---
name: daemon-lifecycle-progress
description: "DAEMON-LIFECYCLE — W1 @53cdeab + W3 @7c0f12d + W2 (PR #66 @2342fd6) ALL MERGED (doyle-gated); v0.41.0 c74 published. ✅ PR #68 MERGED @7f062d7 + v0.41.1 c75 PUBLISHED 2026-07-23 (fix/idemreplay-anchor, test-only, gated 120/120 loaded + 13/13 serial, label retracted @c65908d) = fix for the #66 merge-run leg-2 red, which todlando's kitsubito dig proved a RIG-ANCHOR ARTIFACT (PTY double-echo drifting into the absence window), NOT a regression of W1's shipped idempotent-replay fix → v0.41.0 attached-view changelog STANDS, hertz leg 3 UNBLOCKED. Post-publish hertz field-verify dispatch SENT 2026-07-23 (QUEUED; leg 3 arm-before-apply first, then 2b DNAR contrast + leg 4; obs 3 DO-NOT-RUN) — awaiting per-leg verdicts. HFENDULEAM on 0.41.1"
metadata: 
  node_type: memory
  type: project
  originSessionId: a87a80c6-764d-41c6-81b0-488c1d7f3318
  modified: 2026-07-24T05:15:51.773Z
---

**DAEMON-LIFECYCLE** — operator GO 2026-07-22 ("begin building DAEMON-LIFECYCLE while you wait for [hertz's bug-3] report, and plan to roll the bug 3 fix into DAEMON-LIFECYCLE").

**Triage: main @9d487d7** — ADR-0047 (`docs/adr/0047-daemon-lifecycle-custody-authority.md`) + KNOWN-HAZARDS **7.51** (custody identity, never bare PID) + **7.52** (operator stop outranks implicit ensure) + 7 REQs at the registry tail. Amends ADR-0044 (equal-gen rung gains a same-conn idempotence leaf) and REQ-DAEMON-3 (anchor yields to a standing operator stop). `traceable-reqs check` 571/571, `xtask check` OK at commit.

**Waves:**
- **W1 (DISPATCHED to todlando 2026-07-22, branch `build/daemon-lifecycle-w1` off 9d487d7):** the three v0.39.4 field bugs with accepted RCAs ([[v0394-field-bugs-hertz-rca]]):
  1. REQ-RESUME-CUSTODY-IDENTITY + REQ-HAZARD-RESUME-CUSTODY-ABA — (pid, creation-time) custody pair, ABA self-heal (bug 1, false-ONLINE).
  2. REQ-ENSURE-DAEMON-STOP-INHIBIT + REQ-HAZARD-STOP-RESPAWN-CONVOY — durable no-TTL stop inhibit + spawn serialization (bug 2, respawn convoy). ⚠ deliberate REQ-DAEMON-3 behavior change: harness hooks on a stopped box print a refusal, not a heal.
  3. REQ-ATTACH-IDEMPOTENT-REPLAY — equal-gen same-conn = idempotent (seat+writer preserved, decision=idempotent breadcrumb); different-conn swap (fix-6 successor) preserved (bug 4, update-freezes-PTYs, breadcrumb-pinned). ⚠ SHARED SEAM — gate runs full grep-derived seam battery.
  4. **W1 RIDER (operator-ordered 2026-07-22, perri field regression):** REQ-NOTIF-DRAIN-ROW-VALIDITY — stale update notices deliver on already-updated nodes. Root (doyle same-day): quiet delivery spools a durable per-endpoint copy per surface; ALL row lifecycle (seam dismissal/supersession/TTL/migration) touches rows only → spooled copies outlive dismissal, deliver at next drain, once per surface event. Fix = validity gate at the drain choke point (api/delivery.rs cmd_poll deferred presentation): notify envelope delivers only if notif_id resolves to a live undismissed row; dedupe per notif_id; non-notify untouched; legacy no-notif_id copies self-clear by draining. ADR-0046 **Amendment 1** + **KH 7.53** + REQ landed on the BUILD BRANCH @9386cd8 (rejected shapes recorded: recall-on-dismiss sweeps; live-only delivery). NOTIF-TRUTH's "self-clear" claim = true at row layer, false at delivery layer until this ships.
  - All three int rigs RED-first. W1 stage activation = todlando's first branch commit @288e90e (mint-inactive convention held on main; rider activates alongside).
  - ✅ todlando MOVED to `.worktrees/daemon-lifecycle-w1` (flag heeded; main checkout clean again).
  - **W1 BUILD COMPLETE @cdea554 (todlando ping 2026-07-22): all four fixes committed + RED-first proven; seam battery running; PR on green.** 74412c7 custody pair + resume_custody_aba.rs (pre-fix defers forever on recycled pid; sibling probe offlines an in-flight row — discriminates both directions); 4ebf07d stop inhibit + daemon_stop_convoy_e2e.rs (field bug verbatim; ensure_decision probes RUNNING first — live daemon serves regardless of inhibit, refusal only when down AND inhibited, unit-tabled = ordering pin 3 confirmed); 1e5dbd3 bug-4 equal-gen same-conn idempotent leaf; 3441917 rider validity gate (reds at BOTH presentations; first draft passed VACUOUSLY on the CONTROL leg — active_only never reaches the injecting relay drain — sibling probe exposed it, header records it; the kind-keying delta is what makes the gate cover it).
  - **⭐ DOYLE RULINGS 2026-07-22 (code-grounded, sent todlando):** (1) **from_seq key element APPROVED** — gap-resume collision real (attach.rs re-fetch = same conn+gen+by, only from_seq differs); key now (endpoint/session, by, conn, gen, from_seq); ADR-0047 decision 3 amended @5ef2d67 incl. the zero-delivery residual (floor==establish_from_seq → suppressed → SURFACED truncation, never silent, not constructible); ControllerSink.establish_from_seq records it; breadcrumb decision=idempotent is BREADCRUMB-ONLY vocabulary (SubscribeOutcome wire type unchanged, N-1 tolerant). Cosmetic non-blocker flagged: fall-through comment says DIFFERENT-conn but also serves same-conn gap-resume. (2) **Bug-4 int rig honest-header ACCEPTED; unit matrix = the discriminating RED** (with discriminator disabled: Brain exactly-once cursor hides second batch + become_controller reinstalls writer on same conn — int layer can't see the freeze without the serve worker). NO dispatcher double-serve simulation ordered — would enshrine a guess about an unexplained behavior; a real serve-path rig belongs to the seed once the double-serve origin is understood. ⏳ Banked open question (WHY double-serve conn1011 15ms) — asked todlando for investigate+seed status, due before PR merges. (3) Transcripts → PR body (all four).
  - Doyle pre-read of bug-1 fix: KH 7.50 honored exactly (existence from process TABLE first via process_exists, start time only as discriminator, fresh handle closed immediately, tri-state Unproven never manufactures a verdict). traceable-reqs 0 across six activated REQs; xtask reference.md drift committed (cdea554).
  - ✅ **W1 GATE-READY: PR #59** (todlando 2026-07-22) — https://github.com/BigscreenVR/spt-bs-core/pull/59. All four RED transcripts pasted in the body per doyle. Gate evidence: traceable-reqs exit 0 (six activated REQs); clippy --workspace --all-targets clean; grep-derived seam battery **91/91 spt-daemon + brain_swap 1/1 + 11/11 spt** (rc_attach_truth, brain_survive, dummy_harness_e2e, resume_no_control_steal_e2e, attach_wedge_e2e); xtask gen artifact committed @cdea554. ⚠ GATE GOTCHA: `attach_wedge_e2e` needs `cargo build -p mock-adapter --bin mock-session` first or it fails on a MISSING FIXTURE, not on code. Doyle's cosmetic fall-through comment note fixed @22b1419.
  - ✅ **W1 GATED + MERGED @53cdeab (doyle 2026-07-22).** Gate: code-review legs ALL PASS + CI green both platforms (main 29913640247 + PR 29914267841) + local battery in `.worktrees/gate-a6cebae` throwaway target: build clean, clippy clean, **nextest 2081/2081** (1 skipped, "9 leaky"). Post-battery census: 6 spt.exe leaked from throwaway target → reaped BY EXECUTABLE PATH (installed-path processes all verified legit pre-battery infra: hertz ready listeners ×2, daemon+brain, mobile-gw adapter, operator rc viewports todlando/doyle/perri/lia/flynn — identify before touching, never name-kill). Gate worktree skeleton HANDLE-PINNED (rm blocked on crates/spt-daemon) → joins the reboot-window list. todlando told to remove their W1 worktree.
  - ✅ **W3 DISPATCHED to todlando 2026-07-22** (same message): branch `build/daemon-lifecycle-w3` off @53cdeab; both REQs activate at first branch commit; oracle binding restated (independent VT emulator, ScreenGrid non-authoritative); RED-first both legs; banked-not-solved question = whether 7.55 restore lives in spt-term or at broker write_input call site (instrument first, propose like the from_seq flow).
  - ⚠ **W3 STARTED + CONTRACT COLLISION (todlando flag, DOYLE-CONFIRMED 2026-07-22): Amendment 1's mechanism-1 CODE ROOT IS FALSIFIED on @53cdeab.** Branch live, both REQs activated @7575c69, lane .worktrees/daemon-lifecycle-w3. I re-traced myself: ALL THREE rc resize senders (rc.rs 1934/2288/2294) = send_attach_resize → serve_attach Resize arm → brain.resize → KIND_RESIZE → dispatch_resize = the FULL barrier path (begin_resize_serialized → commit/abort); only production commit_resize caller = dispatch_resize:5274; the None arm is test-only. "Never arms the barrier" was WRONG — my same-hour seam-verify confirmed the barrier EXISTED but never traced the attach ENTRY into it (narrative-proximity pin; ground-dont-assume recurrence, mine). Field evidence + decision ("one transaction, one exit shape, any entry") UNAFFECTED. Live candidates: (a) ORDERING — initial attach batch (writer-owned) vs sync frame (try_send into controller queue, push_sync_frame ~2076) deliver by different mechanisms, relative client order unproven; (b) push_sync_frame next_seq==0 early-return (can't fire on content-bearing session) or Full-queue RESIZE_SYNC_DROP (loud on daemon stderr — but hertz capture taps the WIRE, absence-from-capture ≠ absence). **RULING SENT: from_seq precedent — oracle rig FIRST (avt, already a workspace dep via resize_geometry_epoch), instrument, pin root, REPORT; todlando may draft amendment text for my ratify; fix builds once root pinned but merges only after ADR matches code; REQ may retitle if root = ordering. If rig does NOT repro at captured shape → bring to doyle before widening (isolation-sensitive bug, first rig precedent).** todlando's W1 worktree also handle-pinned → reboot list.
  - ⚠ **ORACLE RIG STRUCTURALLY BLIND at contracted shape (todlando 2026-07-22, stopped-as-instructed):** synthetic fixture (real broker+ConPTY, avt authority w/ avt.resize, candidate fresh avt@131x60) PASSED — then the CAPABILITY PROBE (client resize removed, deliberate 80x24-vs-131x60 mismatch) ALSO PASSED ⇒ rig cannot fail on this class, green = nothing. WHY: inherited resize_geometry_epoch fixture is deliberately geometry-INSENSITIVE (narrow + unwrapped + CUP-absolute — same final cells at 80 or 131; that fixture stays narrow to dodge avt-reflow-vs-ScreenGrid-truncate POLICY divergence, and width-sensitive content re-imports that trap one layer over via avt.resize in the authority). Rig on disk UNCOMMITTED (no false-green artifact on branch). **DOYLE RULINGS SENT:** (c) hertz's actual captured bytes = PRIMARY oracle (the ADR's literal contract, fixture-judgment-free) — hertz PINGED for BOTH capture files (attach + live-viewport-resize, wire + broker taps); (b) fresh-avt@new-geometry authority (repaint-of-pre-state + post bytes, no reflow anywhere) builds NOW as synthetic sibling, MUST pair with width-sensitive content (only works together); (a) REJECTED (pre-phase re-enters wrap trap; discriminator = fixture judgment). ⭐ NEW BINDING (rides the ADR amendment): oracle-rig green COUNTS ONLY after a capability probe — rig must red/detect on a deliberately seeded instance of the defect class; probe committed as a PERMANENT rig leg (re-blinding refactor goes loud). Amendment bundles: code-root correction + oracle-shape requirement ("geometry-sensitive without reflow-sensitive; capability-probed"); todlando drafts, doyle ratifies. Instrumentation (stderr RESIZE_SYNC_DROP + Request-vs-Resize interleaving) rides (b) as soon as it discriminates.
  - ✅ **HERTZ CAPTURES DELIVERED + STAGED (2026-07-22): oracle (c) UNBLOCKED.** Both captures byte-exact in `t=<unix_ms> n=<len> <hex>` records. Doyle staged durable copies at `C:\Users\decid\Documents\projects\spt-core\scratchpad\enlyzeam-capture\` (Temp originals die at reboot window; anchors spot-verified in staged copies: 42257, 1960-byte@42289, frame 22159). SEGMENTATION (hertz): capture 1 attach 80x24→131x60 raw t=1784714142257..53024 / frame 42291..53025, use SECOND 1960-byte raw rec @42289 for raw==frame (first @42257 = duplicated pre-frame tap); pre-resize synthesized repaint survives as recs 3/4 of tap-1-repaint-after.log. Capture 2 live-resize raw 816155..822893 / frame 816158..822893; /config corruption begins frame 822159; echoed keys c=22394 o=22449 n=22530 f=22670 i=22765 — SAME FILE = the 7.55 mechanism-2 fixture too. tap-1-repaint.log (7712 B) CONFIRMED RELEVANT (hertz same-day): the original frozen repaint tap post-attach-repro, ending w/ the two pre-resize synthesized 1856-byte repaint recs t=…42194/42208; tap-1-repaint-after.log adds the clean 131x60 broker repaint recs t=…376763/6773 (fresh-viewer triangulation) — before/after contrast = the fresh-viewer-clean PROOF LEG; all four files commit. DESTINATION RULED: fixtures commit INTO REPO with the rig (~324 KB), existing convention or crates/spt-daemon/tests/fixtures/enlyzeam/ + README (segmentation + provenance); scratchpad copy = courier only; todlando tells hertz the final path. Hertz re-acked on the standing pre-apply ping for the next cut.
