Save Selector Gate Base Proof Gap

route map1_01a -> map2_02d; current writer 0x005428bc; opcode 0x20 candidate 0x005428a8; handler signatures 7/7; nested dispatcher uses general table True; nested runner swaps context stream True; context+0xf2 refs/read/write 204/141/63; context+0xf2 object selectors 16; context+0xf2 runtime table required True; local direct base setters before gate 0; descriptor+4 specific gate base proven False; descriptor+4 encoded route-target scalars 0/0/0; all descriptor-script gate writers/readers 0/0; all descriptor-script selection-buffer opcode-shaped rows 362; all descriptor-script encoded route-target scalars 0/0/0; all descriptor-script specific gate base proven False; diagnostic active order gate base proven False; diagnostic active-order recheck route hits 125/0/0; diagnostic active-order recheck count 0x00x679; diagnostic active-order recheck gate base still unproven True; public predecessor active order gate base proven False; public predecessor left-overrun active order gate base proven False; proof found False; gate base proof found False; active order proof found False; gate-time base proof found False; failed gate-base gates opcode20-runtime-base-path,predecessor-state-persistence,strict-source-hotspot; missing evidence count 3; evidence refs 19; gate pass if save/runtime base and predecessor state False; promotion status blocked.

The current gate pass calculation only becomes useful if the gate-time context+0xa8 base is known. The local stream before 0x005428c4 has no direct context+0xa8 base setter; the only base-affecting candidate in the activation window is opcode 0x20 at 0x005428a8, which runs runtime descriptor+4 nested scripts through the general handler table. The opcode 0x20 handler signature scan confirms that this row uses the descriptor+4 nested stream shape, and the nested runner swaps into the general dispatcher rather than executing the save-selector stream inline. Static descriptor scanning finds no descriptor+4 field-map records, no direct or encoded-scalar current-frontier/route refs, and no 0xe8/0xea gate readers or writers. The same gate-offset count is zero across descriptor+0, descriptor+4, and descriptor+8 scripts even though those scripts contain 362 selection-buffer opcode-shaped rows, so the active descriptor order alone cannot prove this route. The patched selector 2:0 diagnostic active order selects descriptor 0x004f867c, but its descriptor+4 script has no field-map/current-frontier/gate rows and its last context+0xa8 setter is a pointer-dword-low-byte-collision, so that diagnostic path is also non-promoting. A public predecessor direction sweep reaches selector 1:0 with active order 0x01/[0x00] and the same descriptor 0x004f867c, but it still does not reach selector 2:0 or the route context and descriptor+4 remains without field/frontier/gate rows. The constructed diagnostic left-route hit is not reproduced by either the selector-only recheck or the active-order recheck, and that active-order recheck stays at count 0, so it does not prove the gate-time base. A public predecessor left-overrun activation sweep also reaches selector 1:0 with the same non-promoting active-order evidence and still misses selector 2:0/current root. Therefore the context+0xf2 source scan is part of this gate-base proof: it sees runtime object-table reads and copies, not a fixed current-route object pointer. The supporting gate-offset, base-candidate, sample-value, selection-buffer-base, object-base, order-space, slot-source, descriptor-writer, and runtime-materializer reports also remain blocked/non-promoting: the gate offsets are inherited reader-only state, public samples do not cover selector 2:0, active order is not proven for the current frontier, and slot/materializer scans still require runtime descriptor/object state. save/runtime pass matrix narrows the hypothesis but cannot promote map1_01a -> map2_02d until the opcode 0x20 runtime descriptor/base path or an equivalent runtime trace is proven.

