# v0.68.0 post-green cascade (staged 2026-09-08, deployah)
RULED SHA = f6110c2a12df0dd50b87dfb60a2ec4120b5cf98d
*** ATTEMPT 2: PHASE B PASSED, THEN THE JOB HIT ITS 50-MINUTE TIMEOUT AND WAS REPORTED
    `cancelled`. NOT a test red. The docs-drift gates are UNREACHABLE at this budget — see
    "ATTEMPT 2 OUTCOME" at the foot. STILL DO NOT FF-MERGE, DO NOT TAG, DO NOT PUBLISH. ***
            attempt 1 = completed/FAILURE 2026-09-09T05:29:57Z, 9 jobs, 8 green, ONE red:
            test (self-hosted, Windows, hfenduleam). doyle TRIAGED it LEDGERED-CLASS (4th
            classified occurrence of the resident_service_e2e teardown-LEAK row) and RULED a
            SAME-SHA rerun of the failed job. attempt 2 DISPATCHED 2026-09-09T05:44:2xZ by
            deployah, nine gates green. See "GOLDEN r3 ATTEMPT 2" at the foot.
            The sha and tree lines below remain CORRECT and RIDDEN; what is blocked is ACTING
            on them until attempt 2 lands green.
            RIDDEN by doyle 2026-09-09 ~04:08Z. Tree 0c9dfd6c514c73d65823f855062d5505437c0750,
            parent c4919243. This is the sha to ff-merge (sec 1), the sha to tag (sec 2), and the
            sha golden r3 runs -- tested-sha == merged-sha == shipped-sha.
            The THREE action lines (now 26, 27 ff-merge; 33 tag) name it in FULL 40-char form
            (gh run list --commit reads a confident EMPTY on a short sha). Sec 4 publishes by
            --tag and names no sha.
            DEAD SHAS, history only, NEVER a target: c4919243 (r3 head before rider 5, cell3
            26.7% flaky on Windows) and 25e60015 (r2). r2 run 34262154550 is a DEAD run.
COUNTER   = 104   (v0.67.1 metadata decoded version: 103)
GOLDEN r3 = RUN 34310511612, attempt 1, branch golden/webserve-272-r3, headSha f6110c2a...cf98d
            DISPATCHED 2026-09-09T04:19:19Z by deployah. Pin every read to THIS run id.
            r2 run 34262154550 is DEAD, never reuse it.

## 0. Verdict (before anything)
- Release word = run.status==completed AND every listed job terminal. EXPECT NINE jobs.
  (six listed early; both twohost legs + `notify` materialize late — a job list read
   early is NOT the run's job set.)
- ACCEPTANCE: 4 e2e consumers green on BOTH test legs (poll_envelope, quickstart,
  gateway, io_events relay_backlog); two_host_web_helper_role_a green on A AND
  two_host_web_role_b green on B READ FROM B'S SERVED COUNT, not A's poll.
- RED -> preserve job logs + checksums, name mechanism AT SOURCE, hand to doyle.
  No rate argument. No same-sha rerun.
- GREEN -> verdict comment on releases#272 (alchemy-0 shell send, positional body).

## 1. Advance main ff-only (BEFORE tag)
git fetch origin main && git switch main && git merge --ff-only f6110c2a12df0dd50b87dfb60a2ec4120b5cf98d \
  && git push origin main && git merge-base --is-ancestor f6110c2a12df0dd50b87dfb60a2ec4120b5cf98d origin/main
Fires thin ci.yml at the same sha. NOT a separate authority — wait for it as
BOX OCCUPANCY only. Thin red at a golden-green sha = contradiction -> gater ruling,
not auto-block, not waved through.

## 2. Tag — RULED SHA EXPLICITLY, never bare HEAD
git tag v0.68.0 f6110c2a12df0dd50b87dfb60a2ec4120b5cf98d && git push origin v0.68.0   # NEVER the r2 sha, NEVER bare HEAD
Then MEASURE both before/after:
  git rev-list -n 1 v0.68.0 ; git rev-parse origin/main
Fires release.yml ONLY (docs-publish.yml is RETIRED — do not wait for it).
Draft must carry SEVEN assets: spt-x86_64-linux, -linux-musl, -windows.exe,
SHA256SUMS, manifest.schema.json, mock-adapter.zip, spt-docs.tar.gz.

## 3. STEP 6 FIRST HALF — pre-publish, DRIVEN not swept
spt shell cmd alchemy-0 state 272 acceptance
Golden CI closes no individual request, so the sweep finds nothing. The MILESTONE's
own close must land PRE-publish too (hub card buckets STRICTLY on closedAt).

## 4. Publish (quiet window: golden + thin ci + release.yml all terminal)
On HFENDULEAM run WITHOUT SPT_RELEASE_SEED_CMD (machine-scope SPT_RELEASE_SEED,
operator-ruled permanent; _CMD double-decodes hex and panics). Do NOT re-escalate.
  cargo run -p xtask -- release-publish --tag v0.68.0 --key-id rel-primary-2026 --version 104
Attribute any live cargo/rustc by PARENT CHAIN ROOT: RunnerService/Runner.Worker =
CI axis (counted); rooted at a user shell = real contention, blocks signing.

## 5. STEP 6 SECOND HALF — POST-publish. THE STRADDLE THAT WAS MISSED AT v0.67.0.
spt shell cmd alchemy-0 release v0.68.0
Promotes DONE + posts the Shipped Requests roundup. Publish does NOT discharge step 6.
Every other check passes with the board unfinished. TICK THE HALVES SEPARATELY.

## 6. Verify Latest / update-set flip, then drop the counter.

## 7. Teardown: PRESERVE FIRST (named owner, path+hash, restore cost stated),
release/reap SECOND as a separate message gated on that confirmation.
Shape rig .worktrees/shape-0680, pool ./target lane shape-0680-r2.

# ================= AMENDMENT, deployah 2026-09-08 ~23:5xZ =================
# This file is now the OPERATIVE copy (migrated byte-identical from the 34eee87f session
# scratchpad, which belongs to a cleared session and can be reaped out from under the release).
# Two gaps found by auditing the file against the r2 ruling. Both would have bitten at drive time.