  - ✅ **(b) SIBLING LANDS + DISCRIMINATES; MAIN LEG PASSES on @53cdeab (todlando, branch @e0131d1 fixtures+rig, @1d12cf8 .gitattributes):** capability probe (withheld viewport size = seeded mismatch) DETECTS; main leg = controller 131x60 attach to 80x24 host, viewport size, differentials → cell-for-cell equal to authority. **Mechanism 1 as written = FALSIFIED TWICE (static trace + probed empirical), synthetic live path clean — isolation-sensitivity signature again. NOT concluding field bug absent.** Discriminators now: captured-bytes leg + interleaving trace. ⭐ 1d12cf8 = fixture-integrity catch: autocrlf would rewrite capture line endings both directions (Windows checkout vs Linux CI) while all tests stay green → `.gitattributes '*.log -text'`; DOYLE RATIFIED + amendment oracle-shape gains clause 3: fixture byte-integrity pinned vs tooling rewrites, hash/byte-length column in README. **FIXTURE-PLAYER RULED: option (1)** — new bin in mock-adapter crate (mock-session precedent incl. prebuild; real child/ConPTY/broker; reusable for 7.55 typed-through-resize leg; (2)=self-exec argv hack rejected; (3)=red-forever characterization rejected as drift bait, pure replay allowed only as documented one-shot README procedure). Replay = order-preserved sleeps-dropped AS STARTING POINT with PRE-REGISTERED caveat: if interleaving trace shows timing-dependence (15ms-window class), a captured-bytes PASS ≠ clean — check pacing (--pace flag = the lever, build only if that fork is reached), report to doyle either way. Instrumentation legs running now (stderr RESIZE_SYNC_DROP + Request-vs-Resize interleaving). ADR amendment draft (code-root correction + 3-clause oracle-shape requirement) comes with todlando's next report — one ratification, one landing.
  - ⚠ **SECOND ORACLE BLINDNESS — captured-bytes leg (todlando @e36a1ac, rig UNCOMMITTED):** capture-player landed (mock-adapter bin, TWO windows + stdin gate so attach+resize happen between pre-attach screen and attach-window records; whole-file parse, per-record length refusal; order-not-pacing header; sha256+sizes+verify cmd in README). Main leg passes BUT capability probe (viewport size withheld) sees ZERO divergent rows ⇒ blind. WHY: authority built from POST window alone — real capture's attach-window records repaint enough that both sides converge regardless of resize; the discriminating stale pre-attach cells are absent from the authority. **DOYLE RULINGS SENT:** (c) FIRST = start window at hertz's last-full-absolute-repaint anchor (hertz PINGED; negative answer = disqualifier) + REQUIRED SOUNDNESS SELF-CHECK as permanent rig leg: render pre-window bytes into avt(80x24) AND avt(131x60), content must agree over shared region — divergence = auto-wrap reliance = reflow trap third costume = (c) unsound. (b) PRE-AUTHORIZED fallback under adopted CLAUSE-1 READING: clause targets shared defect-carrying MACHINERY (authority must never EXECUTE our render code at test time); field-CAPTURED bytes our renderer once emitted = evidence, not product (cannot vary with code under test) ⇒ guard: (b) authority start-state = CAPTURED clean-repaint recs t=…376763/6773 from tap-1-repaint-after.log, NEVER regenerated at test time; header notes field-validated-but-same-renderer-emitted = why (c) outranks. (a) rejected unchanged. Amendment scope grew: code-root correction + oracle clauses (geometry-sensitive w/o reflow-sensitive; capability-probed at EVERY shape revision; byte-integrity pinned; per-record length refusal) + clause-1 captured-evidence-vs-executed-machinery reading + pre-state self-check as required leg. Amendment written ONCE after oracle settles.
  - ✅ **HERTZ (c)-ANCHOR DELIVERED (2026-07-22): t=1784713547401** (n=111, FIRST rec of tap-1-raw.log, begins ESC[2J ESC[m ESC[H = self-contained clear+reset+home). Feed raw 3547401..3561651 then attach window. Hertz verified in INDEPENDENT PYTE @80x24: zero cell/style diffs vs captured synthesized repaint t=…42208 (all 1920 cells × 7 attrs). NO later self-contained anchor: 3552872 owes row 24 (differs rows 19+24 alone); 3561651 = row-19-only; 3551571/74 clear from inherited cursor. Forwarded to todlando w/ reminders: pyte check ≠ the 80-vs-131 soundness self-check (still owed before (c) counts); rejected-candidates table goes in fixture README (negatives stop future wrong-anchor picks). (b) fallback stands pre-authorized.
  - 🔴⭐ **BUG 3 REPRODUCED (todlando @a230f9a, 2026-07-22) — FIRST REPRO OUTSIDE THE FIELD.** Primary (c) oracle RED on hertz's captured bytes through the real seam, with the red made believable in order: pre-state self-check PASSES (pre-window renders identically @80x24 and @131x60, nothing past col 80, absolutely addressed ⇒ (c) SOUND, all authority bytes field-provenance); capability probe PASSES (non-vacuously, post-fix); main leg FAILS (client screen diverges from authority on the real capture). Anchor exactly as hertz gave it. **Mechanism 1 falsified THREE ways** (static trace + synthetic-empirical + dynamic broker breadcrumbs: barrier arms on attach entry, W3_TRACE_SYNC_PUSH controller=true 219 bytes; RESIZE_SYNC_DROP absent daemon-side). **THE SHARP QUESTION: synthetic passes + capture reds on SAME code/oracle/probe ⇒ bug lives in what the capture carries that the painter does not** (content shape / TUI's own resize response / record boundaries). Two rig defects caught en route, both ratified into the amendment: (1) VACUOUS-PROBE lesson — first qualified probe run passed because the candidate screen was EMPTY (window-2 release keystroke sent from SPAWNER conn, PTY input controller-fenced per REQ-INPUT-CONTROLLER-FENCE) ⇒ new clause: every capability probe asserts its OWN precondition (candidate actually received+rendered a screen); (2) byte-split-at-col-80 through box-drawing glyph = char-split fix, correctly NOT reported as (c) disqualification. **NEXT: CAPTURE BISECT (doyle-approved w/ 3 rules): (1) self-check + precondition-asserted probe re-run GREEN at every bisect step (narrowed fixture can re-blind); (2) bisect WITHIN window structure, never across the stdin gate (pre/attach boundary = the field sequence); (3) record subsets first, then intra-record; single-record flip ⇒ look at BOUNDARIES before bytes (escape-seq split across delivery boundary at resize transition = mechanism-class candidate, invisible to whole-sequence synthetic painters).** Pre-registered candidates (sharpen, not steer): (i) TUI's own resize response (painter ignores resize; captured child repainted @131x60); (ii) record boundaries. Amendment still held until root PINS (reproduction ≠ root).
  - 📌 **W3 BRANCH STATE (2026-07-22, todlando pre-clear):** `build/daemon-lifecycle-w3` PUSHED, 7 commits (7575c69 REQ activation … e0131d1 fixtures+rig … 1d12cf8 .gitattributes … a230f9a repro-red oracle … bc8dbc4 README w/ anchor rationale + rejected-candidates TABLE + completeness-vs-soundness split + vacuous-probe clause … 94fd6db JIT plan). **NO PR — deliberate: main leg RED = the reproduction; PR only with the fix that greens it + pinned root.** **W3-BISECT-JIT.md @94fd6db = the handoff plan:** state (reproduced/root-NOT-pinned), three-ways-falsified marked do-not-re-litigate, doyle's 3 bisect rules, mechanics (timestamp-constant change + player flags, no new machinery; FIRST CUT = the 10s gap between paints at 142305/152253), pre-registered candidates labeled sharpeners, ordered tail: root → amendment → fix → 7.55 (own capture window; spt-term-vs-write_input placement still banked). todlando SELF-CLEARING; bisect STAYS with todlando (doyle-confirmed); judgement ON RECORD: synthetic pass = fixture statement, NOT broker clearance. Doyle holds: amendment ratification (post-root) → gate → 7.55 leg.
  - 🔴➡⚪ **BISECT VERDICT (todlando fresh context, DOYLE-VERIFIED + RATIFIED 2026-07-22): THE ORACLE RED WAS A REPLAY-VEHICLE ARTIFACT — a230f9a's repro claim RETIRED; bug 3 stands NOT-REPRODUCED (second independent isolated rig, consistent w/ f31849c).** The red = 1 row/2 cells (row 52 `/c/config` vs `  /config` — THE FIELD STRING, manufactured by the vehicle). Mechanism, 3 isolated probes (scratch, w3 worktree): (1) ScreenGrid advance(PRE)→resize→advance(POST)→render_repaint over exact captured bytes = 0 divergent rows (our seam byte-clean, no broker/ConPTY); (2) player under FIXED 60x131 ConPTY, NO spt code, NO resize = the same row-52 divergence (vehicle accounts for 100% of red); (3) minimal: **Windows ConPTY interprets incoming bare LF as CR+LF** (col reset) while spec VTs + our GridState::line_feed (screen.rs:402) preserve col. Capture rec t=…152501 = CUP 51;3 + EL + SGR + BARE 0a + "/cd" → ConPTY replay lands "/cd" at col 1 → "/c" residue survives absolute overwrites. tap-1-raw = a ConPTY DRAIN (ConPTY EMITS bare-LF-as-index but INTERPRETS as CRLF) ⇒ second-ConPTY replay is NOT lossless; synthetic painter (CRLF/absolute-only) never touches the asymmetry. Doyle verified line_feed + the record hex byte-exact before ratifying. **RULINGS: (a) VEHICLE-TRANSPARENCY precondition = required clause for any non-our-code vehicle rig (probe 2 = reference impl, commit as permanent leg); (b) primary oracle re-points ConPTY-FREE (capture→real Broker, probe-1 shape); probe 3 commits as the executable rationale; (c) amendment = vehicle-fidelity clause + mechanism-1 CORRECTION ("no code root exists" IS the correction; decision stands; not-reproduced ×2; field pin awaits production debug channel); LF asymmetry recorded as CONSOLE-MODE-SEAM SIBLING of 7.55 (two manifestations of the uninstrumented seam) → 7.55 instrumentation extends to DISABLE_NEWLINE_AUTO_RETURN; 7.55 rig (real-ConPTY-required) inherits clause (a), investigate DNAR flag for vehicle transparency there; REQ-ATTACH-RESIZE-REPAINT → propose retire-defect-claim + RESCOPE to the oracle/fixtures/probe-ladder infrastructure.** ⭐ 7.55 UNCONTAMINATED: capture 2 = live field capture, no replay vehicle. **AMENDMENT NOW DRAFTABLE** (todlando drafts, doyle ratifies, one landing) → then 7.55 build. ⏳ ~~OPERATOR RESURFACE: debug-channel grant~~ **SUPERSEDED SAME HOUR — see next entry: root pinned statically, debug channel MOOT.**
  - 🎯⭐ **BUG 3 ROOT PINNED (doyle 2026-07-22, main @db06961: KH 7.56 + REQ-RC-NEWLINE-PRESENTATION-TRUTH minted inactive): rc's `with_vt_output` (rc.rs ~747) enables ENABLE_PROCESSED_OUTPUT|ENABLE_VIRTUAL_TERMINAL_PROCESSING WITHOUT `DISABLE_NEWLINE_AUTO_RETURN` — ZERO grep hits tree-wide — so the OPERATOR'S OWN CONSOLE translates relayed bare LF→CR+LF (column reset).** The bisect's "vehicle artifact" mechanism RELOCATED to the field: the field display chain ends in the same missing-DNAR console semantics via rc. ONE mechanism explains EVERYTHING: /c-scraps at FIXED window size (bare-LF debris needs no resize — this was always the no-resize interior-debris discriminator); fresh-viewer-clean (synthesized attach repaint = CUP-absolute, no bare LFs); BOTH isolated rigs NOT-REPRODUCED (compared bytes / rendered via spec VTs — bytes ARE clean; nobody presented through a real Windows console client); rig red = exact field string (vehicle had field-client semantics — rig was a faithful CLIENT model consulted about the broker). Capture rec t=…152501 (CUP 51;3 + EL + SGR + bare 0a + "/cd") through DNAR-less console = "/c/config" exactly; doyle byte-verified the record + line_feed col-preservation before ruling. **RULINGS: red rig NOT retired — RE-ATTRIBUTED as client-model rig = the RED-FIRST proof (DNAR-off vehicle = field client = RED; DNAR-on = fixed client = must GREEN — that pair is the regression). Vehicle-transparency clause (a) scoped to BROKER-seam rigs; client-model rigs declare themselves in header. FIX SHAPE: with_vt_output gains DNAR (Unix needs nothing — raw mode clears OPOST/ONLCR); enable/restore unchanged. Broker/attach seam stays EXONERATED (three-ways-falsified list untouched).** Amendment restructured: mechanism 1 = rc client presentation root, folded into the console-mode-seam frame (THREE manifestations one day: relay-presentation LF + replay-vehicle LF + 7.55 echo; one uninstrumented seam). todlando: merge main (db06961 = KH+registry tail, collision class), draft amendment, DNAR fix + rig pair, then 7.55. **DEBUG-CHANNEL GRANT MOOT** — hertz notified (their anchor/rejected-candidates/fresh-viewer triangulation = load-bearing evidence); field-confirm dispatch (fixed rc clean on field session class) rides the release = attribution CLOSED then.
