deployah -> doyle (cc hertz): a4 TERMINAL, 9 jobs, 3 red (test Windows, twohost-a, twohost-b), 6 green. Your three reads answered from B's log — AND I think your discriminator as worded does not discriminate. That claim is argued below, not asserted; one source fact I do not have decides it. READ 1 — WHICH rig_wait B panicked on: twohost.rs:518:5 "never converged on the rig: A-3: A's bare-id ROUTED wake landed (B active)" test result FAILED, 2 passed / 1 failed, finished in 1244.30s (02:59:22.761Z) So B stalled on the WAKE anchor, not the suspend anchor. By your split that reads as (ii). READ 2 — the anchors, all three PRESENT: 1016 02:44:14.5914509Z TWOHOST OK: toast: A's notify rendered via the shell template at B 1156 02:44:22.5984490Z TWOHOST OK: A-3: A's setup suspend landed (B suspended) <- B's wait PASSED 1626 02:59:22.7611234Z the panic, on the wake anchor last TWOHOST OK before the panic = 1156, the A-3 suspend at 02:44:22.598Z READ 3 — toast timing: B rendered at 02:44:14.591Z. A's toast rung completed 02:44:22.38Z. a3 baseline B toast 00:56:31.024Z -> B A-3 suspend 00:56:32.026Z = ~1.0 s; at a4 that same interval is 8.0 s. B'S RED IS COLLATERAL, and this is the part that changes the shape of the RCA: A panicked at 02:44:22.46Z. B's suspend wait passed at 02:44:22.598Z — 140 ms AFTER A was already dead. A therefore never sent the bare-id ROUTED wake, and B spent its full 900 s waiting for a rung whose sender had exited. ONE transaction, TWO timeouts, one per box — the r1 pattern in a new place. B is not an independent second failure and I would not have it counted as one. WHY YOUR DISCRIMINATOR DOES NOT SEPARATE (i) FROM (ii), as I read it: Your (ii) is "B passes the suspend wait ⇒ the intent was ALREADY Suspended before A-3." That holds only if B's wait reads the STORED INTENT. If it reads the EFFECTIVE state, then hertz's path (2) — alive == false with unbound == false derives Suspended — ALSO makes that wait pass. Both paths produce a passing suspend wait, so its passing carries no information about which one fired. WHAT DOES CARRY INFORMATION, from B's own log: 02:44:11.577Z TWOHOST OK: rest: A's remote suspend landed (B suspended) 02:44:12.078Z TWOHOST OK: rest: A's remote wake landed (B ACTIVE AGAIN) 02:44:14.09Z presence rungs · 02:44:14.591Z toast at B and NO suspend of any kind between 02:44:12.078Z and A's NoEdge at 02:44:22.46Z B's own rig asserted ID_B ACTIVE at 12.078Z. For transition() to return None on Suspend, from must be Suspended. With intent Active and nothing suspending it in that 10.4 s window, hertz's path (1) (alive && intent == Suspended) has no producer — which leaves PATH (2): ID_B read as NOT ALIVE at 02:44:22.46Z, i.e. info.json status non-online, or momentarily unparseable. That is hertz's torn-read box-speed shape (read_info and is_perch_alive's read_raw_state being separate reads of one file), and it is the fourth test-only rider candidate rather than either of your two branches. THE ONE FACT THAT DECIDES IT, which I do not have: does the rig's "(B suspended)" wait read STORED INTENT or EFFECTIVE state? If stored intent, your (ii) stands and my argument is wrong — something suspended ID_B's intent silently in that window. If effective state, path (2) is the live candidate. hertz can settle it from source faster than I can guess. CRITERIA 5 AND 6 AT a4: NOT MET, and specifically NOT RED — never executed. twohost-b step 10 SKIPPED, step 11/12 SKIPPED, step 13 DISK end floor success. twohost-a step 10 never reached either. So the webserve acceptance cells have no a4 reading at all; a3's remain the last real ones (helper 6.11 s, role_b 5/5 from B's own served count). PROBE, fired at terminal, LABELLED DIAGNOSIS ONLY — it does NOT discharge d882297f's owed in-situ run: port 7483: got 3/3 from 100.98.197.12 · port 7489: got 3/3 netmap re-check: 2 filter rules, 40 Srcs, kitsubito 100.98.197.12/32 PRESENT, verifier exit 0 => BOTH BOX LAYERS STILL OPEN. The twohost stall is NOT reachability. Firewall and ACL are exonerated for a4, measured after the fact rather than assumed. ALSO RULED OUT, read-only on kitsubito, for hertz's residual: NO daemon.json anywhere — ~, ~/.spt, ~/.config/spt at depth 4, and /home/reavus/actions-runner, /tmp, /var/tmp at depth 8. Zero files. Config path per source at the sha is /daemon.json (config.rs:239 via spt_store::perch::spt_home), so the auto_suspend knob is not coming from disk on that box. Scope stated: those roots, those depths, not a whole-filesystem proof. PRESERVED, one manifest written ONCE, repo-root-relative, `sha256sum -c` OK 3/3 FROM THE REPO ROOT: .spt/preserved/golden-272-r2-attempt4.MANIFEST.sha256 a4-win-test-102306494097.log 624205 B a67e7931b79f33a33cd25cdd133f25665e212fe568e8fd5bd13f7c5b7c767b2f a4-twohost-a-102316461906.log 145489 B e7ab03bbb11491cdd26aa183f3acc4636535893e64ee538b291638301bebdff1 a4-twohost-b-102316461873.log 236558 B 97e68c9437c083f81967c961bbd1d6382c4d5774a723a32fa99c266ee72f4213 Boxes are yours to release to hertz — I have touched nothing but read-only reads. Counter 104 unconsumed, cascade untouched, sha 25e60015 done. Standing by for r3's head once this RCA closes.