# FIX-164 JIT — engine-room briefing spools but is never presented

## ✅ STATUS 2026-08-19 (LATEST): ARMS 4+5 LANDED @`72efb6a` — AT doyle'S RE-GATE

Lane = `704de7a` -> `adc29c7` -> **`72efb6a`**, stacked on `0c86b2d`, NOT pushed. New commit, not an
amend (his gate had already read adc29c7). Re-gate he named: diff read + presented cell x3 + treqs.
Report sent (SENT). NOTHING is blocked on me; do NOT rebuild any of this.

RE-GATE STATE (doyle, 2026-08-19): legs RUNNING (presented x3 + treqs + clippy -p spt). His diff +
toml read is DONE and ACCEPTED as the record — int-gate amendment is the fence-4 parity he asked for,
declared residual worded right, commit message honest about the unflagged narrowing. He calls control
B the strongest evidence on the lane (converts the restart from judgement to measurement AND
independently corroborates the per-seat re-brief read via pending=2). Verdict pending.

⚖ IR-50 RULED (doyle): **FOLD into the existing row, NO fresh entry** — this cell IS the class's
population and the entry is a census; he is appending the fold note + helper-adoption residual to the
register branch HIMSELF. Do NOT file a row. My local both-places fix STANDS in 72efb6a. Adopting an
exported `stderrlog::sink_path` helper is a POST-LAND follow-up, not this lane: hertz's IR-50 lane
bases on `0c86b2d`, which PREDATES this cell, so it cannot census what is not in its tree.

Measured: cell 3/3 green (33.12s / 38.91s / 33.12s); loud line at 10.66-11.80s against the 10s bound
(so the >=9s assertion is live); clippy 0; treqs [OK] +impl +int. Negative control A (loud eprintln
deleted) reds AT the LOUD assertion with arms 1-3 green; negative control B (daemon restart skipped)
reds at must-BIND with pending=2 and the retained row undelivered.

⚠ THE ONE THING WORTH CARRYING FORWARD — **a blank diagnostic panel is not a silent product.** Arm 4's
first run reported the loud line ABSENT and every stderr panel BLANK, and I was one inference from
reporting a product defect. It was MINE: `daemon run` calls `stderrlog::install` a few statements in
and repoints std-error at `SPT_HOME/logs/daemon.stderr.log`, so the file `spawn_broker` inherits holds
only the PRE-REDIRECT window. Every panel in this cell had been printing blank on the PASSING arms
too — nothing had ever needed to read one, so nobody noticed. `engine_room_bringup_e2e.rs` had already
measured the identical trap on this family and documents it. Read BOTH places. This is the IR-50
rig-panel class; if hertz's sink census lands an exported `sink_path` helper, this cell should adopt
it instead of keeping its local copy.

## 🔄 Prior status: AT GATE, ONE NAMED QUESTION ANSWERED — ARMS 4+5 IN BUILD

doyle's gate found ONE undeclared NARROWING (not a refusal): fence 4 as ruled wants the miss path
witnessed too — the loud UNPRESENTED arm and the miss->release->retained->re-drive chain — and the
minted REQ's int gate carried only arms 1-3. I did NOT argue it. Answered **(b) author the cell**;
he ACCEPTED and ruled:
- Arms 4+5 GO as specified, negative controls included; carry the elapsed wait out on the red path.
- **DROP** the third miss shape (eligible-but-inject-FAILS): its only unique witness is the second
  eprintln branch, the claim-then-release is the same shared `drain_spool_offering` arms 1-3 already
  walk, and the manifest surface is a measured race-widener on this rig family. DECLARED residual,
  recorded in the gate record — it earns a cell if that branch ever fires unwitnessed in the field.
- **New commit on the lane, NEVER amend** — his gate has already read `adc29c7` and the re-gate wants
  a clean diff.
- ⛔ **HOLD all cargo** until he calls his legs done (clippy/presented x5/rig x5/idle_edge/spt-store/
  treqs running in `.worktrees/gate-adc29c7`, pool `gate-164-doyle`, SAME BOX). Authoring only.

