# Infra register — CI / build-pipeline debt

Operator-ruled 2026-08-02: infrastructure and CI-pipeline work items live HERE, not on the
`spt-bs-releases` board. The board carries product surface the operator triages; this register
carries what the gater triages. **Mandate: doyle sweeps this file at every milestone intake and
every release close, and composes ripe entries into waves/milestone riders.** An entry leaves
this file only by being built (link the lane) or being retired with a stated reason.

Entry format: status · origin · what/why · trigger condition (what makes it ripe) · size guess.

Last sweep: **2026-09-11, v0.69.0 RELEASE CLOSE — FULL REGISTER**, source `e5a2fed9`.
All **97 entries (IR-1–97, including headingless IR-31)** read in two disjoint ranges; audit
population checked for missing/duplicate IDs (97 rows, 97 unique, zero missing). Per-entry
trigger and disposition evidence: `.spt/preserved/infra-close069-20260911/audit.json`.
UNKNOWN means no qualifying event established, not a disproved trigger or a discharged debt.

- **Release facts, not a blanket green:** v0.69.0 at `16df0e41`, counter **105**, Latest,
  11 assets; #294 and all eight members DONE. Explicit operator SHIP overrode the known
  sync-cell red at candidate `a9e786b2`; the release neither classifies nor closes that defect.
  Source closeout: releases#294 comment **5628538587**. The scoped four-package `--lib` battery
  passed **121/121**; push CI **34550282074** passed **3167 Windows units**, then failed the
  END disk floor (**15,360,114,688 < 34,359,738,368 bytes**). Release build **34550300527**
  succeeded. Earlier PR unit-red logs remain unavailable/cause-unclassified. These are separate
  verdict objects; no pass substitutes for a red, missing specimen, or unexecuted acceptance.
- **Close already-built work, retain residuals:** IR-1/4 stale unlanded headers reconciled to
  their landed rider and recorded golden exercise. IR-66 CLOSED using its existing two-platform
  gates and WEBSERVE satisfaction ruling. IR-73 CLOSED: eight post-checkout sites plus both
  docs-floor rereads are present; IR-86 retains sizing/dependency debt. Other established
  BUILT/RETIRED decisions stand. IR-18's deferred consolidation and IR-53/62's narrower
  touch-triggered siblings remain carried; closing their built halves does not erase those.
- **Do not redispatch existing implementations:** IR-26 build-side identity is committed,
  but claim-time observation and old-reader issues remain; IR-29's first fix landed, later
  rung faces remain; IR-33's 16 MiB CLI stack exists, acceptance/margin reconciliation remains.
  IR-57 `pick-audit`, IR-59 `disk-floor`, and IR-46 workflow floor tokens exist; residual adoption
  and receipt reconciliation are the work. IR-69's original product lane landed; #243 residuals
  remain. IR-83's universal LAN-only prescription is superseded by IR-89's layer-specific box
  proof. IR-89's next-golden trigger has fired; exact step acceptance still needs reconciliation,
  not a second guard implementation or renewed operator permission.
- **IR-92 stays OPEN:** core#215 shipped the documentation/register rider, NOT the product
  remedy; core#217 is the separate brainread audit. `try_spt_hosted_inject` still lacks the
  MSG_IN publisher. Deployah corrected comment **5628532753** in place and confirmed readback.
  Inject coverage, relay publication ordering and per-msg-id exact-once are distinct obligations.
- **Next-intake composition, owned by doyle until accepted:** hertz's driver/workflow package
  takes IR-31/46/59/60/76/86/87/90/97: aggregate capacity, truthful producer status, existing
  quiet-window contract, independent rendezvous clocks, and mandatory between-run identity
  census. IR-88 adopts the already-proven prebuilt release-before-delete recipe; IR-64 remains
  a separate operator capacity decision. No new loaded comparison before these prerequisites.
  Hertz's lifecycle package retains IR-7/17/20/22/25/34/35/55/63/79/80; guard adoption must
  distinguish unwinding from hard process death. IR-74/75 ride the next Linux box audit.
  IR-85/95/96 are scoped diagnostic continuation, NOT budget widening or a load/disk diagnosis.
  Todlando owns product-side IR-81/82/92 composition; #285's completion did not build IR-82's
  predecessor record. Both builders are offline: existing briefs are delivered, unacknowledged,
  and **not executing**. No board mutation or new run authorization is implied.
- **Small seam riders remain explicit:** next tooling intake weighs IR-5/6/10/11/32/37/47/58/94
  (IR-37 upstream release is not downstream adoption: golden still requests 0.2.0).
  IR-93 remains a separate symbol-packaging decision before a release-workflow rider, not a
  property proven by a successful release build. All other open entries retain their recorded
  trigger, residual, and owner where named; the complete audit records each, not a sampled set.
- **Cleanup is mitigation, not closure:** 38 clean merged worktrees and classified obsolete
  artifacts removed; dirty/unmerged/retained evidence preserved. Net free-space change
  **4,532,350,976 bytes**, ending **83,382,472,704 bytes** (concurrent-activity caveat).
  `.spt/cleanup-20260911.json` is the receipt. Root-target and CI-debug reclaims are separate
  earlier measurements, not additions to that net. IR-14/26/27/49 remain structurally OPEN.

Prior sweep: 2026-09-06, v0.67.1 RELEASE CLOSE + WEBSERVE (#272) INTAKE (one delta pass; the 08-30
full pass stands) — shipped counter 103, tag == main == tested `04e32c8c`, golden 34017906638 att4
9/9 on a QUIET box after three reds (:473 attach_link structural test defect; wtlock :147 under
builder load; resident_service_e2e :664 ledgered leak row, 3rd occurrence) — the quiet-box arm is
IR-76's origin. Enumeration by a read-only subagent into `REGISTER-SWEEP-0671-DRAFT.md` (75
entries, 10 trigger-text candidates; IR-31 has NO `###` heading — its body sits under IR-30's,
flagged, not normalized). Rulings: **IR-46 trigger FIRED and was MISSED** — `golden.yml` was
touched by `04e32c8c` itself (2-line HEAVY reclass on the respin) and no remedy was weighed; a
respin edit under a pre-registered hard stop is not a remedy window, so the entry gains that datum
and is COMPOSED forward. **Composed: the floor trio IR-46 + IR-59 (log-the-floor half) + IR-73
(8 literal-first sites) as ONE hertz workflow rider on WEBSERVE** (`ci.yml`/`golden.yml`/
`release.yml`, thin PR off the golden path, before the WEBSERVE golden head so that head runs
under it); **IR-59's log-the-floor line ALSO rides IR-76's three-arm pre-flight on W0's driver
template** (todlando authors; free space recorded beside the floor check). **IR-66 residual (two
first-chunk-needle members) = hertz WEBSERVE test rider** (two one-line edits). **IR-12 residual =
W3 drift-gate rider** (hertz already holds W3's drift-gate riders). IR-67 satisfied at this intake
by construction (`--no-fail-fast` in the W0 driver template; todlando's 2026-09-06 correction).
IR-34 unchanged, lane-linked to hertz's `test/attach-relink-barrier` @`b976cc09` (thin PR queued
behind the release runs). NOT fired: IR-3 (a new stream family is neither endpoint lifecycle nor
daemon supervision), IR-48, IR-52 (DOCS-NITS item 2 is a parent-option placement filing, not a
deep-help divergence — adjacent, noted), IR-64 (att4 did not die at preflight; no operator ruling).
Board mints this arc: #277 (io-events seq reset), #278 (adapter update never prunes strings/),
#279 (ER_HOSTED_PROBE on every bind), #280 (MSG_IN never published on the relay edge). Design
rulings on the grill branch: ADR-0056 Am.1 (router precedence), ADR-0057 Am.1 (served root =
`adapters/<adapter>/web/`), ADR-0058 Am.1 (#17 auto-serve, reference-served). No entries retired.

