.github/ci/push-main-unit-reuse-selftest.py:17: "unit_reuse", Path(__file__).with_name("push-main-unit-reuse.py")) .github/ci/push-main-unit-reuse-selftest.py:56:# [unit->REQ-CI-PUSH-MAIN-UNIT-REUSE] .github/ci/push-main-unit-reuse-selftest.py:103: self.assertEqual(self.invoke({}, True, "not-push-main", env), []) .github/ci/push-main-unit-reuse.py:110:# [impl->REQ-CI-PUSH-MAIN-UNIT-REUSE] .github/ci/push-main-unit-reuse.py:113: return True, "not-push-main" .github/ci/reaper-breadcrumb-census.ps1:47: # flow — the exact shape the fix spec's file list was drawn from). .github/workflows/ci.yml:64: - name: Self-test push-main unit reuse .github/workflows/ci.yml:65: run: python3 .github/ci/push-main-unit-reuse-selftest.py .github/workflows/ci.yml:66: # [impl->REQ-CI-PUSH-MAIN-UNIT-REUSE] .github/workflows/ci.yml:73: if ! python3 .github/ci/push-main-unit-reuse.py; then .github/workflows/ci.yml:98: # [impl->REQ-CI-PUSH-MAIN-UNIT-REUSE] CONTEXT.md:169:**capability declaration** — which endpoint types a harness/node can host (a Pi node might host only Shells, never a LiveAgent). Static manifest list, consumed by the subnet registry GATE-W2-272-CHECKLIST.md:35: tested == merged (run 34090992646 5/5), post-land push run 34095728691. W2 rebases onto ff4b405d GATE-W2-272-CHECKLIST.md:331: merged, run 34090992646 5/5) → post-land push run both boxes ~20 min → W2 PR opens, queues behind. GATE-W2-272-CHECKLIST.md:586:## 2026-09-08 08:08Z — RESUME after across-commune (main=bccfaee8). ci push run 34201369312 on bccfaee8: traceability/changes/Windows unit/Linux unit/lint ALL SUCCESS (P GATE-W2-272-CHECKLIST.md:671:## 17:58:46Z -- LANE 3 WINDOWS GREEN (hertz .spt-lane1/p2 at e4444413 on 110c7c4c, pushed --force-with-lease from 17443615): helper 2.176 s (was 63.4 s), not-ready 1 (was GATE-W2-272-CHECKLIST.md:672:## 18:07:52Z -- LANE 3 LANDED: test/twohost-web-per-cell-identity @ e4444413 -> main by ff-push (PR #205 MERGED, mergeCommit == e4444413 == origin/main). My gate .spt-gate GATE-W2-272-CHECKLIST.md:684:## 19:54:28Z -- r2 TWOHOST-B RED, MECHANISM = STARVED PARTNER (my REST read, job 102207296960, log 81692 bytes sha256 67403f04...8030): role B built and rostered, then pol GATE-W2-272-CHECKLIST.md:827:## 10:31Z — hertz AMENDED lane RE-AUDITED clean (d32d5c4c IR-85 / 44c6ecd9 IR-86..89 / 88701366 ledger on b66a9612; +317 -1; added lines 0 x IR-79..82, 0 x NEEDS-OPERATO GATE-W2-272-CHECKLIST.md:829:## 10:34Z — hertz register lane PUSHED: origin docs/ir85-89-register = 88701366 (tree 192498f6, chain d32d5c4c -> 44c6ecd9 -> 88701366 on b66a9612, +317 -1) verified by GATE-W2-272-CHECKLIST.md:830:## 10:37Z — PR #207 LANDED ff-only: thin run 34340894990 att1 SUCCESS at 88701366 (docs-only shape, kitsubito-only), guarded push (run head == object, origin/main == b66 GATE-W2-272-CHECKLIST.md:833:## 10:59Z — CO-TENANT ATTRIBUTED, MINE: hertz measured two GitHub unit jobs on hfenduleam through his window. Mechanism (ci.yml classify :49): every NON-pull_request eve GATE-W2-272-CHECKLIST.md:836:## 11:06Z — CARGO CLEAR sent to todlando (153.19 GiB, box idle, window closed): bin cell first, then commit 2. hertz ruled: IR-90 (rig-start free-space guard that refuse GATE-W2-272-CHECKLIST.md:850:## 12:06Z — PR #208 thin run 34347531875 att1: LINUX UNIT FAILED (step 6, 11:51:43-11:55:08): spt::bin/spt wansend::tests::wan_send_ships_to_the_resolved_node panicked w GATE-W2-272-CHECKLIST.md:859:## 13:05Z — hertz IR-90 lane PR #210 = 5888c5de on 5a50e625 (+99 -0 docs/INFRA-REGISTER.md; thin run 34354516836 green docs-only). Audits: IR-90 heading x1, no IR-9[1-9] GATE-W2-272-CHECKLIST.md:860:## 13:08Z — PR #210 LANDED ff-only: 46e12676 (amended in place from 5888c5de; bullet 1 = run 34337797758 CANCELLED at the 40-min wall, cancel string once in IR-90 with t GATE-W2-272-CHECKLIST.md:876:## 14:33Z — PR #211 LANDED ff-only: run 34361733081 five/five green at 7d2f0d70 (Windows unit completed ~14:31Z); guarded