His source read ALSO settled: fences 1+3 hold, fence 2 CONFIRMED (settle_engine_room_seat fires for
BringUp AND Code admissions gated on Controller|TookControl, so every seat-taking attach re-briefs +
re-drives; claim kernel keeps it spam-safe) — that fact is what makes arm 5's re-offer legitimate.
All THREE flagged judgement calls ACCEPTED (NativeInject discriminator, idle-arm-only evaporation,
bind-wait poll).

AUTHORED (uncommitted, +381 lines in `crates/spt/tests/er_briefing_presented_e2e.rs`):
- Arm 4 — the MISS, deterministic with ZERO product mutation via the pre-existing `--mode
  hold-unbound` fixture (live PTY + heartbeat, never binds ⇒ eligibility never holds ⇒ the 10s poll
  expires). Asserts loud UNPRESENTED fired AND only after the bound was honestly spent (>=9s), row
  pending with taker columns UNSTAMPED, seat holder still alive (never-refused).
- Arm 5 — the RE-OFFER. Same adapter NAME re-pointed onto the binding harness, **daemon restarted
  between the seats** (killing `rc4` ends the CONTROLLER only; the unbound harness is a BROKER child
  and would otherwise still be sitting there, making seat 2 measure the same miss twice while reading
  like a re-offer). Asserts the row id captured in arm 4 is the one that goes delivered, on
  `native-inject`, `.idle` still never written, pending 0.
- Arms 4+5 SHARE one home on purpose — arm 5's claim is about the row arm 4 failed to present.

NEXT: on all-clear — build, run the cell, run the negative control for BOTH new arms, then commit as
a NEW commit on the lane and report. Nothing else is open on me.

## ✅ Prior status: BUILT AND HANDED TO doyle'S GATE. Everything below is provenance.

Lane `fix/164-er-briefing-presented`, STACKED on `0c86b2d` (the #199 lane tip) per doyle's ruling —
NOT on origin/main `9ea595c`. Two commits:
- `704de7a` test(er): the measurement rig
- `adc29c7` fix(er): present the briefing (REQ-ER-BRIEFING-PRESENTED, impl+int)

ROOT, MEASURED AND ACCEPTED BY doyle: a TIMING defect, not an eligibility one. At the seat the ER
perch is already a fully eligible inject target (all three `is_spt_hosted_no_relay` legs true); the
row is claimable; the existing idle leg takes and delivers it correctly — at the FIRST IDLE, which is
after the first actionable turn by construction, while clause 5's bar is before it. Remedy rides the
NATIVE arm, proven to carry into a never-idle ACTIVE session BEFORE any fix was written (leg D).

WHAT THE FLAKE TURNED OUT TO BE: my rig died 4-of-5 with `RESERVED_ID` at `9ea595c` and is 6/6 green
at `0c86b2d`. It was #199's defect (the broker recording a bring-up AFTER spawning the harness that
binds), NOT a new mechanism — sampler measured 0/225 unreachable with the ER session first entering
the broker table at 201ms, refuting the fail-closed-on-unreachable leg. Filed as corroborating
evidence on releases#199 (comment 5347558298), framed to PROMOTE candidate (a) without closing the
labelled hole; the post-ship re-probe on the frozen HFENDULEAM perch remains the settler.

⚠ THE ONE THING TO RE-READ IF YOU TOUCH THIS: the two rigs differ ON PURPOSE.
`er_briefing_presentation_e2e.rs` is an INSTRUMENT (reports, barely asserts, runs green on BOTH sides
of the fix); `er_briefing_presented_e2e.rs` is the ACCEPTANCE cell (reds without the fix — negative
control run and confirmed at the clause-5 assertion). Do not "tidy" the first into the second.


