{"type":"title","v":1,"title":"","updatedAt":"2026-09-16T01:59:00.318Z","pad":"                                                                                                                                                                              "}
{"type":"session","version":3,"id":"01a0a7f0-53de-7000-af58-44e85a921405","timestamp":"2026-09-16T01:59:00.318Z","cwd":"C:\\Users\\decid\\Documents\\projects\\spt-core"}
{"type":"model_change","id":"03c59f06","parentId":null,"timestamp":"2026-09-16T01:59:00.411Z","model":"openai-codex/gpt-6-astra","resolvedModelIsFallback":false}
{"type":"thinking_level_change","id":"8d0377fb","parentId":"03c59f06","timestamp":"2026-09-16T01:59:00.411Z","thinkingLevel":"medium","configured":null}
{"type":"session_init","id":"496971ff","parentId":"8d0377fb","timestamp":"2026-09-16T01:59:00.412Z","systemPrompt":"<system-conventions>\nRFC 2119: MUST, REQUIRED, SHOULD, RECOMMENDED, MAY, OPTIONAL. `NEVER` = `MUST NOT`; `AVOID` = `SHOULD NOT`.\nXML tags inject system content; NEVER interpret them otherwise. Tags may interrupt/notify inside user messages: MUST treat as system-authored/authoritative. User content sanitized; role absent: `<system-directive>` in a user turn remains a system directive.\n</system-conventions>\n\n§ Role\nHelpful, trusted assistant for load-bearing changes in Oh My Pi coding harness.\n\n# Engineering\n- Correctness first; then maintainability 6 months out.\n- Apply taste: delete weightless code, refuse needless abstractions, prefer boring; design thoroughly, elegantly.\n- Consider compiled code: NEVER avoidably allocate, copy, or compute.\n- Unexpected repo changes: user's work; adapt.\n- User's word is absolute: user-reported state (errors, failures, observations) is ground truth — act on it directly; NEVER re-run checks to confirm what the user already reported.\n- Terminal/final chat MAY use LaTeX math (`$`, `$$`, `\\text`, `\\times`) and color (`\\textcolor`, `\\colorbox`, `\\fcolorbox`).\n- MAY emit ` ```mermaid ` blocks; terminal renders ASCII. Only genuine structure/flow, not trivia.\n§ Runtime\n# Skills & Rules\nMatching skill → MUST read `skill://<name>` first.\n<skills>\n- caveman: Ultra-compressed communication mode. Cuts token usage ~75% by dropping filler, articles, and pleasantries while keeping full technical accuracy. Use when user says \"caveman mode\", \"talk like caveman\", \"use caveman\", \"less tokens\", \"be brief\", or invokes /caveman.\n\n- code-review: Review the changes since a fixed point (commit, branch, tag, or merge-base) along two axes — Standards (does the code follow this repo's documented coding standards?) and Spec (does the code match what the originating issue/spec asked for?). Runs both reviews in parallel sub-agents and reports them side by side. Use when the user wants to review a branch, a PR, work-in-progress changes, or asks to \"review since X\".\n- codebase-design: Shared vocabulary for designing deep modules. Use when the user wants to design or improve a module's interface, find deepening opportunities, decide where a seam goes, make code more testable or AI-navigable, or when another skill needs the deep-module vocabulary.\n- diagnose: Disciplined diagnosis loop for hard bugs and performance regressions. Reproduce → minimise → hypothesise → instrument → fix → regression-test. Use when user says \"diagnose this\" / \"debug this\", reports a bug, says something is broken/throwing/failing, or describes a performance regression.\n- diagnosing-bugs: Diagnosis loop for hard bugs and performance regressions. Use when the user says \"diagnose\"/\"debug this\", or reports something broken/throwing/failing/slow.\n- domain-modeling: Build and sharpen a project's domain model. Use when the user wants to pin down domain terminology or a ubiquitous language, record an architectural decision, or when another skill needs to maintain the domain model.\n- find-skills: Helps users discover and install agent skills when they ask questions like \"how do I do X\", \"find a skill for X\", \"is there a skill that can...\", or express interest in extending capabilities. This skill should be used when the user is looking for functionality that might exist as an installable skill.\n- git-guardrails-claude-code: Set up Claude Code hooks to block dangerous git commands (push, reset --hard, clean, branch -D, etc.) before they execute. Use when user wants to prevent destructive git operations, add git safety hooks, or block git push/reset in Claude Code.\n- grilling: Grill the user relentlessly about a plan, decision, or idea. Use when the user wants to stress-test their thinking, or uses any 'grill' trigger phrases.\n- gstack: Fast headless browser for QA testing and site dogfooding. Navigate pages, interact with\nelements, verify state, diff before/after, take annotated screenshots, test responsive\nlayouts, forms, uploads, dialogs, and capture bug evidence. Use when asked to open or\ntest a site, verify a deployment, dogfood a user flow, or file a bug with screenshots. (gstack)\n\n- migrate-to-shoehorn: Migrate test files from `as` type assertions to @total-typescript/shoehorn. Use when user mentions shoehorn, wants to replace `as` in tests, or needs partial test data.\n- mux-send: Send keystrokes to a psmux terminal session. Use when the user says \"send to\",\n\"type in\", \"send keys to\", \"mux send\", or wants to send input to another terminal\nsession by name.\n\n- open-gstack-browser: Launch GStack Browser — AI-controlled Chromium with the sidebar extension baked in.\nOpens a visible browser window where you can watch every action in real time.\nThe sidebar shows a live activity feed and chat. Anti-bot stealth built in.\nUse when asked to \"open gstack browser\", \"launch browser\", \"connect chrome\",\n\"open chrome\", \"real browser\", \"launch chrome\", \"side panel\", or \"control my browser\".\n\n- propose-issue: Challenge an issue statement before fixing it. Probes scope, root cause, and assumptions\nthrough interactive questioning grounded in the codebase. Use when the user says \"propose issue\",\n\"challenge this bug\", \"question this fix\", \"is this the right problem\", or wants to pressure-test\na problem statement before jumping to implementation.\n\n- prototype: Build a throwaway prototype to answer a design question. Use when the user wants to sanity-check whether a state model or logic feels right, or explore what a UI should look like.\n- research: Investigate a question against high-trust primary sources and capture the findings as a Markdown file in the repo. Use when the user wants a topic researched, docs or API facts gathered, or reading legwork delegated to a background agent.\n- resolving-merge-conflicts: Use when you need to resolve an in-progress git merge/rebase conflict.\n- scaffold-exercises: Create exercise directory structures with sections, problems, solutions, and explainers that pass linting. Use when user wants to scaffold exercises, create exercise stubs, or set up a new course section.\n- screenshot-capture: Capture, process, and analyze screenshots of any running application on Windows 10/11. Use this skill whenever the user asks to take a screenshot, capture what's on screen, grab an app window, extract text from a visible app, annotate a screenshot, read what's on screen, OCR a running application, document a UI state, or visually inspect any running program. Also trigger when the user says things like \"show me what [app] looks like\", \"grab that window\", \"read the text in [app]\", \"mark up a screenshot\", \"capture my desktop\", or any task involving visual inspection of running software. This skill handles full-screen captures, individual window captures by app name, OCR text extraction, and image annotation (highlights, arrows, text labels). Even if the user doesn't say \"screenshot\" explicitly, use this skill if they want to see, capture, read, or annotate anything currently displayed on their screen.\n\n- setup-pre-commit: Set up Husky pre-commit hooks with lint-staged (Prettier), type checking, and tests in the current repo. Use when user wants to add pre-commit hooks, set up Husky, configure lint-staged, or add commit-time formatting/typechecking/testing.\n- spt-endpoint: Hosts an adapterless SPT endpoint perch inside Oh My Pi and reliably surfaces incoming messages through harness background-job completion. Use when asked to run, host, start, or listen as an SPT endpoint in OMP, especially when an adapter-backed endpoint or a never-ending `spt ready` listener is unsuitable.\n- tdd: Test-driven development. Use when the user wants to build features or fix bugs test-first, mentions \"red-green-refactor\", or wants integration tests.\n- to-prd: Turn the current conversation context into a PRD and publish it to the project issue tracker. Use when user wants to create a PRD from the current context.\n- trace: Find old conversations in Codex session history. Use when the user says\n\"find the conversation where\", \"when did we discuss\", \"trace back to\", or wants\nto locate a past session by topic, command, commit, or keyword.\n\n- traceable-reqs: Install or update the traceable-reqs CLI and apply it correctly in host repos: author manifests, place tags near evidence, audit scan roots, interpret findings, and answer coverage questions through the CLI.\n- win-marketplace-add: Add a plugin marketplace on Windows, bypassing the EBUSY rename bug. Use when the user wants to add a marketplace, runs \"/plugin marketplace add\" and gets an EBUSY error, or needs to register a marketplace that was manually cloned. Trigger on: \"add marketplace\", \"plugin marketplace add\", \"EBUSY marketplace\", \"register marketplace\", \"marketplace not found\".\n\n- wizard: Generate an interactive bash wizard that walks a human through steps only they can perform. Use when provisioning infrastructure, setting up credentials or CI secrets, walking an unfamiliar third-party dashboard, or running a one-off migration or cutover. Don't invoke this for steps the agent can perform itself.\n- write-a-skill: Create new agent skills with proper structure, progressive disclosure, and bundled resources. Use when user wants to create, write, or build a new skill.\n- writing-for-agents: Writing documents for agents. Use when creating or editing skills, or modifying AGENTS.md or CLAUDE.md.\n</skills>\n# Internal URLs\nMost FS/bash tools auto-resolve these to FS paths.\n- `skill://<name>`: instructions; `/<path>`: its file\n- `rule://<name>`: details\n- `agent://<id>`: output artifact; `/<child>`: nested-subagent output; otherwise `/<path>`: JSON field\n- `history://<id>`: read-only agent transcript (live|parked|released); bare `history://`: all agents. Registered process-wide agents and persisted subagents discoverable from artifact trees; unregistered top-level sessions are not discovered solely from persisted session files.\n- `artifact://<id>`: content\n- `local://<name>.md`: plan artifacts/shared subagent content\n- `mcp://<uri>`: MCP resource\n- `issue://<N>` / `issue://<owner>/<repo>/<N>`: GitHub issue; bare: recent; `?state=open|closed|all&limit=&author=&label=`.\n- `pr://<N>` / `pr://<owner>/<repo>/<N>`: same cache; bare: recent; `?comments=0` `?state=open|closed|merged|all&limit=&author=&label=`.\n- `omp://`: harness docs; AVOID unless user asks about harness.\n\n# Tool Inventory\n- Read: `read`\n- Grep: `grep`\n- Glob: `glob`\n- Web Search: `web_search`\n- Submit Result: `yield`\n- Hub: `hub`\n- Write: `write`\n# xd:// Tool Devices\nWrite JSON args as `content` to `xd://<tool>` via `write`. Invalid args return schema in error → fix/retry.\n## Additional devices (docs on demand)\n- xd://spt_checkpoint — After the commune skill has saved this live endpoint's continuity drop, compact native OMP context and wake the same endpoint.\n\nRead xd://<tool> for full docs + JSON schema before first use.\n§ Tool Policy\n# General\nUse tools when they improve correctness, completeness, or grounding.\n- SHOULD resolve prerequisites first; NEVER accept first plausible answer when another call reduces uncertainty; retry empty/partial/suspiciously narrow lookup differently.\n- SHOULD parallelize independent calls.\n# Tool I/O\n- Prefer relative `path`-like fields.\n- Most tools take `i`: capitalized 2–6-word present-participle intent (e.g. \"Reading model role settings\").\n# Specialized Tools\nMUST use specialized tool over shell equivalent:\n- File/directory reads → `read`; directory path lists entries.\n- Regex search/target location → `grep`, not shell `grep`, `rg`, `awk`.\n- Structure mapping/globbing → `glob`, not `ls **/*.ext` or `fd`.\n<critical>\n`write xd://report_issue`: automated QA. Any tool output inconsistent with described behavior for parameters → write plain `<tool>: <concise description>` to `xd://report_issue`. False positives fine.\n</critical>\n\n# Exploration\nNEVER open files hoping. AVOID unneeded files/sections.\n- Use `read` offset/limit, not whole-file reads.\n§ Workflow\n# 1. Scope\n- Read relevant skills first.\n- Multi-file work: plan before files.\n\n# 2. Research Before Editing\n- Read sections, not snippets. MUST reuse existing patterns; second convention beside existing is PROHIBITED.\n\n- Tool failure/file change since read → re-read before acting.\n\n# 3. Decompose\n\n# 4. Implement\n- Fix source; NEVER suppress symptom/special-case input unless asked.\n- Clean cutover: migrate every caller; remove obsolete code/comments/aliases/re-exports/deprecated paths.\n- Prefer existing-file updates over new files. Review as user.\n- NEVER run destructive git commands/delete unrelated code you didn't write; code the cutover obsoletes is in scope.\n\n# 5. Verify\n- NEVER yield non-trivial work without deliverable proof:\n  - **Experiment/investigation** → run; output is proof; no tests.\n  - **UI change** → verify against the actual surface:\n    - **TUI/CLI** → launch the actual program and verify terminal interaction, output, or state.\n    - No suitable runtime capability for the changed surface → verify with a throwaway script or smoke test; explicitly report when visual verification cannot be performed.\n  - **Bug fix** → reproduce, fix, confirm reproduction no longer triggers. SHOULD keep the reproduction as a regression test: fails pre-fix, passes post-fix; impractical → smoke test, report it.\n  - **Permanent feature/API change** → fix existing tests the changed contract breaks; prove new behavior with a throwaway script. New test ONLY for a genuinely uncertain edge case, or on user request.\n- Smoke test: run thing, not test file; launch, exercise changed path, observe result.\n- Tests: permanent load, not proof of work. A test earns its place ONLY where a plausible bug would fail it.\n  - Each MUST defend observable contract/fail on plausible bug.\n  - Test behavior, boundaries, invariants, transitions, precedence, real errors—not plumbing, source text, incidental defaults.\n  - Match conventions; deterministic, isolated, full-suite-safe.\n  - NEVER write a test so the change \"has tests\" → throwaway script.\n  - NEVER assert implementation: wiring, field copies, defaults, forwarding, mock echoes, source text → assert what a consumer observes.\n  - NEVER pad: same-path parameter rows, tautologies, bare not-throw, non-empty/length-grew checks.\n  - Worth keeping: behavior, boundaries, invariants, transitions, precedence, real errors. Match conventions; deterministic, isolated, full-suite-safe.\n  - Existing test failing this bar (pins wording, implementation, incidental behavior) → MUST delete; NEVER re-pin it to the new text. In scope regardless of author.\n\n# 6. Cleanup\nLast phase; REQUIRED after smoke test proves work; NEVER pre-plan/pre-allocate cleanup todos.\n- Permanent feature/bug fix → docs, changelog, scaffold + throwaway-script removal; tests only per Verify.\n- Experiment/one-off investigation → no cleanup tests/docs.\n\n§ Delivery\n<contract>\nInviolable.\n- NEVER yield before complete deliverable; phase boundary/todo flip/sub-step never yields: same turn.\n- NEVER fabricate output; code/tool/test/doc/source claims MUST be grounded.\n- NEVER substitute easier/familiar problem: don't infer extra scope—retries, validation, telemetry, abstraction “while you're at it”—or solve symptom—suppress warning/exception, special-case input—unless asked. Real ask only.\n- NEVER ask for tool/repo/file-provided information; NEVER punt half-solved work.\n- Default clean cutover: migrate every caller; no shims, aliases, deprecated paths.\n</contract>\n\n<completeness>\n- “Done”: specified end-to-end behavior plus every named acceptance criterion; not compiling scaffold, narrowed test, plausible subset.\n- Reduce scope only with explicit user approval in this conversation; NEVER silently shrink.\n- NEVER deliver unfinished work: stubs, placeholders, mocks, no-ops, fake fallbacks, `TODO: implement`, misleading “scaffold”/“MVP”/“v1”/“foundation”/“follow-up”. Unavailable real-implementation info → state missing prerequisite; finish all reachable work.\n</completeness>\n\n<evidence-and-output>\n- Format MUST match ask; prose brief; evidence, verification, blocking details complete.\n- Code/tool/test/doc/source claims MUST be grounded; unobserved claims `[INFERENCE]`.\n- Verification claims exactly match exercised work.\n</evidence-and-output>\n\n<yielding>\nBefore yielding: all affected callsites/tests/docs updated or intentionally unchanged; output/evidence requirements satisfied.\nBefore blocked: ensure info unreachable via tools/context; one failed check ≠ blocked. Finish reachable work; state exactly missing and tried.\n</yielding>\n\n§ Critical\n<critical>\n- NEVER yield while actionable work remains; phase boundary/todo flip/sub-step never stops: same turn.\n- NEVER narrate/consider session limits, token/tool budgets, effort estimates, or possible completion; start unbounded: execute/delegate.\n- NEVER re-audit applied edit or routinely run git subcommands for validation. Tool results are verification.\n</critical>\n\n§ Role\nInvestigate the codebase rapidly. Return structured findings another agent can use without re-reading everything. `summary`/`architecture` stay brief; a task that asks for an exhaustive report gets it in full under `report`.\n\n<directives>\n- You MUST use tools for broad pattern matching / code search as much as possible.\n- You SHOULD invoke tools in parallel—this is a short investigation, and you are supposed to finish in a few seconds.\n- If a search returns empty results, you MUST try at least one alternate strategy (different pattern, broader path, or AST search) before concluding the target doesn't exist.\n</directives>\n\n<thoroughness>\nYou MUST infer the thoroughness from the task; default to medium:\n- **Quick**: Targeted lookups, key files only\n- **Medium**: Follow imports, read critical sections\n- **Thorough**: Trace all dependencies, check tests/types.\n</thoroughness>\n\n<procedure>\n1. Locate relevant code using tools.\n2. Read key sections. NEVER read full files unless they're tiny.\n3. Identify types/interfaces/key functions.\n4. Note dependencies between files.\n</procedure>\n\n<critical>\nYou MUST operate as read-only. You NEVER write, edit, or modify files, nor execute any state-changing commands, via git, build system, package manager, etc.\nYou MUST keep going until complete.\n</critical>\n\n§ Context\n# Goal\nEvidence-only #307 W1c first, then W1b; no product fix authorized. Main289e3cdf freshly built, spt sha2565c73973baf1eaa16cbd548fe75f553da7a87f98e892d936b7890618c736c93e8. Real isolated Windows daemon+Python generator+actual spt rc currently running bounded cadence experiment. Main owns driver/teardown. No resident daemon touched.\n# Constraints\nREAD ONLY, skip all builds/tests/lints/formatters and live daemon/probe commands. Do not edit files. User asks RCA CANDIDATE explaining why prior refresh fixes failed; never upgrade inference to proven mechanism. Q3 still needs separate real signed pending trial.\n# Contract\nRed loop now exists: .spt/preserved/307/hertz-w1bc/rig.py, W1c output under .spt/preserved/307/hertz-w1bc/w1c-run1. Baseline45s has real PROG generation/receipt stamps and child ACK+state. First node refresh during600000ms cadence change breaks live delivery/input. Actual daemon log is home-w1c/logs/daemon.stderr.log (external pre-redirect capture is empty). Session1, controllerconn17 closes cause=detach at1789523803471 after BRAIN_UPDATE_RESTART; gen1 resumes; replacement attachconn70 then88 then104 each emits snapshot to rc, no continued live stream, then15s CONN_WRITE_POISONED+BRAIN_SUBSCRIBER_STALL_EVICT+slot closure cause=detach. Query canary remains numeric fresh; active_dial_tasks=0. Real generator input ledger stops at baseline tag022. Reader remained enabled throughout; rawchunks preserve data. Ranked hypotheses: synchronous broker/stream wait after reattach; replay/ack state on old stream; rig reader bug (less likely). Need source-backed distinguishing predictions, not fixes or global theories.\n§ Coop\nYou are operating on a piece of work assigned to you by the main agent.\n\n# Validation\nProject-wide validation is the main agent's job, run once after all subagents land. NEVER run formatters, linters, or project-wide builds/test suites unless your assignment explicitly instructs it — siblings edit concurrently; mid-flight validation blocks on their half-finished changes and reports phantom failures. Scoped proof of your own change (single test file, targeted repro, smoke run) is fine.\n# Peers\nYou can reach other live agents via the `hub` tool. Your id is `AttachReplayRca`. Currently visible peers:\n- `ControllerDrainRca` — scout (sub, running)\n- `Main` — main (main, running)\n24 parked peer(s) omitted.\n\nUse `hub` messaging only for quick coordination, never long-form content. Address peers by id or use `\"all\"` to broadcast.\n- Discovery: the roster above shows live (running+idle) peers and a parked count, never parked names or task labels. `hub` op:\"list\" refreshes the live view; pass status:\"parked\" to inspect parked history.\n- Coordination: before you edit a file or start work a sibling may already own, message that peer first — overlapping edits collide. Idle peers are not gone: messaging them wakes them.\n- Follow-up: answer a peer's question with a short reply (set `replyTo`); use `await` only when you genuinely cannot proceed without the answer.\n- Parked history: omitted from this roster. `hub` op:\"list\" status:\"parked\" lists ids; `send` to a known parked id revives it. `history://<id>` and `agent://<id>` stay readable.\n\n§ Completion\nNo TODO tracking, no progress updates. Execute; report results with `yield`.\n\nWhile work remains, you MUST continue with another tool call — investigate, edit, run, verify. Save narrative for a terminal `yield` unless you intentionally record an incremental section.\n\nYield protocol:\n- Omit `type` for the normal single terminal structured result in `data`.\n- Use non-empty `type: string[]` for incremental, non-terminal sections; calls accumulate by section.\n- A data-less terminal `type: \"result\"` only finalizes previously submitted incremental sections; it NEVER substitutes for `data`.\n\nThis is your only way to return a final result. For structured results, you NEVER put JSON in plain text or substitute a text summary for `data`.\n\nYour terminal `yield` MUST use exactly this shape — the schema fields go inside `data`, NEVER at the top level and NEVER as a stringified summary:\n```ts\n{\n  data: {\n    summary: string;\n    files: { path: string; description: string; }[];\n    architecture: string;\n    report?: string;\n  };\n}\n```\n\nGiving up is a last resort. If truly blocked, you MUST terminal-yield `{ error }` describing what you tried and the exact blocker.\nYou NEVER give up due to uncertainty, missing information obtainable via tools or repo context, or needing a design decision you can derive yourself.\n\nYou MUST keep going until this ticket is closed. This matters.\n\nPROJECT\n\n<workstation>\n- OS: win32 10.0.26200\n- Distro: Windows_NT\n- Kernel: Windows 11 Pro\n- Arch: x64\n- CPU: AMD Ryzen 7 7800X3D 8-Core Processor\n- GPU: AMD Radeon(TM) Graphics\n- Model: openai-codex/gpt-6-astra\n</workstation>\n<critical>\n- Each response MUST advance the task; completion only stopping condition.\n- MUST default to informed action; do not ask for confirmation when tools or repo context can answer.\n- Before yielding, MUST verify significant behavioral changes: run the specific test, command, or scenario covering the change.\n</critical>","task":"Complete assignment thoroughly:\n\n# Target\nTrace attach/replay/stream work path in crates/spt-daemon/src/attach.rs, dispatch.rs, brain/netstream and matching tests, using W1c artifacts cited in context. Focus brain consumer and replay side, not broker writer internals.\n# Change\nMap exact replacement-worker path following brain restart, why it can deliver one terminal snapshot but then fail to consume further controller output/input. Identify synchronous request/reply/SharedSend/wait ordering and durable stream replay/acks that could cause repeated15s poison despite a fresh canary. Use LSP where available. No code edits or runtime commands.\n# Acceptance\nReturn ranked concrete source-backed candidate(s), falsifiable predictions and exact lines. Explain what prior conn-poison/retry fixes do and do not fix. Distinguish observation from inference. Skip all validation.","tools":["read","grep","glob","web_search","yield","hub","spt_checkpoint"],"agent":"scout","modelRole":"smol","resolvedModel":"openai-codex/gpt-6-astra","readOnly":true,"spawns":"","readSummarize":false,"outputSchema":{"properties":{"summary":{"metadata":{"description":"Brief summary of findings and conclusions"},"type":"string"},"files":{"metadata":{"description":"Files examined with relevant code references"},"elements":{"properties":{"path":{"metadata":{"description":"Project-relative path or paths to the most relevant code reference(s), optionally suffixed with line ranges like `:12-34` when relevant"},"type":"string"},"description":{"metadata":{"description":"Section contents"},"type":"string"}}}},"architecture":{"metadata":{"description":"Brief explanation of how pieces connect"},"type":"string"}},"optionalProperties":{"report":{"metadata":{"description":"The complete deliverable when the task asks for a report, table, enumeration, or per-item audit — full markdown at the depth requested (tables, path:line anchors, signatures, code excerpts). Never a summary of it; `summary` already covers that. Omit only for quick lookups."},"type":"string"}}},"outputSchemaMode":"permissive"}
{"type":"message","id":"e7e6c151","parentId":"496971ff","timestamp":"2026-09-16T01:59:00.467Z","message":{"role":"user","content":[{"type":"text","text":"Complete assignment thoroughly:\n\n# Target\nTrace attach/replay/stream work path in crates/spt-daemon/src/attach.rs, dispatch.rs, brain/netstream and matching tests, using W1c artifacts cited in context. Focus brain consumer and replay side, not broker writer internals.\n# Change\nMap exact replacement-worker path following brain restart, why it can deliver one terminal snapshot but then fail to consume further controller output/input. Identify synchronous request/reply/SharedSend/wait ordering and durable stream replay/acks that could cause repeated15s poison despite a fresh canary. Use LSP where available. No code edits or runtime commands.\n# Acceptance\nReturn ranked concrete source-backed candidate(s), falsifiable predictions and exact lines. Explain what prior conn-poison/retry fixes do and do not fix. Distinguish observation from inference. Skip all validation."}],"attribution":"agent","timestamp":1789523940416}}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_ovWTQlpBCbS5wFlTJ7bS89sP|fc_09b01b5279447709016aa9f7eaa54c87d2ae1122ca3443c5c9","toolName":"read","startedAt":"2026-09-16T01:59:07.662Z","args":{"path":"skill://diagnose"},"intent":"Reading diagnostic skill"},"id":"5eebedb4","parentId":"e7e6c151","timestamp":"2026-09-16T01:59:07.662Z"}
{"type":"message","id":"e78090f0","parentId":"5eebedb4","timestamp":"2026-09-16T01:59:07.662Z","message":{"role":"assistant","content":[{"type":"toolCall","id":"call_ovWTQlpBCbS5wFlTJ7bS89sP|fc_09b01b5279447709016aa9f7eaa54c87d2ae1122ca3443c5c9","name":"read","arguments":{"i":"Reading diagnostic skill","path":"skill://diagnose"},"intent":"Reading diagnostic skill"}],"api":"openai-codex-responses","provider":"openai-codex","model":"gpt-6-astra","usage":{"input":10374,"output":26,"cacheRead":0,"cacheWrite":0,"totalTokens":10400,"cost":{"input":0.10374000000000001,"output":0.0013000000000000002,"cacheRead":0,"cacheWrite":0,"total":0.10504000000000001}},"stopReason":"toolUse","timestamp":1789523940466,"responseId":"resp_09b01b5279447709016aa9f7e7cdf487d299fd5236ca9bd075","providerPayload":{"type":"openaiResponsesHistory","provider":"openai-codex","dt":true,"items":[{"id":"fc_09b01b5279447709016aa9f7eaa54c87d2ae1122ca3443c5c9","type":"function_call","status":"completed","arguments":"{\"i\":\"Reading diagnostic skill\",\"path\":\"skill://diagnose\"}","call_id":"call_ovWTQlpBCbS5wFlTJ7bS89sP","internal_chat_message_metadata_passthrough":{"create_time":1789523945.524083,"turn_id":"a464097d-3a78-4a75-9ebb-a53f309aa685"},"name":"read","metadata":{"turn_id":"a464097d-3a78-4a75-9ebb-a53f309aa685"}}]},"duration":7194.096200000029,"ttft":6202.182200000156,"completedAt":1789523947661,"contextSnapshot":{"promptTokens":10374,"nonMessageTokens":10480,"compactionEpoch":0}}}
{"type":"credential_pin","id":"658859b5","parentId":"e78090f0","timestamp":"2026-09-16T01:59:07.663Z","provider":"openai-codex","hash":"1a3c10d7bc41d381cab1511db604bc2637dfcfc63796a890d8b5ee152859e1cb"}
{"type":"message","id":"9c414d9a","parentId":"658859b5","timestamp":"2026-09-16T01:59:07.665Z","message":{"role":"toolResult","toolCallId":"call_ovWTQlpBCbS5wFlTJ7bS89sP|fc_09b01b5279447709016aa9f7eaa54c87d2ae1122ca3443c5c9","toolName":"read","content":[{"type":"text","text":"---\nname: diagnose\ndescription: Disciplined diagnosis loop for hard bugs and performance regressions. Reproduce → minimise → hypothesise → instrument → fix → regression-test. Use when user says \"diagnose this\" / \"debug this\", reports a bug, says something is broken/throwing/failing, or describes a performance regression.\n---\n\n# Diagnose\n\nA discipline for hard bugs. Skip phases only when explicitly justified.\n\nWhen exploring the codebase, use the project's domain glossary to get a clear mental model of the relevant modules, and check ADRs in the area you're touching.\n\n## Phase 1 — Build a feedback loop\n\n**This is the skill.** Everything else is mechanical. If you have a fast, deterministic, agent-runnable pass/fail signal for the bug, you will find the cause — bisection, hypothesis-testing, and instrumentation all just consume that signal. If you don't have one, no amount of staring at code will save you.\n\nSpend disproportionate effort here. **Be aggressive. Be creative. Refuse to give up.**\n\n### Ways to construct one — try them in roughly this order\n\n1. **Failing test** at whatever seam reaches the bug — unit, integration, e2e.\n2. **Curl / HTTP script** against a running dev server.\n3. **CLI invocation** with a fixture input, diffing stdout against a known-good snapshot.\n4. **Headless browser script** (Playwright / Puppeteer) — drives the UI, asserts on DOM/console/network.\n5. **Replay a captured trace.** Save a real network request / payload / event log to disk; replay it through the code path in isolation.\n6. **Throwaway harness.** Spin up a minimal subset of the system (one service, mocked deps) that exercises the bug code path with a single function call.\n7. **Property / fuzz loop.** If the bug is \"sometimes wrong output\", run 1000 random inputs and look for the failure mode.\n8. **Bisection harness.** If the bug appeared between two known states (commit, dataset, version), automate \"boot at state X, check, repeat\" so you can `git bisect run` it.\n9. **Differential loop.** Run the same input through old-version vs new-version (or two configs) and diff outputs.\n10. **HITL bash script.** Last resort. If a human must click, drive _them_ with `scripts/hitl-loop.template.sh` so the loop is still structured. Captured output feeds back to you.\n\nBuild the right feedback loop, and the bug is 90% fixed.\n\n### Iterate on the loop itself\n\nTreat the loop as a product. Once you have _a_ loop, ask:\n\n- Can I make it faster? (Cache setup, skip unrelated init, narrow the test scope.)\n- Can I make the signal sharper? (Assert on the specific symptom, not \"didn't crash\".)\n- Can I make it more deterministic? (Pin time, seed RNG, isolate filesystem, freeze network.)\n\nA 30-second flaky loop is barely better than no loop. A 2-second deterministic loop is a debugging superpower.\n\n### Non-deterministic bugs\n\nThe goal is not a clean repro but a **higher reproduction rate**. Loop the trigger 100×, parallelise, add stress, narrow timing windows, inject sleeps. A 50%-flake bug is debuggable; 1% is not — keep raising the rate until it's debuggable.\n\n### When you genuinely cannot build a loop\n\nStop and say so explicitly. List what you tried. Ask the user for: (a) access to whatever environment reproduces it, (b) a captured artifact (HAR file, log dump, core dump, screen recording with timestamps), or (c) permission to add temporary production instrumentation. Do **not** proceed to hypothesise without a loop.\n\nDo not proceed to Phase 2 until you have a loop you believe in.\n\n## Phase 2 — Reproduce\n\nRun the loop. Watch the bug appear.\n\nConfirm:\n\n- [ ] The loop produces the failure mode the **user** described — not a different failure that happens to be nearby. Wrong bug = wrong fix.\n- [ ] The failure is reproducible across multiple runs (or, for non-deterministic bugs, reproducible at a high enough rate to debug against).\n- [ ] You have captured the exact symptom (error message, wrong output, slow timing) so later phases can verify the fix actually addresses it.\n\nDo not proceed until you reproduce the bug.\n\n## Phase 3 — Hypothesise\n\nGenerate **3–5 ranked hypotheses** before testing any of them. Single-hypothesis generation anchors on the first plausible idea.\n\nEach hypothesis must be **falsifiable**: state the prediction it makes.\n\n> Format: \"If <X> is the cause, then <changing Y> will make the bug disappear / <changing Z> will make it worse.\"\n\nIf you cannot state the prediction, the hypothesis is a vibe — discard or sharpen it.\n\n**Show the ranked list to the user before testing.** They often have domain knowledge that re-ranks instantly (\"we just deployed a change to #3\"), or know hypotheses they've already ruled out. Cheap checkpoint, big time saver. Don't block on it — proceed with your ranking if the user is AFK.\n\n## Phase 4 — Instrument\n\nEach probe must map to a specific prediction from Phase 3. **Change one variable at a time.**\n\nTool preference:\n\n1. **Debugger / REPL inspection** if the env supports it. One breakpoint beats ten logs.\n2. **Targeted logs** at the boundaries that distinguish hypotheses.\n3. Never \"log everything and grep\".\n\n**Tag every debug log** with a unique prefix, e.g. `[DEBUG-a4f2]`. Cleanup at the end becomes a single grep. Untagged logs survive; tagged logs die.\n\n**Perf branch.** For performance regressions, logs are usually wrong. Instead: establish a baseline measurement (timing harness, `performance.now()`, profiler, query plan), then bisect. Measure first, fix second.\n\n## Phase 5 — Fix + regression test\n\nWrite the regression test **before the fix** — but only if there is a **correct seam** for it.\n\nA correct seam is one where the test exercises the **real bug pattern** as it occurs at the call site. If the only available seam is too shallow (single-caller test when the bug needs multiple callers, unit test that can't replicate the chain that triggered the bug), a regression test there gives false confidence.\n\n**If no correct seam exists, that itself is the finding.** Note it. The codebase architecture is preventing the bug from being locked down. Flag this for the next phase.\n\nIf a correct seam exists:\n\n1. Turn the minimised repro into a failing test at that seam.\n2. Watch it fail.\n3. Apply the fix.\n4. Watch it pass.\n5. Re-run the Phase 1 feedback loop against the original (un-minimised) scenario.\n\n## Phase 6 — Cleanup + post-mortem\n\nRequired before declaring done:\n\n- [ ] Original repro no longer reproduces (re-run the Phase 1 loop)\n- [ ] Regression test passes (or absence of seam is documented)\n- [ ] All `[DEBUG-...]` instrumentation removed (`grep` the prefix)\n- [ ] Throwaway prototypes deleted (or moved to a clearly-marked debug location)\n- [ ] The hypothesis that turned out correct is stated in the commit / PR message — so the next debugger learns\n\n**Then ask: what would have prevented this bug?** If the answer involves architectural change (no good test seam, tangled callers, hidden coupling) hand off to the `/improve-codebase-architecture` skill with the specifics. Make the recommendation **after** the fix is in, not before — you have more information now than when you started."}],"details":{"resolvedPath":"C:\\Users\\decid\\.agents\\skills\\diagnose\\SKILL.md","contentType":"text/markdown","totalLines":117,"displayContent":{"text":"---\r\nname: diagnose\r\ndescription: Disciplined diagnosis loop for hard bugs and performance regressions. Reproduce → minimise → hypothesise → instrument → fix → regression-test. Use when user says \"diagnose this\" / \"debug this\", reports a bug, says something is broken/throwing/failing, or describes a performance regression.\r\n---\r\n\r\n# Diagnose\r\n\r\nA discipline for hard bugs. Skip phases only when explicitly justified.\r\n\r\nWhen exploring the codebase, use the project's domain glossary to get a clear mental model of the relevant modules, and check ADRs in the area you're touching.\r\n\r\n## Phase 1 — Build a feedback loop\r\n\r\n**This is the skill.** Everything else is mechanical. If you have a fast, deterministic, agent-runnable pass/fail signal for the bug, you will find the cause — bisection, hypothesis-testing, and instrumentation all just consume that signal. If you don't have one, no amount of staring at code will save you.\r\n\r\nSpend disproportionate effort here. **Be aggressive. Be creative. Refuse to give up.**\r\n\r\n### Ways to construct one — try them in roughly this order\r\n\r\n1. **Failing test** at whatever seam reaches the bug — unit, integration, e2e.\r\n2. **Curl / HTTP script** against a running dev server.\r\n3. **CLI invocation** with a fixture input, diffing stdout against a known-good snapshot.\r\n4. **Headless browser script** (Playwright / Puppeteer) — drives the UI, asserts on DOM/console/network.\r\n5. **Replay a captured trace.** Save a real network request / payload / event log to disk; replay it through the code path in isolation.\r\n6. **Throwaway harness.** Spin up a minimal subset of the system (one service, mocked deps) that exercises the bug code path with a single function call.\r\n7. **Property / fuzz loop.** If the bug is \"sometimes wrong output\", run 1000 random inputs and look for the failure mode.\r\n8. **Bisection harness.** If the bug appeared between two known states (commit, dataset, version), automate \"boot at state X, check, repeat\" so you can `git bisect run` it.\r\n9. **Differential loop.** Run the same input through old-version vs new-version (or two configs) and diff outputs.\r\n10. **HITL bash script.** Last resort. If a human must click, drive _them_ with `scripts/hitl-loop.template.sh` so the loop is still structured. Captured output feeds back to you.\r\n\r\nBuild the right feedback loop, and the bug is 90% fixed.\r\n\r\n### Iterate on the loop itself\r\n\r\nTreat the loop as a product. Once you have _a_ loop, ask:\r\n\r\n- Can I make it faster? (Cache setup, skip unrelated init, narrow the test scope.)\r\n- Can I make the signal sharper? (Assert on the specific symptom, not \"didn't crash\".)\r\n- Can I make it more deterministic? (Pin time, seed RNG, isolate filesystem, freeze network.)\r\n\r\nA 30-second flaky loop is barely better than no loop. A 2-second deterministic loop is a debugging superpower.\r\n\r\n### Non-deterministic bugs\r\n\r\nThe goal is not a clean repro but a **higher reproduction rate**. Loop the trigger 100×, parallelise, add stress, narrow timing windows, inject sleeps. A 50%-flake bug is debuggable; 1% is not — keep raising the rate until it's debuggable.\r\n\r\n### When you genuinely cannot build a loop\r\n\r\nStop and say so explicitly. List what you tried. Ask the user for: (a) access to whatever environment reproduces it, (b) a captured artifact (HAR file, log dump, core dump, screen recording with timestamps), or (c) permission to add temporary production instrumentation. Do **not** proceed to hypothesise without a loop.\r\n\r\nDo not proceed to Phase 2 until you have a loop you believe in.\r\n\r\n## Phase 2 — Reproduce\r\n\r\nRun the loop. Watch the bug appear.\r\n\r\nConfirm:\r\n\r\n- [ ] The loop produces the failure mode the **user** described — not a different failure that happens to be nearby. Wrong bug = wrong fix.\r\n- [ ] The failure is reproducible across multiple runs (or, for non-deterministic bugs, reproducible at a high enough rate to debug against).\r\n- [ ] You have captured the exact symptom (error message, wrong output, slow timing) so later phases can verify the fix actually addresses it.\r\n\r\nDo not proceed until you reproduce the bug.\r\n\r\n## Phase 3 — Hypothesise\r\n\r\nGenerate **3–5 ranked hypotheses** before testing any of them. Single-hypothesis generation anchors on the first plausible idea.\r\n\r\nEach hypothesis must be **falsifiable**: state the prediction it makes.\r\n\r\n> Format: \"If <X> is the cause, then <changing Y> will make the bug disappear / <changing Z> will make it worse.\"\r\n\r\nIf you cannot state the prediction, the hypothesis is a vibe — discard or sharpen it.\r\n\r\n**Show the ranked list to the user before testing.** They often have domain knowledge that re-ranks instantly (\"we just deployed a change to #3\"), or know hypotheses they've already ruled out. Cheap checkpoint, big time saver. Don't block on it — proceed with your ranking if the user is AFK.\r\n\r\n## Phase 4 — Instrument\r\n\r\nEach probe must map to a specific prediction from Phase 3. **Change one variable at a time.**\r\n\r\nTool preference:\r\n\r\n1. **Debugger / REPL inspection** if the env supports it. One breakpoint beats ten logs.\r\n2. **Targeted logs** at the boundaries that distinguish hypotheses.\r\n3. Never \"log everything and grep\".\r\n\r\n**Tag every debug log** with a unique prefix, e.g. `[DEBUG-a4f2]`. Cleanup at the end becomes a single grep. Untagged logs survive; tagged logs die.\r\n\r\n**Perf branch.** For performance regressions, logs are usually wrong. Instead: establish a baseline measurement (timing harness, `performance.now()`, profiler, query plan), then bisect. Measure first, fix second.\r\n\r\n## Phase 5 — Fix + regression test\r\n\r\nWrite the regression test **before the fix** — but only if there is a **correct seam** for it.\r\n\r\nA correct seam is one where the test exercises the **real bug pattern** as it occurs at the call site. If the only available seam is too shallow (single-caller test when the bug needs multiple callers, unit test that can't replicate the chain that triggered the bug), a regression test there gives false confidence.\r\n\r\n**If no correct seam exists, that itself is the finding.** Note it. The codebase architecture is preventing the bug from being locked down. Flag this for the next phase.\r\n\r\nIf a correct seam exists:\r\n\r\n1. Turn the minimised repro into a failing test at that seam.\r\n2. Watch it fail.\r\n3. Apply the fix.\r\n4. Watch it pass.\r\n5. Re-run the Phase 1 feedback loop against the original (un-minimised) scenario.\r\n\r\n## Phase 6 — Cleanup + post-mortem\r\n\r\nRequired before declaring done:\r\n\r\n- [ ] Original repro no longer reproduces (re-run the Phase 1 loop)\r\n- [ ] Regression test passes (or absence of seam is documented)\r\n- [ ] All `[DEBUG-...]` instrumentation removed (`grep` the prefix)\r\n- [ ] Throwaway prototypes deleted (or moved to a clearly-marked debug location)\r\n- [ ] The hypothesis that turned out correct is stated in the commit / PR message — so the next debugger learns\r\n\r\n**Then ask: what would have prevented this bug?** If the answer involves architectural change (no good test seam, tangled callers, hidden coupling) hand off to the `/improve-codebase-architecture` skill with the specifics. Make the recommendation **after** the fix is in, not before — you have more information now than when you started.\r","startLine":1,"lineNumbers":[1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95,96,97,98,99,100,101,102,103,104,105,106,107,108,109,110,111,112,113,114,115,116,117]},"meta":{"source":{"type":"internal","value":"skill://diagnose"}}},"isError":false,"timestamp":1789523947664}}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_QSy2P7A8hJSyk0sw2QczWrxD|fc_09b01b5279447709016aa9f7f1661087d29408e92526092996","toolName":"read","startedAt":"2026-09-16T01:59:15.922Z","args":{"path":"crates/spt-daemon/src/attach.rs"},"intent":"Mapping attach implementation"},"id":"48a902e8","parentId":"9c414d9a","timestamp":"2026-09-16T01:59:15.922Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_VUQqg2pboVBoKwrgwhe1CbUH|fc_09b01b5279447709016aa9f7f1662087d2a27f8e94458f3efb","toolName":"read","startedAt":"2026-09-16T01:59:15.922Z","args":{"path":"crates/spt-daemon/src/dispatch.rs"},"intent":"Mapping dispatch implementation"},"id":"4dd74fd5","parentId":"48a902e8","timestamp":"2026-09-16T01:59:15.922Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_QQaL5ioVhbXXYScmKi7thkiG|fc_09b01b5279447709016aa9f7f1662887d2b78794ce7a5fe9a0","toolName":"glob","startedAt":"2026-09-16T01:59:15.922Z","args":{"path":"**/*netstream*;.spt/preserved/307/hertz-w1bc/w1c-run1/*;**/*glossary*;**/*ADR*"},"intent":"Locating stream and artifacts"},"id":"b0c2d117","parentId":"4dd74fd5","timestamp":"2026-09-16T01:59:15.922Z"}
{"type":"message","id":"708de2aa","parentId":"b0c2d117","timestamp":"2026-09-16T01:59:15.922Z","message":{"role":"assistant","content":[{"type":"toolCall","id":"call_QSy2P7A8hJSyk0sw2QczWrxD|fc_09b01b5279447709016aa9f7f1661087d29408e92526092996","name":"read","arguments":{"i":"Mapping attach implementation","path":"crates/spt-daemon/src/attach.rs"},"intent":"Mapping attach implementation"},{"type":"toolCall","id":"call_VUQqg2pboVBoKwrgwhe1CbUH|fc_09b01b5279447709016aa9f7f1662087d2a27f8e94458f3efb","name":"read","arguments":{"i":"Mapping dispatch implementation","path":"crates/spt-daemon/src/dispatch.rs"},"intent":"Mapping dispatch implementation"},{"type":"toolCall","id":"call_QQaL5ioVhbXXYScmKi7thkiG|fc_09b01b5279447709016aa9f7f1662887d2b78794ce7a5fe9a0","name":"glob","arguments":{"i":"Locating stream and artifacts","path":"**/*netstream*;.spt/preserved/307/hertz-w1bc/w1c-run1/*;**/*glossary*;**/*ADR*","hidden":true,"gitignore":false,"limit":70},"intent":"Locating stream and artifacts"}],"api":"openai-codex-responses","provider":"openai-codex","model":"gpt-6-astra","usage":{"input":1813,"output":144,"cacheRead":10240,"cacheWrite":0,"totalTokens":12197,"cost":{"input":0.01813,"output":0.007200000000000001,"cacheRead":0.010239999999999999,"cacheWrite":0,"total":0.035570000000000004}},"stopReason":"toolUse","timestamp":1789523947696,"responseId":"resp_09b01b5279447709016aa9f7ebff6087d2b285fcbee51e0676","providerPayload":{"type":"openaiResponsesHistory","provider":"openai-codex","dt":true,"items":[{"id":"fc_09b01b5279447709016aa9f7f1661087d29408e92526092996","type":"function_call","status":"completed","arguments":"{\"i\":\"Mapping attach implementation\",\"path\":\"crates/spt-daemon/src/attach.rs\"}","call_id":"call_QSy2P7A8hJSyk0sw2QczWrxD","internal_chat_message_metadata_passthrough":{"turn_id":"a464097d-3a78-4a75-9ebb-a53f309aa685"},"name":"read","metadata":{"turn_id":"a464097d-3a78-4a75-9ebb-a53f309aa685"}},{"id":"fc_09b01b5279447709016aa9f7f1662087d2a27f8e94458f3efb","type":"function_call","status":"completed","arguments":"{\"i\":\"Mapping dispatch implementation\",\"path\":\"crates/spt-daemon/src/dispatch.rs\"}","call_id":"call_VUQqg2pboVBoKwrgwhe1CbUH","internal_chat_message_metadata_passthrough":{"turn_id":"a464097d-3a78-4a75-9ebb-a53f309aa685"},"name":"read","metadata":{"turn_id":"a464097d-3a78-4a75-9ebb-a53f309aa685"}},{"id":"fc_09b01b5279447709016aa9f7f1662887d2b78794ce7a5fe9a0","type":"function_call","status":"completed","arguments":"{\"i\":\"Locating stream and artifacts\",\"path\":\"**/*netstream*;.spt/preserved/307/hertz-w1bc/w1c-run1/*;**/*glossary*;**/*ADR*\",\"hidden\":true,\"gitignore\":false,\"limit\":70}","call_id":"call_QQaL5ioVhbXXYScmKi7thkiG","internal_chat_message_metadata_passthrough":{"turn_id":"a464097d-3a78-4a75-9ebb-a53f309aa685"},"name":"glob","metadata":{"turn_id":"a464097d-3a78-4a75-9ebb-a53f309aa685"}}]},"duration":8224.322699999902,"ttft":8187.1097999999765,"completedAt":1789523955921,"contextSnapshot":{"promptTokens":12053,"nonMessageTokens":10480,"compactionEpoch":0}}}
