265 the verbatim-asm bank lane — two in-tree precedents, the MASPSX decimal-immediate
rule, and a REVIEW-ADDED accounting caveat: an __asm__ body is not an INCLUDE_ASM
stub, so corpus.stubs() counts it as MATCHED. Bytes proven, function not
decompiled. Fine for hand-written asm; for an -O0 C function the right answer is
the -O0 object, and this lane is a temporary hold at best.
266 the inert-rider law — a lever is only citable when its solo removal breaks the
match. Measured 4 of 8 credited levers on this batch were byte-inert: a $2 pin
silently dropped, a volatile the scheduler already ordered, a named zero, and a
statement split. The banked artifact CONTAINS the rider precisely because it is
inert, which reads as proof. R40 applied to the flywheel itself.
267 eleven addenda to existing sections, six with fresh match_one A/Bs.
The batch's real headline: 145 of 165 candidates were ALREADY COVERED, and 8 claims
were refuted (4 by live A/B) — the harvest is mostly re-derivation, and an unchecked
wrong law is worse than no law.
42 KiB
Distillation — waves at · bh · bk · bl (batch .run/distill_inflight/atbhbkbl.json)
PROPOSED ONLY — nothing here has been applied to docs/matching-cookbook.md or docs/cookbook-index.md.
Reviewer lands the sections. All A/B evidence lives under .run/s59_distill/ (each variant file re-runnable
with the match_one line quoted beside it).
0. The ledger — counts first (R41: every number's denominator stated)
165 candidate notes read — all of them — from 4 files: at 52, bh 60, bk 42, bl 11
(matches the batch manifest's novel: 165).
| disposition | rows | of 165 |
|---|---|---|
| Already covered (cited § per row below; most by the 3-hour-old §233–§259 layer) | 145 | 87.9% |
| Feed a proposed addendum (11 addendum items, ADD-1…ADD-11) | 9 | 5.5% |
| Feed a proposed new law (§265; 2 exemplar cards) | 2 | 1.2% |
Refuted (8 distinct claims across 9 rows; 4 by live match_one A/B, 4 by artifact) |
9 | 5.5% |
One further proposed law (§266) is sourced from this distillation's own A/B campaign, not from any single candidate row — its evidence is the 4-of-8 inert-lever rate measured below.
Batch-hygiene note for the campaign: wave at lies inside the aa–bg range that §233–§259 already
mined (its file was re-emitted at 11:30 after that commit). 46 of its 52 rows resolve to sections that
landed three hours ago, several citing these exact functions by name (func_8018270C → §249-3/§257-1,
func_8017ECA8 → §236-6, func_80181D68 → §236-3, func_8017FCBC → §242-2/§250, func_8017FA94 →
§234/§238/§226-add). A harvester dedup guard (skip waves ≤ bg) would have shrunk this batch by a third.
0a. Per-candidate disposition (one line each; spot-check any row)
Verdicts: cov §X = already covered by §X (drop; where marked ⊕ the row is ALSO a cross-confirmation
card worth appending to §X per §259's standing instruction — collected in ADD-11). ADD-n = feeds
proposed addendum n. §265 = feeds the new law. REF = refuted (see part 4).
Wave at (52):
| fn | verdict |
|---|---|
| func_800CF010 | cov §236/§259-4 (gate-null; decl audit clean) |
| func_8018270C | cov §249-3 + §257-1/-2 (its asm-la instrument is already quoted verbatim at cookbook L23874-84) |
| func_8017FB04 | REF-3 (note analyzes the HANDWRITTEN ov_SC03_030 homonym; also feeds §265's cautionary tale) |
| func_80188770 | REF-7 (volatile lever inert by A/B) · salvage → ADD-1 (masked-jal illusion) |
| func_8018516C | cov §209-addendum (cited there by name — the "no-local row") |
| func_801A5BBC | cov §246-UNSOLVED (cited by name) + §259-4 |
| func_80181D68 | cov §236-3 (cited by name) |
| func_800CF078 | cov §236/§259-4 |
| func_8017FDE4 | REF-4 (common.h re-include hypothesis; guards exist) · rest cov §236-5/§195-A |
| func_80181864 | cov §259-4 |
| func_80187074 | cov §259-4 + §237 |
| func_80187118 | cov §214-addendum retrieval note + §195-F |
| func_801AB5D4 | cov §246-UNSOLVED (cited) + §259-4 |
| func_801832D0 | cov §259-4 (gate infra) |
| func_80180820 | ADD-2 (§42a: named shared-const across a call = iso→TU drift hazard) |
| func_8017DA98 | cov §236-9 (cited by name, "×2") |
| func_8018BB18 | cov §259-4 + §260/§260-A (jtbl pipeline now automated) |
| func_8017FA94 | cov §238-1 + §234 + §226-addendum (cited by name in all three) |
| func_801839C4 | cov §214/§238 ⊕ (verify twin by callee identity) + §236-1 |
| func_801A06AC | cov §259-4 (wave-batch revert semantics) |
| func_8018017C | cov §259-4 |
| func_8017ECA8 | cov §236-6 (cited by name — narrow-prototype def-site mask) |
| func_8017FCBC | cov §242-2 + §250 (cited by name in both) |
| func_8017FA18 | cov §223/§213 (self-declared no-gap) |
| func_801A01D4 | cov §193-A + §223 (self-declared) |
| func_801821A0 | cov §247/§225 (fall-through returns) |
| func_801819D0 | cov §238 tell-4 + §236-7 (both cite it by name) |