Ticket: releases#164, `state: GREENLIT` / `type: BUGFIX`. Requester doyle, ruled shape in the
body (5 clauses). Picked off the ready queue 2026-08-19 after doyle closed the #199 lane and
said "pull from ready queue"; no next brief was assigned.

Base: `origin/main` @`9ea595c`. MEASURED, not assumed — `git log HEAD..origin/main` is EMPTY and
the merge-base of the #199 lane and origin/main is `9ea595c`, so origin/main is the #199 lane's
own base, 7 behind it. Local `main` @`8d4c224` is a STALE pointer sitting mid-lane; do not
branch from it. #164 is independent of #199 (briefing presentation vs bring-up in-flight
ledger), so this lane branches from `origin/main`, not from the #199 tip.

## The ruled shape (doyle, in the ticket body — not mine to relitigate)

1. Keep #142 post-seat composition (posture correctness).
2. Actively deliver the fresh row through the session's EXISTING delivery path — no second
   renderer.
3. Delivery claims the row via the SAME audited atomic take any poll uses (`taken_*` columns),
   so a poll race cannot double-present — exactly-one-taker by claim, not timing.
4. Presentation failure = loud post-seat notice + row retained pending; attach NEVER refused
   (extends the denial-of-governance doctrine already at the spool-failure arm).
5. Regression: real mock ER session, briefing reaches session input BEFORE first actionable
   turn + spool audit one taker + never-seated arm zero.

## Recon — measured this session

### The spool site
`brief_engine_room` (`crates/spt-daemon/src/broker.rs:1941`) composes and calls
`spt_store::briefing::spool_briefing_at` (`crates/spt-store/src/briefing.rs:439`). It is an
INSERT and nothing else. Its only loud arm is spool FAILURE
(`ENGINE_ROOM_BRIEFING_UNSPOOLED`) — spooled-but-never-taken is silent, exactly as the ticket
states. Called from `OutputLog::brief_engine_room` (:1978) from `settle_engine_room_seat`
(:2045), which is reached from :2500 — i.e. already post-seat per #142.

### There is no presenter in this repo
`grep -rn briefing crates/spt --include=*.rs` returns ONLY the ruleset-table render
(`cli.rs:18656`) and tests. No code path in `crates/spt` reads a spooled briefing row and
presents it. The adapter's startup/backlog poll is the would-be reader and it lives outside
this repo, and by post-seat time it has already run. This corroborates the ticket's root rather
than resting on it.

### The existing delivery path (clause 2's target) — already shaped right
`crates/spt-daemon/src/inject.rs::drain_idle_spool` (:110) is the shared core behind both the
send-time already-idle path and the pulse-tick re-offer belt. It ALREADY does what clauses 2-4
ask for, which is why clause 2 says "existing path, no second renderer":

- claims audited on the `idle-inject` leg via `claim_idle_edge_audited_at` (:127), which rides
  the ONE cross-carrier claim kernel `claim_rows` (`spool.rs:495`, `BEGIN IMMEDIATE`,
  REQ-CARRIER-CLAIM-EXCLUSIVE) — clause 3 satisfied by reuse, not by new code;
- offers each row through `try_spt_hosted_inject` (:75), which renders via
  `spt_msg::emit::render_event_whole_for` — the single renderer, so clause 2 holds;
- on the first miss RELEASES the claimed row and every not-yet-attempted one back to the spool
  intact (:143-149), leaving them pending — clause 4's "row retained pending" already exists;
- prints `IDLE_PARKED_DRAIN:` loudly on success and never refuses anything.

Same crate as `broker.rs`, so the call is in-crate.

### Hypothesis raised and REFUTED (recorded so it is not re-run)
Suspected the briefing was spooled to a different DB than the drain reads — `spool_briefing_at`
takes `engine_room_perch()` while the drain resolves `resolve_perch_path(id, Infer)`. FALSE:
`engine_room_perch()` (`engineroom.rs:389`) is literally
`resolve_perch_path(ENGINE_ROOM_ID, ParentHint::Infer)`, the same resolver with
`ENGINE_ROOM_ID = "engine-room"`. Same path, same DB. Perch-mismatch is NOT the root.

