---
name: field-truth-w1-progress
description: "FIELD-TRUTH W1 milestone — operator-ruled 2026-07-26 build of the ranked field findings, drive to release publish (counter 80)"
metadata: 
  node_type: memory
  type: project
  originSessionId: 80c9a314-2db5-4941-b7db-db79170ae815
  modified: 2026-07-28T01:31:43.583Z
---

# FIELD-TRUTH W1 (opened 2026-07-26 ~21:30)

## 🏁 SHIPPED (2026-07-27 ~17:2x): v0.45.0 counter 80 @899f466 — read this block first
- **PUBLISHED** ([[v0450-published]], deployah's note = record). #104 + #111 merged on green; #112 release PR; #113 runbook tail gated+merged post-tag. mobile-gw + perri pinged at publish. Repeat-proof rerun of the post-tag wake_single_flight red = GREEN at-sha on drained window (1 sighting stands; 2nd on #106's seam = real-defect routing, deployah clause adopted).
- **✅ todlando's leg of the choreography DONE (2026-07-27 ~18:0x) — box released, nothing of his blocks the bounce.** Stock-cadence rounds 3/3 GREEN 19/19 on a predicate-clean window ⇒ **g6 cadence/observer axis FALSIFIED**; day tally 8 GREEN vs 1 RED; **sole surviving axis = restart-transient adjacency** (red ran ~4 min into a fresh daemon, all greens hours post-restart). Experiment ARMED not run — fire `pwsh -File .worktrees\g6-postbounce.ps1` inside the first 4 min of the NEXT daemon restart (any cause), control run an hour later; red-then-green = confirmed + repro recipe, green = file 1-in-N unreproduced and stop spending windows. Detail in [[spt-core-findings-backlog]]. Orphan sweep = no-op (all 4 PIDs self-exited). **#100 informant debt CLOSED by doyle as watch owner** — real production traffic delivered both verdict classes (green 13:37 @87db24b, red 13:12Z + tonight's CI FAILURE @4a3f7c6 and @899f466), so the contrived green/red demo runs are CANCELLED, not owed.
- **OPEN CHOREOGRAPHY:** (1) ~~todlando's g6 rounds + orphan sweep~~ DONE, see above; (2) THEN daemon bounce (broker 0.44.0→0.45.0; operator or doyle drives) — closes perri #7 verify + env-refresh/cred-removal verify (docs :5474 already healed by 15:34 reset, stopgap gone); (3) perri verifies ping-wake + #7 post-bounce.
- **NEW RULES/EVIDENCE THIS STRETCH:** [[quiet-window-predicate]] BINDING (CI-drain + no-local-cargo); runner cancel-mid-claim zombie variant banked ([[runner-online-but-deaf]]); `ssh reavus@kitsubito` works ([[kitsubito-linux-rig]]); coordinator-image "not reported" wording seed (old-broker cause omitted); g6 seed = sibling-contention axis, timestamp-cleared of the sick-daemon window, cadence/observer discriminator pending todlando's rounds; PACER displaced-image 2nd specimen.
- **POST-BOUNCE QUEUE:** ✅ idle-delivery RCA RULED 2026-07-27 ~18:2x: **CORE, relay exonerated, #12 stays core** — sick brain 19412 logged ZERO inject-class lines its whole 5.6h life (no ENDPOINT_INJECT either shape, no IDLE_PARKED_DRAIN, 0/122k vs 362 pre-crash same build; bind-path WAKE_RESUME still worked 13:36) + crash cause found: brain 46476 OOM-abort on 0x1800000000 alloc (corrupt length-prefix class, possible kin of >400B empty-body onset 09:20). Full ruling + 2 new seeds (belt liveness observability; OOM length-prefix) in [[spt-core-findings-backlog]]. ✅ hertz bounce-commands CLOSED 2026-07-27 ~18:4x: his exact sequence was `spt adapter update omp-spt` then EXPLICIT `spt daemon stop` + `spt daemon start` + `spt endpoint run --adapter omp-spt --id hertz --create --start` — the fleet-daemon cycle was his own command, NO adapter-apply escalation defect exists; seed retired. Rider banked: brain 46476 was still writing at 09:39:26 and OOM-aborted within ~12s, during/adjacent to his stop — corrupt-length read may sit on the stop/teardown path. ✅ #12 CLOSED by perri on the ruling; fresh-daemon verify healthy (broker+coordinator both 0.45.0 — 18:09 bounce was the full bounce). Empty-body >400B routing RULED to emphasys (3rd repro on fresh daemon). STILL OPEN: digest-continuity seed (residual: digest fate when session unbound mid-restart); gate-23d5ceb pinned dir retry. 🆕 daemon bounced AGAIN 18:09 (fresh brain pid 14764) — perri to run ping-wake verify on THIS daemon (live repro window if dead again); todlando g6 dose-response curve staged for next operator bounce.

## CLOSE-OUT STATE (2026-07-27 ~15:5x — superseded by SHIPPED block)
- ✅ **SACRED BASELINE GREEN: run 30303479435 @1a294b6 SUCCESS** (quickstart_e2e red was 1st-sighting flake, at-sha rerun cleared; todlando verified terminal-state directly). Sweep fully green on main.
- 🔨 **todlando RUNNING the #104 wedge pair NOW** (quiet window taken: base 3d9ec73 leg then 2aae246, shared throwaway target, -j2). Pair verdict → #104 merges (CI already green) → ALL GATES → **GO deployah counter 80** (deployah OFFLINE, send QUEUED-ok) → AT PUBLISH: `spt send mobile-gw` + perri release-number ping.
- 🆕 **PR #111 open (ci/notify-ssh-hop):** informant sends ride `ssh decid@hfenduleam` = same-node delivery, hop PROVEN live (test spooled+drained to doyle). Merge on green. Infra: sshd installed+running on hfenduleam (operator UAC), kitsubito hop key in ProgramData administrators_authorized_keys, /etc/hosts pin `192.168.1.81 hfenduleam` on kitsubito (DNS there resolves a poisoned link-local IPv6 — ipv6-poisons theme again).
- 🚑 **daemon recovered by OPERATOR** (post-15:35): idle-delivery-dead state GONE — RCA now rests entirely on the preserved snapshot `scratchpad/evidence-daemon-stderr-0939-bounce.log` + perri's timeline. Post-release RCA queue: (1) idle-ephemeral dead after DAEMON_RESTART_RESUME; (2) digest-continuity across bounce; (3) hertz's bounce commands (why an adapter bounce cycled the fleet daemon).
- 🧹 Housekeeping owed: worktrees notify-hop + retrig-97 removal post-merge; stale pacer-spool flood classified; pacer instance restart for 0.5.0 (perri) after release.

## ENDGAME (session 1655598c, 2026-07-27 13:4x): SWEEP MERGES COMPLETE
- ✅ **ALL NINE MERGED:** 105/107 (todlando, v5) + 109/102/108/100/110/97/103 (doyle). Main @1a294b6. **SACRED BASELINE = run 30303479435 @1a294b6** — todlando pinged (QUEUED, his session down) to arm guard; nothing pushes behind it till complete. AGENTS.md note committed to main @deaa8c8 mid-sweep (operator task DONE; shared checkout mod cleared).
- 🟢 **CI-INFORMANT FIELD-PROVEN end-to-end:** CI-KITSUBITO delivered main @87db24b SUCCESS live to doyle's perch 13:37 — #100's delivery leg closed. (Earlier: red-path demo discharged on 13:12Z real-failure evidence; wrap NOTIFY_SEND_TIMEOUT worked.)
- ⏳ **OPEN: #104 ONLY** — held on todlando's drained-window wedge pair (his detector likely killed by 09:39 daemon restart; re-check on his resume) + baseline-complete. Then merge → ALL GATES → **GO deployah counter 80** → AT PUBLISH: `spt send mobile-gw` + ping perri release number.
- 🚨 **09:36 MASS SESSION DROP:** hertz's omp-spt 0.3.30 bounce (~09:33 "daemon-coordinated apply" + "clean hertz bounce") cycled the DAEMON — new pid 24092 @09:39:38; every spt-hosted session dropped ~4h (doyle 09:36→13:37). Operator asked, answered. Seed-worthy: an adapter bounce should not cycle the fleet daemon — get hertz's exact commands on his resume.
- 🚨 **DELIVERY DEFECT (field-blocking candidate, banked in backlog):** bodies >~400B post-escape arrive EMPTY on hertz's perch (2 repro: tag-send + CLI-from-file; short bodies deliver). Chunk-REASSEMBLY drop. Workaround active: short bodies. perri ranks.
- ✅ hertz W1 lane closed + his 0.3.30 bounce EXECUTED (the daemon-cycling one above). #97 landed with 2 bonus hardenings (digest setup-split ruled structural fix; servicehost provably_gone repin per KH 7.50). #97 also hit the unmergeable-DIRTY-no-CI class (2nd bite) — rebased out.
- 💾 **hfenduleam disk: TWO more preflight true-positives** (29.2GiB, then 13.9GiB windows) — preflight 3-for-3 converting mystery reds into named fast-fails. ~100GB reclaimed across two cleanups (dead session scratchpads 48GB, dead rigs incl. merged-#108's 24.5GB; 48GB "ghost" = deleted-file handles releasing late). GC-mechanism seed banked. Reserve if it recurs: shared-checkout target = 111.5GB.
- Flake sightings tonight for the future registry: autostart :517 (4th+), trial_drain :541 (1st), brain_resume ticks (1st), input_ack_deadlock :551 (1st, on #103 suite-inert diff), wake_single_flight::two_concurrent_wakes (1st, main @899f466 post-tag, suite-inert tree, release-build load window; mechanism candidate = #106's ACCEPTED residual arbiter race load-widened — todlando informed). ⚠ AMENDED per deployah caveat (adopted): test sits ON #106's shipped seam ⇒ one observation does NOT file as load flake; at-sha rerun = FIRST LEG of repeat-proof, 2nd sighting on this seam = real-defect routing (product seam ⇒ todlando), not a load note.