Prior sweep: 2026-08-30, NOW-SIGNAL (#23) / v0.67.0 RELEASE CLOSE — shipped counter 102, tag ==
main-at-tag == tested `da71b785`, 9/9 golden att2 (att1 sole red = FLAKE-LEDGER :664
teardown-leak row, ruled ledgered-class at triage — signature predates the diff — rerun
non-vacuity proven by cell re-execution; ledger row +1 with new data, stays OPEN; hertz
IR-34/35 cluster strengthened). Same-day second sweep, so most composition state is the
morning's; deltas only: IR-59 gained the SEVENTH face (parallel-lane fill rate: 236.6 GB /
3.5 h across four wave pools drove the box to 0.01 GB mid-close; per-wave pool reaping rule).
IR-12 gained the stale-binary kin note (xtask reference-drift arm reads the ON-DISK spt binary;
structural remedy = the now-mandatory workspace-bins prebuild leg, adopted this arc after it
also caught W2's spacerun red). IR-63's conhost litter REPRODUCED on cue: 14 fresh CWD pins on
the four party trees at the same `crates/spt-daemon` relative path, killed by pid via the PEB
probe, all four worktrees then removed FIRST TRY — the pin-check-first party rule held
(+58.2 GB; earlier emergency reap of the same wave's finished-lane targets +186.6 GB).
Test-craft banked to memory, not entries: `cargo test -- <bare> --exact` runs NOTHING and exits
0 (todlando's structural fix: names carry the filter token); Win32_Process CommandLine filters
CANNOT answer a CWD-pin question (todlando's false-positive self-catch). Board mints this arc:
#244/#246/#247/#254 (BACKLOG). #16/#17 discharged drops (detach + EVAL). IR-73's ci.yml/
release.yml floor-site reorders did NOT ride this arc's workflow commits — still owed, next
touch. No entries retired.

Prior sweep: 2026-08-30, SEMAPHORE (#242) / v0.66.0 RELEASE CLOSE — shipped counter 101, tag ==
main == tested `d931dd63`, 9/9 at one sha across two attempts; full-register pass executed from
`REGISTER-SWEEP-242-DRAFT.md` (72 entries enumerated pre-golden, load-bearing claims re-measured
in-tree). Rulings: IR-69 close-out re-census RAN and FOUND the entry's own predicted truncation
blind spot LIVE (338 cli.rs + 2 main.rs shipping sites never censused; addendum on the entry,
stays OPEN; residual conversion + generator fix + seam enforcement = releases#243, scoping
reconciled on the issue; common-word matcher RULED a separate hertz test-side rider). IR-17
three corrections by replacement (08-03 kitsubito "empty stderr" = METER ARTIFACT — panel
capture postdates the specimen by 16 days; kitsubito family member CLOSED under the RCA-242
exe-hash-on-ready-path mechanism, behaviour-change request minted as releases#244; Windows
specimen + hfenduleam sub-observation stay the live population). Daemon-leak cluster
IR-7/17/20/34/35/63 LANE-LINKED to hertz's queued fixup lane (briefs in his spool cite the entry
ids). IR-57 first-real-assembly use appended (ASM-241: 6 picks, 5 MATCH / 1 LOSS reconciled
byte-for-byte to the deliberate resolution; its earlier "figure correction rides next batch"
note was STALE — the correction landed inline 2026-08-29, retired here). IR-46 gained the #242
golden additions (per-job floor instants; the `/runs/<id>/jobs` run_attempt trap with
`started_at` discriminator + `/attempts/N/jobs` authority; raw-bytes rerun preflight;
non-vacuous rerun check). IR-59 gained the SIXTH face (r4 LNK1318 at the job's internal
low-water; within-job floor re-read rides the next workflow commit; box ~51 GB non-recovering
consumption → audit slot). FILED: IR-73 (ci.yml/release.yml literal-first floor sites off the
golden path, 8 sites), IR-74 (kitsubito 21,643 /tmp endpoint homes, hertz's measurement), IR-75
(kitsubito treqs 127 vacuous leg — install-or-drop; IR-37 deliberately NOT reopened, different
surface). Composed: IR-14/26/27/49 as ONE between-milestone pool/worktree audit slot (window
open now); IR-11 + IR-33(a) as next-intake small riders; IR-59's log-the-floor half + IR-57's
scripted audit stand as the next intake's tooling pair. IR-54 evidence noted: the #242 cut's
unshaped-head intake miss (self-caught by deployah, shape-on-top `e4f52047`, 8th consecutive
shape-inside-candidate) is another construction-not-discipline datum. No entries retired.

Prior sweep: 2026-08-27, IO-PARSER (#22) INTAKE (wave map: `IO-PARSER-22-JIT.md` + #22 comment).
Rulings: IR-66 COMPOSED as the parallel hertz rider (the two attach-cell later-needle treatments,
attach.rs:561/:672 — the "rides next intake" note comes due here). IR-52 conditional rider
CARRIED FORWARD on this milestone's docs lane, same terms as WAX-SEAL (depth fix lands iff the
lane touches the docs-site CLI reference generator, else stays open). IR-67 COMPOSED as JIT gate
discipline (no wave battery leans on a `-p spt --bins` leg as integration coverage); the entry
stays open until its named construction fix. IR-55 stays armed with hertz; IR-6 LOCKSMITH
composition still unreported, stays; IR-2 trigger unevaluated this sweep (teardown just cleared
the unlanded-lane field — re-check next sweep). No entries retired; none filed.

Prior sweep: 2026-08-23, WAX-SEAL (#21) INTAKE (wave map: `WAX-SEAL-21-JIT.md` + #21 comment
5390092115). Rulings: IR-52 COMPOSED as a CONDITIONAL W4 rider on the wax-seal docs lane —
the milestone mints new nested `spt seal` CLI verbs, exactly the shallow-render class the entry
names; the depth fix lands iff that lane touches the docs-site CLI reference generator, else the
entry stays open here. IR-2 trigger NOT met (todlando's PR set parked unlanded for the next
golden chain). IR-55 stays ARMED-FOR-CAPTURE with hertz. IR-6 conditional composition from
LOCKSMITH still unreported — stays open. IR-56/57/58/59/60/61 are discipline/craft entries or
await their named triggers; IR-62 is hertz-class test/rig work, unscheduled. No entries retired;
none filed.

Prior sweep: 2026-08-19, CONCIERGE (#183) INTAKE (wave map: `CONCIERGE-183-JIT.md` + #183
comment 5347768797) — rows read from the LOCAL register stack (`4799031→ecd640c→8d4c224`;
origin/main lacks IR-49/50/51 until the chain lands — absence ≠ not-filed). Rulings: IR-50
COMPOSED — dispatched to hertz same day (sink-path-helper-FIRST sequencing per the entry;
`engine_room_bringup_e2e.rs` excluded, its panel sites ride the gated #199 lane), with the
engineroom.rs:145 misnomer as a rider on the same lane. IR-47 = candidate co-rider IF this
chain touches golden.yml/ci-notify, else holds. IR-48 holds (next xtask parity-cell touch).
IR-49 holds (next poolguard touch or first landed-lane takeover request). IR-51 holds —
gated on #199 attribution; a net-off fix must NOT precede attribution. IR-2 trigger NOT met
(queued unlanded lanes exist). No entries retired; none filed — the intake window's product
finding (rc terminal-Exit omission, hertz RCA: proven invariant violation, load excluded
92/92, H2 candidate unconfirmed) routed to the BOARD as releases#201, the correct venue for
product surface.

