> RELEASE sub-index — split out of MEMORY.md 2026-08-04 against the read-limit cliff (index was
> 23926B against a 24986B limit, ~1KB margin; the tail drops SILENTLY, and this file's own record
> shows that recurring once already when sessions kept appending). Entries below are VERBATIM from
> the index, ZERO pointers dropped — this is a move, not a compaction. The 17.1KB nag stays refused
> per the ⛔ ruling in [two-memory-roots-diverged](two-memory-roots-diverged.md); splitting a
> consult-class section is the FOURTH lever that ruling names, and Release was the candidate it
> named next. Read this when working a release, a tag window, or a milestone close.

## Release
- [milestones skip WIP: GREENLIT goes straight to ACCEPTANCE](milestones-skip-wip-greenlit-goes-straight-to-acceptance.md) doyle 2026-09-09 from LABEL TIMELINES (#272, #23): a milestone reading `state: greenlit` late in its build is CORRECT; `type:` stays unset (request-level); prose saying "this comment is the flag" made no label. AGENTS.md's WIP chain is the REQUEST chain.
- [a step that STRADDLES an irreversible action reads as done AT the action](a-step-that-straddles-an-irreversible-action-reads-as-done-at-the-action.md) x2 v0.67.0: drove step 6's pre-publish cascade, published, verified publish, STOPPED — the post-publish `release` verb (DONE promotion + roundup) never ran, #23 + 8 members sat CLOSED-but-ACCEPTANCE ~50min, card empty, OPERATOR caught it. Every check I had passes with the board unfinished (they measure the ARTIFACT; the miss is on the BOARD) and I reported the arc closed. The verb WAS documented — measuring the file refuted the "doc gap" framing I was handed, so the fix was SHAPE not addition. Split straddling steps into two ticks; re-read from the top after the big event.
- [release-verb grace vs hub-card strict window](release-verb-grace-vs-hub-card-window.md) ⭐ post-publish cascade = board card off-by-one (GitHub right, display wrong; never repair states); fix = spt-progress-tool#78
- [greenlit form = the DELTA SEQUENCE](greenlit-form-is-the-delta-sequence-not-its-head.md) ⭐⭐ STANDING intake rule (doyle 2026-08-21): fold ALL deltas in order before comparing head to greenlit form — #212 delta 1 said "no member added/dropped/relocated" (true when written), delta 2 CUT #153 and minted #213 into its slot. First-alone refuses a good head; latest-alone loses the baseline. Cite the pair you folded.
- [ledger](v0121-published.md) — latest **v0.68.0 c104 @`a2f335f8`** (2026-09-09T09:36:41Z, WEBSERVE #272 + 4 merge-closed riders #276/#277/#279/#280, 13 DONE; tag==main==golden-tested sha; golden 34322232036 9/9 att1 at r4 after r1/r2 reds closed at mechanism, r3 att1 ledgered teardown-LEAK + att2 killed by the 50-min job WALL (rider 6 = CI-only 50->80/25->40 on parent f6110c2a); Windows test 54m35s, docs-drift step EARNED first time after six skips; measured: a green Windows job costs MORE wall than a red one, so every earlier drift skip flattered the budget; record GATE-W2-272-CHECKLIST.md at repo root). Prior **v0.67.1 c103 @`04e32c8c`** (2026-09-06, docs PATCH #274, [arc](v0671-arc-service-docs.md)); **v0.67.0 c102 @`da71b785`** (2026-08-30, NOW-SIGNAL #23, [arc](v0670-arc-in-flight.md)); **v0.66.0 c101 @`d931dd63`** (2026-08-30, SEMAPHORE #242, [arc](v0660-arc-in-flight.md)); **v0.65.0 c100 @`4d6007ac`** (2026-08-29, CONDUIT #236, [arc](v0650-arc-in-flight.md)) -- these four were MISSING from this ledger line until 2026-09-09 (measured: zero v0.65-v0.67 mentions in the file). Prior **v0.64.0 c99 @`ba36f221`** (2026-08-28 ~09:20Z, IO-PARSER #22, [note](v0640-arc-io-parser.md); members #12/#226/#233, zero dropped/added, board DONE all four. tag==main==golden-tested sha `ba36f221` (deployah's shape commit was the tip — the head arrived a version behind and was shaped BEFORE the golden, so no provability-bar route needed; respins would have rebased onto the shape commit). Golden 