## Wake session 1655598c (2026-07-27 ~04:15→) — freeze-window state
- ✅ **#109 ALL GREEN** (banked; its own Win leg passed = silent-peer fix holding). ✅ **#102 ALL GREEN** after rerun — its only red was the preflight FIRING CORRECTLY (hfenduleam 29.2GiB < 32GiB floor, transient window; box later self-recovered) = field true-positive evidence for the REQ; hertz ACK'd, no change.
- 🧹 **hfenduleam cleaned (this box):** cancelled stale run 30248852016 (Win test of MERGED #106's old sha — zero evidentiary value, freed the Win lane); reaped 8 leaked test daemons pinning closed gate rigs (path-attributed: gate-target-a8a26ed = orphan-pinned skeletons of already-deleted dir, ft-w1c-target); deleted ft-w1c-target 12.9GB ⇒ 80GB free. ⚠ Self-report: the 12.9GB delete I/O ran during #108's Win Phase A window.
- 🟡 **#108: Win red x2 attributed, rerun DELIBERATELY HELD** for main-run lane priority: silent-peer (pre-#109-fix branch, expected) + `trial_drain_drive_e2e::trial_candidate_self_drives_the_reap_of_a_black_holed_old_gen_controller` :541 FIRST sighting (load-window candidate — disk-low tail + my cleanup I/O). Rerun after main's Win legs clear. Linux + both n1 green.
- 🟡 **#100 complete: sole red = silent-peer (~8th sighting) on .github-only diff** (suite-inert proof). **todlando's timeout-wrap pushed @e2b34a60 + PROVEN: notify job green 1m5s, both sends NOTIFY_SEND_TIMEOUT @30s loudly** ⇒ cross-node send hang now 4/4 on kitsubito (seed hardened: deterministic-on-box); informant delivery proof awaits send-hang root fix. At merge time: have todlando rebase #100 onto post-#109 main so the fresh run drops the flake.
- 🕐 **Main run 30260486513: traceability/changes/n1(L)/test(L)/test(W) ALL GREEN; only n1(W) queued** behind #107-run's Win legs (FIFO). Verdict = freeze lift.
- ⚖ **GOLDEN CI RULED this session** (operator grill): see [[golden-ci-strategy]] + ADR-0050 + docs PR #110 (docs-only, CI green). hertz ACK'd; his CI bundle absorbed+grown. Tonight's sweep = old rules to completion.

⚠ **PENDING COMMIT (operator task 2026-07-27):** AGENTS.md "Issue tracking (unique case)" section (issues live on BigscreenVR/spt-bs-releases, NOT spt-bs-core) sits UNCOMMITTED in the shared checkout (parked on hertz's #97 branch) — commit to MAIN after the merge sweep, never to a build branch. alchemy-0 spawned+bound to spt-bs-releases (doyle-owned, Requests shell, 16 labels bootstrapped).

**Operator ruling:** root-cause + build the ranked findings NOW, drive to release publish. MODE-2 corruption = DELEGATED to emphasys (omp-spt DRI; hertz only affected + only omp-spt runner) — NOT in milestone. omp-spt F-032 (shutdown leaves harness alive) rolled in by operator addendum.

**Registry open @be4182b (PR #94):** mints REQ-ENDPOINT-STOP-RESOLVES, REQ-TEST-TMPDIR-HYGIENE, REQ-CI-FREE-SPACE-PREFLIGHT; amends REQ-SHELL-CLI-SPAWN-JOB-EXPOSURE (relink in-process CORRECTION + reachable-daemon routing fix ruled in). ALL per-wave activation ([[traceable-per-wave-activation]]) — build PRs flip stages WITH evidence.

## Lanes
- **todlando (product), dispatched:** leg A = stop-resolves (cli.rs ~7405); leg B = relink routing (cli.rs ~12559, unit-only decision seam — NO live-job int, VIEWER-CLOSE-DETACH CI lesson). Both cli.rs, he sequences. Awaiting receipt.
- **hertz (test-infra), dispatched, order 1-2-3:** (1) tmpdir leak; (2) W0 re-verify of F-032 + F-034's 4 shapes on 0.44.0 — spec FILE in session scratchpad `field-truth-w0-verify-spec.md` (5 items, verify-only, absence-needs-sibling-probe); (3) CI free-space preflight. Channel discipline: SHORT bodies + echo-back-from-FILE before each leg. Awaiting echo.
- **emphasys (MODE-2), delegated:** evidence pack sent (working hypothesis: F-033 EVENT-PART reassembly identity — size-dependence fits; tonight's refinement: NOT purely size-classed, mid-length Q corrupted while longer echo survived same round). Awaiting receipt + fold-or-separate answer.
- ✅ **W0-close DONE (doyle, 2026-07-27): hertz's 5-item pass complete, all sibling-probed, findings @.claude/reports/2026-07-27-field-truth-w0-findings.md (gitignored — evidence baked into REQ titles). SURVIVORS (2): F-034 shape 1 dead-relay ONLINE-HARNESS-ONLY + shape 2 rest_state sticky → minted REQ-RELAY-DEATH-CONVERGENCE + REQ-CREATE-BIND-REST-ACTIVE, registry PR #101 @72327c8 (inactive, per-wave; builder todlando, queued AFTER C/D/B). DISCHARGED (3): F-032 shutdown survivor (⚠ operator-report caveat: field re-presentation reopens WITH exact node versions), dead-owner re-pin, childless-zombie shim — no fix legs. hertz 0.3.30 bounce: item-1 evidence ✅ + #97 merge ⏳ (both required). hertz next = leg 3 CI preflight.**
- **Release at close:** deployah, counter 80 ([[release-counter-from-published]]), after all gates. deployah also still owes the runbook docs-publish.yml drift PR (pre-existing tail, I gate). 📱 **OPERATOR DIRECTIVE (2026-07-27): when the release PUBLISHES, notify operator's phone via `spt send mobile-gw`** (release number + counter). Also owed at publish: ping perri the release number (no-floor-before-ship rule finally satisfied).

