{
  "summary": "The actual reusable hertz Windows S2 cohort is .spt/preserved/304-handoff/hertz-phase-b-B2FGTAFA/triage-run.py, historically operating .worktrees/hertz-304-phase-b. It is distinct from the S2 release-build rig and the older hertz-304 W1 rig. Exact attachment selection and safe ownership templates are below. No commands, builds, claims, fixtures, or edits were executed; investigation used reads/searches only. One important reuse defect: the historical driver's capacity StopFile is ignored by its launcher in step mode.",
  "files": [
    {
      "path": ".spt/preserved/304-handoff/hertz-phase-b-B2FGTAFA/triage-run.py",
      "description": "Actual Windows S2 driver. Lines 10–22 hardcode historical tree, launcher and two old selections; 24–85 retain isolated producer evidence and native containment; 87–109 implement build inventory and repeated ci-windows/retries0 runs."
    },
    {
      "path": ".spt/preserved/304-handoff/hertz-phase-b-B2FGTAFA/verdict.md",
      "description": "Identifies exact S2 commit 527cd8e8, .worktrees/hertz-304-phase-b, ten repetitions per changed cell, preserved evidence, released private pool and historical END."
    },
    {
      "path": ".spt/preserved/304-handoff/hertz-phase-b-B2FGTAFA/s2-final-receipt.json",
      "description": "Historical 10/10 counts, profile ci-windows, retries0, 45 native jobs complete/gone, final target/build census and pool_released=true. Historical evidence, not current admission."
    },
    {
      "path": ".spt/preserved/hertz-fp-driver-review/d2/field-rig-r5-S6ESSJ3N/support/fp-bin/launch-v2.ps1",
      "description": "Reusable launcher plus colocated launch-v2.cs. PS lines 1–15 define argv interface; 65–104 enforce fresh absolute destinations and load C# native job launcher."
    },
    {
      "path": ".spt/preserved/hertz-fp-driver-review/d2/field-rig-r5-S6ESSJ3N/support/fp-bin/launch-v2.cs",
      "description": "Native process creation/job containment. Lines 521–545 assign suspended child and read membership before resume; 555–564 reveal StopFile honored only for scope=run; 599–613 distinguish confirmation, deadline and native exit."
    },
    {
      "path": ".spt/preserved/304-handoff/box-clear/box-clear.ps1",
      "description": "Public S2 admission wrapper. Lines 1–38 retain runner ancestry; 40–72 execution census/positive control and unreadable handling; 74–88 CI axes. It writes evidence and copies/starts a control executable, so it is NOT a read-only metadata probe."
    },
    {
      "path": ".spt/preserved/hertz-304-w1-c468e9df/admission.py",
      "description": "Older admission builder/execution population distinction and live positive controls. Imports hardcoded lane_run.POOL/EVID; not safe to invoke against new ownership without adaptation."
    },
    {
      "path": ".spt/preserved/hertz-304-w1-c468e9df/lane_run.py",
      "description": "Older runner: free-space floor32GiB/growth64GiB, process ancestry, per-label private TEMP outside Git and PID/birth observation. Hardcoded historical target; insufficient modern OWL/SPT scrub and injects extra SPT_HOME/SPT_INSTALL_NO_FIREWALL."
    },
    {
      "path": ".github/ci/test-temp-sandbox.ps1",
      "description": "Lines 23–56 setup private spt-test-tmp-* direct child of RUNNER_TEMP via GITHUB_ENV; lines 59–108 guarded cleanup. Caller must apply emitted environment to child; parent owns cleanup after process reap."
    },
    {
      "path": ".github/ci/reap-census.ps1",
      "description": "Start/end/prerelink process census/reap. Lines 75–121 define scope roots and exclusions. Inherited broad GITHUB_WORKSPACE/RUNNER_TEMP plus unconditional USERPROFILE/spt-n1-oldbroker make unadapted interactive invocation unsafe."
    },
    {
      "path": ".spt/preserved/304-handoff/consumer-windows-7890ead3/run.ps1",
      "description": "Current consumer, lines 7–34: hardcoded .worktrees/asm-304-v3, exact SHA/clean-tree guards, full OWL/SPT name scrub, ci-windows, advisory ephemeral ports, jobs2, full A/B nextest. Does not establish private TEMP or override CARGO_TARGET_DIR itself."
    },
    {
      "path": ".spt/preserved/304-handoff/consumer-linux-S2-527cd8e8/windows-release/gate.py",
      "description": "Separate S2 release-build wrapper: .worktrees/release-S2-527cd8e8, exclusive output log, OWL/SPT scrub, own target/jobs2/incremental0 and32GiB monitoring. Not the ten-run S2 test rig."
    },
    {
      "path": "crates/xtask/src/main.rs",
      "description": "Lines 3024–3145 pool_claim: cwd/tree match, label, advisory long-lived holder PID plus birth, detached commit identity. Lines3212–3230 pool_release clears lane claim but retains ownership imprint."