33149474948 GREEN at attempt 2: attempt-1's two Windows reds were DISK-FLOOR refusals with checkout SKIPPED (diff never on box; 7.1 GB vs 32 GiB floor, cleared by two classified target reaps totalling ~101 GB), same-sha partial rerun both green end-to-end, twohost passing the identical floor step = positive control. Six lanes (W1-W5 + docs, PRs #162-#167) + two hertz riders (#161 IR-66, #168 reap-carrier) rode ONE assembly merge — the wave stack was linear, all six gated individually pre-assembly, zero golden respins. POST-PUBLISH CONTRADICTION referred by deployah and ruled test-side: thin ci.yml Windows unit red at the SAME sha (servicehost orphan-reap cell, KillFailed(pid) at the 2s awaits_death budget, 3.649s at-budget vs golden's 0.106s, ran in the release build's tail) — product treats KillFailed as RETRYABLE (record kept for next sweep) while the test demands first-sweep Killed, so the cell binds tighter than its contract; hertz rider dispatched. main advanced ONE docs commit past the tag (91638eda register sweep) — expected post-tag gap, ancestry green.) Prior **v0.63.0 c98 @`dbe3daad`** (2026-08-26T01:35:09Z, FIELD-SEAL #225, [note](v0630-arc-in-flight.md); 8 members, zero dropped/added. **THREE respins, all the SAME Linux/kitsubito Phase B leg, THREE DIFFERENT victims, each run’s prior victim recovering — the RANDOM-VICTIM family (IR-30’s signature, Linux face). r2 and r3 were the SAME SHA, which is the arithmetic that exonerates the tree: a tree defect does not migrate between cells across re-runs of one commit.** All three victims were TEST defects, product never implicated: r1 `input_ack_deadlock` (real, latent since v0.61.0 `53be5270` — see [[a-tests-banner-can-go-stale-against-its-own-assert]]), r2 `er_brief` (declared PRECONDITION, proves nothing when it trips), r3 `resume` spawn-first-chunk needle (0.824s cell dying at 62.7s). ESCALATED to the operator after r3 on doyle’s own pre-commitment (option A, root-side audit); mechanism = kernel audit backlog bursts from 14:00Z with default `audit_backlog_wait_time` **60s**, matching the 59.4/62.7s deaths — a WINDOW-STRETCHER that made an existing spawn-race reachable, NOT the fault. Discriminating evidence was a same-box same-window pair 5 min apart: light `unit` leg GREEN vs heavy SERIALIZED Phase B RED — see [[presence-under-both-outcomes-refutes-the-argument-not-the-cause]]. **tag==main==golden-tested sha**, shape-on-top surviving THREE respins (fixups landed ON TOP of the version material, so zero re-shape and no provability bar ever applied). ⭐⭐ **THE PUBLISH FAILED WHILE THE HARNESS REPORTED SUCCESS**: the background-task notification said "exit code 0", the leg’s own exit FILE said **101**. Writing the leg exit to a file is what stood between me and announcing a release that was still a draft — read the FILE, never the wrapper/notification. ⚠ The failure was `SPT_POOL_FOREIGN`: main `target/` still carried POOL-OWNER.json naming the VANISHED `.worktrees/assembly-signet-218` (the v0.62.0 lane). Nothing was signed/flipped — draft verified intact first. Takeover justified on all THREE arms the rule names (worktree vanished + branch `feb4049a` an ancestor of origin/main + no lane claimed), claimed with the hatch the build script itself prescribes, released after. ⚠ **A CACHED BUILD SCRIPT REPLAYS ITS STORED WARNING**: the SUCCESSFUL publish build still printed the `SPT_POOL_UNCHECKED` override text naming the old worktree, in an 0.85s run where build.rs never re-ran and the flag was NOT set — a future reader grepping that log will see an override warning on the shipped commit and be wrong about it. Post-publish board close is DRIVEN not swept: `state <mref> acceptance` before publish, then `release v0.X.Y`; the state verb needs the **`#N`** ref form — bare `225` errors, and the SHELL_SPOOLED receipt returns exit 0 REGARDLESS, so verify the BOARD, never the spool. RE-HIT deployah 