Prior sweep: 2026-08-18, KEYSTONE (#182) INTAKE — the prior sweep's four composition rulings
EXECUTED (wave map: `KEYSTONE-182-JIT.md`, base main @`8248bc3`): (1) IR-9 pin lane DISPATCHED to
hertz (W0 item 1; interim kitsubito-clippy-authoritative dies when it lands). (2) IR-21 remedy
(2) + IR-39 vs `f24e732` DISPOSED: the branch is a BEACHHEAD (golden.yml prebuild step = the
prebuild-made-a-rule arm, ONE fail-fast site, one ledger row) — hertz rebases it off its
abandoned parent `b483699` (the id-collision draft; content landed renumbered as IR-46 @`8248bc3`)
and lands it in W0; the class remainder (IR-39's SHARED precondition helper + 24-site sibling_bin
sweep, the 33 cross-package build-edge expressions) folds into the test-hygiene lane. (3)
Test-hygiene family DECIDED-ACTIVATED as a dedicated hertz lane inside the KEYSTONE window,
sequenced after W0 (members: IR-13/23/36/37/38 + IR-21 clarity half + IR-39 helper +
twohost.rs:394 doc comment). (4) First-execution-cells discipline restated in the JIT's
golden-head step. Board members #84/#85 ride hertz's W0; #166/#57/#185 are todlando's W1. IR-46
id-collision RULED this intake (renumber-and-land, parallel issuance not authored disagreement;
deployah landed it @`8248bc3`). No new entries filed; no entries retired.

Prior sweep: 2026-08-19, NAMEPLATE (#181) / v0.56.0 RELEASE CLOSE — shipped c91 @`60d74ea`
(tag == golden-tested sha, run 32209922535; one respin, both first-golden reds ruled rig defects).
Filed IR-42 (pool-claim writes / build enforces — BUILT in this same commit, AGENTS.md line),
IR-43 (knock NoReply past its 30s carrier bound), IR-44 (perch-sentinel comment overclaims
preservation), IR-45 (twohost rig home premise; SETTLED + RETIRED
2026-08-19 — pump paths resolve under the per-run temp root, see the entry; #189 corrected on the
board, comment 5337519936). Two cycle findings ruled RUNBOOK-homed and
landed in this commit rather than as entries: the first-execution-cells intake question
(RELEASE-RUNBOOK golden-head intake — name the never-executed cells before the run) and
deployah's sweep-vs-cascade mechanism (RELEASE-RUNBOOK board step — under golden CI the cascade
is DRIVEN via `state <mref> acceptance`, never swept). ⚠ LABELLED HOLE — CLOSED UNDERIVABLE
(2026-08-19): the close commune's batch list named "alchemy create-races"; its content did not
survive the author's context reset and was not recoverable from #181, the JIT records, or memory.
Deployah answered the query: he ran ZERO create ops at the cut (could not have witnessed a create
race), a fresh probe over the milestone window shows no duplicate mints (the 4-issues-in-2s batch
mint is batching, not duplication), and the only surviving trace is doyle's own pre-reset message
naming the item as already-known — a pointer, not a sighting. Item DROPPED; the hole stands as
the record. Deployah's sweep-vs-cascade ship-path trap (#181 comment 5337402639, runbook-homed
above) is explicitly NOT this item's content — do not fold it in. Composition: IR-9's pin lane
(`rust-toolchain.toml` @ 1.96.0) goes to hertz AT KEYSTONE #182 INTAKE per the 2026-08-05
ruling; IR-21 remedy (2) + IR-39's precondition helper compose with hertz's standing
fixture-prebuild-hardening branch `f24e732` — disposition at the same intake; the test-hygiene
family (IR-13/23/36/37/38 + IR-21's clarity half) stays the dedicated post-batch lane candidate,
decision at intake; IR-29's proving run + IR-30's instrument lanes ride the next golden batch.
IR-2's trigger explicitly NOT met (queued unlanded lanes exist: IR-29/IR-30 instruments,
four-arm refusal eprintln, f24e732). IR-14 hygiene movement: `.worktrees/nameplate-asm-2bd36f1`
reaped this sweep (+66.98 GB by FS delta 120.53→187.51; claim `gate-w7-courtesy` base `fd3dc5a`
in main = finished lane; zero inbound reparse points) — stale-lane audit itself still open.

Prior sweep: 2026-08-05, LOCKSMITH tranche-2 (#141) CLOSE — golden run 30971976024 green on all 9
jobs, main ff'd to `0a25b77`, v0.55.0. IR-40 filed (stale-resume-brief + early-informant class).
IR-9's decision trigger FIRED 2026-08-05: doyle read the runner-account versions off this run's
`test` legs and RULED — pin in-repo via `rust-toolchain.toml` @ 1.96.0, kitsubito's clippy leg
authoritative in the interim; pin lane to hertz at next intake (see the entry). IR-41 filed the
same night (queued main run superseded without a record; runbook step 3 corrected in the same
commit). IR-1/IR-4's golden-only steps (link probe both boxes, toolchain
print both legs) had their FIRST EXERCISE here, discharging the "unexercised until a golden run"
caveat at the CI-RIDER LANE STATE foot section. IR-35's re-measure rode the batch (`c65b838`).
Owlery-noun thin lane SCOPED and dispatched to hertz for the next batch (class A only, two sites;
class B on-disk rename is an explicit non-goal — see IR-40's kin discipline for why the boundary is
written into the brief rather than left to judgement).

---

## OPEN

### IR-1 — Quiet predicate needs a network axis (tailscale RTT probe)
- **Status:** BUILT AND LANDED — reconciled at [[CI-RIDER LANE STATE]]; golden-only exercise
  recorded at the 2026-08-05 close (30971976024). Header corrected 2026-09-11. Originally
  carried by `bf8c4a2` → `REQ-CI-LINK-HEALTH-PROBE`, mapping CONFIRMED by builder hertz 2026-08-03
  (by content: tailscale ping ×5, med/max RTT rows into the bench ledger, three arms
  success/NO-REPLY/UNAVAILABLE, always exit 0 — instrument, not gate). NOTE `bf8c4a2` is NOT
  single-purpose: it also corrects the free-space preflight floor read
  (`REQ-CI-FREE-SPACE-PREFLIGHT`, the ci-runner-has-no-warm-target shape) — no 1:1 commit→IR map
  for this commit · **Origin:** golden/bench-wiring red triage 2026-08-02 (ex releases#126)
- **What/why:** the shared-runner quiet predicate (zero non-terminal runs + no local
  cargo/rustc/nextest by parent chain) is process-shaped; both axes passed on a box whose only
  link was degrading (321s for a 1s checkout, bidirectional 10s QUIC dial timeouts). A tailscale
  RTT probe to the peer box before two-host rendezvous, carried in the bench ledger, would have
  called run 30771155390's red in seconds. Evidence: the arm-1 count table (PUMP_PEER_FAIL
  a 0→3→0, b 8→22→8 across green/red/rerun).
- **Permanent, not stopgap:** operator-confirmed 2026-08-02 that kitsubito cannot be provided
  ethernet — wifi-only indefinitely, so the link cannot be hardened and the predicate must see
  link health.
- **Ripe when:** next CI-touching wave, or the next network-shaped golden red — whichever first.
- **Size:** small (one probe step + ledger row + predicate doc).
- **Composed:** LOCKSMITH (#132) CI-rider cluster, hertz thin lane — 2026-08-03. GREENLIT with
  #132 and **DISPATCHED to hertz 2026-08-03** (direct brief; the register is the spec, there is no
  board issue). Leaves the register only when the lane lands or the entry is retired.
- **FIRST FIELD USE, and it DISCRIMINATED (2026-08-04, golden 30873007187 attempt 1):** the probe
  (landed via the rider lane, riding `4b37512`) read 4–7ms RTT healthy on both twohost legs
  minutes before both legs redded — REFUTING the degraded-link read for that red and steering
  triage to the real mechanism (the [[IR-29]] serve-window race) instead of a link chase. The
  instrument's first catch was a correct NEGATIVE — exactly the call run 30771155390 needed and
  could not make.

