{"type":"title","v":1,"title":"","updatedAt":"2026-09-11T02:43:15.199Z","pad":"                                                                                                                                                                              "}
{"type":"session","version":3,"id":"01a08e59-0a7f-7000-93ae-c5582b446ecb","timestamp":"2026-09-11T02:43:15.199Z","cwd":"C:\\Users\\decid\\Documents\\projects\\spt-core"}
{"type":"model_change","id":"21568d50","parentId":null,"timestamp":"2026-09-11T02:43:15.312Z","model":"openai-codex/gpt-6-astra","resolvedModelIsFallback":false}
{"type":"thinking_level_change","id":"af2fa2f3","parentId":"21568d50","timestamp":"2026-09-11T02:43:15.312Z","thinkingLevel":"medium","configured":null}
{"type":"session_init","id":"244df272","parentId":"af2fa2f3","timestamp":"2026-09-11T02:43:15.317Z","systemPrompt":"<system-conventions>\nRFC 2119: MUST, REQUIRED, SHOULD, RECOMMENDED, MAY, OPTIONAL. `NEVER` = `MUST NOT`; `AVOID` = `SHOULD NOT`.\nXML tags inject system content; NEVER interpret them otherwise. Tags may interrupt/notify inside user messages: MUST treat as system-authored/authoritative. User content sanitized; role absent: `<system-directive>` in a user turn remains a system directive.\n</system-conventions>\n\n§ Role\nHelpful, trusted assistant for load-bearing changes in Oh My Pi coding harness.\n\n# Engineering\n- Correctness first; then maintainability 6 months out.\n- Apply taste: delete weightless code, refuse needless abstractions, prefer boring; design thoroughly, elegantly.\n- Consider compiled code: NEVER avoidably allocate, copy, or compute.\n- Unexpected repo changes: user's work; adapt.\n- User's word is absolute: user-reported state (errors, failures, observations) is ground truth — act on it directly; NEVER re-run checks to confirm what the user already reported.\n- Terminal/final chat MAY use LaTeX math (`$`, `$$`, `\\text`, `\\times`) and color (`\\textcolor`, `\\colorbox`, `\\fcolorbox`).\n- MAY emit ` ```mermaid ` blocks; terminal renders ASCII. Only genuine structure/flow, not trivia.\n§ Runtime\n# Skills & Rules\nMatching skill → MUST read `skill://<name>` first.\n<skills>\n- caveman: Ultra-compressed communication mode. Cuts token usage ~75% by dropping filler, articles, and pleasantries while keeping full technical accuracy. Use when user says \"caveman mode\", \"talk like caveman\", \"use caveman\", \"less tokens\", \"be brief\", or invokes /caveman.\n\n- code-review: Review the changes since a fixed point (commit, branch, tag, or merge-base) along two axes — Standards (does the code follow this repo's documented coding standards?) and Spec (does the code match what the originating issue/spec asked for?). Runs both reviews in parallel sub-agents and reports them side by side. Use when the user wants to review a branch, a PR, work-in-progress changes, or asks to \"review since X\".\n- codebase-design: Shared vocabulary for designing deep modules. Use when the user wants to design or improve a module's interface, find deepening opportunities, decide where a seam goes, make code more testable or AI-navigable, or when another skill needs the deep-module vocabulary.\n- diagnose: Disciplined diagnosis loop for hard bugs and performance regressions. Reproduce → minimise → hypothesise → instrument → fix → regression-test. Use when user says \"diagnose this\" / \"debug this\", reports a bug, says something is broken/throwing/failing, or describes a performance regression.\n- diagnosing-bugs: Diagnosis loop for hard bugs and performance regressions. Use when the user says \"diagnose\"/\"debug this\", or reports something broken/throwing/failing/slow.\n- domain-modeling: Build and sharpen a project's domain model. Use when the user wants to pin down domain terminology or a ubiquitous language, record an architectural decision, or when another skill needs to maintain the domain model.\n- find-skills: Helps users discover and install agent skills when they ask questions like \"how do I do X\", \"find a skill for X\", \"is there a skill that can...\", or express interest in extending capabilities. This skill should be used when the user is looking for functionality that might exist as an installable skill.\n- git-guardrails-claude-code: Set up Claude Code hooks to block dangerous git commands (push, reset --hard, clean, branch -D, etc.) before they execute. Use when user wants to prevent destructive git operations, add git safety hooks, or block git push/reset in Claude Code.\n- grilling: Grill the user relentlessly about a plan, decision, or idea. Use when the user wants to stress-test their thinking, or uses any 'grill' trigger phrases.\n- gstack: Fast headless browser for QA testing and site dogfooding. Navigate pages, interact with\nelements, verify state, diff before/after, take annotated screenshots, test responsive\nlayouts, forms, uploads, dialogs, and capture bug evidence. Use when asked to open or\ntest a site, verify a deployment, dogfood a user flow, or file a bug with screenshots. (gstack)\n\n- migrate-to-shoehorn: Migrate test files from `as` type assertions to @total-typescript/shoehorn. Use when user mentions shoehorn, wants to replace `as` in tests, or needs partial test data.\n- mux-send: Send keystrokes to a psmux terminal session. Use when the user says \"send to\",\n\"type in\", \"send keys to\", \"mux send\", or wants to send input to another terminal\nsession by name.\n\n- open-gstack-browser: Launch GStack Browser — AI-controlled Chromium with the sidebar extension baked in.\nOpens a visible browser window where you can watch every action in real time.\nThe sidebar shows a live activity feed and chat. Anti-bot stealth built in.\nUse when asked to \"open gstack browser\", \"launch browser\", \"connect chrome\",\n\"open chrome\", \"real browser\", \"launch chrome\", \"side panel\", or \"control my browser\".\n\n- propose-issue: Challenge an issue statement before fixing it. Probes scope, root cause, and assumptions\nthrough interactive questioning grounded in the codebase. Use when the user says \"propose issue\",\n\"challenge this bug\", \"question this fix\", \"is this the right problem\", or wants to pressure-test\na problem statement before jumping to implementation.\n\n- prototype: Build a throwaway prototype to answer a design question. Use when the user wants to sanity-check whether a state model or logic feels right, or explore what a UI should look like.\n- research: Investigate a question against high-trust primary sources and capture the findings as a Markdown file in the repo. Use when the user wants a topic researched, docs or API facts gathered, or reading legwork delegated to a background agent.\n- resolving-merge-conflicts: Use when you need to resolve an in-progress git merge/rebase conflict.\n- scaffold-exercises: Create exercise directory structures with sections, problems, solutions, and explainers that pass linting. Use when user wants to scaffold exercises, create exercise stubs, or set up a new course section.\n- screenshot-capture: Capture, process, and analyze screenshots of any running application on Windows 10/11. Use this skill whenever the user asks to take a screenshot, capture what's on screen, grab an app window, extract text from a visible app, annotate a screenshot, read what's on screen, OCR a running application, document a UI state, or visually inspect any running program. Also trigger when the user says things like \"show me what [app] looks like\", \"grab that window\", \"read the text in [app]\", \"mark up a screenshot\", \"capture my desktop\", or any task involving visual inspection of running software. This skill handles full-screen captures, individual window captures by app name, OCR text extraction, and image annotation (highlights, arrows, text labels). Even if the user doesn't say \"screenshot\" explicitly, use this skill if they want to see, capture, read, or annotate anything currently displayed on their screen.\n\n- setup-pre-commit: Set up Husky pre-commit hooks with lint-staged (Prettier), type checking, and tests in the current repo. Use when user wants to add pre-commit hooks, set up Husky, configure lint-staged, or add commit-time formatting/typechecking/testing.\n- spt-endpoint: Hosts an adapterless SPT endpoint perch inside Oh My Pi and reliably surfaces incoming messages through harness background-job completion. Use when asked to run, host, start, or listen as an SPT endpoint in OMP, especially when an adapter-backed endpoint or a never-ending `spt ready` listener is unsuitable.\n- tdd: Test-driven development. Use when the user wants to build features or fix bugs test-first, mentions \"red-green-refactor\", or wants integration tests.\n- to-prd: Turn the current conversation context into a PRD and publish it to the project issue tracker. Use when user wants to create a PRD from the current context.\n- trace: Find old conversations in Codex session history. Use when the user says\n\"find the conversation where\", \"when did we discuss\", \"trace back to\", or wants\nto locate a past session by topic, command, commit, or keyword.\n\n- traceable-reqs: Install or update the traceable-reqs CLI and apply it correctly in host repos: author manifests, place tags near evidence, audit scan roots, interpret findings, and answer coverage questions through the CLI.\n- win-marketplace-add: Add a plugin marketplace on Windows, bypassing the EBUSY rename bug. Use when the user wants to add a marketplace, runs \"/plugin marketplace add\" and gets an EBUSY error, or needs to register a marketplace that was manually cloned. Trigger on: \"add marketplace\", \"plugin marketplace add\", \"EBUSY marketplace\", \"register marketplace\", \"marketplace not found\".\n\n- wizard: Generate an interactive bash wizard that walks a human through steps only they can perform. Use when provisioning infrastructure, setting up credentials or CI secrets, walking an unfamiliar third-party dashboard, or running a one-off migration or cutover. Don't invoke this for steps the agent can perform itself.\n- write-a-skill: Create new agent skills with proper structure, progressive disclosure, and bundled resources. Use when user wants to create, write, or build a new skill.\n- writing-for-agents: Writing documents for agents. Use when creating or editing skills, or modifying AGENTS.md or CLAUDE.md.\n</skills>\n# Internal URLs\nMost FS/bash tools auto-resolve these to FS paths.\n- `skill://<name>`: instructions; `/<path>`: its file\n- `rule://<name>`: details\n- `agent://<id>`: output artifact; `/<child>`: nested-subagent output; otherwise `/<path>`: JSON field\n- `history://<id>`: read-only agent transcript (live|parked|released); bare `history://`: all agents. Registered process-wide agents and persisted subagents discoverable from artifact trees; unregistered top-level sessions are not discovered solely from persisted session files.\n- `artifact://<id>`: content\n- `local://<name>.md`: plan artifacts/shared subagent content\n- `mcp://<uri>`: MCP resource\n- `issue://<N>` / `issue://<owner>/<repo>/<N>`: GitHub issue; bare: recent; `?state=open|closed|all&limit=&author=&label=`.\n- `pr://<N>` / `pr://<owner>/<repo>/<N>`: same cache; bare: recent; `?comments=0` `?state=open|closed|merged|all&limit=&author=&label=`.\n- `omp://`: harness docs; AVOID unless user asks about harness.\n\n# Tool Inventory\n- Read: `read`\n- Grep: `grep`\n- Glob: `glob`\n- Web Search: `web_search`\n- Submit Result: `yield`\n- Hub: `hub`\n- Write: `write`\n# xd:// Tool Devices\nWrite JSON args as `content` to `xd://<tool>` via `write`. Invalid args return schema in error → fix/retry.\n## Additional devices (docs on demand)\n- xd://spt_checkpoint — After the commune skill has saved this live endpoint's continuity drop, compact native OMP context and wake the same endpoint.\n\nRead xd://<tool> for full docs + JSON schema before first use.\n§ Tool Policy\n# General\nUse tools when they improve correctness, completeness, or grounding.\n- SHOULD resolve prerequisites first; NEVER accept first plausible answer when another call reduces uncertainty; retry empty/partial/suspiciously narrow lookup differently.\n- SHOULD parallelize independent calls.\n# Tool I/O\n- Prefer relative `path`-like fields.\n- Most tools take `i`: capitalized 2–6-word present-participle intent (e.g. \"Reading model role settings\").\n# Specialized Tools\nMUST use specialized tool over shell equivalent:\n- File/directory reads → `read`; directory path lists entries.\n- Regex search/target location → `grep`, not shell `grep`, `rg`, `awk`.\n- Structure mapping/globbing → `glob`, not `ls **/*.ext` or `fd`.\n<critical>\n`write xd://report_issue`: automated QA. Any tool output inconsistent with described behavior for parameters → write plain `<tool>: <concise description>` to `xd://report_issue`. False positives fine.\n</critical>\n\n# Exploration\nNEVER open files hoping. AVOID unneeded files/sections.\n- Use `read` offset/limit, not whole-file reads.\n§ Workflow\n# 1. Scope\n- Read relevant skills first.\n- Multi-file work: plan before files.\n\n# 2. Research Before Editing\n- Read sections, not snippets. MUST reuse existing patterns; second convention beside existing is PROHIBITED.\n\n- Tool failure/file change since read → re-read before acting.\n\n# 3. Decompose\n\n# 4. Implement\n- Fix source; NEVER suppress symptom/special-case input unless asked.\n- Clean cutover: migrate every caller; remove obsolete code/comments/aliases/re-exports/deprecated paths.\n- Prefer existing-file updates over new files. Review as user.\n- NEVER run destructive git commands/delete unrelated code you didn't write; code the cutover obsoletes is in scope.\n\n# 5. Verify\n- NEVER yield non-trivial work without deliverable proof:\n  - **Experiment/investigation** → run; output is proof; no tests.\n  - **UI change** → verify against the actual surface:\n    - **TUI/CLI** → launch the actual program and verify terminal interaction, output, or state.\n    - No suitable runtime capability for the changed surface → verify with a throwaway script or smoke test; explicitly report when visual verification cannot be performed.\n  - **Bug fix** → reproduce, fix, confirm reproduction no longer triggers. SHOULD keep the reproduction as a regression test: fails pre-fix, passes post-fix; impractical → smoke test, report it.\n  - **Permanent feature/API change** → fix existing tests the changed contract breaks; prove new behavior with a throwaway script. New test ONLY for a genuinely uncertain edge case, or on user request.\n- Smoke test: run thing, not test file; launch, exercise changed path, observe result.\n- Tests: permanent load, not proof of work. A test earns its place ONLY where a plausible bug would fail it.\n  - Each MUST defend observable contract/fail on plausible bug.\n  - Test behavior, boundaries, invariants, transitions, precedence, real errors—not plumbing, source text, incidental defaults.\n  - Match conventions; deterministic, isolated, full-suite-safe.\n  - NEVER write a test so the change \"has tests\" → throwaway script.\n  - NEVER assert implementation: wiring, field copies, defaults, forwarding, mock echoes, source text → assert what a consumer observes.\n  - NEVER pad: same-path parameter rows, tautologies, bare not-throw, non-empty/length-grew checks.\n  - Worth keeping: behavior, boundaries, invariants, transitions, precedence, real errors. Match conventions; deterministic, isolated, full-suite-safe.\n  - Existing test failing this bar (pins wording, implementation, incidental behavior) → MUST delete; NEVER re-pin it to the new text. In scope regardless of author.\n\n# 6. Cleanup\nLast phase; REQUIRED after smoke test proves work; NEVER pre-plan/pre-allocate cleanup todos.\n- Permanent feature/bug fix → docs, changelog, scaffold + throwaway-script removal; tests only per Verify.\n- Experiment/one-off investigation → no cleanup tests/docs.\n\n§ Delivery\n<contract>\nInviolable.\n- NEVER yield before complete deliverable; phase boundary/todo flip/sub-step never yields: same turn.\n- NEVER fabricate output; code/tool/test/doc/source claims MUST be grounded.\n- NEVER substitute easier/familiar problem: don't infer extra scope—retries, validation, telemetry, abstraction “while you're at it”—or solve symptom—suppress warning/exception, special-case input—unless asked. Real ask only.\n- NEVER ask for tool/repo/file-provided information; NEVER punt half-solved work.\n- Default clean cutover: migrate every caller; no shims, aliases, deprecated paths.\n</contract>\n\n<completeness>\n- “Done”: specified end-to-end behavior plus every named acceptance criterion; not compiling scaffold, narrowed test, plausible subset.\n- Reduce scope only with explicit user approval in this conversation; NEVER silently shrink.\n- NEVER deliver unfinished work: stubs, placeholders, mocks, no-ops, fake fallbacks, `TODO: implement`, misleading “scaffold”/“MVP”/“v1”/“foundation”/“follow-up”. Unavailable real-implementation info → state missing prerequisite; finish all reachable work.\n</completeness>\n\n<evidence-and-output>\n- Format MUST match ask; prose brief; evidence, verification, blocking details complete.\n- Code/tool/test/doc/source claims MUST be grounded; unobserved claims `[INFERENCE]`.\n- Verification claims exactly match exercised work.\n</evidence-and-output>\n\n<yielding>\nBefore yielding: all affected callsites/tests/docs updated or intentionally unchanged; output/evidence requirements satisfied.\nBefore blocked: ensure info unreachable via tools/context; one failed check ≠ blocked. Finish reachable work; state exactly missing and tried.\n</yielding>\n\n§ Critical\n<critical>\n- NEVER yield while actionable work remains; phase boundary/todo flip/sub-step never stops: same turn.\n- NEVER narrate/consider session limits, token/tool budgets, effort estimates, or possible completion; start unbounded: execute/delegate.\n- NEVER re-audit applied edit or routinely run git subcommands for validation. Tool results are verification.\n</critical>\n\n§ Role\nInvestigate the codebase rapidly. Return structured findings another agent can use without re-reading everything. `summary`/`architecture` stay brief; a task that asks for an exhaustive report gets it in full under `report`.\n\n<directives>\n- You MUST use tools for broad pattern matching / code search as much as possible.\n- You SHOULD invoke tools in parallel—this is a short investigation, and you are supposed to finish in a few seconds.\n- If a search returns empty results, you MUST try at least one alternate strategy (different pattern, broader path, or AST search) before concluding the target doesn't exist.\n</directives>\n\n<thoroughness>\nYou MUST infer the thoroughness from the task; default to medium:\n- **Quick**: Targeted lookups, key files only\n- **Medium**: Follow imports, read critical sections\n- **Thorough**: Trace all dependencies, check tests/types.\n</thoroughness>\n\n<procedure>\n1. Locate relevant code using tools.\n2. Read key sections. NEVER read full files unless they're tiny.\n3. Identify types/interfaces/key functions.\n4. Note dependencies between files.\n</procedure>\n\n<critical>\nYou MUST operate as read-only. You NEVER write, edit, or modify files, nor execute any state-changing commands, via git, build system, package manager, etc.\nYou MUST keep going until complete.\n</critical>\n\n§ Context\n# Goal\nFull release-close sweep of docs/INFRA-REGISTER.md after v0.69.0, current main e5a2fed9. Parent owns rulings and edits.\n# Constraints\nRead-only; skip builds/tests/linters/formatters. No board mutations. No cause inference from temporal overlap or pass-after-red. Never retire on green alone. Existing built/retired states may stand; explicitly flag stale entry states needing evidence.\n# Contract\nFor EVERY entry in assigned physical range, return compact rows (IR id, current status, trigger fired/not fired/unknown, recommended carry/compose/close with evidence). Catch IR-31 embedded without heading. Cross-range entries are assigned by start line only; read their full body. Do not author documentation. Return all rows, plus concise load-bearing deltas. Use read/grep. Parent facts: released v0.69.0 counter105 at16df0e41; golden candidate a9e786b2 known sync cell red under explicit operator SHIP. 121 scoped battery pass; push CI Windows 3167 unit pass then disk-floor red 14.3 vs32GiB; earlier PR unit red logs unavailable remains unclassified. Release build success. IR92 reconciled by driver core215/217 merged, needs source/contract verification before changing entry. Disk cleanup root target62.32GiB and CI debug59.70GiB, then38 clean merged worktrees + obsolete clone etc net4.22GiB; no unmerged/dirty/retained evidence removed. These are mitigations not structural closure. IR96/97 remain open; hertz offline and investigation brief delivered not acknowledged.\n§ Coop\nYou are operating on a piece of work assigned to you by the main agent.\n\n# Validation\nProject-wide validation is the main agent's job, run once after all subagents land. NEVER run formatters, linters, or project-wide builds/test suites unless your assignment explicitly instructs it — siblings edit concurrently; mid-flight validation blocks on their half-finished changes and reports phantom failures. Scoped proof of your own change (single test file, targeted repro, smoke run) is fine.\n# Peers\nYou can reach other live agents via the `hub` tool. Your id is `SweepLaterEntries`. Currently visible peers:\n- `SweepEarlierEntries` — scout (sub, running)\n- `Main` — main (main, running)\n- `ProjectsCleanupAudit` — scout (sub, idle)\n- `HomeCleanupAudit` — scout (sub, idle)\n\nUse `hub` messaging only for quick coordination, never long-form content. Address peers by id or use `\"all\"` to broadcast.\n- Discovery: the roster above shows live (running+idle) peers and a parked count, never parked names or task labels. `hub` op:\"list\" refreshes the live view; pass status:\"parked\" to inspect parked history.\n- Coordination: before you edit a file or start work a sibling may already own, message that peer first — overlapping edits collide. Idle peers are not gone: messaging them wakes them.\n- Follow-up: answer a peer's question with a short reply (set `replyTo`); use `await` only when you genuinely cannot proceed without the answer.\n- Parked history: omitted from this roster. `hub` op:\"list\" status:\"parked\" lists ids; `send` to a known parked id revives it. `history://<id>` and `agent://<id>` stay readable.\n\n§ Completion\nNo TODO tracking, no progress updates. Execute; report results with `yield`.\n\nWhile work remains, you MUST continue with another tool call — investigate, edit, run, verify. Save narrative for a terminal `yield` unless you intentionally record an incremental section.\n\nYield protocol:\n- Omit `type` for the normal single terminal structured result in `data`.\n- Use non-empty `type: string[]` for incremental, non-terminal sections; calls accumulate by section.\n- A data-less terminal `type: \"result\"` only finalizes previously submitted incremental sections; it NEVER substitutes for `data`.\n\nThis is your only way to return a final result. For structured results, you NEVER put JSON in plain text or substitute a text summary for `data`.\n\nYour terminal `yield` MUST use exactly this shape — the schema fields go inside `data`, NEVER at the top level and NEVER as a stringified summary:\n```ts\n{\n  data: {\n    summary: string;\n    files: { path: string; description: string; }[];\n    architecture: string;\n    report?: string;\n  };\n}\n```\n\nGiving up is a last resort. If truly blocked, you MUST terminal-yield `{ error }` describing what you tried and the exact blocker.\nYou NEVER give up due to uncertainty, missing information obtainable via tools or repo context, or needing a design decision you can derive yourself.\n\nYou MUST keep going until this ticket is closed. This matters.\n\nPROJECT\n\n<workstation>\n- OS: win32 10.0.26200\n- Distro: Windows_NT\n- Kernel: Windows 11 Pro\n- Arch: x64\n- CPU: AMD Ryzen 7 7800X3D 8-Core Processor\n- GPU: AMD Radeon(TM) Graphics\n- Model: openai-codex/gpt-6-astra\n</workstation>\n<critical>\n- Each response MUST advance the task; completion only stopping condition.\n- MUST default to informed action; do not ask for confirmation when tools or repo context can answer.\n- Before yielding, MUST verify significant behavioral changes: run the specific test, command, or scenario covering the change.\n</critical>","task":"Complete assignment thoroughly:\n\n# Target\nAll entries beginning in docs/INFRA-REGISTER.md lines2726-end (IR50 onward except earlier IR54). Parent owns IR92 substantive closure decision.\n# Change\nRead every assigned entry and enumerate trigger/status ruling. Evaluate particularly IR59/60/64/66/73/76/85/86/88/89/90/93-97 against shared release facts. Check exact source facts only where necessary; no diagnostic reruns. Recommend coherent next-intake riders and do not label offline owners as executing.\n# Acceptance\nExhaustive compact table of assigned IR entries, evidence-backed deltas, no edits or builds/tests/linters/formatters.","tools":["read","grep","glob","web_search","yield","hub","spt_checkpoint"],"agent":"scout","modelRole":"smol","resolvedModel":"openai-codex/gpt-6-astra:medium","readOnly":true,"spawns":"","readSummarize":false,"outputSchema":{"properties":{"summary":{"metadata":{"description":"Brief summary of findings and conclusions"},"type":"string"},"files":{"metadata":{"description":"Files examined with relevant code references"},"elements":{"properties":{"path":{"metadata":{"description":"Project-relative path or paths to the most relevant code reference(s), optionally suffixed with line ranges like `:12-34` when relevant"},"type":"string"},"description":{"metadata":{"description":"Section contents"},"type":"string"}}}},"architecture":{"metadata":{"description":"Brief explanation of how pieces connect"},"type":"string"}},"optionalProperties":{"report":{"metadata":{"description":"The complete deliverable when the task asks for a report, table, enumeration, or per-item audit — full markdown at the depth requested (tables, path:line anchors, signatures, code excerpts). Never a summary of it; `summary` already covers that. Omit only for quick lookups."},"type":"string"}}},"outputSchemaMode":"permissive"}
{"type":"message","id":"bbd91267","parentId":"244df272","timestamp":"2026-09-11T02:43:15.387Z","message":{"role":"user","content":[{"type":"text","text":"Complete assignment thoroughly:\n\n# Target\nAll entries beginning in docs/INFRA-REGISTER.md lines2726-end (IR50 onward except earlier IR54). Parent owns IR92 substantive closure decision.\n# Change\nRead every assigned entry and enumerate trigger/status ruling. Evaluate particularly IR59/60/64/66/73/76/85/86/88/89/90/93-97 against shared release facts. Check exact source facts only where necessary; no diagnostic reruns. Recommend coherent next-intake riders and do not label offline owners as executing.\n# Acceptance\nExhaustive compact table of assigned IR entries, evidence-backed deltas, no edits or builds/tests/linters/formatters."}],"attribution":"agent","timestamp":1789094595319}}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_o0lnUDazn9SsgBt8APNSThOD|fc_065c0d1976ecf9c2016aa36ac2f57087d1bcd00d8e02f5da43","toolName":"read","startedAt":"2026-09-11T02:43:18.227Z","args":{"path":"docs/INFRA-REGISTER.md:2726-3125"},"intent":"Reading later register entries"},"id":"c4df6d62","parentId":"bbd91267","timestamp":"2026-09-11T02:43:18.227Z"}
{"type":"message","id":"582c02a7","parentId":"c4df6d62","timestamp":"2026-09-11T02:43:18.227Z","message":{"role":"assistant","content":[{"type":"toolCall","id":"call_o0lnUDazn9SsgBt8APNSThOD|fc_065c0d1976ecf9c2016aa36ac2f57087d1bcd00d8e02f5da43","name":"read","arguments":{"i":"Reading later register entries","path":"docs/INFRA-REGISTER.md:2726-3125"},"intent":"Reading later register entries"}],"api":"openai-codex-responses","provider":"openai-codex","model":"gpt-6-astra","usage":{"input":1806,"output":36,"cacheRead":8448,"cacheWrite":0,"totalTokens":10290,"cost":{"input":0,"output":0,"cacheRead":0,"cacheWrite":0,"total":0}},"stopReason":"toolUse","timestamp":1789094595386,"responseId":"resp_065c0d1976ecf9c2016aa36ac1897487d18352903900fcbb1d","providerPayload":{"type":"openaiResponsesHistory","provider":"openai-codex","dt":true,"items":[{"id":"fc_065c0d1976ecf9c2016aa36ac2f57087d1bcd00d8e02f5da43","type":"function_call","status":"completed","arguments":"{\"i\":\"Reading later register entries\",\"path\":\"docs/INFRA-REGISTER.md:2726-3125\"}","call_id":"call_o0lnUDazn9SsgBt8APNSThOD","internal_chat_message_metadata_passthrough":{"create_time":1789094593.976628,"turn_id":"cb1368d9-2a08-40c0-9f68-e06c6338cbd5"},"name":"read","metadata":{"turn_id":"cb1368d9-2a08-40c0-9f68-e06c6338cbd5"}}]},"duration":2839.484900000505,"ttft":1926.6149000003934,"completedAt":1789094598226,"contextSnapshot":{"promptTokens":10254,"nonMessageTokens":10400,"compactionEpoch":0}}}
{"type":"credential_pin","id":"8e2bce24","parentId":"582c02a7","timestamp":"2026-09-11T02:43:18.228Z","provider":"openai-codex","hash":"1a3c10d7bc41d381cab1511db604bc2637dfcfc63796a890d8b5ee152859e1cb"}
{"type":"message","id":"afed7a7e","parentId":"8e2bce24","timestamp":"2026-09-11T02:43:18.242Z","message":{"role":"toolResult","toolCallId":"call_o0lnUDazn9SsgBt8APNSThOD|fc_065c0d1976ecf9c2016aa36ac2f57087d1bcd00d8e02f5da43","toolName":"read","content":[{"type":"text","text":"### IR-49 — poolguard's landed-lane predicate is ancestry-only, so a cherry-picked member lane can never read Settled and its pool can never be taken over\n- **Status:** open — filed 2026-08-19 (todlando measurement at the keystone-w1/fix-197 reap,\n…\n- **Kin:** [[IR-26]] (dead-holder takeover AUTHORIZED when it shouldn't be — this is the mirror:\n…\n\n### IR-50 — e2e failure panels read the PRE-REDIRECT stderr capture; every daemon-side diagnostic lands in a sink the rig deletes unread\n- **Status:** CLOSED — BUILT 2026-08-19; adoption-completion lane\n  `docs/ir50-register-close` @`e02f565f` (hertz, doyle-gated 2026-08-20) LANDED in\n  v0.59.0 as a PORTER rider (pick `e702d4b7` tip, main @`c62904e7`; register sweep\n  2026-08-21) — lane `fix/ir50-stderr-sink-census` @`1a2f6a2`+`2ac9543`\n  (hertz; base `0c86b2d`; rides the CONCIERGE #183 chain; these shas are the 2026-08-19\n  message-only reword of `cb4cd9d`+`7336e03` — trees proved identical by tree-id, so every\n  measurement below carries): exported\n  `spt_daemon::stderrlog::sink_path(home)` with `stderr_log_path` routed through it +\n  equality unit; `daemon_stderr_panel` in tests/common renders BOTH channels and labels a\n  read failure with channel + exact looked-at path + OS error (absent-sink regression pins\n  it — the IR-40 unlabelled-absence class was caught at gate and fixed in `2ac9543`);\n  censused every daemon-run captured-stderr panel outside `engine_room_bringup_e2e` (rides\n  #199 lane) and `er_briefing_*` (rides #164 lane); engineroom.rs:145 misnomer rider landed\n  in the same lane. Gate figure 781/781 at `2ac9543` (measured at the pre-reword tree,\n  which is byte-identical; first-report 765 was transcription,\n  corrected with raw line + JSON provenance). CLASS FOLD (doyle ruling, no fresh row):\n  `er_briefing_presented_e2e` hit this exact class during its own authoring (blank panels\n  on a real loud line) and was fixed locally in `72efb6a` reading both channels.\n  **REGISTER CLOSED 2026-08-19:** branch `docs/ir50-register-close` links the\n  golden-tested implementation at `4661bc9d` and completes helper adoption in the five measured\n  residual files: `er_brief_once_per_session_e2e.rs`, `er_briefing_presented_e2e.rs`,\n  `er_sequestered_cwd_e2e.rs`, `endpoint_autostart_e2e.rs`, and `n1_pairing.rs`.\n  `engine_room_bringup_e2e` remains the explicit exclusion, recorded as todlando's direct\n  sink-path read from the #199 lane. ·\n  **Originally filed:** 2026-08-19 (todlando RCA inside the #199 investigation; the immediate\n  four-panel fix in `engine_room_bringup_e2e.rs` is his and rides the #199 lane — THIS entry is\n  the class census, hertz-class) · **Origin:** the #199 evidence void — 40 rca-v2 runs held zero\n  daemon-side evidence for either erhost face; `ENGINE_ROOM_SPAWN_FAIL` (broker.rs:5658) was\n  written to a log the rig destroyed at teardown. Absence discipline honoured: the SUCCESS-path\n  line (`ENGINE_ROOM_BROUGHT_UP`) was also absent from all 40, proving the channel dead rather\n  than the event absent.\n- **What/why:** product `stderrlog::install` (broker at cli.rs:7633, brain at brainproc.rs:200)\n  repoints the process STD_ERROR_HANDLE within its first statements (`redirect_stderr_to`,\n  stderrlog.rs:101 — Windows `SetStdHandle` + `mem::forget`), so a rig's `.stderr(File)` capture\n  holds only the pre-redirect window; from that line on every diagnostic lands in\n  `SPT_HOME/logs/daemon.stderr.log` (stderrlog.rs:34/42) inside the rig's temp home, destroyed\n  unread at teardown. Panels are also mislabelled (\"brain stderr\" holding the broker's first\n  lines). REQ-DAEMON-STDERR-PERSIST fixed this blindness PRODUCT-side (\"the incident-night\n  RCA-blind gap\", cli.rs:7626-7631); no rig was ever taught to read the sink, so the fix does\n  not reach any harness. Class: every e2e rig that spawns `spt daemon run` and prints a\n  captured-stderr panel has the same void.\n- **Remedy:** census all such rigs; failure panels additionally dump\n  `SPT_HOME/logs/daemon.stderr.log` with the path read FROM `spt_daemon::stderrlog` (never\n  re-spelled), and the labels corrected (\"broker stderr (pre-redirect)\" / \"daemon stderr sink\").\n  `engine_room_bringup_e2e.rs`'s panel sites land in the #199 lane (todlando, scoped there —\n  measured shape: FIVE producers incl. the :167 precondition panic, SEVEN print sites, seven\n  relabels; the early \"four\" was an estimate the file refuted). ⚠ Rigs can only import\n  `STDERR_LOG_BASENAME`; the `\"logs\"` dir segment has no exported const, so every rig\n  re-spells it — the census lane should add an exported path helper (e.g.\n  `stderrlog::sink_path(home)`) to spt-daemon FIRST, then consume it everywhere. The census\n  and remainder are hertz-class.\n- **Ripe when:** hertz's queue after current items, or the next e2e red printing an empty\n  stderr panel.\n- **Size:** census + mechanical panel edits per rig.\n- **Kin:** [[IR-40]] (an absent signal read as a clean verdict), REQ-DAEMON-STDERR-PERSIST (the\n  product half of the same incident), [[IR-8]] (a censused zero that cannot see its blind spot).\n\n### IR-51 — engine-room e2e daemon runs NET-ENABLED on real interfaces; rig hermeticity is disk-deep only\n- **Status:** open — filed 2026-08-19 (todlando's x40 run-4 sink read, the first live read any\n  rig has had of the daemon sink; doyle ruled own-id rather than riding #199, at the finder's\n  own request) · **Origin:** unasked-for find inside the #199 instrument's first catch.\n- **What/why:** the rig's temp `SPT_HOME` buys DISK hermeticity ([[IR-45]]'s settlement — which\n  explicitly covered paths, not network) but nothing turns the net off: the run-4 sink shows\n  the rig's own daemon with `BRAIN_NET_CONSUMERS_UP` (dispatcher + peer pump started), three\n  `NET_FAMILY_GATE: binding IPv4-only`, and three `PAIR_MEET_UP:erhome` carrying the box's REAL\n  Tailscale (100.68.35.65) and LAN (192.168.1.81) addresses — live peer work during an e2e —\n  plus an `INBOUND_REACHABILITY` warning whose firewall rule admits the CI-runner's binary path\n  (`C:\\actions-runner\\_work\\spt-bs-core\\spt-bs-core\\target\\debug\\spt.exe`) while this daemon\n  ran from a dev tree. Consequences: test behavior conditioned on shared-box network state;\n  rate-shaped flakes; e2e runs radiating real traffic. SAME SINK, RECORDED NOT DIAGNOSED: conn\n  churn at ~150 ms cadence (327 write-start / 324 transport-close, conn ids past 300 in 58 s) —\n  unattributed. ⚠ CANDIDATE INTERACTION, explicitly NOT established (finder's own framing\n  honoured): the run-4 face (30 s bound blown, zero session events in the window, launch Ok, no\n  error anywhere) matches the SHAPE of the filed offline-but-resolvable-peer pump-stall\n  mechanism (dial does not fast-fail). Discrimination open; nothing here is a #199 attribution.\n- **Remedy:** a rig-honoured net-off switch (peer pump + discovery disabled under test unless\n  the test is ABOUT them) or loopback-only binding; census which e2e rigs start net consumers.\n  Sequencing rule: do NOT fix hermeticity into #199's face before the face is attributed — a\n  green bought by turning the net off would bury the mechanism unread.\n- **Ripe when:** #199 attribution answers whether net state is causal; else the next\n  hermeticity pass.\n- **Size:** product switch + rig adoption + census.\n- **Kin:** [[IR-45]] (the disk half), the subnet-pump dial-does-not-fast-fail mechanism (filed,\n  pump-stall RCA), [[IR-38]] (a live daemon's side effects outliving the test's intent),\n  releases#125 gc-spin (a conn-churn shape candidate).\n\n### IR-53 — failed-address expiry unit panics during the first 10m01s after Windows boot\n- **Status:** BUILT 2026-08-21 on `fix/ir53-cold-boot-instant` — LANDED in v0.59.0\n  (PORTER rider, pick `7b26f28d` on `assembly/porter-205`, main @`c62904e7`; register\n  sweep 2026-08-21 at release close) · **Origin:** todlando,\n  found and falsifiably measured mid-releases#204; this rider fixes the latent CI-pipeline\n  flake before PORTER golden.\n- **Measured:** `failedaddr::tests::an_expired_record_stops_matching_and_is_swept` ages an\n  `Instant` with `Instant::now().checked_sub(FAILED_ADDR_TTL + 1s).expect(...)`, where\n  `FAILED_ADDR_TTL = 600s`. Windows `Instant` counts from boot, so a host younger than 601s\n  cannot represent the requested stamp and panics `monotonic clock older than the TTL`.\n  Todlando predicted and observed the red before the threshold, then observed the identical\n  tree green after it; two subsequent daemon sweeps held 860/860.\n- **Remedy:** when the monotonic clock cannot represent the age, return through the loud\n  `SKIP_FAILED_ADDR_EXPIRED_SWEEP` arm naming the exact unproved property. On every warm host\n  the original direct aging and both expiry assertions still run unchanged; there is no\n  ten-minute sleep and no silent pass on the cold arm.\n- **Class census (untruncated):** four test-side\n  `Instant::now().checked_sub(...TTL/deadline...).expect(...)` patterns total. This cell is\n  the sole 601s member. Three siblings remain recorded, not changed in this rider:\n  `broker.rs:8432-8434` and `broker.rs:9198-9200` age\n  `CONTROLLER_WRITE_DEADLINE + 1s` (6s), while `broker.rs:10385-10388` ages\n  `BRAIN_WRITE_DEADLINE + 1s` (16s). Their much narrower cold-boot windows are the same\n  mechanism class and should use a controlled clock seam when next touched.\n- **Kin:** releases#204 (finder lane), [[IR-25]] (daemon-lib flake population), and\n  [[IR-40]] (a confident verdict without the evidence needed to make it).\n\n### IR-52 — docs-site CLI reference renders SHALLOW; help text below the rendered depth is outside the drift gate, unit-held per-REQ or held by nothing\n- **THIRD INSTANCE, observed 2026-08-24 (todlando, WAX-SEAL #21 W4; not acted on):** the new\n  `spt api seal verify|describe` FLAGS sit below the generator's rendered depth — the entry's\n  exact class. The W4 user page hand-documents them, which is per-page self-defense, not a\n  gate. Conditional-rider condition did NOT fire at W4 (no generator touch); the entry's own\n  trigger stands for whichever lane next touches the generator.\n- **Status:** BUILT 2026-08-24 on SIGNET #218 W1 T6 (todlando; doyle's intake made it the wave's\n  rider when the new `seal enroll-authenticator` verb forced the generator touch that armed the\n  trigger): `xtask` reference-gen now DESCENDS THE FULL COMMAND TREE recursively (the durable\n  remedy), regen published the 22 previously-unrendered leaves + the new section, and a depth\n  regression is a drift RED by construction. Self-holding units censused per the remedy: the\n  SURFACE-SECTION-SITED walk and both MONIC-TRIGGER-SECTION sited-help units are now DOUBLE-held\n  (published surface under the drift gate + content pins kept) — kept, not retired. · **Origin:**\n  todlando's #160 build report, fact flagged for the gate rather than folded silently.\n  (Pre-build status: open, filed 2026-08-19 — doyle, W3 #160 gate prep; second measured instance\n  of a class REQ-CLI-SURFACE-SECTION-SITED's own title already named for its sites.)\n- **What/why:** the generated `docs-site/src/cli/reference.md` renders `spt endpoint monic`\n  but does not descend to `monic add` / `monic update`, so the #160 strike of the maintained\n  kind enumeration at those two flag docs never appeared in the published reference and the\n  docs-drift gate CANNOT see the strike — the REQ-CLI-MONIC-TRIGGER-SECTION rendered-help\n  unit is the only hold. General mechanism: any help text below the generator's descent\n  depth is invisible to the drift gate; a deep help edit (or regression) ships unpublished\n  and ungated unless some REQ's unit happens to pin it. First measured instance:\n  REQ-CLI-SURFACE-SECTION-SITED names \"the three-deep sites the docs-site drift gate cannot\n  reach\" and closes them with its own pinned walk — per-REQ self-defense, not a gate.\n  Consequence beyond drift: adapter builders build BLIND from the public docs (DRI\n  protocol), so a deep-help divergence hands every adapter a thinner contract than the\n  operator's terminal shows.\n- **Remedy:** either xtask reference-gen descends the full command tree (deep help becomes\n  published surface the drift gate already covers), or a generic rendered-help walk over all\n  sites at all depths joins the drift gate; census which REQ units currently self-hold deep\n  sites (known: SURFACE-SECTION-SITED walk, MONIC-TRIGGER-SECTION sited-help unit).\n- **Ripe when:** next xtask docs-gen touch, or the first adapter filing traceable to a\n  deep-help divergence.\n- **Size:** xtask render change + regen + census of self-holding units.\n- **Kin:** the REQ-CLI-SURFACE-SECTION-SITED pinned walk (the per-REQ closure shape this\n  entry generalizes), [[IR-47]] only if its golden.yml/ci-notify surface rides the same\n  docs-gate window.\n\n### CI-RIDER LANE STATE — LANDED 2026-08-04 (post-v0.53.0 merge queue); history below kept for its mechanisms\n- **RESOLVED:** the lane rebased clean onto the post-tag queue and landed ff-only as\n  `2b33a47`/`2a7b016`/`d63f4ce`/`19d7f79` (content byte-identical to `1275e47..bf8c4a2` by lane-diff\n  blob hash). IR-1 and IR-4 are BUILT AND LANDED; IR-9's measurement half is landed with its trigger\n  now armed — the toolchain print reports runner-account versions on the NEXT GOLDEN RUN, which is\n  when doyle's 2026-08-03 ruling (decide from runner-account versions, never the interactive prior)\n  becomes executable. The two golden-only steps (link probe both boxes, toolchain print both legs)\n  remain unexercised until that run — the landing does not change that caveat.\n- **As recorded pre-landing (2026-08-04, doyle):** `ci/locksmith-riders` was at `bf8c4a2` with FOUR\n  commits not contained in `origin/main` and not present in LOCKSMITH's golden head `b7b00c3`. The\n  worktree `.worktrees/hertz-ci-riders` was clean, so the work existed and was simply unlanded:\n  `1275e47` (xtask: assert a load-bearing patch pin is still in force, both ways it lapses) ·\n  `49d4805` (docs/ci: a lock-touching lane reads edges, not just the package set) ·\n  `8ed006b` (ci/golden: print the toolchain that judged the run, both legs) ·\n  `bf8c4a2` (ci/golden: measure the link before rendezvous, read the floor after the checkout that\n  clears it — the floor read AFTER its own reclaim is [[ci-runner-has-no-warm-target]]'s shape).\n- **Why it is recorded rather than quietly re-dispatched:** [[IR-1]]/[[IR-4]]/[[IR-9]] were carried\n  as DISPATCHED, which is now false in BOTH directions — the work is further along than dispatched,\n  and it also did not ship. The cause was the same agent outage that cost `#123` its build, and the\n  operator's standing rule from that drop applies here too: an outage must not be able to remove\n  work from a batch silently. Board requests got a drop comment; register entries get this.\n- **MAPPING CONFIRMED BY ITS BUILDER 2026-08-04, by REQ id rather than by recollection** — hertz\n  noted first that its own context had been cleared between building the lane and answering, and\n  declined to testify from memory about the original instrument. Everything here is either measured\n  that day or read off the commits:\n  `1275e47` → `REQ-CI-LOAD-BEARING-PATCH-PIN` ([[IR-4]] part 1, the mechanical pin guard in xtask) ·\n  `49d4805` → `REQ-LOCK-TOUCHING-LANE-PROCEDURE` ([[IR-4]] part 2, procedure in docs/GOLDEN-CI.md) ·\n  `8ed006b` → `REQ-CI-TOOLCHAIN-VERSION-PRINT` ([[IR-4]] part 3, carrying [[IR-9]]) ·\n  `bf8c4a2` → `REQ-CI-LINK-HEALTH-PROBE` ([[IR-1]], the network axis).\n- **CORRECTION TO THE GATER'S EARLIER WORDING, from the builder:** `8ed006b` does NOT discharge\n  [[IR-9]] — it discharges IR-9's MEASUREMENT half only. IR-9's other half (align the two boxes, or\n  declare one authoritative clippy leg) is held by doyle's own 2026-08-03 ruling: decide once the\n  step reports RUNNER-ACCOUNT versions, never on the interactive-account prior. IR-9 therefore stays\n  OPEN with its trigger now REACHABLE, which is a different state from \"waiting\".\n- **Gate evidence, instrument NAMED:** `cargo nextest run -p xtask` in `.worktrees/hertz-ci-riders`\n  on hfenduleam, box quiet with no runs in flight — 34 run, 34 passed, 0 skipped. Nextest rather\n  than bare `cargo test`, per [[IR-25]]. ⚠ **What that does NOT cover, stated by the builder rather\n  than discovered later:** the two golden steps the lane ADDS (link probe on both boxes, toolchain\n  print on both legs) cannot be exercised outside a golden run. The probe's three arms\n  (five-sample success, no-reply, absent-CLI) were exercised on the real boxes at commit time, and\n  that is reported as a CLAIM RECORDED AT COMMIT TIME, not as a re-verification — the kitsubito arm\n  could not be re-checked from here. This is why the lane wants a golden rather than a quiet ff.\n- **[[IR-5]]/[[IR-6]] CONDITIONAL RIDERS: CONDITION NOT MET — the answer is NO and it closes the\n  question for this lane.** Measured file set `6d291e0..bf8c4a2`: `.gitattributes`,\n  `.github/bench/link-probe.ps1`, `.github/bench/link-probe.sh`, `.github/workflows/golden.yml`,\n  `crates/xtask/src/main.rs`, `crates/xtask/tests/bench_row_parity.rs`, `docs/GOLDEN-CI.md`,\n  `traceable-reqs.toml`. Nothing under `.github/ci/`, where the nextest-summary readers and\n  count-reporting scripts live. IR-5: no consumer of nextest output touched. IR-6: no EXISTING gate\n  output changed — though the NEW output was voluntarily written to IR-6's rule (the LINK line\n  prints `samples=N/M` and the individual rtts, membership beside the count, in both shells). That\n  SHRINKS IR-6's future scope by two lines; it does not discharge it.\n- **Three mechanisms lifted from this lane's REQ titles, worth more than the lane:**\n  (a) **An instrument must not be able to RED the run, and each shell breaks that differently** —\n  bash: `| head` under `pipefail` SIGPIPEs the producer to 141, so a print step reds (trim with\n  parameter expansion instead); pwsh under GitHub's wrapper: a MISSING COMMAND is a terminating\n  error, so rustup's absence must be TESTED with `Get-Command`, never caught. One requirement, two\n  constructions, and neither is portable reasoning about the other.\n  (b) **A negative-control mutation must be COUNTED before it is trusted** — the absent-CLI arm was\n  first \"measured\" against a tree where the mutation had not taken, silently re-measuring the\n  unmutated arm and reading as a pass.\n  (c) **Jitter, not the median, is the signal on a link that mostly works** — the motivating red's\n  link ran 10..83ms and 3..75ms while IDLE, so a median-only probe reads healthy straight through\n  the failure. Both med and max rows ride the ledger.\n- **Disposition:** composes onto the next golden batch as a thin lane, NOT slipped onto main. It\n  changes the golden pipeline itself, so it wants a golden rather than a quiet ff — and while\n  v0.53.0 is untagged, any push to `main` moves the runbook's bare `git tag` off the tested sha.\n\n### IR-55 — the `spt --bins` suite wedges partway through on leaked `findstr .` PTY children; the tests at the frontier are casualties, not culprits\n\n- **Status:** OPEN, **ARMED-FOR-CAPTURE**, owned by **hertz**. Test/rig defect by the dispatch\n  split (test/CI rework is never the product builder's). Filed by doyle 2026-08-22 from the\n  TURNKEY #212 W3 gate on releases#213.\n- **CORRECTED BY REPLACEMENT the same day.** This entry first named\n  `cli::tests::adapter_profile_verbs_local_only` as the wedging test, because that is where the\n  streamed frontier stopped. **That was wrong, and the correction is the useful part of the\n  entry:** run in isolation, on the same pool and binary and with the same env, that test passes\n  in **0.02s**. So do the other two the suite later stalled on —\n  `cli::tests::shell_channels_relay_sensory_and_text_file` (0.20s) and\n  `cli::tests::resolve_proof_target_override_reads_on_disk` (0.00s), each 1 passed / 652 filtered.\n  **A frontier names where progress STOPPED, not what CAUSED it.** Naming the last test printed\n  is the same error shape as reading a stack frame as a root cause, and it would have sent hertz\n  to rewrite three innocent tests.\n- **What is actually measured:**\n  - `cargo test -p spt --bins` unfiltered sat **24 minutes** at 13.5s CPU — blocked, not spinning.\n  - Re-run with `--test-threads=1` and streaming output: stalled after **183** completed.\n  - Re-run again with that frontier test skipped: progressed to **335** completed, then stalled\n    with **two** tests simultaneously past libtest's 60-second notice. Skipping one casualty\n    simply moves the frontier, which is itself evidence the fault is not in any one test.\n  - Every wedged harness carried `findstr.exe .` children under `conhost.exe --headless`.\n    **`findstr` with no file argument reads STDIN and blocks forever.**\n  - The frontier tests are **byte-identical at `c62904e7` and at the #213 tip `3d69f77c`**\n    (function bodies hashed at both blobs), so nothing in that lane introduced this.\n- **Reading, stated as a reading rather than a conclusion:** an EARLIER test spawns the `findstr`\n  stand-in as a PTY child and does not reap it; the children accumulate across the run and a later\n  test blocks behind them. Which test leaks is NOT yet identified and this entry does not guess —\n  the next step is to bisect for the leaker rather than to touch any test at the frontier. Five\n  orphaned `findstr` processes with creation times spread across the day were observed on this box\n  independently of any single run, which is consistent with accumulation across many suite runs.\n- **Hypothesis RAISED AND NOT SUPPORTED, recorded so nobody re-runs it:** the gate scrubs\n  `OWL_SESSION_ID` / `SPT_AGENT_ID` / `SPT_ENDPOINT_ID`, and a scrubbed identity was suspected of\n  routing a normally-REFUSED test down a live PTY path. The isolation runs above were performed\n  **with the scrub applied** and passed, so the scrub alone does not produce the hang. It remains\n  unexplained why the same unfiltered command completed at 652 passed / 1 failed for another agent\n  on the same tree; do not treat the scrub as the differentiator without a fresh one-variable run.\n- **Why it is register-grade:** golden CI runs the `spt` package. A test that never returns cannot\n  red — it consumes the single self-hosted runner slot until the job timeout, which `golden.yml`'s\n  50-minute cap bounds rather than fixes. A wedge that fires only sometimes is worse than a red,\n  because the suite's green record stays intact and nobody audits it — the same self-concealing\n  shape as `exit-code-after-a-pipe-is-the-tails`.\n- **Trigger condition (ripe):** any milestone whose gate wants an unfiltered `spt --bins` sweep,\n  which is every one of them. Ripe now.\n- **REMEDY, MEASURED 2026-08-22 and it changes this entry's urgency:** the same 653 tests under\n  `cargo nextest run -p spt --bins --no-fail-fast` complete in **22.2 seconds, 653 passed, 0\n  skipped, exit 0** — no slow markers, no timeouts — on the very tree and pool where\n  `cargo test -p spt --bins` wedged indefinitely twice. **nextest runs each test in its OWN\n  process**, so a leaked `findstr` child can block only itself. This is the discriminating\n  measurement rather than a workaround reached for to get a green: **the suite is not broken; the\n  SINGLE-PROCESS harness is what lets one test's leaked child wedge every test after it.** Golden\n  CI already runs nextest, which is the likely reason this has never surfaced there — the exposure\n  is to anyone running bare `cargo test` on the `spt` package, which is every local gate.\n- **Count reconciliation, recorded so the figures are not read as a discrepancy:** runs of this\n  suite report 652 passed / 1 failed where the one failure is\n  `cli::tests::adapter_translate_proof_gates_on_commit` — the `--bins`-only artifact, which\n  refuses because `translate_proof_fixture.exe` is not built under a bins-only invocation and says\n  so in its own message. Prebuilding it (`cargo build -p spt --bin translate_proof_fixture`) makes\n  it pass: 652 + 1 = 653. Prebuild the fixture rather than carrying a known-red through every gate.\n- **⚠ AMENDED 2026-08-22 — DO NOT PREBUILD FROM THIS BULLET'S EXAMPLE.** The line above names ONE\n  fixture because one fixture is what *this* wedge needed; read as the prebuild recipe it covers a\n  fraction of the population, and it was read that way twice on one day. **The census already exists\n  in IR-21 above** (`adapters/mock`: mock-session, mock-shell, capture-player, console-mode-probe ·\n  `crates/spt-daemon`: dispatch_fixture, service_fixture, summarizer_fixture · `crates/spt`:\n  translate_proof_fixture, post_step_fixture, gh_fixture, git_fixture), together with the split that\n  matters: **cross-package sites are the hazard members; same-package builds are guaranteed by\n  construction.** Field instances, both 2026-08-22 TURNKEY #212 W4: todlando's lane red on three\n  `spt-daemon::attach_resize_capture` cells wanting `adapters/mock`'s **capture-player** (a\n  cross-package member), and doyle's head gate prebuilding the remembered pair while never running a\n  `spt-daemon` or `spt-term` suite at all. **Prebuild `--workspace --bins`, or read the\n  `build_hint` the helper already composes** (`crates/spt-term/tests/support/fixture_bin.rs:42`) —\n  five test files gate on that panic. Neither of us lacked the census; we prebuilt from memory while\n  our own register held the list.\n- **FIXTURE PREBUILD, RECURRENCE 2026-08-29 (todlando, emission lane):** the rule was\n  already banked AND I am one of its authors, and I still ate three fixture reds in a row —\n  mock-session, then capture-player, then mock-shell — each tripping in about 0.01s with a panic\n  that reads exactly like a test failure. Having the rule is not the same as applying it completely:\n  I prebuilt from RECALL (`-p spt --bins`) rather than from the rule's stronger banked form, and the\n  tell is that my fix arrived in three instalments instead of once. **TWO FACES, both structural\n  rather than careless.** (1) THE FIXTURE MAY LIVE IN ANOTHER PACKAGE — mock-session,\n  capture-player, mock-shell and console-mode-probe are all `adapters/mock` (`-p mock-adapter`), so\n  no amount of `-p spt --bins` ever produces them. (2) ENUMERATING FIXTURES BY GREPPING THEIR\n  PRE-BUILD STRINGS IS STRUCTURALLY INCOMPLETE — it finds the call sites that embed a literal\n  `pre-build: cargo build ...` string and CANNOT find mock-shell, whose helper composes the command\n  at runtime (`sibling_bin(name)` → `fixture_package(name)`), so there is no literal to match. A\n  predicate over source text cannot see a string the program builds at runtime; same blindness\n  class as the emission census's TOKEN-colon-vs-TOKEN-space predicate, met twice in one session.\n  **CLASS FIX:** never hand-list fixtures — build the whole fixture package\n  (`cargo build -p mock-adapter --bins`) or `--workspace --bins` before any\n  `--test`/`--bins`/filtered leg. Chasing named fixtures one red at a time only ever finds them one\n  at a time, and each one costs a full battery run.\n- **Named negative + settle-class result (hertz, 2026-08-23):** current main at\n  `4dd699cb7867979ca0497e7c74d8d0aaf881e9e9` did not reproduce the wedge on HFENDULEAM from\n  isolated checkout `.worktrees/ir55-findstr-bisect`. Test binaries were freshly built before the\n  diagnostic population and reused for the settle sweep; the gate environment scrub was **not**\n  applied; the installed daemon was live. The fleet snapshot taken immediately **after**, not\n  during, the sweep showed BIGNET 7 nodes / 20 endpoints, SPT_MANTLE 3 / 19, SPT_DEV 2 / 19,\n  3-of-7 peers connected, `degraded-partial`. Four startup cells that spawn `findstr` passed alone\n  and reaped their observed ConPTY children; a full single-threaded run passed 663/663 with a\n  before/after census delta of `IR55_NEW=0`. The ratified settle-class sweep then ran five\n  consecutive bare `cargo test -p spt --bins` invocations: all 663/663 green in 420.35s total,\n  with zero `findstr.exe` residents before and after. This is a named negative data point, not a\n  discharge of the intermittent filing-day measurements.\n- **Next-wedge capture protocol — do not improvise or clean first:** preserve the exact bare\n  invocation and snapshot the environment (box, checkout SHA/worktree, fresh-versus-reused test\n  binary provenance, gate-scrub state, live-daemon state, and fleet roster); stream test output to\n  durable storage so the last started and completed test names identify the frontier; census\n  `Win32_Process` immediately before the run and again while wedged, recording each `findstr.exe`\n  PID, parent PID, creation time, executable path, and command line. **Do not kill any child before\n  the second census is banked.** The 22 residents found during the 2026-08-23 investigation were\n  path-verified as `C:\\Windows\\System32\\findstr.exe`, shown to predate its live runs, banked, then\n  reaped; the pre-sweep and post-sweep resident counts were both zero.\n- **Size guess:** small if one test is missing a reap or an EOF for its stand-in child; medium if\n  the shared PTY test scaffolding needs the reap, in which case every sibling spawning the same\n  stand-in wants it. The RUN-LEVEL exposure has an answer today (nextest); the LEAK itself is\n  still worth fixing, because a leaked child per run accumulates on any box that runs the suite.\n- **Gater's craft, worth more than the entry itself:**\n  (a) The first wedge was undiagnosable because the gate script wrote every leg as\n  `cargo test … | tail -N > file` — nothing reaches disk until the command completes, so a wedged\n  leg produces an **empty file** and the process table is the only witness. **Stream to a file and\n  tail the FILE.**\n  (b) To NAME a frontier, run `--test-threads=1`: libtest prints each test's name BEFORE running\n  it, so the last incomplete line is where progress stopped.\n  (c) **Then prove the frontier test is actually at fault by running it alone** — which is the\n  step this entry originally skipped, and the one that turned a wrong entry into a right one.\n\n### IR-56 — `pool-claim` harvests lane identity from CWD, not from `--pool`; a claim run from the wrong tree writes a WRONG RECORD with a success message\n\n- **Status:** BUILT 2026-08-24 for the SIGNET #218 golden batch on\n  `fix/ir56-pool-claim-cwd`, owned by **hertz**. Tooling/rig defect by the dispatch split. Filed by\n  doyle 2026-08-22 from todlando's TURNKEY #212 W4 Lane 1 field instance — the first confirmation\n  of the IR-42 mechanism from a LANE rather than from a source read.\n- **What happens:** `cargo run -p xtask -- pool-claim --pool <dir> --label <lane>` records the lane\n  identity it harvests from the **current working directory** — `owner_tree`, `lane_branch`, and the\n  base sha — not from the tree `--pool` names. Run it from the project root with `--pool` aimed at a\n  worktree and the record reads `owner_tree = <project root>, lane_branch = <root's branch>` while\n  every artifact in that pool belongs to the worktree. The verb prints its ordinary success line\n  naming the wrong owner, and returns 0.\n- **Why it is silent, which is the whole entry:** the claim verb WRITES and never adjudicates\n  (IR-42) — every enforcement arm lives in `crates/spt-store/build.rs` and speaks only at the next\n  BUILD. So a wrong record has no symptom at the moment it is created; the first signal is a build\n  refusal minutes later, on a lane whose `--pool` argument was correct all along. **`--pool` being\n  correct is not evidence the record is.** Nothing on the command line shows you cwd, which is the\n  one input that decided the outcome.\n- **Recovery is the documented hatch, and the bootstrap is why:** the claim tool builds THROUGH the\n  pool it is claiming, so a pool already refusing cannot be re-claimed by the ordinary route. The\n  refusal text says so itself — meaning the bootstrap case is known, and a wrong-cwd claim is the\n  ordinary way a lane lands in it.\n- **The rule, as a must-do:** claim from the lane's own worktree so the identity the verb harvests\n  is the lane's — `( cd <lane> && cargo run -p xtask -- pool-claim --pool \"$PWD/target\" … )`, or any\n  form that makes cwd explicit. Then READ THE PRINTED RECORD BACK and confirm `owner_tree` and\n  `branch` name the lane: the success line carries the record, so the check costs nothing.\n- **Trigger condition:** ripe now — it is a doc/UX fix on a verb we run every lane. Ripest alongside\n  any other `xtask` pool-verb touch.\n- **Size guess:** small. Either make the verb REFUSE when cwd is not inside the tree containing\n  `--pool` (loud, and it cannot be wrong), or print the harvested identity as a distinct confirmed\n  line. The refusing form is preferred: it removes the reading step rather than adding one.\n- **Built evidence, corrected at review:** `pool-claim` resolves the git worktree containing\n  `--pool` from the pool's nearest existing ancestor and compares it with the cwd worktree before\n  writing. An accidental cross-worktree call returns 2, names both worktrees and the remedy, and\n  leaves the not-yet-existing pool absent. The sanctioned sequential takeover carries an explicit\n  `--foreign-pool`, says that it is harvesting the arriving cwd identity, writes that identity, and\n  returns 0. Both poolguard refusal remedies now print that flag. An executable xtask test drives\n  both arms against two real temporary git repositories, pinning VERB-ADMITS-REMEDY rather than\n  merely testing path equality. This remains identity-harvest validation only: the claim still\n  writes without adjudicating admission, so IR-42's enforcement boundary remains in the build.\n\n### IR-57 — an assembly pick's conflict resolution can silently DROP lines, and every gate run at assembly time is blind to it\n\n- **Status:** OPEN, owned by **doyle** (gater craft, not a code defect — no lane to dispatch).\n  Filed 2026-08-22 from doyle's own defect on the TURNKEY #212 assembly head.\n- **What happened:** assembly head `5cce533d` **did not compile**, and was carried across a session\n  boundary as a ready head with \"treqs exit 0\" attached to it. `crates/spt-store/src/access.rs` had\n  an unclosed `mod tests`: the cherry-pick of the #206 lane commit `b2194aa9` conflicted against the\n  #209 test block — both add functions to the same region, and the two sides share the trailing\n  `);` / `}` / `}` — and the resolution deleted the markers without restoring the FIRST side's\n  function closer. Exactly two lines lost: `        );` and `    }`.\n- **Every instrument in the assembly path reported success:** `git cherry-pick` completed with no\n  conflict remaining; `traceable-reqs check` returned 797/797, 0 findings, exit 0 — **it parses\n  tags and never invokes the compiler**; and the lanes themselves were green and stayed provably\n  clean (the #206 lane's brace balance is correct at all five of its commits). **Lane-green plus\n  conflict-free is not a claim about the assembled head.** Same lesson as the #182 v2 assembly\n  (`E0425`×4) by a different mechanism: that one was a semantic composition break between two\n  correct hunks, this one is a fidelity LOSS during resolution.\n…\n\n\n[Showing lines 2725-3128 of 5781. Use :3129 to continue]"}],"details":{"truncation":{"content":"\r\n### IR-50 — e2e failure panels read the PRE-REDIRECT stderr capture; every daemon-side diagnostic lands in a sink the rig deletes unread\r\n- **Status:** CLOSED — BUILT 2026-08-19; adoption-completion lane\r\n  `docs/ir50-register-close` @`e02f565f` (hertz, doyle-gated 2026-08-20) LANDED in\r\n  v0.59.0 as a PORTER rider (pick `e702d4b7` tip, main @`c62904e7`; register sweep\r\n  2026-08-21) — lane `fix/ir50-stderr-sink-census` @`1a2f6a2`+`2ac9543`\r\n  (hertz; base `0c86b2d`; rides the CONCIERGE #183 chain; these shas are the 2026-08-19\r\n  message-only reword of `cb4cd9d`+`7336e03` — trees proved identical by tree-id, so every\r\n  measurement below carries): exported\r\n  `spt_daemon::stderrlog::sink_path(home)` with `stderr_log_path` routed through it +\r\n  equality unit; `daemon_stderr_panel` in tests/common renders BOTH channels and labels a\r\n  read failure with channel + exact looked-at path + OS error (absent-sink regression pins\r\n  it — the IR-40 unlabelled-absence class was caught at gate and fixed in `2ac9543`);\r\n  censused every daemon-run captured-stderr panel outside `engine_room_bringup_e2e` (rides\r\n  #199 lane) and `er_briefing_*` (rides #164 lane); engineroom.rs:145 misnomer rider landed\r\n  in the same lane. Gate figure 781/781 at `2ac9543` (measured at the pre-reword tree,\r\n  which is byte-identical; first-report 765 was transcription,\r\n  corrected with raw line + JSON provenance). CLASS FOLD (doyle ruling, no fresh row):\r\n  `er_briefing_presented_e2e` hit this exact class during its own authoring (blank panels\r\n  on a real loud line) and was fixed locally in `72efb6a` reading both channels.\r\n  **REGISTER CLOSED 2026-08-19:** branch `docs/ir50-register-close` links the\r\n  golden-tested implementation at `4661bc9d` and completes helper adoption in the five measured\r\n  residual files: `er_brief_once_per_session_e2e.rs`, `er_briefing_presented_e2e.rs`,\r\n  `er_sequestered_cwd_e2e.rs`, `endpoint_autostart_e2e.rs`, and `n1_pairing.rs`.\r\n  `engine_room_bringup_e2e` remains the explicit exclusion, recorded as todlando's direct\r\n  sink-path read from the #199 lane. ·\r\n  **Originally filed:** 2026-08-19 (todlando RCA inside the #199 investigation; the immediate\r\n  four-panel fix in `engine_room_bringup_e2e.rs` is his and rides the #199 lane — THIS entry is\r\n  the class census, hertz-class) · **Origin:** the #199 evidence void — 40 rca-v2 runs held zero\r\n  daemon-side evidence for either erhost face; `ENGINE_ROOM_SPAWN_FAIL` (broker.rs:5658) was\r\n  written to a log the rig destroyed at teardown. Absence discipline honoured: the SUCCESS-path\r\n  line (`ENGINE_ROOM_BROUGHT_UP`) was also absent from all 40, proving the channel dead rather\r\n  than the event absent.\r\n- **What/why:** product `stderrlog::install` (broker at cli.rs:7633, brain at brainproc.rs:200)\r\n  repoints the process STD_ERROR_HANDLE within its first statements (`redirect_stderr_to`,\r\n  stderrlog.rs:101 — Windows `SetStdHandle` + `mem::forget`), so a rig's `.stderr(File)` capture\r\n  holds only the pre-redirect window; from that line on every diagnostic lands in\r\n  `SPT_HOME/logs/daemon.stderr.log` (stderrlog.rs:34/42) inside the rig's temp home, destroyed\r\n  unread at teardown. Panels are also mislabelled (\"brain stderr\" holding the broker's first\r\n  lines). REQ-DAEMON-STDERR-PERSIST fixed this blindness PRODUCT-side (\"the incident-night\r\n  RCA-blind gap\", cli.rs:7626-7631); no rig was ever taught to read the sink, so the fix does\r\n  not reach any harness. Class: every e2e rig that spawns `spt daemon run` and prints a\r\n  captured-stderr panel has the same void.\r\n- **Remedy:** census all such rigs; failure panels additionally dump\r\n  `SPT_HOME/logs/daemon.stderr.log` with the path read FROM `spt_daemon::stderrlog` (never\r\n  re-spelled), and the labels corrected (\"broker stderr (pre-redirect)\" / \"daemon stderr sink\").\r\n  `engine_room_bringup_e2e.rs`'s panel sites land in the #199 lane (todlando, scoped there —\r\n  measured shape: FIVE producers incl. the :167 precondition panic, SEVEN print sites, seven\r\n  relabels; the early \"four\" was an estimate the file refuted). ⚠ Rigs can only import\r\n  `STDERR_LOG_BASENAME`; the `\"logs\"` dir segment has no exported const, so every rig\r\n  re-spells it — the census lane should add an exported path helper (e.g.\r\n  `stderrlog::sink_path(home)`) to spt-daemon FIRST, then consume it everywhere. The census\r\n  and remainder are hertz-class.\r\n- **Ripe when:** hertz's queue after current items, or the next e2e red printing an empty\r\n  stderr panel.\r\n- **Size:** census + mechanical panel edits per rig.\r\n- **Kin:** [[IR-40]] (an absent signal read as a clean verdict), REQ-DAEMON-STDERR-PERSIST (the\r\n  product half of the same incident), [[IR-8]] (a censused zero that cannot see its blind spot).\r\n\r\n### IR-51 — engine-room e2e daemon runs NET-ENABLED on real interfaces; rig hermeticity is disk-deep only\r\n- **Status:** open — filed 2026-08-19 (todlando's x40 run-4 sink read, the first live read any\r\n  rig has had of the daemon sink; doyle ruled own-id rather than riding #199, at the finder's\r\n  own request) · **Origin:** unasked-for find inside the #199 instrument's first catch.\r\n- **What/why:** the rig's temp `SPT_HOME` buys DISK hermeticity ([[IR-45]]'s settlement — which\r\n  explicitly covered paths, not network) but nothing turns the net off: the run-4 sink shows\r\n  the rig's own daemon with `BRAIN_NET_CONSUMERS_UP` (dispatcher + peer pump started), three\r\n  `NET_FAMILY_GATE: binding IPv4-only`, and three `PAIR_MEET_UP:erhome` carrying the box's REAL\r\n  Tailscale (100.68.35.65) and LAN (192.168.1.81) addresses — live peer work during an e2e —\r\n  plus an `INBOUND_REACHABILITY` warning whose firewall rule admits the CI-runner's binary path\r\n  (`C:\\actions-runner\\_work\\spt-bs-core\\spt-bs-core\\target\\debug\\spt.exe`) while this daemon\r\n  ran from a dev tree. Consequences: test behavior conditioned on shared-box network state;\r\n  rate-shaped flakes; e2e runs radiating real traffic. SAME SINK, RECORDED NOT DIAGNOSED: conn\r\n  churn at ~150 ms cadence (327 write-start / 324 transport-close, conn ids past 300 in 58 s) —\r\n  unattributed. ⚠ CANDIDATE INTERACTION, explicitly NOT established (finder's own framing\r\n  honoured): the run-4 face (30 s bound blown, zero session events in the window, launch Ok, no\r\n  error anywhere) matches the SHAPE of the filed offline-but-resolvable-peer pump-stall\r\n  mechanism (dial does not fast-fail). Discrimination open; nothing here is a #199 attribution.\r\n- **Remedy:** a rig-honoured net-off switch (peer pump + discovery disabled under test unless\r\n  the test is ABOUT them) or loopback-only binding; census which e2e rigs start net consumers.\r\n  Sequencing rule: do NOT fix hermeticity into #199's face before the face is attributed — a\r\n  green bought by turning the net off would bury the mechanism unread.\r\n- **Ripe when:** #199 attribution answers whether net state is causal; else the next\r\n  hermeticity pass.\r\n- **Size:** product switch + rig adoption + census.\r\n- **Kin:** [[IR-45]] (the disk half), the subnet-pump dial-does-not-fast-fail mechanism (filed,\r\n  pump-stall RCA), [[IR-38]] (a live daemon's side effects outliving the test's intent),\r\n  releases#125 gc-spin (a conn-churn shape candidate).\r\n\r\n### IR-53 — failed-address expiry unit panics during the first 10m01s after Windows boot\r\n- **Status:** BUILT 2026-08-21 on `fix/ir53-cold-boot-instant` — LANDED in v0.59.0\r\n  (PORTER rider, pick `7b26f28d` on `assembly/porter-205`, main @`c62904e7`; register\r\n  sweep 2026-08-21 at release close) · **Origin:** todlando,\r\n  found and falsifiably measured mid-releases#204; this rider fixes the latent CI-pipeline\r\n  flake before PORTER golden.\r\n- **Measured:** `failedaddr::tests::an_expired_record_stops_matching_and_is_swept` ages an\r\n  `Instant` with `Instant::now().checked_sub(FAILED_ADDR_TTL + 1s).expect(...)`, where\r\n  `FAILED_ADDR_TTL = 600s`. Windows `Instant` counts from boot, so a host younger than 601s\r\n  cannot represent the requested stamp and panics `monotonic clock older than the TTL`.\r\n  Todlando predicted and observed the red before the threshold, then observed the identical\r\n  tree green after it; two subsequent daemon sweeps held 860/860.\r\n- **Remedy:** when the monotonic clock cannot represent the age, return through the loud\r\n  `SKIP_FAILED_ADDR_EXPIRED_SWEEP` arm naming the exact unproved property. On every warm host\r\n  the original direct aging and both expiry assertions still run unchanged; there is no\r\n  ten-minute sleep and no silent pass on the cold arm.\r\n- **Class census (untruncated):** four test-side\r\n  `Instant::now().checked_sub(...TTL/deadline...).expect(...)` patterns total. This cell is\r\n  the sole 601s member. Three siblings remain recorded, not changed in this rider:\r\n  `broker.rs:8432-8434` and `broker.rs:9198-9200` age\r\n  `CONTROLLER_WRITE_DEADLINE + 1s` (6s), while `broker.rs:10385-10388` ages\r\n  `BRAIN_WRITE_DEADLINE + 1s` (16s). Their much narrower cold-boot windows are the same\r\n  mechanism class and should use a controlled clock seam when next touched.\r\n- **Kin:** releases#204 (finder lane), [[IR-25]] (daemon-lib flake population), and\r\n  [[IR-40]] (a confident verdict without the evidence needed to make it).\r\n\r\n### IR-52 — docs-site CLI reference renders SHALLOW; help text below the rendered depth is outside the drift gate, unit-held per-REQ or held by nothing\r\n- **THIRD INSTANCE, observed 2026-08-24 (todlando, WAX-SEAL #21 W4; not acted on):** the new\r\n  `spt api seal verify|describe` FLAGS sit below the generator's rendered depth — the entry's\r\n  exact class. The W4 user page hand-documents them, which is per-page self-defense, not a\r\n  gate. Conditional-rider condition did NOT fire at W4 (no generator touch); the entry's own\r\n  trigger stands for whichever lane next touches the generator.\r\n- **Status:** BUILT 2026-08-24 on SIGNET #218 W1 T6 (todlando; doyle's intake made it the wave's\r\n  rider when the new `seal enroll-authenticator` verb forced the generator touch that armed the\r\n  trigger): `xtask` reference-gen now DESCENDS THE FULL COMMAND TREE recursively (the durable\r\n  remedy), regen published the 22 previously-unrendered leaves + the new section, and a depth\r\n  regression is a drift RED by construction. Self-holding units censused per the remedy: the\r\n  SURFACE-SECTION-SITED walk and both MONIC-TRIGGER-SECTION sited-help units are now DOUBLE-held\r\n  (published surface under the drift gate + content pins kept) — kept, not retired. · **Origin:**\r\n  todlando's #160 build report, fact flagged for the gate rather than folded silently.\r\n  (Pre-build status: open, filed 2026-08-19 — doyle, W3 #160 gate prep; second measured instance\r\n  of a class REQ-CLI-SURFACE-SECTION-SITED's own title already named for its sites.)\r\n- **What/why:** the generated `docs-site/src/cli/reference.md` renders `spt endpoint monic`\r\n  but does not descend to `monic add` / `monic update`, so the #160 strike of the maintained\r\n  kind enumeration at those two flag docs never appeared in the published reference and the\r\n  docs-drift gate CANNOT see the strike — the REQ-CLI-MONIC-TRIGGER-SECTION rendered-help\r\n  unit is the only hold. General mechanism: any help text below the generator's descent\r\n  depth is invisible to the drift gate; a deep help edit (or regression) ships unpublished\r\n  and ungated unless some REQ's unit happens to pin it. First measured instance:\r\n  REQ-CLI-SURFACE-SECTION-SITED names \"the three-deep sites the docs-site drift gate cannot\r\n  reach\" and closes them with its own pinned walk — per-REQ self-defense, not a gate.\r\n  Consequence beyond drift: adapter builders build BLIND from the public docs (DRI\r\n  protocol), so a deep-help divergence hands every adapter a thinner contract than the\r\n  operator's terminal shows.\r\n- **Remedy:** either xtask reference-gen descends the full command tree (deep help becomes\r\n  published surface the drift gate already covers), or a generic rendered-help walk over all\r\n  sites at all depths joins the drift gate; census which REQ units currently self-hold deep\r\n  sites (known: SURFACE-SECTION-SITED walk, MONIC-TRIGGER-SECTION sited-help unit).\r\n- **Ripe when:** next xtask docs-gen touch, or the first adapter filing traceable to a\r\n  deep-help divergence.\r\n- **Size:** xtask render change + regen + census of self-holding units.\r\n- **Kin:** the REQ-CLI-SURFACE-SECTION-SITED pinned walk (the per-REQ closure shape this\r\n  entry generalizes), [[IR-47]] only if its golden.yml/ci-notify surface rides the same\r\n  docs-gate window.\r\n\r\n### CI-RIDER LANE STATE — LANDED 2026-08-04 (post-v0.53.0 merge queue); history below kept for its mechanisms\r\n- **RESOLVED:** the lane rebased clean onto the post-tag queue and landed ff-only as\r\n  `2b33a47`/`2a7b016`/`d63f4ce`/`19d7f79` (content byte-identical to `1275e47..bf8c4a2` by lane-diff\r\n  blob hash). IR-1 and IR-4 are BUILT AND LANDED; IR-9's measurement half is landed with its trigger\r\n  now armed — the toolchain print reports runner-account versions on the NEXT GOLDEN RUN, which is\r\n  when doyle's 2026-08-03 ruling (decide from runner-account versions, never the interactive prior)\r\n  becomes executable. The two golden-only steps (link probe both boxes, toolchain print both legs)\r\n  remain unexercised until that run — the landing does not change that caveat.\r\n- **As recorded pre-landing (2026-08-04, doyle):** `ci/locksmith-riders` was at `bf8c4a2` with FOUR\r\n  commits not contained in `origin/main` and not present in LOCKSMITH's golden head `b7b00c3`. The\r\n  worktree `.worktrees/hertz-ci-riders` was clean, so the work existed and was simply unlanded:\r\n  `1275e47` (xtask: assert a load-bearing patch pin is still in force, both ways it lapses) ·\r\n  `49d4805` (docs/ci: a lock-touching lane reads edges, not just the package set) ·\r\n  `8ed006b` (ci/golden: print the toolchain that judged the run, both legs) ·\r\n  `bf8c4a2` (ci/golden: measure the link before rendezvous, read the floor after the checkout that\r\n  clears it — the floor read AFTER its own reclaim is [[ci-runner-has-no-warm-target]]'s shape).\r\n- **Why it is recorded rather than quietly re-dispatched:** [[IR-1]]/[[IR-4]]/[[IR-9]] were carried\r\n  as DISPATCHED, which is now false in BOTH directions — the work is further along than dispatched,\r\n  and it also did not ship. The cause was the same agent outage that cost `#123` its build, and the\r\n  operator's standing rule from that drop applies here too: an outage must not be able to remove\r\n  work from a batch silently. Board requests got a drop comment; register entries get this.\r\n- **MAPPING CONFIRMED BY ITS BUILDER 2026-08-04, by REQ id rather than by recollection** — hertz\r\n  noted first that its own context had been cleared between building the lane and answering, and\r\n  declined to testify from memory about the original instrument. Everything here is either measured\r\n  that day or read off the commits:\r\n  `1275e47` → `REQ-CI-LOAD-BEARING-PATCH-PIN` ([[IR-4]] part 1, the mechanical pin guard in xtask) ·\r\n  `49d4805` → `REQ-LOCK-TOUCHING-LANE-PROCEDURE` ([[IR-4]] part 2, procedure in docs/GOLDEN-CI.md) ·\r\n  `8ed006b` → `REQ-CI-TOOLCHAIN-VERSION-PRINT` ([[IR-4]] part 3, carrying [[IR-9]]) ·\r\n  `bf8c4a2` → `REQ-CI-LINK-HEALTH-PROBE` ([[IR-1]], the network axis).\r\n- **CORRECTION TO THE GATER'S EARLIER WORDING, from the builder:** `8ed006b` does NOT discharge\r\n  [[IR-9]] — it discharges IR-9's MEASUREMENT half only. IR-9's other half (align the two boxes, or\r\n  declare one authoritative clippy leg) is held by doyle's own 2026-08-03 ruling: decide once the\r\n  step reports RUNNER-ACCOUNT versions, never on the interactive-account prior. IR-9 therefore stays\r\n  OPEN with its trigger now REACHABLE, which is a different state from \"waiting\".\r\n- **Gate evidence, instrument NAMED:** `cargo nextest run -p xtask` in `.worktrees/hertz-ci-riders`\r\n  on hfenduleam, box quiet with no runs in flight — 34 run, 34 passed, 0 skipped. Nextest rather\r\n  than bare `cargo test`, per [[IR-25]]. ⚠ **What that does NOT cover, stated by the builder rather\r\n  than discovered later:** the two golden steps the lane ADDS (link probe on both boxes, toolchain\r\n  print on both legs) cannot be exercised outside a golden run. The probe's three arms\r\n  (five-sample success, no-reply, absent-CLI) were exercised on the real boxes at commit time, and\r\n  that is reported as a CLAIM RECORDED AT COMMIT TIME, not as a re-verification — the kitsubito arm\r\n  could not be re-checked from here. This is why the lane wants a golden rather than a quiet ff.\r\n- **[[IR-5]]/[[IR-6]] CONDITIONAL RIDERS: CONDITION NOT MET — the answer is NO and it closes the\r\n  question for this lane.** Measured file set `6d291e0..bf8c4a2`: `.gitattributes`,\r\n  `.github/bench/link-probe.ps1`, `.github/bench/link-probe.sh`, `.github/workflows/golden.yml`,\r\n  `crates/xtask/src/main.rs`, `crates/xtask/tests/bench_row_parity.rs`, `docs/GOLDEN-CI.md`,\r\n  `traceable-reqs.toml`. Nothing under `.github/ci/`, where the nextest-summary readers and\r\n  count-reporting scripts live. IR-5: no consumer of nextest output touched. IR-6: no EXISTING gate\r\n  output changed — though the NEW output was voluntarily written to IR-6's rule (the LINK line\r\n  prints `samples=N/M` and the individual rtts, membership beside the count, in both shells). That\r\n  SHRINKS IR-6's future scope by two lines; it does not discharge it.\r\n- **Three mechanisms lifted from this lane's REQ titles, worth more than the lane:**\r\n  (a) **An instrument must not be able to RED the run, and each shell breaks that differently** —\r\n  bash: `| head` under `pipefail` SIGPIPEs the producer to 141, so a print step reds (trim with\r\n  parameter expansion instead); pwsh under GitHub's wrapper: a MISSING COMMAND is a terminating\r\n  error, so rustup's absence must be TESTED with `Get-Command`, never caught. One requirement, two\r\n  constructions, and neither is portable reasoning about the other.\r\n  (b) **A negative-control mutation must be COUNTED before it is trusted** — the absent-CLI arm was\r\n  first \"measured\" against a tree where the mutation had not taken, silently re-measuring the\r\n  unmutated arm and reading as a pass.\r\n  (c) **Jitter, not the median, is the signal on a link that mostly works** — the motivating red's\r\n  link ran 10..83ms and 3..75ms while IDLE, so a median-only probe reads healthy straight through\r\n  the failure. Both med and max rows ride the ledger.\r\n- **Disposition:** composes onto the next golden batch as a thin lane, NOT slipped onto main. It\r\n  changes the golden pipeline itself, so it wants a golden rather than a quiet ff — and while\r\n  v0.53.0 is untagged, any push to `main` moves the runbook's bare `git tag` off the tested sha.\r\n\r\n### IR-55 — the `spt --bins` suite wedges partway through on leaked `findstr .` PTY children; the tests at the frontier are casualties, not culprits\r\n\r\n- **Status:** OPEN, **ARMED-FOR-CAPTURE**, owned by **hertz**. Test/rig defect by the dispatch\r\n  split (test/CI rework is never the product builder's). Filed by doyle 2026-08-22 from the\r\n  TURNKEY #212 W3 gate on releases#213.\r\n- **CORRECTED BY REPLACEMENT the same day.** This entry first named\r\n  `cli::tests::adapter_profile_verbs_local_only` as the wedging test, because that is where the\r\n  streamed frontier stopped. **That was wrong, and the correction is the useful part of the\r\n  entry:** run in isolation, on the same pool and binary and with the same env, that test passes\r\n  in **0.02s**. So do the other two the suite later stalled on —\r\n  `cli::tests::shell_channels_relay_sensory_and_text_file` (0.20s) and\r\n  `cli::tests::resolve_proof_target_override_reads_on_disk` (0.00s), each 1 passed / 652 filtered.\r\n  **A frontier names where progress STOPPED, not what CAUSED it.** Naming the last test printed\r\n  is the same error shape as reading a stack frame as a root cause, and it would have sent hertz\r\n  to rewrite three innocent tests.\r\n- **What is actually measured:**\r\n  - `cargo test -p spt --bins` unfiltered sat **24 minutes** at 13.5s CPU — blocked, not spinning.\r\n  - Re-run with `--test-threads=1` and streaming output: stalled after **183** completed.\r\n  - Re-run again with that frontier test skipped: progressed to **335** completed, then stalled\r\n    with **two** tests simultaneously past libtest's 60-second notice. Skipping one casualty\r\n    simply moves the frontier, which is itself evidence the fault is not in any one test.\r\n  - Every wedged harness carried `findstr.exe .` children under `conhost.exe --headless`.\r\n    **`findstr` with no file argument reads STDIN and blocks forever.**\r\n  - The frontier tests are **byte-identical at `c62904e7` and at the #213 tip `3d69f77c`**\r\n    (function bodies hashed at both blobs), so nothing in that lane introduced this.\r\n- **Reading, stated as a reading rather than a conclusion:** an EARLIER test spawns the `findstr`\r\n  stand-in as a PTY child and does not reap it; the children accumulate across the run and a later\r\n  test blocks behind them. Which test leaks is NOT yet identified and this entry does not guess —\r\n  the next step is to bisect for the leaker rather than to touch any test at the frontier. Five\r\n  orphaned `findstr` processes with creation times spread across the day were observed on this box\r\n  independently of any single run, which is consistent with accumulation across many suite runs.\r\n- **Hypothesis RAISED AND NOT SUPPORTED, recorded so nobody re-runs it:** the gate scrubs\r\n  `OWL_SESSION_ID` / `SPT_AGENT_ID` / `SPT_ENDPOINT_ID`, and a scrubbed identity was suspected of\r\n  routing a normally-REFUSED test down a live PTY path. The isolation runs above were performed\r\n  **with the scrub applied** and passed, so the scrub alone does not produce the hang. It remains\r\n  unexplained why the same unfiltered command completed at 652 passed / 1 failed for another agent\r\n  on the same tree; do not treat the scrub as the differentiator without a fresh one-variable run.\r\n- **Why it is register-grade:** golden CI runs the `spt` package. A test that never returns cannot\r\n  red — it consumes the single self-hosted runner slot until the job timeout, which `golden.yml`'s\r\n  50-minute cap bounds rather than fixes. A wedge that fires only sometimes is worse than a red,\r\n  because the suite's green record stays intact and nobody audits it — the same self-concealing\r\n  shape as `exit-code-after-a-pipe-is-the-tails`.\r\n- **Trigger condition (ripe):** any milestone whose gate wants an unfiltered `spt --bins` sweep,\r\n  which is every one of them. Ripe now.\r\n- **REMEDY, MEASURED 2026-08-22 and it changes this entry's urgency:** the same 653 tests under\r\n  `cargo nextest run -p spt --bins --no-fail-fast` complete in **22.2 seconds, 653 passed, 0\r\n  skipped, exit 0** — no slow markers, no timeouts — on the very tree and pool where\r\n  `cargo test -p spt --bins` wedged indefinitely twice. **nextest runs each test in its OWN\r\n  process**, so a leaked `findstr` child can block only itself. This is the discriminating\r\n  measurement rather than a workaround reached for to get a green: **the suite is not broken; the\r\n  SINGLE-PROCESS harness is what lets one test's leaked child wedge every test after it.** Golden\r\n  CI already runs nextest, which is the likely reason this has never surfaced there — the exposure\r\n  is to anyone running bare `cargo test` on the `spt` package, which is every local gate.\r\n- **Count reconciliation, recorded so the figures are not read as a discrepancy:** runs of this\r\n  suite report 652 passed / 1 failed where the one failure is\r\n  `cli::tests::adapter_translate_proof_gates_on_commit` — the `--bins`-only artifact, which\r\n  refuses because `translate_proof_fixture.exe` is not built under a bins-only invocation and says\r\n  so in its own message. Prebuilding it (`cargo build -p spt --bin translate_proof_fixture`) makes\r\n  it pass: 652 + 1 = 653. Prebuild the fixture rather than carrying a known-red through every gate.\r\n- **⚠ AMENDED 2026-08-22 — DO NOT PREBUILD FROM THIS BULLET'S EXAMPLE.** The line above names ONE\r\n  fixture because one fixture is what *this* wedge needed; read as the prebuild recipe it covers a\r\n  fraction of the population, and it was read that way twice on one day. **The census already exists\r\n  in IR-21 above** (`adapters/mock`: mock-session, mock-shell, capture-player, console-mode-probe ·\r\n  `crates/spt-daemon`: dispatch_fixture, service_fixture, summarizer_fixture · `crates/spt`:\r\n  translate_proof_fixture, post_step_fixture, gh_fixture, git_fixture), together with the split that\r\n  matters: **cross-package sites are the hazard members; same-package builds are guaranteed by\r\n  construction.** Field instances, both 2026-08-22 TURNKEY #212 W4: todlando's lane red on three\r\n  `spt-daemon::attach_resize_capture` cells wanting `adapters/mock`'s **capture-player** (a\r\n  cross-package member), and doyle's head gate prebuilding the remembered pair while never running a\r\n  `spt-daemon` or `spt-term` suite at all. **Prebuild `--workspace --bins`, or read the\r\n  `build_hint` the helper already composes** (`crates/spt-term/tests/support/fixture_bin.rs:42`) —\r\n  five test files gate on that panic. Neither of us lacked the census; we prebuilt from memory while\r\n  our own register held the list.\r\n- **FIXTURE PREBUILD, RECURRENCE 2026-08-29 (todlando, emission lane):** the rule was\r\n  already banked AND I am one of its authors, and I still ate three fixture reds in a row —\r\n  mock-session, then capture-player, then mock-shell — each tripping in about 0.01s with a panic\r\n  that reads exactly like a test failure. Having the rule is not the same as applying it completely:\r\n  I prebuilt from RECALL (`-p spt --bins`) rather than from the rule's stronger banked form, and the\r\n  tell is that my fix arrived in three instalments instead of once. **TWO FACES, both structural\r\n  rather than careless.** (1) THE FIXTURE MAY LIVE IN ANOTHER PACKAGE — mock-session,\r\n  capture-player, mock-shell and console-mode-probe are all `adapters/mock` (`-p mock-adapter`), so\r\n  no amount of `-p spt --bins` ever produces them. (2) ENUMERATING FIXTURES BY GREPPING THEIR\r\n  PRE-BUILD STRINGS IS STRUCTURALLY INCOMPLETE — it finds the call sites that embed a literal\r\n  `pre-build: cargo build ...` string and CANNOT find mock-shell, whose helper composes the command\r\n  at runtime (`sibling_bin(name)` → `fixture_package(name)`), so there is no literal to match. A\r\n  predicate over source text cannot see a string the program builds at runtime; same blindness\r\n  class as the emission census's TOKEN-colon-vs-TOKEN-space predicate, met twice in one session.\r\n  **CLASS FIX:** never hand-list fixtures — build the whole fixture package\r\n  (`cargo build -p mock-adapter --bins`) or `--workspace --bins` before any\r\n  `--test`/`--bins`/filtered leg. Chasing named fixtures one red at a time only ever finds them one\r\n  at a time, and each one costs a full battery run.\r\n- **Named negative + settle-class result (hertz, 2026-08-23):** current main at\r\n  `4dd699cb7867979ca0497e7c74d8d0aaf881e9e9` did not reproduce the wedge on HFENDULEAM from\r\n  isolated checkout `.worktrees/ir55-findstr-bisect`. Test binaries were freshly built before the\r\n  diagnostic population and reused for the settle sweep; the gate environment scrub was **not**\r\n  applied; the installed daemon was live. The fleet snapshot taken immediately **after**, not\r\n  during, the sweep showed BIGNET 7 nodes / 20 endpoints, SPT_MANTLE 3 / 19, SPT_DEV 2 / 19,\r\n  3-of-7 peers connected, `degraded-partial`. Four startup cells that spawn `findstr` passed alone\r\n  and reaped their observed ConPTY children; a full single-threaded run passed 663/663 with a\r\n  before/after census delta of `IR55_NEW=0`. The ratified settle-class sweep then ran five\r\n  consecutive bare `cargo test -p spt --bins` invocations: all 663/663 green in 420.35s total,\r\n  with zero `findstr.exe` residents before and after. This is a named negative data point, not a\r\n  discharge of the intermittent filing-day measurements.\r\n- **Next-wedge capture protocol — do not improvise or clean first:** preserve the exact bare\r\n  invocation and snapshot the environment (box, checkout SHA/worktree, fresh-versus-reused test\r\n  binary provenance, gate-scrub state, live-daemon state, and fleet roster); stream test output to\r\n  durable storage so the last started and completed test names identify the frontier; census\r\n  `Win32_Process` immediately before the run and again while wedged, recording each `findstr.exe`\r\n  PID, parent PID, creation time, executable path, and command line. **Do not kill any child before\r\n  the second census is banked.** The 22 residents found during the 2026-08-23 investigation were\r\n  path-verified as `C:\\Windows\\System32\\findstr.exe`, shown to predate its live runs, banked, then\r\n  reaped; the pre-sweep and post-sweep resident counts were both zero.\r\n- **Size guess:** small if one test is missing a reap or an EOF for its stand-in child; medium if\r\n  the shared PTY test scaffolding needs the reap, in which case every sibling spawning the same\r\n  stand-in wants it. The RUN-LEVEL exposure has an answer today (nextest); the LEAK itself is\r\n  still worth fixing, because a leaked child per run accumulates on any box that runs the suite.\r\n- **Gater's craft, worth more than the entry itself:**\r\n  (a) The first wedge was undiagnosable because the gate script wrote every leg as\r\n  `cargo test … | tail -N > file` — nothing reaches disk until the command completes, so a wedged\r\n  leg produces an **empty file** and the process table is the only witness. **Stream to a file and\r\n  tail the FILE.**\r\n  (b) To NAME a frontier, run `--test-threads=1`: libtest prints each test's name BEFORE running\r\n  it, so the last incomplete line is where progress stopped.\r\n  (c) **Then prove the frontier test is actually at fault by running it alone** — which is the\r\n  step this entry originally skipped, and the one that turned a wrong entry into a right one.\r\n\r\n### IR-56 — `pool-claim` harvests lane identity from CWD, not from `--pool`; a claim run from the wrong tree writes a WRONG RECORD with a success message\r\n\r\n- **Status:** BUILT 2026-08-24 for the SIGNET #218 golden batch on\r\n  `fix/ir56-pool-claim-cwd`, owned by **hertz**. Tooling/rig defect by the dispatch split. Filed by\r\n  doyle 2026-08-22 from todlando's TURNKEY #212 W4 Lane 1 field instance — the first confirmation\r\n  of the IR-42 mechanism from a LANE rather than from a source read.\r\n- **What happens:** `cargo run -p xtask -- pool-claim --pool <dir> --label <lane>` records the lane\r\n  identity it harvests from the **current working directory** — `owner_tree`, `lane_branch`, and the\r\n  base sha — not from the tree `--pool` names. Run it from the project root with `--pool` aimed at a\r\n  worktree and the record reads `owner_tree = <project root>, lane_branch = <root's branch>` while\r\n  every artifact in that pool belongs to the worktree. The verb prints its ordinary success line\r\n  naming the wrong owner, and returns 0.\r\n- **Why it is silent, which is the whole entry:** the claim verb WRITES and never adjudicates\r\n  (IR-42) — every enforcement arm lives in `crates/spt-store/build.rs` and speaks only at the next\r\n  BUILD. So a wrong record has no symptom at the moment it is created; the first signal is a build\r\n  refusal minutes later, on a lane whose `--pool` argument was correct all along. **`--pool` being\r\n  correct is not evidence the record is.** Nothing on the command line shows you cwd, which is the\r\n  one input that decided the outcome.\r\n- **Recovery is the documented hatch, and the bootstrap is why:** the claim tool builds THROUGH the\r\n  pool it is claiming, so a pool already refusing cannot be re-claimed by the ordinary route. The\r\n  refusal text says so itself — meaning the bootstrap case is known, and a wrong-cwd claim is the\r\n  ordinary way a lane lands in it.\r\n- **The rule, as a must-do:** claim from the lane's own worktree so the identity the verb harvests\r\n  is the lane's — `( cd <lane> && cargo run -p xtask -- pool-claim --pool \"$PWD/target\" … )`, or any\r\n  form that makes cwd explicit. Then READ THE PRINTED RECORD BACK and confirm `owner_tree` and\r\n  `branch` name the lane: the success line carries the record, so the check costs nothing.\r\n- **Trigger condition:** ripe now — it is a doc/UX fix on a verb we run every lane. Ripest alongside\r\n  any other `xtask` pool-verb touch.\r\n- **Size guess:** small. Either make the verb REFUSE when cwd is not inside the tree containing\r\n  `--pool` (loud, and it cannot be wrong), or print the harvested identity as a distinct confirmed\r\n  line. The refusing form is preferred: it removes the reading step rather than adding one.\r\n- **Built evidence, corrected at review:** `pool-claim` resolves the git worktree containing\r\n  `--pool` from the pool's nearest existing ancestor and compares it with the cwd worktree before\r\n  writing. An accidental cross-worktree call returns 2, names both worktrees and the remedy, and\r\n  leaves the not-yet-existing pool absent. The sanctioned sequential takeover carries an explicit\r\n  `--foreign-pool`, says that it is harvesting the arriving cwd identity, writes that identity, and\r\n  returns 0. Both poolguard refusal remedies now print that flag. An executable xtask test drives\r\n  both arms against two real temporary git repositories, pinning VERB-ADMITS-REMEDY rather than\r\n  merely testing path equality. This remains identity-harvest validation only: the claim still\r\n  writes without adjudicating admission, so IR-42's enforcement boundary remains in the build.\r\n\r\n### IR-57 — an assembly pick's conflict resolution can silently DROP lines, and every gate run at assembly time is blind to it\r\n\r\n- **Status:** OPEN, owned by **doyle** (gater craft, not a code defect — no lane to dispatch).\r\n  Filed 2026-08-22 from doyle's own defect on the TURNKEY #212 assembly head.\r\n- **What happened:** assembly head `5cce533d` **did not compile**, and was carried across a session\r\n  boundary as a ready head with \"treqs exit 0\" attached to it. `crates/spt-store/src/access.rs` had\r\n  an unclosed `mod tests`: the cherry-pick of the #206 lane commit `b2194aa9` conflicted against the\r\n  #209 test block — both add functions to the same region, and the two sides share the trailing\r\n  `);` / `}` / `}` — and the resolution deleted the markers without restoring the FIRST side's\r\n  function closer. Exactly two lines lost: `        );` and `    }`.\r\n- **Every instrument in the assembly path reported success:** `git cherry-pick` completed with no\r\n  conflict remaining; `traceable-reqs check` returned 797/797, 0 findings, exit 0 — **it parses\r\n  tags and never invokes the compiler**; and the lanes themselves were green and stayed provably\r\n  clean (the #206 lane's brace balance is correct at all five of its commits). **Lane-green plus\r\n  conflict-free is not a claim about the assembled head.** Same lesson as the #182 v2 assembly\r\n  (`E0425`×4) by a different mechanism: that one was a semantic composition break between two\r\n  correct hunks, this one is a fidelity LOSS during resolution.\r","truncated":true,"truncatedBy":"lines","totalLines":3057,"totalBytes":35264,"outputLines":404,"outputBytes":35264,"lastLinePartial":false,"firstLineExceedsLimit":false},"totalLines":5781,"displayContent":{"text":"### IR-49 — poolguard's landed-lane predicate is ancestry-only, so a cherry-picked member lane can never read Settled and its pool can never be taken over\n- **Status:** open — filed 2026-08-19 (todlando measurement at the keystone-w1/fix-197 reap,\n…\n- **Kin:** [[IR-26]] (dead-holder takeover AUTHORIZED when it shouldn't be — this is the mirror:\n…\n\r\n### IR-50 — e2e failure panels read the PRE-REDIRECT stderr capture; every daemon-side diagnostic lands in a sink the rig deletes unread\r\n- **Status:** CLOSED — BUILT 2026-08-19; adoption-completion lane\r\n  `docs/ir50-register-close` @`e02f565f` (hertz, doyle-gated 2026-08-20) LANDED in\r\n  v0.59.0 as a PORTER rider (pick `e702d4b7` tip, main @`c62904e7`; register sweep\r\n  2026-08-21) — lane `fix/ir50-stderr-sink-census` @`1a2f6a2`+`2ac9543`\r\n  (hertz; base `0c86b2d`; rides the CONCIERGE #183 chain; these shas are the 2026-08-19\r\n  message-only reword of `cb4cd9d`+`7336e03` — trees proved identical by tree-id, so every\r\n  measurement below carries): exported\r\n  `spt_daemon::stderrlog::sink_path(home)` with `stderr_log_path` routed through it +\r\n  equality unit; `daemon_stderr_panel` in tests/common renders BOTH channels and labels a\r\n  read failure with channel + exact looked-at path + OS error (absent-sink regression pins\r\n  it — the IR-40 unlabelled-absence class was caught at gate and fixed in `2ac9543`);\r\n  censused every daemon-run captured-stderr panel outside `engine_room_bringup_e2e` (rides\r\n  #199 lane) and `er_briefing_*` (rides #164 lane); engineroom.rs:145 misnomer rider landed\r\n  in the same lane. Gate figure 781/781 at `2ac9543` (measured at the pre-reword tree,\r\n  which is byte-identical; first-report 765 was transcription,\r\n  corrected with raw line + JSON provenance). CLASS FOLD (doyle ruling, no fresh row):\r\n  `er_briefing_presented_e2e` hit this exact class during its own authoring (blank panels\r\n  on a real loud line) and was fixed locally in `72efb6a` reading both channels.\r\n  **REGISTER CLOSED 2026-08-19:** branch `docs/ir50-register-close` links the\r\n  golden-tested implementation at `4661bc9d` and completes helper adoption in the five measured\r\n  residual files: `er_brief_once_per_session_e2e.rs`, `er_briefing_presented_e2e.rs`,\r\n  `er_sequestered_cwd_e2e.rs`, `endpoint_autostart_e2e.rs`, and `n1_pairing.rs`.\r\n  `engine_room_bringup_e2e` remains the explicit exclusion, recorded as todlando's direct\r\n  sink-path read from the #199 lane. ·\r\n  **Originally filed:** 2026-08-19 (todlando RCA inside the #199 investigation; the immediate\r\n  four-panel fix in `engine_room_bringup_e2e.rs` is his and rides the #199 lane — THIS entry is\r\n  the class census, hertz-class) · **Origin:** the #199 evidence void — 40 rca-v2 runs held zero\r\n  daemon-side evidence for either erhost face; `ENGINE_ROOM_SPAWN_FAIL` (broker.rs:5658) was\r\n  written to a log the rig destroyed at teardown. Absence discipline honoured: the SUCCESS-path\r\n  line (`ENGINE_ROOM_BROUGHT_UP`) was also absent from all 40, proving the channel dead rather\r\n  than the event absent.\r\n- **What/why:** product `stderrlog::install` (broker at cli.rs:7633, brain at brainproc.rs:200)\r\n  repoints the process STD_ERROR_HANDLE within its first statements (`redirect_stderr_to`,\r\n  stderrlog.rs:101 — Windows `SetStdHandle` + `mem::forget`), so a rig's `.stderr(File)` capture\r\n  holds only the pre-redirect window; from that line on every diagnostic lands in\r\n  `SPT_HOME/logs/daemon.stderr.log` (stderrlog.rs:34/42) inside the rig's temp home, destroyed\r\n  unread at teardown. Panels are also mislabelled (\"brain stderr\" holding the broker's first\r\n  lines). REQ-DAEMON-STDERR-PERSIST fixed this blindness PRODUCT-side (\"the incident-night\r\n  RCA-blind gap\", cli.rs:7626-7631); no rig was ever taught to read the sink, so the fix does\r\n  not reach any harness. Class: every e2e rig that spawns `spt daemon run` and prints a\r\n  captured-stderr panel has the same void.\r\n- **Remedy:** census all such rigs; failure panels additionally dump\r\n  `SPT_HOME/logs/daemon.stderr.log` with the path read FROM `spt_daemon::stderrlog` (never\r\n  re-spelled), and the labels corrected (\"broker stderr (pre-redirect)\" / \"daemon stderr sink\").\r\n  `engine_room_bringup_e2e.rs`'s panel sites land in the #199 lane (todlando, scoped there —\r\n  measured shape: FIVE producers incl. the :167 precondition panic, SEVEN print sites, seven\r\n  relabels; the early \"four\" was an estimate the file refuted). ⚠ Rigs can only import\r\n  `STDERR_LOG_BASENAME`; the `\"logs\"` dir segment has no exported const, so every rig\r\n  re-spells it — the census lane should add an exported path helper (e.g.\r\n  `stderrlog::sink_path(home)`) to spt-daemon FIRST, then consume it everywhere. The census\r\n  and remainder are hertz-class.\r\n- **Ripe when:** hertz's queue after current items, or the next e2e red printing an empty\r\n  stderr panel.\r\n- **Size:** census + mechanical panel edits per rig.\r\n- **Kin:** [[IR-40]] (an absent signal read as a clean verdict), REQ-DAEMON-STDERR-PERSIST (the\r\n  product half of the same incident), [[IR-8]] (a censused zero that cannot see its blind spot).\r\n\r\n### IR-51 — engine-room e2e daemon runs NET-ENABLED on real interfaces; rig hermeticity is disk-deep only\r\n- **Status:** open — filed 2026-08-19 (todlando's x40 run-4 sink read, the first live read any\r\n  rig has had of the daemon sink; doyle ruled own-id rather than riding #199, at the finder's\r\n  own request) · **Origin:** unasked-for find inside the #199 instrument's first catch.\r\n- **What/why:** the rig's temp `SPT_HOME` buys DISK hermeticity ([[IR-45]]'s settlement — which\r\n  explicitly covered paths, not network) but nothing turns the net off: the run-4 sink shows\r\n  the rig's own daemon with `BRAIN_NET_CONSUMERS_UP` (dispatcher + peer pump started), three\r\n  `NET_FAMILY_GATE: binding IPv4-only`, and three `PAIR_MEET_UP:erhome` carrying the box's REAL\r\n  Tailscale (100.68.35.65) and LAN (192.168.1.81) addresses — live peer work during an e2e —\r\n  plus an `INBOUND_REACHABILITY` warning whose firewall rule admits the CI-runner's binary path\r\n  (`C:\\actions-runner\\_work\\spt-bs-core\\spt-bs-core\\target\\debug\\spt.exe`) while this daemon\r\n  ran from a dev tree. Consequences: test behavior conditioned on shared-box network state;\r\n  rate-shaped flakes; e2e runs radiating real traffic. SAME SINK, RECORDED NOT DIAGNOSED: conn\r\n  churn at ~150 ms cadence (327 write-start / 324 transport-close, conn ids past 300 in 58 s) —\r\n  unattributed. ⚠ CANDIDATE INTERACTION, explicitly NOT established (finder's own framing\r\n  honoured): the run-4 face (30 s bound blown, zero session events in the window, launch Ok, no\r\n  error anywhere) matches the SHAPE of the filed offline-but-resolvable-peer pump-stall\r\n  mechanism (dial does not fast-fail). Discrimination open; nothing here is a #199 attribution.\r\n- **Remedy:** a rig-honoured net-off switch (peer pump + discovery disabled under test unless\r\n  the test is ABOUT them) or loopback-only binding; census which e2e rigs start net consumers.\r\n  Sequencing rule: do NOT fix hermeticity into #199's face before the face is attributed — a\r\n  green bought by turning the net off would bury the mechanism unread.\r\n- **Ripe when:** #199 attribution answers whether net state is causal; else the next\r\n  hermeticity pass.\r\n- **Size:** product switch + rig adoption + census.\r\n- **Kin:** [[IR-45]] (the disk half), the subnet-pump dial-does-not-fast-fail mechanism (filed,\r\n  pump-stall RCA), [[IR-38]] (a live daemon's side effects outliving the test's intent),\r\n  releases#125 gc-spin (a conn-churn shape candidate).\r\n\r\n### IR-53 — failed-address expiry unit panics during the first 10m01s after Windows boot\r\n- **Status:** BUILT 2026-08-21 on `fix/ir53-cold-boot-instant` — LANDED in v0.59.0\r\n  (PORTER rider, pick `7b26f28d` on `assembly/porter-205`, main @`c62904e7`; register\r\n  sweep 2026-08-21 at release close) · **Origin:** todlando,\r\n  found and falsifiably measured mid-releases#204; this rider fixes the latent CI-pipeline\r\n  flake before PORTER golden.\r\n- **Measured:** `failedaddr::tests::an_expired_record_stops_matching_and_is_swept` ages an\r\n  `Instant` with `Instant::now().checked_sub(FAILED_ADDR_TTL + 1s).expect(...)`, where\r\n  `FAILED_ADDR_TTL = 600s`. Windows `Instant` counts from boot, so a host younger than 601s\r\n  cannot represent the requested stamp and panics `monotonic clock older than the TTL`.\r\n  Todlando predicted and observed the red before the threshold, then observed the identical\r\n  tree green after it; two subsequent daemon sweeps held 860/860.\r\n- **Remedy:** when the monotonic clock cannot represent the age, return through the loud\r\n  `SKIP_FAILED_ADDR_EXPIRED_SWEEP` arm naming the exact unproved property. On every warm host\r\n  the original direct aging and both expiry assertions still run unchanged; there is no\r\n  ten-minute sleep and no silent pass on the cold arm.\r\n- **Class census (untruncated):** four test-side\r\n  `Instant::now().checked_sub(...TTL/deadline...).expect(...)` patterns total. This cell is\r\n  the sole 601s member. Three siblings remain recorded, not changed in this rider:\r\n  `broker.rs:8432-8434` and `broker.rs:9198-9200` age\r\n  `CONTROLLER_WRITE_DEADLINE + 1s` (6s), while `broker.rs:10385-10388` ages\r\n  `BRAIN_WRITE_DEADLINE + 1s` (16s). Their much narrower cold-boot windows are the same\r\n  mechanism class and should use a controlled clock seam when next touched.\r\n- **Kin:** releases#204 (finder lane), [[IR-25]] (daemon-lib flake population), and\r\n  [[IR-40]] (a confident verdict without the evidence needed to make it).\r\n\r\n### IR-52 — docs-site CLI reference renders SHALLOW; help text below the rendered depth is outside the drift gate, unit-held per-REQ or held by nothing\r\n- **THIRD INSTANCE, observed 2026-08-24 (todlando, WAX-SEAL #21 W4; not acted on):** the new\r\n  `spt api seal verify|describe` FLAGS sit below the generator's rendered depth — the entry's\r\n  exact class. The W4 user page hand-documents them, which is per-page self-defense, not a\r\n  gate. Conditional-rider condition did NOT fire at W4 (no generator touch); the entry's own\r\n  trigger stands for whichever lane next touches the generator.\r\n- **Status:** BUILT 2026-08-24 on SIGNET #218 W1 T6 (todlando; doyle's intake made it the wave's\r\n  rider when the new `seal enroll-authenticator` verb forced the generator touch that armed the\r\n  trigger): `xtask` reference-gen now DESCENDS THE FULL COMMAND TREE recursively (the durable\r\n  remedy), regen published the 22 previously-unrendered leaves + the new section, and a depth\r\n  regression is a drift RED by construction. Self-holding units censused per the remedy: the\r\n  SURFACE-SECTION-SITED walk and both MONIC-TRIGGER-SECTION sited-help units are now DOUBLE-held\r\n  (published surface under the drift gate + content pins kept) — kept, not retired. · **Origin:**\r\n  todlando's #160 build report, fact flagged for the gate rather than folded silently.\r\n  (Pre-build status: open, filed 2026-08-19 — doyle, W3 #160 gate prep; second measured instance\r\n  of a class REQ-CLI-SURFACE-SECTION-SITED's own title already named for its sites.)\r\n- **What/why:** the generated `docs-site/src/cli/reference.md` renders `spt endpoint monic`\r\n  but does not descend to `monic add` / `monic update`, so the #160 strike of the maintained\r\n  kind enumeration at those two flag docs never appeared in the published reference and the\r\n  docs-drift gate CANNOT see the strike — the REQ-CLI-MONIC-TRIGGER-SECTION rendered-help\r\n  unit is the only hold. General mechanism: any help text below the generator's descent\r\n  depth is invisible to the drift gate; a deep help edit (or regression) ships unpublished\r\n  and ungated unless some REQ's unit happens to pin it. First measured instance:\r\n  REQ-CLI-SURFACE-SECTION-SITED names \"the three-deep sites the docs-site drift gate cannot\r\n  reach\" and closes them with its own pinned walk — per-REQ self-defense, not a gate.\r\n  Consequence beyond drift: adapter builders build BLIND from the public docs (DRI\r\n  protocol), so a deep-help divergence hands every adapter a thinner contract than the\r\n  operator's terminal shows.\r\n- **Remedy:** either xtask reference-gen descends the full command tree (deep help becomes\r\n  published surface the drift gate already covers), or a generic rendered-help walk over all\r\n  sites at all depths joins the drift gate; census which REQ units currently self-hold deep\r\n  sites (known: SURFACE-SECTION-SITED walk, MONIC-TRIGGER-SECTION sited-help unit).\r\n- **Ripe when:** next xtask docs-gen touch, or the first adapter filing traceable to a\r\n  deep-help divergence.\r\n- **Size:** xtask render change + regen + census of self-holding units.\r\n- **Kin:** the REQ-CLI-SURFACE-SECTION-SITED pinned walk (the per-REQ closure shape this\r\n  entry generalizes), [[IR-47]] only if its golden.yml/ci-notify surface rides the same\r\n  docs-gate window.\r\n\r\n### CI-RIDER LANE STATE — LANDED 2026-08-04 (post-v0.53.0 merge queue); history below kept for its mechanisms\r\n- **RESOLVED:** the lane rebased clean onto the post-tag queue and landed ff-only as\r\n  `2b33a47`/`2a7b016`/`d63f4ce`/`19d7f79` (content byte-identical to `1275e47..bf8c4a2` by lane-diff\r\n  blob hash). IR-1 and IR-4 are BUILT AND LANDED; IR-9's measurement half is landed with its trigger\r\n  now armed — the toolchain print reports runner-account versions on the NEXT GOLDEN RUN, which is\r\n  when doyle's 2026-08-03 ruling (decide from runner-account versions, never the interactive prior)\r\n  becomes executable. The two golden-only steps (link probe both boxes, toolchain print both legs)\r\n  remain unexercised until that run — the landing does not change that caveat.\r\n- **As recorded pre-landing (2026-08-04, doyle):** `ci/locksmith-riders` was at `bf8c4a2` with FOUR\r\n  commits not contained in `origin/main` and not present in LOCKSMITH's golden head `b7b00c3`. The\r\n  worktree `.worktrees/hertz-ci-riders` was clean, so the work existed and was simply unlanded:\r\n  `1275e47` (xtask: assert a load-bearing patch pin is still in force, both ways it lapses) ·\r\n  `49d4805` (docs/ci: a lock-touching lane reads edges, not just the package set) ·\r\n  `8ed006b` (ci/golden: print the toolchain that judged the run, both legs) ·\r\n  `bf8c4a2` (ci/golden: measure the link before rendezvous, read the floor after the checkout that\r\n  clears it — the floor read AFTER its own reclaim is [[ci-runner-has-no-warm-target]]'s shape).\r\n- **Why it is recorded rather than quietly re-dispatched:** [[IR-1]]/[[IR-4]]/[[IR-9]] were carried\r\n  as DISPATCHED, which is now false in BOTH directions — the work is further along than dispatched,\r\n  and it also did not ship. The cause was the same agent outage that cost `#123` its build, and the\r\n  operator's standing rule from that drop applies here too: an outage must not be able to remove\r\n  work from a batch silently. Board requests got a drop comment; register entries get this.\r\n- **MAPPING CONFIRMED BY ITS BUILDER 2026-08-04, by REQ id rather than by recollection** — hertz\r\n  noted first that its own context had been cleared between building the lane and answering, and\r\n  declined to testify from memory about the original instrument. Everything here is either measured\r\n  that day or read off the commits:\r\n  `1275e47` → `REQ-CI-LOAD-BEARING-PATCH-PIN` ([[IR-4]] part 1, the mechanical pin guard in xtask) ·\r\n  `49d4805` → `REQ-LOCK-TOUCHING-LANE-PROCEDURE` ([[IR-4]] part 2, procedure in docs/GOLDEN-CI.md) ·\r\n  `8ed006b` → `REQ-CI-TOOLCHAIN-VERSION-PRINT` ([[IR-4]] part 3, carrying [[IR-9]]) ·\r\n  `bf8c4a2` → `REQ-CI-LINK-HEALTH-PROBE` ([[IR-1]], the network axis).\r\n- **CORRECTION TO THE GATER'S EARLIER WORDING, from the builder:** `8ed006b` does NOT discharge\r\n  [[IR-9]] — it discharges IR-9's MEASUREMENT half only. IR-9's other half (align the two boxes, or\r\n  declare one authoritative clippy leg) is held by doyle's own 2026-08-03 ruling: decide once the\r\n  step reports RUNNER-ACCOUNT versions, never on the interactive-account prior. IR-9 therefore stays\r\n  OPEN with its trigger now REACHABLE, which is a different state from \"waiting\".\r\n- **Gate evidence, instrument NAMED:** `cargo nextest run -p xtask` in `.worktrees/hertz-ci-riders`\r\n  on hfenduleam, box quiet with no runs in flight — 34 run, 34 passed, 0 skipped. Nextest rather\r\n  than bare `cargo test`, per [[IR-25]]. ⚠ **What that does NOT cover, stated by the builder rather\r\n  than discovered later:** the two golden steps the lane ADDS (link probe on both boxes, toolchain\r\n  print on both legs) cannot be exercised outside a golden run. The probe's three arms\r\n  (five-sample success, no-reply, absent-CLI) were exercised on the real boxes at commit time, and\r\n  that is reported as a CLAIM RECORDED AT COMMIT TIME, not as a re-verification — the kitsubito arm\r\n  could not be re-checked from here. This is why the lane wants a golden rather than a quiet ff.\r\n- **[[IR-5]]/[[IR-6]] CONDITIONAL RIDERS: CONDITION NOT MET — the answer is NO and it closes the\r\n  question for this lane.** Measured file set `6d291e0..bf8c4a2`: `.gitattributes`,\r\n  `.github/bench/link-probe.ps1`, `.github/bench/link-probe.sh`, `.github/workflows/golden.yml`,\r\n  `crates/xtask/src/main.rs`, `crates/xtask/tests/bench_row_parity.rs`, `docs/GOLDEN-CI.md`,\r\n  `traceable-reqs.toml`. Nothing under `.github/ci/`, where the nextest-summary readers and\r\n  count-reporting scripts live. IR-5: no consumer of nextest output touched. IR-6: no EXISTING gate\r\n  output changed — though the NEW output was voluntarily written to IR-6's rule (the LINK line\r\n  prints `samples=N/M` and the individual rtts, membership beside the count, in both shells). That\r\n  SHRINKS IR-6's future scope by two lines; it does not discharge it.\r\n- **Three mechanisms lifted from this lane's REQ titles, worth more than the lane:**\r\n  (a) **An instrument must not be able to RED the run, and each shell breaks that differently** —\r\n  bash: `| head` under `pipefail` SIGPIPEs the producer to 141, so a print step reds (trim with\r\n  parameter expansion instead); pwsh under GitHub's wrapper: a MISSING COMMAND is a terminating\r\n  error, so rustup's absence must be TESTED with `Get-Command`, never caught. One requirement, two\r\n  constructions, and neither is portable reasoning about the other.\r\n  (b) **A negative-control mutation must be COUNTED before it is trusted** — the absent-CLI arm was\r\n  first \"measured\" against a tree where the mutation had not taken, silently re-measuring the\r\n  unmutated arm and reading as a pass.\r\n  (c) **Jitter, not the median, is the signal on a link that mostly works** — the motivating red's\r\n  link ran 10..83ms and 3..75ms while IDLE, so a median-only probe reads healthy straight through\r\n  the failure. Both med and max rows ride the ledger.\r\n- **Disposition:** composes onto the next golden batch as a thin lane, NOT slipped onto main. It\r\n  changes the golden pipeline itself, so it wants a golden rather than a quiet ff — and while\r\n  v0.53.0 is untagged, any push to `main` moves the runbook's bare `git tag` off the tested sha.\r\n\r\n### IR-55 — the `spt --bins` suite wedges partway through on leaked `findstr .` PTY children; the tests at the frontier are casualties, not culprits\r\n\r\n- **Status:** OPEN, **ARMED-FOR-CAPTURE**, owned by **hertz**. Test/rig defect by the dispatch\r\n  split (test/CI rework is never the product builder's). Filed by doyle 2026-08-22 from the\r\n  TURNKEY #212 W3 gate on releases#213.\r\n- **CORRECTED BY REPLACEMENT the same day.** This entry first named\r\n  `cli::tests::adapter_profile_verbs_local_only` as the wedging test, because that is where the\r\n  streamed frontier stopped. **That was wrong, and the correction is the useful part of the\r\n  entry:** run in isolation, on the same pool and binary and with the same env, that test passes\r\n  in **0.02s**. So do the other two the suite later stalled on —\r\n  `cli::tests::shell_channels_relay_sensory_and_text_file` (0.20s) and\r\n  `cli::tests::resolve_proof_target_override_reads_on_disk` (0.00s), each 1 passed / 652 filtered.\r\n  **A frontier names where progress STOPPED, not what CAUSED it.** Naming the last test printed\r\n  is the same error shape as reading a stack frame as a root cause, and it would have sent hertz\r\n  to rewrite three innocent tests.\r\n- **What is actually measured:**\r\n  - `cargo test -p spt --bins` unfiltered sat **24 minutes** at 13.5s CPU — blocked, not spinning.\r\n  - Re-run with `--test-threads=1` and streaming output: stalled after **183** completed.\r\n  - Re-run again with that frontier test skipped: progressed to **335** completed, then stalled\r\n    with **two** tests simultaneously past libtest's 60-second notice. Skipping one casualty\r\n    simply moves the frontier, which is itself evidence the fault is not in any one test.\r\n  - Every wedged harness carried `findstr.exe .` children under `conhost.exe --headless`.\r\n    **`findstr` with no file argument reads STDIN and blocks forever.**\r\n  - The frontier tests are **byte-identical at `c62904e7` and at the #213 tip `3d69f77c`**\r\n    (function bodies hashed at both blobs), so nothing in that lane introduced this.\r\n- **Reading, stated as a reading rather than a conclusion:** an EARLIER test spawns the `findstr`\r\n  stand-in as a PTY child and does not reap it; the children accumulate across the run and a later\r\n  test blocks behind them. Which test leaks is NOT yet identified and this entry does not guess —\r\n  the next step is to bisect for the leaker rather than to touch any test at the frontier. Five\r\n  orphaned `findstr` processes with creation times spread across the day were observed on this box\r\n  independently of any single run, which is consistent with accumulation across many suite runs.\r\n- **Hypothesis RAISED AND NOT SUPPORTED, recorded so nobody re-runs it:** the gate scrubs\r\n  `OWL_SESSION_ID` / `SPT_AGENT_ID` / `SPT_ENDPOINT_ID`, and a scrubbed identity was suspected of\r\n  routing a normally-REFUSED test down a live PTY path. The isolation runs above were performed\r\n  **with the scrub applied** and passed, so the scrub alone does not produce the hang. It remains\r\n  unexplained why the same unfiltered command completed at 652 passed / 1 failed for another agent\r\n  on the same tree; do not treat the scrub as the differentiator without a fresh one-variable run.\r\n- **Why it is register-grade:** golden CI runs the `spt` package. A test that never returns cannot\r\n  red — it consumes the single self-hosted runner slot until the job timeout, which `golden.yml`'s\r\n  50-minute cap bounds rather than fixes. A wedge that fires only sometimes is worse than a red,\r\n  because the suite's green record stays intact and nobody audits it — the same self-concealing\r\n  shape as `exit-code-after-a-pipe-is-the-tails`.\r\n- **Trigger condition (ripe):** any milestone whose gate wants an unfiltered `spt --bins` sweep,\r\n  which is every one of them. Ripe now.\r\n- **REMEDY, MEASURED 2026-08-22 and it changes this entry's urgency:** the same 653 tests under\r\n  `cargo nextest run -p spt --bins --no-fail-fast` complete in **22.2 seconds, 653 passed, 0\r\n  skipped, exit 0** — no slow markers, no timeouts — on the very tree and pool where\r\n  `cargo test -p spt --bins` wedged indefinitely twice. **nextest runs each test in its OWN\r\n  process**, so a leaked `findstr` child can block only itself. This is the discriminating\r\n  measurement rather than a workaround reached for to get a green: **the suite is not broken; the\r\n  SINGLE-PROCESS harness is what lets one test's leaked child wedge every test after it.** Golden\r\n  CI already runs nextest, which is the likely reason this has never surfaced there — the exposure\r\n  is to anyone running bare `cargo test` on the `spt` package, which is every local gate.\r\n- **Count reconciliation, recorded so the figures are not read as a discrepancy:** runs of this\r\n  suite report 652 passed / 1 failed where the one failure is\r\n  `cli::tests::adapter_translate_proof_gates_on_commit` — the `--bins`-only artifact, which\r\n  refuses because `translate_proof_fixture.exe` is not built under a bins-only invocation and says\r\n  so in its own message. Prebuilding it (`cargo build -p spt --bin translate_proof_fixture`) makes\r\n  it pass: 652 + 1 = 653. Prebuild the fixture rather than carrying a known-red through every gate.\r\n- **⚠ AMENDED 2026-08-22 — DO NOT PREBUILD FROM THIS BULLET'S EXAMPLE.** The line above names ONE\r\n  fixture because one fixture is what *this* wedge needed; read as the prebuild recipe it covers a\r\n  fraction of the population, and it was read that way twice on one day. **The census already exists\r\n  in IR-21 above** (`adapters/mock`: mock-session, mock-shell, capture-player, console-mode-probe ·\r\n  `crates/spt-daemon`: dispatch_fixture, service_fixture, summarizer_fixture · `crates/spt`:\r\n  translate_proof_fixture, post_step_fixture, gh_fixture, git_fixture), together with the split that\r\n  matters: **cross-package sites are the hazard members; same-package builds are guaranteed by\r\n  construction.** Field instances, both 2026-08-22 TURNKEY #212 W4: todlando's lane red on three\r\n  `spt-daemon::attach_resize_capture` cells wanting `adapters/mock`'s **capture-player** (a\r\n  cross-package member), and doyle's head gate prebuilding the remembered pair while never running a\r\n  `spt-daemon` or `spt-term` suite at all. **Prebuild `--workspace --bins`, or read the\r\n  `build_hint` the helper already composes** (`crates/spt-term/tests/support/fixture_bin.rs:42`) —\r\n  five test files gate on that panic. Neither of us lacked the census; we prebuilt from memory while\r\n  our own register held the list.\r\n- **FIXTURE PREBUILD, RECURRENCE 2026-08-29 (todlando, emission lane):** the rule was\r\n  already banked AND I am one of its authors, and I still ate three fixture reds in a row —\r\n  mock-session, then capture-player, then mock-shell — each tripping in about 0.01s with a panic\r\n  that reads exactly like a test failure. Having the rule is not the same as applying it completely:\r\n  I prebuilt from RECALL (`-p spt --bins`) rather than from the rule's stronger banked form, and the\r\n  tell is that my fix arrived in three instalments instead of once. **TWO FACES, both structural\r\n  rather than careless.** (1) THE FIXTURE MAY LIVE IN ANOTHER PACKAGE — mock-session,\r\n  capture-player, mock-shell and console-mode-probe are all `adapters/mock` (`-p mock-adapter`), so\r\n  no amount of `-p spt --bins` ever produces them. (2) ENUMERATING FIXTURES BY GREPPING THEIR\r\n  PRE-BUILD STRINGS IS STRUCTURALLY INCOMPLETE — it finds the call sites that embed a literal\r\n  `pre-build: cargo build ...` string and CANNOT find mock-shell, whose helper composes the command\r\n  at runtime (`sibling_bin(name)` → `fixture_package(name)`), so there is no literal to match. A\r\n  predicate over source text cannot see a string the program builds at runtime; same blindness\r\n  class as the emission census's TOKEN-colon-vs-TOKEN-space predicate, met twice in one session.\r\n  **CLASS FIX:** never hand-list fixtures — build the whole fixture package\r\n  (`cargo build -p mock-adapter --bins`) or `--workspace --bins` before any\r\n  `--test`/`--bins`/filtered leg. Chasing named fixtures one red at a time only ever finds them one\r\n  at a time, and each one costs a full battery run.\r\n- **Named negative + settle-class result (hertz, 2026-08-23):** current main at\r\n  `4dd699cb7867979ca0497e7c74d8d0aaf881e9e9` did not reproduce the wedge on HFENDULEAM from\r\n  isolated checkout `.worktrees/ir55-findstr-bisect`. Test binaries were freshly built before the\r\n  diagnostic population and reused for the settle sweep; the gate environment scrub was **not**\r\n  applied; the installed daemon was live. The fleet snapshot taken immediately **after**, not\r\n  during, the sweep showed BIGNET 7 nodes / 20 endpoints, SPT_MANTLE 3 / 19, SPT_DEV 2 / 19,\r\n  3-of-7 peers connected, `degraded-partial`. Four startup cells that spawn `findstr` passed alone\r\n  and reaped their observed ConPTY children; a full single-threaded run passed 663/663 with a\r\n  before/after census delta of `IR55_NEW=0`. The ratified settle-class sweep then ran five\r\n  consecutive bare `cargo test -p spt --bins` invocations: all 663/663 green in 420.35s total,\r\n  with zero `findstr.exe` residents before and after. This is a named negative data point, not a\r\n  discharge of the intermittent filing-day measurements.\r\n- **Next-wedge capture protocol — do not improvise or clean first:** preserve the exact bare\r\n  invocation and snapshot the environment (box, checkout SHA/worktree, fresh-versus-reused test\r\n  binary provenance, gate-scrub state, live-daemon state, and fleet roster); stream test output to\r\n  durable storage so the last started and completed test names identify the frontier; census\r\n  `Win32_Process` immediately before the run and again while wedged, recording each `findstr.exe`\r\n  PID, parent PID, creation time, executable path, and command line. **Do not kill any child before\r\n  the second census is banked.** The 22 residents found during the 2026-08-23 investigation were\r\n  path-verified as `C:\\Windows\\System32\\findstr.exe`, shown to predate its live runs, banked, then\r\n  reaped; the pre-sweep and post-sweep resident counts were both zero.\r\n- **Size guess:** small if one test is missing a reap or an EOF for its stand-in child; medium if\r\n  the shared PTY test scaffolding needs the reap, in which case every sibling spawning the same\r\n  stand-in wants it. The RUN-LEVEL exposure has an answer today (nextest); the LEAK itself is\r\n  still worth fixing, because a leaked child per run accumulates on any box that runs the suite.\r\n- **Gater's craft, worth more than the entry itself:**\r\n  (a) The first wedge was undiagnosable because the gate script wrote every leg as\r\n  `cargo test … | tail -N > file` — nothing reaches disk until the command completes, so a wedged\r\n  leg produces an **empty file** and the process table is the only witness. **Stream to a file and\r\n  tail the FILE.**\r\n  (b) To NAME a frontier, run `--test-threads=1`: libtest prints each test's name BEFORE running\r\n  it, so the last incomplete line is where progress stopped.\r\n  (c) **Then prove the frontier test is actually at fault by running it alone** — which is the\r\n  step this entry originally skipped, and the one that turned a wrong entry into a right one.\r\n\r\n### IR-56 — `pool-claim` harvests lane identity from CWD, not from `--pool`; a claim run from the wrong tree writes a WRONG RECORD with a success message\r\n\r\n- **Status:** BUILT 2026-08-24 for the SIGNET #218 golden batch on\r\n  `fix/ir56-pool-claim-cwd`, owned by **hertz**. Tooling/rig defect by the dispatch split. Filed by\r\n  doyle 2026-08-22 from todlando's TURNKEY #212 W4 Lane 1 field instance — the first confirmation\r\n  of the IR-42 mechanism from a LANE rather than from a source read.\r\n- **What happens:** `cargo run -p xtask -- pool-claim --pool <dir> --label <lane>` records the lane\r\n  identity it harvests from the **current working directory** — `owner_tree`, `lane_branch`, and the\r\n  base sha — not from the tree `--pool` names. Run it from the project root with `--pool` aimed at a\r\n  worktree and the record reads `owner_tree = <project root>, lane_branch = <root's branch>` while\r\n  every artifact in that pool belongs to the worktree. The verb prints its ordinary success line\r\n  naming the wrong owner, and returns 0.\r\n- **Why it is silent, which is the whole entry:** the claim verb WRITES and never adjudicates\r\n  (IR-42) — every enforcement arm lives in `crates/spt-store/build.rs` and speaks only at the next\r\n  BUILD. So a wrong record has no symptom at the moment it is created; the first signal is a build\r\n  refusal minutes later, on a lane whose `--pool` argument was correct all along. **`--pool` being\r\n  correct is not evidence the record is.** Nothing on the command line shows you cwd, which is the\r\n  one input that decided the outcome.\r\n- **Recovery is the documented hatch, and the bootstrap is why:** the claim tool builds THROUGH the\r\n  pool it is claiming, so a pool already refusing cannot be re-claimed by the ordinary route. The\r\n  refusal text says so itself — meaning the bootstrap case is known, and a wrong-cwd claim is the\r\n  ordinary way a lane lands in it.\r\n- **The rule, as a must-do:** claim from the lane's own worktree so the identity the verb harvests\r\n  is the lane's — `( cd <lane> && cargo run -p xtask -- pool-claim --pool \"$PWD/target\" … )`, or any\r\n  form that makes cwd explicit. Then READ THE PRINTED RECORD BACK and confirm `owner_tree` and\r\n  `branch` name the lane: the success line carries the record, so the check costs nothing.\r\n- **Trigger condition:** ripe now — it is a doc/UX fix on a verb we run every lane. Ripest alongside\r\n  any other `xtask` pool-verb touch.\r\n- **Size guess:** small. Either make the verb REFUSE when cwd is not inside the tree containing\r\n  `--pool` (loud, and it cannot be wrong), or print the harvested identity as a distinct confirmed\r\n  line. The refusing form is preferred: it removes the reading step rather than adding one.\r\n- **Built evidence, corrected at review:** `pool-claim` resolves the git worktree containing\r\n  `--pool` from the pool's nearest existing ancestor and compares it with the cwd worktree before\r\n  writing. An accidental cross-worktree call returns 2, names both worktrees and the remedy, and\r\n  leaves the not-yet-existing pool absent. The sanctioned sequential takeover carries an explicit\r\n  `--foreign-pool`, says that it is harvesting the arriving cwd identity, writes that identity, and\r\n  returns 0. Both poolguard refusal remedies now print that flag. An executable xtask test drives\r\n  both arms against two real temporary git repositories, pinning VERB-ADMITS-REMEDY rather than\r\n  merely testing path equality. This remains identity-harvest validation only: the claim still\r\n  writes without adjudicating admission, so IR-42's enforcement boundary remains in the build.\r\n\r\n### IR-57 — an assembly pick's conflict resolution can silently DROP lines, and every gate run at assembly time is blind to it\r\n\r\n- **Status:** OPEN, owned by **doyle** (gater craft, not a code defect — no lane to dispatch).\r\n  Filed 2026-08-22 from doyle's own defect on the TURNKEY #212 assembly head.\r\n- **What happened:** assembly head `5cce533d` **did not compile**, and was carried across a session\r\n  boundary as a ready head with \"treqs exit 0\" attached to it. `crates/spt-store/src/access.rs` had\r\n  an unclosed `mod tests`: the cherry-pick of the #206 lane commit `b2194aa9` conflicted against the\r\n  #209 test block — both add functions to the same region, and the two sides share the trailing\r\n  `);` / `}` / `}` — and the resolution deleted the markers without restoring the FIRST side's\r\n  function closer. Exactly two lines lost: `        );` and `    }`.\r\n- **Every instrument in the assembly path reported success:** `git cherry-pick` completed with no\r\n  conflict remaining; `traceable-reqs check` returned 797/797, 0 findings, exit 0 — **it parses\r\n  tags and never invokes the compiler**; and the lanes themselves were green and stayed provably\r\n  clean (the #206 lane's brace balance is correct at all five of its commits). **Lane-green plus\r\n  conflict-free is not a claim about the assembled head.** Same lesson as the #182 v2 assembly\r\n  (`E0425`×4) by a different mechanism: that one was a semantic composition break between two\r\n  correct hunks, this one is a fidelity LOSS during resolution.\r\n…\n","startLine":2692,"lineNumbers":[2692,2693,null,2722,null,2725,2726,2727,2728,2729,2730,2731,2732,2733,2734,2735,2736,2737,2738,2739,2740,2741,2742,2743,2744,2745,2746,2747,2748,2749,2750,2751,2752,2753,2754,2755,2756,2757,2758,2759,2760,2761,2762,2763,2764,2765,2766,2767,2768,2769,2770,2771,2772,2773,2774,2775,2776,2777,2778,2779,2780,2781,2782,2783,2784,2785,2786,2787,2788,2789,2790,2791,2792,2793,2794,2795,2796,2797,2798,2799,2800,2801,2802,2803,2804,2805,2806,2807,2808,2809,2810,2811,2812,2813,2814,2815,2816,2817,2818,2819,2820,2821,2822,2823,2824,2825,2826,2827,2828,2829,2830,2831,2832,2833,2834,2835,2836,2837,2838,2839,2840,2841,2842,2843,2844,2845,2846,2847,2848,2849,2850,2851,2852,2853,2854,2855,2856,2857,2858,2859,2860,2861,2862,2863,2864,2865,2866,2867,2868,2869,2870,2871,2872,2873,2874,2875,2876,2877,2878,2879,2880,2881,2882,2883,2884,2885,2886,2887,2888,2889,2890,2891,2892,2893,2894,2895,2896,2897,2898,2899,2900,2901,2902,2903,2904,2905,2906,2907,2908,2909,2910,2911,2912,2913,2914,2915,2916,2917,2918,2919,2920,2921,2922,2923,2924,2925,2926,2927,2928,2929,2930,2931,2932,2933,2934,2935,2936,2937,2938,2939,2940,2941,2942,2943,2944,2945,2946,2947,2948,2949,2950,2951,2952,2953,2954,2955,2956,2957,2958,2959,2960,2961,2962,2963,2964,2965,2966,2967,2968,2969,2970,2971,2972,2973,2974,2975,2976,2977,2978,2979,2980,2981,2982,2983,2984,2985,2986,2987,2988,2989,2990,2991,2992,2993,2994,2995,2996,2997,2998,2999,3000,3001,3002,3003,3004,3005,3006,3007,3008,3009,3010,3011,3012,3013,3014,3015,3016,3017,3018,3019,3020,3021,3022,3023,3024,3025,3026,3027,3028,3029,3030,3031,3032,3033,3034,3035,3036,3037,3038,3039,3040,3041,3042,3043,3044,3045,3046,3047,3048,3049,3050,3051,3052,3053,3054,3055,3056,3057,3058,3059,3060,3061,3062,3063,3064,3065,3066,3067,3068,3069,3070,3071,3072,3073,3074,3075,3076,3077,3078,3079,3080,3081,3082,3083,3084,3085,3086,3087,3088,3089,3090,3091,3092,3093,3094,3095,3096,3097,3098,3099,3100,3101,3102,3103,3104,3105,3106,3107,3108,3109,3110,3111,3112,3113,3114,3115,3116,3117,3118,3119,3120,3121,3122,3123,3124,3125,3126,3127,3128,null,3170]},"fileSize":501961,"meta":{"source":{"type":"path","value":"C:\\Users\\decid\\Documents\\projects\\spt-core\\docs\\INFRA-REGISTER.md"},"truncation":{"direction":"head","truncatedBy":"lines","totalLines":5781,"totalBytes":35264,"outputLines":404,"outputBytes":35264,"shownRange":{"start":2725,"end":3128},"nextOffset":3129}}},"isError":false,"timestamp":1789094598241}}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_j9030mSuht3Bk4MNPanNX5rG|fc_065c0d1976ecf9c2016aa36ac9e4ec87d1839ef4cf6d5db058","toolName":"read","startedAt":"2026-09-11T02:43:24.301Z","args":{"path":"docs/INFRA-REGISTER.md:3129-3620"},"intent":"Reading middle later entries"},"id":"1d3bf4c5","parentId":"afed7a7e","timestamp":"2026-09-11T02:43:24.301Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_CAdkTQKgwNlSODdaTUJ509Xj|fc_065c0d1976ecf9c2016aa36ac9e4fc87d1a75c12cce479a55a","toolName":"read","startedAt":"2026-09-11T02:43:24.301Z","args":{"path":"docs/INFRA-REGISTER.md:3621-4140"},"intent":"Reading later trigger records"},"id":"b6bc1454","parentId":"1d3bf4c5","timestamp":"2026-09-11T02:43:24.301Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_uld1OBQG2aDmBLc0eS4hRT5Z|fc_065c0d1976ecf9c2016aa36ac9e50487d1a5accf2750af8035","toolName":"grep","startedAt":"2026-09-11T02:43:24.301Z","args":{"path":"docs/INFRA-REGISTER.md:2726-5781"},"intent":"Indexing assigned entry headings"},"id":"dd8c94aa","parentId":"b6bc1454","timestamp":"2026-09-11T02:43:24.301Z"}
{"type":"message","id":"0866fea4","parentId":"dd8c94aa","timestamp":"2026-09-11T02:43:24.301Z","message":{"role":"assistant","content":[{"type":"toolCall","id":"call_j9030mSuht3Bk4MNPanNX5rG|fc_065c0d1976ecf9c2016aa36ac9e4ec87d1839ef4cf6d5db058","name":"read","arguments":{"i":"Reading middle later entries","path":"docs/INFRA-REGISTER.md:3129-3620"},"intent":"Reading middle later entries"},{"type":"toolCall","id":"call_CAdkTQKgwNlSODdaTUJ509Xj|fc_065c0d1976ecf9c2016aa36ac9e4fc87d1a75c12cce479a55a","name":"read","arguments":{"i":"Reading later trigger records","path":"docs/INFRA-REGISTER.md:3621-4140"},"intent":"Reading later trigger records"},{"type":"toolCall","id":"call_uld1OBQG2aDmBLc0eS4hRT5Z|fc_065c0d1976ecf9c2016aa36ac9e50487d1a5accf2750af8035","name":"grep","arguments":{"i":"Indexing assigned entry headings","pattern":"^### IR-|^## |^-[ ]\\*\\*(Status|Ripe when|Trigger)","path":"docs/INFRA-REGISTER.md:2726-5781","case":false,"gitignore":true,"skip":0},"intent":"Indexing assigned entry headings"}],"api":"openai-codex-responses","provider":"openai-codex","model":"gpt-6-astra","usage":{"input":9581,"output":156,"cacheRead":10112,"cacheWrite":0,"totalTokens":19849,"cost":{"input":0,"output":0,"cacheRead":0,"cacheWrite":0,"total":0}},"stopReason":"toolUse","timestamp":1789094598294,"responseId":"resp_065c0d1976ecf9c2016aa36ac4314887d198e90486ea4743bb","providerPayload":{"type":"openaiResponsesHistory","provider":"openai-codex","dt":true,"items":[{"id":"fc_065c0d1976ecf9c2016aa36ac9e4ec87d1839ef4cf6d5db058","type":"function_call","status":"completed","arguments":"{\"i\":\"Reading middle later entries\",\"path\":\"docs/INFRA-REGISTER.md:3129-3620\"}","call_id":"call_j9030mSuht3Bk4MNPanNX5rG","internal_chat_message_metadata_passthrough":{"turn_id":"cb1368d9-2a08-40c0-9f68-e06c6338cbd5"},"name":"read","metadata":{"turn_id":"cb1368d9-2a08-40c0-9f68-e06c6338cbd5"}},{"id":"fc_065c0d1976ecf9c2016aa36ac9e4fc87d1a75c12cce479a55a","type":"function_call","status":"completed","arguments":"{\"i\":\"Reading later trigger records\",\"path\":\"docs/INFRA-REGISTER.md:3621-4140\"}","call_id":"call_CAdkTQKgwNlSODdaTUJ509Xj","internal_chat_message_metadata_passthrough":{"turn_id":"cb1368d9-2a08-40c0-9f68-e06c6338cbd5"},"name":"read","metadata":{"turn_id":"cb1368d9-2a08-40c0-9f68-e06c6338cbd5"}},{"id":"fc_065c0d1976ecf9c2016aa36ac9e50487d1a5accf2750af8035","type":"function_call","status":"completed","arguments":"{\"i\":\"Indexing assigned entry headings\",\"pattern\":\"^### IR-|^## |^-[ ]\\\\*\\\\*(Status|Ripe when|Trigger)\",\"path\":\"docs/INFRA-REGISTER.md:2726-5781\",\"case\":false,\"gitignore\":true,\"skip\":0}","call_id":"call_uld1OBQG2aDmBLc0eS4hRT5Z","internal_chat_message_metadata_passthrough":{"turn_id":"cb1368d9-2a08-40c0-9f68-e06c6338cbd5"},"name":"grep","metadata":{"turn_id":"cb1368d9-2a08-40c0-9f68-e06c6338cbd5"}}]},"duration":6005.700799999759,"ttft":5955.393600000069,"completedAt":1789094604300,"contextSnapshot":{"promptTokens":19693,"nonMessageTokens":10400,"compactionEpoch":0}}}
{"type":"message","id":"25042ecb","parentId":"0866fea4","timestamp":"2026-09-11T02:43:24.315Z","message":{"role":"toolResult","toolCallId":"call_j9030mSuht3Bk4MNPanNX5rG|fc_065c0d1976ecf9c2016aa36ac9e4ec87d1839ef4cf6d5db058","toolName":"read","content":[{"type":"text","text":"### IR-57 — an assembly pick's conflict resolution can silently DROP lines, and every gate run at assembly time is blind to it\n…\n- **Status:** OPEN, owned by **doyle** (gater craft, not a code defect — no lane to dispatch).\n…\n- **Every instrument in the assembly path reported success:** `git cherry-pick` completed with no\n…\n  correct hunks, this one is a fidelity LOSS during resolution.\n- **Two must-dos, both cheap:**\n  1. **Compile the assembled head before it is handed anywhere — including forward to your own next\n     session.** A head is not ready on a treqs exit; it is ready on a build. Any sentence carrying a\n     head sha to another agent must name the instrument that proved it.\n  2. **Audit pick fidelity on CHANGED LINES for every pick on the chain**, not just the one that\n     tripped you: hash `git show --format= <sha> | grep -E '^[+-]' | grep -vE '^(\\+\\+\\+|---)'` for\n     the lane source and for the pick, and compare. Whole-diff comparison is useless here — hunk\n     headers and context legitimately drift once the head's copy of the file has moved.\n- **Read COUNT and HASH together, because they fail in opposite directions.** Of 24 picks on this\n  chain two did not match. `b2194aa9 → 4d6deed1` differed in COUNT (302 lane / 300 pick by the header-excluding pipeline above; **this entry originally cited 310/308, which is the RAW `^[+-]` count INCLUDING the 8 `+++`/`---` header lines of its 4 files** — the figures were taken without the second grep the entry itself prescribes. The DELTA is 2 under either meter, which is why the wrong figures never surfaced: they supported a correct conclusion, so nothing pressed them. Corrected todlando 2026-08-29, measured both ways in-tree) — the real\n  defect. `f27f15c6 → 5865cc98` had the SAME count and a different HASH — benign: a `CONTEXT.md`\n  paragraph the head had already amended for #209, whose merged result correctly carries both lanes'\n  sentences. A count check MISSES the first class entirely; a hash check FLAGS the second as if it\n  were a defect. Neither alone classifies a pick.\n- **Repair shape used, recorded because it is the cheap one:** reset to the commit before the bad\n  pick, re-pick the lane source, resolve the same conflict correctly, then replay the remaining picks\n  in chain order with the fidelity check on each. Verify the repair changed nothing else with a\n  WHOLE-TREE diff against the old head — it must show exactly the restored lines and no other file.\n  Where a later pick re-conflicts, check its pre-pick blobs against the old chain\n  (`git rev-parse <old-pick>~1:<file>`); if they match, the old chain's post-pick blob is a\n  transferable, already-reviewed resolution.\n- **AND GATE THE REPAIR'S OWN SUBJECT.** The rebuilt head passed six legs — clippy `-D warnings`,\n  sweep 660/660, treqs 803/803, xtask OK — while the restored lines live in `spt-store`, whose LIB\n  tests `-p spt --bins` never runs. Six greens, and not one executed the function the repair\n  restored; it was proven to COMPILE and assumed to PASS. Proven afterwards by name (4/4) and by the\n  full `spt-store --lib` suite (519/519). **A repair's gate must include the suite that owns the\n  repaired file**, which is not necessarily the suite the head gate runs.\n- **FIRST LIVE CATCH, and it was the author's own resolution (2026-08-29, one hour after the verb landed):** rebasing the IR-59 rider over the IR-57 rider produced four conflicts — three additive keep-both, one usage line both sides had edited. `xtask pick-audit` read the rebase as **LOSS, 282 lane / 280 pick**. The two missing lines were a `[[requirements]]` header and its blank line in `traceable-reqs.toml`, so `id = REQ-DISK-FLOOR-PREFLIGHT` landed INSIDE the previous table as a duplicate key: **`traceable-reqs check` exit 2, the registry unparseable, every reading after that edit checking nothing**. Restored, the same audit reads **DRIFT 282/282** whose one differing line is the usage string whose base copy legitimately gained the other verb — both verdi…\n- **FIRST REAL-ASSEMBLY USE (2026-08-29, #241 emission head, ASM-241-GATE-VERDICT.md):** `xtask\n  pick-audit --range 57a0d27c..HEAD --lane 4d6007ac..d0fdd58d` over 6 picks — **5 MATCH\n  (digest-identical), 1 LOSS, 0 drift, 0 unclassified**, exit 1 forcing the accounting. The LOSS\n  was exactly the one human-resolved conflict (`cfb9d9f8 <- 10f12e4c`, count 432/402), and the\n  delta RECONCILED to the resolution rather than assumed: lane stat 15 files/235+/197- vs pick\n  14 files/205+/197-, difference byte-for-byte the deliberately-dropped 30-line interim IR-69\n  register block superseded by main's consolidated entry. No false positives, no silent pass.\n  Entry stays OPEN as living procedure; both live uses (the rebase catch above, this assembly)\n  produced the verdict classes in the order the entry predicts.\n- **Trigger condition:** ripe at the next assembly — this is procedure, and its cost is one command\n  per pick.\n- **Size guess:** small as a scripted check in `xtask` (fidelity audit over a pick range); zero as\n  discipline, which is how it is being applied now.\n\n### IR-58 — a `[[bin]]` grep is not a census: cargo AUTODISCOVERS `src/bin/*.rs` targets, and a hand-built bin list produced a confident false \"this bin does not exist\"\n\n- **Status:** OPEN, unowned. Filed by doyle 2026-08-22; **its original filing was WRONG and is\n  retracted in full below.** The entry is kept because the way it was wrong is the finding.\n- **RETRACTED CLAIM, stated plainly so no reader acts on it:** this entry first said that\n  `crates/spt/Cargo.toml:18-21` and `crates/spt/src/cli.rs:30355` forbid a bin-name collision with\n  `xlate_choreo_fixture`, \"a bin that does not exist\", and that spt-daemon's third helper had been\n  renamed to `summarizer_fixture`. **`xlate_choreo_fixture` EXISTS** — at\n  `crates/spt-daemon/src/bin/xlate_choreo_fixture.rs`, verified at the assembly head. The collision\n  rule's counterpart is real, both prose sites are CORRECT, and IR-21's original table row was\n  correct too; it merely predated `summarizer_fixture`. Nothing in that prose needs fixing.\n- **How the false claim was produced, which is the entry:** the census was built by grepping\n  `^\\[\\[bin\\]\\]` across `Cargo.toml`s. **Cargo AUTODISCOVERS `src/bin/*.rs` as bin targets with no\n  stanza at all**, so a stanza grep cannot see them, and it fails SILENTLY — it returns a clean,\n  well-formed list that is simply short. From that list it read as established fact that a named bin\n  had been renamed away, and that \"fact\" was then written into a register table, an IR entry, and a\n  message to the builder. **A pattern-built population encodes the pattern's assumption; the count\n  looks like a census and is a property of the pattern.**\n  (Found by todlando, resolving one of doyle's figures against his own tree under the pointer rule.)\n- **A CENSUS IS ALSO A PROPERTY OF A TREE.** Stanza counts differed legitimately across trees the\n  same hour — 13 at the assembly head, 11 at `dc1c7532` — because `summarizer_fixture` exists at one\n  and not the other. Two correct censuses of the same workspace disagree unless each names its sha.\n- **The must-do, and it removes the list rather than lengthening it:** never hand-maintain a bin\n  roster. Run `cargo build --workspace --bins` and let cargo enumerate its own targets — the same\n  enumeration the test harness resolves against, so it cannot drift from what a fixture lookup\n  expects. Stanza-derived lists, remembered pairs, and register tables are all the roster problem at\n  different depths; only cargo's own enumeration is the population.\n- **Kin:** IR-55's amended prebuild bullet (prebuild the census, not a remembered pair) and IR-42\n  (a verb that writes without adjudicating). The shared shape is an instrument returning an orderly\n  answer about a set it never fully saw.\n- **Trigger condition:** ripe on any `xtask` check work — a duplicate-bin-name check over cargo's\n  target enumeration (NOT over manifest stanzas) is a handful of lines and cannot go stale.\n- **Size guess:** small. The prose fix originally proposed here is WITHDRAWN — there was nothing\n  wrong with the prose.\n\n### IR-59 — pool arithmetic: this box holds TWO cold pools, not four; and a build that exhausts the volume reds as a LINKER defect that names no disk\n\n- **Status:** OPEN, unowned — it is arithmetic and discipline, not a code lane. Filed by doyle\n  2026-08-22 from a live disk-floor abort during the TURNKEY #212 W4 gate; footprint figures measured\n  by todlando the same hour.\n- **SECOND FACE, measured 2026-08-23/24 (WAX-SEAL #21 W2 gate, doyle — the violator this time):**\n  both predicted mechanisms fired at once, WITHOUT the floor guard because the gate legs ran as a\n  plain script. (1) doyle minted a THIRD cold pool (gate rig) while todlando's lane pool was LIVE —\n  the two-pool arithmetic, violated by the gater. (2) The lane pool had silently accumulated\n  **104.8 GB** over repeated full-workspace sweeps (nothing bounds or even measures a pool's\n  accumulation until the volume dies). The volume hit **3 MB free**; the reds wore exactly the\n  entry's predicted costume — `LNK1318: Unexpected PDB error; LIMIT (12)` naming no disk — plus a\n  second face worth keeping: `traceable-reqs check` died as a PANIC printing to stdout\n  (`os error 112`), so a REGISTRY gate red can also be the disk's. Both gate verdicts VOIDED\n  (clippy's full compile had exited 0 before space died — the code was never the question).\n  Recovery measured: gate pool reap 9.6 GB, lane pool clean 100.2 GB, drive back to 109.6 GB free.\n  **Remedies adopted at the incident:** the gate never mints its own pool while a builder lane is\n  live on the box — it takes the lane pool over SEQUENTIALLY at pool-release (warm, loud, the\n  releases#103 pattern); and gate/lane scripts get the disk-floor preflight the golden runner\n  already carries (this entry's part 2, still unbuilt).\n- **THIRD FACE, measured 2026-08-24 (WAX-SEAL #21 golden window, doyle):** two new mechanisms, both\n  about the REMEDY rather than the red. (1) The wax-seal-w1 lane pool **re-accumulated to 152–169 GB\n  (two meters, IR-46 caveat) within ONE DAY of the 08-23 clean** and rode the volume back down to\n  4.92 GB free — a reap is an instant, not a state; nothing yet bounds a pool between reaps.\n  (2) **The remedy itself arrived garbled through relay:** the golden push was held \"waiting on the\n  IR-59 reboot\" when this entry prescribes no reboot anywhere — tens of releases have shipped without\n  one; the operator refused the premise and the register's own recorded remedy (reap finished-lane\n  pools) cleared it in ten minutes. A remedy relayed as a DIFFERENT remedy is the relay trap wearing\n  infra clothes: the entry is the author — read it before adopting a hold. Recovery measured: five\n  finished-lane pools reaped after ancestry classification (`git cherry` catches rebased lands that\n  a plain `merge-base --is-ancestor` calls unlanded — gate-w4l1's 90.9 GB pool was reapable only by\n  that meter), 4.92 → 260.88 GB free (~256 GB free-delta vs ~270–287 GB sum-of-lengths). Two main\n  runs red inside the low-disk window (09:17Z/09:41Z) were re-run, not re-read, per this entry's\n  must-do.\n- **FOURTH FACE, measured 2026-08-24 same day (SIGNET #218 W2 gate, doyle — the gater's own pool\n  this time):** the MAIN pool went **13.7 GB → 158.3 GB in ONE DAY** absorbing four full gate\n  batteries across two lane tips, and dragged the volume to **18 GB free mid-gate** — so the\n  entry's mechanism is not a lane-pool problem, it is EVERY pool under repeated full sweeps, the\n  gate rig included. Two riders worth the ink: (1) the golden runner's **free-space floor step\n  produced its first live catch** — a thin CI leg refused at 14:14 local over exactly this window\n  with zero test signal, and the register's re-run-not-re-read rule resolved it in one command;\n  (2) the reap-and-rebuild trade (\"cleaning a live pool buys one window at rebuild price\") was\n  taken deliberately mid-gate and cost ~35 minutes cold — cheaper than one uninterpretable red.\n  A red measured at 18 GB free in this gate got NO read at all, and the next sweep's red was a\n  DIFFERENT test: low disk manufactures random victims before it manufactures link errors.\n- **The event:** a gate's preflight refused with `GATE_ABORTED_DISK_FLOOR` at **4.75 GB free on a\n  1863 GB volume**. Four cold pools plus the milestone head's pool were standing at once. The floor\n  guard did its job — without it a full workspace build would have started with under 5 GB of\n  headroom and produced a red belonging to nothing.\n- **THE ARITHMETIC, and it corrects the intuition that worktrees are the cost.** Measured across the\n  whole `.worktrees` tree: **45 worktrees = 0.79 GB total** (~18 MB each). **3 pools = 130.45 GB.**\n  Worktrees are **0.6%** of the footprint; pools are **99.4%**. **One cold pool is worth roughly 2,500\n  worktrees.** A rule keyed on worktree count would cost a day of `git worktree remove` work for under\n  a gigabyte, risk removing a lane someone still wants, and leave the lever untouched.\n- **THE CEILING, as arithmetic rather than hygiene:** at **45–75 GB per cold pool** on this workspace\n  against a **40 GB floor**, this box supports **TWO live pools comfortably, THREE only if one is\n  small**. The two rules that already exist need no replacement, only this number attached:\n  - **Reap a pool when its lane is finished** → 45–75 GB back immediately.\n  - **Do not run two builds at once** → not only the contention argument, but **75–150 GB of\n    simultaneous allocation** against that floor.\n- **A FULL VOLUME REDS AS A LINKER DEFECT.** `LINK: fatal error LNK1318: Unexpected PDB error`\n  (variously `OK (0)` or `LIMIT (12)`), often beside `LNK4209: debugging information corrupt`. It\n  reads as a corrupt artifact or a broken toolchain and is neither — it is the linker unable to grow\n  a large `.pdb`. **Nothing in the failure text says \"disk\".** Do not key recognition on the\n  parenthesised code; it varies.\n- **THE DANGER WINDOW IS THE TAIL OF A COLD BUILD, not a steady state you can check once.** The\n  2026-08-22 instance died at the link of `spt` — the last and largest artifact of a **74 GB** cold\n  pool — while that same build was draining the volume out from under itself. A free-space reading\n  taken before the build would have looked fine.\n- **Positive tell, with its own refutation attached:** `traceable-reqs check` alone surviving a leg\n  table is suggestive, because it is the only leg that never links. It is a POSITIVE tell ONLY — a\n  full disk can red before any link step, so the signature's ABSENCE clears nothing.\n- **THE FALSIFIER IS FREE SPACE AT THE TIME OF THE RUN**, not the shape of the leg table.\n- **Must-do, both cheap:**\n  1. **A free-space reading goes in the FIRST LINE of any build-failure report** — not in the\n     controls, not as a follow-up. Two agents spent hours on a mechanism for this failure and neither\n     ran `df`; the falsifier was one command away throughout.\n  2. **Rig and gate logs should record free space at run start.** Today they do not, which makes \"was\n     the disk full\" **unanswerable after the fact for every red already in hand**. Any red produced\n     under ~1 GB free is UNINTERPRETABLE and must be **re-run, not re-read**.\n- **Measurement caveat, observed twice in one hour:** sum-of-file-lengths and free-space delta\n  disagree by several percent when anything else on the box is writing (98.07 GB of subtrees → 92.25\n  GB reclaimed; 47.28 GB → 40.81 GB). Report BOTH, derive neither from the other, and treat any single\n  free-space number as an instant rather than headroom — see IR-46.\n- **FIFTH FACE, measured 2026-08-29 at the CONDUIT #236/v0.65.0 cut (deployah):**\n  the finished milestone's sequential lane-sharing accumulated **140.51 GB**, while a freshly\n  rebuilt pool measured **7.78 GB** — about **18× one build's working set** retained across lane\n  hand-offs with no reap between them. This is the budgetable rate behind that cut's disk-floor\n  red: sequential execution prevents concurrent ownership corruption, but it does not bound\n  historical artifacts inside the shared pool. Treat takeover and reclamation as separate\n  operations; a pool may be safe to reuse and still be too large to keep.\n- **SEVENTH FACE, measured 2026-08-30 (v0.67.0 milestone close — the PARALLEL-LANE fill\n  rate):** the #23 wave arc drove C: from ~240 GB free to **0.01 GB in ~3.5 hours**: four\n  concurrent/serial lane+gate pools totalled **236.6 GB** (ns23-w1 87.7 + ns23-113 72.3 +\n  gate rig 57.3 + ns23-w3 19.1) — effectively the entire ir57 reclaim re-consumed inside one\n  milestone's build window. The head gate and two thin-CI runs redded with the entry's exact\n  costume (\"could not compile\" + treqs panic, zero disk words) at 0.01 GB and all re-earned\n  green after reclaim (+186.6 GB, finished-lane targets only, single-actor rule held under\n  racing consent). Budget rule this face adds: a MULTI-WAVE milestone on one box books\n  ~60-90 GB PER LANE-PLUS-GATE cycle, so the pool budget is per-wave, not per-milestone —\n  reap each wave's pool at its LAND, not at the milestone party (the party inherited only\n  ~58 GB because the emergency had already forced the other ~179).\n- **SIXTH FACE, measured 2026-08-30 (#242 golden r4, Windows test job, LNK1318 at the PDB\n  write):** the floor is asserted ONCE at job START, but the job's internal LOW-WATER sits at its\n  LAST heavy step — the docs-drift build, ~28 minutes in. r4's floor read 65.1 GiB honest at\n  23:07; the box was at ~37–39 GB by the 23:35 link failure. LNK1318 on PDB write = this entry's\n  documented low-disk costume; the incremental-corruption candidate was retired by preservation\n  snapshot (no xtask state existed at failure). **Durable fix = a floor RE-READ (or reclaim)\n  immediately before the docs-drift build** — the WITHIN-job sibling of the across-job\n  read-after-checkout fix, rides the next workflow commit. Riders: incremental hygiene as\n  disk-pressure maintenance (the dir measured 4.56 GB), and the box's **~51 GB non-recovering\n  post-run consumption** is this entry's pool-weight face — classify at the IR-14/26/27/49 audit\n  slot (composed this sweep).\n- **Composed for next intake (doyle, v0.65.0 close):** the still-open log-the-floor build half\n  rides with [[IR-57]]'s scripted pick-fidelity audit as the next milestone's two tooling riders.\n- **Trigger condition:** ripe now for the log-the-floor half (it rides any gate-script or CI touch);\n  the arithmetic is discipline and applies immediately.\n- **Size guess:** small — one line in each rig/gate preflight to record free space alongside the\n  existing floor check.\n\n### IR-60 — a wrapper that CAPTURES a leg's exit status ends with the capture, so the wrapper's own status is the capture's, not the leg's\n\n- **Status:** OPEN, unowned — script-shape discipline, not a code lane. Filed by doyle 2026-08-22\n  during the TURNKEY #212 W5 lane; mechanism measured by todlando, who reported it first as a\n  possible harness misreport and then RETRACTED that reading himself on a minimal probe.\n- **The reading that started it:** a background leg was summarised as `exit code 0` while the leg's\n  own exit file read `100`. Reported as-is, that is a task runner lying about a red — the worst\n  possible direction for a purposeful-red claim, since it would turn two reds that DID fire into two\n  reds reported as not having fired.\n- **The measurement, minimal and on this box:**\n\n      ( exit 100 ); echo $? > probe.exit; FINAL=$?\n      leg status captured to file : 100\n      wrapper's own final status  : 0\n\n  The wrapper's shape is `( cd <lane> && cargo nextest ... > leg.raw 2>&1 ); echo $? > leg.exit`.\n  **The last command is the `echo`, which succeeds**, so the wrapper genuinely exits 0 while the leg\n  genuinely exited 100. THE RUNNER TOLD THE TRUTH ABOUT THE WRAPPER. There is nothing to file against\n  the task runner, and it would have been filed.\n- **The class, and this is why it is worth an entry rather than a fix:** it is the truncation-pipe\n  family — the meter measured something real, it just was not the thing about to be quoted. **Three\n  shapes now share ONE trigger, and the trigger is not \"is this a pipe\":**\n  1. a truncation pipe (`cmd | tail`, `cmd | head`) — `$?` measures the truncator, and `head` closing\n     the pipe can MANUFACTURE a status (SIGPIPE → 101), so `PIPESTATUS` is not protection either;\n  2. a flattened `$?` read after any intervening command;\n  3. **a wrapper whose last command is the capture itself.**\n  **The trigger in all three is the REPORTING** — every instance happened while trimming or capturing\n  output in order to QUOTE it as evidence.\n- **The practice that held, and the one to keep:** the leg's own file is the leg's verdict. Both reds\n  were real, and the only reason that was knowable is that every leg wrote its exit to its own file\n  rather than to the wrapper's status.\n- **Remedy, in preference order:** (1) never read a wrapper's status as a leg's — read the leg's exit\n  FILE, which the per-leg rule already requires; (2) if a wrapper's own status must be meaningful,\n  end it by re-raising the captured status (`exit \"$(cat leg.exit)\"`) or set the status before the\n  capture is the last word; (3) for anything that becomes evidence, redirect to a file and read the\n  file.\n- **Trigger condition:** ripe now — it rides the next gate-script touch, and the gate scripts in this\n  milestone already write per-leg exit files, which is what makes this discipline rather than debt.\n- **Size guess:** small — a convention line in the gate-script preamble; no product code.\n\n### IR-61 — spacerun's test-module skip carries a SECOND literal tracker; the two answers can drift, and today only a cell stands between them\n\n- **Status:** OPEN, unowned, accepted-with-mitigation. Filed by doyle 2026-08-22 at the TURNKEY #212\n  head gate, as the named residual of the latch repair (the repair itself rides the milestone).\n- **What the debt is.** `crates/xtask/src/spacerun.rs` now skips a column-0 `#[cfg(test)]` module by\n  BRACE DEPTH and resumes after its close, rather than latching the scan to end-of-file. Counting\n  braces safely means knowing when a brace is inside a string, a raw string or a char literal — and\n  the scanner ALREADY tracks literals for its rendering pass. It does not reuse that tracking. There\n  are now TWO answers in one file to \"am I inside a literal\", and **two answers to one question is a\n  disagreement waiting for a reader who fixes one of them.**\n- **Why it was accepted rather than refactored on the spot, stated so the trade is auditable:** the\n  two trackers answer genuinely different questions — the rendering walk is PER LINE and forward\n  from an opening quote (\"where does this literal start and end\"), while the skip needs \"am I inside\n  a literal right now\" carried CONTINUOUSLY across lines. Unifying them is a real refactor of a check\n  that is already gated, already carries five fixed defects, and sits on the tree being handed to\n  golden. The narrow change with an OBSERVABLE failure mode beat the correct-shaped change with a\n  wide blast radius, on that tree, on that day.\n- **The mitigation, and its exact limit.** Three brace cells fail the moment the two trackers\n  disagree about a raw string, a normal string or a char literal, plus a cell that reds when the skip\n  stops consulting a literal tracker at all (`match lit` -> `match Lit::None`). **That is a cell\n  standing in for a refactor.** It catches drift in the three forms it names and nothing else — a\n  fourth literal form, or a change to only one tracker in a form neither cell covers, passes.\n- **The general shape, which is why this is a register entry rather than a comment:** a check whose\n  own correctness depends on a second implementation of a thing it already implements is one\n  refactor away from the defect class it exists to prevent. This same file has already produced\n  three instrument defects (an indented-marker latch, a column-0 latch, and a suppression that\n  decided what got PARSED rather than what got REPORTED). The pattern is not carelessness; it is a\n  scanner accumulating special cases.\n- **Trigger condition:** the next SUBSTANTIVE change to spacerun's scanning — any new skip, any new\n  literal form, any change to either tracker. At that point unify, rather than adding a third answer.\n- **Size guess:** small to medium — one continuous literal-state walk serving both the render pass\n  and the skip, with the existing corpus and brace cells as the regression net.\n\n### IR-62 — an e2e daemon binds well-known ports and collides with the resident fleet on shared runners\n\nFiled 2026-08-23 (doyle), from the #212 r2 golden's Windows Phase A red — one witnessed\ninstance, mechanism verified from the run's own capture, filed on the mechanism per the\nregister's standard.\n\n**Mechanism.** `endpoint_autostart_e2e::saved_endpoint_replays_on_daemon_restart` failed its\nown PRECONDITION (\"daemon B must come up with a fresh brain\") because daemon B's broker came up\ndegraded: `NODE_KEY_FAIL: identity unavailable` (net-less broker, no retry) and\n`DOCS_SERVER_BIND_FAIL` port 5474 `os error 10048` — the docs port was held by a CO-RESIDENT\ndaemon. HFENDULEAM is live infra: the resident fleet's daemon legitimately holds well-known\nports, and any e2e that brings up a daemon with default port bindings is in a race with it BY\nCONSTRUCTION. An isolated SPT_HOME isolates the store and broker socket, NOT globally-numbered\nTCP ports.\n\n**Classification history.** r2: red (35.4s, precondition panic). Run 1 and r3 on the same box:\ngreen. Folded into r3 under a pre-registered predicate (reds twice → dedicated triage); it\ngreened, so this stays an environment-shaped intermittent, NOT a product defect and NOT\nclosed — the collision window is real and will re-fire under the right co-residence timing.\n\n**Remedy direction (not built).** Test daemons should bind ephemeral/rig-scoped ports for\nevery advisory surface (the docs server is advisory — a bind failure should degrade the rig\nloudly, not poison an unrelated cell's precondition), or the precondition should name the\nport-collision cause distinctly so the red self-classifies. Either lane is test/CI work\n(hertz's), triggered the next time this class fires anywhere.\n\n**Kin.** IR-51 (e2e daemon net-enabled on real interfaces — hermeticity is disk-deep only);\nthe known not-ours red classes list in the #212 hand-off.\n\n**BUILT 2026-08-24 (hertz, SIGNET #218 batch; PR #158).** The class fired its second witnessed\ninstance the same day — doyle's W2 gate rig, `engine_room_bringup_e2e` precondition panic with\nthe IR-50 panel naming `DOCS_SERVER_BIND_FAIL` port 5474 `os error 10048` — which armed this\nentry's own trigger. Hertz repro'd deterministically (held the port; brain still reached\nBRAIN_UP), pre-ranked three mechanisms before probing, and built the ephemeral-advisory form:\nrig-only `SPT_TEST_EPHEMERAL_ADVISORY_PORTS=1` makes the daemon's docs listener bind port 0\n(production config/`SPT_DOCS_PORT`/docs-url untouched; the flag matches the literal \"1\" only).\nThe golden workflow's test job sets it globally on both self-hosted legs, the standalone ER rig\nsets it too. Scope note kept honest per his own ranking: the docs collision is retired; if a\nco-diagnostic bind elsewhere still poisons a precondition, that is a residual face of THIS\nentry, not a closed question.\n\n### IR-63 — suite-mix sweeps leak job-escaped autostart daemons that LOCK the pool's spt.exe; and the same box conditions manufacture one random victim per sweep\n\n- **Status:** OPEN, mitigated-by-rig-step — the reap is adopted discipline, not yet construction.\n  Filed by doyle 2026-08-24 at the SIGNET #218 gates; first measured by todlando the same day\n  (his W1 build: four reap rounds of 2, 8, 1, 1 processes, count-by-path stated each round).\n- **Mechanism, two faces of one condition:** (1) e2e sweeps that exercise autostart leave\n  job-escaped daemons running `target/debug/spt.exe`; the NEXT build or `xtask check` then dies\n  on `os error 5` removing the exe — a rig red wearing a build defect's clothes. nextest's own\n  `leaky` flags corroborate (4–8 per sweep measured). (2) The same co-residence (leaked daemons +\n  resident fleet + runner traffic) manufactures ONE red per full sweep with a DIFFERENT victim\n  each time: doyle's W2 gate measured FOUR distinct one-off victims in four same-sha sweeps\n  (ER bringup, composite+bootstrap pair under CI load, resident_service, brain_resume), every\n  one green alone and/or in a sibling sweep. The e2e-leaked-daemons rule holds: a different test\n  dying each run on one sha is ONE environment cause, and hardening members never closes it.\n- **Mitigation adopted (rig step, both todlando's lanes and doyle's gate runner):** reap\n  `spt.exe` BY PATH (`*spt-core\\target*`) before EVERY cargo invocation and after every sweep;\n  report the count each time so a zero is a claim, not silence.\n- **Remedy direction (unbuilt):** the durable form is construction, not discipline — either\n  nextest wrap/xtask verb that performs the by-path reap as a pre-step on this box's rigs, or\n  autostart e2es gain teardown that provably outlives job escape (kin IR-38's built wedge-namer,\n  IR-62's ephemeral ports which retire one collision axis, IR-35's victim-rate ledger).\n- **THIRD FACE, measured 2026-08-30 (doyle, ir57/asm-241 reaps):** the leaked population is not\n  only daemons — battery legs leave ORPHANED HEADLESS `conhost.exe` processes whose CWD sits in\n  the worktree's `crates/spt-daemon` (where the leg ran), and a CWD pin blocks `Remove-Item`/\n  `git worktree remove` on the whole tree with \"being used by another process\" naming the DIR.\n  This is the mechanism behind every recent \"handle-pinned, retry later\" worktree removal: 31\n  such conhosts found at once (Aug 26–29 vintages) pinning FIVE dead worktrees. cargo/rustc\n  absence does NOT clear the suspect list — the conhost outlives its client. Holder census\n  tool: a ~30-line NtQueryInformationProcess CWD probe (PEB→ProcessParameters→CurrentDirectory)\n  over all pids, filtered on the path — names every holder in one pass where no handle.exe\n  exists. 13 killed scoped to the two consented reaps; 18 remain pinning gate-w1-a8f04aff (12),\n  io-parser-w1 (5), gate-w1-786d2381 (1 after kills) — sweep them at the IR-14/26/27/49 audit\n  slot before those removals.\n- **LANE-LINKED 2026-08-30 (#242 close sweep):** hertz's queued daemon-leak fixup lane carries\n  this entry (brief cites IR-7/17/20/34/35/63); leaves the register when that lane lands.\n- **Trigger condition:** next rig/gate-script construction touch, or the first golden red that\n  classifies to face (1).\n- **Size guess:** small-medium — one wrapper seam plus adopting it in the gate/lane scripts.\n\n### IR-64 — HFENDULEAM's disk floor is set by non-CI bulk: ~845 GB of operator payload leaves the golden box ~2 GB of slack against its own 32 GB preflight\n\n- **Status:** OPEN · **Origin:** doyle, v0.63.0 close sweep 2026-08-26; mechanism first measured\n  at the FIELD-SEAL golden window (deployah's IR-31 fifth addendum carries the POOL side of the\n  same event by agreed division — this entry is the OTHER reservoir, deliberately not his).\n- **Mechanism:** the 1.86 TB C: carries ~614 GB Steam + ~230 GB Downloads (operator payload, not\n  CI state). With that floor fixed, normal lane traffic alone walks the box under the 32 GB\n  golden preflight — a full-sweep pool WEIGHS ~90–112 GB steady state (IR-59's measurement) and\n  five FIELD-SEAL lanes cost 148.48 GB (IR-31 fifth addendum), so ONE milestone's pools exceed\n  the entire free margin. Reaping buys windows, not headroom: deployah measured free fall\n  167 → 108 GB within hours of his reap, ~59 GB re-consumed by lane builds. The recurring shape:\n  every milestone pays a reap-and-measure tax to rent space the box does not structurally have.\n- **Why register-worthy rather than \"clean up more\":** agent-side discipline (IR-31's budgeting,\n  pool reaps, teardown steps) is already adopted and still only rents windows — the reservoir\n  that would durably move the floor is operator-owned bulk no agent may touch. Naming it here is\n  the boundary: agents keep budgeting IN POOLS (not GB); moving Steam/Downloads (or adding a\n  disk, or pinning golden to a box without operator payload) is an OPERATOR decision this entry\n  exists to put in front of them once, with numbers, instead of re-deriving the floor each cut.\n- **Ripe when:** operator rules on the bulk (move/expand/accept-the-tax), OR the first golden\n  that dies at the 32 GB preflight despite adopted pool discipline (IR-59's LNK1180-class red).\n- **Size:** zero code; one operator decision + at most a runbook line naming the chosen floor.\n\n### IR-65 — kitsubito kernel-audit backpressure: a tailscale-snap AppArmor denial storm + no auditd turned the default audit backlog into a CI-wide stall amplifier (REMEDIATED AT BOX; re-check triggers named)\n\n- **Status:** REMEDIATED-AT-BOX 2026-08-25 (doyle, operator-authorized root — ruling pinned\n  releases#225 comment 5418800776); entry stays OPEN as the re-check record because the storm\n  SOURCE persists and two named events can silently revert the fix.\n- **Mechanism:** `snap.tailscale.tailscaled` (1.92.5) polls /proc and takes an AppArmor\n  ptrace-read DENIED per poll — a continuous kernel-audit record storm scaling with process\n  count (spawn-heavy serialized CI legs amplify their own storm). With NO auditd installed the\n  records rode printk (kauditd throttling) and the 8192 kernel backlog overran\n  (lost=1,537,743); the default `backlog_wait_time` 60000ms turns a full backlog into A 60s\n  SLEEP INSIDE ANY AUDITED SYSCALL — the broker dispatch stall that stretched IR-30's\n  Linux-face race window (see IR-30's Linux-face addendum; deaths clustered 59–63s ↔ this\n  knob's value).\n- **Remediation (verified at the EFFECTIVE layer, not the fragment):** auditd installed +\n  active (storm consumed, backlog drains to 0, lost flat), backlog_limit 32768,\n  backlog_wait_time 0 (full backlog may DROP, never STALL). ⚠ THE TRAP PAID FOR ONCE: the first\n  knob write (`50-backlog.rules`) silently LOST the augenrules merge — apt's own\n  `/etc/audit/rules.d/audit.rules` sorts LAST (digits before letters) and its `-b 8192` /\n  `--backlog_wait_time 60000` won; a whole proof run executed under the defaults while the\n  fragment grepped perfect. Values now live in the merge-WINNING file; verified `auditctl -s`.\n- **Re-check triggers (the reason this entry stays):** (1) tailscale snap update — the plug\n  landscape may change, the storm may stop or grow; (2) auditd package update/reinstall — may\n  rewrite `rules.d/audit.rules` and re-lose the merge; (3) box reimage. On any of these: one\n  `auditctl -s` (expect 32768/0) + one `journalctl -k | grep 'backlog limit'` (expect silence).\n- **Ripe when:** a re-check trigger fires. **Size:** two read-only commands per check.\n\n### IR-66 — first-chunk-needle test class: two latent members remain after the v0.63.0 fix (attach.rs:561, :672)\n\n- **Status:** BUILT — confirmed present at `17815c9c` (hertz 2026-09-06); leaves the register at the WEBSERVE close sweep. Hertz rider PR #161, landed ff at `d04b922d` (2026-08-27, IO-PARSER #22\n  intake rider). Both members got the later-needle treatment (TICK39 delayed past burst on both\n  OS arms; alt-screen entered before delayed ALT_VIEWPORT_MARKER). Gate: doyle — diff-scope\n  review; Windows isolated worktree 3× TICK39 PASS + clippy + treqs; Linux CLEAN worktree at the\n  PR sha on kitsubito 3× both cells PASS (independent of the builder's dirty-shared-tree proof,\n  disclosure on record). · **Origin:** doyle tree-wide census at `dbe3daad`\n  (releases#225 comment 5418844404 — the census that corrected my own resume.rs-scoped\n  overclaim), after the class's first member was RCA'd and fixed in v0.63.0's head.\n- **Mechanism (cite, not restate):** KNOWN-HAZARDS 6.9 same-session face, amended at\n  `dbe3daad` — `spawn_session_pid`'s Spawned-wait consumes-and-discards a first output chunk\n  that races the reply (~2ms window on a healthy Linux box; load-stretched under backpressure,\n  see IR-30 Linux-face + IR-65). A test whose needle exists ONLY in the child's first chunk\n  asserts winning a race the contract does not promise.\n- **The two members:** `crates/spt-daemon/tests/attach.rs:561` (TICK0..39 instant burst then\n  `cat`; needle TICK39 read directly after spawn — the whole burst can sit in the first\n  chunks) and `:672` `cross_node_cold_attach_to_alt_screen_gets_clean_repaint` (unix-only;\n  `printf '…ALT_VIEWPORT_MARKER'; cat` — needle in the first chunk). Failure shape differs from\n  the fixed member: both children idle on `cat`, so a lost prefix is a HANG killed by nextest's\n  backstop at exactly 240s (slow-timeout 60s × terminate-after 4) — not a natural-life death.\n  Verified NOT in the class: daemon_e2e.rs:209 (needle = echo of post-spawn input), attach.rs:995\n  + brain_swap.rs:170 (attach/replay reads, not spawn-waits).\n- **Fix shape (ruled at the v0.63.0 close):** hertz lane, NEXT intake — the same one-line\n  later-needle / robust-read treatment the resume seed got in `dbe3daad`; deliberately NOT\n  landed mid-r4. Both cells passed r4 (0.010–0.058s) — the members are latent, not failing.\n- **Ripe when:** next milestone intake (hertz test lane) or the first golden red at ~240s on an\n  attach cell — either way the mechanism and fix are pre-derived, triage should cite this entry\n  and skip the RCA. **Size:** two one-line test edits.\n\n### IR-67 — wave-battery gap: a `-p spt --bins` leg compiles bin targets as harnesses and runs ZERO integration/e2e tests, so batteries that lean on it carry silent no-coverage legs\n\n- **Status:** BUILT — remedy applied across the IO-PARSER #22 milestone (2026-08-27/28): every\n  wave battery named explicit `-p spt --test <suite>` e2e legs beside the `--bins` unit leg\n  (GW1..GW5 evidence), every builder evidence report carried a named real e2e per the dispatch\n  template, and the one filter mistake (a `--test` name not matching its file) REFUSED loudly\n  rather than silently skipping — the failure mode this entry exists to kill. Battery template =\n  the dispatch text now carried forward in gate craft.\n- **Was:** OPEN · **Origin:** doyle, banked at the SIGNET #218 gates 2026-08-25 (\"gate\n  battery gap learned\"), filed at this sweep per the standing rule.\n- **Mechanism:** `cargo test/nextest -p spt --bins` builds `[[bin]]` targets as TEST HARNESSES\n  (unit tests inside bins only) — `tests/` integration and e2e suites of the crate NEVER run,\n  and the leg's green output is indistinguishable from coverage. Kin of the two banked pool\n  faces (`--bins` never emits fixture exes; fresh-pool fixture reds) but this face is about the\n  BATTERY TEMPLATE: my SIGNET wave batteries carried a `-p spt --bins` leg believed to cover\n  the crate.\n- **Remedy:** at next intake, the wave-battery template gains an explicit `tests/` leg for the\n  spt crate (nextest `-p spt --test <suites>` or unfiltered `-p spt` where pool history\n  permits), and any battery doc that lists `--bins` as a coverage leg gets the one-line caveat.\n- **Ripe when:** next milestone intake (the battery template is touched at every intake).\n  **Size:** template lines only.\n\n### IR-68 — PSYCHE_INGEST_FAIL cause class unproven: git index.lock did NOT reproduce the ingest failure it was blamed for\n\n- **Status:** OPEN, investigation-shaped · **Origin:** todlando measurement at the W2 int-leg rig\n  (IO-PARSER #22, PR #163 at `769fb0a9`, 2026-08-27), reported measure-first; filed by doyle.\n- **The contradiction:** the six silent `PSYCHE_INGEST_FAIL:todlando` lines observed at the\n  drop-dir probe (2026-08-25) were attributed to shared-checkout git `index.lock` contention. The\n  W2 rig planted NON-EMPTY `index.lock` files in BOTH places git takes one (bare git-dir + every\n  `<git_dir>/worktrees/<name>/`, mirroring `branchstore::sweep_stale_index_locks`, plant count\n  asserted >= 2) — and the ingest COMMITTED ANYWAY (tier write `Written`; `route_slices`\n  propagates `commit_live(...)?`, so a blocked checkpoint would have failed it). Non-empty was\n  deliberate: KH 1.3 reaps only 0-byte locks, and `pulse_tick` runs no boot sweep. So on this\n  store an `index.lock` does not block the checkpoint, and the field incident's mechanism is\n  UNKNOWN, not merely unconfirmed. The rig's doc comment records the attempt; the shipped int leg\n  fails the ingest at the drop READ instead (upstream of the store).\n- **Strongest negative evidence, pinned to the executable rig:**\n  `crates/spt-daemon/tests/commune_io_events_int.rs:95-107` documents that the lock mechanism was\n  tried **first**, planted non-empty locks in both the bare git-dir and every linked-worktree\n  location, asserted that the population was non-empty, and still observed `Written`. Its own\n  sentence is the required scope boundary: “This leg does not claim to reproduce a mechanism it\n  measured as inert.” The working injection is instead drop-file → directory replacement, which\n  fails the upstream read deterministically and proves only the `COMMUNE_FAIL` event contract.\n- **NOT claimed:** that the field incident was misattributed to ingest failure generally — the\n  files did survive with failed-ingest log lines; what is unproven is the index.lock CAUSE.\n- **Ripe when:** next PSYCHE_INGEST_FAIL sighting in the field (capture the failing store state\n  before touching it), or a dedicated probe slot. W2's COMMUNE_FAIL event now pushes a NAMED\n  reason on every failure, so the next occurrence self-reports its cause — read that first.\n  **Size:** investigation; no product change until the mechanism is pinned.