Missing Evidence

Evidence Refs

pathfields
out/save_selector_current_writer_paths.jsonclassification,rootHex,writerVaHex,activationContext,trace
out/save_selector_opcode20_nested_base_modes.jsoncurrentModeIsNestedObjectPlus4,directContextA8SetterCount,nestedRunner,opcode20SignatureSummary,promotionStatus
out/save_selector_opcode20_descriptor_scripts.jsonscript4SpecificGateBaseProven,script4GateWriterCount,script4GateReaderCount,allScriptsSpecificGateBaseProven,allScriptSelectionOpcodeCount,runtimeActiveOrderRequired
out/save_selector_opcode20_sample_order_effects.jsonsampleCount,currentFrontierSampleCovered,sampleFinalNonPointerContextA8BaseHistogram,promotionStatus
out/save_selector_gate_pass_matrix.jsonsaveRuntimePassMatrix,saveRuntimePredecessorAllGatePassSampleCount,saveRuntimeZeroTableAllGatePassSampleCount,runtimeBaseProofRequired,predecessorPersistenceProofRequired,strictHotspotProofRequired,promotionStatus
out/runtime_patched_selector_followup_context.jsonactiveOrderRuntimeEvidence,leftStabilityRuntimeEvidence,promotionStatus
out/runtime_selected_pointer_predecessor_direction_sweep_active_order_poll.jsonobservedPublicSaveSelectors,rows,anyReachedCurrentRoot,anyReachedRouteSelectorContext,promotionStatus
out/runtime_selected_pointer_predecessor_left_overrun_activation_active_order_poll.jsonobservedPublicSaveSelectors,rows,anyReachedCurrentRoot,anyReachedRouteSelectorContext,promotionStatus
out/save_selector_gate_offset_sources.jsongateOffsetsHex,anyScriptLocalSelectionWriter,anyGlobalScriptSelectionWriter,controlPathGateStatus,controlPathProofStatus,proofFound,gateOffsetSourceProofFound,failedGateOffsetSourceGateIds,missingEvidence,evidenceRefs,evidenceRefCount,promotionStatus
out/save_selector_gate_offset_patterns.jsonoffsets,totalReaderCount,totalWriterCount,proofFound,gateOffsetPatternProofFound,failedGateOffsetPatternGateIds,missingEvidence,evidenceRefs,evidenceRefCount,promotionStatus
out/save_selector_gate_base_candidates.jsoncandidateCount,directRefCandidateCount,partySlotStatByteCandidateCount,runtimePointerModeStillRequired,proofFound,gateBaseCandidateProofFound,failedGateBaseCandidateGateIds,missingEvidence,evidenceRefs,evidenceRefCount,promotionStatus
out/save_selector_gate_sample_values.jsonsampleCount,uniqueSelectorCount,currentFrontierSampleCovered,runtimePointerModeStillRequired,proofFound,gateSampleValueProofFound,failedGateSampleValueGateIds,missingEvidence,evidenceRefs,evidenceRefCount,promotionStatus
out/save_selector_selection_buffer_bases.jsonknownStaticGateOffsetDirectRefCount,runtimePointerModeStillRequired,proofFound,selectionBufferBaseProofFound,failedSelectionBufferBaseGateIds,missingEvidence,evidenceRefs,evidenceRefCount,promotionStatus
out/save_selector_opcode20_object_base_candidates.jsoncandidateCount,contextF2ObjectSelectorCount,fieldMapRowsAfterCandidateCount,currentFrontierRowsAfterCandidateCount,gateSelectionRowsAfterCandidateCount,runtimeObjectPointerProofRequired,proofFound,opcode20ObjectBaseProofFound,failedOpcode20ObjectBaseGateIds,missingEvidence,evidenceRefs,evidenceRefCount,promotionStatus
out/save_selector_opcode20_order_space.jsondescriptorRowCount,currentFrontierSampleCovered,activeOrderAlonePromotesRoute,runtimeDescriptorObjectStateRequired,proofFound,opcode20OrderSpaceProofFound,failedOpcode20OrderSpaceGateIds,missingEvidence,evidenceRefs,evidenceRefCount,promotionStatus
out/save_selector_opcode20_slot_sources.jsonruntimeSlotCountRequired,runtimeSlotDescriptorPointersRequired,controlPathProofStatus,proofFound,opcode20SlotSourceProofFound,failedOpcode20SlotSourceGateIds,missingEvidence,evidenceRefs,evidenceRefCount,promotionStatus
out/save_selector_opcode20_slot_descriptor_writers.jsondescriptorWriteCount,opcode20Mode0ScriptSource,runtimeActiveOrderRequired,controlPathProofStatus,proofFound,opcode20DescriptorWriterProofFound,failedOpcode20DescriptorWriterGateIds,missingEvidence,evidenceRefs,evidenceRefCount,promotionStatus
out/save_selector_opcode20_runtime_materializers.jsonmaterializers,loadRebuildEvidence,currentRouteSameLowByteRowCount,descriptorScriptMutationRowCount,currentFrontierActiveOrderProven,opcode20SelfMutationPathEliminated,controlPathProofStatus,proofFound,opcode20RuntimeMaterializerProofFound,failedOpcode20RuntimeMaterializerGateIds,missingEvidence,evidenceRefs,evidenceRefCount,promotionStatus
out/save_selector_opcode20_context_f2_sources.jsonreferenceCount,readReferenceCount,writeReferenceCount,runtimeObjectTableReaderCount,specificRuntimeObjectPointerProven,runtimeObjectTableStateRequired,diagnosticRuntimeObjectTableEvidence,promotionStatus

Local Base-Affecting Rows

vavalueopcodekinddirect settermeaning
0x005428a80x002000200x20nested descriptor runnerFalsedispatch/load runtime object or party-member script references

Gate Window Trace

The gate window trace shows that between opcode 0x20 and the first 0xe8 gate, the gate window only opcode 0x20 base candidate flag is true.

