---
name: msg-identity-milestone-progress
description: "MSG-IDENTITY milestone (operator GO 2026-07-10): messaging delivery-integrity + endpoint identity fix cluster off v0.30.6; F-037 EXCLUDED. Triage PR #78; todlando dispatched; one release at end (target v0.31.0)."
metadata: 
  node_type: memory
  type: project
  originSessionId: c9c02696-1ec3-4319-8b23-b7f72090fdb3
---

**✅ MILESTONE CLOSED 2026-07-14 — v0.31.0 field-verify complete across all three partners:** perri stamps CLOSED 07-10, flynn F-038 autostart PASS 07-13 (OS-boot-replay confirmatory rides next real reboot), todlando CLOSED 07-14 (W6 stderr semantics CLEAN on 535k-record evidence + F-038 live daemon-restart leg PASS; riders → [[spt-core-findings-backlog]]: lia no-comeback, emphasys vanish, deadline litter, daemon-restart verb). Detail in [[v0310-published]]. Historical ledger below.

**MSG-IDENTITY milestone** — operator GO 2026-07-10: "two triages + prominent backlog seeds, especially messaging + endpoint identity"; gather data → missing roots → JIT plan → todlando/deployah build → release publish. **F-037 EXCLUDED by operator (covered later).** Test-hardening cluster stays queued.

**BUILD COMPLETE 2026-07-11: ALL SIX WAVES MERGED — main @a6ff501. deployah GO'd for v0.31.0 (SENT live).** W6 #84 merged @a6ff501: read-gate via 3 parallel agents (legs a-d PASS, harness PASS after required R1 survivor-identity rework @06a2d74 — u_at_release snapshot closes leaked-handler false-green; traceability PASS 482/482; verdict = PR #84 comment). New-tip CI full green. One-off Windows red on old tip = shellhost close_shell promptness bound (10.9s vs 10s) — load class, did NOT recur; todlando pre-triage parked (two mechanisms: saturated-runner scheduling OR live-host cross-talk via unbounded drive_clear on default SPT_HOME; doyle lean if re-red = SPT_HOME isolation + bounded hub clears). 2 new backlog seeds registered (PUMP_PEER_FAIL unstamped; harness count-seams→stderr-scrape upgrade); STALL_EVICT describe() polish ruled backlog. Stack + triage branches DELETED local+remote; gate worktree removed. REMAINING: deployah cuts v0.31.0 (counter from published metadata, last=57; RESTART-REQUIRED apply; CHANGELOG field-symptom census in GO msg) → doyle verifies publish → field-verify (flynn autostart, perri stamps + adapter export >0.20.0). Operator note: HFENDULEAM live daemon runs echo-verify force-on until v0.31.0 apply restart.

**MERGE STATE 2026-07-11 (historical): ALL W1-W5 MERGED — #82 W4 @ffb031d + #83 W5 @706ad88 landed** (CI green both platforms: W4 run 29135494564, W5 run 29135532403, all jobs success incl. traceability + n1-gate; job conclusions verified via jobs listing not watch exit). Branches kept until W6 lands, then delete whole stack's branches. **W6 IN PROGRESS (todlando):** branch build/msg-identity-w6-f039 @8951793, 4 commits — REQ moves 4e0916c (DIAL-SCOPE addendum + POISON-ATTRIBUTION + BLACKHOLE-LIFECYCLE-HARNESS mints), legs a-d fc048bb (token split POISONED/CONN_WRITE_RETIRED w/ attribution parity, monotonic conn ids, wall+monotonic stamps, unconditional bounded lifecycle events; net_worker_starve → serialized quiet-box class, 300ms bound untouched), brain_decouple fix 8951793 (break>=1, assert accepts {1,2}, >=3 fails — tally-race root of evicts_seen=0 flake). ACK'd consistent w/ LOCK + amendments 1-3. OWED: leg (e) five-invariant harness (test engineer building) + full isolated-worktree workspace suite → gate-ready ping → doyle read-gate vs LOCK, full CI, retarget→main, merge. todlando go-ahead SENT; perri carry DELIVERED (class split + OWL_SESSION_ID unexported rider — no action owed). Then deployah ping for v0.31.0.

