---
name: next-batch-register-v0461
description: "The fast-follow v0.46.1 candidate pool — 11 items + instrument notes, banked in durable memory because the scratchpad copy dies with the session"
metadata: 
  node_type: memory
  type: project
  originSessionId: f15d7520-3b76-4e8f-93f3-056a2fdc746c
  modified: 2026-07-30T02:54:50.456Z
---

**doyle named this "the fast-follow's candidate pool" (2026-07-30). The working copy lives in a SESSION scratchpad
which does NOT survive a reset — that is exactly the defect that cost us twice tonight
([[commune-is-testimony-not-an-artifact]]), so the authoritative copy is here.**

⚠ **GROUP A IS RECONSTRUCTED FROM COMMUNE TEXT AND UNVERIFIED.** doyle ruled it stays marked and that **nothing in
it reaches the grill without being re-derived from source first.** Do not strip the marking. Prefer dropping an
item to promoting it on a commune's word.
⚠ **Nobody builds and nobody proposes until the operator's fast-follow grill sets scope.** This is a bank, not a plan.

## Group A — reconstructed, UNVERIFIED, re-derive before proposing
1. **`census.sh` → `.github/ci/`** — rationale not recoverable; re-derive.
2. **nextest `success-output`** — `.config/nextest.toml@8f3e10b` sets none, so the default `never` discards a passing
   test's stdout. Measured consequence: `worker_lifecycle_e2e` passed (`PASS [4.618s] (79/2170)`) yet
   `grep -c WORKER_E2E` on the 432,517-byte log = 0. One-line setting. ⚠ I once called that output "inherently
   unreachable on every green" — false, corrected by hertz and doyle.
3. **`/tmp` exposure test** — distinguish commands that fail LOUD under a temp-dir outage (plain `>`) from those
   that exit 0 having written nothing (`sed -i`, `mktemp`, staging paths).
4. **CHANGELOG voice pass** — scope not recoverable; re-derive against the release-notes standard.