\n\n### IR-69 — inherited stderr tokens can tear between format fragments; 26 test consumers parse that surface as structured truth\n\n- **Status:** OPEN, product remedy complete and parked GREEN-AND-READY at `d0fdd58d` on\n  `feat/emit-single-write`, owned by **todlando**, awaiting golden-batch assembly; board request\n  releases#241 carries the product remedy and full lane evidence in comment 5461613480. This entry\n  is the exposure map and census discipline, not the implementation. · **Origin:** CONDUIT #236 r3\n  golden attempt 2,\n  2026-08-29: `endpoint_autostart_e2e` missed its contiguous\n  `ENDPOINT_AUTOSTART:gwauto` keystone although the matching fresh session id proved the replay\n  happened. Attempt 3 was clean on the same discarded SHA after 139 GB was reaped; unequal load\n  makes the pair corroborating, never a rate.\n- **Mechanism, recovered from the literal torn bytes:** two daemon processes inherited one stderr\n  pipe. `BRAIN_UP` and `ENDPOINT_AUTOSTART` are each one `eprintln!`, but `write_fmt` may reach the\n  handle once per format fragment; the per-process stderr lock cannot serialize the other process.\n  The observed interleave split the autostart token between `ENDPOINT_AUTOSTART:` and `gwauto`.\n  This is fragment-level cross-process interleaving, not a failed replay and not a two-thread race.\n- **Durable remedy, ruled product-side:** render a complete diagnostic line into one buffer and\n…\n  sibling token remains exposed.\n…\n\n\n[Showing lines 3128-3623 of 5781. Use :3624 to continue. Some lines truncated to 768 chars]"}],"details":{"truncation":{"content":"  correct hunks, this one is a fidelity LOSS during resolution.\r\n- **Two must-dos, both cheap:**\r\n  1. **Compile the assembled head before it is handed anywhere — including forward to your own next\r\n     session.** A head is not ready on a treqs exit; it is ready on a build. Any sentence carrying a\r\n     head sha to another agent must name the instrument that proved it.\r\n  2. **Audit pick fidelity on CHANGED LINES for every pick on the chain**, not just the one that\r\n     tripped you: hash `git show --format= <sha> | grep -E '^[+-]' | grep -vE '^(\\+\\+\\+|---)'` for\r\n     the lane source and for the pick, and compare. Whole-diff comparison is useless here — hunk\r\n     headers and context legitimately drift once the head's copy of the file has moved.\r\n- **Read COUNT and HASH together, because they fail in opposite directions.** Of 24 picks on this\r\n  chain two did not match. `b2194aa9 → 4d6deed1` differed in COUNT (302 lane / 300 pick by the header-excluding pipeline above; **this entry originally cited 310/308, which is the RAW `^[+-]` count INCLUDING the 8 `+++`/`---` header lines of its 4 files** — the figures were taken without the second grep the entry itself prescribes. The DELTA is 2 under either meter, which is why the wrong figures never surfaced: they supported a correct conclusion, so nothing pressed them. Corrected todlando 2026-08-29, measured both ways in-tree) — the real\r\n  defect. `f27f15c6 → 5865cc98` had the SAME count and a different HASH — benign: a `CONTEXT.md`\r\n  paragraph the head had already amended for #209, whose merged result correctly carries both lanes'\r\n  sentences. A count check MISSES the first class entirely; a hash check FLAGS the second as if it\r\n  were a defect. Neither alone classifies a pick.\r\n- **Repair shape used, recorded because it is the cheap one:** reset to the commit before the bad\r\n  pick, re-pick the lane source, resolve the same conflict correctly, then replay the remaining picks\r\n  in chain order with the fidelity check on each. Verify the repair changed nothing else with a\r\n  WHOLE-TREE diff against the old head — it must show exactly the restored lines and no other file.\r\n  Where a later pick re-conflicts, check its pre-pick blobs against the old chain\r\n  (`git rev-parse <old-pick>~1:<file>`); if they match, the old chain's post-pick blob is a\r\n  transferable, already-reviewed resolution.\r\n- **AND GATE THE REPAIR'S OWN SUBJECT.** The rebuilt head passed six legs — clippy `-D warnings`,\r\n  sweep 660/660, treqs 803/803, xtask OK — while the restored lines live in `spt-store`, whose LIB\r\n  tests `-p spt --bins` never runs. Six greens, and not one executed the function the repair\r\n  restored; it was proven to COMPILE and assumed to PASS. Proven afterwards by name (4/4) and by the\r\n  full `spt-store --lib` suite (519/519). **A repair's gate must include the suite that owns the\r\n  repaired file**, which is not necessarily the suite the head gate runs.\r\n- **FIRST LIVE CATCH, and it was the author's own resolution (2026-08-29, one hour after the verb landed):** rebasing the IR-59 rider over the IR-57 rider produced four conflicts — three additive keep-both, one usage line both sides had edited. `xtask pick-audit` read the rebase as **LOSS, 282 lane / 280 pick**. The two missing lines were a `[[requirements]]` header and its blank line in `traceable-reqs.toml`, so `id = REQ-DISK-FLOOR-PREFLIGHT` landed INSIDE the previous table as a duplicate key: **`traceable-reqs check` exit 2, the registry unparseable, every reading after that edit checking nothing**. Restored, the same audit reads **DRIFT 282/282** whose one differing line is the usage string whose base copy legitimately gained the other verb — both verdi…\n- **FIRST REAL-ASSEMBLY USE (2026-08-29, #241 emission head, ASM-241-GATE-VERDICT.md):** `xtask\r\n  pick-audit --range 57a0d27c..HEAD --lane 4d6007ac..d0fdd58d` over 6 picks — **5 MATCH\r\n  (digest-identical), 1 LOSS, 0 drift, 0 unclassified**, exit 1 forcing the accounting. The LOSS\r\n  was exactly the one human-resolved conflict (`cfb9d9f8 <- 10f12e4c`, count 432/402), and the\r\n  delta RECONCILED to the resolution rather than assumed: lane stat 15 files/235+/197- vs pick\r\n  14 files/205+/197-, difference byte-for-byte the deliberately-dropped 30-line interim IR-69\r\n  register block superseded by main's consolidated entry. No false positives, no silent pass.\r\n  Entry stays OPEN as living procedure; both live uses (the rebase catch above, this assembly)\r\n  produced the verdict classes in the order the entry predicts.\r\n- **Trigger condition:** ripe at the next assembly — this is procedure, and its cost is one command\r\n  per pick.\r\n- **Size guess:** small as a scripted check in `xtask` (fidelity audit over a pick range); zero as\r\n  discipline, which is how it is being applied now.\r\n\r\n### IR-58 — a `[[bin]]` grep is not a census: cargo AUTODISCOVERS `src/bin/*.rs` targets, and a hand-built bin list produced a confident false \"this bin does not exist\"\r\n\r\n- **Status:** OPEN, unowned. Filed by doyle 2026-08-22; **its original filing was WRONG and is\r\n  retracted in full below.** The entry is kept because the way it was wrong is the finding.\r\n- **RETRACTED CLAIM, stated plainly so no reader acts on it:** this entry first said that\r\n  `crates/spt/Cargo.toml:18-21` and `crates/spt/src/cli.rs:30355` forbid a bin-name collision with\r\n  `xlate_choreo_fixture`, \"a bin that does not exist\", and that spt-daemon's third helper had been\r\n  renamed to `summarizer_fixture`. **`xlate_choreo_fixture` EXISTS** — at\r\n  `crates/spt-daemon/src/bin/xlate_choreo_fixture.rs`, verified at the assembly head. The collision\r\n  rule's counterpart is real, both prose sites are CORRECT, and IR-21's original table row was\r\n  correct too; it merely predated `summarizer_fixture`. Nothing in that prose needs fixing.\r\n- **How the false claim was produced, which is the entry:** the census was built by grepping\r\n  `^\\[\\[bin\\]\\]` across `Cargo.toml`s. **Cargo AUTODISCOVERS `src/bin/*.rs` as bin targets with no\r\n  stanza at all**, so a stanza grep cannot see them, and it fails SILENTLY — it returns a clean,\r\n  well-formed list that is simply short. From that list it read as established fact that a named bin\r\n  had been renamed away, and that \"fact\" was then written into a register table, an IR entry, and a\r\n  message to the builder. **A pattern-built population encodes the pattern's assumption; the count\r\n  looks like a census and is a property of the pattern.**\r\n  (Found by todlando, resolving one of doyle's figures against his own tree under the pointer rule.)\r\n- **A CENSUS IS ALSO A PROPERTY OF A TREE.** Stanza counts differed legitimately across trees the\r\n  same hour — 13 at the assembly head, 11 at `dc1c7532` — because `summarizer_fixture` exists at one\r\n  and not the other. Two correct censuses of the same workspace disagree unless each names its sha.\r\n- **The must-do, and it removes the list rather than lengthening it:** never hand-maintain a bin\r\n  roster. Run `cargo build --workspace --bins` and let cargo enumerate its own targets — the same\r\n  enumeration the test harness resolves against, so it cannot drift from what a fixture lookup\r\n  expects. Stanza-derived lists, remembered pairs, and register tables are all the roster problem at\r\n  different depths; only cargo's own enumeration is the population.\r\n- **Kin:** IR-55's amended prebuild bullet (prebuild the census, not a remembered pair) and IR-42\r\n  (a verb that writes without adjudicating). The shared shape is an instrument returning an orderly\r\n  answer about a set it never fully saw.\r\n- **Trigger condition:** ripe on any `xtask` check work — a duplicate-bin-name check over cargo's\r\n  target enumeration (NOT over manifest stanzas) is a handful of lines and cannot go stale.\r\n- **Size guess:** small. The prose fix originally proposed here is WITHDRAWN — there was nothing\r\n  wrong with the prose.\r\n\r\n### IR-59 — pool arithmetic: this box holds TWO cold pools, not four; and a build that exhausts the volume reds as a LINKER defect that names no disk\r\n\r\n- **Status:** OPEN, unowned — it is arithmetic and discipline, not a code lane. Filed by doyle\r\n  2026-08-22 from a live disk-floor abort during the TURNKEY #212 W4 gate; footprint figures measured\r\n  by todlando the same hour.\r\n- **SECOND FACE, measured 2026-08-23/24 (WAX-SEAL #21 W2 gate, doyle — the violator this time):**\r\n  both predicted mechanisms fired at once, WITHOUT the floor guard because the gate legs ran as a\r\n  plain script. (1) doyle minted a THIRD cold pool (gate rig) while todlando's lane pool was LIVE —\r\n  the two-pool arithmetic, violated by the gater. (2) The lane pool had silently accumulated\r\n  **104.8 GB** over repeated full-workspace sweeps (nothing bounds or even measures a pool's\r\n  accumulation until the volume dies). The volume hit **3 MB free**; the reds wore exactly the\r\n  entry's predicted costume — `LNK1318: Unexpected PDB error; LIMIT (12)` naming no disk — plus a\r\n  second face worth keeping: `traceable-reqs check` died as a PANIC printing to stdout\r\n  (`os error 112`), so a REGISTRY gate red can also be the disk's. Both gate verdicts VOIDED\r\n  (clippy's full compile had exited 0 before space died — the code was never the question).\r\n  Recovery measured: gate pool reap 9.6 GB, lane pool clean 100.2 GB, drive back to 109.6 GB free.\r\n  **Remedies adopted at the incident:** the gate never mints its own pool while a builder lane is\r\n  live on the box — it takes the lane pool over SEQUENTIALLY at pool-release (warm, loud, the\r\n  releases#103 pattern); and gate/lane scripts get the disk-floor preflight the golden runner\r\n  already carries (this entry's part 2, still unbuilt).\r\n- **THIRD FACE, measured 2026-08-24 (WAX-SEAL #21 golden window, doyle):** two new mechanisms, both\r\n  about the REMEDY rather than the red. (1) The wax-seal-w1 lane pool **re-accumulated to 152–169 GB\r\n  (two meters, IR-46 caveat) within ONE DAY of the 08-23 clean** and rode the volume back down to\r\n  4.92 GB free — a reap is an instant, not a state; nothing yet bounds a pool between reaps.\r\n  (2) **The remedy itself arrived garbled through relay:** the golden push was held \"waiting on the\r\n  IR-59 reboot\" when this entry prescribes no reboot anywhere — tens of releases have shipped without\r\n  one; the operator refused the premise and the register's own recorded remedy (reap finished-lane\r\n  pools) cleared it in ten minutes. A remedy relayed as a DIFFERENT remedy is the relay trap wearing\r\n  infra clothes: the entry is the author — read it before adopting a hold. Recovery measured: five\r\n  finished-lane pools reaped after ancestry classification (`git cherry` catches rebased lands that\r\n  a plain `merge-base --is-ancestor` calls unlanded — gate-w4l1's 90.9 GB pool was reapable only by\r\n  that meter), 4.92 → 260.88 GB free (~256 GB free-delta vs ~270–287 GB sum-of-lengths). Two main\r\n  runs red inside the low-disk window (09:17Z/09:41Z) were re-run, not re-read, per this entry's\r\n  must-do.\r\n- **FOURTH FACE, measured 2026-08-24 same day (SIGNET #218 W2 gate, doyle — the gater's own pool\r\n  this time):** the MAIN pool went **13.7 GB → 158.3 GB in ONE DAY** absorbing four full gate\r\n  batteries across two lane tips, and dragged the volume to **18 GB free mid-gate** — so the\r\n  entry's mechanism is not a lane-pool problem, it is EVERY pool under repeated full sweeps, the\r\n  gate rig included. Two riders worth the ink: (1) the golden runner's **free-space floor step\r\n  produced its first live catch** — a thin CI leg refused at 14:14 local over exactly this window\r\n  with zero test signal, and the register's re-run-not-re-read rule resolved it in one command;\r\n  (2) the reap-and-rebuild trade (\"cleaning a live pool buys one window at rebuild price\") was\r\n  taken deliberately mid-gate and cost ~35 minutes cold — cheaper than one uninterpretable red.\r\n  A red measured at 18 GB free in this gate got NO read at all, and the next sweep's red was a\r\n  DIFFERENT test: low disk manufactures random victims before it manufactures link errors.\r\n- **The event:** a gate's preflight refused with `GATE_ABORTED_DISK_FLOOR` at **4.75 GB free on a\r\n  1863 GB volume**. Four cold pools plus the milestone head's pool were standing at once. The floor\r\n  guard did its job — without it a full workspace build would have started with under 5 GB of\r\n  headroom and produced a red belonging to nothing.\r\n- **THE ARITHMETIC, and it corrects the intuition that worktrees are the cost.** Measured across the\r\n  whole `.worktrees` tree: **45 worktrees = 0.79 GB total** (~18 MB each). **3 pools = 130.45 GB.**\r\n  Worktrees are **0.6%** of the footprint; pools are **99.4%**. **One cold pool is worth roughly 2,500\r\n  worktrees.** A rule keyed on worktree count would cost a day of `git worktree remove` work for under\r\n  a gigabyte, risk removing a lane someone still wants, and leave the lever untouched.\r\n- **THE CEILING, as arithmetic rather than hygiene:** at **45–75 GB per cold pool** on this workspace\r\n  against a **40 GB floor**, this box supports **TWO live pools comfortably, THREE only if one is\r\n  small**. The two rules that already exist need no replacement, only this number attached:\r\n  - **Reap a pool when its lane is finished** → 45–75 GB back immediately.\r\n  - **Do not run two builds at once** → not only the contention argument, but **75–150 GB of\r\n    simultaneous allocation** against that floor.\r\n- **A FULL VOLUME REDS AS A LINKER DEFECT.** `LINK: fatal error LNK1318: Unexpected PDB error`\r\n  (variously `OK (0)` or `LIMIT (12)`), often beside `LNK4209: debugging information corrupt`. It\r\n  reads as a corrupt artifact or a broken toolchain and is neither — it is the linker unable to grow\r\n  a large `.pdb`. **Nothing in the failure text says \"disk\".** Do not key recognition on the\r\n  parenthesised code; it varies.\r\n- **THE DANGER WINDOW IS THE TAIL OF A COLD BUILD, not a steady state you can check once.** The\r\n  2026-08-22 instance died at the link of `spt` — the last and largest artifact of a **74 GB** cold\r\n  pool — while that same build was draining the volume out from under itself. A free-space reading\r\n  taken before the build would have looked fine.\r\n- **Positive tell, with its own refutation attached:** `traceable-reqs check` alone surviving a leg\r\n  table is suggestive, because it is the only leg that never links. It is a POSITIVE tell ONLY — a\r\n  full disk can red before any link step, so the signature's ABSENCE clears nothing.\r\n- **THE FALSIFIER IS FREE SPACE AT THE TIME OF THE RUN**, not the shape of the leg table.\r\n- **Must-do, both cheap:**\r\n  1. **A free-space reading goes in the FIRST LINE of any build-failure report** — not in the\r\n     controls, not as a follow-up. Two agents spent hours on a mechanism for this failure and neither\r\n     ran `df`; the falsifier was one command away throughout.\r\n  2. **Rig and gate logs should record free space at run start.** Today they do not, which makes \"was\r\n     the disk full\" **unanswerable after the fact for every red already in hand**. Any red produced\r\n     under ~1 GB free is UNINTERPRETABLE and must be **re-run, not re-read**.\r\n- **Measurement caveat, observed twice in one hour:** sum-of-file-lengths and free-space delta\r\n  disagree by several percent when anything else on the box is writing (98.07 GB of subtrees → 92.25\r\n  GB reclaimed; 47.28 GB → 40.81 GB). Report BOTH, derive neither from the other, and treat any single\r\n  free-space number as an instant rather than headroom — see IR-46.\r\n- **FIFTH FACE, measured 2026-08-29 at the CONDUIT #236/v0.65.0 cut (deployah):**\r\n  the finished milestone's sequential lane-sharing accumulated **140.51 GB**, while a freshly\r\n  rebuilt pool measured **7.78 GB** — about **18× one build's working set** retained across lane\r\n  hand-offs with no reap between them. This is the budgetable rate behind that cut's disk-floor\r\n  red: sequential execution prevents concurrent ownership corruption, but it does not bound\r\n  historical artifacts inside the shared pool. Treat takeover and reclamation as separate\r\n  operations; a pool may be safe to reuse and still be too large to keep.\r\n- **SEVENTH FACE, measured 2026-08-30 (v0.67.0 milestone close — the PARALLEL-LANE fill\r\n  rate):** the #23 wave arc drove C: from ~240 GB free to **0.01 GB in ~3.5 hours**: four\r\n  concurrent/serial lane+gate pools totalled **236.6 GB** (ns23-w1 87.7 + ns23-113 72.3 +\r\n  gate rig 57.3 + ns23-w3 19.1) — effectively the entire ir57 reclaim re-consumed inside one\r\n  milestone's build window. The head gate and two thin-CI runs redded with the entry's exact\r\n  costume (\"could not compile\" + treqs panic, zero disk words) at 0.01 GB and all re-earned\r\n  green after reclaim (+186.6 GB, finished-lane targets only, single-actor rule held under\r\n  racing consent). Budget rule this face adds: a MULTI-WAVE milestone on one box books\r\n  ~60-90 GB PER LANE-PLUS-GATE cycle, so the pool budget is per-wave, not per-milestone —\r\n  reap each wave's pool at its LAND, not at the milestone party (the party inherited only\r\n  ~58 GB because the emergency had already forced the other ~179).\r\n- **SIXTH FACE, measured 2026-08-30 (#242 golden r4, Windows test job, LNK1318 at the PDB\r\n  write):** the floor is asserted ONCE at job START, but the job's internal LOW-WATER sits at its\r\n  LAST heavy step — the docs-drift build, ~28 minutes in. r4's floor read 65.1 GiB honest at\r\n  23:07; the box was at ~37–39 GB by the 23:35 link failure. LNK1318 on PDB write = this entry's\r\n  documented low-disk costume; the incremental-corruption candidate was retired by preservation\r\n  snapshot (no xtask state existed at failure). **Durable fix = a floor RE-READ (or reclaim)\r\n  immediately before the docs-drift build** — the WITHIN-job sibling of the across-job\r\n  read-after-checkout fix, rides the next workflow commit. Riders: incremental hygiene as\r\n  disk-pressure maintenance (the dir measured 4.56 GB), and the box's **~51 GB non-recovering\r\n  post-run consumption** is this entry's pool-weight face — classify at the IR-14/26/27/49 audit\r\n  slot (composed this sweep).\r\n- **Composed for next intake (doyle, v0.65.0 close):** the still-open log-the-floor build half\r\n  rides with [[IR-57]]'s scripted pick-fidelity audit as the next milestone's two tooling riders.\r\n- **Trigger condition:** ripe now for the log-the-floor half (it rides any gate-script or CI touch);\r\n  the arithmetic is discipline and applies immediately.\r\n- **Size guess:** small — one line in each rig/gate preflight to record free space alongside the\r\n  existing floor check.\r\n\r\n### IR-60 — a wrapper that CAPTURES a leg's exit status ends with the capture, so the wrapper's own status is the capture's, not the leg's\r\n\r\n- **Status:** OPEN, unowned — script-shape discipline, not a code lane. Filed by doyle 2026-08-22\r\n  during the TURNKEY #212 W5 lane; mechanism measured by todlando, who reported it first as a\r\n  possible harness misreport and then RETRACTED that reading himself on a minimal probe.\r\n- **The reading that started it:** a background leg was summarised as `exit code 0` while the leg's\r\n  own exit file read `100`. Reported as-is, that is a task runner lying about a red — the worst\r\n  possible direction for a purposeful-red claim, since it would turn two reds that DID fire into two\r\n  reds reported as not having fired.\r\n- **The measurement, minimal and on this box:**\r\n\r\n      ( exit 100 ); echo $? > probe.exit; FINAL=$?\r\n      leg status captured to file : 100\r\n      wrapper's own final status  : 0\r\n\r\n  The wrapper's shape is `( cd <lane> && cargo nextest ... > leg.raw 2>&1 ); echo $? > leg.exit`.\r\n  **The last command is the `echo`, which succeeds**, so the wrapper genuinely exits 0 while the leg\r\n  genuinely exited 100. THE RUNNER TOLD THE TRUTH ABOUT THE WRAPPER. There is nothing to file against\r\n  the task runner, and it would have been filed.\r\n- **The class, and this is why it is worth an entry rather than a fix:** it is the truncation-pipe\r\n  family — the meter measured something real, it just was not the thing about to be quoted. **Three\r\n  shapes now share ONE trigger, and the trigger is not \"is this a pipe\":**\r\n  1. a truncation pipe (`cmd | tail`, `cmd | head`) — `$?` measures the truncator, and `head` closing\r\n     the pipe can MANUFACTURE a status (SIGPIPE → 101), so `PIPESTATUS` is not protection either;\r\n  2. a flattened `$?` read after any intervening command;\r\n  3. **a wrapper whose last command is the capture itself.**\r\n  **The trigger in all three is the REPORTING** — every instance happened while trimming or capturing\r\n  output in order to QUOTE it as evidence.\r\n- **The practice that held, and the one to keep:** the leg's own file is the leg's verdict. Both reds\r\n  were real, and the only reason that was knowable is that every leg wrote its exit to its own file\r\n  rather than to the wrapper's status.\r\n- **Remedy, in preference order:** (1) never read a wrapper's status as a leg's — read the leg's exit\r\n  FILE, which the per-leg rule already requires; (2) if a wrapper's own status must be meaningful,\r\n  end it by re-raising the captured status (`exit \"$(cat leg.exit)\"`) or set the status before the\r\n  capture is the last word; (3) for anything that becomes evidence, redirect to a file and read the\r\n  file.\r\n- **Trigger condition:** ripe now — it rides the next gate-script touch, and the gate scripts in this\r\n  milestone already write per-leg exit files, which is what makes this discipline rather than debt.\r\n- **Size guess:** small — a convention line in the gate-script preamble; no product code.\r\n\r\n### IR-61 — spacerun's test-module skip carries a SECOND literal tracker; the two answers can drift, and today only a cell stands between them\r\n\r\n- **Status:** OPEN, unowned, accepted-with-mitigation. Filed by doyle 2026-08-22 at the TURNKEY #212\r\n  head gate, as the named residual of the latch repair (the repair itself rides the milestone).\r\n- **What the debt is.** `crates/xtask/src/spacerun.rs` now skips a column-0 `#[cfg(test)]` module by\r\n  BRACE DEPTH and resumes after its close, rather than latching the scan to end-of-file. Counting\r\n  braces safely means knowing when a brace is inside a string, a raw string or a char literal — and\r\n  the scanner ALREADY tracks literals for its rendering pass. It does not reuse that tracking. There\r\n  are now TWO answers in one file to \"am I inside a literal\", and **two answers to one question is a\r\n  disagreement waiting for a reader who fixes one of them.**\r\n- **Why it was accepted rather than refactored on the spot, stated so the trade is auditable:** the\r\n  two trackers answer genuinely different questions — the rendering walk is PER LINE and forward\r\n  from an opening quote (\"where does this literal start and end\"), while the skip needs \"am I inside\r\n  a literal right now\" carried CONTINUOUSLY across lines. Unifying them is a real refactor of a check\r\n  that is already gated, already carries five fixed defects, and sits on the tree being handed to\r\n  golden. The narrow change with an OBSERVABLE failure mode beat the correct-shaped change with a\r\n  wide blast radius, on that tree, on that day.\r\n- **The mitigation, and its exact limit.** Three brace cells fail the moment the two trackers\r\n  disagree about a raw string, a normal string or a char literal, plus a cell that reds when the skip\r\n  stops consulting a literal tracker at all (`match lit` -> `match Lit::None`). **That is a cell\r\n  standing in for a refactor.** It catches drift in the three forms it names and nothing else — a\r\n  fourth literal form, or a change to only one tracker in a form neither cell covers, passes.\r\n- **The general shape, which is why this is a register entry rather than a comment:** a check whose\r\n  own correctness depends on a second implementation of a thing it already implements is one\r\n  refactor away from the defect class it exists to prevent. This same file has already produced\r\n  three instrument defects (an indented-marker latch, a column-0 latch, and a suppression that\r\n  decided what got PARSED rather than what got REPORTED). The pattern is not carelessness; it is a\r\n  scanner accumulating special cases.\r\n- **Trigger condition:** the next SUBSTANTIVE change to spacerun's scanning — any new skip, any new\r\n  literal form, any change to either tracker. At that point unify, rather than adding a third answer.\r\n- **Size guess:** small to medium — one continuous literal-state walk serving both the render pass\r\n  and the skip, with the existing corpus and brace cells as the regression net.\r\n\r\n### IR-62 — an e2e daemon binds well-known ports and collides with the resident fleet on shared runners\r\n\r\nFiled 2026-08-23 (doyle), from the #212 r2 golden's Windows Phase A red — one witnessed\r\ninstance, mechanism verified from the run's own capture, filed on the mechanism per the\r\nregister's standard.\r\n\r\n**Mechanism.** `endpoint_autostart_e2e::saved_endpoint_replays_on_daemon_restart` failed its\r\nown PRECONDITION (\"daemon B must come up with a fresh brain\") because daemon B's broker came up\r\ndegraded: `NODE_KEY_FAIL: identity unavailable` (net-less broker, no retry) and\r\n`DOCS_SERVER_BIND_FAIL` port 5474 `os error 10048` — the docs port was held by a CO-RESIDENT\r\ndaemon. HFENDULEAM is live infra: the resident fleet's daemon legitimately holds well-known\r\nports, and any e2e that brings up a daemon with default port bindings is in a race with it BY\r\nCONSTRUCTION. An isolated SPT_HOME isolates the store and broker socket, NOT globally-numbered\r\nTCP ports.\r\n\r\n**Classification history.** r2: red (35.4s, precondition panic). Run 1 and r3 on the same box:\r\ngreen. Folded into r3 under a pre-registered predicate (reds twice → dedicated triage); it\r\ngreened, so this stays an environment-shaped intermittent, NOT a product defect and NOT\r\nclosed — the collision window is real and will re-fire under the right co-residence timing.\r\n\r\n**Remedy direction (not built).** Test daemons should bind ephemeral/rig-scoped ports for\r\nevery advisory surface (the docs server is advisory — a bind failure should degrade the rig\r\nloudly, not poison an unrelated cell's precondition), or the precondition should name the\r\nport-collision cause distinctly so the red self-classifies. Either lane is test/CI work\r\n(hertz's), triggered the next time this class fires anywhere.\r\n\r\n**Kin.** IR-51 (e2e daemon net-enabled on real interfaces — hermeticity is disk-deep only);\r\nthe known not-ours red classes list in the #212 hand-off.\r\n\r\n**BUILT 2026-08-24 (hertz, SIGNET #218 batch; PR #158).** The class fired its second witnessed\r\ninstance the same day — doyle's W2 gate rig, `engine_room_bringup_e2e` precondition panic with\r\nthe IR-50 panel naming `DOCS_SERVER_BIND_FAIL` port 5474 `os error 10048` — which armed this\r\nentry's own trigger. Hertz repro'd deterministically (held the port; brain still reached\r\nBRAIN_UP), pre-ranked three mechanisms before probing, and built the ephemeral-advisory form:\r\nrig-only `SPT_TEST_EPHEMERAL_ADVISORY_PORTS=1` makes the daemon's docs listener bind port 0\r\n(production config/`SPT_DOCS_PORT`/docs-url untouched; the flag matches the literal \"1\" only).\r\nThe golden workflow's test job sets it globally on both self-hosted legs, the standalone ER rig\r\nsets it too. Scope note kept honest per his own ranking: the docs collision is retired; if a\r\nco-diagnostic bind elsewhere still poisons a precondition, that is a residual face of THIS\r\nentry, not a closed question.\r\n\r\n### IR-63 — suite-mix sweeps leak job-escaped autostart daemons that LOCK the pool's spt.exe; and the same box conditions manufacture one random victim per sweep\r\n\r\n- **Status:** OPEN, mitigated-by-rig-step — the reap is adopted discipline, not yet construction.\r\n  Filed by doyle 2026-08-24 at the SIGNET #218 gates; first measured by todlando the same day\r\n  (his W1 build: four reap rounds of 2, 8, 1, 1 processes, count-by-path stated each round).\r\n- **Mechanism, two faces of one condition:** (1) e2e sweeps that exercise autostart leave\r\n  job-escaped daemons running `target/debug/spt.exe`; the NEXT build or `xtask check` then dies\r\n  on `os error 5` removing the exe — a rig red wearing a build defect's clothes. nextest's own\r\n  `leaky` flags corroborate (4–8 per sweep measured). (2) The same co-residence (leaked daemons +\r\n  resident fleet + runner traffic) manufactures ONE red per full sweep with a DIFFERENT victim\r\n  each time: doyle's W2 gate measured FOUR distinct one-off victims in four same-sha sweeps\r\n  (ER bringup, composite+bootstrap pair under CI load, resident_service, brain_resume), every\r\n  one green alone and/or in a sibling sweep. The e2e-leaked-daemons rule holds: a different test\r\n  dying each run on one sha is ONE environment cause, and hardening members never closes it.\r\n- **Mitigation adopted (rig step, both todlando's lanes and doyle's gate runner):** reap\r\n  `spt.exe` BY PATH (`*spt-core\\target*`) before EVERY cargo invocation and after every sweep;\r\n  report the count each time so a zero is a claim, not silence.\r\n- **Remedy direction (unbuilt):** the durable form is construction, not discipline — either\r\n  nextest wrap/xtask verb that performs the by-path reap as a pre-step on this box's rigs, or\r\n  autostart e2es gain teardown that provably outlives job escape (kin IR-38's built wedge-namer,\r\n  IR-62's ephemeral ports which retire one collision axis, IR-35's victim-rate ledger).\r\n- **THIRD FACE, measured 2026-08-30 (doyle, ir57/asm-241 reaps):** the leaked population is not\r\n  only daemons — battery legs leave ORPHANED HEADLESS `conhost.exe` processes whose CWD sits in\r\n  the worktree's `crates/spt-daemon` (where the leg ran), and a CWD pin blocks `Remove-Item`/\r\n  `git worktree remove` on the whole tree with \"being used by another process\" naming the DIR.\r\n  This is the mechanism behind every recent \"handle-pinned, retry later\" worktree removal: 31\r\n  such conhosts found at once (Aug 26–29 vintages) pinning FIVE dead worktrees. cargo/rustc\r\n  absence does NOT clear the suspect list — the conhost outlives its client. Holder census\r\n  tool: a ~30-line NtQueryInformationProcess CWD probe (PEB→ProcessParameters→CurrentDirectory)\r\n  over all pids, filtered on the path — names every holder in one pass where no handle.exe\r\n  exists. 13 killed scoped to the two consented reaps; 18 remain pinning gate-w1-a8f04aff (12),\r\n  io-parser-w1 (5), gate-w1-786d2381 (1 after kills) — sweep them at the IR-14/26/27/49 audit\r\n  slot before those removals.\r\n- **LANE-LINKED 2026-08-30 (#242 close sweep):** hertz's queued daemon-leak fixup lane carries\r\n  this entry (brief cites IR-7/17/20/34/35/63); leaves the register when that lane lands.\r\n- **Trigger condition:** next rig/gate-script construction touch, or the first golden red that\r\n  classifies to face (1).\r\n- **Size guess:** small-medium — one wrapper seam plus adopting it in the gate/lane scripts.\r\n\r\n### IR-64 — HFENDULEAM's disk floor is set by non-CI bulk: ~845 GB of operator payload leaves the golden box ~2 GB of slack against its own 32 GB preflight\r\n\r\n- **Status:** OPEN · **Origin:** doyle, v0.63.0 close sweep 2026-08-26; mechanism first measured\r\n  at the FIELD-SEAL golden window (deployah's IR-31 fifth addendum carries the POOL side of the\r\n  same event by agreed division — this entry is the OTHER reservoir, deliberately not his).\r\n- **Mechanism:** the 1.86 TB C: carries ~614 GB Steam + ~230 GB Downloads (operator payload, not\r\n  CI state). With that floor fixed, normal lane traffic alone walks the box under the 32 GB\r\n  golden preflight — a full-sweep pool WEIGHS ~90–112 GB steady state (IR-59's measurement) and\r\n  five FIELD-SEAL lanes cost 148.48 GB (IR-31 fifth addendum), so ONE milestone's pools exceed\r\n  the entire free margin. Reaping buys windows, not headroom: deployah measured free fall\r\n  167 → 108 GB within hours of his reap, ~59 GB re-consumed by lane builds. The recurring shape:\r\n  every milestone pays a reap-and-measure tax to rent space the box does not structurally have.\r\n- **Why register-worthy rather than \"clean up more\":** agent-side discipline (IR-31's budgeting,\r\n  pool reaps, teardown steps) is already adopted and still only rents windows — the reservoir\r\n  that would durably move the floor is operator-owned bulk no agent may touch. Naming it here is\r\n  the boundary: agents keep budgeting IN POOLS (not GB); moving Steam/Downloads (or adding a\r\n  disk, or pinning golden to a box without operator payload) is an OPERATOR decision this entry\r\n  exists to put in front of them once, with numbers, instead of re-deriving the floor each cut.\r\n- **Ripe when:** operator rules on the bulk (move/expand/accept-the-tax), OR the first golden\r\n  that dies at the 32 GB preflight despite adopted pool discipline (IR-59's LNK1180-class red).\r\n- **Size:** zero code; one operator decision + at most a runbook line naming the chosen floor.\r\n\r\n### IR-65 — kitsubito kernel-audit backpressure: a tailscale-snap AppArmor denial storm + no auditd turned the default audit backlog into a CI-wide stall amplifier (REMEDIATED AT BOX; re-check triggers named)\r\n\r\n- **Status:** REMEDIATED-AT-BOX 2026-08-25 (doyle, operator-authorized root — ruling pinned\r\n  releases#225 comment 5418800776); entry stays OPEN as the re-check record because the storm\r\n  SOURCE persists and two named events can silently revert the fix.\r\n- **Mechanism:** `snap.tailscale.tailscaled` (1.92.5) polls /proc and takes an AppArmor\r\n  ptrace-read DENIED per poll — a continuous kernel-audit record storm scaling with process\r\n  count (spawn-heavy serialized CI legs amplify their own storm). With NO auditd installed the\r\n  records rode printk (kauditd throttling) and the 8192 kernel backlog overran\r\n  (lost=1,537,743); the default `backlog_wait_time` 60000ms turns a full backlog into A 60s\r\n  SLEEP INSIDE ANY AUDITED SYSCALL — the broker dispatch stall that stretched IR-30's\r\n  Linux-face race window (see IR-30's Linux-face addendum; deaths clustered 59–63s ↔ this\r\n  knob's value).\r\n- **Remediation (verified at the EFFECTIVE layer, not the fragment):** auditd installed +\r\n  active (storm consumed, backlog drains to 0, lost flat), backlog_limit 32768,\r\n  backlog_wait_time 0 (full backlog may DROP, never STALL). ⚠ THE TRAP PAID FOR ONCE: the first\r\n  knob write (`50-backlog.rules`) silently LOST the augenrules merge — apt's own\r\n  `/etc/audit/rules.d/audit.rules` sorts LAST (digits before letters) and its `-b 8192` /\r\n  `--backlog_wait_time 60000` won; a whole proof run executed under the defaults while the\r\n  fragment grepped perfect. Values now live in the merge-WINNING file; verified `auditctl -s`.\r\n- **Re-check triggers (the reason this entry stays):** (1) tailscale snap update — the plug\r\n  landscape may change, the storm may stop or grow; (2) auditd package update/reinstall — may\r\n  rewrite `rules.d/audit.rules` and re-lose the merge; (3) box reimage. On any of these: one\r\n  `auditctl -s` (expect 32768/0) + one `journalctl -k | grep 'backlog limit'` (expect silence).\r\n- **Ripe when:** a re-check trigger fires. **Size:** two read-only commands per check.\r\n\r\n### IR-66 — first-chunk-needle test class: two latent members remain after the v0.63.0 fix (attach.rs:561, :672)\r\n\r\n- **Status:** BUILT — confirmed present at `17815c9c` (hertz 2026-09-06); leaves the register at the WEBSERVE close sweep. Hertz rider PR #161, landed ff at `d04b922d` (2026-08-27, IO-PARSER #22\r\n  intake rider). Both members got the later-needle treatment (TICK39 delayed past burst on both\r\n  OS arms; alt-screen entered before delayed ALT_VIEWPORT_MARKER). Gate: doyle — diff-scope\r\n  review; Windows isolated worktree 3× TICK39 PASS + clippy + treqs; Linux CLEAN worktree at the\r\n  PR sha on kitsubito 3× both cells PASS (independent of the builder's dirty-shared-tree proof,\r\n  disclosure on record). · **Origin:** doyle tree-wide census at `dbe3daad`\r\n  (releases#225 comment 5418844404 — the census that corrected my own resume.rs-scoped\r\n  overclaim), after the class's first member was RCA'd and fixed in v0.63.0's head.\r\n- **Mechanism (cite, not restate):** KNOWN-HAZARDS 6.9 same-session face, amended at\r\n  `dbe3daad` — `spawn_session_pid`'s Spawned-wait consumes-and-discards a first output chunk\r\n  that races the reply (~2ms window on a healthy Linux box; load-stretched under backpressure,\r\n  see IR-30 Linux-face + IR-65). A test whose needle exists ONLY in the child's first chunk\r\n  asserts winning a race the contract does not promise.\r\n- **The two members:** `crates/spt-daemon/tests/attach.rs:561` (TICK0..39 instant burst then\r\n  `cat`; needle TICK39 read directly after spawn — the whole burst can sit in the first\r\n  chunks) and `:672` `cross_node_cold_attach_to_alt_screen_gets_clean_repaint` (unix-only;\r\n  `printf '…ALT_VIEWPORT_MARKER'; cat` — needle in the first chunk). Failure shape differs from\r\n  the fixed member: both children idle on `cat`, so a lost prefix is a HANG killed by nextest's\r\n  backstop at exactly 240s (slow-timeout 60s × terminate-after 4) — not a natural-life death.\r\n  Verified NOT in the class: daemon_e2e.rs:209 (needle = echo of post-spawn input), attach.rs:995\r\n  + brain_swap.rs:170 (attach/replay reads, not spawn-waits).\r\n- **Fix shape (ruled at the v0.63.0 close):** hertz lane, NEXT intake — the same one-line\r\n  later-needle / robust-read treatment the resume seed got in `dbe3daad`; deliberately NOT\r\n  landed mid-r4. Both cells passed r4 (0.010–0.058s) — the members are latent, not failing.\r\n- **Ripe when:** next milestone intake (hertz test lane) or the first golden red at ~240s on an\r\n  attach cell — either way the mechanism and fix are pre-derived, triage should cite this entry\r\n  and skip the RCA. **Size:** two one-line test edits.\r\n\r\n### IR-67 — wave-battery gap: a `-p spt --bins` leg compiles bin targets as harnesses and runs ZERO integration/e2e tests, so batteries that lean on it carry silent no-coverage legs\r\n\r\n- **Status:** BUILT — remedy applied across the IO-PARSER #22 milestone (2026-08-27/28): every\r\n  wave battery named explicit `-p spt --test <suite>` e2e legs beside the `--bins` unit leg\r\n  (GW1..GW5 evidence), every builder evidence report carried a named real e2e per the dispatch\r\n  template, and the one filter mistake (a `--test` name not matching its file) REFUSED loudly\r\n  rather than silently skipping — the failure mode this entry exists to kill. Battery template =\r\n  the dispatch text now carried forward in gate craft.\r\n- **Was:** OPEN · **Origin:** doyle, banked at the SIGNET #218 gates 2026-08-25 (\"gate\r\n  battery gap learned\"), filed at this sweep per the standing rule.\r\n- **Mechanism:** `cargo test/nextest -p spt --bins` builds `[[bin]]` targets as TEST HARNESSES\r\n  (unit tests inside bins only) — `tests/` integration and e2e suites of the crate NEVER run,\r\n  and the leg's green output is indistinguishable from coverage. Kin of the two banked pool\r\n  faces (`--bins` never emits fixture exes; fresh-pool fixture reds) but this face is about the\r\n  BATTERY TEMPLATE: my SIGNET wave batteries carried a `-p spt --bins` leg believed to cover\r\n  the crate.\r\n- **Remedy:** at next intake, the wave-battery template gains an explicit `tests/` leg for the\r\n  spt crate (nextest `-p spt --test <suites>` or unfiltered `-p spt` where pool history\r\n  permits), and any battery doc that lists `--bins` as a coverage leg gets the one-line caveat.\r\n- **Ripe when:** next milestone intake (the battery template is touched at every intake).\r\n  **Size:** template lines only.\r\n\r\n### IR-68 — PSYCHE_INGEST_FAIL cause class unproven: git index.lock did NOT reproduce the ingest failure it was blamed for\r\n\r\n- **Status:** OPEN, investigation-shaped · **Origin:** todlando measurement at the W2 int-leg rig\r\n  (IO-PARSER #22, PR #163 at `769fb0a9`, 2026-08-27), reported measure-first; filed by doyle.\r\n- **The contradiction:** the six silent `PSYCHE_INGEST_FAIL:todlando` lines observed at the\r\n  drop-dir probe (2026-08-25) were attributed to shared-checkout git `index.lock` contention. The\r\n  W2 rig planted NON-EMPTY `index.lock` files in BOTH places git takes one (bare git-dir + every\r\n  `<git_dir>/worktrees/<name>/`, mirroring `branchstore::sweep_stale_index_locks`, plant count\r\n  asserted >= 2) — and the ingest COMMITTED ANYWAY (tier write `Written`; `route_slices`\r\n  propagates `commit_live(...)?`, so a blocked checkpoint would have failed it). Non-empty was\r\n  deliberate: KH 1.3 reaps only 0-byte locks, and `pulse_tick` runs no boot sweep. So on this\r\n  store an `index.lock` does not block the checkpoint, and the field incident's mechanism is\r\n  UNKNOWN, not merely unconfirmed. The rig's doc comment records the attempt; the shipped int leg\r\n  fails the ingest at the drop READ instead (upstream of the store).\r\n- **Strongest negative evidence, pinned to the executable rig:**\r\n  `crates/spt-daemon/tests/commune_io_events_int.rs:95-107` documents that the lock mechanism was\r\n  tried **first**, planted non-empty locks in both the bare git-dir and every linked-worktree\r\n  location, asserted that the population was non-empty, and still observed `Written`. Its own\r\n  sentence is the required scope boundary: “This leg does not claim to reproduce a mechanism it\r\n  measured as inert.” The working injection is instead drop-file → directory replacement, which\r\n  fails the upstream read deterministically and proves only the `COMMUNE_FAIL` event contract.\r\n- **NOT claimed:** that the field incident was misattributed to ingest failure generally — the\r\n  files did survive with failed-ingest log lines; what is unproven is the index.lock CAUSE.\r\n- **Ripe when:** next PSYCHE_INGEST_FAIL sighting in the field (capture the failing store state\r\n  before touching it), or a dedicated probe slot. W2's COMMUNE_FAIL event now pushes a NAMED\r\n  reason on every failure, so the next occurrence self-reports its cause — read that first.\r\n  **Size:** investigation; no product change until the mechanism is pinned.\r\n\r\n### IR-69 — inherited stderr tokens can tear between format fragments; 26 test consumers parse that surface as structured truth\r\n\r\n- **Status:** OPEN, product remedy complete and parked GREEN-AND-READY at `d0fdd58d` on\r\n  `feat/emit-single-write`, owned by **todlando**, awaiting golden-batch assembly; board request\r\n  releases#241 carries the product remedy and full lane evidence in comment 5461613480. This entry\r\n  is the exposure map and census discipline, not the implementation. · **Origin:** CONDUIT #236 r3\r\n  golden attempt 2,\r\n  2026-08-29: `endpoint_autostart_e2e` missed its contiguous\r\n  `ENDPOINT_AUTOSTART:gwauto` keystone although the matching fresh session id proved the replay\r\n  happened. Attempt 3 was clean on the same discarded SHA after 139 GB was reaped; unequal load\r\n  makes the pair corroborating, never a rate.\r\n- **Mechanism, recovered from the literal torn bytes:** two daemon processes inherited one stderr\r\n  pipe. `BRAIN_UP` and `ENDPOINT_AUTOSTART` are each one `eprintln!`, but `write_fmt` may reach the\r\n  handle once per format fragment; the per-process stderr lock cannot serialize the other process.\r\n  The observed interleave split the autostart token between `ENDPOINT_AUTOSTART:` and `gwauto`.\r\n  This is fragment-level cross-process interleaving, not a failed replay and not a two-thread race.\r\n- **Durable remedy, ruled product-side:** render a complete diagnostic line into one buffer and\r","truncated":true,"truncatedBy":"lines","totalLines":2654,"totalBytes":43839,"outputLines":496,"outputBytes":43839,"lastLinePartial":false,"firstLineExceedsLimit":false},"totalLines":5781,"displayContent":{"text":"### IR-57 — an assembly pick's conflict resolution can silently DROP lines, and every gate run at assembly time is blind to it\n…\n- **Status:** OPEN, owned by **doyle** (gater craft, not a code defect — no lane to dispatch).\n…\n- **Every instrument in the assembly path reported success:** `git cherry-pick` completed with no\n…\n  correct hunks, this one is a fidelity LOSS during resolution.\r\n- **Two must-dos, both cheap:**\r\n  1. **Compile the assembled head before it is handed anywhere — including forward to your own next\r\n     session.** A head is not ready on a treqs exit; it is ready on a build. Any sentence carrying a\r\n     head sha to another agent must name the instrument that proved it.\r\n  2. **Audit pick fidelity on CHANGED LINES for every pick on the chain**, not just the one that\r\n     tripped you: hash `git show --format= <sha> | grep -E '^[+-]' | grep -vE '^(\\+\\+\\+|---)'` for\r\n     the lane source and for the pick, and compare. Whole-diff comparison is useless here — hunk\r\n     headers and context legitimately drift once the head's copy of the file has moved.\r\n- **Read COUNT and HASH together, because they fail in opposite directions.** Of 24 picks on this\r\n  chain two did not match. `b2194aa9 → 4d6deed1` differed in COUNT (302 lane / 300 pick by the header-excluding pipeline above; **this entry originally cited 310/308, which is the RAW `^[+-]` count INCLUDING the 8 `+++`/`---` header lines of its 4 files** — the figures were taken without the second grep the entry itself prescribes. The DELTA is 2 under either meter, which is why the wrong figures never surfaced: they supported a correct conclusion, so nothing pressed them. Corrected todlando 2026-08-29, measured both ways in-tree) — the real\r\n  defect. `f27f15c6 → 5865cc98` had the SAME count and a different HASH — benign: a `CONTEXT.md`\r\n  paragraph the head had already amended for #209, whose merged result correctly carries both lanes'\r\n  sentences. A count check MISSES the first class entirely; a hash check FLAGS the second as if it\r\n  were a defect. Neither alone classifies a pick.\r\n- **Repair shape used, recorded because it is the cheap one:** reset to the commit before the bad\r\n  pick, re-pick the lane source, resolve the same conflict correctly, then replay the remaining picks\r\n  in chain order with the fidelity check on each. Verify the repair changed nothing else with a\r\n  WHOLE-TREE diff against the old head — it must show exactly the restored lines and no other file.\r\n  Where a later pick re-conflicts, check its pre-pick blobs against the old chain\r\n  (`git rev-parse <old-pick>~1:<file>`); if they match, the old chain's post-pick blob is a\r\n  transferable, already-reviewed resolution.\r\n- **AND GATE THE REPAIR'S OWN SUBJECT.** The rebuilt head passed six legs — clippy `-D warnings`,\r\n  sweep 660/660, treqs 803/803, xtask OK — while the restored lines live in `spt-store`, whose LIB\r\n  tests `-p spt --bins` never runs. Six greens, and not one executed the function the repair\r\n  restored; it was proven to COMPILE and assumed to PASS. Proven afterwards by name (4/4) and by the\r\n  full `spt-store --lib` suite (519/519). **A repair's gate must include the suite that owns the\r\n  repaired file**, which is not necessarily the suite the head gate runs.\r\n- **FIRST LIVE CATCH, and it was the author's own resolution (2026-08-29, one hour after the verb landed):** rebasing the IR-59 rider over the IR-57 rider produced four conflicts — three additive keep-both, one usage line both sides had edited. `xtask pick-audit` read the rebase as **LOSS, 282 lane / 280 pick**. The two missing lines were a `[[requirements]]` header and its blank line in `traceable-reqs.toml`, so `id = REQ-DISK-FLOOR-PREFLIGHT` landed INSIDE the previous table as a duplicate key: **`traceable-reqs check` exit 2, the registry unparseable, every reading after that edit checking nothing**. Restored, the same audit reads **DRIFT 282/282** whose one differing line is the usage string whose base copy legitimately gained the other verb — both verdi…\n- **FIRST REAL-ASSEMBLY USE (2026-08-29, #241 emission head, ASM-241-GATE-VERDICT.md):** `xtask\r\n  pick-audit --range 57a0d27c..HEAD --lane 4d6007ac..d0fdd58d` over 6 picks — **5 MATCH\r\n  (digest-identical), 1 LOSS, 0 drift, 0 unclassified**, exit 1 forcing the accounting. The LOSS\r\n  was exactly the one human-resolved conflict (`cfb9d9f8 <- 10f12e4c`, count 432/402), and the\r\n  delta RECONCILED to the resolution rather than assumed: lane stat 15 files/235+/197- vs pick\r\n  14 files/205+/197-, difference byte-for-byte the deliberately-dropped 30-line interim IR-69\r\n  register block superseded by main's consolidated entry. No false positives, no silent pass.\r\n  Entry stays OPEN as living procedure; both live uses (the rebase catch above, this assembly)\r\n  produced the verdict classes in the order the entry predicts.\r\n- **Trigger condition:** ripe at the next assembly — this is procedure, and its cost is one command\r\n  per pick.\r\n- **Size guess:** small as a scripted check in `xtask` (fidelity audit over a pick range); zero as\r\n  discipline, which is how it is being applied now.\r\n\r\n### IR-58 — a `[[bin]]` grep is not a census: cargo AUTODISCOVERS `src/bin/*.rs` targets, and a hand-built bin list produced a confident false \"this bin does not exist\"\r\n\r\n- **Status:** OPEN, unowned. Filed by doyle 2026-08-22; **its original filing was WRONG and is\r\n  retracted in full below.** The entry is kept because the way it was wrong is the finding.\r\n- **RETRACTED CLAIM, stated plainly so no reader acts on it:** this entry first said that\r\n  `crates/spt/Cargo.toml:18-21` and `crates/spt/src/cli.rs:30355` forbid a bin-name collision with\r\n  `xlate_choreo_fixture`, \"a bin that does not exist\", and that spt-daemon's third helper had been\r\n  renamed to `summarizer_fixture`. **`xlate_choreo_fixture` EXISTS** — at\r\n  `crates/spt-daemon/src/bin/xlate_choreo_fixture.rs`, verified at the assembly head. The collision\r\n  rule's counterpart is real, both prose sites are CORRECT, and IR-21's original table row was\r\n  correct too; it merely predated `summarizer_fixture`. Nothing in that prose needs fixing.\r\n- **How the false claim was produced, which is the entry:** the census was built by grepping\r\n  `^\\[\\[bin\\]\\]` across `Cargo.toml`s. **Cargo AUTODISCOVERS `src/bin/*.rs` as bin targets with no\r\n  stanza at all**, so a stanza grep cannot see them, and it fails SILENTLY — it returns a clean,\r\n  well-formed list that is simply short. From that list it read as established fact that a named bin\r\n  had been renamed away, and that \"fact\" was then written into a register table, an IR entry, and a\r\n  message to the builder. **A pattern-built population encodes the pattern's assumption; the count\r\n  looks like a census and is a property of the pattern.**\r\n  (Found by todlando, resolving one of doyle's figures against his own tree under the pointer rule.)\r\n- **A CENSUS IS ALSO A PROPERTY OF A TREE.** Stanza counts differed legitimately across trees the\r\n  same hour — 13 at the assembly head, 11 at `dc1c7532` — because `summarizer_fixture` exists at one\r\n  and not the other. Two correct censuses of the same workspace disagree unless each names its sha.\r\n- **The must-do, and it removes the list rather than lengthening it:** never hand-maintain a bin\r\n  roster. Run `cargo build --workspace --bins` and let cargo enumerate its own targets — the same\r\n  enumeration the test harness resolves against, so it cannot drift from what a fixture lookup\r\n  expects. Stanza-derived lists, remembered pairs, and register tables are all the roster problem at\r\n  different depths; only cargo's own enumeration is the population.\r\n- **Kin:** IR-55's amended prebuild bullet (prebuild the census, not a remembered pair) and IR-42\r\n  (a verb that writes without adjudicating). The shared shape is an instrument returning an orderly\r\n  answer about a set it never fully saw.\r\n- **Trigger condition:** ripe on any `xtask` check work — a duplicate-bin-name check over cargo's\r\n  target enumeration (NOT over manifest stanzas) is a handful of lines and cannot go stale.\r\n- **Size guess:** small. The prose fix originally proposed here is WITHDRAWN — there was nothing\r\n  wrong with the prose.\r\n\r\n### IR-59 — pool arithmetic: this box holds TWO cold pools, not four; and a build that exhausts the volume reds as a LINKER defect that names no disk\r\n\r\n- **Status:** OPEN, unowned — it is arithmetic and discipline, not a code lane. Filed by doyle\r\n  2026-08-22 from a live disk-floor abort during the TURNKEY #212 W4 gate; footprint figures measured\r\n  by todlando the same hour.\r\n- **SECOND FACE, measured 2026-08-23/24 (WAX-SEAL #21 W2 gate, doyle — the violator this time):**\r\n  both predicted mechanisms fired at once, WITHOUT the floor guard because the gate legs ran as a\r\n  plain script. (1) doyle minted a THIRD cold pool (gate rig) while todlando's lane pool was LIVE —\r\n  the two-pool arithmetic, violated by the gater. (2) The lane pool had silently accumulated\r\n  **104.8 GB** over repeated full-workspace sweeps (nothing bounds or even measures a pool's\r\n  accumulation until the volume dies). The volume hit **3 MB free**; the reds wore exactly the\r\n  entry's predicted costume — `LNK1318: Unexpected PDB error; LIMIT (12)` naming no disk — plus a\r\n  second face worth keeping: `traceable-reqs check` died as a PANIC printing to stdout\r\n  (`os error 112`), so a REGISTRY gate red can also be the disk's. Both gate verdicts VOIDED\r\n  (clippy's full compile had exited 0 before space died — the code was never the question).\r\n  Recovery measured: gate pool reap 9.6 GB, lane pool clean 100.2 GB, drive back to 109.6 GB free.\r\n  **Remedies adopted at the incident:** the gate never mints its own pool while a builder lane is\r\n  live on the box — it takes the lane pool over SEQUENTIALLY at pool-release (warm, loud, the\r\n  releases#103 pattern); and gate/lane scripts get the disk-floor preflight the golden runner\r\n  already carries (this entry's part 2, still unbuilt).\r\n- **THIRD FACE, measured 2026-08-24 (WAX-SEAL #21 golden window, doyle):** two new mechanisms, both\r\n  about the REMEDY rather than the red. (1) The wax-seal-w1 lane pool **re-accumulated to 152–169 GB\r\n  (two meters, IR-46 caveat) within ONE DAY of the 08-23 clean** and rode the volume back down to\r\n  4.92 GB free — a reap is an instant, not a state; nothing yet bounds a pool between reaps.\r\n  (2) **The remedy itself arrived garbled through relay:** the golden push was held \"waiting on the\r\n  IR-59 reboot\" when this entry prescribes no reboot anywhere — tens of releases have shipped without\r\n  one; the operator refused the premise and the register's own recorded remedy (reap finished-lane\r\n  pools) cleared it in ten minutes. A remedy relayed as a DIFFERENT remedy is the relay trap wearing\r\n  infra clothes: the entry is the author — read it before adopting a hold. Recovery measured: five\r\n  finished-lane pools reaped after ancestry classification (`git cherry` catches rebased lands that\r\n  a plain `merge-base --is-ancestor` calls unlanded — gate-w4l1's 90.9 GB pool was reapable only by\r\n  that meter), 4.92 → 260.88 GB free (~256 GB free-delta vs ~270–287 GB sum-of-lengths). Two main\r\n  runs red inside the low-disk window (09:17Z/09:41Z) were re-run, not re-read, per this entry's\r\n  must-do.\r\n- **FOURTH FACE, measured 2026-08-24 same day (SIGNET #218 W2 gate, doyle — the gater's own pool\r\n  this time):** the MAIN pool went **13.7 GB → 158.3 GB in ONE DAY** absorbing four full gate\r\n  batteries across two lane tips, and dragged the volume to **18 GB free mid-gate** — so the\r\n  entry's mechanism is not a lane-pool problem, it is EVERY pool under repeated full sweeps, the\r\n  gate rig included. Two riders worth the ink: (1) the golden runner's **free-space floor step\r\n  produced its first live catch** — a thin CI leg refused at 14:14 local over exactly this window\r\n  with zero test signal, and the register's re-run-not-re-read rule resolved it in one command;\r\n  (2) the reap-and-rebuild trade (\"cleaning a live pool buys one window at rebuild price\") was\r\n  taken deliberately mid-gate and cost ~35 minutes cold — cheaper than one uninterpretable red.\r\n  A red measured at 18 GB free in this gate got NO read at all, and the next sweep's red was a\r\n  DIFFERENT test: low disk manufactures random victims before it manufactures link errors.\r\n- **The event:** a gate's preflight refused with `GATE_ABORTED_DISK_FLOOR` at **4.75 GB free on a\r\n  1863 GB volume**. Four cold pools plus the milestone head's pool were standing at once. The floor\r\n  guard did its job — without it a full workspace build would have started with under 5 GB of\r\n  headroom and produced a red belonging to nothing.\r\n- **THE ARITHMETIC, and it corrects the intuition that worktrees are the cost.** Measured across the\r\n  whole `.worktrees` tree: **45 worktrees = 0.79 GB total** (~18 MB each). **3 pools = 130.45 GB.**\r\n  Worktrees are **0.6%** of the footprint; pools are **99.4%**. **One cold pool is worth roughly 2,500\r\n  worktrees.** A rule keyed on worktree count would cost a day of `git worktree remove` work for under\r\n  a gigabyte, risk removing a lane someone still wants, and leave the lever untouched.\r\n- **THE CEILING, as arithmetic rather than hygiene:** at **45–75 GB per cold pool** on this workspace\r\n  against a **40 GB floor**, this box supports **TWO live pools comfortably, THREE only if one is\r\n  small**. The two rules that already exist need no replacement, only this number attached:\r\n  - **Reap a pool when its lane is finished** → 45–75 GB back immediately.\r\n  - **Do not run two builds at once** → not only the contention argument, but **75–150 GB of\r\n    simultaneous allocation** against that floor.\r\n- **A FULL VOLUME REDS AS A LINKER DEFECT.** `LINK: fatal error LNK1318: Unexpected PDB error`\r\n  (variously `OK (0)` or `LIMIT (12)`), often beside `LNK4209: debugging information corrupt`. It\r\n  reads as a corrupt artifact or a broken toolchain and is neither — it is the linker unable to grow\r\n  a large `.pdb`. **Nothing in the failure text says \"disk\".** Do not key recognition on the\r\n  parenthesised code; it varies.\r\n- **THE DANGER WINDOW IS THE TAIL OF A COLD BUILD, not a steady state you can check once.** The\r\n  2026-08-22 instance died at the link of `spt` — the last and largest artifact of a **74 GB** cold\r\n  pool — while that same build was draining the volume out from under itself. A free-space reading\r\n  taken before the build would have looked fine.\r\n- **Positive tell, with its own refutation attached:** `traceable-reqs check` alone surviving a leg\r\n  table is suggestive, because it is the only leg that never links. It is a POSITIVE tell ONLY — a\r\n  full disk can red before any link step, so the signature's ABSENCE clears nothing.\r\n- **THE FALSIFIER IS FREE SPACE AT THE TIME OF THE RUN**, not the shape of the leg table.\r\n- **Must-do, both cheap:**\r\n  1. **A free-space reading goes in the FIRST LINE of any build-failure report** — not in the\r\n     controls, not as a follow-up. Two agents spent hours on a mechanism for this failure and neither\r\n     ran `df`; the falsifier was one command away throughout.\r\n  2. **Rig and gate logs should record free space at run start.** Today they do not, which makes \"was\r\n     the disk full\" **unanswerable after the fact for every red already in hand**. Any red produced\r\n     under ~1 GB free is UNINTERPRETABLE and must be **re-run, not re-read**.\r\n- **Measurement caveat, observed twice in one hour:** sum-of-file-lengths and free-space delta\r\n  disagree by several percent when anything else on the box is writing (98.07 GB of subtrees → 92.25\r\n  GB reclaimed; 47.28 GB → 40.81 GB). Report BOTH, derive neither from the other, and treat any single\r\n  free-space number as an instant rather than headroom — see IR-46.\r\n- **FIFTH FACE, measured 2026-08-29 at the CONDUIT #236/v0.65.0 cut (deployah):**\r\n  the finished milestone's sequential lane-sharing accumulated **140.51 GB**, while a freshly\r\n  rebuilt pool measured **7.78 GB** — about **18× one build's working set** retained across lane\r\n  hand-offs with no reap between them. This is the budgetable rate behind that cut's disk-floor\r\n  red: sequential execution prevents concurrent ownership corruption, but it does not bound\r\n  historical artifacts inside the shared pool. Treat takeover and reclamation as separate\r\n  operations; a pool may be safe to reuse and still be too large to keep.\r\n- **SEVENTH FACE, measured 2026-08-30 (v0.67.0 milestone close — the PARALLEL-LANE fill\r\n  rate):** the #23 wave arc drove C: from ~240 GB free to **0.01 GB in ~3.5 hours**: four\r\n  concurrent/serial lane+gate pools totalled **236.6 GB** (ns23-w1 87.7 + ns23-113 72.3 +\r\n  gate rig 57.3 + ns23-w3 19.1) — effectively the entire ir57 reclaim re-consumed inside one\r\n  milestone's build window. The head gate and two thin-CI runs redded with the entry's exact\r\n  costume (\"could not compile\" + treqs panic, zero disk words) at 0.01 GB and all re-earned\r\n  green after reclaim (+186.6 GB, finished-lane targets only, single-actor rule held under\r\n  racing consent). Budget rule this face adds: a MULTI-WAVE milestone on one box books\r\n  ~60-90 GB PER LANE-PLUS-GATE cycle, so the pool budget is per-wave, not per-milestone —\r\n  reap each wave's pool at its LAND, not at the milestone party (the party inherited only\r\n  ~58 GB because the emergency had already forced the other ~179).\r\n- **SIXTH FACE, measured 2026-08-30 (#242 golden r4, Windows test job, LNK1318 at the PDB\r\n  write):** the floor is asserted ONCE at job START, but the job's internal LOW-WATER sits at its\r\n  LAST heavy step — the docs-drift build, ~28 minutes in. r4's floor read 65.1 GiB honest at\r\n  23:07; the box was at ~37–39 GB by the 23:35 link failure. LNK1318 on PDB write = this entry's\r\n  documented low-disk costume; the incremental-corruption candidate was retired by preservation\r\n  snapshot (no xtask state existed at failure). **Durable fix = a floor RE-READ (or reclaim)\r\n  immediately before the docs-drift build** — the WITHIN-job sibling of the across-job\r\n  read-after-checkout fix, rides the next workflow commit. Riders: incremental hygiene as\r\n  disk-pressure maintenance (the dir measured 4.56 GB), and the box's **~51 GB non-recovering\r\n  post-run consumption** is this entry's pool-weight face — classify at the IR-14/26/27/49 audit\r\n  slot (composed this sweep).\r\n- **Composed for next intake (doyle, v0.65.0 close):** the still-open log-the-floor build half\r\n  rides with [[IR-57]]'s scripted pick-fidelity audit as the next milestone's two tooling riders.\r\n- **Trigger condition:** ripe now for the log-the-floor half (it rides any gate-script or CI touch);\r\n  the arithmetic is discipline and applies immediately.\r\n- **Size guess:** small — one line in each rig/gate preflight to record free space alongside the\r\n  existing floor check.\r\n\r\n### IR-60 — a wrapper that CAPTURES a leg's exit status ends with the capture, so the wrapper's own status is the capture's, not the leg's\r\n\r\n- **Status:** OPEN, unowned — script-shape discipline, not a code lane. Filed by doyle 2026-08-22\r\n  during the TURNKEY #212 W5 lane; mechanism measured by todlando, who reported it first as a\r\n  possible harness misreport and then RETRACTED that reading himself on a minimal probe.\r\n- **The reading that started it:** a background leg was summarised as `exit code 0` while the leg's\r\n  own exit file read `100`. Reported as-is, that is a task runner lying about a red — the worst\r\n  possible direction for a purposeful-red claim, since it would turn two reds that DID fire into two\r\n  reds reported as not having fired.\r\n- **The measurement, minimal and on this box:**\r\n\r\n      ( exit 100 ); echo $? > probe.exit; FINAL=$?\r\n      leg status captured to file : 100\r\n      wrapper's own final status  : 0\r\n\r\n  The wrapper's shape is `( cd <lane> && cargo nextest ... > leg.raw 2>&1 ); echo $? > leg.exit`.\r\n  **The last command is the `echo`, which succeeds**, so the wrapper genuinely exits 0 while the leg\r\n  genuinely exited 100. THE RUNNER TOLD THE TRUTH ABOUT THE WRAPPER. There is nothing to file against\r\n  the task runner, and it would have been filed.\r\n- **The class, and this is why it is worth an entry rather than a fix:** it is the truncation-pipe\r\n  family — the meter measured something real, it just was not the thing about to be quoted. **Three\r\n  shapes now share ONE trigger, and the trigger is not \"is this a pipe\":**\r\n  1. a truncation pipe (`cmd | tail`, `cmd | head`) — `$?` measures the truncator, and `head` closing\r\n     the pipe can MANUFACTURE a status (SIGPIPE → 101), so `PIPESTATUS` is not protection either;\r\n  2. a flattened `$?` read after any intervening command;\r\n  3. **a wrapper whose last command is the capture itself.**\r\n  **The trigger in all three is the REPORTING** — every instance happened while trimming or capturing\r\n  output in order to QUOTE it as evidence.\r\n- **The practice that held, and the one to keep:** the leg's own file is the leg's verdict. Both reds\r\n  were real, and the only reason that was knowable is that every leg wrote its exit to its own file\r\n  rather than to the wrapper's status.\r\n- **Remedy, in preference order:** (1) never read a wrapper's status as a leg's — read the leg's exit\r\n  FILE, which the per-leg rule already requires; (2) if a wrapper's own status must be meaningful,\r\n  end it by re-raising the captured status (`exit \"$(cat leg.exit)\"`) or set the status before the\r\n  capture is the last word; (3) for anything that becomes evidence, redirect to a file and read the\r\n  file.\r\n- **Trigger condition:** ripe now — it rides the next gate-script touch, and the gate scripts in this\r\n  milestone already write per-leg exit files, which is what makes this discipline rather than debt.\r\n- **Size guess:** small — a convention line in the gate-script preamble; no product code.\r\n\r\n### IR-61 — spacerun's test-module skip carries a SECOND literal tracker; the two answers can drift, and today only a cell stands between them\r\n\r\n- **Status:** OPEN, unowned, accepted-with-mitigation. Filed by doyle 2026-08-22 at the TURNKEY #212\r\n  head gate, as the named residual of the latch repair (the repair itself rides the milestone).\r\n- **What the debt is.** `crates/xtask/src/spacerun.rs` now skips a column-0 `#[cfg(test)]` module by\r\n  BRACE DEPTH and resumes after its close, rather than latching the scan to end-of-file. Counting\r\n  braces safely means knowing when a brace is inside a string, a raw string or a char literal — and\r\n  the scanner ALREADY tracks literals for its rendering pass. It does not reuse that tracking. There\r\n  are now TWO answers in one file to \"am I inside a literal\", and **two answers to one question is a\r\n  disagreement waiting for a reader who fixes one of them.**\r\n- **Why it was accepted rather than refactored on the spot, stated so the trade is auditable:** the\r\n  two trackers answer genuinely different questions — the rendering walk is PER LINE and forward\r\n  from an opening quote (\"where does this literal start and end\"), while the skip needs \"am I inside\r\n  a literal right now\" carried CONTINUOUSLY across lines. Unifying them is a real refactor of a check\r\n  that is already gated, already carries five fixed defects, and sits on the tree being handed to\r\n  golden. The narrow change with an OBSERVABLE failure mode beat the correct-shaped change with a\r\n  wide blast radius, on that tree, on that day.\r\n- **The mitigation, and its exact limit.** Three brace cells fail the moment the two trackers\r\n  disagree about a raw string, a normal string or a char literal, plus a cell that reds when the skip\r\n  stops consulting a literal tracker at all (`match lit` -> `match Lit::None`). **That is a cell\r\n  standing in for a refactor.** It catches drift in the three forms it names and nothing else — a\r\n  fourth literal form, or a change to only one tracker in a form neither cell covers, passes.\r\n- **The general shape, which is why this is a register entry rather than a comment:** a check whose\r\n  own correctness depends on a second implementation of a thing it already implements is one\r\n  refactor away from the defect class it exists to prevent. This same file has already produced\r\n  three instrument defects (an indented-marker latch, a column-0 latch, and a suppression that\r\n  decided what got PARSED rather than what got REPORTED). The pattern is not carelessness; it is a\r\n  scanner accumulating special cases.\r\n- **Trigger condition:** the next SUBSTANTIVE change to spacerun's scanning — any new skip, any new\r\n  literal form, any change to either tracker. At that point unify, rather than adding a third answer.\r\n- **Size guess:** small to medium — one continuous literal-state walk serving both the render pass\r\n  and the skip, with the existing corpus and brace cells as the regression net.\r\n\r\n### IR-62 — an e2e daemon binds well-known ports and collides with the resident fleet on shared runners\r\n\r\nFiled 2026-08-23 (doyle), from the #212 r2 golden's Windows Phase A red — one witnessed\r\ninstance, mechanism verified from the run's own capture, filed on the mechanism per the\r\nregister's standard.\r\n\r\n**Mechanism.** `endpoint_autostart_e2e::saved_endpoint_replays_on_daemon_restart` failed its\r\nown PRECONDITION (\"daemon B must come up with a fresh brain\") because daemon B's broker came up\r\ndegraded: `NODE_KEY_FAIL: identity unavailable` (net-less broker, no retry) and\r\n`DOCS_SERVER_BIND_FAIL` port 5474 `os error 10048` — the docs port was held by a CO-RESIDENT\r\ndaemon. HFENDULEAM is live infra: the resident fleet's daemon legitimately holds well-known\r\nports, and any e2e that brings up a daemon with default port bindings is in a race with it BY\r\nCONSTRUCTION. An isolated SPT_HOME isolates the store and broker socket, NOT globally-numbered\r\nTCP ports.\r\n\r\n**Classification history.** r2: red (35.4s, precondition panic). Run 1 and r3 on the same box:\r\ngreen. Folded into r3 under a pre-registered predicate (reds twice → dedicated triage); it\r\ngreened, so this stays an environment-shaped intermittent, NOT a product defect and NOT\r\nclosed — the collision window is real and will re-fire under the right co-residence timing.\r\n\r\n**Remedy direction (not built).** Test daemons should bind ephemeral/rig-scoped ports for\r\nevery advisory surface (the docs server is advisory — a bind failure should degrade the rig\r\nloudly, not poison an unrelated cell's precondition), or the precondition should name the\r\nport-collision cause distinctly so the red self-classifies. Either lane is test/CI work\r\n(hertz's), triggered the next time this class fires anywhere.\r\n\r\n**Kin.** IR-51 (e2e daemon net-enabled on real interfaces — hermeticity is disk-deep only);\r\nthe known not-ours red classes list in the #212 hand-off.\r\n\r\n**BUILT 2026-08-24 (hertz, SIGNET #218 batch; PR #158).** The class fired its second witnessed\r\ninstance the same day — doyle's W2 gate rig, `engine_room_bringup_e2e` precondition panic with\r\nthe IR-50 panel naming `DOCS_SERVER_BIND_FAIL` port 5474 `os error 10048` — which armed this\r\nentry's own trigger. Hertz repro'd deterministically (held the port; brain still reached\r\nBRAIN_UP), pre-ranked three mechanisms before probing, and built the ephemeral-advisory form:\r\nrig-only `SPT_TEST_EPHEMERAL_ADVISORY_PORTS=1` makes the daemon's docs listener bind port 0\r\n(production config/`SPT_DOCS_PORT`/docs-url untouched; the flag matches the literal \"1\" only).\r\nThe golden workflow's test job sets it globally on both self-hosted legs, the standalone ER rig\r\nsets it too. Scope note kept honest per his own ranking: the docs collision is retired; if a\r\nco-diagnostic bind elsewhere still poisons a precondition, that is a residual face of THIS\r\nentry, not a closed question.\r\n\r\n### IR-63 — suite-mix sweeps leak job-escaped autostart daemons that LOCK the pool's spt.exe; and the same box conditions manufacture one random victim per sweep\r\n\r\n- **Status:** OPEN, mitigated-by-rig-step — the reap is adopted discipline, not yet construction.\r\n  Filed by doyle 2026-08-24 at the SIGNET #218 gates; first measured by todlando the same day\r\n  (his W1 build: four reap rounds of 2, 8, 1, 1 processes, count-by-path stated each round).\r\n- **Mechanism, two faces of one condition:** (1) e2e sweeps that exercise autostart leave\r\n  job-escaped daemons running `target/debug/spt.exe`; the NEXT build or `xtask check` then dies\r\n  on `os error 5` removing the exe — a rig red wearing a build defect's clothes. nextest's own\r\n  `leaky` flags corroborate (4–8 per sweep measured). (2) The same co-residence (leaked daemons +\r\n  resident fleet + runner traffic) manufactures ONE red per full sweep with a DIFFERENT victim\r\n  each time: doyle's W2 gate measured FOUR distinct one-off victims in four same-sha sweeps\r\n  (ER bringup, composite+bootstrap pair under CI load, resident_service, brain_resume), every\r\n  one green alone and/or in a sibling sweep. The e2e-leaked-daemons rule holds: a different test\r\n  dying each run on one sha is ONE environment cause, and hardening members never closes it.\r\n- **Mitigation adopted (rig step, both todlando's lanes and doyle's gate runner):** reap\r\n  `spt.exe` BY PATH (`*spt-core\\target*`) before EVERY cargo invocation and after every sweep;\r\n  report the count each time so a zero is a claim, not silence.\r\n- **Remedy direction (unbuilt):** the durable form is construction, not discipline — either\r\n  nextest wrap/xtask verb that performs the by-path reap as a pre-step on this box's rigs, or\r\n  autostart e2es gain teardown that provably outlives job escape (kin IR-38's built wedge-namer,\r\n  IR-62's ephemeral ports which retire one collision axis, IR-35's victim-rate ledger).\r\n- **THIRD FACE, measured 2026-08-30 (doyle, ir57/asm-241 reaps):** the leaked population is not\r\n  only daemons — battery legs leave ORPHANED HEADLESS `conhost.exe` processes whose CWD sits in\r\n  the worktree's `crates/spt-daemon` (where the leg ran), and a CWD pin blocks `Remove-Item`/\r\n  `git worktree remove` on the whole tree with \"being used by another process\" naming the DIR.\r\n  This is the mechanism behind every recent \"handle-pinned, retry later\" worktree removal: 31\r\n  such conhosts found at once (Aug 26–29 vintages) pinning FIVE dead worktrees. cargo/rustc\r\n  absence does NOT clear the suspect list — the conhost outlives its client. Holder census\r\n  tool: a ~30-line NtQueryInformationProcess CWD probe (PEB→ProcessParameters→CurrentDirectory)\r\n  over all pids, filtered on the path — names every holder in one pass where no handle.exe\r\n  exists. 13 killed scoped to the two consented reaps; 18 remain pinning gate-w1-a8f04aff (12),\r\n  io-parser-w1 (5), gate-w1-786d2381 (1 after kills) — sweep them at the IR-14/26/27/49 audit\r\n  slot before those removals.\r\n- **LANE-LINKED 2026-08-30 (#242 close sweep):** hertz's queued daemon-leak fixup lane carries\r\n  this entry (brief cites IR-7/17/20/34/35/63); leaves the register when that lane lands.\r\n- **Trigger condition:** next rig/gate-script construction touch, or the first golden red that\r\n  classifies to face (1).\r\n- **Size guess:** small-medium — one wrapper seam plus adopting it in the gate/lane scripts.\r\n\r\n### IR-64 — HFENDULEAM's disk floor is set by non-CI bulk: ~845 GB of operator payload leaves the golden box ~2 GB of slack against its own 32 GB preflight\r\n\r\n- **Status:** OPEN · **Origin:** doyle, v0.63.0 close sweep 2026-08-26; mechanism first measured\r\n  at the FIELD-SEAL golden window (deployah's IR-31 fifth addendum carries the POOL side of the\r\n  same event by agreed division — this entry is the OTHER reservoir, deliberately not his).\r\n- **Mechanism:** the 1.86 TB C: carries ~614 GB Steam + ~230 GB Downloads (operator payload, not\r\n  CI state). With that floor fixed, normal lane traffic alone walks the box under the 32 GB\r\n  golden preflight — a full-sweep pool WEIGHS ~90–112 GB steady state (IR-59's measurement) and\r\n  five FIELD-SEAL lanes cost 148.48 GB (IR-31 fifth addendum), so ONE milestone's pools exceed\r\n  the entire free margin. Reaping buys windows, not headroom: deployah measured free fall\r\n  167 → 108 GB within hours of his reap, ~59 GB re-consumed by lane builds. The recurring shape:\r\n  every milestone pays a reap-and-measure tax to rent space the box does not structurally have.\r\n- **Why register-worthy rather than \"clean up more\":** agent-side discipline (IR-31's budgeting,\r\n  pool reaps, teardown steps) is already adopted and still only rents windows — the reservoir\r\n  that would durably move the floor is operator-owned bulk no agent may touch. Naming it here is\r\n  the boundary: agents keep budgeting IN POOLS (not GB); moving Steam/Downloads (or adding a\r\n  disk, or pinning golden to a box without operator payload) is an OPERATOR decision this entry\r\n  exists to put in front of them once, with numbers, instead of re-deriving the floor each cut.\r\n- **Ripe when:** operator rules on the bulk (move/expand/accept-the-tax), OR the first golden\r\n  that dies at the 32 GB preflight despite adopted pool discipline (IR-59's LNK1180-class red).\r\n- **Size:** zero code; one operator decision + at most a runbook line naming the chosen floor.\r\n\r\n### IR-65 — kitsubito kernel-audit backpressure: a tailscale-snap AppArmor denial storm + no auditd turned the default audit backlog into a CI-wide stall amplifier (REMEDIATED AT BOX; re-check triggers named)\r\n\r\n- **Status:** REMEDIATED-AT-BOX 2026-08-25 (doyle, operator-authorized root — ruling pinned\r\n  releases#225 comment 5418800776); entry stays OPEN as the re-check record because the storm\r\n  SOURCE persists and two named events can silently revert the fix.\r\n- **Mechanism:** `snap.tailscale.tailscaled` (1.92.5) polls /proc and takes an AppArmor\r\n  ptrace-read DENIED per poll — a continuous kernel-audit record storm scaling with process\r\n  count (spawn-heavy serialized CI legs amplify their own storm). With NO auditd installed the\r\n  records rode printk (kauditd throttling) and the 8192 kernel backlog overran\r\n  (lost=1,537,743); the default `backlog_wait_time` 60000ms turns a full backlog into A 60s\r\n  SLEEP INSIDE ANY AUDITED SYSCALL — the broker dispatch stall that stretched IR-30's\r\n  Linux-face race window (see IR-30's Linux-face addendum; deaths clustered 59–63s ↔ this\r\n  knob's value).\r\n- **Remediation (verified at the EFFECTIVE layer, not the fragment):** auditd installed +\r\n  active (storm consumed, backlog drains to 0, lost flat), backlog_limit 32768,\r\n  backlog_wait_time 0 (full backlog may DROP, never STALL). ⚠ THE TRAP PAID FOR ONCE: the first\r\n  knob write (`50-backlog.rules`) silently LOST the augenrules merge — apt's own\r\n  `/etc/audit/rules.d/audit.rules` sorts LAST (digits before letters) and its `-b 8192` /\r\n  `--backlog_wait_time 60000` won; a whole proof run executed under the defaults while the\r\n  fragment grepped perfect. Values now live in the merge-WINNING file; verified `auditctl -s`.\r\n- **Re-check triggers (the reason this entry stays):** (1) tailscale snap update — the plug\r\n  landscape may change, the storm may stop or grow; (2) auditd package update/reinstall — may\r\n  rewrite `rules.d/audit.rules` and re-lose the merge; (3) box reimage. On any of these: one\r\n  `auditctl -s` (expect 32768/0) + one `journalctl -k | grep 'backlog limit'` (expect silence).\r\n- **Ripe when:** a re-check trigger fires. **Size:** two read-only commands per check.\r\n\r\n### IR-66 — first-chunk-needle test class: two latent members remain after the v0.63.0 fix (attach.rs:561, :672)\r\n\r\n- **Status:** BUILT — confirmed present at `17815c9c` (hertz 2026-09-06); leaves the register at the WEBSERVE close sweep. Hertz rider PR #161, landed ff at `d04b922d` (2026-08-27, IO-PARSER #22\r\n  intake rider). Both members got the later-needle treatment (TICK39 delayed past burst on both\r\n  OS arms; alt-screen entered before delayed ALT_VIEWPORT_MARKER). Gate: doyle — diff-scope\r\n  review; Windows isolated worktree 3× TICK39 PASS + clippy + treqs; Linux CLEAN worktree at the\r\n  PR sha on kitsubito 3× both cells PASS (independent of the builder's dirty-shared-tree proof,\r\n  disclosure on record). · **Origin:** doyle tree-wide census at `dbe3daad`\r\n  (releases#225 comment 5418844404 — the census that corrected my own resume.rs-scoped\r\n  overclaim), after the class's first member was RCA'd and fixed in v0.63.0's head.\r\n- **Mechanism (cite, not restate):** KNOWN-HAZARDS 6.9 same-session face, amended at\r\n  `dbe3daad` — `spawn_session_pid`'s Spawned-wait consumes-and-discards a first output chunk\r\n  that races the reply (~2ms window on a healthy Linux box; load-stretched under backpressure,\r\n  see IR-30 Linux-face + IR-65). A test whose needle exists ONLY in the child's first chunk\r\n  asserts winning a race the contract does not promise.\r\n- **The two members:** `crates/spt-daemon/tests/attach.rs:561` (TICK0..39 instant burst then\r\n  `cat`; needle TICK39 read directly after spawn — the whole burst can sit in the first\r\n  chunks) and `:672` `cross_node_cold_attach_to_alt_screen_gets_clean_repaint` (unix-only;\r\n  `printf '…ALT_VIEWPORT_MARKER'; cat` — needle in the first chunk). Failure shape differs from\r\n  the fixed member: both children idle on `cat`, so a lost prefix is a HANG killed by nextest's\r\n  backstop at exactly 240s (slow-timeout 60s × terminate-after 4) — not a natural-life death.\r\n  Verified NOT in the class: daemon_e2e.rs:209 (needle = echo of post-spawn input), attach.rs:995\r\n  + brain_swap.rs:170 (attach/replay reads, not spawn-waits).\r\n- **Fix shape (ruled at the v0.63.0 close):** hertz lane, NEXT intake — the same one-line\r\n  later-needle / robust-read treatment the resume seed got in `dbe3daad`; deliberately NOT\r\n  landed mid-r4. Both cells passed r4 (0.010–0.058s) — the members are latent, not failing.\r\n- **Ripe when:** next milestone intake (hertz test lane) or the first golden red at ~240s on an\r\n  attach cell — either way the mechanism and fix are pre-derived, triage should cite this entry\r\n  and skip the RCA. **Size:** two one-line test edits.\r\n\r\n### IR-67 — wave-battery gap: a `-p spt --bins` leg compiles bin targets as harnesses and runs ZERO integration/e2e tests, so batteries that lean on it carry silent no-coverage legs\r\n\r\n- **Status:** BUILT — remedy applied across the IO-PARSER #22 milestone (2026-08-27/28): every\r\n  wave battery named explicit `-p spt --test <suite>` e2e legs beside the `--bins` unit leg\r\n  (GW1..GW5 evidence), every builder evidence report carried a named real e2e per the dispatch\r\n  template, and the one filter mistake (a `--test` name not matching its file) REFUSED loudly\r\n  rather than silently skipping — the failure mode this entry exists to kill. Battery template =\r\n  the dispatch text now carried forward in gate craft.\r\n- **Was:** OPEN · **Origin:** doyle, banked at the SIGNET #218 gates 2026-08-25 (\"gate\r\n  battery gap learned\"), filed at this sweep per the standing rule.\r\n- **Mechanism:** `cargo test/nextest -p spt --bins` builds `[[bin]]` targets as TEST HARNESSES\r\n  (unit tests inside bins only) — `tests/` integration and e2e suites of the crate NEVER run,\r\n  and the leg's green output is indistinguishable from coverage. Kin of the two banked pool\r\n  faces (`--bins` never emits fixture exes; fresh-pool fixture reds) but this face is about the\r\n  BATTERY TEMPLATE: my SIGNET wave batteries carried a `-p spt --bins` leg believed to cover\r\n  the crate.\r\n- **Remedy:** at next intake, the wave-battery template gains an explicit `tests/` leg for the\r\n  spt crate (nextest `-p spt --test <suites>` or unfiltered `-p spt` where pool history\r\n  permits), and any battery doc that lists `--bins` as a coverage leg gets the one-line caveat.\r\n- **Ripe when:** next milestone intake (the battery template is touched at every intake).\r\n  **Size:** template lines only.\r\n\r\n### IR-68 — PSYCHE_INGEST_FAIL cause class unproven: git index.lock did NOT reproduce the ingest failure it was blamed for\r\n\r\n- **Status:** OPEN, investigation-shaped · **Origin:** todlando measurement at the W2 int-leg rig\r\n  (IO-PARSER #22, PR #163 at `769fb0a9`, 2026-08-27), reported measure-first; filed by doyle.\r\n- **The contradiction:** the six silent `PSYCHE_INGEST_FAIL:todlando` lines observed at the\r\n  drop-dir probe (2026-08-25) were attributed to shared-checkout git `index.lock` contention. The\r\n  W2 rig planted NON-EMPTY `index.lock` files in BOTH places git takes one (bare git-dir + every\r\n  `<git_dir>/worktrees/<name>/`, mirroring `branchstore::sweep_stale_index_locks`, plant count\r\n  asserted >= 2) — and the ingest COMMITTED ANYWAY (tier write `Written`; `route_slices`\r\n  propagates `commit_live(...)?`, so a blocked checkpoint would have failed it). Non-empty was\r\n  deliberate: KH 1.3 reaps only 0-byte locks, and `pulse_tick` runs no boot sweep. So on this\r\n  store an `index.lock` does not block the checkpoint, and the field incident's mechanism is\r\n  UNKNOWN, not merely unconfirmed. The rig's doc comment records the attempt; the shipped int leg\r\n  fails the ingest at the drop READ instead (upstream of the store).\r\n- **Strongest negative evidence, pinned to the executable rig:**\r\n  `crates/spt-daemon/tests/commune_io_events_int.rs:95-107` documents that the lock mechanism was\r\n  tried **first**, planted non-empty locks in both the bare git-dir and every linked-worktree\r\n  location, asserted that the population was non-empty, and still observed `Written`. Its own\r\n  sentence is the required scope boundary: “This leg does not claim to reproduce a mechanism it\r\n  measured as inert.” The working injection is instead drop-file → directory replacement, which\r\n  fails the upstream read deterministically and proves only the `COMMUNE_FAIL` event contract.\r\n- **NOT claimed:** that the field incident was misattributed to ingest failure generally — the\r\n  files did survive with failed-ingest log lines; what is unproven is the index.lock CAUSE.\r\n- **Ripe when:** next PSYCHE_INGEST_FAIL sighting in the field (capture the failing store state\r\n  before touching it), or a dedicated probe slot. W2's COMMUNE_FAIL event now pushes a NAMED\r\n  reason on every failure, so the next occurrence self-reports its cause — read that first.\r\n  **Size:** investigation; no product change until the mechanism is pinned.\r\n\r\n### IR-69 — inherited stderr tokens can tear between format fragments; 26 test consumers parse that surface as structured truth\r\n\r\n- **Status:** OPEN, product remedy complete and parked GREEN-AND-READY at `d0fdd58d` on\r\n  `feat/emit-single-write`, owned by **todlando**, awaiting golden-batch assembly; board request\r\n  releases#241 carries the product remedy and full lane evidence in comment 5461613480. This entry\r\n  is the exposure map and census discipline, not the implementation. · **Origin:** CONDUIT #236 r3\r\n  golden attempt 2,\r\n  2026-08-29: `endpoint_autostart_e2e` missed its contiguous\r\n  `ENDPOINT_AUTOSTART:gwauto` keystone although the matching fresh session id proved the replay\r\n  happened. Attempt 3 was clean on the same discarded SHA after 139 GB was reaped; unequal load\r\n  makes the pair corroborating, never a rate.\r\n- **Mechanism, recovered from the literal torn bytes:** two daemon processes inherited one stderr\r\n  pipe. `BRAIN_UP` and `ENDPOINT_AUTOSTART` are each one `eprintln!`, but `write_fmt` may reach the\r\n  handle once per format fragment; the per-process stderr lock cannot serialize the other process.\r\n  The observed interleave split the autostart token between `ENDPOINT_AUTOSTART:` and `gwauto`.\r\n  This is fragment-level cross-process interleaving, not a failed replay and not a two-thread race.\r\n- **Durable remedy, ruled product-side:** render a complete diagnostic line into one buffer and\r\n…\n  sibling token remains exposed.\n…\n","startLine":3112,"lineNumbers":[3112,null,3114,null,3122,null,3128,3129,3130,3131,3132,3133,3134,3135,3136,3137,3138,3139,3140,3141,3142,3143,3144,3145,3146,3147,3148,3149,3150,3151,3152,3153,3154,3155,3156,3157,3158,3159,3160,3161,3162,3163,3164,3165,3166,3167,3168,3169,3170,3171,3172,3173,3174,3175,3176,3177,3178,3179,3180,3181,3182,3183,3184,3185,3186,3187,3188,3189,3190,3191,3192,3193,3194,3195,3196,3197,3198,3199,3200,3201,3202,3203,3204,3205,3206,3207,3208,3209,3210,3211,3212,3213,3214,3215,3216,3217,3218,3219,3220,3221,3222,3223,3224,3225,3226,3227,3228,3229,3230,3231,3232,3233,3234,3235,3236,3237,3238,3239,3240,3241,3242,3243,3244,3245,3246,3247,3248,3249,3250,3251,3252,3253,3254,3255,3256,3257,3258,3259,3260,3261,3262,3263,3264,3265,3266,3267,3268,3269,3270,3271,3272,3273,3274,3275,3276,3277,3278,3279,3280,3281,3282,3283,3284,3285,3286,3287,3288,3289,3290,3291,3292,3293,3294,3295,3296,3297,3298,3299,3300,3301,3302,3303,3304,3305,3306,3307,3308,3309,3310,3311,3312,3313,3314,3315,3316,3317,3318,3319,3320,3321,3322,3323,3324,3325,3326,3327,3328,3329,3330,3331,3332,3333,3334,3335,3336,3337,3338,3339,3340,3341,3342,3343,3344,3345,3346,3347,3348,3349,3350,3351,3352,3353,3354,3355,3356,3357,3358,3359,3360,3361,3362,3363,3364,3365,3366,3367,3368,3369,3370,3371,3372,3373,3374,3375,3376,3377,3378,3379,3380,3381,3382,3383,3384,3385,3386,3387,3388,3389,3390,3391,3392,3393,3394,3395,3396,3397,3398,3399,3400,3401,3402,3403,3404,3405,3406,3407,3408,3409,3410,3411,3412,3413,3414,3415,3416,3417,3418,3419,3420,3421,3422,3423,3424,3425,3426,3427,3428,3429,3430,3431,3432,3433,3434,3435,3436,3437,3438,3439,3440,3441,3442,3443,3444,3445,3446,3447,3448,3449,3450,3451,3452,3453,3454,3455,3456,3457,3458,3459,3460,3461,3462,3463,3464,3465,3466,3467,3468,3469,3470,3471,3472,3473,3474,3475,3476,3477,3478,3479,3480,3481,3482,3483,3484,3485,3486,3487,3488,3489,3490,3491,3492,3493,3494,3495,3496,3497,3498,3499,3500,3501,3502,3503,3504,3505,3506,3507,3508,3509,3510,3511,3512,3513,3514,3515,3516,3517,3518,3519,3520,3521,3522,3523,3524,3525,3526,3527,3528,3529,3530,3531,3532,3533,3534,3535,3536,3537,3538,3539,3540,3541,3542,3543,3544,3545,3546,3547,3548,3549,3550,3551,3552,3553,3554,3555,3556,3557,3558,3559,3560,3561,3562,3563,3564,3565,3566,3567,3568,3569,3570,3571,3572,3573,3574,3575,3576,3577,3578,3579,3580,3581,3582,3583,3584,3585,3586,3587,3588,3589,3590,3591,3592,3593,3594,3595,3596,3597,3598,3599,3600,3601,3602,3603,3604,3605,3606,3607,3608,3609,3610,3611,3612,3613,3614,3615,3616,3617,3618,3619,3620,3621,3622,3623,null,3629,null,3697]},"fileSize":501961,"meta":{"source":{"type":"path","value":"C:\\Users\\decid\\Documents\\projects\\spt-core\\docs\\INFRA-REGISTER.md"},"truncation":{"direction":"head","truncatedBy":"lines","totalLines":5781,"totalBytes":43839,"outputLines":496,"outputBytes":43839,"shownRange":{"start":3128,"end":3623},"nextOffset":3624},"limits":{"columnTruncated":{"maxColumn":768}}}},"isError":false,"timestamp":1789094604314}}
{"type":"message","id":"71ab5a00","parentId":"25042ecb","timestamp":"2026-09-11T02:43:24.324Z","message":{"role":"toolResult","toolCallId":"call_CAdkTQKgwNlSODdaTUJ509Xj|fc_065c0d1976ecf9c2016aa36ac9e4fc87d1a75c12cce479a55a","toolName":"read","content":[{"type":"text","text":"### IR-69 — inherited stderr tokens can tear between format fragments; 26 test consumers parse that surface as structured truth\n…\n- **Status:** OPEN, product remedy complete and parked GREEN-AND-READY at `d0fdd58d` on\n…\n- **Mechanism, recovered from the literal torn bytes:** two daemon processes inherited one stderr\n…\n  handle once per format fragment; the per-process stderr lock cannot serialize the other process.\n  The observed interleave split the autostart token between `ENDPOINT_AUTOSTART:` and `gwauto`.\n  This is fragment-level cross-process interleaving, not a failed replay and not a two-thread race.\n- **Durable remedy, ruled product-side:** render a complete diagnostic line into one buffer and\n  issue the complete rendered text, newline included, as **ONE handle call**. An OS short-write\n  may retry the late tail so completeness wins over a silently truncated line; the deterministic\n  property pins application-side fragmentation, not syscall count under that rare retry. It makes\n  no claim that the OS write is atomic on Windows, and no CI re-fire against a 1-of-2 observation\n  may stand in for it. Widening one test's grep is refused: it greens one consumer while every\n  sibling token remains exposed.\n- **Cut-SHA census** (todlando generator, independently hash-verified by hertz), measured from\n  `4d6007ac4ee3d0991f4bc60b7e1a55825aad1aaf` via `git show`, not a dirty worktree:\n  **486 real emitter sites / 383 distinct tokens / 26 consumer test files**. The generator emitted\n  487 site rows, but one is a known phantom: `sealverb.rs:456` is a `format!` inside `map_err`\n  that the four-line lookback attributed to a neighbouring real `eprintln!`. Corrected real emitters\n  by crate: spt-daemon 270, spt 194, spt-runtime 8, spt-live 5, spt-net 5, spt-store 4; by macro:\n  `eprintln!` 484, `println!` 1, `eprint!` 1. `DRIVEN_BY` is the sole stdout row and therefore\n  outside the stderr remedy. A consumer means the test both mentions `TOKEN:` and reads a\n  stderr/log surface; bare-token matching inflated the population to 72 files by admitting prose.\n  This is an **exposure map**, not a rate and not a claim that all 26 have torn.\n- **Artifacts (the preserved raw generator outputs contain 487 site rows):** cut census SHA-256:\n  sites `f10d6bfe5e0399f98945cf63bb5719a01a62e1251be84165c73030fa9bb224f5`,\n  tokens `80b0d1835d9d46376b2f200b1c50be4ca0e185a135168444414255f9308ed92b`,\n  consumers `249a2e33df43a30570ca82b5bd200d8b6e2bf07aa8250fcc8bace47fe23e3cbc`.\n  The sealed sites file's macro column is wrong on 7 of its 487 raw rows; the corrected raw split\n  is `eprintln!` 485 / `println!` 1 / `eprint!` 1. The sealed tokens file has no final newline, so\n  `wc -l` reports 382 although it contains 383 logical records. The sealed files remain unedited;\n  these corrections are textual.\n  Generator `81df82f01ef33a82307920d9804a2394b787ef2ffbe3b41d2d7dda560d9a62a9`\n  was recorded as asserting newline-terminated output, but the sealed tokens artifact refutes that\n  claim for at least one output. Its remaining guards cover logical record counts, a known-positive\n  `SUBSCRIBE_DECISION` sentinel, four-line macro lookback, and truncation only at a\n  `#[cfg(test)]` that opens a module.\n- **Census hazards paid for while constructing and reconciling the population:** the provisional\n  instrument moved `277/243 → 286 → 412 → 487 raw → 486 real` as four silent assumptions were\n  found: same-line matching misses multi-line macros; truncating at the first `#[cfg(test)]` drops\n  later shipping code; lookback must prefer the token line's own macro over a neighbouring arm;\n  and even that lookback can promote a nested token literal beneath a real macro into a phantom\n  second site. A file without a final newline also makes `wc -l` silently undercount logical\n  records by one. Every future census must name its SHA, assert a known member, count records\n  inside the generator, and reconcile emitted rows to real sites.\n- **Separate anchored-matcher finding:** `IDLE`, `DISPATCH`, `BUSY`, and `BOUND` are common words\n  matched as substrings in exposed consumers. One-write emission does not prevent an unrelated log\n  line from satisfying them; those predicates need anchored token matching. Keep this separate from\n  the tear remedy so neither defect is claimed to close the other.\n- **Kin:** [[IR-50]] (the sink must be read before its absence means anything), [[IR-40]] (a\n  confident signal that does not describe the source truth), [[IR-8]] (a plausible census whose\n  blind spot returns a clean answer).\n- **CLOSE-OUT ADDENDUM 2026-08-30 (#242/v0.66.0 sweep — the entry's own close-out re-census RAN\n  and FOUND the predicted blind spot LIVE; entry stays OPEN):** re-census at the landed sha\n  `ec6da9b0` (independent containment-classified meter, reconciled with todlando's independent\n  meter — full write-up `EMISSION-RESIDUAL-CENSUS-FINDING.md`): the generator truncated\n  `crates/spt/src/cli.rs` at its FIRST module-opening `#[cfg(test)]` (line 3007, module closes\n  3164, file runs to 39118) and never scanned the rest — **338 TOKEN-shaped shipping sites remain\n  bare (332 colon-form, i.e. misses under the sealed census's own predicate, + 6 space-form)**,\n  plus `main.rs` 2 sites behind the same mechanism; exactly TWO files tree-wide carry the\n  triggering property (first module-opening cfg(test) precedes shipping code) — the generator\n  fix's owed blind-spot measurement, answered. The census-hazards bullet above already NAMES this\n  third-face truncation hazard; the module-opening fix narrowed the trigger and kept the blind\n  spot for files where a test module CLOSES and shipping resumes — IR-8 shape, predicted by this\n  entry's own text. The shipped #241 conversions are UNAFFECTED (495 removals ≈ censused 486 +\n  space family; the SEEN population is closed; golden green stands). Residual conversion +\n  generator fix + enforcement-at-the-seam = **releases#243** (BACKLOG, operator triages);\n  delivery.rs:149/313 are post-cut MINTS relative to the census sha (todlando's own, settled\n  attribution), deliberately outside #243's census-mechanism scope — and ALREADY CONVERTED: the\n  fix rode his breadcrumb branch (`60a12056`) into the r4 head and shipped IN-TAG (todlando\n  flagged the stale \"his thin lane converts post-cut\" claim 2026-08-30; re-measured — zero bare\n  TOKEN `eprintln!` in delivery.rs at both `d931dd63` and origin/main). No lane is owed for it. Re-runnable meter\n  `EMISSION-RESIDUAL-CENSUS-METER.py` (repo root, untracked; version-control rides #243's lane).\n  **Common-word matcher RULED at this sweep (discharges the \"decide\" clause below):** the four\n  common-word consumers (`IDLE`/`DISPATCH`/`BUSY`/`BOUND` substring predicates) get a SEPARATE\n  hertz test-side rider — anchored token matching is consumer-predicate work, NOT folded into\n  #243 (keeps #243 product-scoped) and not claimed closed by one-write emission; lane-link when\n  hertz's spool drains.\n- **Closes when:** releases#243's residual conversion + generator fix land and a re-census at\n  that sha reads zero shipping residue under both delimiter forms. **Size:** product lane\n  complete elsewhere; register follow-through small.\n\n### IR-70 — a hand-built `IoBus` silently omitted later sinks while every gate stayed green\n\n- **Status:** OPEN, remedy unscheduled; the v0.65.0 respin fixed the witnessed call site on PR #173.\n  This entry owns the recurrence class, not that shipped correction. · **Origin:** releases#234,\n  commit `c5459795167`, CONDUIT #236 respin.\n- **Mechanism:** `publish_commune_io` constructed `IoBus` itself and registered only the sink it\n  knew. `default_bus` already existed as the assembly point and its module contract explicitly says\n  emitters must know only `IoBus::publish`, so adding a later sink costs one registration rather\n  than an emitter sweep. The hand-built publisher recreated exactly the drift that contract warned\n  against: `COMMUNE` and `COMMUNE_FAIL` reached the old sink but never the adapter log, leaving\n  `spt api io-events` permanently short on two documented kinds.\n- **Why the complete battery was green:** the e2e was vacuous on the broken kinds; units synthesized\n  rows without traversing `publish_commune_io`; and traceability checked attached tags, not whether\n  the tagged path exercised the real publisher. Three green instruments shared one blind seam.\n  The respin routed the site through `crate::iobus::default_bus`, and its source comment now records\n  the failure shape.\n- **Durable remedy direction (todlando mechanism, not scheduled):** enforce the assembly point so\n  the next hand-built bus is impossible rather than found — make production publishers obtain the\n  composed bus through one construction API, and gate the real publish path for every documented\n  kind. A search or comment is not enforcement; another emitter can satisfy both while rebuilding\n  a partial sink list.\n- **Kin:** [[IR-39]] (a green fixture never reached the missing dependency), [[IR-37]]\n  (traceability tags prove coverage bookkeeping, not behavioral truth), [[IR-58]] (a hand-built\n  population returns an orderly but incomplete answer).\n- **Ripe when:** the next `IoBus` construction/API touch, or a new sink registration. **Size:**\n  small-to-medium assembly-point enforcement plus a real-path population test.\n\n### IR-71 — controller-seat release has no persisted breadcrumb, so tests cannot distinguish propagation lag from a missing detach\n\n- **Status:** OPEN, observability gap; no remedy scheduled. · **Origin:** CONDUIT #236 r3\n  `er_brief_once_per_session_e2e` intermittent, classified test-side and fixed on PR #174.\n- **What/why:** killing rc1 reaps the controller process, but the broker is another process and\n  notices the socket close later. On that detach edge it clears `driven_by` and `controlled` in\n  `info.json`; rc2's preflight reads that file locally and can race the write, refuse normally, and\n  exit 0 without dialing the broker. The test originally spawned rc2 immediately and had no\n  observable precondition separating “release is propagating” from “release never happened.”\n- **The missing surface:** broker lifecycle state records `session-detach was_controller=true`, but\n  there is no always-on persisted breadcrumb that states the controller stamp was cleared, names\n  the resulting `driven_by`/`controlled` state, or measures detach-to-persist latency. The repaired\n  test therefore polls `info.json` itself, prints elapsed time (0.075s on the first local real run),\n  and uses a named 60s timeout whose failure promotes the finding from timing to missing release.\n  Its deliberately latched-seat unit proves the barrier can red.\n- **Remedy direction:** add one structured release breadcrumb after the persisted clear, carrying\n  session/connection identity and the resulting control state; if latency is carried, measure it\n  from the detach edge. It must ride the persisted daemon sink and remain distinct from\n  `session-detach`, which proves the connection event but not the file write.\n- **Kin:** [[IR-50]] (the sink a test must actually read), [[IR-40]] (an event timestamp is not a\n  completion signal), REQ-HAZARD-CONTROL-STAMP-CONVERGENCE.\n- **Ripe when:** the next controller lifecycle or structured-breadcrumb touch, or a field timeout\n  from PR #174's barrier. **Size:** small emitter plus one contract-level assertion.\n\n### IR-72 — no product read verb surfaces which process holds a perch or controller seat\n\n- **Status:** OPEN, observability gap; no remedy scheduled. · **Origin:** CONDUIT #236 r3\n  two-host RCA and PR #174 (`70c1a303`), corrected by doyle after IR-18 and daemon-status were\n  ruled out as different classes.\n- **Source-verified boundary:** the holder identity already exists in durable/internal records\n  (`InfoJson.pid`, `parent_pid`, and the broker's session pid), and product internals read it for\n  liveness, teardown, and self-detection. No product **read verb** returns the process that holds a\n  named perch/seat. PID-bearing teardown messages are failure outcomes, not an inspection surface;\n  daemon status is process-wide, not perch- or seat-scoped. This also does not collapse into\n  [[IR-18]], where an existing internal `read_pid` collapses absent and unreadable records.\n- **Paid-for consequence 1 — rigs manufacture custody:** PR #174's two-host repair had to add\n  `PidHolder` in `crates/spt/tests/twohost_cli.rs:401-437`, spawn a long-lived sibling process,\n  write that pid directly into each synthetic perch, retain the child handle, and kill+wait it on\n  drop. The rig can make a known holder; it cannot ask the product which holder the product sees.\n- **Paid-for consequence 2 — ambiguity stayed latent until behavior flipped:** the r3 fixture\n  seeded three perches with one test-process pid. Self-detection then enumerated a directory whose\n  first matching row was a filesystem-order coin, so a green could name the wrong perch. The\n  repaired resolver refuses an ambiguous candidate set instead of guessing, and the fixture's\n  `assert_only_ancestor_candidate` now re-reads every `info.json` rig-side\n  (`twohost_cli.rs:439-457`). Refusal is enforcement, not observability: it proves a tie but still\n  offers no supported verb that names each holding process.\n- **Remedy direction:** add one machine-readable, named-perch inspection surface that reports the\n  custody fields the product actually used — holder pid and role/source (bind relay, stable harness\n  parent, brokered controller/session) — without asking callers to parse private `info.json` or\n  scan the process table. PID alone is recyclable; where a birth/image/session stamp exists, carry\n  it so the output does not become a new bare-pid oracle.\n- **Kin:** [[IR-18]] (read primitive loses error class, explicitly distinct), [[IR-71]] (release\n  completion lacks a persisted breadcrumb), REQ-HAZARD-SELF-DETECT-TIE (refuse ambiguous ancestry\n  rather than select by enumeration order).\n- **Ripe when:** the next roster/status read-model change or another rig needs to reap a named\n  holder. **Size:** small read-model/API addition, medium if seat and perch custody need separate\n  typed variants.\n\n### IR-73 — ci.yml and release.yml still read the free-space floor PRE-checkout (literal-first sites off the golden path); and any job's floor is stale by its last heavy step\n\n- **Status:** OPEN, filed by doyle 2026-08-30 at the #242/v0.66.0 close sweep (deployah flag\n  2026-08-29, widen lane). · **Origin:** the #242 cut lost two golden attempts to exactly this\n  REQ-CI-FREE-SPACE-PREFLIGHT trap on `golden.yml`'s n1-gate (floor read BEFORE checkout, so the\n  checkout's own cost lands after the assertion); `golden.yml` is fully reshaped (`ac7d2609`,\n  both jobs, checkout-protective reaps verified to stay pre-checkout) — but `ci.yml` (5 tagged\n  sites) and `release.yml` (3 tagged sites) keep the literal-first shape, deliberately NOT\n  widened off the back of a golden.yml-scoped ruling.\n- **What/why:** review each of the 8 sites' comments for checkout-protective purpose (the\n  `ac7d2609` method), then reorder the read after checkout or RECORD why not, per site. The\n  \"other jobs keep the literal-first shape\" clause is the trap's carrier: every un-reviewed site\n  is a queued golden-attempt loss on a loaded box.\n- **Second half (from #242 r4, same family):** a single job-start floor read is stale by the\n  job's LAST heavy step — the r4 LNK1318 low-water face recorded on [[IR-59]] (sixth face);\n  the within-job re-read before the docs-drift build rides the next workflow commit alongside\n  this entry's reorders.\n- **Kin:** [[IR-46]] (a floor asserts an instant), [[IR-59]] (full volume reds as a linker\n  defect), REQ-CI-FREE-SPACE-PREFLIGHT.\n- **Ripe when:** next touch of `ci.yml`/`release.yml`, or the next intake's tooling-rider slot\n  (compose with IR-59/IR-57's standing pair). · **Size:** small — reorder or comment per site,\n  8 sites.\n\n### IR-74 — kitsubito holds 21,643 /tmp endpoint homes: box-side accumulation nothing bounds or measures\n\n- **Status:** OPEN, filed by doyle 2026-08-30 at the #242/v0.66.0 close sweep; measurement by\n  hertz (2026-08-29). · **Origin:** rig work on kitsubito found `/tmp` carrying 21,643 endpoint\n  homes — per-run spt homes that outlive their runs.\n- **What/why:** sibling of the [[IR-31]]/[[IR-59]]/[[IR-64]] family (box accumulation the\n  preflights never see): each is small, the population is not, and /tmp on a long-lived box is\n  never reaped by CI. Un-reaped homes also widen every by-path census a rig runs. Needs a\n  bounded lifecycle (per-run temp root reaped at run end, or a box-side sweep with a stated\n  retention), and the reap must state its count so a zero is a claim.\n- **Ripe when:** next kitsubito rig touch, or the between-milestone box-audit slot.\n- **Size:** small (one sweep script + adoption in the box's rig steps); the measurement rerun is\n  one `find | wc`.\n\n### IR-75 — traceable-reqs is not installed on kitsubito, so every Linux gate driver's treqs leg exits 127 (vacuous, wrapper-green shape)\n\n- **Status:** OPEN, filed by doyle 2026-08-30 at the #242/v0.66.0 close sweep (deployah\n  co-flagged at intake). · **Origin:** ASM-241 Linux battery — `ASM_treqs.exit` = 127, raw\n  `env: 'traceable-reqs': No such file or directory`; leg vacuous, covered that day by the\n  Windows treqs = 0 at the identical tree (treqs is a platform-independent text scan).\n- **What/why:** a 127 leg is exactly the wrapper-green shape [[IR-60]] documents — a driver that\n  doesn't read the exit FILE would report the leg green. Fix is either: install traceable-reqs on\n  kitsubito (then the leg is real), or DROP the leg from Linux gate drivers and state the\n  Windows-covers-it rule in the driver comment. Do NOT reopen [[IR-37]] for this — IR-37's\n  consume lane is spt-core CI (GitHub runners, green all week); this is BOX tooling, a different\n  surface (ruled at the sweep against the enumerating agent's overcautious flag).\n- **Ripe when:** next Linux gate-driver touch or kitsubito box-audit slot.\n- **Size:** trivial (install or one driver edit + comment).\n\n### IR-76 — hfenduleam is the golden Windows runner AND the builders' box: a local workspace nextest fully contained a golden Phase A and manufactured a load-timing red, and the job-start census cannot see it\n\n- **Status:** OPEN, filed by doyle 2026-09-06 during v0.67.1 golden triage (run 34017906638\n  att2). · **Origin:** the Windows Phase A red on\n  `spt-store::wtlock_two_process_int two_processes_commit_into_one_worktree_without_failing`\n  (B hit the 10 s worktree-lock bound while A's six serial commits took 13.5 s; 12 other\n  cells ran >10 s in the same phase). Load audit by todlando from his own `.raw`\n  CreationTimeUtc / `.exit` LastWriteTimeUtc: his #276 gate's 1240-cell workspace nextest\n  (`--no-fail-fast`, test phase 08:50:06–08:58:00Z) FULLY CONTAINED the golden Phase A\n  (08:52:38–08:56:49Z), every core saturated. He had been dispatched into that window and\n  never told the box was under a golden hold; perri and hertz had been.\n- **What/why:** two mechanisms, both unmeasured by anything in CI today. (1) The box is\n  shared by design — every agent's gate rig, adapter build and workspace nextest runs on the\n  same host as the self-hosted golden Windows runner, so a golden Windows leg is a QUIET\n  WINDOW only if every agent knows it is open; nothing says so, and a dispatch brief that\n  starts a gate is exactly how a builder lands inside it. (2) The job-start\n  `reap-census.ps1` counts the SPT FAMILY only (`family_total=12 scoped=0 unscoped=12` at\n  att2's 08:39:46Z start, with a builder's prebuild live on the box); cargo/nextest/rustc\n  load is outside its predicate, so the one instrument that runs at the right moment is\n  blind to the load that matters. Every load-timing red on Windows therefore triages as a\n  random victim with the cause off the record — the [[IR-63]] \"one random victim per sweep\"\n  face, now with a named source.\n- **Fix shape:** (a) driver templates (every gate/battery driver an agent authors here)\n  gain a PRE-FLIGHT leg with THREE outcomes, never two (todlando's amendment at filing: an\n  empty `gh run list` is the same bytes for CLEAR and for a broken meter — wrong filter,\n  expired token, rate limit, wrong repo default all return exit 0 and no rows — so a\n  two-arm guard fails OPEN into the exact hazard it guards, the `--commit <short-sha>`\n  confident-EMPTY class): run `gh run list --workflow golden --status in_progress`; rows\n  present -> HOLD, print the run id; no rows AND a positive control (`gh run list -L 1`\n  unfiltered, or `gh auth status`) returns a row -> CLEAR; control empty or erroring ->\n  REFUSE and say the meter is broken. A refusal, not a warning, so a wrapper-green shape\n  cannot swallow it ([[IR-60]]); the dispatch-brief line in (b) is likewise a MEASURED\n  clear with a live meter, never the absence of a sentence; (b) dispatch briefs that start a gate NAME the hold state of the box; (c)\n  the job-start census gains a second predicate — cargo/nextest/rustc/link processes by\n  image name, count + total CPU — reported beside the family count so a red's triage can\n  place foreign load from the log alone; (d) the golden hand-off contract\n  (docs/golden-head-intake) states the quiet-window rule once.\n- **Kin:** [[IR-63]] (random victim per sweep), [[IR-59]] (box conditions the preflights\n  never see), [[IR-64]] (hfenduleam's non-CI payload), FLAKE-LEDGER rows for\n  `wtlock_two_process_int` and `attach_link_push_e2e` (2026-09-06).\n- **Ripe when:** next driver-template touch (a/b are text; a is one leg), next `ci.yml`\n  touch for (c) — compose with [[IR-73]]'s reorders; (d) rides the next runbook edit.\n- **Size:** small — one pre-flight leg + one census predicate + two doc sentences.\n\n### IR-77 — nothing stamps the interval between a daemon child's spawn and the brain's first log line, so a readiness-deadline red cannot say WHERE the time went\n\n- **Status:** OPEN, filed by hertz 2026-09-07 from the W1 #249 kitsubito battery at the gated\n  sha `8d980fdf`; doyle-ruled at filing to be a register entry rather than a lane rider. ·\n  **Origin:** FLAKE-LEDGER `resident_service_e2e` :453 PRECONDITION (53 s) and\n  `resume_no_control_steal_e2e` (46 s), co-victims of ONE window — nextest exit 100, ONE\n  Summary `2999 tests run: 2997 passed (8 slow, 1 leaky), 2 failed, 1 skipped`. Evidence\n  preserved at `.spt/preserved/w1-kitsubito-8d980fdf/nextest.raw`, sha256\n  `9c456e21a6a0f75d8b0375ac648f232dba07f3887ec5e8dc232daef36253b51e`, hash-verified against\n  the kitsubito original.\n- **What/why:** both reds are a 45 s wait on `brain.ready` that expired, and the panel each\n  one prints shows the tree ALIVE — `BRAIN_UP`, `BRAIN_PHASE:announce done in 1ms`,\n  `BRAIN_PHASE:resume done in 0ms`, `SERVICE_STARTED` for both services, both later reaped\n  with an empty survivor set. So the daemon came up; it came up after the clock. WHERE those\n  45 s went is not recoverable from any artifact we keep: the first timestamped line in the\n  daemon's own sink is emitted by a process that has already started, and nothing stamps the\n  interval from the test's `Command::spawn` to it. The consequence is that every red of this\n  family is triaged by inference — v0.66.0 measured a ~10.1 s exe-hash on the ready path, and\n  that number is a CANDIDATE for the gap and can never be more than a candidate while the\n  interval is unmeasured. Remedy: one monotonic breadcrumb at daemon-child entry (before any\n  work), a second at the point `brain.ready` is stamped, both into the stderr sink the panel\n  already renders — then a red of this family reports its own split without a rerun.\n- **Kin:** [[IR-71]] (a seat release with no breadcrumb, same shape one layer over),\n  FLAKE-LEDGER `resident_service_e2e` :453 and `resume_no_control_steal_e2e` (2026-09-07),\n  and the HEAVY census stanza in `.config/nextest.toml`, which hardens the RECIPE these reds\n  came from and deliberately leaves the deadlines alone — a budget retune is the same race\n  with a different number, and it would also destroy the only signal this entry wants.\n- **Ripe when:** the next touch of the daemon boot path or of `brainproc`'s ready stamp; also\n  ripe as a rider on any lane that re-opens this test family.\n- **Size:** small — two `emit_line_err!` breadcrumbs and the sentence in the panel that says\n  what they mean.\n\n### IR-78 — `SPT_TEST_EPHEMERAL_ADVISORY_PORTS` silently overrides an explicitly set `SPT_DOCS_PORT`\n\n- **Status:** OPEN, filed by hertz 2026-09-07, MEASURED by doyle the same night on his W2\n  field pair (both boxes). · **Origin:** the 5474 rig-hygiene sweep in\n  `test/rig-advisory-ports-and-heavy-class`, which sets the rig flag at 37 `spt daemon run`\n  spawn sites.\n- **What/why:** `resolve_daemon_docs_port` (crates/spt-daemon/src/docshost.rs) returns `0`\n  whenever the rig flag is set, BEFORE the `SPT_DOCS_PORT` env override is consulted. With\n  both set, doyle's rig daemons took ephemeral ports (`DOCS_SERVER_UP` on 55369 Windows,\n  44015 Linux) while `SPT_DOCS_PORT=5480` was ignored without a word. The precedence itself is\n  defensible — the rig flag exists precisely so a test tree cannot take a well-known port —\n  but a SET override discarded in SILENCE is the shape IR-37 files under a different name: the\n  operator is left believing the value they set is the value in force. Remedy is a line, not a\n  redesign: emit one notice naming both env vars when the flag wins. No test cell is proposed\n  with it — none of the 31 swept binaries asserts on a docs port, so a cell here would assert\n  a behaviour nothing consumes.\n- **Kin:** [[IR-37]] (a set input silently ignored), the 5474 hygiene sweep, and the\n  `DOCS_SERVER_BIND_FAIL: port 5474: Address already in use (os error 98)` lines in\n  `.spt/preserved/w1-kitsubito-8d980fdf/nextest.raw` that started the sweep.\n- **NOT measured, stated so nobody reads it as covered:** doyle measured that the WMI\n  auto-start rung DOES carry the caller's environment (rig daemon pid 50088 on hfenduleam:\n  `DAEMON_LAUNCH_VIA_WMI`, its environ carrying `SPT_HOME`, `SPT_DOCS_PORT` and the rig flag\n  as his shell set them, `brain.ready` in the rig home). The schtasks (at-logon) rung was NOT\n  measured, and neither was the unix path.\n- **Ripe when:** the next `docshost.rs` touch, or the first time someone sets `SPT_DOCS_PORT`\n  on a rig and believes it.\n- **Size:** tiny — one emitted notice.\n\n### IR-79 — 22 of the 31 rig binaries leak their daemon tree on a failing assert: teardown is a statement, not a guard\n\n- **Status:** OPEN, filed by hertz 2026-09-07 on doyle's dispatch during PR #198's CI window,\n  from todlando's red 6 (a stale same-port daemon from his own previous run answering the next\n  one). · **Origin:** PR #198 moved 31 rigs to `SPT_TEST_EPHEMERAL_ADVISORY_PORTS=1`. Under an\n  ephemeral port a leaked daemon can no longer ANSWER the next run, so that PR is right as it\n  stands and this entry is not a defect in it; what remains is the orphan process itself — it pins\n  `spt.exe` (the Windows delete-and-rebuild hazard) and holds an `SPT_HOME` that nothing reaps. · **SCOPE BROADENED 07:20Z:** the title says \"on a failing\n  assert\" because that is the face it was filed from; the SECOND FACE bullet below shows the same\n  mechanism firing on a nextest TIMEOUT and leaking THREADS rather than a daemon. Read the title as\n  the handle, not the boundary — the trigger is any exit that does not reach the teardown statement.\n- **What/why:** measured over the 31, classifying each binary by whether its daemon teardown\n  survives a panic (a failing `assert!` unwinds, so only a guard or an ordering discipline saves\n  the child):\n  - **panic-safe, 9:** `impl Drop` guard — `endpoint_autostart_e2e`,\n    `knock_mutual_cross_node_e2e`, `twohost_cli`; `catch_unwind` teardown —\n    `activity_link_push_e2e`, `attach_link_push_e2e`, `wake_resume_bind_e2e`;\n    teardown-then-assert with zero exposed asserts — `endpoint_teardown_authority_e2e`,\n    `er_briefing_session_scoped_e2e`, `er_sequestered_cwd_e2e`.\n  - **leaks on a failing assert, 22** (exposed asserts / total asserts in the test body):\n    `projindex_writer_e2e` 21/21, `projindex_reader_e2e` 18/18,\n    `live_adapt_translation_swap_e2e` 15/38, `brain_split` 12/12,\n    `er_briefing_presented_e2e` 10/28, `rc_attach_truth` 8/29, `brain_respawn_rename` 6/6,\n    `dummy_harness_e2e` 4/11, `idle_edge_drain_e2e` 4/11, `multi_subnet_bringup_e2e` 4/20,\n    `bind_honest_cross_perch_e2e` 3/6, `idle_edge_seal_e2e` 3/17, `resident_service_e2e` 3/24,\n    `attach_wedge_e2e` 2/8, `bind_cwd_project_e2e` 2/8, `daemon_refresh_e2e` 2/11,\n    `er_brief_once_per_session_e2e` 2/13, `n1_pairing` 2/5, `resume_template_e2e` 2/10,\n    `run_no_dup_session_e2e` 2/14, `er_briefing_presentation_e2e` 1/4,\n    `livehost_bootgate_e2e` 1/3.\n  **FIRST WAVE of the Drop-guard generalization lane (doyle-ruled 2026-09-07, composed at the next\n  register sweep, not now): `projindex_writer_e2e`, `projindex_reader_e2e`, `brain_split`,\n  `brain_respawn_rename`.** These four expose EVERY assert they have — their teardown is the last\n  statement in the body, so any red at all leaks, which makes them both the worst cases and the\n  cleanest proofs that a guard works. The remedy already exists in this tree —\n  todlando's `DaemonReaper`, a `Drop` guard armed BEFORE the first CLI call — and the follow-up\n  lane is to generalise it into `crates/spt/tests/common` and adopt it at these 22 sites, which is\n  also the only shape that covers a `SIGKILL`-free timeout kill by nextest.\n- **METHOD, and its limits, so the count can be re-derived and challenged:** the classifier reads\n  each `#[test]` body, resolves file-local helper fns whose own body tears down (so a teardown\n  called through `sweep()` counts), and reports every `assert!`/`panic!` positioned before the LAST\n  teardown call in that body. It therefore (a) misses asserts written inline inside a closure or a\n  macro argument rather than at statement position, (b) treats the last teardown as THE teardown —\n  a partial earlier teardown still leaves the tree, so the true exposure is >= this count, and\n  (c) does not model `?` or early `return`. Spot-verified by hand on `resident_service_e2e`, whose\n  3 exposed asserts are real: they fire in the `wait_until` legs well before the `sweep()` at :435\n  that the \"── ASSERTIONS ──\" block follows.\n- **TONIGHT'S LIVE SAMPLE, so this is not an academic count (doyle's hfenduleam census 06:43Z):**\n  10 leaked `spt.exe` from todlando's pool, pairing by start time, from his pre-yield legs — a\n  single evening's rig work on one box. Each pins the binary against a rebuild and holds an\n  `SPT_HOME` nothing reaps.\n- **SECOND FACE — the same hazard in THREAD clothes, and it blocks the RUNNER, not just the box\n  (measured by todlando 07:17Z, relayed by doyle 07:20Z; I did not measure it myself and record it\n  as his testimony):** a nextest TIMEOUT on a `twohost_web` cell left the cell's child process\n  holding the broker + listener THREADS. Consequences, with his numbers:\n  - nextest itself blocked **14 minutes** at **0.61 CPU-seconds** — a wall-clock hang with\n    essentially no CPU, which is the signature of a parent waiting on a child's pipe rather than\n    of work being done;\n  - **`a.exit` was never written**, while **every verdict was already in `a.raw`** — so the leg\n    read as INCOMPLETE at the exact moment its results were complete. A reader who trusts the\n    exit file over the raw would call this a hung or failed leg and rerun it;\n  - **killing the path-verified orphan let the parent finish at once** — which is the causal test,\n    not a correlation: the kill is the intervention and the unblock is the response.\n  **Why it belongs in THIS entry rather than a new one:** the leaked thing is a thread inside a\n  child, not a daemon, but the mechanism is identical — a teardown that is a STATEMENT does not run\n  when the body does not reach it, and a timeout kill reaches the body even less reliably than a\n  panic does. The `Drop`-guard lane covers both faces with one remedy, which is doyle's ruling and\n  the reason no separate entry is opened. It also raises the lane's value: the daemon face costs a\n  pinned binary and an unreaped `SPT_HOME`, this face costs **14 minutes of a serialized golden\n  leg** and manufactures a false INCOMPLETE.\n  **Reading rule this hands the gate, worth stating because it is cheap:** when a leg's `.exit` is\n  missing, read the `.raw` for a Summary BEFORE concluding the leg hung — kin to\n  [[a-stopped-local-ssh-does-not-stop-its-remote-command]], where the raw was likewise the honest\n  record and the wrapper was not.\n- **Kin:** FLAKE-LEDGER `resident_service_e2e` :664 teardown LEAK row (3 occurrences, the Windows\n  face of the same class), [[IR-34]], [[IR-74]] (kitsubito's 21,643 `/tmp` endpoint homes — this is\n  one of the producers), and todlando's red 6.\n- **Ripe when:** the next lane that touches `crates/spt/tests/common` — the guard belongs there,\n  not copied 22 times.\n- **Size:** medium — one guard in `common`, then 22 mechanical adoptions, each provable by\n  panicking the body under a temporary test and watching the census go quiet.\n\n### IR-80 — five leaky cells on ONE module (`brainproc` / `supervise_brain`), Windows only: a candidate PRODUCT leak on the promotion/rollback path, or a cluster of names — nobody has looked yet\n\n- **Status:** OPEN, filed by hertz 2026-09-07 07:40Z on doyle's ruling (07:38Z) that this is its\n  OWN entry and **not** a third face of [[IR-79]] — IR-79 is rig teardown, this is a candidate\n  defect in the PRODUCT path, so its owner may be todlando rather than the rig lane. ·\n  **Origin:** noticed while measuring the #198 HEAVY scan-root gap ([[IR-37]] rider 2); the leak\n  roster was read out of the baseline golden log for an unrelated reason.\n- **⚠ WHAT THIS ENTRY IS, STATED FIRST SO IT IS NOT OVERREAD: a CLUSTER OF NAMES.** Five cells\n  that leaked share one module and one code path by their identifiers. Nothing has been measured\n  about WHAT is left alive, and a shared module is not a shared cause. Do not cite this as a\n  product defect until the census below has run.\n- **The observation, exact.** Golden run **34017906638**, sha `04e32c8c95cf`, both boxes, Phase A.\n  Windows (hfenduleam) reported **9 leaky** cells; Linux (kitsubito) **1** (`livehost::tests::\n  legacy_psyche_sweep_guard_is_id_specific_and_fail_safe`, unrelated). **Five of the Windows nine\n  are the same module:**\n\n  | cell | kind | time |\n  |---|---|---|\n  | `spt-daemon brainproc::tests::clear_before_spawn_defeats_exact_generation_stale_file` (:2200) | lib | 0.457s |\n  | `spt-daemon brainproc::tests::ready_but_old_gen_never_drains_does_not_promote_rolls_back` (:1834) | lib | 0.554s |\n  | `spt-daemon brainproc::tests::stale_generation_minus_one_ready_never_promotes` (:2155) | lib | 0.731s |\n  | `spt-daemon brainproc::tests::trial_kills_alive_never_ready_candidate_before_rollback` (:2109) | lib | 0.582s |\n  | `spt-daemon::false_promote ready_candidate_does_not_promote_until_the_wedged_old_gen_conn_drains` | int | 1.744s |\n\n  Denominator for the lib half: `brainproc`'s test module holds **26** `#[test]`/`#[tokio::test]`\n  cells, so **4 of 26 leaked, and all four are the trial/promote/rollback cells by name.** The\n  fifth is the integration rig that drives the same path.\n- **Why it is worth an entry even unmeasured:** four of the five are `kind(lib)`, so they run in\n  **`ci.yml` on every push**, not only in golden — if something really is left alive it is being\n  left alive on the shared Windows box many times a day. That is the same standing cost as\n  [[IR-79]]'s daemon face, arrived at from the opposite direction.\n- **HYPOTHESIS, labelled as such and NOT measured.** `supervise_brain` (:935) takes an injected\n  `spawn_child: impl FnMut(...) -> io::Result<Child>` (:941) and reaps candidates with bare\n  `let _ = child.kill();` at :998, :1015, :1055, :1071, :1081 — **`kill()` with no `wait()`.** On\n  Windows termination is asynchronous, and a killed-but-unreaped child can still hold the\n  inherited stdout/stderr pipe past the test's exit, which is exactly what nextest reports as\n  LEAK. The production spawner's own doc comment at :1190 states the intent — \"dies with no\n  orphaning. NOT `spawn_detached`\" — so if this is the mechanism, the code's intent and its\n  behaviour have diverged on one platform. **Every clause of this bullet is a reading of source,\n  not an observation of a live process. It may be entirely wrong.**\n- **FIRST MEASUREMENT — and doyle sharpened it 07:41Z from a census into a FALSIFIER, which is the\n  form to run:** on a free Windows box after W2, run\n  `trial_kills_alive_never_ready_candidate_before_rollback` **alone** and read one thing —\n  **is the killed pid still present, with the pipe handle open?** That is a yes/no against the\n  hypothesis above, not an open look at what happens to be running, and it is the difference\n  between a reading that settles the entry and a reading that produces more names. Capture pid,\n  image path and parent alongside the answer so a YES is immediately actionable, but the ANSWER is\n  the deliverable. One cell, one read. **Owner stays UNASSIGNED until it is taken** (doyle) — a\n  product path and a rig artifact are not distinguishable from here, and assigning before the read\n  would pick one by guess.\n- **Limits, so the entry cannot be overread:** nextest `LEAK` is **not a failure** — none of these\n  cells reds anything, and the run was green. Windows-only in **one** run; no trend established.\n  The clustering is by identifier and shared module, which is suggestive and is not causation.\n  I have not run any of these cells. Everything above is source plus one golden log — no box, no\n  build.\n- **Kin:** [[IR-79]] (children outliving the cell — the rig-teardown face of the same symptom, and\n  the reason doyle ruled these must stay SEPARATE: same symptom, different suspected owner),\n  [[IR-37]] rider 2 (the measurement that surfaced it), FLAKE-LEDGER's `resident_service_e2e` :664\n  teardown LEAK row.\n- **Ripe when:** the first free Windows box after W2 lands — it is a single-cell census, so it\n  fits any gap.\n- **Size:** unknown until the census. Tiny if it is a missing `wait()`; not tiny if the promotion\n  path leaves a real candidate brain alive on rollback.\n\n---\n\n#### THE LEAK SET IS NOISY — measured across three shas, 2026-09-07 (hertz)\n\n**This retracts the \"8 -> 5 leaky, direction favourable\" reading I flagged at 09:31Z.** It is not a\nfix and not an improvement; it is threshold noise, and the census this draft was built on inherits\nthat noise.\n\nWindows `ci` unit leg (`--workspace -E 'kind(lib) + kind(bin)'`), three consecutive shas:\n\n| cell | ff4b405d | e3bd53d4 | 401a19ad |\n|---|---|---|---|\n| brainproc::clear_before_spawn_defeats_exact_generation_stale_file | ● | ● | ● |\n| brainproc::ready_but_old_gen_never_drains_does_not_promote_rolls_back | ● | ● | ● |\n| brainproc::trial_kills_alive_never_ready_candidate_before_rollback | ● | ● | ● |\n| spt-runtime runtime::bounded_run_kills_on_timeout | ● | ● | ● |\n| brainproc::stale_generation_minus_one_ready_never_promotes | ● | ● | — |\n| spt-live digest::extractor_timeout_errors | ● | ● | — |\n| spt-live history::fetcher_timeout_errors | ● | ● | — |\n| spt-daemon broker::windows_session_is_zombie_sees_a_handle_held_corpse_as_dead | ● | — | — |\n| spt-daemon shellwake::kill_waker_at_still_kills_a_matching_pair | — | ● | ● |\n| **total** | **8** | **8** | **5** |\n\n**Causality check, which is what makes this a retraction rather than a hypothesis:** the three\ncommits between e3bd53d4 and 401a19ad touch **zero files** in brainproc, spt-live, spt-runtime,\nshellwake or broker (`git diff --name-only` over those paths returns nothing). The count fell by 3\nwith no change to any leaking module. So the drop cannot be a fix; the membership simply moves.\nNine cells appear in the union, only **four** are present at all three shas, and one\n(`shellwake::kill_waker_at`) *appeared* rather than vanished — a count that falls while a new member\njoins is the signature of a threshold, not of a repair.\n\n#### Three consequences for this draft\n\n1. **A count is not a quality signal here, in either direction.** Any future \"leaky went down\"\n   claim needs the NAME diff and a causality check against the changed files, or it is noise\n   reported as progress. I made exactly that error and it survived about twenty minutes.\n2. **The five-cell cluster is really \"three stable + one intermittent\".**\n   `stale_generation_minus_one_ready_never_promotes` is absent at 401a19ad. The cluster framing\n   still holds — three brainproc cells leak at every sha and they are all one module — but the\n   membership count must not be quoted as fixed.\n3. **doyle's falsifier beats my census, and this is the evidence.** The census (count the leaky\n   cells, name the cluster) is exactly what the noise destroys. His falsifier — *after\n   `trial_kills_alive_never_ready_candidate_before_rollback` on Windows, is the killed pid still\n   present with the pipe handle open?* — names ONE cell and probes a MECHANISM, and that cell is\n   **leaky at all three shas**, so it is the most stable target available. A mechanism probe is\n   immune to the threshold that moves the population. Owner stays UNASSIGNED until that read.\n\n#### One structural finding the noise does NOT touch\n**All nine union members spawn a child and then kill it, let it time out, or inspect its corpse** —\n`trial_kills_alive`, `kill_waker_at`, `bounded_run_kills_on_timeout`, `extractor_timeout_errors`,\n`fetcher_timeout_errors`, `windows_session_is_zombie_sees_a_handle_held_corpse_as_dead`, and the\nthree brainproc spawn/promote/rollback cells. Not one unrelated cell is in the set. Membership\nfluctuates; the *kind* of cell does not. That is a real signal about where child-process teardown\nis unreliable on Windows, and it is the same territory as [[ir79]] (rigs leaking daemons on a\nfailing assert) and [[ir81]] (kill scoping) — three drafts converging on one seam.\n\n---\n\n#### THE 12-CELL UNION — 4 shas x 2 OSes, membership beside the invariant (hertz, 2026-09-07 10:15Z)\n\n…\n\n…\n\n\n[Showing lines 3620-4143 of 5781. Use :4144 to continue]"}],"details":{"truncation":{"content":"  handle once per format fragment; the per-process stderr lock cannot serialize the other process.\r\n  The observed interleave split the autostart token between `ENDPOINT_AUTOSTART:` and `gwauto`.\r\n  This is fragment-level cross-process interleaving, not a failed replay and not a two-thread race.\r\n- **Durable remedy, ruled product-side:** render a complete diagnostic line into one buffer and\r\n  issue the complete rendered text, newline included, as **ONE handle call**. An OS short-write\r\n  may retry the late tail so completeness wins over a silently truncated line; the deterministic\r\n  property pins application-side fragmentation, not syscall count under that rare retry. It makes\r\n  no claim that the OS write is atomic on Windows, and no CI re-fire against a 1-of-2 observation\r\n  may stand in for it. Widening one test's grep is refused: it greens one consumer while every\r\n  sibling token remains exposed.\r\n- **Cut-SHA census** (todlando generator, independently hash-verified by hertz), measured from\r\n  `4d6007ac4ee3d0991f4bc60b7e1a55825aad1aaf` via `git show`, not a dirty worktree:\r\n  **486 real emitter sites / 383 distinct tokens / 26 consumer test files**. The generator emitted\r\n  487 site rows, but one is a known phantom: `sealverb.rs:456` is a `format!` inside `map_err`\r\n  that the four-line lookback attributed to a neighbouring real `eprintln!`. Corrected real emitters\r\n  by crate: spt-daemon 270, spt 194, spt-runtime 8, spt-live 5, spt-net 5, spt-store 4; by macro:\r\n  `eprintln!` 484, `println!` 1, `eprint!` 1. `DRIVEN_BY` is the sole stdout row and therefore\r\n  outside the stderr remedy. A consumer means the test both mentions `TOKEN:` and reads a\r\n  stderr/log surface; bare-token matching inflated the population to 72 files by admitting prose.\r\n  This is an **exposure map**, not a rate and not a claim that all 26 have torn.\r\n- **Artifacts (the preserved raw generator outputs contain 487 site rows):** cut census SHA-256:\r\n  sites `f10d6bfe5e0399f98945cf63bb5719a01a62e1251be84165c73030fa9bb224f5`,\r\n  tokens `80b0d1835d9d46376b2f200b1c50be4ca0e185a135168444414255f9308ed92b`,\r\n  consumers `249a2e33df43a30570ca82b5bd200d8b6e2bf07aa8250fcc8bace47fe23e3cbc`.\r\n  The sealed sites file's macro column is wrong on 7 of its 487 raw rows; the corrected raw split\r\n  is `eprintln!` 485 / `println!` 1 / `eprint!` 1. The sealed tokens file has no final newline, so\r\n  `wc -l` reports 382 although it contains 383 logical records. The sealed files remain unedited;\r\n  these corrections are textual.\r\n  Generator `81df82f01ef33a82307920d9804a2394b787ef2ffbe3b41d2d7dda560d9a62a9`\r\n  was recorded as asserting newline-terminated output, but the sealed tokens artifact refutes that\r\n  claim for at least one output. Its remaining guards cover logical record counts, a known-positive\r\n  `SUBSCRIBE_DECISION` sentinel, four-line macro lookback, and truncation only at a\r\n  `#[cfg(test)]` that opens a module.\r\n- **Census hazards paid for while constructing and reconciling the population:** the provisional\r\n  instrument moved `277/243 → 286 → 412 → 487 raw → 486 real` as four silent assumptions were\r\n  found: same-line matching misses multi-line macros; truncating at the first `#[cfg(test)]` drops\r\n  later shipping code; lookback must prefer the token line's own macro over a neighbouring arm;\r\n  and even that lookback can promote a nested token literal beneath a real macro into a phantom\r\n  second site. A file without a final newline also makes `wc -l` silently undercount logical\r\n  records by one. Every future census must name its SHA, assert a known member, count records\r\n  inside the generator, and reconcile emitted rows to real sites.\r\n- **Separate anchored-matcher finding:** `IDLE`, `DISPATCH`, `BUSY`, and `BOUND` are common words\r\n  matched as substrings in exposed consumers. One-write emission does not prevent an unrelated log\r\n  line from satisfying them; those predicates need anchored token matching. Keep this separate from\r\n  the tear remedy so neither defect is claimed to close the other.\r\n- **Kin:** [[IR-50]] (the sink must be read before its absence means anything), [[IR-40]] (a\r\n  confident signal that does not describe the source truth), [[IR-8]] (a plausible census whose\r\n  blind spot returns a clean answer).\r\n- **CLOSE-OUT ADDENDUM 2026-08-30 (#242/v0.66.0 sweep — the entry's own close-out re-census RAN\r\n  and FOUND the predicted blind spot LIVE; entry stays OPEN):** re-census at the landed sha\r\n  `ec6da9b0` (independent containment-classified meter, reconciled with todlando's independent\r\n  meter — full write-up `EMISSION-RESIDUAL-CENSUS-FINDING.md`): the generator truncated\r\n  `crates/spt/src/cli.rs` at its FIRST module-opening `#[cfg(test)]` (line 3007, module closes\r\n  3164, file runs to 39118) and never scanned the rest — **338 TOKEN-shaped shipping sites remain\r\n  bare (332 colon-form, i.e. misses under the sealed census's own predicate, + 6 space-form)**,\r\n  plus `main.rs` 2 sites behind the same mechanism; exactly TWO files tree-wide carry the\r\n  triggering property (first module-opening cfg(test) precedes shipping code) — the generator\r\n  fix's owed blind-spot measurement, answered. The census-hazards bullet above already NAMES this\r\n  third-face truncation hazard; the module-opening fix narrowed the trigger and kept the blind\r\n  spot for files where a test module CLOSES and shipping resumes — IR-8 shape, predicted by this\r\n  entry's own text. The shipped #241 conversions are UNAFFECTED (495 removals ≈ censused 486 +\r\n  space family; the SEEN population is closed; golden green stands). Residual conversion +\r\n  generator fix + enforcement-at-the-seam = **releases#243** (BACKLOG, operator triages);\r\n  delivery.rs:149/313 are post-cut MINTS relative to the census sha (todlando's own, settled\r\n  attribution), deliberately outside #243's census-mechanism scope — and ALREADY CONVERTED: the\r\n  fix rode his breadcrumb branch (`60a12056`) into the r4 head and shipped IN-TAG (todlando\r\n  flagged the stale \"his thin lane converts post-cut\" claim 2026-08-30; re-measured — zero bare\r\n  TOKEN `eprintln!` in delivery.rs at both `d931dd63` and origin/main). No lane is owed for it. Re-runnable meter\r\n  `EMISSION-RESIDUAL-CENSUS-METER.py` (repo root, untracked; version-control rides #243's lane).\r\n  **Common-word matcher RULED at this sweep (discharges the \"decide\" clause below):** the four\r\n  common-word consumers (`IDLE`/`DISPATCH`/`BUSY`/`BOUND` substring predicates) get a SEPARATE\r\n  hertz test-side rider — anchored token matching is consumer-predicate work, NOT folded into\r\n  #243 (keeps #243 product-scoped) and not claimed closed by one-write emission; lane-link when\r\n  hertz's spool drains.\r\n- **Closes when:** releases#243's residual conversion + generator fix land and a re-census at\r\n  that sha reads zero shipping residue under both delimiter forms. **Size:** product lane\r\n  complete elsewhere; register follow-through small.\r\n\r\n### IR-70 — a hand-built `IoBus` silently omitted later sinks while every gate stayed green\r\n\r\n- **Status:** OPEN, remedy unscheduled; the v0.65.0 respin fixed the witnessed call site on PR #173.\r\n  This entry owns the recurrence class, not that shipped correction. · **Origin:** releases#234,\r\n  commit `c5459795167`, CONDUIT #236 respin.\r\n- **Mechanism:** `publish_commune_io` constructed `IoBus` itself and registered only the sink it\r\n  knew. `default_bus` already existed as the assembly point and its module contract explicitly says\r\n  emitters must know only `IoBus::publish`, so adding a later sink costs one registration rather\r\n  than an emitter sweep. The hand-built publisher recreated exactly the drift that contract warned\r\n  against: `COMMUNE` and `COMMUNE_FAIL` reached the old sink but never the adapter log, leaving\r\n  `spt api io-events` permanently short on two documented kinds.\r\n- **Why the complete battery was green:** the e2e was vacuous on the broken kinds; units synthesized\r\n  rows without traversing `publish_commune_io`; and traceability checked attached tags, not whether\r\n  the tagged path exercised the real publisher. Three green instruments shared one blind seam.\r\n  The respin routed the site through `crate::iobus::default_bus`, and its source comment now records\r\n  the failure shape.\r\n- **Durable remedy direction (todlando mechanism, not scheduled):** enforce the assembly point so\r\n  the next hand-built bus is impossible rather than found — make production publishers obtain the\r\n  composed bus through one construction API, and gate the real publish path for every documented\r\n  kind. A search or comment is not enforcement; another emitter can satisfy both while rebuilding\r\n  a partial sink list.\r\n- **Kin:** [[IR-39]] (a green fixture never reached the missing dependency), [[IR-37]]\r\n  (traceability tags prove coverage bookkeeping, not behavioral truth), [[IR-58]] (a hand-built\r\n  population returns an orderly but incomplete answer).\r\n- **Ripe when:** the next `IoBus` construction/API touch, or a new sink registration. **Size:**\r\n  small-to-medium assembly-point enforcement plus a real-path population test.\r\n\r\n### IR-71 — controller-seat release has no persisted breadcrumb, so tests cannot distinguish propagation lag from a missing detach\r\n\r\n- **Status:** OPEN, observability gap; no remedy scheduled. · **Origin:** CONDUIT #236 r3\r\n  `er_brief_once_per_session_e2e` intermittent, classified test-side and fixed on PR #174.\r\n- **What/why:** killing rc1 reaps the controller process, but the broker is another process and\r\n  notices the socket close later. On that detach edge it clears `driven_by` and `controlled` in\r\n  `info.json`; rc2's preflight reads that file locally and can race the write, refuse normally, and\r\n  exit 0 without dialing the broker. The test originally spawned rc2 immediately and had no\r\n  observable precondition separating “release is propagating” from “release never happened.”\r\n- **The missing surface:** broker lifecycle state records `session-detach was_controller=true`, but\r\n  there is no always-on persisted breadcrumb that states the controller stamp was cleared, names\r\n  the resulting `driven_by`/`controlled` state, or measures detach-to-persist latency. The repaired\r\n  test therefore polls `info.json` itself, prints elapsed time (0.075s on the first local real run),\r\n  and uses a named 60s timeout whose failure promotes the finding from timing to missing release.\r\n  Its deliberately latched-seat unit proves the barrier can red.\r\n- **Remedy direction:** add one structured release breadcrumb after the persisted clear, carrying\r\n  session/connection identity and the resulting control state; if latency is carried, measure it\r\n  from the detach edge. It must ride the persisted daemon sink and remain distinct from\r\n  `session-detach`, which proves the connection event but not the file write.\r\n- **Kin:** [[IR-50]] (the sink a test must actually read), [[IR-40]] (an event timestamp is not a\r\n  completion signal), REQ-HAZARD-CONTROL-STAMP-CONVERGENCE.\r\n- **Ripe when:** the next controller lifecycle or structured-breadcrumb touch, or a field timeout\r\n  from PR #174's barrier. **Size:** small emitter plus one contract-level assertion.\r\n\r\n### IR-72 — no product read verb surfaces which process holds a perch or controller seat\r\n\r\n- **Status:** OPEN, observability gap; no remedy scheduled. · **Origin:** CONDUIT #236 r3\r\n  two-host RCA and PR #174 (`70c1a303`), corrected by doyle after IR-18 and daemon-status were\r\n  ruled out as different classes.\r\n- **Source-verified boundary:** the holder identity already exists in durable/internal records\r\n  (`InfoJson.pid`, `parent_pid`, and the broker's session pid), and product internals read it for\r\n  liveness, teardown, and self-detection. No product **read verb** returns the process that holds a\r\n  named perch/seat. PID-bearing teardown messages are failure outcomes, not an inspection surface;\r\n  daemon status is process-wide, not perch- or seat-scoped. This also does not collapse into\r\n  [[IR-18]], where an existing internal `read_pid` collapses absent and unreadable records.\r\n- **Paid-for consequence 1 — rigs manufacture custody:** PR #174's two-host repair had to add\r\n  `PidHolder` in `crates/spt/tests/twohost_cli.rs:401-437`, spawn a long-lived sibling process,\r\n  write that pid directly into each synthetic perch, retain the child handle, and kill+wait it on\r\n  drop. The rig can make a known holder; it cannot ask the product which holder the product sees.\r\n- **Paid-for consequence 2 — ambiguity stayed latent until behavior flipped:** the r3 fixture\r\n  seeded three perches with one test-process pid. Self-detection then enumerated a directory whose\r\n  first matching row was a filesystem-order coin, so a green could name the wrong perch. The\r\n  repaired resolver refuses an ambiguous candidate set instead of guessing, and the fixture's\r\n  `assert_only_ancestor_candidate` now re-reads every `info.json` rig-side\r\n  (`twohost_cli.rs:439-457`). Refusal is enforcement, not observability: it proves a tie but still\r\n  offers no supported verb that names each holding process.\r\n- **Remedy direction:** add one machine-readable, named-perch inspection surface that reports the\r\n  custody fields the product actually used — holder pid and role/source (bind relay, stable harness\r\n  parent, brokered controller/session) — without asking callers to parse private `info.json` or\r\n  scan the process table. PID alone is recyclable; where a birth/image/session stamp exists, carry\r\n  it so the output does not become a new bare-pid oracle.\r\n- **Kin:** [[IR-18]] (read primitive loses error class, explicitly distinct), [[IR-71]] (release\r\n  completion lacks a persisted breadcrumb), REQ-HAZARD-SELF-DETECT-TIE (refuse ambiguous ancestry\r\n  rather than select by enumeration order).\r\n- **Ripe when:** the next roster/status read-model change or another rig needs to reap a named\r\n  holder. **Size:** small read-model/API addition, medium if seat and perch custody need separate\r\n  typed variants.\r\n\r\n### IR-73 — ci.yml and release.yml still read the free-space floor PRE-checkout (literal-first sites off the golden path); and any job's floor is stale by its last heavy step\r\n\r\n- **Status:** OPEN, filed by doyle 2026-08-30 at the #242/v0.66.0 close sweep (deployah flag\r\n  2026-08-29, widen lane). · **Origin:** the #242 cut lost two golden attempts to exactly this\r\n  REQ-CI-FREE-SPACE-PREFLIGHT trap on `golden.yml`'s n1-gate (floor read BEFORE checkout, so the\r\n  checkout's own cost lands after the assertion); `golden.yml` is fully reshaped (`ac7d2609`,\r\n  both jobs, checkout-protective reaps verified to stay pre-checkout) — but `ci.yml` (5 tagged\r\n  sites) and `release.yml` (3 tagged sites) keep the literal-first shape, deliberately NOT\r\n  widened off the back of a golden.yml-scoped ruling.\r\n- **What/why:** review each of the 8 sites' comments for checkout-protective purpose (the\r\n  `ac7d2609` method), then reorder the read after checkout or RECORD why not, per site. The\r\n  \"other jobs keep the literal-first shape\" clause is the trap's carrier: every un-reviewed site\r\n  is a queued golden-attempt loss on a loaded box.\r\n- **Second half (from #242 r4, same family):** a single job-start floor read is stale by the\r\n  job's LAST heavy step — the r4 LNK1318 low-water face recorded on [[IR-59]] (sixth face);\r\n  the within-job re-read before the docs-drift build rides the next workflow commit alongside\r\n  this entry's reorders.\r\n- **Kin:** [[IR-46]] (a floor asserts an instant), [[IR-59]] (full volume reds as a linker\r\n  defect), REQ-CI-FREE-SPACE-PREFLIGHT.\r\n- **Ripe when:** next touch of `ci.yml`/`release.yml`, or the next intake's tooling-rider slot\r\n  (compose with IR-59/IR-57's standing pair). · **Size:** small — reorder or comment per site,\r\n  8 sites.\r\n\r\n### IR-74 — kitsubito holds 21,643 /tmp endpoint homes: box-side accumulation nothing bounds or measures\r\n\r\n- **Status:** OPEN, filed by doyle 2026-08-30 at the #242/v0.66.0 close sweep; measurement by\r\n  hertz (2026-08-29). · **Origin:** rig work on kitsubito found `/tmp` carrying 21,643 endpoint\r\n  homes — per-run spt homes that outlive their runs.\r\n- **What/why:** sibling of the [[IR-31]]/[[IR-59]]/[[IR-64]] family (box accumulation the\r\n  preflights never see): each is small, the population is not, and /tmp on a long-lived box is\r\n  never reaped by CI. Un-reaped homes also widen every by-path census a rig runs. Needs a\r\n  bounded lifecycle (per-run temp root reaped at run end, or a box-side sweep with a stated\r\n  retention), and the reap must state its count so a zero is a claim.\r\n- **Ripe when:** next kitsubito rig touch, or the between-milestone box-audit slot.\r\n- **Size:** small (one sweep script + adoption in the box's rig steps); the measurement rerun is\r\n  one `find | wc`.\r\n\r\n### IR-75 — traceable-reqs is not installed on kitsubito, so every Linux gate driver's treqs leg exits 127 (vacuous, wrapper-green shape)\r\n\r\n- **Status:** OPEN, filed by doyle 2026-08-30 at the #242/v0.66.0 close sweep (deployah\r\n  co-flagged at intake). · **Origin:** ASM-241 Linux battery — `ASM_treqs.exit` = 127, raw\r\n  `env: 'traceable-reqs': No such file or directory`; leg vacuous, covered that day by the\r\n  Windows treqs = 0 at the identical tree (treqs is a platform-independent text scan).\r\n- **What/why:** a 127 leg is exactly the wrapper-green shape [[IR-60]] documents — a driver that\r\n  doesn't read the exit FILE would report the leg green. Fix is either: install traceable-reqs on\r\n  kitsubito (then the leg is real), or DROP the leg from Linux gate drivers and state the\r\n  Windows-covers-it rule in the driver comment. Do NOT reopen [[IR-37]] for this — IR-37's\r\n  consume lane is spt-core CI (GitHub runners, green all week); this is BOX tooling, a different\r\n  surface (ruled at the sweep against the enumerating agent's overcautious flag).\r\n- **Ripe when:** next Linux gate-driver touch or kitsubito box-audit slot.\r\n- **Size:** trivial (install or one driver edit + comment).\r\n\r\n### IR-76 — hfenduleam is the golden Windows runner AND the builders' box: a local workspace nextest fully contained a golden Phase A and manufactured a load-timing red, and the job-start census cannot see it\r\n\r\n- **Status:** OPEN, filed by doyle 2026-09-06 during v0.67.1 golden triage (run 34017906638\r\n  att2). · **Origin:** the Windows Phase A red on\r\n  `spt-store::wtlock_two_process_int two_processes_commit_into_one_worktree_without_failing`\r\n  (B hit the 10 s worktree-lock bound while A's six serial commits took 13.5 s; 12 other\r\n  cells ran >10 s in the same phase). Load audit by todlando from his own `.raw`\r\n  CreationTimeUtc / `.exit` LastWriteTimeUtc: his #276 gate's 1240-cell workspace nextest\r\n  (`--no-fail-fast`, test phase 08:50:06–08:58:00Z) FULLY CONTAINED the golden Phase A\r\n  (08:52:38–08:56:49Z), every core saturated. He had been dispatched into that window and\r\n  never told the box was under a golden hold; perri and hertz had been.\r\n- **What/why:** two mechanisms, both unmeasured by anything in CI today. (1) The box is\r\n  shared by design — every agent's gate rig, adapter build and workspace nextest runs on the\r\n  same host as the self-hosted golden Windows runner, so a golden Windows leg is a QUIET\r\n  WINDOW only if every agent knows it is open; nothing says so, and a dispatch brief that\r\n  starts a gate is exactly how a builder lands inside it. (2) The job-start\r\n  `reap-census.ps1` counts the SPT FAMILY only (`family_total=12 scoped=0 unscoped=12` at\r\n  att2's 08:39:46Z start, with a builder's prebuild live on the box); cargo/nextest/rustc\r\n  load is outside its predicate, so the one instrument that runs at the right moment is\r\n  blind to the load that matters. Every load-timing red on Windows therefore triages as a\r\n  random victim with the cause off the record — the [[IR-63]] \"one random victim per sweep\"\r\n  face, now with a named source.\r\n- **Fix shape:** (a) driver templates (every gate/battery driver an agent authors here)\r\n  gain a PRE-FLIGHT leg with THREE outcomes, never two (todlando's amendment at filing: an\r\n  empty `gh run list` is the same bytes for CLEAR and for a broken meter — wrong filter,\r\n  expired token, rate limit, wrong repo default all return exit 0 and no rows — so a\r\n  two-arm guard fails OPEN into the exact hazard it guards, the `--commit <short-sha>`\r\n  confident-EMPTY class): run `gh run list --workflow golden --status in_progress`; rows\r\n  present -> HOLD, print the run id; no rows AND a positive control (`gh run list -L 1`\r\n  unfiltered, or `gh auth status`) returns a row -> CLEAR; control empty or erroring ->\r\n  REFUSE and say the meter is broken. A refusal, not a warning, so a wrapper-green shape\r\n  cannot swallow it ([[IR-60]]); the dispatch-brief line in (b) is likewise a MEASURED\r\n  clear with a live meter, never the absence of a sentence; (b) dispatch briefs that start a gate NAME the hold state of the box; (c)\r\n  the job-start census gains a second predicate — cargo/nextest/rustc/link processes by\r\n  image name, count + total CPU — reported beside the family count so a red's triage can\r\n  place foreign load from the log alone; (d) the golden hand-off contract\r\n  (docs/golden-head-intake) states the quiet-window rule once.\r\n- **Kin:** [[IR-63]] (random victim per sweep), [[IR-59]] (box conditions the preflights\r\n  never see), [[IR-64]] (hfenduleam's non-CI payload), FLAKE-LEDGER rows for\r\n  `wtlock_two_process_int` and `attach_link_push_e2e` (2026-09-06).\r\n- **Ripe when:** next driver-template touch (a/b are text; a is one leg), next `ci.yml`\r\n  touch for (c) — compose with [[IR-73]]'s reorders; (d) rides the next runbook edit.\r\n- **Size:** small — one pre-flight leg + one census predicate + two doc sentences.\r\n\r\n### IR-77 — nothing stamps the interval between a daemon child's spawn and the brain's first log line, so a readiness-deadline red cannot say WHERE the time went\r\n\r\n- **Status:** OPEN, filed by hertz 2026-09-07 from the W1 #249 kitsubito battery at the gated\r\n  sha `8d980fdf`; doyle-ruled at filing to be a register entry rather than a lane rider. ·\r\n  **Origin:** FLAKE-LEDGER `resident_service_e2e` :453 PRECONDITION (53 s) and\r\n  `resume_no_control_steal_e2e` (46 s), co-victims of ONE window — nextest exit 100, ONE\r\n  Summary `2999 tests run: 2997 passed (8 slow, 1 leaky), 2 failed, 1 skipped`. Evidence\r\n  preserved at `.spt/preserved/w1-kitsubito-8d980fdf/nextest.raw`, sha256\r\n  `9c456e21a6a0f75d8b0375ac648f232dba07f3887ec5e8dc232daef36253b51e`, hash-verified against\r\n  the kitsubito original.\r\n- **What/why:** both reds are a 45 s wait on `brain.ready` that expired, and the panel each\r\n  one prints shows the tree ALIVE — `BRAIN_UP`, `BRAIN_PHASE:announce done in 1ms`,\r\n  `BRAIN_PHASE:resume done in 0ms`, `SERVICE_STARTED` for both services, both later reaped\r\n  with an empty survivor set. So the daemon came up; it came up after the clock. WHERE those\r\n  45 s went is not recoverable from any artifact we keep: the first timestamped line in the\r\n  daemon's own sink is emitted by a process that has already started, and nothing stamps the\r\n  interval from the test's `Command::spawn` to it. The consequence is that every red of this\r\n  family is triaged by inference — v0.66.0 measured a ~10.1 s exe-hash on the ready path, and\r\n  that number is a CANDIDATE for the gap and can never be more than a candidate while the\r\n  interval is unmeasured. Remedy: one monotonic breadcrumb at daemon-child entry (before any\r\n  work), a second at the point `brain.ready` is stamped, both into the stderr sink the panel\r\n  already renders — then a red of this family reports its own split without a rerun.\r\n- **Kin:** [[IR-71]] (a seat release with no breadcrumb, same shape one layer over),\r\n  FLAKE-LEDGER `resident_service_e2e` :453 and `resume_no_control_steal_e2e` (2026-09-07),\r\n  and the HEAVY census stanza in `.config/nextest.toml`, which hardens the RECIPE these reds\r\n  came from and deliberately leaves the deadlines alone — a budget retune is the same race\r\n  with a different number, and it would also destroy the only signal this entry wants.\r\n- **Ripe when:** the next touch of the daemon boot path or of `brainproc`'s ready stamp; also\r\n  ripe as a rider on any lane that re-opens this test family.\r\n- **Size:** small — two `emit_line_err!` breadcrumbs and the sentence in the panel that says\r\n  what they mean.\r\n\r\n### IR-78 — `SPT_TEST_EPHEMERAL_ADVISORY_PORTS` silently overrides an explicitly set `SPT_DOCS_PORT`\r\n\r\n- **Status:** OPEN, filed by hertz 2026-09-07, MEASURED by doyle the same night on his W2\r\n  field pair (both boxes). · **Origin:** the 5474 rig-hygiene sweep in\r\n  `test/rig-advisory-ports-and-heavy-class`, which sets the rig flag at 37 `spt daemon run`\r\n  spawn sites.\r\n- **What/why:** `resolve_daemon_docs_port` (crates/spt-daemon/src/docshost.rs) returns `0`\r\n  whenever the rig flag is set, BEFORE the `SPT_DOCS_PORT` env override is consulted. With\r\n  both set, doyle's rig daemons took ephemeral ports (`DOCS_SERVER_UP` on 55369 Windows,\r\n  44015 Linux) while `SPT_DOCS_PORT=5480` was ignored without a word. The precedence itself is\r\n  defensible — the rig flag exists precisely so a test tree cannot take a well-known port —\r\n  but a SET override discarded in SILENCE is the shape IR-37 files under a different name: the\r\n  operator is left believing the value they set is the value in force. Remedy is a line, not a\r\n  redesign: emit one notice naming both env vars when the flag wins. No test cell is proposed\r\n  with it — none of the 31 swept binaries asserts on a docs port, so a cell here would assert\r\n  a behaviour nothing consumes.\r\n- **Kin:** [[IR-37]] (a set input silently ignored), the 5474 hygiene sweep, and the\r\n  `DOCS_SERVER_BIND_FAIL: port 5474: Address already in use (os error 98)` lines in\r\n  `.spt/preserved/w1-kitsubito-8d980fdf/nextest.raw` that started the sweep.\r\n- **NOT measured, stated so nobody reads it as covered:** doyle measured that the WMI\r\n  auto-start rung DOES carry the caller's environment (rig daemon pid 50088 on hfenduleam:\r\n  `DAEMON_LAUNCH_VIA_WMI`, its environ carrying `SPT_HOME`, `SPT_DOCS_PORT` and the rig flag\r\n  as his shell set them, `brain.ready` in the rig home). The schtasks (at-logon) rung was NOT\r\n  measured, and neither was the unix path.\r\n- **Ripe when:** the next `docshost.rs` touch, or the first time someone sets `SPT_DOCS_PORT`\r\n  on a rig and believes it.\r\n- **Size:** tiny — one emitted notice.\r\n\r\n### IR-79 — 22 of the 31 rig binaries leak their daemon tree on a failing assert: teardown is a statement, not a guard\r\n\r\n- **Status:** OPEN, filed by hertz 2026-09-07 on doyle's dispatch during PR #198's CI window,\r\n  from todlando's red 6 (a stale same-port daemon from his own previous run answering the next\r\n  one). · **Origin:** PR #198 moved 31 rigs to `SPT_TEST_EPHEMERAL_ADVISORY_PORTS=1`. Under an\r\n  ephemeral port a leaked daemon can no longer ANSWER the next run, so that PR is right as it\r\n  stands and this entry is not a defect in it; what remains is the orphan process itself — it pins\r\n  `spt.exe` (the Windows delete-and-rebuild hazard) and holds an `SPT_HOME` that nothing reaps. · **SCOPE BROADENED 07:20Z:** the title says \"on a failing\r\n  assert\" because that is the face it was filed from; the SECOND FACE bullet below shows the same\r\n  mechanism firing on a nextest TIMEOUT and leaking THREADS rather than a daemon. Read the title as\r\n  the handle, not the boundary — the trigger is any exit that does not reach the teardown statement.\r\n- **What/why:** measured over the 31, classifying each binary by whether its daemon teardown\r\n  survives a panic (a failing `assert!` unwinds, so only a guard or an ordering discipline saves\r\n  the child):\r\n  - **panic-safe, 9:** `impl Drop` guard — `endpoint_autostart_e2e`,\r\n    `knock_mutual_cross_node_e2e`, `twohost_cli`; `catch_unwind` teardown —\r\n    `activity_link_push_e2e`, `attach_link_push_e2e`, `wake_resume_bind_e2e`;\r\n    teardown-then-assert with zero exposed asserts — `endpoint_teardown_authority_e2e`,\r\n    `er_briefing_session_scoped_e2e`, `er_sequestered_cwd_e2e`.\r\n  - **leaks on a failing assert, 22** (exposed asserts / total asserts in the test body):\r\n    `projindex_writer_e2e` 21/21, `projindex_reader_e2e` 18/18,\r\n    `live_adapt_translation_swap_e2e` 15/38, `brain_split` 12/12,\r\n    `er_briefing_presented_e2e` 10/28, `rc_attach_truth` 8/29, `brain_respawn_rename` 6/6,\r\n    `dummy_harness_e2e` 4/11, `idle_edge_drain_e2e` 4/11, `multi_subnet_bringup_e2e` 4/20,\r\n    `bind_honest_cross_perch_e2e` 3/6, `idle_edge_seal_e2e` 3/17, `resident_service_e2e` 3/24,\r\n    `attach_wedge_e2e` 2/8, `bind_cwd_project_e2e` 2/8, `daemon_refresh_e2e` 2/11,\r\n    `er_brief_once_per_session_e2e` 2/13, `n1_pairing` 2/5, `resume_template_e2e` 2/10,\r\n    `run_no_dup_session_e2e` 2/14, `er_briefing_presentation_e2e` 1/4,\r\n    `livehost_bootgate_e2e` 1/3.\r\n  **FIRST WAVE of the Drop-guard generalization lane (doyle-ruled 2026-09-07, composed at the next\r\n  register sweep, not now): `projindex_writer_e2e`, `projindex_reader_e2e`, `brain_split`,\r\n  `brain_respawn_rename`.** These four expose EVERY assert they have — their teardown is the last\r\n  statement in the body, so any red at all leaks, which makes them both the worst cases and the\r\n  cleanest proofs that a guard works. The remedy already exists in this tree —\r\n  todlando's `DaemonReaper`, a `Drop` guard armed BEFORE the first CLI call — and the follow-up\r\n  lane is to generalise it into `crates/spt/tests/common` and adopt it at these 22 sites, which is\r\n  also the only shape that covers a `SIGKILL`-free timeout kill by nextest.\r\n- **METHOD, and its limits, so the count can be re-derived and challenged:** the classifier reads\r\n  each `#[test]` body, resolves file-local helper fns whose own body tears down (so a teardown\r\n  called through `sweep()` counts), and reports every `assert!`/`panic!` positioned before the LAST\r\n  teardown call in that body. It therefore (a) misses asserts written inline inside a closure or a\r\n  macro argument rather than at statement position, (b) treats the last teardown as THE teardown —\r\n  a partial earlier teardown still leaves the tree, so the true exposure is >= this count, and\r\n  (c) does not model `?` or early `return`. Spot-verified by hand on `resident_service_e2e`, whose\r\n  3 exposed asserts are real: they fire in the `wait_until` legs well before the `sweep()` at :435\r\n  that the \"── ASSERTIONS ──\" block follows.\r\n- **TONIGHT'S LIVE SAMPLE, so this is not an academic count (doyle's hfenduleam census 06:43Z):**\r\n  10 leaked `spt.exe` from todlando's pool, pairing by start time, from his pre-yield legs — a\r\n  single evening's rig work on one box. Each pins the binary against a rebuild and holds an\r\n  `SPT_HOME` nothing reaps.\r\n- **SECOND FACE — the same hazard in THREAD clothes, and it blocks the RUNNER, not just the box\r\n  (measured by todlando 07:17Z, relayed by doyle 07:20Z; I did not measure it myself and record it\r\n  as his testimony):** a nextest TIMEOUT on a `twohost_web` cell left the cell's child process\r\n  holding the broker + listener THREADS. Consequences, with his numbers:\r\n  - nextest itself blocked **14 minutes** at **0.61 CPU-seconds** — a wall-clock hang with\r\n    essentially no CPU, which is the signature of a parent waiting on a child's pipe rather than\r\n    of work being done;\r\n  - **`a.exit` was never written**, while **every verdict was already in `a.raw`** — so the leg\r\n    read as INCOMPLETE at the exact moment its results were complete. A reader who trusts the\r\n    exit file over the raw would call this a hung or failed leg and rerun it;\r\n  - **killing the path-verified orphan let the parent finish at once** — which is the causal test,\r\n    not a correlation: the kill is the intervention and the unblock is the response.\r\n  **Why it belongs in THIS entry rather than a new one:** the leaked thing is a thread inside a\r\n  child, not a daemon, but the mechanism is identical — a teardown that is a STATEMENT does not run\r\n  when the body does not reach it, and a timeout kill reaches the body even less reliably than a\r\n  panic does. The `Drop`-guard lane covers both faces with one remedy, which is doyle's ruling and\r\n  the reason no separate entry is opened. It also raises the lane's value: the daemon face costs a\r\n  pinned binary and an unreaped `SPT_HOME`, this face costs **14 minutes of a serialized golden\r\n  leg** and manufactures a false INCOMPLETE.\r\n  **Reading rule this hands the gate, worth stating because it is cheap:** when a leg's `.exit` is\r\n  missing, read the `.raw` for a Summary BEFORE concluding the leg hung — kin to\r\n  [[a-stopped-local-ssh-does-not-stop-its-remote-command]], where the raw was likewise the honest\r\n  record and the wrapper was not.\r\n- **Kin:** FLAKE-LEDGER `resident_service_e2e` :664 teardown LEAK row (3 occurrences, the Windows\r\n  face of the same class), [[IR-34]], [[IR-74]] (kitsubito's 21,643 `/tmp` endpoint homes — this is\r\n  one of the producers), and todlando's red 6.\r\n- **Ripe when:** the next lane that touches `crates/spt/tests/common` — the guard belongs there,\r\n  not copied 22 times.\r\n- **Size:** medium — one guard in `common`, then 22 mechanical adoptions, each provable by\r\n  panicking the body under a temporary test and watching the census go quiet.\r\n\r\n### IR-80 — five leaky cells on ONE module (`brainproc` / `supervise_brain`), Windows only: a candidate PRODUCT leak on the promotion/rollback path, or a cluster of names — nobody has looked yet\r\n\r\n- **Status:** OPEN, filed by hertz 2026-09-07 07:40Z on doyle's ruling (07:38Z) that this is its\r\n  OWN entry and **not** a third face of [[IR-79]] — IR-79 is rig teardown, this is a candidate\r\n  defect in the PRODUCT path, so its owner may be todlando rather than the rig lane. ·\r\n  **Origin:** noticed while measuring the #198 HEAVY scan-root gap ([[IR-37]] rider 2); the leak\r\n  roster was read out of the baseline golden log for an unrelated reason.\r\n- **⚠ WHAT THIS ENTRY IS, STATED FIRST SO IT IS NOT OVERREAD: a CLUSTER OF NAMES.** Five cells\r\n  that leaked share one module and one code path by their identifiers. Nothing has been measured\r\n  about WHAT is left alive, and a shared module is not a shared cause. Do not cite this as a\r\n  product defect until the census below has run.\r\n- **The observation, exact.** Golden run **34017906638**, sha `04e32c8c95cf`, both boxes, Phase A.\r\n  Windows (hfenduleam) reported **9 leaky** cells; Linux (kitsubito) **1** (`livehost::tests::\r\n  legacy_psyche_sweep_guard_is_id_specific_and_fail_safe`, unrelated). **Five of the Windows nine\r\n  are the same module:**\r\n\r\n  | cell | kind | time |\r\n  |---|---|---|\r\n  | `spt-daemon brainproc::tests::clear_before_spawn_defeats_exact_generation_stale_file` (:2200) | lib | 0.457s |\r\n  | `spt-daemon brainproc::tests::ready_but_old_gen_never_drains_does_not_promote_rolls_back` (:1834) | lib | 0.554s |\r\n  | `spt-daemon brainproc::tests::stale_generation_minus_one_ready_never_promotes` (:2155) | lib | 0.731s |\r\n  | `spt-daemon brainproc::tests::trial_kills_alive_never_ready_candidate_before_rollback` (:2109) | lib | 0.582s |\r\n  | `spt-daemon::false_promote ready_candidate_does_not_promote_until_the_wedged_old_gen_conn_drains` | int | 1.744s |\r\n\r\n  Denominator for the lib half: `brainproc`'s test module holds **26** `#[test]`/`#[tokio::test]`\r\n  cells, so **4 of 26 leaked, and all four are the trial/promote/rollback cells by name.** The\r\n  fifth is the integration rig that drives the same path.\r\n- **Why it is worth an entry even unmeasured:** four of the five are `kind(lib)`, so they run in\r\n  **`ci.yml` on every push**, not only in golden — if something really is left alive it is being\r\n  left alive on the shared Windows box many times a day. That is the same standing cost as\r\n  [[IR-79]]'s daemon face, arrived at from the opposite direction.\r\n- **HYPOTHESIS, labelled as such and NOT measured.** `supervise_brain` (:935) takes an injected\r\n  `spawn_child: impl FnMut(...) -> io::Result<Child>` (:941) and reaps candidates with bare\r\n  `let _ = child.kill();` at :998, :1015, :1055, :1071, :1081 — **`kill()` with no `wait()`.** On\r\n  Windows termination is asynchronous, and a killed-but-unreaped child can still hold the\r\n  inherited stdout/stderr pipe past the test's exit, which is exactly what nextest reports as\r\n  LEAK. The production spawner's own doc comment at :1190 states the intent — \"dies with no\r\n  orphaning. NOT `spawn_detached`\" — so if this is the mechanism, the code's intent and its\r\n  behaviour have diverged on one platform. **Every clause of this bullet is a reading of source,\r\n  not an observation of a live process. It may be entirely wrong.**\r\n- **FIRST MEASUREMENT — and doyle sharpened it 07:41Z from a census into a FALSIFIER, which is the\r\n  form to run:** on a free Windows box after W2, run\r\n  `trial_kills_alive_never_ready_candidate_before_rollback` **alone** and read one thing —\r\n  **is the killed pid still present, with the pipe handle open?** That is a yes/no against the\r\n  hypothesis above, not an open look at what happens to be running, and it is the difference\r\n  between a reading that settles the entry and a reading that produces more names. Capture pid,\r\n  image path and parent alongside the answer so a YES is immediately actionable, but the ANSWER is\r\n  the deliverable. One cell, one read. **Owner stays UNASSIGNED until it is taken** (doyle) — a\r\n  product path and a rig artifact are not distinguishable from here, and assigning before the read\r\n  would pick one by guess.\r\n- **Limits, so the entry cannot be overread:** nextest `LEAK` is **not a failure** — none of these\r\n  cells reds anything, and the run was green. Windows-only in **one** run; no trend established.\r\n  The clustering is by identifier and shared module, which is suggestive and is not causation.\r\n  I have not run any of these cells. Everything above is source plus one golden log — no box, no\r\n  build.\r\n- **Kin:** [[IR-79]] (children outliving the cell — the rig-teardown face of the same symptom, and\r\n  the reason doyle ruled these must stay SEPARATE: same symptom, different suspected owner),\r\n  [[IR-37]] rider 2 (the measurement that surfaced it), FLAKE-LEDGER's `resident_service_e2e` :664\r\n  teardown LEAK row.\r\n- **Ripe when:** the first free Windows box after W2 lands — it is a single-cell census, so it\r\n  fits any gap.\r\n- **Size:** unknown until the census. Tiny if it is a missing `wait()`; not tiny if the promotion\r\n  path leaves a real candidate brain alive on rollback.\r\n\r\n---\r\n\r\n#### THE LEAK SET IS NOISY — measured across three shas, 2026-09-07 (hertz)\r\n\r\n**This retracts the \"8 -> 5 leaky, direction favourable\" reading I flagged at 09:31Z.** It is not a\r\nfix and not an improvement; it is threshold noise, and the census this draft was built on inherits\r\nthat noise.\r\n\r\nWindows `ci` unit leg (`--workspace -E 'kind(lib) + kind(bin)'`), three consecutive shas:\r\n\r\n| cell | ff4b405d | e3bd53d4 | 401a19ad |\r\n|---|---|---|---|\r\n| brainproc::clear_before_spawn_defeats_exact_generation_stale_file | ● | ● | ● |\r\n| brainproc::ready_but_old_gen_never_drains_does_not_promote_rolls_back | ● | ● | ● |\r\n| brainproc::trial_kills_alive_never_ready_candidate_before_rollback | ● | ● | ● |\r\n| spt-runtime runtime::bounded_run_kills_on_timeout | ● | ● | ● |\r\n| brainproc::stale_generation_minus_one_ready_never_promotes | ● | ● | — |\r\n| spt-live digest::extractor_timeout_errors | ● | ● | — |\r\n| spt-live history::fetcher_timeout_errors | ● | ● | — |\r\n| spt-daemon broker::windows_session_is_zombie_sees_a_handle_held_corpse_as_dead | ● | — | — |\r\n| spt-daemon shellwake::kill_waker_at_still_kills_a_matching_pair | — | ● | ● |\r\n| **total** | **8** | **8** | **5** |\r\n\r\n**Causality check, which is what makes this a retraction rather than a hypothesis:** the three\r\ncommits between e3bd53d4 and 401a19ad touch **zero files** in brainproc, spt-live, spt-runtime,\r\nshellwake or broker (`git diff --name-only` over those paths returns nothing). The count fell by 3\r\nwith no change to any leaking module. So the drop cannot be a fix; the membership simply moves.\r\nNine cells appear in the union, only **four** are present at all three shas, and one\r\n(`shellwake::kill_waker_at`) *appeared* rather than vanished — a count that falls while a new member\r\njoins is the signature of a threshold, not of a repair.\r\n\r\n#### Three consequences for this draft\r\n\r\n1. **A count is not a quality signal here, in either direction.** Any future \"leaky went down\"\r\n   claim needs the NAME diff and a causality check against the changed files, or it is noise\r\n   reported as progress. I made exactly that error and it survived about twenty minutes.\r\n2. **The five-cell cluster is really \"three stable + one intermittent\".**\r\n   `stale_generation_minus_one_ready_never_promotes` is absent at 401a19ad. The cluster framing\r\n   still holds — three brainproc cells leak at every sha and they are all one module — but the\r\n   membership count must not be quoted as fixed.\r\n3. **doyle's falsifier beats my census, and this is the evidence.** The census (count the leaky\r\n   cells, name the cluster) is exactly what the noise destroys. His falsifier — *after\r\n   `trial_kills_alive_never_ready_candidate_before_rollback` on Windows, is the killed pid still\r\n   present with the pipe handle open?* — names ONE cell and probes a MECHANISM, and that cell is\r\n   **leaky at all three shas**, so it is the most stable target available. A mechanism probe is\r\n   immune to the threshold that moves the population. Owner stays UNASSIGNED until that read.\r\n\r\n#### One structural finding the noise does NOT touch\r\n**All nine union members spawn a child and then kill it, let it time out, or inspect its corpse** —\r\n`trial_kills_alive`, `kill_waker_at`, `bounded_run_kills_on_timeout`, `extractor_timeout_errors`,\r\n`fetcher_timeout_errors`, `windows_session_is_zombie_sees_a_handle_held_corpse_as_dead`, and the\r\nthree brainproc spawn/promote/rollback cells. Not one unrelated cell is in the set. Membership\r\nfluctuates; the *kind* of cell does not. That is a real signal about where child-process teardown\r\nis unreliable on Windows, and it is the same territory as [[ir79]] (rigs leaking daemons on a\r\nfailing assert) and [[ir81]] (kill scoping) — three drafts converging on one seam.\r\n\r\n---\r\n\r\n#### THE 12-CELL UNION — 4 shas x 2 OSes, membership beside the invariant (hertz, 2026-09-07 10:15Z)\r\n\r","truncated":true,"truncatedBy":"lines","totalLines":2162,"totalBytes":42702,"outputLines":524,"outputBytes":42702,"lastLinePartial":false,"firstLineExceedsLimit":false},"totalLines":5781,"displayContent":{"text":"### IR-69 — inherited stderr tokens can tear between format fragments; 26 test consumers parse that surface as structured truth\n…\n- **Status:** OPEN, product remedy complete and parked GREEN-AND-READY at `d0fdd58d` on\n…\n- **Mechanism, recovered from the literal torn bytes:** two daemon processes inherited one stderr\n…\n  handle once per format fragment; the per-process stderr lock cannot serialize the other process.\r\n  The observed interleave split the autostart token between `ENDPOINT_AUTOSTART:` and `gwauto`.\r\n  This is fragment-level cross-process interleaving, not a failed replay and not a two-thread race.\r\n- **Durable remedy, ruled product-side:** render a complete diagnostic line into one buffer and\r\n  issue the complete rendered text, newline included, as **ONE handle call**. An OS short-write\r\n  may retry the late tail so completeness wins over a silently truncated line; the deterministic\r\n  property pins application-side fragmentation, not syscall count under that rare retry. It makes\r\n  no claim that the OS write is atomic on Windows, and no CI re-fire against a 1-of-2 observation\r\n  may stand in for it. Widening one test's grep is refused: it greens one consumer while every\r\n  sibling token remains exposed.\r\n- **Cut-SHA census** (todlando generator, independently hash-verified by hertz), measured from\r\n  `4d6007ac4ee3d0991f4bc60b7e1a55825aad1aaf` via `git show`, not a dirty worktree:\r\n  **486 real emitter sites / 383 distinct tokens / 26 consumer test files**. The generator emitted\r\n  487 site rows, but one is a known phantom: `sealverb.rs:456` is a `format!` inside `map_err`\r\n  that the four-line lookback attributed to a neighbouring real `eprintln!`. Corrected real emitters\r\n  by crate: spt-daemon 270, spt 194, spt-runtime 8, spt-live 5, spt-net 5, spt-store 4; by macro:\r\n  `eprintln!` 484, `println!` 1, `eprint!` 1. `DRIVEN_BY` is the sole stdout row and therefore\r\n  outside the stderr remedy. A consumer means the test both mentions `TOKEN:` and reads a\r\n  stderr/log surface; bare-token matching inflated the population to 72 files by admitting prose.\r\n  This is an **exposure map**, not a rate and not a claim that all 26 have torn.\r\n- **Artifacts (the preserved raw generator outputs contain 487 site rows):** cut census SHA-256:\r\n  sites `f10d6bfe5e0399f98945cf63bb5719a01a62e1251be84165c73030fa9bb224f5`,\r\n  tokens `80b0d1835d9d46376b2f200b1c50be4ca0e185a135168444414255f9308ed92b`,\r\n  consumers `249a2e33df43a30570ca82b5bd200d8b6e2bf07aa8250fcc8bace47fe23e3cbc`.\r\n  The sealed sites file's macro column is wrong on 7 of its 487 raw rows; the corrected raw split\r\n  is `eprintln!` 485 / `println!` 1 / `eprint!` 1. The sealed tokens file has no final newline, so\r\n  `wc -l` reports 382 although it contains 383 logical records. The sealed files remain unedited;\r\n  these corrections are textual.\r\n  Generator `81df82f01ef33a82307920d9804a2394b787ef2ffbe3b41d2d7dda560d9a62a9`\r\n  was recorded as asserting newline-terminated output, but the sealed tokens artifact refutes that\r\n  claim for at least one output. Its remaining guards cover logical record counts, a known-positive\r\n  `SUBSCRIBE_DECISION` sentinel, four-line macro lookback, and truncation only at a\r\n  `#[cfg(test)]` that opens a module.\r\n- **Census hazards paid for while constructing and reconciling the population:** the provisional\r\n  instrument moved `277/243 → 286 → 412 → 487 raw → 486 real` as four silent assumptions were\r\n  found: same-line matching misses multi-line macros; truncating at the first `#[cfg(test)]` drops\r\n  later shipping code; lookback must prefer the token line's own macro over a neighbouring arm;\r\n  and even that lookback can promote a nested token literal beneath a real macro into a phantom\r\n  second site. A file without a final newline also makes `wc -l` silently undercount logical\r\n  records by one. Every future census must name its SHA, assert a known member, count records\r\n  inside the generator, and reconcile emitted rows to real sites.\r\n- **Separate anchored-matcher finding:** `IDLE`, `DISPATCH`, `BUSY`, and `BOUND` are common words\r\n  matched as substrings in exposed consumers. One-write emission does not prevent an unrelated log\r\n  line from satisfying them; those predicates need anchored token matching. Keep this separate from\r\n  the tear remedy so neither defect is claimed to close the other.\r\n- **Kin:** [[IR-50]] (the sink must be read before its absence means anything), [[IR-40]] (a\r\n  confident signal that does not describe the source truth), [[IR-8]] (a plausible census whose\r\n  blind spot returns a clean answer).\r\n- **CLOSE-OUT ADDENDUM 2026-08-30 (#242/v0.66.0 sweep — the entry's own close-out re-census RAN\r\n  and FOUND the predicted blind spot LIVE; entry stays OPEN):** re-census at the landed sha\r\n  `ec6da9b0` (independent containment-classified meter, reconciled with todlando's independent\r\n  meter — full write-up `EMISSION-RESIDUAL-CENSUS-FINDING.md`): the generator truncated\r\n  `crates/spt/src/cli.rs` at its FIRST module-opening `#[cfg(test)]` (line 3007, module closes\r\n  3164, file runs to 39118) and never scanned the rest — **338 TOKEN-shaped shipping sites remain\r\n  bare (332 colon-form, i.e. misses under the sealed census's own predicate, + 6 space-form)**,\r\n  plus `main.rs` 2 sites behind the same mechanism; exactly TWO files tree-wide carry the\r\n  triggering property (first module-opening cfg(test) precedes shipping code) — the generator\r\n  fix's owed blind-spot measurement, answered. The census-hazards bullet above already NAMES this\r\n  third-face truncation hazard; the module-opening fix narrowed the trigger and kept the blind\r\n  spot for files where a test module CLOSES and shipping resumes — IR-8 shape, predicted by this\r\n  entry's own text. The shipped #241 conversions are UNAFFECTED (495 removals ≈ censused 486 +\r\n  space family; the SEEN population is closed; golden green stands). Residual conversion +\r\n  generator fix + enforcement-at-the-seam = **releases#243** (BACKLOG, operator triages);\r\n  delivery.rs:149/313 are post-cut MINTS relative to the census sha (todlando's own, settled\r\n  attribution), deliberately outside #243's census-mechanism scope — and ALREADY CONVERTED: the\r\n  fix rode his breadcrumb branch (`60a12056`) into the r4 head and shipped IN-TAG (todlando\r\n  flagged the stale \"his thin lane converts post-cut\" claim 2026-08-30; re-measured — zero bare\r\n  TOKEN `eprintln!