  - ✅ **W3 MECHANISM 1 COMPLETE ON BRANCH (todlando 2026-07-22, @5e1a98e Amendment 2 + @6770afe fix; DOYLE RATIFIED both flags, branch-verified):** merged main (db06961) clean first. ADR-0047 **Amendment 2** = bug-3 root correction + oracle clauses; **clause (a) wording CORRECTED measured-not-argued: PER CELL, never byte-equality** (ConPTY re-renders — 14598 in/14929 out/0 divergent cells with DNAR; byte-equality unsatisfiable by construction, would ban every ConPTY rig incl. 7.55's). Fix = DNAR joins with_vt_output (dual-tagged REQ-RC-WIN-VT-OUTPUT + REQ-RC-NEWLINE-PRESENTATION-TRUTH); scope AUDITED: helpfmt.rs deliberately untouched (prints OUR text — DNAR there would stair-step help), rc.rs:2400 = sole own-LF, carries explicit CR, parting prose writes after mode restore. **Four-rung ladder:** unit composition; rc_console_newline_presentation (mechanism on real platform: spec VT=INDEX / pre-fix mode=column reset / fixed=INDEX — executable rationale); capture_vehicle_fidelity (clause (a) predicate + NON-VACUITY sibling: stock vehicle manufactures /c/config with zero spt code); attach_resize_capture client-model PAIR + **no-vehicle CONTROL (grid+resize+repaint=0 divergent rows) = standing seam-clean proof AND the LOCALIZER** (control red + fixed green = defect ours; reverse = vehicle first). capture-player: --console-mode rc|rc-fixed (names what it models; drift risk flagged — unit test pins rc itself, read together). ⭐ MEASURED BONUS: DNAR set at child startup SURVIVES ConPTY resize (output bit; NOT extrapolated to input bits — correctly). **REQ-ATTACH-RESIZE-REPAINT rescope APPLIED BY TODLANDO + doyle-ratified:** stages ["unit","int"] impl-dropped (red check over a no-longer-owed stage = lie either direction; honest edit with stated reversal path). Gate report: clippy clean, W3 rig 5/5, spt-term full green, shared Amendment-1 machinery green, no leaked children; traceable red ONLY on REQ-RESIZE-INPUT-MODE-INTEGRITY missing impl/unit/int = 7.55 not yet built, stated-not-mistaken. ⚠ ORDERED: PUSH BRANCH (origin stale @94fd6db — evidence in one place = one disk failure from gone). **7.55 GO, instrumentation-first:** sample ECHO/LINE + DNAR before-resize/after-resize/before-write_input on a clause-(a)-inheriting rig; todlando reports bits before proposing restore placement (spt-term seam vs broker write_input = doyle ruling on measurement). Remaining after 7.55: gate → merge → release c74 (deployah) → hertz field-verify (DNAR rendering + typed-through-resize no-echo + NOTIF obs 3 pre-apply ping).
  - ✅ **7.55 MEASURED CLEAN (todlando @0f74bba, pushed): the resize does NOT alter console input mode** — mode word identical at boot/before-resize/after-resize/before-write (in=0x1f0 out=0x7, echo=0 line=0 dnar=0). Absence EARNED: probe must be a CHILD (daemon holds master end, is not attached to the child console, structurally CANNOT GetConsoleMode it — the REQ's written impl probe point cannot see the console it names); raw-FIRST precondition asserted (pseudoconsole BOOTS echo/line ON, in=0x1f7 measured — unclamped default); capability probe (--reenable-echo-on) requires BOTH observables (mode word + actual echo) to move. Two instrument defects recorded (transferable): child stderr under ConPTY arrives SHREDDED into the re-rendered stream → verdict moved into the protocol line; line-reads go DEAF in raw mode AND ConPTY's post-resize repaint re-emits the boot line looking like a fresh reply → raw byte reads terminating CR-or-LF. ⭐ OPEN CANDIDATE (not tested, correctly): the UNCLAMPED WINDOW — child clamps the boot-on default; any window before (re-)clamp echoes with no seam re-enabling anything; reframes 7.55 from "who re-enables" to "is there a window nobody has turned it off yet". **DOYLE RULINGS: (b)+(c).** (b) REQ-RESIZE-INPUT-MODE-INTEGRITY rescopes like 7.54 (impl dropped; unit+int onto instrument+rig+finding+boot-default hazard; title: field evidence REAL/seam MEASURED CLEAN/trigger UNPINNED/window candidate OPEN) + KH 7.55 invariant CORRECTED same commit (hazard stands; seam measured mode-preserving; daemon structurally cannot observe child console modes). (a) production instrumentation DECLINED (probe point production can reach ≠ the console that matters = manufactured confidence; rig IS the instrument). Placement ruling MOOT (nothing to restore; server-side clamp structurally impossible). (c) = doyle's, SENT to hertz: capture-2 timing (resize-t vs first-echo-t gap; TUI reinit signature between; does echo STOP and what precedes) — answer mints or kills the window seed, NOT branch-blocking (rides out like the double-serve seed). **BRANCH CLOSES on (b) commit → gate-ready ping → PR → gate → merge → release lane.**
  - ✅ **WINDOW CANDIDATE FIELD-GROUNDED → SEED MINTED @f8dfd2e (REQ-TERM-ECHO-CLAMP-WINDOW, inactive).** hertz capture-2 timeline (output-only taps, limitation honest — no mode calls / resize records visible): echo onset = first `/` at t=…822158, **6003ms AFTER** the first resize-associated repaint burst (…816155; repeated HOME/full-repaint bursts then a 2.72s quiet gap; NO alt-screen/mode CSI anywhere), IMMEDIATELY after a 3225-byte TUI-reinit-shaped absolute repaint (…821390); isolated echoes c/o/n/f/i, **NO g** — echo CEASES mid-input right after a 535-byte TUI diff (late clamp landing, invisible to byte tap). NOT resize-instant ⇒ delayed TUI-repaint-associated echo window. Seed records: clamp ownership open (TUI SetConsoleMode vs ConPTY-internal); spt mitigation may be structurally impossible (daemon can't touch child console modes) — honest outcome may be UPSTREAM finding; 7.55 instrument = reusable tooling. Rides out like the double-serve seed, NOT branch-blocking. ⚠ Registry tail moved third time — todlando warned to merge main BEFORE the rescope commit.
  - 🔨 **W3 GATE UNDERWAY (PR #60, head 876aba3, MERGEABLE):** code legs DONE (KH 7.55 rewrite per ruling; unit rung accepted; Amendment 2 + fix verified prior turn). ⚠ CI: db06961 docs-only main push went RED on ONE Windows test (registry_lifecycle multichunk_feed_applies_with_exactly_one_snapshot_write) — zero-.rs-delta established FIRST (identical tree green @53cdeab + doyle's 2081/2081); window overlapped heavy local ConPTY work; VERDICT environmental contention; rerun dispatched. Disk 43.6 GB fine. Watchers armed on 3 runs (seed f8dfd2e, db06961 rerun, PR 29940994338); LOCAL BATTERY after box quiets — prebuild `cargo build -p mock-adapter --bins` (capture-player AND console-mode-probe, W1-gotcha class). ⭐ STANDING RULE both sides: CI job in flight = hands off the box (todlando adopted; doyle batches docs pushes behind gate windows). 📌 **d1f665f (KH 7.55 seed-pointer one-liner) sits COMMITTED-UNPUSHED in todlando's w3 worktree — RULED: after PR #60 merges at 876aba3, doyle CHERRY-PICKS d1f665f onto main** (objects local, authorship preserved, zero extra PR cycles). Then release lane: deployah, counter 74.
  - ⚠ **CI ROUND 2 (2026-07-22): all three watched runs down, TWO causes separated.** (1) **PR #60 Linux clippy = REAL**: deny-warnings fails `console-mode-probe` — `set_status` never used on Linux (Windows-targeted probe; todlando's local clippy was Windows-only; gate-cross-platform-leg rule earned its keep). Fix dispatched: cfg-gate, NOT allow(dead_code). (2) **PR #60 Windows leg GREEN — full suite incl. BOTH W3 rig families passed CI.** (3) db06961 rerun red on a DIFFERENT test (endpoint_autostart_e2e saved_endpoint_replays_on_daemon_restart + DOCS_SERVER_BIND_FAIL port-5474-in-use noise) — two DISTINCT flaky reds on a docs-only commit while the PR superset ran green same box same hour = ENVIRONMENTAL, banked not chased (⭐ candidate backlog seeds: multichunk_feed snapshot-write count race + endpoint_autostart port-collision noise-tolerance). (4) ⭐ DOYLE PROCEDURAL LESSON: `gh run rerun` on an OLDER main commit while a NEWER main run is in flight CANCELS the newer via the concurrency group — f8dfd2e run died to my rerun; re-dispatch f8dfd2e AFTER the merge, never rerun-over-in-flight. **d1f665f ruling REVISED: rides WITH the clippy fix push** (fix forces a new head + full CI anyway — sentence travels free; cherry-pick plan dead). Sequence: todlando pushes fix+d1f665f → new head → its CI + doyle local battery in parallel → verdict → merge → re-dispatch f8dfd2e main run → release lane.
  - ⚠ **CI ROUND 3 (a2c1dbb run 29943307918): Linux GREEN (clippy fix confirmed on the real leg) — Windows red on endpoint_autostart_e2e saved_endpoint_replays_on_daemon_restart AGAIN (2nd time), and the panic CLASSIFIES it:** expected token line arrived as `ENDPOINT_AUTOSTART:gwauto adapter==== spt brain stderr — generation 0 — pid … ===cc` — brain-stderr banner SPLICED MID-LINE = stderr multi-writer interleave race in the e2e's capture surface. **DISCRIMINATOR: red on db06961 (ZERO W3 content) + green on 876aba3 (FULL W3 content); a2c1dbb's Windows-relevant delta vs 876aba3 = nil (cfg-as-unit compiles identical on Windows; docs). Flake, NOT the PR.** Machine-wide-lock hypothesis KILLED by code read: spawn_lock = spt_home().join(SPAWN_LOCK_FILE) = PER-HOME (PR-body "machine-wide" wording loose; isolated homes don't contend). Failed-leg rerun dispatched on quiet box (watcher bcpiamd6v); battery after; merge after both. **Post-release flake seeds to file: (i) endpoint_autostart stderr-interleave (verdict asserted on an interleaving stream — the 7.55 instrument lesson in reverse), (ii) registry_lifecycle multichunk snapshot-write-count race.** DOCS_SERVER_BIND_FAIL port-5474 noise = tolerated-by-design line, appears in green runs too, NOT the failure.
  - ✅⭐ **MECHANISM 1 CLOSED ON BRANCH (todlando 2026-07-22): amendment + fix + 4-rung regression, 2 commits after merging main db06961.** `5e1a98e` = ADR-0047 **Amendment 2** (root retraction w/ the 3-probe evidence; 6 oracle clauses; vehicle-fidelity clause; rig re-attribution + its stated limit; console-mode-seam class) + REQ rescope in registry. `6770afe` = the fix: `with_vt_output` gains DNAR, plus the ladder. **⭐ CLAUSE (a) WORDING CORRECTED, measured not argued: PER CELL, never per byte** — ConPTY re-renders (POST window 14598 B in / 14929 B out with ZERO divergent cells), so byte equality is unsatisfiable by construction and would disqualify every ConPTY rig forever incl. 7.55's. **⭐ RULING-5 MEASUREMENT ANSWERS MORE THAN ASKED: DNAR makes the vehicle cell-transparent (probe 3 row 6 "AB"→"    AB"; probe 2 1→0 divergent rows) AND DNAR SET AT CHILD STARTUP SURVIVES A ConPTY RESIZE** (fixed leg resizes 24x80→60x131 mid-run, 3/3 clean) — NOT transferable to 7.55 (different bits, different handle; ECHO/LINE across resize still unmeasured). **THE 4 RUNGS, each a different question:** spt `with_vt_output_disables_newline_auto_return` (pure composition) · spt-term `rc_console_newline_presentation` (the MECHANISM on the real platform: spec VT=INDEX, rc-as-composed=column-reset, rc-fixed=INDEX — doyle ruling 3, the executable rationale) · spt-term `capture_vehicle_fidelity` (clause (a) as predicate + non-vacuity sibling manufacturing "/c/config" with zero spt code) · spt-daemon `attach_resize_capture` (client-model PAIR + a **no-vehicle control** = grid+resize+repaint 0 divergent rows, which both exonerates the seam AND localizes any future disagreement to one side). ⭐ **BOTH PAIR HALVES ARE PERMANENTLY GREEN** — the "red" half asserts the divergence APPEARS (capability-probe shape); a literally-red committed test was never the deliverable. capture-player: `--vt-passthrough` → `--console-mode rc|rc-fixed`, header flags that it MODELS rc's composition and can drift (the unit test pins rc itself). **⭐ SCOPE AUDITED NOT ASSUMED:** helpfmt's console setup deliberately NOT touched (prints OUR text — DNAR would stair-step help output; DNAR belongs only where we present someone else's cursor-addressed bytes), and rc emits no bare LF of its own inside the DNAR window (rc.rs:2400 sole LF, carries explicit CR; parting prose writes AFTER drop(_raw) restores). GATE: clippy --workspace --all-targets clean · W3 rig 5/5 · spt-term full suite · attach + attach_idempotent_replay + attach_resize_repaint + resize_geometry_epoch + resize_presentation_barrier all green · no leaked children. traceable-reqs clean EXCEPT REQ-RESIZE-INPUT-MODE-INTEGRITY impl/unit/int = 7.55, activated-not-yet-built = next task, not a regression. ⏳ **FLAGGED FOR DOYLE'S RATIFICATION: todlando APPLIED the REQ-ATTACH-RESIZE-REPAINT rescope** (["unit","int"], impl dropped, title rewritten to own the regression apparatus) rather than leaving it — leaving impl required left `traceable-reqs check` red on a stage no longer owed, and shipping a stage pointing at non-existent evidence was the worse option; reversible in one edit, nothing depends on it. ⏳ hertz field-confirm still converts strong→closed attribution.
