## Stacking **Stacks on #216** at frozen product SHA `9d71871905766e293322eb94ed0748d04d7aba75`. Base is main; assemble #289 -> #293 -> this census sibling. No further product-lane push. Candidate: `1ebd03dcd66fcc794ed86b16cefb88621f01f045`. Module commit `c0ef040c` is equivalent to hertz's `0c7c3d49` by patch-id `d7f74d2b`. ## Change - Add `xtask::brainread` pure lexical predicates and synthetic-input unit tests, authored by hertz; wire the real-tree audit into `xtask check`, which golden runs on both OSes. - Refuse retired reader calls/declarations across crate Rust sources, including tests; refuse call_deadline inside serve_*_feed or serve_attach bodies. - Require the nine existing feeds plus attach to retain explicit None and preserve representative reply-wait controls, including peek_first_line. - Activate unit evidence on REQ-BRAIN-READ-BOUNDED-PER-CALL. Predicate tests consume synthetic Rust text, not repository files. - Update the existing hazard 7.6 amendment with the static enforcement path and remove the stale resume panic-message mention. No new hazard entry. - Add the focused `brain-read-check` command to thin CI's Linux lint job after clippy. It runs only when the changes job classifies code=true; docs-only PRs skip it. Golden retains full `xtask check` on both OSes. - Regenerate the changelog page for the frozen #216 entry: separate docs-only commit `7a5e5093`, exactly six added lines from doyle's generated patch. ## Local proof No Cargo run or CI-runner contention. Main independently repeated these after integration: - `rustc --edition=2021 --test crates/xtask/src/brainread.rs -o ` followed by that executable: **4 passed, 0 failed, 0 ignored/filtered**. - Standalone Rust driver compiled against the actual module and called `brainread::check(repo_root)`: **BRAIN_READ_AUDIT_OK: 501 crate Rust files; nine feeds + attach explicit None; four reply controls; zero retired reader symbols**. - Throwaway fixture using the three actual production source files: feed call-budget insertion, attach call-budget insertion, rearmed peek reply budget, retired member call, and retired declaration each returned **exit 1 with named file/line diagnostics**. Restored fixture returned **exit 0**. - Exact production `repo_root` and `check_brain_read_policy` functions compiled into a standalone driver: the real tree emitted the success line on stderr and exited 0; a missing tree emitted `xtask check: FAILED -- Brain read policy` plus its named diagnostic and exited 1. Hertz's predicate module stayed unchanged. - Doyle's independent module gate reports the pre-fix main tree fails with 100+ findings; this negative control is separate from Main's five mutation checks. - `traceable-reqs check --json` after the final registry hand-edit: **893 complete / 893, zero findings** with required stages doc/impl/int/unit. - Temporary executable/fixture scaffolding removed after proof. Unrelated rustfmt reflow was removed before `05e96e11`; the subsequent CLI arm and usage change implement the accepted thin-CI correction. **Complete-run gate pending.** At this SHA, deployah read `BRAIN_READ_AUDIT_OK` in run `34424166884`, attempt 1, lint job `102705969612`, at `01:10:06.5954548Z`. Both unit cells were still running at his latest observation. Main's own exact-command proof awaits the exclusive warm-worktree handoff; doyle's separate proof below is not presented as Main's execution. ## Gater command evidence at this SHA Doyle ran these on kitsubito at `1ebd03dc`, `01:06:59Z–01:08:06Z`: - `cargo run -p xtask -- brain-read-check`: clean **exit 0**, `BRAIN_READ_AUDIT_OK: 501 crate Rust files; nine feeds + attach explicit None; four reply controls; zero retired reader symbols`. - Landed exactly one mutation in `serve_registry_feed`: explicit `None` replaced with `brain.call_deadline()`; dispatch.rs **1 insertion / 1 deletion**. The same command returned **exit 1**: ```text xtask check: FAILED -- Brain read policy BRAIN_READ_AUDIT_FAIL: crates/spt-daemon/src/dispatch.rs:1351: serve_registry_feed: stream lifetime must not use call_deadline crates/spt-daemon/src/dispatch.rs:1327: serve_registry_feed: explicit stream/reply deadline control missing ``` - Restored dispatch.rs; the same command returned **exit 0**, with the same OK line. Both predicates identified the one changed feed; sibling feeds stayed silent. - Full `xtask check`: **exit 0**, `xtask check: OK`. Clippy: **exit 0**. xtask bin nextest: **103/103 passed**. Raw gate artifacts: kitsubito `~/gate-293c-out/b-*.raw` and `legs217b.log`. The pinned checkout SHA establishes provenance; matching output/counts alone do not establish tree identity. ## Product runtime evidence remains separate The real-IPC pumpdeadline regressions belong to #216. At 9d718719: all-target workspace check passed; `cargo test -p spt-daemon --test pumpdeadline -- --test-threads=1 --nocapture` passed 5/5 in 2.21s. Those results establish the product head, not an assembled-head runtime result for this sibling.