## todlando build state (2026-07-27)
- ✅ **LEG A SHIPPED — PR #95 @`23d5ceb`**, branch `build/field-truth-w1-stop`, worktree `.worktrees/ft-w1a` off `be4182b`. REQ-ENDPOINT-STOP-RESOLVES activated `["impl","unit"]` in-PR. Four-source `StopEvidence` census (ready marker / perch record / registered address / broker row) ahead of every best-effort leg ⇒ zero evidence = `NoSuchEndpoint` exit 1 naming id + node; ANY evidence = old path untouched. ⭐ `known()` is ANY-not-all and the WHY is in the type doc — refusal must never make a wedged-but-evidenced endpoint harder to kill. Broker read injected as a closure (mirrors `teardown::unconfirmed_verdict`) ⇒ census unit-tests on a tempdir owlery, no daemon; local-first ordering proven by a PANICKING closure. Honest success clauses (address row read BEFORE delete — `DELETE` succeeds on zero rows). `purge --force` does NOT inherit the refusal. Gate: clippy 0, `-p spt --bins` 450/450, teardown units 4/4, traceable 0, xtask OK.
- ⚠ **Shared-seam PARTIAL (surfaced to doyle, not hidden):** only TWO `endpoint stop` call sites exist in the whole suite, both `endpoint_teardown_authority_e2e` on a bound id. Did NOT run that e2e locally — 3 CI runs QUEUED on the shared runner. PR CI is its verifier.
- ⛔ **LEG B VERIFICATION DONE 2026-07-27 — loopback shell-link reuse is UNSOUND. Fork sent to doyle (QUEUED), awaiting (a)/(b)/(c) ruling. No verb minted.** Two INDEPENDENT structural refusals: (1) `wansend.rs` `wan_shell_link_with` — `if instance.node == own_hex { return NotFound }`, operator side never dials itself; (2) `dispatch.rs` claims only `initiated_locally == false` rows, documented reason "serving our own requester stream would deadlock the requester against ourselves" ⇒ a loopback request is never served, failure mode is a HANG not an error. ⭐ Gating was NOT the blocker: `access.rs` `access_check` allows same-node FIRST ("never whitelisted away"), and relink needs no re-approval (spawn gates govern minting). op_id = wire-substrate only (`MintedOp` exists for exactly-once NET stream-open across broker restart, ADR-0034). Degrade today = `NoReply` rendered as "SHELL_REMOTE_REFUSED … (access gate)" — a LIE on loopback, since the gate can never refuse same-node. **Premise HOLDS:** `daemon.rs` `detached_no_inherit` doc — "a daemon-spawned shell is already job-neutral once the daemon itself is".
- ✅ **FORK RULED (doyle, 2026-07-27): (c) extend the DRIVE control socket.** Rationale on record: relink is a shell-family op, drive socket is the shell-family local control channel (M11-W2); (a) mints a listener that ages for one op, (b) "closest code ≠ right home". Gate criteria: (1) both wire guards LOAD-BEARING, untouched — fix routes AROUND the wire; (2) unknown-op refused LOUDLY (SERVICE_CONTROL_UNKNOWN_OP pattern) — drive socket grows it with this op; (3) route PROBE budget-bounded, relink WORK leg NOT; (4) route seam + confirm no caller reaches `wan_shell_link_with` self-node and renders the gate lie; (5) no op_id/MintedOp on local socket; (6) unit-only, flip REQ stages in-PR with evidence.
- 🏗 **Design census done, sent to doyle (QUEUED), building on his non-objection:** (1) **constraint 4 CLEAN, no code** — `wan_shell_link_with` reachable only via `wan_shell_link`←`shell_link_remote`, whose 3 call sites (cmd/drive/relink) are ALL behind `shell_ref.split_once('@')`; a self-node target renders `NO_ENDPOINT`, never the gate line (that string needs `NoReply` = a real dial to a real remote). (2) ⚠ **drive socket LACKS unknown-op discipline** — `drivehub.rs` `handle_conn` ends `_ => {}` "tolerated, not fatal"; fine for its 4 fire-and-forget kinds, FATAL for a reply-expecting op ⇒ becomes named loud refusal + hang-up. Safe: every existing sender is connect→1 frame→maybe read→drop. (3) **budget split via ONE op pair, two-phase reply** — bounded wait for an immediate `accepted` ack (old daemon never sends ⇒ TimedOut discriminates), then UNBOUNDED wait for the outcome; the ack manufactures the "same age" property that let `adapter_service_reconcile` skip its deadline. (4) ⭐⭐ **SCOPE + TRAP:** REQ covers spawn/relink/wake — CLI in-process launches are cli.rs shell-spawn (`shellhost::launch_shell` direct) + relink + local-wake (both via `spt_daemon::relink_shell`). **The daemon op must NOT be "call relink_shell"** — a fresh spawn has no parked link token ⇒ `NoLink`. It is the THIN LAUNCH keyed `{owner, shell_id}`: resolve record → merged shell section + install dir (the 3 lines `cascade_owner_edge` runs) → `launch_shell` → reply pid. Works for all three because `shellinfo::spawn_record` writes the record BEFORE launch. Gates/consent/AlreadyOnline/vocabulary stay CLI-side (TTY is there).
- 🔱 **(superseded, kept for the reasoning) the fork options:** ride the established LOCAL CLI→daemon control-socket family (digest/drive/tunnel/service; broker-served, Envelope kind+payload, `Role::Brain` handshake). RESIDENT-SERVICE W1 already supplies the degrade answers: unknown-op ⇒ server HANGS UP loudly (`SERVICE_CONTROL_UNKNOWN_OP`); client bounded by a budget thread ⇒ "daemon up, listener predates op" = TimedOut, distinct from "not running"; real-work op (reconcile) deliberately NOT budget-bounded vs a lookup that is. Relink = real work ⇒ reconcile pattern. Options: **(c) RECOMMENDED extend drive socket** (already shell-family, no new listener) · (a) new `link_socket_name` · (b) extend service-control. Then build: route-selection seam = socket reachable ⇒ daemon path; unreachable/TimedOut ⇒ in-process fallback + diagnostic naming WHOSE job coupled the child. Unit-only.
- 🆕 **LEG C DISPATCHED (doyle, 2026-07-27, operator-directed roll-in): spt-shells shell-informant must NEVER start a turn.** RCA already done by doyle (spool take-audit on his own perch): every boundary-spooled shell-context row (window=active_only, deferred=1) shows `taken_leg=idle-inject` ~200ms after spooling ⇒ **the turn-starter is the F-023 leg-2 deferred rescue in the shared idle-edge/parked claim, NOT the adapter handoff F-035 ruled at.** Registry PR #96 open — its three amended titles ARE the spec (REQ-MSG-IDLE-EDGE-DRAIN narrows to non-deferred unconditionally; REQ-HAZARD-DELIVERY-STARVATION scoped to default+idle_only, active_only explicitly outside; REQ-SEND-WINDOW-DRAIN-HONOR gains guard (4), and the F-035-CONFLICT rejection is SUPERSEDED on new evidence). Build: (1) `claim_idle_edge_*` → deferred=0 unconditionally, `include_deferred` param + resting-gate coupling retire AT THIS LEG (hook drain `poll_drain` untouched — REQ-INST-6 lives there); (2) `inject.rs` drops `deferred_held` computation; (3) unit = idle-edge claim never returns deferred; int = `spool_while_active_then_idle_fires_injection` INVERTED for the deferred row + a non-deferred row proving inject still fires (old assertion deleted, never preserved); (4) docs KH 7.23 scope note + dated ADR-0028/F-023 amendments, `[doc->REQ-HAZARD-DELIVERY-STARVATION]`; (5) stage flips w/ evidence. SEAM RUN: idle_edge_drain_e2e, active_only_never_relay_e2e, notif drain-validity units, redispatch+starvation suites. Independent of leg B; #96 merges first. **I take C first** (unblocked at #96 merge; B waits on #95 regardless).
- ✅ **LEG C fork-clause census DONE (2026-07-27), fork does NOT fire.** Producers of deferred rows = exactly THREE: cli.rs `--active-only` (+hidden `--deferred`), `api/reporting.rs send_deferred(id,"spt-shells",ctx)`, `notif.rs` quiet copies (WINDOW_ACTIVE_ONLY unconditional, ADR-0046). No fourth. Consumers of deferred idle-injection = exactly ONE product site: `inject.rs drain_idle_spool` → `claim_idle_edge_audited_at`. ⭐ **`drain_idle_spool` is BY ITS OWN DOC the shared core behind BOTH the send-time already-idle path AND the pulse-tick re-offer belt** ⇒ idle-edge claim and parked re-offer are the SAME claim; build items 1+2 narrow both, no second site to chase. 📌 Honest note sent (my read: intended, not a fork): producer 1 is affected via the BELT only — cli.rs send-time parked re-offer already guards `&& !active_only`, so an explicit `--active-only` send was never idle-injected at send time, but the belt reached it; post-change it waits indefinitely on a hook-quiet spt-hosted endpoint, which is exactly what ADR-0028 + the narrowed starvation REQ now say.
- 🆕 **LEG D DISPATCHED (doyle, 2026-07-27, 2nd operator roll-in): daemon status must divulge the COORDINATOR (brain) image; stale warning re-keys to it.** Registry PR #99 open — amended REQ-UPDATE-RUNNING-IMAGE-SURFACE title IS the spec. Defect: status shows broker image + CLI version but not the brain's, and the stale warning keys on the BROKER image — which legitimately stays old after every apply (brain-only restart, ADR-0018 D3-3) — so it nags the healthy freshly-updated node, and its remedy (stop+start) kills every hosted session where `daemon refresh` cycles the coordinator in place. Build: coordinator self-report (same HARD CONSTRAINT as F-025: value from the RUNNING brain process, never disk) · warning ONLY on coordinator-vs-installed · remedy solely `spt daemon refresh` · broker line informational (no warning/remedy) · coordinator unreported ⇒ not-reported, no warning · JSON `coordinator_image`/`coordinator_stale` mirroring broker_* EXACTLY incl. final-wave tightening (None on query FAILURE, definite bool only after Ok) · unit matrix (matched / stale→warn+refresh / unreported→no warn / **broker stale ALONE → NO warn**) + int live brain round-trip. Substrate = my own F-025 build (`KIND_BROKER_IMAGE`, `render_broker_image_line` cli.rs ~4555-4910). ⚠ If refresh can't remedy a coordinator-stale state, BRING IT — don't improvise wording.
- ⚠⚠ **LEG D pre-code findings (2026-07-27), sent to doyle:** **D1 TRAP — role cannot identify the coordinator.** `broker.rs` accepts EVERY client with `recv_hello(&mut recv, Role::Brain)`, and the CLI's own `Brain::cold_start` announces `Role::Brain` too (as do drive/tunnel/service control clients). Caching an image off any Role::Brain hello ⇒ a CLI connection (BY DEFINITION always the freshly-installed version) overwrites the coordinator's ⇒ **`coordinator_stale` false forever on every node, including the sick one**. Discriminator mandatory. **D2 CORRECTION — `BRAIN_PROMOTED`'s version is DISK-sourced**, from `AppliedRecord::AppliedPending { version }`, not the brain's build constant; and it exists ONLY on the trial/promotion path, so a normally-booted brain never emits one. Fails the hard constraint AND misses the common case — not building on it (doyle had suggested it as "the obvious shape"). **PROPOSED MECHANISM (no new plumbing):** broker hands the brain its `generation` at spawn (`run_brain(generation, reason)`, ADR-0018 V2) ⇒ brain announces `{image: env!("CARGO_PKG_VERSION"), generation}` post-hello; broker records it as coordinator image ONLY when generation matches the child it currently supervises (same exact-generation discipline as the D6-2 ready gate; a CLI was handed no generation and can never satisfy it); CLI queries new `KIND_COORDINATOR_IMAGE` → `Option<String>`, exact mirror of `KIND_BROKER_IMAGE`. **REJECTED transport:** the `brain.ready` file (`{pid, generation, exe_hash}`) — a file OUTLIVES its process ⇒ stale-record class my own `adapter_service_status` doc refuses ("a record answering a question the record cannot know"); a dead coordinator would keep reporting a version.
- 📋 **SEQUENCING (3 legs, all read-complete, ALL blocked only on merges):** C first (needs #96 only) → D (needs #99; shares cli.rs with B but different region — status ~4555-4910 vs relink ~12950) → B (needs #95). 5 PRs open 2026-07-27, all UNSTABLE on the shared runner.
- 🚀 **CI-RUNNER-INFORMANT SHIPPED 2026-07-27 — PR #100, branch `ci/runner-informant` @6351b90** (infra dispatch, built while C/D/B sat merge-blocked; `.github/` only, zero cli.rs collision). CI pushes run verdicts to agents over SPT_DEV instead of agents polling `gh`. **NO REQ / no registry / no traceable tags — operator-ruled infra, not product surface.** ⭐⭐ **In-repo evidence killed doyle's shape:** ci.yml's own "Two shells" note records a real failed run — *the Windows runner has no bash on PATH* — and EVERY `shell: pwsh` step is gated `if: runner.os == 'Windows'`, so **no interpreter is proven on both OSes**. Bare `runs-on: self-hosted` would silently never notify when the scheduler picked hfenduleam (invisible under `|| true`). RULED FIX (doyle approved, beat his box-pin): `runs-on: [self-hosted, Linux]` — the **OS label, not a box name** ⇒ future Linux runner eligible automatically, future Windows runner contributes jobs without hosting notify; zero per-runner config either way. ⭐ **Verdict trap:** `test`/`n1-gate` are `if:`-gated on REQ-CI-DOCS-ONLY-THIN ⇒ report `skipped` on Markdown-only PRs; "not success = failure" would have cried FAILURE on every green docs PR — only `failure`+`cancelled` are red. ⭐ Script lives at **`.github/ci/`** (NOT a new `.github/scripts/`): that dir already holds reap-census.* and `.gitattributes` already pins it `text eol=lf` with a comment naming the exact CRLF-on-kitsubito failure (`$'\r': command not found`) — extended the pin, verified all blobs LF-clean. ⭐ Trailer parse matches ONLY the project's `Co-authored by:` (space) spelling — git's hyphenated form mints junk ids (a real commit yields `OpenAICodex`). Hazards resolved: `spt send` CANNOT autostart (cmd_send guards `is_running`; the 4 `ensure_running` sites are status/adapter/shell-drive/shell-tunnel) and a down daemon still SPOOLS ⇒ log, don't skip; `grep -rn SPT_HOME .github/` = none and jobs can't inherit sibling-job env ⇒ leak structurally impossible, SPT_HOME neither set nor unset. ⏳ Red-path verify (one deliberate failing step, observe, revert) pending the green run — serialized because `concurrency: cancel-in-progress` would eat one.
- ⚠️ **Self-report (my near-miss, 2026-07-27):** `git reset --hard HEAD~1` to drop a throwaway probe commit ALSO discarded an uncommitted working-tree edit (the ci.yml notify job). Caught pre-push, reconstructed, amended — no wrong bytes shipped. **Lesson: never `reset --hard` while carrying uncommitted work in the same tree; stash or commit first.**
- 🟡 **LEG C BUILT + PUSHED, PR NOT YET OPENED — branch `build/field-truth-w1-inject` @2aae246** off #96's merge (3d9ec73). impl: `claim_idle_edge_inner` = single `delivered = 0 AND deferred = 0` query, **`include_deferred` parameter DELETED from both entry points** (structural exclusion, not caller convention); `inject.rs drain_idle_spool` drops the dead `deferred_held` read; rest gate stays on the HOOK drain (REQ-INST-6). ⭐ One narrowing covered BOTH claims (idle-edge + parked belt share `drain_idle_spool`). unit `idle_edge_claims_never_take_a_deferred_row` claims TWICE (permanently out of reach ≠ deferred-until-later); int inverted with the survivor **IDENTIFIED by draining it as a hook, not counted** — a count alone would pass if the edge injected the deferred row and stranded the default one. Docs: KH 7.23 SCOPE, ADR-0028 dated amendment, **reversal banner on `docs/F-035-CONFLICT.md`** (my own 2026-07-09 escalation that argued AGAINST this collapse and won on a then-green gate — what changed was field evidence, not reasoning). Gates by exit code: traceable 0, clippy 0, spt-store 276/276, spt --bins 447/447, spt-msg 7/7, notif 27/27, relay 11/11, carrier_claim 1/1, **idle_edge_drain_e2e + active_only_never_relay_e2e 1/1 on real broker+PTY** (int printed `hook_carried=["background context (active_only)"]` — survivor provably the deferred row).
- ⛔ **OPEN, blocks leg C's PR:** `spt-daemon --test inject_control_wedge` (F-023 **leg 1** acceptance, sibling of what I changed) is RED here: **13 passed / 6 failed, causes NOT uniform** — one `bind broker: Os { code: 5, PermissionDenied }`, five behavioural (ping never received, fault stamping, respawn count, re-spool). **All fixture bins verified present**, so NOT the unbuilt-fixture rig class. Unknown whether mine or the box (hfenduleam = live fleet daemon + 6 CI runs queued during the run). **Discriminating run was cut off by the operator pause: same test at BASE 3d9ec73 in `.worktrees/ft-w1c-base` (already cut, shares a copied target dir).** Base red ⇒ box, leg C stands; base green ⇒ mine, fix before PR. **Do not claim leg C green until this settles.**
- 📌 **PROCESS RULING (operator via doyle, 2026-07-27, BINDING):** registry mints ride the BUILD PR by default (registry hunk in the same commit as first evidence satisfies rule 3 by diff ordering). Separate registry PRs only for multi-builder fan-out or ruling-only amendments — and when one exists, **STACK the build branch on it and start immediately, no merge-waiting**. ⇒ leg D stacks on `req/daemon-status-coordinator-image` NOW; the two W0-survivor legs stack on #101.
- 🔧 Rig notes (leg C additions): `idle_edge_drain_e2e` needs **`cargo build -p mock-adapter --bins`** too — `mock-session` lives in the `mock-adapter` package (`adapters/mock`), not `spt`, and `-p spt --bins` does not build it (precondition assert fires at the `mock_session.exists()` line). `inject_control_wedge` lives in **spt-daemon**, not spt. Also: `cargo test -p spt --bins` emits several per-target result blocks — `tail -4` catches only the LAST (a 0-test fixture bin); grep all `^test result` lines and read the EXIT code.
- 🔧 Rig notes: `cargo test -p spt --bins` alone reds `adapter_translate_proof_gates_on_commit` (`--bins` builds test harnesses, not the plain fixture exe) → `cargo build -p spt --bins` first. cli.rs imported only `PathBuf`.