### IR-2 — Settle the warm-runner CARGO_INCREMENTAL delta
- **Status:** RETIRED 2026-08-28, measurement run, verdict NO FLIP — incremental stays ON.
  hertz paired goldens at main fed965f8: ON run 33167693879 GREEN; OFF run 33172022108 RED
  (Windows input_ack_deadlock SetupFailed at a 3.0s IPC read deadline — the box-load family,
  discarded with the leg). Disk: OFF target 7.49 GB vs ON 11.40 GB = 3.91 GB / 34.3% saved
  (smaller than the entry's 5.65 GB cold figure). Timing NOT causal-quality: sequential runs in
  one persistent workspace let OFF inherit ON's cache (order contamination dominates the
  apparent OFF speedups); Windows build-spt-bin +3.8%, Linux -5.1%. Retire reasoning: the
  DECISION is answerable now — OFF produced no green golden, the timing question needs 4+
  counterbalanced fresh-cache windows to answer cleanly, and the disk motivation has weakened
  (box at ~148 GB free under the teardown discipline; the LNK1318 pressure era predates it).
  Runs/artifacts preserved on the record. Reopen only if runner disk pressure returns as a
  recurring floor-class red.
- **Was:** open · **Origin:** #103/#108 bench-wiring lane 2026-08-02 (ex releases#127)
- **What/why:** the #103 measurement (−29.8% wall, −5.65 GB/target, n=3) is COLD-build only.
  Golden's runner `_work` target persists warm, where incremental is exactly what keeps it cheap;
  CARGO_INCREMENTAL=0 was applied only to the genuine cold build (n1-gate pinned old-broker
  cache) + local rig recipes (docs/GOLDEN-CI.md). Open question: does incremental still pay on
  the warm runner, weighed against 5.65 GB/target on a box with LNK1318 free-space history?
- **Method (hertz):** one full golden each way on a quiet box, outside a milestone, compared
  per-step from the bench ledger.
- **Ripe when:** a quiet between-milestone window with no queued lanes (the measurement burns
  two golden windows).
- **Size:** medium (two proving runs + verdict + possible leg flips).

### IR-3 — Daemon-level guard: broker-net wakeup rate bounded across endpoint churn
- **Status:** open · **Origin:** releases#125 remediation, todlando REQ call 1 (ex releases#128)
- **What/why:** the swarm-discovery GC-spin burned two cores for two weeks visible only in a
  process table — no suite assertion sees the class. Wanted: a daemon-level assertion that
  broker-net workers stay quiescent across repeated endpoint create/destroy churn.
- **Design constraint (pre-ruled):** assert on WAKEUP RATE / voluntary ctxt-switch delta over
  the churn window, NOT %CPU — CPU thresholds flake under CI load; the defect signature
  (~100 Hz per orphan loop) is load-independent. Mint the REQ at activation.
- **Near-product:** this is runtime-defect visibility, the most product-adjacent entry here —
  a candidate rider on any daemon-lifecycle milestone.
- **Ripe when:** the next milestone touching spt-net endpoint lifecycle or daemon supervision.
- **Size:** medium (churn harness + counter plumbing + flake-safe assertion).

### IR-4 — Lock-pin guard + lock-procedure rule + toolchain print (three riders, one lane)
- **Status:** BUILT AND LANDED — `1275e47` / `49d4805` / `8ed006b` mapped and landed in the
  [[CI-RIDER LANE STATE]] reconciliation; golden toolchain-print exercise recorded at the
  2026-08-05 close (30971976024). Stale unlanded header corrected 2026-09-11. ·
  **Origin:** releases#125 fix-lane intake hold (ex releases#129 + riders)
- **What/why, three parts that land together:**
  1. **xtask check leg:** assert Cargo.lock resolves swarm-discovery to git rev
     `89a2200d54a4e3cab2f46cc75ebff49a1fb07614` while the patch is load-bearing; the check's
     message states its own drop condition (upstream ships a post-PR#27 release AND iroh's pin
     reaches it). Without it, stanza removal or a routine iroh bump silently returns the lock to
     the spinning crate and nothing reds.
  2. **Procedure rule for lock-touching lanes** (docs): targeted `cargo update -p <crate>` only,
     never full re-resolve; count changed `[[package]]` blocks AND diff per-block edges (set-identical
     hid 8 windows-sys edge movers at acaaa4f); two resolutions disagreeing = toolchain drift —
     stop and compare against CI before shipping either lock; hand-edited lock acceptable iff
     `cargo check --workspace --locked` passes.
  3. **Toolchain-version print step in golden** (cargo/rustc versions, both OS legs): the acaaa4f
     comparison against CI was impossible because no run log prints a version. One-grep audit.
- **Ripe when:** next CI-touching wave; part 1 sooner if any iroh bump is proposed.
- **Size:** small-medium (one xtask leg, one docs section, one workflow step).
- **Composed:** LOCKSMITH (#132) CI-rider cluster, hertz thin lane — 2026-08-03. GREENLIT with
  #132 and **DISPATCHED to hertz 2026-08-03** (all three parts land together).

### IR-5 — Shared nextest summary parser
- **Status:** open · **Origin:** BAROMETER triage (standing recommendation, pre-register)
- **What/why:** two agents in one day wrote `[0-9]+ tests run` parsers that read "1 test run"
  (singular) as zero — a guard fed by a broken parser condemns valid rounds. One shared,
  singular-aware parser (single-source discriminant) for every consumer of nextest summaries.
- **Ripe-when REWORDED 2026-08-04 (todlando audit): the old trigger was unfireable as worded.** At
  `b7b00c3` the in-tree population of nextest-SUMMARY parsers is ZERO — the two scripts that read
  nextest output (`g6-curve.ps1:83-90` per-test lines, `g6-postbounce.ps1:44` display-only grep)
  neither parse counts nor carry the defect, so "next wave touching any gate script that reads
  nextest output" could fire on a non-defective script while the real population (agent-authored
  throwaway parsers, which never enter the tree) stays out of reach. New trigger: **the next time
  anyone — agent or lane — needs a nextest summary COUNT**, the shared parser is built FIRST and the
  need consumes it; rig briefs should name it so throwaways stop being authored.
- **Size:** small.
- **Composed:** LOCKSMITH (#132) CI-rider cluster, CONDITIONAL — lands iff the hertz thin lane
  touches gate scripts; otherwise stays open here. 2026-08-03. Carried in hertz's 2026-08-03
  dispatch brief as a **conditional** rider. **Condition NOT MET**, answered by the file-set
  audit at [[CI-RIDER LANE STATE]]; remains open for its next count-consuming use.

### IR-6 — Membership logging on subnet gates
- **Status:** open · **Origin:** BAROMETER triage (standing recommendation, pre-register)
- **What/why:** counts beside results, membership beside counts — gate logs that state a count
  without naming the population keep producing unreadable reds. Standardize membership
  enumeration in gate output.
- **Ripe when:** next wave touching gate scripts / CI legs that report counts.
- **Size:** small.
- **Composed:** LOCKSMITH (#132) CI-rider cluster, CONDITIONAL — lands iff the hertz thin lane
  touches gate scripts; otherwise stays open here. 2026-08-03. Carried in hertz's 2026-08-03
  dispatch brief as a **conditional** rider. **Condition NOT MET**, answered by the file-set
  audit at [[CI-RIDER LANE STATE]]; new LINK output complied, existing gate-output estate remains.

### IR-7 — Phase A rigs leak a daemon+brain pair on Windows (exe-lock kills notify relink)
- **Status:** open · **Origin:** BAROMETER post-publish triage (ex releases#124 — full mechanism on the closed issue)
- **What/why:** two Phase A rigs launch daemons that escape the job object via WMI-rung autostart
  (double-space unquoted cmdline fingerprint; SPT_HOME in the wrapper cmdline is the attribution
  key); the leaked pair holds target/debug/spt.exe and kills every golden job reaching the notify
  relink. CI reaps as tourniquet (fa6e597); in-job test launch is the fix.
- **LANE-LINKED 2026-08-30 (#242 close sweep):** hertz's queued daemon-leak fixup lane carries
  this entry (brief cites IR-7/17/20/34/35/63); leaves the register when that lane lands.
- **Ripe when:** next wave touching the Phase A rigs or daemon autostart path.
- **Size:** medium.