` in delivery.rs at both `d931dd63` and origin/main). No lane is owed for it. Re-runnable meter\r\n  `EMISSION-RESIDUAL-CENSUS-METER.py` (repo root, untracked; version-control rides #243's lane).\r\n  **Common-word matcher RULED at this sweep (discharges the \"decide\" clause below):** the four\r\n  common-word consumers (`IDLE`/`DISPATCH`/`BUSY`/`BOUND` substring predicates) get a SEPARATE\r\n  hertz test-side rider — anchored token matching is consumer-predicate work, NOT folded into\r\n  #243 (keeps #243 product-scoped) and not claimed closed by one-write emission; lane-link when\r\n  hertz's spool drains.\r\n- **Closes when:** releases#243's residual conversion + generator fix land and a re-census at\r\n  that sha reads zero shipping residue under both delimiter forms. **Size:** product lane\r\n  complete elsewhere; register follow-through small.\r\n\r\n### IR-70 — a hand-built `IoBus` silently omitted later sinks while every gate stayed green\r\n\r\n- **Status:** OPEN, remedy unscheduled; the v0.65.0 respin fixed the witnessed call site on PR #173.\r\n  This entry owns the recurrence class, not that shipped correction. · **Origin:** releases#234,\r\n  commit `c5459795167`, CONDUIT #236 respin.\r\n- **Mechanism:** `publish_commune_io` constructed `IoBus` itself and registered only the sink it\r\n  knew. `default_bus` already existed as the assembly point and its module contract explicitly says\r\n  emitters must know only `IoBus::publish`, so adding a later sink costs one registration rather\r\n  than an emitter sweep. The hand-built publisher recreated exactly the drift that contract warned\r\n  against: `COMMUNE` and `COMMUNE_FAIL` reached the old sink but never the adapter log, leaving\r\n  `spt api io-events` permanently short on two documented kinds.\r\n- **Why the complete battery was green:** the e2e was vacuous on the broken kinds; units synthesized\r\n  rows without traversing `publish_commune_io`; and traceability checked attached tags, not whether\r\n  the tagged path exercised the real publisher. Three green instruments shared one blind seam.\r\n  The respin routed the site through `crate::iobus::default_bus`, and its source comment now records\r\n  the failure shape.\r\n- **Durable remedy direction (todlando mechanism, not scheduled):** enforce the assembly point so\r\n  the next hand-built bus is impossible rather than found — make production publishers obtain the\r\n  composed bus through one construction API, and gate the real publish path for every documented\r\n  kind. A search or comment is not enforcement; another emitter can satisfy both while rebuilding\r\n  a partial sink list.\r\n- **Kin:** [[IR-39]] (a green fixture never reached the missing dependency), [[IR-37]]\r\n  (traceability tags prove coverage bookkeeping, not behavioral truth), [[IR-58]] (a hand-built\r\n  population returns an orderly but incomplete answer).\r\n- **Ripe when:** the next `IoBus` construction/API touch, or a new sink registration. **Size:**\r\n  small-to-medium assembly-point enforcement plus a real-path population test.\r\n\r\n### IR-71 — controller-seat release has no persisted breadcrumb, so tests cannot distinguish propagation lag from a missing detach\r\n\r\n- **Status:** OPEN, observability gap; no remedy scheduled. · **Origin:** CONDUIT #236 r3\r\n  `er_brief_once_per_session_e2e` intermittent, classified test-side and fixed on PR #174.\r\n- **What/why:** killing rc1 reaps the controller process, but the broker is another process and\r\n  notices the socket close later. On that detach edge it clears `driven_by` and `controlled` in\r\n  `info.json`; rc2's preflight reads that file locally and can race the write, refuse normally, and\r\n  exit 0 without dialing the broker. The test originally spawned rc2 immediately and had no\r\n  observable precondition separating “release is propagating” from “release never happened.”\r\n- **The missing surface:** broker lifecycle state records `session-detach was_controller=true`, but\r\n  there is no always-on persisted breadcrumb that states the controller stamp was cleared, names\r\n  the resulting `driven_by`/`controlled` state, or measures detach-to-persist latency. The repaired\r\n  test therefore polls `info.json` itself, prints elapsed time (0.075s on the first local real run),\r\n  and uses a named 60s timeout whose failure promotes the finding from timing to missing release.\r\n  Its deliberately latched-seat unit proves the barrier can red.\r\n- **Remedy direction:** add one structured release breadcrumb after the persisted clear, carrying\r\n  session/connection identity and the resulting control state; if latency is carried, measure it\r\n  from the detach edge. It must ride the persisted daemon sink and remain distinct from\r\n  `session-detach`, which proves the connection event but not the file write.\r\n- **Kin:** [[IR-50]] (the sink a test must actually read), [[IR-40]] (an event timestamp is not a\r\n  completion signal), REQ-HAZARD-CONTROL-STAMP-CONVERGENCE.\r\n- **Ripe when:** the next controller lifecycle or structured-breadcrumb touch, or a field timeout\r\n  from PR #174's barrier. **Size:** small emitter plus one contract-level assertion.\r\n\r\n### IR-72 — no product read verb surfaces which process holds a perch or controller seat\r\n\r\n- **Status:** OPEN, observability gap; no remedy scheduled. · **Origin:** CONDUIT #236 r3\r\n  two-host RCA and PR #174 (`70c1a303`), corrected by doyle after IR-18 and daemon-status were\r\n  ruled out as different classes.\r\n- **Source-verified boundary:** the holder identity already exists in durable/internal records\r\n  (`InfoJson.pid`, `parent_pid`, and the broker's session pid), and product internals read it for\r\n  liveness, teardown, and self-detection. No product **read verb** returns the process that holds a\r\n  named perch/seat. PID-bearing teardown messages are failure outcomes, not an inspection surface;\r\n  daemon status is process-wide, not perch- or seat-scoped. This also does not collapse into\r\n  [[IR-18]], where an existing internal `read_pid` collapses absent and unreadable records.\r\n- **Paid-for consequence 1 — rigs manufacture custody:** PR #174's two-host repair had to add\r\n  `PidHolder` in `crates/spt/tests/twohost_cli.rs:401-437`, spawn a long-lived sibling process,\r\n  write that pid directly into each synthetic perch, retain the child handle, and kill+wait it on\r\n  drop. The rig can make a known holder; it cannot ask the product which holder the product sees.\r\n- **Paid-for consequence 2 — ambiguity stayed latent until behavior flipped:** the r3 fixture\r\n  seeded three perches with one test-process pid. Self-detection then enumerated a directory whose\r\n  first matching row was a filesystem-order coin, so a green could name the wrong perch. The\r\n  repaired resolver refuses an ambiguous candidate set instead of guessing, and the fixture's\r\n  `assert_only_ancestor_candidate` now re-reads every `info.json` rig-side\r\n  (`twohost_cli.rs:439-457`). Refusal is enforcement, not observability: it proves a tie but still\r\n  offers no supported verb that names each holding process.\r\n- **Remedy direction:** add one machine-readable, named-perch inspection surface that reports the\r\n  custody fields the product actually used — holder pid and role/source (bind relay, stable harness\r\n  parent, brokered controller/session) — without asking callers to parse private `info.json` or\r\n  scan the process table. PID alone is recyclable; where a birth/image/session stamp exists, carry\r\n  it so the output does not become a new bare-pid oracle.\r\n- **Kin:** [[IR-18]] (read primitive loses error class, explicitly distinct), [[IR-71]] (release\r\n  completion lacks a persisted breadcrumb), REQ-HAZARD-SELF-DETECT-TIE (refuse ambiguous ancestry\r\n  rather than select by enumeration order).\r\n- **Ripe when:** the next roster/status read-model change or another rig needs to reap a named\r\n  holder. **Size:** small read-model/API addition, medium if seat and perch custody need separate\r\n  typed variants.\r\n\r\n### IR-73 — ci.yml and release.yml still read the free-space floor PRE-checkout (literal-first sites off the golden path); and any job's floor is stale by its last heavy step\r\n\r\n- **Status:** OPEN, filed by doyle 2026-08-30 at the #242/v0.66.0 close sweep (deployah flag\r\n  2026-08-29, widen lane). · **Origin:** the #242 cut lost two golden attempts to exactly this\r\n  REQ-CI-FREE-SPACE-PREFLIGHT trap on `golden.yml`'s n1-gate (floor read BEFORE checkout, so the\r\n  checkout's own cost lands after the assertion); `golden.yml` is fully reshaped (`ac7d2609`,\r\n  both jobs, checkout-protective reaps verified to stay pre-checkout) — but `ci.yml` (5 tagged\r\n  sites) and `release.yml` (3 tagged sites) keep the literal-first shape, deliberately NOT\r\n  widened off the back of a golden.yml-scoped ruling.\r\n- **What/why:** review each of the 8 sites' comments for checkout-protective purpose (the\r\n  `ac7d2609` method), then reorder the read after checkout or RECORD why not, per site. The\r\n  \"other jobs keep the literal-first shape\" clause is the trap's carrier: every un-reviewed site\r\n  is a queued golden-attempt loss on a loaded box.\r\n- **Second half (from #242 r4, same family):** a single job-start floor read is stale by the\r\n  job's LAST heavy step — the r4 LNK1318 low-water face recorded on [[IR-59]] (sixth face);\r\n  the within-job re-read before the docs-drift build rides the next workflow commit alongside\r\n  this entry's reorders.\r\n- **Kin:** [[IR-46]] (a floor asserts an instant), [[IR-59]] (full volume reds as a linker\r\n  defect), REQ-CI-FREE-SPACE-PREFLIGHT.\r\n- **Ripe when:** next touch of `ci.yml`/`release.yml`, or the next intake's tooling-rider slot\r\n  (compose with IR-59/IR-57's standing pair). · **Size:** small — reorder or comment per site,\r\n  8 sites.\r\n\r\n### IR-74 — kitsubito holds 21,643 /tmp endpoint homes: box-side accumulation nothing bounds or measures\r\n\r\n- **Status:** OPEN, filed by doyle 2026-08-30 at the #242/v0.66.0 close sweep; measurement by\r\n  hertz (2026-08-29). · **Origin:** rig work on kitsubito found `/tmp` carrying 21,643 endpoint\r\n  homes — per-run spt homes that outlive their runs.\r\n- **What/why:** sibling of the [[IR-31]]/[[IR-59]]/[[IR-64]] family (box accumulation the\r\n  preflights never see): each is small, the population is not, and /tmp on a long-lived box is\r\n  never reaped by CI. Un-reaped homes also widen every by-path census a rig runs. Needs a\r\n  bounded lifecycle (per-run temp root reaped at run end, or a box-side sweep with a stated\r\n  retention), and the reap must state its count so a zero is a claim.\r\n- **Ripe when:** next kitsubito rig touch, or the between-milestone box-audit slot.\r\n- **Size:** small (one sweep script + adoption in the box's rig steps); the measurement rerun is\r\n  one `find | wc`.\r\n\r\n### IR-75 — traceable-reqs is not installed on kitsubito, so every Linux gate driver's treqs leg exits 127 (vacuous, wrapper-green shape)\r\n\r\n- **Status:** OPEN, filed by doyle 2026-08-30 at the #242/v0.66.0 close sweep (deployah\r\n  co-flagged at intake). · **Origin:** ASM-241 Linux battery — `ASM_treqs.exit` = 127, raw\r\n  `env: 'traceable-reqs': No such file or directory`; leg vacuous, covered that day by the\r\n  Windows treqs = 0 at the identical tree (treqs is a platform-independent text scan).\r\n- **What/why:** a 127 leg is exactly the wrapper-green shape [[IR-60]] documents — a driver that\r\n  doesn't read the exit FILE would report the leg green. Fix is either: install traceable-reqs on\r\n  kitsubito (then the leg is real), or DROP the leg from Linux gate drivers and state the\r\n  Windows-covers-it rule in the driver comment. Do NOT reopen [[IR-37]] for this — IR-37's\r\n  consume lane is spt-core CI (GitHub runners, green all week); this is BOX tooling, a different\r\n  surface (ruled at the sweep against the enumerating agent's overcautious flag).\r\n- **Ripe when:** next Linux gate-driver touch or kitsubito box-audit slot.\r\n- **Size:** trivial (install or one driver edit + comment).\r\n\r\n### IR-76 — hfenduleam is the golden Windows runner AND the builders' box: a local workspace nextest fully contained a golden Phase A and manufactured a load-timing red, and the job-start census cannot see it\r\n\r\n- **Status:** OPEN, filed by doyle 2026-09-06 during v0.67.1 golden triage (run 34017906638\r\n  att2). · **Origin:** the Windows Phase A red on\r\n  `spt-store::wtlock_two_process_int two_processes_commit_into_one_worktree_without_failing`\r\n  (B hit the 10 s worktree-lock bound while A's six serial commits took 13.5 s; 12 other\r\n  cells ran >10 s in the same phase). Load audit by todlando from his own `.raw`\r\n  CreationTimeUtc / `.exit` LastWriteTimeUtc: his #276 gate's 1240-cell workspace nextest\r\n  (`--no-fail-fast`, test phase 08:50:06–08:58:00Z) FULLY CONTAINED the golden Phase A\r\n  (08:52:38–08:56:49Z), every core saturated. He had been dispatched into that window and\r\n  never told the box was under a golden hold; perri and hertz had been.\r\n- **What/why:** two mechanisms, both unmeasured by anything in CI today. (1) The box is\r\n  shared by design — every agent's gate rig, adapter build and workspace nextest runs on the\r\n  same host as the self-hosted golden Windows runner, so a golden Windows leg is a QUIET\r\n  WINDOW only if every agent knows it is open; nothing says so, and a dispatch brief that\r\n  starts a gate is exactly how a builder lands inside it. (2) The job-start\r\n  `reap-census.ps1` counts the SPT FAMILY only (`family_total=12 scoped=0 unscoped=12` at\r\n  att2's 08:39:46Z start, with a builder's prebuild live on the box); cargo/nextest/rustc\r\n  load is outside its predicate, so the one instrument that runs at the right moment is\r\n  blind to the load that matters. Every load-timing red on Windows therefore triages as a\r\n  random victim with the cause off the record — the [[IR-63]] \"one random victim per sweep\"\r\n  face, now with a named source.\r\n- **Fix shape:** (a) driver templates (every gate/battery driver an agent authors here)\r\n  gain a PRE-FLIGHT leg with THREE outcomes, never two (todlando's amendment at filing: an\r\n  empty `gh run list` is the same bytes for CLEAR and for a broken meter — wrong filter,\r\n  expired token, rate limit, wrong repo default all return exit 0 and no rows — so a\r\n  two-arm guard fails OPEN into the exact hazard it guards, the `--commit <short-sha>`\r\n  confident-EMPTY class): run `gh run list --workflow golden --status in_progress`; rows\r\n  present -> HOLD, print the run id; no rows AND a positive control (`gh run list -L 1`\r\n  unfiltered, or `gh auth status`) returns a row -> CLEAR; control empty or erroring ->\r\n  REFUSE and say the meter is broken. A refusal, not a warning, so a wrapper-green shape\r\n  cannot swallow it ([[IR-60]]); the dispatch-brief line in (b) is likewise a MEASURED\r\n  clear with a live meter, never the absence of a sentence; (b) dispatch briefs that start a gate NAME the hold state of the box; (c)\r\n  the job-start census gains a second predicate — cargo/nextest/rustc/link processes by\r\n  image name, count + total CPU — reported beside the family count so a red's triage can\r\n  place foreign load from the log alone; (d) the golden hand-off contract\r\n  (docs/golden-head-intake) states the quiet-window rule once.\r\n- **Kin:** [[IR-63]] (random victim per sweep), [[IR-59]] (box conditions the preflights\r\n  never see), [[IR-64]] (hfenduleam's non-CI payload), FLAKE-LEDGER rows for\r\n  `wtlock_two_process_int` and `attach_link_push_e2e` (2026-09-06).\r\n- **Ripe when:** next driver-template touch (a/b are text; a is one leg), next `ci.yml`\r\n  touch for (c) — compose with [[IR-73]]'s reorders; (d) rides the next runbook edit.\r\n- **Size:** small — one pre-flight leg + one census predicate + two doc sentences.\r\n\r\n### IR-77 — nothing stamps the interval between a daemon child's spawn and the brain's first log line, so a readiness-deadline red cannot say WHERE the time went\r\n\r\n- **Status:** OPEN, filed by hertz 2026-09-07 from the W1 #249 kitsubito battery at the gated\r\n  sha `8d980fdf`; doyle-ruled at filing to be a register entry rather than a lane rider. ·\r\n  **Origin:** FLAKE-LEDGER `resident_service_e2e` :453 PRECONDITION (53 s) and\r\n  `resume_no_control_steal_e2e` (46 s), co-victims of ONE window — nextest exit 100, ONE\r\n  Summary `2999 tests run: 2997 passed (8 slow, 1 leaky), 2 failed, 1 skipped`. Evidence\r\n  preserved at `.spt/preserved/w1-kitsubito-8d980fdf/nextest.raw`, sha256\r\n  `9c456e21a6a0f75d8b0375ac648f232dba07f3887ec5e8dc232daef36253b51e`, hash-verified against\r\n  the kitsubito original.\r\n- **What/why:** both reds are a 45 s wait on `brain.ready` that expired, and the panel each\r\n  one prints shows the tree ALIVE — `BRAIN_UP`, `BRAIN_PHASE:announce done in 1ms`,\r\n  `BRAIN_PHASE:resume done in 0ms`, `SERVICE_STARTED` for both services, both later reaped\r\n  with an empty survivor set. So the daemon came up; it came up after the clock. WHERE those\r\n  45 s went is not recoverable from any artifact we keep: the first timestamped line in the\r\n  daemon's own sink is emitted by a process that has already started, and nothing stamps the\r\n  interval from the test's `Command::spawn` to it. The consequence is that every red of this\r\n  family is triaged by inference — v0.66.0 measured a ~10.1 s exe-hash on the ready path, and\r\n  that number is a CANDIDATE for the gap and can never be more than a candidate while the\r\n  interval is unmeasured. Remedy: one monotonic breadcrumb at daemon-child entry (before any\r\n  work), a second at the point `brain.ready` is stamped, both into the stderr sink the panel\r\n  already renders — then a red of this family reports its own split without a rerun.\r\n- **Kin:** [[IR-71]] (a seat release with no breadcrumb, same shape one layer over),\r\n  FLAKE-LEDGER `resident_service_e2e` :453 and `resume_no_control_steal_e2e` (2026-09-07),\r\n  and the HEAVY census stanza in `.config/nextest.toml`, which hardens the RECIPE these reds\r\n  came from and deliberately leaves the deadlines alone — a budget retune is the same race\r\n  with a different number, and it would also destroy the only signal this entry wants.\r\n- **Ripe when:** the next touch of the daemon boot path or of `brainproc`'s ready stamp; also\r\n  ripe as a rider on any lane that re-opens this test family.\r\n- **Size:** small — two `emit_line_err!` breadcrumbs and the sentence in the panel that says\r\n  what they mean.\r\n\r\n### IR-78 — `SPT_TEST_EPHEMERAL_ADVISORY_PORTS` silently overrides an explicitly set `SPT_DOCS_PORT`\r\n\r\n- **Status:** OPEN, filed by hertz 2026-09-07, MEASURED by doyle the same night on his W2\r\n  field pair (both boxes). · **Origin:** the 5474 rig-hygiene sweep in\r\n  `test/rig-advisory-ports-and-heavy-class`, which sets the rig flag at 37 `spt daemon run`\r\n  spawn sites.\r\n- **What/why:** `resolve_daemon_docs_port` (crates/spt-daemon/src/docshost.rs) returns `0`\r\n  whenever the rig flag is set, BEFORE the `SPT_DOCS_PORT` env override is consulted. With\r\n  both set, doyle's rig daemons took ephemeral ports (`DOCS_SERVER_UP` on 55369 Windows,\r\n  44015 Linux) while `SPT_DOCS_PORT=5480` was ignored without a word. The precedence itself is\r\n  defensible — the rig flag exists precisely so a test tree cannot take a well-known port —\r\n  but a SET override discarded in SILENCE is the shape IR-37 files under a different name: the\r\n  operator is left believing the value they set is the value in force. Remedy is a line, not a\r\n  redesign: emit one notice naming both env vars when the flag wins. No test cell is proposed\r\n  with it — none of the 31 swept binaries asserts on a docs port, so a cell here would assert\r\n  a behaviour nothing consumes.\r\n- **Kin:** [[IR-37]] (a set input silently ignored), the 5474 hygiene sweep, and the\r\n  `DOCS_SERVER_BIND_FAIL: port 5474: Address already in use (os error 98)` lines in\r\n  `.spt/preserved/w1-kitsubito-8d980fdf/nextest.raw` that started the sweep.\r\n- **NOT measured, stated so nobody reads it as covered:** doyle measured that the WMI\r\n  auto-start rung DOES carry the caller's environment (rig daemon pid 50088 on hfenduleam:\r\n  `DAEMON_LAUNCH_VIA_WMI`, its environ carrying `SPT_HOME`, `SPT_DOCS_PORT` and the rig flag\r\n  as his shell set them, `brain.ready` in the rig home). The schtasks (at-logon) rung was NOT\r\n  measured, and neither was the unix path.\r\n- **Ripe when:** the next `docshost.rs` touch, or the first time someone sets `SPT_DOCS_PORT`\r\n  on a rig and believes it.\r\n- **Size:** tiny — one emitted notice.\r\n\r\n### IR-79 — 22 of the 31 rig binaries leak their daemon tree on a failing assert: teardown is a statement, not a guard\r\n\r\n- **Status:** OPEN, filed by hertz 2026-09-07 on doyle's dispatch during PR #198's CI window,\r\n  from todlando's red 6 (a stale same-port daemon from his own previous run answering the next\r\n  one). · **Origin:** PR #198 moved 31 rigs to `SPT_TEST_EPHEMERAL_ADVISORY_PORTS=1`. Under an\r\n  ephemeral port a leaked daemon can no longer ANSWER the next run, so that PR is right as it\r\n  stands and this entry is not a defect in it; what remains is the orphan process itself — it pins\r\n  `spt.exe` (the Windows delete-and-rebuild hazard) and holds an `SPT_HOME` that nothing reaps. · **SCOPE BROADENED 07:20Z:** the title says \"on a failing\r\n  assert\" because that is the face it was filed from; the SECOND FACE bullet below shows the same\r\n  mechanism firing on a nextest TIMEOUT and leaking THREADS rather than a daemon. Read the title as\r\n  the handle, not the boundary — the trigger is any exit that does not reach the teardown statement.\r\n- **What/why:** measured over the 31, classifying each binary by whether its daemon teardown\r\n  survives a panic (a failing `assert!` unwinds, so only a guard or an ordering discipline saves\r\n  the child):\r\n  - **panic-safe, 9:** `impl Drop` guard — `endpoint_autostart_e2e`,\r\n    `knock_mutual_cross_node_e2e`, `twohost_cli`; `catch_unwind` teardown —\r\n    `activity_link_push_e2e`, `attach_link_push_e2e`, `wake_resume_bind_e2e`;\r\n    teardown-then-assert with zero exposed asserts — `endpoint_teardown_authority_e2e`,\r\n    `er_briefing_session_scoped_e2e`, `er_sequestered_cwd_e2e`.\r\n  - **leaks on a failing assert, 22** (exposed asserts / total asserts in the test body):\r\n    `projindex_writer_e2e` 21/21, `projindex_reader_e2e` 18/18,\r\n    `live_adapt_translation_swap_e2e` 15/38, `brain_split` 12/12,\r\n    `er_briefing_presented_e2e` 10/28, `rc_attach_truth` 8/29, `brain_respawn_rename` 6/6,\r\n    `dummy_harness_e2e` 4/11, `idle_edge_drain_e2e` 4/11, `multi_subnet_bringup_e2e` 4/20,\r\n    `bind_honest_cross_perch_e2e` 3/6, `idle_edge_seal_e2e` 3/17, `resident_service_e2e` 3/24,\r\n    `attach_wedge_e2e` 2/8, `bind_cwd_project_e2e` 2/8, `daemon_refresh_e2e` 2/11,\r\n    `er_brief_once_per_session_e2e` 2/13, `n1_pairing` 2/5, `resume_template_e2e` 2/10,\r\n    `run_no_dup_session_e2e` 2/14, `er_briefing_presentation_e2e` 1/4,\r\n    `livehost_bootgate_e2e` 1/3.\r\n  **FIRST WAVE of the Drop-guard generalization lane (doyle-ruled 2026-09-07, composed at the next\r\n  register sweep, not now): `projindex_writer_e2e`, `projindex_reader_e2e`, `brain_split`,\r\n  `brain_respawn_rename`.** These four expose EVERY assert they have — their teardown is the last\r\n  statement in the body, so any red at all leaks, which makes them both the worst cases and the\r\n  cleanest proofs that a guard works. The remedy already exists in this tree —\r\n  todlando's `DaemonReaper`, a `Drop` guard armed BEFORE the first CLI call — and the follow-up\r\n  lane is to generalise it into `crates/spt/tests/common` and adopt it at these 22 sites, which is\r\n  also the only shape that covers a `SIGKILL`-free timeout kill by nextest.\r\n- **METHOD, and its limits, so the count can be re-derived and challenged:** the classifier reads\r\n  each `#[test]` body, resolves file-local helper fns whose own body tears down (so a teardown\r\n  called through `sweep()` counts), and reports every `assert!`/`panic!` positioned before the LAST\r\n  teardown call in that body. It therefore (a) misses asserts written inline inside a closure or a\r\n  macro argument rather than at statement position, (b) treats the last teardown as THE teardown —\r\n  a partial earlier teardown still leaves the tree, so the true exposure is >= this count, and\r\n  (c) does not model `?` or early `return`. Spot-verified by hand on `resident_service_e2e`, whose\r\n  3 exposed asserts are real: they fire in the `wait_until` legs well before the `sweep()` at :435\r\n  that the \"── ASSERTIONS ──\" block follows.\r\n- **TONIGHT'S LIVE SAMPLE, so this is not an academic count (doyle's hfenduleam census 06:43Z):**\r\n  10 leaked `spt.exe` from todlando's pool, pairing by start time, from his pre-yield legs — a\r\n  single evening's rig work on one box. Each pins the binary against a rebuild and holds an\r\n  `SPT_HOME` nothing reaps.\r\n- **SECOND FACE — the same hazard in THREAD clothes, and it blocks the RUNNER, not just the box\r\n  (measured by todlando 07:17Z, relayed by doyle 07:20Z; I did not measure it myself and record it\r\n  as his testimony):** a nextest TIMEOUT on a `twohost_web` cell left the cell's child process\r\n  holding the broker + listener THREADS. Consequences, with his numbers:\r\n  - nextest itself blocked **14 minutes** at **0.61 CPU-seconds** — a wall-clock hang with\r\n    essentially no CPU, which is the signature of a parent waiting on a child's pipe rather than\r\n    of work being done;\r\n  - **`a.exit` was never written**, while **every verdict was already in `a.raw`** — so the leg\r\n    read as INCOMPLETE at the exact moment its results were complete. A reader who trusts the\r\n    exit file over the raw would call this a hung or failed leg and rerun it;\r\n  - **killing the path-verified orphan let the parent finish at once** — which is the causal test,\r\n    not a correlation: the kill is the intervention and the unblock is the response.\r\n  **Why it belongs in THIS entry rather than a new one:** the leaked thing is a thread inside a\r\n  child, not a daemon, but the mechanism is identical — a teardown that is a STATEMENT does not run\r\n  when the body does not reach it, and a timeout kill reaches the body even less reliably than a\r\n  panic does. The `Drop`-guard lane covers both faces with one remedy, which is doyle's ruling and\r\n  the reason no separate entry is opened. It also raises the lane's value: the daemon face costs a\r\n  pinned binary and an unreaped `SPT_HOME`, this face costs **14 minutes of a serialized golden\r\n  leg** and manufactures a false INCOMPLETE.\r\n  **Reading rule this hands the gate, worth stating because it is cheap:** when a leg's `.exit` is\r\n  missing, read the `.raw` for a Summary BEFORE concluding the leg hung — kin to\r\n  [[a-stopped-local-ssh-does-not-stop-its-remote-command]], where the raw was likewise the honest\r\n  record and the wrapper was not.\r\n- **Kin:** FLAKE-LEDGER `resident_service_e2e` :664 teardown LEAK row (3 occurrences, the Windows\r\n  face of the same class), [[IR-34]], [[IR-74]] (kitsubito's 21,643 `/tmp` endpoint homes — this is\r\n  one of the producers), and todlando's red 6.\r\n- **Ripe when:** the next lane that touches `crates/spt/tests/common` — the guard belongs there,\r\n  not copied 22 times.\r\n- **Size:** medium — one guard in `common`, then 22 mechanical adoptions, each provable by\r\n  panicking the body under a temporary test and watching the census go quiet.\r\n\r\n### IR-80 — five leaky cells on ONE module (`brainproc` / `supervise_brain`), Windows only: a candidate PRODUCT leak on the promotion/rollback path, or a cluster of names — nobody has looked yet\r\n\r\n- **Status:** OPEN, filed by hertz 2026-09-07 07:40Z on doyle's ruling (07:38Z) that this is its\r\n  OWN entry and **not** a third face of [[IR-79]] — IR-79 is rig teardown, this is a candidate\r\n  defect in the PRODUCT path, so its owner may be todlando rather than the rig lane. ·\r\n  **Origin:** noticed while measuring the #198 HEAVY scan-root gap ([[IR-37]] rider 2); the leak\r\n  roster was read out of the baseline golden log for an unrelated reason.\r\n- **⚠ WHAT THIS ENTRY IS, STATED FIRST SO IT IS NOT OVERREAD: a CLUSTER OF NAMES.** Five cells\r\n  that leaked share one module and one code path by their identifiers. Nothing has been measured\r\n  about WHAT is left alive, and a shared module is not a shared cause. Do not cite this as a\r\n  product defect until the census below has run.\r\n- **The observation, exact.** Golden run **34017906638**, sha `04e32c8c95cf`, both boxes, Phase A.\r\n  Windows (hfenduleam) reported **9 leaky** cells; Linux (kitsubito) **1** (`livehost::tests::\r\n  legacy_psyche_sweep_guard_is_id_specific_and_fail_safe`, unrelated). **Five of the Windows nine\r\n  are the same module:**\r\n\r\n  | cell | kind | time |\r\n  |---|---|---|\r\n  | `spt-daemon brainproc::tests::clear_before_spawn_defeats_exact_generation_stale_file` (:2200) | lib | 0.457s |\r\n  | `spt-daemon brainproc::tests::ready_but_old_gen_never_drains_does_not_promote_rolls_back` (:1834) | lib | 0.554s |\r\n  | `spt-daemon brainproc::tests::stale_generation_minus_one_ready_never_promotes` (:2155) | lib | 0.731s |\r\n  | `spt-daemon brainproc::tests::trial_kills_alive_never_ready_candidate_before_rollback` (:2109) | lib | 0.582s |\r\n  | `spt-daemon::false_promote ready_candidate_does_not_promote_until_the_wedged_old_gen_conn_drains` | int | 1.744s |\r\n\r\n  Denominator for the lib half: `brainproc`'s test module holds **26** `#[test]`/`#[tokio::test]`\r\n  cells, so **4 of 26 leaked, and all four are the trial/promote/rollback cells by name.** The\r\n  fifth is the integration rig that drives the same path.\r\n- **Why it is worth an entry even unmeasured:** four of the five are `kind(lib)`, so they run in\r\n  **`ci.yml` on every push**, not only in golden — if something really is left alive it is being\r\n  left alive on the shared Windows box many times a day. That is the same standing cost as\r\n  [[IR-79]]'s daemon face, arrived at from the opposite direction.\r\n- **HYPOTHESIS, labelled as such and NOT measured.** `supervise_brain` (:935) takes an injected\r\n  `spawn_child: impl FnMut(...) -> io::Result<Child>` (:941) and reaps candidates with bare\r\n  `let _ = child.kill();` at :998, :1015, :1055, :1071, :1081 — **`kill()` with no `wait()`.** On\r\n  Windows termination is asynchronous, and a killed-but-unreaped child can still hold the\r\n  inherited stdout/stderr pipe past the test's exit, which is exactly what nextest reports as\r\n  LEAK. The production spawner's own doc comment at :1190 states the intent — \"dies with no\r\n  orphaning. NOT `spawn_detached`\" — so if this is the mechanism, the code's intent and its\r\n  behaviour have diverged on one platform. **Every clause of this bullet is a reading of source,\r\n  not an observation of a live process. It may be entirely wrong.**\r\n- **FIRST MEASUREMENT — and doyle sharpened it 07:41Z from a census into a FALSIFIER, which is the\r\n  form to run:** on a free Windows box after W2, run\r\n  `trial_kills_alive_never_ready_candidate_before_rollback` **alone** and read one thing —\r\n  **is the killed pid still present, with the pipe handle open?** That is a yes/no against the\r\n  hypothesis above, not an open look at what happens to be running, and it is the difference\r\n  between a reading that settles the entry and a reading that produces more names. Capture pid,\r\n  image path and parent alongside the answer so a YES is immediately actionable, but the ANSWER is\r\n  the deliverable. One cell, one read. **Owner stays UNASSIGNED until it is taken** (doyle) — a\r\n  product path and a rig artifact are not distinguishable from here, and assigning before the read\r\n  would pick one by guess.\r\n- **Limits, so the entry cannot be overread:** nextest `LEAK` is **not a failure** — none of these\r\n  cells reds anything, and the run was green. Windows-only in **one** run; no trend established.\r\n  The clustering is by identifier and shared module, which is suggestive and is not causation.\r\n  I have not run any of these cells. Everything above is source plus one golden log — no box, no\r\n  build.\r\n- **Kin:** [[IR-79]] (children outliving the cell — the rig-teardown face of the same symptom, and\r\n  the reason doyle ruled these must stay SEPARATE: same symptom, different suspected owner),\r\n  [[IR-37]] rider 2 (the measurement that surfaced it), FLAKE-LEDGER's `resident_service_e2e` :664\r\n  teardown LEAK row.\r\n- **Ripe when:** the first free Windows box after W2 lands — it is a single-cell census, so it\r\n  fits any gap.\r\n- **Size:** unknown until the census. Tiny if it is a missing `wait()`; not tiny if the promotion\r\n  path leaves a real candidate brain alive on rollback.\r\n\r\n---\r\n\r\n#### THE LEAK SET IS NOISY — measured across three shas, 2026-09-07 (hertz)\r\n\r\n**This retracts the \"8 -> 5 leaky, direction favourable\" reading I flagged at 09:31Z.** It is not a\r\nfix and not an improvement; it is threshold noise, and the census this draft was built on inherits\r\nthat noise.\r\n\r\nWindows `ci` unit leg (`--workspace -E 'kind(lib) + kind(bin)'`), three consecutive shas:\r\n\r\n| cell | ff4b405d | e3bd53d4 | 401a19ad |\r\n|---|---|---|---|\r\n| brainproc::clear_before_spawn_defeats_exact_generation_stale_file | ● | ● | ● |\r\n| brainproc::ready_but_old_gen_never_drains_does_not_promote_rolls_back | ● | ● | ● |\r\n| brainproc::trial_kills_alive_never_ready_candidate_before_rollback | ● | ● | ● |\r\n| spt-runtime runtime::bounded_run_kills_on_timeout | ● | ● | ● |\r\n| brainproc::stale_generation_minus_one_ready_never_promotes | ● | ● | — |\r\n| spt-live digest::extractor_timeout_errors | ● | ● | — |\r\n| spt-live history::fetcher_timeout_errors | ● | ● | — |\r\n| spt-daemon broker::windows_session_is_zombie_sees_a_handle_held_corpse_as_dead | ● | — | — |\r\n| spt-daemon shellwake::kill_waker_at_still_kills_a_matching_pair | — | ● | ● |\r\n| **total** | **8** | **8** | **5** |\r\n\r\n**Causality check, which is what makes this a retraction rather than a hypothesis:** the three\r\ncommits between e3bd53d4 and 401a19ad touch **zero files** in brainproc, spt-live, spt-runtime,\r\nshellwake or broker (`git diff --name-only` over those paths returns nothing). The count fell by 3\r\nwith no change to any leaking module. So the drop cannot be a fix; the membership simply moves.\r\nNine cells appear in the union, only **four** are present at all three shas, and one\r\n(`shellwake::kill_waker_at`) *appeared* rather than vanished — a count that falls while a new member\r\njoins is the signature of a threshold, not of a repair.\r\n\r\n#### Three consequences for this draft\r\n\r\n1. **A count is not a quality signal here, in either direction.** Any future \"leaky went down\"\r\n   claim needs the NAME diff and a causality check against the changed files, or it is noise\r\n   reported as progress. I made exactly that error and it survived about twenty minutes.\r\n2. **The five-cell cluster is really \"three stable + one intermittent\".**\r\n   `stale_generation_minus_one_ready_never_promotes` is absent at 401a19ad. The cluster framing\r\n   still holds — three brainproc cells leak at every sha and they are all one module — but the\r\n   membership count must not be quoted as fixed.\r\n3. **doyle's falsifier beats my census, and this is the evidence.** The census (count the leaky\r\n   cells, name the cluster) is exactly what the noise destroys. His falsifier — *after\r\n   `trial_kills_alive_never_ready_candidate_before_rollback` on Windows, is the killed pid still\r\n   present with the pipe handle open?* — names ONE cell and probes a MECHANISM, and that cell is\r\n   **leaky at all three shas**, so it is the most stable target available. A mechanism probe is\r\n   immune to the threshold that moves the population. Owner stays UNASSIGNED until that read.\r\n\r\n#### One structural finding the noise does NOT touch\r\n**All nine union members spawn a child and then kill it, let it time out, or inspect its corpse** —\r\n`trial_kills_alive`, `kill_waker_at`, `bounded_run_kills_on_timeout`, `extractor_timeout_errors`,\r\n`fetcher_timeout_errors`, `windows_session_is_zombie_sees_a_handle_held_corpse_as_dead`, and the\r\nthree brainproc spawn/promote/rollback cells. Not one unrelated cell is in the set. Membership\r\nfluctuates; the *kind* of cell does not. That is a real signal about where child-process teardown\r\nis unreliable on Windows, and it is the same territory as [[ir79]] (rigs leaking daemons on a\r\nfailing assert) and [[ir81]] (kill scoping) — three drafts converging on one seam.\r\n\r\n---\r\n\r\n#### THE 12-CELL UNION — 4 shas x 2 OSes, membership beside the invariant (hertz, 2026-09-07 10:15Z)\r\n\r\n…\n\n…\n","startLine":3607,"lineNumbers":[3607,null,3609,null,3618,null,3620,3621,3622,3623,3624,3625,3626,3627,3628,3629,3630,3631,3632,3633,3634,3635,3636,3637,3638,3639,3640,3641,3642,3643,3644,3645,3646,3647,3648,3649,3650,3651,3652,3653,3654,3655,3656,3657,3658,3659,3660,3661,3662,3663,3664,3665,3666,3667,3668,3669,3670,3671,3672,3673,3674,3675,3676,3677,3678,3679,3680,3681,3682,3683,3684,3685,3686,3687,3688,3689,3690,3691,3692,3693,3694,3695,3696,3697,3698,3699,3700,3701,3702,3703,3704,3705,3706,3707,3708,3709,3710,3711,3712,3713,3714,3715,3716,3717,3718,3719,3720,3721,3722,3723,3724,3725,3726,3727,3728,3729,3730,3731,3732,3733,3734,3735,3736,3737,3738,3739,3740,3741,3742,3743,3744,3745,3746,3747,3748,3749,3750,3751,3752,3753,3754,3755,3756,3757,3758,3759,3760,3761,3762,3763,3764,3765,3766,3767,3768,3769,3770,3771,3772,3773,3774,3775,3776,3777,3778,3779,3780,3781,3782,3783,3784,3785,3786,3787,3788,3789,3790,3791,3792,3793,3794,3795,3796,3797,3798,3799,3800,3801,3802,3803,3804,3805,3806,3807,3808,3809,3810,3811,3812,3813,3814,3815,3816,3817,3818,3819,3820,3821,3822,3823,3824,3825,3826,3827,3828,3829,3830,3831,3832,3833,3834,3835,3836,3837,3838,3839,3840,3841,3842,3843,3844,3845,3846,3847,3848,3849,3850,3851,3852,3853,3854,3855,3856,3857,3858,3859,3860,3861,3862,3863,3864,3865,3866,3867,3868,3869,3870,3871,3872,3873,3874,3875,3876,3877,3878,3879,3880,3881,3882,3883,3884,3885,3886,3887,3888,3889,3890,3891,3892,3893,3894,3895,3896,3897,3898,3899,3900,3901,3902,3903,3904,3905,3906,3907,3908,3909,3910,3911,3912,3913,3914,3915,3916,3917,3918,3919,3920,3921,3922,3923,3924,3925,3926,3927,3928,3929,3930,3931,3932,3933,3934,3935,3936,3937,3938,3939,3940,3941,3942,3943,3944,3945,3946,3947,3948,3949,3950,3951,3952,3953,3954,3955,3956,3957,3958,3959,3960,3961,3962,3963,3964,3965,3966,3967,3968,3969,3970,3971,3972,3973,3974,3975,3976,3977,3978,3979,3980,3981,3982,3983,3984,3985,3986,3987,3988,3989,3990,3991,3992,3993,3994,3995,3996,3997,3998,3999,4000,4001,4002,4003,4004,4005,4006,4007,4008,4009,4010,4011,4012,4013,4014,4015,4016,4017,4018,4019,4020,4021,4022,4023,4024,4025,4026,4027,4028,4029,4030,4031,4032,4033,4034,4035,4036,4037,4038,4039,4040,4041,4042,4043,4044,4045,4046,4047,4048,4049,4050,4051,4052,4053,4054,4055,4056,4057,4058,4059,4060,4061,4062,4063,4064,4065,4066,4067,4068,4069,4070,4071,4072,4073,4074,4075,4076,4077,4078,4079,4080,4081,4082,4083,4084,4085,4086,4087,4088,4089,4090,4091,4092,4093,4094,4095,4096,4097,4098,4099,4100,4101,4102,4103,4104,4105,4106,4107,4108,4109,4110,4111,4112,4113,4114,4115,4116,4117,4118,4119,4120,4121,4122,4123,4124,4125,4126,4127,4128,4129,4130,4131,4132,4133,4134,4135,4136,4137,4138,4139,4140,4141,4142,4143,null,4164,null,4299]},"fileSize":501961,"meta":{"source":{"type":"path","value":"C:\\Users\\decid\\Documents\\projects\\spt-core\\docs\\INFRA-REGISTER.md"},"truncation":{"direction":"head","truncatedBy":"lines","totalLines":5781,"totalBytes":42702,"outputLines":524,"outputBytes":42702,"shownRange":{"start":3620,"end":4143},"nextOffset":4144}}},"isError":false,"timestamp":1789094604322}}
{"type":"message","id":"b13a6a12","parentId":"71ab5a00","timestamp":"2026-09-11T02:43:24.339Z","message":{"role":"toolResult","toolCallId":"call_uld1OBQG2aDmBLc0eS4hRT5Z|fc_065c0d1976ecf9c2016aa36ac9e50487d1a5accf2750af8035","toolName":"grep","content":[{"type":"text","text":"*2726|### IR-50 — e2e failure panels read the PRE-REDIRECT stderr capture; every daemon-side diagnostic lands in a sink the rig deletes unread\n*2727|- **Status:** CLOSED — BUILT 2026-08-19; adoption-completion lane\n 2728|  `docs/ir50-register-close` @`e02f565f` (hertz, doyle-gated 2026-08-20) LANDED in\n 2729|  v0.59.0 as a PORTER rider (pick `e702d4b7` tip, main @`c62904e7`; register sweep\n 2730|  2026-08-21) — lane `fix/ir50-stderr-sink-census` @`1a2f6a2`+`2ac9543`\n...\n 2777|  and remainder are hertz-class.\n*2778|- **Ripe when:** hertz's queue after current items, or the next e2e red printing an empty\n 2779|  stderr panel.\n 2780|- **Size:** census + mechanical panel edits per rig.\n 2781|- **Kin:** [[IR-40]] (an absent signal read as a clean verdict), REQ-DAEMON-STDERR-PERSIST (the\n...\n 2783|\n*2784|### IR-51 — engine-room e2e daemon runs NET-ENABLED on real interfaces; rig hermeticity is disk-deep only\n*2785|- **Status:** open — filed 2026-08-19 (todlando's x40 run-4 sink read, the first live read any\n 2786|  rig has had of the daemon sink; doyle ruled own-id rather than riding #199, at the finder's\n 2787|  own request) · **Origin:** unasked-for find inside the #199 instrument's first catch.\n 2788|- **What/why:** the rig's temp `SPT_HOME` buys DISK hermeticity ([[IR-45]]'s settlement — which\n...\n 2805|  green bought by turning the net off would bury the mechanism unread.\n*2806|- **Ripe when:** #199 attribution answers whether net state is causal; else the next\n 2807|  hermeticity pass.\n 2808|- **Size:** product switch + rig adoption + census.\n 2809|- **Kin:** [[IR-45]] (the disk half), the subnet-pump dial-does-not-fast-fail mechanism (filed,\n...\n 2812|\n*2813|### IR-53 — failed-address expiry unit panics during the first 10m01s after Windows boot\n*2814|- **Status:** BUILT 2026-08-21 on `fix/ir53-cold-boot-instant` — LANDED in v0.59.0\n 2815|  (PORTER rider, pick `7b26f28d` on `assembly/porter-205`, main @`c62904e7`; register\n 2816|  sweep 2026-08-21 at release close) · **Origin:** todlando,\n 2817|  found and falsifiably measured mid-releases#204; this rider fixes the latent CI-pipeline\n...\n 2838|\n*2839|### IR-52 — docs-site CLI reference renders SHALLOW; help text below the rendered depth is outside the drift gate, unit-held per-REQ or held by nothing\n 2840|- **THIRD INSTANCE, observed 2026-08-24 (todlando, WAX-SEAL #21 W4; not acted on):** the new\n 2841|  `spt api seal verify|describe` FLAGS sit below the generator's rendered depth — the entry's\n 2842|  exact class. The W4 user page hand-documents them, which is per-page self-defense, not a\n...\n 2844|  trigger stands for whichever lane next touches the generator.\n*2845|- **Status:** BUILT 2026-08-24 on SIGNET #218 W1 T6 (todlando; doyle's intake made it the wave's\n 2846|  rider when the new `seal enroll-authenticator` verb forced the generator touch that armed the\n 2847|  trigger): `xtask` reference-gen now DESCENDS THE FULL COMMAND TREE recursively (the durable\n 2848|  remedy), regen published the 22 previously-unrendered leaves + the new section, and a depth\n...\n 2870|  sites (known: SURFACE-SECTION-SITED walk, MONIC-TRIGGER-SECTION sited-help unit).\n*2871|- **Ripe when:** next xtask docs-gen touch, or the first adapter filing traceable to a\n 2872|  deep-help divergence.\n 2873|- **Size:** xtask render change + regen + census of self-holding units.\n 2874|- **Kin:** the REQ-CLI-SURFACE-SECTION-SITED pinned walk (the per-REQ closure shape this\n...\n 2944|\n*2945|### IR-55 — the `spt --bins` suite wedges partway through on leaked `findstr .` PTY children; the tests at the frontier are casualties, not culprits\n 2946|\n*2947|- **Status:** OPEN, **ARMED-FOR-CAPTURE**, owned by **hertz**. Test/rig defect by the dispatch\n 2948|  split (test/CI rework is never the product builder's). Filed by doyle 2026-08-22 from the\n 2949|  TURNKEY #212 W3 gate on releases#213.\n 2950|- **CORRECTED BY REPLACEMENT the same day.** This entry first named\n...\n 2986|  shape as `exit-code-after-a-pipe-is-the-tails`.\n*2987|- **Trigger condition (ripe):** any milestone whose gate wants an unfiltered `spt --bins` sweep,\n 2988|  which is every one of them. Ripe now.\n 2989|- **REMEDY, MEASURED 2026-08-22 and it changes this entry's urgency:** the same 653 tests under\n 2990|  `cargo nextest run -p spt --bins --no-fail-fast` complete in **22.2 seconds, 653 passed, 0\n...\n 3070|\n*3071|### IR-56 — `pool-claim` harvests lane identity from CWD, not from `--pool`; a claim run from the wrong tree writes a WRONG RECORD with a success message\n 3072|\n*3073|- **Status:** BUILT 2026-08-24 for the SIGNET #218 golden batch on\n 3074|  `fix/ir56-pool-claim-cwd`, owned by **hertz**. Tooling/rig defect by the dispatch split. Filed by\n 3075|  doyle 2026-08-22 from todlando's TURNKEY #212 W4 Lane 1 field instance — the first confirmation\n 3076|  of the IR-42 mechanism from a LANE rather than from a source read.\n...\n 3096|  `branch` name the lane: the success line carries the record, so the check costs nothing.\n*3097|- **Trigger condition:** ripe now — it is a doc/UX fix on a verb we run every lane. Ripest alongside\n 3098|  any other `xtask` pool-verb touch.\n 3099|- **Size guess:** small. Either make the verb REFUSE when cwd is not inside the tree containing\n 3100|  `--pool` (loud, and it cannot be wrong), or print the harvested identity as a distinct confirmed\n...\n 3111|\n*3112|### IR-57 — an assembly pick's conflict resolution can silently DROP lines, and every gate run at assembly time is blind to it\n 3113|\n*3114|- **Status:** OPEN, owned by **doyle** (gater craft, not a code defect — no lane to dispatch).\n 3115|  Filed 2026-08-22 from doyle's own defect on the TURNKEY #212 assembly head.\n 3116|- **What happened:** assembly head `5cce533d` **did not compile**, and was carried across a session\n 3117|  boundary as a ready head with \"treqs exit 0\" attached to it. `crates/spt-store/src/access.rs` had\n...\n 3165|  produced the verdict classes in the order the entry predicts.\n*3166|- **Trigger condition:** ripe at the next assembly — this is procedure, and its cost is one command\n 3167|  per pick.\n 3168|- **Size guess:** small as a scripted check in `xtask` (fidelity audit over a pick range); zero as\n 3169|  discipline, which is how it is being applied now.\n 3170|\n*3171|### IR-58 — a `[[bin]]` grep is not a census: cargo AUTODISCOVERS `src/bin/*.rs` targets, and a hand-built bin list produced a confident false \"this bin does not exist\"\n 3172|\n*3173|- **Status:** OPEN, unowned. Filed by doyle 2026-08-22; **its original filing was WRONG and is\n 3174|  retracted in full below.** The entry is kept because the way it was wrong is the finding.\n 3175|- **RETRACTED CLAIM, stated plainly so no reader acts on it:** this entry first said that\n 3176|  `crates/spt/Cargo.toml:18-21` and `crates/spt/src/cli.rs:30355` forbid a bin-name collision with\n...\n 3200|  answer about a set it never fully saw.\n*3201|- **Trigger condition:** ripe on any `xtask` check work — a duplicate-bin-name check over cargo's\n 3202|  target enumeration (NOT over manifest stanzas) is a handful of lines and cannot go stale.\n 3203|- **Size guess:** small. The prose fix originally proposed here is WITHDRAWN — there was nothing\n 3204|  wrong with the prose.\n 3205|\n*3206|### IR-59 — pool arithmetic: this box holds TWO cold pools, not four; and a build that exhausts the volume reds as a LINKER defect that names no disk\n 3207|\n*3208|- **Status:** OPEN, unowned — it is arithmetic and discipline, not a code lane. Filed by doyle\n 3209|  2026-08-22 from a live disk-floor abort during the TURNKEY #212 W4 gate; footprint figures measured\n 3210|  by todlando the same hour.\n 3211|- **SECOND FACE, measured 2026-08-23/24 (WAX-SEAL #21 W2 gate, doyle — the violator this time):**\n...\n 3320|  rides with [[IR-57]]'s scripted pick-fidelity audit as the next milestone's two tooling riders.\n*3321|- **Trigger condition:** ripe now for the log-the-floor half (it rides any gate-script or CI touch);\n 3322|  the arithmetic is discipline and applies immediately.\n 3323|- **Size guess:** small — one line in each rig/gate preflight to record free space alongside the\n 3324|  existing floor check.\n 3325|\n*3326|### IR-60 — a wrapper that CAPTURES a leg's exit status ends with the capture, so the wrapper's own status is the capture's, not the leg's\n 3327|\n*3328|- **Status:** OPEN, unowned — script-shape discipline, not a code lane. Filed by doyle 2026-08-22\n 3329|  during the TURNKEY #212 W5 lane; mechanism measured by todlando, who reported it first as a\n 3330|  possible harness misreport and then RETRACTED that reading himself on a minimal probe.\n 3331|- **The reading that started it:** a background leg was summarised as `exit code 0` while the leg's\n...\n 3361|  file.\n*3362|- **Trigger condition:** ripe now — it rides the next gate-script touch, and the gate scripts in this\n 3363|  milestone already write per-leg exit files, which is what makes this discipline rather than debt.\n 3364|- **Size guess:** small — a convention line in the gate-script preamble; no product code.\n 3365|\n*3366|### IR-61 — spacerun's test-module skip carries a SECOND literal tracker; the two answers can drift, and today only a cell stands between them\n 3367|\n*3368|- **Status:** OPEN, unowned, accepted-with-mitigation. Filed by doyle 2026-08-22 at the TURNKEY #212\n 3369|  head gate, as the named residual of the latch repair (the repair itself rides the milestone).\n 3370|- **What the debt is.** `crates/xtask/src/spacerun.rs` now skips a column-0 `#[cfg(test)]` module by\n 3371|  BRACE DEPTH and resumes after its close, rather than latching the scan to end-of-file. Counting\n...\n 3393|  scanner accumulating special cases.\n*3394|- **Trigger condition:** the next SUBSTANTIVE change to spacerun's scanning — any new skip, any new\n 3395|  literal form, any change to either tracker. At that point unify, rather than adding a third answer.\n 3396|- **Size guess:** small to medium — one continuous literal-state walk serving both the render pass\n 3397|  and the skip, with the existing corpus and brace cells as the regression net.\n 3398|\n*3399|### IR-62 — an e2e daemon binds well-known ports and collides with the resident fleet on shared runners\n 3400|\n 3401|Filed 2026-08-23 (doyle), from the #212 r2 golden's Windows Phase A red — one witnessed\n 3402|instance, mechanism verified from the run's own capture, filed on the mechanism per the\n...\n 3439|\n*3440|### IR-63 — suite-mix sweeps leak job-escaped autostart daemons that LOCK the pool's spt.exe; and the same box conditions manufacture one random victim per sweep\n 3441|\n*3442|- **Status:** OPEN, mitigated-by-rig-step — the reap is adopted discipline, not yet construction.\n 3443|  Filed by doyle 2026-08-24 at the SIGNET #218 gates; first measured by todlando the same day\n 3444|  (his W1 build: four reap rounds of 2, 8, 1, 1 processes, count-by-path stated each round).\n 3445|- **Mechanism, two faces of one condition:** (1) e2e sweeps that exercise autostart leave\n...\n 3474|  this entry (brief cites IR-7/17/20/34/35/63); leaves the register when that lane lands.\n*3475|- **Trigger condition:** next rig/gate-script construction touch, or the first golden red that\n 3476|  classifies to face (1).\n 3477|- **Size guess:** small-medium — one wrapper seam plus adopting it in the gate/lane scripts.\n 3478|\n*3479|### IR-64 — HFENDULEAM's disk floor is set by non-CI bulk: ~845 GB of operator payload leaves the golden box ~2 GB of slack against its own 32 GB preflight\n 3480|\n*3481|- **Status:** OPEN · **Origin:** doyle, v0.63.0 close sweep 2026-08-26; mechanism first measured\n 3482|  at the FIELD-SEAL golden window (deployah's IR-31 fifth addendum carries the POOL side of the\n 3483|  same event by agreed division — this entry is the OTHER reservoir, deliberately not his).\n 3484|- **Mechanism:** the 1.86 TB C: carries ~614 GB Steam + ~230 GB Downloads (operator payload, not\n...\n 3496|  exists to put in front of them once, with numbers, instead of re-deriving the floor each cut.\n*3497|- **Ripe when:** operator rules on the bulk (move/expand/accept-the-tax), OR the first golden\n 3498|  that dies at the 32 GB preflight despite adopted pool discipline (IR-59's LNK1180-class red).\n 3499|- **Size:** zero code; one operator decision + at most a runbook line naming the chosen floor.\n 3500|\n*3501|### IR-65 — kitsubito kernel-audit backpressure: a tailscale-snap AppArmor denial storm + no auditd turned the default audit backlog into a CI-wide stall amplifier (REMEDIATED AT BOX; re-check triggers named)\n 3502|\n*3503|- **Status:** REMEDIATED-AT-BOX 2026-08-25 (doyle, operator-authorized root — ruling pinned\n 3504|  releases#225 comment 5418800776); entry stays OPEN as the re-check record because the storm\n 3505|  SOURCE persists and two named events can silently revert the fix.\n 3506|- **Mechanism:** `snap.tailscale.tailscaled` (1.92.5) polls /proc and takes an AppArmor\n...\n 3524|  `auditctl -s` (expect 32768/0) + one `journalctl -k | grep 'backlog limit'` (expect silence).\n*3525|- **Ripe when:** a re-check trigger fires. **Size:** two read-only commands per check.\n 3526|\n*3527|### IR-66 — first-chunk-needle test class: two latent members remain after the v0.63.0 fix (attach.rs:561, :672)\n 3528|\n*3529|- **Status:** BUILT — confirmed present at `17815c9c` (hertz 2026-09-06); leaves the register at the WEBSERVE close sweep. Hertz rider PR #161, landed ff at `d04b922d` (2026-08-27, IO-PARSER #22\n 3530|  intake rider). Both members got the later-needle treatment (TICK39 delayed past burst on both\n 3531|  OS arms; alt-screen entered before delayed ALT_VIEWPORT_MARKER). Gate: doyle — diff-scope\n 3532|  review; Windows isolated worktree 3× TICK39 PASS + clippy + treqs; Linux CLEAN worktree at the\n...\n 3552|  landed mid-r4. Both cells passed r4 (0.010–0.058s) — the members are latent, not failing.\n*3553|- **Ripe when:** next milestone intake (hertz test lane) or the first golden red at ~240s on an\n 3554|  attach cell — either way the mechanism and fix are pre-derived, triage should cite this entry\n 3555|  and skip the RCA. **Size:** two one-line test edits.\n 3556|\n*3557|### IR-67 — wave-battery gap: a `-p spt --bins` leg compiles bin targets as harnesses and runs ZERO integration/e2e tests, so batteries that lean on it carry silent no-coverage legs\n 3558|\n*3559|- **Status:** BUILT — remedy applied across the IO-PARSER #22 milestone (2026-08-27/28): every\n 3560|  wave battery named explicit `-p spt --test <suite>` e2e legs beside the `--bins` unit leg\n 3561|  (GW1..GW5 evidence), every builder evidence report carried a named real e2e per the dispatch\n 3562|  template, and the one filter mistake (a `--test` name not matching its file) REFUSED loudly\n...\n 3575|  permits), and any battery doc that lists `--bins` as a coverage leg gets the one-line caveat.\n*3576|- **Ripe when:** next milestone intake (the battery template is touched at every intake).\n 3577|  **Size:** template lines only.\n 3578|\n*3579|### IR-68 — PSYCHE_INGEST_FAIL cause class unproven: git index.lock did NOT reproduce the ingest failure it was blamed for\n 3580|\n*3581|- **Status:** OPEN, investigation-shaped · **Origin:** todlando measurement at the W2 int-leg rig\n 3582|  (IO-PARSER #22, PR #163 at `769fb0a9`, 2026-08-27), reported measure-first; filed by doyle.\n 3583|- **The contradiction:** the six silent `PSYCHE_INGEST_FAIL:todlando` lines observed at the\n 3584|  drop-dir probe (2026-08-25) were attributed to shared-checkout git `index.lock` contention. The\n...\n 3601|  files did survive with failed-ingest log lines; what is unproven is the index.lock CAUSE.\n*3602|- **Ripe when:** next PSYCHE_INGEST_FAIL sighting in the field (capture the failing store state\n 3603|  before touching it), or a dedicated probe slot. W2's COMMUNE_FAIL event now pushes a NAMED\n 3604|  reason on every failure, so the next occurrence self-reports its cause — read that first.\n 3605|  **Size:** investigation; no product change until the mechanism is pinned.\n 3606|\n*3607|### IR-69 — inherited stderr tokens can tear between format fragments; 26 test consumers parse that surface as structured truth\n 3608|\n*3609|- **Status:** OPEN, product remedy complete and parked GREEN-AND-READY at `d0fdd58d` on\n 3610|  `feat/emit-single-write`, owned by **todlando**, awaiting golden-batch assembly; board request\n 3611|  releases#241 carries the product remedy and full lane evidence in comment 5461613480. This entry\n 3612|  is the exposure map and census discipline, not the implementation. · **Origin:** CONDUIT #236 r3\n...\n 3697|\n*3698|### IR-70 — a hand-built `IoBus` silently omitted later sinks while every gate stayed green\n 3699|\n*3700|- **Status:** OPEN, remedy unscheduled; the v0.65.0 respin fixed the witnessed call site on PR #173.\n 3701|  This entry owns the recurrence class, not that shipped correction. · **Origin:** releases#234,\n 3702|  commit `c5459795167`, CONDUIT #236 respin.\n 3703|- **Mechanism:** `publish_commune_io` constructed `IoBus` itself and registered only the sink it\n...\n 3721|  population returns an orderly but incomplete answer).\n*3722|- **Ripe when:** the next `IoBus` construction/API touch, or a new sink registration. **Size:**\n 3723|  small-to-medium assembly-point enforcement plus a real-path population test.\n 3724|\n*3725|### IR-71 — controller-seat release has no persisted breadcrumb, so tests cannot distinguish propagation lag from a missing detach\n 3726|\n*3727|- **Status:** OPEN, observability gap; no remedy scheduled. · **Origin:** CONDUIT #236 r3\n 3728|  `er_brief_once_per_session_e2e` intermittent, classified test-side and fixed on PR #174.\n 3729|- **What/why:** killing rc1 reaps the controller process, but the broker is another process and\n 3730|  notices the socket close later. On that detach edge it clears `driven_by` and `controlled` in\n...\n 3745|  completion signal), REQ-HAZARD-CONTROL-STAMP-CONVERGENCE.\n*3746|- **Ripe when:** the next controller lifecycle or structured-breadcrumb touch, or a field timeout\n 3747|  from PR #174's barrier. **Size:** small emitter plus one contract-level assertion.\n 3748|\n*3749|### IR-72 — no product read verb surfaces which process holds a perch or controller seat\n 3750|\n*3751|- **Status:** OPEN, observability gap; no remedy scheduled. · **Origin:** CONDUIT #236 r3\n 3752|  two-host RCA and PR #174 (`70c1a303`), corrected by doyle after IR-18 and daemon-status were\n 3753|  ruled out as different classes.\n 3754|- **Source-verified boundary:** the holder identity already exists in durable/internal records\n...\n 3778|  rather than select by enumeration order).\n*3779|- **Ripe when:** the next roster/status read-model change or another rig needs to reap a named\n 3780|  holder. **Size:** small read-model/API addition, medium if seat and perch custody need separate\n 3781|  typed variants.\n 3782|\n*3783|### IR-73 — ci.yml and release.yml still read the free-space floor PRE-checkout (literal-first sites off the golden path); and any job's floor is stale by its last heavy step\n 3784|\n*3785|- **Status:** OPEN, filed by doyle 2026-08-30 at the #242/v0.66.0 close sweep (deployah flag\n 3786|  2026-08-29, widen lane). · **Origin:** the #242 cut lost two golden attempts to exactly this\n 3787|  REQ-CI-FREE-SPACE-PREFLIGHT trap on `golden.yml`'s n1-gate (floor read BEFORE checkout, so the\n 3788|  checkout's own cost lands after the assertion); `golden.yml` is fully reshaped (`ac7d2609`,\n...\n 3801|  defect), REQ-CI-FREE-SPACE-PREFLIGHT.\n*3802|- **Ripe when:** next touch of `ci.yml`/`release.yml`, or the next intake's tooling-rider slot\n 3803|  (compose with IR-59/IR-57's standing pair). · **Size:** small — reorder or comment per site,\n 3804|  8 sites.\n 3805|\n*3806|### IR-74 — kitsubito holds 21,643 /tmp endpoint homes: box-side accumulation nothing bounds or measures\n 3807|\n*3808|- **Status:** OPEN, filed by doyle 2026-08-30 at the #242/v0.66.0 close sweep; measurement by\n 3809|  hertz (2026-08-29). · **Origin:** rig work on kitsubito found `/tmp` carrying 21,643 endpoint\n 3810|  homes — per-run spt homes that outlive their runs.\n 3811|- **What/why:** sibling of the [[IR-31]]/[[IR-59]]/[[IR-64]] family (box accumulation the\n...\n 3815|  retention), and the reap must state its count so a zero is a claim.\n*3816|- **Ripe when:** next kitsubito rig touch, or the between-milestone box-audit slot.\n 3817|- **Size:** small (one sweep script + adoption in the box's rig steps); the measurement rerun is\n 3818|  one `find | wc`.\n 3819|\n*3820|### IR-75 — traceable-reqs is not installed on kitsubito, so every Linux gate driver's treqs leg exits 127 (vacuous, wrapper-green shape)\n 3821|\n*3822|- **Status:** OPEN, filed by doyle 2026-08-30 at the #242/v0.66.0 close sweep (deployah\n 3823|  co-flagged at intake). · **Origin:** ASM-241 Linux battery — `ASM_treqs.exit` = 127, raw\n 3824|  `env: 'traceable-reqs': No such file or directory`; leg vacuous, covered that day by the\n 3825|  Windows treqs = 0 at the identical tree (treqs is a platform-independent text scan).\n...\n 3831|  surface (ruled at the sweep against the enumerating agent's overcautious flag).\n*3832|- **Ripe when:** next Linux gate-driver touch or kitsubito box-audit slot.\n 3833|- **Size:** trivial (install or one driver edit + comment).\n 3834|\n*3835|### IR-76 — hfenduleam is the golden Windows runner AND the builders' box: a local workspace nextest fully contained a golden Phase A and manufactured a load-timing red, and the job-start census cannot see it\n 3836|\n*3837|- **Status:** OPEN, filed by doyle 2026-09-06 during v0.67.1 golden triage (run 34017906638\n 3838|  att2). · **Origin:** the Windows Phase A red on\n 3839|  `spt-store::wtlock_two_process_int two_processes_commit_into_one_worktree_without_failing`\n 3840|  (B hit the 10 s worktree-lock bound while A's six serial commits took 13.5 s; 12 other\n...\n 3874|  `wtlock_two_process_int` and `attach_link_push_e2e` (2026-09-06).\n*3875|- **Ripe when:** next driver-template touch (a/b are text; a is one leg), next `ci.yml`\n 3876|  touch for (c) — compose with [[IR-73]]'s reorders; (d) rides the next runbook edit.\n 3877|- **Size:** small — one pre-flight leg + one census predicate + two doc sentences.\n 3878|\n*3879|### IR-77 — nothing stamps the interval between a daemon child's spawn and the brain's first log line, so a readiness-deadline red cannot say WHERE the time went\n 3880|\n*3881|- **Status:** OPEN, filed by hertz 2026-09-07 from the W1 #249 kitsubito battery at the gated\n 3882|  sha `8d980fdf`; doyle-ruled at filing to be a register entry rather than a lane rider. ·\n 3883|  **Origin:** FLAKE-LEDGER `resident_service_e2e` :453 PRECONDITION (53 s) and\n 3884|  `resume_no_control_steal_e2e` (46 s), co-victims of ONE window — nextest exit 100, ONE\n...\n 3905|  with a different number, and it would also destroy the only signal this entry wants.\n*3906|- **Ripe when:** the next touch of the daemon boot path or of `brainproc`'s ready stamp; also\n 3907|  ripe as a rider on any lane that re-opens this test family.\n 3908|- **Size:** small — two `emit_line_err!` breadcrumbs and the sentence in the panel that says\n 3909|  what they mean.\n 3910|\n*3911|### IR-78 — `SPT_TEST_EPHEMERAL_ADVISORY_PORTS` silently overrides an explicitly set `SPT_DOCS_PORT`\n 3912|\n*3913|- **Status:** OPEN, filed by hertz 2026-09-07, MEASURED by doyle the same night on his W2\n 3914|  field pair (both boxes). · **Origin:** the 5474 rig-hygiene sweep in\n 3915|  `test/rig-advisory-ports-and-heavy-class`, which sets the rig flag at 37 `spt daemon run`\n 3916|  spawn sites.\n...\n 3934|  measured, and neither was the unix path.\n*3935|- **Ripe when:** the next `docshost.rs` touch, or the first time someone sets `SPT_DOCS_PORT`\n 3936|  on a rig and believes it.\n 3937|- **Size:** tiny — one emitted notice.\n 3938|\n*3939|### IR-79 — 22 of the 31 rig binaries leak their daemon tree on a failing assert: teardown is a statement, not a guard\n 3940|\n*3941|- **Status:** OPEN, filed by hertz 2026-09-07 on doyle's dispatch during PR #198's CI window,\n 3942|  from todlando's red 6 (a stale same-port daemon from his own previous run answering the next\n 3943|  one). · **Origin:** PR #198 moved 31 rigs to `SPT_TEST_EPHEMERAL_ADVISORY_PORTS=1`. Under an\n 3944|  ephemeral port a leaked daemon can no longer ANSWER the next run, so that PR is right as it\n...\n 4014|  one of the producers), and todlando's red 6.\n*4015|- **Ripe when:** the next lane that touches `crates/spt/tests/common` — the guard belongs there,\n 4016|  not copied 22 times.\n 4017|- **Size:** medium — one guard in `common`, then 22 mechanical adoptions, each provable by\n 4018|  panicking the body under a temporary test and watching the census go quiet.\n 4019|\n*4020|### IR-80 — five leaky cells on ONE module (`brainproc` / `supervise_brain`), Windows only: a candidate PRODUCT leak on the promotion/rollback path, or a cluster of names — nobody has looked yet\n 4021|\n*4022|- **Status:** OPEN, filed by hertz 2026-09-07 07:40Z on doyle's ruling (07:38Z) that this is its\n 4023|  OWN entry and **not** a third face of [[IR-79]] — IR-79 is rig teardown, this is a candidate\n 4024|  defect in the PRODUCT path, so its owner may be todlando rather than the rig lane. ·\n 4025|  **Origin:** noticed while measuring the #198 HEAVY scan-root gap ([[IR-37]] rider 2); the leak\n...\n 4078|  teardown LEAK row.\n*4079|- **Ripe when:** the first free Windows box after W2 lands — it is a single-cell census, so it\n 4080|  fits any gap.\n 4081|- **Size:** unknown until the census. Tiny if it is a missing `wait()`; not tiny if the promotion\n 4082|  path leaves a real candidate brain alive on rollback.\n...\n 4299|\n*4300|### IR-81 — a process kill can be written scoped or machine-wide, and nothing makes the scoped form the only reachable one: both codebases carry the right pattern beside the wrong one\n 4301|\n*4302|- **Status:** OPEN, drafted by hertz 2026-09-07 08:38Z on doyle's dispatch (08:36Z), from the\n 4303|  fleet-daemon death on hfenduleam at 08:03:15Z ([[RCA-FLEET-DAEMON-14444]], cause still UNNAMED).\n 4304|  Census body: `docs/PID-KILL-CENSUS.md`. · **Origin:** doyle asked which sites kill a REMEMBERED\n 4305|  pid without re-verifying identity AT KILL TIME. The census answered that, and then answered a\n...\n 4356|  site in one repo is stronger evidence about PROCESS than either site is about code.\n*4357|- **Ripe when:** the next touch of `spt-store/src/proc.rs` (for remedy 1) or of `xtask check`'s\n 4358|  gate family (for remedy 2). The adapter half is perri's, filed separately, and does not wait\n 4359|  on this.\n 4360|- **Size:** small for remedy 2, medium for remedy 1 (signature + every caller). The census that\n...\n 4424|\n*4425|### IR-82 — a daemon death leaves NO record of who died: autostart decides on a socket ping, says \"no daemon\", and the successor overwrites the only handle on the corpse\n 4426|\n*4427|- **Status:** RULED 2026-09-07 11:07Z (doyle), drafted by hertz 11:04Z on doyle's dispatch (11:03Z: *\"the autostart\n 4428|  death-cause item is an IR, not a board item — mint it IR-82 in your thin PR\"*). Register on main\n 4429|  ends at IR-78; 79/80/81 are drafts in the same PR. · **Origin:** the fleet-daemon death on\n 4430|  hfenduleam at 08:03:14.87Z ([[RCA-FLEET-DAEMON-14444]]) whose cause is **still UNNAMED after a day\n...\n 4530|\n*4531|### IR-83 — a two-host rig addressed over the tailnet cannot receive INBOUND on Windows, and the whole rig population had only ever run the admitted direction\n 4532|\n*4533|- **Status:** OPEN, minted by hertz 2026-09-07 11:41Z on doyle's dispatch (11:40Z). **Provenance: the\n 4534|  mechanism below is DOYLE'S measurement, not mine** — eight probe arms, each with sender, listener\n 4535|  and output file, recorded in `GATE-W2-272-CHECKLIST.md` rows 11:36Z–11:39Z. I am off cargo on both\n 4536|  boxes and have re-measured none of it; this entry is the register form of his finding plus the\n...\n 4663|\n*4664|### IR-84 — the one `PUMP_PEER_FAIL` arm the rigs actually fire was the only one carrying no clock, so the stall that produced it could be counted but never timed\n 4665|\n*4666|- **Status:** OPEN, filed by hertz 2026-09-09 with the instrument that closes its first half. ·\n 4667|  **Origin:** the 65 s two-host helper stall (design written before the run,\n 4668|  `docs/design/RIDER-65S-DESIGN.md`). The number was branch-claimed 2026-09-08 by name only — IR-85\n 4669|  records that it carried no entry text in any register file in any worktree — and this is that text.\n...\n 4709|  supervised restart, never a per-peer retry), ADR-0039 Decision 5.\n*4710|- **Ripe when:** now, and it lands with this entry — the stamp is one emit line, tagged\n 4711|  `[impl->REQ-PUMP-STAGE-TRUTH]` at the site. · **Size:** one emit line plus its comment.\n 4712|  **Follow-up, not this lane:** a cell that walks every `PUMP_PEER_FAIL` arm and asserts each one\n 4713|  stamps, so the fifth site added cannot be born silent.\n*4714|### IR-85 — the Windows self-hosted box runs its fs-heavy tests 3-4x slower than a week ago; two CI wall clocks were sized for the old box, and a red run kept hiding it\n 4715|\n*4716|- **Status:** OPEN, filed by hertz 2026-09-09 at the #272/v0.68.0 golden r3/r4 arc, on doyle's\n 4717|  dispatch. Number ruled by doyle from his own census of main@`a2f335f8` (register ended at IR-83;\n 4718|  IR-84 was branch-claimed by name only, with no entry text in any register file in any worktree —\n 4719|  that gap is now closed: **IR-84 was filed 2026-09-09 in PR #213**, so this sentence records the\n...\n 4835|  `e2e-leaked-daemons-shared-box` (memory).\n*4836|- **Ripe when:** arm 1 now; arms 2-4 on the operator's answer; arm 5 at the next `golden.yml` touch\n 4837|  after any of them. · **Size:** arm 1 a measurement, arm 4 one census line, arm 5 two literals.\n 4838|- **AMENDMENT 2026-09-09 (two terms this entry did not name when it landed at `d32d5c4c`).**\n 4839|  1. **`ci.yml`'s `changes` job runs `unit` on BOTH runners for every push to `main`.** The classify\n...\n 4873|\n*4874|### IR-86 — golden's 32 GiB floor is BELOW the measured 67.4 GiB Windows suite footprint, so a start floor passes a box that cannot finish\n 4875|\n*4876|- **Status:** OPEN, filed by doyle 2026-09-08 at the #272/v0.68.0 golden r2 triage. · **Origin:**\n 4877|  run 34262154550 @ `25e60015` (shaped on `e4444413`), Windows test job 102182665033: every product\n 4878|  step green (Phase A 3346/3346, Phase B 234/234, Summary 2, FAIL 0), the ONLY reds were the two\n 4879|  in-job floor gates. `FLOOR_START` 97,649,786,880 B PASS at 18:47:23Z -> `FLOOR_DOCS`\n...\n 4909|  `FLOOR_END`.\n*4910|- **Ripe when:** next `golden.yml` touch (hertz workflow rider slot). · **Size:** small — one\n 4911|  literal per start-floor site + one printed subtraction.\n 4912|\n*4913|### IR-87 — two-host ceremony halves are INDEPENDENT jobs on DIFFERENT runners (A Windows/hfenduleam, B Linux/kitsubito); B's 900 s budget runs on B's own clock, so any older queued Windows job starves A and reds B deterministically, and the panic text blames pairing\n 4914|\n*4915|- **Status:** OPEN, filed by doyle 2026-09-08 at the #272 golden r2 triage. · **Origin:**\n 4916|  run 34262154550, twohost-b job 102207296960 (log 81,692 B, sha256 67403f04…8030): role B built,\n 4917|  rostered, polled PAIR_MEET_UP every 30 s from 19:34:30Z, and hit the rig_wait barrier\n 4918|  \"pairing: A rostered via the daemon-hosted responder\" at its 900 s deadline 19:49:17Z\n...\n 4938|  run while one half waits.\n*4939|- **Ripe when:** next `golden.yml`/twohost rig touch. · **Size:** small-medium (job shape or\n 4940|  barrier rework + panic text).\n 4941|\n 4942|- **AMENDMENT 2026-09-10 (releases#294, golden 34445961595 att1 @ `a9e786b2`) — THE STARVING RUN CAN\n...\n 4965|\n*4966|### IR-88 — `pool-release` via `cargo run -p xtask` REBUILDS xtask INTO the pool it is releasing, so a reaped pool regrows ~2.8 GB in silence\n 4967|\n*4968|- **Status:** OPEN, filed by doyle 2026-09-08 from hertz's reap report (20:00Z) during the #272\n 4969|  golden r2 repair. · **Origin:** hertz reaped hertz-lane4 / hertz-repin / hertz-percell-id target\n 4970|  subtrees (Length-sum upper bounds 68.16 / 47.11 / 8.79 GB) and then ran `cargo run -p xtask --\n 4971|  pool-release …` from each worktree: cargo rebuilt xtask into the just-reaped `target/` (2.8 GB\n...\n 4991|  family, same \"the tool acts on where it stands\" shape), releases#103.\n*4992|- **Ripe when:** next xtask pool-verb touch or the teardown runbook edit. · **Size:** tiny —\n 4993|  one guard or one doc line.\n 4994|\n*4995|### IR-89 — hfenduleam's Windows Firewall drops cold inbound UDP to the runner-built test exes, so the two-host rig's first B→A claim (W2 helper) reds for its whole 900 s budget and the panic blames A\n 4996|\n*4997|- **Status:** BOX HALF **APPLIED** 2026-09-08; WORKFLOW HALF **BUILT** 2026-09-09 — PR #211\n 4998|  (`9b96d7e7` + this amendment), **LANDED-pending-golden**: the `golden.yml` steps are UNEXERCISED\n 4999|  until the next golden run, because thin CI compiles the cells and skips them. Filed by doyle 2026-09-08\n 5000|  at the #272 golden r2 terminal triage; the operator-blocked flag is retired here, because\n...\n 5113|  proof; treat the workflow half as landed-pending-golden and not as verified by its own PR.\n*5114|- **Ripe when:** the next GOLDEN run, which is the first thing that exercises the steps — the\n 5115|  code half is built and field-measured (PR #211). (The box half was ripe \"now\" against\n 5116|  `25e60015` and is done; #272 golden acceptance is no longer blocked by it.) · **Size:** one\n 5117|  workflow step remaining; the elevated command is spent.\n...\n 5149|\n*5150|### IR-90 — a full disk on the self-hosted box reds a rig as a PRODUCT refusal, not a build error, and no rig or gate records the free space that would falsify it\n 5151|\n*5152|- **Status:** OPEN, filed by hertz 2026-09-09 from the disk-full incident on hfenduleam. ·\n 5153|  **Origin:** the IR-85 discriminator lane's head arm, killed by the volume rather than by the code\n 5154|  under test.\n 5155|- **Symptom:** `spt-daemon::sync concurrent_writes_reconcile_on_elected_node_and_converge` FAILED at\n...\n 5236|  gap), `test-profile-pool-outgrows-the-disk-floor`, `free-space-floor-blocks-golden`.\n*5237|- **Ripe when:** now. · **Size:** one assertion plus one error-context append, both test-side.\n 5238|\n*5239|### IR-91 — 561 untracked files sat at the repo root, 18 of them cited by tracked files, and the census that classified them used a corpus that made the discriminator invisible\n 5240|\n*5241|- **Status:** CLOSED by the lane that filed it (the root-scratch classify PR), hertz 2026-09-09 on\n 5242|  doyle's census and rulings. · **Origin:** the `.spt/` ignore lane (PR #212) named 561 untracked\n 5243|  root files as explicitly out of scope; this is that half.\n 5244|- **The population, measured at `2037bcb8`:** `git status --porcelain --untracked-files=all` = **561\n...\n 5289|  never a repo path), `ignoring-a-directory-buries-what-the-repo-cites-in-it` (memory).\n*5290|- **Ripe when:** landed with this entry. · **Size:** one `.gitignore` stanza, 18 adds, 543\n 5291|  preserved files, no deletions.\n 5292|\n*5293|### IR-92 — the message that WAKES an idle spt-hosted endpoint rides a delivery leg that never publishes MSG_IN, so a woken agent's own funnel holds none of the messages that woke it\n 5294|\n*5295|- **Status:** OPEN — filed doyle 2026-09-09 from hertz's census, probe and proposed text (his by\n 5296|  role; the recorder read and the REQ reading are doyle's). Fix lane unassigned: product change in\n 5297|  `spt-daemon` (todlando), test-side legs (hertz). · **Origin:** a 22:35Z empty `<msg from=\"hertz\"/>`\n 5298|  turn trigger after the #292 daemon restart, chased for its body; the body was in a spill file, and\n...\n 5338|  the greens is deployah's.)\n*5339|- **Status of that red: UNEXPLAINED between DELAYED and ABSENT publication.** Path B makes the race\n 5340|  MECHANICALLY AVAILABLE, which is more than \"not excluded\" — but availability is not occurrence,\n 5341|  and one observation does not separate them. Kinship to this entry stays a HYPOTHESIS. The cell is\n 5342|  in neither `docs/FLAKE-LEDGER.md` nor this register (0 hits each): an unregistered signature.\n...\n 5413|  a restart), memory `an-empty-msg-from-tag-is-a-turn-trigger-whose-body-lives-in-the-spill`.\n*5414|- **Ripe when:** any lane touches `spt-daemon::inject` or the IO funnel; small enough to ride the\n 5415|  next product batch. · **Size:** one publish call at one chokepoint, one unit cell, one `int` leg\n 5416|  (a hook-hosted receiver woken by a `SENT`, then `io-events` replayed for the msg-id).\n 5417|\n*5418|### IR-93 — no PDB ships beside the installed `spt` binary, so the one non-invasive read of a wedged production daemon comes back without a single named frame\n 5419|\n*5420|- **Status:** OPEN, filed by doyle 2026-09-10. **The number was reserved by NAME on 2026-09-09** at\n 5421|  the #293 mechanism read (\"PDB ask -> IR-93 at next sweep\") and this entry closes that claim — a\n 5422|  name-only IR with no entry text is the exact gap [[IR-85]]'s status line had to spend a paragraph\n 5423|  explaining about IR-84, and it is not being left open a second time. · **Origin:** the #293 pump\n...\n 5443|  cannot say how much it burned).\n*5444|- **Ripe when:** next installer / release-packaging touch. · **Size:** packaging (profile + install\n 5445|  layout), no product code.\n 5446|\n*5447|### IR-94 — xtask's brainread deadline gate cannot SEE `serve_sync`: its registry is three hand-listed files and its predicate is a name shape, so a stream server outside both got the reply form and the gate stayed green\n 5448|\n*5449|- **Status:** OPEN, filed by doyle 2026-09-10 at the releases#294 / v0.69.0 golden RED triage. **This\n 5450|  is an INDEPENDENT gate finding, not the cause of that red** — it was found while reading the\n 5451|  milestone's diff and stands whatever Finding 1 turns out to be. · **Origin:**\n 5452|  `xtask/src/brainread.rs`, new this milestone (the #293 fix's zero-call-site guard).\n...\n 5473|  makes this inert today), `REQ-BRAIN-READ-BOUNDED-PER-CALL`.\n*5474|- **Ripe when:** next `brainread`/xtask touch, **and mandatorily BEFORE `serve_sync` is migrated to a\n 5475|  bounded carrier.** · **Size:** small.\n 5476|\n*5477|### IR-95 — a burned polling budget names WHAT it wanted and never HOW LONG it waited, so no run, green or red, can say how close it came\n 5478|\n*5479|- **Status:** OPEN, filed by doyle 2026-09-10 at the releases#294 golden RED, where it cost this\n 5480|  triage most of a morning and four agents. · **Origin:** the two Windows Phase A failures at\n 5481|  `a9e786b2`, both polling budgets burned rather than value mismatches.\n 5482|- **The two sites, read at source.** They are not even the same KIND of budget, which is the first\n...\n 5727|  readiness red cannot say where the time went), [[IR-90]].\n*5728|- **Ripe when:** with the releases#294 instrumented base-vs-head comparison, which **cannot be run\n 5729|  without it** — the experiment's whole output is the margins these sites do not print. ·\n 5730|  **Size:** small per site; the census is the larger half.\n 5731|\n*5732|### IR-96 — the `daemon_stop_convoy_e2e` API-storm cell fails 3-of-3 under the HEAVY suite at the diagnostic tree while passing at the candidate in golden CI, and nothing yet separates instrumentation from box from product\n 5733|\n*5734|- **Status:** OPEN, **cause-unclassified** (todlando's and hertz's stipulation, adopted verbatim — a\n 5735|  triage placement here is NOT a finding of non-defect).\n 5736|- **Origin:** releases#294 / v0.69.0 Arm B, 2026-09-10, deployah executing at diagnostic tree\n 5737|  `ed8ecd94` (= candidate `a9e786b2` + the unlanded sync instrumentation, never merged).\n...\n 5750|- **Confounded by IR-97** (below): the three runs were not equivalent conditions.\n*5751|- **Ripe when:** any lane touches daemon stop/start convoy behaviour, OR a golden run reds this cell\n 5752|  at a candidate, OR someone runs the cell at `a9e786b2` under the same local HEAVY workload — that\n 5753|  last one is the cheap discriminator and nobody has run it. · **Size:** one targeted local run to\n 5754|  discriminate; unknown beyond that.\n 5755|\n*5756|### IR-97 — a suite that leaks a fixed cohort of child processes per invocation makes consecutive runs non-comparable, and the between-run accounting the protocol required was not enforced\n 5757|\n*5758|- **Status:** OPEN. **Protocol deviation** (hertz's framing, and it is stronger than \"confounder\":\n 5759|  the protocol ALREADY required between-run accounting — execution did not enforce it, so the fix is\n 5760|  enforcement, not a limitations paragraph).\n 5761|- **Origin:** releases#294 Arm B, 2026-09-10. Derived by doyle from deployah's preserved\n...\n 5779|  fleet including the gater's own session.\n*5780|- **Ripe when:** any repeated-run experiment is designed on this box — census BETWEEN runs, not only\n 5781|  at the end. · **Size:** a between-run census step plus a scoped reap in the harness."}],"details":{"scopePath":"docs/INFRA-REGISTER.md","searchPath":"C:\\Users\\decid\\Documents\\projects\\spt-core\\docs\\INFRA-REGISTER.md","cwd":"C:\\Users\\decid\\Documents\\projects\\spt-core","matchCount":136,"fileCount":1,"files":["docs/INFRA-REGISTER.md"],"fileMatches":[{"path":"docs/INFRA-REGISTER.md","count":136}],"truncated":false,"displayContent":"*2726│### IR-50 — e2e failure panels read the PRE-REDIRECT stderr capture; every daemon-side diagnostic lands in a sink the rig deletes unread\n*2727│- **Status:** CLOSED — BUILT 2026-08-19; adoption-completion lane\n 2728│  `docs/ir50-register-close` @`e02f565f` (hertz, doyle-gated 2026-08-20) LANDED in\n 2729│  v0.59.0 as a PORTER rider (pick `e702d4b7` tip, main @`c62904e7`; register sweep\n 2730│  2026-08-21) — lane `fix/ir50-stderr-sink-census` @`1a2f6a2`+`2ac9543`\n     │...\n 2777│  and remainder are hertz-class.\n*2778│- **Ripe when:** hertz's queue after current items, or the next e2e red printing an empty\n 2779│  stderr panel.\n 2780│- **Size:** census + mechanical panel edits per rig.\n 2781│- **Kin:** [[IR-40]] (an absent signal read as a clean verdict), REQ-DAEMON-STDERR-PERSIST (the\n     │...\n 2783│\n*2784│### IR-51 — engine-room e2e daemon runs NET-ENABLED on real interfaces; rig hermeticity is disk-deep only\n*2785│- **Status:** open — filed 2026-08-19 (todlando's x40 run-4 sink read, the first live read any\n 2786│  rig has had of the daemon sink; doyle ruled own-id rather than riding #199, at the finder's\n 2787│  own request) · **Origin:** unasked-for find inside the #199 instrument's first catch.\n 2788│- **What/why:** the rig's temp `SPT_HOME` buys DISK hermeticity ([[IR-45]]'s settlement — which\n     │...\n 2805│  green bought by turning the net off would bury the mechanism unread.\n*2806│- **Ripe when:** #199 attribution answers whether net state is causal; else the next\n 2807│  hermeticity pass.\n 2808│- **Size:** product switch + rig adoption + census.\n 2809│- **Kin:** [[IR-45]] (the disk half), the subnet-pump dial-does-not-fast-fail mechanism (filed,\n     │...\n 2812│\n*2813│### IR-53 — failed-address expiry unit panics during the first 10m01s after Windows boot\n*2814│- **Status:** BUILT 2026-08-21 on `fix/ir53-cold-boot-instant` — LANDED in v0.59.0\n 2815│  (PORTER rider, pick `7b26f28d` on `assembly/porter-205`, main @`c62904e7`; register\n 2816│  sweep 2026-08-21 at release close) · **Origin:** todlando,\n 2817│  found and falsifiably measured mid-releases#204; this rider fixes the latent CI-pipeline\n     │...\n 2838│\n*2839│### IR-52 — docs-site CLI reference renders SHALLOW; help text below the rendered depth is outside the drift gate, unit-held per-REQ or held by nothing\n 2840│- **THIRD INSTANCE, observed 2026-08-24 (todlando, WAX-SEAL #21 W4; not acted on):** the new\n 2841│  `spt api seal verify|describe` FLAGS sit below the generator's rendered depth — the entry's\n 2842│  exact class. The W4 user page hand-documents them, which is per-page self-defense, not a\n     │...\n 2844│  trigger stands for whichever lane next touches the generator.\n*2845│- **Status:** BUILT 2026-08-24 on SIGNET #218 W1 T6 (todlando; doyle's intake made it the wave's\n 2846│  rider when the new `seal enroll-authenticator` verb forced the generator touch that armed the\n 2847│  trigger): `xtask` reference-gen now DESCENDS THE FULL COMMAND TREE recursively (the durable\n 2848│  remedy), regen published the 22 previously-unrendered leaves + the new section, and a depth\n     │...\n 2870│  sites (known: SURFACE-SECTION-SITED walk, MONIC-TRIGGER-SECTION sited-help unit).\n*2871│- **Ripe when:** next xtask docs-gen touch, or the first adapter filing traceable to a\n 2872│  deep-help divergence.\n 2873│- **Size:** xtask render change + regen + census of self-holding units.\n 2874│- **Kin:** the REQ-CLI-SURFACE-SECTION-SITED pinned walk (the per-REQ closure shape this\n     │...\n 2944│\n*2945│### IR-55 — the `spt --bins` suite wedges partway through on leaked `findstr .` PTY children; the tests at the frontier are casualties, not culprits\n 2946│\n*2947│- **Status:** OPEN, **ARMED-FOR-CAPTURE**, owned by **hertz**. Test/rig defect by the dispatch\n 2948│  split (test/CI rework is never the product builder's). Filed by doyle 2026-08-22 from the\n 2949│  TURNKEY #212 W3 gate on releases#213.\n 2950│- **CORRECTED BY REPLACEMENT the same day.** This entry first named\n     │...\n 2986│  shape as `exit-code-after-a-pipe-is-the-tails`.\n*2987│- **Trigger condition (ripe):** any milestone whose gate wants an unfiltered `spt --bins` sweep,\n 2988│  which is every one of them. Ripe now.\n 2989│- **REMEDY, MEASURED 2026-08-22 and it changes this entry's urgency:** the same 653 tests under\n 2990│  `cargo nextest run -p spt --bins --no-fail-fast` complete in **22.2 seconds, 653 passed, 0\n     │...\n 3070│\n*3071│### IR-56 — `pool-claim` harvests lane identity from CWD, not from `--pool`; a claim run from the wrong tree writes a WRONG RECORD with a success message\n 3072│\n*3073│- **Status:** BUILT 2026-08-24 for the SIGNET #218 golden batch on\n 3074│  `fix/ir56-pool-claim-cwd`, owned by **hertz**. Tooling/rig defect by the dispatch split. Filed by\n 3075│  doyle 2026-08-22 from todlando's TURNKEY #212 W4 Lane 1 field instance — the first confirmation\n 3076│  of the IR-42 mechanism from a LANE rather than from a source read.\n     │...\n 3096│  `branch` name the lane: the success line carries the record, so the check costs nothing.\n*3097│- **Trigger condition:** ripe now — it is a doc/UX fix on a verb we run every lane. Ripest alongside\n 3098│  any other `xtask` pool-verb touch.\n 3099│- **Size guess:** small. Either make the verb REFUSE when cwd is not inside the tree containing\n 3100│  `--pool` (loud, and it cannot be wrong), or print the harvested identity as a distinct confirmed\n     │...\n 3111│\n*3112│### IR-57 — an assembly pick's conflict resolution can silently DROP lines, and every gate run at assembly time is blind to it\n 3113│\n*3114│- **Status:** OPEN, owned by **doyle** (gater craft, not a code defect — no lane to dispatch).\n 3115│  Filed 2026-08-22 from doyle's own defect on the TURNKEY #212 assembly head.\n 3116│- **What happened:** assembly head `5cce533d` **did not compile**, and was carried across a session\n 3117│  boundary as a ready head with \"treqs exit 0\" attached to it. `crates/spt-store/src/access.rs` had\n     │...\n 3165│  produced the verdict classes in the order the entry predicts.\n*3166│- **Trigger condition:** ripe at the next assembly — this is procedure, and its cost is one command\n 3167│  per pick.\n 3168│- **Size guess:** small as a scripted check in `xtask` (fidelity audit over a pick range); zero as\n 3169│  discipline, which is how it is being applied now.\n 3170│\n*3171│### IR-58 — a `[[bin]]` grep is not a census: cargo AUTODISCOVERS `src/bin/*.rs` targets, and a hand-built bin list produced a confident false \"this bin does not exist\"\n 3172│\n*3173│- **Status:** OPEN, unowned. Filed by doyle 2026-08-22; **its original filing was WRONG and is\n 3174│  retracted in full below.** The entry is kept because the way it was wrong is the finding.\n 3175│- **RETRACTED CLAIM, stated plainly so no reader acts on it:** this entry first said that\n 3176│  `crates/spt/Cargo.toml:18-21` and `crates/spt/src/cli.rs:30355` forbid a bin-name collision with\n     │...\n 3200│  answer about a set it never fully saw.\n*3201│- **Trigger condition:** ripe on any `xtask` check work — a duplicate-bin-name check over cargo's\n 3202│  target enumeration (NOT over manifest stanzas) is a handful of lines and cannot go stale.\n 3203│- **Size guess:** small. The prose fix originally proposed here is WITHDRAWN — there was nothing\n 3204│  wrong with the prose.\n 3205│\n*3206│### IR-59 — pool arithmetic: this box holds TWO cold pools, not four; and a build that exhausts the volume reds as a LINKER defect that names no disk\n 3207│\n*3208│- **Status:** OPEN, unowned — it is arithmetic and discipline, not a code lane. Filed by doyle\n 3209│  2026-08-22 from a live disk-floor abort during the TURNKEY #212 W4 gate; footprint figures measured\n 3210│  by todlando the same hour.\n 3211│- **SECOND FACE, measured 2026-08-23/24 (WAX-SEAL #21 W2 gate, doyle — the violator this time):**\n     │...\n 3320│  rides with [[IR-57]]'s scripted pick-fidelity audit as the next milestone's two tooling riders.\n*3321│- **Trigger condition:** ripe now for the log-the-floor half (it rides any gate-script or CI touch);\n 3322│  the arithmetic is discipline and applies immediately.\n 3323│- **Size guess:** small — one line in each rig/gate preflight to record free space alongside the\n 3324│  existing floor check.\n 3325│\n*3326│### IR-60 — a wrapper that CAPTURES a leg's exit status ends with the capture, so the wrapper's own status is the capture's, not the leg's\n 3327│\n*3328│- **Status:** OPEN, unowned — script-shape discipline, not a code lane. Filed by doyle 2026-08-22\n 3329│  during the TURNKEY #212 W5 lane; mechanism measured by todlando, who reported it first as a\n 3330│  possible harness misreport and then RETRACTED that reading himself on a minimal probe.\n 3331│- **The reading that started it:** a background leg was summarised as `exit code 0` while the leg's\n     │...\n 3361│  file.\n*3362│- **Trigger condition:** ripe now — it rides the next gate-script touch, and the gate scripts in this\n 3363│  milestone already write per-leg exit files, which is what makes this discipline rather than debt.\n 3364│- **Size guess:** small — a convention line in the gate-script preamble; no product code.\n 3365│\n*3366│### IR-61 — spacerun's test-module skip carries a SECOND literal tracker; the two answers can drift, and today only a cell stands between them\n 3367│\n*3368│- **Status:** OPEN, unowned, accepted-with-mitigation. Filed by doyle 2026-08-22 at the TURNKEY #212\n 3369│  head gate, as the named residual of the latch repair (the repair itself rides the milestone).\n 3370│- **What the debt is.** `crates/xtask/src/spacerun.rs` now skips a column-0 `#[cfg(test)]` module by\n 3371│  BRACE DEPTH and resumes after its close, rather than latching the scan to end-of-file. Counting\n     │...\n 3393│  scanner accumulating special cases.\n*3394│- **Trigger condition:** the next SUBSTANTIVE change to spacerun's scanning — any new skip, any new\n 3395│  literal form, any change to either tracker. At that point unify, rather than adding a third answer.\n 3396│- **Size guess:** small to medium — one continuous literal-state walk serving both the render pass\n 3397│  and the skip, with the existing corpus and brace cells as the regression net.\n 3398│\n*3399│### IR-62 — an e2e daemon binds well-known ports and collides with the resident fleet on shared runners\n 3400│\n 3401│Filed 2026-08-23 (doyle), from the #212 r2 golden's Windows Phase A red — one witnessed\n 3402│instance, mechanism verified from the run's own capture, filed on the mechanism per the\n     │...\n 3439│\n*3440│### IR-63 — suite-mix sweeps leak job-escaped autostart daemons that LOCK the pool's spt.exe; and the same box conditions manufacture one random victim per sweep\n 3441│\n*3442│- **Status:** OPEN, mitigated-by-rig-step — the reap is adopted discipline, not yet construction.\n 3443│  Filed by doyle 2026-08-24 at the SIGNET #218 gates; first measured by todlando the same day\n 3444│  (his W1 build: four reap rounds of 2, 8, 1, 1 processes, count-by-path stated each round).\n 3445│- **Mechanism, two faces of one condition:** (1) e2e sweeps that exercise autostart leave\n     │...\n 3474│  this entry (brief cites IR-7/17/20/34/35/63); leaves the register when that lane lands.\n*3475│- **Trigger condition:** next rig/gate-script construction touch, or the first golden red that\n 3476│  classifies to face (1).\n 3477│- **Size guess:** small-medium — one wrapper seam plus adopting it in the gate/lane scripts.\n 3478│\n*3479│### IR-64 — HFENDULEAM's disk floor is set by non-CI bulk: ~845 GB of operator payload leaves the golden box ~2 GB of slack against its own 32 GB preflight\n 3480│\n*3481│- **Status:** OPEN · **Origin:** doyle, v0.63.0 close sweep 2026-08-26; mechanism first measured\n 3482│  at the FIELD-SEAL golden window (deployah's IR-31 fifth addendum carries the POOL side of the\n 3483│  same event by agreed division — this entry is the OTHER reservoir, deliberately not his).\n 3484│- **Mechanism:** the 1.86 TB C: carries ~614 GB Steam + ~230 GB Downloads (operator payload, not\n     │...\n 3496│  exists to put in front of them once, with numbers, instead of re-deriving the floor each cut.\n*3497│- **Ripe when:** operator rules on the bulk (move/expand/accept-the-tax), OR the first golden\n 3498│  that dies at the 32 GB preflight despite adopted pool discipline (IR-59's LNK1180-class red).\n 3499│- **Size:** zero code; one operator decision + at most a runbook line naming the chosen floor.\n 3500│\n*3501│### IR-65 — kitsubito kernel-audit backpressure: a tailscale-snap AppArmor denial storm + no auditd turned the default audit backlog into a CI-wide stall amplifier (REMEDIATED AT BOX; re-check triggers named)\n 3502│\n*3503│- **Status:** REMEDIATED-AT-BOX 2026-08-25 (doyle, operator-authorized root — ruling pinned\n 3504│  releases#225 comment 5418800776); entry stays OPEN as the re-check record because the storm\n 3505│  SOURCE persists and two named events can silently revert the fix.\n 3506│- **Mechanism:** `snap.tailscale.tailscaled` (1.92.5) polls /proc and takes an AppArmor\n     │...\n 3524│  `auditctl -s` (expect 32768/0) + one `journalctl -k | grep 'backlog limit'` (expect silence).\n*3525│- **Ripe when:** a re-check trigger fires. **Size:** two read-only commands per check.\n 3526│\n*3527│### IR-66 — first-chunk-needle test class: two latent members remain after the v0.63.0 fix (attach.rs:561, :672)\n 3528│\n*3529│- **Status:** BUILT — confirmed present at `17815c9c` (hertz 2026-09-06); leaves the register at the WEBSERVE close sweep. Hertz rider PR #161, landed ff at `d04b922d` (2026-08-27, IO-PARSER #22\n 3530│  intake rider). Both members got the later-needle treatment (TICK39 delayed past burst on both\n 3531│  OS arms; alt-screen entered before delayed ALT_VIEWPORT_MARKER). Gate: doyle — diff-scope\n 3532│  review; Windows isolated worktree 3× TICK39 PASS + clippy + treqs; Linux CLEAN worktree at the\n     │...\n 3552│  landed mid-r4. Both cells passed r4 (0.010–0.058s) — the members are latent, not failing.\n*3553│- **Ripe when:** next milestone intake (hertz test lane) or the first golden red at ~240s on an\n 3554│  attach cell — either way the mechanism and fix are pre-derived, triage should cite this entry\n 3555│  and skip the RCA. **Size:** two one-line test edits.\n 3556│\n*3557│### IR-67 — wave-battery gap: a `-p spt --bins` leg compiles bin targets as harnesses and runs ZERO integration/e2e tests, so batteries that lean on it carry silent no-coverage legs\n 3558│\n*3559│- **Status:** BUILT — remedy applied across the IO-PARSER #22 milestone (2026-08-27/28): every\n 3560│  wave battery named explicit `-p spt --test <suite>` e2e legs beside the `--bins` unit leg\n 3561│  (GW1..GW5 evidence), every builder evidence report carried a named real e2e per the dispatch\n 3562│  template, and the one filter mistake (a `--test` name not matching its file) REFUSED loudly\n     │...\n 3575│  permits), and any battery doc that lists `--bins` as a coverage leg gets the one-line caveat.\n*3576│- **Ripe when:** next milestone intake (the battery template is touched at every intake).\n 3577│  **Size:** template lines only.\n 3578│\n*3579│### IR-68 — PSYCHE_INGEST_FAIL cause class unproven: git index.lock did NOT reproduce the ingest failure it was blamed for\n 3580│\n*3581│- **Status:** OPEN, investigation-shaped · **Origin:** todlando measurement at the W2 int-leg rig\n 3582│  (IO-PARSER #22, PR #163 at `769fb0a9`, 2026-08-27), reported measure-first; filed by doyle.\n 3583│- **The contradiction:** the six silent `PSYCHE_INGEST_FAIL:todlando` lines observed at the\n 3584│  drop-dir probe (2026-08-25) were attributed to shared-checkout git `index.lock` contention. The\n     │...\n 3601│  files did survive with failed-ingest log lines; what is unproven is the index.lock CAUSE.\n*3602│- **Ripe when:** next PSYCHE_INGEST_FAIL sighting in the field (capture the failing store state\n 3603│  before touching it), or a dedicated probe slot. W2's COMMUNE_FAIL event now pushes a NAMED\n 3604│  reason on every failure, so the next occurrence self-reports its cause — read that first.\n 3605│  **Size:** investigation; no product change until the mechanism is pinned.\n 3606│\n*3607│### IR-69 — inherited stderr tokens can tear between format fragments; 26 test consumers parse that surface as structured truth\n 3608│\n*3609│- **Status:** OPEN, product remedy complete and parked GREEN-AND-READY at `d0fdd58d` on\n 3610│  `feat/emit-single-write`, owned by **todlando**, awaiting golden-batch assembly; board request\n 3611│  releases#241 carries the product remedy and full lane evidence in comment 5461613480. This entry\n 3612│  is the exposure map and census discipline, not the implementation. · **Origin:** CONDUIT #236 r3\n     │...\n 3697│\n*3698│### IR-70 — a hand-built `IoBus` silently omitted later sinks while every gate stayed green\n 3699│\n*3700│- **Status:** OPEN, remedy unscheduled; the v0.65.0 respin fixed the witnessed call site on PR #173.\n 3701│  This entry owns the recurrence class, not that shipped correction. · **Origin:** releases#234,\n 3702│  commit `c5459795167`, CONDUIT #236 respin.\n 3703│- **Mechanism:** `publish_commune_io` constructed `IoBus` itself and registered only the sink it\n     │...\n 3721│  population returns an orderly but incomplete answer).\n*3722│- **Ripe when:** the next `IoBus` construction/API touch, or a new sink registration. **Size:**\n 3723│  small-to-medium assembly-point enforcement plus a real-path population test.\n 3724│\n*3725│### IR-71 — controller-seat release has no persisted breadcrumb, so tests cannot distinguish propagation lag from a missing detach\n 3726│\n*3727│- **Status:** OPEN, observability gap; no remedy scheduled. · **Origin:** CONDUIT #236 r3\n 3728│  `er_brief_once_per_session_e2e` intermittent, classified test-side and fixed on PR #174.\n 3729│- **What/why:** killing rc1 reaps the controller process, but the broker is another process and\n 3730│  notices the socket close later. On that detach edge it clears `driven_by` and `controlled` in\n     │...\n 3745│  completion signal), REQ-HAZARD-CONTROL-STAMP-CONVERGENCE.\n*3746│- **Ripe when:** the next controller lifecycle or structured-breadcrumb touch, or a field timeout\n 3747│  from PR #174's barrier. **Size:** small emitter plus one contract-level assertion.\n 3748│\n*3749│### IR-72 — no product read verb surfaces which process holds a perch or controller seat\n 3750│\n*3751│- **Status:** OPEN, observability gap; no remedy scheduled. · **Origin:** CONDUIT #236 r3\n 3752│  two-host RCA and PR #174 (`70c1a303`), corrected by doyle after IR-18 and daemon-status were\n 3753│  ruled out as different classes.\n 3754│- **Source-verified boundary:** the holder identity already exists in durable/internal records\n     │...\n 3778│  rather than select by enumeration order).\n*3779│- **Ripe when:** the next roster/status read-model change or another rig needs to reap a named\n 3780│  holder. **Size:** small read-model/API addition, medium if seat and perch custody need separate\n 3781│  typed variants.\n 3782│\n*3783│### IR-73 — ci.yml and release.yml still read the free-space floor PRE-checkout (literal-first sites off the golden path); and any job's floor is stale by its last heavy step\n 3784│\n*3785│- **Status:** OPEN, filed by doyle 2026-08-30 at the #242/v0.66.0 close sweep (deployah flag\n 3786│  2026-08-29, widen lane). · **Origin:** the #242 cut lost two golden attempts to exactly this\n 3787│  REQ-CI-FREE-SPACE-PREFLIGHT trap on `golden.yml`'s n1-gate (floor read BEFORE checkout, so the\n 3788│  checkout's own cost lands after the assertion); `golden.yml` is fully reshaped (`ac7d2609`,\n     │...\n 3801│  defect), REQ-CI-FREE-SPACE-PREFLIGHT.\n*3802│- **Ripe when:** next touch of `ci.yml`/`release.yml`, or the next intake's tooling-rider slot\n 3803│  (compose with IR-59/IR-57's standing pair). · **Size:** small — reorder or comment per site,\n 3804│  8 sites.\n 3805│\n*3806│### IR-74 — kitsubito holds 21,643 /tmp endpoint homes: box-side accumulation nothing bounds or measures\n 3807│\n*3808│- **Status:** OPEN, filed by doyle 2026-08-30 at the #242/v0.66.0 close sweep; measurement by\n 3809│  hertz (2026-08-29). · **Origin:** rig work on kitsubito found `/tmp` carrying 21,643 endpoint\n 3810│  homes — per-run spt homes that outlive their runs.\n 3811│- **What/why:** sibling of the [[IR-31]]/[[IR-59]]/[[IR-64]] family (box accumulation the\n     │...\n 3815│  retention), and the reap must state its count so a zero is a claim.\n*3816│- **Ripe when:** next kitsubito rig touch, or the between-milestone box-audit slot.\n 3817│- **Size:** small (one sweep script + adoption in the box's rig steps); the measurement rerun is\n 3818│  one `find | wc`.\n 3819│\n*3820│### IR-75 — traceable-reqs is not installed on kitsubito, so every Linux gate driver's treqs leg exits 127 (vacuous, wrapper-green shape)\n 3821│\n*3822│- **Status:** OPEN, filed by doyle 2026-08-30 at the #242/v0.66.0 close sweep (deployah\n 3823│  co-flagged at intake). · **Origin:** ASM-241 Linux battery — `ASM_treqs.exit` = 127, raw\n 3824│  `env: 'traceable-reqs': No such file or directory`; leg vacuous, covered that day by the\n 3825│  Windows treqs = 0 at the identical tree (treqs is a platform-independent text scan).\n     │...\n 3831│  surface (ruled at the sweep against the enumerating agent's overcautious flag).\n*3832│- **Ripe when:** next Linux gate-driver touch or kitsubito box-audit slot.\n 3833│- **Size:** trivial (install or one driver edit + comment).\n 3834│\n*3835│### IR-76 — hfenduleam is the golden Windows runner AND the builders' box: a local workspace nextest fully contained a golden Phase A and manufactured a load-timing red, and the job-start census cannot see it\n 3836│\n*3837│- **Status:** OPEN, filed by doyle 2026-09-06 during v0.67.1 golden triage (run 34017906638\n 3838│  att2). · **Origin:** the Windows Phase A red on\n 3839│  `spt-store::wtlock_two_process_int two_processes_commit_into_one_worktree_without_failing`\n 3840│  (B hit the 10 s worktree-lock bound while A's six serial commits took 13.5 s; 12 other\n     │...\n 3874│  `wtlock_two_process_int` and `attach_link_push_e2e` (2026-09-06).\n*3875│- **Ripe when:** next driver-template touch (a/b are text; a is one leg), next `ci.yml`\n 3876│  touch for (c) — compose with [[IR-73]]'s reorders; (d) rides the next runbook edit.\n 3877│- **Size:** small — one pre-flight leg + one census predicate + two doc sentences.\n 3878│\n*3879│### IR-77 — nothing stamps the interval between a daemon child's spawn and the brain's first log line, so a readiness-deadline red cannot say WHERE the time went\n 3880│\n*3881│- **Status:** OPEN, filed by hertz 2026-09-07 from the W1 #249 kitsubito battery at the gated\n 3882│  sha `8d980fdf`; doyle-ruled at filing to be a register entry rather than a lane rider. ·\n 3883│  **Origin:** FLAKE-LEDGER `resident_service_e2e` :453 PRECONDITION (53 s) and\n 3884│  `resume_no_control_steal_e2e` (46 s), co-victims of ONE window — nextest exit 100, ONE\n     │...\n 3905│  with a different number, and it would also destroy the only signal this entry wants.\n*3906│- **Ripe when:** the next touch of the daemon boot path or of `brainproc`'s ready stamp; also\n 3907│  ripe as a rider on any lane that re-opens this test family.\n 3908│- **Size:** small — two `emit_line_err!` breadcrumbs and the sentence in the panel that says\n 3909│  what they mean.\n 3910│\n*3911│### IR-78 — `SPT_TEST_EPHEMERAL_ADVISORY_PORTS` silently overrides an explicitly set `SPT_DOCS_PORT`\n 3912│\n*3913│- **Status:** OPEN, filed by hertz 2026-09-07, MEASURED by doyle the same night on his W2\n 3914│  field pair (both boxes). · **Origin:** the 5474 rig-hygiene sweep in\n 3915│  `test/rig-advisory-ports-and-heavy-class`, which sets the rig flag at 37 `spt daemon run`\n 3916│  spawn sites.\n     │...\n 3934│  measured, and neither was the unix path.\n*3935│- **Ripe when:** the next `docshost.rs` touch, or the first time someone sets `SPT_DOCS_PORT`\n 3936│  on a rig and believes it.\n 3937│- **Size:** tiny — one emitted notice.\n 3938│\n*3939│### IR-79 — 22 of the 31 rig binaries leak their daemon tree on a failing assert: teardown is a statement, not a guard\n 3940│\n*3941│- **Status:** OPEN, filed by hertz 2026-09-07 on doyle's dispatch during PR #198's CI window,\n 3942│  from todlando's red 6 (a stale same-port daemon from his own previous run answering the next\n 3943│  one). · **Origin:** PR #198 moved 31 rigs to `SPT_TEST_EPHEMERAL_ADVISORY_PORTS=1`. Under an\n 3944│  ephemeral port a leaked daemon can no longer ANSWER the next run, so that PR is right as it\n     │...\n 4014│  one of the producers), and todlando's red 6.\n*4015│- **Ripe when:** the next lane that touches `crates/spt/tests/common` — the guard belongs there,\n 4016│  not copied 22 times.\n 4017│- **Size:** medium — one guard in `common`, then 22 mechanical adoptions, each provable by\n 4018│  panicking the body under a temporary test and watching the census go quiet.\n 4019│\n*4020│### IR-80 — five leaky cells on ONE module (`brainproc` / `supervise_brain`), Windows only: a candidate PRODUCT leak on the promotion/rollback path, or a cluster of names — nobody has looked yet\n 4021│\n*4022│- **Status:** OPEN, filed by hertz 2026-09-07 07:40Z on doyle's ruling (07:38Z) that this is its\n 4023│  OWN entry and **not** a third face of [[IR-79]] — IR-79 is rig teardown, this is a candidate\n 4024│  defect in the PRODUCT path, so its owner may be todlando rather than the rig lane. ·\n 4025│  **Origin:** noticed while measuring the #198 HEAVY scan-root gap ([[IR-37]] rider 2); the leak\n     │...\n 4078│  teardown LEAK row.\n*4079│- **Ripe when:** the first free Windows box after W2 lands — it is a single-cell census, so it\n 4080│  fits any gap.\n 4081│- **Size:** unknown until the census. Tiny if it is a missing `wait()`; not tiny if the promotion\n 4082│  path leaves a real candidate brain alive on rollback.\n     │...\n 4299│\n*4300│### IR-81 — a process kill can be written scoped or machine-wide, and nothing makes the scoped form the only reachable one: both codebases carry the right pattern beside the wrong one\n 4301│\n*4302│- **Status:** OPEN, drafted by hertz 2026-09-07 08:38Z on doyle's dispatch (08:36Z), from the\n 4303│  fleet-daemon death on hfenduleam at 08:03:15Z ([[RCA-FLEET-DAEMON-14444]], cause still UNNAMED).\n 4304│  Census body: `docs/PID-KILL-CENSUS.md`. · **Origin:** doyle asked which sites kill a REMEMBERED\n 4305│  pid without re-verifying identity AT KILL TIME. The census answered that, and then answered a\n     │...\n 4356│  site in one repo is stronger evidence about PROCESS than either site is about code.\n*4357│- **Ripe when:** the next touch of `spt-store/src/proc.rs` (for remedy 1) or of `xtask check`'s\n 4358│  gate family (for remedy 2). The adapter half is perri's, filed separately, and does not wait\n 4359│  on this.\n 4360│- **Size:** small for remedy 2, medium for remedy 1 (signature + every caller). The census that\n     │...\n 4424│\n*4425│### IR-82 — a daemon death leaves NO record of who died: autostart decides on a socket ping, says \"no daemon\", and the successor overwrites the only handle on the corpse\n 4426│\n*4427│- **Status:** RULED 2026-09-07 11:07Z (doyle), drafted by hertz 11:04Z on doyle's dispatch (11:03Z: *\"the autostart\n 4428│  death-cause item is an IR, not a board item — mint it IR-82 in your thin PR\"*). Register on main\n 4429│  ends at IR-78; 79/80/81 are drafts in the same PR. · **Origin:** the fleet-daemon death on\n 4430│  hfenduleam at 08:03:14.87Z ([[RCA-FLEET-DAEMON-14444]]) whose cause is **still UNNAMED after a day\n     │...\n 4530│\n*4531│### IR-83 — a two-host rig addressed over the tailnet cannot receive INBOUND on Windows, and the whole rig population had only ever run the admitted direction\n 4532│\n*4533│- **Status:** OPEN, minted by hertz 2026-09-07 11:41Z on doyle's dispatch (11:40Z). **Provenance: the\n 4534│  mechanism below is DOYLE'S measurement, not mine** — eight probe arms, each with sender, listener\n 4535│  and output file, recorded in `GATE-W2-272-CHECKLIST.md` rows 11:36Z–11:39Z. I am off cargo on both\n 4536│  boxes and have re-measured none of it; this entry is the register form of his finding plus the\n     │...\n 4663│\n*4664│### IR-84 — the one `PUMP_PEER_FAIL` arm the rigs actually fire was the only one carrying no clock, so the stall that produced it could be counted but never timed\n 4665│\n*4666│- **Status:** OPEN, filed by hertz 2026-09-09 with the instrument that closes its first half. ·\n 4667│  **Origin:** the 65 s two-host helper stall (design written before the run,\n 4668│  `docs/design/RIDER-65S-DESIGN.md`). The number was branch-claimed 2026-09-08 by name only — IR-85\n 4669│  records that it carried no entry text in any register file in any worktree — and this is that text.\n     │...\n 4709│  supervised restart, never a per-peer retry), ADR-0039 Decision 5.\n*4710│- **Ripe when:** now, and it lands with this entry — the stamp is one emit line, tagged\n 4711│  `[impl->REQ-PUMP-STAGE-TRUTH]` at the site. · **Size:** one emit line plus its comment.\n 4712│  **Follow-up, not this lane:** a cell that walks every `PUMP_PEER_FAIL` arm and asserts each one\n 4713│  stamps, so the fifth site added cannot be born silent.\n*4714│### IR-85 — the Windows self-hosted box runs its fs-heavy tests 3-4x slower than a week ago; two CI wall clocks were sized for the old box, and a red run kept hiding it\n 4715│\n*4716│- **Status:** OPEN, filed by hertz 2026-09-09 at the #272/v0.68.0 golden r3/r4 arc, on doyle's\n 4717│  dispatch. Number ruled by doyle from his own census of main@`a2f335f8` (register ended at IR-83;\n 4718│  IR-84 was branch-claimed by name only, with no entry text in any register file in any worktree —\n 4719│  that gap is now closed: **IR-84 was filed 2026-09-09 in PR #213**, so this sentence records the\n     │...\n 4835│  `e2e-leaked-daemons-shared-box` (memory).\n*4836│- **Ripe when:** arm 1 now; arms 2-4 on the operator's answer; arm 5 at the next `golden.yml` touch\n 4837│  after any of them. · **Size:** arm 1 a measurement, arm 4 one census line, arm 5 two literals.\n 4838│- **AMENDMENT 2026-09-09 (two terms this entry did not name when it landed at `d32d5c4c`).**\n 4839│  1. **`ci.yml`'s `changes` job runs `unit` on BOTH runners for every push to `main`.** The classify\n     │...\n 4873│\n*4874│### IR-86 — golden's 32 GiB floor is BELOW the measured 67.4 GiB Windows suite footprint, so a start floor passes a box that cannot finish\n 4875│\n*4876│- **Status:** OPEN, filed by doyle 2026-09-08 at the #272/v0.68.0 golden r2 triage. · **Origin:**\n 4877│  run 34262154550 @ `25e60015` (shaped on `e4444413`), Windows test job 102182665033: every product\n 4878│  step green (Phase A 3346/3346, Phase B 234/234, Summary 2, FAIL 0), the ONLY reds were the two\n 4879│  in-job floor gates. `FLOOR_START` 97,649,786,880 B PASS at 18:47:23Z -> `FLOOR_DOCS`\n     │...\n 4909│  `FLOOR_END`.\n*4910│- **Ripe when:** next `golden.yml` touch (hertz workflow rider slot). · **Size:** small — one\n 4911│  literal per start-floor site + one printed subtraction.\n 4912│\n*4913│### IR-87 — two-host ceremony halves are INDEPENDENT jobs on DIFFERENT runners (A Windows/hfenduleam, B Linux/kitsubito); B's 900 s budget runs on B's own clock, so any older queued Windows job starves A and reds B deterministically, and the panic text blames pairing\n 4914│\n*4915│- **Status:** OPEN, filed by doyle 2026-09-08 at the #272 golden r2 triage. · **Origin:**\n 4916│  run 34262154550, twohost-b job 102207296960 (log 81,692 B, sha256 67403f04…8030): role B built,\n 4917│  rostered, polled PAIR_MEET_UP every 30 s from 19:34:30Z, and hit the rig_wait barrier\n 4918│  \"pairing: A rostered via the daemon-hosted responder\" at its 900 s deadline 19:49:17Z\n     │...\n 4938│  run while one half waits.\n*4939│- **Ripe when:** next `golden.yml`/twohost rig touch. · **Size:** small-medium (job shape or\n 4940│  barrier rework + panic text).\n 4941│\n 4942│- **AMENDMENT 2026-09-10 (releases#294, golden 34445961595 att1 @ `a9e786b2`) — THE STARVING RUN CAN\n     │...\n 4965│\n*4966│### IR-88 — `pool-release` via `cargo run -p xtask` REBUILDS xtask INTO the pool it is releasing, so a reaped pool regrows ~2.8 GB in silence\n 4967│\n*4968│- **Status:** OPEN, filed by doyle 2026-09-08 from hertz's reap report (20:00Z) during the #272\n 4969│  golden r2 repair. · **Origin:** hertz reaped hertz-lane4 / hertz-repin / hertz-percell-id target\n 4970│  subtrees (Length-sum upper bounds 68.16 / 47.11 / 8.79 GB) and then ran `cargo run -p xtask --\n 4971│  pool-release …` from each worktree: cargo rebuilt xtask into the just-reaped `target/` (2.8 GB\n     │...\n 4991│  family, same \"the tool acts on where it stands\" shape), releases#103.\n*4992│- **Ripe when:** next xtask pool-verb touch or the teardown runbook edit. · **Size:** tiny —\n 4993│  one guard or one doc line.\n 4994│\n*4995│### IR-89 — hfenduleam's Windows Firewall drops cold inbound UDP to the runner-built test exes, so the two-host rig's first B→A claim (W2 helper) reds for its whole 900 s budget and the panic blames A\n 4996│\n*4997│- **Status:** BOX HALF **APPLIED** 2026-09-08; WORKFLOW HALF **BUILT** 2026-09-09 — PR #211\n 4998│  (`9b96d7e7` + this amendment), **LANDED-pending-golden**: the `golden.yml` steps are UNEXERCISED\n 4999│  until the next golden run, because thin CI compiles the cells and skips them. Filed by doyle 2026-09-08\n 5000│  at the #272 golden r2 terminal triage; the operator-blocked flag is retired here, because\n     │...\n 5113│  proof; treat the workflow half as landed-pending-golden and not as verified by its own PR.\n*5114│- **Ripe when:** the next GOLDEN run, which is the first thing that exercises the steps — the\n 5115│  code half is built and field-measured (PR #211). (The box half was ripe \"now\" against\n 5116│  `25e60015` and is done; #272 golden acceptance is no longer blocked by it.) · **Size:** one\n 5117│  workflow step remaining; the elevated command is spent.\n     │...\n 5149│\n*5150│### IR-90 — a full disk on the self-hosted box reds a rig as a PRODUCT refusal, not a build error, and no rig or gate records the free space that would falsify it\n 5151│\n*5152│- **Status:** OPEN, filed by hertz 2026-09-09 from the disk-full incident on hfenduleam. ·\n 5153│  **Origin:** the IR-85 discriminator lane's head arm, killed by the volume rather than by the code\n 5154│  under test.\n 5155│- **Symptom:** `spt-daemon::sync concurrent_writes_reconcile_on_elected_node_and_converge` FAILED at\n     │...\n 5236│  gap), `test-profile-pool-outgrows-the-disk-floor`, `free-space-floor-blocks-golden`.\n*5237│- **Ripe when:** now. · **Size:** one assertion plus one error-context append, both test-side.\n 5238│\n*5239│### IR-91 — 561 untracked files sat at the repo root, 18 of them cited by tracked files, and the census that classified them used a corpus that made the discriminator invisible\n 5240│\n*5241│- **Status:** CLOSED by the lane that filed it (the root-scratch classify PR), hertz 2026-09-09 on\n 5242│  doyle's census and rulings. · **Origin:** the `.spt/` ignore lane (PR #212) named 561 untracked\n 5243│  root files as explicitly out of scope; this is that half.\n 5244│- **The population, measured at `2037bcb8`:** `git status --porcelain --untracked-files=all` = **561\n     │...\n 5289│  never a repo path), `ignoring-a-directory-buries-what-the-repo-cites-in-it` (memory).\n*5290│- **Ripe when:** landed with this entry. · **Size:** one `.gitignore` stanza, 18 adds, 543\n 5291│  preserved files, no deletions.\n 5292│\n*5293│### IR-92 — the message that WAKES an idle spt-hosted endpoint rides a delivery leg that never publishes MSG_IN, so a woken agent's own funnel holds none of the messages that woke it\n 5294│\n*5295│- **Status:** OPEN — filed doyle 2026-09-09 from hertz's census, probe and proposed text (his by\n 5296│  role; the recorder read and the REQ reading are doyle's). Fix lane unassigned: product change in\n 5297│  `spt-daemon` (todlando), test-side legs (hertz). · **Origin:** a 22:35Z empty `<msg from=\"hertz\"/>`\n 5298│  turn trigger after the #292 daemon restart, chased for its body; the body was in a spill file, and\n     │...\n 5338│  the greens is deployah's.)\n*5339│- **Status of that red: UNEXPLAINED between DELAYED and ABSENT publication.** Path B makes the race\n 5340│  MECHANICALLY AVAILABLE, which is more than \"not excluded\" — but availability is not occurrence,\n 5341│  and one observation does not separate them. Kinship to this entry stays a HYPOTHESIS. The cell is\n 5342│  in neither `docs/FLAKE-LEDGER.md` nor this register (0 hits each): an unregistered signature.\n     │...\n 5413│  a restart), memory `an-empty-msg-from-tag-is-a-turn-trigger-whose-body-lives-in-the-spill`.\n*5414│- **Ripe when:** any lane touches `spt-daemon::inject` or the IO funnel; small enough to ride the\n 5415│  next product batch. · **Size:** one publish call at one chokepoint, one unit cell, one `int` leg\n 5416│  (a hook-hosted receiver woken by a `SENT`, then `io-events` replayed for the msg-id).\n 5417│\n*5418│### IR-93 — no PDB ships beside the installed `spt` binary, so the one non-invasive read of a wedged production daemon comes back without a single named frame\n 5419│\n*5420│- **Status:** OPEN, filed by doyle 2026-09-10. **The number was reserved by NAME on 2026-09-09** at\n 5421│  the #293 mechanism read (\"PDB ask -> IR-93 at next sweep\") and this entry closes that claim — a\n 5422│  name-only IR with no entry text is the exact gap [[IR-85]]'s status line had to spend a paragraph\n 5423│  explaining about IR-84, and it is not being left open a second time. · **Origin:** the #293 pump\n     │...\n 5443│  cannot say how much it burned).\n*5444│- **Ripe when:** next installer / release-packaging touch. · **Size:** packaging (profile + install\n 5445│  layout), no product code.\n 5446│\n*5447│### IR-94 — xtask's brainread deadline gate cannot SEE `serve_sync`: its registry is three hand-listed files and its predicate is a name shape, so a stream server outside both got the reply form and the gate stayed green\n 5448│\n*5449│- **Status:** OPEN, filed by doyle 2026-09-10 at the releases#294 / v0.69.0 golden RED triage. **This\n 5450│  is an INDEPENDENT gate finding, not the cause of that red** — it was found while reading the\n 5451│  milestone's diff and stands whatever Finding 1 turns out to be. · **Origin:**\n 5452│  `xtask/src/brainread.rs`, new this milestone (the #293 fix's zero-call-site guard).\n     │...\n 5473│  makes this inert today), `REQ-BRAIN-READ-BOUNDED-PER-CALL`.\n*5474│- **Ripe when:** next `brainread`/xtask touch, **and mandatorily BEFORE `serve_sync` is migrated to a\n 5475│  bounded carrier.** · **Size:** small.\n 5476│\n*5477│### IR-95 — a burned polling budget names WHAT it wanted and never HOW LONG it waited, so no run, green or red, can say how close it came\n 5478│\n*5479│- **Status:** OPEN, filed by doyle 2026-09-10 at the releases#294 golden RED, where it cost this\n 5480│  triage most of a morning and four agents. · **Origin:** the two Windows Phase A failures at\n 5481│  `a9e786b2`, both polling budgets burned rather than value mismatches.\n 5482│- **The two sites, read at source.** They are not even the same KIND of budget, which is the first\n     │...\n 5727│  readiness red cannot say where the time went), [[IR-90]].\n*5728│- **Ripe when:** with the releases#294 instrumented base-vs-head comparison, which **cannot be run\n 5729│  without it** — the experiment's whole output is the margins these sites do not print. ·\n 5730│  **Size:** small per site; the census is the larger half.\n 5731│\n*5732│### IR-96 — the `daemon_stop_convoy_e2e` API-storm cell fails 3-of-3 under the HEAVY suite at the diagnostic tree while passing at the candidate in golden CI, and nothing yet separates instrumentation from box from product\n 5733│\n*5734│- **Status:** OPEN, **cause-unclassified** (todlando's and hertz's stipulation, adopted verbatim — a\n 5735│  triage placement here is NOT a finding of non-defect).\n 5736│- **Origin:** releases#294 / v0.69.0 Arm B, 2026-09-10, deployah executing at diagnostic tree\n 5737│  `ed8ecd94` (= candidate `a9e786b2` + the unlanded sync instrumentation, never merged).\n     │...\n 5750│- **Confounded by IR-97** (below): the three runs were not equivalent conditions.\n*5751│- **Ripe when:** any lane touches daemon stop/start convoy behaviour, OR a golden run reds this cell\n 5752│  at a candidate, OR someone runs the cell at `a9e786b2` under the same local HEAVY workload — that\n 5753│  last one is the cheap discriminator and nobody has run it. · **Size:** one targeted local run to\n 5754│  discriminate; unknown beyond that.\n 5755│\n*5756│### IR-97 — a suite that leaks a fixed cohort of child processes per invocation makes consecutive runs non-comparable, and the between-run accounting the protocol required was not enforced\n 5757│\n*5758│- **Status:** OPEN. **Protocol deviation** (hertz's framing, and it is stronger than \"confounder\":\n 5759│  the protocol ALREADY required between-run accounting — execution did not enforce it, so the fix is\n 5760│  enforcement, not a limitations paragraph).\n 5761│- **Origin:** releases#294 Arm B, 2026-09-10. Derived by doyle from deployah's preserved\n     │...\n 5779│  fleet including the gater's own session.\n*5780│- **Ripe when:** any repeated-run experiment is designed on this box — census BETWEEN runs, not only\n 5781│  at the end. · **Size:** a between-run census step plus a scoped reap in the harness."},"isError":false,"timestamp":1789094604338}}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_RjOILJi8oXwvNWmFdXU4dCPC|fc_065c0d1976ecf9c2016aa36ad0793c87d1a4ed1fb473d15dbe","toolName":"read","startedAt":"2026-09-11T02:43:30.887Z","args":{"path":"docs/INFRA-REGISTER.md:4144-4663:raw"},"intent":"Reading leak and custody endings"},"id":"05a94739","parentId":"b13a6a12","timestamp":"2026-09-11T02:43:30.887Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_isrSVpRThwn8DnhR42nVpYw9|fc_065c0d1976ecf9c2016aa36ad0795087d1aec3c60d771a2ed8","toolName":"read","startedAt":"2026-09-11T02:43:30.888Z","args":{"path":"docs/INFRA-REGISTER.md:4664-5149:raw"},"intent":"Reading workflow capacity entries"},"id":"71b9e171","parentId":"05a94739","timestamp":"2026-09-11T02:43:30.888Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_OetHQWIjLwC0fSOEY4gWm7I0|fc_065c0d1976ecf9c2016aa36ad0795887d19b8f10efcf1f3f34","toolName":"read","startedAt":"2026-09-11T02:43:30.888Z","args":{"path":"docs/INFRA-REGISTER.md:5150-5481:raw"},"intent":"Reading release investigation entries"},"id":"06af222f","parentId":"71b9e171","timestamp":"2026-09-11T02:43:30.888Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_IZtPuIzzW6suje5HQLQPZ5oP|fc_065c0d1976ecf9c2016aa36ad0795c87d1b8e4ea5b47e2bd2c","toolName":"read","startedAt":"2026-09-11T02:43:30.888Z","args":{"path":"docs/INFRA-REGISTER.md:5482-5781:raw"},"intent":"Reading final investigation details"},"id":"954a2de4","parentId":"06af222f","timestamp":"2026-09-11T02:43:30.888Z"}
{"type":"message","id":"ce2faec8","parentId":"954a2de4","timestamp":"2026-09-11T02:43:30.888Z","message":{"role":"assistant","content":[{"type":"toolCall","id":"call_RjOILJi8oXwvNWmFdXU4dCPC|fc_065c0d1976ecf9c2016aa36ad0793c87d1a4ed1fb473d15dbe","name":"read","arguments":{"i":"Reading leak and custody endings","path":"docs/INFRA-REGISTER.md:4144-4663:raw"},"intent":"Reading leak and custody endings"},{"type":"toolCall","id":"call_isrSVpRThwn8DnhR42nVpYw9|fc_065c0d1976ecf9c2016aa36ad0795087d1aec3c60d771a2ed8","name":"read","arguments":{"i":"Reading workflow capacity entries","path":"docs/INFRA-REGISTER.md:4664-5149:raw"},"intent":"Reading workflow capacity entries"},{"type":"toolCall","id":"call_OetHQWIjLwC0fSOEY4gWm7I0|fc_065c0d1976ecf9c2016aa36ad0795887d19b8f10efcf1f3f34","name":"read","arguments":{"i":"Reading release investigation entries","path":"docs/INFRA-REGISTER.md:5150-5481:raw"},"intent":"Reading release investigation entries"},{"type":"toolCall","id":"call_IZtPuIzzW6suje5HQLQPZ5oP|fc_065c0d1976ecf9c2016aa36ad0795c87d1b8e4ea5b47e2bd2c","name":"read","arguments":{"i":"Reading final investigation details","path":"docs/INFRA-REGISTER.md:5482-5781:raw"},"intent":"Reading final investigation details"}],"api":"openai-codex-responses","provider":"openai-codex","model":"gpt-6-astra","usage":{"input":35352,"output":157,"cacheRead":19584,"cacheWrite":0,"totalTokens":55093,"cost":{"input":0,"output":0,"cacheRead":0,"cacheWrite":0,"total":0}},"stopReason":"toolUse","timestamp":1789094604388,"responseId":"resp_065c0d1976ecf9c2016aa36aca81a887d1bd2939049bdb58f4","providerPayload":{"type":"openaiResponsesHistory","provider":"openai-codex","dt":true,"items":[{"id":"fc_065c0d1976ecf9c2016aa36ad0793c87d1a4ed1fb473d15dbe","type":"function_call","status":"completed","arguments":"{\"i\":\"Reading leak and custody endings\",\"path\":\"docs/INFRA-REGISTER.md:4144-4663:raw\"}","call_id":"call_RjOILJi8oXwvNWmFdXU4dCPC","internal_chat_message_metadata_passthrough":{"turn_id":"cb1368d9-2a08-40c0-9f68-e06c6338cbd5"},"name":"read","metadata":{"turn_id":"cb1368d9-2a08-40c0-9f68-e06c6338cbd5"}},{"id":"fc_065c0d1976ecf9c2016aa36ad0795087d1aec3c60d771a2ed8","type":"function_call","status":"completed","arguments":"{\"i\":\"Reading workflow capacity entries\",\"path\":\"docs/INFRA-REGISTER.md:4664-5149:raw\"}","call_id":"call_isrSVpRThwn8DnhR42nVpYw9","internal_chat_message_metadata_passthrough":{"turn_id":"cb1368d9-2a08-40c0-9f68-e06c6338cbd5"},"name":"read","metadata":{"turn_id":"cb1368d9-2a08-40c0-9f68-e06c6338cbd5"}},{"id":"fc_065c0d1976ecf9c2016aa36ad0795887d19b8f10efcf1f3f34","type":"function_call","status":"completed","arguments":"{\"i\":\"Reading release investigation entries\",\"path\":\"docs/INFRA-REGISTER.md:5150-5481:raw\"}","call_id":"call_OetHQWIjLwC0fSOEY4gWm7I0","internal_chat_message_metadata_passthrough":{"turn_id":"cb1368d9-2a08-40c0-9f68-e06c6338cbd5"},"name":"read","metadata":{"turn_id":"cb1368d9-2a08-40c0-9f68-e06c6338cbd5"}},{"id":"fc_065c0d1976ecf9c2016aa36ad0795c87d1b8e4ea5b47e2bd2c","type":"function_call","status":"completed","arguments":"{\"i\":\"Reading final investigation details\",\"path\":\"docs/INFRA-REGISTER.md:5482-5781:raw\"}","call_id":"call_IZtPuIzzW6suje5HQLQPZ5oP","internal_chat_message_metadata_passthrough":{"turn_id":"cb1368d9-2a08-40c0-9f68-e06c6338cbd5"},"name":"read","metadata":{"turn_id":"cb1368d9-2a08-40c0-9f68-e06c6338cbd5"}}]},"duration":6497.13560000062,"ttft":6440.696000000462,"completedAt":1789094610886,"contextSnapshot":{"promptTokens":54936,"nonMessageTokens":10400,"compactionEpoch":0}}}
{"type":"message","id":"9f116758","parentId":"ce2faec8","timestamp":"2026-09-11T02:43:30.895Z","message":{"role":"toolResult","toolCallId":"call_OetHQWIjLwC0fSOEY4gWm7I0|fc_065c0d1976ecf9c2016aa36ad0795887d19b8f10efcf1f3f34","toolName":"read","content":[{"type":"text","text":"### IR-90 — a full disk on the self-hosted box reds a rig as a PRODUCT refusal, not a build error, and no rig or gate records the free space that would falsify it\n\n- **Status:** OPEN, filed by hertz 2026-09-09 from the disk-full incident on hfenduleam. ·\n  **Origin:** the IR-85 discriminator lane's head arm, killed by the volume rather than by the code\n  under test.\n- **Symptom:** `spt-daemon::sync concurrent_writes_reconcile_on_elected_node_and_converge` FAILED at\n  67.588 s with a panic in our own test at `crates\\spt-daemon\\tests\\sync.rs:198`:\n  `pull: Custom { kind: Other, error: \"sync refused: bundle failed: git -C <tmp>\\tracked-b\\.seed.git\n  bundle create <tmp>\\scratch\\serve\\serve-pull-6.bundle ^d12a7134... a-doyle failed (exit Some(1)):\n  fatal: sha1 file '<stdout>' write error. Out of diskspace\\nerror: pack-objects died\" }`, then a\n  second panic at `:213` (`pull thread: Any { .. }`) as the harness thread unwound.\n- **Cause:** `C:` was at **0.018 GiB free of 1862.02 GiB (0.00%)** at that instant\n  (`Win32_LogicalDisk`, 10:57Z). `git bundle create` could not write; the daemon's serve path turned\n  that into its real product refusal string `sync refused: bundle failed`; the test asserted on the\n  refusal. **Every layer behaved correctly, and the report reads as a sync regression at the sha\n  under test.**\n- **Why it is worse than the disk faces already known:** the two banked faces\n  (`disk-full-reds-as-lnk1318-pdb-error`) are TOOLCHAIN costumes — `LNK1318` at link, and rustc\n  I/O before any link — and both route a reader to \"the box is sick\". This one routes to a CODE\n  OWNER: it names our file, our line and our refusal string, and the disk word sits in the FOURTH\n  nested clause behind a git exit code. It arrived mid-discriminator with an old sha and a new sha\n  side by side, where the cheapest reading — \"the head arm failed, the old arm passed\" — is a\n  head regression that does not exist.\n- **Blast radius, same incident:** the volume also carried a live `unit (self-hosted, Windows,\n  hfenduleam)` job (run 34341010297) compiling into it, which completed FAILURE on its own and was\n  ruled VOID after the fact. doyle's cancel of THAT run returned `Cannot cancel a workflow run that\n  is completed` — recorded because a register that credits a controlled action nobody performed\n  teaches the next reader that the box was under control. (The earlier run 34337797758, in\n  **IR-85**'s amendment, is a different run with a different ending: CANCELLED at the job wall. One\n  register putting one cancel string on the wrong run is the same defect, one run over.) `spt daemon status` went to peer pump last tick 185 s with 24 brain\n  subscribers stall-evicted (last evict 10:51:22Z, inside the disk window), with an operator restart\n  under consideration — a restart that risks the releases#287 shell stranding and that, had it\n  appeared to help, would have taught everyone the wrong cause.\n- **⚠ Two things that looked like disk fallout and are NOT**, recorded so this entry does not\n  overclaim. (a) `serve list` returning `SERVE_UNCONFIRMED`: doyle read it from source —\n  `servehost.rs` and `KIND_SERVE_REQUEST` are ABSENT at 0.67.0/0.67.1 and were minted by 0.68.0, and\n  the resident broker is still the 0.67.0 image after the brain-only flip, so the CLI's 10 s bound\n  times out **by design** against an older daemon. (b) `peer reachability: DEGRADED, 4 of 7 peers\n  unreachable for 882775 s` — 10.2 days, predating the incident entirely. Even the pump term is\n  claimed as CONCURRENT, not caused: hertz called the pump recovered off ONE post-reclaim sample\n  (54 s) and doyle falsified it two minutes later (133 s), because a single reading of a monotonic\n  \"last tick N s ago\" counter cannot separate STILL TICKING from TICKED ONCE, and a fresh project\n  index proves the coordinator loop, not the pump.\n- **Remedy — one guard, two placements, and it REFUSES rather than runs:**\n  1. **Rig start.** For the two-host rig and any test rig that shells out to `git bundle` or writes a\n     store: read free space on the volume holding the rig's temp root and `target`, and under a floor\n     fail immediately with a message that says DISK and prints the number — never enter the\n     ceremony. Floor: start at **10 GiB**, above the largest single artifact these rigs write and far\n     below any healthy state of this box; tune only with a measurement.\n  2. **Failure text**, for the case where space runs out MID-run and no start check can catch it:\n     when a shelled-out git/store operation fails, append the current free space to the error before\n     it becomes a product refusal string, so the panic that reaches a human already carries the\n     falsifier.\n- **WHY BOTH, measured rather than argued (hertz, 2026-09-09, the #209 lane):** a floor read ONCE at\n  rig start would have PASSED that run and the run still ended nearly empty — `cargo check` started\n  at **136.32 GiB** free, the test-profile build of 221 binaries took it to **40.18 GiB in ten\n  minutes**, the legs finished at **16.24 GiB**, and it read **12.27 GiB** ninety seconds later. A\n  start-only guard is a guard against yesterday's disk. That last ~4 GiB fell with those legs already\n  terminal; the candidates are the runner's CI job and its `_work` tree, unsampled and therefore\n  UNATTRIBUTED.\n- **The record itself, and the only one that caught the dip (hertz, 2026-09-09):**\n  `.spt/preserved/hertz-leak-670-legs/disk-full-trace.log` — **139 samples, 11:52:46Z–13:57:07Z, one\n  per minute**, max **238.41 GiB** @12:45:20Z, min **12.53 GiB** @12:12:45Z. Two samples fall under\n  15 GiB — **14.85** @12:12:11Z and **12.53** @12:12:45Z — both inside the #209 leak lane's\n  build-and-teardown window, i.e. AFTER a start floor would have passed the run at **136.15 GiB**\n  (the window's first sample). Two caveats, both binding on any reading of it: **the true minimum is\n  unbounded below 12.53 — the sampler cannot see between its samples**, and **it attributes nothing:\n  hertz's own legs and the runner's CI job are indistinguishable in it.** It is the SECOND instrument\n  on this incident and the only one covering the dip: doyle's 30 s trace, preserved at\n  `.spt/preserved/ir90-free-space-trace-2026-09-09/free-sampler-12-13Z-to-12-28Z.txt`, runs\n  12:15:37Z–12:31:10Z and so begins after hertz's reap — it records the RECOVERY, this one records\n  the FALL. sha256 `d58ce838b677e62d4a017e77524f899fda81e7bacf73a0e2a05a1192e60abaf2`\n  (doyle's, `8bdae01bc151597070d7011443a2cdc74614232dbc962faec1b1b1833c71f22a`).\n- **Explicitly NOT the remedy:** a bigger disk, or a reap schedule. ~195 GiB of headroom was consumed\n  by ordinary work, ACCRUED across a ~45-minute build phase; **no reading bounds a rate** — the\n  free-space observations either side are endpoints of an accrual, and a rate derived from them\n  retargets a hunt (deployah's went to runaway logs, VSS and torrent preallocation on the strength of\n  a `>150 MB/s` derived that way, while the measured live box-wide write rate was ~1.5 MB/s). What\n  consumed it: two `cargo nextest run -E <5-test filter>` lanes at **82.88** and **64.44 GiB** — a\n  filter narrows the RUN, never the BUILD, and both built 221 test binaries under the `test` profile\n  — plus 40.93 GiB of `C:\\actions-runner\\_work` and 9.8 GiB of `%TEMP%`. Any headroom this box\n  has is two cold pools away from gone, so the guard must be a REFUSAL, not a budget.\n- **Kin:** **IR-85** (the same box's fs-heavy slowdown; a near-full volume is now a named environment\n  term there), **IR-86** (a start floor that passes a box which cannot finish — the same defect one\n  layer up, and this entry is its mid-run half), **IR-76** (the golden runner is the operator's\n  desktop), `disk-full-reds-as-lnk1318-pdb-error` (memory; this is its third face and its standing\n  gap), `test-profile-pool-outgrows-the-disk-floor`, `free-space-floor-blocks-golden`.\n- **Ripe when:** now. · **Size:** one assertion plus one error-context append, both test-side.\n\n### IR-91 — 561 untracked files sat at the repo root, 18 of them cited by tracked files, and the census that classified them used a corpus that made the discriminator invisible\n\n- **Status:** CLOSED by the lane that filed it (the root-scratch classify PR), hertz 2026-09-09 on\n  doyle's census and rulings. · **Origin:** the `.spt/` ignore lane (PR #212) named 561 untracked\n  root files as explicitly out of scope; this is that half.\n- **The population, measured at `2037bcb8`:** `git status --porcelain --untracked-files=all` = **561\n  `??` rows, all at the repo root, zero in subdirectories**, 50,034,994 bytes (47.7 MiB). By\n  extension: 268 `.raw`, 184 `.exit`, 87 `.md`, 7 `.out`, 4 `.log`, 4 `.done`, 2 `.txt`,\n  2 `.stackdump`, 2 `.sh`, 1 `.py`. **A `git add -A` at the root staged every one of them**, which\n  is the same landmine `.spt/` carried before #212 and the reason this is one arc in two lanes.\n- **⚠ THE FINDING, and it is about the CENSUS, not the files:** the first classification put two\n  cited files in the \"bury\" class. `W3-196-CENSUS.md` and `WEBSERVE-272-JIT.md` were recorded as\n  \"cited only from other root scratch\" — citing files `W3-196-JIT.md` and `W3-272-MEASUREMENTS.md`,\n  which are **TRACKED**. The census corpus was tracked-only, so **every hit it produced was a\n  tracked citation by construction**; the two were then relabelled by their PATH, because a `.md`\n  sitting at the repo root reads as scratch. **The discriminator is TRACKED-OR-NOT, never\n  ROOT-OR-NOT** — and a corpus that can only return tracked hits cannot tell you which of its own\n  hits are tracked, because it has already thrown away the distinction. Burying those two would have\n  left two tracked files citing paths that no longer existed: the `launch-battery.py` mechanism from\n  **IR-90**'s sibling lane with the sides swapped, caught here only because the burial list was\n  re-verified against the corpus a second time by a different reader.\n- **The second finding, which withdrew the lane's own destinations:** the repo root **already holds\n  140 tracked files, 134 of them `.md`, 25 with `JIT` in the name** — `IDLE-EDGE-JIT.md`,\n  `W3-196-JIT.md`, `WEBSERVE-272-W2-JIT.md`, every `M*-PLAN.md`, `MESH-D*-PLAN.md`,\n  `RESTORATION-D*-PLAN.md`. **The house convention is measured, not assumed: a plan or record lives\n  at the repo root and is TRACKED.** The first ruling would have relocated the cited files into\n  `docs/intake/`, `docs/design/` and `docs/gate-records/` — splitting siblings across two homes\n  (`WEBSERVE-272-W2-JIT.md` at root, `WEBSERVE-272-W3-DRIFT-RIDERS.md` in `docs/intake/`) and\n  repointing 18 citation lines to buy that split. **Destinations withdrawn; the 18 are tracked where\n  they are.** Zero moves, zero repoints, zero sha-transfer risk. A lane that tidies against a\n  measured convention is not tidying.\n- **THE RULE, which is what this entry is for:** *a plan or record cited from a tracked file is\n  itself tracked, at the path the citation already names.* The root is a legal home. What decides a\n  file's fate is whether the repo points at it — not where it sits, not what it is called, and not\n  whether it looks like scratch.\n- **What the lane did:** **18 Class A** files `git add`ed in place. **473 Class B** gate legs\n  (`.raw`/`.exit`/`.done`/`.log`/`.out`/`.stackdump`/`.sh`/`.txt`, zero tracked citations, each\n  word-bounded against the whole 911-file tracked corpus) **MOVED — not deleted** — to\n  `.spt/preserved/root-gate-legs-2026-09-09/` with a sha256 manifest, every file hashed before and\n  after the move. **70 Class C** uncited `.md` likewise to `.spt/preserved/root-md-2026-09-09/`.\n  Then five **root-anchored** ignore lines: `/*.raw` `/*.exit` `/*.done` `/*.out` `/*.stackdump`.\n- **Why those five and not more.** Legs are the one class whose FUTURE instances are scratch **by\n  construction**, so ignoring them institutionalizes no loss. `/*.md`, `/*.log`, `/*.sh` and\n  `/*.txt` are deliberately NOT ignored: a plan or script dropped at the root must keep showing as\n  `??` so the next census classifies it — **that is exactly the pattern that produced this repo's\n  140-file tracked root corpus**, and an ignore line there would hide the next one. The anchoring is\n  load-bearing and was proved with a negative control: `crates/probe.raw` is **not** ignored, which\n  an unanchored `*.raw` would have swallowed.\n- **Kin:** the `.spt/` ignore lane (PR #212 — same arc, and its `launch-battery.py` case is why\n  nothing here was deleted), **IR-90** (a citation into `.spt/preserved/` is machine-bound evidence,\n  never a repo path), `ignoring-a-directory-buries-what-the-repo-cites-in-it` (memory).\n- **Ripe when:** landed with this entry. · **Size:** one `.gitignore` stanza, 18 adds, 543\n  preserved files, no deletions.\n\n### IR-92 — the message that WAKES an idle spt-hosted endpoint rides a delivery leg that never publishes MSG_IN, so a woken agent's own funnel holds none of the messages that woke it\n\n- **Status:** OPEN — filed doyle 2026-09-09 from hertz's census, probe and proposed text (his by\n  role; the recorder read and the REQ reading are doyle's). Fix lane unassigned: product change in\n  `spt-daemon` (todlando), test-side legs (hertz). · **Origin:** a 22:35Z empty `<msg from=\"hertz\"/>`\n  turn trigger after the #292 daemon restart, chased for its body; the body was in a spill file, and\n  the chase exposed that neither agent's io-events log held the messages that woke it.\n- **THE TWO PUBLISH SITES ORDER THEMSELVES OPPOSITELY — read at `de5a44bc`, 2026-09-10, from the\n  bare-baseline red on `io_events_undriven_kinds_e2e` (golden 34467873057, Linux Phase A).** The\n  count below is right and the ORDERING is what this entry was missing:\n  · **PATH A, hook poll** (`delivery.rs`): `poll_drain()` publishes EVERY delivered row (`:757`) and\n    RETURNS them; its only caller `cmd_poll` (`:660`) then loops `emit_event` over the returned rows.\n    **Publication happens-before presentation**, strictly. An immediate log read after observed\n    presentation is CONTRACT-CORRECT here, and a bounded retry on this path WOULD conceal a real\n    violation. **Leave Path A alone.**\n  · **PATH B, the relay** (`startup.rs:1057`, the `deliver` closure): `emit(id, from, body)` — the\n    presentation — runs, and `publish_msg_io(...MSG_IN...)` runs AFTER it, per message, in the same\n    closure; the closure's own comment records that \"Both backlog (after notif validity) and live TCP\n    reach this edge.\" **Presentation happens-before publication.**\n  A test that detects presentation by reading the listener child's STDOUT through a pipe and then\n  reads the io-events log immediately is therefore **racy BY CONTRACT on Path B** — publication for\n  that message runs after its emit, in the child, and the pipe read can win. A bounded wait on the\n  log is permitted on Path B: **it does not weaken any publication-before-presentation guarantee\n  there, because there is none** (hertz's and todlando's narrowing — NOT \"conceals nothing\": the\n  wait still DEFINES WHICH PUBLICATION DELAYS THE TEST ACCEPTS, and it does not establish why any\n  given execution missed a row). A timeout would establish \"not published within the bound\", never\n  \"never publishes\", and cannot alone identify this entry's defect.\n- **A SECOND, INDEPENDENT DEFECT IN THAT CELL'S ASSERTION, true regardless of the above.**\n  `io_events_undriven_kinds_e2e.rs:818` asserts exact-once as\n  `vec![(\"MSG_IN\", Some(AUTHOR)), (\"MSG_IN\", Some(AUTHOR))]` — a `(kind, author)` pair per row, and\n  **both rows are identical**, so the assertion cannot tell the backlog row from the live row and\n  **two BACKLOG rows would satisfy it**. The identities exist and are already stamped:\n  `publish_msg_io_local` carries `.with_msg_id(msg_id_of(body))` — the short ID the failing panel\n  itself printed. Exact-once belongs per MESSAGE ID, not per author.\n  **AND IT CUTS BACKWARDS, WEAKENING EVERY GREEN THIS CELL HAS EVER RETURNED (deployah, on\n  arm-comparability grounds — the point nobody else had drawn):** the three PASSING executions of\n  this cell in the instrumented pair (base linux 3.612 s, head linux 2.343 s, head windows 16.411 s)\n  did **NOT** establish that both relay arms published. They established that two rows matching\n  `(MSG_IN, alice)` were present at read time. A green here is a WEAKER fact than it reads as — the\n  verdict stands in for a measurement the assertion never made. So \"both Linux legs were green\n  across the instrumented pair\" does not become FALSE, it becomes NARROWER than it was being used\n  for: it is a statement about the ASSERTION's outcome, not about publication. It does **not** make\n  the bare red likelier to be a product defect, does not classify anything, and does not separate\n  the race from non-publication — it removes a comparison the RCA was implicitly leaning on.\n  (Raised independently by hertz and todlando as an assertion defect; its backwards consequence for\n  the greens is deployah's.)\n- **Status of that red: UNEXPLAINED between DELAYED and ABSENT publication.** Path B makes the race\n  MECHANICALLY AVAILABLE, which is more than \"not excluded\" — but availability is not occurrence,\n  and one observation does not separate them. Kinship to this entry stays a HYPOTHESIS. The cell is\n  in neither `docs/FLAKE-LEDGER.md` nor this register (0 hits each): an unregistered signature.\n- **The mechanism, read at `de5a44bc`:** `MSG_IN` has exactly two publish sites in the tree —\n  `crates/spt/src/api/delivery.rs:757` (`publish_msg_io_local`, reached only from `poll_drain`, the\n  hook-poll leg, `TakerLeg::HookPoll`) and `crates/spt/src/api/startup.rs:1064` (`publish_msg_io`\n  inside the `api listen` relay's `deliver` sink — the Monitor-stream surface a hook-hosted session\n  never uses). **The spt-hosted inject leg reaches neither.** `crates/spt-daemon/src/inject.rs:75`\n  `try_spt_hosted_inject` renders the envelope and hands it to `brain.inject_endpoint`; the file has\n  zero `publish_msg_io` / `iobus` / `IO_KIND_MSG_IN` references in 343 lines (control: `TakerAudit`\n  / `claim_idle_edge_at` hit, so the grep is live). Every caller delivers through it unobserved:\n  `cli.rs:11739` send-time direct inject when the broker reports the target IDLE (the sender is\n  answered `SENT`), `cli.rs:11684` `--force-native`, `inject.rs:168` `drain_spool_offering` (the\n  idle-EDGE drain `delivery.rs:801`, the send-time already-idle re-offer, the pulse-tick belt, and the\n  native ER-briefing arm), and `wan.rs:822` / `:1173` WAN ingress. Two more drain edges are silent by\n  the same shape and did not fire here: `cmd_poll_shell` (`delivery.rs:705`, shell surface) and\n  `cmd_worker_poll` (`worker.rs:138`, worker surface). A call-site grep would have marked `relay.rs`\n  silent too — it publishes through its sink one crate up — so \"does this edge observe\" is answered\n  by following the row to a bus, never by grepping the edge.\n- **The rule it produces (hertz's refinement, measured across both logs):** for a hook-hosted live\n  agent (`is_spt_hosted_no_relay`), **`SENT` to an idle peer → direct inject → NEVER recorded on\n  the peer** (deterministic). **`QUEUED` → recorded IFF the hook poll takes the row.** One stamped\n  census, **as of 23:04Z 2026-09-09** (the counts grow with every message, so an unstamped figure is\n  stale on arrival): SENT-to-idle unrecorded on the receiver **12/12** (hertz’s five to doyle, doyle’s\n  seven to hertz — the seventh being the message that announced this filing, delivered by the defect\n  it named); QUEUED recorded **8/8**, every one drained mid-tool. Each side’s absence census matched\n  the other side’s verdict log without either seeing the other’s data.\n  by the caller census a spooled row can also be taken by the send-time already-idle re-offer or the\n  pulse-tick belt (`inject.rs:168`, unrecorded), so a `QUEUED` row’s fate is decided by the TAKER,\n  not the verdict — that arm was not observed tonight and stays a prediction.\n- **Measured, hfenduleam 2026-09-09, both full streams read end to end, same 23:04Z stamp:** hertz’s\n  log (through seq 1812): the messages that arrived as turn triggers (`UserPromptSubmit`, idle) — **7/7\n  unlogged**; those that arrived mid-tool (`PreToolUse`, busy) — **4/4 logged**, msg-id present,\n  `<LAST_MSGS>` clock moved (doyle's 22:55Z probe was `QUEUED`, drained mid-Bash, logged as 1804).\n  His \"zero `MSG_IN` since 14:02:34Z\" was **not a state change**: 1633 at 14:02 was the last message\n  that happened to catch him inside a tool call; everything after found him idle. doyle's log (1,121\n  events): PACER-0 **7 received / 6 logged**, the missing one `G4NK5FFT` being the row that woke the\n  session; hertz’s five `SENT` wake messages **absent entirely** and his four `QUEUED` ones **present\n  4/4**, each drained mid-tool; riders in the same spill (1856/1857 beside the promoted 1855;\n  `3NGTHQHN` beside a task-notification trigger) logged. One variable moved.\n- **Scope, corrected once (hertz struck his own \"bilateral\" clause on doyle's control):**\n  receiver-side only. The sender's `MSG_OUT` rows are intact on both sides, so an exchange IS\n  reconstructible from the **peer's** log — but not from the woken agent's own, which is the surface\n  a post-reset agent reads. hertz re-grounded his 22:36 session off seq 1786 of a log that holds his\n  half of every exchange since 14:02 and none of doyle's; a replay of an idle-woken agent shows its\n  own outbound answering nothing, and the last-received clock skips exactly the moments the peer was\n  talking, which reads as \"peer gone quiet\".\n- **Against the requirement's own words:** `REQ-IO-MSG-EDGES` (activated, `doc`/`impl`/`unit`)\n  states that \"MSG_IN publishes where core **delivers or injects** an inbound one, so the funnel\n  observes the edges rather than growing a parallel notion of what a message is\". This is not a case\n  the requirement failed to anticipate: **its own second clause is unimplemented** while `impl` and\n  `unit` read green on the first. The inject edge was never given a publisher when F-023 (idle-edge\n  drain), W5 (parked re-offer) and the WAN ingress added takers; the unit cell at `delivery.rs:1251`\n  pins the poll leg only, so the coverage the registry reports is green on two edges and vacuous on\n  the one the requirement names by verb.\n- **Remedy, and where it must sit:** publish `MSG_IN` **inside `try_spt_hosted_inject` on\n  `Some((true, _))`** — the one chokepoint all four callers share — so no caller can deliver\n  unobserved; a fix placed in `drain_spool_offering` would leave the send-time direct inject and WAN\n  ingress silent. Keep it observation-only (REQ-IO-EVENT-BUS): the inject verdict must not depend on\n  the bus. The unit cell to add mirrors `delivery.rs:1251`: an injected row owes exactly one\n  `MSG_IN`, a refused inject owes none. Post-hoc census of what was lost: spooled rows carry\n  `TakerLeg::IdleInject` / `NativeInject` in the audit column (REQ-SPOOL-TAKE-AUDIT); direct injects\n  never spooled and are enumerable only from the sender's `MSG_OUT`.\n- **OPEN, unranked, not smoothed:** doyle's pre-clear 1855 got a **bodiless** `USER_INPUT msg\n  from=\"hertz\"` row (the `api state busy` payload path, `delivery.rs:115` `state_io_kind`) while his\n  post-clear five got **no row at all**. Both are wake-delivered; the difference is downstream of\n  this gap, in what the adapter passed as the state payload, and is not this entry's mechanism.\n  Also out of scope, perri's surface: the claude-spt overflow notice names spills of the CURRENT\n  session id only, so the last spill before a `/clear` is never named again (how the 22:35Z body\n  went unread in the first place).\n- **Kin:** `REQ-IO-MSG-EDGES`, `REQ-MSG-IDLE-EDGE-DRAIN`, `REQ-IDLE-PARKED-DELIVERY`,\n  `REQ-SPOOL-TAKE-AUDIT`, **IR-84** (the arm the rigs fire was the only one without a clock — same\n  shape: the leg that fires most is the one the instrument never covered), releases#287 (shells after\n  a restart), memory `an-empty-msg-from-tag-is-a-turn-trigger-whose-body-lives-in-the-spill`.\n- **Ripe when:** any lane touches `spt-daemon::inject` or the IO funnel; small enough to ride the\n  next product batch. · **Size:** one publish call at one chokepoint, one unit cell, one `int` leg\n  (a hook-hosted receiver woken by a `SENT`, then `io-events` replayed for the msg-id).\n\n### IR-93 — no PDB ships beside the installed `spt` binary, so the one non-invasive read of a wedged production daemon comes back without a single named frame\n\n- **Status:** OPEN, filed by doyle 2026-09-10. **The number was reserved by NAME on 2026-09-09** at\n  the #293 mechanism read (\"PDB ask -> IR-93 at next sweep\") and this entry closes that claim — a\n  name-only IR with no entry text is the exact gap [[IR-85]]'s status line had to spend a paragraph\n  explaining about IR-84, and it is not being left open a second time. · **Origin:** the #293 pump\n  wedge on hfenduleam.\n- **What was actually paid.** With the daemon wedged and unrecoverable, hertz's `cdb -pv -p 31856`\n  dump (2026-09-09 23:23:26-31Z, 4.79 s suspend, 35 threads, preserved at\n  `.spt/preserved/293-brain-stacks-20260909T232326Z/`) was the ONLY direct observation available of\n  the live wedged process — the pump had already stopped, so the suspend cost the fleet nothing it\n  still had. It came back **with NO SYMBOLS: there is no PDB beside the installed exe.** Both\n  pump-ipc-reader threads were visible in `SleepEx` and all 32 brain threads in Wait, but the frames\n  are addresses.\n- **The cost, stated at the strength it holds.** The mechanism was named anyway — from SOURCE reading\n  (`Brain::read_event()` unbounded at `brain.rs:1025-1027`, 17 in-brain loopers), not from the dump.\n  What the dump could not do is say **WHICH call site parked THAT instance**, and that remains NOT\n  ESTABLISHED. A symbolised dump is the one artifact that answers it directly, and the next wedge\n  will present the same choice with the same empty answer.\n- **Remedy:** retain and ship the PDB beside the installed binary (or publish a symbol store the\n  debugger can resolve against) so a production dump names frames. **Weigh it honestly at rider\n  time:** this is a packaging/size decision, and a release profile that emits no debug info is a\n  deliberate choice someone made — this entry is the bill for it, not a claim it was wrong.\n- **Kin:** [[IR-82]] (a daemon death leaves no record of who died — same family: the corpse is the\n  evidence and nothing preserves it), [[IR-84]] (the arm with no clock), [[IR-95]] (a budget that\n  cannot say how much it burned).\n- **Ripe when:** next installer / release-packaging touch. · **Size:** packaging (profile + install\n  layout), no product code.\n\n### IR-94 — xtask's brainread deadline gate cannot SEE `serve_sync`: its registry is three hand-listed files and its predicate is a name shape, so a stream server outside both got the reply form and the gate stayed green\n\n- **Status:** OPEN, filed by doyle 2026-09-10 at the releases#294 / v0.69.0 golden RED triage. **This\n  is an INDEPENDENT gate finding, not the cause of that red** — it was found while reading the\n  milestone's diff and stands whatever Finding 1 turns out to be. · **Origin:**\n  `xtask/src/brainread.rs`, new this milestone (the #293 fix's zero-call-site guard).\n- **Mechanism, read at source.** The gate's REACH is two hand-authored narrowings stacked:\n  **registry = exactly three files** (`dispatch.rs`, `attach.rs`, `brain.rs`) and **predicate = a name\n  shape** (`starts_with(\"serve_\") && ends_with(\"_feed\")` or `== \"serve_attach\"`). `serve_sync` is a\n  stream server that lives in **no registry file** and whose name **escapes the pattern**, so it is\n  invisible on both axes at once. It therefore carries the **REPLY form — the exact form this gate\n  REJECTS for every stream server it can see — and the gate is GREEN.** An enforcement whose\n  population is enumerated by hand reports compliance over the set it can see, which is not the set\n  that matters.\n- **Why it is inert TODAY and why that is not reassuring.** The production carrier is unbounded:\n  `dispatch::connect()` (`dispatch.rs:898`) uses `Brain::cold_start` with `io_timeout: None`, so\n  `call_deadline()` is `None` and the read is unbounded regardless of which form the server carries.\n  **It becomes LATENT the day `serve_sync` rides a pump carrier** — which is precisely the direction\n  the #293 fix is moving the codebase. The guard will still be green on that day.\n- **Owned:** todlando has taken that his migration/census missed `serve_sync`'s lifetime semantics.\n  Recorded because the entry is about the GATE's reach, not about who missed it.\n- **Remedy shape:** derive the population from the **behaviour** (a fn that serves a stream) rather\n  than from the file it sits in or the name it happens to carry, and make the gate **FAIL on a server\n  it cannot classify instead of skipping it**. Add a census leg that PRINTS the population checked —\n  a count is what would have exposed a three-file registry at a glance.\n- **Kin:** [[IR-84]], `unbounded-brain-carrier-cannot-be-bounded` (memory — the carrier question that\n  makes this inert today), `REQ-BRAIN-READ-BOUNDED-PER-CALL`.\n- **Ripe when:** next `brainread`/xtask touch, **and mandatorily BEFORE `serve_sync` is migrated to a\n  bounded carrier.** · **Size:** small.\n\n### IR-95 — a burned polling budget names WHAT it wanted and never HOW LONG it waited, so no run, green or red, can say how close it came\n\n- **Status:** OPEN, filed by doyle 2026-09-10 at the releases#294 golden RED, where it cost this\n  triage most of a morning and four agents. · **Origin:** the two Windows Phase A failures at\n  `a9e786b2`, both polling budgets burned rather than value mismatches.\n\n[Showing lines 5150-5481 of 5782. Use :5482 to continue]"}],"details":{"truncation":{"content":"### IR-90 — a full disk on the self-hosted box reds a rig as a PRODUCT refusal, not a build error, and no rig or gate records the free space that would falsify it\r\n\r\n- **Status:** OPEN, filed by hertz 2026-09-09 from the disk-full incident on hfenduleam. ·\r\n  **Origin:** the IR-85 discriminator lane's head arm, killed by the volume rather than by the code\r\n  under test.\r\n- **Symptom:** `spt-daemon::sync concurrent_writes_reconcile_on_elected_node_and_converge` FAILED at\r\n  67.588 s with a panic in our own test at `crates\\spt-daemon\\tests\\sync.rs:198`:\r\n  `pull: Custom { kind: Other, error: \"sync refused: bundle failed: git -C <tmp>\\tracked-b\\.seed.git\r\n  bundle create <tmp>\\scratch\\serve\\serve-pull-6.bundle ^d12a7134... a-doyle failed (exit Some(1)):\r\n  fatal: sha1 file '<stdout>' write error. Out of diskspace\\nerror: pack-objects died\" }`, then a\r\n  second panic at `:213` (`pull thread: Any { .. }`) as the harness thread unwound.\r\n- **Cause:** `C:` was at **0.018 GiB free of 1862.02 GiB (0.00%)** at that instant\r\n  (`Win32_LogicalDisk`, 10:57Z). `git bundle create` could not write; the daemon's serve path turned\r\n  that into its real product refusal string `sync refused: bundle failed`; the test asserted on the\r\n  refusal. **Every layer behaved correctly, and the report reads as a sync regression at the sha\r\n  under test.**\r\n- **Why it is worse than the disk faces already known:** the two banked faces\r\n  (`disk-full-reds-as-lnk1318-pdb-error`) are TOOLCHAIN costumes — `LNK1318` at link, and rustc\r\n  I/O before any link — and both route a reader to \"the box is sick\". This one routes to a CODE\r\n  OWNER: it names our file, our line and our refusal string, and the disk word sits in the FOURTH\r\n  nested clause behind a git exit code. It arrived mid-discriminator with an old sha and a new sha\r\n  side by side, where the cheapest reading — \"the head arm failed, the old arm passed\" — is a\r\n  head regression that does not exist.\r\n- **Blast radius, same incident:** the volume also carried a live `unit (self-hosted, Windows,\r\n  hfenduleam)` job (run 34341010297) compiling into it, which completed FAILURE on its own and was\r\n  ruled VOID after the fact. doyle's cancel of THAT run returned `Cannot cancel a workflow run that\r\n  is completed` — recorded because a register that credits a controlled action nobody performed\r\n  teaches the next reader that the box was under control. (The earlier run 34337797758, in\r\n  **IR-85**'s amendment, is a different run with a different ending: CANCELLED at the job wall. One\r\n  register putting one cancel string on the wrong run is the same defect, one run over.) `spt daemon status` went to peer pump last tick 185 s with 24 brain\r\n  subscribers stall-evicted (last evict 10:51:22Z, inside the disk window), with an operator restart\r\n  under consideration — a restart that risks the releases#287 shell stranding and that, had it\r\n  appeared to help, would have taught everyone the wrong cause.\r\n- **⚠ Two things that looked like disk fallout and are NOT**, recorded so this entry does not\r\n  overclaim. (a) `serve list` returning `SERVE_UNCONFIRMED`: doyle read it from source —\r\n  `servehost.rs` and `KIND_SERVE_REQUEST` are ABSENT at 0.67.0/0.67.1 and were minted by 0.68.0, and\r\n  the resident broker is still the 0.67.0 image after the brain-only flip, so the CLI's 10 s bound\r\n  times out **by design** against an older daemon. (b) `peer reachability: DEGRADED, 4 of 7 peers\r\n  unreachable for 882775 s` — 10.2 days, predating the incident entirely. Even the pump term is\r\n  claimed as CONCURRENT, not caused: hertz called the pump recovered off ONE post-reclaim sample\r\n  (54 s) and doyle falsified it two minutes later (133 s), because a single reading of a monotonic\r\n  \"last tick N s ago\" counter cannot separate STILL TICKING from TICKED ONCE, and a fresh project\r\n  index proves the coordinator loop, not the pump.\r\n- **Remedy — one guard, two placements, and it REFUSES rather than runs:**\r\n  1. **Rig start.** For the two-host rig and any test rig that shells out to `git bundle` or writes a\r\n     store: read free space on the volume holding the rig's temp root and `target`, and under a floor\r\n     fail immediately with a message that says DISK and prints the number — never enter the\r\n     ceremony. Floor: start at **10 GiB**, above the largest single artifact these rigs write and far\r\n     below any healthy state of this box; tune only with a measurement.\r\n  2. **Failure text**, for the case where space runs out MID-run and no start check can catch it:\r\n     when a shelled-out git/store operation fails, append the current free space to the error before\r\n     it becomes a product refusal string, so the panic that reaches a human already carries the\r\n     falsifier.\r\n- **WHY BOTH, measured rather than argued (hertz, 2026-09-09, the #209 lane):** a floor read ONCE at\r\n  rig start would have PASSED that run and the run still ended nearly empty — `cargo check` started\r\n  at **136.32 GiB** free, the test-profile build of 221 binaries took it to **40.18 GiB in ten\r\n  minutes**, the legs finished at **16.24 GiB**, and it read **12.27 GiB** ninety seconds later. A\r\n  start-only guard is a guard against yesterday's disk. That last ~4 GiB fell with those legs already\r\n  terminal; the candidates are the runner's CI job and its `_work` tree, unsampled and therefore\r\n  UNATTRIBUTED.\r\n- **The record itself, and the only one that caught the dip (hertz, 2026-09-09):**\r\n  `.spt/preserved/hertz-leak-670-legs/disk-full-trace.log` — **139 samples, 11:52:46Z–13:57:07Z, one\r\n  per minute**, max **238.41 GiB** @12:45:20Z, min **12.53 GiB** @12:12:45Z. Two samples fall under\r\n  15 GiB — **14.85** @12:12:11Z and **12.53** @12:12:45Z — both inside the #209 leak lane's\r\n  build-and-teardown window, i.e. AFTER a start floor would have passed the run at **136.15 GiB**\r\n  (the window's first sample). Two caveats, both binding on any reading of it: **the true minimum is\r\n  unbounded below 12.53 — the sampler cannot see between its samples**, and **it attributes nothing:\r\n  hertz's own legs and the runner's CI job are indistinguishable in it.** It is the SECOND instrument\r\n  on this incident and the only one covering the dip: doyle's 30 s trace, preserved at\r\n  `.spt/preserved/ir90-free-space-trace-2026-09-09/free-sampler-12-13Z-to-12-28Z.txt`, runs\r\n  12:15:37Z–12:31:10Z and so begins after hertz's reap — it records the RECOVERY, this one records\r\n  the FALL. sha256 `d58ce838b677e62d4a017e77524f899fda81e7bacf73a0e2a05a1192e60abaf2`\r\n  (doyle's, `8bdae01bc151597070d7011443a2cdc74614232dbc962faec1b1b1833c71f22a`).\r\n- **Explicitly NOT the remedy:** a bigger disk, or a reap schedule. ~195 GiB of headroom was consumed\r\n  by ordinary work, ACCRUED across a ~45-minute build phase; **no reading bounds a rate** — the\r\n  free-space observations either side are endpoints of an accrual, and a rate derived from them\r\n  retargets a hunt (deployah's went to runaway logs, VSS and torrent preallocation on the strength of\r\n  a `>150 MB/s` derived that way, while the measured live box-wide write rate was ~1.5 MB/s). What\r\n  consumed it: two `cargo nextest run -E <5-test filter>` lanes at **82.88** and **64.44 GiB** — a\r\n  filter narrows the RUN, never the BUILD, and both built 221 test binaries under the `test` profile\r\n  — plus 40.93 GiB of `C:\\actions-runner\\_work` and 9.8 GiB of `%TEMP%`. Any headroom this box\r\n  has is two cold pools away from gone, so the guard must be a REFUSAL, not a budget.\r\n- **Kin:** **IR-85** (the same box's fs-heavy slowdown; a near-full volume is now a named environment\r\n  term there), **IR-86** (a start floor that passes a box which cannot finish — the same defect one\r\n  layer up, and this entry is its mid-run half), **IR-76** (the golden runner is the operator's\r\n  desktop), `disk-full-reds-as-lnk1318-pdb-error` (memory; this is its third face and its standing\r\n  gap), `test-profile-pool-outgrows-the-disk-floor`, `free-space-floor-blocks-golden`.\r\n- **Ripe when:** now. · **Size:** one assertion plus one error-context append, both test-side.\r\n\r\n### IR-91 — 561 untracked files sat at the repo root, 18 of them cited by tracked files, and the census that classified them used a corpus that made the discriminator invisible\r\n\r\n- **Status:** CLOSED by the lane that filed it (the root-scratch classify PR), hertz 2026-09-09 on\r\n  doyle's census and rulings. · **Origin:** the `.spt/` ignore lane (PR #212) named 561 untracked\r\n  root files as explicitly out of scope; this is that half.\r\n- **The population, measured at `2037bcb8`:** `git status --porcelain --untracked-files=all` = **561\r\n  `??` rows, all at the repo root, zero in subdirectories**, 50,034,994 bytes (47.7 MiB). By\r\n  extension: 268 `.raw`, 184 `.exit`, 87 `.md`, 7 `.out`, 4 `.log`, 4 `.done`, 2 `.txt`,\r\n  2 `.stackdump`, 2 `.sh`, 1 `.py`. **A `git add -A` at the root staged every one of them**, which\r\n  is the same landmine `.spt/` carried before #212 and the reason this is one arc in two lanes.\r\n- **⚠ THE FINDING, and it is about the CENSUS, not the files:** the first classification put two\r\n  cited files in the \"bury\" class. `W3-196-CENSUS.md` and `WEBSERVE-272-JIT.md` were recorded as\r\n  \"cited only from other root scratch\" — citing files `W3-196-JIT.md` and `W3-272-MEASUREMENTS.md`,\r\n  which are **TRACKED**. The census corpus was tracked-only, so **every hit it produced was a\r\n  tracked citation by construction**; the two were then relabelled by their PATH, because a `.md`\r\n  sitting at the repo root reads as scratch. **The discriminator is TRACKED-OR-NOT, never\r\n  ROOT-OR-NOT** — and a corpus that can only return tracked hits cannot tell you which of its own\r\n  hits are tracked, because it has already thrown away the distinction. Burying those two would have\r\n  left two tracked files citing paths that no longer existed: the `launch-battery.py` mechanism from\r\n  **IR-90**'s sibling lane with the sides swapped, caught here only because the burial list was\r\n  re-verified against the corpus a second time by a different reader.\r\n- **The second finding, which withdrew the lane's own destinations:** the repo root **already holds\r\n  140 tracked files, 134 of them `.md`, 25 with `JIT` in the name** — `IDLE-EDGE-JIT.md`,\r\n  `W3-196-JIT.md`, `WEBSERVE-272-W2-JIT.md`, every `M*-PLAN.md`, `MESH-D*-PLAN.md`,\r\n  `RESTORATION-D*-PLAN.md`. **The house convention is measured, not assumed: a plan or record lives\r\n  at the repo root and is TRACKED.** The first ruling would have relocated the cited files into\r\n  `docs/intake/`, `docs/design/` and `docs/gate-records/` — splitting siblings across two homes\r\n  (`WEBSERVE-272-W2-JIT.md` at root, `WEBSERVE-272-W3-DRIFT-RIDERS.md` in `docs/intake/`) and\r\n  repointing 18 citation lines to buy that split. **Destinations withdrawn; the 18 are tracked where\r\n  they are.** Zero moves, zero repoints, zero sha-transfer risk. A lane that tidies against a\r\n  measured convention is not tidying.\r\n- **THE RULE, which is what this entry is for:** *a plan or record cited from a tracked file is\r\n  itself tracked, at the path the citation already names.* The root is a legal home. What decides a\r\n  file's fate is whether the repo points at it — not where it sits, not what it is called, and not\r\n  whether it looks like scratch.\r\n- **What the lane did:** **18 Class A** files `git add`ed in place. **473 Class B** gate legs\r\n  (`.raw`/`.exit`/`.done`/`.log`/`.out`/`.stackdump`/`.sh`/`.txt`, zero tracked citations, each\r\n  word-bounded against the whole 911-file tracked corpus) **MOVED — not deleted** — to\r\n  `.spt/preserved/root-gate-legs-2026-09-09/` with a sha256 manifest, every file hashed before and\r\n  after the move. **70 Class C** uncited `.md` likewise to `.spt/preserved/root-md-2026-09-09/`.\r\n  Then five **root-anchored** ignore lines: `/*.raw` `/*.exit` `/*.done` `/*.out` `/*.stackdump`.\r\n- **Why those five and not more.** Legs are the one class whose FUTURE instances are scratch **by\r\n  construction**, so ignoring them institutionalizes no loss. `/*.md`, `/*.log`, `/*.sh` and\r\n  `/*.txt` are deliberately NOT ignored: a plan or script dropped at the root must keep showing as\r\n  `??` so the next census classifies it — **that is exactly the pattern that produced this repo's\r\n  140-file tracked root corpus**, and an ignore line there would hide the next one. The anchoring is\r\n  load-bearing and was proved with a negative control: `crates/probe.raw` is **not** ignored, which\r\n  an unanchored `*.raw` would have swallowed.\r\n- **Kin:** the `.spt/` ignore lane (PR #212 — same arc, and its `launch-battery.py` case is why\r\n  nothing here was deleted), **IR-90** (a citation into `.spt/preserved/` is machine-bound evidence,\r\n  never a repo path), `ignoring-a-directory-buries-what-the-repo-cites-in-it` (memory).\r\n- **Ripe when:** landed with this entry. · **Size:** one `.gitignore` stanza, 18 adds, 543\r\n  preserved files, no deletions.\r\n\r\n### IR-92 — the message that WAKES an idle spt-hosted endpoint rides a delivery leg that never publishes MSG_IN, so a woken agent's own funnel holds none of the messages that woke it\r\n\r\n- **Status:** OPEN — filed doyle 2026-09-09 from hertz's census, probe and proposed text (his by\r\n  role; the recorder read and the REQ reading are doyle's). Fix lane unassigned: product change in\r\n  `spt-daemon` (todlando), test-side legs (hertz). · **Origin:** a 22:35Z empty `<msg from=\"hertz\"/>`\r\n  turn trigger after the #292 daemon restart, chased for its body; the body was in a spill file, and\r\n  the chase exposed that neither agent's io-events log held the messages that woke it.\r\n- **THE TWO PUBLISH SITES ORDER THEMSELVES OPPOSITELY — read at `de5a44bc`, 2026-09-10, from the\r\n  bare-baseline red on `io_events_undriven_kinds_e2e` (golden 34467873057, Linux Phase A).** The\r\n  count below is right and the ORDERING is what this entry was missing:\r\n  · **PATH A, hook poll** (`delivery.rs`): `poll_drain()` publishes EVERY delivered row (`:757`) and\r\n    RETURNS them; its only caller `cmd_poll` (`:660`) then loops `emit_event` over the returned rows.\r\n    **Publication happens-before presentation**, strictly. An immediate log read after observed\r\n    presentation is CONTRACT-CORRECT here, and a bounded retry on this path WOULD conceal a real\r\n    violation. **Leave Path A alone.**\r\n  · **PATH B, the relay** (`startup.rs:1057`, the `deliver` closure): `emit(id, from, body)` — the\r\n    presentation — runs, and `publish_msg_io(...MSG_IN...)` runs AFTER it, per message, in the same\r\n    closure; the closure's own comment records that \"Both backlog (after notif validity) and live TCP\r\n    reach this edge.\" **Presentation happens-before publication.**\r\n  A test that detects presentation by reading the listener child's STDOUT through a pipe and then\r\n  reads the io-events log immediately is therefore **racy BY CONTRACT on Path B** — publication for\r\n  that message runs after its emit, in the child, and the pipe read can win. A bounded wait on the\r\n  log is permitted on Path B: **it does not weaken any publication-before-presentation guarantee\r\n  there, because there is none** (hertz's and todlando's narrowing — NOT \"conceals nothing\": the\r\n  wait still DEFINES WHICH PUBLICATION DELAYS THE TEST ACCEPTS, and it does not establish why any\r\n  given execution missed a row). A timeout would establish \"not published within the bound\", never\r\n  \"never publishes\", and cannot alone identify this entry's defect.\r\n- **A SECOND, INDEPENDENT DEFECT IN THAT CELL'S ASSERTION, true regardless of the above.**\r\n  `io_events_undriven_kinds_e2e.rs:818` asserts exact-once as\r\n  `vec![(\"MSG_IN\", Some(AUTHOR)), (\"MSG_IN\", Some(AUTHOR))]` — a `(kind, author)` pair per row, and\r\n  **both rows are identical**, so the assertion cannot tell the backlog row from the live row and\r\n  **two BACKLOG rows would satisfy it**. The identities exist and are already stamped:\r\n  `publish_msg_io_local` carries `.with_msg_id(msg_id_of(body))` — the short ID the failing panel\r\n  itself printed. Exact-once belongs per MESSAGE ID, not per author.\r\n  **AND IT CUTS BACKWARDS, WEAKENING EVERY GREEN THIS CELL HAS EVER RETURNED (deployah, on\r\n  arm-comparability grounds — the point nobody else had drawn):** the three PASSING executions of\r\n  this cell in the instrumented pair (base linux 3.612 s, head linux 2.343 s, head windows 16.411 s)\r\n  did **NOT** establish that both relay arms published. They established that two rows matching\r\n  `(MSG_IN, alice)` were present at read time. A green here is a WEAKER fact than it reads as — the\r\n  verdict stands in for a measurement the assertion never made. So \"both Linux legs were green\r\n  across the instrumented pair\" does not become FALSE, it becomes NARROWER than it was being used\r\n  for: it is a statement about the ASSERTION's outcome, not about publication. It does **not** make\r\n  the bare red likelier to be a product defect, does not classify anything, and does not separate\r\n  the race from non-publication — it removes a comparison the RCA was implicitly leaning on.\r\n  (Raised independently by hertz and todlando as an assertion defect; its backwards consequence for\r\n  the greens is deployah's.)\r\n- **Status of that red: UNEXPLAINED between DELAYED and ABSENT publication.** Path B makes the race\r\n  MECHANICALLY AVAILABLE, which is more than \"not excluded\" — but availability is not occurrence,\r\n  and one observation does not separate them. Kinship to this entry stays a HYPOTHESIS. The cell is\r\n  in neither `docs/FLAKE-LEDGER.md` nor this register (0 hits each): an unregistered signature.\r\n- **The mechanism, read at `de5a44bc`:** `MSG_IN` has exactly two publish sites in the tree —\r\n  `crates/spt/src/api/delivery.rs:757` (`publish_msg_io_local`, reached only from `poll_drain`, the\r\n  hook-poll leg, `TakerLeg::HookPoll`) and `crates/spt/src/api/startup.rs:1064` (`publish_msg_io`\r\n  inside the `api listen` relay's `deliver` sink — the Monitor-stream surface a hook-hosted session\r\n  never uses). **The spt-hosted inject leg reaches neither.** `crates/spt-daemon/src/inject.rs:75`\r\n  `try_spt_hosted_inject` renders the envelope and hands it to `brain.inject_endpoint`; the file has\r\n  zero `publish_msg_io` / `iobus` / `IO_KIND_MSG_IN` references in 343 lines (control: `TakerAudit`\r\n  / `claim_idle_edge_at` hit, so the grep is live). Every caller delivers through it unobserved:\r\n  `cli.rs:11739` send-time direct inject when the broker reports the target IDLE (the sender is\r\n  answered `SENT`), `cli.rs:11684` `--force-native`, `inject.rs:168` `drain_spool_offering` (the\r\n  idle-EDGE drain `delivery.rs:801`, the send-time already-idle re-offer, the pulse-tick belt, and the\r\n  native ER-briefing arm), and `wan.rs:822` / `:1173` WAN ingress. Two more drain edges are silent by\r\n  the same shape and did not fire here: `cmd_poll_shell` (`delivery.rs:705`, shell surface) and\r\n  `cmd_worker_poll` (`worker.rs:138`, worker surface). A call-site grep would have marked `relay.rs`\r\n  silent too — it publishes through its sink one crate up — so \"does this edge observe\" is answered\r\n  by following the row to a bus, never by grepping the edge.\r\n- **The rule it produces (hertz's refinement, measured across both logs):** for a hook-hosted live\r\n  agent (`is_spt_hosted_no_relay`), **`SENT` to an idle peer → direct inject → NEVER recorded on\r\n  the peer** (deterministic). **`QUEUED` → recorded IFF the hook poll takes the row.** One stamped\r\n  census, **as of 23:04Z 2026-09-09** (the counts grow with every message, so an unstamped figure is\r\n  stale on arrival): SENT-to-idle unrecorded on the receiver **12/12** (hertz’s five to doyle, doyle’s\r\n  seven to hertz — the seventh being the message that announced this filing, delivered by the defect\r\n  it named); QUEUED recorded **8/8**, every one drained mid-tool. Each side’s absence census matched\r\n  the other side’s verdict log without either seeing the other’s data.\r\n  by the caller census a spooled row can also be taken by the send-time already-idle re-offer or the\r\n  pulse-tick belt (`inject.rs:168`, unrecorded), so a `QUEUED` row’s fate is decided by the TAKER,\r\n  not the verdict — that arm was not observed tonight and stays a prediction.\r\n- **Measured, hfenduleam 2026-09-09, both full streams read end to end, same 23:04Z stamp:** hertz’s\r\n  log (through seq 1812): the messages that arrived as turn triggers (`UserPromptSubmit`, idle) — **7/7\r\n  unlogged**; those that arrived mid-tool (`PreToolUse`, busy) — **4/4 logged**, msg-id present,\r\n  `<LAST_MSGS>` clock moved (doyle's 22:55Z probe was `QUEUED`, drained mid-Bash, logged as 1804).\r\n  His \"zero `MSG_IN` since 14:02:34Z\" was **not a state change**: 1633 at 14:02 was the last message\r\n  that happened to catch him inside a tool call; everything after found him idle. doyle's log (1,121\r\n  events): PACER-0 **7 received / 6 logged**, the missing one `G4NK5FFT` being the row that woke the\r\n  session; hertz’s five `SENT` wake messages **absent entirely** and his four `QUEUED` ones **present\r\n  4/4**, each drained mid-tool; riders in the same spill (1856/1857 beside the promoted 1855;\r\n  `3NGTHQHN` beside a task-notification trigger) logged. One variable moved.\r\n- **Scope, corrected once (hertz struck his own \"bilateral\" clause on doyle's control):**\r\n  receiver-side only. The sender's `MSG_OUT` rows are intact on both sides, so an exchange IS\r\n  reconstructible from the **peer's** log — but not from the woken agent's own, which is the surface\r\n  a post-reset agent reads. hertz re-grounded his 22:36 session off seq 1786 of a log that holds his\r\n  half of every exchange since 14:02 and none of doyle's; a replay of an idle-woken agent shows its\r\n  own outbound answering nothing, and the last-received clock skips exactly the moments the peer was\r\n  talking, which reads as \"peer gone quiet\".\r\n- **Against the requirement's own words:** `REQ-IO-MSG-EDGES` (activated, `doc`/`impl`/`unit`)\r\n  states that \"MSG_IN publishes where core **delivers or injects** an inbound one, so the funnel\r\n  observes the edges rather than growing a parallel notion of what a message is\". This is not a case\r\n  the requirement failed to anticipate: **its own second clause is unimplemented** while `impl` and\r\n  `unit` read green on the first. The inject edge was never given a publisher when F-023 (idle-edge\r\n  drain), W5 (parked re-offer) and the WAN ingress added takers; the unit cell at `delivery.rs:1251`\r\n  pins the poll leg only, so the coverage the registry reports is green on two edges and vacuous on\r\n  the one the requirement names by verb.\r\n- **Remedy, and where it must sit:** publish `MSG_IN` **inside `try_spt_hosted_inject` on\r\n  `Some((true, _))`** — the one chokepoint all four callers share — so no caller can deliver\r\n  unobserved; a fix placed in `drain_spool_offering` would leave the send-time direct inject and WAN\r\n  ingress silent. Keep it observation-only (REQ-IO-EVENT-BUS): the inject verdict must not depend on\r\n  the bus. The unit cell to add mirrors `delivery.rs:1251`: an injected row owes exactly one\r\n  `MSG_IN`, a refused inject owes none. Post-hoc census of what was lost: spooled rows carry\r\n  `TakerLeg::IdleInject` / `NativeInject` in the audit column (REQ-SPOOL-TAKE-AUDIT); direct injects\r\n  never spooled and are enumerable only from the sender's `MSG_OUT`.\r\n- **OPEN, unranked, not smoothed:** doyle's pre-clear 1855 got a **bodiless** `USER_INPUT msg\r\n  from=\"hertz\"` row (the `api state busy` payload path, `delivery.rs:115` `state_io_kind`) while his\r\n  post-clear five got **no row at all**. Both are wake-delivered; the difference is downstream of\r\n  this gap, in what the adapter passed as the state payload, and is not this entry's mechanism.\r\n  Also out of scope, perri's surface: the claude-spt overflow notice names spills of the CURRENT\r\n  session id only, so the last spill before a `/clear` is never named again (how the 22:35Z body\r\n  went unread in the first place).\r\n- **Kin:** `REQ-IO-MSG-EDGES`, `REQ-MSG-IDLE-EDGE-DRAIN`, `REQ-IDLE-PARKED-DELIVERY`,\r\n  `REQ-SPOOL-TAKE-AUDIT`, **IR-84** (the arm the rigs fire was the only one without a clock — same\r\n  shape: the leg that fires most is the one the instrument never covered), releases#287 (shells after\r\n  a restart), memory `an-empty-msg-from-tag-is-a-turn-trigger-whose-body-lives-in-the-spill`.\r\n- **Ripe when:** any lane touches `spt-daemon::inject` or the IO funnel; small enough to ride the\r\n  next product batch. · **Size:** one publish call at one chokepoint, one unit cell, one `int` leg\r\n  (a hook-hosted receiver woken by a `SENT`, then `io-events` replayed for the msg-id).\r\n\r\n### IR-93 — no PDB ships beside the installed `spt` binary, so the one non-invasive read of a wedged production daemon comes back without a single named frame\r\n\r\n- **Status:** OPEN, filed by doyle 2026-09-10. **The number was reserved by NAME on 2026-09-09** at\r\n  the #293 mechanism read (\"PDB ask -> IR-93 at next sweep\") and this entry closes that claim — a\r\n  name-only IR with no entry text is the exact gap [[IR-85]]'s status line had to spend a paragraph\r\n  explaining about IR-84, and it is not being left open a second time. · **Origin:** the #293 pump\r\n  wedge on hfenduleam.\r\n- **What was actually paid.