vavalueopcodehandlerbase candidatewriterfirst gatemeaning
0x005428a80x002000200x20-TrueFalseFalsedispatch/load runtime object or party-member script references
0x005428b00x005428a40xa4-FalseFalseFalse-
0x005428b40x001c81120x120x0040b55fFalseFalseFalsewrite selected active branch-state slot to selectionBuffer[0x1c]
0x005428b80x001000000x000x0040239fFalseFalseFalse-
0x005428bc0x002082120x120x0040b55fFalseTrueFalsewrite selected active branch-state slot to selectionBuffer[0x20]
0x005428c00x002000000x000x0040239fFalseFalseFalse-
0x005428c40x00e881110x110x0040b4e6FalseFalseTrueread secondaryBranchState[selectionBuffer[0xe8]] and gate next stream value

Descriptor+4 Static Gate Evidence

descriptor+4 field-map/current-frontier refs and gate offset rows are kept separate from active order alone sufficient for gate proof.

field-map recordscurrent frontier refsencoded raw/proof/promotinggate writersgate readersnon-pointer context+0xa8 settersnon-pointer basesactive order alone sufficient
000/0/00016dword[0x0059db30 + context[0xf2]*4] or dword[0x0059db30 + stream[2]*4]False

Opcode 0x20 Context+0xf2 Source Evidence

The context+0xf2 source scan is kept inside this gate-base proof so the non-pointer context+0xa8 rows cannot be read as fixed route bases.

artifactrefs/read/writeobject readersinit/copy/constant writesobject selectorsfixed stream+2 selectorscurrent sample coveredpointer provenruntime table requireddiagnostic object tablestatus
save_selector_opcode20_context_f2_sources.json204 / 141 / 63652 / 61 / 0160FalseFalseTrue210/374 0x01/0x00 diagnostic-onlyblocked

Descriptor All-Slot Static Gate Evidence

descriptor+0, descriptor+4, and descriptor+8 are scanned together to rule out a gate-offset row hiding in another descriptor script slot.

field-map recordscurrent frontier refsencoded raw/proof/promotingselection opcodesgate writersgate readersspecific gate base proven
000/0/036200False

Diagnostic Active-Order Gate Evidence

The diagnostic active order came from a patched public-base save load, so it is diagnostic active order evidence and not route proof.

source pollstaged savenot route proofactive orderfirst descriptormatches scriptfield/frontier refsencoded raw/proof/promotinggate writers/readersnon-pointer context+0xa8 setterslast context+0xa8 shapegate base proven
runtime_selected_pointer_patched_public_selector_2_0_active_order_poll.jsonpatched public-base diagnostic active-order watchTrue0x01/0x000x004f867cTrue0 / 00 / 0 / 00 / 00pointer-dword-low-byte-collisionFalse

Diagnostic Active-Order Recheck

The selector-only and active-order rechecks are kept separate from the first constructed left-route hit.

stability pollroute hitsselector recheckactive-order recheckactive-order countslot0 descriptorreproducedgate base still unproven
runtime_patched_selector_left_stability_poll.json125runtime_patched_selector_left_stability_recheck_poll.json 0 hits / 50:0runtime_patched_selector_left_active_order_poll.json 0 hits / 50:00x00x6790x00266004x679FalseTrue

Public Predecessor Active-Order Gate Evidence

The public predecessor active order came from the real public savedat direction sweep. It reaches selector 1:0 but not selector 2:0 or the route context.

source pollstaged savenot route proofsamplesactive orderfirst descriptor runtime/staticruntime slot base table0runtime object tablestablefield/frontier refsencoded raw/proof/promotinggate writers/readersnon-pointer context+0xa8 setterslast context+0xa8 shapegate base proven
runtime_selected_pointer_predecessor_direction_sweep_active_order_poll.jsonpublic predecessor direction sweep active-order watchTrue1689/33780x01/0x000x0021867c / 0x004f867c0x001777500x0027be00,0x0027d2f8,0x0027d5d4True0 / 00 / 0 / 00 / 00pointer-dword-low-byte-collisionFalse

Public Predecessor Left-Overrun Active-Order Gate Evidence

The left-overrun activation sweep is a second public predecessor calibration run. It reaches selector 1:0 but not selector 2:0 or the current root.

source pollstaged savenot route proofsamplesactive orderfirst descriptor runtime/staticruntime slot base table0runtime object tablestablefield/frontier refsencoded raw/proof/promotinggate writers/readersnon-pointer context+0xa8 setterslast context+0xa8 shapegate base proven
runtime_selected_pointer_predecessor_left_overrun_activation_active_order_poll.jsonpublic predecessor left-overrun activation active-order watchTrue584/22930x01/0x000x0021867c / 0x004f867c0x001777500x0027be00,0x0027d2f8,0x0027d5d4True0 / 00 / 0 / 00 / 00pointer-dword-low-byte-collisionFalse

Sample Non-Pointer Context+0xa8 Base Histogram

base expressionsample count

Remaining Proofs