push (run headSha == 7d2f0d70 full + conclusion GATE-W2-272-CHECKLIST.md:877:## 14:44Z — PR #212 (hertz, chore/spt-scratch-ignore, 54d7b122 on 7d2f0d70, 8 files +663 -3) READ IN FULL: R100 x2 (tracked pair, blob-identical per his two-layer check: GATE-W2-272-CHECKLIST.md:879:## 15:19Z — PR #212 LANDED ff-only: run 34365591875 five/five green at b0b67aaa (Windows unit 14:52:50-15:12:33Z); guarded push (run headSha == b0b67aaa full + success, GATE-W2-272-CHECKLIST.md:884:## 16:06Z — PR #213 LANDED ff-only: run 34372095878 five/five green at 2037bcb8 (Windows unit 15:46-16:04:29Z); guarded push (run headSha == 2037bcb8 full + success, ori GATE-W2-272-CHECKLIST.md:887:## 16:49Z — PR #214 LANDED ff-only: run 34376092990 five/five green at de5a44bc (Windows unit 16:27-16:47:01Z); guarded push (run headSha == full sha + success, origin/m GATE-W2-272-CHECKLIST.md:900:## 23:40Z — IR-92 FILED: d8e9c5f0 on docs/ir92-inject-leg-unobserved, PR #215 (docs-only; ff to main deferred -- a main push runs unit on both runners). Blob LF 5331 / C MESH-D5-PLAN.md:18:So: **gate on `RosterStore::is_member(subnet, origin)`, loaded fresh per gate call** — the exact shape the gates already use for `TrustStore::is_trusted` (each `*Policy::load()` l RCA-274-R1-LINUX.md:31:- **Same-sha rerun** of the failed job(s) via `gh run rerun --failed` once the run is TERMINAL (`--json status` first — rerun refuses in flight and fails toward a false "permi RESTORATION-D2-PLAN.md:6:> cross-OS CI-green on main (0c95435). RESTORATION-D3-PLAN.md:5:> D2 (loop relocation) are DONE + cross-OS CI-green on main (7398d7c). This is RESTORATION-D4-PLAN.md:5:> trigger) are DONE + cross-OS CI-green on main (348a739). D3-3 made `apply` RESTORATION-D5-PLAN.md:6:> retired) are DONE + cross-OS CI-green on main (@3055eb7). The brain the RESTORATION-D6-PLAN.md:12:> CI-green on main (@2ba4fd7). The broker now owns the brain supervisor RESTORATION-D7-PLAN.md:9:> cross-OS CI-green on main @ad15a1e. D7 adds **no new daemon capability** — it is RESTORATION-D7-PLAN.md:25:> are DONE + cross-OS CI-green on main (@ad15a1e). The broker is the always-up V032-PLAN.md:37:## Verification (the real cross-platform test — the bug's exact shape) docs/GOLDEN-CI.md:9:Pushing the assembled `golden/**` branch starts the full suite, including both coordinated two-host jobs. `workflow_dispatch` is the explicit rerun/manual avenue and must target th docs/GOLDEN-CI.md:11:## Push-main unit evidence reuse docs/GOLDEN-CI.md:13: docs/GOLDEN-CI.md:18:to `false`, through `.github/ci/push-main-unit-reuse.py`. PR classification and docs/GOLDEN-CI.md:55:`python3 .github/ci/push-main-unit-reuse-selftest.py` (also a changes-job docs/GOLDEN-CI.md:58:first real post-merge run**. A qualifying push must show the exact PR proof docs/INFRA-REGISTER.md:68:03:02:33Z** (post-merge run 34556292801, unit job `FLOOR_END`, RED against the docs/INFRA-REGISTER.md:73:**247,894,224,896 bytes at 08:39:20Z** (hertz, GetDiskFreeSpaceExW, during post-merge run docs/INFRA-REGISTER.md:82:runner appears to purge and cold-rebuild its resident target per run. A post-merge run therefore docs/INFRA-REGISTER.md:85:Third sample, post-merge run 34580045779 on `b12d4619` (GREEN): `FLOOR_START` 249,872,142,336 at docs/INFRA-REGISTER.md:1175: the classifier to pushes leaves a docs-only main TIP with no run of its own — fine if docs/INFRA-REGISTER.md:1177: not fine if any gate or reader takes "main tip has a green run" as the check. One person reads docs/INFRA-REGISTER.md:1182: it for main pushes. Main-tip evidence remains full by design; no classifier docs/INFRA-REGISTER.md:1233: produced the four-name shape (ruled sha == main tip == golden ref == tag == `c62904e7`, docs/INFRA-REGISTER.md:1992: STARTS the automatic post-merge ci run on the same box** (hertz, measured to the second: docs/INFRA-REGISTER.md:1994: the box empties after the POST-MERGE run, not after the golden; the box has a