---
name: resident-service-w1-gate
description: "PR #89 RESIDENT-SERVICE W1 gate state — Linux red root-caused (provably_gone zombie gap), fixup with todlando, counter 79 verified"
metadata: 
  node_type: memory
  type: project
  originSessionId: 614b697b-2f3d-48fb-a473-23042fed797d
  modified: 2026-07-27T01:18:21.322Z
---

PR #89 (RESIDENT-SERVICE W1, todlando) gate state as of 2026-07-26 ~17:15:

- Content-gated PASS earlier (Windows-side). First full CI run: **Linux test leg RED x2, DETERMINISTIC product gap** — `spt_store::proc::provably_gone` reads a Linux ZOMBIE as not-gone: `process_exists` = /proc table presence, zombies stay in table until reaped, and the `Some(true)` arm never consults `is_process_alive` (which already rules Z-state dead). Failures: `a_tree_teardown_reaches_a_grandchild_the_service_spawned` (direct-child assert, also UNPOLLED — rider: wrap in poll) and `a_path_verified_orphan_is_reaped_and_confirmed_by_a_post_kill_read` (awaits_death burns full 2s → KillFailed). Windows green is structural (Toolhelp excludes terminated). Fix shape sent to todlando (SENT, ~17:10): unix `Some(true)` arm → `!is_process_alive(pid)`; Windows keeps table-authoritative. **Re-gate on new head before merge.**
- **FIXUP PUSHED (todlando) @`a89fc63`, awaiting doyle re-gate.** `provably_gone` present arm split per platform (unix `!is_process_alive` / Windows `false`); new Linux-only unit `a_zombie_is_gone_to_the_owned_process_oracle` (rig asserts the zombie shape before claiming); tree-teardown rider taken (both pids on one polled deadline); KH 7.50 second-instance bullet + servicehost mapping. Windows-side: clippy `-D warnings` 0, proc 12/12, servicehost 45/45, tree-teardown pass, `traceable-reqs check` 0, `xtask check` OK. Windows can NOT execute the new test (cfg linux) — Linux leg is the verification.
- ✅ **RIDER 2 RULED FOLD-NOW (doyle, sent ~17:25):** `spt/src/teardown.rs::root_provably_gone` — same unix zombie gap, asker is unreaping-by-construction (broker-spawned root) ⇒ TimedOut where StaleRow honest; ships broken in 79 if waved, and this PR's KH amendment names the file. Fold terms: SEPARATE commit; `[impl+unit->REQ-ENDPOINT-TEARDOWN-AUTHORITY]`; Linux zombie unit with rig-proves-zombie precondition; repin old-shape units same commit (todlando's lane — product change carrying its tests); KH mapping rephrase "handle-half correct, zombie-half fixed 2026-07-26". ⚠ ratified: NO delegation to `proc::provably_gone` — empty-table false (refusal survives) is load-bearing; Z-demotion on present branch only. ONE re-gate cycle covers both fixups; Linux leg = real verifier.
- ✅ **RIDER 2 FOLD PUSHED @`7f36d06`** (separate commit on a89fc63) — `root_provably_gone` three-arm rewrite (empty⇒false preserved, absent⇒true, present⇒unix `!is_process_alive` / win `false`); impl tags added (fn had NONE before — pre-existing gap); Linux unit `a_zombie_root_is_provably_gone_not_a_survivor` asserts probe AND `unconfirmed_verdict ⇒ StaleRow`; KH mapping = doyle's phrasing verbatim. ⚠ **repin item had NOTHING to repin** — no unit was ever keyed on the old present-arm behavior, which is HOW the zombie half went unaudited; surfaced to doyle, not absorbed. Windows gate: clippy 0, teardown 4/4, traceable 0, xtask OK. Branch ready for one re-gate cycle covering both fixups.
- ⚠ **Box rebooted uncontrolled mid-work 2026-07-26 ~17:40** — fold edits survived (uncommitted working tree). Killed build left a CORRUPT PDB in the throwaway target ⇒ next cargo call died `LNK1207 incompatible PDB format` on iroh: an ENVIRONMENTAL red wearing a compiler-shaped signature. Fix = delete the stale `*.pdb`, rebuild. Don't read a post-crash LNK1207 as a code red.
- ⭐ KH 7.50 blast-radius: NEW instance — presence-in-table is NOT proof of life on unix. Fold into my queued KH 7.50 amendment ([[idle-edge-w1-progress]] follow-up branch).
- Counter for next cut VERIFIED from published signed metadata (BigscreenVR/spt-bs-releases v0.43.1 `spt-x86_64-windows.exe.release.json` → `"version":78`) ⇒ **v0.44.0 = counter 79**.
- ✅ **RE-GATE PASS + MERGED @`12555b4`** (2026-07-26 ~18:25): Linux leg GREEN on 7f36d06 (both zombie units verified); Windows leg one red `daemon_e2e::daemon_hosts_lifecycle_and_survives_brain_restart` ("child exit must reap the session from the broker table") — ruled ENVIRONMENTAL (zero Windows-semantic delta in both fixup commits + post-crash busy box + load pushes the reap window toward red), rerun GREEN, merged. 📌 If this daemon_e2e test reds again on a quiet box, the environmental ruling is SPENT — treat as real race candidate.
- ✅ Fan-out DONE (~18:30): deployah GO SENT (v0.44.0/79, changelog range verified = #89+#87+#88, seed _CMD, runner heads-up); flynn pinged (alchemy Hub Daemon adoption, sequence-not-floor); perri pinged ([service] substrate for rebound + REQ-INSTALL-11 shell wiring; Copy-mode case explicitly NOT claimed fixed); hertz UNBLOCKED (repin against NEW provably_gone shape). ⏳ awaiting deployah release PR number → gate release shape.
- 📌 dangling memory ref resolved: "adapter-dir-delivery-notify-perri" file never existed; the substance = PR #89 leg E REQ-INSTALL-11 shell wiring (released shell adapters launch). Told perri from the PR contract, not from summary.
- Worktree debris: `.worktrees/gate-89-red` handle-pinned (plus gate-87, readenv-staleness) — rm when unpinned.

## Index-line archive (compacted out of MEMORY.md 2026-07-26)
- [RESIDENT-SERVICE W1 gate](resident-service-w1-gate.md) — 🏁 **SHIPPED v0.44.0 c79 @2189f87** ([[v0440-published]]). PR #89 merged @12555b4 (both zombie-oracle fixes a89fc63/7f36d06 rode it — RIDER 2 folded in, not deferred); release PR #90 shape-gated by doyle zero re-cuts. ✅ tails closed: flynn+perri+emphasys all notified post-publish ([service] adoption gates open); hertz repin in flight (⚠ his channel corrupting — verify-first+echo-back discipline, see backlog); deployah owes runbook docs-publish.yml drift PR (doyle gates).
