---
name: v0680-arc-in-flight
description: "v0.68.0 WEBSERVE #272 arc — greenlit 2026-09-06 ~10:30Z after a two-round grill-with-docs (ADR-0056..0061 + CONTEXT.md Web serving on docs/webserve-272-grill @a87bd42a); wave map WEBSERVE-272-JIT.md; W0 dispatched to todlando"
metadata: 
  node_type: memory
  type: project
  originSessionId: 647c7dc2-d1c2-49f5-9513-98ffb742a36a
  modified: 2026-09-07T03:54:58.293Z
---

**GREENLIT 2026-09-06 ~10:30Z** by the operator in chat ("shared understanding confirmed.
proceed with WEBSERVE"). Design record on branch `docs/webserve-272-grill` @a87bd42a (off
main; first thin PR after v0.67.1): ADR-0056 node-prefixed URLs (+grammar, http-only), 0057
registry primitive + `~n` served names, 0058 pull-model attachments (snapshot, 30 d TTL),
0059 LAN bootstrap-only listener (port 5470), 0060 mint WEB / retire XFER, 0061 node-scoped
message short-ID; CONTEXT.md `## Web serving` (10 terms) + access-surface entry amended.
Grill rounds at repo root `WEBSERVE-272-GRILL-ROUND-{1,2}.md`; board record #272 comments
5558410252 + 5558560333. Round-1 text had been LOST once to an across-commune (recovered from
the session transcript) — the ceremony's docs now live in git, not in chat.

**Members:** ride #248 #249 #246 #265 #268 #147 #266; #17 closing rider (flips with W2);
#148 DETACHED (deferred, BACKLOG, reason commented); #271 SHELVED.

**Wave map** `WEBSERVE-272-JIT.md` (repo root): W0 substrate (URL grammar + registry + WEB
row; REQ-WEB-URL-NODE-PREFIX, REQ-WEB-SERVING-REGISTRY, REQ-WEB-ACCESS-SURFACE) → W1
cross-node proxy (REQ-WEB-CROSS-NODE-PROXY) → W2 attachments + short-ID + #17
(REQ-WEB-ATTACHMENT-PULL, REQ-WEB-FETCH-VERB, REQ-MSG-SHORT-ID) → W3 facets (adapter docs,
changelog page, LAN bootstrap listener; two MEASURE-FIRST items) → close riders (XFER
retirement REQ-XFER-RETIRED, IR-76 pre-flight in the driver template). All lanes base off
main AFTER v0.67.1 lands; todlando's queue = #276 PR → #277 → W0 (W0 store work may start
now, rebase at the land).

**Open beside it:** v0.67.1 golden 34017906638 att4 (Windows leg from 10:12Z; hard stop on
any red → hertz's leak hardening rides a respin); #277/#278/#279 thin lanes; DOCS-NITS-0672.

Related: [[v0670-arc-in-flight]], [[resumed-session-reground-before-acting]].