## Group B — tonight, well-sourced
5. **The bye rung burns ~900s of dead CI wall per golden run, BY CONSTRUCTION.** twohost-b step 10 = 122.65s of real
   work (all rungs `GATED OK` by 01:28:40.8Z) + 900.3s = exactly one `rig.wait`. ⭐ doyle's sizing: A's dismissal is
   `let _ = store.dismiss(...)` (return DISCARDED) then `sleep(3s)` then A's daemon dies — so B waits up to 900s for
   a flush A allows 3 seconds. **The tolerated timeout is the EXPECTED path, every run.** Fix: bound B's hold to A's
   flush, or give A's dismissal a confirmed ship before teardown.
6. **The bye timeout LINE misdescribes what it tolerates.** It prints `(tolerated: A asserts delivery on its side)`,
   which reads as the hazard shape — **three of us misread it identically before anyone opened the source.** What is
   actually unobserved is A's `dismissed=true` latch replicating back to B. Print the unobserved event.
7. ~~contract read behind the unclassified asymmetry~~ — **DISCHARGED.** doyle read it (929 lines, 5 `SIG_BYE`,
   10 case-insensitive `bye`, counted): `rig_wait` PANICS on timeout, so A's assert is hard. **No fourth
   proposition, no defect, guard count stays THREE.**
8. **`MANIFEST_DEAD_KEY:gatedresume`** — b @01:26:38.469Z, non-fatal: `[session.psyche_init]` references
   `{psyche_dir}`, not a fillable key; role retired, never spawned. **Provenance vs this batch UNCHECKED.**
9. **PSYCHE COMMUNE-INGEST FAILS CLOSED AND QUIET** — the biggest of these. Four parts.
   ⚖ **9(e) IS CLOSED-MECHANISM / OPEN-FIX** (doyle ruled from source 2026-07-30 ~02:45Z, re-measured by me).
   **Answer is (ii): the watch is PER-ENDPOINT, resolved against the endpoint's own recorded `info.cwd`.** See the
   dated measurement section at the bottom of this file for the verified source chain and the new findings that
   came out of checking it. **Fix shape is the grill's; nobody builds it.**
   - **(a)** Surface it on the commune path with explicit **last-success** and **failed-at** timestamps.
     Memory-index freshness is **NOT** a proxy: memory is ordinary file writes (no daemon, no bound), ingest is a
     bounded daemon spawn. Treat them as independent health propositions.
   - **(b)** The 30s `echo-commune` bound may be load-sensitive — **hypothesis with a mechanism, not a diagnosis.**
     deployah's failed at 02:05:14Z under release load. Discriminating test: same bounded spawn on an idle box.
     ⚠ deployah **withdrew** his "recovered without intervention" claim — absence of the annotation at 02:13Z is
     equally consistent with *no further spawn was attempted*. What survives: 3 spawns killed at 30s under load,
     and **no evidence of a successful ingest at any point, by anyone.**
   - **(c)** STANDING: every agent runs `spt endpoint list` and reads its **own** SELF line — nobody can do it for
     anybody else.
   - **(d)** ⭐⭐ **THERE IS NO SUCCESS SURFACE AT ALL.** `spt --help | grep -icE 'psyche|commune|echo-commune'` = **0**
     (my run 02:17Z); `endpoint list --detail` adds only the endpoint description; `psyche-host` appears zero times
     on peers across 14 endpoints. **The only observable is a FAILURE annotation ⇒ "healthy", "never attempted" and
     "silently not ingesting" are the same reading.** chert and I both claimed health off a clean line and neither
     was entitled to — I had written no commune this session, so my path was never invoked.
   - **(e)** ⚠ **PHYSICAL ARTIFACT: `.claude/flynn-commune.md`, 307 bytes, mtime 2026-07-09 21:25 PDT, unconsumed
     20 days, while `flynn` reads ONLINE.** (Also `rc-exit-probe-commune.md`, 2026-07-19.) Two candidates, not
     chosen between: (i) ingest silently never consumed it; (ii) **flynn's project is `spt-progress-tool/` and the
     file sits in `spt-core`'s `.claude/`** — a commune in the wrong project dir may never be watched.
     ⭐ **THREE MEASUREMENTS NOW FAVOUR (ii):**
     ```
     chert    commune, MATCHING project dir -> consumed 5.2s (02:20:36.540 present -> 02:20:41.843 absent)
     todlando commune, MATCHING project dir -> consumed <~3s (ABSENT at first poll, 02:41:38.617Z)
     flynn    commune, NON-MATCHING dir     -> unconsumed 20 days, endpoint ONLINE
     ```
     **A daemon consuming matching-dir communes within seconds while a non-matching-dir file sits 20 days is the
     signature of a file nobody is watching, not of a broken ingest.**
     ⚠ NOT closed — three observations; the clean test is one source read, **is the watch per-project or global?**
     Unrun. Do not upgrade to settled.
     ⚠ **If (ii) holds it is WORSE for the author:** a commune in the wrong directory produces **no failure
     annotation at all**, because nothing was ever attempted to fail. deployah at least got a FAILED line.
     ⚖ Consumption speed is the best available signal and still not proof of ingest — there is no success surface
     (9d). Per chert's practice: **write the commune, then stat it within ~10s; put the substance in the memory
     index first so a silent ingest failure costs the pointer, not the payload.**
10. ~~`AccessModel.cfg` state-count comment~~ — **STRUCK**, doyle allowed chert's one-commit fix (437,678 generated /
    123,842 distinct) with the command + both blob hashes in the body. ⚠ **KEPT AND OPEN: `InvUniqueTierMatch` is
    killed by NO variant ⇒ zero fidelity pin.**
11. **RUNBOOK: release state is queried against `spt-bs-releases`; a bare `gh release` query from the code worktree
    is silently wrong** (infers `spt-bs-core`, which has never held a release → empty at **exit 0**, before and
    after a publish alike). Discriminating command: `gh api repos/BigscreenVR/spt-bs-releases/releases/latest`.
    Ruled into the runbook by doyle. See [[verdict-from-probe-competence]].

