route map1_01a -> map2_02d; current writer 0x005428bc; opcode 0x20 candidate 0x005428a8; handler signatures 7/7; nested dispatcher uses general table True; nested runner swaps context stream True; context+0xf2 refs/read/write 204/141/63; context+0xf2 object selectors 16; context+0xf2 runtime table required True; local direct base setters before gate 0; descriptor+4 specific gate base proven False; descriptor+4 encoded route-target scalars 0/0/0; all descriptor-script gate writers/readers 0/0; all descriptor-script selection-buffer opcode-shaped rows 362; all descriptor-script encoded route-target scalars 0/0/0; all descriptor-script specific gate base proven False; diagnostic active order gate base proven False; diagnostic active-order recheck route hits 125/0/0; diagnostic active-order recheck count 0x00x679; diagnostic active-order recheck gate base still unproven True; public predecessor active order gate base proven False; public predecessor left-overrun active order gate base proven False; proof found False; gate base proof found False; active order proof found False; gate-time base proof found False; failed gate-base gates opcode20-runtime-base-path,predecessor-state-persistence,strict-source-hotspot; missing evidence count 3; evidence refs 19; gate pass if save/runtime base and predecessor state False; promotion status blocked.
The current gate pass calculation only becomes useful if the gate-time context+0xa8 base is known. The local stream before 0x005428c4 has no direct context+0xa8 base setter; the only base-affecting candidate in the activation window is opcode 0x20 at 0x005428a8, which runs runtime descriptor+4 nested scripts through the general handler table. The opcode 0x20 handler signature scan confirms that this row uses the descriptor+4 nested stream shape, and the nested runner swaps into the general dispatcher rather than executing the save-selector stream inline. Static descriptor scanning finds no descriptor+4 field-map records, no direct or encoded-scalar current-frontier/route refs, and no 0xe8/0xea gate readers or writers. The same gate-offset count is zero across descriptor+0, descriptor+4, and descriptor+8 scripts even though those scripts contain 362 selection-buffer opcode-shaped rows, so the active descriptor order alone cannot prove this route. The patched selector 2:0 diagnostic active order selects descriptor 0x004f867c, but its descriptor+4 script has no field-map/current-frontier/gate rows and its last context+0xa8 setter is a pointer-dword-low-byte-collision, so that diagnostic path is also non-promoting. A public predecessor direction sweep reaches selector 1:0 with active order 0x01/[0x00] and the same descriptor 0x004f867c, but it still does not reach selector 2:0 or the route context and descriptor+4 remains without field/frontier/gate rows. The constructed diagnostic left-route hit is not reproduced by either the selector-only recheck or the active-order recheck, and that active-order recheck stays at count 0, so it does not prove the gate-time base. A public predecessor left-overrun activation sweep also reaches selector 1:0 with the same non-promoting active-order evidence and still misses selector 2:0/current root. Therefore the context+0xf2 source scan is part of this gate-base proof: it sees runtime object-table reads and copies, not a fixed current-route object pointer. The supporting gate-offset, base-candidate, sample-value, selection-buffer-base, object-base, order-space, slot-source, descriptor-writer, and runtime-materializer reports also remain blocked/non-promoting: the gate offsets are inherited reader-only state, public samples do not cover selector 2:0, active order is not proven for the current frontier, and slot/materializer scans still require runtime descriptor/object state. save/runtime pass matrix narrows the hypothesis but cannot promote map1_01a -> map2_02d until the opcode 0x20 runtime descriptor/base path or an equivalent runtime trace is proven.
