---
name: v0620-arc-in-flight
description: "v0.62.0 (SIGNET #218) release arc — PUBLISHED 2026-08-25, counter 97, tag/main/tested sha all 12ab4a7a; one respin over a Linux-only clippy dead-const"
metadata: 
  node_type: memory
  type: project
  originSessionId: 68ec592a-933a-479e-9046-1cccca94f355
  modified: 2026-08-25T02:26:55.022Z
---

v0.62.0 (milestone SIGNET, releases#218, sole member #217 — wax-seal FIDO2 ceremony) **SHIPPED**
2026-08-25T02:24:31Z.

- **Counter 97**, derived from the published `*.release.json` (`"version":96` at v0.61.0) and
  re-verified in the published metadata AFTER the flip — never by arithmetic on a remembered number.
- **tag == main == golden-tested sha == `12ab4a7ab3f1129f`**, one object with four names. No
  provability-bar argument anywhere in this cut, because the version material was authored ON TOP of
  the gater's head before golden (see [[shape-the-head-before-golden]]) and the respin fix then landed
  on top of THAT — so the shape survived the respin with no re-shape.
- Binaries verified against `SHA256SUMS` before signing; update-set v97, three platforms; 11 assets
  live. Signed via the hex-env fallback per the standing ruling for this box (`_CMD` unset, confirmed
  in both shells before firing).
- Board: cascade driven BEFORE publish (the `closedAt < publishedAt` gate), roundup credited 2 —
  #218 + #217, both DONE. **Rider reconcile done, not assumed**: IR-52/56/62/63 are all
  INFRA-REGISTER entries with no board home, so no rider could be under-credited
  ([[rider-open-at-publish-is-invisible-to-release-verb]]).
- Intake record #218 comment `5403001889`; r1 red-set `5403561203`; r2 green `5404051116`.

**ONE RESPIN.** Golden r1 `32790838399` @ `5a9f9bdc` red on ONE step — Linux clippy, an ungated
`BACKEND_KIND_HELLO_RS256` dead on Linux while its sibling `KEY_NAME` was gated (third face of
[[cfg-gated-code-is-invisible-to-the-other-platform-gate]]). Fix was one line; r2 `32796133406` @
`12ab4a7a` green 9/9.

**THE CALL WORTH REUSING — hold a red golden run to completion.** `twohost-a/b` are `needs: test`
with `!cancelled()`, so they still ran behind the failed test job, and the pre-declared
never-executed S1e enrollment rung got its **first orchestrated climb at the red sha** and PASSED.
A cfg attribute on a Linux-dead const cannot move a twohost verdict, so that evidence transferred to
the respin and made it cheap. Killing the run at the red would have deferred S1e a full cycle.
Ask before killing any red run: what evidence is still downstream of this failure, and is it
independent of the fix?

**Uncovered, named not percentaged (carry to the next cut):** Dormancy budget steps 38/39/40 did NOT
execute in either run on either OS. Verified *condition*-derived rather than failure-suppressed by
the decisive control — the r1 **Windows** leg was fully green and skipped all three anyway. Standing
coverage hole, not a regression. Also: the real Windows Hello prompt stays field-exercised only per
`REQ-SEAL-AUTH-BACKEND-SEAM`.

**Open, not mine:** doyle authors the `CONTEXT.md` wax-seal amendment post-publish on advanced main
(docs-only), naming the v1 signer-is-minter boundary that the REQ title and published page already
carry. Prior arc: [[v0610-arc-in-flight]].