**STACK STATE 2026-07-11 (re-gate cycle, superseded by MERGE STATE):** stack #80@53b1d59 ← #81@17dc68e ← #82@a632e2b ← #83@c9ca08f(W5 NEW, shape (a) exact: run --save after-success + boot replay + fresh-sid int). ALL FOUR read-gate PASS. CI: W4 GREEN both platforms; W2 Windows-only red = spt-store registry concurrent_registration_never_locks (timing class, OUTSIDE W2 blast radius, 3 stacked runs contending) → rerun-failed when queue clears; W3+W5 CI queued. MERGE PLAN: green → merge 80, 81; #82 HOLDS for leg-(b) echo-scrub commit (todlando notified), restack 83, merge 82 then 83. W6 RCA GO'd (expanded scope incl hertz attribution work). todlando disclosures (flood-wedge flake, WIP-red-repaired) accepted.

**GATE STATE 2026-07-10 (HISTORICAL — superseded by stack state) (doyle, W1-W3 reviewed via 3 parallel read-only agents — tree was todlando's moving checkout, hands off):** W1 #79 **✅ MERGED @2ea0ac0** (CI green after flake-rerun; W1 branch KEPT — #80 stacks on it, delete after stack unwinds; substitution seam verified SAFE — [env] inject path disjoint from command_for scrub). W2 #80 **REWORK**: blocking = seed-restore on StaleSeed/EmptySession re-arms dead-pid seed (pid-recycle vector; ruled SPEND-on-stale/RESTORE-on-recoverable + unit); required = sid-path custody-squat test + bearer-string doc qualification. W3 #81 **REWORK**: blocking = signoff-suffix pending reaped by sweep_stale_signoff (ruled: preserve into commune-suffix pending + test); riders = project-tier suppress unit, KH note on forever-pending. Verdicts in PR comments; todlando pinged (QUEUED — mid-W4). New seed registered in backlog: write_resume_commune direct-route project-slice loss (same F-032 class, out of W3 scope). PR #79 brain_decouple Windows flake (poison-beats-evict, 2nd occurrence) rerunning — W6 rider validated as needed.

**STATUS: TRIAGE MERGED @17b770a 2026-07-10 (PR #78)** — registry + docs/MSG-IDENTITY-DISPATCH.md; todlando dispatched + merge-notified (build waves off main@17b770a), deployah heads-up (SENT). Worktree removed.

**CI LESSON (PR #78, 3 runs to green):** `net_worker_starve` canaries (dead_peer/unreachable dial_burst_vs_net_runtime_canary, 300ms scheduling bound) hover AT bound under full-parallel nextest on shared runners — kitsubito red 2× (387/311ms) incl. once with NO concurrent job, then GREEN on idle box; hfenduleam unreachable-leg hit 2164ms under concurrent n1-gate. Discriminator that settled it: ssh kitsubito — load 15-min avg 12.79 DURING runs vs 0.08 idle, resident daemon ZERO poison/PUMP_PEER_FAIL churn → load-marginal canary, NOT live seam. Also `brain_decouple` stall-evict int flaked once poison-first (evicts_seen=0) — poison-beats-evict IS field-accepted v0.30.6 behavior; test expectation may need widening. BOTH folded as W6 riders (todlando notified). Main@d73e19e CI red = same contention class (hfenduleam during field-acceptance rig), different tests.

