> PROJECT index (all agents here load it). Keep under ~17KB β€” past the read limit the TAIL IS > SILENTLY DROPPED. Compacted 2026-08-03: 37.5KB->25.6KB->19.7KB->here, NO topic file deleted; > 41 entries lost their index LINE, then 11 were RESTORED (doyle's mechanism-not-event test: a > write-up whose MECHANISM can recur is a hazard wearing a date and keeps its pointer). 30 stay > dropped, all closed events. 194 files in this dir have no index line β€” 153 orphaned by EARLIER > passes and never mechanism-tested. Grep this dir; do not assume the index is the population. > 2026-08-04: gate/test craft SPLIT OUT VERBATIM to GATE-TEST-INDEX.md (23.3KB -> 14.2KB, 29 > entries MOVED, zero dropped, diff-verified byte-identical). Growth is handled by SPLITTING a > whole section out to a πŸ”Ž sub-index, never by dropping entries β€” the ~17KB nag is refused. > 2026-08-19: judgement rules SPLIT OUT VERBATIM to JUDGEMENT-INDEX.md by the same method > (21.9KB -> 13.6KB, 24 entries MOVED, zero dropped, byte-identity asserted in the move script, > not eyeballed). The nag fired again mid-split and was refused again: it asks for compaction, > and compaction is what cost this index 30 pointers in 2026-08-03. > 2026-08-22: change-shape traps SPLIT OUT VERBATIM to CHANGE-SHAPE-INDEX.md, same method (25,938 > -> 20,331 bytes, 12 entries MOVED, zero dropped, byte-identity asserted per line in the move > script). ⚠ MEASURED, not assumed: the index was ALREADY OVER its 24,436-byte read limit BEFORE > that session's one-line addition β€” the tail was being silently dropped at the time, so "my edit > caused it" was the flattering read and it was wrong. SIDE EFFECT DECLARED: the rewrite also > normalized this file CRLF -> LF (84 CRLF -> 0); entry CONTENT is byte-identical, the line > TERMINATORS are not. There is no single house form here β€” GATE-TEST-INDEX is CRLF, HAZARD-INDEX is LF, > JUDGEMENT-INDEX is CRLF (that clause measured WRONG, corrected 2026-08-29) β€” so it was left LF rather than restored. > 2026-08-29: roles/scope/comms SPLIT OUT VERBATIM to COMMS-ROLES-INDEX.md, same method (23,862 > -> 18,742 bytes, 11 entries MOVED, zero dropped; the move script asserted byte identity of the > moved block AND of both untouched regions, then re-found every moved line with grep -Fx in the > sub-index). Headroom was under 600 bytes before this β€” the tail was one entry from dropping. > 2026-08-30: judgement entries accumulated since the 08-19 split MOVED VERBATIM into > JUDGEMENT-INDEX.md, same method (24,206 -> 17,002 bytes, 10 entries MOVED, zero dropped, > byte identity asserted per line in the move script; both files measured LF, 0 CRLF, > so no terminator side-effect). Headroom was ~230 bytes before this β€” the tail was > one entry from dropping. The compaction nag remains refused. > 2026-09-07: record-hygiene entries SPLIT OUT VERBATIM to RECORD-HYGIENE-INDEX.md, same method > (23,434 -> 19,484 bytes, 8 entries MOVED, zero dropped; prefix/suffix/moved-block byte identity > asserted in the move script, line terminators copied as bytes). Headroom was ~1,000 bytes. > 2026-09-08: the nine v0.61.0..v0.68.0 ARC entries MOVED VERBATIM to ACTIVE-WORK-INDEX.md (#arcs-moved-2026-09-08), > same method (23,737 -> 20,246 bytes, 9 entries MOVED, zero dropped; every moved line re-found verbatim in the > sub-index and the prefix region asserted identical in the move script). Headroom was ~700 bytes. > 2026-09-08 (later): today's gate-craft entries MOVED VERBATIM to GATE-TEST-INDEX.md (#moved-2026-09-08), same method > (moved lines re-found verbatim, prefix