2026-09-09 #272 v0.68.0: bare `272` spooled exit 0, async 'bad ref' seconds later; rule was in this line and was repeated anyway -- it belongs in the cascade's command text, not here.) Prior **v0.62.0 c97 @`12ab4a7a`** (2026-08-25T02:24:31Z, SIGNET #218, [note](v0620-arc-in-flight.md); ONE respin over a Linux-only clippy dead-const; **tag==main==golden-tested sha**, the second cut running the shape-on-top form and the first where it survived a RESPIN — the fix landed on top of the version material, so no re-shape. ⭐⭐ **HOLD A RED GOLDEN RUN TO COMPLETION**: twohost is `needs: test` + `!cancelled()`, so the pre-declared never-executed S1e rung climbed and PASSED at the RED sha and that evidence transferred to the respin. Respin fired on a **FRESH ref** `golden/signet-218-r2` — golden's concurrency keys on `github.ref` with `cancel-in-progress: false`, so reusing the old ref queues behind the dead run's group and misattributes the respin later. Uncovered-by-name: Dormancy steps 38/39/40 ran in NEITHER run on EITHER OS, proven condition-derived by the r1 Windows leg being green and skipping them anyway.) Prior **v0.61.0 c96 @`618a35dc`** ([note](v0610-arc-in-flight.md) — WAX-SEAL #21). Prior **v0.60.0 c95 @`517c9f6f`** ([note](v0600-published.md) — TURNKEY #212, 2 respins, both reds ruled test-side; acceptance cascade verified on all 12 members). Prior **v0.59.0 c94 @`c62904e7`** (2026-08-21 13:44:01Z, PORTER #205, eight BUILT members + #187 fulfilled pre-milestone by `e8a35829`; riders IR-53 + IR-50-close; #199 shipped INSTRUMENT-ONLY, accepted-with-number, closed at `state: ACCEPTANCE` by the ADR-0004 cascade and gets NO DONE at roundup). ✅ **THE UNSHAPED-HEAD RECURRENCE IS CLOSED — BY CONSTRUCTION, NOT DISCIPLINE:** I authored the version material ON TOP of doyle's head `e702d4b7` and pushed THAT as the golden ref, so **ruled sha == main tip == golden ref == tag**, one object with four names, and nothing had to be argued inert. See [shape-the-head-before-golden](shape-the-head-before-golden.md) — doyle adopted the matching assembly-intake question the same day, so the role seam is covered from both sides. Golden 32482048369 GREEN first attempt, nine jobs, both twohost legs. Evidence standard held: new cells cited by per-HOST occurrence (2x = two hosts, NOT the nextest live/summary duplicate — check which before reading it as coverage), armed verifier by DURATION (2.78s vs v0.59.0 post-publish). ⚠ **THE THIRD-PARTY VERSION COLLISION IS LIVE AGAIN**: `windows-sys` sits at 0.59.0, so counting `version = "0.59.0"` in Cargo.lock returns 15 against a first-party 14 and the extra row is REAL — the third instance after quick-xml@v0.39.4 and aws-lc-sys@v0.41.0. Verify by DIFF; it cost nothing here. Also measured: `xtask gen` rewrote `docs-site/src/cli/reference.md` and git called it modified while the `--ignore-cr-at-eol` diff was EMPTY (autocrlf) — reverted, not committed. Lockfile refreshed with `cargo update --workspace --offline` where step 1 names `cargo metadata --offline`; doyle RULED the property (workspace members only, third-party untouched, proven by diff) is the rule and the command a vehicle, and is amending the runbook. Prior **v0.58.0 c93 @`b88fab2a`** (2026-08-20 19:22:01Z, CONCIERGE #183, ten members + #171 CUT; board 11 DONE incl. the #203 rider). **tag sha ≠ golden sha AGAIN** — golden tested `4661bc9d` carrying 0.57.0 and a `## [0.57.0]` section (the ALREADY-SHIPPED cut), so the bump rode the tested head via the PROVABILITY-BAR route; that is now **4 of the last 5 cuts**, so treat the unshaped head as the norm and the two-command check as mandatory. Intake REFUSED TWO HEADS before running: `c0878cbd` (greenlit member #177 had no build AND no disposition record, and the head PINNED the behaviour #177 asks to change; declared rider 4 absent from the chain) and `24edc166` (golden RED, one cell). Respin `4661bc9d` green, nine jobs, first attempt. The