### ⛔ THE ROOT BELOW IS FALSIFIED — READ THIS BLOCK FIRST (2026-08-19)

The "no production `.idle` writer ⇒ the ER is ACTIVE forever" root is **WRONG and struck**.
doyle amended the #164 body a SECOND time on it (correction comment 5347229246); the ticket's
root is now OPEN, with both falsified roots recorded. Two independent falsifiers:

1. `.idle` HAS a production writer in this repo: `crates/spt/src/api/delivery.rs:37` `cmd_state`
   — the `spt api state idle --id <id>` seam — writes it at :45 via `sentinel_path(id,
   IDLE_SENTINEL)` (:38/:29). Production, not test (`mod tests` opens at delivery.rs:338). The
   original claim was a NEGATIVE EXISTENTIAL proven from ONE grep spelling (`resolve_idle_file`);
   the write uses another. **Adopted as a gate rule by doyle: no "no production X exists" passes
   review again without a second spelling of the write AND the reader's own path to it.**
2. The ER is NOT "a hosted terminal with no agent adapter". Its bring-up spawns the room's BOUND
   HARNESS adapter's `[session.self]` — `broker.rs:5640-5656` refuses the bring-up outright unless
   that adapter is a registered HARNESS adapter ("it cannot host its own mind") — and the endpoint
   id is injected into the session env (claude-spt manifest `[env.SPT_ENDPOINT_ID] = {id}`). An ER
   session reports idle for `engine-room` like any other endpoint.

AND TWO DRIVE SITES WOULD FIRE ONCE IT DID: `delivery.rs:65` (`cmd_state idle` →
`drain_idle_window` → the shared `drain_idle_spool`, delivery.rs:321) and `livehost.rs:264-268`
(the pulse belt, iterating `perch::list_self_perch_ids(owlery)` — engine-room included). So on a
healthy ER session the spooled briefing WOULD be delivered, at the session's FIRST IDLE.

WHAT SURVIVES THE FALSIFICATION (doyle, same ruling):
- Shape (d), on CLAUSE-5 TIMING ground: first idle is after the first actionable turn by
  construction, and clause 5's bar is "reaches session input BEFORE the first actionable turn".
  A window-gated arm cannot meet that bar; native can. (d) is a timing/eligibility fix, NOT a
  rescue of an unreachable row.
- Fence 3's controllable chain (below), which doyle called gate-grade.

### FENCE 3 — ANSWERED, PRODUCTION-SOURCE ONLY (no test helper in the chain)
1. `broker.rs:5699` — the ER bring-up spawns the room's harness via `launch_harness_brokered_in`.
2. `startup.rs:1090-1093` — `cmd_bind`'s own doc: "The engine room's own harness binds its own
   perch through this verb."
3. `crates/spt/src/api/mod.rs:98` — `api bind` declares `#[arg(long = "type", default_value =
   "live_agent")]`.
4. `startup.rs:1115-1119` — `endpoint_type == "live_agent"` ⇒ `HostingAuthority::BrokerPty`.
5. `startup.rs:241` — `resolve_controllable(BrokerPty, ..) = Some(true)`, unconditional.
Relay leg: the ER bring-up is the BIND path, not seed→listen, so no `api listen` runs and
`resolve_address` is None. Corroboration only (NOT the proof): `engine_room_bringup_e2e.rs:125`
spawns the ER harness `--type live_agent` and :243-258 assert the ER perch carries a non-empty
session_id after bring-up.
NOT inferred from `bind_engine_room_perch` (`broker.rs:10706`) — confirmed test-only (`mod tests`
opens at broker.rs:7714; all five call sites are 10784+). The doc at
`crates/spt/src/api/engineroom.rs:145` calls it "the broker's own", which reads as production and
is not — reported; doyle queued it as a hertz hygiene rider at next intake.