and suffix regions asserted identical). Headroom was ~1.5 KB. > 2026-09-09: the three RELEASE entries MOVED VERBATIM into RELEASE-INDEX.md, same method > (23,830 -> 22,495 bytes; 3 entries MOVED, zero dropped; the move script RECONSTRUCTED the > original file from the kept lines plus the moved ones and asserted byte identity before > writing, then re-found each moved line verbatim in the sub-index and confirmed its absence > here; moved-byte conservation checked both files). Headroom was ~600 bytes before this -- > the tail, which is Active work, was one entry from dropping silently. Compaction refused again. > 2026-09-09: the 14 trap entries that had accumulated under Active work MOVED VERBATIM to ACTIVE-WORK-INDEX.md > (#moved-2026-09-09), same method (23,423 -> 19,545 bytes, zero dropped; prefix identity + per-line re-find asserted in the > move script; both files LF, 0 CR). Headroom was ~1,000 bytes. The compaction nag remains refused. > 2026-09-09 (later, doyle): 8 judgement entries MOVED VERBATIM to JUDGEMENT-INDEX.md (#moved-2026-09-09) and 4 gate entries > to GATE-TEST-INDEX.md (#moved-2026-09-09), same method (22,594 -> 18,988 bytes, 12 MOVED, zero dropped; the move script > REBUILT the original by index from kept + moved lines and asserted byte identity before writing, then re-found each moved > line once in its sub-index). GATE-TEST-INDEX is CRLF, so its appended block carries CRLF terminators with byte-identical > CONTENT; a `grep -c $'\r'` had printed a false 0 on that file minutes earlier -- count CR bytes in python, not with a > shell grep. Headroom was ~1.8 KB (deployah's measurement). The compaction nag remains refused. - πŸ”Ž [HAZARD-INDEX.md](HAZARD-INDEX.md) β€” defect/mechanism sub-index, read when HUNTING a symptom: attach wedges, apply/adapter defects, Windows traps, rig traps, + a RETIRED list you must NOT act on. This file = RULES you obey; that = MECHANISMS you consult. Neither is the population. ## Judgement rules (binding) - [8 judgement entries banked 2026-09-06..09-09](JUDGEMENT-INDEX.md#moved-2026-09-09) MOVED VERBATIM 2026-09-09 (byte identity asserted per line in the move script; zero dropped): sever-the-branch, success-token-matches-panic, compound-spelling grep, Length-sum hardlinks, one-value column, stamp-from-previous-clock, out-of-usage peer, claim-before-check. - πŸ”Ž [JUDGEMENT-INDEX.md](JUDGEMENT-INDEX.md) β€” the FULL judgement-rules sub-index (measurement discipline, claim hygiene, falsifiability, absence/silence traps, figure provenance), split out 2026-08-19 against the read-limit cliff (24 entries) + SECOND verbatim move 2026-08-30 (10 more, incl. every truncation-pipe/meter/frontier rule accumulated since; zero dropped either time). Read it before reasoning from a measurement or reporting a figure. ## Record hygiene - [check-ignore with a TRAILING SLASH mints a false ignored; .spt/ is NOT ignored](check-ignore-on-a-bare-directory-is-not-a-probe.md) ⭐ 2026-09-09 hertz+doyle+todlando: `check-ignore -v .spt/` (slash) rc=0 citing BLANK .gitignore:20, empty pattern field = the tell; three agents called .spt/ gitignored; `.spt/preserved/` (golden evidence + 325 MB xtask) is untracked-unignored, so `git add -A` at root stages it. CONTROLS re-measured 4/4: `.worktrees/` and `target/` answer the SAME slash spelling rc=0 with a POPULATED pattern, so ALL FOUR exit 0 and the EXIT CODE SEPARATES NOTHING β€” the pattern field is the discriminator, a path INSIDE the dir only the cross-check; stage by PATH until the ignore lane lands. - [a git refusal HALTS; a tree answers git