IS **NOT** BYTE-NEUTRAL WHEN A LATER PARAMETER ALSO NEEDS A CALLEE-SAVED REGISTER (P31 S67; byte-proven ov_SC07_002/func_80181394, NEW LAW) <sub>L31257</sub>
- **§343** — `decl_prior`'s FLEET MAJORITY CAN BE WRONG ABOUT THE TRUE SIGNATURE — READ THE RIVALS, NOT JUST THE WINNER (P31 S67; measured on func_8012BD14 / func_8012D624 / func_80143C74) <sub>L31274</sub>
- **§344** — RAISE A BIV'S global_alloc PRIORITY WITH A ZERO-BYTE REFERENCE INSTEAD OF PINNING IT; PINNING THE COUNTER KILLS LSR ENTIRELY (P31 S67; byte-proven ov_SC03_121/func_80180E64, 222 ins) <sub>L31296</sub>
- **§345** — A VOLATILE **STORE** EVICTS THE MEM FROM cse AND KEEPS `sh`; A VOLATILE **LOAD** BLOCKS combine AND DEGRADES `lh` INTO `lhu+sll+sra` (P31 S67; byte-proven ov_SC01_084/func_80181A7C) <sub>L31312</sub>
- **§346** — `c ? X : -X` TAKES expand_expr's COND_EXPR **SINGLETON** PATH (copy, then negate IN PLACE) — AN if/else STATEMENT GIVES THE TWO-ARM FORM (P31 S67; byte-proven ov_SC03_102/func_80180C38, closed the last instruction) <sub>L31322</sub>
- **§347** — LOOP REGISTER ASSIGNMENT IS A **DECLARATION-ORDER + LIVE-RANGE** DIAL: FIVE COMPOSABLE LEVERS, 178 -> 0 (P31 S67; byte-proven ov_SC06_029/func_8017EF34, 243 ins) <sub>L31342</sub>
- **§347-addendum** — A THIRD INSTANCE, AND THE SHARPEST STATEMENT OF THE RULE (md_MAIN_025/func_800CB300, 243 ins) <sub>L31372</sub>
- **§343-addendum** — SECOND INSTANCE OF THE WRONG-MAJORITY DECL (same function) <sub>L31390</sub>
- **§348** — THE BASE SPELLING PICKS THE ADDRESSING MODE: A SYMBOL GIVES THE 3-INSN `lui/%lo` FORM, A POINTER VARIABLE GIVES THE 2-INSN `addu/lw` FORM (P31 S67; byte-proven ov_SC07_007/func_80182184, 264 -> 30 on this row alone) <sub>L31397</sub>
- **§349** — RE-ASSIGN A BASE POINTER AT THE END OF THE LOOP BODY TO MAKE `n_times_set > 1` — THAT KILLS BOTH loop.c's INVARIANT HOIST **AND** THE ADDRESS GIV, REPRODUCING A REMATERIALISED `addiu $aN,$sp,K` (P31 S67; byte-proven ov_SC06_029/func_801804C8, 255 ins) <sub>L31414</sub>
- **§350** — A ZERO-BYTE RE-TIE SETS `reg_n_sets=2`, WHICH KILLS sched1's `birthing_insn_p` LAUNCH_PRIORITY BOOST — THE MECHANISM BEHIND "MY ADDS ARE GLUED TO THEIR STORES" (P31 S67; byte-proven ov_SC04_011/func_80180B24, 215 ins) <sub>L31435</sub>
- **§351** — `/s` (MEM_IN_STRUCT_P) IS A DIAL YOU CHOOSE PER ACCESS: A COMPONENT_REF GRANTS IT AND LETS cse KEEP AN INDEX ACROSS THE STORE; A PLAIN CAST DENIES IT (P31 S67; ov_SC01_000/func_8017DD04, 186 -> 5) <sub>L31456</sub>
- **§352** — ⚠ TWO IDENTICAL `__asm__ __volatile__("")` BARRIERS **MERGE WITH EACH OTHER** — SPELL THE SECOND ONE DIFFERENTLY (P31 S67; byte-proven resident/func_800D128C, measured closeness 105 when they merged) <sub>L31486</sub>
- **§353** — USE `-fno-thread-jumps` AS AN **ORACLE** TO PROVE A RESIDUAL IS thread_jumps, THEN LAUNDER THE *VALUE* TO KEEP A DEAD RE-TEST (P31 S67; byte-proven ov_SC01_008/func_8017EC68, 279 ins) <sub>L31519</sub>
- **§354** — THE giv **WORTH-WHILE TEST** IS A DIAL: RE-ASSOCIATE THE ADDEND INTO THE INDEX TERM AND `strength_reduce` DECLINES (P31 S68; byte-proven ov_SC03_105/func_801824CC, 320 ins, 201 → 5 → 0) <sub>L31542</sub>
- **§355** — A REMAPPED SIBLING'S **SOURCE BIAS IS NOT ITS EMITTED BIAS** — DO NOT HAND-SHIFT OFFSETS TO MATCH THE ASM (P31 S68; byte-proven ov_SC07_007/func_8013DD68, 187/187 in 2 iterations) <sub>L31560</sub>
- **§356** — MEASURE A DRAFT IN THE TU IT WILL LIVE IN, NOT IN THE STANDALONE PROBE (P31 S68; measured over 47 stored drafts) <sub>L31574</sub>
- **§357** — ONE STRUCT POINTER, NOT TWO: A SECOND SOURCE VARIABLE BUILDS A THIRD IV (P31 S68; byte-proven ov_SC06_029/func_80181DF8, 335 ins, 330 → 13) <sub>L31589</sub>
- **§358** — (sharpens §333) — AN **UNREFERENCED** FIXED-SIZE AGGREGATE LOCAL IS LOAD-BEARING (P31 S68; same function) <sub>L31598</sub>
- **§359** — (§43-adjacent) — SPELL A SIGN-WIDEN AS AN EXPLICIT TWO-STEP, FUNCTION-SCOPED TEMP (P31 S68; byte-proven main/func_80012B58, 69 ins, 58 → 3 → 0) <sub>L31608</sub>
- **§360** — THE "COMPILER FOUND A SHORTER EQUIVALENT THAN THE TARGET" PAIR (P31 S68; main/func_800241C0, 68 ins, 68 → 19) <sub>L31621</sub>
- **§361** — ★ — A LOOP-TAIL BYTE SIGNATURE THAT NAMES ITS SOURCE SHAPE — AND THE LAW THAT A "SCHEDULING TIE" MAY BE YOUR OWN EARLIER LEVER (P31 S68; byte-proven main/func_800241C0, fable escalation, 19 → 0 in 3 iterations) <sub>L31637</sub>
- **§362** — TWO TRAPS WHEN A CARVE MOVES A STUB INTO THE `-O0` TU (P31 S68; byte-proven, 6 fns / 2,547 ins across ov_MAIN_012 / ov_SC02_037 / ov_SC03_107) <sub>L31682</sub>
- **§363** — ★★ — THE OVERLAY-LAYOUT ASSUMPTION IS A SYSTEMIC BUG CLASS, AND `main` IS THE EXCEPTION THAT FINDS IT (P31 S68; six instances, four of them in one session) <sub>L31705</sub>
- **§364** — ★ — THE libgpu `P_TAG` BITFIELD SPELLING IS **OPT-LEVEL DEPENDENT** (P31 S68; two functions, opposite verdicts, same session) <sub>L31734</sub>
- **§365** — PIN **BOTH** MASKS OR NEITHER (P31 S68; ov_SC01_000/func_8017E594, 357 ins) <sub>L31748</sub>
- **§366** — ★★ — `group_case_nodes` MERGES **STACKED CONSECUTIVE** CASE LABELS: GIVE EVERY CASE ITS OWN BODY (P31 S68; ov_SC01_001/func_8017EC28, **first-try MATCH 360/360**, 96/96 relocs audited) <sub>L31757</sub>
- **§367** — RECONCILING A DECL CONFLICT BETWEEN TWO DRAFTS FOR THE SAME TU (P31 S68; main) <sub>L31777</sub>
- **§368** — ★★★ — THE **RELOAD-REMAT CONSTANT**: REACH A REGISTER NO PIN CAN REACH (P31 S68; ov_SC03_105/func_80187A30, 339 ins, fable escalation closed 8 → 0 in ONE edit) <sub>L31792</sub>
- **§369** — REUSE THE **COMPARE CONSTANT'S OWN VARIABLE** FOR A MASK THAT KEEPS COALESCING (P31 S68; md_SC07_004/func_801AEC38, 365 ins) <sub>L31822</sub>
- **§370** — ★★ — A **HARD BOUND** FROM sched.c, AND THE reorg SLOT-STEAL DIAGNOSTIC (P31 S68; main/func_8001BC6C, 69 ins, NOT closed — 33 → 28 over ~45 measured compiles) <sub>L31838</sub>
- **§371** — ★★ — CARVING A **SINGLE-OBJECT MODULE BINARY**, AND THE spimdisasm RODATA-MIGRATION TRAP THAT FOLLOWS (P31 S68; byte-proven md_MAIN_003, func_800D0D6C 345 ins) <sub>L31890</sub>
- **§372** — ★★★ — THE **COPY-CAPTURE PAIR**, AND THE ONE ZERO-BYTE EDIT THAT DEFEATS BOTH (P31 S68; byte-proven main/func_8003491C, 78 ins, fable escalation closed 5 → 0) <sub>L31939</sub>
- **§373** — ★★★ — THE **DEAD-RESET CSE-BREAKER**, THE PIN THAT BREAKS A sched2 ANTI-DEP, AND WHY AN `asm` CAN NEVER RAISE PRIORITY (P31 S68; byte-proven ov_SC06_010/func_8017E764, 438 ins, fable escalation closed 8 → 0) <sub>L31977</sub>
- **§3-1.** — DEAD-RESET CSE-BREAKER — the zero-footprint replacement for a §195-I asm re-tie <sub>L31979</sub>
- **§3-2.** — A REGISTER PIN THAT DELETES A sched2 ANTI-DEPENDENCE <sub>L31997</sub>
- **§3-3.** — HARD FACT FOR THE SCHEDULING MAP — an `asm` ALWAYS has priority 1 <sub>L32010</sub>
- **CROSS-REFERENCE** — TO §370 — checked and found INAPPLICABLE here, which is the point <sub>L32018</sub>
- **§374** — A `register … __asm__("$30")` RESERVATION IS **NOT HONOURED** BY `move_movables` (P31 S68; main/func_80015608, 86 ins) <sub>L32026</sub>
- **§375** — AN `$a0`-`$a3` PIN USED LATE RELOCATES AN **EARLIER** OUTGOING-CALL USE OF THAT REGISTER (P31 S68; main/func_8005F0C8, 88 ins) <sub>L32042</sub>
- **§376** — ★★★ — A STANDALONE `match_one` CLOSENESS OF 0 IS A CLAIM ABOUT THE **BODY**, NEVER ABOUT THE **TU** (P31 S69; measured 0/28) <sub>L32055</sub>
- **§377** — THREE HARNESS DEFECTS FOUND IN ONE GATING SESSION, ALL "A CONFIDENT NUMBER ABOUT A SMALLER WORLD" (P31 S69) <sub>L32097</sub>
- **§378** — ★★★ — THE **SELF-CALLER CAST**: LET A TU KEEP CALLING THE FUNCTION IT IS ABOUT TO DEFINE (P31 S69; byte-proven ov_SC04_010/func_8017D6CC) <sub>L32114</sub>
- **§379** — ★★★ — **MEM_IN_STRUCT_P**: THE SAME LOAD, WRITTEN AS A STRUCT MEMBER, SCHEDULES WHERE A CAST CANNOT (P31 S69; byte-proven main/func_80021284 220 ins and main/func_8002D904 217 ins, found INDEPENDENTLY by two agents) <sub>L32164</sub>
- **§380** — ★★★ — **A SECOND SET OF A PSEUDO DISQUALIFIES IT FROM `move_movables`** (P31 S69; main/func_800215F4, 465 ins, closeness 106 → 59 → 39) <sub>L32195</sub>
- **§381** — THE `insn_count` HOIST THRESHOLD IS A DIAL YOU CAN READ WITH `cc1 -dL` (P31 S69; four independent uses in one wave) <sub>L32216</sub>
- **§382** — TWO FOLD REASSOCIATIONS THAT NEED THEIR OWN STATEMENT (P31 S69) <sub>L32232</sub>
- **§383** — TWO TOOLCHAIN FACTS THE PACKS DID NOT CARRY (P31 S69) <sub>L32244</sub>
- **§384** — ★★★ — A CARVE-CONFIG BANK IS RED UNTIL YOU RE-EXTRACT, AND THAT LOOKS EXACTLY LIKE A FALSE BANK (P31 S69; measured twice, cost one destroyed match) <sub>L32259</sub>
- **§385** — ★★★ — THE **SCHED2 PRIORITY-DONOR ASM**: closing the "hoisted-invariant vs IV-init preheader swap" class (P31 S69; byte-proven main/func_80038A58, 347 ins, fable escalation 2 → 0) <sub>L32309</sub>
- **§386** — ★★★ — A BYTE LOAD ON THE **BIV** BASE WAS BORN IN THE COMBINE PASS: SPELL IT AS A SHIFT-MASK, NEVER A DEREF (P31 S69; byte-proven main/func_80020598, 292 ins, escalation 1 → 0) <sub>L32335</sub>
- **§387** — ★★ — **SPLIT-FOLD DISPATCH CLOBBER**: one switch case needs a reload, another must keep the fold (P31 S69; byte-proven main/func_80030F80, 343 ins, escalation 3 → 0) <sub>L32361</sub>
- **§388** — ★★★ — THE **-O0 COLOURING ORACLE**: simulate `stupid.c` instead of grinding spellings (P31 S69; main/func_80011380 proved a C-level WALL at 6) <sub>L32384</sub>
- **§389** — ★★★ — `h_norm` IS BLIND TO INDEXED-GLOBAL RELOCS, SO FREE WORK BECOMES AN INVISIBLE SINGLETON (P31 S69; 31 stubs / 4,811 ins recovered, 8 banked same day) <sub>L32409</sub>
- **§390** — ★★★ — MINIMUM DISTANCE IS NOT MINIMUM WORK; RANK TWIN CANDIDATES BY EFFORT, AND FILTER LOOKALIKES BY RATIO (P31 S69; byte-proven ov_SC01_077/func_80184D50, banked) <sub>L32450</sub>
- **§391** — ★★ — A BYTE-ALIGNED STRUCT COPIES IN FOUR INSTRUCTIONS, A WORD-ALIGNED ONE IN TWO (P31 S69) <sub>L32488</sub>
- **§392** — ★★★ — THE SONNET-WAVE HARVEST (P31 S69): SEVEN TYPE/ORDER LEVERS THAT EACH CLOSED A MATCH <sub>L32502</sub>
- **§393** — ★★ — THE **BIRTHING BOOST**: A SINGLE-SET LOCAL IS SCHEDULED LAST; GIVE IT A SECOND SET (P31 S69; byte-proven ov_SC02_017/func_8017FCFC) <sub>L32543</sub>
- **§394** — ★★ — TWO ALIGN-1 ACCESSES IN ONE FUNCTION RESERVE A PHANTOM STACK SLOT (P31 S69; ov_SC02_005/func_80180610) <sub>L32560</sub>
- **§378b** — ★★★ — THE FOUR VARIANTS OF THE DECL BLOCKER, AND THE TWO PLACES §378 DOES **NOT** APPLY (P31 S69, all four measured the same day) <sub>L32572</sub>
- **§395** — ★★★ — FIVE NARROWING/PLACEMENT LEVERS FROM ONE 91-INSTRUCTION CRACK (P31 S69; byte-proven ov_SC06_018/func_80189E60, warm start 32 off → MATCH 91/91) <sub>L32611</sub>
- **§314b** — ★★ — TWO ABS-RANGE GUARDS IN ONE FUNCTION NEED **DIFFERENT SPELLINGS** (P31 S69; byte-proven ov_SC04_002/func_8018691C, 111 ins) <sub>L32645</sub>
- **§322b** — ★★★ — THE CARVE CLASS IS COMPLETABLE, AND EVERY WORKTREE `CARVE-REFUSED` WAS AN INSTRUMENT VERDICT (P31 S69, Fable-3 audit; byte-proven end-to-end) <sub>L32667</sub>
- **§332b** — ★★★ — THE §332 "WALLS" ARE A PER-OBJECT ASSEMBLER MODE, NOT A C LIMIT — 6 CLOSE AS REAL C (P31 S69, Fable-3) <sub>L32702</sub>
- **§378c** — ★★ — THE FIFTH DECL-BLOCKER VARIANT: THE DRAFT REDECLARES WHAT THE TU ALREADY OWNS (P31 S69) <sub>L32722</sub>
- **§396** — ★★★ — SIX LEVERS FROM THE S69 SINGLETON ROUND, INCLUDING ONE THAT ONLY A `COND_EXPR` REACHES (P31 S69) <sub>L32737</sub>
- **§397** — ★★★ — RE-RUN THE TWIN SCAN AFTER EVERY EXEMPLAR BANK; A CLUSTER SIBLING IS FREE THE MOMENT ITS EXEMPLAR LANDS (P31 S69; ~250k tokens spent proving it the expensive way) <sub>L32785</sub>
- **§396g** — ★★ — A GUARD LADDER'S RUNGS MUST STAY SYMMETRIC OR `reorg.c` LOSES ITS BRANCH REDIRECT (P31 S69; byte-proven ov_SC03_028/func_80184C90, 92 ins) <sub>L32818</sub>
- **§398** — ★★★ — `family_remap` CARRIES THE **SOURCE** TU's DECL ENVIRONMENT INTO A DESTINATION THAT ALREADY OWNS THOSE NAMES (P31 S69; measured 3 banked of 22) <sub>L32835</sub>
- **§398b** — ★★ — NAMING A SUB-EXPRESSION IN A LOCAL CHANGES WHICH PSEUDO SURVIVES; INLINE IT AT BOTH USE SITES (P31 S69; byte-proven ov_SC03_028/func_80183264, 93 ins) <sub>L32865</sub>
- **§399** — ★★★ — FOUR LEVERS FROM THE FINAL S69 ROUND (P31 S69; each byte-proven, none previously in the cookbook) <sub>L32892</sub>
- **§400** — ★★ — A BASELINE CHECK THAT CONFLATES "ABSENT EVERYWHERE" WITH "CHANGED UNDER US" SILENTLY DROPS NEW FILES (P31 S69; 8 files, one session) <sub>L32932</sub>
- **§401** — §401 <sub>L32967</sub>
- **§402** — §402 <sub>L33000</sub>
- **§403** — §403 <sub>L33024</sub>
- **§404** — §404 <sub>L33056</sub>
- **§405** — ★★★ — THE S70 WAVE HARVEST: 130 agents, 113 MATCH, and the laws they brought back <sub>L33092</sub>
- **§3-A.** — THE ORACLE HAS A HOLE: match_one cannot see a jump table (§405-A) <sub>L33098</sub>
- **§3-B.** — THE SCHEDULER DIALS (the dominant residual family this wave) <sub>L33108</sub>
- **§3-C.** — REGISTER ALLOCATION FROM C, WITHOUT PINS <sub>L33124</sub>
- **§3-D.** — INTEGRATION IS STILL THE BOTTLENECK, AND THE TU IS THE AUTHORITY <sub>L33140</sub>
- **§3-E.** — WHAT THE AGENTS REFUTED <sub>L33148</sub>
- **§406** — ★★ — THE PROLOGUE-WEAVE CLASS IS MECHANICAL AND LARGE (134 open stubs) <sub>L33158</sub>
- **§407** — ★★ — LATE-WAVE ADDENDA TO §405 (the last agents in) <sub>L33180</sub>
- **§408** — ★★★ — §406 REFUTED AS A SWEEP: THE SHAPE IS THE FAMILY, THE DISAGREEMENT IS THE DEFECT (P31 S71; 0 MATCH / 14 applied, 0 / 210) <sub>L33209</sub>
- **§409** — ★★★ — THE S71 JOURNAL-FUELLED WAVE: 100% FIRST-PASS MATCH, AND THE NINE LAWS IT BROUGHT BACK (P31 S71) <sub>L33261</sub>
- **§3-The** — nine laws this wave produced <sub>L33288</sub>
- **§410** — ★★★ — COPY THEN ACCUMULATE ON THE COPY: resolving the birthing-boost vs register-allocation dilemma (P31 S71; byte-proven `ov_SC04_015/func_8017EB78`, 98 ins) <sub>L33353</sub>
- **§411** — ★★★ — THE PACK MUST CARRY THAT FUNCTION'S OWN HISTORY (P31 S71; measured 38/39 vs 124/131) <sub>L33386</sub>
- **§412** — ★★★ — §323 CARVE BLOCKER 2 WAS A REGEX THAT COULD NOT SEE PAST `__attribute__` (P31 S71) <sub>L33424</sub>
- **§413** — ★★★ — DIFFICULTY IS THE RESIDUAL CLASS, NOT `nins` — ROUTE THE MODEL TIER OFF HISTORY (P31 S71, Drew) <sub>L33473</sub>
- **§414** — ★★★ — `parallel_gate` ON `main` IS A FALSE PASS, AND THE RULE WAS ALREADY WRITTEN DOWN (P31 S71) <sub>L33510</sub>
- **§415** — ★★ — A FILE-SCOPE DECL MAKES gcc-2.7.2 MERGE THE TU'S LATER *BLOCK-SCOPE* EXTERNS INTO IT (P31 S71; byte-proven `ov_SC04_011/func_80180B24`, 215 ins) <sub>L33547</sub>
- **§416** — ★★ — FOUR LEVERS FROM THE S71 OVERNIGHT LANE, none of which the cookbook held (P31 S71) <sub>L33572</sub>
- **§417** — ★★★ — A REGISTER PIN CAN BLOCK `jump.c`'s SELECT COLLAPSE, AND UNPINNING THEN EXPOSES A `cse` SKIP-BLOCKS MERGE (P31 S71; byte-proven `ov_SC03_013/func_8017E6F4`, 182 ins) <sub>L33605</sub>
- **§418** — ★★★ — TWO LOOP-STRUCTURE LEVERS: MAKE THE SECOND INDEX A GIV, AND KEEP A TABLE ADDRESS UNFOLDED (P31 S71; byte-proven `ov_SC04_016/func_8017DF8C`, 184 ins, 32 → 0 in seven compiles) <sub>L33632</sub>
- **§419** — ★★★ — WHEN A PIN IS IMPOSSIBLE, WIN THE local-alloc DENSITY CONTEST INSTEAD (P31 S71; byte-proven `ov_SC01_000/func_8017DD04`, 297 ins) <sub>L33658</sub>
- **§420** — ★★★ — A MULTI-CLUSTER SYMBOL REBASE, AND THE BARE-NAME DEDUP THAT HID THREE QUARTERS OF IT (P31 S71; 4 banked in 57 s) <sub>L33692</sub>
- **§421** — ★★★ — A `la $tN` + `addiu` PAIR CAN BE A **RELOAD** ARTIFACT THAT NO C SPELLING REACHES (P31 S71; byte-proven `md_SC07_003/func_801A293C`, 313 ins, 6 → 0) <sub>L33729</sub>
- **§422** — ★★ — QImode ARITHMETIC VIA `(u8)(x - K)`, AND `flag ^ 1` NEEDS ITS OWN TEMP (P31 S71; byte-proven `resident/func_800D06E8`, 344 ins) <sub>L33760</sub>
- **§423** — ★★★ — "MATCH IN ISOLATION + GATE REJECTS + CAUSE NOT DETERMINED" ⇒ GREP THE TU FOR A FILE-SCOPE TYPEDEF THE DRAFT ALSO CARRIES (P31 S71; byte-proven `ov_SC03_092/func_8017FA74`) <sub>L33780</sub>
- **§424** — ★★★ — EQUAL-PRIORITY STORES COME OUT **REVERSED**: sched1's LUID tie picks the LAST statement first (P31 S71; byte-proven `ov_SC07_006/func_801890FC`, 387 ins) <sub>L33807</sub>
- **§425** — ★★★ — `sb` ALIASES SCALAR GLOBALS WHILE `sh`/`sw` STRUCT STORES DO NOT, AND TWO MORE ALIAS/BOOST RULES (P31 S71; `md_MAIN_003/func_800CF3E8`, 467 of 469 ins, all four byte-verified from `-dS`/`-dR`/`-dl`/`-dr`) <sub>L33829</sub>
- **§426** — ★★★ — main's SWITCH FUNCTIONS WERE NEVER A CODEGEN WALL: ONE RODATA CARVE HAD BEEN MISSING SINCE PHASE 7 (P31 S72; 3 of the 11 "PROVEN gate-rejects" banked byte-identical in 14 s) <sub>L33855</sub>
- **§427** — ★★ — A HASH IS A CORRECTNESS ORACLE WITH ZERO DIAGNOSTIC CONTENT; PRESERVE THE RED ARTIFACT BEFORE ANYTHING REBUILDS OVER IT (P31 S72) <sub>L33931</sub>
- **§428** — ★★★ — A ZERO-BYTE CROSS-JUMP BARRIER: ADVANCE THE POINTER INSIDE EACH SWITCH ARM (P31 S72; `main/func_80026D64`, 218 ins, MATCH in 2 compiles) <sub>L33950</sub>
- **§428a** — ★★★ — TWO RESIDUALS THAT MOVE IN OPPOSITE DIRECTIONS UNDER EVERY LEVER USUALLY SHARE ONE CAUSE (P31 S72; `main/func_8001B0D4`, NEAR/53 -> MATCH; **my first answer here was WRONG and is kept below as the refutation**) <sub>L33988</sub>
- **§430** — ★★★ — A SHARED TAIL IS A LATE CROSS-JUMP MERGE, NOT A SOURCE `goto` — AND SPELLING IT AS ONE CAN INVALIDATE A LOOP (P31 S72; `main/CdReadSectorReadyCB`, 422/424 ins, verified with `cc1 -dL`) <sub>L34023</sub>
- **§431** — ★★★ — SPLITTING A 27,000-LINE TU AT ITS ORIGINAL BOUNDARIES: THE JTBL SPANS TELL YOU WHERE, AND THE COMPILER TELLS YOU WHAT CROSSES (P31 S72; `src/800.c` -> `800.c`/`800_b.c`/`800_c.c`, byte-identical with nothing banked) <sub>L34061</sub>
---
## L-number → section (if you cited `§1234` and the grep failed, it was a LINE number)
Index rows carry a `<sub>L…</sub>` anchor = the section's line in `docs/matching-cookbook.md`.