### FIELD FINDING — ruled, and the evidence is FROZEN
On HFENDULEAM the `engine-room` perch dir holds `spool.db` + `.has-messages` and **NO info.json,
no ready file** — the only perch of six checked (todlando/doyle/deployah/webbie/flynn) with no
record — despite four ER control establishes on 2026-08-05 (`obs/rc-establish.log:403-406`). An
unbound perch makes `is_spt_hosted_no_relay` false, which kills BOTH drive sites and the native
arm too. Cause UNPROVEN (harness stderr goes to the broker PTY, not daemon stderr; the adapter
hook trace has rolled). Candidates: the #199 refusal (fix landed-unreleased in the sibling lane)
or a hand-run elevated purge (`cli.rs:22301`; not routine teardown).
doyle's four-part ruling: (1) #164 comment 5347199566 binds #164 and #199 to the SAME milestone
batch; this lane's gate claims impl+int RIG evidence only, field acceptance deferred until the
fleet carries both. (2) #199 comment 5347199304 labels the evidence hole so absence of
RESERVED_ID lines never later reads as absence of the refusal. (3) **STANDING INSTRUCTION: leave
the HFENDULEAM ER perch dir UNTOUCHED as evidence — no purge, no hand-repair.** Post-ship re-probe
settles it: a clean bind is strong evidence for #199-as-cause; a repeat refusal means capture the
broker PTY live. (4) the engineroom.rs:145 misnomer is doyle's to route.

### THE RIG — BUILT 2026-08-19: `crates/spt/tests/er_briefing_presentation_e2e.rs`

The fusion doyle ruled, as one new heavy integration binary (HEAVY-AT-BIRTH: added to the
`heavy-broker-pty` binary filter in `.config/nextest.toml` in the same change).

- FROM `engine_room_bringup_e2e.rs`: `seed_subnet_and_code` (the test plays the operator's
  authenticator), the ceremony verb with its three declared env-marker removals, `spawn_broker`,
  the real `spt rc engine-room --code …` held open on a piped stdin with output on FILES, and
  the on-disk-record witness (`info.session_id` non-empty).
- FROM `idle_edge_drain_e2e.rs`: the `[message-idle-translation-binary]` table in the registered
  manifest, staged from the real `translate_proof_fixture` into the install dir, and the
  `spt api state idle <id>` edge with a non-destructive spool read as the witness.
- THE ONE THING TAKEN FROM NEITHER: the rig does **not** stamp `controllable = Some(true)`.
  `idle_edge_drain_e2e.rs:192` does, which is a defensible fixture stance there (its subject is
  the drain) and would BE the whole answer to measurement A here.
- The harness stays `--mode dummy` deliberately: it binds and heartbeats and never declares idle,
  so ACTIVE is a controlled variable and the test — not a racing harness — owns the idle edge.

**MEASUREMENT ORDER IS A-B-D-C, NOT A-B-C-D, and the reorder is load-bearing.** C writes the
`.idle` sentinel; after it the session is no longer ACTIVE, and a native offer landing into an
IDLE session proves nothing about (d), whose entire premise is delivery into a session that has
never yet declared idle — the state the ER seat leaves and the only one in which clause 5's
"before the first actionable turn" bar can be met. D does not disturb C: `--force-native` is
binary-or-nothing and never spools (`cli.rs:10701-10746`), so the briefing row is exactly as
pending after D as before it (reported as `pending_after_probe` so a surprise is visible).

INSTRUMENT, NOT A GATE: it asserts only the three preconditions that make its readings mean
anything (nothing seated/spooled before the bring-up; the seat happened; a briefing row exists),
and REPORTS the four measurements behind an `ER164_MEASURE:` prefix. An assertion on the readings
would encode the defect's current shape as the expected one and red the day the fix lands, and the
root is OPEN. The acceptance cell is derived FROM these readings after the root is restated.
D's reading carries the CLI's own leg marker (`sent` / `broker-spooled-active` /
`broker-spooled-no-binary` / `cli-gate-not-hosted`), so it names its own mechanism; C's carries
`audit_rows_at` so a take shows its `taken_leg` — the difference between "the fix must add a
taker" and "a taker exists and runs too late".

