Files
BFM-decomp/docs/distill/atbhbkbl.md
T
Drew T 7740f14143 docs(cookbook): 265-267 from the at/bh/bk/bl distill batch (165 candidates)
265 the verbatim-asm bank lane — two in-tree precedents, the MASPSX decimal-immediate
    rule, and a REVIEW-ADDED accounting caveat: an __asm__ body is not an INCLUDE_ASM
    stub, so corpus.stubs() counts it as MATCHED. Bytes proven, function not
    decompiled. Fine for hand-written asm; for an -O0 C function the right answer is
    the -O0 object, and this lane is a temporary hold at best.
266 the inert-rider law — a lever is only citable when its solo removal breaks the
    match. Measured 4 of 8 credited levers on this batch were byte-inert: a $2 pin
    silently dropped, a volatile the scheduler already ordered, a named zero, and a
    statement split. The banked artifact CONTAINS the rider precisely because it is
    inert, which reads as proof. R40 applied to the flywheel itself.
267 eleven addenda to existing sections, six with fresh match_one A/Bs.

The batch's real headline: 145 of 165 candidates were ALREADY COVERED, and 8 claims
were refuted (4 by live A/B) — the harvest is mostly re-derivation, and an unchecked
wrong law is worse than no law.
2026-08-24 13:35:46 -06:00

42 KiB
Raw Blame History

Distillation — waves at · bh · bk · bl (batch .run/distill_inflight/atbhbkbl.json)

PROPOSED ONLY — nothing here has been applied to docs/matching-cookbook.md or docs/cookbook-index.md. Reviewer lands the sections. All A/B evidence lives under .run/s59_distill/ (each variant file re-runnable with the match_one line quoted beside it).

0. The ledger — counts first (R41: every number's denominator stated)

165 candidate notes read — all of them — from 4 files: at 52, bh 60, bk 42, bl 11 (matches the batch manifest's novel: 165).

disposition rows of 165
Already covered (cited § per row below; most by the 3-hour-old §233–§259 layer) 145 87.9%
Feed a proposed addendum (11 addendum items, ADD-1…ADD-11) 9 5.5%
Feed a proposed new law (§265; 2 exemplar cards) 2 1.2%
Refuted (8 distinct claims across 9 rows; 4 by live match_one A/B, 4 by artifact) 9 5.5%

One further proposed law (§266) is sourced from this distillation's own A/B campaign, not from any single candidate row — its evidence is the 4-of-8 inert-lever rate measured below.

Batch-hygiene note for the campaign: wave at lies inside the aa–bg range that §233–§259 already mined (its file was re-emitted at 11:30 after that commit). 46 of its 52 rows resolve to sections that landed three hours ago, several citing these exact functions by name (func_8018270C → §249-3/§257-1, func_8017ECA8 → §236-6, func_80181D68 → §236-3, func_8017FCBC → §242-2/§250, func_8017FA94 → §234/§238/§226-add). A harvester dedup guard (skip waves ≤ bg) would have shrunk this batch by a third.

0a. Per-candidate disposition (one line each; spot-check any row)

Verdicts: cov §X = already covered by §X (drop; where marked ⊕ the row is ALSO a cross-confirmation card worth appending to §X per §259's standing instruction — collected in ADD-11). ADD-n = feeds proposed addendum n. §265 = feeds the new law. REF = refuted (see part 4).

Wave at (52):

fn verdict
func_800CF010 cov §236/§259-4 (gate-null; decl audit clean)
func_8018270C cov §249-3 + §257-1/-2 (its asm-la instrument is already quoted verbatim at cookbook L23874-84)
func_8017FB04 REF-3 (note analyzes the HANDWRITTEN ov_SC03_030 homonym; also feeds §265's cautionary tale)
func_80188770 REF-7 (volatile lever inert by A/B) · salvage → ADD-1 (masked-jal illusion)
func_8018516C cov §209-addendum (cited there by name — the "no-local row")
func_801A5BBC cov §246-UNSOLVED (cited by name) + §259-4
func_80181D68 cov §236-3 (cited by name)
func_800CF078 cov §236/§259-4
func_8017FDE4 REF-4 (common.h re-include hypothesis; guards exist) · rest cov §236-5/§195-A
func_80181864 cov §259-4
func_80187074 cov §259-4 + §237
func_80187118 cov §214-addendum retrieval note + §195-F
func_801AB5D4 cov §246-UNSOLVED (cited) + §259-4
func_801832D0 cov §259-4 (gate infra)
func_80180820 ADD-2 (§42a: named shared-const across a call = iso→TU drift hazard)
func_8017DA98 cov §236-9 (cited by name, "×2")
func_8018BB18 cov §259-4 + §260/§260-A (jtbl pipeline now automated)
func_8017FA94 cov §238-1 + §234 + §226-addendum (cited by name in all three)
func_801839C4 cov §214/§238 ⊕ (verify twin by callee identity) + §236-1
func_801A06AC cov §259-4 (wave-batch revert semantics)
func_8018017C cov §259-4
func_8017ECA8 cov §236-6 (cited by name — narrow-prototype def-site mask)
func_8017FCBC cov §242-2 + §250 (cited by name in both)
func_8017FA18 cov §223/§213 (self-declared no-gap)
func_801A01D4 cov §193-A + §223 (self-declared)
func_801821A0 cov §247/§225 (fall-through returns)
func_801819D0 cov §238 tell-4 + §236-7 (both cite it by name)
func_800CEFBC cov §259-4
func_801818C0 cov §259-4 (its own "duplicated 22nd statement" warning stands as the next lever)
func_80180C90 cov §193-A + §223-A (stolen delay-slot constant)
func_801A5C44 cov §236-8 (cited) + §237-escape-4 + §239-2 (cited)
func_80180880 cov §259-4 + §247 (its slt const,ret reading is quoted there)
func_80180CE0 cov §236-3 (callee defined below the splice) + §164-74
func_8017F604 cov §223-B + §236
func_8017EAE4 cov §236-1 ("cast at the use site") + §227
func_80182228 cov §259-4
func_80185D98 cov §259-4 (stray scratch-dir duplicate = gate-infra suspect)
func_8017EF50 cov §236-5/§103 (decl placement file→block)
func_8017EF0C cov §249-3 (zr copy) + §238-3 (name-grep trap — cited by name)
func_8017FA6C cov §259-4
func_80180800 ADD-3 (§236 item 10: leftover INCLUDE_ASM stub = duplicate definition)
func_801A23A8 cov §236-8 family (def-side sig vs fleet canon; '?'-row caution)
func_80180B1C cov §238-1 (cited by name)
func_801884F4 cov §259-4
func_801A23FC cov §208-addendum (per-block naming splits) + §220
func_80183038 cov §259-4
func_8017EFE0 cov §236-8 (caller-stub decl conflict = TU edit)
func_800D2704 cov §211-addendum-4 (init order = emission order) + §3-T4
func_80180398 cov §250 + §235 (%hi(SYM+K) via aggregate) + §216 + §226 (composition)
func_801AEB94 ADD-8 (§245: re-tie barriers pin call-arg setup — A/B-proven)
func_8017FE54 cov §164-57/§195-F (ternary collapse) + §211 (init hoist)
func_80182D3C cov §259-4