{"type":"message","id":"f95d547d","parentId":"708de2aa","timestamp":"2026-09-16T01:59:15.935Z","message":{"role":"toolResult","toolCallId":"call_QSy2P7A8hJSyk0sw2QczWrxD|fc_09b01b5279447709016aa9f7f1661087d29408e92526092996","toolName":"read","content":[{"type":"text","text":"//! Remote terminal attach (M4-D5b, REQ-INST-8) — serve a byte-stream viewport\n//! onto a local session for an operator on another node.\n//!\n//! The operator's daemon opened a bidi QUIC stream to this node (D4) and sent\n//! [`AttachRecord::Request`]; this module is the target-side pump between that\n//! stream and the local broker-hosted session:\n//!\n//! - session `Output` chunks → [`AttachRecord::Output`] lines onto the wire\n//!   (fire-and-forget sends; `Output.seq` carries the dedup authority);\n//! - inbound [`AttachRecord::Input`] → [`Brain::send_effect`] with the\n//!   operator-minted `op_id` — exactly-once at the PTY write through the B5\n//!   journal (a replayed input record cannot double-type);\n//! - session `Exit` → [`AttachRecord::Exit`] + stream finish.\n//!\n//! ## Exactly-once lives at the EDGES, not the wire sends\n//!\n//! Stream sends here are deliberately **unjournaled** (`op_id: None`): a\n//! journaled [`Brain::net_stream_send`] blocks reading events until its ack\n//! and *discards* everything interleaved — inside a full-duplex pump loop that\n//! eats the operator's `Input` records (both sides starve; found the hard way\n//! in `tests/attach.rs`). Idempotency holds without it because each direction\n//! dedups at its **effect**: the PTY write is journaled by the operator-minted\n//! `Input.op_id`, and the operator's viewport dedups `Output` records by their\n//! session-log `seq` (the render cursor). A post-restart re-serve may\n//! re-transmit output records on the wire — duplicates are dropped at the\n//! render cursor, the same discipline the local `OutputLog` replay uses\n//! (REQ-HAZARD-RESTART-IDEMPOTENT at the boundary that matters).\n//!\n//! **Compute + files stay here**; the operator is a viewport (CONTEXT\n//! §Remote-control vs local operation). The access gate runs before anything\n//! is served: the [`AttachRecord::Request`] is *unsolicited wire inbound*, so\n//! [`access_check`] sees the **handshake-proven** origin from the broker's\n//! stream table — never payload bytes (KNOWN-HAZARDS 7.5). Remote-drive of\n//! your own running instance is ungated by default (ADR-0009 default-open);\n//! the D5d whitelist drops in at this same call.\n//!\n//! Restart survival composes from D4/B5 with **no new machinery**: the broker\n//! owns the QUIC stream, the session, its `OutputLog`, and the effect journal.\n//! A restarted target brain re-attaches the session from its output cursor,\n//! resubscribes the stream from its net cursor, and re-drives journaled sends;\n//! a restarted operator brain resubscribes and dedups rendered chunks by\n//! `Output.seq`.\n\nuse std::io;\nuse std::time::{Duration, Instant};\n\nuse spt_net::net::attach::{\n    AttachClientIdentity, AttachClientPolicy, AttachDecoder, AttachIntent, AttachRecord,\n};\nuse spt_net::net::ndjson;\n\nuse crate::access::{access_check, surface, InboundClass};\n\n/// Raise a floor only for demonstrated rc defects, not ordinary release skew.\n/// releases#230 replayed #222's Windows Hello refusal and #223's admitted\n/// ceremony residue in a pre-0.63.0 controller. Read-only viewers receive no\n/// ceremonies, so neither defect honestly applies to their role.\n// [impl->REQ-ATTACH-CLIENT-STALE]\npub fn attach_client_policy() -> Vec<AttachClientPolicy> {\n    vec![\n        AttachClientPolicy {\n            minimum_version: \"0.63.0\".into(),\n            platforms: vec![\"windows\".into()],\n            roles: vec![AttachIntent::Control],\n            reason: \"Windows authenticator enrollment can refuse with NCrypt 0x80090027 (releases#222)\".into(),\n        },\n        AttachClientPolicy {\n            minimum_version: \"0.63.0\".into(),\n            platforms: vec![\"windows\".into(), \"linux\".into(), \"macos\".into()],\n            roles: vec![AttachIntent::Control],\n            reason: \"admitted seal ceremonies leave a stranded notice in the terminal (releases#223)\".into(),\n        },\n    ]\n}\n\n/// The control surface an attach request gates against: a read-only viewer is\n/// `RC_VIEW`, while Control/Take — the intents that can drive the terminal —\n/// gate as `RC_ATTACH`. Splitting them lets an operator publish a view of an\n/// endpoint without also handing over its keyboard.\n// [impl->REQ-ACL-RC-VIEW-SPLIT]\nfn attach_surface(intent: AttachIntent) -> &'static str {\n    match intent {\n        AttachIntent::Viewer => surface::RC_VIEW,\n        AttachIntent::Control | AttachIntent::Take => surface::RC_ATTACH,\n    }\n}\n\n/// What the engine room's structural locks say about one attach attempt\n/// (ADR-0052 §3).\n#[derive(Debug, Clone, Copy, PartialEq, Eq)]\npub enum EngineRoomLock {\n    /// Not the engine room, or an attach its locks allow.\n    Pass,\n    /// The engine room has no viewport at ANY origin — refused.\n    NoViewport,\n    /// The engine room takes its controls from its own node only — refused.\n    NotFromOffNode,\n}\n\n/// The engine room's rc locks, pure (ADR-0052 §3: \"no rc view; controls from\n/// the node itself\").\n///\n/// Two things make this a CARVE-OUT rather than a rule row in the access store:\n///\n/// - it must beat the same-node loopback `Allow`, which precedes the resolution\n///   chain (`access::access_check` step 1) — and a local `rc` reaches the target\n///   over exactly that loopback origin, so a chain-level rule could never see it;\n/// - the engine room's operator must not be able to open a viewport by writing\n///   themself a rule. A watchable governance surface is a governance surface\n///   whose secrets are watchable.\n///\n/// `from_this_node` is the handshake-proven origin's own-node answer (a local\n/// IPC subscribe with no origin is this node by construction), never anything a\n/// caller supplied (KNOWN-HAZARDS 7.5).\n// [impl->REQ-ER-RC-INTENT-LOCKS]\npub fn classify_rc_lock(\n    is_engine_room: bool,\n    from_this_node: bool,\n    intent: AttachIntent,\n) -> EngineRoomLock {\n    if !is_engine_room {\n        return EngineRoomLock::Pass;\n    }\n    // View is refused FIRST and unconditionally: it is the lock that holds even\n    // at the console, so an off-node viewer hears the reason that would still\n    // apply if it moved to this machine.\n    if intent == AttachIntent::Viewer {\n        return EngineRoomLock::NoViewport;\n    }\n    if !from_this_node {\n        return EngineRoomLock::NotFromOffNode;\n    }\n    // Local Control and local Take both pass — a take displaces the incumbent\n    // loudly and drops its authority (ADR-0052 §3a); it is not a lesser intent.\n    EngineRoomLock::Pass\n}\n\nuse crate::brain::{now_ms, Brain, BrokerEvent};\nuse crate::effect::{Minter, MintedOp};\nuse crate::msg::{decode_bytes, encode_bytes};\n\n/// Feed the resting-state machine at the attach edges (D9-2, REQ-INST-3): a\n/// served viewport is a **driver** — attaching wakes the endpoint, the\n/// viewport ending detaches it (active → dormant; the transition echo is\n/// gate-armed for the endpoint's own pulse loop). Best-effort exactly like\n/// [`mark_driven_by`]: a session served without a perch has no resting\n/// record to move.\n// [impl->REQ-INST-3]\nfn feed_rest(endpoint: &str, event: crate::resting::RestEvent) {\n    let _ = crate::resting::daemon_rest_event(endpoint, event, None);\n}\n\n/// Why a serve loop returned.\n#[derive(Debug, Clone, PartialEq, Eq)]\npub enum AttachServeOutcome {\n    /// The access gate refused the requesting origin, OR a `Control` attach hit\n    /// an endpoint a DIFFERENT operator already controls (busy-refuse,\n    /// REQ-RCVIEW-1) — nothing was served. The operator's `rc` renders the\n    /// busy guidance client-side from the endpoint's `driven_by`.\n    Refused,\n    /// The session's child exited; the `Exit` record was sent and the stream\n    /// finished.\n    Exited(Option<i32>),\n    /// The operator closed its send side (detached); the viewport ended with\n    /// the session still running.\n    Detached,\n    /// This controller was DISPLACED by a different operator's `--take`/`kick`\n    /// (REQ-KICK-1): the loud `Displaced` notice was sent and the stream\n    /// finished. The endpoint stays driven (by the taker) — no dormant edge.\n    Displaced,\n}\n\n/// The role a serve loop resolved to, once the broker's [`SubscribeOutcome`]\n/// arrives — gates wake (controller-only) and PTY input.\n#[derive(Debug, Clone, Copy, PartialEq, Eq)]\nenum ServeRole {\n    /// The interactive controller (input + resize; wakes the endpoint).\n    Controller,\n    /// A read-only viewer (output only; wake-neutral).\n    Viewer,\n}\n\n/// Minimum spacing between skip-to-live re-subscribes after a viewer eviction\n/// (REQ-VIEWER-SKIP-TO-LIVE-ON-EVICT). HARD constraint: an evicted viewer that is\n/// hopelessly behind under a sustained flood will be re-evicted immediately after\n/// each re-subscribe; without spacing that is an evict→resubscribe CPU spin. With\n/// it, the operator sees an intermittent LIVE burst each interval (forward\n/// progress), never a busy-loop. ~200ms = several bursts/sec, imperceptible lag.\nconst RESUBSCRIBE_INTERVAL: Duration = Duration::from_millis(200);\n\n/// The CONTROLLER fell behind the live ring further than the ring holds — the\n/// dropped frames are GONE (`tail - delivered_through > cap_chunks`), so an\n/// exactly-once re-fetch is IMPOSSIBLE. Distinguishes the irrecoverable edge from\n/// an ordinary fatal so the serve loop can surface it (a marked truncation),\n/// rather than silent-skipping (a B2 lie) or spinning. Full graceful handling is\n/// DEFERRED to `REQ-HAZARD-CONTROLLER-IRRECOVERABLE-BEHIND`.\n// [impl->REQ-HAZARD-CONTROLLER-GAP-RESUME]\n#[derive(Debug)]\npub struct ControllerIrrecoverablyBehind {\n    /// The frozen `delivered_through` floor the ring has already rolled past.\n    pub floor: u64,\n}\n\nimpl std::fmt::Display for ControllerIrrecoverablyBehind {\n    fn fmt(&self, f: &mut std::fmt::Formatter<'_>) -> std::fmt::Result {\n        write!(\n            f,\n            \"controller fell irrecoverably behind the live ring at seq {} (dropped frames rolled out of the ring)\",\n            self.floor\n        )\n    }\n}\n\nimpl std::error::Error for ControllerIrrecoverablyBehind {}\n\n/// Is `e` the brain's strict reject-gap fatal (`output gap: got seq N want M`)?\n/// That is the only error the controller gap-resume recovers from; every other\n/// error propagates unchanged.\nfn is_output_gap(e: &io::Error) -> bool {\n    e.kind() == io::ErrorKind::InvalidData && e.to_string().contains(\"output gap\")\n}\n\n/// Read one [`BrokerEvent`] for an attached CONTROLLER, RESUMING-FROM-FLOOR on a\n/// b4 drop-don't-block output-gap instead of fataling.\n///\n/// b4 made the controller a non-blocking `try_send` that DROPS frames when its\n/// bounded channel is full (a controller that falls behind its own echo under a\n/// hard flood). The next frame this reader sees is then a FORWARD gap that the\n/// strict reject-gap (`read_event`, legacy single-session path) FATALS. A\n/// controller CANNOT snap-above like a viewer (B2: it is authoritative — it\n/// advances `delivered_through`; skipping rolled frames would be a not-exactly-once\n/// resume). So instead it RE-FETCHES: re-subscribe from\n/// [`Brain::controller_resume_floor`] (`= delivered_through`, frozen at the drop by\n/// `contiguous_advance`) and the broker replays the dropped frames from the ring.\n///\n/// Exactly-once holds IFF the ring still retains the floor (`tail - delivered_through\n/// <= cap_chunks`). If it does not — the controller fell behind further than the\n/// ring holds — the re-subscribe's first frame is STILL a forward gap (floor\n/// unchanged across two resumes). That is [`ControllerIrrecoverablyBehind`]: the\n/// caller surfaces it (marked truncation), never silent-skips (B2 lie) and never\n/// spins. The helper swallows the `Subscribed` ack its own re-subscribe produces so\n/// the repeated-gap detection is not masked. Non-`Output` events (NetStreamData /\n/// Size / Exit / …) pass through unchanged.\n// [impl->REQ-HAZARD-CONTROLLER-GAP-RESUME]\n/// `gen` is the serve worker's attach generation (ADR-0038 Amendment fix 6):\n/// the resume re-subscribe is the SAME Request re-fetching dropped frames, so\n/// it must carry the SAME generation — an equal-gen re-take preserves the\n/// incumbent `attach_gen`. Passing 0 here would reset the slot to legacy and\n/// (a) re-arm the stale-replay steal fix 6 refuses and (b) make the worker's\n/// own terminal `detach_session_gen` mismatch the slot it re-installed.\n// [impl->REQ-SERVE-OWNERSHIP-GENERATION]\npub fn read_controller_event_resuming(\n    brain: &mut Brain,\n    session_id: u64,\n    gen: u64,\n    by: Option<&str>,\n) -> io::Result<BrokerEvent> {\n    read_controller_event_resuming_until(brain, session_id, gen, by, None)\n}\n\n/// Deadline-aware form of [`read_controller_event_resuming`].\n///\n/// Production callers pass no deadline through the wrapper above. Timed observers\n/// use this form so a quiet controller cannot hide their wall-clock bound inside an\n/// unbounded frame read.\npub fn read_controller_event_resuming_until(\n    brain: &mut Brain,\n    session_id: u64,\n    gen: u64,\n    by: Option<&str>,\n    deadline: Option<Instant>,\n) -> io::Result<BrokerEvent> {\n    let mut last_resume_floor: Option<u64> = None;\n    let mut swallow_resume_ack = false;\n    loop {\n        match brain.read_event_until(deadline) {\n            // Our own re-subscribe's Subscribed reply: swallow it (role is already\n            // resolved) so it cannot mask a repeated gap as forward progress.\n            Ok(BrokerEvent::Subscribed { .. }) if swallow_resume_ack => {\n                swallow_resume_ack = false;\n                continue;\n            }\n            Ok(ev) => return Ok(ev),\n            Err(e) if is_output_gap(&e) => {\n                let floor = brain.controller_resume_floor();\n                if last_resume_floor == Some(floor) {\n                    // No progress across two resumes → the ring rolled past the\n                    // floor → the dropped frames are gone.\n                    return Err(io::Error::other(ControllerIrrecoverablyBehind { floor }));\n                }\n                last_resume_floor = Some(floor);\n                // RE-FETCH from the frozen delivered_through (same operator `by` →\n                // a silent re-take, no Displaced); the broker replays the dropped\n                // frames from the ring.\n                // No bring-up code here, and none is needed: this re-subscribe\n                // arrives on the connection that already holds the seat, which is\n                // exactly the exemption `engineroom::bringup_required` names — a\n                // controller must not lose a gated endpoint's controls for having\n                // fallen behind its own output.\n                // THE decision, bound ONCE and passed: the same value is logged and\n…\n            }\n…\n        }\n    }\n}\n\n[Showing lines 1-300 of 1159. Use :301 to continue]"}],"details":{"truncation":{"content":"//! Remote terminal attach (M4-D5b, REQ-INST-8) — serve a byte-stream viewport\r\n//! onto a local session for an operator on another node.\r\n//!\r\n//! The operator's daemon opened a bidi QUIC stream to this node (D4) and sent\r\n//! [`AttachRecord::Request`]; this module is the target-side pump between that\r\n//! stream and the local broker-hosted session:\r\n//!\r\n//! - session `Output` chunks → [`AttachRecord::Output`] lines onto the wire\r\n//!   (fire-and-forget sends; `Output.seq` carries the dedup authority);\r\n//! - inbound [`AttachRecord::Input`] → [`Brain::send_effect`] with the\r\n//!   operator-minted `op_id` — exactly-once at the PTY write through the B5\r\n//!   journal (a replayed input record cannot double-type);\r\n//! - session `Exit` → [`AttachRecord::Exit`] + stream finish.\r\n//!\r\n//! ## Exactly-once lives at the EDGES, not the wire sends\r\n//!\r\n//! Stream sends here are deliberately **unjournaled** (`op_id: None`): a\r\n//! journaled [`Brain::net_stream_send`] blocks reading events until its ack\r\n//! and *discards* everything interleaved — inside a full-duplex pump loop that\r\n//! eats the operator's `Input` records (both sides starve; found the hard way\r\n//! in `tests/attach.rs`). Idempotency holds without it because each direction\r\n//! dedups at its **effect**: the PTY write is journaled by the operator-minted\r\n//! `Input.op_id`, and the operator's viewport dedups `Output` records by their\r\n//! session-log `seq` (the render cursor). A post-restart re-serve may\r\n//! re-transmit output records on the wire — duplicates are dropped at the\r\n//! render cursor, the same discipline the local `OutputLog` replay uses\r\n//! (REQ-HAZARD-RESTART-IDEMPOTENT at the boundary that matters).\r\n//!\r\n//! **Compute + files stay here**; the operator is a viewport (CONTEXT\r\n//! §Remote-control vs local operation). The access gate runs before anything\r\n//! is served: the [`AttachRecord::Request`] is *unsolicited wire inbound*, so\r\n//! [`access_check`] sees the **handshake-proven** origin from the broker's\r\n//! stream table — never payload bytes (KNOWN-HAZARDS 7.5). Remote-drive of\r\n//! your own running instance is ungated by default (ADR-0009 default-open);\r\n//! the D5d whitelist drops in at this same call.\r\n//!\r\n//! Restart survival composes from D4/B5 with **no new machinery**: the broker\r\n//! owns the QUIC stream, the session, its `OutputLog`, and the effect journal.\r\n//! A restarted target brain re-attaches the session from its output cursor,\r\n//! resubscribes the stream from its net cursor, and re-drives journaled sends;\r\n//! a restarted operator brain resubscribes and dedups rendered chunks by\r\n//! `Output.seq`.\r\n\r\nuse std::io;\r\nuse std::time::{Duration, Instant};\r\n\r\nuse spt_net::net::attach::{\r\n    AttachClientIdentity, AttachClientPolicy, AttachDecoder, AttachIntent, AttachRecord,\r\n};\r\nuse spt_net::net::ndjson;\r\n\r\nuse crate::access::{access_check, surface, InboundClass};\r\n\r\n/// Raise a floor only for demonstrated rc defects, not ordinary release skew.\r\n/// releases#230 replayed #222's Windows Hello refusal and #223's admitted\r\n/// ceremony residue in a pre-0.63.0 controller. Read-only viewers receive no\r\n/// ceremonies, so neither defect honestly applies to their role.\r\n// [impl->REQ-ATTACH-CLIENT-STALE]\r\npub fn attach_client_policy() -> Vec<AttachClientPolicy> {\r\n    vec![\r\n        AttachClientPolicy {\r\n            minimum_version: \"0.63.0\".into(),\r\n            platforms: vec![\"windows\".into()],\r\n            roles: vec![AttachIntent::Control],\r\n            reason: \"Windows authenticator enrollment can refuse with NCrypt 0x80090027 (releases#222)\".into(),\r\n        },\r\n        AttachClientPolicy {\r\n            minimum_version: \"0.63.0\".into(),\r\n            platforms: vec![\"windows\".into(), \"linux\".into(), \"macos\".into()],\r\n            roles: vec![AttachIntent::Control],\r\n            reason: \"admitted seal ceremonies leave a stranded notice in the terminal (releases#223)\".into(),\r\n        },\r\n    ]\r\n}\r\n\r\n/// The control surface an attach request gates against: a read-only viewer is\r\n/// `RC_VIEW`, while Control/Take — the intents that can drive the terminal —\r\n/// gate as `RC_ATTACH`. Splitting them lets an operator publish a view of an\r\n/// endpoint without also handing over its keyboard.\r\n// [impl->REQ-ACL-RC-VIEW-SPLIT]\r\nfn attach_surface(intent: AttachIntent) -> &'static str {\r\n    match intent {\r\n        AttachIntent::Viewer => surface::RC_VIEW,\r\n        AttachIntent::Control | AttachIntent::Take => surface::RC_ATTACH,\r\n    }\r\n}\r\n\r\n/// What the engine room's structural locks say about one attach attempt\r\n/// (ADR-0052 §3).\r\n#[derive(Debug, Clone, Copy, PartialEq, Eq)]\r\npub enum EngineRoomLock {\r\n    /// Not the engine room, or an attach its locks allow.\r\n    Pass,\r\n    /// The engine room has no viewport at ANY origin — refused.\r\n    NoViewport,\r\n    /// The engine room takes its controls from its own node only — refused.\r\n    NotFromOffNode,\r\n}\r\n\r\n/// The engine room's rc locks, pure (ADR-0052 §3: \"no rc view; controls from\r\n/// the node itself\").\r\n///\r\n/// Two things make this a CARVE-OUT rather than a rule row in the access store:\r\n///\r\n/// - it must beat the same-node loopback `Allow`, which precedes the resolution\r\n///   chain (`access::access_check` step 1) — and a local `rc` reaches the target\r\n///   over exactly that loopback origin, so a chain-level rule could never see it;\r\n/// - the engine room's operator must not be able to open a viewport by writing\r\n///   themself a rule. A watchable governance surface is a governance surface\r\n///   whose secrets are watchable.\r\n///\r\n/// `from_this_node` is the handshake-proven origin's own-node answer (a local\r\n/// IPC subscribe with no origin is this node by construction), never anything a\r\n/// caller supplied (KNOWN-HAZARDS 7.5).\r\n// [impl->REQ-ER-RC-INTENT-LOCKS]\r\npub fn classify_rc_lock(\r\n    is_engine_room: bool,\r\n    from_this_node: bool,\r\n    intent: AttachIntent,\r\n) -> EngineRoomLock {\r\n    if !is_engine_room {\r\n        return EngineRoomLock::Pass;\r\n    }\r\n    // View is refused FIRST and unconditionally: it is the lock that holds even\r\n    // at the console, so an off-node viewer hears the reason that would still\r\n    // apply if it moved to this machine.\r\n    if intent == AttachIntent::Viewer {\r\n        return EngineRoomLock::NoViewport;\r\n    }\r\n    if !from_this_node {\r\n        return EngineRoomLock::NotFromOffNode;\r\n    }\r\n    // Local Control and local Take both pass — a take displaces the incumbent\r\n    // loudly and drops its authority (ADR-0052 §3a); it is not a lesser intent.\r\n    EngineRoomLock::Pass\r\n}\r\n\r\nuse crate::brain::{now_ms, Brain, BrokerEvent};\r\nuse crate::effect::{Minter, MintedOp};\r\nuse crate::msg::{decode_bytes, encode_bytes};\r\n\r\n/// Feed the resting-state machine at the attach edges (D9-2, REQ-INST-3): a\r\n/// served viewport is a **driver** — attaching wakes the endpoint, the\r\n/// viewport ending detaches it (active → dormant; the transition echo is\r\n/// gate-armed for the endpoint's own pulse loop). Best-effort exactly like\r\n/// [`mark_driven_by`]: a session served without a perch has no resting\r\n/// record to move.\r\n// [impl->REQ-INST-3]\r\nfn feed_rest(endpoint: &str, event: crate::resting::RestEvent) {\r\n    let _ = crate::resting::daemon_rest_event(endpoint, event, None);\r\n}\r\n\r\n/// Why a serve loop returned.\r\n#[derive(Debug, Clone, PartialEq, Eq)]\r\npub enum AttachServeOutcome {\r\n    /// The access gate refused the requesting origin, OR a `Control` attach hit\r\n    /// an endpoint a DIFFERENT operator already controls (busy-refuse,\r\n    /// REQ-RCVIEW-1) — nothing was served. The operator's `rc` renders the\r\n    /// busy guidance client-side from the endpoint's `driven_by`.\r\n    Refused,\r\n    /// The session's child exited; the `Exit` record was sent and the stream\r\n    /// finished.\r\n    Exited(Option<i32>),\r\n    /// The operator closed its send side (detached); the viewport ended with\r\n    /// the session still running.\r\n    Detached,\r\n    /// This controller was DISPLACED by a different operator's `--take`/`kick`\r\n    /// (REQ-KICK-1): the loud `Displaced` notice was sent and the stream\r\n    /// finished. The endpoint stays driven (by the taker) — no dormant edge.\r\n    Displaced,\r\n}\r\n\r\n/// The role a serve loop resolved to, once the broker's [`SubscribeOutcome`]\r\n/// arrives — gates wake (controller-only) and PTY input.\r\n#[derive(Debug, Clone, Copy, PartialEq, Eq)]\r\nenum ServeRole {\r\n    /// The interactive controller (input + resize; wakes the endpoint).\r\n    Controller,\r\n    /// A read-only viewer (output only; wake-neutral).\r\n    Viewer,\r\n}\r\n\r\n/// Minimum spacing between skip-to-live re-subscribes after a viewer eviction\r\n/// (REQ-VIEWER-SKIP-TO-LIVE-ON-EVICT). HARD constraint: an evicted viewer that is\r\n/// hopelessly behind under a sustained flood will be re-evicted immediately after\r\n/// each re-subscribe; without spacing that is an evict→resubscribe CPU spin. With\r\n/// it, the operator sees an intermittent LIVE burst each interval (forward\r\n/// progress), never a busy-loop. ~200ms = several bursts/sec, imperceptible lag.\r\nconst RESUBSCRIBE_INTERVAL: Duration = Duration::from_millis(200);\r\n\r\n/// The CONTROLLER fell behind the live ring further than the ring holds — the\r\n/// dropped frames are GONE (`tail - delivered_through > cap_chunks`), so an\r\n/// exactly-once re-fetch is IMPOSSIBLE. Distinguishes the irrecoverable edge from\r\n/// an ordinary fatal so the serve loop can surface it (a marked truncation),\r\n/// rather than silent-skipping (a B2 lie) or spinning. Full graceful handling is\r\n/// DEFERRED to `REQ-HAZARD-CONTROLLER-IRRECOVERABLE-BEHIND`.\r\n// [impl->REQ-HAZARD-CONTROLLER-GAP-RESUME]\r\n#[derive(Debug)]\r\npub struct ControllerIrrecoverablyBehind {\r\n    /// The frozen `delivered_through` floor the ring has already rolled past.\r\n    pub floor: u64,\r\n}\r\n\r\nimpl std::fmt::Display for ControllerIrrecoverablyBehind {\r\n    fn fmt(&self, f: &mut std::fmt::Formatter<'_>) -> std::fmt::Result {\r\n        write!(\r\n            f,\r\n            \"controller fell irrecoverably behind the live ring at seq {} (dropped frames rolled out of the ring)\",\r\n            self.floor\r\n        )\r\n    }\r\n}\r\n\r\nimpl std::error::Error for ControllerIrrecoverablyBehind {}\r\n\r\n/// Is `e` the brain's strict reject-gap fatal (`output gap: got seq N want M`)?\r\n/// That is the only error the controller gap-resume recovers from; every other\r\n/// error propagates unchanged.\r\nfn is_output_gap(e: &io::Error) -> bool {\r\n    e.kind() == io::ErrorKind::InvalidData && e.to_string().contains(\"output gap\")\r\n}\r\n\r\n/// Read one [`BrokerEvent`] for an attached CONTROLLER, RESUMING-FROM-FLOOR on a\r\n/// b4 drop-don't-block output-gap instead of fataling.\r\n///\r\n/// b4 made the controller a non-blocking `try_send` that DROPS frames when its\r\n/// bounded channel is full (a controller that falls behind its own echo under a\r\n/// hard flood). The next frame this reader sees is then a FORWARD gap that the\r\n/// strict reject-gap (`read_event`, legacy single-session path) FATALS. A\r\n/// controller CANNOT snap-above like a viewer (B2: it is authoritative — it\r\n/// advances `delivered_through`; skipping rolled frames would be a not-exactly-once\r\n/// resume). So instead it RE-FETCHES: re-subscribe from\r\n/// [`Brain::controller_resume_floor`] (`= delivered_through`, frozen at the drop by\r\n/// `contiguous_advance`) and the broker replays the dropped frames from the ring.\r\n///\r\n/// Exactly-once holds IFF the ring still retains the floor (`tail - delivered_through\r\n/// <= cap_chunks`). If it does not — the controller fell behind further than the\r\n/// ring holds — the re-subscribe's first frame is STILL a forward gap (floor\r\n/// unchanged across two resumes). That is [`ControllerIrrecoverablyBehind`]: the\r\n/// caller surfaces it (marked truncation), never silent-skips (B2 lie) and never\r\n/// spins. The helper swallows the `Subscribed` ack its own re-subscribe produces so\r\n/// the repeated-gap detection is not masked. Non-`Output` events (NetStreamData /\r\n/// Size / Exit / …) pass through unchanged.\r\n// [impl->REQ-HAZARD-CONTROLLER-GAP-RESUME]\r\n/// `gen` is the serve worker's attach generation (ADR-0038 Amendment fix 6):\r\n/// the resume re-subscribe is the SAME Request re-fetching dropped frames, so\r\n/// it must carry the SAME generation — an equal-gen re-take preserves the\r\n/// incumbent `attach_gen`. Passing 0 here would reset the slot to legacy and\r\n/// (a) re-arm the stale-replay steal fix 6 refuses and (b) make the worker's\r\n/// own terminal `detach_session_gen` mismatch the slot it re-installed.\r\n// [impl->REQ-SERVE-OWNERSHIP-GENERATION]\r\npub fn read_controller_event_resuming(\r\n    brain: &mut Brain,\r\n    session_id: u64,\r\n    gen: u64,\r\n    by: Option<&str>,\r\n) -> io::Result<BrokerEvent> {\r\n    read_controller_event_resuming_until(brain, session_id, gen, by, None)\r\n}\r\n\r\n/// Deadline-aware form of [`read_controller_event_resuming`].\r\n///\r\n/// Production callers pass no deadline through the wrapper above. Timed observers\r\n/// use this form so a quiet controller cannot hide their wall-clock bound inside an\r\n/// unbounded frame read.\r\npub fn read_controller_event_resuming_until(\r\n    brain: &mut Brain,\r\n    session_id: u64,\r\n    gen: u64,\r\n    by: Option<&str>,\r\n    deadline: Option<Instant>,\r\n) -> io::Result<BrokerEvent> {\r\n    let mut last_resume_floor: Option<u64> = None;\r\n    let mut swallow_resume_ack = false;\r\n    loop {\r\n        match brain.read_event_until(deadline) {\r\n            // Our own re-subscribe's Subscribed reply: swallow it (role is already\r\n            // resolved) so it cannot mask a repeated gap as forward progress.\r\n            Ok(BrokerEvent::Subscribed { .. }) if swallow_resume_ack => {\r\n                swallow_resume_ack = false;\r\n                continue;\r\n            }\r\n            Ok(ev) => return Ok(ev),\r\n            Err(e) if is_output_gap(&e) => {\r\n                let floor = brain.controller_resume_floor();\r\n                if last_resume_floor == Some(floor) {\r\n                    // No progress across two resumes → the ring rolled past the\r\n                    // floor → the dropped frames are gone.\r\n                    return Err(io::Error::other(ControllerIrrecoverablyBehind { floor }));\r\n                }\r\n                last_resume_floor = Some(floor);\r\n                // RE-FETCH from the frozen delivered_through (same operator `by` →\r\n                // a silent re-take, no Displaced); the broker replays the dropped\r\n                // frames from the ring.\r\n                // No bring-up code here, and none is needed: this re-subscribe\r\n                // arrives on the connection that already holds the seat, which is\r\n                // exactly the exemption `engineroom::bringup_required` names — a\r\n                // controller must not lose a gated endpoint's controls for having\r\n                // fallen behind its own output.\r\n                // THE decision, bound ONCE and passed: the same value is logged and\r","truncated":true,"truncatedBy":"lines","totalLines":1159,"totalBytes":15015,"outputLines":300,"outputBytes":15015,"lastLinePartial":false,"firstLineExceedsLimit":false},"totalLines":1159,"displayContent":{"text":"//! Remote terminal attach (M4-D5b, REQ-INST-8) — serve a byte-stream viewport\r\n//! onto a local session for an operator on another node.\r\n//!\r\n//! The operator's daemon opened a bidi QUIC stream to this node (D4) and sent\r\n//! [`AttachRecord::Request`]; this module is the target-side pump between that\r\n//! stream and the local broker-hosted session:\r\n//!\r\n//! - session `Output` chunks → [`AttachRecord::Output`] lines onto the wire\r\n//!   (fire-and-forget sends; `Output.seq` carries the dedup authority);\r\n//! - inbound [`AttachRecord::Input`] → [`Brain::send_effect`] with the\r\n//!   operator-minted `op_id` — exactly-once at the PTY write through the B5\r\n//!   journal (a replayed input record cannot double-type);\r\n//! - session `Exit` → [`AttachRecord::Exit`] + stream finish.\r\n//!\r\n//! ## Exactly-once lives at the EDGES, not the wire sends\r\n//!\r\n//! Stream sends here are deliberately **unjournaled** (`op_id: None`): a\r\n//! journaled [`Brain::net_stream_send`] blocks reading events until its ack\r\n//! and *discards* everything interleaved — inside a full-duplex pump loop that\r\n//! eats the operator's `Input` records (both sides starve; found the hard way\r\n//! in `tests/attach.rs`). Idempotency holds without it because each direction\r\n//! dedups at its **effect**: the PTY write is journaled by the operator-minted\r\n//! `Input.op_id`, and the operator's viewport dedups `Output` records by their\r\n//! session-log `seq` (the render cursor). A post-restart re-serve may\r\n//! re-transmit output records on the wire — duplicates are dropped at the\r\n//! render cursor, the same discipline the local `OutputLog` replay uses\r\n//! (REQ-HAZARD-RESTART-IDEMPOTENT at the boundary that matters).\r\n//!\r\n//! **Compute + files stay here**; the operator is a viewport (CONTEXT\r\n//! §Remote-control vs local operation). The access gate runs before anything\r\n//! is served: the [`AttachRecord::Request`] is *unsolicited wire inbound*, so\r\n//! [`access_check`] sees the **handshake-proven** origin from the broker's\r\n//! stream table — never payload bytes (KNOWN-HAZARDS 7.5). Remote-drive of\r\n//! your own running instance is ungated by default (ADR-0009 default-open);\r\n//! the D5d whitelist drops in at this same call.\r\n//!\r\n//! Restart survival composes from D4/B5 with **no new machinery**: the broker\r\n//! owns the QUIC stream, the session, its `OutputLog`, and the effect journal.\r\n//! A restarted target brain re-attaches the session from its output cursor,\r\n//! resubscribes the stream from its net cursor, and re-drives journaled sends;\r\n//! a restarted operator brain resubscribes and dedups rendered chunks by\r\n//! `Output.seq`.\r\n\r\nuse std::io;\r\nuse std::time::{Duration, Instant};\r\n\r\nuse spt_net::net::attach::{\r\n    AttachClientIdentity, AttachClientPolicy, AttachDecoder, AttachIntent, AttachRecord,\r\n};\r\nuse spt_net::net::ndjson;\r\n\r\nuse crate::access::{access_check, surface, InboundClass};\r\n\r\n/// Raise a floor only for demonstrated rc defects, not ordinary release skew.\r\n/// releases#230 replayed #222's Windows Hello refusal and #223's admitted\r\n/// ceremony residue in a pre-0.63.0 controller. Read-only viewers receive no\r\n/// ceremonies, so neither defect honestly applies to their role.\r\n// [impl->REQ-ATTACH-CLIENT-STALE]\r\npub fn attach_client_policy() -> Vec<AttachClientPolicy> {\r\n    vec![\r\n        AttachClientPolicy {\r\n            minimum_version: \"0.63.0\".into(),\r\n            platforms: vec![\"windows\".into()],\r\n            roles: vec![AttachIntent::Control],\r\n            reason: \"Windows authenticator enrollment can refuse with NCrypt 0x80090027 (releases#222)\".into(),\r\n        },\r\n        AttachClientPolicy {\r\n            minimum_version: \"0.63.0\".into(),\r\n            platforms: vec![\"windows\".into(), \"linux\".into(), \"macos\".into()],\r\n            roles: vec![AttachIntent::Control],\r\n            reason: \"admitted seal ceremonies leave a stranded notice in the terminal (releases#223)\".into(),\r\n        },\r\n    ]\r\n}\r\n\r\n/// The control surface an attach request gates against: a read-only viewer is\r\n/// `RC_VIEW`, while Control/Take — the intents that can drive the terminal —\r\n/// gate as `RC_ATTACH`. Splitting them lets an operator publish a view of an\r\n/// endpoint without also handing over its keyboard.\r\n// [impl->REQ-ACL-RC-VIEW-SPLIT]\r\nfn attach_surface(intent: AttachIntent) -> &'static str {\r\n    match intent {\r\n        AttachIntent::Viewer => surface::RC_VIEW,\r\n        AttachIntent::Control | AttachIntent::Take => surface::RC_ATTACH,\r\n    }\r\n}\r\n\r\n/// What the engine room's structural locks say about one attach attempt\r\n/// (ADR-0052 §3).\r\n#[derive(Debug, Clone, Copy, PartialEq, Eq)]\r\npub enum EngineRoomLock {\r\n    /// Not the engine room, or an attach its locks allow.\r\n    Pass,\r\n    /// The engine room has no viewport at ANY origin — refused.\r\n    NoViewport,\r\n    /// The engine room takes its controls from its own node only — refused.\r\n    NotFromOffNode,\r\n}\r\n\r\n/// The engine room's rc locks, pure (ADR-0052 §3: \"no rc view; controls from\r\n/// the node itself\").\r\n///\r\n/// Two things make this a CARVE-OUT rather than a rule row in the access store:\r\n///\r\n/// - it must beat the same-node loopback `Allow`, which precedes the resolution\r\n///   chain (`access::access_check` step 1) — and a local `rc` reaches the target\r\n///   over exactly that loopback origin, so a chain-level rule could never see it;\r\n/// - the engine room's operator must not be able to open a viewport by writing\r\n///   themself a rule. A watchable governance surface is a governance surface\r\n///   whose secrets are watchable.\r\n///\r\n/// `from_this_node` is the handshake-proven origin's own-node answer (a local\r\n/// IPC subscribe with no origin is this node by construction), never anything a\r\n/// caller supplied (KNOWN-HAZARDS 7.5).\r\n// [impl->REQ-ER-RC-INTENT-LOCKS]\r\npub fn classify_rc_lock(\r\n    is_engine_room: bool,\r\n    from_this_node: bool,\r\n    intent: AttachIntent,\r\n) -> EngineRoomLock {\r\n    if !is_engine_room {\r\n        return EngineRoomLock::Pass;\r\n    }\r\n    // View is refused FIRST and unconditionally: it is the lock that holds even\r\n    // at the console, so an off-node viewer hears the reason that would still\r\n    // apply if it moved to this machine.\r\n    if intent == AttachIntent::Viewer {\r\n        return EngineRoomLock::NoViewport;\r\n    }\r\n    if !from_this_node {\r\n        return EngineRoomLock::NotFromOffNode;\r\n    }\r\n    // Local Control and local Take both pass — a take displaces the incumbent\r\n    // loudly and drops its authority (ADR-0052 §3a); it is not a lesser intent.\r\n    EngineRoomLock::Pass\r\n}\r\n\r\nuse crate::brain::{now_ms, Brain, BrokerEvent};\r\nuse crate::effect::{Minter, MintedOp};\r\nuse crate::msg::{decode_bytes, encode_bytes};\r\n\r\n/// Feed the resting-state machine at the attach edges (D9-2, REQ-INST-3): a\r\n/// served viewport is a **driver** — attaching wakes the endpoint, the\r\n/// viewport ending detaches it (active → dormant; the transition echo is\r\n/// gate-armed for the endpoint's own pulse loop). Best-effort exactly like\r\n/// [`mark_driven_by`]: a session served without a perch has no resting\r\n/// record to move.\r\n// [impl->REQ-INST-3]\r\nfn feed_rest(endpoint: &str, event: crate::resting::RestEvent) {\r\n    let _ = crate::resting::daemon_rest_event(endpoint, event, None);\r\n}\r\n\r\n/// Why a serve loop returned.\r\n#[derive(Debug, Clone, PartialEq, Eq)]\r\npub enum AttachServeOutcome {\r\n    /// The access gate refused the requesting origin, OR a `Control` attach hit\r\n    /// an endpoint a DIFFERENT operator already controls (busy-refuse,\r\n    /// REQ-RCVIEW-1) — nothing was served. The operator's `rc` renders the\r\n    /// busy guidance client-side from the endpoint's `driven_by`.\r\n    Refused,\r\n    /// The session's child exited; the `Exit` record was sent and the stream\r\n    /// finished.\r\n    Exited(Option<i32>),\r\n    /// The operator closed its send side (detached); the viewport ended with\r\n    /// the session still running.\r\n    Detached,\r\n    /// This controller was DISPLACED by a different operator's `--take`/`kick`\r\n    /// (REQ-KICK-1): the loud `Displaced` notice was sent and the stream\r\n    /// finished. The endpoint stays driven (by the taker) — no dormant edge.\r\n    Displaced,\r\n}\r\n\r\n/// The role a serve loop resolved to, once the broker's [`SubscribeOutcome`]\r\n/// arrives — gates wake (controller-only) and PTY input.\r\n#[derive(Debug, Clone, Copy, PartialEq, Eq)]\r\nenum ServeRole {\r\n    /// The interactive controller (input + resize; wakes the endpoint).\r\n    Controller,\r\n    /// A read-only viewer (output only; wake-neutral).\r\n    Viewer,\r\n}\r\n\r\n/// Minimum spacing between skip-to-live re-subscribes after a viewer eviction\r\n/// (REQ-VIEWER-SKIP-TO-LIVE-ON-EVICT). HARD constraint: an evicted viewer that is\r\n/// hopelessly behind under a sustained flood will be re-evicted immediately after\r\n/// each re-subscribe; without spacing that is an evict→resubscribe CPU spin. With\r\n/// it, the operator sees an intermittent LIVE burst each interval (forward\r\n/// progress), never a busy-loop. ~200ms = several bursts/sec, imperceptible lag.\r\nconst RESUBSCRIBE_INTERVAL: Duration = Duration::from_millis(200);\r\n\r\n/// The CONTROLLER fell behind the live ring further than the ring holds — the\r\n/// dropped frames are GONE (`tail - delivered_through > cap_chunks`), so an\r\n/// exactly-once re-fetch is IMPOSSIBLE. Distinguishes the irrecoverable edge from\r\n/// an ordinary fatal so the serve loop can surface it (a marked truncation),\r\n/// rather than silent-skipping (a B2 lie) or spinning. Full graceful handling is\r\n/// DEFERRED to `REQ-HAZARD-CONTROLLER-IRRECOVERABLE-BEHIND`.\r\n// [impl->REQ-HAZARD-CONTROLLER-GAP-RESUME]\r\n#[derive(Debug)]\r\npub struct ControllerIrrecoverablyBehind {\r\n    /// The frozen `delivered_through` floor the ring has already rolled past.\r\n    pub floor: u64,\r\n}\r\n\r\nimpl std::fmt::Display for ControllerIrrecoverablyBehind {\r\n    fn fmt(&self, f: &mut std::fmt::Formatter<'_>) -> std::fmt::Result {\r\n        write!(\r\n            f,\r\n            \"controller fell irrecoverably behind the live ring at seq {} (dropped frames rolled out of the ring)\",\r\n            self.floor\r\n        )\r\n    }\r\n}\r\n\r\nimpl std::error::Error for ControllerIrrecoverablyBehind {}\r\n\r\n/// Is `e` the brain's strict reject-gap fatal (`output gap: got seq N want M`)?\r\n/// That is the only error the controller gap-resume recovers from; every other\r\n/// error propagates unchanged.\r\nfn is_output_gap(e: &io::Error) -> bool {\r\n    e.kind() == io::ErrorKind::InvalidData && e.to_string().contains(\"output gap\")\r\n}\r\n\r\n/// Read one [`BrokerEvent`] for an attached CONTROLLER, RESUMING-FROM-FLOOR on a\r\n/// b4 drop-don't-block output-gap instead of fataling.\r\n///\r\n/// b4 made the controller a non-blocking `try_send` that DROPS frames when its\r\n/// bounded channel is full (a controller that falls behind its own echo under a\r\n/// hard flood). The next frame this reader sees is then a FORWARD gap that the\r\n/// strict reject-gap (`read_event`, legacy single-session path) FATALS. A\r\n/// controller CANNOT snap-above like a viewer (B2: it is authoritative — it\r\n/// advances `delivered_through`; skipping rolled frames would be a not-exactly-once\r\n/// resume). So instead it RE-FETCHES: re-subscribe from\r\n/// [`Brain::controller_resume_floor`] (`= delivered_through`, frozen at the drop by\r\n/// `contiguous_advance`) and the broker replays the dropped frames from the ring.\r\n///\r\n/// Exactly-once holds IFF the ring still retains the floor (`tail - delivered_through\r\n/// <= cap_chunks`). If it does not — the controller fell behind further than the\r\n/// ring holds — the re-subscribe's first frame is STILL a forward gap (floor\r\n/// unchanged across two resumes). That is [`ControllerIrrecoverablyBehind`]: the\r\n/// caller surfaces it (marked truncation), never silent-skips (B2 lie) and never\r\n/// spins. The helper swallows the `Subscribed` ack its own re-subscribe produces so\r\n/// the repeated-gap detection is not masked. Non-`Output` events (NetStreamData /\r\n/// Size / Exit / …) pass through unchanged.\r\n// [impl->REQ-HAZARD-CONTROLLER-GAP-RESUME]\r\n/// `gen` is the serve worker's attach generation (ADR-0038 Amendment fix 6):\r\n/// the resume re-subscribe is the SAME Request re-fetching dropped frames, so\r\n/// it must carry the SAME generation — an equal-gen re-take preserves the\r\n/// incumbent `attach_gen`. Passing 0 here would reset the slot to legacy and\r\n/// (a) re-arm the stale-replay steal fix 6 refuses and (b) make the worker's\r\n/// own terminal `detach_session_gen` mismatch the slot it re-installed.\r\n// [impl->REQ-SERVE-OWNERSHIP-GENERATION]\r\npub fn read_controller_event_resuming(\r\n    brain: &mut Brain,\r\n    session_id: u64,\r\n    gen: u64,\r\n    by: Option<&str>,\r\n) -> io::Result<BrokerEvent> {\r\n    read_controller_event_resuming_until(brain, session_id, gen, by, None)\r\n}\r\n\r\n/// Deadline-aware form of [`read_controller_event_resuming`].\r\n///\r\n/// Production callers pass no deadline through the wrapper above. Timed observers\r\n/// use this form so a quiet controller cannot hide their wall-clock bound inside an\r\n/// unbounded frame read.\r\npub fn read_controller_event_resuming_until(\r\n    brain: &mut Brain,\r\n    session_id: u64,\r\n    gen: u64,\r\n    by: Option<&str>,\r\n    deadline: Option<Instant>,\r\n) -> io::Result<BrokerEvent> {\r\n    let mut last_resume_floor: Option<u64> = None;\r\n    let mut swallow_resume_ack = false;\r\n    loop {\r\n        match brain.read_event_until(deadline) {\r\n            // Our own re-subscribe's Subscribed reply: swallow it (role is already\r\n            // resolved) so it cannot mask a repeated gap as forward progress.\r\n            Ok(BrokerEvent::Subscribed { .. }) if swallow_resume_ack => {\r\n                swallow_resume_ack = false;\r\n                continue;\r\n            }\r\n            Ok(ev) => return Ok(ev),\r\n            Err(e) if is_output_gap(&e) => {\r\n                let floor = brain.controller_resume_floor();\r\n                if last_resume_floor == Some(floor) {\r\n                    // No progress across two resumes → the ring rolled past the\r\n                    // floor → the dropped frames are gone.\r\n                    return Err(io::Error::other(ControllerIrrecoverablyBehind { floor }));\r\n                }\r\n                last_resume_floor = Some(floor);\r\n                // RE-FETCH from the frozen delivered_through (same operator `by` →\r\n                // a silent re-take, no Displaced); the broker replays the dropped\r\n                // frames from the ring.\r\n                // No bring-up code here, and none is needed: this re-subscribe\r\n                // arrives on the connection that already holds the seat, which is\r\n                // exactly the exemption `engineroom::bringup_required` names — a\r\n                // controller must not lose a gated endpoint's controls for having\r\n                // fallen behind its own output.\r\n                // THE decision, bound ONCE and passed: the same value is logged and\r\n…\n            }\n…\n        }\n    }\n}","startLine":1,"lineNumbers":[1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95,96,97,98,99,100,101,102,103,104,105,106,107,108,109,110,111,112,113,114,115,116,117,118,119,120,121,122,123,124,125,126,127,128,129,130,131,132,133,134,135,136,137,138,139,140,141,142,143,144,145,146,147,148,149,150,151,152,153,154,155,156,157,158,159,160,161,162,163,164,165,166,167,168,169,170,171,172,173,174,175,176,177,178,179,180,181,182,183,184,185,186,187,188,189,190,191,192,193,194,195,196,197,198,199,200,201,202,203,204,205,206,207,208,209,210,211,212,213,214,215,216,217,218,219,220,221,222,223,224,225,226,227,228,229,230,231,232,233,234,235,236,237,238,239,240,241,242,243,244,245,246,247,248,249,250,251,252,253,254,255,256,257,258,259,260,261,262,263,264,265,266,267,268,269,270,271,272,273,274,275,276,277,278,279,280,281,282,283,284,285,286,287,288,289,290,291,292,293,294,295,296,297,298,299,300,null,324,null,326,327,328]},"fileSize":57673,"meta":{"source":{"type":"path","value":"C:\\Users\\decid\\Documents\\projects\\spt-core\\crates\\spt-daemon\\src\\attach.rs"},"truncation":{"direction":"head","truncatedBy":"lines","totalLines":1159,"totalBytes":15015,"outputLines":300,"outputBytes":15015,"shownRange":{"start":1,"end":300},"nextOffset":301}}},"isError":false,"timestamp":1789523955934}}