| path | fields |
|---|---|
out/save_selector_current_writer_paths.json | classification,rootHex,writerVaHex,activationContext,trace |
out/save_selector_opcode20_nested_base_modes.json | currentModeIsNestedObjectPlus4,directContextA8SetterCount,nestedRunner,opcode20SignatureSummary,promotionStatus |
out/save_selector_opcode20_descriptor_scripts.json | script4SpecificGateBaseProven,script4GateWriterCount,script4GateReaderCount,allScriptsSpecificGateBaseProven,allScriptSelectionOpcodeCount,runtimeActiveOrderRequired |
out/save_selector_opcode20_sample_order_effects.json | sampleCount,currentFrontierSampleCovered,sampleFinalNonPointerContextA8BaseHistogram,promotionStatus |
out/save_selector_gate_pass_matrix.json | saveRuntimePassMatrix,saveRuntimePredecessorAllGatePassSampleCount,saveRuntimeZeroTableAllGatePassSampleCount,runtimeBaseProofRequired,predecessorPersistenceProofRequired,strictHotspotProofRequired,promotionStatus |
out/runtime_patched_selector_followup_context.json | activeOrderRuntimeEvidence,leftStabilityRuntimeEvidence,promotionStatus |
out/runtime_selected_pointer_predecessor_direction_sweep_active_order_poll.json | observedPublicSaveSelectors,rows,anyReachedCurrentRoot,anyReachedRouteSelectorContext,promotionStatus |
out/runtime_selected_pointer_predecessor_left_overrun_activation_active_order_poll.json | observedPublicSaveSelectors,rows,anyReachedCurrentRoot,anyReachedRouteSelectorContext,promotionStatus |
out/save_selector_gate_offset_sources.json | gateOffsetsHex,anyScriptLocalSelectionWriter,anyGlobalScriptSelectionWriter,controlPathGateStatus,controlPathProofStatus,proofFound,gateOffsetSourceProofFound,failedGateOffsetSourceGateIds,missingEvidence,evidenceRefs,evidenceRefCount,promotionStatus |
out/save_selector_gate_offset_patterns.json | offsets,totalReaderCount,totalWriterCount,proofFound,gateOffsetPatternProofFound,failedGateOffsetPatternGateIds,missingEvidence,evidenceRefs,evidenceRefCount,promotionStatus |
out/save_selector_gate_base_candidates.json | candidateCount,directRefCandidateCount,partySlotStatByteCandidateCount,runtimePointerModeStillRequired,proofFound,gateBaseCandidateProofFound,failedGateBaseCandidateGateIds,missingEvidence,evidenceRefs,evidenceRefCount,promotionStatus |
out/save_selector_gate_sample_values.json | sampleCount,uniqueSelectorCount,currentFrontierSampleCovered,runtimePointerModeStillRequired,proofFound,gateSampleValueProofFound,failedGateSampleValueGateIds,missingEvidence,evidenceRefs,evidenceRefCount,promotionStatus |
out/save_selector_selection_buffer_bases.json | knownStaticGateOffsetDirectRefCount,runtimePointerModeStillRequired,proofFound,selectionBufferBaseProofFound,failedSelectionBufferBaseGateIds,missingEvidence,evidenceRefs,evidenceRefCount,promotionStatus |
out/save_selector_opcode20_object_base_candidates.json | candidateCount,contextF2ObjectSelectorCount,fieldMapRowsAfterCandidateCount,currentFrontierRowsAfterCandidateCount,gateSelectionRowsAfterCandidateCount,runtimeObjectPointerProofRequired,proofFound,opcode20ObjectBaseProofFound,failedOpcode20ObjectBaseGateIds,missingEvidence,evidenceRefs,evidenceRefCount,promotionStatus |
out/save_selector_opcode20_order_space.json | descriptorRowCount,currentFrontierSampleCovered,activeOrderAlonePromotesRoute,runtimeDescriptorObjectStateRequired,proofFound,opcode20OrderSpaceProofFound,failedOpcode20OrderSpaceGateIds,missingEvidence,evidenceRefs,evidenceRefCount,promotionStatus |
out/save_selector_opcode20_slot_sources.json | runtimeSlotCountRequired,runtimeSlotDescriptorPointersRequired,controlPathProofStatus,proofFound,opcode20SlotSourceProofFound,failedOpcode20SlotSourceGateIds,missingEvidence,evidenceRefs,evidenceRefCount,promotionStatus |
out/save_selector_opcode20_slot_descriptor_writers.json | descriptorWriteCount,opcode20Mode0ScriptSource,runtimeActiveOrderRequired,controlPathProofStatus,proofFound,opcode20DescriptorWriterProofFound,failedOpcode20DescriptorWriterGateIds,missingEvidence,evidenceRefs,evidenceRefCount,promotionStatus |
out/save_selector_opcode20_runtime_materializers.json | materializers,loadRebuildEvidence,currentRouteSameLowByteRowCount,descriptorScriptMutationRowCount,currentFrontierActiveOrderProven,opcode20SelfMutationPathEliminated,controlPathProofStatus,proofFound,opcode20RuntimeMaterializerProofFound,failedOpcode20RuntimeMaterializerGateIds,missingEvidence,evidenceRefs,evidenceRefCount,promotionStatus |
out/save_selector_opcode20_context_f2_sources.json | referenceCount,readReferenceCount,writeReferenceCount,runtimeObjectTableReaderCount,specificRuntimeObjectPointerProven,runtimeObjectTableStateRequired,diagnosticRuntimeObjectTableEvidence,promotionStatus |
| va | value | opcode | kind | direct setter | meaning |
|---|---|---|---|---|---|
0x005428a8 | 0x00200020 | 0x20 | nested descriptor runner | False | dispatch/load runtime object or party-member script references |
The gate window trace shows that between opcode 0x20 and the first 0xe8 gate, the gate window only opcode 0x20 base candidate flag is true.