status before it dies](a-git-refusal-halts-the-script-and-a-tree-answers-git-status-before-it-dies.md) todlando 2026-09-08: worktree remove refused (rust-analyzer), script fell to rm -rf, no status read first. - πŸ”Ž [RECORD-HYGIENE-INDEX.md](RECORD-HYGIENE-INDEX.md) β€” the FULL record-hygiene sub-index (preservation-before-reap, scratchpad-is-not-preservation, commune/echo/drop mechanics, shared-file clobber, resume re-ground faces, ER ledger ruling), split out 2026-09-07 against the read-limit cliff; 8 entries VERBATIM, zero dropped, byte identity asserted per region in the move script. Read it BEFORE writing a commune, a shared memory file, a preservation claim, or a correction. ## Gate & test craft - [a hand-tracked branch is a snapshot of the last assembly it was moved to](a-hand-tracked-branch-is-a-snapshot-of-the-last-assembly-it-was-moved-to.md) ⭐ 2026-09-09 r3: r3-gate-head froze at assembly 3; a reword on a detached HEAD kept the tree, left the name; pushing the NAME = golden at the 26.7% tree with every gate green about it. Push the OBJECT `<40sha>:refs/heads/golden/`, verify ls-remote + tree, record both before the run id; `branch --contains` empty is a finding. - [4 gate entries banked 2026-09-09](GATE-TEST-INDEX.md#moved-2026-09-09) MOVED VERBATIM 2026-09-09 (same method; content byte-identical, terminators CRLF to match that file; zero dropped): workflow-graph job scope, probe-the-event-path, gh run list --commit full sha, run-level conclusion vs attempt. - [gate-craft rules banked 2026-09-08 (#272 golden r1 respin day)](GATE-TEST-INDEX.md#moved-2026-09-08) MOVED VERBATIM (7 entries: consumer crates, Summary-only counts, sentinel exit files, blind censuses, job-list-early, holders-as-build-red, sample-line census); byte identity asserted. - πŸ”Ž [GATE-TEST-INDEX.md](GATE-TEST-INDEX.md) β€” full sub-index (rig construction, gate population, filters reading as absent, nextest/cargo traps, pipe-verdict traps, two-daemon rigs, gh/CI polling), split out 2026-08-04 against read-limit truncation; 29 entries VERBATIM, none dropped. Read it BEFORE authoring, changing, or running any gate/test/rig β€” the craft is not in this file. - [treqs exit 2 = an UNPARSEABLE registry](traceable-exit-2-is-an-unparseable-registry.md) ⭐⭐ exit 1 = coverage miss, exit 2 = `traceable-reqs.toml` did not PARSE, so nothing was checked and every reading since the bad edit is vacuous. Mine 2026-08-25: a real `"` inside a REQ title (a TOML basic string) killed the parse at that column β€” file greps fine, editor looks fine, every other battery leg green because nothing else reads it. Read the CODE, not "treqs failed"; re-run `check` immediately after any hand-edit; keep `"` out of titles. - [a stale TARGET makes a check pass HARDER, not fail](a-stale-target-makes-a-check-pass-harder-not-fail.md) ⭐⭐ deployah 2026-09-09, SEVEN faces in one arc: dead-run gate default; CASCADE ff/tag action lines; my own audit regex (indented cmds missed, then Unmatched-paren while || echo NONE printed the all-clear); an inherited permit arm whose `gh run rerun` binds the RUN’s sha, not `-Sha`; a BRANCH NAME on a re-committed chain with IDENTICAL trees (tree match != commit identity); a WAKE armed pre-RIDE ordering work already done; and my own verdict reader shelling to an ABSENT jq, whose empty output printed FAIL and manufactured a FALSE RED (a false red costs a gater a hunt). Targets are mandatory params; CLASSIFY hits action-vs-history; check the extractor’s EXIT CODE; build the dry-run switch so the PERMIT arm is provable too. - [OPEN the sub-index