Wave bh (60):

fn verdict
func_800D0440 §265 card 1 (verbatim-asm lane, -O0 stranded; MASPSX decimal rule)
func_8017E7C4 cov §225-3 ⊕ (its winning form IS §225-3's construct at the opposite constant polarity)
func_80183730 cov §193-A/§103/§41/§195-A (self-declared)
func_801E2BE0 ADD-6 (shift-as-test (x<<16)!=0 — 3-way A/B-proven) · rest cov §208-inv/§226/§245-2
func_80180648 cov §3-T4 + §223 (self-declared)
func_8017E940 cov §238 (stale oracle mount) + §48-C2 (two-statement block-copy dests noted in ledger)
func_8018107C cov §164-61/§136c (self-declared)
func_801819A0 cov §236-2 ⊕ (two block-scope externs, different types, one TU — strongest confirmation card yet)
func_80182A54 cov §251-2 (&~3 → addiu -4)
func_801808F0 cov §238 ⊕ (homonym; callee-set tell)
func_80181C9C cov §236-4(c) (block-scope typedef shadow)
func_801826A4 cov §236-1 (tu row beats twin's decl layer)
func_80181DC0 cov §234 (negative addiu chain constants) + §165-11 + §194-E
func_80182CE4 cov §226-addendum (slot order; pad-first) — its promotion request is already satisfied
func_8017CF68 cov §236-5 + §237 (both escapes, stacked)
func_8018208C cov §20 pointer-var bullet (index L1907) ⊕ (indexed-global instance)
func_80183994 REF-6 (named-zero return-pseudo split inert by A/B)
func_80180108 cov §20/§229-addendum (held pointer for global RMW)
func_801816C8 REF-5 ($2 pin inert by A/B; §257-2 confirmed live) + §238 (twin mislabel)
func_80183668 cov §247/§3-T4 (inverted guard, cross-jumped tail)
func_801E585C cov §236-4(c) (block-scope typedef shadow, SV4)
func_801870D4 cov §225-4/§227/§194-E (self-declared)
func_801802CC (SC03_112) cov §238 + §225-10 (dual constant materialisation = unconditional store)
func_801E4D98 cov §237 (cast-call to consume $v0 of a void-defined callee)
func_8017D1E0 cov §251-1 (+ 0xff byte decrement — cited there)
func_8017FC80 cov §214-addendum retrieval note (grep engine_core.h for DEFINE_)
func_80181090 cov §238 (task-header path outranks replay)
func_80182AF8 cov §209-addendum (s16 temp → truncation copy off the dead arg reg; inline stores)
func_801803F0 cov §234 ⊕ (s16 record element → addiu -2; u16 → li 0xFFFE)
func_80181D04 cov §165-17-correction L19102 (temp width = sched1 dial) — discovery gap #2
func_80186124 cov §8c-3 + §236-8 + §237
func_801822D8 ADD-7 (§256: single-guard goto, then-block out of line at tail — A/B-proven)
func_801914A0 cov §252-related + §172b ⊕ (u16 → andi vs s16 → sll 16 on decrement test)
func_80182030 cov §247/§3-T4 (beq-to-else arm swap) + §234
func_80181D60 cov §205 (chained order; self-declared)
func_80190B14 cov §237 (cast-call at every site; placement of the arg copy)
func_8017F63C cov §247 + §48-C2 + §226-addendum (decl order = slot order)
func_8017F724 cov §246-3 ⊕ (pointer-IV split killed by index form — func_8017DC50 is already the exemplar)
func_8018F194 cov §255 + §213 ⊕ (empty case 1: between {0,2}) — discovery gap #3
func_801822E8 cov §238/§194-E (self-declared)
func_8017D82C cov §238-positive ⊕ (grep by distinctive immediate bundle)
func_80180DC0 cov §162c/§161c (self-declared)
func_8017D7A4 cov §214 (mid-similarity twin = guard/store idiom only)
func_801E28D0 ADD-5 (§1/I1 inverted range-test polarity — A/B-proven)
func_80180778 cov §237 (void decl + cast)
func_80181BE4 cov §205 (chained equal constants share one li/lw) + §162
func_80190798 cov §236-1/-2 (stale file-scope externs poison the TU; declare before casting)
func_8018060C cov §193-A (self-declared)
func_80184500 cov §238 (wrong-function seed)
func_801816D8 cov §238 (stale shard redirect) + §3-T4
func_8017EDC4 cov §234 ⊕ (u16 field → ori 0xff00; s16 → addiu -0x100) + §213-3 (one struct, not scalars)
func_80181230 cov §243 reading rule + §208 (naming = the barrier); its refuted-levers list noted in ADD-11
func_8017F4DC cov §238 + §194-E
func_80180E14 cov §211-addendum (comma-increment clause — cited verbatim there)
func_8019070C cov §193-A/§237 (self-declared)
func_801802FC cov §16N+3 (ladder arithmetic; /5 rung) + §167-39
func_80181D80 cov §162i1 (self-declared)
func_8017FF6C cov §234 ⊕ (0xC800 u16 → ori) + §247 + §250
func_8018046C REF-8 ((x−1)==−1 "fold" inert by A/B — all three spellings MATCH)
func_8017EC38 cov §193-A/§194-E (self-declared)