red exposed **releases#203**, a LATENT defect (ticket matched before the seated-controller re-serve exemption) proven latent by a byte-identical call site at main — respin anyway, because Q1 classifies by where the defect LIVES, never by who introduced it. ⚠ **A RIDER IS STRUCTURALLY INVISIBLE TO THE `release` VERB** — see [rider-open-at-publish-is-invisible-to-release-verb](rider-open-at-publish-is-invisible-to-release-verb.md). Evidence standard set this cut: cite the armed anchor row **by DURATION at both ends** (1.48s vs v0.57.0 for the bar, 1.11s vs v0.58.0 after publish). Prior **v0.57.0 c92 @`a0f9ecd`** (2026-08-19 20:22Z, KEYSTONE #182, ten members; roundup credited 11 incl. #182). ⚠ **tag sha ≠ golden sha, by ruling:** golden tested `901a9f5`, which was NOT release-shaped (version 0.56.0, no `## [0.57.0]`) — the bump `a0f9ecd` rode the tested head via the PROVABILITY-BAR route and the record is #182 comment `5347277294`. **Measured: the bump rode inside the golden candidate in only 1 of the last 4 cuts**, so expect an unshaped head and check it with two commands (`git show <sha>:Cargo.toml`, `git show <sha>:CHANGELOG.md`) — no other intake leg implies it. OPEN from this cut: thin-red specimen `rc::attach_viewport_reconnects_across_a_broker_bounce` assertion@33.65s @`9ea595c` (one failing obs, golden-green sha, hertz RCA + FLAKE-LEDGER extension on its own NEW signature — the ledgered 240s-starvation entry does NOT cover it). Also this cut: a post-golden bump makes any HELD sibling stack un-ff-able — when peer lanes base on the held shas, NEVER rebase; the stack rides the NEXT golden chain verbatim (register stack, this cut; how-to arm in [ff-only-absorbs-one-sibling-lane](ff-only-absorbs-one-sibling-lane.md)). Prior **v0.56.0 c91 @`60d74ea`** (2026-08-19 04:06Z, NAMEPLATE #181, six members; tag == golden-tested sha, run 32209922535, main ff'd 27d40b9..60d74ea; one respin — first golden red on two first-ever-executed TEST cells, both ruled rig defects, product clean; respin head = hertz's 62b16af+eb95634 gated by doyle). ⚠ next cutter: under golden CI **alchemy sweep finds NOTHING to reconcile** (no per-request merge-closes to key on) — close-cascade MUST come from `state <mref> acceptance` BEFORE publish (release verb gates closedAt < publishedAt); sweep-only drivers publish past open requests (deployah, this cut). Prior: v0.55.0 c90 (sha not carried here — re-derive), then v0.54.0 c89 @`86f0d84` (2026-08-04, USHER pulled forward, PROVABILITY-BAR route; the `SPT_RELEASE_E2E` vacuous-green and disk-guard labelled-hole caveats live in that entry's file), then v0.53.0 c88 @`b7b00c3`. Re-derive via `gh release list --repo BigscreenVR/spt-bs-releases`.
- [v0.52.0](v0520-published.md) five uncancelled reds, tagged≠tested · [v0.51.0](v0510-published.md) `acceptance` cascades, `done` never · [v0.50.0](v0500-published.md) cross-repo never auto-close · [v0.49.0](v0490-published.md) bump-in-PR refusal · [v0.47.0](v0470-published.md) thin-red vs golden-green = stop-and-refer · [v0.46.0](v0460-published.md).
- [hold pushes in the tag window](hold-pushes-during-the-tag-window.md) ⭐⭐ runbook tags BARE HEAD; a docs commit is enough to point the tag at an untested sha. Gater holds the whole merge queue golden-green → tag.
- [a rider is INVISIBLE to the release verb](rider-open-at-publish-is-invisible-to-release-verb.md) ⭐⭐ `release <tag>` gates on closedAt < publishedAt, and a rider is OPEN at publish BY DESIGN, so the verb silently under-credits: v0.58.0 promoted 11 and missed #203, the fix its own respin was built to carry. Nothing errors; the roundup looks complete. Reconcile the promoted count against **members + riders**, and close each rider on its own record with the ship-fact — never by re-dating or toggling the draft. Inverse face of the entry below (board credited a rider the NOTES dropped; here the notes were right and the BOARD dropped it).