12b. ⚠⚠ **ATTRIBUTION IS BROKEN ON MAIN AT SCALE — 10 LANDED COMMITS INCLUDING THE v0.46.0 TIP.** deployah found it
    on main after I found one in the unpushed set; I reproduced his census independently.
    **POPULATION: last 40 commits on main, tip `8f3e10b`, subject exit guarded → anchored 26 · embedded-literal-`\n`
    10 · genuinely absent 4 = 40.** **All ten embedded name `hertz`; none name anyone else.**
    The ten shas: `8f3e10b` `672d706` `dfdcab2` `0443613` `6bf2bd9` `c73a31f` `6a31386` `a5b379b` `b1801ea`
    `54140ee`. ⚠ **`8f3e10b` is the released tip** — the commit shipped as v0.46.0 carries an attribution its own
    informant cannot read (`grep -c '^Co-authored by:'` = 0, `grep -cF` = 1).
    **hertz's THREE-WAY SEPARATION governs — do not collapse these:**
    **(a)** the commit-message construction path emits **literal backslash-n** so the trailer lands mid-line;
    ⚖ **BOUNDARY RULED 2026-07-30 (hertz's differential, doyle banked it; deployah's stdin-vs-argv framing is
    RETIRED, not amended).** Three commits, one git binary/config, scratch repos, no shared checkout touched:
    `-m` with REAL newline bytes → anchored ✓ · `-m` with literal `\n` → anchored ✗ · `-F -` stdin → anchored ✓.
    ⇒ **"message-via-argument" is NOT the discriminator — git preserves real newlines in argv.** The causal
    boundary is **upstream serialization**: whatever builds the message before git is invoked. **Fix the
    serializer, never the invocation style** — "move everyone to heredoc" leaves the defect live for any other
    argv caller. ⭐⭐ doyle's shape note: three GOOD paths all happened to use stdin, so the correlation was
    **perfect across every observation available and the causal claim was still wrong**; only a deliberately
    CONSTRUCTED case nobody had seen in the wild separated them. **A perfect correlation is not a mechanism.**
    **Outcome contract for the grill:** (a) fix the construction path per hertz's boundary · (b) LOUD
    absent-vs-unparseable discrimination (`ci-notify.sh@8f3e10b:138` silences both) · (c) do NOT merely un-anchor
    the sed · (d) git's tokenizer blindness stays an AUDIT limitation, not automatically a shipped defect ·
    (e) history stays IMMUTABLE.
    **(b)** the shipped parser silently accepts absence/unparseability (`ci-notify.sh@8f3e10b:143` `^`-anchored sed,
    L138 *"Absent or unparseable => skipped, never an error"*);
    **(c)** git's OWN trailer parser cannot read the project's space-spelled key — **an audit limitation, not
    automatically a shipped-path defect.**
    ⭐⭐ **(c) verified by me WITH A CONTROL, and it is worse than a non-matching key:** on `b4d5653`, which has a
    correctly anchored space-spelled trailer (`grep -c '^Co-authored by:'` = 1), both
    `--format='%(trailers:key=Co-authored by,valueonly)'` **and** the unfiltered `--format='%(trailers)'` return
    **empty** — git does not see it as a trailer AT ALL. **CONTROL: `766595d`** carries a git-standard
    `Co-Authored-By: OpenAI Codex <noreply@openai.com>` and `%(trailers)` returns it, proving the machinery works in
    this repo. ⇒ **The failure is at the tokenizer, not the filter, so any native-git attribution audit returns a
    confident zero on all 36 anchored commits too.** Anchored literal-text search is the only working probe.
    **Outcome contract:** construction-path fix **plus** LOUD discrimination on a malformed trailer.
    ⚠ **Do NOT merely un-anchor the sed** — prose mentioning the phrase expands the population.
    ⚠ **Historical commits stay immutable; any attribution repair is out-of-band, never a history rewrite.**
    deployah's `c651175` → **`6777f59`**, tree byte-identical, parser-verified, still unpushed under doyle's hold.

12. **`ci-notify.sh`'s LOUD-on-unparseable-trailer fix is NOT SHIPPED, and the defect is still being produced.**
    Measured at `8f3e10b` (shipped main): `.github/ci/ci-notify.sh` L142-145 extracts with
    `sed -n 's/^Co-authored by:...//Ip'` — **`^`-anchored** — and L138 states the behaviour in words:
    *"Absent or unparseable => skipped, **never an error**."* So hertz's F2 fix-forward has not landed; a
    malformed trailer is silently skipped and notifications go to doyle only.
    ⚠ **Live instance, unpushed: `c651175`** (deployah's `docs/release-runbook-main-advance`). Its body ends
    `...before signing.\n\nCo-authored by: hertz` where `\n` is **two literal characters**, so the trailer sits
    mid-line and `grep -c '^Co-authored by:'` = **0**. Identical to #124's defect.
    ⭐ **Two commits, same authoring path, same literal-`\n` body ⇒ a mechanism repeating, not a slip** — which is
    the argument for the LOUD lane over treating it as a trailer nit.
    ⚖ **The fix window is free only while unpushed.** #124 could not be reminted without breaking
    tested==assembled; `c651175` has never been pushed, tested, or assembled, so amending costs nothing **until
    first push**. deployah's and doyle's call, not mine.