### IR-8 — reap-census scoped_survivors=0 is blind to unreadable-path holders
- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane. · **Origin:** BAROMETER triage
  (ex releases#122)
- **What/why:** a zero that cannot see is not a zero — census scoping skips procs whose exe path is
  unreadable, so the survivors count can report clean while a holder lives. Needs a positive control
  / explicit unreadable bucket in the verdict line (unreadable_path count exists; the ZERO must
  refuse when it is nonzero).
- **Defining specimen (golden 30782259675, hfenduleam test job, 2026-08-03):**
  `CI-REAP summary: killed=5 kill_failed=1 scoped_survivors=0` — an admitted kill failure printed
  beside a zero-survivors claim on the same verdict line. The held image surfaced one step later:
  run-scoped tmp cleanup denied 5/5 attempts on `...\relshell\svcmock.exe` (2nd appearance of the
  svcmock hold; 1st @7a3c08c, pre-kill-auth). hertz's addendum: an image-held survivor also blocks
  WRITES to the exe path — the same class manufactures build/relink access-denied reds that mask as
  build problems, not just cleanup warnings. Not per-run: the same-sha green rerun's leg read
  `kill_failed=0 scoped_survivors=0` throughout (hertz, 30784469908) — intermittent sighting,
  second of its class, not a deterministic fixture property.
- **The Linux twin is strictly worse (todlando audit 2026-08-04, vs `b7b00c3`):** `reap-census.sh`
  has NO `kill_failed` anywhere (0 occurrences vs 2 in the `.ps1`) — its kill loop increments
  `killed` only in the success branch with no else, so a failed kill increments nothing and prints
  nothing. The specimen that made this class VISIBLE on Windows would be INVISIBLE on Linux.
  Population precision so this is not overclaimed: ESRCH is benign (already gone; the kill-time
  re-resolve makes it the common case); the vanishing case is EPERM against another account's
  process. The `.sh` `scoped_survivors` DOES come from a post-reap census re-measure, so survivors
  are measured — the hole is failed kills and the unreadable bucket, not the survivor count.
  Windows precision from the same audit: `unreadable_path` IS on the CI-CENSUS line (:157) but the
  CI-REAP verdict line (:243, :246) still carries only killed/kill_failed/scoped_survivors — the
  zero still does not refuse, exactly this entry's ask.
- **Built evidence:** both verdict lines now carry `unreadable_path`; any nonzero unreadable
  family population renders `scoped_survivors=UNPROVEN` rather than a false zero. Linux also
  counts and reports failed kills. The shared predicate is mutation-pinned by
  `reap-census-selftest.sh`; the PowerShell implementation parses cleanly.
- **Ripe when:** next census/reap script wave (natural pair with IR-7's lane) — now BOTH platforms.
- **Size:** small.

### IR-9 — Golden boxes run different clippy versions
- **Status:** pin LANDED 2026-08-18 at `35968156` (`build: pin Rust 1.96.0`), then
  audited **BUILT** at the 2026-08-29 v0.65.0 close sweep; the pin is an ancestor of
  golden-green cut SHA `4d6007ac`. The earlier measurement half had already landed and run:
  the toolchain print (`8ed006b` → `REQ-CI-TOOLCHAIN-VERSION-PRINT`) exercised both legs of
  golden run 30971976024 (`test` jobs 92198170694/92198170700 — scoped to `test`, not n1-gate;
  grep token `TOOLCHAIN `). Runner-account facts, read by doyle 2026-08-05: hfenduleam
  `cargo/rustc 1.93.0` + `clippy 0.1.93`, kitsubito `cargo/rustc 1.96.0` +
  `clippy 0.1.96`; `stable (default)` on both proved the skew would otherwise decay silently.
- **RULING (doyle, 2026-08-05, on the runner-account facts as the 2026-08-03 hold required):**
  (1) align-by-event REJECTED — with both boxes on unpinned stable, alignment decays silently;
  the skew is a mechanism and the fix must be one too. (2) declare-one-leg REJECTED as the
  terminal state — it repairs lint authority but leaves the legs resolving with different cargo
  versions, and the acaaa4f lock-attribution question this family started from is a resolver
  question. (3) **PIN IN-REPO: `rust-toolchain.toml`, `channel = "1.96.0"`** — both runner
  accounts already resolve their toolchain through rustup (witnessed by the `active=` line), so
  the pin self-applies with zero per-box maintenance, and the judge's version becomes a property
  of the TESTED SHA — the same object golden CI already guarantees. Bumps become reviewed lane
  commits, tested by the golden run they ride; the hfenduleam leg proves 1.96.0 on the pin
  lane's own run. (4) INTERIM until the pin lands: kitsubito's clippy leg is AUTHORITATIVE for
  lint disputes — not because newer is stricter (skew direction stays unasserted) but because
  1.96 is the version the pin names, so interim and terminal rulings agree.
  · **Origin:** BAROMETER (ex releases#121); re-confirmed on the #125 fix lane
  (builder's Windows clippy vs kitsubito's rust-1.96.0 lints); see [[CI-RIDER LANE STATE]]
- **What/why:** a Windows-clean lane can land a lint that only reds on the Linux leg — toolchain
  skew makes local clippy evidence non-transferable. Align versions or declare the authoritative
  leg. Natural companion to IR-4's toolchain-version print step.
- **Built evidence / fulfilment check:** `rust-toolchain.toml` contains
  `channel = "1.96.0"` and rode the tested cut. A source sweep at close found no CI or pool
  machinery keyed to a box-default toolchain **path**: golden invokes `cargo`, `rustc`, `clippy`,
  and `rustup show active-toolchain` through PATH; pool ownership keys on source-tree/lane identity,
  not rustup installation paths. `release.yml`'s `$HOME/.cargo/bin/mdbook` is an installed tool
  location, not a Rust toolchain selector; its builds still invoke PATH-resolved `cargo`.
- **Size:** built.
- **Composed:** LOCKSMITH (#132) CI-rider cluster (rides IR-4's toolchain-version print step) —
  2026-08-03. GREENLIT with #132 and **DISPATCHED to hertz 2026-08-03**; that dispatch delivered
  the measurement half (landed via [[CI-RIDER LANE STATE]], first exercised on run 30971976024).

### IR-10 — Wave gate runs the CONSUMERS of any predicate it changes
- **Status:** open · **Origin:** BAROMETER gate craft (ex releases#119)
- **What/why:** legs chosen from changed crates miss the predicate's callers; a composed red is
  triaged at the wave's own tip first. This is the gate-population rule made binding in the gate
  runbook + scripts rather than living in memory.
- **Ripe when:** next gate-runbook/docs wave.
- **Size:** small (docs + gate-script checklist).

### IR-11 — find-cwd-holders.ps1: --headless discriminator as a column
- **Status:** open · **Origin:** worktree-pin triage tooling (ex releases#118)
- **What/why:** the holder-triage script buries the headless-vs-interactive discriminator in prose;
  as a column it makes the orphan-vs-own-shell call one glance.
- **Ripe when:** any rig-tooling wave; trivial rider.
- **Size:** tiny.

