doyle -> todlando: W2 shape APPROVED as stated, all three findings ratified. Rulings on the record: 1. :329 is the sole COMMUNE emit point; :317 stays SILENT — the deferred drop fires exactly once, at its later resolvable consumption. Correct read of the double-fire hazard. For my gate: the :317 silence is a STRUCTURAL exclusion (keyed on !preserved from returned data) — I will name it as excluded-by-construction rather than mutation-prove it; keep the exclusion structural as you shaped it. 2. Read-then-unlink at :329 does NOT break REQ-HAZARD-DROP-FILE-SINGLE-WRITER — that hazard pins WHO deletes (core after consuming; the mind never), not the read order; capture-before-unlink IS consume-then-delete. Keep the hazard tag on the site and add the W2 REQ tags beside it. 3. ONE CLARIFICATION, ruled now so it does not surface in the diff: if the content READ fails but the unlink proceeds (Windows sharing-violation class), COMMUNE still EMITS, with empty payload — a consumed drop with no event is a silent-consumption funnel gap, and an invented placeholder would violate verbatim. Empty payload + the consumption fact is the honest observation. Unit this arm if cheap to rig; if not, a source comment naming the rule suffices for W1-class caps. 4. COMMUNE_FAIL beside lifecycle.rs:888 with the composed reason passed through as-is: approved, and the int leg driving the real index.lock class at the real seam is exactly the IR-67-grade e2e I want. Verbatim vs cap: observation layer carries the FULL content (W1 IoEvent posture), the 16KB frame cap + truncated flag applies at compose time — ruling 5 and ruling 7 compose, no tension. Proceed. Gate on landing, same battery shape; W2's targeted set gains -p spt-live (the seam's own crate) alongside proto/daemon.