- [board credits a rider the notes drop](board-credits-a-rider-the-notes-drop.md) ⭐⭐ notes read from the MILESTONE miss wave-gap riders the release verb still credits publicly — two published surfaces disagree; repair is docs-only POST-publish (append to the published body verbatim), never a retag, never a draft toggle.
- [standard](release-standard-bump-in-pr.md) ⚖ tested==shipped OUTRANKS bump-in-PR · [counter](release-counter-from-published.md) · [changelog scope](changelog-scope-vs-commit-range.md) · [end-user voice](release-notes-enduser-voice.md) · [--repo required](release-queries-need-repo-flag.md) empty at EXIT 0 on the wrong repo.
- [parity has LEVELS; membership goes blind on SHARED files](parity-membership-level-goes-blind-on-shared-files.md) ⭐⭐ membership-level parity (right lanes ride, none dropped) CANNOT see a lane whose content was mangled in the merge or shaped out after. The blind spot is the files more than one WRITER touches, and THE RELEASE DRIVER IS A WRITER: a lane's own files arrive intact or loudly not at all ONLY while the shaping delta is measured to stay off them — shaping edits the head after sign-off, with no merge and no conflict to make noise. Compute the multi-writer list from the DIFF AT THE SHA, never from what lanes were supposed to touch (deployah's correction of my overstated first draft). CONDUIT 2026-08-28, shaped head `110d1751`: 11/13 W3 files byte-identical, the 2 that differed were CONTEXT.md + traceable-reqs.toml, read verbatim and intact — and that number was evidence about the SHAPER's delta too (measured: CHANGELOG.md + Cargo.lock + Cargo.toml, ZERO .rs), so measure the shape before reading the number. Check the LAST-LANDED change by name first — shortest life in the tree, most chances to be lost. Run the content leg on your OWN lane and report it as an independent confirmation naming the level, never a restatement of the peer's.
- [partial milestone = REJECTED alternative](partial-milestone-golden-is-rejected-alternative.md) ⭐⭐ "tranche" renames eject-and-proceed; parity from `sub_issues`, FULFILMENT not presence.
- [co-author trailer loss](co-author-trailer-attribution-loss.md) ⚠ escaped-vs-real BYTES; fix the BUILDER · [golden respin](golden-respin-test.md) · [wave-gap riders](wave-gap-fixes-in-milestone.md) · [scope-strip](milestone-scope-strip-protocol.md) · [seed machine-env](release-seed-machine-env-ruling.md) · [roundup ordering](release-roundup-ordering.md) · [branch off current main](branch-fixes-off-current-main.md) · [updateset stale window](release-updateset-stale-window.md) · [update-apply message](update-apply-confident-message.md).
- [docs-drift gate](cli-command-docs-drift.md) · [version not milestone](public-docs-version-not-milestone.md) · [docs surface = installed vintage](docs-surface-is-installed-daemon-vintage.md) ⭐ :5474 is the DAEMON; zero-match there claims a VERSION, check before ruling a gap · [ff-only absorbs ONE lane](ff-only-absorbs-one-sibling-lane.md) ⭐ 4th face 2026-09-06: two GREEN sibling PRs — land the EXPENSIVE-rerun one first, hold the 30s docs one; run `--is-ancestor origin/main <tip>` before ever saying "no rebase needed" · [resolve toward SHARED body](resolve-wrapper-conflict-toward-shared-body.md) · [pin stable asset](pin-a-stable-asset-not-a-rolling-tag.md) · [real cross-platform verify is POST-publish](v032-platform-safe-update.md) · [golden CI strategy](golden-ci-strategy.md) ADR-0050.