### IR-12 — xtask contract-drift gate misses a stale manifest.schema.json
- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane (the narrowed blind arm only). · **Origin:** ex
  releases#116
- **KIN NOTE RETIRED (2026-09-06, hertz; doyle measure-first ruling):** the stale-binary
  premise was a rig artifact, not a reproduced product hole. At `9f809f8d`, in isolated Linux
  worktree `hertz-ir12-mutation`, build `spt` once, mutate only its root CLI help string, do not
  rebuild, then run `cargo run -p xtask -- check` alone: **exit 1**, combined output **3435 bytes**,
  ending `xtask check: docs-site/src/cli/reference.md drifted from the binary's --help` (followed
  by the regeneration instruction). The binary hash changed during check; the stale input was
  rebuilt by `gen(true)` → `spt_bin` → `cargo build -q -p spt --bin spt` before comparison.
  `CARGO_TARGET_DIR=UNSET`, `SPT_BLESS=UNSET`; Cargo's metadata target and xtask's read path both
  resolve to this worktree's `target/debug/spt`. Source mutation was restored byte-for-byte.
  Acceptance files: `~/spt-evidence/ir12-mutation-20260906/{check.exit,check.raw,env.txt}` on kitsubito.
  The original rig mechanism remains unproven (old-mtime restoration or two target directories
  are candidates, not findings). No product fix or permanent test added. IR-12 leaves the
  register at the WEBSERVE close sweep.
  The mandatory workspace-bins prebuild leg stays in every gate driver on its own merit (caught W2's spacerun red the night it was adopted); it is no longer justified by this note.
- **What/why (corrected — the consequence sentence was false at `b7b00c3`):** the literal claim
  holds — `xtask check` does not regenerate-and-compare the schema — but staleness does NOT "ship a
  wrong public contract silently": `checked_in_schema_is_current`
  (crates/spt-runtime/src/manifest.rs:2363, `int->REQ-DOCS-5`, landed `be4e46c` 2026-06-05, BEFORE
  this entry's last sweep — docs lagging code) asserts full content equality of the checked-in
  `manifest.schema.json` against what the derives generate, CRLF-normalised, `SPT_BLESS=1` as the
  regenerate path. It is REACHED (lib unit test; ci.yml:114 runs `-E kind(lib)+kind(bin)` on push;
  golden Phase A re-runs the workspace). Exactly ONE schema file exists in the tree; `docs_bundle`
  (xtask main.rs:609-618) COPIES it at build time, so no second stored copy can drift. Chain closes:
  derives → checked-in (unit-gated) → bundle (copied, not stored).
- **What remains open, and the entry narrows to it:** `check_llms_links` (xtask main.rs:521)
  hardcodes `manifest.schema.json` and `llms-full.txt` as always-existing, so the link check can
  never see them MISSING — a blind arm, not a drift hole.
- **The discrimination is now PROVEN, not presumed (todlando 2026-08-04, burn-the-build arms in
  isolated worktree ir12-mutation @`11169c1`, env verified clear of `SPT_BLESS` FIRST — set, the
  test short-circuits into a WRITE and a mutation arm silently self-heals green; that env check is
  now part of the rig recipe):** arm 0 baseline PASS by NAME (1 test run); arm 1 semantic single
  byte (title `…manifest`→`…manifesX`, length unchanged, scripted edit with match-count refusal)
  REDS at manifest.rs:2374 exit 100 — "manifest.schema.json drifted from the derives — regenerate
  with SPT_BLESS=1", with the mutated token appearing exactly once in 96,248 B of assertion output
  so the byte is provably the only delta; arm 2 whitespace-only (CRLF→LF, 1014 endings) PASSES —
  and arm 0 is itself the stronger normalisation proof, since the on-disk file is CRLF while the
  generated string is LF, so an unmutated PASS is only possible because the test normalises; arm 3
  restore re-measured PASS at the pristine sha256. `checked_in_schema_is_current` is a REAL gate.
- **Built evidence:** `check_llms_links` resolves stored root assets to their
  real source paths and runs the `llms-full.txt` generator instead of returning
  hardcoded `true`. A unit cell proves a missing schema and install script are
  refused, then accepted only after the real source file exists.
- **Ripe when:** next xtask/docs-gate wave (now sized to the blind arm only).
- **Size:** tiny.

### IR-13 — Test-soundness follow-ups from the uniform-table sweep
- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane. · **Origin:** ex releases#58
- **What/why:** the remaining candidates from the closed issue were mutation-proved before changing
  tests. `hold_outranks_everything` now walks all four `Opportunity` arms (including
  `HoldRelease`); changing held+release to start reds on that arm. Pure walk tests cover all four
  `QuiesceOutcome` arms and all five `EffectKind` arms; making `KillUnconfirmed` clear or
  `Registry` ephemeral reds independently. The join test now binds all six `JoinFail` variants to
  both hold retention and the emitted failure class/retry payload; misclassifying `WrongCode`
  reds. The access candidates had already landed in the W4 follow-up and its dead-seam removal,
  so the hygiene lane does not manufacture a second test vocabulary beside them.

### IR-14 — .worktrees audit: "how many worktrees are there" has four defensible answers, and the difference is not junk
- **Status:** open · **Origin:** ex releases#56 (was flag: NEEDS-OPERATOR in eval — operator input
  now sought directly when the entry ripens, not via board flag)
- **What/why:** the project `.worktrees/` dir accumulates content beyond what git tracks; audit +
  reap recipe + a hygiene rule for lane close-out. Teardown discipline per docs and memory (classify
  before delete, outbound links first).
- **Release-close cleanup, 2026-09-11 (doyle, operator-requested):** removed **38 registered
  worktree copies** whose heads were ancestors of released `16df0e41`, with no tracked changes,
  untracked files, ignored files, target trees, or inbound links from the project-wide reparse
  census. Branches and commits were retained; seven stale worktree registrations were repaired
  with Git before ordinary, non-forced removal. This count is removals, NOT a census of all
  remaining work. Dirty/unmerged/evidence-bearing lanes and the sync diagnostic trees stayed.
  The broader home/Documents/projects cleanup also removed the reproducible N-1 checkout and
  its separately classified target, an old release download, and generated scratch artifacts:
  net free-space increase **4,532,350,976 bytes (4.22 GiB)**, ending at **83,382,472,704 bytes
  (77.66 GiB)**. Concurrent machine activity makes this a net volume delta, not the sum of file
  lengths. Receipt: `.spt/cleanup-20260911.json`. One cleanup discharges this audit instance,
  not the recurring hygiene requirement; IR-14/26/27/49 are not closed by deletion.
- ⚠ **The header of this entry previously read "14 untracked orphan dirs vs 25 git-tracked". Both
  numbers were stale AND UNDATED**, so nobody could tell drift from error. Every count below is dated
  and carries its command.

#### THE COUNT DISAGREEMENT IS THE FINDING (measured 2026-08-03, todlando + doyle, main @`3efd7e6`)

Three people measuring "the worktrees" got three answers. None was wrong; they answered three
different questions, and nothing in the tree states which one is meant:

| answer | question it actually answers | command |
|---|---|---|
| **73** | all ENTRIES under `.worktrees/` | `ls -A .worktrees \| wc -l` |
| **52** | DIRECTORIES under `.worktrees/` | `ls -dA .worktrees/*/` |
| **38** | registered worktrees INCLUDING the root checkout | `git worktree list` |
| **37** | registered worktrees under `.worktrees/` | above, minus the root |

**52 − 37 = 15 unregistered directories.** The 73 − 52 = **21 loose FILES** are covered below.

**A count is only as good as its question.** Treat "how many worktrees" as under-specified until the
answer names its population — the same defect that made a naive `grep -rn` from the project root
inflate a code count by **34.9×** (426 tracked `.rs` vs 14865 on disk excluding all `target/`), and
made that grep run past 120s while `git ls-files | xargs grep` returned instantly. **Scan roots and
population definitions are the same class of error.** Use `git grep` / `git ls-files` for tracked
content and `git worktree list --porcelain` for worktrees.

#### THE 15 UNREGISTERED DIRECTORIES ARE FOUR DIFFERENT KINDS OF THING

⛔ **CLASS A — LIVE BUILD POOLS, NOT ORPHANS. DO NOT DELETE.** 3 dirs, 13.2 GB. Each is the TARGET of
a junction that a REGISTERED worktree uses as its `target/`:

| dir | inbound junction from | size | claim |
|---|---|---|---|
| `gate-target` | assembly-doorbell, doorbell-w1, doorbell-w2, doorbell-w3 | EMPTY | none |
| `gate-target-render` | golden-render | 5.84 GB | `POOL-OWNER.json` → golden-render |
| `gate-target-w4doc` | w4-cli-doc | 7.36 GB | none |

**These are exactly the directories that read as obviously junk** — no `.git`, no source, leftover
names — and deleting one destroys a registered worktree's build pool and leaves a dangling junction.
**Polarity was checked BEFORE classification, which is what caught it:** all 15 top-level dirs are
REAL directories, none is itself a reparse point; the six junctions are **INBOUND**, at
`<registered-worktree>/target`. See [[worktree-target-junction]], [[gate-worktree-target-disk]].

