---
name: w2-two-key-subnet-progress
description: "W2 (two-key subnet) of milestone A ACCESS-CONTROL — committed, gated green, PR #121 open against build/acl-core awaiting doyle's gate"
metadata: 
  node_type: memory
  type: project
  originSessionId: f438335b-fb84-458b-874d-de4b67400c4b
  modified: 2026-07-29T14:39:34.883Z
---

W2 = two-key subnet, milestone A (ACCESS-CONTROL). Committed **@4972b6d** on `build/two-key-subnet`, pushed, **PR #121** open against base `build/acl-core` (NOT main), `fixes BigscreenVR/spt-bs-releases#15`. Gate green 2026-07-29: check + clippy `-D warnings` clean workspace-wide, units 65/12/7/113, int pairjoin+access 3 and n1_pairing 1, `traceable-reqs check` exit 0.

Shipped: **T2** admin-code join (responder answers the same `msg_a` twice, member candidate LEADS, joiner builds two side-A states over one scalar via `start_a_with_rng`); **T5** advisory mode gossip (`classify_mode_gossip` pure Capture/Advise/Nothing, split from I/O); **T6** `spt api access-refresh` minted-but-refusing until W3; **rider** loud `ACCESS_STORE_MINTED` on baseline mint.

⚠ **Open gate condition doyle ACCEPTED and will re-derive himself, from code not from my summary:** two acceptable secrets = a **2× online-guess budget**, bounded by *rate* not count (per-subnet one-at-a-time slot + exponential backoff). That makes the rate limiter **load-bearing for a security property it was not previously load-bearing for**. Recorded in ADR-0051 §1a.

⭐ Offering the weakest point in my own work as an explicit gate condition is what got the rest of the report trusted — see [[lead-with-the-defect-that-needs-no-box]].

Still to be ruled in doyle's W2 gate: W2b sequencing, and where the admin-seed-rotation wave lands (REQ-SUBNET-ADMIN-SEED-ROTATION is minted but inactive). Next build leg after that is W3, the engine room (ADR-0052) — which is what `access-refresh` currently refuses on.

**2026-07-29 drift-fix leg:** @ecbf582 pushed (xtask gen output + T6 clap doc-comment rewrite + 9 rustdoc/ADR-0053 path fixes, one commit). ⭐ `xtask check` caught a SECOND gate pre-push: internal ADR codes in clap `///` ship verbatim into public --help (see [[cli-command-docs-drift]]). M4-D5-PLAN.md ruled OUT of drift class (historical plan snapshot). Sender-stamp rebase clean @7f572d6; battery runs gen on sender-stamp too (cli.rs +27 there).

⚠ **#121 refire (run 30451664318) Windows Phase B RED — NOT the delta (docs-only):** input_ack_deadlock::input_flood…broker :580 singleton; flood_sent=false but broker_alive+sessions_answered=true, attach leg dead ⇒ whole serve_attach path stalled >20s watchdog; test header says Windows N=64 passes even PRE-fix, so red requires a 20s+ stall not the modeled deadlock. **BOX PATTERN (hfenduleam): 3 Windows Phase B observations 2026-07-29 morning — green 11:49, red 12:11 (#122 daemon_e2e reap singleton), red 12:42 (#121 input_ack singleton). Different tests, both timing-window asserts, deltas docs-only. Box vitals at 12:50 probe healthy (92GB free, CPU 20%, no runner/cargo).** Classified environmental-suspect pattern; 3rd sighting in todlando's battery ⇒ box quarantine + RCA before anything else runs. Queue: battery → #121 at-sha Windows rerun (jumps AHEAD of hertz, W2 gate needs the green) → hertz → #122 at-sha rerun → chert push.

**2026-07-29 mechanism (todlando, revised): Phase B fully serialized (heavy group max-threads=1) — CI-vs-CI dead. ⚠ todlando's "near-red margin" claim RETRACTED by him (compared 32s total vs 20s SUB-watchdog — different quantities; do not re-bank it). Replacement arithmetic: red run only 2.0s longer than green ⇒ 20s recv_timeout expiry CANNOT fit ⇒ #121 red was a SEND-ERROR at input_ack_deadlock.rs:381 (send_attach_input Err → immediate flood_sent=false), not a stall. Test's failure message asserts "stall" for both arms = diagnostic defect (test-only fix → hertz: carry Err + op index). Happy path deterministic: 31.990/31.993s across shas/machines, 3ms apart.** Candidate root: **Phase B LEAKS spt.exe daemon children** — battery leaked 6 holding the binary (os error 5); leaked daemons on the CI runner between jobs = plausible source of the send error. Ratified REQ-CI-WINDOWS-PHASE-A-BOUND coverage gap (fleet-vs-CI unbounded on Phase B) stays live as alternate.

**W2b BATTERY GREEN @7f572d6, gate RULED GREEN by me 2026-07-29:** 8 legs exit 0, Phase A 2126/2126, Phase B 182/182 NO singleton (stop-condition not tripped), gen blob-identical, traceable +REQ-MSG-SENDER-STAMP. FLEET_PROCS: Phase A 37→37, Phase B 35→38 (green baseline). todlando lane: sender-stamp PR GO (gh only); admin-seed-rotation HOLD-prep-only (operator cut-to-B veto window open); W3 recon = slack work.