## Roll-in leg C (operator-directed 2026-07-26 late): shell-informant never starts a turn
- **Operator:** spt-shells shell-informant (session-start/post-clear) "should be --active-only (never starts a turn)".
- ⭐⭐ **RCA (2-minute, via REQ-SPOOL-TAKE-AUDIT):** rows ALREADY spool active_only (`send_deferred` → WINDOW_ACTIVE_ONLY; deferred MIRRORS window at the insert chokepoint, spool.rs:47). doyle's own perch spool: every spt-shells row `taken_leg=idle-inject` ~200ms after boundary spooling ⇒ the turn-starter is the **F-023 leg-2 deferred rescue** in the shared idle-edge/parked claim (`inject.rs:116 include_deferred=!resting` → `claim_idle_edge`). NOT the adapter poll→idle handoff (F-035's ruled leak). Spool db: `%LOCALAPPDATA%\spt-core\owlery\<id>\spool.db`.
- **Ruling (doyle):** idle-edge + parked-re-offer claims exclude deferred UNCONDITIONALLY — active_only is hook-carried on EVERY endpoint class, waits without hook cadence (ADR-0028 letter restored). This ADOPTS the collapse rejected in docs/F-035-CONFLICT.md (new field evidence supersedes) and REVOKES the F-023 deferred rescue. Quiet-notify copies (ADR-0046) stop idle-injecting too — intended (safe-point delivery).
- **Registry PR #96** (req/active-only-never-inject @8f4acea): amends REQ-MSG-IDLE-EDGE-DRAIN (non-deferred only), REQ-HAZARD-DELIVERY-STARVATION (guarantee scoped to default+idle_only), REQ-SEND-WINDOW-DRAIN-HONOR (guard 4: inject claims never take deferred). traceable EXIT=0. Build = todlando leg C (dispatched, full spec SENT): spool.rs claim narrow + inject.rs dead code + int test REWRITTEN to inverse + KH 7.23/ADR-0028/F-023 doc notes. Fork clause: any OTHER consumer relying on deferred idle-inject → back to me.
- 📌 Backlog seed: hundreds of stale `deadline-*.json` litter `%LOCALAPPDATA%\spt-core\` root — needs GC leg.

