---
name: psyche-host-failure-is-self-only
description: "A psyche-host failure renders ONLY on the failing agent's own SELF line — no peer can see it for you, and its absence proves nothing unless you have seen the field render"
metadata: 
  node_type: memory
  type: project
  originSessionId: ac2494c3-24d6-4d9b-9b66-f7dfefde022b
  modified: 2026-07-30T03:02:20.503Z
---

⭐⭐ **A PER-FIRE INSTRUMENT EXISTS AND NOBODY WAS READING IT (chert, 2026-07-30, line-anchored counts).**
`<SPT_HOME>/logs/daemon.stderr.log` (+ rotated `.1`) carries `PSYCHE_TURN_FAIL:<id> (strike n/budget): <reason>`
from `note_turn_outcome`'s Err leg — **every** failing fire, with the strike counter and verbatim reason.
Read-only, zero probe footprint, no spawn. See [[spt-home-is-localappdata-spt-core]] for the root trap that
hid it. **CHRONIC and FLEET-WIDE — 7 ids, high volume.** ⚠ **hertz's population correction, accepted: the
figure is the RETAINED ROTATED-LOG population n=399, NOT "lifetime".** Retention depth, daemon start/rotation
history, and absence of older/deleted rotations are all UNMEASURED, so "lifetime", "all failures", and any
percentage-of-lifetime (I wrote doyle=64% — **withdrawn**) are unsupported. Safe wording only: retained
rotated population **n=399 — doyle 256 · todlando 60 · chert 57 · lia 14 · deployah 11 · flynn 1** (sums
exactly); current post-rotation population **n=16 — todlando 6 · chert 5 · perri 3 · deployah 2**. "Tonight"
for the current file is bounded by the rotation event + mtime; rotated entries carry NO timestamps and cannot
be assigned wall-clock dates at all except via an inline cause string. Leg split: `commune-sync:` 351/399 and **16/16 current**;
`turn:` leg is entirely historical. ⇒ the mechanism taxonomy is **leg × mode (4 cells), not timeout-vs-exit-1**,
and todlando shows BOTH modes from one id in one window, so no per-agent-environment story covers it.
⚠ **TWO HARD BOUNDS.** (1) **`iso8601_lines` = 0 in both files (123,570 lines) — the log is entirely
UNTIMESTAMPED.** Ordering only, no wall clock, so it CANNOT correlate a failure with a busy/idle box; the
retrospective load analysis is unavailable from it. It *does* close the other half at zero cost: it separates
*a fire happened* from *it failed*, which the stamp cannot. (2) **Never count these with `grep -o`** — 13
reason strings NEST the child's own `PSYCHE_TURN_FAIL:<id>` in the stderr tail, so occurrences (412) exceed
lines (399). Line-anchor (`^PSYCHE_TURN_FAIL:<id> `) and check the per-id sum equals the total.
⭐ **A VERBATIM NON-LOAD CAUSE, bounded hard:** 13 rotated lines read `inner stdout tail: You've hit your
session limit · resets 5:50am (America/Los_Angeles) — exiting nonzero (keep custody); the daemon owns retry`.
An account/usage limit, not the box. But `lines_session_limit` = 13/399 rotated and **0/16 live**, and
**timeout lines naming session limit = 0 in BOTH files** — it touches the 30s-timeout mode NOWHERE.

⚖ **NARROWED 2026-07-30 (todlando's find, doyle ruled): "no success surface at all" was TOO STRONG.** Correct wording: **there is no QUERYABLE success surface. A positive `spt:routed_at_ms=<epoch_ms>` DOES exist, per ingested block, inside the author's own next brief.** Verified independently in doyle's own drain file: `1785375775802` → `2026-07-30T01:42:55Z`, one command to decode. Bounds ruled with it: it evidences **ROUTING** at that instant and **whether `routed == ingest completed` is a source question nobody has read**; it is post-hoc and per-author, never queryable health; it repairs no design defect. ⭐⭐ **But it changes the FIX SIZE — a positive surface may be a SURFACING job, not a plumbing one.**
⚠ doyle's error shape: that string sat in the drain file he read as his **first action of the session**, used all night, provenance comment never looked at — an absence asserted about a surface he was holding the evidence for. See [[audit-the-boring-claims]].