Two findings inside class A, neither of them a deletion question:
- **`gate-target` has FOUR registered trees junctioned into ONE pool, with no `POOL-OWNER.json` at
  all** — so nothing would refuse a second LIVE lane there. That is releases#103's exact hazard
  sitting armed. The pool is also empty: someone reclaimed it and left four junctions aimed at a hole.
- **`gate-target-render`'s `POOL-OWNER.json` carries only `owner_tree` and `written_by` — no pid and
  no birth stamp.** A claim that cannot distinguish a live lane from a finished one is missing the one
  property the claim mechanism exists to provide.

**CLASS B — EMPTIED SKELETONS, ONE UNIFORM SHAPE.** 8 dirs, **0 files**: `acl-core`, `engine-room`,
`ff-fastfollow`, `gate-23d5ceb`, `gate-ff`, `golden-a`, `golden-b`, `w2b-sender-stamp`. Every one is
exactly `crates/spt-daemon/` and nothing else. **Eight independent removals stopping at the SAME
relative path is a mechanism, not litter.**

**MECHANISM CORROBORATED LIVE, 2026-08-03:** a read-only PEB sweep of process CWDs during a running
`spt-daemon` suite found ~20 processes — `spt_daemon-<hash>` test harnesses, `PING`, `cmd` — whose
CWD was **exactly `<worktree>/crates/spt-daemon/`**, the precise path all eight skeletons froze at. A
`git worktree remove` racing a straggler there deletes everything else and leaves that chain pinned.
The processes churn fast (all 17 sampled pids were gone within 30s, one already showing **pid reuse**
— see [[pid-reuse-across-reboot]] for why a pid alone is never an identity), so the pin is a race, not
a steady state, and it recurs on every daemon-suite worktree.

**CLASS C — FULLY EMPTY, no inbound junction.** 3 dirs, 0 bytes: `gate-41`, `gate-559632e`,
`release-runbook-main-advance`. Class B with even the chain gone.

**CLASS D — DELIBERATE SCRATCH, NOT RESIDUE.** 1 dir, 12 files, 50 KB: `_patches` — three `.patch`
files with their `.untracked` manifests, plus `ir18-gate-logs/`. Modified the day before the audit,
i.e. someone's working state.

3 + 8 + 3 + 1 = 15.

#### PIN STATE: NO SKELETON IS HELD TODAY (with a stated blind spot)

Read-only PEB CWD sweep, 2026-08-03: **zero processes hold a CWD in any class-B or class-C
directory** — every live pin was in `gate-ec5f38a` and `gate-main`, both REGISTERED and both running
rigs at the time. So removal of B and C would succeed today; nothing is retrying it.

⚠ **The sweep read 412 of 593 processes; 181 were unreadable** (elevated/system, no
`PROCESS_VM_READ`). The no-pin result therefore holds over the READABLE population only. Cheap to
re-run elevated before acting — [[absence-needs-sibling-probe]].

#### THE LOOSE FILES: A SHARED LOCATION WITH NO STATED CONTRACT

**21 loose files sit in `.worktrees/`** — gate logs (`gate-*.log`, `gate-559632e-log.txt`), rig
scripts (`g6-curve.ps1`, `g6-postbounce.ps1`, `gate-w5-*.ps1`), and `gate-w5-notes.md`. **Nobody
declared `.worktrees/` a log drop; it became one.** Same class as the memory index: a shared location
with no stated contract accumulates whatever anyone puts there, and **the first person to tidy it
cannot tell residue from someone's working state** — class D is that risk already realised. The
hygiene rule this entry owes should name where gate logs and rig scripts belong, not only how to reap
worktrees.

#### RECLAIM ARITHMETIC — AND WHY THIS ENTRY IS NOT THE DISK FIX

Classes B, C and D together are **under 51 KB**. All 13.2 GB of the unregistered population is class
A, behind live junctions. **An orphan sweep is not a disk-space remedy**, and reading it as one sends
you at the wrong target: on the audit date, free space was **12.5 GB against the 32 GB golden floor**
([[free-space-floor-blocks-golden]]) while the two largest pools on the box were `gate-ec5f38a/target`
(14.33 GB) and `gate-main/target` (28.12 GB) — **both REGISTERED, so both outside the orphan
population entirely.** The disk question and the orphan question have different populations; answering
one correctly says nothing about the other.

- **AUDIT EXECUTED 2026-08-30 (doyle, the v0.66.0→NOW-SIGNAL between-milestone window; full
  output `wt-census-2026-08-30.txt` in the session scratchpad, method = this entry's own):**
  four answers BEFORE the sweep: 85 entries / 85 dirs / 76 registered incl root / 75 under
  `.worktrees` → 10 unregistered, 0 loose files (the 21 loose files of 08-03 are gone).
  **The 08-03 headline populations have INVERTED:** zero pools and zero junctions exist under
  `.worktrees` at all (every registered tree reads `target=none`; the reparse sweep found no
  inbound junction) — class A is EMPTY, so the armed pool hazards this entry named are
  currently unpopulated. Unregistered classified: 4 fully-empty (C), 3 `crates/spt-daemon`
  skeletons (B — the mechanism's fingerprint again), `_patches` (D, kept — working scratch),
  and TWO content-bearing checkout remnants (gate-signet-w1 10.8MB, gate-w1-a8f04aff 27MB) =
  registry-pruned dirs held by the conhost CWD pins IR-63's third face names. **Sweep
  executed on the gater's own rigs:** evidence preserved FIRST
  (`spt-preserve\audit-2026-08-30\`: gate-w1-a8f04aff's 229 non-HEAD files as a verified
  tarball; er-instrument's 115-line UNCOMMITTED instrument diff as a patch — that worktree
  belongs to hertz's lane and was NOT touched beyond the read-only copy), 16 pinning conhosts
  killed by pid after a fresh probe, 9 dead rigs removed. AFTER: **76 dirs = 75 registered +
  `_patches`, fully reconciled; zero unexplained entries, zero pins.** Reclaim was ~38MB —
  reconfirming this entry's arithmetic that the orphan sweep is hygiene, not a disk remedy.
  Landed-classification caveat: `git cherry` patch-id reads conflict-resolved picks
  as UNLANDED (emit-single-write, fix-206/208/209 all show UNLANDED with shipped content), so
  the census's landed column is a datum, never a reap authorization.
- **HYGIENE RULE (the text this entry owed, written 2026-08-30 while the loose-file population
  is zero — the rule exists BEFORE it refills):** `.worktrees/` holds exactly two kinds of
  entry: **registered worktrees** and **`_patches/`** (the one declared scratch location).
  Nothing else. Gate/rig artifacts follow their lifetime: (1) driver scripts, exit/raw files,
  and logs live INSIDE their rig's worktree for the rig's life — they leave WITH it, via the
  preservation step (copy what the verdict cites into `spt-preserve/<occasion>/`, verified by
  cmp or a listed tarball, restore cost stated) and never accumulate beside the rigs; (2)
  anything meant to outlive its rig goes to the repo ROOT beside the verdicts and RCAs it
  supports (the census/finding/JIT convention) or into `spt-preserve/` — never loose in
  `.worktrees/`; (3) a file found loose in `.worktrees/` is treated as UNCLASSIFIED WORKING
  STATE — moved to `_patches/` with a dated note, never deleted on sight (class D is the risk
  realised). Lane close-out = `git worktree remove` + prune + the conhost CWD-pin check
  ([[IR-63]] third face) when removal refuses; a registry-pruned dir left behind is a defect
  to sweep, not a norm.
- **Ripe when:** between-milestone idle window (it is a dev-box chore, zero product risk) — but the
  class-A pool findings are armed hazards and do not wait for it.
- **Size:** small for the sweep; the hygiene rule and the pool-claim gaps are separate small items.
- **Field instance (hertz sweep, 2026-08-04 — an unclaimed pool found rather than reasoned about):**
  `.worktrees\gate-target-w4doc` held **7,907,558,098 B with NO POOL-OWNER.json at all**. Not a stale
  claim, not a foreign claim — no claim. Exactly this entry's shape, first measured instance. Reaped
  under doyle's ruling as part of [[IR-27]]'s two-step teardown; the measurement stands on its own.