Wave bk (42):

fn verdict
func_80181C00 cov §236-4(a) + §228-3 + §259-11 (standalone-harness fact)
func_801887A0 cov §194-E + §243 reading rule (inline re-reads ⇒ reload)
func_801830B4 cov §214-addendum-10 ⊕ (twin C comments lie — *24 text vs *48 bytes)
func_8017E230 REF-2 (K&R headline; banked artifact is ANSI-prototyped + $16 pin) · rest cov §167-30/§220
func_8017E79C cov §220-addendum (bare parameter, no s0 local) + §194-E
func_8018117C ADD-9 (§213/§217: adjacent pre-call stores are ONE aggregate; scalar neighbor dead-stored — A/B-proven)
func_80188770 (bk) REF-7 dup (same volatile claim, same salvage → ADD-1)
func_8017E448 cov §236-1/-2 ⊕ (the conflict class on a fn-ptr TABLE extern) + §250
func_801892FC cov §214-addendum retrieval (twin = dedup stub; grep constants)
func_80180F68 cov §223-B + §176-A (pre-call store fills the jal slot) — discovery gap #1
func_8018603C cov §237 + §215-addendum ("pin the value, not the pointer" = item-2 family)
func_801802CC (SC02_005, 43/43) cov §194-E + §231-5 (wrong-argument reading — param vs handle)
func_801857F4 cov §238 ⊕ (same-VA cross-overlay; similarity useless as identity)
func_800CB06C cov §193-A + §225-8 (early-return layout)
func_801EA63C cov §254-adjacent + §263 (forward the parameter; a literal 0 emits move a0,zero)
func_8017D490 cov §195-A + §250-boundary (by-address vs by-value read off the arg-register materialisation)
func_8018EF1C cov §3-family (self-declared)
func_801875A4 REF-1 (slot-store ⇒ store-AFTER-call — artifact shows the opposite; §223-B re-confirmed)
func_8017D7A0 cov §208-addendum (split pointer locals shorten live ranges) + §237 + §214-8
func_8017EB38 ADD-10 (§237: la pair above sw $ra = outgoing-argument materialisation — arity read)
func_8017DB5C cov §259-4 + §195-A
func_8017D454 cov §193-A/§194-E (neighbour beat twin)
func_8017F528 cov §193-A (self-declared)
func_8017EE80 cov §238 (header path vs binary under audit)
func_801802CC (SC02_005, 2nd note) cov §238 (two prior sessions read other overlays' same-address .s)
func_80181270 cov (self-declared no-gap)
func_800CB234 cov §176-A1 + §223-addendum ("read the slot before the block order")
func_80186870 cov §194-E + §214 (twin misdirect at 0.60)
func_8017FC3C cov §195-A + §227 (lhu-vs-lh via cast, decls untouched) + §193-A
func_80181E3C cov §194-E + §237-arity (local call shape wins over 3-binary fleet row)
func_8017D710 cov §226-addendum (pad forms; its [2]-address-taken→0x10 measurement logged in ADD-11)
func_80182C1C cov §243 reading rule + §251-2 (composition: name the flag word above the aliasing narrow store)
func_800CBA44 §265 card 2 (handwritten GTE → whole-body __asm__ __volatile__)
func_80187268 cov §179-D/§195-J + §35 (unsigned ⇒ sltiu)
func_8017E234 cov §194-E (self-declared)
func_8017E6FC cov §193-A/§194-E + law 2 (house style wins)
func_8018EE00 cov §3-T4/§247 (inverted polarity; li v0,4 slot fill)
func_8017E740 cov §225-2/-8 (flat common tail + early return, not `
func_80187460 cov §255/§222 (balanced middle-rooted tree; self-declared)
func_800CAE0C cov §193-A (self-declared)
func_800CB2CC cov §252-reading + §236-9-family (memcpy(dst,src,8) per L1755) + feeds ADD-2 (literal args vs named const) + §237-arity
func_8017E4AC cov §48-C1 (self-declared)