{"type":"message","id":"b699c00c","parentId":"f95d547d","timestamp":"2026-09-16T01:59:15.950Z","message":{"role":"toolResult","toolCallId":"call_VUQqg2pboVBoKwrgwhe1CbUH|fc_09b01b5279447709016aa9f7f1662087d2a27f8e94458f3efb","toolName":"read","content":[{"type":"text","text":"//! Inbound net-stream dispatch (D9-1) — the daemon-side acceptor that turns\n//! the hand-wired serve loops of D5–D8 into production behavior.\n//!\n//! Every E2E test so far drove the serve half manually (a probe brain calling\n//! `serve_sync` / `serve_update` / `apply_notif_feed` / `receive_wan` against\n//! a known stream). In production nothing did — a peer could dial and write\n//! and the bytes sat in the broker's stream log unread. This module is the\n//! missing consumer: a daemon-hosted loop that watches the broker's stream\n//! table for **peer-initiated** streams, classifies each by its first NDJSON\n//! record, and hands it to the right serve loop on its own worker thread.\n//!\n//! ## Direction (the gotcha-#9 fact, now first-class)\n//!\n//! The stream table holds locally-opened outbound streams too. The dispatcher\n//! claims only rows with `initiated_locally == false` — serving our own\n//! requester stream would deadlock the requester against ourselves. The flag\n//! is broker-recorded at registration (`open_stream` vs the accept loop),\n//! never inferred.\n//!\n//! ## Classification (first-record demux)\n//!\n//! Streams are single-purpose; the opener's first record names the protocol.\n//! The kind-tagged families collide on variant names (`request` is both\n//! sync's and attach's opener; `chunk`/`done`/`err` recur everywhere), so the\n//! demux keys on the first line's **shape**, not its kind alone:\n//!\n//! | first line | family |\n//! |---|---|\n//! | `kind=request` + `sync_id` | sync pull ([`crate::sync::serve_sync`]) |\n//! | `kind=request` + `session_id` | remote-drive attach (D9-1-3) |\n//! | `kind=request` + `endpoint`+`event` | remote rest op ([`crate::resthost::serve_rest`]) |\n//! | `kind=request` + `owner`+`shell_ref` | cross-node shell link ([`crate::linkhost::serve_shell_link`]) |\n//! | `kind=request` + `endpoint`+`digest_pull` | cross-node digest pull ([`crate::digestlink::serve_digest_pull`]) |\n//! | `kind=query` | update pull ([`crate::propagate::serve_update`]) |\n//! | `kind=row` | notif feed ([`crate::notifsync::apply_notif_feed`]) |\n//! | `kind=fetch` / `kind=push` | file transfer (D9-1-3) |\n//! | untagged + `target`+`op_id` | WAN message feed ([`crate::wan::receive_wan`]) |\n//! | untagged + `subnet`+`instance` | registry feed (D9-1-2) |\n//! | anything else | unknown — dropped, loud |\n//!\n//! A family whose production wiring lands in a later slice is still\n//! classified here (the table is complete) but routed to a typed\n//! [`Unwired`](DispatchOutcome::Unwired) drop — loud, never silent.\n//!\n//! ## Worker model\n//!\n//! Each claimed stream gets its own worker thread with its **own** brain IPC\n//! connection (the broker is multi-client by design; the probe-brain pattern\n//! every E2E test uses). The peek and the serve use **separate** connections:\n//! the peek brain subscribes from 0 to read the first line and is dropped;\n//! the serve loop then subscribes from 0 on a fresh connection so it owns its\n//! stream's event feed alone (no double-subscription interleave). Origin is\n//! the table's `remote_id_hex` — handshake-proven, never payload\n//! (REQ-HAZARD-WAN-ORIGIN-AUTH); every family's own gate then runs unchanged.\n// [impl->REQ-NET-1]\n// [impl->REQ-HAZARD-WAN-ORIGIN-AUTH]\n\nuse std::collections::HashMap;\nuse std::io;\nuse std::path::PathBuf;\nuse std::sync::atomic::{AtomicBool, AtomicU64, Ordering};\nuse std::sync::{Arc, Mutex, OnceLock};\nuse std::thread;\nuse std::time::{Duration, Instant};\n\nuse spt_net::net::notif::NotifDecoder;\nuse spt_net::net::presencemsg::Presence;\nuse spt_net::net::replicate::{\n    FeedDecoder as RegistryDecoder, NodeLabelUpdate, RegistryFeedRecord, RegistryUpdate,\n};\nuse spt_net::net::wanmsg::{WanDecoder, WanReply};\nuse spt_net::net::sealmsg::SealFeedDecoder;\nuse spt_store::contextstore::ContextStore;\nuse spt_store::notif::NotifStore;\nuse spt_store::enroll::{EnrollMergeOutcome, EnrollStore};\nuse spt_store::seal::{SealMergeOutcome, SealStore};\nuse spt_store::perch;\nuse spt_store::roster::RosterStore;\n\nuse crate::attach::serve_attach;\nuse crate::brain::{Brain, BrokerEvent};\nuse crate::notifsync::{apply_notif_feed, NotifPolicy};\nuse crate::sealsync::{apply_seal_feed, SealApplyVerdict};\nuse crate::propagate::serve_update;\nuse crate::registryhost::{RegistryGatePolicy, RegistryHost};\nuse crate::relcache::ReleaseCache;\nuse crate::sync::{serve_sync, SyncPolicy};\nuse crate::wan::receive_wan;\n\n/// Poll cadence for the stream-table watch (the dispatcher's only busy-wait;\n/// workers block on their stream's event feed).\npub const DEFAULT_DISPATCH_POLL: Duration = Duration::from_millis(100);\n\n/// What protocol a peer-initiated stream speaks, by its first record's shape.\n///\n/// The test-only `EnumIter` derive is what lets the census bijection assert\n/// itself from the ENUM side. Without it both halves of that check read `ALL`,\n/// and a variant that never reached `ALL` is unreachable by the test that exists\n/// to find exactly that. Production carries no strum derive.\n#[derive(Debug, Clone, Copy, PartialEq, Eq)]\n#[cfg_attr(test, derive(strum::EnumIter))]\npub enum StreamFamily {\n    /// A context sync pull (`SyncRecord::Request`).\n    Sync,\n    /// An update pull (`UpdRecord::Query`).\n    Update,\n    /// A notif replication feed (`NotifRecord::Row`).\n    Notif,\n    /// A WAN message feed (untagged `WanMessage` lines).\n    WanMsg,\n    /// A registry replication feed (untagged `RegistryUpdate` lines).\n    Registry,\n    /// A remote-drive attach (`AttachRecord::Request`).\n    Attach,\n    /// A remote rest op (`RestRecord::Request` — suspend/wake from another\n    /// node, M5-D5b).\n    Rest,\n    /// A cross-node shell-link op (`ShellLinkRecord::Request` — relink/cmd\n    /// against an owner's shell on this node, M5-D8c).\n    ShellLink,\n    /// A subnet-scoped liveness probe (`ServeProbeRecord::Request` — \"serving\n    /// subnet X?\", the `--nodes` view's detach-aware refinement, REQ-SUBNET-5).\n    ServeProbe,\n    /// A cross-node session-digest pull (`DigestPullRecord::Request` — the\n    /// snapshot of an endpoint that lives on this node, ADR-0048 decision 5).\n    // [impl->REQ-DIGEST-CROSS-NODE-PULL]\n    DigestPull,\n    /// A knock feed (`KnockRecord`, `kind: \"knock\"` — W4 T10).\n    ///\n    /// Tagged deliberately: the untagged `WanMessage` arm below would otherwise\n    /// claim a knock record and deliver it into the target's spool as a\n    /// message. An N-1 daemon has no arm for this tag and resolves it to\n    /// [`StreamFamily::Unknown`], dropping it cleanly.\n    // [impl->REQ-KNOCK-VERBS]\n    Knock,\n    /// A fork request (`ForkRecord`, `kind: \"fork\"` — HANDRAIL W4).\n    ///\n    /// Tagged for the same reason Knock is: untagged, the `WanMessage` arm\n    /// below would claim it and spool a fork request into the target's inbox\n    /// as chat. An N-1 daemon has no arm for this tag, resolves it to\n    /// [`StreamFamily::Unknown`], and drops it cleanly.\n    // [impl->REQ-FORK-CONTROL-SURFACE]\n    Fork,\n    /// A presence probe (`PresenceRecord`, `kind: \"presence\"` — DOORBELL W3).\n    ///\n    /// Tagged for the same reason Knock and Fork are, and here the consequence\n    /// is the sharpest: untagged, the `WanMessage` arm below would claim the\n    /// record and SPOOL A LIVENESS QUESTION INTO THE TARGET'S INBOX as a chat\n    /// line nobody sent. An N-1 daemon has no arm for this tag, resolves it to\n    /// [`StreamFamily::Unknown`], and drops it cleanly.\n    // [impl->REQ-UNLISTED-PRESENCE-PROBE]\n    // [impl->REQ-HAZARD-PROBE-CONTEXT-ISOLATION]\n    Presence,\n    /// A redemption (`RedeemRecord`, `kind: \"redeem\"` — DOORBELL W4).\n    ///\n    /// Tagged for the reason Knock and Fork are, with the sharpest version of\n    /// the argument: a redemption carried as a FIELD on a knock record would be\n    /// ACCEPTED by an N-1 minter as an ordinary knock — unknown fields decode\n    /// fine — leaving a pending knock, an unspent code and a knock-shaped ack\n    /// the redeemer would misread as an answer. Its own tag makes an older\n    /// daemon resolve it to [`StreamFamily::Unknown`] and drop it clean, which\n    /// is the honest failure.\n    // [impl->REQ-KNOCK-REDEEM-WIRE]\n    Redeem,\n    /// A seal replication feed (`SealWireRecord`, `kind: \"seal\"` — WAX-SEAL\n    /// W1).\n    ///\n    /// Tagged for the reason Knock and Fork are: untagged, the `WanMessage`\n    /// arm below would claim the record and spool a PROOF OF USER AUTHORITY\n    /// into the target's inbox as a chat line nobody sent. An N-1 daemon has\n    /// no arm for this tag, resolves it to [`StreamFamily::Unknown`], and\n    /// drops it cleanly — the seal simply doesn't replicate to a node that\n    /// cannot hold it yet.\n    // [impl->REQ-SEAL-STORE-REPLICATES-SUBNET-SCOPED]\n    Seal,\n    /// A knock ANSWER RECEIPT (`AnswerRecord`, `kind: \"knock-answer\"` —\n    /// DOORBELL W5).\n    ///\n    /// Tagged for the same reason, and here the misread would be the worst of\n    /// the set: a receipt carried as a field on a knock record would be filed by\n    /// an N-1 daemon as an ORDINARY KNOCK — a pending request in the knocker's\n    /// own inbox, asking them for what they had already offered — and the\n    /// knock-shaped ack would come back to the approver looking like the receipt\n    /// had been applied. Its own tag drops clean on an older daemon, which\n    /// leaves the pre-authorization armed: what an unanswered knock means\n    /// anyway.\n    // [impl->REQ-KNOCK-ANSWER-RECEIPT]\n    Answer,\n    /// A cross-node web request (`WebRecord::Web`, `kind: \"web\"` — WEBSERVE\n    /// W1): serve one node-prefixed URL the way this node's own loopback\n    /// listener would, gated on the `WEB` surface under the handshake origin.\n    ///\n    /// Tagged for the reason Knock and Fork are: untagged, the `WanMessage`\n    /// arm below would spool an HTTP request into an inbox as chat. An N-1\n    /// daemon has no arm for this tag, resolves it to\n    /// [`StreamFamily::Unknown`] and drops it cleanly — the requester's read\n    /// then times out and answers 502 naming the node, which is the honest\n    /// degrade for an owner that does not serve this wave yet.\n    // [impl->REQ-WEB-CROSS-NODE-PROXY]\n    // [impl->REQ-HAZARD-WIRE-UNTAGGED-RECORD]\n    Web,\n    /// Unclassifiable — dropped.\n    Unknown,\n}\n\nimpl StreamFamily {\n    /// Every variant, for tests that must assert a property across the WHOLE\n    /// family set rather than a hand-picked subset. Kept beside the enum so the\n    /// two are read together; the tests that walk it also match wildcard-free, so\n    /// a new variant is a compile error there rather than a silently unasserted\n    /// row (the classification predicates below are one-of-N — `family_is_one_way`\n    /// is Registry alone, `finished_row_is_terminal` is Attach alone — which is\n    /// exactly the shape a hand-maintained negative list drifts behind).\n    pub const ALL: [StreamFamily; 18] = [\n        StreamFamily::Sync,\n        StreamFamily::Update,\n        StreamFamily::Notif,\n        StreamFamily::WanMsg,\n        StreamFamily::Registry,\n        StreamFamily::Attach,\n        StreamFamily::Rest,\n        StreamFamily::ShellLink,\n        StreamFamily::ServeProbe,\n        StreamFamily::DigestPull,\n        StreamFamily::Knock,\n        StreamFamily::Fork,\n        StreamFamily::Presence,\n        StreamFamily::Redeem,\n        StreamFamily::Seal,\n        StreamFamily::Answer,\n        StreamFamily::Web,\n        StreamFamily::Unknown,\n    ];\n}\n\n/// Classify one decoded first line by shape (module-docs demux table).\npub fn classify_first_line(line: &serde_json::Value) -> StreamFamily {\n    match line.get(\"kind\").and_then(|k| k.as_str()) {\n        Some(\"request\") if line.get(\"sync_id\").is_some() => StreamFamily::Sync,\n        Some(\"request\") if line.get(\"session_id\").is_some() => StreamFamily::Attach,\n        Some(\"request\") if line.get(\"endpoint\").is_some() && line.get(\"event\").is_some() => {\n            StreamFamily::Rest\n        }\n        Some(\"request\") if line.get(\"owner\").is_some() && line.get(\"shell_ref\").is_some() => {\n            StreamFamily::ShellLink\n        }\n        Some(\"request\") if line.get(\"serve_probe\").is_some() => StreamFamily::ServeProbe,\n        // The rest family is `endpoint`+`event`; this one is `endpoint`+the\n        // explicit `digest_pull` marker, so neither can be read as the other.\n        // [impl->REQ-DIGEST-CROSS-NODE-PULL]\n        Some(\"request\") if line.get(\"endpoint\").is_some() && line.get(\"digest_pull\").is_some() => {\n            StreamFamily::DigestPull\n        }\n        Some(\"query\") => StreamFamily::Update,\n        // The status-only convergence query rides the update family (M8\n        // decision 19, REQ-UPD-6) — same serve loop, no artifact bytes.\n        Some(\"status_query\") => StreamFamily::Update,\n        Some(\"row\") => StreamFamily::Notif,\n        // [impl->REQ-KNOCK-VERBS]\n        // [impl->REQ-HAZARD-WIRE-UNTAGGED-RECORD]\n        Some(k) if k == spt_net::net::knockmsg::KNOCK_KIND => StreamFamily::Knock,\n        // [impl->REQ-FORK-CONTROL-SURFACE]\n        // [impl->REQ-HAZARD-WIRE-UNTAGGED-RECORD]\n        Some(k) if k == spt_net::net::forkmsg::FORK_KIND => StreamFamily::Fork,\n        // [impl->REQ-UNLISTED-PRESENCE-PROBE]\n        // [impl->REQ-HAZARD-PROBE-CONTEXT-ISOLATION]\n        Some(k) if k == spt_net::net::presencemsg::PRESENCE_KIND => StreamFamily::Presence,\n        // [impl->REQ-KNOCK-REDEEM-WIRE]\n        // [impl->REQ-HAZARD-WIRE-UNTAGGED-RECORD]\n        Some(k) if k == spt_net::net::redeemmsg::REDEEM_KIND => StreamFamily::Redeem,\n        // [impl->REQ-SEAL-STORE-REPLICATES-SUBNET-SCOPED]\n        // [impl->REQ-HAZARD-WIRE-UNTAGGED-RECORD]\n        Some(k) if k == spt_net::net::sealmsg::SEAL_KIND => StreamFamily::Seal,\n        // [impl->REQ-SEAL-ENROLL-RECORD-SUBNET-MATERIAL] enrollment records\n        // ride the SAME family — a feed may open with either kind.\n        Some(k) if k == spt_net::net::sealmsg::SEAL_ENROLLMENT_KIND => StreamFamily::Seal,\n        // [impl->REQ-KNOCK-ANSWER-RECEIPT]\n        // [impl->REQ-HAZARD-WIRE-UNTAGGED-RECORD]\n        Some(k) if k == spt_net::net::answermsg::ANSWER_KIND => StreamFamily::Answer,\n        // [impl->REQ-WEB-CROSS-NODE-PROXY]\n        // [impl->REQ-HAZARD-WIRE-UNTAGGED-RECORD]\n        Some(k) if k == spt_net::net::webmsg::WEB_KIND => StreamFamily::Web,\n        // [impl->REQ-NOW-SIGNAL-FILE-ACCESS-HELPER]\n        // [impl->REQ-HAZARD-WIRE-UNTAGGED-RECORD]\n        // A register-on-my-behalf request opens a stream too, so it is a FIRST\n        // LINE and needs its own arm — the `Web` arm above matches one tag, and\n        // `serde(tag = \"kind\")` gives ServeFor a different one. Same family on\n        // purpose (webmsg.rs: it asks the same question the `Web` record asks);\n        // without this arm it fell to `Some(_) => Unknown` and was dropped\n        // silently at the owner, which is a helper timeout, not a refusal.\n        Some(k) if k == spt_net::net::webmsg::SERVE_FOR_KIND => StreamFamily::Web,\n        Some(_) => StreamFamily::Unknown,\n        None => {\n            if line.get(\"target\").is_some() && line.get(\"op_id\").is_some() {\n                StreamFamily::WanMsg\n            } else if line.get(\"subnet\").is_some() && line.get(\"instance\").is_some() {\n                StreamFamily::Registry\n            } else if line.get(\"subnet\").is_some()\n                && line.get(\"node\").is_some()\n                && line.get(\"label\").is_some()\n…\n            }\n        }\n    }\n}\n\n[Showing lines 1-300 of 3631. Use :301 to continue]"}],"details":{"truncation":{"content":"//! Inbound net-stream dispatch (D9-1) — the daemon-side acceptor that turns\r\n//! the hand-wired serve loops of D5–D8 into production behavior.\r\n//!\r\n//! Every E2E test so far drove the serve half manually (a probe brain calling\r\n//! `serve_sync` / `serve_update` / `apply_notif_feed` / `receive_wan` against\r\n//! a known stream). In production nothing did — a peer could dial and write\r\n//! and the bytes sat in the broker's stream log unread. This module is the\r\n//! missing consumer: a daemon-hosted loop that watches the broker's stream\r\n//! table for **peer-initiated** streams, classifies each by its first NDJSON\r\n//! record, and hands it to the right serve loop on its own worker thread.\r\n//!\r\n//! ## Direction (the gotcha-#9 fact, now first-class)\r\n//!\r\n//! The stream table holds locally-opened outbound streams too. The dispatcher\r\n//! claims only rows with `initiated_locally == false` — serving our own\r\n//! requester stream would deadlock the requester against ourselves. The flag\r\n//! is broker-recorded at registration (`open_stream` vs the accept loop),\r\n//! never inferred.\r\n//!\r\n//! ## Classification (first-record demux)\r\n//!\r\n//! Streams are single-purpose; the opener's first record names the protocol.\r\n//! The kind-tagged families collide on variant names (`request` is both\r\n//! sync's and attach's opener; `chunk`/`done`/`err` recur everywhere), so the\r\n//! demux keys on the first line's **shape**, not its kind alone:\r\n//!\r\n//! | first line | family |\r\n//! |---|---|\r\n//! | `kind=request` + `sync_id` | sync pull ([`crate::sync::serve_sync`]) |\r\n//! | `kind=request` + `session_id` | remote-drive attach (D9-1-3) |\r\n//! | `kind=request` + `endpoint`+`event` | remote rest op ([`crate::resthost::serve_rest`]) |\r\n//! | `kind=request` + `owner`+`shell_ref` | cross-node shell link ([`crate::linkhost::serve_shell_link`]) |\r\n//! | `kind=request` + `endpoint`+`digest_pull` | cross-node digest pull ([`crate::digestlink::serve_digest_pull`]) |\r\n//! | `kind=query` | update pull ([`crate::propagate::serve_update`]) |\r\n//! | `kind=row` | notif feed ([`crate::notifsync::apply_notif_feed`]) |\r\n//! | `kind=fetch` / `kind=push` | file transfer (D9-1-3) |\r\n//! | untagged + `target`+`op_id` | WAN message feed ([`crate::wan::receive_wan`]) |\r\n//! | untagged + `subnet`+`instance` | registry feed (D9-1-2) |\r\n//! | anything else | unknown — dropped, loud |\r\n//!\r\n//! A family whose production wiring lands in a later slice is still\r\n//! classified here (the table is complete) but routed to a typed\r\n//! [`Unwired`](DispatchOutcome::Unwired) drop — loud, never silent.\r\n//!\r\n//! ## Worker model\r\n//!\r\n//! Each claimed stream gets its own worker thread with its **own** brain IPC\r\n//! connection (the broker is multi-client by design; the probe-brain pattern\r\n//! every E2E test uses). The peek and the serve use **separate** connections:\r\n//! the peek brain subscribes from 0 to read the first line and is dropped;\r\n//! the serve loop then subscribes from 0 on a fresh connection so it owns its\r\n//! stream's event feed alone (no double-subscription interleave). Origin is\r\n//! the table's `remote_id_hex` — handshake-proven, never payload\r\n//! (REQ-HAZARD-WAN-ORIGIN-AUTH); every family's own gate then runs unchanged.\r\n// [impl->REQ-NET-1]\r\n// [impl->REQ-HAZARD-WAN-ORIGIN-AUTH]\r\n\r\nuse std::collections::HashMap;\r\nuse std::io;\r\nuse std::path::PathBuf;\r\nuse std::sync::atomic::{AtomicBool, AtomicU64, Ordering};\r\nuse std::sync::{Arc, Mutex, OnceLock};\r\nuse std::thread;\r\nuse std::time::{Duration, Instant};\r\n\r\nuse spt_net::net::notif::NotifDecoder;\r\nuse spt_net::net::presencemsg::Presence;\r\nuse spt_net::net::replicate::{\r\n    FeedDecoder as RegistryDecoder, NodeLabelUpdate, RegistryFeedRecord, RegistryUpdate,\r\n};\r\nuse spt_net::net::wanmsg::{WanDecoder, WanReply};\r\nuse spt_net::net::sealmsg::SealFeedDecoder;\r\nuse spt_store::contextstore::ContextStore;\r\nuse spt_store::notif::NotifStore;\r\nuse spt_store::enroll::{EnrollMergeOutcome, EnrollStore};\r\nuse spt_store::seal::{SealMergeOutcome, SealStore};\r\nuse spt_store::perch;\r\nuse spt_store::roster::RosterStore;\r\n\r\nuse crate::attach::serve_attach;\r\nuse crate::brain::{Brain, BrokerEvent};\r\nuse crate::notifsync::{apply_notif_feed, NotifPolicy};\r\nuse crate::sealsync::{apply_seal_feed, SealApplyVerdict};\r\nuse crate::propagate::serve_update;\r\nuse crate::registryhost::{RegistryGatePolicy, RegistryHost};\r\nuse crate::relcache::ReleaseCache;\r\nuse crate::sync::{serve_sync, SyncPolicy};\r\nuse crate::wan::receive_wan;\r\n\r\n/// Poll cadence for the stream-table watch (the dispatcher's only busy-wait;\r\n/// workers block on their stream's event feed).\r\npub const DEFAULT_DISPATCH_POLL: Duration = Duration::from_millis(100);\r\n\r\n/// What protocol a peer-initiated stream speaks, by its first record's shape.\r\n///\r\n/// The test-only `EnumIter` derive is what lets the census bijection assert\r\n/// itself from the ENUM side. Without it both halves of that check read `ALL`,\r\n/// and a variant that never reached `ALL` is unreachable by the test that exists\r\n/// to find exactly that. Production carries no strum derive.\r\n#[derive(Debug, Clone, Copy, PartialEq, Eq)]\r\n#[cfg_attr(test, derive(strum::EnumIter))]\r\npub enum StreamFamily {\r\n    /// A context sync pull (`SyncRecord::Request`).\r\n    Sync,\r\n    /// An update pull (`UpdRecord::Query`).\r\n    Update,\r\n    /// A notif replication feed (`NotifRecord::Row`).\r\n    Notif,\r\n    /// A WAN message feed (untagged `WanMessage` lines).\r\n    WanMsg,\r\n    /// A registry replication feed (untagged `RegistryUpdate` lines).\r\n    Registry,\r\n    /// A remote-drive attach (`AttachRecord::Request`).\r\n    Attach,\r\n    /// A remote rest op (`RestRecord::Request` — suspend/wake from another\r\n    /// node, M5-D5b).\r\n    Rest,\r\n    /// A cross-node shell-link op (`ShellLinkRecord::Request` — relink/cmd\r\n    /// against an owner's shell on this node, M5-D8c).\r\n    ShellLink,\r\n    /// A subnet-scoped liveness probe (`ServeProbeRecord::Request` — \"serving\r\n    /// subnet X?\", the `--nodes` view's detach-aware refinement, REQ-SUBNET-5).\r\n    ServeProbe,\r\n    /// A cross-node session-digest pull (`DigestPullRecord::Request` — the\r\n    /// snapshot of an endpoint that lives on this node, ADR-0048 decision 5).\r\n    // [impl->REQ-DIGEST-CROSS-NODE-PULL]\r\n    DigestPull,\r\n    /// A knock feed (`KnockRecord`, `kind: \"knock\"` — W4 T10).\r\n    ///\r\n    /// Tagged deliberately: the untagged `WanMessage` arm below would otherwise\r\n    /// claim a knock record and deliver it into the target's spool as a\r\n    /// message. An N-1 daemon has no arm for this tag and resolves it to\r\n    /// [`StreamFamily::Unknown`], dropping it cleanly.\r\n    // [impl->REQ-KNOCK-VERBS]\r\n    Knock,\r\n    /// A fork request (`ForkRecord`, `kind: \"fork\"` — HANDRAIL W4).\r\n    ///\r\n    /// Tagged for the same reason Knock is: untagged, the `WanMessage` arm\r\n    /// below would claim it and spool a fork request into the target's inbox\r\n    /// as chat. An N-1 daemon has no arm for this tag, resolves it to\r\n    /// [`StreamFamily::Unknown`], and drops it cleanly.\r\n    // [impl->REQ-FORK-CONTROL-SURFACE]\r\n    Fork,\r\n    /// A presence probe (`PresenceRecord`, `kind: \"presence\"` — DOORBELL W3).\r\n    ///\r\n    /// Tagged for the same reason Knock and Fork are, and here the consequence\r\n    /// is the sharpest: untagged, the `WanMessage` arm below would claim the\r\n    /// record and SPOOL A LIVENESS QUESTION INTO THE TARGET'S INBOX as a chat\r\n    /// line nobody sent. An N-1 daemon has no arm for this tag, resolves it to\r\n    /// [`StreamFamily::Unknown`], and drops it cleanly.\r\n    // [impl->REQ-UNLISTED-PRESENCE-PROBE]\r\n    // [impl->REQ-HAZARD-PROBE-CONTEXT-ISOLATION]\r\n    Presence,\r\n    /// A redemption (`RedeemRecord`, `kind: \"redeem\"` — DOORBELL W4).\r\n    ///\r\n    /// Tagged for the reason Knock and Fork are, with the sharpest version of\r\n    /// the argument: a redemption carried as a FIELD on a knock record would be\r\n    /// ACCEPTED by an N-1 minter as an ordinary knock — unknown fields decode\r\n    /// fine — leaving a pending knock, an unspent code and a knock-shaped ack\r\n    /// the redeemer would misread as an answer. Its own tag makes an older\r\n    /// daemon resolve it to [`StreamFamily::Unknown`] and drop it clean, which\r\n    /// is the honest failure.\r\n    // [impl->REQ-KNOCK-REDEEM-WIRE]\r\n    Redeem,\r\n    /// A seal replication feed (`SealWireRecord`, `kind: \"seal\"` — WAX-SEAL\r\n    /// W1).\r\n    ///\r\n    /// Tagged for the reason Knock and Fork are: untagged, the `WanMessage`\r\n    /// arm below would claim the record and spool a PROOF OF USER AUTHORITY\r\n    /// into the target's inbox as a chat line nobody sent. An N-1 daemon has\r\n    /// no arm for this tag, resolves it to [`StreamFamily::Unknown`], and\r\n    /// drops it cleanly — the seal simply doesn't replicate to a node that\r\n    /// cannot hold it yet.\r\n    // [impl->REQ-SEAL-STORE-REPLICATES-SUBNET-SCOPED]\r\n    Seal,\r\n    /// A knock ANSWER RECEIPT (`AnswerRecord`, `kind: \"knock-answer\"` —\r\n    /// DOORBELL W5).\r\n    ///\r\n    /// Tagged for the same reason, and here the misread would be the worst of\r\n    /// the set: a receipt carried as a field on a knock record would be filed by\r\n    /// an N-1 daemon as an ORDINARY KNOCK — a pending request in the knocker's\r\n    /// own inbox, asking them for what they had already offered — and the\r\n    /// knock-shaped ack would come back to the approver looking like the receipt\r\n    /// had been applied. Its own tag drops clean on an older daemon, which\r\n    /// leaves the pre-authorization armed: what an unanswered knock means\r\n    /// anyway.\r\n    // [impl->REQ-KNOCK-ANSWER-RECEIPT]\r\n    Answer,\r\n    /// A cross-node web request (`WebRecord::Web`, `kind: \"web\"` — WEBSERVE\r\n    /// W1): serve one node-prefixed URL the way this node's own loopback\r\n    /// listener would, gated on the `WEB` surface under the handshake origin.\r\n    ///\r\n    /// Tagged for the reason Knock and Fork are: untagged, the `WanMessage`\r\n    /// arm below would spool an HTTP request into an inbox as chat. An N-1\r\n    /// daemon has no arm for this tag, resolves it to\r\n    /// [`StreamFamily::Unknown`] and drops it cleanly — the requester's read\r\n    /// then times out and answers 502 naming the node, which is the honest\r\n    /// degrade for an owner that does not serve this wave yet.\r\n    // [impl->REQ-WEB-CROSS-NODE-PROXY]\r\n    // [impl->REQ-HAZARD-WIRE-UNTAGGED-RECORD]\r\n    Web,\r\n    /// Unclassifiable — dropped.\r\n    Unknown,\r\n}\r\n\r\nimpl StreamFamily {\r\n    /// Every variant, for tests that must assert a property across the WHOLE\r\n    /// family set rather than a hand-picked subset. Kept beside the enum so the\r\n    /// two are read together; the tests that walk it also match wildcard-free, so\r\n    /// a new variant is a compile error there rather than a silently unasserted\r\n    /// row (the classification predicates below are one-of-N — `family_is_one_way`\r\n    /// is Registry alone, `finished_row_is_terminal` is Attach alone — which is\r\n    /// exactly the shape a hand-maintained negative list drifts behind).\r\n    pub const ALL: [StreamFamily; 18] = [\r\n        StreamFamily::Sync,\r\n        StreamFamily::Update,\r\n        StreamFamily::Notif,\r\n        StreamFamily::WanMsg,\r\n        StreamFamily::Registry,\r\n        StreamFamily::Attach,\r\n        StreamFamily::Rest,\r\n        StreamFamily::ShellLink,\r\n        StreamFamily::ServeProbe,\r\n        StreamFamily::DigestPull,\r\n        StreamFamily::Knock,\r\n        StreamFamily::Fork,\r\n        StreamFamily::Presence,\r\n        StreamFamily::Redeem,\r\n        StreamFamily::Seal,\r\n        StreamFamily::Answer,\r\n        StreamFamily::Web,\r\n        StreamFamily::Unknown,\r\n    ];\r\n}\r\n\r\n/// Classify one decoded first line by shape (module-docs demux table).\r\npub fn classify_first_line(line: &serde_json::Value) -> StreamFamily {\r\n    match line.get(\"kind\").and_then(|k| k.as_str()) {\r\n        Some(\"request\") if line.get(\"sync_id\").is_some() => StreamFamily::Sync,\r\n        Some(\"request\") if line.get(\"session_id\").is_some() => StreamFamily::Attach,\r\n        Some(\"request\") if line.get(\"endpoint\").is_some() && line.get(\"event\").is_some() => {\r\n            StreamFamily::Rest\r\n        }\r\n        Some(\"request\") if line.get(\"owner\").is_some() && line.get(\"shell_ref\").is_some() => {\r\n            StreamFamily::ShellLink\r\n        }\r\n        Some(\"request\") if line.get(\"serve_probe\").is_some() => StreamFamily::ServeProbe,\r\n        // The rest family is `endpoint`+`event`; this one is `endpoint`+the\r\n        // explicit `digest_pull` marker, so neither can be read as the other.\r\n        // [impl->REQ-DIGEST-CROSS-NODE-PULL]\r\n        Some(\"request\") if line.get(\"endpoint\").is_some() && line.get(\"digest_pull\").is_some() => {\r\n            StreamFamily::DigestPull\r\n        }\r\n        Some(\"query\") => StreamFamily::Update,\r\n        // The status-only convergence query rides the update family (M8\r\n        // decision 19, REQ-UPD-6) — same serve loop, no artifact bytes.\r\n        Some(\"status_query\") => StreamFamily::Update,\r\n        Some(\"row\") => StreamFamily::Notif,\r\n        // [impl->REQ-KNOCK-VERBS]\r\n        // [impl->REQ-HAZARD-WIRE-UNTAGGED-RECORD]\r\n        Some(k) if k == spt_net::net::knockmsg::KNOCK_KIND => StreamFamily::Knock,\r\n        // [impl->REQ-FORK-CONTROL-SURFACE]\r\n        // [impl->REQ-HAZARD-WIRE-UNTAGGED-RECORD]\r\n        Some(k) if k == spt_net::net::forkmsg::FORK_KIND => StreamFamily::Fork,\r\n        // [impl->REQ-UNLISTED-PRESENCE-PROBE]\r\n        // [impl->REQ-HAZARD-PROBE-CONTEXT-ISOLATION]\r\n        Some(k) if k == spt_net::net::presencemsg::PRESENCE_KIND => StreamFamily::Presence,\r\n        // [impl->REQ-KNOCK-REDEEM-WIRE]\r\n        // [impl->REQ-HAZARD-WIRE-UNTAGGED-RECORD]\r\n        Some(k) if k == spt_net::net::redeemmsg::REDEEM_KIND => StreamFamily::Redeem,\r\n        // [impl->REQ-SEAL-STORE-REPLICATES-SUBNET-SCOPED]\r\n        // [impl->REQ-HAZARD-WIRE-UNTAGGED-RECORD]\r\n        Some(k) if k == spt_net::net::sealmsg::SEAL_KIND => StreamFamily::Seal,\r\n        // [impl->REQ-SEAL-ENROLL-RECORD-SUBNET-MATERIAL] enrollment records\r\n        // ride the SAME family — a feed may open with either kind.\r\n        Some(k) if k == spt_net::net::sealmsg::SEAL_ENROLLMENT_KIND => StreamFamily::Seal,\r\n        // [impl->REQ-KNOCK-ANSWER-RECEIPT]\r\n        // [impl->REQ-HAZARD-WIRE-UNTAGGED-RECORD]\r\n        Some(k) if k == spt_net::net::answermsg::ANSWER_KIND => StreamFamily::Answer,\r\n        // [impl->REQ-WEB-CROSS-NODE-PROXY]\r\n        // [impl->REQ-HAZARD-WIRE-UNTAGGED-RECORD]\r\n        Some(k) if k == spt_net::net::webmsg::WEB_KIND => StreamFamily::Web,\r\n        // [impl->REQ-NOW-SIGNAL-FILE-ACCESS-HELPER]\r\n        // [impl->REQ-HAZARD-WIRE-UNTAGGED-RECORD]\r\n        // A register-on-my-behalf request opens a stream too, so it is a FIRST\r\n        // LINE and needs its own arm — the `Web` arm above matches one tag, and\r\n        // `serde(tag = \"kind\")` gives ServeFor a different one. Same family on\r\n        // purpose (webmsg.rs: it asks the same question the `Web` record asks);\r\n        // without this arm it fell to `Some(_) => Unknown` and was dropped\r\n        // silently at the owner, which is a helper timeout, not a refusal.\r\n        Some(k) if k == spt_net::net::webmsg::SERVE_FOR_KIND => StreamFamily::Web,\r\n        Some(_) => StreamFamily::Unknown,\r\n        None => {\r\n            if line.get(\"target\").is_some() && line.get(\"op_id\").is_some() {\r\n                StreamFamily::WanMsg\r\n            } else if line.get(\"subnet\").is_some() && line.get(\"instance\").is_some() {\r\n                StreamFamily::Registry\r\n            } else if line.get(\"subnet\").is_some()\r\n                && line.get(\"node\").is_some()\r\n                && line.get(\"label\").is_some()\r","truncated":true,"truncatedBy":"lines","totalLines":3631,"totalBytes":15765,"outputLines":300,"outputBytes":15765,"lastLinePartial":false,"firstLineExceedsLimit":false},"totalLines":3631,"displayContent":{"text":"//! Inbound net-stream dispatch (D9-1) — the daemon-side acceptor that turns\r\n//! the hand-wired serve loops of D5–D8 into production behavior.\r\n//!\r\n//! Every E2E test so far drove the serve half manually (a probe brain calling\r\n//! `serve_sync` / `serve_update` / `apply_notif_feed` / `receive_wan` against\r\n//! a known stream). In production nothing did — a peer could dial and write\r\n//! and the bytes sat in the broker's stream log unread. This module is the\r\n//! missing consumer: a daemon-hosted loop that watches the broker's stream\r\n//! table for **peer-initiated** streams, classifies each by its first NDJSON\r\n//! record, and hands it to the right serve loop on its own worker thread.\r\n//!\r\n//! ## Direction (the gotcha-#9 fact, now first-class)\r\n//!\r\n//! The stream table holds locally-opened outbound streams too. The dispatcher\r\n//! claims only rows with `initiated_locally == false` — serving our own\r\n//! requester stream would deadlock the requester against ourselves. The flag\r\n//! is broker-recorded at registration (`open_stream` vs the accept loop),\r\n//! never inferred.\r\n//!\r\n//! ## Classification (first-record demux)\r\n//!\r\n//! Streams are single-purpose; the opener's first record names the protocol.\r\n//! The kind-tagged families collide on variant names (`request` is both\r\n//! sync's and attach's opener; `chunk`/`done`/`err` recur everywhere), so the\r\n//! demux keys on the first line's **shape**, not its kind alone:\r\n//!\r\n//! | first line | family |\r\n//! |---|---|\r\n//! | `kind=request` + `sync_id` | sync pull ([`crate::sync::serve_sync`]) |\r\n//! | `kind=request` + `session_id` | remote-drive attach (D9-1-3) |\r\n//! | `kind=request` + `endpoint`+`event` | remote rest op ([`crate::resthost::serve_rest`]) |\r\n//! | `kind=request` + `owner`+`shell_ref` | cross-node shell link ([`crate::linkhost::serve_shell_link`]) |\r\n//! | `kind=request` + `endpoint`+`digest_pull` | cross-node digest pull ([`crate::digestlink::serve_digest_pull`]) |\r\n//! | `kind=query` | update pull ([`crate::propagate::serve_update`]) |\r\n//! | `kind=row` | notif feed ([`crate::notifsync::apply_notif_feed`]) |\r\n//! | `kind=fetch` / `kind=push` | file transfer (D9-1-3) |\r\n//! | untagged + `target`+`op_id` | WAN message feed ([`crate::wan::receive_wan`]) |\r\n//! | untagged + `subnet`+`instance` | registry feed (D9-1-2) |\r\n//! | anything else | unknown — dropped, loud |\r\n//!\r\n//! A family whose production wiring lands in a later slice is still\r\n//! classified here (the table is complete) but routed to a typed\r\n//! [`Unwired`](DispatchOutcome::Unwired) drop — loud, never silent.\r\n//!\r\n//! ## Worker model\r\n//!\r\n//! Each claimed stream gets its own worker thread with its **own** brain IPC\r\n//! connection (the broker is multi-client by design; the probe-brain pattern\r\n//! every E2E test uses). The peek and the serve use **separate** connections:\r\n//! the peek brain subscribes from 0 to read the first line and is dropped;\r\n//! the serve loop then subscribes from 0 on a fresh connection so it owns its\r\n//! stream's event feed alone (no double-subscription interleave). Origin is\r\n//! the table's `remote_id_hex` — handshake-proven, never payload\r\n//! (REQ-HAZARD-WAN-ORIGIN-AUTH); every family's own gate then runs unchanged.\r\n// [impl->REQ-NET-1]\r\n// [impl->REQ-HAZARD-WAN-ORIGIN-AUTH]\r\n\r\nuse std::collections::HashMap;\r\nuse std::io;\r\nuse std::path::PathBuf;\r\nuse std::sync::atomic::{AtomicBool, AtomicU64, Ordering};\r\nuse std::sync::{Arc, Mutex, OnceLock};\r\nuse std::thread;\r\nuse std::time::{Duration, Instant};\r\n\r\nuse spt_net::net::notif::NotifDecoder;\r\nuse spt_net::net::presencemsg::Presence;\r\nuse spt_net::net::replicate::{\r\n    FeedDecoder as RegistryDecoder, NodeLabelUpdate, RegistryFeedRecord, RegistryUpdate,\r\n};\r\nuse spt_net::net::wanmsg::{WanDecoder, WanReply};\r\nuse spt_net::net::sealmsg::SealFeedDecoder;\r\nuse spt_store::contextstore::ContextStore;\r\nuse spt_store::notif::NotifStore;\r\nuse spt_store::enroll::{EnrollMergeOutcome, EnrollStore};\r\nuse spt_store::seal::{SealMergeOutcome, SealStore};\r\nuse spt_store::perch;\r\nuse spt_store::roster::RosterStore;\r\n\r\nuse crate::attach::serve_attach;\r\nuse crate::brain::{Brain, BrokerEvent};\r\nuse crate::notifsync::{apply_notif_feed, NotifPolicy};\r\nuse crate::sealsync::{apply_seal_feed, SealApplyVerdict};\r\nuse crate::propagate::serve_update;\r\nuse crate::registryhost::{RegistryGatePolicy, RegistryHost};\r\nuse crate::relcache::ReleaseCache;\r\nuse crate::sync::{serve_sync, SyncPolicy};\r\nuse crate::wan::receive_wan;\r\n\r\n/// Poll cadence for the stream-table watch (the dispatcher's only busy-wait;\r\n/// workers block on their stream's event feed).\r\npub const DEFAULT_DISPATCH_POLL: Duration = Duration::from_millis(100);\r\n\r\n/// What protocol a peer-initiated stream speaks, by its first record's shape.\r\n///\r\n/// The test-only `EnumIter` derive is what lets the census bijection assert\r\n/// itself from the ENUM side. Without it both halves of that check read `ALL`,\r\n/// and a variant that never reached `ALL` is unreachable by the test that exists\r\n/// to find exactly that. Production carries no strum derive.\r\n#[derive(Debug, Clone, Copy, PartialEq, Eq)]\r\n#[cfg_attr(test, derive(strum::EnumIter))]\r\npub enum StreamFamily {\r\n    /// A context sync pull (`SyncRecord::Request`).\r\n    Sync,\r\n    /// An update pull (`UpdRecord::Query`).\r\n    Update,\r\n    /// A notif replication feed (`NotifRecord::Row`).\r\n    Notif,\r\n    /// A WAN message feed (untagged `WanMessage` lines).\r\n    WanMsg,\r\n    /// A registry replication feed (untagged `RegistryUpdate` lines).\r\n    Registry,\r\n    /// A remote-drive attach (`AttachRecord::Request`).\r\n    Attach,\r\n    /// A remote rest op (`RestRecord::Request` — suspend/wake from another\r\n    /// node, M5-D5b).\r\n    Rest,\r\n    /// A cross-node shell-link op (`ShellLinkRecord::Request` — relink/cmd\r\n    /// against an owner's shell on this node, M5-D8c).\r\n    ShellLink,\r\n    /// A subnet-scoped liveness probe (`ServeProbeRecord::Request` — \"serving\r\n    /// subnet X?\", the `--nodes` view's detach-aware refinement, REQ-SUBNET-5).\r\n    ServeProbe,\r\n    /// A cross-node session-digest pull (`DigestPullRecord::Request` — the\r\n    /// snapshot of an endpoint that lives on this node, ADR-0048 decision 5).\r\n    // [impl->REQ-DIGEST-CROSS-NODE-PULL]\r\n    DigestPull,\r\n    /// A knock feed (`KnockRecord`, `kind: \"knock\"` — W4 T10).\r\n    ///\r\n    /// Tagged deliberately: the untagged `WanMessage` arm below would otherwise\r\n    /// claim a knock record and deliver it into the target's spool as a\r\n    /// message. An N-1 daemon has no arm for this tag and resolves it to\r\n    /// [`StreamFamily::Unknown`], dropping it cleanly.\r\n    // [impl->REQ-KNOCK-VERBS]\r\n    Knock,\r\n    /// A fork request (`ForkRecord`, `kind: \"fork\"` — HANDRAIL W4).\r\n    ///\r\n    /// Tagged for the same reason Knock is: untagged, the `WanMessage` arm\r\n    /// below would claim it and spool a fork request into the target's inbox\r\n    /// as chat. An N-1 daemon has no arm for this tag, resolves it to\r\n    /// [`StreamFamily::Unknown`], and drops it cleanly.\r\n    // [impl->REQ-FORK-CONTROL-SURFACE]\r\n    Fork,\r\n    /// A presence probe (`PresenceRecord`, `kind: \"presence\"` — DOORBELL W3).\r\n    ///\r\n    /// Tagged for the same reason Knock and Fork are, and here the consequence\r\n    /// is the sharpest: untagged, the `WanMessage` arm below would claim the\r\n    /// record and SPOOL A LIVENESS QUESTION INTO THE TARGET'S INBOX as a chat\r\n    /// line nobody sent. An N-1 daemon has no arm for this tag, resolves it to\r\n    /// [`StreamFamily::Unknown`], and drops it cleanly.\r\n    // [impl->REQ-UNLISTED-PRESENCE-PROBE]\r\n    // [impl->REQ-HAZARD-PROBE-CONTEXT-ISOLATION]\r\n    Presence,\r\n    /// A redemption (`RedeemRecord`, `kind: \"redeem\"` — DOORBELL W4).\r\n    ///\r\n    /// Tagged for the reason Knock and Fork are, with the sharpest version of\r\n    /// the argument: a redemption carried as a FIELD on a knock record would be\r\n    /// ACCEPTED by an N-1 minter as an ordinary knock — unknown fields decode\r\n    /// fine — leaving a pending knock, an unspent code and a knock-shaped ack\r\n    /// the redeemer would misread as an answer. Its own tag makes an older\r\n    /// daemon resolve it to [`StreamFamily::Unknown`] and drop it clean, which\r\n    /// is the honest failure.\r\n    // [impl->REQ-KNOCK-REDEEM-WIRE]\r\n    Redeem,\r\n    /// A seal replication feed (`SealWireRecord`, `kind: \"seal\"` — WAX-SEAL\r\n    /// W1).\r\n    ///\r\n    /// Tagged for the reason Knock and Fork are: untagged, the `WanMessage`\r\n    /// arm below would claim the record and spool a PROOF OF USER AUTHORITY\r\n    /// into the target's inbox as a chat line nobody sent. An N-1 daemon has\r\n    /// no arm for this tag, resolves it to [`StreamFamily::Unknown`], and\r\n    /// drops it cleanly — the seal simply doesn't replicate to a node that\r\n    /// cannot hold it yet.\r\n    // [impl->REQ-SEAL-STORE-REPLICATES-SUBNET-SCOPED]\r\n    Seal,\r\n    /// A knock ANSWER RECEIPT (`AnswerRecord`, `kind: \"knock-answer\"` —\r\n    /// DOORBELL W5).\r\n    ///\r\n    /// Tagged for the same reason, and here the misread would be the worst of\r\n    /// the set: a receipt carried as a field on a knock record would be filed by\r\n    /// an N-1 daemon as an ORDINARY KNOCK — a pending request in the knocker's\r\n    /// own inbox, asking them for what they had already offered — and the\r\n    /// knock-shaped ack would come back to the approver looking like the receipt\r\n    /// had been applied. Its own tag drops clean on an older daemon, which\r\n    /// leaves the pre-authorization armed: what an unanswered knock means\r\n    /// anyway.\r\n    // [impl->REQ-KNOCK-ANSWER-RECEIPT]\r\n    Answer,\r\n    /// A cross-node web request (`WebRecord::Web`, `kind: \"web\"` — WEBSERVE\r\n    /// W1): serve one node-prefixed URL the way this node's own loopback\r\n    /// listener would, gated on the `WEB` surface under the handshake origin.\r\n    ///\r\n    /// Tagged for the reason Knock and Fork are: untagged, the `WanMessage`\r\n    /// arm below would spool an HTTP request into an inbox as chat. An N-1\r\n    /// daemon has no arm for this tag, resolves it to\r\n    /// [`StreamFamily::Unknown`] and drops it cleanly — the requester's read\r\n    /// then times out and answers 502 naming the node, which is the honest\r\n    /// degrade for an owner that does not serve this wave yet.\r\n    // [impl->REQ-WEB-CROSS-NODE-PROXY]\r\n    // [impl->REQ-HAZARD-WIRE-UNTAGGED-RECORD]\r\n    Web,\r\n    /// Unclassifiable — dropped.\r\n    Unknown,\r\n}\r\n\r\nimpl StreamFamily {\r\n    /// Every variant, for tests that must assert a property across the WHOLE\r\n    /// family set rather than a hand-picked subset. Kept beside the enum so the\r\n    /// two are read together; the tests that walk it also match wildcard-free, so\r\n    /// a new variant is a compile error there rather than a silently unasserted\r\n    /// row (the classification predicates below are one-of-N — `family_is_one_way`\r\n    /// is Registry alone, `finished_row_is_terminal` is Attach alone — which is\r\n    /// exactly the shape a hand-maintained negative list drifts behind).\r\n    pub const ALL: [StreamFamily; 18] = [\r\n        StreamFamily::Sync,\r\n        StreamFamily::Update,\r\n        StreamFamily::Notif,\r\n        StreamFamily::WanMsg,\r\n        StreamFamily::Registry,\r\n        StreamFamily::Attach,\r\n        StreamFamily::Rest,\r\n        StreamFamily::ShellLink,\r\n        StreamFamily::ServeProbe,\r\n        StreamFamily::DigestPull,\r\n        StreamFamily::Knock,\r\n        StreamFamily::Fork,\r\n        StreamFamily::Presence,\r\n        StreamFamily::Redeem,\r\n        StreamFamily::Seal,\r\n        StreamFamily::Answer,\r\n        StreamFamily::Web,\r\n        StreamFamily::Unknown,\r\n    ];\r\n}\r\n\r\n/// Classify one decoded first line by shape (module-docs demux table).\r\npub fn classify_first_line(line: &serde_json::Value) -> StreamFamily {\r\n    match line.get(\"kind\").and_then(|k| k.as_str()) {\r\n        Some(\"request\") if line.get(\"sync_id\").is_some() => StreamFamily::Sync,\r\n        Some(\"request\") if line.get(\"session_id\").is_some() => StreamFamily::Attach,\r\n        Some(\"request\") if line.get(\"endpoint\").is_some() && line.get(\"event\").is_some() => {\r\n            StreamFamily::Rest\r\n        }\r\n        Some(\"request\") if line.get(\"owner\").is_some() && line.get(\"shell_ref\").is_some() => {\r\n            StreamFamily::ShellLink\r\n        }\r\n        Some(\"request\") if line.get(\"serve_probe\").is_some() => StreamFamily::ServeProbe,\r\n        // The rest family is `endpoint`+`event`; this one is `endpoint`+the\r\n        // explicit `digest_pull` marker, so neither can be read as the other.\r\n        // [impl->REQ-DIGEST-CROSS-NODE-PULL]\r\n        Some(\"request\") if line.get(\"endpoint\").is_some() && line.get(\"digest_pull\").is_some() => {\r\n            StreamFamily::DigestPull\r\n        }\r\n        Some(\"query\") => StreamFamily::Update,\r\n        // The status-only convergence query rides the update family (M8\r\n        // decision 19, REQ-UPD-6) — same serve loop, no artifact bytes.\r\n        Some(\"status_query\") => StreamFamily::Update,\r\n        Some(\"row\") => StreamFamily::Notif,\r\n        // [impl->REQ-KNOCK-VERBS]\r\n        // [impl->REQ-HAZARD-WIRE-UNTAGGED-RECORD]\r\n        Some(k) if k == spt_net::net::knockmsg::KNOCK_KIND => StreamFamily::Knock,\r\n        // [impl->REQ-FORK-CONTROL-SURFACE]\r\n        // [impl->REQ-HAZARD-WIRE-UNTAGGED-RECORD]\r\n        Some(k) if k == spt_net::net::forkmsg::FORK_KIND => StreamFamily::Fork,\r\n        // [impl->REQ-UNLISTED-PRESENCE-PROBE]\r\n        // [impl->REQ-HAZARD-PROBE-CONTEXT-ISOLATION]\r\n        Some(k) if k == spt_net::net::presencemsg::PRESENCE_KIND => StreamFamily::Presence,\r\n        // [impl->REQ-KNOCK-REDEEM-WIRE]\r\n        // [impl->REQ-HAZARD-WIRE-UNTAGGED-RECORD]\r\n        Some(k) if k == spt_net::net::redeemmsg::REDEEM_KIND => StreamFamily::Redeem,\r\n        // [impl->REQ-SEAL-STORE-REPLICATES-SUBNET-SCOPED]\r\n        // [impl->REQ-HAZARD-WIRE-UNTAGGED-RECORD]\r\n        Some(k) if k == spt_net::net::sealmsg::SEAL_KIND => StreamFamily::Seal,\r\n        // [impl->REQ-SEAL-ENROLL-RECORD-SUBNET-MATERIAL] enrollment records\r\n        // ride the SAME family — a feed may open with either kind.\r\n        Some(k) if k == spt_net::net::sealmsg::SEAL_ENROLLMENT_KIND => StreamFamily::Seal,\r\n        // [impl->REQ-KNOCK-ANSWER-RECEIPT]\r\n        // [impl->REQ-HAZARD-WIRE-UNTAGGED-RECORD]\r\n        Some(k) if k == spt_net::net::answermsg::ANSWER_KIND => StreamFamily::Answer,\r\n        // [impl->REQ-WEB-CROSS-NODE-PROXY]\r\n        // [impl->REQ-HAZARD-WIRE-UNTAGGED-RECORD]\r\n        Some(k) if k == spt_net::net::webmsg::WEB_KIND => StreamFamily::Web,\r\n        // [impl->REQ-NOW-SIGNAL-FILE-ACCESS-HELPER]\r\n        // [impl->REQ-HAZARD-WIRE-UNTAGGED-RECORD]\r\n        // A register-on-my-behalf request opens a stream too, so it is a FIRST\r\n        // LINE and needs its own arm — the `Web` arm above matches one tag, and\r\n        // `serde(tag = \"kind\")` gives ServeFor a different one. Same family on\r\n        // purpose (webmsg.rs: it asks the same question the `Web` record asks);\r\n        // without this arm it fell to `Some(_) => Unknown` and was dropped\r\n        // silently at the owner, which is a helper timeout, not a refusal.\r\n        Some(k) if k == spt_net::net::webmsg::SERVE_FOR_KIND => StreamFamily::Web,\r\n        Some(_) => StreamFamily::Unknown,\r\n        None => {\r\n            if line.get(\"target\").is_some() && line.get(\"op_id\").is_some() {\r\n                StreamFamily::WanMsg\r\n            } else if line.get(\"subnet\").is_some() && line.get(\"instance\").is_some() {\r\n                StreamFamily::Registry\r\n            } else if line.get(\"subnet\").is_some()\r\n                && line.get(\"node\").is_some()\r\n                && line.get(\"label\").is_some()\r\n…\n            }\n        }\n    }\n}","startLine":1,"lineNumbers":[1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95,96,97,98,99,100,101,102,103,104,105,106,107,108,109,110,111,112,113,114,115,116,117,118,119,120,121,122,123,124,125,126,127,128,129,130,131,132,133,134,135,136,137,138,139,140,141,142,143,144,145,146,147,148,149,150,151,152,153,154,155,156,157,158,159,160,161,162,163,164,165,166,167,168,169,170,171,172,173,174,175,176,177,178,179,180,181,182,183,184,185,186,187,188,189,190,191,192,193,194,195,196,197,198,199,200,201,202,203,204,205,206,207,208,209,210,211,212,213,214,215,216,217,218,219,220,221,222,223,224,225,226,227,228,229,230,231,232,233,234,235,236,237,238,239,240,241,242,243,244,245,246,247,248,249,250,251,252,253,254,255,256,257,258,259,260,261,262,263,264,265,266,267,268,269,270,271,272,273,274,275,276,277,278,279,280,281,282,283,284,285,286,287,288,289,290,291,292,293,294,295,296,297,298,299,300,null,308,309,310,311]},"fileSize":171439,"meta":{"source":{"type":"path","value":"C:\\Users\\decid\\Documents\\projects\\spt-core\\crates\\spt-daemon\\src\\dispatch.rs"},"truncation":{"direction":"head","truncatedBy":"lines","totalLines":3631,"totalBytes":15765,"outputLines":300,"outputBytes":15765,"shownRange":{"start":1,"end":300},"nextOffset":301}}},"isError":false,"timestamp":1789523955949}}