- 2026-09-06 ~10:35Z todlando signoff (operator call, back promptly): W0 STARTED + parked — worktree .worktrees/ws272-w0, branch build/ws272-w0 off 8a21a3b0, HEAD 884b9124, three REQs minted and committed ALONE first (treqs exit 1 = exactly the 11 missing-stage findings those activations imply; parses). NO pool claimed, zero cargo since the box hold. Board correction: the commit says `Refs #248, #272` NOT fixes — W0 delivers #248 + the LOCAL half of #249; nothing closes until impl lands, and #249 stays OPEN for W1's cross-node half regardless. Next for todlando: W0 spt-store registry format + ADR-0057 served-name rule clause-by-clause; #276 rebase the moment v0.67.1 lands.
- 2026-09-06 10:44Z FILED #280 (bugfix, BACKLOG): MSG_IN never published on the `api listen` relay edge — only hook-poll drain (`delivery.rs:752`) stamps it; relay `deliver` closure (`startup.rs:1057`) serves backlog + live and publishes nothing. emphasys F-038, confirmed in source at 04e32c8c. Fix shape in comment 5558693022 (publish in the closure post-notif-filter; check lastmsg.rs + iobus.rs:272 consumers; add relay arm to io_events_undriven_kinds_e2e). Routes todlando AFTER #276 rebase + #277; rides the next batch (v0.68.0 head unless a point cut opens). ALSO today: ADR-0057 Amendment 1 (served root = core-owned `adapters/<adapter>/web/`, `a/<adapter>` facet, `web_short_path` = alias) committed a5a39e8a on docs/webserve-272-grill — the thin PR for that branch must now carry a5a39e8a, not a87bd42a.
- 2026-09-06 12:38Z post-land merge queue (ff-only, my gate): #187 register (4bf43598) → #188 grill docs (a26ca59a) → #186 = #276 echo-direct-route (914805d1; mutation dump verbatim, range-diff 1:1, both OS green on the rebased head) LANDED on main. Next: hertz #189 (test/attach-relink-barrier, rebase onto 914805d1, one run) → todlando #190 docs-nits (content gate PASS 12:00Z; rebases last) → #277 (+#279 + cursor rider) → #280 → W0. #276 behaviour notes for adapters (unreleased until the next tag): `[session.echo_commune]` without commune_dir now ECHOES (was a no-op); nonempty echo project slice without a project anchor → loud `ECHO_PROJECT_UNROUTABLE`, no pending file. Interim commune rule (mid-turn + one tool call) stays until a release CARRIES #276.
- 2026-09-06 12:57Z #189 LANDED ff (17815c9c, all 5 jobs green attempt 1, range-diff 1:1 on 914805d1); webserve-272-docs worktree + docs/webserve-272-grill removed (ancestry vs origin/main). hertz opened ci/webserve-floor-riders at 17815c9c. RULED 13:01Z: IR-66 SATISFIED (register body BUILT at d04b922d; both cells present at 17815c9c — my "residual, two one-line edits" was the entry's own Size: line carried forward as work; corrected by replacement in WEBSERVE-272-JIT.md); IR-73 half-2 = IR-46 remedy re-read, one composed edit set; IR-46 remedy ACCEPTED as hertz proposed (pre-docs-drift re-read + `if: always()` end-of-job floor assert, 32 GiB kept, samples labelled instants, raise-floor + continuous-sampling refused) with riders: raw bytes per job, greppable FLOOR_START/FLOOR_END tokens, step name says DISK, ready call cites both tokens from the PR's own ci.yml run. Operator: todlando signs off for omp-spt 0.9.0 update; I confirm offline then `spt endpoint resume todlando`; #190 rebase waits for their return.
- 2026-09-06 13:08Z todlando signoff (omp-spt 0.9.0 update) → OFFLINE 13:06:39Z confirmed by listing + edge transition → `spt endpoint resume todlando` → ONLINE 13:08:12Z session 21. #190 rebased to bb25787a on 17815c9c (lane-diff delta = the 4-line anchor paragraph only; content gate PASS; lands LAST after #191, #192). #191 (#277+#279, f9452008) diff gate via forked reviewer + my own hunk read: PASS with ONE hand-back (engineroom.rs reserved-id test dropped `contains("spt rc engine-room")` + `== reserved_id_refusal` asserts; restore) ; RULED always-full-scan-on-append accepted (declared deviation from the JIT's first<last lean, bounded by the 1250-row cap). hertz #192 floor trio 2446dd61 on 17815c9c, CI queued behind #191 on this box. todlando scoping #280 in .worktrees/relay-msg-in-280.
- 2026-09-06 13:35Z #192 floor trio (2446dd61) gate: CI 5/5 green; I pulled all 10 FLOOR_START/END lines myself (first grep `head -6`'d the Linux OUTPUT lines away behind the runner's script echo — truncated grep = wrong population, again). PASS with ONE hand-back: golden.yml `changes` (pre-checkout, literal-first) + `twohost-b` never got tokens/review. FIRST MEASURED PER-JOB PEAK DELTA: Windows unit ~64 GB, Linux unit ~68 GB in one job (the number a raised floor would argue from). Register status lines IR-46/59/73 → BUILT + #192 link = MINE at the WEBSERVE close sweep. #191 respun twice (5bfb4155 did not COMPILE — my textual PASS missed a dropped `engineroom::` qualifier; b1ce4baf fixed, legs 14/14) — a restored-assertion hunk is gated by COMPILE, not by diff read.
- 2026-09-06 13:51Z #190 docs-nits LANDED ff (bb25787a, 5/5 green at 17815c9c). Order re-derived: "docs last" exists to avoid forcing product re-runs, but #191 sat on 914805d1 (needed rebase+re-run anyway) and #192 re-runs behind whichever lands first — so docs-first cost ZERO extra runs and saved one Windows window. Rule of thumb: count the re-runs each order forces; the docs-last heuristic is the answer only when the product PRs are ALREADY on the tip. Next: #191 rebase → bb25787a, land; then #192 rebase → #191's sha, land; #280 (Linux green + mutation-proven 13:47Z) Windows legs when box quiet; W0 parked.
- 2026-09-06 14:26Z #191 (#277+#279 iolog seq reset + true-head cursor + lazy reserved-bind probe) LANDED ff: main = 7689dc33, 5/5 green attempt 1 at the rebased head. Queue now: #192 floor trio rebases onto 7689dc33 → land; then #280 (Linux green + mutation-proven; Windows legs after #192's run); then WEBSERVE W0 per JIT §W0. Post-land: alchemy sweep for #277/#279 ACCEPTANCE. Windows runner pickup lag measured ~10 min after a free box (14:04 free → 14:14 start).
- 2026-09-06 14:50Z #192 floor trio LANDED ff: main = 9f809f8d (9f809f8d = 70db2c9f rebased 1:1 on 7689dc33; 5/5 green attempt 1). MERGE QUEUE COMPLETE: #189 17815c9c → #190 bb25787a → #191 7689dc33 → #192 9f809f8d, every land tested==merged, zero force, zero reruns. Board: #276/#277/#279 ACCEPTANCE via alchemy sweep (the `#< sweep #>` inline tag FANS OUT to every alchemy instance — alchemy-1/spt-progress-tool answered "nothing" AND alchemy-0 reconciled 3). Next: #280 Windows legs → PR → gate → land; then WEBSERVE W0 (JIT §W0 + ADR-0056/57/58 Am.1). Register status lines IR-46/59/73 → BUILT(#192) = mine at the WEBSERVE close sweep. hertz: cleanup + pool-claim audit.
- 2026-09-06 15:47Z #194 = #280 relay MSG_IN LANDED ff: main = eb38b71a (ec7936b9 rebased 1:1 onto 68e34ae5, 5/5 green at BOTH shas). Gate read against SOURCE not the PR body: publish sits in the `deliver` closure fed by drain_backlog/pump_once/run; drain_backlog filters via notifgate::retain_deliverable BEFORE the sink; emitter cli::publish_msg_io → default_bus → iobus sink records lastmsg; tag REQ-IO-MSG-EDGES matches the poll edge (my fix-shape comment named REQ-IO-EVENT-TAXONOMY — wrong id, todlando followed the code). Mutation delivery-red/filtered-green on both hosts. #280 → ACCEPTANCE (alchemy-0 sweep). ⚠ LAND-ORDER MISS, mine: hertz's #193 (IR-12 kin retirement, docs-only, main 68e34ae5) landed FIRST while #194's CI ran at a sibling head, AND I told todlando "no rebase needed" without running the discriminator → forced #194 a 10-min two-box rerun to save a 30 s docs rerun; filed as the 4th face in ff-only-absorbs-one-sibling-lane.md. hertz today: floor-riders cleanup verified; pool audit → gate-242-w1 reaped (+85.2 GB, evidence hashed at ~/spt-evidence/gate-242-w1-20260906), IAVO pool HELD (447 unclassified insertions, patch preserved, re-enters at the WEBSERVE close sweep), #185 pools retained, ir12 pool reaped (+6.3 GB); IR-12 kin premise RETIRED by mutation (xtask check builds its own spt input since 992547de) — entry leaves the register at the close sweep. Sweep rule added: step 1 asserts origin/main == GitHub main (`git fetch` exit 0 with a rejected ref update is a silent stale). W0 DISPATCHED to todlando 15:25Z (alchemy dispatch #248 → WIP; ws272-w0 rebased clean to 67ce6b5f on 68e34ae5, re-rebase onto eb38b71a + pool + step 1 opened 15:46Z). Amended ADRs are ON MAIN under rebased shas (a26ca59a = ADR-0058 Am.1); the hold-state's f54309cc/6888d867 are pre-rebase fossils.
- 2026-09-06 16:13Z Post-clear re-ground clean (main eb38b71a both sides; W0 f0bc6637 rebased on it, ancestor verified). todlando: relay-280 cleanup ACCEPTED after I verified (worktree/branches gone; 355 evidence files under project-root .spt/relay-280-evidence/; my first ls missed it from a STALE cwd after an earlier cd — absolute paths, always). W0: pools claimed both hosts, IR-76 pre-flight clear w/ floor line, step 1 done (listener rename, 5 refs), steps 3+4 parallel, 5+6 next, uncompiled. hertz W3 drift-gate riders COMPOSED 16:12Z (WEBSERVE-272-W3-DRIFT-RIDERS.md): #265 MEASURE-FIRST answered by me — none of 7 installed adapters ships docs → ruled manifest key docs_dir; REQ-DOCS-CHANGELOG-PAGE gains unit stage (hertz); TRAP: CHANGELOG.md carries <!-- [doc->REQ-…] --> tags, so a generated changelog page joined to the internal-codes scan fires on run one unless the generator strips comments. hertz cells ride INSIDE todlando's W3 PR (one gate), hertz does not mint REQ ids. W3 contract also sent to todlando so W0/W1 design does not fight it.
- 2026-09-06 16:36Z W0 smoke (11 CLI ops, 14 HTTP, Chromium index) PASSED except a DESIGN defect the smoke surfaced: adapter reactivation allocated reports~1 with reports 404 — ADR-0057's own letter (entry removed at deactivation + freed never reused) churns every adapter alias on adapter update. RULED ADR-0057 Am.2: a freed name may be re-taken ONLY by the absolute path it last named (history = name->last path). Lesson: a smoke line that reads as CORRECT under the letter still needs the CONSEQUENCE walked one cycle forward (what happens on the second update?) — the builder reported it as a pass and it was one. Also today: my 'top-level docs_dir' pin was an inference from a fixture's append shape, RETRACTED within 2 min after measuring W0's [adapter].web_short_path home + HARNESS_COPY's [shell] tail; hertz caught that his escape REDs proved nothing about the intended field. hertz W3 RED cells at 045ef16f (test/ws272-w3-drift).
- 2026-09-06 18:02Z ⛔ OPERATOR CPU HOLD on hfenduleam (this Windows box) until the operator says "i'm done" (game, ~2 h): no cargo/nextest/clippy/analyzer/smoke daemons here, and NO pushes that trigger the Windows CI runner here. kitsubito OPEN. Relayed to todlando (QUEUED — coming back from quota) + hertz (SENT). I relay the release when it comes. todlando + hertz were OUT OF USAGE ~12:36Z-17:57Z (shared account), not held.
- 2026-09-06 18:08Z SECOND retraction on the same seam in one hour: I told both agents HARNESS_COPY's tail header was [shell] — from awk '/const HARNESS_COPY/,/";/' whose end pattern a RAW string (r#"…"#;) never matches, so the range swallowed the next consts and I read several strings' headers as one. hertz refuted it by PARSING the composed fixture (docs_dir under [adapter] = True). Re-measured with /"#;/: one header, [adapter], ends registry.rs:861. Both my docs_dir errors today came from reading SHAPE (an append, an awk range) instead of parsing the ARTIFACT; hertz's two catches both came from composing the exact bytes and parsing them. When ruling on where a key lands, PARSE the composed TOML — never read the source string.
- 2026-09-06 18:27Z W0 head 0b9554b3 on build/ws272-w0 (mint 2c5d3187 → driver 0160ff7d → feature 0b9554b3; no CI fires on branch push). Am.2 allocator IN and smoke-proven on Linux at e3e1cd47 (rm+re-add same = report.md; third = report~2.md; alias kept across deactivate; reports~1 never allocated). REQ-MANIFEST-UNKNOWN-KEY-WARN minted + built as a GENERIC schema walk (toml::Value vs schema_for!(Manifest); additionalProperties tables unjudged; one stderr line per key at register/update; 5 cells). CONTEXT.md served-name sentence re-stated to Am.2 — APPROVED: cite-not-reword guards builder paraphrase, not a ruled amendment; correct by replacement applies. hertz's 5-deny_unknown_fields claim corrected: ZERO usages, all comments (design tolerance, asserted :1839). Under operator CPU hold: Windows legs + PR wait for the release word. Gate checklist GATE-W0-272-CHECKLIST.md staged.