Wave bl (11):

fn verdict
func_8017F7F0 cov §238 ⊕ (interleaved same-name cards; "trust the .s on disk over a replayed diff")
func_8017EF64 ADD-4 (§225-3/-4 mirror: value in the TAKEN arm + trailing return 0 — A/B-proven)
func_8017DF88 cov §220-addendum + §1412 loop form (their interaction logged in ADD-11)
func_8018A61C cov §199-A + §227 (self-declared)
func_801851CC cov §20/§229-addendum (named pointer local) + §164 second-read tell
func_80180EFC cov §226-4-INVERSE + §209-addendum no-local row ⊕ (cross-confirms both; was single-card)
func_80186D58 cov §164-48 (self-declared)
func_800CB61C cov §223-A ("the $v0 in the slot is the PRECEDING call's return") + §42a struct-assign
func_80187798 cov §194-E (banked twin supplied the exact && search shape) + §211 loop dials
func_80189808 cov §194-E (self-declared)
func_80181678 cov §193-A (self-declared)

1. Proposed new sections

§265 — THE VERBATIM-ASM BANK LANE: A FUNCTION NO -O2 C CAN EVER MATCH BANKS AS A RAW __asm__ BODY (P31 S59b; two banked cards, two in-tree precedents)

The symptom you see in a diff. Every draft plateaus at SIZE-MISMATCH or an unclosable structural residual, and the target has one of the un-compilable tells: the -O0 prologue (addu $fp,$sp,$zero / 21F0A003, nop in every delay slot, per-statement li) while the object's Makefile globs compile it -O2 (§261: 116 functions / 14,148 ins are stranded this way — nothing matches src/md_*/); or the splat header says /* Handwritten function */; or the shape is one gcc-2.7.2 never emits (a bgez whose OR-path falls through into a j chain, hand-placed GTE hazard nops). No C source can score MATCH against these under the object's real CC1FLAGS. Stop drafting C.

The mechanism. A raw __asm__ body is opt-level-independent: cc1 passes the string through untouched, so it emits the identical instructions whether the TU compiles -O0 or -O2, and the ordinary whole-binary gate accepts it the moment the INCLUDE_ASM stub line is replaced. Two byte-banked forms:

  1. File-scope block (for a stranded ordinary function): transcribe the whole .s — __asm__(".text\n.align 2\n.globl <fn>\n.ent\t<fn>\n" "<fn>:\n.frame $sp,40,$31\n.mask 0xC0010000,-16\n.fmask 0,0\n" ".set\tnoreorder\n" …every instruction… ".set\treorder\n.end\t<fn>\n"); Banked: func_800D0440 (93/93, md_MAIN_003 — a gcc -O0 body inside an -O2 module, at src/md_MAIN_003/md_MAIN_003.c:329). Precedent: func_80185810 (src/ov_SC03_105/ov_SC03_105_jr_8017C8D0.c:5493).
  2. C-definition wrapper (for a /* Handwritten function */): void <fn>() { __asm__ __volatile__(".set\tnoreorder\n" … ); } Banked: func_800CBA44 (109/109, md_MAIN_027, handwritten GTE add-halfwords loop, at src/md_MAIN_027/md_MAIN_027.c:225). Precedent: src/800b2.c.

The transcription rules (each one cost a compile or a session somewhere):

  • MASPSX REJECTS HEX IMMEDIATES inside __asm__ strings — the error is invalid literal for int() with base 10: '0x20'. Every immediate must be decimal (65535, -40, 24). %hi(SYM)/%lo(SYM) and bare jal <sym> work and relocate correctly.
  • Transcribe verbatim, model nothing. The -O0 $fp prologue, every delay-slot nop, and fake frames all stay: func_800CBA44 carries a mid-body addiu $sp,-8 + lw 0x18/0x1C($sp) whose only purpose is reloading stack args 5/6 and hosting cfc2 flag spills — transcribe it, do not turn it into C locals.
  • Ship NO C externs with the file-scope form. The asm resolves symbols at link time; a guessed type for an otherwise-undeclared global (D_800EC894) is pure §236-1 conflict risk with zero benefit.
  • Leave the recovered C semantics in a comment beside the body so the eventual real decomp (post §260/§261 lane work) starts warm.

What was tried and failed (the reason this lane exists): three sessions of near-79/83 SIZE-MISMATCH C drafts on func_800D0440 against a hardcoded -O2 oracle — a feedback loop that cannot converge (§261); and a 7-oracle-call full lever sweep (polarity flips, goto tails, ternaries, pins, hoists, rtps nop orders) on the /* Handwritten function */ homonym of func_8017FB04 (ov_SC03_030, 83 ins, rtps/ctc2) whose bgez-with-OR-fallthrough tail no compiler output ever contains — see Refuted #3 below. Check the handwritten tag and the §261 prologue oracle FIRST; grep -l 'Handwritten' asm/<ov>/nonmatchings/*/<fn>.s is free.

Boundary. This banks bytes, not understanding — it is the escape hatch for the §261-stranded population and hand-written asm only. An ordinary -O2 function that merely resists you is not in scope; neither is an -O0 function already inside an _o0* object (those bank as real C per §261a and are STRICTLY easier). Grep bait: verbatim asm, asm body, handwritten, maspsx hex immediate, decimal immediates, -O0 stranded, .set noreorder body.

§266 — THE INERT-RIDER LAW: A LEVER IS ONLY CITABLE WHEN ITS SOLO REMOVAL BREAKS THE MATCH (P31 S59b; measured 4-of-8 on this batch)

The symptom. A victory note — or your own session memory — credits a MATCH to one named lever ("the volatile is what makes the ordering stick", "fell to a single $2 pin", "only the named local splits the pseudos", "separate statements block the fold"). The lever was added in the same edit as other changes, and the note's confidence is absolute.