Notes routinely quote that as a section id. This table resolves it. Grep bait: `L-number`,
`line number cited as section`, `§ grep failed`.
| L | section | title |
|---|---|---|
| L30 | §3-How | to use this |
| L39 | §1 | Idiom catalog (asm pattern → C that produces it) |
| L41 | §3-I1 | Unsigned range check: `(x - lo) < (hi-lo)` → `addiu`+`sltiu` |
| L47 | §3-I2 | Byte mask forces `andi` even after `lbu` |
| L54 | §3-I3 | Division by a constant → magic multiply |
| L60 | §3-I4 | Runtime (variable) division → `divu` + zero-check `break` (NEEDS `--expand-div`) |
| L69 | §2 | Writing matching C (what makes gcc emit X) |
| L71 | §3-T1 | Loop pointer: top-of-body for `addu` induction, not constant-folded `addiu` |
| L78 | §3-T2 | Source statement order drives instruction scheduling |
| L85 | §3-T3 | Types |
| L90 | §3-T4 | Branch polarity: invert the source condition to flip gcc's chosen branch |
| L107 | §3 | When a diff is pure scheduling → decomp-permuter (harness built, Phase 6) |
| L128 | §3a | Escalation TIER above the permuter — web-research the compiler internals (HIGH VALUE, prov |
| L147 | §3b | §31-directed permuter mutation — bias the search over the class's levers (Phase 24 T5) |
| L190 | §4 | Flag/toolchain gotchas |
| L199 | §5 | Known hard-residual classes (instruction-identical, one byte-exact blocker) |
| L211 | §5a | Cross-jump tail-merge — gcc collapses two byte-identical blocks the original kept separate |
| L265 | §6 | Per-module optimization mixing — the -O0 boot module (Phase 7) |
| L273 | Detecting | the opt level (do this first) |
| L307 | Build | mechanism — per-file opt override (splat resegmentation) |
| L322 | §7 | PsyQ SDK types & symbols (the library-call prerequisite) |
| L339 | §8 | rodata island (compiler jump tables) — the `.data→.rodata→.data` sandwich (Phase 7) |
| L361 | §8a | rodata island in a flat OVERLAY — the tail sandwich, per matched jr-function (Phase 26 — P |
| L399 | §8a-pad | a trailing `.word 0x00000000` under a jtbl dlabel is `.align` PAD, not an entry (Phase 26 |
| L423 | §8b | MULTI-jtbl per overlay — the `ld_interleave --order` sandwich + the same-subseg cases (Pha |
| L456 | §8c | Splitting a TU means rebuilding its DECLARATION ENVIRONMENT, not moving text (Phase 26 ses |
| L502 | §8d | Templating a body INTO a TU must not CHANGE its declaration environment — demote the carri |
| L549 | §8e | The jtbl ALIGNMENT LAW + the pad-spec filter — multi-table .rodata spans (Phase 29, byte-p |
| L632 | §9 | Link real PsyQ library objects byte-exact (Phase 7 — GO proven) |
| L661 | §9.1 | Generalised per-object linker — `tools/psyq_link.py` (+ `psyq_link_lib.py`), 18/18 libcd b |
| L685 | §9.2 | Wire a library region into the build with NOLOAD — no data carving (`tools/psyq_link_regio |
| L704 | §9.3 | Make it the build: resegment + swap + resolve (`tools/psyq_integrate.py`, libcd DONE) |
| L731 | §9.4 | Integrating a SECOND library (libgs block 6 after libcd) — multi-library gotchas |
| L759 | §9.5 | Integrating a WHOLE multi-block library in one call (full libgs — Phase 7 session G) |
| L785 | §9.6 | Scaling library linking to the whole EXE (Phase 8 — 8 libs linked, 20%→50% byte-identical) |
| L821 | §9.7 | Binary-agnostic toolchain refactor (Phase 9) — the reusable pattern for Gen2 |
| L854 | §10 | Closing the regalloc/scheduling hard tail by hand (LZSS, Phase 7 session F — the full clos |
| L863 | §3-The | clean object-level metric (use this, not the permuter score, for jtbl/rodata functions) |
| L875 | Residual | A — commutative `|`/`&`/`+` result lands in the wrong source-operand register |
| L886 | Residual | B — a `return <const>` materialised late / merged instead of distributed per-site |
| L927 | §11 | Cross-binary dedup & code-sharing (Phase 11 — "one match unlocks many") |
| L945 | §3-The | mechanism: game-code dedup is SOURCE-LEVEL, not an object swap (R-D1, the key lesson) |
| L978 | Per-binary | toolchain provenance (R24) |
| L983 | §12 | Ultracode harvest — parallel-draft + byte-gate at scale (Phase 12, resident: 1.4%→71.7% in |
| L1075 | §13 | Add a location overlay — the canonical runbook (Phase 13; the Phase-15 fleet recipe) |
| L1081 | One-command | onboarding — `tools/new_overlay.sh <SCxx> <FILE_nnn>` |
| L1090 | §3-The | flat-blob overlay config (what the template encodes) |
| L1098 | §3-THE | NON-4-ALIGNED-OVERLAY GOTCHA (≈75% of the fleet; fixed in the template + Makefile, automat |
| L1110 | §3-The | A→B→C per-overlay workflow |
| L1127 | Dedup-credit | (§11) for overlays — two shapes |
| L1139 | Fleet | build — `make build-all` / `make check-all` |
| L1145 | §14 | Propagate a matched function across the fleet — `tools/dedup_propagate.py` (Phase 15) |
| L1188 | §14a | The fleet bulk run (Phase 15 — `--auto-from`, 947 REAL → 74,527; 3.82% → 22.14% in one pas |
| L1211 | §14b | Harvesting the UNMATCHED shared core — the match_one wall (Phase 15) |
| L1232 | §14c | Callee-signature-aware harvest — breaking the extern-type-conflict wall (Phase 15, T6) |
| L1288 | §14d | Deterministic recovery beats agent waves on the hard tail (Phase 15, the final-session fin |
| L1317 | §14e | Two hard-tail dead-ends (Phase 15 — documented so they aren't re-attempted) |
| L1332 | §15 | Struct-heavy shared-core pipeline (Phase 16) — empirical determinations (S0) |
| L1354 | §16 | Guided hand-matching the struct-heavy core (Phase 17 — beats the §15 brute-force) |
| L1395 | §17 | The compiler-quirk wall — the matching TOOLKIT (Phase 18; gcc-2.7.2 source + byte-gated) |
| L1403 | Register-allocation | ORDER (call-crossing $s0/$s1 swap) → FORCE it with register pins (byte-proven) |
| L1423 | §3-The | STEERABLE idioms (byte-confirmed this phase) |
| L1440 | §3-The | pipeline gotcha — match_one ≠ the gate; `sig_unify` is MANDATORY |
| L1447 | §3-The | LOOSE-TYPING wall is real for narrow params (Phase 16, reconfirmed) |
| L1454 | Strategic | conclusion — the match-% lever post-research |
| L1464 | §17a | The TOOLKIT at WAVE scale (Phase-18 Step-3b/Step-1 — measured) + the pipeline-integration |
| L1538 | §18 | Per-file `-O0` split inside an overlay/blob (Phase 19 T1) |
| L1616 | §19 | Scaling the toolkit waves — the recovery PIPELINE + the propagation CAP (Phase 19 T3) |
| L1651 | §20 | The wave-at-scale GATE CAP + residual-class verdicts (Phase 20) |
| L1656 | §3-THE | CAP: at this tail the match_one→gate gap is the LOOSE-TYPING CALL-GRAPH wall (not cheap pl |
| L1673 | Diagnostic | lesson: a failed in-TU build leaves a STALE `.o` |
| L1679 | §3-NEW | / CONFIRMED residual classes (this session) |
| L1700 | Operational | gotchas (cost real time) |
| L1708 | What | WORKED — the Phase-20 reusable wins |
| L1720 | Phase-20 | RESOLUTION — `tools/cast_call_sites.py` BUILT + the cap re-diagnosed (R14, byte-proven) |
| L1771 | §21 | wave-distilled idioms (Phase 21) |
| L2024 | §22 | DEF-side loose-typing recovery + grinder blacklist (Phase 21) |
| L2051 | §23 | Giant `func_80153E00` cracked (scalar-data CAST); BUT most giant drafts are STALE+INCOMPLE |
| L2104 | §24 | The `ov_SC01_077_a.c` split-file vein: split-aware propagation, but loose-typing-gated (Ph |
| L2151 | §25 | The "schedule" class is mostly COALESCING (pin-crackable), not scheduling; + the gate two- |
| L2163 | §3-The | crack: the residual was gcc-2.7.2 COPY-COALESCING, not the instruction scheduler |
| L2179 | §3-The | genuine scheduler — `rank_for_schedule` (sched.c), for when it IS scheduling |
| L2188 | §3-The | genuine schedule WALLS (do NOT re-grind — stub) |
| L2196 | §3-h | _exact OVER-COUNTS ×134 — verify shareability before crediting a class's "reach-134" (R14) |
| L2208 | §3-The | gate two-stage — sig_unify is a FALLBACK, not unconditional (`gate_stage.py`, §19 folded i |
| L2218 | §26 | The cheap close=0 recovery lever is EXHAUSTED; `idiom_loop --assess` was DOUBLY inflated ( |
| L2224 | §3-The | `_a` close=0 recovery banks 0/20 — same def-side wall as MAIN (0/40) |
| L2252 | Where | this leaves the reach-134 tail (cont.6 option-3, now CONFIRMED byte-backed) |
| L2278 | §27 | Giant matching recipe (Phase 21 cont.7b — validated on func_80176D94, 152 ins) |
| L2344 | §28 | Banking a "close=0 gate-rejected" giant: the canonical-extern recovery (Phase 22 T1, byte- |
| L2364 | §28a | decomp.wiki GCC patterns worth trying on BFM giants (decomp.wiki/compilers/GCC, raw at dec |
| L2371 | §28c | The close=0 recovery is NOT fully exhausted (§26 corrected, R14); + the dedup_propagate re |
| L2376 | §28b | The struct-walled close=0 giant (§28 case #3) IS bankable: the engine_types.h type-lift (P |
| L2385 | §28d | The "macro-extern-injection" lever: freeing reach-134 inline matches dedup_propagate skips |
| L2393 | §29 | Reasoning-model (GLM5.2) DEF-side reconciliation idioms + the wall's hard limit (Phase 23 |
| L2401 | §30 | Fable5Max cracks §20/§10 "unsteerable" from the gcc SOURCE: store-vs-load is a `/s` aliasi |
| L2413 | §30a | §30 generalizes to the FULL near-miss backlog (via STANDARD Opus agents, not just Fable5) |
| L2421 | §31 | THE gcc-2.7.2 CODEGEN MAP: pass → residual → C-lever catalog (Phase 23; 4 Fable5 agents re |
| L2441 | §32 | The region-a CAMERA-GIANT idiom set: struct-base hoisting + 4 sibling levers (Phase 24 T7, |
| L2453 | §33 | Automating the giant decl-reconcile: `tools/reconcile_decls.py` (the DATA analog of §20's |
| L2473 | §34 | The `func_80138ED0` giant crack: gcc-2.7.2's **3-qty sort bug** + the **zero-byte asm allo |
| L2490 | §35 | The region-a sibling-giant harvest: difficulty ≠ $s-reg count (it's global-array hoisting) |
| L2506 | §36 | Fable5 giant-crack levers (Phase 24 T7 Fable5 batch; accumulates as each lands — full RTL |
| L2525 | §37 | The T7 §G giant endgame: 6/8 cracked, meta-laws + transferable levers (Phase 24, 2026-07-0 |
| L2546 | §38 | The WHALE `func_80144B9C` (770 ins): the -O0 struct-assign memcpy idiom + the -O0 reach-13 |
| L2556 | §39 | The ×1→×134 giant-endgame: propagate a matched **-O2** giant via the NATIVE DEFINE-macro p |
| L2572 | §40 | Structural families: the MECHANICAL symbol-remap (crack one exemplar → remap the rest, ~0 |
| L2620 | §40a | The DECL-RECONCILE pass (type-lift so remapped drafts compile in the sibling TU) (Phase 25 |
| L2653 | §40b | The reloc-tracker blind spot: the indexed-global idiom that hid the "reach-1 tail" (Phase |
| L2695 | §40c | The h_seq per-sibling reconcile: templating a reconcile-class crack ×134 (Phase 26 Task 8, |
| L2712 | §31-triage | R17 applies to CODEGEN residuals, never to a compile ERROR (Phase 26 session 7, Drew asked |
| L2729 | §41 | The DEF-SIDE canonical-sig wall: mechanically banking a drafted giant past `conflicting ty |
| L2788 | §41a | v3.1: the def-side wall was ~71% TOOL-shaped — the five measured defects + the laws that d |
| L2843 | §41b | T7 execution: the object-only probe OVER-counts BANKABLE by two link/rodata classes (Phase |
| L2873 | §41c | T7-M2: the ×134 def-side-wall sweep via per-sibling RE-reconcile (Phase 25, 2026-07-10; 4, |
| L2892 | §41b | addendum — M4 "reconcile_decls" tier is ALSO a probe over-count: 0/8 mechanical (Phase 25 |
| L2912 | §41d | `void`→`s32` is NOT always byte-neutral: gate the RAW draft FIRST (Phase 26 session 6, byt |
| L2934 | §42 | The F-band ≤28 regalloc crack wave: register-pin/DENSITY levers beat the permuter (Phase 2 |
| L2987 | §42a | addendum — wave 2 (residuals + 29-100 band): iso-MATCH ≠ real-TU bank, the memcpy→struct-a |
| L3028 | §42b | addendum — wave 3 (Max, 2026-07-10c): THE STALE-OBJECT GATE TRAP + the read-global `&`-cas |
| L3067 | §42c | addendum — wave 3 (Max orchestrator + CORRECTED Ultracode fan-out, 2026-07-10c): the real- |
| L3116 | §42d | addendum — wave 4 (rtu_match fan-out over the mapped frontier, 2026-07-10c): 24/26 MATCH, |
| L3155 | §42e | propagating a CRACK ×134: the def-finder bug + the byte-drift residual (the "remap-fail" m |
| L3229 | §43 | The K&R s16-param definition DISSOLVES the "narrow-param wall" for by-value register args |
| L3276 | §44 | The Phase-25 cheap-Opus giant batch: 5 structural levers + the §43 extension (2026-07-11, |
| L3332 | §45 | The flagship `func_80133CD4` crack (399 ins ×134): the merged-variable permutation-breaker |
| L3347 | §46 | The `func_80178D40` crack (890 ins ×134, the heaviest core in the game): four LOOP-STRUCTU |
| L3399 | §47 | The live-length SLIDER: splitting a global.c allocno-priority TIE with one zero-byte asm ( |
| L3439 | §48 | The 12-core jr crack wave: the ALLOCNO-PRICING dials and the EBB rule (Phase 26 session 8, |
| L3447 | §3-A. | ALLOCNO-PRICING DIALS — move a value into the register you want, byte-neutrally |
| L3478 | §3-A4 | SINK THE CONSUMER CALL INTO THE ARMS (the inverse of A1; `func_8016AB6C`, byte-proven) |
| L3502 | §3-B. | THE EBB RULE — the general form of §46-L2 |
| L3518 | §3-C. | TYPE- AND SHAPE-DRIVEN CODEGEN (the C type literally selects the addressing mode) |
| L3542 | §3-D. | THE CROSS-JUMP RATCHET (the sharpest new trap — `func_80131340` L-C) |
| L3552 | §3-E. | Meta |
| L3561 | §49 | The LUID DIAL: a zero-byte SCHEDULING dial (the sched.c analogue of §47) — `func_8017A4AC` |
| L3610 | §50 | Refinements that BOUND §47/§48 (from the `func_80135EB0` wall, 21→6; Phase 26 session 8) |
| L3664 | §51 | TOOLING INTEGRITY: the silent skip, and how to hunt it |
| L3670 | §51a | The bug class |
| L3686 | §51b | Why the byte-gate cannot save you |
| L3696 | §51c | THE METHOD (do not audit by reading the regex) |
| L3711 | §51d | THE LAWS |
| L3773 | §51e | The false-wall pipeline (why this is not just hygiene) |
| L3789 | §51f | Checklist for any new corpus-scanning tool |
| L3803 | §51g | When the thing you are scanning has a GRAMMAR, parse the grammar (`tools/cdecl.py`) |
| L3947 | §52 | The WALKER-FAMILY skeleton: 6 regalloc-order levers + a deeply-characterized intrinsic wal |
| L3958 | §3-The | 6 levers (the "walker-family skeleton" — apply to the 12 siblings; levers 1-5 retire ~half |
| L3979 | §3-Why | the wall is (probably) intrinsic |
| L3993 | §52a | The regalloc sibling wave: new levers + two new wall classes (cheap-Opus applying §52, 202 |
| L4031 | §52b | Sibling wave 2: more de-pin levers, a third wall class, and the match_one→whole-binary gap |
| L4062 | §53 | SWEEP A FAMILY WITH THE TOOL ITS EXEMPLAR NEEDED: the jr/switch carve, and how omitting it |
| L4067 | §3-The | case |
| L4079 | §3-Why | 0/8 was structural, and predictable from two words |
| L4096 | §3-The | rule |
| L4112 | §3-The | meta-lesson (R35, and why this one is expensive) |
| L4127 | §55 | Core-crack wave levers + the GATE-ORCHESTRATION law (Phase 29 T3, 13-agent ultracode wave, |
| L4132 | §55a | New byte-proven levers (each from a banked or near draft) |
| L4156 | §55b | THE GATE-ORCHESTRATION LAW (3 traps, ~3.5h lost; all recovered, 0 data lost) |
| L4175 | §55c | Sizing the propagate: a TARGETED propagate is ~4 min/core, and "it's slow" was a BROKEN-TR |
| L4197 | §54 | `--fix-def-sig`: the member's CANONICAL DECLARATION is a build step too (tiny-IMM mega-poo |
| L4221 | §56 | Banking a hand-drafted GIANT into its exemplar TU: self-contained draft vs live-TU decls, |