- 2026-09-06 19:16Z W0 Linux battery at 0b9554b3 VOID: two concurrent drivers (orphaned remote bash from a TaskStop'ped ssh + detached relaunch) shared one target + one nextest.raw (two Summary lines: 1 failed / 3 failed) + port 5474; todlando's first map named LOAD (exe-hash ready path) from the 1-failed summary alone; I found the second summary 60 lines down, he measured the orphan (.spt/gate-head-driver.log) and WITHDREW the map himself. Solo battery → .spt/gate-head2 (~19:35Z). hertz RCA stood down. New memory: stopped-local-ssh-does-not-stop-its-remote-command.md. Rider: per-output-dir lockfile goes into the W0 driver commit.
- 2026-09-06 19:43Z W0 Linux GREEN at 0b9554b3 (gate-head2 solo: ONE Summary, 2776/2776, all exits 0, smoke 20/20/0) — read from exit files by me. Contaminated gate-head reds VOID, nothing owed (hertz's discriminator adopted: solo red + no BIND_FAIL = probe suspect; solo red + BIND_FAIL quiet box = fixed-port singleton row; green = void). Ruled driver lock at WORKTREE level, not $OUT (hertz caught the scope gap). Pre-PR items dispatched hold-independent; Windows battery + PR open wait on the operator's 'i'm done'.
- 2026-09-06 19:47Z W0 tip 02adfbc1 (2c5d3187 mint → 9b3caa92 driver + WORKTREE-level lane lock .spt/driver.lock, holder-pid refusal, self-test → 02adfbc1 feature); delta vs Linux-tested 0b9554b3 = driver +75 / llms.txt +1 (serving page was missing from the curated index — my checklist line caught it). Linux COMPLETE: gate-head2 battery green at 0b9554b3 + gate-head4 xtask check/treqs 0 at 02adfbc1. PR body drafted in worktree PR-BODY-W0.md. BLOCKED ON OPERATOR CPU HOLD: Windows battery → PR open → CI → my gate (GATE-W0-272-CHECKLIST.md) → field acceptance → land → alchemy sweep #248 → W1 dispatch #249.
- 2026-09-06 22:08Z OPERATOR HOLD RELEASED ('i'm done'). Relayed to todlando (Windows battery at 02adfbc1 → PR) + hertz (stay idle). Gate worktree .worktrees/gate-w0-02adfbc1 staged git-only; pool claim + my legs wait until todlando's battery exit files are in (one battery per box; the Windows CI runner is this box).
- 2026-09-06 22:45Z W0 Windows battery #1 at 02adfbc1: 2803 run / 4 failed under a launcher ENV LEAK (SPT_ENDPOINT_ID → DAEMON_STOP_REFUSED ×2, the perched-gate trio rule again); (3) job_escape :608 reachable=false (unledgered) + (4) resident_service :664 teardown LEAK = FLAKE-LEDGER L42 row (todlando searched flake-registry.json — WRONG REGISTER, 2 rows; the ledger is docs/FLAKE-LEDGER.md). Decider = battery #2 scrubbed at the same sha (gate-head-b). Measured: W0's reconcile_at runs AFTER the broker exists (daemon.rs:291), so IPC readiness is off W0's path — pre-registered reads in GATE-W0-272-CHECKLIST.md. Battery #1 ate ~48 GB target (floor 130 → 82.8 GiB): read the floor before MY legs. Ruled: driver env-scrub hardening into the driver commit AFTER #2 (tree stays clean for the decider).
- 2026-09-06 22:48Z hertz (source read): job_escape_e2e 'reachable' = exit status of a 'spt daemon stop' subprocess with stderr NULLED and env inherited (job_escape_e2e.rs:519) — an authorization refusal and an unreachable daemon are the same false; 'carries no refusal text' was the PROBE discarding it, not a different mechanism. Red (3) → same env leak as (1)/(2), pending battery #2. Probe fix (capture stderr into the DIAGNOSTIC, assert the specific exit) = hertz thin lane after W0 lands. Lesson: 'no refusal text' is evidence only if the probe could have SHOWN one — ask what the probe reads before reading its silence.
- 2026-09-06 22:50Z Battery #2 took THREE launches (todlando, measured): att1 prebuild 101 — SIX leaked test daemons from battery #1 (spawned by the refused daemon stops) held target\debug\spt.exe (os error 5); att2 launched from PowerShell after a process-env edit REPORTED scrubbed — psutil read-back of the driver showed SPT_ENDPOINT_ID/SPT_SESSION_NAME/SPT_INJECT_VERIFY_ECHO still present (PowerShell's $env edit did not reach Start-Process's child); att3 = .spt/launch-battery.py with explicit env= AND a psutil READ-BACK that refuses the launch unless the child's env agrees ('LAUNCH PROVEN'). Lesson: a scrub is proven by reading the CHILD's environment back, never by the launcher's view of its own; OWL_SESSION_ID was present in bash and invisible from PowerShell. Leaked daemons from a refused stop lock the lane's spt.exe and fabricate the NEXT battery's red (sub-index L80 class).
- 2026-09-06 22:46Z REAPED .worktrees/echo-276/target (lane fix/276 landed 914805d1; owner todlando: 'nothing named worth keeping', one 3.7 KB PR body with restore cost = gh pr view 186; real dir, 0 inbound links): free 83.1 → 125.9 GiB, +42.7. Worktree/branch kept. Proven-scrub launcher copied into .worktrees/gate-w0-02adfbc1/.spt/launch-battery.py for my legs (my shell carries all six identity vars — read back the CHILD). Battery #2 = gate-head-d (att3, LAUNCH PROVEN, verified by my own psutil read-back).
- 2026-09-06 23:06Z Battery #2 (gate-head-d, PROVEN scrub) reds mid-run: resident_service :664 = L42 row 4th sighting (hertz records); io_events_undriven_kinds_e2e relay_backlog… :87 'explicit daemon start failed: ' EMPTY stderr 0.872 s (PASSED battery #1 same sha 11.8 s; green on CI at its landing + Linux solo). Measured: spawn failure panics differently; every start_daemon outcome eprintln!s; a W0-changed CHILD failure returns Err → DAEMON_START_FAIL text; both stderr-silencing sites live in daemon RUN not START; test-vs-test reap REFUTED (sweeps observe, kills are pid-authenticated); todlando's kills predate att3 by 9 min; no WER event. ⇒ the CLI died SILENTLY (external kill or abort status) and the rig DISCARDS the exit code + TempDir logs — UNCLASSIFIED by rig construction, W0 exonerated by the signature. hertz lane: print status {:?} + persist <home>/logs on failure + ledger row. Lesson: 'prints stderr only' asserts (sub-index L52 class) leave a silent death undiagnosable — the exit CODE is the discriminator between kill and abort.
- 2026-09-06 23:20Z ⚠ MY collision: a backtick-quoted cargo command inside a double-quoted printf message body EXECUTED (command substitution) in the gate worktree — 2-min cold compile beside CI 34066156428's Windows unit job (23:17-23:19Z), killed by the tool timeout; message undelivered; resent via quoted heredoc with the CI-contamination note. Memory: backticks-in-a-double-quoted-message-body-execute.md. Also: my launched driver had REFUSED on its own (cold pool → no prebuilt xtask → DISK_FLOOR:REFUSE, zero CPU) = gate finding #1 (driver bootstrap), batched. PR #195 open at tip 1d8f6f2e (Fixes #248 only ✓); CI: changes/traceability/lint/Linux-unit green, Windows unit in progress. Gate reads so far: trailers 3/3, wip 0, docs surfaces all touched, api.md untouched, ADR-0057 Am.2 present, CHANGELOG hits = 4 HTML doc-tag comments only, Am.2 allocator at serving.rs:240-256 (owner.path==path && kind ⇒ reclaim), activation refusal manifest.rs:1196→serving.rs:357, WEB_NODE_RESERVED daemon.rs:298 + pairhost 864/891, unknown_keys manifest.rs:1160/1516 + cell :1665, ttl/audience Option.
- 2026-09-06 23:24Z W0 gate SOURCE READS at 1d8f6f2e COMPLETE: PASS on every JIT §W0 line (router = ADR-0056 Am.1 order; Am.2 allocator; alias refused at manifest front door; WEB_NODE_RESERVED warn+continue; unknown-key warn-then-proceed registry.rs:327; WEB row default_on=true/attributable=false; XFER kept; no web-dir deletion in product; trailers/wip/api.md/CHANGELOG/SUMMARY/llms clean). ONE finding: driver cannot bootstrap a cold pool (fail-closed refuse on missing xtask.exe) — fix shape approved (DISK_FLOOR:BOOTSTRAP direct read, same floor), respin ONCE. Sequence ruled: CI(1d8f6f2e) Windows concludes → I warm my gate pool (quiet window) → todlando pushes fix → CI(T2) → my battery at T2 after its Windows unit → field acceptance → land.
- 2026-09-06 23:28Z PR #195 CI 34066156428 at 1d8f6f2e GREEN 5/5 (Windows unit 23:26Z; my 23:17-19Z accidental compile overlapped it and manufactured nothing). Gate pool warming at 1d8f6f2e (background); respin c33dc521 (driver bootstrap fix, +35/-9 driver only) STAGED, pushes on my 'warm done'. Field script .worktrees/gate-w0-02adfbc1/.spt/field-w0.sh (node start/stop verbs, port 5480, Am.2 arcs, adapter alias stability, unknown-key typo probe).
- 2026-09-07 00:30Z **W0 LANDED ff: main = c33dc521** (PR #195 MERGED 00:29:09Z, tested==merged; chain 2c5d3187 mint → 8d7b8289 driver → c33dc521 feature off eb38b71a). Gate battery #3 (gate-doyle2, LAUNCH PROVEN, procs-before 0, after CI's Windows unit concluded): treqs/claim/prebuild/xtask/clippy 0, nextest 2803/2802 ONE Summary, mdbook 0 (driver stops at the first red leg — run the tail legs by hand), CI 5/5. The one red = spt-store monic `an_imparted_monic_never_overwrites_a_standing_judgement` exit 1 / zero panic text / 7.8s = breadcrumb-pid sibling kill (memory breadcrumb-pid-tree-kill-hazard; class present at c33dc521: 53 taskkill files, 40 breadcrumb readers, 3 path-authenticating); alone 3/3 green; hertz row cb261d68 on docs/flake-ledger-monic-breadcrumb-kill (no PR yet). Rule-2.5 mutation (webserve.rs:298 → false) red at webserve_e2e.rs:256 `302 vs 200`, green on revert; ":259 intact" was UNWITNESSED (structural: :256 panics first) — recorded honestly. Field 37/37 on 5480; my first probe expected 502 from an UNKNOWN label (502 is only for a KNOWN peer, webserve.rs:301; unknown → docs 404 :307) — probe corrected, not the product; exact 404 bodies asserted, not letter-greps. Board: alchemy sweep #248 WIP → ACCEPTANCE; W1 #249 dispatched to todlando (first dispatch REFUSED: `--no-fail-fast` inside the note parsed as a shell flag — keep `--` tokens out of alchemy notes). hertz broker.rs blind-panel instrument built, NOT deployed (bounce = operator's call; window opened by my "gate done"). Gate pool reaped post-preservation (67.8 GB real dir, 0 inbound links; raws under .spt/preserved/gate-w0-c33dc521). Ledger GATE-W0-272-CHECKLIST.md complete.
- 2026-09-07 00:50Z Post-clear re-ground clean (main c33dc521 both sides; no ws272-w1 remote branch yet; main checkout sits on hertz's fix/rc-subscribe-blind-panel @bd3a337b — shared checkout, left alone). W1 gate ledger STAGED: GATE-W1-272-CHECKLIST.md (anchors at c33dc521: StreamFamily dispatch.rs:103 tagged-family shape, serve_xfer xfer.rs:225 origin-from-stream, surface::WEB access.rs:146/:218, W0 placeholder 502 arm webserve.rs:298-303 = the line W1 replaces; twohost is HEAVY golden.yml:158 + own job :1029 → gate runs it ALONE; two mutation arms pre-registered as SEPARATE invocations so sibling-intact is witnessed; field = two RIG daemons on 5480 paired into a fresh subnet, exact bodies). RULED: JIT §W1 "unknown node → 404 naming it" REPLACED by the docs compat 404 (Am.1 order, :307); N-1 owner → 502-naming-node under a deadline. Sent to todlando 00:40Z (QUEUED) + his two leaked ws272-w0 test daemons 26588/18264 flagged as his to kill. Leftover .worktrees/gate-w0-02adfbc1: 4 orphan spt.exe from its reaped target killed (perch 14444 untouched), dir STILL pinned at crates/spt-daemon by an invisible cwd handle (no handle.exe on box; cargo procs are another account's = CI runner) — 0 MB, parked. Bash AND PowerShell tool cwds both drifted after one `cd` — absolute paths only.
- 2026-09-07 02:10Z W1 gate in flight at respin 8d980fdf (three findings closed: WebErr refused flag, docs WEB-rule sentence, WEB_STREAM breadcrumb positive control — my DISPATCH_EV premise was wrong, it logs non-Served only). Disk 0.5 GB → 109 GB by three reaps (todlando W0 pool 83.6; my main target 24.2 + hertz's released w2-rig-fixups 9.2, `.spt/reap-main-w2.ps1`); gate legs run SEQUENTIALLY in todlando's ws272-w1 pool after his release via one hatch-wrapped `pool-claim --foreign-pool` from my gate worktree (predicted from spt_poolguard::decide lib.rs:225). Field scaled: subnet ceremony needs elevation (cli.rs:770 "never runnable from an agent session"), so browser/pairing leg = operator option; agent field = e2e rig (2 real daemons) + twohost_web cross-box (scripts .spt/twohost-web-local.sh / -xbox.sh in the gate worktree). hertz GEARS RC defect localized off his preserved specimen: nethost.rs:552 begin_attach WouldBlock refusal is silent by construction (:2246 `let _ =`), gears never gets a stream-subscriber seat; RULED: fold a begin_attach breadcrumb into the blind-panel lane (bd3a337b alone would print nothing for gears — do NOT spend the bounce on it alone), check the specimen for `stream-sub-writer-poison` (:213, written) first, product fix = todlando BUGFIX lane after the panel speaks. RCA-GEARS-RC-UNREACHABLE.md untracked in main checkout; preserved artifacts under .spt/preserved/ (instrument exe + gears-specimen).

