Files
BFM-decomp/tools
Drew T 590fb37447 fix(gate_main): refuse to destroy uncommitted main work; name a tool refusal instead of hiding it
TWO DEFECTS, both found by the SaveLoadRoutine decompile and both of which made
this gate unable to bank a whole class of function.

1. try_batch() opens with `git checkout -- <main TUs>`. Correct for the normal
   flow (restore stubs, re-extract, substitute drafts) and CATASTROPHIC for
   anything uncommitted. Measured twice today: the SaveLoadRoutine decompile
   (1,179 ins, byte-identical) sat uncommitted while a gate ran and survived only
   because it was committed first; and a §265 verbatim body converted to a stub
   is UNCOMMITTED BY CONSTRUCTION, so this line restored the __asm__ block NEXT
   TO the substituted C -- 9 jump tables instead of 5, jtbl_rodata_pads refused,
   and the gate REJECTED a byte-identical bank. gate_main could not bank anything
   in the verbatim class, by construction.

   Now refuses when main's TUs are dirty, printing the offending paths and
   telling the operator to commit (R42) or stash. --allow-dirty /
   GATE_MAIN_ALLOW_DIRTY=1 is the deliberate override. A destructive step that
   cannot be undone must ASK, not assume.

2. The failure analysis looks for error/undefined/conflict/..., and
   jtbl_rodata_pads aborts via sys.exit with a message containing none of them --
   so a carve REFUSAL surfaced as "only warnings" and the real cause of a
   rejected bank was invisible. Refusals from jtbl_rodata_pads / jtbl_carve /
   corpus / jr_isolate_all are now named explicitly as the cause.

Negative-controlled both directions: the guard fires on a dirty src/800_b.c
naming the file, and --assert-baseline on a clean tree still reports
BASELINE GREEN 143dbb89... BYTE-IDENTICAL.
2026-09-03 10:41:13 -06:00
..