# v0.68.0 post-green cascade (staged 2026-09-08, deployah)
RULED SHA = 25e6001585ed0cd495a72c7634dded9dd207bdae
COUNTER   = 104   (v0.67.1 metadata decoded version: 103)
GOLDEN r2 = run 34262154550, branch golden/webserve-272-r2

## 0. Verdict (before anything)
- Release word = run.status==completed AND every listed job terminal. EXPECT NINE jobs.
  (six listed early; both twohost legs + `notify` materialize late — a job list read
   early is NOT the run's job set.)
- ACCEPTANCE: 4 e2e consumers green on BOTH test legs (poll_envelope, quickstart,
  gateway, io_events relay_backlog); two_host_web_helper_role_a green on A AND
  two_host_web_role_b green on B READ FROM B'S SERVED COUNT, not A's poll.
- RED -> preserve job logs + checksums, name mechanism AT SOURCE, hand to doyle.
  No rate argument. No same-sha rerun.
- GREEN -> verdict comment on releases#272 (alchemy-0 shell send, positional body).

## 1. Advance main ff-only (BEFORE tag)
git fetch origin main && git switch main && git merge --ff-only 25e60015 \
  && git push origin main && git merge-base --is-ancestor 25e60015 origin/main
Fires thin ci.yml at the same sha. NOT a separate authority — wait for it as
BOX OCCUPANCY only. Thin red at a golden-green sha = contradiction -> gater ruling,
not auto-block, not waved through.

## 2. Tag — RULED SHA EXPLICITLY, never bare HEAD
git tag v0.68.0 25e6001585ed0cd495a72c7634dded9dd207bdae && git push origin v0.68.0
Then MEASURE both before/after:
  git rev-list -n 1 v0.68.0 ; git rev-parse origin/main
Fires release.yml ONLY (docs-publish.yml is RETIRED — do not wait for it).
Draft must carry SEVEN assets: spt-x86_64-linux, -linux-musl, -windows.exe,
SHA256SUMS, manifest.schema.json, mock-adapter.zip, spt-docs.tar.gz.

## 3. STEP 6 FIRST HALF — pre-publish, DRIVEN not swept
spt shell cmd alchemy-0 state 272 acceptance
Golden CI closes no individual request, so the sweep finds nothing. The MILESTONE's
own close must land PRE-publish too (hub card buckets STRICTLY on closedAt).

## 4. Publish (quiet window: golden + thin ci + release.yml all terminal)
On HFENDULEAM run WITHOUT SPT_RELEASE_SEED_CMD (machine-scope SPT_RELEASE_SEED,
operator-ruled permanent; _CMD double-decodes hex and panics). Do NOT re-escalate.
  cargo run -p xtask -- release-publish --tag v0.68.0 --key-id rel-primary-2026 --version 104
Attribute any live cargo/rustc by PARENT CHAIN ROOT: RunnerService/Runner.Worker =
CI axis (counted); rooted at a user shell = real contention, blocks signing.

## 5. STEP 6 SECOND HALF — POST-publish. THE STRADDLE THAT WAS MISSED AT v0.67.0.
spt shell cmd alchemy-0 release v0.68.0
Promotes DONE + posts the Shipped Requests roundup. Publish does NOT discharge step 6.
Every other check passes with the board unfinished. TICK THE HALVES SEPARATELY.

## 6. Verify Latest / update-set flip, then drop the counter.

## 7. Teardown: PRESERVE FIRST (named owner, path+hash, restore cost stated),
release/reap SECOND as a separate message gated on that confirmation.
Shape rig .worktrees/shape-0680, pool ./target lane shape-0680-r2.

# ================= AMENDMENT, deployah 2026-09-08 ~23:5xZ =================
# This file is now the OPERATIVE copy (migrated byte-identical from the 34eee87f session
# scratchpad, which belongs to a cleared session and can be reaped out from under the release).
# Two gaps found by auditing the file against the r2 ruling. Both would have bitten at drive time.

## GAP 1 — section 0's ACCEPTANCE list is INCOMPLETE and would pass a run that never
## proved the thing r2 exists to prove. It names only the 4 e2e consumers + the twohost pair.
## THE AUTHORITATIVE LIST IS SEVEN (RERUN-GATE.md, doyle, unchanged):
##   1. FLOOR_DOCS verdict = PASS
##   2. step 'Docs drift gate (CLI ref + llms links) — windows' = success   <-- ABSENT FROM S0
##   3. FLOOR_END verdict = PASS                                            <-- ABSENT FROM S0
##   4. Summary lines == 2                                                  <-- ABSENT FROM S0
##   5. two_host_web_helper_role_a green on A
##   6. two_host_web_role_b green on B, FROM B'S OWN SERVED COUNT
##   7. run terminal, EVERY job green (expect NINE)
## Criterion 2 is the dangerous one: the Windows docs-drift gate has NEVER run at this sha —
## SKIPPED THREE TIMES now (r2 attempt 1 behind the floor red; attempt 2 behind Phase B's
## failure at step 21; and it is gated behind Phase B, so it cannot run until Phase B is green).
## A THIRD/FOURTH SKIP IS NOT A PASS. The axis is per-OS because it diffs the WINDOWS binary's
## own --help; a green Linux docs gate is NOT Windows evidence. Read the STEP's conclusion,
## never the job's.