** With the daemon wedged and unrecoverable, hertz's `cdb -pv -p 31856`\r\n  dump (2026-09-09 23:23:26-31Z, 4.79 s suspend, 35 threads, preserved at\r\n  `.spt/preserved/293-brain-stacks-20260909T232326Z/`) was the ONLY direct observation available of\r\n  the live wedged process — the pump had already stopped, so the suspend cost the fleet nothing it\r\n  still had. It came back **with NO SYMBOLS: there is no PDB beside the installed exe.** Both\r\n  pump-ipc-reader threads were visible in `SleepEx` and all 32 brain threads in Wait, but the frames\r\n  are addresses.\r\n- **The cost, stated at the strength it holds.** The mechanism was named anyway — from SOURCE reading\r\n  (`Brain::read_event()` unbounded at `brain.rs:1025-1027`, 17 in-brain loopers), not from the dump.\r\n  What the dump could not do is say **WHICH call site parked THAT instance**, and that remains NOT\r\n  ESTABLISHED. A symbolised dump is the one artifact that answers it directly, and the next wedge\r\n  will present the same choice with the same empty answer.\r\n- **Remedy:** retain and ship the PDB beside the installed binary (or publish a symbol store the\r\n  debugger can resolve against) so a production dump names frames. **Weigh it honestly at rider\r\n  time:** this is a packaging/size decision, and a release profile that emits no debug info is a\r\n  deliberate choice someone made — this entry is the bill for it, not a claim it was wrong.\r\n- **Kin:** [[IR-82]] (a daemon death leaves no record of who died — same family: the corpse is the\r\n  evidence and nothing preserves it), [[IR-84]] (the arm with no clock), [[IR-95]] (a budget that\r\n  cannot say how much it burned).\r\n- **Ripe when:** next installer / release-packaging touch. · **Size:** packaging (profile + install\r\n  layout), no product code.\r\n\r\n### IR-94 — xtask's brainread deadline gate cannot SEE `serve_sync`: its registry is three hand-listed files and its predicate is a name shape, so a stream server outside both got the reply form and the gate stayed green\r\n\r\n- **Status:** OPEN, filed by doyle 2026-09-10 at the releases#294 / v0.69.0 golden RED triage. **This\r\n  is an INDEPENDENT gate finding, not the cause of that red** — it was found while reading the\r\n  milestone's diff and stands whatever Finding 1 turns out to be. · **Origin:**\r\n  `xtask/src/brainread.rs`, new this milestone (the #293 fix's zero-call-site guard).\r\n- **Mechanism, read at source.** The gate's REACH is two hand-authored narrowings stacked:\r\n  **registry = exactly three files** (`dispatch.rs`, `attach.rs`, `brain.rs`) and **predicate = a name\r\n  shape** (`starts_with(\"serve_\") && ends_with(\"_feed\")` or `== \"serve_attach\"`). `serve_sync` is a\r\n  stream server that lives in **no registry file** and whose name **escapes the pattern**, so it is\r\n  invisible on both axes at once. It therefore carries the **REPLY form — the exact form this gate\r\n  REJECTS for every stream server it can see — and the gate is GREEN.** An enforcement whose\r\n  population is enumerated by hand reports compliance over the set it can see, which is not the set\r\n  that matters.\r\n- **Why it is inert TODAY and why that is not reassuring.** The production carrier is unbounded:\r\n  `dispatch::connect()` (`dispatch.rs:898`) uses `Brain::cold_start` with `io_timeout: None`, so\r\n  `call_deadline()` is `None` and the read is unbounded regardless of which form the server carries.\r\n  **It becomes LATENT the day `serve_sync` rides a pump carrier** — which is precisely the direction\r\n  the #293 fix is moving the codebase. The guard will still be green on that day.\r\n- **Owned:** todlando has taken that his migration/census missed `serve_sync`'s lifetime semantics.\r\n  Recorded because the entry is about the GATE's reach, not about who missed it.\r\n- **Remedy shape:** derive the population from the **behaviour** (a fn that serves a stream) rather\r\n  than from the file it sits in or the name it happens to carry, and make the gate **FAIL on a server\r\n  it cannot classify instead of skipping it**. Add a census leg that PRINTS the population checked —\r\n  a count is what would have exposed a three-file registry at a glance.\r\n- **Kin:** [[IR-84]], `unbounded-brain-carrier-cannot-be-bounded` (memory — the carrier question that\r\n  makes this inert today), `REQ-BRAIN-READ-BOUNDED-PER-CALL`.\r\n- **Ripe when:** next `brainread`/xtask touch, **and mandatorily BEFORE `serve_sync` is migrated to a\r\n  bounded carrier.** · **Size:** small.\r\n\r\n### IR-95 — a burned polling budget names WHAT it wanted and never HOW LONG it waited, so no run, green or red, can say how close it came\r\n\r\n- **Status:** OPEN, filed by doyle 2026-09-10 at the releases#294 golden RED, where it cost this\r\n  triage most of a morning and four agents. · **Origin:** the two Windows Phase A failures at\r\n  `a9e786b2`, both polling budgets burned rather than value mismatches.\r","truncated":true,"truncatedBy":"lines","totalLines":633,"totalBytes":30256,"outputLines":332,"outputBytes":30256,"lastLinePartial":false,"firstLineExceedsLimit":false},"totalLines":5782,"displayContent":{"text":"### IR-90 — a full disk on the self-hosted box reds a rig as a PRODUCT refusal, not a build error, and no rig or gate records the free space that would falsify it\r\n\r\n- **Status:** OPEN, filed by hertz 2026-09-09 from the disk-full incident on hfenduleam. ·\r\n  **Origin:** the IR-85 discriminator lane's head arm, killed by the volume rather than by the code\r\n  under test.\r\n- **Symptom:** `spt-daemon::sync concurrent_writes_reconcile_on_elected_node_and_converge` FAILED at\r\n  67.588 s with a panic in our own test at `crates\\spt-daemon\\tests\\sync.rs:198`:\r\n  `pull: Custom { kind: Other, error: \"sync refused: bundle failed: git -C <tmp>\\tracked-b\\.seed.git\r\n  bundle create <tmp>\\scratch\\serve\\serve-pull-6.bundle ^d12a7134... a-doyle failed (exit Some(1)):\r\n  fatal: sha1 file '<stdout>' write error. Out of diskspace\\nerror: pack-objects died\" }`, then a\r\n  second panic at `:213` (`pull thread: Any { .. }`) as the harness thread unwound.\r\n- **Cause:** `C:` was at **0.018 GiB free of 1862.02 GiB (0.00%)** at that instant\r\n  (`Win32_LogicalDisk`, 10:57Z). `git bundle create` could not write; the daemon's serve path turned\r\n  that into its real product refusal string `sync refused: bundle failed`; the test asserted on the\r\n  refusal. **Every layer behaved correctly, and the report reads as a sync regression at the sha\r\n  under test.**\r\n- **Why it is worse than the disk faces already known:** the two banked faces\r\n  (`disk-full-reds-as-lnk1318-pdb-error`) are TOOLCHAIN costumes — `LNK1318` at link, and rustc\r\n  I/O before any link — and both route a reader to \"the box is sick\". This one routes to a CODE\r\n  OWNER: it names our file, our line and our refusal string, and the disk word sits in the FOURTH\r\n  nested clause behind a git exit code. It arrived mid-discriminator with an old sha and a new sha\r\n  side by side, where the cheapest reading — \"the head arm failed, the old arm passed\" — is a\r\n  head regression that does not exist.\r\n- **Blast radius, same incident:** the volume also carried a live `unit (self-hosted, Windows,\r\n  hfenduleam)` job (run 34341010297) compiling into it, which completed FAILURE on its own and was\r\n  ruled VOID after the fact. doyle's cancel of THAT run returned `Cannot cancel a workflow run that\r\n  is completed` — recorded because a register that credits a controlled action nobody performed\r\n  teaches the next reader that the box was under control. (The earlier run 34337797758, in\r\n  **IR-85**'s amendment, is a different run with a different ending: CANCELLED at the job wall. One\r\n  register putting one cancel string on the wrong run is the same defect, one run over.) `spt daemon status` went to peer pump last tick 185 s with 24 brain\r\n  subscribers stall-evicted (last evict 10:51:22Z, inside the disk window), with an operator restart\r\n  under consideration — a restart that risks the releases#287 shell stranding and that, had it\r\n  appeared to help, would have taught everyone the wrong cause.\r\n- **⚠ Two things that looked like disk fallout and are NOT**, recorded so this entry does not\r\n  overclaim. (a) `serve list` returning `SERVE_UNCONFIRMED`: doyle read it from source —\r\n  `servehost.rs` and `KIND_SERVE_REQUEST` are ABSENT at 0.67.0/0.67.1 and were minted by 0.68.0, and\r\n  the resident broker is still the 0.67.0 image after the brain-only flip, so the CLI's 10 s bound\r\n  times out **by design** against an older daemon. (b) `peer reachability: DEGRADED, 4 of 7 peers\r\n  unreachable for 882775 s` — 10.2 days, predating the incident entirely. Even the pump term is\r\n  claimed as CONCURRENT, not caused: hertz called the pump recovered off ONE post-reclaim sample\r\n  (54 s) and doyle falsified it two minutes later (133 s), because a single reading of a monotonic\r\n  \"last tick N s ago\" counter cannot separate STILL TICKING from TICKED ONCE, and a fresh project\r\n  index proves the coordinator loop, not the pump.\r\n- **Remedy — one guard, two placements, and it REFUSES rather than runs:**\r\n  1. **Rig start.** For the two-host rig and any test rig that shells out to `git bundle` or writes a\r\n     store: read free space on the volume holding the rig's temp root and `target`, and under a floor\r\n     fail immediately with a message that says DISK and prints the number — never enter the\r\n     ceremony. Floor: start at **10 GiB**, above the largest single artifact these rigs write and far\r\n     below any healthy state of this box; tune only with a measurement.\r\n  2. **Failure text**, for the case where space runs out MID-run and no start check can catch it:\r\n     when a shelled-out git/store operation fails, append the current free space to the error before\r\n     it becomes a product refusal string, so the panic that reaches a human already carries the\r\n     falsifier.\r\n- **WHY BOTH, measured rather than argued (hertz, 2026-09-09, the #209 lane):** a floor read ONCE at\r\n  rig start would have PASSED that run and the run still ended nearly empty — `cargo check` started\r\n  at **136.32 GiB** free, the test-profile build of 221 binaries took it to **40.18 GiB in ten\r\n  minutes**, the legs finished at **16.24 GiB**, and it read **12.27 GiB** ninety seconds later. A\r\n  start-only guard is a guard against yesterday's disk. That last ~4 GiB fell with those legs already\r\n  terminal; the candidates are the runner's CI job and its `_work` tree, unsampled and therefore\r\n  UNATTRIBUTED.\r\n- **The record itself, and the only one that caught the dip (hertz, 2026-09-09):**\r\n  `.spt/preserved/hertz-leak-670-legs/disk-full-trace.log` — **139 samples, 11:52:46Z–13:57:07Z, one\r\n  per minute**, max **238.41 GiB** @12:45:20Z, min **12.53 GiB** @12:12:45Z. Two samples fall under\r\n  15 GiB — **14.85** @12:12:11Z and **12.53** @12:12:45Z — both inside the #209 leak lane's\r\n  build-and-teardown window, i.e. AFTER a start floor would have passed the run at **136.15 GiB**\r\n  (the window's first sample). Two caveats, both binding on any reading of it: **the true minimum is\r\n  unbounded below 12.53 — the sampler cannot see between its samples**, and **it attributes nothing:\r\n  hertz's own legs and the runner's CI job are indistinguishable in it.** It is the SECOND instrument\r\n  on this incident and the only one covering the dip: doyle's 30 s trace, preserved at\r\n  `.spt/preserved/ir90-free-space-trace-2026-09-09/free-sampler-12-13Z-to-12-28Z.txt`, runs\r\n  12:15:37Z–12:31:10Z and so begins after hertz's reap — it records the RECOVERY, this one records\r\n  the FALL. sha256 `d58ce838b677e62d4a017e77524f899fda81e7bacf73a0e2a05a1192e60abaf2`\r\n  (doyle's, `8bdae01bc151597070d7011443a2cdc74614232dbc962faec1b1b1833c71f22a`).\r\n- **Explicitly NOT the remedy:** a bigger disk, or a reap schedule. ~195 GiB of headroom was consumed\r\n  by ordinary work, ACCRUED across a ~45-minute build phase; **no reading bounds a rate** — the\r\n  free-space observations either side are endpoints of an accrual, and a rate derived from them\r\n  retargets a hunt (deployah's went to runaway logs, VSS and torrent preallocation on the strength of\r\n  a `>150 MB/s` derived that way, while the measured live box-wide write rate was ~1.5 MB/s). What\r\n  consumed it: two `cargo nextest run -E <5-test filter>` lanes at **82.88** and **64.44 GiB** — a\r\n  filter narrows the RUN, never the BUILD, and both built 221 test binaries under the `test` profile\r\n  — plus 40.93 GiB of `C:\\actions-runner\\_work` and 9.8 GiB of `%TEMP%`. Any headroom this box\r\n  has is two cold pools away from gone, so the guard must be a REFUSAL, not a budget.\r\n- **Kin:** **IR-85** (the same box's fs-heavy slowdown; a near-full volume is now a named environment\r\n  term there), **IR-86** (a start floor that passes a box which cannot finish — the same defect one\r\n  layer up, and this entry is its mid-run half), **IR-76** (the golden runner is the operator's\r\n  desktop), `disk-full-reds-as-lnk1318-pdb-error` (memory; this is its third face and its standing\r\n  gap), `test-profile-pool-outgrows-the-disk-floor`, `free-space-floor-blocks-golden`.\r\n- **Ripe when:** now. · **Size:** one assertion plus one error-context append, both test-side.\r\n\r\n### IR-91 — 561 untracked files sat at the repo root, 18 of them cited by tracked files, and the census that classified them used a corpus that made the discriminator invisible\r\n\r\n- **Status:** CLOSED by the lane that filed it (the root-scratch classify PR), hertz 2026-09-09 on\r\n  doyle's census and rulings. · **Origin:** the `.spt/` ignore lane (PR #212) named 561 untracked\r\n  root files as explicitly out of scope; this is that half.\r\n- **The population, measured at `2037bcb8`:** `git status --porcelain --untracked-files=all` = **561\r\n  `??` rows, all at the repo root, zero in subdirectories**, 50,034,994 bytes (47.7 MiB). By\r\n  extension: 268 `.raw`, 184 `.exit`, 87 `.md`, 7 `.out`, 4 `.log`, 4 `.done`, 2 `.txt`,\r\n  2 `.stackdump`, 2 `.sh`, 1 `.py`. **A `git add -A` at the root staged every one of them**, which\r\n  is the same landmine `.spt/` carried before #212 and the reason this is one arc in two lanes.\r\n- **⚠ THE FINDING, and it is about the CENSUS, not the files:** the first classification put two\r\n  cited files in the \"bury\" class. `W3-196-CENSUS.md` and `WEBSERVE-272-JIT.md` were recorded as\r\n  \"cited only from other root scratch\" — citing files `W3-196-JIT.md` and `W3-272-MEASUREMENTS.md`,\r\n  which are **TRACKED**. The census corpus was tracked-only, so **every hit it produced was a\r\n  tracked citation by construction**; the two were then relabelled by their PATH, because a `.md`\r\n  sitting at the repo root reads as scratch. **The discriminator is TRACKED-OR-NOT, never\r\n  ROOT-OR-NOT** — and a corpus that can only return tracked hits cannot tell you which of its own\r\n  hits are tracked, because it has already thrown away the distinction. Burying those two would have\r\n  left two tracked files citing paths that no longer existed: the `launch-battery.py` mechanism from\r\n  **IR-90**'s sibling lane with the sides swapped, caught here only because the burial list was\r\n  re-verified against the corpus a second time by a different reader.\r\n- **The second finding, which withdrew the lane's own destinations:** the repo root **already holds\r\n  140 tracked files, 134 of them `.md`, 25 with `JIT` in the name** — `IDLE-EDGE-JIT.md`,\r\n  `W3-196-JIT.md`, `WEBSERVE-272-W2-JIT.md`, every `M*-PLAN.md`, `MESH-D*-PLAN.md`,\r\n  `RESTORATION-D*-PLAN.md`. **The house convention is measured, not assumed: a plan or record lives\r\n  at the repo root and is TRACKED.** The first ruling would have relocated the cited files into\r\n  `docs/intake/`, `docs/design/` and `docs/gate-records/` — splitting siblings across two homes\r\n  (`WEBSERVE-272-W2-JIT.md` at root, `WEBSERVE-272-W3-DRIFT-RIDERS.md` in `docs/intake/`) and\r\n  repointing 18 citation lines to buy that split. **Destinations withdrawn; the 18 are tracked where\r\n  they are.** Zero moves, zero repoints, zero sha-transfer risk. A lane that tidies against a\r\n  measured convention is not tidying.\r\n- **THE RULE, which is what this entry is for:** *a plan or record cited from a tracked file is\r\n  itself tracked, at the path the citation already names.* The root is a legal home. What decides a\r\n  file's fate is whether the repo points at it — not where it sits, not what it is called, and not\r\n  whether it looks like scratch.\r\n- **What the lane did:** **18 Class A** files `git add`ed in place. **473 Class B** gate legs\r\n  (`.raw`/`.exit`/`.done`/`.log`/`.out`/`.stackdump`/`.sh`/`.txt`, zero tracked citations, each\r\n  word-bounded against the whole 911-file tracked corpus) **MOVED — not deleted** — to\r\n  `.spt/preserved/root-gate-legs-2026-09-09/` with a sha256 manifest, every file hashed before and\r\n  after the move. **70 Class C** uncited `.md` likewise to `.spt/preserved/root-md-2026-09-09/`.\r\n  Then five **root-anchored** ignore lines: `/*.raw` `/*.exit` `/*.done` `/*.out` `/*.stackdump`.\r\n- **Why those five and not more.** Legs are the one class whose FUTURE instances are scratch **by\r\n  construction**, so ignoring them institutionalizes no loss. `/*.md`, `/*.log`, `/*.sh` and\r\n  `/*.txt` are deliberately NOT ignored: a plan or script dropped at the root must keep showing as\r\n  `??` so the next census classifies it — **that is exactly the pattern that produced this repo's\r\n  140-file tracked root corpus**, and an ignore line there would hide the next one. The anchoring is\r\n  load-bearing and was proved with a negative control: `crates/probe.raw` is **not** ignored, which\r\n  an unanchored `*.raw` would have swallowed.\r\n- **Kin:** the `.spt/` ignore lane (PR #212 — same arc, and its `launch-battery.py` case is why\r\n  nothing here was deleted), **IR-90** (a citation into `.spt/preserved/` is machine-bound evidence,\r\n  never a repo path), `ignoring-a-directory-buries-what-the-repo-cites-in-it` (memory).\r\n- **Ripe when:** landed with this entry. · **Size:** one `.gitignore` stanza, 18 adds, 543\r\n  preserved files, no deletions.\r\n\r\n### IR-92 — the message that WAKES an idle spt-hosted endpoint rides a delivery leg that never publishes MSG_IN, so a woken agent's own funnel holds none of the messages that woke it\r\n\r\n- **Status:** OPEN — filed doyle 2026-09-09 from hertz's census, probe and proposed text (his by\r\n  role; the recorder read and the REQ reading are doyle's). Fix lane unassigned: product change in\r\n  `spt-daemon` (todlando), test-side legs (hertz). · **Origin:** a 22:35Z empty `<msg from=\"hertz\"/>`\r\n  turn trigger after the #292 daemon restart, chased for its body; the body was in a spill file, and\r\n  the chase exposed that neither agent's io-events log held the messages that woke it.\r\n- **THE TWO PUBLISH SITES ORDER THEMSELVES OPPOSITELY — read at `de5a44bc`, 2026-09-10, from the\r\n  bare-baseline red on `io_events_undriven_kinds_e2e` (golden 34467873057, Linux Phase A).** The\r\n  count below is right and the ORDERING is what this entry was missing:\r\n  · **PATH A, hook poll** (`delivery.rs`): `poll_drain()` publishes EVERY delivered row (`:757`) and\r\n    RETURNS them; its only caller `cmd_poll` (`:660`) then loops `emit_event` over the returned rows.\r\n    **Publication happens-before presentation**, strictly. An immediate log read after observed\r\n    presentation is CONTRACT-CORRECT here, and a bounded retry on this path WOULD conceal a real\r\n    violation. **Leave Path A alone.**\r\n  · **PATH B, the relay** (`startup.rs:1057`, the `deliver` closure): `emit(id, from, body)` — the\r\n    presentation — runs, and `publish_msg_io(...MSG_IN...)` runs AFTER it, per message, in the same\r\n    closure; the closure's own comment records that \"Both backlog (after notif validity) and live TCP\r\n    reach this edge.\" **Presentation happens-before publication.**\r\n  A test that detects presentation by reading the listener child's STDOUT through a pipe and then\r\n  reads the io-events log immediately is therefore **racy BY CONTRACT on Path B** — publication for\r\n  that message runs after its emit, in the child, and the pipe read can win. A bounded wait on the\r\n  log is permitted on Path B: **it does not weaken any publication-before-presentation guarantee\r\n  there, because there is none** (hertz's and todlando's narrowing — NOT \"conceals nothing\": the\r\n  wait still DEFINES WHICH PUBLICATION DELAYS THE TEST ACCEPTS, and it does not establish why any\r\n  given execution missed a row). A timeout would establish \"not published within the bound\", never\r\n  \"never publishes\", and cannot alone identify this entry's defect.\r\n- **A SECOND, INDEPENDENT DEFECT IN THAT CELL'S ASSERTION, true regardless of the above.**\r\n  `io_events_undriven_kinds_e2e.rs:818` asserts exact-once as\r\n  `vec![(\"MSG_IN\", Some(AUTHOR)), (\"MSG_IN\", Some(AUTHOR))]` — a `(kind, author)` pair per row, and\r\n  **both rows are identical**, so the assertion cannot tell the backlog row from the live row and\r\n  **two BACKLOG rows would satisfy it**. The identities exist and are already stamped:\r\n  `publish_msg_io_local` carries `.with_msg_id(msg_id_of(body))` — the short ID the failing panel\r\n  itself printed. Exact-once belongs per MESSAGE ID, not per author.\r\n  **AND IT CUTS BACKWARDS, WEAKENING EVERY GREEN THIS CELL HAS EVER RETURNED (deployah, on\r\n  arm-comparability grounds — the point nobody else had drawn):** the three PASSING executions of\r\n  this cell in the instrumented pair (base linux 3.612 s, head linux 2.343 s, head windows 16.411 s)\r\n  did **NOT** establish that both relay arms published. They established that two rows matching\r\n  `(MSG_IN, alice)` were present at read time. A green here is a WEAKER fact than it reads as — the\r\n  verdict stands in for a measurement the assertion never made. So \"both Linux legs were green\r\n  across the instrumented pair\" does not become FALSE, it becomes NARROWER than it was being used\r\n  for: it is a statement about the ASSERTION's outcome, not about publication. It does **not** make\r\n  the bare red likelier to be a product defect, does not classify anything, and does not separate\r\n  the race from non-publication — it removes a comparison the RCA was implicitly leaning on.\r\n  (Raised independently by hertz and todlando as an assertion defect; its backwards consequence for\r\n  the greens is deployah's.)\r\n- **Status of that red: UNEXPLAINED between DELAYED and ABSENT publication.** Path B makes the race\r\n  MECHANICALLY AVAILABLE, which is more than \"not excluded\" — but availability is not occurrence,\r\n  and one observation does not separate them. Kinship to this entry stays a HYPOTHESIS. The cell is\r\n  in neither `docs/FLAKE-LEDGER.md` nor this register (0 hits each): an unregistered signature.\r\n- **The mechanism, read at `de5a44bc`:** `MSG_IN` has exactly two publish sites in the tree —\r\n  `crates/spt/src/api/delivery.rs:757` (`publish_msg_io_local`, reached only from `poll_drain`, the\r\n  hook-poll leg, `TakerLeg::HookPoll`) and `crates/spt/src/api/startup.rs:1064` (`publish_msg_io`\r\n  inside the `api listen` relay's `deliver` sink — the Monitor-stream surface a hook-hosted session\r\n  never uses). **The spt-hosted inject leg reaches neither.** `crates/spt-daemon/src/inject.rs:75`\r\n  `try_spt_hosted_inject` renders the envelope and hands it to `brain.inject_endpoint`; the file has\r\n  zero `publish_msg_io` / `iobus` / `IO_KIND_MSG_IN` references in 343 lines (control: `TakerAudit`\r\n  / `claim_idle_edge_at` hit, so the grep is live). Every caller delivers through it unobserved:\r\n  `cli.rs:11739` send-time direct inject when the broker reports the target IDLE (the sender is\r\n  answered `SENT`), `cli.rs:11684` `--force-native`, `inject.rs:168` `drain_spool_offering` (the\r\n  idle-EDGE drain `delivery.rs:801`, the send-time already-idle re-offer, the pulse-tick belt, and the\r\n  native ER-briefing arm), and `wan.rs:822` / `:1173` WAN ingress. Two more drain edges are silent by\r\n  the same shape and did not fire here: `cmd_poll_shell` (`delivery.rs:705`, shell surface) and\r\n  `cmd_worker_poll` (`worker.rs:138`, worker surface). A call-site grep would have marked `relay.rs`\r\n  silent too — it publishes through its sink one crate up — so \"does this edge observe\" is answered\r\n  by following the row to a bus, never by grepping the edge.\r\n- **The rule it produces (hertz's refinement, measured across both logs):** for a hook-hosted live\r\n  agent (`is_spt_hosted_no_relay`), **`SENT` to an idle peer → direct inject → NEVER recorded on\r\n  the peer** (deterministic). **`QUEUED` → recorded IFF the hook poll takes the row.** One stamped\r\n  census, **as of 23:04Z 2026-09-09** (the counts grow with every message, so an unstamped figure is\r\n  stale on arrival): SENT-to-idle unrecorded on the receiver **12/12** (hertz’s five to doyle, doyle’s\r\n  seven to hertz — the seventh being the message that announced this filing, delivered by the defect\r\n  it named); QUEUED recorded **8/8**, every one drained mid-tool. Each side’s absence census matched\r\n  the other side’s verdict log without either seeing the other’s data.\r\n  by the caller census a spooled row can also be taken by the send-time already-idle re-offer or the\r\n  pulse-tick belt (`inject.rs:168`, unrecorded), so a `QUEUED` row’s fate is decided by the TAKER,\r\n  not the verdict — that arm was not observed tonight and stays a prediction.\r\n- **Measured, hfenduleam 2026-09-09, both full streams read end to end, same 23:04Z stamp:** hertz’s\r\n  log (through seq 1812): the messages that arrived as turn triggers (`UserPromptSubmit`, idle) — **7/7\r\n  unlogged**; those that arrived mid-tool (`PreToolUse`, busy) — **4/4 logged**, msg-id present,\r\n  `<LAST_MSGS>` clock moved (doyle's 22:55Z probe was `QUEUED`, drained mid-Bash, logged as 1804).\r\n  His \"zero `MSG_IN` since 14:02:34Z\" was **not a state change**: 1633 at 14:02 was the last message\r\n  that happened to catch him inside a tool call; everything after found him idle. doyle's log (1,121\r\n  events): PACER-0 **7 received / 6 logged**, the missing one `G4NK5FFT` being the row that woke the\r\n  session; hertz’s five `SENT` wake messages **absent entirely** and his four `QUEUED` ones **present\r\n  4/4**, each drained mid-tool; riders in the same spill (1856/1857 beside the promoted 1855;\r\n  `3NGTHQHN` beside a task-notification trigger) logged. One variable moved.\r\n- **Scope, corrected once (hertz struck his own \"bilateral\" clause on doyle's control):**\r\n  receiver-side only. The sender's `MSG_OUT` rows are intact on both sides, so an exchange IS\r\n  reconstructible from the **peer's** log — but not from the woken agent's own, which is the surface\r\n  a post-reset agent reads. hertz re-grounded his 22:36 session off seq 1786 of a log that holds his\r\n  half of every exchange since 14:02 and none of doyle's; a replay of an idle-woken agent shows its\r\n  own outbound answering nothing, and the last-received clock skips exactly the moments the peer was\r\n  talking, which reads as \"peer gone quiet\".\r\n- **Against the requirement's own words:** `REQ-IO-MSG-EDGES` (activated, `doc`/`impl`/`unit`)\r\n  states that \"MSG_IN publishes where core **delivers or injects** an inbound one, so the funnel\r\n  observes the edges rather than growing a parallel notion of what a message is\". This is not a case\r\n  the requirement failed to anticipate: **its own second clause is unimplemented** while `impl` and\r\n  `unit` read green on the first. The inject edge was never given a publisher when F-023 (idle-edge\r\n  drain), W5 (parked re-offer) and the WAN ingress added takers; the unit cell at `delivery.rs:1251`\r\n  pins the poll leg only, so the coverage the registry reports is green on two edges and vacuous on\r\n  the one the requirement names by verb.\r\n- **Remedy, and where it must sit:** publish `MSG_IN` **inside `try_spt_hosted_inject` on\r\n  `Some((true, _))`** — the one chokepoint all four callers share — so no caller can deliver\r\n  unobserved; a fix placed in `drain_spool_offering` would leave the send-time direct inject and WAN\r\n  ingress silent. Keep it observation-only (REQ-IO-EVENT-BUS): the inject verdict must not depend on\r\n  the bus. The unit cell to add mirrors `delivery.rs:1251`: an injected row owes exactly one\r\n  `MSG_IN`, a refused inject owes none. Post-hoc census of what was lost: spooled rows carry\r\n  `TakerLeg::IdleInject` / `NativeInject` in the audit column (REQ-SPOOL-TAKE-AUDIT); direct injects\r\n  never spooled and are enumerable only from the sender's `MSG_OUT`.\r\n- **OPEN, unranked, not smoothed:** doyle's pre-clear 1855 got a **bodiless** `USER_INPUT msg\r\n  from=\"hertz\"` row (the `api state busy` payload path, `delivery.rs:115` `state_io_kind`) while his\r\n  post-clear five got **no row at all**. Both are wake-delivered; the difference is downstream of\r\n  this gap, in what the adapter passed as the state payload, and is not this entry's mechanism.\r\n  Also out of scope, perri's surface: the claude-spt overflow notice names spills of the CURRENT\r\n  session id only, so the last spill before a `/clear` is never named again (how the 22:35Z body\r\n  went unread in the first place).\r\n- **Kin:** `REQ-IO-MSG-EDGES`, `REQ-MSG-IDLE-EDGE-DRAIN`, `REQ-IDLE-PARKED-DELIVERY`,\r\n  `REQ-SPOOL-TAKE-AUDIT`, **IR-84** (the arm the rigs fire was the only one without a clock — same\r\n  shape: the leg that fires most is the one the instrument never covered), releases#287 (shells after\r\n  a restart), memory `an-empty-msg-from-tag-is-a-turn-trigger-whose-body-lives-in-the-spill`.\r\n- **Ripe when:** any lane touches `spt-daemon::inject` or the IO funnel; small enough to ride the\r\n  next product batch. · **Size:** one publish call at one chokepoint, one unit cell, one `int` leg\r\n  (a hook-hosted receiver woken by a `SENT`, then `io-events` replayed for the msg-id).\r\n\r\n### IR-93 — no PDB ships beside the installed `spt` binary, so the one non-invasive read of a wedged production daemon comes back without a single named frame\r\n\r\n- **Status:** OPEN, filed by doyle 2026-09-10. **The number was reserved by NAME on 2026-09-09** at\r\n  the #293 mechanism read (\"PDB ask -> IR-93 at next sweep\") and this entry closes that claim — a\r\n  name-only IR with no entry text is the exact gap [[IR-85]]'s status line had to spend a paragraph\r\n  explaining about IR-84, and it is not being left open a second time. · **Origin:** the #293 pump\r\n  wedge on hfenduleam.\r\n- **What was actually paid.** With the daemon wedged and unrecoverable, hertz's `cdb -pv -p 31856`\r\n  dump (2026-09-09 23:23:26-31Z, 4.79 s suspend, 35 threads, preserved at\r\n  `.spt/preserved/293-brain-stacks-20260909T232326Z/`) was the ONLY direct observation available of\r\n  the live wedged process — the pump had already stopped, so the suspend cost the fleet nothing it\r\n  still had. It came back **with NO SYMBOLS: there is no PDB beside the installed exe.** Both\r\n  pump-ipc-reader threads were visible in `SleepEx` and all 32 brain threads in Wait, but the frames\r\n  are addresses.\r\n- **The cost, stated at the strength it holds.** The mechanism was named anyway — from SOURCE reading\r\n  (`Brain::read_event()` unbounded at `brain.rs:1025-1027`, 17 in-brain loopers), not from the dump.\r\n  What the dump could not do is say **WHICH call site parked THAT instance**, and that remains NOT\r\n  ESTABLISHED. A symbolised dump is the one artifact that answers it directly, and the next wedge\r\n  will present the same choice with the same empty answer.\r\n- **Remedy:** retain and ship the PDB beside the installed binary (or publish a symbol store the\r\n  debugger can resolve against) so a production dump names frames. **Weigh it honestly at rider\r\n  time:** this is a packaging/size decision, and a release profile that emits no debug info is a\r\n  deliberate choice someone made — this entry is the bill for it, not a claim it was wrong.\r\n- **Kin:** [[IR-82]] (a daemon death leaves no record of who died — same family: the corpse is the\r\n  evidence and nothing preserves it), [[IR-84]] (the arm with no clock), [[IR-95]] (a budget that\r\n  cannot say how much it burned).\r\n- **Ripe when:** next installer / release-packaging touch. · **Size:** packaging (profile + install\r\n  layout), no product code.\r\n\r\n### IR-94 — xtask's brainread deadline gate cannot SEE `serve_sync`: its registry is three hand-listed files and its predicate is a name shape, so a stream server outside both got the reply form and the gate stayed green\r\n\r\n- **Status:** OPEN, filed by doyle 2026-09-10 at the releases#294 / v0.69.0 golden RED triage. **This\r\n  is an INDEPENDENT gate finding, not the cause of that red** — it was found while reading the\r\n  milestone's diff and stands whatever Finding 1 turns out to be. · **Origin:**\r\n  `xtask/src/brainread.rs`, new this milestone (the #293 fix's zero-call-site guard).\r\n- **Mechanism, read at source.** The gate's REACH is two hand-authored narrowings stacked:\r\n  **registry = exactly three files** (`dispatch.rs`, `attach.rs`, `brain.rs`) and **predicate = a name\r\n  shape** (`starts_with(\"serve_\") && ends_with(\"_feed\")` or `== \"serve_attach\"`). `serve_sync` is a\r\n  stream server that lives in **no registry file** and whose name **escapes the pattern**, so it is\r\n  invisible on both axes at once. It therefore carries the **REPLY form — the exact form this gate\r\n  REJECTS for every stream server it can see — and the gate is GREEN.** An enforcement whose\r\n  population is enumerated by hand reports compliance over the set it can see, which is not the set\r\n  that matters.\r\n- **Why it is inert TODAY and why that is not reassuring.** The production carrier is unbounded:\r\n  `dispatch::connect()` (`dispatch.rs:898`) uses `Brain::cold_start` with `io_timeout: None`, so\r\n  `call_deadline()` is `None` and the read is unbounded regardless of which form the server carries.\r\n  **It becomes LATENT the day `serve_sync` rides a pump carrier** — which is precisely the direction\r\n  the #293 fix is moving the codebase. The guard will still be green on that day.\r\n- **Owned:** todlando has taken that his migration/census missed `serve_sync`'s lifetime semantics.\r\n  Recorded because the entry is about the GATE's reach, not about who missed it.\r\n- **Remedy shape:** derive the population from the **behaviour** (a fn that serves a stream) rather\r\n  than from the file it sits in or the name it happens to carry, and make the gate **FAIL on a server\r\n  it cannot classify instead of skipping it**. Add a census leg that PRINTS the population checked —\r\n  a count is what would have exposed a three-file registry at a glance.\r\n- **Kin:** [[IR-84]], `unbounded-brain-carrier-cannot-be-bounded` (memory — the carrier question that\r\n  makes this inert today), `REQ-BRAIN-READ-BOUNDED-PER-CALL`.\r\n- **Ripe when:** next `brainread`/xtask touch, **and mandatorily BEFORE `serve_sync` is migrated to a\r\n  bounded carrier.** · **Size:** small.\r\n\r\n### IR-95 — a burned polling budget names WHAT it wanted and never HOW LONG it waited, so no run, green or red, can say how close it came\r\n\r\n- **Status:** OPEN, filed by doyle 2026-09-10 at the releases#294 golden RED, where it cost this\r\n  triage most of a morning and four agents. · **Origin:** the two Windows Phase A failures at\r\n  `a9e786b2`, both polling budgets burned rather than value mismatches.\r","startLine":5150,"lineNumbers":[5150,5151,5152,5153,5154,5155,5156,5157,5158,5159,5160,5161,5162,5163,5164,5165,5166,5167,5168,5169,5170,5171,5172,5173,5174,5175,5176,5177,5178,5179,5180,5181,5182,5183,5184,5185,5186,5187,5188,5189,5190,5191,5192,5193,5194,5195,5196,5197,5198,5199,5200,5201,5202,5203,5204,5205,5206,5207,5208,5209,5210,5211,5212,5213,5214,5215,5216,5217,5218,5219,5220,5221,5222,5223,5224,5225,5226,5227,5228,5229,5230,5231,5232,5233,5234,5235,5236,5237,5238,5239,5240,5241,5242,5243,5244,5245,5246,5247,5248,5249,5250,5251,5252,5253,5254,5255,5256,5257,5258,5259,5260,5261,5262,5263,5264,5265,5266,5267,5268,5269,5270,5271,5272,5273,5274,5275,5276,5277,5278,5279,5280,5281,5282,5283,5284,5285,5286,5287,5288,5289,5290,5291,5292,5293,5294,5295,5296,5297,5298,5299,5300,5301,5302,5303,5304,5305,5306,5307,5308,5309,5310,5311,5312,5313,5314,5315,5316,5317,5318,5319,5320,5321,5322,5323,5324,5325,5326,5327,5328,5329,5330,5331,5332,5333,5334,5335,5336,5337,5338,5339,5340,5341,5342,5343,5344,5345,5346,5347,5348,5349,5350,5351,5352,5353,5354,5355,5356,5357,5358,5359,5360,5361,5362,5363,5364,5365,5366,5367,5368,5369,5370,5371,5372,5373,5374,5375,5376,5377,5378,5379,5380,5381,5382,5383,5384,5385,5386,5387,5388,5389,5390,5391,5392,5393,5394,5395,5396,5397,5398,5399,5400,5401,5402,5403,5404,5405,5406,5407,5408,5409,5410,5411,5412,5413,5414,5415,5416,5417,5418,5419,5420,5421,5422,5423,5424,5425,5426,5427,5428,5429,5430,5431,5432,5433,5434,5435,5436,5437,5438,5439,5440,5441,5442,5443,5444,5445,5446,5447,5448,5449,5450,5451,5452,5453,5454,5455,5456,5457,5458,5459,5460,5461,5462,5463,5464,5465,5466,5467,5468,5469,5470,5471,5472,5473,5474,5475,5476,5477,5478,5479,5480,5481]},"fileSize":501961,"meta":{"source":{"type":"path","value":"C:\\Users\\decid\\Documents\\projects\\spt-core\\docs\\INFRA-REGISTER.md"},"truncation":{"direction":"head","truncatedBy":"lines","totalLines":5782,"totalBytes":30256,"outputLines":332,"outputBytes":30256,"shownRange":{"start":5150,"end":5481},"nextOffset":5482}}},"isError":false,"timestamp":1789094610894}}
{"type":"message","id":"f62c0caa","parentId":"9f116758","timestamp":"2026-09-11T02:43:30.899Z","message":{"role":"toolResult","toolCallId":"call_isrSVpRThwn8DnhR42nVpYw9|fc_065c0d1976ecf9c2016aa36ad0795087d1aec3c60d771a2ed8","toolName":"read","content":[{"type":"text","text":"### IR-84 — the one `PUMP_PEER_FAIL` arm the rigs actually fire was the only one carrying no clock, so the stall that produced it could be counted but never timed\n\n- **Status:** OPEN, filed by hertz 2026-09-09 with the instrument that closes its first half. ·\n  **Origin:** the 65 s two-host helper stall (design written before the run,\n  `docs/design/RIDER-65S-DESIGN.md`). The number was branch-claimed 2026-09-08 by name only — IR-85\n  records that it carried no entry text in any register file in any worktree — and this is that text.\n- **Symptom:** `two_host_web_helper_role_a` takes **61.956–69.096 s** across five runs while its\n  siblings in the same binary and the same run take **0.135–0.753 s**. Every ladder rig —\n  win-onebox, linux-onebox, cross-box — logs **exactly ONE**\n  `PUMP_PEER_FAIL:<node>:peer reply-read: no progress within budget — dropping peer (brain IPC read\n  deadline elapsed)` on B before completing. **3/3, one each, never on A** (doyle's GATE-W3 readout).\n- **Cause of the DIAGNOSTIC failure, which is what this entry is about:** that line is emitted from\n  the `Err(e)` arm of `peer_leg_outcome` (`crates/spt-daemon/src/pump/mod.rs`), and at\n  `b0b67aaa` it read `emit_line_err!(\"PUMP_PEER_FAIL:{peer_hex}:{e}\")` — **no timestamp**. Measured\n  at that sha rather than recalled: the file carries **four** `PUMP_PEER_FAIL` emit sites, **three**\n  of them stamped `wall_ms=… mono_ms=…` (the submit arm, the no-route arm, and the\n  `PRESENCE_DIAL_FAILED` arm), and this one was **the only unstamped site left**. It is also the\n  arm the rigs actually fire — a `PEER_REPLY_READ_BUDGET` expiry reclassified out of `TimedOut` by\n  `brain::reclassify_peer_reply_err` so it drops one peer rather than poisoning the round. **The\n  single arm a reader most needs to time was the single arm that could not be timed.**\n- **What that cost, stated as the open question it left:** the arithmetic does not close and this\n  entry does not close it. `PUMP_PEER_IO_TIMEOUT` is **30 s** (`:118`) and `SUPERVISE_BACKOFF_BASE`\n  is **5 s** (`:121`) — read as constants, not recalled — so one deadline plus one supervise floor\n  accounts for **35 s** against **61.956–69.096 s** observed. **~27–34 s is unaccounted**, itself\n  close to another 30, which is exactly the coincidence the design document warns against; and the\n  count of **exactly one** fail forbids the easy reading that two deadlines elapsed. Three candidates\n  stay open and are NOT ranked here: a first ~30 s burned before the deadline's clock starts; a\n  second budget stacking on the first; or the restart's re-prime costing materially more than its\n  5 s floor. **Separating them needs the deadline's own timestamps against the fail line** — which\n  is precisely what the log did not carry.\n- **⚠ WHAT THIS ENTRY DOES NOT CLAIM.** The instrument does not explain the stall, does not shorten\n  it, and changes no product behaviour: the same peer is dropped at the same instant with the same\n  backoff. It makes the stall **answerable from a log that already contains the failure**, instead of\n  requiring a rebuild to learn when the budget started. `PUMP_PEER_IO_TIMEOUT` is a hard const with\n  no env knob, so varying it costs a rebuild — deliberately deferred until the stamps say which half\n  of the arithmetic is missing.\n- **Kin and the recurrence that matters:** this is the **SECOND** time an unstamped\n  `PUMP_PEER_FAIL` cost a hunt. The `PRESENCE_DIAL_FAILED` arm carries a comment naming the\n  \"2026-07-14 `PUMP_PEER_FAIL`-unstamped seed, folded here\", and **REQ-PUMP-STAGE-TRUTH** already\n  requires every peer failure \"stamped (wall+mono) and peer-attributed\", explicitly subsuming that\n  seed. So the contract was written, three of four sites complied, and the fourth stayed silent for\n  eight weeks — **a convention enforced by no mechanism degrades one arm at a time, and every reader\n  of a complying arm reports the convention as held**, the same shape as the `validate_docs_dir`\n  refusal-arm rider in the same design document. Also kin: **IR-83** (the rig population had only\n  ever run the admitted direction), `REQ-HAZARD-PUMP-IPC-DEADLINE` (a `TimedOut` brain-IPC read is a\n  supervised restart, never a per-peer retry), ADR-0039 Decision 5.\n- **Ripe when:** now, and it lands with this entry — the stamp is one emit line, tagged\n  `[impl->REQ-PUMP-STAGE-TRUTH]` at the site. · **Size:** one emit line plus its comment.\n  **Follow-up, not this lane:** a cell that walks every `PUMP_PEER_FAIL` arm and asserts each one\n  stamps, so the fifth site added cannot be born silent.\n### IR-85 — the Windows self-hosted box runs its fs-heavy tests 3-4x slower than a week ago; two CI wall clocks were sized for the old box, and a red run kept hiding it\n\n- **Status:** OPEN, filed by hertz 2026-09-09 at the #272/v0.68.0 golden r3/r4 arc, on doyle's\n  dispatch. Number ruled by doyle from his own census of main@`a2f335f8` (register ended at IR-83;\n  IR-84 was branch-claimed by name only, with no entry text in any register file in any worktree —\n  that gap is now closed: **IR-84 was filed 2026-09-09 in PR #213**, so this sentence records the\n  state at `a2f335f8` and is no longer a reason to go looking for a missing entry).\n  **Absorbs two drafts:** doyle's `IR-DRAFT-windows-fs-heavy-slowdown-and-golden-wall` (his IR-A +\n  IR-B) and his earlier `IR-NEXT` (operator-desktop load), both retired by reference — this is the\n  single entry. Every job/step and per-test timing below is **doyle's**, read via the job/step API.\n  · **Origin:** #272 golden r3 attempt 2 was CANCELLED by a wall clock with both test phases green.\n- **⚠ THE CAP CHANGE IN `a2f335f8` IS NOT THE FIX AND MUST NOT BE READ AS ONE.** It bounds the run;\n  it repairs nothing. A future reader who finds an 80-minute wall and no entry here would reasonably\n  conclude the problem was solved. It was only made visible.\n\n- **A GREEN RUN COSTS MORE THAN A RED ONE, WHICH IS WHY THIS WENT UNSEEN.** A failing run\n  short-circuits past the wall a green run has to cross. r3 att1 finished in **48m39s only because\n  it FAILED at Phase B**; att2, green, hit 49m59s and was cancelled. Every earlier docs-drift skip\n  therefore presented as \"upstream failure\" — the wall was never the reported cause of anything, and\n  the surviving evidence systematically flattered the budget.\n\n- **THE WALL.** Windows golden `test` job (48 steps), fully GREEN: **30m53s** (2026-08-30, run\n  33296634901) and **33m21s** (2026-09-06, run 34017906638). At the v0.68.0 head against the\n  then-current 50-minute cap — **r3 att2**, job 102352551368 at `f6110c2a`: Phase A 17m14s, Phase B\n  20m25s, doctests 1m04s, clippy 3m31s, **CANCELLED at step 30 at 49m59s with everything green**;\n  steps 31-42 (installer, docs floor, both docs-drift gates, dormancy) never ran. r2 att1\n  (`25e60015`, 09-08 18:47Z) reached step 34 at 44m30s. Steps 30..39 cost ~3m30s on the 09-06 green\n  (notify 47s, installer 13s, docs-drift 1m54s). Predicted green need ~**56 min**; cap raised to\n  **80** (need + ~40% for day-to-day variance) in `a2f335f8`, ci unit 25 -> 40 in the same commit.\n- **r4, GREEN — the first complete measurement at the head: 54m35s** (07:12:26Z -> 08:07:01Z),\n  **25m25s** headroom under 80; docs-drift (step 38) 2m23s; Phase A 15m51s, Phase B 22m56s. The ~56\n  prediction held to within 1.5 min, so the cap is sized on evidence, not generosity. **What that\n  does NOT establish:** it was a sizing forecast, and its holding says nothing about the cause\n  diagnosis below. Nor are att2-vs-r4 per-phase deltas a trend — att2 was cancelled mid-run, so only\n  its phase legs are comparable at all, and the spread they sit in is the same variance the 40% is\n  there to absorb.\n\n- **THE SLOWDOWN, per test, same box, same tests.** `spt-daemon::sync` concurrent_writes\n  **22.4s -> 74.8s**, two_tier_sync 18.7 -> 67.4; `spt-store` monic clone_copies 17.7 -> 62.9,\n  different_monics 18.2 -> 64.9; syncmerge reconciled_write 27.3 -> 51.2. **~25 spt-store/spt-daemon\n  tests now exceed 30s on Windows Phase A at `f6110c2a`, against 1-2s each on kitsubito.**\n  Phase-level: Phase A nextest 170s (09-06) -> 642s (att1) -> 1034s (att2); Phase B 710s -> 1164s.\n  The suite did not get more expensive — Linux is unchanged.\n\n- **DATING SAYS ENVIRONMENT DOMINATES, AND BY HOW MUCH.** main's own ci Windows `unit` job:\n  11-12 min on 09-06 (runs 34040416870, 34041526195, 34043323577) -> 13-20 min on 09-07 -> 12-24 min\n  on 09-08, hitting **22 min at `e4444413`** (run 34261096301) three minutes under its own 25-minute\n  wall. **Gradual over days, under no single gate change, is the shape of an environment term, not a\n  commit's.** Head growth is real but MINOR: +138 Phase A tests, +20 Phase B, HEAVY 34 -> 35.\n\n- **THE BOX IS AN OPERATOR DESKTOP (folded in from the retired IR-NEXT), and that turns every fixed\n  wall-clock budget in the Windows suite into a coin.** From the r2 arc, three attempts at ONE sha\n  (run 34262154550 @ `25e60015`): Phase B red each time on a **different single cell or none** — a1\n  234/234 (job red on disk floors only), a2 `spt::webserve_attachment_e2e` arm 12, a3\n  `spt-daemon::mesh_recovery roster_route_survives_a_transient_dial_failure_with_discovery_disabled`\n  (15.0s `converge()` budget, cell 15.715s; the same cell 9.8s / 7.2s on a1/a2). Phase A — 3,346\n  spawn-dominated unit cells — slowed **monotonically 448.7 -> 495.1 -> 542.6s at that one sha**.\n  Per-cell a3/a2 over 73 Phase B cells >= 1s: median 1.05x, mean 1.34x, 19 cells >= 1.5x, worst 5.2x\n  (`endpoint_lifecycle poll_vs_reap` 1.1 -> 5.8s) — **BURSTY, not uniform**. A rotating single victim\n  across attempts at one sha is ONE environment cause; hardening victims one at a time never closes\n  it (paid before: `e2e-leaked-daemons-shared-box`). The budgets that lost were ~1.5x the fast\n  observation — inside the box's measured variance, so they were coins that had been landing right.\n- **Box census (doyle 01:13-01:19Z, no cargo/rustc/nextest running, CPU 31%, ~1.1 of 16 cores busy):**\n  `qbittorrent.exe` seeding since 09-08 10:20Z (box tx 21.3 MB/s over 5s); fleet `spt daemon brain`\n  with 516 GB read since 09-07 08:03Z (~3.5 MB/s steady); Defender real-time ON, `MsMpEng` at\n  67.8/62.8/48.9/32.2/12.2% of a core over 5s **on the idle box**; a fresh 35 MB exe pays\n  2092/994/1171/1043 ms on FIRST execution against 31/263/19/260 ms on the second — **and every CI\n  attempt rebuilds every test binary fresh.** At 06:45Z on 09-09, with the twohost legs running:\n  MsMpEng 89% CPU / 991 MB WS, qbittorrent pid 47056 holding 7817 CPU-seconds (2.2 h) since\n  09-08 03:20, free 134 GiB (275 -> 197 -> 131 across the three r3 dispatches).\n- **⚠ AN UNREADABLE ROW IS NOT AN ABSENT ONE.** The Defender exclusion list cannot be read\n  unelevated on this box: `Get-MpPreference` returns the literal string\n  `N/A: Must be an administrator to view exclusions` **as the ExclusionPath VALUE**, so a\n  `-contains` test reads ABSENT and is meaningless; the HKLM `Windows Defender\\Exclusions\\Paths`\n  read throws `SecurityException`. Nobody may report the runner directory as unexcluded from an\n  unelevated shell.\n\n- **HYPOTHESIS ALREADY KILLED, so nobody re-runs it:** the Windows-only `ADAPTER_WEB_PENDING`\n  reconcile failure (servehost nudge) **cannot** explain this — spt-store monic and contextstore\n  never touch that path.\n\n- **WHAT IS STILL NOT ESTABLISHED (labelled, so it is not inherited as fact).** The dating argument\n  establishes environment-DOMINANT and bounds head growth as the minor term. It does **not**\n  apportion the environment term itself: Defender vs the third-party torrent load vs the fleet\n  brain's steady read vs anything else is unsplit, and **\"MsMpEng at 89%\" remains a correlate\n  measured beside the slowdown, not a proven cause.** The discriminator lane below is what settles\n  head-vs-environment on evidence rather than on the shape of a drift curve.\n\n- **REMEDY — none landed. This entry is the debt, and its middle arms need an operator.** Sequence\n  matters; run them in this order:\n  1. **DISCRIMINATOR LANE (hertz, one box, ~1.5-2 h).** Run the five named tests at `04e32c8c` and\n     at `f6110c2a` on hfenduleam. **Same-slow at both = environment; slow only at the head = head\n     growth.** Cheap and decidable, and it must precede any operator ask — do not spend an elevation\n     request on a hypothesis a one-lane measurement can test. Design note, because it is the part\n     that makes the number trustworthy: the arms run **INTERLEAVED** (A/B/A/B/A/B, 3 reps each), not\n     all-A-then-all-B, so drift that hits the whole box cancels in the comparison instead of landing\n     on one arm. **A measurement that only works if everyone behaves is not a measurement** — the\n     torrent client and Defender are running throughout and are the thing under test, not noise\n     anyone gets to remove. Confounder already excluded: the three test-bearing files\n     (`spt-daemon/tests/sync.rs`, `spt-store/src/monic.rs`, `spt-store/src/syncmerge.rs`) are\n     **byte-identical blobs at both shas**, so a difference cannot be the tests changing; the two\n     crates around them are not (+11,388 lines over 48 files).\n  2. **Remove the third-party load first.** No torrent client on the CI box during golden windows.\n     It is the cheapest variable to remove, and removing it first makes arm 3's benefit measurable\n     instead of confounded.\n  3. **OPERATOR ASK — Defender path exclusions** for `C:\\actions-runner\\_work` and the gate pools,\n     read from an ADMIN shell first (see the unreadable-row warning above), then re-measure the\n     first-touch tax on a file **under that path** — the scratchpad measurement is outside the\n     runner dir, so it proves the mechanism's size, not the runner's exposure. Unsettable\n     unelevated; same shape as **IR-89**'s elevated firewall rule.\n  4. **CI census, cheap and durable:** print `Get-MpComputerStatus` RealTimeProtectionEnabled plus\n     the ExclusionPath read **verbatim, refusal text included**, in the Windows job's census step,\n     so a run's own record says what Defender it ran under.\n  5. **Re-measure both caps after any arm lands — the arm a future reader will skip, so it is loud\n     here.** A cap sized against a degraded box is correct only while the box stays degraded.\n     Leaving 80 in place after a repair silently restores the original hazard: a wall so generous it\n     no longer catches a wedged test, which is the job the golden cap was added to do in the first\n     place (the 2026-06-03 handoff.rs ConPTY stall, 22 unbounded hosted minutes).\n- **Kin:** [[IR-76]] (the golden runner IS the builders' box — the structural reason a desktop's\n  load reaches CI at all), [[IR-64]] (box-level facts only the operator can move), [[IR-89]] (the\n  other elevated box-rule ask), `defender-first-touch-tax-on-fresh-test-binaries` and\n  `e2e-leaked-daemons-shared-box` (memory).\n- **Ripe when:** arm 1 now; arms 2-4 on the operator's answer; arm 5 at the next `golden.yml` touch\n  after any of them. · **Size:** arm 1 a measurement, arm 4 one census line, arm 5 two literals.\n- **AMENDMENT 2026-09-09 (two terms this entry did not name when it landed at `d32d5c4c`).**\n  1. **`ci.yml`'s `changes` job runs `unit` on BOTH runners for every push to `main`.** The classify\n     step at `.github/workflows/ci.yml:49` emits `code=true` for every non-`pull_request` event, so\n     the docs-only skip that PR runs #206/#207 demonstrated is **`pull_request`-only** — read from\n     `ci.yml` at `main` by doyle, who names it his own error after twice ruling the opposite from the\n     PR runs alone. Consequence for this entry's wall clock: run **34337797758** (the ff of\n     `b66a9612`, a docs-only delta over golden-green `a2f335f8`) ran `unit (Windows)` 09:59:57Z →\n     10:40:48Z and was **CANCELLED at the 40-minute job wall** (job timeout; conclusion `cancelled`,\n     step 6 `Unit tests` 10:08:23 → 10:40:03) — a red on `main` at a sha whose content cannot fail a\n     unit test. It is an IR-85 face, not a flake row.\n  2. **A near-full volume is an environment term for the slowdown**, alongside the Defender\n     first-touch tax and the operator-desktop load already recorded. **Deliberately unquantified:**\n     the discriminator window that would have apportioned it was VOID, because the one leg that\n     completed ran under both a CI job and a falling disk. See **IR-90**.\n- **WHAT THE VOIDED DISCRIMINATOR ESTABLISHED, negatively (hertz, 2026-09-09).** The fs-heavy\n  slowdown REPRODUCES at `04e32c8c`, which predates the +11,388-line head growth: spt-daemon\n  `concurrent_writes` 105.420 s, `two_tier_sync` 58.362 s, spt-store `clone_copies` 65.657 s,\n  `different_monics` 73.967 s, `syncmerge reconciled_write` 86.765 s, against the 09-06 baseline of\n  22.4 / 18.7 / 17.7 / 18.2 / 27.3 s — **3.2x to 4.7x on all five, at the OLD sha**. So head growth\n  is **not NECESSARY** for the slowdown. That is the whole of it: it does NOT measure how much the\n  environment explains, and it is not evidence about the head arm at all — that leg ran inside run\n  34337797758's window and on a volume that reached 0.018 GiB free, and the head arm never produced\n  a comparable pair. **Arm 1 stays OPEN**, its re-run deferred until **IR-90**'s guard exists and a\n  window with no `main` push and no CI job on the box can be scheduled.\n\n- **AMENDMENT 2026-09-10 (hertz, on THIS ENTRY'S OWN arm-1 design note).** The note says the arms run\n  **INTERLEAVED** A/B/A/B so box drift cancels. It does not cancel: **B is always the later arm within\n  each pair**, so a monotone drift across the session lands on B every time and is read as an arm\n  effect. Alternate the PAIR ORDER — **A/B then B/A** — record per-leg timestamps and conditions, and\n  describe the result as **REDUCING order confounding, not eliminating it**. Second binding change,\n  from the releases#294 triage: **instrument, do not infer.** `cargo nextest run --success-output\n  immediate` retains stdout for PASSING tests (deployah), so a passing arm can still print poll\n  elapsed, iteration count, IPC time and producer progress — **a failing arm is not required** for a\n  margin measurement (todlando, correcting deployah's \"it has to fail to be informative\"). Arm 1 was\n  never re-run, so this lands before the measurement, not after it.\n\n### IR-86 — golden's 32 GiB floor is BELOW the measured 67.4 GiB Windows suite footprint, so a start floor passes a box that cannot finish\n\n- **Status:** OPEN, filed by doyle 2026-09-08 at the #272/v0.68.0 golden r2 triage. · **Origin:**\n  run 34262154550 @ `25e60015` (shaped on `e4444413`), Windows test job 102182665033: every product\n  step green (Phase A 3346/3346, Phase B 234/234, Summary 2, FAIL 0), the ONLY reds were the two\n  in-job floor gates. `FLOOR_START` 97,649,786,880 B PASS at 18:47:23Z -> `FLOOR_DOCS`\n  25,284,501,504 B RED at 19:31:55Z -> `FLOOR_END` RED. Consumed in-job: 67.4 GiB.\n- **Mechanism:** `golden.yml` derives 32 GiB as \"the observed tens-of-GB full-suite footprint\n  rounded up to the next binary boundary, preserving headroom for one complete run\" (comment\n  above the Windows start floor). The measured footprint is 67.4 GiB, so a start reading anywhere\n  in [32, ~100) GiB passes and the job then walks under the floor by construction: box baseline\n  91 GiB minus 67.4 = 23.5 < 32. This is a shortfall of the DERIVATION, not a rate, not a product\n  red, and not the instant-vs-sustained face IR-46 files (that face is fixed by the FLOOR_DOCS\n  re-read, which is what caught it). The start floor must be footprint + end-floor (~100 GiB) or\n  it asserts nothing about finishing.\n- **Coverage consequence (the load-bearing part):** the Windows `Docs drift gate (CLI ref + llms\n  links)` step is sequenced BEHIND `FLOOR_DOCS`, so it SKIPPED and r2 held NO Windows CLI-ref\n  axis at that sha until the rerun. A floor red that skips a gate is a coverage hole wearing a\n  disk red.\n- **Kin:** [[IR-46]] (a floor asserts an instant), [[IR-59]] (pool arithmetic, LNK-class reds\n  that name no disk), [[IR-64]] (the operator-payload reservoir that sets the box baseline; its\n  ripe-when arm — a golden that dies at the floor despite adopted pool discipline — FIRED here\n  in the in-job form), [[IR-73]] (second half BUILT: the within-job re-read exists and is what\n  produced the FLOOR_DOCS reading), REQ-CI-FREE-SPACE-PREFLIGHT.\n- **Coupling (deployah 23:54Z, from `golden.yml` at `25e60015`):** the Windows `DISK docs floor`\n  (:616) and `Docs drift gate — windows` (:629) carry only `if: runner.os == 'Windows'`, no\n  `always()`, while `DISK end floor` does (`always() && runner.os == 'Windows'`, ~:705). Actions'\n  default is \"previous steps succeeded\", so ANY Phase B red skips the docs axis by construction —\n  observed three times at this sha (floor red, ttl cell, ttl cell). The docs gate is therefore never\n  independent evidence: it can only be banked when Phase B is green in the same job. Remedy line:\n  gate the two docs steps on `!cancelled()` plus the success of the steps they actually depend on\n  (checkout/build), not on Phase B — a rig change, new sha, hertz workflow rider slot.\n- **Remedy shape:** re-derive the start floor from the measured footprint (67.4 GiB Windows,\n  Linux to be measured) plus the 32 GiB end floor, print the footprint (start minus end free)\n  on every run so the number re-measures itself, and keep the 32 GiB literal only for\n  `FLOOR_END`.\n- **Ripe when:** next `golden.yml` touch (hertz workflow rider slot). · **Size:** small — one\n  literal per start-floor site + one printed subtraction.\n\n### IR-87 — two-host ceremony halves are INDEPENDENT jobs on DIFFERENT runners (A Windows/hfenduleam, B Linux/kitsubito); B's 900 s budget runs on B's own clock, so any older queued Windows job starves A and reds B deterministically, and the panic text blames pairing\n\n- **Status:** OPEN, filed by doyle 2026-09-08 at the #272 golden r2 triage. · **Origin:**\n  run 34262154550, twohost-b job 102207296960 (log 81,692 B, sha256 67403f04…8030): role B built,\n  rostered, polled PAIR_MEET_UP every 30 s from 19:34:30Z, and hit the rig_wait barrier\n  \"pairing: A rostered via the daemon-hosted responder\" at its 900 s deadline 19:49:17Z\n  (`crates/spt-daemon/tests/twohost.rs`, exit 101, 2 passed 1 failed). twohost-a (102207296985)\n  was QUEUED from 19:32:13Z with no runner: the Windows runner went to thin ci run 34261096301\n  (post-merge on main @ `e4444413`) the second the golden test job released it at 19:31:56Z.\n- **Mechanism:** `golden.yml` sequences twohost-a and twohost-b after `test`, but they are two\n  jobs on two runners (measured 2026-09-08 20:56Z via the jobs API `runner_name`: twohost-a on\n  hfenduleam, twohost-b on kitsubito), and GitHub's queue does not honour a workflow's intra-run\n  job ordering against a FOREIGN run on either runner. B starts, its whole budget ticks against a partner that has not been\n  scheduled, and `rig_wait` panics `never converged on the rig: {what}` — a text that reads as a\n  pairing defect. The lanes were not at fault, and twohost-a's outcome was predetermined once B\n  exited (a later A pass would be vacuous).\n- **Kin:** [[IR-76]] (hfenduleam is golden runner AND builders' box; the job-start census cannot\n  see a competing GitHub run either), [[IR-62]] (rig collisions on shared runners), the W1 two-host\n  rig, `a-barrier-cannot-ride-a-carrier-its-sender-outlives` (memory, same family: a barrier needs\n  the receiver's own answer).\n- **Remedy shape (pick at rider time):** (1) start barrier on B keyed to A's job having STARTED\n  (a run-scoped artifact or a `needs`+matrix collapse into ONE job that spawns both roles), or\n  (2) B's deadline clock starts at first A-rostered signal with a separate, longer \"A never\n  appeared\" budget, or (3) the panic names the missing partner's job state so triage does not\n  chase pairing. Any option: the two-host halves must never share a runner queue with a foreign\n  run while one half waits.\n- **Ripe when:** next `golden.yml`/twohost rig touch. · **Size:** small-medium (job shape or\n  barrier rework + panic text).\n\n- **AMENDMENT 2026-09-10 (releases#294, golden 34445961595 att1 @ `a9e786b2`) — THE STARVING RUN CAN\n  BE GOLDEN'S OWN PR, which makes this self-inflicted and recurrent on every golden run with a PR\n  open.** Measured timeline: **07:18:59Z** golden `test (Windows)` completes and releases hfenduleam;\n  **07:18:59Z** twohost-a queued; **07:19:01Z** PR run **34446095808** job `unit (Windows,\n  hfenduleam)` SEIZES the runner; **07:19:02Z** twohost-b starts on the free kitsubito; **07:36:16Z**\n  twohost-b fails at **900.41s** — `never converged on the rig: pairing: A rostered via the\n  daemon-hosted responder`. The origin case (2026-09-08) was a post-merge push on `main`: a run\n  belonging to someone else. **Here the starving run is the `pull_request` run of the very PR carrying\n  the golden head**, so opening the golden PR arms the starvation of that same head's twohost pair.\n  **Consequence for the remedy shape above: any option that only de-conflicts against OTHER lanes'\n  runs does not reach this case.** The golden head's own PR has to be excluded from the Windows\n  runner for the duration of the golden run (or the pair collapsed into one job, option 1).\n- **SECOND-ORDER FACE (deployah, same run): starvation does not merely red B — it desynchronises the\n  pair past repair.** twohost-b was TERMINAL at 07:36:16Z; twohost-a did not start until **07:48:07Z**\n  — the two halves never overlapped for a single second, so twohost-a's outcome is uninformative\n  **whatever it says**, and a red there must not be counted as a second product failure. Recorded\n  honestly at deployah's own insistence: **VOID is his SCORING interpretation, not a fact about the\n  run** — the release record carries GitHub's raw `conclusion` for both jobs beside the scoring, not\n  laundered into it.\n- **⚠ ITS WALL CLOCK IS INDISTINGUISHABLE FROM [[IR-89]]'s.** A 900 s twohost red whose panel blames\n  pairing is ALSO the exact signature of the banked Windows-firewall hazard. The panel alone cannot\n  separate them; **the job TIMELINE can**. Check the schedule before accepting the firewall hazard for\n  any 900 s twohost red — this one fit that signature perfectly and was not it.\n\n### IR-88 — `pool-release` via `cargo run -p xtask` REBUILDS xtask INTO the pool it is releasing, so a reaped pool regrows ~2.8 GB in silence\n\n- **Status:** OPEN, filed by doyle 2026-09-08 from hertz's reap report (20:00Z) during the #272\n  golden r2 repair. · **Origin:** hertz reaped hertz-lane4 / hertz-repin / hertz-percell-id target\n  subtrees (Length-sum upper bounds 68.16 / 47.11 / 8.79 GB) and then ran `cargo run -p xtask --\n  pool-release …` from each worktree: cargo rebuilt xtask into the just-reaped `target/` (2.8 GB\n  back in lane4, partial in repin), nothing printed said so, and the descendancy stopper killed\n  the second before it finished. Removed by hand afterwards; the post-reap free reading on the\n  record (275.95 GiB at 19:55:51Z) predates the regrowth.\n- **Mechanism:** the documented verb (AGENTS.md: \"drop it with `pool-release`\") is a `cargo run`,\n  and cargo's default target for that run IS the pool being released. The verb's own success path\n  recreates the state the operator just measured away; a teardown step that runs it AFTER a reap\n  undoes part of the reap and leaves the recorded free reading stale.\n- **Remedy shape:** either (a) `pool-release` documented and scripted as a PREBUILT `xtask.exe`\n  invoked against `--pool <dir>` from another pool, or (b) the verb refuses when its own\n  `CARGO_TARGET_DIR`/default target equals `--pool` and prints the prebuilt form, or (c) the reap\n  recipe orders release BEFORE the subtree delete. Memory banked 2026-09-08\n  (`pool-release-rebuilds-xtask-into-the-pool-you-just-reaped`); this entry is the durable home.\n- **POSITIVE CONTROL (hertz, 2026-09-09, ruling-3 gate-r3 teardown):** the same release run\n  from a PREBUILT `xtask.exe` invoked from outside the pool regrew NOTHING — the pool's own\n  `xtask.exe` still carried its original 21:00:42 mtime afterwards, and the reap that followed\n  reclaimed 63.71 GiB (132.03 -> 195.74 GiB free) against a 64.88 GiB Length-sum. So the\n  regrowth is a property of the `cargo run` VEHICLE, not of the verb, and remedy (a) is proven\n  rather than merely proposed.\n- **Kin:** [[IR-31]] (pool budgeting), [[IR-56]] (pool-claim identity from CWD — same verb\n  family, same \"the tool acts on where it stands\" shape), releases#103.\n- **Ripe when:** next xtask pool-verb touch or the teardown runbook edit. · **Size:** tiny —\n  one guard or one doc line.\n\n### IR-89 — hfenduleam's Windows Firewall drops cold inbound UDP to the runner-built test exes, so the two-host rig's first B→A claim (W2 helper) reds for its whole 900 s budget and the panic blames A\n\n- **Status:** BOX HALF **APPLIED** 2026-09-08; WORKFLOW HALF **BUILT** 2026-09-09 — PR #211\n  (`9b96d7e7` + this amendment), **LANDED-pending-golden**: the `golden.yml` steps are UNEXERCISED\n  until the next golden run, because thin CI compiles the cells and skips them. Filed by doyle 2026-09-08\n  at the #272 golden r2 terminal triage; the operator-blocked flag is retired here, because\n  the operator acted.\n  The operator applied BOTH layers that evening — the Windows inbound rule (~23:41Z) and the\n  tailnet ACL grant (~23:56Z) — and the re-probe with the same rule-less pwsh listener read\n  **3/3 over Tailscale on 7483 AND 3/3 on 7489 at 23:57:50Z** from `100.98.197.12`, with a\n  post-terminal probe 3/3 on both ports at attempt 4. v0.68.0 then shipped at `a2f335f8` with\n  both two-host legs GREEN on golden r4, so the box half is closed by measurement and not by\n  assertion. **STILL OPEN, and it is the durable half:** the WORKFLOW guard (hertz) — the\n  pre-ceremony B→A UDP probe at `d882297f` that reds `INBOUND_BLOCKED` in 10 s with its own\n  name instead of burning 900 s blaming pairing, plus retiring the dead `_work\\spt-core`\n  rules note in the runner runbook. Until that lands, the next box (or the next ACL edit)\n  re-opens the 900 s face with nothing to name it. · **Origin:** run 34262154550 @ `25e60015`, twohost-a 102229928746\n  (`two_host_web_helper_role_a`, :968, 900.40 s) and twohost-b 102229928689\n  (`two_host_web_role_b`, :559, 910.20 s): B logged 75 × \"A not ready … broker QUIC op exceeded\n  the 10s bound (peer unresponsive)\" from 20:49:49Z to 21:04:37Z and was never ADMITTED. Ladder\n  green both sides; both halves started 20:41:23Z on their own runners (not IR-87's starvation).\n- **Mechanism (MEASURED 21:11Z):** the box's firewall policy is `BlockInbound,AllowOutbound` on\n  all three profiles (Ethernet and Tailscale both Private). Inbound allow rules exist only for\n  exes under `Documents\\projects\\spt-core\\target` (interactive Allow clicks) and under the DEAD\n  pre-rename runner path `_work\\spt-core\\spt-core`; exactly ONE under `_work\\spt-bs-core` (its\n  `target\\debug\\spt.exe`, the CLI, not the binder — deployah's count, mine had said zero), none for\n  any `twohost_web-*.exe`. `Get-NetFirewallProfile` shows `DefaultInboundAction = NotConfigured`,\n  whose effective default IS block: the block is Windows' default, not a configured policy, so there\n  is no policy to \"restore\". The runner is a service (`.\\decid`), so the Allow dialog that minted the\n  old rules cannot appear. A's helper cell 3 bound `broker udp 7483` inside\n  `_work\\spt-bs-core\\spt-bs-core\\target\\debug\\deps\\twohost_web-f73bc44be13353fb.exe`; B dialled\n  `100.68.35.65:7483` cold. Probe: a rule-less pwsh UDP listener on hfenduleam:7483 received 0 of\n  3 datagrams from kitsubito `100.98.197.12`; the reverse control (python listener on\n  kitsubito:7483) received 3 of 3 from hfenduleam.\n- **Why three faces from one cause:** the shared-key rig (pre-`e4444413`) reached A only through\n  holes A's OUT-dialling cells (7480–7482) had opened for `id_a` — six 10 s bounds until B's\n  magicsock fell onto one of those paths, then ADMITTED (the 63 s stall, helper-stall memory), or\n  onto a live same-key sibling that never replied (the 21 min hang in 34239258523). Per-cell A\n  identity (`id_a_for`, `e4444413`) removed the accidental route by construction, leaving only\n  the cold path, which the firewall drops. hertz's one-box discriminator \"vanishes\" was true on\n  one box because one box never crosses the firewall. Product and rig are both exonerated; the\n  rig's `a_addr` comment already names W2 as the first A-ward claim.\n- **Remedy (two halves):** (1) BOX, operator-owned, elevated on hfenduleam:\n  `New-NetFirewallRule -DisplayName \"spt-ci two-host rig UDP-In (kitsubito only)\" -Direction Inbound -Action Allow -Protocol UDP -LocalPort 7460-7499 -RemoteAddress 100.98.197.12 -Profile Any`\n  (rig ports at the sha: ladder 7460/7461; web `PORT_OFFSET` 20 → A cells 7480–7483, B 7481; the\n  A-ward surface today is exactly UDP 7480–7483 — deployah's tighter range — and the whole range\n  moves with any `SPT_TWO_HOST_PORT_A` override, so the rule must move with it);\n  program-path rules are the wrong shape because the exe hash changes per build. Verify with the\n  same probe (3/3) before any rerun. (2) WORKFLOW, hertz: a B→A UDP probe step in the twohost\n  jobs before the ceremony, so this reds in 10 s with its own name instead of 900 s blaming\n  pairing; and retire the dead `_work\\spt-core` rules note in the runner runbook.\n- **Kin:** [[IR-83]] (the tailnet-ACL face of a cross-box inbound block — KIN, **NOT the same\n  finding**: that entry is the tailnet policy layer, this one is the Windows firewall layer, and\n  the SECOND LAYER note below is exactly the measurement that separates them), [[IR-87]] (the\n  other way a half waits 900 s on a partner), [[IR-76]] (golden runner\n  is the operator's box), [[IR-64]] (box-level facts only the operator can move),\n  `twohost-web-helper-stall-shared-a-identity-stale-path` (memory; its CONFIRMED arm is re-read\n  by this entry).\n- **AMENDMENT 2026-09-09 — the WORKFLOW half is BUILT and FIELD-MEASURED; it is LANDED-pending-golden\n  (hertz).** The guard is two cells in `twohost_web.rs` plus a step per half in `golden.yml`, and it\n  grew four design corrections that are worth more than the guard itself, because each one is a way a\n  probe can certify the fault it exists to catch.\n  1. **A FIXED SYMMETRIC WINDOW ADDS A THIRD CAUSE THAT LOOKS LIKE THE OTHER TWO.** The step boundary\n     orders the probe on ONE host; it does not align two, and after the ladder each half pays its own\n     wrapper and `cargo test` (on Windows a fingerprint scan plus Defender's first touch of a fresh\n     exe). MEASURED: the first hand-run in the A=kitsubito direction (13:14:13 → 13:14:51Z) redded\n     `INBOUND_BLOCKED` at 10.24 s with text asserting \"a BOX rule, not a product or rig fault\" — and\n     the cause was `cargo`'s start-up on the SENDER putting its first datagram after the receiver's\n     10 s window closed. An innocent box, the guard's own words against it. What stopped it being\n     filed as a kitsubito block was that the box facts contradicted the text (`tailscale debug\n     netmap` on kitsubito lists `100.68.35.65/32` among its permitted inbound sources, and `ufw` is\n     inactive) — a failure text that contradicts a measured box is the text's defect. So the\n     rendezvous is DATA: A listens up to the rig budget and beacons once a second; B binds first,\n     waits for a beacon, and only then starts a ten-second clock, so B's red has already excluded\n     \"A is not up\". That is a FOURTH outcome with its own name, `PROBE_NO_BEACON`, never\n     `INBOUND_BLOCKED`.\n  2. **THE LISTENING SOCKET MUST NEVER SEND.** Any outbound datagram from the measured port opens\n     stateful return state for it, so B's probe then arrives SOLICITED and crosses under both layers\n     — this entry's own \"solicited return traffic works under either fault\" applied to the guard\n     rather than to the ceremony. MEASURED: with the beacon sharing A's listening socket, the\n     out-of-grant control went **GREEN at 13:28Z** on a port a listen-only run had measured BLOCKED\n     at 13:20Z; a further green at 13:31Z with the beacon moved but the ack still leaving that socket\n     was residual state from 13:28 — true BY ELIMINATION rather than by assertion: nothing in the\n     13:31 run sent from 7509 before the first arrival, so the only outbound that could have opened\n     that port's return state belongs to the previous run. Beacon and ack both leave an ephemeral socket now, and B sends\n     from an ephemeral port too, so no run repeats a 4-tuple a previous run opened.\n  3. **THE ACK IS ADDRESSED TO B'S RIG PORT, not to the probe's source port.** MEASURED: acking to\n     `from` produced a run that CONTRADICTED ITSELF — A said `INBOUND OK` and B said\n     `INBOUND_BLOCKED`, same run, 13:41:33 → 13:41:50Z — because A's ack leaves its ephemeral\n     socket, is therefore not return traffic of the flow B opened, and a receiver whose inbound rule\n     is a port RANGE drops it. The rig port is the only address either host is reachable on cold.\n  4. **THE FALSIFIER, and it is the operator's own rule used as an instrument.** Forcing the probe\n     port to **7509** (`SPT_TWO_HOST_PORT_A=7480`), one port outside the granted udp 7460-7499, reds\n     the guard on demand with no elevation and no policy edit. Run TWICE BACK TO BACK at the final\n     code, 13:43:41 → 13:44:23Z and 13:44:25 → 13:45:07Z: **RED, RED** — A after 40 s having sent\n     39 beacons, B in its ten seconds having sent 48 and 47 datagrams with no ack, both exit 101.\n     One red would only prove a state timeout expired; two consecutive reds prove the design writes\n     none. The grant boundary is therefore measured from inside the test binary: 7489 crosses, 7509\n     does not, same hosts, same binary, one env var apart.\n  5. **ONE ACK IS NOT ENOUGH — the same split verdict arrives by packet loss** (doyle, reviewing the\n     built lane). A acking ONCE and breaking leaves B's red resting on a single unrepeated UDP\n     datagram: lose it and A prints `INBOUND OK` while B reds `INBOUND_BLOCKED`, blaming a firewall\n     for ordinary loss — correction 3's defect reached by a different road. A now keeps draining for\n     a short window after its own verdict is already settled and acks EVERY probe in it, while B\n     stops on the first ack. The A-side assertion is unchanged: it was decided by the first datagram.\n  6. **THE PROBE STEPS CARRY THEIR OWN BUDGET, 300 s, set EXPLICITLY** beside ceremony steps that say\n     900. It bounds RENDEZVOUS skew, not pairing, so a blocked link costs 300 s ONCE instead of 900\n     per cell per half. Left unset it would have been `from_env`'s invisible default sitting next to\n     a visible 900 on the step below — a number the next reader would have inferred wrongly, which is\n     this entry's whole failure mode in miniature.\n- **FIELD PROOF, 2026-09-09, and it is the ONLY proof this guard has:** `dir 1` (A=hfenduleam,\n  B=kitsubito) 13:45:14 → 13:45:18Z and `dir 2` (A=kitsubito, B=hfenduleam) 13:45:41 → 13:45:58Z,\n  both GREEN with the ack after ONE datagram, both exits 0, both hosts running byte-identical source\n  (md5 `f31779339266f8034dcd72917c56a37e`, checked on both sides). Free space 174.38 GiB, flat across\n  all four arms.\n  ⚠ **THE `golden.yml` STEPS THEMSELVES ARE UNEXERCISED UNTIL THE NEXT GOLDEN RUN.** Thin CI\n  compiles the cells and SKIPS them — `Rig::from_env` returns `None` without `SPT_TWO_HOST`, so a\n  green thin run says the code builds and nothing about the steps. The wall times above are the field\n  proof; treat the workflow half as landed-pending-golden and not as verified by its own PR.\n- **Ripe when:** the next GOLDEN run, which is the first thing that exercises the steps — the\n  code half is built and field-measured (PR #211). (The box half was ripe \"now\" against\n  `25e60015` and is done; #272 golden acceptance is no longer blocked by it.) · **Size:** one\n  workflow step remaining; the elevated command is spent.\n- **SECOND LAYER (measured 23:41–23:50Z, after the operator applied the Windows rule exactly as\n  asked and the re-probe STILL read 0/3):** the tailnet ACL. The same `python.exe` listener (own\n  program rule) received 3/3 from kitsubito over the LAN (`192.168.1.168 → 192.168.1.81:7483`) and\n  0/3 over Tailscale (`100.98.197.12 → 100.68.35.65`), TCP connect over Tailscale times out too,\n  solicited return over Tailscale works, ShieldsUp false both ends. `tailscale debug netmap` on\n  hfenduleam: one PacketFilter rule, 18 permitted inbound sources, kitsubito ABSENT; kitsubito is\n  `tag:eye-tracking-resource` owned by a different tailnet user, and its own filter DOES permit\n  hfenduleam. Asymmetric policy: member device → tagged resource allowed, reverse denied. The\n  Windows rule was NECESSARY (rule-less exe, LAN probe 0/2 earlier) and NOT SUFFICIENT. Remedy\n  half (1) gains an ACL grant, operator-owned in the admin console:\n  `{\"action\":\"accept\",\"src\":[\"tag:eye-tracking-resource\"],\"dst\":[\"hfenduleam:7460-7499\"],\"proto\":\"udp\"}`.\n  Rider 4's failure text names both layers and the LAN-vs-Tailscale probe as the discriminator.\n  Lesson for the entry: a cross-box \"unresponsive\" has at least THREE layers (Windows rule, tailnet\n  policy, the exe's own bind); probe through the SAME path the rig uses, and re-probe after every\n  single change — the first fix reading as \"applied\" is not the probe reading 3/3.\n- **Corroboration + reading traps (deployah 23:50Z, from the box):** Windows rule found present by\n  FILTER search (`netsh advfirewall firewall show rule name=all dir=in verbose`), not by name — the\n  operator's name is hyphenated \"two-host\" and a `twohost` grep reads it ABSENT. Netmap: the single\n  filter permits ALL ports and ALL protocols from its 18 sources, so the grant is SOURCE-scoped, not\n  port-scoped — \"this peer is not a permitted source at all\", which is why TCP timed out beside UDP.\n  Two permitted sources (100.98.213.33, 100.98.214.87) share kitsubito's 100.98/16 and read as hits\n  to an eyeball scan for \"100.98.\"; test membership of the full /32, never a prefix. His first netmap\n  read extracted a non-existent field (`SrcIPs`; the real key is `Srcs`), printed an empty list and\n  minted a confident \"ABSENT\" — an empty extraction cannot witness absence; the 18-count is from the\n  corrected read. Prefs on the box: ShieldsUp false, NoStatefulFiltering true, RouteAll true,\n  NetfilterMode 2 — nothing there explains the drop.\n- **Probe-rider design rule (hertz, d882297f):** the pre-ceremony probe reds `INBOUND_BLOCKED` for\n  EITHER layer and does not pretend to know which — its job is \"the box cannot receive, stop triaging\n  the product\"; the layer is named only by the one measurement that decides it (same listener, LAN\n  vs Tailscale), which the failure text prints as a recipe. A guard that names a cause it did not\n  measure is the defect class this whole entry documents.\n\n\n[Showing lines 4664-5149 of 5782. Use :5150 to continue]"}],"details":{"truncation":{"content":"### IR-84 — the one `PUMP_PEER_FAIL` arm the rigs actually fire was the only one carrying no clock, so the stall that produced it could be counted but never timed\r\n\r\n- **Status:** OPEN, filed by hertz 2026-09-09 with the instrument that closes its first half. ·\r\n  **Origin:** the 65 s two-host helper stall (design written before the run,\r\n  `docs/design/RIDER-65S-DESIGN.md`). The number was branch-claimed 2026-09-08 by name only — IR-85\r\n  records that it carried no entry text in any register file in any worktree — and this is that text.\r\n- **Symptom:** `two_host_web_helper_role_a` takes **61.956–69.096 s** across five runs while its\r\n  siblings in the same binary and the same run take **0.135–0.753 s**. Every ladder rig —\r\n  win-onebox, linux-onebox, cross-box — logs **exactly ONE**\r\n  `PUMP_PEER_FAIL:<node>:peer reply-read: no progress within budget — dropping peer (brain IPC read\r\n  deadline elapsed)` on B before completing. **3/3, one each, never on A** (doyle's GATE-W3 readout).\r\n- **Cause of the DIAGNOSTIC failure, which is what this entry is about:** that line is emitted from\r\n  the `Err(e)` arm of `peer_leg_outcome` (`crates/spt-daemon/src/pump/mod.rs`), and at\r\n  `b0b67aaa` it read `emit_line_err!(\"PUMP_PEER_FAIL:{peer_hex}:{e}\")` — **no timestamp**. Measured\r\n  at that sha rather than recalled: the file carries **four** `PUMP_PEER_FAIL` emit sites, **three**\r\n  of them stamped `wall_ms=… mono_ms=…` (the submit arm, the no-route arm, and the\r\n  `PRESENCE_DIAL_FAILED` arm), and this one was **the only unstamped site left**. It is also the\r\n  arm the rigs actually fire — a `PEER_REPLY_READ_BUDGET` expiry reclassified out of `TimedOut` by\r\n  `brain::reclassify_peer_reply_err` so it drops one peer rather than poisoning the round. **The\r\n  single arm a reader most needs to time was the single arm that could not be timed.**\r\n- **What that cost, stated as the open question it left:** the arithmetic does not close and this\r\n  entry does not close it. `PUMP_PEER_IO_TIMEOUT` is **30 s** (`:118`) and `SUPERVISE_BACKOFF_BASE`\r\n  is **5 s** (`:121`) — read as constants, not recalled — so one deadline plus one supervise floor\r\n  accounts for **35 s** against **61.956–69.096 s** observed. **~27–34 s is unaccounted**, itself\r\n  close to another 30, which is exactly the coincidence the design document warns against; and the\r\n  count of **exactly one** fail forbids the easy reading that two deadlines elapsed. Three candidates\r\n  stay open and are NOT ranked here: a first ~30 s burned before the deadline's clock starts; a\r\n  second budget stacking on the first; or the restart's re-prime costing materially more than its\r\n  5 s floor. **Separating them needs the deadline's own timestamps against the fail line** — which\r\n  is precisely what the log did not carry.\r\n- **⚠ WHAT THIS ENTRY DOES NOT CLAIM.** The instrument does not explain the stall, does not shorten\r\n  it, and changes no product behaviour: the same peer is dropped at the same instant with the same\r\n  backoff. It makes the stall **answerable from a log that already contains the failure**, instead of\r\n  requiring a rebuild to learn when the budget started. `PUMP_PEER_IO_TIMEOUT` is a hard const with\r\n  no env knob, so varying it costs a rebuild — deliberately deferred until the stamps say which half\r\n  of the arithmetic is missing.\r\n- **Kin and the recurrence that matters:** this is the **SECOND** time an unstamped\r\n  `PUMP_PEER_FAIL` cost a hunt. The `PRESENCE_DIAL_FAILED` arm carries a comment naming the\r\n  \"2026-07-14 `PUMP_PEER_FAIL`-unstamped seed, folded here\", and **REQ-PUMP-STAGE-TRUTH** already\r\n  requires every peer failure \"stamped (wall+mono) and peer-attributed\", explicitly subsuming that\r\n  seed. So the contract was written, three of four sites complied, and the fourth stayed silent for\r\n  eight weeks — **a convention enforced by no mechanism degrades one arm at a time, and every reader\r\n  of a complying arm reports the convention as held**, the same shape as the `validate_docs_dir`\r\n  refusal-arm rider in the same design document. Also kin: **IR-83** (the rig population had only\r\n  ever run the admitted direction), `REQ-HAZARD-PUMP-IPC-DEADLINE` (a `TimedOut` brain-IPC read is a\r\n  supervised restart, never a per-peer retry), ADR-0039 Decision 5.\r\n- **Ripe when:** now, and it lands with this entry — the stamp is one emit line, tagged\r\n  `[impl->REQ-PUMP-STAGE-TRUTH]` at the site. · **Size:** one emit line plus its comment.\r\n  **Follow-up, not this lane:** a cell that walks every `PUMP_PEER_FAIL` arm and asserts each one\r\n  stamps, so the fifth site added cannot be born silent.\r\n### IR-85 — the Windows self-hosted box runs its fs-heavy tests 3-4x slower than a week ago; two CI wall clocks were sized for the old box, and a red run kept hiding it\r\n\r\n- **Status:** OPEN, filed by hertz 2026-09-09 at the #272/v0.68.0 golden r3/r4 arc, on doyle's\r\n  dispatch. Number ruled by doyle from his own census of main@`a2f335f8` (register ended at IR-83;\r\n  IR-84 was branch-claimed by name only, with no entry text in any register file in any worktree —\r\n  that gap is now closed: **IR-84 was filed 2026-09-09 in PR #213**, so this sentence records the\r\n  state at `a2f335f8` and is no longer a reason to go looking for a missing entry).\r\n  **Absorbs two drafts:** doyle's `IR-DRAFT-windows-fs-heavy-slowdown-and-golden-wall` (his IR-A +\r\n  IR-B) and his earlier `IR-NEXT` (operator-desktop load), both retired by reference — this is the\r\n  single entry. Every job/step and per-test timing below is **doyle's**, read via the job/step API.\r\n  · **Origin:** #272 golden r3 attempt 2 was CANCELLED by a wall clock with both test phases green.\r\n- **⚠ THE CAP CHANGE IN `a2f335f8` IS NOT THE FIX AND MUST NOT BE READ AS ONE.** It bounds the run;\r\n  it repairs nothing. A future reader who finds an 80-minute wall and no entry here would reasonably\r\n  conclude the problem was solved. It was only made visible.\r\n\r\n- **A GREEN RUN COSTS MORE THAN A RED ONE, WHICH IS WHY THIS WENT UNSEEN.** A failing run\r\n  short-circuits past the wall a green run has to cross. r3 att1 finished in **48m39s only because\r\n  it FAILED at Phase B**; att2, green, hit 49m59s and was cancelled. Every earlier docs-drift skip\r\n  therefore presented as \"upstream failure\" — the wall was never the reported cause of anything, and\r\n  the surviving evidence systematically flattered the budget.\r\n\r\n- **THE WALL.** Windows golden `test` job (48 steps), fully GREEN: **30m53s** (2026-08-30, run\r\n  33296634901) and **33m21s** (2026-09-06, run 34017906638). At the v0.68.0 head against the\r\n  then-current 50-minute cap — **r3 att2**, job 102352551368 at `f6110c2a`: Phase A 17m14s, Phase B\r\n  20m25s, doctests 1m04s, clippy 3m31s, **CANCELLED at step 30 at 49m59s with everything green**;\r\n  steps 31-42 (installer, docs floor, both docs-drift gates, dormancy) never ran. r2 att1\r\n  (`25e60015`, 09-08 18:47Z) reached step 34 at 44m30s. Steps 30..39 cost ~3m30s on the 09-06 green\r\n  (notify 47s, installer 13s, docs-drift 1m54s). Predicted green need ~**56 min**; cap raised to\r\n  **80** (need + ~40% for day-to-day variance) in `a2f335f8`, ci unit 25 -> 40 in the same commit.\r\n- **r4, GREEN — the first complete measurement at the head: 54m35s** (07:12:26Z -> 08:07:01Z),\r\n  **25m25s** headroom under 80; docs-drift (step 38) 2m23s; Phase A 15m51s, Phase B 22m56s. The ~56\r\n  prediction held to within 1.5 min, so the cap is sized on evidence, not generosity. **What that\r\n  does NOT establish:** it was a sizing forecast, and its holding says nothing about the cause\r\n  diagnosis below. Nor are att2-vs-r4 per-phase deltas a trend — att2 was cancelled mid-run, so only\r\n  its phase legs are comparable at all, and the spread they sit in is the same variance the 40% is\r\n  there to absorb.\r\n\r\n- **THE SLOWDOWN, per test, same box, same tests.** `spt-daemon::sync` concurrent_writes\r\n  **22.4s -> 74.8s**, two_tier_sync 18.7 -> 67.4; `spt-store` monic clone_copies 17.7 -> 62.9,\r\n  different_monics 18.2 -> 64.9; syncmerge reconciled_write 27.3 -> 51.2. **~25 spt-store/spt-daemon\r\n  tests now exceed 30s on Windows Phase A at `f6110c2a`, against 1-2s each on kitsubito.**\r\n  Phase-level: Phase A nextest 170s (09-06) -> 642s (att1) -> 1034s (att2); Phase B 710s -> 1164s.\r\n  The suite did not get more expensive — Linux is unchanged.\r\n\r\n- **DATING SAYS ENVIRONMENT DOMINATES, AND BY HOW MUCH.** main's own ci Windows `unit` job:\r\n  11-12 min on 09-06 (runs 34040416870, 34041526195, 34043323577) -> 13-20 min on 09-07 -> 12-24 min\r\n  on 09-08, hitting **22 min at `e4444413`** (run 34261096301) three minutes under its own 25-minute\r\n  wall. **Gradual over days, under no single gate change, is the shape of an environment term, not a\r\n  commit's.** Head growth is real but MINOR: +138 Phase A tests, +20 Phase B, HEAVY 34 -> 35.\r\n\r\n- **THE BOX IS AN OPERATOR DESKTOP (folded in from the retired IR-NEXT), and that turns every fixed\r\n  wall-clock budget in the Windows suite into a coin.** From the r2 arc, three attempts at ONE sha\r\n  (run 34262154550 @ `25e60015`): Phase B red each time on a **different single cell or none** — a1\r\n  234/234 (job red on disk floors only), a2 `spt::webserve_attachment_e2e` arm 12, a3\r\n  `spt-daemon::mesh_recovery roster_route_survives_a_transient_dial_failure_with_discovery_disabled`\r\n  (15.0s `converge()` budget, cell 15.715s; the same cell 9.8s / 7.2s on a1/a2). Phase A — 3,346\r\n  spawn-dominated unit cells — slowed **monotonically 448.7 -> 495.1 -> 542.6s at that one sha**.\r\n  Per-cell a3/a2 over 73 Phase B cells >= 1s: median 1.05x, mean 1.34x, 19 cells >= 1.5x, worst 5.2x\r\n  (`endpoint_lifecycle poll_vs_reap` 1.1 -> 5.8s) — **BURSTY, not uniform**. A rotating single victim\r\n  across attempts at one sha is ONE environment cause; hardening victims one at a time never closes\r\n  it (paid before: `e2e-leaked-daemons-shared-box`). The budgets that lost were ~1.5x the fast\r\n  observation — inside the box's measured variance, so they were coins that had been landing right.\r\n- **Box census (doyle 01:13-01:19Z, no cargo/rustc/nextest running, CPU 31%, ~1.1 of 16 cores busy):**\r\n  `qbittorrent.exe` seeding since 09-08 10:20Z (box tx 21.3 MB/s over 5s); fleet `spt daemon brain`\r\n  with 516 GB read since 09-07 08:03Z (~3.5 MB/s steady); Defender real-time ON, `MsMpEng` at\r\n  67.8/62.8/48.9/32.2/12.2% of a core over 5s **on the idle box**; a fresh 35 MB exe pays\r\n  2092/994/1171/1043 ms on FIRST execution against 31/263/19/260 ms on the second — **and every CI\r\n  attempt rebuilds every test binary fresh.** At 06:45Z on 09-09, with the twohost legs running:\r\n  MsMpEng 89% CPU / 991 MB WS, qbittorrent pid 47056 holding 7817 CPU-seconds (2.2 h) since\r\n  09-08 03:20, free 134 GiB (275 -> 197 -> 131 across the three r3 dispatches).\r\n- **⚠ AN UNREADABLE ROW IS NOT AN ABSENT ONE.** The Defender exclusion list cannot be read\r\n  unelevated on this box: `Get-MpPreference` returns the literal string\r\n  `N/A: Must be an administrator to view exclusions` **as the ExclusionPath VALUE**, so a\r\n  `-contains` test reads ABSENT and is meaningless; the HKLM `Windows Defender\\Exclusions\\Paths`\r\n  read throws `SecurityException`. Nobody may report the runner directory as unexcluded from an\r\n  unelevated shell.\r\n\r\n- **HYPOTHESIS ALREADY KILLED, so nobody re-runs it:** the Windows-only `ADAPTER_WEB_PENDING`\r\n  reconcile failure (servehost nudge) **cannot** explain this — spt-store monic and contextstore\r\n  never touch that path.\r\n\r\n- **WHAT IS STILL NOT ESTABLISHED (labelled, so it is not inherited as fact).** The dating argument\r\n  establishes environment-DOMINANT and bounds head growth as the minor term. It does **not**\r\n  apportion the environment term itself: Defender vs the third-party torrent load vs the fleet\r\n  brain's steady read vs anything else is unsplit, and **\"MsMpEng at 89%\" remains a correlate\r\n  measured beside the slowdown, not a proven cause.** The discriminator lane below is what settles\r\n  head-vs-environment on evidence rather than on the shape of a drift curve.\r\n\r\n- **REMEDY — none landed. This entry is the debt, and its middle arms need an operator.** Sequence\r\n  matters; run them in this order:\r\n  1. **DISCRIMINATOR LANE (hertz, one box, ~1.5-2 h).** Run the five named tests at `04e32c8c` and\r\n     at `f6110c2a` on hfenduleam. **Same-slow at both = environment; slow only at the head = head\r\n     growth.** Cheap and decidable, and it must precede any operator ask — do not spend an elevation\r\n     request on a hypothesis a one-lane measurement can test. Design note, because it is the part\r\n     that makes the number trustworthy: the arms run **INTERLEAVED** (A/B/A/B/A/B, 3 reps each), not\r\n     all-A-then-all-B, so drift that hits the whole box cancels in the comparison instead of landing\r\n     on one arm. **A measurement that only works if everyone behaves is not a measurement** — the\r\n     torrent client and Defender are running throughout and are the thing under test, not noise\r\n     anyone gets to remove. Confounder already excluded: the three test-bearing files\r\n     (`spt-daemon/tests/sync.rs`, `spt-store/src/monic.rs`, `spt-store/src/syncmerge.rs`) are\r\n     **byte-identical blobs at both shas**, so a difference cannot be the tests changing; the two\r\n     crates around them are not (+11,388 lines over 48 files).\r\n  2. **Remove the third-party load first.** No torrent client on the CI box during golden windows.\r\n     It is the cheapest variable to remove, and removing it first makes arm 3's benefit measurable\r\n     instead of confounded.\r\n  3. **OPERATOR ASK — Defender path exclusions** for `C:\\actions-runner\\_work` and the gate pools,\r\n     read from an ADMIN shell first (see the unreadable-row warning above), then re-measure the\r\n     first-touch tax on a file **under that path** — the scratchpad measurement is outside the\r\n     runner dir, so it proves the mechanism's size, not the runner's exposure. Unsettable\r\n     unelevated; same shape as **IR-89**'s elevated firewall rule.\r\n  4. **CI census, cheap and durable:** print `Get-MpComputerStatus` RealTimeProtectionEnabled plus\r\n     the ExclusionPath read **verbatim, refusal text included**, in the Windows job's census step,\r\n     so a run's own record says what Defender it ran under.\r\n  5. **Re-measure both caps after any arm lands — the arm a future reader will skip, so it is loud\r\n     here.** A cap sized against a degraded box is correct only while the box stays degraded.\r\n     Leaving 80 in place after a repair silently restores the original hazard: a wall so generous it\r\n     no longer catches a wedged test, which is the job the golden cap was added to do in the first\r\n     place (the 2026-06-03 handoff.rs ConPTY stall, 22 unbounded hosted minutes).\r\n- **Kin:** [[IR-76]] (the golden runner IS the builders' box — the structural reason a desktop's\r\n  load reaches CI at all), [[IR-64]] (box-level facts only the operator can move), [[IR-89]] (the\r\n  other elevated box-rule ask), `defender-first-touch-tax-on-fresh-test-binaries` and\r\n  `e2e-leaked-daemons-shared-box` (memory).\r\n- **Ripe when:** arm 1 now; arms 2-4 on the operator's answer; arm 5 at the next `golden.yml` touch\r\n  after any of them. · **Size:** arm 1 a measurement, arm 4 one census line, arm 5 two literals.\r\n- **AMENDMENT 2026-09-09 (two terms this entry did not name when it landed at `d32d5c4c`).**\r\n  1. **`ci.yml`'s `changes` job runs `unit` on BOTH runners for every push to `main`.** The classify\r\n     step at `.github/workflows/ci.yml:49` emits `code=true` for every non-`pull_request` event, so\r\n     the docs-only skip that PR runs #206/#207 demonstrated is **`pull_request`-only** — read from\r\n     `ci.yml` at `main` by doyle, who names it his own error after twice ruling the opposite from the\r\n     PR runs alone. Consequence for this entry's wall clock: run **34337797758** (the ff of\r\n     `b66a9612`, a docs-only delta over golden-green `a2f335f8`) ran `unit (Windows)` 09:59:57Z →\r\n     10:40:48Z and was **CANCELLED at the 40-minute job wall** (job timeout; conclusion `cancelled`,\r\n     step 6 `Unit tests` 10:08:23 → 10:40:03) — a red on `main` at a sha whose content cannot fail a\r\n     unit test. It is an IR-85 face, not a flake row.\r\n  2. **A near-full volume is an environment term for the slowdown**, alongside the Defender\r\n     first-touch tax and the operator-desktop load already recorded. **Deliberately unquantified:**\r\n     the discriminator window that would have apportioned it was VOID, because the one leg that\r\n     completed ran under both a CI job and a falling disk. See **IR-90**.\r\n- **WHAT THE VOIDED DISCRIMINATOR ESTABLISHED, negatively (hertz, 2026-09-09).** The fs-heavy\r\n  slowdown REPRODUCES at `04e32c8c`, which predates the +11,388-line head growth: spt-daemon\r\n  `concurrent_writes` 105.420 s, `two_tier_sync` 58.362 s, spt-store `clone_copies` 65.657 s,\r\n  `different_monics` 73.967 s, `syncmerge reconciled_write` 86.765 s, against the 09-06 baseline of\r\n  22.4 / 18.7 / 17.7 / 18.2 / 27.3 s — **3.2x to 4.7x on all five, at the OLD sha**. So head growth\r\n  is **not NECESSARY** for the slowdown. That is the whole of it: it does NOT measure how much the\r\n  environment explains, and it is not evidence about the head arm at all — that leg ran inside run\r\n  34337797758's window and on a volume that reached 0.018 GiB free, and the head arm never produced\r\n  a comparable pair. **Arm 1 stays OPEN**, its re-run deferred until **IR-90**'s guard exists and a\r\n  window with no `main` push and no CI job on the box can be scheduled.\r\n\r\n- **AMENDMENT 2026-09-10 (hertz, on THIS ENTRY'S OWN arm-1 design note).** The note says the arms run\r\n  **INTERLEAVED** A/B/A/B so box drift cancels. It does not cancel: **B is always the later arm within\r\n  each pair**, so a monotone drift across the session lands on B every time and is read as an arm\r\n  effect. Alternate the PAIR ORDER — **A/B then B/A** — record per-leg timestamps and conditions, and\r\n  describe the result as **REDUCING order confounding, not eliminating it**. Second binding change,\r\n  from the releases#294 triage: **instrument, do not infer.** `cargo nextest run --success-output\r\n  immediate` retains stdout for PASSING tests (deployah), so a passing arm can still print poll\r\n  elapsed, iteration count, IPC time and producer progress — **a failing arm is not required** for a\r\n  margin measurement (todlando, correcting deployah's \"it has to fail to be informative\"). Arm 1 was\r\n  never re-run, so this lands before the measurement, not after it.\r\n\r\n### IR-86 — golden's 32 GiB floor is BELOW the measured 67.4 GiB Windows suite footprint, so a start floor passes a box that cannot finish\r\n\r\n- **Status:** OPEN, filed by doyle 2026-09-08 at the #272/v0.68.0 golden r2 triage. · **Origin:**\r\n  run 34262154550 @ `25e60015` (shaped on `e4444413`), Windows test job 102182665033: every product\r\n  step green (Phase A 3346/3346, Phase B 234/234, Summary 2, FAIL 0), the ONLY reds were the two\r\n  in-job floor gates. `FLOOR_START` 97,649,786,880 B PASS at 18:47:23Z -> `FLOOR_DOCS`\r\n  25,284,501,504 B RED at 19:31:55Z -> `FLOOR_END` RED. Consumed in-job: 67.4 GiB.\r\n- **Mechanism:** `golden.yml` derives 32 GiB as \"the observed tens-of-GB full-suite footprint\r\n  rounded up to the next binary boundary, preserving headroom for one complete run\" (comment\r\n  above the Windows start floor). The measured footprint is 67.4 GiB, so a start reading anywhere\r\n  in [32, ~100) GiB passes and the job then walks under the floor by construction: box baseline\r\n  91 GiB minus 67.4 = 23.5 < 32. This is a shortfall of the DERIVATION, not a rate, not a product\r\n  red, and not the instant-vs-sustained face IR-46 files (that face is fixed by the FLOOR_DOCS\r\n  re-read, which is what caught it). The start floor must be footprint + end-floor (~100 GiB) or\r\n  it asserts nothing about finishing.\r\n- **Coverage consequence (the load-bearing part):** the Windows `Docs drift gate (CLI ref + llms\r\n  links)` step is sequenced BEHIND `FLOOR_DOCS`, so it SKIPPED and r2 held NO Windows CLI-ref\r\n  axis at that sha until the rerun. A floor red that skips a gate is a coverage hole wearing a\r\n  disk red.\r\n- **Kin:** [[IR-46]] (a floor asserts an instant), [[IR-59]] (pool arithmetic, LNK-class reds\r\n  that name no disk), [[IR-64]] (the operator-payload reservoir that sets the box baseline; its\r\n  ripe-when arm — a golden that dies at the floor despite adopted pool discipline — FIRED here\r\n  in the in-job form), [[IR-73]] (second half BUILT: the within-job re-read exists and is what\r\n  produced the FLOOR_DOCS reading), REQ-CI-FREE-SPACE-PREFLIGHT.\r\n- **Coupling (deployah 23:54Z, from `golden.yml` at `25e60015`):** the Windows `DISK docs floor`\r\n  (:616) and `Docs drift gate — windows` (:629) carry only `if: runner.os == 'Windows'`, no\r\n  `always()`, while `DISK end floor` does (`always() && runner.os == 'Windows'`, ~:705). Actions'\r\n  default is \"previous steps succeeded\", so ANY Phase B red skips the docs axis by construction —\r\n  observed three times at this sha (floor red, ttl cell, ttl cell). The docs gate is therefore never\r\n  independent evidence: it can only be banked when Phase B is green in the same job. Remedy line:\r\n  gate the two docs steps on `!cancelled()` plus the success of the steps they actually depend on\r\n  (checkout/build), not on Phase B — a rig change, new sha, hertz workflow rider slot.\r\n- **Remedy shape:** re-derive the start floor from the measured footprint (67.4 GiB Windows,\r\n  Linux to be measured) plus the 32 GiB end floor, print the footprint (start minus end free)\r\n  on every run so the number re-measures itself, and keep the 32 GiB literal only for\r\n  `FLOOR_END`.\r\n- **Ripe when:** next `golden.yml` touch (hertz workflow rider slot). · **Size:** small — one\r\n  literal per start-floor site + one printed subtraction.\r\n\r\n### IR-87 — two-host ceremony halves are INDEPENDENT jobs on DIFFERENT runners (A Windows/hfenduleam, B Linux/kitsubito); B's 900 s budget runs on B's own clock, so any older queued Windows job starves A and reds B deterministically, and the panic text blames pairing\r\n\r\n- **Status:** OPEN, filed by doyle 2026-09-08 at the #272 golden r2 triage. · **Origin:**\r\n  run 34262154550, twohost-b job 102207296960 (log 81,692 B, sha256 67403f04…8030): role B built,\r\n  rostered, polled PAIR_MEET_UP every 30 s from 19:34:30Z, and hit the rig_wait barrier\r\n  \"pairing: A rostered via the daemon-hosted responder\" at its 900 s deadline 19:49:17Z\r\n  (`crates/spt-daemon/tests/twohost.rs`, exit 101, 2 passed 1 failed). twohost-a (102207296985)\r\n  was QUEUED from 19:32:13Z with no runner: the Windows runner went to thin ci run 34261096301\r\n  (post-merge on main @ `e4444413`) the second the golden test job released it at 19:31:56Z.\r\n- **Mechanism:** `golden.yml` sequences twohost-a and twohost-b after `test`, but they are two\r\n  jobs on two runners (measured 2026-09-08 20:56Z via the jobs API `runner_name`: twohost-a on\r\n  hfenduleam, twohost-b on kitsubito), and GitHub's queue does not honour a workflow's intra-run\r\n  job ordering against a FOREIGN run on either runner. B starts, its whole budget ticks against a partner that has not been\r\n  scheduled, and `rig_wait` panics `never converged on the rig: {what}` — a text that reads as a\r\n  pairing defect. The lanes were not at fault, and twohost-a's outcome was predetermined once B\r\n  exited (a later A pass would be vacuous).\r\n- **Kin:** [[IR-76]] (hfenduleam is golden runner AND builders' box; the job-start census cannot\r\n  see a competing GitHub run either), [[IR-62]] (rig collisions on shared runners), the W1 two-host\r\n  rig, `a-barrier-cannot-ride-a-carrier-its-sender-outlives` (memory, same family: a barrier needs\r\n  the receiver's own answer).\r\n- **Remedy shape (pick at rider time):** (1) start barrier on B keyed to A's job having STARTED\r\n  (a run-scoped artifact or a `needs`+matrix collapse into ONE job that spawns both roles), or\r\n  (2) B's deadline clock starts at first A-rostered signal with a separate, longer \"A never\r\n  appeared\" budget, or (3) the panic names the missing partner's job state so triage does not\r\n  chase pairing. Any option: the two-host halves must never share a runner queue with a foreign\r\n  run while one half waits.\r\n- **Ripe when:** next `golden.yml`/twohost rig touch. · **Size:** small-medium (job shape or\r\n  barrier rework + panic text).\r\n\r\n- **AMENDMENT 2026-09-10 (releases#294, golden 34445961595 att1 @ `a9e786b2`) — THE STARVING RUN CAN\r\n  BE GOLDEN'S OWN PR, which makes this self-inflicted and recurrent on every golden run with a PR\r\n  open.** Measured timeline: **07:18:59Z** golden `test (Windows)` completes and releases hfenduleam;\r\n  **07:18:59Z** twohost-a queued; **07:19:01Z** PR run **34446095808** job `unit (Windows,\r\n  hfenduleam)` SEIZES the runner; **07:19:02Z** twohost-b starts on the free kitsubito; **07:36:16Z**\r\n  twohost-b fails at **900.41s** — `never converged on the rig: pairing: A rostered via the\r\n  daemon-hosted responder`. The origin case (2026-09-08) was a post-merge push on `main`: a run\r\n  belonging to someone else. **Here the starving run is the `pull_request` run of the very PR carrying\r\n  the golden head**, so opening the golden PR arms the starvation of that same head's twohost pair.\r\n  **Consequence for the remedy shape above: any option that only de-conflicts against OTHER lanes'\r\n  runs does not reach this case.** The golden head's own PR has to be excluded from the Windows\r\n  runner for the duration of the golden run (or the pair collapsed into one job, option 1).\r\n- **SECOND-ORDER FACE (deployah, same run): starvation does not merely red B — it desynchronises the\r\n  pair past repair.** twohost-b was TERMINAL at 07:36:16Z; twohost-a did not start until **07:48:07Z**\r\n  — the two halves never overlapped for a single second, so twohost-a's outcome is uninformative\r\n  **whatever it says**, and a red there must not be counted as a second product failure. Recorded\r\n  honestly at deployah's own insistence: **VOID is his SCORING interpretation, not a fact about the\r\n  run** — the release record carries GitHub's raw `conclusion` for both jobs beside the scoring, not\r\n  laundered into it.\r\n- **⚠ ITS WALL CLOCK IS INDISTINGUISHABLE FROM [[IR-89]]'s.** A 900 s twohost red whose panel blames\r\n  pairing is ALSO the exact signature of the banked Windows-firewall hazard. The panel alone cannot\r\n  separate them; **the job TIMELINE can**. Check the schedule before accepting the firewall hazard for\r\n  any 900 s twohost red — this one fit that signature perfectly and was not it.\r\n\r\n### IR-88 — `pool-release` via `cargo run -p xtask` REBUILDS xtask INTO the pool it is releasing, so a reaped pool regrows ~2.8 GB in silence\r\n\r\n- **Status:** OPEN, filed by doyle 2026-09-08 from hertz's reap report (20:00Z) during the #272\r\n  golden r2 repair. · **Origin:** hertz reaped hertz-lane4 / hertz-repin / hertz-percell-id target\r\n  subtrees (Length-sum upper bounds 68.16 / 47.11 / 8.79 GB) and then ran `cargo run -p xtask --\r\n  pool-release …` from each worktree: cargo rebuilt xtask into the just-reaped `target/` (2.8 GB\r\n  back in lane4, partial in repin), nothing printed said so, and the descendancy stopper killed\r\n  the second before it finished. Removed by hand afterwards; the post-reap free reading on the\r\n  record (275.95 GiB at 19:55:51Z) predates the regrowth.\r\n- **Mechanism:** the documented verb (AGENTS.md: \"drop it with `pool-release`\") is a `cargo run`,\r\n  and cargo's default target for that run IS the pool being released. The verb's own success path\r\n  recreates the state the operator just measured away; a teardown step that runs it AFTER a reap\r\n  undoes part of the reap and leaves the recorded free reading stale.\r\n- **Remedy shape:** either (a) `pool-release` documented and scripted as a PREBUILT `xtask.exe`\r\n  invoked against `--pool <dir>` from another pool, or (b) the verb refuses when its own\r\n  `CARGO_TARGET_DIR`/default target equals `--pool` and prints the prebuilt form, or (c) the reap\r\n  recipe orders release BEFORE the subtree delete. Memory banked 2026-09-08\r\n  (`pool-release-rebuilds-xtask-into-the-pool-you-just-reaped`); this entry is the durable home.\r\n- **POSITIVE CONTROL (hertz, 2026-09-09, ruling-3 gate-r3 teardown):** the same release run\r\n  from a PREBUILT `xtask.exe` invoked from outside the pool regrew NOTHING — the pool's own\r\n  `xtask.exe` still carried its original 21:00:42 mtime afterwards, and the reap that followed\r\n  reclaimed 63.71 GiB (132.03 -> 195.74 GiB free) against a 64.88 GiB Length-sum. So the\r\n  regrowth is a property of the `cargo run` VEHICLE, not of the verb, and remedy (a) is proven\r\n  rather than merely proposed.\r\n- **Kin:** [[IR-31]] (pool budgeting), [[IR-56]] (pool-claim identity from CWD — same verb\r\n  family, same \"the tool acts on where it stands\" shape), releases#103.\r\n- **Ripe when:** next xtask pool-verb touch or the teardown runbook edit. · **Size:** tiny —\r\n  one guard or one doc line.\r\n\r\n### IR-89 — hfenduleam's Windows Firewall drops cold inbound UDP to the runner-built test exes, so the two-host rig's first B→A claim (W2 helper) reds for its whole 900 s budget and the panic blames A\r\n\r\n- **Status:** BOX HALF **APPLIED** 2026-09-08; WORKFLOW HALF **BUILT** 2026-09-09 — PR #211\r\n  (`9b96d7e7` + this amendment), **LANDED-pending-golden**: the `golden.yml` steps are UNEXERCISED\r\n  until the next golden run, because thin CI compiles the cells and skips them. Filed by doyle 2026-09-08\r\n  at the #272 golden r2 terminal triage; the operator-blocked flag is retired here, because\r\n  the operator acted.\r\n  The operator applied BOTH layers that evening — the Windows inbound rule (~23:41Z) and the\r\n  tailnet ACL grant (~23:56Z) — and the re-probe with the same rule-less pwsh listener read\r\n  **3/3 over Tailscale on 7483 AND 3/3 on 7489 at 23:57:50Z** from `100.98.197.12`, with a\r\n  post-terminal probe 3/3 on both ports at attempt 4. v0.68.0 then shipped at `a2f335f8` with\r\n  both two-host legs GREEN on golden r4, so the box half is closed by measurement and not by\r\n  assertion. **STILL OPEN, and it is the durable half:** the WORKFLOW guard (hertz) — the\r\n  pre-ceremony B→A UDP probe at `d882297f` that reds `INBOUND_BLOCKED` in 10 s with its own\r\n  name instead of burning 900 s blaming pairing, plus retiring the dead `_work\\spt-core`\r\n  rules note in the runner runbook. Until that lands, the next box (or the next ACL edit)\r\n  re-opens the 900 s face with nothing to name it. · **Origin:** run 34262154550 @ `25e60015`, twohost-a 102229928746\r\n  (`two_host_web_helper_role_a`, :968, 900.40 s) and twohost-b 102229928689\r\n  (`two_host_web_role_b`, :559, 910.20 s): B logged 75 × \"A not ready … broker QUIC op exceeded\r\n  the 10s bound (peer unresponsive)\" from 20:49:49Z to 21:04:37Z and was never ADMITTED. Ladder\r\n  green both sides; both halves started 20:41:23Z on their own runners (not IR-87's starvation).\r\n- **Mechanism (MEASURED 21:11Z):** the box's firewall policy is `BlockInbound,AllowOutbound` on\r\n  all three profiles (Ethernet and Tailscale both Private). Inbound allow rules exist only for\r\n  exes under `Documents\\projects\\spt-core\\target` (interactive Allow clicks) and under the DEAD\r\n  pre-rename runner path `_work\\spt-core\\spt-core`; exactly ONE under `_work\\spt-bs-core` (its\r\n  `target\\debug\\spt.exe`, the CLI, not the binder — deployah's count, mine had said zero), none for\r\n  any `twohost_web-*.exe`. `Get-NetFirewallProfile` shows `DefaultInboundAction = NotConfigured`,\r\n  whose effective default IS block: the block is Windows' default, not a configured policy, so there\r\n  is no policy to \"restore\". The runner is a service (`.\\decid`), so the Allow dialog that minted the\r\n  old rules cannot appear. A's helper cell 3 bound `broker udp 7483` inside\r\n  `_work\\spt-bs-core\\spt-bs-core\\target\\debug\\deps\\twohost_web-f73bc44be13353fb.exe`; B dialled\r\n  `100.68.35.65:7483` cold. Probe: a rule-less pwsh UDP listener on hfenduleam:7483 received 0 of\r\n  3 datagrams from kitsubito `100.98.197.12`; the reverse control (python listener on\r\n  kitsubito:7483) received 3 of 3 from hfenduleam.\r\n- **Why three faces from one cause:** the shared-key rig (pre-`e4444413`) reached A only through\r\n  holes A's OUT-dialling cells (7480–7482) had opened for `id_a` — six 10 s bounds until B's\r\n  magicsock fell onto one of those paths, then ADMITTED (the 63 s stall, helper-stall memory), or\r\n  onto a live same-key sibling that never replied (the 21 min hang in 34239258523). Per-cell A\r\n  identity (`id_a_for`, `e4444413`) removed the accidental route by construction, leaving only\r\n  the cold path, which the firewall drops. hertz's one-box discriminator \"vanishes\" was true on\r\n  one box because one box never crosses the firewall. Product and rig are both exonerated; the\r\n  rig's `a_addr` comment already names W2 as the first A-ward claim.\r\n- **Remedy (two halves):** (1) BOX, operator-owned, elevated on hfenduleam:\r\n  `New-NetFirewallRule -DisplayName \"spt-ci two-host rig UDP-In (kitsubito only)\" -Direction Inbound -Action Allow -Protocol UDP -LocalPort 7460-7499 -RemoteAddress 100.98.197.12 -Profile Any`\r\n  (rig ports at the sha: ladder 7460/7461; web `PORT_OFFSET` 20 → A cells 7480–7483, B 7481; the\r\n  A-ward surface today is exactly UDP 7480–7483 — deployah's tighter range — and the whole range\r\n  moves with any `SPT_TWO_HOST_PORT_A` override, so the rule must move with it);\r\n  program-path rules are the wrong shape because the exe hash changes per build. Verify with the\r\n  same probe (3/3) before any rerun. (2) WORKFLOW, hertz: a B→A UDP probe step in the twohost\r\n  jobs before the ceremony, so this reds in 10 s with its own name instead of 900 s blaming\r\n  pairing; and retire the dead `_work\\spt-core` rules note in the runner runbook.\r\n- **Kin:** [[IR-83]] (the tailnet-ACL face of a cross-box inbound block — KIN, **NOT the same\r\n  finding**: that entry is the tailnet policy layer, this one is the Windows firewall layer, and\r\n  the SECOND LAYER note below is exactly the measurement that separates them), [[IR-87]] (the\r\n  other way a half waits 900 s on a partner), [[IR-76]] (golden runner\r\n  is the operator's box), [[IR-64]] (box-level facts only the operator can move),\r\n  `twohost-web-helper-stall-shared-a-identity-stale-path` (memory; its CONFIRMED arm is re-read\r\n  by this entry).\r\n- **AMENDMENT 2026-09-09 — the WORKFLOW half is BUILT and FIELD-MEASURED; it is LANDED-pending-golden\r\n  (hertz).** The guard is two cells in `twohost_web.rs` plus a step per half in `golden.yml`, and it\r\n  grew four design corrections that are worth more than the guard itself, because each one is a way a\r\n  probe can certify the fault it exists to catch.\r\n  1. **A FIXED SYMMETRIC WINDOW ADDS A THIRD CAUSE THAT LOOKS LIKE THE OTHER TWO.** The step boundary\r\n     orders the probe on ONE host; it does not align two, and after the ladder each half pays its own\r\n     wrapper and `cargo test` (on Windows a fingerprint scan plus Defender's first touch of a fresh\r\n     exe). MEASURED: the first hand-run in the A=kitsubito direction (13:14:13 → 13:14:51Z) redded\r\n     `INBOUND_BLOCKED` at 10.24 s with text asserting \"a BOX rule, not a product or rig fault\" — and\r\n     the cause was `cargo`'s start-up on the SENDER putting its first datagram after the receiver's\r\n     10 s window closed. An innocent box, the guard's own words against it. What stopped it being\r\n     filed as a kitsubito block was that the box facts contradicted the text (`tailscale debug\r\n     netmap` on kitsubito lists `100.68.35.65/32` among its permitted inbound sources, and `ufw` is\r\n     inactive) — a failure text that contradicts a measured box is the text's defect. So the\r\n     rendezvous is DATA: A listens up to the rig budget and beacons once a second; B binds first,\r\n     waits for a beacon, and only then starts a ten-second clock, so B's red has already excluded\r\n     \"A is not up\". That is a FOURTH outcome with its own name, `PROBE_NO_BEACON`, never\r\n     `INBOUND_BLOCKED`.\r\n  2. **THE LISTENING SOCKET MUST NEVER SEND.** Any outbound datagram from the measured port opens\r\n     stateful return state for it, so B's probe then arrives SOLICITED and crosses under both layers\r\n     — this entry's own \"solicited return traffic works under either fault\" applied to the guard\r\n     rather than to the ceremony. MEASURED: with the beacon sharing A's listening socket, the\r\n     out-of-grant control went **GREEN at 13:28Z** on a port a listen-only run had measured BLOCKED\r\n     at 13:20Z; a further green at 13:31Z with the beacon moved but the ack still leaving that socket\r\n     was residual state from 13:28 — true BY ELIMINATION rather than by assertion: nothing in the\r\n     13:31 run sent from 7509 before the first arrival, so the only outbound that could have opened\r\n     that port's return state belongs to the previous run. Beacon and ack both leave an ephemeral socket now, and B sends\r\n     from an ephemeral port too, so no run repeats a 4-tuple a previous run opened.\r\n  3. **THE ACK IS ADDRESSED TO B'S RIG PORT, not to the probe's source port.** MEASURED: acking to\r\n     `from` produced a run that CONTRADICTED ITSELF — A said `INBOUND OK` and B said\r\n     `INBOUND_BLOCKED`, same run, 13:41:33 → 13:41:50Z — because A's ack leaves its ephemeral\r\n     socket, is therefore not return traffic of the flow B opened, and a receiver whose inbound rule\r\n     is a port RANGE drops it. The rig port is the only address either host is reachable on cold.\r\n  4. **THE FALSIFIER, and it is the operator's own rule used as an instrument.** Forcing the probe\r\n     port to **7509** (`SPT_TWO_HOST_PORT_A=7480`), one port outside the granted udp 7460-7499, reds\r\n     the guard on demand with no elevation and no policy edit. Run TWICE BACK TO BACK at the final\r\n     code, 13:43:41 → 13:44:23Z and 13:44:25 → 13:45:07Z: **RED, RED** — A after 40 s having sent\r\n     39 beacons, B in its ten seconds having sent 48 and 47 datagrams with no ack, both exit 101.\r\n     One red would only prove a state timeout expired; two consecutive reds prove the design writes\r\n     none. The grant boundary is therefore measured from inside the test binary: 7489 crosses, 7509\r\n     does not, same hosts, same binary, one env var apart.\r\n  5. **ONE ACK IS NOT ENOUGH — the same split verdict arrives by packet loss** (doyle, reviewing the\r\n     built lane). A acking ONCE and breaking leaves B's red resting on a single unrepeated UDP\r\n     datagram: lose it and A prints `INBOUND OK` while B reds `INBOUND_BLOCKED`, blaming a firewall\r\n     for ordinary loss — correction 3's defect reached by a different road. A now keeps draining for\r\n     a short window after its own verdict is already settled and acks EVERY probe in it, while B\r\n     stops on the first ack. The A-side assertion is unchanged: it was decided by the first datagram.\r\n  6. **THE PROBE STEPS CARRY THEIR OWN BUDGET, 300 s, set EXPLICITLY** beside ceremony steps that say\r\n     900. It bounds RENDEZVOUS skew, not pairing, so a blocked link costs 300 s ONCE instead of 900\r\n     per cell per half. Left unset it would have been `from_env`'s invisible default sitting next to\r\n     a visible 900 on the step below — a number the next reader would have inferred wrongly, which is\r\n     this entry's whole failure mode in miniature.\r\n- **FIELD PROOF, 2026-09-09, and it is the ONLY proof this guard has:** `dir 1` (A=hfenduleam,\r\n  B=kitsubito) 13:45:14 → 13:45:18Z and `dir 2` (A=kitsubito, B=hfenduleam) 13:45:41 → 13:45:58Z,\r\n  both GREEN with the ack after ONE datagram, both exits 0, both hosts running byte-identical source\r\n  (md5 `f31779339266f8034dcd72917c56a37e`, checked on both sides). Free space 174.38 GiB, flat across\r\n  all four arms.\r\n  ⚠ **THE `golden.yml` STEPS THEMSELVES ARE UNEXERCISED UNTIL THE NEXT GOLDEN RUN.** Thin CI\r\n  compiles the cells and SKIPS them — `Rig::from_env` returns `None` without `SPT_TWO_HOST`, so a\r\n  green thin run says the code builds and nothing about the steps. The wall times above are the field\r\n  proof; treat the workflow half as landed-pending-golden and not as verified by its own PR.\r\n- **Ripe when:** the next GOLDEN run, which is the first thing that exercises the steps — the\r\n  code half is built and field-measured (PR #211). (The box half was ripe \"now\" against\r\n  `25e60015` and is done; #272 golden acceptance is no longer blocked by it.) · **Size:** one\r\n  workflow step remaining; the elevated command is spent.\r\n- **SECOND LAYER (measured 23:41–23:50Z, after the operator applied the Windows rule exactly as\r\n  asked and the re-probe STILL read 0/3):** the tailnet ACL. The same `python.exe` listener (own\r\n  program rule) received 3/3 from kitsubito over the LAN (`192.168.1.168 → 192.168.1.81:7483`) and\r\n  0/3 over Tailscale (`100.98.197.12 → 100.68.35.65`), TCP connect over Tailscale times out too,\r\n  solicited return over Tailscale works, ShieldsUp false both ends. `tailscale debug netmap` on\r\n  hfenduleam: one PacketFilter rule, 18 permitted inbound sources, kitsubito ABSENT; kitsubito is\r\n  `tag:eye-tracking-resource` owned by a different tailnet user, and its own filter DOES permit\r\n  hfenduleam. Asymmetric policy: member device → tagged resource allowed, reverse denied. The\r\n  Windows rule was NECESSARY (rule-less exe, LAN probe 0/2 earlier) and NOT SUFFICIENT. Remedy\r\n  half (1) gains an ACL grant, operator-owned in the admin console:\r\n  `{\"action\":\"accept\",\"src\":[\"tag:eye-tracking-resource\"],\"dst\":[\"hfenduleam:7460-7499\"],\"proto\":\"udp\"}`.\r\n  Rider 4's failure text names both layers and the LAN-vs-Tailscale probe as the discriminator.\r\n  Lesson for the entry: a cross-box \"unresponsive\" has at least THREE layers (Windows rule, tailnet\r\n  policy, the exe's own bind); probe through the SAME path the rig uses, and re-probe after every\r\n  single change — the first fix reading as \"applied\" is not the probe reading 3/3.\r\n- **Corroboration + reading traps (deployah 23:50Z, from the box):** Windows rule found present by\r\n  FILTER search (`netsh advfirewall firewall show rule name=all dir=in verbose`), not by name — the\r\n  operator's name is hyphenated \"two-host\" and a `twohost` grep reads it ABSENT. Netmap: the single\r\n  filter permits ALL ports and ALL protocols from its 18 sources, so the grant is SOURCE-scoped, not\r\n  port-scoped — \"this peer is not a permitted source at all\", which is why TCP timed out beside UDP.\r\n  Two permitted sources (100.98.213.33, 100.98.214.87) share kitsubito's 100.98/16 and read as hits\r\n  to an eyeball scan for \"100.98.\"; test membership of the full /32, never a prefix. His first netmap\r\n  read extracted a non-existent field (`SrcIPs`; the real key is `Srcs`), printed an empty list and\r\n  minted a confident \"ABSENT\" — an empty extraction cannot witness absence; the 18-count is from the\r\n  corrected read. Prefs on the box: ShieldsUp false, NoStatefulFiltering true, RouteAll true,\r\n  NetfilterMode 2 — nothing there explains the drop.\r\n- **Probe-rider design rule (hertz, d882297f):** the pre-ceremony probe reds `INBOUND_BLOCKED` for\r\n  EITHER layer and does not pretend to know which — its job is \"the box cannot receive, stop triaging\r\n  the product\"; the layer is named only by the one measurement that decides it (same listener, LAN\r\n  vs Tailscale), which the failure text prints as a recipe. A guard that names a cause it did not\r\n  measure is the defect class this whole entry documents.\r\n\r","truncated":true,"truncatedBy":"lines","totalLines":1119,"totalBytes":43730,"outputLines":486,"outputBytes":43730,"lastLinePartial":false,"firstLineExceedsLimit":false},"totalLines":5782,"displayContent":{"text":"### IR-84 — the one `PUMP_PEER_FAIL` arm the rigs actually fire was the only one carrying no clock, so the stall that produced it could be counted but never timed\r\n\r\n- **Status:** OPEN, filed by hertz 2026-09-09 with the instrument that closes its first half. ·\r\n  **Origin:** the 65 s two-host helper stall (design written before the run,\r\n  `docs/design/RIDER-65S-DESIGN.md`). The number was branch-claimed 2026-09-08 by name only — IR-85\r\n  records that it carried no entry text in any register file in any worktree — and this is that text.\r\n- **Symptom:** `two_host_web_helper_role_a` takes **61.956–69.096 s** across five runs while its\r\n  siblings in the same binary and the same run take **0.135–0.753 s**. Every ladder rig —\r\n  win-onebox, linux-onebox, cross-box — logs **exactly ONE**\r\n  `PUMP_PEER_FAIL:<node>:peer reply-read: no progress within budget — dropping peer (brain IPC read\r\n  deadline elapsed)` on B before completing. **3/3, one each, never on A** (doyle's GATE-W3 readout).\r\n- **Cause of the DIAGNOSTIC failure, which is what this entry is about:** that line is emitted from\r\n  the `Err(e)` arm of `peer_leg_outcome` (`crates/spt-daemon/src/pump/mod.rs`), and at\r\n  `b0b67aaa` it read `emit_line_err!(\"PUMP_PEER_FAIL:{peer_hex}:{e}\")` — **no timestamp**. Measured\r\n  at that sha rather than recalled: the file carries **four** `PUMP_PEER_FAIL` emit sites, **three**\r\n  of them stamped `wall_ms=… mono_ms=…` (the submit arm, the no-route arm, and the\r\n  `PRESENCE_DIAL_FAILED` arm), and this one was **the only unstamped site left**. It is also the\r\n  arm the rigs actually fire — a `PEER_REPLY_READ_BUDGET` expiry reclassified out of `TimedOut` by\r\n  `brain::reclassify_peer_reply_err` so it drops one peer rather than poisoning the round. **The\r\n  single arm a reader most needs to time was the single arm that could not be timed.**\r\n- **What that cost, stated as the open question it left:** the arithmetic does not close and this\r\n  entry does not close it. `PUMP_PEER_IO_TIMEOUT` is **30 s** (`:118`) and `SUPERVISE_BACKOFF_BASE`\r\n  is **5 s** (`:121`) — read as constants, not recalled — so one deadline plus one supervise floor\r\n  accounts for **35 s** against **61.956–69.096 s** observed. **~27–34 s is unaccounted**, itself\r\n  close to another 30, which is exactly the coincidence the design document warns against; and the\r\n  count of **exactly one** fail forbids the easy reading that two deadlines elapsed. Three candidates\r\n  stay open and are NOT ranked here: a first ~30 s burned before the deadline's clock starts; a\r\n  second budget stacking on the first; or the restart's re-prime costing materially more than its\r\n  5 s floor. **Separating them needs the deadline's own timestamps against the fail line** — which\r\n  is precisely what the log did not carry.\r\n- **⚠ WHAT THIS ENTRY DOES NOT CLAIM.** The instrument does not explain the stall, does not shorten\r\n  it, and changes no product behaviour: the same peer is dropped at the same instant with the same\r\n  backoff. It makes the stall **answerable from a log that already contains the failure**, instead of\r\n  requiring a rebuild to learn when the budget started. `PUMP_PEER_IO_TIMEOUT` is a hard const with\r\n  no env knob, so varying it costs a rebuild — deliberately deferred until the stamps say which half\r\n  of the arithmetic is missing.\r\n- **Kin and the recurrence that matters:** this is the **SECOND** time an unstamped\r\n  `PUMP_PEER_FAIL` cost a hunt. The `PRESENCE_DIAL_FAILED` arm carries a comment naming the\r\n  \"2026-07-14 `PUMP_PEER_FAIL`-unstamped seed, folded here\", and **REQ-PUMP-STAGE-TRUTH** already\r\n  requires every peer failure \"stamped (wall+mono) and peer-attributed\", explicitly subsuming that\r\n  seed. So the contract was written, three of four sites complied, and the fourth stayed silent for\r\n  eight weeks — **a convention enforced by no mechanism degrades one arm at a time, and every reader\r\n  of a complying arm reports the convention as held**, the same shape as the `validate_docs_dir`\r\n  refusal-arm rider in the same design document. Also kin: **IR-83** (the rig population had only\r\n  ever run the admitted direction), `REQ-HAZARD-PUMP-IPC-DEADLINE` (a `TimedOut` brain-IPC read is a\r\n  supervised restart, never a per-peer retry), ADR-0039 Decision 5.\r\n- **Ripe when:** now, and it lands with this entry — the stamp is one emit line, tagged\r\n  `[impl->REQ-PUMP-STAGE-TRUTH]` at the site. · **Size:** one emit line plus its comment.\r\n  **Follow-up, not this lane:** a cell that walks every `PUMP_PEER_FAIL` arm and asserts each one\r\n  stamps, so the fifth site added cannot be born silent.\r\n### IR-85 — the Windows self-hosted box runs its fs-heavy tests 3-4x slower than a week ago; two CI wall clocks were sized for the old box, and a red run kept hiding it\r\n\r\n- **Status:** OPEN, filed by hertz 2026-09-09 at the #272/v0.68.0 golden r3/r4 arc, on doyle's\r\n  dispatch. Number ruled by doyle from his own census of main@`a2f335f8` (register ended at IR-83;\r\n  IR-84 was branch-claimed by name only, with no entry text in any register file in any worktree —\r\n  that gap is now closed: **IR-84 was filed 2026-09-09 in PR #213**, so this sentence records the\r\n  state at `a2f335f8` and is no longer a reason to go looking for a missing entry).\r\n  **Absorbs two drafts:** doyle's `IR-DRAFT-windows-fs-heavy-slowdown-and-golden-wall` (his IR-A +\r\n  IR-B) and his earlier `IR-NEXT` (operator-desktop load), both retired by reference — this is the\r\n  single entry. Every job/step and per-test timing below is **doyle's**, read via the job/step API.\r\n  · **Origin:** #272 golden r3 attempt 2 was CANCELLED by a wall clock with both test phases green.\r\n- **⚠ THE CAP CHANGE IN `a2f335f8` IS NOT THE FIX AND MUST NOT BE READ AS ONE.** It bounds the run;\r\n  it repairs nothing. A future reader who finds an 80-minute wall and no entry here would reasonably\r\n  conclude the problem was solved. It was only made visible.\r\n\r\n- **A GREEN RUN COSTS MORE THAN A RED ONE, WHICH IS WHY THIS WENT UNSEEN.** A failing run\r\n  short-circuits past the wall a green run has to cross. r3 att1 finished in **48m39s only because\r\n  it FAILED at Phase B**; att2, green, hit 49m59s and was cancelled. Every earlier docs-drift skip\r\n  therefore presented as \"upstream failure\" — the wall was never the reported cause of anything, and\r\n  the surviving evidence systematically flattered the budget.\r\n\r\n- **THE WALL.** Windows golden `test` job (48 steps), fully GREEN: **30m53s** (2026-08-30, run\r\n  33296634901) and **33m21s** (2026-09-06, run 34017906638). At the v0.68.0 head against the\r\n  then-current 50-minute cap — **r3 att2**, job 102352551368 at `f6110c2a`: Phase A 17m14s, Phase B\r\n  20m25s, doctests 1m04s, clippy 3m31s, **CANCELLED at step 30 at 49m59s with everything green**;\r\n  steps 31-42 (installer, docs floor, both docs-drift gates, dormancy) never ran. r2 att1\r\n  (`25e60015`, 09-08 18:47Z) reached step 34 at 44m30s. Steps 30..39 cost ~3m30s on the 09-06 green\r\n  (notify 47s, installer 13s, docs-drift 1m54s). Predicted green need ~**56 min**; cap raised to\r\n  **80** (need + ~40% for day-to-day variance) in `a2f335f8`, ci unit 25 -> 40 in the same commit.\r\n- **r4, GREEN — the first complete measurement at the head: 54m35s** (07:12:26Z -> 08:07:01Z),\r\n  **25m25s** headroom under 80; docs-drift (step 38) 2m23s; Phase A 15m51s, Phase B 22m56s. The ~56\r\n  prediction held to within 1.5 min, so the cap is sized on evidence, not generosity. **What that\r\n  does NOT establish:** it was a sizing forecast, and its holding says nothing about the cause\r\n  diagnosis below. Nor are att2-vs-r4 per-phase deltas a trend — att2 was cancelled mid-run, so only\r\n  its phase legs are comparable at all, and the spread they sit in is the same variance the 40% is\r\n  there to absorb.\r\n\r\n- **THE SLOWDOWN, per test, same box, same tests.** `spt-daemon::sync` concurrent_writes\r\n  **22.4s -> 74.8s**, two_tier_sync 18.7 -> 67.4; `spt-store` monic clone_copies 17.7 -> 62.9,\r\n  different_monics 18.2 -> 64.9; syncmerge reconciled_write 27.3 -> 51.2. **~25 spt-store/spt-daemon\r\n  tests now exceed 30s on Windows Phase A at `f6110c2a`, against 1-2s each on kitsubito.**\r\n  Phase-level: Phase A nextest 170s (09-06) -> 642s (att1) -> 1034s (att2); Phase B 710s -> 1164s.\r\n  The suite did not get more expensive — Linux is unchanged.\r\n\r\n- **DATING SAYS ENVIRONMENT DOMINATES, AND BY HOW MUCH.** main's own ci Windows `unit` job:\r\n  11-12 min on 09-06 (runs 34040416870, 34041526195, 34043323577) -> 13-20 min on 09-07 -> 12-24 min\r\n  on 09-08, hitting **22 min at `e4444413`** (run 34261096301) three minutes under its own 25-minute\r\n  wall. **Gradual over days, under no single gate change, is the shape of an environment term, not a\r\n  commit's.** Head growth is real but MINOR: +138 Phase A tests, +20 Phase B, HEAVY 34 -> 35.\r\n\r\n- **THE BOX IS AN OPERATOR DESKTOP (folded in from the retired IR-NEXT), and that turns every fixed\r\n  wall-clock budget in the Windows suite into a coin.** From the r2 arc, three attempts at ONE sha\r\n  (run 34262154550 @ `25e60015`): Phase B red each time on a **different single cell or none** — a1\r\n  234/234 (job red on disk floors only), a2 `spt::webserve_attachment_e2e` arm 12, a3\r\n  `spt-daemon::mesh_recovery roster_route_survives_a_transient_dial_failure_with_discovery_disabled`\r\n  (15.0s `converge()` budget, cell 15.715s; the same cell 9.8s / 7.2s on a1/a2). Phase A — 3,346\r\n  spawn-dominated unit cells — slowed **monotonically 448.7 -> 495.1 -> 542.6s at that one sha**.\r\n  Per-cell a3/a2 over 73 Phase B cells >= 1s: median 1.05x, mean 1.34x, 19 cells >= 1.5x, worst 5.2x\r\n  (`endpoint_lifecycle poll_vs_reap` 1.1 -> 5.8s) — **BURSTY, not uniform**. A rotating single victim\r\n  across attempts at one sha is ONE environment cause; hardening victims one at a time never closes\r\n  it (paid before: `e2e-leaked-daemons-shared-box`). The budgets that lost were ~1.5x the fast\r\n  observation — inside the box's measured variance, so they were coins that had been landing right.\r\n- **Box census (doyle 01:13-01:19Z, no cargo/rustc/nextest running, CPU 31%, ~1.1 of 16 cores busy):**\r\n  `qbittorrent.exe` seeding since 09-08 10:20Z (box tx 21.3 MB/s over 5s); fleet `spt daemon brain`\r\n  with 516 GB read since 09-07 08:03Z (~3.5 MB/s steady); Defender real-time ON, `MsMpEng` at\r\n  67.8/62.8/48.9/32.2/12.2% of a core over 5s **on the idle box**; a fresh 35 MB exe pays\r\n  2092/994/1171/1043 ms on FIRST execution against 31/263/19/260 ms on the second — **and every CI\r\n  attempt rebuilds every test binary fresh.** At 06:45Z on 09-09, with the twohost legs running:\r\n  MsMpEng 89% CPU / 991 MB WS, qbittorrent pid 47056 holding 7817 CPU-seconds (2.2 h) since\r\n  09-08 03:20, free 134 GiB (275 -> 197 -> 131 across the three r3 dispatches).\r\n- **⚠ AN UNREADABLE ROW IS NOT AN ABSENT ONE.** The Defender exclusion list cannot be read\r\n  unelevated on this box: `Get-MpPreference` returns the literal string\r\n  `N/A: Must be an administrator to view exclusions` **as the ExclusionPath VALUE**, so a\r\n  `-contains` test reads ABSENT and is meaningless; the HKLM `Windows Defender\\Exclusions\\Paths`\r\n  read throws `SecurityException`. Nobody may report the runner directory as unexcluded from an\r\n  unelevated shell.\r\n\r\n- **HYPOTHESIS ALREADY KILLED, so nobody re-runs it:** the Windows-only `ADAPTER_WEB_PENDING`\r\n  reconcile failure (servehost nudge) **cannot** explain this — spt-store monic and contextstore\r\n  never touch that path.\r\n\r\n- **WHAT IS STILL NOT ESTABLISHED (labelled, so it is not inherited as fact).** The dating argument\r\n  establishes environment-DOMINANT and bounds head growth as the minor term. It does **not**\r\n  apportion the environment term itself: Defender vs the third-party torrent load vs the fleet\r\n  brain's steady read vs anything else is unsplit, and **\"MsMpEng at 89%\" remains a correlate\r\n  measured beside the slowdown, not a proven cause.** The discriminator lane below is what settles\r\n  head-vs-environment on evidence rather than on the shape of a drift curve.\r\n\r\n- **REMEDY — none landed. This entry is the debt, and its middle arms need an operator.** Sequence\r\n  matters; run them in this order:\r\n  1. **DISCRIMINATOR LANE (hertz, one box, ~1.5-2 h).** Run the five named tests at `04e32c8c` and\r\n     at `f6110c2a` on hfenduleam. **Same-slow at both = environment; slow only at the head = head\r\n     growth.** Cheap and decidable, and it must precede any operator ask — do not spend an elevation\r\n     request on a hypothesis a one-lane measurement can test. Design note, because it is the part\r\n     that makes the number trustworthy: the arms run **INTERLEAVED** (A/B/A/B/A/B, 3 reps each), not\r\n     all-A-then-all-B, so drift that hits the whole box cancels in the comparison instead of landing\r\n     on one arm. **A measurement that only works if everyone behaves is not a measurement** — the\r\n     torrent client and Defender are running throughout and are the thing under test, not noise\r\n     anyone gets to remove. Confounder already excluded: the three test-bearing files\r\n     (`spt-daemon/tests/sync.rs`, `spt-store/src/monic.rs`, `spt-store/src/syncmerge.rs`) are\r\n     **byte-identical blobs at both shas**, so a difference cannot be the tests changing; the two\r\n     crates around them are not (+11,388 lines over 48 files).\r\n  2. **Remove the third-party load first.** No torrent client on the CI box during golden windows.\r\n     It is the cheapest variable to remove, and removing it first makes arm 3's benefit measurable\r\n     instead of confounded.\r\n  3. **OPERATOR ASK — Defender path exclusions** for `C:\\actions-runner\\_work` and the gate pools,\r\n     read from an ADMIN shell first (see the unreadable-row warning above), then re-measure the\r\n     first-touch tax on a file **under that path** — the scratchpad measurement is outside the\r\n     runner dir, so it proves the mechanism's size, not the runner's exposure. Unsettable\r\n     unelevated; same shape as **IR-89**'s elevated firewall rule.\r\n  4. **CI census, cheap and durable:** print `Get-MpComputerStatus` RealTimeProtectionEnabled plus\r\n     the ExclusionPath read **verbatim, refusal text included**, in the Windows job's census step,\r\n     so a run's own record says what Defender it ran under.\r\n  5. **Re-measure both caps after any arm lands — the arm a future reader will skip, so it is loud\r\n     here.** A cap sized against a degraded box is correct only while the box stays degraded.\r\n     Leaving 80 in place after a repair silently restores the original hazard: a wall so generous it\r\n     no longer catches a wedged test, which is the job the golden cap was added to do in the first\r\n     place (the 2026-06-03 handoff.rs ConPTY stall, 22 unbounded hosted minutes).\r\n- **Kin:** [[IR-76]] (the golden runner IS the builders' box — the structural reason a desktop's\r\n  load reaches CI at all), [[IR-64]] (box-level facts only the operator can move), [[IR-89]] (the\r\n  other elevated box-rule ask), `defender-first-touch-tax-on-fresh-test-binaries` and\r\n  `e2e-leaked-daemons-shared-box` (memory).\r\n- **Ripe when:** arm 1 now; arms 2-4 on the operator's answer; arm 5 at the next `golden.yml` touch\r\n  after any of them. · **Size:** arm 1 a measurement, arm 4 one census line, arm 5 two literals.\r\n- **AMENDMENT 2026-09-09 (two terms this entry did not name when it landed at `d32d5c4c`).**\r\n  1. **`ci.yml`'s `changes` job runs `unit` on BOTH runners for every push to `main`.** The classify\r\n     step at `.github/workflows/ci.yml:49` emits `code=true` for every non-`pull_request` event, so\r\n     the docs-only skip that PR runs #206/#207 demonstrated is **`pull_request`-only** — read from\r\n     `ci.yml` at `main` by doyle, who names it his own error after twice ruling the opposite from the\r\n     PR runs alone. Consequence for this entry's wall clock: run **34337797758** (the ff of\r\n     `b66a9612`, a docs-only delta over golden-green `a2f335f8`) ran `unit (Windows)` 09:59:57Z →\r\n     10:40:48Z and was **CANCELLED at the 40-minute job wall** (job timeout; conclusion `cancelled`,\r\n     step 6 `Unit tests` 10:08:23 → 10:40:03) — a red on `main` at a sha whose content cannot fail a\r\n     unit test. It is an IR-85 face, not a flake row.\r\n  2. **A near-full volume is an environment term for the slowdown**, alongside the Defender\r\n     first-touch tax and the operator-desktop load already recorded. **Deliberately unquantified:**\r\n     the discriminator window that would have apportioned it was VOID, because the one leg that\r\n     completed ran under both a CI job and a falling disk. See **IR-90**.\r\n- **WHAT THE VOIDED DISCRIMINATOR ESTABLISHED, negatively (hertz, 2026-09-09).** The fs-heavy\r\n  slowdown REPRODUCES at `04e32c8c`, which predates the +11,388-line head growth: spt-daemon\r\n  `concurrent_writes` 105.420 s, `two_tier_sync` 58.362 s, spt-store `clone_copies` 65.657 s,\r\n  `different_monics` 73.967 s, `syncmerge reconciled_write` 86.765 s, against the 09-06 baseline of\r\n  22.4 / 18.7 / 17.7 / 18.2 / 27.3 s — **3.2x to 4.7x on all five, at the OLD sha**. So head growth\r\n  is **not NECESSARY** for the slowdown. That is the whole of it: it does NOT measure how much the\r\n  environment explains, and it is not evidence about the head arm at all — that leg ran inside run\r\n  34337797758's window and on a volume that reached 0.018 GiB free, and the head arm never produced\r\n  a comparable pair. **Arm 1 stays OPEN**, its re-run deferred until **IR-90**'s guard exists and a\r\n  window with no `main` push and no CI job on the box can be scheduled.\r\n\r\n- **AMENDMENT 2026-09-10 (hertz, on THIS ENTRY'S OWN arm-1 design note).** The note says the arms run\r\n  **INTERLEAVED** A/B/A/B so box drift cancels. It does not cancel: **B is always the later arm within\r\n  each pair**, so a monotone drift across the session lands on B every time and is read as an arm\r\n  effect. Alternate the PAIR ORDER — **A/B then B/A** — record per-leg timestamps and conditions, and\r\n  describe the result as **REDUCING order confounding, not eliminating it**. Second binding change,\r\n  from the releases#294 triage: **instrument, do not infer.** `cargo nextest run --success-output\r\n  immediate` retains stdout for PASSING tests (deployah), so a passing arm can still print poll\r\n  elapsed, iteration count, IPC time and producer progress — **a failing arm is not required** for a\r\n  margin measurement (todlando, correcting deployah's \"it has to fail to be informative\"). Arm 1 was\r\n  never re-run, so this lands before the measurement, not after it.\r\n\r\n### IR-86 — golden's 32 GiB floor is BELOW the measured 67.4 GiB Windows suite footprint, so a start floor passes a box that cannot finish\r\n\r\n- **Status:** OPEN, filed by doyle 2026-09-08 at the #272/v0.68.0 golden r2 triage. · **Origin:**\r\n  run 34262154550 @ `25e60015` (shaped on `e4444413`), Windows test job 102182665033: every product\r\n  step green (Phase A 3346/3346, Phase B 234/234, Summary 2, FAIL 0), the ONLY reds were the two\r\n  in-job floor gates. `FLOOR_START` 97,649,786,880 B PASS at 18:47:23Z -> `FLOOR_DOCS`\r\n  25,284,501,504 B RED at 19:31:55Z -> `FLOOR_END` RED. Consumed in-job: 67.4 GiB.\r\n- **Mechanism:** `golden.yml` derives 32 GiB as \"the observed tens-of-GB full-suite footprint\r\n  rounded up to the next binary boundary, preserving headroom for one complete run\" (comment\r\n  above the Windows start floor). The measured footprint is 67.4 GiB, so a start reading anywhere\r\n  in [32, ~100) GiB passes and the job then walks under the floor by construction: box baseline\r\n  91 GiB minus 67.4 = 23.5 < 32. This is a shortfall of the DERIVATION, not a rate, not a product\r\n  red, and not the instant-vs-sustained face IR-46 files (that face is fixed by the FLOOR_DOCS\r\n  re-read, which is what caught it). The start floor must be footprint + end-floor (~100 GiB) or\r\n  it asserts nothing about finishing.\r\n- **Coverage consequence (the load-bearing part):** the Windows `Docs drift gate (CLI ref + llms\r\n  links)` step is sequenced BEHIND `FLOOR_DOCS`, so it SKIPPED and r2 held NO Windows CLI-ref\r\n  axis at that sha until the rerun. A floor red that skips a gate is a coverage hole wearing a\r\n  disk red.\r\n- **Kin:** [[IR-46]] (a floor asserts an instant), [[IR-59]] (pool arithmetic, LNK-class reds\r\n  that name no disk), [[IR-64]] (the operator-payload reservoir that sets the box baseline; its\r\n  ripe-when arm — a golden that dies at the floor despite adopted pool discipline — FIRED here\r\n  in the in-job form), [[IR-73]] (second half BUILT: the within-job re-read exists and is what\r\n  produced the FLOOR_DOCS reading), REQ-CI-FREE-SPACE-PREFLIGHT.\r\n- **Coupling (deployah 23:54Z, from `golden.yml` at `25e60015`):** the Windows `DISK docs floor`\r\n  (:616) and `Docs drift gate — windows` (:629) carry only `if: runner.os == 'Windows'`, no\r\n  `always()`, while `DISK end floor` does (`always() && runner.os == 'Windows'`, ~:705). Actions'\r\n  default is \"previous steps succeeded\", so ANY Phase B red skips the docs axis by construction —\r\n  observed three times at this sha (floor red, ttl cell, ttl cell). The docs gate is therefore never\r\n  independent evidence: it can only be banked when Phase B is green in the same job. Remedy line:\r\n  gate the two docs steps on `!cancelled()` plus the success of the steps they actually depend on\r\n  (checkout/build), not on Phase B — a rig change, new sha, hertz workflow rider slot.\r\n- **Remedy shape:** re-derive the start floor from the measured footprint (67.4 GiB Windows,\r\n  Linux to be measured) plus the 32 GiB end floor, print the footprint (start minus end free)\r\n  on every run so the number re-measures itself, and keep the 32 GiB literal only for\r\n  `FLOOR_END`.\r\n- **Ripe when:** next `golden.yml` touch (hertz workflow rider slot). · **Size:** small — one\r\n  literal per start-floor site + one printed subtraction.\r\n\r\n### IR-87 — two-host ceremony halves are INDEPENDENT jobs on DIFFERENT runners (A Windows/hfenduleam, B Linux/kitsubito); B's 900 s budget runs on B's own clock, so any older queued Windows job starves A and reds B deterministically, and the panic text blames pairing\r\n\r\n- **Status:** OPEN, filed by doyle 2026-09-08 at the #272 golden r2 triage. · **Origin:**\r\n  run 34262154550, twohost-b job 102207296960 (log 81,692 B, sha256 67403f04…8030): role B built,\r\n  rostered, polled PAIR_MEET_UP every 30 s from 19:34:30Z, and hit the rig_wait barrier\r\n  \"pairing: A rostered via the daemon-hosted responder\" at its 900 s deadline 19:49:17Z\r\n  (`crates/spt-daemon/tests/twohost.rs`, exit 101, 2 passed 1 failed). twohost-a (102207296985)\r\n  was QUEUED from 19:32:13Z with no runner: the Windows runner went to thin ci run 34261096301\r\n  (post-merge on main @ `e4444413`) the second the golden test job released it at 19:31:56Z.\r\n- **Mechanism:** `golden.yml` sequences twohost-a and twohost-b after `test`, but they are two\r\n  jobs on two runners (measured 2026-09-08 20:56Z via the jobs API `runner_name`: twohost-a on\r\n  hfenduleam, twohost-b on kitsubito), and GitHub's queue does not honour a workflow's intra-run\r\n  job ordering against a FOREIGN run on either runner. B starts, its whole budget ticks against a partner that has not been\r\n  scheduled, and `rig_wait` panics `never converged on the rig: {what}` — a text that reads as a\r\n  pairing defect. The lanes were not at fault, and twohost-a's outcome was predetermined once B\r\n  exited (a later A pass would be vacuous).\r\n- **Kin:** [[IR-76]] (hfenduleam is golden runner AND builders' box; the job-start census cannot\r\n  see a competing GitHub run either), [[IR-62]] (rig collisions on shared runners), the W1 two-host\r\n  rig, `a-barrier-cannot-ride-a-carrier-its-sender-outlives` (memory, same family: a barrier needs\r\n  the receiver's own answer).\r\n- **Remedy shape (pick at rider time):** (1) start barrier on B keyed to A's job having STARTED\r\n  (a run-scoped artifact or a `needs`+matrix collapse into ONE job that spawns both roles), or\r\n  (2) B's deadline clock starts at first A-rostered signal with a separate, longer \"A never\r\n  appeared\" budget, or (3) the panic names the missing partner's job state so triage does not\r\n  chase pairing. Any option: the two-host halves must never share a runner queue with a foreign\r\n  run while one half waits.\r\n- **Ripe when:** next `golden.yml`/twohost rig touch. · **Size:** small-medium (job shape or\r\n  barrier rework + panic text).\r\n\r\n- **AMENDMENT 2026-09-10 (releases#294, golden 34445961595 att1 @ `a9e786b2`) — THE STARVING RUN CAN\r\n  BE GOLDEN'S OWN PR, which makes this self-inflicted and recurrent on every golden run with a PR\r\n  open.** Measured timeline: **07:18:59Z** golden `test (Windows)` completes and releases hfenduleam;\r\n  **07:18:59Z** twohost-a queued; **07:19:01Z** PR run **34446095808** job `unit (Windows,\r\n  hfenduleam)` SEIZES the runner; **07:19:02Z** twohost-b starts on the free kitsubito; **07:36:16Z**\r\n  twohost-b fails at **900.41s** — `never converged on the rig: pairing: A rostered via the\r\n  daemon-hosted responder`. The origin case (2026-09-08) was a post-merge push on `main`: a run\r\n  belonging to someone else. **Here the starving run is the `pull_request` run of the very PR carrying\r\n  the golden head**, so opening the golden PR arms the starvation of that same head's twohost pair.\r\n  **Consequence for the remedy shape above: any option that only de-conflicts against OTHER lanes'\r\n  runs does not reach this case.** The golden head's own PR has to be excluded from the Windows\r\n  runner for the duration of the golden run (or the pair collapsed into one job, option 1).\r\n- **SECOND-ORDER FACE (deployah, same run): starvation does not merely red B — it desynchronises the\r\n  pair past repair.** twohost-b was TERMINAL at 07:36:16Z; twohost-a did not start until **07:48:07Z**\r\n  — the two halves never overlapped for a single second, so twohost-a's outcome is uninformative\r\n  **whatever it says**, and a red there must not be counted as a second product failure. Recorded\r\n  honestly at deployah's own insistence: **VOID is his SCORING interpretation, not a fact about the\r\n  run** — the release record carries GitHub's raw `conclusion` for both jobs beside the scoring, not\r\n  laundered into it.\r\n- **⚠ ITS WALL CLOCK IS INDISTINGUISHABLE FROM [[IR-89]]'s.** A 900 s twohost red whose panel blames\r\n  pairing is ALSO the exact signature of the banked Windows-firewall hazard. The panel alone cannot\r\n  separate them; **the job TIMELINE can**. Check the schedule before accepting the firewall hazard for\r\n  any 900 s twohost red — this one fit that signature perfectly and was not it.\r\n\r\n### IR-88 — `pool-release` via `cargo run -p xtask` REBUILDS xtask INTO the pool it is releasing, so a reaped pool regrows ~2.8 GB in silence\r\n\r\n- **Status:** OPEN, filed by doyle 2026-09-08 from hertz's reap report (20:00Z) during the #272\r\n  golden r2 repair. · **Origin:** hertz reaped hertz-lane4 / hertz-repin / hertz-percell-id target\r\n  subtrees (Length-sum upper bounds 68.16 / 47.11 / 8.79 GB) and then ran `cargo run -p xtask --\r\n  pool-release …` from each worktree: cargo rebuilt xtask into the just-reaped `target/` (2.8 GB\r\n  back in lane4, partial in repin), nothing printed said so, and the descendancy stopper killed\r\n  the second before it finished. Removed by hand afterwards; the post-reap free reading on the\r\n  record (275.95 GiB at 19:55:51Z) predates the regrowth.\r\n- **Mechanism:** the documented verb (AGENTS.md: \"drop it with `pool-release`\") is a `cargo run`,\r\n  and cargo's default target for that run IS the pool being released. The verb's own success path\r\n  recreates the state the operator just measured away; a teardown step that runs it AFTER a reap\r\n  undoes part of the reap and leaves the recorded free reading stale.\r\n- **Remedy shape:** either (a) `pool-release` documented and scripted as a PREBUILT `xtask.exe`\r\n  invoked against `--pool <dir>` from another pool, or (b) the verb refuses when its own\r\n  `CARGO_TARGET_DIR`/default target equals `--pool` and prints the prebuilt form, or (c) the reap\r\n  recipe orders release BEFORE the subtree delete. Memory banked 2026-09-08\r\n  (`pool-release-rebuilds-xtask-into-the-pool-you-just-reaped`); this entry is the durable home.\r\n- **POSITIVE CONTROL (hertz, 2026-09-09, ruling-3 gate-r3 teardown):** the same release run\r\n  from a PREBUILT `xtask.exe` invoked from outside the pool regrew NOTHING — the pool's own\r\n  `xtask.exe` still carried its original 21:00:42 mtime afterwards, and the reap that followed\r\n  reclaimed 63.71 GiB (132.03 -> 195.74 GiB free) against a 64.88 GiB Length-sum. So the\r\n  regrowth is a property of the `cargo run` VEHICLE, not of the verb, and remedy (a) is proven\r\n  rather than merely proposed.\r\n- **Kin:** [[IR-31]] (pool budgeting), [[IR-56]] (pool-claim identity from CWD — same verb\r\n  family, same \"the tool acts on where it stands\" shape), releases#103.\r\n- **Ripe when:** next xtask pool-verb touch or the teardown runbook edit. · **Size:** tiny —\r\n  one guard or one doc line.\r\n\r\n### IR-89 — hfenduleam's Windows Firewall drops cold inbound UDP to the runner-built test exes, so the two-host rig's first B→A claim (W2 helper) reds for its whole 900 s budget and the panic blames A\r\n\r\n- **Status:** BOX HALF **APPLIED** 2026-09-08; WORKFLOW HALF **BUILT** 2026-09-09 — PR #211\r\n  (`9b96d7e7` + this amendment), **LANDED-pending-golden**: the `golden.yml` steps are UNEXERCISED\r\n  until the next golden run, because thin CI compiles the cells and skips them. Filed by doyle 2026-09-08\r\n  at the #272 golden r2 terminal triage; the operator-blocked flag is retired here, because\r\n  the operator acted.\r\n  The operator applied BOTH layers that evening — the Windows inbound rule (~23:41Z) and the\r\n  tailnet ACL grant (~23:56Z) — and the re-probe with the same rule-less pwsh listener read\r\n  **3/3 over Tailscale on 7483 AND 3/3 on 7489 at 23:57:50Z** from `100.98.197.12`, with a\r\n  post-terminal probe 3/3 on both ports at attempt 4. v0.68.0 then shipped at `a2f335f8` with\r\n  both two-host legs GREEN on golden r4, so the box half is closed by measurement and not by\r\n  assertion. **STILL OPEN, and it is the durable half:** the WORKFLOW guard (hertz) — the\r\n  pre-ceremony B→A UDP probe at `d882297f` that reds `INBOUND_BLOCKED` in 10 s with its own\r\n  name instead of burning 900 s blaming pairing, plus retiring the dead `_work\\spt-core`\r\n  rules note in the runner runbook. Until that lands, the next box (or the next ACL edit)\r\n  re-opens the 900 s face with nothing to name it. · **Origin:** run 34262154550 @ `25e60015`, twohost-a 102229928746\r\n  (`two_host_web_helper_role_a`, :968, 900.40 s) and twohost-b 102229928689\r\n  (`two_host_web_role_b`, :559, 910.20 s): B logged 75 × \"A not ready … broker QUIC op exceeded\r\n  the 10s bound (peer unresponsive)\" from 20:49:49Z to 21:04:37Z and was never ADMITTED. Ladder\r\n  green both sides; both halves started 20:41:23Z on their own runners (not IR-87's starvation).\r\n- **Mechanism (MEASURED 21:11Z):** the box's firewall policy is `BlockInbound,AllowOutbound` on\r\n  all three profiles (Ethernet and Tailscale both Private). Inbound allow rules exist only for\r\n  exes under `Documents\\projects\\spt-core\\target` (interactive Allow clicks) and under the DEAD\r\n  pre-rename runner path `_work\\spt-core\\spt-core`; exactly ONE under `_work\\spt-bs-core` (its\r\n  `target\\debug\\spt.exe`, the CLI, not the binder — deployah's count, mine had said zero), none for\r\n  any `twohost_web-*.exe`. `Get-NetFirewallProfile` shows `DefaultInboundAction = NotConfigured`,\r\n  whose effective default IS block: the block is Windows' default, not a configured policy, so there\r\n  is no policy to \"restore\". The runner is a service (`.\\decid`), so the Allow dialog that minted the\r\n  old rules cannot appear. A's helper cell 3 bound `broker udp 7483` inside\r\n  `_work\\spt-bs-core\\spt-bs-core\\target\\debug\\deps\\twohost_web-f73bc44be13353fb.exe`; B dialled\r\n  `100.68.35.65:7483` cold. Probe: a rule-less pwsh UDP listener on hfenduleam:7483 received 0 of\r\n  3 datagrams from kitsubito `100.98.197.12`; the reverse control (python listener on\r\n  kitsubito:7483) received 3 of 3 from hfenduleam.\r\n- **Why three faces from one cause:** the shared-key rig (pre-`e4444413`) reached A only through\r\n  holes A's OUT-dialling cells (7480–7482) had opened for `id_a` — six 10 s bounds until B's\r\n  magicsock fell onto one of those paths, then ADMITTED (the 63 s stall, helper-stall memory), or\r\n  onto a live same-key sibling that never replied (the 21 min hang in 34239258523). Per-cell A\r\n  identity (`id_a_for`, `e4444413`) removed the accidental route by construction, leaving only\r\n  the cold path, which the firewall drops. hertz's one-box discriminator \"vanishes\" was true on\r\n  one box because one box never crosses the firewall. Product and rig are both exonerated; the\r\n  rig's `a_addr` comment already names W2 as the first A-ward claim.\r\n- **Remedy (two halves):** (1) BOX, operator-owned, elevated on hfenduleam:\r\n  `New-NetFirewallRule -DisplayName \"spt-ci two-host rig UDP-In (kitsubito only)\" -Direction Inbound -Action Allow -Protocol UDP -LocalPort 7460-7499 -RemoteAddress 100.98.197.12 -Profile Any`\r\n  (rig ports at the sha: ladder 7460/7461; web `PORT_OFFSET` 20 → A cells 7480–7483, B 7481; the\r\n  A-ward surface today is exactly UDP 7480–7483 — deployah's tighter range — and the whole range\r\n  moves with any `SPT_TWO_HOST_PORT_A` override, so the rule must move with it);\r\n  program-path rules are the wrong shape because the exe hash changes per build. Verify with the\r\n  same probe (3/3) before any rerun. (2) WORKFLOW, hertz: a B→A UDP probe step in the twohost\r\n  jobs before the ceremony, so this reds in 10 s with its own name instead of 900 s blaming\r\n  pairing; and retire the dead `_work\\spt-core` rules note in the runner runbook.\r\n- **Kin:** [[IR-83]] (the tailnet-ACL face of a cross-box inbound block — KIN, **NOT the same\r\n  finding**: that entry is the tailnet policy layer, this one is the Windows firewall layer, and\r\n  the SECOND LAYER note below is exactly the measurement that separates them), [[IR-87]] (the\r\n  other way a half waits 900 s on a partner), [[IR-76]] (golden runner\r\n  is the operator's box), [[IR-64]] (box-level facts only the operator can move),\r\n  `twohost-web-helper-stall-shared-a-identity-stale-path` (memory; its CONFIRMED arm is re-read\r\n  by this entry).\r\n- **AMENDMENT 2026-09-09 — the WORKFLOW half is BUILT and FIELD-MEASURED; it is LANDED-pending-golden\r\n  (hertz).** The guard is two cells in `twohost_web.rs` plus a step per half in `golden.yml`, and it\r\n  grew four design corrections that are worth more than the guard itself, because each one is a way a\r\n  probe can certify the fault it exists to catch.\r\n  1. **A FIXED SYMMETRIC WINDOW ADDS A THIRD CAUSE THAT LOOKS LIKE THE OTHER TWO.** The step boundary\r\n     orders the probe on ONE host; it does not align two, and after the ladder each half pays its own\r\n     wrapper and `cargo test` (on Windows a fingerprint scan plus Defender's first touch of a fresh\r\n     exe). MEASURED: the first hand-run in the A=kitsubito direction (13:14:13 → 13:14:51Z) redded\r\n     `INBOUND_BLOCKED` at 10.24 s with text asserting \"a BOX rule, not a product or rig fault\" — and\r\n     the cause was `cargo`'s start-up on the SENDER putting its first datagram after the receiver's\r\n     10 s window closed. An innocent box, the guard's own words against it. What stopped it being\r\n     filed as a kitsubito block was that the box facts contradicted the text (`tailscale debug\r\n     netmap` on kitsubito lists `100.68.35.65/32` among its permitted inbound sources, and `ufw` is\r\n     inactive) — a failure text that contradicts a measured box is the text's defect. So the\r\n     rendezvous is DATA: A listens up to the rig budget and beacons once a second; B binds first,\r\n     waits for a beacon, and only then starts a ten-second clock, so B's red has already excluded\r\n     \"A is not up\". That is a FOURTH outcome with its own name, `PROBE_NO_BEACON`, never\r\n     `INBOUND_BLOCKED`.\r\n  2. **THE LISTENING SOCKET MUST NEVER SEND.** Any outbound datagram from the measured port opens\r\n     stateful return state for it, so B's probe then arrives SOLICITED and crosses under both layers\r\n     — this entry's own \"solicited return traffic works under either fault\" applied to the guard\r\n     rather than to the ceremony. MEASURED: with the beacon sharing A's listening socket, the\r\n     out-of-grant control went **GREEN at 13:28Z** on a port a listen-only run had measured BLOCKED\r\n     at 13:20Z; a further green at 13:31Z with the beacon moved but the ack still leaving that socket\r\n     was residual state from 13:28 — true BY ELIMINATION rather than by assertion: nothing in the\r\n     13:31 run sent from 7509 before the first arrival, so the only outbound that could have opened\r\n     that port's return state belongs to the previous run. Beacon and ack both leave an ephemeral socket now, and B sends\r\n     from an ephemeral port too, so no run repeats a 4-tuple a previous run opened.\r\n  3. **THE ACK IS ADDRESSED TO B'S RIG PORT, not to the probe's source port.** MEASURED: acking to\r\n     `from` produced a run that CONTRADICTED ITSELF — A said `INBOUND OK` and B said\r\n     `INBOUND_BLOCKED`, same run, 13:41:33 → 13:41:50Z — because A's ack leaves its ephemeral\r\n     socket, is therefore not return traffic of the flow B opened, and a receiver whose inbound rule\r\n     is a port RANGE drops it. The rig port is the only address either host is reachable on cold.\r\n  4. **THE FALSIFIER, and it is the operator's own rule used as an instrument.** Forcing the probe\r\n     port to **7509** (`SPT_TWO_HOST_PORT_A=7480`), one port outside the granted udp 7460-7499, reds\r\n     the guard on demand with no elevation and no policy edit. Run TWICE BACK TO BACK at the final\r\n     code, 13:43:41 → 13:44:23Z and 13:44:25 → 13:45:07Z: **RED, RED** — A after 40 s having sent\r\n     39 beacons, B in its ten seconds having sent 48 and 47 datagrams with no ack, both exit 101.\r\n     One red would only prove a state timeout expired; two consecutive reds prove the design writes\r\n     none. The grant boundary is therefore measured from inside the test binary: 7489 crosses, 7509\r\n     does not, same hosts, same binary, one env var apart.\r\n  5. **ONE ACK IS NOT ENOUGH — the same split verdict arrives by packet loss** (doyle, reviewing the\r\n     built lane). A acking ONCE and breaking leaves B's red resting on a single unrepeated UDP\r\n     datagram: lose it and A prints `INBOUND OK` while B reds `INBOUND_BLOCKED`, blaming a firewall\r\n     for ordinary loss — correction 3's defect reached by a different road. A now keeps draining for\r\n     a short window after its own verdict is already settled and acks EVERY probe in it, while B\r\n     stops on the first ack. The A-side assertion is unchanged: it was decided by the first datagram.\r\n  6. **THE PROBE STEPS CARRY THEIR OWN BUDGET, 300 s, set EXPLICITLY** beside ceremony steps that say\r\n     900. It bounds RENDEZVOUS skew, not pairing, so a blocked link costs 300 s ONCE instead of 900\r\n     per cell per half. Left unset it would have been `from_env`'s invisible default sitting next to\r\n     a visible 900 on the step below — a number the next reader would have inferred wrongly, which is\r\n     this entry's whole failure mode in miniature.\r\n- **FIELD PROOF, 2026-09-09, and it is the ONLY proof this guard has:** `dir 1` (A=hfenduleam,\r\n  B=kitsubito) 13:45:14 → 13:45:18Z and `dir 2` (A=kitsubito, B=hfenduleam) 13:45:41 → 13:45:58Z,\r\n  both GREEN with the ack after ONE datagram, both exits 0, both hosts running byte-identical source\r\n  (md5 `f31779339266f8034dcd72917c56a37e`, checked on both sides). Free space 174.38 GiB, flat across\r\n  all four arms.\r\n  ⚠ **THE `golden.yml` STEPS THEMSELVES ARE UNEXERCISED UNTIL THE NEXT GOLDEN RUN.** Thin CI\r\n  compiles the cells and SKIPS them — `Rig::from_env` returns `None` without `SPT_TWO_HOST`, so a\r\n  green thin run says the code builds and nothing about the steps. The wall times above are the field\r\n  proof; treat the workflow half as landed-pending-golden and not as verified by its own PR.\r\n- **Ripe when:** the next GOLDEN run, which is the first thing that exercises the steps — the\r\n  code half is built and field-measured (PR #211). (The box half was ripe \"now\" against\r\n  `25e60015` and is done; #272 golden acceptance is no longer blocked by it.) · **Size:** one\r\n  workflow step remaining; the elevated command is spent.\r\n- **SECOND LAYER (measured 23:41–23:50Z, after the operator applied the Windows rule exactly as\r\n  asked and the re-probe STILL read 0/3):** the tailnet ACL. The same `python.exe` listener (own\r\n  program rule) received 3/3 from kitsubito over the LAN (`192.168.1.168 → 192.168.1.81:7483`) and\r\n  0/3 over Tailscale (`100.98.197.12 → 100.68.35.65`), TCP connect over Tailscale times out too,\r\n  solicited return over Tailscale works, ShieldsUp false both ends. `tailscale debug netmap` on\r\n  hfenduleam: one PacketFilter rule, 18 permitted inbound sources, kitsubito ABSENT; kitsubito is\r\n  `tag:eye-tracking-resource` owned by a different tailnet user, and its own filter DOES permit\r\n  hfenduleam. Asymmetric policy: member device → tagged resource allowed, reverse denied. The\r\n  Windows rule was NECESSARY (rule-less exe, LAN probe 0/2 earlier) and NOT SUFFICIENT. Remedy\r\n  half (1) gains an ACL grant, operator-owned in the admin console:\r\n  `{\"action\":\"accept\",\"src\":[\"tag:eye-tracking-resource\"],\"dst\":[\"hfenduleam:7460-7499\"],\"proto\":\"udp\"}`.\r\n  Rider 4's failure text names both layers and the LAN-vs-Tailscale probe as the discriminator.\r\n  Lesson for the entry: a cross-box \"unresponsive\" has at least THREE layers (Windows rule, tailnet\r\n  policy, the exe's own bind); probe through the SAME path the rig uses, and re-probe after every\r\n  single change — the first fix reading as \"applied\" is not the probe reading 3/3.\r\n- **Corroboration + reading traps (deployah 23:50Z, from the box):** Windows rule found present by\r\n  FILTER search (`netsh advfirewall firewall show rule name=all dir=in verbose`), not by name — the\r\n  operator's name is hyphenated \"two-host\" and a `twohost` grep reads it ABSENT. Netmap: the single\r\n  filter permits ALL ports and ALL protocols from its 18 sources, so the grant is SOURCE-scoped, not\r\n  port-scoped — \"this peer is not a permitted source at all\", which is why TCP timed out beside UDP.\r\n  Two permitted sources (100.98.213.33, 100.98.214.87) share kitsubito's 100.98/16 and read as hits\r\n  to an eyeball scan for \"100.98.\"; test membership of the full /32, never a prefix. His first netmap\r\n  read extracted a non-existent field (`SrcIPs`; the real key is `Srcs`), printed an empty list and\r\n  minted a confident \"ABSENT\" — an empty extraction cannot witness absence; the 18-count is from the\r\n  corrected read. Prefs on the box: ShieldsUp false, NoStatefulFiltering true, RouteAll true,\r\n  NetfilterMode 2 — nothing there explains the drop.\r\n- **Probe-rider design rule (hertz, d882297f):** the pre-ceremony probe reds `INBOUND_BLOCKED` for\r\n  EITHER layer and does not pretend to know which — its job is \"the box cannot receive, stop triaging\r\n  the product\"; the layer is named only by the one measurement that decides it (same listener, LAN\r\n  vs Tailscale), which the failure text prints as a recipe. A guard that names a cause it did not\r\n  measure is the defect class this whole entry documents.\r\n\r","startLine":4664,"lineNumbers":[4664,4665,4666,4667,4668,4669,4670,4671,4672,4673,4674,4675,4676,4677,4678,4679,4680,4681,4682,4683,4684,4685,4686,4687,4688,4689,4690,4691,4692,4693,4694,4695,4696,4697,4698,4699,4700,4701,4702,4703,4704,4705,4706,4707,4708,4709,4710,4711,4712,4713,4714,4715,4716,4717,4718,4719,4720,4721,4722,4723,4724,4725,4726,4727,4728,4729,4730,4731,4732,4733,4734,4735,4736,4737,4738,4739,4740,4741,4742,4743,4744,4745,4746,4747,4748,4749,4750,4751,4752,4753,4754,4755,4756,4757,4758,4759,4760,4761,4762,4763,4764,4765,4766,4767,4768,4769,4770,4771,4772,4773,4774,4775,4776,4777,4778,4779,4780,4781,4782,4783,4784,4785,4786,4787,4788,4789,4790,4791,4792,4793,4794,4795,4796,4797,4798,4799,4800,4801,4802,4803,4804,4805,4806,4807,4808,4809,4810,4811,4812,4813,4814,4815,4816,4817,4818,4819,4820,4821,4822,4823,4824,4825,4826,4827,4828,4829,4830,4831,4832,4833,4834,4835,4836,4837,4838,4839,4840,4841,4842,4843,4844,4845,4846,4847,4848,4849,4850,4851,4852,4853,4854,4855,4856,4857,4858,4859,4860,4861,4862,4863,4864,4865,4866,4867,4868,4869,4870,4871,4872,4873,4874,4875,4876,4877,4878,4879,4880,4881,4882,4883,4884,4885,4886,4887,4888,4889,4890,4891,4892,4893,4894,4895,4896,4897,4898,4899,4900,4901,4902,4903,4904,4905,4906,4907,4908,4909,4910,4911,4912,4913,4914,4915,4916,4917,4918,4919,4920,4921,4922,4923,4924,4925,4926,4927,4928,4929,4930,4931,4932,4933,4934,4935,4936,4937,4938,4939,4940,4941,4942,4943,4944,4945,4946,4947,4948,4949,4950,4951,4952,4953,4954,4955,4956,4957,4958,4959,4960,4961,4962,4963,4964,4965,4966,4967,4968,4969,4970,4971,4972,4973,4974,4975,4976,4977,4978,4979,4980,4981,4982,4983,4984,4985,4986,4987,4988,4989,4990,4991,4992,4993,4994,4995,4996,4997,4998,4999,5000,5001,5002,5003,5004,5005,5006,5007,5008,5009,5010,5011,5012,5013,5014,5015,5016,5017,5018,5019,5020,5021,5022,5023,5024,5025,5026,5027,5028,5029,5030,5031,5032,5033,5034,5035,5036,5037,5038,5039,5040,5041,5042,5043,5044,5045,5046,5047,5048,5049,5050,5051,5052,5053,5054,5055,5056,5057,5058,5059,5060,5061,5062,5063,5064,5065,5066,5067,5068,5069,5070,5071,5072,5073,5074,5075,5076,5077,5078,5079,5080,5081,5082,5083,5084,5085,5086,5087,5088,5089,5090,5091,5092,5093,5094,5095,5096,5097,5098,5099,5100,5101,5102,5103,5104,5105,5106,5107,5108,5109,5110,5111,5112,5113,5114,5115,5116,5117,5118,5119,5120,5121,5122,5123,5124,5125,5126,5127,5128,5129,5130,5131,5132,5133,5134,5135,5136,5137,5138,5139,5140,5141,5142,5143,5144,5145,5146,5147,5148,5149]},"fileSize":501961,"meta":{"source":{"type":"path","value":"C:\\Users\\decid\\Documents\\projects\\spt-core\\docs\\INFRA-REGISTER.md"},"truncation":{"direction":"head","truncatedBy":"lines","totalLines":5782,"totalBytes":43730,"outputLines":486,"outputBytes":43730,"shownRange":{"start":4664,"end":5149},"nextOffset":5150}}},"isError":false,"timestamp":1789094610898}}
