---
name: f028-runtruth-w3-progress
description: F-028 W3+W4 — C3(b)+(c) shipped+pushed (gate armed); B6 RCA done (poison-cascade, evidence-blocked); B7 version-skew
metadata: 
  node_type: memory
  type: project
  originSessionId: cb40e675-05a5-454a-b67f-dbd9806107aa
---

**SESSION TALLY (todlando 2026-07-03): 7 commits shipped + pushed @546d9ca..259aec2, ALL gated.** CI @edddb48 (W3 chunk, 5 commits) ALL-GREEN attempt-1 both legs. B2 @259aec2 folded into the chunk gate (doyle re-scoped, six commits, one run).

**GATE VERDICT (doyle 2026-07-03 ~05:40): chunk @546d9ca..259aec2 GREEN.** CI 28658750322 @259aec2 attempt-1 all-green both legs; isolated-worktree fresh-target nextest --workspace 1514/1514; clippy + traceable green same sha. B2+B3 line-reviews clean (2 non-blocking notes sent todlando: B3 pre-reap info-snapshot re-clear idempotent; B1/B2 doc-stranding — cmd_endpoint_run doc + REQ-HOST-RUN-1 tag rustdoc-attach to ResumeResolution). perri B2 GO revised: no published cut carries 259aec2 (counter 42 predates chunk) → her 2 live-verify ints slotted as COUNTER-43 RELEASE-CANDIDATE verification; doyle pings at upload-before-flip so a red blocks the release pre-flip. Her plans armed (INT-1 env scrub via environ(); INT-2 resume argv -r UUID + negative FRESH leg — purge via whole sessions.log delete, not row-edit). **C3(b) landed @b2351a0 post-gate — UNGATED; todlando mid-flight C3(c) (tree-kill primitive in spt-store::proc landed, Win held-Child-handle test fix pending); C3(b)+(c) gate TOGETHER on his ping.** C3 gate reqs set by doyle: both CI legs (Toolhelp/proc divergent), tree-kill test needs ≥1 DESCENDANT + dead-descendant assert (single-pid test false-greens vs kill_pid), red-first via kill_pid swap + wire-revert for the C3(b) reconcile trigger test. C3 COUPLING CLOSED: perri adapter-half @50af830 uncut — instant<2s, backoff 0.5s×2 cap 5s, give-up 8 consecutive → exit 3 (PSYCHE_HOST_GIVE_UP). Ordering CONFIRMED vs core 10/60s (≤8 boundaries ≤38.5s; steady ≈8.6/60s). Nuance: streak-dodging just-over-2s cycles (~24/60s) legitimately trip core on a GUARDED wrapper — correct backstop, perri fixing her §2.6 wording. Counter-43 RC window = 3 perri ints (B2 pair + C3 give-up), any red blocks flip. GOTCHA: pre-clear background gate task survived /clear and ran CONCURRENTLY with doyle's fresh gate → probe_all_cap starvation red in the loaded run (passed quiet) — check for in-flight gate tasks before launching one post-resume.