**✅ #121 at-sha rerun GREEN (13:45 UTC 07-29): all 9 checks pass @ecbf582, Windows test 21m20s — MATRIX ARM 1 FIRED, W2 CI GREEN COMPLETE.** Runner serialized #123 behind it (no co-tenancy; #123 Windows legs started 13:45:04, 10s after #121's job ended). **#123 (sender-stamp, 7f572d6) Windows RED = DISK: free 10.86GB vs 32GB n1-gate floor, both jobs fast-failed in 10s by the preflight (working as designed, v0.44.0 lesson). Code unindicted — Linux full suite green. C: went 92GB→10GB free across battery + rerun window (~80GB consumed; known hfenduleam disk-full class + tmpdir leak).** DISK RCA CLOSED: todlando's battery throwaway target = 47.08GB (bulk of 92→10GB); removed after zero-user verify, C: 55.5GB free. Disposal leg adopted BINDING (see [[gate-clean-target-not-incremental]] rule 7). NOT touched (standing infra, operator/hertz+census conversation if ever): shared-checkout target 117.46GB, runner's own target 44.64GB.

**v2 CURVE VERDICT: foreign spt.exe DIE WITH JOB (post+30s=0, zero from 13:43:08) → hertz REQ routed = FLEET-LOAD EXPOSURE on Phase B** (the ratified Phase-A mitigation's coverage gap), NOT daemon cleanup. Real finding inside the green: 6 identical foreign spt.exe persisted ~2min AFTER suite end (13:40:50–13:42:52, nextest=0), reaped by runner cleanup before job end — same count as todlando's local leak, which NEVER got reaped. Leak is real, CI-contained, bites GATE RIGS (os error 5). Both datums to hertz. **Mechanism derivation corrected (todlando struck his own n=2 claims): pass durations vary ~2s (31.990/31.993/33.887); the strong form = red 33.99 vs nearest-condition green 33.887 = 0.1s apart ⇒ 20s timeout did NOT fire ⇒ flood_sent=false via immediate send-error path at :381 (or helper Disconnected). hertz's typed-verdict fix justified by code-reading fact alone.**

**✅ #123 GREEN (all jobs @7f572d6) — sender-stamp CLOSED; W2 LANE FULLY GREEN (#121 + #123 + W2b battery).** FIFTH input_ack observation: passes 31.990/31.993/32.057/33.887, fail 33.99 = 0.1s above top pass — **duration discriminates NOTHING; send-error mechanism + hertz diagnostic fix stand on the timeout-arithmetic + code-reading only.** FLEET_PROCS 13→33 during a GREEN = load-as-sufficient-cause weakened again; hertz reframes REQ as **local gate-battery parity** (path-scoped reap before target disposal + free-byte proof), not machine-wide anything — I approved that shape.

DISPOSAL LEDGER CLOSED 07-29: flynn 3.43GB (alchemy verify), doyle 13.03GB (f438335b), todlando 19.14GB (3e92c075 + dead mirror + temp; he re-verified my attribution before deleting — correct), deployah 7.75GB (release-lane target). Box ~85-90GB free. 61a4c4e0 acl-target (1.8GB) = todlando's, possibly live, his call. ⭐ deployah's structural point absorbed: ONE CI run swings ~22GB, census between runs OVERSTATES headroom — floor is always one battery away; the job-start preflight is the honest check, disposal leg non-optional. todlando note: ADR-0052 is NOT docs/adr/0052-engine-room-enforcement.md (guessed path, doesn't exist) — locate by index.

**✅ #122 Windows at-sha rerun GREEN (~07:38) — reap singleton CLOSED ENVIRONMENTAL; rotating-victim family 2-for-2 green at-sha (input_ack + daemon_e2e reap), no second sighting, no product defect.** Remaining #122 reds both expected: traceability (operator token) + tla (chert fix). ⚠ informant AGAIN blind to tla (needs-list omission — verified job-level via gh before ruling). BOX QUEUE DRAINED: hertz UNCONDITIONAL GO issued; chert push window opened (his refire = full CI ~25min, hertz advised to plan first cargo leg around it). W3 DISPATCHED (see [[w3-engine-room-progress]]). Remaining sequence: rotation tail (operator veto) → W3 build → W4 → W5 → chert W-SPEC last in golden assembly → golden run → ff main → deployah publish → #117 riders.

Historical (superseded by green above) — rerun context: ⚠ todlando's pre-fire census RETRACTED — path-prefix filter structurally blind (see [[absence-needs-sibling-probe]] fourth surface); "empty" = UNMEASURED, not evidence. v2 poller (NULL-path = foreign/runner-context discriminator) running across rerun: foreign_spt PIDs + fleet count + Runner.Worker + nextest @15s, PLUS post-job+30s survival sample = the leg that answers the leak question. One foreign spt.exe (PID 50312) alive DURING rerun = likely legitimate test child, not a leak; leak question = survival past job end. MATRIX: (1) GREEN → gate takes green; hertz REQ routed by v2 curve — foreign spt survive job end = leaked-daemon cleanup, die with job = fleet-load exposure. (2) RED SAME TEST → product investigation, todlando. (3) RED DIFFERENT TEST → quarantine. hertz pre-briefed both items (typed flood verdict repin approved; probe_all count-not-clock approved in principle), zero-cargo until explicit GO. todlando PR #123 (sender-stamp → build/two-key-subnet) open; rotation prep-only (operator veto window).

**Gate 4 audit ruling (lia, this session):** S1 entry ≥30 approved (+31% rescaled-up pairs are the mechanism working; ±20 drift blinds ≥40 entry). Riders: slice slopes must land in 0.75–1.75 envelope else FLAG+hold; S2→S3 checkpoint (stop if S2 >~2,000 vs ~800 projected); S3 single-pass = sole ranking authority.

Related: [[access-control-grill-2026-07]], [[spt-crate-is-binary-only-no-lib]], [[gate-clean-target-not-incremental]].