**Waves** (full detail docs/MSG-IDENTITY-DISPATCH.md):
- W1 F-036 legs a+c: REQ-HAZARD-DAEMON-IDENTITY-ENV-SANITIZE (+ leg-b recursion_guard_env schema-doc fold, manifest.rs:314 + schema.json:306) + REQ-BIND-PSYCHE-CUSTODY-SQUAT-GUARD. perri field-verify.
- W2 F-034 a/b/c (REQs registered @5555648): hint form / seed consume-after-bind / sid fallback. hertz+perri verify.
- W3 F-032 REQ-HAZARD-COMMUNE-INGEST-BLACKHOLE (@6767a4d).
- W4 dup-delivery: buildable legs COMMITTED @eb8a8c2 (F-033 inject exclusion + send-stamp b2 SPT_ENDPOINT_ID). **CARRIER RCA LOCKED + RULED 2026-07-10** (full ruling = .claude/doyle-to-todlando.md, verified in code by doyle): only claim_idle_edge_inner (spt-store spool.rs:616) is a real BEGIN IMMEDIATE claim; hook-poll:543/relay-backlog:480/worker-poll = autocommit SELECT-then-UPDATE → WAL race double-deliver; release_at:662 never clears taken_* → stale-stamp misattribution (field row 156). RULED: (i) shared BEGIN IMMEDIATE claim helper all 4 legs [REQ-CARRIER-CLAIM-EXCLUSIVE], (ii) release_at clears taken_*, (iii) REQ-RELAY-NO-BUSY-DELIVER REDUCED to ordering assertion under claim, (iv) rewrite false guard comment spool.rs:580-583. Evidence: concurrent-take unit + release-clears unit + busy-agent int rig; F-023/IDLE-PARKED predicates unchanged. perri rider queued: OWL_SESSION_ID unexported in shells.
- W5 F-038 REQ-ENDPOINT-AUTOSTART — **shape (a) RULED: `endpoint run --save` + daemon-start replay** (shape c rejected: couples to effective_rest_state/F-035 neighborhood). Impl in progress on build/msg-identity-w5-f038 (daemon.json startup_endpoints + boot replay), tests+doc next. Rider REQ-DAEMON-SERVICE-INSTALL stays QUEUED. flynn verify.
- **W1 census widening RULED 2026-07-10:** custody_squatter guard wired bind-only (startup.rs:280); dead-owner re-pin (auth.rs:124, custody-BLIND) + boundary rotate (reporting.rs cmd_boundary) still pinnable → WIDEN both seams, additive same predicate, unit each, rider on W2 #80 rework push.
- **Build order ruled:** W4 carrier legs → W2 rework(+widening rider) → W3 rework; doyle re-gates + merges bottom-up 79✓→80→81→82, then W5/W6.
- **W4 #82 GATE = REWORK 2026-07-10 (PR comment authoritative):** carrier-claim @4b29512 CLEAN (read-gate pass, all ruled shapes exact, int substitution accepted); regression pinned to @eb8a8c2 F-033 inject-exclusion leg — 3 inject-seam tests red BOTH CI platforms (idle_edge_drain_e2e spool_while_active, boundary_ready_strand_e2e restamp, wan no_binary_spools_not_pty; W3 tip green) — predicate over-broad, hits spt-hosted/ready seams not just live_agent. todlando told: fix predicate or intent-retag w/ justification, FULL workspace suite before gate-ready (declared ready off spt-store-only suites = shared-seam violation, called out).
- **F-033 RE-RULED 2026-07-10 (todlando counter ACCEPTED, doyle ground-checked):** state:live_agent exclusion premise FALSIFIED — conflates hosting modes. spt-hosted/CONTROLLED live agents (doyle himself): inject leg IS the delivery reader; harness-hosted (api listen): controllable=Some(false), no broker PTY, structurally never inject targets (startup.rs:694 stamps-by-hosting-mode, livehost.rs:2125 unit). RULED: revert exclusion (predicate back to controllable-gated); dup mechanism closed by carrier-claim; REQ-LIVE-AGENT-NO-INJECT-DELIVERY RE-SCOPED in place (leg a: [unit] harness-hosted-never-inject, tag existing evidence; leg b: report-before-fix — pin typed-unsubmitted garbage origin, verify raw payload+CR path dead per v0.14.3; stages [] until b reports); registry text must record the class split (perri's adapter-channels-only model wrong for CONTROLLED class — doyle carries that to perri post-merge). todlando @21928cb unpushed, full-suite-then-ping standard adopted.
- **F-033 leg(b) VERIFIED + RULED 2026-07-10:** raw payload+CR path PROVABLY DEAD (broker.rs dispatch_endpoint_input ~:3582 — no-binary → spool loud, v0.14.3 LAW holds). Typed-garbage origin PINNED: SPT_INJECT_VERIFY_ECHO ambient-env force-enables Layer-2 echo-verify host-wide (broker.rs:2164-2177, default OFF/adapter-declared); false miss on busy TUI → RE-DRIVE retypes payload = operator's typed-unsubmitted garbage (composes w/ pre-claim dup). RULED: scrub-at-entry — fold SPT_INJECT_VERIFY_ECHO + SPT_INJECT_FORCE_ECHO_MISS into W1 daemon-startup env-scrub; manifest capability = only production on-switch; CONDITION: grep+sweep echo rigs to pass knob explicitly. REQ stages [impl,unit]; registry title rewrite (hosting split + raw-dead + echo root). Rides W4 branch. THIS explains why gate discipline always needed 'unset SPT_INJECT_VERIFY_ECHO'. Live daemon keeps knob till restart (v0.31.0 apply). hertz FYI'd (non-default inject timing/logs + freeze-correlation lead).
- **GATE GOTCHA (new):** `gh run watch --exit-status` returned exit 0 on a FAILED run — never trust watch exit; verify `gh run view --json jobs` conclusions. Also: piping gate cmds to `tail` eats exit codes — capture PIPESTATUS[0]. NOTE: todlando's batch claimed "no rework pending" = STALE (pre-verdict $OWL-lost content); REWORK verdicts stand, todlando pointed at PR comments.
- **hertz PTY-freeze RCA DELIVERED+ACCEPTED 2026-07-10** (.claude/hertz-pty-freeze-rca.md): historical v0.30.4 SharedSend non-draining-resume wedge pinned (fixed 30.5/30.6); residual v0.30.6 freeze NOT pinnable without timestamped incident (peer-dial + echo roots FALSIFIED; two per-session indefinite paths = discriminators: rc.rs:1948 stdout flush, broker.rs:1706→pty.rs:235 PTY-input writer). RULED: attribution instrumentation + wall-clock log stamps + per-conn lifecycle events + black-holed-controller harness → FOLDED INTO W6 (todlando builds, REQ mints on W6 branch: extend CONN-POISON-DIAL-SCOPE + mint REQ-CONN-POISON-ATTRIBUTION); NO timeout changes/log suppression as freeze fix; hertz owns incident-correlation pass when operator supplies timestamps, standing by.
- **W6 RCA LOCKED 2026-07-11 (todlando census accepted, doyle cite-verified):** QUIC dial ruled out (iroh, never BrokerConn); per-failed-dial carrier writes = presence DIAL_FAILED push (nethost.rs:373, result discarded) + NetDialSubmitted ack (broker.rs:3894, discarded), both shared long-lived carriers. Token collision: poison_and_cancel 4 callers — 282/291/381 deadline (timed_out latched) vs 431 organic fast-fail (never latched) — SAME loud token; once-per-conn latch ⇒ observed '1:1 churn' = fresh-carrier churn OR stderrlog interleave artifact (no per-line timestamps, no conn id anywhere) — undecidable until attribution lands. Retire path benign (no wedge). SHAPE LOCKED: (a) token split POISONED=timed_out-only / CONN_WRITE_RETIRED=organic w/ SAME attribution fields (amendment 1); (b) stable monotonic conn id + role/endpoint/session on all lifecycle records; (c) stderrlog per-line wall-clock+monotonic; (d) UNCONDITIONAL bounded lifecycle events; (e) hertz harness = own REQ. Mints: extend CONN-POISON-DIAL-SCOPE + mint REQ-CONN-POISON-ATTRIBUTION + REQ-CONN-BLACKHOLE-LIFECYCLE-HARNESS, W6 branch first commit off W5 tip. Canary rider lean: SERIALIZE rig over bound-loosening (amendment 2). No timeout changes, no suppression.
- W6 F-039 REQ-CONN-POISON-DIAL-SCOPE — **RCA-first** (LOCKED above, historical): CONN_WRITE_POISONED churn 1:1 w/ PUMP_PEER_FAIL offline-peer dials; conn.rs:181 poison_and_cancel logs same loud token for timeout AND fast-fail; pin WHICH broker write fails per dial cycle before scoping loudness. Poison/retire behavior unchanged.