{"type":"message","id":"4d5901f7","parentId":"f62c0caa","timestamp":"2026-09-11T02:43:30.903Z","message":{"role":"toolResult","toolCallId":"call_RjOILJi8oXwvNWmFdXU4dCPC|fc_065c0d1976ecf9c2016aa36ad0793c87d1a4ed1fb473d15dbe","toolName":"read","content":[{"type":"text","text":"Machine-generated from the eight ci unit logs, not transcribed (a hand-typed 12x8 matrix is where\ntranscription errors live). `X` = reported LEAK at that sha on that box.\n\n| cell | W ff4b405d | W e3bd53d4 | W 401a19ad | W f3c8495b | L ff4b405d | L e3bd53d4 | L 401a19ad | L f3c8495b |\n|---|---|---|---|---|---|---|---|---|\n| `spt-daemon brainproc::tests::clear_before_spawn_defeats_exact_generation_stale_file` | X | X | X | X | . | . | . | . |\n| `spt-daemon brainproc::tests::ready_but_old_gen_never_drains_does_not_promote_rolls_back` | X | X | X | X | . | . | . | . |\n| `spt-daemon brainproc::tests::stale_generation_minus_one_ready_never_promotes` | X | X | . | X | . | . | . | . |\n| `spt-daemon brainproc::tests::trial_kills_alive_never_ready_candidate_before_rollback` | X | X | X | X | . | . | . | . |\n| `spt-daemon broker::tests::windows_session_is_zombie_sees_a_handle_held_corpse_as_dead` | X | . | . | X | . | . | . | . |\n| `spt-daemon livehost::tests::legacy_psyche_sweep_guard_is_id_specific_and_fail_safe` | . | . | . | . | X | X | X | . |\n| `spt-daemon shellhost::tests::kill_shell_at_still_kills_a_matching_pair` | . | . | . | X | . | . | . | . |\n| `spt-daemon shellwake::tests::kill_waker_at_still_kills_a_matching_pair` | . | X | X | X | . | . | . | . |\n| `spt-live digest::tests::extractor_timeout_errors` | X | X | . | X | . | . | . | . |\n| `spt-live history::tests::fetcher_timeout_errors` | X | X | . | . | . | . | . | . |\n| `spt-runtime runtime::tests::bounded_run_kills_on_timeout` | X | X | X | X | . | . | . | . |\n| `spt-store proc::tests::process_cmdline_reads_a_live_arg_marker` | . | . | . | . | X | X | X | X |\n| **leaky count** | 8 | 8 | 5 | 9 | 2 | 2 | 2 | 1 |\n\nUnion = 12 cells across 4 shas x 2 OSes. Present at EVERY Windows sha: 4. Present at every Linux sha: 1.\n\n#### Three readings, in increasing order of what they support\n\n**1. The churn is total and it is the whole point.** Windows counts run 8, 8, 5, 9 — the HIGHEST\nvalue is at `f3c8495b`, the tip carrying every fix F1-F16. Only **4 of 12** cells are present at\nevery Windows sha; only **1 of 2** at every Linux sha. Read as a quality signal the series says W2\nmade leaking worse, which is exactly as wrong as my retracted \"8 -> 5, favourable\" read and wrong\nfor the same reason. **A leaky count is not a signal in either direction.**\n\n**2. NEW, and I had not said it before building this table: the two OS sets are DISJOINT.** Ten\ncells leak only on Windows, two only on Linux, and **not one cell leaks on both**. Windows carries\n8-9 leaky cells per run against Linux's 1-2. So this is not one flaky population sampled twice —\nit is two populations with no overlap, and the Windows one is roughly five times larger. Any\nexplanation that treats \"leaky tests\" as a single phenomenon has to account for a clean partition\nby OS.\n\n**This is an OPEN QUESTION and the draft does not answer it. I do not have that explanation yet.**\nRecorded deliberately without a candidate cause: the partition is a measurement, and the temptation\nto pair a striking measurement with a plausible story is how the \"8 -> 5 is favourable\" reading got\ninto the record in the first place. Whoever takes this should arrive at a cause by reading, not by\ninheriting one from me.\n\n**SCOPED CAUSE, IN SOURCE, FOR ONE FAMILY ONLY (doyle ruled 10:22Z: source beats story; a source\ncause covering one family is a measurement and is filed as one).** The brainproc family leaks on\nWindows and not Linux because *its own fixture is asymmetric*: `long_child()` (brainproc.rs:1359)\nspawns `Command::new(\"cmd\").args([\"/C\",\"ping\",\"-n\",\"30\",\"127.0.0.1\"])` on Windows but\n`Command::new(\"sleep\").arg(\"30\")` on Unix — a shell wrapper on one box, a bare process on the other.\nThe Windows candidate the supervisor kills is `cmd`; the process burning 29 seconds is its child.\nThat is two lines of source, not an inference from the symptom. **And it is NOT the whole partition:**\n`process_cmdline_reads_a_live_arg_marker` uses a shell on BOTH arms (`sh -c \"sleep 30; : marker\"` /\n`cmd /C \"ping … & rem marker\"`) yet leaks on **Linux only** — the shell mechanism predicts it should\nleak on both boxes and it does not. So one family has a cause I can point at in the source, the\npartition as a whole remains OPEN, and the counterexample stands in this paragraph rather than a\nfootnote so no one carries the cause further than it goes.\n\n**THE PRODUCT PATH HAS NO INTERMEDIARY; THE FIXTURE DOES.** I chased the obvious escalation — if the\nreal supervisor also killed a shell wrapper, then \"never two live brains\"\n(REQ-HAZARD-BROKER-PROCESS-ISOLATION, the invariant this very cell guards) could be violated on\nWindows in production while the test stayed green. It cannot: `spawn_brain_child` (brainproc.rs:1224)\ndoes `Command::new(exe)` — the brain is spawned DIRECTLY, no shell, no grandchild, so a single-pid\nkill reaches it. **This is a test-fixture artifact, not a product defect**, and the fixture's shell\nis a Windows-only convenience for \"a process that blocks ~30s\" that introduced a layer the real path\ndoes not have. The negative is the useful half: it keeps the crashloop invariant out of IR-81 (a).\n\n**Why the cell passed review for as long as it did.** It asserts `pid != 0 && !pid_alive(pid)` before\nrollback, and that assertion is TRUE — `cmd` really is dead. The process still doing work is the one\nit never looks at. The leak and the green are not in tension; they are the same fact from two ends.\n**An assertion over a pid cannot see a tree.**\n\n**3. The invariant holds at 12 of 12, and it survived the population being shuffled three times.**\nEvery union member spawns a child process and then kills it, lets it time out, or inspects its\ncorpse — `trial_kills_alive`, `kill_shell_at`, `kill_waker_at`, `bounded_run_kills_on_timeout`,\n`extractor_timeout_errors`, `fetcher_timeout_errors`, `windows_session_is_zombie_..._corpse_as_dead`,\n`legacy_psyche_sweep_guard_...`, `process_cmdline_reads_a_live_arg_marker`, and the three brainproc\nspawn/promote/rollback cells. Membership churns freely across four shas and two OSes; the KIND of\ncell has not varied once. **This is the IR-80 headline** and it is better supported now than when it\nrested on a stable-looking five-cell cluster, precisely because the population underneath it has\nbeen reshuffled and the invariant did not move.\n\n#### A MECHANISM, read out of the source of the two Linux cells — calibrated, not generalized\n`process_cmdline_reads_a_live_arg_marker` spawns **`sh -c \"sleep 30; : marker\"`**, and the test's\nown comment says the trailing `; :` is deliberate — it keeps the shell RESIDENT so its\n`/proc/<pid>/cmdline` still carries the marker instead of being tail-exec-replaced by `sleep`. The\nteardown is `child.kill()` then `child.wait()`. **But `child` is the SHELL, and `sleep 30` is the\nshell's own child.** Killing the shell orphans the sleeper, which outlives the test by up to 30\nseconds — which is precisely what nextest reports as a LEAK. The Windows arm has the same shape:\n`cmd /C \"ping -n 30 127.0.0.1 >NUL & rem marker\"`, where `cmd` forks `ping`.\nSo the very construct that makes the test work (a resident shell, so the cmdline stays readable) is\nwhat guarantees a grandchild that a single-pid kill cannot reach.\n\n**What is verified and what is not, stated separately because the difference decides who owns this.**\nVERIFIED by reading source: this shape in BOTH Linux-only cells. CONSISTENT but not proven: the\nWindows family kills the same way — `kill_waker_at_still_kills_a_matching_pair` tears down with\n`kill_shell_pid(ours.id())`, a single-pid kill — so the mechanism is available to it, but I have not\nread every spawn helper. UNVERIFIED: the brainproc, broker and spt-live cells; those spawn real\nbrains and time out extractors, and may leak for unrelated reasons.\n\n**Why this matters beyond IR-80:** a single-pid kill that cannot reach a grandchild is exactly\n[[ir81]] arm (a) — identity and tree-awareness pushed into `kill_pid_tree`/`kill_pid` so no caller\ncan express the unreachable kill. If the mechanism above generalizes, IR-79 (rigs leaking daemons\non a failing assert), IR-80 (this) and IR-81 (kill scoping) are not three findings that share a\nseam, they are three FACES of one defect: **the codebase kills pids, and the things it needs dead\nare trees.** That is a claim worth testing, not asserting — and doyle's one-cell mechanism probe\nis still the right instrument, now with a sharper question: after the kill, is the surviving\nprocess the CHILD or the GRANDCHILD?\n\n---\n\n#### AMENDMENT 1 — \"a pid is not a tree\" has THREE faces, and only one of them is a kill\n\n*(hertz 2026-09-07, ruled by doyle 11:17Z: write this as an IR-80 amendment naming the three faces\nrather than three separate entries, so a reader hunting any one face lands on all three.)*\n\nThe register sentence this lane has been running on is doyle's: **a pid is not an identity and a pid\nis not a tree.** IR-80 and IR-81 were both filed against the KILL side, which made the sentence read\nlike a rule about killing. It is not. It is a rule about **which process you are talking about**, and\nkilling is only the face we happened to find first. Three faces are now measured, each found by a\ndifferent agent working a different problem:\n\n| face | the operation | what going one level too high produces | measured |\n|---|---|---|---|\n| **KILL** | `kill_pid(pid)` on a wrapper | the wrapper dies, the grandchild keeps working — the leak | IR-80's 12-cell union; `proc.rs:430`'s own doc states it |\n| **IDENTITY** | `kill_pid_tree(remembered_pid)` with no image read | you kill *a* process with that number, not the one you meant | IR-81 / #285, `broker.rs:8102` vs `servicehost.rs:651` |\n| **ENV READ** | `psutil.Process(child.pid).environ()` | the wrapper's env certifies a launch the battery would have failed | hertz 2026-09-07, self-test of `.github/bench/launch-battery.py` |\n\n**The third face, in full, because it is the newest and the least intuitive.** Reading back the\nenvironment of the process you spawned is the standard remedy for \"did my scrub/export actually\nland\" — it is what this project's own memory banked after the W0 perch-identity leak. It is\ninsufficient, and it fails in the flattering direction. A wrapper (`env VAR=x`, `cargo`, `nextest`,\n`bash -lc`) modifies the environment it hands the process **below** it, while its own `environ()`\nstill shows exactly what you passed in. So the read-back agrees with your intent, prints PROVEN, and\nsays nothing whatsoever about the process under test. Measured: the first version of\n`launch-battery.py` passed BOTH deliberately-negative tests. The corrected version walks descendants\nand, in the refusal, prints the wrapper as CLEAN beside the grandchild as VIOLATOR — that contrast\nis the face made visible in one line of output.\n\n**Why this belongs in IR-80 rather than in a new entry.** All three are the same error committed at\nthe same seam: an operation is aimed at a pid when the thing it needs to reach is a tree (or a\nspecific member of one). The remedies rhyme — walk the tree, read the identity, report the scope you\nactually covered — and a reader who finds any one face is one paragraph away from the other two.\nFiling them separately would have hidden that, which is the concrete cost doyle's ruling avoids.\n\n**What this amendment does NOT claim.** It does not widen IR-80's population: the 12-cell union\ntable and its Windows/Linux partition are unchanged, and the env face is not a test leak. It does\nnot add a remedy owner — the ENV face's fix is a tool (`.github/bench/launch-battery.py`), not product code, and the KILL and\nIDENTITY faces keep the owners they already have (#285 / todlando post-W2). It is a naming, and its\nwhole value is that the next instance of this error gets recognized as an instance instead of being\nfiled fresh.\n\n**Standing prediction, so this is falsifiable rather than tidy:** a fourth face exists wherever the\ncodebase asks a question *of* a pid that is really a question *about* a tree. The candidates I would\nlook at first are (a) liveness — `process_exists(pid)` answering \"is the work still running\" when\nthe work is a grandchild, and (b) resource attribution — reading a pid's handles/memory to decide\nwhether a lane is finished. Neither is measured; both are named so that finding one counts as\nconfirmation and finding none over the next few incidents counts against the generalization.\n\n### IR-81 — a process kill can be written scoped or machine-wide, and nothing makes the scoped form the only reachable one: both codebases carry the right pattern beside the wrong one\n\n- **Status:** OPEN, drafted by hertz 2026-09-07 08:38Z on doyle's dispatch (08:36Z), from the\n  fleet-daemon death on hfenduleam at 08:03:15Z ([[RCA-FLEET-DAEMON-14444]], cause still UNNAMED).\n  Census body: `docs/PID-KILL-CENSUS.md`. · **Origin:** doyle asked which sites kill a REMEMBERED\n  pid without re-verifying identity AT KILL TIME. The census answered that, and then answered a\n  better question nobody asked: **why the unguarded sites exist at all when the guarded ones sit\n  feet away.**\n- **⚠ THIS ENTRY IS NOT \"FIX THESE TWO SITES.\"** Both individual fixes are small and are dispatched\n  elsewhere (broker.rs:8102 → todlando's lane post-W2; live-relay-int.sh:78 → filed to perri). This\n  entry is about the thing that PRODUCED them and will produce the next one: the scoped form and the\n  machine-wide form are equally easy to write, equally plausible on review, and only one of them is\n  correct on a shared box.\n- **THE PAIRED EXHIBITS — same repo, same hand, feet apart.**\n\n  | | correct, and it says why | incorrect |\n  |---|---|---|\n  | **spt-core** | `spt-daemon/src/servicehost.rs:651` — `provably_gone` first, then `exe_path(pid)` compared to the parked image via `same_image`, then a FRESH post-kill read. Its comment IS the rule: *\"The pid is live. WHO is it? The image path decides — never the number.\"* | `spt-daemon/src/broker.rs:8102` — kills `spid`, a pid REMEMBERED off the session record, through `kill_pid_tree`. `zombie_verdict` consults liveness BY NUMBER (`process_exists`/`is_process_alive`), `adapter_labeled` (a property of the RECORD, not the live process), descendants and grace. **The live process's image is never read.** |\n  | **spt-claude-code** | `ci/launcher/bind-int.sh:50` — `wmic process where \"name='claude-spt.exe' and commandline like '%$ID%'\"`, scoped to this run's unique id, comment *\"never wall-a's\"*. Also `multi-subnet-bringup-int.sh:117` ($C3_ID) and `wake-survival-int.sh:64` (`-match '$PROBE'`). | `ci/psyche/live-relay-int.sh:78` — `for p in $(tasklist \\| grep -i claude-spt \\| awk '{print $2}'); do taskkill //PID \"$p\" //T //F; done` — **every** `claude-spt.exe` on the box, tree-force, no run-scoping. Comment: *\"by marker pid then name.\"* |\n\n  **The knowledge is not missing in either codebase. It is present, written down, and adjacent.**\n  Three correct sites to one wrong one in the adapter; a rule-stating comment in core. What is\n  missing is any mechanism that makes the wrong spelling hard to reach.\n- **Why \"just fix the sites\" is the wrong remedy:** it has already been tried implicitly — someone\n  wrote the scoped form three times, which is what a team looks like when it knows the rule and\n  still ships the exception. A fourth correct site does not prevent a fifth incorrect one. The\n  remedy has to change what is REACHABLE, not what is written.\n- **REMEDY — RULED 2026-09-07 08:40Z (doyle): (a) AND (b), not a choice between them. Two owners,\n  two lanes, and they cover different halves of the hazard.**\n  1. **(a) PRODUCT — push the identity requirement into the primitive.** `spt_store::proc::kill_pid_tree`\n     / `kill_pid` take an expected identity (image path, or a `same_image` closure) and refuse\n     without it, so a caller **cannot express** the unguarded kill; `servicehost.rs:651` stops being\n     the exception among callers and becomes the shape of all of them. **Owner: todlando, post-W2.**\n     ⇄ **This IS the fix shape of the `broker.rs:8102` board BUGFIX — that item and this entry\n     cross-reference each other; neither is complete alone.** Reaches Rust callers only.\n  2. **(b) GATE — `xtask check` refuses the unscoped spelling in CI scripts.** A `tasklist` /\n     `Get-Process` enumeration piped into a kill, or a bare `taskkill` with no\n     `commandline like` / `-match` scope in the same block, is a build failure. **Owner: hertz,\n     rides the IR-37 thin PR after W2 lands.** This is the half remedy (a) can NEVER reach — the\n     unguarded adapter site is a shell script, and no Rust signature constrains a shell script.\n  3. **(c) Fix the two sites and stop.** Recorded as CONSIDERED AND LOSING, not omitted: it has\n     already been tried implicitly — the adapter's author wrote the scoped form three times and\n     shipped the exception anyway — so a fourth correct site does not prevent a fifth wrong one.\n     It leaves the next instance free to appear.\n  **The (a)/(b) split is the entry's real content:** the hazard lives in two languages, and a remedy\n  in one of them is a half-measure that will read as a fix.\n- **STANDING LIMIT, so this entry is not overread as an incident cause:** none of these sites\n  explains the 08:03:15Z death. broker.rs:8102 would have been saved from firing by\n  `has_live_descendants` (the daemon had a live brain) — accidental protection, not deliberate —\n  and every claude-spt site enumerates `claude-spt.exe` while the dead process was `spt.exe`. The\n  census found a real hazard while looking for a different one. **Do not let this entry close the\n  incident.** The instrument at `C:\\Users\\decid\\.spt-watch\\daemon-watch.log` is what will answer\n  that, or fail to.\n- **Kin:** [[IR-79]] and [[IR-80]] (children outliving their cell; the leak family), the\n  [[RCA-FLEET-DAEMON-14444]] timeline, `servicehost.rs`'s own \"image path decides\" comment as the\n  in-tree statement of the rule, and the paired-exhibit method itself — a correct and an incorrect\n  site in one repo is stronger evidence about PROCESS than either site is about code.\n- **Ripe when:** the next touch of `spt-store/src/proc.rs` (for remedy 1) or of `xtask check`'s\n  gate family (for remedy 2). The adapter half is perri's, filed separately, and does not wait\n  on this.\n- **Size:** small for remedy 2, medium for remedy 1 (signature + every caller). The census that\n  justifies either is already written and does not need redoing.\n\n---\n\n#### ADAPTER-SIDE ARM: CLOSED (claude-spt, perri, 2026-09-07)\n\n**Status: closed in the consumer repo, test-only, does not close IR-81 here.**\n\n- **Commit `9c87372`** (spt-claude-code). Broad `tasklist | grep claude-spt | taskkill` replaced\n  with an **id-scoped wmic** call, **name-pinned so wmic cannot self-match**; the three\n  remembered-pid kills additionally got a **kill-time recheck**, covering the stale-identity face\n  as well as the unscoped-pattern face.\n- **Guard: `tests/ci-kill-scoping.sh`, traced as `REQ-HAZARD-CI-KILL-SCOPING`.** Gate green.\n  This is the check-shape arm (b) proposes for spt-core, already landed once — precedent, not\n  merely agreement.\n- **Scope: test/CI infrastructure only.** No product code changed. (doyle, 08:50Z.)\n- **`live-relay-int.sh:78` is retained as the historical RED exhibit** — the one genuinely\n  machine-wide kill found in the whole fleet census. It is the reason this hazard is written as a\n  hazard rather than a style note; do not quietly replace the exhibit with the fixed line.\n\n**Population lesson carried into arm (b)'s census.** I filed ONE site; perri confirmed **four**, and\nreports the idiom was already present in that repo **3x** before the filing. A filing that names one\nline under-counts its class by 3-4x in a single repo. **Census the ACT — any taskkill / pkill /\nwmic-delete reachable from a script root — never the literal string that led me to the first site.**\nState the walked roots in the check's own message, and give the gate a negative control that goes\nRED on a known-bad line before its green is trusted.\n\n**Still open here, unchanged:** arm (a), Rust-side identity pushed into `kill_pid_tree` / `kill_pid`\nso no Rust caller can express the unguarded kill (todlando, post-W2, cross-referenced with the\nbroker.rs:8102 board BUGFIX); and arm (b), the xtask script gate (mine, rides IR-37).\n\n---\n\n#### SCOPING ARM (a) — the product path has no intermediary; the fixture does\n*(hertz 2026-09-07, ruled by doyle 10:22Z off the IR-80 leak work.)*\n\n> **A pid is not an identity and a pid is not a tree. IR-80 needs CALLERS, not code.**\n> *(The register's sentence — doyle 10:23Z. Arm (a) fixes the identity half in\n> `kill_pid`/`kill_pid_tree`; the tree half needs no new machinery, because `kill_pid_tree` already\n> exists at proc.rs:430 with the defect stated in its own doc. This is why IR-79, IR-80 and IR-81\n> converge on one seam without collapsing into one finding.)*\n\nMeasured, not inferred: **`spawn_brain_child` (crates/spt-daemon/src/brainproc.rs:1224) does\n`Command::new(exe)`** — the real brain is spawned DIRECTLY, with no shell and no launcher between\nthe daemon and the process it supervises. So on the crashloop/rollback path a single-pid kill\n*does* reach the thing it aims at, and the \"orphaned grandchild\" mechanism found in the IR-80 leak\ncells is **a property of the TEST FIXTURE**, whose `long_child()` (brainproc.rs:1359) goes through\n`cmd /C` on Windows, not of the product.\n\n**What that scopes.** Arm (a) is NOT about the brain-supervision path and must not be sold as\nprotecting `REQ-HAZARD-BROKER-PROCESS-ISOLATION` (\"never two live brains\") — that invariant is not\nat risk here, and claiming it would be borrowing urgency this arm has not earned. Arm (a) stays\npointed at **the broker.rs:8102 reap, where the image is never read** — a kill aimed by pid alone\nat a process whose identity was never verified. That is the real unguarded form, and it is a\ndifferent failure (kill the wrong process) from the one IR-80 surfaced (fail to kill the right\none).\n\n**The two failures are different, which is why the drafts converge without collapsing.** Arm (a) is\n*kill the wrong process* (identity never read); IR-80 is *fail to kill the right one* (tree never\nwalked). The identity half is todlando's, post-W2. The tree half is already solved in-tree —\n`kill_pid_tree` at proc.rs:430, whose doc states the defect outright (\"a single-pid `kill_pid` leaves\nthe wrapper's harness children orphaned + running\") — so IR-80 ships callers, not machinery. See\n[[RIDER 4]] for the two test-side callers.\n\n### IR-82 — a daemon death leaves NO record of who died: autostart decides on a socket ping, says \"no daemon\", and the successor overwrites the only handle on the corpse\n\n- **Status:** RULED 2026-09-07 11:07Z (doyle), drafted by hertz 11:04Z on doyle's dispatch (11:03Z: *\"the autostart\n  death-cause item is an IR, not a board item — mint it IR-82 in your thin PR\"*). Register on main\n  ends at IR-78; 79/80/81 are drafts in the same PR. · **Origin:** the fleet-daemon death on\n  hfenduleam at 08:03:14.87Z ([[RCA-FLEET-DAEMON-14444]]) whose cause is **still UNNAMED after a day\n  of measurement** — and the reason it is unnamed is this entry. Filed as a defect in\n  OBSERVABILITY, not in the death.\n- **⚠ THIS IS NOT \"find the killer.\"** The killer hunt is the RCA and stays open there. This entry\n  is about the fact that a killer hunt had to be run at all from a cold start, with a watcher script\n  written by hand after the event, because the product recorded nothing about the transition at the\n  moment it noticed it.\n\n- **THE MEASUREMENT — all four facts read at source, no build (gate was live on both boxes).**\n\n  1. **The daemon writes its pid.** `crates/spt-daemon/src/daemon.rs:471` —\n     `let _ = std::fs::write(daemon_pid_path(), std::process::id().to_string());`, into\n     `<spt_home>/daemon.pid` (`crates/spt-daemon/src/endpoint.rs:81`). Unconditional overwrite, no\n     read-before-write, no rotation, no history.\n  2. **Autostart never looks at it.** `ensure_running_outcome`\n     (`crates/spt-daemon/src/daemon.rs:686-724`) decides on `is_running()`, which is\n     `seedmap::ping(&seed_socket_name()).is_ok()` (`daemon.rs:598-600`) — **a socket ping and\n     nothing else.** The decision consults no pid, no mtime, no prior state.\n  3. **The breadcrumb it emits carries no identity.** `daemon.rs:721` —\n     `DAEMON_AUTOSTART: no daemon and no standing operator stop — starting one`. Deliberately\n     \"always-on, ids-free\" per its own comment, because its job is to be COUNTED (the convoy\n     serialization observable that `daemon_stop_convoy_e2e` asserts at :178/:237). That design is\n     correct for what it was built for and is exactly why it answers nothing here.\n  4. **Then the successor destroys the evidence.** The new daemon reaches :471 and overwrites\n     `daemon.pid` with its own pid. The dead pid, and the file mtime that bracketed its life, are\n     gone — overwritten by the very event that should have recorded them.\n\n- **THE SHARP FORM — the file is read ONLY in the state where it can tell you nothing.** The only\n  two readers of `daemon_pid_path()` in the tree are `crates/spt/src/cli.rs:8581` and `:8754` (both inside `cmd_daemon_status`, :8573), and\n  **both are gated on `running`** (`if running { let pid = read(...) }`). So `daemon.pid` is consulted\n  exclusively when a daemon is alive — when its contents are guaranteed fresh and merely restate\n  what the ping already proved — and is ignored in the one state where its staleness is the only\n  evidence anyone has. Its doc comment (`endpoint.rs:82-85`) says *\"a stale pid here is harmless\n  because callers probe the socket, never this file.\"* **That is true for LIVENESS and false for\n  FORENSICS**, and the entry is that the codebase has only ever considered the first reading.\n\n- **WHAT IT COST, concretely, on 2026-09-07.** Daemon pid 14444 died at 08:03:14.87Z inside the ci\n  Windows unit leg's nextest LIST phase; successor 48232 cold-started at 08:03:20Z and\n  `DAEMON_RESTART_RESUME`d every session, orphaning live agents' monitors and readers and handing at\n  least one agent a stale brief. Neither peer ran a kill. To get ANY signal at all I had to hand-write\n  an external watcher (`C:\\Users\\decid\\.spt-watch\\watch-daemon.ps1`, 1s cadence, identity re-verified\n  by image path AND creation time every poll) **after** the death, which by construction cannot\n  observe the event it was written for. 6600+ polls later the successor is alive and the original\n  death is still uncharacterized. A product-side record of the transition would have cost bytes.\n\n- **WHY THIS IS NOT THE CONVOY BREADCRUMB'S JOB, and must not be bolted onto it.**\n  `DAEMON_AUTOSTART` is load-bearing as a COUNTABLE line: `daemon_stop_convoy_e2e` asserts *exactly\n  one* appears under a storm (:178) and counts N under a deliberate race (:237). Adding identity\n  fields to that line risks the count and buries a forensic record inside a line whose contract is\n  its cardinality. **The record belongs in its own line and its own artifact.**\n\n- **REMEDY — RULED 2026-09-07 11:07Z (doyle), APPROVED as proposed with two refinements. Small,\n  product-side, no wire change.** doyle re-derived the census independently at `f3c8495b` (one\n  writer `daemon.rs:471`, two readers `cli.rs:8581` + `:8754`, both inside `if running`) before\n  ruling — the falsifiable claim below has been checked, not taken.\n  1. **Read before you clobber.** At `daemon.rs:471`, read the existing `daemon.pid` and its mtime\n     BEFORE the write; if it holds a pid that is not ours, emit a distinct, greppable line naming\n     the predecessor pid and how long ago the file was last touched — e.g.\n     `DAEMON_SUCCEEDS_PID: prior=<pid> prior_pidfile_age_ms=<n> reason=<socket-ping-failed>`. The\n     value is that the successor is the only process in the system that is guaranteed to run at\n     exactly the moment the question becomes askable.\n  2. **Keep one generation.** Rename the existing `daemon.pid` to `daemon.pid.prev` instead of\n     overwriting it (best-effort, same directory, same failure posture as today's `let _ =`). One\n     generation is enough to answer \"which pid did I replace, and when did it last write?\" and costs\n     no rotation policy.\n  3. **REFINED BY THE RULING — the discriminator is a FIELD, not a second line.** I proposed a\n     separate \"what the ping saw\" record; doyle collapsed it: `prior=<pid|none>` already separates\n     the two incidents, because `none` **is** the fresh-home case. One line, one field, no second\n     breadcrumb to keep in sync.\n  4. **ADDED BY THE RULING — `alive=<bool>`, from a by-number liveness READ at write time.** With\n     the prior pid in hand, read whether that number is still live and put the answer on the line.\n     It splits the two incidents that otherwise look identical: **`alive` prior = two daemons racing\n     the seed bind** (the convoy case), **dead prior = the corpse** (the 14444 case). This is a\n     READ, not a kill — #285's identity-before-kill rule binds kills and is not weakened here; a\n     by-number read that informs a log line commits no action on the pid.\n  5. **UNIT, specified by the ruling:** seed a pidfile with a fake pid and an aged mtime, run the\n     write path, assert the emitted fields (`prior`, `age_ms`, `alive`) AND the `daemon.pid.prev`\n     bytes. The `.prev` bytes are part of the assertion, not an afterthought — the generation kept\n     is the half that survives the process.\n  6. **NOT proposed, and the ruling kept it out:** a liveness change. `is_running()` must stay the socket ping — this entry does\n     not argue the pidfile should become a liveness signal, which is the exact mistake\n     `endpoint.rs:82-85` was written to prevent. The pidfile stays advisory; it just stops being\n     silently destroyed.\n\n- **LANE — SPLIT BY THE RULING, and the two halves ship separately.** The **IR-82 ENTRY** (this\n  text) rides hertz's IR-37 thin PR alongside IR-79/80/81. The **PRODUCT REMEDY** rides **#285's\n  lane** (todlando, post-W2) because it is the same pid-identity gate: #285 makes a kill read an\n  identity, this makes a successor read the identity it is about to erase. One lane, one owner,\n  one review of the pid-identity question. Do not implement the remedy in the thin PR.\n\n- **Kin:** [[RCA-FLEET-DAEMON-14444]] (the open incident this serves — IR-82 does not close it and\n  must not be read as closing it), [[IR-81]] (a pid is not an identity — the same lesson from the\n  KILL side; here it is the RECORD side), [[IR-80]]/[[IR-79]] (processes outliving what should have\n  accounted for them). The through-line doyle named at 10:22Z holds: *a pid is not an identity and a\n  pid is not a tree* — and IR-82 adds that **a pid nobody wrote down is not evidence.**\n\n- **Falsifiable claim, so it can be checked rather than believed:** at `f3c8495b` the tree contains\n  exactly ONE writer of `daemon_pid_path()` (`daemon.rs:471`) and exactly TWO readers\n  (`cli.rs:8581`, `cli.rs:8754`), both inside a `running` gate. If a future reader appears in an\n  unguarded path, this entry's premise weakens and it should be re-measured, not re-asserted.\n\n### IR-83 — a two-host rig addressed over the tailnet cannot receive INBOUND on Windows, and the whole rig population had only ever run the admitted direction\n\n- **Status:** OPEN, minted by hertz 2026-09-07 11:41Z on doyle's dispatch (11:40Z). **Provenance: the\n  mechanism below is DOYLE'S measurement, not mine** — eight probe arms, each with sender, listener\n  and output file, recorded in `GATE-W2-272-CHECKLIST.md` rows 11:36Z–11:39Z. I am off cargo on both\n  boxes and have re-measured none of it; this entry is the register form of his finding plus the\n  structural reading it supports. Board face: **F18**. Register slot: IR-83 (79/80/81/82 are the\n  same thin PR).\n- **THE FINDING, in one line:** two-host rigs must address peers by **LAN**, never the tailnet.\n\n- **HALF ONE — the tailnet ACL is per-node and ONE-WAY.** `hfenduleam` admits 9 sources and\n  `kitsubito` is **not** among them; `kitsubito` admits `hfenduleam`. So a rig cell needing INBOUND\n  to the Windows box over `100.x` fails **at the receiver**, and it fails there **whatever the host\n  firewall says** — which is why a host-firewall investigation can be run to completion, come back\n  clean, and explain nothing.\n\n- **HALF TWO — Windows defaults `BlockInbound`, and a hash-named test exe has no rule.** Test\n  binaries are built with hash-suffixed names, so a rule written against the *program* is keyed to a\n  name that changes on the next build. The stale `spt_net-d037…` rule is the precedent already in\n  the tree: a rule that was correct once, is present, greps fine, and admits nothing. **The durable\n  form is PORT-scoped, not program-scoped:** ports `7480-7499`, `remoteip` = the peer's LAN address,\n  added by the operator.\n\n- **WHY IT SURFACED ONLY NOW, and this is the part that generalizes.** The W2 helper cell is the\n  **first cell in the entire rig population that ever needed `kitsubito -> hfenduleam` inbound.**\n  W1's four xbox cells and golden's old-twohost job are all `hfenduleam -> kitsubito` — the admitted\n  direction. So the population had a **direction monoculture**, and a one-way ACL is invisible to a\n  suite that only ever runs the admitted way. Every green in that population was consistent with the\n  ACL being wide open and equally consistent with it being one-way; the suite could not tell the\n  difference, and nobody had reason to ask. **A capability exercised in only one direction is not\n  covered, it is merely unexamined** — the same shape as an assertion that only ever sees the\n  passing arm.\n\n- **THE SECOND STRUCTURAL POINT — a rule keyed to a MUTABLE identity is the lane's own through-line.**\n  A per-hash program rule is an exception bound to an identity the build changes underneath it,\n  exactly as [[IR-81]] is about a kill bound to a pid the OS may reassign and IR-80 Amendment 1's ENV\n  READ face is about a read bound to a process identity `exec` can change. Port-scoping replaces a\n  mutable identity with a stable property. That is the same remedy shape as reading an image path\n  before a kill and reporting an environment in-band: **stop keying on the thing that moves.** I am\n  flagging the rhyme, not claiming a fourth face — this is infrastructure config, not a code path,\n  and the amendment's standing prediction is about pid-shaped questions.\n\n- **FALSIFIABLE CLAIM (doyle's, recorded verbatim as the entry's test):** with the rig on **LAN\n  addresses AND the port-scoped rule present**, the helper cell's owner raw carries `WEB_SERVE_FOR`;\n  with **either** missing, it carries none. Both arms matter — this is a conjunction, so a single\n  green with one of the two absent would refute it, and a red with both present would too.\n\n- **WHAT THIS ENTRY DOES NOT CLAIM.** It does not say the host firewall was ever misconfigured; the\n  ACL half fails at the receiver independently. It does not close F17 or explain the vacuous-green\n  run (that was the mid-flight script rewrite — different cause, different fix, and the two were\n  live in the same hour, which is precisely why each needed its own named mechanism rather than one\n  story). It proposes no product change: both halves are rig addressing and operator-added firewall\n  config.\n\n- **REMEDY.** (1) Rig-side: address peers by LAN in two-host rigs, and make the tailnet address\n  unreachable-by-construction rather than merely unused, so a future rig cannot quietly pick it up.\n  (2) Operator-side: the port-scoped inbound rule (`7480-7499`, `remoteip` = peer LAN), replacing\n  per-hash program rules; the stale `spt_net-d037…` rule should be removed in the same pass so it\n  stops reading as coverage. (3) Population-side — **RULED 11:42Z (doyle), with a precision that\n  changes the shape:** this is NOT a new cell. **The W2 helper cell IS the first reverse-direction\n  cell**, and on LAN it exercises `kitsubito -> hfenduleam` inbound for real once the rule exists.\n  The remedy is therefore to **keep at least one reverse cell in the xbox battery permanently and\n  NAME it as the direction witness**, so its role is a stated property rather than an accident of\n  what W2 happened to need. A suite that only runs one way cannot discover the next one-way ACL\n  either, and the way that recurs is not \"nobody wrote the cell\" but \"the cell that had it stopped\n  being run.\"\n\n  **The hazard that follows from naming it, stated here so the naming is not decorative:** a witness\n  cell that is SKIPPED stops being a witness while still reporting green — the exact confusion this\n  lane already paid for, where a must-skip `role_b` PASS was indistinguishable from four cells that\n  no-opped. So the direction witness needs its skip to be loud: if it is filtered out, phase-reclassed,\n  or short-circuits on a missing precondition, that must read as ABSENT COVERAGE and not as a pass.\n  Whoever names it owns that half too. **Concrete enforcement, doyle-ruled 11:44Z and written up\n  as the RIDER 5 ADDENDUM:** the xbox driver's HELPER WITNESS verdict line already refuses a\n  `0.0x s` helper PASS and a `b.raw` without `WEB_SERVE_FOR outcome=registered`; it must ALSO\n  print `NOT-A-WITNESS` when the cell is absent from the LIST leg. Those first two are\n  *ran-but-vacuous*; absence is *never-ran*, and a verdict built only from the first two passes\n  it by omission — every refusal condition evaluates against output that does not exist, finds\n  nothing to object to, and falls through to green.\n\n- **GATING CLAUSE — added 2026-09-07 12:56Z on doyle's dispatch (gate reshape, same minute).** An\n  inbound-to-Windows cell in a two-host rig is **gated on the port-scoped rule being present**, and\n  without it the cell must **SKIP LOUDLY**: it may not run, may not report PASS, and may not be\n  silently filtered — its absence must render as ABSENT COVERAGE in the verdict, on the RIDER 5\n  ADDENDUM's `NOT-A-WITNESS:NEVER-RAN` face. The precondition is machine-readable, so the driver\n  reads `netsh` at start and the gate is a measured fact rather than a remembered one; a cell whose\n  precondition is unmet and which therefore emits nothing is exactly the case a verdict assembled\n  only from ran-but-vacuous refusals passes by omission. **This clause is what stops the rule's\n  ABSENCE from reading as the rig's health.**\n\n  **How the reshaped W2 F17 gate applies it (doyle 12:56Z, recorded, not re-measured by me — I am\n  still off cargo on both boxes).** With the rule absent 75+ minutes and no operator activity, and\n  golden carrying no cross-box `twohost_web`, the shortfall is a **rig blocker, not a golden one**.\n  So the HELPER WITNESS was reshaped to the **ONE-BOX pair on BOTH OSes** — doyle's gate tree on\n  Windows, a kitsubito clone at the tip on Linux with the rig shipped as the frozen copy — on the\n  basis that the 03:31Z one-box run at `f3c8495b` reproduced F17 end to end (A `outcome=unanswered`,\n  B `DISPATCH:4:Unknown`), i.e. the one-box pair drives the real dispatcher on both roles.\n  Mutation D must turn the classify unit cell red **and** the one-box helper cell red\n  (owner `family=Unknown`>0, `registered`=0) while deny/fetch stay green; revert dirty 0. The\n  cross-box pair still runs as the A->B regression (deny/fetch must PASS), and while the rule is\n  absent its helper/range TIMEOUTs are classified **F18-INFRA** — becoming a witness automatically\n  if the rule lands before the run, because the driver reads `netsh` at start.\n  **The cross-box helper witness therefore stays an OPEN rider on the operator's rule, not a land\n  blocker.** Note the shape this preserves: the reshape moves the witness to a pair that CAN run,\n  and leaves the direction it cannot exercise named and open — it does not let the one-box green\n  stand in for the direction coverage that is still missing. A one-box pair proves the dispatcher;\n  it cannot prove an inbound ACL, and nothing here claims it does.\n\n  **PROBE RESOLUTION — doyle 12:59Z, ADOPTED INTO THIS GATE (not deferred to the rider).** The\n  precondition read is now THREE-VALUE in `gate-w2-f17.sh`: `Rule Name` in stdout -> PRESENT,\n  `No rules match` -> ABSENT, empty stdout or anything else -> PROBE-FAILED. **PROBE-FAILED\n  classifies the cross-box helper/range as `UNCLASSIFIED: this run cannot tell INFRA from a real\n  red` — never F18-INFRA** — and xbox-D's skip line names the state. The raw probe (exit code +\n  first 3 lines) is printed into the driver log, so the classification is auditable after the fact\n  rather than inferred from what got bucketed. Exercised standalone on all three arms: real\n  `netsh` = exit 1 + `No rules match` -> ABSENT; forced bad args -> PROBE-FAILED; empty stdout ->\n  PROBE-FAILED.\n\n  **Recorded because it corrects the asker (me), not the implementer:** I proposed the three-value\n  shape AND, in the same message, proposed discriminating on the exit code. doyle's standalone\n  exercise measured `netsh` exiting **1 on a clean ABSENT**, so an exit-code discriminator would\n  have classified every legitimately-absent rule as an instrument fault — turning the run's most\n  common honest state into PROBE-FAILED and, with it, `UNCLASSIFIED`. The discriminator that landed\n  is STDOUT CONTENT. The general form belongs in the entry because it is the reason the third arm\n  needed measuring at all: **a CLI's exit code is a claim about the QUERY, not about the ANSWER**,\n  and an empty-but-correct result is reported non-zero by a great many tools. A third value added\n  to a probe needs its own evidence, obtained by making all three arms fire on purpose — which is\n  this lane's standing rule that a tool whose success path has never been made to fail on purpose\n  is untested, applied to a tool's FAILURE path instead.\n\n- **Kin:** [[IR-81]] and IR-80 Amendment 1 (keying on a mutable identity), the F17 riders (a witness\n  that never executed the direction it certifies).\n\n\n[Showing lines 4144-4663 of 5782. Use :4664 to continue]"}],"details":{"truncation":{"content":"Machine-generated from the eight ci unit logs, not transcribed (a hand-typed 12x8 matrix is where\r\ntranscription errors live). `X` = reported LEAK at that sha on that box.\r\n\r\n| cell | W ff4b405d | W e3bd53d4 | W 401a19ad | W f3c8495b | L ff4b405d | L e3bd53d4 | L 401a19ad | L f3c8495b |\r\n|---|---|---|---|---|---|---|---|---|\r\n| `spt-daemon brainproc::tests::clear_before_spawn_defeats_exact_generation_stale_file` | X | X | X | X | . | . | . | . |\r\n| `spt-daemon brainproc::tests::ready_but_old_gen_never_drains_does_not_promote_rolls_back` | X | X | X | X | . | . | . | . |\r\n| `spt-daemon brainproc::tests::stale_generation_minus_one_ready_never_promotes` | X | X | . | X | . | . | . | . |\r\n| `spt-daemon brainproc::tests::trial_kills_alive_never_ready_candidate_before_rollback` | X | X | X | X | . | . | . | . |\r\n| `spt-daemon broker::tests::windows_session_is_zombie_sees_a_handle_held_corpse_as_dead` | X | . | . | X | . | . | . | . |\r\n| `spt-daemon livehost::tests::legacy_psyche_sweep_guard_is_id_specific_and_fail_safe` | . | . | . | . | X | X | X | . |\r\n| `spt-daemon shellhost::tests::kill_shell_at_still_kills_a_matching_pair` | . | . | . | X | . | . | . | . |\r\n| `spt-daemon shellwake::tests::kill_waker_at_still_kills_a_matching_pair` | . | X | X | X | . | . | . | . |\r\n| `spt-live digest::tests::extractor_timeout_errors` | X | X | . | X | . | . | . | . |\r\n| `spt-live history::tests::fetcher_timeout_errors` | X | X | . | . | . | . | . | . |\r\n| `spt-runtime runtime::tests::bounded_run_kills_on_timeout` | X | X | X | X | . | . | . | . |\r\n| `spt-store proc::tests::process_cmdline_reads_a_live_arg_marker` | . | . | . | . | X | X | X | X |\r\n| **leaky count** | 8 | 8 | 5 | 9 | 2 | 2 | 2 | 1 |\r\n\r\nUnion = 12 cells across 4 shas x 2 OSes. Present at EVERY Windows sha: 4. Present at every Linux sha: 1.\r\n\r\n#### Three readings, in increasing order of what they support\r\n\r\n**1. The churn is total and it is the whole point.** Windows counts run 8, 8, 5, 9 — the HIGHEST\r\nvalue is at `f3c8495b`, the tip carrying every fix F1-F16. Only **4 of 12** cells are present at\r\nevery Windows sha; only **1 of 2** at every Linux sha. Read as a quality signal the series says W2\r\nmade leaking worse, which is exactly as wrong as my retracted \"8 -> 5, favourable\" read and wrong\r\nfor the same reason. **A leaky count is not a signal in either direction.**\r\n\r\n**2. NEW, and I had not said it before building this table: the two OS sets are DISJOINT.** Ten\r\ncells leak only on Windows, two only on Linux, and **not one cell leaks on both**. Windows carries\r\n8-9 leaky cells per run against Linux's 1-2. So this is not one flaky population sampled twice —\r\nit is two populations with no overlap, and the Windows one is roughly five times larger. Any\r\nexplanation that treats \"leaky tests\" as a single phenomenon has to account for a clean partition\r\nby OS.\r\n\r\n**This is an OPEN QUESTION and the draft does not answer it. I do not have that explanation yet.**\r\nRecorded deliberately without a candidate cause: the partition is a measurement, and the temptation\r\nto pair a striking measurement with a plausible story is how the \"8 -> 5 is favourable\" reading got\r\ninto the record in the first place. Whoever takes this should arrive at a cause by reading, not by\r\ninheriting one from me.\r\n\r\n**SCOPED CAUSE, IN SOURCE, FOR ONE FAMILY ONLY (doyle ruled 10:22Z: source beats story; a source\r\ncause covering one family is a measurement and is filed as one).** The brainproc family leaks on\r\nWindows and not Linux because *its own fixture is asymmetric*: `long_child()` (brainproc.rs:1359)\r\nspawns `Command::new(\"cmd\").args([\"/C\",\"ping\",\"-n\",\"30\",\"127.0.0.1\"])` on Windows but\r\n`Command::new(\"sleep\").arg(\"30\")` on Unix — a shell wrapper on one box, a bare process on the other.\r\nThe Windows candidate the supervisor kills is `cmd`; the process burning 29 seconds is its child.\r\nThat is two lines of source, not an inference from the symptom. **And it is NOT the whole partition:**\r\n`process_cmdline_reads_a_live_arg_marker` uses a shell on BOTH arms (`sh -c \"sleep 30; : marker\"` /\r\n`cmd /C \"ping … & rem marker\"`) yet leaks on **Linux only** — the shell mechanism predicts it should\r\nleak on both boxes and it does not. So one family has a cause I can point at in the source, the\r\npartition as a whole remains OPEN, and the counterexample stands in this paragraph rather than a\r\nfootnote so no one carries the cause further than it goes.\r\n\r\n**THE PRODUCT PATH HAS NO INTERMEDIARY; THE FIXTURE DOES.** I chased the obvious escalation — if the\r\nreal supervisor also killed a shell wrapper, then \"never two live brains\"\r\n(REQ-HAZARD-BROKER-PROCESS-ISOLATION, the invariant this very cell guards) could be violated on\r\nWindows in production while the test stayed green. It cannot: `spawn_brain_child` (brainproc.rs:1224)\r\ndoes `Command::new(exe)` — the brain is spawned DIRECTLY, no shell, no grandchild, so a single-pid\r\nkill reaches it. **This is a test-fixture artifact, not a product defect**, and the fixture's shell\r\nis a Windows-only convenience for \"a process that blocks ~30s\" that introduced a layer the real path\r\ndoes not have. The negative is the useful half: it keeps the crashloop invariant out of IR-81 (a).\r\n\r\n**Why the cell passed review for as long as it did.** It asserts `pid != 0 && !pid_alive(pid)` before\r\nrollback, and that assertion is TRUE — `cmd` really is dead. The process still doing work is the one\r\nit never looks at. The leak and the green are not in tension; they are the same fact from two ends.\r\n**An assertion over a pid cannot see a tree.**\r\n\r\n**3. The invariant holds at 12 of 12, and it survived the population being shuffled three times.**\r\nEvery union member spawns a child process and then kills it, lets it time out, or inspects its\r\ncorpse — `trial_kills_alive`, `kill_shell_at`, `kill_waker_at`, `bounded_run_kills_on_timeout`,\r\n`extractor_timeout_errors`, `fetcher_timeout_errors`, `windows_session_is_zombie_..._corpse_as_dead`,\r\n`legacy_psyche_sweep_guard_...`, `process_cmdline_reads_a_live_arg_marker`, and the three brainproc\r\nspawn/promote/rollback cells. Membership churns freely across four shas and two OSes; the KIND of\r\ncell has not varied once. **This is the IR-80 headline** and it is better supported now than when it\r\nrested on a stable-looking five-cell cluster, precisely because the population underneath it has\r\nbeen reshuffled and the invariant did not move.\r\n\r\n#### A MECHANISM, read out of the source of the two Linux cells — calibrated, not generalized\r\n`process_cmdline_reads_a_live_arg_marker` spawns **`sh -c \"sleep 30; : marker\"`**, and the test's\r\nown comment says the trailing `; :` is deliberate — it keeps the shell RESIDENT so its\r\n`/proc/<pid>/cmdline` still carries the marker instead of being tail-exec-replaced by `sleep`. The\r\nteardown is `child.kill()` then `child.wait()`. **But `child` is the SHELL, and `sleep 30` is the\r\nshell's own child.** Killing the shell orphans the sleeper, which outlives the test by up to 30\r\nseconds — which is precisely what nextest reports as a LEAK. The Windows arm has the same shape:\r\n`cmd /C \"ping -n 30 127.0.0.1 >NUL & rem marker\"`, where `cmd` forks `ping`.\r\nSo the very construct that makes the test work (a resident shell, so the cmdline stays readable) is\r\nwhat guarantees a grandchild that a single-pid kill cannot reach.\r\n\r\n**What is verified and what is not, stated separately because the difference decides who owns this.**\r\nVERIFIED by reading source: this shape in BOTH Linux-only cells. CONSISTENT but not proven: the\r\nWindows family kills the same way — `kill_waker_at_still_kills_a_matching_pair` tears down with\r\n`kill_shell_pid(ours.id())`, a single-pid kill — so the mechanism is available to it, but I have not\r\nread every spawn helper. UNVERIFIED: the brainproc, broker and spt-live cells; those spawn real\r\nbrains and time out extractors, and may leak for unrelated reasons.\r\n\r\n**Why this matters beyond IR-80:** a single-pid kill that cannot reach a grandchild is exactly\r\n[[ir81]] arm (a) — identity and tree-awareness pushed into `kill_pid_tree`/`kill_pid` so no caller\r\ncan express the unreachable kill. If the mechanism above generalizes, IR-79 (rigs leaking daemons\r\non a failing assert), IR-80 (this) and IR-81 (kill scoping) are not three findings that share a\r\nseam, they are three FACES of one defect: **the codebase kills pids, and the things it needs dead\r\nare trees.** That is a claim worth testing, not asserting — and doyle's one-cell mechanism probe\r\nis still the right instrument, now with a sharper question: after the kill, is the surviving\r\nprocess the CHILD or the GRANDCHILD?\r\n\r\n---\r\n\r\n#### AMENDMENT 1 — \"a pid is not a tree\" has THREE faces, and only one of them is a kill\r\n\r\n*(hertz 2026-09-07, ruled by doyle 11:17Z: write this as an IR-80 amendment naming the three faces\r\nrather than three separate entries, so a reader hunting any one face lands on all three.)*\r\n\r\nThe register sentence this lane has been running on is doyle's: **a pid is not an identity and a pid\r\nis not a tree.** IR-80 and IR-81 were both filed against the KILL side, which made the sentence read\r\nlike a rule about killing. It is not. It is a rule about **which process you are talking about**, and\r\nkilling is only the face we happened to find first. Three faces are now measured, each found by a\r\ndifferent agent working a different problem:\r\n\r\n| face | the operation | what going one level too high produces | measured |\r\n|---|---|---|---|\r\n| **KILL** | `kill_pid(pid)` on a wrapper | the wrapper dies, the grandchild keeps working — the leak | IR-80's 12-cell union; `proc.rs:430`'s own doc states it |\r\n| **IDENTITY** | `kill_pid_tree(remembered_pid)` with no image read | you kill *a* process with that number, not the one you meant | IR-81 / #285, `broker.rs:8102` vs `servicehost.rs:651` |\r\n| **ENV READ** | `psutil.Process(child.pid).environ()` | the wrapper's env certifies a launch the battery would have failed | hertz 2026-09-07, self-test of `.github/bench/launch-battery.py` |\r\n\r\n**The third face, in full, because it is the newest and the least intuitive.** Reading back the\r\nenvironment of the process you spawned is the standard remedy for \"did my scrub/export actually\r\nland\" — it is what this project's own memory banked after the W0 perch-identity leak. It is\r\ninsufficient, and it fails in the flattering direction. A wrapper (`env VAR=x`, `cargo`, `nextest`,\r\n`bash -lc`) modifies the environment it hands the process **below** it, while its own `environ()`\r\nstill shows exactly what you passed in. So the read-back agrees with your intent, prints PROVEN, and\r\nsays nothing whatsoever about the process under test. Measured: the first version of\r\n`launch-battery.py` passed BOTH deliberately-negative tests. The corrected version walks descendants\r\nand, in the refusal, prints the wrapper as CLEAN beside the grandchild as VIOLATOR — that contrast\r\nis the face made visible in one line of output.\r\n\r\n**Why this belongs in IR-80 rather than in a new entry.** All three are the same error committed at\r\nthe same seam: an operation is aimed at a pid when the thing it needs to reach is a tree (or a\r\nspecific member of one). The remedies rhyme — walk the tree, read the identity, report the scope you\r\nactually covered — and a reader who finds any one face is one paragraph away from the other two.\r\nFiling them separately would have hidden that, which is the concrete cost doyle's ruling avoids.\r\n\r\n**What this amendment does NOT claim.** It does not widen IR-80's population: the 12-cell union\r\ntable and its Windows/Linux partition are unchanged, and the env face is not a test leak. It does\r\nnot add a remedy owner — the ENV face's fix is a tool (`.github/bench/launch-battery.py`), not product code, and the KILL and\r\nIDENTITY faces keep the owners they already have (#285 / todlando post-W2). It is a naming, and its\r\nwhole value is that the next instance of this error gets recognized as an instance instead of being\r\nfiled fresh.\r\n\r\n**Standing prediction, so this is falsifiable rather than tidy:** a fourth face exists wherever the\r\ncodebase asks a question *of* a pid that is really a question *about* a tree. The candidates I would\r\nlook at first are (a) liveness — `process_exists(pid)` answering \"is the work still running\" when\r\nthe work is a grandchild, and (b) resource attribution — reading a pid's handles/memory to decide\r\nwhether a lane is finished. Neither is measured; both are named so that finding one counts as\r\nconfirmation and finding none over the next few incidents counts against the generalization.\r\n\r\n### IR-81 — a process kill can be written scoped or machine-wide, and nothing makes the scoped form the only reachable one: both codebases carry the right pattern beside the wrong one\r\n\r\n- **Status:** OPEN, drafted by hertz 2026-09-07 08:38Z on doyle's dispatch (08:36Z), from the\r\n  fleet-daemon death on hfenduleam at 08:03:15Z ([[RCA-FLEET-DAEMON-14444]], cause still UNNAMED).\r\n  Census body: `docs/PID-KILL-CENSUS.md`. · **Origin:** doyle asked which sites kill a REMEMBERED\r\n  pid without re-verifying identity AT KILL TIME. The census answered that, and then answered a\r\n  better question nobody asked: **why the unguarded sites exist at all when the guarded ones sit\r\n  feet away.**\r\n- **⚠ THIS ENTRY IS NOT \"FIX THESE TWO SITES.\"** Both individual fixes are small and are dispatched\r\n  elsewhere (broker.rs:8102 → todlando's lane post-W2; live-relay-int.sh:78 → filed to perri). This\r\n  entry is about the thing that PRODUCED them and will produce the next one: the scoped form and the\r\n  machine-wide form are equally easy to write, equally plausible on review, and only one of them is\r\n  correct on a shared box.\r\n- **THE PAIRED EXHIBITS — same repo, same hand, feet apart.**\r\n\r\n  | | correct, and it says why | incorrect |\r\n  |---|---|---|\r\n  | **spt-core** | `spt-daemon/src/servicehost.rs:651` — `provably_gone` first, then `exe_path(pid)` compared to the parked image via `same_image`, then a FRESH post-kill read. Its comment IS the rule: *\"The pid is live. WHO is it? The image path decides — never the number.\"* | `spt-daemon/src/broker.rs:8102` — kills `spid`, a pid REMEMBERED off the session record, through `kill_pid_tree`. `zombie_verdict` consults liveness BY NUMBER (`process_exists`/`is_process_alive`), `adapter_labeled` (a property of the RECORD, not the live process), descendants and grace. **The live process's image is never read.** |\r\n  | **spt-claude-code** | `ci/launcher/bind-int.sh:50` — `wmic process where \"name='claude-spt.exe' and commandline like '%$ID%'\"`, scoped to this run's unique id, comment *\"never wall-a's\"*. Also `multi-subnet-bringup-int.sh:117` ($C3_ID) and `wake-survival-int.sh:64` (`-match '$PROBE'`). | `ci/psyche/live-relay-int.sh:78` — `for p in $(tasklist \\| grep -i claude-spt \\| awk '{print $2}'); do taskkill //PID \"$p\" //T //F; done` — **every** `claude-spt.exe` on the box, tree-force, no run-scoping. Comment: *\"by marker pid then name.\"* |\r\n\r\n  **The knowledge is not missing in either codebase. It is present, written down, and adjacent.**\r\n  Three correct sites to one wrong one in the adapter; a rule-stating comment in core. What is\r\n  missing is any mechanism that makes the wrong spelling hard to reach.\r\n- **Why \"just fix the sites\" is the wrong remedy:** it has already been tried implicitly — someone\r\n  wrote the scoped form three times, which is what a team looks like when it knows the rule and\r\n  still ships the exception. A fourth correct site does not prevent a fifth incorrect one. The\r\n  remedy has to change what is REACHABLE, not what is written.\r\n- **REMEDY — RULED 2026-09-07 08:40Z (doyle): (a) AND (b), not a choice between them. Two owners,\r\n  two lanes, and they cover different halves of the hazard.**\r\n  1. **(a) PRODUCT — push the identity requirement into the primitive.** `spt_store::proc::kill_pid_tree`\r\n     / `kill_pid` take an expected identity (image path, or a `same_image` closure) and refuse\r\n     without it, so a caller **cannot express** the unguarded kill; `servicehost.rs:651` stops being\r\n     the exception among callers and becomes the shape of all of them. **Owner: todlando, post-W2.**\r\n     ⇄ **This IS the fix shape of the `broker.rs:8102` board BUGFIX — that item and this entry\r\n     cross-reference each other; neither is complete alone.** Reaches Rust callers only.\r\n  2. **(b) GATE — `xtask check` refuses the unscoped spelling in CI scripts.** A `tasklist` /\r\n     `Get-Process` enumeration piped into a kill, or a bare `taskkill` with no\r\n     `commandline like` / `-match` scope in the same block, is a build failure. **Owner: hertz,\r\n     rides the IR-37 thin PR after W2 lands.** This is the half remedy (a) can NEVER reach — the\r\n     unguarded adapter site is a shell script, and no Rust signature constrains a shell script.\r\n  3. **(c) Fix the two sites and stop.** Recorded as CONSIDERED AND LOSING, not omitted: it has\r\n     already been tried implicitly — the adapter's author wrote the scoped form three times and\r\n     shipped the exception anyway — so a fourth correct site does not prevent a fifth wrong one.\r\n     It leaves the next instance free to appear.\r\n  **The (a)/(b) split is the entry's real content:** the hazard lives in two languages, and a remedy\r\n  in one of them is a half-measure that will read as a fix.\r\n- **STANDING LIMIT, so this entry is not overread as an incident cause:** none of these sites\r\n  explains the 08:03:15Z death. broker.rs:8102 would have been saved from firing by\r\n  `has_live_descendants` (the daemon had a live brain) — accidental protection, not deliberate —\r\n  and every claude-spt site enumerates `claude-spt.exe` while the dead process was `spt.exe`. The\r\n  census found a real hazard while looking for a different one. **Do not let this entry close the\r\n  incident.** The instrument at `C:\\Users\\decid\\.spt-watch\\daemon-watch.log` is what will answer\r\n  that, or fail to.\r\n- **Kin:** [[IR-79]] and [[IR-80]] (children outliving their cell; the leak family), the\r\n  [[RCA-FLEET-DAEMON-14444]] timeline, `servicehost.rs`'s own \"image path decides\" comment as the\r\n  in-tree statement of the rule, and the paired-exhibit method itself — a correct and an incorrect\r\n  site in one repo is stronger evidence about PROCESS than either site is about code.\r\n- **Ripe when:** the next touch of `spt-store/src/proc.rs` (for remedy 1) or of `xtask check`'s\r\n  gate family (for remedy 2). The adapter half is perri's, filed separately, and does not wait\r\n  on this.\r\n- **Size:** small for remedy 2, medium for remedy 1 (signature + every caller). The census that\r\n  justifies either is already written and does not need redoing.\r\n\r\n---\r\n\r\n#### ADAPTER-SIDE ARM: CLOSED (claude-spt, perri, 2026-09-07)\r\n\r\n**Status: closed in the consumer repo, test-only, does not close IR-81 here.**\r\n\r\n- **Commit `9c87372`** (spt-claude-code). Broad `tasklist | grep claude-spt | taskkill` replaced\r\n  with an **id-scoped wmic** call, **name-pinned so wmic cannot self-match**; the three\r\n  remembered-pid kills additionally got a **kill-time recheck**, covering the stale-identity face\r\n  as well as the unscoped-pattern face.\r\n- **Guard: `tests/ci-kill-scoping.sh`, traced as `REQ-HAZARD-CI-KILL-SCOPING`.** Gate green.\r\n  This is the check-shape arm (b) proposes for spt-core, already landed once — precedent, not\r\n  merely agreement.\r\n- **Scope: test/CI infrastructure only.** No product code changed. (doyle, 08:50Z.)\r\n- **`live-relay-int.sh:78` is retained as the historical RED exhibit** — the one genuinely\r\n  machine-wide kill found in the whole fleet census. It is the reason this hazard is written as a\r\n  hazard rather than a style note; do not quietly replace the exhibit with the fixed line.\r\n\r\n**Population lesson carried into arm (b)'s census.** I filed ONE site; perri confirmed **four**, and\r\nreports the idiom was already present in that repo **3x** before the filing. A filing that names one\r\nline under-counts its class by 3-4x in a single repo. **Census the ACT — any taskkill / pkill /\r\nwmic-delete reachable from a script root — never the literal string that led me to the first site.**\r\nState the walked roots in the check's own message, and give the gate a negative control that goes\r\nRED on a known-bad line before its green is trusted.\r\n\r\n**Still open here, unchanged:** arm (a), Rust-side identity pushed into `kill_pid_tree` / `kill_pid`\r\nso no Rust caller can express the unguarded kill (todlando, post-W2, cross-referenced with the\r\nbroker.rs:8102 board BUGFIX); and arm (b), the xtask script gate (mine, rides IR-37).\r\n\r\n---\r\n\r\n#### SCOPING ARM (a) — the product path has no intermediary; the fixture does\r\n*(hertz 2026-09-07, ruled by doyle 10:22Z off the IR-80 leak work.)*\r\n\r\n> **A pid is not an identity and a pid is not a tree. IR-80 needs CALLERS, not code.**\r\n> *(The register's sentence — doyle 10:23Z. Arm (a) fixes the identity half in\r\n> `kill_pid`/`kill_pid_tree`; the tree half needs no new machinery, because `kill_pid_tree` already\r\n> exists at proc.rs:430 with the defect stated in its own doc. This is why IR-79, IR-80 and IR-81\r\n> converge on one seam without collapsing into one finding.)*\r\n\r\nMeasured, not inferred: **`spawn_brain_child` (crates/spt-daemon/src/brainproc.rs:1224) does\r\n`Command::new(exe)`** — the real brain is spawned DIRECTLY, with no shell and no launcher between\r\nthe daemon and the process it supervises. So on the crashloop/rollback path a single-pid kill\r\n*does* reach the thing it aims at, and the \"orphaned grandchild\" mechanism found in the IR-80 leak\r\ncells is **a property of the TEST FIXTURE**, whose `long_child()` (brainproc.rs:1359) goes through\r\n`cmd /C` on Windows, not of the product.\r\n\r\n**What that scopes.** Arm (a) is NOT about the brain-supervision path and must not be sold as\r\nprotecting `REQ-HAZARD-BROKER-PROCESS-ISOLATION` (\"never two live brains\") — that invariant is not\r\nat risk here, and claiming it would be borrowing urgency this arm has not earned. Arm (a) stays\r\npointed at **the broker.rs:8102 reap, where the image is never read** — a kill aimed by pid alone\r\nat a process whose identity was never verified. That is the real unguarded form, and it is a\r\ndifferent failure (kill the wrong process) from the one IR-80 surfaced (fail to kill the right\r\none).\r\n\r\n**The two failures are different, which is why the drafts converge without collapsing.** Arm (a) is\r\n*kill the wrong process* (identity never read); IR-80 is *fail to kill the right one* (tree never\r\nwalked). The identity half is todlando's, post-W2. The tree half is already solved in-tree —\r\n`kill_pid_tree` at proc.rs:430, whose doc states the defect outright (\"a single-pid `kill_pid` leaves\r\nthe wrapper's harness children orphaned + running\") — so IR-80 ships callers, not machinery. See\r\n[[RIDER 4]] for the two test-side callers.\r\n\r\n### IR-82 — a daemon death leaves NO record of who died: autostart decides on a socket ping, says \"no daemon\", and the successor overwrites the only handle on the corpse\r\n\r\n- **Status:** RULED 2026-09-07 11:07Z (doyle), drafted by hertz 11:04Z on doyle's dispatch (11:03Z: *\"the autostart\r\n  death-cause item is an IR, not a board item — mint it IR-82 in your thin PR\"*). Register on main\r\n  ends at IR-78; 79/80/81 are drafts in the same PR. · **Origin:** the fleet-daemon death on\r\n  hfenduleam at 08:03:14.87Z ([[RCA-FLEET-DAEMON-14444]]) whose cause is **still UNNAMED after a day\r\n  of measurement** — and the reason it is unnamed is this entry. Filed as a defect in\r\n  OBSERVABILITY, not in the death.\r\n- **⚠ THIS IS NOT \"find the killer.\"** The killer hunt is the RCA and stays open there. This entry\r\n  is about the fact that a killer hunt had to be run at all from a cold start, with a watcher script\r\n  written by hand after the event, because the product recorded nothing about the transition at the\r\n  moment it noticed it.\r\n\r\n- **THE MEASUREMENT — all four facts read at source, no build (gate was live on both boxes).**\r\n\r\n  1. **The daemon writes its pid.** `crates/spt-daemon/src/daemon.rs:471` —\r\n     `let _ = std::fs::write(daemon_pid_path(), std::process::id().to_string());`, into\r\n     `<spt_home>/daemon.pid` (`crates/spt-daemon/src/endpoint.rs:81`). Unconditional overwrite, no\r\n     read-before-write, no rotation, no history.\r\n  2. **Autostart never looks at it.** `ensure_running_outcome`\r\n     (`crates/spt-daemon/src/daemon.rs:686-724`) decides on `is_running()`, which is\r\n     `seedmap::ping(&seed_socket_name()).is_ok()` (`daemon.rs:598-600`) — **a socket ping and\r\n     nothing else.** The decision consults no pid, no mtime, no prior state.\r\n  3. **The breadcrumb it emits carries no identity.** `daemon.rs:721` —\r\n     `DAEMON_AUTOSTART: no daemon and no standing operator stop — starting one`. Deliberately\r\n     \"always-on, ids-free\" per its own comment, because its job is to be COUNTED (the convoy\r\n     serialization observable that `daemon_stop_convoy_e2e` asserts at :178/:237). That design is\r\n     correct for what it was built for and is exactly why it answers nothing here.\r\n  4. **Then the successor destroys the evidence.** The new daemon reaches :471 and overwrites\r\n     `daemon.pid` with its own pid. The dead pid, and the file mtime that bracketed its life, are\r\n     gone — overwritten by the very event that should have recorded them.\r\n\r\n- **THE SHARP FORM — the file is read ONLY in the state where it can tell you nothing.** The only\r\n  two readers of `daemon_pid_path()` in the tree are `crates/spt/src/cli.rs:8581` and `:8754` (both inside `cmd_daemon_status`, :8573), and\r\n  **both are gated on `running`** (`if running { let pid = read(...) }`). So `daemon.pid` is consulted\r\n  exclusively when a daemon is alive — when its contents are guaranteed fresh and merely restate\r\n  what the ping already proved — and is ignored in the one state where its staleness is the only\r\n  evidence anyone has. Its doc comment (`endpoint.rs:82-85`) says *\"a stale pid here is harmless\r\n  because callers probe the socket, never this file.\"* **That is true for LIVENESS and false for\r\n  FORENSICS**, and the entry is that the codebase has only ever considered the first reading.\r\n\r\n- **WHAT IT COST, concretely, on 2026-09-07.** Daemon pid 14444 died at 08:03:14.87Z inside the ci\r\n  Windows unit leg's nextest LIST phase; successor 48232 cold-started at 08:03:20Z and\r\n  `DAEMON_RESTART_RESUME`d every session, orphaning live agents' monitors and readers and handing at\r\n  least one agent a stale brief. Neither peer ran a kill. To get ANY signal at all I had to hand-write\r\n  an external watcher (`C:\\Users\\decid\\.spt-watch\\watch-daemon.ps1`, 1s cadence, identity re-verified\r\n  by image path AND creation time every poll) **after** the death, which by construction cannot\r\n  observe the event it was written for. 6600+ polls later the successor is alive and the original\r\n  death is still uncharacterized. A product-side record of the transition would have cost bytes.\r\n\r\n- **WHY THIS IS NOT THE CONVOY BREADCRUMB'S JOB, and must not be bolted onto it.**\r\n  `DAEMON_AUTOSTART` is load-bearing as a COUNTABLE line: `daemon_stop_convoy_e2e` asserts *exactly\r\n  one* appears under a storm (:178) and counts N under a deliberate race (:237). Adding identity\r\n  fields to that line risks the count and buries a forensic record inside a line whose contract is\r\n  its cardinality. **The record belongs in its own line and its own artifact.**\r\n\r\n- **REMEDY — RULED 2026-09-07 11:07Z (doyle), APPROVED as proposed with two refinements. Small,\r\n  product-side, no wire change.** doyle re-derived the census independently at `f3c8495b` (one\r\n  writer `daemon.rs:471`, two readers `cli.rs:8581` + `:8754`, both inside `if running`) before\r\n  ruling — the falsifiable claim below has been checked, not taken.\r\n  1. **Read before you clobber.** At `daemon.rs:471`, read the existing `daemon.pid` and its mtime\r\n     BEFORE the write; if it holds a pid that is not ours, emit a distinct, greppable line naming\r\n     the predecessor pid and how long ago the file was last touched — e.g.\r\n     `DAEMON_SUCCEEDS_PID: prior=<pid> prior_pidfile_age_ms=<n> reason=<socket-ping-failed>`. The\r\n     value is that the successor is the only process in the system that is guaranteed to run at\r\n     exactly the moment the question becomes askable.\r\n  2. **Keep one generation.** Rename the existing `daemon.pid` to `daemon.pid.prev` instead of\r\n     overwriting it (best-effort, same directory, same failure posture as today's `let _ =`). One\r\n     generation is enough to answer \"which pid did I replace, and when did it last write?\" and costs\r\n     no rotation policy.\r\n  3. **REFINED BY THE RULING — the discriminator is a FIELD, not a second line.** I proposed a\r\n     separate \"what the ping saw\" record; doyle collapsed it: `prior=<pid|none>` already separates\r\n     the two incidents, because `none` **is** the fresh-home case. One line, one field, no second\r\n     breadcrumb to keep in sync.\r\n  4. **ADDED BY THE RULING — `alive=<bool>`, from a by-number liveness READ at write time.** With\r\n     the prior pid in hand, read whether that number is still live and put the answer on the line.\r\n     It splits the two incidents that otherwise look identical: **`alive` prior = two daemons racing\r\n     the seed bind** (the convoy case), **dead prior = the corpse** (the 14444 case). This is a\r\n     READ, not a kill — #285's identity-before-kill rule binds kills and is not weakened here; a\r\n     by-number read that informs a log line commits no action on the pid.\r\n  5. **UNIT, specified by the ruling:** seed a pidfile with a fake pid and an aged mtime, run the\r\n     write path, assert the emitted fields (`prior`, `age_ms`, `alive`) AND the `daemon.pid.prev`\r\n     bytes. The `.prev` bytes are part of the assertion, not an afterthought — the generation kept\r\n     is the half that survives the process.\r\n  6. **NOT proposed, and the ruling kept it out:** a liveness change. `is_running()` must stay the socket ping — this entry does\r\n     not argue the pidfile should become a liveness signal, which is the exact mistake\r\n     `endpoint.rs:82-85` was written to prevent. The pidfile stays advisory; it just stops being\r\n     silently destroyed.\r\n\r\n- **LANE — SPLIT BY THE RULING, and the two halves ship separately.** The **IR-82 ENTRY** (this\r\n  text) rides hertz's IR-37 thin PR alongside IR-79/80/81. The **PRODUCT REMEDY** rides **#285's\r\n  lane** (todlando, post-W2) because it is the same pid-identity gate: #285 makes a kill read an\r\n  identity, this makes a successor read the identity it is about to erase. One lane, one owner,\r\n  one review of the pid-identity question. Do not implement the remedy in the thin PR.\r\n\r\n- **Kin:** [[RCA-FLEET-DAEMON-14444]] (the open incident this serves — IR-82 does not close it and\r\n  must not be read as closing it), [[IR-81]] (a pid is not an identity — the same lesson from the\r\n  KILL side; here it is the RECORD side), [[IR-80]]/[[IR-79]] (processes outliving what should have\r\n  accounted for them). The through-line doyle named at 10:22Z holds: *a pid is not an identity and a\r\n  pid is not a tree* — and IR-82 adds that **a pid nobody wrote down is not evidence.**\r\n\r\n- **Falsifiable claim, so it can be checked rather than believed:** at `f3c8495b` the tree contains\r\n  exactly ONE writer of `daemon_pid_path()` (`daemon.rs:471`) and exactly TWO readers\r\n  (`cli.rs:8581`, `cli.rs:8754`), both inside a `running` gate. If a future reader appears in an\r\n  unguarded path, this entry's premise weakens and it should be re-measured, not re-asserted.\r\n\r\n### IR-83 — a two-host rig addressed over the tailnet cannot receive INBOUND on Windows, and the whole rig population had only ever run the admitted direction\r\n\r\n- **Status:** OPEN, minted by hertz 2026-09-07 11:41Z on doyle's dispatch (11:40Z). **Provenance: the\r\n  mechanism below is DOYLE'S measurement, not mine** — eight probe arms, each with sender, listener\r\n  and output file, recorded in `GATE-W2-272-CHECKLIST.md` rows 11:36Z–11:39Z. I am off cargo on both\r\n  boxes and have re-measured none of it; this entry is the register form of his finding plus the\r\n  structural reading it supports. Board face: **F18**. Register slot: IR-83 (79/80/81/82 are the\r\n  same thin PR).\r\n- **THE FINDING, in one line:** two-host rigs must address peers by **LAN**, never the tailnet.\r\n\r\n- **HALF ONE — the tailnet ACL is per-node and ONE-WAY.** `hfenduleam` admits 9 sources and\r\n  `kitsubito` is **not** among them; `kitsubito` admits `hfenduleam`. So a rig cell needing INBOUND\r\n  to the Windows box over `100.x` fails **at the receiver**, and it fails there **whatever the host\r\n  firewall says** — which is why a host-firewall investigation can be run to completion, come back\r\n  clean, and explain nothing.\r\n\r\n- **HALF TWO — Windows defaults `BlockInbound`, and a hash-named test exe has no rule.** Test\r\n  binaries are built with hash-suffixed names, so a rule written against the *program* is keyed to a\r\n  name that changes on the next build. The stale `spt_net-d037…` rule is the precedent already in\r\n  the tree: a rule that was correct once, is present, greps fine, and admits nothing. **The durable\r\n  form is PORT-scoped, not program-scoped:** ports `7480-7499`, `remoteip` = the peer's LAN address,\r\n  added by the operator.\r\n\r\n- **WHY IT SURFACED ONLY NOW, and this is the part that generalizes.** The W2 helper cell is the\r\n  **first cell in the entire rig population that ever needed `kitsubito -> hfenduleam` inbound.**\r\n  W1's four xbox cells and golden's old-twohost job are all `hfenduleam -> kitsubito` — the admitted\r\n  direction. So the population had a **direction monoculture**, and a one-way ACL is invisible to a\r\n  suite that only ever runs the admitted way. Every green in that population was consistent with the\r\n  ACL being wide open and equally consistent with it being one-way; the suite could not tell the\r\n  difference, and nobody had reason to ask. **A capability exercised in only one direction is not\r\n  covered, it is merely unexamined** — the same shape as an assertion that only ever sees the\r\n  passing arm.\r\n\r\n- **THE SECOND STRUCTURAL POINT — a rule keyed to a MUTABLE identity is the lane's own through-line.**\r\n  A per-hash program rule is an exception bound to an identity the build changes underneath it,\r\n  exactly as [[IR-81]] is about a kill bound to a pid the OS may reassign and IR-80 Amendment 1's ENV\r\n  READ face is about a read bound to a process identity `exec` can change. Port-scoping replaces a\r\n  mutable identity with a stable property. That is the same remedy shape as reading an image path\r\n  before a kill and reporting an environment in-band: **stop keying on the thing that moves.** I am\r\n  flagging the rhyme, not claiming a fourth face — this is infrastructure config, not a code path,\r\n  and the amendment's standing prediction is about pid-shaped questions.\r\n\r\n- **FALSIFIABLE CLAIM (doyle's, recorded verbatim as the entry's test):** with the rig on **LAN\r\n  addresses AND the port-scoped rule present**, the helper cell's owner raw carries `WEB_SERVE_FOR`;\r\n  with **either** missing, it carries none. Both arms matter — this is a conjunction, so a single\r\n  green with one of the two absent would refute it, and a red with both present would too.\r\n\r\n- **WHAT THIS ENTRY DOES NOT CLAIM.** It does not say the host firewall was ever misconfigured; the\r\n  ACL half fails at the receiver independently. It does not close F17 or explain the vacuous-green\r\n  run (that was the mid-flight script rewrite — different cause, different fix, and the two were\r\n  live in the same hour, which is precisely why each needed its own named mechanism rather than one\r\n  story). It proposes no product change: both halves are rig addressing and operator-added firewall\r\n  config.\r\n\r\n- **REMEDY.** (1) Rig-side: address peers by LAN in two-host rigs, and make the tailnet address\r\n  unreachable-by-construction rather than merely unused, so a future rig cannot quietly pick it up.\r\n  (2) Operator-side: the port-scoped inbound rule (`7480-7499`, `remoteip` = peer LAN), replacing\r\n  per-hash program rules; the stale `spt_net-d037…` rule should be removed in the same pass so it\r\n  stops reading as coverage. (3) Population-side — **RULED 11:42Z (doyle), with a precision that\r\n  changes the shape:** this is NOT a new cell. **The W2 helper cell IS the first reverse-direction\r\n  cell**, and on LAN it exercises `kitsubito -> hfenduleam` inbound for real once the rule exists.\r\n  The remedy is therefore to **keep at least one reverse cell in the xbox battery permanently and\r\n  NAME it as the direction witness**, so its role is a stated property rather than an accident of\r\n  what W2 happened to need. A suite that only runs one way cannot discover the next one-way ACL\r\n  either, and the way that recurs is not \"nobody wrote the cell\" but \"the cell that had it stopped\r\n  being run.\"\r\n\r\n  **The hazard that follows from naming it, stated here so the naming is not decorative:** a witness\r\n  cell that is SKIPPED stops being a witness while still reporting green — the exact confusion this\r\n  lane already paid for, where a must-skip `role_b` PASS was indistinguishable from four cells that\r\n  no-opped. So the direction witness needs its skip to be loud: if it is filtered out, phase-reclassed,\r\n  or short-circuits on a missing precondition, that must read as ABSENT COVERAGE and not as a pass.\r\n  Whoever names it owns that half too. **Concrete enforcement, doyle-ruled 11:44Z and written up\r\n  as the RIDER 5 ADDENDUM:** the xbox driver's HELPER WITNESS verdict line already refuses a\r\n  `0.0x s` helper PASS and a `b.raw` without `WEB_SERVE_FOR outcome=registered`; it must ALSO\r\n  print `NOT-A-WITNESS` when the cell is absent from the LIST leg. Those first two are\r\n  *ran-but-vacuous*; absence is *never-ran*, and a verdict built only from the first two passes\r\n  it by omission — every refusal condition evaluates against output that does not exist, finds\r\n  nothing to object to, and falls through to green.\r\n\r\n- **GATING CLAUSE — added 2026-09-07 12:56Z on doyle's dispatch (gate reshape, same minute).** An\r\n  inbound-to-Windows cell in a two-host rig is **gated on the port-scoped rule being present**, and\r\n  without it the cell must **SKIP LOUDLY**: it may not run, may not report PASS, and may not be\r\n  silently filtered — its absence must render as ABSENT COVERAGE in the verdict, on the RIDER 5\r\n  ADDENDUM's `NOT-A-WITNESS:NEVER-RAN` face. The precondition is machine-readable, so the driver\r\n  reads `netsh` at start and the gate is a measured fact rather than a remembered one; a cell whose\r\n  precondition is unmet and which therefore emits nothing is exactly the case a verdict assembled\r\n  only from ran-but-vacuous refusals passes by omission. **This clause is what stops the rule's\r\n  ABSENCE from reading as the rig's health.**\r\n\r\n  **How the reshaped W2 F17 gate applies it (doyle 12:56Z, recorded, not re-measured by me — I am\r\n  still off cargo on both boxes).** With the rule absent 75+ minutes and no operator activity, and\r\n  golden carrying no cross-box `twohost_web`, the shortfall is a **rig blocker, not a golden one**.\r\n  So the HELPER WITNESS was reshaped to the **ONE-BOX pair on BOTH OSes** — doyle's gate tree on\r\n  Windows, a kitsubito clone at the tip on Linux with the rig shipped as the frozen copy — on the\r\n  basis that the 03:31Z one-box run at `f3c8495b` reproduced F17 end to end (A `outcome=unanswered`,\r\n  B `DISPATCH:4:Unknown`), i.e. the one-box pair drives the real dispatcher on both roles.\r\n  Mutation D must turn the classify unit cell red **and** the one-box helper cell red\r\n  (owner `family=Unknown`>0, `registered`=0) while deny/fetch stay green; revert dirty 0. The\r\n  cross-box pair still runs as the A->B regression (deny/fetch must PASS), and while the rule is\r\n  absent its helper/range TIMEOUTs are classified **F18-INFRA** — becoming a witness automatically\r\n  if the rule lands before the run, because the driver reads `netsh` at start.\r\n  **The cross-box helper witness therefore stays an OPEN rider on the operator's rule, not a land\r\n  blocker.** Note the shape this preserves: the reshape moves the witness to a pair that CAN run,\r\n  and leaves the direction it cannot exercise named and open — it does not let the one-box green\r\n  stand in for the direction coverage that is still missing. A one-box pair proves the dispatcher;\r\n  it cannot prove an inbound ACL, and nothing here claims it does.\r\n\r\n  **PROBE RESOLUTION — doyle 12:59Z, ADOPTED INTO THIS GATE (not deferred to the rider).** The\r\n  precondition read is now THREE-VALUE in `gate-w2-f17.sh`: `Rule Name` in stdout -> PRESENT,\r\n  `No rules match` -> ABSENT, empty stdout or anything else -> PROBE-FAILED. **PROBE-FAILED\r\n  classifies the cross-box helper/range as `UNCLASSIFIED: this run cannot tell INFRA from a real\r\n  red` — never F18-INFRA** — and xbox-D's skip line names the state. The raw probe (exit code +\r\n  first 3 lines) is printed into the driver log, so the classification is auditable after the fact\r\n  rather than inferred from what got bucketed. Exercised standalone on all three arms: real\r\n  `netsh` = exit 1 + `No rules match` -> ABSENT; forced bad args -> PROBE-FAILED; empty stdout ->\r\n  PROBE-FAILED.\r\n\r\n  **Recorded because it corrects the asker (me), not the implementer:** I proposed the three-value\r\n  shape AND, in the same message, proposed discriminating on the exit code. doyle's standalone\r\n  exercise measured `netsh` exiting **1 on a clean ABSENT**, so an exit-code discriminator would\r\n  have classified every legitimately-absent rule as an instrument fault — turning the run's most\r\n  common honest state into PROBE-FAILED and, with it, `UNCLASSIFIED`. The discriminator that landed\r\n  is STDOUT CONTENT. The general form belongs in the entry because it is the reason the third arm\r\n  needed measuring at all: **a CLI's exit code is a claim about the QUERY, not about the ANSWER**,\r\n  and an empty-but-correct result is reported non-zero by a great many tools. A third value added\r\n  to a probe needs its own evidence, obtained by making all three arms fire on purpose — which is\r\n  this lane's standing rule that a tool whose success path has never been made to fail on purpose\r\n  is untested, applied to a tool's FAILURE path instead.\r\n\r\n- **Kin:** [[IR-81]] and IR-80 Amendment 1 (keying on a mutable identity), the F17 riders (a witness\r\n  that never executed the direction it certifies).\r\n\r","truncated":true,"truncatedBy":"lines","totalLines":1639,"totalBytes":42735,"outputLines":520,"outputBytes":42735,"lastLinePartial":false,"firstLineExceedsLimit":false},"totalLines":5782,"displayContent":{"text":"Machine-generated from the eight ci unit logs, not transcribed (a hand-typed 12x8 matrix is where\r\ntranscription errors live). `X` = reported LEAK at that sha on that box.\r\n\r\n| cell | W ff4b405d | W e3bd53d4 | W 401a19ad | W f3c8495b | L ff4b405d | L e3bd53d4 | L 401a19ad | L f3c8495b |\r\n|---|---|---|---|---|---|---|---|---|\r\n| `spt-daemon brainproc::tests::clear_before_spawn_defeats_exact_generation_stale_file` | X | X | X | X | . | . | . | . |\r\n| `spt-daemon brainproc::tests::ready_but_old_gen_never_drains_does_not_promote_rolls_back` | X | X | X | X | . | . | . | . |\r\n| `spt-daemon brainproc::tests::stale_generation_minus_one_ready_never_promotes` | X | X | . | X | . | . | . | . |\r\n| `spt-daemon brainproc::tests::trial_kills_alive_never_ready_candidate_before_rollback` | X | X | X | X | . | . | . | . |\r\n| `spt-daemon broker::tests::windows_session_is_zombie_sees_a_handle_held_corpse_as_dead` | X | . | . | X | . | . | . | . |\r\n| `spt-daemon livehost::tests::legacy_psyche_sweep_guard_is_id_specific_and_fail_safe` | . | . | . | . | X | X | X | . |\r\n| `spt-daemon shellhost::tests::kill_shell_at_still_kills_a_matching_pair` | . | . | . | X | . | . | . | . |\r\n| `spt-daemon shellwake::tests::kill_waker_at_still_kills_a_matching_pair` | . | X | X | X | . | . | . | . |\r\n| `spt-live digest::tests::extractor_timeout_errors` | X | X | . | X | . | . | . | . |\r\n| `spt-live history::tests::fetcher_timeout_errors` | X | X | . | . | . | . | . | . |\r\n| `spt-runtime runtime::tests::bounded_run_kills_on_timeout` | X | X | X | X | . | . | . | . |\r\n| `spt-store proc::tests::process_cmdline_reads_a_live_arg_marker` | . | . | . | . | X | X | X | X |\r\n| **leaky count** | 8 | 8 | 5 | 9 | 2 | 2 | 2 | 1 |\r\n\r\nUnion = 12 cells across 4 shas x 2 OSes. Present at EVERY Windows sha: 4. Present at every Linux sha: 1.\r\n\r\n#### Three readings, in increasing order of what they support\r\n\r\n**1. The churn is total and it is the whole point.** Windows counts run 8, 8, 5, 9 — the HIGHEST\r\nvalue is at `f3c8495b`, the tip carrying every fix F1-F16. Only **4 of 12** cells are present at\r\nevery Windows sha; only **1 of 2** at every Linux sha. Read as a quality signal the series says W2\r\nmade leaking worse, which is exactly as wrong as my retracted \"8 -> 5, favourable\" read and wrong\r\nfor the same reason. **A leaky count is not a signal in either direction.**\r\n\r\n**2. NEW, and I had not said it before building this table: the two OS sets are DISJOINT.** Ten\r\ncells leak only on Windows, two only on Linux, and **not one cell leaks on both**. Windows carries\r\n8-9 leaky cells per run against Linux's 1-2. So this is not one flaky population sampled twice —\r\nit is two populations with no overlap, and the Windows one is roughly five times larger. Any\r\nexplanation that treats \"leaky tests\" as a single phenomenon has to account for a clean partition\r\nby OS.\r\n\r\n**This is an OPEN QUESTION and the draft does not answer it. I do not have that explanation yet.**\r\nRecorded deliberately without a candidate cause: the partition is a measurement, and the temptation\r\nto pair a striking measurement with a plausible story is how the \"8 -> 5 is favourable\" reading got\r\ninto the record in the first place. Whoever takes this should arrive at a cause by reading, not by\r\ninheriting one from me.\r\n\r\n**SCOPED CAUSE, IN SOURCE, FOR ONE FAMILY ONLY (doyle ruled 10:22Z: source beats story; a source\r\ncause covering one family is a measurement and is filed as one).** The brainproc family leaks on\r\nWindows and not Linux because *its own fixture is asymmetric*: `long_child()` (brainproc.rs:1359)\r\nspawns `Command::new(\"cmd\").args([\"/C\",\"ping\",\"-n\",\"30\",\"127.0.0.1\"])` on Windows but\r\n`Command::new(\"sleep\").arg(\"30\")` on Unix — a shell wrapper on one box, a bare process on the other.\r\nThe Windows candidate the supervisor kills is `cmd`; the process burning 29 seconds is its child.\r\nThat is two lines of source, not an inference from the symptom. **And it is NOT the whole partition:**\r\n`process_cmdline_reads_a_live_arg_marker` uses a shell on BOTH arms (`sh -c \"sleep 30; : marker\"` /\r\n`cmd /C \"ping … & rem marker\"`) yet leaks on **Linux only** — the shell mechanism predicts it should\r\nleak on both boxes and it does not. So one family has a cause I can point at in the source, the\r\npartition as a whole remains OPEN, and the counterexample stands in this paragraph rather than a\r\nfootnote so no one carries the cause further than it goes.\r\n\r\n**THE PRODUCT PATH HAS NO INTERMEDIARY; THE FIXTURE DOES.** I chased the obvious escalation — if the\r\nreal supervisor also killed a shell wrapper, then \"never two live brains\"\r\n(REQ-HAZARD-BROKER-PROCESS-ISOLATION, the invariant this very cell guards) could be violated on\r\nWindows in production while the test stayed green. It cannot: `spawn_brain_child` (brainproc.rs:1224)\r\ndoes `Command::new(exe)` — the brain is spawned DIRECTLY, no shell, no grandchild, so a single-pid\r\nkill reaches it. **This is a test-fixture artifact, not a product defect**, and the fixture's shell\r\nis a Windows-only convenience for \"a process that blocks ~30s\" that introduced a layer the real path\r\ndoes not have. The negative is the useful half: it keeps the crashloop invariant out of IR-81 (a).\r\n\r\n**Why the cell passed review for as long as it did.** It asserts `pid != 0 && !pid_alive(pid)` before\r\nrollback, and that assertion is TRUE — `cmd` really is dead. The process still doing work is the one\r\nit never looks at. The leak and the green are not in tension; they are the same fact from two ends.\r\n**An assertion over a pid cannot see a tree.**\r\n\r\n**3. The invariant holds at 12 of 12, and it survived the population being shuffled three times.**\r\nEvery union member spawns a child process and then kills it, lets it time out, or inspects its\r\ncorpse — `trial_kills_alive`, `kill_shell_at`, `kill_waker_at`, `bounded_run_kills_on_timeout`,\r\n`extractor_timeout_errors`, `fetcher_timeout_errors`, `windows_session_is_zombie_..._corpse_as_dead`,\r\n`legacy_psyche_sweep_guard_...`, `process_cmdline_reads_a_live_arg_marker`, and the three brainproc\r\nspawn/promote/rollback cells. Membership churns freely across four shas and two OSes; the KIND of\r\ncell has not varied once. **This is the IR-80 headline** and it is better supported now than when it\r\nrested on a stable-looking five-cell cluster, precisely because the population underneath it has\r\nbeen reshuffled and the invariant did not move.\r\n\r\n#### A MECHANISM, read out of the source of the two Linux cells — calibrated, not generalized\r\n`process_cmdline_reads_a_live_arg_marker` spawns **`sh -c \"sleep 30; : marker\"`**, and the test's\r\nown comment says the trailing `; :` is deliberate — it keeps the shell RESIDENT so its\r\n`/proc/<pid>/cmdline` still carries the marker instead of being tail-exec-replaced by `sleep`. The\r\nteardown is `child.kill()` then `child.wait()`. **But `child` is the SHELL, and `sleep 30` is the\r\nshell's own child.** Killing the shell orphans the sleeper, which outlives the test by up to 30\r\nseconds — which is precisely what nextest reports as a LEAK. The Windows arm has the same shape:\r\n`cmd /C \"ping -n 30 127.0.0.1 >NUL & rem marker\"`, where `cmd` forks `ping`.\r\nSo the very construct that makes the test work (a resident shell, so the cmdline stays readable) is\r\nwhat guarantees a grandchild that a single-pid kill cannot reach.\r\n\r\n**What is verified and what is not, stated separately because the difference decides who owns this.**\r\nVERIFIED by reading source: this shape in BOTH Linux-only cells. CONSISTENT but not proven: the\r\nWindows family kills the same way — `kill_waker_at_still_kills_a_matching_pair` tears down with\r\n`kill_shell_pid(ours.id())`, a single-pid kill — so the mechanism is available to it, but I have not\r\nread every spawn helper. UNVERIFIED: the brainproc, broker and spt-live cells; those spawn real\r\nbrains and time out extractors, and may leak for unrelated reasons.\r\n\r\n**Why this matters beyond IR-80:** a single-pid kill that cannot reach a grandchild is exactly\r\n[[ir81]] arm (a) — identity and tree-awareness pushed into `kill_pid_tree`/`kill_pid` so no caller\r\ncan express the unreachable kill. If the mechanism above generalizes, IR-79 (rigs leaking daemons\r\non a failing assert), IR-80 (this) and IR-81 (kill scoping) are not three findings that share a\r\nseam, they are three FACES of one defect: **the codebase kills pids, and the things it needs dead\r\nare trees.** That is a claim worth testing, not asserting — and doyle's one-cell mechanism probe\r\nis still the right instrument, now with a sharper question: after the kill, is the surviving\r\nprocess the CHILD or the GRANDCHILD?\r\n\r\n---\r\n\r\n#### AMENDMENT 1 — \"a pid is not a tree\" has THREE faces, and only one of them is a kill\r\n\r\n*(hertz 2026-09-07, ruled by doyle 11:17Z: write this as an IR-80 amendment naming the three faces\r\nrather than three separate entries, so a reader hunting any one face lands on all three.)*\r\n\r\nThe register sentence this lane has been running on is doyle's: **a pid is not an identity and a pid\r\nis not a tree.** IR-80 and IR-81 were both filed against the KILL side, which made the sentence read\r\nlike a rule about killing. It is not. It is a rule about **which process you are talking about**, and\r\nkilling is only the face we happened to find first. Three faces are now measured, each found by a\r\ndifferent agent working a different problem:\r\n\r\n| face | the operation | what going one level too high produces | measured |\r\n|---|---|---|---|\r\n| **KILL** | `kill_pid(pid)` on a wrapper | the wrapper dies, the grandchild keeps working — the leak | IR-80's 12-cell union; `proc.rs:430`'s own doc states it |\r\n| **IDENTITY** | `kill_pid_tree(remembered_pid)` with no image read | you kill *a* process with that number, not the one you meant | IR-81 / #285, `broker.rs:8102` vs `servicehost.rs:651` |\r\n| **ENV READ** | `psutil.Process(child.pid).environ()` | the wrapper's env certifies a launch the battery would have failed | hertz 2026-09-07, self-test of `.github/bench/launch-battery.py` |\r\n\r\n**The third face, in full, because it is the newest and the least intuitive.** Reading back the\r\nenvironment of the process you spawned is the standard remedy for \"did my scrub/export actually\r\nland\" — it is what this project's own memory banked after the W0 perch-identity leak. It is\r\ninsufficient, and it fails in the flattering direction. A wrapper (`env VAR=x`, `cargo`, `nextest`,\r\n`bash -lc`) modifies the environment it hands the process **below** it, while its own `environ()`\r\nstill shows exactly what you passed in. So the read-back agrees with your intent, prints PROVEN, and\r\nsays nothing whatsoever about the process under test. Measured: the first version of\r\n`launch-battery.py` passed BOTH deliberately-negative tests. The corrected version walks descendants\r\nand, in the refusal, prints the wrapper as CLEAN beside the grandchild as VIOLATOR — that contrast\r\nis the face made visible in one line of output.\r\n\r\n**Why this belongs in IR-80 rather than in a new entry.** All three are the same error committed at\r\nthe same seam: an operation is aimed at a pid when the thing it needs to reach is a tree (or a\r\nspecific member of one). The remedies rhyme — walk the tree, read the identity, report the scope you\r\nactually covered — and a reader who finds any one face is one paragraph away from the other two.\r\nFiling them separately would have hidden that, which is the concrete cost doyle's ruling avoids.\r\n\r\n**What this amendment does NOT claim.** It does not widen IR-80's population: the 12-cell union\r\ntable and its Windows/Linux partition are unchanged, and the env face is not a test leak. It does\r\nnot add a remedy owner — the ENV face's fix is a tool (`.github/bench/launch-battery.py`), not product code, and the KILL and\r\nIDENTITY faces keep the owners they already have (#285 / todlando post-W2). It is a naming, and its\r\nwhole value is that the next instance of this error gets recognized as an instance instead of being\r\nfiled fresh.\r\n\r\n**Standing prediction, so this is falsifiable rather than tidy:** a fourth face exists wherever the\r\ncodebase asks a question *of* a pid that is really a question *about* a tree. The candidates I would\r\nlook at first are (a) liveness — `process_exists(pid)` answering \"is the work still running\" when\r\nthe work is a grandchild, and (b) resource attribution — reading a pid's handles/memory to decide\r\nwhether a lane is finished. Neither is measured; both are named so that finding one counts as\r\nconfirmation and finding none over the next few incidents counts against the generalization.\r\n\r\n### IR-81 — a process kill can be written scoped or machine-wide, and nothing makes the scoped form the only reachable one: both codebases carry the right pattern beside the wrong one\r\n\r\n- **Status:** OPEN, drafted by hertz 2026-09-07 08:38Z on doyle's dispatch (08:36Z), from the\r\n  fleet-daemon death on hfenduleam at 08:03:15Z ([[RCA-FLEET-DAEMON-14444]], cause still UNNAMED).\r\n  Census body: `docs/PID-KILL-CENSUS.md`. · **Origin:** doyle asked which sites kill a REMEMBERED\r\n  pid without re-verifying identity AT KILL TIME. The census answered that, and then answered a\r\n  better question nobody asked: **why the unguarded sites exist at all when the guarded ones sit\r\n  feet away.**\r\n- **⚠ THIS ENTRY IS NOT \"FIX THESE TWO SITES.\"** Both individual fixes are small and are dispatched\r\n  elsewhere (broker.rs:8102 → todlando's lane post-W2; live-relay-int.sh:78 → filed to perri). This\r\n  entry is about the thing that PRODUCED them and will produce the next one: the scoped form and the\r\n  machine-wide form are equally easy to write, equally plausible on review, and only one of them is\r\n  correct on a shared box.\r\n- **THE PAIRED EXHIBITS — same repo, same hand, feet apart.**\r\n\r\n  | | correct, and it says why | incorrect |\r\n  |---|---|---|\r\n  | **spt-core** | `spt-daemon/src/servicehost.rs:651` — `provably_gone` first, then `exe_path(pid)` compared to the parked image via `same_image`, then a FRESH post-kill read. Its comment IS the rule: *\"The pid is live. WHO is it? The image path decides — never the number.\"* | `spt-daemon/src/broker.rs:8102` — kills `spid`, a pid REMEMBERED off the session record, through `kill_pid_tree`. `zombie_verdict` consults liveness BY NUMBER (`process_exists`/`is_process_alive`), `adapter_labeled` (a property of the RECORD, not the live process), descendants and grace. **The live process's image is never read.** |\r\n  | **spt-claude-code** | `ci/launcher/bind-int.sh:50` — `wmic process where \"name='claude-spt.exe' and commandline like '%$ID%'\"`, scoped to this run's unique id, comment *\"never wall-a's\"*. Also `multi-subnet-bringup-int.sh:117` ($C3_ID) and `wake-survival-int.sh:64` (`-match '$PROBE'`). | `ci/psyche/live-relay-int.sh:78` — `for p in $(tasklist \\| grep -i claude-spt \\| awk '{print $2}'); do taskkill //PID \"$p\" //T //F; done` — **every** `claude-spt.exe` on the box, tree-force, no run-scoping. Comment: *\"by marker pid then name.\"* |\r\n\r\n  **The knowledge is not missing in either codebase. It is present, written down, and adjacent.**\r\n  Three correct sites to one wrong one in the adapter; a rule-stating comment in core. What is\r\n  missing is any mechanism that makes the wrong spelling hard to reach.\r\n- **Why \"just fix the sites\" is the wrong remedy:** it has already been tried implicitly — someone\r\n  wrote the scoped form three times, which is what a team looks like when it knows the rule and\r\n  still ships the exception. A fourth correct site does not prevent a fifth incorrect one. The\r\n  remedy has to change what is REACHABLE, not what is written.\r\n- **REMEDY — RULED 2026-09-07 08:40Z (doyle): (a) AND (b), not a choice between them. Two owners,\r\n  two lanes, and they cover different halves of the hazard.**\r\n  1. **(a) PRODUCT — push the identity requirement into the primitive.** `spt_store::proc::kill_pid_tree`\r\n     / `kill_pid` take an expected identity (image path, or a `same_image` closure) and refuse\r\n     without it, so a caller **cannot express** the unguarded kill; `servicehost.rs:651` stops being\r\n     the exception among callers and becomes the shape of all of them. **Owner: todlando, post-W2.**\r\n     ⇄ **This IS the fix shape of the `broker.rs:8102` board BUGFIX — that item and this entry\r\n     cross-reference each other; neither is complete alone.** Reaches Rust callers only.\r\n  2. **(b) GATE — `xtask check` refuses the unscoped spelling in CI scripts.** A `tasklist` /\r\n     `Get-Process` enumeration piped into a kill, or a bare `taskkill` with no\r\n     `commandline like` / `-match` scope in the same block, is a build failure. **Owner: hertz,\r\n     rides the IR-37 thin PR after W2 lands.** This is the half remedy (a) can NEVER reach — the\r\n     unguarded adapter site is a shell script, and no Rust signature constrains a shell script.\r\n  3. **(c) Fix the two sites and stop.** Recorded as CONSIDERED AND LOSING, not omitted: it has\r\n     already been tried implicitly — the adapter's author wrote the scoped form three times and\r\n     shipped the exception anyway — so a fourth correct site does not prevent a fifth wrong one.\r\n     It leaves the next instance free to appear.\r\n  **The (a)/(b) split is the entry's real content:** the hazard lives in two languages, and a remedy\r\n  in one of them is a half-measure that will read as a fix.\r\n- **STANDING LIMIT, so this entry is not overread as an incident cause:** none of these sites\r\n  explains the 08:03:15Z death. broker.rs:8102 would have been saved from firing by\r\n  `has_live_descendants` (the daemon had a live brain) — accidental protection, not deliberate —\r\n  and every claude-spt site enumerates `claude-spt.exe` while the dead process was `spt.exe`. The\r\n  census found a real hazard while looking for a different one. **Do not let this entry close the\r\n  incident.** The instrument at `C:\\Users\\decid\\.spt-watch\\daemon-watch.log` is what will answer\r\n  that, or fail to.\r\n- **Kin:** [[IR-79]] and [[IR-80]] (children outliving their cell; the leak family), the\r\n  [[RCA-FLEET-DAEMON-14444]] timeline, `servicehost.rs`'s own \"image path decides\" comment as the\r\n  in-tree statement of the rule, and the paired-exhibit method itself — a correct and an incorrect\r\n  site in one repo is stronger evidence about PROCESS than either site is about code.\r\n- **Ripe when:** the next touch of `spt-store/src/proc.rs` (for remedy 1) or of `xtask check`'s\r\n  gate family (for remedy 2). The adapter half is perri's, filed separately, and does not wait\r\n  on this.\r\n- **Size:** small for remedy 2, medium for remedy 1 (signature + every caller). The census that\r\n  justifies either is already written and does not need redoing.\r\n\r\n---\r\n\r\n#### ADAPTER-SIDE ARM: CLOSED (claude-spt, perri, 2026-09-07)\r\n\r\n**Status: closed in the consumer repo, test-only, does not close IR-81 here.**\r\n\r\n- **Commit `9c87372`** (spt-claude-code). Broad `tasklist | grep claude-spt | taskkill` replaced\r\n  with an **id-scoped wmic** call, **name-pinned so wmic cannot self-match**; the three\r\n  remembered-pid kills additionally got a **kill-time recheck**, covering the stale-identity face\r\n  as well as the unscoped-pattern face.\r\n- **Guard: `tests/ci-kill-scoping.sh`, traced as `REQ-HAZARD-CI-KILL-SCOPING`.** Gate green.\r\n  This is the check-shape arm (b) proposes for spt-core, already landed once — precedent, not\r\n  merely agreement.\r\n- **Scope: test/CI infrastructure only.** No product code changed. (doyle, 08:50Z.)\r\n- **`live-relay-int.sh:78` is retained as the historical RED exhibit** — the one genuinely\r\n  machine-wide kill found in the whole fleet census. It is the reason this hazard is written as a\r\n  hazard rather than a style note; do not quietly replace the exhibit with the fixed line.\r\n\r\n**Population lesson carried into arm (b)'s census.** I filed ONE site; perri confirmed **four**, and\r\nreports the idiom was already present in that repo **3x** before the filing. A filing that names one\r\nline under-counts its class by 3-4x in a single repo. **Census the ACT — any taskkill / pkill /\r\nwmic-delete reachable from a script root — never the literal string that led me to the first site.**\r\nState the walked roots in the check's own message, and give the gate a negative control that goes\r\nRED on a known-bad line before its green is trusted.\r\n\r\n**Still open here, unchanged:** arm (a), Rust-side identity pushed into `kill_pid_tree` / `kill_pid`\r\nso no Rust caller can express the unguarded kill (todlando, post-W2, cross-referenced with the\r\nbroker.rs:8102 board BUGFIX); and arm (b), the xtask script gate (mine, rides IR-37).\r\n\r\n---\r\n\r\n#### SCOPING ARM (a) — the product path has no intermediary; the fixture does\r\n*(hertz 2026-09-07, ruled by doyle 10:22Z off the IR-80 leak work.)*\r\n\r\n> **A pid is not an identity and a pid is not a tree. IR-80 needs CALLERS, not code.**\r\n> *(The register's sentence — doyle 10:23Z. Arm (a) fixes the identity half in\r\n> `kill_pid`/`kill_pid_tree`; the tree half needs no new machinery, because `kill_pid_tree` already\r\n> exists at proc.rs:430 with the defect stated in its own doc. This is why IR-79, IR-80 and IR-81\r\n> converge on one seam without collapsing into one finding.)*\r\n\r\nMeasured, not inferred: **`spawn_brain_child` (crates/spt-daemon/src/brainproc.rs:1224) does\r\n`Command::new(exe)`** — the real brain is spawned DIRECTLY, with no shell and no launcher between\r\nthe daemon and the process it supervises. So on the crashloop/rollback path a single-pid kill\r\n*does* reach the thing it aims at, and the \"orphaned grandchild\" mechanism found in the IR-80 leak\r\ncells is **a property of the TEST FIXTURE**, whose `long_child()` (brainproc.rs:1359) goes through\r\n`cmd /C` on Windows, not of the product.\r\n\r\n**What that scopes.** Arm (a) is NOT about the brain-supervision path and must not be sold as\r\nprotecting `REQ-HAZARD-BROKER-PROCESS-ISOLATION` (\"never two live brains\") — that invariant is not\r\nat risk here, and claiming it would be borrowing urgency this arm has not earned. Arm (a) stays\r\npointed at **the broker.rs:8102 reap, where the image is never read** — a kill aimed by pid alone\r\nat a process whose identity was never verified. That is the real unguarded form, and it is a\r\ndifferent failure (kill the wrong process) from the one IR-80 surfaced (fail to kill the right\r\none).\r\n\r\n**The two failures are different, which is why the drafts converge without collapsing.** Arm (a) is\r\n*kill the wrong process* (identity never read); IR-80 is *fail to kill the right one* (tree never\r\nwalked). The identity half is todlando's, post-W2. The tree half is already solved in-tree —\r\n`kill_pid_tree` at proc.rs:430, whose doc states the defect outright (\"a single-pid `kill_pid` leaves\r\nthe wrapper's harness children orphaned + running\") — so IR-80 ships callers, not machinery. See\r\n[[RIDER 4]] for the two test-side callers.\r\n\r\n### IR-82 — a daemon death leaves NO record of who died: autostart decides on a socket ping, says \"no daemon\", and the successor overwrites the only handle on the corpse\r\n\r\n- **Status:** RULED 2026-09-07 11:07Z (doyle), drafted by hertz 11:04Z on doyle's dispatch (11:03Z: *\"the autostart\r\n  death-cause item is an IR, not a board item — mint it IR-82 in your thin PR\"*). Register on main\r\n  ends at IR-78; 79/80/81 are drafts in the same PR. · **Origin:** the fleet-daemon death on\r\n  hfenduleam at 08:03:14.87Z ([[RCA-FLEET-DAEMON-14444]]) whose cause is **still UNNAMED after a day\r\n  of measurement** — and the reason it is unnamed is this entry. Filed as a defect in\r\n  OBSERVABILITY, not in the death.\r\n- **⚠ THIS IS NOT \"find the killer.\"** The killer hunt is the RCA and stays open there. This entry\r\n  is about the fact that a killer hunt had to be run at all from a cold start, with a watcher script\r\n  written by hand after the event, because the product recorded nothing about the transition at the\r\n  moment it noticed it.\r\n\r\n- **THE MEASUREMENT — all four facts read at source, no build (gate was live on both boxes).**\r\n\r\n  1. **The daemon writes its pid.** `crates/spt-daemon/src/daemon.rs:471` —\r\n     `let _ = std::fs::write(daemon_pid_path(), std::process::id().to_string());`, into\r\n     `<spt_home>/daemon.pid` (`crates/spt-daemon/src/endpoint.rs:81`). Unconditional overwrite, no\r\n     read-before-write, no rotation, no history.\r\n  2. **Autostart never looks at it.** `ensure_running_outcome`\r\n     (`crates/spt-daemon/src/daemon.rs:686-724`) decides on `is_running()`, which is\r\n     `seedmap::ping(&seed_socket_name()).is_ok()` (`daemon.rs:598-600`) — **a socket ping and\r\n     nothing else.** The decision consults no pid, no mtime, no prior state.\r\n  3. **The breadcrumb it emits carries no identity.** `daemon.rs:721` —\r\n     `DAEMON_AUTOSTART: no daemon and no standing operator stop — starting one`. Deliberately\r\n     \"always-on, ids-free\" per its own comment, because its job is to be COUNTED (the convoy\r\n     serialization observable that `daemon_stop_convoy_e2e` asserts at :178/:237). That design is\r\n     correct for what it was built for and is exactly why it answers nothing here.\r\n  4. **Then the successor destroys the evidence.** The new daemon reaches :471 and overwrites\r\n     `daemon.pid` with its own pid. The dead pid, and the file mtime that bracketed its life, are\r\n     gone — overwritten by the very event that should have recorded them.\r\n\r\n- **THE SHARP FORM — the file is read ONLY in the state where it can tell you nothing.** The only\r\n  two readers of `daemon_pid_path()` in the tree are `crates/spt/src/cli.rs:8581` and `:8754` (both inside `cmd_daemon_status`, :8573), and\r\n  **both are gated on `running`** (`if running { let pid = read(...) }`). So `daemon.pid` is consulted\r\n  exclusively when a daemon is alive — when its contents are guaranteed fresh and merely restate\r\n  what the ping already proved — and is ignored in the one state where its staleness is the only\r\n  evidence anyone has. Its doc comment (`endpoint.rs:82-85`) says *\"a stale pid here is harmless\r\n  because callers probe the socket, never this file.\"* **That is true for LIVENESS and false for\r\n  FORENSICS**, and the entry is that the codebase has only ever considered the first reading.\r\n\r\n- **WHAT IT COST, concretely, on 2026-09-07.** Daemon pid 14444 died at 08:03:14.87Z inside the ci\r\n  Windows unit leg's nextest LIST phase; successor 48232 cold-started at 08:03:20Z and\r\n  `DAEMON_RESTART_RESUME`d every session, orphaning live agents' monitors and readers and handing at\r\n  least one agent a stale brief. Neither peer ran a kill. To get ANY signal at all I had to hand-write\r\n  an external watcher (`C:\\Users\\decid\\.spt-watch\\watch-daemon.ps1`, 1s cadence, identity re-verified\r\n  by image path AND creation time every poll) **after** the death, which by construction cannot\r\n  observe the event it was written for. 6600+ polls later the successor is alive and the original\r\n  death is still uncharacterized. A product-side record of the transition would have cost bytes.\r\n\r\n- **WHY THIS IS NOT THE CONVOY BREADCRUMB'S JOB, and must not be bolted onto it.**\r\n  `DAEMON_AUTOSTART` is load-bearing as a COUNTABLE line: `daemon_stop_convoy_e2e` asserts *exactly\r\n  one* appears under a storm (:178) and counts N under a deliberate race (:237). Adding identity\r\n  fields to that line risks the count and buries a forensic record inside a line whose contract is\r\n  its cardinality. **The record belongs in its own line and its own artifact.**\r\n\r\n- **REMEDY — RULED 2026-09-07 11:07Z (doyle), APPROVED as proposed with two refinements. Small,\r\n  product-side, no wire change.** doyle re-derived the census independently at `f3c8495b` (one\r\n  writer `daemon.rs:471`, two readers `cli.rs:8581` + `:8754`, both inside `if running`) before\r\n  ruling — the falsifiable claim below has been checked, not taken.\r\n  1. **Read before you clobber.** At `daemon.rs:471`, read the existing `daemon.pid` and its mtime\r\n     BEFORE the write; if it holds a pid that is not ours, emit a distinct, greppable line naming\r\n     the predecessor pid and how long ago the file was last touched — e.g.\r\n     `DAEMON_SUCCEEDS_PID: prior=<pid> prior_pidfile_age_ms=<n> reason=<socket-ping-failed>`. The\r\n     value is that the successor is the only process in the system that is guaranteed to run at\r\n     exactly the moment the question becomes askable.\r\n  2. **Keep one generation.** Rename the existing `daemon.pid` to `daemon.pid.prev` instead of\r\n     overwriting it (best-effort, same directory, same failure posture as today's `let _ =`). One\r\n     generation is enough to answer \"which pid did I replace, and when did it last write?\" and costs\r\n     no rotation policy.\r\n  3. **REFINED BY THE RULING — the discriminator is a FIELD, not a second line.** I proposed a\r\n     separate \"what the ping saw\" record; doyle collapsed it: `prior=<pid|none>` already separates\r\n     the two incidents, because `none` **is** the fresh-home case. One line, one field, no second\r\n     breadcrumb to keep in sync.\r\n  4. **ADDED BY THE RULING — `alive=<bool>`, from a by-number liveness READ at write time.** With\r\n     the prior pid in hand, read whether that number is still live and put the answer on the line.\r\n     It splits the two incidents that otherwise look identical: **`alive` prior = two daemons racing\r\n     the seed bind** (the convoy case), **dead prior = the corpse** (the 14444 case). This is a\r\n     READ, not a kill — #285's identity-before-kill rule binds kills and is not weakened here; a\r\n     by-number read that informs a log line commits no action on the pid.\r\n  5. **UNIT, specified by the ruling:** seed a pidfile with a fake pid and an aged mtime, run the\r\n     write path, assert the emitted fields (`prior`, `age_ms`, `alive`) AND the `daemon.pid.prev`\r\n     bytes. The `.prev` bytes are part of the assertion, not an afterthought — the generation kept\r\n     is the half that survives the process.\r\n  6. **NOT proposed, and the ruling kept it out:** a liveness change. `is_running()` must stay the socket ping — this entry does\r\n     not argue the pidfile should become a liveness signal, which is the exact mistake\r\n     `endpoint.rs:82-85` was written to prevent. The pidfile stays advisory; it just stops being\r\n     silently destroyed.\r\n\r\n- **LANE — SPLIT BY THE RULING, and the two halves ship separately.** The **IR-82 ENTRY** (this\r\n  text) rides hertz's IR-37 thin PR alongside IR-79/80/81. The **PRODUCT REMEDY** rides **#285's\r\n  lane** (todlando, post-W2) because it is the same pid-identity gate: #285 makes a kill read an\r\n  identity, this makes a successor read the identity it is about to erase. One lane, one owner,\r\n  one review of the pid-identity question. Do not implement the remedy in the thin PR.\r\n\r\n- **Kin:** [[RCA-FLEET-DAEMON-14444]] (the open incident this serves — IR-82 does not close it and\r\n  must not be read as closing it), [[IR-81]] (a pid is not an identity — the same lesson from the\r\n  KILL side; here it is the RECORD side), [[IR-80]]/[[IR-79]] (processes outliving what should have\r\n  accounted for them). The through-line doyle named at 10:22Z holds: *a pid is not an identity and a\r\n  pid is not a tree* — and IR-82 adds that **a pid nobody wrote down is not evidence.**\r\n\r\n- **Falsifiable claim, so it can be checked rather than believed:** at `f3c8495b` the tree contains\r\n  exactly ONE writer of `daemon_pid_path()` (`daemon.rs:471`) and exactly TWO readers\r\n  (`cli.rs:8581`, `cli.rs:8754`), both inside a `running` gate. If a future reader appears in an\r\n  unguarded path, this entry's premise weakens and it should be re-measured, not re-asserted.\r\n\r\n### IR-83 — a two-host rig addressed over the tailnet cannot receive INBOUND on Windows, and the whole rig population had only ever run the admitted direction\r\n\r\n- **Status:** OPEN, minted by hertz 2026-09-07 11:41Z on doyle's dispatch (11:40Z). **Provenance: the\r\n  mechanism below is DOYLE'S measurement, not mine** — eight probe arms, each with sender, listener\r\n  and output file, recorded in `GATE-W2-272-CHECKLIST.md` rows 11:36Z–11:39Z. I am off cargo on both\r\n  boxes and have re-measured none of it; this entry is the register form of his finding plus the\r\n  structural reading it supports. Board face: **F18**. Register slot: IR-83 (79/80/81/82 are the\r\n  same thin PR).\r\n- **THE FINDING, in one line:** two-host rigs must address peers by **LAN**, never the tailnet.\r\n\r\n- **HALF ONE — the tailnet ACL is per-node and ONE-WAY.** `hfenduleam` admits 9 sources and\r\n  `kitsubito` is **not** among them; `kitsubito` admits `hfenduleam`. So a rig cell needing INBOUND\r\n  to the Windows box over `100.x` fails **at the receiver**, and it fails there **whatever the host\r\n  firewall says** — which is why a host-firewall investigation can be run to completion, come back\r\n  clean, and explain nothing.\r\n\r\n- **HALF TWO — Windows defaults `BlockInbound`, and a hash-named test exe has no rule.** Test\r\n  binaries are built with hash-suffixed names, so a rule written against the *program* is keyed to a\r\n  name that changes on the next build. The stale `spt_net-d037…` rule is the precedent already in\r\n  the tree: a rule that was correct once, is present, greps fine, and admits nothing. **The durable\r\n  form is PORT-scoped, not program-scoped:** ports `7480-7499`, `remoteip` = the peer's LAN address,\r\n  added by the operator.\r\n\r\n- **WHY IT SURFACED ONLY NOW, and this is the part that generalizes.** The W2 helper cell is the\r\n  **first cell in the entire rig population that ever needed `kitsubito -> hfenduleam` inbound.**\r\n  W1's four xbox cells and golden's old-twohost job are all `hfenduleam -> kitsubito` — the admitted\r\n  direction. So the population had a **direction monoculture**, and a one-way ACL is invisible to a\r\n  suite that only ever runs the admitted way. Every green in that population was consistent with the\r\n  ACL being wide open and equally consistent with it being one-way; the suite could not tell the\r\n  difference, and nobody had reason to ask. **A capability exercised in only one direction is not\r\n  covered, it is merely unexamined** — the same shape as an assertion that only ever sees the\r\n  passing arm.\r\n\r\n- **THE SECOND STRUCTURAL POINT — a rule keyed to a MUTABLE identity is the lane's own through-line.**\r\n  A per-hash program rule is an exception bound to an identity the build changes underneath it,\r\n  exactly as [[IR-81]] is about a kill bound to a pid the OS may reassign and IR-80 Amendment 1's ENV\r\n  READ face is about a read bound to a process identity `exec` can change. Port-scoping replaces a\r\n  mutable identity with a stable property. That is the same remedy shape as reading an image path\r\n  before a kill and reporting an environment in-band: **stop keying on the thing that moves.** I am\r\n  flagging the rhyme, not claiming a fourth face — this is infrastructure config, not a code path,\r\n  and the amendment's standing prediction is about pid-shaped questions.\r\n\r\n- **FALSIFIABLE CLAIM (doyle's, recorded verbatim as the entry's test):** with the rig on **LAN\r\n  addresses AND the port-scoped rule present**, the helper cell's owner raw carries `WEB_SERVE_FOR`;\r\n  with **either** missing, it carries none. Both arms matter — this is a conjunction, so a single\r\n  green with one of the two absent would refute it, and a red with both present would too.\r\n\r\n- **WHAT THIS ENTRY DOES NOT CLAIM.** It does not say the host firewall was ever misconfigured; the\r\n  ACL half fails at the receiver independently. It does not close F17 or explain the vacuous-green\r\n  run (that was the mid-flight script rewrite — different cause, different fix, and the two were\r\n  live in the same hour, which is precisely why each needed its own named mechanism rather than one\r\n  story). It proposes no product change: both halves are rig addressing and operator-added firewall\r\n  config.\r\n\r\n- **REMEDY.** (1) Rig-side: address peers by LAN in two-host rigs, and make the tailnet address\r\n  unreachable-by-construction rather than merely unused, so a future rig cannot quietly pick it up.\r\n  (2) Operator-side: the port-scoped inbound rule (`7480-7499`, `remoteip` = peer LAN), replacing\r\n  per-hash program rules; the stale `spt_net-d037…` rule should be removed in the same pass so it\r\n  stops reading as coverage. (3) Population-side — **RULED 11:42Z (doyle), with a precision that\r\n  changes the shape:** this is NOT a new cell. **The W2 helper cell IS the first reverse-direction\r\n  cell**, and on LAN it exercises `kitsubito -> hfenduleam` inbound for real once the rule exists.\r\n  The remedy is therefore to **keep at least one reverse cell in the xbox battery permanently and\r\n  NAME it as the direction witness**, so its role is a stated property rather than an accident of\r\n  what W2 happened to need. A suite that only runs one way cannot discover the next one-way ACL\r\n  either, and the way that recurs is not \"nobody wrote the cell\" but \"the cell that had it stopped\r\n  being run.\"\r\n\r\n  **The hazard that follows from naming it, stated here so the naming is not decorative:** a witness\r\n  cell that is SKIPPED stops being a witness while still reporting green — the exact confusion this\r\n  lane already paid for, where a must-skip `role_b` PASS was indistinguishable from four cells that\r\n  no-opped. So the direction witness needs its skip to be loud: if it is filtered out, phase-reclassed,\r\n  or short-circuits on a missing precondition, that must read as ABSENT COVERAGE and not as a pass.\r\n  Whoever names it owns that half too. **Concrete enforcement, doyle-ruled 11:44Z and written up\r\n  as the RIDER 5 ADDENDUM:** the xbox driver's HELPER WITNESS verdict line already refuses a\r\n  `0.0x s` helper PASS and a `b.raw` without `WEB_SERVE_FOR outcome=registered`; it must ALSO\r\n  print `NOT-A-WITNESS` when the cell is absent from the LIST leg. Those first two are\r\n  *ran-but-vacuous*; absence is *never-ran*, and a verdict built only from the first two passes\r\n  it by omission — every refusal condition evaluates against output that does not exist, finds\r\n  nothing to object to, and falls through to green.\r\n\r\n- **GATING CLAUSE — added 2026-09-07 12:56Z on doyle's dispatch (gate reshape, same minute).** An\r\n  inbound-to-Windows cell in a two-host rig is **gated on the port-scoped rule being present**, and\r\n  without it the cell must **SKIP LOUDLY**: it may not run, may not report PASS, and may not be\r\n  silently filtered — its absence must render as ABSENT COVERAGE in the verdict, on the RIDER 5\r\n  ADDENDUM's `NOT-A-WITNESS:NEVER-RAN` face. The precondition is machine-readable, so the driver\r\n  reads `netsh` at start and the gate is a measured fact rather than a remembered one; a cell whose\r\n  precondition is unmet and which therefore emits nothing is exactly the case a verdict assembled\r\n  only from ran-but-vacuous refusals passes by omission. **This clause is what stops the rule's\r\n  ABSENCE from reading as the rig's health.**\r\n\r\n  **How the reshaped W2 F17 gate applies it (doyle 12:56Z, recorded, not re-measured by me — I am\r\n  still off cargo on both boxes).** With the rule absent 75+ minutes and no operator activity, and\r\n  golden carrying no cross-box `twohost_web`, the shortfall is a **rig blocker, not a golden one**.\r\n  So the HELPER WITNESS was reshaped to the **ONE-BOX pair on BOTH OSes** — doyle's gate tree on\r\n  Windows, a kitsubito clone at the tip on Linux with the rig shipped as the frozen copy — on the\r\n  basis that the 03:31Z one-box run at `f3c8495b` reproduced F17 end to end (A `outcome=unanswered`,\r\n  B `DISPATCH:4:Unknown`), i.e. the one-box pair drives the real dispatcher on both roles.\r\n  Mutation D must turn the classify unit cell red **and** the one-box helper cell red\r\n  (owner `family=Unknown`>0, `registered`=0) while deny/fetch stay green; revert dirty 0. The\r\n  cross-box pair still runs as the A->B regression (deny/fetch must PASS), and while the rule is\r\n  absent its helper/range TIMEOUTs are classified **F18-INFRA** — becoming a witness automatically\r\n  if the rule lands before the run, because the driver reads `netsh` at start.\r\n  **The cross-box helper witness therefore stays an OPEN rider on the operator's rule, not a land\r\n  blocker.** Note the shape this preserves: the reshape moves the witness to a pair that CAN run,\r\n  and leaves the direction it cannot exercise named and open — it does not let the one-box green\r\n  stand in for the direction coverage that is still missing. A one-box pair proves the dispatcher;\r\n  it cannot prove an inbound ACL, and nothing here claims it does.\r\n\r\n  **PROBE RESOLUTION — doyle 12:59Z, ADOPTED INTO THIS GATE (not deferred to the rider).** The\r\n  precondition read is now THREE-VALUE in `gate-w2-f17.sh`: `Rule Name` in stdout -> PRESENT,\r\n  `No rules match` -> ABSENT, empty stdout or anything else -> PROBE-FAILED. **PROBE-FAILED\r\n  classifies the cross-box helper/range as `UNCLASSIFIED: this run cannot tell INFRA from a real\r\n  red` — never F18-INFRA** — and xbox-D's skip line names the state. The raw probe (exit code +\r\n  first 3 lines) is printed into the driver log, so the classification is auditable after the fact\r\n  rather than inferred from what got bucketed. Exercised standalone on all three arms: real\r\n  `netsh` = exit 1 + `No rules match` -> ABSENT; forced bad args -> PROBE-FAILED; empty stdout ->\r\n  PROBE-FAILED.\r\n\r\n  **Recorded because it corrects the asker (me), not the implementer:** I proposed the three-value\r\n  shape AND, in the same message, proposed discriminating on the exit code. doyle's standalone\r\n  exercise measured `netsh` exiting **1 on a clean ABSENT**, so an exit-code discriminator would\r\n  have classified every legitimately-absent rule as an instrument fault — turning the run's most\r\n  common honest state into PROBE-FAILED and, with it, `UNCLASSIFIED`. The discriminator that landed\r\n  is STDOUT CONTENT. The general form belongs in the entry because it is the reason the third arm\r\n  needed measuring at all: **a CLI's exit code is a claim about the QUERY, not about the ANSWER**,\r\n  and an empty-but-correct result is reported non-zero by a great many tools. A third value added\r\n  to a probe needs its own evidence, obtained by making all three arms fire on purpose — which is\r\n  this lane's standing rule that a tool whose success path has never been made to fail on purpose\r\n  is untested, applied to a tool's FAILURE path instead.\r\n\r\n- **Kin:** [[IR-81]] and IR-80 Amendment 1 (keying on a mutable identity), the F17 riders (a witness\r\n  that never executed the direction it certifies).\r\n\r","startLine":4144,"lineNumbers":[4144,4145,4146,4147,4148,4149,4150,4151,4152,4153,4154,4155,4156,4157,4158,4159,4160,4161,4162,4163,4164,4165,4166,4167,4168,4169,4170,4171,4172,4173,4174,4175,4176,4177,4178,4179,4180,4181,4182,4183,4184,4185,4186,4187,4188,4189,4190,4191,4192,4193,4194,4195,4196,4197,4198,4199,4200,4201,4202,4203,4204,4205,4206,4207,4208,4209,4210,4211,4212,4213,4214,4215,4216,4217,4218,4219,4220,4221,4222,4223,4224,4225,4226,4227,4228,4229,4230,4231,4232,4233,4234,4235,4236,4237,4238,4239,4240,4241,4242,4243,4244,4245,4246,4247,4248,4249,4250,4251,4252,4253,4254,4255,4256,4257,4258,4259,4260,4261,4262,4263,4264,4265,4266,4267,4268,4269,4270,4271,4272,4273,4274,4275,4276,4277,4278,4279,4280,4281,4282,4283,4284,4285,4286,4287,4288,4289,4290,4291,4292,4293,4294,4295,4296,4297,4298,4299,4300,4301,4302,4303,4304,4305,4306,4307,4308,4309,4310,4311,4312,4313,4314,4315,4316,4317,4318,4319,4320,4321,4322,4323,4324,4325,4326,4327,4328,4329,4330,4331,4332,4333,4334,4335,4336,4337,4338,4339,4340,4341,4342,4343,4344,4345,4346,4347,4348,4349,4350,4351,4352,4353,4354,4355,4356,4357,4358,4359,4360,4361,4362,4363,4364,4365,4366,4367,4368,4369,4370,4371,4372,4373,4374,4375,4376,4377,4378,4379,4380,4381,4382,4383,4384,4385,4386,4387,4388,4389,4390,4391,4392,4393,4394,4395,4396,4397,4398,4399,4400,4401,4402,4403,4404,4405,4406,4407,4408,4409,4410,4411,4412,4413,4414,4415,4416,4417,4418,4419,4420,4421,4422,4423,4424,4425,4426,4427,4428,4429,4430,4431,4432,4433,4434,4435,4436,4437,4438,4439,4440,4441,4442,4443,4444,4445,4446,4447,4448,4449,4450,4451,4452,4453,4454,4455,4456,4457,4458,4459,4460,4461,4462,4463,4464,4465,4466,4467,4468,4469,4470,4471,4472,4473,4474,4475,4476,4477,4478,4479,4480,4481,4482,4483,4484,4485,4486,4487,4488,4489,4490,4491,4492,4493,4494,4495,4496,4497,4498,4499,4500,4501,4502,4503,4504,4505,4506,4507,4508,4509,4510,4511,4512,4513,4514,4515,4516,4517,4518,4519,4520,4521,4522,4523,4524,4525,4526,4527,4528,4529,4530,4531,4532,4533,4534,4535,4536,4537,4538,4539,4540,4541,4542,4543,4544,4545,4546,4547,4548,4549,4550,4551,4552,4553,4554,4555,4556,4557,4558,4559,4560,4561,4562,4563,4564,4565,4566,4567,4568,4569,4570,4571,4572,4573,4574,4575,4576,4577,4578,4579,4580,4581,4582,4583,4584,4585,4586,4587,4588,4589,4590,4591,4592,4593,4594,4595,4596,4597,4598,4599,4600,4601,4602,4603,4604,4605,4606,4607,4608,4609,4610,4611,4612,4613,4614,4615,4616,4617,4618,4619,4620,4621,4622,4623,4624,4625,4626,4627,4628,4629,4630,4631,4632,4633,4634,4635,4636,4637,4638,4639,4640,4641,4642,4643,4644,4645,4646,4647,4648,4649,4650,4651,4652,4653,4654,4655,4656,4657,4658,4659,4660,4661,4662,4663]},"fileSize":501961,"meta":{"source":{"type":"path","value":"C:\\Users\\decid\\Documents\\projects\\spt-core\\docs\\INFRA-REGISTER.md"},"truncation":{"direction":"head","truncatedBy":"lines","totalLines":5782,"totalBytes":42735,"outputLines":520,"outputBytes":42735,"shownRange":{"start":4144,"end":4663},"nextOffset":4664}}},"isError":false,"timestamp":1789094610902}}
{"type":"message","id":"ec1e8e71","parentId":"4d5901f7","timestamp":"2026-09-11T02:43:30.911Z","message":{"role":"toolResult","toolCallId":"call_IZtPuIzzW6suje5HQLQPZ5oP|fc_065c0d1976ecf9c2016aa36ad0795c87d1b8e4ea5b47e2bd2c","toolName":"read","content":[{"type":"text","text":"- **The two sites, read at source.** They are not even the same KIND of budget, which is the first\n  thing no reader can tell from the panel:\n  · `crates/spt/tests/contract_e2e.rs:393-407` — a **WALL** deadline,\n  `let deadline = Instant::now() + Duration::from_secs(30)`, panicking\n  `\"the brain pulse must ingest the commune into the live context tier\"`. **No elapsed.**\n  · `crates/spt-daemon/tests/sync.rs:98-110` — an **ITERATION** budget, `for _ in 0..400 {\n  net_streams(); sleep(25ms) }`, panicking `\"sync stream never appeared at the responder's broker\"`.\n  **No elapsed, no iteration count** — and its own comment calls it a \"10s budget\", which is a\n  NOMINAL sum of sleeps, not a wall bound: each `net_streams()` IPC call adds to it (hertz), so on a\n  loaded box the wall it grants is unknown and larger.\n- **Four costs MEASURED in this one triage, each traceable to the missing clock:**\n  1. **The panic reads as a CONTENT claim.** `contract_e2e.rs:403`'s message is what a 30 s DEADLINE\n     EXPIRY prints, and doyle relayed it to three peers as \"a clean content assert, not a stall\"\n     before opening the source.\n  2. **History cannot supply margins at all.** nextest suppresses passing output by default, so\n     **eight consecutive goldens** of this cell's Windows durations exist and **not one carries an\n     internal margin**. (`--success-output immediate` retains it — so this is recoverable going\n     forward, and was not, going back.)\n  3. **A whole-test total cannot locate the poll inside the test.** This conflation was committed\n     **five times in forty minutes by three different agents** — deployah twice (retracted both),\n     doyle once *in the message correcting deployah for it*, and it was caught each time by todlando\n     and hertz. A defect that costs three careful agents five errors in one morning is not a people\n     problem; the number they needed was not printed anywhere.\n  4. **A FAIL and a PASS are not the same quantity.** `wait_for_stream_except` is called at\n     `sync.rs:201`, with `serve_sync`, the puller join and every assertion AFTER it — so a failing\n     run **truncates** there. This cell FAILED at 58.77 s and PASSED at 61.304 s, and that 2.5 s gap\n     carries no information in either direction. It was read as an anomaly (\"it took LESS time and\n     still failed\") until the call site was opened.\n- **Remedy:** on expiry, print **elapsed, the budget, and iterations consumed**; where the poll waits\n  on another party, print that party's **PRODUCER PROGRESS** too — a watcher's own timings cannot\n  separate a slow watcher from a slow producer (hertz, todlando), which is the single fact this\n  triage most needed and could not get. Keep the content sentence; it is the panic's `{what}`, not\n  its whole body.\n- **Population CENSUSED 2026-09-10 (doyle), discharging the census this entry declared OWED — 323\n  poll sites detected, 304 of them classified blind. SUPERSEDED 2026-09-10 by the validation\n  below: 317 blind of a 321-site population, and the census's own coverage measured.** Read-only, run beside golden diagnostic 34458491560\n  without dispatching anything to either runner. Preserved with its method, its raw classification\n  and its discarded first attempt at `.spt/preserved/ir95-poll-census-20260910/`.\n- **Method, deliberately WORDING-INDEPENDENT.** Over the 212 tracked `*.rs` files under\n  `**/tests/**` plus `xtask/`, take every loop by SHAPE — `for _ in 0..N`, `while Instant::now() <\n  deadline`, `while <x>.elapsed() < budget`, bare `loop {` — keep it only if it SLEEPS (a poll, not\n  a spin) and can FAIL (`panic!`/`assert!`/`expect(`/`bail!` on its exit path), then ask whether its\n  failure path emits a MEASURED VALUE (`.elapsed()`, `.as_millis()`, an iteration counter). **String\n  literals are stripped before that question is asked**, so the word \"budget\" inside a panic message\n  cannot credit itself with a clock. **Result: 323 sites, 19 apparently clocked, 304 blind.**\n- **304 of 323 DETECTED CANDIDATES CLASSIFIED BLIND — a classifier count, NOT a proven floor.**\n  Stated at that strength on hertz's and todlando's correction of a stronger form this entry\n  briefly carried. What was actually spot-checked is the CLOCK bucket, and both errors found there\n  ran the same direction, undercounting blindness: `brain_read_deadline.rs:87` was credited from\n  elsewhere in the read window while its real failure path is `panic!(\"whole-carrier brain never\n  connected to {name}\")`, carrying no clock at all; `er_briefing_presented_e2e.rs:310` returns\n  `Some(started.elapsed())` on SUCCESS and a bare `None` on expiry.\n- **What that does NOT license.** Finding only false-CLOCK errors does not exclude false-BLIND ones,\n  and nothing here establishes POPULATION COVERAGE — whether the four loop shapes catch every poll\n  in the corpus is unvalidated, so a poll expressed as a helper, a retry combinator or an iterator\n  chain is uncounted and unmeasured. **No repository-wide `>= 94%` claim is made and none should be\n  repeated from this entry.** The honest sentence is: 304 classified BLIND among 323 detected\n  candidates, with the checked errors so far undercounting blindness. Validating both buckets and\n  the population is owed before any bound is asserted.\n- **VALIDATED 2026-09-10 (doyle) — all three owed checks discharged; the headline figure MOVES to\n  317 blind of 321.** Preserved as `VALIDATION.md` beside the census (machine-bound per [[IR-90]]).\n  (1) **The CLOCK bucket is now adjudicated EXHAUSTIVELY, not spot-checked**: of 19, only **4** emit\n  a measured value on their own expiry path, **13 were FALSE CLOCKs** and move to BLIND, and **2 are\n  not poll-failure sites at all**. Two mechanisms cover all 13, neither of them a wording problem:\n  **window bleed** (7 — four credited by a `const CONVERGE_BUDGET: Duration = …as_millis()…`\n  *declaration* 20-25 lines BELOW a bare `panic!(\"brain could not connect\")`, one by a different\n  loop 57 lines away, two by an unrelated `now_ms()` helper) and **condition-use, not emission** (6 —\n  `assert!(started.elapsed() < Duration::from_secs(30), \"…viewer_count={count:?}\")` reads the clock\n  in the PREDICATE and omits it from the MESSAGE). Stripping string literals stopped a message\n  crediting itself; it does not stop CODE crediting a site whose message stays silent.\n  (2) **False-BLINDs checked at last — a seeded 30-site random sample of the BLIND bucket\n  (`random.seed(95)`), hand-adjudicated: 30 of 30 confirm BLIND, zero false-BLIND.** By the rule of\n  three that bounds the false-BLIND rate at **<= ~10%, at 95% confidence** — a binomial upper bound\n  assuming the 30 are a simple random sample of the 304 and each site's adjudication is independent;\n  it is **not a deterministic guarantee**, and zero errors in 30 excludes nothing outright (hertz).\n  This is the FIRST check run in the\n  direction that would REDUCE the blind count and it found nothing; every error found in either\n  bucket still runs the other way.\n  (3) **Population coverage, measured against every `sleep` in the corpus** — 472 call-sites, 349\n  inside a detected window, 75 one-shot settles in no loop. The remaining 48 dedup to 47 loop\n  headers and **every one is explained, 0 unexplained**: **32** matched a census shape but cannot\n  FAIL within 60 lines (excluded BY DESIGN — the census counts loops that wait AND can fail), and\n  **15 are the detector's true false negatives**, a fixed nameable set:\n  `while std::time::Instant::now() < deadline` (the PATH-QUALIFIED spelling — the regex demands a\n  bare `Instant::now()`; `broker.rs:389`, `shellchan.rs:114`), `while !stop.load(Ordering::Relaxed)`,\n  `while <predicate>(…)` (`shell_relink_force_e2e.rs:194/241`, `shell_stale_online_e2e.rs:146`,\n  `redispatch.rs:269`), and one `for (a, b) in [...]`. Those 15 stay UNCLASSIFIED.\n  **The 32 change how this census may be QUOTED:** \"323 poll loops that wait and can fail\" silently\n  excludes 32 loops that wait and CANNOT fail at the poll — a defensible scope, but a scope, and the\n  sentence must carry it.\n- **Restated census, and the form to quote.** **321** sites in the adjudicated population (323 minus\n  2 membership errors from the CLOCK bucket; a 3rd — `net_worker_starve.rs:99`, a fixed-window\n  SAMPLER that always runs its window and has no expiry failure — turned up in the BLIND sample, so\n  3 errors in 49 hand-adjudicated sites means the population carries ~6% slop and **321 is not\n  exact**). **317** classified BLIND. **4** report a measurement. **15** poll loops outside the\n  detector's reach, unclassified. **Still not established, and still not to be written: that 317 is\n  a FLOOR, or any repository-wide rate.** One direction is now exhaustive, the other bounded at\n  <=10% by a 30-site sample — a bounded estimate, never a floor, and silent about the 15.\n- **A distinction this validation surfaced, and the remedy above should carry: \"emits a clock\" is\n  TWO different things.** `transport_death_eof.rs:540` prints the OBSERVED quantity\n  (`{canary_after}ms`); `er_brief_once_per_session_e2e.rs:288` prints the MARGIN (`elapsed=`). Only\n  the second tells a reader how close the budget came. 3 of the 4 surviving CLOCK sites report a\n  margin, 1 reports an observation — and **a binary CLOCK/BLIND classifier cannot see that\n  difference**, which is a limit of the census, not of the sites.\n- **One edit to preserved evidence, DECLARED.** `census.py` printed `<-- IR-95 population (a FLOOR)`\n  on its blind line. That sentence was retracted the day it was written, but the retraction never\n  reached the SCRIPT, so re-running the preserved artifact reprinted the withdrawn claim at whoever\n  ran it — a retraction does not propagate to the next reader on its own. The LABEL, and only the\n  label, is corrected in place; the computation is untouched and **still reproduces 323 / 19 / 304**,\n  which is what makes this validation checkable against it. The old line is quoted verbatim in\n  `VALIDATION.md`.\n- **A FIRST detector was discarded, and its failure is itself evidence for cost 1 above.** Keying on\n  expiry VOCABULARY (\"never\", \"timed out\", \"did not appear\") found 53 sites and **missed\n  `contract_e2e.rs:393` entirely — the very site this entry was filed from** — because its panic\n  message is a CONTENT sentence. A wording-keyed census is structurally blind to exactly the sites\n  whose messages mislead. Recorded so no one re-runs the cheap version and reports 53 as the answer.\n- **Positive control passes, and it found siblings.** Both originating sites appear, both BLIND:\n  `sync.rs:102` and `contract_e2e.rs:395`. The census also surfaced **two fixed budgets nobody had\n  noticed** — `sync.rs:89` (`0..300`, beside the `0..400` at :102) and `contract_e2e.rs:51`\n  (`0..400`, beside the wall deadline at :393). Concentration: `inject_control_wedge.rs` 18,\n  `broker.rs` 10, `endpoint_lifecycle.rs` 9, `dispatch.rs` 7, `twohost.rs` 7.\n- **PRODUCER-PROGRESS INSTRUMENT — SPEC, 2026-09-10, and the three readings it does NOT support.**\n  The remedy above asks for the waited-on party's progress because a watcher's own timings cannot\n  separate a slow watcher from a slow producer. `last_streams_seen=0` throughout is equally\n  consistent with \"the producer never produced\" and \"the watcher never saw it\", and neither arm of\n  the releases#294 pair can tell those apart. **Design (doyle), narrowed by hertz and todlando, who\n  independently found the same three defects in the first form of it.**\n  **INSTRUMENT** — rides the IPC the poll ALREADY makes, so it adds no channel and no budget: the\n  responder's broker surfaces, alongside `net_streams`, a monotonic `streams_created_total` AND a\n  monotonic `streams_retired_total` for the session, the sequence and age of its last transition,\n  and the STREAM IDS of the most recent transitions so the watcher can correlate them against the\n  ids it sees and skips. The watcher prints the producer's counters beside its own observation.\n  **SEMANTICS THAT MUST BE DECLARED BEFORE A SINGLE READING IS TAKEN** — a bare count is not a\n  measurement until these are fixed: WHICH HOOK \"created\" fires at (broker stream-table\n  registration? wire acceptance?), WHICH KEY the counter is scoped to and what a session rotation\n  does to it, the COUNTER LIFETIME and reset behaviour (process lifetime, per session, what a broker\n  restart does), and WHICH CLOCK the age is measured against and whether it is comparable to the\n  watcher's.\n  **WHAT EACH READING LICENSES, and what it does NOT** (the first form of this table asserted three\n  causal conclusions it had not earned):\n  · `created=0` at expiry means **no creation was RECORDED AT THAT HOOK, in that counter's scope,\n    for that session key**. It does **NOT** establish that the requester never produced, and it does\n    **NOT** exonerate the watcher — the hook may sit downstream of the real production, or be scoped\n    to a different key.\n  · `created>0` with every snapshot empty is **CONSISTENT WITH a visibility/registration defect AND\n    with a stream being created and retired entirely between two 25 ms polls**. On its own it\n    establishes neither; the retire counter and the ids are what separate them.\n  · **Creation AFTER expiry cannot be observed by a poll that has already stopped.** A last-change\n    age cannot supply it. That needs either a separately bounded, separately declared post-expiry\n    observation, or a retained producer event trace with timestamps.\n  **Process constraints:** separately versioned and announced, never slipped between arms of a\n  comparison, and the existing diagnostic patch and every budget stay UNCHANGED. Widening a budget\n  to make a red go green remains refused.\n- **`last_streams_seen` IS A FILTERED-VIEW COUNT — the sharpest narrowing this field has had, and it\n  applies to all three expiries in the releases#294 pair.** The poll calls `net_streams`; the broker\n  answers at `broker.rs:9546` `dispatch_net_streams` -> `host.dispatch_stream_infos()`\n  (`nethost.rs:1952`) -> `stream_infos_filtered(FALSE)`, and that filter drops TWO classes\n  SERVER-SIDE, before serialization (ADR-0040 decision 2, `REQ-STREAM-INFOS-SERVER-FILTER`):\n  `!e.retired.load(SeqCst)` and `!e.initiated_locally`. So `last_streams_seen=0` does **NOT** mean\n  the broker held no streams. It means **zero NON-RETIRED, NON-LOCALLY-INITIATED rows at that\n  instant** — a row that exists and is retired is invisible to the poll BY DESIGN. That is narrower\n  than the corrected form the RCA had settled on (\"the final snapshot was empty\"), and it is a\n  hook-scope fact of exactly the kind the preconditions above demand be pinned before any reading.\n- **A \"reuse it, no product change\" stage-1 design WAS PROPOSED AND IS WITHDRAWN — recorded because\n  the reason generalises.** `NetHost::stream_counts()` (`nethost.rs:1980`) is already surfaced as\n  `NetStatusReply.streams_held` (`broker.rs:9002`, `msg.rs:874`) and documents itself as\n  \"retirement-blind ON PURPOSE ... the resource truth the eligibility view hides\". Reading it beside\n  `net_streams` looked like it would separate \"filtered out\" from \"absent\" for free. It does not,\n  for four reasons, and hertz and todlando raised them independently:\n  · **Two IPC replies are not an atomic snapshot.** `filtered=0` then `held>0` is equally consistent\n    with a row ARRIVING BETWEEN THE TWO CALLS. Such a pair must never be labelled proof of filtering,\n    and needs call order and timestamps recorded if it is read at all.\n  · **`streams_held` is HOST-SCOPED, not exchange-scoped.** It counts unrelated and locally-initiated\n    rows the filtered view drops, so it cannot speak to the exchange under investigation without\n    stream-ID correlation; any conclusion from it stays aggregate.\n  · **It adds UNMEASURED perturbation** — a second IPC per iteration changes the 400-iteration\n    window's wall duration by an amount nobody has measured. **CORRECTED 2026-09-10 (hertz,\n    todlando), because the first form of this bullet was itself an overclaim in two ways and both\n    are instructive:** (a) it called perturbation DISQUALIFYING, and it is not — instrumentation\n    that perturbs timing can still be useful; the objection is ADDED, UNMEASURED perturbation, not\n    perturbation as such. (b) It SIZED that perturbation from two figures that cannot carry it: the\n    measured `net_streams` cost (60,295 us / 400 = 0.151 ms per iteration) does **not** estimate the\n    `net-status` cost — different call, different work — and the **0.29% expiry difference between\n    the two arms is NOT an established causal effect size**, only an unexplained gap between two n=1\n    observations. Sizing an observer effect against it treats an open question as a known\n    quantity.\n  · A single POST-EXPIRY sample avoids perturbing the poll but then describes LATER state, not\n    expiry state, and is still host-scoped.\n- **THE INSTRUMENT THAT SURVIVES REVIEW: a retained, EXCHANGE-CORRELATED create/retire TRACE**\n  (hertz and todlando, converged independently). Recorded per stream lifecycle transition on the\n  producer side — stream id, conn id, remote id, transition, `initiated_locally`, a monotonic\n  sequence and a timestamp on a NAMED clock — retained and read AFTER the fact rather than sampled\n  by the watcher, so it adds **NO POLL CALLS**. Say that, and not \"adds nothing\" (hertz): it still\n  adds PRODUCER-SIDE work that may affect arrival timing and resource contention, and **that effect\n  is unmeasured too**. The trace is preferable for having no watcher IPC, not for being free. It captures between-poll transitions,\n  which neither a gauge nor an in-loop counter can: **a gauge reads 0 for a stream created and\n  retired between two 25 ms polls exactly as it does for one never created.** Correlation to the\n  exchange is by stream id against the ids the watcher saw and skipped.\n  **MEASURED: it does not exist today** — zero stream-lifetime log lines in `nethost.rs`. So this is\n  a PRODUCT change, not a reuse, and it stays unbuilt while the product is frozen. Its preconditions\n  are the ones above, unchanged. Production AFTER the trace's retention window remains outside it.\n- **THE FIRST MARGINS THIS ENTRY PRODUCED UNDER CI / GOLDEN CONDITIONS — instrumented run\n  34458491560, 2026-09-10\n  (hertz's patch; deployah's lane; read independently by doyle).** The remedy above was argued for\n  on the ground that a poll which prints nothing cannot say how close it came. It has now printed\n  on a runner. **NOT the first margins overall** — the earlier local 12-leg run already reported\n  them, including a 392/400 (hertz, todlando). **The genuinely novel quantity is narrower and\n  sharper than \"CI margins\" (deployah): it is a FAILING poll's margin, which no local leg could\n  produce because all 12 of them PASSED.** A budget's behaviour at expiry is the one thing a green\n  run structurally cannot report, and it is the case the remedy exists for.\n  **The figure is the MAXIMUM AMONG SUCCESSFUL polls in this run — explicitly NOT a ceiling, and not\n  a bound on observations**: the poll that EXPIRED in this same run consumed 400/400 = 100%. So:\n  among the polls that PASSED on hfenduleam, both instrumented sites peak at ~63% of budget. The\n  seven successful\n  `[IR95-SYNC]` waits in that run are 92, 19, 72, 254, 21, 21 and 20 iterations — **worst 254/400 =\n  63.5%** (6.449393 s) — and the `[IR95-CONTRACT]` success consumed **18.857089 s of its 30.000 s\n  wall = 62.9%**. Two independent sites, two different budget KINDS, the same maximum-among-passes.\n  Headroom at that worst SUCCESSFUL case ~37%; the failing case had none left. **n=7 and n=1, one\n  box, one run: a first CI measurement, not a stability claim, and NO budget change is proposed on\n  it.**\n- **The iteration budget's WALL EQUIVALENT, also measured for the first time.** The expiring poll's\n  400 iterations cost **10.199907 s against 400 × 25 ms = 10.000 s nominal — 2.0% over**, with\n  per-iteration overhead ~0.5 ms against a 25 ms sleep (IPC 60.295 ms total, 0.151 ms per iteration,\n  **0.59% of elapsed**; sleep is 99.4%). So on this box in this run a \"400 iteration\" budget and a\n  \"~10.2 s wall\" are nearly the same object — the iteration budget did NOT silently become a\n  different budget under load. That bounds one standing worry about blind iteration counts, and it\n  is precisely the class of thing that stops being guessable the moment a clock prints. Box-local\n  and run-local; it is not a general result.\n- **A scope limit the instrumentation itself imposes, and a smaller ask than it first looks.**\n  `last_streams_seen` is an ASSIGNMENT per iteration (`sync.rs:111`), not an accumulator, so\n  `last_streams_seen=0` at expiry describes the FINAL iteration only — not all 400 (todlando's\n  correction; deployah withdrew the aggregate reading, doyle confirmed it at source). But the loop's\n  CONTROL FLOW already proves the interesting half for free: the `find()` at `:113` returns the\n  instant a non-skipped stream appears, so **reaching the expiry print IS proof that no non-skipped\n  stream was seen in any of the 400 SNAPSHOTS** — no aggregate trace required. **It does NOT mean\n  no stream EXISTED between snapshots** (hertz): the poll samples at 25 ms, and nothing here\n  observes the gaps. What is genuinely\n  unmeasured is only whether a SKIPPED stream was ever present, and `skip` is empty on that call.\n  An aggregate/per-iteration trace therefore buys less here than the gap first suggests.\n- **NOT ESTABLISHED: that all 304 deserve a clock.** The census SIZES the problem; it does not\n  schedule it, and it does not pre-judge which sites are worth the edit. Remedy triage is owed\n  separately and is the larger half.\n- **Kin:** [[IR-84]] (the one `PUMP_PEER_FAIL` arm the rigs fire was the only one carrying no clock —\n  **the same class in product code**; this entry is its test-corpus face), [[IR-85]] (budgets sized\n  against a box whose speed moved), [[IR-77]] (nothing stamps the spawn-to-first-log interval, so a\n  readiness red cannot say where the time went), [[IR-90]].\n- **Ripe when:** with the releases#294 instrumented base-vs-head comparison, which **cannot be run\n  without it** — the experiment's whole output is the margins these sites do not print. ·\n  **Size:** small per site; the census is the larger half.\n\n### IR-96 — the `daemon_stop_convoy_e2e` API-storm cell fails 3-of-3 under the HEAVY suite at the diagnostic tree while passing at the candidate in golden CI, and nothing yet separates instrumentation from box from product\n\n- **Status:** OPEN, **cause-unclassified** (todlando's and hertz's stipulation, adopted verbatim — a\n  triage placement here is NOT a finding of non-defect).\n- **Origin:** releases#294 / v0.69.0 Arm B, 2026-09-10, deployah executing at diagnostic tree\n  `ed8ecd94` (= candidate `a9e786b2` + the unlanded sync instrumentation, never merged).\n- **What:** `spt::daemon_stop_convoy_e2e stop_under_an_api_storm_stays_down_then_start_brings_up_exactly_one`\n  FAILED in **all three** Arm B runs, with durations **growing every run: 9.473s · 10.973s ·\n  14.553s**. Different signature from the #294 sync cell; nothing was filed against #294.\n- **THE DIFFERENTIAL that makes it worth an entry rather than a shrug:** the same cell shows **0\n  failures at the candidate** in golden 34481993681 Phase A on this same box — that run's single\n  failure was the sync cell (`3381 tests run: 3380 passed (6 slow, 5 leaky), 1 failed, 1 skipped`).\n  So: 0-of-1 at `a9e786b2` under CI load, 3-of-3 at `ed8ecd94` under local HEAVY load.\n- **WHAT THAT DOES NOT ESTABLISH.** It does **not** isolate the instrumentation or the box as the\n  only candidates — a condition-dependent or intermittent PRODUCT defect remains live, and a single\n  CI pass is not evidence of absence. doyle claimed that elimination on 2026-09-10 and **withdrew\n  it** the same hour under todlando's and hertz's correction; the withdrawal is recorded in\n  `.spt/preserved/gate-r2-34481993681-20260910/CLASSIFICATION-AMENDMENT-2-doyle.md`.\n- **Confounded by IR-97** (below): the three runs were not equivalent conditions.\n- **Ripe when:** any lane touches daemon stop/start convoy behaviour, OR a golden run reds this cell\n  at a candidate, OR someone runs the cell at `a9e786b2` under the same local HEAVY workload — that\n  last one is the cheap discriminator and nobody has run it. · **Size:** one targeted local run to\n  discriminate; unknown beyond that.\n\n### IR-97 — a suite that leaks a fixed cohort of child processes per invocation makes consecutive runs non-comparable, and the between-run accounting the protocol required was not enforced\n\n- **Status:** OPEN. **Protocol deviation** (hertz's framing, and it is stronger than \"confounder\":\n  the protocol ALREADY required between-run accounting — execution did not enforce it, so the fix is\n  enforcement, not a limitations paragraph).\n- **Origin:** releases#294 Arm B, 2026-09-10. Derived by doyle from deployah's preserved\n  `10-residual-births.json` against the run windows.\n- **What:** each Arm B suite leaked **exactly 6** `spt` children that outlived it; all **18** were\n  still alive at the post-B3 census. Because a process alive at census whose OS birth time falls in\n  an earlier window existed continuously through the runs between (pid + birth time is an identity),\n  the carried diag-tree residue was **0 during B1 · 6 during B2 · 12 during B3**. The three\n  \"repetitions\" were therefore not three equivalent conditions, and every cross-run comparison in\n  that arm inherits it.\n- **LIMITS, stated so the entry is not over-read:** process **COUNT** is measured; **LOAD is not** —\n  idle orphans may cost nothing, contention was UNMEASURED (overlap UNVERIFIED all arm), and this is\n  **not** a drift meter. It neither implicates nor excludes residue as a cause of the one expiry, and\n  it does not explain it: B3 carried twice the orphans and **passed**.\n- **Also unestablished, in both directions:** 18 censused against 15 killed shows only that three\n  were absent at the second read. \"Three self-exited\" needs exit evidence; \"I killed 18\" was\n  likewise refused by deployah at the time.\n- **Kin:** the LEAK rows every Arm A/B run reported; `REQ-HAZARD-RESUME-CUSTODY-ABA` (KH 7.51) and\n  KH 7.58 — the cleanup that resolved this was correctly scoped by **pid + image path**, leaving 15\n  unrelated `spt` processes untouched, where a name-based kill would have taken down the live agent\n  fleet including the gater's own session.\n- **Ripe when:** any repeated-run experiment is designed on this box — census BETWEEN runs, not only\n  at the end. · **Size:** a between-run census step plus a scoped reap in the harness.\n\n[Showing lines 5482-5781 of 5782. Use :5782 to continue]"}],"details":{"truncation":{"content":"- **The two sites, read at source.** They are not even the same KIND of budget, which is the first\r\n  thing no reader can tell from the panel:\r\n  · `crates/spt/tests/contract_e2e.rs:393-407` — a **WALL** deadline,\r\n  `let deadline = Instant::now() + Duration::from_secs(30)`, panicking\r\n  `\"the brain pulse must ingest the commune into the live context tier\"`. **No elapsed.**\r\n  · `crates/spt-daemon/tests/sync.rs:98-110` — an **ITERATION** budget, `for _ in 0..400 {\r\n  net_streams(); sleep(25ms) }`, panicking `\"sync stream never appeared at the responder's broker\"`.\r\n  **No elapsed, no iteration count** — and its own comment calls it a \"10s budget\", which is a\r\n  NOMINAL sum of sleeps, not a wall bound: each `net_streams()` IPC call adds to it (hertz), so on a\r\n  loaded box the wall it grants is unknown and larger.\r\n- **Four costs MEASURED in this one triage, each traceable to the missing clock:**\r\n  1. **The panic reads as a CONTENT claim.** `contract_e2e.rs:403`'s message is what a 30 s DEADLINE\r\n     EXPIRY prints, and doyle relayed it to three peers as \"a clean content assert, not a stall\"\r\n     before opening the source.\r\n  2. **History cannot supply margins at all.** nextest suppresses passing output by default, so\r\n     **eight consecutive goldens** of this cell's Windows durations exist and **not one carries an\r\n     internal margin**. (`--success-output immediate` retains it — so this is recoverable going\r\n     forward, and was not, going back.)\r\n  3. **A whole-test total cannot locate the poll inside the test.** This conflation was committed\r\n     **five times in forty minutes by three different agents** — deployah twice (retracted both),\r\n     doyle once *in the message correcting deployah for it*, and it was caught each time by todlando\r\n     and hertz. A defect that costs three careful agents five errors in one morning is not a people\r\n     problem; the number they needed was not printed anywhere.\r\n  4. **A FAIL and a PASS are not the same quantity.** `wait_for_stream_except` is called at\r\n     `sync.rs:201`, with `serve_sync`, the puller join and every assertion AFTER it — so a failing\r\n     run **truncates** there. This cell FAILED at 58.77 s and PASSED at 61.304 s, and that 2.5 s gap\r\n     carries no information in either direction. It was read as an anomaly (\"it took LESS time and\r\n     still failed\") until the call site was opened.\r\n- **Remedy:** on expiry, print **elapsed, the budget, and iterations consumed**; where the poll waits\r\n  on another party, print that party's **PRODUCER PROGRESS** too — a watcher's own timings cannot\r\n  separate a slow watcher from a slow producer (hertz, todlando), which is the single fact this\r\n  triage most needed and could not get. Keep the content sentence; it is the panic's `{what}`, not\r\n  its whole body.\r\n- **Population CENSUSED 2026-09-10 (doyle), discharging the census this entry declared OWED — 323\r\n  poll sites detected, 304 of them classified blind. SUPERSEDED 2026-09-10 by the validation\r\n  below: 317 blind of a 321-site population, and the census's own coverage measured.** Read-only, run beside golden diagnostic 34458491560\r\n  without dispatching anything to either runner. Preserved with its method, its raw classification\r\n  and its discarded first attempt at `.spt/preserved/ir95-poll-census-20260910/`.\r\n- **Method, deliberately WORDING-INDEPENDENT.** Over the 212 tracked `*.rs` files under\r\n  `**/tests/**` plus `xtask/`, take every loop by SHAPE — `for _ in 0..N`, `while Instant::now() <\r\n  deadline`, `while <x>.elapsed() < budget`, bare `loop {` — keep it only if it SLEEPS (a poll, not\r\n  a spin) and can FAIL (`panic!`/`assert!`/`expect(`/`bail!` on its exit path), then ask whether its\r\n  failure path emits a MEASURED VALUE (`.elapsed()`, `.as_millis()`, an iteration counter). **String\r\n  literals are stripped before that question is asked**, so the word \"budget\" inside a panic message\r\n  cannot credit itself with a clock. **Result: 323 sites, 19 apparently clocked, 304 blind.**\r\n- **304 of 323 DETECTED CANDIDATES CLASSIFIED BLIND — a classifier count, NOT a proven floor.**\r\n  Stated at that strength on hertz's and todlando's correction of a stronger form this entry\r\n  briefly carried. What was actually spot-checked is the CLOCK bucket, and both errors found there\r\n  ran the same direction, undercounting blindness: `brain_read_deadline.rs:87` was credited from\r\n  elsewhere in the read window while its real failure path is `panic!(\"whole-carrier brain never\r\n  connected to {name}\")`, carrying no clock at all; `er_briefing_presented_e2e.rs:310` returns\r\n  `Some(started.elapsed())` on SUCCESS and a bare `None` on expiry.\r\n- **What that does NOT license.** Finding only false-CLOCK errors does not exclude false-BLIND ones,\r\n  and nothing here establishes POPULATION COVERAGE — whether the four loop shapes catch every poll\r\n  in the corpus is unvalidated, so a poll expressed as a helper, a retry combinator or an iterator\r\n  chain is uncounted and unmeasured. **No repository-wide `>= 94%` claim is made and none should be\r\n  repeated from this entry.** The honest sentence is: 304 classified BLIND among 323 detected\r\n  candidates, with the checked errors so far undercounting blindness. Validating both buckets and\r\n  the population is owed before any bound is asserted.\r\n- **VALIDATED 2026-09-10 (doyle) — all three owed checks discharged; the headline figure MOVES to\r\n  317 blind of 321.** Preserved as `VALIDATION.md` beside the census (machine-bound per [[IR-90]]).\r\n  (1) **The CLOCK bucket is now adjudicated EXHAUSTIVELY, not spot-checked**: of 19, only **4** emit\r\n  a measured value on their own expiry path, **13 were FALSE CLOCKs** and move to BLIND, and **2 are\r\n  not poll-failure sites at all**. Two mechanisms cover all 13, neither of them a wording problem:\r\n  **window bleed** (7 — four credited by a `const CONVERGE_BUDGET: Duration = …as_millis()…`\r\n  *declaration* 20-25 lines BELOW a bare `panic!(\"brain could not connect\")`, one by a different\r\n  loop 57 lines away, two by an unrelated `now_ms()` helper) and **condition-use, not emission** (6 —\r\n  `assert!(started.elapsed() < Duration::from_secs(30), \"…viewer_count={count:?}\")` reads the clock\r\n  in the PREDICATE and omits it from the MESSAGE). Stripping string literals stopped a message\r\n  crediting itself; it does not stop CODE crediting a site whose message stays silent.\r\n  (2) **False-BLINDs checked at last — a seeded 30-site random sample of the BLIND bucket\r\n  (`random.seed(95)`), hand-adjudicated: 30 of 30 confirm BLIND, zero false-BLIND.** By the rule of\r\n  three that bounds the false-BLIND rate at **<= ~10%, at 95% confidence** — a binomial upper bound\r\n  assuming the 30 are a simple random sample of the 304 and each site's adjudication is independent;\r\n  it is **not a deterministic guarantee**, and zero errors in 30 excludes nothing outright (hertz).\r\n  This is the FIRST check run in the\r\n  direction that would REDUCE the blind count and it found nothing; every error found in either\r\n  bucket still runs the other way.\r\n  (3) **Population coverage, measured against every `sleep` in the corpus** — 472 call-sites, 349\r\n  inside a detected window, 75 one-shot settles in no loop. The remaining 48 dedup to 47 loop\r\n  headers and **every one is explained, 0 unexplained**: **32** matched a census shape but cannot\r\n  FAIL within 60 lines (excluded BY DESIGN — the census counts loops that wait AND can fail), and\r\n  **15 are the detector's true false negatives**, a fixed nameable set:\r\n  `while std::time::Instant::now() < deadline` (the PATH-QUALIFIED spelling — the regex demands a\r\n  bare `Instant::now()`; `broker.rs:389`, `shellchan.rs:114`), `while !stop.load(Ordering::Relaxed)`,\r\n  `while <predicate>(…)` (`shell_relink_force_e2e.rs:194/241`, `shell_stale_online_e2e.rs:146`,\r\n  `redispatch.rs:269`), and one `for (a, b) in [...]`. Those 15 stay UNCLASSIFIED.\r\n  **The 32 change how this census may be QUOTED:** \"323 poll loops that wait and can fail\" silently\r\n  excludes 32 loops that wait and CANNOT fail at the poll — a defensible scope, but a scope, and the\r\n  sentence must carry it.\r\n- **Restated census, and the form to quote.** **321** sites in the adjudicated population (323 minus\r\n  2 membership errors from the CLOCK bucket; a 3rd — `net_worker_starve.rs:99`, a fixed-window\r\n  SAMPLER that always runs its window and has no expiry failure — turned up in the BLIND sample, so\r\n  3 errors in 49 hand-adjudicated sites means the population carries ~6% slop and **321 is not\r\n  exact**). **317** classified BLIND. **4** report a measurement. **15** poll loops outside the\r\n  detector's reach, unclassified. **Still not established, and still not to be written: that 317 is\r\n  a FLOOR, or any repository-wide rate.** One direction is now exhaustive, the other bounded at\r\n  <=10% by a 30-site sample — a bounded estimate, never a floor, and silent about the 15.\r\n- **A distinction this validation surfaced, and the remedy above should carry: \"emits a clock\" is\r\n  TWO different things.** `transport_death_eof.rs:540` prints the OBSERVED quantity\r\n  (`{canary_after}ms`); `er_brief_once_per_session_e2e.rs:288` prints the MARGIN (`elapsed=`). Only\r\n  the second tells a reader how close the budget came. 3 of the 4 surviving CLOCK sites report a\r\n  margin, 1 reports an observation — and **a binary CLOCK/BLIND classifier cannot see that\r\n  difference**, which is a limit of the census, not of the sites.\r\n- **One edit to preserved evidence, DECLARED.** `census.py` printed `<-- IR-95 population (a FLOOR)`\r\n  on its blind line. That sentence was retracted the day it was written, but the retraction never\r\n  reached the SCRIPT, so re-running the preserved artifact reprinted the withdrawn claim at whoever\r\n  ran it — a retraction does not propagate to the next reader on its own. The LABEL, and only the\r\n  label, is corrected in place; the computation is untouched and **still reproduces 323 / 19 / 304**,\r\n  which is what makes this validation checkable against it. The old line is quoted verbatim in\r\n  `VALIDATION.md`.\r\n- **A FIRST detector was discarded, and its failure is itself evidence for cost 1 above.** Keying on\r\n  expiry VOCABULARY (\"never\", \"timed out\", \"did not appear\") found 53 sites and **missed\r\n  `contract_e2e.rs:393` entirely — the very site this entry was filed from** — because its panic\r\n  message is a CONTENT sentence. A wording-keyed census is structurally blind to exactly the sites\r\n  whose messages mislead. Recorded so no one re-runs the cheap version and reports 53 as the answer.\r\n- **Positive control passes, and it found siblings.** Both originating sites appear, both BLIND:\r\n  `sync.rs:102` and `contract_e2e.rs:395`. The census also surfaced **two fixed budgets nobody had\r\n  noticed** — `sync.rs:89` (`0..300`, beside the `0..400` at :102) and `contract_e2e.rs:51`\r\n  (`0..400`, beside the wall deadline at :393). Concentration: `inject_control_wedge.rs` 18,\r\n  `broker.rs` 10, `endpoint_lifecycle.rs` 9, `dispatch.rs` 7, `twohost.rs` 7.\r\n- **PRODUCER-PROGRESS INSTRUMENT — SPEC, 2026-09-10, and the three readings it does NOT support.**\r\n  The remedy above asks for the waited-on party's progress because a watcher's own timings cannot\r\n  separate a slow watcher from a slow producer. `last_streams_seen=0` throughout is equally\r\n  consistent with \"the producer never produced\" and \"the watcher never saw it\", and neither arm of\r\n  the releases#294 pair can tell those apart. **Design (doyle), narrowed by hertz and todlando, who\r\n  independently found the same three defects in the first form of it.**\r\n  **INSTRUMENT** — rides the IPC the poll ALREADY makes, so it adds no channel and no budget: the\r\n  responder's broker surfaces, alongside `net_streams`, a monotonic `streams_created_total` AND a\r\n  monotonic `streams_retired_total` for the session, the sequence and age of its last transition,\r\n  and the STREAM IDS of the most recent transitions so the watcher can correlate them against the\r\n  ids it sees and skips. The watcher prints the producer's counters beside its own observation.\r\n  **SEMANTICS THAT MUST BE DECLARED BEFORE A SINGLE READING IS TAKEN** — a bare count is not a\r\n  measurement until these are fixed: WHICH HOOK \"created\" fires at (broker stream-table\r\n  registration? wire acceptance?), WHICH KEY the counter is scoped to and what a session rotation\r\n  does to it, the COUNTER LIFETIME and reset behaviour (process lifetime, per session, what a broker\r\n  restart does), and WHICH CLOCK the age is measured against and whether it is comparable to the\r\n  watcher's.\r\n  **WHAT EACH READING LICENSES, and what it does NOT** (the first form of this table asserted three\r\n  causal conclusions it had not earned):\r\n  · `created=0` at expiry means **no creation was RECORDED AT THAT HOOK, in that counter's scope,\r\n    for that session key**. It does **NOT** establish that the requester never produced, and it does\r\n    **NOT** exonerate the watcher — the hook may sit downstream of the real production, or be scoped\r\n    to a different key.\r\n  · `created>0` with every snapshot empty is **CONSISTENT WITH a visibility/registration defect AND\r\n    with a stream being created and retired entirely between two 25 ms polls**. On its own it\r\n    establishes neither; the retire counter and the ids are what separate them.\r\n  · **Creation AFTER expiry cannot be observed by a poll that has already stopped.** A last-change\r\n    age cannot supply it. That needs either a separately bounded, separately declared post-expiry\r\n    observation, or a retained producer event trace with timestamps.\r\n  **Process constraints:** separately versioned and announced, never slipped between arms of a\r\n  comparison, and the existing diagnostic patch and every budget stay UNCHANGED. Widening a budget\r\n  to make a red go green remains refused.\r\n- **`last_streams_seen` IS A FILTERED-VIEW COUNT — the sharpest narrowing this field has had, and it\r\n  applies to all three expiries in the releases#294 pair.** The poll calls `net_streams`; the broker\r\n  answers at `broker.rs:9546` `dispatch_net_streams` -> `host.dispatch_stream_infos()`\r\n  (`nethost.rs:1952`) -> `stream_infos_filtered(FALSE)`, and that filter drops TWO classes\r\n  SERVER-SIDE, before serialization (ADR-0040 decision 2, `REQ-STREAM-INFOS-SERVER-FILTER`):\r\n  `!e.retired.load(SeqCst)` and `!e.initiated_locally`. So `last_streams_seen=0` does **NOT** mean\r\n  the broker held no streams. It means **zero NON-RETIRED, NON-LOCALLY-INITIATED rows at that\r\n  instant** — a row that exists and is retired is invisible to the poll BY DESIGN. That is narrower\r\n  than the corrected form the RCA had settled on (\"the final snapshot was empty\"), and it is a\r\n  hook-scope fact of exactly the kind the preconditions above demand be pinned before any reading.\r\n- **A \"reuse it, no product change\" stage-1 design WAS PROPOSED AND IS WITHDRAWN — recorded because\r\n  the reason generalises.** `NetHost::stream_counts()` (`nethost.rs:1980`) is already surfaced as\r\n  `NetStatusReply.streams_held` (`broker.rs:9002`, `msg.rs:874`) and documents itself as\r\n  \"retirement-blind ON PURPOSE ... the resource truth the eligibility view hides\". Reading it beside\r\n  `net_streams` looked like it would separate \"filtered out\" from \"absent\" for free. It does not,\r\n  for four reasons, and hertz and todlando raised them independently:\r\n  · **Two IPC replies are not an atomic snapshot.** `filtered=0` then `held>0` is equally consistent\r\n    with a row ARRIVING BETWEEN THE TWO CALLS. Such a pair must never be labelled proof of filtering,\r\n    and needs call order and timestamps recorded if it is read at all.\r\n  · **`streams_held` is HOST-SCOPED, not exchange-scoped.** It counts unrelated and locally-initiated\r\n    rows the filtered view drops, so it cannot speak to the exchange under investigation without\r\n    stream-ID correlation; any conclusion from it stays aggregate.\r\n  · **It adds UNMEASURED perturbation** — a second IPC per iteration changes the 400-iteration\r\n    window's wall duration by an amount nobody has measured. **CORRECTED 2026-09-10 (hertz,\r\n    todlando), because the first form of this bullet was itself an overclaim in two ways and both\r\n    are instructive:** (a) it called perturbation DISQUALIFYING, and it is not — instrumentation\r\n    that perturbs timing can still be useful; the objection is ADDED, UNMEASURED perturbation, not\r\n    perturbation as such. (b) It SIZED that perturbation from two figures that cannot carry it: the\r\n    measured `net_streams` cost (60,295 us / 400 = 0.151 ms per iteration) does **not** estimate the\r\n    `net-status` cost — different call, different work — and the **0.29% expiry difference between\r\n    the two arms is NOT an established causal effect size**, only an unexplained gap between two n=1\r\n    observations. Sizing an observer effect against it treats an open question as a known\r\n    quantity.\r\n  · A single POST-EXPIRY sample avoids perturbing the poll but then describes LATER state, not\r\n    expiry state, and is still host-scoped.\r\n- **THE INSTRUMENT THAT SURVIVES REVIEW: a retained, EXCHANGE-CORRELATED create/retire TRACE**\r\n  (hertz and todlando, converged independently). Recorded per stream lifecycle transition on the\r\n  producer side — stream id, conn id, remote id, transition, `initiated_locally`, a monotonic\r\n  sequence and a timestamp on a NAMED clock — retained and read AFTER the fact rather than sampled\r\n  by the watcher, so it adds **NO POLL CALLS**. Say that, and not \"adds nothing\" (hertz): it still\r\n  adds PRODUCER-SIDE work that may affect arrival timing and resource contention, and **that effect\r\n  is unmeasured too**. The trace is preferable for having no watcher IPC, not for being free. It captures between-poll transitions,\r\n  which neither a gauge nor an in-loop counter can: **a gauge reads 0 for a stream created and\r\n  retired between two 25 ms polls exactly as it does for one never created.** Correlation to the\r\n  exchange is by stream id against the ids the watcher saw and skipped.\r\n  **MEASURED: it does not exist today** — zero stream-lifetime log lines in `nethost.rs`. So this is\r\n  a PRODUCT change, not a reuse, and it stays unbuilt while the product is frozen. Its preconditions\r\n  are the ones above, unchanged. Production AFTER the trace's retention window remains outside it.\r\n- **THE FIRST MARGINS THIS ENTRY PRODUCED UNDER CI / GOLDEN CONDITIONS — instrumented run\r\n  34458491560, 2026-09-10\r\n  (hertz's patch; deployah's lane; read independently by doyle).** The remedy above was argued for\r\n  on the ground that a poll which prints nothing cannot say how close it came. It has now printed\r\n  on a runner. **NOT the first margins overall** — the earlier local 12-leg run already reported\r\n  them, including a 392/400 (hertz, todlando). **The genuinely novel quantity is narrower and\r\n  sharper than \"CI margins\" (deployah): it is a FAILING poll's margin, which no local leg could\r\n  produce because all 12 of them PASSED.** A budget's behaviour at expiry is the one thing a green\r\n  run structurally cannot report, and it is the case the remedy exists for.\r\n  **The figure is the MAXIMUM AMONG SUCCESSFUL polls in this run — explicitly NOT a ceiling, and not\r\n  a bound on observations**: the poll that EXPIRED in this same run consumed 400/400 = 100%. So:\r\n  among the polls that PASSED on hfenduleam, both instrumented sites peak at ~63% of budget. The\r\n  seven successful\r\n  `[IR95-SYNC]` waits in that run are 92, 19, 72, 254, 21, 21 and 20 iterations — **worst 254/400 =\r\n  63.5%** (6.449393 s) — and the `[IR95-CONTRACT]` success consumed **18.857089 s of its 30.000 s\r\n  wall = 62.9%**. Two independent sites, two different budget KINDS, the same maximum-among-passes.\r\n  Headroom at that worst SUCCESSFUL case ~37%; the failing case had none left. **n=7 and n=1, one\r\n  box, one run: a first CI measurement, not a stability claim, and NO budget change is proposed on\r\n  it.**\r\n- **The iteration budget's WALL EQUIVALENT, also measured for the first time.** The expiring poll's\r\n  400 iterations cost **10.199907 s against 400 × 25 ms = 10.000 s nominal — 2.0% over**, with\r\n  per-iteration overhead ~0.5 ms against a 25 ms sleep (IPC 60.295 ms total, 0.151 ms per iteration,\r\n  **0.59% of elapsed**; sleep is 99.4%). So on this box in this run a \"400 iteration\" budget and a\r\n  \"~10.2 s wall\" are nearly the same object — the iteration budget did NOT silently become a\r\n  different budget under load. That bounds one standing worry about blind iteration counts, and it\r\n  is precisely the class of thing that stops being guessable the moment a clock prints. Box-local\r\n  and run-local; it is not a general result.\r\n- **A scope limit the instrumentation itself imposes, and a smaller ask than it first looks.**\r\n  `last_streams_seen` is an ASSIGNMENT per iteration (`sync.rs:111`), not an accumulator, so\r\n  `last_streams_seen=0` at expiry describes the FINAL iteration only — not all 400 (todlando's\r\n  correction; deployah withdrew the aggregate reading, doyle confirmed it at source). But the loop's\r\n  CONTROL FLOW already proves the interesting half for free: the `find()` at `:113` returns the\r\n  instant a non-skipped stream appears, so **reaching the expiry print IS proof that no non-skipped\r\n  stream was seen in any of the 400 SNAPSHOTS** — no aggregate trace required. **It does NOT mean\r\n  no stream EXISTED between snapshots** (hertz): the poll samples at 25 ms, and nothing here\r\n  observes the gaps. What is genuinely\r\n  unmeasured is only whether a SKIPPED stream was ever present, and `skip` is empty on that call.\r\n  An aggregate/per-iteration trace therefore buys less here than the gap first suggests.\r\n- **NOT ESTABLISHED: that all 304 deserve a clock.** The census SIZES the problem; it does not\r\n  schedule it, and it does not pre-judge which sites are worth the edit. Remedy triage is owed\r\n  separately and is the larger half.\r\n- **Kin:** [[IR-84]] (the one `PUMP_PEER_FAIL` arm the rigs fire was the only one carrying no clock —\r\n  **the same class in product code**; this entry is its test-corpus face), [[IR-85]] (budgets sized\r\n  against a box whose speed moved), [[IR-77]] (nothing stamps the spawn-to-first-log interval, so a\r\n  readiness red cannot say where the time went), [[IR-90]].\r\n- **Ripe when:** with the releases#294 instrumented base-vs-head comparison, which **cannot be run\r\n  without it** — the experiment's whole output is the margins these sites do not print. ·\r\n  **Size:** small per site; the census is the larger half.\r\n\r\n### IR-96 — the `daemon_stop_convoy_e2e` API-storm cell fails 3-of-3 under the HEAVY suite at the diagnostic tree while passing at the candidate in golden CI, and nothing yet separates instrumentation from box from product\r\n\r\n- **Status:** OPEN, **cause-unclassified** (todlando's and hertz's stipulation, adopted verbatim — a\r\n  triage placement here is NOT a finding of non-defect).\r\n- **Origin:** releases#294 / v0.69.0 Arm B, 2026-09-10, deployah executing at diagnostic tree\r\n  `ed8ecd94` (= candidate `a9e786b2` + the unlanded sync instrumentation, never merged).\r\n- **What:** `spt::daemon_stop_convoy_e2e stop_under_an_api_storm_stays_down_then_start_brings_up_exactly_one`\r\n  FAILED in **all three** Arm B runs, with durations **growing every run: 9.473s · 10.973s ·\r\n  14.553s**. Different signature from the #294 sync cell; nothing was filed against #294.\r\n- **THE DIFFERENTIAL that makes it worth an entry rather than a shrug:** the same cell shows **0\r\n  failures at the candidate** in golden 34481993681 Phase A on this same box — that run's single\r\n  failure was the sync cell (`3381 tests run: 3380 passed (6 slow, 5 leaky), 1 failed, 1 skipped`).\r\n  So: 0-of-1 at `a9e786b2` under CI load, 3-of-3 at `ed8ecd94` under local HEAVY load.\r\n- **WHAT THAT DOES NOT ESTABLISH.** It does **not** isolate the instrumentation or the box as the\r\n  only candidates — a condition-dependent or intermittent PRODUCT defect remains live, and a single\r\n  CI pass is not evidence of absence. doyle claimed that elimination on 2026-09-10 and **withdrew\r\n  it** the same hour under todlando's and hertz's correction; the withdrawal is recorded in\r\n  `.spt/preserved/gate-r2-34481993681-20260910/CLASSIFICATION-AMENDMENT-2-doyle.md`.\r\n- **Confounded by IR-97** (below): the three runs were not equivalent conditions.\r\n- **Ripe when:** any lane touches daemon stop/start convoy behaviour, OR a golden run reds this cell\r\n  at a candidate, OR someone runs the cell at `a9e786b2` under the same local HEAVY workload — that\r\n  last one is the cheap discriminator and nobody has run it. · **Size:** one targeted local run to\r\n  discriminate; unknown beyond that.\r\n\r\n### IR-97 — a suite that leaks a fixed cohort of child processes per invocation makes consecutive runs non-comparable, and the between-run accounting the protocol required was not enforced\r\n\r\n- **Status:** OPEN. **Protocol deviation** (hertz's framing, and it is stronger than \"confounder\":\r\n  the protocol ALREADY required between-run accounting — execution did not enforce it, so the fix is\r\n  enforcement, not a limitations paragraph).\r\n- **Origin:** releases#294 Arm B, 2026-09-10. Derived by doyle from deployah's preserved\r\n  `10-residual-births.json` against the run windows.\r\n- **What:** each Arm B suite leaked **exactly 6** `spt` children that outlived it; all **18** were\r\n  still alive at the post-B3 census. Because a process alive at census whose OS birth time falls in\r\n  an earlier window existed continuously through the runs between (pid + birth time is an identity),\r\n  the carried diag-tree residue was **0 during B1 · 6 during B2 · 12 during B3**. The three\r\n  \"repetitions\" were therefore not three equivalent conditions, and every cross-run comparison in\r\n  that arm inherits it.\r\n- **LIMITS, stated so the entry is not over-read:** process **COUNT** is measured; **LOAD is not** —\r\n  idle orphans may cost nothing, contention was UNMEASURED (overlap UNVERIFIED all arm), and this is\r\n  **not** a drift meter. It neither implicates nor excludes residue as a cause of the one expiry, and\r\n  it does not explain it: B3 carried twice the orphans and **passed**.\r\n- **Also unestablished, in both directions:** 18 censused against 15 killed shows only that three\r\n  were absent at the second read. \"Three self-exited\" needs exit evidence; \"I killed 18\" was\r\n  likewise refused by deployah at the time.\r\n- **Kin:** the LEAK rows every Arm A/B run reported; `REQ-HAZARD-RESUME-CUSTODY-ABA` (KH 7.51) and\r\n  KH 7.58 — the cleanup that resolved this was correctly scoped by **pid + image path**, leaving 15\r\n  unrelated `spt` processes untouched, where a name-based kill would have taken down the live agent\r\n  fleet including the gater's own session.\r\n- **Ripe when:** any repeated-run experiment is designed on this box — census BETWEEN runs, not only\r\n  at the end. · **Size:** a between-run census step plus a scoped reap in the harness.\r","truncated":true,"truncatedBy":"lines","totalLines":301,"totalBytes":27143,"outputLines":300,"outputBytes":27143,"lastLinePartial":false,"firstLineExceedsLimit":false},"totalLines":5782,"displayContent":{"text":"- **The two sites, read at source.** They are not even the same KIND of budget, which is the first\r\n  thing no reader can tell from the panel:\r\n  · `crates/spt/tests/contract_e2e.rs:393-407` — a **WALL** deadline,\r\n  `let deadline = Instant::now() + Duration::from_secs(30)`, panicking\r\n  `\"the brain pulse must ingest the commune into the live context tier\"`. **No elapsed.**\r\n  · `crates/spt-daemon/tests/sync.rs:98-110` — an **ITERATION** budget, `for _ in 0..400 {\r\n  net_streams(); sleep(25ms) }`, panicking `\"sync stream never appeared at the responder's broker\"`.\r\n  **No elapsed, no iteration count** — and its own comment calls it a \"10s budget\", which is a\r\n  NOMINAL sum of sleeps, not a wall bound: each `net_streams()` IPC call adds to it (hertz), so on a\r\n  loaded box the wall it grants is unknown and larger.\r\n- **Four costs MEASURED in this one triage, each traceable to the missing clock:**\r\n  1. **The panic reads as a CONTENT claim.** `contract_e2e.rs:403`'s message is what a 30 s DEADLINE\r\n     EXPIRY prints, and doyle relayed it to three peers as \"a clean content assert, not a stall\"\r\n     before opening the source.\r\n  2. **History cannot supply margins at all.** nextest suppresses passing output by default, so\r\n     **eight consecutive goldens** of this cell's Windows durations exist and **not one carries an\r\n     internal margin**. (`--success-output immediate` retains it — so this is recoverable going\r\n     forward, and was not, going back.)\r\n  3. **A whole-test total cannot locate the poll inside the test.** This conflation was committed\r\n     **five times in forty minutes by three different agents** — deployah twice (retracted both),\r\n     doyle once *in the message correcting deployah for it*, and it was caught each time by todlando\r\n     and hertz. A defect that costs three careful agents five errors in one morning is not a people\r\n     problem; the number they needed was not printed anywhere.\r\n  4. **A FAIL and a PASS are not the same quantity.** `wait_for_stream_except` is called at\r\n     `sync.rs:201`, with `serve_sync`, the puller join and every assertion AFTER it — so a failing\r\n     run **truncates** there. This cell FAILED at 58.77 s and PASSED at 61.304 s, and that 2.5 s gap\r\n     carries no information in either direction. It was read as an anomaly (\"it took LESS time and\r\n     still failed\") until the call site was opened.\r\n- **Remedy:** on expiry, print **elapsed, the budget, and iterations consumed**; where the poll waits\r\n  on another party, print that party's **PRODUCER PROGRESS** too — a watcher's own timings cannot\r\n  separate a slow watcher from a slow producer (hertz, todlando), which is the single fact this\r\n  triage most needed and could not get. Keep the content sentence; it is the panic's `{what}`, not\r\n  its whole body.\r\n- **Population CENSUSED 2026-09-10 (doyle), discharging the census this entry declared OWED — 323\r\n  poll sites detected, 304 of them classified blind. SUPERSEDED 2026-09-10 by the validation\r\n  below: 317 blind of a 321-site population, and the census's own coverage measured.** Read-only, run beside golden diagnostic 34458491560\r\n  without dispatching anything to either runner. Preserved with its method, its raw classification\r\n  and its discarded first attempt at `.spt/preserved/ir95-poll-census-20260910/`.\r\n- **Method, deliberately WORDING-INDEPENDENT.** Over the 212 tracked `*.rs` files under\r\n  `**/tests/**` plus `xtask/`, take every loop by SHAPE — `for _ in 0..N`, `while Instant::now() <\r\n  deadline`, `while <x>.elapsed() < budget`, bare `loop {` — keep it only if it SLEEPS (a poll, not\r\n  a spin) and can FAIL (`panic!`/`assert!`/`expect(`/`bail!` on its exit path), then ask whether its\r\n  failure path emits a MEASURED VALUE (`.elapsed()`, `.as_millis()`, an iteration counter). **String\r\n  literals are stripped before that question is asked**, so the word \"budget\" inside a panic message\r\n  cannot credit itself with a clock. **Result: 323 sites, 19 apparently clocked, 304 blind.**\r\n- **304 of 323 DETECTED CANDIDATES CLASSIFIED BLIND — a classifier count, NOT a proven floor.**\r\n  Stated at that strength on hertz's and todlando's correction of a stronger form this entry\r\n  briefly carried. What was actually spot-checked is the CLOCK bucket, and both errors found there\r\n  ran the same direction, undercounting blindness: `brain_read_deadline.rs:87` was credited from\r\n  elsewhere in the read window while its real failure path is `panic!(\"whole-carrier brain never\r\n  connected to {name}\")`, carrying no clock at all; `er_briefing_presented_e2e.rs:310` returns\r\n  `Some(started.elapsed())` on SUCCESS and a bare `None` on expiry.\r\n- **What that does NOT license.** Finding only false-CLOCK errors does not exclude false-BLIND ones,\r\n  and nothing here establishes POPULATION COVERAGE — whether the four loop shapes catch every poll\r\n  in the corpus is unvalidated, so a poll expressed as a helper, a retry combinator or an iterator\r\n  chain is uncounted and unmeasured. **No repository-wide `>= 94%` claim is made and none should be\r\n  repeated from this entry.** The honest sentence is: 304 classified BLIND among 323 detected\r\n  candidates, with the checked errors so far undercounting blindness. Validating both buckets and\r\n  the population is owed before any bound is asserted.\r\n- **VALIDATED 2026-09-10 (doyle) — all three owed checks discharged; the headline figure MOVES to\r\n  317 blind of 321.** Preserved as `VALIDATION.md` beside the census (machine-bound per [[IR-90]]).\r\n  (1) **The CLOCK bucket is now adjudicated EXHAUSTIVELY, not spot-checked**: of 19, only **4** emit\r\n  a measured value on their own expiry path, **13 were FALSE CLOCKs** and move to BLIND, and **2 are\r\n  not poll-failure sites at all**. Two mechanisms cover all 13, neither of them a wording problem:\r\n  **window bleed** (7 — four credited by a `const CONVERGE_BUDGET: Duration = …as_millis()…`\r\n  *declaration* 20-25 lines BELOW a bare `panic!(\"brain could not connect\")`, one by a different\r\n  loop 57 lines away, two by an unrelated `now_ms()` helper) and **condition-use, not emission** (6 —\r\n  `assert!(started.elapsed() < Duration::from_secs(30), \"…viewer_count={count:?}\")` reads the clock\r\n  in the PREDICATE and omits it from the MESSAGE). Stripping string literals stopped a message\r\n  crediting itself; it does not stop CODE crediting a site whose message stays silent.\r\n  (2) **False-BLINDs checked at last — a seeded 30-site random sample of the BLIND bucket\r\n  (`random.seed(95)`), hand-adjudicated: 30 of 30 confirm BLIND, zero false-BLIND.** By the rule of\r\n  three that bounds the false-BLIND rate at **<= ~10%, at 95% confidence** — a binomial upper bound\r\n  assuming the 30 are a simple random sample of the 304 and each site's adjudication is independent;\r\n  it is **not a deterministic guarantee**, and zero errors in 30 excludes nothing outright (hertz).\r\n  This is the FIRST check run in the\r\n  direction that would REDUCE the blind count and it found nothing; every error found in either\r\n  bucket still runs the other way.\r\n  (3) **Population coverage, measured against every `sleep` in the corpus** — 472 call-sites, 349\r\n  inside a detected window, 75 one-shot settles in no loop. The remaining 48 dedup to 47 loop\r\n  headers and **every one is explained, 0 unexplained**: **32** matched a census shape but cannot\r\n  FAIL within 60 lines (excluded BY DESIGN — the census counts loops that wait AND can fail), and\r\n  **15 are the detector's true false negatives**, a fixed nameable set:\r\n  `while std::time::Instant::now() < deadline` (the PATH-QUALIFIED spelling — the regex demands a\r\n  bare `Instant::now()`; `broker.rs:389`, `shellchan.rs:114`), `while !stop.load(Ordering::Relaxed)`,\r\n  `while <predicate>(…)` (`shell_relink_force_e2e.rs:194/241`, `shell_stale_online_e2e.rs:146`,\r\n  `redispatch.rs:269`), and one `for (a, b) in [...]`. Those 15 stay UNCLASSIFIED.\r\n  **The 32 change how this census may be QUOTED:** \"323 poll loops that wait and can fail\" silently\r\n  excludes 32 loops that wait and CANNOT fail at the poll — a defensible scope, but a scope, and the\r\n  sentence must carry it.\r\n- **Restated census, and the form to quote.** **321** sites in the adjudicated population (323 minus\r\n  2 membership errors from the CLOCK bucket; a 3rd — `net_worker_starve.rs:99`, a fixed-window\r\n  SAMPLER that always runs its window and has no expiry failure — turned up in the BLIND sample, so\r\n  3 errors in 49 hand-adjudicated sites means the population carries ~6% slop and **321 is not\r\n  exact**). **317** classified BLIND. **4** report a measurement. **15** poll loops outside the\r\n  detector's reach, unclassified. **Still not established, and still not to be written: that 317 is\r\n  a FLOOR, or any repository-wide rate.** One direction is now exhaustive, the other bounded at\r\n  <=10% by a 30-site sample — a bounded estimate, never a floor, and silent about the 15.\r\n- **A distinction this validation surfaced, and the remedy above should carry: \"emits a clock\" is\r\n  TWO different things.** `transport_death_eof.rs:540` prints the OBSERVED quantity\r\n  (`{canary_after}ms`); `er_brief_once_per_session_e2e.rs:288` prints the MARGIN (`elapsed=`). Only\r\n  the second tells a reader how close the budget came. 3 of the 4 surviving CLOCK sites report a\r\n  margin, 1 reports an observation — and **a binary CLOCK/BLIND classifier cannot see that\r\n  difference**, which is a limit of the census, not of the sites.\r\n- **One edit to preserved evidence, DECLARED.** `census.py` printed `<-- IR-95 population (a FLOOR)`\r\n  on its blind line. That sentence was retracted the day it was written, but the retraction never\r\n  reached the SCRIPT, so re-running the preserved artifact reprinted the withdrawn claim at whoever\r\n  ran it — a retraction does not propagate to the next reader on its own. The LABEL, and only the\r\n  label, is corrected in place; the computation is untouched and **still reproduces 323 / 19 / 304**,\r\n  which is what makes this validation checkable against it. The old line is quoted verbatim in\r\n  `VALIDATION.md`.\r\n- **A FIRST detector was discarded, and its failure is itself evidence for cost 1 above.** Keying on\r\n  expiry VOCABULARY (\"never\", \"timed out\", \"did not appear\") found 53 sites and **missed\r\n  `contract_e2e.rs:393` entirely — the very site this entry was filed from** — because its panic\r\n  message is a CONTENT sentence. A wording-keyed census is structurally blind to exactly the sites\r\n  whose messages mislead. Recorded so no one re-runs the cheap version and reports 53 as the answer.\r\n- **Positive control passes, and it found siblings.** Both originating sites appear, both BLIND:\r\n  `sync.rs:102` and `contract_e2e.rs:395`. The census also surfaced **two fixed budgets nobody had\r\n  noticed** — `sync.rs:89` (`0..300`, beside the `0..400` at :102) and `contract_e2e.rs:51`\r\n  (`0..400`, beside the wall deadline at :393). Concentration: `inject_control_wedge.rs` 18,\r\n  `broker.rs` 10, `endpoint_lifecycle.rs` 9, `dispatch.rs` 7, `twohost.rs` 7.\r\n- **PRODUCER-PROGRESS INSTRUMENT — SPEC, 2026-09-10, and the three readings it does NOT support.**\r\n  The remedy above asks for the waited-on party's progress because a watcher's own timings cannot\r\n  separate a slow watcher from a slow producer. `last_streams_seen=0` throughout is equally\r\n  consistent with \"the producer never produced\" and \"the watcher never saw it\", and neither arm of\r\n  the releases#294 pair can tell those apart. **Design (doyle), narrowed by hertz and todlando, who\r\n  independently found the same three defects in the first form of it.**\r\n  **INSTRUMENT** — rides the IPC the poll ALREADY makes, so it adds no channel and no budget: the\r\n  responder's broker surfaces, alongside `net_streams`, a monotonic `streams_created_total` AND a\r\n  monotonic `streams_retired_total` for the session, the sequence and age of its last transition,\r\n  and the STREAM IDS of the most recent transitions so the watcher can correlate them against the\r\n  ids it sees and skips. The watcher prints the producer's counters beside its own observation.\r\n  **SEMANTICS THAT MUST BE DECLARED BEFORE A SINGLE READING IS TAKEN** — a bare count is not a\r\n  measurement until these are fixed: WHICH HOOK \"created\" fires at (broker stream-table\r\n  registration? wire acceptance?), WHICH KEY the counter is scoped to and what a session rotation\r\n  does to it, the COUNTER LIFETIME and reset behaviour (process lifetime, per session, what a broker\r\n  restart does), and WHICH CLOCK the age is measured against and whether it is comparable to the\r\n  watcher's.\r\n  **WHAT EACH READING LICENSES, and what it does NOT** (the first form of this table asserted three\r\n  causal conclusions it had not earned):\r\n  · `created=0` at expiry means **no creation was RECORDED AT THAT HOOK, in that counter's scope,\r\n    for that session key**. It does **NOT** establish that the requester never produced, and it does\r\n    **NOT** exonerate the watcher — the hook may sit downstream of the real production, or be scoped\r\n    to a different key.\r\n  · `created>0` with every snapshot empty is **CONSISTENT WITH a visibility/registration defect AND\r\n    with a stream being created and retired entirely between two 25 ms polls**. On its own it\r\n    establishes neither; the retire counter and the ids are what separate them.\r\n  · **Creation AFTER expiry cannot be observed by a poll that has already stopped.** A last-change\r\n    age cannot supply it. That needs either a separately bounded, separately declared post-expiry\r\n    observation, or a retained producer event trace with timestamps.\r\n  **Process constraints:** separately versioned and announced, never slipped between arms of a\r\n  comparison, and the existing diagnostic patch and every budget stay UNCHANGED. Widening a budget\r\n  to make a red go green remains refused.\r\n- **`last_streams_seen` IS A FILTERED-VIEW COUNT — the sharpest narrowing this field has had, and it\r\n  applies to all three expiries in the releases#294 pair.** The poll calls `net_streams`; the broker\r\n  answers at `broker.rs:9546` `dispatch_net_streams` -> `host.dispatch_stream_infos()`\r\n  (`nethost.rs:1952`) -> `stream_infos_filtered(FALSE)`, and that filter drops TWO classes\r\n  SERVER-SIDE, before serialization (ADR-0040 decision 2, `REQ-STREAM-INFOS-SERVER-FILTER`):\r\n  `!e.retired.load(SeqCst)` and `!e.initiated_locally`. So `last_streams_seen=0` does **NOT** mean\r\n  the broker held no streams. It means **zero NON-RETIRED, NON-LOCALLY-INITIATED rows at that\r\n  instant** — a row that exists and is retired is invisible to the poll BY DESIGN. That is narrower\r\n  than the corrected form the RCA had settled on (\"the final snapshot was empty\"), and it is a\r\n  hook-scope fact of exactly the kind the preconditions above demand be pinned before any reading.\r\n- **A \"reuse it, no product change\" stage-1 design WAS PROPOSED AND IS WITHDRAWN — recorded because\r\n  the reason generalises.** `NetHost::stream_counts()` (`nethost.rs:1980`) is already surfaced as\r\n  `NetStatusReply.streams_held` (`broker.rs:9002`, `msg.rs:874`) and documents itself as\r\n  \"retirement-blind ON PURPOSE ... the resource truth the eligibility view hides\". Reading it beside\r\n  `net_streams` looked like it would separate \"filtered out\" from \"absent\" for free. It does not,\r\n  for four reasons, and hertz and todlando raised them independently:\r\n  · **Two IPC replies are not an atomic snapshot.** `filtered=0` then `held>0` is equally consistent\r\n    with a row ARRIVING BETWEEN THE TWO CALLS. Such a pair must never be labelled proof of filtering,\r\n    and needs call order and timestamps recorded if it is read at all.\r\n  · **`streams_held` is HOST-SCOPED, not exchange-scoped.** It counts unrelated and locally-initiated\r\n    rows the filtered view drops, so it cannot speak to the exchange under investigation without\r\n    stream-ID correlation; any conclusion from it stays aggregate.\r\n  · **It adds UNMEASURED perturbation** — a second IPC per iteration changes the 400-iteration\r\n    window's wall duration by an amount nobody has measured. **CORRECTED 2026-09-10 (hertz,\r\n    todlando), because the first form of this bullet was itself an overclaim in two ways and both\r\n    are instructive:** (a) it called perturbation DISQUALIFYING, and it is not — instrumentation\r\n    that perturbs timing can still be useful; the objection is ADDED, UNMEASURED perturbation, not\r\n    perturbation as such. (b) It SIZED that perturbation from two figures that cannot carry it: the\r\n    measured `net_streams` cost (60,295 us / 400 = 0.151 ms per iteration) does **not** estimate the\r\n    `net-status` cost — different call, different work — and the **0.29% expiry difference between\r\n    the two arms is NOT an established causal effect size**, only an unexplained gap between two n=1\r\n    observations. Sizing an observer effect against it treats an open question as a known\r\n    quantity.\r\n  · A single POST-EXPIRY sample avoids perturbing the poll but then describes LATER state, not\r\n    expiry state, and is still host-scoped.\r\n- **THE INSTRUMENT THAT SURVIVES REVIEW: a retained, EXCHANGE-CORRELATED create/retire TRACE**\r\n  (hertz and todlando, converged independently). Recorded per stream lifecycle transition on the\r\n  producer side — stream id, conn id, remote id, transition, `initiated_locally`, a monotonic\r\n  sequence and a timestamp on a NAMED clock — retained and read AFTER the fact rather than sampled\r\n  by the watcher, so it adds **NO POLL CALLS**. Say that, and not \"adds nothing\" (hertz): it still\r\n  adds PRODUCER-SIDE work that may affect arrival timing and resource contention, and **that effect\r\n  is unmeasured too**. The trace is preferable for having no watcher IPC, not for being free. It captures between-poll transitions,\r\n  which neither a gauge nor an in-loop counter can: **a gauge reads 0 for a stream created and\r\n  retired between two 25 ms polls exactly as it does for one never created.** Correlation to the\r\n  exchange is by stream id against the ids the watcher saw and skipped.\r\n  **MEASURED: it does not exist today** — zero stream-lifetime log lines in `nethost.rs`. So this is\r\n  a PRODUCT change, not a reuse, and it stays unbuilt while the product is frozen. Its preconditions\r\n  are the ones above, unchanged. Production AFTER the trace's retention window remains outside it.\r\n- **THE FIRST MARGINS THIS ENTRY PRODUCED UNDER CI / GOLDEN CONDITIONS — instrumented run\r\n  34458491560, 2026-09-10\r\n  (hertz's patch; deployah's lane; read independently by doyle).** The remedy above was argued for\r\n  on the ground that a poll which prints nothing cannot say how close it came. It has now printed\r\n  on a runner. **NOT the first margins overall** — the earlier local 12-leg run already reported\r\n  them, including a 392/400 (hertz, todlando). **The genuinely novel quantity is narrower and\r\n  sharper than \"CI margins\" (deployah): it is a FAILING poll's margin, which no local leg could\r\n  produce because all 12 of them PASSED.** A budget's behaviour at expiry is the one thing a green\r\n  run structurally cannot report, and it is the case the remedy exists for.\r\n  **The figure is the MAXIMUM AMONG SUCCESSFUL polls in this run — explicitly NOT a ceiling, and not\r\n  a bound on observations**: the poll that EXPIRED in this same run consumed 400/400 = 100%. So:\r\n  among the polls that PASSED on hfenduleam, both instrumented sites peak at ~63% of budget. The\r\n  seven successful\r\n  `[IR95-SYNC]` waits in that run are 92, 19, 72, 254, 21, 21 and 20 iterations — **worst 254/400 =\r\n  63.5%** (6.449393 s) — and the `[IR95-CONTRACT]` success consumed **18.857089 s of its 30.000 s\r\n  wall = 62.9%**. Two independent sites, two different budget KINDS, the same maximum-among-passes.\r\n  Headroom at that worst SUCCESSFUL case ~37%; the failing case had none left. **n=7 and n=1, one\r\n  box, one run: a first CI measurement, not a stability claim, and NO budget change is proposed on\r\n  it.**\r\n- **The iteration budget's WALL EQUIVALENT, also measured for the first time.** The expiring poll's\r\n  400 iterations cost **10.199907 s against 400 × 25 ms = 10.000 s nominal — 2.0% over**, with\r\n  per-iteration overhead ~0.5 ms against a 25 ms sleep (IPC 60.295 ms total, 0.151 ms per iteration,\r\n  **0.59% of elapsed**; sleep is 99.4%). So on this box in this run a \"400 iteration\" budget and a\r\n  \"~10.2 s wall\" are nearly the same object — the iteration budget did NOT silently become a\r\n  different budget under load. That bounds one standing worry about blind iteration counts, and it\r\n  is precisely the class of thing that stops being guessable the moment a clock prints. Box-local\r\n  and run-local; it is not a general result.\r\n- **A scope limit the instrumentation itself imposes, and a smaller ask than it first looks.**\r\n  `last_streams_seen` is an ASSIGNMENT per iteration (`sync.rs:111`), not an accumulator, so\r\n  `last_streams_seen=0` at expiry describes the FINAL iteration only — not all 400 (todlando's\r\n  correction; deployah withdrew the aggregate reading, doyle confirmed it at source). But the loop's\r\n  CONTROL FLOW already proves the interesting half for free: the `find()` at `:113` returns the\r\n  instant a non-skipped stream appears, so **reaching the expiry print IS proof that no non-skipped\r\n  stream was seen in any of the 400 SNAPSHOTS** — no aggregate trace required. **It does NOT mean\r\n  no stream EXISTED between snapshots** (hertz): the poll samples at 25 ms, and nothing here\r\n  observes the gaps. What is genuinely\r\n  unmeasured is only whether a SKIPPED stream was ever present, and `skip` is empty on that call.\r\n  An aggregate/per-iteration trace therefore buys less here than the gap first suggests.\r\n- **NOT ESTABLISHED: that all 304 deserve a clock.** The census SIZES the problem; it does not\r\n  schedule it, and it does not pre-judge which sites are worth the edit. Remedy triage is owed\r\n  separately and is the larger half.\r\n- **Kin:** [[IR-84]] (the one `PUMP_PEER_FAIL` arm the rigs fire was the only one carrying no clock —\r\n  **the same class in product code**; this entry is its test-corpus face), [[IR-85]] (budgets sized\r\n  against a box whose speed moved), [[IR-77]] (nothing stamps the spawn-to-first-log interval, so a\r\n  readiness red cannot say where the time went), [[IR-90]].\r\n- **Ripe when:** with the releases#294 instrumented base-vs-head comparison, which **cannot be run\r\n  without it** — the experiment's whole output is the margins these sites do not print. ·\r\n  **Size:** small per site; the census is the larger half.\r\n\r\n### IR-96 — the `daemon_stop_convoy_e2e` API-storm cell fails 3-of-3 under the HEAVY suite at the diagnostic tree while passing at the candidate in golden CI, and nothing yet separates instrumentation from box from product\r\n\r\n- **Status:** OPEN, **cause-unclassified** (todlando's and hertz's stipulation, adopted verbatim — a\r\n  triage placement here is NOT a finding of non-defect).\r\n- **Origin:** releases#294 / v0.69.0 Arm B, 2026-09-10, deployah executing at diagnostic tree\r\n  `ed8ecd94` (= candidate `a9e786b2` + the unlanded sync instrumentation, never merged).\r\n- **What:** `spt::daemon_stop_convoy_e2e stop_under_an_api_storm_stays_down_then_start_brings_up_exactly_one`\r\n  FAILED in **all three** Arm B runs, with durations **growing every run: 9.473s · 10.973s ·\r\n  14.553s**. Different signature from the #294 sync cell; nothing was filed against #294.\r\n- **THE DIFFERENTIAL that makes it worth an entry rather than a shrug:** the same cell shows **0\r\n  failures at the candidate** in golden 34481993681 Phase A on this same box — that run's single\r\n  failure was the sync cell (`3381 tests run: 3380 passed (6 slow, 5 leaky), 1 failed, 1 skipped`).\r\n  So: 0-of-1 at `a9e786b2` under CI load, 3-of-3 at `ed8ecd94` under local HEAVY load.\r\n- **WHAT THAT DOES NOT ESTABLISH.** It does **not** isolate the instrumentation or the box as the\r\n  only candidates — a condition-dependent or intermittent PRODUCT defect remains live, and a single\r\n  CI pass is not evidence of absence. doyle claimed that elimination on 2026-09-10 and **withdrew\r\n  it** the same hour under todlando's and hertz's correction; the withdrawal is recorded in\r\n  `.spt/preserved/gate-r2-34481993681-20260910/CLASSIFICATION-AMENDMENT-2-doyle.md`.\r\n- **Confounded by IR-97** (below): the three runs were not equivalent conditions.\r\n- **Ripe when:** any lane touches daemon stop/start convoy behaviour, OR a golden run reds this cell\r\n  at a candidate, OR someone runs the cell at `a9e786b2` under the same local HEAVY workload — that\r\n  last one is the cheap discriminator and nobody has run it. · **Size:** one targeted local run to\r\n  discriminate; unknown beyond that.\r\n\r\n### IR-97 — a suite that leaks a fixed cohort of child processes per invocation makes consecutive runs non-comparable, and the between-run accounting the protocol required was not enforced\r\n\r\n- **Status:** OPEN. **Protocol deviation** (hertz's framing, and it is stronger than \"confounder\":\r\n  the protocol ALREADY required between-run accounting — execution did not enforce it, so the fix is\r\n  enforcement, not a limitations paragraph).\r\n- **Origin:** releases#294 Arm B, 2026-09-10. Derived by doyle from deployah's preserved\r\n  `10-residual-births.json` against the run windows.\r\n- **What:** each Arm B suite leaked **exactly 6** `spt` children that outlived it; all **18** were\r\n  still alive at the post-B3 census. Because a process alive at census whose OS birth time falls in\r\n  an earlier window existed continuously through the runs between (pid + birth time is an identity),\r\n  the carried diag-tree residue was **0 during B1 · 6 during B2 · 12 during B3**. The three\r\n  \"repetitions\" were therefore not three equivalent conditions, and every cross-run comparison in\r\n  that arm inherits it.\r\n- **LIMITS, stated so the entry is not over-read:** process **COUNT** is measured; **LOAD is not** —\r\n  idle orphans may cost nothing, contention was UNMEASURED (overlap UNVERIFIED all arm), and this is\r\n  **not** a drift meter. It neither implicates nor excludes residue as a cause of the one expiry, and\r\n  it does not explain it: B3 carried twice the orphans and **passed**.\r\n- **Also unestablished, in both directions:** 18 censused against 15 killed shows only that three\r\n  were absent at the second read. \"Three self-exited\" needs exit evidence; \"I killed 18\" was\r\n  likewise refused by deployah at the time.\r\n- **Kin:** the LEAK rows every Arm A/B run reported; `REQ-HAZARD-RESUME-CUSTODY-ABA` (KH 7.51) and\r\n  KH 7.58 — the cleanup that resolved this was correctly scoped by **pid + image path**, leaving 15\r\n  unrelated `spt` processes untouched, where a name-based kill would have taken down the live agent\r\n  fleet including the gater's own session.\r\n- **Ripe when:** any repeated-run experiment is designed on this box — census BETWEEN runs, not only\r\n  at the end. · **Size:** a between-run census step plus a scoped reap in the harness.\r","startLine":5482,"lineNumbers":[5482,5483,5484,5485,5486,5487,5488,5489,5490,5491,5492,5493,5494,5495,5496,5497,5498,5499,5500,5501,5502,5503,5504,5505,5506,5507,5508,5509,5510,5511,5512,5513,5514,5515,5516,5517,5518,5519,5520,5521,5522,5523,5524,5525,5526,5527,5528,5529,5530,5531,5532,5533,5534,5535,5536,5537,5538,5539,5540,5541,5542,5543,5544,5545,5546,5547,5548,5549,5550,5551,5552,5553,5554,5555,5556,5557,5558,5559,5560,5561,5562,5563,5564,5565,5566,5567,5568,5569,5570,5571,5572,5573,5574,5575,5576,5577,5578,5579,5580,5581,5582,5583,5584,5585,5586,5587,5588,5589,5590,5591,5592,5593,5594,5595,5596,5597,5598,5599,5600,5601,5602,5603,5604,5605,5606,5607,5608,5609,5610,5611,5612,5613,5614,5615,5616,5617,5618,5619,5620,5621,5622,5623,5624,5625,5626,5627,5628,5629,5630,5631,5632,5633,5634,5635,5636,5637,5638,5639,5640,5641,5642,5643,5644,5645,5646,5647,5648,5649,5650,5651,5652,5653,5654,5655,5656,5657,5658,5659,5660,5661,5662,5663,5664,5665,5666,5667,5668,5669,5670,5671,5672,5673,5674,5675,5676,5677,5678,5679,5680,5681,5682,5683,5684,5685,5686,5687,5688,5689,5690,5691,5692,5693,5694,5695,5696,5697,5698,5699,5700,5701,5702,5703,5704,5705,5706,5707,5708,5709,5710,5711,5712,5713,5714,5715,5716,5717,5718,5719,5720,5721,5722,5723,5724,5725,5726,5727,5728,5729,5730,5731,5732,5733,5734,5735,5736,5737,5738,5739,5740,5741,5742,5743,5744,5745,5746,5747,5748,5749,5750,5751,5752,5753,5754,5755,5756,5757,5758,5759,5760,5761,5762,5763,5764,5765,5766,5767,5768,5769,5770,5771,5772,5773,5774,5775,5776,5777,5778,5779,5780,5781]},"fileSize":501961,"meta":{"source":{"type":"path","value":"C:\\Users\\decid\\Documents\\projects\\spt-core\\docs\\INFRA-REGISTER.md"},"truncation":{"direction":"head","truncatedBy":"lines","totalLines":5782,"totalBytes":27143,"outputLines":300,"outputBytes":27143,"shownRange":{"start":5482,"end":5781},"nextOffset":5782}}},"isError":false,"timestamp":1789094610911}}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_r51zWsrdMoPHYXu4kkUjTiai|fc_065c0d1976ecf9c2016aa36add6f8c87d18e8e3a51c2b4f05f","toolName":"grep","startedAt":"2026-09-11T02:43:43.850Z","args":{"path":".github/workflows/ci.yml;.github/workflows/release.yml;.github/workflows/golden.yml"},"intent":"Checking workflow floor contracts"},"id":"99b3fa2e","parentId":"ec1e8e71","timestamp":"2026-09-11T02:43:43.850Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_k3QkJBYSYUXbiulasB4EWpnR|fc_065c0d1976ecf9c2016aa36add6fa087d1890b6d80cb4519d3","toolName":"grep","startedAt":"2026-09-11T02:43:43.850Z","args":{"path":"crates/spt-daemon/tests/attach.rs"},"intent":"Checking stale implementation states"},"id":"fa611855","parentId":"99b3fa2e","timestamp":"2026-09-11T02:43:43.850Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_SdofjrQzq6Mv2DthPW98144r|fc_065c0d1976ecf9c2016aa36add6fa887d197333a8abba82dd4","toolName":"grep","startedAt":"2026-09-11T02:43:43.850Z","args":{"path":"crates/spt-store/src/proc.rs;crates/spt-daemon/src/daemon.rs;.github/bench/launch-battery.py;crates/xtask/src/main.rs"},"intent":"Checking implemented rider seams"},"id":"0d6ab5d9","parentId":"fa611855","timestamp":"2026-09-11T02:43:43.850Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_ZeF5JGFiIhvC80nLCavu1Lhx|fc_065c0d1976ecf9c2016aa36add6fb087d1b433d32f681a273c","toolName":"grep","startedAt":"2026-09-11T02:43:43.850Z","args":{"path":"docs;*.md"},"intent":"Locating release close evidence"},"id":"003c6070","parentId":"0d6ab5d9","timestamp":"2026-09-11T02:43:43.850Z"}