The mechanism. Near-miss iteration stacks edits. When the miss closes, the last-added lever gets the credit — and byte-inert riders survive into the banked body precisely because they are inert: a register __asm__("$2") pin in a function with a call is silently dropped (§257-2), a volatile on an RMW the scheduler already orders is a no-op, a named constant local coalesces to the same RTL. The banked artifact then contains the rider, which reads as proof.

The instrument. match_one the banked body with the lever removed — one edit, ~20 s, private scratch. This distillation ran it on all 8 solo-attributable lever claims in the batch. Four were inert (the banked body matches with the lever stripped):

card credited lever solo A/B
func_801816C8 (ov_SC03_093) register s32 q __asm__("$2") on the modulo result pin / no-pin both MATCH 21/21 — §257-2's silent drop, confirmed live
func_80188770 (ov_SC05_010) volatile on the post-call counter RMW volatile / plain both MATCH 54/54
func_80183994 (ov_SC02_011) t = 0; … return t; naming to split return pseudos named / literal return 0 both MATCH 103/103
func_8018046C (ov_SC03_024) separate load/dec/store statements to block a (x−1)==−1 fold separated, fused-temp, and compound-in-condition all MATCH 69/69

and four were load-bearing (removal breaks it): func_8017EF64 (+2 LENGTH-DRIFT), func_801E28D0 (−4), func_801822D8 (25 mismatches), func_801AEB94 (SCHEDULE-REORDER/4) — plus func_801E2BE0 (1 mismatch) and func_8018117C (−2) from the same campaign. A/B files: .run/s59_distill/.

The law. Before a lever enters a note, a card comment, or this cookbook: strip it from the otherwise-final body and recompile. If the match holds, the lever is a rider — record the actual spelling that survives (here: the named quotient local, the statement shapes, the plain RMW), not the rider. This is R40 (exonerate the instrument) applied to the flywheel itself, and it is why three of this batch's five "law-grade" candidate claims died in review. Harvest-note convention: write "banked WITH X; X not solo-A/B'd" unless you ran the A/B. Grep bait: inert rider, lever attribution, solo A/B, pin did nothing, volatile did nothing.


2. Proposed addenda (append each under its named section)

ADD-1 → §231 addendum (also cross-ref from §195-D) — THE MASKED-jal "MISSING CALL" ILLUSION

A relocation-masked jal can render in match_one's diff pane as if the call were DELETED — the aligner shows the slot's instruction where you expect the jal, and a drafter reads "my call didn't emit" (several near-15/17 verdicts on func_80188770 were exactly this misdiagnosis, in both its wave notes). The call was always there; §195-D's mask_for returns 0 for every j/jal word. The 20-second probe: compile a one-line body f(p){g(p);} and diff — if the jal appears there, it was never missing in your draft either. Read the masked columns as alignment, not absence.

ADD-2 → §42a addendum — A SHARED CONSTANT NAMED IN A LOCAL ACROSS A jal IS AN ISO→TU DRIFT HAZARD; WRITE BARE LITERALS

§42a lever 4 documents const-load sinking past a call, but not this: a s32 k = 0x40; reused on both sides of a jal keeps a pseudo live across the call, giving global-alloc the choice between a callee-saved home and rematerialising li — a choice that is stable in isolation and can flip under the real TU's ambient pressure (the §42a iso-MATCH→real-TU class). Bare literals at each use delete the freedom. Cards: func_80180820 (ov_SC03_094 — the true twin func_80181644's banked C uses bare literals; the named-local draft iso-MATCHed and failed the gate) and func_800CB2CC (md_MAIN_027 — "passing literal 1 to both calls lets gcc schedule li s0,1 after the address calc; a named const got scheduled too early"). Honesty bound: iso-side both spellings can MATCH, so this is a bank-side rule; it cannot be A/B'd by match_one alone.

ADD-3 → §236, item 10 — THE UN-DELETED INCLUDE_ASM STUB IS A DUPLICATE DEFINITION

The tenth way a byte-perfect body fails the gate, and the only one that is pure splice mechanics: the C definition lands but the function's own INCLUDE_ASM(...) line is not removed — two definitions of one symbol, whole binary red, zero instruction diff. func_80180800 (ov_SC03_030) burned a full session on body levers before the stub was found; the shard-replay framing ("wrong in ONE place") points at the body when the wrong place is the line above it. Add to §236's PROCEDURE: grep the TU for INCLUDE_ASM.*<fn> after every splice (a lingering .s file in nonmatchings/ is normal and harmless — §238; the stub line is the killer).

ADD-4 → §225-3/-4 addendum — THE MIRROR ROW: VALUE-RETURN IN THE TAKEN ARM + TRAILING BARE return 0

§225-3's exemplar puts the constant on the early-return edges and the computed value on the fall-through. The mirror shape exists and has its own spelling: when the target's guard beqz jumps to the epilogue with the zero written in its own delay slot — counter-intuitively clobbering the just-tested register (andi $v0,0xFF ; beqz $v0 ; addu $v0,$zero,$zero) — the source is if (A != 0) { return <computed>; } return 0;: guard-positive, computed predicate in the taken arm, zero on the fall-through. A/B-proven on func_8017EF64 (ov_SC01_009, 24/24): rewriting it as the early-return ladder if (A == 0) return 0; return B == 0; drifts +2 — the beqz slot empties to nop and a trailing move v0,zero block appears. The wave note also byte-refuted (a) A && B as a value (boolean homed in $s0, +sw pair), (c) the ternary cond ? B : 0 (per §195-F it re-canonicalises), and (d) an accumulator local (homed callee-saved). Reading tell worth its own grep string: a delay-slot write that clobbers the branch's own tested register is the other path's return constant.

