todlando -> doyle. RESIDUAL CLEANUP: pid 52608 TERMINATED AND VERIFIED ABSENT. Three of your four post-checks pass. The fourth is BLOCKED on a hung instrument and I am not filling the gap with an assumption. REVALIDATION BEFORE ACTING, all four immediately before the stop, at 20:48:04Z: CreationUTC 2026-09-12T20:29:39Z -- EXACT match to the authorized value ExecutablePath C:\Users\decid\Documents\projects\spt-core\.worktrees\304-w2-repr\target\release\spt.exe -- match CommandLine "...\target\release\spt.exe daemon run --detached" -- the expected shape Association with THIS run's isolated home: fp-home/daemon.pid reads 52608, AND the daemon's own self-written stderr header reads "=== spt broker stderr — generation 0 — pid 52608 ===". Negative control: that log names 4732 ZERO times, so the header is identifying rather than matching anything. Nothing differed, so I acted under your authorization and not past it. ACTION: Stop-Process -Id 52608, single process. No tree kill, no guard bypass, nothing aimed at 4732. POST-CHECKS: 1. 52608 ABSENT. Positive control alongside it: 4732 alive, so the probe can still find a live pid and the absence is measured rather than a dead check. 2. 29470 CLEAR, nothing bound. 3. SOMETHING YOU DID NOT KNOW ABOUT, and I did not touch it: the rig home had a SECOND live process -- the brain, pid 53496, same worktree exe, same 20:29:39Z creation, "daemon brain --generation 0 --start-reason cold". It was outside your authorization so I left it alone and was prepared to bring it back to you. After the broker stopped it EXITED ON ITS OWN. Measured absent, not assumed, and not killed by me. 4. 5470 POST-STATE: NOT ESTABLISHED. BLOCKER. I re-ran the driver's own portfields.ps1 against 5470 for comparability; it has produced a ZERO-BYTE output and has been running four minutes. I am explicitly NOT reading that empty file as "unchanged" -- an unelevated firewall census returning nothing is the known clean-zero trap, and treating it as equality is exactly the fabrication it produces. What IS measured: the driver's own final-post-cleanup guard diff at 20:45:13Z was EMPTY, i.e. equal to its baseline, taken after teardown. That is the last real reading of 5470 and it predates the kill by three minutes. My reasoning that the kill should not have touched 5470 -- teardown already verified LAN_FIREWALL_CLEAN with the owned named rules measured absent, and stopping a daemon writes no firewall rules -- is REASONING, not a measurement, and I am labelling it as such rather than reporting it as a result. Tell me whether you want the 5470 re-measurement pursued (a different instrument, or elevated, either of which is a new action I do not have), or whether the 20:45:13Z reading closes it. I am taking no further action meanwhile: no broader termination, no new field run, nothing elevated.