| L4266 | §56b | PROPAGATING an h_seq giant: the exemplar's externs MUST be fleet-canonical, not the draft' |
| L4290 | §57 | The SELF-decl normalize: the sibling's OWN caller declares the templated fn divergently (t |
| L4337 | §57a | Two NSD corrections + the SURGICAL-ONLY law + the honest broad-sweep yield (Phase 29, 2026 |
| L4377 | §58 | match_one MATCH ≠ BANK: the four blind spots + the crack-wave reconcile-before-bank law (P |
| L4411 | §59 | Three h_seq sweep-residual classes match_one/the-exemplar-bank don't reveal (Phase 29 crac |
| L4441 | §60 | Classify the residual, don't rank it: the deterministic residual→class classifier and what |
| L4465 | What | it measured — the whole open backlog, byte-grounded |
| L4484 | §3-Two | corollaries worth remembering |
| L4497 | §3-The | parallel-probe race this surfaced |
| L4506 | §60a | What the first DIRECTED grinder run exposed (Phase 29 Task-13B, 2026-07-21) |
| L4544 | §60b | The plateau autopsy's verdict: a `partial` drift is a WRONG DRAFT, not a missing transform |
| L4579 | §61 | Task 14: the gate ladder's missing stage is the ARITY pre-pass, and it is TU-side not draf |
| L4640 | §61a | The Task-5 wave: 11/12 MATCH, 0 banked — three DISTINCT integration walls, each now named |
| L4692 | §61b | The jtbl gate stage: built, and the ORDERING law it exposed (Phase 29 Task-14 stage 4, 202 |
| L4747 | §61c | The jtbl bank is INCREMENTALLY valid and CLEAN-INVALID (Phase 29, 2026-07-21) — the blocki |
| L4813 | §61d | The undo was eating the tree: two tools, one defect, invisible to the byte-gate (Phase 29, |
| L4867 | §62 | The jtbl RECONCILE must also follow the carve: the post-carve draft reconcile (`harvest_ve |
| L4911 | §63 | The fresh-138 DEF-SIDE blocker: fix the HEADER decl, not the draft (`fix_header_decl.py`, |
| L4942 | §64 | The §20 type-lift's three laws: fold the tagged typedef, check VISIBILITY, and strip only |
| L4991 | §64a | VARIANT types: UNIQUIFY the camps, do not reconcile them (`uniquify_type.py`, Phase 29 SES |
| L5034 | §63 | UPDATE (Phase 29 SESSION-14) — `fix_header_decl`'s "SAFE" verdict is FLEET-BLIND; it MUST |
| L5049 | §65 | The stranded-draft recovery: BLAST-RADIUS TIERS, and the per-overlay de-macroize that refu |
| L5064 | §65a | The blast-radius taxonomy (makes §61's law structural instead of remembered) |
| L5079 | §65b | The escape: de-macroize the instantiation, don't touch the shared header |
| L5115 | §65c | `rtu_match` MATCH → bank held 13/13 on self-decl, but broke on the FIRST callee-decl case |
| L5125 | §65d | Existing-ladder baseline, measured (do this before building a recovery stage) |
| L5135 | §65e | Two oracles, and the disagreement is the finding (R34 in practice) |
| L5152 | §65f | The de-macroize lever's BOUNDARY, measured: byte-neutral 14 times of 15, and the 15th is w |
| L5173 | §65g | Where the cheap levers STOP: the local-type and in-TU-self-decl classes did not yield |
| L5193 | §66 | Exercise a banking driver's SUCCESS path before pointing it at a wave: the free re-bank te |
| L5215 | §66a | The widest write in a pipeline is the one most likely to be UNDECLARED |
| L5234 | §66b | A metric parsed out of another tool's prose goes NULL silently when the label changes |
| L5251 | §66c | Before a wave, verify the FUEL exists; an "already attempted" set built from the wrong dir |
| L5279 | §66d | The permuter⇄reader loop: alternate a random search with a byte-verified idiom, and let `r |
| L5314 | §66d-1 | What transfers between giants is the LOOP, not the PIN |
| L5323 | §66d-2 | Two operational sharp edges |
| L5334 | §66d-3 | Read the ILS per-cycle SERIES, not its final best: a repeated score and a still-falling on |
| L5349 | §67 | The arg-copy PLACEMENT lever: launder a parameter into a fresh pseudo AT the statement whe |
| L5439 | §67a | Run the symbol-set guard BEFORE you pay for a gate (`tools/symcheck.py`, Phase 29 SESSION- |
| L5472 | §66d-4 | "ILS converged" means converged FOR THAT WEIGHT PROFILE, not a floor (amends §66d-3; Phase |
| L5525 | §66d-5 | `residual_class`'s "structural ⇒ permuter CPU is waste" is WRONG for schedule permutations |
| L5558 | §68 | A comment-only line halted the extern scan, and the skip label blamed the type cap (Phase |
| L5603 | §69 | How to attack a behemoth: map it, don't draft it (Phase 29 SESSION-18, `func_80183814`, 5, |
| L5653 | §70 | The giv-init base register: walk the PARAMETER, not a copy of it (Phase 29 SESSION-18, `fu |
| L5694 | §71 | Before mapping a giant, look for an already-matched SIBLING beside it (Phase 29 SESSION-18 |
| L5760 | §72 | A `register __asm__` pin is a PREFERENCE, not a reservation (Phase 29 SESSION-18, `func_80 |
| L5784 | §3-The | honest fix was source-level and cheap |
| L5794 | §3-Giv | record order (the §70 family) |
| L5800 | What | is left, and what is byte-recorded as SPENT |
| L5817 | §73 | A def-side self-decl conflict has TWO axes: RETURN (fleet widen, T2) and PARAMS (casts at |
| L5856 | §74 | Auditing a pinned draft: the §72 hazard is CALLER-SAVED pins spanning a call, and only the |
| L5900 | §75 | A propagation cap is usually a MINORITY-SPELLING SOURCE OVERLAY, not a wall: census the ca |
| L5959 | §75a | The exclusion classes, enumerated with named causes (Phase 29 SESSION-19, the 134-binary ` |
| L5982 | §75b | A body's preamble can carry `#define`s, not just `extern`s; extraction lifts only the exte |
| L6031 | §75c | Class-B's remedy is the FULL §17a-1 PAIR (decl **and** call-site cast); a decl-only fix mo |
| L6062 | §76 | The allocno CLASS (local vs global) is the dominant regalloc lever, and C reaches it ONLY |
| L6071 | §3-The | mechanism, with citations |
| L6091 | §3-The | attribution primitive (use this before calling anything a scheduling residual) |
| L6098 | §3-Two | diagnosis traps this function proved |
| L6108 | Practice | Practice |
| L6118 | §77 | Every extraction tool carries a NARROW hard-coded preamble set; anything outside it silent |
| L6158 | §3-The | CANDIDATE gate and the REAL gate need DIFFERENT preambles — keep the difference out of the |
| L6208 | §78 | A LENGTH drift can be a register grant in disguise; and `fold` never leaves a literal firs |
| L6214 | §3-The | drift was an allocation decision, not missing code |
| L6245 | §3-The | economics |
| L6254 | §79 | For a 0-callee giant, fingerprint by DATA symbols (§71 cannot fire); and the STACK-SLOT OR |
| L6260 | §71 | has a blind spot, and this is it |
| L6274 | §3-NEW | LEVER — the frame layout reads back the original declaration order |
| L6285 | §76 | confirmed at scale, and a pin nuance |
| L6294 | §3-The | residual, and the honest read |
| L6304 | §80 | A do-not-re-buy entry is scoped to its BASE, not to the function; and the pin's hidden cos |
| L6325 | §3-The | pin's hidden cost, with the citation |
| L6336 | §3-The | flagged "#1 move" LOST — and why the failure is informative |
| L6346 | §78 | 's attribution primitive, run and reproduced |
| L6352 | Cold-start | economics, now complete |
| L6357 | §81 | Banking a jr (jump-table) function: the 3-step carve chain, and why `match_one` cannot see |
| L6388 | §3-The | defect this exposed: a shared type that is present but invisible |
| L6404 | §82 | Two source-shape oracles from behemoth #6: a duplicated `addiu $aN,$sp,K` across a `jal` m |
| L6409 | §3-1. | The inlined-helper signature |
| L6423 | §3-2. | Scalar vs aggregate decides *when* the slot is allocated |
| L6435 | Also | reproduced on this function |
| L6439 | §3-And | the banking footnote (§75a class A, one line) |
| L6446 | §83 | The parameterised-repeat law, the spill-area trap, and why a per-case edit cannot move a p |
| L6453 | §83a | READ THE HEADLINE NUMBER CORRECTLY: a LENGTH drift makes `match_one`'s count meaningless |
| L6461 | §83b | THE LEVER: find the parameterised REPEAT before decoding case-by-case |
| L6479 | §83c | TRAP: a "dead local" in a prior draft may be gcc's OWN spill area |
| L6486 | §83d | CSE's quantity budget is WHOLE-FUNCTION, so a local rewrite cannot fix a local symptom |
| L6500 | §83e | §80 vindicated again, on the same day it was written |
| L6506 | §84 | The DERIVED-OFFSET remap bug: a hand-computed literal that encodes the DISTANCE between tw |
| L6511 | §3-The | construct |
| L6529 | §3-Why | it survived every candidate gate |
| L6544 | §3-THE | FIX IS MECHANICAL — the tool already holds the answer |
| L6552 | Scope | , measured (do not over-generalise — §80) |
| L6562 | §3-Two | ladder lessons banked with it |
| L6573 | §85 | The RETURN-axis fleet widen is ALL-OR-NOTHING: widening the shared header alone guarantees |
| L6578 | §3-The | conflict |
| L6586 | §3-THE | FAILURE MODE — widening only `engine_core.h` is worse than not starting |
| L6593 | §3-The | precondition, and how to check it in one grep |
| L6601 | §3-Do | the WHOLE axis in one edit, then R22 once |
| L6610 | Reading | , for the next person |
| L6623 | §86 | Pinned-exemplar templatability is a PER-FAMILY property, not a per-member rate; and the §4 |
| L6625 | §3-The | guard refuses a class that largely works |
| L6634 | §3-THE | LAW: all-or-nothing PER FAMILY |
| L6661 | §3-Why | the two live families differ from the three dead ones — the open question |
| L6667 | §87 | `match_one` COMPILES but never LINKS, so an unresolvable data symbol reads as MATCH; and s |
| L6683 | §3-The | blindness ladder, now complete — FOUR classes `match_one` cannot see |
| L6693 | Consequence | for the backlog ledger |
| L6700 | §3-The | cheap discriminator, before spending a sweep |
| L6708 | §88 | `cross_jump` will not merge a common suffix containing a CALL; and §78 is scoped to ORDERE |
| L6713 | §88a | repeated CALL-shaped blocks are left UNMERGED; call-free tails are merged for you |
| L6720 | §88b | the `slti` literal-position law (extends §78 to comparisons) |
| L6735 | §88d | BANKING ORDER: run the §81 carve chain BEFORE banking, never after |
| L6742 | §88e | a wrong diagnosis, refuted properly (the model for how to treat an inherited lever) |
| L6752 | §88f | the missing rung: a RELOCATION gate between `match_one` and the binary |
| L6760 | §89 | Two throughput rules the project already had written down and was not following (Phase 29 |
| L6766 | §89a | MEASURE the write set; do not assert its tier (`tools/blast_radius.py`) |
| L6779 | §89b | the parallel gate farm existed; the family path could not reach it (`tools/sweep_parallel. |
| L6792 | §3-The | standing sequence |
| L6800 | §90 | Five tool-integrity laws from one session, each of which changed an answer (Phase 29 SESSI |
| L6806 | §90a | A comparison tool MUST share its reference oracle's index space, exactly |
| L6823 | §90b | "Byte-neutral" is not "wanted": undo on the SUCCESS path too |
| L6833 | §90c | A library-callable function must FAIL CLOSED on an unconfigured module |
| L6844 | §90d | Do not measure a live wave's drafts (§87 in real time) |
| L6852 | §90e | An agent's CONCLUSION and its EVIDENCE fail independently — re-derive the premise, not the |
| L6876 | §91 | A structure-TRANSFER is only valid where the structure corresponds: the `--like` role trap |
| L6905 | §3-The | three-hypothesis trail, because two of them were wrong and the wrongness is instructive |
| L6925 | §92 | Conforming a DECLARATION: pointer changes are caller-neutral, scalar-WIDTH changes are not |
| L6956 | §93 | `set -o pipefail` attributes a pipeline failure to the LAST stage, not the failing one (Ph |
| L6981 | §94 | A family sweep's `0/N` is a TYPE-CARRY failure until proven otherwise: lift the exemplar's |
| L7017 | §95 | `reconcile_tu` dropped the SIBLING declarators of a multi-symbol `extern` line (Phase 29 S |
| L7052 | §96 | The same rewrite, one shape down: `reconcile_tu` matched statements to lines by TEXT, so e |
| L7100 | §97 | The gate's own tree hygiene: a refused carve, an unchecked recovery, and a snapshot that c |
| L7147 | §98 | `conform_decls` had three defects, and only the third needed R22 to find (Phase 29 SESSION |
| L7201 | §99 | The narrow-param wall is a DEF-side problem with a ZERO-blast-radius fix: convert the defi |
| L7224 | §3-Two | `reconcile_tu` bugs found underneath, one introduced while fixing the other |
| L7250 | §100 | Prefer the DRAFT-LOCAL fix: a type only one function uses belongs in its BODY, not in a sh |
| L7279 | §101 | The STALE DEFAULT class: a guard whose cause was removed is a silent skip wearing a safety |
| L7306 | §102 | A PLUMBING verdict can MASK a DIFF; and K&R is not always a codegen change (Phase 29 SESSI |
| L7341 | §103 | A FILE-scope `extern` in a shared overlay TU is a GLOBAL constraint on every LATER functio |
| L7429 | §104 | Two silent-skip defects in one scan: match on MASKED text, emit from the ORIGINAL (Phase 2 |
| L7465 | §105 | A gate's revert must survive an EXCEPTION, not just a failure (Phase 29 T53, `jtbl_family_ |
| L7504 | §106 | Persist the MEASUREMENT, derive the POLICY: a stored route let a stale file out-vote the l |
| L7547 | §107 | A lever wired into ONE gate path is a lever most families cannot reach (Phase 29 T56, `fun |
| L7585 | §108 | Diagnosing a family `0/N`: the four causes, and the third opt-in lever (Phase 29 T59) |
| L7634 | §109 | Conforming a definition to a shared header: fix the NAMES, then check the RETURN precondit |
| L7674 | §110 | A unit must define exactly ONE function, and "ends in `;`" does not tell you which line de |
| L7715 | §111 | The distinct-code metric is not noisy: a family pays it only if its members are byte-VARIA |
| L7764 | §112 | A macro-scoped declaration only collides where the macro is INSTANTIATED (Phase 29 T67/T69 |
| L7810 | §113 | An ARITY blocker only exists if the macro CALLS the function; an address-taken use has no |
| L7842 | §114 | The THIRD decl axis: a CALLEE the draft declares differently from the target TU (Phase 29 |
| L7884 | §115 | A `func_XXXXXXXX` predicate rots by design: the same name-form assumption in THREE places |
| L7911 | §116 | Optimization level is a property of the FILE, not the function: read a family 0/N against |
| L7929 | §3-The | fix moves the DEFINITION, not the stub — and here is why the obvious shortcut fails |
| L7960 | §117 | Spell the sibling's symbol from the SIBLING's address, not the exemplar's kind (Phase 29 T |
| L7987 | §3-Why | it survived so long: a MASKED oracle will MATCH a wrong symbol |
| L7997 | §118 | Ordinal (positional) immediate resolution: compare C tokens to the DIFFERING asm uses (Pha |
| L8031 | §119 | Two levers on the SAME axis, opposite directions: test the off-diagonal (Phase 29 T89) |
| L8060 | §120 | Uniquify draft-defined TYPE names; and check which of N staging sites you actually patched |
| L8071 | §3-Do | NOT "strip the duplicate typedef" — it breaks the extern that uses it |
| L8077 | §3-The | wiring trap that cost two attempts |
| L8095 | §121 | Synthesise externs for macro-DEFINED callees from the macro's own definition head (Phase 2 |
| L8118 | §122 | GATE RAW BEFORE TRANSFORMING; the undo belongs to the WRITER, as a per-edit journal (P30 T |