### IR-17 — Deadline-burn bring-up family: a test burns its full window while the daemon/brain never comes up
- **Status:** open · **Origin:** golden 30782259675 red triage 2026-08-03
- **What/why:** two different tests on two runner hosts now share one signature — bring-up misses
  its ONLINE window under leg load and the test burns its ENTIRE deadline before the PRECONDITION
  panic: `spt::resident_service_e2e::a_declared_service_rises_with_the_daemon_and_reaches_the_cli`
  (hfenduleam, FAIL 123.99s, "PRECONDITION: the daemon never came up", run 30782259675, green on
  same-sha rerun 30784469908) and `spt::activity_link_push_e2e` (kitsubito, full 30s, run
  30607903133 specimen, green on same-sha rerun; its "brain stderr EMPTY" leg and its family
  membership are both CORRECTED in the 2026-08-30 sweep update below — the kitsubito member is
  CLOSED under a named mechanism).
  Family reading, not one flake: same missed-window shape, host-independent, both mid-leg under
  load. Cross-ref KNOWN-HAZARDS 5.13 — bring-up has a hard ONLINE budget with known sensitivity to
  anything that stalls it (the blanket-fsync canary; `attach_wedge_e2e` guards that budget).
- **State line (the discriminating datum, resident_service red):** `daemon_up=false boot_alive=true
  boot_pid=Some(8920) rel_started=false broker_survived=false` — the boot process was ALIVE at
  panic time and the daemon never reached up. Any characterization run records this line per run,
  not the verdict (hertz protocol 2026-08-03).
- **Read of that line, CORRECTED 2026-08-03 (hertz):** it is NOT "started-but-never-bound" (the
  earlier reading here) and not "never-started" — it is **started, did work, then killed** —
  CANDIDATE via [[IR-18]]. The daemon spawned its boot service and that service reached the CLI
  (the spool holds its message), and `broker_survived=false`. The DISCRIMINATING field is
  `broker_survived`: false in every killed round of the positive control, true in every healthy
  round. **An earlier evidence leg here is RETRACTED (hertz, same night, off the negative arm he
  ran before reporting; deployah, who had carried the leg into four register sites, swept every
  placement): "empty daemon.stderr.log = TerminateProcess signature" was false — the stderr
  block is empty on PASSING runs too, so it carries zero information in either direction; it
  failed the discriminator question and does not support the kill read.** The kill read now rests
  on the control's field-for-field reproduction and the IR-18 mechanism, not on the log.
  Consequences: (a) the bring-up window is **exonerated for this specimen** — measuring it would
  have measured nothing; (b) the candidate mechanism and its evidence now live in [[IR-18]]
  (a sibling test's bare breadcrumb tree-kill), CANDIDATE — not reproduced, not proven;
  (c) **the characterization population changed, and the rate run is CANCELLED** (doyle ruling
  2026-08-03) — `resident_service_e2e` run ALONE has no sibling to collide with, so the mechanism
  predicts 0/N and that number answers no live question; the only sound population was the test
  INSIDE the Phase A parallel pool, which costs a full Phase A leg per sample, and the fix is
  warranted by the source-verified hazard class regardless of the specimen's rate. No rate figure
  will exist for this specimen — do not later read its absence as a low rate; (d) **positive
  control still runs, falling out of the
  hypothesis:** kill the spawned daemon by pid mid-bring-up — after boot-service spawn, before
  ready — and it must reproduce the observed line field for field (`daemon_up=false
  boot_alive=true broker_survived=false`). If the rig cannot make that shape on
  demand, a 0/N from the untouched arm is worth nothing and must be reported as worth nothing.
  The host-INDEPENDENT family claim (kitsubito's `activity_link_push_e2e`) is untouched by this:
  it has no such kill site named, so the family survives even if this specimen leaves it.
- **POSITIVE CONTROL RAN 2026-08-03 (hertz, prebuilt a5042ec binary, box confirmed clear —
  0 open runs, 145.95 GB free): shape reproduced 3/3, deterministic.** Negative arm n=2: 2/2 PASS
  (5.59s, 5.46s), `daemon_up=true boot_alive=true rel_started=true broker_survived=true
  survived_teardown=true`. Positive arm (daemon killed by parent-scoped descent after
  boot-service spawn, before ready) n=3: 3/3 FAIL (93.95/93.25/93.50s), state line identical to
  the CI red in EVERY field except boot_pid (a pid, must differ), same panic, same site
  (resident_service_e2e.rs:382). Structural fact the arm settled, and the refutation risk that
  made it worth running: the boot service rises BEFORE brain.ready becomes readable — had the
  order been reversed the arm would have produced daemon_up=true and refuted the mechanism.
  CEILING MET, NOT EXCEEDED: the control used Stop-Process -Force (TerminateProcess — the same
  primitive as taskkill /F), so it proves a forced daemon kill after breakaway-service spawn
  produces this exact line ON DEMAND; it says nothing about WHO issued one in golden 30782259675.
  Candidate mechanism, shape reproduced on demand — "root caused" written by nobody. Duration
  note, recorded not explained: 93.5s local (idle box) vs 123.99s CI (Phase A parallelism), both
  burning the same three 45s windows — consistent, not verified.
- **Same-host sub-observation (hertz, host-CONSTANT — narrower claim, kept separate):** both
  reds of 2026-08-03 sat on hfenduleam Windows Phase A and burned their full windows:
  `a_tree_teardown_reaches_a_grandchild_the_service_spawned` (run 30776330383, FAIL 10.176s = the
  full poll deadline, vs a 0.19–0.66s pass band — 15–50x out) + the resident_service row above.
  MEMBERSHIP PROVISIONAL for the teardown row: it carries a candidate mechanism the bring-up burn
  does not share — the pid-only oracle IR-15 just replaced. If the oracle caused it, that row
  leaves the family and host-constant collapses to one sighting. The host-INDEPENDENT pair above
  is the claim that survives someone fixing this box; the sub-observation is what is actionable
  about hfenduleam (a live-daemon host) meanwhile. **UPDATE 2026-08-04 (golden 30873007187
  attempt 1 — SECOND sighting, and the provisional question above is now ANSWERED): the
  pid-only-oracle candidate is REFUTED for this row** — IR-15's authenticated repin rode the
  failing tree (a5042ec ancestor of 4b37512) and the row failed anyway (10.225s, "grandchild
  51848 outlived the tree teardown"), with is_stamped() asserted before the kill so the verdict
  passed the authenticated gate. The row therefore STAYS a family member with its mechanism OPEN,
  narrowed by hertz's log forensics (competence-controlled: the capture channel demonstrably
  prints): no DETACH_BREAKAWAY_DENIED (breakaway rung taken), no SERVICE_JOB_UNAVAILABLE (job
  created + child enrolled), no SERVICE_TREE_KILL_INCOMPLETE (TerminateJobObject returned
  success) — everything enrolled died; THE SURVIVOR WAS NEVER ENROLLED. Two hypotheses,
  inseparable in existing evidence: H1 test defect — the grandchild SELECTION is a bare
…
  the false-repeat correction (the 10.176s red was the PRE-a5042ec bare-pid mechanism).
…

…

…
  at the end. · **Size:** a between-run census step plus a scoped reap in the harness.