## GAP 1 — section 0's ACCEPTANCE list is INCOMPLETE and would pass a run that never
## proved the thing r2 exists to prove. It names only the 4 e2e consumers + the twohost pair.
## THE AUTHORITATIVE LIST IS SEVEN (RERUN-GATE.md, doyle, unchanged):
##   1. FLOOR_DOCS verdict = PASS
##   2. step 'Docs drift gate (CLI ref + llms links) — windows' = success   <-- ABSENT FROM S0
##   3. FLOOR_END verdict = PASS                                            <-- ABSENT FROM S0
##   4. Summary lines == 2   *** AMENDED BY DOYLE 2026-09-09 05:40Z, see foot ***
##      Under the Phase A/B split the invariant is: EACH LEG carries exactly ONE Phase A
##      and ONE Phase B Summary (4 total across two legs). >1 of either phase ON ONE LEG
##      is the doubled-run signature the rule exists to catch.        <-- ABSENT FROM S0
##   5. two_host_web_helper_role_a green on A
##   6. two_host_web_role_b green on B, FROM B'S OWN SERVED COUNT
##   7. run terminal, EVERY job green (expect NINE)
## Criterion 2 is the dangerous one: the Windows docs-drift gate has NEVER run at this sha —
## SKIPPED THREE TIMES now (r2 attempt 1 behind the floor red; attempt 2 behind Phase B's
## failure at step 21; and it is gated behind Phase B, so it cannot run until Phase B is green).
## A THIRD/FOURTH SKIP IS NOT A PASS. The axis is per-OS because it diffs the WINDOWS binary's
## own --help; a green Linux docs gate is NOT Windows evidence. Read the STEP's conclusion,
## never the job's.

## GAP 2 — section 0 says "No rate argument. No same-sha rerun." That was true when staged and
## is now SUPERSEDED for this run only. doyle authorized (a) ONE rate rerun for the
## webserve_attachment_e2e ttl cell, and (b) a repaired-mechanism rerun of the twohost pair once
## the inbound path is open. Both ride ONE `gh run rerun 34262154550 --failed`. Still no THIRD
## attempt at this sha: if the ttl cell reds again, STOP — hertz's deterministic repin goes on a
## new head with a full golden.

## CURRENT BLOCKER (not in the original file at all): the run cannot go green until kitsubito can
## reach hfenduleam on the rig's ports. TWO layers, both measured:
##   L1 Windows Firewall inbound — DONE. Operator applied "spt-ci two-host rig UDP-In (kitsubito
##      only)": Enabled Yes, In, UDP, LocalPort 7460-7499, RemoteIP 100.98.197.12/32, all profiles.
##      Verified on the box BY FILTER (a name grep for 'twohost' misses it — it is 'two-host').
##   L2 tailnet ACL — OPEN, operator-owned, the current hold. hfenduleam's netmap has ONE
##      PacketFilter rule, Srcs = 18 entries (9 v4 + 9 v6), Dsts 0.0.0.0/0/::0 all ports,
##      IPProto [6,17,1,58]; 100.98.197.12 ABSENT. Near-misses 100.98.213.33 / 100.98.214.87 are
##      the same /16 and read as PRESENT on an eyeball — they are not kitsubito. The grant is
##      SOURCE-scoped, not port-scoped, which is why TCP timed out beside UDP.
## VERIFY-AFTER-GRANT (mine, no elevation needed): 100.98.197.12/32 appears in `tailscale debug
## netmap` Srcs (field is `Srcs` — NOT SrcIPs; an empty extraction printed "ABSENT" once already
## and that verdict was vacuous). Then doyle's Tailscale re-probe must read 3/3 BEFORE my gates.

## ORDER, unchanged after that: five gates -> ONE rerun-failed -> seven acceptance criteria ->
## sections 1..7 of this file, with the STEP 6 STRADDLE ticked as two separate halves.

## PRE-FLIGHT MEASURED 2026-09-08 23:5xZ (deployah, read-only, while held on the ACL grant)
All clean — none of these can surprise us at drive time now.
  SPT_RELEASE_SEED (Machine)     : PRESENT, length 64, matches ^[0-9a-fA-F]{64}$  (value never printed)
  SPT_RELEASE_SEED_CMD (Machine) : absent  <- REQUIRED absent on this box (hex double-decode panic)
  SPT_RELEASE_SEED_CMD (Process) : absent  <- checked too; a process-scope leak would panic identically
  tag v0.68.0 local              : does not exist
  tag v0.68.0 on origin          : does not exist  (git ls-remote --tags -> empty)
  ruled sha ancestor of origin/main : NO — the step-1 ff-only merge is genuinely still pending
  origin/main head               : e44444136dc4eacf07516531ee3b8604f933498c
                                   (the same sha the interfering thin `ci` 34261096301 ran on — consistent)
  refs/heads/golden/webserve-272-r2 : 25e6001585ed0cd495a72c7634dded9dd207bdae — matched the RULED SHA
                                   AS OF THAT r2 READING ONLY. The ruled sha is now f6110c2a...cf98d
                                   and r2 is dead; this line is a dated record, not a live match.
Deliberately NOT pre-flighted: any cargo build (xtask included). Building now would occupy the box
and the pool that CI needs for the rerun, and a warm xtask is worth less than a quiet runner.

## STAGED VERIFIER: r2/verify-acl-grant.ps1 — run it the moment the operator lands the ACL grant.
Exits 0 = kitsubito PRESENT in netmap Srcs (ACL open) · 1 = still absent, prints the v4 set and the
100.98/16 near-miss warning · 2 = extractor read ZERO Srcs, which is NOT absence — re-dump the shape.

## STEP 3 START STATE — RULED, doyle 2026-09-09 00:1xZ, from the GitHub LABEL TIMELINE
#272 goes GREENLIT -> ACCEPTANCE. It was NEVER WIP: BACKLOG 09-05 03:15Z -> GREENLIT 09-06 10:25Z,
nothing since. Precedent #23 (v0.67.0): GREENLIT 07-29 -> ACCEPTANCE 08-30 08:18Z -> DONE 09:28Z,
no WIP either. So `spt shell cmd alchemy-0 state 272 acceptance` is a GREENLIT->ACCEPTANCE move and
the "state: greenlit" the view renders is CORRECT — do not repair it, do not expect WIP.
(doyle's own 09-07 22:53Z comment premised WIP and was wrong on the state; superseded by his timeline
read. The AGENTS.md taxonomy lists WIP in the chain, but milestones skip it in practice — twice
measured now.)