fourth actor no docs/INFRA-REGISTER.md:1996: must gate on `gh run view --json jobs` of the post-merge run before any timing-sensitive work. docs/INFRA-REGISTER.md:5144: (post-merge on main @ `e4444413`) the second the golden test job released it at 19:31:56Z. docs/INFRA-REGISTER.md:5171: daemon-hosted responder`. The origin case (2026-09-08) was a post-merge push on `main`: a run docs/INFRA-REGISTER.md:5344: green thin run says the code builds and nothing about the steps. The wall times above are the field docs/INFRA-REGISTER.md:6971:- **Instance 2 — a DIFFERENT tool surface, 2026-09-12 03:39Z (hertz).** The mechanism is not a property of todlando's guard. hertz ran a recursive `grep -rl` over the pro docs/INFRA-REGISTER.md:7227:- **Rule.** Before authorizing local cargo while a runner leg is in flight, read the leg's uncontended wall from its last green run and compare to its `timeout-minutes`; ov docs/INFRA-REGISTER.md:7228:- **Third instance, non-agent contender (doyle, 2026-09-18 12:07Z).** Post-merge `ci` `35339675565` (main @71165e35) Windows unit CANCELLED at 40m19s with EVERY step green docs/INFRA-REGISTER.md:7237:- **Measured.** PR run [`35990810517`](https://github.com/BigscreenVR/spt-bs-core/actions/runs/35990810517) at `b4490c4f`: `changes` code=false ⇒ **`unit` and `lint` SKIP docs/INFRA-REGISTER.md:7240:- **Ripe when:** `ci.yml`'s `changes` job is next touched, or the next docs-only lane is about to land; hertz CI lane, small. **Acceptance:** one post-merge run record for docs/INFRA-REGISTER.md:7276:### IR-144 — a push-main `ci` run re-tests the exact sha whose pull_request run just went green, costing ~35 min of hfenduleam per ff-only merge docs/INFRA-REGISTER.md:7281: two real post-merge scheduler observations below discharge acceptance. docs/INFRA-REGISTER.md:7283: (15:24Z), then push run `35362584091` re-ran unit on both boxes (15:28–16:31Z); docs/INFRA-REGISTER.md:7284: `629e33e1` PR run `35362720511` success 5/5 (16:05Z), then push run docs/INFRA-REGISTER.md:7291:- **Mechanism.** ff-only main can re-present the exact SHA of a successful PR run. That identity is necessary, not sufficient: the original candidate's single green check c docs/INFRA-REGISTER.md:7292:- **Implementation (hertz lane).** `changes` keeps `code` and adds default-true `run-unit`; only push `refs/heads/main` with exact PR proof may turn it false. `.github/ci/p docs/INFRA-REGISTER.md:7294: docs/INFRA-REGISTER.md:7298: and exact SHA below. Each source `pull_request` run's numbered attempt contains docs/INFRA-REGISTER.md:7301: | Push-main run | Exact head SHA | Source PR run / attempt | Observed scheduler unit record | docs/INFRA-REGISTER.md:7312: That [push run](https://github.com/BigscreenVR/spt-bs-core/actions/runs/35400571953) docs/INFRA-REGISTER.md:7314: unit `105779407831`. The two successor push-main runs above demonstrate the new docs/REGISTRY-LIFECYCLE-TRIAGE.md:48: O(chunks × record-kinds). Attention-shift side effects fire once, post-merge. docs/RELEASE-RUNBOOK.md:111: construction — ruled sha == main tip == golden ref == tag, one object with docs/RELEASE-RUNBOOK.md:198: INSTANT, not a reservation. Post-merge `ci` runs, other lanes' pools and the docs/RELEASE-RUNBOOK.md:206:**The push run IS the golden run.** Pushing the head to `golden/**` runs the docs/RELEASE-RUNBOOK.md:220:property held; the citation had already rotted). Pin the push run's id at push time docs/RELEASE-RUNBOOK.md:526: If this thin run reds at a SHA whose golden run is green, that is a docs/RELEASE-RUNBOOK.md:599: be terminal. This wait is about **box occupancy**, not the thin run blessing docs/TWO-HOST-RUNBOOK.md:72:Both rig hosts are the repo's self-hosted runners, so one tagged push runs both legs: docs/adr/0050-golden-ci-merge-integration.md:53:The omission became visible because the release driver published his exact commands for review before running them: his first step fast-forwarded only a