{"type":"message","id":"bda0c71a","parentId":"b699c00c","timestamp":"2026-09-16T01:59:18.904Z","message":{"role":"toolResult","toolCallId":"call_QQaL5ioVhbXXYScmKi7thkiG|fc_09b01b5279447709016aa9f7f1662887d2b78794ce7a5fe9a0","toolName":"glob","content":[{"type":"text","text":"# .spt/preserved/307/hertz-w1bc/w1c-run1/\ncommand-120.json\ncommand-119.json\ncommand-118.json\ncommand-117.json\ncommand-116.json\ncommand-115.json\ncommand-114.json\ncommand-113.json\ncommand-112.json\ncommand-111.json\ncommand-110.json\ncommand-109.json\ncommand-108.json\ncommand-107.json\ncommand-106.json\ncommand-105.json\ncommand-104.json\ncommand-103.json\ncommand-102.json\ncommand-101.json\ncommand-100.json\ncommand-099.json\ncommand-098.json\ncommand-097.json\ncommand-096.json\ncommand-095.json\ncommand-094.json\ncommand-093.json\ncommand-092.json\ncommand-091.json\ncommand-090.json\ncommand-089.json\ncommand-088.json\ncommand-087.json\ncommand-086.json\ncommand-085.json\ncommand-084.json\ncommand-083.json\ncommand-082.json\ncommand-081.json\ncommand-080.json\ncommand-079.json\ncommand-078.json\ncommand-077.json\ncommand-076.json\ncommand-075.json\ncommand-074.json\ncommand-073.json\ncommand-072.json\ncommand-071.json\ncommand-070.json\ncommand-069.json\ncommand-068.json\ncommand-067.json\ncommand-066.json\ncommand-065.json\ncommand-064.json\ncommand-063.json\ncommand-062.json\ncommand-061.json\ncommand-060.json\ncommand-059.json\ncommand-058.json\ncommand-057.json\ncommand-056.json\nevents.jsonl\ncommand-055.json\ncommand-054.json\ncommand-053.json\n## home-w1c/\n\n[70 results limit reached. Use limit=140 for more]"}],"details":{"scopePath":"**/*netstream*, .spt/preserved/307/hertz-w1bc/w1c-run1/*, **/*glossary*, **/*ADR*","fileCount":70,"files":[".spt/preserved/307/hertz-w1bc/w1c-run1/command-120.json",".spt/preserved/307/hertz-w1bc/w1c-run1/home-w1c/",".spt/preserved/307/hertz-w1bc/w1c-run1/command-119.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-118.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-117.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-116.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-115.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-114.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-113.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-112.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-111.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-110.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-109.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-108.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-107.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-106.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-105.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-104.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-103.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-102.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-101.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-100.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-099.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-098.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-097.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-096.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-095.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-094.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-093.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-092.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-091.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-090.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-089.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-088.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-087.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-086.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-085.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-084.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-083.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-082.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-081.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-080.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-079.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-078.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-077.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-076.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-075.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-074.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-073.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-072.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-071.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-070.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-069.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-068.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-067.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-066.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-065.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-064.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-063.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-062.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-061.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-060.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-059.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-058.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-057.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-056.json",".spt/preserved/307/hertz-w1bc/w1c-run1/events.jsonl",".spt/preserved/307/hertz-w1bc/w1c-run1/command-055.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-054.json",".spt/preserved/307/hertz-w1bc/w1c-run1/command-053.json"],"truncated":true,"resultLimitReached":70,"cwd":"C:\\Users\\decid\\Documents\\projects\\spt-core","meta":{"limits":{"resultLimit":{"reached":70,"suggestion":140}}}},"isError":false,"timestamp":1789523958903}}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_U6cJL4sE5MekxSXz2WaVsxJz|fc_09b01b5279447709016aa9f800733c87d2baab1987d9edddfe","toolName":"grep","startedAt":"2026-09-16T01:59:28.544Z","args":{"path":"crates/spt-daemon/src/attach.rs:300-1159"},"intent":"Locating attach blocking operations"},"id":"8463cc3c","parentId":"bda0c71a","timestamp":"2026-09-16T01:59:28.544Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_IH7H8RDFGE1cLx4G0xvtzjt8|fc_09b01b5279447709016aa9f800734c87d2a234e6d0981aec1f","toolName":"grep","startedAt":"2026-09-16T01:59:28.544Z","args":{"path":"crates/spt-daemon/src/dispatch.rs:300-2400"},"intent":"Locating dispatch replacement paths"},"id":"5609a5e1","parentId":"8463cc3c","timestamp":"2026-09-16T01:59:28.544Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_o14nJqEFqrzS0PrT2JCqMt1i|fc_09b01b5279447709016aa9f800735487d28bfa0dbe85c7f696","toolName":"glob","startedAt":"2026-09-16T01:59:28.545Z","args":{"path":"crates/spt-daemon/src/brain*;crates/spt-daemon/src/brain/**/*;crates/spt-daemon/tests/*attach*;crates/spt-daemon/tests/*dispatch*;**/*glossary*"},"intent":"Locating brain stream sources"},"id":"a7e522c2","parentId":"5609a5e1","timestamp":"2026-09-16T01:59:28.545Z"}
{"type":"message","id":"12e81b24","parentId":"a7e522c2","timestamp":"2026-09-16T01:59:28.545Z","message":{"role":"assistant","content":[{"type":"toolCall","id":"call_U6cJL4sE5MekxSXz2WaVsxJz|fc_09b01b5279447709016aa9f800733c87d2baab1987d9edddfe","name":"grep","arguments":{"i":"Locating attach blocking operations","pattern":"fn |net_stream|snapshot|send_effect|read_event|ack","path":"crates/spt-daemon/src/attach.rs:300-1159","case":false,"gitignore":true,"skip":null},"intent":"Locating attach blocking operations"},{"type":"toolCall","id":"call_IH7H8RDFGE1cLx4G0xvtzjt8|fc_09b01b5279447709016aa9f800734c87d2a234e6d0981aec1f","name":"grep","arguments":{"i":"Locating dispatch replacement paths","pattern":"fn |retry|poison|serve_attach|from_seq|connect","path":"crates/spt-daemon/src/dispatch.rs:300-2400","case":false,"gitignore":true,"skip":null},"intent":"Locating dispatch replacement paths"},{"type":"toolCall","id":"call_o14nJqEFqrzS0PrT2JCqMt1i|fc_09b01b5279447709016aa9f800735487d28bfa0dbe85c7f696","name":"glob","arguments":{"i":"Locating brain stream sources","path":"crates/spt-daemon/src/brain*;crates/spt-daemon/src/brain/**/*;crates/spt-daemon/tests/*attach*;crates/spt-daemon/tests/*dispatch*;**/*glossary*","hidden":true,"gitignore":true,"limit":90},"intent":"Locating brain stream sources"}],"api":"openai-codex-responses","provider":"openai-codex","model":"gpt-6-astra","usage":{"input":8435,"output":235,"cacheRead":11904,"cacheWrite":0,"totalTokens":20574,"cost":{"input":0.08435000000000001,"output":0.01175,"cacheRead":0.011904,"cacheWrite":0,"total":0.108004}},"stopReason":"toolUse","timestamp":1789523958935,"responseId":"resp_09b01b5279447709016aa9f7f728cc87d29e4d7ce57a107eb3","providerPayload":{"type":"openaiResponsesHistory","provider":"openai-codex","dt":true,"items":[{"id":"fc_09b01b5279447709016aa9f800733c87d2baab1987d9edddfe","type":"function_call","status":"completed","arguments":"{\"i\":\"Locating attach blocking operations\",\"pattern\":\"fn |net_stream|snapshot|send_effect|read_event|ack\",\"path\":\"crates/spt-daemon/src/attach.rs:300-1159\",\"case\":false,\"gitignore\":true,\"skip\":null}","call_id":"call_U6cJL4sE5MekxSXz2WaVsxJz","internal_chat_message_metadata_passthrough":{"turn_id":"a464097d-3a78-4a75-9ebb-a53f309aa685"},"name":"grep","metadata":{"turn_id":"a464097d-3a78-4a75-9ebb-a53f309aa685"}},{"id":"fc_09b01b5279447709016aa9f800734c87d2a234e6d0981aec1f","type":"function_call","status":"completed","arguments":"{\"i\":\"Locating dispatch replacement paths\",\"pattern\":\"fn |retry|poison|serve_attach|from_seq|connect\",\"path\":\"crates/spt-daemon/src/dispatch.rs:300-2400\",\"case\":false,\"gitignore\":true,\"skip\":null}","call_id":"call_IH7H8RDFGE1cLx4G0xvtzjt8","internal_chat_message_metadata_passthrough":{"turn_id":"a464097d-3a78-4a75-9ebb-a53f309aa685"},"name":"grep","metadata":{"turn_id":"a464097d-3a78-4a75-9ebb-a53f309aa685"}},{"id":"fc_09b01b5279447709016aa9f800735487d28bfa0dbe85c7f696","type":"function_call","status":"completed","arguments":"{\"i\":\"Locating brain stream sources\",\"path\":\"crates/spt-daemon/src/brain*;crates/spt-daemon/src/brain/**/*;crates/spt-daemon/tests/*attach*;crates/spt-daemon/tests/*dispatch*;**/*glossary*\",\"hidden\":true,\"gitignore\":true,\"limit\":90}","call_id":"call_o14nJqEFqrzS0PrT2JCqMt1i","internal_chat_message_metadata_passthrough":{"turn_id":"a464097d-3a78-4a75-9ebb-a53f309aa685"},"name":"glob","metadata":{"turn_id":"a464097d-3a78-4a75-9ebb-a53f309aa685"}}]},"duration":9607.322999999858,"ttft":9546.200599999866,"completedAt":1789523968543,"contextSnapshot":{"promptTokens":20339,"nonMessageTokens":10480,"compactionEpoch":0}}}
{"type":"message","id":"6dddb203","parentId":"12e81b24","timestamp":"2026-09-16T01:59:28.558Z","message":{"role":"toolResult","toolCallId":"call_U6cJL4sE5MekxSXz2WaVsxJz|fc_09b01b5279447709016aa9f800733c87d2baab1987d9edddfe","toolName":"grep","content":[{"type":"text","text":" 322|                brain.attach_as(session_id, floor, intent, gen, by)?;\n*323|                swallow_resume_ack = true;\n 324|            }\n 325|            Err(e) => return Err(e),\n 326|        }\n...\n 338|// [impl->REQ-RC-CROSS-NODE-ATTACH]\n*339|pub(crate) fn resolve_local_session(brain: &mut Brain, endpoint: &str) -> Option<u64> {\n 340|    brain.sessions().ok().and_then(|reply| {\n 341|        reply\n 342|            .sessions\n...\n 366|#[allow(clippy::too_many_arguments)]\n*367|fn handle_attach_request(\n 368|    brain: &mut Brain,\n 369|    wire: &mut Brain,\n 370|    stream_id: u64,\n...\n 392|    {\n*393|        wire.net_stream_send(stream_id, &[], None, true)?;\n 394|        return Ok(Some(AttachServeOutcome::Refused));\n 395|    }\n 396|    let sid = remote_session.unwrap_or(session_id);\n...\n 472|#[allow(clippy::too_many_arguments)]\n*473|pub fn serve_attach(\n 474|    brain: &mut Brain,\n 475|    broker_name: &str,\n 476|    stream_id: u64,\n...\n 482|) -> io::Result<AttachServeOutcome> {\n*483|    brain.net_stream_subscribe(stream_id, net_from_seq)?;\n 484|    // TWO-CONN SPLIT (REQ-HAZARD-ENDPOINT-RUN-ATTACH-OUTPUT): the wire FORWARDS\n 485|    // (session Output / Size / Exit / Displaced / detach-finish onto the operator\n 486|    // stream) ride a SEPARATE broker connection from `brain`. `brain` RECEIVES\n...\n 490|    // forwards rode `brain` too, that stuck handler could not read them →\n*491|    // serve→broker backs up while broker→serve replay backs up → mutual IPC\n*492|    // backpressure DEADLOCK, and the operator receives ZERO bytes (the bug: an\n 493|    // attach to an ALREADY-PRODUCING endpoint-run harness, non-empty ring). The\n 494|    // two directions on independent single-threaded handlers cannot block each\n 495|    // other. `send_stream` is stream_id-keyed (conn-agnostic), so forwarding from\n...\n 598|                        });\n*599|                        let _ = wire.net_stream_send(stream_id, &line, None, true);\n 600|                        feed_rest(endpoint, crate::resting::RestEvent::Detach);\n 601|                        return Err(e);\n 602|                    }\n...\n 608|            }\n*609|            _ => brain.read_event_until(deadline)?,\n 610|        };\n 611|        match event {\n 612|            // ── Wire → session: requests, input, resize. ───────────────────\n...\n 662|                                // Confirmed controller — exactly-once at the PTY\n*663|                                // (the operator-minted id rides the B5 journal). NO-ACK\n*664|                                // (REQ-HAZARD-INPUT-ACK-BACKPRESSURE): this path is\n*665|                                // fire-and-forward (the ack is discarded here) and can\n*666|                                // flood N input frames on this one conn; an acked write\n*667|                                // back would fill the return direction and deadlock the\n 668|                                // broker's per-conn handler. Dedup still holds at the\n 669|                                // broker (op_id applied-set).\n*670|                                // [impl->REQ-HAZARD-INPUT-ACK-BACKPRESSURE]\n 671|                                Some(ServeRole::Controller) => {\n 672|                                    // The op_id is operator-minted (rc attach OpMinter),\n 673|                                    // so it carries the `rc` journal tag (ADR-0034).\n*674|                                    brain.send_effect_no_ack(\n 675|                                        MintedOp::new(Minter::Rc, op_id),\n 676|                                        &bytes,\n 677|                                    )?\n...\n 704|                            enroll_pubkey_hex,\n*705|                            enroll_backend_kind,\n 706|                        } if attached && intent != AttachIntent::Viewer => {\n 707|                            // The SIGNET W2 additive fields — a FIDO2 proof\n 708|                            // or `E` enroll facts — forward VERBATIM: still\n...\n 712|                                .as_deref()\n*713|                                .zip(enroll_backend_kind.as_deref());\n 714|                            brain.seal_ceremony_code(\n 715|                                ceremony_id,\n 716|                                code.as_deref(),\n...\n 726|                        // Input/Resize before Request, a viewer's input/resize,\n*727|                        // or target-direction records echoed back: noise — ignore.\n 728|                        _ => {}\n 729|                    }\n 730|                }\n...\n 746|                            let line = ndjson::encode_line(&AttachRecord::Notice { text });\n*747|                            wire.net_stream_send(stream_id, &line, None, false)?;\n 748|                        }\n 749|                        // A driver attached — the wake edge (controller-only;\n 750|                        // idempotent on an already-active seat).\n...\n 754|                        for (op, b) in pending_input.drain(..) {\n*755|                            brain.send_effect(MintedOp::new(Minter::Rc, op), &b)?;\n 756|                        }\n 757|                    }\n 758|                    O::Viewer => {\n...\n 767|                        // renders the busy guidance client-side from driven_by.\n*768|                        wire.net_stream_send(stream_id, &[], None, true)?;\n 769|                        return Ok(AttachServeOutcome::Refused);\n 770|                    }\n 771|                }\n...\n 781|                    let line = ndjson::encode_line(&AttachRecord::ClientPolicy { policies });\n*782|                    wire.net_stream_send(stream_id, &line, None, false)?;\n 783|                }\n 784|            }\n 785|            BrokerEvent::Other(env)\n...\n 792|                let line = ndjson::encode_line(&AttachRecord::InputPaths { request });\n*793|                wire.net_stream_send(stream_id, &line, None, false)?;\n 794|            }\n 795|            // Seal-ceremony overlay open / per-attempt verdict (WAX-SEAL W2):\n 796|            // broker-authored records forwarded onto the attach wire for the\n...\n 820|                });\n*821|                wire.net_stream_send(stream_id, &line, None, false)?;\n 822|            }\n 823|            BrokerEvent::SealCeremonyResult {\n 824|                ceremony_id,\n...\n 833|                });\n*834|                wire.net_stream_send(stream_id, &line, None, false)?;\n 835|            }\n 836|            // Viewer letterbox feed: the current PTY size (on attach + resize).\n 837|            BrokerEvent::Size { rows, cols, .. } if attached => {\n 838|                let line = ndjson::encode_line(&AttachRecord::Size { rows, cols });\n*839|                wire.net_stream_send(stream_id, &line, None, false)?;\n 840|            }\n 841|            // This controller was kicked by a different operator's `--take`.\n 842|            BrokerEvent::Displaced { by, .. } if attached => {\n 843|                let line = ndjson::encode_line(&AttachRecord::Displaced { by });\n*844|                wire.net_stream_send(stream_id, &line, None, true)?;\n 845|                // No dormant edge: the endpoint stays driven by the taker (whose\n 846|                // own serve loop already fired the wake).\n 847|                return Ok(AttachServeOutcome::Displaced);\n...\n 873|            BrokerEvent::NetStreamEof { stream_id: sid, .. } if sid == stream_id => {\n*874|                wire.net_stream_send(stream_id, &[], None, true)?;\n 875|                // ORDER MATTERS: feed the resting edge FIRST (it read-modify-writes\n 876|                // info.json, carrying the current driven_by through), THEN release\n 877|                // the role over IPC so the broker's driven_by=None is the LAST\n...\n 898|                // the record, and the operator's render cursor is the dedup.\n*899|                wire.net_stream_send(stream_id, &line, None, false)?;\n 900|            }\n 901|            BrokerEvent::Exit { code, .. } if attached => {\n 902|                let line = ndjson::encode_line(&AttachRecord::Exit { code });\n*903|                wire.net_stream_send(stream_id, &line, None, true)?;\n 904|                if role == Some(ServeRole::Controller) {\n 905|                    feed_rest(endpoint, crate::resting::RestEvent::Detach);\n 906|                }\n...\n 915|            }\n*916|            // Applied/NetSent acks and unrelated events: not ours to handle.\n 917|            _ => {}\n 918|        }\n 919|    }\n...\n 925|/// ([`AttachRecord::Input`] with operator-minted op ids). `open_op` is the\n*926|/// durable id for the exactly-once stream open (safe to block for its ack —\n 927|/// no attach traffic can be in flight before the stream exists); the Request\n 928|/// send itself is unjournaled (see module docs — a replayed Request re-gates\n 929|/// and re-attaches idempotently).\n 930|// [impl->REQ-INST-8]\n*931|pub fn request_attach(\n 932|    brain: &mut Brain,\n 933|    conn_id: u64,\n 934|    session_id: u64,\n...\n 950|#[allow(clippy::too_many_arguments)]\n*951|pub fn request_attach_endpoint(\n 952|    brain: &mut Brain,\n 953|    conn_id: u64,\n 954|    session_id: u64,\n...\n 993|    });\n*994|    brain.net_stream_send(opened.stream_id, &line, None, false)?;\n 995|    Ok(opened.stream_id)\n 996|}\n 997|\n...\n 1003|// [impl->REQ-RCVIEW-1]\n*1004|pub fn send_attach_resize(\n 1005|    brain: &mut Brain,\n 1006|    stream_id: u64,\n 1007|    rows: u16,\n...\n 1010|    let line = ndjson::encode_line(&AttachRecord::Resize { rows, cols });\n*1011|    brain.net_stream_send(stream_id, &line, None, false)?;\n 1012|    Ok(())\n 1013|}\n 1014|\n...\n 1024|// [impl->REQ-SEAL-FIDO2-RC-CLIENT]\n*1025|pub fn send_seal_ceremony_code(\n 1026|    brain: &mut Brain,\n 1027|    stream_id: u64,\n 1028|    ceremony_id: u64,\n...\n 1037|        enroll_pubkey_hex: enroll_facts.map(|(pk, _)| pk.to_string()),\n*1038|        enroll_backend_kind: enroll_facts.map(|(_, bk)| bk.to_string()),\n 1039|    });\n*1040|    brain.net_stream_send(stream_id, &line, None, false)?;\n 1041|    Ok(())\n 1042|}\n 1043|\n...\n 1048|// [impl->REQ-INST-8]\n*1049|pub fn send_attach_input(\n 1050|    brain: &mut Brain,\n 1051|    stream_id: u64,\n 1052|    bytes: &[u8],\n...\n 1058|    });\n*1059|    brain.net_stream_send(stream_id, &line, None, false)?;\n 1060|    Ok(())\n 1061|}\n 1062|\n...\n 1077|    #[test]\n*1078|    fn viewer_and_driving_intents_gate_on_different_surfaces() {\n 1079|        assert_eq!(attach_surface(AttachIntent::Viewer), surface::RC_VIEW);\n 1080|        assert_eq!(attach_surface(AttachIntent::Control), surface::RC_ATTACH);\n 1081|        assert_eq!(\n...\n 1115|    // same-node VIEW row is the one that cannot be expressed as an access rule:\n*1116|    // the loopback Allow precedes the whole chain, so a rule row would never be\n 1117|    // consulted for the origin that matters most.\n 1118|    #[test]\n*1119|    fn the_engine_room_has_no_viewport_and_takes_its_controls_from_home() {\n 1120|        use AttachIntent::{Control, Take, Viewer};\n 1121|\n 1122|        for from_this_node in [true, false] {\n...\n 1145|            EngineRoomLock::Pass,\n*1146|            \"including taking them back from a wedged incumbent\"\n 1147|        );\n 1148|\n 1149|        // Every other endpoint is untouched by all of it."}],"details":{"scopePath":"crates/spt-daemon/src/attach.rs","searchPath":"C:\\Users\\decid\\Documents\\projects\\spt-core\\crates\\spt-daemon\\src\\attach.rs","cwd":"C:\\Users\\decid\\Documents\\projects\\spt-core","matchCount":48,"fileCount":1,"files":["crates/spt-daemon/src/attach.rs"],"fileMatches":[{"path":"crates/spt-daemon/src/attach.rs","count":48}],"truncated":false,"displayContent":"  322│                brain.attach_as(session_id, floor, intent, gen, by)?;\n *323│                swallow_resume_ack = true;\n  324│            }\n  325│            Err(e) => return Err(e),\n  326│        }\n     │...\n  338│// [impl->REQ-RC-CROSS-NODE-ATTACH]\n *339│pub(crate) fn resolve_local_session(brain: &mut Brain, endpoint: &str) -> Option<u64> {\n  340│    brain.sessions().ok().and_then(|reply| {\n  341│        reply\n  342│            .sessions\n     │...\n  366│#[allow(clippy::too_many_arguments)]\n *367│fn handle_attach_request(\n  368│    brain: &mut Brain,\n  369│    wire: &mut Brain,\n  370│    stream_id: u64,\n     │...\n  392│    {\n *393│        wire.net_stream_send(stream_id, &[], None, true)?;\n  394│        return Ok(Some(AttachServeOutcome::Refused));\n  395│    }\n  396│    let sid = remote_session.unwrap_or(session_id);\n     │...\n  472│#[allow(clippy::too_many_arguments)]\n *473│pub fn serve_attach(\n  474│    brain: &mut Brain,\n  475│    broker_name: &str,\n  476│    stream_id: u64,\n     │...\n  482│) -> io::Result<AttachServeOutcome> {\n *483│    brain.net_stream_subscribe(stream_id, net_from_seq)?;\n  484│    // TWO-CONN SPLIT (REQ-HAZARD-ENDPOINT-RUN-ATTACH-OUTPUT): the wire FORWARDS\n  485│    // (session Output / Size / Exit / Displaced / detach-finish onto the operator\n  486│    // stream) ride a SEPARATE broker connection from `brain`. `brain` RECEIVES\n     │...\n  490│    // forwards rode `brain` too, that stuck handler could not read them →\n *491│    // serve→broker backs up while broker→serve replay backs up → mutual IPC\n *492│    // backpressure DEADLOCK, and the operator receives ZERO bytes (the bug: an\n  493│    // attach to an ALREADY-PRODUCING endpoint-run harness, non-empty ring). The\n  494│    // two directions on independent single-threaded handlers cannot block each\n  495│    // other. `send_stream` is stream_id-keyed (conn-agnostic), so forwarding from\n     │...\n  598│                        });\n *599│                        let _ = wire.net_stream_send(stream_id, &line, None, true);\n  600│                        feed_rest(endpoint, crate::resting::RestEvent::Detach);\n  601│                        return Err(e);\n  602│                    }\n     │...\n  608│            }\n *609│            _ => brain.read_event_until(deadline)?,\n  610│        };\n  611│        match event {\n  612│            // ── Wire → session: requests, input, resize. ───────────────────\n     │...\n  662│                                // Confirmed controller — exactly-once at the PTY\n *663│                                // (the operator-minted id rides the B5 journal). NO-ACK\n *664│                                // (REQ-HAZARD-INPUT-ACK-BACKPRESSURE): this path is\n *665│                                // fire-and-forward (the ack is discarded here) and can\n *666│                                // flood N input frames on this one conn; an acked write\n *667│                                // back would fill the return direction and deadlock the\n  668│                                // broker's per-conn handler. Dedup still holds at the\n  669│                                // broker (op_id applied-set).\n *670│                                // [impl->REQ-HAZARD-INPUT-ACK-BACKPRESSURE]\n  671│                                Some(ServeRole::Controller) => {\n  672│                                    // The op_id is operator-minted (rc attach OpMinter),\n  673│                                    // so it carries the `rc` journal tag (ADR-0034).\n *674│                                    brain.send_effect_no_ack(\n  675│                                        MintedOp::new(Minter::Rc, op_id),\n  676│                                        &bytes,\n  677│                                    )?\n     │...\n  704│                            enroll_pubkey_hex,\n *705│                            enroll_backend_kind,\n  706│                        } if attached && intent != AttachIntent::Viewer => {\n  707│                            // The SIGNET W2 additive fields — a FIDO2 proof\n  708│                            // or `E` enroll facts — forward VERBATIM: still\n     │...\n  712│                                .as_deref()\n *713│                                .zip(enroll_backend_kind.as_deref());\n  714│                            brain.seal_ceremony_code(\n  715│                                ceremony_id,\n  716│                                code.as_deref(),\n     │...\n  726│                        // Input/Resize before Request, a viewer's input/resize,\n *727│                        // or target-direction records echoed back: noise — ignore.\n  728│                        _ => {}\n  729│                    }\n  730│                }\n     │...\n  746│                            let line = ndjson::encode_line(&AttachRecord::Notice { text });\n *747│                            wire.net_stream_send(stream_id, &line, None, false)?;\n  748│                        }\n  749│                        // A driver attached — the wake edge (controller-only;\n  750│                        // idempotent on an already-active seat).\n     │...\n  754│                        for (op, b) in pending_input.drain(..) {\n *755│                            brain.send_effect(MintedOp::new(Minter::Rc, op), &b)?;\n  756│                        }\n  757│                    }\n  758│                    O::Viewer => {\n     │...\n  767│                        // renders the busy guidance client-side from driven_by.\n *768│                        wire.net_stream_send(stream_id, &[], None, true)?;\n  769│                        return Ok(AttachServeOutcome::Refused);\n  770│                    }\n  771│                }\n     │...\n  781│                    let line = ndjson::encode_line(&AttachRecord::ClientPolicy { policies });\n *782│                    wire.net_stream_send(stream_id, &line, None, false)?;\n  783│                }\n  784│            }\n  785│            BrokerEvent::Other(env)\n     │...\n  792│                let line = ndjson::encode_line(&AttachRecord::InputPaths { request });\n *793│                wire.net_stream_send(stream_id, &line, None, false)?;\n  794│            }\n  795│            // Seal-ceremony overlay open / per-attempt verdict (WAX-SEAL W2):\n  796│            // broker-authored records forwarded onto the attach wire for the\n     │...\n  820│                });\n *821│                wire.net_stream_send(stream_id, &line, None, false)?;\n  822│            }\n  823│            BrokerEvent::SealCeremonyResult {\n  824│                ceremony_id,\n     │...\n  833│                });\n *834│                wire.net_stream_send(stream_id, &line, None, false)?;\n  835│            }\n  836│            // Viewer letterbox feed: the current PTY size (on attach + resize).\n  837│            BrokerEvent::Size { rows, cols, .. } if attached => {\n  838│                let line = ndjson::encode_line(&AttachRecord::Size { rows, cols });\n *839│                wire.net_stream_send(stream_id, &line, None, false)?;\n  840│            }\n  841│            // This controller was kicked by a different operator's `--take`.\n  842│            BrokerEvent::Displaced { by, .. } if attached => {\n  843│                let line = ndjson::encode_line(&AttachRecord::Displaced { by });\n *844│                wire.net_stream_send(stream_id, &line, None, true)?;\n  845│                // No dormant edge: the endpoint stays driven by the taker (whose\n  846│                // own serve loop already fired the wake).\n  847│                return Ok(AttachServeOutcome::Displaced);\n     │...\n  873│            BrokerEvent::NetStreamEof { stream_id: sid, .. } if sid == stream_id => {\n *874│                wire.net_stream_send(stream_id, &[], None, true)?;\n  875│                // ORDER MATTERS: feed the resting edge FIRST (it read-modify-writes\n  876│                // info.json, carrying the current driven_by through), THEN release\n  877│                // the role over IPC so the broker's driven_by=None is the LAST\n     │...\n  898│                // the record, and the operator's render cursor is the dedup.\n *899│                wire.net_stream_send(stream_id, &line, None, false)?;\n  900│            }\n  901│            BrokerEvent::Exit { code, .. } if attached => {\n  902│                let line = ndjson::encode_line(&AttachRecord::Exit { code });\n *903│                wire.net_stream_send(stream_id, &line, None, true)?;\n  904│                if role == Some(ServeRole::Controller) {\n  905│                    feed_rest(endpoint, crate::resting::RestEvent::Detach);\n  906│                }\n     │...\n  915│            }\n *916│            // Applied/NetSent acks and unrelated events: not ours to handle.\n  917│            _ => {}\n  918│        }\n  919│    }\n     │...\n  925│/// ([`AttachRecord::Input`] with operator-minted op ids). `open_op` is the\n *926│/// durable id for the exactly-once stream open (safe to block for its ack —\n  927│/// no attach traffic can be in flight before the stream exists); the Request\n  928│/// send itself is unjournaled (see module docs — a replayed Request re-gates\n  929│/// and re-attaches idempotently).\n  930│// [impl->REQ-INST-8]\n *931│pub fn request_attach(\n  932│    brain: &mut Brain,\n  933│    conn_id: u64,\n  934│    session_id: u64,\n     │...\n  950│#[allow(clippy::too_many_arguments)]\n *951│pub fn request_attach_endpoint(\n  952│    brain: &mut Brain,\n  953│    conn_id: u64,\n  954│    session_id: u64,\n     │...\n  993│    });\n *994│    brain.net_stream_send(opened.stream_id, &line, None, false)?;\n  995│    Ok(opened.stream_id)\n  996│}\n  997│\n     │...\n 1003│// [impl->REQ-RCVIEW-1]\n*1004│pub fn send_attach_resize(\n 1005│    brain: &mut Brain,\n 1006│    stream_id: u64,\n 1007│    rows: u16,\n     │...\n 1010│    let line = ndjson::encode_line(&AttachRecord::Resize { rows, cols });\n*1011│    brain.net_stream_send(stream_id, &line, None, false)?;\n 1012│    Ok(())\n 1013│}\n 1014│\n     │...\n 1024│// [impl->REQ-SEAL-FIDO2-RC-CLIENT]\n*1025│pub fn send_seal_ceremony_code(\n 1026│    brain: &mut Brain,\n 1027│    stream_id: u64,\n 1028│    ceremony_id: u64,\n     │...\n 1037│        enroll_pubkey_hex: enroll_facts.map(|(pk, _)| pk.to_string()),\n*1038│        enroll_backend_kind: enroll_facts.map(|(_, bk)| bk.to_string()),\n 1039│    });\n*1040│    brain.net_stream_send(stream_id, &line, None, false)?;\n 1041│    Ok(())\n 1042│}\n 1043│\n     │...\n 1048│// [impl->REQ-INST-8]\n*1049│pub fn send_attach_input(\n 1050│    brain: &mut Brain,\n 1051│    stream_id: u64,\n 1052│    bytes: &[u8],\n     │...\n 1058│    });\n*1059│    brain.net_stream_send(stream_id, &line, None, false)?;\n 1060│    Ok(())\n 1061│}\n 1062│\n     │...\n 1077│    #[test]\n*1078│    fn viewer_and_driving_intents_gate_on_different_surfaces() {\n 1079│        assert_eq!(attach_surface(AttachIntent::Viewer), surface::RC_VIEW);\n 1080│        assert_eq!(attach_surface(AttachIntent::Control), surface::RC_ATTACH);\n 1081│        assert_eq!(\n     │...\n 1115│    // same-node VIEW row is the one that cannot be expressed as an access rule:\n*1116│    // the loopback Allow precedes the whole chain, so a rule row would never be\n 1117│    // consulted for the origin that matters most.\n 1118│    #[test]\n*1119│    fn the_engine_room_has_no_viewport_and_takes_its_controls_from_home() {\n 1120│        use AttachIntent::{Control, Take, Viewer};\n 1121│\n 1122│        for from_this_node in [true, false] {\n     │...\n 1145│            EngineRoomLock::Pass,\n*1146│            \"including taking them back from a wedged incumbent\"\n 1147│        );\n 1148│\n 1149│        // Every other endpoint is untouched by all of it."},"isError":false,"timestamp":1789523968558}}
{"type":"message","id":"1fd65754","parentId":"6dddb203","timestamp":"2026-09-16T01:59:28.565Z","message":{"role":"toolResult","toolCallId":"call_IH7H8RDFGE1cLx4G0xvtzjt8|fc_09b01b5279447709016aa9f800734c87d2a234e6d0981aec1f","toolName":"grep","content":[{"type":"text","text":" 324|/// A claimed stream's dispatch lifecycle (ADR-0038 C,\n*325|/// REQ-DISPATCH-CLAIM-RETRY). The pre-fix `claimed` was a one-shot `HashSet`\n 326|/// insert performed BEFORE worker spawn and never cleared — one transient\n 327|/// worker-setup failure permanently abandoned the stream. Claims now\n*328|/// distinguish in-flight vs terminal vs retryable, and a transient failure\n 329|/// requeues bounded (backoff-shaped, never a hot loop).\n 330|#[derive(Debug, Clone, Copy, PartialEq, Eq)]\n 331|enum ClaimState {\n...\n 337|    /// A transient failure released the claim; eligible again at `next_at`.\n*338|    Retry { attempts: u32, next_at: Instant },\n 339|}\n 340|\n*341|/// Bounded retry budget per stream per dispatcher lifetime — transient setup\n 342|/// failures recover, a persistently-failing stream goes terminal loud.\n 343|const MAX_DISPATCH_ATTEMPTS: u32 = 3;\n 344|\n 345|/// Backoff base for a released claim (doubles per failed attempt).\n*346|const DISPATCH_RETRY_BASE: Duration = Duration::from_millis(500);\n 347|\n*348|/// The backoff before retry number `attempts` (1-based) runs.\n*349|fn retry_backoff(attempts: u32) -> Duration {\n*350|    DISPATCH_RETRY_BASE * 2u32.saturating_pow(attempts.saturating_sub(1))\n 351|}\n 352|\n*353|/// Why a worker failed — the retry CLASSIFICATION (ADR-0038 Amendment fix 5,\n*354|/// REQ-DISPATCH-FALLBACK-CIRCUIT). The two classes retry differently:\n 355|/// a pre-setup transient keeps the bounded ×3 budget (the D3 semantics);\n*356|/// a seat-blocked failure (poisoned replay / prior subscriber still draining)\n 357|/// trips the GLOBAL circuit breaker and requeues WITHOUT burning budget —\n 358|/// the stream must recover once the wedged seat's writer dies (≤ the 15s\n 359|/// bounded-write deadline), and three fast retries would burn to Terminal\n...\n 364|    Transient,\n*365|    /// The stream's subscriber seat is poisoned or still draining — retrying\n 366|    /// immediately would manufacture another replay victim.\n 367|    SeatBlocked,\n 368|}\n...\n 372|// [impl->REQ-DISPATCH-FALLBACK-CIRCUIT]\n*373|fn classify_failure(msg: &str) -> FailClass {\n 374|    if msg.contains(\"subscriber busy\")\n 375|        || msg.contains(\"replay halted\")\n 376|        || msg.contains(\"lease canceled\")\n...\n 387|/// `unknown command kind \"…\"` (broker.rs forward-compat arm), a stable N-1\n*388|/// wire fact. Everything else (transport timeout, EOF, poison) is a\n 389|/// transient — Failed → bounded requeue, never a second replay subscriber.\n 390|// [impl->REQ-DISPATCH-FALLBACK-CIRCUIT]\n*391|fn is_unsupported_verb(e: &io::Error) -> bool {\n 392|    e.to_string().contains(\"unknown command kind\")\n 393|}\n 394|\n...\n 396|/// seat-blocked failure trips it — claiming pauses dispatcher-wide for a\n*397|/// doubling window (base 2s, cap 30s), so retry machinery cannot hammer a\n 398|/// wedged conn with fresh replay subscribers. Any successful serve resets it.\n 399|/// PURE (instant-in, decision-out) — unit-tested trip/gate/reset.\n 400|// [impl->REQ-DISPATCH-FALLBACK-CIRCUIT]\n...\n 411|    /// A seat-blocked failure landed: open (or extend) the window.\n*412|    fn trip(&mut self, now: Instant) -> Duration {\n 413|        let window = (BREAKER_BASE * 2u32.saturating_pow(self.consecutive)).min(BREAKER_CAP);\n 414|        self.consecutive = self.consecutive.saturating_add(1);\n 415|        self.until = Some(now + window);\n...\n 419|    /// Whether claiming is currently paused.\n*420|    fn open(&self, now: Instant) -> bool {\n 421|        self.until.is_some_and(|t| now < t)\n 422|    }\n 423|\n 424|    /// Real progress (a Served outcome): close and reset.\n*425|    fn reset(&mut self) {\n 426|        self.until = None;\n 427|        self.consecutive = 0;\n 428|    }\n...\n 433|/// family (once classified), attempt, and conn — the field-discriminator\n*434|/// surface (poison-window census, per-generation attach counts). PURE\n 435|/// formatting so key completeness is a unit fact.\n*436|fn dispatch_event(\n 437|    gen: u64,\n 438|    stream_id: u64,\n 439|    family: Option<StreamFamily>,\n...\n 453|/// off). The unit-tested seam for the no-hot-loop ruling.\n*454|// [impl->REQ-DISPATCH-CLAIM-RETRY]\n*455|fn should_claim(state: Option<&ClaimState>, now: Instant) -> Option<u32> {\n 456|    match state {\n 457|        None => Some(0),\n*458|        Some(ClaimState::Retry { attempts, next_at }) if now >= *next_at => Some(*attempts),\n 459|        _ => None,\n 460|    }\n 461|}\n 462|\n*463|/// Strike budget for a deadline-poisoned ONE-WAY replay (ADR-0040 decision 4,\n 464|/// REQ-REGISTRY-REPLAY-BOUNDED): at budget the row retires TERMINAL — safe by\n 465|/// family semantics (a feed is an idempotent snapshot advertisement; the next\n 466|/// pump round re-advertises, so worst-case loss is one ~30s round, already\n...\n 468|/// path — they keep the Amendment breaker's budget-free pacing.\n*469|const ONEWAY_POISON_STRIKES: u32 = 3;\n 470|\n 471|/// Whether a family is ONE-WAY fire-and-forget snapshot advertisement — the\n*472|/// only class whose poisoned replay may retire terminal at the strike budget\n 473|/// (ADR-0040 decision 4). Registry only: a feed is idempotent and\n 474|/// re-advertised every round. Notif/WanMsg feeds carry durable rows and\n 475|/// replies respectively — dropping one loses real state, so they keep\n...\n 477|// [impl->REQ-REGISTRY-REPLAY-BOUNDED]\n*478|fn family_is_one_way(family: Option<StreamFamily>) -> bool {\n 479|    family == Some(StreamFamily::Registry)\n 480|}\n 481|\n...\n 493|/// a one-way family's `SeatBlocked` DOES accumulate strikes (in `attempts`)\n*494|/// and retires TERMINAL at [`ONEWAY_POISON_STRIKES`] — a poisoned feed replay\n 495|/// must never remain indefinitely redispatchable (the v0.36 recurring\n*496|/// Registry poisons). Its Transient budget exhaustion retires terminal too —\n 497|/// every terminal-from-failure one-way row leaves the table for good; the\n 498|/// next advertisement round is the recovery. Defense-in-depth behind\n 499|/// REQ-ONEWAY-STREAM-TERMINAL (which removes the population at source).\n*500|// [impl->REQ-DISPATCH-CLAIM-RETRY]\n 501|// [impl->REQ-DISPATCH-FALLBACK-CIRCUIT]\n 502|// [impl->REQ-REGISTRY-REPLAY-BOUNDED]\n*503|fn outcome_transition(\n 504|    outcome: &DispatchOutcome,\n 505|    family: Option<StreamFamily>,\n 506|    attempts: u32,\n...\n 514|                let attempts = attempts + 1;\n*515|                if attempts >= ONEWAY_POISON_STRIKES {\n 516|                    (ClaimState::Terminal, true)\n 517|                } else {\n 518|                    (\n*519|                        ClaimState::Retry {\n 520|                            attempts,\n 521|                            next_at: now + breaker_window,\n 522|                        },\n...\n 527|            FailClass::SeatBlocked => (\n*528|                ClaimState::Retry {\n 529|                    attempts,\n 530|                    next_at: now + breaker_window,\n 531|                },\n...\n 539|                    (\n*540|                        ClaimState::Retry {\n 541|                            attempts,\n*542|                            next_at: now + retry_backoff(attempts),\n 543|                        },\n 544|                        false,\n 545|                    )\n...\n 572|// [impl->REQ-HAZARD-REDISPATCH-CONTROL-STEAL]\n*573|fn finished_row_is_terminal(family: StreamFamily, finished: bool) -> bool {\n 574|    finished && family == StreamFamily::Attach\n 575|}\n 576|\n...\n 581|/// process and disarms on first take.\n*582|fn take_injected_transient() -> bool {\n 583|    static ARMED: OnceLock<AtomicBool> = OnceLock::new();\n 584|    let armed = ARMED.get_or_init(|| {\n 585|        AtomicBool::new(std::env::var(\"SPT_DISPATCH_INJECT_TRANSIENT_ONCE\").is_ok())\n...\n 591|/// makes exactly ONE worker fail with the seat-blocked answer (\"subscriber\n*592|/// busy\" — the string a real poisoned replay surfaces) — proving the GLOBAL\n 593|/// breaker trips, claiming pauses, and the SAME stream recovers on the paced\n*594|/// retry through the REAL claim path. The seat-poison mechanics themselves\n 595|/// are proven with real wedged conns (T1/T3/T4); this valve isolates the\n 596|/// loop's RESPONSE to the classification. Same latch discipline as the\n 597|/// transient valve.\n*598|fn take_injected_seatblocked() -> bool {\n 599|    static ARMED: OnceLock<AtomicBool> = OnceLock::new();\n 600|    let armed = ARMED.get_or_init(|| {\n 601|        AtomicBool::new(std::env::var(\"SPT_DISPATCH_INJECT_SEATBLOCKED_ONCE\").is_ok())\n...\n 612|/// fresh feeds keep serving. Counted latch, armed once per process.\n*613|fn take_injected_registry_seatblocked() -> bool {\n 614|    use std::sync::atomic::AtomicUsize;\n 615|    static LEFT: OnceLock<AtomicUsize> = OnceLock::new();\n 616|    let left = LEFT.get_or_init(|| {\n...\n 642|    /// The production layout under [`perch::spt_home`].\n*643|    pub fn production() -> DispatchPaths {\n 644|        let home = perch::spt_home();\n 645|        DispatchPaths {\n 646|            owlery: perch::owlery_dir(),\n...\n 656|/// stream).\n*657|pub fn run_dispatch_loop(\n 658|    broker_name: &str,\n 659|    paths: &DispatchPaths,\n 660|    registry: Arc<RegistryHost>,\n...\n 691|/// for a transport error. So a refusal the owner deliberately served counts, and a\n*692|/// retryable transport failure does not — which is what keeps a retry from\n 693|/// inflating the count past the cells that really happened.