- **W1 #249 (cross-node proxy) head UP 2026-09-07 02:30Z**: build/ws272-w1 tip `8d980fdf` (one
  commit on c33dc521), PR #196, doyle's source reads done + respin (F1 WebErr refused flag, F2 WEB
  row wording, F3 WEB_STREAM breadcrumb as positive control) accepted. Batteries at the tip on both
  boxes: every red NAMED (Windows: brain_resume_conn_deadlock viewer-seam race, 3x same-pool
  control 3/3; Linux: two ready-deadline-under-cold-pool-load spt e2e bins, load-free control 2/2
  in ~11 s). First Windows attempt VOID at disk-full (see test-profile-pool-outgrows-the-disk-floor).
  Pools RELEASED both boxes for doyle's sequential gate legs. Thin CI 34073766394 red = env only.
- 2026-09-07 03:53Z **W1 LANDED ff: main = 9489ef60** (PR #196 MERGED 03:53:24Z, tested==merged; 8d980fdf feat + 9489ef60 hertz fixup; thin CI 34079849863 5/5 green attempt 1; #249 → ACCEPTANCE via alchemy sweep). Gate at 8d980fdf: treqs/xtask/clippy 0, nextest 1765/1765, e2e 1/1; local pair A 3/3; arms A/B exactly as pre-registered. ONE finding, TEST: twohost_web role B's completion witness (net_streams polled 250 ms) saw 0/3 rows B provably served (WEB_STREAM breadcrumbs 403/200/206) — served rows leave the table via retire_stream/retire_stream_terminal before the poll; first-ever real execution (kitsubito's leg had been the env-gated no-op). hertz fix = `run_dispatch_loop_observed` served counter, count-before-retire, FLAKE-LEDGER row 49 NOT a flake. Re-gate at 9489ef60 both boxes: 963/963 slice, pair 4/4 (B 1/3..3/3 in 21 s), arms hold with B completing, cross-box pair GREEN over tailscale (kitsubito B 46.6 s; fixup carried there by format-patch + git am, tree ab30c429 identical, no push). FOUR rig defects, all mine, all memories: treqs exe flipped 0.2.0→0.4.0 under the gate by an unknown hand (CI pins 0.2.0; pinned back; IR-37 lane needs a third arm for the file-root drop); git-bash `tasklist /FI` → path; pair wrapper exit = last grep's (mutation arms ran on a red baseline, killed + reverted by hand); one-box pair ports 7460/7461 collided (cell 1 on B's broker); plain ssh to kitsubito has no cargo on PATH. Disk: pool 176 GB → reaped debug/incremental 38.9 GB + hertz-released main target 14.4 GB (preservation re-verified off disk), free 28 → 75.3 GB before the push (CI floor 32 GiB). Records `.spt/preserved/gate-w1-9489ef60/`. Ruled for todlando W2: --reply-to = amend REQ-SEND-REPLYTO-REMOVE by replacement + repin same change + ADR-0061 supersession note naming ADR-0020; #17 remote arm builds FIRST once the pool is his (order, not a drop); envelope-consequence cells named + repinned in-lane with the clause cited. Box order after land: hertz row-46 thin PR now (boxes free) → todlando W2 compile may overlap, W2 battery/PR wait for hertz's CI.
- 2026-09-07 04:05Z Post-clear re-ground: main 9489ef60 both sides. +52 GB free EXPLAINED: push-to-main CI 34081163501 (fires on the ff push, both boxes, started 03:53:25Z) — its Windows unit checkout git-cleaned the runner's ~50 GB target; my 03:54Z 'boxes free' was wrong for ~20 min, corrected to hertz + todlando (memory a-pr-open-is-a-ci-battery-on-both-runner-boxes.md 2nd face). hertz row-46 lane test/viewer-attach-monotonic @bfb5d58a (3 files +65/-16, no PR yet) gating in the main-checkout pool beside CI + todlando's W2 compile + an editor rust-analyzer check (pid 13452); told him a load red is suspect, PR opens after the main CI concludes. IR-37 MEASURED by hertz: [placement] module_banner=accept clears 305/313; 8 residual = int/unit tags in markdown prose (4 docs), coverage-checked load-bearing NONE; 83 missing_stage = single-FILE [scan] root (CONTEXT.md) credits nothing in 0.4.0. RULED: items 1-3 in-lane (8 deletions one commit, body lists each with surviving evidence); item 4 needs ARM C (dir root + excludes) before any upstream question; traceable-reqs project untouched, NEEDS-OPERATOR with repro if C fails; pin-bump PR opens only after W2 lands.
- 2026-09-07 04:22Z GATE-W2-272-CHECKLIST.md STAGED (repo root) against W2 head 58f0e2c8 (2 commits on 9489ef60, 32 files +4114; #17 remote arm present as commit 2; ADR-0061 supersession + REQ-SEND-REPLYTO-REMOVE amendment present). Pre-empts sent to todlando: api.md now-signal category list + llms.txt absent from his diff (docs lines); ws272-w1 pool 137 GB = his W2 headroom, preservation confirmed by me (.spt/preserved/gate-w1-9489ef60), reap is his with numbers; /m/<id> body-resolution design approved. IR-37 CLOSED IN-MANIFEST by hertz ARM C/D (roots=['.'] + git=auto + exclude → 882/882 complete; 0.4.0 spec says dir-only roots, our manifest was the bug; sharp edge = a file root is SILENTLY ignored, register note only). RULED: fence with the reason comment in the manifest (quote-docs vs evidence-docs), design docs stay in scope and get cleaned, 12 deletions after the same redundancy check, one commit body; thin PR opens after W2 lands (bump ci.yml:246 AND golden.yml:1320). Row-46 gate: claim 0, nextest 3/3 green under load (evidence; load fakes reds not greens); clippy+treqs pending; PR after main-push CI 34081163501.
- 2026-09-07 04:32Z hertz row-46 lane LANDED ff: main = bfb5d58a (PR #197 MERGED 04:32:01Z, tested==merged, CI 34082336298 5/5 first attempt, Windows unit 16m37s). My source read PASS (test-only seam test_session_viewer_attaches; next_viewer_id written only at init + add_viewer). hertz's own framing kept in the record: fix holds where the defect fired; the old assert was NOT re-run in these windows. Ruled (b) for the box: a PR run is the battery; todlando's W2 battery after land + rebase. todlando reaped ws272-w1 target (137.33 GB real dir, free 110.79→245.41 GB) and built the #17 remote arm first (ServeFor/ServeForReply, helperline carrier instead of forging attachments); clippy round 4 at his report. IR-37 fully measured + written (.spt/ir37-redundancy-evidence.md), opens after W2 lands.
- 2026-09-07 04:40Z W2 F1 (my gate finding, raised before the battery): serve_for lacked the ADR-0058 Am.1 user-attach-session binding — default-on WEB + audience-on-requester + path rules = any subnet node exposes any owner path to itself 24h. todlando confirmed REAL, built local_msg_out_in (owner's own MSG_OUT row, flat+nested perches, last 512 rows) + conjunct (3) in serve_for + 7 int cells (refusals assert registry EMPTY) + 2 unit; his old int arm had passed on a never-sent origin = the hole. Memory: walk-a-refusal-chain-under-the-default-posture.md. W2 rebased onto bfb5d58a (4 commits), battery after main run 34083455082 Windows unit.
- 2026-09-07 05:20Z W2 battery #2 at 37e31324+: 6/2441 red, ALL in todlando's new code (extractor fixed-point trim, helperline torn-tail fuse, help 80-col, attachment-rig precondition), zero pre-existing → envelope-consequence family EMPTY; cross_node VOID by my ruling (his mid-battery patch slip, self-reported, reverted) → solo breadcrumb re-run is the decider. Filter gap caught by me (kind(bin) never selects tests/ binaries), his POPULATION meter counted 1 of 1673 (phrase regex) → fixed to row count. Two new memories: walk-a-refusal-chain-under-the-default-posture (F1), a-population-floor-proves-the-filter-selected-something-not-the-right-something.
- 2026-09-07 05:30Z W2 solo cross_node leg: exit 100 before arm (i) — 'brain IPC read deadline' at :629 = RIG-SHAPE (test process dialing B with its own Brain; production's request_serve_for runs inside the receiving daemon). RULED (a): drive the int arm end to end (user-attributed send A→B quoting a path; B helperline gains the line; A registry vi; B fetch vii), refusal arms same way asserting registry+helperline unchanged; gate mutation = disable ingress caller → vi/vii red. (b) = the 4 spt-store unit cells (already green), cannot close an 'end to end' int stage; (c) twohost_web is golden-only. todlando communing across at 70%; next session builds (a) → solo leg → 4 fixed cells → PR. Ledger GATE-W2-272-CHECKLIST.md carries all of it.