| func_800CEFBC | cov §259-4 |
| func_801818C0 | cov §259-4 (its own "duplicated 22nd statement" warning stands as the next lever) |
| func_80180C90 | cov §193-A + §223-A (stolen delay-slot constant) |
| func_801A5C44 | cov §236-8 (cited) + §237-escape-4 + §239-2 (cited) |
| func_80180880 | cov §259-4 + §247 (its slt const,ret reading is quoted there) |
| func_80180CE0 | cov §236-3 (callee defined below the splice) + §164-74 |
| func_8017F604 | cov §223-B + §236 |
| func_8017EAE4 | cov §236-1 ("cast at the use site") + §227 |
| func_80182228 | cov §259-4 |
| func_80185D98 | cov §259-4 (stray scratch-dir duplicate = gate-infra suspect) |
| func_8017EF50 | cov §236-5/§103 (decl placement file→block) |
| func_8017EF0C | cov §249-3 (zr copy) + §238-3 (name-grep trap — cited by name) |
| func_8017FA6C | cov §259-4 |
| func_80180800 | ADD-3 (§236 item 10: leftover INCLUDE_ASM stub = duplicate definition) |
| func_801A23A8 | cov §236-8 family (def-side sig vs fleet canon; '?'-row caution) |
| func_80180B1C | cov §238-1 (cited by name) |
| func_801884F4 | cov §259-4 |
| func_801A23FC | cov §208-addendum (per-block naming splits) + §220 |
| func_80183038 | cov §259-4 |
| func_8017EFE0 | cov §236-8 (caller-stub decl conflict = TU edit) |
| func_800D2704 | cov §211-addendum-4 (init order = emission order) + §3-T4 |
| func_80180398 | cov §250 + §235 (%hi(SYM+K) via aggregate) + §216 + §226 (composition) |
| func_801AEB94 | ADD-8 (§245: re-tie barriers pin call-arg setup — A/B-proven) |
| func_8017FE54 | cov §164-57/§195-F (ternary collapse) + §211 (init hoist) |
| func_80182D3C | cov §259-4 |
Wave bh (60):
| fn | verdict |
|---|---|
| func_800D0440 | §265 card 1 (verbatim-asm lane, -O0 stranded; MASPSX decimal rule) |
| func_8017E7C4 | cov §225-3 ⊕ (its winning form IS §225-3's construct at the opposite constant polarity) |
| func_80183730 | cov §193-A/§103/§41/§195-A (self-declared) |
| func_801E2BE0 | ADD-6 (shift-as-test (x<<16)!=0 — 3-way A/B-proven) · rest cov §208-inv/§226/§245-2 |
| func_80180648 | cov §3-T4 + §223 (self-declared) |
| func_8017E940 | cov §238 (stale oracle mount) + §48-C2 (two-statement block-copy dests noted in ledger) |
| func_8018107C | cov §164-61/§136c (self-declared) |
| func_801819A0 | cov §236-2 ⊕ (two block-scope externs, different types, one TU — strongest confirmation card yet) |
| func_80182A54 | cov §251-2 (&~3 → addiu -4) |
| func_801808F0 | cov §238 ⊕ (homonym; callee-set tell) |
| func_80181C9C | cov §236-4(c) (block-scope typedef shadow) |
| func_801826A4 | cov §236-1 (tu row beats twin's decl layer) |
| func_80181DC0 | cov §234 (negative addiu chain constants) + §165-11 + §194-E |
| func_80182CE4 | cov §226-addendum (slot order; pad-first) — its promotion request is already satisfied |
| func_8017CF68 | cov §236-5 + §237 (both escapes, stacked) |
| func_8018208C | cov §20 pointer-var bullet (index L1907) ⊕ (indexed-global instance) |
| func_80183994 | REF-6 (named-zero return-pseudo split inert by A/B) |
| func_80180108 | cov §20/§229-addendum (held pointer for global RMW) |
| func_801816C8 | REF-5 ($2 pin inert by A/B; §257-2 confirmed live) + §238 (twin mislabel) |
| func_80183668 | cov §247/§3-T4 (inverted guard, cross-jumped tail) |
| func_801E585C | cov §236-4(c) (block-scope typedef shadow, SV4) |
| func_801870D4 | cov §225-4/§227/§194-E (self-declared) |
| func_801802CC (SC03_112) | cov §238 + §225-10 (dual constant materialisation = unconditional store) |
| func_801E4D98 | cov §237 (cast-call to consume $v0 of a void-defined callee) |
| func_8017D1E0 | cov §251-1 (+ 0xff byte decrement — cited there) |
| func_8017FC80 | cov §214-addendum retrieval note (grep engine_core.h for DEFINE_) |
| func_80181090 | cov §238 (task-header path outranks replay) |
| func_80182AF8 | cov §209-addendum (s16 temp → truncation copy off the dead arg reg; inline stores) |
| func_801803F0 | cov §234 ⊕ (s16 record element → addiu -2; u16 → li 0xFFFE) |
| func_80181D04 | cov §165-17-correction L19102 (temp width = sched1 dial) — discovery gap #2 |
| func_80186124 | cov §8c-3 + §236-8 + §237 |
| func_801822D8 | ADD-7 (§256: single-guard goto, then-block out of line at tail — A/B-proven) |
| func_801914A0 | cov §252-related + §172b ⊕ (u16 → andi vs s16 → sll 16 on decrement test) |
| func_80182030 | cov §247/§3-T4 (beq-to-else arm swap) + §234 |
| func_80181D60 | cov §205 (chained order; self-declared) |
| func_80190B14 | cov §237 (cast-call at every site; placement of the arg copy) |
| func_8017F63C | cov §247 + §48-C2 + §226-addendum (decl order = slot order) |
| func_8017F724 | cov §246-3 ⊕ (pointer-IV split killed by index form — func_8017DC50 is already the exemplar) |
| func_8018F194 | cov §255 + §213 ⊕ (empty case 1: between {0,2}) — discovery gap #3 |
| func_801822E8 | cov §238/§194-E (self-declared) |