or the split was worthless](open-the-subindex-before-running-a-gate.md) ⭐⭐ ran a whole golden gate without opening GATE-TEST-INDEX, hit a trap it covers ⭐⭐ WITH the command, and thanked doyle for handing back craft I had filed myself 2026-08-04. A missing memory is not experienced as missing β€” it is experienced as the TOOL having a limitation, and I reported that false constraint to a gater. Trigger is the ACT: first touch of a gate/rig/test-filter/CI log, open it before the first command. ## Boxes / CI / infra - [a PUSH TO MAIN runs the full thin lane on BOTH runners](a-push-to-main-runs-the-full-thin-lane-on-both-runners.md) ⭐ doyle 2026-09-09: docs-only skip is PR-only (ci.yml classify :49); my two ff pushes ran 40-min Windows unit jobs through hertz's timing window after I promised 'kitsubito only'. Read the PUSH run's jobs, not the PR's. - [Defender first-touch tax on fresh test binaries](defender-first-touch-tax-on-fresh-test-binaries.md) ⭐ 2026-09-09 (todlando's hypothesis, doyle measured): fresh 35 MB exe 1.0-2.1 s first run vs 20-260 ms warm, MsMpEng 68% on an idle box; Phase A +21% over 3 attempts at ONE sha + rotating single Phase B victim = random-victim env cause; exclusion list UNREADABLE unelevated (operator ask, never apply). - [Windows runner firewall drops COLD inbound to rule-less test exes](windows-runner-firewall-drops-cold-inbound-to-rule-less-test-exes.md) ⭐ 2026-09-08: 900 s "peer unresponsive" on B, per-cell-identity fix in the sha, 0/3 vs 3/3 probe; three helper-stall faces = one cause; probe both directions before any product word; fix is an elevated operator rule (IR-82). - [pool-release REBUILDS xtask into the pool you just reaped](pool-release-rebuilds-xtask-into-the-pool-you-just-reaped.md) hertz 2026-09-08: 2.8 GB back in hertz-lane4, nothing said; release with a PREBUILT xtask.exe from another pool, Test-Path the target after any reap. - [link exit 0xc0000142 under load reads as a toolchain repair](link-exit-0xc0000142-under-load-reads-as-a-toolchain-repair.md) todlando 2026-09-08 x2: DLL_INIT_FAILED = contention, leg VOID; census beside it, re-run alone, never repair VS. - [a Length-sum census OVERSTATES a cargo pool](a-length-sum-census-overstates-a-cargo-pool.md) 2026-09-08: du dedups hardlinks, `Length` sums every entry β€” 15.1% over on one pool, arithmetic closes to 0.03%; census RANKS pools, never predicts reclaim. - πŸ”Ž [CI-INFRA-INDEX.md](CI-INFRA-INDEX.md) β€” full sub-index (runners, pools, rigs, teardown, box traps), split out 2026-08-03 against read-limit truncation; entries VERBATIM, none dropped. ## Release - πŸ”Ž [RELEASE-INDEX.md](RELEASE-INDEX.md) β€” full sub-index (ledger + latest published version, tag-window holds, milestone/parity rulings, docs-surface traps), split out 2026-08-04 against read-limit truncation; entries VERBATIM, none dropped. Latest cut lives there, not here β€” read it before any release, tag, or milestone close. ## Roles, scope, comms - [spt shell send takes an ARG, not stdin](spt-shell-send-takes-arg-not-stdin.md) ⭐ re-hit 2026-09-09: a piped comment printed USAGE and nothing fired; with --file the pipe is SILENTLY dropped and the file stages; a comment's --file ATTACHES. Payload = one quoted argument with real newlines. `spt send` is the opposite (stdin). - [alchemy --file ALWAYS stages; create body caps at 1600](alchemy-file-always-stages-and-create-body-caps-at-1600.md) 2026-09-08 #289: verb+title+short body as TEXT, `--attach` turns staged files into attachments, no unstage verb. - πŸ”Ž [COMMS-ROLES-INDEX.md](COMMS-ROLES-INDEX.md) β€” the