**2026-09-07 07:30Z:** hertz PR #198 (rig-advisory-ports + HEAVY-at-birth, 12 binaries into HEAVY, xtask classification check) LANDED ff at ff4b405d, tested == merged, push run 34095728691. W2 (todlando) yielded 07:28Z with leg 1 unwitnessed-on-one-box (helper/range TIMEOUT by construction) and leg 2 = a REAL W2 defect ruled in-lane (spool rows never carried the short_id) fixed + unit cell + falsifier + attach9 green; rebasing onto ff4b405d, PR next. Gate record = GATE-W2-272-CHECKLIST.md (rulings 06:26Z-07:30Z + golden discriminator baseline).


**INCIDENT 2026-09-07 08:03Z (unresolved, evidence recorded):** fleet daemon pid 14444 (up since Sep 4) died abruptly ~08:03:15Z — stderr ends mid-stream on ordinary lines (last 08:03:14.87Z), no shutdown/panic line, no WER dump, alchemy adapter left orphaned (a graceful stop tears services down). Fresh gen-0 cold daemon pid 48232 autostarted 08:03:20Z from the INSTALLED exe by a transient spt CLI (parent 59384 gone); it DAEMON_RESTART_RESUMEd every live session (doyle, deployah, todlando…) — the resume REBINDS CC sessions (new task dir, SessionStart hook, orphaned Monitors/agents, STALE brief from an old commune), which is what a "CC process died" report actually is. Temporal correlation: CI run 34097634781 Windows unit leg started its nextest run at 08:03:15.80Z (26 binaries, 3101 tests) — same second; but ci.yml unit job has NO reap step and no kill verb (reap-census.ps1 is golden-only), and no test in the death window (311 done by 08:03:20) is a daemon-stopper by name. todlando: no kill verb all session (his only live process was a gh poll). hertz: pending. Gap found: the daemon leaves NO record of HOW it died and the autostart logs no "found dead pid X" line — IR candidate (death-cause breadcrumb at autostart + supervisor exit-code capture). Also: todlando+hertz echo-communes REFUSED (Codex usage_limit_reached) — their minds are stale until the account is restored.