TYPE: leave UNSET on #272. Milestones carry `kind: MILESTONE` only; `type: BUGFIX/ADDITION/CHANGE`
is request-level. #23 closed DONE with no type label. Do NOT set it.

FLAG: there is no `flag: NEEDS-OPERATOR` on #272 to clear — labeled 09-05 03:16Z, UNLABELED
09-06 10:24Z, never re-set. doyle's 09-07 "this comment is the flag" was prose, not a label.
Nothing to strip at any cascade step.

## ============ r3 SHAPE FINAL (doyle, 2026-09-09 ~03:16Z) — TEST-ONLY ============
FOUR riders on 25e60015, no product change, GREENLIT FORM OF #272 UNCHANGED (nothing dropped, nothing
added — so the intake parity check should record zero of each, and that is the EXPECTED reading, not
a formality to skip):
  88625fa0  arm 12 deterministic
  b359e40e  converge budgets derived (31 sites)
  4c7309ec  registry_lifecycle bounded-rendezvous join
  hertz r4  the FOUR wire-Edge assertions in twohost.rs accept Edge|NoEdge per resthost.rs:21-27 and
            :198-202; the WITNESS becomes the durable observable. (I corroborated both doc quotes
            verbatim at the sha, and found the durable wait ALREADY sits immediately after the assert
            on A's side — rig_wait "A-3: B advertises Suspended at A" — with B's :1368 read_rest doing
            the same, so the assert can go with ZERO coverage lost.)
TWOHOST-A RED MECHANISM (todlando, doyle spot-checked): ONE rest request served by TWO dispatcher
instances = two brain processes against B's broker. PRE-EXISTING at v0.67.0, claim path untouched by
#272, and the redelivery is INSIDE the documented at-least-once contract. Two post-publish lanes
seeded (served-path telemetry; the overlap hazard). So the product is exonerated for this release and
r3 stays test-only.

MY SEQUENCE WHEN hertz HANDS THE HEAD SHA:
  1. Intake per docs/RELEASE-RUNBOOK.md "Golden-head intake" — greenlit-form parity against #272's
     INTAKE comment of 2026-09-06T10:24:57Z (the snapshot, not a reconstruction); any dropped/added
     request needs a reason comment ON THE ISSUE before golden runs, and a dropped one must also be
     relocated or moved back to eval. NONE EXPECTED — record zero/zero explicitly.
  2. Release-shape check at the assembled head (IR-54): read Cargo.toml's first version line and
     CHANGELOG.md's first heading AT THE SHA before assuming; author version material on top if the
     head is unshaped, as at r1 and r2.
  3. Golden r3 on the shaped sha, run id pinned by FULL sha at push time.
  4. Dispatch preconditions AS FOR a4: census 0 both boxes (parent-chain-root attribution on
     hfenduleam, ssh census on kitsubito), free >= 110 GiB, runner quiet, foreign queue 0, ACL meter
     verified by my own netmap read, Defender line printed VERBATIM (it is a record line, not a gate).
     Gate script: r2/gate3-dispatch.ps1 — REMEMBER to repoint $RUN to the NEW run id; it defaults to
     34262154550 which is now a DEAD run.
  5. Then this file's sections 1..7, with the STEP 6 STRADDLE ticked as two separate halves and
     step 3 starting from GREENLIT (never WIP).
Counter STILL 104, unconsumed — nothing was published from r1, r2 or any a-attempt.

# ===== r3 HEAD RULED + INTAKE CLOSED (deployah 2026-09-09 ~03:38Z) — SUPERSEDED BY RIDER 5 =====
## The "HEAD =" line below is the PRE-RIDER-5 head. The ridden head is f6110c2a...cf98d (see header).
HEAD = c4919243. Chain linear on 25e60015: afb711c9 -> 3f683357 -> 73e3f59b -> c4919243,
4 commits, ZERO merges, trailers 4/4 "Co-authored by: hertz" (raw body read).
Head arrives SHAPED — Cargo.toml 0.68.0, CHANGELOG "## [0.68.0]". NO version material owed from me;
the sha hertz names IS the sha golden runs on and the sha that gets tagged. (Unlike r1 and r2.)
INTAKE CLOSED by doyle at this head: zero dropped / zero added, gates nothing. Full record and every
measurement in r2/INTAKE-BASELINE-272.md.
NOTE the run-id repoint burden is GONE: gate3-dispatch.ps1 now takes -Run and -Sha as MANDATORY
params (the dead-r2-run default is removed; it used to PASS gate 1 about the wrong run). Pass the
FULL 40-char sha.

## >>> CARRY INTO THE RELEASE CLOSE NOTE — doyle-ruled 2026-09-09, one line, do not drop it:
##   "heading dated 09-08, tagged 09-09Z, left to keep the proven tree"
## Rationale, so the next reader does not rediscover it as a defect: the CHANGELOG heading reads
## 2026-09-08 while the tag lands 2026-09-09Z. Precedent is that the heading tracks the tag's UTC
## date (v0.67.1 dated 09-06/tagged 09-06Z; v0.67.0 dated 08-30/tagged 08-30Z), so this DEVIATES —
## deliberately. Editing the date would move a proven chain, re-bind every clippy/cell proof to a
## new tree, and tested-sha == shipped-sha forbids fixing it once golden opens. The runbook checks
## the VERSION in the heading, not the date, so no checked leg is violated. Deliberate, not missed.

# ========== HEAD RIDDEN -- f6110c2a12df0dd50b87dfb60a2ec4120b5cf98d (deployah 2026-09-09 ~04:1xZ) ==========
## Action lines REPOINTED. c4919243 and 25e60015 below are HISTORY ONLY -- never tag either.
This block was written while the head was still PENDING; it is REPLACED rather than annotated,
because an executor acts at the top of a block and a correction appended under it arrives too late.

READ THIS AS THE POINT OF THE AMENDMENT, not as a note: a retired sha does not fail loudly, it
TAGS WITHOUT COMPLAINT. That is [[a-stale-target-makes-a-check-pass-harder-not-fail]], banked this
same arc after it bit at the r2->r3 transition, where this file's ff-merge and tag lines still
named the dead 25e60015. It is now poised to bite a THIRD time at r3->r4. A short sha and a full
sha are different strings; a dead sha and a live one are different strings; a find/replace that
reports "N changed" has told you nothing about the ones it missed.