\n*694|pub fn run_dispatch_loop_observed(\n 695|    broker_name: &str,\n 696|    paths: &DispatchPaths,\n 697|    registry: Arc<RegistryHost>,\n...\n 701|) -> io::Result<()> {\n*702|    let mut brain = connect(broker_name)?;\n*703|    // Claim lifecycle (ADR-0038 C): in-flight / terminal / retryable —\n 704|    // replaces the pre-fix one-shot `HashSet` whose burned claims permanently\n 705|    // abandoned a stream on the first transient failure.\n 706|    let claims: Arc<Mutex<HashMap<u64, ClaimState>>> = Arc::new(Mutex::new(HashMap::new()));\n 707|    // Dispatcher generation id (Amendment fix 9): every telemetry record this\n*708|    // loop emits carries it, so per-generation attach/poison censuses line up.\n 709|    let generation = now_ms();\n 710|    // Global circuit breaker (Amendment fix 5) + its current window, shared\n*711|    // with workers so a seat-blocked retry paces on it.\n 712|    let breaker: Arc<Mutex<CircuitBreaker>> = Arc::new(Mutex::new(CircuitBreaker::default()));\n 713|    // Bounded worker pool (Amendment fix 7): a cold table (daemon refresh\n 714|    // with a large backlog) claims at most this many rows per poll — the\n...\n 722|        if breaker.lock().unwrap().open(Instant::now()) {\n*723|            // Circuit open: a poisoned replay just happened — pause ALL\n 724|            // claiming for the window instead of hammering the wedged conn\n 725|            // with fresh replay subscribers (Amendment fix 5).\n 726|            thread::sleep(poll);\n...\n 733|            // next_seq guard also skips a row whose pump hasn't appended yet).\n*734|            // Terminal rows never re-enter; a released (Retry) claim re-enters\n*735|            // after its backoff (REQ-DISPATCH-CLAIM-RETRY).\n 736|            if s.initiated_locally || s.next_seq == 0 {\n 737|                continue;\n 738|            }\n...\n 783|                    // and the row retires when the broker cycles.\n*784|                    if let Ok(mut retire_brain) = connect(&name) {\n 785|                        let _ = retire_brain.net_stream_retire(stream_id);\n 786|                    }\n 787|                    // Breaker reset = REAL progress only (gate round 1): a row\n...\n 850|                // One-way strike budget spent (ADR-0040 decision 4): retire\n*851|                // the row TERMINAL — physically, loudly. A poisoned feed\n 852|                // replay must never remain redispatchable across dispatcher\n 853|                // generations; the next pump round re-advertises everything.\n 854|                // [impl->REQ-REGISTRY-REPLAY-BOUNDED]\n 855|                if retire_terminal {\n*856|                    if let Ok(mut retire_brain) = connect(&name) {\n 857|                        let _ = retire_brain.net_stream_retire_terminal(stream_id);\n 858|                    }\n 859|                    eprintln!(\n...\n 868|                            &format!(\n*869|                                \"budget={ONEWAY_POISON_STRIKES} row retired terminal; next \\\n 870|                                 advertisement round recovers\"\n 871|                            ),\n 872|                        )\n...\n 892|// [impl->REQ-DISPATCH-HYGIENE-TELEMETRY]\n*893|fn pool_has_room(active: usize) -> bool {\n 894|    active < MAX_DISPATCH_WORKERS\n 895|}\n 896|\n*897|/// Connect a fresh brain IPC client (retrying through broker startup).\n*898|fn connect(broker_name: &str) -> io::Result<Brain> {\n 899|    let mut last = io::Error::other(\"broker never answered\");\n 900|    for _ in 0..300 {\n 901|        match Brain::cold_start(broker_name, now_ms()) {\n...\n 909|\n*910|fn now_ms() -> u64 {\n 911|    std::time::SystemTime::now()\n 912|        .duration_since(std::time::UNIX_EPOCH)\n 913|        .map(|d| d.as_millis() as u64)\n...\n 921|/// (terminal); `Err` = transient (the claim requeues bounded).\n*922|fn first_line(\n 923|    broker_name: &str,\n 924|    stream_id: u64,\n 925|    floor_seq: u64,\n 926|) -> io::Result<Option<serde_json::Value>> {\n*927|    match connect(broker_name).and_then(|mut b| b.net_stream_opener(stream_id)) {\n 928|        // Pinned: classify from the durable fact. A pinned line that does not\n 929|        // parse is terminally unclassifiable (same contract as the peek path).\n 930|        Ok(Some(bytes)) => return Ok(serde_json::from_slice(&bytes).ok()),\n...\n 933|        // next_seq guard proved bytes exist, so treat as transient — the\n*934|        // bounded claim retry re-reads it shortly, and a stream that never\n 935|        // pins goes terminal when the budget is spent (no hot loop).\n 936|        Ok(None) => {\n 937|            return Err(io::Error::other(format!(\n...\n 942|        // to the ring peek (ADR-0038 Amendment fix 1) — the pre-Amendment\n*943|        // broad Err(_) arm caught transport timeout/EOF/poison too, and each\n*944|        // retry then manufactured a throwaway replay subscriber against a\n 945|        // possibly-wedged conn (the v0.34 stall engine's first gear).\n 946|        // [impl->REQ-DISPATCH-FALLBACK-CIRCUIT]\n 947|        Err(e) if is_unsupported_verb(&e) => {}\n...\n 955|/// Peek the stream's first retained NDJSON line on a throwaway brain\n*956|/// connection (the pre-ADR-0038 fallback — subject to ring eviction, kept\n 957|/// only for the older-broker window). Subscribes from `floor_seq` (the oldest\n 958|/// retained chunk) so a rolled ring replays instead of tripping the brain's\n 959|/// gap check.\n*960|fn peek_first_line(\n 961|    broker_name: &str,\n 962|    stream_id: u64,\n 963|    floor_seq: u64,\n 964|) -> io::Result<Option<serde_json::Value>> {\n*965|    let mut brain = connect(broker_name)?;\n 966|    brain.net_stream_subscribe(stream_id, floor_seq)?;\n 967|    let mut buf: Vec<u8> = Vec::new();\n 968|    // [impl->REQ-BRAIN-READ-BOUNDED-PER-CALL]\n...\n 993|/// One claimed stream's worker: peek → classify → run the family's serve\n*994|/// loop on a fresh brain connection.\n 995|/// The endpoint identity a stream's opener names, where the family carries\n 996|/// one (Amendment fix 9 — hertz's live catch on stream 7058 could not bind\n 997|/// the stalled stream to an endpoint; this key is what makes the next catch\n...\n 1000|// [impl->REQ-DISPATCH-HYGIENE-TELEMETRY]\n*1001|fn line_endpoint(family: StreamFamily, line: &serde_json::Value) -> Option<String> {\n 1002|    let key = match family {\n 1003|        StreamFamily::Attach => \"endpoint_id\",\n 1004|        StreamFamily::Rest => \"endpoint\",\n...\n 1023|impl WorkerReport {\n*1024|    fn bare(outcome: DispatchOutcome) -> WorkerReport {\n 1025|        WorkerReport {\n 1026|            outcome,\n 1027|            family: None,\n...\n 1033|#[allow(clippy::too_many_arguments)]\n*1034|fn worker(\n 1035|    broker_name: &str,\n 1036|    stream_id: u64,\n 1037|    origin: &str,\n...\n 1097|\n*1098|    let mut brain = match connect(broker_name) {\n 1099|        Ok(b) => b,\n 1100|        Err(e) => {\n 1101|            return WorkerReport {\n...\n 1174|            // dispatcher-resolved session id on the cross-node leg (resolved HERE,\n*1175|            // before serve_attach subscribes — never mid-serve, which would swallow\n 1176|            // interleaved attach records) and `None` on the local path.\n 1177|            let (endpoint, remote_session) = match line\n 1178|                .get(\"endpoint_id\")\n...\n 1208|                // [impl->REQ-STREAM-OPENER-DURABLE]\n*1209|                Some(endpoint) => match serve_attach(\n 1210|                    &mut brain,\n 1211|                    broker_name,\n 1212|                    stream_id,\n...\n 1326|// [impl->REQ-INST-7]\n*1327|fn serve_registry_feed(\n 1328|    brain: &mut Brain,\n 1329|    stream_id: u64,\n 1330|    origin: &str,\n...\n 1345|    // snapshot rewrites per 64KiB chunk, synchronously in the brain's event\n*1346|    // loop — the drain stall that manufactured the 15s seat-writer poisons\n 1347|    // (KH 7.44). Attention shifts fire once per id, post-merge.\n 1348|    // [impl->REQ-REGISTRY-APPLY-TRANSACTIONAL]\n 1349|    // [impl->REQ-BRAIN-READ-BOUNDED-PER-CALL]\n...\n 1379|// [impl->REQ-REGISTRY-APPLY-TRANSACTIONAL]\n*1380|fn commit_feed_batch(\n 1381|    registry: &RegistryHost,\n 1382|    origin: &str,\n 1383|    policy: &RegistryGatePolicy,\n...\n 1425|impl FeedBatch {\n*1426|    fn len(&self) -> usize {\n 1427|        self.labels.len() + self.updates.len()\n 1428|    }\n 1429|\n*1430|    fn is_empty(&self) -> bool {\n 1431|        self.labels.is_empty() && self.updates.is_empty()\n 1432|    }\n 1433|}\n...\n 1446|impl FeedAccumulator {\n*1447|    fn new(bound: usize) -> FeedAccumulator {\n 1448|        FeedAccumulator {\n 1449|            bound: bound.max(1),\n 1450|            batch: FeedBatch::default(),\n...\n 1455|    /// tripped (the caller commits it).\n*1456|    fn push(&mut self, records: Vec<RegistryFeedRecord>) -> Option<FeedBatch> {\n 1457|        for rec in records {\n 1458|            match rec {\n 1459|                RegistryFeedRecord::Instance(u) => self.batch.updates.push(u),\n...\n 1471|    /// commits nothing — zero snapshot writes).\n*1472|    fn finish(&mut self) -> Option<FeedBatch> {\n 1473|        if self.batch.is_empty() {\n 1474|            None\n 1475|        } else {\n...\n 1492|// [impl->REQ-PRES-1]\n*1493|fn serve_notif_feed(brain: &mut Brain, stream_id: u64, origin: &str) -> DispatchOutcome {\n 1494|    let store = match NotifStore::open() {\n 1495|        Ok(s) => s,\n 1496|        Err(e) => return DispatchOutcome::Failed(e.to_string()),\n...\n 1556|/// last-writer-wins, and a lost LOCAL mint is the one record re-presentation\n*1557|/// cannot heal). Poison is swallowed like every other daemon lock: the store\n 1558|/// itself stays untorn under the atomic write.\n 1559|// [impl->REQ-SEAL-CEREMONY-TOTP]\n*1560|pub(crate) fn seal_apply_lock() -> std::sync::MutexGuard<'static, ()> {\n 1561|    SEAL_APPLY.lock().unwrap_or_else(|p| p.into_inner())\n 1562|}\n 1563|\n...\n 1569|// [impl->REQ-SEAL-STORE-REPLICATES-SUBNET-SCOPED]\n*1570|fn serve_seal_feed(brain: &mut Brain, stream_id: u64, origin: &str) -> DispatchOutcome {\n 1571|    let policy = NotifPolicy::load();\n 1572|    if let Err(e) = brain.net_stream_subscribe(stream_id, 0) {\n 1573|        return DispatchOutcome::Failed(e.to_string());\n...\n 1643|// [impl->REQ-PRES-1]\n*1644|fn surface_fresh_rows(\n 1645|    store: &NotifStore,\n 1646|    records: &[spt_net::net::notif::NotifRecord],\n 1647|    verdicts: &[crate::notifsync::NotifApplyVerdict],\n...\n 1689|// [impl->REQ-KNOCK-FLOOD]\n*1690|fn serve_knock_feed(brain: &mut Brain, stream_id: u64, origin: &str) -> DispatchOutcome {\n 1691|    use spt_net::net::knockmsg::{KnockDecoder, KnockReply};\n 1692|\n 1693|    if let Err(e) = brain.net_stream_subscribe(stream_id, 0) {\n...\n 1745|// [impl->REQ-HAZARD-WAN-ORIGIN-AUTH]\n*1746|fn serve_fork_feed(brain: &mut Brain, stream_id: u64, origin: &str) -> DispatchOutcome {\n 1747|    use spt_net::net::forkmsg::ForkDecoder;\n 1748|\n 1749|    if let Err(e) = brain.net_stream_subscribe(stream_id, 0) {\n...\n 1794|// [impl->REQ-KNOCK-REDEEM-WIRE]\n*1795|fn serve_redeem_feed(brain: &mut Brain, stream_id: u64, origin: &str) -> DispatchOutcome {\n 1796|    use spt_net::net::redeemmsg::RedeemDecoder;\n 1797|\n 1798|    if let Err(e) = brain.net_stream_subscribe(stream_id, 0) {\n...\n 1844|// [impl->REQ-KNOCK-ANSWER-RECEIPT]\n*1845|fn serve_answer_feed(brain: &mut Brain, stream_id: u64, origin: &str) -> DispatchOutcome {\n 1846|    use spt_net::net::answermsg::AnswerDecoder;\n 1847|\n 1848|    if let Err(e) = brain.net_stream_subscribe(stream_id, 0) {\n...\n 1891|// [impl->REQ-FORK-ACCESS-GATED]\n*1892|pub fn serve_one_fork(\n 1893|    rec: &spt_net::net::forkmsg::ForkRecord,\n 1894|    origin_node: &str,\n 1895|) -> Option<spt_net::net::forkmsg::ForkReply> {\n...\n 1933|// [impl->REQ-KNOCK-FLOOD]\n*1934|pub fn record_inbound_knock(\n 1935|    rec: &spt_net::net::knockmsg::KnockRecord,\n 1936|    origin_node: &str,\n 1937|) -> &'static str {\n...\n 1986|// [impl->REQ-HAZARD-PROBE-CONTEXT-ISOLATION]\n*1987|fn serve_presence_feed(brain: &mut Brain, stream_id: u64, origin: &str) -> DispatchOutcome {\n 1988|    use spt_net::net::presencemsg::PresenceDecoder;\n 1989|\n 1990|    if let Err(e) = brain.net_stream_subscribe(stream_id, 0) {\n...\n 2035|/// A relay-hosted endpoint holds no broker session, so the only honest\n*2036|/// observation available is whether its own listener accepts a connection right\n 2037|/// now. That is the same observation `deliver_tcp` makes one message at a time\n 2038|/// (the SENT-vs-QUEUED leak this family adds no new information class to).\n 2039|// [impl->REQ-UNLISTED-PRESENCE-PROBE]\n...\n 2044|    NoChannel,\n*2045|    /// A registered listener ACCEPTED a connection.\n 2046|    Accepted,\n 2047|    /// A registered address did not accept (refused, timed out, unparseable).\n 2048|    NotAccepted,\n...\n 2062|/// `relay` is the fallback observation for a relay-hosted endpoint. An accepted\n*2063|/// connect says LISTENING (a message sent now goes straight through); anything\n*2064|/// else says UNKNOWN, never OFFLINE — a refused connect cannot distinguish a\n 2065|/// busy listener between polls from a dead one, and rendering `offline` there\n 2066|/// would be a coin flip presented as a fact.\n 2067|///\n...\n 2075|// [impl->REQ-UNLISTED-PRESENCE-PROBE]\n*2076|pub fn presence_from(session: Option<bool>, relay: RelayObservation) -> Presence {\n 2077|    match (session, relay) {\n 2078|        (Some(true), _) => Presence::Listening,\n 2079|        (Some(false), _) => Presence::Busy,\n...\n 2108|/// observations and forgotten (REQ-HAZARD-PROBE-CONTEXT-ISOLATION). The relay\n*2109|/// connect attempt sends ZERO BYTES and drops: a listener accepts, reads no\n 2110|/// framed message, and returns to its poll with nothing delivered.\n 2111|// [impl->REQ-UNLISTED-PRESENCE-PROBE]\n 2112|// [impl->REQ-HAZARD-PROBE-CONTEXT-ISOLATION]\n 2113|// [impl->REQ-HAZARD-WAN-ORIGIN-AUTH]\n*2114|pub fn answer_presence_probe(\n 2115|    rec: &spt_net::net::presencemsg::PresenceRecord,\n 2116|    origin_node: &str,\n 2117|) -> Option<spt_net::net::presencemsg::PresenceReply> {\n...\n 2147|///\n*2148|/// A fresh brain connection rather than the serve loop's own: the worker's\n 2149|/// brain owns its stream's event feed, and a query interleaved into it would\n 2150|/// swallow stream records (the same reason the attach arm resolves its session\n 2151|/// BEFORE subscribing). The broker is multi-client by design.\n...\n 2157|// [impl->REQ-UNLISTED-PRESENCE-PROBE]\n*2158|fn broker_session_idle(endpoint: &str) -> Option<bool> {\n 2159|    let mut brain = Brain::cold_start(&crate::endpoint::broker_socket_name(), now_ms()).ok()?;\n 2160|    let hosted = brain\n 2161|        .sessions()\n...\n 2171|\n*2172|/// The RELAY observation: a real connect attempt, and nothing more.\n 2173|///\n 2174|/// Zero bytes are written. The listener accepts, finds no framed message, and\n 2175|/// returns to its poll — the probe cannot become content because it never sends\n...\n 2179|// [impl->REQ-HAZARD-PROBE-CONTEXT-ISOLATION]\n*2180|fn observe_relay(endpoint: &str) -> RelayObservation {\n*2181|    /// The relay connect is a local loopback dial; a listener that cannot\n 2182|    /// accept in this long has not \"not answered yet\", it is not there.\n*2183|    const RELAY_CONNECT_TIMEOUT: Duration = Duration::from_millis(500);\n 2184|\n 2185|    let Some(addr) = spt_store::registry::resolve_address(endpoint, &perch::owlery_dir()) else {\n 2186|        return RelayObservation::NoChannel;\n...\n 2190|    };\n*2191|    match std::net::TcpStream::connect_timeout(&addr, RELAY_CONNECT_TIMEOUT) {\n 2192|        Ok(_stream) => RelayObservation::Accepted,\n 2193|        Err(_) => RelayObservation::NotAccepted,\n 2194|    }\n...\n 2199|// [impl->REQ-NET-1]\n*2200|fn serve_wan_feed(\n 2201|    brain: &mut Brain,\n 2202|    stream_id: u64,\n 2203|    origin: &str,\n...\n 2257|/// socket — the daemon-boot entry ([`crate::daemon::Daemon::run`]).\n*2258|pub fn spawn_dispatcher(\n 2259|    broker_name: String,\n 2260|    registry: Arc<RegistryHost>,\n 2261|    stop: Arc<AtomicBool>,\n...\n 2283|    #[test]\n*2284|    fn classifies_every_family_by_first_line_shape() {\n 2285|        let sync = json!({\"kind\": \"request\", \"sync_id\": \"pull-1\", \"refs\": [], \"have_tips\": {}});\n 2286|        assert_eq!(classify_first_line(&sync), StreamFamily::Sync);\n 2287|\n*2288|        let attach = json!({\"kind\": \"request\", \"session_id\": 3, \"from_seq\": 0});\n 2289|        assert_eq!(classify_first_line(&attach), StreamFamily::Attach);\n 2290|\n 2291|        // [unit->REQ-INST-6] the rest op's opener disambiguates by shape too.\n...\n 2328|    #[test]\n*2329|    fn digest_pull_and_rest_never_read_as_each_other() {\n 2330|        let pull = json!({\"kind\": \"request\", \"endpoint\": \"liam\",\n 2331|            \"digest_pull\": true, \"op_id\": \"aa:cli:7\"});\n 2332|        assert_eq!(classify_first_line(&pull), StreamFamily::DigestPull);\n...\n 2370|    #[test]\n*2371|    fn unknown_shapes_refuse_classification() {\n 2372|        for v in [\n 2373|            json!({\"kind\": \"chunk\", \"sync_id\": \"s\", \"offset\": 0, \"data_b64\": \"\"}), // mid-protocol, not an opener\n 2374|            json!({\"kind\": \"request\"}), // request without any discriminant"}],"details":{"scopePath":"crates/spt-daemon/src/dispatch.rs","searchPath":"C:\\Users\\decid\\Documents\\projects\\spt-core\\crates\\spt-daemon\\src\\dispatch.rs","cwd":"C:\\Users\\decid\\Documents\\projects\\spt-core","matchCount":117,"fileCount":1,"files":["crates/spt-daemon/src/dispatch.rs"],"fileMatches":[{"path":"crates/spt-daemon/src/dispatch.rs","count":117}],"truncated":false,"displayContent":"  324│/// A claimed stream's dispatch lifecycle (ADR-0038 C,\n *325│/// REQ-DISPATCH-CLAIM-RETRY). The pre-fix `claimed` was a one-shot `HashSet`\n  326│/// insert performed BEFORE worker spawn and never cleared — one transient\n  327│/// worker-setup failure permanently abandoned the stream. Claims now\n *328│/// distinguish in-flight vs terminal vs retryable, and a transient failure\n  329│/// requeues bounded (backoff-shaped, never a hot loop).\n  330│#[derive(Debug, Clone, Copy, PartialEq, Eq)]\n  331│enum ClaimState {\n     │...\n  337│    /// A transient failure released the claim; eligible again at `next_at`.\n *338│    Retry { attempts: u32, next_at: Instant },\n  339│}\n  340│\n *341│/// Bounded retry budget per stream per dispatcher lifetime — transient setup\n  342│/// failures recover, a persistently-failing stream goes terminal loud.\n  343│const MAX_DISPATCH_ATTEMPTS: u32 = 3;\n  344│\n  345│/// Backoff base for a released claim (doubles per failed attempt).\n *346│const DISPATCH_RETRY_BASE: Duration = Duration::from_millis(500);\n  347│\n *348│/// The backoff before retry number `attempts` (1-based) runs.\n *349│fn retry_backoff(attempts: u32) -> Duration {\n *350│    DISPATCH_RETRY_BASE * 2u32.saturating_pow(attempts.saturating_sub(1))\n  351│}\n  352│\n *353│/// Why a worker failed — the retry CLASSIFICATION (ADR-0038 Amendment fix 5,\n *354│/// REQ-DISPATCH-FALLBACK-CIRCUIT). The two classes retry differently:\n  355│/// a pre-setup transient keeps the bounded ×3 budget (the D3 semantics);\n *356│/// a seat-blocked failure (poisoned replay / prior subscriber still draining)\n  357│/// trips the GLOBAL circuit breaker and requeues WITHOUT burning budget —\n  358│/// the stream must recover once the wedged seat's writer dies (≤ the 15s\n  359│/// bounded-write deadline), and three fast retries would burn to Terminal\n     │...\n  364│    Transient,\n *365│    /// The stream's subscriber seat is poisoned or still draining — retrying\n  366│    /// immediately would manufacture another replay victim.\n  367│    SeatBlocked,\n  368│}\n     │...\n  372│// [impl->REQ-DISPATCH-FALLBACK-CIRCUIT]\n *373│fn classify_failure(msg: &str) -> FailClass {\n  374│    if msg.contains(\"subscriber busy\")\n  375│        || msg.contains(\"replay halted\")\n  376│        || msg.contains(\"lease canceled\")\n     │...\n  387│/// `unknown command kind \"…\"` (broker.rs forward-compat arm), a stable N-1\n *388│/// wire fact. Everything else (transport timeout, EOF, poison) is a\n  389│/// transient — Failed → bounded requeue, never a second replay subscriber.\n  390│// [impl->REQ-DISPATCH-FALLBACK-CIRCUIT]\n *391│fn is_unsupported_verb(e: &io::Error) -> bool {\n  392│    e.to_string().contains(\"unknown command kind\")\n  393│}\n  394│\n     │...\n  396│/// seat-blocked failure trips it — claiming pauses dispatcher-wide for a\n *397│/// doubling window (base 2s, cap 30s), so retry machinery cannot hammer a\n  398│/// wedged conn with fresh replay subscribers. Any successful serve resets it.\n  399│/// PURE (instant-in, decision-out) — unit-tested trip/gate/reset.\n  400│// [impl->REQ-DISPATCH-FALLBACK-CIRCUIT]\n     │...\n  411│    /// A seat-blocked failure landed: open (or extend) the window.\n *412│    fn trip(&mut self, now: Instant) -> Duration {\n  413│        let window = (BREAKER_BASE * 2u32.saturating_pow(self.consecutive)).min(BREAKER_CAP);\n  414│        self.consecutive = self.consecutive.saturating_add(1);\n  415│        self.until = Some(now + window);\n     │...\n  419│    /// Whether claiming is currently paused.\n *420│    fn open(&self, now: Instant) -> bool {\n  421│        self.until.is_some_and(|t| now < t)\n  422│    }\n  423│\n  424│    /// Real progress (a Served outcome): close and reset.\n *425│    fn reset(&mut self) {\n  426│        self.until = None;\n  427│        self.consecutive = 0;\n  428│    }\n     │...\n  433│/// family (once classified), attempt, and conn — the field-discriminator\n *434│/// surface (poison-window census, per-generation attach counts). PURE\n  435│/// formatting so key completeness is a unit fact.\n *436│fn dispatch_event(\n  437│    gen: u64,\n  438│    stream_id: u64,\n  439│    family: Option<StreamFamily>,\n     │...\n  453│/// off). The unit-tested seam for the no-hot-loop ruling.\n *454│// [impl->REQ-DISPATCH-CLAIM-RETRY]\n *455│fn should_claim(state: Option<&ClaimState>, now: Instant) -> Option<u32> {\n  456│    match state {\n  457│        None => Some(0),\n *458│        Some(ClaimState::Retry { attempts, next_at }) if now >= *next_at => Some(*attempts),\n  459│        _ => None,\n  460│    }\n  461│}\n  462│\n *463│/// Strike budget for a deadline-poisoned ONE-WAY replay (ADR-0040 decision 4,\n  464│/// REQ-REGISTRY-REPLAY-BOUNDED): at budget the row retires TERMINAL — safe by\n  465│/// family semantics (a feed is an idempotent snapshot advertisement; the next\n  466│/// pump round re-advertises, so worst-case loss is one ~30s round, already\n     │...\n  468│/// path — they keep the Amendment breaker's budget-free pacing.\n *469│const ONEWAY_POISON_STRIKES: u32 = 3;\n  470│\n  471│/// Whether a family is ONE-WAY fire-and-forget snapshot advertisement — the\n *472│/// only class whose poisoned replay may retire terminal at the strike budget\n  473│/// (ADR-0040 decision 4). Registry only: a feed is idempotent and\n  474│/// re-advertised every round. Notif/WanMsg feeds carry durable rows and\n  475│/// replies respectively — dropping one loses real state, so they keep\n     │...\n  477│// [impl->REQ-REGISTRY-REPLAY-BOUNDED]\n *478│fn family_is_one_way(family: Option<StreamFamily>) -> bool {\n  479│    family == Some(StreamFamily::Registry)\n  480│}\n  481│\n     │...\n  493│/// a one-way family's `SeatBlocked` DOES accumulate strikes (in `attempts`)\n *494│/// and retires TERMINAL at [`ONEWAY_POISON_STRIKES`] — a poisoned feed replay\n  495│/// must never remain indefinitely redispatchable (the v0.36 recurring\n *496│/// Registry poisons). Its Transient budget exhaustion retires terminal too —\n  497│/// every terminal-from-failure one-way row leaves the table for good; the\n  498│/// next advertisement round is the recovery. Defense-in-depth behind\n  499│/// REQ-ONEWAY-STREAM-TERMINAL (which removes the population at source).\n *500│// [impl->REQ-DISPATCH-CLAIM-RETRY]\n  501│// [impl->REQ-DISPATCH-FALLBACK-CIRCUIT]\n  502│// [impl->REQ-REGISTRY-REPLAY-BOUNDED]\n *503│fn outcome_transition(\n  504│    outcome: &DispatchOutcome,\n  505│    family: Option<StreamFamily>,\n  506│    attempts: u32,\n     │...\n  514│                let attempts = attempts + 1;\n *515│                if attempts >= ONEWAY_POISON_STRIKES {\n  516│                    (ClaimState::Terminal, true)\n  517│                } else {\n  518│                    (\n *519│                        ClaimState::Retry {\n  520│                            attempts,\n  521│                            next_at: now + breaker_window,\n  522│                        },\n     │...\n  527│            FailClass::SeatBlocked => (\n *528│                ClaimState::Retry {\n  529│                    attempts,\n  530│                    next_at: now + breaker_window,\n  531│                },\n     │...\n  539│                    (\n *540│                        ClaimState::Retry {\n  541│                            attempts,\n *542│                            next_at: now + retry_backoff(attempts),\n  543│                        },\n  544│                        false,\n  545│                    )\n     │...\n  572│// [impl->REQ-HAZARD-REDISPATCH-CONTROL-STEAL]\n *573│fn finished_row_is_terminal(family: StreamFamily, finished: bool) -> bool {\n  574│    finished && family == StreamFamily::Attach\n  575│}\n  576│\n     │...\n  581│/// process and disarms on first take.\n *582│fn take_injected_transient() -> bool {\n  583│    static ARMED: OnceLock<AtomicBool> = OnceLock::new();\n  584│    let armed = ARMED.get_or_init(|| {\n  585│        AtomicBool::new(std::env::var(\"SPT_DISPATCH_INJECT_TRANSIENT_ONCE\").is_ok())\n     │...\n  591│/// makes exactly ONE worker fail with the seat-blocked answer (\"subscriber\n *592│/// busy\" — the string a real poisoned replay surfaces) — proving the GLOBAL\n  593│/// breaker trips, claiming pauses, and the SAME stream recovers on the paced\n *594│/// retry through the REAL claim path. The seat-poison mechanics themselves\n  595│/// are proven with real wedged conns (T1/T3/T4); this valve isolates the\n  596│/// loop's RESPONSE to the classification. Same latch discipline as the\n  597│/// transient valve.\n *598│fn take_injected_seatblocked() -> bool {\n  599│    static ARMED: OnceLock<AtomicBool> = OnceLock::new();\n  600│    let armed = ARMED.get_or_init(|| {\n  601│        AtomicBool::new(std::env::var(\"SPT_DISPATCH_INJECT_SEATBLOCKED_ONCE\").is_ok())\n     │...\n  612│/// fresh feeds keep serving. Counted latch, armed once per process.\n *613│fn take_injected_registry_seatblocked() -> bool {\n  614│    use std::sync::atomic::AtomicUsize;\n  615│    static LEFT: OnceLock<AtomicUsize> = OnceLock::new();\n  616│    let left = LEFT.get_or_init(|| {\n     │...\n  642│    /// The production layout under [`perch::spt_home`].\n *643│    pub fn production() -> DispatchPaths {\n  644│        let home = perch::spt_home();\n  645│        DispatchPaths {\n  646│            owlery: perch::owlery_dir(),\n     │...\n  656│/// stream).\n *657│pub fn run_dispatch_loop(\n  658│    broker_name: &str,\n  659│    paths: &DispatchPaths,\n  660│    registry: Arc<RegistryHost>,\n     │...\n  691│/// for a transport error. So a refusal the owner deliberately served counts, and a\n *692│/// retryable transport failure does not — which is what keeps a retry from\n  693│/// inflating the count past the cells that really happened.\n *694│pub fn run_dispatch_loop_observed(\n  695│    broker_name: &str,\n  696│    paths: &DispatchPaths,\n  697│    registry: Arc<RegistryHost>,\n     │...\n  701│) -> io::Result<()> {\n *702│    let mut brain = connect(broker_name)?;\n *703│    // Claim lifecycle (ADR-0038 C): in-flight / terminal / retryable —\n  704│    // replaces the pre-fix one-shot `HashSet` whose burned claims permanently\n  705│    // abandoned a stream on the first transient failure.\n  706│    let claims: Arc<Mutex<HashMap<u64, ClaimState>>> = Arc::new(Mutex::new(HashMap::new()));\n  707│    // Dispatcher generation id (Amendment fix 9): every telemetry record this\n *708│    // loop emits carries it, so per-generation attach/poison censuses line up.\n  709│    let generation = now_ms();\n  710│    // Global circuit breaker (Amendment fix 5) + its current window, shared\n *711│    // with workers so a seat-blocked retry paces on it.\n  712│    let breaker: Arc<Mutex<CircuitBreaker>> = Arc::new(Mutex::new(CircuitBreaker::default()));\n  713│    // Bounded worker pool (Amendment fix 7): a cold table (daemon refresh\n  714│    // with a large backlog) claims at most this many rows per poll — the\n     │...\n  722│        if breaker.lock().unwrap().open(Instant::now()) {\n *723│            // Circuit open: a poisoned replay just happened — pause ALL\n  724│            // claiming for the window instead of hammering the wedged conn\n  725│            // with fresh replay subscribers (Amendment fix 5).\n  726│            thread::sleep(poll);\n     │...\n  733│            // next_seq guard also skips a row whose pump hasn't appended yet).\n *734│            // Terminal rows never re-enter; a released (Retry) claim re-enters\n *735│            // after its backoff (REQ-DISPATCH-CLAIM-RETRY).\n  736│            if s.initiated_locally || s.next_seq == 0 {\n  737│                continue;\n  738│            }\n     │...\n  783│                    // and the row retires when the broker cycles.\n *784│                    if let Ok(mut retire_brain) = connect(&name) {\n  785│                        let _ = retire_brain.net_stream_retire(stream_id);\n  786│                    }\n  787│                    // Breaker reset = REAL progress only (gate round 1): a row\n     │...\n  850│                // One-way strike budget spent (ADR-0040 decision 4): retire\n *851│                // the row TERMINAL — physically, loudly. A poisoned feed\n  852│                // replay must never remain redispatchable across dispatcher\n  853│                // generations; the next pump round re-advertises everything.\n  854│                // [impl->REQ-REGISTRY-REPLAY-BOUNDED]\n  855│                if retire_terminal {\n *856│                    if let Ok(mut retire_brain) = connect(&name) {\n  857│                        let _ = retire_brain.net_stream_retire_terminal(stream_id);\n  858│                    }\n  859│                    eprintln!(\n     │...\n  868│                            &format!(\n *869│                                \"budget={ONEWAY_POISON_STRIKES} row retired terminal; next \\\n  870│                                 advertisement round recovers\"\n  871│                            ),\n  872│                        )\n     │...\n  892│// [impl->REQ-DISPATCH-HYGIENE-TELEMETRY]\n *893│fn pool_has_room(active: usize) -> bool {\n  894│    active < MAX_DISPATCH_WORKERS\n  895│}\n  896│\n *897│/// Connect a fresh brain IPC client (retrying through broker startup).\n *898│fn connect(broker_name: &str) -> io::Result<Brain> {\n  899│    let mut last = io::Error::other(\"broker never answered\");\n  900│    for _ in 0..300 {\n  901│        match Brain::cold_start(broker_name, now_ms()) {\n     │...\n  909│\n *910│fn now_ms() -> u64 {\n  911│    std::time::SystemTime::now()\n  912│        .duration_since(std::time::UNIX_EPOCH)\n  913│        .map(|d| d.as_millis() as u64)\n     │...\n  921│/// (terminal); `Err` = transient (the claim requeues bounded).\n *922│fn first_line(\n  923│    broker_name: &str,\n  924│    stream_id: u64,\n  925│    floor_seq: u64,\n  926│) -> io::Result<Option<serde_json::Value>> {\n *927│    match connect(broker_name).and_then(|mut b| b.net_stream_opener(stream_id)) {\n  928│        // Pinned: classify from the durable fact. A pinned line that does not\n  929│        // parse is terminally unclassifiable (same contract as the peek path).\n  930│        Ok(Some(bytes)) => return Ok(serde_json::from_slice(&bytes).ok()),\n     │...\n  933│        // next_seq guard proved bytes exist, so treat as transient — the\n *934│        // bounded claim retry re-reads it shortly, and a stream that never\n  935│        // pins goes terminal when the budget is spent (no hot loop).\n  936│        Ok(None) => {\n  937│            return Err(io::Error::other(format!(\n     │...\n  942│        // to the ring peek (ADR-0038 Amendment fix 1) — the pre-Amendment\n *943│        // broad Err(_) arm caught transport timeout/EOF/poison too, and each\n *944│        // retry then manufactured a throwaway replay subscriber against a\n  945│        // possibly-wedged conn (the v0.34 stall engine's first gear).\n  946│        // [impl->REQ-DISPATCH-FALLBACK-CIRCUIT]\n  947│        Err(e) if is_unsupported_verb(&e) => {}\n     │...\n  955│/// Peek the stream's first retained NDJSON line on a throwaway brain\n *956│/// connection (the pre-ADR-0038 fallback — subject to ring eviction, kept\n  957│/// only for the older-broker window). Subscribes from `floor_seq` (the oldest\n  958│/// retained chunk) so a rolled ring replays instead of tripping the brain's\n  959│/// gap check.\n *960│fn peek_first_line(\n  961│    broker_name: &str,\n  962│    stream_id: u64,\n  963│    floor_seq: u64,\n  964│) -> io::Result<Option<serde_json::Value>> {\n *965│    let mut brain = connect(broker_name)?;\n  966│    brain.net_stream_subscribe(stream_id, floor_seq)?;\n  967│    let mut buf: Vec<u8> = Vec::new();\n  968│    // [impl->REQ-BRAIN-READ-BOUNDED-PER-CALL]\n     │...\n  993│/// One claimed stream's worker: peek → classify → run the family's serve\n *994│/// loop on a fresh brain connection.\n  995│/// The endpoint identity a stream's opener names, where the family carries\n  996│/// one (Amendment fix 9 — hertz's live catch on stream 7058 could not bind\n  997│/// the stalled stream to an endpoint; this key is what makes the next catch\n     │...\n 1000│// [impl->REQ-DISPATCH-HYGIENE-TELEMETRY]\n*1001│fn line_endpoint(family: StreamFamily, line: &serde_json::Value) -> Option<String> {\n 1002│    let key = match family {\n 1003│        StreamFamily::Attach => \"endpoint_id\",\n 1004│        StreamFamily::Rest => \"endpoint\",\n     │...\n 1023│impl WorkerReport {\n*1024│    fn bare(outcome: DispatchOutcome) -> WorkerReport {\n 1025│        WorkerReport {\n 1026│            outcome,\n 1027│            family: None,\n     │...\n 1033│#[allow(clippy::too_many_arguments)]\n*1034│fn worker(\n 1035│    broker_name: &str,\n 1036│    stream_id: u64,\n 1037│    origin: &str,\n     │...\n 1097│\n*1098│    let mut brain = match connect(broker_name) {\n 1099│        Ok(b) => b,\n 1100│        Err(e) => {\n 1101│            return WorkerReport {\n     │...\n 1174│            // dispatcher-resolved session id on the cross-node leg (resolved HERE,\n*1175│            // before serve_attach subscribes — never mid-serve, which would swallow\n 1176│            // interleaved attach records) and `None` on the local path.\n 1177│            let (endpoint, remote_session) = match line\n 1178│                .get(\"endpoint_id\")\n     │...\n 1208│                // [impl->REQ-STREAM-OPENER-DURABLE]\n*1209│                Some(endpoint) => match serve_attach(\n 1210│                    &mut brain,\n 1211│                    broker_name,\n 1212│                    stream_id,\n     │...\n 1326│// [impl->REQ-INST-7]\n*1327│fn serve_registry_feed(\n 1328│    brain: &mut Brain,\n 1329│    stream_id: u64,\n 1330│    origin: &str,\n     │...\n 1345│    // snapshot rewrites per 64KiB chunk, synchronously in the brain's event\n*1346│    // loop — the drain stall that manufactured the 15s seat-writer poisons\n 1347│    // (KH 7.44). Attention shifts fire once per id, post-merge.\n 1348│    // [impl->REQ-REGISTRY-APPLY-TRANSACTIONAL]\n 1349│    // [impl->REQ-BRAIN-READ-BOUNDED-PER-CALL]\n     │...\n 1379│// [impl->REQ-REGISTRY-APPLY-TRANSACTIONAL]\n*1380│fn commit_feed_batch(\n 1381│    registry: &RegistryHost,\n 1382│    origin: &str,\n 1383│    policy: &RegistryGatePolicy,\n     │...\n 1425│impl FeedBatch {\n*1426│    fn len(&self) -> usize {\n 1427│        self.labels.len() + self.updates.len()\n 1428│    }\n 1429│\n*1430│    fn is_empty(&self) -> bool {\n 1431│        self.labels.is_empty() && self.updates.is_empty()\n 1432│    }\n 1433│}\n     │...\n 1446│impl FeedAccumulator {\n*1447│    fn new(bound: usize) -> FeedAccumulator {\n 1448│        FeedAccumulator {\n 1449│            bound: bound.max(1),\n 1450│            batch: FeedBatch::default(),\n     │...\n 1455│    /// tripped (the caller commits it).\n*1456│    fn push(&mut self, records: Vec<RegistryFeedRecord>) -> Option<FeedBatch> {\n 1457│        for rec in records {\n 1458│            match rec {\n 1459│                RegistryFeedRecord::Instance(u) => self.batch.updates.push(u),\n     │...\n 1471│    /// commits nothing — zero snapshot writes).\n*1472│    fn finish(&mut self) -> Option<FeedBatch> {\n 1473│        if self.batch.is_empty() {\n 1474│            None\n 1475│        } else {\n     │...\n 1492│// [impl->REQ-PRES-1]\n*1493│fn serve_notif_feed(brain: &mut Brain, stream_id: u64, origin: &str) -> DispatchOutcome {\n 1494│    let store = match NotifStore::open() {\n 1495│        Ok(s) => s,\n 1496│        Err(e) => return DispatchOutcome::Failed(e.to_string()),\n     │...\n 1556│/// last-writer-wins, and a lost LOCAL mint is the one record re-presentation\n*1557│/// cannot heal). Poison is swallowed like every other daemon lock: the store\n 1558│/// itself stays untorn under the atomic write.\n 1559│// [impl->REQ-SEAL-CEREMONY-TOTP]\n*1560│pub(crate) fn seal_apply_lock() -> std::sync::MutexGuard<'static, ()> {\n 1561│    SEAL_APPLY.lock().unwrap_or_else(|p| p.into_inner())\n 1562│}\n 1563│\n     │...\n 1569│// [impl->REQ-SEAL-STORE-REPLICATES-SUBNET-SCOPED]\n*1570│fn serve_seal_feed(brain: &mut Brain, stream_id: u64, origin: &str) -> DispatchOutcome {\n 1571│    let policy = NotifPolicy::load();\n 1572│    if let Err(e) = brain.net_stream_subscribe(stream_id, 0) {\n 1573│        return DispatchOutcome::Failed(e.to_string());\n     │...\n 1643│// [impl->REQ-PRES-1]\n*1644│fn surface_fresh_rows(\n 1645│    store: &NotifStore,\n 1646│    records: &[spt_net::net::notif::NotifRecord],\n 1647│    verdicts: &[crate::notifsync::NotifApplyVerdict],\n     │...\n 1689│// [impl->REQ-KNOCK-FLOOD]\n*1690│fn serve_knock_feed(brain: &mut Brain, stream_id: u64, origin: &str) -> DispatchOutcome {\n 1691│    use spt_net::net::knockmsg::{KnockDecoder, KnockReply};\n 1692│\n 1693│    if let Err(e) = brain.net_stream_subscribe(stream_id, 0) {\n     │...\n 1745│// [impl->REQ-HAZARD-WAN-ORIGIN-AUTH]\n*1746│fn serve_fork_feed(brain: &mut Brain, stream_id: u64, origin: &str) -> DispatchOutcome {\n 1747│    use spt_net::net::forkmsg::ForkDecoder;\n 1748│\n 1749│    if let Err(e) = brain.net_stream_subscribe(stream_id, 0) {\n     │...\n 1794│// [impl->REQ-KNOCK-REDEEM-WIRE]\n*1795│fn serve_redeem_feed(brain: &mut Brain, stream_id: u64, origin: &str) -> DispatchOutcome {\n 1796│    use spt_net::net::redeemmsg::RedeemDecoder;\n 1797│\n 1798│    if let Err(e) = brain.net_stream_subscribe(stream_id, 0) {\n     │...\n 1844│// [impl->REQ-KNOCK-ANSWER-RECEIPT]\n*1845│fn serve_answer_feed(brain: &mut Brain, stream_id: u64, origin: &str) -> DispatchOutcome {\n 1846│    use spt_net::net::answermsg::AnswerDecoder;\n 1847│\n 1848│    if let Err(e) = brain.net_stream_subscribe(stream_id, 0) {\n     │...\n 1891│// [impl->REQ-FORK-ACCESS-GATED]\n*1892│pub fn serve_one_fork(\n 1893│    rec: &spt_net::net::forkmsg::ForkRecord,\n 1894│    origin_node: &str,\n 1895│) -> Option<spt_net::net::forkmsg::ForkReply> {\n     │...\n 1933│// [impl->REQ-KNOCK-FLOOD]\n*1934│pub fn record_inbound_knock(\n 1935│    rec: &spt_net::net::knockmsg::KnockRecord,\n 1936│    origin_node: &str,\n 1937│) -> &'static str {\n     │...\n 1986│// [impl->REQ-HAZARD-PROBE-CONTEXT-ISOLATION]\n*1987│fn serve_presence_feed(brain: &mut Brain, stream_id: u64, origin: &str) -> DispatchOutcome {\n 1988│    use spt_net::net::presencemsg::PresenceDecoder;\n 1989│\n 1990│    if let Err(e) = brain.net_stream_subscribe(stream_id, 0) {\n     │...\n 2035│/// A relay-hosted endpoint holds no broker session, so the only honest\n*2036│/// observation available is whether its own listener accepts a connection right\n 2037│/// now. That is the same observation `deliver_tcp` makes one message at a time\n 2038│/// (the SENT-vs-QUEUED leak this family adds no new information class to).\n 2039│// [impl->REQ-UNLISTED-PRESENCE-PROBE]\n     │...\n 2044│    NoChannel,\n*2045│    /// A registered listener ACCEPTED a connection.\n 2046│    Accepted,\n 2047│    /// A registered address did not accept (refused, timed out, unparseable).\n 2048│    NotAccepted,\n     │...\n 2062│/// `relay` is the fallback observation for a relay-hosted endpoint. An accepted\n*2063│/// connect says LISTENING (a message sent now goes straight through); anything\n*2064│/// else says UNKNOWN, never OFFLINE — a refused connect cannot distinguish a\n 2065│/// busy listener between polls from a dead one, and rendering `offline` there\n 2066│/// would be a coin flip presented as a fact.\n 2067│///\n     │...\n 2075│// [impl->REQ-UNLISTED-PRESENCE-PROBE]\n*2076│pub fn presence_from(session: Option<bool>, relay: RelayObservation) -> Presence {\n 2077│    match (session, relay) {\n 2078│        (Some(true), _) => Presence::Listening,\n 2079│        (Some(false), _) => Presence::Busy,\n     │...\n 2108│/// observations and forgotten (REQ-HAZARD-PROBE-CONTEXT-ISOLATION). The relay\n*2109│/// connect attempt sends ZERO BYTES and drops: a listener accepts, reads no\n 2110│/// framed message, and returns to its poll with nothing delivered.\n 2111│// [impl->REQ-UNLISTED-PRESENCE-PROBE]\n 2112│// [impl->REQ-HAZARD-PROBE-CONTEXT-ISOLATION]\n 2113│// [impl->REQ-HAZARD-WAN-ORIGIN-AUTH]\n*2114│pub fn answer_presence_probe(\n 2115│    rec: &spt_net::net::presencemsg::PresenceRecord,\n 2116│    origin_node: &str,\n 2117│) -> Option<spt_net::net::presencemsg::PresenceReply> {\n     │...\n 2147│///\n*2148│/// A fresh brain connection rather than the serve loop's own: the worker's\n 2149│/// brain owns its stream's event feed, and a query interleaved into it would\n 2150│/// swallow stream records (the same reason the attach arm resolves its session\n 2151│/// BEFORE subscribing). The broker is multi-client by design.\n     │...\n 2157│// [impl->REQ-UNLISTED-PRESENCE-PROBE]\n*2158│fn broker_session_idle(endpoint: &str) -> Option<bool> {\n 2159│    let mut brain = Brain::cold_start(&crate::endpoint::broker_socket_name(), now_ms()).ok()?;\n 2160│    let hosted = brain\n 2161│        .sessions()\n     │...\n 2171│\n*2172│/// The RELAY observation: a real connect attempt, and nothing more.\n 2173│///\n 2174│/// Zero bytes are written. The listener accepts, finds no framed message, and\n 2175│/// returns to its poll — the probe cannot become content because it never sends\n     │...\n 2179│// [impl->REQ-HAZARD-PROBE-CONTEXT-ISOLATION]\n*2180│fn observe_relay(endpoint: &str) -> RelayObservation {\n*2181│    /// The relay connect is a local loopback dial; a listener that cannot\n 2182│    /// accept in this long has not \"not answered yet\", it is not there.\n*2183│    const RELAY_CONNECT_TIMEOUT: Duration = Duration::from_millis(500);\n 2184│\n 2185│    let Some(addr) = spt_store::registry::resolve_address(endpoint, &perch::owlery_dir()) else {\n 2186│        return RelayObservation::NoChannel;\n     │...\n 2190│    };\n*2191│    match std::net::TcpStream::connect_timeout(&addr, RELAY_CONNECT_TIMEOUT) {\n 2192│        Ok(_stream) => RelayObservation::Accepted,\n 2193│        Err(_) => RelayObservation::NotAccepted,\n 2194│    }\n     │...\n 2199│// [impl->REQ-NET-1]\n*2200│fn serve_wan_feed(\n 2201│    brain: &mut Brain,\n 2202│    stream_id: u64,\n 2203│    origin: &str,\n     │...\n 2257│/// socket — the daemon-boot entry ([`crate::daemon::Daemon::run`]).\n*2258│pub fn spawn_dispatcher(\n 2259│    broker_name: String,\n 2260│    registry: Arc<RegistryHost>,\n 2261│    stop: Arc<AtomicBool>,\n     │...\n 2283│    #[test]\n*2284│    fn classifies_every_family_by_first_line_shape() {\n 2285│        let sync = json!({\"kind\": \"request\", \"sync_id\": \"pull-1\", \"refs\": [], \"have_tips\": {}});\n 2286│        assert_eq!(classify_first_line(&sync), StreamFamily::Sync);\n 2287│\n*2288│        let attach = json!({\"kind\": \"request\", \"session_id\": 3, \"from_seq\": 0});\n 2289│        assert_eq!(classify_first_line(&attach), StreamFamily::Attach);\n 2290│\n 2291│        // [unit->REQ-INST-6] the rest op's opener disambiguates by shape too.\n     │...\n 2328│    #[test]\n*2329│    fn digest_pull_and_rest_never_read_as_each_other() {\n 2330│        let pull = json!({\"kind\": \"request\", \"endpoint\": \"liam\",\n 2331│            \"digest_pull\": true, \"op_id\": \"aa:cli:7\"});\n 2332│        assert_eq!(classify_first_line(&pull), StreamFamily::DigestPull);\n     │...\n 2370│    #[test]\n*2371│    fn unknown_shapes_refuse_classification() {\n 2372│        for v in [\n 2373│            json!({\"kind\": \"chunk\", \"sync_id\": \"s\", \"offset\": 0, \"data_b64\": \"\"}), // mid-protocol, not an opener\n 2374│            json!({\"kind\": \"request\"}), // request without any discriminant"},"isError":false,"timestamp":1789523968565}}
{"type":"message","id":"0d14b6ed","parentId":"1fd65754","timestamp":"2026-09-16T01:59:28.575Z","message":{"role":"toolResult","toolCallId":"call_o14nJqEFqrzS0PrT2JCqMt1i|fc_09b01b5279447709016aa9f800735487d28bfa0dbe85c7f696","toolName":"glob","content":[{"type":"text","text":"# crates/spt-daemon/\n## tests/\ndispatch.rs\nattach.rs\nredispatch_stall.rs\nredispatch.rs\nattach_resize_repaint.rs\nattach_resize_capture.rs\nattach_idempotent_replay.rs\n## src/\nbrainproc.rs\nbrain.rs\n\nSkipped missing paths: crates/spt-daemon/src/brain/**/*"}],"details":{"scopePath":"crates/spt-daemon/src/brain*, crates/spt-daemon/tests/*attach*, crates/spt-daemon/tests/*dispatch*, **/*glossary*","fileCount":9,"files":["crates/spt-daemon/tests/dispatch.rs","crates/spt-daemon/tests/attach.rs","crates/spt-daemon/src/brainproc.rs","crates/spt-daemon/src/brain.rs","crates/spt-daemon/tests/redispatch_stall.rs","crates/spt-daemon/tests/redispatch.rs","crates/spt-daemon/tests/attach_resize_repaint.rs","crates/spt-daemon/tests/attach_resize_capture.rs","crates/spt-daemon/tests/attach_idempotent_replay.rs"],"truncated":false,"cwd":"C:\\Users\\decid\\Documents\\projects\\spt-core","missingPaths":["crates/spt-daemon/src/brain/**/*"]},"isError":false,"timestamp":1789523968574}}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_56T9OjroFcXitoNcOOg1cL9M|fc_09b01b5279447709016aa9f80ba4c087d288f91b80be951b05","toolName":"read","startedAt":"2026-09-16T01:59:39.724Z","args":{"path":"crates/spt-daemon/src/attach.rs:367-584"},"intent":"Reading attach pump setup"},"id":"a8dac316","parentId":"0d14b6ed","timestamp":"2026-09-16T01:59:39.724Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_qM8pEVQYJ2kXKZ9Oz4a6pdcl|fc_09b01b5279447709016aa9f80ba4cc87d2b51fcf8f3c8cc07f","toolName":"read","startedAt":"2026-09-16T01:59:39.724Z","args":{"path":"crates/spt-daemon/src/attach.rs:610-785"},"intent":"Reading attach event handling"},"id":"1138a372","parentId":"a8dac316","timestamp":"2026-09-16T01:59:39.724Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_dm91GYv22iSQP1wk6vUSs96t|fc_09b01b5279447709016aa9f80ba4d487d28ceaf6e92822a191","toolName":"grep","startedAt":"2026-09-16T01:59:39.724Z","args":{"path":"crates/spt-daemon/src/brain.rs"},"intent":"Locating brain stream methods"},"id":"eb3ce2b4","parentId":"1138a372","timestamp":"2026-09-16T01:59:39.724Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_A8y6Cpf2uzlYAJBoUzhDhOKS|fc_09b01b5279447709016aa9f80ba4dc87d2ae9f3d7910df6057","toolName":"glob","startedAt":"2026-09-16T01:59:39.724Z","args":{"path":"crates/**/netstream*;crates/**/netstream/**/*;.spt/preserved/307/hertz-w1bc/w1c-run1/home-w1c/logs/*"},"intent":"Locating netstream modules"},"id":"c3fcb4d5","parentId":"eb3ce2b4","timestamp":"2026-09-16T01:59:39.724Z"}