### NEXT STEP — RULED BY DOYLE: RIG RE-MEASUREMENT FIRST. NO REQ MINT, NO CODE UNTIL THE CHAIN IS IN.
The lane branch `fix/164-er-briefing-presented` exists off `origin/main` @`9ea595c` and is EMPTY
(verified: origin/main still `9ea595c` after fetch). A first-draft of (d) WAS written this session
and REVERTED so it cannot contaminate the measurement; it is saved as a patch at
`<scratchpad>/164-d-draft.patch` (152 lines: an `inject.rs` refactor of `drain_idle_spool` into a
shared `drain_spool_offering(id, owlery, native)` core + a `drain_spool_native` sibling with a
self-naming log tag, and a `broker.rs` `present_engine_room_briefing()` driven off-handler after
`settle_engine_room_seat` at :2500 on every taken ER seat). Re-derive it against the restated root
rather than replaying it unread.

THE RIG THE MEASUREMENT NEEDS = the ER bring-up scaffolding FUSED with the idle/translation-binary
scaffolding. Neither existing rig can answer this alone:
- `crates/spt/tests/engine_room_bringup_e2e.rs` brings the ER up through the REAL verbs, but its
  adapter runs the mock in `--mode dummy` (adapters/mock/src/main.rs:~190-235): it binds and
  heartbeats, NEVER declares idle, and carries NO translation binary — so no inject can land.
- `crates/spt/tests/idle_edge_drain_e2e.rs` has the missing half: a real
  `translate_proof_fixture` idle-translation binary and the `spt api state idle <id>` edge, with
  `pending == 0` as the cross-platform witness.

FOUR MEASUREMENTS TO TAKE, in this order:
- A. After the seat: does the ER perch exist, and is `controllable == Some(true)`? (reads
  fence 3's conclusion off a real bring-up instead of off source.)
- B. At seat-settle: is the briefing row PENDING and undelivered, and does it STAY pending while
  the session is ACTIVE? (this is the ticket's "never presented", measured rather than argued.)
- C. Then drive `spt api state idle engine-room` — is the row taken at that edge? (this is what
  the restated root turns on: if yes, the defect is TIMING, not eligibility.)
- D. THE (d) FEASIBILITY PROOF, and it needs no fix to run: `spt send engine-room --force-native`
  into the ACTIVE ER session. If a native offer lands while the session is ACTIVE, (d)'s carrier
  is proven on the existing surface before a line of it is written.
The briefing spools `WINDOW_DEFAULT` (`briefing.rs:440` → `spool.rs:328-330`, `deferred = 0`), so
the idle-inject claim CAN take it — checked, not assumed.

### THE ROOT AS FIRST MEASURED — FALSIFIED, kept only for provenance (see the ⛔ block above)

The `.idle` sentinel has **NO production writer in this repository.** Every `resolve_idle_file`
site is a READ (`.exists()`) except exactly two writes, and both are test-only:
`inject.rs:280` (its `mod tests` opens at :177) and `pulse.rs:238` (its `mod tests` opens at
:95). The sentinel is authored by the ADAPTER, harness-side, when a session declares itself
idle.

The broker states the consequence in its own words at `broker.rs:6631`, at the read that
decides every delivery: *"An endpoint is ACTIVE until it declares idle."*

An engine-room session is `spt rc engine-room` — a hosted terminal with no agent adapter, so
nothing ever declares it idle. It is therefore **ACTIVE forever** from the broker's view, which
kills BOTH delivery arms at once:

- `try_spt_hosted_inject(..., native=false)` sees ACTIVE → spools DEFERRED, never injects;
- `has_parked_idle_spool` sees no `.idle` → false → the pulse-tick belt never fires for
  `engine-room` at all.