## Roll-in leg D (operator-directed 2026-07-27): daemon status coordinator image
- **Operator:** status must divulge COORDINATOR (brain) image (most relevant version); stale warning ONLY when coordinator outdated; remedy solely `spt daemon refresh`. **Registry PR #99** amends REQ-UPDATE-RUNNING-IMAGE-SURFACE (4-point addendum). Dispatched todlando.
- ⭐ **todlando D1 trap (ratified):** EVERY control client hellos Role::Brain (CLI included) — caching image off any hello ⇒ fresh CLI overwrites coordinator image ⇒ coordinator_stale FALSE FOREVER. Mechanism approved: generation-scoped post-hello announce ({image, generation}, brain-side env! constant), broker records only on supervised-child generation match (D6-2 discipline), KIND_COORDINATOR_IMAGE mirror. D2: BRAIN_PROMOTED version is DISK-sourced + promotion-only — rejected as source. brain.ready breadcrumb rejected (file outlives writer). **My added criterion: cache INVALIDATED on supervised-child change (refresh gen N+1 clears gen-N; death clears) — unit-pinned.**
- **flynn field instance same night:** ADAPTER_SERVICE_NO_ANSWER on 0.43.1 broker — ruled branch (a) correct refusal: adapter-service socket is BROKER-served (verified daemon.rs:329), coordinator reload never touches it; full bounce required. ⭐ ONE bounce window closes THREE: flynn W25 supervision proof + HFENDULEAM env-refresh deferred bounce + flynn cred-removal ping. Operator schedules.
- **2026-07-27 post-bounce update (doyle):** ✅ flynn W25 supervision proof GREEN on the bounced daemon (kill → relaunch pid 23964, ownership proven) — flynn leg of the bounce triple CLOSED. 🆕 Docs :5474 DOWN since the bounce: broker-side one-shot bind lost the port race (10048); `daemon refresh` verified INEFFECTIVE (brain-only; probe 000, no rebind attempt logged; sole `docshost::start` site = daemon.rs ~236). Remedy = full stop+start ⇒ **docs rebind JOINS the operator bounce window** (now: env-refresh + cred-removal ping + docs). Operator informed mid-session. Two seeds banked in [[spt-core-findings-backlog]]: supervisor startup_fault latch on double-daemon clean exit-0 (flynn, adoption-day default trap, 3 sub-defects) + docs bind lacks REQ-DAEMON-9-style boot-race retry. ⚠ perri's #98-publish blind-verify reads HIS OWN node's :5474 (docs are node-local per release) — HFENDULEAM outage does not gate perri, but flynn reads locally and is dark until the bounce.
- **PR #95 gate PASS posted** (2237/2237 + teardown e2e 2/2 + traceable + xtask after known exe-lock reap). **PR #97 (hertz tmpdir) gate HOLD posted:** endpoint_lifecycle.rs:27-28 doc_lazy_continuation FAILS COMPILE of test target (aborted nextest 1111/2235, census invalidated — 4 residuals = abort artifacts); + TestHome lacks TMPDIR set/restore (Linux tempfile reads TMPDIR; registry claim untrue off-CI). Both flagged to hertz, awaiting push, warm rig ready (.worktrees/gate-a8a26ed). digest_cross_node silent-peer red = load-window flake candidate, observe on clean rerun.
- 🛑 **MERGE FREEZE (doyle-echoed 2026-07-27): ALL merges hold until main run 30260486513 @8515f43 completes — sole verifier of the arbiter fix; any main push cancels it. My ci-watch.sh is REPORT-ONLY (never merges) — hold is manual and kept. BASELINE RULING AMENDED: sacred baseline = last of ALL merges (whole-sweep main, not todlando's subset). Sequence: 8515f43 completes → todlando 105/107 (sha-equality-gated, v4) → my five (97/100/102/108/109) serially → AGENTS.md note commit rides before final merge → LAST push's run = sacred, guarded. todlando killed his own requeue-105 pre-stale-green (bare merge, no --match-head-commit). **v5 armed (2 legs then STAND DOWN): guard 30260486513, then merge 105/107 sha-equality-gated. I OWE: ping todlando the FINAL push's sha+run-id after my fifth merge (he arms baseline guard on that run only, no inference). Also owed at queue-drain: wedge-rerun + #100-demos ping. My merge order: 109→108→102→100→(#97 post-rebase); AGENTS.md commit before final merge.**
- 🔭 **WATCHER v5 (todlando, supersedes v4 — v4 KILLED, not patched):** v4 pointed phase 3 at the last of *todlando's* merges and its cancel-handler fires one at-sha rerun — under the whole-sweep sequence EVERY push in (3)/(4) legitimately cancels its predecessor, so v4 would have burned queue slots reruning dead shas. **v5 owns exactly two legs then STANDS DOWN:** guard 30260486513 @8515f43 → merge #105/#107 sha-equality-gated → exit. It will NOT guard or rerun any main run after that. ⇒ **the baseline guard is armed only on doyle's ping naming the LAST push's sha/run id** — deliberately not inferred from "newest main run", because the AGENTS.md docs-only push riding before the final merge makes newest-run guessing wrong exactly once. See [[audit-live-watchers-before-rearming]].
- ✅ **BOTH TODLANDO LEGS CLOSED 13:34Z 2026-07-27.** (1) **ARBITER FIX VERIFIED**: run 30260486513 @8515f43 = completed/**success** after ~2h30m queued — the freeze held on both sides and the only-ever execution of #106's arbiter fix is now green on main. (2) **#105 @62862a7 + #107 @1dbc004 MERGED**, both sha-equality gated; main head 41ec737. (3) ⭐ **#107's cfg(target_os="linux") unit confirmed BY NAME, not by green tick** — `proc::tests::a_zombie_is_absent_to_the_identity_oracle_and_gone_to_relay_liveness` + `zombie_child_reads_dead` + `relay_liveness_kills_only_a_provably_gone_relay` + `converge_dead_relay_guards_on_pid_session_and_online` all PASS on kitsubito, plus the REST-ACTIVE pair. Linux `test` job was **success, not skipped** — the docs-only thin gate makes skipped and green identical in the rollup, so a green claim on a first-ever-executed unit must be name-verified. v5 stood down; baseline guard stays unarmed pending doyle's final-sha ping. Queue drained (doyle already pushing c2a123e behind 41ec737 — cancellations there are BY DESIGN, not defects).
- ⚠ **#106 MERGED @8515f43 on a STALE GREEN (merge race, todlando self-reported): v2 requeue watcher reran OLD sha 93a70db → green (pid race fell the hiding way) → merged the by-then-pushed head 92394d9. Content correct (arbiter fix in), evidence UNVERIFIED — main run 30260486513 @8515f43 = FIRST execution of the arbiter fix AND sacred-baseline candidate (double weight; todlando guarding: complete⇒verdict, cancelled⇒one at-sha rerun, red⇒escalate, nothing pushes behind). ⭐ Process data: same-sha rerun-green = timing hides THIS defect ⇒ rerun-until-green would bury it; names-first was the detector. v3 watcher: --match-head-commit belt + NO auto-rerun on red. ⭐ Rerun-button discipline (doyle): rerun-after-attribution OK / rerun-before-names banned / rerun-as-merge-evidence requires green-sha==head-sha.**
- 🟢 **#104 CI ALL GREEN (rerun cleared both flakes) — merge HELD on the one remaining gate: todlando's drained-window paired inject_control_wedge rerun (fires at queue-drain ping, imminent). Then merge + it rides the release for perri's #7.**
- 🔴 **#107 Linux red = 2nd REAL DEFECT of the night (todlando): `process_identity` Linux-zombie hole — unreaped dead child reads Present(matching birth) ⇒ Held forever ⇒ relay-death convergence NEVER fires on Linux for the field shape. Fix rides #107 (in-resolver zombie demotion, ratified; cfg(linux) unit's first execution = CI leg; non-reaping pinned load-bearing). Mirror of WIN-PROC-LIVENESS-ORACLE — banked in backlog. #106 arbiter fix pushed @92394d9 RED-proven.**
- 🔴 **#106 Win red = REAL PRODUCT DEFECT (todlando, 2026-07-27, caught by CI not gates):** `launch_routed` consults `live_launch_winner` on EVERY fallback_allowed cause; sound ONLY for LAUNCH_ROUTE_UNANSWERED (late-ack window). NO_DAEMON + still-alive prior pid ⇒ arbiter adopts zombie, relink = success-reporting no-op WITHOUT minting fresh token (flynn's stale-online class via the arbiter; Linux green only by pid-death race). Impl diverged from its own comment; BOTH doyle's gate and todlando missed the divergence — ⭐ lesson: gate comments-as-design by DIFFING impl against comment. FIX rides #106 (approved): `may_have_launched()` on the cause (Unanswered only), arbiter gated on it, 2 units (NO_DAEMON+live ⇒ spawn runs / UNANSWERED+live ⇒ adopt). Side benefit: narrows corpse-oracle exposure to the genuine late-ack window. **#105 Win red = `registry::tests::concurrent_registration_never_locks` (spt-store, zero diff overlap, 16-thread sqlite load flake) — rerun in flight.**