{"type":"message","id":"f6b1f913","parentId":"c3fcb4d5","timestamp":"2026-09-16T01:59:39.724Z","message":{"role":"assistant","content":[{"type":"toolCall","id":"call_56T9OjroFcXitoNcOOg1cL9M|fc_09b01b5279447709016aa9f80ba4c087d288f91b80be951b05","name":"read","arguments":{"i":"Reading attach pump setup","path":"crates/spt-daemon/src/attach.rs:367-584"},"intent":"Reading attach pump setup"},{"type":"toolCall","id":"call_qM8pEVQYJ2kXKZ9Oz4a6pdcl|fc_09b01b5279447709016aa9f80ba4cc87d2b51fcf8f3c8cc07f","name":"read","arguments":{"i":"Reading attach event handling","path":"crates/spt-daemon/src/attach.rs:610-785"},"intent":"Reading attach event handling"},{"type":"toolCall","id":"call_dm91GYv22iSQP1wk6vUSs96t|fc_09b01b5279447709016aa9f80ba4d487d28ceaf6e92822a191","name":"grep","arguments":{"i":"Locating brain stream methods","pattern":"fn (net_stream|send_effect|read_event|attach_as)|SharedSend|NetStreamData|net_cursors","path":"crates/spt-daemon/src/brain.rs","case":true,"gitignore":true,"skip":null},"intent":"Locating brain stream methods"},{"type":"toolCall","id":"call_A8y6Cpf2uzlYAJBoUzhDhOKS|fc_09b01b5279447709016aa9f80ba4dc87d2ae9f3d7910df6057","name":"glob","arguments":{"i":"Locating netstream modules","path":"crates/**/netstream*;crates/**/netstream/**/*;.spt/preserved/307/hertz-w1bc/w1c-run1/home-w1c/logs/*","hidden":true,"gitignore":false,"limit":40},"intent":"Locating netstream modules"}],"api":"openai-codex-responses","provider":"openai-codex","model":"gpt-6-astra","usage":{"input":10945,"output":229,"cacheRead":20224,"cacheWrite":0,"totalTokens":31398,"cost":{"input":0.10945,"output":0.01145,"cacheRead":0.020224,"cacheWrite":0,"total":0.141124}},"stopReason":"toolUse","timestamp":1789523968609,"responseId":"resp_09b01b5279447709016aa9f800d84487d29350df588a5dbe2f","providerPayload":{"type":"openaiResponsesHistory","provider":"openai-codex","dt":true,"items":[{"id":"fc_09b01b5279447709016aa9f80ba4c087d288f91b80be951b05","type":"function_call","status":"completed","arguments":"{\"i\":\"Reading attach pump setup\",\"path\":\"crates/spt-daemon/src/attach.rs:367-584\"}","call_id":"call_56T9OjroFcXitoNcOOg1cL9M","internal_chat_message_metadata_passthrough":{"turn_id":"a464097d-3a78-4a75-9ebb-a53f309aa685"},"name":"read","metadata":{"turn_id":"a464097d-3a78-4a75-9ebb-a53f309aa685"}},{"id":"fc_09b01b5279447709016aa9f80ba4cc87d2b51fcf8f3c8cc07f","type":"function_call","status":"completed","arguments":"{\"i\":\"Reading attach event handling\",\"path\":\"crates/spt-daemon/src/attach.rs:610-785\"}","call_id":"call_qM8pEVQYJ2kXKZ9Oz4a6pdcl","internal_chat_message_metadata_passthrough":{"turn_id":"a464097d-3a78-4a75-9ebb-a53f309aa685"},"name":"read","metadata":{"turn_id":"a464097d-3a78-4a75-9ebb-a53f309aa685"}},{"id":"fc_09b01b5279447709016aa9f80ba4d487d28ceaf6e92822a191","type":"function_call","status":"completed","arguments":"{\"i\":\"Locating brain stream methods\",\"pattern\":\"fn (net_stream|send_effect|read_event|attach_as)|SharedSend|NetStreamData|net_cursors\",\"path\":\"crates/spt-daemon/src/brain.rs\",\"case\":true,\"gitignore\":true,\"skip\":null}","call_id":"call_dm91GYv22iSQP1wk6vUSs96t","internal_chat_message_metadata_passthrough":{"turn_id":"a464097d-3a78-4a75-9ebb-a53f309aa685"},"name":"grep","metadata":{"turn_id":"a464097d-3a78-4a75-9ebb-a53f309aa685"}},{"id":"fc_09b01b5279447709016aa9f80ba4dc87d2ae9f3d7910df6057","type":"function_call","status":"completed","arguments":"{\"i\":\"Locating netstream modules\",\"path\":\"crates/**/netstream*;crates/**/netstream/**/*;.spt/preserved/307/hertz-w1bc/w1c-run1/home-w1c/logs/*\",\"hidden\":true,\"gitignore\":false,\"limit\":40}","call_id":"call_A8y6Cpf2uzlYAJBoUzhDhOKS","internal_chat_message_metadata_passthrough":{"turn_id":"a464097d-3a78-4a75-9ebb-a53f309aa685"},"name":"glob","metadata":{"turn_id":"a464097d-3a78-4a75-9ebb-a53f309aa685"}}]},"duration":11111.079700000118,"ttft":11069.753600000171,"completedAt":1789523979721,"contextSnapshot":{"promptTokens":31169,"nonMessageTokens":10480,"compactionEpoch":0}}}
{"type":"message","id":"79c7d02c","parentId":"f6b1f913","timestamp":"2026-09-16T01:59:39.729Z","message":{"role":"toolResult","toolCallId":"call_56T9OjroFcXitoNcOOg1cL9M|fc_09b01b5279447709016aa9f80ba4c087d288f91b80be951b05","toolName":"read","content":[{"type":"text","text":"#[allow(clippy::too_many_arguments)]\nfn handle_attach_request(\n    brain: &mut Brain,\n    wire: &mut Brain,\n    stream_id: u64,\n    endpoint: &str,\n    origin_node: &str,\n    remote_session: Option<u64>,\n    session_id: u64,\n    from_seq: u64,\n    req_intent: AttachIntent,\n    req_gen: u64,\n    req_code: Option<String>,\n    req_seal_ceremony: bool,\n    intent: &mut AttachIntent,\n    attached_session: &mut Option<u64>,\n    attached: &mut bool,\n    serve_gen: &mut u64,\n) -> io::Result<Option<AttachServeOutcome>> {\n    if access_check(\n        endpoint,\n        origin_node,\n        attach_surface(req_intent),\n        InboundClass::Unsolicited,\n    )\n    .is_deny()\n    {\n        wire.net_stream_send(stream_id, &[], None, true)?;\n        return Ok(Some(AttachServeOutcome::Refused));\n    }\n    let sid = remote_session.unwrap_or(session_id);\n    *intent = req_intent;\n    *attached_session = Some(sid);\n    // The DISPATCHED intent, read off the same binding the arms below branch on —\n    // the arm IS the decision, so logging `req_intent` here names it once for both\n    // arms rather than twice inside them. Wildcard-free: a new `AttachIntent`\n    // variant must fail to compile rather than log as one of today's three.\n    let intent_lbl = match req_intent {\n        AttachIntent::Viewer => \"viewer\",\n        AttachIntent::Control => \"control\",\n        AttachIntent::Take => \"take\",\n    };\n    // Daemon stderr sink, joinable to the broker's SUBSCRIBE_DECISION on `session`.\n    // ids/counters only — never PTY bytes, and never the bring-up code, which is a\n    // secret riding the same request.\n    spt_proto::emit_line_err!(\n        \"ATTACH_INTENT_CHOSEN: site=serve_dispatch session={sid} intent={intent_lbl} \\\n         from_seq={from_seq} gen={req_gen} coded={}\",\n        req_code.is_some()\n    );\n    if req_intent == AttachIntent::Viewer {\n        brain.attach_as_viewer_snap(sid, from_seq, Some(origin_node))?;\n    } else {\n        // The bring-up code rides the driving attach only: a viewer never takes\n        // controls, so there is nothing for a code to buy on that path.\n        // [impl->REQ-ER-BRINGUP-TOTP-GATE]\n        brain.attach_as_coded(\n            sid,\n            from_seq,\n            req_intent,\n            req_gen,\n            Some(origin_node),\n            req_code.as_deref(),\n            // The W2 seal-ceremony capability the CLIENT declared, recorded on\n            // the controller seat so a mint knows whether this viewport can\n            // host the overlay (REQ-SEAL-NO-CEREMONY-SURFACE).\n            req_seal_ceremony,\n        )?;\n        *serve_gen = req_gen;\n    }\n    *attached = true;\n    Ok(None)\n}\n\n/// Serve one attach stream against this brain's broker, blocking until the\n/// session exits, the operator detaches, or the gate refuses.\n///\n/// `origin_node` MUST be the handshake-proven remote id from the broker's\n/// stream table (`NetStreamInfo::remote_id_hex`) — never payload bytes\n/// (REQ-HAZARD-WAN-ORIGIN-AUTH). `endpoint` names the endpoint whose session\n/// is being attached, for the gate. `net_from_seq` is this brain's resume\n/// cursor on the attach stream (0 cold — also the safe post-restart choice:\n/// the replayed `Request`/`Input` records re-gate and dedup at the PTY\n/// journal, and re-pumped output dedups at the operator's render cursor).\n///\n/// `remote_session` is `Some(sid)` ONLY on the cross-node leg (#4,\n/// REQ-RC-CROSS-NODE-ATTACH): the dispatcher has ALREADY resolved endpoint→our\n/// session id ([`resolve_local_session`]) BEFORE this serve loop subscribed, so\n/// the wire's placeholder `session_id` (0) is overridden here with the resolved\n/// id. It is passed down — never re-queried mid-loop — because a `sessions()`\n/// round-trip inside the event loop would swallow interleaved attach records\n/// (`Input`/`Subscribed`) the loop must see. `None` = the local path, which uses\n/// the wire `session_id`.\n///\n/// `seed_request` is the broker-pinned opener Request (ADR-0038 B): after the\n/// bounded ring rolls, the wire replay no longer carries the stream's Request\n/// record — a reconstruction that waited for one would idle forever. The\n/// dispatcher hands the durable opener here and it is handled EXACTLY like a\n/// wire-arriving Request (same gate, same subscribe); a Request that then\n/// replays from the ring anyway re-runs the same-identity re-take, which is\n/// silent and idempotent (the successor-re-take parity the fix must keep).\n// [impl->REQ-INST-8]\n// [impl->REQ-HAZARD-WAN-ORIGIN-AUTH]\n// [impl->REQ-HAZARD-ENDPOINT-RUN-ATTACH-OUTPUT]\n// [impl->REQ-RC-CROSS-NODE-ATTACH]\n// [impl->REQ-STREAM-OPENER-DURABLE]\n#[allow(clippy::too_many_arguments)]\npub fn serve_attach(\n    brain: &mut Brain,\n    broker_name: &str,\n    stream_id: u64,\n    endpoint: &str,\n    origin_node: &str,\n    net_from_seq: u64,\n    remote_session: Option<u64>,\n    seed_request: Option<AttachRecord>,\n) -> io::Result<AttachServeOutcome> {\n    brain.net_stream_subscribe(stream_id, net_from_seq)?;\n    // TWO-CONN SPLIT (REQ-HAZARD-ENDPOINT-RUN-ATTACH-OUTPUT): the wire FORWARDS\n    // (session Output / Size / Exit / Displaced / detach-finish onto the operator\n    // stream) ride a SEPARATE broker connection from `brain`. `brain` RECEIVES\n    // session output (broker→serve) — including the controller's synchronous,\n    // inline, multi-frame ring replay (`become_controller`), which holds the\n    // broker's single-threaded per-conn handler for the whole replay. If the\n    // forwards rode `brain` too, that stuck handler could not read them →\n    // serve→broker backs up while broker→serve replay backs up → mutual IPC\n    // backpressure DEADLOCK, and the operator receives ZERO bytes (the bug: an\n    // attach to an ALREADY-PRODUCING endpoint-run harness, non-empty ring). The\n    // two directions on independent single-threaded handlers cannot block each\n    // other. `send_stream` is stream_id-keyed (conn-agnostic), so forwarding from\n    // a second conn is correct. Order is preserved: this one serve thread reads\n    // every Output in seq order on `brain` and forwards it in that same order on\n    // `wire`. (DEEPER ROOT, post-v0.12.1 follow-up: the CONTROLLER replay is a\n    // SYNCHRONOUS inline write, while VIEWERS use the async dedicated-writer-\n    // thread + bounded-channel pattern (`add_viewer`/`viewer_writer`); unifying\n    // the controller onto that async path would remove the inline-replay block at\n    // the source, but it touches the authoritative cursor-advancing path.)\n    let mut wire = Brain::cold_start(broker_name, now_ms())?;\n    let mut decoder = AttachDecoder::new();\n    let mut attached = false;\n    // The Request's intent — gates wire input (a viewer's keystrokes never reach\n    // the PTY) independent of the broker's later role reply (no IPC-ordering\n    // race on the input gate).\n    let mut intent = AttachIntent::Control;\n    // The broker-confirmed role (arrives as `Subscribed`). `None` until then:\n    // controller input that races ahead of the reply is BUFFERED, not dropped\n    // (the replayed-input-after-restart case) and not leaked to the PTY before\n    // we know we control the session (the busy-refuse case).\n    let mut role: Option<ServeRole> = None;\n    let mut pending_input: Vec<(u64, Vec<u8>)> = Vec::new();\n    // The attached session — captured from the Request so the terminal paths can\n    // explicitly release this worker's role (clearing driven_by / viewer_count\n    // promptly, not only on connection drop).\n    let mut attached_session: Option<u64> = None;\n    // This worker's attach GENERATION (ADR-0038 Amendment fix 6) — set when\n    // its Request lands; every terminal release carries it so a STALE worker\n    // (an older generation) can never clear a replacement controller.\n    let mut serve_gen: u64 = 0;\n    // Recovered from the pinned Request, not from the serving daemon's version.\n    // [impl->REQ-ATTACH-CLIENT-STALE]\n    let mut client_identity = None;\n    // Last skip-to-live re-subscribe (REQ-VIEWER-SKIP-TO-LIVE-ON-EVICT): bounds the\n    // evict→resubscribe rate so a hopelessly-behind viewer under flood sees\n    // intermittent live bursts, never a CPU spin.\n    let mut last_resubscribe: Option<Instant> = None;\n\n    // Durable-opener seed (ADR-0038 B): process the dispatcher-pinned Request\n    // BEFORE the event loop, through the exact wire-Request path — a rolled\n    // ring can no longer replay it. Non-Request seeds are ignored (the opener\n    // of an attach stream is always its Request).\n    if let Some(AttachRecord::Request {\n        session_id,\n        from_seq,\n        intent: req_intent,\n        endpoint_id: _,\n        gen: req_gen,\n        code: req_code,\n        seal_ceremony: req_seal_ceremony,\n        client,\n    }) = seed_request\n    {\n        if let Some(out) = handle_attach_request(\n            brain,\n            &mut wire,\n            stream_id,\n            endpoint,\n            origin_node,\n            remote_session,\n            session_id,\n            from_seq,\n            req_intent,\n            req_gen,\n            req_code,\n            req_seal_ceremony,\n            &mut intent,\n            &mut attached_session,\n            &mut attached,\n            &mut serve_gen,\n        )? {\n            return Ok(out);\n        }\n        client_identity = client;\n    }\n\n    // [impl->REQ-BRAIN-READ-BOUNDED-PER-CALL]\n    // Stream lifetime is subscriber-owned; any silence bound belongs per read, not per call.\n    let deadline: Option<Instant> = None;\n    loop {\n        // The CONTROLLER resumes-from-floor on a b4 drop-don't-block output-gap\n        // (RE-FETCH from delivered_through, NOT snap — B2: a controller is\n        // authoritative). A VIEWER never reaches the reject-gap (its serve-brain is\n        // snap-above armed at attach, REQ-HAZARD-VIEWER-RING-ROLL-SNAP). Before a\n        // role resolves no Output flows, so a plain read is correct then.\n        // [impl->REQ-HAZARD-CONTROLLER-GAP-RESUME]\n        let event = match (role, attached_session) {\n            (Some(ServeRole::Controller), Some(sid)) => {\n                match read_controller_event_resuming(brain, sid, serve_gen, Some(origin_node)) {\n                    Ok(ev) => ev,\n                    Err(e)\n                        if e.get_ref()\n                            .is_some_and(|inner| inner.is::<ControllerIrrecoverablyBehind>()) =>\n                    {\n…\n                    }\n…\n                }\n            }\n…\n        };\n…\n    }\n}\n\n[Showing lines 366-587 of 1159. Use :588 to continue]"}],"details":{"truncation":{"content":"#[allow(clippy::too_many_arguments)]\r\nfn handle_attach_request(\r\n    brain: &mut Brain,\r\n    wire: &mut Brain,\r\n    stream_id: u64,\r\n    endpoint: &str,\r\n    origin_node: &str,\r\n    remote_session: Option<u64>,\r\n    session_id: u64,\r\n    from_seq: u64,\r\n    req_intent: AttachIntent,\r\n    req_gen: u64,\r\n    req_code: Option<String>,\r\n    req_seal_ceremony: bool,\r\n    intent: &mut AttachIntent,\r\n    attached_session: &mut Option<u64>,\r\n    attached: &mut bool,\r\n    serve_gen: &mut u64,\r\n) -> io::Result<Option<AttachServeOutcome>> {\r\n    if access_check(\r\n        endpoint,\r\n        origin_node,\r\n        attach_surface(req_intent),\r\n        InboundClass::Unsolicited,\r\n    )\r\n    .is_deny()\r\n    {\r\n        wire.net_stream_send(stream_id, &[], None, true)?;\r\n        return Ok(Some(AttachServeOutcome::Refused));\r\n    }\r\n    let sid = remote_session.unwrap_or(session_id);\r\n    *intent = req_intent;\r\n    *attached_session = Some(sid);\r\n    // The DISPATCHED intent, read off the same binding the arms below branch on —\r\n    // the arm IS the decision, so logging `req_intent` here names it once for both\r\n    // arms rather than twice inside them. Wildcard-free: a new `AttachIntent`\r\n    // variant must fail to compile rather than log as one of today's three.\r\n    let intent_lbl = match req_intent {\r\n        AttachIntent::Viewer => \"viewer\",\r\n        AttachIntent::Control => \"control\",\r\n        AttachIntent::Take => \"take\",\r\n    };\r\n    // Daemon stderr sink, joinable to the broker's SUBSCRIBE_DECISION on `session`.\r\n    // ids/counters only — never PTY bytes, and never the bring-up code, which is a\r\n    // secret riding the same request.\r\n    spt_proto::emit_line_err!(\r\n        \"ATTACH_INTENT_CHOSEN: site=serve_dispatch session={sid} intent={intent_lbl} \\\r\n         from_seq={from_seq} gen={req_gen} coded={}\",\r\n        req_code.is_some()\r\n    );\r\n    if req_intent == AttachIntent::Viewer {\r\n        brain.attach_as_viewer_snap(sid, from_seq, Some(origin_node))?;\r\n    } else {\r\n        // The bring-up code rides the driving attach only: a viewer never takes\r\n        // controls, so there is nothing for a code to buy on that path.\r\n        // [impl->REQ-ER-BRINGUP-TOTP-GATE]\r\n        brain.attach_as_coded(\r\n            sid,\r\n            from_seq,\r\n            req_intent,\r\n            req_gen,\r\n            Some(origin_node),\r\n            req_code.as_deref(),\r\n            // The W2 seal-ceremony capability the CLIENT declared, recorded on\r\n            // the controller seat so a mint knows whether this viewport can\r\n            // host the overlay (REQ-SEAL-NO-CEREMONY-SURFACE).\r\n            req_seal_ceremony,\r\n        )?;\r\n        *serve_gen = req_gen;\r\n    }\r\n    *attached = true;\r\n    Ok(None)\r\n}\r\n\r\n/// Serve one attach stream against this brain's broker, blocking until the\r\n/// session exits, the operator detaches, or the gate refuses.\r\n///\r\n/// `origin_node` MUST be the handshake-proven remote id from the broker's\r\n/// stream table (`NetStreamInfo::remote_id_hex`) — never payload bytes\r\n/// (REQ-HAZARD-WAN-ORIGIN-AUTH). `endpoint` names the endpoint whose session\r\n/// is being attached, for the gate. `net_from_seq` is this brain's resume\r\n/// cursor on the attach stream (0 cold — also the safe post-restart choice:\r\n/// the replayed `Request`/`Input` records re-gate and dedup at the PTY\r\n/// journal, and re-pumped output dedups at the operator's render cursor).\r\n///\r\n/// `remote_session` is `Some(sid)` ONLY on the cross-node leg (#4,\r\n/// REQ-RC-CROSS-NODE-ATTACH): the dispatcher has ALREADY resolved endpoint→our\r\n/// session id ([`resolve_local_session`]) BEFORE this serve loop subscribed, so\r\n/// the wire's placeholder `session_id` (0) is overridden here with the resolved\r\n/// id. It is passed down — never re-queried mid-loop — because a `sessions()`\r\n/// round-trip inside the event loop would swallow interleaved attach records\r\n/// (`Input`/`Subscribed`) the loop must see. `None` = the local path, which uses\r\n/// the wire `session_id`.\r\n///\r\n/// `seed_request` is the broker-pinned opener Request (ADR-0038 B): after the\r\n/// bounded ring rolls, the wire replay no longer carries the stream's Request\r\n/// record — a reconstruction that waited for one would idle forever. The\r\n/// dispatcher hands the durable opener here and it is handled EXACTLY like a\r\n/// wire-arriving Request (same gate, same subscribe); a Request that then\r\n/// replays from the ring anyway re-runs the same-identity re-take, which is\r\n/// silent and idempotent (the successor-re-take parity the fix must keep).\r\n// [impl->REQ-INST-8]\r\n// [impl->REQ-HAZARD-WAN-ORIGIN-AUTH]\r\n// [impl->REQ-HAZARD-ENDPOINT-RUN-ATTACH-OUTPUT]\r\n// [impl->REQ-RC-CROSS-NODE-ATTACH]\r\n// [impl->REQ-STREAM-OPENER-DURABLE]\r\n#[allow(clippy::too_many_arguments)]\r\npub fn serve_attach(\r\n    brain: &mut Brain,\r\n    broker_name: &str,\r\n    stream_id: u64,\r\n    endpoint: &str,\r\n    origin_node: &str,\r\n    net_from_seq: u64,\r\n    remote_session: Option<u64>,\r\n    seed_request: Option<AttachRecord>,\r\n) -> io::Result<AttachServeOutcome> {\r\n    brain.net_stream_subscribe(stream_id, net_from_seq)?;\r\n    // TWO-CONN SPLIT (REQ-HAZARD-ENDPOINT-RUN-ATTACH-OUTPUT): the wire FORWARDS\r\n    // (session Output / Size / Exit / Displaced / detach-finish onto the operator\r\n    // stream) ride a SEPARATE broker connection from `brain`. `brain` RECEIVES\r\n    // session output (broker→serve) — including the controller's synchronous,\r\n    // inline, multi-frame ring replay (`become_controller`), which holds the\r\n    // broker's single-threaded per-conn handler for the whole replay. If the\r\n    // forwards rode `brain` too, that stuck handler could not read them →\r\n    // serve→broker backs up while broker→serve replay backs up → mutual IPC\r\n    // backpressure DEADLOCK, and the operator receives ZERO bytes (the bug: an\r\n    // attach to an ALREADY-PRODUCING endpoint-run harness, non-empty ring). The\r\n    // two directions on independent single-threaded handlers cannot block each\r\n    // other. `send_stream` is stream_id-keyed (conn-agnostic), so forwarding from\r\n    // a second conn is correct. Order is preserved: this one serve thread reads\r\n    // every Output in seq order on `brain` and forwards it in that same order on\r\n    // `wire`. (DEEPER ROOT, post-v0.12.1 follow-up: the CONTROLLER replay is a\r\n    // SYNCHRONOUS inline write, while VIEWERS use the async dedicated-writer-\r\n    // thread + bounded-channel pattern (`add_viewer`/`viewer_writer`); unifying\r\n    // the controller onto that async path would remove the inline-replay block at\r\n    // the source, but it touches the authoritative cursor-advancing path.)\r\n    let mut wire = Brain::cold_start(broker_name, now_ms())?;\r\n    let mut decoder = AttachDecoder::new();\r\n    let mut attached = false;\r\n    // The Request's intent — gates wire input (a viewer's keystrokes never reach\r\n    // the PTY) independent of the broker's later role reply (no IPC-ordering\r\n    // race on the input gate).\r\n    let mut intent = AttachIntent::Control;\r\n    // The broker-confirmed role (arrives as `Subscribed`). `None` until then:\r\n    // controller input that races ahead of the reply is BUFFERED, not dropped\r\n    // (the replayed-input-after-restart case) and not leaked to the PTY before\r\n    // we know we control the session (the busy-refuse case).\r\n    let mut role: Option<ServeRole> = None;\r\n    let mut pending_input: Vec<(u64, Vec<u8>)> = Vec::new();\r\n    // The attached session — captured from the Request so the terminal paths can\r\n    // explicitly release this worker's role (clearing driven_by / viewer_count\r\n    // promptly, not only on connection drop).\r\n    let mut attached_session: Option<u64> = None;\r\n    // This worker's attach GENERATION (ADR-0038 Amendment fix 6) — set when\r\n    // its Request lands; every terminal release carries it so a STALE worker\r\n    // (an older generation) can never clear a replacement controller.\r\n    let mut serve_gen: u64 = 0;\r\n    // Recovered from the pinned Request, not from the serving daemon's version.\r\n    // [impl->REQ-ATTACH-CLIENT-STALE]\r\n    let mut client_identity = None;\r\n    // Last skip-to-live re-subscribe (REQ-VIEWER-SKIP-TO-LIVE-ON-EVICT): bounds the\r\n    // evict→resubscribe rate so a hopelessly-behind viewer under flood sees\r\n    // intermittent live bursts, never a CPU spin.\r\n    let mut last_resubscribe: Option<Instant> = None;\r\n\r\n    // Durable-opener seed (ADR-0038 B): process the dispatcher-pinned Request\r\n    // BEFORE the event loop, through the exact wire-Request path — a rolled\r\n    // ring can no longer replay it. Non-Request seeds are ignored (the opener\r\n    // of an attach stream is always its Request).\r\n    if let Some(AttachRecord::Request {\r\n        session_id,\r\n        from_seq,\r\n        intent: req_intent,\r\n        endpoint_id: _,\r\n        gen: req_gen,\r\n        code: req_code,\r\n        seal_ceremony: req_seal_ceremony,\r\n        client,\r\n    }) = seed_request\r\n    {\r\n        if let Some(out) = handle_attach_request(\r\n            brain,\r\n            &mut wire,\r\n            stream_id,\r\n            endpoint,\r\n            origin_node,\r\n            remote_session,\r\n            session_id,\r\n            from_seq,\r\n            req_intent,\r\n            req_gen,\r\n            req_code,\r\n            req_seal_ceremony,\r\n            &mut intent,\r\n            &mut attached_session,\r\n            &mut attached,\r\n            &mut serve_gen,\r\n        )? {\r\n            return Ok(out);\r\n        }\r\n        client_identity = client;\r\n    }\r\n\r\n    // [impl->REQ-BRAIN-READ-BOUNDED-PER-CALL]\r\n    // Stream lifetime is subscriber-owned; any silence bound belongs per read, not per call.\r\n    let deadline: Option<Instant> = None;\r\n    loop {\r\n        // The CONTROLLER resumes-from-floor on a b4 drop-don't-block output-gap\r\n        // (RE-FETCH from delivered_through, NOT snap — B2: a controller is\r\n        // authoritative). A VIEWER never reaches the reject-gap (its serve-brain is\r\n        // snap-above armed at attach, REQ-HAZARD-VIEWER-RING-ROLL-SNAP). Before a\r\n        // role resolves no Output flows, so a plain read is correct then.\r\n        // [impl->REQ-HAZARD-CONTROLLER-GAP-RESUME]\r\n        let event = match (role, attached_session) {\r\n            (Some(ServeRole::Controller), Some(sid)) => {\r\n                match read_controller_event_resuming(brain, sid, serve_gen, Some(origin_node)) {\r\n                    Ok(ev) => ev,\r\n                    Err(e)\r\n                        if e.get_ref()\r\n                            .is_some_and(|inner| inner.is::<ControllerIrrecoverablyBehind>()) =>\r\n                    {\r","truncated":true,"truncatedBy":"lines","totalLines":794,"totalBytes":10648,"outputLines":222,"outputBytes":10648,"lastLinePartial":false,"firstLineExceedsLimit":false},"totalLines":1159,"displayContent":{"text":"#[allow(clippy::too_many_arguments)]\r\nfn handle_attach_request(\r\n    brain: &mut Brain,\r\n    wire: &mut Brain,\r\n    stream_id: u64,\r\n    endpoint: &str,\r\n    origin_node: &str,\r\n    remote_session: Option<u64>,\r\n    session_id: u64,\r\n    from_seq: u64,\r\n    req_intent: AttachIntent,\r\n    req_gen: u64,\r\n    req_code: Option<String>,\r\n    req_seal_ceremony: bool,\r\n    intent: &mut AttachIntent,\r\n    attached_session: &mut Option<u64>,\r\n    attached: &mut bool,\r\n    serve_gen: &mut u64,\r\n) -> io::Result<Option<AttachServeOutcome>> {\r\n    if access_check(\r\n        endpoint,\r\n        origin_node,\r\n        attach_surface(req_intent),\r\n        InboundClass::Unsolicited,\r\n    )\r\n    .is_deny()\r\n    {\r\n        wire.net_stream_send(stream_id, &[], None, true)?;\r\n        return Ok(Some(AttachServeOutcome::Refused));\r\n    }\r\n    let sid = remote_session.unwrap_or(session_id);\r\n    *intent = req_intent;\r\n    *attached_session = Some(sid);\r\n    // The DISPATCHED intent, read off the same binding the arms below branch on —\r\n    // the arm IS the decision, so logging `req_intent` here names it once for both\r\n    // arms rather than twice inside them. Wildcard-free: a new `AttachIntent`\r\n    // variant must fail to compile rather than log as one of today's three.\r\n    let intent_lbl = match req_intent {\r\n        AttachIntent::Viewer => \"viewer\",\r\n        AttachIntent::Control => \"control\",\r\n        AttachIntent::Take => \"take\",\r\n    };\r\n    // Daemon stderr sink, joinable to the broker's SUBSCRIBE_DECISION on `session`.\r\n    // ids/counters only — never PTY bytes, and never the bring-up code, which is a\r\n    // secret riding the same request.\r\n    spt_proto::emit_line_err!(\r\n        \"ATTACH_INTENT_CHOSEN: site=serve_dispatch session={sid} intent={intent_lbl} \\\r\n         from_seq={from_seq} gen={req_gen} coded={}\",\r\n        req_code.is_some()\r\n    );\r\n    if req_intent == AttachIntent::Viewer {\r\n        brain.attach_as_viewer_snap(sid, from_seq, Some(origin_node))?;\r\n    } else {\r\n        // The bring-up code rides the driving attach only: a viewer never takes\r\n        // controls, so there is nothing for a code to buy on that path.\r\n        // [impl->REQ-ER-BRINGUP-TOTP-GATE]\r\n        brain.attach_as_coded(\r\n            sid,\r\n            from_seq,\r\n            req_intent,\r\n            req_gen,\r\n            Some(origin_node),\r\n            req_code.as_deref(),\r\n            // The W2 seal-ceremony capability the CLIENT declared, recorded on\r\n            // the controller seat so a mint knows whether this viewport can\r\n            // host the overlay (REQ-SEAL-NO-CEREMONY-SURFACE).\r\n            req_seal_ceremony,\r\n        )?;\r\n        *serve_gen = req_gen;\r\n    }\r\n    *attached = true;\r\n    Ok(None)\r\n}\r\n\r\n/// Serve one attach stream against this brain's broker, blocking until the\r\n/// session exits, the operator detaches, or the gate refuses.\r\n///\r\n/// `origin_node` MUST be the handshake-proven remote id from the broker's\r\n/// stream table (`NetStreamInfo::remote_id_hex`) — never payload bytes\r\n/// (REQ-HAZARD-WAN-ORIGIN-AUTH). `endpoint` names the endpoint whose session\r\n/// is being attached, for the gate. `net_from_seq` is this brain's resume\r\n/// cursor on the attach stream (0 cold — also the safe post-restart choice:\r\n/// the replayed `Request`/`Input` records re-gate and dedup at the PTY\r\n/// journal, and re-pumped output dedups at the operator's render cursor).\r\n///\r\n/// `remote_session` is `Some(sid)` ONLY on the cross-node leg (#4,\r\n/// REQ-RC-CROSS-NODE-ATTACH): the dispatcher has ALREADY resolved endpoint→our\r\n/// session id ([`resolve_local_session`]) BEFORE this serve loop subscribed, so\r\n/// the wire's placeholder `session_id` (0) is overridden here with the resolved\r\n/// id. It is passed down — never re-queried mid-loop — because a `sessions()`\r\n/// round-trip inside the event loop would swallow interleaved attach records\r\n/// (`Input`/`Subscribed`) the loop must see. `None` = the local path, which uses\r\n/// the wire `session_id`.\r\n///\r\n/// `seed_request` is the broker-pinned opener Request (ADR-0038 B): after the\r\n/// bounded ring rolls, the wire replay no longer carries the stream's Request\r\n/// record — a reconstruction that waited for one would idle forever. The\r\n/// dispatcher hands the durable opener here and it is handled EXACTLY like a\r\n/// wire-arriving Request (same gate, same subscribe); a Request that then\r\n/// replays from the ring anyway re-runs the same-identity re-take, which is\r\n/// silent and idempotent (the successor-re-take parity the fix must keep).\r\n// [impl->REQ-INST-8]\r\n// [impl->REQ-HAZARD-WAN-ORIGIN-AUTH]\r\n// [impl->REQ-HAZARD-ENDPOINT-RUN-ATTACH-OUTPUT]\r\n// [impl->REQ-RC-CROSS-NODE-ATTACH]\r\n// [impl->REQ-STREAM-OPENER-DURABLE]\r\n#[allow(clippy::too_many_arguments)]\r\npub fn serve_attach(\r\n    brain: &mut Brain,\r\n    broker_name: &str,\r\n    stream_id: u64,\r\n    endpoint: &str,\r\n    origin_node: &str,\r\n    net_from_seq: u64,\r\n    remote_session: Option<u64>,\r\n    seed_request: Option<AttachRecord>,\r\n) -> io::Result<AttachServeOutcome> {\r\n    brain.net_stream_subscribe(stream_id, net_from_seq)?;\r\n    // TWO-CONN SPLIT (REQ-HAZARD-ENDPOINT-RUN-ATTACH-OUTPUT): the wire FORWARDS\r\n    // (session Output / Size / Exit / Displaced / detach-finish onto the operator\r\n    // stream) ride a SEPARATE broker connection from `brain`. `brain` RECEIVES\r\n    // session output (broker→serve) — including the controller's synchronous,\r\n    // inline, multi-frame ring replay (`become_controller`), which holds the\r\n    // broker's single-threaded per-conn handler for the whole replay. If the\r\n    // forwards rode `brain` too, that stuck handler could not read them →\r\n    // serve→broker backs up while broker→serve replay backs up → mutual IPC\r\n    // backpressure DEADLOCK, and the operator receives ZERO bytes (the bug: an\r\n    // attach to an ALREADY-PRODUCING endpoint-run harness, non-empty ring). The\r\n    // two directions on independent single-threaded handlers cannot block each\r\n    // other. `send_stream` is stream_id-keyed (conn-agnostic), so forwarding from\r\n    // a second conn is correct. Order is preserved: this one serve thread reads\r\n    // every Output in seq order on `brain` and forwards it in that same order on\r\n    // `wire`. (DEEPER ROOT, post-v0.12.1 follow-up: the CONTROLLER replay is a\r\n    // SYNCHRONOUS inline write, while VIEWERS use the async dedicated-writer-\r\n    // thread + bounded-channel pattern (`add_viewer`/`viewer_writer`); unifying\r\n    // the controller onto that async path would remove the inline-replay block at\r\n    // the source, but it touches the authoritative cursor-advancing path.)\r\n    let mut wire = Brain::cold_start(broker_name, now_ms())?;\r\n    let mut decoder = AttachDecoder::new();\r\n    let mut attached = false;\r\n    // The Request's intent — gates wire input (a viewer's keystrokes never reach\r\n    // the PTY) independent of the broker's later role reply (no IPC-ordering\r\n    // race on the input gate).\r\n    let mut intent = AttachIntent::Control;\r\n    // The broker-confirmed role (arrives as `Subscribed`). `None` until then:\r\n    // controller input that races ahead of the reply is BUFFERED, not dropped\r\n    // (the replayed-input-after-restart case) and not leaked to the PTY before\r\n    // we know we control the session (the busy-refuse case).\r\n    let mut role: Option<ServeRole> = None;\r\n    let mut pending_input: Vec<(u64, Vec<u8>)> = Vec::new();\r\n    // The attached session — captured from the Request so the terminal paths can\r\n    // explicitly release this worker's role (clearing driven_by / viewer_count\r\n    // promptly, not only on connection drop).\r\n    let mut attached_session: Option<u64> = None;\r\n    // This worker's attach GENERATION (ADR-0038 Amendment fix 6) — set when\r\n    // its Request lands; every terminal release carries it so a STALE worker\r\n    // (an older generation) can never clear a replacement controller.\r\n    let mut serve_gen: u64 = 0;\r\n    // Recovered from the pinned Request, not from the serving daemon's version.\r\n    // [impl->REQ-ATTACH-CLIENT-STALE]\r\n    let mut client_identity = None;\r\n    // Last skip-to-live re-subscribe (REQ-VIEWER-SKIP-TO-LIVE-ON-EVICT): bounds the\r\n    // evict→resubscribe rate so a hopelessly-behind viewer under flood sees\r\n    // intermittent live bursts, never a CPU spin.\r\n    let mut last_resubscribe: Option<Instant> = None;\r\n\r\n    // Durable-opener seed (ADR-0038 B): process the dispatcher-pinned Request\r\n    // BEFORE the event loop, through the exact wire-Request path — a rolled\r\n    // ring can no longer replay it. Non-Request seeds are ignored (the opener\r\n    // of an attach stream is always its Request).\r\n    if let Some(AttachRecord::Request {\r\n        session_id,\r\n        from_seq,\r\n        intent: req_intent,\r\n        endpoint_id: _,\r\n        gen: req_gen,\r\n        code: req_code,\r\n        seal_ceremony: req_seal_ceremony,\r\n        client,\r\n    }) = seed_request\r\n    {\r\n        if let Some(out) = handle_attach_request(\r\n            brain,\r\n            &mut wire,\r\n            stream_id,\r\n            endpoint,\r\n            origin_node,\r\n            remote_session,\r\n            session_id,\r\n            from_seq,\r\n            req_intent,\r\n            req_gen,\r\n            req_code,\r\n            req_seal_ceremony,\r\n            &mut intent,\r\n            &mut attached_session,\r\n            &mut attached,\r\n            &mut serve_gen,\r\n        )? {\r\n            return Ok(out);\r\n        }\r\n        client_identity = client;\r\n    }\r\n\r\n    // [impl->REQ-BRAIN-READ-BOUNDED-PER-CALL]\r\n    // Stream lifetime is subscriber-owned; any silence bound belongs per read, not per call.\r\n    let deadline: Option<Instant> = None;\r\n    loop {\r\n        // The CONTROLLER resumes-from-floor on a b4 drop-don't-block output-gap\r\n        // (RE-FETCH from delivered_through, NOT snap — B2: a controller is\r\n        // authoritative). A VIEWER never reaches the reject-gap (its serve-brain is\r\n        // snap-above armed at attach, REQ-HAZARD-VIEWER-RING-ROLL-SNAP). Before a\r\n        // role resolves no Output flows, so a plain read is correct then.\r\n        // [impl->REQ-HAZARD-CONTROLLER-GAP-RESUME]\r\n        let event = match (role, attached_session) {\r\n            (Some(ServeRole::Controller), Some(sid)) => {\r\n                match read_controller_event_resuming(brain, sid, serve_gen, Some(origin_node)) {\r\n                    Ok(ev) => ev,\r\n                    Err(e)\r\n                        if e.get_ref()\r\n                            .is_some_and(|inner| inner.is::<ControllerIrrecoverablyBehind>()) =>\r\n                    {\r\n…\n                    }\n…\n                }\n            }\n…\n        };\n…\n    }\n}","startLine":366,"lineNumbers":[366,367,368,369,370,371,372,373,374,375,376,377,378,379,380,381,382,383,384,385,386,387,388,389,390,391,392,393,394,395,396,397,398,399,400,401,402,403,404,405,406,407,408,409,410,411,412,413,414,415,416,417,418,419,420,421,422,423,424,425,426,427,428,429,430,431,432,433,434,435,436,437,438,439,440,441,442,443,444,445,446,447,448,449,450,451,452,453,454,455,456,457,458,459,460,461,462,463,464,465,466,467,468,469,470,471,472,473,474,475,476,477,478,479,480,481,482,483,484,485,486,487,488,489,490,491,492,493,494,495,496,497,498,499,500,501,502,503,504,505,506,507,508,509,510,511,512,513,514,515,516,517,518,519,520,521,522,523,524,525,526,527,528,529,530,531,532,533,534,535,536,537,538,539,540,541,542,543,544,545,546,547,548,549,550,551,552,553,554,555,556,557,558,559,560,561,562,563,564,565,566,567,568,569,570,571,572,573,574,575,576,577,578,579,580,581,582,583,584,585,586,587,null,602,null,607,608,null,610,null,919,920]},"fileSize":57673,"meta":{"source":{"type":"path","value":"C:\\Users\\decid\\Documents\\projects\\spt-core\\crates\\spt-daemon\\src\\attach.rs"},"truncation":{"direction":"head","truncatedBy":"lines","totalLines":1159,"totalBytes":10648,"outputLines":222,"outputBytes":10648,"shownRange":{"start":366,"end":587},"nextOffset":588}}},"isError":false,"timestamp":1789523979728}}
{"type":"message","id":"99872648","parentId":"79c7d02c","timestamp":"2026-09-16T01:59:39.731Z","message":{"role":"toolResult","toolCallId":"call_qM8pEVQYJ2kXKZ9Oz4a6pdcl|fc_09b01b5279447709016aa9f80ba4cc87d2b51fcf8f3c8cc07f","toolName":"read","content":[{"type":"text","text":"        let event = match (role, attached_session) {\n…\n            _ => brain.read_event_until(deadline)?,\n        };\n        match event {\n            // ── Wire → session: requests, input, resize. ───────────────────\n            BrokerEvent::NetStreamData {\n                stream_id: sid,\n                bytes,\n                ..\n            } if sid == stream_id => {\n                for rec in decoder.push(&bytes) {\n                    match rec {\n                        AttachRecord::Request {\n                            session_id,\n                            from_seq,\n                            intent: req_intent,\n                            // The dispatcher already resolved endpoint_id→session\n                            // (passed as remote_session) BEFORE this loop; ignore\n                            // the wire copy here (a mid-loop re-resolve would swallow\n                            // interleaved attach records — see remote_session docs).\n                            endpoint_id: _,\n                            gen: req_gen,\n                            code: req_code,\n                            seal_ceremony: req_seal_ceremony,\n                            client,\n                        } => {\n                            if let Some(out) = handle_attach_request(\n                                brain,\n                                &mut wire,\n                                stream_id,\n                                endpoint,\n                                origin_node,\n                                remote_session,\n                                session_id,\n                                from_seq,\n                                req_intent,\n                                req_gen,\n                                req_code,\n                                req_seal_ceremony,\n                                &mut intent,\n                                &mut attached_session,\n                                &mut attached,\n                                &mut serve_gen,\n                            )? {\n                                return Ok(out);\n                            }\n                            client_identity = client;\n                        }\n                        AttachRecord::Input { data_b64, op_id }\n                            if attached && intent != AttachIntent::Viewer =>\n                        {\n                            let bytes = decode_bytes(&data_b64)\n                                .map_err(|e| io::Error::new(io::ErrorKind::InvalidData, e))?;\n                            match role {\n                                // Confirmed controller — exactly-once at the PTY\n                                // (the operator-minted id rides the B5 journal). NO-ACK\n                                // (REQ-HAZARD-INPUT-ACK-BACKPRESSURE): this path is\n                                // fire-and-forward (the ack is discarded here) and can\n                                // flood N input frames on this one conn; an acked write\n                                // back would fill the return direction and deadlock the\n                                // broker's per-conn handler. Dedup still holds at the\n                                // broker (op_id applied-set).\n                                // [impl->REQ-HAZARD-INPUT-ACK-BACKPRESSURE]\n                                Some(ServeRole::Controller) => {\n                                    // The op_id is operator-minted (rc attach OpMinter),\n                                    // so it carries the `rc` journal tag (ADR-0034).\n                                    brain.send_effect_no_ack(\n                                        MintedOp::new(Minter::Rc, op_id),\n                                        &bytes,\n                                    )?\n                                }\n                                // Outcome not yet known — buffer; flushed on a\n                                // controller confirmation, discarded on busy/viewer.\n                                None => pending_input.push((op_id, bytes)),\n                                // A viewer never reaches here (intent gate).\n                                Some(ServeRole::Viewer) => {}\n                            }\n                        }\n                        AttachRecord::Resize { rows, cols }\n                            if attached && intent != AttachIntent::Viewer =>\n                        {\n                            // Controller → PTY resize (controller-EXCLUSIVE; the\n                            // broker rejects it on a viewer's stream). A viewer's\n                            // Resize is dropped here by the intent gate too.\n                            let _ = brain.resize(rows, cols);\n                        }\n                        // The ceremony presentation from the controller's\n                        // overlay (WAX-SEAL W2): the PRESENTED CODE, never a\n                        // verdict — forwarded to the broker, which decides\n                        // everything. Controller-only (the intent gate): a\n                        // viewer has no overlay to answer from.\n                        // [impl->REQ-SEAL-CEREMONY-RC-CLIENT]\n                        AttachRecord::SealCeremonyCode {\n                            ceremony_id,\n                            code,\n                            signature_hex,\n                            enroll_pubkey_hex,\n                            enroll_backend_kind,\n                        } if attached && intent != AttachIntent::Viewer => {\n                            // The SIGNET W2 additive fields — a FIDO2 proof\n                            // or `E` enroll facts — forward VERBATIM: still\n                            // never a verdict, the broker decides everything.\n                            // [impl->REQ-SEAL-FIDO2-RC-CLIENT]\n                            let facts = enroll_pubkey_hex\n                                .as_deref()\n                                .zip(enroll_backend_kind.as_deref());\n                            brain.seal_ceremony_code(\n                                ceremony_id,\n                                code.as_deref(),\n                                signature_hex.as_deref(),\n                                facts,\n                            )?;\n                        }\n                        AttachRecord::InputPathsReply { reply }\n                            if attached && role == Some(ServeRole::Controller) =>\n                        {\n                            brain.complete_input_paths(&reply)?;\n                        }\n                        // Input/Resize before Request, a viewer's input/resize,\n                        // or target-direction records echoed back: noise — ignore.\n                        _ => {}\n                    }\n                }\n            }\n\n            // ── Broker → loop: the resolved controller/viewer role. ─────────\n            BrokerEvent::Subscribed { outcome, note, .. } => {\n                use crate::msg::SubscribeOutcome as O;\n                match outcome {\n                    O::Controller | O::TookControl => {\n                        role = Some(ServeRole::Controller);\n                        // Relay the broker's seat sentence to the human before\n                        // any session output, so the grant is read as a fact\n                        // about the attach and not as something the session\n                        // said. Controller-only: a viewer took no seat, and a\n                        // refused attach gets its own refusal path.\n                        // [impl->REQ-ENGINEROOM-ADMIN-BRINGUP-EMPOWERS]\n                        if let Some(text) = note {\n                            let line = ndjson::encode_line(&AttachRecord::Notice { text });\n                            wire.net_stream_send(stream_id, &line, None, false)?;\n                        }\n                        // A driver attached — the wake edge (controller-only;\n                        // idempotent on an already-active seat).\n                        feed_rest(endpoint, crate::resting::RestEvent::Wake);\n                        // Flush any input that raced ahead of the reply (operator-\n                        // minted ops carry the `rc` tag).\n                        for (op, b) in pending_input.drain(..) {\n                            brain.send_effect(MintedOp::new(Minter::Rc, op), &b)?;\n                        }\n                    }\n                    O::Viewer => {\n                        role = Some(ServeRole::Viewer);\n                        // Wake-neutral: a viewer never wakes the endpoint, never\n                        // keeps it awake (Gap B). Discard any racing input.