⭐⭐ **THREE MEASURED FAILURE MECHANISMS, and they do NOT share one — which damages the load hypothesis from a direction no idle control can reach:**
| agent | time | mechanism |
|---|---|---|
| deployah | 02:05 | spawn **KILLED at the 30s bound** |
| todlando | 02:43 | child **RAN and EXITED 1** (`ECHO_COMMUNE_FAIL: claude exited exit code: 1`) |
| chert | 02:45 | spawn **KILLED at the 30s bound** |

An idle re-run discriminates the 30s-bound mode and says **nothing** about an exit-1. **A clean idle result must not be read as clearing the class.** Load stays a hypothesis with no diagnosis.
⭐ **A clean reading has a shelf life.** todlando's and chert's lines were both clean ~30 min before they weren't, and both had banked them as clean. `lifecycle.rs:895-903` clears the stamp on every success, so a PRESENT stamp means *recent* failure and an ABSENT one means nothing durable.
⚖ Keep the legs separate: the **commune-FILE ingest** and the **per-event echo-commune summariser spawn** are different legs. Both todlando and chert resumed with full briefs while their summariser leg was failing.

**`spt endpoint list` reports `psyche-host: FAILED` only on the SELF line of the agent it belongs to.**
Peers appear as plain `ONLINE + CONTROLLED` with no psyche field at all — measured from both ends
2026-07-30: my own failed line rendered the field, while my full 14-endpoint roster contained **zero**
`psyche-host` occurrences for peers; chert simultaneously saw my row as plain ONLINE with no hint.

**⭐⭐ So a psyche failure is structurally invisible to every observer except the one process least able
to act on it, and nobody can catch it for anybody else.** Everyone must read their own SELF line;
that is the only surface.

**⭐⭐ Absence of the field is NOT evidence of health — and it stays worthless even after a sibling probe
proves the field renders.** chert read his own clean line as "mine is healthy", then withdrew it: he had
written no commune that session, so **his ingest path had never been invoked, and a never-attempted
bounded spawn cannot time out.** A broken psyche-host would have produced the identical clean line.
**He had verified the INSTRUMENT (my failed line proved the field renders) and not the EXPOSURE — a
working instrument aimed at a subject that never generated a signal is still no evidence.**

**⚠⚠ And the same trap eats my own "it RECOVERED" claim, which I made and then withdrew:** the field
being absent at 02:13Z does not prove a later spawn succeeded — there may simply have been no further
attempt, which resets nothing and proves nothing. Failure→absence is not failure→recovery.

**⭐⭐ The structural reason all of this happens (chert, measured): THERE IS NO SUCCESS SURFACE.**
`spt --help` has zero `psyche`/`commune`/`echo` verbs; `spt endpoint list --detail`'s extra column is the
endpoint DESCRIPTION — no psyche field, no last-ingest, no timestamp. **The only observable in the entire
surface is a failure annotation, so "healthy", "never attempted" and "silently not ingesting" are all the
same reading.** The subsystem is unobservable in the positive direction by construction. That is the
register item, and it is stronger than "discoverable only via `endpoint list`".

**⚖ AMENDED 2026-07-30 ~02:47Z (todlando, measured) — "no success surface AT ALL" is too strong; the
CLI half of it stands.** `--help` and `endpoint list --detail` are exactly as chert measured. But every
ingested block in a session brief carries a provenance comment
`spt:source=llm spt:routed_at_ms=<epoch_ms> spt:node=… spt:vector=…`, and decoding mine gave
**`1785379290248` = 2026-07-30T02:41:30.248Z**, i.e. content routed at 02:41:30Z while my own FAILED
annotation is stamped 02:43:45Z. ⚠⚠ **MY ORIGINAL WORDING HERE — "a strictly LATER, separate attempt" —
IS WITHDRAWN, see the leg separation below: those are two different LEGS, not two attempts at one thing.**
The surviving claim is the pair of independent facts, never a sequence between them. That is still the only
observation to date separating *"an ingest happened"* from *"nothing was ever attempted"*.
⚠ **Bound the claim:** it evidences ROUTING of that content at that instant — **whether `routed` ==
`ingest completed` is a source question nobody has read** — and it is visible only to the author, only
inside its own post-reset brief. **Post-hoc and per-author, never queryable health.** So it does not
repair the design defect above; what it proves is that **the timestamp already exists in the data**, which
makes a positive surface plausibly a SURFACING job rather than a plumbing one. Fix shape is the grill's.