{"type":"message","id":"7e69b36f","parentId":"003c6070","timestamp":"2026-09-11T02:43:43.851Z","message":{"role":"assistant","content":[{"type":"thinking","thinking":"**Locating exact source**"},{"type":"toolCall","id":"call_r51zWsrdMoPHYXu4kkUjTiai|fc_065c0d1976ecf9c2016aa36add6f8c87d18e8e3a51c2b4f05f","name":"grep","arguments":{"i":"Checking workflow floor contracts","pattern":"FLOOR_|32GB|32 \\*|100GB|checkout@|DISK|INBOUND|inbound|timeout-minutes","path":".github/workflows/ci.yml;.github/workflows/release.yml;.github/workflows/golden.yml","case":false,"gitignore":true,"skip":0},"intent":"Checking workflow floor contracts"},{"type":"toolCall","id":"call_k3QkJBYSYUXbiulasB4EWpnR|fc_065c0d1976ecf9c2016aa36add6fa087d1890b6d80cb4519d3","name":"grep","arguments":{"i":"Checking stale implementation states","pattern":"TICK39|ALT_VIEWPORT_MARKER","path":"crates/spt-daemon/tests/attach.rs","case":true,"gitignore":true,"skip":0},"intent":"Checking stale implementation states"},{"type":"toolCall","id":"call_SdofjrQzq6Mv2DthPW98144r|fc_065c0d1976ecf9c2016aa36add6fa887d197333a8abba82dd4","name":"grep","arguments":{"i":"Checking implemented rider seams","pattern":"DAEMON_SUCCEEDS_PID|daemon.pid.prev|pub fn kill_pid|pub fn kill_pid_tree|IR-8[012]|IR-7[569]|IR-59|IR-60|golden|disk","path":"crates/spt-store/src/proc.rs;crates/spt-daemon/src/daemon.rs;.github/bench/launch-battery.py;crates/xtask/src/main.rs","case":false,"gitignore":true,"skip":0},"intent":"Checking implemented rider seams"},{"type":"toolCall","id":"call_ZeF5JGFiIhvC80nLCavu1Lhx|fc_065c0d1976ecf9c2016aa36add6fb087d1b433d32f681a273c","name":"grep","arguments":{"i":"Locating release close evidence","pattern":"IR-89|IR-66|IR-73|IR-88|34481993681|34445961595|e5a2fed9","path":"docs;*.md","case":true,"gitignore":true,"skip":0},"intent":"Locating release close evidence"}],"api":"openai-codex-responses","provider":"openai-codex","model":"gpt-6-astra","usage":{"input":39262,"output":368,"cacheRead":54784,"cacheWrite":0,"totalTokens":94414,"reasoningTokens":12,"cost":{"input":0,"output":0,"cacheRead":0,"cacheWrite":0,"total":0}},"stopReason":"toolUse","timestamp":1789094610962,"responseId":"resp_065c0d1976ecf9c2016aa36ad0ff3c87d198307ca1b76c0c18","providerPayload":{"type":"openaiResponsesHistory","provider":"openai-codex","dt":true,"items":[{"id":"rs_065c0d1976ecf9c2016aa36ad2685887d1af9911f8b4c50244","type":"reasoning","content":[],"encrypted_content":"gAAAAABqo2rdPuFIklnYWFSNyPdYl93lKZfWuNaE06AsfaFdQXKnONsivho_yacdwlAGqAr0TCfafTn0bmCIq2GN88hob-Ly6ZtEsa0ILmY5Ocd660m5Uv8MkYlfZ-Iz8Q-G86sQ9DBG_8EUop-9NKzEpSUG5p31Bt4ouo95qwm3Sb5GpRvY-GENXDn7BNKqfzPFhcUDuVpUgq4zvIr0dMesc3xLCfttRS3FdsKfcR4USWNyc347ATfAzoqnj9dbJB3uJc-UfSc0gThH0bkYtnMBLiz8CweSFbrYsNJT82moveAQwGoAlUOfY7NzSJV8N3lVsUYBeU-YAfxq3qWOwkiN6a4T8UA2xLB-A6SRGXgSVIp0igNlQ_van8kEvowKOcFH5VpB61lBeonq_TEcEj26_rR23U15VQsxgSiyZ9mppn1nT75zw419pdc3UgyAhHzNwedIdFl90a3ZiK6a9rIWVuZbaP3NiDUofa6lE9O-BroN6qOQBdr5FUkf7lvXwFbGj0vkkvlkvhhldofpOllKyExGXsqU953pUPfOyDHE9zD2cUVQLRyxU1GjxdG4IQUDluaYhH3Jjtc2oXt51KiXUzcN9AEHuiT23H0KHCuN6ZxfJaGLcv_z3d3ep_xDgi75R99zayDZxaP9bTrmcWKp0C80aKBwBlVeGl1SpiA3kJA4oO5ZboThL9QrvtlZ6i-sg0_Z2E6wVJL0bdHUymuBRLP4MJL3jFA3Ffa5WRE2anLj4XVsshYdcRrS8SwT7C6CCHw4Gk5mu-Lv4jxCSEzwHd6BeszXoUu9goCIsUnESVb0O6HpxEPfwh0PD5le3QeIcnJhLQNeTZrjrOXH3txiV7lx3GkvUA_wmK7KNyu5HGE2a4hvNYSIjgLdarKLLtzvyGrae4c9G1kiR28fcG_uYvjAklOCOGlw5_mWmzgnn1lfAkoV963byCZhRJ3vDAsH-2rv9bPRvVhNRW0ZCa2jN7M49b0L3euo9a1Goz5vQu3nQMWi2e98CeQT6fe1005Wyi-vQJBc4yBZXiGTd0H0BWHrZ2qzFRCdHhECdonCwhLMKnGbNeumLDNHTPtuu-hssRzPrcwYrA_cqQuoP2uO3elyCRlY8k9F2fwxef10q0KMUXtYdbdA_r4P241eYLEqpSweFjIEqTs6hPzXZhe5IG-8GSBn4uOWVqZlAjDuNmBvkOHXS4HmdN2Bd0WDcjsDrneo0ofsi1VGSwWCGlD-SPZDbWp33vjlzO-6WacNFqNBEOW_-rplUEtCysY6KFZLcXsTgTgT5DzzuuqmAZ0CFvzBsWad5Uh-b9PbcCmpgs_25e3bAx-GZDDFbKdDku-CoItJfpM-","internal_chat_message_metadata_passthrough":{"turn_id":"cb1368d9-2a08-40c0-9f68-e06c6338cbd5"},"summary":[{"type":"summary_text","text":"**Locating exact source**"}],"metadata":{"turn_id":"cb1368d9-2a08-40c0-9f68-e06c6338cbd5"}},{"id":"fc_065c0d1976ecf9c2016aa36add6f8c87d18e8e3a51c2b4f05f","type":"function_call","status":"completed","arguments":"{\"i\":\"Checking workflow floor contracts\",\"pattern\":\"FLOOR_|32GB|32 \\\\*|100GB|checkout@|DISK|INBOUND|inbound|timeout-minutes\",\"path\":\".github/workflows/ci.yml;.github/workflows/release.yml;.github/workflows/golden.yml\",\"case\":false,\"gitignore\":true,\"skip\":0}","call_id":"call_r51zWsrdMoPHYXu4kkUjTiai","internal_chat_message_metadata_passthrough":{"turn_id":"cb1368d9-2a08-40c0-9f68-e06c6338cbd5"},"name":"grep","metadata":{"turn_id":"cb1368d9-2a08-40c0-9f68-e06c6338cbd5"}},{"id":"fc_065c0d1976ecf9c2016aa36add6fa087d1890b6d80cb4519d3","type":"function_call","status":"completed","arguments":"{\"i\":\"Checking stale implementation states\",\"pattern\":\"TICK39|ALT_VIEWPORT_MARKER\",\"path\":\"crates/spt-daemon/tests/attach.rs\",\"case\":true,\"gitignore\":true,\"skip\":0}","call_id":"call_k3QkJBYSYUXbiulasB4EWpnR","internal_chat_message_metadata_passthrough":{"turn_id":"cb1368d9-2a08-40c0-9f68-e06c6338cbd5"},"name":"grep","metadata":{"turn_id":"cb1368d9-2a08-40c0-9f68-e06c6338cbd5"}},{"id":"fc_065c0d1976ecf9c2016aa36add6fa887d197333a8abba82dd4","type":"function_call","status":"completed","arguments":"{\"i\":\"Checking implemented rider seams\",\"pattern\":\"DAEMON_SUCCEEDS_PID|daemon.pid.prev|pub fn kill_pid|pub fn kill_pid_tree|IR-8[012]|IR-7[569]|IR-59|IR-60|golden|disk\",\"path\":\"crates/spt-store/src/proc.rs;crates/spt-daemon/src/daemon.rs;.github/bench/launch-battery.py;crates/xtask/src/main.rs\",\"case\":false,\"gitignore\":true,\"skip\":0}","call_id":"call_SdofjrQzq6Mv2DthPW98144r","internal_chat_message_metadata_passthrough":{"turn_id":"cb1368d9-2a08-40c0-9f68-e06c6338cbd5"},"name":"grep","metadata":{"turn_id":"cb1368d9-2a08-40c0-9f68-e06c6338cbd5"}},{"id":"fc_065c0d1976ecf9c2016aa36add6fb087d1b433d32f681a273c","type":"function_call","status":"completed","arguments":"{\"i\":\"Locating release close evidence\",\"pattern\":\"IR-89|IR-66|IR-73|IR-88|34481993681|34445961595|e5a2fed9\",\"path\":\"docs;*.md\",\"case\":true,\"gitignore\":true,\"skip\":0}","call_id":"call_ZeF5JGFiIhvC80nLCavu1Lhx","internal_chat_message_metadata_passthrough":{"turn_id":"cb1368d9-2a08-40c0-9f68-e06c6338cbd5"},"name":"grep","metadata":{"turn_id":"cb1368d9-2a08-40c0-9f68-e06c6338cbd5"}}]},"duration":12885.240199999884,"ttft":1795.316300000064,"completedAt":1789094623848,"contextSnapshot":{"promptTokens":94046,"nonMessageTokens":10400,"compactionEpoch":0}}}
{"type":"message","id":"ef8d244f","parentId":"7e69b36f","timestamp":"2026-09-11T02:43:43.860Z","message":{"role":"toolResult","toolCallId":"call_k3QkJBYSYUXbiulasB4EWpnR|fc_065c0d1976ecf9c2016aa36add6fa087d1890b6d80cb4519d3","toolName":"grep","content":[{"type":"text","text":" 523|    // A child that emits a BURST of lines (many ring chunks) then blocks on stdin\n*524|    // so it never exits before we attach. `TICK39` (the last line) proves the whole\n 525|    // populated ring replayed + forwarded in order — not just the first chunk.\n 526|    #[cfg(unix)]\n 527|    let (program, args) = (\n...\n 530|            \"-c\".to_string(),\n*531|            \"i=0; while [ $i -lt 39 ]; do echo TICK$i; i=$((i+1)); done; sleep 0.2; echo TICK39; cat\".to_string(),\n 532|        ],\n 533|    );\n 534|    #[cfg(windows)]\n...\n 538|            \"/c\".to_string(),\n*539|            \"(for /L %i in (0,1,38) do @echo TICK%i) & ping -n 2 127.0.0.1 >nul & echo TICK39 & findstr \\\".\\\"\".to_string(),\n 540|        ],\n 541|    );\n 542|\n...\n 561|    spawner\n*562|        .read_output_until(b\"TICK39\", &mut drained)\n 563|        .expect(\"the burst lands in the ring\");\n 564|    drop(spawner); // spawn conn gone — a fresh attach must replay the populated ring\n 565|\n...\n 610|        &mut viewport,\n*611|        b\"TICK39\",\n 612|    );\n 613|    assert!(\n*614|        count(&viewport, b\"TICK39\") >= 1,\n 615|        \"the full pre-populated ring replayed + forwarded to the operator (no deadlock)\"\n 616|    );\n 617|\n...\n 655|                // default) — rides the same round-trip.\n*656|                \"printf '\\\\033]2;E2_TITLE\\\\007MAIN_SCROLLBACK_LINE\\\\n\\\\033[?1049h\\\\033[2J\\\\033[H'; sleep 0.2; printf 'ALT_VIEWPORT_MARKER'; cat\"\n 657|                    .into(),\n 658|            ],\n 659|            rows: 24,\n...\n 672|    spawner\n*673|        .read_output_until(b\"ALT_VIEWPORT_MARKER\", &mut drained)\n 674|        .expect(\"the alt-screen paint lands\");\n 675|    drop(spawner);\n 676|\n...\n 728|        &mut viewport,\n*729|        b\"ALT_VIEWPORT_MARKER\",\n 730|    );\n 731|    operator\n 732|        .net_stream_send(stream_b, &[], None, true)\n...\n 737|    assert!(\n*738|        count(&viewport, b\"ALT_VIEWPORT_MARKER\") >= 1,\n 739|        \"the cross-node cold attach received the alt-screen repaint\"\n 740|    );\n 741|    assert!(\n...\n 757|    assert!(\n*758|        painted.contains(\"ALT_VIEWPORT_MARKER\"),\n 759|        \"rendered screen shows the alt viewport across the cross-node path: {painted:?}\"\n 760|    );\n 761|    assert!("}],"details":{"scopePath":"crates/spt-daemon/tests/attach.rs","searchPath":"C:\\Users\\decid\\Documents\\projects\\spt-core\\crates\\spt-daemon\\tests\\attach.rs","cwd":"C:\\Users\\decid\\Documents\\projects\\spt-core","matchCount":11,"fileCount":1,"files":["crates/spt-daemon/tests/attach.rs"],"fileMatches":[{"path":"crates/spt-daemon/tests/attach.rs","count":11}],"truncated":false,"displayContent":" 523│    // A child that emits a BURST of lines (many ring chunks) then blocks on stdin\n*524│    // so it never exits before we attach. `TICK39` (the last line) proves the whole\n 525│    // populated ring replayed + forwarded in order — not just the first chunk.\n 526│    #[cfg(unix)]\n 527│    let (program, args) = (\n    │...\n 530│            \"-c\".to_string(),\n*531│            \"i=0; while [ $i -lt 39 ]; do echo TICK$i; i=$((i+1)); done; sleep 0.2; echo TICK39; cat\".to_string(),\n 532│        ],\n 533│    );\n 534│    #[cfg(windows)]\n    │...\n 538│            \"/c\".to_string(),\n*539│            \"(for /L %i in (0,1,38) do @echo TICK%i) & ping -n 2 127.0.0.1 >nul & echo TICK39 & findstr \\\".\\\"\".to_string(),\n 540│        ],\n 541│    );\n 542│\n    │...\n 561│    spawner\n*562│        .read_output_until(b\"TICK39\", &mut drained)\n 563│        .expect(\"the burst lands in the ring\");\n 564│    drop(spawner); // spawn conn gone — a fresh attach must replay the populated ring\n 565│\n    │...\n 610│        &mut viewport,\n*611│        b\"TICK39\",\n 612│    );\n 613│    assert!(\n*614│        count(&viewport, b\"TICK39\") >= 1,\n 615│        \"the full pre-populated ring replayed + forwarded to the operator (no deadlock)\"\n 616│    );\n 617│\n    │...\n 655│                // default) — rides the same round-trip.\n*656│                \"printf '\\\\033]2;E2_TITLE\\\\007MAIN_SCROLLBACK_LINE\\\\n\\\\033[?1049h\\\\033[2J\\\\033[H'; sleep 0.2; printf 'ALT_VIEWPORT_MARKER'; cat\"\n 657│                    .into(),\n 658│            ],\n 659│            rows: 24,\n    │...\n 672│    spawner\n*673│        .read_output_until(b\"ALT_VIEWPORT_MARKER\", &mut drained)\n 674│        .expect(\"the alt-screen paint lands\");\n 675│    drop(spawner);\n 676│\n    │...\n 728│        &mut viewport,\n*729│        b\"ALT_VIEWPORT_MARKER\",\n 730│    );\n 731│    operator\n 732│        .net_stream_send(stream_b, &[], None, true)\n    │...\n 737│    assert!(\n*738│        count(&viewport, b\"ALT_VIEWPORT_MARKER\") >= 1,\n 739│        \"the cross-node cold attach received the alt-screen repaint\"\n 740│    );\n 741│    assert!(\n    │...\n 757│    assert!(\n*758│        painted.contains(\"ALT_VIEWPORT_MARKER\"),\n 759│        \"rendered screen shows the alt viewport across the cross-node path: {painted:?}\"\n 760│    );\n 761│    assert!("},"isError":false,"timestamp":1789094623859}}
{"type":"message","id":"1399a1b1","parentId":"ef8d244f","timestamp":"2026-09-11T02:43:43.889Z","message":{"role":"toolResult","toolCallId":"call_r51zWsrdMoPHYXu4kkUjTiai|fc_065c0d1976ecf9c2016aa36add6f8c87d18e8e3a51c2b4f05f","toolName":"grep","content":[{"type":"text","text":"# .github/workflows/\n## ci.yml\n 19|    runs-on: [self-hosted, Linux, kitsubito]\n*20|    timeout-minutes: 5\n 21|    outputs:\n 22|      code: ${{ steps.classify.outputs.code }}\n 23|    steps:\n*24|      - uses: actions/checkout@v5\n 25|        with:\n 26|          fetch-depth: 2\n 27|      # IR-46/IR-59: 32 GiB is an instantaneous floor, not a headroom guarantee.\n...\n 29|      # [int->REQ-CI-FREE-SPACE-PREFLIGHT]\n*30|      - name: DISK floor start\n 31|        shell: bash\n 32|        run: |\n 33|          set -euo pipefail\n*34|          floor_bytes=$((32 * 1024 * 1024 * 1024))\n 35|          drive=$(df -P \"$GITHUB_WORKSPACE\" | awk 'NR == 2 { print $1 }')\n 36|          free_bytes=$(df -PB1 \"$GITHUB_WORKSPACE\" | awk 'NR == 2 { print $4 }')\n 37|          verdict=PASS\n*38|          if [ \"$free_bytes\" -lt \"$floor_bytes\" ]; then verdict=RED; fi\n*39|          printf 'FLOOR_START job=${{ github.job }} runner=${{ runner.os }} free_bytes=%s floor_bytes=%s verdict=%s sample=INSTANT\\n' \\\n*40|            \"$free_bytes\" \"$floor_bytes\" \"$verdict\"\n*41|          if [ \"$free_bytes\" -lt \"$floor_bytes\" ]; then\n*42|            echo \"::error title=Insufficient free disk::RESOURCE=disk drive=$drive free_bytes=$free_bytes floor_bytes=$floor_bytes\"\n 43|            exit 1\n 44|          fi\n 45|      - id: classify\n...\n 67|      # [int->REQ-CI-FREE-SPACE-PREFLIGHT]\n*68|      - name: DISK floor end\n 69|        if: always()\n 70|        shell: bash\n 71|        run: |\n 72|          set -euo pipefail\n*73|          floor_bytes=$((32 * 1024 * 1024 * 1024))\n 74|          drive=$(df -P \"$GITHUB_WORKSPACE\" | awk 'NR == 2 { print $1 }')\n 75|          free_bytes=$(df -PB1 \"$GITHUB_WORKSPACE\" | awk 'NR == 2 { print $4 }')\n 76|          verdict=PASS\n*77|          if [ \"$free_bytes\" -lt \"$floor_bytes\" ]; then verdict=RED; fi\n*78|          printf 'FLOOR_END job=${{ github.job }} runner=${{ runner.os }} free_bytes=%s floor_bytes=%s verdict=%s sample=INSTANT\\n' \\\n*79|            \"$free_bytes\" \"$floor_bytes\" \"$verdict\"\n*80|          if [ \"$free_bytes\" -lt \"$floor_bytes\" ]; then\n*81|            echo \"::error title=Insufficient free disk::RESOURCE=disk drive=$drive free_bytes=$free_bytes floor_bytes=$floor_bytes\"\n 82|            exit 1\n 83|          fi\n 84|\n...\n 94|    # 34261096301), 3min under its own wall, for the same box-wide slowdown.\n*95|    timeout-minutes: 40\n 96|    steps:\n*97|      - uses: actions/checkout@v5\n 98|      # IR-73: This floor is not protective, so it runs after checkout.\n 99|      # [int->REQ-CI-FREE-SPACE-PREFLIGHT]\n*100|      - name: DISK floor start (Windows)\n 101|        if: runner.os == 'Windows'\n 102|        shell: pwsh\n 103|        run: |\n*104|          $floorBytes = 32GB\n 105|          $drive = (Get-Item $env:GITHUB_WORKSPACE).PSDrive\n 106|          $freeBytes = [int64]$drive.Free\n 107|          $verdict = if ($freeBytes -lt $floorBytes) { 'RED' } else { 'PASS' }\n## release.yml\n 49|    runs-on: ${{ matrix.runner }}\n*50|    timeout-minutes: 30\n 51|    steps:\n*52|      - uses: actions/checkout@v5\n 53|      # IR-46/IR-59: 32 GiB is an instantaneous floor, not a headroom guarantee.\n 54|      # IR-73: This floor is not protective, so it runs after checkout.\n 55|      # [int->REQ-CI-FREE-SPACE-PREFLIGHT]\n*56|      - name: DISK floor start (Windows)\n 57|        if: runner.os == 'Windows'\n 58|        shell: pwsh\n 59|        run: |\n*60|          $floorBytes = 32GB\n 61|          $drive = (Get-Item $env:GITHUB_WORKSPACE).PSDrive\n 62|          $freeBytes = [int64]$drive.Free\n 63|          $verdict = if ($freeBytes -lt $floorBytes) { 'RED' } else { 'PASS' }\n*64|          Write-Host \"FLOOR_START job=${{ github.job }} runner=${{ runner.os }} free_bytes=$freeBytes floor_bytes=$floorBytes verdict=$verdict sample=INSTANT\"\n 65|          if ($freeBytes -lt $floorBytes) {\n*66|            Write-Error \"RESOURCE=disk drive=$($drive.Root) free_bytes=$freeBytes floor_bytes=$floorBytes\"\n 67|            exit 1\n 68|          }\n 69|      # IR-73: This floor is not protective, so it runs after checkout.\n 70|      # [int->REQ-CI-FREE-SPACE-PREFLIGHT]\n*71|      - name: DISK floor start (Linux)\n 72|        if: runner.os == 'Linux'\n 73|        shell: bash\n 74|        run: |\n 75|          set -euo pipefail\n*76|          floor_bytes=$((32 * 1024 * 1024 * 1024))\n 77|          drive=$(df -P \"$GITHUB_WORKSPACE\" | awk 'NR == 2 { print $1 }')\n 78|          free_bytes=$(df -PB1 \"$GITHUB_WORKSPACE\" | awk 'NR == 2 { print $4 }')\n 79|          verdict=PASS\n*80|          if [ \"$free_bytes\" -lt \"$floor_bytes\" ]; then verdict=RED; fi\n*81|          printf 'FLOOR_START job=${{ github.job }} runner=${{ runner.os }} free_bytes=%s floor_bytes=%s verdict=%s sample=INSTANT\\n' \\\n*82|            \"$free_bytes\" \"$floor_bytes\" \"$verdict\"\n*83|          if [ \"$free_bytes\" -lt \"$floor_bytes\" ]; then\n*84|            echo \"::error title=Insufficient free disk::RESOURCE=disk drive=$drive free_bytes=$free_bytes floor_bytes=$floor_bytes\"\n 85|            exit 1\n 86|          fi\n 87|      # musl cross-build prerequisites — installed in-job on kitsubito. musl-gcc\n...\n 131|      # [int->REQ-CI-FREE-SPACE-PREFLIGHT]\n*132|      - name: DISK floor end (Windows)\n 133|        if: always() && runner.os == 'Windows'\n 134|        shell: pwsh\n 135|        run: |\n*136|          $floorBytes = 32GB\n 137|          $drive = (Get-Item $env:GITHUB_WORKSPACE).PSDrive\n 138|          $freeBytes = [int64]$drive.Free\n 139|          $verdict = if ($freeBytes -lt $floorBytes) { 'RED' } else { 'PASS' }\n*140|          Write-Host \"FLOOR_END job=${{ github.job }} runner=${{ runner.os }} free_bytes=$freeBytes floor_bytes=$floorBytes verdict=$verdict sample=INSTANT\"\n 141|          if ($freeBytes -lt $floorBytes) {\n*142|            Write-Error \"RESOURCE=disk drive=$($drive.Root) free_bytes=$freeBytes floor_bytes=$floorBytes\"\n 143|            exit 1\n 144|          }\n 145|      # [int->REQ-CI-FREE-SPACE-PREFLIGHT]\n*146|      - name: DISK floor end (Linux)\n 147|        if: always() && runner.os == 'Linux'\n 148|        shell: bash\n 149|        run: |\n 150|          set -euo pipefail\n*151|          floor_bytes=$((32 * 1024 * 1024 * 1024))\n 152|          drive=$(df -P \"$GITHUB_WORKSPACE\" | awk 'NR == 2 { print $1 }')\n 153|          free_bytes=$(df -PB1 \"$GITHUB_WORKSPACE\" | awk 'NR == 2 { print $4 }')\n 154|          verdict=PASS\n*155|          if [ \"$free_bytes\" -lt \"$floor_bytes\" ]; then verdict=RED; fi\n## golden.yml\n 29|    runs-on: [self-hosted, Linux, kitsubito]\n*30|    timeout-minutes: 5\n 31|    outputs:\n 32|      code: ${{ steps.classify.outputs.code }}\n 33|    steps:\n*34|      - uses: actions/checkout@v5\n 35|      # IR-46: this floor guards downstream work, not checkout; read after its reclaim.\n 36|      # Retain 32 GiB; each sample is an INSTANT, not sustained headroom.\n 37|      # [int->REQ-CI-FREE-SPACE-PREFLIGHT]\n*38|      - name: DISK start floor\n 39|        shell: bash\n 40|        run: |\n 41|          set -euo pipefail\n*42|          floor_bytes=$((32 * 1024 * 1024 * 1024))\n 43|          drive=$(df -P \"$GITHUB_WORKSPACE\" | awk 'NR == 2 { print $1 }')\n 44|          free_bytes=$(df -PB1 \"$GITHUB_WORKSPACE\" | awk 'NR == 2 { print $4 }')\n 45|          verdict=PASS\n*46|          if [ \"$free_bytes\" -lt \"$floor_bytes\" ]; then verdict=RED; fi\n*47|          printf 'FLOOR_START job=${{ github.job }} runner=${{ runner.os }} free_bytes=%s floor_bytes=%s verdict=%s sample=INSTANT\\n' \\\n*48|            \"$free_bytes\" \"$floor_bytes\" \"$verdict\"\n*49|          if [ \"$free_bytes\" -lt \"$floor_bytes\" ]; then\n*50|            echo \"::error title=Insufficient free disk::RESOURCE=disk drive=$drive free_bytes=$free_bytes floor_bytes=$floor_bytes\"\n 51|            exit 1\n 52|          fi\n 53|      - name: Validate flake registry\n...\n 59|      # [int->REQ-CI-FREE-SPACE-PREFLIGHT]\n*60|      - name: DISK end floor\n 61|        if: always()\n 62|        shell: bash\n 63|        run: |\n 64|          set -euo pipefail\n*65|          floor_bytes=$((32 * 1024 * 1024 * 1024))\n 66|          drive=$(df -P \"$GITHUB_WORKSPACE\" | awk 'NR == 2 { print $1 }')\n 67|          free_bytes=$(df -PB1 \"$GITHUB_WORKSPACE\" | awk 'NR == 2 { print $4 }')\n 68|          verdict=PASS\n*69|          if [ \"$free_bytes\" -lt \"$floor_bytes\" ]; then verdict=RED; fi\n*70|          printf 'FLOOR_END job=${{ github.job }} runner=${{ runner.os }} free_bytes=%s floor_bytes=%s verdict=%s sample=INSTANT\\n' \\\n*71|            \"$free_bytes\" \"$floor_bytes\" \"$verdict\"\n*72|          if [ \"$free_bytes\" -lt \"$floor_bytes\" ]; then\n*73|            echo \"::error title=Insufficient free disk::RESOURCE=disk drive=$drive free_bytes=$free_bytes floor_bytes=$floor_bytes\"\n 74|            exit 1\n 75|          fi\n 76|\n...\n 98|      # [int->REQ-TEST-DAEMON-EPHEMERAL-ADVISORY-PORTS] Test daemons share\n*99|      # these self-hosted boxes with the resident fleet. Their disk/IPC homes\n 100|      # are isolated, but advisory TCP listeners must not claim fleet ports.\n 101|      SPT_TEST_EPHEMERAL_ADVISORY_PORTS: \"1\"\n 102|      # Concurrent-attach gate watchdog headroom (a_journaled / p0_paste). Those\n...\n 171|    # fix a slow box; it can only stop hiding it.\n*172|    timeout-minutes: 80\n 173|    steps:\n 174|      # Pre-checkout exe-lock guard (Windows): a PRIOR run's leaked workspace\n 175|      # daemon (an spt.exe spawned from this checkout's target/) can survive into\n*176|      # this run and lock target\\debug\\spt.exe, so actions/checkout@v5's clean\n 177|      # step fails with EPERM (\"unlink ... spt.exe\"). Reap it BEFORE checkout —\n 178|      # the post-checkout guard below is too late for the clean. Scoped to\n 179|      # $GITHUB_WORKSPACE so it never touches a live agent's daemon on this shared\n...\n 211|          exit 0\n*212|      - uses: actions/checkout@v5\n 213|      # Floor asserted AFTER checkout, same reason and same ruling as the n1-gate\n 214|      # job below (REQ-CI-FREE-SPACE-PREFLIGHT, the 2026-08-03 amendment, widened\n 215|      # here 2026-08-29): checkout runs `git clean -ffdx` and THAT is the reclaim,"}],"details":{"scopePath":".github/workflows/ci.yml, .github/workflows/release.yml, .github/workflows/golden.yml","searchPath":"C:\\Users\\decid\\Documents\\projects\\spt-core\\.github\\workflows","cwd":"C:\\Users\\decid\\Documents\\projects\\spt-core","matchCount":60,"fileCount":3,"files":[".github/workflows/ci.yml",".github/workflows/release.yml",".github/workflows/golden.yml"],"fileMatches":[{"path":".github/workflows/ci.yml","count":20},{"path":".github/workflows/release.yml","count":20},{"path":".github/workflows/golden.yml","count":20}],"truncated":true,"perFileLimitReached":20,"displayContent":"# .github/workflows/\n## ci.yml\n  19│    runs-on: [self-hosted, Linux, kitsubito]\n *20│    timeout-minutes: 5\n  21│    outputs:\n  22│      code: ${{ steps.classify.outputs.code }}\n  23│    steps:\n *24│      - uses: actions/checkout@v5\n  25│        with:\n  26│          fetch-depth: 2\n  27│      # IR-46/IR-59: 32 GiB is an instantaneous floor, not a headroom guarantee.\n    │...\n  29│      # [int->REQ-CI-FREE-SPACE-PREFLIGHT]\n *30│      - name: DISK floor start\n  31│        shell: bash\n  32│        run: |\n  33│          set -euo pipefail\n *34│          floor_bytes=$((32 * 1024 * 1024 * 1024))\n  35│          drive=$(df -P \"$GITHUB_WORKSPACE\" | awk 'NR == 2 { print $1 }')\n  36│          free_bytes=$(df -PB1 \"$GITHUB_WORKSPACE\" | awk 'NR == 2 { print $4 }')\n  37│          verdict=PASS\n *38│          if [ \"$free_bytes\" -lt \"$floor_bytes\" ]; then verdict=RED; fi\n *39│          printf 'FLOOR_START job=${{ github.job }} runner=${{ runner.os }} free_bytes=%s floor_bytes=%s verdict=%s sample=INSTANT\\n' \\\n *40│            \"$free_bytes\" \"$floor_bytes\" \"$verdict\"\n *41│          if [ \"$free_bytes\" -lt \"$floor_bytes\" ]; then\n *42│            echo \"::error title=Insufficient free disk::RESOURCE=disk drive=$drive free_bytes=$free_bytes floor_bytes=$floor_bytes\"\n  43│            exit 1\n  44│          fi\n  45│      - id: classify\n    │...\n  67│      # [int->REQ-CI-FREE-SPACE-PREFLIGHT]\n *68│      - name: DISK floor end\n  69│        if: always()\n  70│        shell: bash\n  71│        run: |\n  72│          set -euo pipefail\n *73│          floor_bytes=$((32 * 1024 * 1024 * 1024))\n  74│          drive=$(df -P \"$GITHUB_WORKSPACE\" | awk 'NR == 2 { print $1 }')\n  75│          free_bytes=$(df -PB1 \"$GITHUB_WORKSPACE\" | awk 'NR == 2 { print $4 }')\n  76│          verdict=PASS\n *77│          if [ \"$free_bytes\" -lt \"$floor_bytes\" ]; then verdict=RED; fi\n *78│          printf 'FLOOR_END job=${{ github.job }} runner=${{ runner.os }} free_bytes=%s floor_bytes=%s verdict=%s sample=INSTANT\\n' \\\n *79│            \"$free_bytes\" \"$floor_bytes\" \"$verdict\"\n *80│          if [ \"$free_bytes\" -lt \"$floor_bytes\" ]; then\n *81│            echo \"::error title=Insufficient free disk::RESOURCE=disk drive=$drive free_bytes=$free_bytes floor_bytes=$floor_bytes\"\n  82│            exit 1\n  83│          fi\n  84│\n    │...\n  94│    # 34261096301), 3min under its own wall, for the same box-wide slowdown.\n *95│    timeout-minutes: 40\n  96│    steps:\n *97│      - uses: actions/checkout@v5\n  98│      # IR-73: This floor is not protective, so it runs after checkout.\n  99│      # [int->REQ-CI-FREE-SPACE-PREFLIGHT]\n*100│      - name: DISK floor start (Windows)\n 101│        if: runner.os == 'Windows'\n 102│        shell: pwsh\n 103│        run: |\n*104│          $floorBytes = 32GB\n 105│          $drive = (Get-Item $env:GITHUB_WORKSPACE).PSDrive\n 106│          $freeBytes = [int64]$drive.Free\n 107│          $verdict = if ($freeBytes -lt $floorBytes) { 'RED' } else { 'PASS' }\n## release.yml\n  49│    runs-on: ${{ matrix.runner }}\n *50│    timeout-minutes: 30\n  51│    steps:\n *52│      - uses: actions/checkout@v5\n  53│      # IR-46/IR-59: 32 GiB is an instantaneous floor, not a headroom guarantee.\n  54│      # IR-73: This floor is not protective, so it runs after checkout.\n  55│      # [int->REQ-CI-FREE-SPACE-PREFLIGHT]\n *56│      - name: DISK floor start (Windows)\n  57│        if: runner.os == 'Windows'\n  58│        shell: pwsh\n  59│        run: |\n *60│          $floorBytes = 32GB\n  61│          $drive = (Get-Item $env:GITHUB_WORKSPACE).PSDrive\n  62│          $freeBytes = [int64]$drive.Free\n  63│          $verdict = if ($freeBytes -lt $floorBytes) { 'RED' } else { 'PASS' }\n *64│          Write-Host \"FLOOR_START job=${{ github.job }} runner=${{ runner.os }} free_bytes=$freeBytes floor_bytes=$floorBytes verdict=$verdict sample=INSTANT\"\n  65│          if ($freeBytes -lt $floorBytes) {\n *66│            Write-Error \"RESOURCE=disk drive=$($drive.Root) free_bytes=$freeBytes floor_bytes=$floorBytes\"\n  67│            exit 1\n  68│          }\n  69│      # IR-73: This floor is not protective, so it runs after checkout.\n  70│      # [int->REQ-CI-FREE-SPACE-PREFLIGHT]\n *71│      - name: DISK floor start (Linux)\n  72│        if: runner.os == 'Linux'\n  73│        shell: bash\n  74│        run: |\n  75│          set -euo pipefail\n *76│          floor_bytes=$((32 * 1024 * 1024 * 1024))\n  77│          drive=$(df -P \"$GITHUB_WORKSPACE\" | awk 'NR == 2 { print $1 }')\n  78│          free_bytes=$(df -PB1 \"$GITHUB_WORKSPACE\" | awk 'NR == 2 { print $4 }')\n  79│          verdict=PASS\n *80│          if [ \"$free_bytes\" -lt \"$floor_bytes\" ]; then verdict=RED; fi\n *81│          printf 'FLOOR_START job=${{ github.job }} runner=${{ runner.os }} free_bytes=%s floor_bytes=%s verdict=%s sample=INSTANT\\n' \\\n *82│            \"$free_bytes\" \"$floor_bytes\" \"$verdict\"\n *83│          if [ \"$free_bytes\" -lt \"$floor_bytes\" ]; then\n *84│            echo \"::error title=Insufficient free disk::RESOURCE=disk drive=$drive free_bytes=$free_bytes floor_bytes=$floor_bytes\"\n  85│            exit 1\n  86│          fi\n  87│      # musl cross-build prerequisites — installed in-job on kitsubito. musl-gcc\n    │...\n 131│      # [int->REQ-CI-FREE-SPACE-PREFLIGHT]\n*132│      - name: DISK floor end (Windows)\n 133│        if: always() && runner.os == 'Windows'\n 134│        shell: pwsh\n 135│        run: |\n*136│          $floorBytes = 32GB\n 137│          $drive = (Get-Item $env:GITHUB_WORKSPACE).PSDrive\n 138│          $freeBytes = [int64]$drive.Free\n 139│          $verdict = if ($freeBytes -lt $floorBytes) { 'RED' } else { 'PASS' }\n*140│          Write-Host \"FLOOR_END job=${{ github.job }} runner=${{ runner.os }} free_bytes=$freeBytes floor_bytes=$floorBytes verdict=$verdict sample=INSTANT\"\n 141│          if ($freeBytes -lt $floorBytes) {\n*142│            Write-Error \"RESOURCE=disk drive=$($drive.Root) free_bytes=$freeBytes floor_bytes=$floorBytes\"\n 143│            exit 1\n 144│          }\n 145│      # [int->REQ-CI-FREE-SPACE-PREFLIGHT]\n*146│      - name: DISK floor end (Linux)\n 147│        if: always() && runner.os == 'Linux'\n 148│        shell: bash\n 149│        run: |\n 150│          set -euo pipefail\n*151│          floor_bytes=$((32 * 1024 * 1024 * 1024))\n 152│          drive=$(df -P \"$GITHUB_WORKSPACE\" | awk 'NR == 2 { print $1 }')\n 153│          free_bytes=$(df -PB1 \"$GITHUB_WORKSPACE\" | awk 'NR == 2 { print $4 }')\n 154│          verdict=PASS\n*155│          if [ \"$free_bytes\" -lt \"$floor_bytes\" ]; then verdict=RED; fi\n## golden.yml\n  29│    runs-on: [self-hosted, Linux, kitsubito]\n *30│    timeout-minutes: 5\n  31│    outputs:\n  32│      code: ${{ steps.classify.outputs.code }}\n  33│    steps:\n *34│      - uses: actions/checkout@v5\n  35│      # IR-46: this floor guards downstream work, not checkout; read after its reclaim.\n  36│      # Retain 32 GiB; each sample is an INSTANT, not sustained headroom.\n  37│      # [int->REQ-CI-FREE-SPACE-PREFLIGHT]\n *38│      - name: DISK start floor\n  39│        shell: bash\n  40│        run: |\n  41│          set -euo pipefail\n *42│          floor_bytes=$((32 * 1024 * 1024 * 1024))\n  43│          drive=$(df -P \"$GITHUB_WORKSPACE\" | awk 'NR == 2 { print $1 }')\n  44│          free_bytes=$(df -PB1 \"$GITHUB_WORKSPACE\" | awk 'NR == 2 { print $4 }')\n  45│          verdict=PASS\n *46│          if [ \"$free_bytes\" -lt \"$floor_bytes\" ]; then verdict=RED; fi\n *47│          printf 'FLOOR_START job=${{ github.job }} runner=${{ runner.os }} free_bytes=%s floor_bytes=%s verdict=%s sample=INSTANT\\n' \\\n *48│            \"$free_bytes\" \"$floor_bytes\" \"$verdict\"\n *49│          if [ \"$free_bytes\" -lt \"$floor_bytes\" ]; then\n *50│            echo \"::error title=Insufficient free disk::RESOURCE=disk drive=$drive free_bytes=$free_bytes floor_bytes=$floor_bytes\"\n  51│            exit 1\n  52│          fi\n  53│      - name: Validate flake registry\n    │...\n  59│      # [int->REQ-CI-FREE-SPACE-PREFLIGHT]\n *60│      - name: DISK end floor\n  61│        if: always()\n  62│        shell: bash\n  63│        run: |\n  64│          set -euo pipefail\n *65│          floor_bytes=$((32 * 1024 * 1024 * 1024))\n  66│          drive=$(df -P \"$GITHUB_WORKSPACE\" | awk 'NR == 2 { print $1 }')\n  67│          free_bytes=$(df -PB1 \"$GITHUB_WORKSPACE\" | awk 'NR == 2 { print $4 }')\n  68│          verdict=PASS\n *69│          if [ \"$free_bytes\" -lt \"$floor_bytes\" ]; then verdict=RED; fi\n *70│          printf 'FLOOR_END job=${{ github.job }} runner=${{ runner.os }} free_bytes=%s floor_bytes=%s verdict=%s sample=INSTANT\\n' \\\n *71│            \"$free_bytes\" \"$floor_bytes\" \"$verdict\"\n *72│          if [ \"$free_bytes\" -lt \"$floor_bytes\" ]; then\n *73│            echo \"::error title=Insufficient free disk::RESOURCE=disk drive=$drive free_bytes=$free_bytes floor_bytes=$floor_bytes\"\n  74│            exit 1\n  75│          fi\n  76│\n    │...\n  98│      # [int->REQ-TEST-DAEMON-EPHEMERAL-ADVISORY-PORTS] Test daemons share\n *99│      # these self-hosted boxes with the resident fleet. Their disk/IPC homes\n 100│      # are isolated, but advisory TCP listeners must not claim fleet ports.\n 101│      SPT_TEST_EPHEMERAL_ADVISORY_PORTS: \"1\"\n 102│      # Concurrent-attach gate watchdog headroom (a_journaled / p0_paste). Those\n    │...\n 171│    # fix a slow box; it can only stop hiding it.\n*172│    timeout-minutes: 80\n 173│    steps:\n 174│      # Pre-checkout exe-lock guard (Windows): a PRIOR run's leaked workspace\n 175│      # daemon (an spt.exe spawned from this checkout's target/) can survive into\n*176│      # this run and lock target\\debug\\spt.exe, so actions/checkout@v5's clean\n 177│      # step fails with EPERM (\"unlink ... spt.exe\"). Reap it BEFORE checkout —\n 178│      # the post-checkout guard below is too late for the clean. Scoped to\n 179│      # $GITHUB_WORKSPACE so it never touches a live agent's daemon on this shared\n    │...\n 211│          exit 0\n*212│      - uses: actions/checkout@v5\n 213│      # Floor asserted AFTER checkout, same reason and same ruling as the n1-gate\n 214│      # job below (REQ-CI-FREE-SPACE-PREFLIGHT, the 2026-08-03 amendment, widened\n 215│      # here 2026-08-29): checkout runs `git clean -ffdx` and THAT is the reclaim,"},"isError":false,"timestamp":1789094623889}}
{"type":"message","id":"bb5c16dc","parentId":"1399a1b1","timestamp":"2026-09-11T02:43:43.893Z","message":{"role":"toolResult","toolCallId":"call_ZeF5JGFiIhvC80nLCavu1Lhx|fc_065c0d1976ecf9c2016aa36add6fb087d1b433d32f681a273c","toolName":"grep","content":[{"type":"text","text":"# GATE-W2-272-CHECKLIST.md\n 691|\n*692|## 20:06:42Z -- RESUMED post-clear. Rerun 34262154550 in_progress: test Windows started 20:00:38Z, twohost-a/b not yet materialized; deployah owns verdict. Wait window filled: IR-79 (32 GiB floor below 67.4 GiB footprint; IR-64 ripe-arm FIRED in-job form; IR-73 second half BUILT), IR-80 (two-host halves independent jobs on one runner, B 900 s on own clock, panic blames pairing), IR-81 (pool-release rebuilds xtask into reaped pool) DRAFTED to scratchpad/IR-79-81-draft.md (6749 B) for the release-close reg...\n 693|\n 694|## 20:14:41Z -- ROOT LANE SCRATCH CLASSIFIED + PRESERVED (delete deferred to release close). 102 untracked driver-output files (exit/raw/log/done), 6.8 MB, seven closed-lane families by content+mtime: ASM22/ASM22B = assembly-io-parser-22 on the ROOT pool (08-28, v0.63.0; the 20 reap_N legs are compile outputs); ASM63 = #63 on worktree gate-222-ca30a79e (08-25, v0.62.0); ASM241 = worktree asm-241 (08-29, v0.65.0; only family with a record pointer, ASM-241-GATE-VERDICT.md, which stays); E276 = echo-276 wor...\n 695|\n...\n 814|## 09:43Z — alchemy release v0.68.0 DONE: 13 Requests -> DONE (#272 milestone + members #147 #246 #248 #249 #265 #266 #268 #17 + merge-closed #276 #277 #279 #280); board #272 CLOSED state: DONE (gh read). todlando given the filing word (2 creates + #289 scope comment). hertz's ledger lane now carries my 4 rows (.spt/preserved/doyle-flake-rows-2026-09-09/, 4/4) + resident_service 4th. RELEASE-INDEX ledger line updated: latest v0.68.0 c104 @a2f335f8 + the four missing cuts v0.65.0 c100 / v0.66.0 c101 / v...\n*815|## 09:46Z — REGISTER CENSUS main@a2f335f8 vs my 09-08 draft: ALL FIVE draft entries UNLANDED (main's IR-79..83 = hertz's rig entries, other subjects; zero hits for 67.4 GiB footprint / two-host halves 900 s / pool-release rebuilds xtask / firewall cold inbound / desktop load). Draft copied to root .spt/preserved/doyle-r3-triage/IR-79-82-NEXT-old-draft-2026-09-08.md (99b05f2a). RULED: hertz's register lane lands IR-85 (his + IR-NEXT folded) and IR-86 floor / IR-87 two-host halves / IR-88 pool-release re...\n 816|## 09:45Z — deployah step 7 shape-0680 teardown PROPOSAL (preserve-first): worktree detached at dead r2 sha 25e60015 (ancestor of main), pool lane shape-0680-r2 lane_base e4444413 (ancestor of main = finished), Length-sum 11.59 GiB (overstated by hardlinks, stated), OUTBOUND real dir, INBOUND none, not locked, untracked 0, one stat-cache M proven identical raw + preserved (8525a194). CONFIRMED steps 1-3: pool-release with PREBUILT xtask + Test-Path, reap TARGET subtree, then git worktree remove (refusa...\n 817|## 09:47Z — RESUMED post-recharge. hertz STOP-AND-READ: my r3 triage log (05:39Z-06:50Z, 9 rows) lived ONLY in .worktrees/gate-r3-25e60015/GATE-W2-272-CHECKLIST.md; his by-NAME preservation check hit the UNRELATED root file of the same name (newer mtime too), sha256 separated them (12163af4 vs root). Rescued to .spt/preserved/hertz-r3-gate-worktree-rescue/doyle-r3-gate-triage-log-2026-09-09.md, sibling manifest verified from repo root by MY read 1/1 OK, 6178 B == worktree original re-hashed. The nine r...\n 818|## 09:48Z — root-lane-scratch close item: .spt/preserved/root-lane-scratch-2026-09-08.MANIFEST.sha256 paths are relative to the PRESERVED DIR, not the repo root (102 'could not be read' from root, 0 OK); from its own dir 102/102 OK. All seven manifested dirs (asm22*, asm241, asm63, b222-c222, claim-r2-lanes, e276-echo) ABSENT under root .spt/ and absent everywhere outside preserved (find, depth 4) -- the delete is already DONE; item retired. 'Fails from root' on this manifest is a path convention, not ...\n...\n 821|## 09:51Z — todlando CORRECTION on #289 (read-only, lane idle): the ruled shape (call-site deadline into read_event_until on the CLI's WHOLE carrier) does not bound anything -- it REFUSES instantly with ErrorKind::Unsupported by design (brain.rs:2457-2463, REQ-HAZARD-PUMP-IPC-DEADLINE, releases#190), so all six calls would error immediately. His falsifier was one layer too low (helper None off-pump, not 'is a deadline honorable on this carrier'). Revised shape: six wansend.rs callers (:480 wan, :615 kn...\n*822|## 09:54Z — hertz RULING-3 DONE: gate-r3 pool reaped 63.71 GiB (Length-sum 64.88, 1.8% over -- third hardlink instance, mildest); pool-release with PREBUILT xtask left xtask.exe mtime unmoved = positive control for IR-88; worktree remove refused on 3 untracked, all 9 hash-accounted (7 via manifests, 2 direct root-vs-worktree because a manifest does not list itself), then --force; pruned. COST he declared: that pool WAS the warm f6110c2a pool for his discriminator lane; neither of us connected the two; ...\n 823|## 09:55Z — docs lane PUSHED b66a9612 (force-with-lease, ls-remote == sha), PR #206 opened base main, MERGEABLE; thin ci run 34337341610 pull_request QUEUED 09:54:36Z (expect ~32 min, terminal ~10:27Z). Lands ff-only on green (PR 200 precedent).\n 824|## 09:56Z — #289 RULED after my own source read at a2f335f8 (all four of todlando's claims hold): REFUSE at the seam (shared helper lifted from digestlink.rs:93, called first in all six request_*, refusal cell names cold_start_pump), six wansend constructors -> cold_start_pump(DIAL_CARRIER_TIMEOUT, PumpTrace::from_env), loop bounded by reply_read_deadline, expiry = DISTINCT variant per family (read_peer_reply_until reclassifies TimedOut -> Other at brain.rs:2525, discriminator must survive), silent-pee...\n 825|## 09:59Z — PR #206 LANDED ff-only: thin ci 34337341610 att1 SUCCESS at b66a9612 (changes code=false for docs/RELEASE-RUNBOOK.md -> lint + unit SKIPPED by design, REQ-CI-DOCS-ONLY-THIN; traceability green; identical shape to PR 200's run 34217692226). Pushed the OBJECT b66a9612:refs/heads/main (a2f335f8..b66a9612, ff), ls-remote == sha, a2f335f8 ancestor, PR state MERGED mergeCommit b66a9612; local root main ff'd. hertz told: his measurement gate is satisfied, register base = b66a9612, WINDOW OPEN/CLOS...\n*826|## 10:20Z — hertz REGISTER LANE REVIEWED (.worktrees/hertz-register-85-89, 4045e0c9 IR-85 +123 / b603630c IR-86..89 +176 / 9834545a ledger +6-1, on b66a9612, clean, 0 CR, treqs rc=0, trailers as main). Ledger commit CLEAN (35 rows x 4 cols, no prose between rows, resident_service 3->4 in place naming :664/:670, my 4 rows verbatim; registry consumer census: golden.yml:54 validate-only, --match has no caller, an entry = authorization to rerun a red per GOLDEN-CI.md steps 3-4 -> ledger-only stands). TWO R...\n*827|## 10:31Z — hertz AMENDED lane RE-AUDITED clean (d32d5c4c IR-85 / 44c6ecd9 IR-86..89 / 88701366 ledger on b66a9612; +317 -1; added lines 0 x IR-79..82, 0 x NEEDS-OPERATOR; IR-85 firewall refs -> IR-89; IR-89 Status 'BOX HALF APPLIED 2026-09-08, WORKFLOW HALF OPEN', ripe on d882297f's PR; his grep-surface reword kept; CR 0; treqs 0). PUSH CLEARED (kitsubito-only thin run). His scoping lesson: the renumber audit ran on the TRANSFORMATION (commit 2's draft), not the LANE (commit 1's absorbed draft). Conta...\n 828|## 10:33Z — todlando #289 COMMIT 1 = 168c8622 on build/289-wan-reply-bound (parent a2f335f8, tree 1c67d6ca, 9 files +503 -34, treqs EXIT 0 with REQ-WAN-REPLY-BOUND [OK] impl/unit/int). READ IN FULL: refuse_unbounded_carrier(brain, verb) lifted to brain.rs (digestlink keeps its verb const + reason); WanRequestOutcome::PeerSilent (!took_custody), request_wan refuses pre-wire then read_event_until bounded by reply_read_deadline re-armed per frame on our stream, TimedOut -> PeerSilent (discriminator surviv...\n 829|## 10:34Z — hertz register lane PUSHED: origin docs/ir85-89-register = 88701366 (tree 192498f6, chain d32d5c4c -> 44c6ecd9 -> 88701366 on b66a9612, +317 -1) verified by my own ls-remote + fetch; PR #207 opened base main. Thin run is docs-only (kitsubito-only) -> ff on green. todlando commit 1 verdict SENT: accepted on shape; REQUIRED commit 1b = docs-site/src/messaging/overview.md verdict row WAN_PEER_SILENT:<id>@<node> + [doc->REQ-WAN-REPLY-BOUND] tag + 'doc' stage in the toml (zero cargo); same rule ...\n*830|## 10:37Z — PR #207 LANDED ff-only: thin run 34340894990 att1 SUCCESS at 88701366 (docs-only shape, kitsubito-only), guarded push (run head == object, origin/main == b66a9612 checked in the same script) b66a9612..88701366 = refs/heads/main, PR MERGED mergeCommit 88701366, local main ff'd. main now carries IR-85..89 + the five ledger rows; register ends IR-89. hertz WINDOW still OPEN (measurement on hfenduleam). todlando holding cargo, doing commit 1b (docs row + doc stage) + twin source reads.\n 831|## 10:42Z — todlando commit 1b = 5ca85851 (docs row WAN_PEER_SILENT + inline doc tag, 'doc' stage; treqs [OK] 4/4) ACCEPTED. Commit-2 docs census ruled: fork sibling sentence (instances/overview.md:67), redeem sibling row (knocking.md 'What you can be told' + :211 paragraph kept true); knock/answer/presence unpublished -> no row, tokens named in body. PRESENCE: wire enum (token/from_token, Unknown = probe unanswered), one caller wansend :678, consumed as the endpoint-list presence COLUMN (cli.rs :6983-...\n 832|## 10:54Z — OPERATOR: local node flipped to v0.68.0. Verified: spt 0.68.0; PACER-0 / alchemy-0 / alchemy-1 all online (no #287 strand this time); my perch live; endpoint roster all ONLINE (deployah, hertz, gears, sparrow, webbie, mobile-gw, emphasys). Peers on this node told to run spt shell list; hertz told to check his measurement legs against the process record across the restart instant.\n 833|## 10:59Z — CO-TENANT ATTRIBUTED, MINE: hertz measured two GitHub unit jobs on hfenduleam through his window. Mechanism (ci.yml classify :49): every NON-pull_request event emits code=true, so a PUSH TO MAIN runs lint + unit on BOTH runners; the docs-only skip is PR-only. My claim to hertz (twice) that docs-only pushes schedule kitsubito only was WRONG -- read from the PR run + runs-on, never the push run. Windows unit jobs: run 34337797758 (b66a9612 push) 09:59:57 -> 10:40:48 CANCELLED at the 40-min wa...\n...\n 859|## 13:05Z — hertz IR-90 lane PR #210 = 5888c5de on 5a50e625 (+99 -0 docs/INFRA-REGISTER.md; thin run 34354516836 green docs-only). Audits: IR-90 heading x1, no IR-9[1-9] tokens, amendment inside IR-85 (29 added lines before the IR-90 heading), both earlier corrections present, blob LF at both shas (his '5,072 CR' = working copy, layer misnamed while citing the rule). ONE REQUIRED FIX: amendment bullet 1 conflates run 34337797758 (b66a9612 push: CANCELLED at the 40-min wall, nobody's cancel) with run 34...\n*860|## 13:08Z — PR #210 LANDED ff-only: 46e12676 (amended in place from 5888c5de; bullet 1 = run 34337797758 CANCELLED at the 40-min wall, cancel string once in IR-90 with the separation parenthetical kept; blob LF; thin run 34354910726 green docs-only), guarded push 5a50e625..46e12676 = refs/heads/main, PR MERGED mergeCommit 46e12676, local main ff'd. main: IR-90 + IR-85 amendment landed; register ends IR-90. hertz queue confirmed: d882297f cross-OS run (IR-89 workflow half) then the .spt/ ignore lane.\n 861|## 13:09Z — PR #208 THIN CI GREEN at 8d974751: run 34351362639 att1, per-job success x5 (Linux unit 12:33-12:38, Windows unit 12:44:37 -> 13:04:53 on the emptied box, 32 GiB floor held). Commit-3 re-gate MET (test-only diff read + PR unit set green both runners, no third pool). #289 LANE COMPLETE AND PARKED: 168c8622 / 5ca85851 / f6eaa935 / 54259091 / 8d974751 on a2f335f8, PR #208 open + green, pool released; lands via the golden batch the operator greenlights (board: BACKLOG, no milestone, no open mil...\n*862|## 13:18Z — WAKE post-#289 (context reset 13:10Z). Board re-read: #289 BACKLOG / no milestone / no open milestone (last comment 09:49Z, mine); PR #208 green x5 at 8d974751, parked; no operator word on greenlight or the #292 restart. todlando runbook line (3f9ce68a, docs/seam-consumers-refusal off 46e12676, +9 -1, treqs 0, unpushed) ACCEPTED with the #289 parenthetical KEPT -- held for the next docs batch. hertz d882297f REVIEWED IN FULL before his in-situ run (merge-base e4444413, +204 -1 golden.yml + ...\n 863|## 13:21Z — DAEMON (own sample): broker image still 0.67.0 -> no restart yet. peer pump STALLED last tick 8048 s, last successful dial 8062 s; with my 11:07:42Z sample (223 s) the two readings agree on ONE last tick at ~11:05Z and none since -- 2 h 15 min with no round, longer than any bound a 4-dead-peer round can take (40 s), so this is NOT the 'slow rounds' reading I gave at 11:09Z: the pump stopped after the disk window and stayed stopped. 3/7 peers still connected on standing connections; new dial...\n*864|## 13:24Z — hertz: FULL probe design taken (rig.wait listen + ACK + A->B beacon, B's 10 s clock from first beacon; his reason = the fast red IS IR-89's promise and the beacon is what excludes 'A not up'); tag/doc fixup accepted (his second today, banking a fourth face); rebased test/twohost-inbound-probe to 0c963966 on 46e12676, twohost_web.rs blob 0eb2371c identical both sides, golden.yml 40f06699 -> a8c9f894 (main moved). Running the 7509 arm on the current binaries before the redesign. Told him: thr...\n*865|## 13:27Z — hertz THREE ARMS reported, labelled: DIR 1 (A hfenduleam, 7489) GREEN x2 (d882297f 13:13Z A cell 0.40 s; 0c963966 13:18Z 2.44 s, B 20 sent; no free-space stamps on either -- stated gap). DIR 2 (A kitsubito) att1 13:14Z RED INBOUND_BLOCKED 10.24 s = FINDING 2 MEASURED (cargo startup on the Windows SENDER put B's first datagram outside A's 10 s window; text blamed the box; kitsubito netmap lists 100.68.35.65/32 + ufw inactive contradicted it, so he re-ran instead of filing); att2 13:16Z direc...\n 866|## 13:35Z — hertz REDESIGN (beacon/ack) at 0c963966: 13:28Z all three arms GREEN incl. the 7509 CONTROL that red at 13:20Z -- he stopped. First cause his: A beaconed FROM ITS LISTENING SOCKET, opening return state for 7509 so B's probe crossed as SOLICITED traffic (the file's own sentence violated by its guard); fixed to an ephemeral beacon socket. 13:31Z re-run STILL GREEN on 7509, cause open: (a) residual state from 13:28 (146 s later), (b) program-scoped rule (none readable unelevated; port-filter e...\n 867|## 13:39Z — hertz: socket ruling IMPLEMENTED (A's listening socket never sends, beacon + ack from one ephemeral socket; B fixed port_b+9 receives beacons only, ephemeral socket sends probes + takes the ack; counted in source: 0 sends from either listening socket; build green; int tags re-checked immediately above fn two_host_web_role_b). HIS INCIDENT, disclosed: `git checkout <file>` run to READ dirtiness REVERTED the uncommitted redesign; recovered byte-for-byte by replaying his scratchpad splice scri...\n*868|## 13:48Z — hertz FINAL CODE 3a38d30d (one commit on 46e12676, force-with-lease, ls-remote == local, +396 -1 golden.yml +50 / twohost_web.rs +347, treqs 0, source md5 f317793... identical both hosts). PAIR red/red back-to-back (13:43:41-13:44:23Z A 101 after 40 s 39 beacons, B 101 48 sent acked=false beacon-first; 13:44:25-13:45:07Z same shape) = design writes no state; dir 1 13:45:14Z GREEN ack after 1 datagram; dir 2 13:45:41Z GREEN; free 174.38 flat. FOURTH DEFECT caught by dir 2 at the previous cod...\n*869|## 13:56Z — 3a38d30d REVIEWED IN FULL: design as ruled; golden.yml probe steps carry every var from_env requires (no silent pass). FOUR REQUIRED FIXES sent: (1) A acks ONCE and breaks -> one lost UDP datagram = A INBOUND OK + B INBOUND_BLOCKED in the same run (the split verdict he just fixed, now from packet loss); ack every probe for a 2 s drain window; (2) stale comment in B's cell still says the ack comes to the ephemeral port via `from` (contradicts the rig-port fix 30 lines lower) + dead set_read_...\n*870|## 14:02Z — hertz PR #211 OPEN: 9b96d7e7 (guard, four fixes folded in by amend) + 06c0ae6b (IR-89 amendment, six corrections + field-proof block + UNEXERCISED-until-golden warning) on 46e12676; ls-remote == local; +489 -1 over three files; treqs 0. Re-run at the fixup (md5 010ab075... both hosts): 7509 pair 13:54:20Z / 13:55:02Z RED/RED (A 39 beacons, B 47 datagrams, no ack, 101/101); dir 1 13:55:44Z GREEN \"acked 1 probe(s) in 2s\"; free 231.6 -> 231.01. His near-miss disclosed: a WAIT_SECS insert ancho...\n*871|## 14:04Z — hertz disk watchdog trace (observe-only, 139 samples 11:52:46-13:57:07Z, 1/min, preserved .spt/preserved/hertz-leak-670-legs/disk-full-trace.log, hash d58ce838b677e62d both copies): max 238.41 @12:45:20Z, min 12.53 @12:12:45Z, two samples under 15 GiB (14.85 @12:12:11Z, 12.53 @12:12:45Z) inside the #209 leak lane's build+teardown window after a start floor would have passed it at 136.15. Caveats his: 1-min sampling leaves the true minimum unbounded below; attributes nothing. Ruled: ONE line...\n 872|## 14:08Z — hertz fb71292b (docs amend in place over 9b96d7e7; ls-remote == local; +8 -3 register): Status -> WORKFLOW HALF BUILT 2026-09-09, PR #211, LANDED-pending-golden with the unexercised clause; correction 2 gained the by-elimination clause; Ripe-when -> the next golden run. Read and accepted. IR-90 disk-trace line NOT in it (messages crossed); run 34360822987 created 14:01:01Z pending -> told him to fold it now as one more amend (restart at minute two beats a later both-runner main push).\n 873|## 14:12Z — CORRECTION, mine: the \"64.33 @12:13\" I handed hertz as the seam between the two disk traces is NOT in the preserved sampler file (first line 12:15:37Z 54.25). It was a spot read taken in the sampler's launch command (my 12:16Z row) and my 12:21Z row concatenated it with sampler values as one series. hertz caught it by reading the file before writing the register line and wrote the seam without a number -- correct. Line stands; README dropped in the preserved dir naming the filename's 12-13Z...\n 874|## 14:24Z — .spt/ IGNORE LANE (hertz classify-only census: 152 entries, 277.2 MiB, preserved/ 204.8 MiB / 1133 files; nothing touched; by-path check-ignore rc=1 on all rows). FINDING: TWO files under .spt/ are TRACKED (6f620ce4 todlando, deliberate W2 record) -- a blanket ignore leaves them tracked and the lane would ship believing .spt/ sealed. RULED: RELOCATE via git mv (twohost-web-local.sh -> .github/bench/, pump-on-one-box-rig.patch -> docs/spikes/; zero repo citations, five memory citations stay ...\n 875|## 14:30Z — hertz per-file report on the seven + an eighth, ruled: IR37-RIDER-NOTES DEAD; PID-KILL-CENSUS -> docs/ + IR-81 path fix (:4304); REAUDIT-REFS DEAD (its unlanded \"repo column on the census rows\" ruling = MINE, OPEN, re-derive later); RIDER-65S-DESIGN LIVE (d7c2105e not in main, IR-84 unfiled) -> docs/design/; ir37-redundancy-evidence, operator-brief-rc-panel, pr-rigports-body DEAD; launch-battery.py (register cites :4267 + :4276; its docstring says it was ALREADY LOST ONCE to a .spt/ sweep a...\n*876|## 14:33Z — PR #211 LANDED ff-only: run 34361733081 five/five green at 7d2f0d70 (Windows unit completed ~14:31Z); guarded push (run headSha == 7d2f0d70 full + conclusion success, origin/main == 46e12676, ancestor check) 46e12676..7d2f0d70 = refs/heads/main; PR MERGED mergeCommit 7d2f0d70; local main ff'd (3 files +509 -3). main now carries the IR-89 workflow half (beacon/ack inbound probe, both golden.yml steps, WAIT_SECS 300 explicit) + the six-correction amendment + the IR-90 disk-trace line. Golden....\n 877|## 14:44Z — PR #212 (hertz, chore/spt-scratch-ignore, 54d7b122 on 7d2f0d70, 8 files +663 -3) READ IN FULL: R100 x2 (tracked pair, blob-identical per his two-layer check: wc != blob because CRLF-normalized at 6f620ce4), A x4, register edits exactly :4267/:4288/:4304 (:4276 = bare filename, his \"four\" retracted to three before I read), .gitignore +22 with `.spt/` at :51, bench_row_parity read_dir sweep cleared by measurement (ext filter :81, no step template in the .sh). Proof legs: hash before/after 6/6...\n 878|## 14:47Z — hertz #212 amended 54d7b122 -> b0b67aaa (force-with-lease, ls-remote == local): (1) launch-battery.py Usage -> .github/bench/ path; (2) .gitignore enumeration -> rule + count (six cited paths, measured seven raw hits with the patch's own self-reference identified as the non-citation); (3) HIS third of the same class: the pump patch's line-34 \"Restore with: git apply .spt/preserved/...\" repointed to docs/spikes/ (R099 now, header prose, git apply --stat still parses 1 file +403 -148). Re-pro...\n 879|## 15:19Z — PR #212 LANDED ff-only: run 34365591875 five/five green at b0b67aaa (Windows unit 14:52:50-15:12:33Z); guarded push (run headSha == b0b67aaa full + success, origin/main == 7d2f0d70, ancestor) 7d2f0d70..b0b67aaa = refs/heads/main; PR MERGED mergeCommit b0b67aaa; local main == origin/main. Post-landing proof on this checkout: zero `?? .spt/` rows, check-ignore by path -> .gitignore:52:.spt/ populated, all six moved files present at their new paths. Memories updated with the landing sha: git-s...\n\n# IO-PARSER-22-JIT.md\n 81|\n*82|- IR-66: the two first-chunk-needle latent members — TICK39 at attach.rs:561,\n 83|  ALT_VIEWPORT_MARKER at attach.rs:672 — the one-line later-needle treatment proven at v0.63.0.\n 84|\n 85|## Gate discipline (this milestone)\n\n# REGISTER-SWEEP-0671-DRAFT.md\n 81|| IR-65 | kitsubito kernel-audit backpressure (remediated) | \"REMEDIATED-AT-BOX 2026-08-25 ...; entry stays OPEN as the re-check record because the storm SOURCE persists\" | \"a re-check trigger fires\" (tailscale snap update / auditd update / box reimage) | \"two read-only commands per check\" | releases#225 | 2026-08-25 |\n*82|| IR-66 | First-chunk-needle test class: two members remain | \"BUILT — hertz rider PR #161, landed ff at `d04b922d` (2026-08-27, IO-PARSER #22 intake rider)\" | \"next milestone intake (hertz test lane) or the first golden red at ~240s on an attach cell\" | \"two one-line test edits\" | hertz rider PR #161, IO-PARSER #22 | 2026-08-27 |\n 83|| IR-67 | `-p spt --bins` leg runs zero e2e coverage | \"BUILT — remedy applied across the IO-PARSER #22 milestone (2026-08-27/28)\" | \"next milestone intake (the battery template is touched at every intake)\" | \"template lines only\" | IO-PARSER #22 milestone | 2026-08-28 |\n 84|| IR-68 | PSYCHE_INGEST_FAIL cause unproven, index.lock cleared | \"OPEN, investigation-shaped\" | \"next PSYCHE_INGEST_FAIL sighting in the field (capture the failing store state before touching it), or a dedicated probe slot\" | \"investigation; no product change until the mechanism is pinned\" | IO-PARSER #22, PR #163 | 2026-08-27 |\n 85|| IR-69 | Inherited stderr tokens tear between fragments | \"OPEN, product remedy complete and parked GREEN-AND-READY at `d0fdd58d` on `feat/emit-single-write`, owned by todlando, awaiting golden-batch assembly\" | \"Closes when: releases#243's residual conversion + generator fix land and a re-census at that sha reads zero shipping residue under both delimiter forms\" | \"product lane complete elsewhere; register follow-through small\" | releases#241 (product remedy, landed); releases#243 (residual conversion,...\n...\n 88|| IR-72 | No read verb names a perch/seat holder | \"OPEN, observability gap; no remedy scheduled\" | \"the next roster/status read-model change or another rig needs to reap a named holder\" | \"small read-model/API addition, medium if seat and perch custody need separate typed variants\" | PR #174 (`70c1a303`) | 2026-08-29 |\n*89|| IR-73 | ci.yml/release.yml read floor pre-checkout | \"OPEN, filed by doyle 2026-08-30 at the #242/v0.66.0 close sweep\" | \"next touch of `ci.yml`/`release.yml`, or the next intake's tooling-rider slot (compose with IR-59/IR-57's standing pair)\" | \"small — reorder or comment per site, 8 sites\" | Compose with IR-59/IR-57 tooling-rider slot; per top-of-file note this arc's workflow commits did NOT carry it | 2026-08-30 |\n 90|| IR-74 | kitsubito holds 21,643 /tmp endpoint homes | \"OPEN, filed by doyle 2026-08-30 at the #242/v0.66.0 close sweep\" | \"next kitsubito rig touch, or the between-milestone box-audit slot\" | \"small (one sweep script + adoption in the box's rig steps); the measurement rerun is one `find \\| wc`\" | No | 2026-08-30 |\n 91|| IR-75 | traceable-reqs not installed on kitsubito (treqs exit 127) | \"OPEN, filed by doyle 2026-08-30 at the #242/v0.66.0 close sweep\" | \"next Linux gate-driver touch or kitsubito box-audit slot\" | \"trivial (install or one driver edit + comment)\" | No | 2026-08-30 |\n 92|\n...\n 121|  \"preflight\", and \"v0.67.1 shipped (golden ... green)\" on \"golden\".\n*122|- **IR-66** — trigger \"next milestone intake (hertz test lane)\" matches \"WEBSERVE milestone #272\n 123|  GREENLIT with waves W0–W3\" on the word \"milestone intake\".\n 124|- **IR-67** — trigger \"next milestone intake (the battery template is touched at every intake)\"\n 125|  matches \"WEBSERVE milestone #272 GREENLIT\" on \"milestone intake\", and also matches \"nextest\n...\n 127|  template) though the word \"nextest\" itself is not in this entry's trigger text.\n*128|- **IR-73** — trigger \"next intake's tooling-rider slot (compose with IR-59/IR-57's standing pair)\"\n 129|  matches \"WEBSERVE milestone #272 GREENLIT\" on \"next intake\", and its subject (ci.yml/release.yml\n 130|  floor sites) matches \"IR-76 ... three-arm pre-flight\" on the shared golden-box preflight topic.\n 131|\n\n# WEBSERVE-272-JIT.md\n 108|  the `golden.yml` touch at `04e32c8c` fired the trigger unweighed), IR-59 log-the-floor half\n*109|  (record free space beside every floor check), IR-73 (the 8 literal-first floor sites in\n 110|  `ci.yml`/`release.yml`). Entry text in `docs/INFRA-REGISTER.md` is the spec.\n*111|- **IR-66 — RULED SATISFIED 2026-09-06 (hertz measured, doyle ruled)**: the register body says\n 112|  BUILT at `d04b922d`/#161 and both cells are present at `17815c9c` (attach.rs:530/:538,\n 113|  :655). The earlier \"residual — two one-line test edits\" line here was a carried-forward\n 114|  fossil of the entry's own \"Size:\" line, which describes the fix that LANDED. No edits; the\n\n# docs/\n## INFRA-REGISTER.md\n 19|respin edit under a pre-registered hard stop is not a remedy window, so the entry gains that datum\n*20|and is COMPOSED forward. **Composed: the floor trio IR-46 + IR-59 (log-the-floor half) + IR-73\n 21|(8 literal-first sites) as ONE hertz workflow rider on WEBSERVE** (`ci.yml`/`golden.yml`/\n 22|`release.yml`, thin PR off the golden path, before the WEBSERVE golden head so that head runs\n 23|under it); **IR-59's log-the-floor line ALSO rides IR-76's three-arm pre-flight on W0's driver\n*24|template** (todlando authors; free space recorded beside the floor check). **IR-66 residual (two\n 25|first-chunk-needle members) = hertz WEBSERVE test rider** (two one-line edits). **IR-12 residual =\n 26|W3 drift-gate rider** (hertz already holds W3's drift-gate riders). IR-67 satisfied at this intake\n 27|by construction (`--no-fail-fast` in the W0 driver template; todlando's 2026-09-06 correction).\n...\n 52|CANNOT answer a CWD-pin question (todlando's false-positive self-catch). Board mints this arc:\n*53|#244/#246/#247/#254 (BACKLOG). #16/#17 discharged drops (detach + EVAL). IR-73's ci.yml/\n 54|release.yml floor-site reorders did NOT ride this arc's workflow commits — still owed, next\n 55|touch. No entries retired.\n 56|\n...\n 75|low-water; within-job floor re-read rides the next workflow commit; box ~51 GB non-recovering\n*76|consumption → audit slot). FILED: IR-73 (ci.yml/release.yml literal-first floor sites off the\n 77|golden path, 8 sites), IR-74 (kitsubito 21,643 /tmp endpoint homes, hertz's measurement), IR-75\n 78|(kitsubito treqs 127 vacuous leg — install-or-drop; IR-37 deliberately NOT reopened, different\n 79|surface). Composed: IR-14/26/27/49 as ONE between-milestone pool/worktree audit slot (window\n...\n 85|Prior sweep: 2026-08-27, IO-PARSER (#22) INTAKE (wave map: `IO-PARSER-22-JIT.md` + #22 comment).\n*86|Rulings: IR-66 COMPOSED as the parallel hertz rider (the two attach-cell later-needle treatments,\n 87|attach.rs:561/:672 — the \"rides next intake\" note comes due here). IR-52 conditional rider\n 88|CARRIED FORWARD on this milestone's docs lane, same terms as WAX-SEAL (depth fix lands iff the\n 89|lane touches the docs-site CLI reference generator, else stays open). IR-67 COMPOSED as JIT gate\n...\n 2631|\n*2632|- **2026-09-06 addendum (doyle, v0.67.1 close sweep): trigger FIRED at `04e32c8c` — `golden.yml` touched (2-line HEAVY reclass of `brain_resume_conn_deadlock` on the respin) with no remedy weighed. Not a drive-by by choice: the touch rode a respin under a pre-registered hard stop, which is no remedy window. COMPOSED with IR-59 (log-the-floor) + IR-73 (literal-first sites) as one hertz workflow rider on WEBSERVE #272; the remedy weighing happens on THAT lane, before the WEBSERVE golden head.**\n 2633|\n 2634|<!-- [doc->REQ-CI-FREE-SPACE-PREFLIGHT] -->\n 2635|- **2026-09-06 remedy ruling (doyle, WEBSERVE rider):** retain 32 GiB; record raw-byte\n...\n 2637|  End DISK assertions run `if: always()` before teardown, including after failed workloads.\n*2638|  A fresh `FLOOR_DOCS` assertion immediately before docs-drift composes with IR-73's second half.\n 2639|  Raising the floor is refused without a measured peak; continuous sampling adds lifecycle\n 2640|  machinery while remaining blind between samples. Start/end are a dataset, not a minimum or\n 2641|  headroom guarantee. Golden execution evidence waits for the WEBSERVE golden head; the thin\n...\n 3526|\n*3527|### IR-66 — first-chunk-needle test class: two latent members remain after the v0.63.0 fix (attach.rs:561, :672)\n 3528|\n 3529|- **Status:** BUILT — confirmed present at `17815c9c` (hertz 2026-09-06); leaves the register at the WEBSERVE close sweep. Hertz rider PR #161, landed ff at `d04b922d` (2026-08-27, IO-PARSER #22\n 3530|  intake rider). Both members got the later-needle treatment (TICK39 delayed past burst on both\n...\n 3782|\n*3783|### IR-73 — ci.yml and release.yml still read the free-space floor PRE-checkout (literal-first sites off the golden path); and any job's floor is stale by its last heavy step\n 3784|\n 3785|- **Status:** OPEN, filed by doyle 2026-08-30 at the #242/v0.66.0 close sweep (deployah flag\n 3786|  2026-08-29, widen lane). · **Origin:** the #242 cut lost two golden attempts to exactly this\n...\n 3875|- **Ripe when:** next driver-template touch (a/b are text; a is one leg), next `ci.yml`\n*3876|  touch for (c) — compose with [[IR-73]]'s reorders; (d) rides the next runbook edit.\n 3877|- **Size:** small — one pre-flight leg + one census predicate + two doc sentences.\n 3878|\n 3879|### IR-77 — nothing stamps the interval between a daemon child's spawn and the brain's first log line, so a readiness-deadline red cannot say WHERE the time went\n...\n 4822|     runner dir, so it proves the mechanism's size, not the runner's exposure. Unsettable\n*4823|     unelevated; same shape as **IR-89**'s elevated firewall rule.\n 4824|  4. **CI census, cheap and durable:** print `Get-MpComputerStatus` RealTimeProtectionEnabled plus\n 4825|     the ExclusionPath read **verbatim, refusal text included**, in the Windows job's census step,\n 4826|     so a run's own record says what Defender it ran under.\n...\n 4832|- **Kin:** [[IR-76]] (the golden runner IS the builders' box — the structural reason a desktop's\n*4833|  load reaches CI at all), [[IR-64]] (box-level facts only the operator can move), [[IR-89]] (the\n 4834|  other elevated box-rule ask), `defender-first-touch-tax-on-fresh-test-binaries` and\n 4835|  `e2e-leaked-daemons-shared-box` (memory).\n 4836|- **Ripe when:** arm 1 now; arms 2-4 on the operator's answer; arm 5 at the next `golden.yml` touch\n...\n 4895|  ripe-when arm — a golden that dies at the floor despite adopted pool discipline — FIRED here\n*4896|  in the in-job form), [[IR-73]] (second half BUILT: the within-job re-read exists and is what\n 4897|  produced the FLOOR_DOCS reading), REQ-CI-FREE-SPACE-PREFLIGHT.\n 4898|- **Coupling (deployah 23:54Z, from `golden.yml` at `25e60015`):** the Windows `DISK docs floor`\n 4899|  (:616) and `Docs drift gate — windows` (:629) carry only `if: runner.os == 'Windows'`, no\n...\n 4941|\n*4942|- **AMENDMENT 2026-09-10 (releases#294, golden 34445961595 att1 @ `a9e786b2`) — THE STARVING RUN CAN\n 4943|  BE GOLDEN'S OWN PR, which makes this self-inflicted and recurrent on every golden run with a PR\n 4944|  open.** Measured timeline: **07:18:59Z** golden `test (Windows)` completes and releases hfenduleam;\n 4945|  **07:18:59Z** twohost-a queued; **07:19:01Z** PR run **34446095808** job `unit (Windows,\n...\n 4960|  laundered into it.\n*4961|- **⚠ ITS WALL CLOCK IS INDISTINGUISHABLE FROM [[IR-89]]'s.** A 900 s twohost red whose panel blames\n 4962|  pairing is ALSO the exact signature of the banked Windows-firewall hazard. The panel alone cannot\n 4963|  separate them; **the job TIMELINE can**. Check the schedule before accepting the firewall hazard for\n 4964|  any 900 s twohost red — this one fit that signature perfectly and was not it.\n 4965|\n*4966|### IR-88 — `pool-release` via `cargo run -p xtask` REBUILDS xtask INTO the pool it is releasing, so a reaped pool regrows ~2.8 GB in silence\n 4967|\n 4968|- **Status:** OPEN, filed by doyle 2026-09-08 from hertz's reap report (20:00Z) during the #272\n 4969|  golden r2 repair. · **Origin:** hertz reaped hertz-lane4 / hertz-repin / hertz-percell-id target\n...\n 4994|\n*4995|### IR-89 — hfenduleam's Windows Firewall drops cold inbound UDP to the runner-built test exes, so the two-host rig's first B→A claim (W2 helper) reds for its whole 900 s budget and the panic blames A\n 4996|\n 4997|- **Status:** BOX HALF **APPLIED** 2026-09-08; WORKFLOW HALF **BUILT** 2026-09-09 — PR #211\n 4998|  (`9b96d7e7` + this amendment), **LANDED-pending-golden**: the `golden.yml` steps are UNEXERCISED\n...\n 5741|- **THE DIFFERENTIAL that makes it worth an entry rather than a shrug:** the same cell shows **0\n*5742|  failures at the candidate** in golden 34481993681 Phase A on this same box — that run's single\n 5743|  failure was the sync cell (`3381 tests run: 3380 passed (6 slow, 5 leaky), 1 failed, 1 skipped`).\n 5744|  So: 0-of-1 at `a9e786b2` under CI load, 3-of-3 at `ed8ecd94` under local HEAVY load.\n 5745|- **WHAT THAT DOES NOT ESTABLISH.** It does **not** isolate the instrumentation or the box as the\n...\n 5748|  it** the same hour under todlando's and hertz's correction; the withdrawal is recorded in\n*5749|  `.spt/preserved/gate-r2-34481993681-20260910/CLASSIFICATION-AMENDMENT-2-doyle.md`.\n 5750|- **Confounded by IR-97** (below): the three runs were not equivalent conditions.\n 5751|- **Ripe when:** any lane touches daemon stop/start convoy behaviour, OR a golden run reds this cell\n 5752|  at a candidate, OR someone runs the cell at `a9e786b2` under the same local HEAVY workload — that\n## KNOWN-HAZARDS.md\n 1038|<!-- [doc->REQ-HAZARD-RETRY-MARGIN-UNMEASURED] -->\n*1039|- **Failure (paid-for, releases#294 / v0.69.0: gate runs `34445961595` and `34481993681`, two reds at the SAME cell, `spt-daemon::sync two_tier_sync_lands_and_gate_refuses_server_side`):** the wait that gates the assertion is the house-standard 400 iterations x 25 ms — a 10.0 s budget — and it reports PASS or FAIL and nothing else. The elapsed is discarded. Two full gate arms across two boxes were spent and the cause of the red is still **UNCLASSIFIED**, because the instrument could not answer a ques...\n 1040|- **Defect (a) — a green carries no margin.** Instrumented at 400 observations on the Windows cell, successes landed at **4.448 s** (observation 176/400) and **9.940 s** (observation 392/400). Those are the SAME GREEN to the loop. A pass one scheduling hiccup from red is indistinguishable from a healthy one, so **a history of passes is not evidence of headroom** — every prior green of this cell is silent about margin, including the greens on the record head.\n 1041|- **Defect (b) — an expiry is RIGHT-CENSORED, not a sample.** The loop stops looking at the bound (measured 10.156–10.200 s wall), so it establishes that no eligible condition was observed BEFORE expiry and **nothing whatsoever about after**. A censored expiry has **no upper endpoint**: it cannot be averaged in, cannot be called a latency or \"the tail\", and cannot separate DELAYED from ABSENT, RETIRED, or FILTERED. Write `CENSORED at X, no upper endpoint`.\n 1042|- **THIS IS THE SEAM THAT WITHDREW THREE CAUSE PHRASINGS IN ONE HOUR** (2026-09-10, all mine): *\"delayed publication, measured\"* — censoring, caught by hertz; *\"a ceiling outside the measured tail\"* — unspecifiable, hertz **refused to implement rather than invent a number**, and that refusal was worth more than compliance; *\"boundary defect MEASURED\"* — caught by todlando, **proximity to a threshold is a RISK SIGNAL, never a verdict that the threshold is wrong**. If the 9.940 s success is itself pa...\n\n[Some lines truncated to 512 chars]"}],"details":{"scopePath":"docs, *.md","searchPath":"C:\\Users\\decid\\Documents\\projects\\spt-core","cwd":"C:\\Users\\decid\\Documents\\projects\\spt-core","matchCount":42,"fileCount":6,"files":["GATE-W2-272-CHECKLIST.md","IO-PARSER-22-JIT.md","REGISTER-SWEEP-0671-DRAFT.md","WEBSERVE-272-JIT.md","docs/INFRA-REGISTER.md","docs/KNOWN-HAZARDS.md"],"fileMatches":[{"path":"GATE-W2-272-CHECKLIST.md","count":15},{"path":"IO-PARSER-22-JIT.md","count":1},{"path":"REGISTER-SWEEP-0671-DRAFT.md","count":4},{"path":"WEBSERVE-272-JIT.md","count":2},{"path":"docs/INFRA-REGISTER.md","count":19},{"path":"docs/KNOWN-HAZARDS.md","count":1}],"truncated":true,"displayContent":"# GATE-W2-272-CHECKLIST.md\n 691│\n*692│## 20:06:42Z -- RESUMED post-clear. Rerun 34262154550 in_progress: test Windows started 20:00:38Z, twohost-a/b not yet materialized; deployah owns verdict. Wait window filled: IR-79 (32 GiB floor below 67.4 GiB footprint; IR-64 ripe-arm FIRED in-job form; IR-73 second half BUILT), IR-80 (two-host halves independent jobs on one runner, B 900 s on own clock, panic blames pairing), IR-81 (pool-release rebuilds xtask into reaped pool) DRAFTED to scratchpad/IR-79-81-draft.md (6749 B) for the release-close reg...\n 693│\n 694│## 20:14:41Z -- ROOT LANE SCRATCH CLASSIFIED + PRESERVED (delete deferred to release close). 102 untracked driver-output files (exit/raw/log/done), 6.8 MB, seven closed-lane families by content+mtime: ASM22/ASM22B = assembly-io-parser-22 on the ROOT pool (08-28, v0.63.0; the 20 reap_N legs are compile outputs); ASM63 = #63 on worktree gate-222-ca30a79e (08-25, v0.62.0); ASM241 = worktree asm-241 (08-29, v0.65.0; only family with a record pointer, ASM-241-GATE-VERDICT.md, which stays); E276 = echo-276 wor...\n 695│\n    │...\n 814│## 09:43Z — alchemy release v0.68.0 DONE: 13 Requests -> DONE (#272 milestone + members #147 #246 #248 #249 #265 #266 #268 #17 + merge-closed #276 #277 #279 #280); board #272 CLOSED state: DONE (gh read). todlando given the filing word (2 creates + #289 scope comment). hertz's ledger lane now carries my 4 rows (.spt/preserved/doyle-flake-rows-2026-09-09/, 4/4) + resident_service 4th. RELEASE-INDEX ledger line updated: latest v0.68.0 c104 @a2f335f8 + the four missing cuts v0.65.0 c100 / v0.66.0 c101 / v...\n*815│## 09:46Z — REGISTER CENSUS main@a2f335f8 vs my 09-08 draft: ALL FIVE draft entries UNLANDED (main's IR-79..83 = hertz's rig entries, other subjects; zero hits for 67.4 GiB footprint / two-host halves 900 s / pool-release rebuilds xtask / firewall cold inbound / desktop load). Draft copied to root .spt/preserved/doyle-r3-triage/IR-79-82-NEXT-old-draft-2026-09-08.md (99b05f2a). RULED: hertz's register lane lands IR-85 (his + IR-NEXT folded) and IR-86 floor / IR-87 two-host halves / IR-88 pool-release re...\n 816│## 09:45Z — deployah step 7 shape-0680 teardown PROPOSAL (preserve-first): worktree detached at dead r2 sha 25e60015 (ancestor of main), pool lane shape-0680-r2 lane_base e4444413 (ancestor of main = finished), Length-sum 11.59 GiB (overstated by hardlinks, stated), OUTBOUND real dir, INBOUND none, not locked, untracked 0, one stat-cache M proven identical raw + preserved (8525a194). CONFIRMED steps 1-3: pool-release with PREBUILT xtask + Test-Path, reap TARGET subtree, then git worktree remove (refusa...\n 817│## 09:47Z — RESUMED post-recharge. hertz STOP-AND-READ: my r3 triage log (05:39Z-06:50Z, 9 rows) lived ONLY in .worktrees/gate-r3-25e60015/GATE-W2-272-CHECKLIST.md; his by-NAME preservation check hit the UNRELATED root file of the same name (newer mtime too), sha256 separated them (12163af4 vs root). Rescued to .spt/preserved/hertz-r3-gate-worktree-rescue/doyle-r3-gate-triage-log-2026-09-09.md, sibling manifest verified from repo root by MY read 1/1 OK, 6178 B == worktree original re-hashed. The nine r...\n 818│## 09:48Z — root-lane-scratch close item: .spt/preserved/root-lane-scratch-2026-09-08.MANIFEST.sha256 paths are relative to the PRESERVED DIR, not the repo root (102 'could not be read' from root, 0 OK); from its own dir 102/102 OK. All seven manifested dirs (asm22*, asm241, asm63, b222-c222, claim-r2-lanes, e276-echo) ABSENT under root .spt/ and absent everywhere outside preserved (find, depth 4) -- the delete is already DONE; item retired. 'Fails from root' on this manifest is a path convention, not ...\n    │...\n 821│## 09:51Z — todlando CORRECTION on #289 (read-only, lane idle): the ruled shape (call-site deadline into read_event_until on the CLI's WHOLE carrier) does not bound anything -- it REFUSES instantly with ErrorKind::Unsupported by design (brain.rs:2457-2463, REQ-HAZARD-PUMP-IPC-DEADLINE, releases#190), so all six calls would error immediately. His falsifier was one layer too low (helper None off-pump, not 'is a deadline honorable on this carrier'). Revised shape: six wansend.rs callers (:480 wan, :615 kn...\n*822│## 09:54Z — hertz RULING-3 DONE: gate-r3 pool reaped 63.71 GiB (Length-sum 64.88, 1.8% over -- third hardlink instance, mildest); pool-release with PREBUILT xtask left xtask.exe mtime unmoved = positive control for IR-88; worktree remove refused on 3 untracked, all 9 hash-accounted (7 via manifests, 2 direct root-vs-worktree because a manifest does not list itself), then --force; pruned. COST he declared: that pool WAS the warm f6110c2a pool for his discriminator lane; neither of us connected the two; ...\n 823│## 09:55Z — docs lane PUSHED b66a9612 (force-with-lease, ls-remote == sha), PR #206 opened base main, MERGEABLE; thin ci run 34337341610 pull_request QUEUED 09:54:36Z (expect ~32 min, terminal ~10:27Z). Lands ff-only on green (PR 200 precedent).\n 824│## 09:56Z — #289 RULED after my own source read at a2f335f8 (all four of todlando's claims hold): REFUSE at the seam (shared helper lifted from digestlink.rs:93, called first in all six request_*, refusal cell names cold_start_pump), six wansend constructors -> cold_start_pump(DIAL_CARRIER_TIMEOUT, PumpTrace::from_env), loop bounded by reply_read_deadline, expiry = DISTINCT variant per family (read_peer_reply_until reclassifies TimedOut -> Other at brain.rs:2525, discriminator must survive), silent-pee...\n 825│## 09:59Z — PR #206 LANDED ff-only: thin ci 34337341610 att1 SUCCESS at b66a9612 (changes code=false for docs/RELEASE-RUNBOOK.md -> lint + unit SKIPPED by design, REQ-CI-DOCS-ONLY-THIN; traceability green; identical shape to PR 200's run 34217692226). Pushed the OBJECT b66a9612:refs/heads/main (a2f335f8..b66a9612, ff), ls-remote == sha, a2f335f8 ancestor, PR state MERGED mergeCommit b66a9612; local root main ff'd. hertz told: his measurement gate is satisfied, register base = b66a9612, WINDOW OPEN/CLOS...\n*826│## 10:20Z — hertz REGISTER LANE REVIEWED (.worktrees/hertz-register-85-89, 4045e0c9 IR-85 +123 / b603630c IR-86..89 +176 / 9834545a ledger +6-1, on b66a9612, clean, 0 CR, treqs rc=0, trailers as main). Ledger commit CLEAN (35 rows x 4 cols, no prose between rows, resident_service 3->4 in place naming :664/:670, my 4 rows verbatim; registry consumer census: golden.yml:54 validate-only, --match has no caller, an entry = authorization to rerun a red per GOLDEN-CI.md steps 3-4 -> ledger-only stands). TWO R...\n*827│## 10:31Z — hertz AMENDED lane RE-AUDITED clean (d32d5c4c IR-85 / 44c6ecd9 IR-86..89 / 88701366 ledger on b66a9612; +317 -1; added lines 0 x IR-79..82, 0 x NEEDS-OPERATOR; IR-85 firewall refs -> IR-89; IR-89 Status 'BOX HALF APPLIED 2026-09-08, WORKFLOW HALF OPEN', ripe on d882297f's PR; his grep-surface reword kept; CR 0; treqs 0). PUSH CLEARED (kitsubito-only thin run). His scoping lesson: the renumber audit ran on the TRANSFORMATION (commit 2's draft), not the LANE (commit 1's absorbed draft). Conta...\n 828│## 10:33Z — todlando #289 COMMIT 1 = 168c8622 on build/289-wan-reply-bound (parent a2f335f8, tree 1c67d6ca, 9 files +503 -34, treqs EXIT 0 with REQ-WAN-REPLY-BOUND [OK] impl/unit/int). READ IN FULL: refuse_unbounded_carrier(brain, verb) lifted to brain.rs (digestlink keeps its verb const + reason); WanRequestOutcome::PeerSilent (!took_custody), request_wan refuses pre-wire then read_event_until bounded by reply_read_deadline re-armed per frame on our stream, TimedOut -> PeerSilent (discriminator surviv...\n 829│## 10:34Z — hertz register lane PUSHED: origin docs/ir85-89-register = 88701366 (tree 192498f6, chain d32d5c4c -> 44c6ecd9 -> 88701366 on b66a9612, +317 -1) verified by my own ls-remote + fetch; PR #207 opened base main. Thin run is docs-only (kitsubito-only) -> ff on green. todlando commit 1 verdict SENT: accepted on shape; REQUIRED commit 1b = docs-site/src/messaging/overview.md verdict row WAN_PEER_SILENT:<id>@<node> + [doc->REQ-WAN-REPLY-BOUND] tag + 'doc' stage in the toml (zero cargo); same rule ...\n*830│## 10:37Z — PR #207 LANDED ff-only: thin run 34340894990 att1 SUCCESS at 88701366 (docs-only shape, kitsubito-only), guarded push (run head == object, origin/main == b66a9612 checked in the same script) b66a9612..88701366 = refs/heads/main, PR MERGED mergeCommit 88701366, local main ff'd. main now carries IR-85..89 + the five ledger rows; register ends IR-89. hertz WINDOW still OPEN (measurement on hfenduleam). todlando holding cargo, doing commit 1b (docs row + doc stage) + twin source reads.\n 831│## 10:42Z — todlando commit 1b = 5ca85851 (docs row WAN_PEER_SILENT + inline doc tag, 'doc' stage; treqs [OK] 4/4) ACCEPTED. Commit-2 docs census ruled: fork sibling sentence (instances/overview.md:67), redeem sibling row (knocking.md 'What you can be told' + :211 paragraph kept true); knock/answer/presence unpublished -> no row, tokens named in body. PRESENCE: wire enum (token/from_token, Unknown = probe unanswered), one caller wansend :678, consumed as the endpoint-list presence COLUMN (cli.rs :6983-...\n 832│## 10:54Z — OPERATOR: local node flipped to v0.68.0. Verified: spt 0.68.0; PACER-0 / alchemy-0 / alchemy-1 all online (no #287 strand this time); my perch live; endpoint roster all ONLINE (deployah, hertz, gears, sparrow, webbie, mobile-gw, emphasys). Peers on this node told to run spt shell list; hertz told to check his measurement legs against the process record across the restart instant.\n 833│## 10:59Z — CO-TENANT ATTRIBUTED, MINE: hertz measured two GitHub unit jobs on hfenduleam through his window. Mechanism (ci.yml classify :49): every NON-pull_request event emits code=true, so a PUSH TO MAIN runs lint + unit on BOTH runners; the docs-only skip is PR-only. My claim to hertz (twice) that docs-only pushes schedule kitsubito only was WRONG -- read from the PR run + runs-on, never the push run. Windows unit jobs: run 34337797758 (b66a9612 push) 09:59:57 -> 10:40:48 CANCELLED at the 40-min wa...\n    │...\n 859│## 13:05Z — hertz IR-90 lane PR #210 = 5888c5de on 5a50e625 (+99 -0 docs/INFRA-REGISTER.md; thin run 34354516836 green docs-only). Audits: IR-90 heading x1, no IR-9[1-9] tokens, amendment inside IR-85 (29 added lines before the IR-90 heading), both earlier corrections present, blob LF at both shas (his '5,072 CR' = working copy, layer misnamed while citing the rule). ONE REQUIRED FIX: amendment bullet 1 conflates run 34337797758 (b66a9612 push: CANCELLED at the 40-min wall, nobody's cancel) with run 34...\n*860│## 13:08Z — PR #210 LANDED ff-only: 46e12676 (amended in place from 5888c5de; bullet 1 = run 34337797758 CANCELLED at the 40-min wall, cancel string once in IR-90 with the separation parenthetical kept; blob LF; thin run 34354910726 green docs-only), guarded push 5a50e625..46e12676 = refs/heads/main, PR MERGED mergeCommit 46e12676, local main ff'd. main: IR-90 + IR-85 amendment landed; register ends IR-90. hertz queue confirmed: d882297f cross-OS run (IR-89 workflow half) then the .spt/ ignore lane.\n 861│## 13:09Z — PR #208 THIN CI GREEN at 8d974751: run 34351362639 att1, per-job success x5 (Linux unit 12:33-12:38, Windows unit 12:44:37 -> 13:04:53 on the emptied box, 32 GiB floor held). Commit-3 re-gate MET (test-only diff read + PR unit set green both runners, no third pool). #289 LANE COMPLETE AND PARKED: 168c8622 / 5ca85851 / f6eaa935 / 54259091 / 8d974751 on a2f335f8, PR #208 open + green, pool released; lands via the golden batch the operator greenlights (board: BACKLOG, no milestone, no open mil...\n*862│## 13:18Z — WAKE post-#289 (context reset 13:10Z). Board re-read: #289 BACKLOG / no milestone / no open milestone (last comment 09:49Z, mine); PR #208 green x5 at 8d974751, parked; no operator word on greenlight or the #292 restart. todlando runbook line (3f9ce68a, docs/seam-consumers-refusal off 46e12676, +9 -1, treqs 0, unpushed) ACCEPTED with the #289 parenthetical KEPT -- held for the next docs batch. hertz d882297f REVIEWED IN FULL before his in-situ run (merge-base e4444413, +204 -1 golden.yml + ...\n 863│## 13:21Z — DAEMON (own sample): broker image still 0.67.0 -> no restart yet. peer pump STALLED last tick 8048 s, last successful dial 8062 s; with my 11:07:42Z sample (223 s) the two readings agree on ONE last tick at ~11:05Z and none since -- 2 h 15 min with no round, longer than any bound a 4-dead-peer round can take (40 s), so this is NOT the 'slow rounds' reading I gave at 11:09Z: the pump stopped after the disk window and stayed stopped. 3/7 peers still connected on standing connections; new dial...\n*864│## 13:24Z — hertz: FULL probe design taken (rig.wait listen + ACK + A->B beacon, B's 10 s clock from first beacon; his reason = the fast red IS IR-89's promise and the beacon is what excludes 'A not up'); tag/doc fixup accepted (his second today, banking a fourth face); rebased test/twohost-inbound-probe to 0c963966 on 46e12676, twohost_web.rs blob 0eb2371c identical both sides, golden.yml 40f06699 -> a8c9f894 (main moved). Running the 7509 arm on the current binaries before the redesign. Told him: thr...\n*865│## 13:27Z — hertz THREE ARMS reported, labelled: DIR 1 (A hfenduleam, 7489) GREEN x2 (d882297f 13:13Z A cell 0.40 s; 0c963966 13:18Z 2.44 s, B 20 sent; no free-space stamps on either -- stated gap). DIR 2 (A kitsubito) att1 13:14Z RED INBOUND_BLOCKED 10.24 s = FINDING 2 MEASURED (cargo startup on the Windows SENDER put B's first datagram outside A's 10 s window; text blamed the box; kitsubito netmap lists 100.68.35.65/32 + ufw inactive contradicted it, so he re-ran instead of filing); att2 13:16Z direc...\n 866│## 13:35Z — hertz REDESIGN (beacon/ack) at 0c963966: 13:28Z all three arms GREEN incl. the 7509 CONTROL that red at 13:20Z -- he stopped. First cause his: A beaconed FROM ITS LISTENING SOCKET, opening return state for 7509 so B's probe crossed as SOLICITED traffic (the file's own sentence violated by its guard); fixed to an ephemeral beacon socket. 13:31Z re-run STILL GREEN on 7509, cause open: (a) residual state from 13:28 (146 s later), (b) program-scoped rule (none readable unelevated; port-filter e...\n 867│## 13:39Z — hertz: socket ruling IMPLEMENTED (A's listening socket never sends, beacon + ack from one ephemeral socket; B fixed port_b+9 receives beacons only, ephemeral socket sends probes + takes the ack; counted in source: 0 sends from either listening socket; build green; int tags re-checked immediately above fn two_host_web_role_b). HIS INCIDENT, disclosed: `git checkout <file>` run to READ dirtiness REVERTED the uncommitted redesign; recovered byte-for-byte by replaying his scratchpad splice scri...\n*868│## 13:48Z — hertz FINAL CODE 3a38d30d (one commit on 46e12676, force-with-lease, ls-remote == local, +396 -1 golden.yml +50 / twohost_web.rs +347, treqs 0, source md5 f317793... identical both hosts). PAIR red/red back-to-back (13:43:41-13:44:23Z A 101 after 40 s 39 beacons, B 101 48 sent acked=false beacon-first; 13:44:25-13:45:07Z same shape) = design writes no state; dir 1 13:45:14Z GREEN ack after 1 datagram; dir 2 13:45:41Z GREEN; free 174.38 flat. FOURTH DEFECT caught by dir 2 at the previous cod...\n*869│## 13:56Z — 3a38d30d REVIEWED IN FULL: design as ruled; golden.yml probe steps carry every var from_env requires (no silent pass). FOUR REQUIRED FIXES sent: (1) A acks ONCE and breaks -> one lost UDP datagram = A INBOUND OK + B INBOUND_BLOCKED in the same run (the split verdict he just fixed, now from packet loss); ack every probe for a 2 s drain window; (2) stale comment in B's cell still says the ack comes to the ephemeral port via `from` (contradicts the rig-port fix 30 lines lower) + dead set_read_...\n*870│## 14:02Z — hertz PR #211 OPEN: 9b96d7e7 (guard, four fixes folded in by amend) + 06c0ae6b (IR-89 amendment, six corrections + field-proof block + UNEXERCISED-until-golden warning) on 46e12676; ls-remote == local; +489 -1 over three files; treqs 0. Re-run at the fixup (md5 010ab075... both hosts): 7509 pair 13:54:20Z / 13:55:02Z RED/RED (A 39 beacons, B 47 datagrams, no ack, 101/101); dir 1 13:55:44Z GREEN \"acked 1 probe(s) in 2s\"; free 231.6 -> 231.01. His near-miss disclosed: a WAIT_SECS insert ancho...\n*871│## 14:04Z — hertz disk watchdog trace (observe-only, 139 samples 11:52:46-13:57:07Z, 1/min, preserved .spt/preserved/hertz-leak-670-legs/disk-full-trace.log, hash d58ce838b677e62d both copies): max 238.41 @12:45:20Z, min 12.53 @12:12:45Z, two samples under 15 GiB (14.85 @12:12:11Z, 12.53 @12:12:45Z) inside the #209 leak lane's build+teardown window after a start floor would have passed it at 136.15. Caveats his: 1-min sampling leaves the true minimum unbounded below; attributes nothing. Ruled: ONE line...\n 872│## 14:08Z — hertz fb71292b (docs amend in place over 9b96d7e7; ls-remote == local; +8 -3 register): Status -> WORKFLOW HALF BUILT 2026-09-09, PR #211, LANDED-pending-golden with the unexercised clause; correction 2 gained the by-elimination clause; Ripe-when -> the next golden run. Read and accepted. IR-90 disk-trace line NOT in it (messages crossed); run 34360822987 created 14:01:01Z pending -> told him to fold it now as one more amend (restart at minute two beats a later both-runner main push).\n 873│## 14:12Z — CORRECTION, mine: the \"64.33 @12:13\" I handed hertz as the seam between the two disk traces is NOT in the preserved sampler file (first line 12:15:37Z 54.25). It was a spot read taken in the sampler's launch command (my 12:16Z row) and my 12:21Z row concatenated it with sampler values as one series. hertz caught it by reading the file before writing the register line and wrote the seam without a number -- correct. Line stands; README dropped in the preserved dir naming the filename's 12-13Z...\n 874│## 14:24Z — .spt/ IGNORE LANE (hertz classify-only census: 152 entries, 277.2 MiB, preserved/ 204.8 MiB / 1133 files; nothing touched; by-path check-ignore rc=1 on all rows). FINDING: TWO files under .spt/ are TRACKED (6f620ce4 todlando, deliberate W2 record) -- a blanket ignore leaves them tracked and the lane would ship believing .spt/ sealed. RULED: RELOCATE via git mv (twohost-web-local.sh -> .github/bench/, pump-on-one-box-rig.patch -> docs/spikes/; zero repo citations, five memory citations stay ...\n 875│## 14:30Z — hertz per-file report on the seven + an eighth, ruled: IR37-RIDER-NOTES DEAD; PID-KILL-CENSUS -> docs/ + IR-81 path fix (:4304); REAUDIT-REFS DEAD (its unlanded \"repo column on the census rows\" ruling = MINE, OPEN, re-derive later); RIDER-65S-DESIGN LIVE (d7c2105e not in main, IR-84 unfiled) -> docs/design/; ir37-redundancy-evidence, operator-brief-rc-panel, pr-rigports-body DEAD; launch-battery.py (register cites :4267 + :4276; its docstring says it was ALREADY LOST ONCE to a .spt/ sweep a...\n*876│## 14:33Z — PR #211 LANDED ff-only: run 34361733081 five/five green at 7d2f0d70 (Windows unit completed ~14:31Z); guarded push (run headSha == 7d2f0d70 full + conclusion success, origin/main == 46e12676, ancestor check) 46e12676..7d2f0d70 = refs/heads/main; PR MERGED mergeCommit 7d2f0d70; local main ff'd (3 files +509 -3). main now carries the IR-89 workflow half (beacon/ack inbound probe, both golden.yml steps, WAIT_SECS 300 explicit) + the six-correction amendment + the IR-90 disk-trace line. Golden....\n 877│## 14:44Z — PR #212 (hertz, chore/spt-scratch-ignore, 54d7b122 on 7d2f0d70, 8 files +663 -3) READ IN FULL: R100 x2 (tracked pair, blob-identical per his two-layer check: wc != blob because CRLF-normalized at 6f620ce4), A x4, register edits exactly :4267/:4288/:4304 (:4276 = bare filename, his \"four\" retracted to three before I read), .gitignore +22 with `.spt/` at :51, bench_row_parity read_dir sweep cleared by measurement (ext filter :81, no step template in the .sh). Proof legs: hash before/after 6/6...\n 878│## 14:47Z — hertz #212 amended 54d7b122 -> b0b67aaa (force-with-lease, ls-remote == local): (1) launch-battery.py Usage -> .github/bench/ path; (2) .gitignore enumeration -> rule + count (six cited paths, measured seven raw hits with the patch's own self-reference identified as the non-citation); (3) HIS third of the same class: the pump patch's line-34 \"Restore with: git apply .spt/preserved/...\" repointed to docs/spikes/ (R099 now, header prose, git apply --stat still parses 1 file +403 -148). Re-pro...\n 879│## 15:19Z — PR #212 LANDED ff-only: run 34365591875 five/five green at b0b67aaa (Windows unit 14:52:50-15:12:33Z); guarded push (run headSha == b0b67aaa full + success, origin/main == 7d2f0d70, ancestor) 7d2f0d70..b0b67aaa = refs/heads/main; PR MERGED mergeCommit b0b67aaa; local main == origin/main. Post-landing proof on this checkout: zero `?? .spt/` rows, check-ignore by path -> .gitignore:52:.spt/ populated, all six moved files present at their new paths. Memories updated with the landing sha: git-s...\n\n# IO-PARSER-22-JIT.md\n 81│\n*82│- IR-66: the two first-chunk-needle latent members — TICK39 at attach.rs:561,\n 83│  ALT_VIEWPORT_MARKER at attach.rs:672 — the one-line later-needle treatment proven at v0.63.0.\n 84│\n 85│## Gate discipline (this milestone)\n\n# REGISTER-SWEEP-0671-DRAFT.md\n  81│| IR-65 | kitsubito kernel-audit backpressure (remediated) | \"REMEDIATED-AT-BOX 2026-08-25 ...; entry stays OPEN as the re-check record because the storm SOURCE persists\" | \"a re-check trigger fires\" (tailscale snap update / auditd update / box reimage) | \"two read-only commands per check\" | releases#225 | 2026-08-25 |\n *82│| IR-66 | First-chunk-needle test class: two members remain | \"BUILT — hertz rider PR #161, landed ff at `d04b922d` (2026-08-27, IO-PARSER #22 intake rider)\" | \"next milestone intake (hertz test lane) or the first golden red at ~240s on an attach cell\" | \"two one-line test edits\" | hertz rider PR #161, IO-PARSER #22 | 2026-08-27 |\n  83│| IR-67 | `-p spt --bins` leg runs zero e2e coverage | \"BUILT — remedy applied across the IO-PARSER #22 milestone (2026-08-27/28)\" | \"next milestone intake (the battery template is touched at every intake)\" | \"template lines only\" | IO-PARSER #22 milestone | 2026-08-28 |\n  84│| IR-68 | PSYCHE_INGEST_FAIL cause unproven, index.lock cleared | \"OPEN, investigation-shaped\" | \"next PSYCHE_INGEST_FAIL sighting in the field (capture the failing store state before touching it), or a dedicated probe slot\" | \"investigation; no product change until the mechanism is pinned\" | IO-PARSER #22, PR #163 | 2026-08-27 |\n  85│| IR-69 | Inherited stderr tokens tear between fragments | \"OPEN, product remedy complete and parked GREEN-AND-READY at `d0fdd58d` on `feat/emit-single-write`, owned by todlando, awaiting golden-batch assembly\" | \"Closes when: releases#243's residual conversion + generator fix land and a re-census at that sha reads zero shipping residue under both delimiter forms\" | \"product lane complete elsewhere; register follow-through small\" | releases#241 (product remedy, landed); releases#243 (residual conversion,...\n    │...\n  88│| IR-72 | No read verb names a perch/seat holder | \"OPEN, observability gap; no remedy scheduled\" | \"the next roster/status read-model change or another rig needs to reap a named holder\" | \"small read-model/API addition, medium if seat and perch custody need separate typed variants\" | PR #174 (`70c1a303`) | 2026-08-29 |\n *89│| IR-73 | ci.yml/release.yml read floor pre-checkout | \"OPEN, filed by doyle 2026-08-30 at the #242/v0.66.0 close sweep\" | \"next touch of `ci.yml`/`release.yml`, or the next intake's tooling-rider slot (compose with IR-59/IR-57's standing pair)\" | \"small — reorder or comment per site, 8 sites\" | Compose with IR-59/IR-57 tooling-rider slot; per top-of-file note this arc's workflow commits did NOT carry it | 2026-08-30 |\n  90│| IR-74 | kitsubito holds 21,643 /tmp endpoint homes | \"OPEN, filed by doyle 2026-08-30 at the #242/v0.66.0 close sweep\" | \"next kitsubito rig touch, or the between-milestone box-audit slot\" | \"small (one sweep script + adoption in the box's rig steps); the measurement rerun is one `find \\| wc`\" | No | 2026-08-30 |\n  91│| IR-75 | traceable-reqs not installed on kitsubito (treqs exit 127) | \"OPEN, filed by doyle 2026-08-30 at the #242/v0.66.0 close sweep\" | \"next Linux gate-driver touch or kitsubito box-audit slot\" | \"trivial (install or one driver edit + comment)\" | No | 2026-08-30 |\n  92│\n    │...\n 121│  \"preflight\", and \"v0.67.1 shipped (golden ... green)\" on \"golden\".\n*122│- **IR-66** — trigger \"next milestone intake (hertz test lane)\" matches \"WEBSERVE milestone #272\n 123│  GREENLIT with waves W0–W3\" on the word \"milestone intake\".\n 124│- **IR-67** — trigger \"next milestone intake (the battery template is touched at every intake)\"\n 125│  matches \"WEBSERVE milestone #272 GREENLIT\" on \"milestone intake\", and also matches \"nextest\n    │...\n 127│  template) though the word \"nextest\" itself is not in this entry's trigger text.\n*128│- **IR-73** — trigger \"next intake's tooling-rider slot (compose with IR-59/IR-57's standing pair)\"\n 129│  matches \"WEBSERVE milestone #272 GREENLIT\" on \"next intake\", and its subject (ci.yml/release.yml\n 130│  floor sites) matches \"IR-76 ... three-arm pre-flight\" on the shared golden-box preflight topic.\n 131│\n\n# WEBSERVE-272-JIT.md\n 108│  the `golden.yml` touch at `04e32c8c` fired the trigger unweighed), IR-59 log-the-floor half\n*109│  (record free space beside every floor check), IR-73 (the 8 literal-first floor sites in\n 110│  `ci.yml`/`release.yml`). Entry text in `docs/INFRA-REGISTER.md` is the spec.\n*111│- **IR-66 — RULED SATISFIED 2026-09-06 (hertz measured, doyle ruled)**: the register body says\n 112│  BUILT at `d04b922d`/#161 and both cells are present at `17815c9c` (attach.rs:530/:538,\n 113│  :655). The earlier \"residual — two one-line test edits\" line here was a carried-forward\n 114│  fossil of the entry's own \"Size:\" line, which describes the fix that LANDED. No edits; the\n\n# docs/\n## INFRA-REGISTER.md\n   19│respin edit under a pre-registered hard stop is not a remedy window, so the entry gains that datum\n  *20│and is COMPOSED forward. **Composed: the floor trio IR-46 + IR-59 (log-the-floor half) + IR-73\n   21│(8 literal-first sites) as ONE hertz workflow rider on WEBSERVE** (`ci.yml`/`golden.yml`/\n   22│`release.yml`, thin PR off the golden path, before the WEBSERVE golden head so that head runs\n   23│under it); **IR-59's log-the-floor line ALSO rides IR-76's three-arm pre-flight on W0's driver\n  *24│template** (todlando authors; free space recorded beside the floor check). **IR-66 residual (two\n   25│first-chunk-needle members) = hertz WEBSERVE test rider** (two one-line edits). **IR-12 residual =\n   26│W3 drift-gate rider** (hertz already holds W3's drift-gate riders). IR-67 satisfied at this intake\n   27│by construction (`--no-fail-fast` in the W0 driver template; todlando's 2026-09-06 correction).\n     │...\n   52│CANNOT answer a CWD-pin question (todlando's false-positive self-catch). Board mints this arc:\n  *53│#244/#246/#247/#254 (BACKLOG). #16/#17 discharged drops (detach + EVAL). IR-73's ci.yml/\n   54│release.yml floor-site reorders did NOT ride this arc's workflow commits — still owed, next\n   55│touch. No entries retired.\n   56│\n     │...\n   75│low-water; within-job floor re-read rides the next workflow commit; box ~51 GB non-recovering\n  *76│consumption → audit slot). FILED: IR-73 (ci.yml/release.yml literal-first floor sites off the\n   77│golden path, 8 sites), IR-74 (kitsubito 21,643 /tmp endpoint homes, hertz's measurement), IR-75\n   78│(kitsubito treqs 127 vacuous leg — install-or-drop; IR-37 deliberately NOT reopened, different\n   79│surface). Composed: IR-14/26/27/49 as ONE between-milestone pool/worktree audit slot (window\n     │...\n   85│Prior sweep: 2026-08-27, IO-PARSER (#22) INTAKE (wave map: `IO-PARSER-22-JIT.md` + #22 comment).\n  *86│Rulings: IR-66 COMPOSED as the parallel hertz rider (the two attach-cell later-needle treatments,\n   87│attach.rs:561/:672 — the \"rides next intake\" note comes due here). IR-52 conditional rider\n   88│CARRIED FORWARD on this milestone's docs lane, same terms as WAX-SEAL (depth fix lands iff the\n   89│lane touches the docs-site CLI reference generator, else stays open). IR-67 COMPOSED as JIT gate\n     │...\n 2631│\n*2632│- **2026-09-06 addendum (doyle, v0.67.1 close sweep): trigger FIRED at `04e32c8c` — `golden.yml` touched (2-line HEAVY reclass of `brain_resume_conn_deadlock` on the respin) with no remedy weighed. Not a drive-by by choice: the touch rode a respin under a pre-registered hard stop, which is no remedy window. COMPOSED with IR-59 (log-the-floor) + IR-73 (literal-first sites) as one hertz workflow rider on WEBSERVE #272; the remedy weighing happens on THAT lane, before the WEBSERVE golden head.**\n 2633│\n 2634│<!-- [doc->REQ-CI-FREE-SPACE-PREFLIGHT] -->\n 2635│- **2026-09-06 remedy ruling (doyle, WEBSERVE rider):** retain 32 GiB; record raw-byte\n     │...\n 2637│  End DISK assertions run `if: always()` before teardown, including after failed workloads.\n*2638│  A fresh `FLOOR_DOCS` assertion immediately before docs-drift composes with IR-73's second half.\n 2639│  Raising the floor is refused without a measured peak; continuous sampling adds lifecycle\n 2640│  machinery while remaining blind between samples. Start/end are a dataset, not a minimum or\n 2641│  headroom guarantee. Golden execution evidence waits for the WEBSERVE golden head; the thin\n     │...\n 3526│\n*3527│### IR-66 — first-chunk-needle test class: two latent members remain after the v0.63.0 fix (attach.rs:561, :672)\n 3528│\n 3529│- **Status:** BUILT — confirmed present at `17815c9c` (hertz 2026-09-06); leaves the register at the WEBSERVE close sweep. Hertz rider PR #161, landed ff at `d04b922d` (2026-08-27, IO-PARSER #22\n 3530│  intake rider). Both members got the later-needle treatment (TICK39 delayed past burst on both\n     │...\n 3782│\n*3783│### IR-73 — ci.yml and release.yml still read the free-space floor PRE-checkout (literal-first sites off the golden path); and any job's floor is stale by its last heavy step\n 3784│\n 3785│- **Status:** OPEN, filed by doyle 2026-08-30 at the #242/v0.66.0 close sweep (deployah flag\n 3786│  2026-08-29, widen lane). · **Origin:** the #242 cut lost two golden attempts to exactly this\n     │...\n 3875│- **Ripe when:** next driver-template touch (a/b are text; a is one leg), next `ci.yml`\n*3876│  touch for (c) — compose with [[IR-73]]'s reorders; (d) rides the next runbook edit.\n 3877│- **Size:** small — one pre-flight leg + one census predicate + two doc sentences.\n 3878│\n 3879│### IR-77 — nothing stamps the interval between a daemon child's spawn and the brain's first log line, so a readiness-deadline red cannot say WHERE the time went\n     │...\n 4822│     runner dir, so it proves the mechanism's size, not the runner's exposure. Unsettable\n*4823│     unelevated; same shape as **IR-89**'s elevated firewall rule.\n 4824│  4. **CI census, cheap and durable:** print `Get-MpComputerStatus` RealTimeProtectionEnabled plus\n 4825│     the ExclusionPath read **verbatim, refusal text included**, in the Windows job's census step,\n 4826│     so a run's own record says what Defender it ran under.\n     │...\n 4832│- **Kin:** [[IR-76]] (the golden runner IS the builders' box — the structural reason a desktop's\n*4833│  load reaches CI at all), [[IR-64]] (box-level facts only the operator can move), [[IR-89]] (the\n 4834│  other elevated box-rule ask), `defender-first-touch-tax-on-fresh-test-binaries` and\n 4835│  `e2e-leaked-daemons-shared-box` (memory).\n 4836│- **Ripe when:** arm 1 now; arms 2-4 on the operator's answer; arm 5 at the next `golden.yml` touch\n     │...\n 4895│  ripe-when arm — a golden that dies at the floor despite adopted pool discipline — FIRED here\n*4896│  in the in-job form), [[IR-73]] (second half BUILT: the within-job re-read exists and is what\n 4897│  produced the FLOOR_DOCS reading), REQ-CI-FREE-SPACE-PREFLIGHT.\n 4898│- **Coupling (deployah 23:54Z, from `golden.yml` at `25e60015`):** the Windows `DISK docs floor`\n 4899│  (:616) and `Docs drift gate — windows` (:629) carry only `if: runner.os == 'Windows'`, no\n     │...\n 4941│\n*4942│- **AMENDMENT 2026-09-10 (releases#294, golden 34445961595 att1 @ `a9e786b2`) — THE STARVING RUN CAN\n 4943│  BE GOLDEN'S OWN PR, which makes this self-inflicted and recurrent on every golden run with a PR\n 4944│  open.** Measured timeline: **07:18:59Z** golden `test (Windows)` completes and releases hfenduleam;\n 4945│  **07:18:59Z** twohost-a queued; **07:19:01Z** PR run **34446095808** job `unit (Windows,\n     │...\n 4960│  laundered into it.\n*4961│- **⚠ ITS WALL CLOCK IS INDISTINGUISHABLE FROM [[IR-89]]'s.** A 900 s twohost red whose panel blames\n 4962│  pairing is ALSO the exact signature of the banked Windows-firewall hazard. The panel alone cannot\n 4963│  separate them; **the job TIMELINE can**. Check the schedule before accepting the firewall hazard for\n 4964│  any 900 s twohost red — this one fit that signature perfectly and was not it.\n 4965│\n*4966│### IR-88 — `pool-release` via `cargo run -p xtask` REBUILDS xtask INTO the pool it is releasing, so a reaped pool regrows ~2.8 GB in silence\n 4967│\n 4968│- **Status:** OPEN, filed by doyle 2026-09-08 from hertz's reap report (20:00Z) during the #272\n 4969│  golden r2 repair. · **Origin:** hertz reaped hertz-lane4 / hertz-repin / hertz-percell-id target\n     │...\n 4994│\n*4995│### IR-89 — hfenduleam's Windows Firewall drops cold inbound UDP to the runner-built test exes, so the two-host rig's first B→A claim (W2 helper) reds for its whole 900 s budget and the panic blames A\n 4996│\n 4997│- **Status:** BOX HALF **APPLIED** 2026-09-08; WORKFLOW HALF **BUILT** 2026-09-09 — PR #211\n 4998│  (`9b96d7e7` + this amendment), **LANDED-pending-golden**: the `golden.yml` steps are UNEXERCISED\n     │...\n 5741│- **THE DIFFERENTIAL that makes it worth an entry rather than a shrug:** the same cell shows **0\n*5742│  failures at the candidate** in golden 34481993681 Phase A on this same box — that run's single\n 5743│  failure was the sync cell (`3381 tests run: 3380 passed (6 slow, 5 leaky), 1 failed, 1 skipped`).\n 5744│  So: 0-of-1 at `a9e786b2` under CI load, 3-of-3 at `ed8ecd94` under local HEAVY load.\n 5745│- **WHAT THAT DOES NOT ESTABLISH.** It does **not** isolate the instrumentation or the box as the\n     │...\n 5748│  it** the same hour under todlando's and hertz's correction; the withdrawal is recorded in\n*5749│  `.spt/preserved/gate-r2-34481993681-20260910/CLASSIFICATION-AMENDMENT-2-doyle.md`.\n 5750│- **Confounded by IR-97** (below): the three runs were not equivalent conditions.\n 5751│- **Ripe when:** any lane touches daemon stop/start convoy behaviour, OR a golden run reds this cell\n 5752│  at a candidate, OR someone runs the cell at `a9e786b2` under the same local HEAVY workload — that\n## KNOWN-HAZARDS.md\n 1038│<!-- [doc->REQ-HAZARD-RETRY-MARGIN-UNMEASURED] -->\n*1039│- **Failure (paid-for, releases#294 / v0.69.0: gate runs `34445961595` and `34481993681`, two reds at the SAME cell, `spt-daemon::sync two_tier_sync_lands_and_gate_refuses_server_side`):** the wait that gates the assertion is the house-standard 400 iterations x 25 ms — a 10.0 s budget — and it reports PASS or FAIL and nothing else. The elapsed is discarded. Two full gate arms across two boxes were spent and the cause of the red is still **UNCLASSIFIED**, because the instrument could not answer a ques...\n 1040│- **Defect (a) — a green carries no margin.** Instrumented at 400 observations on the Windows cell, successes landed at **4.448 s** (observation 176/400) and **9.940 s** (observation 392/400). Those are the SAME GREEN to the loop. A pass one scheduling hiccup from red is indistinguishable from a healthy one, so **a history of passes is not evidence of headroom** — every prior green of this cell is silent about margin, including the greens on the record head.\n 1041│- **Defect (b) — an expiry is RIGHT-CENSORED, not a sample.** The loop stops looking at the bound (measured 10.156–10.200 s wall), so it establishes that no eligible condition was observed BEFORE expiry and **nothing whatsoever about after**. A censored expiry has **no upper endpoint**: it cannot be averaged in, cannot be called a latency or \"the tail\", and cannot separate DELAYED from ABSENT, RETIRED, or FILTERED. Write `CENSORED at X, no upper endpoint`.\n 1042│- **THIS IS THE SEAM THAT WITHDREW THREE CAUSE PHRASINGS IN ONE HOUR** (2026-09-10, all mine): *\"delayed publication, measured\"* — censoring, caught by hertz; *\"a ceiling outside the measured tail\"* — unspecifiable, hertz **refused to implement rather than invent a number**, and that refusal was worth more than compliance; *\"boundary defect MEASURED\"* — caught by todlando, **proximity to a threshold is a RISK SIGNAL, never a verdict that the threshold is wrong**. If the 9.940 s success is itself pa...","linesTruncated":true,"meta":{"limits":{"columnTruncated":{"maxColumn":512}}}},"isError":false,"timestamp":1789094623893}}
{"type":"message","id":"0a541862","parentId":"bb5c16dc","timestamp":"2026-09-11T02:43:43.905Z","message":{"role":"toolResult","toolCallId":"call_SdofjrQzq6Mv2DthPW98144r|fc_065c0d1976ecf9c2016aa36add6fa887d197333a8abba82dd4","toolName":"grep","content":[{"type":"text","text":"# crates/\n\n## spt-store/src/\n### proc.rs\n 45|// [impl->REQ-HAZARD-BRAIN-RESTART-PSYCHE-DUP]\n*46|pub fn kill_pid(pid: u32) {\n 47|    if pid == 0 {\n 48|        return; // never a real per-process target (see is_process_alive)\n 49|    }\n...\n 429|// [impl->REQ-PSYCHE-CRASHLOOP-BACKOFF-SHUTDOWN]\n*430|pub fn kill_pid_tree(root: u32) {\n 431|    if root == 0 {\n 432|        return;\n 433|    }\n\n## spt-daemon/src/\n### daemon.rs\n 247|                    // the controller slot, the viewer map, and the viewer origin\n*248|                    // nodes retained on `ViewerSink`. A disk reconciler could not\n 249|                    // compose its frame, and snapshotting attachment identity to\n*250|                    // disk for one to read was refused. Background + best-effort:\n 251|                    // a spawn failure logs loud and the daemon runs on, exactly\n 252|                    // like the docs server below — shells simply do not learn who\n 253|                    // is watching, which degrades a signal rather than a surface.\n...\n 396|        // resource, which is the ADR-0018 Q2/Q5 broker-side test. The shellwake\n*397|        // Q5 exception reads \"a pure disk-reconciler\" and this is not one. Hosting\n 398|        // it in the restartable brain would also make every routine brain restart\n 399|        // — `StartReason::Update` is exactly that — bounce every resident service\n 400|        // through the orphan path with no quiesce, no grace and no hold, which is\n...\n 432|        // D2-2): shellwake is brain-owned logic (ADR-0018 Q5 exception), a pure\n*433|        // disk-reconciler whose boot sweep re-reconciles the watcher children on\n 434|        // every brain start. The broker no longer hosts it; see\n 435|        // [`crate::brainproc::run_brain`].\n 436|        // [impl->REQ-HAZARD-BROKER-PROCESS-ISOLATION]\n...\n 2049|/// The Win32 `GetFileType` result for a PIPE handle — the ONLY std-handle sink that\n*2050|/// BLOCKS when it fills. (DISK=1, CHAR=2, PIPE=3, UNKNOWN=0.)\n 2051|pub const FILE_TYPE_PIPE: u32 = 0x0003;\n 2052|\n 2053|/// Decide whether `daemon run` must NULL its std handles as a detached-in-fact\n...\n 2056|/// daemon once full. Every OTHER sink is safe and MUST survive: a FILE (`2>run.log`,\n*2057|/// AND every int test's `Stdio::from(file)` brain-log capture) is a disk handle that\n 2058|/// never blocks; a CONSOLE scrolls; a NULL/absent handle (the DETACHED_PROCESS rungs)\n 2059|/// already discards. So we DELIBERATELY do NOT gate on \"no console\" (`GetConsoleWindow`):\n 2060|/// a CREATE_NO_WINDOW daemon has no console window yet a perfectly-drained FILE stderr\n...\n 2078|/// pipe-tee ergonomics. The SANCTIONED foreground-capture form is a FILE redirect\n*2079|/// (`spt daemon run 2>run.log`): a disk handle is not a pipe, so it survives (this is\n 2080|/// exactly why the int-test brain-log capture is safe). Called unconditionally at\n 2081|/// `daemon run` startup. // [impl->REQ-HAZARD-DETACHED-DAEMON-STDIO]\n 2082|#[cfg(windows)]\n...\n 2476|    /// of this row and left the SELECTION on a bare pid, so a red has two readings\n*2477|    /// that are IDENTICAL in the log — golden 30873007187 could not be called:\n 2478|    ///\n 2479|    /// - **H1, test defect.** The scan matched a STRANGER carrying a stale\n 2480|    ///   `th32_parent_process_id` equal to our child's recycled pid. The row then\n...\n 2786|        // reads the stranger as our grandchild, still alive, and burns the whole\n*2787|        // window: the 10.176s red (golden 30776330383) against 0.19s passes.\n 2788|        // The direct child needs no pin and does not get a misleading one: this\n 2789|        // test RETAINS its handle (`DetachedChild` holds it until drop), and\n 2790|        // Windows will not recycle a pid while a handle to it is open, so\n...\n 3084|        const FILE_TYPE_UNKNOWN: u32 = 0x0000;\n*3085|        const FILE_TYPE_DISK: u32 = 0x0001;\n 3086|        const FILE_TYPE_CHAR: u32 = 0x0002;\n 3087|        assert!(should_null_std_handles(FILE_TYPE_PIPE), \"an undrained pipe blocks ⇒ null\");\n 3088|        assert!(\n*3089|            !should_null_std_handles(FILE_TYPE_DISK),\n*3090|            \"a FILE redirect (2>run.log / the int-test brain-log) is disk ⇒ survives\"\n 3091|        );\n 3092|        assert!(\n 3093|            !should_null_std_handles(FILE_TYPE_CHAR),\n\n## xtask/src/\n### main.rs\n 22|mod brainread;\n*23|mod diskfloor;\n 24|mod perjob;\n 25|mod pickaudit;\n 26|mod spacerun;\n...\n 69|        \"pick-audit\" => pickaudit::pick_audit(&args[1..]),\n*70|        \"disk-floor\" => diskfloor::disk_floor(&args[1..]),\n 71|        \"bench-wrap\" => bench_wrap(&args[1..]),\n 72|        \"bench-report\" => bench_report(&args[1..]),\n 73|        \"pool-claim\" => pool_claim(&args[1..]),\n...\n 85|            eprintln!(\n*86|                \"usage: xtask <gen|check|brain-read-check|binedge-check [--no-prebuilds] [--baseline|--write-baseline] [--sites]|perjob-map|pick-audit --range <base>..<head> --lane <base>..<tip> [--lane <base>..<tip>] [--pair <lane-rev>:<pick-rev>] [--repo <dir>]|disk-floor [--path <dir>] [--floor-gb <n>] [--label <lane>]|docs-bundle <out.tar.gz>|bench-wrap --step <name> [--key <k>] -- <cmd...>|bench-report [--top <n>] [--window-hours <h>]|pool-claim --pool <dir> --label <lane> [--holder-pid <pid>] [--fo...\n 87|            );\n 88|            std::process::exit(2);\n 89|        }\n...\n 311|    if check {\n*312|        let on_disk = std::fs::read_to_string(&path)\n 313|            .map_err(|e| {\n 314|                format!(\n 315|                    \"xtask check: read checked-in {relative}: {e} \\\n...\n 319|            .replace(\"\\r\\n\", \"\\n\");\n*320|        if on_disk != generated {\n 321|            return Err(format!(\n 322|                \"xtask check: {relative} drifted from CHANGELOG.md — \\\n 323|                 run `cargo run -p xtask -- gen` and commit\"\n...\n 341|    if check {\n*342|        let on_disk = std::fs::read_to_string(&path)\n 343|            .unwrap_or_else(|_| panic!(\"checked-in {relative} (run `cargo run -p xtask -- gen`)\"))\n 344|            .replace(\"\\r\\n\", \"\\n\");\n*345|        if on_disk != generated {\n 346|            eprintln!(\n 347|                \"xtask check: {relative} drifted from {source} — \\\n 348|                 run `cargo run -p xtask -- gen` and commit\"\n...\n 528|    // is LF, like every other generated page and like the `check` comparison,\n*529|    // which normalizes what it reads off disk. Without this the heading keeps a\n 530|    // stray CR and the blank line after it doubles — measured on this box, and\n 531|    // invisible to any test that compares strings a test itself wrote.\n 532|    let changelog = changelog.replace(\"\\r\\n\", \"\\n\");\n...\n 759|/// It also asserts the two `<HEAVY>` copies are byte-identical. They had ALREADY\n*760|/// drifted when this check was written (`twohost_web` was in golden.yml's job-level\n 761|/// env and not in this file's test-group override, one commit old), which is the\n 762|/// failure the stanza's own comment warns about: a filter that silently\n 763|/// repartitions the suite does not red, it just runs the test in the wrong phase.\n...\n 771|        .expect(\".config/nextest.toml (the test-group overrides)\");\n*772|    let golden = std::fs::read_to_string(root.join(\".github/workflows/golden.yml\"))\n*773|        .expect(\".github/workflows/golden.yml (the job-level HEAVY env)\");\n 774|    let from_nextest = heavy_expression(&nextest, \"filter = '\")\n 775|        .expect(\".config/nextest.toml must carry the heavy test-group filter\");\n*776|    let from_golden = heavy_expression(&golden, \"HEAVY: '\")\n*777|        .expect(\"golden.yml must carry the job-level HEAVY env\");\n*778|    if from_nextest != from_golden {\n 779|        eprintln!(\n 780|            \"xtask check: the two <HEAVY> strings have DRIFTED — .config/nextest.toml's \\\n*781|             test-group filter and golden.yml's job-level HEAVY env must be identical, or the \\\n*782|             suite is partitioned one way on golden and another way locally.\\n  \\\n*783|             only in .config/nextest.toml: {:?}\\n  only in golden.yml: {:?}\",\n*784|            names_only_in(from_nextest, from_golden),\n*785|            names_only_in(from_golden, from_nextest),\n 786|        );\n 787|        std::process::exit(1);\n 788|    }\n...\n 819|             PRECONDITION). Add each to BOTH <HEAVY> strings (.config/nextest.toml's test-group \\\n*820|             filter and golden.yml's job-level HEAVY env), alphabetically:\\n  {}\",\n 821|            unclassified.join(\"\\n  \")\n 822|        );\n 823|        std::process::exit(1);\n\n# .github/bench/\n## launch-battery.py\n 30|So this tool verifies the child AND its descendants — `a pid is not a tree`\n*31|(IR-80/IR-81) applies to reading an environment exactly as it does to killing.\n 32|The `.env` sidecar records every process actually inspected, by pid, so the\n*33|claim's SCOPE is on disk and not in a sentence.\n 34|\n 35|A NOTE ON ENV PREFIXES (todlando, 2026-09-07): a shell prefix launch — `VAR=1\n 36|cmd` — never enters the SCRIPT's own environment, so grepping `env` earlier in\n...\n 242|            # Kill the TREE, not the pid — the wrapper is the thing we hold and\n*243|            # the battery is the thing that would keep running (IR-80).\n 244|            _kill_tree(proc)\n 245|            print(\"LAUNCH REFUSED: the environment is not what was asked for.\")\n 246|            print(\"\\n\".join(problems))\n...\n 271|    \"\"\"Kill the wrapper AND its descendants. A single-pid kill here would leave\n*272|    the battery running under a refused launch — the exact IR-80 shape.\"\"\"\n 273|    try:\n 274|        victims = psutil.Process(proc.pid).children(recursive=True)\n 275|    except psutil.NoSuchProcess:\n\n[Some lines truncated to 512 chars]"}],"details":{"scopePath":"crates/spt-store/src/proc.rs, crates/spt-daemon/src/daemon.rs, .github/bench/launch-battery.py, crates/xtask/src/main.rs","searchPath":"C:\\Users\\decid\\Documents\\projects\\spt-core","cwd":"C:\\Users\\decid\\Documents\\projects\\spt-core","matchCount":38,"fileCount":4,"files":["crates/spt-store/src/proc.rs","crates/spt-daemon/src/daemon.rs",".github/bench/launch-battery.py","crates/xtask/src/main.rs"],"fileMatches":[{"path":"crates/spt-store/src/proc.rs","count":2},{"path":"crates/spt-daemon/src/daemon.rs","count":12},{"path":".github/bench/launch-battery.py","count":4},{"path":"crates/xtask/src/main.rs","count":20}],"truncated":true,"perFileLimitReached":20,"displayContent":"# crates/\n\n## spt-store/src/\n### proc.rs\n  45│// [impl->REQ-HAZARD-BRAIN-RESTART-PSYCHE-DUP]\n *46│pub fn kill_pid(pid: u32) {\n  47│    if pid == 0 {\n  48│        return; // never a real per-process target (see is_process_alive)\n  49│    }\n    │...\n 429│// [impl->REQ-PSYCHE-CRASHLOOP-BACKOFF-SHUTDOWN]\n*430│pub fn kill_pid_tree(root: u32) {\n 431│    if root == 0 {\n 432│        return;\n 433│    }\n\n## spt-daemon/src/\n### daemon.rs\n  247│                    // the controller slot, the viewer map, and the viewer origin\n *248│                    // nodes retained on `ViewerSink`. A disk reconciler could not\n  249│                    // compose its frame, and snapshotting attachment identity to\n *250│                    // disk for one to read was refused. Background + best-effort:\n  251│                    // a spawn failure logs loud and the daemon runs on, exactly\n  252│                    // like the docs server below — shells simply do not learn who\n  253│                    // is watching, which degrades a signal rather than a surface.\n     │...\n  396│        // resource, which is the ADR-0018 Q2/Q5 broker-side test. The shellwake\n *397│        // Q5 exception reads \"a pure disk-reconciler\" and this is not one. Hosting\n  398│        // it in the restartable brain would also make every routine brain restart\n  399│        // — `StartReason::Update` is exactly that — bounce every resident service\n  400│        // through the orphan path with no quiesce, no grace and no hold, which is\n     │...\n  432│        // D2-2): shellwake is brain-owned logic (ADR-0018 Q5 exception), a pure\n *433│        // disk-reconciler whose boot sweep re-reconciles the watcher children on\n  434│        // every brain start. The broker no longer hosts it; see\n  435│        // [`crate::brainproc::run_brain`].\n  436│        // [impl->REQ-HAZARD-BROKER-PROCESS-ISOLATION]\n     │...\n 2049│/// The Win32 `GetFileType` result for a PIPE handle — the ONLY std-handle sink that\n*2050│/// BLOCKS when it fills. (DISK=1, CHAR=2, PIPE=3, UNKNOWN=0.)\n 2051│pub const FILE_TYPE_PIPE: u32 = 0x0003;\n 2052│\n 2053│/// Decide whether `daemon run` must NULL its std handles as a detached-in-fact\n     │...\n 2056│/// daemon once full. Every OTHER sink is safe and MUST survive: a FILE (`2>run.log`,\n*2057│/// AND every int test's `Stdio::from(file)` brain-log capture) is a disk handle that\n 2058│/// never blocks; a CONSOLE scrolls; a NULL/absent handle (the DETACHED_PROCESS rungs)\n 2059│/// already discards. So we DELIBERATELY do NOT gate on \"no console\" (`GetConsoleWindow`):\n 2060│/// a CREATE_NO_WINDOW daemon has no console window yet a perfectly-drained FILE stderr\n     │...\n 2078│/// pipe-tee ergonomics. The SANCTIONED foreground-capture form is a FILE redirect\n*2079│/// (`spt daemon run 2>run.log`): a disk handle is not a pipe, so it survives (this is\n 2080│/// exactly why the int-test brain-log capture is safe). Called unconditionally at\n 2081│/// `daemon run` startup. // [impl->REQ-HAZARD-DETACHED-DAEMON-STDIO]\n 2082│#[cfg(windows)]\n     │...\n 2476│    /// of this row and left the SELECTION on a bare pid, so a red has two readings\n*2477│    /// that are IDENTICAL in the log — golden 30873007187 could not be called:\n 2478│    ///\n 2479│    /// - **H1, test defect.** The scan matched a STRANGER carrying a stale\n 2480│    ///   `th32_parent_process_id` equal to our child's recycled pid. The row then\n     │...\n 2786│        // reads the stranger as our grandchild, still alive, and burns the whole\n*2787│        // window: the 10.176s red (golden 30776330383) against 0.19s passes.\n 2788│        // The direct child needs no pin and does not get a misleading one: this\n 2789│        // test RETAINS its handle (`DetachedChild` holds it until drop), and\n 2790│        // Windows will not recycle a pid while a handle to it is open, so\n     │...\n 3084│        const FILE_TYPE_UNKNOWN: u32 = 0x0000;\n*3085│        const FILE_TYPE_DISK: u32 = 0x0001;\n 3086│        const FILE_TYPE_CHAR: u32 = 0x0002;\n 3087│        assert!(should_null_std_handles(FILE_TYPE_PIPE), \"an undrained pipe blocks ⇒ null\");\n 3088│        assert!(\n*3089│            !should_null_std_handles(FILE_TYPE_DISK),\n*3090│            \"a FILE redirect (2>run.log / the int-test brain-log) is disk ⇒ survives\"\n 3091│        );\n 3092│        assert!(\n 3093│            !should_null_std_handles(FILE_TYPE_CHAR),\n\n## xtask/src/\n### main.rs\n  22│mod brainread;\n *23│mod diskfloor;\n  24│mod perjob;\n  25│mod pickaudit;\n  26│mod spacerun;\n    │...\n  69│        \"pick-audit\" => pickaudit::pick_audit(&args[1..]),\n *70│        \"disk-floor\" => diskfloor::disk_floor(&args[1..]),\n  71│        \"bench-wrap\" => bench_wrap(&args[1..]),\n  72│        \"bench-report\" => bench_report(&args[1..]),\n  73│        \"pool-claim\" => pool_claim(&args[1..]),\n    │...\n  85│            eprintln!(\n *86│                \"usage: xtask <gen|check|brain-read-check|binedge-check [--no-prebuilds] [--baseline|--write-baseline] [--sites]|perjob-map|pick-audit --range <base>..<head> --lane <base>..<tip> [--lane <base>..<tip>] [--pair <lane-rev>:<pick-rev>] [--repo <dir>]|disk-floor [--path <dir>] [--floor-gb <n>] [--label <lane>]|docs-bundle <out.tar.gz>|bench-wrap --step <name> [--key <k>] -- <cmd...>|bench-report [--top <n>] [--window-hours <h>]|pool-claim --pool <dir> --label <lane> [--holder-pid <pid>] [--fo...\n  87│            );\n  88│            std::process::exit(2);\n  89│        }\n    │...\n 311│    if check {\n*312│        let on_disk = std::fs::read_to_string(&path)\n 313│            .map_err(|e| {\n 314│                format!(\n 315│                    \"xtask check: read checked-in {relative}: {e} \\\n    │...\n 319│            .replace(\"\\r\\n\", \"\\n\");\n*320│        if on_disk != generated {\n 321│            return Err(format!(\n 322│                \"xtask check: {relative} drifted from CHANGELOG.md — \\\n 323│                 run `cargo run -p xtask -- gen` and commit\"\n    │...\n 341│    if check {\n*342│        let on_disk = std::fs::read_to_string(&path)\n 343│            .unwrap_or_else(|_| panic!(\"checked-in {relative} (run `cargo run -p xtask -- gen`)\"))\n 344│            .replace(\"\\r\\n\", \"\\n\");\n*345│        if on_disk != generated {\n 346│            eprintln!(\n 347│                \"xtask check: {relative} drifted from {source} — \\\n 348│                 run `cargo run -p xtask -- gen` and commit\"\n    │...\n 528│    // is LF, like every other generated page and like the `check` comparison,\n*529│    // which normalizes what it reads off disk. Without this the heading keeps a\n 530│    // stray CR and the blank line after it doubles — measured on this box, and\n 531│    // invisible to any test that compares strings a test itself wrote.\n 532│    let changelog = changelog.replace(\"\\r\\n\", \"\\n\");\n    │...\n 759│/// It also asserts the two `<HEAVY>` copies are byte-identical. They had ALREADY\n*760│/// drifted when this check was written (`twohost_web` was in golden.yml's job-level\n 761│/// env and not in this file's test-group override, one commit old), which is the\n 762│/// failure the stanza's own comment warns about: a filter that silently\n 763│/// repartitions the suite does not red, it just runs the test in the wrong phase.\n    │...\n 771│        .expect(\".config/nextest.toml (the test-group overrides)\");\n*772│    let golden = std::fs::read_to_string(root.join(\".github/workflows/golden.yml\"))\n*773│        .expect(\".github/workflows/golden.yml (the job-level HEAVY env)\");\n 774│    let from_nextest = heavy_expression(&nextest, \"filter = '\")\n 775│        .expect(\".config/nextest.toml must carry the heavy test-group filter\");\n*776│    let from_golden = heavy_expression(&golden, \"HEAVY: '\")\n*777│        .expect(\"golden.yml must carry the job-level HEAVY env\");\n*778│    if from_nextest != from_golden {\n 779│        eprintln!(\n 780│            \"xtask check: the two <HEAVY> strings have DRIFTED — .config/nextest.toml's \\\n*781│             test-group filter and golden.yml's job-level HEAVY env must be identical, or the \\\n*782│             suite is partitioned one way on golden and another way locally.\\n  \\\n*783│             only in .config/nextest.toml: {:?}\\n  only in golden.yml: {:?}\",\n*784│            names_only_in(from_nextest, from_golden),\n*785│            names_only_in(from_golden, from_nextest),\n 786│        );\n 787│        std::process::exit(1);\n 788│    }\n    │...\n 819│             PRECONDITION). Add each to BOTH <HEAVY> strings (.config/nextest.toml's test-group \\\n*820│             filter and golden.yml's job-level HEAVY env), alphabetically:\\n  {}\",\n 821│            unclassified.join(\"\\n  \")\n 822│        );\n 823│        std::process::exit(1);\n\n# .github/bench/\n## launch-battery.py\n  30│So this tool verifies the child AND its descendants — `a pid is not a tree`\n *31│(IR-80/IR-81) applies to reading an environment exactly as it does to killing.\n  32│The `.env` sidecar records every process actually inspected, by pid, so the\n *33│claim's SCOPE is on disk and not in a sentence.\n  34│\n  35│A NOTE ON ENV PREFIXES (todlando, 2026-09-07): a shell prefix launch — `VAR=1\n  36│cmd` — never enters the SCRIPT's own environment, so grepping `env` earlier in\n    │...\n 242│            # Kill the TREE, not the pid — the wrapper is the thing we hold and\n*243│            # the battery is the thing that would keep running (IR-80).\n 244│            _kill_tree(proc)\n 245│            print(\"LAUNCH REFUSED: the environment is not what was asked for.\")\n 246│            print(\"\\n\".join(problems))\n    │...\n 271│    \"\"\"Kill the wrapper AND its descendants. A single-pid kill here would leave\n*272│    the battery running under a refused launch — the exact IR-80 shape.\"\"\"\n 273│    try:\n 274│        victims = psutil.Process(proc.pid).children(recursive=True)\n 275│    except psutil.NoSuchProcess:","linesTruncated":true,"meta":{"limits":{"columnTruncated":{"maxColumn":512}}}},"isError":false,"timestamp":1789094623905}}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_cWYKmi0nchahOAbBE1SJnQzS|fc_065c0d1976ecf9c2016aa36aead84887d1af538449b44db8e5","toolName":"grep","startedAt":"2026-09-11T02:43:57.256Z","args":{"path":".github/workflows/ci.yml;.github/workflows/release.yml;.github/workflows/golden.yml:210-1500"},"intent":"Mapping all reordered workflow sites"},"id":"b81d0544","parentId":"0a541862","timestamp":"2026-09-11T02:43:57.256Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_2VYE4VKI1HnJxIXaRzaKBWLh|fc_065c0d1976ecf9c2016aa36aead85887d1b17ce7e42f0d590d","toolName":"grep","startedAt":"2026-09-11T02:43:57.256Z","args":{"path":"WEBSERVE-272-JIT.md;.github/ci/reap-census.ps1;docs/golden-head-intake.md;docs/RELEASE-RUNBOOK.md;AGENTS.md"},"intent":"Checking rider closure evidence"},"id":"47d8dc13","parentId":"b81d0544","timestamp":"2026-09-11T02:43:57.256Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_s1AqWTwfta765v3SU2Pb4BDV|fc_065c0d1976ecf9c2016aa36aead86487d1a6c6fde91994e976","toolName":"grep","startedAt":"2026-09-11T02:43:57.256Z","args":{"path":"crates/spt-daemon/src/daemon.rs"},"intent":"Checking missing forensic implementation"},"id":"e4671ba4","parentId":"47d8dc13","timestamp":"2026-09-11T02:43:57.256Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_TWb3NAXi5haZkSa9TowrVKQn|fc_065c0d1976ecf9c2016aa36aead86887d185534291b7b8f419","toolName":"grep","startedAt":"2026-09-11T02:43:57.257Z","args":{"path":"Cargo.toml;.github/workflows/release.yml;crates/xtask/src/brainread.rs"},"intent":"Checking release symbols and gate reach"},"id":"6395324f","parentId":"e4671ba4","timestamp":"2026-09-11T02:43:57.257Z"}
{"type":"message","id":"38170d68","parentId":"6395324f","timestamp":"2026-09-11T02:43:57.257Z","message":{"role":"assistant","content":[{"type":"thinking","thinking":"**Checking eight sources**"},{"type":"toolCall","id":"call_cWYKmi0nchahOAbBE1SJnQzS|fc_065c0d1976ecf9c2016aa36aead84887d1af538449b44db8e5","name":"grep","arguments":{"i":"Mapping all reordered workflow sites","pattern":"checkout@|IR-73|name: DISK|floorBytes =|floor_bytes=|FLOOR_DOCS|Docs drift|INBOUND|inbound","path":".github/workflows/ci.yml;.github/workflows/release.yml;.github/workflows/golden.yml:210-1500","case":true,"gitignore":true,"skip":0},"intent":"Mapping all reordered workflow sites"},{"type":"toolCall","id":"call_2VYE4VKI1HnJxIXaRzaKBWLh|fc_065c0d1976ecf9c2016aa36aead85887d1b17ce7e42f0d590d","name":"grep","arguments":{"i":"Checking rider closure evidence","pattern":"IR-73|IR-76|IR-59|IR-60|IR-88|IR-89|DAEMON_SUCCEEDS|kill.scop|compiler|foreign|CLEAR|HOLD|REFUSE","path":"WEBSERVE-272-JIT.md;.github/ci/reap-census.ps1;docs/golden-head-intake.md;docs/RELEASE-RUNBOOK.md;AGENTS.md","case":false,"gitignore":true,"skip":0},"intent":"Checking rider closure evidence"},{"type":"toolCall","id":"call_s1AqWTwfta765v3SU2Pb4BDV|fc_065c0d1976ecf9c2016aa36aead86487d1a6c6fde91994e976","name":"grep","arguments":{"i":"Checking missing forensic implementation","pattern":"daemon_pid_path|pid.prev|SUCCEEDS","path":"crates/spt-daemon/src/daemon.rs","case":true,"gitignore":true,"skip":0},"intent":"Checking missing forensic implementation"},{"type":"toolCall","id":"call_TWb3NAXi5haZkSa9TowrVKQn|fc_065c0d1976ecf9c2016aa36aead86887d185534291b7b8f419","name":"grep","arguments":{"i":"Checking release symbols and gate reach","pattern":"debug =|pdb|PDB|serve_|dispatch.rs|attach.rs|brain.rs","path":"Cargo.toml;.github/workflows/release.yml;crates/xtask/src/brainread.rs","case":true,"gitignore":true,"skip":0},"intent":"Checking release symbols and gate reach"}],"api":"openai-codex-responses","provider":"openai-codex","model":"gpt-6-astra","usage":{"input":18488,"output":389,"cacheRead":93952,"cacheWrite":0,"totalTokens":112829,"reasoningTokens":16,"cost":{"input":0,"output":0,"cacheRead":0,"cacheWrite":0,"total":0}},"stopReason":"toolUse","timestamp":1789094623961,"responseId":"resp_065c0d1976ecf9c2016aa36addd8b487d1831f64ec8abb0bd5","providerPayload":{"type":"openaiResponsesHistory","provider":"openai-codex","dt":true,"items":[{"id":"rs_065c0d1976ecf9c2016aa36adf2d1087d19d69de92744dccfb","type":"reasoning","content":[],"encrypted_content":"gAAAAABqo2rqw8yvi6TpQhBOAJ2bpgYUtiNjmLJm8N4qjEO1P0Kmth0am13e20c3nXzX_OiPIgjhqKiYCE8qdHnXSgIiNTa1YfkErcyzlVqrf1oarDBebQ4ySo7ut8hMVAqAgEyA3wZGhPnsrfCC0vqeQrhQ7dNu87o7ZnYeI2XaFEpSWK-C7vN0CNnYyLJlCD3svfNAulCGso2kj0xDhauBHVCouWUwcxzwjQf1q7W784yPVy0OZ4jXzUv9zYcnyd1NCZTHCqFC0GNvgPH6XM3f9SVbshBJBO4h7xkpQVwubvw6dpMDdsP4RxDSb55gd75lIvNoysPnDhqXyIips4qVn9eaCrfMeOMl-QHq4nmS-hnThNg6beagwQuJFCGnK_zt9SLZL4Wax3_a1TgBpNED7rikmMT3QdgdIQUjfP_7HacyPZL8QqqiyzHnoruI4hlfrqNLOxE6g7WOpXrHrra4cYIKvIB3Qb7oTOTyoe_vw29z6MWu8VP18t5L2Q5kcCuEkqIEr_70gi9qGwIldPjMb05hzQEpX0RmZpUo6NenC7DM5QVkjph1nHuYyDYeTTGA8_uWX2rEcxdHPog4J-hzqoWFMnzoZ2bVQJ3rC342xPPwNtViY3SADcGvVE9pjO6Q-lv1rOQX394M8fjWE8Fr2jCcPCsl1q0M2L4pmtX7Um-OezaXphi9RYHJDJVtTgp0pyhMsxAP4X-qu4ZwosLgNIekNrk7R0vi8X-3F5UGsp6NeqnplxtxqsmKRNz9nV4N8K1wjeILh1VXAYY55xvRjByPnZ8_FxakHB55Cix4rjv3mS9VF-qzcqapPI12F9iOi1C-foSlNQ1YTPVaHna-I0XAYNHcq_1ksyhi0HezcoNTCTjsQeVbZ0Xd0JQF10y5ZtHi0XfMxyOw0KP_34oLN1pqLxOIpjNHQrjDbV97iZWRmSRvn9e9jmg6e_J3okLrS8RTNLmAFMH5n2-wRlPeoNwKXZxamZBFUfyS7mOVDSoWCjwvPmgqHdoZiNJ6nXUG5X5CgGs_MKZM5nPY8u9cnGjnfuRlhiyzRmrfxW3wYQ5GoJ68ERu0h-no2BnYBewI5aEhmqy-y-Z7xVO1L12gdj4ZR83od-BAMoYTO8L1knMzzLZwDdC9tytpSlnaM5Abc7Xc9Re9CXGrMHfIwIhO6BEMs6zi_lkbIRwCheYCTUUUTTDq2mEqbplI1YO-mESASZoHyO-cWGjqZptf1D-9lI27gFjrbjqGIvSV9odqVQwaidGtgMCaYj6KUnuB-tEVY85QXWAwLkJTQnGbbh7tj6hZ5ZoCBhQrweA4Ybi9uBOyaH-0-ovILMmDDXbrZQYJUa7H-QKiaT6hAC_WqbFV4ZP8iHWqmQ==","internal_chat_message_metadata_passthrough":{"turn_id":"cb1368d9-2a08-40c0-9f68-e06c6338cbd5"},"summary":[{"type":"summary_text","text":"**Checking eight sources**"}],"metadata":{"turn_id":"cb1368d9-2a08-40c0-9f68-e06c6338cbd5"}},{"id":"fc_065c0d1976ecf9c2016aa36aead84887d1af538449b44db8e5","type":"function_call","status":"completed","arguments":"{\"i\":\"Mapping all reordered workflow sites\",\"pattern\":\"checkout@|IR-73|name: DISK|floorBytes =|floor_bytes=|FLOOR_DOCS|Docs drift|INBOUND|inbound\",\"path\":\".github/workflows/ci.yml;.github/workflows/release.yml;.github/workflows/golden.yml:210-1500\",\"case\":true,\"gitignore\":true,\"skip\":0}","call_id":"call_cWYKmi0nchahOAbBE1SJnQzS","internal_chat_message_metadata_passthrough":{"turn_id":"cb1368d9-2a08-40c0-9f68-e06c6338cbd5"},"name":"grep","metadata":{"turn_id":"cb1368d9-2a08-40c0-9f68-e06c6338cbd5"}},{"id":"fc_065c0d1976ecf9c2016aa36aead85887d1b17ce7e42f0d590d","type":"function_call","status":"completed","arguments":"{\"i\":\"Checking rider closure evidence\",\"pattern\":\"IR-73|IR-76|IR-59|IR-60|IR-88|IR-89|DAEMON_SUCCEEDS|kill.scop|compiler|foreign|CLEAR|HOLD|REFUSE\",\"path\":\"WEBSERVE-272-JIT.md;.github/ci/reap-census.ps1;docs/golden-head-intake.md;docs/RELEASE-RUNBOOK.md;AGENTS.md\",\"case\":false,\"gitignore\":true,\"skip\":0}","call_id":"call_2VYE4VKI1HnJxIXaRzaKBWLh","internal_chat_message_metadata_passthrough":{"turn_id":"cb1368d9-2a08-40c0-9f68-e06c6338cbd5"},"name":"grep","metadata":{"turn_id":"cb1368d9-2a08-40c0-9f68-e06c6338cbd5"}},{"id":"fc_065c0d1976ecf9c2016aa36aead86487d1a6c6fde91994e976","type":"function_call","status":"completed","arguments":"{\"i\":\"Checking missing forensic implementation\",\"pattern\":\"daemon_pid_path|pid.prev|SUCCEEDS\",\"path\":\"crates/spt-daemon/src/daemon.rs\",\"case\":true,\"gitignore\":true,\"skip\":0}","call_id":"call_s1AqWTwfta765v3SU2Pb4BDV","internal_chat_message_metadata_passthrough":{"turn_id":"cb1368d9-2a08-40c0-9f68-e06c6338cbd5"},"name":"grep","metadata":{"turn_id":"cb1368d9-2a08-40c0-9f68-e06c6338cbd5"}},{"id":"fc_065c0d1976ecf9c2016aa36aead86887d185534291b7b8f419","type":"function_call","status":"completed","arguments":"{\"i\":\"Checking release symbols and gate reach\",\"pattern\":\"debug =|pdb|PDB|serve_|dispatch.rs|attach.rs|brain.rs\",\"path\":\"Cargo.toml;.github/workflows/release.yml;crates/xtask/src/brainread.rs\",\"case\":true,\"gitignore\":true,\"skip\":0}","call_id":"call_TWb3NAXi5haZkSa9TowrVKQn","internal_chat_message_metadata_passthrough":{"turn_id":"cb1368d9-2a08-40c0-9f68-e06c6338cbd5"},"name":"grep","metadata":{"turn_id":"cb1368d9-2a08-40c0-9f68-e06c6338cbd5"}}]},"duration":13292.940600000322,"ttft":1561.810300000012,"completedAt":1789094637255,"contextSnapshot":{"promptTokens":112440,"nonMessageTokens":10400,"compactionEpoch":0}}}
{"type":"message","id":"d0f9ab0e","parentId":"38170d68","timestamp":"2026-09-11T02:43:57.261Z","message":{"role":"toolResult","toolCallId":"call_s1AqWTwfta765v3SU2Pb4BDV|fc_065c0d1976ecf9c2016aa36aead86487d1a6c6fde91994e976","toolName":"grep","content":[{"type":"text","text":" 29|use crate::endpoint::{\n*30|    broker_socket_name, daemon_pid_path, digest_socket_name, drive_socket_name, seed_socket_name,\n 31|};\n 32|use crate::nethost::{NetConfig, NetHost};\n 33|use crate::seedmap::{self, SeedRegistry};\n...\n 475|        // is the socket ping, never this file, so a stale value is harmless.\n*476|        let _ = std::fs::write(daemon_pid_path(), std::process::id().to_string());\n 477|\n 478|        // The seed-control channel is the foreground loop. Binding it is what\n 479|        // arbitrates the single-daemon-per-home invariant: a second daemon racing\n...\n 3453|        // Second skip path (sibling of the ACCESS_DENIED skip above): on some\n*3454|        // self-hosted runners the breakaway spawn SUCCEEDS (no ACCESS_DENIED) yet\n 3455|        // the grandchild never actually leaves a job (`gc_in_any_job=1`) — the\n 3456|        // ancestor-job policy silently confounds a clean escape. The escape cannot\n 3457|        // be proven faithfully here, so SKIP rather than false-fail. This is the"}],"details":{"scopePath":"crates/spt-daemon/src/daemon.rs","searchPath":"C:\\Users\\decid\\Documents\\projects\\spt-core\\crates\\spt-daemon\\src\\daemon.rs","cwd":"C:\\Users\\decid\\Documents\\projects\\spt-core","matchCount":3,"fileCount":1,"files":["crates/spt-daemon/src/daemon.rs"],"fileMatches":[{"path":"crates/spt-daemon/src/daemon.rs","count":3}],"truncated":false,"displayContent":"   29│use crate::endpoint::{\n  *30│    broker_socket_name, daemon_pid_path, digest_socket_name, drive_socket_name, seed_socket_name,\n   31│};\n   32│use crate::nethost::{NetConfig, NetHost};\n   33│use crate::seedmap::{self, SeedRegistry};\n     │...\n  475│        // is the socket ping, never this file, so a stale value is harmless.\n *476│        let _ = std::fs::write(daemon_pid_path(), std::process::id().to_string());\n  477│\n  478│        // The seed-control channel is the foreground loop. Binding it is what\n  479│        // arbitrates the single-daemon-per-home invariant: a second daemon racing\n     │...\n 3453│        // Second skip path (sibling of the ACCESS_DENIED skip above): on some\n*3454│        // self-hosted runners the breakaway spawn SUCCEEDS (no ACCESS_DENIED) yet\n 3455│        // the grandchild never actually leaves a job (`gc_in_any_job=1`) — the\n 3456│        // ancestor-job policy silently confounds a clean escape. The escape cannot\n 3457│        // be proven faithfully here, so SKIP rather than false-fail. This is the"},"isError":false,"timestamp":1789094637260}}
{"type":"message","id":"1c459eff","parentId":"d0f9ab0e","timestamp":"2026-09-11T02:43:57.286Z","message":{"role":"toolResult","toolCallId":"call_cWYKmi0nchahOAbBE1SJnQzS|fc_065c0d1976ecf9c2016aa36aead84887d1af538449b44db8e5","toolName":"grep","content":[{"type":"text","text":"# .github/workflows/\n## ci.yml\n 23|    steps:\n*24|      - uses: actions/checkout@v5\n 25|        with:\n 26|          fetch-depth: 2\n 27|      # IR-46/IR-59: 32 GiB is an instantaneous floor, not a headroom guarantee.\n*28|      # IR-73: This floor is not protective, so it runs after checkout.\n 29|      # [int->REQ-CI-FREE-SPACE-PREFLIGHT]\n*30|      - name: DISK floor start\n 31|        shell: bash\n 32|        run: |\n 33|          set -euo pipefail\n*34|          floor_bytes=$((32 * 1024 * 1024 * 1024))\n 35|          drive=$(df -P \"$GITHUB_WORKSPACE\" | awk 'NR == 2 { print $1 }')\n 36|          free_bytes=$(df -PB1 \"$GITHUB_WORKSPACE\" | awk 'NR == 2 { print $4 }')\n 37|          verdict=PASS\n 38|          if [ \"$free_bytes\" -lt \"$floor_bytes\" ]; then verdict=RED; fi\n*39|          printf 'FLOOR_START job=${{ github.job }} runner=${{ runner.os }} free_bytes=%s floor_bytes=%s verdict=%s sample=INSTANT\\n' \\\n 40|            \"$free_bytes\" \"$floor_bytes\" \"$verdict\"\n 41|          if [ \"$free_bytes\" -lt \"$floor_bytes\" ]; then\n*42|            echo \"::error title=Insufficient free disk::RESOURCE=disk drive=$drive free_bytes=$free_bytes floor_bytes=$floor_bytes\"\n 43|            exit 1\n 44|          fi\n 45|      - id: classify\n...\n 67|      # [int->REQ-CI-FREE-SPACE-PREFLIGHT]\n*68|      - name: DISK floor end\n 69|        if: always()\n 70|        shell: bash\n 71|        run: |\n 72|          set -euo pipefail\n*73|          floor_bytes=$((32 * 1024 * 1024 * 1024))\n 74|          drive=$(df -P \"$GITHUB_WORKSPACE\" | awk 'NR == 2 { print $1 }')\n 75|          free_bytes=$(df -PB1 \"$GITHUB_WORKSPACE\" | awk 'NR == 2 { print $4 }')\n 76|          verdict=PASS\n 77|          if [ \"$free_bytes\" -lt \"$floor_bytes\" ]; then verdict=RED; fi\n*78|          printf 'FLOOR_END job=${{ github.job }} runner=${{ runner.os }} free_bytes=%s floor_bytes=%s verdict=%s sample=INSTANT\\n' \\\n 79|            \"$free_bytes\" \"$floor_bytes\" \"$verdict\"\n 80|          if [ \"$free_bytes\" -lt \"$floor_bytes\" ]; then\n*81|            echo \"::error title=Insufficient free disk::RESOURCE=disk drive=$drive free_bytes=$free_bytes floor_bytes=$floor_bytes\"\n 82|            exit 1\n 83|          fi\n 84|\n...\n 96|    steps:\n*97|      - uses: actions/checkout@v5\n*98|      # IR-73: This floor is not protective, so it runs after checkout.\n 99|      # [int->REQ-CI-FREE-SPACE-PREFLIGHT]\n*100|      - name: DISK floor start (Windows)\n 101|        if: runner.os == 'Windows'\n 102|        shell: pwsh\n 103|        run: |\n*104|          $floorBytes = 32GB\n 105|          $drive = (Get-Item $env:GITHUB_WORKSPACE).PSDrive\n 106|          $freeBytes = [int64]$drive.Free\n 107|          $verdict = if ($freeBytes -lt $floorBytes) { 'RED' } else { 'PASS' }\n*108|          Write-Host \"FLOOR_START job=${{ github.job }} runner=${{ runner.os }} free_bytes=$freeBytes floor_bytes=$floorBytes verdict=$verdict sample=INSTANT\"\n 109|          if ($freeBytes -lt $floorBytes) {\n*110|            Write-Error \"RESOURCE=disk drive=$($drive.Root) free_bytes=$freeBytes floor_bytes=$floorBytes\"\n 111|            exit 1\n 112|          }\n*113|      # IR-73: This floor is not protective, so it runs after checkout.\n 114|      # [int->REQ-CI-FREE-SPACE-PREFLIGHT]\n*115|      - name: DISK floor start (Linux)\n 116|        if: runner.os == 'Linux'\n 117|        shell: bash\n 118|        run: |\n 119|          set -euo pipefail\n*120|          floor_bytes=$((32 * 1024 * 1024 * 1024))\n 121|          drive=$(df -P \"$GITHUB_WORKSPACE\" | awk 'NR == 2 { print $1 }')\n 122|          free_bytes=$(df -PB1 \"$GITHUB_WORKSPACE\" | awk 'NR == 2 { print $4 }')\n 123|          verdict=PASS\n 124|          if [ \"$free_bytes\" -lt \"$floor_bytes\" ]; then verdict=RED; fi\n*125|          printf 'FLOOR_START job=${{ github.job }} runner=${{ runner.os }} free_bytes=%s floor_bytes=%s verdict=%s sample=INSTANT\\n' \\\n 126|            \"$free_bytes\" \"$floor_bytes\" \"$verdict\"\n 127|          if [ \"$free_bytes\" -lt \"$floor_bytes\" ]; then\n## release.yml\n 51|    steps:\n*52|      - uses: actions/checkout@v5\n 53|      # IR-46/IR-59: 32 GiB is an instantaneous floor, not a headroom guarantee.\n*54|      # IR-73: This floor is not protective, so it runs after checkout.\n 55|      # [int->REQ-CI-FREE-SPACE-PREFLIGHT]\n*56|      - name: DISK floor start (Windows)\n 57|        if: runner.os == 'Windows'\n 58|        shell: pwsh\n 59|        run: |\n*60|          $floorBytes = 32GB\n 61|          $drive = (Get-Item $env:GITHUB_WORKSPACE).PSDrive\n 62|          $freeBytes = [int64]$drive.Free\n 63|          $verdict = if ($freeBytes -lt $floorBytes) { 'RED' } else { 'PASS' }\n*64|          Write-Host \"FLOOR_START job=${{ github.job }} runner=${{ runner.os }} free_bytes=$freeBytes floor_bytes=$floorBytes verdict=$verdict sample=INSTANT\"\n 65|          if ($freeBytes -lt $floorBytes) {\n*66|            Write-Error \"RESOURCE=disk drive=$($drive.Root) free_bytes=$freeBytes floor_bytes=$floorBytes\"\n 67|            exit 1\n 68|          }\n*69|      # IR-73: This floor is not protective, so it runs after checkout.\n 70|      # [int->REQ-CI-FREE-SPACE-PREFLIGHT]\n*71|      - name: DISK floor start (Linux)\n 72|        if: runner.os == 'Linux'\n 73|        shell: bash\n 74|        run: |\n 75|          set -euo pipefail\n*76|          floor_bytes=$((32 * 1024 * 1024 * 1024))\n 77|          drive=$(df -P \"$GITHUB_WORKSPACE\" | awk 'NR == 2 { print $1 }')\n 78|          free_bytes=$(df -PB1 \"$GITHUB_WORKSPACE\" | awk 'NR == 2 { print $4 }')\n 79|          verdict=PASS\n 80|          if [ \"$free_bytes\" -lt \"$floor_bytes\" ]; then verdict=RED; fi\n*81|          printf 'FLOOR_START job=${{ github.job }} runner=${{ runner.os }} free_bytes=%s floor_bytes=%s verdict=%s sample=INSTANT\\n' \\\n 82|            \"$free_bytes\" \"$floor_bytes\" \"$verdict\"\n 83|          if [ \"$free_bytes\" -lt \"$floor_bytes\" ]; then\n*84|            echo \"::error title=Insufficient free disk::RESOURCE=disk drive=$drive free_bytes=$free_bytes floor_bytes=$floor_bytes\"\n 85|            exit 1\n 86|          fi\n 87|      # musl cross-build prerequisites — installed in-job on kitsubito. musl-gcc\n...\n 131|      # [int->REQ-CI-FREE-SPACE-PREFLIGHT]\n*132|      - name: DISK floor end (Windows)\n 133|        if: always() && runner.os == 'Windows'\n 134|        shell: pwsh\n 135|        run: |\n*136|          $floorBytes = 32GB\n 137|          $drive = (Get-Item $env:GITHUB_WORKSPACE).PSDrive\n 138|          $freeBytes = [int64]$drive.Free\n 139|          $verdict = if ($freeBytes -lt $floorBytes) { 'RED' } else { 'PASS' }\n*140|          Write-Host \"FLOOR_END job=${{ github.job }} runner=${{ runner.os }} free_bytes=$freeBytes floor_bytes=$floorBytes verdict=$verdict sample=INSTANT\"\n 141|          if ($freeBytes -lt $floorBytes) {\n*142|            Write-Error \"RESOURCE=disk drive=$($drive.Root) free_bytes=$freeBytes floor_bytes=$floorBytes\"\n 143|            exit 1\n 144|          }\n 145|      # [int->REQ-CI-FREE-SPACE-PREFLIGHT]\n*146|      - name: DISK floor end (Linux)\n 147|        if: always() && runner.os == 'Linux'\n 148|        shell: bash\n 149|        run: |\n 150|          set -euo pipefail\n*151|          floor_bytes=$((32 * 1024 * 1024 * 1024))\n 152|          drive=$(df -P \"$GITHUB_WORKSPACE\" | awk 'NR == 2 { print $1 }')\n 153|          free_bytes=$(df -PB1 \"$GITHUB_WORKSPACE\" | awk 'NR == 2 { print $4 }')\n 154|          verdict=PASS\n 155|          if [ \"$free_bytes\" -lt \"$floor_bytes\" ]; then verdict=RED; fi\n*156|          printf 'FLOOR_END job=${{ github.job }} runner=${{ runner.os }} free_bytes=%s floor_bytes=%s verdict=%s sample=INSTANT\\n' \\\n 157|            \"$free_bytes\" \"$floor_bytes\" \"$verdict\"\n 158|          if [ \"$free_bytes\" -lt \"$floor_bytes\" ]; then\n*159|            echo \"::error title=Insufficient free disk::RESOURCE=disk drive=$drive free_bytes=$free_bytes floor_bytes=$floor_bytes\"\n 160|            exit 1\n 161|          fi\n 162|\n...\n 167|    steps:\n*168|      - uses: actions/checkout@v5\n## golden.yml\n 211|          exit 0\n*212|      - uses: actions/checkout@v5\n 213|      # Floor asserted AFTER checkout, same reason and same ruling as the n1-gate\n 214|      # job below (REQ-CI-FREE-SPACE-PREFLIGHT, the 2026-08-03 amendment, widened\n 215|      # here 2026-08-29): checkout runs `git clean -ffdx` and THAT is the reclaim,\n...\n 224|      # [int->REQ-CI-FREE-SPACE-PREFLIGHT]\n*225|      - name: DISK start floor (Windows)\n 226|        if: runner.os == 'Windows'\n 227|        shell: pwsh\n 228|        run: |\n*229|          $floorBytes = 32GB\n 230|          $drive = (Get-Item $env:GITHUB_WORKSPACE).PSDrive\n 231|          $freeBytes = [int64]$drive.Free\n 232|          $verdict = if ($freeBytes -lt $floorBytes) { \"RED\" } else { \"PASS\" }\n*233|          Write-Host \"FLOOR_START job=${{ github.job }} runner=${{ runner.os }} free_bytes=$freeBytes floor_bytes=$floorBytes verdict=$verdict sample=INSTANT\"\n 234|          if ($freeBytes -lt $floorBytes) {\n*235|            Write-Error \"RESOURCE=disk drive=$($drive.Root) free_bytes=$freeBytes floor_bytes=$floorBytes\"\n 236|            exit 1\n 237|          }\n 238|      # [int->REQ-CI-FREE-SPACE-PREFLIGHT]\n*239|      - name: DISK start floor (Linux)\n 240|        if: runner.os == 'Linux'\n 241|        shell: bash\n 242|        run: |\n 243|          set -euo pipefail\n*244|          floor_bytes=$((32 * 1024 * 1024 * 1024))\n 245|          drive=$(df -P \"$GITHUB_WORKSPACE\" | awk 'NR == 2 { print $1 }')\n 246|          free_bytes=$(df -PB1 \"$GITHUB_WORKSPACE\" | awk 'NR == 2 { print $4 }')\n 247|          verdict=PASS\n 248|          if [ \"$free_bytes\" -lt \"$floor_bytes\" ]; then verdict=RED; fi\n*249|          printf 'FLOOR_START job=${{ github.job }} runner=${{ runner.os }} free_bytes=%s floor_bytes=%s verdict=%s sample=INSTANT\\n' \\\n 250|            \"$free_bytes\" \"$floor_bytes\" \"$verdict\"\n 251|          if [ \"$free_bytes\" -lt \"$floor_bytes\" ]; then\n*252|            echo \"::error title=Insufficient free disk::RESOURCE=disk drive=$drive free_bytes=$free_bytes floor_bytes=$floor_bytes\"\n 253|            exit 1\n 254|          fi\n 255|      # Linux: link with mold (gcc -fuse-ld=mold). The slow part of a Linux\n...\n 502|      - name: Checkout spt-shell-notify (real-shell dogfood)\n*503|        uses: actions/checkout@v5\n 504|        with:\n 505|          repository: SaberMage/spt-shell-notify\n 506|          path: .adapter-notify\n...\n 596|      # normal test sweep.\n*597|      # IR-46 / IR-73: reread immediately before the docs build; start headroom is stale.\n 598|      # [int->REQ-CI-FREE-SPACE-PREFLIGHT]\n*599|      - name: DISK docs floor (Linux)\n 600|        if: runner.os == 'Linux'\n 601|        shell: bash\n 602|        run: |\n 603|          set -euo pipefail\n*604|          floor_bytes=$((32 * 1024 * 1024 * 1024))\n 605|          drive=$(df -P \"$GITHUB_WORKSPACE\" | awk 'NR == 2 { print $1 }')\n 606|          free_bytes=$(df -PB1 \"$GITHUB_WORKSPACE\" | awk 'NR == 2 { print $4 }')\n 607|          verdict=PASS\n 608|          if [ \"$free_bytes\" -lt \"$floor_bytes\" ]; then verdict=RED; fi\n*609|          printf 'FLOOR_DOCS job=${{ github.job }} runner=${{ runner.os }} free_bytes=%s floor_bytes=%s verdict=%s sample=INSTANT\\n' \\\n 610|            \"$free_bytes\" \"$floor_bytes\" \"$verdict\"\n 611|          if [ \"$free_bytes\" -lt \"$floor_bytes\" ]; then\n*612|            echo \"::error title=Insufficient free disk::RESOURCE=disk drive=$drive free_bytes=$free_bytes floor_bytes=$floor_bytes\"\n 613|            exit 1\n 614|          fi\n 615|      # [int->REQ-DOCS-5]\n*616|      - name: Docs drift gate (CLI ref + llms links) — linux\n 617|        if: runner.os == 'Linux'\n 618|        shell: bash\n 619|        run: bash .github/bench/wrap.sh xtask-check -- cargo run -p xtask -- check\n*620|      # IR-46 / IR-73: fresh native read, not the job-start value.\n 621|      # [int->REQ-CI-FREE-SPACE-PREFLIGHT]\n*622|      - name: DISK docs floor (Windows)\n 623|        if: runner.os == 'Windows'\n 624|        shell: pwsh\n 625|        run: |\n*626|          $floorBytes = 32GB\n 627|          $drive = (Get-Item $env:GITHUB_WORKSPACE).PSDrive\n 628|          $freeBytes = [int64]$drive.Free\n 629|          $verdict = if ($freeBytes -lt $floorBytes) { \"RED\" } else { \"PASS\" }\n*630|          Write-Host \"FLOOR_DOCS job=${{ github.job }} runner=${{ runner.os }} free_bytes=$freeBytes floor_bytes=$floorBytes verdict=$verdict sample=INSTANT\"\n 631|          if ($freeBytes -lt $floorBytes) {"}],"details":{"scopePath":".github/workflows/ci.yml, .github/workflows/release.yml, .github/workflows/golden.yml","searchPath":"C:\\Users\\decid\\Documents\\projects\\spt-core\\.github\\workflows","cwd":"C:\\Users\\decid\\Documents\\projects\\spt-core","matchCount":60,"fileCount":3,"files":[".github/workflows/ci.yml",".github/workflows/release.yml",".github/workflows/golden.yml"],"fileMatches":[{"path":".github/workflows/ci.yml","count":20},{"path":".github/workflows/release.yml","count":20},{"path":".github/workflows/golden.yml","count":20}],"truncated":true,"perFileLimitReached":20,"displayContent":"# .github/workflows/\n## ci.yml\n  23│    steps:\n *24│      - uses: actions/checkout@v5\n  25│        with:\n  26│          fetch-depth: 2\n  27│      # IR-46/IR-59: 32 GiB is an instantaneous floor, not a headroom guarantee.\n *28│      # IR-73: This floor is not protective, so it runs after checkout.\n  29│      # [int->REQ-CI-FREE-SPACE-PREFLIGHT]\n *30│      - name: DISK floor start\n  31│        shell: bash\n  32│        run: |\n  33│          set -euo pipefail\n *34│          floor_bytes=$((32 * 1024 * 1024 * 1024))\n  35│          drive=$(df -P \"$GITHUB_WORKSPACE\" | awk 'NR == 2 { print $1 }')\n  36│          free_bytes=$(df -PB1 \"$GITHUB_WORKSPACE\" | awk 'NR == 2 { print $4 }')\n  37│          verdict=PASS\n  38│          if [ \"$free_bytes\" -lt \"$floor_bytes\" ]; then verdict=RED; fi\n *39│          printf 'FLOOR_START job=${{ github.job }} runner=${{ runner.os }} free_bytes=%s floor_bytes=%s verdict=%s sample=INSTANT\\n' \\\n  40│            \"$free_bytes\" \"$floor_bytes\" \"$verdict\"\n  41│          if [ \"$free_bytes\" -lt \"$floor_bytes\" ]; then\n *42│            echo \"::error title=Insufficient free disk::RESOURCE=disk drive=$drive free_bytes=$free_bytes floor_bytes=$floor_bytes\"\n  43│            exit 1\n  44│          fi\n  45│      - id: classify\n    │...\n  67│      # [int->REQ-CI-FREE-SPACE-PREFLIGHT]\n *68│      - name: DISK floor end\n  69│        if: always()\n  70│        shell: bash\n  71│        run: |\n  72│          set -euo pipefail\n *73│          floor_bytes=$((32 * 1024 * 1024 * 1024))\n  74│          drive=$(df -P \"$GITHUB_WORKSPACE\" | awk 'NR == 2 { print $1 }')\n  75│          free_bytes=$(df -PB1 \"$GITHUB_WORKSPACE\" | awk 'NR == 2 { print $4 }')\n  76│          verdict=PASS\n  77│          if [ \"$free_bytes\" -lt \"$floor_bytes\" ]; then verdict=RED; fi\n *78│          printf 'FLOOR_END job=${{ github.job }} runner=${{ runner.os }} free_bytes=%s floor_bytes=%s verdict=%s sample=INSTANT\\n' \\\n  79│            \"$free_bytes\" \"$floor_bytes\" \"$verdict\"\n  80│          if [ \"$free_bytes\" -lt \"$floor_bytes\" ]; then\n *81│            echo \"::error title=Insufficient free disk::RESOURCE=disk drive=$drive free_bytes=$free_bytes floor_bytes=$floor_bytes\"\n  82│            exit 1\n  83│          fi\n  84│\n    │...\n  96│    steps:\n *97│      - uses: actions/checkout@v5\n *98│      # IR-73: This floor is not protective, so it runs after checkout.\n  99│      # [int->REQ-CI-FREE-SPACE-PREFLIGHT]\n*100│      - name: DISK floor start (Windows)\n 101│        if: runner.os == 'Windows'\n 102│        shell: pwsh\n 103│        run: |\n*104│          $floorBytes = 32GB\n 105│          $drive = (Get-Item $env:GITHUB_WORKSPACE).PSDrive\n 106│          $freeBytes = [int64]$drive.Free\n 107│          $verdict = if ($freeBytes -lt $floorBytes) { 'RED' } else { 'PASS' }\n*108│          Write-Host \"FLOOR_START job=${{ github.job }} runner=${{ runner.os }} free_bytes=$freeBytes floor_bytes=$floorBytes verdict=$verdict sample=INSTANT\"\n 109│          if ($freeBytes -lt $floorBytes) {\n*110│            Write-Error \"RESOURCE=disk drive=$($drive.Root) free_bytes=$freeBytes floor_bytes=$floorBytes\"\n 111│            exit 1\n 112│          }\n*113│      # IR-73: This floor is not protective, so it runs after checkout.\n 114│      # [int->REQ-CI-FREE-SPACE-PREFLIGHT]\n*115│      - name: DISK floor start (Linux)\n 116│        if: runner.os == 'Linux'\n 117│        shell: bash\n 118│        run: |\n 119│          set -euo pipefail\n*120│          floor_bytes=$((32 * 1024 * 1024 * 1024))\n 121│          drive=$(df -P \"$GITHUB_WORKSPACE\" | awk 'NR == 2 { print $1 }')\n 122│          free_bytes=$(df -PB1 \"$GITHUB_WORKSPACE\" | awk 'NR == 2 { print $4 }')\n 123│          verdict=PASS\n 124│          if [ \"$free_bytes\" -lt \"$floor_bytes\" ]; then verdict=RED; fi\n*125│          printf 'FLOOR_START job=${{ github.job }} runner=${{ runner.os }} free_bytes=%s floor_bytes=%s verdict=%s sample=INSTANT\\n' \\\n 126│            \"$free_bytes\" \"$floor_bytes\" \"$verdict\"\n 127│          if [ \"$free_bytes\" -lt \"$floor_bytes\" ]; then\n## release.yml\n  51│    steps:\n *52│      - uses: actions/checkout@v5\n  53│      # IR-46/IR-59: 32 GiB is an instantaneous floor, not a headroom guarantee.\n *54│      # IR-73: This floor is not protective, so it runs after checkout.\n  55│      # [int->REQ-CI-FREE-SPACE-PREFLIGHT]\n *56│      - name: DISK floor start (Windows)\n  57│        if: runner.os == 'Windows'\n  58│        shell: pwsh\n  59│        run: |\n *60│          $floorBytes = 32GB\n  61│          $drive = (Get-Item $env:GITHUB_WORKSPACE).PSDrive\n  62│          $freeBytes = [int64]$drive.Free\n  63│          $verdict = if ($freeBytes -lt $floorBytes) { 'RED' } else { 'PASS' }\n *64│          Write-Host \"FLOOR_START job=${{ github.job }} runner=${{ runner.os }} free_bytes=$freeBytes floor_bytes=$floorBytes verdict=$verdict sample=INSTANT\"\n  65│          if ($freeBytes -lt $floorBytes) {\n *66│            Write-Error \"RESOURCE=disk drive=$($drive.Root) free_bytes=$freeBytes floor_bytes=$floorBytes\"\n  67│            exit 1\n  68│          }\n *69│      # IR-73: This floor is not protective, so it runs after checkout.\n  70│      # [int->REQ-CI-FREE-SPACE-PREFLIGHT]\n *71│      - name: DISK floor start (Linux)\n  72│        if: runner.os == 'Linux'\n  73│        shell: bash\n  74│        run: |\n  75│          set -euo pipefail\n *76│          floor_bytes=$((32 * 1024 * 1024 * 1024))\n  77│          drive=$(df -P \"$GITHUB_WORKSPACE\" | awk 'NR == 2 { print $1 }')\n  78│          free_bytes=$(df -PB1 \"$GITHUB_WORKSPACE\" | awk 'NR == 2 { print $4 }')\n  79│          verdict=PASS\n  80│          if [ \"$free_bytes\" -lt \"$floor_bytes\" ]; then verdict=RED; fi\n *81│          printf 'FLOOR_START job=${{ github.job }} runner=${{ runner.os }} free_bytes=%s floor_bytes=%s verdict=%s sample=INSTANT\\n' \\\n  82│            \"$free_bytes\" \"$floor_bytes\" \"$verdict\"\n  83│          if [ \"$free_bytes\" -lt \"$floor_bytes\" ]; then\n *84│            echo \"::error title=Insufficient free disk::RESOURCE=disk drive=$drive free_bytes=$free_bytes floor_bytes=$floor_bytes\"\n  85│            exit 1\n  86│          fi\n  87│      # musl cross-build prerequisites — installed in-job on kitsubito. musl-gcc\n    │...\n 131│      # [int->REQ-CI-FREE-SPACE-PREFLIGHT]\n*132│      - name: DISK floor end (Windows)\n 133│        if: always() && runner.os == 'Windows'\n 134│        shell: pwsh\n 135│        run: |\n*136│          $floorBytes = 32GB\n 137│          $drive = (Get-Item $env:GITHUB_WORKSPACE).PSDrive\n 138│          $freeBytes = [int64]$drive.Free\n 139│          $verdict = if ($freeBytes -lt $floorBytes) { 'RED' } else { 'PASS' }\n*140│          Write-Host \"FLOOR_END job=${{ github.job }} runner=${{ runner.os }} free_bytes=$freeBytes floor_bytes=$floorBytes verdict=$verdict sample=INSTANT\"\n 141│          if ($freeBytes -lt $floorBytes) {\n*142│            Write-Error \"RESOURCE=disk drive=$($drive.Root) free_bytes=$freeBytes floor_bytes=$floorBytes\"\n 143│            exit 1\n 144│          }\n 145│      # [int->REQ-CI-FREE-SPACE-PREFLIGHT]\n*146│      - name: DISK floor end (Linux)\n 147│        if: always() && runner.os == 'Linux'\n 148│        shell: bash\n 149│        run: |\n 150│          set -euo pipefail\n*151│          floor_bytes=$((32 * 1024 * 1024 * 1024))\n 152│          drive=$(df -P \"$GITHUB_WORKSPACE\" | awk 'NR == 2 { print $1 }')\n 153│          free_bytes=$(df -PB1 \"$GITHUB_WORKSPACE\" | awk 'NR == 2 { print $4 }')\n 154│          verdict=PASS\n 155│          if [ \"$free_bytes\" -lt \"$floor_bytes\" ]; then verdict=RED; fi\n*156│          printf 'FLOOR_END job=${{ github.job }} runner=${{ runner.os }} free_bytes=%s floor_bytes=%s verdict=%s sample=INSTANT\\n' \\\n 157│            \"$free_bytes\" \"$floor_bytes\" \"$verdict\"\n 158│          if [ \"$free_bytes\" -lt \"$floor_bytes\" ]; then\n*159│            echo \"::error title=Insufficient free disk::RESOURCE=disk drive=$drive free_bytes=$free_bytes floor_bytes=$floor_bytes\"\n 160│            exit 1\n 161│          fi\n 162│\n    │...\n 167│    steps:\n*168│      - uses: actions/checkout@v5\n## golden.yml\n 211│          exit 0\n*212│      - uses: actions/checkout@v5\n 213│      # Floor asserted AFTER checkout, same reason and same ruling as the n1-gate\n 214│      # job below (REQ-CI-FREE-SPACE-PREFLIGHT, the 2026-08-03 amendment, widened\n 215│      # here 2026-08-29): checkout runs `git clean -ffdx` and THAT is the reclaim,\n    │...\n 224│      # [int->REQ-CI-FREE-SPACE-PREFLIGHT]\n*225│      - name: DISK start floor (Windows)\n 226│        if: runner.os == 'Windows'\n 227│        shell: pwsh\n 228│        run: |\n*229│          $floorBytes = 32GB\n 230│          $drive = (Get-Item $env:GITHUB_WORKSPACE).PSDrive\n 231│          $freeBytes = [int64]$drive.Free\n 232│          $verdict = if ($freeBytes -lt $floorBytes) { \"RED\" } else { \"PASS\" }\n*233│          Write-Host \"FLOOR_START job=${{ github.job }} runner=${{ runner.os }} free_bytes=$freeBytes floor_bytes=$floorBytes verdict=$verdict sample=INSTANT\"\n 234│          if ($freeBytes -lt $floorBytes) {\n*235│            Write-Error \"RESOURCE=disk drive=$($drive.Root) free_bytes=$freeBytes floor_bytes=$floorBytes\"\n 236│            exit 1\n 237│          }\n 238│      # [int->REQ-CI-FREE-SPACE-PREFLIGHT]\n*239│      - name: DISK start floor (Linux)\n 240│        if: runner.os == 'Linux'\n 241│        shell: bash\n 242│        run: |\n 243│          set -euo pipefail\n*244│          floor_bytes=$((32 * 1024 * 1024 * 1024))\n 245│          drive=$(df -P \"$GITHUB_WORKSPACE\" | awk 'NR == 2 { print $1 }')\n 246│          free_bytes=$(df -PB1 \"$GITHUB_WORKSPACE\" | awk 'NR == 2 { print $4 }')\n 247│          verdict=PASS\n 248│          if [ \"$free_bytes\" -lt \"$floor_bytes\" ]; then verdict=RED; fi\n*249│          printf 'FLOOR_START job=${{ github.job }} runner=${{ runner.os }} free_bytes=%s floor_bytes=%s verdict=%s sample=INSTANT\\n' \\\n 250│            \"$free_bytes\" \"$floor_bytes\" \"$verdict\"\n 251│          if [ \"$free_bytes\" -lt \"$floor_bytes\" ]; then\n*252│            echo \"::error title=Insufficient free disk::RESOURCE=disk drive=$drive free_bytes=$free_bytes floor_bytes=$floor_bytes\"\n 253│            exit 1\n 254│          fi\n 255│      # Linux: link with mold (gcc -fuse-ld=mold). The slow part of a Linux\n    │...\n 502│      - name: Checkout spt-shell-notify (real-shell dogfood)\n*503│        uses: actions/checkout@v5\n 504│        with:\n 505│          repository: SaberMage/spt-shell-notify\n 506│          path: .adapter-notify\n    │...\n 596│      # normal test sweep.\n*597│      # IR-46 / IR-73: reread immediately before the docs build; start headroom is stale.\n 598│      # [int->REQ-CI-FREE-SPACE-PREFLIGHT]\n*599│      - name: DISK docs floor (Linux)\n 600│        if: runner.os == 'Linux'\n 601│        shell: bash\n 602│        run: |\n 603│          set -euo pipefail\n*604│          floor_bytes=$((32 * 1024 * 1024 * 1024))\n 605│          drive=$(df -P \"$GITHUB_WORKSPACE\" | awk 'NR == 2 { print $1 }')\n 606│          free_bytes=$(df -PB1 \"$GITHUB_WORKSPACE\" | awk 'NR == 2 { print $4 }')\n 607│          verdict=PASS\n 608│          if [ \"$free_bytes\" -lt \"$floor_bytes\" ]; then verdict=RED; fi\n*609│          printf 'FLOOR_DOCS job=${{ github.job }} runner=${{ runner.os }} free_bytes=%s floor_bytes=%s verdict=%s sample=INSTANT\\n' \\\n 610│            \"$free_bytes\" \"$floor_bytes\" \"$verdict\"\n 611│          if [ \"$free_bytes\" -lt \"$floor_bytes\" ]; then\n*612│            echo \"::error title=Insufficient free disk::RESOURCE=disk drive=$drive free_bytes=$free_bytes floor_bytes=$floor_bytes\"\n 613│            exit 1\n 614│          fi\n 615│      # [int->REQ-DOCS-5]\n*616│      - name: Docs drift gate (CLI ref + llms links) — linux\n 617│        if: runner.os == 'Linux'\n 618│        shell: bash\n 619│        run: bash .github/bench/wrap.sh xtask-check -- cargo run -p xtask -- check\n*620│      # IR-46 / IR-73: fresh native read, not the job-start value.\n 621│      # [int->REQ-CI-FREE-SPACE-PREFLIGHT]\n*622│      - name: DISK docs floor (Windows)\n 623│        if: runner.os == 'Windows'\n 624│        shell: pwsh\n 625│        run: |\n*626│          $floorBytes = 32GB\n 627│          $drive = (Get-Item $env:GITHUB_WORKSPACE).PSDrive\n 628│          $freeBytes = [int64]$drive.Free\n 629│          $verdict = if ($freeBytes -lt $floorBytes) { \"RED\" } else { \"PASS\" }\n*630│          Write-Host \"FLOOR_DOCS job=${{ github.job }} runner=${{ runner.os }} free_bytes=$freeBytes floor_bytes=$floorBytes verdict=$verdict sample=INSTANT\"\n 631│          if ($freeBytes -lt $floorBytes) {"},"isError":false,"timestamp":1789094637284}}