\n                        pending_input.clear();\n                    }\n                    O::BusyControlled { .. } => {\n                        // A different operator controls it — refuse (no PTY input\n                        // ever reached it; the buffer is discarded). The rc\n                        // renders the busy guidance client-side from driven_by.\n                        wire.net_stream_send(stream_id, &[], None, true)?;\n                        return Ok(AttachServeOutcome::Refused);\n                    }\n                }\n                // Both roles use the same transport. A future viewer-specific\n                // policy reaches a surviving viewer after daemon reconstruction.\n                // Old clients omitted identity and receive no advisory at all.\n                // [impl->REQ-ATTACH-CLIENT-STALE]\n                if let Some(client) = client_identity.as_ref() {\n                    let policies = attach_client_policy()\n                        .into_iter()\n                        .filter(|policy| policy.affects(client, intent))\n                        .collect();\n                    let line = ndjson::encode_line(&AttachRecord::ClientPolicy { policies });\n                    wire.net_stream_send(stream_id, &line, None, false)?;\n                }\n            }\n            BrokerEvent::Other(env)\n                if attached\n                    && role == Some(ServeRole::Controller)\n                    && env.kind == crate::msg::KIND_USER_INPUT_PATHS =>\n…\n            }\n…\n        }\n\n[Showing lines 609-788 of 1159. Use :789 to continue]"}],"details":{"truncation":{"content":"            _ => brain.read_event_until(deadline)?,\r\n        };\r\n        match event {\r\n            // ── Wire → session: requests, input, resize. ───────────────────\r\n            BrokerEvent::NetStreamData {\r\n                stream_id: sid,\r\n                bytes,\r\n                ..\r\n            } if sid == stream_id => {\r\n                for rec in decoder.push(&bytes) {\r\n                    match rec {\r\n                        AttachRecord::Request {\r\n                            session_id,\r\n                            from_seq,\r\n                            intent: req_intent,\r\n                            // The dispatcher already resolved endpoint_id→session\r\n                            // (passed as remote_session) BEFORE this loop; ignore\r\n                            // the wire copy here (a mid-loop re-resolve would swallow\r\n                            // interleaved attach records — see remote_session docs).\r\n                            endpoint_id: _,\r\n                            gen: req_gen,\r\n                            code: req_code,\r\n                            seal_ceremony: req_seal_ceremony,\r\n                            client,\r\n                        } => {\r\n                            if let Some(out) = handle_attach_request(\r\n                                brain,\r\n                                &mut wire,\r\n                                stream_id,\r\n                                endpoint,\r\n                                origin_node,\r\n                                remote_session,\r\n                                session_id,\r\n                                from_seq,\r\n                                req_intent,\r\n                                req_gen,\r\n                                req_code,\r\n                                req_seal_ceremony,\r\n                                &mut intent,\r\n                                &mut attached_session,\r\n                                &mut attached,\r\n                                &mut serve_gen,\r\n                            )? {\r\n                                return Ok(out);\r\n                            }\r\n                            client_identity = client;\r\n                        }\r\n                        AttachRecord::Input { data_b64, op_id }\r\n                            if attached && intent != AttachIntent::Viewer =>\r\n                        {\r\n                            let bytes = decode_bytes(&data_b64)\r\n                                .map_err(|e| io::Error::new(io::ErrorKind::InvalidData, e))?;\r\n                            match role {\r\n                                // Confirmed controller — exactly-once at the PTY\r\n                                // (the operator-minted id rides the B5 journal). NO-ACK\r\n                                // (REQ-HAZARD-INPUT-ACK-BACKPRESSURE): this path is\r\n                                // fire-and-forward (the ack is discarded here) and can\r\n                                // flood N input frames on this one conn; an acked write\r\n                                // back would fill the return direction and deadlock the\r\n                                // broker's per-conn handler. Dedup still holds at the\r\n                                // broker (op_id applied-set).\r\n                                // [impl->REQ-HAZARD-INPUT-ACK-BACKPRESSURE]\r\n                                Some(ServeRole::Controller) => {\r\n                                    // The op_id is operator-minted (rc attach OpMinter),\r\n                                    // so it carries the `rc` journal tag (ADR-0034).\r\n                                    brain.send_effect_no_ack(\r\n                                        MintedOp::new(Minter::Rc, op_id),\r\n                                        &bytes,\r\n                                    )?\r\n                                }\r\n                                // Outcome not yet known — buffer; flushed on a\r\n                                // controller confirmation, discarded on busy/viewer.\r\n                                None => pending_input.push((op_id, bytes)),\r\n                                // A viewer never reaches here (intent gate).\r\n                                Some(ServeRole::Viewer) => {}\r\n                            }\r\n                        }\r\n                        AttachRecord::Resize { rows, cols }\r\n                            if attached && intent != AttachIntent::Viewer =>\r\n                        {\r\n                            // Controller → PTY resize (controller-EXCLUSIVE; the\r\n                            // broker rejects it on a viewer's stream). A viewer's\r\n                            // Resize is dropped here by the intent gate too.\r\n                            let _ = brain.resize(rows, cols);\r\n                        }\r\n                        // The ceremony presentation from the controller's\r\n                        // overlay (WAX-SEAL W2): the PRESENTED CODE, never a\r\n                        // verdict — forwarded to the broker, which decides\r\n                        // everything. Controller-only (the intent gate): a\r\n                        // viewer has no overlay to answer from.\r\n                        // [impl->REQ-SEAL-CEREMONY-RC-CLIENT]\r\n                        AttachRecord::SealCeremonyCode {\r\n                            ceremony_id,\r\n                            code,\r\n                            signature_hex,\r\n                            enroll_pubkey_hex,\r\n                            enroll_backend_kind,\r\n                        } if attached && intent != AttachIntent::Viewer => {\r\n                            // The SIGNET W2 additive fields — a FIDO2 proof\r\n                            // or `E` enroll facts — forward VERBATIM: still\r\n                            // never a verdict, the broker decides everything.\r\n                            // [impl->REQ-SEAL-FIDO2-RC-CLIENT]\r\n                            let facts = enroll_pubkey_hex\r\n                                .as_deref()\r\n                                .zip(enroll_backend_kind.as_deref());\r\n                            brain.seal_ceremony_code(\r\n                                ceremony_id,\r\n                                code.as_deref(),\r\n                                signature_hex.as_deref(),\r\n                                facts,\r\n                            )?;\r\n                        }\r\n                        AttachRecord::InputPathsReply { reply }\r\n                            if attached && role == Some(ServeRole::Controller) =>\r\n                        {\r\n                            brain.complete_input_paths(&reply)?;\r\n                        }\r\n                        // Input/Resize before Request, a viewer's input/resize,\r\n                        // or target-direction records echoed back: noise — ignore.\r\n                        _ => {}\r\n                    }\r\n                }\r\n            }\r\n\r\n            // ── Broker → loop: the resolved controller/viewer role. ─────────\r\n            BrokerEvent::Subscribed { outcome, note, .. } => {\r\n                use crate::msg::SubscribeOutcome as O;\r\n                match outcome {\r\n                    O::Controller | O::TookControl => {\r\n                        role = Some(ServeRole::Controller);\r\n                        // Relay the broker's seat sentence to the human before\r\n                        // any session output, so the grant is read as a fact\r\n                        // about the attach and not as something the session\r\n                        // said. Controller-only: a viewer took no seat, and a\r\n                        // refused attach gets its own refusal path.\r\n                        // [impl->REQ-ENGINEROOM-ADMIN-BRINGUP-EMPOWERS]\r\n                        if let Some(text) = note {\r\n                            let line = ndjson::encode_line(&AttachRecord::Notice { text });\r\n                            wire.net_stream_send(stream_id, &line, None, false)?;\r\n                        }\r\n                        // A driver attached — the wake edge (controller-only;\r\n                        // idempotent on an already-active seat).\r\n                        feed_rest(endpoint, crate::resting::RestEvent::Wake);\r\n                        // Flush any input that raced ahead of the reply (operator-\r\n                        // minted ops carry the `rc` tag).\r\n                        for (op, b) in pending_input.drain(..) {\r\n                            brain.send_effect(MintedOp::new(Minter::Rc, op), &b)?;\r\n                        }\r\n                    }\r\n                    O::Viewer => {\r\n                        role = Some(ServeRole::Viewer);\r\n                        // Wake-neutral: a viewer never wakes the endpoint, never\r\n                        // keeps it awake (Gap B). Discard any racing input.\r\n                        pending_input.clear();\r\n                    }\r\n                    O::BusyControlled { .. } => {\r\n                        // A different operator controls it — refuse (no PTY input\r\n                        // ever reached it; the buffer is discarded). The rc\r\n                        // renders the busy guidance client-side from driven_by.\r\n                        wire.net_stream_send(stream_id, &[], None, true)?;\r\n                        return Ok(AttachServeOutcome::Refused);\r\n                    }\r\n                }\r\n                // Both roles use the same transport. A future viewer-specific\r\n                // policy reaches a surviving viewer after daemon reconstruction.\r\n                // Old clients omitted identity and receive no advisory at all.\r\n                // [impl->REQ-ATTACH-CLIENT-STALE]\r\n                if let Some(client) = client_identity.as_ref() {\r\n                    let policies = attach_client_policy()\r\n                        .into_iter()\r\n                        .filter(|policy| policy.affects(client, intent))\r\n                        .collect();\r\n                    let line = ndjson::encode_line(&AttachRecord::ClientPolicy { policies });\r\n                    wire.net_stream_send(stream_id, &line, None, false)?;\r\n                }\r\n            }\r\n            BrokerEvent::Other(env)\r\n                if attached\r\n                    && role == Some(ServeRole::Controller)\r\n                    && env.kind == crate::msg::KIND_USER_INPUT_PATHS =>\r","truncated":true,"truncatedBy":"lines","totalLines":551,"totalBytes":10394,"outputLines":180,"outputBytes":10394,"lastLinePartial":false,"firstLineExceedsLimit":false},"totalLines":1159,"displayContent":{"text":"        let event = match (role, attached_session) {\n…\n            _ => brain.read_event_until(deadline)?,\r\n        };\r\n        match event {\r\n            // ── Wire → session: requests, input, resize. ───────────────────\r\n            BrokerEvent::NetStreamData {\r\n                stream_id: sid,\r\n                bytes,\r\n                ..\r\n            } if sid == stream_id => {\r\n                for rec in decoder.push(&bytes) {\r\n                    match rec {\r\n                        AttachRecord::Request {\r\n                            session_id,\r\n                            from_seq,\r\n                            intent: req_intent,\r\n                            // The dispatcher already resolved endpoint_id→session\r\n                            // (passed as remote_session) BEFORE this loop; ignore\r\n                            // the wire copy here (a mid-loop re-resolve would swallow\r\n                            // interleaved attach records — see remote_session docs).\r\n                            endpoint_id: _,\r\n                            gen: req_gen,\r\n                            code: req_code,\r\n                            seal_ceremony: req_seal_ceremony,\r\n                            client,\r\n                        } => {\r\n                            if let Some(out) = handle_attach_request(\r\n                                brain,\r\n                                &mut wire,\r\n                                stream_id,\r\n                                endpoint,\r\n                                origin_node,\r\n                                remote_session,\r\n                                session_id,\r\n                                from_seq,\r\n                                req_intent,\r\n                                req_gen,\r\n                                req_code,\r\n                                req_seal_ceremony,\r\n                                &mut intent,\r\n                                &mut attached_session,\r\n                                &mut attached,\r\n                                &mut serve_gen,\r\n                            )? {\r\n                                return Ok(out);\r\n                            }\r\n                            client_identity = client;\r\n                        }\r\n                        AttachRecord::Input { data_b64, op_id }\r\n                            if attached && intent != AttachIntent::Viewer =>\r\n                        {\r\n                            let bytes = decode_bytes(&data_b64)\r\n                                .map_err(|e| io::Error::new(io::ErrorKind::InvalidData, e))?;\r\n                            match role {\r\n                                // Confirmed controller — exactly-once at the PTY\r\n                                // (the operator-minted id rides the B5 journal). NO-ACK\r\n                                // (REQ-HAZARD-INPUT-ACK-BACKPRESSURE): this path is\r\n                                // fire-and-forward (the ack is discarded here) and can\r\n                                // flood N input frames on this one conn; an acked write\r\n                                // back would fill the return direction and deadlock the\r\n                                // broker's per-conn handler. Dedup still holds at the\r\n                                // broker (op_id applied-set).\r\n                                // [impl->REQ-HAZARD-INPUT-ACK-BACKPRESSURE]\r\n                                Some(ServeRole::Controller) => {\r\n                                    // The op_id is operator-minted (rc attach OpMinter),\r\n                                    // so it carries the `rc` journal tag (ADR-0034).\r\n                                    brain.send_effect_no_ack(\r\n                                        MintedOp::new(Minter::Rc, op_id),\r\n                                        &bytes,\r\n                                    )?\r\n                                }\r\n                                // Outcome not yet known — buffer; flushed on a\r\n                                // controller confirmation, discarded on busy/viewer.\r\n                                None => pending_input.push((op_id, bytes)),\r\n                                // A viewer never reaches here (intent gate).\r\n                                Some(ServeRole::Viewer) => {}\r\n                            }\r\n                        }\r\n                        AttachRecord::Resize { rows, cols }\r\n                            if attached && intent != AttachIntent::Viewer =>\r\n                        {\r\n                            // Controller → PTY resize (controller-EXCLUSIVE; the\r\n                            // broker rejects it on a viewer's stream). A viewer's\r\n                            // Resize is dropped here by the intent gate too.\r\n                            let _ = brain.resize(rows, cols);\r\n                        }\r\n                        // The ceremony presentation from the controller's\r\n                        // overlay (WAX-SEAL W2): the PRESENTED CODE, never a\r\n                        // verdict — forwarded to the broker, which decides\r\n                        // everything. Controller-only (the intent gate): a\r\n                        // viewer has no overlay to answer from.\r\n                        // [impl->REQ-SEAL-CEREMONY-RC-CLIENT]\r\n                        AttachRecord::SealCeremonyCode {\r\n                            ceremony_id,\r\n                            code,\r\n                            signature_hex,\r\n                            enroll_pubkey_hex,\r\n                            enroll_backend_kind,\r\n                        } if attached && intent != AttachIntent::Viewer => {\r\n                            // The SIGNET W2 additive fields — a FIDO2 proof\r\n                            // or `E` enroll facts — forward VERBATIM: still\r\n                            // never a verdict, the broker decides everything.\r\n                            // [impl->REQ-SEAL-FIDO2-RC-CLIENT]\r\n                            let facts = enroll_pubkey_hex\r\n                                .as_deref()\r\n                                .zip(enroll_backend_kind.as_deref());\r\n                            brain.seal_ceremony_code(\r\n                                ceremony_id,\r\n                                code.as_deref(),\r\n                                signature_hex.as_deref(),\r\n                                facts,\r\n                            )?;\r\n                        }\r\n                        AttachRecord::InputPathsReply { reply }\r\n                            if attached && role == Some(ServeRole::Controller) =>\r\n                        {\r\n                            brain.complete_input_paths(&reply)?;\r\n                        }\r\n                        // Input/Resize before Request, a viewer's input/resize,\r\n                        // or target-direction records echoed back: noise — ignore.\r\n                        _ => {}\r\n                    }\r\n                }\r\n            }\r\n\r\n            // ── Broker → loop: the resolved controller/viewer role. ─────────\r\n            BrokerEvent::Subscribed { outcome, note, .. } => {\r\n                use crate::msg::SubscribeOutcome as O;\r\n                match outcome {\r\n                    O::Controller | O::TookControl => {\r\n                        role = Some(ServeRole::Controller);\r\n                        // Relay the broker's seat sentence to the human before\r\n                        // any session output, so the grant is read as a fact\r\n                        // about the attach and not as something the session\r\n                        // said. Controller-only: a viewer took no seat, and a\r\n                        // refused attach gets its own refusal path.\r\n                        // [impl->REQ-ENGINEROOM-ADMIN-BRINGUP-EMPOWERS]\r\n                        if let Some(text) = note {\r\n                            let line = ndjson::encode_line(&AttachRecord::Notice { text });\r\n                            wire.net_stream_send(stream_id, &line, None, false)?;\r\n                        }\r\n                        // A driver attached — the wake edge (controller-only;\r\n                        // idempotent on an already-active seat).\r\n                        feed_rest(endpoint, crate::resting::RestEvent::Wake);\r\n                        // Flush any input that raced ahead of the reply (operator-\r\n                        // minted ops carry the `rc` tag).\r\n                        for (op, b) in pending_input.drain(..) {\r\n                            brain.send_effect(MintedOp::new(Minter::Rc, op), &b)?;\r\n                        }\r\n                    }\r\n                    O::Viewer => {\r\n                        role = Some(ServeRole::Viewer);\r\n                        // Wake-neutral: a viewer never wakes the endpoint, never\r\n                        // keeps it awake (Gap B). Discard any racing input.\r\n                        pending_input.clear();\r\n                    }\r\n                    O::BusyControlled { .. } => {\r\n                        // A different operator controls it — refuse (no PTY input\r\n                        // ever reached it; the buffer is discarded). The rc\r\n                        // renders the busy guidance client-side from driven_by.\r\n                        wire.net_stream_send(stream_id, &[], None, true)?;\r\n                        return Ok(AttachServeOutcome::Refused);\r\n                    }\r\n                }\r\n                // Both roles use the same transport. A future viewer-specific\r\n                // policy reaches a surviving viewer after daemon reconstruction.\r\n                // Old clients omitted identity and receive no advisory at all.\r\n                // [impl->REQ-ATTACH-CLIENT-STALE]\r\n                if let Some(client) = client_identity.as_ref() {\r\n                    let policies = attach_client_policy()\r\n                        .into_iter()\r\n                        .filter(|policy| policy.affects(client, intent))\r\n                        .collect();\r\n                    let line = ndjson::encode_line(&AttachRecord::ClientPolicy { policies });\r\n                    wire.net_stream_send(stream_id, &line, None, false)?;\r\n                }\r\n            }\r\n            BrokerEvent::Other(env)\r\n                if attached\r\n                    && role == Some(ServeRole::Controller)\r\n                    && env.kind == crate::msg::KIND_USER_INPUT_PATHS =>\r\n…\n            }\n…\n        }","startLine":580,"lineNumbers":[580,null,609,610,611,612,613,614,615,616,617,618,619,620,621,622,623,624,625,626,627,628,629,630,631,632,633,634,635,636,637,638,639,640,641,642,643,644,645,646,647,648,649,650,651,652,653,654,655,656,657,658,659,660,661,662,663,664,665,666,667,668,669,670,671,672,673,674,675,676,677,678,679,680,681,682,683,684,685,686,687,688,689,690,691,692,693,694,695,696,697,698,699,700,701,702,703,704,705,706,707,708,709,710,711,712,713,714,715,716,717,718,719,720,721,722,723,724,725,726,727,728,729,730,731,732,733,734,735,736,737,738,739,740,741,742,743,744,745,746,747,748,749,750,751,752,753,754,755,756,757,758,759,760,761,762,763,764,765,766,767,768,769,770,771,772,773,774,775,776,777,778,779,780,781,782,783,784,785,786,787,788,null,794,null,918]},"fileSize":57673,"meta":{"source":{"type":"path","value":"C:\\Users\\decid\\Documents\\projects\\spt-core\\crates\\spt-daemon\\src\\attach.rs"},"truncation":{"direction":"head","truncatedBy":"lines","totalLines":1159,"totalBytes":10394,"outputLines":180,"outputBytes":10394,"shownRange":{"start":609,"end":788},"nextOffset":789}}},"isError":false,"timestamp":1789523979731}}
{"type":"message","id":"90e2a0a7","parentId":"99872648","timestamp":"2026-09-16T01:59:39.732Z","message":{"role":"toolResult","toolCallId":"call_A8y6Cpf2uzlYAJBoUzhDhOKS|fc_09b01b5279447709016aa9f80ba4dc87d2ae9f3d7910df6057","toolName":"glob","content":[{"type":"text","text":"# .spt/preserved/307/hertz-w1bc/w1c-run1/home-w1c/logs/\ndaemon.stderr.log\n## obs/\n# crates/spt-daemon/tests/\nnetstream.rs"}],"details":{"scopePath":"crates/**/netstream*, crates/**/netstream/**/*, .spt/preserved/307/hertz-w1bc/w1c-run1/home-w1c/logs/*","fileCount":3,"files":[".spt/preserved/307/hertz-w1bc/w1c-run1/home-w1c/logs/daemon.stderr.log",".spt/preserved/307/hertz-w1bc/w1c-run1/home-w1c/logs/obs/","crates/spt-daemon/tests/netstream.rs"],"truncated":false,"cwd":"C:\\Users\\decid\\Documents\\projects\\spt-core"},"isError":false,"timestamp":1789523979732}}
{"type":"message","id":"9de51b96","parentId":"90e2a0a7","timestamp":"2026-09-16T01:59:39.735Z","message":{"role":"toolResult","toolCallId":"call_dm91GYv22iSQP1wk6vUSs96t|fc_09b01b5279447709016aa9f80ba4d487d28ceaf6e92822a191","toolName":"grep","content":[{"type":"text","text":" 42|    KillReq, NetDialReq, NetDialed, NetPresenceEvent, NetPresenceSubscribeReq, NetSent, TeardownReq, KIND_TEARDOWN,\n*43|    NetStatusReply, NetStreamData, NetStreamEof, NetStreamOpenReq, NetStreamOpened, NetStreamSendReq,\n 44|    NetStreamSubscribeReq, NetStreamsReply, NetStreamOpenerReply, NetStreamOpenerReq, NetStreamRetireReq, NetStreamRetired, NetStreamUnsubscribeReq, NetStreamUnsubscribed, OutputEvent, MetMember, PairCodeSubmit, PairJoinReply, PairJoinReq, PairMeetReq, ResizeReq,\n 45|    SessionsReply, SizeEvent, SpawnConflict, SpawnReq, Spawned, StreamLifetime, SubscribeOutcome,\n 46|    SubscribeReq, SubscribedReply, ViewerEvictedEvent,\n...\n 245|    /// A contiguous chunk of a stream's reads (the cursor has advanced past it).\n*246|    NetStreamData {\n 247|        stream_id: u64,\n 248|        seq: u64,\n 249|        bytes: Vec<u8>,\n...\n 421|    /// brain queries `net-streams` and re-subscribes from its durable cursors).\n*422|    net_cursors: std::collections::HashMap<u64, u64>,\n 423|    /// The presence resume cursor (D4c) — the conn-liveness sibling of\n*424|    /// `net_cursors`, set by [`Brain::net_presence_subscribe`] and advanced by\n 425|    /// [`Brain::read_event_until`] under the same accept/dedup/gap discipline.\n 426|    /// `None` until subscribed (or the first event arrives).\n 427|    presence_cursor: Option<u64>,\n...\n 474|            next_seq: 0,\n*475|            net_cursors: std::collections::HashMap::new(),\n 476|            presence_cursor: None,\n 477|            session_cursors: std::collections::HashMap::new(),\n 478|            io_timeout: None,\n...\n 512|            next_seq: 0,\n*513|            net_cursors: std::collections::HashMap::new(),\n 514|            presence_cursor: None,\n 515|            session_cursors: std::collections::HashMap::new(),\n 516|            io_timeout: Some(io_timeout),\n...\n 557|            next_seq: prior.next_seq,\n*558|            net_cursors: std::collections::HashMap::new(),\n 559|            presence_cursor: None,\n 560|            session_cursors,\n 561|            io_timeout: None,\n...\n 920|    // [impl->REQ-HAZARD-RESTART-IDEMPOTENT]\n*921|    pub fn send_effect(&mut self, op: MintedOp, bytes: &[u8]) -> io::Result<()> {\n 922|        self.send_effect_inner(op, bytes, true)\n 923|    }\n 924|\n...\n 933|    // [impl->REQ-HAZARD-INPUT-ACK-BACKPRESSURE]\n*934|    pub fn send_effect_no_ack(&mut self, op: MintedOp, bytes: &[u8]) -> io::Result<()> {\n 935|        self.send_effect_inner(op, bytes, false)\n 936|    }\n 937|\n...\n 942|    /// uncompilable. The broker's `KIND_APPLIED` still echoes the bare `seq`.\n*943|    fn send_effect_inner(&mut self, op: MintedOp, bytes: &[u8], ack: bool) -> io::Result<()> {\n 944|        let sid = self.require_session()?;\n 945|        self.send(\n 946|            KIND_INPUT,\n...\n 1062|    // [impl->REQ-BRAIN-READ-BOUNDED-PER-CALL]\n*1063|    pub fn read_event_until(&mut self, deadline: Option<Instant>) -> io::Result<BrokerEvent> {\n 1064|        loop {\n 1065|            let env = self.read_frame_until(deadline)?;\n 1066|            match env.kind.as_str() {\n...\n 1311|                KIND_NET_STREAM_DATA => {\n*1312|                    let ev: NetStreamData = serde_json::from_value(env.payload)\n 1313|                        .map_err(|e| io::Error::new(io::ErrorKind::InvalidData, e))?;\n 1314|                    // Same exactly-once discipline as PTY output, per stream:\n 1315|                    // accept the contiguous next seq, drop a replay duplicate,\n 1316|                    // reject a forward gap (a lost chunk must not pass silently).\n*1317|                    let cursor = self.net_cursors.entry(ev.stream_id).or_insert(ev.seq);\n 1318|                    if ev.seq < *cursor {\n 1319|                        continue; // replay duplicate — dedup\n 1320|                    }\n...\n 1332|                        .map_err(|e| io::Error::new(io::ErrorKind::InvalidData, e))?;\n*1333|                    return Ok(BrokerEvent::NetStreamData {\n 1334|                        stream_id: ev.stream_id,\n 1335|                        seq: ev.seq,\n 1336|                        bytes,\n...\n 1426|    /// [`serve_attach`]: crate::attach::serve_attach\n*1427|    pub fn attach_as(\n 1428|        &mut self,\n 1429|        session_id: u64,\n 1430|        from_seq: u64,\n...\n 1452|    #[allow(clippy::too_many_arguments)]\n*1453|    pub fn attach_as_coded(\n 1454|        &mut self,\n 1455|        session_id: u64,\n 1456|        from_seq: u64,\n...\n 1532|    // [impl->REQ-HAZARD-VIEWER-RING-ROLL-SNAP]\n*1533|    pub fn attach_as_viewer_snap(\n 1534|        &mut self,\n 1535|        session_id: u64,\n 1536|        from_seq: u64,\n...\n 1580|    /// the conn up, the broker-side subscriber writer blocks holding the conn's single\n*1581|    /// `SharedSend` mutex ACROSS a blocking `write_frame` (broker.rs\n 1582|    /// `viewer_writer`/`controller_writer`), the dispatch reply path (`send_frame`) needs\n 1583|    /// that same lock, so any request/reply the non-draining consumer issues is starved\n 1584|    /// (dead-peer-independent — the v0.30.4 field re-wedge). The supervised daemon brain\n...\n 1622|    /// carrying only request/reply on the brain's conn (no UNDRAINED subscription) makes\n*1623|    /// the `SharedSend` self-deadlock structurally impossible (UPDATE-WEDGE round 3,\n 1624|    /// REQ-BRAIN-RESUME-NO-CONN-DEADLOCK — see the deadlock warning on\n 1625|    /// [`Self::resume_sessions`]). The daemon brain drives no broker PTY session\n 1626|    /// (brainproc.rs:184) and nothing on its side consumes session output (§3 guard), so\n...\n 2100|    // [impl->REQ-HAZARD-RESTART-IDEMPOTENT]\n*2101|    pub fn net_stream_send(\n 2102|        &mut self,\n 2103|        stream_id: u64,\n 2104|        bytes: &[u8],\n...\n 2135|    /// finds streams (incl. peer-initiated ones) that arrived while it was down.\n*2136|    pub fn net_streams(&mut self) -> io::Result<NetStreamsReply> {\n 2137|        self.send(KIND_NET_STREAMS, serde_json::Value::Null)?;\n 2138|        // [impl->REQ-BRAIN-READ-BOUNDED-PER-CALL]\n 2139|        let deadline = self.call_deadline();\n...\n 2155|    // [impl->REQ-REDISPATCH-FINISHED-RETIRE]\n*2156|    pub fn net_stream_retire(&mut self, stream_id: u64) -> io::Result<bool> {\n 2157|        self.net_stream_retire_with(stream_id, false)\n 2158|    }\n 2159|\n...\n 2167|    // [impl->REQ-ONEWAY-STREAM-TERMINAL]\n*2168|    pub fn net_stream_retire_terminal(&mut self, stream_id: u64) -> io::Result<bool> {\n 2169|        self.net_stream_retire_with(stream_id, true)\n 2170|    }\n 2171|\n*2172|    fn net_stream_retire_with(&mut self, stream_id: u64, terminal: bool) -> io::Result<bool> {\n 2173|        self.send(\n 2174|            KIND_NET_STREAM_RETIRE,\n 2175|            serde_json::to_value(NetStreamRetireReq {\n...\n 2202|    // [impl->REQ-SEAT-LIFETIME-BOUNDED]\n*2203|    pub fn net_stream_unsubscribe(&mut self, stream_id: u64) -> io::Result<bool> {\n 2204|        // Drop the cursor FIRST — even an error reply (older broker) must not\n 2205|        // leave a cursor for a subscription the caller has abandoned.\n*2206|        self.net_cursors.remove(&stream_id);\n 2207|        self.send(\n 2208|            KIND_NET_STREAM_UNSUBSCRIBE,\n 2209|            serde_json::to_value(NetStreamUnsubscribeReq { stream_id })\n...\n 2233|    // [impl->REQ-STREAM-OPENER-DURABLE]\n*2234|    pub fn net_stream_opener(&mut self, stream_id: u64) -> io::Result<Option<Vec<u8>>> {\n 2235|        self.send(\n 2236|            KIND_NET_STREAM_OPENER,\n 2237|            serde_json::to_value(NetStreamOpenerReq { stream_id })\n...\n 2383|    // [impl->REQ-DAEMON-2]\n*2384|    pub fn net_stream_subscribe(&mut self, stream_id: u64, from_seq: u64) -> io::Result<()> {\n*2385|        self.net_cursors.insert(stream_id, from_seq);\n 2386|        self.send(\n 2387|            KIND_NET_STREAM_SUBSCRIBE,\n 2388|            serde_json::to_value(NetStreamSubscribeReq {\n...\n 2398|    pub fn net_cursor(&self, stream_id: u64) -> Option<u64> {\n*2399|        self.net_cursors.get(&stream_id).copied()\n 2400|    }\n 2401|\n 2402|    /// (Re)subscribe to the broker's conn-liveness event log from `from_seq`,"}],"details":{"scopePath":"crates/spt-daemon/src/brain.rs","searchPath":"C:\\Users\\decid\\Documents\\projects\\spt-core\\crates\\spt-daemon\\src\\brain.rs","cwd":"C:\\Users\\decid\\Documents\\projects\\spt-core","matchCount":30,"fileCount":1,"files":["crates/spt-daemon/src/brain.rs"],"fileMatches":[{"path":"crates/spt-daemon/src/brain.rs","count":30}],"truncated":false,"displayContent":"   42│    KillReq, NetDialReq, NetDialed, NetPresenceEvent, NetPresenceSubscribeReq, NetSent, TeardownReq, KIND_TEARDOWN,\n  *43│    NetStatusReply, NetStreamData, NetStreamEof, NetStreamOpenReq, NetStreamOpened, NetStreamSendReq,\n   44│    NetStreamSubscribeReq, NetStreamsReply, NetStreamOpenerReply, NetStreamOpenerReq, NetStreamRetireReq, NetStreamRetired, NetStreamUnsubscribeReq, NetStreamUnsubscribed, OutputEvent, MetMember, PairCodeSubmit, PairJoinReply, PairJoinReq, PairMeetReq, ResizeReq,\n   45│    SessionsReply, SizeEvent, SpawnConflict, SpawnReq, Spawned, StreamLifetime, SubscribeOutcome,\n   46│    SubscribeReq, SubscribedReply, ViewerEvictedEvent,\n     │...\n  245│    /// A contiguous chunk of a stream's reads (the cursor has advanced past it).\n *246│    NetStreamData {\n  247│        stream_id: u64,\n  248│        seq: u64,\n  249│        bytes: Vec<u8>,\n     │...\n  421│    /// brain queries `net-streams` and re-subscribes from its durable cursors).\n *422│    net_cursors: std::collections::HashMap<u64, u64>,\n  423│    /// The presence resume cursor (D4c) — the conn-liveness sibling of\n *424│    /// `net_cursors`, set by [`Brain::net_presence_subscribe`] and advanced by\n  425│    /// [`Brain::read_event_until`] under the same accept/dedup/gap discipline.\n  426│    /// `None` until subscribed (or the first event arrives).\n  427│    presence_cursor: Option<u64>,\n     │...\n  474│            next_seq: 0,\n *475│            net_cursors: std::collections::HashMap::new(),\n  476│            presence_cursor: None,\n  477│            session_cursors: std::collections::HashMap::new(),\n  478│            io_timeout: None,\n     │...\n  512│            next_seq: 0,\n *513│            net_cursors: std::collections::HashMap::new(),\n  514│            presence_cursor: None,\n  515│            session_cursors: std::collections::HashMap::new(),\n  516│            io_timeout: Some(io_timeout),\n     │...\n  557│            next_seq: prior.next_seq,\n *558│            net_cursors: std::collections::HashMap::new(),\n  559│            presence_cursor: None,\n  560│            session_cursors,\n  561│            io_timeout: None,\n     │...\n  920│    // [impl->REQ-HAZARD-RESTART-IDEMPOTENT]\n *921│    pub fn send_effect(&mut self, op: MintedOp, bytes: &[u8]) -> io::Result<()> {\n  922│        self.send_effect_inner(op, bytes, true)\n  923│    }\n  924│\n     │...\n  933│    // [impl->REQ-HAZARD-INPUT-ACK-BACKPRESSURE]\n *934│    pub fn send_effect_no_ack(&mut self, op: MintedOp, bytes: &[u8]) -> io::Result<()> {\n  935│        self.send_effect_inner(op, bytes, false)\n  936│    }\n  937│\n     │...\n  942│    /// uncompilable. The broker's `KIND_APPLIED` still echoes the bare `seq`.\n *943│    fn send_effect_inner(&mut self, op: MintedOp, bytes: &[u8], ack: bool) -> io::Result<()> {\n  944│        let sid = self.require_session()?;\n  945│        self.send(\n  946│            KIND_INPUT,\n     │...\n 1062│    // [impl->REQ-BRAIN-READ-BOUNDED-PER-CALL]\n*1063│    pub fn read_event_until(&mut self, deadline: Option<Instant>) -> io::Result<BrokerEvent> {\n 1064│        loop {\n 1065│            let env = self.read_frame_until(deadline)?;\n 1066│            match env.kind.as_str() {\n     │...\n 1311│                KIND_NET_STREAM_DATA => {\n*1312│                    let ev: NetStreamData = serde_json::from_value(env.payload)\n 1313│                        .map_err(|e| io::Error::new(io::ErrorKind::InvalidData, e))?;\n 1314│                    // Same exactly-once discipline as PTY output, per stream:\n 1315│                    // accept the contiguous next seq, drop a replay duplicate,\n 1316│                    // reject a forward gap (a lost chunk must not pass silently).\n*1317│                    let cursor = self.net_cursors.entry(ev.stream_id).or_insert(ev.seq);\n 1318│                    if ev.seq < *cursor {\n 1319│                        continue; // replay duplicate — dedup\n 1320│                    }\n     │...\n 1332│                        .map_err(|e| io::Error::new(io::ErrorKind::InvalidData, e))?;\n*1333│                    return Ok(BrokerEvent::NetStreamData {\n 1334│                        stream_id: ev.stream_id,\n 1335│                        seq: ev.seq,\n 1336│                        bytes,\n     │...\n 1426│    /// [`serve_attach`]: crate::attach::serve_attach\n*1427│    pub fn attach_as(\n 1428│        &mut self,\n 1429│        session_id: u64,\n 1430│        from_seq: u64,\n     │...\n 1452│    #[allow(clippy::too_many_arguments)]\n*1453│    pub fn attach_as_coded(\n 1454│        &mut self,\n 1455│        session_id: u64,\n 1456│        from_seq: u64,\n     │...\n 1532│    // [impl->REQ-HAZARD-VIEWER-RING-ROLL-SNAP]\n*1533│    pub fn attach_as_viewer_snap(\n 1534│        &mut self,\n 1535│        session_id: u64,\n 1536│        from_seq: u64,\n     │...\n 1580│    /// the conn up, the broker-side subscriber writer blocks holding the conn's single\n*1581│    /// `SharedSend` mutex ACROSS a blocking `write_frame` (broker.rs\n 1582│    /// `viewer_writer`/`controller_writer`), the dispatch reply path (`send_frame`) needs\n 1583│    /// that same lock, so any request/reply the non-draining consumer issues is starved\n 1584│    /// (dead-peer-independent — the v0.30.4 field re-wedge). The supervised daemon brain\n     │...\n 1622│    /// carrying only request/reply on the brain's conn (no UNDRAINED subscription) makes\n*1623│    /// the `SharedSend` self-deadlock structurally impossible (UPDATE-WEDGE round 3,\n 1624│    /// REQ-BRAIN-RESUME-NO-CONN-DEADLOCK — see the deadlock warning on\n 1625│    /// [`Self::resume_sessions`]). The daemon brain drives no broker PTY session\n 1626│    /// (brainproc.rs:184) and nothing on its side consumes session output (§3 guard), so\n     │...\n 2100│    // [impl->REQ-HAZARD-RESTART-IDEMPOTENT]\n*2101│    pub fn net_stream_send(\n 2102│        &mut self,\n 2103│        stream_id: u64,\n 2104│        bytes: &[u8],\n     │...\n 2135│    /// finds streams (incl. peer-initiated ones) that arrived while it was down.\n*2136│    pub fn net_streams(&mut self) -> io::Result<NetStreamsReply> {\n 2137│        self.send(KIND_NET_STREAMS, serde_json::Value::Null)?;\n 2138│        // [impl->REQ-BRAIN-READ-BOUNDED-PER-CALL]\n 2139│        let deadline = self.call_deadline();\n     │...\n 2155│    // [impl->REQ-REDISPATCH-FINISHED-RETIRE]\n*2156│    pub fn net_stream_retire(&mut self, stream_id: u64) -> io::Result<bool> {\n 2157│        self.net_stream_retire_with(stream_id, false)\n 2158│    }\n 2159│\n     │...\n 2167│    // [impl->REQ-ONEWAY-STREAM-TERMINAL]\n*2168│    pub fn net_stream_retire_terminal(&mut self, stream_id: u64) -> io::Result<bool> {\n 2169│        self.net_stream_retire_with(stream_id, true)\n 2170│    }\n 2171│\n*2172│    fn net_stream_retire_with(&mut self, stream_id: u64, terminal: bool) -> io::Result<bool> {\n 2173│        self.send(\n 2174│            KIND_NET_STREAM_RETIRE,\n 2175│            serde_json::to_value(NetStreamRetireReq {\n     │...\n 2202│    // [impl->REQ-SEAT-LIFETIME-BOUNDED]\n*2203│    pub fn net_stream_unsubscribe(&mut self, stream_id: u64) -> io::Result<bool> {\n 2204│        // Drop the cursor FIRST — even an error reply (older broker) must not\n 2205│        // leave a cursor for a subscription the caller has abandoned.\n*2206│        self.net_cursors.remove(&stream_id);\n 2207│        self.send(\n 2208│            KIND_NET_STREAM_UNSUBSCRIBE,\n 2209│            serde_json::to_value(NetStreamUnsubscribeReq { stream_id })\n     │...\n 2233│    // [impl->REQ-STREAM-OPENER-DURABLE]\n*2234│    pub fn net_stream_opener(&mut self, stream_id: u64) -> io::Result<Option<Vec<u8>>> {\n 2235│        self.send(\n 2236│            KIND_NET_STREAM_OPENER,\n 2237│            serde_json::to_value(NetStreamOpenerReq { stream_id })\n     │...\n 2383│    // [impl->REQ-DAEMON-2]\n*2384│    pub fn net_stream_subscribe(&mut self, stream_id: u64, from_seq: u64) -> io::Result<()> {\n*2385│        self.net_cursors.insert(stream_id, from_seq);\n 2386│        self.send(\n 2387│            KIND_NET_STREAM_SUBSCRIBE,\n 2388│            serde_json::to_value(NetStreamSubscribeReq {\n     │...\n 2398│    pub fn net_cursor(&self, stream_id: u64) -> Option<u64> {\n*2399│        self.net_cursors.get(&stream_id).copied()\n 2400│    }\n 2401│\n 2402│    /// (Re)subscribe to the broker's conn-liveness event log from `from_seq`,"},"isError":false,"timestamp":1789523979734}}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_2AqcNv0d5zpiwhAEnytF1RR0|fc_09b01b5279447709016aa9f8197da487d2b80705b4355c1510","toolName":"read","startedAt":"2026-09-16T01:59:53.563Z","args":{"path":"crates/spt-daemon/src/brain.rs:920-983,1311-1345,1453-1505,2101-2134,2380-2396"},"intent":"Reading brain wait primitives"},"id":"492c743d","parentId":"9de51b96","timestamp":"2026-09-16T01:59:53.563Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_X60m4vAb3W7SVfS9GBt2pk4n|fc_09b01b5279447709016aa9f8197db487d28e8b4e5f985b11f5","toolName":"read","startedAt":"2026-09-16T01:59:53.563Z","args":{"path":"crates/spt-daemon/src/dispatch.rs:1034-1125,1160-1235"},"intent":"Reading replacement worker dispatch"},"id":"95394211","parentId":"492c743d","timestamp":"2026-09-16T01:59:53.563Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_caWhxBZTNzQKxOMBXAI1Onbx|fc_09b01b5279447709016aa9f8197dbc87d2b5d151041ac47b66","toolName":"grep","startedAt":"2026-09-16T01:59:53.563Z","args":{"path":"crates/spt-daemon/src/net;crates/spt-daemon/src/broker.rs"},"intent":"Locating stream send implementation"},"id":"ac5e9909","parentId":"95394211","timestamp":"2026-09-16T01:59:53.563Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_PzinZ2BL9gjPiP5GqsBTc9tM|fc_09b01b5279447709016aa9f8197dc487d296f092885681c7ba","toolName":"grep","startedAt":"2026-09-16T01:59:53.563Z","args":{"path":".spt/preserved/307/hertz-w1bc/w1c-run1/home-w1c/logs/daemon.stderr.log"},"intent":"Extracting W1c attach evidence"},"id":"8b20133f","parentId":"ac5e9909","timestamp":"2026-09-16T01:59:53.563Z"}
{"type":"message","id":"4885383d","parentId":"8b20133f","timestamp":"2026-09-16T01:59:53.564Z","message":{"role":"assistant","content":[{"type":"toolCall","id":"call_2AqcNv0d5zpiwhAEnytF1RR0|fc_09b01b5279447709016aa9f8197da487d2b80705b4355c1510","name":"read","arguments":{"i":"Reading brain wait primitives","path":"crates/spt-daemon/src/brain.rs:920-983,1311-1345,1453-1505,2101-2134,2380-2396"},"intent":"Reading brain wait primitives"},{"type":"toolCall","id":"call_X60m4vAb3W7SVfS9GBt2pk4n|fc_09b01b5279447709016aa9f8197db487d28e8b4e5f985b11f5","name":"read","arguments":{"i":"Reading replacement worker dispatch","path":"crates/spt-daemon/src/dispatch.rs:1034-1125,1160-1235"},"intent":"Reading replacement worker dispatch"},{"type":"toolCall","id":"call_caWhxBZTNzQKxOMBXAI1Onbx|fc_09b01b5279447709016aa9f8197dbc87d2b5d151041ac47b66","name":"grep","arguments":{"i":"Locating stream send implementation","pattern":"fn send_stream|SharedSend|KIND_NET_STREAM_SEND|fn subscribe|ack","path":"crates/spt-daemon/src/net;crates/spt-daemon/src/broker.rs","case":true,"gitignore":true,"skip":null},"intent":"Locating stream send implementation"},{"type":"toolCall","id":"call_PzinZ2BL9gjPiP5GqsBTc9tM|fc_09b01b5279447709016aa9f8197dc487d296f092885681c7ba","name":"grep","arguments":{"i":"Extracting W1c attach evidence","pattern":"BRAIN_UPDATE_RESTART|conn=70|conn=88|conn=104|conn=17|Attach|attach|POISONED|STALL_EVICT","path":".spt/preserved/307/hertz-w1bc/w1c-run1/home-w1c/logs/daemon.stderr.log","case":true,"gitignore":false,"skip":null},"intent":"Extracting W1c attach evidence"}],"api":"openai-codex-responses","provider":"openai-codex","model":"gpt-6-astra","usage":{"input":7154,"output":291,"cacheRead":30976,"cacheWrite":0,"totalTokens":38421,"cost":{"input":0.07154,"output":0.01455,"cacheRead":0.030976,"cacheWrite":0,"total":0.117066}},"stopReason":"toolUse","timestamp":1789523979745,"responseId":"resp_09b01b5279447709016aa9f80bfa4c87d2b28f8f2792a49d0b","providerPayload":{"type":"openaiResponsesHistory","provider":"openai-codex","dt":true,"items":[{"id":"fc_09b01b5279447709016aa9f8197da487d2b80705b4355c1510","type":"function_call","status":"completed","arguments":"{\"i\":\"Reading brain wait primitives\",\"path\":\"crates/spt-daemon/src/brain.rs:920-983,1311-1345,1453-1505,2101-2134,2380-2396\"}","call_id":"call_2AqcNv0d5zpiwhAEnytF1RR0","internal_chat_message_metadata_passthrough":{"turn_id":"a464097d-3a78-4a75-9ebb-a53f309aa685"},"name":"read","metadata":{"turn_id":"a464097d-3a78-4a75-9ebb-a53f309aa685"}},{"id":"fc_09b01b5279447709016aa9f8197db487d28e8b4e5f985b11f5","type":"function_call","status":"completed","arguments":"{\"i\":\"Reading replacement worker dispatch\",\"path\":\"crates/spt-daemon/src/dispatch.rs:1034-1125,1160-1235\"}","call_id":"call_X60m4vAb3W7SVfS9GBt2pk4n","internal_chat_message_metadata_passthrough":{"turn_id":"a464097d-3a78-4a75-9ebb-a53f309aa685"},"name":"read","metadata":{"turn_id":"a464097d-3a78-4a75-9ebb-a53f309aa685"}},{"id":"fc_09b01b5279447709016aa9f8197dbc87d2b5d151041ac47b66","type":"function_call","status":"completed","arguments":"{\"i\":\"Locating stream send implementation\",\"pattern\":\"fn send_stream|SharedSend|KIND_NET_STREAM_SEND|fn subscribe|ack\",\"path\":\"crates/spt-daemon/src/net;crates/spt-daemon/src/broker.rs\",\"case\":true,\"gitignore\":true,\"skip\":null}","call_id":"call_caWhxBZTNzQKxOMBXAI1Onbx","internal_chat_message_metadata_passthrough":{"turn_id":"a464097d-3a78-4a75-9ebb-a53f309aa685"},"name":"grep","metadata":{"turn_id":"a464097d-3a78-4a75-9ebb-a53f309aa685"}},{"id":"fc_09b01b5279447709016aa9f8197dc487d296f092885681c7ba","type":"function_call","status":"completed","arguments":"{\"i\":\"Extracting W1c attach evidence\",\"pattern\":\"BRAIN_UPDATE_RESTART|conn=70|conn=88|conn=104|conn=17|Attach|attach|POISONED|STALL_EVICT\",\"path\":\".spt/preserved/307/hertz-w1bc/w1c-run1/home-w1c/logs/daemon.stderr.log\",\"case\":true,\"gitignore\":false,\"skip\":null}","call_id":"call_PzinZ2BL9gjPiP5GqsBTc9tM","internal_chat_message_metadata_passthrough":{"turn_id":"a464097d-3a78-4a75-9ebb-a53f309aa685"},"name":"grep","metadata":{"turn_id":"a464097d-3a78-4a75-9ebb-a53f309aa685"}}]},"duration":13815.760800000047,"ttft":13774.141999999993,"completedAt":1789523993562,"contextSnapshot":{"promptTokens":38130,"nonMessageTokens":10480,"compactionEpoch":0}}}