13. **Attribution in this shared checkout requires the TRAILER, never `%an`.** All 32 unpushed commits read author
    `Reavo End` — one shared git identity, so author name yields a clean, uniform, useless answer.
    **Population: commits on local branches not on any remote, this checkout, subject-command exit guarded = 32.**
    Split (hertz made me separate these rather than treat one bucket as a class):
    **24 anchored/parseable (16 todlando · 8 doyle) · 1 EMBEDDED-malformed (`c651175`) · 7 genuinely absent.**
    An earlier version of this entry said "7 with no line-anchored trailer", conflating the malformed one with the
    absent ones — corrected.
    ⚖ **Check, never answer from memory:** I stated "nothing unpushed" while holding 16. deployah nearly told doyle
    "nothing pending" during a push freeze while holding `c651175`.
    ⚠⚠ **BUT THE OBVIOUS CORRECTIVE IS WRONG, and hertz caught it on me the same turn I banked it.** "Print the
    COUNT, not the interpretation — a count cannot disagree with itself" is FALSE twice over:
    **(a) a pipeline masks upstream failure into zero** — my own `n=$(git log … 2>/dev/null | wc -l)` would have
    printed `n=0` on a git failure, i.e. the corrective for "don't claim nothing-unpushed from memory" would have
    manufactured that exact false claim; **(b) a perfect count can quantify the wrong population** (deployah's
    file-wide `TRUST` grep, my unanchored `proc\.rs`, doyle's wrong-repo release list).
    ✅ **Correct form: capture and GUARD the subject command's exit BEFORE counting, then name the predicate and
    the population alongside the number.** A count is only as good as the exit that produced it and the population
    it ranged over. This is [[verdict-from-exit-not-from-silence]] and
    [[a-predicate-without-its-tool-is-not-evidence]] meeting in one line.
    chert's prose form of the same family: **a label placed by the author encodes the EXPECTED result, so it
    survives exactly the case it exists to catch.**

## Also banked for the grill (not register items)
**Admin-seed rotation is OFF PREP-ONLY** — operator authorized it into the fast-follow. Eviction rotates only the
member seed (`SubnetStore::rotate_seed`), so **an evicted node keeps the admin seed forever, and an admin key IS a
membership key (`REQ-SUBNET-ADMIN-CODE-JOIN`), so it can rejoin.** Wire/security change ⇒ **its own gate, never
rides another diff.** Legs specced: rotate both seeds with one epoch bump; redistribute over `add_joined`/
`adopt_rotation`; one-deep grace stays member-seed-only (`prev_seed_bytes`); ADR-0051 doc stage; units for
"rotated subnet's admin seed changes" and "pre-rotation holder neither verifies an admin op nor rejoins."
Check overlap with `REQ-HAZARD-PAIR-SEED-ROTATION` and the revoke/coalescing-window REQ.

## Instrument notes (not work items)
- **`grep -i -F` core-dumps under grep 3.0** on the twohost job logs (b: 148,821 bytes, sha256 `712b3495…`;
  a: 143,452). Emits no count — **failure to measure, never a zero.** Read regions verbatim with awk.
- **`tasklist /v | grep -icE '^(rustc|cargo)\.exe'` returns a clean WRONG zero on hfenduleam** — the `/v` format
  defeats the anchored match. Plain `tasklist` and `Get-Process` both returned 1.
- **A process count during a release build is a SAMPLE of a churning population** — chert measured 11 → 1 in 16s.
  Primary quiet predicate is **"no non-terminal CI run"** (a state); attribute survivors by walking parent chains
  **within one snapshot**, never re-querying by name between count and walk.
- **kitsubito FOREIGN `spt`** pid 1358109, `/home/reavus/.local/bin/spt` — user-installed, not a leak, not to be
  killed.