FULL roles/scope/comms sub-index (agent roles, R&D + subnet population rulings, alchemy filing, relay-is-not-the-gater's-word, credential-holder boundary, every `spt send` / commune / perch mechanic), split out 2026-08-29 against the read-limit cliff; 11 entries VERBATIM, zero dropped, byte identity asserted per line in the move script. Read it BEFORE sending to a peer, relaying testimony, or reasoning about who owns what. ## Architecture / boundary - [harness boundary](spt-core-harness-boundary-and-grounding.md) BINDING: never cater to a harness Β· [adapter glue-model](adapter-glue-model-boundary.md) manifest + binary only Β· [unbounded brain carrier](unbounded-brain-carrier-cannot-be-bounded.md) caller-side budget is a NO-OP -- 3rd instance 09-09: RULED against this line while it was loaded; fix the CONSTRUCTOR. - [mints ride build PRs](registry-mints-ride-build-prs.md) Β· [adapter impl triage](adapter-impl-question-triage.md) fix the PUBLIC contract Β· [adapter-agnostic resolution](harness-adapter-agnostic-resolution.md) Β· [plugin name](sptc-plugin-name-ruling.md) Β· [--release archive](adapter-add-release-archive.md) Β· [tips β†’ published docs](adapter-tips-published-docs.md) Β· [cplugs publish](cplugs-publish-mechanics.md). - [broker is state anchor](broker-is-daemon-state-anchor.md) Β· [QUIC deadline](v083-broker-quic-deadline.md) Β· [pump IPC deadline](pump-ipc-deadline-fix.md) Β· [boot-race self-heal](boot-race-self-heal.md) Β· [EVENT envelope](event-envelope-reply-to-removal.md) Β· [F-007 relay](f007-live-relay-acceptance.md). ## Change-shape traps - [a barrier cannot ride a carrier its sender outlives](a-barrier-cannot-ride-a-carrier-its-sender-outlives.md) ⭐ 2026-09-08: swapped a retired SYNCHRONOUS file push for a replicated row; A wrote the barrier and exited, B dialled a gone endpoint for its whole window (A exit 0, B exit 100). Ask how long the sender lives after the call; a barrier needs the receiver's own answer. Reusing a mechanism that works elsewhere in the SAME file is not evidence it works here. - [a fallback that fires ONLY in release is untestable by construction](a-fallback-that-fires-only-in-release-is-untestable-by-construction.md) ⭐ doyle 2026-08-29: `debug_assert` + carry-on puts the REAL behaviour in the one build no assert watches and no test looks at. Pick a tolerant branch that PRESERVES the invariant (escape/clamp/truncate-with-marker), never one that abandons it, and make the fallback its own breadcrumb. - πŸ”Ž [CHANGE-SHAPE-INDEX.md](CHANGE-SHAPE-INDEX.md) β€” the FULL change-shape-trap sub-index (narrowing an unconditional call, censusing enforcers AND staters, per-line suppression, authored-but-unlanded text, reading source at the measured sha, bare `cd`, sequenced edits, placing a correction), split out 2026-08-22 against the read-limit cliff; 12 entries VERBATIM, zero dropped. Read it BEFORE shaping any change or correction. - [backticks in a double-quoted message body EXECUTE](backticks-in-a-double-quoted-message-body-execute.md) ⭐⭐ 2026-09-06: printf "…`cargo build`…" | spt send ran a 2-min cold compile beside CI on this box, one message after I said the collision was avoided. Compose peer messages via a QUOTED heredoc to a file; census cargo by cwd/parent after any shell timeout and kill only your own. - [a stopped local ssh does NOT stop its remote command](stopped-local-ssh-does-not-stop-its-remote-command.md) ⭐ 2026-09-06: TaskStop + relaunch = TWO full nextests in one pool + one nextest.raw (two Summary lines, three forged load reds, a map that cited only the