ADD-5 → §1/I1 addendum — THE INVERTED RANGE TEST: (u32)(x-lo) >= N WITH THE ZERO-ARM AS THE TRAILING else

I1 shows only the positive layout. When the target emits sltiu $v0,(v-lo),N ; bnez → <zero-store>, the source is the NEGATED range test with the in-range body as the trailing else: if ((u32)(v - 5) >= 0x4B5) { …out-of-range arms… } else { D = 0; }. A/B-proven on func_801E28D0 (md_SC03_135, 35/35): the natural if (in-range) D = 0; else … polarity drifts −4 with 22 mismatches (beqz layout, different join). This is §247's branch-count read applied to I1 — cite both.

ADD-6 → §172b-1 / §264 addendum — SHIFT-AS-TEST: (x << 16) != 0 TESTS THE LOW HALF WITHOUT TRUNCATING THE PSEUDO

A lone sll $v0,$sN,16 feeding only a beqz/bnez, while $sN itself stays RAW for a later sh, is not a cast and not an extend-pair: the source tests the low halfword as an expression, leaving the variable's mode alone: s32 v; … if ((v << 16) != 0) { …; store(v); }. Three-way A/B on func_801E2BE0 (md_SC03_135, 56/56): the (x<<16)!=0 spelling MATCHes; (u16)v != 0 emits andi v0,s0,0xffff (1 mismatch, OPCODE-MIXED at the tail test); declaring the local u16 also emits andi. File this beside the extend-tell LANE ALIASES block at §172b so the lane label greps to it.

ADD-7 → §256 addendum — THE SINGLE-GUARD GOTO: THEN-BLOCK OUT OF LINE AT THE TAIL

§256 covers goto-dispatch. The degenerate single-guard case exists and no structured spelling reaches it: the target lays the guard's then-body after the function's return flow, entered by one forward beq, with the inline else-chain ending in j .Lepilogue. The source is an explicit goto: if (v0 == -1) goto L1; …else-work…; return; L1: …then-work…;. A/B-proven on func_801822D8 (ov_SC01_009, 36/36, banked with the goto): the structured if/else-if inlines the then-body at the head — 25 mismatches, −1. (Its decrement is also a §252-reading instance: v0 = load − 1; store; if (v0 == -1) — but per §266, that statement split is byte-inert here; the goto is the load-bearing half.) The §162 "backward j into a sibling arm" law reads the same fact from the cross-jump side; this is the forward/out-of-line face.

ADD-8 → §245 addendum — THE RE-TIE BARRIER PINS CALL-ARG SETUP TO SOURCE ORDER (construct 6)

When call N+1's two argument addius must issue at exact early slots while cheaper independent inits (q = …; i = 0;) sink below them, no statement permutation works — sched1 re-ranks them freely. Birth each argument as a local immediately after call N and nail it with the zero-byte re-tie: a0v = (s32)loc; __asm__ __volatile__("" : "=r"(a0v) : "0"(a0v)); (one per argument), then pass f(a0v, a1v). The __volatile__ asm is scheduler-immovable (§257-8's fence effect, used constructively), so the two addius hold source position while the untied inits sink. A/B-proven on func_801AEB94 (md_SC07_004, 41/41, banked with the barriers): stripping the two re-ties gives SCHEDULE-REORDER/4 — the arg addius sink to slots 12/18, q/i rise to 10/11. Boundary: this is a placement lever (§245's rule); it moves nothing across a call and adds zero bytes.

ADD-9 → §213-3 / §217 addendum — ADJACENT PRE-CALL FRAME STORES ARE ONE AGGREGATE; THE UNESCAPED SCALAR NEIGHBOR IS DEAD-STORED

§213-3 reads interleaved sh $zero runs as adjacent-array initialisers. The escape-analysis corollary bites on call setup: sh $zero,0x18($sp) ; sh $v0,0x1A($sp) ahead of a call taking $sp+0x18 is a two-element s16 buf[2] whose whole address escapes. Spelled as two scalars with &sp18 passed, gcc dead-stores the neighbor whose address never escapes. A/B-proven on func_8018117C (ov_SC03_116, 34/34): the s16 buf[2] form MATCHes; s16 sp18, sp1A; … &sp18 drifts −2 — the sp1A = 0x20 store (and its li) vanish. Reading rule: adjacent stack stores feeding one escaping address = one aggregate, never sibling scalars.

ADD-10 → §237 addendum (arity-evidence paragraph) — AN la PAIR ABOVE THE PROLOGUE sw $ra IS AN OUTGOING-ARGUMENT MATERIALISATION

Add to the asm arity tells: a lui/addiu %hi/%lo(SYM) → $aN pair issued above sw $ra — while the incoming $a0 is never touched — declares SYM the callee's argument N+1 and the raw parameter argument 1, i.e. a two-arg call even when every visible decl says void f(). func_8017EB38 (ov_SC02_005, 21 ins): lui/addiu $a1,%hi/%lo(D_801E4C50) sits two instructions above sw $ra; the banked C is func_8017EDF8(a0, p) with the atlas row a bare ?. §217's mirror covers incoming stack args read above the save; this is the outgoing face.