| L8150 | §123 | PROPAGATE A FAMILY WITH THE TOOL ITS TIER NEEDS: `dedup_propagate` is h_exact-only; its re |
| L8187 | §124 | A "not matched" verdict can mean the definition is there under a DIFFERENT C NAME: the asm |
| L8232 | §124a | a family sweep's `0 matched-exemplar families` may be a FILTER, not a wall |
| L8240 | §125 | Split the CARVE from the BODY before calling a jr residue a wall — and measure it by SHA f |
| L8247 | §3-The | method (keep this) |
| L8257 | §3-The | instrument rules that make its answer trustworthy (this is where I failed) |
| L8272 | §3-The | corrected results (each SHA-verified, from a clean tree, restore re-verified) |
| L8282 | §3-Two | further notes worth keeping |
| L8291 | §3-The | meta-lesson |
| L8298 | §126 | The carve-within-a-carve: an ADDRESS RANGE is not an OPTIMIZATION REGION (P30 T2, byte-pro |
| L8313 | §3-The | finding: opt level is per FILE, so the file's contents must be opt-HOMOGENEOUS |
| L8324 | §3-The | instrument trap that hid it (and it is §124's shape again) |
| L8333 | §3-The | mechanics |
| L8351 | §126a | a bare `except: continue` around a coverage-asserting oracle re-creates the silent skip (P |
| L8383 | §127 | The `-O0` regime: the CONSTANT-OFFSET FOLD, and why `-O0` needs its own idiom set (P30 T3 |
| L8390 | §3-The | idiom they kept re-deriving: the constant-offset fold |
| L8401 | §3-The | rest of the `-O0` regime (write PLAIN C, and mean it) |
| L8411 | §127a | §71 (sibling-first) is the strongest `-O0` lever, and it beats the index |
| L8420 | §127b | the knowledge was in a SOURCE COMMENT, not the cookbook |
| L8427 | §128 | A raw NUL in C source makes grep SILENTLY SKIP the file (P30 S28, 137 files) |
| L8459 | §128a | a negative control must corrupt a SCRATCH COPY, never the tracked file |
| L8471 | §129 | Post-carve, `rtu_match`/`match_one` COUNT THE JUMP TABLE AS INSTRUCTIONS; and a carve must |
| L8475 | §129a | the target instruction count is INFLATED after a carve |
| L8496 | §129b | never commit a carve whose owner is still a stub (it strands the carve) |
| L8511 | §3-The | real blocker underneath, for the record |
| L8520 | §130 | An INCREMENTAL build can report BYTE-IDENTICAL for a change the CLEAN build cannot even LI |
| L8557 | §3-The | diagnostic ladder that finally located it (reusable) |
| L8567 | §131 | The jtbl OVER-SPAN: `sltiu N` is ground truth in BOTH directions, and the zero-word rule o |
| L8604 | §132 | The `JR-PAIR-IN-ONE-O0-OBJECT` "wall" was TWO instrument defects: a merged-double span the |
| L8613 | Defect | 1 — a pre-§8e MERGED DOUBLE is not a single-table predecessor |
| L8631 | Defect | 2 — `as` writes a corpse and nothing deletes it |
| L8641 | §3-The | fingerprint, and the 30-second ladder that found it |
| L8662 | §3-The | transferable rule |
| L8669 | §132a | `--like` is for a sibling with NO record; against one that HAS a record it over-derives (P |
| L8694 | §132b | When the span's already-matched owner is ITSELF multi-switch: `--span-rel` (P30 S1, `func_ |
| L8719 | §133 | The DEFAULT-FILTER class: three times in one session, a tool silently answered a narrower |
| L8745 | §134 | MULTI-LINE BLINDNESS: one root cause, four faces, in `family_remap`'s preamble scanner (P3 |
| L8799 | §135 | Six byte-verified gcc-2.7.2 idioms from the P30 S6f-h waves (and the two-lane wave shape t |
| L8804 | §3-The | codegen idioms |
| L8838 | §3-The | integration idioms (these decide whether a byte-correct draft BANKS) |
| L8853 | §3-The | wave shape that produced these |
| L8871 | §136 | The LOCAL-VARIABLE lever: how many C locals, at what scope (P30 wave 4a, 25 byte-verified |
| L8887 | §3-The | splitting/merging rules (each closed a residual, byte-gated) |
| L8913 | §3-The | type-form rules |
| L8946 | §3-The | scheduling rules (refining §135-2 and §135-4) |
| L8975 | §3-The | declaration surface (integration, not codegen) |
| L8987 | Wave | economics (measured, for the next batch's sizing) |
| L9010 | §136a | Blocker capture: classify on the OUTPUT, never on the exit status |
| L9067 | §136b | A prior wave's "genuine byte-DIFF" verdict is NOT reliable evidence (4 of 4 refuted) |
| L9103 | §136c | SIBLING-FIRST is a DERIVATION shortcut, not just a conflict fix (the fastest route in a fa |
| L9128 | §136d | Four gcc-2.7.2 levers the redraft lane found (each closed a residual no other lever moved) |
| L9172 | §136e | §136c's PRECONDITION, and two more symptom keys (wave 4b batch 3) |
| L9220 | §136f | Two declaration sub-cases the reconcile lane surfaced (lane now 15/15 lifetime) |
| L9245 | §136g | When the index points at the WRONG lever: two byte-refuted routings (func_801863B4) |
| L9274 | §136h | CORRECTION: the zero-crack pool does NOT "refill with cheap work" (my error, byte-measured |
| L9304 | §136i | The drafter model LADDER: Haiku → **Sonnet** → Opus → Fable5 (Drew, 2026-08-03) |
| L9336 | §136j | The failure MIX flips with function size (measured across four bands, one session) |
| L9378 | §137 | REGALLOC-PERM is a TWO-COMPILE ARITHMETIC PROBLEM, not a permuter job |
| L9420 | §137a | A gate verdict has a TIMESTAMP; re-check it against the draft's mtime |
| L9449 | §138 | The propagation lanes: a gate refusal is a DECLARATION, and which lever you owe depends on |
| L9455 | §3-The | triage, cheapest first |
| L9507 | §3-The | DEFINITION-side alias is the only escape when the fleet canon disagrees on a promoting par |
| L9515 | Rank | the lane by measured concentration, not by class count |
| L9524 | THREE | carry variants hide in one "CARRY-FIXABLE" bucket — and they need different fixes |
| L9560 | §134 | again, in a second tool — and the waiter rule corrected |
| L9580 | STEP | 0 of sibling-first: grep `src/` for a distinctive LITERAL from the `.s` |
| L9599 | Reconciling | a gate-refused draft: which way you edit depends on WHERE the TU's decl is |
| L9628 | §139 | A GATE THAT GREPS FOR VERDICTS MUST ASSERT 1:1 ACCOUNTING; and a `--src` filter must not s |
| L9660 | §3-The | generalisation — three corollaries worth more than the bug |
| L9677 | §3-And | the inverse-lookup trap, same session |
| L9694 | §140 | A METRIC IS NOT A MEASUREMENT UNTIL IT IS REPRODUCIBLE FROM THE COMMITTED TREE (P30 S1e: a |
| L9714 | §3-The | three-line proof (do this before diagnosing any metric movement) |
| L9723 | §3-The | two instrument defects it exposed |
| L9743 | §3-The | same swallow, twice more, in the integration spine |
| L9754 | §3-Two | wrong mechanisms I chased first, and why they were wrong |
| L9774 | §141 | The §134 class is CLOSED: every line-shape decision now routes through `cdecl._mask` (P30 |
| L9812 | §142 | An open stub whose `h_exact` class is MATCHED elsewhere is FREE. Propagate the body; do no |
| L9824 | §3-The | measurement (do this before any wave; it is ~20 lines and needs no builds) |
| L9839 | §3-The | trap that hid it — SAME FUNCTION, TWO ROUTES, ONLY ONE IS FREE |
| L9848 | Route | selection (why `--addr` sometimes says "nothing changed") |
| L9856 | §3-And | the report-vs-bytes lesson attached to it |
| L9868 | §143 | `cast_call_sites` read a RETURN STATEMENT as a prototype and deleted it. A 0/39 sweep beca |
| L9922 | §144 | THE LITERAL'S SPELLING PICKS THE IMMEDIATE ENCODING (P30 S40 wave 1, `func_801822E0`) |
| L9961 | §145 | Three loop/combine levers from the S40 wave-2 drafters (16/16 match_one) |
| L10011 | §146 | RE-MEASURE A WALL BEFORE YOU RESPECT IT. Both "permanent" giants fell to drafts already on |
| L10022 | §3-Why | a correct draft can read as an intrinsic wall |
| L10034 | Then | propagation returned 0/137 TWICE — both times a missing TYPE |
| L10043 | §3-Two | errors of mine, both instructive |
| L10057 | §3-The | rule |
| L10070 | §147 | The three-stratum FRAME LAW, and four "stop searching" verdicts (P30 S42, `func_8017C294`, |
| L10075 | §3-A. | The frame has THREE strata, and stratum 3 is unreachable from C |
| L10091 | §3-B. | A `?:` on MEMORY operands costs ~16 bytes of invisible frame; on REGISTER operands, zero |
| L10102 | §3-C. | Inner-block declaration does NOT delay slot allocation — BYTE-REFUTED |
| L10107 | §3-D. | A lone `$t8`/`$t9` in the target is RELOAD SCRATCH — reproduce the spill, don't pin the re |
| L10117 | §3-E. | A `qty_compare` TIE is not spelling-reachable — recognise it and stop |
| L10129 | Consequence | for the family (a real scheduling decision) |
| L10179 | §148 | The loop.c hoisting THRESHOLD is arithmetic you can compute, and the `?:` clamp that folds |
| L10185 | §3-A. | `move_movables` hoists iff `threshold × savings × lifetime ≥ insn_count` — and you can rea |
| L10204 | §3-B. | `(v < 0x40) ? v : 0x3F` is folded to `MIN_EXPR` and expands to the WRONG SHAPE |
| L10218 | §3-C. | A zero-byte ALLOCNO-PRIORITY slider |
| L10228 | §3-D. | Reproduce the original's BUGS verbatim |
| L10277 | §149 | Four instrument defects in one session, and the two questions they were hiding (P30 S43) |
| L10283 | §3-A. | A prep step that returns its input on failure is indistinguishable from a search that foun |
| L10301 | §3-B. | Same address + same name ≠ same body — and the ledger keys on address |
| L10317 | §3-C. | `make: *** [...] Error N` is a summary, never a diagnosis |
| L10327 | §3-D. | "Cheap fuel" that was never probed: 0 of 31 templatable |
| L10346 | §150 | A register ROTATION across symmetric blocks is VARIABLE-IDENTITY evidence, not an allocato |
| L10353 | §3-The | fix |
| L10363 | §3-The | method that found it (this is the transferable part) |
| L10379 | §3-Two | corrections to the record |
| L10390 | Diagnostic | order (adopt this) |
| L10401 | §151 | THE GHOST WEDGE: when a load-before-store transposition is unreachable by ANY statement or |
| L10406 | §3-The | mechanism (read from cc1's own `-dR` trace, not inferred) |
| L10421 | §3-The | lever — a zero-emission insn that absorbs the blocked tick |
| L10429 | §3-The | two fallouts, and how to close them (both measured, in order) |
| L10441 | When | to reach for it |
| L10452 | §152 | BYTE SIZE is the family key that name- and h_seq-grouping both miss (P30 S43, the 0xECC fa |
| L10457 | §3-The | finding |
| L10466 | §3-The | key |
| L10477 | §3-Two | cautions that must travel with this technique |
| L10488 | §3-The | companion defect (open) |
| L10500 | §153 | THE ADDRESS-REMATERIALISATION LAUNDER: a third zero-emission asm lever (P30 S43, `func_801 |
| L10508 | Symptom | Symptom |
| L10513 | Mechanism | (gcc source + RTL dumps, not inferred) |
| L10520 | What | does NOT work (14 byte-measured probes) |
| L10526 | §3-The | cure — a fresh launder per site, each in its own block |
| L10536 | Companion | levers from the same function |
| L10556 | §154 | Reading a disc payload: the module-id word, static base derivation, and "type 1 = uncompre |
| L10561 | §3-A. | Payload word0 is a global MODULE ID; code starts after the header |
| L10570 | §3-B. | Two static base-derivation methods that must AGREE (use both) |
| L10582 | §3-C. | PAC type 1 = the same payload class as type 4, just NOT compressed |
| L10592 | §155 | hi/lo literal scanning MUST track base registers (S45) |
| L10601 | §155a | the same failure class, one level up: SHAPE-blind table scanning (S45 p5) |
| L10621 | §155b | check the TYPE your oracle returns before comparing against it (S45 p5) |
| L10644 | §155c | the ZERO-REFERENCE trap: gcc splits a global-array address across the `lui` and the LOAD ( |
| L10674 | §156 | an ORPHANED reconcile poisons the fleet: `dedup_propagate`'s kept edit (S45 p6/p7) |
| L10721 | §157 | the cheap-tier size cliff, measured (S45 p6) |
| L10746 | §158 | The RANGE-EXTENDER: a fourth zero-emission asm lever completes the allocno toolkit (P30 S4 |
| L10755 | Symptom | Symptom |
| L10761 | §3-Why | the fork is chained (gcc source, validated insn-by-insn against -dS/-dR dumps) |
| L10774 | §3-The | method (dump-arithmetic first, then place — no probing) |
| L10791 | Bonus | facts worth keeping |
| L10806 | §156 | THE PREFERENCE-DONOR MERGE: cross-region variable reuse is what fills a0-a3, and a call-ar |
| L10862 | §159 | THE DECLARATION AXIS: conform to byte-truth, and make every guard state its COVERAGE (P30 |
| L10927 | §160 | THE REACH-15 WAVE HARVEST: an align-1 block move, and the instrument that called it a wall |
| L11003 | §161 | THE RETRY-WAVE HARVEST: a jump table indexed from zero, and two allocator traps (P30 S47) |
| L11048 | §162 | S48 WAVE-1 HARVEST (P30, 2026-08-11): the reach-ordered sibling campaign's first 12 target |
| L11075 | §162a | SHARPENS *(sharpens §161a, §131, §8a-pad, §129a)* |
| L11104 | §162b | SHARPENS *(sharpens §48-A3, §156, §150, §76)* |
| L11133 | §162d | SHARPENS *(sharpens §31, §21, §30, §55a)* |
| L11175 | §162e | NEW |
| L11177 | §162 | THE LICM PAIR: what makes an address a movable AT ALL, and why the preheader order is the |
| L11243 | §162f | SHARPENS *(sharpens §42d, §41d, §73, §10)* |
| L11298 | §162g | NEW |
| L11300 | §162 | CROSS-JUMP DIRECTION: the surviving copy is always the LATER one, so a BACKWARD `j` into a |
| L11334 | §162h | SHARPENS *(sharpens §88, §88a, §50-B, §8)* |
| L11336 | §162 | The cross-jump "CALL veto" is a COUNT law, not a CALL law (BOUNDS §88a; P30 S48, `func_801 |
| L11402 | §162i | SHARPENS *(sharpens §135, §21, §42, §32)* |
| L11427 | §162j | SHARPENS *(sharpens §25, §136d-1, §48-B, §46-L2)* |
| L11456 | §162k | SHARPENS *(sharpens §1-I2, §12, §160d, §21)* |
| L11519 | §162l | SHARPENS *(sharpens §48-B, §48-C1, §20, §21)* |
| L11574 | §162m | SHARPENS *(sharpens §36, §158, §148, §153)* |
| L11576 | §158a | THE FIFTH LEVER IS NOT AN ASM: `do { } while (0)` is a REGION ref-multiplier you MINT (P30 |
| L11583 | §3-The | law |
| L11594 | Size | it before you write it (§158 step 1-2, applied) |
| L11615 | §3-The | wrap BOUNDARY is the dial — and it is indiscriminate |
| L11621 | §3-Not | a pure dial |
| L11625 | DIAGNOSTIC | TELL — two faces, one law |
| L11647 | §162n | NEW |
| L11680 | §162o | SHARPENS *(sharpens §158, §136-1, §136-6, §79)* |
| L11739 | §162p | SHARPENS *(sharpens §48-B, §46-L2, §156, §136d-1)* |
| L11756 | §162q | SHARPENS *(sharpens §30, §30a, §135-2, §136-13)* |
| L11794 | §163 | S48 WAVES 2-3 HARVEST (P30, 2026-08-11/12): the five that were byte-probed and are actiona |
| L11862 | §163z | THE UNVETTED REMAINDER (do not cite as law; each needs a dedupe pass) |
| L11882 | §164 | S48 §163z SKEPTIC PASS (P30, 2026-08-12): 190 claims vetted, 82 banked |
| L12334 | §16Xy | SHARPENS *(sharpens §136d-3, §37 /s-DEP LATTICE, §135-2, §136-13, §162q)* |
| L12336 | §3-The | `/s` drop clause is in ALL THREE dependence predicates, so the FIXED-ADDRESS STORE is what |
| L13670 | §164z | REFUTED CLAIMS: do NOT re-derive these |
| L13736 | §165 | S48 WAVE-4 HARVEST (P30, 2026-08-12): banked the same day the wave landed |
| L14394 | §16Z | SHARPENS *(sharpens §37 "the /s-DEP LATTICE", §136-13, §136-14, §16Xy, §162q, `gcc-2.7.2- |
| L14396 | §3-The | ADDRESS-CLASS TABLE: which load/store pairs even REACH the `/s` clause (P30 S48 wave 4, `f |
| L14912 | §165z | REFUTED THIS WAVE: do NOT re-derive |
| L14956 | §166 | THE DESTINATION-TU ORACLE (P30 S48): the seven-attempt bug that was never codegen |