- ✅ **#98 MERGED 10:43Z (rerun-3 green), perri courtesy ping SENT (two docs deltas ride next release).** ⚠ **#100 notify hang REPRODUCED 2/2 (5m16s exactly, sole red on run 2 — deterministic reproducer kitsubito→bigscreen); todlando wrap-GO sent.** 🔴 **kitsubito runner DEAF-CANDIDATE: online+idle 30+min with ≥5 queued Linux jobs (NTP-dark + send-hang + runner-deaf = box network-health cluster); next cycle unchanged ⇒ runner-deaf playbook (_diag SSL/cert, force-cancel zombie).**
- 📋 **MAIN-BASELINE RULING (doyle 2026-07-27): main UNVERIFIED since be4182b 03:47Z (5 merge runs all concurrency-cancelled — todlando finding). Procedure: final merge of todlando's sweep = SACRED BASELINE run, nothing pushes behind it till complete; doyle's 5 merges hold if they'd cancel it; cancelled anyway ⇒ workflow_dispatch main. Interim: doyle's rerun of 30241033173 (#96-merge Win leg) in flight = partial baseline. SEED: hertz CI-lane PR (AFTER his current two) = BUNDLE: (1) `cancel-in-progress: ${{ github.ref != 'refs/heads/main' }}` (todlando's one-liner, ratified) + (2) add `workflow_dispatch:` trigger (ci.yml has push+PR only — gap found 2026-07-27). AMENDED fallback for cancelled baseline: `gh run rerun <cancelled-id>` at same sha (executable today); empty-commit trigger REFUSED. todlando's 3rd watcher guards the sacred run: ESTABLISHED/RED-escalate/UNRESOLVED.** #105 + #106 both Win-Phase-A red singles (6m43s/6m51s), names gated on run completion, both on todlando's abandon-extract-rerun-escalate watchers; prior = Phase-A rotation but names-first.
- ✅ **wedged_viewer 240s RCA CLOSED (todlando, ratified doyle 2026-07-27):** `read_event()`=unbounded on controller path (viewer helper has the bound, controller never did) + EDGE-TRIGGERED gap detection + b4 drop-don't-block ⇒ burst AND ISOLATED marker dropped in same overflow window = NO frame ever arrives = neither accepted outcome representable = block to nextest kill. Latent test-liveness defect, first-ever sighting needed tonight's starvation. Isolation property itself likely intact (drain alive @15016ms poison-on-schedule; controller conn open-silent not closed). **FIX = hertz's lane (dispatch split binding; todlando hands spec verbatim), OWN THIN PR never riding #104; shape = `read_controller_event_resuming_until` (production byte-identical) + named third outcome + fresh-reader ring probe discriminator. SEED CLASS banked: edge-triggered-gap + drop-quiet = unrepresentable outcome — audit all timed observers in b4 plane.** #104 paired base protocol now OPTIONAL. hertz holds 2 start-gated items, his sequencing.
- 🔁 **#104 first full run RED both OSes (triaged, reruns dispatched):** Win = silent-peer 4TH sighting (same 429/445 — pure flake-class reinforcement, feeds hertz's characterization). Linux = `attach::wedged_viewer_does_not_stall_controller` TIMEOUT 240s, **FIRST sighting**, attach/viewer plane = OUTSIDE #104's ruled seam — watch: repeat on rerun ⇒ real-suspect analysis vs todlando's claim narrowing (distant subsystem but unruled). #104 merge also still owes his paired wedge rerun (parked on queue drain).
- ✅ **silent-peer flake ROOT-CLOSED (hertz PR #109, READ-PASS, 2026-07-27): 4/30 quiet-box repro — 250ms SHORT_BUDGET covered the SETUP net_dial too; worker panicked at setup (:429 unnamed-thread in all 7 sightings), outer mislabeled as hang. Fix = 1s test budget (semantics kept, production 10s untouched), 30/30 after. Also #108 (viewer liveness + broker_image_until) READ-PASS + audit ledger accepted. Both gate on CI green, I merge. coordinator_until tail held on #105 worktree.**
- 🚨 (superseded) **silent-peer flake = 3 SIGHTINGS, hertz DISPATCHED (2026-07-27, start-gated on queue drain):** digest_cross_node::a_silent_peer_bounded... red on #97-gate obs + #98 docs-only leg + main post-#96 rerun (all Win/hfenduleam load windows, identical panic sites 429/445). Dispatch = loop-to-characterize on quiet box THEN repin-vs-harden; NO local loops till CI queue drains; does NOT gate his #97 merge/bounce. Main failed-leg rerun dispatched (main needs green baseline for release). Probe also confirmed both runners ALIVE (not deaf) — queue deep only. Two cancelled main runs (#95/#99 merge-triggered, 07:09/07:25Z) = concurrency casualties, unwatched.
- 🔁 **#97 Win red triaged (wake session): `registry_lifecycle::multichunk_feed_applies_with_exactly_one_snapshot_write` 0-vs-1, Phase B — matches SEEDED flake (backlog 2026-07-22, "honest-input wrong-count race", predates hertz's rig change; Phase A 2055/2055 green incl. all touched files). NOT hertz's. Rerun dispatched; hertz pinged. 3rd same-test red ⇒ loop-to-characterize.**
- 🔁 **#98 Win red triaged (2026-07-27 wake session): `digest_cross_node::a_silent_peer_is_bounded_and_named_rather_than_hanging_the_caller` — SECOND sighting (first flagged at #97 gate), this one on a DOCS-ONLY diff = suite-inert proof it's not the change. Timed-window test, load pushes red. Failed-leg rerun dispatched. If 3rd sighting → hertz flake-hardening dispatch (post-queue).**
- **PR #98 (docs, mine):** flynn docs gap — [shell].spawn/wake_command missing from install-dir resolution docs (b3b2bd5 amended docs/MANIFEST.md not docs-site; dual-doc drift class seeded) + perri fat-archive musl staleness (musl recognized since v0.30.0, list now names its registry). flynn's 0.43.0 record stands (resolution genuinely new in 0.44.0); his runbook-undo acceptance test GO, watching #98 publish.
- **perri seeds:** resident-alias link-authed visibility (banked, unranked; PACER-0 ships canonical-id signing). All three seeds in [[spt-core-findings-backlog]].
- **2026-07-27 late-night sweep (doyle, post-clear session f591f21d):** ✅ **#99 MERGED** (Win-test rerun GREEN — load-window attribution confirmed). 🆕 **LEG D SHIPPED — PR #105 @62862a7** (base main, `build/field-truth-w1-coordinator`): generation-scoped announce built as ratified; RED-verified gate; my two rulings SENT: (1) coordinator_stale=None on unreported RATIFIED over literal broker mirror (definite bool only after definite comparison; broker Ok(None)=pre-self-report vintage IS evidence, coordinator absence has innocent mid-cycle cause) — condition: if #99 title pins EXACT mirror, dated title clause rides #105; (2) generation KEPT over per-spawn random token (guesser already owns broker socket = full control; accepted-scope caveat in PR is the right artifact). My #105 read owed after merge sweep. 💾 **DISK EPISODE:** hfenduleam hit 37 MB free; my two closed gate rigs (87.5 GB) deleted on todlando's flag → 96.4 GB free; his leg-D int LNK1318 = disk, rebuilt after. 📦 **perri PACER 0.3.0 RELEASED** — operator LIFTED the docs-publish gate (musl-in-archive supported today) ⇒ perri UNBLOCKED, #98 demoted to docs-only follow-up (publish ping = courtesy delta, not a gate). My rebound-0 → PACER-0 migration DONE (teardown+update+spawn, pid 41628). 🔧 **flynn T7:** alchemy 0.5.0 installed; add --release hold question RULED from source (hold = daemon-apply ceremony ONLY, broker.rs ~6048; add --release = CLI crc-swap by design; interim contract = kill + desired-state relaunch, flynn documents) — seed banked. W25 acceptance PASSED (release-pointer spawn, absolute-path instruction deleted) ⇒ shell-launch-truth interim CLOSED. ⚠ **corpse-handle seed UPGRADED FIELD-BLOCKING** (flynn pid 5756 + liam pid 25944, independent identical specimens, 3 owners blocked in one window) — raised for operator ranking. 🩹 **docs :5474 served by operator STOPGAP daemon** (`Temp\spt\docs-host\`, pid 45796); fleet daemon's binding still lost until bounce; tear stopgap down at real bounce.
- 📡 **Leg C third field sighting (perri, 2026-07-27 00:37):** --active-only send WAKES an idle target on 0.44.0 — pacer-free minimal repro, busy-path contrast correct. Ruled: doc right, behavior = the F-023 deferred-rescue defect #104 fixes; banked as field evidence on the REQ. perri may note pacer known-issue ONLY after release ships (no-floor-before-ship). ⚠ **#97 + main Windows test reds = DISK-WINDOW casualties** (failures 07:16-07:18Z inside the 37MB window; sub-20ms fail shapes) — failed-leg reruns dispatched for both. **flynn relink-advice finding: advice string is ALCHEMY-authored** ([update].message channel), not core — grep-proven absent from tree; core-side remainder banked = no non-destructive relaunch verb for an ONLINE shell instance (relink correctly refuses; teardown+spawn pays identity). Suggested honest interim wording sent.