| func_8017D82C | cov §238-positive ⊕ (grep by distinctive immediate bundle) |
| func_80180DC0 | cov §162c/§161c (self-declared) |
| func_8017D7A4 | cov §214 (mid-similarity twin = guard/store idiom only) |
| func_801E28D0 | ADD-5 (§1/I1 inverted range-test polarity — A/B-proven) |
| func_80180778 | cov §237 (void decl + cast) |
| func_80181BE4 | cov §205 (chained equal constants share one li/lw) + §162 |
| func_80190798 | cov §236-1/-2 (stale file-scope externs poison the TU; declare before casting) |
| func_8018060C | cov §193-A (self-declared) |
| func_80184500 | cov §238 (wrong-function seed) |
| func_801816D8 | cov §238 (stale shard redirect) + §3-T4 |
| func_8017EDC4 | cov §234 ⊕ (u16 field → ori 0xff00; s16 → addiu -0x100) + §213-3 (one struct, not scalars) |
| func_80181230 | cov §243 reading rule + §208 (naming = the barrier); its refuted-levers list noted in ADD-11 |
| func_8017F4DC | cov §238 + §194-E |
| func_80180E14 | cov §211-addendum (comma-increment clause — cited verbatim there) |
| func_8019070C | cov §193-A/§237 (self-declared) |
| func_801802FC | cov §16N+3 (ladder arithmetic; /5 rung) + §167-39 |
| func_80181D80 | cov §162i1 (self-declared) |
| func_8017FF6C | cov §234 ⊕ (0xC800 u16 → ori) + §247 + §250 |
| func_8018046C | REF-8 ((x−1)==−1 "fold" inert by A/B — all three spellings MATCH) |
| func_8017EC38 | cov §193-A/§194-E (self-declared) |
Wave bk (42):
| fn | verdict |
|---|---|
| func_80181C00 | cov §236-4(a) + §228-3 + §259-11 (standalone-harness fact) |
| func_801887A0 | cov §194-E + §243 reading rule (inline re-reads ⇒ reload) |
| func_801830B4 | cov §214-addendum-10 ⊕ (twin C comments lie — *24 text vs *48 bytes) |
| func_8017E230 | REF-2 (K&R headline; banked artifact is ANSI-prototyped + $16 pin) · rest cov §167-30/§220 |
| func_8017E79C | cov §220-addendum (bare parameter, no s0 local) + §194-E |
| func_8018117C | ADD-9 (§213/§217: adjacent pre-call stores are ONE aggregate; scalar neighbor dead-stored — A/B-proven) |
| func_80188770 (bk) | REF-7 dup (same volatile claim, same salvage → ADD-1) |
| func_8017E448 | cov §236-1/-2 ⊕ (the conflict class on a fn-ptr TABLE extern) + §250 |
| func_801892FC | cov §214-addendum retrieval (twin = dedup stub; grep constants) |
| func_80180F68 | cov §223-B + §176-A (pre-call store fills the jal slot) — discovery gap #1 |
| func_8018603C | cov §237 + §215-addendum ("pin the value, not the pointer" = item-2 family) |
| func_801802CC (SC02_005, 43/43) | cov §194-E + §231-5 (wrong-argument reading — param vs handle) |
| func_801857F4 | cov §238 ⊕ (same-VA cross-overlay; similarity useless as identity) |
| func_800CB06C | cov §193-A + §225-8 (early-return layout) |
| func_801EA63C | cov §254-adjacent + §263 (forward the parameter; a literal 0 emits move a0,zero) |
| func_8017D490 | cov §195-A + §250-boundary (by-address vs by-value read off the arg-register materialisation) |
| func_8018EF1C | cov §3-family (self-declared) |
| func_801875A4 | REF-1 (slot-store ⇒ store-AFTER-call — artifact shows the opposite; §223-B re-confirmed) |
| func_8017D7A0 | cov §208-addendum (split pointer locals shorten live ranges) + §237 + §214-8 |
| func_8017EB38 | ADD-10 (§237: la pair above sw $ra = outgoing-argument materialisation — arity read) |
| func_8017DB5C | cov §259-4 + §195-A |
| func_8017D454 | cov §193-A/§194-E (neighbour beat twin) |
| func_8017F528 | cov §193-A (self-declared) |
| func_8017EE80 | cov §238 (header path vs binary under audit) |
| func_801802CC (SC02_005, 2nd note) | cov §238 (two prior sessions read other overlays' same-address .s) |
| func_80181270 | cov (self-declared no-gap) |
| func_800CB234 | cov §176-A1 + §223-addendum ("read the slot before the block order") |
| func_80186870 | cov §194-E + §214 (twin misdirect at 0.60) |
| func_8017FC3C | cov §195-A + §227 (lhu-vs-lh via cast, decls untouched) + §193-A |
| func_80181E3C | cov §194-E + §237-arity (local call shape wins over 3-binary fleet row) |
| func_8017D710 | cov §226-addendum (pad forms; its [2]-address-taken→0x10 measurement logged in ADD-11) |
| func_80182C1C | cov §243 reading rule + §251-2 (composition: name the flag word above the aliasing narrow store) |
| func_800CBA44 | §265 card 2 (handwritten GTE → whole-body __asm__ __volatile__) |
| func_80187268 | cov §179-D/§195-J + §35 (unsigned ⇒ sltiu) |
| func_8017E234 | cov §194-E (self-declared) |
| func_8017E6FC | cov §193-A/§194-E + law 2 (house style wins) |
| func_8018EE00 | cov §3-T4/§247 (inverted polarity; li v0,4 slot fill) |
| func_8017E740 | cov §225-2/-8 (flat common tail + early return, not ` |
| func_80187460 | cov §255/§222 (balanced middle-rooted tree; self-declared) |
| func_800CAE0C | cov §193-A (self-declared) |
| func_800CB2CC | cov §252-reading + §236-9-family (memcpy(dst,src,8) per L1755) + feeds ADD-2 (literal args vs named const) + §237-arity |
