{
  "status": "implemented_not_executed",
  "paths": [
    ".spt/preserved/hertz-fp-driver-review/d2/fp-driver-d2-r6.sh",
    ".spt/preserved/hertz-fp-driver-review/d2/controls/r6-deadline-controls.py"
  ],
  "intended_invocation": "python .spt/preserved/hertz-fp-driver-review/d2/controls/r6-deadline-controls.py --bash \"C:/Program Files/Git/bin/bash.exe\" --output-root .spt/preserved/hertz-fp-driver-review/d2/controls/r6-deadline-proof-Doyle6U2UZVXK",
  "exact_deltas": [
    "Created r6 from unchanged r5; changed revision header and relevant preparation/provenance comments.",
    "Cleared W, SP, EXE_SHA, SUBJECT_SHA, SUBJECT_BLOB; RIG_ROOT remains empty. Added required_config refusal (exit64) before evidence/root creation when any of those six slots is empty.",
    "Replaced fresh process-start preparation clock with explicit SPT_RIG_PREP_EPOCH/SPT_RIG_PREP_DEADLINE validation: both unsigned decimal Unix seconds, 1–18 digits; leading zeroes converted explicitly as decimal; epoch <= now < deadline; deadline = epoch + PREP_BUDGET_S (600). Refusal exits8 before runtime evidence creation. No restart600 fallback.",
    "handoff_await now computes min(entry_now + requested duration, entry_now + HANDOFF_CAP_S, phase deadline). Cleanup explicitly uses WORK_DEADLINE, including pre-GO cleanup and unopened-work-deadline refusal.",
    "Changed cur_deadline precedence to cleanup first, then preparation, then experiment; pre-GO cleanup can no longer select PREP_DEADLINE.",
    "handoff_await rereads time around receipt checking and after receipt recording; acceptance at/after deadline fails. Final sleep is min(5, remaining), and all elapsed overhead consumes the absolute deadline.",
    "prep_left now subtracts current time from inherited PREP_DEADLINE.",
    "Exact whole-line nonce-count/rejection code, authorizer checks outside handoff_await, ordinary ABORT versus cleanup behavior, and native containment implementation remain unchanged."
  ],
  "controls": "Exclusive, preserved output root; pinned original r5; extracted actual function/initialization source saved and hashed per arm. Deterministic r5 counterexamples and r6 qualifications cover common cap, preparation/experiment deadlines, pre-/post-GO cleanup reserve, request clamp, scheduling/check/record overhead, exact/late receipt boundaries, duplicate/mismatched/substring nonce rejection, ordinary/cleanup ABORT, actual on_signal handler with host cleanup replaced solely by extracted handoff wait, missing configuration, inherited/missing/malformed/expired preparation interface. Includes a small real-clock actual-function wait smoke. No driver top-level, product, launcher, keys, firewall/provider, field home, or field process is exercised.",
  "verification": "No controls, parse commands, tests, formatters, builds, or field commands run, per assignment. Main must execute invocation after both slices settle. The edit tool automatically issued one suspect syntax warning near comment line4 after the first patch; touched regions were reread and intact, tool issue reported. Later edit emitted no such warning, but this is not claimed as Bash parse proof.",
  "interface": "No unresolved design question. Main supplies/fills final six configuration slots and inherited preparation epoch/deadline, then freezes configured driver SHA. Control --output-root parent must exist and destination must not exist; no reused output is cleared."
}