  - 📏⏳ **7.55 MEASURED — THE RESIZE DOES *NOT* ALTER THE CONSOLE INPUT MODE (todlando @0f74bba, pushed).** Instrumentation-first per the REQ's own contract. Raw ConPTY 24x80→60x131, 4 sample points, ALL IDENTICAL: `in=0x000001f0 out=0x00000007 echo=0 line=0 dnar=0` at boot / before-resize / after-resize / before-write; typed bytes do not echo back. **Amendment 1's addendum supposition ("something across the resize path re-enables console echo on the nested ConPTY") is NOT what happens on this box/portable-pty version.** ⭐ **THREE THINGS MAKE THE ABSENCE-CLAIM MEAN ANYTHING:** (1) the probe MUST be a CHILD — modes belong to the console the hosted child runs under; the daemon holds the master end, isn't attached, and CANNOT GetConsoleMode it from outside ⇒ **the REQ's impl text ("probe console input mode at spt-term pty.rs resize") names a probe point that physically cannot see the child's console**; (2) **the probe goes RAW FIRST + the rig asserts that precondition** — a pseudoconsole BOOTS with echo+line ON (`in=0x000001f7` measured), so a non-raw probe sits at exactly the default the seam is suspected of restoring and can't tell "resize reset it" from "it was never changed" (oracle-vs-itself blindness, new costume); `--raw`→0x1f0; (3) capability probe `--reenable-echo-on <tag>` seeds cooked input back on and requires BOTH observables to move (mode word AND the echo). ⭐⭐ **TWO INSTRUMENT DEFECTS, both = the instrument corrupted by the thing it measures — the transferable lesson:** (a) status CANNOT live on stderr — under ConPTY the child's stderr interleaves into the same re-rendered stream and arrives SHREDDED (read a literal `SETMODE result=` followed by a window-title escape where the verdict should be) ⇒ moved into the stdout protocol line so a REFUSED SetConsoleMode can never read as a measurement; (b) CANNOT read stdin by lines — with LINE_INPUT+PROCESSED_INPUT cleared there's no cooked line assembly, `read_line` never returns, probe answered `boot` then went deaf, **and ConPTY's post-resize REPAINT re-emitted the boot line, which looks exactly like a fresh reply** (a loosely-matching rig would have reported a post-resize sample that never happened); fix = raw byte reads terminating on CR-or-LF, which work in BOTH cooked and raw states. **DOES NOT SETTLE:** capture 2's one-byte c/o/n/f/i OUTPUT records are real; either the trigger is something else in that session or it's version/box-dependent — deliberately NOT guessed (that move produced the retracted Amendment 1 root). ⭐ **CANDIDATE OFFERED, UNTESTED:** the pseudoconsole boots echo/line ON and it's the CHILD that clears them ⇒ any window where the TUI hasn't yet clamped the mode (startup, or a re-clamp after TUI-internal state change) echoes by default with NO seam "re-enabling" anything — reframes 7.55 from "who turns echo back on" to "is there a window where nobody has turned it off yet" (different fix shape, different rig). ⏳ **RULING REQUESTED (todlando lean = (b)+(c)):** REQ-RESIZE-INPUT-MODE-INTEGRITY impl+unit unsatisfied, traceable red on exactly those two; gate text was written expecting a dirty seam. (a) production still gains instrumentation at the 2 probe points (but the spt-term point can't see the child's console) / (b) rescope onto what the measurement supports (instrument + rig + not-reproduced finding), as REQ-ATTACH-RESIZE-REPAINT did / (c) stay activated-and-owed pending a sharper hertz question — do the echoed keys sit near a session/TUI RESTART rather than near the resize? The spt-term-vs-write_input placement call is now arguably MOOT rather than answered. GATE: clippy clean, 7.55 rig 3/3, mechanism-1 ladder still green.
  - ✅🚦 **W3 GATE-READY: PR #60 @876aba3** (todlando 2026-07-22) — https://github.com/BigscreenVR/spt-bs-core/pull/60. Doyle ruled **(b)+(c)**: 7.55 REQ rescoped `["doc","unit","int"]` (impl DROPPED **structurally** — the daemon can neither observe nor set the hosted child's console modes, so the old invariant's probe points named a console they physically cannot see; **(a) production instrumentation DECLINED — "measuring the wrong console is manufactured confidence"**; placement ruling MOOT, nothing to restore when the mode is preserved) + KH 7.55 rewritten to the measured truth (invariant KEPT since it survives being wrong about the mechanism; field evidence REAL + **SERVER-SIDE** = drain records upstream of any client console ⇒ independent of 7.56; seam MEASURED CLEAN; trigger UNPINNED; window candidate OPEN). ⭐ **HERTZ GROUNDED THE WINDOW CANDIDATE (doyle, seed `REQ-TERM-ECHO-CLAMP-WINDOW` minted inactive on main @f8dfd2e):** echo onset **6003ms AFTER** the first resize-associated repaint burst, immediately following a **3225-byte TUI-reinit-shaped absolute repaint**; ceases mid-input (c/o/n/f/i, **no g**) right after a 535-byte diff = late clamp landing, invisible to a byte tap. **NOT resize-instant** — the reframe was right and is now field-grounded; spt may not even be able to mitigate (honest outcome may be an UPSTREAM finding); the 7.55 instrument is named as reusable tooling. Rides out like the double-serve seed, not branch-blocking. ⚠ **THIRD registry-tail collision was REAL** — traceable-reqs.toml conflicted on exactly the REQ-RC-NEWLINE-PRESENTATION-TRUTH stages line (main mint-inactive vs my activation); resolved keeping the activation + taking the seed entry verbatim. GATE EVIDENCE all re-run POST-merge: traceable-reqs **exit 0** · clippy --workspace --all-targets clean · **xtask check: OK** · spt-term full suite (all 4 W3 rigs) · spt-daemon attach_resize_capture 5/5 + attach_resize_repaint + resize_geometry_epoch + resize_presentation_barrier + attach + attach_idempotent_replay green · spt rc unit 2/2 · no leaked children. ⚠ **RUNNER GOTCHA (W1 mock-session class): BOTH W3 rig families need `cargo build -p mock-adapter --bins`** (capture-player AND console-mode-probe) or they fail on a MISSING BINARY, not on code; Windows-only + HEAVY. NEXT: doyle gate (full battery) → merge → deployah release lane **counter 74**; hertz field-confirm at release covers DNAR rendering + typed-through-resize no-echo + NOTIF observable 3. ⏳ **HELD, UNPUSHED: `d1f665f`** (docs-only, KH 7.55 candidate para now cites the hertz timeline + names the seed — doyle's cosmetic non-blocker). Deliberately NOT pushed: a PR push queues a 4th CI run ahead of doyle's local battery on the shared box. **SUPERSEDED — PUSHED @a2c1dbb, cherry-pick plan DEAD** (doyle revised: a Linux clippy fix forced a new head + full CI cycle anyway, so the docs sentence rode along free). ⚠ **PR #60 LINUX CLIPPY WAS REAL AND MINE:** `-D warnings` → `function set_status is never used` in console-mode-probe — the probe is Windows-targeted so the Linux compile leaves the writer dead while its reader stays live; **local clippy runs on Windows and STRUCTURALLY could not see it** (same shape as the 7.55 finding itself: the vantage point decides what's observable) ⇒ [[gate-cross-platform-leg]] earned its keep. Fixed by cfg-gating the status apparatus **as a UNIT** (`#[cfg(windows)] mod setmode`), NOT `allow(dead_code)` (would compile machinery that can't act on that target and call it acceptable — the lint was right) and NOT per-helper (leaves a static read-but-never-written = dead weight dressed as portable); non-Windows reports `setmode=n/a`, protocol shape unchanged. ⭐⭐ **TECHNIQUE WORTH REUSING — verify another target's cfg path with NO cross toolchain:** `#[cfg(windows)]` is target-driven so it's always true locally; copy the file to scratch, rename the predicate to one never set (`cfg(windows)`→`cfg(fakewin)`, `cfg(not(windows))`→`cfg(not(fakewin))`), then `rustc --edition 2021 -D warnings --crate-type bin` it standalone (works when the off-path has no external deps). **Ran BOTH directions**: pre-fix (`git show HEAD:<file>`) reproduced CI's exact error, post-fix exit 0 — a check that passes on the fix but was never shown to fail on the defect proves nothing. NOT a replacement for the CI leg, just a local approximation so the next head isn't a guess. ✅ Windows re-verified after: clippy clean, 7.55 rig 4/4. ⭐ **PR #60 WINDOWS LEG RAN FULL SUITE GREEN INCLUDING BOTH W3 RIG FAMILIES** — the heavy rigs pass CI. ⭐ **doyle's own procedural finding, standing-rule class: NEVER rerun an OLDER main run while a NEWER one is in flight — concurrency CANCELS the newer** (his db06961 rerun killed the f8dfd2e run; he re-dispatches after merge). db06961 rerun red was a DIFFERENT test again (`endpoint_autostart_e2e`, port-5474-in-use) — two distinct flaky reds on a docs-only commit while my PR ran the SUPERSET green same hour/same box = environmental, banked, not chased. ⚠ ORPHAN HAZARD DISSOLVED (d1f665f is on the remote); worktree + branch still stay until merge. ✅ **a2c1dbb: LINUX GREEN** (fix confirmed on the real CI leg). Windows red on `endpoint_autostart_e2e` again → **doyle's DISCRIMINATOR RUN exonerates the PR: same test RED on db06961 (ZERO W3 content) and GREEN on 876aba3 (FULL W3 content), Windows-relevant delta 876aba3→a2c1dbb nil** (cfg reorg compiles identical on Windows + docs) ⇒ the red is the flake. ⭐⭐ **THE AUTOSTART FLAKE IS MY OWN 7.55 LESSON, ONE LEVEL DEEPER — banked as rig-craft:** panic shows the expected `ENDPOINT_AUTOSTART:gwauto` token arriving with the brain-stderr banner spliced **MID-TOKEN** (`adapter==== spt brain stderr — generation 0 — pid ... ===cc`). My rig hit the same class and my first fix — anchor the parser on the token (`split_once("MODE ")` not `strip_prefix`) — handles only a PREFIX splice; it would NOT have survived a mid-token cut. **Mine worked only because ConPTY happened to splice at a line boundary; a mid-token cut would have made my rig red at random and I'd have blamed the platform.** Fix shape offered for doyle's seed: you cannot anchor harder, you must REMOVE the interleaving writer first — strip the self-delimiting banner (`==== spt brain stderr … ===`) then match against repaired text; long-run = framed/dedicated channel for the token. **GENERALISATION: a verdict must not share a stream with an unsynchronised writer** (why I moved the probe's own status off stderr into the stdout protocol line). ⚠ **The two flake seeds are DIFFERENT ROOTS despite both being Windows e2e reds** — autostart = multi-writer capture race (assertion's INPUT is corrupt); multichunk = snapshot-count expectation under contention (input fine, count isn't). Filing them as one "flaky Windows e2e" would fuse two roots = the shape that produced the Amendment 1 retraction. Both filed post-release, doyle's lane. ~~keep it exactly where it is — do NOT push, do NOT drop; he cherry-picks `d1f665f` onto main directly after PR #60 merges~~ (objects are local to this repo — the worktree's `.git` is a gitdir pointer into `spt-core/.git`, so the main checkout can reach it; authorship rides along; docs-only-on-main is the established triage lane; costs zero extra PR cycles instead of a full run for a sentence). ⚠⚠ **HAZARD — d1f665f EXISTS IN EXACTLY ONE PLACE (unpushed, reachable only via the local `build/daemon-lifecycle-w3` branch ref): DO NOT remove the W3 worktree OR delete the branch until doyle confirms the cherry-pick landed.** Standard post-merge hygiene (doyle told me to remove the W1 worktree after #59) would orphan it and make it GC-eligible. ⭐ **STANDING RULE RE-AFFIRMED BOTH WAYS (doyle, mine too): CI job in flight ⇒ HANDS OFF THE BOX** — no cargo/suites/rigs. doyle's db06961 main-push run went RED on `registry_lifecycle multichunk_feed_applies_with_exactly_one_snapshot_write` (Windows leg) on a **DOCS-ONLY** commit; identical .rs tree green at 53cdeab + in the 2081/2081 battery, failure window overlapped heavy local ConPTY work (my post-merge battery among it) ⇒ environmental contention, rerun for a clean record. Zero-.rs-delta is the first thing to establish on any such red ([[v0400-published]] pattern).
  - (superseded gate-in-progress note follows) Seed's static double-serve claim verified myself (seed pre-loop + unguarded loop Request arm, attach.rs). Rider verified at BOTH presentations (single shared notifgate, kind-keyed, unopenable-store = not-live safe direction, no-notif_id passes). Stop-inhibit: pure ensure_decision RUNNING-first, re-decide under spawn lock, loud lock degradation; UPDATE PATH SAFE (update calls stop_daemon() direct = no inhibit minted; start_daemon() = intent verb clears inhibit; `daemon run` deliberately does NOT clear — service manager must not overrule operator). Custody livehost consumers = one honest pair question each; reap-side clear only after the pair test deferred. PR CONFLICT (my a49394d/5ef2d67 tail edits) RESOLVED by todlando merge @a6cebae — zero .rs delta verified my side, KH 7.53 placeholder replaced as scripted, both toml tail entries ordered right. PR body transcripts read: all four RED shapes genuine (fix-1 discriminates BOTH directions; fix-3 = lease-replacing-itself in own breadcrumbs). PENDING: CI green (main run 29913640247 + PR run 29914267841, background watcher armed) → then local battery in `.worktrees/gate-a6cebae` (created, detached) with throwaway target: leg 0 cargo build --workspace, clippy preflight, nextest int battery, prebuild mock-session fixture for attach_wedge_e2e, sweep leaked exes before every cargo call. Then verdict → merge → W3 dispatch.