| func_8017E4AC | cov §48-C1 (self-declared) |
Wave bl (11):
| fn | verdict |
|---|---|
| func_8017F7F0 | cov §238 ⊕ (interleaved same-name cards; "trust the .s on disk over a replayed diff") |
| func_8017EF64 | ADD-4 (§225-3/-4 mirror: value in the TAKEN arm + trailing return 0 — A/B-proven) |
| func_8017DF88 | cov §220-addendum + §1412 loop form (their interaction logged in ADD-11) |
| func_8018A61C | cov §199-A + §227 (self-declared) |
| func_801851CC | cov §20/§229-addendum (named pointer local) + §164 second-read tell |
| func_80180EFC | cov §226-4-INVERSE + §209-addendum no-local row ⊕ (cross-confirms both; was single-card) |
| func_80186D58 | cov §164-48 (self-declared) |
| func_800CB61C | cov §223-A ("the $v0 in the slot is the PRECEDING call's return") + §42a struct-assign |
| func_80187798 | cov §194-E (banked twin supplied the exact && search shape) + §211 loop dials |
| func_80189808 | cov §194-E (self-declared) |
| func_80181678 | cov §193-A (self-declared) |
1. Proposed new sections
§265 — THE VERBATIM-ASM BANK LANE: A FUNCTION NO -O2 C CAN EVER MATCH BANKS AS A RAW __asm__ BODY (P31 S59b; two banked cards, two in-tree precedents)
The symptom you see in a diff. Every draft plateaus at SIZE-MISMATCH or an unclosable structural
residual, and the target has one of the un-compilable tells: the -O0 prologue (addu $fp,$sp,$zero /
21F0A003, nop in every delay slot, per-statement li) while the object's Makefile globs compile it
-O2 (§261: 116 functions / 14,148 ins are stranded this way — nothing matches src/md_*/); or the
splat header says /* Handwritten function */; or the shape is one gcc-2.7.2 never emits (a bgez
whose OR-path falls through into a j chain, hand-placed GTE hazard nops). No C source can score
MATCH against these under the object's real CC1FLAGS. Stop drafting C.
The mechanism. A raw __asm__ body is opt-level-independent: cc1 passes the string through
untouched, so it emits the identical instructions whether the TU compiles -O0 or -O2, and the ordinary
whole-binary gate accepts it the moment the INCLUDE_ASM stub line is replaced. Two byte-banked forms:
- File-scope block (for a stranded ordinary function): transcribe the whole
.s—__asm__(".text\n.align 2\n.globl <fn>\n.ent\t<fn>\n" "<fn>:\n.frame $sp,40,$31\n.mask 0xC0010000,-16\n.fmask 0,0\n" ".set\tnoreorder\n" …every instruction… ".set\treorder\n.end\t<fn>\n");Banked:func_800D0440(93/93, md_MAIN_003 — a gcc -O0 body inside an -O2 module, atsrc/md_MAIN_003/md_MAIN_003.c:329). Precedent:func_80185810(src/ov_SC03_105/ov_SC03_105_jr_8017C8D0.c:5493). - C-definition wrapper (for a
/* Handwritten function */):void <fn>() { __asm__ __volatile__(".set\tnoreorder\n" … ); }Banked:func_800CBA44(109/109, md_MAIN_027, handwritten GTE add-halfwords loop, atsrc/md_MAIN_027/md_MAIN_027.c:225). Precedent:src/800b2.c.
The transcription rules (each one cost a compile or a session somewhere):
- MASPSX REJECTS HEX IMMEDIATES inside
__asm__strings — the error isinvalid literal for int() with base 10: '0x20'. Every immediate must be decimal (65535,-40,24).%hi(SYM)/%lo(SYM)and barejal <sym>work and relocate correctly. - Transcribe verbatim, model nothing. The -O0
$fpprologue, every delay-slotnop, and fake frames all stay:func_800CBA44carries a mid-bodyaddiu $sp,-8+lw 0x18/0x1C($sp)whose only purpose is reloading stack args 5/6 and hostingcfc2flag spills — transcribe it, do not turn it into C locals. - Ship NO C externs with the file-scope form. The asm resolves symbols at link time; a guessed type
for an otherwise-undeclared global (
D_800EC894) is pure §236-1 conflict risk with zero benefit. - Leave the recovered C semantics in a comment beside the body so the eventual real decomp (post §260/§261 lane work) starts warm.
What was tried and failed (the reason this lane exists): three sessions of near-79/83
SIZE-MISMATCH C drafts on func_800D0440 against a hardcoded -O2 oracle — a feedback loop that cannot
converge (§261); and a 7-oracle-call full lever sweep (polarity flips, goto tails, ternaries, pins,
hoists, rtps nop orders) on the /* Handwritten function */ homonym of func_8017FB04
(ov_SC03_030, 83 ins, rtps/ctc2) whose bgez-with-OR-fallthrough tail no compiler output ever
contains — see Refuted #3 below. Check the handwritten tag and the §261 prologue oracle FIRST;
grep -l 'Handwritten' asm/<ov>/nonmatchings/*/<fn>.s is free.
Boundary. This banks bytes, not understanding — it is the escape hatch for the §261-stranded
population and hand-written asm only. An ordinary -O2 function that merely resists you is not in
scope; neither is an -O0 function already inside an _o0* object (those bank as real C per §261a and
are STRICTLY easier). Grep bait: verbatim asm, asm body, handwritten, maspsx hex immediate,
decimal immediates, -O0 stranded, .set noreorder body.
