# 🟑 The three built-ins that appear *inside* clear conditions β€” read, not named [`isl-phase-guards`](isl-phase-guards.md) produced the per-phase clear conditions, but three of the built-ins in them were unread, so the conditions were only half-readable. All three are read now. **None of them is named** β€” the corpus has withdrawn two names taken from usage shape, and what I read is not enough to name these. Implementations via the vtable at `0x820A84BC` (control: built-in 69 `unit_state` β†’ slot 184 β†’ `0x8226ADF0`, as recorded). | built-in | slot | implementation | |---|---|---| | **104** | 288 | `0x8226BFE0` | | **141** | 428 | `0x8226C9B8` | | **7** | 40 | `0x82266C68` | ## βœ… `builtin104` is a pure getter β€” and it is the whole tutorial clear condition ``` 8226BFE0 lwz r11, 10160(r3) ; r3 = the ScriptPhase 8226BFE4 stw r11, 164(r3) ; -> special[0] 8226BFE8 blr ``` Three instructions. It returns **`[phase+10160]`** and nothing else. So all six tutorial stages (S18–S23) end on the value of a **single engine-written word** β€” which is exactly why their exits have one dominating condition each and why `isl-builtins.md` saw built-in 104 only ever inside a poll loop. **That word has exactly one writer** in the whole image: ``` 821AAD74 lwz r11, 104(r30) 821AAD84 lwz r11, 12(r11) 821AAD88 cmpi cr6, 0, r11, 16 ; skip if == 16 821AAD90 cmpi cr6, 0, r11, 32 ; skip if > 32 821AAD98 lwz r11, 4(r10) 821AAD9C stw r29, 10160(r11) ; <- the only write ``` inside `sub_821AA1B0`, gated on a type/kind field being in `(16, 32]`. `r29` there comes from `or r29, r3, r3` β€” the return of a preceding call β€” so **what the value means is not established**, and neither is what the gate selects. 🟑 Its neighbours belong to the same cluster: `builtin103` reads `[phase+10156]` and `[phase+10152]` (9 and 7 writers), and a sibling vtable stub clears `[phase+10152]`. The shape is an engineβ†’script status trio, but that is a description, not a name. ## βœ… `builtin7`'s mechanism β€” and an independent confirmation ``` 82266C84 lwz r11, 324(r25) ; the unit array 82266C88 lwz r10, 4(r26) ; local[4] 82266C94 lwzx r11, r10, r11 ; -> the record 82266C98 lwz r10, 4(r11) ; the handle … (alive?) 82266CA4 lwz r11, 16(r11) ; rec+16 = the unit STATE 82266CA8..CBC ; bail if state == 1, 3 or 4 82266CC0 lwz r10, 12(r26) ; local[12] 82266CC8 lwz r11, 244(r25) ; [phase+244] = SYMBOL TABLE 1 82266CD8 lwzx r10, r10, r11 ; -> resolve local[12] as a symtab-1 index 82266CD0 lfd f31, 25600(r9) ; a double constant 82266CD4 lwz r9, 16(r26) ; local[16] ``` πŸ”‘ **`isl.py`'s `SYM1_SLOTS` already lists slot 12 for built-in 7**, derived purely from operand ranges. Reading the implementation shows the *mechanism* β€” `local[12]` is indexed into `[phase+244]`, which [`isl-bytecode.md`](isl-bytecode.md) documents as symbol table 1 (routes, messages, objectives). **Two independent methods, same conclusion.** That makes the Stage 02 phase-2 condition ``` builtin7(TCT206, 1, Route_TCT206_p2S, 4294967295, 500) == 1 ``` structurally coherent β€” a unit, a **route symbol**, and two numbers β€” but *what* it asks about the route is not read, so it stays `builtin7`. ## 🟑 `builtin141` β€” only the entry read ``` 8226C9D4 lwz r11, 324(r29) ; unit array 8226C9D8 lwz r10, 4(r31) ; local[4] 8226C9E8 lwz r8, 4(r8) ; handle 8226C9F0 bc … 0x8226CA0C ; if alive, continue 8226C9F4 addi r11, r0, 0 8226C9F8 stw r11, 164(r29) ; dead -> special[0] = 0 ``` The same unit-array opening as every unit predicate, returning 0 when the unit is gone. Everything past `0x8226CA0C` is unread. Stage 16 calls it twice with arguments differing in one position (`0` vs `-4000`), which *looks* like a coordinate β€” and looking like one is precisely the evidence this corpus does not accept. ## 🟑 Not settled * **No name for any of the three.** For 104 that needs the meaning of `r29` at `0x821AAD9C` and of the `(16, 32]` gate; for 7 and 141, their bodies past the entry checks. * `builtin103`'s fields `[phase+10152]` / `[phase+10156]` have 9 and 7 writers, none read. * This does not change any artefact β€” the conditions already printed `builtin104`, `builtin7`, `builtin141`, and still do.