## GAP 2 — section 0 says "No rate argument. No same-sha rerun." That was true when staged and
## is now SUPERSEDED for this run only. doyle authorized (a) ONE rate rerun for the
## webserve_attachment_e2e ttl cell, and (b) a repaired-mechanism rerun of the twohost pair once
## the inbound path is open. Both ride ONE `gh run rerun 34262154550 --failed`. Still no THIRD
## attempt at this sha: if the ttl cell reds again, STOP — hertz's deterministic repin goes on a
## new head with a full golden.

## CURRENT BLOCKER (not in the original file at all): the run cannot go green until kitsubito can
## reach hfenduleam on the rig's ports. TWO layers, both measured:
##   L1 Windows Firewall inbound — DONE. Operator applied "spt-ci two-host rig UDP-In (kitsubito
##      only)": Enabled Yes, In, UDP, LocalPort 7460-7499, RemoteIP 100.98.197.12/32, all profiles.
##      Verified on the box BY FILTER (a name grep for 'twohost' misses it — it is 'two-host').
##   L2 tailnet ACL — OPEN, operator-owned, the current hold. hfenduleam's netmap has ONE
##      PacketFilter rule, Srcs = 18 entries (9 v4 + 9 v6), Dsts 0.0.0.0/0/::0 all ports,
##      IPProto [6,17,1,58]; 100.98.197.12 ABSENT. Near-misses 100.98.213.33 / 100.98.214.87 are
##      the same /16 and read as PRESENT on an eyeball — they are not kitsubito. The grant is
##      SOURCE-scoped, not port-scoped, which is why TCP timed out beside UDP.
## VERIFY-AFTER-GRANT (mine, no elevation needed): 100.98.197.12/32 appears in `tailscale debug
## netmap` Srcs (field is `Srcs` — NOT SrcIPs; an empty extraction printed "ABSENT" once already
## and that verdict was vacuous). Then doyle's Tailscale re-probe must read 3/3 BEFORE my gates.

## ORDER, unchanged after that: five gates -> ONE rerun-failed -> seven acceptance criteria ->
## sections 1..7 of this file, with the STEP 6 STRADDLE ticked as two separate halves.

## PRE-FLIGHT MEASURED 2026-09-08 23:5xZ (deployah, read-only, while held on the ACL grant)
All clean — none of these can surprise us at drive time now.
  SPT_RELEASE_SEED (Machine)     : PRESENT, length 64, matches ^[0-9a-fA-F]{64}$  (value never printed)
  SPT_RELEASE_SEED_CMD (Machine) : absent  <- REQUIRED absent on this box (hex double-decode panic)
  SPT_RELEASE_SEED_CMD (Process) : absent  <- checked too; a process-scope leak would panic identically
  tag v0.68.0 local              : does not exist
  tag v0.68.0 on origin          : does not exist  (git ls-remote --tags -> empty)
  ruled sha ancestor of origin/main : NO — the step-1 ff-only merge is genuinely still pending
  origin/main head               : e44444136dc4eacf07516531ee3b8604f933498c
                                   (the same sha the interfering thin `ci` 34261096301 ran on — consistent)
  refs/heads/golden/webserve-272-r2 : 25e6001585ed0cd495a72c7634dded9dd207bdae — MATCHES the ruled sha
Deliberately NOT pre-flighted: any cargo build (xtask included). Building now would occupy the box
and the pool that CI needs for the rerun, and a warm xtask is worth less than a quiet runner.

## STAGED VERIFIER: r2/verify-acl-grant.ps1 — run it the moment the operator lands the ACL grant.
Exits 0 = kitsubito PRESENT in netmap Srcs (ACL open) · 1 = still absent, prints the v4 set and the
100.98/16 near-miss warning · 2 = extractor read ZERO Srcs, which is NOT absence — re-dump the shape.

## STEP 3 START STATE — RULED, doyle 2026-09-09 00:1xZ, from the GitHub LABEL TIMELINE
#272 goes GREENLIT -> ACCEPTANCE. It was NEVER WIP: BACKLOG 09-05 03:15Z -> GREENLIT 09-06 10:25Z,
nothing since. Precedent #23 (v0.67.0): GREENLIT 07-29 -> ACCEPTANCE 08-30 08:18Z -> DONE 09:28Z,
no WIP either. So `spt shell cmd alchemy-0 state 272 acceptance` is a GREENLIT->ACCEPTANCE move and
the "state: greenlit" the view renders is CORRECT — do not repair it, do not expect WIP.
(doyle's own 09-07 22:53Z comment premised WIP and was wrong on the state; superseded by his timeline
read. The AGENTS.md taxonomy lists WIP in the chain, but milestones skip it in practice — twice
measured now.)

TYPE: leave UNSET on #272. Milestones carry `kind: MILESTONE` only; `type: BUGFIX/ADDITION/CHANGE`
is request-level. #23 closed DONE with no type label. Do NOT set it.