§266 — THE INERT-RIDER LAW: A LEVER IS ONLY CITABLE WHEN ITS SOLO REMOVAL BREAKS THE MATCH (P31 S59b; measured 4-of-8 on this batch)
The symptom. A victory note — or your own session memory — credits a MATCH to one named lever
("the volatile is what makes the ordering stick", "fell to a single $2 pin", "only the named local
splits the pseudos", "separate statements block the fold"). The lever was added in the same edit as
other changes, and the note's confidence is absolute.
The mechanism. Near-miss iteration stacks edits. When the miss closes, the last-added lever
gets the credit — and byte-inert riders survive into the banked body precisely because they are
inert: a register __asm__("$2") pin in a function with a call is silently dropped (§257-2), a
volatile on an RMW the scheduler already orders is a no-op, a named constant local coalesces to the
same RTL. The banked artifact then contains the rider, which reads as proof.
The instrument. match_one the banked body with the lever removed — one edit, ~20 s, private
scratch. This distillation ran it on all 8 solo-attributable lever claims in the batch. Four were
inert (the banked body matches with the lever stripped):
| card | credited lever | solo A/B |
|---|---|---|
func_801816C8 (ov_SC03_093) |
register s32 q __asm__("$2") on the modulo result |
pin / no-pin both MATCH 21/21 — §257-2's silent drop, confirmed live |
func_80188770 (ov_SC05_010) |
volatile on the post-call counter RMW |
volatile / plain both MATCH 54/54 |
func_80183994 (ov_SC02_011) |
t = 0; … return t; naming to split return pseudos |
named / literal return 0 both MATCH 103/103 |
func_8018046C (ov_SC03_024) |
separate load/dec/store statements to block a (x−1)==−1 fold |
separated, fused-temp, and compound-in-condition all MATCH 69/69 |
and four were load-bearing (removal breaks it): func_8017EF64 (+2 LENGTH-DRIFT), func_801E28D0
(−4), func_801822D8 (25 mismatches), func_801AEB94 (SCHEDULE-REORDER/4) — plus func_801E2BE0
(1 mismatch) and func_8018117C (−2) from the same campaign. A/B files: .run/s59_distill/.
The law. Before a lever enters a note, a card comment, or this cookbook: strip it from the
otherwise-final body and recompile. If the match holds, the lever is a rider — record the actual
spelling that survives (here: the named quotient local, the statement shapes, the plain RMW), not the
rider. This is R40 (exonerate the instrument) applied to the flywheel itself, and it is why three of
this batch's five "law-grade" candidate claims died in review. Harvest-note convention: write
"banked WITH X; X not solo-A/B'd" unless you ran the A/B. Grep bait: inert rider, lever attribution, solo A/B, pin did nothing, volatile did nothing.
2. Proposed addenda (append each under its named section)
ADD-1 → §231 addendum (also cross-ref from §195-D) — THE MASKED-jal "MISSING CALL" ILLUSION
A relocation-masked jal can render in match_one's diff pane as if the call were DELETED — the
aligner shows the slot's instruction where you expect the jal, and a drafter reads "my call didn't
emit" (several near-15/17 verdicts on func_80188770 were exactly this misdiagnosis, in both its
wave notes). The call was always there; §195-D's mask_for returns 0 for every j/jal word.
The 20-second probe: compile a one-line body f(p){g(p);} and diff — if the jal appears there, it
was never missing in your draft either. Read the masked columns as alignment, not absence.
ADD-2 → §42a addendum — A SHARED CONSTANT NAMED IN A LOCAL ACROSS A jal IS AN ISO→TU DRIFT HAZARD; WRITE BARE LITERALS
§42a lever 4 documents const-load sinking past a call, but not this: a s32 k = 0x40; reused on both
sides of a jal keeps a pseudo live across the call, giving global-alloc the choice between a
callee-saved home and rematerialising li — a choice that is stable in isolation and can flip under
the real TU's ambient pressure (the §42a iso-MATCH→real-TU class). Bare literals at each use delete
the freedom. Cards: func_80180820 (ov_SC03_094 — the true twin func_80181644's banked C uses bare
literals; the named-local draft iso-MATCHed and failed the gate) and func_800CB2CC (md_MAIN_027 —
"passing literal 1 to both calls lets gcc schedule li s0,1 after the address calc; a named const
got scheduled too early"). Honesty bound: iso-side both spellings can MATCH, so this is a bank-side
rule; it cannot be A/B'd by match_one alone.
ADD-3 → §236, item 10 — THE UN-DELETED INCLUDE_ASM STUB IS A DUPLICATE DEFINITION
The tenth way a byte-perfect body fails the gate, and the only one that is pure splice mechanics: the
C definition lands but the function's own INCLUDE_ASM(...) line is not removed — two definitions of
one symbol, whole binary red, zero instruction diff. func_80180800 (ov_SC03_030) burned a full
session on body levers before the stub was found; the shard-replay framing ("wrong in ONE place")
points at the body when the wrong place is the line above it. Add to §236's PROCEDURE: grep the TU
for INCLUDE_ASM.*<fn> after every splice (a lingering .s file in nonmatchings/ is normal and
harmless — §238; the stub line is the killer).
