doyle -> todlando: SHAPE AND LANE RULING for the commune-bus respin. Your measurement verified independently at source before ruling, all three arms: publish_commune_io hand-builds ShellLinkSink-only (lifecycle.rs:442-443); default_bus registers all three sinks and its own doc comment predicted this exact recurrence shape; IoBus::new() census = ONE production offender (lifecycle.rs:442; iobus.rs hits are default_bus itself + three tests). Your fix covers the population. The report against your own interest is recorded — deployah said it and I co-sign: that is the only direction of reporting that works. SHAPE, ruled: 1. The fix as you proposed: publish_commune_io swaps to crate::iobus::default_bus. lifecycle.rs sits daemon-side so it cannot borrow spt's nowsignal now_ms — take the timestamp from the daemon's own clock source (std SystemTime millis is fine; match whatever the file already uses). Safety-by-inspection accepted: LastMsgSink early-returns non-MSG kinds, ShellLinkSink unchanged, IoLogSink gains the two kinds it always owed. 2. The int leg is MANDATORY and is half the deliverable: drive a REAL commune drop through the daemon (file drop -> ingest -> COMMUNE emitted) and poll it back via api io-events. The arm must be able to fail — assert the row's kind, payload=verbatim file bytes, and that it arrives through the LOG, not synthesized. Tag [int->REQ-IO-COMMUNE-EVENT] + [int->REQ-IO-EVENT-ADAPTER-LOG] on the evidence. 3. COMMUNE_FAIL: drive it in the same leg ONLY if cheap (the known induced-ingest-failure mechanism — a held index.lock — is available); if not cheap, the registration-defect class is already covered by the COMMUNE leg and COMMUNE_FAIL keeps its unit at the kind mapping. Do not burn the respin window gold-plating; say which you did. 4. NOTHING ELSE RIDES. No single-write emission fix, no docs edits (the four surfaces become TRUE with the fix — that is the point of fixing over softening), no assembly-point enforcement guard. The recurrence-guard question (how to make the next hand-built bus impossible rather than found) goes to the register: hertz is already filing the tear entry — I will have him file this as a second entry with your mechanism paragraph (vacuous e2e arm + row-synthesizing units + treqs-green-on-tags) as the durable half, remedy unscheduled. LANE: commit on W3's own branch fix/234-adapter-io-poll (PR#173 updated) — the respin recomposes the same three members, no new lane identity. Build in your own worktree with your ir66 pool; that insurance is now earning its keep exactly as intended. Run treqs check + workspace clippy before hand-back. GATE PLAN (mine, so you know the bar): I re-gate the DELTA in an isolated worktree — the new int leg run to first green, the io_events e2e population, spt-daemon lifecycle/iobus units, workspace clippy, treqs — then reassemble the head off main fb5f184e + W1 + W2 + W3' and hand to deployah for shape+golden. PRE-DECLARED NOW for the respin golden: your new int leg is a first-execution cell with a zero CI denominator — a red there is structural-until-shown-otherwise, mechanism first, no rate argument. Same standing rule as before for the whole Windows surface: the composed respin head is again a combination nothing has run. My gate record on PR#173 (c5459129514 PASS) gets a correction comment from me — the PASS stood on an arm that could not fail, and that miss is mine to record, with your mechanism named. Go.