So the briefing row can never be claimed by any leg. This is a STRONGER root than the ticket's
("the adapter's startup/backlog poll has passed"): the poll having passed is incidental — even
a poll that had NOT passed would face a row that no leg is able to take.

**This refutes design option (a).** A one-shot drive of `drain_idle_spool` at post-seat returns
0: the broker reports ACTIVE, the row is released, and nothing re-offers it. Clause 4's
"retained pending" would mean retained forever.

**Proposed remedy, on the measurement — doyle's to ratify.** Deliver the briefing on the
NATIVE arm. `native=true` is defined in this codebase as exactly this case
(`inject.rs:65`, `broker.rs:6631`): *the binary delivers REGARDLESS of the `.idle` gate — the
window owns WHEN, native owns THROUGH WHAT.* A session-opening briefing is not an
activity-windowed message; it is a fact the session must hold before its first actionable turn,
which is clause 5's own acceptance bar. Riding native keeps every ruled clause satisfied by
REUSE rather than new machinery: same delivery path and same single renderer (clause 2), same
`BEGIN IMMEDIATE` claim kernel and `taken_*` stamping (clause 3), miss → release → row retained
pending + loud notice, attach never refused (clause 4).

### THE OPEN QUESTION AS FIRST WRITTEN — now answered above, kept for provenance
If a re-offer belt already exists, why did the field row stay `delivered=0` forever rather than
being picked up on a later tick? The belt's gate is `has_parked_idle_spool` (:165), which
requires ALL of: `is_spt_hosted_no_relay`, the `.idle` sentinel file present, and >=1 pending
row. And `is_spt_hosted_no_relay` (:37) itself requires `is_online(target)`, NO relay listener
registered, and `info.controllable == Some(true)`.

Leading candidate: an engine-room session never satisfies one of those — most likely the
`.idle` sentinel (written by an adapter reporting idle; an ER/`spt rc` session may have no such
reporter), or `controllable`/relay-listener state on the ER perch. If so the belt CANNOT fire
for `engine-room` at all, and that — not merely "the poll had passed" — is why the row sleeps
forever. This changes the fix: a one-shot drive at post-seat would deliver only when the
session happens to be idle at that instant, and the belt would never rescue the miss, so
clause 4's "retained pending" would be retained FOREVER rather than re-offered.

MEASURE FIRST (next action): read `.idle` sentinel authorship and whether an ER perch carries
`controllable=true` / a relay listener. Do not write the fix until this is answered — it
decides whether the remedy is (a) drive the existing drain once post-seat, or (b) drive it AND
make the ER endpoint belt-eligible, or (c) a distinct ER-side carrier.

## Fences carried in
- Do NOT add a second renderer (clause 2 is explicit).
- Do NOT refuse an attach on presentation failure (clause 4, denial-of-governance doctrine).
- Do NOT relitigate #142 post-seat composition (clause 1).
- The false-confidence e2e (proves exactly-one-SPOOLED, not consumed) gets REPINNED on the
  product diff, per the ticket's closing line.

## Adjacent ticket, scoped but not claimed
releases#177 ("engine room brief is inconsistent", GREENLIT, operator-reported) has two faces.
Its HFENDULEAM half — "engine-room received no brief at all" — is very likely THIS defect and
should discharge with #164. Its ENLYZEAM half — "receives a re-brief on every user attach,
pointless more than once per session" — is a SEPARATE face about brief cadence, not
presentation, and is not in #164's ruled shape. Flagged to doyle; not folded in unilaterally.

## REQ
REQ-ER-SESSION-BRIEFING already exists and is tagged at the spool sites
(`broker.rs:1938/1976/2010`). It is currently satisfiable by an INSERT that nobody reads —
which is the false-confidence the ticket names. Expect either a tightened existing REQ or a new
`REQ-ER-BRIEFING-PRESENTED` at impl+int. Decide with doyle at design sign-off, since minting
vs tightening changes what the gate reads.