**DELIVERY-FAULT RCA 2026-07-10 (todlando→doyle silence):** todlando's doyle-bound replies used legacy `$OWL send` (owl.exe → legacy home spool) — invisible to spt-core, reported success. RESOLVED: all inter-agent traffic from migrated agents = `spt send` only; retire `$OWL` habit. Diagnostic recipe that worked: self-ping (perch path OK) → target spool.db dump via python/sqlite (zero rows from sender = send-side) → daemon log (no NO_PERCH) → process sweep (no leaked dev daemons) → asymmetry pins client side. LIVE F-033 field repro: hook-shell sends stamp `from=cli@HFENDULEAM` not agent id (doyle spool 186, todlando spool 93-96) — evidence for W4 stamp leg @eb8a8c2. W4 buildable legs COMMITTED @eb8a8c2 (inject exclusion + send-stamp); tree carries W5 autostart delta (config.rs/daemon.rs).

**Discipline:** REQ stages all QUEUED [] on the triage PR — todlando flips per wave IN the build commit with evidence tags ([[traceable-per-wave-activation]]; activating in triage = check exit-1 = red CI, verified). RCA locks (W4/W6) return to doyle for fix-shape ruling BEFORE build. Release: deployah, one cut at end, target v0.31.0 (new verb = minor); CHANGELOG census = field symptoms across all six waves.

Kin: [[spt-core-findings-backlog]], [[v0306-published]] (the PASS handoff that seeded F-038/F-039), [[gateway-liveness-and-f035-progress]].