FLAG: there is no `flag: NEEDS-OPERATOR` on #272 to clear — labeled 09-05 03:16Z, UNLABELED
09-06 10:24Z, never re-set. doyle's 09-07 "this comment is the flag" was prose, not a label.
Nothing to strip at any cascade step.

## ============ r3 SHAPE FINAL (doyle, 2026-09-09 ~03:16Z) — TEST-ONLY ============
FOUR riders on 25e60015, no product change, GREENLIT FORM OF #272 UNCHANGED (nothing dropped, nothing
added — so the intake parity check should record zero of each, and that is the EXPECTED reading, not
a formality to skip):
  88625fa0  arm 12 deterministic
  b359e40e  converge budgets derived (31 sites)
  4c7309ec  registry_lifecycle bounded-rendezvous join
  hertz r4  the FOUR wire-Edge assertions in twohost.rs accept Edge|NoEdge per resthost.rs:21-27 and
            :198-202; the WITNESS becomes the durable observable. (I corroborated both doc quotes
            verbatim at the sha, and found the durable wait ALREADY sits immediately after the assert
            on A's side — rig_wait "A-3: B advertises Suspended at A" — with B's :1368 read_rest doing
            the same, so the assert can go with ZERO coverage lost.)
TWOHOST-A RED MECHANISM (todlando, doyle spot-checked): ONE rest request served by TWO dispatcher
instances = two brain processes against B's broker. PRE-EXISTING at v0.67.0, claim path untouched by
#272, and the redelivery is INSIDE the documented at-least-once contract. Two post-publish lanes
seeded (served-path telemetry; the overlap hazard). So the product is exonerated for this release and
r3 stays test-only.

MY SEQUENCE WHEN hertz HANDS THE HEAD SHA:
  1. Intake per docs/RELEASE-RUNBOOK.md "Golden-head intake" — greenlit-form parity against #272's
     INTAKE comment of 2026-09-06T10:24:57Z (the snapshot, not a reconstruction); any dropped/added
     request needs a reason comment ON THE ISSUE before golden runs, and a dropped one must also be
     relocated or moved back to eval. NONE EXPECTED — record zero/zero explicitly.
  2. Release-shape check at the assembled head (IR-54): read Cargo.toml's first version line and
     CHANGELOG.md's first heading AT THE SHA before assuming; author version material on top if the
     head is unshaped, as at r1 and r2.
  3. Golden r3 on the shaped sha, run id pinned by FULL sha at push time.
  4. Dispatch preconditions AS FOR a4: census 0 both boxes (parent-chain-root attribution on
     hfenduleam, ssh census on kitsubito), free >= 110 GiB, runner quiet, foreign queue 0, ACL meter
     verified by my own netmap read, Defender line printed VERBATIM (it is a record line, not a gate).
     Gate script: r2/gate3-dispatch.ps1 — REMEMBER to repoint $RUN to the NEW run id; it defaults to
     34262154550 which is now a DEAD run.
  5. Then this file's sections 1..7, with the STEP 6 STRADDLE ticked as two separate halves and
     step 3 starting from GREENLIT (never WIP).
Counter STILL 104, unconsumed — nothing was published from r1, r2 or any a-attempt.

# ===== r3 HEAD RULED + INTAKE CLOSED (deployah 2026-09-09 ~03:38Z) =====
HEAD = c4919243. Chain linear on 25e60015: afb711c9 -> 3f683357 -> 73e3f59b -> c4919243,
4 commits, ZERO merges, trailers 4/4 "Co-authored by: hertz" (raw body read).
Head arrives SHAPED — Cargo.toml 0.68.0, CHANGELOG "## [0.68.0]". NO version material owed from me;
the sha hertz names IS the sha golden runs on and the sha that gets tagged. (Unlike r1 and r2.)
INTAKE CLOSED by doyle at this head: zero dropped / zero added, gates nothing. Full record and every
measurement in r2/INTAKE-BASELINE-272.md.
NOTE the run-id repoint burden is GONE: gate3-dispatch.ps1 now takes -Run and -Sha as MANDATORY
params (the dead-r2-run default is removed; it used to PASS gate 1 about the wrong run). Pass the
FULL 40-char sha.

## >>> CARRY INTO THE RELEASE CLOSE NOTE — doyle-ruled 2026-09-09, one line, do not drop it:
##   "heading dated 09-08, tagged 09-09Z, left to keep the proven tree"
## Rationale, so the next reader does not rediscover it as a defect: the CHANGELOG heading reads
## 2026-09-08 while the tag lands 2026-09-09Z. Precedent is that the heading tracks the tag's UTC
## date (v0.67.1 dated 09-06/tagged 09-06Z; v0.67.0 dated 08-30/tagged 08-30Z), so this DEVIATES —
## deliberately. Editing the date would move a proven chain, re-bind every clippy/cell proof to a
## new tree, and tested-sha == shipped-sha forbids fixing it once golden opens. The runbook checks
## the VERSION in the heading, not the date, so no checked leg is violated. Deliberate, not missed.