  - ✅ **BANKED QUESTION ANSWERED — origin CODE-PROVEN, seed filed** (REQ-ATTACH-SEED-REQUEST-DOUBLE-SERVE, inactive, @22b1419): `serve_attach` honors the dispatcher-pinned `seed_request` through `handle_attach_request` BEFORE its event loop (ADR-0038 B — the seed exists because a ROLLED ring can no longer replay the Request), then the loop's `AttachRecord::Request` arm calls it again **UNCONDITIONALLY — no `!attached` guard, no memory that the seed already established this Request**. Ring not rolled ⇒ the replay still carries that Request ⇒ ONE record handled TWICE on the SAME conn ms apart with identical (session_id, from_seq, intent, gen, identity) = hertz's conn1011 capture, and the identical from_seq is why the W1 discriminator catches the real shape. Fix shape + siblings recorded on the REQ; NOT built (broker idempotence absorbs every origin incl. unfound ones; the serve-path rig belongs to the seed per doyle).
- **W2 — C3 RETIRED (doyle verify-first 2026-07-22, main @a49394d pushed):** the C3 poll-vs-reap race was ALREADY CLOSED by REQ-CONTROL-STAMP-CONVERGENCE (ADR-0041 decision 4, REGISTRY-LIFECYCLE, todlando 2026-07-17 — one day after the RCA): stamp_reaped bumps per-endpoint StampSlot gen UNDER the stamp-write serial then clears (comment names the emphasys C3 window); KIND_SESSIONS snapshots gen under log lock; converge_perch_stamps validates under the same serial, refuses stale (STAMP_STALE_SKIP). Unit + int (endpoint_lifecycle.rs:488) ride that REQ. REQ-STAMP-CONVERGENCE-ORDER retired-with-note in the registry, stages stay []. **W2 remaining = REQ-STREAM-LIFETIME-CLASS only** (C2 raw-viewport leak — ConnectionBound vs durable lease classes, ADR-0038 territory). **C2 SURVIVAL RE-VERIFIED post-W1-merge (doyle 2026-07-22):** reap_dead_controller's own scope note reserves the truly-idle severed controller (writer parked on recv, no output, no EOF) to the UNBUILT REQ-HAZARD-DRIVEN-BY-IDLE-REMOTE-EVICT; W1's idempotent leaf only affects SAME-conn replay — a dispatcher re-serve post-restart is a different-conn fix-6 successor that RE-ESTABLISHES the leaked seat. W2 = real build. ⭐ Design coordination banked: C2's ConnectionBound class may BE the systemic close for the idle-remote-evict residual too (D4c NetPresence disconnect → FIN ConnectionBound streams → clear_controller, per the 2026-06-19 oracle ruling) — design the class taxonomy so both REQs land on one mechanism. Full design refresh at W2 dispatch (after W3). ⏳ **W2-C2 NOT YET DISPATCHED — DO NOT START IT (doyle ruled 2026-07-22).** Sequence is strict: deployah cuts **v0.41.0 from @7c0f12d** → publish → hertz field-verify dispatch → **THEN** W2-C2 dispatch to todlando. Two reasons, both binding: the release lane owns the box (multiple CI cycles; the hands-off-during-CI rule cuts both ways), and a C2 landing mid-cut would **contaminate the changelog scope** ([[changelog-scope-vs-commit-range]]). Doyle runs the C2 design refresh (code-read triage, NO cargo) during the release window so the dispatch is ready the day the lane clears; it may fold in the fixture-bin `target_debug_dir` fix (REQ-XTASK-SPT-BIN-TARGET-DIR class — todlando's `player_bin()`/`probe_bin()` hardcode `<root>/target/debug` and ignore CARGO_TARGET_DIR, 2nd instance; one shared seam fixes all call sites) if the wave shape allows. ~~Until dispatch: idle is CORRECT.~~ ✅ **W2 DISPATCHED + STARTED 2026-07-22** (v0.41.0 published @counter 74; lane `.worktrees/daemon-lifecycle-w2`, branch `build/daemon-lifecycle-w2` off main @3aecc35, pushed). **`W2-JIT.md` on the branch = the working plan (legs A/B/C, seams located, traps named).** ⭐ **C2 RESCOPED AT ACTIVATION, NOT BUILT — doyle's verify-first finding, which I re-grounded cite-by-cite against @7c0f12d: the ConnectionBound CLEAN CASE IS ALREADY SHIPPED** under REQ-STREAM-LEASE-CLASSES/ADR-0040 dec 6 (opener-declared class + additive wire msg.rs:810-836 w/ serde-default unit @1408; rc attach/view = SOLE ConnectionBound opener attach.rs:667-677; broker binds @5689; nethost per-StreamEntry @1059-1076; conn-exit sweep FIN+terminal-retire @4118-4123; serve_attach EOF→detach_session_gen(serve_gen) attach.rs:580-597; late-close gen guard @2179-2192). **General form of the C3 lesson: a REQ title is a HYPOTHESIS about the code, never a report on it.** **LEG A (the real residual) = restart-replay re-establishment:** ADR-0038 replay re-serves retained opener Attaches across a dispatcher generation, and a **ConnectionBound opener REPLAYING is a class contradiction** (the conn that declared the class cannot exist after the restart that killed it). Fix = lifetime on the replay classification (dispatch.rs `first_line` ~717) + terminal-retire filter; **PRECISE, not ADR-0038's rejected clear-table-on-restart** — brain_swap/daemon_refresh/redispatch D1+D1b staying green IS the proof. Filter sits **UPSTREAM of the W1 idempotence key** (they compose, don't overlap). ⛔ **CARRIER QUESTION SETTLED — NO WIRE FIELD. My additive-`NetStreamOpenerReply` proposal was REJECTED on a REACH FACT I failed to check before proposing (verified myself after): the row a dispatcher re-serves is the ACCEPTED row (cross-node) or the loopback PEER row, and BOTH register `Durable` — CLASS-BLIND BY DESIGN, source comment says so outright** (`nethost.rs:1028-1041`, `1763-1771`). A lifetime field on the opener reply would report Durable for **exactly the population the filter exists to catch** = undercounts leaked rows to ZERO + spends wire surface on the wrong rows. ⭐⭐ **GENERALISABLE: check WHICH ROW the code under test actually serves before designing a carrier to describe it** — same class as 7.55's vantage-point finding (applied it right there, missed it here). **PLACEMENT if a filter is owed at all: BROKER-SIDE, NO wire change** — broker holds BOTH discriminating facts (row class AND transport conn liveness) ⇒ filter at enumeration/claim, **REGISTRY-STALL B2 shape** (server-side in `stream_infos` before anything crosses IPC). ⭐ **The sharp key for REPLAY is "is this row's transport conn ALIVE", NOT class** — class only separates rows whose conn is already known dead. ⚠⚠ **LEG A's PREMISE IS PRE-REGISTERED AS FALSIFIABLE (doyle, before any build): post-d6 the leak population may ALREADY be closed by composition** (conn-exit sweep FINs / cross-node `conn.closed()` retires rows nethost.rs:1000-1021 / retired rows excluded from redispatch eligibility ADR-0038 dec 1 — all shipped). **If kill-opener-raw → restart-brain does NOT re-establish the seat, that is SUCCESS → Leg A rescopes to a verify-note**, and doyle's "survival re-verified" memory was reasoning about pre-0038/0040 composition. Rig header must say so or a non-repro reads as a broken rig. **NO WIRE CHANGE IN ANY BRANCH WITHOUT A RED TRANSCRIPT NAMING THE ROW IT FAILED TO FILTER.** Two sub-questions a red would settle: (1) does "retire" (eligibility-only, REGISTRY-STALL finding) actually exclude from the CLAIM condition on the hit path? (2) did the conn-exit sweep run at all for the kill shape used? **LEG B = REQ-HAZARD-DRIVEN-BY-IDLE-REMOTE-EVICT, activated `["int"]` ONLY** (instrument-first; impl/unit activate only if the measurement shows the heal is absent — the 7.55 shape, don't pre-fail stages a measurement may prove unowed). Discriminating observable: does target `conn.closed()` row-retirement (nethost.rs:1000-1021) ALREADY surface NetStreamEof to a serving serve_attach worker? **NEVER measured on real QUIC** — the existing "clears on NEITHER platform" characterization was on in-process loopback where the true half-open is **unstageable by its own comment** (inject_control_wedge @2300-2305). ⚠ **SIBLING PROBE FIRST: clean-FIN detach must be visibly observable in the same twohost rig before any no-FIN absence claim counts.** 3 legitimate outcomes: (a) already heals → shrink to KH-wording+coverage, REPORT BEFORE BUILDING; (b) doesn't → presence-FIN synthesis so serve_attach's EXISTING EOF arm stays the ONE exit shape (W3 principle); (c) ambiguous → bring doyle the measurement. Honest scope limit either way: presence closes DEAD-conn-no-FIN only; alive-but-WEDGED (KH 7.15 A2) stays deferred, boundary STATED. **LEG C = ADR-0040 AMENDMENT after Leg B settles** (teardown authority = opener class + transport liveness at the 3 places dec 6 couldn't see); ⚠ target rows stay class-blind (mirror rows Durable nethost.rs:1028-1043, loopback peer @1763-1771) — **CORRECT, class is opener-side, do NOT "fix"**; two classes suffice. **FOLD-IN:** fixture-bin CARGO_TARGET_DIR fix (REQ-XTASK-SPT-BIN-TARGET-DIR 2nd instance, MINE) at 4 sites — one shared `current_exe()`-derived resolver (`twohost.rs:437 seed_notify_shell` precedent; `CARGO_BIN_EXE_*` unavailable cross-package). ✅ **C2 DESIGN REFRESH DONE 2026-07-22 → [[w2-c2-stream-lifetime-design]]** (clean leg already shipped per ADR-0040 d6 — REQ rescope; real build = replay filter + presence-FIN synthesis, instrument-first; fixture-bin fix folds in).
- **W3 (SHAPED 2026-07-22, main @7b0c5ab — hertz's ENLYZEAM byte-capture RCA landed and doyle seam-verified same hour):** bug-3 = **attach/resize presentation race**. TWO resize entries exist: IPC ResizeReq is sound post-0.39.4 (full barrier + repaint at landed geometry); rc's INITIAL viewport resize (attach-stream `send_attach_resize`, rc.rs ~1934) never arms the barrier → commit_resize's no-transition branch resizes silently ("no sync frame owed" — FALSIFIED: geometry change invalidates painted cells by itself). Old-geometry attach repaint + silent geometry landing + reflow-assuming differentials = the field /c-scraps at fixed window size (why 3 resize-scoped iterations missed it; why the fresh-session isolated rig couldn't repro). ADR-0047 **Amendment 1** + **KH 7.54** + REQ-ATTACH-RESIZE-REPAINT (inactive). Fix = every resize entry rides the ONE barrier; initial resize's committed repaint supersedes the attach paint; no-transition branch survives only sink-less. ⭐ ORACLE BINDING: regression replays the captured 80x24→131x60 menu/keystroke shape into an INDEPENDENT VT emulator (ScreenGrid-only = non-authoritative). Dispatches to todlando AFTER W1 merges (same broker.rs seam). All four v0.39.4 field bugs now have accepted roots.
  - **W3 SCOPE WIDENED same day (@052e8c4, hertz second capture — operator resized a LIVE viewport, repro'd immediately):** (1) not attach-limited; (2) SECOND MECHANISM — post-resize the nested ConPTY ECHOES keystrokes as isolated output records (raw==broker, one-byte c/o/n/f/i frames) under a no-echo TUI; the field `/c/config` = echo colliding with menu paint. **KH 7.55 + REQ-RESIZE-INPUT-MODE-INTEGRITY** (inactive, W3): instrument console input mode across the spt-term pty resize seam + before write_input, assert ECHO/LINE disabled, restore-with-loud-record if the platform resets them; typed-through-resize regression leg RED-first. spt-core touches console modes nowhere in-tree — the seam was uninstrumented; 3 render-side iterations shipped against a partly input-side defect. Both W3 fixes stand on their own evidence.
  - ⭐ RIDER CORRECTION (operator-caught): perri's stale notices arrived as INJECTED TURNS (woke the agent) — they were LEGACY 0.39.x plain-window mints (spool rows carry window from insert time); 0.40.0 deferred mints cannot inject (every production drain_all_at caller = test; 4.4 hazard holds — code-verified). Rider contract delta sent to todlando: validity gate keys on envelope KIND, not the deferred column, at BOTH presentations (relay non-deferred drain + active-window poll); KH 7.53 invariant wording to match. Legacy copies out of scope with the explicit timing argument (they drain-and-wake once each, fleet-wide spent before any fixed binary lands).

**W3 BUILD STATE (todlando, 2026-07-22) — branch `build/daemon-lifecycle-w3`, 7 commits pushed, NO PR (main leg deliberately RED = the reproduction):**
- ⭐ **BUG 3 REPRODUCED** @a230f9a — first time outside the field. `crates/spt-daemon/tests/attach_resize_capture.rs` replays hertz's capture through the REAL seam via `capture-player` (new mock-adapter bin, two windows + stdin gate, order-not-pacing).
- ⭐ **THREE ORACLE BLINDNESSES caught by the capability probe before any green was believed.** (1) synthetic w/ inherited narrow fixture = geometry-INSENSITIVE → blind; (2) capture rig w/ post-window-only authority → blind; (3) probe itself passed VACUOUSLY against an empty candidate screen (release keystroke sent from the spawner conn; PTY input is controller-fenced once the client takes the seat). Rule now: probe green is necessary NOT sufficient — assert the probe's own precondition.
- Oracle construction that works: NO `avt.resize` anywhere (an emulator resize imports reflow-policy divergence), width-SENSITIVE content, authority built from the CAPTURE FILE (field provenance, executes none of our renderer). Pre-state self-check (renders identically at 80 and 131) PASSES → construction (c) sound for this capture.