**2026-09-07 08:30Z — hertz's three deliveries on the 08:03Z incident (doyle verified the census headline at source):** (1) INSTRUMENT ARMED: `C:\Users\decid\.spt-watch\daemon-watch.log` (+ watch-daemon.ps1, watcher.pid), outside the repo on purpose; 1 s cadence on fleet daemon pid 48232, path+creation-time re-verified every poll (a reused pid logs IDENTITY-CHANGED, not alive), every-30th-poll heartbeat (stale last line = watcher died), on death dumps a witness list (cargo/rustc/nextest/spt/Runner/…) and timestamps the replacement. Two instrument faults he hit and fixed: AllSigned policy → `-File` refused, process ran but log stayed EMPTY (caught by checking for the first LINE, not the process; fixed with -EncodedCommand); a command-line census matched ITSELF (found "the watcher" 4× incl. his own probes; fixed by verifying from watcher.pid). His only kill tonight: ~08:17Z, one of his own powershell probes. (2) KILL-BY-REMEMBERED-PID CENSUS `.spt/PID-KILL-CENSUS.md`: owned-handle kills (22 sites) safe by construction; GUARDED servicehost.rs:651 (image-path rule) + livehost.rs:1135 (positive match else DECLINE); **UNGUARDED broker.rs:8102 zombie reap — `kill_pid_tree(spid)` on a pid remembered in the session record, `session_is_zombie` consults liveness BY NUMBER, never reads the live image (doyle confirmed at source 08:30Z)**; narrow: daemon.rs:3472, shellhost.rs:639. Honest limit: this does NOT explain 08:03:15Z — the daemon had a live brain so `has_live_descendants` returns false; protection is ACCIDENTAL. Adapter half incomplete (4 of 5 uncensused: sources are ~/Documents/projects/spt-pacer-tool, spt-alchemy, spt-claude-code, spt-mobile; omp-spt done, owned handles only). (3) Board paragraph drafted: fleet daemon pid 14444 wrote 303,128,498 B stderr over ~72 h; final 2 MB = 3,238 write-start + 3,086 transport-close (role=brain, REQ-CONN-POISON-ATTRIBUTION) + 1,163 NET_FAMILY_GATE lines; conn ids reached 720,837; every retired conn never reused (CONN_WRITE_RETIRED BrokenPipe os 232). Whether churn is a defect or the log merely loud is NOT established — file it saying so. DISPOSITION (doyle): broker.rs:8102 image-guard = PRODUCT change → board BUGFIX (todlando lane after W2; fix shape: lift `same_image` into `kill_pid_tree` so no caller can forget); conn-churn = board BUGFIX; autostart death-cause breadcrumb = IR. All three queued until alchemy shells are back online.

**08:35Z hertz adapter census COMPLETE (`.spt/PID-KILL-CENSUS.md`):** pacer-tool 0 kill sites; alchemy 1 owned handle; mobile 2 owned handles; spt-claude-code 7 across 4 CI scripts — the only adapter with remembered-pid + by-NAME kills. **UNGUARDED, worst shape: `ci/psyche/live-relay-int.sh:78` = `tasklist | grep -i claude-spt` → `taskkill //PID //T //F` for EVERY claude-spt.exe on the box, no run-scoping** (a shared runner = every other agent's live adapter). Guarded in the same repo: bind-int.sh:50, multi-subnet-bringup-int.sh:117 (cmdline-like '%$ID%'), wake-survival-int.sh:64. Same shape as core (servicehost.rs:651 guard beside broker.rs:8102 bare number): knowledge present, no rule making the scoped form the only reachable one — THAT is the IR entry, not either patch. Does NOT explain 08:03:15Z: all sites enumerate claude-spt.exe, the dead process was spt.exe, the box job was spt-core's unit job; residual (//T tree-kill of a claude-spt.exe whose descendant was the daemon needs the detached spawn to have failed — nothing shows that) recorded, not claimed. Filed to perri as a filing with the non-attribution stated. Watcher healthy poll 330. hertz filed the two instrument faults into his own memories (grep-l-census-counts-name-collisions; instrument-soundness-guards guard 3).

**08:40Z IR-81 drafted (hertz, `.spt/ir81-draft.md`; register tops at IR-78, 79/80 his drafts):** "make the scoped kill form the only reachable one", paired-exhibit table (servicehost.rs:651 vs broker.rs:8102; bind-int.sh:50 vs live-relay-int.sh:78), explicit refusal of "fix the two sites", three remedy shapes, standing not-a-closure bullet. RULED doyle: keep all three inclusions; remedy = BOTH (a) identity requirement pushed into `kill_pid_tree`/`kill_pid` = product, todlando post-W2 (this is the 8102 BUGFIX's fix shape, so IR-81 and that board item cross-reference), AND (b) xtask grep gate for unscoped tasklist/Get-Process→kill and bare taskkill in CI scripts = test-craft, hertz, rides the IR-37 thin PR; (c) listed as considered-and-loses. Files when alchemy is back. Watcher poll 420, alive.

**08:50Z perri closed the claude-spt half of IR-81:** live-relay-int.sh:78 broad kill + 3 remembered-pid tree-kills fixed + guarded, claude-spt commit 9c87372, REQ-HAZARD-CI-KILL-SCOPING, gate green, test-only no release; she restates non-attribution (none match spt.exe). IR-81 exhibit stays as the historical RED (cite 9c87372 as the adapter-side close).