RULE FOR THE NEXT DRIVER (possibly a post-recharge me): do NOT run a gate, an ff-merge, or a tag
off this file until the HEAD line above reads a sha doyle actually handed off, and you have
repointed the action lines yourself and COUNTED the remaining occurrences of the dead sha:
    grep -n 'c4919243' CASCADE-v0.68.0.md   # DONE: every remaining hit is history, classified
Classify every hit ACTION-vs-HISTORY. Do not count them and call it done.

## RIDER 5 — why the head moves (doyle, verified by him from source at c4919243)
hertz's Windows cell3 x5 at c4919243 went 4/5. The FAIL was the FASTEST run (14.591 s):
webserve_attachment_e2e.rs:551, the count-delta arm (ARM 11), raced ARM 10's deliberate 1 s-ttl
corpse against the 5 s reap pulse — a sibling of the arm-12 race the attachment rider already
retired, one arm up. Rider 5 is TEST-ONLY: it drops the count and asserts IDENTITY instead.
(Same shape as [[a-widened-wall-clock-margin-is-a-longer-coin]] — a count taken across a reaper's
pulse is a coin, not an observable. Identity is the durable observable.)

## OWED BY ME AT THE FINAL SHA — three items, none discharged by this amendment
1. INTAKE, REGISTRY HALF ONLY, re-read at the final sha. doyle keeps the board half closed
   (greenlit form unchanged, zero dropped / zero added). Record zero/zero explicitly — it is the
   EXPECTED reading, not a formality to skip.
2. IR-54 SHAPE RE-CHECK at the final sha. c4919243 arrived shaped, but a rider preserves shape
   only if it leaves Cargo.toml and CHANGELOG.md alone. That is a PREDICTION, not a measurement:
   read the first version line and the first CHANGELOG heading AT THE FINAL SHA.
3. REPOINT this file's action lines, then re-verify the preservation manifest.

## doyle's PREDICTIONS for the final sha — recorded so they can be FALSIFIED, not adopted
   diff confined to crates/spt/tests/webserve_attachment_e2e.rs · treqs untouched ·
   tag delta 0 · files 8
Measure each at the sha. A prediction that matches is evidence; a prediction assumed is a guess
wearing a peer's name. If any of the four misses, that is a finding for doyle BEFORE golden opens.

STILL TRUE, unchanged by rider 5: r3 is TEST-ONLY, the greenlit form of #272 is unchanged, the
counter is 104 and UNCONSUMED (nothing published from r1, r2, r3 or any a-attempt), and the box
stays untouched — no build, no pool claim — until dispatch.

# ===== RIDER-5 HEAD MEASURED (deployah 2026-09-09 ~04:0xZ) — HEADER STAYS PENDING =====
HEAD CANDIDATE = f6110c2a12df0dd50b87dfb60a2ec4120b5cf98d  (tree 0c9dfd6c5147…, parent c4919243)
NOT YET RIDDEN. doyle holds the ride call; the three ACTION lines stay pointed at the dead sha
until he says RIDE, precisely so they are repointed ONCE, to a sha that is final.

IDENTITY: 5 riders on 25e60015, ZERO merges, linear. Trailers 5/5 "Co-authored by:" space
spelling (raw body read — never %(trailers:), which returns a confident EMPTY on this project's
spelling). Rider 5 = "test(attachment): name the two entries, do not count the registry".

MY THREE OWED READS — DISCHARGED:
1. INTAKE, REGISTRY HALF: **ZERO DROPPED / ZERO ADDED**, proven by BLOB IDENTITY rather than
   re-derivation — traceable-reqs.toml is the same blob 21917ea9373fa28c0ca604947e6ee67dc0d5ef4d
   at 25e60015, c4919243 AND f6110c2a. Same blob = same registry; nothing to re-read. The 11
   activated REQ ids are unchanged. Tag delta across 25e60015..head is +1 / -0, the single
   `[int->REQ-INST-6]`, IDENTICAL to the intake baseline's recorded figure.
   ⚠ `traceable-reqs check` deliberately NOT run: it scans the WORKING TREE, and this session sits
   on another branch, so it would have measured the wrong tree and returned a verdict about it.
   Blob identity + tag delta IS the registry half; a green from the wrong tree would be worse than
   no reading. (Also: treqs exit 2 = unparseable registry, not a coverage miss.)
2. IR-54 SHAPE — **SHAPED, READ AT THE SHA, NOT INFERRED** from "Cargo/CHANGELOG untouched":
     root Cargo.toml line 19 : version = "0.68.0"     (all 13 workspace crates version.workspace)
     CHANGELOG.md line 13    : ## [0.68.0] - 2026-09-08
   NO version material owed from me. The sha doyle rides IS the sha golden runs and the sha tagged.
3. REPOINT -- DONE at RIDE (2026-09-09 ~04:1xZ), to the full sha. See the header and the foot.

doyle's FOUR PREDICTIONS, ALL CONFIRMED (recorded as falsifiable, measured not adopted):
     diff c4919243..head = crates/spt/tests/webserve_attachment_e2e.rs ONLY, +25/-7   CONFIRMED
     Cargo.toml / CHANGELOG.md / traceable-reqs.toml untouched                        CONFIRMED
     tag delta introduced by rider 5 = 0 added / 0 removed                            CONFIRMED
     files vs 25e60015 = 7                                                            CONFIRMED
   His own correction of an earlier "files 8" to 7 was right, and arrived BEFORE I measured it.

⚠ TRAP FOR THE NEXT READER OF INTAKE-BASELINE-272.md: a bare grep for REQ ids in that file returns
TWELVE distinct strings, not the eleven members. The activation table (its lines 45-55) is the
membership and lists ELEVEN — REQ-XFER-RETIRED IS one of them (close rider, ADR-0060). The twelfth
string, REQ-INST-6, occurs ONLY in the tag-delta note at line 86 and is NOT a milestone member.
A grep COUNT is not the membership; read the table.

STILL TRUE: counter 104 UNCONSUMED, box untouched by me (no build, no pool claim), the seven
acceptance criteria unchanged, and the close-note line "heading dated 09-08, tagged 09-09Z, left
to keep the proven tree" still carries — the heading date is unchanged at this head too.

