doyle -> deployah: a4 STOP CONFIRMED, hand-back accepted, sha 25e60015 is DONE - no a5. Log verified my side (manifest OK from repo root; Summary 2; Phase A 3346/3346 in 742.239 s; Phase B 233/234 in 1168.430 s; criterion 4 MET: arm-12 cell PASS 25.136 s, mesh_recovery PASS 8.341 s). RCA of the third victim (registry_lifecycle oneway_rounds... :514, held 0 -> 1, seats 1, 11.594 s; passed 10.8 / 10.5 / 23.3 s on a1-a3): RIG SAMPLE RACE, load-widened, not product. Mechanism from the source: A's pump is a bare thread::spawn stopped by a FLAG and never joined (:307 spawn, :386 pump_stop, no join); the drains converge on B's gauges, gen-1 is joined, then b_held_before is sampled (0) and gen-2 started; A's pump's LAST 100 ms-cadence round can still deliver ONE feed to B after that sample, and B then holds one row with one in-flight seat - which is exactly the reading. One row, not a storm: the re-apply bound one assertion earlier PASSED, and a replay regression re-subscribes the whole history. The test's own comment at :500-506 records this face ("the extra held row was ONE straggler feed ... mis-attributed to gen-2"). Product path untouched: diff v0.67.0..25e60015 on registryhost.rs / pump = none; dispatch.rs changes are the Web stream family only; broker.rs = a test accessor. Your qualifier stands and is answered: the CLASS changed (timeout -> count), the FAMILY did not (a fixed sample or budget racing an unjoined background actor). todlando's falsifier: third distinct victim = one env cause, confirmed with that qualifier. Box at a4: per-cell a4/a2 median 1.00, 12 of 72 cells >= 1.5x, worst 4.75x - bursty again, not uniformly slow. Phase A 742 s vs 495 s at a2. RESPIN SHAPE (r3): new shaped head = 25e60015 + three TEST-ONLY riders rebased by hertz: 88625fa0 (arm 12 deterministic), b359e40e (converge budgets derived), + a NEW rider on registry_lifecycle (join the pump thread before the before-sample; the panic prints stream ids). d882297f and d7c2105e stay OUT of the release gate. hertz proves clippy + treqs + the three victim cells on both OSes before hand-off; then you assemble/verify per the intake runbook and run r3. The operator asks (Defender exclusion, seeding pause) stand as box-level; they are not preconditions unless he grants them. Attempt 4's pair: still read criteria 5 and 6 fresh when it concludes (started 02:36:42Z), probe only after terminal as gated, preserve as before. Boxes stay QUIET until the run is terminal; I release them to hertz at that point, not you. Board comment from me now.