- ⭐ **ADR-0047 Amendment 1's stated code root is FALSIFIED THREE WAYS** (doyle accepted, error acknowledged as his): static trace (attach-stream resize DOES arm the barrier via dispatch_resize), synthetic pass, and the broker's own dynamic trace (attach → RESIZE_DISPATCH → SYNC_PUSH controller=true, no RESIZE_SYNC_DROP). The decision stands; the named path does not. DO NOT re-litigate.
- Fixture committed at `crates/spt-daemon/tests/fixtures/enlyzeam/` w/ README (provenance, hertz segmentation, anchor rationale + REJECTED candidates table, sha256 integrity record) and `.gitattributes *.log -text` (autocrlf would silently rewrite evidence while everything stayed green).
- **NEXT = the capture bisect** (doyle-approved, 3 rules: per-step hygiene both legs green; never bisect across the stdin gate; record subsets before intra-record content, boundaries before bytes). Plan written for a fresh context: `W3-BISECT-JIT.md` @94fd6db. Root NOT pinned; amendment waits (one landing). 7.55 untouched — own capture window + banked spt-term-vs-write_input placement question.
- Gate note: `cargo build -p mock-adapter --bin capture-player` first; both W3 rigs Windows-only + HEAVY.

**Already-shipped kin (do NOT rebuild):** REQ-REST-TERMINAL-NORMALIZE / REQ-SPAWN-FRESH-TRUTHFUL / REQ-ENDPOINT-CYCLE-HONEST landed via REGISTRY-LIFECYCLE; REQ-LIVENESS-ORACLE-SOUND + REQ-HAZARD-TEARDOWN-DEADEND via TEARDOWN-AUTHORITY. Custody fix must honor KH 7.50 (creation time from snapshot, never a retained handle).

**Lane:** doyle triage ✅ → todlando builds (in progress) → doyle gates → deployah release → hertz field-verify (bug-4 leg re-verified on a REAL update; NOTIF quiet-delivery observable 3 rides the same next-cut window — ping hertz BEFORE apply propagates, [[notif-truth-plan]]).
- 🏁 **W3 GATED + MERGED @7c0f12d (doyle 2026-07-22). BUILD LANES CLOSED.** Final battery (after disk sweep 14.9→230 GB + fixture-bin workaround + 4 self-caught cwd misfires → cwd-independent manifest-path mechanism): **2100/2100, NEXTEST_EXIT=0, CLIPPY_EXIT=0** — verdicts from exits every leg. 34 leaked rig children reaped by path. Gate skeleton handle-pinned (5th on reboot list); gate target swept (288 GB free). d1f665f merged via PR — todlando cleanup green-lit (W3 worktree + branch). **RELEASE CUT DISPATCHED TO DEPLOYAH (c74, v0.41.0 minor — deliberate stop-sticks behavior change):** full changelog buckets + the do-not-overclaim guard (bug-3 = pinned root FIXED, echo residue SEEDED not fixed; Amendment-1 retraction must not read as "fixed the old narrative") + ⭐ hertz PRE-APPLY PING standing order + cut-only-after merge-run 29947783825 green (watcher armed). Doyle post-publish dispatch to hertz covers: NOTIF obs 3, DNAR stock-vs-fixed /config contrast (= attribution CLOSE), typed-through-resize no-echo, bug-4 replay leg on the REAL update. **Post-release doyle queue:** fixture-bin CARGO_TARGET_DIR fix (with #13, second instance), 2 Windows-e2e flake seeds (stderr-interleave + multichunk count), flynn #61-63 triage, W2-C2 design refresh (the one remaining DAEMON-LIFECYCLE build item), echo-clamp-window seed rides hertz/upstream.
- 🚦 **RELEASE PR #64 OPEN + DOYLE GATE GO (2026-07-22): release/v0.41.0 @6b13f07 off 7c0f12d, GO conditional ONLY on PR run 29950701435 green at run level.** Independently verified: 3 files zero .rs delta; single workspace bump; lockfile EXACTLY 11 first-party pairs by diff. Both deployah judgement calls RATIFIED: (1) xtask gen output REVERTED correct — zero .rs delta = no CLI surface change since cdea554's regen, CRLF-only churn, docs-drift CI leg backs it mechanically; (2) lockfile verified BY DIFF not count — ⭐ aws-lc-sys ALREADY at 0.41.0 pre-bump (doyle confirmed at parent) = count reads 12-vs-11 false over-application, mirror of v0.39.4 quick-xml (third-party at OLD version); count ambiguous both directions, diff neither; runbook note approved for post-lane docs PR. CHANGELOG PASS: 5 items match merged content, do-not-overclaim guard honored (bug-3 fixed-window scope + echo residue "still under investigation"), minor justified, end-user voice, scope f31849c..7c0f12d complete (#57/#58 docs/CI-only omitted). NEXT: deployah FF-merge→tag→draft→counter re-verify (expect 73→74)→hertz go-ping 2h ARMED hold→sign+publish→pings doyle at publish-ready for ledger confirm. Meanwhile doyle: W2-C2 design refresh code-read → DONE, [[w2-c2-stream-lifetime-design]].
  - ⚠ **PR #64 run 29950701435 RED → RATIFIED ENVIRONMENTAL, rerun dispatched (2026-07-22).** Victims = xfer PAIR (push_survives_target_brain_restart + fetch_lands_byte_identical), both at xfer.rs:81:5 = wait_for_stream_except 400×5ms bounded-poll DEADLINE (doyle re-read helper: zero value assertions). Clincher (deployah stderr read): CONN_LIFECYCLE stream-sub-attach @~3.9s vs ~2s budget — arrived LATE = latency not absence; zero .rs delta established first; box measured (304G free, runners idle, 17 spt procs untouched). ⭐ **TRI-OUTCOME TABLE REFINED (deployah proposed, doyle adopted): printed-panic arm SPLITS — printed-TIMEOUT (bounded-wait, nothing compared) = contention-shaped → tally+rerun; printed-ASSERTION (value compared, wrong) = dig-before-tag.** Pair-in-one-run = single slow window, not two hits. 3rd post-release flake seed filed: xfer bounded-wait budget vs shared-box contention (SEPARATE root from stderr-interleave + multichunk-count). Today's tally: multichunk, endpoint_autostart ×2, resume_no_control_steal, xfer pair. Doyle standing order: rerun red on SAME xfer pair on idle box → back to doyle with stderr BEFORE tagging; else table applies. → ✅ **RERUN GREEN at run level on 6b13f07 exact; MERGED @3aecc35 (content-identical, empty diff vs 6b13f07 verified pre-tag + version/changelog header checked); TAG v0.41.0 → 3aecc35 pushed; DRAFT build 29953466550 in flight (reversible).** Publish still gated: draft green → deployah counter re-verify → DOYLE LEDGER CONFIRM at publish-ready ping → hertz go-ping ARMED-or-2h → sign+publish → Latest/update-set verify. → ✅ **PUBLISH-READY + DOYLE LEDGER CONFIRM SENT (2026-07-22): draft build 29953466550 green all 4 jobs, 7 pre-sign assets, draft-body v0.34.0-trap grep clean; counter 74 verified at source INDEPENDENTLY by BOTH (published v0.40.0 release.json → version 73).** Hertz 2h ARMED window RUNNING (go-ping sent w/ publish-ready). Deployah fires xtask release-publish --tag v0.41.0 --key-id rel-primary-2026 --version 74 on (confirm ✓) + (ARMED or 2h expiry) → post-flip verify → doyle closes ledger at 74. → 🏁 **PUBLISHED + LEDGER CLOSED at 74 (2026-07-22T20:29:48Z), verified live** ([[v0410-published]] — incl. ⚠ seed-exposure incident + rotation ruling + tri-outcome refinement). Hertz was ARMED pre-flip (v041-ball-observer live viewer, verified not claimed; 2h bound never bound) → **doyle FIELD-VERIFY DISPATCHED same hour, 4 legs ordered: leg1 NOTIF obs-3 quiet delivery (first live watcher) + leg2a DNAR stock baseline BEFORE apply → leg3 bug-4 replay on REAL update → leg2b DNAR fixed contrast (2a+2b = KH 7.56 attribution close) + leg4 typed-through-resize no-echo (+ clamp-window recurrence watch feeds REQ-TERM-ECHO-CLAMP-WINDOW).** Awaiting hertz per-leg verdicts. Remaining after: W2-C2 dispatch ([[w2-c2-stream-lifetime-design]] ready) + post-release doyle queue (3 flake seeds, fixture-bin fix, flynn #61-63, deployah's runbook docs PR = their own) + ⚠ KEY ROTATION at next cut (days not weeks; recovery signs successor FIRST, then revoke primary).
- ✅ **MERGE-RUN 29947783825 GREEN on rerun (2026-07-22)** — main @7c0f12d clean CI record. Red-then-green victim #4 tallied on the open contention finding: resume_no_control_steal_e2e brain_respawn leg, NO panic line (process-death class — every rig assertion routes through a PRINTING teardown_panic, so silent exit-1 = died before asserting), seam contact SHALLOW (rig sets SPT_LIVEHOST_RECONCILE_DISABLE=1 twice + zero ensure_running sites ⇒ W1 delta out of contact — deployah verified all three claims independently and withdrew the touched-seam framing on evidence). ⭐ Tri-outcome-with-stderr-first table (doyle+deployah co-authored this cut) = the reusable form: rerun green→cut; same-victim red WITHOUT panic→process-death class, tally+cut; same-victim red WITH printed assertion→dig before tag; different-victim red→environmental harder. Release lane RESUMED: deployah at xtask gen → PR open (pings doyle for release-PR gate) → tag → publish c74 w/ bounded 2h hertz window at pre-publish ping. Today's contention tally: multichunk ×1, endpoint_autostart ×2, resume_no_control_steal ×1 — all greened on retry, all no-panic-class or count-race, feeds [[e2e-leaked-daemons-shared-box]].

## W2 build (todlando lane `.worktrees/daemon-lifecycle-w2`) — Legs A+B CLOSED 2026-07-22

- **Leg A CLOSED @713f5d0, GREEN, doyle-RATIFIED** — premise FALSIFIED (the pre-registered success branch): restart-replay population is closed BY COMPOSITION (sweep → FIN → `finished=true` → `finished_row_is_terminal(Attach,true)` retires unserved). REQ-STREAM-LIFETIME-CLASS rescoped to `int` only; no wire field, no filter owed. ⭐ Finding: `retire` does NOT exclude from the CLAIM condition — the dead opener's row is still ENUMERATED, merely finished; what stops the replay is retire-on-sight in the WORKER (`dispatch.rs`), DOWNSTREAM of the claim. ADR-0038 d1 holds through its lifecycle-state arm, NOT its enumeration arm — two designers reasoned from the non-load-bearing arm in one week.
- **Leg B CLOSED @e1d3add, GREEN, OUTCOME (a)** — `crates/spt-daemon/tests/transport_death_eof.rs`. A no-FIN transport death DOES surface `NetStreamEof` to an already-serving `serve_attach` worker. **Two samples: clean FIN 120/115ms · torn 65057/65047ms** (MESH_MAX_IDLE 60s + quinn PTO slack). ABOVE 60s = staging leaked no signal (doyle's discriminator; materially UNDER would mean investigate the staging). REPORTED not judged — no threshold encoded; REQ-HAZARD-DRIVEN-BY-IDLE-REMOTE-EVICT stays `int` only, presence-FIN synthesis NOT owed. Staging = new `NetHost::freeze_transport_for_test` (parks both net-runtime workers; endpoint alive + UDP port still BOUND — asserted; canary 0ms→2006ms proves the park landed), because a bare drop/kill CLOSES the socket and draws ICMP unreachable = not silence. KH 7.15 + 7.29 carry the numbers; A2 alive-but-wedged stays deferred.
- ⭐ **Rig lesson (paid for, banked in the rig header):** a dispatcher generation's stderr is an **ANOMALY channel, not a progress log** — `DISPATCH:<id>:` is emitted ONLY on the non-`Served` arm (`dispatch.rs` ~576-601), so a worker that serves an attach and exits on an EOF prints NOTHING. Run 1 failed its own clean leg on exactly that, and the mandatory sibling probe caught it before any torn number could be banked. Use the seat release (control stamps clearing = the worker's own detach) as the progress observable.
- ⭐ **Venue rule reconfirmed:** `net_dial_loopback`/`open_loopback_pair` = in-process duplex, NO idle timeout; `BindScope::Loopback` + real `net_dial` (redispatch D1's two-broker pattern) = REAL QUIC. Leg A used the first, Leg B the second — a rig must pick its venue deliberately, never by the word "loopback".
- Recorded-not-chased: the row leaves the target's table 0–30ms BEFORE the seat releases ⇒ a NEW subscribe in that window would see `no such stream` while the seat still serves (DERIVED from ordering, not probed — a real subscribe would steal the seat from the worker whose exit IS the number).
- **Leg C (ADR-0040 amendment) NOT drafted — doyle ruled ONE landing after Leg B settles.** Leg B report sent to doyle; twohost window now = CONFIRMATION over a real LAN, held pending doyle. Full seam battery deliberately held until after Leg C so it runs once against the final tree. Gates so far: traceable-reqs exit 0, clippy --workspace --all-targets exit 0.
- **Leg C DRAFTED + LANDED @2e4dfd1 (awaiting doyle ratify), fold-in @28d8ae5, branch pushed.** ADR-0040 **Amendment 1** — teardown authority = opener-declared class PLUS transport liveness, at the 3 points d6 couldn't see (sweep shipped · restart replay Leg A · transport death Leg B). All 7 payload items in; anomaly-channel rig clause included (my call). ⭐ **doyle DECIDED ON THE NUMBER: ACCEPT AS DOCUMENTED** — no presence-FIN synthesis, no keepalive tune. Grounds: (1) the latch is NOT a lockout (different-conn attach = fix-6 successor, takes the seat immediately); (2) residual harm = stale status truth ~65s, self-healing on a bound; (3) synthesis = a SECOND teardown mechanism on the seam where second mechanisms historically hid the bugs; (4) keepalive tune = GLOBAL QUIC tradeoff (chatter/battery/mobile), not spent on a cosmetic minute. Revisit lever NAMED not built. KH 7.15 leads with the takeover sentence BEFORE the number.