| L15012 | §167 | S48 WAVE-5/6 HARVEST (P30, 2026-08-12): the saturation point |
| L16208 | §167z | REFUTED IN WAVES 5/6: do NOT re-derive |
| L16265 | §168 | THE COUSIN TIER (P30 S49, 2026-08-12): h_seq's exact-hash brittleness, measured — and the |
| L16317 | §169 | THE MICRO-ADAPT LANE (P30 S49): edit a proven body, don't crack a new one |
| L16364 | §170 | THE A-PROP WORD-DIFF CARD (P30 S49): the lane that had no owner |
| L16408 | §171 | THE STALE SEED SYMBOL (P30 S50, 2026-08-13): why §170's 91%→57% was never codegen |
| L16474 | §171a | THE MECHANICAL A-PROP DRAFT (P30 S50): 256 members banked with no agent in the loop |
| L16524 | §171b | THREE CARRIES THE MECHANICAL DRAFT NEEDS (P30 S50, banking the top-reach families) |
| L16557 | §172 | THE ORPHAN-SLOT MECHANISM v2 (P30 S50-Max): the complete frame-residue model for gcc-2.7.2 |
| L16611 | §172a | TWO DECOMPILATION TELLS FROM THE SAME DIG (P30 S50-Max) |
| L16627 | §172b | THREE MORE TELLS FROM THE GCC READ (P30 S50-Max, banked on Drew's ask) |
| L16670 | §173 | THE STORED-PLUMBING RECOVERY RECIPE (P31 T6): symfix-first, per-group isolation, and where |
| L16706 | §174 | THE ADAPT-CARD WAVE RECIPE (P31 waves A/B, 2026-08-14): prevention beats recovery |
| L16776 | §175 | A CALLER-SAVED REGISTER PIN CAN BE A CORRECTNESS BUG, NOT JUST A SCHEDULING CHOICE (P31 wa |
| L16801 | §176a | THE VERIFICATION-LAYER LAWS (P31 overnight, 2026-08-15). What each check can and cannot pr |
| L16841 | §176b | BATCH-GATING MECHANICS (P31): what changes when N drafts land in ONE .c |
| L16867 | §176d | THE CONFLICT TABLE MUST BE SEEDED FROM THE TU, AND KEYED PER FILE (P31 S52, 2026-08-15) |
| L16906 | §176e | SYMBOL IDENTITY IS COMPUTABLE OFFLINE (P31 S52): `tools/reloc_identity.py` |
| L16963 | §176f | THE DECLARATION FORM IS A MATCHING LEVER, SO RECONCILE TOWARD THE FORM THE MATCH NEEDS (P3 |
| L16994 | §176g | SIZE A WAVE BY INSTRUCTIONS, NOT BY CARDS (P31 S52 — the adopted doctrine) |
| L17032 | §176h | THE BATCH-SUBSTITUTION HAZARD MAP (P31 S52): seven holes, three wrong fixes, one law |
| L17040 | §3-A. | The seven under-reporting holes (all in `gate_main`, all the same shape) |
| L17058 | §3-B. | Typedef handling — the only strategy that survives contact |
| L17080 | §3-C. | The limit that remains (recorded, not solved) |
| L17087 | §3-C2. | RECONCILE BEFORE THE FIRST GATE — a parked draft gets HARDER to bank, not easier |
| L17110 | §3-D. | The measured cost shape, and what to build next |
| L17128 | §176i | WHAT A STATIC PRE-GATE CHECK CAN AND CANNOT PROVE (P31 S52, wave Q) |
| L17160 | §176j | STOPPING A WAVE MID-FLIGHT COSTS THE IN-FLIGHT TAIL (and how much is recoverable) |
| L17186 | §176j-2 | THE REPAIR PASS, MEASURED (do this instead of resuming) |
| L17206 | §176k | TWO SELECTOR BUGS THAT SILENTLY SHRINK A WAVE |
| L17223 | §177 | 🔴 THE EPILOGUE RETURN-DELAY SLOT IS DECIDED BY YOUR SAVED-REGISTER SET, NOT BY SCHEDULING |
| L17280 | §178 | SIX LEVERS MINED FROM THE WAVE-P JOURNALS (P31 S52), each byte-proven and source-cited |
| L17292 | §3-A. | THE `$0`-ADD OPAQUE COPY defeats `make_regs_eqv` (func_80033398, 93 ins) |
| L17308 | §3-B. | A `return <const>` IS A PRIORITY-1 HARD-REG SET THE SCHEDULER PLACES FIRST (func_8001BE30, |
| L17321 | §3-C. | SINGLE-SET TEMPS GET THE BIRTHING BOOST (func_8001D3FC, 196 ins) |
| L17329 | §3-D. | A NARROW TYPE BLOCKS COPY ELISION (func_8001D3FC — new idiom) |
| L17336 | §3-E. | THE ZERO-OFFSET ALIAS HOLE (func_80037028, 71 ins) |
| L17345 | §3-F. | `MEM_IN_STRUCT_P` ASYMMETRY IN `true_dependence` (func_80037144, 124 ins) |
| L17351 | §3-G. | TWO MODELLING TRAPS THAT COST THESE AGENTS SWEEPS OF HUNDREDS OF COMPILES |
| L17367 | §179 | IDIOMS MINED FROM THE WAVE P/Q JOURNALS (P31 S52, harvest pass) |
| L17377 | §179-A | 🔴 A LOOP-WALKED POINTER **PARAMETER** HANDS ITS ARGUMENT REGISTER TO THE GIV (9 byte-proof |
| L17426 | §179-B | 🔴 THE HAND-WRITTEN-ASM TRANSCRIPTION CHECKLIST (maspsx + masked_diff; 10 byte-proofs) |
| L17476 | §179-C | 🔴 A FUNCTION WITH NO EPILOGUE (falls into a sibling's shared tail) MUST BE FILE-SCOPE `__a |
| L17527 | §179-D | `gte_stflg` MUST CLOBBER `"$12"` OR THE WHOLE TEMP FILE ROTATES BY ONE |
| L17547 | §179-E | A `>2*MAX_MOVE_BYTES` BLOCK COPY IS A **STRUCT ASSIGNMENT**, NOT A HAND LOOP |
| L17573 | §179-F | PINNING A LOOP-WALKED POINTER IS A TOTAL OFF-SWITCH FOR STRENGTH REDUCTION |
| L17596 | §179-G | 🟡 A PIN CAN **CREATE** A COMBINE `LOG_LINK` AND DELETE AN `andi` (sixth RC-5 channel, n=1) |
| L17623 | §179-H | A MID-BODY `.global LABEL` PAIR SLICES A BYTE-COMPARABLE FRAGMENT OUT OF A LARGER ROUTINE |
| L17646 | Considered | and NOT banked |
| L17663 | §176c | MAIN (SLUS_007.26) CANNOT BE GATED INCREMENTALLY |
| L17674 | §176 | SEVEN LEVERS FROM THE P31 OVERNIGHT WAVES (2026-08-15): statement order, false regalloc, a |
| L17680 | §176-A | "SCHEDULE / DELAY-SLOT / LENGTH-DRIFT ±1" ⇒ check STATEMENT ORDER around the call first |
| L17704 | §176-B | "REGALLOC-PERM, 1-4 instructions off" ⇒ it is usually NOT register allocation |
| L17750 | §176-C | 🔴 WALL REFUTATION: a hard-register pin CANNOT schedule around a call, because of a genuine |
| L17776 | §176-D | CSE-class levers used in reverse (two sharpenings of §153 and cse_expr §2) |
| L17802 | §176-E | Two cheap source spellings, both cc1-probed |
| L17824 | §176-F | Misdiagnosis triage: four residual verdicts that were lying |
| L17841 | What | is NOT banked here |
| L17854 | §180 | THE LEFTOVER-DRAFT HARVEST: RE-VERIFY WHAT YOU ALREADY HAVE BEFORE DRAFTING ANYTHING NEW |
| L17883 | §180b | WHAT THE PRE-GATE LADDER ACTUALLY FINDS IN A COLD PILE (the shape of integration debt) |
| L17902 | §180c | WHEN A BINARY'S MASS BAND IS SPENT, THE FLEET-WIDE DRAW IS STRICTLY BETTER |
| L17920 | §181 | WHAT A WAVE'S GATE ACTUALLY REJECTS (P31 S53, measured on wave R's 45-draft main pile) |
| L17921 | Only | ONE of 27 blocked drafts was wrong. The other 26 were correct and unbankable. |
| L17976 | §182 | §177's HONEST NEGATIVE: the epilogue lever cracked 4 of 16, and the `800c3` cluster held |
| L17990 | §180d | THE `pgrep` BRACKET TRICK PROTECTS THE PATTERN, NOT THE COMMAND LINE |
| L18002 | §183 | THE DECLARATION-RECONCILIATION PLAYBOOK (P31 S53, measured on 20 byte-verified drafts) |
| L18003 | §3-18 | of 20 reconciled while keeping the match. The two that did not are mechanism, not effort. |
| L18073 | §184 | COMMENT-BLINDNESS IS A DEFECT CLASS, NOT A BUG (P31 S53: three tools, one root cause, one |
| L18101 | §185 | EDIT THE SIDE THAT IS CHEAP TO VERIFY, AND CHECK A TU RETYPE AT ITS USE SITES |
| L18133 | §186 | CROSS-JUMPING RUNS **AFTER** SCHEDULING, SO NO C-LEVEL BARRIER CAN STEER IT |
| L18154 | §186b | A NO-SAVE 16-BYTE FRAME IN A LEAF FUNCTION MEANS `s16` LOCALS, NOT A HIDDEN CALL |
| L18162 | §186c | WHERE A VALUE IS LOADED DECIDES WHICH ALLOCATOR OWNS IT, AND THEREFORE ITS REGISTER |
| L18179 | §187 | 🔴 "SAME SOURCE" IS NOT "SAME OBJECT": THE SDK BUILD AND THE GAME BUILD DISAGREE ON GTE NOP |
| L18217 | §188 | 🔴 THE `jr $ra` + `addiu $sp` TAIL IS AN **ASSEMBLER** ARTIFACT, NOT A FRAME SHAPE |
| L18267 | §189 | FIVE COMPILER LAWS MINED FROM THE WAVE R/S JOURNALS (P31 S53), each source-cited and re-de |
| L18342 | §190 | THREE PRESCRIPTIONS FROM THE SAME HARVEST (weaker evidence than §189, honestly labelled) |
| L18379 | §191 | WHAT THIS HARVEST DID **NOT** BANK (4 rejected, 4 narrowed) — recorded so it is not re-der |
| L18401 | §192 | THE PRE-GATE LADDER WAS MAIN-ONLY, AND NOBODY COULD SEE IT (P31 S54) |
| L18402 | Three | defects in one call path; the overlay slates that carry most of the wave work were being w |
| L18466 | §193 | THE WAVE-T HARVEST (P31 S54): 71 index_gap reports -> 9 laws, 5 rejected, 61 already-cover |
| L18483 | §193-A | The wave card ships only OPEN-set pointers and discards the atlas's BANKED one — `exemplar |
| L18550 | §193-B | A NARROW CAST OF A WIDE PARAMETER COSTS ONE EXTRA INSTRUCTION WHEN ITS STATEMENT SITS AFTE |
| L18588 | §193-C | gcc-2.7.2 cross_jump merges the SCHEDULED common SUFFIX only — there is no prefix/head mer |
| L18622 | §193-D | A COMPILER-GENERATED ARGUMENT COPY IS A `optimize_reg_copy_1` TRIGGER: when the pointer's |
| L18693 | §193-E | A varying-address (pointer) load is re-emitted once per CSE-LIVE INTERVAL, and naming it i |
| L18723 | §193-F | §148-A2 — The `threshold -= 3` STAIRCASE: `move_movables` admits a COUNT of invariants, no |
| L18787 | §193-G | §164-54's "scope to ≥4 arms" bound is byte-wrong — the dispatch-topology oracle goes live |
| L18848 | §193-H | A pointer-derived base load `*(s32*)(p+K)` is uncacheable across ANY memory write or call |
| L18888 | §193-I | A DECLARED AGGREGATE LOCAL HAS AN 8-BYTE FRAME STRIDE — CEIL(size,8), NOT size. N ARRAYS T |
| L18947 | §193-REJECTED | what this harvest did NOT bank (recorded so it is not re-derived) |
| L18974 | §194 | THE WAVE-U HARVEST (P31 S54): 64 index_gap reports -> 14 laws, 5 rejected, 44 already-cove |
| L18991 | §194-A | A zero-byte scheduling fence goes AFTER the defining statement to make that computation em |
| L19057 | §194-B | A `addu $rA,$rB,$zero` copy feeding ≥2 `sh` stores is a SECOND, 16-BIT-DECLARED local — th |
| L19095 | §194-C | A CALLER-SAVED loop counter proves its live range crosses ZERO calls — so it cannot share |
| L19158 | §194-D | Declared width of a computed-value local is a sched1 dial (count-neutral) — a replication |
| L19199 | §194-E | The wave card's `exemplar` is the TARGET ITSELF on 42/73 wave-U and 36/71 wave-T cards — a |
| L19236 | §194-F | `if ((*p = v = f()) == 0)` is an expand-time pseudo SPLITTER (store_expr's `want_value && |
| L19309 | §194-G | Reading the integer half of a 16.16 stack aggregate: REGISTER-LIVENESS, not the C spelling |
| L19352 | §194-H | §164-29's WAR fence runs again at SCHED2 ON HARD REGISTERS: an in-place `v &= K` before a |
| L19390 | §194-I | §16N+2's magic-per-odd-part ladder has exactly one broken row — read the divisor arithmeti |
| L19433 | §194-J | Back-to-back identical stores: flow.c's `last_mem_set` deletes the first, and only `volati |
| L19485 | §194-K | Blind sched1's alias oracle with a second SET of a pointer pseudo — the first zero-byte, n |
| L19563 | §194-L | §88b and §189-E are BOTH half-wrong, but not the way the candidate says: the compare-const |
| L19611 | §194-M | A STORE in a CONDITIONAL branch's delay slot proves its C statement DOMINATES the branch — |
| L19669 | §194-N | §193-D's C dial is misstated: the lever is a SURVIVING CODE_LABEL (a label with a real inc |
| L19729 | §194-REJECTED | what this harvest did NOT bank (recorded so it is not re-derived) |
| L19750 | §195 | THE WAVE-V HARVEST (P31 S54): 67 index_gap reports -> 14 laws, 9 rejected, 76 already-cove |
| L19764 | §195-A | §167-08's "an $aN READ before the jal is scratch" has a byte-proven FALSE-NEGATIVE class: |
| L19835 | §195-B | A CALL_INSN does not start a basic block in gcc-2.7.2 — so a call-crossing temp can be a L |
| L19877 | §195-C | A call-argument `%hi/%lo` pair sitting at the block head, far above its `jal`, is a load-d |
| L19925 | §195-D | §195 — `masked_diff.mask_for` returns 0 for EVERY `j`/`jal` word, so an internal `j` desti |
| L19993 | §195-E | A 0/1 materialised at a JOIN immediately before the controlling `beqz`/`bnez` proves the s |
| L20051 | §195-F | fold-const.c:4825 canonicalises a `?:` whose THEN arm is zero (or constant against a non-c |
| L20103 | §195-G | §NEW — TWO ARMS CALLING THE SAME CALLEE MERGE INTO ONE `jal` UNLESS EACH ARM'S OWN CODE CO |
| L20151 | §195-H | §165-27g — ON A FIXED-SYMBOL GLOBAL, `extern T D[];` + `D[0]` IS THE CSE RELOAD DIAL, AT Z |
| L20198 | §195-I | §145(b) AMENDED — the pointer-bump `addiu` is saved by cse, not combine: ANY second SET of |
| L20263 | §195-J | GTE / PsyQ op CALL-vs-INLINE is a PER-SITE SOURCE FACT, not a TU style — both forms coexis |
| L20307 | §195-K | At -O2 the §18 array-of-struct lever is a FRAME lever, not a length lever — but only when |
| L20359 | §195-L | The cse store-re-seed does not cross a JOIN LABEL: per-arm stores + a join read keep the r |
| L20411 | §195-M | Frame `vars` is a SEQUENTIAL bump-allocation, not a flat sum: §193-I's CEIL(aggregate,8) t |
| L20460 | §195-N | In a call-bearing chain of N≥2 `if (f(...)) return 1;` tests closed by `return 0;`, the LA |
| L20507 | §195-REJECTED | what this harvest did NOT bank (recorded so it is not re-derived) |
| L20553 | §196 | PUT ON THE CARD WHAT THE TREE ALREADY KNOWS: the fleet's declaration consensus (P31 S54) |
| L20608 | §197 | THE WAVE-W HARVEST (P31 S54): 68 index_gap reports -> 4 laws, 3 rejected, 41 already-cover |
| L20622 | §197-A | A NARROW SIGNED MEMORY READ FEEDING A CONSTANT `>>` LOSES ITS `lh`, AND THE CURE IS AN ASM |
| L20660 | §197-B | A REPEATED COMPARE OF ONE VALUE AGAINST ONE CONSTANT IS DELETED BY cse's `qty_comparison_c |
| L20688 | §197-C | Fix A1 (operand order) cannot move a commutative destination whose .greg conflict set alre |
| L20733 | §197-REJECTED | §197-REJECTED |
| L20748 | §199 | THE WAVE-X HARVEST (P31 S54/S55): 63 index_gap reports -> 7 laws, 2 rejected, 56 already-c |
| L20759 | §199-A | §189-A's asm→source inference is byte-FALSE: an interloper between a split constant's `lui |
| L20808 | §199-B | A permutation sweep that holds ANY statement fixed is not a sweep: the statement an agent |
| L20853 | §199-C | A NEGATIVE CONSTANT MULTIPLY ALWAYS TAKES expmed's negate_variant — but whether you ever S |
| L20901 | §199-D | A narrow UNSIGNED value compared in an ordered `if` emits `sltiu`/`sltu`; the only dial is |
| L20961 | §199-E | §189-A BOUNDED AND CORRECTED — the discriminator is INSN_PRIORITY, not "is the interloper |
| L21020 | §199-F | §164-36b — THE TARGET-HEAD FENCE IS A DELAY-SLOT THREAD SELECTOR, AND IT ONLY FIRES WHEN ` |
| L21074 | §199-G | At TWO case nodes the switch-vs-if oracle is not blind — but the tell is ALL tests positiv |
| L21129 | §199-REJECTED | §199-REJECTED |
| L21140 | §200 | THE ALIAS IS THE UNIVERSAL DECLARATION ESCAPE: stop negotiating with the TU's spelling (P3 |
| L21189 | §201 | THE WAVE-Y HARVEST (P31 S55): 67 gap reports -> 5 laws, 8 rejected, 53 already-covered |
| L21199 | §201-A | §150-B applies to `decl_prior`'s DEF row: for an overlay-window symbol the banked "definit |
| L21231 | §201-B | In a narrowed PLUS/MINUS/AND/IOR/XOR expression the destination pointee is INERT — the sig |
| L21311 | §201-C | §X — A CALL'S OWN DELAY SLOT AND THE UPSTREAM CONDITIONAL BRANCH'S SLOT COMPETE FOR ONE IN |
| L21362 | §201-D | THE SIGNEDNESS OF A div/mod MAGIC IS DECIDED BY THE STATIC TYPE OF THE DIVIDEND TREE AFTER |
| L21409 | §201-E | §194-J-2 — The `last_mem_set` deletion window is measured in SOURCE/expand order, not in t |
| L21465 | §201-REJECTED | eight, the session's highest |
| L21490 | §202 | THE ALIAS CARRIES A DEFINITION, NOT JUST A DECLARATION: the DEF-SIDE-RETURN wall (P31 S56) |
| L21527 | §203 | A DEDUPED TYPEDEF MUST PRECEDE EVERY SPLICE POINT, NOT JUST ITS OWN (P31 S56) |