ADD-4 → §225-3/-4 addendum — THE MIRROR ROW: VALUE-RETURN IN THE TAKEN ARM + TRAILING BARE return 0
§225-3's exemplar puts the constant on the early-return edges and the computed value on the
fall-through. The mirror shape exists and has its own spelling: when the target's guard beqz jumps
to the epilogue with the zero written in its own delay slot — counter-intuitively clobbering the
just-tested register (andi $v0,0xFF ; beqz $v0 ; addu $v0,$zero,$zero) — the source is
if (A != 0) { return <computed>; } return 0;: guard-positive, computed predicate in the taken arm,
zero on the fall-through. A/B-proven on func_8017EF64 (ov_SC01_009, 24/24): rewriting it as the
early-return ladder if (A == 0) return 0; return B == 0; drifts +2 — the beqz slot empties to
nop and a trailing move v0,zero block appears. The wave note also byte-refuted (a) A && B as a
value (boolean homed in $s0, +sw pair), (c) the ternary cond ? B : 0 (per §195-F it re-canonicalises),
and (d) an accumulator local (homed callee-saved). Reading tell worth its own grep string: a
delay-slot write that clobbers the branch's own tested register is the other path's return constant.
ADD-5 → §1/I1 addendum — THE INVERTED RANGE TEST: (u32)(x-lo) >= N WITH THE ZERO-ARM AS THE TRAILING else
I1 shows only the positive layout. When the target emits sltiu $v0,(v-lo),N ; bnez → <zero-store>,
the source is the NEGATED range test with the in-range body as the trailing else:
if ((u32)(v - 5) >= 0x4B5) { …out-of-range arms… } else { D = 0; }. A/B-proven on
func_801E28D0 (md_SC03_135, 35/35): the natural if (in-range) D = 0; else … polarity drifts −4
with 22 mismatches (beqz layout, different join). This is §247's branch-count read applied to I1 —
cite both.
ADD-6 → §172b-1 / §264 addendum — SHIFT-AS-TEST: (x << 16) != 0 TESTS THE LOW HALF WITHOUT TRUNCATING THE PSEUDO
A lone sll $v0,$sN,16 feeding only a beqz/bnez, while $sN itself stays RAW for a later sh,
is not a cast and not an extend-pair: the source tests the low halfword as an expression, leaving
the variable's mode alone: s32 v; … if ((v << 16) != 0) { …; store(v); }. Three-way A/B on
func_801E2BE0 (md_SC03_135, 56/56): the (x<<16)!=0 spelling MATCHes; (u16)v != 0 emits
andi v0,s0,0xffff (1 mismatch, OPCODE-MIXED at the tail test); declaring the local u16 also emits
andi. File this beside the extend-tell LANE ALIASES block at §172b so the lane label greps to it.
ADD-7 → §256 addendum — THE SINGLE-GUARD GOTO: THEN-BLOCK OUT OF LINE AT THE TAIL
§256 covers goto-dispatch. The degenerate single-guard case exists and no structured spelling reaches
it: the target lays the guard's then-body after the function's return flow, entered by one
forward beq, with the inline else-chain ending in j .Lepilogue. The source is an explicit goto:
if (v0 == -1) goto L1; …else-work…; return; L1: …then-work…;. A/B-proven on func_801822D8
(ov_SC01_009, 36/36, banked with the goto): the structured if/else-if inlines the then-body at the
head — 25 mismatches, −1. (Its decrement is also a §252-reading instance: v0 = load − 1; store; if (v0 == -1) — but per §266, that statement split is byte-inert here; the goto is the load-bearing
half.) The §162 "backward j into a sibling arm" law reads the same fact from the cross-jump side;
this is the forward/out-of-line face.
ADD-8 → §245 addendum — THE RE-TIE BARRIER PINS CALL-ARG SETUP TO SOURCE ORDER (construct 6)
When call N+1's two argument addius must issue at exact early slots while cheaper independent inits
(q = …; i = 0;) sink below them, no statement permutation works — sched1 re-ranks them freely. Birth
each argument as a local immediately after call N and nail it with the zero-byte re-tie:
a0v = (s32)loc; __asm__ __volatile__("" : "=r"(a0v) : "0"(a0v)); (one per argument), then pass
f(a0v, a1v). The __volatile__ asm is scheduler-immovable (§257-8's fence effect, used
constructively), so the two addius hold source position while the untied inits sink. A/B-proven on
func_801AEB94 (md_SC07_004, 41/41, banked with the barriers): stripping the two re-ties gives
SCHEDULE-REORDER/4 — the arg addius sink to slots 12/18, q/i rise to 10/11. Boundary: this is a
placement lever (§245's rule); it moves nothing across a call and adds zero bytes.
ADD-9 → §213-3 / §217 addendum — ADJACENT PRE-CALL FRAME STORES ARE ONE AGGREGATE; THE UNESCAPED SCALAR NEIGHBOR IS DEAD-STORED
§213-3 reads interleaved sh $zero runs as adjacent-array initialisers. The escape-analysis corollary
bites on call setup: sh $zero,0x18($sp) ; sh $v0,0x1A($sp) ahead of a call taking $sp+0x18 is a
two-element s16 buf[2] whose whole address escapes. Spelled as two scalars with &sp18 passed,
gcc dead-stores the neighbor whose address never escapes. A/B-proven on func_8018117C
(ov_SC03_116, 34/34): the s16 buf[2] form MATCHes; s16 sp18, sp1A; … &sp18 drifts −2 — the
sp1A = 0x20 store (and its li) vanish. Reading rule: adjacent stack stores feeding one escaping
address = one aggregate, never sibling scalars.
ADD-10 → §237 addendum (arity-evidence paragraph) — AN la PAIR ABOVE THE PROLOGUE sw $ra IS AN OUTGOING-ARGUMENT MATERIALISATION
Add to the asm arity tells: a lui/addiu %hi/%lo(SYM) → $aN pair issued above sw $ra — while
the incoming $a0 is never touched — declares SYM the callee's argument N+1 and the raw parameter
argument 1, i.e. a two-arg call even when every visible decl says void f(). func_8017EB38
(ov_SC02_005, 21 ins): lui/addiu $a1,%hi/%lo(D_801E4C50) sits two instructions above sw $ra; the
banked C is func_8017EDF8(a0, p) with the atlas row a bare ?. §217's mirror covers incoming
stack args read above the save; this is the outgoing face.