- [v0.67.1 / SERVICE-DOCS patch](v0671-arc-service-docs.md) ⭐ **LATEST PUBLISHED: v0.67.1, counter 103, 2026-09-06T11:30:58Z, tag==main==tested `04e32c8c`, 11 assets verified at source.** Docs-only patch, operator-directed batch of one (no milestone), #274 DONE via release verb. Six golden attempts across two shas — r1 Linux light-pool starvation of an un-swept HEAVY flood rig (reclass respin, discriminator confirmed by prediction both OS), then three DIFFERENT Windows Phase A victims one per attempt (:473 structural barrier, wtlock at-budget under a peer’s unheld workspace nextest, :664 ledger row 42 third hit); gater overrode his own stop-arm on the record with a hard stop for att4; att4 9/9. twohost green 6/6. ~5.5h push→publish.
- [v0.66.0 / SEMAPHORE arc](v0660-arc-in-flight.md) ⭐⭐ **LATEST PUBLISHED: v0.66.0, counter 101, 2026-08-30T01:42Z, tag==main==tested `d931dd63`, publish verified at source (Latest flipped, 11 assets, counter re-decoded live).** Four golden attempts, every red closed at NAMED mechanism, zero by rerun: r2/r3 floor red = deterministic adjacency (reclaim is checkout's own `git clean -ffdx`; floor moved AFTER checkout, ac7d2609); Linux 4-cell red = `current_exe_hash()` ~10.1s/boot ON the ready path (debug sha2 × 440MB binary; BRAIN_PHASE breadcrumbs + tempdir harvest-loop repro named it in one grep; budgets 30→120s field-validated — all four cells passed ABOVE the old budget); r4 LNK1318 = disk low-water at the job's LAST heavy step, confirmed PREDICTIVELY by reclaim (65.1GiB→died / 85.85GB→success, only variable the reclaim; incremental candidate retired by its own preservation snapshot). 9/9 at ONE sha across two attempts, stated plainly. ir57 near-miss: reap identity = the checked-out REF, never the directory name (203GB live lane saved). Follow-ons ride RCA-242-R2-LINUX.md riders + sweep draft; 24-site ready-wait population → hertz.
- [v0.65.0 / CONDUIT arc](v0650-arc-in-flight.md) ⭐⭐ **v0.65.0, counter 100, 2026-08-29, tag==main==tested `4d6007ac`.** **A full golden GREEN was discarded on purpose** (`110d1751`, run 33223968222 a3) — `io-events` could never return COMMUNE/COMMUNE_FAIL while four landed surfaces said all six kinds were visible; the no-ship ruling was written on the board WHILE that run was still in flight and its verdict unknown, throw-away-a-green clause included. ⭐⭐ **There is no cheap middle: the docs-drift gate reads the gated docs, so a docs-only softening is Q1-YES under the respin test exactly as a code fix is** — identical window cost, so keep the promise rather than narrow it. CHECK THIS before assuming a docs-only escape hatch exists. ⭐⭐ **Pool ratio: reaped 140.51 GB, a fresh full rebuild of the same tree is 7.78 GB ⇒ ~18× accumulation across a milestone's sequential lane-sharing** — that ratio is what predicts the next box's free-space floor red; "the disk filled up" does not. Respin intake gained a leg: prove the DISCARDED head is not an ancestor (it would carry the bump forward and pass every other leg, shape leg included).
- [a release-note baseline is the LAST RELEASE, not the lane's previous commit](a-release-note-baseline-is-the-last-release-not-the-lanes-previous-commit.md) ⭐⭐ 2026-09-09 v0.69.0 #287: diffed a respin against the lane's PREVIOUS COMMIT and proposed "Previously the close could fail..." for an abort that was INTRODUCED AND FIXED INSIDE THE UNRELEASED LANE — a phantom regression the product never had. Every other gate check is sha-to-sha, which is the habit that misfires here. ⚠ MY OWN PROOF RULE WAS WRONG TWICE (hertz, minutes later): symbol-absent does NOT prove behaviour-absent (it can live under another name or inline), and I grepped de5a44bc — the LANE BASE — not the last released object a2f335f8. Compare BEHAVIOUR at the released sha; a grep miss raises a question, never settles one. What settled it was the BUILDER's provenance.
- [v0.72.0 / HANDED-FILE #318](v0720-published.md) ⭐ **LATEST PUBLISHED: v0.72.0, counter 108, 2026-09-22T06:29:16Z, tag==main==tested `73f19d51`, 11 assets verified at source, Ed25519 via openssl pkeyutl.** Golden a1 Windows floor resource red (128 GiB, doyle pool), a2 9/9; cascade needs `#318` not `318`.