- ✅ **LEG B SHIPPED — PR #106 @`ed0ef4f`**, branch `build/field-truth-w1-jobexposure`, worktree `.worktrees/ft-w1b` off main @56a3497. REQ activated `["impl","unit"]` in-PR. Thin `KIND_SHELL_LAUNCH` on the drive socket keyed {owner, shell_id} → `linkhost::launch_shell_daemon_side` (resolve record + [shell] + install dir, spawn job-neutrally); `LaunchOrigin::{Cli,Daemon}` threaded through `launch_shell_from` / `relink_shell_from` / `wake_if_offline_persistent_from` so the 3 CLI sites route and every daemon-side caller is byte-identical. Two-phase: bounded ack (`LAUNCH_ACK_BOUND` 5s) then UNBOUNDED outcome. Five named pre-ack causes: LAUNCH_ROUTE_NO_DAEMON / _UNANSWERED / LAUNCH_REFUSED_FOREIGN_HOME / _RECEIPT / _UNRESOLVED, plus server-side DRIVE_UNKNOWN_OP (the `_ => {}` arm now refuses loudly + hangs up). `DETACH_BREAKAWAY_DENIED` names the launching process (exe+pid) at BOTH primitives. ⭐ **RED PROVEN twice:** `fallback_allowed→true` reds the 3 commitment tests; `_ => {}` restored reds the hang-up test WHILE ITS ORACLE PASSES. Gates: 52 units green (drivehub/shellhost/linkhost/shellwake), clippy 0, xtask check OK, traceable 0. Flagged to doyle: sibling primitive rode along · `shell_launch_bounded` pub for the 300ms test · 5s bound cost.
- ✅ **#105 READ-PASS posted (doyle, 2026-07-27 wake session a2e7369c):** full diff read; discriminator pure+unit-tested with read-time re-check, announce round-trip drains old-broker error, coordinator_stale=None-on-unreported per ruling 1, broker line de-fanged w/ negative assertions, field case pinned, scope caveat present (ruling 2 artifact). Cosmetic only: toml comment tail keeps old unit name in broker-leg history. #105 remaining gate = CI green only.
- 🪦 **CORPSE-HANDLE SEED CAUSALLY CLOSED (liam, 2026-07-27, ratified doyle+flynn):** real instance pid 47076 — held handle ⇒ SHELL_ALREADY_ONLINE ×6 (t=0.1–10.3s), CloseHandle ⇒ SHELL_RELINKED next probe. Fixtures locked: unit=dispose-flip, int=six-refusal sequence. Named oracle: GetExitCodeProcess on held handle, NEVER OpenProcess-succeeds; fix holder-independent. flynn counterexample resolved via #22 (in-process CLI spawner = fast class). Sole open q (open-question framing): is resident holder the daemon. Full detail in [[spt-core-findings-backlog]]. Seed FIELD-BLOCKING, spec-ready on rank.
- ⚖ **#106 RULINGS (doyle, sent):** sibling naming KEPT (#93/KH-7.50 precedent, provenance in PR body suffices) · `shell_launch_bounded` → pub(crate)+test re-export (spt-daemon public surface = contract boundary) · LAUNCH_ACK_BOUND STAYS 5s (shortening widens the late-ack race). ✅ **LATE-ACK CLOSED (2026-07-27, commit @93a70db):** arbiter = recorded live pid BOTH sides (`shellhost::live_launch_winner`, resolve_wake's rule EXTRACTED; ordering: ack precedes launch ⇒ caller spawns first, DAEMON stands down); loser adopts winner pid = SUCCESS, non-fault wording both sides; 3 new units + RED re-proven (55 green). My rulings posted on PR: residual check-then-act window ACCEPTED, NO per-instance launch lock (orphan-bounded beats stale-lock class; doc at LAUNCH_ACK_BOUND); pub(crate) w/o re-export accepted. ⚠ Recorded inheritance (non-blocker): live_launch_winner probes is_process_alive = the unsound Win oracle the corpse-handle seed condemns — call site added to seed's consumers-to-audit; central oracle fix heals it. **#106 PASS gates on CI green ONLY.** todlando moved to two W0 survivors stacked on #101.
- ⚠️ **NEW LESSON (mine, 2026-07-27): never `cargo fmt` in this repo** — no rustfmt gate exists and the tree is NOT rustfmt-clean; `cargo fmt --all` churned 251 files (cli.rs alone +601 unrelated lines). Caught on the diff stat, restored the tree, re-applied edits by anchored python replacement (CRLF-preserving) → shipped diff 7 files/+1025/-18, zero fmt noise. See [[no-cargo-fmt-in-spt-core]].
- 🏗 **LEG B design record (todlando, 2026-07-27 late):** `.worktrees/ft-w1b`, `build/field-truth-w1-jobexposure` off main @56a3497, registry activation IN the build PR. Shape = ruled (c): thin LAUNCH op on DRIVE socket keyed {owner, shell_id}, two-phase reply. **Three design calls RULED (doyle, all approved):** (a) ack = COMMITMENT TRANSFER (pre-ack CLI may fall back, post-ack NEVER — hard error, no second spawn; unit-pinned invariant); (b) post-ack connection loss = INDETERMINATE, spawn record KEPT (recoverable-record beats orphaned-binary; record-before-launch already the store's crash shape) — gate criterion: indeterminate message claims NEITHER outcome, names both + relink recovery; (c) owlery-mismatch refused PRE-ACK (custom-home rigs stay on today's path; non-relay receipts pre-refused, daemon never self-connects) — gate criterion: mismatch refusal NAMED distinctly from unknown-op AND TimedOut-old-daemon (three causes = three diagnostics). #99 title verified on main: tolerates coordinator_stale=None, no clause needed in #105. todlando's owed items (wedge rerun #104, #100 demos) parked on my queue-drain ping.
- ✅ **PR #107 SHIPPED + READ-PASS (2026-07-27 wake session): both W0 survivors** — @771779b, `build/field-truth-w1-w0survivors`, STACKED on #101 per mints-ride ruling; both REQs activated ["impl","unit","int"] in-PR. RELAY-DEATH: `liveness::relay_liveness` via `process_identity` table oracle + `info.pid_started_at` birth pair (recycled pid ⇒ Gone; Unproven never kills); `converge_dead_relay` session+pid+online CAS, record-first retirement; int rig = real killed child under live owner with `forget(child)` DELIBERATE pinned-corpse trap (proves table immunity) + both hertz sibling probes. REST-ACTIVE: `fresh_bind_over_dead_life` = terminal prior AND new session (4 non-normalizing cases tested); same locked write as online; real-binary e2e. RED both legs. **My RULING: HOSTING_AUTHORITY_DEMOTED rows converging under the arm = CORRECT intended kin, proof-gated.** Merge gate = CI green (watcher has 107). NOTE: #107 stacked on #101 ⇒ merge #101 FIRST, then retarget/merge #107. **MERGE SPLIT (doyle→todlando 2026-07-27): todlando DRIVES #101→#107→#105→#106 on green (authorized, no further word needed); doyle keeps #97/#98/#100/#102/#103 (post-merge choreography: #98→perri ping, #97→hertz bounce+emphasys two-ping, #100→notify demos). todlando's W1 build lane DONE.**
- **todlando sequencing: C ✅ BUILT — PR #104 @2aae246, my READ-PASS interim posted (remaining: CI green + owed drained-window paired inject_control_wedge rerun; load-window attribution accepted — base 5 red vs mine 6, disjoint rotation, PermissionDenied on base too, plus strict-subset claim argument). → D (STACKING on req/daemon-status-coordinator-image branch now per new ruling, no merge-wait) → B (needs #95, todlando merges after my posted PASS) → two W0-survivor legs stacked on #101. I merge #98/#99/#100/#101/#102/#103 on CI green. #97: hertz 0f7722b re-gate INTERIM GREEN (targeted clippy+unit); census leg + merge verdict deferred to quiet box. #99 Win-test red = Phase-B load-window family flake (banked in backlog), rerun dispatched.**
- **hertz W1 lane COMPLETE pending gates: #97 (tmpdir, interim green) + #102 (free-space preflight, READ-PASS — kill-check: no GH-hosted job exists, 32GiB floor safe) + #103 (registry thin-lane classifier, READ-PASS — traceable-reqs.toml joins docs lane; traceability job unconditional; three-list matrix verified). 0.3.30 bounce gate = #97 merge only now (W0 item-1 evidence banked).**
- **Operator restart 2026-07-27 (~lateNight): spt-core daemon bounced (fresh pid 44644), my session carried across, watcher re-armed. todlando's baseline log survived — that's how leg C's box-attribution closed.**
- 🆕 **CI-RUNNER-INFORMANT built (operator-directed roll-in 2026-07-27): PR #100 @6351b90 (todlando, `ci/runner-informant`)** — notify job `runs-on: [self-hosted, Linux]` (todlando's fix: Windows runner has NO bash — my either-box shape had a coin-flip silent mode), one script `.github/ci/ci-notify.sh` (LF-pinned dir, extends existing .gitattributes convention), verdict rule skipped=non-failure (docs-only thin gate), doyle always + trailer-agent best-effort, `--from CI-<RUNNER>`, default window, `|| true` never reds CI. Gate legs: receipt of green self-notify + red-path demo (deliberate red, reverted) + code read. Post-merge: every CI run self-announces; my watcher demotes to belt. Seed detail in [[spt-core-findings-backlog]].