**W4 SESSION (todlando 2026-07-03 PM): C3(b)+(c) SHIPPED+PUSHED + B6 RCA.** Pushed 259aec2..d99d86d + c4ff9f5 (docs). **C3 PAIR GATED GREEN (doyle ~13:00): CI 28660921710 attempt-1 both legs + worktree gate (clippy clean, nextest 1520/1520, traceable OK) + line-reviews clean.** C1 GO'd to todlando (W5, PR#48 Linux leg). B6 fix PRE-BUILT both-legs-red-first-verified (lock_floor idiom ×3 + run_inject_worker_supervised catch_unwind→fault+terminate), commit HELD for perri path-2 evidence; routing pre-answered (H4⇒poison-root framing / H1⇒hardening framing + decay hunt). Local incremental smoke only (proc::+livehost:: 51/51, my 4 clean; clippy+traceable green) — worktree gate is authority.
- **C3(b) @b2351a0**: classify_thrash (pure Thrashing/Steady/Reanchor window+threshold) + LiveSet.ledger_anchor (ordinal-delta over Instant, no rfc3339) + detect_psyche_thrash_or_unhost wired reconcile stop-side after residency-confirm (stamps parent psyche_host_error{rate}, clears phantom nested perch, un-host, arm nonresident cooldown). Threshold 10/60s = BACKSTOP below perri adapter give-up ≈8.6/60s.
- **C3(c) @d99d86d**: NEW spt-store::proc primitive — process_table (Toolhelp Win / /proc Linux / empty non-Linux-unix), process_descendants (BFS, cycle-guarded, root-first, scope-strict), kill_pid_tree (snapshot subtree BEFORE kill — Linux reparents orphan on parent death — then leaves→root). stop_host snapshots owned-wrapper descendants pre-handle-reap; reap_orphan_psyche_for kill_pid→kill_pid_tree — ALSO closes leg-(ii) shutdown-reaps-wedged-wrapper. Tests: kill_pid_tree_kills_the_whole_subtree (2-level tree, asserts DESCENDANT dead = discriminator vs kill_pid; RED-FIRST verified Win no-job; Linux CI proves init-reparent) + crashloop_ledger_rate_stamps_and_unhosts (reconcile trigger, RED-FIRST via wire-revert). GOTCHA: held std::process::Child handle masks TerminateProcess via OpenProcess (drop before is_process_alive probe).
- **B6 RCA @c4ff9f5** [REQ-TRANSLATE-BINARY-LIVENESS-DECAY]: framing is a MIS-DIAGNOSIS. "no live translation binary" = CLI GENERIC force-native-miss string (cli.rs:5037), never probes binary → live pid 297520 is a RED HERRING. REFUTED H1 (is_spt_hosted_no_relay: .ready+status+controllable all survive resting — apply_event writes only rest_state, auto-suspend≠signoff_with), H3 (fault→terminate kills pid), H2 (session drops only on KIND_EXIT). LEADING **H4 = PANIC in run_inject_worker**: floor Mutex bare .lock().unwrap() at 3 SHARED sites — worker (broker.rs:1297) + controller-input dispatch_input L-C (2142 = rc nudges) + flush (1163); a panic under it POISONS → worker's next lock panics → worker dies WITHOUT fault/terminate → event_rx drops, child NEVER reaped (pid alive) + event_tx.send fails → "worker-gone" delivered=false → PERMANENT force-native refusal. CONFIRM ASK (perri, via doyle): daemon stderr 02:38-02:53 — panic backtrace + ENDPOINT_INJECT worker-gone line. FIX (precedent bug#16 EFFECT-JOURNAL poison-tolerance): poison-tolerant floor locks (unwrap_or_else into_inner) ×3 + panic-resilient worker (catch_unwind→fault+terminate). Fix HELD until stderr confirms H4 vs re-opens H1.
- **F-028 WAVE COMPLETE + FULLY GATED @5005a75 (doyle ~16:20 2026-07-03)**: wave-final commit = 3 ints (B3 control-reap extend / B1+B4 shared run-over-live E2E / C2-ROOT cross-perch dead-owner-repin-REFUSED identity E2E — doyle overrode keep-unit lean, conformance convention), all red-first via guard-revert reproducing the exact field bugs. CI 28669754166 both legs + worktree 1531/1531 + clippy + traceable (int stages satisfied). Kept impl+unit (int-grade-in-unit): C3/C1/C2/hardening pair. [twohost] NO (single-node slice). B6 parked open → RC int #4. B7 closed.
- **A7 HITL PASSED (operator, ~16:50 2026-07-03)**: @5005a75 dev build staged to ENLYZEAM as spt-a7-test.exe (avoid update/setup/install names — UAC-740), operator verified properly colored output in raw conhost (--help / endpoint list / daemon status). Binary + build worktree cleaned.
- **NEXT — RELEASE IN FLIGHT**: deployah GO'd for v0.23.0 counter-43 (bump-in-PR, no [twohost], B6 NOT in changelog as fixed — REQ open). doyle gates the release PR. RC-WINDOW: deployah HOLDS at upload-before-flip → doyle pings perri for 4 RC ints (B2 env-scrub, B2 resume-UUID argv, C3 give-up, B6 real-/clear-boundary re-repro w/ capture spec) — any red BLOCKS flip. Settle-check patience ~1min post-flip.
- **HARDENING SET GATED GREEN @976ff4d (doyle ~15:15)**: REQ-HAZARD-INJECT-WORKER-POISON (lock_floor ×3 + supervised worker) + REQ-HAZARD-DETACHED-DAEMON-STDIO (pipe-only null-handles + line-82 --detached belt + stale-task nag). Doyle review round: caught OR-version no_console leg would blank ~15 int tests' CREATE_NO_WINDOW file-captured brain-logs → amended @976ff4d pipe-only (pipe = only blocking sink; sanctioned capture form = `2>file`). CI 28667579830 both legs + worktree 1528/1528 + clippy + traceable. GOTCHA/RULE: delete gate `_gate-target` IMMEDIATELY post-verdict even when worktree dir lock-sticks — three stuck ~22GB targets caused tonight's box disk-full (LNK1318 class).
- **C1 GATED GREEN @d772ffb (doyle ~14:00)**: displace-not-replace + gated Phase-0 GC (doyle amendment: GC only when target exists — unconditional GC opened a no-binary double-fault on crash-mid-commit recovery; red-first verified) + swap_err op/path context + rename seam. CI 28663309160 both legs + worktree 1524/1524 + clippy + traceable. REQ-CRC-SWAP-OLD-DISPLACE impl+unit.
- **B6 ROOT HUNT CONCLUDED UNPINNED (2026-07-03 ~13:00-14:30) — full matrix exonerated, root NOT reproduced**: perri's 5-cell live matrix ALL CLEAN (env-static / dormancy 18/18 / thrash 12/12 no-poison / detached×time 18/18 / sustained-rc-churn 30/30). Incident's alive-translate refusal NEVER reproduced. Hypotheses killed in order: H4 floor-poison (never fired incl. under thrash; floor is PER-SESSION broker.rs:1217), static env-root (present when delivery worked), undrained-pipe fill (NO Win spawn path both inherits + skips nulling — create_process_detached bInheritHandles=FALSE, spawn_deelevated token-boundary no-inherit hidden-conhost, schtasks conhost scrolls). REPRODUCED along the way: pump-stall via rc-churn (1 cycle to stall, self-heals ~3.5min — F-a/B5, recoverable) + one transient RC_FAIL brain-IPC-deadline (--take vs stale controller). LAST UNDRIVEN CELL = real agent-fired /clear boundary (SessionStart checkpoint_fire self-send --force-native) — old rc can't drive it. ROOT CANDIDATE (todlando inspection, sharpest): broker binding EXONERATED (endpoint-keyed, clear-transparent) → CLI-side BOUNDARY-TRANSITION RACE — is_spt_hosted_no_relay gate (ready-file && ONLINE && controllable) evaluated by SessionStart checkpoint force-native at the instant /clear rotates the perch re-stamp → transient false → generic miss, translate alive, zero matrix reproducibility. Fix shape if confirmed: re-stamp-before-hook ordering or hook bounded-retry. perri RC int #4 capture spec banked: perch status/ready/controllable + detect_self_id resolution AT hook-fire instant. HARDENING SET lands now honest-framed under MINTED REQ-HAZARD-INJECT-WORKER-POISON (floor poison-tolerance + supervised worker) + REQ-HAZARD-DETACHED-DAEMON-STDIO (daemon-run null-handles on no-console/pipe-stderr + --detached belt daemon.rs:82 + stale-task-argv detection NAG — installer already registers safe `daemon start` in-tree; bare `daemon run` = FIELD DRIFT, ENLYZEAM live example). REQ-TRANSLATE-BINARY-LIVENESS-DECAY stays OPEN. perri B6 rig torn down, evidence archived scratchpad/b6-evidence-archive/ (her box) w/ README manifest. Seeds: churn-resilient pump (B5), rest_state void on 0.22.0 read surface.