# ===== hertz RE-PROOF AT f6110c2a — CLEAN (reported 2026-09-09 ~04:06Z) =====
BOX QUIET: no cargo of hertz's on hfenduleam or kitsubito; every r3 leg finished.
Re-proof at the committed head f6110c2a (tree 0c9dfd6c), NOT at a working tree:
  clippy      : exit 0 BOTH OSes
  treqs       : exit 0   <- this is the WORKING-TREE check my blob-identity read deliberately
                           did not attempt (a foreign-branch scan would have judged the wrong tree)
  cell3       : 10/10 Windows, 5/5 Linux; every run ONE Summary line and one passed
  diff        : one file, crates/spt/tests/webserve_attachment_e2e.rs, +25/-7 — matches my read
WHY c4919243 HAD TO BE SUPERSEDED, in a number: its cell3 measured 26.7% FLAKY ON WINDOWS,
4 reds in 15. Tagging c4919243 would have shipped a known-flaky cell. This is the whole reason the
header was forced to PENDING; keep it with the sha, not in a chat log.

⚠ BOX-QUIET IS A PRECONDITION, NOT A FACT TO CARRY. It was true at 04:06Z. RE-MEASURE the census
and the free-space read yourself at gate time — a quiet box goes busy without telling you, and the
whole point of gate 2 is that it reads the box AT DISPATCH.

RIDE ARRIVED 2026-09-09 ~04:08Z (doyle). The three ACTION lines (26, 27 ff-merge; 33 tag) are
REPOINTED to the full
40-char sha f6110c2a12df0dd50b87dfb60a2ec4120b5cf98d -- done ONCE, at a final sha, as designed.
Every remaining c4919243 / 25e60015 occurrence in this file is HISTORY, classified line by line.

# ===== GOLDEN r3 DISPATCHED — deployah 2026-09-09T04:19:19Z =====
RUN 34310511612  attempt 1  branch golden/webserve-272-r3  headSha f6110c2a12df0dd50b87dfb60a2ec4120b5cf98d

DISPATCH METHOD: pushed the OBJECT, never a branch name (doyle ruling 1, 2026-09-09 ~04:19Z):
    git push origin f6110c2a12df0dd50b87dfb60a2ec4120b5cf98d:refs/heads/golden/webserve-272-r3
The branch name r3-gate-head is a TRAP: it points at 3fef8375, whose tree be2184af IS c4919243 tree
exactly — riders 1-4 re-committed, NO rider 5, the 26.7%-flaky-on-Windows tree. doyle measured the
same in his store: f6110c2a is on NO branch, held only by the detached worktree gate-r3-25e60015.

doyle-REQUIRED VERIFICATION, both lines measured AFTER the push, recorded BEFORE the run id:
    git ls-remote origin refs/heads/golden/webserve-272-r3
      -> f6110c2a12df0dd50b87dfb60a2ec4120b5cf98d   (equals the ruled sha)
    git rev-parse f6110c2a12df0dd50b87dfb60a2ec4120b5cf98d^{tree}
      -> 0c9dfd6c514c73d65823f855062d5505437c0750   (equals the ruled tree)

GATE SCRIPT: gate-r3-dispatch.ps1 (this dir) SUPERSEDES gate3-dispatch.ps1, which was an r2
artefact with two stale-target defects, BOTH confirmed by doyle in his own store and approved:
  D1 its permit arm ran `gh run rerun <run> --failed`. A rerun runs at the RUN’s own head sha, so
     it would have run golden at the DEAD 25e60015 whatever -Sha said; -Sha was read only by the
     post-dispatch echo, i.e. after the wrong run was already going. golden.yml triggers on
     `push: branches: [golden/**]` — the dispatch is a PUSH.
  D2 its gate 1 asked "is run <id> terminal" against a DEAD run, which answers that HARDER than a
     live run would. Gates 1 and 3 are re-scoped to zero non-completed runs repo-wide; there is no
     pre-existing r3 run to exclude, and an exclusion is exactly what let a dead run pass.
  Also fixed: gate 7 pointed at ANOTHER SESSION’s scratchpad; under ErrorActionPreference=Stop a
  vanished path THROWS rather than failing the gate. It now uses the preserved in-repo verifier.
  NEW -DryRun switch: runs every gate and the whole permit arm except the push. The r2 permit arm
  was unproven BY CONSTRUCTION because it had no such switch. Dry run exit 0 at 04:18:31Z.

EIGHT GATES, measured at 04:19:01Z immediately before the push (not carried from the dry run):
  gate0 sha_identity   type=commit tree=0c9dfd6c...750 == ruled tree            PASS
  gate1 golden_idle    non_completed_golden=0                                   PASS
  gate2 runner_quiet   hfenduleam busy=False status=online (kitsubito idle too) PASS
  gate3 queue_empty    non_completed_any=0                                      PASS
  gate4 free_space     145575067648 B = 135.58 GiB (need >=110)                 PASS
  gate5 no_user_cargo  user_rooted=0 total_builders=0                           PASS
  gate6 kitsubito_quiet builders=0 load=0.00 0.01 0.36                          PASS
  gate7 acl_open       verify-acl-grant.ps1 exit=0                              PASS
RECORD LINES, verbatim, NOT gates:
  defender exclusions (non-admin): "N/A: Must be an administrator to view exclusions"
    ^ a REFUSAL SHAPED LIKE A VALUE. It is not evidence of absence and never was.
  defender real-time protection: True
  qbittorrent at dispatch: RUNNING pid=47056

FREE-SPACE RECONCILIATION: my 133.0 GiB and doyle’s 137.0 GiB earlier readings were never
reconciled; the gate read its own number at dispatch (135.58 GiB) rather than carrying either.

.spt/ HOLD (doyle standing, todlando independently confirmed): .spt/ is untracked AND UNIGNORED.
Stage by PATH only; never `git add -A`/`git add .` at either repo root — it would stage the r2/r3
evidence and ~325 MB of prebuilt xtask binaries. The golden dispatch is a ref-to-sha push of
already-committed objects, so it carried NO working-tree state.
TRAP, verified here: `git check-ignore -v ".spt/preserved/"` (TRAILING SLASH) returns rc=0 citing
.gitignore:20 — a BLANK line. A fabricated match whose only tell is an EMPTY pattern field. Probed
the correct way, by a REAL FILE PATH with no trailing slash:
    git check-ignore -v .spt/preserved/golden-272-r3-drive/CASCADE-v0.68.0.md  -> rc=1 (NOT ignored)

NEXT: the SEVEN acceptance criteria against run 34310511612 ONLY. Expect NINE jobs — the twohost
legs and `notify` materialize LATE, so an early job list is not the run’s job set. The Windows
"Docs drift gate" STEP conclusion must read success; it has SKIPPED FIVE TIMES and a skip is NOT a
pass, and a green LINUX docs gate is not Windows evidence. Read the STEP, never the job.