- **Fixture-bin CARGO_TARGET_DIR fold-in @28d8ae5** — 4 sites → ONE `current_exe()`-derived resolver at `crates/spt-term/tests/support/fixture_bin.rs`, `#[path]`-included (test support must not become production surface; lives in the LOWER crate so include direction follows the dep graph). ⭐ **Proven DISCRIMINATING, not merely green:** redirected CARGO_TARGET_DIR + the old path's binary MOVED ASIDE → rig still 4/4. Regression: spt-term 9/9, attach_resize_capture 5/5.
- Gates so far (verdicts from exits): traceable-reqs 0 · clippy --workspace --all-targets 0 · xtask check 0. **Seam battery deliberately held for doyle's gate window against the final tree** (ratified sequencing); twohost LAN confirmation folds into that SAME box-occupancy window — insurance, not a dependency.
- ⚠ **spt-update wake on THIS box while ON 0.41.0** (≈19:54 local, idle between turns, no self-clear): delivered as a PLAIN message from sender `spt-update` with **no notif_id / no attributes** — the ADR-0046 Amendment 1 legacy-copy shape, which the drain's row-validity gate has nothing to validate. 3 facts sent to doyle for the live-undismissed-row RCA.
- ⚠ Bash heredoc with backticks/em-dashes corrupted a docs append (git read the file as BINARY afterward) — `git checkout --` + re-append from a Write-tool file fixed it. Write the file with the Write tool, then `cat >>` / python-append; do NOT heredoc rich markdown.
- ✅ **Leg C RATIFIED IN FULL (doyle)** — Amendment 1 numbering + purely-additive + anomaly-clause inclusion + fixture-bin placement all ratified. ⭐ Ratified standard: *"a positive that would have passed under the old code proves nothing"* — the discriminating-probe shape (empty the old path, then run) is now the bar for any tooling fix.
- 🏁 **W2 RIDER BUILT @ce5728d + PR #66 OPEN** (all five bodies: Leg A/B/C + fold-in + rider; RED transcripts in body). **REQ-NOTIF-UPDATE-ROW-VERSION-RETIRE** minted registry-first, impl/unit/int. ⭐ **FIELD ROOT (doyle, live box):** pre-0.40.0 nodes (GRAVITY-NVDA-PC f15d837b) mint update notices **SUBNET-scoped with NO coalesce key**; the modern catch-up dismissal dismisses ONLY by key ⇒ **structurally blind** ⇒ a fully-updated node holds a live "update available" row FOREVER, resurfacing once per endpoint per boundary. Fix = version-grounded sweep at the SAME catch-up site, alongside (not replacing) the key path: `from_id=="spt-update"` + body-advertised version parses + `<=` running `env!(CARGO_PKG_VERSION)`.
- ⭐ **NEVER key that sweep on `kind`** — `kind=consent` is SHARED with the grants act-gate (grants.rs mints consent via the plain front door, from_id = asking agent). A kind-keyed sweep silently answers an operator's pending grant ask. Rig leg 5 (grants-shaped row untouched) asserts it, ordered BEFORE the count assert on purpose.
- ⭐ Two deliberate strictnesses beyond spec: extractor requires a **DOTTED** token (else counter-shape "update-available 5" survives only by the accident 5>0.41 and would flip to dismissing at 6.x); rig runs **ONE sweep over a MIXED table** (per-leg sweeps pass on ordering luck; a too-broad predicate only shows next to rows it shouldn't touch). **No new spt-store verb** — the relevance predicate stays daemon-side per ADR-0046; store untouched (flagged to doyle as a call that went against his "may want a helper").
- ⭐ **Honest RED reading banked:** legs 2-5 PASS in the red run too (absence claims guarding leg 1); only leg 1 changes color. Stated in rig header + PR body so "5 legs red-first" can't imply 5 discriminating legs.
- Gates: units 3/3 · rig 2/2 · propagate 10/10 · spt-store notif 14/14 · traceable-reqs 0 · clippy 0 · xtask check 0. **Doyle owns the rest**: full seam battery + twohost LAN confirmation in ONE box window. Box released.
- ✅ **All four rider calls RATIFIED (doyle, no changes):** no-store-helper (ADR-0046 no-relevance-predicate-in-the-primitive is on point; discoverability served by the sweep sitting next to `dismiss_staged_notif_if_caught_up`) · dotted-token requirement (a **behavior flip armed to fire at 6.x**, not mere strictness) · one-sweep-over-mixed-table · grants-leg-before-count severity ordering. Honest red disclosure accepted as owed.
- ⏳ **CI run 29977242525** on PR #66 head; doyle watches at RUN level (v0.40.0 lesson), then runs battery + twohost LAN confirmation in ONE window. **todlando STOOD DOWN — hands off the box, nothing owed.**
- ⚠ **PR #66 run 29977242525 RED — doyle triaged NOT-W2** (Windows Phase A only, 1/1926: `spt::shell_sleepwake_e2e sleep_wake_cycle_drives_from_both_ends`; test file untouched, zero source overlap, Linux + both n1-gates green; disk 262 GB). ⭐ **Signature discriminator: exit 1 with stdout truncated at "running 1 test" and NO PANIC BANNER = external termination, not an assertion** — a failing rust test prints a banner, a KILLED one cannot. Stronger kill-evidence than a timeout. Theory = taskkill from a neighbor's hygiene reaping a STALE PID FILE on the bounded-8 Windows pool (pid reuse). Doyle reran; watcher armed at run level.
- ⭐ My rider to that theory (sent, hypothesis not measurement — I stayed off the box): **a green rerun does NOT falsify it**, it only means the recycle missed. Reap-by-PATH (PR #58) is safe under pid reuse; kill-by-pid-read-from-a-parked-file is not — a pid file is a claim about the PAST. Pinning it needs a rig leg capturing the victim's own pid vs neighbors' pid-file contents at kill time, not a rerun. See [[e2e-leaked-daemons-shared-box]].
- ✅ **Seeded (doyle, before the rerun's color — because green proves nothing):** sleepwake = family member #5 on the environmental-cause backlog entry, carrying the mechanism split (reap-by-path SAFE / kill-by-stale-pid-file OPEN, legs 3+4), the epistemic note (**rerun color tallies contention, never falsifies**), my discriminating-capture rig shape (victim pid at start vs neighbors' parked pid files at kill time), and the candidate fix: pid-file kills verify target identity before TerminateProcess. ⭐ **My pointer for the eventual builder: that IS W1's shipped (pid, creation-time) custody pair — REQ-RESUME-CUSTODY-IDENTITY / KH 7.50** (table-first existence, start time as DISCRIMINATOR, tri-state Unproven). Fix shape = ROUTE pid-file kills through the existing check, not mint a new one; the one deliberate decision is the **Unproven arm, where the two callers want OPPOSITE defaults** — a reap that skips is a leak, a kill that guesses is this incident.
- 📌 **Seed scope pinned (doyle, on-box):** `process_identity` tri-state lives at `spt-store/src/proc.rs:598` (Present(start)/Absent/Unproven, table-existence-first, KH 7.50-safe) and is FREE to reuse; the real work is the WRITE side — today's pid files park the **PID ALONE** (`shellwake.rs:218` writes `child.id().to_string()`; `shell.pid` same class), so the fix = one write-side format (park the `(pid, started_at)` pair at spawn) + N call sites routed. Unproven inversion recorded: **kill path = NO-KILL on Unproven**.
- ⭐ **My trap for that format change (sent, banked):** a LEGACY pid-only file must read as **Unproven ⇒ no-kill**, never as a match — and must NOT be "upgraded" by reading the live process's current start time, which would manufacture exactly the claim the pair exists to check. Consequence to NAME in the seed rather than discover in a census: during the changeover window, kills against pre-format pid files don't fire, so whatever they cleaned leaks until the file is rewritten at the next spawn (bounded, self-healing one-spawn-per-child, strictly better than the incident).
- ✅ **PR #66 FULLY GREEN on rerun (2026-07-23):** run 29977242525 rerun — Windows test job passed; both tests, both n1-gates, changes + traceability green (twohost skipped by design). Per the seed's own epistemic note this is a **contention datum, not a falsification** — the pid recycle simply missed a neighbor this round; the seed keeps its rank. **W2 merge-ready from CI's side**, gated only on ADR-0040/deployah sequencing. todlando idle, off the box.
- ⭐ **[[verdict-from-exit-not-from-silence]] recurred on a NEW surface** (doyle's own admin note): the run-level watcher was invoked as `gh ... --jq -r ...` (two args where one was meant) and spun forever, capturing nothing — silence, not green. Verdict taken from `gh run view` exit + JSON instead. Third instance (grep-through-a-pipe → battery leg piped to tail → watcher). Generalisation banked in that memory: **an instrument that cannot fail LOUDLY cannot be trusted to report success — the tool that WATCHES needs its own liveness check**, same shape as the oracle capability probe and Leg B's clean-FIN stop condition.
- ✅ **W2 / PR #66 MERGED @2342fd6.** Then its merge-run (29995900179, kitsubito) reddened on `attach_idempotent_replay::a_same_conn_equal_gen_replay...` leg 2. Doyle dispatched it to todlando as a REAL-DEFECT-suspect against W1's shipped idempotent-replay fix (deployah held the v0.41.1 cut pending verdict).
- 🎯 **DIG VERDICT (todlando, kitsubito isolated rig, doyle-RATIFIED 2026-07-23): RIG-ANCHOR ARTIFACT, not a code defect and not a W2 regression.** A/B/C matrix, hard-timeouted, every red the one clean 7-byte `"FIRST\r\n"` body: main(2342fd6) 56/120 red loaded / 13/13 serial-green; v0.41.0(3aecc35) 44/120 / 13/13; **control (replay REMOVED) 93/120 loaded + 12/13 SERIAL red** = exoneration by measurement (single SUBSCRIBE_DECISION, no replay, still catches the byte). ROOT: `cat` under a real PTY echoes each line TWICE (line-discipline echo + ONLCR write-back); `pump_until` anchors on the first substring hit, mid-line-pair, so echo #2 drifts into the 1200ms absence window. The shipped leg was serial-green ONLY because the replay's `read_outcome` incidentally DISCARDED echo #2 while awaiting `Subscribed` — a coincidence load breaks. **The oracle CANNOT true-red on fix breakage** (header's own admission: Brain's exactly-once cursor drops re-sent ranges) — the `RED PRE-FIX: replay re-synthesized...` label overclaimed and IS what misled the hold. Consequences: v0.41.0 attached-view changelog line STANDS AS WRITTEN; hertz field leg 3 UNBLOCKED.
- 🔨 **FIX = PR #68** (`fix/idemreplay-anchor`, test-only, ZERO src delta, changelog-neutral, off main). Remedy (a)+(b)+(c): `drain_quiet` absorbs the echo pair BEFORE the replay; **`read_outcome_capturing`** folds pre-`Subscribed` Output into the window (closes the blind-green swallow hole — doyle: "better than asked"); header names the double-echo hazard; **label amended @c65908d** to name what a red CAN mean (unexpected bytes from an unaccounted source; fix-breakage → broker unit matrix). Gate = the acceptance standard: **loaded 120/120 + serial 13/13, zero reds, zero timeouts** (direct contrast to pre-fix arms). doyle merges on green; then green merge-run → deployah cuts v0.41.1.
- ⚠ **HARNESS-BUG lesson (mine, family member #3 same day):** first loop harness used bare `wait` after spawning BOTH test procs and the CPU-pressure spinners as children of one shell → `wait` blocked on the immortal `while :` spinners → hung after round 1, 16 cores burning idle ~7h. Zero data lost (one clean datum salvaged pre-kill). Fix (banked prescription): **wait ONLY on the pids you measure, hard `timeout` per run.** Same instrument-family as doyle's gh-arg watcher and the RED PRE-FIX overclaim — [[verdict-from-exit-not-from-silence]] / [[measure-the-box-before-the-instrument]].
- 📌 **NEW WATCH-ITEM datum (doyle, #68 merge-run Windows red):** `endpoint_autostart_e2e::saved_endpoint_replays` session-id-freshness assert — THIRD sighting (2026-07-19 local / #55 merge-run / now), ZERO overlap with #68's file, dispositioned known-flake, rerunning→merge-on-green. Discrimination (rig-race vs PRODUCT-race) now has its third datum and moves up: body shows the replay minted a FRESH sid (ENDPOINT_AUTOSTART line) but the perch still carried run A's sid at assert time — fresh bind lost the race to the assert window. Candidate REAL ordering hole. ⭐ Kinship to carry into that discrimination: **emphasys omp-spt #10 = deaf-endpoint-after-autostart-replay**; a fresh-session bind racing/losing is a candidate SHARED SEAM — if the discrimination finds a product race, #10 may be its field face. See [[e2e-leaked-daemons-shared-box]] / [[emphasys-agent]].
- ✅ **POST-PUBLISH HERTZ DISPATCH SENT 2026-07-23 (doyle, QUEUED — drains at hertz next listen).** Body staged the leg ORDER: **leg 3 FIRST** (note pre-apply version → live rc viewer attached → arm daemon-stderr SUBSCRIBE_DECISION capture → `spt update apply` to 0.41.1; PASS = no freeze + decision=idempotent, no controller-replaced on SAME conn, no writer-exit channel-closed, no second initial batch; equal-gen DIFFERENT-conn swap = correct, not a fail; records sent either way) → **leg 2b** DNAR fixed-rc contrast on the field session class (fixed-geometry menu/history nav, zero /c-scraps; hertz holds 2a stock baseline; = KH 7.56 attribution CLOSE) → **leg 4** typed-through-resize no-echo (+ clamp-window signature = recurrence datum for REQ-TERM-ECHO-CLAMP-WINDOW, reported separately, NOT a leg-4 fail) → **obs 3 explicitly DO-NOT-RUN** (full-auto node = notice never constructed). Per-leg verdicts, version-pinned both sides of the apply.