| L21588 | §204 | THE WAVE-Z HARVEST (P31 S56): 82 gap reports -> 5 laws, 16 rejected, 30 already-covered |
| L21607 | §204-A | A COMPARE THAT APPEARS BOTH IN A BRANCH'S DELAY SLOT AND AGAIN ON THE FALL-THROUGH IS A JO |
| L21682 | §204-B | A LOOP COUNT THAT ARRIVES ON THE STACK IS DECREMENTED IN PLACE: a fresh counter local can |
| L21746 | §204-C | WHEN A LOCAL BUFFER'S ADDRESS IS PASSED TO A CALL, ITS SIZE IS A FACT ABOUT THE CALLEE'S B |
| L21804 | §204-D | A LOOP-INVARIANT LOAD IS ADMITTED AS A MOVABLE ONLY IF ITS ADDRESS CANNOT TRAP: `local.fie |
| L21879 | §204-E | `decl_prior`'s `%hi/%lo` ARM HAS NEVER FIRED: the card's promised GLOBAL-TYPE row is 0 of |
| L21931 | §204-CONFIRMED | 30 reports that the index already answered |
| L22025 | §204-REJECTED | sixteen, twice the previous record |
| L22098 | §205 | THE CHAINED ASSIGNMENT IS ITS OWN SCHEDULING DIAL: `*b = *a = v;` moves an argument copy t |
| L22153 | §206 | THE JTBL-CARVE DRAFTING IDIOM: the bounds check is the entry count, and an EMPTY case owns |
| L22222 | §207 | THE WAVE ab–ag HARVEST (P31 S58): 278 byte-banked notes → 25 laws, 103 self-reported no-ga |
| L22243 | §208 | TWO NAMED LOCALS FOR ONE RELOADED EXPRESSION BUY TWO ALLOCNOS — the naming granularity own |
| L22292 | §209 | THE NARROW LOCAL IS A DIAL IN TWO OPPOSITE DIRECTIONS, AND §194-B's "≥2 `sh` STORES" BOUND |
| L22369 | §210 | THE SINGLE-BIT MASK IN A BOOLEAN TAIL: `andi K ; sltu $zero,v` vs `srl n ; andi 1` is a ST |
| L22415 | §211 | HOIST THE LOOP INIT ABOVE THE DOMINATING GUARD: it fills the guard's delay slot AND flips |
| L22474 | §212 | THE WALKING CURSOR IS COUNTABLE: `*wp++` emits one `addiu` PER STORE, `wp[0..2]` emits one |
| L22519 | §213 | INDEPENDENT SAME-BASE STORES: THE EMISSION ORDER IS A PERMUTATION OF SOURCE ORDER, AND THE |
| L22555 | §214 | THE BANKED TWIN MAY BE A MACRO, A DELETED `.s`, OR A SEMANTIC INVERSE — six ways a ≥0.9 si |
| L22601 | §215 | PIN ECONOMY: the twin's pins are NOT part of the shape, and §17's "pin every call-crossing |
| L22657 | §216 | DISTINCT ADJACENT SCALARS vs ONE ARRAY: one `lui` per access is the tell, and the array de |
| L22697 | §217 | DECODING A CALL'S STACK ARGUMENT SLOTS: `sw` at `0x10`/`0x14`/`0x18` are params 5/6/7 **(s |
| L22723 | §218 | A NARROW TYPE AT THE ABI BOUNDARY COSTS AN IN-PLACE `sll/sra` PAIR — on the RETURN as well |
| L22752 | §219 | COMPOUND `+=`, FULL ASSIGNMENT, AND AN EXPLICIT TEMP ARE THREE DIFFERENT SCHEDULES OF ONE |
| L22779 | §220 | THE PARAMETER ITSELF IS A REGALLOC DIAL: use it directly, prefer `s32` to `void*`, and pla |
| L22819 | §221 | A CONSTANT SHARED BY TWO STORES DIES AT THE CALL WHOSE DELAY SLOT REFILLS ITS REGISTER **( |
| L22835 | §222 | SWITCH vs IF-CHAIN, PART 3: source arm order IS emission order, a leading EMPTY case buys |
| L22877 | §223 | READING A `jal` DELAY SLOT: the value in it was produced BEFORE the call, so it is NEVER t |
| L22939 | §224 | CROSS-JUMP: WRITE THE DUPLICATE, AND READ A SHARED DELAY SLOT AS THE MERGE SIGNATURE (P31 |
| L22975 | §225 | THREE CONTROL-FLOW SHAPES NO STRUCTURED SPELLING REACHES (P31 S58) |
| L23018 | §226 | FRAME PADS: FOUR WAYS §162i1/§2429's DEAD-LOCAL LEVER MISFIRES (P31 S58) |
| L23059 | §227 | TYPE THE SOURCE BY THE **LOAD** WIDTH, NOT BY THE STORE WIDTH (P31 S58) |
| L23079 | §228 | READING THE DIVIDE, PART N: the off-by-one compare is `% K == 1`, and three more discrimin |
| L23116 | §229 | THE ADDRESS IS A VALUE: NAMING IT MOVES THE `lui`/`addiu` PAIR — AND §L14410 SAYS THE OPPO |
| L23165 | §230 | THE ANCHOR PROBE: with `%hi`/`%lo` masked, the surviving `addiu` deltas tell you which ass |
| L23180 | §231 | TRANSCRIPTION AND SEMANTIC-READ HYGIENE: six ways the listing misleads (P31 S58) |
| L23221 | §232 | WHEN THE `jr` DELAY SLOT'S STORE STORES THE RETURN VALUE, TIE THEM WITH ONE PSEUDO **(sing |
| L23257 | §30 | addendum (P31 S58) — the `/s` grant closes a SCHEDULING residual and a REGISTER residual w |
| L23277 | §194-B | addendum (P31 S58) — BOUND 2 is byte-wrong; see §209 Direction A |
| L23283 | §176-B | addendum (P31 S58) — the misdiagnosis direction |
| L23289 | §165-40 | addendum (P31 S58) — the barrier goes at the COPY SITE, not inside the region it protects |
| L23298 | §164-63 | addendum (P31 S58) — the interposed asm works when the SECOND value is an ordinary assignm |
| L23307 | §193-A | / §194-E addendum (P31 S58) — where the twin's body actually lives |
| L23313 | §233 | THE WAVE aa–bg HARVEST (P31 S58b): 1,101 byte-banked notes → 24 new laws, 21 addenda, ~700 |
| L23357 | §234 | CONSTANT MATERIALISATION: THE STORE LVALUE'S SIGNEDNESS PICKS `addiu` vs `li`/`ori` (P31 S |
| L23398 | §235 | THE PHANTOM SYMBOL: A MASKED `MATCH` CAN CARRY A RELOCATION THAT DOES NOT EXIST (P31 S58b) |
| L23427 | §236 | THE DECLARATION LAYER IS THE DOMINANT BANK-BLOCKER: NINE WAYS A BYTE-PERFECT BODY FAILS TH |
| L23506 | §237 | THE CAST-AT-CALL-SITE DECISION TABLE: WHAT §17a-1 FIXES, WHAT IT CANNOT, AND THE FOUR ESCA |
| L23561 | §238 | SAME NAME, DIFFERENT FUNCTION: THE OVERLAY-HOMONYM TRAP (P31 S58b) |
| L23601 | §239 | TWO-STATEMENT INTEGER-SPACE MATERIALISATION REORDERS `la` vs `sll`; AND THE PLUS-TREE OPER |
| L23635 | §240 | `A + K + B`: WRITE THE CONSTANT **BETWEEN** THE TWO RUNTIME TERMS (P31 S58b) |
| L23664 | §241 | THE FOLDED SIGN-EXTEND-AND-SCALE: `sll 16 ; sra (16 − log2 scale)` (P31 S58b) |
| L23693 | §242 | `*k` vs `<<n`, AND `/2^n` vs `>>n`: EXPRESSION SPELLING OWNS THE LOAD WIDTH AND THE ROUNDI |
| L23721 | §243 | SPELL THE CSE BARRIER AS A REASSIGNED POINTER; AND THE `nop`-AFTER-EVERY-`lh` SIGNATURE (P |
| L23751 | §244 | `volatile` IS A COUNTING INSTRUMENT, A STORE-ORDER PIN, AND MUST SOMETIMES BE ASYMMETRIC ( |
| L23786 | §245 | THE CALL'S ARGUMENT LIST IS A SCHEDULING SLOT (P31 S58b) |
| L23833 | §246 | THREE-LIVE-VALUE SCAN LOOPS WANT ADDRESS-FROM-INDEX; AND TWO SYMBOLS CAN SHARE ONE giv (P3 |
| L23873 | §247 | TWO BRANCHES TO **ONE** LABEL MEANS THE SOURCE CONDITION IS NEGATED (P31 S58b) |
| L23907 | §248 | SPLIT THE LOAD FROM THE ARITHMETIC: A FUSED `g + K` DENIES THE CALLEE-SAVED REGISTER ITS D |
| L23931 | §249 | THE SELF-ASSIGN, THE DEAD RE-ASSIGN, AND THE `+ zr` COPY: THREE WAYS TO MAKE A DELETED INS |
| L23973 | §250 | `%hi/%lo` vs `lw`: THE EXTERN'S ARRAY-vs-SCALAR SHAPE DECIDES ADDRESS MATERIALISATION (P31 |
| L24010 | §251 | IMMEDIATE-SPELLING TRIGGERS: `+= 0xFF`, FULL-WIDTH `~K`, AND THE TWO-OR SPLIT (P31 S58b) |
| L24032 | §252 | THE GUARDED PRE-DECREMENT: `(x != 0) && (--x == 0)` (P31 S58b) |
| L24053 | §253 | POSTFIX `++` vs `+= 1` PICKS A DIFFERENT SCRATCH REGISTER **(single observation — not yet |
| L24067 | §254 | THE DEAD PARAMETER IS A REGISTER-PLACEMENT TOOL **(single observation — not yet cross-conf |
| L24079 | §255 | THE EMPTY CASE, PART 2: FOUR TREE SHAPES IT BUYS (P31 S58b) |
| L24114 | §256 | GOTOS IN THE TARGET'S BLOCK ORDER REPRODUCE SWITCH PLACEMENT WITHOUT SWITCH'S SIDE EFFECTS |
| L24151 | §257 | THE DEAD-END LEDGER (P31 S58b): ELEVEN LEVERS THAT MEASURED NULL OR BACKFIRED |
| L24194 | §258 | ADDENDA TO EXISTING SECTIONS (P31 S58b) |
| L24199 | §30 | addendum (P31 S58b) — THE ANONYMOUS STRUCT MEMBER REF GRANTS `/s`, AND THAT IS A TWO-FOR-O |
| L24220 | §194-B | / §209 addendum (P31 S58b) — TWO MORE INSTANCES, AND THE BOUND IS NOW REFUTED FOUR WAYS |
| L24243 | §202 | addendum (P31 S58b) — THE DEF-SIDE ALIAS ALSO CLEARS A RETURN+PARAM DOUBLE CONFLICT |
| L24254 | §205 | addendum (P31 S58b) — CHAINED ASSIGNMENT: N≥3 IS INNERMOST-FIRST, AND THE TEXT MIRRORS EMI |
| L24271 | §208 | addendum (P31 S58b) — IT SCALES TO SIX SITES, AND IT HAS AN EXACT INVERSE |
| L24300 | §210 | addendum (P31 S58b) — THREE CONFIRMED SPELLINGS OF THE BOOLEAN TAIL |
| L24316 | §211 | addendum (P31 S58b) — INIT PLACEMENT: FIVE MORE DIALS BEYOND THE GUARD HOIST |
| L24359 | §213 | addendum (P31 S58b) — THREE MORE PERMUTATION LAWS FOR INDEPENDENT SAME-BASE STORES |
| L24388 | §214 | addendum (P31 S58b) — FOUR MORE WAYS A HIGH-SIMILARITY TWIN LIES |
| L24424 | §215 | addendum (P31 S58b) — PIN ECONOMY, PART 2: NINE REFINEMENTS |
| L24476 | §217 | CROSS-CONFIRMED (P31 S58b) — AND THE INCOMING HOME SLOT IS THE MIRROR |
| L24493 | §220 | addendum (P31 S58b) — THE PARAMETER, NOT A COPY (SEVEN CARDS) |
| L24518 | §222 | addendum (P31 S58b) — IF-CHAIN vs SWITCH: THREE MORE DISCRIMINATORS |
| L24536 | §223 | addendum (P31 S58b) — FIVE MORE CONFIRMATIONS, AND THE CONSTANT-IN-`$v0` CASE |
| L24560 | §224 | addendum (P31 S58b) — CROSS-JUMP MERGES *CALLS*, AND THE DELAY SLOT IS THE DISCRIMINATOR |
| L24590 | §225 | addendum (P31 S58b) — THE GUARD-CLAUSE FINGERPRINT, AND THREE MORE SHAPES |
| L24617 | §226 | addendum (P31 S58b) — THE FRAME CATALOGUE: SEVEN MORE LEVERS, AND SLOT ORDER IS DECLARATIO |
| L24662 | §229 | addendum (P31 S58b) — NAME IT **INSIDE** THE ARM |
| L24673 | §230 | CROSS-CONFIRMED (P31 S58b) |
| L24682 | §231 | addendum (P31 S58b) — FOUR MORE WAYS THE LISTING MISLEADS |
| L24713 | §232 | CROSS-CONFIRMED (P31 S58b) |
| L24724 | §259 | THE DISCARD LEDGER FOR THE aa–bg HARVEST (P31 S58b): WHAT WAS MINED AND REJECTED, AND WHY |
| L24763 | §260 | THE §154-A LEADING-ISLAND SPLIT: ONE CONFIG LINE, AND THE ISLAND PEELS FROM THE END (P31 S |
| L24813 | §260-A | STAGE 2 IS PROVEN, AND THE WHOLE jtbl PIPELINE IS AUTOMATED AT THE GATE (P31 S59, same day |
| L24849 | §261 | THE -O0 ORACLE: DERIVE THE OPT LEVEL FROM THE TARGET, AND `$fp` IS NOT THE TELL (P31 S59) |
| L24875 | §261a | THE -O0 FRAME-RELOAD GRAMMAR: reload COUNT disambiguates the C spelling (P31 S59, byte-pro |
| L24897 | §262 | A LANE'S YIELD IS ONLY A LANE FACT IF IT IS SIZE-MATCHED (P31 S59) |
| L24927 | §263 | A STOLEN DELAY SLOT WHOSE INSTRUCTION IS AN ARG-REGISTER COPY IS AN ARITY ERROR, NOT A SCH |
| L24968 | §264 | FOUR TELLS-LANE C RECIPES, EACH DRIVEN TO MATCH (P31 S59) |
| L25018 | §265 | THE VERBATIM-ASM BANK LANE: A FUNCTION NO -O2 C CAN EVER MATCH BANKS AS A RAW `__asm__` BO |
| L25080 | §266 | THE INERT-RIDER LAW: A LEVER IS ONLY CITABLE WHEN ITS SOLO REMOVAL BREAKS THE MATCH (P31 S |
| L25120 | §267 | ADDENDA HARVESTED FROM WAVES at/bh/bk/bl (P31 S59b) |
| L25128 | ADD-1 | → §231 addendum (also cross-ref from §195-D) — THE MASKED-`jal` "MISSING CALL" ILLUSION |
| L25137 | ADD-2 | → §42a addendum — A SHARED CONSTANT *NAMED IN A LOCAL* ACROSS A `jal` IS AN ISO→TU DRIFT H |
| L25149 | ADD-3 | → §236, item 10 — THE UN-DELETED `INCLUDE_ASM` STUB IS A DUPLICATE DEFINITION |
| L25159 | ADD-4 | → §225-3/-4 addendum — THE MIRROR ROW: VALUE-RETURN IN THE *TAKEN* ARM + TRAILING BARE `re |
| L25173 | ADD-5 | → §1/I1 addendum — THE INVERTED RANGE TEST: `(u32)(x-lo) >= N` WITH THE ZERO-ARM AS THE TR |
| L25182 | ADD-6 | → §172b-1 / §264 addendum — SHIFT-AS-TEST: `(x << 16) != 0` TESTS THE LOW HALF WITHOUT TRU |
| L25191 | ADD-7 | → §256 addendum — THE SINGLE-GUARD GOTO: THEN-BLOCK OUT OF LINE AT THE TAIL |
| L25203 | ADD-8 | → §245 addendum — THE RE-TIE BARRIER PINS CALL-ARG SETUP TO SOURCE ORDER (construct 6) |
| L25215 | ADD-9 | → §213-3 / §217 addendum — ADJACENT PRE-CALL FRAME STORES ARE ONE AGGREGATE; THE UNESCAPED |
| L25225 | ADD-10 | → §237 addendum (arity-evidence paragraph) — AN `la` PAIR ABOVE THE PROLOGUE `sw $ra` IS A |
| L25234 | ADD-11 | → Cross-confirmation card block (per §259's standing instruction: confirmation, not news) |
| L25285 | §268 | A `register __asm__` PIN ON A CALL-CLOBBERED REGISTER IS HONORED EXACTLY WHEN THE PINNED R |
| L25339 | §269 | ADDENDA HARVESTED FROM WAVES ax/bm (P31 S59c) |
| L25354 | ADD-1 | → §257-8 addendum — THE INTERPOSED ASM'S `__volatile__` IS A PER-SHAPE DIAL, AND THE "NO-O |
| L25367 | ADD-2 | → §236 addendum (item 1 corollary) — THE SILENT-SPLICE DECLARATION LADDER: WHERE THE TU HA |
| L25381 | ADD-3 | → §238 addendum — TWO BINARIES CAN EACH DEFINE THE SAME `func_` NAME WITH DIFFERENT BYTES, |
| L25394 | ADD-4 | → §167-37 addendum — THE FIFTH PRECONDITION, NOW MEASURED: DOWNSTREAM FIELD RE-READS ⇒ NAM |
| L25411 | ADD-5 | → §267-ADD-6 / §172b-1 addendum — THE SIGN-TEST FACE: `(s16)v < 0` IS `sll 16` + `bgez` ON |
| L25427 | ADD-6 | → §220-addendum — THE FOURTH FACE: WHEN THE NAMED COPY ITSELF BUYS THE EXTRA CALLEE-SAVED, |
| L25443 | ADD-7 | → §229 addendum — THE VALUE FACE: A LOOP-STORE CONSTANT SPELLED AS A LITERAL HAS NO SOURCE |
| L25456 | ADD-8 | → §30a addendum — THE THIRD COLUMN: `*p++` IS ALSO SERIALIZED BUT BURNS `addiu`; ONLY CAST |
| L25471 | ADD-9 | → §255 "AND CASE-BODY PLACEMENT" bound / §222-addendum-3 — ON A LARGE SPARSE TREE, BODIES |
| L25485 | ADD-10 | → Cross-confirmation card block (per §259's standing instruction: confirmation, not news) |
| L25526 | §3-1a. | The §266 sweep — every solo-lever A/B run for this batch |
| L25559 | §270 | The A-prop 0-bank anatomy: a byte-correct body still needs FOUR layers to agree (P31 S59) |
| L25577 | §271 | Ordinal IMM pairing: text order is NOT emission order; emit CANDIDATES, let the oracle pic |
| L25599 | §272 | The `(void)`-decl + empty-call wall: K&R the DEFINITION, not just the decls (P31 S59) |
| L25619 | §273 | A standalone compile is the WRONG oracle for a TU-destined draft (P31 S59) |
| L25634 | §274 | ADDENDA HARVESTED FROM 18 WAVES (P31 S60): 315 candidates, 255 already covered, 21 sharpen |
| L25640 | ADDENDUM | to §179-C — the `.type NAME, @function` requirement |
| L25687 | ADDENDUM | to §134 — a typedef defined BELOW the splice point is stripped anyway |
| L25717 | ADDENDUM | to §179-D (GTE macro reference family) — `gte_SetRotMatrix`/`gte_SetTransMatrix` bodies |
| L25743 | ADDENDUM | to §82 — struct copies must stay MEMBER-WISE, not block-moved, to match a spill-slot save |
| L25781 | ADDENDUM | to §136d-1 (RC-12, the `$0`-add / opaque-copy family) — two symptoms beyond "compare reads |
| L25820 | ADDENDUM | to §20 — a global declared as `T *` may itself BE the array base, not a pointer to derefer |
| L25849 | ADDENDUM | to §1-I5 |
| L25914 | ADDENDUM | to §164-51 |
| L25930 | ADDENDUM | to §176-F5 |
| L25959 | ADDENDUM | to §225 |
| L26004 | ADDENDUM | to §224 — CROSS-JUMP: THE DUPLICATE CAN BE A PLAIN STORE, NOT ONLY A CALL |
| L26038 | ADDENDUM | to §164-64 — AN EMPTY CLOBBER ON AN ARGUMENT REGISTER CAN BE THE DELIBERATE FIX, NOT JUST |
| L26069 | ADDENDUM | to §244 — THE COMPILER BARRIER, NOT `volatile`, BLOCKS A STORE→LOAD HOIST THROUGH A POINTE |
| L26100 | ADDENDUM | to §172b-1 — TWO PLACEMENT DIALS THE PROMOTION LAW DOESN'T NAME: NARROW THE COUNTER'S DECL |
| L26147 | ADDENDUM | to §229 — A POINTER'S NUMBER OF USES DECIDES WHETHER ITS ADDRESS FOLDS OR SURVIVES A CALL |
| L26192 | ADDENDUM | to §172b-4 — THE PLAIN CAST-DIVISION ALREADY PRODUCES THE PATTERN; DON'T HAND-ROLL THE BIA |
| L26222 | ADDENDUM | to §8 — WHEN `INCLUDE_RODATA` NEEDS A STANDALONE `.s` YOU CAN'T CREATE, CARRY THE FRAGMENT |
| L26265 | ADDENDUM | to §226 — A DEAD LOCAL SCOPED TO A NESTED BLOCK BUYS A MID-FUNCTION `addiu sp` PAIR, NOT A |
| L26304 | ADDENDUM | to §172a — RE-READING MEMORY (NOT NAMING A TEMP) IS WHAT KEEPS AN INCREMENT'S DELAY-SLOT F |
| L26335 | ADDENDUM | to §225 / §256 — A GOTO TO A SHARED SET-POINT PREVENTS IF-CONVERSION FROM COLLAPSING A LAT |