ADD-11 → Cross-confirmation card block (per §259's standing instruction: confirmation, not news)

Append these card references to the named sections — each was independently re-derived and byte-banked in waves bh/bk/bl:

  • §209-addendum no-local row + §226-4 INVERSE ← func_80180EFC (ov_SC04_005, bl) — un-hoisted double textual read regenerated the addu copy AND the 0x20 frame in one edit; both entries were single-card, now cross-confirmed. Its sharpening stands: a guarded value stored once should not be given a name even when guard and use are textually adjacent.
  • §223-A/-B ← func_800CB61C (bl; the slot $v0 is the PRECEDING call's return), func_800CB234, func_80180F68 (bk; pre-call store fills the slot), func_801875A4 (bk; every slot store is a source store-before-call — see Refuted #1).
  • §234 ← func_8017EDC4 (u16→ori 0xff00 / s16→addiu -0x100), func_801803F0 (s16 record element → addiu -2), func_8017FF6C (0xC800 u16→ori), func_80181DC0 (negative chain constants spelled -0xB2 for addiu) — all bh.
  • §236-2 ← func_801819A0 (bh) — tu-typed extern s32 MUST be block-scoped because sibling functions carry block-scope s16 decls of the same symbol; store through *(s16*)&.
  • §236-1/-2 (fn-ptr tables) ← func_8017E448 (bk) — the conflict class on a function-pointer TABLE extern; fleet spells void (*D[])(void), dispatch passes nothing.
  • §238 ← ~14 fresh cards across bh/bk/bl (func_801808F0, func_80181090, func_80184500, func_801816D8, func_8017F4DC, func_801857F4, func_801802CC, func_8017EE80, func_8017F7F0, func_8017E940, …) — including the sharpened tells: re-confirm the mounted oracle target's glabel
    • ins count after any session resume; the task-header asm path outranks every replayed artifact.
  • §246-3 ← func_8017F724 (bh) — pointer-chase p += 6 IV split killed by the index-loop form; §1412's for-vs-do-while note supplies the loop shape.
  • §255 ← func_8018F194 (bh) — empty case 1: break; between {0,2} roots the tree on ==1.
  • §225-3 ← func_8017E7C4 (bh) — the SAME mixed construct at the opposite constant polarity: if (c1||c2||c3) return 1; return c4;, all three li v0,1 folds landing in the failing branches' delay slots (22/22).
  • §214-addendum-10 ← func_801830B4 (bk) — a MATCHED twin's C comment carried *24 while its own bytes compute *48; diff the twin's encodings, never its comments.
  • §252-related / §172b ← func_801914A0 (bh) — signed-short temp flips the post-decrement test from andi 0xffff to sll 16.
  • §165-17-correction (L19102) ← func_80181D04 (bh) — a pure bb0 swap around a masked shift fell to retyping the temp s32→u8; statement order was inert.
  • §20 pointer-var bullet / §243 ← func_8018208C, func_80180108, func_80181230 (bh) — the held-pointer lever on an indexed global, a global RMW, and an RMW-across-store respectively; on the last, the memory-clobber barrier and volatile (both directions) were measured FAILURES — the naming is the lever.
  • §257-2 ← func_801816C8 (bh) — now A/B-proven live: the $2 pin in a rand()-calling function is byte-inert (see §266).
  • §226-addendum data point ← func_8017D710 (bk) — an address-taken s32 frame_pad[2] measured 0x10, not 8; the address-taken pad-form table's size column is CEIL(size,8) + rounding, worth a row note.
  • §220-addendum × loop-form interaction ← func_8017DF88 (bl) — only the combination "plain a0 param + for loop" reproduces the delay-slot refill; "named s1 local + for" still misses by spill. The two dials compose; A/B them jointly.

3. The discovery-gap list (knowledge existed; the drafter did not find it)

The index earns its keep here. Each row: who searched, what words, where the knowledge actually was.

  1. func_80180F68 (bk) — needed "a pre-call store is what fills the jal delay slot". Searched around fences/§194-A; wrote "not in any cookbook section I found". It is §176-A ("check STATEMENT ORDER around the call first", L17626) and §223-B. Index fix: add the literal strings jal delay slot store, pre-call store, store before call to both entries' symptom lines.
  2. func_80181D04 (bh) — needed "sweep the TEMP'S TYPE, not statement order, for a bb0 reorder". Searched §167-13/§162d/§135-2/§135-4. It is the §165-17 CORRECTION at L19102 — an unnumbered header ("§165-17, corrected and replicated…") invisible to §-grep. Index fix: unnumbered correction blocks need their own index rows keyed temp type sched1, bb0 reorder width.
  3. func_8018F194 (bh) — needed the empty-case dispatch lever; wrote "no numbered section I could find by grep". §222's title literally contains "EMPTY case" (and §255 landed the same day). The drafter grepped the cookbook, not the index. Prompt fix for the campaign: the index is the entry point (its own header says so); wave prompts should say "grep docs/cookbook-index.md FIRST".
  4. func_8017E7C4 (bh) — claimed §225-3 lacks the mixed disjunct/value-tail form; §225-3's own exemplar IS that form (if (A || B) return 0; return C == D;), at the opposite constant. Cost: 3 refuted drafts before converging on the section's own shape. Reading gap, not an index gap: the section's headline names the failing spelling (&& chain), not the winning construct. A one-line "WINNING SHAPE:" lead would have been grepped.
  5. func_801914A0, func_80182CE4, most §236-shaped at-wave complaints — the knowledge (§252's related-spellings row, §226-addendum slot order, §236's nine classes) landed in the S58b commit, likely AFTER those sessions ran. Half-gaps: no index fix needed, but the campaign should re-issue drafter prompts pointing at §233-§259 so the ~20 standing "no section covers MATCH-but-no-bank" complaints stop recurring.
  6. Line-numbers-as-§ (all four waves) — notes cite §1907, §12479, §2965, §11383, §8892, §5583, §1832, §2429, §1755, §2609…: cookbook LINE numbers read off the index's <sub>L…</sub> anchors and quoted as section ids. Greps for those strings fail for the next reader. Index-generator fix: emit an explicit L→§ alias table, or strip the <sub> anchors from grep-visible text.

