Phase 4 batch 3: 6 PPCBUGs in the same-shape-as-addis (4b) sub-section. All share the pattern of computing on 64-bit values when the 32-bit ABI requires u32 arithmetic. - PPCBUG-001 addi: `li rT, -1` produced 0xFFFFFFFF_FFFFFFFF; now 0x00000000_FFFFFFFF. - PPCBUG-002 addic: writeback truncated + CA from u32 unsigned compare matching canary's `AddDidCarry`. - PPCBUG-003 addicx: same plus CR0 i32 view (regression vs. the frozen ppc-manual snapshot which had the correct form). - PPCBUG-004 mulli: 64-bit signed product now truncated to 32 bits. - PPCBUG-005 subficx: writeback + CA in u32 space; removes the bits-32-63 pollution from sign-extended negative SIMM. - PPCBUG-007 subfcx: defensive 32-bit truncation of CA compare. Same shape as the compare that broke addis (0x828F3F98 / 0x828F3F68 case). Tests: - addi_li_neg_one_zero_extends_upper (PPCBUG-001). - addic_carry_uses_32bit_compare (PPCBUG-002). - mulli_overflow_wraps_to_32 (PPCBUG-004). - subficx_neg_simm_zero_extends (PPCBUG-005). - subfcx_addis_incident_case (PPCBUG-007 — exact addis-incident case). Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>