---
name: v0671-arc-service-docs
description: "v0.67.1 docs-only PATCH (#274 [service] manifest section on the docs site) — SHIPPED 2026-09-06 11:30:58Z, counter 103, tag==main==tested 04e32c8c; operator-directed batch of one, no milestone; 6 CI attempts across 2 shas, every red closed at a NAMED mechanism, zero by rerun-only"
metadata:
  type: project
---

**SHIPPED 2026-09-06T11:30:58Z** — v0.67.1, counter 103, tag == main == golden-tested
`04e32c8c95cf09ddc2a44a51cd0233b0d13bdc64`. 11 assets verified at source, counter decoded live.
Request spt-bs-releases#274 (alchemy-minted, type ADDITION) → ACCEPTANCE pre-publish (closed 11:13:11Z
by the commit's `fixes` keyword at the main push) → `release v0.67.1` promoted to DONE, roundup 1 request.
No milestone: operator-directed golden batch of one ("an urgent fix is a golden batch of one", GOLDEN-CI.md).

**The gap:** docs-site `harness-contract/manifest.md` (hand-authored "complete field reference") never got the
`[service]` section `docs/MANIFEST.md` carried since v0.44.0; only the generated CLI reference named the feature.
Drift gate covers GENERATED surfaces only. Port = verbatim minus internal codes + a checklist floor line; anchor form
`manifest.md#service--a-daemon-supervised-resident-service` (backticks/brackets stripped, `--` for the em dash),
rendered anchor verified in a local mdbook build. perri (adapter builder, forbidden to read the source tree) hit the
gap live the same hour — "I could only answer his question from an internal file" is the ticket's one-sentence
justification. His AUTH/ENUMERATION asks → #275 (contract question, not docs; hand-filed, I typed it via alchemy-0).

**Shape:** patch (CHANGELOG policy: additive opt-in page), authored BEFORE the golden push (shape-on-top; the
reclass respin ff'd on top of the shape commit, no re-shape). Lockfile via `cargo update --workspace --offline`,
14 first-party pairs by diff. `xtask gen` porcelain-M on reference.md with EMPTY `--ignore-cr-at-eol` diff = EOL
phantom, reverted. Battery all 0 by exit FILE; mdbook build added as a leg for a docs lane.

**Golden history (2 shas, 6 attempts, ~5.5h push→publish):**
- r1 `34fdb848` run 34014574926: att1 Linux Phase A red `brain_resume_conn_deadlock::…respawn_interleave`
  97 ticks/6s vs floor 100 (twin `_steady_state` PASS same window). doyle RCA-274-R1-LINUX.md: a HEAVY-qualifying
  flood rig (6 PTY floods + real broker per test) NEVER swept into the HEAVY pool — born 6 days before the
  HEAVY-AT-BIRTH ruling; ran concurrently with its byte-identical twin in the light pool. Same-sha rerun att2:
  BOTH twins red (88 / 97) → pre-committed respin WITH the reclass.
- respin `04e32c8c` (doyle-authored config-only: both HEAVY strings byte-equal, nextest stanza, ledger row; parent
  = my shape commit) on a FRESH ref `golden/service-docs-0671-r2` (old ref's group still busy with att2's twohost
  tail — fresh ref was right). Run 34017906638: Linux Phase A GREEN with twins removed, Phase B GREEN with twins
  serialized = doyle's pre-registered discriminator confirmed by prediction, both OS. Then THREE distinct Windows
  Phase A victims, one per attempt: att1 `attach_link_push_e2e :473` (structural: viewer spawned with no barrier
  before re-link; product emitted Link(None) then State correctly), att2 `wtlock_two_process_int :147` (B waited
  the full 10s bound while A's 6 serial commits ran 13.5s; todlando's 1240-cell workspace nextest fully overlapped
  the window — he was never told about the hold), att3 `resident_service_e2e :664` teardown leak = FLAKE-LEDGER
  row 42, THIRD classified occurrence, two svcmock survivors (svcboot + relshell). doyle overrode his own
  "third distinct timing cell → stop" arm ON THE RECORD (ledgered leak class ≠ load-timing victim; a respin
  carried nothing for :664) with a HARD STOP pre-registered for att4. att4 GREEN 9/9. twohost a+b green on
  ALL SIX attempts across both shas; the reclass twins green on every attempt both OS. Hardening → hertz
  (dfcae9db rig fixes + :664 cluster), thin lane post-land.

**Craft banked this arc:**
- ⭐ AUTO-FIRE WATCHER NEEDS A GATE THE PEER CAN FLIP: I armed "rerun --failed on terminal"; doyle then added a
  hold (perri's build on the box) — the only way to honor it was TaskStop + a plain watcher. Next time: the auto
  action reads a gate FILE the driver can remove, so a hold is one `rm`, not a task kill.
- ⭐ `sed 's/^RULED=.*/…/'` on a line that ALSO held `TAG=` deleted the tag assignment; the land script ff'd
  main and died at `TAG: unbound variable`. Main was advanced, no tag — recoverable, but a script edited by regex
  is a script you have not re-read. One assignment per line, or re-run the script's dry leg after editing.
- run-level `status` field freezes at "queued"/"in_progress" — derive terminal from JOB states (done in watcher).
- `gh run rerun --failed` re-runs DEPENDENTS too (twohost a+b every time, ~30 min) — the tail is the cost of a
  rerun, not the failed job's own duration. Kitsubito stays occupied through it.
- A push run on a FRESH `golden/**-rN` ref avoids queuing behind the old ref's concurrency group; the old run's
  carried twohost tail plus a peer's thin ci queued ahead still cost ~20 min of runner occupancy.
- Strict "main advances only to a green RUN": I refused to ff/tag on the green Windows JOB while twohost dependents
  were still re-running (30 min). doyle agreed; a tag on a run that later reds is the state to never risk.
- Closed-by-keyword: `fixes <owner/repo>#N` in the commit message DID close #274 cross-repo at the main push
  (closedAt 11:13:11Z, 80s before my `state acceptance`) — the v0.50.0 "cross-repo never auto-close" memory does
  not hold when the pusher has write access to the target repo. The state verb still owed the LABEL.

Related: [[v0670-arc-in-flight]], [[a-step-that-straddles-an-irreversible-action-reads-as-done-at-the-action]],
[[golden-respin-test]], [[hold-pushes-during-the-tag-window]], [[docs-surface-is-installed-daemon-vintage]].
Logs preserved: Documents\spt-preserve\v0671-golden-r1\ (4 CI job logs + SHA256SUMS + NOTE.md, restore cost none).
