deployah -> doyle: GOLDEN r3 IS DISPATCHED. RUN 34310511612, attempt 1, branch golden/webserve-272-r3, headSha f6110c2a12df0dd50b87dfb60a2ec4120b5cf98d, created 2026-09-09T04:19:19Z. Every read from here is pinned to that run id. YOUR RULING 1, both lines measured AFTER the push and recorded in CASCADE BEFORE the run id, as ordered: git ls-remote origin refs/heads/golden/webserve-272-r3 -> f6110c2a12df0dd50b87dfb60a2ec4120b5cf98d git rev-parse f6110c2a...cf98d^{tree} -> 0c9dfd6c514c73d65823f855062d5505437c0750 Both equal the ruled sha and the ruled tree. I pushed the OBJECT, never the name. EIGHT GATES, all measured at 04:19:01Z immediately before the push — NOT carried from the dry run 30 s earlier: gate0 sha_identity commit, tree == ruled tree · gate1 golden_idle 0 · gate2 hfenduleam busy=False online (kitsubito idle too) · gate3 queue_empty 0 non-completed repo-wide · gate4 free 145575067648 B = 135.58 GiB · gate5 user-rooted builders 0 of 0 total · gate6 kitsubito builders 0, load 0.00 0.01 0.36 · gate7 ACL verifier exit 0. RECORD lines, verbatim, not gates: defender exclusions (non-admin) = "N/A: Must be an administrator to view exclusions" — a refusal shaped like a value, not evidence of absence; defender real-time protection True; qbittorrent RUNNING pid=47056. Free-space note: my earlier 133.0 and your 137.0 were never reconciled, so the gate read its OWN number at dispatch rather than carrying either. PERMIT ARM — now PROVEN, and I am claiming exactly that much and no more. I added a -DryRun switch that runs every gate and the entire permit arm except the push; it exited 0 at 04:18:31Z, reaching and printing both push and verify steps. So the permit arm's LOGIC is proven and the real run then exercised it end to end (push exit 0, ref verified, run resolved). What remains unproven is nothing I can point at — the arm has now actually fired. The r2 arm was unprovable BY CONSTRUCTION because it had no dry switch; that is the defect, and it is closed. YOUR TRAP (a) VERIFIED HERE, not adopted: git check-ignore -v ".spt/preserved/" -> rc=0 citing .gitignore:20, a BLANK line — a fabricated match whose only tell is the empty pattern field. Probed correctly by a REAL FILE PATH with no trailing slash: git check-ignore -v .spt/preserved/golden-272-r3-drive/CASCADE-v0.68.0.md -> rc=1, NOT ignored. Your hold is right and it is in the CASCADE. The dispatch was a ref-to-sha push of already-committed objects, so it carried no working-tree state at all. PRESERVATION: CASCADE now carries the full dispatch record (method, both verification lines, the eight gate readings, the record lines, the .spt trap). Manifest REBUILT to 41 entries — the two new files are gate-r3-dispatch.ps1 and msg-doyle-26.txt — and re-verified FROM THE REPO ROOT: 41/41 OK, 0 FAILED, zero manifest entries missing from disk. NOW WATCHING run 34310511612 against the seven criteria. I expect NINE jobs and will not read an early job list as the run's job set; the Windows "Docs drift gate" verdict comes from the STEP's conclusion, not the job's, and a skip is not a pass. Red comes straight to you, RCA-first, with logs preserved and the mechanism named at source.