# ===== GOLDEN r3 RESULT — RED — deployah 2026-09-09T05:29:57Z =====
Run 34310511612 attempt 1, headSha f6110c2a...cf98d (re-read from the API, matches the ruled sha).
NINE jobs materialized (twohost legs + notify included). EIGHT green. ONE red:
  FAILURE  test (self-hosted, Windows, hfenduleam)   [Phase B, heavy class, serialized]

THE RED AT SOURCE — Windows Phase B, test 69/234:
  FAIL [71.881s] spt::resident_service_e2e a_declared_service_rises_with_the_daemon_and_reaches_the_cli
  panicked at crates/spt/tests/resident_service_e2e.rs:670:5 — "teardown LEAKED":
    survivor pid 25596, srcs/svcboot/svcmock.exe
    settle: went_clean=false after 60.6070532s of a 60s budget
The FUNCTIONAL assertions ALL PASSED — the rig’s own line reads daemon_up=true boot_alive=true
rel_started=true broker_survived=true rel_online=true dir_online=true survived_teardown=true with
the spooled message present. The failure is entirely TEARDOWN HYGIENE, not the feature under test.

HYPOTHESIS (deployah, FALSIFIABLE, NOT a ruling — doyle owns triage): the rig reaps the supervised
CHILDREN BEFORE THE SUPERVISOR. Reap order was boot(53100 svcboot) -> rel(25012 relshell) ->
brain(42716) LAST, all verdict=KILLED. Survivor 25596 is the SAME IMAGE as the already-killed
53100. A supervisor doing its job would restart the service between the boot kill and the brain
kill. If so this is a RIG ORDERING RACE and the product behaviour is CORRECT supervision.
TO KILL IT: the rig records started_at for every pid it REAPS but not for the SURVIVOR. Capture the
survivor’s start time — after the boot kill proves respawn, before it kills the hypothesis.
COUNTER-INDICATION, recorded against my own hypothesis: settle burned the FULL 60.607s of a 60s
budget, i.e. it NEVER read clean. The rig’s own message says a SHORT wait with survivors listed
means late appearance — a different defect. Full-budget fits "alive throughout" at least as well as
"respawned early". Those two are NOT separated yet.

#272’S OWN PRODUCT IS GREEN ON WINDOWS — the red sits outside the milestone surface:
  PASS [16.022s] (77/234) spt::webserve_attachment_e2e an_attachment_is_snapshot_served_fetched_back_and_named_by_its_message
      ^ the EXACT cell rider 5 fixed; the structural fix held on the box that measured 26.7% flaky.
  PASS [26.317s] (78/234) spt::webserve_cross_node_e2e a_peers_url_is_served_by_its_owner_through_the_local_listener
  both twohost web legs green, role B verified BY B’S OWN SERVED COUNT (see C6).

SEVEN CRITERIA:
  C1 FLOOR_DOCS       NOT MET — only the LINUX docs floor ran (PASS). The Windows docs-floor step
                      SKIPPED downstream of the step-21 failure. A green Linux floor is not Windows
                      evidence, by the same rule that governs the drift gate.
  C2 Win docs drift   NOT MET — step 38 SKIPPED, its SIXTH consecutive skip. A skip is not a pass.
                      Downstream of the failure, so it cannot be assessed on this run at all.
  C3 FLOOR_END        MET on every job incl. both Windows (test Win free 87339024384 = 81.3 GiB).
  C4 Summary == 2     MEASURED 4. The CRITERION is mis-specified for the A/B phase split, NOT a red:
                      2 legs x 2 phases, each leg exactly one Phase A and one Phase B. This is NOT
                      the doubled-run signature the "==2" rule exists to catch, so the FAIL
                      attribution is sound. Correct invariant under the split: 2 per leg / 4 total.
  C5 role_a on A      MET — twohost-a green; two_host_web_helper_role_a ok, deny/fetch/range ok.
  C6 role_b on B      MET, from B’S OWN emission not A’s poll: "TWOHOST-WEB role B: served cell
                      1/5..5/5", "role B served all 5 requester cells", two_host_web_role_b ok.
  C7 terminal/all green/NINE  terminal YES, NINE YES, all-green NO (1 of 9).

INSTRUMENT DEFECT, DISCLOSED: accept-r3.sh used the `jq` BINARY, which is not installed on this box.
Every jq-backed criterion printed FAIL when the reading was VOID — it claimed "job count < 9" and
"no Windows Docs drift STEP found" purely from jq’s absence; both were FALSE (there were 9 jobs and
the step exists, skipped). Re-read with gh’s BUILT-IN -q and the raw jobs endpoint. The script is
preserved AS RUN, defect included, rather than silently repaired. This is the extractor-exit-code
trap firing in my own instrument one arc after I banked it.

A QUESTION, NOT A FINDING: the failing test’s stderr carries, in its "add (no daemon)" phase,
  ADAPTER_WEB_PENDING: serving registry reconciliation failed: The system cannot find the file
  specified. (os error 2); retry at the next daemon start
the only webserve-shaped line in the one red test of a WEBSERVE milestone. It sits where a pending
state looks expected by design. NOT chased, NOT claimed as a defect — raised for doyle to rule.

STATE: nothing rerun, nothing merged, nothing tagged. Counter 104 UNCONSUMED. origin/main still
e4444413. No v0.68.0 tag. Branch golden/webserve-272-r3 exists on origin at the ruled sha.
Same-sha rerun is doyle’s call, not mine.


# ================= GOLDEN r3 ATTEMPT 2 — dispatched 2026-09-09T05:44Z, deployah =================
SOURCE OF EVERY RULING IN THIS SECTION: msg-doyle-29-triage-ruling.txt (preserved verbatim beside
this file). Nothing here is my own call except the gates and the mechanics of the rerun call.

## DOYLE'S TRIAGE OF ATTEMPT 1 — LEDGERED-CLASS, outside the milestone surface
FOURTH classified occurrence of docs/FLAKE-LEDGER.md's `spt::resident_service_e2e` teardown-LEAK
row: 08-04 run 30940180764 · 08-30 run 33296634901 att1 · 09-06 run 34017906638 att3 · 09-09 att1.
All hfenduleam Windows golden. Assert text BYTE-IDENTICAL between 04e32c8c:664 and f6110c2a:670
(the line moved by 8d10b280, which is on main); `git diff e4444413 f6110c2a -- <test>` is EMPTY —
ZERO riders touch it. Same survivor class as 08-30 and 09-06 (svcboot mock, went_clean=false at the
FULL 60 s budget, three reap verdicts Killed, functional half all TRUE).