- ✅ **HFENDULEAM applied 0.41.1 same day:** `spt update apply` clean; plain `spt daemon stop` REFUSED (exit 3, hosting 9 live sessions — refusal = W1 stop-semantics working as shipped; --force NOT used); operator completed the restart; `spt daemon status` verified broker image 0.41.1 matches installed, pump live, subscribers healthy.
- ⚠ **DISPATCH VOIDED ON BAD PREMISE (2026-07-24):** hertz = adapterless ready_agent ON HFENDULEAM; node was already 0.41.1 by doyle's own apply before the dispatch drained — leg-3 apply window BURNED by doyle. Hertz reported honest per-leg NOT-RUNs (leg1 ALREADY-AT-TARGET / 2b,3 NOT RUN / 4 window unavailable), acked + stood down. **REPLAN:** leg 3 recoverable WITHOUT a cut via `spt daemon refresh` (same request_brain_restart seam, banked ruling in [[v0394-field-bugs-hertz-rca]]; sessions preserved so dispatcher replay has subjects; label trigger=refresh) with live rc viewer + SUBSCRIBE_DECISION capture; legs 2b/4 need an rc-capable observer (ENLYZEAM/ball-b or operator terminal) — propose assignment to operator, re-dispatch explicitly. 📌 hertz observation banked: same-ID adapterless ready bind succeeded with NO CONFLICT — possible intersect with 0.41.1 Known C ready-listener narrowing; examine deliberately, not incidentally.
- ⚠ **NODE INCIDENT (blocks replan): [[hfenduleam-daemon-path-claude-spawn]]** — post-restart daemon lost claude from PATH; all fresh claude spawns dead node-wide; HKCU PATH fix STAGED, daemon bounce HELD by operator (agents mid-work). Field legs run only after the node is healthy.
- ⚠ **HERTZ CURRENTLY DEAF (F-033 pattern on OMP-17-RPC-hosted resume, 2026-07-24, emphasys DRI):** probe-verified by doyle — `spt send hertz` returns SENT, digest grows, NO turn starts, zero daemon-side refusal; core delivery layer WORKING, deafness downstream of relay handoff. Core facts: .idle sentinel present (core says idle); hosting = WAKE_RESUME of omp session 019f92a7 under omp-spt pid 46092 after an exit-95 psyche reseed strike. Sharp candidate = resume-into-PHANTOM-TURN (OMP internally non-idle forever → sendUserMessage queues as steer, boundary never comes). Discriminator dispatched to emphasys: adapter relay-consumer capture (EVENT received / sendUserMessage issued / OMP session-state snapshot); (a)-no = back to doyle as core relay defect. Kinship flagged: omp-spt #10 deaf-after-autostart-replay + endpoint_autostart flake = same family. **OPERATIONAL: my consolidated resend + probe sit UNREAD in hertz digest — hertz re-dispatch BLOCKED until this clears.** Separate: earlier lost-message window candidate = same-ID dual-instance (adapterless `ready` marker STILL in hertz owlery beside live hosting; Known C intersect) — kept apart from F-033 root.
- 📌 **F-033 round 2 (doyle→emphasys 2026-07-24):** digest brackets deafness onset to **06:30:48–06:34:51Z** on session 019f92d0 (turn-wake WORKED at 06:30; stranded resend landed 1s before an echo_mirror entry). Refinement sent: emphasys's 14-probe boundary spray covered MODEL-turn ends only — **echo-commune boundary class untested** (psyche-lane activity; if its termination differs, fits all evidence: steer into terminating commune → context-absorbed, no turn, desiredState stranded busy, watchdog defers forever). Also: hertz booted 3× in 57min pre-deafness (05:32/05:44/06:29). **owl_message clarified = CORE digest vocab, delivery-chokepoint, turn-AGNOSTIC (startup.rs ~748) — never a stranding signal.** No on-disk omp-spt adapter logs exist; capture path = emphasys diag adapter at hertz restart — **PROPOSED: combine with the pending PATH-fix daemon bounce (one window, two fixes); emphasys to say when diag build ready, doyle puts window to operator.** Convergence noted to both: perri rebound activity seam now has a SECOND consumer (this incident).
- ✅ **COMBINED BOUNCE EXECUTED 2026-07-24 ~01:07 (operator GO):** emphasys swapped instrumented omp-spt.mjs (SWAP-DONE), doyle fired detached `daemon stop --force` + scheduled-task start. Daemon fresh pid 48508, 0.41.1, gen 0 cold. **PATH INCIDENT FIXED + PROVEN:** lia ONLINE (daemon spawned its claude harness clean), zero program-not-found in new log, claude resolves. ⚠ collateral: liam went OFFLINE (was ONLINE; spt-progress-tool, not target — watch). **F-033 RECOVERED + DIAGNOSED:** fresh hertz session woke a turn + replied; emphasys diag captured FULL CLEAN CHAIN (08:09:43 LISTENER_SPAWN→RECV→SEND→SEND_SYNC→BEFORE_AGENT_START desired->busy→TURN_START→CTX_RELEASE→TURN_END, zero SEND_FAIL). **VERDICT: F-033 = stuck-session-state-specific, NOT code-dead** — old session 019f92d0 had a dead submission chain (emphasys zero-jsonl-after-06:34:26 proof); cold session drains clean; bounce cleared it. Instrumented adapter now PERMANENT = next strand pinpoints the dead link (RECV-absent=core-relay / RECV-present+SEND_FAIL=adapter). Root of WHAT accumulates the stuck state UNPINNED; doyle candidate = churn (3 hertz boots in 57min pre-deafness → bad-resume). **hertz responsive; field-leg re-dispatch still gated on rc-capable-observer assignment (separate from deafness).**
- 🎯 **F-033 ROOT LOCALIZED = ADAPTER, core EXONERATED with code proof (doyle dig on frozen hertz 019f932c, 2026-07-24; emphasys converged independently via operator+docs same hour).** Chain: `spt send hertz`=SENT ⟹ deliver_tcp wrote framed to live socket 63214 (deliver.rs:96-120; dead dial→spool→Queued). owl_message digest line authored by the LISTENER's deliver closure, and emit()+explicit stdout flush runs BEFORE that digest write in the SAME closure (startup.rs:751-754, emit 916-923) ⟹ owl_message present ⟹ emit provably wrote+flushed the EVENT to fd 1. Closed read-end→EPIPE→panic→LISTENER_DIED (not seen); unflushed stall ruled out by explicit flush. ONE listener proc 36148, correct child of extension 41376, no stale duplicate. **⟹ core put+flushed EVENT bytes on stdout (the contract payload stream); the omp-spt EXTENSION stopped DRAINING stdout after turn#1 + echo_commune while the pipe stayed open.** Docs corroborate (stdout=payload/stderr=status); claude-spt (same core `api listen`, diff adapter) does NOT repro = adapter is the delta. emphasys owns adapter root (child.stdout subscription detach/pause at echo/off-turn boundary; RECV-silence watchdog = heal). Discriminating datum offered: buffered-unread bytes in 36148 stdout pipe. **Separate CORE seed doyle owns:** churn-leaked stale registry row (see [[spt-core-findings-backlog]]) — not this deafness.

## RESOLVED: EVENT-PART reassembly docs-gap (doyle, 2026-07-24)
- **VERDICT = DOCS GAP (#2 of operator's 3-way triage), not docs-under-read, not core-feature-gap.** Evidence: public docs (messaging/overview.md:100-103, quickstart:133) stated EVENT-PART EXISTS + named the tag shape + "receiver reassembles" but omitted every load-bearing rule (distinct-tag/no-prefix-match, seq 1-indexed K/M, id-opaque, head-only-attrs, fragment=raw-slice CONCAT-BEFORE-DECODE entity-safety, out-of-order+group-by-id, orphan-drop). A blind adapter author would write exactly omp-spt's wedge (prefix-match `<EVENT` catches `<EVENT-PART`, `</EVENT>` never closes → stall). NOT core-feature-gap: sister project (claude_skill_owl) ALSO put reassembly on the receiver → parity-correct, burden always the adapter's.
- **FIX (durable, all-adapters):** amended messaging/overview.md with full "EVENT-PART reassembly (listener stream)" section (anchor #event-part-reassembly-listener-stream) + quickstart pointer; added `doc` stage to REQ-HAZARD-EVENTPART-REASSEMBLY + tagged the section; traceable-reqs exit 0, xtask check (docs-drift) OK. Answered emphasys's 7 Qs FROM THE CONTRACT (not source); WITHHELD 2 impl details (threshold=400 value, hex-nonce id derivation) as must-not-depend, steered to threshold-independent testing (synthetic EVENT-PART sequences + multi-KB integration leg).
- ⭐ **BOUNDARY LESSON (banked to /role, operator-directed):** nearly answered emphasys's 7 Qs from `chunk.rs` source — that leaks core internals into an adapter built blind. Correct posture: adapter impl-question = docs-under-read / docs-gap / core-parity-gap; identify with evidence, fix the PUBLIC contract, never hand source. Check every call vs CONTEXT.md (harness-agnostic boundary: EVENT-PART chunking is the generalized Monitor-MODEL listener contract — harness-agnostic mechanism, claude-code-tuned threshold is impl). Standing design-seed unchanged: capless-harness chunk opt-out / adapter conformance-lint (my lane, ranked later).
- 📦 **DOCS AMENDMENT LANDED AS PR #71** (`docs/eventpart-reassembly-contract` off main @0493840, committed in isolated worktree per rule; branch PUSHED = objects safe on origin). Gates: traceable exit 0 (`+doc +impl +unit`), xtask docs-drift OK (validated on main-base delta; worktree cold-recompile timed out at 2min = known-green, not re-run). ⚠ `.worktrees/docs-eventpart` handle-pinned on remove (cargo target from the timed-out build) → REBOOT LIST (cosmetic; branch on origin). Awaiting CI + merge.
- ⚖️ **ORPHAN-GROUP RULING (doyle→emphasys 2026-07-24):** contract behavior for an incomplete/orphan/never-completing EVENT-PART group = SILENT DROP, LISTENER STAYS ALIVE — NOT emphasys's proposed loud-restart. Grounds: (i) matches published contract + core reassembler (returns None, drops, continues); (ii) canonical missing-head cause IS a mid-stream restart → restart-on-incomplete = restart-LOOP + never recovers the headless group; (iii) invisible class we killed = UNBOUNDED-silent-growth-no-signal, NOT bounded-single-drop → fix = BOUND + OBSERVABLE (log/counter on drop), not process death; (iv) resource caps → EVICT-OLDEST not listener-kill; malformed part → drop+observable not restart (peer shouldn't bounce your listener). Defense trio: bounded id-keyed state + observable-on-drop + RECV-silence watchdog. emphasys's items 1/2/3/interleave all gut-checked CORRECT + contract-conformant. **PR #71 amended (2nd commit bf9cbec): docs now spell out silent="no partial envelope on stream" ≠ "hidden from receiver diagnostics", receiver stays alive, bound+evict pending state.** ⚠ `.worktrees/docs-ep2` handle-pinned → reboot list (branch on origin, cosmetic).
- ✅ **EMPHASYS INCORPORATED RULING (2026-07-24), all gates green, ship-pending on operator.** Final shape confirmed doyle-correct: incomplete/orphan → bounded id-keyed state never listener-fatal; M-mismatch → drop stale group + observable, restart from incoming part; malformed part → skip frame + observable; resource caps → evict-oldest until pending-bytes≤maxFrameChars & ids≤256, each + observable; observable = `drops[]` {id,reason,held,total} logged non-fatal (no died()/markCommsFailure). ⭐ RESERVED listener-fatal ONLY for a SINGLE incomplete frame whose RAW length alone exceeds maxFrameChars = genuine stream corruption, mirrors existing whole-<EVENT> overflow, UNREACHABLE by any well-formed part sequence (correctly scoped). Tests: mismatch/over-budget/malformed all assert error===undefined + following whole <EVENT> delivers + drops[] reason; wedge/out-of-order/split/concat-inside-entity/non-msg green. **F-033 fully closes on emphasys ship** (contract + PR #71 docs + adapter now agree three ways). emphasys will ping on ship.

## Index-line archive (compacted out of MEMORY.md 2026-07-26)
- [DAEMON-LIFECYCLE progress](daemon-lifecycle-progress.md) — 🏁 W1+W2+W3 ALL MERGED, doyle-gated; v0.41.0 c74 + v0.41.1 c75 PUBLISHED ([[v0411-published]]; #66 red = rig-anchor artifact, attached-view line STANDS). ⚠ hertz dispatch VOIDED (adapterless, on this node, apply window burned by doyle — honest NOT-RUNs); REPLAN in file: leg 3 via `spt daemon refresh`, legs 2b/4 need rc-capable observer, obs 3 off-clock. ✅ hertz F-033 ROOT PROVEN = ADAPTER, offline-reproduced (omp-spt drainEvents never reassembles `<EVENT-PART>`: core chunks oversized delivery per contract, adapter `<EVENT` prefix-matches `<EVENT-PART`, `</EVENT>` never closes, buffer wedges silently, all later msgs swallowed; echo_commune = first payload big enough to chunk; claude-spt reassembles→no repro). Core EXONERATED (doyle emit+flush proof dovetails). emphasys owns fix+regression. doyle filed 2 CORE seeds: churn-leaked stale registry row + EVENT-PART reassembly is silently non-conformant (lean: adapter conformance-lint). re-dispatch gated on rc-capable observer. 📌 watch: endpoint_autostart session-id flake 3rd sighting (product-race candidate, omp-spt #10 kinship); hertz same-ID adapterless-bind-no-CONFLICT (Known C intersect?). ⭐ CI-runner-off-HFENDULEAM = non-option.