**LIVE OPS (doyle 2026-07-03 ~06:00-12:50):**
- **B7 RETESTED GREEN — CLOSED no-code-bug.** Operator authorized ENLYZEAM bounce; doyle over ssh: broker 0.21.0→0.22.0 (`spt daemon stop` + `schtasks /run /tn 'spt-core daemon'`), ball-b fresh bringup, local rc attach → CONTROLLED rendered BOTH nodes. Version skew = confirmed root. D-track stale-broker-nag seed stands.
- **ball-b trust-prompt root FIXED**: duplicate .claude.json project keys — `C:\Users\decid` (backslash) trust=True SHADOWED by `C:/Users/decid` (fwd-slash) trust=False; CC canonicalizes fwd-slash → prompted every start. node-script flip (backup .claude.json.doyle-bak). Class: check BOTH slash-forms on trust bugs.
- **NEW wave-final seed (banked w/ todlando): abandoned-controller eviction MISS, live-session leg** — rc controller hard-killed, broker session stays live → controlled stuck ≥10min BOTH nodes (gossip honest; LOCAL stamp stale). B3 exempts live-session (Gap A → clear_controller on serve-conn-close which never registered); w5_a2 documents divergence. Seed: controller-pid liveness / conn keepalive deadline / widen B3 reap.
- **B6 path-1 = DELIVERY** (force-native via hall-b, same daemon 139644, 3h post-incident) → daemon-wide-poison DEAD. CAVEAT (doyle): if floor mutex is PER-ENDPOINT, per-endpoint-poison H4 still live — scope Q with todlando. **Path 2 GO** (perri): foreground daemon stderr repro, staged — pass 1 boundary+dormancy, pass 2 adds psyche-thrash. todlando PRE-BUILDS poison-tolerance fix (commit held for true-root naming). perri stderr for original incident = NULL CHANNEL (detached WMI spawn, no redirect).

