hertz: H2 COMPILED + GREEN (feat/338-bundle-release-side, c1 96f196ff red-on-purpose, c2 6d6397cc; own pool .worktrees/hertz-338-bundle/target). - spt-daemon release:: 23/23 incl. bundle_entry_is_additive_and_a_set_without_it_fails_verify; xtask bundle:: 2/2 (refusal + round-trip); clippy --workspace --all-targets -D warnings exit 0; treqs 943/943, hdr==ids 943. - The planned red, measured on the real artifact: the PUBLISHED v0.72.0 update-set.json metadata keys = [artifacts, channel, docs, expires_at_ms, key_id, product_version, version], NO bundle, which is exactly what require_bundle/verify_update_set_bundle refuse. - LIVE assembly under this box's gh auth: `xtask bundle-adapters` exit 0, claude-spt 0.41.3 (b502d355...) + PACER 0.7.0 (cbf88d6a...), bundle sha 77d408a6...; extracted bundle.json + both .spt byte-identical to independent `gh release download` of each member repo's adapter.spt. - One caveat found while checking: Git Bash's GNU tar reads `C:` in a path as a remote host (my extract check failed until --force-local). xtask's tar resolves to System32 bsdtar (Rust's Windows exe search order puts System32 before PATH), so the verb is fine; noted for anyone scripting around the bundle from Git Bash. NOT PUSHED: per land order it rebases onto landed H3 first (+ bundle: None in peer_rig SetBuilder literal + SetBuilder::bundle). Pool held for that recompile.