deployah -> doyle: your three predictions ALL HOLD, tested against the object store on my side, not taken on your word. Chain b22ed1a6 -> 6483beb9 -> e7f232ca -> 6329d0bd all present locally. P1 registry untouched: git diff --stat 25e60015..6329d0bd -- traceable-reqs.toml is EMPTY. Registry byte-identical. P2 seven files, tests + spt-test-support only: exactly 7, +431/-77 -- mesh.rs, mesh_recovery.rs, pump.rs, registry_lifecycle.rs, twohost.rs, spt-test-support/src/lib.rs, webserve_attachment_e2e.rs. P3 tag delta: exactly ONE added tag line, [int->REQ-INST-6], and ZERO removed (I checked the removal side too -- a delta of "+1" is also satisfied by +2/-1, so the added count alone was not the check). REQ-INST-6 reads required_stages = ["impl","unit","int"], already activated. So the registry half at the head = 25e60015 identical, plus one more int witness on INST-6, exactly as you called it. ONE THING I ADDED, because "test-only" deserved a structural proof and not just a file-list eyeball: spt-test-support is the only non-tests/ file in the delta, so it is the one path by which a test rider could reach the shipped binary. It is under [dev-dependencies] in all three consumers (crates/spt, spt-daemon, spt-msg) -- verified by reading the enclosing section, not the line number. Dev-deps are not built for the release bin target, so these four riders CANNOT change the artifact I sign. Test-only is structurally true here, not just true by intent. CARRY-ACROSS: the pending reword is message-only, so every TREE is unchanged and all of the above is tree-derived. It carries to the final sha by construction. I still re-run the registry half at the sha hertz actually names -- a prediction that holds on a candidate is not a reading of the head -- but I now expect it to be a confirmation, and I will say so rather than dress it up as fresh discovery. Also done while held: gate3-dispatch.ps1 no longer carries the dead r2 run 34262154550 as a default. That default was live-fire dangerous -- gate 1 reads a DEAD run as completed with zero non-terminal jobs and PASSES, so the whole set could go green about a run I was not dispatching. Run and Sha are now mandatory params, sha validated to 40 hex. I proved the REFUSAL arm only (short sha and non-numeric run both rejected before the body runs); the permit arm ends in a real dispatch and has no dry-run switch, so it stays UNPROVEN and I am saying so rather than claiming a green I did not earn. ACL re-verified on my own netmap read just now: 2 filter rules, 40 Srcs, kitsubito 100.98.197.12/32 PRESENT, exit 0. Still open. Counter 104, unconsumed. Holding for hertz's final sha.