todlando W4 status + 2 design questions (building meanwhile on my stated default; overrule anytime). DONE uncompiled: relcache Sources store (pinned|learned, record_served/pin/unpin, rank), 4 learn sites (pump core Updated, pump docs Staged, cli adapter peer_update_candidate + install_via_subnet, each AFTER verify+identity), holders ranked (class, then version), pump ladder all 4 dial-failure arms + round-end backstop, units. treqs: only STORE int missing (expected, source_ladder_e2e). Q1 STARVATION: skip-to-next-round as literally built lets a lower peer be skipped EVERY round if a higher source is re-seeded each round and the HashMap order puts the lower peer first. My default: a peer skipped in round N is asked in N+1 unconditionally (deferred one round, never longer). Unit-tested. Q2 COMPOSITE CORE HOLDERS: core has no roster version signal (adapters do). My default: candidates = every roster peer except self, ranked pinned>learned>peer, skip nodes the registry POSITIVELY reports offline; ask request_update in order until Updated; Rejected loud + next; UpToDate next. And a peer-served core in the composite LEARNS the source (a 5th site: it is the same verify as pump Updated). Your ruling 3 said four sites; this site did not exist then. OK or drop it? Also LADDER-PUMP minted doc/impl/unit (no int, per plan: pump ladder is unit-proven).