**11:15Z incident sharpened (hertz, from the preserved job 101664801162 log):** LIST phase bracketed `Finished test profile` 08:03:08.010Z → `Starting 3101 tests across 26 binaries (1 test and 200 binaries skipped)` 08:03:15.805Z = 7.795 s, 226 binaries touched; pid 14444 died 08:03:14.87Z = 6.86 s INTO that window, 0.93 s before the first test. The pending Windows unit leg of run 34105034028 is the SAME workflow/runner/~226-binary LIST phase → a genuine repeat, not an analogue; alive-through = hypothesis tested-once (does not refute pid reuse). Incident stays OPEN either way: no killer shown.

**11:30Z LIST-phase natural experiment — ALIVE THROUGH (hertz, run 34105034028 Windows unit job 101688097059):** window `Finished test profile` 09:26:17.780Z → `Starting 3114 tests across 26 binaries` 09:26:27.901Z = 10.121 s, 226 binaries (30% MORE exposure than the 7.795 s window that killed 14444, same workflow/runner). Watcher pid 48232: ~9 probes inside the window, DEATH/IDENTITY-CHANGED logged unconditionally per poll (script lines 27/45; only heartbeats are sampled) → zero death, zero identity change, zero witness = a NEGATIVE, not a sampling gap. Pid-reuse hypothesis: untested → tested-once, negative; does not refute (probabilistic). **Incident stays OPEN — no killer shown.** Discriminator: Windows ci 3101 → 3114 (+13) exactly as posted before the leg; equal +13 on both OSes = platform-neutrality RISKED and survived. Side flag RETRACTED by hertz 09:36Z (25 min after posting, before anyone acted): Windows leaky 8 → 8 → 5 across ff4b405d/e3bd53d4/401a19ad is THRESHOLD NOISE, not improvement — name diff: 9-cell union, only 4 present at all three shas, 3 vanished + 1 appeared, and the three W2 commits touch ZERO files in brainproc/spt-live/spt-runtime/shellwake/broker (no causal edit). RULE: a leaky COUNT is not a quality signal in either direction; require the name diff + a causality check against changed files. Real signal that survives: all 9 union members are child-spawn-then-kill/timeout/corpse cells — same seam as IR-79 (rigs leak daemons on a failing assert) and IR-81 (kill scoping); IR-80 reframed as 3 stable brainproc + 1 intermittent, census framing dropped for doyle's one-cell mechanism probe (trial_kills_alive… on Windows: killed pid still present with the pipe handle open?), leaky at all three shas.

**2026-09-08 12:03Z — W3 GATE BATTERY LAUNCHED at `ff034bf5` (todlando's lane).** Head =
bf6f493d (my 5 commits + hertz's 2 drift riders) + ONE fix commit. hertz's `fa7c4aa4` is
SUPERSEDED by patch-id, NOT merged (`origin/test/ws272-w3-drift` left as the lane record).
Two reds, both mine, both closed at a named mechanism before the gate:
RED 1 `E0432` — the riders import `gen_changelog`/`PUBLISHED_DOC_PATHS`, seams the rider
contract named and I never cut. Fix: `gen_changelog(root,check) -> Result<(),String>` (root
parameterised + RETURNING so the drift arm is callable; exit stays at the CLI edge in `gen`),
and `PUBLISHED_DOC_PATHS` REPLACES the scanner's local array rather than sitting beside it.
RED 2 (found by my own nextest, ruled by doyle) — `widen_cut` cut VISIBLE body codes, i.e. the
page was laundered rather than gated, contradicting the 2026-09-06 16:20Z ruling in
`WEBSERVE-272-W3-DRIFT-RIDERS.md`. Fix: `None` outside an HTML comment + the author rewrites
the two ` (releases#222)` citations at CHANGELOG.md:328/339. Generated page byte-identical
either way — only the REASON moved from generator to source.
Evidence (run 3, alone in the pool): gen/clippy/nextest/check/treqs all 0, `procs-before: []`,
Summary count 1, 99/99. Runs 1 and 2 VOID — I restarted a battery without stopping the first,
two writers into one output dir over a tree I edited mid-run. Driver `.spt-fix-driver3.sh`
now locks the OUTPUT dir, censuses procs-before, and refuses on a Summary count that is not 1.
Disk: my cold pool hit 75 GB and took the box to 39.3 GB free (BELOW the ~80 GB nextest floor
that voided a leg on 09-07); reaped after classifying → 114.3 GB, +74.9 measured; hertz reaped
two more finished-lane pools → 125.8 GB. Gate ETA 60-90 min; field arm pin 2b after.

**W3 LANDED 2026-09-08 14:08Z main=fd296557** (PR #201, ff, tested==merged): #265 adapter docs facet, #268 changelog page, #266 LAN bootstrap, #246 XFER-retirement rider; three reds before the shipping sha (bf6f493d E0432 seams; generator laundering; ff034bf5 census stale + unnamed ParentDir refusal), every one closed at a named mechanism; field arm pin 2b WITNESSED at fd296557 (release 3 applied on rig A, LAN fetch sha==printed==sidecar from kitsubito, docs loopback-only, rig B unsigned-exe). Register candidates: apply-relaunched daemon re-mints env from the CLI caller (advisory flag lost -> 5474 collision); POOL_GUARD per-leg line (hertz rider 3); doubled 'manifest invalid:' prefix; pre-nextest disk re-measure. Rigs A (55496, release 3) / B (365022) LEFT UP. NEXT: hertz queue (65 s rider, refusal-arm cell, #287 thin lane, rider 3), golden head to deployah.

**2026-09-08 14:08:18Z — W3 LANDED.** PR #201 "WEBSERVE W3 — changelog page, adapter docs
facet, LAN bootstrap, XFER retired" merged ff; `origin/main` == `fd296557` == the gated sha
(tested == merged). Lane = my 5 commits + hertz's 2 drift riders + my 2 fix commits. Three
gate reds, all closed at a named mechanism, none by rerun (E0432 uncut seams / laundering
generator / stale census + unnamed refusal). Measured by me from `gh pr list` and
`git log origin/main`, not from a report. NEXT: v0.68.0 WEBSERVE milestone close (doyle's),
issues 268/265/266 close from #201, #246 was already closed at W2 by #199.

## GOLDEN INTAKE + SHAPE (deployah, 2026-09-08)

Assembled head from doyle: `fd296557` (== origin/main, ff; W0 c33dc521, W1 9489ef60, W2 bccfaee8, W3 fd296557; thin lanes #198, #200).

**Intake verdict GO**, recorded as comment 5586834724 on releases#272 BEFORE the run.
- Parity PASS against the greenlight SNAPSHOT (the 2026-09-06T10:24:57Z intake comment), not a reconstruction: all 8 riders #248 #249 #246 #265 #268 #147 #266 #17 at ACCEPTANCE; #148 BACKLOG, #271 SHELVED (both greenlight-time rulings, not drops). Zero dropped, zero added. XFER retirement (21c14703 + fd296557) and IR-76 pre-flight (8d7b8289 + 7c435564) were greenlight-time CLOSE RIDERS, so no add-discharge owed.
- Head was UNSHAPED (`0.67.1` / `## [Unreleased]`) — the documented default. Shaped on top per IR-54: **shaped sha `2f4229908ad1bf990b7413b2f218f622b59a20fa`**, diff vs assembled head = CHANGELOG.md, Cargo.lock, Cargo.toml, docs-site/src/changelog.md, ZERO .rs; lock diff exactly 14 first-party pairs (proved by diff).
- Counter for the cut = **104**, decoded from v0.67.1's published `.release.json` (`version: 103`). Compat constants unchanged at the candidate by diff: `BROKER_RESOURCE_ABI = 1`, `brain_ipc_version: 1`, release.rs moves one line in the range (helper visibility).
- Never-executed-cells list was MISSING from the hand-off -> bounced as a hand-off defect (not filled here). doyle delivered branch `never-executed-272` @ `0a122453`; file sha256 e5e1f307... matched byte-for-byte. **172 cells added since the last golden, 172/172 at their FIRST CI EXECUTION at this run**, 60 never in any GitHub job. Triage pre-declared: a red on one is structural-until-shown-otherwise, mechanism first, no same-sha rerun.