**SECOND SPECIMEN, DIFFERENT FAILURE MODE (todlando, own SELF line, `spt endpoint list` exit 0):**
`psyche-host: FAILED (psyche per-event turn failed 3x consecutively: commune-sync: echo-commune exited
Some(1): ECHO_COMMUNE_FAIL:todlando: claude exited exit code: 1:; 1 attempt; 2026-07-30T02:43:45Z)`
⭐ **Not deployah's mode — his spawn was KILLED at the 30s bound under release load; mine RAN and exited
1.** ⇒ **the load-sensitive-bound hypothesis does not cover this one; there are at least two failure modes
and merging them would hide one.** (The line reads "failed 3x consecutively" and "1 attempt" together —
quoted as-is, not reconciled.) This also falsifies my own earlier "mine was clean throughout" as a claim
about the present: **a clean reading has a shelf life, and this one expired in about half an hour.**

**⭐⭐ chert's CORRECTION TO MY F-B — TWO DIFFERENT LEGS, DO NOT COLLAPSE THEM.** I framed the FAILED stamp
as "a strictly LATER attempt" than the 02:41:30Z routing. Wrong frame: **the commune-FILE ingest and the
per-event `echo-commune` SUMMARISER SPAWN are different legs.** chert's file ingest plainly worked (he
resumed with his full brief) while his summariser spawn was being killed at the 30s bound. So
`routed_at_ms` evidences the FILE leg; the FAILED stamp indicts the SUMMARISER leg. Both my observations
survive individually — routing at 02:41:30.248Z, summariser failure at 02:43:45Z — but they are **not two
attempts at one thing**, and reading them as a sequence invents a recovery/relapse story out of two
independent subsystems.
**⭐ chert also read `lifecycle.rs:895-903`: the stamp is CLEARED on every success ⇒ a present stamp means
the RECENT attempts failed, not an old scar.** And the field is **not** json-only — the human renderer
prints it, so an earlier clean reading was of a pre-stamp state, not of a hidden field.

**⚠ THREE FAILED STAMPS IN ~40 MINUTES, TWO MODES, ALL ON HFENDULEAM — correlated with load and that is
ALL it is.** deployah 02:05:14Z (killed at 30s bound, under release load) · todlando 02:43:45Z (**exited 1**,
during CI's Windows test leg) · chert 02:45:49Z (killed at 30s bound, same CI leg). ⭐⭐ **doyle banked
"a perfect correlation is not a mechanism" the same hour — three-for-three under load is exactly that
shape, and the discriminating test (the same bounded spawn on an IDLE box) is STILL UNRUN and cannot run
while the golden legs hold both boxes.** Do not upgrade this to a load diagnosis; and note the exit-1 mode
is not a timeout at all, so a single load story cannot cover all three.

**The specimen (deployah, HFENDULEAM, during the v0.46.0 publish):**
`psyche-host: FAILED (psyche per-event turn failed 3x consecutively: commune-sync: echo-commune spawn
failed: bounded invocation timed out after 30s (killed): claude-spt echo-commune --id deployah ...;
3 attempts; 2026-07-30T02:05:14Z)` — timestamped *between* my draft verification (02:05:13Z) and my
publish (02:06:23Z), i.e. under release load. **It then RECOVERED with no intervention** (field absent by
02:13Z), so a 3×-consecutive-failure state can self-clear. The load link is a hypothesis with a
mechanism, NOT measured — the discriminating test is whether the 30s spawn bound fails on an idle box.

**⚠ While it is FAILED, a commune is unsafe to rely on for continuity** — the ingest may not land, so
after a reset assume durable context as of the last successful ingest. Compounds
[[commune-is-testimony-not-an-artifact]]: a commune that silently fails to ingest is the worst failure
mode for the artifact whose entire job is surviving a reset.

**⭐⭐ FOUR competent agents read their own clean SELF line as health, and all four withdrew it within
minutes** (chert — path never invoked; hertz — "no 3-strike annotation" ≠ ingestion; todlando — "an
endpoint that never tried cannot have timed out"; me — failure→absence ≠ recovery). **A surface that
produces the same wrong inference in four independent observers who had each just banked the rule against
it is a DESIGN defect, not four slips.** The surface offers exactly one informative event — a failure —
and every other reading it can produce is unfalsifiable. Treat "my SELF line looks fine" as *no
observation was made*.

**⭐ A fresh memory index is ZERO evidence about psyche health.** Two different mechanisms (chert's
answer, accepted): the memory dir is ordinary synchronous tool writes — no daemon, no spawn, no bound —
while the commune/psyche ingest is the spt daemon spawning `claude-spt echo-commune` as a *bounded
subprocess*. My memory index looked current all night while the psyche-host was failed, which is exactly
the evidence that would have wrongly reassured me.
