Chasing which of sub_8226EAB8's 16 callers grows the trigger count: sub_8226E458 decrements a count at 8(r30) then calls the insert helper -- a splice -- and has exactly one caller, inside sub_8226D740, the per-frame engine->script drain. That suggests the engine moves records into the phase queue each frame. But the call site refutes the neat reading: at 0x8226D780 the argument is lwz r4, 324(r29), the UNIT ARRAY, not the trigger container. So I have not shown sub_8226E458 touches the trigger queue at all, and 'the engine feeds triggers each frame' is my inference rather than the disassembly's. Recorded unresolved. Taking a function's shape for its purpose is what produced the 'push' mislabel on sub_8226E3B8 and the ADN110-for-null pretty-print, each of which cost an iteration. Unaffected and solid: sub_8226EAB8 increments a count at +8 of its container, the trigger container embeds its list at +12, so the watched word at phase+272+20 is that inner list's count, and the guest was inside sub_8226EAB8 at the write. Next: instead of guessing among 16 callers, re-run the watchpoint and read the guest LR from the context -- the technique that named the writer will name its caller.