first). `grep -c Summary` before any FAIL read; two = VOID. Kill by remote pid; lockfile per output dir. - [Windows lock contention is NOT WouldBlock](windows-lock-contention-is-not-wouldblock.md) ⭐ contended fs2 `try_lock` returns raw OS 33 / `ErrorKind::Uncategorized`; matching on the KIND made every contended acquire fail instantly β€” the exact fail-fast the lock replaced. Compare `raw_os_error()` against `fs2::lock_contended_error()`. General: `ErrorKind` is a portability abstraction and `Uncategorized` is where real OS errors land, so `match e.kind()` over a platform failure is a guess. ## Runtime defects - [a daemon restart strands persistent shells β€” boot instant is MACHINE boot](a-daemon-restart-strands-persistent-shells-boot-instant-is-machine-boot.md) ⭐ 2026-09-08: every self-update leaves PACER-0/alchemy-N offline for good (restore discriminant reads GetTickCount64 boot, a daemon restart = force-kill arm); 27 h silent pacer. After any restart: `spt shell list`, relink your own, tell peers. releases#287. - [tail-window read_to_string mints a FALSE ZERO](tail-window-read-to-string-mints-a-false-zero.md) ⭐⭐ 2026-09-06: io-events seq restarted at 1 past 256KB (seek mid-codepoint β†’ InvalidData β†’ 0 β†’ seq 1; 9/9 on my log, 4 perches); adapters' --after polls went BLIND or replayed old communes β†’ wake refire. Count DISTINCT seqs first; test the direction the symptom came from. - πŸ”Ž [HAZARD-INDEX.md](HAZARD-INDEX.md#runtime-defects) β€” the FULL runtime-defect entries (TLS dtors, rest_state, identity-by-hash, Windows liveness/pid reuse, pump + wedge mechanisms, psyche failure scope, UNBOUND unwedge, spt home), MOVED there 2026-08-25 by the documented method when this file crossed its read limit again; 8 entries VERBATIM, zero dropped, byte identity asserted per line in the move script. They sit beside the mechanism write-ups they point at, which is where a symptom hunt already looks. ## Active work / project state - [`api listen --once` gives a live message ONE 500 ms window](api-listen-once-gives-a-live-message-one-500ms-window.md) 2026-09-08 golden r1 fourth red: rig race, lane 4 hertz; open the assertion, not the printed context. - [helper-stall = shared A identity, stale path: CONFIRMED](twohost-web-helper-stall-shared-a-identity-stale-path.md) 2026-09-08 63.4->3.4 s one variable; fix = hertz thin lane, register QUESTION at release close. - πŸ”Ž [ACTIVE-WORK-INDEX.md](ACTIVE-WORK-INDEX.md) β€” the FULL active-work sub-index, split out 2026-08-04 against the read-limit cliff (this section sat last and would drop first, reading as "no active work"; entries VERBATIM, zero pointers dropped). Includes #145 LANDED @`4b37512`; the four IR-30 instrument lanes LANDED v0.54.0/v0.55.0 (measured 2026-08-25 β€” earlier "riding next batch" here was stale). State decays fastest β€” re-ground before acting. - [v0.61.0..v0.68.0 arc entries](ACTIVE-WORK-INDEX.md#arcs-moved-2026-09-08) MOVED VERBATIM 2026-09-08 (9 entries, byte identity asserted); v0.68.0 = #272 WEBSERVE, golden r1 RED 2026-09-08, respin in flight. - [14 trap entries accumulated 2026-09-06..09-08](ACTIVE-WORK-INDEX.md#moved-2026-09-09) MOVED VERBATIM 2026-09-09 (byte identity asserted per line in the move script; zero dropped): api listen --once window, helper-stall CONFIRMED stay above; the rest = alchemy `--` flags, Bash 10-min cap, stopped ssh, perch-inherited identity, pool vs disk floor, kitsubito launch traps, TaskOutput, ephemeral-ports, tombstone, rig fetch port, gh run view --log, tag-shaped prose, curl -w partial, multi-target shortform.