    },
    {
      "path": "AGENTS.md",
      "description": "Lines38–41: worktrees under project .worktrees; pool belongs to one source tree; target classification before deletion; never share another checkout's target or place target in session scratch."
    },
    {
      "path": ".config/nextest.toml",
      "description": "Lines417–460: ci-windows does not inherit default overrides; test-threads8 and only four unit-group overrides. Single exact integration cell is not serialized by default heavy group under this profile; sequential external loop is essential."
    }
  ],
  "architecture": "Use a new exact-SHA worktree with its own real target and long-lived pool holder; adapt the public S2 driver into a new public evidence directory, retaining the existing native launcher pair. Establish outside-Git per-run TEMP and names-only environment scrub; admit after Doyle END; enumerate exact cell once, then ten sequential contained executions with independent receipts; confirm native jobs gone, release only own pool and clean only owned TEMP.",
  "report": "IDENTIFICATION\nThe S2 rig Doyle's reference most closely matches is proven by hertz-phase-b-B2FGTAFA/verdict.md and s2-final-receipt.json: .worktrees/hertz-304-phase-b at 527cd8e8, with s2-hardened-01 through -10 native records. The known release-S2-527cd8e8 tree was a separate release-binary build (windows-release/worktree-setup.txt says build/S2-527cd8e8). The older hertz-304/W1 runner is useful history for admission/TEMP hazards, not the final S2 cohort. Current consumer7890ead3 instead runs asm-304-v3 (run.ps1:8); its launch receipt says PID42440, start13:08:06Z. Do not treat any historical PID, released pool, or census as current ownership.\n\nEXACT SINGLE-CELL ARGV (PROPOSED; NOT EXECUTED)\nFilter F = package(=spt) & kind(test) & binary(=webserve_attachment_e2e) & test(=an_attachment_is_snapshot_served_fetched_back_and_named_by_its_message)\nInventory argv JSON for cargo executable:\n[\"nextest\",\"list\",\"-p\",\"spt\",\"--test\",\"webserve_attachment_e2e\",\"--profile\",\"ci-windows\",\"-E\",F,\"--message-format\",\"json\"]\nRequire exactly the named selected test in the inventory, not merely one matching substring. This list compiles if needed, so it too must wait for Windows END/admission.\nEach of ten sequential execution argv:\n[\"nextest\",\"run\",\"-p\",\"spt\",\"--test\",\"webserve_attachment_e2e\",\"--profile\",\"ci-windows\",\"-E\",F,\"--retries\",\"0\",\"--no-fail-fast\",\"--success-output\",\"immediate\",\"--failure-output\",\"immediate\",\"--color\",\"never\"]\nDo not inherit the historical two-package/two-binary scope or use --workspace. Preserve all ten native exits; test failures normally return100 in historical driver logic, while setup/build/timeout/containment failures must remain distinct from cell reds. Profile ci-windows is explicitly requested and matches current consumer; its integration heavy override is absent, so run sequentially (one selected cell per process), never parallel ten jobs.\n\nFRESH OWNERSHIP TEMPLATE (MAIN ONLY, AFTER AUTHORITY)\nSuggested new locations: .worktrees/attachment-NO4JJOEL-7890ead3 with target underneath; .spt/preserved/304-handoff/attachment-NO4JJOEL-7890ead3 for driver/receipts. Names are proposed, not claimed absent.\nFrom project root: git worktree add --detach .worktrees/attachment-NO4JJOEL-7890ead3 7890ead39bb7f14ed44aaae44b0951f098ffe9ac\nThen assert exact HEAD and clean tracked source before producers, cwd=new worktree, CARGO_TARGET_DIR=<new tree>\\target. Do not checkout any preserved release/hertz/asm tree, junction or redirect to their pools, or copy warmed targets. Cold target capacity must be separately admitted; if capacity unavailable, HOLD for an explicit sanctioned alternative, not silent pool reuse.\nFrom that new worktree, using an admitted existing xtask binary for bookkeeping:\n<xtask.exe> pool-claim --pool <absolute new tree\\target> --label attachment-NO4JJOEL-7890ead3 --holder-pid <long-lived cohort driver PID>\nRelease only after producers and owned descendants are gone:\n<xtask.exe> pool-release --pool <absolute new tree\\target>\nFallback repository convention is cargo run -p xtask -- pool-claim ... but that builds; using a separately approved existing xtask executable avoids bootstrapping merely to claim. Do not use --foreign-pool here. Claim and release functions write stamps; explicit admission remains essential because the observed claim body writes the owner after cwd/tree checks, and release clears a claim without authenticating caller ownership. Never let a short-lived helper PID represent the ten-run lane.\n\nNATIVE LAUNCH TEMPLATE\nReuse existing public launch-v2.ps1 with colocated launch-v2.cs read-only; adapt driver into NEW evidence rather than edit/run historical triage-run.py, which hardcodes old tree and HERE.