# RCA — golden r2 33273378238 RED 2 (Linux test, kitsubito) — doyle ruling, 2026-08-29 ~21:30Z

Run at `e4f52047` (v0.66.0 shape), ref golden/semaphore-242-r2. 3157 run: 3153 pass
(2 leaky), 4 fail, 1 skip. RED 1 (Windows n1-gate floor, 26.5→87.55 GB self-recovered)
is deployah's, no RCA owed, cleared without intervention.

## Verdict: TEST DEFECT (readiness-detection), product not implicated. Close at named mechanism; r3 same-sha is the release leg, not the closer.

## The four (one mechanism)

activity_link_push_e2e / endpoint_autostart_e2e / idle_edge_seal_e2e /
idle_edge_drain_e2e — each panicked `PRECONDITION: brain never came up` after burning
an identical, untuned 30s `wait_for_ready_pid` budget (50ms file poll for a `pid` key
in `brain.ready`; knows nothing about brain-up).

## Named mechanism

1. **The panic message is false by construction.** Every cell's captured daemon stderr
   shows `BRAIN_UP` — the brain connected to its broker in 27–65 ms and latched its
   first write (`CONN_LIFECYCLE conn=1 role=brain event=write-start`). What timed out
   is the `brain.ready` FILE, not the brain.
2. **The silent window.** Between `BRAIN_UP` and the ready file, `run_brain`
   (brainproc.rs:194–274 at the measured sha) executes: `announce_coordinator_image`
   (sync broker round-trip, silent on success) → `resume_session_cursors` (sync
   round-trip, silent on the always-taken empty arm — daemon hosts no PTY sessions) →
   `write_ready`, whose `current_exe_hash()` first call `std::fs::read`s the entire
   debug-profile binary and SHA-256s it before the atomic write. Nothing in this
   window emits on the happy path.
3. **Stall point within the window: UNDISCRIMINATED, and bounded so.** Panels exclude
   the loud arms (CONN_WRITE_POISONED=0, CONN_WRITE_RETIRED=0, no transport close, no
   error match arms) — so the stall is (a) blocked on a broker reply READ (ms bound is
   write-side only) or (b) inside the exe-hash read. Log surface exhausted (deployah,
   grep of R2_lin_test.log); the two are not separable without instrumentation. Both
   are product code running SLOW under load, neither is a wedge; the split does not
   change the classification, and the fixup lane makes the window observable so the
   next occurrence answers in one grep.
4. **The load is in the record.** Three of the four brains issued first writes within
   365 ms of each other (wall_ms 1788035430340/430667/430705) — three concurrent
   daemon boots, Phase A full-parallel, distinct brokers ⇒ BOX contention. The r2
   shape bumped every workspace crate version (Cargo.lock), forcing a full workspace
   recompile where r1 rode a warm ec6da9b0 cache — cold page cache under recompile
   load is the plausible tail-widener (deployah arm 4, offered as lead; consistent,
   not separately proven).
5. **Code cause excluded by construction.** e4f52047 − ec6da9b0 = Cargo.toml,
   Cargo.lock, CHANGELOG; zero `.rs`. Same 4 cells GREEN at parent, same box, same job
   (r1 33268589586: 3157/3157; durations 21.5–43.2s vs 30s budget — deadline-adjacent
   even when passing).

## Rulings

- **Structural presumption DISCHARGED** for these cells (pre-declared
  never-executed-cells tension): green-at-parent on byte-identical source is the
  "shown otherwise" the declaration anticipated. They execute and assert for real;
  these are load-tail flakes, not structural vacancies.
- **r3 same-sha (`e4f52047`) on both boxes** — release leg. Warm e4f52047 cache now on
  kitsubito removes the unique load source; Windows floor self-recovered.
- **hertz fixup lane (test-only, POST-cut, not blocking):** (1) correct the false
  precondition message (name the ready FILE and quote observed BRAIN_UP); (2) harden
  the 4 cells' precondition budget (untuned 30s under full-parallel Phase A is inside
  its own passing distribution).
- **todlando thin-lane scope +1 (product, POST-cut):** breadcrumb(s) making the
  BRAIN_UP→ready window discriminable in one grep (round-trips vs exe-hash vs
  post-ready), via `emit_line_err!`. Rides with his delivery.rs:149,313 conversion.

## ADDENDUM — r3 outcome splits the ruling (2026-08-29 ~22:30Z)

r3 (attempt 2, same sha, warm cache) = 3156/3157: idle_edge_seal, idle_edge_drain,
endpoint_autostart PASS — **load-tail ruling CONFIRMED for those three** (recovered
exactly as the self-discharging argument predicted). **activity_link_push_e2e FAILED
AGAIN** — identical signature (BRAIN_UP 26ms, no poison/retire/error arms, full 30.062s
budget burned), now cold AND warm, 4 recorded occurrences. A tail that survives removal
of its supposed load is not a tail: this cell is CARVED OUT of the load-tail ruling,
reclassified deterministic-and-unexplained, and the undiscriminated stall point
(reply-read vs first-call exe-hash) is now gate-blocking, not a footnote. Ruling: the
BRAIN_PHASE breadcrumb lane is PULLED AHEAD of the cut (was post-cut); local kitsubito
repro with the instrumented build before any further golden attempt.

Also superseded by r3: "RED 1 self-recovered" — FALSE. The Windows floor red is
DETERMINISTIC adjacency: the Win test job's ~57 GB of artifacts are not yet reclaimed
(async cleanup) when n1-gate's preflight fires 2s after it; two low-water readings 64
minutes apart agree within 10 MB (32229498880 / 32219230208 vs 34359738368 floor,
~2.1 GiB short every adjacent placement; r1-attempt-2 passed only by accidental time
separation). Fix belongs in the workflow (bounded-wait floor preflight), not in disk
clearing.

Meter correction (deployah, self-caught): his r2/r3 watcher exit files read 0 on red
runs — `gh run watch` without `--exit-status` exits 0 regardless. Control and treatment
identical ⇒ instrument indicted. All session verdicts came from API `conclusion` JSON,
so no verdict changes; the RULE is restated — an exit file is only as good as its
producer's exit semantics; authority for gh runs is the API conclusion.

## Artifacts

deployah's box, scratchpad `dfdf64db-*/scratchpad`: R2_lin_test.log (4306 lines),
R1_lin_test.log (control, 5097), R2_win_n1.log, R2B_verdict.json, R2B_alljobs.json.
Restore cost: ship-on-request from deployah; quote-bearing excerpts reproduced above.