| va | value | opcode | handler | base candidate | writer | first gate | meaning |
|---|---|---|---|---|---|---|---|
0x005428a8 | 0x00200020 | 0x20 | - | True | False | False | dispatch/load runtime object or party-member script references |
0x005428b0 | 0x005428a4 | 0xa4 | - | False | False | False | - |
0x005428b4 | 0x001c8112 | 0x12 | 0x0040b55f | False | False | False | write selected active branch-state slot to selectionBuffer[0x1c] |
0x005428b8 | 0x00100000 | 0x00 | 0x0040239f | False | False | False | - |
0x005428bc | 0x00208212 | 0x12 | 0x0040b55f | False | True | False | write selected active branch-state slot to selectionBuffer[0x20] |
0x005428c0 | 0x00200000 | 0x00 | 0x0040239f | False | False | False | - |
0x005428c4 | 0x00e88111 | 0x11 | 0x0040b4e6 | False | False | True | read secondaryBranchState[selectionBuffer[0xe8]] and gate next stream value |
descriptor+4 field-map/current-frontier refs and gate offset rows are kept separate from active order alone sufficient for gate proof.
| field-map records | current frontier refs | encoded raw/proof/promoting | gate writers | gate readers | non-pointer context+0xa8 setters | non-pointer bases | active order alone sufficient |
|---|---|---|---|---|---|---|---|
| 0 | 0 | 0/0/0 | 0 | 0 | 16 | dword[0x0059db30 + context[0xf2]*4] or dword[0x0059db30 + stream[2]*4] | False |
The context+0xf2 source scan is kept inside this gate-base proof so the non-pointer context+0xa8 rows cannot be read as fixed route bases.
| artifact | refs/read/write | object readers | init/copy/constant writes | object selectors | fixed stream+2 selectors | current sample covered | pointer proven | runtime table required | diagnostic object table | status |
|---|---|---|---|---|---|---|---|---|---|---|
save_selector_opcode20_context_f2_sources.json | 204 / 141 / 63 | 65 | 2 / 61 / 0 | 16 | 0 | False | False | True | 210/374 0x01/0x00 diagnostic-only | blocked |
descriptor+0, descriptor+4, and descriptor+8 are scanned together to rule out a gate-offset row hiding in another descriptor script slot.
| field-map records | current frontier refs | encoded raw/proof/promoting | selection opcodes | gate writers | gate readers | specific gate base proven |
|---|---|---|---|---|---|---|
| 0 | 0 | 0/0/0 | 362 | 0 | 0 | False |
The diagnostic active order came from a patched public-base save load, so it is diagnostic active order evidence and not route proof.
| source poll | staged save | not route proof | active order | first descriptor | matches script | field/frontier refs | encoded raw/proof/promoting | gate writers/readers | non-pointer context+0xa8 setters | last context+0xa8 shape | gate base proven |
|---|---|---|---|---|---|---|---|---|---|---|---|
runtime_selected_pointer_patched_public_selector_2_0_active_order_poll.json | patched public-base diagnostic active-order watch | True | 0x01/0x00 | 0x004f867c | True | 0 / 0 | 0 / 0 / 0 | 0 / 0 | 0 | pointer-dword-low-byte-collision | False |
The selector-only and active-order rechecks are kept separate from the first constructed left-route hit.
| stability poll | route hits | selector recheck | active-order recheck | active-order count | slot0 descriptor | reproduced | gate base still unproven |
|---|---|---|---|---|---|---|---|
runtime_patched_selector_left_stability_poll.json | 125 | runtime_patched_selector_left_stability_recheck_poll.json 0 hits / 50:0 | runtime_patched_selector_left_active_order_poll.json 0 hits / 50:0 | 0x00x679 | 0x00266004x679 | False | True |
The public predecessor active order came from the real public savedat direction sweep. It reaches selector 1:0 but not selector 2:0 or the route context.
| source poll | staged save | not route proof | samples | active order | first descriptor runtime/static | runtime slot base table0 | runtime object table | stable | field/frontier refs | encoded raw/proof/promoting | gate writers/readers | non-pointer context+0xa8 setters | last context+0xa8 shape | gate base proven |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
runtime_selected_pointer_predecessor_direction_sweep_active_order_poll.json | public predecessor direction sweep active-order watch | True | 1689/3378 | 0x01/0x00 | 0x0021867c / 0x004f867c | 0x00177750 | 0x0027be00,0x0027d2f8,0x0027d5d4 | True | 0 / 0 | 0 / 0 / 0 | 0 / 0 | 0 | pointer-dword-low-byte-collision | False |
The left-overrun activation sweep is a second public predecessor calibration run. It reaches selector 1:0 but not selector 2:0 or the current root.
| source poll | staged save | not route proof | samples | active order | first descriptor runtime/static | runtime slot base table0 | runtime object table | stable | field/frontier refs | encoded raw/proof/promoting | gate writers/readers | non-pointer context+0xa8 setters | last context+0xa8 shape | gate base proven |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
runtime_selected_pointer_predecessor_left_overrun_activation_active_order_poll.json | public predecessor left-overrun activation active-order watch | True | 584/2293 | 0x01/0x00 | 0x0021867c / 0x004f867c | 0x00177750 | 0x0027be00,0x0027d2f8,0x0027d5d4 | True | 0 / 0 | 0 / 0 / 0 | 0 / 0 | 0 | pointer-dword-low-byte-collision | False |
| base expression | sample count |
|---|