ADD-11 → Cross-confirmation card block (per §259's standing instruction: confirmation, not news)
Append these card references to the named sections — each was independently re-derived and byte-banked in waves bh/bk/bl:
- §209-addendum no-local row + §226-4 INVERSE ←
func_80180EFC(ov_SC04_005, bl) — un-hoisted double textual read regenerated theadducopy AND the 0x20 frame in one edit; both entries were single-card, now cross-confirmed. Its sharpening stands: a guarded value stored once should not be given a name even when guard and use are textually adjacent. - §223-A/-B ←
func_800CB61C(bl; the slot$v0is the PRECEDING call's return),func_800CB234,func_80180F68(bk; pre-call store fills the slot),func_801875A4(bk; every slot store is a source store-before-call — see Refuted #1). - §234 ←
func_8017EDC4(u16→ori 0xff00/ s16→addiu -0x100),func_801803F0(s16 record element →addiu -2),func_8017FF6C(0xC800 u16→ori),func_80181DC0(negative chain constants spelled-0xB2foraddiu) — all bh. - §236-2 ←
func_801819A0(bh) — tu-typedextern s32MUST be block-scoped because sibling functions carry block-scopes16decls of the same symbol; store through*(s16*)&. - §236-1/-2 (fn-ptr tables) ←
func_8017E448(bk) — the conflict class on a function-pointer TABLE extern; fleet spellsvoid (*D[])(void), dispatch passes nothing. - §238 ← ~14 fresh cards across bh/bk/bl (
func_801808F0,func_80181090,func_80184500,func_801816D8,func_8017F4DC,func_801857F4,func_801802CC,func_8017EE80,func_8017F7F0,func_8017E940, …) — including the sharpened tells: re-confirm the mounted oracle target'sglabel- ins count after any session resume; the task-header asm path outranks every replayed artifact.
- §246-3 ←
func_8017F724(bh) — pointer-chasep += 6IV split killed by the index-loop form; §1412's for-vs-do-while note supplies the loop shape. - §255 ←
func_8018F194(bh) — emptycase 1: break;between {0,2} roots the tree on ==1. - §225-3 ←
func_8017E7C4(bh) — the SAME mixed construct at the opposite constant polarity:if (c1||c2||c3) return 1; return c4;, all threeli v0,1folds landing in the failing branches' delay slots (22/22). - §214-addendum-10 ←
func_801830B4(bk) — a MATCHED twin's C comment carried*24while its own bytes compute*48; diff the twin's encodings, never its comments. - §252-related / §172b ←
func_801914A0(bh) — signed-short temp flips the post-decrement test fromandi 0xfffftosll 16. - §165-17-correction (L19102) ←
func_80181D04(bh) — a pure bb0 swap around a masked shift fell to retyping the temps32→u8; statement order was inert. - §20 pointer-var bullet / §243 ←
func_8018208C,func_80180108,func_80181230(bh) — the held-pointer lever on an indexed global, a global RMW, and an RMW-across-store respectively; on the last, the memory-clobber barrier andvolatile(both directions) were measured FAILURES — the naming is the lever. - §257-2 ←
func_801816C8(bh) — now A/B-proven live: the$2pin in a rand()-calling function is byte-inert (see §266). - §226-addendum data point ←
func_8017D710(bk) — an address-takens32 frame_pad[2]measured 0x10, not 8; the address-taken pad-form table's size column isCEIL(size,8)+ rounding, worth a row note. - §220-addendum × loop-form interaction ←
func_8017DF88(bl) — only the combination "plaina0param +forloop" reproduces the delay-slot refill; "nameds1local +for" still misses by spill. The two dials compose; A/B them jointly.
3. The discovery-gap list (knowledge existed; the drafter did not find it)
The index earns its keep here. Each row: who searched, what words, where the knowledge actually was.
func_80180F68(bk) — needed "a pre-call store is what fills thejaldelay slot". Searched around fences/§194-A; wrote "not in any cookbook section I found". It is §176-A ("check STATEMENT ORDER around the call first", L17626) and §223-B. Index fix: add the literal stringsjal delay slot store,pre-call store,store before callto both entries' symptom lines.func_80181D04(bh) — needed "sweep the TEMP'S TYPE, not statement order, for a bb0 reorder". Searched §167-13/§162d/§135-2/§135-4. It is the §165-17 CORRECTION at L19102 — an unnumbered header ("§165-17, corrected and replicated…") invisible to §-grep. Index fix: unnumbered correction blocks need their own index rows keyedtemp type sched1,bb0 reorder width.func_8018F194(bh) — needed the empty-case dispatch lever; wrote "no numbered section I could find by grep". §222's title literally contains "EMPTY case" (and §255 landed the same day). The drafter grepped the cookbook, not the index. Prompt fix for the campaign: the index is the entry point (its own header says so); wave prompts should say "grep docs/cookbook-index.md FIRST".func_8017E7C4(bh) — claimed §225-3 lacks the mixed disjunct/value-tail form; §225-3's own exemplar IS that form (if (A || B) return 0; return C == D;), at the opposite constant. Cost: 3 refuted drafts before converging on the section's own shape. Reading gap, not an index gap: the section's headline names the failing spelling (&&chain), not the winning construct. A one-line "WINNING SHAPE:" lead would have been grepped.func_801914A0,func_80182CE4, most §236-shaped at-wave complaints — the knowledge (§252's related-spellings row, §226-addendum slot order, §236's nine classes) landed in the S58b commit, likely AFTER those sessions ran. Half-gaps: no index fix needed, but the campaign should re-issue drafter prompts pointing at §233-§259 so the ~20 standing "no section covers MATCH-but-no-bank" complaints stop recurring.- Line-numbers-as-§ (all four waves) — notes cite
§1907, §12479, §2965, §11383, §8892, §5583, §1832, §2429, §1755, §2609…: cookbook LINE numbers read off the index's<sub>L…</sub>anchors and quoted as section ids. Greps for those strings fail for the next reader. Index-generator fix: emit an explicitL→§alias table, or strip the<sub>anchors from grep-visible text.