\npwsh -NoProfile -File <public launch-v2.ps1> -Label attachment-01 -Seconds 180 -Scope step -Admission process-tree -RecordFile <absolute new run dir\\native.json> -ArgsFile <absolute new run dir\\argv.json> -Exe <absolute cargo.exe> -OutFile <absolute new run dir\\stdout.log> -ErrFile <absolute new run dir\\stderr.log> -EnvironmentFile <absolute new run dir\\environment.json>\n180 seconds is the historical per-cohort ceiling, not proof of adequacy for cold compilation. Use separate inventory/build admission (historical list allowance2400s), then measured cohort. Destinations must be absolute and fresh; wrapper rejects aliases/existing files. It compiles C# through Add-Type and starts native processes, hence forbidden before END.\nCheck subject.native_exit, completion_reason, coverage=COMPLETE, termination=CONFIRMED_GONE, job.active_processes=0; retain argv/cwd/source SHA, environment NAMES, start/end UTC, stdout/stderr/raw hashes and launcher/native exit separately.\nCRITICAL: historical triage-run.py:63–66 writes StopFile on disk pressure while launching Scope=step (49). launch-v2.cs:555–564 polls StopFile ONLY under Scope=run. Thus the historical step-mode capacity guard detects/reports pressure but cannot promptly stop the producer; do NOT advertise or copy it as effective protection. Main needs an actually effective admitted containment-stop path (and proof) in the new driver before capacity-sensitive execution. Scope=run is not a drop-in replacement: it intentionally stays alive after direct child exit until stop/deadline. No launcher change or execution done here.\n\nENVIRONMENT/TEMP\nNew child environment should purge OWL_/SPT_ keys case-insensitively and log names only. Match current consumer's sole added producer flag SPT_TEST_EPHEMERAL_ADVISORY_PORTS=1; do not accidentally inherit/add SPT_HOME, endpoint identity, watchdog overrides, or historical SPT_INSTALL_NO_FIREWALL. Explicitly own CARGO_TARGET_DIR, jobs2; remove ambient RUSTFLAGS/CARGO_ENCODED_RUSTFLAGS and nextest retry/thread overrides, pin intended profile/retries in argv. Incremental0 is a release/modern consumer precedent, not a measured property of the historical S2 test driver; record chosen value.\nFor private TEMP, use a new RUNNER_TEMP root outside every Git worktree, not .spt/preserved or .worktrees. CI sandbox setup requires RUNNER_TEMP and GITHUB_ENV and writes SPT_CI_TEST_TMP/TEMP/TMP lines to that file, NOT the parent process environment. Caller must read/apply emitted paths; set TMPDIR consistently if needed. Retain SPT_CI_TEST_TMP only in cleanup-parent state, not scrubbed producer environment. Verify outside-Git boundary after authorization. Per-iteration directories avoid shared fixture residue. Reap before sandbox cleanup. Existing lane_run.py documents the proven in-repo TEMP identity-discovery defect; do not inherit its negative-control HERTZ_RIG_TMP_IN_REPO=1.\n\nADMISSION/REAP\nbox-clear.ps1 takes -Tag <fresh unique tag> -Candidate 7890ead39bb7f14ed44aaae44b0951f098ffe9ac -Roots \"<owned target>;...\". It calls public runner-census.ps1, requires valid live self-positive ancestry, no Runner.Worker/cargo build/runner-descended/unresolved shim; separately samples target images with a live copied cmd.exe positive control; unreadable relevant processes HOLD absent prior evidence. It additionally checks CI queued/running/requested/waiting/pending status. It is a sample, NOT a lease, and hardcodes its public output directory; copy/adapt it to fresh evidence if preservation requires isolation. Its first root must be the NEW owned target because it copies/starts/removes a control there. Older admission.py likewise mutates old targets and creates live controls; don't invoke unadapted.\nPrefer native job disposal for owned descendant reap. CI reap-census.ps1 is not safe to run blindly on this interactive shared host: its roots include inherited GITHUB_WORKSPACE, RUNNER_TEMP and USERPROFILE/spt-n1-oldbroker. Setting GITHUB_WORKSPACE to project root would sweep other .worktrees; RUNNER_TEMP to common user TEMP would sweep peers. If needed, adapt a new copy to explicit owned roots plus PID/birth/image identity checks; never use image-wide or PID-only kills, never delete historical targets. Any unreadable process remains unverified, not clean.\n\nWHAT WAITS\nExplicit Doyle Windows END, not merely estimated14:05Z or a quiet instantaneous census, precedes cohort work, cargo/nextest list/build/run, pool claim/release, checkout/worktree mutation, TEMP setup, native launcher fixture/positive-control execution, reaping, and any target allocation/reclamation. Current Windows consumer retains the box until END. Then obtain/record admission, capacity and ownership prerequisites before starting. No test/source edits without separate Doyle GO. Reading public scripts/receipts is the only activity performed here; no top-level failure classification is asserted."
}