MECHANISM as far as evidence carries it — MY hypothesis with doyle's supervisor HOST pinned: the
test does `let _ = spt daemon stop --force` (:389, RESULT DISCARDED), then authenticated-kills boot
53100 -> rel 25012 -> brain 42716 -> broker handle. The BRAIN hosts the service supervisors, and was
PROVABLY ALIVE when boot was killed (its own reap verdict afterwards is KILLED, taskkill SUCCESS on
42716 and on child 50480). servicehost.rs:794-880: an exit the supervisor did not ask for, with
neither stop nor hold set, goes on_exit -> ExitAction::Relaunch. A relaunched svcboot (25596, same
image as 53100) in the boot-kill..brain-kill window is the consistent shape. NOT PROVEN — the
SERVICE_EXIT/relaunch line lived in the brain's stderr sink in the temp sandbox the job cleaned.
MY COUNTER-INDICATION IS ANSWERED, NOT WAVED: a respawned child nobody kills is alive for the whole
settle, so the full-budget settle never reads clean either way — it does not discriminate.
REPAIR = a RIG ordering fix, hertz, POST-PUBLISH: observe the daemon-stop result, kill the
supervisor host BEFORE its children, capture the survivor's start time.

## DECISION EXECUTED: same-sha rerun of the failed job
Precedent doyle cited: 08-30 att2 re-executed this cell PASS 5.16 s; r2 att4 ran it PASS 11.48 s.
doyle's measured input, 05:35Z: ZERO svcmock.exe and ZERO runner-scoped spt.exe on hfenduleam (CIM,
not tasklist) — survivor 25596 gone. I RE-MEASURED rather than inherit it (gate 8 below).
hertz + todlando stay OFF cargo through attempt 2. doyle releases them, not me.

## GATES — gate-r3-rerun.ps1, NINE, all True, printed before the command fired
A NEW SCRIPT, not gate-r3-dispatch.ps1: that script's permit arm PUSHES A SHA to golden/**, which is
how r3 was dispatched. This is the opposite verb — the run exists and is re-run IN PLACE so this
sha's evidence stays ONE run id. An inherited gate script carries the previous dispatch's METHOD.
BOTH ARMS PROVEN: -DryRun at 05:43:34Z reached the permit branch and printed the exact rerun command
without spending it; the real fire followed at 05:44:11Z.
  gate0 target_run     completed/failure attempt=1 headSha=f6110c2a...cf98d workflow=golden
        (terminal is a REAL precondition here because the run is the TARGET, not a bystander; the
         thing terminal cannot tell you — that the rerun lands on the ruled sha — is asserted
         separately as headSha equality)
  gate1 golden_idle    non-completed golden, target excluded = 0
  gate2 runner_quiet   hfenduleam busy=False status=online (kitsubito also online, busy=False)
  gate3 queue_empty    non-completed repo-wide, target excluded = 0
  gate4 free_space     140614541312 B = 130.96 GiB (floor 110)
  gate5 no_user_cargo  user-rooted 0 of 0 total (parent-chain-root attribution)
  gate6 kitsubito_quiet builders=0 load=0.00
  gate7 acl_open       verify-acl-grant.ps1 exit 0
  gate8 no_survivors   svcmock.exe=0 · spt.exe total=14, runner-rooted=0   [NEW THIS ATTEMPT]
RECORD LINES (not gates, quoted never inferred):
  defender exclusions: "N/A: Must be an administrator to view exclusions" — a REFUSAL SHAPED LIKE A
    VALUE. Never read it as absence.
  defender real-time protection: True
  qbittorrent at dispatch: RUNNING pid=47056
FREE-SPACE TREND, flagged not blocking: 275.74 -> 197.23 -> 130.96 GiB across the three dispatches
of this milestone. Still 21 GiB above doyle's floor; the r2 in-job footprint measured 67.4 GiB, so
the projected trough is ~63.6 GiB against a 32 GiB in-job floor. Comfortable this run, and the trend
is a thing to look at before a fourth.

## DISPATCH RECORD
  gh run rerun 34310511612 --repo BigscreenVR/spt-bs-core --failed   exit 0
  post-rerun VERIFIED IN THE SAME SCRIPT: attempt=2 · status=in_progress ·
  headSha f6110c2a12df0dd50b87dfb60a2ec4120b5cf98d UNCHANGED.
  Log: r3-a2-dispatch.log (tee'd as run).
WATCH RE-ARMED: watch-a2.ps1, detached pwsh pid 49016, log r3-a2-watch.log, polls every 120 s and
exits ONLY on completed AND run_attempt >= 2. A watcher that exits on "completed" alone is satisfied
by the DEAD attempt-1 record and goes blind to the attempt it was armed for (r2 lesson, re-applied).
First poll 05:45:18Z: run in_progress attempt=2, jobs 5/6, notgreen 0. COUNT READS 6, EXPECT 9 —
twohost-a/b and notify are `needs: test` DEPENDENTS and materialize after test(Windows).

## CRITERIA FOR ATTEMPT 2 — as doyle ruled them
  C1 FLOOR_DOCS (Windows)  RE-EARNED at attempt 2. Not carried from attempt 1.
  C2 Win docs drift        MUST BE EARNED at attempt 2 — it reruns with the Windows test job.
                           SKIP != PASS stands. It has now skipped SIX times at this milestone.
  C3 FLOOR_END             met at attempt 1; re-read at attempt 2 with the rest.
  C4 Summary               AMENDED BY DOYLE, this message its source: the invariant under the A/B
                           split is EACH LEG carries exactly ONE Phase A and ONE Phase B Summary
                           (4 total across two legs). >1 of either phase ON ONE LEG is the
                           doubled-run signature. The attempt-1 reading of 4 was therefore CORRECT,
                           and the "==2" spelling was the defect, not the run.
  C5 role_a on A           carried greens keep their attempt-1 records; re-read at terminal.
  C6 role_b on B           same, still FROM B'S OWN SERVED COUNT, never A's poll.
  C7 terminal/all green/NINE.
READING THE VERDICT: pass run_attempt in the same command; carried jobs dedupe on
(run, box, started_at).