**Golden run `34239258523`** (workflow golden, event push, ref `golden/webserve-272`), pinned by FULL sha at push time.

Shape worktree `.worktrees/shape-0680`, pool claimed as lane shape-0680 and released after gen/check.

**Attachment hosting gotcha, measured 2026-09-08:** an alchemy comment attachment is uploaded to an **untagged DRAFT RELEASE** on `spt-bs-releases` (`.../releases/download/untagged-3ecc0debcb4b3bffe480/shx-…-NEVER-EXECUTED-CELLS-272.md`). At publish time that draft sits beside the release draft being cut — do NOT mistake it for the cut's draft, and do not reap it: deleting it breaks a board comment's attachment link.

## r1 RED + r2 LANE SET (2026-09-08)

**Golden r1 `34239258523` @ shaped sha `2f422990` — RED, respin ruled.** Linux test job 102104983586 (3 reds), Windows test job 102104983643 (4 reds: `Summary` says 4 failed; `FAIL + LEAK` row nearly cost me one). Mechanism named at source by doyle: `crates/spt-msg/src/emit.rs` `splice_typed_msg` (new in W2 `92715374`) rebuilds the envelope from `parsed.attrs` while `compose_typed_event` also writes `type`, and `parse_attrs` keeps `type` in the list -> **every delivered envelope carries `type="msg"` twice**. W2's own unit cell passed because `attr` returns the FIRST match and nothing counts occurrences. Fourth Windows red = `io_events_undriven_kinds_e2e::relay_backlog_...` — a W2 cell on the never-executed list's 60 (first execution in ANY GitHub job, red on first firing). `gateway_e2e:225` is a different face: a REPIN (spool holds the pre-composed envelope; doubling is at delivery).

**doyle's stated gate gap (the durable lesson):** the population that needed re-running was the CHANGED SEAM'S CONSUMERS, not the added cells. My never-executed leg cannot catch that class by construction. He is adding a "which cells drive a seam this batch changed, and when did each last execute" artifact to the intake checklist (lane `docs/intake-changed-seam-consumers` @ 1a9f5d23, NOT in r2).

**r2 lane set, ruled final by doyle 15:38Z** (land order 1,2,3, each ff on its own gate):
1. todlando `fix/272-splice-double-type` @ `4be9e5c9` — product fix + counting cells
2. hertz `test/272-gateway-spool-envelope-repin` @ `d84fbdf6` — test-only repin
3. hertz `test/twohost-web-per-cell-identity` @ `17443615` — test-only rider; four role-A cells shared ONE node id across four ports, iroh keys path state by node id -> B handshakes a dead port until liveness expiry (Win 63.371->1.299 s, Linux 69.096->2.072 s)
NOT in r2: hertz `fix/ir84-pump-peer-budget-instrument` @ `6383de2f` (fixes no red, clippy unrun), doyle's docs lane.

**r2 protocol agreed:** not-an-ancestor check against `2f422990` explicitly, version material authored FRESH (a respin RE-SHAPES, never inherits), push `golden/webserve-272-r2`, counter stays **104** (nothing published consumed it). Reuse `.worktrees/shape-0680` + its warm pool, re-claimed under a new lane label.

## r1 VERDICT POSTED + FINAL MECHANISM (2026-09-08 16:0xZ)

Run `34239258523` TERMINAL: status=completed, conclusion=failure, **9/9 jobs** (the ninth is `notify`, NOT `verdict` — `verdict` was a name I guessed off golden.yml's `needs:` list; the late-materialization trap is real, that name was not). Board record = **#272 comment 5588134766** (r1 verdict), after 5586834724 (intake) and 5586872072 (never-executed precision).

**Mechanism 2, final wording (doyle's source ruling, verified by me):** four role-A web cells run as THREADS in ONE process (pid 52964, broker udp 7480-7483) all keyed `id_a`, and only cell 3 owns a dispatch loop. B dials `id_a`, the handshake completes against a live same-key sibling with NO loop, so the stream is accepted and never read. `two_host_web_helper_role_a` (A, 900 s) and `two_host_web_role_b` (B, 1260 s) are ONE transaction's two ends. `cargo test` (threads) shows it as a silent hang; the gater's nextest rigs (process per cell) showed the SAME defect as a 63 s stall — that is why hertz's lane 3 measured a stall and golden measured a hang. **Lane 3 `17443615` is FIX-SET and fixes it by construction; r2 stays THREE lanes, no fourth, no descope, #17's remote arm ships.**

**`NoReply` is NOT a peer's answer** — minted only at the requester's own NetStreamEof arm (`wan.rs:306-307`). My "A refused custody + missing breadcrumb as an independent defect" reading is WITHDRAWN; see [[dont-infer-a-mechanism-from-wording-open-the-emitter]].

**Four hypotheses died by measurement this arc** (each had an advocate): build-contention window (failing batch began 15:36:06Z, load ended 15:31:02Z); identity churn (the PASSING ladder shows the same ~30 s cadence); re-stamp-on-arrival (sibling decline branches carry different text); vacuous web passes (A carries all three owner-side proofs — **W1/W2 cross-node serving is proven green at this sha**).

**Two register items, neither #272's to fix, both named in the r2 intake comment:** the unbounded WAN reply read (`ec360f16`, 2026-06-30, present at `04e32c8c` — B waited 21 min against a 900 s budget) and the silent accept (a daemon that accepts a WAN stream it will never read logs nothing).

**Preserved + cross-checked identical with the gater:** lin-test `a8040e81…`, win-test `c89b4a6a…`, twohost-a `83241b20…` (338,891 B), twohost-b `0be18031…` (520,777 B), NEVER-EXECUTED-CELLS `e5e1f307…`.

**NEXT:** doyle lands 4be9e5c9 -> d84fbdf6 -> 17443615 ff on main and hands ONE assembled sha. Then: not-an-ancestor check vs `2f422990`, FRESH 0.68.0 version material (bump + lock 14 pairs + CHANGELOG + `xtask gen`/`check`), push `golden/webserve-272-r2`, pin by FULL sha, r2 acceptance = the two twohost cells green with B's SERVED count read. Counter **104** unconsumed. Reuse `.worktrees/shape-0680` + warm pool (re-claim under a new lane label).

**2026-09-08 16:25Z — GOLDEN r1 FAILED, three fix lanes; LANE 1 (mine) LANDED `4be9e5c9`.**
Golden 34239258523 at 2f422990 red on four e2e cells: `splice_typed_msg` carried the parsed
attrs whole, so EVERY delivered envelope read `<EVENT type="msg" type="msg" …>` since W2 (W2 put
the splice on every send; before it, a plain body never reached it). Fix = `ParsedEvent::
carried_attrs()` (the attrs a re-compose MAY carry) + two COUNTING cells, both falsified at exit
100. PR #202 ff, tested == merged. **The four cells did NOT go green and were never meant to:
they were red for TWO reasons** — my doubling AND literal expectations predating W2's `msg-id`
(hertz's repin, lane 2). Acceptance was the FAILURE TEXT changing beside hertz's peer-measured
BEFORE at `fd296557`. I misclassified the fourth cell (io_events :635) as the same literal
shape; it asserts `contains(LIVE)` and the live message is ABSENT — corrected before hertz acted
on it. Also settled today: the twohost pair is hertz's same-key collision (four A cells in one
process, pid 52964, B dialled a sibling with no dispatch loop), not my splice — deployah
withdrew the breadcrumb datum after my source read of `wan.rs:1067`. NEXT (queued, not started):
**releases#289**, the unbounded `brain.read_event` reply read in `request_wan` (wan.rs:283-312,
NoReply only on EOF, pre-existing since `ec360f16`) — bounded read + DISTINCT outcome + a
fake-peer cell that accepts and never replies. Starts only when doyle hands the issue after r2
is pushed. Lane set for r2: 4be9e5c9, d84fbdf6, 17443615, ff in that order; counter stays 104.