## ⚖ MEASURED 2026-07-30 ~02:47Z (todlando) — 9(e) closed, and THREE new findings out of checking it

**doyle's source chain, re-measured by me at `8f3e10b` — holds, including the step he did not quote:**
- `crates/spt/src/api/reporting.rs:686-698` `resolve_filedrops` = `PathBuf::from(dir).join("<id>-commune.md")` from
  the manifest's `[session] commune_dir`, which for claude-spt is the **relative** string `".claude"` — no base.
- `crates/spt-daemon/src/lifecycle.rs` `fire_echo` (~L859-866): `resolve_perch_path` → `read_info().cwd` →
  `resolve_endpoint_drop_dir(raw, endpoint_cwd)`; **the only loud path is `warn_echo_no_cwd_once`.**
- ⭐ **The load-bearing body doyle asserted but did not quote — I read it, `lifecycle.rs:212`:**
  `if raw.is_absolute() { as-is } else { endpoint_cwd.map(|cwd| cwd.join(raw)) }`. So relative + a cwd → a
  perfectly valid path under THAT endpoint's cwd; relative + NO cwd → `None` → the single warn. **Confirms (ii)
  by construction:** a commune in another project's `.claude/` yields a valid unwatched path and no attempt, so
  there is nothing to fail and nothing to annotate.
- ⭐⭐ **Its own doc comment records a PRIOR PAID instance of this exact class:** *"NEVER falls back to the daemon's
  own process cwd, the pre-fix bug that read a directory the endpoint never drops into so the two-tier store
  stayed pristine."* Same defect, other base. Relevant to the grill's fix shape; **not a proposal.**
  ⚠ Two `fn resolve_endpoint_drop_dir` matches (L212, L1977); second is presumably a test fn name prefix-match,
  **unverified** — I did not open it. ⚖ **CLOSED by doyle:** L1977 = `fn resolve_endpoint_drop_dir_cases()`, unit,
  `[unit->REQ-STORE-CONTEXT-BRANCH-FILL]`, pins all three arms incl. `None`.
  ⭐⭐ **AND THE POPULATION WAS BIGGER THAN ANY OF US SAMPLED: three real CALL SITES (L634, L862, L1169) + def +
  test = FIVE matches, and doyle, chert and I had each read a different subset of TWO.** The ruling holds at every
  site, so nobody was wrong — but **three independent "confirmed, same three sites" were three confirmations of an
  incomplete list. Agreement among readers who each sampled is not coverage.** Sibling to
  [[absence-needs-sibling-probe]]; this is the version where the instrument was fine and the ENUMERATION was short.

**F-A ⚠⚠ MY OWN psyche-host IS `FAILED` RIGHT NOW, and my banked "Mine was clean throughout" is FALSE as a
statement about the present.** Verbatim off my own SELF line, `spt endpoint list` exit 0:
`psyche-host: FAILED (psyche per-event turn failed 3x consecutively: commune-sync: echo-commune exited Some(1):
ECHO_COMMUNE_FAIL:todlando: claude exited exit code: 1:; 1 attempt; 2026-07-30T02:43:45Z)`
⭐ **DIFFERENT FAILURE MODE FROM deployah's** — his was *killed at the 30s bound* under release load; mine is
`claude exited exit code: 1`, a child that ran and failed. **So 9(b)'s load-sensitive-bound hypothesis does not
cover mine; there are at least TWO failure modes, do not merge them.** (The line also reads "failed 3x
consecutively" and "1 attempt" together — quoted as-is, not reconciled.)

**F-B ⭐⭐ A SUCCESS SURFACE DOES EXIST — on the READ side, and it contradicts 9(d) as stated.** Every ingested
block in my session brief carries a provenance HTML comment:
`spt:source=llm spt:routed_at_ms=1785379290248 spt:node=… spt:vector=…`. Decoded (one command):
**`routed_at_ms` 1785379290248 = 2026-07-30T02:41:30.248Z**, brief file stamp 1785379396909 = 02:43:16.909Z,
FAILED annotation 02:43:45Z. ⇒ **content WAS routed at 02:41:30Z and the FAILED annotation is a strictly LATER,
separate attempt.** This is the only observation all night that separates *"an ingest happened"* from *"nothing was
ever attempted"* — the exact conflation 9(d) says has no observable.
⚠ **Do NOT overclaim it:** (1) it proves *routing* of that content at that instant; **whether `routed` ==
`ingest completed` is a source question I have NOT read**; (2) it is visible only to the author, only in its own
post-reset brief ⇒ **post-hoc and per-author, NOT queryable health**; so it does **not** satisfy 9(a). What it does
prove is that **the timestamp already exists in the data** — 9(a) may be a surfacing job, not a plumbing job.