| L26377 | ADDENDUM | to §211 — AN IN-LOOP ACCUMULATOR WANTS A CLOSED-FORM EXPRESSION WHEN THE TARGET REMATERIAL |
| L26412 | §275 | THE LEFTOVER-REGISTER READ |
| L26452 | §276 | MIXED ADDRESS-EXPRESSION SPELLING FOR ADJACENT RELOCATABLE SYMBOLS IS A CSE-UNIFICATION DI |
| L26561 | §277 | RETURN-TAIL C SPELLING PICKS THE DELAY-SLOT-FILL vs TRAILING-MOVE TOPOLOGY, AND A NARROWER |
| L26625 | §278 | ADDENDA HARVESTED FROM WAVE cf (P31 S60): 34 candidates, 13 already covered, 8 sharpenings |
| L26633 | ADDENDUM | to §74 (func_800D0E30, resident) |
| L26669 | ADDENDUM | to §172b-4 (func_80185054, ov_SC03_097) |
| L26707 | ADDENDUM | to §265 (func_8017DC80, ov_SC07_002) |
| L26746 | ADDENDUM | to §17 (func_800CB794, md_MAIN_036) |
| L26794 | ADDENDUM | to §162p (func_8017C120, ov_MAIN_012) |
| L26828 | ADDENDUM | to §20 (~L1947) (func_80186AD0, ov_SC06_032) |
| L26858 | ADDENDUM | to §164-56 (func_8017F644, ov_SC04_005) |
| L26893 | ADDENDUM | to §237 (func_8017F7FC, ov_SC03_092) |
| L26922 | §279 | A `do/while (p < end)` LOOP UNDER AN ENTRY GUARD: the guard decides the compare, not the l |
| L26923 | §NNN | A DO-WHILE'S GUARD AND LATCH MUST REPEAT THE SAME BOUND EXPRESSION, NOT SHARE ONE LOCAL: T |
| L26956 | §280 | THE CURSOR'S DECLARED TYPE PICKS `sltu` vs `slt`: a `T*` bound test is UNSIGNED by C rule, |
| L26957 | §NNN | A LOOP CURSOR'S C TYPE (POINTER vs PLAIN INTEGER) SELECTS `sltu` vs `slt` FOR ITS BOUND TE |
| L26990 | §281 | GROUP COPY-THEN-RMW BY OPERATION KIND, NOT FIELD BY FIELD: sched1 does the interleaving, t |
| L26991 | §NNN | A DEPENDENT COPY-THEN-RMW BLOCK MUST BE SOURCE-GROUPED BY OPERATION KIND, NOT BY FIELD, AN |
| L27036 | §282 | gcc's OWN LOOP REVERSAL PUTS THE COUNTER INIT AFTER THE HOISTED MOVABLES — a position no h |
| L27037 | §NNN | WRITE THE UP-COUNT LOOP: gcc's OWN REVERSAL PRODUCES A COUNTER-INIT INSTRUCTION THAT LANDS |
| L27074 | What | I could not verify |
| L27121 | §283 | ADDENDA HARVESTED FROM THE 36-WAVE BATCH (P31 S60): 1,216 candidates, 859 already covered, |
| L27131 | ADDENDUM | to §164-75 — the fold-reassociation law also fires at a variable's INITIALIZER, not only a |
| L27157 | ADDENDUM | to §21 — the `bltz`+`slti` (or N-separate-compares) signed-range-split bullet is now CONFI |
| L27203 | ADDENDUM | to §202 — the DEF-SIDE ALIAS also resolves a function-vs-DATA-symbol identifier clash, not |
| L27226 | ADDENDUM | to §22 (`volatile`-qualified-global reload lever, cookbook ~L1922) — for a NON-constant, s |
| L27245 | ADDENDUM | to §195-E — a goto-ladder's STORES must sit AT the labels, after the gotos, not inline bef |
| L27307 | ADDENDUM | to §195-N — a GNU statement-expression slider must sit INSIDE the conditional arm's value |
| L27364 | ADDENDUM | to §176-B2 — in a micro-function with no long/short lifetime asymmetry, BOTH contending ps |
| L27411 | ADDENDUM | to §199-G — A `default:` LABEL GROUPED ONTO THE LAST CASE REMOVES THE `j default` TAIL, EV |
| L27480 | ADDENDUM | to §220 — REFERENCING THE RAW PARAMETER (NO NAMED COPY, NOT EVEN A PIN) LETS THE CALLEE-SA |
| L27538 | ADDENDUM | to §252 — a `>=0`/`<0` split on an unconditionally-decremented value needs the POSTFIX ope |
| L27565 | ADDENDUM | to §215 — FIFTH SHAPE: reused mask constants across two call-free merge sites each get the |
| L27648 | What | I could not verify |
| L27719 | Harness-defect | flags |
| L27812 | ADDENDUM | to §167-40 (func_8017E2CC, ov_SC04_015 — wave dg) |
| L27832 | ADDENDUM | to §20's cross-jump EXPLOIT bullet (func_8017E360, ov_SC05_007 — wave dg) |
| L27846 | ADDENDUM | to §87 (func_801815F4 ov_SC06_032; corroborating func_801840DC ov_SC05_017, func_80189C68 |
| L27865 | ADDENDUM | to §153 / §236-5 (func_801A419C, md_SC07_003 — waves di and dl, corroborating; refutes a c |
| L27885 | ADDENDUM | to §263 (func_801E83AC, md_SC04_029 — wave dj) |
| L27899 | ADDENDUM | to §265 (func_8017D878, ov_SC03_107 — wave dj; corroborated by a REJECTED, contradicted ca |
| L27913 | ADDENDUM | to §6 (func_801811F0, ov_SC03_102 — waves dj and dl, corroborated by a self-reported "noth |
| L27927 | ADDENDUM | to §195-G (func_80183BB0, ov_SC05_001 — wave dj) |
| L27955 | ADDENDUM | to the zero-byte-asm-slider family (§47 / §148-C / §153) (func_800CB874, md_MAIN_040 — wav |
| L27973 | ADDENDUM | to §194-B (func_8017EB34, ov_SC03_117 — wave dk; distinct from the §74 co-pinning finding |
| L28005 | ADDENDUM | to §74 (func_8017EB34, ov_SC03_117 — counter/clamp variant; wave dj, corroborated by dk/dl |
| L28025 | ADDENDUM | §37 — merged into the §153/§236-5 entry above (func_801A419C, wave dl) |
| L28033 | ADDENDUM | §6 — merged into the §6 entry above (func_801811F0, wave dl) |
| L28041 | ADDENDUM | to §238 (func_80182CB4, ov_SC02_000 — wave dl) |
| L28059 | ADDENDUM | to §137a (func_801684B4, ov_MAIN_012; corroborated independently by func_80189E68, func_80 |
| L28075 | ADDENDUM | to §8c / §88d (func_8016AB6C, ov_MAIN_012 — wave dm) |
| L28089 | ADDENDUM | to §73 / §30#2 (func_800D1984, resident — wave dm) |
| L28105 | What | I could not verify |
| L28125 | ADDENDUM | to §174 Law 4 (func_8017E9A8, ov_SC06_015) |
| L28165 | ADDENDUM | the zero-emission-asm family gains a REF-SLIDER PLACEMENT LAW and a paired RESTORER (func_ |
| L28217 | From | ck + cl + cm |
| L28223 | ADDENDUM | §NNN — sharpens §55a / §164-37 / §165-28 (switch-vs-tree cluster): A SHAPE THAT LOOKS LIKE |
| L28260 | ADDENDUM | §NNN — sharpens §167-13's boundary: CHAINING TWO IDENTICAL SIDE-BY-SIDE STORES INTO ONE C |
| L28293 | ADDENDUM | §NNN — sharpens §162a3/§60b: A `sll $v0,16 / sltiu $v0,1` ZERO-TEST OF A JUST-DECREMENTED |
| L28326 | ADDENDUM | §NNN — sharpens §37/§124 (unspecified-parameter-list family): DERIVE A CALLEE'S ARITY LOWE |
| L28359 | ADDENDUM | to §5a (func_80181F74, ov_SC03_112, wave cn) |
| L28409 | ADDENDUM | to §265 (func_8017E26C, ov_SC04_016, wave cn) |
| L28447 | ADDENDUM | to §42b (func_8018247C, ov_SC07_002, waves cu + cw) |
| L28478 | ADDENDUM | to §199-F family (func_8017EFB0, ov_SC02_021, wave cu) |
| L28533 | ADDENDUM | to §195-E (func_800CFC1C, md_MAIN_003, wave cv) |
| L28578 | ADDENDUM | to §215 addendum (func_800CB2C8, md_MAIN_033, waves cv + cw) |
| L28634 | ADDENDUM | to §236 item 4 (func_8017D268, ov_SC04_006, wave cw) |
| L28663 | What | I could not verify |
| L28695 | Harness-defect | flags (not idioms — flagged for the operator) |
| L28736 | ADDENDUM | to §250 (func_8017D7CC, ov_SC03_115 — cx/cy/cz/dr) |
| L28781 | ADDENDUM | to §225 (func_8017E190, ov_SC03_115 — cx/cy/cz) |
| L28834 | ADDENDUM | to §45-A (func_8017F6A4, ov_SC02_016 — cy/cz) |
| L28878 | ADDENDUM | to §249 (func_80182ED4, ov_SC04_004 — dp/dr/dt) |
| L28923 | ADDENDUM | to §199-A (func_801816FC, ov_SC02_005 — dp/dr/dt) |
| L28969 | What | I could not verify |
| L29012 | Harness-defect | flags |
| L29074 | §284 | COMBINE CAN REASSOCIATE TWO SEQUENTIAL BITWISE-AND MASKS INTO ONE AGAINST THE PRE-MASK VAL |
| L29078 | §285 | PRE-INITIALIZING A VARIABLE WITH A SHARED CONSTANT BEFORE A BRANCH MAKES BOTH ARMS OF THE |
| L29082 | §286 | FOLD A STATEMENT'S SIDE EFFECT INTO A COMMA-EXPRESSION IN AN ARGUMENT POSITION TO PLACE IT |
| L29086 | §287 | A STACK-FRAME HOLE BELOW TWO ADDRESS-TAKEN AGGREGATE LOCALS IS A LEADING PAD MEMBER OF ONE |
| L29090 | §288 | A REGISTER PIN DECLARED UNINITIALIZED AND ASSIGNED ONLY AT ITS LATE, SOLE USE STILL FORCES |
| L29094 | §289 | an array local's address-taken base keeps every element's store alive, even though only on |
| L29098 | §290 | A SINGLE STRENGTH-REDUCED GIV CAN DRIVE STORES TO SEVERAL DISTINCT RELOCATABLE SYMBOLS, EA |
| L29102 | §291 | THE DELAY-SLOT FALSE-VALUE: A CONDITIONAL BRANCH'S ZERO ARM MUST BE A FALL-THROUGH-ADJACEN |
| L29106 | §292 | DECLARING A SYMBOL UPSTREAM OF AN ALREADY-BANKED SIBLING THAT RELIES ON THAT SYMBOL'S IMPL |
| L29109 | §293 | THE "WHOLE-OBJECT GATE NEEDS EVERY SIBLING" LAW, WRITTEN PROPERLY: IT IS THREE LAWS, AND T |
| L29159 | §294 | ADDENDA HARVESTED FROM THE S61 GEN0/MAXTOK/MAIN/DEEPSEEK BATCH (waves ab8/ab16/ab24/ab32 · |
| L29170 | ADDENDUM | to §127 — the -O0 constant-offset fold keys on the MEMBER-ACCESS tree shape, not on the in |
| L29198 | ADDENDUM | to §261a — FOUR MORE -O0 DIALS BEYOND THE RELOAD COUNT (boot.c + md_MAIN_011/003, wave m0a |
| L29248 | ADDENDUM | to §264-3 — the explicit entry copy's BOUND: required exactly when the RAW value must outl |
| L29268 | ADDENDUM | to §172b-1 (counter-type dial) — the sll's SOURCE REGISTER is the placement discriminator |
| L29280 | ADDENDUM | to §276 — the SHARE direction: spell the second adjacent symbol RELATIVE to force ONE anch |
| L29296 | ADDENDUM | to §31's density-dummy dial (L2460/L2497) — the dose is TWO refs, and the dummy must sit w |
| L29313 | ADDENDUM | to §282 — the ADDRESS-GIV face: write the walked address INLINE so strength reduction birt |
| L29336 | ADDENDUM | to §253 — SECOND byte-proven card (upgrade from single-observation), and the placement fac |
| L29357 | ADDENDUM | to the L1800 anchor-steer bullet — a DERIVED-POINTER local silently flips the merged giv's |
| L29380 | ADDENDUM | to §31's asm→layout inference — TWO WIDTH-PAIR DISCRIMINATORS (same offset, different widt |
| L29401 | §295 | THE KERNEL-TRAP STUB: §81's jr-DETECTOR WITHOUT A TABLE IS A PsyQ SYSCALL TRAMPOLINE — ROU |
| L29456 | §296 | THE FRAME CHECK OUTRANKS THE ATLAS LEVER: READ PROLOGUE/EPILOGUE BEFORE DRAFTING ANY C — A |
| L29499 | §297 | ONE GIV SERVING MIXED-WIDTH LOADS *AND* A STORE NEEDS STRUCT-MEMBER SPELLING; CAST/INDEX S |
| L29542 | §298 | THE SHARED-TAIL POSITION DIAGNOSTIC: A FOLDED TAIL *BETWEEN* SWITCH ARMS MEANS PER-ARM DUP |
| L29567 | §299 | TWO INDEPENDENT EXTRACTION CHAINS EMIT CONTIGUOUSLY INSIDE ONE EXPRESSION; ONLY A STATEMEN |
| L29602 | §300 | S61 DISTILL BATCH NOTES (waves ab8/ab16/ab24/ab32 · g0a–g0f · m0a · ds1/ds2 · m0b) |
| L29671 | §301 | AN INTERNAL `j` CARRIES `R_MIPS_26 .text`: rtu/match_one "MATCH" COULD NOT SEE WHICH LABEL |
| L29719 | §302 | A RED BINARY IS A DRIFTED SPEC, NOT A MYSTERY: THE THREE CARVE-STATE INVARIANTS AND HOW TO |
| L29763 | §303 | MODULE ISLAND TABLES: DERIVE THE PADS AT BUILD TIME, PEEL NOTHING — THE §154-A/§260 "islan |
| L29799 | §304 | SELF-DEFINING RODATA: WHEN A FUNCTION'S `.s` IS THE ONLY OWNER OF THE DATA IT REFERENCES, |
| L29822 | §305 | "CARVE-REFUSED" AT GATE TIME IS THREE NAMED, DETERMINISTIC CLASSES — NONE OF THEM A CARVE |
| L29874 | §306 | A HAZARD `nop` IN FRONT OF A DIV-RESULT STORE IS A STATEMENT-ORDER DEFECT: THE INDEPENDENT |
| L29901 | §306a | T4 DISTILL ADDENDA (P31 S62; four byte-proven refinements to existing laws, verified again |
| L29939 | §307 | THE BRUTE-FORCE-THE-STATEMENT-ORDERS LEVER HAS A BOUND: A FAN-OUT COPY'S PRIORITY IS SCHED |
| L29983 | §308 | A NAIVE FINAL `goto` DELETES THE TARGET'S `j`+`nop`: SPELL THAT EDGE AS A TAUTOLOGICAL `if |
| L30012 | §308a | A TWO-INSTRUCTION ARM STUB LAID *BEFORE* THE OTHER ARM AND REACHED ONLY BY A TRAILING `j` |
| L30046 | §309 | A FRAME-ADDRESS EQUIVALENCE RIDES *THROUGH* A SKIPPABLE CONDITIONAL: POST-`if` STORES FOLD |
| L30086 | §310 | A TWO-OPERAND `subu`'s DESTINATION TIES ONLY TO THE OPERAND THAT IS BLOCK-LOCAL: SHARE *ON |
| L30117 | §311 | A JOIN-BLOCK STORE CAN SWALLOW AN ARM'S LOAD-DELAY `nop`: WHEN ONE ARM'S VALUE COMES FROM |
| L30159 | §312 | A BARE RELATIONAL IN AN `if` GIVES THE `slt` NO TARGET: ASSIGN THE COMPARISON INTO THE ALR |
| L30185 | §313 | A RECOVERY STAGE THAT REWRITES THE DRAFT IS PART OF THE MEASUREMENT: GATE THE RAW DRAFT FI |
| L30241 | §314 | AN IF/ELSE-IF ABS-RANGE CHECK'S C SPELLING IS INERT: FOUR STRUCTURALLY DIFFERENT REWRITES |
| L30273 | §315 | ALL-CONSTANT AGGREGATE FILL: THE EMISSION ORDER IS SHARED-LITERAL GROUPS × DESCENDING INDE |
| L30310 | §316 | A GUARD CHAIN THAT GATES A SUCCESS BLOCK ROUTES ITS FAILING GUARDS TO A LABEL **BEFORE** T |
| L30344 | §317 | A NARROW STRUCT-FIELD STORE TURNS A *LIVE SImode VARIABLE* INTO A `li`: convert.c's TRUNCA |
| L30378 | §318 | A UNARY MINUS STORED BACK INTO THE SAME HALFWORD IS COMPUTED IN HImode, SO ITS LOAD IS `lh |
| L30453 | Addendum | §148-A2 addendum — the empty-asm insn_count dial (N bare `__asm__("")` = exactly +N real i |
| L30461 | Addendum | §312 addendum — naming the compare's dest is the vehicle, the hard-reg pin on that name is |
| L30465 | Addendum | subu/sh dest reuses a pinned operand's dying register (func_8017F498) |
| L30473 | Addendum | Addendum to §261a — the -O0 increment-operator copy also fires on the POINTER LOCAL itself |
| L30477 | Addendum | Addendum to §164-XX/§165-06 — at -O0 a bare local IS a memory lvalue, so the increment ope |
| L30481 | Addendum | Addendum to §312 — the compare's named destination must itself carry a hard register: nami |
| L30485 | Addendum | Addendum to §167-12 — the single-operand volatile keepalive, re-confirmed at a gated MATCH |
| L30489 | Addendum | A §5a BARRIER SITS IN REORG'S FILL WINDOW TOO, SO ITS SIDE OF THE INNER `goto` IS CHOSEN P |
| L30493 | Addendum | Loop sentinel wrongly hoisted out of a call-containing loop (func_801835B0) |
| L30505 | Addendum | Reversed-operand sltu then xori 1 means unsigned less-or-equal (func_8017D948) |
| L30509 | Addendum | Chained *2*2 array index folds to one copy;sll, not two (func_80011380) |
| L30523 | Addendum | REGALLOC-PERM: one memory-clobber barrier insufficient — stack two (func_80182D1C) |
| L30529 | Addendum | Last if-arm's nested if un-fuses the whole preceding chain (func_8017FE88) |
| L30533 | Addendum | A plain global-RMW triplet is a fillable scheduling window too — zero drift, and the fille |
| L30537 | Addendum | Shared arithmetic that CONSUMES the selected value cannot be hoisted above the `if` — narr |
| L30541 | REFUTED | claim — Dead call-arg register address-fold: no C-level lever found (func_8017ECAC) |
| L30560 | Addendum | Truncating assign must be the lazy `||` operand, not hoisted (func_80012B58) |
| L30572 | Addendum | WIDTH sh!=lhu residual: hoist a sibling field's load first (func_80182538) |
| L30589 | REFUTED | claim — REFUTED — the `j`-slot store is an ASPSX macro-expansion hop, not a cse split; mas |
| L30591 | §NNN | REFUTED: A `sw %lo(SYM)($at)` IN A JUMP'S DELAY SLOT WITH ITS `lui $at` STRANDED ABOVE THE |
| L30615 | Addendum | Static local_type blocker survives typedef removal — it's textual (func_801588CC) |
| L30622 | Addendum | Orphan sh triplet to $sp is a write-only local array (func_8017F274) |
| L30626 | Addendum | REGALLOC-PERM: the store reads the narrow copy's register — split the one narrow local by |
| L30630 | Addendum | REGALLOC-PERM store in a cross-jump shared tail defeats §137's barrier (func_8017EDE8) |
| L30634 | Addendum | LENGTH-DRIFT nop clears when offset math precedes the symbol launder (func_80039B20) |
| L30638 | REFUTED | claim — REFUTED: a block shared across TWO switch statements is ordinary forward cross_jum |
| L30640 | §NNN | REFUTED: A CODE BLOCK SHARED BY TWO *DIFFERENT* SWITCH STATEMENTS IS ORDINARY FORWARD `cro |
| L30656 | RETRIEVAL | FAILURES this round (not new knowledge — a RETRIEVAL defect) |
| L30671 | §319 | N TEXTUALLY DUPLICATED `return v;` TAILS PUT THE LAST `or` AND THE RETURN-REGISTER MOVE IN |