## Merge sweep state (todlando, 2026-07-27 09:5x — all four of mine gate on CI green ONLY)
- ⏳ **OWED BY ME, HELD DELIBERATELY: #100's `timeout 30` wrap** (`.github/ci/ci-notify.sh` line ~150, the single send site, once per recipient) + a loud `NOTIFY_SEND_TIMEOUT` line on exit 124 + `|| true` kept + job `timeout-minutes` STAYS 5 (raising it would hide the class instead of bounding it). **NOT pushed yet, on purpose:** ci.yml's `concurrency: ci-${{ github.ref }}` + cancel-in-progress means a push to the PR ref would CANCEL doyle's in-flight notify rerun and destroy the perishable 2nd data point (reproducible hang vs transient kitsubito network). Push AFTER the rerun verdict. doyle RATIFIED the hold and the whole wrap design. Rule encoded: a notifier must be best-effort in TIME, not merely in exit code — `|| true` cannot guard a hang.
- ✅ **#101 MERGED 09:50:50Z (f30aa86) by my own watcher** on its green. **#107 retargeted to main BY HAND** — see the retarget trap in [[registry-mints-ride-build-prs]]; conflict-freedom proved by `git diff main...req/field-truth-w0-survivors` = EMPTY. #107 mergeable, run 30251150890 queued.
- ⚠ **watcher v1 BUG I shipped and fixed (doyle flagged the class):** a failed `gh pr merge` did not mark the PR done ⇒ it stayed pending and would retry the doomed merge every 180s, silently, forever. v2: mergeability checked BEFORE any attempt, and CONFLICTING / merge-failure / RED are ALL terminal-escalate; UNKNOWN waits instead of guessing. One attempt per PR, never a loop. ⭐ Did NOT patch v1 in flight — **bash reads a script lazily by byte offset, so editing a running script can corrupt its execution** (doyle: worth keeping).
- **doyle's word: DRIVE ALL FOUR** (#101 registry → #107 on retarget → #105/#106 either order). His five (#97/#98/#100/#102/#103) stay his (perri/hertz/emphasys/notify choreography). Repo has **NO auto-merge and NO branch protection on main** ⇒ the CI gate is enforced by MY watchers, not by GitHub; merge method `--merge` (repo history = merge commits).
- **THREE watchers armed** (mechanism, not vigilance — merge ONLY on `gh pr checks` exit 0, RED = abandon+escalate, never retry into main): (1) main watcher on 101/107/105/106 with #107 code-gated until its base reads `main`; (2) per-PR requeue watchers for #105/#106 — wait for run completion → EXTRACT failing test names → rerun failed jobs only → re-arm merge gate → stop on a second red; (3) sacred-baseline guard per [[main-baseline-procedure]].
- ⚠ **#105 and #106 BOTH RED on Windows "Test — Phase A"** (6m43s @09:07:10-09:13:35Z, 6m51s @09:23:23-09:29:55Z). Names NOT yet obtainable — logs gated until each run completes (both stalled on kitsubito's queued Linux legs); **three dead ends proven: zero artifacts uploaded, no junit in nextest.toml, runner-local `_diag/Worker_*.log` carry runner internals only (console pages are uploaded-then-deleted)**. doyle's prior = his Phase-A-Windows rotation (silent-peer 6 sightings tonight, autostart-interleave 4); names-first discipline HELD, no attribution before the log opens.
- ⭐ **BASE ANALYSIS killed the "main is red, both inherit it" shortcut (doyle RATIFIED):** #105's base 6ecec12 (#99 registry merge) does NOT contain #95; #106's base 56a3497 IS the #95 merge; #101/#107 sit on 3d9ec73 and #101's Win test PASSED. A red present at 6ecec12 cannot come from #95 nor from a registry-only diff over a passing base ⇒ attribution returns to each PR's OWN diff or the flake rotation.
- **Self-report (shared-box discipline):** no local cargo in either failing window (my gate ended ~08:45, reds ran 09:07+), so contention-from-me is unsupported — but a CI job started ~08:47, closer to my gate than my own rule likes. Recorded, doyle: "no concern".
- **#104 Linux 240s timeout RCA → hertz's lane** (test-liveness = his even when my build lane is empty). Spec at `.claude/reports/2026-07-27-attach-viewer-liveness-spec.md`; hertz ECHOED it back accurately and holds it + silent-peer characterization, his sequencing. Class seed banked in [[spt-core-findings-backlog]]. My 3 riders sent: deadline must stay a TOTAL bound (brain.rs forbids the per-frame reset), the `attach_as` resume leg is ALSO unbounded, and `ControllerIrrecoverablyBehind` must stay a PASS (only zero-events becomes the named FAIL).

## envelope calibration for emphasys probe matrix (2026-07-27)
- Confirmed from source: plain msg = `<EVENT type="msg" from>` ONLY (no ts/id); chunk boundary INCLUSIVE 400 BYTES (`len()<=400` unchanged, 401+ chunks); threshold applies POST-ESCAPE (`\n`→`<br>`, entities). emphasys matrix validated on all three; steering choreography: at hertz 0.3.30 boundary → ping emphasys, hand hertz ~5-min busywork, ping emphasys again on start.

## Tonight's precursors (same session, already landed)
- PR #91 seed REQ-MSG-INJECT-LEG-DROP-VISIBLE + is_process_alive doc-anchor check closed-no-action.
- PR #92 hertz digest label repin (gate PASS) + PR #93 authorless servicehost provably_gone hunk adopted (both hertz + todlando denied authorship; doyle-ruled correct per KH 7.50; hertz carried with provenance body).
- hertz channel echo-back protocol PROVEN working (2 clean task cycles); his pre-reset "servicehost repin DONE" claim classified phantom.