4. Refuted claims (checked and found wrong — do NOT let these harden into laws)
Four refuted by live match_one A/B against the banked body (files in .run/s59_distill/), four
by artifact inspection. An unchecked wrong "law" is worse than no law; several of these directly
contradict standing byte-proven sections.
func_801875A4(bk): "ashsitting in a jal DELAY SLOT proves the source stored AFTER the call." WRONG — and it contradicts §223-B. The banked C (src/ov_SC06_024/ov_SC06_024_jr_80186F00.c:3063) writes every slot-landing store BEFORE its call (sh 0x2at 801875DC and 8018767C,sw 0x1Cat 80187624 — all before-call in source), and the one genuinely after-call store (*(s32*)(s0+0x1C) = 0x200in thef&4arm) sits at 80187680 — AFTER the slot, in plain fall-through. The note's real (unstated) lesson is trivial §223-B complement: an instruction after the slot is an after-call statement. §223-B stands, +1 confirmation card.func_8017E230(bk): "the lever was a K&R-style unprototyped definition; every prototyped spelling let gcc coalesce the raw-arg copy away." WRONG — the banked artifact (src/ov_SC03_023/ov_SC03_023_jr_8017AE2C.c:4344) is ANSI-prototypedvoid func_8017E230(void *a0)withregister void *s0 __asm__("$16"); s0 = a0;— the hard-reg pin is what keeps the copy. No §43 addendum warranted from this card.func_8017FB04(at): the bgez/OR-fallthrough/two-entry-merge "gcc-2.7.2 emits bgez only when…" analyses. MIS-ATTRIBUTED — the note's subject (luiD_80126CB0, 8×ctc2, rtps, the bgez tail) is ov_SC03_030's func_8017FB04, which is tagged/* Handwritten function */in its.sheader. No compiler law can be extracted from hand-written asm; the "levers exhausted" wall was unwinnable by construction (feeds §265's cautionary tale). The card's actual ov_SC05_001 function banked as an ordinary 37-ins state helper (…jr_8017BEBC.c:5098).func_8017FDE4(at): "a mid-file#include "common.h"re-expansion is a C89 typedef-redefinition error that kills the TU." WRONG PREMISE —include/common.hcarries include guards; re-inclusion is inert. (The note itself flagged this as an uninstrumented hypothesis; the gate failure is unexplained by it. Recorded so it does not harden into splice-lore.)func_801816C8(bh): "the final 2-insn residual fell toregister s32 q __asm__("$2")on the modulo result — no C spelling fixed it." INERT RIDER — A/B: pin and no-pin both MATCH 21/21 (the function callsrand(), so §257-2's silent pin drop applies, now confirmed live). The surviving spelling is the named quotient local (r = rand(); q = r % 64;), a §208-family naming lever. The proposed "pin the div-quotient into $v0" §215 extension is withdrawn.func_80183994(bh): "materialize the failure return into a named local (t = 0; … return t;) — every other spelling collapses the two return pseudos;return 0;remats the wrong insn in the slot." INERT RIDER — A/B: the literalreturn 0;version also MATCHes 103/103,addu $v0,$zero,$zerolands in thebneslot either way. The proposed §266-numbered "split return pseudo" law from the first draft of this distillation is withdrawn (and the incident is Exhibit A for the actual §266).func_80188770(at + bk, same claim twice): "the counter RMW must be spelled volatile — non- volatile, gcc hoists the lhu above the call and deserializes the tail." INERT RIDER — A/B: the plain (non-volatile) spelling also MATCHes 54/54 in the banked context. gcc cannot hoist a memory load above an opaque call in the first place (the call sets the memory resource). The bankedvolatileis harmless but carries no bytes; the load-bearing content of these two notes is the masked-jal illusion (ADD-1) and the reg-plan facts, which stand.func_8018046C(bh): "drafting the decrement inside theifputs MINUS_EXPR in the compare tree and gcc folds(load-1)==-1→load==0, killing the addiu — separate statements block the fold." NOT REPRODUCIBLE — A/B on the banked body: the separated form, the fused-temp form (t = load - 1; store; if (t==-1)), and the fully-folded compound (if ((*(s32*)(s2+0x200) -= 1) == -1)) ALL MATCH 69/69. Whatever his failing draft did differently, it was not this. §252's reading rule (store-in-slot ⇒ unconditional decrement) is untouched.
5. Plain-language summary for the reviewer
Of 165 notes, 145 are already written down — overwhelmingly by the §233–§259 layer that landed three
hours before this batch was drawn, which also means wave at (inside the already-mined aa–bg range)
should not have been re-batched. The genuinely new material is: one lane law (§265 verbatim-asm
banking for -O0-stranded and handwritten functions, two banked exemplars), one process law (§266
inert-rider — earned by this review itself: half of the batch's confident "the lever was X" claims
failed a 20-second solo A/B), ten §-addenda (six of them A/B-proven placement/spelling dials, the
rest reading tells and a splice-mechanics class), and a card-reference block cross-confirming ten
existing sections. Eight claims were refuted outright — two of which, if landed as written, would have
contradicted byte-proven standing law (§223-B, §257-2).