# NOW-SIGNAL #23 — W1 lane JIT (todlando, 2026-08-30)

Lane worktree `.worktrees/ns23-w1`, branch `feat/ns23-w1-updates-sealbrief`, base `aa9ac15a`.
Pool claimed `ns23-w1` from this worktree. **Nothing committed yet.**

## Dispatch (doyle, W1)

1. **#245 UPDATES** category — update events + version for spt-core, the endpoint's harness
   adapter, and the adapters of registered shells.
2. **#18 SEAL_BRIEF** category — ≤2 short sentences (operator constraint VERBATIM, not ours to
   relax), once per session.
3. **#11b render rider** — the EDGE_TRANSITIONS subnet-join line.

## DONE so far (builds clean: `cargo build -p spt` = 0)

- `Category::Updates` + `Category::SealBrief` on the enum, in `V1` (appended at the END —
  render order is declaration order, so the ratified v1 order is untouched), tags `UPDATES` /
  `SEAL_BRIEF`, dispatch arms in `cmd_now_signal`.
- `gather_updates` — three subjects; **the seen-set key carries the version**, which is what
  makes the delta discipline the event detector and is why no event journal is built. Shell
  adapters keyed PER SHELL. Absence is silence.
- `gather_seal_brief` + `SEAL_BRIEF_TEXT` constant.
- `REQ-NOW-SIGNAL-UPDATES` and `REQ-NOW-SIGNAL-SEAL-BRIEF` minted and activated
  (`doc, impl, unit`). `traceable-reqs check` = 1 with exactly the two expected misses:
  **doc and unit for both**. impl is covered.

⚠ **Caught mid-build, worth not re-learning:** the first `SEAL_BRIEF_TEXT` cited
`spt seal verify`, which **does not exist**. The real surface is `spt api seal verify <token>`
with the content on **stdin** (`api/mod.rs:599`, `SealCmd::Verify`); `spt seal` is the MINT verb
(TOTP ceremony). A payload whose whole job is telling an agent how to act is the worst place for
an invented command. Corrected, and the REQ title carries the correction so it cannot silently
regress.

## REMAINING, in order

1. **The #11b rider** (not started). Measured while designing it, and it REFINES my own W0
   finding — hand this back to doyle rather than silently implementing the old framing:
   `RosterEntry` is a **node** (pubkey, subnet, `label` = OS hostname), so the subnet-join arm is
   **node-level only**. There is no endpoint-join in this arm to distinguish, and a node does not
   join "from" a node — so the ticket's "z joined `<subnet>` from `<node>`" is **an unbuilt data
   source, not a mis-render**. What IS fixable here: say `node <label> joined subnet <x>` so the
   line names what it is, and stop the bare 12-hex degradation reading as an endpoint name.
2. **`doc` stage for both REQs** — `docs-site/src/harness-contract/api.md` now-signal section
   (the category list lives there); add both tags.
3. **`unit` stage for both** — at minimum: UPDATES fires once per subject and RE-fires when a
   version changes (both arms, or the delta claim is unpinned); SEAL_BRIEF is once-per-session
   and **is two sentences** (assert the sentence count against the constant — that is the
   operator constraint made executable).
4. `xtask check`, `traceable-reqs check` → 0, then the battery **env-scrubbed with the leg-0
   reap** (`env -u OWL_SESSION_ID -u SPT_AGENT_ID -u SPT_ENDPOINT_ID -u SPT_HOME`, and reap lane
   `spt.exe` by PATH before AND after — three tolls paid for that yesterday).
5. Hand doyle the sha. **Do not land to main** without his gate.

## Standing context

- #113 is fully unblocked behind W1 (all four forks ruled). Fork 2's ruling: REMOVE the
  mirror-into-running-context, KEEP the digest record, RE-KIND it (`echo_commune`, not
  `echo_mirror` — the old name becomes false the moment nothing mirrors); read ADR-0019 first,
  retag `REQ-TERM-7` evidence in the same commit, and the **boundary-delta measurement is that
  lane's FIRST step**.
- #44/#45 are W2, after this.