## MY ADAPTER_WEB_PENDING QUESTION — doyle's disposition
Recorded as a QUESTION for the register/seeded lane, NOT a gate item. He is reading its emit site
and the green Linux leg for the same line. It does NOT move the rerun. Do not re-raise it as a
blocker on this run.

## STILL TRUE AT ATTEMPT 2 DISPATCH
origin/main e4444413 · no v0.68.0 tag local or remote · counter 104 UNCONSUMED · nothing merged,
tagged or published · branch golden/webserve-272-r3 on origin at the ruled sha.
STOP CONDITION: a THIRD attempt at this sha is doyle's call, never mine.

## STANDING NOTE FOR THE NEXT GATER — how to read a per-OS STEP, and how not to
## (doyle ruled this into the CASCADE 2026-09-09 05:58Z, after it bit my own reader)
THE WORKFLOW PROPERTY: the WINDOWS test job carries BOTH OS VARIANTS of every floor and drift
step, with the wrong-OS one SKIPPED. Measured on r2 34262154550 attempt 4, verbatim step list:
  35 skipped  DISK docs floor (Linux)
  36 skipped  Docs drift gate (CLI ref + llms links) — linux
  37 skipped  DISK docs floor (Windows)
  38 skipped  Docs drift gate (CLI ref + llms links) — windows
  43 success  DISK end floor (Windows)
  44 skipped  DISK end floor (Linux)
CONSEQUENCE: a SUBSTRING step match inside the Windows job can hand back the LINUX step's
conclusion for a WINDOWS criterion. That is the exact collapse C2 exists to prevent — "a green
Linux docs gate is not Windows evidence" — except it happens INSIDE THE INSTRUMENT, with no Linux
job anywhere in the reading to make it look wrong. On the control run every candidate happened to
be skipped, so the two readings agreed and the defect was survivable BY LUCK; on a run where the
Windows step passes and the Linux one is skipped, a pick-first reader returns whichever jq emits
first.
HOW TO READ IT CORRECTLY (this is the C2 criterion as doyle means it):
  - select the job by EXACT name, and ASSERT exactly one job carries it in the attempt;
  - select the step by an ANCHORED predicate, never a substring:
      floors      .name == "DISK docs floor (Windows)" / "DISK end floor (Windows)"
      drift gate  startswith("Docs drift gate") and endswith("windows")
      ^ written as startswith/endswith deliberately, so no EM DASH has to survive a shell round
        trip for the match to be correct;
  - treat a MULTI-LINE answer as VOID, never as a value. A column that must hold ONE value is
    only read correctly when >1 is an ERROR — pick-first and compare-the-concatenation both mint
    confident wrong verdicts, and both fail toward something that LOOKS like a measurement.
Reference implementation: accept-r3-a2.sh beside this file. accept-r3.sh is preserved AS RUN with
its original jq defect and must not be repaired in place.

# ========== ATTEMPT 2 OUTCOME: test(Windows) CANCELLED BY THE JOB TIMEOUT, NOT FAILED ==========
# deployah 2026-09-09 ~06:40Z. Handed to doyle as msg-doyle-32.txt. NOT a test red. NOT the
# ledgered class. Do not triage it as either.

## PHASE B PASSED. The ruling worked.
  step 19  Test — Phase A — windows   SUCCESS  05:51:42 -> 06:08:56Z  (17m14s)
  step 21  Test — Phase B — windows   SUCCESS  06:08:56 -> 06:29:21Z  (20m25s)
The resident_service_e2e teardown-LEAK cell CLEARED on the same-sha rerun, as the 08-30 att2 and
r2 att4 precedents predicted.

## WHAT KILLED IT — arithmetic, not inference
golden.yml:166 at f6110c2a carries `timeout-minutes: 50` on the test job.
  job start 05:44:37Z · first step 05:44:39Z · job end 06:35:16Z = 50m39s
  step 30 "Real-shell E2E (notify) — windows" CANCELLED 06:34:38Z = 49m59s after step 1 began
The 50-minute wall to the second. GITHUB REPORTS A TIMEOUT KILL AS `cancelled`, NEVER `failure` —
a run-level or job-level `cancelled` on this workflow should be checked against the job's own
duration BEFORE anyone reaches for a cancellation story or a test triage.

## THE STRUCTURAL FINDING — C1/C2 ARE UNREACHABLE AT THIS BUDGET
Attempt 2 ran four steps ATTEMPT 1 NEVER REACHED, because a FAILING Phase B short-circuits to
cleanup and a PASSING one does not:
  23 Doctests — windows  success 1m04s · 25 Clippy  success 3m31s · 26/27/28 notify  success ~21s
  30 Real-shell E2E (notify)  CANCELLED at the wall
Steps 31-42 then never ran — including the whole docs block: 34 reap-before-docs-build, 35/37 DISK
docs floor (Linux/Windows), 36/38 Docs drift gate (linux/windows), 39 Docs bundle drift gate.
=> C1 and C2 are NOT "skipped behind an upstream failure" this time. They are UNREACHABLE INSIDE
THE JOB'S OWN BUDGET once everything ahead of them passes. A GREEN Phase B costs MORE wall-clock
than a red one, so THE FAILURE WAS MASKING THE WALL. Attempt 1 finished 48m39s — within 1m21s of
the same timeout WHILE FAILING EARLY. The margin was already gone and could not be seen.
Every earlier skip was correctly attributed to the failure above it, and that correct attribution
is exactly what hid this.

## NOT MEASURED, so do not quote it as measured
How long steps 30-42 actually take on Windows is UNKNOWN — they have never run to completion at
this milestone. "The job needs ~60-70 min" is an ESTIMATE. What IS measured: 49m59s bought
everything through step 28, all green.

## STATE AT THIS ENTRY
twohost-a + twohost-b STARTED 06:35:19Z, three seconds after the cancel, under `!cancelled()`
independence — C5/C6 evidence is being produced and THE RUN IS NOT TERMINAL. Each carries its own
40-minute window; terminal expected ~07:15Z.
Raising `timeout-minutes` or splitting the Windows test job is a WORKFLOW CHANGE — a rider, a new
head, a fresh golden under the intake rules. That is a milestone-shape decision and it is doyle's,
not a rerun mechanic. Nothing rerun, merged, tagged or published. Counter 104 unconsumed.
origin/main still e4444413.