**F-C flynn exposure confirmed FROM THE ROSTER, and `rc-exit-probe` is a DIFFERENT CASE — separate them.**
Population, `spt-core/.claude/`, guarded, exit 0: **2 commune drops, 0 signoff drops.**
```
flynn-commune.md          307 B  mtime 2026-07-09 21:25:06 local   roster: flynn spt-progress-tool/ ONLINE  -> NON-MATCHING dir, live 20-day loss
rc-exit-probe-commune.md  859 B  mtime 2026-07-19 02:56:17 local   roster: ABSENT from all 14 endpoints    -> ORPHAN of a retired/never-registered endpoint, NOT live loss
```
⚠ The register listed these two together; **only flynn is a live data-loss case.**
✅ **flynn NOTIFIED 2026-07-30 ~02:55Z, `SENT` live** (doyle released it — **the push hold is on PUSHES, not
comms**; my read of that was right and I asked rather than assumed). Told as measured, including the two things
we do NOT know: his actual `info.cwd`, and therefore where the file should have gone. **Nothing owed on this.**
⚠ **My signoff commune was consumed before I could amend it and it carries a STALE "flynn unsent" line** — the
file-ingest leg is fast (consumed within seconds, third such observation) and **a commune is immutable the moment
you write it.** If a future me reads "someone should carry the flynn message": **it is already sent, this line is
the correction.** New face of [[commune-is-testimony-not-an-artifact]]: not a reconstruction problem this time but
a WRITE-ONCE problem — the artifact froze mid-turn while the facts kept moving.
⚠ **INVERSE EXPOSURE IS UNCENSUSED:** a drop of mine (or a peer's) sitting in some OTHER project's `.claude/` is
**not measurable from this dir**. Nobody has counted that direction.

**CORRECTIONS TO THE ABOVE, from chert's independent re-measurement (he confirmed all three sites, separately):**
- ⭐⭐ **F-B's FRAME WAS WRONG — the file-ingest leg and the per-event `echo-commune` SUMMARISER leg are DIFFERENT
  LEGS.** `routed_at_ms` evidences the FILE leg; the FAILED stamp indicts the SUMMARISER spawn. Both observations
  survive; **"a strictly later attempt at the same thing" does not.** chert's file ingest worked (full brief on
  resume) while his summariser was being killed. Also `lifecycle.rs:895-903` **clears the stamp on success** ⇒ a
  present stamp = RECENT failures, not an old scar; and the field is **not** json-only.
- ⭐⭐ **PER-ENDPOINT RESOLUTION IS SHIPPED CONFORMANCE, not incidental behaviour** — `traceable-reqs.toml:1732`
  (F026 SI-1, shipped v0.22.0) documents this exact RCA, KH §7.28 is the class rule, and an int test
  `relative_commune_dir_resolves_against_endpoint_cwd_and_fills_project_branch` pins it RED-first. **A refactor
  cannot quietly move it.** (⇒ this class has now been paid for TWICE: that REQ, plus the daemon-process-cwd
  fallback named in the resolver's own doc comment.)
- ⚠ **TWO PREMISES ARE QUOTED, NOT MEASURED, and I repeated both:** (1) claude-spt's manifest is **not in this
  repo** — the only tracked `commune_dir` literal at 8f3e10b is `adapters/mock/manifest.toml:37 = ".mock"`, so
  `.claude` is corroborated only by REQ **prose**; (2) **`endpoint list --json` carries NO cwd field** (chert:
  `n_cwd_fields=0`), so **flynn's actual `info.cwd` is UNMEASURED by anyone** — the roster's `spt-progress-tool/`
  is a derived LABEL, and the path that label suggests does not even exist on disk. ⇒ **the data-loss claim
  survives (his file sits where spt-core endpoints resolve, and he is not one), but "where it SHOULD have gone"
  is unnamed.** The one field that decides it is exposed by no read verb we can find.
- Figures, to the day: flynn 307 B unconsumed **19d22h** (commonly quoted as "20 days"); rc-exit-probe 859 B
  unconsumed **10d17h** ("ten days", chert's figure, correct).
⚖ **PRACTICE THIS ENFORCES ON ME NOW:** my ingest is failing at this moment, so **the memory index is the only
durable tier** — substance goes here FIRST, the commune second. [[psyche-host-failure-is-self-only]].
⚠ **RUN-STATUS INSTRUMENT NOTE (chert, and it matters for every hold decision):** `gh run view <id> --json status`
returned `queued` with `updatedAt` **frozen at 02:40:38Z** while per-job `changes`/`traceability` were already
`completed success` and **both `test` legs were IN_PROGRESS**. **Poll `--json jobs`, never `--json status`** — the
run-level field is not tracking its jobs, and it produces a stale answer at exit 0. Same species as
[[opt-in-ci-legs-skip-silently]] and the check-(b) blindness window.

Related: [[milestone-a-golden-landed]], [[v0460-published]], [[verdict-from-probe-competence]],
[[absence-needs-sibling-probe]], [[w3-engine-room-progress]], [[psyche-host-failure-is-self-only]],
[[commune-is-testimony-not-an-artifact]].