**(HISTORICAL) NEXT-SESSION READY-TO-BUILD (doyle rulings banked) — C3(b)+(c) now DONE above:**
- **C3 (b) ledger-rate thrash-detect** [REQ-PSYCHE-CRASHLOOP-BACKOFF-SHUTDOWN, spt-core]: spt-core already paces DAEMON re-host (RESIDENCY_RETRY_COOLDOWN ~5s + nonresident_until); the ~3 boots/sec (ledger ordinal 5358/30min) is the WRAPPER restarting CC internally while staying resident → residency never trips. Signal = LEDGER-RATE (doyle: harness-agnostic; C2 made ledger honest). Threshold ≥10 boundaries/60s sustained over the PSYCHE's OWN nested ledger → stamp psyche_host_error{reason:"wrapper thrash", rate} + un-host + cooldown via existing nonresident machinery. NOTE: timefmt has NO rfc3339 parser — use STATEFUL ordinal-delta in LiveSet (last_k_with_ordinals max ordinal + Instant sample per host) to avoid a hand-rolled date parser.
- **C3 (c) tree-kill** [same REQ, spt-core]: reap_orphan_psyche_for does single kill_pid(recorded wrapper pid) — a looping wrapper's child CC survives. FIX: kill the whole {id}-psyche DESCENDANT tree. proc.rs has parent_pid_of (UP) but NO process enumeration — must ADD a cross-platform primitive (Win CreateToolhelp32Snapshot / Linux /proc scan) to invert parent→children + BFS from the recorded pid. SCOPE STRICTLY to the wrapper's tree (no-machinewide-kill). Needs BOTH gate legs.
- **C3 (a) wrapper CC-restart backoff** = ADAPTER/perri (their F-h asked for it); doyle briefs; binary change, batches, NO coupling.
- **B6** [REQ-TRANSLATE-BINARY-LIVENESS-DECAY]: RCA-first, repro packet IS IN THE TRIAGE DOC (B6 section ~L240-258: daemon 139644, alive translate pid 297520, good 02:29+02:37, refused 02:52, dormancy window, wake NO_EDGE, 15-min repro sketch). NO perri dependency.
- **B7** [REQ-GOSSIP-CONTROLLED-CROSS-NODE]: root = VERSION SKEW not code (ENLYZEAM broker_image 0.21.0/broker_stale, CLI 0.22.0 — 0.22.0 sender #4 enrichments absent). send/serialize/render code-verify STANDS. HOLD for a clean two-0.22.0-broker retest (operator's call); if green → close no-code-bug + add D-track post-update stale-broker NAG surface.

