Fixed a boot-time white screen on Mario Kart: Super Circuit. Probing and mGBA differential analysis traced it to the IRQ return address after waking from SWI halt missing one pipeline width, so the wake re-executed the SWI and swallowed the continuation. A mutation-verified lock test was added; a 1200-frame headless run shows per-frame hashes changing (truly running, not a frozen frame), reaching the title screen. This was the second systemic defect found by a real cartridge despite fully green lock tests.
商业卡带《Mario Kart: Super Circuit》此前引导即白屏卡死。经探针与 mGBA 差分定位,根因是 SWI 停机被中断唤醒后,IRQ 返回地址少补一个流水线宽度,唤醒后重执行 SWI、吞掉续接点。修复后新增锁测试(变异两向可红),harness 1200 帧逐帧哈希逐档变化——确认真跑非冻帧——已到标题画面,用户确认可运行。这是第二例「锁测试全绿却由真卡带暴露」的系统性缺陷。
v2.0.1 opens with a fix to ARM-mode SWI numbering: the comment field lives in bits 16–23, but the low byte was read — every ARM-mode BIOS call became a SoftReset and programs reset-looped. The fix exposed that two of our own SWI encoders (gate and dispatch) shared the same bug: 246 lock tests stayed green the whole time the defect existed. Both encoders were corrected, with 2 new lock tests and two-way mutation verification; the lesson is now固化 — recorded in governance docs.
ARM 模式下 SWI 编号应取 bits 16–23,此前误读低字节——每次 ARM 模式 BIOS 调用都变成 SoftReset,程序自复位卡死。修复同时发现本仓库两处 ARM SWI 编码器(门禁与 dispatch)与缺陷同错:246 项锁测试在缺陷存在的整段时间里全绿,门禁是错误信念的镜像。两处编码器已一并改正,新增 2 条锁测试并做双向变异验证;教训已固化进治理文档。
Line B measured the PRESCALER routine at 2× the expected cycles and found S-cycles double-billed between fetch and execution; after the fix four instruction-timing tests recovered, and 227 vendor-core tests that had never run were restored. The TIMER root cause was the prescaler reading the wrong register (TMxCNT_H forces ÷1), followed by the TM0 cascade bit and the enable start delay; one direction-of-division change was refuted by AGS and rolled back. All three AGS TIMER entries now pass, closing P4.
「Line B」量出 PRESCALER 例程纯指令时序 2 倍超计,定位到取指与执行体的 S 周期被双计费,修复后四条指令周期测试转正,并恢复了 vendor 核心从未跑起来的 227 项自测。TIMER 失败真根因是分频读错寄存器(读 TMxCNT_H 恒为 ÷1),随后补上 TM0 cascade 位与使能启动延迟;一次方向性修改被 AGS 期望表证伪并回退。最终 AGS TIMER 三项全过,P4 关闭。
P3 rebinds the prefetch-hit criterion from last_used_address to the instruction-fetch stream, so data accesses no longer break hits — both PREFETCH BUFFER readings hit 24/51 exactly, AGS 24→25. P1 narrowed its failure surface to timers freezing during DMA: the fix extracts drain_clocked_peripherals(), adds a +3-cycle start delay per block and drains clocked peripherals before every unit. All five MEMORY tests are green (MEMORY 9/9), AGS 25/33 → 30/33. Remaining DMA DISPLAY START and DMA PRIORITY each need their own RE and are logged as long-tail.
P3 将预取命中判据从 last_used_address 改绑取指流地址——数据访问不再打断命中,PREFETCH BUFFER 两档读数 24/51 精确,AGS 24→25。P1 三轮侦察后把失败面收窄到 DMA 期间定时器冻结:修复抽取出 drain_clocked_peripherals(),块首计入 +3 周期起始延迟、每单元前排水时钟外设。五个 MEMORY 测试全部转绿(MEMORY 9/9),AGS 25/33 → 30/33。剩余 DMA DISPLAY START 与 DMA PRIORITY 需各自独立逆向,记入长尾。