{"type":"message","id":"f3e4e0ad","parentId":"1c459eff","timestamp":"2026-09-11T02:43:57.288Z","message":{"role":"toolResult","toolCallId":"call_TWb3NAXi5haZkSa9TowrVKQn|fc_065c0d1976ecf9c2016aa36aead86887d185534291b7b8f419","toolName":"grep","content":[{"type":"text","text":"# crates/xtask/src/\n## brainread.rs\n 193|\n*194|/// Includes all future serve_*_feed bodies, not merely the current nine.\n 195|pub fn feed_bodies_calling_call_deadline(src: &str) -> Result<Vec<Finding>, String> {\n 196|    let words = tokens(src)?;\n 197|    let mut findings = Vec::new();\n 198|    for f in functions(&words)? {\n*199|        if (f.name.starts_with(\"serve_\") && f.name.ends_with(\"_feed\")) || f.name == \"serve_attach\" {\n 200|            for token in f.body.iter().filter(|t| t.text == \"call_deadline\") {\n 201|                findings.push(Finding {\n 202|                    line: token.line,\n...\n 295|    let feeds = [\n*296|        \"serve_registry_feed\",\n*297|        \"serve_notif_feed\",\n*298|        \"serve_seal_feed\",\n*299|        \"serve_knock_feed\",\n*300|        \"serve_fork_feed\",\n*301|        \"serve_redeem_feed\",\n*302|        \"serve_answer_feed\",\n*303|        \"serve_presence_feed\",\n*304|        \"serve_wan_feed\",\n 305|    ];\n 306|    for (relative, streams, replies) in [\n 307|        (\n*308|            \"crates/spt-daemon/src/dispatch.rs\",\n 309|            feeds.as_slice(),\n 310|            vec![(\"peek_first_line\", \"brain\")],\n 311|        ),\n 312|        (\n*313|            \"crates/spt-daemon/src/attach.rs\",\n*314|            [\"serve_attach\"].as_slice(),\n 315|            vec![],\n 316|        ),\n 317|        (\n*318|            \"crates/spt-daemon/src/brain.rs\",\n 319|            [].as_slice(),\n 320|            vec![\n 321|                (\"net_stream_send\", \"self\"),\n...\n 346|    fn stream_deadline_is_rejected_but_reply_deadline_is_not() {\n*347|        let src = \"fn serve_future_feed() {\\n brain.call_deadline();\\n}\\nfn peek_first_line() { brain.call_deadline(); }\\nfn serve_attach() { brain.call_deadline(); }\";\n 348|        let findings = feed_bodies_calling_call_deadline(src).unwrap();\n 349|        assert_eq!(findings.iter().map(|f| f.line).collect::<Vec<_>>(), [2, 5]);\n 350|    }\n...\n 368|    fn literal_braces_and_nested_comments_do_not_hide_a_stream_body() {\n*369|        let src = r###\"fn serve_x_feed<'a>() { let s = r##\"} brain.read_event()\"##; let c = '}'; /* outer /* } */ */ brain.call_deadline(); }\"###;\n 370|        assert!(read_event_sites(src).unwrap().is_empty());\n 371|        assert_eq!(feed_bodies_calling_call_deadline(src).unwrap().len(), 1);\n 372|    }"}],"details":{"scopePath":"Cargo.toml, .github/workflows/release.yml, crates/xtask/src/brainread.rs","searchPath":"C:\\Users\\decid\\Documents\\projects\\spt-core","cwd":"C:\\Users\\decid\\Documents\\projects\\spt-core","matchCount":17,"fileCount":1,"files":["crates/xtask/src/brainread.rs"],"fileMatches":[{"path":"crates/xtask/src/brainread.rs","count":17}],"truncated":false,"displayContent":"# crates/xtask/src/\n## brainread.rs\n 193│\n*194│/// Includes all future serve_*_feed bodies, not merely the current nine.\n 195│pub fn feed_bodies_calling_call_deadline(src: &str) -> Result<Vec<Finding>, String> {\n 196│    let words = tokens(src)?;\n 197│    let mut findings = Vec::new();\n 198│    for f in functions(&words)? {\n*199│        if (f.name.starts_with(\"serve_\") && f.name.ends_with(\"_feed\")) || f.name == \"serve_attach\" {\n 200│            for token in f.body.iter().filter(|t| t.text == \"call_deadline\") {\n 201│                findings.push(Finding {\n 202│                    line: token.line,\n    │...\n 295│    let feeds = [\n*296│        \"serve_registry_feed\",\n*297│        \"serve_notif_feed\",\n*298│        \"serve_seal_feed\",\n*299│        \"serve_knock_feed\",\n*300│        \"serve_fork_feed\",\n*301│        \"serve_redeem_feed\",\n*302│        \"serve_answer_feed\",\n*303│        \"serve_presence_feed\",\n*304│        \"serve_wan_feed\",\n 305│    ];\n 306│    for (relative, streams, replies) in [\n 307│        (\n*308│            \"crates/spt-daemon/src/dispatch.rs\",\n 309│            feeds.as_slice(),\n 310│            vec![(\"peek_first_line\", \"brain\")],\n 311│        ),\n 312│        (\n*313│            \"crates/spt-daemon/src/attach.rs\",\n*314│            [\"serve_attach\"].as_slice(),\n 315│            vec![],\n 316│        ),\n 317│        (\n*318│            \"crates/spt-daemon/src/brain.rs\",\n 319│            [].as_slice(),\n 320│            vec![\n 321│                (\"net_stream_send\", \"self\"),\n    │...\n 346│    fn stream_deadline_is_rejected_but_reply_deadline_is_not() {\n*347│        let src = \"fn serve_future_feed() {\\n brain.call_deadline();\\n}\\nfn peek_first_line() { brain.call_deadline(); }\\nfn serve_attach() { brain.call_deadline(); }\";\n 348│        let findings = feed_bodies_calling_call_deadline(src).unwrap();\n 349│        assert_eq!(findings.iter().map(|f| f.line).collect::<Vec<_>>(), [2, 5]);\n 350│    }\n    │...\n 368│    fn literal_braces_and_nested_comments_do_not_hide_a_stream_body() {\n*369│        let src = r###\"fn serve_x_feed<'a>() { let s = r##\"} brain.read_event()\"##; let c = '}'; /* outer /* } */ */ brain.call_deadline(); }\"###;\n 370│        assert!(read_event_sites(src).unwrap().is_empty());\n 371│        assert_eq!(feed_bodies_calling_call_deadline(src).unwrap().len(), 1);\n 372│    }"},"isError":false,"timestamp":1789094637287}}
{"type":"message","id":"185f529a","parentId":"f3e4e0ad","timestamp":"2026-09-11T02:43:57.303Z","message":{"role":"toolResult","toolCallId":"call_2VYE4VKI1HnJxIXaRzaKBWLh|fc_065c0d1976ecf9c2016aa36aead85887d1b17ce7e42f0d590d","toolName":"grep","content":[{"type":"text","text":"# WEBSERVE-272-JIT.md\n 36|  batteries).\n*37|  **IR-76 pre-flight**: three-arm golden check before any local nextest/build on hfenduleam.\n 38|- Docs are the contract adapters build from: every wave lands its docs-site page(s) in the\n 39|  same commit (harness-contract + `reference.md` via `--help`), and CONTEXT.md terms are\n 40|  already ratified — do not re-word them, cite them.\n...\n 91|  a known key emits nothing. Docs: one paragraph in `harness-contract/manifest.md`\n*92|  (\"unknown keys are ignored; the diagnostic names them\"). Never refuse.\n 93|- **REQ-WEB-ACCESS-SURFACE** (ADR-0060; doc, impl, unit): mint the `WEB` row in the surface\n 94|  table (`default_on: true` within subnet — the DISCOVER shape; non-attributable until a\n 95|  sender stamp exists); the `--help` \"Control surfaces\" section grows it by existing\n...\n 107|  golden head so that head runs under it): IR-46 (weigh the disk-floor-instant remedies —\n*108|  the `golden.yml` touch at `04e32c8c` fired the trigger unweighed), IR-59 log-the-floor half\n*109|  (record free space beside every floor check), IR-73 (the 8 literal-first floor sites in\n 110|  `ci.yml`/`release.yml`). Entry text in `docs/INFRA-REGISTER.md` is the spec.\n 111|- **IR-66 — RULED SATISFIED 2026-09-06 (hertz measured, doyle ruled)**: the register body says\n 112|  BUILT at `d04b922d`/#161 and both cells are present at `17815c9c` (attach.rs:530/:538,\n...\n 117|- **IR-12 residual** rides W3's drift-gate riders (already hertz's).\n*118|- IR-59's log-the-floor line ALSO goes into IR-76's three-arm pre-flight on W0's driver\n 119|  template (todlando).\n 120|\n 121|## W1 — cross-node (todlando) — #249\n...\n 126|  shape), streams the response back; the local daemon proxies with NO cache; Range headers\n*127|  pass through; owner unreachable → 502 naming the node; owner refuses → 403 naming the\n 128|  surface. Unknown node name → the docs compat 404 (ADR-0056 Am.1 order, as W0 landed it at\n 129|  webserve.rs:307 — RULED doyle 2026-09-07 00:50Z, replacing an earlier \"404 naming it\" here;\n 130|  a 502 is only ever for a KNOWN subnet peer). An owner that does not speak\n...\n 144|  writes the bytes to `dest` (default: basename in cwd, refusing to clobber without `--force`),\n*145|  prints the path; exit codes: 0 / 3 refused (403) / 1 failed.\n 146|- **REQ-MSG-SHORT-ID** (ADR-0061; doc, impl, unit, int): 8-char base32 over the message hash,\n 147|  node-scoped, minted at commit, collision → lengthen that id; carried in the delivery\n 148|  envelope, in `MSG_IN`/`MSG_OUT` io-event rows, and rendered by `/<node>/m/<id>` (HTML +\n...\n 195|  installed exe's sha256; `curl …:5470/hfenduleam/docs/` = 404; `curl …:5474/` from kitsubito\n*196|  = connection refused (loopback proof).\n 197|\n 198|## Close riders\n 199|\n...\n 205|- **#148** stays detached BACKLOG (deferred by ruling; keys on REQ-MSG-SHORT-ID when built).\n*206|- **IR-76** driver pre-flight is a rider on W0's driver template (todlando authors the\n 207|  battery; the three-arm leg ships in it).\n 208|\n 209|## Sequencing (todlando's queue)\n...\n 247|      per-request `current_exe()`). Mismatch (dev build, hand-copied exe, apply-in-flight) → `spt serve\n*248|      lan --bootstrap` REFUSES with a named line (`LAN_BOOTSTRAP_REFUSED:unsigned-exe` / `:sha-mismatch`);\n 249|      there is no \"serve it marked unsigned\" branch — that is the supply-chain shape the question names.\n 250|   b. **Publish the provenance beside the bytes:** `/bin/<platform>/spt[.exe].release.json` = the exact\n 251|      `SignedRelease` record (metadata JSON + signature hex, relcache `metadata_json()`/`signature_hex()`).\n 252|      `spt.exe install` on the puller re-runs `verify_metadata` + `verify_artifact` against its BUILTIN\n*253|      keys before touching disk, and refuses on any failure. (Circular alone — a tampered exe carries\n 254|      tampered roots — which is why (c) exists; but it makes provenance durable and catches every\n 255|      accidental corruption/truncation/wrong-platform pull for free on the existing substrate.)\n 256|   c. **Out-of-band anchor = the operator's eyes:** `spt serve lan --bootstrap` PRINTS the artifact sha256\n...\n 262|      (`;;…;;` wax-seal over the hex) so a later reader can prove the operator was the publisher.\n*263|   **REFINED doyle 2026-09-07 10:14Z (real clock) — after todlando's measure-first, re-measured by me:** `%LOCALAPPDATA%\\spt-core\\releases\\artifacts\\` holds THREE triples (windows-msvc, linux-gnu, linux-musl) under ONE `release.json`\n 264|   (`metadata_json` + `signature_hex`, key `rel-primary-2026`, set version 102, phase applied); `bin\\spt.exe` sha256\n 265|   `d0ec895a…52db` == the windows-msvc artifact == its `artifact_sha256` entry (three-way, measured twice). So the\n 266|   signature is per SET, not per platform, and conjunct (a) is re-scoped from \"bytes == running exe\" to\n...\n 270|     running exe (canonical path at t=0) AND whose applied-state reads `phase=applied` at that set version. Fail\n*271|     → `LAN_BOOTSTRAP_REFUSED:unsigned-exe` / `:sha-mismatch` / `:set-not-applied`, nothing served. A staged-but-\n 272|     unapplied newer set is never served: the stranger gets what this node RUNS, never what it is about to.\n 273|   - **Per-triple gate (per path):** `/bin/<triple>/spt[.exe]` serves the staged bytes only if they hash to that\n 274|     triple's `artifact_sha256` in the same signed metadata; a missing or mismatched NON-host artifact 404s with\n...\n 288|   Int (kitsubito → hfenduleam): bytes sha256 == installed exe sha256 == `.release.json`'s\n*289|   `artifact_sha256`; `install` with a wrong `--expect-sha256` refuses, exit ≠ 0, nothing written; a\n*290|   truncated download refuses at (b); `serve lan --bootstrap` on a dev-built rig refuses at (a).\n 291|   ~~SUPERSEDED 10:14Z (see REFINED above; todlando caught the placement 10:17Z): \"that last arm means\n 292|   the rig pair (dev bins) CANNOT witness the happy path: the int arm needs a rig whose daemon is a\n 293|   staged signed release (lab-signed set) else a `--allow-unsigned-TEST-ONLY` cfg(test) arm — pick the\n...\n 300|### RULED doyle 2026-09-07 12:05Z — W3 shape questions (todlando 12:15Z-stamped, real 12:04Z; both claims re-verified at source before ruling)\n*301|**#265 mount = (B), beside the core root.** `/<node>/a/<adapter>/` already serves the adapter's registry web root (webserve.rs:455 `fn adapter` -> `serve_entry` on the entry whose `adapter == name`), and ADR-0056 bought a W0 URL its fixed meaning, so `docs_dir` mounts at `/<node>/a/<adapter>/docs/...`. The `docs` segment is RESERVED under the adapter facet, router-first like W0's reserved facets: with `docs_dir` set it serves that dir; absent it answers `NOT_FOUND: facet a adapter <name> docs` and NEVER ...\n 302|**#268 strip = every SCANNED CLASS, not today's population.** `changelog_page` strips by span using the SAME predicate the scan uses (`forbidden_codes_in` or a sibling returning spans, never a second hand-written list): the `<!-- [doc->REQ-...] -->` comments (5 today), the `(releases#N)` citations (CHANGELOG.md:294, :305 today — a public page carries no internal issue refs, so the whole parenthetical goes, not the token), and any ADR-/F-/REQ-/M-block token that a future entry adds. Unit: `forbidden_cod...\n 303|**#266:** riding the REFINED 10:14Z ruling verbatim, no re-measure — correct; a second reading of the same box is not a second witness.\n 304|\n...\n 308|APPROVED with four pins.\n*309|1. Listener lives in the DAEMON, CLI reaches it through servehost::call — correct, and required: the set gate anchors on the daemon's OWN exe canonical path at t=0 (brainproc rule), so the daemon computes the shas and answers; the CLI only prints. ServeRequest/ServeResult are the local IPC envelope (KIND_SERVE_REQUEST), not a sister-project wire schema, so new variants are fine: LanBootstrap {port override} / LanStop, results LanUp {url, shas: one (triple, hex) per SERVED triple} / LanStopped / LanRefu...\n 310|2. Idempotence: --bootstrap while UP answers the SAME url + shas with LAN_BOOTSTRAP_ALREADY_UP (never a second listener, never a re-run of the gate producing a different set); --stop while DOWN answers LAN_BOOTSTRAP_NOT_UP, exit 0. Unit both.\n*311|3. Ephemeral by construction: no persisted up-state; a daemon restart never resurrects the listener (off by default is a property of every boot, not just the first). --stop tears the listener down AND clears LAN-EXPOSED from the now-signal in the same request; unit asserts both.\n 312|4. lanhost.rs beside docshost.rs, same thread + current_thread runtime pattern, shutdown arm for --stop — fine. Router knows ONLY /bin/<triple>/spt[.exe], its .release.json sidecar, /install; everything else 404 with a line naming the listener, never a fall-through into 5474 code paths. The 5474-stays-loopback-while-5470-is-up unit rides here (REQ-WEB-LAN-BOOTSTRAP-LISTENER text).\n 313|\n 314|Acked: REQ-DOCS-CHANGELOG-PAGE unit stays unactivated until hertz's half lands (activate, do not pre-fail). #265 (B) and #268 span-strip as described match the 12:05Z ruling; the decoy-docs no-fall-through cell is the right falsifier. Keep fa286ffb unpushed until you push W2 F17; W2 lands first. Rule still ABSENT here at the stamp below; priority unchanged.\n\n# AGENTS.md\n 38|- **Worktrees (binding, operator-ruled 2026-07-05):** every `git worktree` (gate rigs, agent scratch, anything) goes under `.worktrees/` in THIS project's root (`.gitignore`d) — e.g. `git worktree add --detach .worktrees/gate-<sha> <sha>`. NEVER create worktrees as siblings of the project dir; stray sibling folders accumulate orphan-pinned skeletons and pollute `~/Documents/projects`. Remove yours when done (`git worktree remove` + prune; retry later if a handle pins it).\n*39|<!-- [doc->REQ-POOL-FOREIGN-TREE-REFUSED] -->\n*40|- **Build-cache pools (binding, releases#103):** a cargo `target/` directory belongs to ONE source tree. Two trees building into one pool overwrite each other's artifacts and fabricate reds that belong to neither — the v0.51.0 W1/H1 `E0308` that vanished on re-run. **The rule is about the RELATIONSHIP, not the path:** a junction and a `CARGO_TARGET_DIR` env var reach the same hazard, and the env var leaves no directory entry to notice afterwards, so \"is this dir under `.worktrees/`\" never was the quest...\n 41|- **Target-tree teardown (releases#103, same lane):** never delete a `target/` you have not classified. Check OUTBOUND first (`Get-Item -Force`: a junction is deleted as a link, a real dir as a tree), then sweep INBOUND for reparse points aimed at it before removing a real one, and measure size and free space before and after so the reclaim is a number rather than a claim. Reap the target SUBTREE, never a session or worktree directory around it. Do not point `CARGO_TARGET_DIR` into a scratchpad (v0.50.0 ...\n 42|- **CI / merge strategy:** golden CI (ADR-0050, ruled 2026-07-27) — milestone-batch golden runs, thin-lane PRs, ff-only main (tested sha == merged sha). Piloting from the next milestone; read the ADR before shaping a PR lane.\n 43|\n*44|If you finish a significant body of work without need for user intervention, or if your context gets too high, you can clear your own context and keep moving:\n 45|1. Create a JIT plan for the next immediate body of work, if it isn't already planned\n 46|2. If you are a live agent, /sptc:commune with immediate next steps and broad summary of the project's status + end goal\n*47|3. Execute the /self-clear skill\n\n# .github/ci/\n## reap-census.ps1\n 23|     adapter_digest in turn; run 4 went green once disk and leaked session-0 daemons were\n*24|     cleared.\n 25|\n*26|  KILL SCOPE IS PATH-VERIFIED AND NARROW, per-pid, AT KILL TIME — never machine-wide.\n 27|  A process is eligible only if its on-disk image sits under one of this run's own build\n 28|  roots (workspace, CARGO_TARGET_DIR, the notify-adapter checkout's target, RUNNER_TEMP,\n 29|  the pinned n1 old-broker build cache). Two hard exclusions are checked even for a\n...\n 160|    foreach ($r in ($Rows | Sort-Object Name, Pid)) {\n*161|        $tag = if ($r.InScope) { 'SCOPED  ' } elseif (-not $r.Readable) { 'UNREAD  ' } else { 'FOREIGN ' }\n 162|        Write-Output (\"  {0} pid={1,-7} handles={2,-6} {3} {4}\" -f $tag, $r.Pid, ($r.Handles ?? -1), $r.Name, ($r.Path ?? '<path unreadable — session-0 or access denied>'))\n 163|    }\n 164|    $script:CensusScoped = $scoped.Count\n...\n 258|    $msg = if ($unreadable -gt 0) {\n*259|        \"CI-REAP: clean survivor count REFUSED — $unreadable family process path(s) were unreadable, beside $survivors observed scoped survivor(s).\"\n 260|    }\n 261|    elseif ($isPrerelink) {\n 262|        \"CI-REAP-PRERELINK: $survivors scoped daemon(s) survived the pre-relink reap — the relink step that follows is expected to fail on os-error-5.\"\n\n# docs/\n## RELEASE-RUNBOOK.md\n 256|\n*257|This step is written armed because the unarmed form was cited as bar-clearing\n 258|evidence at the **v0.54.0 cut** and caught on duration rather than on procedure:\n 259|`0.00s` looked wrong for a network-and-crypto e2e, and re-running armed against\n 260|the published v0.53.0 assets took `1.60s` and did the real work. The bar is\n*261|cleared by the armed run; an unarmed green measures nothing, and \"nothing\" has no\n 262|failure mode.\n 263|\n 264|**Q2 — SEVERITY (quality, independent of Q1): does shipping this mislead a user\n...\n 279|Worked example from the v0.51.0 arc: `releases#71` comment `5153399070` read\n*280|\"this gates PUBLISH\", the operator subsequently cleared the acceptance to run\n 281|*post*-publish, and the record went un-updated for an interval during which the\n 282|stale sentence was carried into the release plan twice. The instrument that\n 283|caught it was checking `created == updated` on the comment and confirming no\n...\n 285|it (comment `5155301974`) rather than editing around it. Before acting on a\n*286|dated ruling, read its condition and check it still holds.\n 287|\n 288|<!-- [doc->REQ-GOLDEN-CI-LANE] -->\n 289|\n...\n 331|\n*332|   **Post-golden edits are refused by default.** Not a changelog date, rider\n 333|   line, lockfile adjustment, or regenerated byte. After the run the tree is\n 334|   frozen: ship exactly what was tested, or add the delta to a new batch commit\n 335|   and rerun golden CI.\n...\n 341|   compiled tree re-purchases evidence already held. Such a delta may ride the\n*342|   tested head **only** when it clears the provability bar in *Golden-head\n 343|   intake → the respin test*: a name-only diff confined to non-code, plus the\n 344|   compiled-in exceptions (version material) checked by measurement. A delta\n 345|   that needs an argument rather than a diff buys the full window. This narrows\n*346|   which edits are refused; it does not weaken *tested SHA equals shipped SHA*,\n 347|   which still governs everything golden actually validated.\n 348|\n 349|   The older dedicated-release-PR rule applied before milestone-batch golden CI,\n...\n 475|   The merge and push must succeed, and the final ancestry check must exit 0.\n*476|   `--ff-only` refuses divergence rather than manufacturing an untested merge\n 477|   commit. **A release tag points at a commit already on `main`, never the\n 478|   reverse.**\n 479|\n...\n 483|   already green at this SHA, so its green adds no coverage and must not be\n*484|   waited on **as evidence**. Wait for it **as occupancy**: it holds the box,\n 485|   and step 5 is local Cargo. Measured on 2026-07-29: lint 55s, unit Linux\n 486|   2m53s, unit Windows 8m30s—roughly ten minutes, not a cycle.\n 487|\n...\n 515|   against.** Filing register and docs work on `main` after a golden run is\n*516|   routine practice, and holding the merge queue does not prevent it: the\n*517|   commits that open the gap land *before* the hold, and they are precisely the\n 518|   ones documenting the release just tested. So treat the ruled sha and `main`'s\n 519|   tip as different objects by default, and **print both before pushing** — that\n 520|   makes the tag a measurement instead of an assumption, and it costs one\n...\n 731|7. **Teardown: preserve FIRST, release SECOND — as two messages, in that\n*732|   order (ruled doyle + deployah, convergently, 2026-08-29).** When any hold\n 733|   protecting an artifact is about to lift — an instrumented tree, an\n 734|   unlanded diff, a specimen the arc named worth keeping:\n 735|\n\nSkipped missing paths: docs/golden-head-intake.md\n\n[Some lines truncated to 512 chars]"}],"details":{"scopePath":"WEBSERVE-272-JIT.md, .github/ci/reap-census.ps1, docs/RELEASE-RUNBOOK.md, AGENTS.md","searchPath":"C:\\Users\\decid\\Documents\\projects\\spt-core","cwd":"C:\\Users\\decid\\Documents\\projects\\spt-core","matchCount":38,"fileCount":4,"files":["WEBSERVE-272-JIT.md",".github/ci/reap-census.ps1","docs/RELEASE-RUNBOOK.md","AGENTS.md"],"fileMatches":[{"path":"WEBSERVE-272-JIT.md","count":18},{"path":".github/ci/reap-census.ps1","count":4},{"path":"docs/RELEASE-RUNBOOK.md","count":12},{"path":"AGENTS.md","count":4}],"truncated":true,"displayContent":"# WEBSERVE-272-JIT.md\n  36│  batteries).\n *37│  **IR-76 pre-flight**: three-arm golden check before any local nextest/build on hfenduleam.\n  38│- Docs are the contract adapters build from: every wave lands its docs-site page(s) in the\n  39│  same commit (harness-contract + `reference.md` via `--help`), and CONTEXT.md terms are\n  40│  already ratified — do not re-word them, cite them.\n    │...\n  91│  a known key emits nothing. Docs: one paragraph in `harness-contract/manifest.md`\n *92│  (\"unknown keys are ignored; the diagnostic names them\"). Never refuse.\n  93│- **REQ-WEB-ACCESS-SURFACE** (ADR-0060; doc, impl, unit): mint the `WEB` row in the surface\n  94│  table (`default_on: true` within subnet — the DISCOVER shape; non-attributable until a\n  95│  sender stamp exists); the `--help` \"Control surfaces\" section grows it by existing\n    │...\n 107│  golden head so that head runs under it): IR-46 (weigh the disk-floor-instant remedies —\n*108│  the `golden.yml` touch at `04e32c8c` fired the trigger unweighed), IR-59 log-the-floor half\n*109│  (record free space beside every floor check), IR-73 (the 8 literal-first floor sites in\n 110│  `ci.yml`/`release.yml`). Entry text in `docs/INFRA-REGISTER.md` is the spec.\n 111│- **IR-66 — RULED SATISFIED 2026-09-06 (hertz measured, doyle ruled)**: the register body says\n 112│  BUILT at `d04b922d`/#161 and both cells are present at `17815c9c` (attach.rs:530/:538,\n    │...\n 117│- **IR-12 residual** rides W3's drift-gate riders (already hertz's).\n*118│- IR-59's log-the-floor line ALSO goes into IR-76's three-arm pre-flight on W0's driver\n 119│  template (todlando).\n 120│\n 121│## W1 — cross-node (todlando) — #249\n    │...\n 126│  shape), streams the response back; the local daemon proxies with NO cache; Range headers\n*127│  pass through; owner unreachable → 502 naming the node; owner refuses → 403 naming the\n 128│  surface. Unknown node name → the docs compat 404 (ADR-0056 Am.1 order, as W0 landed it at\n 129│  webserve.rs:307 — RULED doyle 2026-09-07 00:50Z, replacing an earlier \"404 naming it\" here;\n 130│  a 502 is only ever for a KNOWN subnet peer). An owner that does not speak\n    │...\n 144│  writes the bytes to `dest` (default: basename in cwd, refusing to clobber without `--force`),\n*145│  prints the path; exit codes: 0 / 3 refused (403) / 1 failed.\n 146│- **REQ-MSG-SHORT-ID** (ADR-0061; doc, impl, unit, int): 8-char base32 over the message hash,\n 147│  node-scoped, minted at commit, collision → lengthen that id; carried in the delivery\n 148│  envelope, in `MSG_IN`/`MSG_OUT` io-event rows, and rendered by `/<node>/m/<id>` (HTML +\n    │...\n 195│  installed exe's sha256; `curl …:5470/hfenduleam/docs/` = 404; `curl …:5474/` from kitsubito\n*196│  = connection refused (loopback proof).\n 197│\n 198│## Close riders\n 199│\n    │...\n 205│- **#148** stays detached BACKLOG (deferred by ruling; keys on REQ-MSG-SHORT-ID when built).\n*206│- **IR-76** driver pre-flight is a rider on W0's driver template (todlando authors the\n 207│  battery; the three-arm leg ships in it).\n 208│\n 209│## Sequencing (todlando's queue)\n    │...\n 247│      per-request `current_exe()`). Mismatch (dev build, hand-copied exe, apply-in-flight) → `spt serve\n*248│      lan --bootstrap` REFUSES with a named line (`LAN_BOOTSTRAP_REFUSED:unsigned-exe` / `:sha-mismatch`);\n 249│      there is no \"serve it marked unsigned\" branch — that is the supply-chain shape the question names.\n 250│   b. **Publish the provenance beside the bytes:** `/bin/<platform>/spt[.exe].release.json` = the exact\n 251│      `SignedRelease` record (metadata JSON + signature hex, relcache `metadata_json()`/`signature_hex()`).\n 252│      `spt.exe install` on the puller re-runs `verify_metadata` + `verify_artifact` against its BUILTIN\n*253│      keys before touching disk, and refuses on any failure. (Circular alone — a tampered exe carries\n 254│      tampered roots — which is why (c) exists; but it makes provenance durable and catches every\n 255│      accidental corruption/truncation/wrong-platform pull for free on the existing substrate.)\n 256│   c. **Out-of-band anchor = the operator's eyes:** `spt serve lan --bootstrap` PRINTS the artifact sha256\n    │...\n 262│      (`;;…;;` wax-seal over the hex) so a later reader can prove the operator was the publisher.\n*263│   **REFINED doyle 2026-09-07 10:14Z (real clock) — after todlando's measure-first, re-measured by me:** `%LOCALAPPDATA%\\spt-core\\releases\\artifacts\\` holds THREE triples (windows-msvc, linux-gnu, linux-musl) under ONE `release.json`\n 264│   (`metadata_json` + `signature_hex`, key `rel-primary-2026`, set version 102, phase applied); `bin\\spt.exe` sha256\n 265│   `d0ec895a…52db` == the windows-msvc artifact == its `artifact_sha256` entry (three-way, measured twice). So the\n 266│   signature is per SET, not per platform, and conjunct (a) is re-scoped from \"bytes == running exe\" to\n    │...\n 270│     running exe (canonical path at t=0) AND whose applied-state reads `phase=applied` at that set version. Fail\n*271│     → `LAN_BOOTSTRAP_REFUSED:unsigned-exe` / `:sha-mismatch` / `:set-not-applied`, nothing served. A staged-but-\n 272│     unapplied newer set is never served: the stranger gets what this node RUNS, never what it is about to.\n 273│   - **Per-triple gate (per path):** `/bin/<triple>/spt[.exe]` serves the staged bytes only if they hash to that\n 274│     triple's `artifact_sha256` in the same signed metadata; a missing or mismatched NON-host artifact 404s with\n    │...\n 288│   Int (kitsubito → hfenduleam): bytes sha256 == installed exe sha256 == `.release.json`'s\n*289│   `artifact_sha256`; `install` with a wrong `--expect-sha256` refuses, exit ≠ 0, nothing written; a\n*290│   truncated download refuses at (b); `serve lan --bootstrap` on a dev-built rig refuses at (a).\n 291│   ~~SUPERSEDED 10:14Z (see REFINED above; todlando caught the placement 10:17Z): \"that last arm means\n 292│   the rig pair (dev bins) CANNOT witness the happy path: the int arm needs a rig whose daemon is a\n 293│   staged signed release (lab-signed set) else a `--allow-unsigned-TEST-ONLY` cfg(test) arm — pick the\n    │...\n 300│### RULED doyle 2026-09-07 12:05Z — W3 shape questions (todlando 12:15Z-stamped, real 12:04Z; both claims re-verified at source before ruling)\n*301│**#265 mount = (B), beside the core root.** `/<node>/a/<adapter>/` already serves the adapter's registry web root (webserve.rs:455 `fn adapter` -> `serve_entry` on the entry whose `adapter == name`), and ADR-0056 bought a W0 URL its fixed meaning, so `docs_dir` mounts at `/<node>/a/<adapter>/docs/...`. The `docs` segment is RESERVED under the adapter facet, router-first like W0's reserved facets: with `docs_dir` set it serves that dir; absent it answers `NOT_FOUND: facet a adapter <name> docs` and NEVER ...\n 302│**#268 strip = every SCANNED CLASS, not today's population.** `changelog_page` strips by span using the SAME predicate the scan uses (`forbidden_codes_in` or a sibling returning spans, never a second hand-written list): the `<!-- [doc->REQ-...] -->` comments (5 today), the `(releases#N)` citations (CHANGELOG.md:294, :305 today — a public page carries no internal issue refs, so the whole parenthetical goes, not the token), and any ADR-/F-/REQ-/M-block token that a future entry adds. Unit: `forbidden_cod...\n 303│**#266:** riding the REFINED 10:14Z ruling verbatim, no re-measure — correct; a second reading of the same box is not a second witness.\n 304│\n    │...\n 308│APPROVED with four pins.\n*309│1. Listener lives in the DAEMON, CLI reaches it through servehost::call — correct, and required: the set gate anchors on the daemon's OWN exe canonical path at t=0 (brainproc rule), so the daemon computes the shas and answers; the CLI only prints. ServeRequest/ServeResult are the local IPC envelope (KIND_SERVE_REQUEST), not a sister-project wire schema, so new variants are fine: LanBootstrap {port override} / LanStop, results LanUp {url, shas: one (triple, hex) per SERVED triple} / LanStopped / LanRefu...\n 310│2. Idempotence: --bootstrap while UP answers the SAME url + shas with LAN_BOOTSTRAP_ALREADY_UP (never a second listener, never a re-run of the gate producing a different set); --stop while DOWN answers LAN_BOOTSTRAP_NOT_UP, exit 0. Unit both.\n*311│3. Ephemeral by construction: no persisted up-state; a daemon restart never resurrects the listener (off by default is a property of every boot, not just the first). --stop tears the listener down AND clears LAN-EXPOSED from the now-signal in the same request; unit asserts both.\n 312│4. lanhost.rs beside docshost.rs, same thread + current_thread runtime pattern, shutdown arm for --stop — fine. Router knows ONLY /bin/<triple>/spt[.exe], its .release.json sidecar, /install; everything else 404 with a line naming the listener, never a fall-through into 5474 code paths. The 5474-stays-loopback-while-5470-is-up unit rides here (REQ-WEB-LAN-BOOTSTRAP-LISTENER text).\n 313│\n 314│Acked: REQ-DOCS-CHANGELOG-PAGE unit stays unactivated until hertz's half lands (activate, do not pre-fail). #265 (B) and #268 span-strip as described match the 12:05Z ruling; the decoy-docs no-fall-through cell is the right falsifier. Keep fa286ffb unpushed until you push W2 F17; W2 lands first. Rule still ABSENT here at the stamp below; priority unchanged.\n\n# AGENTS.md\n 38│- **Worktrees (binding, operator-ruled 2026-07-05):** every `git worktree` (gate rigs, agent scratch, anything) goes under `.worktrees/` in THIS project's root (`.gitignore`d) — e.g. `git worktree add --detach .worktrees/gate-<sha> <sha>`. NEVER create worktrees as siblings of the project dir; stray sibling folders accumulate orphan-pinned skeletons and pollute `~/Documents/projects`. Remove yours when done (`git worktree remove` + prune; retry later if a handle pins it).\n*39│<!-- [doc->REQ-POOL-FOREIGN-TREE-REFUSED] -->\n*40│- **Build-cache pools (binding, releases#103):** a cargo `target/` directory belongs to ONE source tree. Two trees building into one pool overwrite each other's artifacts and fabricate reds that belong to neither — the v0.51.0 W1/H1 `E0308` that vanished on re-run. **The rule is about the RELATIONSHIP, not the path:** a junction and a `CARGO_TARGET_DIR` env var reach the same hazard, and the env var leaves no directory entry to notice afterwards, so \"is this dir under `.worktrees/`\" never was the quest...\n 41│- **Target-tree teardown (releases#103, same lane):** never delete a `target/` you have not classified. Check OUTBOUND first (`Get-Item -Force`: a junction is deleted as a link, a real dir as a tree), then sweep INBOUND for reparse points aimed at it before removing a real one, and measure size and free space before and after so the reclaim is a number rather than a claim. Reap the target SUBTREE, never a session or worktree directory around it. Do not point `CARGO_TARGET_DIR` into a scratchpad (v0.50.0 ...\n 42│- **CI / merge strategy:** golden CI (ADR-0050, ruled 2026-07-27) — milestone-batch golden runs, thin-lane PRs, ff-only main (tested sha == merged sha). Piloting from the next milestone; read the ADR before shaping a PR lane.\n 43│\n*44│If you finish a significant body of work without need for user intervention, or if your context gets too high, you can clear your own context and keep moving:\n 45│1. Create a JIT plan for the next immediate body of work, if it isn't already planned\n 46│2. If you are a live agent, /sptc:commune with immediate next steps and broad summary of the project's status + end goal\n*47│3. Execute the /self-clear skill\n\n# .github/ci/\n## reap-census.ps1\n  23│     adapter_digest in turn; run 4 went green once disk and leaked session-0 daemons were\n *24│     cleared.\n  25│\n *26│  KILL SCOPE IS PATH-VERIFIED AND NARROW, per-pid, AT KILL TIME — never machine-wide.\n  27│  A process is eligible only if its on-disk image sits under one of this run's own build\n  28│  roots (workspace, CARGO_TARGET_DIR, the notify-adapter checkout's target, RUNNER_TEMP,\n  29│  the pinned n1 old-broker build cache). Two hard exclusions are checked even for a\n    │...\n 160│    foreach ($r in ($Rows | Sort-Object Name, Pid)) {\n*161│        $tag = if ($r.InScope) { 'SCOPED  ' } elseif (-not $r.Readable) { 'UNREAD  ' } else { 'FOREIGN ' }\n 162│        Write-Output (\"  {0} pid={1,-7} handles={2,-6} {3} {4}\" -f $tag, $r.Pid, ($r.Handles ?? -1), $r.Name, ($r.Path ?? '<path unreadable — session-0 or access denied>'))\n 163│    }\n 164│    $script:CensusScoped = $scoped.Count\n    │...\n 258│    $msg = if ($unreadable -gt 0) {\n*259│        \"CI-REAP: clean survivor count REFUSED — $unreadable family process path(s) were unreadable, beside $survivors observed scoped survivor(s).\"\n 260│    }\n 261│    elseif ($isPrerelink) {\n 262│        \"CI-REAP-PRERELINK: $survivors scoped daemon(s) survived the pre-relink reap — the relink step that follows is expected to fail on os-error-5.\"\n\n# docs/\n## RELEASE-RUNBOOK.md\n 256│\n*257│This step is written armed because the unarmed form was cited as bar-clearing\n 258│evidence at the **v0.54.0 cut** and caught on duration rather than on procedure:\n 259│`0.00s` looked wrong for a network-and-crypto e2e, and re-running armed against\n 260│the published v0.53.0 assets took `1.60s` and did the real work. The bar is\n*261│cleared by the armed run; an unarmed green measures nothing, and \"nothing\" has no\n 262│failure mode.\n 263│\n 264│**Q2 — SEVERITY (quality, independent of Q1): does shipping this mislead a user\n    │...\n 279│Worked example from the v0.51.0 arc: `releases#71` comment `5153399070` read\n*280│\"this gates PUBLISH\", the operator subsequently cleared the acceptance to run\n 281│*post*-publish, and the record went un-updated for an interval during which the\n 282│stale sentence was carried into the release plan twice. The instrument that\n 283│caught it was checking `created == updated` on the comment and confirming no\n    │...\n 285│it (comment `5155301974`) rather than editing around it. Before acting on a\n*286│dated ruling, read its condition and check it still holds.\n 287│\n 288│<!-- [doc->REQ-GOLDEN-CI-LANE] -->\n 289│\n    │...\n 331│\n*332│   **Post-golden edits are refused by default.** Not a changelog date, rider\n 333│   line, lockfile adjustment, or regenerated byte. After the run the tree is\n 334│   frozen: ship exactly what was tested, or add the delta to a new batch commit\n 335│   and rerun golden CI.\n    │...\n 341│   compiled tree re-purchases evidence already held. Such a delta may ride the\n*342│   tested head **only** when it clears the provability bar in *Golden-head\n 343│   intake → the respin test*: a name-only diff confined to non-code, plus the\n 344│   compiled-in exceptions (version material) checked by measurement. A delta\n 345│   that needs an argument rather than a diff buys the full window. This narrows\n*346│   which edits are refused; it does not weaken *tested SHA equals shipped SHA*,\n 347│   which still governs everything golden actually validated.\n 348│\n 349│   The older dedicated-release-PR rule applied before milestone-batch golden CI,\n    │...\n 475│   The merge and push must succeed, and the final ancestry check must exit 0.\n*476│   `--ff-only` refuses divergence rather than manufacturing an untested merge\n 477│   commit. **A release tag points at a commit already on `main`, never the\n 478│   reverse.**\n 479│\n    │...\n 483│   already green at this SHA, so its green adds no coverage and must not be\n*484│   waited on **as evidence**. Wait for it **as occupancy**: it holds the box,\n 485│   and step 5 is local Cargo. Measured on 2026-07-29: lint 55s, unit Linux\n 486│   2m53s, unit Windows 8m30s—roughly ten minutes, not a cycle.\n 487│\n    │...\n 515│   against.** Filing register and docs work on `main` after a golden run is\n*516│   routine practice, and holding the merge queue does not prevent it: the\n*517│   commits that open the gap land *before* the hold, and they are precisely the\n 518│   ones documenting the release just tested. So treat the ruled sha and `main`'s\n 519│   tip as different objects by default, and **print both before pushing** — that\n 520│   makes the tag a measurement instead of an assumption, and it costs one\n    │...\n 731│7. **Teardown: preserve FIRST, release SECOND — as two messages, in that\n*732│   order (ruled doyle + deployah, convergently, 2026-08-29).** When any hold\n 733│   protecting an artifact is about to lift — an instrumented tree, an\n 734│   unlanded diff, a specimen the arc named worth keeping:\n 735│","missingPaths":["docs/golden-head-intake.md"],"linesTruncated":true,"meta":{"limits":{"columnTruncated":{"maxColumn":512}}}},"isError":false,"timestamp":1789094637302}}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_n6XpCAKJjfUqoSFAM764yDeD|fc_065c0d1976ecf9c2016aa36af5ca3087d19ea01e73fef9c2ea","toolName":"grep","startedAt":"2026-09-11T02:44:08.333Z","args":{"path":".github/workflows/ci.yml;.github/workflows/release.yml"},"intent":"Completing workflow site census"},"id":"64a3aad4","parentId":"185f529a","timestamp":"2026-09-11T02:44:08.333Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_dtHmZOU11W6MplnZSTVlmQGZ|fc_065c0d1976ecf9c2016aa36af5ca4087d1b534401a3478fe06","toolName":"grep","startedAt":"2026-09-11T02:44:08.333Z","args":{"path":"docs;AGENTS.md;.github/bench"},"intent":"Locating intake contract filename"},"id":"443f3f9d","parentId":"64a3aad4","timestamp":"2026-09-11T02:44:08.333Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_lbOrwRZHulZyS2quOVFUGUzT|fc_065c0d1976ecf9c2016aa36af5ca4887d1909af820d907f213","toolName":"read","startedAt":"2026-09-11T02:44:08.333Z","args":{"path":"docs/INFRA-REGISTER.md:3158:raw"},"intent":"Reading previously truncated audit line"},"id":"32277a55","parentId":"443f3f9d","timestamp":"2026-09-11T02:44:08.333Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_je8wMtg1cJ5pjZKOnhvuOQvA|fc_065c0d1976ecf9c2016aa36af5ca4c87d1ae9331a4acb465eb","toolName":"read","startedAt":"2026-09-11T02:44:08.334Z","args":{"path":"Cargo.toml:70-120"},"intent":"Reading profile and packaging contract"},"id":"86481ca0","parentId":"32277a55","timestamp":"2026-09-11T02:44:08.334Z"}
{"type":"message","id":"1868b78f","parentId":"86481ca0","timestamp":"2026-09-11T02:44:08.334Z","message":{"role":"assistant","content":[{"type":"thinking","thinking":"**Narrowing the search pattern**"},{"type":"toolCall","id":"call_n6XpCAKJjfUqoSFAM764yDeD|fc_065c0d1976ecf9c2016aa36af5ca3087d19ea01e73fef9c2ea","name":"grep","arguments":{"i":"Completing workflow site census","pattern":"checkout@|IR-73","path":".github/workflows/ci.yml;.github/workflows/release.yml","case":true,"gitignore":true,"skip":0},"intent":"Completing workflow site census"},{"type":"toolCall","id":"call_dtHmZOU11W6MplnZSTVlmQGZ|fc_065c0d1976ecf9c2016aa36af5ca4087d1b534401a3478fe06","name":"grep","arguments":{"i":"Locating intake contract filename","pattern":"quiet.window|three.arm|IR-76|prebuilt.*xtask|release.*BEFORE","path":"docs;AGENTS.md;.github/bench","case":false,"gitignore":true,"skip":0},"intent":"Locating intake contract filename"},{"type":"toolCall","id":"call_lbOrwRZHulZyS2quOVFUGUzT|fc_065c0d1976ecf9c2016aa36af5ca4887d1909af820d907f213","name":"read","arguments":{"i":"Reading previously truncated audit line","path":"docs/INFRA-REGISTER.md:3158:raw"},"intent":"Reading previously truncated audit line"},{"type":"toolCall","id":"call_je8wMtg1cJ5pjZKOnhvuOQvA|fc_065c0d1976ecf9c2016aa36af5ca4c87d1ae9331a4acb465eb","name":"read","arguments":{"i":"Reading profile and packaging contract","path":"Cargo.toml:70-120"},"intent":"Reading profile and packaging contract"},{"type":"toolCall","id":"call_EkFTMkjuxA6cfHso8guYFqsA|fc_065c0d1976ecf9c2016aa36af5ca5487d1aed7ba11df25d0c5","name":"grep","arguments":{"i":"Checking probe execution evidence","pattern":"inbound|INBOUND|probe","path":".spt/preserved/gate-r2-34481993681-20260910","case":false,"gitignore":false,"skip":0},"intent":"Checking probe execution evidence"}],"api":"openai-codex-responses","provider":"openai-codex","model":"gpt-6-astra","usage":{"input":10103,"output":317,"cacheRead":112256,"cacheWrite":0,"totalTokens":122676,"reasoningTokens":52,"cost":{"input":0,"output":0,"cacheRead":0,"cacheWrite":0,"total":0}},"stopReason":"toolUse","timestamp":1789094637356,"responseId":"resp_065c0d1976ecf9c2016aa36aeb3ea087d19dbfb60501c02e87","providerPayload":{"type":"openaiResponsesHistory","provider":"openai-codex","dt":true,"items":[{"id":"rs_065c0d1976ecf9c2016aa36aec4edc87d192dd698c9ae02eb5","type":"reasoning","content":[],"encrypted_content":"gAAAAABqo2r1UaybqvX4y75eAyOzGsC0KNwuIZmzUyN1vI4J3GrULZVrURo9n1dB9BFnlWpyxEsKaC3Czn2pGB5yb73edQubZLstArZBcr45k_Hz1lZEAfYJx16L243HtroRRU25UlxEAwghDJzRsLxUCuHWPfa-tmRvGgWvoJQZI5U9UrQ9ctwtJn7da_Z9QrBHMJAkmeSXrBWlm5x9GFEEPy-zCh6xwZxiXjFJ5-jt-oJkX6hyz1RJ80RHpAvCA3J38nOBetHd9fbxmBENdbXXNIdyk7HKxQNkS6LDhE0JQHNGRHZlmw1VHutarPJwbMucv1a55QPyfGz6yKTpF3EbnGpTUy3UX32QidaO2hBzSGfB0Ae6K-ySK7NQAiWVwfHdU1xx6YWggrZ6lM0JpS0cEkkV4hIKPVjuxdYLimAUpBkPPucSHTwj0BEtKFBgCbMhB77U8meDA6iwaMvG0HU97PogzVlfibBUBhESJvGK10AeQThatl_3Ax-SX8svHlpNvnq6wPeETUlKTjCBe8CHlm4N5h8BT3ZnHH7pYKmLueXdsAsASVxU0NeqCRTEZyp_2w-ROfqVJXG9hwZ5vrsPV9SFWH4YzJsT9Pp4uGMkL7qk52fjA2zWEeOq70yZJBmBlRZt2OkAJI4Yk4qbCEkYbpd_5Xf_R2n-lNZ5mDC_FgVzK5ze4jqfNDellORidqVE1L14VXL6OLkT9VAaKdNaABO-Efyg5RuQt1TnvCa5RlcUVIFET9mzRnRK7NXEOeYkBx_QHyJ8RUodRz63W4beQP84jSsbRg9CUdIquXqisViWjyjfk-vPmZkrwzFmo9E2RO6o9P-HTa-jkkv-sf24rI3-KZSMyp5iKxiG3eK4uFdUvQpmMlPCWb-ZpYlsgFxMcMWpwQtdWrI3Ag3dOV8hL5zm8GXLhA_rp_JK2rX2QJpyvd_dHgtYWEmGNrHuJg4rQxC2EC_zAzXrXh4xMJe0TtmeKPzDK0wfZMELfBHjIAyOk4URrBU745_a5G8WAO-qURHxx_x2o0fbM1MHUiJkCsfKZ3G7W3gm13V4w4CAU8IajLGOW9UFmv5DYNpLK63KkDD8VCZsqUk7dZNeDpL8qILx8JOp-8c2yRrv8vkJE0QpIwnAxUqjC2kYH1ikYA5m6Q9eiGOR4opQ9phO3N3Q2aDyJ-vY0iUiJ6ewMYX0y9QLpaKGY2QEptWc1bYVyKCXivfxNWt-ergEA2M59aIxVFCJ4Z9aCXErq46jsUf8g_RhxyzOZmoAgEWYz3MuVA0R-6VhAEh-MQdUHFrITrC__xf9aju83cs4SQ9ZZASmij51na-kdgjkFHFf4RWBnybmQ1RkMxxQF3VazrOZnyE8ny25Gn5Ukute7SbT4jHDWyiII84tTWmChh1wge5ZDh-XOuiUS1OzqhiWkGYfGdGlDVmuMWn5x2kOgAM4NqjJwo2rrtuo5zFDJ2o-_6regmG0DDLBvLm0guEjKBqZK1Z4M_CrZeTWxy66ck2XNuuMqQwhGFCGlDofb9Y0k8k0mWSA2ZUzm2h5Ub4RNftXOGRXhcpN7CBv2tuH7xHGBSQrHnvt32sH8T4GxylaX2Bl8afoh_dUbwJzrx6dTff_ZiBIsYaaAhk8Og==","internal_chat_message_metadata_passthrough":{"turn_id":"cb1368d9-2a08-40c0-9f68-e06c6338cbd5"},"summary":[{"type":"summary_text","text":"**Narrowing the search pattern**"}],"metadata":{"turn_id":"cb1368d9-2a08-40c0-9f68-e06c6338cbd5"}},{"id":"fc_065c0d1976ecf9c2016aa36af5ca3087d19ea01e73fef9c2ea","type":"function_call","status":"completed","arguments":"{\"i\":\"Completing workflow site census\",\"pattern\":\"checkout@|IR-73\",\"path\":\".github/workflows/ci.yml;.github/workflows/release.yml\",\"case\":true,\"gitignore\":true,\"skip\":0}","call_id":"call_n6XpCAKJjfUqoSFAM764yDeD","internal_chat_message_metadata_passthrough":{"turn_id":"cb1368d9-2a08-40c0-9f68-e06c6338cbd5"},"name":"grep","metadata":{"turn_id":"cb1368d9-2a08-40c0-9f68-e06c6338cbd5"}},{"id":"fc_065c0d1976ecf9c2016aa36af5ca4087d1b534401a3478fe06","type":"function_call","status":"completed","arguments":"{\"i\":\"Locating intake contract filename\",\"pattern\":\"quiet.window|three.arm|IR-76|prebuilt.*xtask|release.*BEFORE\",\"path\":\"docs;AGENTS.md;.github/bench\",\"case\":false,\"gitignore\":true,\"skip\":0}","call_id":"call_dtHmZOU11W6MplnZSTVlmQGZ","internal_chat_message_metadata_passthrough":{"turn_id":"cb1368d9-2a08-40c0-9f68-e06c6338cbd5"},"name":"grep","metadata":{"turn_id":"cb1368d9-2a08-40c0-9f68-e06c6338cbd5"}},{"id":"fc_065c0d1976ecf9c2016aa36af5ca4887d1909af820d907f213","type":"function_call","status":"completed","arguments":"{\"i\":\"Reading previously truncated audit line\",\"path\":\"docs/INFRA-REGISTER.md:3158:raw\"}","call_id":"call_lbOrwRZHulZyS2quOVFUGUzT","internal_chat_message_metadata_passthrough":{"turn_id":"cb1368d9-2a08-40c0-9f68-e06c6338cbd5"},"name":"read","metadata":{"turn_id":"cb1368d9-2a08-40c0-9f68-e06c6338cbd5"}},{"id":"fc_065c0d1976ecf9c2016aa36af5ca4c87d1ae9331a4acb465eb","type":"function_call","status":"completed","arguments":"{\"i\":\"Reading profile and packaging contract\",\"path\":\"Cargo.toml:70-120\"}","call_id":"call_je8wMtg1cJ5pjZKOnhvuOQvA","internal_chat_message_metadata_passthrough":{"turn_id":"cb1368d9-2a08-40c0-9f68-e06c6338cbd5"},"name":"read","metadata":{"turn_id":"cb1368d9-2a08-40c0-9f68-e06c6338cbd5"}},{"id":"fc_065c0d1976ecf9c2016aa36af5ca5487d1aed7ba11df25d0c5","type":"function_call","status":"completed","arguments":"{\"i\":\"Checking probe execution evidence\",\"pattern\":\"inbound|INBOUND|probe\",\"path\":\".spt/preserved/gate-r2-34481993681-20260910\",\"case\":false,\"gitignore\":false,\"skip\":0}","call_id":"call_EkFTMkjuxA6cfHso8guYFqsA","internal_chat_message_metadata_passthrough":{"turn_id":"cb1368d9-2a08-40c0-9f68-e06c6338cbd5"},"name":"grep","metadata":{"turn_id":"cb1368d9-2a08-40c0-9f68-e06c6338cbd5"}}]},"duration":10946.382600000128,"ttft":1307.373999999836,"completedAt":1789094648331,"contextSnapshot":{"promptTokens":122359,"nonMessageTokens":10400,"compactionEpoch":0}}}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_EkFTMkjuxA6cfHso8guYFqsA|fc_065c0d1976ecf9c2016aa36af5ca5487d1aed7ba11df25d0c5","toolName":"grep","startedAt":"2026-09-11T02:44:08.334Z","args":{"path":".spt/preserved/gate-r2-34481993681-20260910"},"intent":"Checking probe execution evidence"},"id":"cfb6689d","parentId":"1868b78f","timestamp":"2026-09-11T02:44:08.334Z"}
{"type":"message","id":"a156653b","parentId":"cfb6689d","timestamp":"2026-09-11T02:44:08.350Z","message":{"role":"toolResult","toolCallId":"call_je8wMtg1cJ5pjZKOnhvuOQvA|fc_065c0d1976ecf9c2016aa36af5ca4c87d1ae9331a4acb465eb","toolName":"read","content":[{"type":"text","text":"Line 70 is beyond end of file (54 lines total). Use :1 to read from the start, or :54 to read the last line."}],"details":{"resolvedPath":"C:\\Users\\decid\\Documents\\projects\\spt-core\\Cargo.toml"},"isError":false,"timestamp":1789094648349}}
{"type":"message","id":"c82ad9a3","parentId":"a156653b","timestamp":"2026-09-11T02:44:08.355Z","message":{"role":"toolResult","toolCallId":"call_lbOrwRZHulZyS2quOVFUGUzT|fc_065c0d1976ecf9c2016aa36af5ca4887d1909af820d907f213","toolName":"read","content":[{"type":"text","text":"  pick-audit --range 57a0d27c..HEAD --lane 4d6007ac..d0fdd58d` over 6 picks — **5 MATCH\n  (digest-identical), 1 LOSS, 0 drift, 0 unclassified**, exit 1 forcing the accounting. The LOSS\n  was exactly the one human-resolved conflict (`cfb9d9f8 <- 10f12e4c`, count 432/402), and the\n  delta RECONCILED to the resolution rather than assumed: lane stat 15 files/235+/197- vs pick\n  14 files/205+/197-, difference byte-for-byte the deliberately-dropped 30-line interim IR-69\n  register block superseded by main's consolidated entry. No false positives, no silent pass.\n  Entry stays OPEN as living procedure; both live uses (the rebase catch above, this assembly)\n  produced the verdict classes in the order the entry predicts.\n- **Trigger condition:** ripe at the next assembly — this is procedure, and its cost is one command\n  per pick.\n- **Size guess:** small as a scripted check in `xtask` (fidelity audit over a pick range); zero as\n  discipline, which is how it is being applied now.\n\n### IR-58 — a `[[bin]]` grep is not a census: cargo AUTODISCOVERS `src/bin/*.rs` targets, and a hand-built bin list produced a confident false \"this bin does not exist\"\n\n- **Status:** OPEN, unowned. Filed by doyle 2026-08-22; **its original filing was WRONG and is\n  retracted in full below.** The entry is kept because the way it was wrong is the finding.\n- **RETRACTED CLAIM, stated plainly so no reader acts on it:** this entry first said that\n  `crates/spt/Cargo.toml:18-21` and `crates/spt/src/cli.rs:30355` forbid a bin-name collision with\n  `xlate_choreo_fixture`, \"a bin that does not exist\", and that spt-daemon's third helper had been\n  renamed to `summarizer_fixture`. **`xlate_choreo_fixture` EXISTS** — at\n  `crates/spt-daemon/src/bin/xlate_choreo_fixture.rs`, verified at the assembly head. The collision\n  rule's counterpart is real, both prose sites are CORRECT, and IR-21's original table row was\n  correct too; it merely predated `summarizer_fixture`. Nothing in that prose needs fixing.\n- **How the false claim was produced, which is the entry:** the census was built by grepping\n  `^\\[\\[bin\\]\\]` across `Cargo.toml`s. **Cargo AUTODISCOVERS `src/bin/*.rs` as bin targets with no\n  stanza at all**, so a stanza grep cannot see them, and it fails SILENTLY — it returns a clean,\n  well-formed list that is simply short. From that list it read as established fact that a named bin\n  had been renamed away, and that \"fact\" was then written into a register table, an IR entry, and a\n  message to the builder. **A pattern-built population encodes the pattern's assumption; the count\n  looks like a census and is a property of the pattern.**\n  (Found by todlando, resolving one of doyle's figures against his own tree under the pointer rule.)\n- **A CENSUS IS ALSO A PROPERTY OF A TREE.** Stanza counts differed legitimately across trees the\n  same hour — 13 at the assembly head, 11 at `dc1c7532` — because `summarizer_fixture` exists at one\n  and not the other. Two correct censuses of the same workspace disagree unless each names its sha.\n- **The must-do, and it removes the list rather than lengthening it:** never hand-maintain a bin\n  roster. Run `cargo build --workspace --bins` and let cargo enumerate its own targets — the same\n  enumeration the test harness resolves against, so it cannot drift from what a fixture lookup\n  expects. Stanza-derived lists, remembered pairs, and register tables are all the roster problem at\n  different depths; only cargo's own enumeration is the population.\n- **Kin:** IR-55's amended prebuild bullet (prebuild the census, not a remembered pair) and IR-42\n  (a verb that writes without adjudicating). The shared shape is an instrument returning an orderly\n  answer about a set it never fully saw.\n- **Trigger condition:** ripe on any `xtask` check work — a duplicate-bin-name check over cargo's\n  target enumeration (NOT over manifest stanzas) is a handful of lines and cannot go stale.\n- **Size guess:** small. The prose fix originally proposed here is WITHDRAWN — there was nothing\n  wrong with the prose.\n\n### IR-59 — pool arithmetic: this box holds TWO cold pools, not four; and a build that exhausts the volume reds as a LINKER defect that names no disk\n\n- **Status:** OPEN, unowned — it is arithmetic and discipline, not a code lane. Filed by doyle\n  2026-08-22 from a live disk-floor abort during the TURNKEY #212 W4 gate; footprint figures measured\n  by todlando the same hour.\n- **SECOND FACE, measured 2026-08-23/24 (WAX-SEAL #21 W2 gate, doyle — the violator this time):**\n  both predicted mechanisms fired at once, WITHOUT the floor guard because the gate legs ran as a\n  plain script. (1) doyle minted a THIRD cold pool (gate rig) while todlando's lane pool was LIVE —\n  the two-pool arithmetic, violated by the gater. (2) The lane pool had silently accumulated\n  **104.8 GB** over repeated full-workspace sweeps (nothing bounds or even measures a pool's\n  accumulation until the volume dies). The volume hit **3 MB free**; the reds wore exactly the\n  entry's predicted costume — `LNK1318: Unexpected PDB error; LIMIT (12)` naming no disk — plus a\n  second face worth keeping: `traceable-reqs check` died as a PANIC printing to stdout\n  (`os error 112`), so a REGISTRY gate red can also be the disk's. Both gate verdicts VOIDED\n  (clippy's full compile had exited 0 before space died — the code was never the question).\n  Recovery measured: gate pool reap 9.6 GB, lane pool clean 100.2 GB, drive back to 109.6 GB free.\n  **Remedies adopted at the incident:** the gate never mints its own pool while a builder lane is\n  live on the box — it takes the lane pool over SEQUENTIALLY at pool-release (warm, loud, the\n  releases#103 pattern); and gate/lane scripts get the disk-floor preflight the golden runner\n  already carries (this entry's part 2, still unbuilt).\n- **THIRD FACE, measured 2026-08-24 (WAX-SEAL #21 golden window, doyle):** two new mechanisms, both\n  about the REMEDY rather than the red. (1) The wax-seal-w1 lane pool **re-accumulated to 152–169 GB\n  (two meters, IR-46 caveat) within ONE DAY of the 08-23 clean** and rode the volume back down to\n  4.92 GB free — a reap is an instant, not a state; nothing yet bounds a pool between reaps.\n  (2) **The remedy itself arrived garbled through relay:** the golden push was held \"waiting on the\n  IR-59 reboot\" when this entry prescribes no reboot anywhere — tens of releases have shipped without\n  one; the operator refused the premise and the register's own recorded remedy (reap finished-lane\n  pools) cleared it in ten minutes. A remedy relayed as a DIFFERENT remedy is the relay trap wearing\n  infra clothes: the entry is the author — read it before adopting a hold. Recovery measured: five\n  finished-lane pools reaped after ancestry classification (`git cherry` catches rebased lands that\n  a plain `merge-base --is-ancestor` calls unlanded — gate-w4l1's 90.9 GB pool was reapable only by\n  that meter), 4.92 → 260.88 GB free (~256 GB free-delta vs ~270–287 GB sum-of-lengths). Two main\n  runs red inside the low-disk window (09:17Z/09:41Z) were re-run, not re-read, per this entry's\n  must-do.\n- **FOURTH FACE, measured 2026-08-24 same day (SIGNET #218 W2 gate, doyle — the gater's own pool\n  this time):** the MAIN pool went **13.7 GB → 158.3 GB in ONE DAY** absorbing four full gate\n  batteries across two lane tips, and dragged the volume to **18 GB free mid-gate** — so the\n  entry's mechanism is not a lane-pool problem, it is EVERY pool under repeated full sweeps, the\n  gate rig included. Two riders worth the ink: (1) the golden runner's **free-space floor step\n  produced its first live catch** — a thin CI leg refused at 14:14 local over exactly this window\n  with zero test signal, and the register's re-run-not-re-read rule resolved it in one command;\n  (2) the reap-and-rebuild trade (\"cleaning a live pool buys one window at rebuild price\") was\n  taken deliberately mid-gate and cost ~35 minutes cold — cheaper than one uninterpretable red.\n  A red measured at 18 GB free in this gate got NO read at all, and the next sweep's red was a\n  DIFFERENT test: low disk manufactures random victims before it manufactures link errors.\n- **The event:** a gate's preflight refused with `GATE_ABORTED_DISK_FLOOR` at **4.75 GB free on a\n  1863 GB volume**. Four cold pools plus the milestone head's pool were standing at once. The floor\n  guard did its job — without it a full workspace build would have started with under 5 GB of\n  headroom and produced a red belonging to nothing.\n- **THE ARITHMETIC, and it corrects the intuition that worktrees are the cost.** Measured across the\n  whole `.worktrees` tree: **45 worktrees = 0.79 GB total** (~18 MB each). **3 pools = 130.45 GB.**\n  Worktrees are **0.6%** of the footprint; pools are **99.4%**. **One cold pool is worth roughly 2,500\n  worktrees.** A rule keyed on worktree count would cost a day of `git worktree remove` work for under\n  a gigabyte, risk removing a lane someone still wants, and leave the lever untouched.\n- **THE CEILING, as arithmetic rather than hygiene:** at **45–75 GB per cold pool** on this workspace\n  against a **40 GB floor**, this box supports **TWO live pools comfortably, THREE only if one is\n  small**. The two rules that already exist need no replacement, only this number attached:\n  - **Reap a pool when its lane is finished** → 45–75 GB back immediately.\n  - **Do not run two builds at once** → not only the contention argument, but **75–150 GB of\n    simultaneous allocation** against that floor.\n- **A FULL VOLUME REDS AS A LINKER DEFECT.** `LINK: fatal error LNK1318: Unexpected PDB error`\n  (variously `OK (0)` or `LIMIT (12)`), often beside `LNK4209: debugging information corrupt`. It\n  reads as a corrupt artifact or a broken toolchain and is neither — it is the linker unable to grow\n  a large `.pdb`. **Nothing in the failure text says \"disk\".** Do not key recognition on the\n  parenthesised code; it varies.\n- **THE DANGER WINDOW IS THE TAIL OF A COLD BUILD, not a steady state you can check once.** The\n  2026-08-22 instance died at the link of `spt` — the last and largest artifact of a **74 GB** cold\n  pool — while that same build was draining the volume out from under itself. A free-space reading\n  taken before the build would have looked fine.\n- **Positive tell, with its own refutation attached:** `traceable-reqs check` alone surviving a leg\n  table is suggestive, because it is the only leg that never links. It is a POSITIVE tell ONLY — a\n  full disk can red before any link step, so the signature's ABSENCE clears nothing.\n- **THE FALSIFIER IS FREE SPACE AT THE TIME OF THE RUN**, not the shape of the leg table.\n- **Must-do, both cheap:**\n  1. **A free-space reading goes in the FIRST LINE of any build-failure report** — not in the\n     controls, not as a follow-up. Two agents spent hours on a mechanism for this failure and neither\n     ran `df`; the falsifier was one command away throughout.\n  2. **Rig and gate logs should record free space at run start.** Today they do not, which makes \"was\n     the disk full\" **unanswerable after the fact for every red already in hand**. Any red produced\n     under ~1 GB free is UNINTERPRETABLE and must be **re-run, not re-read**.\n- **Measurement caveat, observed twice in one hour:** sum-of-file-lengths and free-space delta\n  disagree by several percent when anything else on the box is writing (98.07 GB of subtrees → 92.25\n  GB reclaimed; 47.28 GB → 40.81 GB). Report BOTH, derive neither from the other, and treat any single\n  free-space number as an instant rather than headroom — see IR-46.\n- **FIFTH FACE, measured 2026-08-29 at the CONDUIT #236/v0.65.0 cut (deployah):**\n  the finished milestone's sequential lane-sharing accumulated **140.51 GB**, while a freshly\n  rebuilt pool measured **7.78 GB** — about **18× one build's working set** retained across lane\n  hand-offs with no reap between them. This is the budgetable rate behind that cut's disk-floor\n  red: sequential execution prevents concurrent ownership corruption, but it does not bound\n  historical artifacts inside the shared pool. Treat takeover and reclamation as separate\n  operations; a pool may be safe to reuse and still be too large to keep.\n- **SEVENTH FACE, measured 2026-08-30 (v0.67.0 milestone close — the PARALLEL-LANE fill\n  rate):** the #23 wave arc drove C: from ~240 GB free to **0.01 GB in ~3.5 hours**: four\n  concurrent/serial lane+gate pools totalled **236.6 GB** (ns23-w1 87.7 + ns23-113 72.3 +\n  gate rig 57.3 + ns23-w3 19.1) — effectively the entire ir57 reclaim re-consumed inside one\n  milestone's build window. The head gate and two thin-CI runs redded with the entry's exact\n  costume (\"could not compile\" + treqs panic, zero disk words) at 0.01 GB and all re-earned\n  green after reclaim (+186.6 GB, finished-lane targets only, single-actor rule held under\n  racing consent). Budget rule this face adds: a MULTI-WAVE milestone on one box books\n  ~60-90 GB PER LANE-PLUS-GATE cycle, so the pool budget is per-wave, not per-milestone —\n  reap each wave's pool at its LAND, not at the milestone party (the party inherited only\n  ~58 GB because the emergency had already forced the other ~179).\n- **SIXTH FACE, measured 2026-08-30 (#242 golden r4, Windows test job, LNK1318 at the PDB\n  write):** the floor is asserted ONCE at job START, but the job's internal LOW-WATER sits at its\n  LAST heavy step — the docs-drift build, ~28 minutes in. r4's floor read 65.1 GiB honest at\n  23:07; the box was at ~37–39 GB by the 23:35 link failure. LNK1318 on PDB write = this entry's\n  documented low-disk costume; the incremental-corruption candidate was retired by preservation\n  snapshot (no xtask state existed at failure). **Durable fix = a floor RE-READ (or reclaim)\n  immediately before the docs-drift build** — the WITHIN-job sibling of the across-job\n  read-after-checkout fix, rides the next workflow commit. Riders: incremental hygiene as\n  disk-pressure maintenance (the dir measured 4.56 GB), and the box's **~51 GB non-recovering\n  post-run consumption** is this entry's pool-weight face — classify at the IR-14/26/27/49 audit\n  slot (composed this sweep).\n- **Composed for next intake (doyle, v0.65.0 close):** the still-open log-the-floor build half\n  rides with [[IR-57]]'s scripted pick-fidelity audit as the next milestone's two tooling riders.\n- **Trigger condition:** ripe now for the log-the-floor half (it rides any gate-script or CI touch);\n  the arithmetic is discipline and applies immediately.\n- **Size guess:** small — one line in each rig/gate preflight to record free space alongside the\n  existing floor check.\n\n### IR-60 — a wrapper that CAPTURES a leg's exit status ends with the capture, so the wrapper's own status is the capture's, not the leg's\n\n- **Status:** OPEN, unowned — script-shape discipline, not a code lane. Filed by doyle 2026-08-22\n  during the TURNKEY #212 W5 lane; mechanism measured by todlando, who reported it first as a\n  possible harness misreport and then RETRACTED that reading himself on a minimal probe.\n- **The reading that started it:** a background leg was summarised as `exit code 0` while the leg's\n  own exit file read `100`. Reported as-is, that is a task runner lying about a red — the worst\n  possible direction for a purposeful-red claim, since it would turn two reds that DID fire into two\n  reds reported as not having fired.\n- **The measurement, minimal and on this box:**\n\n      ( exit 100 ); echo $? > probe.exit; FINAL=$?\n      leg status captured to file : 100\n      wrapper's own final status  : 0\n\n  The wrapper's shape is `( cd <lane> && cargo nextest ... > leg.raw 2>&1 ); echo $? > leg.exit`.\n  **The last command is the `echo`, which succeeds**, so the wrapper genuinely exits 0 while the leg\n  genuinely exited 100. THE RUNNER TOLD THE TRUTH ABOUT THE WRAPPER. There is nothing to file against\n  the task runner, and it would have been filed.\n- **The class, and this is why it is worth an entry rather than a fix:** it is the truncation-pipe\n  family — the meter measured something real, it just was not the thing about to be quoted. **Three\n  shapes now share ONE trigger, and the trigger is not \"is this a pipe\":**\n  1. a truncation pipe (`cmd | tail`, `cmd | head`) — `$?` measures the truncator, and `head` closing\n     the pipe can MANUFACTURE a status (SIGPIPE → 101), so `PIPESTATUS` is not protection either;\n  2. a flattened `$?` read after any intervening command;\n  3. **a wrapper whose last command is the capture itself.**\n  **The trigger in all three is the REPORTING** — every instance happened while trimming or capturing\n  output in order to QUOTE it as evidence.\n- **The practice that held, and the one to keep:** the leg's own file is the leg's verdict. Both reds\n  were real, and the only reason that was knowable is that every leg wrote its exit to its own file\n  rather than to the wrapper's status.\n- **Remedy, in preference order:** (1) never read a wrapper's status as a leg's — read the leg's exit\n  FILE, which the per-leg rule already requires; (2) if a wrapper's own status must be meaningful,\n  end it by re-raising the captured status (`exit \"$(cat leg.exit)\"`) or set the status before the\n  capture is the last word; (3) for anything that becomes evidence, redirect to a file and read the\n  file.\n- **Trigger condition:** ripe now — it rides the next gate-script touch, and the gate scripts in this\n  milestone already write per-leg exit files, which is what makes this discipline rather than debt.\n- **Size guess:** small — a convention line in the gate-script preamble; no product code.\n\n### IR-61 — spacerun's test-module skip carries a SECOND literal tracker; the two answers can drift, and today only a cell stands between them\n\n- **Status:** OPEN, unowned, accepted-with-mitigation. Filed by doyle 2026-08-22 at the TURNKEY #212\n  head gate, as the named residual of the latch repair (the repair itself rides the milestone).\n- **What the debt is.** `crates/xtask/src/spacerun.rs` now skips a column-0 `#[cfg(test)]` module by\n  BRACE DEPTH and resumes after its close, rather than latching the scan to end-of-file. Counting\n  braces safely means knowing when a brace is inside a string, a raw string or a char literal — and\n  the scanner ALREADY tracks literals for its rendering pass. It does not reuse that tracking. There\n  are now TWO answers in one file to \"am I inside a literal\", and **two answers to one question is a\n  disagreement waiting for a reader who fixes one of them.**\n- **Why it was accepted rather than refactored on the spot, stated so the trade is auditable:** the\n  two trackers answer genuinely different questions — the rendering walk is PER LINE and forward\n  from an opening quote (\"where does this literal start and end\"), while the skip needs \"am I inside\n  a literal right now\" carried CONTINUOUSLY across lines. Unifying them is a real refactor of a check\n  that is already gated, already carries five fixed defects, and sits on the tree being handed to\n  golden. The narrow change with an OBSERVABLE failure mode beat the correct-shaped change with a\n  wide blast radius, on that tree, on that day.\n- **The mitigation, and its exact limit.** Three brace cells fail the moment the two trackers\n  disagree about a raw string, a normal string or a char literal, plus a cell that reds when the skip\n  stops consulting a literal tracker at all (`match lit` -> `match Lit::None`). **That is a cell\n  standing in for a refactor.** It catches drift in the three forms it names and nothing else — a\n  fourth literal form, or a change to only one tracker in a form neither cell covers, passes.\n- **The general shape, which is why this is a register entry rather than a comment:** a check whose\n  own correctness depends on a second implementation of a thing it already implements is one\n  refactor away from the defect class it exists to prevent. This same file has already produced\n  three instrument defects (an indented-marker latch, a column-0 latch, and a suppression that\n  decided what got PARSED rather than what got REPORTED). The pattern is not carelessness; it is a\n  scanner accumulating special cases.\n- **Trigger condition:** the next SUBSTANTIVE change to spacerun's scanning — any new skip, any new\n  literal form, any change to either tracker. At that point unify, rather than adding a third answer.\n- **Size guess:** small to medium — one continuous literal-state walk serving both the render pass\n  and the skip, with the existing corpus and brace cells as the regression net.\n\n### IR-62 — an e2e daemon binds well-known ports and collides with the resident fleet on shared runners\n\nFiled 2026-08-23 (doyle), from the #212 r2 golden's Windows Phase A red — one witnessed\ninstance, mechanism verified from the run's own capture, filed on the mechanism per the\nregister's standard.\n\n**Mechanism.** `endpoint_autostart_e2e::saved_endpoint_replays_on_daemon_restart` failed its\nown PRECONDITION (\"daemon B must come up with a fresh brain\") because daemon B's broker came up\ndegraded: `NODE_KEY_FAIL: identity unavailable` (net-less broker, no retry) and\n`DOCS_SERVER_BIND_FAIL` port 5474 `os error 10048` — the docs port was held by a CO-RESIDENT\ndaemon. HFENDULEAM is live infra: the resident fleet's daemon legitimately holds well-known\nports, and any e2e that brings up a daemon with default port bindings is in a race with it BY\nCONSTRUCTION. An isolated SPT_HOME isolates the store and broker socket, NOT globally-numbered\nTCP ports.\n\n**Classification history.** r2: red (35.4s, precondition panic). Run 1 and r3 on the same box:\ngreen. Folded into r3 under a pre-registered predicate (reds twice → dedicated triage); it\ngreened, so this stays an environment-shaped intermittent, NOT a product defect and NOT\nclosed — the collision window is real and will re-fire under the right co-residence timing.\n\n**Remedy direction (not built).** Test daemons should bind ephemeral/rig-scoped ports for\nevery advisory surface (the docs server is advisory — a bind failure should degrade the rig\nloudly, not poison an unrelated cell's precondition), or the precondition should name the\nport-collision cause distinctly so the red self-classifies. Either lane is test/CI work\n(hertz's), triggered the next time this class fires anywhere.\n\n**Kin.** IR-51 (e2e daemon net-enabled on real interfaces — hermeticity is disk-deep only);\nthe known not-ours red classes list in the #212 hand-off.\n\n**BUILT 2026-08-24 (hertz, SIGNET #218 batch; PR #158).** The class fired its second witnessed\ninstance the same day — doyle's W2 gate rig, `engine_room_bringup_e2e` precondition panic with\nthe IR-50 panel naming `DOCS_SERVER_BIND_FAIL` port 5474 `os error 10048` — which armed this\nentry's own trigger. Hertz repro'd deterministically (held the port; brain still reached\nBRAIN_UP), pre-ranked three mechanisms before probing, and built the ephemeral-advisory form:\nrig-only `SPT_TEST_EPHEMERAL_ADVISORY_PORTS=1` makes the daemon's docs listener bind port 0\n(production config/`SPT_DOCS_PORT`/docs-url untouched; the flag matches the literal \"1\" only).\nThe golden workflow's test job sets it globally on both self-hosted legs, the standalone ER rig\nsets it too. Scope note kept honest per his own ranking: the docs collision is retired; if a\nco-diagnostic bind elsewhere still poisons a precondition, that is a residual face of THIS\nentry, not a closed question.\n\n### IR-63 — suite-mix sweeps leak job-escaped autostart daemons that LOCK the pool's spt.exe; and the same box conditions manufacture one random victim per sweep\n\n- **Status:** OPEN, mitigated-by-rig-step — the reap is adopted discipline, not yet construction.\n  Filed by doyle 2026-08-24 at the SIGNET #218 gates; first measured by todlando the same day\n  (his W1 build: four reap rounds of 2, 8, 1, 1 processes, count-by-path stated each round).\n- **Mechanism, two faces of one condition:** (1) e2e sweeps that exercise autostart leave\n  job-escaped daemons running `target/debug/spt.exe`; the NEXT build or `xtask check` then dies\n  on `os error 5` removing the exe — a rig red wearing a build defect's clothes. nextest's own\n  `leaky` flags corroborate (4–8 per sweep measured). (2) The same co-residence (leaked daemons +\n  resident fleet + runner traffic) manufactures ONE red per full sweep with a DIFFERENT victim\n  each time: doyle's W2 gate measured FOUR distinct one-off victims in four same-sha sweeps\n  (ER bringup, composite+bootstrap pair under CI load, resident_service, brain_resume), every\n  one green alone and/or in a sibling sweep. The e2e-leaked-daemons rule holds: a different test\n  dying each run on one sha is ONE environment cause, and hardening members never closes it.\n- **Mitigation adopted (rig step, both todlando's lanes and doyle's gate runner):** reap\n  `spt.exe` BY PATH (`*spt-core\\target*`) before EVERY cargo invocation and after every sweep;\n  report the count each time so a zero is a claim, not silence.\n- **Remedy direction (unbuilt):** the durable form is construction, not discipline — either\n\n[Showing lines 3158-3457 of 5782. Use :3458 to continue]"}],"details":{"truncation":{"content":"  pick-audit --range 57a0d27c..HEAD --lane 4d6007ac..d0fdd58d` over 6 picks — **5 MATCH\r\n  (digest-identical), 1 LOSS, 0 drift, 0 unclassified**, exit 1 forcing the accounting. The LOSS\r\n  was exactly the one human-resolved conflict (`cfb9d9f8 <- 10f12e4c`, count 432/402), and the\r\n  delta RECONCILED to the resolution rather than assumed: lane stat 15 files/235+/197- vs pick\r\n  14 files/205+/197-, difference byte-for-byte the deliberately-dropped 30-line interim IR-69\r\n  register block superseded by main's consolidated entry. No false positives, no silent pass.\r\n  Entry stays OPEN as living procedure; both live uses (the rebase catch above, this assembly)\r\n  produced the verdict classes in the order the entry predicts.\r\n- **Trigger condition:** ripe at the next assembly — this is procedure, and its cost is one command\r\n  per pick.\r\n- **Size guess:** small as a scripted check in `xtask` (fidelity audit over a pick range); zero as\r\n  discipline, which is how it is being applied now.\r\n\r\n### IR-58 — a `[[bin]]` grep is not a census: cargo AUTODISCOVERS `src/bin/*.rs` targets, and a hand-built bin list produced a confident false \"this bin does not exist\"\r\n\r\n- **Status:** OPEN, unowned. Filed by doyle 2026-08-22; **its original filing was WRONG and is\r\n  retracted in full below.** The entry is kept because the way it was wrong is the finding.\r\n- **RETRACTED CLAIM, stated plainly so no reader acts on it:** this entry first said that\r\n  `crates/spt/Cargo.toml:18-21` and `crates/spt/src/cli.rs:30355` forbid a bin-name collision with\r\n  `xlate_choreo_fixture`, \"a bin that does not exist\", and that spt-daemon's third helper had been\r\n  renamed to `summarizer_fixture`. **`xlate_choreo_fixture` EXISTS** — at\r\n  `crates/spt-daemon/src/bin/xlate_choreo_fixture.rs`, verified at the assembly head. The collision\r\n  rule's counterpart is real, both prose sites are CORRECT, and IR-21's original table row was\r\n  correct too; it merely predated `summarizer_fixture`. Nothing in that prose needs fixing.\r\n- **How the false claim was produced, which is the entry:** the census was built by grepping\r\n  `^\\[\\[bin\\]\\]` across `Cargo.toml`s. **Cargo AUTODISCOVERS `src/bin/*.rs` as bin targets with no\r\n  stanza at all**, so a stanza grep cannot see them, and it fails SILENTLY — it returns a clean,\r\n  well-formed list that is simply short. From that list it read as established fact that a named bin\r\n  had been renamed away, and that \"fact\" was then written into a register table, an IR entry, and a\r\n  message to the builder. **A pattern-built population encodes the pattern's assumption; the count\r\n  looks like a census and is a property of the pattern.**\r\n  (Found by todlando, resolving one of doyle's figures against his own tree under the pointer rule.)\r\n- **A CENSUS IS ALSO A PROPERTY OF A TREE.** Stanza counts differed legitimately across trees the\r\n  same hour — 13 at the assembly head, 11 at `dc1c7532` — because `summarizer_fixture` exists at one\r\n  and not the other. Two correct censuses of the same workspace disagree unless each names its sha.\r\n- **The must-do, and it removes the list rather than lengthening it:** never hand-maintain a bin\r\n  roster. Run `cargo build --workspace --bins` and let cargo enumerate its own targets — the same\r\n  enumeration the test harness resolves against, so it cannot drift from what a fixture lookup\r\n  expects. Stanza-derived lists, remembered pairs, and register tables are all the roster problem at\r\n  different depths; only cargo's own enumeration is the population.\r\n- **Kin:** IR-55's amended prebuild bullet (prebuild the census, not a remembered pair) and IR-42\r\n  (a verb that writes without adjudicating). The shared shape is an instrument returning an orderly\r\n  answer about a set it never fully saw.\r\n- **Trigger condition:** ripe on any `xtask` check work — a duplicate-bin-name check over cargo's\r\n  target enumeration (NOT over manifest stanzas) is a handful of lines and cannot go stale.\r\n- **Size guess:** small. The prose fix originally proposed here is WITHDRAWN — there was nothing\r\n  wrong with the prose.\r\n\r\n### IR-59 — pool arithmetic: this box holds TWO cold pools, not four; and a build that exhausts the volume reds as a LINKER defect that names no disk\r\n\r\n- **Status:** OPEN, unowned — it is arithmetic and discipline, not a code lane. Filed by doyle\r\n  2026-08-22 from a live disk-floor abort during the TURNKEY #212 W4 gate; footprint figures measured\r\n  by todlando the same hour.\r\n- **SECOND FACE, measured 2026-08-23/24 (WAX-SEAL #21 W2 gate, doyle — the violator this time):**\r\n  both predicted mechanisms fired at once, WITHOUT the floor guard because the gate legs ran as a\r\n  plain script. (1) doyle minted a THIRD cold pool (gate rig) while todlando's lane pool was LIVE —\r\n  the two-pool arithmetic, violated by the gater. (2) The lane pool had silently accumulated\r\n  **104.8 GB** over repeated full-workspace sweeps (nothing bounds or even measures a pool's\r\n  accumulation until the volume dies). The volume hit **3 MB free**; the reds wore exactly the\r\n  entry's predicted costume — `LNK1318: Unexpected PDB error; LIMIT (12)` naming no disk — plus a\r\n  second face worth keeping: `traceable-reqs check` died as a PANIC printing to stdout\r\n  (`os error 112`), so a REGISTRY gate red can also be the disk's. Both gate verdicts VOIDED\r\n  (clippy's full compile had exited 0 before space died — the code was never the question).\r\n  Recovery measured: gate pool reap 9.6 GB, lane pool clean 100.2 GB, drive back to 109.6 GB free.\r\n  **Remedies adopted at the incident:** the gate never mints its own pool while a builder lane is\r\n  live on the box — it takes the lane pool over SEQUENTIALLY at pool-release (warm, loud, the\r\n  releases#103 pattern); and gate/lane scripts get the disk-floor preflight the golden runner\r\n  already carries (this entry's part 2, still unbuilt).\r\n- **THIRD FACE, measured 2026-08-24 (WAX-SEAL #21 golden window, doyle):** two new mechanisms, both\r\n  about the REMEDY rather than the red. (1) The wax-seal-w1 lane pool **re-accumulated to 152–169 GB\r\n  (two meters, IR-46 caveat) within ONE DAY of the 08-23 clean** and rode the volume back down to\r\n  4.92 GB free — a reap is an instant, not a state; nothing yet bounds a pool between reaps.\r\n  (2) **The remedy itself arrived garbled through relay:** the golden push was held \"waiting on the\r\n  IR-59 reboot\" when this entry prescribes no reboot anywhere — tens of releases have shipped without\r\n  one; the operator refused the premise and the register's own recorded remedy (reap finished-lane\r\n  pools) cleared it in ten minutes. A remedy relayed as a DIFFERENT remedy is the relay trap wearing\r\n  infra clothes: the entry is the author — read it before adopting a hold. Recovery measured: five\r\n  finished-lane pools reaped after ancestry classification (`git cherry` catches rebased lands that\r\n  a plain `merge-base --is-ancestor` calls unlanded — gate-w4l1's 90.9 GB pool was reapable only by\r\n  that meter), 4.92 → 260.88 GB free (~256 GB free-delta vs ~270–287 GB sum-of-lengths). Two main\r\n  runs red inside the low-disk window (09:17Z/09:41Z) were re-run, not re-read, per this entry's\r\n  must-do.\r\n- **FOURTH FACE, measured 2026-08-24 same day (SIGNET #218 W2 gate, doyle — the gater's own pool\r\n  this time):** the MAIN pool went **13.7 GB → 158.3 GB in ONE DAY** absorbing four full gate\r\n  batteries across two lane tips, and dragged the volume to **18 GB free mid-gate** — so the\r\n  entry's mechanism is not a lane-pool problem, it is EVERY pool under repeated full sweeps, the\r\n  gate rig included. Two riders worth the ink: (1) the golden runner's **free-space floor step\r\n  produced its first live catch** — a thin CI leg refused at 14:14 local over exactly this window\r\n  with zero test signal, and the register's re-run-not-re-read rule resolved it in one command;\r\n  (2) the reap-and-rebuild trade (\"cleaning a live pool buys one window at rebuild price\") was\r\n  taken deliberately mid-gate and cost ~35 minutes cold — cheaper than one uninterpretable red.\r\n  A red measured at 18 GB free in this gate got NO read at all, and the next sweep's red was a\r\n  DIFFERENT test: low disk manufactures random victims before it manufactures link errors.\r\n- **The event:** a gate's preflight refused with `GATE_ABORTED_DISK_FLOOR` at **4.75 GB free on a\r\n  1863 GB volume**. Four cold pools plus the milestone head's pool were standing at once. The floor\r\n  guard did its job — without it a full workspace build would have started with under 5 GB of\r\n  headroom and produced a red belonging to nothing.\r\n- **THE ARITHMETIC, and it corrects the intuition that worktrees are the cost.** Measured across the\r\n  whole `.worktrees` tree: **45 worktrees = 0.79 GB total** (~18 MB each). **3 pools = 130.45 GB.**\r\n  Worktrees are **0.6%** of the footprint; pools are **99.4%**. **One cold pool is worth roughly 2,500\r\n  worktrees.** A rule keyed on worktree count would cost a day of `git worktree remove` work for under\r\n  a gigabyte, risk removing a lane someone still wants, and leave the lever untouched.\r\n- **THE CEILING, as arithmetic rather than hygiene:** at **45–75 GB per cold pool** on this workspace\r\n  against a **40 GB floor**, this box supports **TWO live pools comfortably, THREE only if one is\r\n  small**. The two rules that already exist need no replacement, only this number attached:\r\n  - **Reap a pool when its lane is finished** → 45–75 GB back immediately.\r\n  - **Do not run two builds at once** → not only the contention argument, but **75–150 GB of\r\n    simultaneous allocation** against that floor.\r\n- **A FULL VOLUME REDS AS A LINKER DEFECT.** `LINK: fatal error LNK1318: Unexpected PDB error`\r\n  (variously `OK (0)` or `LIMIT (12)`), often beside `LNK4209: debugging information corrupt`. It\r\n  reads as a corrupt artifact or a broken toolchain and is neither — it is the linker unable to grow\r\n  a large `.pdb`. **Nothing in the failure text says \"disk\".** Do not key recognition on the\r\n  parenthesised code; it varies.\r\n- **THE DANGER WINDOW IS THE TAIL OF A COLD BUILD, not a steady state you can check once.** The\r\n  2026-08-22 instance died at the link of `spt` — the last and largest artifact of a **74 GB** cold\r\n  pool — while that same build was draining the volume out from under itself. A free-space reading\r\n  taken before the build would have looked fine.\r\n- **Positive tell, with its own refutation attached:** `traceable-reqs check` alone surviving a leg\r\n  table is suggestive, because it is the only leg that never links. It is a POSITIVE tell ONLY — a\r\n  full disk can red before any link step, so the signature's ABSENCE clears nothing.\r\n- **THE FALSIFIER IS FREE SPACE AT THE TIME OF THE RUN**, not the shape of the leg table.\r\n- **Must-do, both cheap:**\r\n  1. **A free-space reading goes in the FIRST LINE of any build-failure report** — not in the\r\n     controls, not as a follow-up. Two agents spent hours on a mechanism for this failure and neither\r\n     ran `df`; the falsifier was one command away throughout.\r\n  2. **Rig and gate logs should record free space at run start.** Today they do not, which makes \"was\r\n     the disk full\" **unanswerable after the fact for every red already in hand**. Any red produced\r\n     under ~1 GB free is UNINTERPRETABLE and must be **re-run, not re-read**.\r\n- **Measurement caveat, observed twice in one hour:** sum-of-file-lengths and free-space delta\r\n  disagree by several percent when anything else on the box is writing (98.07 GB of subtrees → 92.25\r\n  GB reclaimed; 47.28 GB → 40.81 GB). Report BOTH, derive neither from the other, and treat any single\r\n  free-space number as an instant rather than headroom — see IR-46.\r\n- **FIFTH FACE, measured 2026-08-29 at the CONDUIT #236/v0.65.0 cut (deployah):**\r\n  the finished milestone's sequential lane-sharing accumulated **140.51 GB**, while a freshly\r\n  rebuilt pool measured **7.78 GB** — about **18× one build's working set** retained across lane\r\n  hand-offs with no reap between them. This is the budgetable rate behind that cut's disk-floor\r\n  red: sequential execution prevents concurrent ownership corruption, but it does not bound\r\n  historical artifacts inside the shared pool. Treat takeover and reclamation as separate\r\n  operations; a pool may be safe to reuse and still be too large to keep.\r\n- **SEVENTH FACE, measured 2026-08-30 (v0.67.0 milestone close — the PARALLEL-LANE fill\r\n  rate):** the #23 wave arc drove C: from ~240 GB free to **0.01 GB in ~3.5 hours**: four\r\n  concurrent/serial lane+gate pools totalled **236.6 GB** (ns23-w1 87.7 + ns23-113 72.3 +\r\n  gate rig 57.3 + ns23-w3 19.1) — effectively the entire ir57 reclaim re-consumed inside one\r\n  milestone's build window. The head gate and two thin-CI runs redded with the entry's exact\r\n  costume (\"could not compile\" + treqs panic, zero disk words) at 0.01 GB and all re-earned\r\n  green after reclaim (+186.6 GB, finished-lane targets only, single-actor rule held under\r\n  racing consent). Budget rule this face adds: a MULTI-WAVE milestone on one box books\r\n  ~60-90 GB PER LANE-PLUS-GATE cycle, so the pool budget is per-wave, not per-milestone —\r\n  reap each wave's pool at its LAND, not at the milestone party (the party inherited only\r\n  ~58 GB because the emergency had already forced the other ~179).\r\n- **SIXTH FACE, measured 2026-08-30 (#242 golden r4, Windows test job, LNK1318 at the PDB\r\n  write):** the floor is asserted ONCE at job START, but the job's internal LOW-WATER sits at its\r\n  LAST heavy step — the docs-drift build, ~28 minutes in. r4's floor read 65.1 GiB honest at\r\n  23:07; the box was at ~37–39 GB by the 23:35 link failure. LNK1318 on PDB write = this entry's\r\n  documented low-disk costume; the incremental-corruption candidate was retired by preservation\r\n  snapshot (no xtask state existed at failure). **Durable fix = a floor RE-READ (or reclaim)\r\n  immediately before the docs-drift build** — the WITHIN-job sibling of the across-job\r\n  read-after-checkout fix, rides the next workflow commit. Riders: incremental hygiene as\r\n  disk-pressure maintenance (the dir measured 4.56 GB), and the box's **~51 GB non-recovering\r\n  post-run consumption** is this entry's pool-weight face — classify at the IR-14/26/27/49 audit\r\n  slot (composed this sweep).\r\n- **Composed for next intake (doyle, v0.65.0 close):** the still-open log-the-floor build half\r\n  rides with [[IR-57]]'s scripted pick-fidelity audit as the next milestone's two tooling riders.\r\n- **Trigger condition:** ripe now for the log-the-floor half (it rides any gate-script or CI touch);\r\n  the arithmetic is discipline and applies immediately.\r\n- **Size guess:** small — one line in each rig/gate preflight to record free space alongside the\r\n  existing floor check.\r\n\r\n### IR-60 — a wrapper that CAPTURES a leg's exit status ends with the capture, so the wrapper's own status is the capture's, not the leg's\r\n\r\n- **Status:** OPEN, unowned — script-shape discipline, not a code lane. Filed by doyle 2026-08-22\r\n  during the TURNKEY #212 W5 lane; mechanism measured by todlando, who reported it first as a\r\n  possible harness misreport and then RETRACTED that reading himself on a minimal probe.\r\n- **The reading that started it:** a background leg was summarised as `exit code 0` while the leg's\r\n  own exit file read `100`. Reported as-is, that is a task runner lying about a red — the worst\r\n  possible direction for a purposeful-red claim, since it would turn two reds that DID fire into two\r\n  reds reported as not having fired.\r\n- **The measurement, minimal and on this box:**\r\n\r\n      ( exit 100 ); echo $? > probe.exit; FINAL=$?\r\n      leg status captured to file : 100\r\n      wrapper's own final status  : 0\r\n\r\n  The wrapper's shape is `( cd <lane> && cargo nextest ... > leg.raw 2>&1 ); echo $? > leg.exit`.\r\n  **The last command is the `echo`, which succeeds**, so the wrapper genuinely exits 0 while the leg\r\n  genuinely exited 100. THE RUNNER TOLD THE TRUTH ABOUT THE WRAPPER. There is nothing to file against\r\n  the task runner, and it would have been filed.\r\n- **The class, and this is why it is worth an entry rather than a fix:** it is the truncation-pipe\r\n  family — the meter measured something real, it just was not the thing about to be quoted. **Three\r\n  shapes now share ONE trigger, and the trigger is not \"is this a pipe\":**\r\n  1. a truncation pipe (`cmd | tail`, `cmd | head`) — `$?` measures the truncator, and `head` closing\r\n     the pipe can MANUFACTURE a status (SIGPIPE → 101), so `PIPESTATUS` is not protection either;\r\n  2. a flattened `$?` read after any intervening command;\r\n  3. **a wrapper whose last command is the capture itself.**\r\n  **The trigger in all three is the REPORTING** — every instance happened while trimming or capturing\r\n  output in order to QUOTE it as evidence.\r\n- **The practice that held, and the one to keep:** the leg's own file is the leg's verdict. Both reds\r\n  were real, and the only reason that was knowable is that every leg wrote its exit to its own file\r\n  rather than to the wrapper's status.\r\n- **Remedy, in preference order:** (1) never read a wrapper's status as a leg's — read the leg's exit\r\n  FILE, which the per-leg rule already requires; (2) if a wrapper's own status must be meaningful,\r\n  end it by re-raising the captured status (`exit \"$(cat leg.exit)\"`) or set the status before the\r\n  capture is the last word; (3) for anything that becomes evidence, redirect to a file and read the\r\n  file.\r\n- **Trigger condition:** ripe now — it rides the next gate-script touch, and the gate scripts in this\r\n  milestone already write per-leg exit files, which is what makes this discipline rather than debt.\r\n- **Size guess:** small — a convention line in the gate-script preamble; no product code.\r\n\r\n### IR-61 — spacerun's test-module skip carries a SECOND literal tracker; the two answers can drift, and today only a cell stands between them\r\n\r\n- **Status:** OPEN, unowned, accepted-with-mitigation. Filed by doyle 2026-08-22 at the TURNKEY #212\r\n  head gate, as the named residual of the latch repair (the repair itself rides the milestone).\r\n- **What the debt is.** `crates/xtask/src/spacerun.rs` now skips a column-0 `#[cfg(test)]` module by\r\n  BRACE DEPTH and resumes after its close, rather than latching the scan to end-of-file. Counting\r\n  braces safely means knowing when a brace is inside a string, a raw string or a char literal — and\r\n  the scanner ALREADY tracks literals for its rendering pass. It does not reuse that tracking. There\r\n  are now TWO answers in one file to \"am I inside a literal\", and **two answers to one question is a\r\n  disagreement waiting for a reader who fixes one of them.**\r\n- **Why it was accepted rather than refactored on the spot, stated so the trade is auditable:** the\r\n  two trackers answer genuinely different questions — the rendering walk is PER LINE and forward\r\n  from an opening quote (\"where does this literal start and end\"), while the skip needs \"am I inside\r\n  a literal right now\" carried CONTINUOUSLY across lines. Unifying them is a real refactor of a check\r\n  that is already gated, already carries five fixed defects, and sits on the tree being handed to\r\n  golden. The narrow change with an OBSERVABLE failure mode beat the correct-shaped change with a\r\n  wide blast radius, on that tree, on that day.\r\n- **The mitigation, and its exact limit.** Three brace cells fail the moment the two trackers\r\n  disagree about a raw string, a normal string or a char literal, plus a cell that reds when the skip\r\n  stops consulting a literal tracker at all (`match lit` -> `match Lit::None`). **That is a cell\r\n  standing in for a refactor.** It catches drift in the three forms it names and nothing else — a\r\n  fourth literal form, or a change to only one tracker in a form neither cell covers, passes.\r\n- **The general shape, which is why this is a register entry rather than a comment:** a check whose\r\n  own correctness depends on a second implementation of a thing it already implements is one\r\n  refactor away from the defect class it exists to prevent. This same file has already produced\r\n  three instrument defects (an indented-marker latch, a column-0 latch, and a suppression that\r\n  decided what got PARSED rather than what got REPORTED). The pattern is not carelessness; it is a\r\n  scanner accumulating special cases.\r\n- **Trigger condition:** the next SUBSTANTIVE change to spacerun's scanning — any new skip, any new\r\n  literal form, any change to either tracker. At that point unify, rather than adding a third answer.\r\n- **Size guess:** small to medium — one continuous literal-state walk serving both the render pass\r\n  and the skip, with the existing corpus and brace cells as the regression net.\r\n\r\n### IR-62 — an e2e daemon binds well-known ports and collides with the resident fleet on shared runners\r\n\r\nFiled 2026-08-23 (doyle), from the #212 r2 golden's Windows Phase A red — one witnessed\r\ninstance, mechanism verified from the run's own capture, filed on the mechanism per the\r\nregister's standard.\r\n\r\n**Mechanism.** `endpoint_autostart_e2e::saved_endpoint_replays_on_daemon_restart` failed its\r\nown PRECONDITION (\"daemon B must come up with a fresh brain\") because daemon B's broker came up\r\ndegraded: `NODE_KEY_FAIL: identity unavailable` (net-less broker, no retry) and\r\n`DOCS_SERVER_BIND_FAIL` port 5474 `os error 10048` — the docs port was held by a CO-RESIDENT\r\ndaemon. HFENDULEAM is live infra: the resident fleet's daemon legitimately holds well-known\r\nports, and any e2e that brings up a daemon with default port bindings is in a race with it BY\r\nCONSTRUCTION. An isolated SPT_HOME isolates the store and broker socket, NOT globally-numbered\r\nTCP ports.\r\n\r\n**Classification history.** r2: red (35.4s, precondition panic). Run 1 and r3 on the same box:\r\ngreen. Folded into r3 under a pre-registered predicate (reds twice → dedicated triage); it\r\ngreened, so this stays an environment-shaped intermittent, NOT a product defect and NOT\r\nclosed — the collision window is real and will re-fire under the right co-residence timing.\r\n\r\n**Remedy direction (not built).** Test daemons should bind ephemeral/rig-scoped ports for\r\nevery advisory surface (the docs server is advisory — a bind failure should degrade the rig\r\nloudly, not poison an unrelated cell's precondition), or the precondition should name the\r\nport-collision cause distinctly so the red self-classifies. Either lane is test/CI work\r\n(hertz's), triggered the next time this class fires anywhere.\r\n\r\n**Kin.** IR-51 (e2e daemon net-enabled on real interfaces — hermeticity is disk-deep only);\r\nthe known not-ours red classes list in the #212 hand-off.\r\n\r\n**BUILT 2026-08-24 (hertz, SIGNET #218 batch; PR #158).** The class fired its second witnessed\r\ninstance the same day — doyle's W2 gate rig, `engine_room_bringup_e2e` precondition panic with\r\nthe IR-50 panel naming `DOCS_SERVER_BIND_FAIL` port 5474 `os error 10048` — which armed this\r\nentry's own trigger. Hertz repro'd deterministically (held the port; brain still reached\r\nBRAIN_UP), pre-ranked three mechanisms before probing, and built the ephemeral-advisory form:\r\nrig-only `SPT_TEST_EPHEMERAL_ADVISORY_PORTS=1` makes the daemon's docs listener bind port 0\r\n(production config/`SPT_DOCS_PORT`/docs-url untouched; the flag matches the literal \"1\" only).\r\nThe golden workflow's test job sets it globally on both self-hosted legs, the standalone ER rig\r\nsets it too. Scope note kept honest per his own ranking: the docs collision is retired; if a\r\nco-diagnostic bind elsewhere still poisons a precondition, that is a residual face of THIS\r\nentry, not a closed question.\r\n\r\n### IR-63 — suite-mix sweeps leak job-escaped autostart daemons that LOCK the pool's spt.exe; and the same box conditions manufacture one random victim per sweep\r\n\r\n- **Status:** OPEN, mitigated-by-rig-step — the reap is adopted discipline, not yet construction.\r\n  Filed by doyle 2026-08-24 at the SIGNET #218 gates; first measured by todlando the same day\r\n  (his W1 build: four reap rounds of 2, 8, 1, 1 processes, count-by-path stated each round).\r\n- **Mechanism, two faces of one condition:** (1) e2e sweeps that exercise autostart leave\r\n  job-escaped daemons running `target/debug/spt.exe`; the NEXT build or `xtask check` then dies\r\n  on `os error 5` removing the exe — a rig red wearing a build defect's clothes. nextest's own\r\n  `leaky` flags corroborate (4–8 per sweep measured). (2) The same co-residence (leaked daemons +\r\n  resident fleet + runner traffic) manufactures ONE red per full sweep with a DIFFERENT victim\r\n  each time: doyle's W2 gate measured FOUR distinct one-off victims in four same-sha sweeps\r\n  (ER bringup, composite+bootstrap pair under CI load, resident_service, brain_resume), every\r\n  one green alone and/or in a sibling sweep. The e2e-leaked-daemons rule holds: a different test\r\n  dying each run on one sha is ONE environment cause, and hardening members never closes it.\r\n- **Mitigation adopted (rig step, both todlando's lanes and doyle's gate runner):** reap\r\n  `spt.exe` BY PATH (`*spt-core\\target*`) before EVERY cargo invocation and after every sweep;\r\n  report the count each time so a zero is a claim, not silence.\r\n- **Remedy direction (unbuilt):** the durable form is construction, not discipline — either\r","truncated":true,"truncatedBy":"lines","totalLines":2625,"totalBytes":25477,"outputLines":300,"outputBytes":25477,"lastLinePartial":false,"firstLineExceedsLimit":false},"totalLines":5782,"displayContent":{"text":"  pick-audit --range 57a0d27c..HEAD --lane 4d6007ac..d0fdd58d` over 6 picks — **5 MATCH\r\n  (digest-identical), 1 LOSS, 0 drift, 0 unclassified**, exit 1 forcing the accounting. The LOSS\r\n  was exactly the one human-resolved conflict (`cfb9d9f8 <- 10f12e4c`, count 432/402), and the\r\n  delta RECONCILED to the resolution rather than assumed: lane stat 15 files/235+/197- vs pick\r\n  14 files/205+/197-, difference byte-for-byte the deliberately-dropped 30-line interim IR-69\r\n  register block superseded by main's consolidated entry. No false positives, no silent pass.\r\n  Entry stays OPEN as living procedure; both live uses (the rebase catch above, this assembly)\r\n  produced the verdict classes in the order the entry predicts.\r\n- **Trigger condition:** ripe at the next assembly — this is procedure, and its cost is one command\r\n  per pick.\r\n- **Size guess:** small as a scripted check in `xtask` (fidelity audit over a pick range); zero as\r\n  discipline, which is how it is being applied now.\r\n\r\n### IR-58 — a `[[bin]]` grep is not a census: cargo AUTODISCOVERS `src/bin/*.rs` targets, and a hand-built bin list produced a confident false \"this bin does not exist\"\r\n\r\n- **Status:** OPEN, unowned. Filed by doyle 2026-08-22; **its original filing was WRONG and is\r\n  retracted in full below.** The entry is kept because the way it was wrong is the finding.\r\n- **RETRACTED CLAIM, stated plainly so no reader acts on it:** this entry first said that\r\n  `crates/spt/Cargo.toml:18-21` and `crates/spt/src/cli.rs:30355` forbid a bin-name collision with\r\n  `xlate_choreo_fixture`, \"a bin that does not exist\", and that spt-daemon's third helper had been\r\n  renamed to `summarizer_fixture`. **`xlate_choreo_fixture` EXISTS** — at\r\n  `crates/spt-daemon/src/bin/xlate_choreo_fixture.rs`, verified at the assembly head. The collision\r\n  rule's counterpart is real, both prose sites are CORRECT, and IR-21's original table row was\r\n  correct too; it merely predated `summarizer_fixture`. Nothing in that prose needs fixing.\r\n- **How the false claim was produced, which is the entry:** the census was built by grepping\r\n  `^\\[\\[bin\\]\\]` across `Cargo.toml`s. **Cargo AUTODISCOVERS `src/bin/*.rs` as bin targets with no\r\n  stanza at all**, so a stanza grep cannot see them, and it fails SILENTLY — it returns a clean,\r\n  well-formed list that is simply short. From that list it read as established fact that a named bin\r\n  had been renamed away, and that \"fact\" was then written into a register table, an IR entry, and a\r\n  message to the builder. **A pattern-built population encodes the pattern's assumption; the count\r\n  looks like a census and is a property of the pattern.**\r\n  (Found by todlando, resolving one of doyle's figures against his own tree under the pointer rule.)\r\n- **A CENSUS IS ALSO A PROPERTY OF A TREE.** Stanza counts differed legitimately across trees the\r\n  same hour — 13 at the assembly head, 11 at `dc1c7532` — because `summarizer_fixture` exists at one\r\n  and not the other. Two correct censuses of the same workspace disagree unless each names its sha.\r\n- **The must-do, and it removes the list rather than lengthening it:** never hand-maintain a bin\r\n  roster. Run `cargo build --workspace --bins` and let cargo enumerate its own targets — the same\r\n  enumeration the test harness resolves against, so it cannot drift from what a fixture lookup\r\n  expects. Stanza-derived lists, remembered pairs, and register tables are all the roster problem at\r\n  different depths; only cargo's own enumeration is the population.\r\n- **Kin:** IR-55's amended prebuild bullet (prebuild the census, not a remembered pair) and IR-42\r\n  (a verb that writes without adjudicating). The shared shape is an instrument returning an orderly\r\n  answer about a set it never fully saw.\r\n- **Trigger condition:** ripe on any `xtask` check work — a duplicate-bin-name check over cargo's\r\n  target enumeration (NOT over manifest stanzas) is a handful of lines and cannot go stale.\r\n- **Size guess:** small. The prose fix originally proposed here is WITHDRAWN — there was nothing\r\n  wrong with the prose.\r\n\r\n### IR-59 — pool arithmetic: this box holds TWO cold pools, not four; and a build that exhausts the volume reds as a LINKER defect that names no disk\r\n\r\n- **Status:** OPEN, unowned — it is arithmetic and discipline, not a code lane. Filed by doyle\r\n  2026-08-22 from a live disk-floor abort during the TURNKEY #212 W4 gate; footprint figures measured\r\n  by todlando the same hour.\r\n- **SECOND FACE, measured 2026-08-23/24 (WAX-SEAL #21 W2 gate, doyle — the violator this time):**\r\n  both predicted mechanisms fired at once, WITHOUT the floor guard because the gate legs ran as a\r\n  plain script. (1) doyle minted a THIRD cold pool (gate rig) while todlando's lane pool was LIVE —\r\n  the two-pool arithmetic, violated by the gater. (2) The lane pool had silently accumulated\r\n  **104.8 GB** over repeated full-workspace sweeps (nothing bounds or even measures a pool's\r\n  accumulation until the volume dies). The volume hit **3 MB free**; the reds wore exactly the\r\n  entry's predicted costume — `LNK1318: Unexpected PDB error; LIMIT (12)` naming no disk — plus a\r\n  second face worth keeping: `traceable-reqs check` died as a PANIC printing to stdout\r\n  (`os error 112`), so a REGISTRY gate red can also be the disk's. Both gate verdicts VOIDED\r\n  (clippy's full compile had exited 0 before space died — the code was never the question).\r\n  Recovery measured: gate pool reap 9.6 GB, lane pool clean 100.2 GB, drive back to 109.6 GB free.\r\n  **Remedies adopted at the incident:** the gate never mints its own pool while a builder lane is\r\n  live on the box — it takes the lane pool over SEQUENTIALLY at pool-release (warm, loud, the\r\n  releases#103 pattern); and gate/lane scripts get the disk-floor preflight the golden runner\r\n  already carries (this entry's part 2, still unbuilt).\r\n- **THIRD FACE, measured 2026-08-24 (WAX-SEAL #21 golden window, doyle):** two new mechanisms, both\r\n  about the REMEDY rather than the red. (1) The wax-seal-w1 lane pool **re-accumulated to 152–169 GB\r\n  (two meters, IR-46 caveat) within ONE DAY of the 08-23 clean** and rode the volume back down to\r\n  4.92 GB free — a reap is an instant, not a state; nothing yet bounds a pool between reaps.\r\n  (2) **The remedy itself arrived garbled through relay:** the golden push was held \"waiting on the\r\n  IR-59 reboot\" when this entry prescribes no reboot anywhere — tens of releases have shipped without\r\n  one; the operator refused the premise and the register's own recorded remedy (reap finished-lane\r\n  pools) cleared it in ten minutes. A remedy relayed as a DIFFERENT remedy is the relay trap wearing\r\n  infra clothes: the entry is the author — read it before adopting a hold. Recovery measured: five\r\n  finished-lane pools reaped after ancestry classification (`git cherry` catches rebased lands that\r\n  a plain `merge-base --is-ancestor` calls unlanded — gate-w4l1's 90.9 GB pool was reapable only by\r\n  that meter), 4.92 → 260.88 GB free (~256 GB free-delta vs ~270–287 GB sum-of-lengths). Two main\r\n  runs red inside the low-disk window (09:17Z/09:41Z) were re-run, not re-read, per this entry's\r\n  must-do.\r\n- **FOURTH FACE, measured 2026-08-24 same day (SIGNET #218 W2 gate, doyle — the gater's own pool\r\n  this time):** the MAIN pool went **13.7 GB → 158.3 GB in ONE DAY** absorbing four full gate\r\n  batteries across two lane tips, and dragged the volume to **18 GB free mid-gate** — so the\r\n  entry's mechanism is not a lane-pool problem, it is EVERY pool under repeated full sweeps, the\r\n  gate rig included. Two riders worth the ink: (1) the golden runner's **free-space floor step\r\n  produced its first live catch** — a thin CI leg refused at 14:14 local over exactly this window\r\n  with zero test signal, and the register's re-run-not-re-read rule resolved it in one command;\r\n  (2) the reap-and-rebuild trade (\"cleaning a live pool buys one window at rebuild price\") was\r\n  taken deliberately mid-gate and cost ~35 minutes cold — cheaper than one uninterpretable red.\r\n  A red measured at 18 GB free in this gate got NO read at all, and the next sweep's red was a\r\n  DIFFERENT test: low disk manufactures random victims before it manufactures link errors.\r\n- **The event:** a gate's preflight refused with `GATE_ABORTED_DISK_FLOOR` at **4.75 GB free on a\r\n  1863 GB volume**. Four cold pools plus the milestone head's pool were standing at once. The floor\r\n  guard did its job — without it a full workspace build would have started with under 5 GB of\r\n  headroom and produced a red belonging to nothing.\r\n- **THE ARITHMETIC, and it corrects the intuition that worktrees are the cost.** Measured across the\r\n  whole `.worktrees` tree: **45 worktrees = 0.79 GB total** (~18 MB each). **3 pools = 130.45 GB.**\r\n  Worktrees are **0.6%** of the footprint; pools are **99.4%**. **One cold pool is worth roughly 2,500\r\n  worktrees.** A rule keyed on worktree count would cost a day of `git worktree remove` work for under\r\n  a gigabyte, risk removing a lane someone still wants, and leave the lever untouched.\r\n- **THE CEILING, as arithmetic rather than hygiene:** at **45–75 GB per cold pool** on this workspace\r\n  against a **40 GB floor**, this box supports **TWO live pools comfortably, THREE only if one is\r\n  small**. The two rules that already exist need no replacement, only this number attached:\r\n  - **Reap a pool when its lane is finished** → 45–75 GB back immediately.\r\n  - **Do not run two builds at once** → not only the contention argument, but **75–150 GB of\r\n    simultaneous allocation** against that floor.\r\n- **A FULL VOLUME REDS AS A LINKER DEFECT.** `LINK: fatal error LNK1318: Unexpected PDB error`\r\n  (variously `OK (0)` or `LIMIT (12)`), often beside `LNK4209: debugging information corrupt`. It\r\n  reads as a corrupt artifact or a broken toolchain and is neither — it is the linker unable to grow\r\n  a large `.pdb`. **Nothing in the failure text says \"disk\".** Do not key recognition on the\r\n  parenthesised code; it varies.\r\n- **THE DANGER WINDOW IS THE TAIL OF A COLD BUILD, not a steady state you can check once.** The\r\n  2026-08-22 instance died at the link of `spt` — the last and largest artifact of a **74 GB** cold\r\n  pool — while that same build was draining the volume out from under itself. A free-space reading\r\n  taken before the build would have looked fine.\r\n- **Positive tell, with its own refutation attached:** `traceable-reqs check` alone surviving a leg\r\n  table is suggestive, because it is the only leg that never links. It is a POSITIVE tell ONLY — a\r\n  full disk can red before any link step, so the signature's ABSENCE clears nothing.\r\n- **THE FALSIFIER IS FREE SPACE AT THE TIME OF THE RUN**, not the shape of the leg table.\r\n- **Must-do, both cheap:**\r\n  1. **A free-space reading goes in the FIRST LINE of any build-failure report** — not in the\r\n     controls, not as a follow-up. Two agents spent hours on a mechanism for this failure and neither\r\n     ran `df`; the falsifier was one command away throughout.\r\n  2. **Rig and gate logs should record free space at run start.** Today they do not, which makes \"was\r\n     the disk full\" **unanswerable after the fact for every red already in hand**. Any red produced\r\n     under ~1 GB free is UNINTERPRETABLE and must be **re-run, not re-read**.\r\n- **Measurement caveat, observed twice in one hour:** sum-of-file-lengths and free-space delta\r\n  disagree by several percent when anything else on the box is writing (98.07 GB of subtrees → 92.25\r\n  GB reclaimed; 47.28 GB → 40.81 GB). Report BOTH, derive neither from the other, and treat any single\r\n  free-space number as an instant rather than headroom — see IR-46.\r\n- **FIFTH FACE, measured 2026-08-29 at the CONDUIT #236/v0.65.0 cut (deployah):**\r\n  the finished milestone's sequential lane-sharing accumulated **140.51 GB**, while a freshly\r\n  rebuilt pool measured **7.78 GB** — about **18× one build's working set** retained across lane\r\n  hand-offs with no reap between them. This is the budgetable rate behind that cut's disk-floor\r\n  red: sequential execution prevents concurrent ownership corruption, but it does not bound\r\n  historical artifacts inside the shared pool. Treat takeover and reclamation as separate\r\n  operations; a pool may be safe to reuse and still be too large to keep.\r\n- **SEVENTH FACE, measured 2026-08-30 (v0.67.0 milestone close — the PARALLEL-LANE fill\r\n  rate):** the #23 wave arc drove C: from ~240 GB free to **0.01 GB in ~3.5 hours**: four\r\n  concurrent/serial lane+gate pools totalled **236.6 GB** (ns23-w1 87.7 + ns23-113 72.3 +\r\n  gate rig 57.3 + ns23-w3 19.1) — effectively the entire ir57 reclaim re-consumed inside one\r\n  milestone's build window. The head gate and two thin-CI runs redded with the entry's exact\r\n  costume (\"could not compile\" + treqs panic, zero disk words) at 0.01 GB and all re-earned\r\n  green after reclaim (+186.6 GB, finished-lane targets only, single-actor rule held under\r\n  racing consent). Budget rule this face adds: a MULTI-WAVE milestone on one box books\r\n  ~60-90 GB PER LANE-PLUS-GATE cycle, so the pool budget is per-wave, not per-milestone —\r\n  reap each wave's pool at its LAND, not at the milestone party (the party inherited only\r\n  ~58 GB because the emergency had already forced the other ~179).\r\n- **SIXTH FACE, measured 2026-08-30 (#242 golden r4, Windows test job, LNK1318 at the PDB\r\n  write):** the floor is asserted ONCE at job START, but the job's internal LOW-WATER sits at its\r\n  LAST heavy step — the docs-drift build, ~28 minutes in. r4's floor read 65.1 GiB honest at\r\n  23:07; the box was at ~37–39 GB by the 23:35 link failure. LNK1318 on PDB write = this entry's\r\n  documented low-disk costume; the incremental-corruption candidate was retired by preservation\r\n  snapshot (no xtask state existed at failure). **Durable fix = a floor RE-READ (or reclaim)\r\n  immediately before the docs-drift build** — the WITHIN-job sibling of the across-job\r\n  read-after-checkout fix, rides the next workflow commit. Riders: incremental hygiene as\r\n  disk-pressure maintenance (the dir measured 4.56 GB), and the box's **~51 GB non-recovering\r\n  post-run consumption** is this entry's pool-weight face — classify at the IR-14/26/27/49 audit\r\n  slot (composed this sweep).\r\n- **Composed for next intake (doyle, v0.65.0 close):** the still-open log-the-floor build half\r\n  rides with [[IR-57]]'s scripted pick-fidelity audit as the next milestone's two tooling riders.\r\n- **Trigger condition:** ripe now for the log-the-floor half (it rides any gate-script or CI touch);\r\n  the arithmetic is discipline and applies immediately.\r\n- **Size guess:** small — one line in each rig/gate preflight to record free space alongside the\r\n  existing floor check.\r\n\r\n### IR-60 — a wrapper that CAPTURES a leg's exit status ends with the capture, so the wrapper's own status is the capture's, not the leg's\r\n\r\n- **Status:** OPEN, unowned — script-shape discipline, not a code lane. Filed by doyle 2026-08-22\r\n  during the TURNKEY #212 W5 lane; mechanism measured by todlando, who reported it first as a\r\n  possible harness misreport and then RETRACTED that reading himself on a minimal probe.\r\n- **The reading that started it:** a background leg was summarised as `exit code 0` while the leg's\r\n  own exit file read `100`. Reported as-is, that is a task runner lying about a red — the worst\r\n  possible direction for a purposeful-red claim, since it would turn two reds that DID fire into two\r\n  reds reported as not having fired.\r\n- **The measurement, minimal and on this box:**\r\n\r\n      ( exit 100 ); echo $? > probe.exit; FINAL=$?\r\n      leg status captured to file : 100\r\n      wrapper's own final status  : 0\r\n\r\n  The wrapper's shape is `( cd <lane> && cargo nextest ... > leg.raw 2>&1 ); echo $? > leg.exit`.\r\n  **The last command is the `echo`, which succeeds**, so the wrapper genuinely exits 0 while the leg\r\n  genuinely exited 100. THE RUNNER TOLD THE TRUTH ABOUT THE WRAPPER. There is nothing to file against\r\n  the task runner, and it would have been filed.\r\n- **The class, and this is why it is worth an entry rather than a fix:** it is the truncation-pipe\r\n  family — the meter measured something real, it just was not the thing about to be quoted. **Three\r\n  shapes now share ONE trigger, and the trigger is not \"is this a pipe\":**\r\n  1. a truncation pipe (`cmd | tail`, `cmd | head`) — `$?` measures the truncator, and `head` closing\r\n     the pipe can MANUFACTURE a status (SIGPIPE → 101), so `PIPESTATUS` is not protection either;\r\n  2. a flattened `$?` read after any intervening command;\r\n  3. **a wrapper whose last command is the capture itself.**\r\n  **The trigger in all three is the REPORTING** — every instance happened while trimming or capturing\r\n  output in order to QUOTE it as evidence.\r\n- **The practice that held, and the one to keep:** the leg's own file is the leg's verdict. Both reds\r\n  were real, and the only reason that was knowable is that every leg wrote its exit to its own file\r\n  rather than to the wrapper's status.\r\n- **Remedy, in preference order:** (1) never read a wrapper's status as a leg's — read the leg's exit\r\n  FILE, which the per-leg rule already requires; (2) if a wrapper's own status must be meaningful,\r\n  end it by re-raising the captured status (`exit \"$(cat leg.exit)\"`) or set the status before the\r\n  capture is the last word; (3) for anything that becomes evidence, redirect to a file and read the\r\n  file.\r\n- **Trigger condition:** ripe now — it rides the next gate-script touch, and the gate scripts in this\r\n  milestone already write per-leg exit files, which is what makes this discipline rather than debt.\r\n- **Size guess:** small — a convention line in the gate-script preamble; no product code.\r\n\r\n### IR-61 — spacerun's test-module skip carries a SECOND literal tracker; the two answers can drift, and today only a cell stands between them\r\n\r\n- **Status:** OPEN, unowned, accepted-with-mitigation. Filed by doyle 2026-08-22 at the TURNKEY #212\r\n  head gate, as the named residual of the latch repair (the repair itself rides the milestone).\r\n- **What the debt is.** `crates/xtask/src/spacerun.rs` now skips a column-0 `#[cfg(test)]` module by\r\n  BRACE DEPTH and resumes after its close, rather than latching the scan to end-of-file. Counting\r\n  braces safely means knowing when a brace is inside a string, a raw string or a char literal — and\r\n  the scanner ALREADY tracks literals for its rendering pass. It does not reuse that tracking. There\r\n  are now TWO answers in one file to \"am I inside a literal\", and **two answers to one question is a\r\n  disagreement waiting for a reader who fixes one of them.**\r\n- **Why it was accepted rather than refactored on the spot, stated so the trade is auditable:** the\r\n  two trackers answer genuinely different questions — the rendering walk is PER LINE and forward\r\n  from an opening quote (\"where does this literal start and end\"), while the skip needs \"am I inside\r\n  a literal right now\" carried CONTINUOUSLY across lines. Unifying them is a real refactor of a check\r\n  that is already gated, already carries five fixed defects, and sits on the tree being handed to\r\n  golden. The narrow change with an OBSERVABLE failure mode beat the correct-shaped change with a\r\n  wide blast radius, on that tree, on that day.\r\n- **The mitigation, and its exact limit.** Three brace cells fail the moment the two trackers\r\n  disagree about a raw string, a normal string or a char literal, plus a cell that reds when the skip\r\n  stops consulting a literal tracker at all (`match lit` -> `match Lit::None`). **That is a cell\r\n  standing in for a refactor.** It catches drift in the three forms it names and nothing else — a\r\n  fourth literal form, or a change to only one tracker in a form neither cell covers, passes.\r\n- **The general shape, which is why this is a register entry rather than a comment:** a check whose\r\n  own correctness depends on a second implementation of a thing it already implements is one\r\n  refactor away from the defect class it exists to prevent. This same file has already produced\r\n  three instrument defects (an indented-marker latch, a column-0 latch, and a suppression that\r\n  decided what got PARSED rather than what got REPORTED). The pattern is not carelessness; it is a\r\n  scanner accumulating special cases.\r\n- **Trigger condition:** the next SUBSTANTIVE change to spacerun's scanning — any new skip, any new\r\n  literal form, any change to either tracker. At that point unify, rather than adding a third answer.\r\n- **Size guess:** small to medium — one continuous literal-state walk serving both the render pass\r\n  and the skip, with the existing corpus and brace cells as the regression net.\r\n\r\n### IR-62 — an e2e daemon binds well-known ports and collides with the resident fleet on shared runners\r\n\r\nFiled 2026-08-23 (doyle), from the #212 r2 golden's Windows Phase A red — one witnessed\r\ninstance, mechanism verified from the run's own capture, filed on the mechanism per the\r\nregister's standard.\r\n\r\n**Mechanism.** `endpoint_autostart_e2e::saved_endpoint_replays_on_daemon_restart` failed its\r\nown PRECONDITION (\"daemon B must come up with a fresh brain\") because daemon B's broker came up\r\ndegraded: `NODE_KEY_FAIL: identity unavailable` (net-less broker, no retry) and\r\n`DOCS_SERVER_BIND_FAIL` port 5474 `os error 10048` — the docs port was held by a CO-RESIDENT\r\ndaemon. HFENDULEAM is live infra: the resident fleet's daemon legitimately holds well-known\r\nports, and any e2e that brings up a daemon with default port bindings is in a race with it BY\r\nCONSTRUCTION. An isolated SPT_HOME isolates the store and broker socket, NOT globally-numbered\r\nTCP ports.\r\n\r\n**Classification history.** r2: red (35.4s, precondition panic). Run 1 and r3 on the same box:\r\ngreen. Folded into r3 under a pre-registered predicate (reds twice → dedicated triage); it\r\ngreened, so this stays an environment-shaped intermittent, NOT a product defect and NOT\r\nclosed — the collision window is real and will re-fire under the right co-residence timing.\r\n\r\n**Remedy direction (not built).** Test daemons should bind ephemeral/rig-scoped ports for\r\nevery advisory surface (the docs server is advisory — a bind failure should degrade the rig\r\nloudly, not poison an unrelated cell's precondition), or the precondition should name the\r\nport-collision cause distinctly so the red self-classifies. Either lane is test/CI work\r\n(hertz's), triggered the next time this class fires anywhere.\r\n\r\n**Kin.** IR-51 (e2e daemon net-enabled on real interfaces — hermeticity is disk-deep only);\r\nthe known not-ours red classes list in the #212 hand-off.\r\n\r\n**BUILT 2026-08-24 (hertz, SIGNET #218 batch; PR #158).** The class fired its second witnessed\r\ninstance the same day — doyle's W2 gate rig, `engine_room_bringup_e2e` precondition panic with\r\nthe IR-50 panel naming `DOCS_SERVER_BIND_FAIL` port 5474 `os error 10048` — which armed this\r\nentry's own trigger. Hertz repro'd deterministically (held the port; brain still reached\r\nBRAIN_UP), pre-ranked three mechanisms before probing, and built the ephemeral-advisory form:\r\nrig-only `SPT_TEST_EPHEMERAL_ADVISORY_PORTS=1` makes the daemon's docs listener bind port 0\r\n(production config/`SPT_DOCS_PORT`/docs-url untouched; the flag matches the literal \"1\" only).\r\nThe golden workflow's test job sets it globally on both self-hosted legs, the standalone ER rig\r\nsets it too. Scope note kept honest per his own ranking: the docs collision is retired; if a\r\nco-diagnostic bind elsewhere still poisons a precondition, that is a residual face of THIS\r\nentry, not a closed question.\r\n\r\n### IR-63 — suite-mix sweeps leak job-escaped autostart daemons that LOCK the pool's spt.exe; and the same box conditions manufacture one random victim per sweep\r\n\r\n- **Status:** OPEN, mitigated-by-rig-step — the reap is adopted discipline, not yet construction.\r\n  Filed by doyle 2026-08-24 at the SIGNET #218 gates; first measured by todlando the same day\r\n  (his W1 build: four reap rounds of 2, 8, 1, 1 processes, count-by-path stated each round).\r\n- **Mechanism, two faces of one condition:** (1) e2e sweeps that exercise autostart leave\r\n  job-escaped daemons running `target/debug/spt.exe`; the NEXT build or `xtask check` then dies\r\n  on `os error 5` removing the exe — a rig red wearing a build defect's clothes. nextest's own\r\n  `leaky` flags corroborate (4–8 per sweep measured). (2) The same co-residence (leaked daemons +\r\n  resident fleet + runner traffic) manufactures ONE red per full sweep with a DIFFERENT victim\r\n  each time: doyle's W2 gate measured FOUR distinct one-off victims in four same-sha sweeps\r\n  (ER bringup, composite+bootstrap pair under CI load, resident_service, brain_resume), every\r\n  one green alone and/or in a sibling sweep. The e2e-leaked-daemons rule holds: a different test\r\n  dying each run on one sha is ONE environment cause, and hardening members never closes it.\r\n- **Mitigation adopted (rig step, both todlando's lanes and doyle's gate runner):** reap\r\n  `spt.exe` BY PATH (`*spt-core\\target*`) before EVERY cargo invocation and after every sweep;\r\n  report the count each time so a zero is a claim, not silence.\r\n- **Remedy direction (unbuilt):** the durable form is construction, not discipline — either\r","startLine":3158,"lineNumbers":[3158,3159,3160,3161,3162,3163,3164,3165,3166,3167,3168,3169,3170,3171,3172,3173,3174,3175,3176,3177,3178,3179,3180,3181,3182,3183,3184,3185,3186,3187,3188,3189,3190,3191,3192,3193,3194,3195,3196,3197,3198,3199,3200,3201,3202,3203,3204,3205,3206,3207,3208,3209,3210,3211,3212,3213,3214,3215,3216,3217,3218,3219,3220,3221,3222,3223,3224,3225,3226,3227,3228,3229,3230,3231,3232,3233,3234,3235,3236,3237,3238,3239,3240,3241,3242,3243,3244,3245,3246,3247,3248,3249,3250,3251,3252,3253,3254,3255,3256,3257,3258,3259,3260,3261,3262,3263,3264,3265,3266,3267,3268,3269,3270,3271,3272,3273,3274,3275,3276,3277,3278,3279,3280,3281,3282,3283,3284,3285,3286,3287,3288,3289,3290,3291,3292,3293,3294,3295,3296,3297,3298,3299,3300,3301,3302,3303,3304,3305,3306,3307,3308,3309,3310,3311,3312,3313,3314,3315,3316,3317,3318,3319,3320,3321,3322,3323,3324,3325,3326,3327,3328,3329,3330,3331,3332,3333,3334,3335,3336,3337,3338,3339,3340,3341,3342,3343,3344,3345,3346,3347,3348,3349,3350,3351,3352,3353,3354,3355,3356,3357,3358,3359,3360,3361,3362,3363,3364,3365,3366,3367,3368,3369,3370,3371,3372,3373,3374,3375,3376,3377,3378,3379,3380,3381,3382,3383,3384,3385,3386,3387,3388,3389,3390,3391,3392,3393,3394,3395,3396,3397,3398,3399,3400,3401,3402,3403,3404,3405,3406,3407,3408,3409,3410,3411,3412,3413,3414,3415,3416,3417,3418,3419,3420,3421,3422,3423,3424,3425,3426,3427,3428,3429,3430,3431,3432,3433,3434,3435,3436,3437,3438,3439,3440,3441,3442,3443,3444,3445,3446,3447,3448,3449,3450,3451,3452,3453,3454,3455,3456,3457]},"fileSize":501961,"meta":{"source":{"type":"path","value":"C:\\Users\\decid\\Documents\\projects\\spt-core\\docs\\INFRA-REGISTER.md"},"truncation":{"direction":"head","truncatedBy":"lines","totalLines":5782,"totalBytes":25477,"outputLines":300,"outputBytes":25477,"shownRange":{"start":3158,"end":3457},"nextOffset":3458}}},"isError":false,"timestamp":1789094648353}}
{"type":"message","id":"a03286b3","parentId":"c82ad9a3","timestamp":"2026-09-11T02:44:08.358Z","message":{"role":"toolResult","toolCallId":"call_n6XpCAKJjfUqoSFAM764yDeD|fc_065c0d1976ecf9c2016aa36af5ca3087d19ea01e73fef9c2ea","toolName":"grep","content":[{"type":"text","text":"# .github/workflows/\n## ci.yml\n 23|    steps:\n*24|      - uses: actions/checkout@v5\n 25|        with:\n 26|          fetch-depth: 2\n 27|      # IR-46/IR-59: 32 GiB is an instantaneous floor, not a headroom guarantee.\n*28|      # IR-73: This floor is not protective, so it runs after checkout.\n 29|      # [int->REQ-CI-FREE-SPACE-PREFLIGHT]\n 30|      - name: DISK floor start\n 31|        shell: bash\n...\n 96|    steps:\n*97|      - uses: actions/checkout@v5\n*98|      # IR-73: This floor is not protective, so it runs after checkout.\n 99|      # [int->REQ-CI-FREE-SPACE-PREFLIGHT]\n 100|      - name: DISK floor start (Windows)\n 101|        if: runner.os == 'Windows'\n...\n 112|          }\n*113|      # IR-73: This floor is not protective, so it runs after checkout.\n 114|      # [int->REQ-CI-FREE-SPACE-PREFLIGHT]\n 115|      - name: DISK floor start (Linux)\n 116|        if: runner.os == 'Linux'\n...\n 182|    steps:\n*183|      - uses: actions/checkout@v5\n*184|      # IR-73: This floor is not protective, so it runs after checkout.\n 185|      # [int->REQ-CI-FREE-SPACE-PREFLIGHT]\n 186|      - name: DISK floor start\n 187|        shell: bash\n...\n 230|    steps:\n*231|      - uses: actions/checkout@v5\n*232|      # IR-73: This floor is not protective, so it runs after checkout.\n 233|      # [int->REQ-CI-FREE-SPACE-PREFLIGHT]\n 234|      - name: DISK floor start\n 235|        shell: bash\n## release.yml\n 51|    steps:\n*52|      - uses: actions/checkout@v5\n 53|      # IR-46/IR-59: 32 GiB is an instantaneous floor, not a headroom guarantee.\n*54|      # IR-73: This floor is not protective, so it runs after checkout.\n 55|      # [int->REQ-CI-FREE-SPACE-PREFLIGHT]\n 56|      - name: DISK floor start (Windows)\n 57|        if: runner.os == 'Windows'\n...\n 68|          }\n*69|      # IR-73: This floor is not protective, so it runs after checkout.\n 70|      # [int->REQ-CI-FREE-SPACE-PREFLIGHT]\n 71|      - name: DISK floor start (Linux)\n 72|        if: runner.os == 'Linux'\n...\n 167|    steps:\n*168|      - uses: actions/checkout@v5\n*169|      # IR-73: This floor is not protective, so it runs after checkout.\n 170|      # [int->REQ-CI-FREE-SPACE-PREFLIGHT]\n 171|      - name: DISK floor start\n 172|        shell: bash"}],"details":{"scopePath":".github/workflows/ci.yml, .github/workflows/release.yml","searchPath":"C:\\Users\\decid\\Documents\\projects\\spt-core\\.github\\workflows","cwd":"C:\\Users\\decid\\Documents\\projects\\spt-core","matchCount":14,"fileCount":2,"files":[".github/workflows/ci.yml",".github/workflows/release.yml"],"fileMatches":[{"path":".github/workflows/ci.yml","count":9},{"path":".github/workflows/release.yml","count":5}],"truncated":false,"displayContent":"# .github/workflows/\n## ci.yml\n  23│    steps:\n *24│      - uses: actions/checkout@v5\n  25│        with:\n  26│          fetch-depth: 2\n  27│      # IR-46/IR-59: 32 GiB is an instantaneous floor, not a headroom guarantee.\n *28│      # IR-73: This floor is not protective, so it runs after checkout.\n  29│      # [int->REQ-CI-FREE-SPACE-PREFLIGHT]\n  30│      - name: DISK floor start\n  31│        shell: bash\n    │...\n  96│    steps:\n *97│      - uses: actions/checkout@v5\n *98│      # IR-73: This floor is not protective, so it runs after checkout.\n  99│      # [int->REQ-CI-FREE-SPACE-PREFLIGHT]\n 100│      - name: DISK floor start (Windows)\n 101│        if: runner.os == 'Windows'\n    │...\n 112│          }\n*113│      # IR-73: This floor is not protective, so it runs after checkout.\n 114│      # [int->REQ-CI-FREE-SPACE-PREFLIGHT]\n 115│      - name: DISK floor start (Linux)\n 116│        if: runner.os == 'Linux'\n    │...\n 182│    steps:\n*183│      - uses: actions/checkout@v5\n*184│      # IR-73: This floor is not protective, so it runs after checkout.\n 185│      # [int->REQ-CI-FREE-SPACE-PREFLIGHT]\n 186│      - name: DISK floor start\n 187│        shell: bash\n    │...\n 230│    steps:\n*231│      - uses: actions/checkout@v5\n*232│      # IR-73: This floor is not protective, so it runs after checkout.\n 233│      # [int->REQ-CI-FREE-SPACE-PREFLIGHT]\n 234│      - name: DISK floor start\n 235│        shell: bash\n## release.yml\n  51│    steps:\n *52│      - uses: actions/checkout@v5\n  53│      # IR-46/IR-59: 32 GiB is an instantaneous floor, not a headroom guarantee.\n *54│      # IR-73: This floor is not protective, so it runs after checkout.\n  55│      # [int->REQ-CI-FREE-SPACE-PREFLIGHT]\n  56│      - name: DISK floor start (Windows)\n  57│        if: runner.os == 'Windows'\n    │...\n  68│          }\n *69│      # IR-73: This floor is not protective, so it runs after checkout.\n  70│      # [int->REQ-CI-FREE-SPACE-PREFLIGHT]\n  71│      - name: DISK floor start (Linux)\n  72│        if: runner.os == 'Linux'\n    │...\n 167│    steps:\n*168│      - uses: actions/checkout@v5\n*169│      # IR-73: This floor is not protective, so it runs after checkout.\n 170│      # [int->REQ-CI-FREE-SPACE-PREFLIGHT]\n 171│      - name: DISK floor start\n 172│        shell: bash"},"isError":false,"timestamp":1789094648357}}
{"type":"message","id":"c429bf07","parentId":"a03286b3","timestamp":"2026-09-11T02:44:08.426Z","message":{"role":"toolResult","toolCallId":"call_dtHmZOU11W6MplnZSTVlmQGZ|fc_065c0d1976ecf9c2016aa36af5ca4087d1b534401a3478fe06","toolName":"grep","content":[{"type":"text","text":"# AGENTS.md\n 40|- **Build-cache pools (binding, releases#103):** a cargo `target/` directory belongs to ONE source tree. Two trees building into one pool overwrite each other's artifacts and fabricate reds that belong to neither — the v0.51.0 W1/H1 `E0308` that vanished on re-run. **The rule is about the RELATIONSHIP, not the path:** a junction and a `CARGO_TARGET_DIR` env var reach the same hazard, and the env var leaves no directory entry to notice afterwards, so \"is this dir under `.worktrees/`\" never was the quest...\n*41|- **Target-tree teardown (releases#103, same lane):** never delete a `target/` you have not classified. Check OUTBOUND first (`Get-Item -Force`: a junction is deleted as a link, a real dir as a tree), then sweep INBOUND for reparse points aimed at it before removing a real one, and measure size and free space before and after so the reclaim is a number rather than a claim. Reap the target SUBTREE, never a session or worktree directory around it. Do not point `CARGO_TARGET_DIR` into a scratchpad (v0.50.0 ...\n 42|- **CI / merge strategy:** golden CI (ADR-0050, ruled 2026-07-27) — milestone-batch golden runs, thin-lane PRs, ff-only main (tested sha == merged sha). Piloting from the next milestone; read the ADR before shaping a PR lane.\n 43|\n 44|If you finish a significant body of work without need for user intervention, or if your context gets too high, you can clear your own context and keep moving:\n\n# docs/\n## BROKER-BRAIN-SPLIT-RESTORATION.md\n 171|\n*172|**[V1] Rollback-state-compat invariant (forward invariant, mint this milestone).** Auto-rollback spawns the **old** binary against durable state the **new** brain may already have written. This is safe *today* (a source audit confirmed zero state-migration code exists), but the first release that migrates a durable-state schema would silently break Q7's rollback. The invariant must be minted now, while it is free: **a brain must not irreversibly migrate durable state before ready-promotion** — equivale...\n 173|\n 174|**Reason.**\n 175|- The dangerous case is a *runtime* bug (new brain panics on boot), not the binary land (already rolled back at `applyhost.rs:167-170`) and not IPC mismatch (the `classify` handshake `brain_ipc_version ≥ broker.min_compatible` is checked pre-swap). A naive supervisor would crashloop the new binary: endpoints alive but logic dead — \"up but useless.\"\n## DEFERRED.md\n 37|| **Origin-source update bootstrap (`spt update fetch` — pull the latest signed release from GitHub into the existing verify→stage→apply pipeline)**: today update DISCOVERY is **peer-only** (REQ-UPD-1: a daemon pulls offers from roster peers via `request_update`; `propagate.rs`/`peerloop.rs`). There is NO origin fetch, so the **first node in a fleet — or any isolated/solo node — cannot get a new release without a peer that already staged it** (the fleet converges by gossip, but only *after* a m...\n*38|| **Test broker socket-bind hardening (CI-flake removal)**: `applyhost` tests' `served_broker` helper does `Broker::bind(name).expect(\"bind broker\")` (`crates/spt-daemon/src/applyhost.rs:293`) where `name` = `spt-daemon-d7b-{pid}-{seq}.sock`. Flakes intermittently on the **kitsubito** self-hosted Linux runner (likely AF_UNIX path collision / stale socket file under the runner's reused workspace — Windows named pipes don't hit it). Cost the v0.3.2 release a full red CI run + a `--failed` rerun (2026-06-...\n*39|| **`spt update fetch` single→set shape-upgrade at same version (REQ-UPD-8 transitional trap)**: `cmd_update_fetch` sets the rollback floor = `staged_version` (the monotonic counter), and the gate is a plain `candidate > floor`. A node that fetched+staged version N as a platform **single** (pre-0.3.2 fetch behavior) can never re-fetch version N as a multi-platform **set** — same counter → `Rollback{current:N, candidate:N}`. Bites the **seed-node bootstrap**: the first node to origin-`fetch` a relea...\n 40|| **On-disk `current_exe` reconcile after auto-rollback (the D6-2 reboot residual)**: readiness-gated auto-rollback (ADR-0018 Q7, restoration D6-2) is **record-driven selection** — after a rollback the broker's supervisor keeps spawning the last-known-good `.old-N` binary, chosen from the durable `RolledBack` record, so the rescue survives a reboot for free **with no file rename at the failure instant** (the brittle path the design rejected). But the bytes on disk at `current_exe` are STILL the quarant...\n 41|| **Quarantine operator override (`spt update apply --force` — the note-i escape hatch)**: D6-2's quarantine guard refuses re-applying a version that auto-rolled-back on this node (the `RolledBack` record is the marker; clears naturally when N+1 stages). But a version whose failure was **environmental** (a transient boot condition, not bad bytes) leaves the node **permanently allergic** to a genuinely-good version with no escape but staging a newer one. FIX = an explicit operator override (`spt update ...\n 42|| **✅ RESOLVED — shipped v0.8.3 (REQ-HAZARD-BROKER-QUIC-DEADLINE, KNOWN-HAZARDS 7.8).** ~~Broker-side bound on brain-waiting QUIC ops (the pump-IPC-deadline B-half)~~: the brain-side deadline (REQ-HAZARD-PUMP-IPC-DEADLINE, KNOWN-HAZARDS 7.6) stops the single-threaded pump wedging when a peer black-holes, by bounding the pump's brain-IPC reads and escalating a TimedOut to a supervised restart. But the ROOT cause is broker-side: the broker's `net_open_stream` / `net_stream_send` / `net_dial` handlers m...\n## FAULT-MATRIX.md\n 38|| 18 | **Compromised relay node serves a tampered update artifact** (bytes corrupted at rest after the relay's own verification) | That one pull ends `Rejected(ArtifactMismatch)` at the puller | The puller's staged release + running binary (nothing staged, nothing applied — no code path from wire bytes to the cache except through `plan_verified`); the rest of the subnet pulls from honest peers | Pull from another peer; the per-node gate (REQ-UPD-2) runs at **every** hop, so one poisoned node never re-p...\n*39|| 19 | **Non-conforming peer offers a rollback/expired/off-channel release** | None — rejected pre-fetch, zero artifact bytes move | The puller's version (monotonic floor holds); the wire (no transfer ever starts) | None needed — the offer-then-fetch shape gates metadata before bytes (REQ-HAZARD-UPDATE-ROLLBACK) | `tests/propagate.rs::rollback_offer_is_rejected_before_any_fetch` |\n 40|| 20 | **Untrusted node queries for the staged update** | None — refused by not offering (fail-closed, the up-to-date shape: learns nothing, not even whether a release exists) | The staged release; the serve loop (one refusal, no state) | None needed; pair the node to entitle it | `tests/propagate.rs::untrusted_origin_gets_no_offer` |\n*41|| 21 | **Stream lost mid-update-artifact** (responder dies / wire tears before `Done`) | That one pull errors at the requester | The requester's staged release (staging is atomic, artifact-then-metadata commit point — a torn pull stages nothing); the scratch file is transient | No resume protocol by design: re-query fresh — the query is idempotent and chunks are positional | torn-pull shape shared with row 14 (`request_update` errors on EOF-before-`Done`); staging atomicity: `relcache.rs::torn_or_cor...\n 42|\n 43|| 22 | **Psyche emits spoofed routing** (`<EVENT type=\"reply\" from=\"evil\" to=\"victim\">` on its stdout) | None — the spoof is structurally inert: the intent parser carries body only (attrs unrepresentable), the daemon re-stamps `from=<psyche_id>` and routes to the inbound message's structural sender (its `from`) alone | The spoof target (receives nothing); the wire (only daemon-authored envelopes); every other agent's identity | None needed (anti-spoof is structural + re-stamp, ADR-0012 / KH 7.3) | `psy...\n 44|| 23 | **Psyche replies with no inbound sender to answer** (alarm-fired turn emits a reply) | That one intent drops with a typed outcome (fail-closed — never broadcast, never guessed) | Every perch (zero deliveries); the notify leg (independent) | The Psyche's next answered turn replies normally | `psyrelay.rs::reply_without_target_is_dropped` |\n## FLAKE-LEDGER.md\n 44|| `spt::engine_room_bringup_e2e a_cleanly_offline_engine_room_is_still_brought_up_by_its_own_gate` — :1150 PRECONDITION (warm bring-up never spawns) | 3×/3 hfenduleam main-checkout pool (2026-08-17, main @27d40b9, agent env scrubbed, 186s each — consistent, not intermittent) | **TEST INFRASTRUCTURE DEFECT, not product evidence (IR-21/IR-39 class).** The clean main target had no `target/debug/mock-session.exe`: `cargo test -p spt` builds the `spt` test target but not another package's `mock-adapter` ...\n*45|| `spt-daemon daemon::tests::a_tree_teardown_reaches_a_grandchild_the_service_spawned` | 2× hfenduleam Windows golden: 10.176s run 30776330383 @184f2ac (2026-08-03); 10.225s run 30873007187 att1 @4b37512 (2026-08-04) | **TWO mechanisms wearing one assert string — do not count as a cross-sha repeat** (doyle source verification 2026-08-04): red 1 was the bare-pid `provably_gone(grandchild)` poller reading a pid-reuse stranger — it is the cited motivating incident in the pin comment (daemon.rs:2726-273...\n 46|| `spt-daemon::brain_resume_conn_deadlock daemon_cursor_only_resume_keeps_heartbeat_live_respawn_interleave` (+ twin `…_steady_state` on att2) | 2× kitsubito Linux golden 34014574926 @34fdb848 (v0.67.1 docs-only patch #274): att1 `respawn_interleave` FAIL 6.822s 97 ticks/6s, twin PASS 6.809s in the same window; att2 (same sha, `rerun --failed`) BOTH twins FAIL — 88 and 97 ticks/6s, ordinals 1652/1655 | **LIGHT-POOL STARVATION OF A HEAVY-QUALIFYING BINARY — a classification miss, not the assert's m...\n 47|| `spt::attach_link_push_e2e attachment_frames_reach_a_linked_shell_through_the_real_daemon` — clause 5 re-link snapshot | 1× Windows Phase B, golden [34017906638](https://github.com/BigscreenVR/spt-bs-core/actions/runs/34017906638), job [101447073928](https://github.com/BigscreenVR/spt-bs-core/actions/runs/34017906638/job/101447073928), sha `04e32c8c`: `changed=Some(node)` where the re-link snapshot requires `None` | **TEST ORDERING RACE:** spawning `rc --view` did not prove attachment before `bind(t...\n 48|| `spt-store::wtlock_two_process_int two_processes_commit_into_one_worktree_without_failing` — ARM1 contention | Loaded golden Windows observation (doyle report, run `34017906638`): a waiter caught no acquisition gap within the 10s production bound while the other child continued committing | **UNFAIR SENTINEL, WAITER LOSES GAPS UNDER LOAD; BOUND 10s SIZED FOR ONE OP.** Starvation is probabilistic: the owner can reacquire between its back-to-back commits, but the waiter can also catch a gap before that...\n...\n 52|| `spt-daemon::mesh_recovery roster_route_survives_a_transient_dial_failure_with_discovery_disabled` — \"never converged: roster route converged after the transient\" (`mesh_recovery.rs:97` at `25e60015`; `converge()` = 600 × 25 ms = 15.0 s wall-clock budget) | 1× hfenduleam Windows golden, #272 WEBSERVE r2 run 34262154550 attempt 3 (2026-09-09 00:43:52Z, job 102283894969, Phase B serialized, cell 15.715 s, 233/234). Same cell PASSED at the same sha on attempts 1 and 2 (9.801 s, 7.172 s). | **BOX CONTE...\n*53|| `spt-daemon::registry_lifecycle oneway_rounds_plateau_rows_seats_and_a_refresh_replays_nothing` — \"the refresh must subscribe NO historical rows (zero replay churn): held 0 -> 1, seats 1\" (`registry_lifecycle.rs:514` at `25e60015`; the directional held/seats assertion after the gen-2 refresh) | 1× hfenduleam Windows golden, #272 WEBSERVE r2 run 34262154550 attempt 4 (2026-09-09 02:36Z, job 102306494097, Phase B serialized, cell 11.594 s, 233/234). Same cell PASSED at the same sha on attempts 1-3 (10...\n 54|| `spt-daemon::twohost two_host_ladder_role_a` — \"A-3 setup suspend applied an edge at B: NoEdge\" (`twohost.rs:2496` at `25e60015`; the rung asserts `matches!(out, RestRequestOutcome::Edge(_))` on the wire reply) | 1× golden twohost-a (hfenduleam role A / kitsubito role B), #272 WEBSERVE r2 run 34262154550 attempt 4 (2026-09-09 02:44:22Z, job 102316461906, 19.95 s; twohost-b job 102316461873 then burned its 900 s on the wake anchor A never sent — collateral, one transaction). The same rung PASSED at...\n 55|| `spt::webserve_attachment_e2e an_attachment_is_snapshot_served_fetched_back_and_named_by_its_message` — ARM 12 \"the attachment this arm just registered is not in the registry\" (`webserve_attachment_e2e.rs:612` at `25e60015`) | 1× hfenduleam Windows golden, #272 WEBSERVE r2 run 34262154550 attempt 2 (2026-09-08 20:33:40Z, job 102216542171, Phase B serialized, cell 11.733 s, 233/234). The emitter's OWN comment records an earlier occurrence at ttl 1 s during lane development (one red then a pass), wide...\n 56|| `spt::webserve_attachment_e2e an_attachment_is_snapshot_served_fetched_back_and_named_by_its_message` ARM 11 — `webserve_attachment_e2e.rs:551` \"each attachment registered its OWN entry\" left 4 right 5 | Windows at c4919243/tree be2184af: 4 reds in 15 runs (x5: FAIL 14.591 s; x10: FAIL runs 4/8/9 at 17.707/22.834/24.498 s), every red exactly -1; fastest run of 15 is a red, slowest a pass — no elapsed correlation. Linux 5/5 at 9.9 s flat (window proportionally smaller; not evidence of absence). | **...\n## GOLDEN-CI.md\n 25|\n*26|## Shared-runner quiet-window predicate\n 27|\n 28|<!-- [doc->REQ-GOLDEN-CI-LANE] -->\n 29|\n## INFRA-REGISTER.md\n 14|builder load; resident_service_e2e :664 ledgered leak row, 3rd occurrence) — the quiet-box arm is\n*15|IR-76's origin. Enumeration by a read-only subagent into `REGISTER-SWEEP-0671-DRAFT.md` (75\n 16|entries, 10 trigger-text candidates; IR-31 has NO `###` heading — its body sits under IR-30's,\n 17|flagged, not normalized). Rulings: **IR-46 trigger FIRED and was MISSED** — `golden.yml` was\n 18|touched by `04e32c8c` itself (2-line HEAVY reclass on the respin) and no remedy was weighed; a\n...\n 21|(8 literal-first sites) as ONE hertz workflow rider on WEBSERVE** (`ci.yml`/`golden.yml`/\n*22|`release.yml`, thin PR off the golden path, before the WEBSERVE golden head so that head runs\n*23|under it); **IR-59's log-the-floor line ALSO rides IR-76's three-arm pre-flight on W0's driver\n 24|template** (todlando authors; free space recorded beside the floor check). **IR-66 residual (two\n 25|first-chunk-needle members) = hertz WEBSERVE test rider** (two one-line edits). **IR-12 residual =\n 26|W3 drift-gate rider** (hertz already holds W3's drift-gate riders). IR-67 satisfied at this intake\n...\n 141|landed in this commit rather than as entries: the first-execution-cells intake question\n*142|(RELEASE-RUNBOOK golden-head intake — name the never-executed cells before the run) and\n 143|deployah's sweep-vs-cascade mechanism (RELEASE-RUNBOOK board step — under golden CI the cascade\n 144|is DRIVEN via `state <mref> acceptance`, never swept). ⚠ LABELLED HOLE — CLOSED UNDERIVABLE\n 145|(2026-08-19): the close commune's batch list named \"alchemy create-races\"; its content did not\n...\n 182|  carried by `bf8c4a2` → `REQ-CI-LINK-HEALTH-PROBE`, mapping CONFIRMED by builder hertz 2026-08-03\n*183|  (by content: tailscale ping ×5, med/max RTT rows into the bench ledger, three arms\n 184|  success/NO-REPLY/UNAVAILABLE, always exit 0 — instrument, not gate). NOTE `bf8c4a2` is NOT\n 185|  single-purpose: it also corrects the free-space preflight floor read\n 186|  (`REQ-CI-FREE-SPACE-PREFLIGHT`, the ci-runner-has-no-warm-target shape) — no 1:1 commit→IR map\n...\n 1480|- **Status:** open · **Origin:** doyle 2026-08-03, found while gating LOCKSMITH tranche 1 in an\n*1481|  isolated worktree; chased to a mechanism and scoped OUT of the release path before the head was\n 1482|  assembled.\n 1483|- **MEASURED, four arms, same box, same hour, matched load** (a second `cargo test -p spt-store\n 1484|  --lib` loop running throughout; `spt-store` itself stayed green in every round, so the box was not\n...\n 1653|  how the v0.51.0 fabricated-red class starts.\n*1654|- **CLAIM-OBSERVABILITY, MEASURED (hertz, 2026-08-04, three-arm rig with competence control):** a\n 1655|  displaced claimant CANNOT distinguish takeover from never-claimed — the two states are byte-identical\n 1656|  on disk (arm 1 vs arm 2 identical; arm 3 proves the rig separates states that differ, so the null is\n 1657|  real). The takeover is silent on BOTH sides: the taker's `pool-claim` prints ordinary success naming\n...\n 1665|  3-4 rebases):** a lane DELIVERING claim-identity cannot claim its own pool WITH that identity until\n*1666|  it lands — the prebuilt origin/main `xtask.exe` writes old-shaped stamps (owner_tree, lane_label,\n 1667|  holder pid+stamp; no lane_branch, no lane_base). Enforcer turnover surfacing at CLAIM time rather\n 1668|  than build time: coverage grows only as trees turn over. Recorded because it reads as a bug the\n 1669|  first time someone meets it in the field. Related lane-craft fact from the same queue: a rebase\n...\n 1673|- **Bootstrap property FIELD INSTANCE, main checkout (todlando 2026-08-04, IR-12 rig):** the\n*1674|  prebuilt `target/debug/xtask.exe` in the MAIN checkout pool was stale against main's own source\n 1675|  at `11169c1` — it printed `(holder pid …, born …)` and wrote a FLAT identity-less claim\n 1676|  (owner_tree/lane_label/holder_pid/holder_started_at/written_by) where main's source\n 1677|  (main.rs:2282) prints `(branch …, base …; advisory holder pid …)` and writes the nested lane.\n...\n 1971|  TRUTHFULLY on a box that cannot run its own work, because the reclaimable population and the\n*1972|  owned-lane population are DISJOINT.** This hazard blocked a release twice before it was seen.\n 1973|  Both Windows legs at the shipped sha `86f0d84` refused at the guard before compiling anything —\n 1974|  `ci.yml` at `free_bytes=28167569408` (26.2 GiB) and `release.yml` at `27690885120` (25.8 GiB),\n 1975|  both against `floor_bytes=34359738368`. `assemble` skipped in consequence, so no draft release\n...\n 2002|  minutes later — it drifted 2.26 GB DOWNWARD while the operator was deciding what to do about it.\n*2003|  **Priced side effect, for the next reader:** reaping the main pool took the prebuilt `xtask` with\n 2004|  it, so the next lane claim rebuilds it first — the lane-check shortcut is cold until then. It cost\n 2005|  a 2m11s cold rebuild inside this release's own publish step.\n 2006|  **What this does NOT license:** reaping another agent's owned lane to clear a floor. The sweep's\n...\n 2915|  than discovered later:** the two golden steps the lane ADDS (link probe on both boxes, toolchain\n*2916|  print on both legs) cannot be exercised outside a golden run. The probe's three arms\n 2917|  (five-sample success, no-reply, absent-CLI) were exercised on the real boxes at commit time, and\n 2918|  that is reported as a CLAIM RECORDED AT COMMIT TIME, not as a re-verification — the kitsubito arm\n 2919|  could not be re-checked from here. This is why the lane wants a golden rather than a quiet ff.\n...\n 3834|\n*3835|### IR-76 — hfenduleam is the golden Windows runner AND the builders' box: a local workspace nextest fully contained a golden Phase A and manufactured a load-timing red, and the job-start census cannot see it\n 3836|\n 3837|- **Status:** OPEN, filed by doyle 2026-09-06 during v0.67.1 golden triage (run 34017906638\n 3838|  att2). · **Origin:** the Windows Phase A red on\n...\n 3870|  place foreign load from the log alone; (d) the golden hand-off contract\n*3871|  (docs/golden-head-intake) states the quiet-window rule once.\n 3872|- **Kin:** [[IR-63]] (random victim per sweep), [[IR-59]] (box conditions the preflights\n 3873|  never see), [[IR-64]] (hfenduleam's non-CI payload), FLAKE-LEDGER rows for\n 3874|  `wtlock_two_process_int` and `attach_link_push_e2e` (2026-09-06).\n...\n 4644|  first 3 lines) is printed into the driver log, so the classification is auditable after the fact\n*4645|  rather than inferred from what got bucketed. Exercised standalone on all three arms: real\n 4646|  `netsh` = exit 1 + `No rules match` -> ABSENT; forced bad args -> PROBE-FAILED; empty stdout ->\n 4647|  PROBE-FAILED.\n 4648|\n...\n 4656|  and an empty-but-correct result is reported non-zero by a great many tools. A third value added\n*4657|  to a probe needs its own evidence, obtained by making all three arms fire on purpose — which is\n 4658|  this lane's standing rule that a tool whose success path has never been made to fail on purpose\n 4659|  is untested, applied to a tool's FAILURE path instead.\n 4660|\n...\n 4831|     place (the 2026-06-03 handoff.rs ConPTY stall, 22 unbounded hosted minutes).\n*4832|- **Kin:** [[IR-76]] (the golden runner IS the builders' box — the structural reason a desktop's\n 4833|  load reaches CI at all), [[IR-64]] (box-level facts only the operator can move), [[IR-89]] (the\n 4834|  other elevated box-rule ask), `defender-first-touch-tax-on-fresh-test-binaries` and\n 4835|  `e2e-leaked-daemons-shared-box` (memory).\n...\n 4928|  exited (a later A pass would be vacuous).\n*4929|- **Kin:** [[IR-76]] (hfenduleam is golden runner AND builders' box; the job-start census cannot\n 4930|  see a competing GitHub run either), [[IR-62]] (rig collisions on shared runners), the W1 two-host\n 4931|  rig, `a-barrier-cannot-ride-a-carrier-its-sender-outlives` (memory, same family: a barrier needs\n 4932|  the receiver's own answer).\n...\n 4978|  undoes part of the reap and leaves the recorded free reading stale.\n*4979|- **Remedy shape:** either (a) `pool-release` documented and scripted as a PREBUILT `xtask.exe`\n 4980|  invoked against `--pool <dir>` from another pool, or (b) the verb refuses when its own\n 4981|  `CARGO_TARGET_DIR`/default target equals `--pool` and prints the prebuilt form, or (c) the reap\n*4982|  recipe orders release BEFORE the subtree delete. Memory banked 2026-09-08\n 4983|  (`pool-release-rebuilds-xtask-into-the-pool-you-just-reaped`); this entry is the durable home.\n 4984|- **POSITIVE CONTROL (hertz, 2026-09-09, ruling-3 gate-r3 teardown):** the same release run\n## KNOWN-HAZARDS.md\n 79|<!-- [doc->REQ-SHELL-PERSISTENT-BOOT-RESTORE] -->\n*80|- **One process generation per read (releases#287):** modern `shell.launch.json` atomically stores `pid`, native `pid_started_at`, and wall-clock `launched_ms`. A modern `pid: 0` means explicitly pidless/cleared and never falls back to the numeric `shell.pid` mirror. Legacy records without `pid` retain their old numeric-PID plus optional-birth read. Publish the complete JSON identity before updating the compatibility mirror; failed publication preserves the previous identity. Never delete the previous bi...\n 81|- **No spontaneous relaunch of a NONPERSISTENT same-boot death:** the releases#78 force-kill freeze still protects nonpersistent instances, so killing one to free its exe does not arm a watcher underneath an overwrite. Recovery remains demand-driven. **Persistent instances are exempt** (operator ruling, releases#287): a kill is not a request to keep a declared-persistent shell down; use `teardown` or a nonpersistent manifest instead.\n 82|- **Watcher eligibility:** recorded `offline`, no live binary awaiting bind, and either `persistent`, no corpse, or a corpse whose launch predates the machine boot instant. A nonpersistent corpse without a launch stamp or boot oracle remains frozen; persistent instances require neither to become eligible. Birth-safe probes prevent a recycled pid from masquerading as a live shell.\n 83|- **spt-core mapping:** `spt_store::shellinfo::{shell_pid_provably_dead, effective_status, is_shell_online}` (the resolver — the shell-side twin of 2.5's `liveness.rs`, which gave *agent* perches exactly this and which shells never got); consumers in `linkhost::{relink_shell, prepare_drive, run_action}`, `shelldisc::discover`, `activity::observe_links`; the class-(c) eligibility read is `spt_daemon::shellwake::watcher_eligible` (+ `launch_predates_boot`, `BOOT_RESTORE_SLACK_MS`), and the birth stamp it...\n...\n 347|- **Do NOT \"fix\" this with the spawn flag.** Flipping the rigs' `CommandNoWindowExt::no_window()` (`crates/spt/tests/common/mod.rs`) from `CREATE_NO_WINDOW` to `DETACHED_PROCESS` removes the conhost (measured: 1 → 0) but does **not** remove the pin (that conhost is never the holder — the `--headless` ConPTY exception above is a host no rig mints through this helper), and it breaks rigs outright per the 5.17 amendment: `job_escape_e2e::conhost_children_of` shells out to **powershell** through that ver...\n*348|- **Source:** hertz, releases#110 — filed diagnosis post-v0.51.0 (2026-08-01); mechanism re-measured and the conhost attribution **refuted** 2026-08-02 (per-parent conhost counts, box-wide conhost cwd census, orphan-grandchild positive control). doyle's live correction the same day supplied the live-shell half of the triage step. **The `--headless` exception is field evidence from todlando** (BAROMETER W4 teardown specimen, the direct-launch inheritance test, and the kill-order rig that excluded pty te...\n 349|\n 350|<!-- [doc->REQ-TEST-ENV-ONE-LOCK] -->\n 351|### 5.19 Two mutexes over one process-global env var guard nothing between them  `[REQ-TEST-ENV-ONE-LOCK]`\n...\n 585|- **Invariant:** `reconcile_hosted_liveness`, when it offlines a sessionless controllable perch (the B2 keystone — no live broker session ⇒ dead harness), ALSO clears `driven_by` (`set_driven_by(perch, None)`). RACE-FREE and single-writer-safe: with NO live broker session there is no controller to re-stamp `driven_by` concurrently, so the brain may write it here without contending the broker. (The LIVE-session leg — a controller gone while its session survives — is NOT this hazard: a clean discon...\n*586|- **MEASURED 2026-07-22 (DAEMON-LIFECYCLE W2 Leg B, `transport_death_eof.rs`) — the residual SPLITS in two, and only one half is still open.** On REAL QUIC (two brokers, `BindScope::Loopback` + a real `net_dial` — NOT the in-process duplex, which has no idle timeout at all), a remote controller whose QUIC STACK DIES WITHOUT A FIN (peer frozen: endpoint alive, UDP port still bound, keepalives unanswered — the sleeping-laptop shape) DOES self-heal: the transport's own idle timeout tears the conn, the...\n 587|- **Watch-out (repro-proven, real broker):** `SessionInfo.controller_by==None` is AMBIGUOUS — `dispatch_spawn` pre-attaches the spawner as the LOCAL controller with `by=None`, so a live LOCALLY-driven session also reads `None`. It is therefore NOT a usable standalone `driven_by` clear trigger (would false-clear a live local session). The shipped Gap-B self-heal needs no controller signal at all (it keys on session ABSENCE).\n 588|- **spt-core mapping:** impl `livehost.rs` `reconcile_hosted_liveness` Gap-B clear + the additive `SessionInfo.controller_by` observability field (`msg.rs`, populated in `broker.rs` `KIND_SESSIONS`); unit `livehost.rs` `pull_liveness…` extended (offlined sessionless perch clears `driven_by`; live/relay perches untouched); int `crates/spt-daemon/tests/driven_by_selfheal.rs` `gap_b` (real broker: reconcile offlines AND clears `driven_by`) + the A1/A2 characterization (`inject_control_wedge.rs` w5_a1/w5_a2).\n 589|- **Cross-ref 7.29 (who MAY clear vs who MUST NOT):** the BRAIN reconcile here MUST NOT clear `driven_by` off `controller_by==None` (ambiguous with a live LOCAL controller). The BROKER stamp-convergence (7.29) MAY — it reads `has_controller()` DEFINITIVELY (its own controller slot), so it authoritatively clears a stale `driven_by` against a live session with no controller (the `has_controller()==false` leg). The invariant's owner for that leg moved to the broker; this brain-side ambiguity-safety is unc...\n...\n 873|<!-- [doc->REQ-BROKER-ZOMBIE-IDENTITY] -->\n*874|- **Zombie-reap kill boundary (releases#285):** `broker.rs` captures the PTY root's creation time before starting its exit waiter; a later zombie verdict alone never licenses killing that remembered number. Fresh death or a different live birth proves the remembered child gone and permits cleanup without a signal; only a matching live birth permits tree-kill. `SPAWN_ZOMBIE_REAP_RECYCLED` identifies both births before de-tabling and clearing stale stamps so respawn can proceed. Unknown identity still emit...\n 875|- **Source:** DAEMON-LIFECYCLE W1 (ADR-0047 decision 1; hertz field RCA bug 1).\n 876|\n 877|### 7.52 An operator stop outranks every implicit ensure — no convenience path resurrects what the operator just killed  `[REQ-HAZARD-STOP-RESPAWN-CONVOY]`\n...\n 989|<!-- [doc->REQ-HAZARD-WIRE-UNTAGGED-RECORD] -->\n*990|- **Failure (caught in design, W4 T10 / releases#53 — before it shipped, by asking what an N-1 daemon actually does rather than assuming it would simply not understand):** the stream dispatcher classifies a feed by sniffing its FIRST LINE, and the message family is deliberately **untagged** — `classify_first_line` reads any first line carrying `target` + `op_id` with no `kind` as `StreamFamily::WanMsg`. A newly minted record type that omits a `kind` tag is therefore not \"unrecognized\" on an older pee...\n 991|- **Invariant:** every wire record minted from here on carries a `kind` tag routed by its own tagged arm, so an older daemon's `Some(_)` catch-all resolves it to `StreamFamily::Unknown` and DROPS it cleanly. The correct degrade for a request an old peer cannot serve is that it **never arrives** — never that it arrives as something else. A record whose absence is silent is recoverable; a record delivered as the wrong kind is not.\n 992|- **Proof obligation — three parts, or the pin goes vacuous:** (a) this version routes the record to its own family, AND is asserted NOT to route it to the message family; (b) the same bytes under a tag this version does not know resolve to `Unknown`; (c) the untagged shape is asserted to genuinely BE claimed by the message arm. Without (c) the test passes for the wrong reason the day the record's fields drift such that it would no longer have collided — the guard would then be measuring nothing whil...\n 993|- **spt-core mapping:** `spt-net/src/net/knockmsg.rs` (`KNOCK_KIND`, the tag on `KnockRecord`); `spt-daemon/src/dispatch.rs` `classify_first_line` (the tagged arm) + `StreamFamily::Unknown` (the clean drop); unit `a_knock_record_routes_here_and_drops_cleanly_on_an_n1_daemon` (all three parts, against the real classifier).\n...\n 1031|- **spt-core mapping:** `spt/src/roster.rs` `match_self_by_ancestry` (distinct-id refusal) + `warn_ambiguous_ancestor_once`; `spt/src/cli.rs` the send site whose `unwrap_or(--from)` fallback makes `None` the accurate answer; `spt/tests/io_events_undriven_kinds_e2e.rs` `bind_endpoint`/`rig` (distinct live owners). Units: `an_ambiguous_ancestor_resolves_to_none_in_either_candidate_order`, `one_perch_matching_on_both_its_pids_still_resolves`, `ambiguity_is_scoped_to_the_nearest_ancestor`.\n*1032|- **Source:** releases#240, filed off the CONDUIT #236 respin RCA (todlando instrument on kitsubito + Windows control on hfenduleam; doyle-ruled fix shape — a named refusal over a silent guess; deployah pre-registered the ship branches before the classification landed). Kin 7.34 (the dead `rec.pid` class this ambiguity rides on), 7.63 (a key narrower than the identity of what it addresses).\n 1033|\n 1034|---\n 1035|\n## MANIFEST.md\n 747|\n*748|**Trust — optional signing, fail-closed.** With no `signing_key`, the fetched `.spt` is trusted on HTTPS + GitHub (the same first-acquisition trust `spt adapter add --release` and the installer's first binary fetch place). With a `signing_key`, the fetched `.spt` is verified against a **detached signature** the author publishes as a sibling release asset named `<asset>.sig` — a lowercase-hex Ed25519 signature over the raw archive bytes. Verification runs **after** the bytes are staged and **before** ...\n 749|\n 750|Validation requires `repo` for `gh_release` (`asset` and `signing_key` optional). `spt adapter add` reuses this section as the **install** mechanism (install is the first update; `--github <user/repo>` fetches the manifest first, then installs via the declared `avenue`). `uninstall` (optional) is its inverse, fired by `spt adapter remove` (soft-deregister; runs when no instance is live under the adapter, or immediately with `--force`). Absent `uninstall` ⇒ spt-core's default cleanup (drop its copy for ...\n 751|\n## MUSL-RELEASE-HANDOFF.md\n 16|## Watch-fors\n*17|- update-set stale-serve window ([[release-updateset-stale-window]]): upload-before-flip covers the musl entry.\n 18|- CI flake NOT to be spooked by: `inject_control_wedge::wan_arrival_to_idle_spt_hosted_injects_with_no_hook_poll` is a Windows-box-timing flake on the 80ms inject settle-window (untouched by W3, PASS on kitsubito, green in v0.29.1). If the hfenduleam test leg trips it, sweep leaked `spt.exe` (scoped) + rerun `--failed` — do NOT read it as a musl regression.\n 19|\n 20|Questions → doyle. gnu is unchanged; musl is purely additive.\n## MUSL-W3-DISPATCH-RULING.md\n 38|- **CI runner contention** ([[seedmap-test-collides-live-daemon]]): kitsubito is the musl BUILD box AND a gnu CI runner — a musl build job racing a gnu test job on the same box can leak/contend. Sequence the matrix or scope the daemon sweep; a Phase-A e2e daemon-timeout on kitsubito is contamination, not a musl regression (W2 CI hit exactly this — rerun cleared it).\n*39|- update-set **stale-serve window** ([[release-updateset-stale-window.md]]): upload-before-flip holds for the musl entry too.\n 40|\n 41|Co-authored by: doyle\n## NEXT-MILESTONE-BUG-TRIAGE.md\n 182|`claude-spt 0.9.0→0.9.2`: fetch OK, unsigned-trusting OK, LIVE daemon-coordinated apply, then `ADAPTER_UPDATE_FAIL:claude-spt: re-register: io: The system cannot find the file specified. (os error 2)`. The post-extract re-register step can't find a file — likely the extracted adapter root path or a manifest-referenced binary/install_dir. Class: adapter update ripple / install-dir resolve (cf. F-019 translation install-dir, REQ-HAZARD-DEFERRED-MANIFEST). perri-adjacent (claude-spt v0.9.2).\n*183|- **Root cause (agent G, conf H): SPT-CORE DEFECT (3 coupled), NOT perri packaging, NOT coupled to #16.** Chain: update writes to HARDCODED `_github/{safe}` dest (cli.rs:7674) ignoring the adapter's registered source_dir — claude-spt was plugin/sptc:setup-installed, NOT via `adapter add --release`, so `create_dir_all(dest)` makes a FRESH EMPTY dir. `adapter_has_live_endpoint` (cli.rs:7394/7407) scans on-disk perch info.json parent-prefix → eel-a alive → routes to `apply_release_via_daemon` (ADAPTER...\n 184|\n 185|## REOPENS (new evidence refutes/extends prior diagnosis)\n 186|\n## RELEASE-RUNBOOK.md\n 348|\n*349|   The older dedicated-release-PR rule applied before milestone-batch golden CI,\n 350|   when that PR's own full CI could validate the tagged commit. It cannot be\n 351|   carried forward into an ff-only lane whose golden run is the full-suite\n 352|   authority.\n...\n 463|   next milestone would branch from stale code. The gap became visible only\n*464|   because the release driver published the exact commands for review before\n 465|   running them: his local fast-forward never pushed.\n 466|\n 467|   ```sh\n...\n 558|\n*559|   Before invoking local Cargo, enter a quiet window: the golden run, the thin\n 560|   main `ci.yml` run fired by step 3, and the tag's `release.yml` run must all\n 561|   be terminal. This wait is about **box occupancy**, not the thin run blessing\n 562|   the SHA: golden remains the full-suite authority. Required golden evidence\n...\n 612|   - **Do not re-escalate it per release.** The finding was raised at the\n*613|     v0.43.0 cut (release driver stopped before signing) and ruled then.\n 614|     Re-raising it at each cut changes nothing and costs a release window.\n 615|     Revisiting the ruling is an operator decision, never a release-driver\n 616|     block.\n\n## adr/\n### 0015-release-signing-two-key-trust-anchor.md\n 13|\n*14|- Releasing is a partly manual ceremony: CI builds artifacts; the maintainer signs the release metadata locally before publishing.\n 15|- The signed metadata published with each release must be in the exact `SignedRelease` format the self-updater consumes, from v0.1 onward.\n### 0024-multi-platform-adapter-spt-packaging.md\n 12|\n*13|An adapter that updates via the `gh_release` avenue is fetched as a single release asset, `adapter.spt` — a tar whose root holds `manifest.toml` + `strings/` + the role binaries, extracted flat into the adapter's `install_dir`, where bare program tokens resolve `<install_dir>/<program>` before `PATH` (REQ-INSTALL-11). That format is **single-platform**: one archive carries one OS's binaries. A cross-platform adapter (e.g. a harness integration shipping a Windows `.exe` and a Linux ELF for its translati...\n 14|\n 15|spt-core's own binary already solves cross-platform distribution with **platform-targeted update sets** (ADR-0016): per-triple *separate* artifacts, one signed set-metadata blob with per-platform digests, and each recipient fetches only its own platform's bytes. That model is bandwidth-optimal at fleet scale but heavier for an adapter author: multiple artifacts plus signed set metadata, for what is often a few kilobytes of binary.\n 16|\n### 0050-golden-ci-merge-integration.md\n 52|\n*53|The omission became visible because the release driver published his exact commands for review before running them: his first step fast-forwarded only a local branch and no later step pushed `main`. **Retired-host side-effect rule: when you retire a mechanism, enumerate its side effects and re-home each one—the work and the sentence that explains the work.** This retirement lost both in opposite directions: a responsibility vanished with its host (the release-PR merge stopped advancing `main`, and no s...\n 54|\n 55|A third paid precedent completes the class in the other direction: the name `docs-publish.yml` outlived the workflow itself after its docs step moved into `release.yml`, so a release driver followed the stale runbook name and waited for a workflow that could never appear (the documentation drift repaired for PR #113). The three failures are distinct consequences of one missing retirement inventory: responsibility vanished with its host, a surviving by-product lost the sentence that gave it meaning, and a...\n 56|\n\n## design/\n### RIDER-65S-DESIGN.md\n 131|arm at a time, and every test aimed at a still-complying arm reports the convention as held. Two of\n*132|three arms named the key here, so the defect was invisible to any cell but the one that happened to\n 133|exercise the third — my four cells caught it by luck, not by coverage. The cell converts \"we name\n 134|our refusals\" from a sentence in a doc-comment into something the suite refuses to let lapse, and\n 135|it fails on the NEXT arm someone adds rather than on the next person to read the file.\n\n[Some lines truncated to 512 chars]"}],"details":{"scopePath":"docs, AGENTS.md, .github/bench","searchPath":"C:\\Users\\decid\\Documents\\projects\\spt-core","cwd":"C:\\Users\\decid\\Documents\\projects\\spt-core","matchCount":47,"fileCount":17,"files":["docs/BROKER-BRAIN-SPLIT-RESTORATION.md","docs/DEFERRED.md","docs/FAULT-MATRIX.md","docs/FLAKE-LEDGER.md","docs/GOLDEN-CI.md","docs/INFRA-REGISTER.md","docs/KNOWN-HAZARDS.md","docs/MANIFEST.md","docs/MUSL-RELEASE-HANDOFF.md","docs/MUSL-W3-DISPATCH-RULING.md","docs/NEXT-MILESTONE-BUG-TRIAGE.md","docs/RELEASE-RUNBOOK.md","docs/adr/0015-release-signing-two-key-trust-anchor.md","docs/adr/0024-multi-platform-adapter-spt-packaging.md","docs/adr/0050-golden-ci-merge-integration.md","docs/design/RIDER-65S-DESIGN.md","AGENTS.md"],"fileMatches":[{"path":"docs/BROKER-BRAIN-SPLIT-RESTORATION.md","count":1},{"path":"docs/DEFERRED.md","count":2},{"path":"docs/FAULT-MATRIX.md","count":2},{"path":"docs/FLAKE-LEDGER.md","count":2},{"path":"docs/GOLDEN-CI.md","count":1},{"path":"docs/INFRA-REGISTER.md","count":20},{"path":"docs/KNOWN-HAZARDS.md","count":6},{"path":"docs/MANIFEST.md","count":1},{"path":"docs/MUSL-RELEASE-HANDOFF.md","count":1},{"path":"docs/MUSL-W3-DISPATCH-RULING.md","count":1},{"path":"docs/NEXT-MILESTONE-BUG-TRIAGE.md","count":1},{"path":"docs/RELEASE-RUNBOOK.md","count":4},{"path":"docs/adr/0015-release-signing-two-key-trust-anchor.md","count":1},{"path":"docs/adr/0024-multi-platform-adapter-spt-packaging.md","count":1},{"path":"docs/adr/0050-golden-ci-merge-integration.md","count":1},{"path":"docs/design/RIDER-65S-DESIGN.md","count":1},{"path":"AGENTS.md","count":1}],"truncated":true,"perFileLimitReached":20,"displayContent":"# AGENTS.md\n 40│- **Build-cache pools (binding, releases#103):** a cargo `target/` directory belongs to ONE source tree. Two trees building into one pool overwrite each other's artifacts and fabricate reds that belong to neither — the v0.51.0 W1/H1 `E0308` that vanished on re-run. **The rule is about the RELATIONSHIP, not the path:** a junction and a `CARGO_TARGET_DIR` env var reach the same hazard, and the env var leaves no directory entry to notice afterwards, so \"is this dir under `.worktrees/`\" never was the quest...\n*41│- **Target-tree teardown (releases#103, same lane):** never delete a `target/` you have not classified. Check OUTBOUND first (`Get-Item -Force`: a junction is deleted as a link, a real dir as a tree), then sweep INBOUND for reparse points aimed at it before removing a real one, and measure size and free space before and after so the reclaim is a number rather than a claim. Reap the target SUBTREE, never a session or worktree directory around it. Do not point `CARGO_TARGET_DIR` into a scratchpad (v0.50.0 ...\n 42│- **CI / merge strategy:** golden CI (ADR-0050, ruled 2026-07-27) — milestone-batch golden runs, thin-lane PRs, ff-only main (tested sha == merged sha). Piloting from the next milestone; read the ADR before shaping a PR lane.\n 43│\n 44│If you finish a significant body of work without need for user intervention, or if your context gets too high, you can clear your own context and keep moving:\n\n# docs/\n## BROKER-BRAIN-SPLIT-RESTORATION.md\n 171│\n*172│**[V1] Rollback-state-compat invariant (forward invariant, mint this milestone).** Auto-rollback spawns the **old** binary against durable state the **new** brain may already have written. This is safe *today* (a source audit confirmed zero state-migration code exists), but the first release that migrates a durable-state schema would silently break Q7's rollback. The invariant must be minted now, while it is free: **a brain must not irreversibly migrate durable state before ready-promotion** — equivale...\n 173│\n 174│**Reason.**\n 175│- The dangerous case is a *runtime* bug (new brain panics on boot), not the binary land (already rolled back at `applyhost.rs:167-170`) and not IPC mismatch (the `classify` handshake `brain_ipc_version ≥ broker.min_compatible` is checked pre-swap). A naive supervisor would crashloop the new binary: endpoints alive but logic dead — \"up but useless.\"\n## DEFERRED.md\n 37│| **Origin-source update bootstrap (`spt update fetch` — pull the latest signed release from GitHub into the existing verify→stage→apply pipeline)**: today update DISCOVERY is **peer-only** (REQ-UPD-1: a daemon pulls offers from roster peers via `request_update`; `propagate.rs`/`peerloop.rs`). There is NO origin fetch, so the **first node in a fleet — or any isolated/solo node — cannot get a new release without a peer that already staged it** (the fleet converges by gossip, but only *after* a m...\n*38│| **Test broker socket-bind hardening (CI-flake removal)**: `applyhost` tests' `served_broker` helper does `Broker::bind(name).expect(\"bind broker\")` (`crates/spt-daemon/src/applyhost.rs:293`) where `name` = `spt-daemon-d7b-{pid}-{seq}.sock`. Flakes intermittently on the **kitsubito** self-hosted Linux runner (likely AF_UNIX path collision / stale socket file under the runner's reused workspace — Windows named pipes don't hit it). Cost the v0.3.2 release a full red CI run + a `--failed` rerun (2026-06-...\n*39│| **`spt update fetch` single→set shape-upgrade at same version (REQ-UPD-8 transitional trap)**: `cmd_update_fetch` sets the rollback floor = `staged_version` (the monotonic counter), and the gate is a plain `candidate > floor`. A node that fetched+staged version N as a platform **single** (pre-0.3.2 fetch behavior) can never re-fetch version N as a multi-platform **set** — same counter → `Rollback{current:N, candidate:N}`. Bites the **seed-node bootstrap**: the first node to origin-`fetch` a relea...\n 40│| **On-disk `current_exe` reconcile after auto-rollback (the D6-2 reboot residual)**: readiness-gated auto-rollback (ADR-0018 Q7, restoration D6-2) is **record-driven selection** — after a rollback the broker's supervisor keeps spawning the last-known-good `.old-N` binary, chosen from the durable `RolledBack` record, so the rescue survives a reboot for free **with no file rename at the failure instant** (the brittle path the design rejected). But the bytes on disk at `current_exe` are STILL the quarant...\n 41│| **Quarantine operator override (`spt update apply --force` — the note-i escape hatch)**: D6-2's quarantine guard refuses re-applying a version that auto-rolled-back on this node (the `RolledBack` record is the marker; clears naturally when N+1 stages). But a version whose failure was **environmental** (a transient boot condition, not bad bytes) leaves the node **permanently allergic** to a genuinely-good version with no escape but staging a newer one. FIX = an explicit operator override (`spt update ...\n 42│| **✅ RESOLVED — shipped v0.8.3 (REQ-HAZARD-BROKER-QUIC-DEADLINE, KNOWN-HAZARDS 7.8).** ~~Broker-side bound on brain-waiting QUIC ops (the pump-IPC-deadline B-half)~~: the brain-side deadline (REQ-HAZARD-PUMP-IPC-DEADLINE, KNOWN-HAZARDS 7.6) stops the single-threaded pump wedging when a peer black-holes, by bounding the pump's brain-IPC reads and escalating a TimedOut to a supervised restart. But the ROOT cause is broker-side: the broker's `net_open_stream` / `net_stream_send` / `net_dial` handlers m...\n## FAULT-MATRIX.md\n 38│| 18 | **Compromised relay node serves a tampered update artifact** (bytes corrupted at rest after the relay's own verification) | That one pull ends `Rejected(ArtifactMismatch)` at the puller | The puller's staged release + running binary (nothing staged, nothing applied — no code path from wire bytes to the cache except through `plan_verified`); the rest of the subnet pulls from honest peers | Pull from another peer; the per-node gate (REQ-UPD-2) runs at **every** hop, so one poisoned node never re-p...\n*39│| 19 | **Non-conforming peer offers a rollback/expired/off-channel release** | None — rejected pre-fetch, zero artifact bytes move | The puller's version (monotonic floor holds); the wire (no transfer ever starts) | None needed — the offer-then-fetch shape gates metadata before bytes (REQ-HAZARD-UPDATE-ROLLBACK) | `tests/propagate.rs::rollback_offer_is_rejected_before_any_fetch` |\n 40│| 20 | **Untrusted node queries for the staged update** | None — refused by not offering (fail-closed, the up-to-date shape: learns nothing, not even whether a release exists) | The staged release; the serve loop (one refusal, no state) | None needed; pair the node to entitle it | `tests/propagate.rs::untrusted_origin_gets_no_offer` |\n*41│| 21 | **Stream lost mid-update-artifact** (responder dies / wire tears before `Done`) | That one pull errors at the requester | The requester's staged release (staging is atomic, artifact-then-metadata commit point — a torn pull stages nothing); the scratch file is transient | No resume protocol by design: re-query fresh — the query is idempotent and chunks are positional | torn-pull shape shared with row 14 (`request_update` errors on EOF-before-`Done`); staging atomicity: `relcache.rs::torn_or_cor...\n 42│\n 43│| 22 | **Psyche emits spoofed routing** (`<EVENT type=\"reply\" from=\"evil\" to=\"victim\">` on its stdout) | None — the spoof is structurally inert: the intent parser carries body only (attrs unrepresentable), the daemon re-stamps `from=<psyche_id>` and routes to the inbound message's structural sender (its `from`) alone | The spoof target (receives nothing); the wire (only daemon-authored envelopes); every other agent's identity | None needed (anti-spoof is structural + re-stamp, ADR-0012 / KH 7.3) | `psy...\n 44│| 23 | **Psyche replies with no inbound sender to answer** (alarm-fired turn emits a reply) | That one intent drops with a typed outcome (fail-closed — never broadcast, never guessed) | Every perch (zero deliveries); the notify leg (independent) | The Psyche's next answered turn replies normally | `psyrelay.rs::reply_without_target_is_dropped` |\n## FLAKE-LEDGER.md\n 44│| `spt::engine_room_bringup_e2e a_cleanly_offline_engine_room_is_still_brought_up_by_its_own_gate` — :1150 PRECONDITION (warm bring-up never spawns) | 3×/3 hfenduleam main-checkout pool (2026-08-17, main @27d40b9, agent env scrubbed, 186s each — consistent, not intermittent) | **TEST INFRASTRUCTURE DEFECT, not product evidence (IR-21/IR-39 class).** The clean main target had no `target/debug/mock-session.exe`: `cargo test -p spt` builds the `spt` test target but not another package's `mock-adapter` ...\n*45│| `spt-daemon daemon::tests::a_tree_teardown_reaches_a_grandchild_the_service_spawned` | 2× hfenduleam Windows golden: 10.176s run 30776330383 @184f2ac (2026-08-03); 10.225s run 30873007187 att1 @4b37512 (2026-08-04) | **TWO mechanisms wearing one assert string — do not count as a cross-sha repeat** (doyle source verification 2026-08-04): red 1 was the bare-pid `provably_gone(grandchild)` poller reading a pid-reuse stranger — it is the cited motivating incident in the pin comment (daemon.rs:2726-273...\n 46│| `spt-daemon::brain_resume_conn_deadlock daemon_cursor_only_resume_keeps_heartbeat_live_respawn_interleave` (+ twin `…_steady_state` on att2) | 2× kitsubito Linux golden 34014574926 @34fdb848 (v0.67.1 docs-only patch #274): att1 `respawn_interleave` FAIL 6.822s 97 ticks/6s, twin PASS 6.809s in the same window; att2 (same sha, `rerun --failed`) BOTH twins FAIL — 88 and 97 ticks/6s, ordinals 1652/1655 | **LIGHT-POOL STARVATION OF A HEAVY-QUALIFYING BINARY — a classification miss, not the assert's m...\n 47│| `spt::attach_link_push_e2e attachment_frames_reach_a_linked_shell_through_the_real_daemon` — clause 5 re-link snapshot | 1× Windows Phase B, golden [34017906638](https://github.com/BigscreenVR/spt-bs-core/actions/runs/34017906638), job [101447073928](https://github.com/BigscreenVR/spt-bs-core/actions/runs/34017906638/job/101447073928), sha `04e32c8c`: `changed=Some(node)` where the re-link snapshot requires `None` | **TEST ORDERING RACE:** spawning `rc --view` did not prove attachment before `bind(t...\n 48│| `spt-store::wtlock_two_process_int two_processes_commit_into_one_worktree_without_failing` — ARM1 contention | Loaded golden Windows observation (doyle report, run `34017906638`): a waiter caught no acquisition gap within the 10s production bound while the other child continued committing | **UNFAIR SENTINEL, WAITER LOSES GAPS UNDER LOAD; BOUND 10s SIZED FOR ONE OP.