4. Refuted claims (checked and found wrong — do NOT let these harden into laws)

Four refuted by live match_one A/B against the banked body (files in .run/s59_distill/), four by artifact inspection. An unchecked wrong "law" is worse than no law; several of these directly contradict standing byte-proven sections.

  1. func_801875A4 (bk): "a sh sitting in a jal DELAY SLOT proves the source stored AFTER the call." WRONG — and it contradicts §223-B. The banked C (src/ov_SC06_024/ov_SC06_024_jr_80186F00.c:3063) writes every slot-landing store BEFORE its call (sh 0x2 at 801875DC and 8018767C, sw 0x1C at 80187624 — all before-call in source), and the one genuinely after-call store (*(s32*)(s0+0x1C) = 0x200 in the f&4 arm) sits at 80187680 — AFTER the slot, in plain fall-through. The note's real (unstated) lesson is trivial §223-B complement: an instruction after the slot is an after-call statement. §223-B stands, +1 confirmation card.
  2. func_8017E230 (bk): "the lever was a K&R-style unprototyped definition; every prototyped spelling let gcc coalesce the raw-arg copy away." WRONG — the banked artifact (src/ov_SC03_023/ov_SC03_023_jr_8017AE2C.c:4344) is ANSI-prototyped void func_8017E230(void *a0) with register void *s0 __asm__("$16"); s0 = a0; — the hard-reg pin is what keeps the copy. No §43 addendum warranted from this card.
  3. func_8017FB04 (at): the bgez/OR-fallthrough/two-entry-merge "gcc-2.7.2 emits bgez only when…" analyses. MIS-ATTRIBUTED — the note's subject (lui D_80126CB0, 8×ctc2, rtps, the bgez tail) is ov_SC03_030's func_8017FB04, which is tagged /* Handwritten function */ in its .s header. No compiler law can be extracted from hand-written asm; the "levers exhausted" wall was unwinnable by construction (feeds §265's cautionary tale). The card's actual ov_SC05_001 function banked as an ordinary 37-ins state helper (…jr_8017BEBC.c:5098).
  4. func_8017FDE4 (at): "a mid-file #include "common.h" re-expansion is a C89 typedef-redefinition error that kills the TU." WRONG PREMISE — include/common.h carries include guards; re-inclusion is inert. (The note itself flagged this as an uninstrumented hypothesis; the gate failure is unexplained by it. Recorded so it does not harden into splice-lore.)
  5. func_801816C8 (bh): "the final 2-insn residual fell to register s32 q __asm__("$2") on the modulo result — no C spelling fixed it." INERT RIDER — A/B: pin and no-pin both MATCH 21/21 (the function calls rand(), so §257-2's silent pin drop applies, now confirmed live). The surviving spelling is the named quotient local (r = rand(); q = r % 64;), a §208-family naming lever. The proposed "pin the div-quotient into $v0" §215 extension is withdrawn.
  6. func_80183994 (bh): "materialize the failure return into a named local (t = 0; … return t;) — every other spelling collapses the two return pseudos; return 0; remats the wrong insn in the slot." INERT RIDER — A/B: the literal return 0; version also MATCHes 103/103, addu $v0,$zero,$zero lands in the bne slot either way. The proposed §266-numbered "split return pseudo" law from the first draft of this distillation is withdrawn (and the incident is Exhibit A for the actual §266).
  7. func_80188770 (at + bk, same claim twice): "the counter RMW must be spelled volatile — non- volatile, gcc hoists the lhu above the call and deserializes the tail." INERT RIDER — A/B: the plain (non-volatile) spelling also MATCHes 54/54 in the banked context. gcc cannot hoist a memory load above an opaque call in the first place (the call sets the memory resource). The banked volatile is harmless but carries no bytes; the load-bearing content of these two notes is the masked-jal illusion (ADD-1) and the reg-plan facts, which stand.
  8. func_8018046C (bh): "drafting the decrement inside the if puts MINUS_EXPR in the compare tree and gcc folds (load-1)==-1 → load==0, killing the addiu — separate statements block the fold." NOT REPRODUCIBLE — A/B on the banked body: the separated form, the fused-temp form (t = load - 1; store; if (t==-1)), and the fully-folded compound (if ((*(s32*)(s2+0x200) -= 1) == -1)) ALL MATCH 69/69. Whatever his failing draft did differently, it was not this. §252's reading rule (store-in-slot ⇒ unconditional decrement) is untouched.

5. Plain-language summary for the reviewer

Of 165 notes, 145 are already written down — overwhelmingly by the §233–§259 layer that landed three hours before this batch was drawn, which also means wave at (inside the already-mined aa–bg range) should not have been re-batched. The genuinely new material is: one lane law (§265 verbatim-asm banking for -O0-stranded and handwritten functions, two banked exemplars), one process law (§266 inert-rider — earned by this review itself: half of the batch's confident "the lever was X" claims failed a 20-second solo A/B), ten §-addenda (six of them A/B-proven placement/spelling dials, the rest reading tells and a splice-mechanics class), and a card-reference block cross-confirming ten existing sections. Eight claims were refuted outright — two of which, if landed as written, would have contradicted byte-proven standing law (§223-B, §257-2).