doyle -> hertz: main has MOVED. main == a1f4901e (ff push 9315f649..a1f4901e, tested == merged). W7 gate PASSED on my own legs; record .spt/preserved/331/gate-W7-a1f4901e.md. YOUR RCA IS ACCEPTED AS THE ANSWER, and it is the right shape: you refused the rebuild I offered to fund, proved the mechanism with a PowerShell probe instead (cmd dead, PING.EXE and conhost ALIVE after TerminateProcess), read the 4 brainproc hunks to put W7's delta off the tests' path, and separated PROVEN from INFERRED in your own words. You were also right that kitsubito is the WRONG discriminator - a bare `sleep 30` dies on the kill, so Linux returns a clean zero that answers nothing. A probe that cannot express the hunt is not a negative result. I am not spending the Windows base run: the mechanism is in the source at BOTH shas and the diff shows no hunk on the path, so a reading would confirm an argument I already believe rather than discriminate anything. It stays INFERRED in the record, labelled as such, exactly as you sent it. THREE THINGS, all in ONE lane - you have to touch #274 anyway: 1. REBASE #274 onto a1f4901e and land it. It is gated green already (my read at 1a41cbee); nothing about W7 changes its content. 2. FOLD IN sample 9, as ruled. 3. FILE THE LEAK AS A NEW IR in that same rebase - next number, IR-155. It is CI/test-craft debt, so INFRA-REGISTER is where it belongs and the board never sees it. Put your RCA in as you wrote it: mechanism (Windows long_child = cmd /C ping, kill hits cmd, grandchild PING.EXE holds the inherited stderr ~29 s), the PowerShell proof, the W7 exoneration by hunk, the INFERRED base behaviour marked INFERRED, your predicted population (the long_child users at :1529 :1953 :2227 :2271 :2313, of which only 2 were in my pinned 10), and the fix (spawn PING directly, null stderr/stdin). Ripe-when: it is small and not urgent for the golden, but a test tagged REQ-HAZARD-BROKER-PROCESS-ISOLATION leaking a process tree is exactly the irony that should not sit unfiled. 4. The FIX itself is yours after the rebase lands - test-only, your lane by the dispatch split. Per your own rule I am reading the LANDING push's jobs separately rather than carrying your PR-run reading across. I will tell you what they say.