| L30700 | Addendum | Masked-OR field-merge plateaus at close=10; bitfield store clears it (func_8017FD64) |
| L30704 | Addendum | Integer-space address arithmetic is a THIRD no-movable spelling, and a distant `SYM[0]` re |
| L30714 | Addendum | LENGTH-DRIFT −1 on a coalesced-away copy: a CALLER-SAVED SOURCE pin can resurrect it, boun |
| L30721 | Addendum | Return-0 statement order: extra j+move vs delay-slot fusion (func_8018BB50) |
| L30725 | Addendum | Counter zero in the DECLARATION slot, empty for-init — the prologue SHIFT-DRIFT/+K face of |
| L30743 | Addendum | The dying-pinned-register reuse on a sign-extend chain: route every later read through a s |
| L30747 | Addendum | Volatile zero-byte asm slider scrambles the prologue schedule (func_801814B0) |
| L30757 | Addendum | Register-pinned helper pointer local regresses closeness; use plain local (func_80013CFC) |
| L30761 | Addendum | §194-A addendum — the bare/colon-less fence measured NULL and only the "memory"-clobber fo |
| L30765 | RETRIEVAL | FAILURES this round |
| L30786 | §320 | THE §43 "RETURN-TYPE FLIP PAIR" IS **NOT** TU-EDIT-REQUIRED: THREE DRAFT-ONLY ESCAPES (P31 |
| L30845 | §321 | FILE-SCOPE DUPLICATE ANONYMOUS-STRUCT TYPEDEFS ARE A HARD ERROR; THE SAME TEXT AT BLOCK SC |
| L30866 | §322 | A PROBE THAT ANSWERS A *NECESSARY BUT NOT SUFFICIENT* QUESTION WILL PRICE BLOCKED WORK AS |
| L30896 | §323 | CARRYING FILE-SCOPE TYPES BETWEEN SPLIT TUs: DEDUPE BY NAME, SKIP HEADER-PROVIDED, AND THE |
| L30926 | §323a | R53, TWICE IN ONE HOUR: A FAILED BUILD LEAVES THE PREVIOUS BINARY, AND `sha1sum` READS GRE |
| L30935 | §323b | A SCRIPT THAT PARSES argv AT IMPORT CANNOT BE SHARED; EXTRACT THE PREDICATE, DO NOT COPY I |
| L30949 | §324 | THE ARITY-SELF WALL NEEDS *BOTH* HALVES: A K&R DEFINITION **AND** A NO-PROTO TU DECL; EITH |
| L30987 | §325 | REGALLOC: A SHARED SMALL CONSTANT STORED TWICE IN THE PRE-LOOP BLOCK IS A *local-alloc* $s |
| L31000 | §326 | DEFEATING ADDRESS-CSE: SPELL TWO READS OF THE SAME HALFWORD DIFFERENTLY AND GCC CANNOT SHA |
| L31009 | §327 | A RANGE TEST MUST BE HImode: WITH `s32` + A `(u16)` CAST GCC *PROVES* THE MASK REDUNDANT A |
| L31024 | §328 | THE VOLATILE ALIAS MUST BE AN *OBJECT*, NOT A CAST: `*(volatile s32*)&sym` UNFOLDS %lo INT |
| L31034 | §329 | fold-const NARROWS `(int)s16_var & 0xFFF` ONTO THE *RAW HImode PSEUDO*, BREAKING THE SIGN- |
| L31042 | §330 | THE NEIGHBOUR-SHAPE LEVER IS THE CHEAPEST FIRST MOVE, AND IT IS UNDER-USED (P31 S67; four |
| L31059 | §331 | OPEN GAP: NO LEVER ELIMINATES AN *UNWANTED DUPLICATE* COPY AT A BRANCH-TARGET BLOCK HEAD ( |
| L31071 | §332 | THE maspsx `la`-IN-A-DELAY-SLOT GAP: gcc EMITS A SYMBOLIC ADDRESS LOAD AS ONE ATOMIC lengt |
| L31096 | §332a | MAIN'S RESIDUAL FRONTIER IS CONTAMINATED WITH TOOLCHAIN WALLS: 4 OF 7 IN ONE WAVE (P31 S67 |
| L31115 | §333 | FRAME SIZE IS SET BY *DECLARED* AGGREGATES, NOT USED ONES: AN UNREFERENCED TRAILING LOCAL |
| L31129 | §334 | A RELOAD SPILL SLOT IS ROUNDED TO `BIGGEST_ALIGNMENT` (8B), SO ONE SPILLED 4-BYTE PSEUDO C |
| L31140 | §335 | AN `extern u16 A[]` READ AT A VARIABLE SUBSCRIPT ALLOCATES DEAD STACK TEMPS (~8B PER ACCES |
| L31149 | §336 | THE §5a CROSS-JUMP BARRIER GOES AT THE *BOTTOM* OF THE TWIN, NOT THE TOP: `find_cross_jump |
| L31157 | §337 | THE CC1-ONLY BLOCKER CLASS: `blocker_probe`'s STATIC ORACLE REPORTS "none" AND THE WHOLE-T |
| L31171 | §338 | `jtbl_carve._sltiu_bounds` MISREADS A NON-SWITCH `sltiu` AS A BOUNDS CHECK, OVER-SPANNING |
| L31181 | §339 | A 2-CASE SWITCH OMITS THE LOW-BOUND RANGE TEST, SO THE PRESENCE OF `slti/bnez` BETWEEN THE |
| L31209 | §340 | §194-K COROLLARY: **FLIP THE FALSE EDGE YOU CANNOT DELETE.** A "scheduler" residual can be |
| L31243 | §341 | AN HImode STORE TEMP REWEIGHTS A sched2 TIE-BREAK THAT NO STATEMENT ORDER CAN REACH (P31 S |
| L31257 | §342 | A `void *` PARAMETER CAST TO ITS REAL TYPE IN A LOCAL IS **NOT** BYTE-NEUTRAL WHEN A LATER |
| L31274 | §343 | `decl_prior`'s FLEET MAJORITY CAN BE WRONG ABOUT THE TRUE SIGNATURE — READ THE RIVALS, NOT |
| L31296 | §344 | RAISE A BIV'S global_alloc PRIORITY WITH A ZERO-BYTE REFERENCE INSTEAD OF PINNING IT; PINN |
| L31312 | §345 | A VOLATILE **STORE** EVICTS THE MEM FROM cse AND KEEPS `sh`; A VOLATILE **LOAD** BLOCKS co |
| L31322 | §346 | `c ? X : -X` TAKES expand_expr's COND_EXPR **SINGLETON** PATH (copy, then negate IN PLACE) |
| L31342 | §347 | LOOP REGISTER ASSIGNMENT IS A **DECLARATION-ORDER + LIVE-RANGE** DIAL: FIVE COMPOSABLE LEV |
| L31372 | §347-addendum | A THIRD INSTANCE, AND THE SHARPEST STATEMENT OF THE RULE (md_MAIN_025/func_800CB300, 243 i |
| L31390 | §343-addendum | SECOND INSTANCE OF THE WRONG-MAJORITY DECL (same function) |
| L31397 | §348 | THE BASE SPELLING PICKS THE ADDRESSING MODE: A SYMBOL GIVES THE 3-INSN `lui/%lo` FORM, A P |
| L31414 | §349 | RE-ASSIGN A BASE POINTER AT THE END OF THE LOOP BODY TO MAKE `n_times_set > 1` — THAT KILL |
| L31435 | §350 | A ZERO-BYTE RE-TIE SETS `reg_n_sets=2`, WHICH KILLS sched1's `birthing_insn_p` LAUNCH_PRIO |
| L31456 | §351 | `/s` (MEM_IN_STRUCT_P) IS A DIAL YOU CHOOSE PER ACCESS: A COMPONENT_REF GRANTS IT AND LETS |
| L31486 | §352 | ⚠ TWO IDENTICAL `__asm__ __volatile__("")` BARRIERS **MERGE WITH EACH OTHER** — SPELL THE |
| L31519 | §353 | USE `-fno-thread-jumps` AS AN **ORACLE** TO PROVE A RESIDUAL IS thread_jumps, THEN LAUNDER |
| L31542 | §354 | THE giv **WORTH-WHILE TEST** IS A DIAL: RE-ASSOCIATE THE ADDEND INTO THE INDEX TERM AND `s |
| L31560 | §355 | A REMAPPED SIBLING'S **SOURCE BIAS IS NOT ITS EMITTED BIAS** — DO NOT HAND-SHIFT OFFSETS T |
| L31574 | §356 | MEASURE A DRAFT IN THE TU IT WILL LIVE IN, NOT IN THE STANDALONE PROBE (P31 S68; measured |
| L31589 | §357 | ONE STRUCT POINTER, NOT TWO: A SECOND SOURCE VARIABLE BUILDS A THIRD IV (P31 S68; byte-pro |
| L31598 | §358 | (sharpens §333) — AN **UNREFERENCED** FIXED-SIZE AGGREGATE LOCAL IS LOAD-BEARING (P31 S68; |
| L31608 | §359 | (§43-adjacent) — SPELL A SIGN-WIDEN AS AN EXPLICIT TWO-STEP, FUNCTION-SCOPED TEMP (P31 S68 |
| L31621 | §360 | THE "COMPILER FOUND A SHORTER EQUIVALENT THAN THE TARGET" PAIR (P31 S68; main/func_800241C |
| L31637 | §361 | ★ — A LOOP-TAIL BYTE SIGNATURE THAT NAMES ITS SOURCE SHAPE — AND THE LAW THAT A "SCHEDULIN |
| L31682 | §362 | TWO TRAPS WHEN A CARVE MOVES A STUB INTO THE `-O0` TU (P31 S68; byte-proven, 6 fns / 2,547 |
| L31705 | §363 | ★★ — THE OVERLAY-LAYOUT ASSUMPTION IS A SYSTEMIC BUG CLASS, AND `main` IS THE EXCEPTION TH |
| L31734 | §364 | ★ — THE libgpu `P_TAG` BITFIELD SPELLING IS **OPT-LEVEL DEPENDENT** (P31 S68; two function |
| L31748 | §365 | PIN **BOTH** MASKS OR NEITHER (P31 S68; ov_SC01_000/func_8017E594, 357 ins) |
| L31757 | §366 | ★★ — `group_case_nodes` MERGES **STACKED CONSECUTIVE** CASE LABELS: GIVE EVERY CASE ITS OW |
| L31777 | §367 | RECONCILING A DECL CONFLICT BETWEEN TWO DRAFTS FOR THE SAME TU (P31 S68; main) |
| L31792 | §368 | ★★★ — THE **RELOAD-REMAT CONSTANT**: REACH A REGISTER NO PIN CAN REACH (P31 S68; ov_SC03_1 |
| L31822 | §369 | REUSE THE **COMPARE CONSTANT'S OWN VARIABLE** FOR A MASK THAT KEEPS COALESCING (P31 S68; m |
| L31838 | §370 | ★★ — A **HARD BOUND** FROM sched.c, AND THE reorg SLOT-STEAL DIAGNOSTIC (P31 S68; main/fun |
| L31890 | §371 | ★★ — CARVING A **SINGLE-OBJECT MODULE BINARY**, AND THE spimdisasm RODATA-MIGRATION TRAP T |
| L31939 | §372 | ★★★ — THE **COPY-CAPTURE PAIR**, AND THE ONE ZERO-BYTE EDIT THAT DEFEATS BOTH (P31 S68; by |
| L31977 | §373 | ★★★ — THE **DEAD-RESET CSE-BREAKER**, THE PIN THAT BREAKS A sched2 ANTI-DEP, AND WHY AN `a |
| L31979 | §3-1. | DEAD-RESET CSE-BREAKER — the zero-footprint replacement for a §195-I asm re-tie |
| L31997 | §3-2. | A REGISTER PIN THAT DELETES A sched2 ANTI-DEPENDENCE |
| L32010 | §3-3. | HARD FACT FOR THE SCHEDULING MAP — an `asm` ALWAYS has priority 1 |
| L32018 | CROSS-REFERENCE | TO §370 — checked and found INAPPLICABLE here, which is the point |
| L32026 | §374 | A `register … __asm__("$30")` RESERVATION IS **NOT HONOURED** BY `move_movables` (P31 S68; |
| L32042 | §375 | AN `$a0`-`$a3` PIN USED LATE RELOCATES AN **EARLIER** OUTGOING-CALL USE OF THAT REGISTER ( |
| L32055 | §376 | ★★★ — A STANDALONE `match_one` CLOSENESS OF 0 IS A CLAIM ABOUT THE **BODY**, NEVER ABOUT T |
| L32097 | §377 | THREE HARNESS DEFECTS FOUND IN ONE GATING SESSION, ALL "A CONFIDENT NUMBER ABOUT A SMALLER |
| L32114 | §378 | ★★★ — THE **SELF-CALLER CAST**: LET A TU KEEP CALLING THE FUNCTION IT IS ABOUT TO DEFINE ( |
| L32164 | §379 | ★★★ — **MEM_IN_STRUCT_P**: THE SAME LOAD, WRITTEN AS A STRUCT MEMBER, SCHEDULES WHERE A CA |
| L32195 | §380 | ★★★ — **A SECOND SET OF A PSEUDO DISQUALIFIES IT FROM `move_movables`** (P31 S69; main/fun |
| L32216 | §381 | THE `insn_count` HOIST THRESHOLD IS A DIAL YOU CAN READ WITH `cc1 -dL` (P31 S69; four inde |
| L32232 | §382 | TWO FOLD REASSOCIATIONS THAT NEED THEIR OWN STATEMENT (P31 S69) |
| L32244 | §383 | TWO TOOLCHAIN FACTS THE PACKS DID NOT CARRY (P31 S69) |
| L32259 | §384 | ★★★ — A CARVE-CONFIG BANK IS RED UNTIL YOU RE-EXTRACT, AND THAT LOOKS EXACTLY LIKE A FALSE |
| L32309 | §385 | ★★★ — THE **SCHED2 PRIORITY-DONOR ASM**: closing the "hoisted-invariant vs IV-init prehead |
| L32335 | §386 | ★★★ — A BYTE LOAD ON THE **BIV** BASE WAS BORN IN THE COMBINE PASS: SPELL IT AS A SHIFT-MA |
| L32361 | §387 | ★★ — **SPLIT-FOLD DISPATCH CLOBBER**: one switch case needs a reload, another must keep th |
| L32384 | §388 | ★★★ — THE **-O0 COLOURING ORACLE**: simulate `stupid.c` instead of grinding spellings (P31 |
| L32409 | §389 | ★★★ — `h_norm` IS BLIND TO INDEXED-GLOBAL RELOCS, SO FREE WORK BECOMES AN INVISIBLE SINGLE |
| L32450 | §390 | ★★★ — MINIMUM DISTANCE IS NOT MINIMUM WORK; RANK TWIN CANDIDATES BY EFFORT, AND FILTER LOO |
| L32488 | §391 | ★★ — A BYTE-ALIGNED STRUCT COPIES IN FOUR INSTRUCTIONS, A WORD-ALIGNED ONE IN TWO (P31 S69 |
| L32502 | §392 | ★★★ — THE SONNET-WAVE HARVEST (P31 S69): SEVEN TYPE/ORDER LEVERS THAT EACH CLOSED A MATCH |
| L32543 | §393 | ★★ — THE **BIRTHING BOOST**: A SINGLE-SET LOCAL IS SCHEDULED LAST; GIVE IT A SECOND SET (P |
| L32560 | §394 | ★★ — TWO ALIGN-1 ACCESSES IN ONE FUNCTION RESERVE A PHANTOM STACK SLOT (P31 S69; ov_SC02_0 |
| L32572 | §378b | ★★★ — THE FOUR VARIANTS OF THE DECL BLOCKER, AND THE TWO PLACES §378 DOES **NOT** APPLY (P |
| L32611 | §395 | ★★★ — FIVE NARROWING/PLACEMENT LEVERS FROM ONE 91-INSTRUCTION CRACK (P31 S69; byte-proven |
| L32645 | §314b | ★★ — TWO ABS-RANGE GUARDS IN ONE FUNCTION NEED **DIFFERENT SPELLINGS** (P31 S69; byte-prov |
| L32667 | §322b | ★★★ — THE CARVE CLASS IS COMPLETABLE, AND EVERY WORKTREE `CARVE-REFUSED` WAS AN INSTRUMENT |
| L32702 | §332b | ★★★ — THE §332 "WALLS" ARE A PER-OBJECT ASSEMBLER MODE, NOT A C LIMIT — 6 CLOSE AS REAL C |
| L32722 | §378c | ★★ — THE FIFTH DECL-BLOCKER VARIANT: THE DRAFT REDECLARES WHAT THE TU ALREADY OWNS (P31 S6 |
| L32737 | §396 | ★★★ — SIX LEVERS FROM THE S69 SINGLETON ROUND, INCLUDING ONE THAT ONLY A `COND_EXPR` REACH |
| L32785 | §397 | ★★★ — RE-RUN THE TWIN SCAN AFTER EVERY EXEMPLAR BANK; A CLUSTER SIBLING IS FREE THE MOMENT |
| L32818 | §396g | ★★ — A GUARD LADDER'S RUNGS MUST STAY SYMMETRIC OR `reorg.c` LOSES ITS BRANCH REDIRECT (P3 |
| L32835 | §398 | ★★★ — `family_remap` CARRIES THE **SOURCE** TU's DECL ENVIRONMENT INTO A DESTINATION THAT |
| L32865 | §398b | ★★ — NAMING A SUB-EXPRESSION IN A LOCAL CHANGES WHICH PSEUDO SURVIVES; INLINE IT AT BOTH U |
| L32892 | §399 | ★★★ — FOUR LEVERS FROM THE FINAL S69 ROUND (P31 S69; each byte-proven, none previously in |
| L32932 | §400 | ★★ — A BASELINE CHECK THAT CONFLATES "ABSENT EVERYWHERE" WITH "CHANGED UNDER US" SILENTLY |
| L32967 | §401 | §401 |
| L33000 | §402 | §402 |
| L33024 | §403 | §403 |
| L33056 | §404 | §404 |
| L33092 | §405 | ★★★ — THE S70 WAVE HARVEST: 130 agents, 113 MATCH, and the laws they brought back |
| L33098 | §3-A. | THE ORACLE HAS A HOLE: match_one cannot see a jump table (§405-A) |
| L33108 | §3-B. | THE SCHEDULER DIALS (the dominant residual family this wave) |
| L33124 | §3-C. | REGISTER ALLOCATION FROM C, WITHOUT PINS |
| L33140 | §3-D. | INTEGRATION IS STILL THE BOTTLENECK, AND THE TU IS THE AUTHORITY |
| L33148 | §3-E. | WHAT THE AGENTS REFUTED |
| L33158 | §406 | ★★ — THE PROLOGUE-WEAVE CLASS IS MECHANICAL AND LARGE (134 open stubs) |
| L33180 | §407 | ★★ — LATE-WAVE ADDENDA TO §405 (the last agents in) |
| L33209 | §408 | ★★★ — §406 REFUTED AS A SWEEP: THE SHAPE IS THE FAMILY, THE DISAGREEMENT IS THE DEFECT (P3 |
| L33261 | §409 | ★★★ — THE S71 JOURNAL-FUELLED WAVE: 100% FIRST-PASS MATCH, AND THE NINE LAWS IT BROUGHT BA |
| L33288 | §3-The | nine laws this wave produced |
| L33353 | §410 | ★★★ — COPY THEN ACCUMULATE ON THE COPY: resolving the birthing-boost vs register-allocatio |
| L33386 | §411 | ★★★ — THE PACK MUST CARRY THAT FUNCTION'S OWN HISTORY (P31 S71; measured 38/39 vs 124/131) |
| L33424 | §412 | ★★★ — §323 CARVE BLOCKER 2 WAS A REGEX THAT COULD NOT SEE PAST `__attribute__` (P31 S71) |
| L33473 | §413 | ★★★ — DIFFICULTY IS THE RESIDUAL CLASS, NOT `nins` — ROUTE THE MODEL TIER OFF HISTORY (P31 |
| L33510 | §414 | ★★★ — `parallel_gate` ON `main` IS A FALSE PASS, AND THE RULE WAS ALREADY WRITTEN DOWN (P3 |
| L33547 | §415 | ★★ — A FILE-SCOPE DECL MAKES gcc-2.7.2 MERGE THE TU'S LATER *BLOCK-SCOPE* EXTERNS INTO IT |
| L33572 | §416 | ★★ — FOUR LEVERS FROM THE S71 OVERNIGHT LANE, none of which the cookbook held (P31 S71) |
| L33605 | §417 | ★★★ — A REGISTER PIN CAN BLOCK `jump.c`'s SELECT COLLAPSE, AND UNPINNING THEN EXPOSES A `c |
| L33632 | §418 | ★★★ — TWO LOOP-STRUCTURE LEVERS: MAKE THE SECOND INDEX A GIV, AND KEEP A TABLE ADDRESS UNF |
| L33658 | §419 | ★★★ — WHEN A PIN IS IMPOSSIBLE, WIN THE local-alloc DENSITY CONTEST INSTEAD (P31 S71; byte |
| L33692 | §420 | ★★★ — A MULTI-CLUSTER SYMBOL REBASE, AND THE BARE-NAME DEDUP THAT HID THREE QUARTERS OF IT |
| L33729 | §421 | ★★★ — A `la $tN` + `addiu` PAIR CAN BE A **RELOAD** ARTIFACT THAT NO C SPELLING REACHES (P |
| L33760 | §422 | ★★ — QImode ARITHMETIC VIA `(u8)(x - K)`, AND `flag ^ 1` NEEDS ITS OWN TEMP (P31 S71; byte |
| L33780 | §423 | ★★★ — "MATCH IN ISOLATION + GATE REJECTS + CAUSE NOT DETERMINED" ⇒ GREP THE TU FOR A FILE- |
| L33807 | §424 | ★★★ — EQUAL-PRIORITY STORES COME OUT **REVERSED**: sched1's LUID tie picks the LAST statem |
| L33829 | §425 | ★★★ — `sb` ALIASES SCALAR GLOBALS WHILE `sh`/`sw` STRUCT STORES DO NOT, AND TWO MORE ALIAS |
| L33855 | §426 | ★★★ — main's SWITCH FUNCTIONS WERE NEVER A CODEGEN WALL: ONE RODATA CARVE HAD BEEN MISSING |
| L33931 | §427 | ★★ — A HASH IS A CORRECTNESS ORACLE WITH ZERO DIAGNOSTIC CONTENT; PRESERVE THE RED ARTIFAC |
| L33950 | §428 | ★★★ — A ZERO-BYTE CROSS-JUMP BARRIER: ADVANCE THE POINTER INSIDE EACH SWITCH ARM (P31 S72; |
| L33988 | §428a | ★★★ — TWO RESIDUALS THAT MOVE IN OPPOSITE DIRECTIONS UNDER EVERY LEVER USUALLY SHARE ONE C |
| L34023 | §430 | ★★★ — A SHARED TAIL IS A LATE CROSS-JUMP MERGE, NOT A SOURCE `goto` — AND SPELLING IT AS O |
| L34061 | §431 | ★★★ — SPLITTING A 27,000-LINE TU AT ITS ORIGINAL BOUNDARIES: THE JTBL SPANS TELL YOU WHERE |