** Starvation is probabilistic: the owner can reacquire between its back-to-back commits, but the waiter can also catch a gap before that...\n   │...\n 52│| `spt-daemon::mesh_recovery roster_route_survives_a_transient_dial_failure_with_discovery_disabled` — \"never converged: roster route converged after the transient\" (`mesh_recovery.rs:97` at `25e60015`; `converge()` = 600 × 25 ms = 15.0 s wall-clock budget) | 1× hfenduleam Windows golden, #272 WEBSERVE r2 run 34262154550 attempt 3 (2026-09-09 00:43:52Z, job 102283894969, Phase B serialized, cell 15.715 s, 233/234). Same cell PASSED at the same sha on attempts 1 and 2 (9.801 s, 7.172 s). | **BOX CONTE...\n*53│| `spt-daemon::registry_lifecycle oneway_rounds_plateau_rows_seats_and_a_refresh_replays_nothing` — \"the refresh must subscribe NO historical rows (zero replay churn): held 0 -> 1, seats 1\" (`registry_lifecycle.rs:514` at `25e60015`; the directional held/seats assertion after the gen-2 refresh) | 1× hfenduleam Windows golden, #272 WEBSERVE r2 run 34262154550 attempt 4 (2026-09-09 02:36Z, job 102306494097, Phase B serialized, cell 11.594 s, 233/234). Same cell PASSED at the same sha on attempts 1-3 (10...\n 54│| `spt-daemon::twohost two_host_ladder_role_a` — \"A-3 setup suspend applied an edge at B: NoEdge\" (`twohost.rs:2496` at `25e60015`; the rung asserts `matches!(out, RestRequestOutcome::Edge(_))` on the wire reply) | 1× golden twohost-a (hfenduleam role A / kitsubito role B), #272 WEBSERVE r2 run 34262154550 attempt 4 (2026-09-09 02:44:22Z, job 102316461906, 19.95 s; twohost-b job 102316461873 then burned its 900 s on the wake anchor A never sent — collateral, one transaction). The same rung PASSED at...\n 55│| `spt::webserve_attachment_e2e an_attachment_is_snapshot_served_fetched_back_and_named_by_its_message` — ARM 12 \"the attachment this arm just registered is not in the registry\" (`webserve_attachment_e2e.rs:612` at `25e60015`) | 1× hfenduleam Windows golden, #272 WEBSERVE r2 run 34262154550 attempt 2 (2026-09-08 20:33:40Z, job 102216542171, Phase B serialized, cell 11.733 s, 233/234). The emitter's OWN comment records an earlier occurrence at ttl 1 s during lane development (one red then a pass), wide...\n 56│| `spt::webserve_attachment_e2e an_attachment_is_snapshot_served_fetched_back_and_named_by_its_message` ARM 11 — `webserve_attachment_e2e.rs:551` \"each attachment registered its OWN entry\" left 4 right 5 | Windows at c4919243/tree be2184af: 4 reds in 15 runs (x5: FAIL 14.591 s; x10: FAIL runs 4/8/9 at 17.707/22.834/24.498 s), every red exactly -1; fastest run of 15 is a red, slowest a pass — no elapsed correlation. Linux 5/5 at 9.9 s flat (window proportionally smaller; not evidence of absence). | **...\n## GOLDEN-CI.md\n 25│\n*26│## Shared-runner quiet-window predicate\n 27│\n 28│<!-- [doc->REQ-GOLDEN-CI-LANE] -->\n 29│\n## INFRA-REGISTER.md\n   14│builder load; resident_service_e2e :664 ledgered leak row, 3rd occurrence) — the quiet-box arm is\n  *15│IR-76's origin. Enumeration by a read-only subagent into `REGISTER-SWEEP-0671-DRAFT.md` (75\n   16│entries, 10 trigger-text candidates; IR-31 has NO `###` heading — its body sits under IR-30's,\n   17│flagged, not normalized). Rulings: **IR-46 trigger FIRED and was MISSED** — `golden.yml` was\n   18│touched by `04e32c8c` itself (2-line HEAVY reclass on the respin) and no remedy was weighed; a\n     │...\n   21│(8 literal-first sites) as ONE hertz workflow rider on WEBSERVE** (`ci.yml`/`golden.yml`/\n  *22│`release.yml`, thin PR off the golden path, before the WEBSERVE golden head so that head runs\n  *23│under it); **IR-59's log-the-floor line ALSO rides IR-76's three-arm pre-flight on W0's driver\n   24│template** (todlando authors; free space recorded beside the floor check). **IR-66 residual (two\n   25│first-chunk-needle members) = hertz WEBSERVE test rider** (two one-line edits). **IR-12 residual =\n   26│W3 drift-gate rider** (hertz already holds W3's drift-gate riders). IR-67 satisfied at this intake\n     │...\n  141│landed in this commit rather than as entries: the first-execution-cells intake question\n *142│(RELEASE-RUNBOOK golden-head intake — name the never-executed cells before the run) and\n  143│deployah's sweep-vs-cascade mechanism (RELEASE-RUNBOOK board step — under golden CI the cascade\n  144│is DRIVEN via `state <mref> acceptance`, never swept). ⚠ LABELLED HOLE — CLOSED UNDERIVABLE\n  145│(2026-08-19): the close commune's batch list named \"alchemy create-races\"; its content did not\n     │...\n  182│  carried by `bf8c4a2` → `REQ-CI-LINK-HEALTH-PROBE`, mapping CONFIRMED by builder hertz 2026-08-03\n *183│  (by content: tailscale ping ×5, med/max RTT rows into the bench ledger, three arms\n  184│  success/NO-REPLY/UNAVAILABLE, always exit 0 — instrument, not gate). NOTE `bf8c4a2` is NOT\n  185│  single-purpose: it also corrects the free-space preflight floor read\n  186│  (`REQ-CI-FREE-SPACE-PREFLIGHT`, the ci-runner-has-no-warm-target shape) — no 1:1 commit→IR map\n     │...\n 1480│- **Status:** open · **Origin:** doyle 2026-08-03, found while gating LOCKSMITH tranche 1 in an\n*1481│  isolated worktree; chased to a mechanism and scoped OUT of the release path before the head was\n 1482│  assembled.\n 1483│- **MEASURED, four arms, same box, same hour, matched load** (a second `cargo test -p spt-store\n 1484│  --lib` loop running throughout; `spt-store` itself stayed green in every round, so the box was not\n     │...\n 1653│  how the v0.51.0 fabricated-red class starts.\n*1654│- **CLAIM-OBSERVABILITY, MEASURED (hertz, 2026-08-04, three-arm rig with competence control):** a\n 1655│  displaced claimant CANNOT distinguish takeover from never-claimed — the two states are byte-identical\n 1656│  on disk (arm 1 vs arm 2 identical; arm 3 proves the rig separates states that differ, so the null is\n 1657│  real). The takeover is silent on BOTH sides: the taker's `pool-claim` prints ordinary success naming\n     │...\n 1665│  3-4 rebases):** a lane DELIVERING claim-identity cannot claim its own pool WITH that identity until\n*1666│  it lands — the prebuilt origin/main `xtask.exe` writes old-shaped stamps (owner_tree, lane_label,\n 1667│  holder pid+stamp; no lane_branch, no lane_base). Enforcer turnover surfacing at CLAIM time rather\n 1668│  than build time: coverage grows only as trees turn over. Recorded because it reads as a bug the\n 1669│  first time someone meets it in the field. Related lane-craft fact from the same queue: a rebase\n     │...\n 1673│- **Bootstrap property FIELD INSTANCE, main checkout (todlando 2026-08-04, IR-12 rig):** the\n*1674│  prebuilt `target/debug/xtask.exe` in the MAIN checkout pool was stale against main's own source\n 1675│  at `11169c1` — it printed `(holder pid …, born …)` and wrote a FLAT identity-less claim\n 1676│  (owner_tree/lane_label/holder_pid/holder_started_at/written_by) where main's source\n 1677│  (main.rs:2282) prints `(branch …, base …; advisory holder pid …)` and writes the nested lane.\n     │...\n 1971│  TRUTHFULLY on a box that cannot run its own work, because the reclaimable population and the\n*1972│  owned-lane population are DISJOINT.** This hazard blocked a release twice before it was seen.\n 1973│  Both Windows legs at the shipped sha `86f0d84` refused at the guard before compiling anything —\n 1974│  `ci.yml` at `free_bytes=28167569408` (26.2 GiB) and `release.yml` at `27690885120` (25.8 GiB),\n 1975│  both against `floor_bytes=34359738368`. `assemble` skipped in consequence, so no draft release\n     │...\n 2002│  minutes later — it drifted 2.26 GB DOWNWARD while the operator was deciding what to do about it.\n*2003│  **Priced side effect, for the next reader:** reaping the main pool took the prebuilt `xtask` with\n 2004│  it, so the next lane claim rebuilds it first — the lane-check shortcut is cold until then. It cost\n 2005│  a 2m11s cold rebuild inside this release's own publish step.\n 2006│  **What this does NOT license:** reaping another agent's owned lane to clear a floor. The sweep's\n     │...\n 2915│  than discovered later:** the two golden steps the lane ADDS (link probe on both boxes, toolchain\n*2916│  print on both legs) cannot be exercised outside a golden run. The probe's three arms\n 2917│  (five-sample success, no-reply, absent-CLI) were exercised on the real boxes at commit time, and\n 2918│  that is reported as a CLAIM RECORDED AT COMMIT TIME, not as a re-verification — the kitsubito arm\n 2919│  could not be re-checked from here. This is why the lane wants a golden rather than a quiet ff.\n     │...\n 3834│\n*3835│### IR-76 — hfenduleam is the golden Windows runner AND the builders' box: a local workspace nextest fully contained a golden Phase A and manufactured a load-timing red, and the job-start census cannot see it\n 3836│\n 3837│- **Status:** OPEN, filed by doyle 2026-09-06 during v0.67.1 golden triage (run 34017906638\n 3838│  att2). · **Origin:** the Windows Phase A red on\n     │...\n 3870│  place foreign load from the log alone; (d) the golden hand-off contract\n*3871│  (docs/golden-head-intake) states the quiet-window rule once.\n 3872│- **Kin:** [[IR-63]] (random victim per sweep), [[IR-59]] (box conditions the preflights\n 3873│  never see), [[IR-64]] (hfenduleam's non-CI payload), FLAKE-LEDGER rows for\n 3874│  `wtlock_two_process_int` and `attach_link_push_e2e` (2026-09-06).\n     │...\n 4644│  first 3 lines) is printed into the driver log, so the classification is auditable after the fact\n*4645│  rather than inferred from what got bucketed. Exercised standalone on all three arms: real\n 4646│  `netsh` = exit 1 + `No rules match` -> ABSENT; forced bad args -> PROBE-FAILED; empty stdout ->\n 4647│  PROBE-FAILED.\n 4648│\n     │...\n 4656│  and an empty-but-correct result is reported non-zero by a great many tools. A third value added\n*4657│  to a probe needs its own evidence, obtained by making all three arms fire on purpose — which is\n 4658│  this lane's standing rule that a tool whose success path has never been made to fail on purpose\n 4659│  is untested, applied to a tool's FAILURE path instead.\n 4660│\n     │...\n 4831│     place (the 2026-06-03 handoff.rs ConPTY stall, 22 unbounded hosted minutes).\n*4832│- **Kin:** [[IR-76]] (the golden runner IS the builders' box — the structural reason a desktop's\n 4833│  load reaches CI at all), [[IR-64]] (box-level facts only the operator can move), [[IR-89]] (the\n 4834│  other elevated box-rule ask), `defender-first-touch-tax-on-fresh-test-binaries` and\n 4835│  `e2e-leaked-daemons-shared-box` (memory).\n     │...\n 4928│  exited (a later A pass would be vacuous).\n*4929│- **Kin:** [[IR-76]] (hfenduleam is golden runner AND builders' box; the job-start census cannot\n 4930│  see a competing GitHub run either), [[IR-62]] (rig collisions on shared runners), the W1 two-host\n 4931│  rig, `a-barrier-cannot-ride-a-carrier-its-sender-outlives` (memory, same family: a barrier needs\n 4932│  the receiver's own answer).\n     │...\n 4978│  undoes part of the reap and leaves the recorded free reading stale.\n*4979│- **Remedy shape:** either (a) `pool-release` documented and scripted as a PREBUILT `xtask.exe`\n 4980│  invoked against `--pool <dir>` from another pool, or (b) the verb refuses when its own\n 4981│  `CARGO_TARGET_DIR`/default target equals `--pool` and prints the prebuilt form, or (c) the reap\n*4982│  recipe orders release BEFORE the subtree delete. Memory banked 2026-09-08\n 4983│  (`pool-release-rebuilds-xtask-into-the-pool-you-just-reaped`); this entry is the durable home.\n 4984│- **POSITIVE CONTROL (hertz, 2026-09-09, ruling-3 gate-r3 teardown):** the same release run\n## KNOWN-HAZARDS.md\n   79│<!-- [doc->REQ-SHELL-PERSISTENT-BOOT-RESTORE] -->\n  *80│- **One process generation per read (releases#287):** modern `shell.launch.json` atomically stores `pid`, native `pid_started_at`, and wall-clock `launched_ms`. A modern `pid: 0` means explicitly pidless/cleared and never falls back to the numeric `shell.pid` mirror. Legacy records without `pid` retain their old numeric-PID plus optional-birth read. Publish the complete JSON identity before updating the compatibility mirror; failed publication preserves the previous identity. Never delete the previous bi...\n   81│- **No spontaneous relaunch of a NONPERSISTENT same-boot death:** the releases#78 force-kill freeze still protects nonpersistent instances, so killing one to free its exe does not arm a watcher underneath an overwrite. Recovery remains demand-driven. **Persistent instances are exempt** (operator ruling, releases#287): a kill is not a request to keep a declared-persistent shell down; use `teardown` or a nonpersistent manifest instead.\n   82│- **Watcher eligibility:** recorded `offline`, no live binary awaiting bind, and either `persistent`, no corpse, or a corpse whose launch predates the machine boot instant. A nonpersistent corpse without a launch stamp or boot oracle remains frozen; persistent instances require neither to become eligible. Birth-safe probes prevent a recycled pid from masquerading as a live shell.\n   83│- **spt-core mapping:** `spt_store::shellinfo::{shell_pid_provably_dead, effective_status, is_shell_online}` (the resolver — the shell-side twin of 2.5's `liveness.rs`, which gave *agent* perches exactly this and which shells never got); consumers in `linkhost::{relink_shell, prepare_drive, run_action}`, `shelldisc::discover`, `activity::observe_links`; the class-(c) eligibility read is `spt_daemon::shellwake::watcher_eligible` (+ `launch_predates_boot`, `BOOT_RESTORE_SLACK_MS`), and the birth stamp it...\n     │...\n  347│- **Do NOT \"fix\" this with the spawn flag.** Flipping the rigs' `CommandNoWindowExt::no_window()` (`crates/spt/tests/common/mod.rs`) from `CREATE_NO_WINDOW` to `DETACHED_PROCESS` removes the conhost (measured: 1 → 0) but does **not** remove the pin (that conhost is never the holder — the `--headless` ConPTY exception above is a host no rig mints through this helper), and it breaks rigs outright per the 5.17 amendment: `job_escape_e2e::conhost_children_of` shells out to **powershell** through that ver...\n *348│- **Source:** hertz, releases#110 — filed diagnosis post-v0.51.0 (2026-08-01); mechanism re-measured and the conhost attribution **refuted** 2026-08-02 (per-parent conhost counts, box-wide conhost cwd census, orphan-grandchild positive control). doyle's live correction the same day supplied the live-shell half of the triage step. **The `--headless` exception is field evidence from todlando** (BAROMETER W4 teardown specimen, the direct-launch inheritance test, and the kill-order rig that excluded pty te...\n  349│\n  350│<!-- [doc->REQ-TEST-ENV-ONE-LOCK] -->\n  351│### 5.19 Two mutexes over one process-global env var guard nothing between them  `[REQ-TEST-ENV-ONE-LOCK]`\n     │...\n  585│- **Invariant:** `reconcile_hosted_liveness`, when it offlines a sessionless controllable perch (the B2 keystone — no live broker session ⇒ dead harness), ALSO clears `driven_by` (`set_driven_by(perch, None)`). RACE-FREE and single-writer-safe: with NO live broker session there is no controller to re-stamp `driven_by` concurrently, so the brain may write it here without contending the broker. (The LIVE-session leg — a controller gone while its session survives — is NOT this hazard: a clean discon...\n *586│- **MEASURED 2026-07-22 (DAEMON-LIFECYCLE W2 Leg B, `transport_death_eof.rs`) — the residual SPLITS in two, and only one half is still open.** On REAL QUIC (two brokers, `BindScope::Loopback` + a real `net_dial` — NOT the in-process duplex, which has no idle timeout at all), a remote controller whose QUIC STACK DIES WITHOUT A FIN (peer frozen: endpoint alive, UDP port still bound, keepalives unanswered — the sleeping-laptop shape) DOES self-heal: the transport's own idle timeout tears the conn, the...\n  587│- **Watch-out (repro-proven, real broker):** `SessionInfo.controller_by==None` is AMBIGUOUS — `dispatch_spawn` pre-attaches the spawner as the LOCAL controller with `by=None`, so a live LOCALLY-driven session also reads `None`. It is therefore NOT a usable standalone `driven_by` clear trigger (would false-clear a live local session). The shipped Gap-B self-heal needs no controller signal at all (it keys on session ABSENCE).\n  588│- **spt-core mapping:** impl `livehost.rs` `reconcile_hosted_liveness` Gap-B clear + the additive `SessionInfo.controller_by` observability field (`msg.rs`, populated in `broker.rs` `KIND_SESSIONS`); unit `livehost.rs` `pull_liveness…` extended (offlined sessionless perch clears `driven_by`; live/relay perches untouched); int `crates/spt-daemon/tests/driven_by_selfheal.rs` `gap_b` (real broker: reconcile offlines AND clears `driven_by`) + the A1/A2 characterization (`inject_control_wedge.rs` w5_a1/w5_a2).\n  589│- **Cross-ref 7.29 (who MAY clear vs who MUST NOT):** the BRAIN reconcile here MUST NOT clear `driven_by` off `controller_by==None` (ambiguous with a live LOCAL controller). The BROKER stamp-convergence (7.29) MAY — it reads `has_controller()` DEFINITIVELY (its own controller slot), so it authoritatively clears a stale `driven_by` against a live session with no controller (the `has_controller()==false` leg). The invariant's owner for that leg moved to the broker; this brain-side ambiguity-safety is unc...\n     │...\n  873│<!-- [doc->REQ-BROKER-ZOMBIE-IDENTITY] -->\n *874│- **Zombie-reap kill boundary (releases#285):** `broker.rs` captures the PTY root's creation time before starting its exit waiter; a later zombie verdict alone never licenses killing that remembered number. Fresh death or a different live birth proves the remembered child gone and permits cleanup without a signal; only a matching live birth permits tree-kill. `SPAWN_ZOMBIE_REAP_RECYCLED` identifies both births before de-tabling and clearing stale stamps so respawn can proceed. Unknown identity still emit...\n  875│- **Source:** DAEMON-LIFECYCLE W1 (ADR-0047 decision 1; hertz field RCA bug 1).\n  876│\n  877│### 7.52 An operator stop outranks every implicit ensure — no convenience path resurrects what the operator just killed  `[REQ-HAZARD-STOP-RESPAWN-CONVOY]`\n     │...\n  989│<!-- [doc->REQ-HAZARD-WIRE-UNTAGGED-RECORD] -->\n *990│- **Failure (caught in design, W4 T10 / releases#53 — before it shipped, by asking what an N-1 daemon actually does rather than assuming it would simply not understand):** the stream dispatcher classifies a feed by sniffing its FIRST LINE, and the message family is deliberately **untagged** — `classify_first_line` reads any first line carrying `target` + `op_id` with no `kind` as `StreamFamily::WanMsg`. A newly minted record type that omits a `kind` tag is therefore not \"unrecognized\" on an older pee...\n  991│- **Invariant:** every wire record minted from here on carries a `kind` tag routed by its own tagged arm, so an older daemon's `Some(_)` catch-all resolves it to `StreamFamily::Unknown` and DROPS it cleanly. The correct degrade for a request an old peer cannot serve is that it **never arrives** — never that it arrives as something else. A record whose absence is silent is recoverable; a record delivered as the wrong kind is not.\n  992│- **Proof obligation — three parts, or the pin goes vacuous:** (a) this version routes the record to its own family, AND is asserted NOT to route it to the message family; (b) the same bytes under a tag this version does not know resolve to `Unknown`; (c) the untagged shape is asserted to genuinely BE claimed by the message arm. Without (c) the test passes for the wrong reason the day the record's fields drift such that it would no longer have collided — the guard would then be measuring nothing whil...\n  993│- **spt-core mapping:** `spt-net/src/net/knockmsg.rs` (`KNOCK_KIND`, the tag on `KnockRecord`); `spt-daemon/src/dispatch.rs` `classify_first_line` (the tagged arm) + `StreamFamily::Unknown` (the clean drop); unit `a_knock_record_routes_here_and_drops_cleanly_on_an_n1_daemon` (all three parts, against the real classifier).\n     │...\n 1031│- **spt-core mapping:** `spt/src/roster.rs` `match_self_by_ancestry` (distinct-id refusal) + `warn_ambiguous_ancestor_once`; `spt/src/cli.rs` the send site whose `unwrap_or(--from)` fallback makes `None` the accurate answer; `spt/tests/io_events_undriven_kinds_e2e.rs` `bind_endpoint`/`rig` (distinct live owners). Units: `an_ambiguous_ancestor_resolves_to_none_in_either_candidate_order`, `one_perch_matching_on_both_its_pids_still_resolves`, `ambiguity_is_scoped_to_the_nearest_ancestor`.\n*1032│- **Source:** releases#240, filed off the CONDUIT #236 respin RCA (todlando instrument on kitsubito + Windows control on hfenduleam; doyle-ruled fix shape — a named refusal over a silent guess; deployah pre-registered the ship branches before the classification landed). Kin 7.34 (the dead `rec.pid` class this ambiguity rides on), 7.63 (a key narrower than the identity of what it addresses).\n 1033│\n 1034│---\n 1035│\n## MANIFEST.md\n 747│\n*748│**Trust — optional signing, fail-closed.** With no `signing_key`, the fetched `.spt` is trusted on HTTPS + GitHub (the same first-acquisition trust `spt adapter add --release` and the installer's first binary fetch place). With a `signing_key`, the fetched `.spt` is verified against a **detached signature** the author publishes as a sibling release asset named `<asset>.sig` — a lowercase-hex Ed25519 signature over the raw archive bytes. Verification runs **after** the bytes are staged and **before** ...\n 749│\n 750│Validation requires `repo` for `gh_release` (`asset` and `signing_key` optional). `spt adapter add` reuses this section as the **install** mechanism (install is the first update; `--github <user/repo>` fetches the manifest first, then installs via the declared `avenue`). `uninstall` (optional) is its inverse, fired by `spt adapter remove` (soft-deregister; runs when no instance is live under the adapter, or immediately with `--force`). Absent `uninstall` ⇒ spt-core's default cleanup (drop its copy for ...\n 751│\n## MUSL-RELEASE-HANDOFF.md\n 16│## Watch-fors\n*17│- update-set stale-serve window ([[release-updateset-stale-window]]): upload-before-flip covers the musl entry.\n 18│- CI flake NOT to be spooked by: `inject_control_wedge::wan_arrival_to_idle_spt_hosted_injects_with_no_hook_poll` is a Windows-box-timing flake on the 80ms inject settle-window (untouched by W3, PASS on kitsubito, green in v0.29.1). If the hfenduleam test leg trips it, sweep leaked `spt.exe` (scoped) + rerun `--failed` — do NOT read it as a musl regression.\n 19│\n 20│Questions → doyle. gnu is unchanged; musl is purely additive.\n## MUSL-W3-DISPATCH-RULING.md\n 38│- **CI runner contention** ([[seedmap-test-collides-live-daemon]]): kitsubito is the musl BUILD box AND a gnu CI runner — a musl build job racing a gnu test job on the same box can leak/contend. Sequence the matrix or scope the daemon sweep; a Phase-A e2e daemon-timeout on kitsubito is contamination, not a musl regression (W2 CI hit exactly this — rerun cleared it).\n*39│- update-set **stale-serve window** ([[release-updateset-stale-window.md]]): upload-before-flip holds for the musl entry too.\n 40│\n 41│Co-authored by: doyle\n## NEXT-MILESTONE-BUG-TRIAGE.md\n 182│`claude-spt 0.9.0→0.9.2`: fetch OK, unsigned-trusting OK, LIVE daemon-coordinated apply, then `ADAPTER_UPDATE_FAIL:claude-spt: re-register: io: The system cannot find the file specified. (os error 2)`. The post-extract re-register step can't find a file — likely the extracted adapter root path or a manifest-referenced binary/install_dir. Class: adapter update ripple / install-dir resolve (cf. F-019 translation install-dir, REQ-HAZARD-DEFERRED-MANIFEST). perri-adjacent (claude-spt v0.9.2).\n*183│- **Root cause (agent G, conf H): SPT-CORE DEFECT (3 coupled), NOT perri packaging, NOT coupled to #16.** Chain: update writes to HARDCODED `_github/{safe}` dest (cli.rs:7674) ignoring the adapter's registered source_dir — claude-spt was plugin/sptc:setup-installed, NOT via `adapter add --release`, so `create_dir_all(dest)` makes a FRESH EMPTY dir. `adapter_has_live_endpoint` (cli.rs:7394/7407) scans on-disk perch info.json parent-prefix → eel-a alive → routes to `apply_release_via_daemon` (ADAPTER...\n 184│\n 185│## REOPENS (new evidence refutes/extends prior diagnosis)\n 186│\n## RELEASE-RUNBOOK.md\n 348│\n*349│   The older dedicated-release-PR rule applied before milestone-batch golden CI,\n 350│   when that PR's own full CI could validate the tagged commit. It cannot be\n 351│   carried forward into an ff-only lane whose golden run is the full-suite\n 352│   authority.\n    │...\n 463│   next milestone would branch from stale code. The gap became visible only\n*464│   because the release driver published the exact commands for review before\n 465│   running them: his local fast-forward never pushed.\n 466│\n 467│   ```sh\n    │...\n 558│\n*559│   Before invoking local Cargo, enter a quiet window: the golden run, the thin\n 560│   main `ci.yml` run fired by step 3, and the tag's `release.yml` run must all\n 561│   be terminal. This wait is about **box occupancy**, not the thin run blessing\n 562│   the SHA: golden remains the full-suite authority. Required golden evidence\n    │...\n 612│   - **Do not re-escalate it per release.** The finding was raised at the\n*613│     v0.43.0 cut (release driver stopped before signing) and ruled then.\n 614│     Re-raising it at each cut changes nothing and costs a release window.\n 615│     Revisiting the ruling is an operator decision, never a release-driver\n 616│     block.\n\n## adr/\n### 0015-release-signing-two-key-trust-anchor.md\n 13│\n*14│- Releasing is a partly manual ceremony: CI builds artifacts; the maintainer signs the release metadata locally before publishing.\n 15│- The signed metadata published with each release must be in the exact `SignedRelease` format the self-updater consumes, from v0.1 onward.\n### 0024-multi-platform-adapter-spt-packaging.md\n 12│\n*13│An adapter that updates via the `gh_release` avenue is fetched as a single release asset, `adapter.spt` — a tar whose root holds `manifest.toml` + `strings/` + the role binaries, extracted flat into the adapter's `install_dir`, where bare program tokens resolve `<install_dir>/<program>` before `PATH` (REQ-INSTALL-11). That format is **single-platform**: one archive carries one OS's binaries. A cross-platform adapter (e.g. a harness integration shipping a Windows `.exe` and a Linux ELF for its translati...\n 14│\n 15│spt-core's own binary already solves cross-platform distribution with **platform-targeted update sets** (ADR-0016): per-triple *separate* artifacts, one signed set-metadata blob with per-platform digests, and each recipient fetches only its own platform's bytes. That model is bandwidth-optimal at fleet scale but heavier for an adapter author: multiple artifacts plus signed set metadata, for what is often a few kilobytes of binary.\n 16│\n### 0050-golden-ci-merge-integration.md\n 52│\n*53│The omission became visible because the release driver published his exact commands for review before running them: his first step fast-forwarded only a local branch and no later step pushed `main`. **Retired-host side-effect rule: when you retire a mechanism, enumerate its side effects and re-home each one—the work and the sentence that explains the work.** This retirement lost both in opposite directions: a responsibility vanished with its host (the release-PR merge stopped advancing `main`, and no s...\n 54│\n 55│A third paid precedent completes the class in the other direction: the name `docs-publish.yml` outlived the workflow itself after its docs step moved into `release.yml`, so a release driver followed the stale runbook name and waited for a workflow that could never appear (the documentation drift repaired for PR #113). The three failures are distinct consequences of one missing retirement inventory: responsibility vanished with its host, a surviving by-product lost the sentence that gave it meaning, and a...\n 56│\n\n## design/\n### RIDER-65S-DESIGN.md\n 131│arm at a time, and every test aimed at a still-complying arm reports the convention as held. Two of\n*132│three arms named the key here, so the defect was invisible to any cell but the one that happened to\n 133│exercise the third — my four cells caught it by luck, not by coverage. The cell converts \"we name\n 134│our refusals\" from a sentence in a doc-comment into something the suite refuses to let lapse, and\n 135│it fails on the NEXT arm someone adds rather than on the next person to read the file.","linesTruncated":true,"meta":{"limits":{"columnTruncated":{"maxColumn":512}}}},"isError":false,"timestamp":1789094648425}}
{"type":"message","id":"1a38fa2d","parentId":"c429bf07","timestamp":"2026-09-11T02:44:08.564Z","message":{"role":"toolResult","toolCallId":"call_EkFTMkjuxA6cfHso8guYFqsA|fc_065c0d1976ecf9c2016aa36af5ca5487d1aed7ba11df25d0c5","toolName":"grep","content":[{"type":"text","text":"# .spt/preserved/gate-r2-34481993681-20260910/\n## test-linux-102886952398.log\n 338|2026-09-10T13:20:40.2847997Z cargo build -p mock-adapter --bin capture-player\n*339|2026-09-10T13:20:40.2848340Z cargo build -p mock-adapter --bin console-mode-probe\n 340|2026-09-10T13:20:40.2848716Z cargo build -p spt-daemon --bin service_fixture\n 341|2026-09-10T13:20:40.2849165Z cargo build --workspace\n 342|2026-09-10T13:20:40.2860573Z shell: /usr/bin/bash -e {0}\n...\n 538|2026-09-10T13:20:48.1420714Z    Compiling arrayvec v0.7.6\n*539|2026-09-10T13:20:48.1571212Z    Compiling openssl-probe v0.2.1\n 540|2026-09-10T13:20:48.3563852Z    Compiling aes-gcm v0.10.3\n 541|2026-09-10T13:20:48.3655907Z    Compiling crossbeam-channel v0.5.15\n 542|2026-09-10T13:20:48.3746431Z    Compiling crossbeam-epoch v0.9.18\n...\n 948|2026-09-10T13:25:51.7430358Z         PASS [   0.022s] (  46/3360) spt::notify_shell_e2e notify_shell_renders_a_commanded_toast\n*949|2026-09-10T13:25:51.7810526Z         PASS [   6.761s] (  47/3360) spt::er_inbound_local a_local_send_meets_the_engine_rooms_inbound_lock_on_every_authoring_path\n 950|2026-09-10T13:25:51.8235265Z         PASS [   0.621s] (  48/3360) spt::live_bind_firsthost_e2e live_bind_marks_online_and_brain_reconcile_hosts\n 951|2026-09-10T13:25:51.8359376Z         PASS [   0.354s] (  49/3360) spt::midturn_span_e2e a_bare_seal_marker_is_refused_in_a_span_and_mints_at_the_close\n 952|2026-09-10T13:25:51.8693980Z         PASS [   4.575s] (  50/3360) spt::io_events_undriven_kinds_e2e a_notification_filtered_by_the_relay_publishes_no_msg_in\n...\n 1042|2026-09-10T13:25:53.5970153Z         PASS [   0.017s] ( 140/3360) spt::bin/spt api::engineroom::tests::subnet_authority_is_the_empowerment_not_the_gate\n*1043|2026-09-10T13:25:53.6040601Z         PASS [   0.026s] ( 141/3360) spt::bin/spt api::engineroom::tests::ordinary_perch_minting_never_probes_the_engine_room\n 1044|2026-09-10T13:25:53.6062752Z         PASS [   0.327s] ( 142/3360) spt::bin/spt api::delivery::tests::poll_drain_holds_deferred_while_resting_and_releases_once_on_wake\n 1045|2026-09-10T13:25:53.6066363Z         PASS [   0.021s] ( 143/3360) spt::bin/spt api::engineroom::tests::the_perch_minting_verbs_admit_the_reserved_id_only_as_a_completion\n 1046|2026-09-10T13:25:53.6090442Z         PASS [   0.022s] ( 144/3360) spt::bin/spt api::engineroom::tests::the_gate_admits_only_the_reserved_id_provisioned_and_authenticated\n...\n 1225|2026-09-10T13:25:54.6539965Z         PASS [   0.023s] ( 323/3360) spt::bin/spt cli::tests::any_single_evidence_source_is_enough_and_only_nothing_refuses\n*1226|2026-09-10T13:25:54.6600093Z         PASS [   0.192s] ( 324/3360) spt::bin/spt cli::tests::a_wedged_probe_costs_one_ceiling_and_reads_unknown_not_offline\n 1227|2026-09-10T13:25:54.6629975Z         PASS [   0.032s] ( 325/3360) spt::bin/spt cli::tests::an_undelivered_receipt_reports_only_the_receipt\n 1228|2026-09-10T13:25:54.6667711Z         PASS [   0.035s] ( 326/3360) spt::bin/spt cli::tests::answering_verbs_declare_no_directionality\n 1229|2026-09-10T13:25:54.6729894Z         PASS [   0.038s] ( 327/3360) spt::bin/spt cli::tests::api_adapter_flag_is_group_level_not_post_subcommand\n...\n 1276|2026-09-10T13:25:54.9680251Z         PASS [   0.128s] ( 374/3360) spt::bin/spt api::startup::tests::a_recycled_relay_pid_is_fixed_too_so_the_role_gate_is_not_carrying_this\n*1277|2026-09-10T13:25:54.9740021Z         PASS [   0.032s] ( 375/3360) spt::bin/spt cli::tests::every_mint_persist_site_asks_the_shared_probe\n 1278|2026-09-10T13:25:54.9799848Z         PASS [   0.125s] ( 376/3360) spt::bin/spt cli::tests::create_provisions_the_admin_key_and_show_code_never_does\n 1279|2026-09-10T13:25:54.9809759Z         PASS [   0.025s] ( 377/3360) spt::bin/spt cli::tests::every_send_outcome_is_answered_by_exactly_one_renderer\n 1280|2026-09-10T13:25:54.9870180Z         PASS [   0.034s] ( 378/3360) spt::bin/spt cli::tests::every_retired_access_token_still_reaches_the_positional\n...\n 1297|2026-09-10T13:25:55.0839739Z         PASS [   0.043s] ( 395/3360) spt::bin/spt cli::tests::grant_subcommands_parse\n*1298|2026-09-10T13:25:55.0909983Z         PASS [   0.027s] ( 396/3360) spt::bin/spt cli::tests::inbound_json_speaks_in_the_two_states_the_human_view_is_silent_in\n*1299|2026-09-10T13:25:55.0959890Z         PASS [   0.025s] ( 397/3360) spt::bin/spt cli::tests::inbound_verdict_rides_the_json_in_every_state_including_ok\n 1300|2026-09-10T13:25:55.1029855Z         PASS [   0.023s] ( 398/3360) spt::bin/spt cli::tests::install_place_is_idempotent_and_path_block_detected\n 1301|2026-09-10T13:25:55.1089952Z         PASS [   0.144s] ( 399/3360) spt::bin/spt api::startup::tests::api_bind_admits_the_reserved_id_only_as_a_bring_ups_completion\n 1302|2026-09-10T13:25:55.1149705Z         PASS [   0.167s] ( 400/3360) spt::bin/spt cli::tests::every_node_flag_teaches_all_three_spellings\n...\n 1330|2026-09-10T13:25:55.2429723Z         PASS [   0.298s] ( 428/3360) spt::bin/spt cli::tests::endpoint_role_overwrite_is_the_sole_writer\n*1331|2026-09-10T13:25:55.2479772Z         PASS [   0.031s] ( 429/3360) spt::bin/spt cli::tests::node_status_rows_settle_cheap_signals_probe_only_stale\n 1332|2026-09-10T13:25:55.2489774Z         PASS [   0.033s] ( 430/3360) spt::bin/spt cli::tests::not_elevated_refuses_without_leaking_code_or_saving\n 1333|2026-09-10T13:25:55.2522533Z         PASS [   0.027s] ( 431/3360) spt::bin/spt cli::tests::only_a_bake_that_can_admit_the_whole_node_demands_the_acknowledgment\n 1334|2026-09-10T13:25:55.2549652Z         PASS [   0.028s] ( 432/3360) spt::bin/spt cli::tests::only_a_multi_subnet_mint_warns_about_older_readers\n...\n 1350|2026-09-10T13:25:55.2718455Z         PASS [   0.031s] ( 448/3360) spt::bin/spt cli::tests::psyche_companion_is_named_without_a_status\n*1351|2026-09-10T13:25:55.2719434Z         PASS [   0.063s] ( 449/3360) spt::bin/spt cli::tests::probe_all_cap_batches_into_windows\n 1352|2026-09-10T13:25:55.2720261Z         PASS [   0.041s] ( 450/3360) spt::bin/spt cli::tests::purge_offline_gate_and_self_guard\n 1353|2026-09-10T13:25:55.2721161Z         PASS [   0.044s] ( 451/3360) spt::bin/spt cli::tests::registered_github_home_detects_active_collision\n 1354|2026-09-10T13:25:55.2722163Z         PASS [   0.024s] ( 452/3360) spt::bin/spt cli::tests::remote_cell_project_ref_from_gossiped_recent_projects\n...\n 1357|2026-09-10T13:25:55.2725548Z         PASS [   0.084s] ( 455/3360) spt::bin/spt cli::tests::release_archive_extracts_to_a_registrable_root\n*1358|2026-09-10T13:25:55.2726458Z         PASS [   0.028s] ( 456/3360) spt::bin/spt cli::tests::resolve_transport_auto_follows_probe\n 1359|2026-09-10T13:25:55.2727345Z         PASS [   0.029s] ( 457/3360) spt::bin/spt cli::tests::resolve_proof_target_override_reads_on_disk\n 1360|2026-09-10T13:25:55.2728220Z         PASS [   0.020s] ( 458/3360) spt::bin/spt cli::tests::rest_filter_status_first_ordering\n 1361|2026-09-10T13:25:55.2729249Z         PASS [   0.021s] ( 459/3360) spt::bin/spt cli::tests::rest_filter_hides_suspended_shows_all_and_corrupt_always\n*1362|2026-09-10T13:25:55.2759489Z         PASS [   0.029s] ( 460/3360) spt::bin/spt cli::tests::resolve_transport_explicit_never_probes\n*1363|2026-09-10T13:25:55.2760559Z         PASS [   0.187s] ( 461/3360) spt::bin/spt cli::tests::probe_all_timeout_settles_false_without_stalling_batch\n 1364|2026-09-10T13:25:55.2761532Z         PASS [   0.020s] ( 462/3360) spt::bin/spt cli::tests::restart_plans_lethal_leg_last\n 1365|2026-09-10T13:25:55.2762438Z         PASS [   0.022s] ( 463/3360) spt::bin/spt cli::tests::rest_filter_total_disclosure_and_corrupt_annotation\n 1366|2026-09-10T13:25:55.2763435Z         PASS [   0.175s] ( 464/3360) spt::bin/spt cli::tests::purge_force_asks_before_it_tears_anything_down\n...\n 1374|2026-09-10T13:25:55.2790255Z         PASS [   0.025s] ( 472/3360) spt::bin/spt cli::tests::self_pin_annotates_psyche_host_failure\n*1375|2026-09-10T13:25:55.2870265Z         PASS [   0.248s] ( 473/3360) spt::bin/spt cli::tests::probe_all_runs_concurrently_in_input_order\n 1376|2026-09-10T13:25:55.2970071Z         PASS [   0.026s] ( 474/3360) spt::bin/spt cli::tests::self_pin_includes_description_when_present\n 1377|2026-09-10T13:25:55.2999762Z         PASS [   0.021s] ( 475/3360) spt::bin/spt cli::tests::self_pin_names_the_registered_drop_dir_only_when_known\n 1378|2026-09-10T13:25:55.3090344Z         PASS [   0.249s] ( 476/3360) spt::bin/spt cli::tests::public_help_carries_no_internal_codes_at_any_ruled_site\n...\n 1432|2026-09-10T13:25:55.8129690Z         PASS [   0.025s] ( 530/3360) spt::bin/spt cli::tests::the_locked_claim_carries_its_caveat_in_the_same_emission\n*1433|2026-09-10T13:25:55.8189731Z         PASS [   0.023s] ( 531/3360) spt::bin/spt cli::tests::the_mint_probe_answers_only_for_a_fresh_mint\n 1434|2026-09-10T13:25:55.8219650Z         PASS [   0.033s] ( 532/3360) spt::bin/spt cli::tests::the_knock_prescription_names_the_fork_pair_only_where_it_is_needed\n 1435|2026-09-10T13:25:55.8309986Z         PASS [   0.024s] ( 533/3360) spt::bin/spt cli::tests::the_positional_allow_spelling_carries_its_flags_into_the_rule\n 1436|2026-09-10T13:25:55.8340214Z         PASS [   0.022s] ( 534/3360) spt::bin/spt cli::tests::the_positional_spelling_cannot_step_around_the_admit_node_acknowledgment\n...\n 1647|2026-09-10T13:25:56.7240189Z         PASS [   0.046s] ( 745/3360) spt::bin/spt roster::tests::detect_self_by_ancestry_resolves_a_live_ancestor_perch\n*1648|2026-09-10T13:25:56.7299970Z         PASS [   0.157s] ( 746/3360) spt::bin/spt rc::tests::establish_attach_reuses_the_probes_carried_pump_conn\n 1649|2026-09-10T13:25:56.7360095Z         PASS [   0.031s] ( 747/3360) spt::bin/spt roster::tests::list_all_perch_dirs_enumerates_nested_psyche_for_self_resolution\n 1650|2026-09-10T13:25:56.7389976Z         PASS [   0.049s] ( 748/3360) spt::bin/spt roster::tests::detect_self_id_resolves_identity_with_zero_git_spawns\n 1651|2026-09-10T13:25:56.7450012Z         PASS [   0.015s] ( 749/3360) spt::bin/spt roster::tests::the_ambiguity_diagnostic_names_every_tied_id_and_the_shared_pid\n...\n 1675|2026-09-10T13:25:56.8789820Z         PASS [   0.032s] ( 773/3360) spt::bin/spt unlisted::tests::a_receipt_proven_cross_node_knock_renders_its_answer\n*1676|2026-09-10T13:25:56.8849823Z         PASS [   0.025s] ( 774/3360) spt::bin/spt unlisted::tests::an_inbound_knock_is_never_read_as_our_own_outbound_act\n 1677|2026-09-10T13:25:56.8909836Z         PASS [   0.037s] ( 775/3360) spt::bin/spt unlisted::tests::a_rule_only_row_has_no_node_to_route_to\n 1678|2026-09-10T13:25:56.8970573Z         PASS [   0.026s] ( 776/3360) spt::bin/spt unlisted::tests::an_unproven_cross_node_knock_says_no_answer_while_a_same_node_one_says_approved\n 1679|2026-09-10T13:25:56.9040496Z         PASS [   0.029s] ( 777/3360) spt::bin/spt unlisted::tests::contact_evidence_outside_the_window_produces_no_row\n...\n 1701|2026-09-10T13:25:57.0339889Z         PASS [   0.034s] ( 799/3360) spt-daemon access::tests::same_node_always_passes_without_minting\n*1702|2026-09-10T13:25:57.0399736Z         PASS [   0.028s] ( 800/3360) spt-daemon access::tests::the_inbound_lock_answers_replies_only_and_only_while_controlled\n*1703|2026-09-10T13:25:57.0459833Z         PASS [   0.029s] ( 801/3360) spt-daemon access::tests::the_engine_room_refuses_even_this_nodes_own_unsolicited_inbound\n 1704|2026-09-10T13:25:57.0489574Z         PASS [   0.026s] ( 802/3360) spt-daemon access::tests::the_wire_origin_stamp_reaches_the_chain\n*1705|2026-09-10T13:25:57.0519736Z         PASS [   0.036s] ( 803/3360) spt-daemon access::tests::the_inbound_lock_is_reached_through_the_sender_stamped_entry_point\n 1706|2026-09-10T13:25:57.0580140Z         PASS [   0.023s] ( 804/3360) spt-daemon activity::tests::a_token_change_with_an_identical_state_owes_a_push\n 1707|2026-09-10T13:25:57.0639951Z         PASS [   0.106s] ( 805/3360) spt::bin/spt api::startup::tests::bind_records_cwd_so_picker_can_group_by_project\n 1708|2026-09-10T13:25:57.0699767Z         PASS [   0.019s] ( 806/3360) spt-daemon activity::tests::an_owner_with_no_linked_shell_is_not_observed\n## test-windows-102886952516.log\n 222|2026-09-10T13:28:59.4630706Z cargo build -p mock-adapter --bin capture-player\n*223|2026-09-10T13:28:59.4630950Z cargo build -p mock-adapter --bin console-mode-probe\n 224|2026-09-10T13:28:59.4631234Z cargo build -p spt-daemon --bin service_fixture\n 225|2026-09-10T13:28:59.4631503Z cargo build --workspace\n 226|2026-09-10T13:28:59.4636299Z shell: C:\\Program Files\\PowerShell\\7\\pwsh.EXE -command \". '{0}'\"\n...\n 824|2026-09-10T13:45:21.2618960Z         PASS [  19.846s] (  26/3381) spt::broker_stop_endpoint_deny_e2e an_endpoint_context_cannot_stop_the_broker_by_any_flag\n*825|2026-09-10T13:45:22.3245837Z         PASS [   8.738s] (  27/3381) spt::er_inbound_local a_local_send_meets_the_engine_rooms_inbound_lock_on_every_authoring_path\n 826|2026-09-10T13:45:22.9220250Z         PASS [   0.598s] (  28/3381) spt::hide_new_remote_rows_e2e hide_new_keeps_our_own_endpoint_hidden_and_leaves_other_nodes_rows_alone\n 827|2026-09-10T13:45:23.0790693Z         PASS [   1.817s] (  29/3381) spt::gateway_e2e gateway_binds_and_is_the_user_backed_origin\n 828|2026-09-10T13:45:23.4695311Z         PASS [  10.317s] (  30/3381) spt::drive_e2e drive_channel_slot_through_the_real_socket\n...\n 947|2026-09-10T13:46:04.1526299Z         PASS [   0.501s] ( 149/3381) spt::bin/spt api::engineroom::tests::another_endpoints_traffic_never_answers_the_engine_rooms_gate\n*948|2026-09-10T13:46:04.1612697Z         PASS [   0.498s] ( 150/3381) spt::bin/spt api::engineroom::tests::ordinary_perch_minting_never_probes_the_engine_room\n 949|2026-09-10T13:46:04.1667735Z         PASS [   0.495s] ( 151/3381) spt::bin/spt api::engineroom::tests::subnet_authority_is_the_empowerment_not_the_gate\n 950|2026-09-10T13:46:04.5173279Z         PASS [   0.782s] ( 152/3381) spt::bin/spt api::engineroom::tests::the_gate_admits_only_the_reserved_id_provisioned_and_authenticated\n 951|2026-09-10T13:46:04.5414657Z         PASS [   0.639s] ( 153/3381) spt::bin/spt api::engineroom::tests::the_perch_minting_verbs_admit_the_reserved_id_only_as_a_completion\n...\n 1102|2026-09-10T13:46:32.7049004Z         PASS [   7.205s] ( 304/3381) spt::bin/spt cli::reserved_id_tests::rename_into_the_reserved_id_is_refused\n*1103|2026-09-10T13:46:32.8059737Z         PASS [   0.247s] ( 305/3381) spt::bin/spt cli::tests::a_wedged_probe_costs_one_ceiling_and_reads_unknown_not_offline\n 1104|2026-09-10T13:46:33.1329994Z         PASS [   0.503s] ( 306/3381) spt::bin/spt api::startup::tests::api_bind_admits_the_reserved_id_only_as_a_bring_ups_completion\n 1105|2026-09-10T13:46:33.1439150Z         PASS [   0.439s] ( 307/3381) spt::bin/spt cli::tests::adapter_name_validation_flags_every_unknown\n 1106|2026-09-10T13:46:33.1552863Z         PASS [   0.349s] ( 308/3381) spt::bin/spt cli::tests::adapter_names_comma_list_parses_and_refuses_empties\n...\n 1191|2026-09-10T13:46:41.8916421Z         PASS [   0.444s] ( 393/3381) spt::bin/spt cli::tests::escalation_choice_parses_fail_closed\n*1192|2026-09-10T13:46:41.9396458Z         PASS [   0.486s] ( 394/3381) spt::bin/spt cli::tests::every_mint_persist_site_asks_the_shared_probe\n 1193|2026-09-10T13:46:41.9936803Z         PASS [   0.161s] ( 395/3381) spt::bin/spt cli::tests::every_retired_access_token_still_reaches_the_positional\n 1194|2026-09-10T13:46:41.9955919Z         PASS [   0.432s] ( 396/3381) spt::bin/spt cli::tests::every_read_status_command_accepts_the_global_json_flag\n 1195|2026-09-10T13:46:42.0020437Z         PASS [   0.111s] ( 397/3381) spt::bin/spt cli::tests::every_send_outcome_is_answered_by_exactly_one_renderer\n...\n 1216|2026-09-10T13:46:43.1152780Z         PASS [   0.544s] ( 418/3381) spt::bin/spt cli::tests::how_to_topics_cover_ready_and_send\n*1217|2026-09-10T13:46:43.1592049Z         PASS [   0.577s] ( 419/3381) spt::bin/spt cli::tests::inbound_json_speaks_in_the_two_states_the_human_view_is_silent_in\n*1218|2026-09-10T13:46:43.1713806Z         PASS [   0.571s] ( 420/3381) spt::bin/spt cli::tests::inbound_verdict_rides_the_json_in_every_state_including_ok\n 1219|2026-09-10T13:46:43.1892121Z         PASS [   0.582s] ( 421/3381) spt::bin/spt api::startup::tests::empty_session_seed_refused\n 1220|2026-09-10T13:46:43.2007729Z         PASS [   0.219s] ( 422/3381) spt::bin/spt cli::tests::install_platform_check_gates_stamp_and_host_arch\n 1221|2026-09-10T13:46:43.2010780Z         PASS [   0.585s] ( 423/3381) spt::bin/spt cli::tests::install_place_is_idempotent_and_path_block_detected\n...\n 1248|2026-09-10T13:46:44.2538937Z         PASS [   0.447s] ( 450/3381) spt::bin/spt cli::tests::node_status_rows_denominator_counts_routable_only\n*1249|2026-09-10T13:46:44.2625609Z         PASS [   0.443s] ( 451/3381) spt::bin/spt cli::tests::node_status_rows_settle_cheap_signals_probe_only_stale\n 1250|2026-09-10T13:46:44.2700247Z         PASS [   0.443s] ( 452/3381) spt::bin/spt cli::tests::not_elevated_refuses_without_leaking_code_or_saving\n 1251|2026-09-10T13:46:44.2815113Z         PASS [   0.447s] ( 453/3381) spt::bin/spt cli::tests::notify_subnet_resolution_home_default\n 1252|2026-09-10T13:46:44.3059226Z         PASS [   0.052s] ( 454/3381) spt::bin/spt cli::tests::only_a_bake_that_can_admit_the_whole_node_demands_the_acknowledgment\n...\n 1266|2026-09-10T13:46:44.8456333Z         PASS [   0.125s] ( 468/3381) spt::bin/spt cli::tests::post_step_notice_arbitration\n*1267|2026-09-10T13:46:44.8575675Z         PASS [   0.098s] ( 469/3381) spt::bin/spt cli::tests::probe_all_cap_batches_into_windows\n 1268|2026-09-10T13:46:44.8854262Z         PASS [   0.049s] ( 470/3381) spt::bin/spt api::startup::tests::listen_online_gate_refuses_capability_only_online\n 1269|2026-09-10T13:46:44.8937677Z         PASS [   0.048s] ( 471/3381) spt::bin/spt cli::tests::project_index_line_states_health_not_presence\n 1270|2026-09-10T13:46:44.9018692Z         PASS [   0.044s] ( 472/3381) spt::bin/spt cli::tests::prune_candidates_resolve_never_guess\n*1271|2026-09-10T13:46:45.0376448Z         PASS [   0.210s] ( 473/3381) spt::bin/spt cli::tests::probe_all_timeout_settles_false_without_stalling_batch\n*1272|2026-09-10T13:46:45.0689919Z         PASS [   0.256s] ( 474/3381) spt::bin/spt cli::tests::probe_all_runs_concurrently_in_input_order\n 1273|2026-09-10T13:46:45.2489852Z         PASS [   0.363s] ( 475/3381) spt::bin/spt api::startup::tests::listen_orphan_exit_line_names_self_and_parent\n 1274|2026-09-10T13:46:45.2860782Z         PASS [   0.392s] ( 476/3381) spt::bin/spt cli::tests::psyche_companion_is_named_without_a_status\n 1275|2026-09-10T13:46:45.4248069Z         PASS [   4.032s] ( 477/3381) spt::bin/spt cli::tests::endpoint_role_overwrite_is_the_sole_writer\n...\n 1286|2026-09-10T13:46:47.7416095Z         PASS [   0.418s] ( 488/3381) spt::bin/spt cli::tests::resolve_proof_target_override_reads_on_disk\n*1287|2026-09-10T13:46:47.7798540Z         PASS [   0.439s] ( 489/3381) spt::bin/spt cli::tests::resolve_transport_auto_follows_probe\n*1288|2026-09-10T13:46:47.8000243Z         PASS [   0.423s] ( 490/3381) spt::bin/spt cli::tests::resolve_transport_explicit_never_probes\n 1289|2026-09-10T13:46:48.1483666Z         PASS [   0.431s] ( 491/3381) spt::bin/spt api::startup::tests::only_an_unverified_refusal_names_its_escape\n 1290|2026-09-10T13:46:48.1875282Z         PASS [   0.446s] ( 492/3381) spt::bin/spt cli::tests::rest_filter_hides_suspended_shows_all_and_corrupt_always\n 1291|2026-09-10T13:46:48.2347282Z         PASS [   0.455s] ( 493/3381) spt::bin/spt cli::tests::rest_filter_status_first_ordering\n...\n 1374|2026-09-10T13:46:59.7366180Z         PASS [   0.030s] ( 576/3381) spt::bin/spt cli::tests::the_locked_claim_carries_its_caveat_in_the_same_emission\n*1375|2026-09-10T13:46:59.7485804Z         PASS [   0.038s] ( 577/3381) spt::bin/spt cli::tests::the_mint_probe_answers_only_for_a_fresh_mint\n 1376|2026-09-10T13:46:59.8301919Z         PASS [   0.137s] ( 578/3381) spt::bin/spt cli::tests::the_local_and_wire_arms_write_one_identical_grant\n 1377|2026-09-10T13:47:00.1463341Z         PASS [   0.316s] ( 579/3381) spt::bin/spt cli::tests::the_positional_allow_spelling_carries_its_flags_into_the_rule\n 1378|2026-09-10T13:47:00.2025108Z         PASS [   0.056s] ( 580/3381) spt::bin/spt cli::tests::the_positional_spelling_cannot_step_around_the_admit_node_acknowledgment\n...\n 1556|2026-09-10T13:47:26.3579006Z         PASS [   2.235s] ( 758/3381) spt::bin/spt rc::tests::fold_code_key_prompt_rules\n*1557|2026-09-10T13:47:26.4197178Z         PASS [   2.677s] ( 759/3381) spt::bin/spt rc::tests::establish_attach_reuses_the_probes_carried_pump_conn\n 1558|2026-09-10T13:47:27.0758162Z         PASS [   2.588s] ( 760/3381) spt::bin/spt rc::tests::give_up_copy_names_daemon_down_vs_generic\n 1559|2026-09-10T13:47:27.7818872Z         PASS [   3.283s] ( 761/3381) spt::bin/spt rc::tests::harness_only_row_matches_online_seatless_live_agents_only\n 1560|2026-09-10T13:47:28.4999714Z         PASS [   3.710s] ( 762/3381) spt::bin/spt rc::tests::broker_host_child\n...\n 1631|2026-09-10T13:47:38.7702664Z         PASS [   1.638s] ( 833/3381) spt::bin/spt unlisted::tests::an_exclusion_outranks_the_strongest_evidence\n*1632|2026-09-10T13:47:39.1579922Z         PASS [   1.986s] ( 834/3381) spt::bin/spt unlisted::tests::an_inbound_knock_is_never_read_as_our_own_outbound_act\n 1633|2026-09-10T13:47:39.5054685Z         PASS [   1.931s] ( 835/3381) spt::bin/spt unlisted::tests::an_unproven_cross_node_knock_says_no_answer_while_a_same_node_one_says_approved\n 1634|2026-09-10T13:47:39.5352370Z         PASS [   1.587s] ( 836/3381) spt::bin/spt unlisted::tests::contact_evidence_outside_the_window_produces_no_row\n 1635|2026-09-10T13:47:39.5586929Z         PASS [   1.589s] ( 837/3381) spt::bin/spt unlisted::tests::listed_local_and_excluded_rows_are_dropped_and_the_rest_survive\n...\n 1656|2026-09-10T13:47:46.5578256Z         PASS [   3.961s] ( 858/3381) spt-daemon access::tests::the_engine_room_is_disclosed_only_to_the_viewers_it_chose\n*1657|2026-09-10T13:47:47.8664056Z         PASS [   4.896s] ( 859/3381) spt-daemon access::tests::the_engine_room_refuses_even_this_nodes_own_unsolicited_inbound\n*1658|2026-09-10T13:47:49.5625496Z         PASS [   6.240s] ( 860/3381) spt-daemon access::tests::the_inbound_lock_answers_replies_only_and_only_while_controlled\n 1659|2026-09-10T13:47:51.2677201Z         PASS [   7.599s] ( 861/3381) spt::bin/spt wansend::tests::a_shared_short_key_refuses_and_an_unknown_one_is_its_own_outcome\n*1660|2026-09-10T13:47:51.3420793Z         PASS [   7.277s] ( 862/3381) spt-daemon access::tests::the_inbound_lock_is_reached_through_the_sender_stamped_entry_point\n 1661|2026-09-10T13:47:51.3555769Z         PASS [   6.247s] ( 863/3381) spt-daemon access::tests::the_trust_warning_fires_only_for_an_entry_admitted_stranger\n 1662|2026-09-10T13:47:51.3767295Z         PASS [   5.590s] ( 864/3381) spt-daemon access::tests::the_wire_origin_stamp_reaches_the_chain\n 1663|2026-09-10T13:47:51.3863925Z         PASS [   6.993s] ( 865/3381) spt-daemon access::tests::the_pass_reason_names_which_arm_admitted_the_interaction\n...\n 1681|2026-09-10T13:47:51.9529269Z         PASS [   0.073s] ( 883/3381) spt-daemon adapter_update::tests::file_pull_verified_against_adapter_key\n*1682|2026-09-10T13:47:51.9677570Z         PASS [   0.072s] ( 884/3381) spt::bin/spt wansend::tests::a_silent_probe_renders_unknown_and_never_offline\n 1683|2026-09-10T13:47:51.9683428Z         PASS [   0.080s] ( 885/3381) spt-daemon adapter_update::tests::file_pull_wrong_key_rejected\n 1684|2026-09-10T13:47:51.9750180Z         PASS [   0.070s] ( 886/3381) spt-daemon adapter_update::tests::gh_release_is_managed_cli_side_not_in_pure_plan\n 1685|2026-09-10T13:47:51.9911572Z         PASS [   0.081s] ( 887/3381) spt-daemon adapter_update::tests::ripple_conducts_each_adapter_in_order"}],"details":{"scopePath":".spt/preserved/gate-r2-34481993681-20260910","searchPath":"C:\\Users\\decid\\Documents\\projects\\spt-core\\.spt\\preserved\\gate-r2-34481993681-20260910","cwd":"C:\\Users\\decid\\Documents\\projects\\spt-core","matchCount":40,"fileCount":2,"files":[".spt/preserved/gate-r2-34481993681-20260910/test-linux-102886952398.log",".spt/preserved/gate-r2-34481993681-20260910/test-windows-102886952516.log"],"fileMatches":[{"path":".spt/preserved/gate-r2-34481993681-20260910/test-linux-102886952398.log","count":20},{"path":".spt/preserved/gate-r2-34481993681-20260910/test-windows-102886952516.log","count":20}],"truncated":true,"perFileLimitReached":20,"displayContent":"# .spt/preserved/gate-r2-34481993681-20260910/\n## test-linux-102886952398.log\n  338│2026-09-10T13:20:40.2847997Z \u001b[36;1mcargo build -p mock-adapter --bin capture-player\u001b[0m\n *339│2026-09-10T13:20:40.2848340Z \u001b[36;1mcargo build -p mock-adapter --bin console-mode-probe\u001b[0m\n  340│2026-09-10T13:20:40.2848716Z \u001b[36;1mcargo build -p spt-daemon --bin service_fixture\u001b[0m\n  341│2026-09-10T13:20:40.2849165Z \u001b[36;1mcargo build --workspace\u001b[0m\n  342│2026-09-10T13:20:40.2860573Z shell: /usr/bin/bash -e {0}\n     │...\n  538│2026-09-10T13:20:48.1420714Z    Compiling arrayvec v0.7.6\n *539│2026-09-10T13:20:48.1571212Z    Compiling openssl-probe v0.2.1\n  540│2026-09-10T13:20:48.3563852Z    Compiling aes-gcm v0.10.3\n  541│2026-09-10T13:20:48.3655907Z    Compiling crossbeam-channel v0.5.15\n  542│2026-09-10T13:20:48.3746431Z    Compiling crossbeam-epoch v0.9.18\n     │...\n  948│2026-09-10T13:25:51.7430358Z         PASS [   0.022s] (  46/3360) spt::notify_shell_e2e notify_shell_renders_a_commanded_toast\n *949│2026-09-10T13:25:51.7810526Z         PASS [   6.761s] (  47/3360) spt::er_inbound_local a_local_send_meets_the_engine_rooms_inbound_lock_on_every_authoring_path\n  950│2026-09-10T13:25:51.8235265Z         PASS [   0.621s] (  48/3360) spt::live_bind_firsthost_e2e live_bind_marks_online_and_brain_reconcile_hosts\n  951│2026-09-10T13:25:51.8359376Z         PASS [   0.354s] (  49/3360) spt::midturn_span_e2e a_bare_seal_marker_is_refused_in_a_span_and_mints_at_the_close\n  952│2026-09-10T13:25:51.8693980Z         PASS [   4.575s] (  50/3360) spt::io_events_undriven_kinds_e2e a_notification_filtered_by_the_relay_publishes_no_msg_in\n     │...\n 1042│2026-09-10T13:25:53.5970153Z         PASS [   0.017s] ( 140/3360) spt::bin/spt api::engineroom::tests::subnet_authority_is_the_empowerment_not_the_gate\n*1043│2026-09-10T13:25:53.6040601Z         PASS [   0.026s] ( 141/3360) spt::bin/spt api::engineroom::tests::ordinary_perch_minting_never_probes_the_engine_room\n 1044│2026-09-10T13:25:53.6062752Z         PASS [   0.327s] ( 142/3360) spt::bin/spt api::delivery::tests::poll_drain_holds_deferred_while_resting_and_releases_once_on_wake\n 1045│2026-09-10T13:25:53.6066363Z         PASS [   0.021s] ( 143/3360) spt::bin/spt api::engineroom::tests::the_perch_minting_verbs_admit_the_reserved_id_only_as_a_completion\n 1046│2026-09-10T13:25:53.6090442Z         PASS [   0.022s] ( 144/3360) spt::bin/spt api::engineroom::tests::the_gate_admits_only_the_reserved_id_provisioned_and_authenticated\n     │...\n 1225│2026-09-10T13:25:54.6539965Z         PASS [   0.023s] ( 323/3360) spt::bin/spt cli::tests::any_single_evidence_source_is_enough_and_only_nothing_refuses\n*1226│2026-09-10T13:25:54.6600093Z         PASS [   0.192s] ( 324/3360) spt::bin/spt cli::tests::a_wedged_probe_costs_one_ceiling_and_reads_unknown_not_offline\n 1227│2026-09-10T13:25:54.6629975Z         PASS [   0.032s] ( 325/3360) spt::bin/spt cli::tests::an_undelivered_receipt_reports_only_the_receipt\n 1228│2026-09-10T13:25:54.6667711Z         PASS [   0.035s] ( 326/3360) spt::bin/spt cli::tests::answering_verbs_declare_no_directionality\n 1229│2026-09-10T13:25:54.6729894Z         PASS [   0.038s] ( 327/3360) spt::bin/spt cli::tests::api_adapter_flag_is_group_level_not_post_subcommand\n     │...\n 1276│2026-09-10T13:25:54.9680251Z         PASS [   0.128s] ( 374/3360) spt::bin/spt api::startup::tests::a_recycled_relay_pid_is_fixed_too_so_the_role_gate_is_not_carrying_this\n*1277│2026-09-10T13:25:54.9740021Z         PASS [   0.032s] ( 375/3360) spt::bin/spt cli::tests::every_mint_persist_site_asks_the_shared_probe\n 1278│2026-09-10T13:25:54.9799848Z         PASS [   0.125s] ( 376/3360) spt::bin/spt cli::tests::create_provisions_the_admin_key_and_show_code_never_does\n 1279│2026-09-10T13:25:54.9809759Z         PASS [   0.025s] ( 377/3360) spt::bin/spt cli::tests::every_send_outcome_is_answered_by_exactly_one_renderer\n 1280│2026-09-10T13:25:54.9870180Z         PASS [   0.034s] ( 378/3360) spt::bin/spt cli::tests::every_retired_access_token_still_reaches_the_positional\n     │...\n 1297│2026-09-10T13:25:55.0839739Z         PASS [   0.043s] ( 395/3360) spt::bin/spt cli::tests::grant_subcommands_parse\n*1298│2026-09-10T13:25:55.0909983Z         PASS [   0.027s] ( 396/3360) spt::bin/spt cli::tests::inbound_json_speaks_in_the_two_states_the_human_view_is_silent_in\n*1299│2026-09-10T13:25:55.0959890Z         PASS [   0.025s] ( 397/3360) spt::bin/spt cli::tests::inbound_verdict_rides_the_json_in_every_state_including_ok\n 1300│2026-09-10T13:25:55.1029855Z         PASS [   0.023s] ( 398/3360) spt::bin/spt cli::tests::install_place_is_idempotent_and_path_block_detected\n 1301│2026-09-10T13:25:55.1089952Z         PASS [   0.144s] ( 399/3360) spt::bin/spt api::startup::tests::api_bind_admits_the_reserved_id_only_as_a_bring_ups_completion\n 1302│2026-09-10T13:25:55.1149705Z         PASS [   0.167s] ( 400/3360) spt::bin/spt cli::tests::every_node_flag_teaches_all_three_spellings\n     │...\n 1330│2026-09-10T13:25:55.2429723Z         PASS [   0.298s] ( 428/3360) spt::bin/spt cli::tests::endpoint_role_overwrite_is_the_sole_writer\n*1331│2026-09-10T13:25:55.2479772Z         PASS [   0.031s] ( 429/3360) spt::bin/spt cli::tests::node_status_rows_settle_cheap_signals_probe_only_stale\n 1332│2026-09-10T13:25:55.2489774Z         PASS [   0.033s] ( 430/3360) spt::bin/spt cli::tests::not_elevated_refuses_without_leaking_code_or_saving\n 1333│2026-09-10T13:25:55.2522533Z         PASS [   0.027s] ( 431/3360) spt::bin/spt cli::tests::only_a_bake_that_can_admit_the_whole_node_demands_the_acknowledgment\n 1334│2026-09-10T13:25:55.2549652Z         PASS [   0.028s] ( 432/3360) spt::bin/spt cli::tests::only_a_multi_subnet_mint_warns_about_older_readers\n     │...\n 1350│2026-09-10T13:25:55.2718455Z         PASS [   0.031s] ( 448/3360) spt::bin/spt cli::tests::psyche_companion_is_named_without_a_status\n*1351│2026-09-10T13:25:55.2719434Z         PASS [   0.063s] ( 449/3360) spt::bin/spt cli::tests::probe_all_cap_batches_into_windows\n 1352│2026-09-10T13:25:55.2720261Z         PASS [   0.041s] ( 450/3360) spt::bin/spt cli::tests::purge_offline_gate_and_self_guard\n 1353│2026-09-10T13:25:55.2721161Z         PASS [   0.044s] ( 451/3360) spt::bin/spt cli::tests::registered_github_home_detects_active_collision\n 1354│2026-09-10T13:25:55.2722163Z         PASS [   0.024s] ( 452/3360) spt::bin/spt cli::tests::remote_cell_project_ref_from_gossiped_recent_projects\n     │...\n 1357│2026-09-10T13:25:55.2725548Z         PASS [   0.084s] ( 455/3360) spt::bin/spt cli::tests::release_archive_extracts_to_a_registrable_root\n*1358│2026-09-10T13:25:55.2726458Z         PASS [   0.028s] ( 456/3360) spt::bin/spt cli::tests::resolve_transport_auto_follows_probe\n 1359│2026-09-10T13:25:55.2727345Z         PASS [   0.029s] ( 457/3360) spt::bin/spt cli::tests::resolve_proof_target_override_reads_on_disk\n 1360│2026-09-10T13:25:55.2728220Z         PASS [   0.020s] ( 458/3360) spt::bin/spt cli::tests::rest_filter_status_first_ordering\n 1361│2026-09-10T13:25:55.2729249Z         PASS [   0.021s] ( 459/3360) spt::bin/spt cli::tests::rest_filter_hides_suspended_shows_all_and_corrupt_always\n*1362│2026-09-10T13:25:55.2759489Z         PASS [   0.029s] ( 460/3360) spt::bin/spt cli::tests::resolve_transport_explicit_never_probes\n*1363│2026-09-10T13:25:55.2760559Z         PASS [   0.187s] ( 461/3360) spt::bin/spt cli::tests::probe_all_timeout_settles_false_without_stalling_batch\n 1364│2026-09-10T13:25:55.2761532Z         PASS [   0.020s] ( 462/3360) spt::bin/spt cli::tests::restart_plans_lethal_leg_last\n 1365│2026-09-10T13:25:55.2762438Z         PASS [   0.022s] ( 463/3360) spt::bin/spt cli::tests::rest_filter_total_disclosure_and_corrupt_annotation\n 1366│2026-09-10T13:25:55.2763435Z         PASS [   0.175s] ( 464/3360) spt::bin/spt cli::tests::purge_force_asks_before_it_tears_anything_down\n     │...\n 1374│2026-09-10T13:25:55.2790255Z         PASS [   0.025s] ( 472/3360) spt::bin/spt cli::tests::self_pin_annotates_psyche_host_failure\n*1375│2026-09-10T13:25:55.2870265Z         PASS [   0.248s] ( 473/3360) spt::bin/spt cli::tests::probe_all_runs_concurrently_in_input_order\n 1376│2026-09-10T13:25:55.2970071Z         PASS [   0.026s] ( 474/3360) spt::bin/spt cli::tests::self_pin_includes_description_when_present\n 1377│2026-09-10T13:25:55.2999762Z         PASS [   0.021s] ( 475/3360) spt::bin/spt cli::tests::self_pin_names_the_registered_drop_dir_only_when_known\n 1378│2026-09-10T13:25:55.3090344Z         PASS [   0.249s] ( 476/3360) spt::bin/spt cli::tests::public_help_carries_no_internal_codes_at_any_ruled_site\n     │...\n 1432│2026-09-10T13:25:55.8129690Z         PASS [   0.025s] ( 530/3360) spt::bin/spt cli::tests::the_locked_claim_carries_its_caveat_in_the_same_emission\n*1433│2026-09-10T13:25:55.8189731Z         PASS [   0.023s] ( 531/3360) spt::bin/spt cli::tests::the_mint_probe_answers_only_for_a_fresh_mint\n 1434│2026-09-10T13:25:55.8219650Z         PASS [   0.033s] ( 532/3360) spt::bin/spt cli::tests::the_knock_prescription_names_the_fork_pair_only_where_it_is_needed\n 1435│2026-09-10T13:25:55.8309986Z         PASS [   0.024s] ( 533/3360) spt::bin/spt cli::tests::the_positional_allow_spelling_carries_its_flags_into_the_rule\n 1436│2026-09-10T13:25:55.8340214Z         PASS [   0.022s] ( 534/3360) spt::bin/spt cli::tests::the_positional_spelling_cannot_step_around_the_admit_node_acknowledgment\n     │...\n 1647│2026-09-10T13:25:56.7240189Z         PASS [   0.046s] ( 745/3360) spt::bin/spt roster::tests::detect_self_by_ancestry_resolves_a_live_ancestor_perch\n*1648│2026-09-10T13:25:56.7299970Z         PASS [   0.157s] ( 746/3360) spt::bin/spt rc::tests::establish_attach_reuses_the_probes_carried_pump_conn\n 1649│2026-09-10T13:25:56.7360095Z         PASS [   0.031s] ( 747/3360) spt::bin/spt roster::tests::list_all_perch_dirs_enumerates_nested_psyche_for_self_resolution\n 1650│2026-09-10T13:25:56.7389976Z         PASS [   0.049s] ( 748/3360) spt::bin/spt roster::tests::detect_self_id_resolves_identity_with_zero_git_spawns\n 1651│2026-09-10T13:25:56.7450012Z         PASS [   0.015s] ( 749/3360) spt::bin/spt roster::tests::the_ambiguity_diagnostic_names_every_tied_id_and_the_shared_pid\n     │...\n 1675│2026-09-10T13:25:56.8789820Z         PASS [   0.032s] ( 773/3360) spt::bin/spt unlisted::tests::a_receipt_proven_cross_node_knock_renders_its_answer\n*1676│2026-09-10T13:25:56.8849823Z         PASS [   0.025s] ( 774/3360) spt::bin/spt unlisted::tests::an_inbound_knock_is_never_read_as_our_own_outbound_act\n 1677│2026-09-10T13:25:56.8909836Z         PASS [   0.037s] ( 775/3360) spt::bin/spt unlisted::tests::a_rule_only_row_has_no_node_to_route_to\n 1678│2026-09-10T13:25:56.8970573Z         PASS [   0.026s] ( 776/3360) spt::bin/spt unlisted::tests::an_unproven_cross_node_knock_says_no_answer_while_a_same_node_one_says_approved\n 1679│2026-09-10T13:25:56.9040496Z         PASS [   0.029s] ( 777/3360) spt::bin/spt unlisted::tests::contact_evidence_outside_the_window_produces_no_row\n     │...\n 1701│2026-09-10T13:25:57.0339889Z         PASS [   0.034s] ( 799/3360) spt-daemon access::tests::same_node_always_passes_without_minting\n*1702│2026-09-10T13:25:57.0399736Z         PASS [   0.028s] ( 800/3360) spt-daemon access::tests::the_inbound_lock_answers_replies_only_and_only_while_controlled\n*1703│2026-09-10T13:25:57.0459833Z         PASS [   0.029s] ( 801/3360) spt-daemon access::tests::the_engine_room_refuses_even_this_nodes_own_unsolicited_inbound\n 1704│2026-09-10T13:25:57.0489574Z         PASS [   0.026s] ( 802/3360) spt-daemon access::tests::the_wire_origin_stamp_reaches_the_chain\n*1705│2026-09-10T13:25:57.0519736Z         PASS [   0.036s] ( 803/3360) spt-daemon access::tests::the_inbound_lock_is_reached_through_the_sender_stamped_entry_point\n 1706│2026-09-10T13:25:57.0580140Z         PASS [   0.023s] ( 804/3360) spt-daemon activity::tests::a_token_change_with_an_identical_state_owes_a_push\n 1707│2026-09-10T13:25:57.0639951Z         PASS [   0.106s] ( 805/3360) spt::bin/spt api::startup::tests::bind_records_cwd_so_picker_can_group_by_project\n 1708│2026-09-10T13:25:57.0699767Z         PASS [   0.019s] ( 806/3360) spt-daemon activity::tests::an_owner_with_no_linked_shell_is_not_observed\n## test-windows-102886952516.log\n  222│2026-09-10T13:28:59.4630706Z \u001b[36;1mcargo build -p mock-adapter --bin capture-player\u001b[0m\n *223│2026-09-10T13:28:59.4630950Z \u001b[36;1mcargo build -p mock-adapter --bin console-mode-probe\u001b[0m\n  224│2026-09-10T13:28:59.4631234Z \u001b[36;1mcargo build -p spt-daemon --bin service_fixture\u001b[0m\n  225│2026-09-10T13:28:59.4631503Z \u001b[36;1mcargo build --workspace\u001b[0m\n  226│2026-09-10T13:28:59.4636299Z shell: C:\\Program Files\\PowerShell\\7\\pwsh.EXE -command \". '{0}'\"\n     │...\n  824│2026-09-10T13:45:21.2618960Z         PASS [  19.846s] (  26/3381) spt::broker_stop_endpoint_deny_e2e an_endpoint_context_cannot_stop_the_broker_by_any_flag\n *825│2026-09-10T13:45:22.3245837Z         PASS [   8.738s] (  27/3381) spt::er_inbound_local a_local_send_meets_the_engine_rooms_inbound_lock_on_every_authoring_path\n  826│2026-09-10T13:45:22.9220250Z         PASS [   0.598s] (  28/3381) spt::hide_new_remote_rows_e2e hide_new_keeps_our_own_endpoint_hidden_and_leaves_other_nodes_rows_alone\n  827│2026-09-10T13:45:23.0790693Z         PASS [   1.817s] (  29/3381) spt::gateway_e2e gateway_binds_and_is_the_user_backed_origin\n  828│2026-09-10T13:45:23.4695311Z         PASS [  10.317s] (  30/3381) spt::drive_e2e drive_channel_slot_through_the_real_socket\n     │...\n  947│2026-09-10T13:46:04.1526299Z         PASS [   0.501s] ( 149/3381) spt::bin/spt api::engineroom::tests::another_endpoints_traffic_never_answers_the_engine_rooms_gate\n *948│2026-09-10T13:46:04.1612697Z         PASS [   0.498s] ( 150/3381) spt::bin/spt api::engineroom::tests::ordinary_perch_minting_never_probes_the_engine_room\n  949│2026-09-10T13:46:04.1667735Z         PASS [   0.495s] ( 151/3381) spt::bin/spt api::engineroom::tests::subnet_authority_is_the_empowerment_not_the_gate\n  950│2026-09-10T13:46:04.5173279Z         PASS [   0.782s] ( 152/3381) spt::bin/spt api::engineroom::tests::the_gate_admits_only_the_reserved_id_provisioned_and_authenticated\n  951│2026-09-10T13:46:04.5414657Z         PASS [   0.639s] ( 153/3381) spt::bin/spt api::engineroom::tests::the_perch_minting_verbs_admit_the_reserved_id_only_as_a_completion\n     │...\n 1102│2026-09-10T13:46:32.7049004Z         PASS [   7.205s] ( 304/3381) spt::bin/spt cli::reserved_id_tests::rename_into_the_reserved_id_is_refused\n*1103│2026-09-10T13:46:32.8059737Z         PASS [   0.247s] ( 305/3381) spt::bin/spt cli::tests::a_wedged_probe_costs_one_ceiling_and_reads_unknown_not_offline\n 1104│2026-09-10T13:46:33.1329994Z         PASS [   0.503s] ( 306/3381) spt::bin/spt api::startup::tests::api_bind_admits_the_reserved_id_only_as_a_bring_ups_completion\n 1105│2026-09-10T13:46:33.1439150Z         PASS [   0.439s] ( 307/3381) spt::bin/spt cli::tests::adapter_name_validation_flags_every_unknown\n 1106│2026-09-10T13:46:33.1552863Z         PASS [   0.349s] ( 308/3381) spt::bin/spt cli::tests::adapter_names_comma_list_parses_and_refuses_empties\n     │...\n 1191│2026-09-10T13:46:41.8916421Z         PASS [   0.444s] ( 393/3381) spt::bin/spt cli::tests::escalation_choice_parses_fail_closed\n*1192│2026-09-10T13:46:41.9396458Z         PASS [   0.486s] ( 394/3381) spt::bin/spt cli::tests::every_mint_persist_site_asks_the_shared_probe\n 1193│2026-09-10T13:46:41.9936803Z         PASS [   0.161s] ( 395/3381) spt::bin/spt cli::tests::every_retired_access_token_still_reaches_the_positional\n 1194│2026-09-10T13:46:41.9955919Z         PASS [   0.432s] ( 396/3381) spt::bin/spt cli::tests::every_read_status_command_accepts_the_global_json_flag\n 1195│2026-09-10T13:46:42.0020437Z         PASS [   0.111s] ( 397/3381) spt::bin/spt cli::tests::every_send_outcome_is_answered_by_exactly_one_renderer\n     │...\n 1216│2026-09-10T13:46:43.1152780Z         PASS [   0.544s] ( 418/3381) spt::bin/spt cli::tests::how_to_topics_cover_ready_and_send\n*1217│2026-09-10T13:46:43.1592049Z         PASS [   0.577s] ( 419/3381) spt::bin/spt cli::tests::inbound_json_speaks_in_the_two_states_the_human_view_is_silent_in\n*1218│2026-09-10T13:46:43.1713806Z         PASS [   0.571s] ( 420/3381) spt::bin/spt cli::tests::inbound_verdict_rides_the_json_in_every_state_including_ok\n 1219│2026-09-10T13:46:43.1892121Z         PASS [   0.582s] ( 421/3381) spt::bin/spt api::startup::tests::empty_session_seed_refused\n 1220│2026-09-10T13:46:43.2007729Z         PASS [   0.219s] ( 422/3381) spt::bin/spt cli::tests::install_platform_check_gates_stamp_and_host_arch\n 1221│2026-09-10T13:46:43.2010780Z         PASS [   0.585s] ( 423/3381) spt::bin/spt cli::tests::install_place_is_idempotent_and_path_block_detected\n     │...\n 1248│2026-09-10T13:46:44.2538937Z         PASS [   0.447s] ( 450/3381) spt::bin/spt cli::tests::node_status_rows_denominator_counts_routable_only\n*1249│2026-09-10T13:46:44.2625609Z         PASS [   0.443s] ( 451/3381) spt::bin/spt cli::tests::node_status_rows_settle_cheap_signals_probe_only_stale\n 1250│2026-09-10T13:46:44.2700247Z         PASS [   0.443s] ( 452/3381) spt::bin/spt cli::tests::not_elevated_refuses_without_leaking_code_or_saving\n 1251│2026-09-10T13:46:44.2815113Z         PASS [   0.447s] ( 453/3381) spt::bin/spt cli::tests::notify_subnet_resolution_home_default\n 1252│2026-09-10T13:46:44.3059226Z         PASS [   0.052s] ( 454/3381) spt::bin/spt cli::tests::only_a_bake_that_can_admit_the_whole_node_demands_the_acknowledgment\n     │...\n 1266│2026-09-10T13:46:44.8456333Z         PASS [   0.125s] ( 468/3381) spt::bin/spt cli::tests::post_step_notice_arbitration\n*1267│2026-09-10T13:46:44.8575675Z         PASS [   0.098s] ( 469/3381) spt::bin/spt cli::tests::probe_all_cap_batches_into_windows\n 1268│2026-09-10T13:46:44.8854262Z         PASS [   0.049s] ( 470/3381) spt::bin/spt api::startup::tests::listen_online_gate_refuses_capability_only_online\n 1269│2026-09-10T13:46:44.8937677Z         PASS [   0.048s] ( 471/3381) spt::bin/spt cli::tests::project_index_line_states_health_not_presence\n 1270│2026-09-10T13:46:44.9018692Z         PASS [   0.044s] ( 472/3381) spt::bin/spt cli::tests::prune_candidates_resolve_never_guess\n*1271│2026-09-10T13:46:45.0376448Z         PASS [   0.210s] ( 473/3381) spt::bin/spt cli::tests::probe_all_timeout_settles_false_without_stalling_batch\n*1272│2026-09-10T13:46:45.0689919Z         PASS [   0.256s] ( 474/3381) spt::bin/spt cli::tests::probe_all_runs_concurrently_in_input_order\n 1273│2026-09-10T13:46:45.2489852Z         PASS [   0.363s] ( 475/3381) spt::bin/spt api::startup::tests::listen_orphan_exit_line_names_self_and_parent\n 1274│2026-09-10T13:46:45.2860782Z         PASS [   0.392s] ( 476/3381) spt::bin/spt cli::tests::psyche_companion_is_named_without_a_status\n 1275│2026-09-10T13:46:45.4248069Z         PASS [   4.032s] ( 477/3381) spt::bin/spt cli::tests::endpoint_role_overwrite_is_the_sole_writer\n     │...\n 1286│2026-09-10T13:46:47.7416095Z         PASS [   0.418s] ( 488/3381) spt::bin/spt cli::tests::resolve_proof_target_override_reads_on_disk\n*1287│2026-09-10T13:46:47.7798540Z         PASS [   0.439s] ( 489/3381) spt::bin/spt cli::tests::resolve_transport_auto_follows_probe\n*1288│2026-09-10T13:46:47.8000243Z         PASS [   0.423s] ( 490/3381) spt::bin/spt cli::tests::resolve_transport_explicit_never_probes\n 1289│2026-09-10T13:46:48.1483666Z         PASS [   0.431s] ( 491/3381) spt::bin/spt api::startup::tests::only_an_unverified_refusal_names_its_escape\n 1290│2026-09-10T13:46:48.1875282Z         PASS [   0.446s] ( 492/3381) spt::bin/spt cli::tests::rest_filter_hides_suspended_shows_all_and_corrupt_always\n 1291│2026-09-10T13:46:48.2347282Z         PASS [   0.455s] ( 493/3381) spt::bin/spt cli::tests::rest_filter_status_first_ordering\n     │...\n 1374│2026-09-10T13:46:59.7366180Z         PASS [   0.030s] ( 576/3381) spt::bin/spt cli::tests::the_locked_claim_carries_its_caveat_in_the_same_emission\n*1375│2026-09-10T13:46:59.7485804Z         PASS [   0.038s] ( 577/3381) spt::bin/spt cli::tests::the_mint_probe_answers_only_for_a_fresh_mint\n 1376│2026-09-10T13:46:59.8301919Z         PASS [   0.137s] ( 578/3381) spt::bin/spt cli::tests::the_local_and_wire_arms_write_one_identical_grant\n 1377│2026-09-10T13:47:00.1463341Z         PASS [   0.316s] ( 579/3381) spt::bin/spt cli::tests::the_positional_allow_spelling_carries_its_flags_into_the_rule\n 1378│2026-09-10T13:47:00.2025108Z         PASS [   0.056s] ( 580/3381) spt::bin/spt cli::tests::the_positional_spelling_cannot_step_around_the_admit_node_acknowledgment\n     │...\n 1556│2026-09-10T13:47:26.3579006Z         PASS [   2.235s] ( 758/3381) spt::bin/spt rc::tests::fold_code_key_prompt_rules\n*1557│2026-09-10T13:47:26.4197178Z         PASS [   2.677s] ( 759/3381) spt::bin/spt rc::tests::establish_attach_reuses_the_probes_carried_pump_conn\n 1558│2026-09-10T13:47:27.0758162Z         PASS [   2.588s] ( 760/3381) spt::bin/spt rc::tests::give_up_copy_names_daemon_down_vs_generic\n 1559│2026-09-10T13:47:27.7818872Z         PASS [   3.283s] ( 761/3381) spt::bin/spt rc::tests::harness_only_row_matches_online_seatless_live_agents_only\n 1560│2026-09-10T13:47:28.4999714Z         PASS [   3.710s] ( 762/3381) spt::bin/spt rc::tests::broker_host_child\n     │...\n 1631│2026-09-10T13:47:38.7702664Z         PASS [   1.638s] ( 833/3381) spt::bin/spt unlisted::tests::an_exclusion_outranks_the_strongest_evidence\n*1632│2026-09-10T13:47:39.1579922Z         PASS [   1.986s] ( 834/3381) spt::bin/spt unlisted::tests::an_inbound_knock_is_never_read_as_our_own_outbound_act\n 1633│2026-09-10T13:47:39.5054685Z         PASS [   1.931s] ( 835/3381) spt::bin/spt unlisted::tests::an_unproven_cross_node_knock_says_no_answer_while_a_same_node_one_says_approved\n 1634│2026-09-10T13:47:39.5352370Z         PASS [   1.587s] ( 836/3381) spt::bin/spt unlisted::tests::contact_evidence_outside_the_window_produces_no_row\n 1635│2026-09-10T13:47:39.5586929Z         PASS [   1.589s] ( 837/3381) spt::bin/spt unlisted::tests::listed_local_and_excluded_rows_are_dropped_and_the_rest_survive\n     │...\n 1656│2026-09-10T13:47:46.5578256Z         PASS [   3.961s] ( 858/3381) spt-daemon access::tests::the_engine_room_is_disclosed_only_to_the_viewers_it_chose\n*1657│2026-09-10T13:47:47.8664056Z         PASS [   4.896s] ( 859/3381) spt-daemon access::tests::the_engine_room_refuses_even_this_nodes_own_unsolicited_inbound\n*1658│2026-09-10T13:47:49.5625496Z         PASS [   6.240s] ( 860/3381) spt-daemon access::tests::the_inbound_lock_answers_replies_only_and_only_while_controlled\n 1659│2026-09-10T13:47:51.2677201Z         PASS [   7.599s] ( 861/3381) spt::bin/spt wansend::tests::a_shared_short_key_refuses_and_an_unknown_one_is_its_own_outcome\n*1660│2026-09-10T13:47:51.3420793Z         PASS [   7.277s] ( 862/3381) spt-daemon access::tests::the_inbound_lock_is_reached_through_the_sender_stamped_entry_point\n 1661│2026-09-10T13:47:51.3555769Z         PASS [   6.247s] ( 863/3381) spt-daemon access::tests::the_trust_warning_fires_only_for_an_entry_admitted_stranger\n 1662│2026-09-10T13:47:51.3767295Z         PASS [   5.590s] ( 864/3381) spt-daemon access::tests::the_wire_origin_stamp_reaches_the_chain\n 1663│2026-09-10T13:47:51.3863925Z         PASS [   6.993s] ( 865/3381) spt-daemon access::tests::the_pass_reason_names_which_arm_admitted_the_interaction\n     │...\n 1681│2026-09-10T13:47:51.9529269Z         PASS [   0.073s] ( 883/3381) spt-daemon adapter_update::tests::file_pull_verified_against_adapter_key\n*1682│2026-09-10T13:47:51.9677570Z         PASS [   0.072s] ( 884/3381) spt::bin/spt wansend::tests::a_silent_probe_renders_unknown_and_never_offline\n 1683│2026-09-10T13:47:51.9683428Z         PASS [   0.080s] ( 885/3381) spt-daemon adapter_update::tests::file_pull_wrong_key_rejected\n 1684│2026-09-10T13:47:51.9750180Z         PASS [   0.070s] ( 886/3381) spt-daemon adapter_update::tests::gh_release_is_managed_cli_side_not_in_pure_plan\n 1685│2026-09-10T13:47:51.9911572Z         PASS [   0.081s] ( 887/3381) spt-daemon adapter_update::tests::ripple_conducts_each_adapter_in_order"},"isError":false,"timestamp":1789094648563}}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_TvdhAFPSgGnVFCB8KbkpWsFC|fc_065c0d1976ecf9c2016aa36b002b8087d1af78b8ab5d25a6bc","toolName":"read","startedAt":"2026-09-11T02:44:18.575Z","args":{"path":"docs/GOLDEN-CI.md:26-60"},"intent":"Reading quiet window rule"},"id":"805c7ab1","parentId":"1a38fa2d","timestamp":"2026-09-11T02:44:18.575Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_h096cQc3R48Kz0t8cKLfvkV4|fc_065c0d1976ecf9c2016aa36b002b9087d1b908897854eebd83","toolName":"read","startedAt":"2026-09-11T02:44:18.576Z","args":{"path":"Cargo.toml:35-54"},"intent":"Reading workspace profile"},"id":"5d7e7484","parentId":"805c7ab1","timestamp":"2026-09-11T02:44:18.576Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_YLrtkY3zMX578FzkdiKqOq5q|fc_065c0d1976ecf9c2016aa36b002b9887d186b69d1e464b8882","toolName":"read","startedAt":"2026-09-11T02:44:18.576Z","args":{"path":"docs/INFRA-REGISTER.md:3155-3156:raw"},"intent":"Reading audit catch untruncated"},"id":"c07f467e","parentId":"5d7e7484","timestamp":"2026-09-11T02:44:18.576Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_6xoq3zboVp94desjJXKoKRFP|fc_065c0d1976ecf9c2016aa36b002b9c87d19b9520f41864f776","toolName":"grep","startedAt":"2026-09-11T02:44:18.576Z","args":{"path":".github/ci/reap-census.ps1"},"intent":"Checking load census scope"},"id":"a2bde7cf","parentId":"c07f467e","timestamp":"2026-09-11T02:44:18.576Z"}
{"type":"message","id":"bd8584ad","parentId":"a2bde7cf","timestamp":"2026-09-11T02:44:18.577Z","message":{"role":"assistant","content":[{"type":"thinking","thinking":"**Locating IR76 document**"},{"type":"toolCall","id":"call_TvdhAFPSgGnVFCB8KbkpWsFC|fc_065c0d1976ecf9c2016aa36b002b8087d1af78b8ab5d25a6bc","name":"read","arguments":{"i":"Reading quiet window rule","path":"docs/GOLDEN-CI.md:26-60"},"intent":"Reading quiet window rule"},{"type":"toolCall","id":"call_h096cQc3R48Kz0t8cKLfvkV4|fc_065c0d1976ecf9c2016aa36b002b9087d1b908897854eebd83","name":"read","arguments":{"i":"Reading workspace profile","path":"Cargo.toml:35-54"},"intent":"Reading workspace profile"},{"type":"toolCall","id":"call_YLrtkY3zMX578FzkdiKqOq5q|fc_065c0d1976ecf9c2016aa36b002b9887d186b69d1e464b8882","name":"read","arguments":{"i":"Reading audit catch untruncated","path":"docs/INFRA-REGISTER.md:3155-3156:raw"},"intent":"Reading audit catch untruncated"},{"type":"toolCall","id":"call_6xoq3zboVp94desjJXKoKRFP|fc_065c0d1976ecf9c2016aa36b002b9c87d19b9520f41864f776","name":"grep","arguments":{"i":"Checking load census scope","pattern":"cargo|rustc|nextest|link.exe|Family|family","path":".github/ci/reap-census.ps1","case":false,"gitignore":true,"skip":0},"intent":"Checking load census scope"},{"type":"toolCall","id":"call_p1uWVWlZixqGMBhWtSl8cLhB|fc_065c0d1976ecf9c2016aa36b002ba487d1acd22b100eb8a734","name":"glob","arguments":{"i":"Locating preserved twohost records","path":".spt/preserved/**/*twohost*;.spt/preserved/**/*344459*","hidden":true,"gitignore":false,"limit":35},"intent":"Locating preserved twohost records"}],"api":"openai-codex-responses","provider":"openai-codex","model":"gpt-6-astra","usage":{"input":27952,"output":247,"cacheRead":122240,"cacheWrite":0,"totalTokens":150439,"reasoningTokens":22,"cost":{"input":0,"output":0,"cacheRead":0,"cacheWrite":0,"total":0}},"stopReason":"toolUse","timestamp":1789094648618,"responseId":"resp_065c0d1976ecf9c2016aa36af6c48087d1ac969f333d01de79","providerPayload":{"type":"openaiResponsesHistory","provider":"openai-codex","dt":true,"items":[{"id":"rs_065c0d1976ecf9c2016aa36af90b8887d19423b5c6e6d0817c","type":"reasoning","content":[],"encrypted_content":"gAAAAABqo2sADnnkvklnAyWsUu_hSfdQfDAqt19jKJI9nPxm2JMuk3T-BbBIvIbVAtmxZfq9a74vU2rXTwNqbGDh_wivRUJ_tZr0msmibK_REtXoCrtOg57WEDVjs_g0XzB9a-vPkKUzCCkuvTJhSimzxfmMTkHx4LVQSQrfhs0CNCDW6yfEcHMWwCiD4WTF-XRcgj0z9YfaFMAS0VPndx0I9awyQ8gry2ROZA57JnD2xifVpAkCQ9TyFpSsS8YYgM7md77SxGDgPVpUaehP6LijCIOlOKcC5johNH8ogjV1ezPKjPPacFkdObXSFIv2uKmESaX5w51e3tBvmWACMc64yvkb41ViYHl9E3ZAmI2vOe5E8pv3dEspXBGNf35cq_s0zvMTmHUIz7ezXQUu4_PTlCZ7quU3uaCS_j3crndKLPE-YL54Q-RwB9S2F_NRgpyVutn9001rC3bzbO30MpiQJr_2e5jcqFWjpdC6kCKpGGsOGPKnFRNKgngobIFMtBD9aB0AS3c5F3-kRc0GEOnx2wkbxQngdbTTr47keIICzeefbFa-bLQFEUBkVrzW3F8Yu18AmFPtVH0nwcVdKgBcCsAW4dJYDfn4LcQBHi7IDrNrljUuZWmNE3q2YqISDaU8btJUEbQ3UM-BY4kewlO3jRmTHDS4kLnATTrLsOoNoiblkeEYl0nm2gF98Avdu4V92U8vSyoE8UGg2qltqmzKnifvMvX_tNkgJLLMOw32dSrJs0VCZxk4KnQwjYMiURUfztr5x3tl9fJl7TVup2prBIdHM0KmPXmEbzBTApZupAkrEsyzI153DsqzGnlVxxJZOc6NRFZYDaHZfRwg9sdxCDgP6VJiBWsMcDlFcslUVdSKxS_28jTaCeyXAh8pjjgP_l7w5WKBe4NTMNpY1Ecn8HFaggrEiq9n8jr5sr6K-zis7qIqlVa_bwDxIXO0lOu_nO6pk3pNTYEDfeomh1-cd-zNcn_OvSDAKduYfXg0rNBgNv1cMOUxPTrZc1tMy1BUzB5BzTVzpqrn2HOuRgD5gfQ_pw2vPKiWrhXFbyWJqMHy3fS5okuqmuC8tQEx8px3F8r0J98lv6QAkefbT0tnq8MMKpDpglq_iAAKzd1NlNhDf6wjhsmaVGgc12JGJC-kGcgx3ts2s4aEBt_7WwMt7spkCBEZUdwZ6ZQYrrx_rZI5VqNhU1ygoiZWqmeR7ebp_7iil56uoDbjSXzhynwm--Dgqc7-ATTPAMQ3LhCB-NInmm9FP8tm0e28BnuVZT6rzopDzOwAbfVoSOEBiFJ1r0csN9j4TZD8pj60T7-lUSxZ7Ui9SVykHwu0sGjXa-NtwydTMlcQxfqVlBPjBcnI-c8f5ybnlIgAmZ1hKe5Fo_RHErzoi7w=","internal_chat_message_metadata_passthrough":{"turn_id":"cb1368d9-2a08-40c0-9f68-e06c6338cbd5"},"summary":[{"type":"summary_text","text":"**Locating IR76 document**"}],"metadata":{"turn_id":"cb1368d9-2a08-40c0-9f68-e06c6338cbd5"}},{"id":"fc_065c0d1976ecf9c2016aa36b002b8087d1af78b8ab5d25a6bc","type":"function_call","status":"completed","arguments":"{\"i\":\"Reading quiet window rule\",\"path\":\"docs/GOLDEN-CI.md:26-60\"}","call_id":"call_TvdhAFPSgGnVFCB8KbkpWsFC","internal_chat_message_metadata_passthrough":{"turn_id":"cb1368d9-2a08-40c0-9f68-e06c6338cbd5"},"name":"read","metadata":{"turn_id":"cb1368d9-2a08-40c0-9f68-e06c6338cbd5"}},{"id":"fc_065c0d1976ecf9c2016aa36b002b9087d1b908897854eebd83","type":"function_call","status":"completed","arguments":"{\"i\":\"Reading workspace profile\",\"path\":\"Cargo.toml:35-54\"}","call_id":"call_h096cQc3R48Kz0t8cKLfvkV4","internal_chat_message_metadata_passthrough":{"turn_id":"cb1368d9-2a08-40c0-9f68-e06c6338cbd5"},"name":"read","metadata":{"turn_id":"cb1368d9-2a08-40c0-9f68-e06c6338cbd5"}},{"id":"fc_065c0d1976ecf9c2016aa36b002b9887d186b69d1e464b8882","type":"function_call","status":"completed","arguments":"{\"i\":\"Reading audit catch untruncated\",\"path\":\"docs/INFRA-REGISTER.md:3155-3156:raw\"}","call_id":"call_YLrtkY3zMX578FzkdiKqOq5q","internal_chat_message_metadata_passthrough":{"turn_id":"cb1368d9-2a08-40c0-9f68-e06c6338cbd5"},"name":"read","metadata":{"turn_id":"cb1368d9-2a08-40c0-9f68-e06c6338cbd5"}},{"id":"fc_065c0d1976ecf9c2016aa36b002b9c87d19b9520f41864f776","type":"function_call","status":"completed","arguments":"{\"i\":\"Checking load census scope\",\"pattern\":\"cargo|rustc|nextest|link.exe|Family|family\",\"path\":\".github/ci/reap-census.ps1\",\"case\":false,\"gitignore\":true,\"skip\":0}","call_id":"call_6xoq3zboVp94desjJXKoKRFP","internal_chat_message_metadata_passthrough":{"turn_id":"cb1368d9-2a08-40c0-9f68-e06c6338cbd5"},"name":"grep","metadata":{"turn_id":"cb1368d9-2a08-40c0-9f68-e06c6338cbd5"}},{"id":"fc_065c0d1976ecf9c2016aa36b002ba487d1acd22b100eb8a734","type":"function_call","status":"completed","arguments":"{\"i\":\"Locating preserved twohost records\",\"path\":\".spt/preserved/**/*twohost*;.spt/preserved/**/*344459*\",\"hidden\":true,\"gitignore\":false,\"limit\":35}","call_id":"call_p1uWVWlZixqGMBhWtSl8cLhB","internal_chat_message_metadata_passthrough":{"turn_id":"cb1368d9-2a08-40c0-9f68-e06c6338cbd5"},"name":"glob","metadata":{"turn_id":"cb1368d9-2a08-40c0-9f68-e06c6338cbd5"}}]},"duration":9952.083700000308,"ttft":2780.7439000001177,"completedAt":1789094658573,"contextSnapshot":{"promptTokens":150192,"nonMessageTokens":10400,"compactionEpoch":0}}}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_p1uWVWlZixqGMBhWtSl8cLhB|fc_065c0d1976ecf9c2016aa36b002ba487d1acd22b100eb8a734","toolName":"glob","startedAt":"2026-09-11T02:44:18.577Z","args":{"path":".spt/preserved/**/*twohost*;.spt/preserved/**/*344459*"},"intent":"Locating preserved twohost records"},"id":"bbea1575","parentId":"bd8584ad","timestamp":"2026-09-11T02:44:18.577Z"}
{"type":"message","id":"a7b94c8a","parentId":"bbea1575","timestamp":"2026-09-11T02:44:18.599Z","message":{"role":"toolResult","toolCallId":"call_TvdhAFPSgGnVFCB8KbkpWsFC|fc_065c0d1976ecf9c2016aa36b002b8087d1af78b8ab5d25a6bc","toolName":"read","content":[{"type":"text","text":"## Step timings leave as an artifact\n…\n\n## Shared-runner quiet-window predicate\n\n<!-- [doc->REQ-GOLDEN-CI-LANE] -->\n\nA shared box is quiet only when **both** conditions hold:\n\n1. zero non-terminal CI runs; and\n2. no local `cargo`, `rustc`, or `cargo-nextest` process alive on the box.\n\nA GitHub-only drain check reads clean while another agent is mid-local-build. That is the contention class that muddied the g6 evidence twice. These axes are proxies for contention, not a definition of quiet; a proxy returning “quiet” is not itself a measurement of quiet.\n\n### Queue status is not occupancy\n\n`gh run list` status is not an occupancy probe. A run can report `queued` while its job is already executing on the box; this was observed on #121/#122 with `Runner.Worker` and `cargo-nextest` live and a suite mid-flight. Therefore `queued` never means “not started,” and an idle-looking queue is not evidence of a deaf runner.\n\nThe authoritative occupancy signal is the process table. `Runner.Worker` means a job is running on this box. `cargo-nextest` means a suite is running, which is the seedmap-starvation collision.\n\n### Attribute process load before counting it\n\nThe two predicate axes are not independent: a CI job manifests in the local process table as `cargo` and `rustc`. Their presence does not imply a second occupant. Walk each PID's parent chain before counting it as new load:\n\n- a chain rooted at `Runner.Worker.exe`, `Runner.Listener.exe`, or `RunnerService.exe` is the CI axis already counted;\n- a chain rooted at a user shell is a genuine second occupant, so hold.\n\nOwner queries alone are insufficient. The runner service account can return empty owner and command-line fields; use the parent chain. Report attributed load, not bare process presence: “live local cargo” and “box free of a second occupant” can both be true.\n\n### The link is a third axis, and it is measured rather than assumed\n\n<!-- [doc->REQ-CI-LINK-HEALTH-PROBE] -->\n\nBoth axes above are process-shaped. A box can be quiet by both and still be a bad place to run a two-host rendezvous, because neither axis can see the link. Run 30771155390 is the specimen: zero non-terminal runs, no local build, and a link so degraded that a 1-second checkout took 321 seconds with bidirectional 10-second QUIC dial timeouts. Its `PUMP_PEER_FAIL` counts moved 0→3→0 on one host and 8→22→8 on the other across green/red/rerun, and the red was triaged as if it were a product failure because nothing in the run recorded what the network was doing.\n\nkitsubito's only link is wifi, indefinitely (operator-confirmed 2026-08-02). The link cannot be hardened, so the predicate has to see it.\n\nBoth two-host jobs therefore probe the peer immediately before rendezvous, via `.github/bench/link-probe.sh` (Linux) and `.github/bench/link-probe.ps1` (Windows), and each writes its result into the run's bench ledger. Read the probe's line like this:\n\n```\nLINK peer=kitsubito ip=100.98.197.12 path=direct samples=5/5 min=10ms med=15ms max=83ms rtts=10,12,15,81,83\n```\n…\n\n…\n\n\n[Showing lines 25-63 of 119. Use :64 to continue]"}],"details":{"truncation":{"content":"\r\n## Shared-runner quiet-window predicate\r\n\r\n<!-- [doc->REQ-GOLDEN-CI-LANE] -->\r\n\r\nA shared box is quiet only when **both** conditions hold:\r\n\r\n1. zero non-terminal CI runs; and\r\n2. no local `cargo`, `rustc`, or `cargo-nextest` process alive on the box.\r\n\r\nA GitHub-only drain check reads clean while another agent is mid-local-build. That is the contention class that muddied the g6 evidence twice. These axes are proxies for contention, not a definition of quiet; a proxy returning “quiet” is not itself a measurement of quiet.\r\n\r\n### Queue status is not occupancy\r\n\r\n`gh run list` status is not an occupancy probe. A run can report `queued` while its job is already executing on the box; this was observed on #121/#122 with `Runner.Worker` and `cargo-nextest` live and a suite mid-flight. Therefore `queued` never means “not started,” and an idle-looking queue is not evidence of a deaf runner.\r\n\r\nThe authoritative occupancy signal is the process table. `Runner.Worker` means a job is running on this box. `cargo-nextest` means a suite is running, which is the seedmap-starvation collision.\r\n\r\n### Attribute process load before counting it\r\n\r\nThe two predicate axes are not independent: a CI job manifests in the local process table as `cargo` and `rustc`. Their presence does not imply a second occupant. Walk each PID's parent chain before counting it as new load:\r\n\r\n- a chain rooted at `Runner.Worker.exe`, `Runner.Listener.exe`, or `RunnerService.exe` is the CI axis already counted;\r\n- a chain rooted at a user shell is a genuine second occupant, so hold.\r\n\r\nOwner queries alone are insufficient. The runner service account can return empty owner and command-line fields; use the parent chain. Report attributed load, not bare process presence: “live local cargo” and “box free of a second occupant” can both be true.\r\n\r\n### The link is a third axis, and it is measured rather than assumed\r\n\r\n<!-- [doc->REQ-CI-LINK-HEALTH-PROBE] -->\r\n\r\nBoth axes above are process-shaped. A box can be quiet by both and still be a bad place to run a two-host rendezvous, because neither axis can see the link. Run 30771155390 is the specimen: zero non-terminal runs, no local build, and a link so degraded that a 1-second checkout took 321 seconds with bidirectional 10-second QUIC dial timeouts. Its `PUMP_PEER_FAIL` counts moved 0→3→0 on one host and 8→22→8 on the other across green/red/rerun, and the red was triaged as if it were a product failure because nothing in the run recorded what the network was doing.\r\n\r\nkitsubito's only link is wifi, indefinitely (operator-confirmed 2026-08-02). The link cannot be hardened, so the predicate has to see it.\r\n\r\nBoth two-host jobs therefore probe the peer immediately before rendezvous, via `.github/bench/link-probe.sh` (Linux) and `.github/bench/link-probe.ps1` (Windows), and each writes its result into the run's bench ledger. Read the probe's line like this:\r\n\r\n```\r\nLINK peer=kitsubito ip=100.98.197.12 path=direct samples=5/5 min=10ms med=15ms max=83ms rtts=10,12,15,81,83\r","truncated":true,"truncatedBy":"lines","totalLines":95,"totalBytes":3047,"outputLines":39,"outputBytes":3047,"lastLinePartial":false,"firstLineExceedsLimit":false},"totalLines":119,"displayContent":{"text":"## Step timings leave as an artifact\n…\n\r\n## Shared-runner quiet-window predicate\r\n\r\n<!-- [doc->REQ-GOLDEN-CI-LANE] -->\r\n\r\nA shared box is quiet only when **both** conditions hold:\r\n\r\n1. zero non-terminal CI runs; and\r\n2. no local `cargo`, `rustc`, or `cargo-nextest` process alive on the box.\r\n\r\nA GitHub-only drain check reads clean while another agent is mid-local-build. That is the contention class that muddied the g6 evidence twice. These axes are proxies for contention, not a definition of quiet; a proxy returning “quiet” is not itself a measurement of quiet.\r\n\r\n### Queue status is not occupancy\r\n\r\n`gh run list` status is not an occupancy probe. A run can report `queued` while its job is already executing on the box; this was observed on #121/#122 with `Runner.Worker` and `cargo-nextest` live and a suite mid-flight. Therefore `queued` never means “not started,” and an idle-looking queue is not evidence of a deaf runner.\r\n\r\nThe authoritative occupancy signal is the process table. `Runner.Worker` means a job is running on this box. `cargo-nextest` means a suite is running, which is the seedmap-starvation collision.\r\n\r\n### Attribute process load before counting it\r\n\r\nThe two predicate axes are not independent: a CI job manifests in the local process table as `cargo` and `rustc`. Their presence does not imply a second occupant. Walk each PID's parent chain before counting it as new load:\r\n\r\n- a chain rooted at `Runner.Worker.exe`, `Runner.Listener.exe`, or `RunnerService.exe` is the CI axis already counted;\r\n- a chain rooted at a user shell is a genuine second occupant, so hold.\r\n\r\nOwner queries alone are insufficient. The runner service account can return empty owner and command-line fields; use the parent chain. Report attributed load, not bare process presence: “live local cargo” and “box free of a second occupant” can both be true.\r\n\r\n### The link is a third axis, and it is measured rather than assumed\r\n\r\n<!-- [doc->REQ-CI-LINK-HEALTH-PROBE] -->\r\n\r\nBoth axes above are process-shaped. A box can be quiet by both and still be a bad place to run a two-host rendezvous, because neither axis can see the link. Run 30771155390 is the specimen: zero non-terminal runs, no local build, and a link so degraded that a 1-second checkout took 321 seconds with bidirectional 10-second QUIC dial timeouts. Its `PUMP_PEER_FAIL` counts moved 0→3→0 on one host and 8→22→8 on the other across green/red/rerun, and the red was triaged as if it were a product failure because nothing in the run recorded what the network was doing.\r\n\r\nkitsubito's only link is wifi, indefinitely (operator-confirmed 2026-08-02). The link cannot be hardened, so the predicate has to see it.\r\n\r\nBoth two-host jobs therefore probe the peer immediately before rendezvous, via `.github/bench/link-probe.sh` (Linux) and `.github/bench/link-probe.ps1` (Windows), and each writes its result into the run's bench ledger. Read the probe's line like this:\r\n\r\n```\r\nLINK peer=kitsubito ip=100.98.197.12 path=direct samples=5/5 min=10ms med=15ms max=83ms rtts=10,12,15,81,83\r\n```\n…\n\n…\n","startLine":22,"lineNumbers":[22,null,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,null,73,null,81]},"fileSize":13755,"meta":{"source":{"type":"path","value":"C:\\Users\\decid\\Documents\\projects\\spt-core\\docs\\GOLDEN-CI.md"},"truncation":{"direction":"head","truncatedBy":"lines","totalLines":119,"totalBytes":3047,"outputLines":39,"outputBytes":3047,"shownRange":{"start":25,"end":63},"nextOffset":64}}},"isError":false,"timestamp":1789094658598}}
{"type":"message","id":"f27b6ffa","parentId":"a7b94c8a","timestamp":"2026-09-11T02:44:18.602Z","message":{"role":"toolResult","toolCallId":"call_h096cQc3R48Kz0t8cKLfvkV4|fc_065c0d1976ecf9c2016aa36b002b9087d1b908897854eebd83","toolName":"read","content":[{"type":"text","text":"[workspace.dependencies]\n…\n# releases#125: swarm-discovery 0.6.0-alpha.2 (reached through iroh, used by\n# spt-net's mDNS advertise/resolve) spins a core per destroyed updater. In\n# `updater::gc`, a `send` to a stopped actor returns false and the code answers\n# by scheduling ANOTHER gc task 10 ms later — a ~100 Hz retry loop that can never\n# reach a live receiver, so every updater recreation leaks one more loop. Field\n# cost: a kitsubito daemon burning two cores for two weeks straight (~9\n# accumulated loops), latent in EVERY daemon since v0.38.1.\n#\n# Upstream fixed it in rkuhn/swarm-discovery PR #27, which is in NO crates.io\n# release (latest 0.6.3 predates it), and iroh 0.98.2 pins swarm-discovery to\n# EXACTLY 0.6.0-alpha.2 — so neither upstream master (0.6.3) nor any existing\n# fork branch satisfies the graph. This target is a minimal-delta backport: base\n# e47e0c6429 (the commit where Cargo.toml reads 0.6.0-alpha.2) + cherry-picks of\n# bbff547299 and bad0fd5b20 (= PR #27) ONLY, so none of the 0.6.1-0.6.3 behavior\n# changes ride along. Pinned by `rev` = content-addressed: the fork account\n# cannot alter what this lock resolves to.\n#\n# DROP THIS PATCH when upstream ships a release containing PR #27 AND iroh lifts\n# its exact pin far enough to reach that release. Neither is true today.\n[patch.crates-io]\nswarm-discovery = { git = \"https://github.com/SaberMage/swarm-discovery\", rev = \"89a2200d54a4e3cab2f46cc75ebff49a1fb07614\" }"}],"details":{"totalLines":54,"displayContent":{"text":"[workspace.dependencies]\n…\n# releases#125: swarm-discovery 0.6.0-alpha.2 (reached through iroh, used by\r\n# spt-net's mDNS advertise/resolve) spins a core per destroyed updater. In\r\n# `updater::gc`, a `send` to a stopped actor returns false and the code answers\r\n# by scheduling ANOTHER gc task 10 ms later — a ~100 Hz retry loop that can never\r\n# reach a live receiver, so every updater recreation leaks one more loop. Field\r\n# cost: a kitsubito daemon burning two cores for two weeks straight (~9\r\n# accumulated loops), latent in EVERY daemon since v0.38.1.\r\n#\r\n# Upstream fixed it in rkuhn/swarm-discovery PR #27, which is in NO crates.io\r\n# release (latest 0.6.3 predates it), and iroh 0.98.2 pins swarm-discovery to\r\n# EXACTLY 0.6.0-alpha.2 — so neither upstream master (0.6.3) nor any existing\r\n# fork branch satisfies the graph. This target is a minimal-delta backport: base\r\n# e47e0c6429 (the commit where Cargo.toml reads 0.6.0-alpha.2) + cherry-picks of\r\n# bbff547299 and bad0fd5b20 (= PR #27) ONLY, so none of the 0.6.1-0.6.3 behavior\r\n# changes ride along. Pinned by `rev` = content-addressed: the fork account\r\n# cannot alter what this lock resolves to.\r\n#\r\n# DROP THIS PATCH when upstream ships a release containing PR #27 AND iroh lifts\r\n# its exact pin far enough to reach that release. Neither is true today.\r\n[patch.crates-io]\r\nswarm-discovery = { git = \"https://github.com/SaberMage/swarm-discovery\", rev = \"89a2200d54a4e3cab2f46cc75ebff49a1fb07614\" }\r","startLine":31,"lineNumbers":[31,null,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54]},"fileSize":3791,"meta":{"source":{"type":"path","value":"C:\\Users\\decid\\Documents\\projects\\spt-core\\Cargo.toml"}}},"isError":false,"timestamp":1789094658602}}
{"type":"message","id":"b1170417","parentId":"f27b6ffa","timestamp":"2026-09-11T02:44:18.605Z","message":{"role":"toolResult","toolCallId":"call_YLrtkY3zMX578FzkdiKqOq5q|fc_065c0d1976ecf9c2016aa36b002b9887d186b69d1e464b8882","toolName":"read","content":[{"type":"text","text":"  repaired file**, which is not necessarily the suite the head gate runs.\n- **FIRST LIVE CATCH, and it was the author's own resolution (2026-08-29, one hour after the verb landed):** rebasing the IR-59 rider over the IR-57 rider produced four conflicts — three additive keep-both, one usage line both sides had edited. `xtask pick-audit` read the rebase as **LOSS, 282 lane / 280 pick**. The two missing lines were a `[[requirements]]` header and its blank line in `traceable-reqs.toml`, so `id = REQ-DISK-FLOOR-PREFLIGHT` landed INSIDE the previous table as a duplicate key: **`traceable-reqs check` exit 2, the registry unparseable, every reading after that edit checking nothing**. Restored, the same audit reads **DRIFT 282/282** whose one differing line is the usage string whose base copy legitimately gained the other verb — both verdict classes, on one resolution, in the order the entry predicts. The instrument's first real save was from the hazard it was filed for, against the agent who built it.\n\n[Showing lines 3155-3156 of 5782. Use :3157 to continue]"}],"details":{"truncation":{"content":"  repaired file**, which is not necessarily the suite the head gate runs.\r\n- **FIRST LIVE CATCH, and it was the author's own resolution (2026-08-29, one hour after the verb landed):** rebasing the IR-59 rider over the IR-57 rider produced four conflicts — three additive keep-both, one usage line both sides had edited. `xtask pick-audit` read the rebase as **LOSS, 282 lane / 280 pick**. The two missing lines were a `[[requirements]]` header and its blank line in `traceable-reqs.toml`, so `id = REQ-DISK-FLOOR-PREFLIGHT` landed INSIDE the previous table as a duplicate key: **`traceable-reqs check` exit 2, the registry unparseable, every reading after that edit checking nothing**. Restored, the same audit reads **DRIFT 282/282** whose one differing line is the usage string whose base copy legitimately gained the other verb — both verdict classes, on one resolution, in the order the entry predicts. The instrument's first real save was from the hazard it was filed for, against the agent who built it.\r","truncated":true,"truncatedBy":"lines","totalLines":2628,"totalBytes":1014,"outputLines":2,"outputBytes":1014,"lastLinePartial":false,"firstLineExceedsLimit":false},"totalLines":5782,"displayContent":{"text":"  repaired file**, which is not necessarily the suite the head gate runs.\r\n- **FIRST LIVE CATCH, and it was the author's own resolution (2026-08-29, one hour after the verb landed):** rebasing the IR-59 rider over the IR-57 rider produced four conflicts — three additive keep-both, one usage line both sides had edited. `xtask pick-audit` read the rebase as **LOSS, 282 lane / 280 pick**. The two missing lines were a `[[requirements]]` header and its blank line in `traceable-reqs.toml`, so `id = REQ-DISK-FLOOR-PREFLIGHT` landed INSIDE the previous table as a duplicate key: **`traceable-reqs check` exit 2, the registry unparseable, every reading after that edit checking nothing**. Restored, the same audit reads **DRIFT 282/282** whose one differing line is the usage string whose base copy legitimately gained the other verb — both verdict classes, on one resolution, in the order the entry predicts. The instrument's first real save was from the hazard it was filed for, against the agent who built it.\r","startLine":3155,"lineNumbers":[3155,3156]},"fileSize":501961,"meta":{"source":{"type":"path","value":"C:\\Users\\decid\\Documents\\projects\\spt-core\\docs\\INFRA-REGISTER.md"},"truncation":{"direction":"head","truncatedBy":"lines","totalLines":5782,"totalBytes":1014,"outputLines":2,"outputBytes":1014,"shownRange":{"start":3155,"end":3156},"nextOffset":3157}}},"isError":false,"timestamp":1789094658605}}
{"type":"message","id":"85d72492","parentId":"b1170417","timestamp":"2026-09-11T02:44:18.613Z","message":{"role":"toolResult","toolCallId":"call_6xoq3zboVp94desjJXKoKRFP|fc_065c0d1976ecf9c2016aa36b002b9c87d19b9520f41864f776","toolName":"grep","content":[{"type":"text","text":" 19|     test dying per run with a bare exit 1 and no assertion output, siblings in the same\n*20|     family green, on byte-identical code. That is not N flaky tests; it is one\n 21|     environmental cause picking a victim. Evidence: release PR #56 ran four times on a\n 22|     zero-`.rs`-delta tree and killed brain_decouple, brain_decouple, adapter_translate and\n 23|     adapter_digest in turn; run 4 went green once disk and leaked session-0 daemons were\n...\n 27|  A process is eligible only if its on-disk image sits under one of this run's own build\n*28|  roots (workspace, CARGO_TARGET_DIR, the notify-adapter checkout's target, RUNNER_TEMP,\n 29|  the pinned n1 old-broker build cache). Two hard exclusions are checked even for a\n 30|  process that passed the root test, because live infra must survive a bug in the root\n 31|  computation: anything under `spt-core\\bin\\` (the installed fleet binaries) and any\n...\n 45|  saved. Windows cannot overwrite a running image, so a leaked `spt.exe` from an earlier\n*46|  E2E phase makes the NEXT `cargo test -p spt --test …` fail with\n 47|  \"failed to remove file …\\target\\debug\\spt.exe: Access is denied. (os error 5)\" — twice\n 48|  out of twice on the BAROMETER golden runs (30754060525, 30758010357), where the job-start\n 49|  census read scoped=0 and the pre-reap census read scoped=4. Same reap, same by-path\n...\n 69|# the hard-exclusion list below and is never eligible for reaping.\n*70|$FamilyNames = @(\n 71|    'spt', 'owl', 'notify-shell', 'mock-session', 'mock-shell',\n 72|    'dispatch_fixture', 'translate_proof_fixture', 'post_step_fixture',\n 73|    'gh_fixture', 'git_fixture'\n...\n 80|        $env:GITHUB_WORKSPACE\n*81|        $env:CARGO_TARGET_DIR\n 82|        if ($env:GITHUB_WORKSPACE) { Join-Path $env:GITHUB_WORKSPACE 'target' }\n 83|        if ($env:GITHUB_WORKSPACE) { Join-Path $env:GITHUB_WORKSPACE '.adapter-notify\\target' }\n 84|        $env:RUNNER_TEMP\n...\n 119|\n*120|function Get-FamilySnapshot {\n 121|    param([string[]]$Roots)\n 122|    $rows = [System.Collections.Generic.List[object]]::new()\n*123|    foreach ($p in (Get-Process -Name $FamilyNames -ErrorAction SilentlyContinue)) {\n 124|        # Path throws (Access denied) for a session-0 process an interactive token cannot\n 125|        # open. That is population B and it is a FACT WORTH LOGGING, not an error.\n 126|        $path = $null\n...\n 156|    # ONE greppable summary line per census, so a run-to-run diff is a grep, not a read.\n*157|    Write-Output (\"CI-CENSUS phase={0} box_procs={1} box_handles={2} family_total={3} family_handles={4} scoped={5} unscoped={6} unreadable_path={7}\" -f `\n 158|            $Label, $boxProcs.Count, ($boxHandles ?? 0), $Rows.Count, ($famHandles ?? 0), $scoped.Count, ($Rows.Count - $scoped.Count), $unreadable.Count)\n 159|\n 160|    foreach ($r in ($Rows | Sort-Object Name, Pid)) {\n...\n 175|    # line on the follow-up run.\n*176|    Write-Census -Label 'start' -Rows (Get-FamilySnapshot -Roots $roots)\n 177|    if ($script:CensusScoped -gt 0) {\n 178|        Write-Output \"::warning::CI-CENSUS start: $($script:CensusScoped) scoped daemon(s) inherited from a previous run — this battery is starting contaminated.\"\n 179|    }\n...\n 188|# prerelink census as an end-of-job one, so every label carries the phase.\n*189|# [impl->REQ-CI-PRERELINK-EXE-LOCK-REAP]\n 190|$isPrerelink = $Phase -eq 'prerelink'\n 191|$labelPrefix = if ($isPrerelink) { 'prerelink-' } else { '' }\n 192|\n*193|$before = Get-FamilySnapshot -Roots $roots\n 194|Write-Output \"CI-REAP: pre-reap state\"\n 195|Write-Census -Label \"${labelPrefix}pre-reap\" -Rows $before\n 196|\n...\n 205|    Start-Sleep -Seconds $settleSecs\n*206|    $before = Get-FamilySnapshot -Roots $roots\n 207|    Write-Census -Label \"${labelPrefix}post-settle\" -Rows $before\n 208|}\n 209|\n...\n 240|\n*241|Write-Census -Label $Phase -Rows (Get-FamilySnapshot -Roots $roots)\n 242|$survivors = $script:CensusScoped\n 243|$unreadable = $script:CensusUnreadable\n 244|$survivorVerdict = if ($unreadable -gt 0) { 'UNPROVEN' } else { $survivors }\n...\n 258|    $msg = if ($unreadable -gt 0) {\n*259|        \"CI-REAP: clean survivor count REFUSED — $unreadable family process path(s) were unreadable, beside $survivors observed scoped survivor(s).\"\n 260|    }\n 261|    elseif ($isPrerelink) {\n 262|        \"CI-REAP-PRERELINK: $survivors scoped daemon(s) survived the pre-relink reap — the relink step that follows is expected to fail on os-error-5.\""}],"details":{"scopePath":".github/ci/reap-census.ps1","searchPath":"C:\\Users\\decid\\Documents\\projects\\spt-core\\.github\\ci\\reap-census.ps1","cwd":"C:\\Users\\decid\\Documents\\projects\\spt-core","matchCount":14,"fileCount":1,"files":[".github/ci/reap-census.ps1"],"fileMatches":[{"path":".github/ci/reap-census.ps1","count":14}],"truncated":false,"displayContent":"  19│     test dying per run with a bare exit 1 and no assertion output, siblings in the same\n *20│     family green, on byte-identical code. That is not N flaky tests; it is one\n  21│     environmental cause picking a victim. Evidence: release PR #56 ran four times on a\n  22│     zero-`.rs`-delta tree and killed brain_decouple, brain_decouple, adapter_translate and\n  23│     adapter_digest in turn; run 4 went green once disk and leaked session-0 daemons were\n    │...\n  27│  A process is eligible only if its on-disk image sits under one of this run's own build\n *28│  roots (workspace, CARGO_TARGET_DIR, the notify-adapter checkout's target, RUNNER_TEMP,\n  29│  the pinned n1 old-broker build cache). Two hard exclusions are checked even for a\n  30│  process that passed the root test, because live infra must survive a bug in the root\n  31│  computation: anything under `spt-core\\bin\\` (the installed fleet binaries) and any\n    │...\n  45│  saved. Windows cannot overwrite a running image, so a leaked `spt.exe` from an earlier\n *46│  E2E phase makes the NEXT `cargo test -p spt --test …` fail with\n  47│  \"failed to remove file …\\target\\debug\\spt.exe: Access is denied. (os error 5)\" — twice\n  48│  out of twice on the BAROMETER golden runs (30754060525, 30758010357), where the job-start\n  49│  census read scoped=0 and the pre-reap census read scoped=4. Same reap, same by-path\n    │...\n  69│# the hard-exclusion list below and is never eligible for reaping.\n *70│$FamilyNames = @(\n  71│    'spt', 'owl', 'notify-shell', 'mock-session', 'mock-shell',\n  72│    'dispatch_fixture', 'translate_proof_fixture', 'post_step_fixture',\n  73│    'gh_fixture', 'git_fixture'\n    │...\n  80│        $env:GITHUB_WORKSPACE\n *81│        $env:CARGO_TARGET_DIR\n  82│        if ($env:GITHUB_WORKSPACE) { Join-Path $env:GITHUB_WORKSPACE 'target' }\n  83│        if ($env:GITHUB_WORKSPACE) { Join-Path $env:GITHUB_WORKSPACE '.adapter-notify\\target' }\n  84│        $env:RUNNER_TEMP\n    │...\n 119│\n*120│function Get-FamilySnapshot {\n 121│    param([string[]]$Roots)\n 122│    $rows = [System.Collections.Generic.List[object]]::new()\n*123│    foreach ($p in (Get-Process -Name $FamilyNames -ErrorAction SilentlyContinue)) {\n 124│        # Path throws (Access denied) for a session-0 process an interactive token cannot\n 125│        # open. That is population B and it is a FACT WORTH LOGGING, not an error.\n 126│        $path = $null\n    │...\n 156│    # ONE greppable summary line per census, so a run-to-run diff is a grep, not a read.\n*157│    Write-Output (\"CI-CENSUS phase={0} box_procs={1} box_handles={2} family_total={3} family_handles={4} scoped={5} unscoped={6} unreadable_path={7}\" -f `\n 158│            $Label, $boxProcs.Count, ($boxHandles ?? 0), $Rows.Count, ($famHandles ?? 0), $scoped.Count, ($Rows.Count - $scoped.Count), $unreadable.Count)\n 159│\n 160│    foreach ($r in ($Rows | Sort-Object Name, Pid)) {\n    │...\n 175│    # line on the follow-up run.\n*176│    Write-Census -Label 'start' -Rows (Get-FamilySnapshot -Roots $roots)\n 177│    if ($script:CensusScoped -gt 0) {\n 178│        Write-Output \"::warning::CI-CENSUS start: $($script:CensusScoped) scoped daemon(s) inherited from a previous run — this battery is starting contaminated.\"\n 179│    }\n    │...\n 188│# prerelink census as an end-of-job one, so every label carries the phase.\n*189│# [impl->REQ-CI-PRERELINK-EXE-LOCK-REAP]\n 190│$isPrerelink = $Phase -eq 'prerelink'\n 191│$labelPrefix = if ($isPrerelink) { 'prerelink-' } else { '' }\n 192│\n*193│$before = Get-FamilySnapshot -Roots $roots\n 194│Write-Output \"CI-REAP: pre-reap state\"\n 195│Write-Census -Label \"${labelPrefix}pre-reap\" -Rows $before\n 196│\n    │...\n 205│    Start-Sleep -Seconds $settleSecs\n*206│    $before = Get-FamilySnapshot -Roots $roots\n 207│    Write-Census -Label \"${labelPrefix}post-settle\" -Rows $before\n 208│}\n 209│\n    │...\n 240│\n*241│Write-Census -Label $Phase -Rows (Get-FamilySnapshot -Roots $roots)\n 242│$survivors = $script:CensusScoped\n 243│$unreadable = $script:CensusUnreadable\n 244│$survivorVerdict = if ($unreadable -gt 0) { 'UNPROVEN' } else { $survivors }\n    │...\n 258│    $msg = if ($unreadable -gt 0) {\n*259│        \"CI-REAP: clean survivor count REFUSED — $unreadable family process path(s) were unreadable, beside $survivors observed scoped survivor(s).\"\n 260│    }\n 261│    elseif ($isPrerelink) {\n 262│        \"CI-REAP-PRERELINK: $survivors scoped daemon(s) survived the pre-relink reap — the relink step that follows is expected to fail on os-error-5.\""},"isError":false,"timestamp":1789094658612}}
{"type":"message","id":"26fd535b","parentId":"85d72492","timestamp":"2026-09-11T02:44:18.618Z","message":{"role":"toolResult","toolCallId":"call_p1uWVWlZixqGMBhWtSl8cLhB|fc_065c0d1976ecf9c2016aa36b002ba487d1acd22b100eb8a734","toolName":"glob","content":[{"type":"text","text":"# .spt/preserved/\ngolden-272-r2-attempt3-twohost.MANIFEST.sha256\ngolden-272-r2-attempt2-twohost.MANIFEST.sha256\n## hertz-65s-rider-leftovers-2026-09-09/spt-twohost-web/\n## doyle-flake-rows-2026-09-09/\nFLAKE-LEDGER-row-twohost-ladder-a3-noedge.md\n## golden-272-r4-drive/\nr4-twohost_b-102387599353.log\nr4-twohost_a-102387599268.log\n## golden-272-r3-drive/\nanalyse-twohost-b-a4.sh\n### a2/\na2-twohost-b-102363522882.log\na2-twohost-b-102363522882.err\na2-twohost-a-102363522929.log\na2-twohost-a-102363522929.err\n### red/\ntwohost-b-102229928689.log\ntwohost-b-102229928689.err\ntwohost-a-102229928746.log\ntwohost-a-102229928746.err\n## golden-272-r2-attempt4/\na4-twohost-b-102316461873.log\na4-twohost-a-102316461906.log\n## golden-272-r2-attempt3-twohost/\ntwohost-b-102294363818.log\ntwohost-a-102294363789.log\n## golden-272-r2-attempt2-twohost/\ntwohost-b-102207296960.log\ntwohost-b-102229928689.log\ntwohost-a-102229928746.log\n## r2-lanes/\n### hertz-percell-id/.spt/\n#### twohost-web/\n#### rig/\ntwohost-web-local.sh\n### hertz-lane4/.spt/rig/\ntwohost-web-local.sh\n### hertz-repin/.spt/rig/\ntwohost-web-local.sh\n## golden-272-r1/\ntwohost-b-102120971710.log\ntwohost-a-102120971742.log\n## w3-fd296557/\n### frozen-driver/\ntwohost-ladder-local.sh\ntwohost-web-local.sh\ntwohost-web-xbox.sh\ntwohost-ladder-xbox.sh\n### gate/\ntwohost-ladder-local.lf.sh\n\n[35 results limit reached. Use limit=70 for more]"}],"details":{"scopePath":".spt/preserved/**/*twohost*, .spt/preserved/**/*344459*","fileCount":35,"files":[".spt/preserved/hertz-65s-rider-leftovers-2026-09-09/spt-twohost-web/",".spt/preserved/doyle-flake-rows-2026-09-09/FLAKE-LEDGER-row-twohost-ladder-a3-noedge.md",".spt/preserved/golden-272-r4-drive/r4-twohost_b-102387599353.log",".spt/preserved/golden-272-r4-drive/r4-twohost_a-102387599268.log",".spt/preserved/golden-272-r3-drive/a2/a2-twohost-b-102363522882.log",".spt/preserved/golden-272-r3-drive/a2/a2-twohost-b-102363522882.err",".spt/preserved/golden-272-r3-drive/a2/a2-twohost-a-102363522929.log",".spt/preserved/golden-272-r3-drive/a2/a2-twohost-a-102363522929.err",".spt/preserved/golden-272-r2-attempt4/a4-twohost-b-102316461873.log",".spt/preserved/golden-272-r3-drive/analyse-twohost-b-a4.sh",".spt/preserved/golden-272-r2-attempt4/a4-twohost-a-102316461906.log",".spt/preserved/golden-272-r2-attempt3-twohost.MANIFEST.sha256",".spt/preserved/golden-272-r2-attempt3-twohost/twohost-b-102294363818.log",".spt/preserved/golden-272-r2-attempt3-twohost/",".spt/preserved/golden-272-r2-attempt3-twohost/twohost-a-102294363789.log",".spt/preserved/golden-272-r2-attempt2-twohost.MANIFEST.sha256",".spt/preserved/golden-272-r2-attempt2-twohost/",".spt/preserved/golden-272-r2-attempt2-twohost/twohost-b-102207296960.log",".spt/preserved/golden-272-r2-attempt2-twohost/twohost-b-102229928689.log",".spt/preserved/golden-272-r2-attempt2-twohost/twohost-a-102229928746.log",".spt/preserved/golden-272-r3-drive/red/twohost-b-102229928689.log",".spt/preserved/golden-272-r3-drive/red/twohost-b-102229928689.err",".spt/preserved/golden-272-r3-drive/red/twohost-a-102229928746.log",".spt/preserved/golden-272-r3-drive/red/twohost-a-102229928746.err",".spt/preserved/r2-lanes/hertz-percell-id/.spt/twohost-web/",".spt/preserved/r2-lanes/hertz-lane4/.spt/rig/twohost-web-local.sh",".spt/preserved/golden-272-r1/twohost-b-102120971710.log",".spt/preserved/golden-272-r1/twohost-a-102120971742.log",".spt/preserved/r2-lanes/hertz-repin/.spt/rig/twohost-web-local.sh",".spt/preserved/r2-lanes/hertz-percell-id/.spt/rig/twohost-web-local.sh",".spt/preserved/w3-fd296557/frozen-driver/twohost-ladder-local.sh",".spt/preserved/w3-fd296557/frozen-driver/twohost-web-local.sh",".spt/preserved/w3-fd296557/frozen-driver/twohost-web-xbox.sh",".spt/preserved/w3-fd296557/frozen-driver/twohost-ladder-xbox.sh",".spt/preserved/w3-fd296557/gate/twohost-ladder-local.lf.sh"],"truncated":true,"resultLimitReached":35,"cwd":"C:\\Users\\decid\\Documents\\projects\\spt-core","meta":{"limits":{"resultLimit":{"reached":35,"suggestion":70}}}},"isError":false,"timestamp":1789094658618}}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_awy02qy4wLPXYTAX0PtNHBbB|fc_065c0d1976ecf9c2016aa36b06d0d487d1a692598bba9732a6","toolName":"yield","startedAt":"2026-09-11T02:46:44.400Z"},"id":"4d5f077d","parentId":"26fd535b","timestamp":"2026-09-11T02:46:44.400Z"}
{"type":"message","id":"da2856d6","parentId":"4d5f077d","timestamp":"2026-09-11T02:46:44.402Z","message":{"role":"assistant","content":[{"type":"thinking","thinking":""},{"type":"toolCall","id":"call_awy02qy4wLPXYTAX0PtNHBbB|fc_065c0d1976ecf9c2016aa36b06d0d487d1a692598bba9732a6","name":"yield","arguments":{"type":null,"data":{"summary":"Read all 47 assigned entries (IR-50–97 excluding earlier IR-54), including every long amendment. Strongest corrections: IR-66 is eligible for closure; IR-73's eight reorders and docs-floor rereads are already implemented; IR-69/83/89 carry stale lifecycle wording. Keep the disk, quiet-window, slowdown, and diagnostic debts open. No edits or runtime checks performed.","files":[{"path":"docs/INFRA-REGISTER.md:2726-5781","description":"Complete assigned population and historical evidence; 47 entries, physical order includes IR-53 before IR-52."},{"path":".github/workflows/ci.yml","description":"All five IR-73 sites now follow checkout (IR-73 comments at 28, 98, 113, 184, 232); Windows start floor remains 32 GiB."},{"path":".github/workflows/release.yml","description":"All three IR-73 sites now follow checkout (comments at 54, 69, 169)."},{"path":".github/workflows/golden.yml","description":"Docs-floor rereads at 599/622; Windows start still 32 GiB at 229; docs steps retain implicit preceding-success coupling."},{"path":"crates/spt-daemon/tests/attach.rs","description":"IR-66 remedies present: delayed TICK39 on Unix/Windows at 531/539, delayed ALT_VIEWPORT_MARKER at 656."},{"path":"WEBSERVE-272-JIT.md:111-119","description":"IR-66 explicitly ruled satisfied; workflow floor rider and driver adoption tracked separately."},{"path":".github/ci/reap-census.ps1","description":"Family-only process predicate remains at 70–73/123; does not implement IR-76's compiler-load predicate."},{"path":"docs/GOLDEN-CI.md:26-51","description":"Existing quiet-window contract includes CI occupancy, local build processes, and parent-chain attribution; reuse instead of introducing another definition."},{"path":"crates/spt-store/src/proc.rs:46-49,430-433","description":"kill_pid and kill_pid_tree still accept bare numeric PIDs; IR-81 primitive-level remedy not present."},{"path":"crates/spt-daemon/src/daemon.rs:475-476","description":"Pidfile still overwritten directly; IR-82 predecessor preservation not implemented."},{"path":"crates/xtask/src/brainread.rs:194-203,295-320","description":"IR-94 name-shape predicate and three-file enumeration remain."},{"path":"crates/xtask/src/main.rs:69-70","description":"pick-audit and disk-floor verbs exist, contradicting stale future-build wording in IR-57/59."}],"architecture":"Separate structural enforcement, procedural adoption, box mitigations, and incident diagnosis. Workflow floor placement is distinct from capacity sizing; process custody is distinct from performance attribution; publication ordering is distinct from inject coverage. Release SHIP authority and passing batteries do not discharge unresolved mechanism claims.","report":"## Scope and reading key\n47 assigned entries: IR-50–97, excluding IR-54 (starts earlier). IR-49's preceding body and the CI-RIDER historical section were seen but not assigned as new IR entries. IR-31 is outside this range and remains the earlier-range owner's embedded-entry responsibility.\n\nTrigger = an entry's remedy/intake trigger, not proof its failure recurred. FIRED may be historically established; UNKNOWN means the supplied release facts and inspected material do not establish a qualifying new touch/event. Existing BUILT/CLOSED states stand without gratuitous re-verification. Actions are recommendations for the parent's ruling, not board mutations.\n\n## Exhaustive disposition table\n| IR | Current entry state | Trigger | Recommendation and evidence |\n|---|---|---|---|\n| 50 | CLOSED / BUILT, landed v0.59.0 | FIRED historically | CARRY closed. Census/adoption completion and explicit engine-room exclusion already evidenced; release facts supply no reopening. |\n| 51 | OPEN | UNKNOWN for #199 causal attribution; historical hermeticity pass available | CARRY. Ephemeral advisory ports do not disable peer pump/discovery or establish network causality. Preserve sequencing prohibition against net-off-as-green. |\n| 52 | BUILT | FIRED historically, generator touch SIGNET | CARRY built. Full recursive command-tree rendering and previously omitted leaves recorded; do not reopen from old third-instance pre-build prose. |\n| 53 | BUILT / landed v0.59.0 | FIRED historically | CARRY built. Cold-boot arm explicitly names unproved property; three narrower clock-aging siblings remain touch-triggered, not newly diagnosed by release success. |\n| 55 | OPEN, ARMED-FOR-CAPTURE, hertz | FIRED (standing unfiltered-battery trigger) | CARRY armed, owner unavailable rather than executing. Nextest containment and prior 5×663 green settle sweep are not leak closure; no fresh wedge reported. Keep capture-before-kill protocol. |\n| 56 | BUILT | FIRED historically | CARRY built. Cross-worktree refusal and explicit foreign-pool takeover measured in entry; IR-42 admission boundary intentionally remains. |\n| 57 | OPEN, living gater procedure | FIRED (assembly/release arc) | CARRY procedure; correct stale proposed-tool wording: pick-audit already exists (xtask main:69) and caught real LOSS. Release build success proves compilation, not per-pick fidelity or repaired-file behavior. |\n| 58 | OPEN, unowned; original claim retracted | FIRED (brainread/xtask work this milestone) | COMPOSE cargo-enumerated duplicate-bin check at next tooling intake; no closure evidence. Never resurrect withdrawn nonexistent-bin/prose correction. |\n| 59 | OPEN, arithmetic/discipline | FIRED, including latest post-push disk-floor red | COMPOSE residual driver adoption/capacity work, carry discipline. Workflow start/end and docs-floor logging now exist; xtask disk-floor exists. Root target 62.32 GiB + CI debug 59.70 GiB and later 4.22 GiB cleanup are mitigations, not bounded accumulation. Do not call 14.3 GiB an explanation for unavailable earlier unit logs. |\n| 60 | OPEN, script discipline | FIRED (diagnostic/gate reporting) | COMPOSE into next shared driver touch, carry open. Preserve leg verdict separately from wrapper completion; 3167 unit pass then floor red must be reported as distinct outcomes, not flattened to all-green or all-unit-red. Missing exit also requires reading raw Summary (IR-79), not inventing completion. |\n| 61 | OPEN, accepted with mitigation | UNKNOWN substantive scanner touch | CARRY. No supplied fact establishes literal-tracker unification; unrelated xtask work alone is not this specific trigger. |\n| 62 | BUILT docs-collision remedy; residual caveat | FIRED historically | CARRY built scoped to docs listener. Other bind surfaces remain conditional residuals; do not imply whole network hermeticity. |\n| 63 | OPEN, mitigated, historical queued hertz lane | FIRED historically/rig work | COMPOSE with teardown/IR-79/97 adoption, keep open. Path-safe reaps are mitigation; no complete producer-side teardown proof. Update queued-owner language to pending acknowledgement, not active execution. Historical rotating victims do not classify the new sync/convoy red. |\n| 64 | OPEN, operator reservoir | FIRED historically by IR-86 in-job floor failure; latest disk red reinforces relevance | COMPOSE operator capacity/accept-tax decision, carry open. Current cleanup does not move operator-owned bulk or prove permanent headroom. Do not recite historical 845 GB as a freshly measured current census. |\n| 65 | REMEDIATED-AT-BOX, OPEN recheck record | UNKNOWN snap/auditd update or reimage | CARRY recheck record; no box commands needed this sweep. Release green is not evidence that effective audit configuration survived a named reset event. |\n| 66 | BUILT; explicitly due to leave at WEBSERVE close | FIRED, close overdue | CLOSE eligible now. JIT:111–116 already rules satisfied; current attach.rs:531/539/656 retains both delayed needles. Remove stale next-intake two-edit rider from sweep summary; this is source-backed closure, not green-alone retirement. |\n| 67 | BUILT, battery-template remedy | FIRED historically/intake | CARRY built. Scoped 121-pass battery is only its named scope; do not use --bins as integration coverage or promote it to full golden acceptance. |\n| 68 | OPEN investigation | UNKNOWN new PSYCHE_INGEST_FAIL/probe slot | CARRY. Existing nonempty-lock experiment refuted the proposed cause; unrelated release facts cannot reinstate index.lock attribution. |\n| 69 | OPEN; header says parked pre-assembly | FIRED historically close-out recensus | COMPOSE #243 residual plus separately tracked anchored-consumer rider; correct stale header. Body already records landed ec6da9b0 and 338 cli + 2 main residuals. Need residual conversion, generator fix, and SHA-pinned zero recensus before closure. Delivery.rs post-cut sites already converted; no new lane owed there. |\n| 70 | OPEN, recurrence remedy unscheduled | UNKNOWN construction/API/sink touch | CARRY. Shipped default_bus site correction is not enforced assembly-point closure. IR-92 funnel work may make this a useful next construction-seam rider, but do not assert its trigger from publication work alone. |\n| 71 | OPEN observability | UNKNOWN qualifying controller-lifecycle/breadcrumb touch | CARRY, eligible next lifecycle instrument rider. Existing info.json polling barrier proves convergence separately; no new persisted-release breadcrumb evidenced. |\n| 72 | OPEN observability | UNKNOWN qualifying read-model/holder-inspection touch | CARRY. Cleanup process-table custody is not a supported named-seat read verb. |\n| 73 | OPEN, title/body claim eight pre-checkout sites still owed | FIRED; implementation already present | CLOSE eligible for the entry's original two halves, with implementation evidence explicitly stated. All 5 ci and 3 release sites are after checkout with IR-73 comments; golden docs rereads exist and IR-86 records their live catch. Current header is stale. Capacity derivation and docs dependency coupling remain IR-86, not reasons to re-build IR-73. |\n| 74 | OPEN /tmp population | FIRED as between-milestone audit opportunity; current Linux touch unknown | COMPOSE bounded /tmp lifecycle at box-audit intake, not a fresh numeric census. Windows cleanup says nothing about kitsubito's 21,643 historical homes. |\n| 75 | OPEN Linux treqs 127 | UNKNOWN new Linux-driver touch; audit opportunity remains | COMPOSE install-or-explicit-platform-independent-coverage decision with Linux box audit. No proof here of current installation or driver removal; retain stale-state verification obligation, never infer it from overall green. |\n| 76 | OPEN quiet-window/measurement | FIRED driver/workflow/runbook arc | COMPOSE outstanding enforcement and compiler-load census. Existing GOLDEN-CI:26–51 already supplies a better occupancy/parent-chain contract; reap-census still selects only SPT family. IR-87 proves queue interference, not cause of sync expiry. Historical headline 'manufactured' is stronger than overlap alone; new sweep must not repeat it as a diagnosis. |\n| 77 | OPEN boot interval visibility | UNKNOWN exact boot/ready-stamp touch | CARRY, compose if next daemon-boot instrumentation lane opens. No timestamped child-entry→ready proof surfaced; full test duration is not boot interval. |\n| 78 | OPEN silent docs-port override | UNKNOWN new docshost touch; historical belief incident already witnessed | CARRY tiny next-docshost rider. No release fact proves notice implemented; precedence need not be redesigned. |\n| 79 | OPEN panic/timeout teardown exposure | UNKNOWN new common-module touch; exposure continues | COMPOSE first-wave guard adoption with IR-63/97; pending owner acknowledgement. Preserve panic-vs-hard-kill boundary: Rust Drop alone does not guarantee cleanup on process termination/SIGKILL. Entry's blanket timeout coverage claim needs qualification, not adoption as a guarantee. |\n| 80 | OPEN; initial product-candidate headline superseded by amendments | FIRED historical investigation opportunity | CARRY residual class, reconcile stale opening. Body identifies brainproc shell-wrapper fixture mechanism and direct production spawn; does not classify all 12 union members. LEAK-count reduction or passing Windows unit set cannot close this. No owner is executing by implication. |\n| 81 | OPEN primitive + gate; adapter arm CLOSED | FIRED historical proc/xtask work | COMPOSE remaining primitive and script-gate obligations. Current kill_pid(pid) and kill_pid_tree(root) remain bare-PID APIs (proc.rs:46/430); KH7.51 records a broker-site birth-safe correction but one site does not close primitive enforceability. Adapter closure stands, incident cause remains separate. |\n| 82 | RULED, remedy historically linked #285 | FIRED historical lifecycle/#285 lane opportunity | COMPOSE unbuilt predecessor record independently of #285's site repair. daemon.rs:476 still direct-writes pidfile; no predecessor retention at this path. Header 'main ends at IR-78' is historical/stale. Do not call linked lane completion IR-82 completion. |\n| 83 | OPEN, operator-rule blocked historical prose | FIRED; superseded box evidence in IR-89 | CARRY direction-witness enforcement residual, reconcile obsolete blocker/LAN-only prescription. IR-89 records actual tailnet ACL+firewall grants and successful tailnet probes, refuting a universal 'never tailnet' necessity. Need parent ruling to replace obsolete remediation with layer-specific admission + permanent reverse witness, not infer full closure from a one-box green. |\n| 84 | OPEN, first instrument half landed with filing | FIRED historically | CARRY unresolved stall arithmetic/enforcement residual; acknowledge clocked emitter half as built. Timestamp instrumentation does not explain the extra ~27–34 s, shorten behavior, or prove every future arm stamped. |\n| 85 | OPEN, caps mitigation only | FIRED arm 1; operator arms UNKNOWN | COMPOSE redesigned discriminator after guard/occupancy prerequisites, keep open. Old-sha slowdown establishes head growth not necessary, not environment apportionment. Alternate AB/BA, bank per-leg conditions/output; cap 80/40 remains mitigation. No Defender/torrent/disk causal allocation from concurrency or reclaim recovery. Hertz offline: brief delivered, unacknowledged. |\n| 86 | OPEN, capacity derivation + docs coupling | FIRED golden/workflow arc | COMPOSE workflow sizing/independent docs dependency rider. golden.yml still 32 GiB start (229), docs floor (626), and OS-only success-coupled conditions (600/617/623). Historical 67.4 GiB footprint motivates re-derivation, not universal guaranteed peak. Latest 14.3<32 post-unit red is additional capacity evidence, not a new product failure. |\n| 87 | OPEN independent job clocks | FIRED; exact recurrence banked at a9e786b2 | COMPOSE scheduling/rendezvous rider. Entry timeline proves B ended before A began, caused by golden head's own PR runner occupancy; include self-PR, not merely other lanes. Keep raw GitHub conclusions alongside VOID scoring. 900s panel alone cannot separate this from firewall. |\n| 88 | OPEN pool-release vehicle | FIRED historical teardown; runbook adoption due | COMPOSE permanent release-before-delete/prebuilt recipe; carry open until adoption documented. Positive control already proves cargo-run regrowth vs prebuilt non-regrowth; current cleanup alone doesn't show recipe institutionalized. Prefer existing proven sequence, not an in-verb refusal that can only run after cargo already rebuilt it. |\n| 89 | BOX applied; WORKFLOW built, landed-pending-golden | FIRED: multiple subsequent goldens | CARRY built pending exact step evidence; flag 'until next golden' stale immediately. No full probe-step outcomes were supplied/read here; next golden occurred but that alone is not exercise proof (steps can skip/partners desynchronize). Read retained step logs to replace pending wording with precise exercised/skipped/failed result; do not reapply operator rules or blame IR-87's 900s red on firewall. |\n| 90 | OPEN disk refusal/context | FIRED, ripe now | COMPOSE rig-root/target-volume start refusal + current free-space failure context, prerequisite for IR-85 rerun. Reclaims mitigate only. Latest known 3167 unit pass followed by disk floor red is classified at its observed step; unavailable earlier PR logs remain unclassified. |\n| 91 | CLOSED by filing lane | FIRED historically | CARRY closed. Preserve cited tracked artifacts and scratch manifests; parent cleanup retained evidence, so no reopening shown. |\n| 92 | OPEN, says fix unassigned | FIRED inject/IO-funnel remedy; parent reports core215/217 merged | PARENT DECISION. Mark header stale but do not close here. Source/contract verification must distinguish inject success publication from relay ordering and per-msg-id exact-once; parent owns substantive reconciliation. |\n| 93 | OPEN production symbols | UNKNOWN new packaging touch; release build alone is not a source touch | COMPOSE next packaging intake decision, keep open. Successful release build is not PDB availability, symbol matching, installation, or usable frame evidence. Preserve size/profile/operator trade rather than assuming approval. |\n| 94 | OPEN scanner reach | FIRED at newly added brainread gate; mandatory before bounded serve_sync migration | COMPOSE fail-on-unclassified stream-server census. Current brainread.rs:199 and 306–320 retain name shape/three-file registry. Independent gate defect, not cause of golden sync red. |\n| 95 | OPEN, measured/censused, diagnostic-only instrumentation | FIRED comparison already ran | COMPOSE prioritized observability + separately versioned exchange-correlated producer trace; retain open. 317/321 is classifier estimate with membership slop, 15 unclassified, not repo-wide floor/rate; no blanket 304-site editing. Diagnostic patch is unlanded, not release behavior. Preserve censored expiry, filtered final snapshot, no stream-between-polls claim, and no inferred budget fix. |\n| 96 | OPEN cause-unclassified | NOT FIRED for named new qualifying event on supplied facts; cheap discriminator still unrun | CARRY with explicit next-intake investigation, not resolved/non-defect. 0/1 candidate CI vs 3/3 diagnostic HEAVY is confounded tree/workload/box, plus IR-97. Brief delivered to offline hertz is pending acknowledgement, not executing. |\n| 97 | OPEN protocol deviation | FIRED repeated-run experiment | COMPOSE mandatory between-run identity census/accounting before any repeated IR-85/95/96 work. 0/6/12 carried residues are counts, not measured load or sync cause; 18 seen vs 15 killed does not prove three self-exits. Cleanups do not cure harness enforcement. |\n\n## Load-bearing deltas for the parent's edit\n1. **Retire duplicate work, not residual mechanisms:** close IR-66; IR-73's source contract is implemented at all eight sites and both docs rereads. Amend their stale top-of-register riders. Keep IR-86 capacity/docs dependency debt separate. IR-57 pick-audit and IR-59 disk-floor are already tools, not future tooling proposals.\n2. **Lifecycle wording needs reconciliation:** IR-69's parked header contradicts its own landed/residual addendum; IR-83's rule-blocked/LAN-only prose conflicts with IR-89's applied tailnet and firewall proof; IR-89's next-golden trigger fired but exact step proof is still needed; IR-92's unassigned header conflicts with parent's merged core215/217 fact. IR-80's product-candidate opening must be read through later scoped fixture findings. IR-82's #285 lane linkage did not deliver its pidfile retention.\n3. **No causal laundering at release close:** v0.69.0 c105 at 16df0e41 shipped under explicit operator SHIP with known candidate a9e786b2 sync red. 121 scoped passes, release build success, and 3167 Windows unit passes prove exactly those observations. The later floor failure at 14.3 vs 32 GiB is not a unit-test failure; unavailable earlier PR unit logs are still unclassified. No disk/load attribution for sync/convoy from overlap or pass-after-reclaim.\n4. **Cleanup accounting remains mitigation:** retain separate 62.32 GiB root-target and 59.70 GiB CI-debug measurements; later 38 clean merged worktrees/obsolete clone etc yielded net 4.22 GiB. Do not conflate file-length totals with free-space deltas, or report a structural capacity fix. Parent confirms no dirty/unmerged/retained evidence removed.\n5. **Coherent next-intake packages:** (A) workflow/driver resource contract: IR-59/60/76/86/87/90/97, preserving separate conditions and budgets; (B) pool teardown adoption: IR-88 with earlier-range pool audit, IR-64 operator decision separate; (C) test lifetime work: IR-63/79/80 plus Linux IR-74/75, without collapsing fixture vs product identity debt IR-81/82; (D) diagnostic continuation: IR-85/95/96 only after occupancy/disk/between-run prerequisites, with no budget widening; (E) small seam-triggered items: IR-94 gate reach and IR-93 symbol packaging. All hertz-shaped work is proposed/pending acknowledgement while offline, not dispatched-and-executing.\n\n## Verification limits\nRead-only tools only; no tests, builds, formatters, linters, probes, re-runs, board writes, or file edits. Closure recommendations use existing recorded proof plus targeted current-source reads, not new runtime verification. Some touch triggers are honestly UNKNOWN because exhaustive change-history traversal was neither supplied nor necessary for a carry ruling."},"error":null}}],"api":"openai-codex-responses","provider":"openai-codex","model":"gpt-6-astra","usage":{"input":3796,"output":4812,"cacheRead":150016,"cacheWrite":0,"totalTokens":158624,"reasoningTokens":96,"cost":{"input":0,"output":0,"cacheRead":0,"cacheWrite":0,"total":0}},"stopReason":"toolUse","timestamp":1789094658636,"responseId":"resp_065c0d1976ecf9c2016aa36b008b1487d1b4620292157754dc","providerPayload":{"type":"openaiResponsesHistory","provider":"openai-codex","dt":true,"items":[{"id":"rs_065c0d1976ecf9c2016aa36b01ab7087d1befae54ff8a9a121","type":"reasoning","content":[],"encrypted_content":"gAAAAABqo2sGA24DWogmWNmtuaZLGGUfwnQumiFC0eZWDvPwqXWhPG53VIclFCav8Bb7DtWiMjOs3C9Hio75smQ_iSWsIgOq6U9pBw8VVCy6rg0Q38NO352QdBPbwROLB4og_jDLXoODguzbVhTS0shW0pPtR866mjFJPnM3XaX835WTUTnGaLtSs_lsFXZXevLDrjMVtaNzRIeaxSjy8LmWYpzb6NoSIYnQMOBm6cUV01RbU14cCVNQbEM5V1F9Emw9FNILNS3Xcwo4tUHmtLc0eCn8fz8XuGPYSU8WTUa67kwqz5VSX7gnHvHJ4RYs-PFkRKejNsPkdNZLC5nKG4RnowmFXpDT2e3j2IEFVh80Re94DxdmrCzLAT3bZa3EB5QlvOpeQJJyW_AGz2ylJM-yiWTdYPbNMWB3nPeEkt9g8pRA94Zag0r4wnV-AETDpiELcTmR_aHJX2Z2HCOOddism8Y2YxLsZxZmSYugVW8Cmnqztlx8kleZl9zAwmqqPACExH6R6_oZgHkBCWwIVGZ6A9Qh5aEOgvaOgmsReUSMKOyLaHrP3XFPtehV_DbcBldyDBmLUv5dgx9xg9fZ-pcs4y-5So7uP6Zu8IJvOO2AtSMuRict6nJMSBxUN1w_EZSQIv18SeYb6cdjoGCzFyIduTi4OV9el6-cf_DdfVUwxvN9AjIh9jiBJL6oOoOYDunCUni6UgI3XULHTEeG83GpLFP0HFAcl1mQyaAg-p25r68ANq3igkAXZD4w4ccjcmDKElVz68RTnJ4GOs8RbOgHpHIaU9HJ4aZXvcYeAp-799kDtRzqzbBFU13PjFA0bx1oSdFA0ZzV5Jsvm_eSMzQtL2cTbzoxgtK7HBG-ZXluz3ha179p3P1RxUQBmPKOdQL-KRpOE4biKRS1o4OSKituIL_ZLJlhsnATw2HzwnYskIGJlARSdFYnW6RC94LXjg9AJ0JgQ94mg16qpIFGAsG2gALl6Os7AQSHiPY1X-KwqrMr-tLEczNQEBES4v01Bvxd_yLnqcxkA-JwUEWZpcyQkF6nYVW2jUrhbAJrXmoMDbQKgfe-fVUyNqlQ-eA3lP4kylP7SYguQV_8HxhcjRCm73uAuZmoBQ5BT915NgPbNhL4bYHL8IO-ofc8WnYNR96vEqYflQU35dGNH3sXN0_95dGiZL_lLIv8mPwhHUtLDl-uM2zibumjrQ6_6x3sXkIAr7UkK21U-UNnvHz3_DwpPwEKpfae5-RArb3v3jOD9Ll9pRlbEza8z_3Oap1_H7tJCg_ab170OSrL7J5wWq7NGqbg-ebVCc0N6qlgbIPNZA21UeiG7f3CMk_j1P6cH3IFWwjeaprpFo5NmoAwA53KZStrvmsmW_9pogiVSw7S02HahsJRM3uTuJ_e78rhCRUYkLX54R_XecvfUM_sX4OE4jsvaT1zrWSxuXvznK1_LY5B_Lyj_UMwpTdnUVGQdEAWJ02JDsHfabHQ8E3Qo3dukMp8vRzunh-TtyKDZtOoysK1TIT2CfoV4H5UQ5QDxvhy0zBhwXpRIKkB2JNDExFN2ruEzf4yQeAp2iFoDHVVwHLCigTZjERewLj59ZqT7d0WO8f2EWNCiOAwW3wneW-7hHLA6j8q1OCzimzsP6KicEgu9-lpZsezoWRPWRECYOyTNNl9A-An2But8pt2u_KJ5dOkJyaH0V9NWWsrRt1H54L8sApp4GzhKfvoVagdMoTFR83Nc-CPjU4NmLfmZPyQrgtuu36vO8FRqAWRIbT0QnK_67N5xfclaqROVx_54jh6wQbYVpXeMgeoHSz2kCbaTx5mywwTORsIXzMwKpwuFgOt6tzmhJZmTzWRnVO1w3rWFTrg0PwF8foiE8hx0a9AdG7s9-3vjn68HEOD2sqV_y5MlEl0ewA=","internal_chat_message_metadata_passthrough":{"turn_id":"cb1368d9-2a08-40c0-9f68-e06c6338cbd5"},"summary":[],"metadata":{"turn_id":"cb1368d9-2a08-40c0-9f68-e06c6338cbd5"}},{"id":"fc_065c0d1976ecf9c2016aa36b06d0d487d1a692598bba9732a6","type":"function_call","status":"completed","arguments":"{\"type\":null,\"data\":{\"summary\":\"Read all 47 assigned entries (IR-50–97 excluding earlier IR-54), including every long amendment. Strongest corrections: IR-66 is eligible for closure; IR-73's eight reorders and docs-floor rereads are already implemented; IR-69/83/89 carry stale lifecycle wording. Keep the disk, quiet-window, slowdown, and diagnostic debts open. No edits or runtime checks performed.\",\"files\":[{\"path\":\"docs/INFRA-REGISTER.md:2726-5781\",\"description\":\"Complete assigned population and historical evidence; 47 entries, physical order includes IR-53 before IR-52.\"},{\"path\":\".github/workflows/ci.yml\",\"description\":\"All five IR-73 sites now follow checkout (IR-73 comments at 28, 98, 113, 184, 232); Windows start floor remains 32 GiB.\"},{\"path\":\".github/workflows/release.yml\",\"description\":\"All three IR-73 sites now follow checkout (comments at 54, 69, 169).\"},{\"path\":\".github/workflows/golden.yml\",\"description\":\"Docs-floor rereads at 599/622; Windows start still 32 GiB at 229; docs steps retain implicit preceding-success coupling.\"},{\"path\":\"crates/spt-daemon/tests/attach.rs\",\"description\":\"IR-66 remedies present: delayed TICK39 on Unix/Windows at 531/539, delayed ALT_VIEWPORT_MARKER at 656.\"},{\"path\":\"WEBSERVE-272-JIT.md:111-119\",\"description\":\"IR-66 explicitly ruled satisfied; workflow floor rider and driver adoption tracked separately.\"},{\"path\":\".github/ci/reap-census.ps1\",\"description\":\"Family-only process predicate remains at 70–73/123; does not implement IR-76's compiler-load predicate.\"},{\"path\":\"docs/GOLDEN-CI.md:26-51\",\"description\":\"Existing quiet-window contract includes CI occupancy, local build processes, and parent-chain attribution; reuse instead of introducing another definition.\"},{\"path\":\"crates/spt-store/src/proc.rs:46-49,430-433\",\"description\":\"kill_pid and kill_pid_tree still accept bare numeric PIDs; IR-81 primitive-level remedy not present.\"},{\"path\":\"crates/spt-daemon/src/daemon.rs:475-476\",\"description\":\"Pidfile still overwritten directly; IR-82 predecessor preservation not implemented.\"},{\"path\":\"crates/xtask/src/brainread.rs:194-203,295-320\",\"description\":\"IR-94 name-shape predicate and three-file enumeration remain.\"},{\"path\":\"crates/xtask/src/main.rs:69-70\",\"description\":\"pick-audit and disk-floor verbs exist, contradicting stale future-build wording in IR-57/59.\"}],\"architecture\":\"Separate structural enforcement, procedural adoption, box mitigations, and incident diagnosis. Workflow floor placement is distinct from capacity sizing; process custody is distinct from performance attribution; publication ordering is distinct from inject coverage. Release SHIP authority and passing batteries do not discharge unresolved mechanism claims.\",\"report\":\"## Scope and reading key\\n47 assigned entries: IR-50–97, excluding IR-54 (starts earlier). IR-49's preceding body and the CI-RIDER historical section were seen but not assigned as new IR entries. IR-31 is outside this range and remains the earlier-range owner's embedded-entry responsibility.\\n\\nTrigger = an entry's remedy/intake trigger, not proof its failure recurred. FIRED may be historically established; UNKNOWN means the supplied release facts and inspected material do not establish a qualifying new touch/event. Existing BUILT/CLOSED states stand without gratuitous re-verification. Actions are recommendations for the parent's ruling, not board mutations.\\n\\n## Exhaustive disposition table\\n| IR | Current entry state | Trigger | Recommendation and evidence |\\n|---|---|---|---|\\n| 50 | CLOSED / BUILT, landed v0.59.0 | FIRED historically | CARRY closed. Census/adoption completion and explicit engine-room exclusion already evidenced; release facts supply no reopening. |\\n| 51 | OPEN | UNKNOWN for #199 causal attribution; historical hermeticity pass available | CARRY. Ephemeral advisory ports do not disable peer pump/discovery or establish network causality. Preserve sequencing prohibition against net-off-as-green. |\\n| 52 | BUILT | FIRED historically, generator touch SIGNET | CARRY built. Full recursive command-tree rendering and previously omitted leaves recorded; do not reopen from old third-instance pre-build prose. |\\n| 53 | BUILT / landed v0.59.0 | FIRED historically | CARRY built. Cold-boot arm explicitly names unproved property; three narrower clock-aging siblings remain touch-triggered, not newly diagnosed by release success. |\\n| 55 | OPEN, ARMED-FOR-CAPTURE, hertz | FIRED (standing unfiltered-battery trigger) | CARRY armed, owner unavailable rather than executing. Nextest containment and prior 5×663 green settle sweep are not leak closure; no fresh wedge reported. Keep capture-before-kill protocol. |\\n| 56 | BUILT | FIRED historically | CARRY built. Cross-worktree refusal and explicit foreign-pool takeover measured in entry; IR-42 admission boundary intentionally remains. |\\n| 57 | OPEN, living gater procedure | FIRED (assembly/release arc) | CARRY procedure; correct stale proposed-tool wording: pick-audit already exists (xtask main:69) and caught real LOSS. Release build success proves compilation, not per-pick fidelity or repaired-file behavior. |\\n| 58 | OPEN, unowned; original claim retracted | FIRED (brainread/xtask work this milestone) | COMPOSE cargo-enumerated duplicate-bin check at next tooling intake; no closure evidence. Never resurrect withdrawn nonexistent-bin/prose correction. |\\n| 59 | OPEN, arithmetic/discipline | FIRED, including latest post-push disk-floor red | COMPOSE residual driver adoption/capacity work, carry discipline. Workflow start/end and docs-floor logging now exist; xtask disk-floor exists. Root target 62.32 GiB + CI debug 59.70 GiB and later 4.22 GiB cleanup are mitigations, not bounded accumulation. Do not call 14.3 GiB an explanation for unavailable earlier unit logs. |\\n| 60 | OPEN, script discipline | FIRED (diagnostic/gate reporting) | COMPOSE into next shared driver touch, carry open. Preserve leg verdict separately from wrapper completion; 3167 unit pass then floor red must be reported as distinct outcomes, not flattened to all-green or all-unit-red. Missing exit also requires reading raw Summary (IR-79), not inventing completion. |\\n| 61 | OPEN, accepted with mitigation | UNKNOWN substantive scanner touch | CARRY. No supplied fact establishes literal-tracker unification; unrelated xtask work alone is not this specific trigger. |\\n| 62 | BUILT docs-collision remedy; residual caveat | FIRED historically | CARRY built scoped to docs listener. Other bind surfaces remain conditional residuals; do not imply whole network hermeticity. |\\n| 63 | OPEN, mitigated, historical queued hertz lane | FIRED historically/rig work | COMPOSE with teardown/IR-79/97 adoption, keep open. Path-safe reaps are mitigation; no complete producer-side teardown proof. Update queued-owner language to pending acknowledgement, not active execution. Historical rotating victims do not classify the new sync/convoy red. |\\n| 64 | OPEN, operator reservoir | FIRED historically by IR-86 in-job floor failure; latest disk red reinforces relevance | COMPOSE operator capacity/accept-tax decision, carry open. Current cleanup does not move operator-owned bulk or prove permanent headroom. Do not recite historical 845 GB as a freshly measured current census. |\\n| 65 | REMEDIATED-AT-BOX, OPEN recheck record | UNKNOWN snap/auditd update or reimage | CARRY recheck record; no box commands needed this sweep. Release green is not evidence that effective audit configuration survived a named reset event. |\\n| 66 | BUILT; explicitly due to leave at WEBSERVE close | FIRED, close overdue | CLOSE eligible now. JIT:111–116 already rules satisfied; current attach.rs:531/539/656 retains both delayed needles. Remove stale next-intake two-edit rider from sweep summary; this is source-backed closure, not green-alone retirement. |\\n| 67 | BUILT, battery-template remedy | FIRED historically/intake | CARRY built. Scoped 121-pass battery is only its named scope; do not use --bins as integration coverage or promote it to full golden acceptance. |\\n| 68 | OPEN investigation | UNKNOWN new PSYCHE_INGEST_FAIL/probe slot | CARRY. Existing nonempty-lock experiment refuted the proposed cause; unrelated release facts cannot reinstate index.lock attribution. |\\n| 69 | OPEN; header says parked pre-assembly | FIRED historically close-out recensus | COMPOSE #243 residual plus separately tracked anchored-consumer rider; correct stale header. Body already records landed ec6da9b0 and 338 cli + 2 main residuals. Need residual conversion, generator fix, and SHA-pinned zero recensus before closure. Delivery.rs post-cut sites already converted; no new lane owed there. |\\n| 70 | OPEN, recurrence remedy unscheduled | UNKNOWN construction/API/sink touch | CARRY. Shipped default_bus site correction is not enforced assembly-point closure. IR-92 funnel work may make this a useful next construction-seam rider, but do not assert its trigger from publication work alone. |\\n| 71 | OPEN observability | UNKNOWN qualifying controller-lifecycle/breadcrumb touch | CARRY, eligible next lifecycle instrument rider. Existing info.json polling barrier proves convergence separately; no new persisted-release breadcrumb evidenced. |\\n| 72 | OPEN observability | UNKNOWN qualifying read-model/holder-inspection touch | CARRY. Cleanup process-table custody is not a supported named-seat read verb. |\\n| 73 | OPEN, title/body claim eight pre-checkout sites still owed | FIRED; implementation already present | CLOSE eligible for the entry's original two halves, with implementation evidence explicitly stated. All 5 ci and 3 release sites are after checkout with IR-73 comments; golden docs rereads exist and IR-86 records their live catch. Current header is stale. Capacity derivation and docs dependency coupling remain IR-86, not reasons to re-build IR-73. |\\n| 74 | OPEN /tmp population | FIRED as between-milestone audit opportunity; current Linux touch unknown | COMPOSE bounded /tmp lifecycle at box-audit intake, not a fresh numeric census. Windows cleanup says nothing about kitsubito's 21,643 historical homes. |\\n| 75 | OPEN Linux treqs 127 | UNKNOWN new Linux-driver touch; audit opportunity remains | COMPOSE install-or-explicit-platform-independent-coverage decision with Linux box audit. No proof here of current installation or driver removal; retain stale-state verification obligation, never infer it from overall green. |\\n| 76 | OPEN quiet-window/measurement | FIRED driver/workflow/runbook arc | COMPOSE outstanding enforcement and compiler-load census. Existing GOLDEN-CI:26–51 already supplies a better occupancy/parent-chain contract; reap-census still selects only SPT family. IR-87 proves queue interference, not cause of sync expiry. Historical headline 'manufactured' is stronger than overlap alone; new sweep must not repeat it as a diagnosis. |\\n| 77 | OPEN boot interval visibility | UNKNOWN exact boot/ready-stamp touch | CARRY, compose if next daemon-boot instrumentation lane opens. No timestamped child-entry→ready proof surfaced; full test duration is not boot interval. |\\n| 78 | OPEN silent docs-port override | UNKNOWN new docshost touch; historical belief incident already witnessed | CARRY tiny next-docshost rider. No release fact proves notice implemented; precedence need not be redesigned. |\\n| 79 | OPEN panic/timeout teardown exposure | UNKNOWN new common-module touch; exposure continues | COMPOSE first-wave guard adoption with IR-63/97; pending owner acknowledgement. Preserve panic-vs-hard-kill boundary: Rust Drop alone does not guarantee cleanup on process termination/SIGKILL. Entry's blanket timeout coverage claim needs qualification, not adoption as a guarantee. |\\n| 80 | OPEN; initial product-candidate headline superseded by amendments | FIRED historical investigation opportunity | CARRY residual class, reconcile stale opening. Body identifies brainproc shell-wrapper fixture mechanism and direct production spawn; does not classify all 12 union members. LEAK-count reduction or passing Windows unit set cannot close this. No owner is executing by implication. |\\n| 81 | OPEN primitive + gate; adapter arm CLOSED | FIRED historical proc/xtask work | COMPOSE remaining primitive and script-gate obligations. Current kill_pid(pid) and kill_pid_tree(root) remain bare-PID APIs (proc.rs:46/430); KH7.51 records a broker-site birth-safe correction but one site does not close primitive enforceability. Adapter closure stands, incident cause remains separate. |\\n| 82 | RULED, remedy historically linked #285 | FIRED historical lifecycle/#285 lane opportunity | COMPOSE unbuilt predecessor record independently of #285's site repair. daemon.rs:476 still direct-writes pidfile; no predecessor retention at this path. Header 'main ends at IR-78' is historical/stale. Do not call linked lane completion IR-82 completion. |\\n| 83 | OPEN, operator-rule blocked historical prose | FIRED; superseded box evidence in IR-89 | CARRY direction-witness enforcement residual, reconcile obsolete blocker/LAN-only prescription. IR-89 records actual tailnet ACL+firewall grants and successful tailnet probes, refuting a universal 'never tailnet' necessity. Need parent ruling to replace obsolete remediation with layer-specific admission + permanent reverse witness, not infer full closure from a one-box green. |\\n| 84 | OPEN, first instrument half landed with filing | FIRED historically | CARRY unresolved stall arithmetic/enforcement residual; acknowledge clocked emitter half as built. Timestamp instrumentation does not explain the extra ~27–34 s, shorten behavior, or prove every future arm stamped. |\\n| 85 | OPEN, caps mitigation only | FIRED arm 1; operator arms UNKNOWN | COMPOSE redesigned discriminator after guard/occupancy prerequisites, keep open. Old-sha slowdown establishes head growth not necessary, not environment apportionment. Alternate AB/BA, bank per-leg conditions/output; cap 80/40 remains mitigation. No Defender/torrent/disk causal allocation from concurrency or reclaim recovery. Hertz offline: brief delivered, unacknowledged. |\\n| 86 | OPEN, capacity derivation + docs coupling | FIRED golden/workflow arc | COMPOSE workflow sizing/independent docs dependency rider. golden.yml still 32 GiB start (229), docs floor (626), and OS-only success-coupled conditions (600/617/623). Historical 67.4 GiB footprint motivates re-derivation, not universal guaranteed peak. Latest 14.3<32 post-unit red is additional capacity evidence, not a new product failure. |\\n| 87 | OPEN independent job clocks | FIRED; exact recurrence banked at a9e786b2 | COMPOSE scheduling/rendezvous rider. Entry timeline proves B ended before A began, caused by golden head's own PR runner occupancy; include self-PR, not merely other lanes. Keep raw GitHub conclusions alongside VOID scoring. 900s panel alone cannot separate this from firewall. |\\n| 88 | OPEN pool-release vehicle | FIRED historical teardown; runbook adoption due | COMPOSE permanent release-before-delete/prebuilt recipe; carry open until adoption documented. Positive control already proves cargo-run regrowth vs prebuilt non-regrowth; current cleanup alone doesn't show recipe institutionalized. Prefer existing proven sequence, not an in-verb refusal that can only run after cargo already rebuilt it. |\\n| 89 | BOX applied; WORKFLOW built, landed-pending-golden | FIRED: multiple subsequent goldens | CARRY built pending exact step evidence; flag 'until next golden' stale immediately. No full probe-step outcomes were supplied/read here; next golden occurred but that alone is not exercise proof (steps can skip/partners desynchronize). Read retained step logs to replace pending wording with precise exercised/skipped/failed result; do not reapply operator rules or blame IR-87's 900s red on firewall. |\\n| 90 | OPEN disk refusal/context | FIRED, ripe now | COMPOSE rig-root/target-volume start refusal + current free-space failure context, prerequisite for IR-85 rerun. Reclaims mitigate only. Latest known 3167 unit pass followed by disk floor red is classified at its observed step; unavailable earlier PR logs remain unclassified. |\\n| 91 | CLOSED by filing lane | FIRED historically | CARRY closed. Preserve cited tracked artifacts and scratch manifests; parent cleanup retained evidence, so no reopening shown. |\\n| 92 | OPEN, says fix unassigned | FIRED inject/IO-funnel remedy; parent reports core215/217 merged | PARENT DECISION. Mark header stale but do not close here. Source/contract verification must distinguish inject success publication from relay ordering and per-msg-id exact-once; parent owns substantive reconciliation. |\\n| 93 | OPEN production symbols | UNKNOWN new packaging touch; release build alone is not a source touch | COMPOSE next packaging intake decision, keep open. Successful release build is not PDB availability, symbol matching, installation, or usable frame evidence. Preserve size/profile/operator trade rather than assuming approval. |\\n| 94 | OPEN scanner reach | FIRED at newly added brainread gate; mandatory before bounded serve_sync migration | COMPOSE fail-on-unclassified stream-server census. Current brainread.rs:199 and 306–320 retain name shape/three-file registry. Independent gate defect, not cause of golden sync red. |\\n| 95 | OPEN, measured/censused, diagnostic-only instrumentation | FIRED comparison already ran | COMPOSE prioritized observability + separately versioned exchange-correlated producer trace; retain open. 317/321 is classifier estimate with membership slop, 15 unclassified, not repo-wide floor/rate; no blanket 304-site editing. Diagnostic patch is unlanded, not release behavior. Preserve censored expiry, filtered final snapshot, no stream-between-polls claim, and no inferred budget fix. |\\n| 96 | OPEN cause-unclassified | NOT FIRED for named new qualifying event on supplied facts; cheap discriminator still unrun | CARRY with explicit next-intake investigation, not resolved/non-defect. 0/1 candidate CI vs 3/3 diagnostic HEAVY is confounded tree/workload/box, plus IR-97. Brief delivered to offline hertz is pending acknowledgement, not executing. |\\n| 97 | OPEN protocol deviation | FIRED repeated-run experiment | COMPOSE mandatory between-run identity census/accounting before any repeated IR-85/95/96 work. 0/6/12 carried residues are counts, not measured load or sync cause; 18 seen vs 15 killed does not prove three self-exits. Cleanups do not cure harness enforcement. |\\n\\n## Load-bearing deltas for the parent's edit\\n1. **Retire duplicate work, not residual mechanisms:** close IR-66; IR-73's source contract is implemented at all eight sites and both docs rereads. Amend their stale top-of-register riders. Keep IR-86 capacity/docs dependency debt separate. IR-57 pick-audit and IR-59 disk-floor are already tools, not future tooling proposals.\\n2. **Lifecycle wording needs reconciliation:** IR-69's parked header contradicts its own landed/residual addendum; IR-83's rule-blocked/LAN-only prose conflicts with IR-89's applied tailnet and firewall proof; IR-89's next-golden trigger fired but exact step proof is still needed; IR-92's unassigned header conflicts with parent's merged core215/217 fact. IR-80's product-candidate opening must be read through later scoped fixture findings. IR-82's #285 lane linkage did not deliver its pidfile retention.\\n3. **No causal laundering at release close:** v0.69.0 c105 at 16df0e41 shipped under explicit operator SHIP with known candidate a9e786b2 sync red. 121 scoped passes, release build success, and 3167 Windows unit passes prove exactly those observations. The later floor failure at 14.3 vs 32 GiB is not a unit-test failure; unavailable earlier PR unit logs are still unclassified. No disk/load attribution for sync/convoy from overlap or pass-after-reclaim.\\n4. **Cleanup accounting remains mitigation:** retain separate 62.32 GiB root-target and 59.70 GiB CI-debug measurements; later 38 clean merged worktrees/obsolete clone etc yielded net 4.22 GiB. Do not conflate file-length totals with free-space deltas, or report a structural capacity fix. Parent confirms no dirty/unmerged/retained evidence removed.\\n5. **Coherent next-intake packages:** (A) workflow/driver resource contract: IR-59/60/76/86/87/90/97, preserving separate conditions and budgets; (B) pool teardown adoption: IR-88 with earlier-range pool audit, IR-64 operator decision separate; (C) test lifetime work: IR-63/79/80 plus Linux IR-74/75, without collapsing fixture vs product identity debt IR-81/82; (D) diagnostic continuation: IR-85/95/96 only after occupancy/disk/between-run prerequisites, with no budget widening; (E) small seam-triggered items: IR-94 gate reach and IR-93 symbol packaging. All hertz-shaped work is proposed/pending acknowledgement while offline, not dispatched-and-executing.\\n\\n## Verification limits\\nRead-only tools only; no tests, builds, formatters, linters, probes, re-runs, board writes, or file edits. Closure recommendations use existing recorded proof plus targeted current-source reads, not new runtime verification. Some touch triggers are honestly UNKNOWN because exhaustive change-history traversal was neither supplied nor necessary for a carry ruling.\"},\"error\":null}","call_id":"call_awy02qy4wLPXYTAX0PtNHBbB","internal_chat_message_metadata_passthrough":{"create_time":1789094656.877176,"turn_id":"cb1368d9-2a08-40c0-9f68-e06c6338cbd5"},"name":"yield","metadata":{"turn_id":"cb1368d9-2a08-40c0-9f68-e06c6338cbd5"}}]},"duration":145762.31069999933,"ttft":1393.0913999993354,"completedAt":1789094804399,"contextSnapshot":{"promptTokens":153812,"nonMessageTokens":10400,"compactionEpoch":0}}}
{"type":"message","id":"b2790272","parentId":"da2856d6","timestamp":"2026-09-11T02:46:44.404Z","message":{"role":"toolResult","toolCallId":"call_awy02qy4wLPXYTAX0PtNHBbB|fc_065c0d1976ecf9c2016aa36b06d0d487d1a692598bba9732a6","toolName":"yield","content":[{"type":"text","text":"Result submitted."}],"details":{"data":{"summary":"Read all 47 assigned entries (IR-50–97 excluding earlier IR-54), including every long amendment. Strongest corrections: IR-66 is eligible for closure; IR-73's eight reorders and docs-floor rereads are already implemented; IR-69/83/89 carry stale lifecycle wording. Keep the disk, quiet-window, slowdown, and diagnostic debts open. No edits or runtime checks performed.","files":[{"path":"docs/INFRA-REGISTER.md:2726-5781","description":"Complete assigned population and historical evidence; 47 entries, physical order includes IR-53 before IR-52."},{"path":".github/workflows/ci.yml","description":"All five IR-73 sites now follow checkout (IR-73 comments at 28, 98, 113, 184, 232); Windows start floor remains 32 GiB."},{"path":".github/workflows/release.yml","description":"All three IR-73 sites now follow checkout (comments at 54, 69, 169)."},{"path":".github/workflows/golden.yml","description":"Docs-floor rereads at 599/622; Windows start still 32 GiB at 229; docs steps retain implicit preceding-success coupling."},{"path":"crates/spt-daemon/tests/attach.rs","description":"IR-66 remedies present: delayed TICK39 on Unix/Windows at 531/539, delayed ALT_VIEWPORT_MARKER at 656."},{"path":"WEBSERVE-272-JIT.md:111-119","description":"IR-66 explicitly ruled satisfied; workflow floor rider and driver adoption tracked separately."},{"path":".github/ci/reap-census.ps1","description":"Family-only process predicate remains at 70–73/123; does not implement IR-76's compiler-load predicate."},{"path":"docs/GOLDEN-CI.md:26-51","description":"Existing quiet-window contract includes CI occupancy, local build processes, and parent-chain attribution; reuse instead of introducing another definition."},{"path":"crates/spt-store/src/proc.rs:46-49,430-433","description":"kill_pid and kill_pid_tree still accept bare numeric PIDs; IR-81 primitive-level remedy not present."},{"path":"crates/spt-daemon/src/daemon.rs:475-476","description":"Pidfile still overwritten directly; IR-82 predecessor preservation not implemented."},{"path":"crates/xtask/src/brainread.rs:194-203,295-320","description":"IR-94 name-shape predicate and three-file enumeration remain."},{"path":"crates/xtask/src/main.rs:69-70","description":"pick-audit and disk-floor verbs exist, contradicting stale future-build wording in IR-57/59."}],"architecture":"Separate structural enforcement, procedural adoption, box mitigations, and incident diagnosis. Workflow floor placement is distinct from capacity sizing; process custody is distinct from performance attribution; publication ordering is distinct from inject coverage. Release SHIP authority and passing batteries do not discharge unresolved mechanism claims.","report":"## Scope and reading key\n47 assigned entries: IR-50–97, excluding IR-54 (starts earlier). IR-49's preceding body and the CI-RIDER historical section were seen but not assigned as new IR entries. IR-31 is outside this range and remains the earlier-range owner's embedded-entry responsibility.\n\nTrigger = an entry's remedy/intake trigger, not proof its failure recurred. FIRED may be historically established; UNKNOWN means the supplied release facts and inspected material do not establish a qualifying new touch/event. Existing BUILT/CLOSED states stand without gratuitous re-verification. Actions are recommendations for the parent's ruling, not board mutations.\n\n## Exhaustive disposition table\n| IR | Current entry state | Trigger | Recommendation and evidence |\n|---|---|---|---|\n| 50 | CLOSED / BUILT, landed v0.59.0 | FIRED historically | CARRY closed. Census/adoption completion and explicit engine-room exclusion already evidenced; release facts supply no reopening. |\n| 51 | OPEN | UNKNOWN for #199 causal attribution; historical hermeticity pass available | CARRY. Ephemeral advisory ports do not disable peer pump/discovery or establish network causality. Preserve sequencing prohibition against net-off-as-green. |\n| 52 | BUILT | FIRED historically, generator touch SIGNET | CARRY built. Full recursive command-tree rendering and previously omitted leaves recorded; do not reopen from old third-instance pre-build prose. |\n| 53 | BUILT / landed v0.59.0 | FIRED historically | CARRY built. Cold-boot arm explicitly names unproved property; three narrower clock-aging siblings remain touch-triggered, not newly diagnosed by release success. |\n| 55 | OPEN, ARMED-FOR-CAPTURE, hertz | FIRED (standing unfiltered-battery trigger) | CARRY armed, owner unavailable rather than executing. Nextest containment and prior 5×663 green settle sweep are not leak closure; no fresh wedge reported. Keep capture-before-kill protocol. |\n| 56 | BUILT | FIRED historically | CARRY built. Cross-worktree refusal and explicit foreign-pool takeover measured in entry; IR-42 admission boundary intentionally remains. |\n| 57 | OPEN, living gater procedure | FIRED (assembly/release arc) | CARRY procedure; correct stale proposed-tool wording: pick-audit already exists (xtask main:69) and caught real LOSS. Release build success proves compilation, not per-pick fidelity or repaired-file behavior. |\n| 58 | OPEN, unowned; original claim retracted | FIRED (brainread/xtask work this milestone) | COMPOSE cargo-enumerated duplicate-bin check at next tooling intake; no closure evidence. Never resurrect withdrawn nonexistent-bin/prose correction. |\n| 59 | OPEN, arithmetic/discipline | FIRED, including latest post-push disk-floor red | COMPOSE residual driver adoption/capacity work, carry discipline. Workflow start/end and docs-floor logging now exist; xtask disk-floor exists. Root target 62.32 GiB + CI debug 59.70 GiB and later 4.22 GiB cleanup are mitigations, not bounded accumulation. Do not call 14.3 GiB an explanation for unavailable earlier unit logs. |\n| 60 | OPEN, script discipline | FIRED (diagnostic/gate reporting) | COMPOSE into next shared driver touch, carry open. Preserve leg verdict separately from wrapper completion; 3167 unit pass then floor red must be reported as distinct outcomes, not flattened to all-green or all-unit-red. Missing exit also requires reading raw Summary (IR-79), not inventing completion. |\n| 61 | OPEN, accepted with mitigation | UNKNOWN substantive scanner touch | CARRY. No supplied fact establishes literal-tracker unification; unrelated xtask work alone is not this specific trigger. |\n| 62 | BUILT docs-collision remedy; residual caveat | FIRED historically | CARRY built scoped to docs listener. Other bind surfaces remain conditional residuals; do not imply whole network hermeticity. |\n| 63 | OPEN, mitigated, historical queued hertz lane | FIRED historically/rig work | COMPOSE with teardown/IR-79/97 adoption, keep open. Path-safe reaps are mitigation; no complete producer-side teardown proof. Update queued-owner language to pending acknowledgement, not active execution. Historical rotating victims do not classify the new sync/convoy red. |\n| 64 | OPEN, operator reservoir | FIRED historically by IR-86 in-job floor failure; latest disk red reinforces relevance | COMPOSE operator capacity/accept-tax decision, carry open. Current cleanup does not move operator-owned bulk or prove permanent headroom. Do not recite historical 845 GB as a freshly measured current census. |\n| 65 | REMEDIATED-AT-BOX, OPEN recheck record | UNKNOWN snap/auditd update or reimage | CARRY recheck record; no box commands needed this sweep. Release green is not evidence that effective audit configuration survived a named reset event. |\n| 66 | BUILT; explicitly due to leave at WEBSERVE close | FIRED, close overdue | CLOSE eligible now. JIT:111–116 already rules satisfied; current attach.rs:531/539/656 retains both delayed needles. Remove stale next-intake two-edit rider from sweep summary; this is source-backed closure, not green-alone retirement. |\n| 67 | BUILT, battery-template remedy | FIRED historically/intake | CARRY built. Scoped 121-pass battery is only its named scope; do not use --bins as integration coverage or promote it to full golden acceptance. |\n| 68 | OPEN investigation | UNKNOWN new PSYCHE_INGEST_FAIL/probe slot | CARRY. Existing nonempty-lock experiment refuted the proposed cause; unrelated release facts cannot reinstate index.lock attribution. |\n| 69 | OPEN; header says parked pre-assembly | FIRED historically close-out recensus | COMPOSE #243 residual plus separately tracked anchored-consumer rider; correct stale header. Body already records landed ec6da9b0 and 338 cli + 2 main residuals. Need residual conversion, generator fix, and SHA-pinned zero recensus before closure. Delivery.rs post-cut sites already converted; no new lane owed there. |\n| 70 | OPEN, recurrence remedy unscheduled | UNKNOWN construction/API/sink touch | CARRY. Shipped default_bus site correction is not enforced assembly-point closure. IR-92 funnel work may make this a useful next construction-seam rider, but do not assert its trigger from publication work alone. |\n| 71 | OPEN observability | UNKNOWN qualifying controller-lifecycle/breadcrumb touch | CARRY, eligible next lifecycle instrument rider. Existing info.json polling barrier proves convergence separately; no new persisted-release breadcrumb evidenced. |\n| 72 | OPEN observability | UNKNOWN qualifying read-model/holder-inspection touch | CARRY. Cleanup process-table custody is not a supported named-seat read verb. |\n| 73 | OPEN, title/body claim eight pre-checkout sites still owed | FIRED; implementation already present | CLOSE eligible for the entry's original two halves, with implementation evidence explicitly stated. All 5 ci and 3 release sites are after checkout with IR-73 comments; golden docs rereads exist and IR-86 records their live catch. Current header is stale. Capacity derivation and docs dependency coupling remain IR-86, not reasons to re-build IR-73. |\n| 74 | OPEN /tmp population | FIRED as between-milestone audit opportunity; current Linux touch unknown | COMPOSE bounded /tmp lifecycle at box-audit intake, not a fresh numeric census. Windows cleanup says nothing about kitsubito's 21,643 historical homes. |\n| 75 | OPEN Linux treqs 127 | UNKNOWN new Linux-driver touch; audit opportunity remains | COMPOSE install-or-explicit-platform-independent-coverage decision with Linux box audit. No proof here of current installation or driver removal; retain stale-state verification obligation, never infer it from overall green. |\n| 76 | OPEN quiet-window/measurement | FIRED driver/workflow/runbook arc | COMPOSE outstanding enforcement and compiler-load census. Existing GOLDEN-CI:26–51 already supplies a better occupancy/parent-chain contract; reap-census still selects only SPT family. IR-87 proves queue interference, not cause of sync expiry. Historical headline 'manufactured' is stronger than overlap alone; new sweep must not repeat it as a diagnosis. |\n| 77 | OPEN boot interval visibility | UNKNOWN exact boot/ready-stamp touch | CARRY, compose if next daemon-boot instrumentation lane opens. No timestamped child-entry→ready proof surfaced; full test duration is not boot interval. |\n| 78 | OPEN silent docs-port override | UNKNOWN new docshost touch; historical belief incident already witnessed | CARRY tiny next-docshost rider. No release fact proves notice implemented; precedence need not be redesigned. |\n| 79 | OPEN panic/timeout teardown exposure | UNKNOWN new common-module touch; exposure continues | COMPOSE first-wave guard adoption with IR-63/97; pending owner acknowledgement. Preserve panic-vs-hard-kill boundary: Rust Drop alone does not guarantee cleanup on process termination/SIGKILL. Entry's blanket timeout coverage claim needs qualification, not adoption as a guarantee. |\n| 80 | OPEN; initial product-candidate headline superseded by amendments | FIRED historical investigation opportunity | CARRY residual class, reconcile stale opening. Body identifies brainproc shell-wrapper fixture mechanism and direct production spawn; does not classify all 12 union members. LEAK-count reduction or passing Windows unit set cannot close this. No owner is executing by implication. |\n| 81 | OPEN primitive + gate; adapter arm CLOSED | FIRED historical proc/xtask work | COMPOSE remaining primitive and script-gate obligations. Current kill_pid(pid) and kill_pid_tree(root) remain bare-PID APIs (proc.rs:46/430); KH7.51 records a broker-site birth-safe correction but one site does not close primitive enforceability. Adapter closure stands, incident cause remains separate. |\n| 82 | RULED, remedy historically linked #285 | FIRED historical lifecycle/#285 lane opportunity | COMPOSE unbuilt predecessor record independently of #285's site repair. daemon.rs:476 still direct-writes pidfile; no predecessor retention at this path. Header 'main ends at IR-78' is historical/stale. Do not call linked lane completion IR-82 completion. |\n| 83 | OPEN, operator-rule blocked historical prose | FIRED; superseded box evidence in IR-89 | CARRY direction-witness enforcement residual, reconcile obsolete blocker/LAN-only prescription. IR-89 records actual tailnet ACL+firewall grants and successful tailnet probes, refuting a universal 'never tailnet' necessity. Need parent ruling to replace obsolete remediation with layer-specific admission + permanent reverse witness, not infer full closure from a one-box green. |\n| 84 | OPEN, first instrument half landed with filing | FIRED historically | CARRY unresolved stall arithmetic/enforcement residual; acknowledge clocked emitter half as built. Timestamp instrumentation does not explain the extra ~27–34 s, shorten behavior, or prove every future arm stamped. |\n| 85 | OPEN, caps mitigation only | FIRED arm 1; operator arms UNKNOWN | COMPOSE redesigned discriminator after guard/occupancy prerequisites, keep open. Old-sha slowdown establishes head growth not necessary, not environment apportionment. Alternate AB/BA, bank per-leg conditions/output; cap 80/40 remains mitigation. No Defender/torrent/disk causal allocation from concurrency or reclaim recovery. Hertz offline: brief delivered, unacknowledged. |\n| 86 | OPEN, capacity derivation + docs coupling | FIRED golden/workflow arc | COMPOSE workflow sizing/independent docs dependency rider. golden.yml still 32 GiB start (229), docs floor (626), and OS-only success-coupled conditions (600/617/623). Historical 67.4 GiB footprint motivates re-derivation, not universal guaranteed peak. Latest 14.3<32 post-unit red is additional capacity evidence, not a new product failure. |\n| 87 | OPEN independent job clocks | FIRED; exact recurrence banked at a9e786b2 | COMPOSE scheduling/rendezvous rider. Entry timeline proves B ended before A began, caused by golden head's own PR runner occupancy; include self-PR, not merely other lanes. Keep raw GitHub conclusions alongside VOID scoring. 900s panel alone cannot separate this from firewall. |\n| 88 | OPEN pool-release vehicle | FIRED historical teardown; runbook adoption due | COMPOSE permanent release-before-delete/prebuilt recipe; carry open until adoption documented. Positive control already proves cargo-run regrowth vs prebuilt non-regrowth; current cleanup alone doesn't show recipe institutionalized. Prefer existing proven sequence, not an in-verb refusal that can only run after cargo already rebuilt it. |\n| 89 | BOX applied; WORKFLOW built, landed-pending-golden | FIRED: multiple subsequent goldens | CARRY built pending exact step evidence; flag 'until next golden' stale immediately. No full probe-step outcomes were supplied/read here; next golden occurred but that alone is not exercise proof (steps can skip/partners desynchronize). Read retained step logs to replace pending wording with precise exercised/skipped/failed result; do not reapply operator rules or blame IR-87's 900s red on firewall. |\n| 90 | OPEN disk refusal/context | FIRED, ripe now | COMPOSE rig-root/target-volume start refusal + current free-space failure context, prerequisite for IR-85 rerun. Reclaims mitigate only. Latest known 3167 unit pass followed by disk floor red is classified at its observed step; unavailable earlier PR logs remain unclassified. |\n| 91 | CLOSED by filing lane | FIRED historically | CARRY closed. Preserve cited tracked artifacts and scratch manifests; parent cleanup retained evidence, so no reopening shown. |\n| 92 | OPEN, says fix unassigned | FIRED inject/IO-funnel remedy; parent reports core215/217 merged | PARENT DECISION. Mark header stale but do not close here. Source/contract verification must distinguish inject success publication from relay ordering and per-msg-id exact-once; parent owns substantive reconciliation. |\n| 93 | OPEN production symbols | UNKNOWN new packaging touch; release build alone is not a source touch | COMPOSE next packaging intake decision, keep open. Successful release build is not PDB availability, symbol matching, installation, or usable frame evidence. Preserve size/profile/operator trade rather than assuming approval. |\n| 94 | OPEN scanner reach | FIRED at newly added brainread gate; mandatory before bounded serve_sync migration | COMPOSE fail-on-unclassified stream-server census. Current brainread.rs:199 and 306–320 retain name shape/three-file registry. Independent gate defect, not cause of golden sync red. |\n| 95 | OPEN, measured/censused, diagnostic-only instrumentation | FIRED comparison already ran | COMPOSE prioritized observability + separately versioned exchange-correlated producer trace; retain open. 317/321 is classifier estimate with membership slop, 15 unclassified, not repo-wide floor/rate; no blanket 304-site editing. Diagnostic patch is unlanded, not release behavior. Preserve censored expiry, filtered final snapshot, no stream-between-polls claim, and no inferred budget fix. |\n| 96 | OPEN cause-unclassified | NOT FIRED for named new qualifying event on supplied facts; cheap discriminator still unrun | CARRY with explicit next-intake investigation, not resolved/non-defect. 0/1 candidate CI vs 3/3 diagnostic HEAVY is confounded tree/workload/box, plus IR-97. Brief delivered to offline hertz is pending acknowledgement, not executing. |\n| 97 | OPEN protocol deviation | FIRED repeated-run experiment | COMPOSE mandatory between-run identity census/accounting before any repeated IR-85/95/96 work. 0/6/12 carried residues are counts, not measured load or sync cause; 18 seen vs 15 killed does not prove three self-exits. Cleanups do not cure harness enforcement. |\n\n## Load-bearing deltas for the parent's edit\n1. **Retire duplicate work, not residual mechanisms:** close IR-66; IR-73's source contract is implemented at all eight sites and both docs rereads. Amend their stale top-of-register riders. Keep IR-86 capacity/docs dependency debt separate. IR-57 pick-audit and IR-59 disk-floor are already tools, not future tooling proposals.\n2. **Lifecycle wording needs reconciliation:** IR-69's parked header contradicts its own landed/residual addendum; IR-83's rule-blocked/LAN-only prose conflicts with IR-89's applied tailnet and firewall proof; IR-89's next-golden trigger fired but exact step proof is still needed; IR-92's unassigned header conflicts with parent's merged core215/217 fact. IR-80's product-candidate opening must be read through later scoped fixture findings. IR-82's #285 lane linkage did not deliver its pidfile retention.\n3. **No causal laundering at release close:** v0.69.0 c105 at 16df0e41 shipped under explicit operator SHIP with known candidate a9e786b2 sync red. 121 scoped passes, release build success, and 3167 Windows unit passes prove exactly those observations. The later floor failure at 14.3 vs 32 GiB is not a unit-test failure; unavailable earlier PR unit logs are still unclassified. No disk/load attribution for sync/convoy from overlap or pass-after-reclaim.\n4. **Cleanup accounting remains mitigation:** retain separate 62.32 GiB root-target and 59.70 GiB CI-debug measurements; later 38 clean merged worktrees/obsolete clone etc yielded net 4.22 GiB. Do not conflate file-length totals with free-space deltas, or report a structural capacity fix. Parent confirms no dirty/unmerged/retained evidence removed.\n5. **Coherent next-intake packages:** (A) workflow/driver resource contract: IR-59/60/76/86/87/90/97, preserving separate conditions and budgets; (B) pool teardown adoption: IR-88 with earlier-range pool audit, IR-64 operator decision separate; (C) test lifetime work: IR-63/79/80 plus Linux IR-74/75, without collapsing fixture vs product identity debt IR-81/82; (D) diagnostic continuation: IR-85/95/96 only after occupancy/disk/between-run prerequisites, with no budget widening; (E) small seam-triggered items: IR-94 gate reach and IR-93 symbol packaging. All hertz-shaped work is proposed/pending acknowledgement while offline, not dispatched-and-executing.\n\n## Verification limits\nRead-only tools only; no tests, builds, formatters, linters, probes, re-runs, board writes, or file edits. Closure recommendations use existing recorded proof plus targeted current-source reads, not new runtime verification. Some touch triggers are honestly UNKNOWN because exhaustive change-history traversal was neither supplied nor necessary for a carry ruling."},"status":"success"},"isError":false,"timestamp":1789094804403}}
{"type":"custom","customType":"session_exit","data":{"reason":"dispose","kind":"normal","recordedAt":"2026-09-11T02:53:44.450Z"},"id":"55a2d8a1","parentId":"b2790272","timestamp":"2026-09-11T02:53:44.450Z"}