BUILD-F028-RUNTRUTH **W3** (identity + session-lifecycle), branch `f028-runtruth`, todlando 2026-07-03. Triage doc `docs/NEXT-MILESTONE-RUNTRUTH-TRIAGE.md`. Order: C2 FIRST (corrupts what B3 reads), then B3, B1, B4, B7.

**SHIPPED + PUSHED (5/6), all impl+unit, int held for wave-final gate:**
- **C2-ROOT** `REQ-BIND-HONEST-SELF-STAMP` — @546d9ca leg1: `detect_self_id` leg(a) nested-inclusive (`spt_store::perch::list_all_perch_dirs`); @f0a25cd leg3a: auth.rs cross-perch guard — dead-owner re-pin REFUSES when incoming sid affirmatively owns another perch. **Sharpened RCA (doyle ACCEPTED): contamination write-path is authenticate()'s DEAD-OWNER RE-PIN, not the hook-stamp framing.** Adapter half (manifest `env_remove` on `[session.psyche_init]`) = PERRI, doyle-routed; runtime.rs:584 already honors role.env_remove.
- **C2** `REQ-SESSIONS-LOG-ENDPOINT-ATTRIBUTION` — @d0a6a60 leg-iii: `resume_rows_from` drops owlery-internal-cwd sessions. leg-iv repair = establish_perch self-heal (existing, unblocked by leg3a) + render-filter; no migration.
- **B3** `REQ-PRESENCE-CONTROL-REAP-ON-EXIT` — @1132ff8: `reconcile_hosted_liveness` control-reap runs BEFORE status gate → clears sticky `controlled`+`driven_by` on sessionless spt-hosted perch regardless of status (perri F-b: >20min + across restart). attached_node derives from both. Covers 4 paths (exit/conn-drop-via-broker/crash/boot-sweep). Closes A2(b); A2(a-render) shipped W1 @1de11cb.
- **B1+B4** `REQ-RUN-NO-DUP-SESSION` / `REQ-RESUME-REAP-PRIOR-HARNESS` — @edddb48: `cmd_endpoint_run` probes `rc::SessionProbe::has_session` BEFORE spawn → `run_on_live_decision` Reattach(attach)/RefuseAlreadyLive(headless)/Spawn(fresh). Two sessions per id can't exist → crossed-attach structurally prevented.

**OPEN — B7** `REQ-GOSSIP-CONTROLLED-CROSS-NODE` (still `required_stages=[]`): remote endpoint's CONTROLLED not rendered cross-node. **CODE-PATH RCA (mine): send-build (registryhost.rs:444-498 reads info.controlled + derives self controller_node), wire-serialize (registry.rs:223 `controlled` true rides, only false skipped), and render (data.rs from_resource_row) are ALL correct.** So the loss is receive-apply / decay / source-stamp — needs the LIVE two-node repro (perri's leg, now unblocked; was ENV-BLOCKED). Do NOT speculative-fix. Caveat: ball-b `controlled` may reflect claude `--remote-control` channel not PTY-attach (B3 caveat).

Gate: doyle per-sha, staggered vs CI (don't run local nextest while CI test job in_progress). C2-ROOT chunk gate sequenced by doyle @d0a6a60. See [[traceable-per-wave-activation]] [[gate-clean-target-not-incremental]] [[presence-dead-shows-online]].