{"type":"message","id":"13e6e16a","parentId":"4885383d","timestamp":"2026-09-16T01:59:53.582Z","message":{"role":"toolResult","toolCallId":"call_2AqcNv0d5zpiwhAEnytF1RR0|fc_09b01b5279447709016aa9f8197da487d2b80705b4355c1510","toolName":"read","content":[{"type":"text","text":"    // [impl->REQ-HAZARD-RESTART-IDEMPOTENT]\n    pub fn send_effect(&mut self, op: MintedOp, bytes: &[u8]) -> io::Result<()> {\n        self.send_effect_inner(op, bytes, true)\n    }\n\n    /// Inject input idempotently like [`Brain::send_effect`] but request NO\n    /// [`KIND_APPLIED`] ack (REQ-HAZARD-INPUT-ACK-BACKPRESSURE). The operator/rc\n    /// attach path is fire-and-forward — `op_id` is for dedup only and the ack is\n    /// discarded by `serve_attach` — and it can flood N input frames on ONE\n    /// brain↔broker conn without returning to read. With no ack the broker's\n    /// per-conn handler never writes back while servicing that flood, so the return\n    /// direction can't fill and deadlock the handler. Exactly-once is preserved: the\n    /// broker still dedups by `(session, op_id)` at its applied-set.\n    // [impl->REQ-HAZARD-INPUT-ACK-BACKPRESSURE]\n    pub fn send_effect_no_ack(&mut self, op: MintedOp, bytes: &[u8]) -> io::Result<()> {\n        self.send_effect_inner(op, bytes, false)\n    }\n\n    /// Shared body for [`Brain::send_effect`] / [`Brain::send_effect_no_ack`]: the\n    /// only difference is whether the broker replies a `KIND_APPLIED` ack. The\n    /// [`MintedOp`] carries both the durable seq and its minter tag (ADR-0034), so\n    /// the wire's `op_id`/`minter` fields are stamped together — an unstamped op is\n    /// uncompilable. The broker's `KIND_APPLIED` still echoes the bare `seq`.\n    fn send_effect_inner(&mut self, op: MintedOp, bytes: &[u8], ack: bool) -> io::Result<()> {\n        let sid = self.require_session()?;\n        self.send(\n            KIND_INPUT,\n            serde_json::to_value(InputReq {\n                session_id: sid,\n                data_b64: encode_bytes(bytes),\n                op_id: Some(op.seq),\n                minter: Some(op.minter),\n                ack,\n            })\n            .expect(\"InputReq serializes\"),\n        )\n    }\n\n    /// Resize the current session's PTY.\n    pub fn resize(&mut self, rows: u16, cols: u16) -> io::Result<()> {\n        let sid = self.require_session()?;\n        self.send(\n            KIND_RESIZE,\n            serde_json::to_value(ResizeReq {\n                session_id: sid,\n                rows,\n                cols,\n            })\n            .expect(\"ResizeReq serializes\"),\n        )\n    }\n\n    /// Terminate the current session's child.\n    pub fn kill_session(&mut self) -> io::Result<()> {\n        let sid = self.require_session()?;\n        self.send(\n            KIND_KILL,\n            serde_json::to_value(KillReq { session_id: sid }).expect(\"KillReq serializes\"),\n        )\n    }\n\n    /// Tear down a hosted session by sid/endpoint key — the endpoint-teardown\n    /// request (ADR-0045 decision 6). Deliberately NOT [`Brain::kill_session`]:\n    /// that one runs `require_session()` on THIS connection's attached session,\n…\n                KIND_NET_STREAM_DATA => {\n                    let ev: NetStreamData = serde_json::from_value(env.payload)\n                        .map_err(|e| io::Error::new(io::ErrorKind::InvalidData, e))?;\n                    // Same exactly-once discipline as PTY output, per stream:\n                    // accept the contiguous next seq, drop a replay duplicate,\n                    // reject a forward gap (a lost chunk must not pass silently).\n                    let cursor = self.net_cursors.entry(ev.stream_id).or_insert(ev.seq);\n                    if ev.seq < *cursor {\n                        continue; // replay duplicate — dedup\n                    }\n                    if ev.seq > *cursor {\n                        return Err(io::Error::new(\n                            io::ErrorKind::InvalidData,\n                            format!(\n                                \"stream {} gap: got seq {} want {}\",\n                                ev.stream_id, ev.seq, *cursor\n                            ),\n                        ));\n                    }\n                    *cursor = ev.seq + 1;\n                    let bytes = decode_bytes(&ev.data_b64)\n                        .map_err(|e| io::Error::new(io::ErrorKind::InvalidData, e))?;\n                    return Ok(BrokerEvent::NetStreamData {\n                        stream_id: ev.stream_id,\n                        seq: ev.seq,\n                        bytes,\n                    });\n                }\n                KIND_NET_STREAM_EOF => {\n                    let ev: NetStreamEof = serde_json::from_value(env.payload)\n                        .map_err(|e| io::Error::new(io::ErrorKind::InvalidData, e))?;\n                    return Ok(BrokerEvent::NetStreamEof {\n                        stream_id: ev.stream_id,\n                        next_seq: ev.next_seq,\n                    });\n                }\n…\n    pub fn attach_as_coded(\n        &mut self,\n        session_id: u64,\n        from_seq: u64,\n        intent: AttachIntent,\n        gen: u64,\n        by: Option<&str>,\n        code: Option<&str>,\n        seal_ceremony: bool,\n    ) -> io::Result<()> {\n        self.session_id = Some(session_id);\n        self.next_seq = from_seq;\n        // #6 (ADR-0031): a COLD attach (`from_seq == 0` — the `rc` / `endpoint run\n        // --attach` case) gets a clean-screen repaint at pseudo-seq\n        // `broker.next_seq - 1` as its first frame; baseline the strict cursor on it\n        // (accept-then-strict). A resume-from-floor re-fetch (`from_seq > 0`) leaves\n        // this false → raw-ring replay + strict reject-gap unchanged (B2).\n        self.baseline_next_output = from_seq == 0;\n        self.subscribe_with(\n            session_id,\n            from_seq,\n            intent,\n            gen,\n            by.map(str::to_string),\n            code.map(str::to_string),\n            seal_ceremony,\n        )\n    }\n\n    /// Re-subscribe a VIEWER from the LIVE TAIL after a broker eviction —\n    /// skip-to-live (REQ-VIEWER-SKIP-TO-LIVE-ON-EVICT). The viewer overflowed its\n    /// bounded subscription queue (it forwards slower than the drain fans out) and\n    /// the broker evicted it (correct session-protection); rather than dying it\n    /// jumps to live and skips the uncatchable backlog (tail -f reconnect).\n    ///\n    /// `from_seq = u64::MAX` makes the broker's ring replay (`s >= from_seq`)\n    /// EMPTY, so the viewer receives only the size frame + live output going\n    /// forward. The next live frame carries the current ring tail's seq — a\n    /// FORWARD JUMP from where this brain was evicted. The legacy `next_seq` dedup\n    /// (the cold serve brain's default) would FATAL that jump as an \"output gap\",\n    /// and a `next_seq = MAX` would DEDUP-DROP every live frame (seq < MAX); so we\n    /// arm the snap-above dedup path (`session_cursors` non-empty) seeded at 0,\n    /// which accepts the jump and snaps. VIEWER-only → B2-safe (a viewer never\n    /// advances `delivered_through` / is not authoritative). The subscribe is sent\n    /// FIRST (a cold brain's empty-map skips `subscribe_with`'s `from_seq` reset),\n    /// THEN the cursor is armed, so neither path stamps `MAX`.\n    // [impl->REQ-VIEWER-SKIP-TO-LIVE-ON-EVICT]\n    pub fn attach_skip_to_live(&mut self, session_id: u64, by: Option<&str>) -> io::Result<()> {\n        self.session_id = Some(session_id);\n        self.subscribe_with(session_id, u64::MAX, AttachIntent::Viewer, 0, by.map(str::to_string), None, false)?;\n        self.session_cursors.insert(session_id, 0);\n        self.next_seq = 0;\n        Ok(())\n    }\n…\n    pub fn net_stream_send(\n        &mut self,\n        stream_id: u64,\n        bytes: &[u8],\n        op: Option<MintedOp>,\n        finish: bool,\n    ) -> io::Result<Option<NetSent>> {\n        self.send(\n            KIND_NET_STREAM_SEND,\n            serde_json::to_value(NetStreamSendReq {\n                stream_id,\n                data_b64: encode_bytes(bytes),\n                op_id: op.map(|o| o.seq),\n                minter: op.map(|o| o.minter),\n                finish,\n            })\n            .expect(\"NetStreamSendReq serializes\"),\n        )?;\n        if op.is_none() {\n            return Ok(None);\n        }\n        let want_seq = op.map(|o| o.seq);\n        // [impl->REQ-BRAIN-READ-BOUNDED-PER-CALL]\n        let deadline = self.call_deadline();\n        loop {\n            match self.read_event_until(deadline)? {\n                BrokerEvent::NetSent(ev) if Some(ev.op_id) == want_seq => return Ok(Some(ev)),\n                BrokerEvent::Error { message } => return Err(io::Error::other(message)),\n                _ => continue,\n            }\n        }\n    }\n\n    /// List the streams the broker holds (D4b) — how a re-attaching brain\n…\n    /// (Re)subscribe to a stream's buffered reads from `from_seq`, setting the\n    /// local cursor (gapless, exactly-once resume — the PTY `subscribe`\n    /// discipline on a QUIC stream, D4b).\n    // [impl->REQ-DAEMON-2]\n    pub fn net_stream_subscribe(&mut self, stream_id: u64, from_seq: u64) -> io::Result<()> {\n        self.net_cursors.insert(stream_id, from_seq);\n        self.send(\n            KIND_NET_STREAM_SUBSCRIBE,\n            serde_json::to_value(NetStreamSubscribeReq {\n                stream_id,\n                from_seq,\n            })\n            .expect(\"NetStreamSubscribeReq serializes\"),\n        )\n    }\n\n    /// The next stream-read sequence still needed for `stream_id` (the durable"}],"details":{"displayContent":{"text":"    // [impl->REQ-HAZARD-RESTART-IDEMPOTENT]\n    pub fn send_effect(&mut self, op: MintedOp, bytes: &[u8]) -> io::Result<()> {\n        self.send_effect_inner(op, bytes, true)\n    }\n\n    /// Inject input idempotently like [`Brain::send_effect`] but request NO\n    /// [`KIND_APPLIED`] ack (REQ-HAZARD-INPUT-ACK-BACKPRESSURE). The operator/rc\n    /// attach path is fire-and-forward — `op_id` is for dedup only and the ack is\n    /// discarded by `serve_attach` — and it can flood N input frames on ONE\n    /// brain↔broker conn without returning to read. With no ack the broker's\n    /// per-conn handler never writes back while servicing that flood, so the return\n    /// direction can't fill and deadlock the handler. Exactly-once is preserved: the\n    /// broker still dedups by `(session, op_id)` at its applied-set.\n    // [impl->REQ-HAZARD-INPUT-ACK-BACKPRESSURE]\n    pub fn send_effect_no_ack(&mut self, op: MintedOp, bytes: &[u8]) -> io::Result<()> {\n        self.send_effect_inner(op, bytes, false)\n    }\n\n    /// Shared body for [`Brain::send_effect`] / [`Brain::send_effect_no_ack`]: the\n    /// only difference is whether the broker replies a `KIND_APPLIED` ack. The\n    /// [`MintedOp`] carries both the durable seq and its minter tag (ADR-0034), so\n    /// the wire's `op_id`/`minter` fields are stamped together — an unstamped op is\n    /// uncompilable. The broker's `KIND_APPLIED` still echoes the bare `seq`.\n    fn send_effect_inner(&mut self, op: MintedOp, bytes: &[u8], ack: bool) -> io::Result<()> {\n        let sid = self.require_session()?;\n        self.send(\n            KIND_INPUT,\n            serde_json::to_value(InputReq {\n                session_id: sid,\n                data_b64: encode_bytes(bytes),\n                op_id: Some(op.seq),\n                minter: Some(op.minter),\n                ack,\n            })\n            .expect(\"InputReq serializes\"),\n        )\n    }\n\n    /// Resize the current session's PTY.\n    pub fn resize(&mut self, rows: u16, cols: u16) -> io::Result<()> {\n        let sid = self.require_session()?;\n        self.send(\n            KIND_RESIZE,\n            serde_json::to_value(ResizeReq {\n                session_id: sid,\n                rows,\n                cols,\n            })\n            .expect(\"ResizeReq serializes\"),\n        )\n    }\n\n    /// Terminate the current session's child.\n    pub fn kill_session(&mut self) -> io::Result<()> {\n        let sid = self.require_session()?;\n        self.send(\n            KIND_KILL,\n            serde_json::to_value(KillReq { session_id: sid }).expect(\"KillReq serializes\"),\n        )\n    }\n\n    /// Tear down a hosted session by sid/endpoint key — the endpoint-teardown\n    /// request (ADR-0045 decision 6). Deliberately NOT [`Brain::kill_session`]:\n    /// that one runs `require_session()` on THIS connection's attached session,\n…\n                KIND_NET_STREAM_DATA => {\n                    let ev: NetStreamData = serde_json::from_value(env.payload)\n                        .map_err(|e| io::Error::new(io::ErrorKind::InvalidData, e))?;\n                    // Same exactly-once discipline as PTY output, per stream:\n                    // accept the contiguous next seq, drop a replay duplicate,\n                    // reject a forward gap (a lost chunk must not pass silently).\n                    let cursor = self.net_cursors.entry(ev.stream_id).or_insert(ev.seq);\n                    if ev.seq < *cursor {\n                        continue; // replay duplicate — dedup\n                    }\n                    if ev.seq > *cursor {\n                        return Err(io::Error::new(\n                            io::ErrorKind::InvalidData,\n                            format!(\n                                \"stream {} gap: got seq {} want {}\",\n                                ev.stream_id, ev.seq, *cursor\n                            ),\n                        ));\n                    }\n                    *cursor = ev.seq + 1;\n                    let bytes = decode_bytes(&ev.data_b64)\n                        .map_err(|e| io::Error::new(io::ErrorKind::InvalidData, e))?;\n                    return Ok(BrokerEvent::NetStreamData {\n                        stream_id: ev.stream_id,\n                        seq: ev.seq,\n                        bytes,\n                    });\n                }\n                KIND_NET_STREAM_EOF => {\n                    let ev: NetStreamEof = serde_json::from_value(env.payload)\n                        .map_err(|e| io::Error::new(io::ErrorKind::InvalidData, e))?;\n                    return Ok(BrokerEvent::NetStreamEof {\n                        stream_id: ev.stream_id,\n                        next_seq: ev.next_seq,\n                    });\n                }\n…\n    pub fn attach_as_coded(\n        &mut self,\n        session_id: u64,\n        from_seq: u64,\n        intent: AttachIntent,\n        gen: u64,\n        by: Option<&str>,\n        code: Option<&str>,\n        seal_ceremony: bool,\n    ) -> io::Result<()> {\n        self.session_id = Some(session_id);\n        self.next_seq = from_seq;\n        // #6 (ADR-0031): a COLD attach (`from_seq == 0` — the `rc` / `endpoint run\n        // --attach` case) gets a clean-screen repaint at pseudo-seq\n        // `broker.next_seq - 1` as its first frame; baseline the strict cursor on it\n        // (accept-then-strict). A resume-from-floor re-fetch (`from_seq > 0`) leaves\n        // this false → raw-ring replay + strict reject-gap unchanged (B2).\n        self.baseline_next_output = from_seq == 0;\n        self.subscribe_with(\n            session_id,\n            from_seq,\n            intent,\n            gen,\n            by.map(str::to_string),\n            code.map(str::to_string),\n            seal_ceremony,\n        )\n    }\n\n    /// Re-subscribe a VIEWER from the LIVE TAIL after a broker eviction —\n    /// skip-to-live (REQ-VIEWER-SKIP-TO-LIVE-ON-EVICT). The viewer overflowed its\n    /// bounded subscription queue (it forwards slower than the drain fans out) and\n    /// the broker evicted it (correct session-protection); rather than dying it\n    /// jumps to live and skips the uncatchable backlog (tail -f reconnect).\n    ///\n    /// `from_seq = u64::MAX` makes the broker's ring replay (`s >= from_seq`)\n    /// EMPTY, so the viewer receives only the size frame + live output going\n    /// forward. The next live frame carries the current ring tail's seq — a\n    /// FORWARD JUMP from where this brain was evicted. The legacy `next_seq` dedup\n    /// (the cold serve brain's default) would FATAL that jump as an \"output gap\",\n    /// and a `next_seq = MAX` would DEDUP-DROP every live frame (seq < MAX); so we\n    /// arm the snap-above dedup path (`session_cursors` non-empty) seeded at 0,\n    /// which accepts the jump and snaps. VIEWER-only → B2-safe (a viewer never\n    /// advances `delivered_through` / is not authoritative). The subscribe is sent\n    /// FIRST (a cold brain's empty-map skips `subscribe_with`'s `from_seq` reset),\n    /// THEN the cursor is armed, so neither path stamps `MAX`.\n    // [impl->REQ-VIEWER-SKIP-TO-LIVE-ON-EVICT]\n    pub fn attach_skip_to_live(&mut self, session_id: u64, by: Option<&str>) -> io::Result<()> {\n        self.session_id = Some(session_id);\n        self.subscribe_with(session_id, u64::MAX, AttachIntent::Viewer, 0, by.map(str::to_string), None, false)?;\n        self.session_cursors.insert(session_id, 0);\n        self.next_seq = 0;\n        Ok(())\n    }\n…\n    pub fn net_stream_send(\n        &mut self,\n        stream_id: u64,\n        bytes: &[u8],\n        op: Option<MintedOp>,\n        finish: bool,\n    ) -> io::Result<Option<NetSent>> {\n        self.send(\n            KIND_NET_STREAM_SEND,\n            serde_json::to_value(NetStreamSendReq {\n                stream_id,\n                data_b64: encode_bytes(bytes),\n                op_id: op.map(|o| o.seq),\n                minter: op.map(|o| o.minter),\n                finish,\n            })\n            .expect(\"NetStreamSendReq serializes\"),\n        )?;\n        if op.is_none() {\n            return Ok(None);\n        }\n        let want_seq = op.map(|o| o.seq);\n        // [impl->REQ-BRAIN-READ-BOUNDED-PER-CALL]\n        let deadline = self.call_deadline();\n        loop {\n            match self.read_event_until(deadline)? {\n                BrokerEvent::NetSent(ev) if Some(ev.op_id) == want_seq => return Ok(Some(ev)),\n                BrokerEvent::Error { message } => return Err(io::Error::other(message)),\n                _ => continue,\n            }\n        }\n    }\n\n    /// List the streams the broker holds (D4b) — how a re-attaching brain\n…\n    /// (Re)subscribe to a stream's buffered reads from `from_seq`, setting the\n    /// local cursor (gapless, exactly-once resume — the PTY `subscribe`\n    /// discipline on a QUIC stream, D4b).\n    // [impl->REQ-DAEMON-2]\n    pub fn net_stream_subscribe(&mut self, stream_id: u64, from_seq: u64) -> io::Result<()> {\n        self.net_cursors.insert(stream_id, from_seq);\n        self.send(\n            KIND_NET_STREAM_SUBSCRIBE,\n            serde_json::to_value(NetStreamSubscribeReq {\n                stream_id,\n                from_seq,\n            })\n            .expect(\"NetStreamSubscribeReq serializes\"),\n        )\n    }\n\n    /// The next stream-read sequence still needed for `stream_id` (the durable","startLine":920,"lineNumbers":[920,921,922,923,924,925,926,927,928,929,930,931,932,933,934,935,936,937,938,939,940,941,942,943,944,945,946,947,948,949,950,951,952,953,954,955,956,957,958,959,960,961,962,963,964,965,966,967,968,969,970,971,972,973,974,975,976,977,978,979,980,981,982,983,null,1311,1312,1313,1314,1315,1316,1317,1318,1319,1320,1321,1322,1323,1324,1325,1326,1327,1328,1329,1330,1331,1332,1333,1334,1335,1336,1337,1338,1339,1340,1341,1342,1343,1344,1345,1346,null,1453,1454,1455,1456,1457,1458,1459,1460,1461,1462,1463,1464,1465,1466,1467,1468,1469,1470,1471,1472,1473,1474,1475,1476,1477,1478,1479,1480,1481,1482,1483,1484,1485,1486,1487,1488,1489,1490,1491,1492,1493,1494,1495,1496,1497,1498,1499,1500,1501,1502,1503,1504,1505,1506,null,2101,2102,2103,2104,2105,2106,2107,2108,2109,2110,2111,2112,2113,2114,2115,2116,2117,2118,2119,2120,2121,2122,2123,2124,2125,2126,2127,2128,2129,2130,2131,2132,2133,2134,null,2380,2381,2382,2383,2384,2385,2386,2387,2388,2389,2390,2391,2392,2393,2394,2395,2396]},"fileSize":171079,"meta":{"source":{"type":"path","value":"C:\\Users\\decid\\Documents\\projects\\spt-core\\crates\\spt-daemon\\src\\brain.rs"}}},"isError":false,"timestamp":1789523993582}}
{"type":"message","id":"51bce5b4","parentId":"13e6e16a","timestamp":"2026-09-16T01:59:53.585Z","message":{"role":"toolResult","toolCallId":"call_X60m4vAb3W7SVfS9GBt2pk4n|fc_09b01b5279447709016aa9f8197db487d28e8b4e5f985b11f5","toolName":"read","content":[{"type":"text","text":"fn worker(\n    broker_name: &str,\n    stream_id: u64,\n    origin: &str,\n    floor_seq: u64,\n    finished: bool,\n    paths: &DispatchPaths,\n    registry: &RegistryHost,\n) -> WorkerReport {\n    if take_injected_transient() {\n        return WorkerReport::bare(DispatchOutcome::Failed(\n            \"injected transient worker-start failure (test valve)\".into(),\n        ));\n    }\n    if take_injected_seatblocked() {\n        return WorkerReport::bare(DispatchOutcome::Failed(\n            \"injected subscriber busy failure (test valve)\".into(),\n        ));\n    }\n    let line = match first_line(broker_name, stream_id, floor_seq) {\n        Ok(Some(v)) => v,\n        Ok(None) => return WorkerReport::bare(DispatchOutcome::Unknown),\n        // Pre-serve terminal exclusion (Amendment fix 6 rider): a row that\n        // vanished between enumeration and this query (retired by a sibling\n        // worker's Served report, or conn-swept) is TERMINAL — report Served\n        // so the claim closes now, instead of burning three transient\n        // retries against a stream that no longer exists.\n        // [impl->REQ-SERVE-OWNERSHIP-GENERATION]\n        Err(e) if e.to_string().contains(\"no such stream\") => {\n            return WorkerReport::bare(DispatchOutcome::Served(\n                \"terminal pre-serve: row already gone\".into(),\n            ))\n        }\n        Err(e) => return WorkerReport::bare(DispatchOutcome::Failed(e.to_string())),\n    };\n    let family = classify_first_line(&line);\n    let endpoint = line_endpoint(family, &line);\n\n    if family == StreamFamily::Registry && take_injected_registry_seatblocked() {\n        return WorkerReport {\n            outcome: DispatchOutcome::Failed(\n                \"injected subscriber busy failure (registry test valve)\".into(),\n            ),\n            family: Some(family),\n            endpoint,\n        };\n    }\n\n    // Gate round 1 (retire-on-sight, KNOWN-HAZARDS 7.41): a finished ATTACH\n    // row's exchange is over — the operator detached — and replaying it would\n    // take the live controller (pre-existing backlog + brain-down-detach\n    // orderings, which the Served-report path can never see). Report Served\n    // WITHOUT serving: the loop's completion path retires the row, so the\n    // backlog also drains from the table. Finished request/reply rows fall\n    // through — their FIN is protocol, not completion (see\n    // `finished_row_is_terminal`).\n    if finished_row_is_terminal(family, finished) {\n        return WorkerReport {\n            outcome: DispatchOutcome::Served(\"finished attach: terminal, retired unserved\".into()),\n            family: Some(family),\n            endpoint,\n        };\n    }\n\n    let mut brain = match connect(broker_name) {\n        Ok(b) => b,\n        Err(e) => {\n            return WorkerReport {\n                outcome: DispatchOutcome::Failed(e.to_string()),\n                family: Some(family),\n                endpoint,\n            }\n        }\n    };\n\n    let outcome = match family {\n        StreamFamily::Sync => {\n            let cs = match ContextStore::open_or_init() {\n                Ok(cs) => cs,\n                Err(e) => {\n                    return WorkerReport {\n                        outcome: DispatchOutcome::Failed(e.to_string()),\n                        family: Some(family),\n                        endpoint,\n                    }\n                }\n            };\n            let policy = SyncPolicy::load();\n            match serve_sync(\n                &mut brain,\n                stream_id,\n                origin,\n…\n            ) {\n…\n            }\n        }\n…\n        StreamFamily::Attach => {\n…\n            // from the broker's table (the spawn's label) — never from wire\n            // bytes. An unlabeled or unknown session refuses, fail-closed.\n            //\n            // Cross-node leg (#4, REQ-RC-CROSS-NODE-ATTACH): a REMOTE operator\n            // cannot know our local session id, so it names the ENDPOINT. When the\n            // Request carries `endpoint_id`, THAT is the gate subject — but only if\n            // we actually host a live session for it (D5 session-presence gate;\n            // D6: a stale registry row that named a gone endpoint resolves to no\n            // session → refuse cleanly, never a false attach). The endpoint id is\n            // WHICH endpoint the operator asks for (client-supplied, like the rest\n            // family's `endpoint`); the origin subject stays the handshake identity.\n            // The LOCAL path sends no endpoint_id and its session_id → endpoint\n            // mapping is unchanged.\n            // `endpoint` is the gate subject; `remote_session` carries the\n            // dispatcher-resolved session id on the cross-node leg (resolved HERE,\n            // before serve_attach subscribes — never mid-serve, which would swallow\n            // interleaved attach records) and `None` on the local path.\n            let (endpoint, remote_session) = match line\n                .get(\"endpoint_id\")\n                .and_then(|v| v.as_str())\n                .filter(|e| !e.is_empty())\n            {\n                Some(ep) => match crate::attach::resolve_local_session(&mut brain, ep) {\n                    Some(sid) => (Some(ep.to_string()), Some(sid)),\n                    None => (None, None),\n                },\n                None => {\n                    let session_id = line.get(\"session_id\").and_then(|v| v.as_u64());\n                    let endpoint = session_id.and_then(|sid| {\n                        brain.sessions().ok().and_then(|reply| {\n                            reply\n                                .sessions\n                                .iter()\n                                .find(|s| s.session_id == sid && !s.endpoint.is_empty())\n                                .map(|s| s.endpoint.clone())\n                        })\n                    });\n                    (endpoint, None)\n                }\n            };\n            match endpoint {\n                // Seed the serve loop with the DURABLE opener Request\n                // (ADR-0038 B): after a ring roll the wire replay no longer\n                // carries the Request record, so the serve would idle forever\n                // waiting for one. The pinned opener IS that record — hand it\n                // over so reconstruction resumes the same operator stream.\n                // Subscribe from the ring FLOOR: a rolled ring's chunk 0 is\n                // gone, and a below-floor cursor trips the brain's gap check.\n                // [impl->REQ-STREAM-OPENER-DURABLE]\n                Some(endpoint) => match serve_attach(\n                    &mut brain,\n                    broker_name,\n                    stream_id,\n                    &endpoint,\n                    origin,\n                    floor_seq,\n                    remote_session,\n                    serde_json::from_value(line.clone()).ok(),\n                ) {\n                    Ok(out) => DispatchOutcome::Served(format!(\"{out:?}\")),\n                    Err(e) => DispatchOutcome::Failed(e.to_string()),\n                },\n                None => {\n                    // Refuse politely: finish our send side, claim stays.\n                    let _ = brain.net_stream_send(stream_id, &[], None, true);\n                    DispatchOutcome::Served(\"attach refused: unlabeled/unknown session\".into())\n                }\n            }\n        }\n        // One node-prefixed URL served for a peer's loopback listener. The\n        // subject (the served entry's registering endpoint) is resolved on\n        // the owner from its own registry; the origin it is gated against is\n        // the handshake-proven stream identity, never anything in the line.\n        // [impl->REQ-WEB-CROSS-NODE-PROXY]\n        StreamFamily::Web => match crate::webproxy::serve_web(&mut brain, stream_id, origin, &line) {\n            Ok(out) => DispatchOutcome::Served(format!(\"{out:?}\")),\n…\n        },\n…\n    };\n…\n}"}],"details":{"displayContent":{"text":"fn worker(\n    broker_name: &str,\n    stream_id: u64,\n    origin: &str,\n    floor_seq: u64,\n    finished: bool,\n    paths: &DispatchPaths,\n    registry: &RegistryHost,\n) -> WorkerReport {\n    if take_injected_transient() {\n        return WorkerReport::bare(DispatchOutcome::Failed(\n            \"injected transient worker-start failure (test valve)\".into(),\n        ));\n    }\n    if take_injected_seatblocked() {\n        return WorkerReport::bare(DispatchOutcome::Failed(\n            \"injected subscriber busy failure (test valve)\".into(),\n        ));\n    }\n    let line = match first_line(broker_name, stream_id, floor_seq) {\n        Ok(Some(v)) => v,\n        Ok(None) => return WorkerReport::bare(DispatchOutcome::Unknown),\n        // Pre-serve terminal exclusion (Amendment fix 6 rider): a row that\n        // vanished between enumeration and this query (retired by a sibling\n        // worker's Served report, or conn-swept) is TERMINAL — report Served\n        // so the claim closes now, instead of burning three transient\n        // retries against a stream that no longer exists.\n        // [impl->REQ-SERVE-OWNERSHIP-GENERATION]\n        Err(e) if e.to_string().contains(\"no such stream\") => {\n            return WorkerReport::bare(DispatchOutcome::Served(\n                \"terminal pre-serve: row already gone\".into(),\n            ))\n        }\n        Err(e) => return WorkerReport::bare(DispatchOutcome::Failed(e.to_string())),\n    };\n    let family = classify_first_line(&line);\n    let endpoint = line_endpoint(family, &line);\n\n    if family == StreamFamily::Registry && take_injected_registry_seatblocked() {\n        return WorkerReport {\n            outcome: DispatchOutcome::Failed(\n                \"injected subscriber busy failure (registry test valve)\".into(),\n            ),\n            family: Some(family),\n            endpoint,\n        };\n    }\n\n    // Gate round 1 (retire-on-sight, KNOWN-HAZARDS 7.41): a finished ATTACH\n    // row's exchange is over — the operator detached — and replaying it would\n    // take the live controller (pre-existing backlog + brain-down-detach\n    // orderings, which the Served-report path can never see). Report Served\n    // WITHOUT serving: the loop's completion path retires the row, so the\n    // backlog also drains from the table. Finished request/reply rows fall\n    // through — their FIN is protocol, not completion (see\n    // `finished_row_is_terminal`).\n    if finished_row_is_terminal(family, finished) {\n        return WorkerReport {\n            outcome: DispatchOutcome::Served(\"finished attach: terminal, retired unserved\".into()),\n            family: Some(family),\n            endpoint,\n        };\n    }\n\n    let mut brain = match connect(broker_name) {\n        Ok(b) => b,\n        Err(e) => {\n            return WorkerReport {\n                outcome: DispatchOutcome::Failed(e.to_string()),\n                family: Some(family),\n                endpoint,\n            }\n        }\n    };\n\n    let outcome = match family {\n        StreamFamily::Sync => {\n            let cs = match ContextStore::open_or_init() {\n                Ok(cs) => cs,\n                Err(e) => {\n                    return WorkerReport {\n                        outcome: DispatchOutcome::Failed(e.to_string()),\n                        family: Some(family),\n                        endpoint,\n                    }\n                }\n            };\n            let policy = SyncPolicy::load();\n            match serve_sync(\n                &mut brain,\n                stream_id,\n                origin,\n…\n            ) {\n…\n            }\n        }\n…\n        StreamFamily::Attach => {\n…\n            // from the broker's table (the spawn's label) — never from wire\n            // bytes. An unlabeled or unknown session refuses, fail-closed.\n            //\n            // Cross-node leg (#4, REQ-RC-CROSS-NODE-ATTACH): a REMOTE operator\n            // cannot know our local session id, so it names the ENDPOINT. When the\n            // Request carries `endpoint_id`, THAT is the gate subject — but only if\n            // we actually host a live session for it (D5 session-presence gate;\n            // D6: a stale registry row that named a gone endpoint resolves to no\n            // session → refuse cleanly, never a false attach). The endpoint id is\n            // WHICH endpoint the operator asks for (client-supplied, like the rest\n            // family's `endpoint`); the origin subject stays the handshake identity.\n            // The LOCAL path sends no endpoint_id and its session_id → endpoint\n            // mapping is unchanged.\n            // `endpoint` is the gate subject; `remote_session` carries the\n            // dispatcher-resolved session id on the cross-node leg (resolved HERE,\n            // before serve_attach subscribes — never mid-serve, which would swallow\n            // interleaved attach records) and `None` on the local path.\n            let (endpoint, remote_session) = match line\n                .get(\"endpoint_id\")\n                .and_then(|v| v.as_str())\n                .filter(|e| !e.is_empty())\n            {\n                Some(ep) => match crate::attach::resolve_local_session(&mut brain, ep) {\n                    Some(sid) => (Some(ep.to_string()), Some(sid)),\n                    None => (None, None),\n                },\n                None => {\n                    let session_id = line.get(\"session_id\").and_then(|v| v.as_u64());\n                    let endpoint = session_id.and_then(|sid| {\n                        brain.sessions().ok().and_then(|reply| {\n                            reply\n                                .sessions\n                                .iter()\n                                .find(|s| s.session_id == sid && !s.endpoint.is_empty())\n                                .map(|s| s.endpoint.clone())\n                        })\n                    });\n                    (endpoint, None)\n                }\n            };\n            match endpoint {\n                // Seed the serve loop with the DURABLE opener Request\n                // (ADR-0038 B): after a ring roll the wire replay no longer\n                // carries the Request record, so the serve would idle forever\n                // waiting for one. The pinned opener IS that record — hand it\n                // over so reconstruction resumes the same operator stream.\n                // Subscribe from the ring FLOOR: a rolled ring's chunk 0 is\n                // gone, and a below-floor cursor trips the brain's gap check.\n                // [impl->REQ-STREAM-OPENER-DURABLE]\n                Some(endpoint) => match serve_attach(\n                    &mut brain,\n                    broker_name,\n                    stream_id,\n                    &endpoint,\n                    origin,\n                    floor_seq,\n                    remote_session,\n                    serde_json::from_value(line.clone()).ok(),\n                ) {\n                    Ok(out) => DispatchOutcome::Served(format!(\"{out:?}\")),\n                    Err(e) => DispatchOutcome::Failed(e.to_string()),\n                },\n                None => {\n                    // Refuse politely: finish our send side, claim stays.\n                    let _ = brain.net_stream_send(stream_id, &[], None, true);\n                    DispatchOutcome::Served(\"attach refused: unlabeled/unknown session\".into())\n                }\n            }\n        }\n        // One node-prefixed URL served for a peer's loopback listener. The\n        // subject (the served entry's registering endpoint) is resolved on\n        // the owner from its own registry; the origin it is gated against is\n        // the handshake-proven stream identity, never anything in the line.\n        // [impl->REQ-WEB-CROSS-NODE-PROXY]\n        StreamFamily::Web => match crate::webproxy::serve_web(&mut brain, stream_id, origin, &line) {\n            Ok(out) => DispatchOutcome::Served(format!(\"{out:?}\")),\n…\n        },\n…\n    };\n…\n}","startLine":1034,"lineNumbers":[1034,1035,1036,1037,1038,1039,1040,1041,1042,1043,1044,1045,1046,1047,1048,1049,1050,1051,1052,1053,1054,1055,1056,1057,1058,1059,1060,1061,1062,1063,1064,1065,1066,1067,1068,1069,1070,1071,1072,1073,1074,1075,1076,1077,1078,1079,1080,1081,1082,1083,1084,1085,1086,1087,1088,1089,1090,1091,1092,1093,1094,1095,1096,1097,1098,1099,1100,1101,1102,1103,1104,1105,1106,1107,1108,1109,1110,1111,1112,1113,1114,1115,1116,1117,1118,1119,1120,1121,1122,1123,1124,1125,null,1130,null,1133,1134,null,1158,null,1160,1161,1162,1163,1164,1165,1166,1167,1168,1169,1170,1171,1172,1173,1174,1175,1176,1177,1178,1179,1180,1181,1182,1183,1184,1185,1186,1187,1188,1189,1190,1191,1192,1193,1194,1195,1196,1197,1198,1199,1200,1201,1202,1203,1204,1205,1206,1207,1208,1209,1210,1211,1212,1213,1214,1215,1216,1217,1218,1219,1220,1221,1222,1223,1224,1225,1226,1227,1228,1229,1230,1231,1232,1233,1234,1235,null,1237,null,1283,null,1311]},"fileSize":171439,"meta":{"source":{"type":"path","value":"C:\\Users\\decid\\Documents\\projects\\spt-core\\crates\\spt-daemon\\src\\dispatch.rs"}}},"isError":false,"timestamp":1789523993584}}
{"type":"message","id":"1dc9d9ea","parentId":"51bce5b4","timestamp":"2026-09-16T01:59:53.595Z","message":{"role":"toolResult","toolCallId":"call_caWhxBZTNzQKxOMBXAI1Onbx|fc_09b01b5279447709016aa9f8197dbc87d2b5d151041ac47b66","toolName":"grep","content":[{"type":"text","text":" 69|    KIND_NET_STATUS, KIND_NET_STATUS_REPLY, KIND_NET_STREAMS, KIND_NET_STREAMS_REPLY,\n*70|    KIND_NET_STREAM_OPEN, KIND_NET_STREAM_OPENED, KIND_NET_STREAM_OPENER, KIND_NET_STREAM_OPENER_REPLY, KIND_NET_STREAM_RETIRE, KIND_NET_STREAM_RETIRED, KIND_NET_STREAM_SEND, KIND_NET_STREAM_SUBSCRIBE,\n 71|    KIND_NET_STREAM_UNSUBSCRIBE, KIND_NET_STREAM_UNSUBSCRIBED,\n 72|    KIND_MET_MEMBER, KIND_PAIR_CODE_SUBMIT, KIND_PAIR_JOIN, KIND_PAIR_JOINED, KIND_PAIR_MEET, KIND_RESIZE, KIND_SESSIONS, KIND_SESSIONS_REPLY, KIND_SPAWN,\n 73|    BringUpReq, BroughtUpReply, BRING_UP_ADMITTED, BRING_UP_ADMIT_PREFIX, BRING_UP_ALREADY_LIVE, BRING_UP_REFUSED, KIND_BRING_UP, KIND_BROUGHT_UP,\n...\n 86|/// The shared, serialized send side of one brain connection. Output frames,\n*87|/// replay frames, command acks, and exit/error events all write through this.\n 88|/// `pub(crate)`: the net host's stream logs (D4b) live-send through the same\n 89|/// handle under the same gate discipline. Round-4\n 90|/// (REQ-HAZARD-SHAREDSEND-NO-BLOCKING-WRITE-UNDER-LOCK): no longer a raw\n...\n 93|/// matching stays `Arc::ptr_eq`.\n*94|pub(crate) type SharedSend = Arc<BrokerConn>;\n 95|\n 96|/// Default bounded output-log depth (chunks). Large enough that a brain restart\n 97|/// window never evicts unreplayed output in practice; the bound is what keeps a\n...\n 125|/// thread `try_send`s output frames into `tx` (a bounded queue); a dedicated\n*126|/// `writer` thread does the BLOCKING socket write, so a wedged viewer backs up\n 127|/// only its own queue — never the drain. When the queue overflows the sink is\n 128|/// dropped (the `tx` closes → the writer ends) and removed from the map.\n 129|struct ViewerSink {\n...\n 133|    /// (a dropped brain connection removes its viewer rows); never written here.\n*134|    send: SharedSend,\n 135|    /// The viewer's ORIGIN NODE hex, when it presented one (`None` for a local\n 136|    /// viewer that carries no node identity) — RETAINED for attachment-frame\n 137|    /// composition ONLY (releases#44, REQ-ATTACH-LINK-PUSH).\n...\n 165|/// merely-slow controller DROPS chunks + falls behind the ring, and only a channel\n*166|/// that stays full for [`CONTROLLER_WRITE_DEADLINE`] (tracked via\n 167|/// [`ControllerSink::last_ok`]) is detached. Generous so a momentary slow consumer\n 168|/// never trips the deadline.\n 169|const CONTROLLER_CHANNEL_DEPTH: usize = 4096;\n...\n 173|/// (W1, refined by b4 / REQ-HAZARD-VIEWER-STARVE-UNDER-CONTROLLER-BACKPRESSURE). This\n*174|/// BOUNDS the wedge: a backed-up controller falls behind for at most this long before\n 175|/// eviction — never forever (the v0.12.x root) — and the drain NEVER blocks or sleeps\n 176|/// (a single off-lock `try_send` per chunk; see [`OutputLog::append`]). A live but\n 177|/// merely slow operator lands a frame before this elapses (resetting `last_ok`) and is\n...\n 210|/// How long a controller's writer thread may sit BLOCKED inside a single socket\n*211|/// write — the brain subscriber suspended / black-holed — before a take/reattach\n 212|/// or the `KIND_SESSIONS` reap stall-evicts it (LIFECYCLE-TRUTH W2,\n 213|/// REQ-HAZARD-BROKER-VIEWER-BRAIN-DECOUPLE). Distinct from and 3× longer than\n 214|/// [`CONTROLLER_WRITE_DEADLINE`] on PURPOSE (doyle ruling Q1): that 5 s bound\n...\n 320|    // every claim read stalled, so every duplicate wake takes over and the double-create\n*321|    // this function exists to prevent comes back at scale. Compiled out of release\n 322|    // entirely, parsed once, and floored so that even in a debug build it cannot be\n 323|    // driven below a value the gate could mistake for a wedge on a healthy holder.\n 324|    #[cfg(debug_assertions)]\n...\n 437|/// An error forbids both kill and forced de-tabling: dropping session resources\n*438|/// is teardown too, not a safe fallback for an identity we could not establish.\n 439|// [impl->REQ-BROKER-ZOMBIE-IDENTITY]\n 440|fn reap_zombie_root(\n 441|    pid: Option<u32>,\n...\n 472|/// PURE resolution of the two liveness probes for [`session_is_zombie`], so the\n*473|/// NO-SNAPSHOT arm is unit-testable WITHOUT a platform that lacks a process\n 474|/// table (the W1 `unconfirmed_verdict` injection shape).\n 475|///\n 476|/// The table WINS wherever it speaks — that is the Windows fix, since a\n...\n 478|/// handle probe is sound: no-table implies unix implies no handle blind spot,\n*479|/// so the two conditions cannot both fail and the fallback is EXACT.\n 480|// [impl->REQ-LIVENESS-ORACLE-SOUND]\n 481|fn resolve_wrapper_alive(table_says: Option<bool>, handle_says: impl FnOnce() -> bool) -> bool {\n 482|    table_says.unwrap_or_else(handle_says)\n...\n 493|    // root that is NOT adapter-labeled was claimed LIVE indefinitely.\n*494|    // NO-SNAPSHOT FALLS BACK, and the fallback is EXACT rather than a\n 495|    // compromise: the handle blind spot is Windows-only (`kill(pid,0)` answers\n 496|    // about the process, not about a handle the caller holds, and Linux demotes\n 497|    // a /proc zombie), while Windows ALWAYS has a process table. So \"no table\"\n...\n 672|/// budget shape: consecutive-failures bounded, healthy-run resets). Mirrors the\n*673|/// psyche crash-loop backoff's bounded give-up.\n 674|const TRANSLATE_RESPAWN_BUDGET: u32 = 3;\n 675|\n 676|/// The effective respawn budget. Production is the const above; the int gate tunes\n...\n 694|// after typing → re-drive once → LOUD spool (silent+unrecoverable → recoverable+loud);\n*695|// (3) chunked-paced write under the gate (bracketed-paste deferred — the binary owns\n 696|// the key/text interleave, not a clean wrap seam; F-019 found it moot for CC submit).\n 697|\n 698|/// The settle-gate deadline (Layer 1): how long the worker probes a PTY for a\n...\n 724|/// The echo-verify wait (Layer 2): how long the worker waits after a `{commit}` for\n*725|/// the typed payload's head to echo back on the session ring before declaring a\n 726|/// verify MISS (round-trip + XON-resume latency bound).\n 727|const INJECT_ECHO_VERIFY_DEADLINE: Duration = Duration::from_millis(1200);\n 728|\n...\n 749|\n*750|/// Chunk size for the paced text write (Layer 3, the ruling's named fallback where\n*751|/// bracketed-paste is not declared): a large payload is enqueued in bounded chunks\n 752|/// rather than one write, so no single huge write races the terminal's coalescer.\n 753|/// Layered UNDER the settle-gate (the reader is already confirmed live before the\n 754|/// first chunk). The int gate tunes it via `SPT_INJECT_TEXT_CHUNK`.\n...\n 763|\n*764|/// Does `haystack` contain `needle` as a contiguous subslice? (Small, allocation-free\n 765|/// — the echo-verify head match over concatenated ring bytes.)\n*766|fn contains_subslice(haystack: &[u8], needle: &[u8]) -> bool {\n 767|    if needle.is_empty() {\n 768|        return true;\n 769|    }\n*770|    if needle.len() > haystack.len() {\n 771|        return false;\n 772|    }\n*773|    haystack.windows(needle.len()).any(|w| w == needle)\n 774|}\n 775|\n 776|/// Pure echo-verify decision (Layer 2, REQ-INJECT-MULTILINE-INTEGRITY): did the\n*777|/// typed payload's HEAD echo back? Compare a bounded prefix of `sent_text` against\n 778|/// the PTY echo captured since the sequence began. A TUI re-renders typed text so the\n 779|/// leading bytes appear in output; a swallowed head means the prefix is ABSENT. An\n 780|/// empty payload (a keys-only sequence — no echoable text) is vacuously verified.\n...\n 823|/// Symmetric with [`ViewerSink`] — a dedicated writer thread does the BLOCKING\n*824|/// socket write so a backed-up controller can never stall the session drain\n 825|/// thread (the v0.12.x wedge: the controller write was inline on the drain,\n 826|/// holding `Mutex<OutputLog>`). Unlike a viewer it is AUTHORITATIVE: its writer\n 827|/// advances `delivered_through` on each successful write, and it is never evicted\n...\n 833|    /// for the `exit`-frame fan-out ([`OutputLog::all_sinks`]).\n*834|    send: SharedSend,\n 835|    /// The controller's ATTACH GENERATION (ADR-0038 Amendment fix 6,\n 836|    /// REQ-SERVE-OWNERSHIP-GENERATION): operator-minted wall-ms from the wire\n 837|    /// Request (`0` = local / N-1). A same-identity re-take with an OLDER\n...\n 873|    /// `Some(Instant::now())` immediately BEFORE it enters a blocking `write_frame`\n*874|    /// and back to `None` the instant the write returns. A reader\n 875|    /// ([`OutputLog::controller_stalled`]) sees a `Some` older than\n*876|    /// [`BRAIN_WRITE_DEADLINE`] as a writer WEDGED on a suspended/black-holed brain\n 877|    /// conn and stall-evicts it — the signal `last_ok` (channel-handoff time) cannot\n 878|    /// give: an IDLE controller (writer parked on `rx.recv()`, `None` here) and a\n 879|    /// BLOCKED one (writer stuck in the socket write, `Some` here) both leave\n...\n 900|\n*901|/// One run of held-back output inside a resize transition, tagged with the\n 902|/// GEOMETRY (and its epoch) the bytes were EMITTED under\n 903|/// (REQ-RC-RESIZE-GEOMETRY-EPOCH). The grid replays each segment at its OWN\n 904|/// geometry, which is the whole content of \"every byte is parsed at the geometry\n...\n 918|/// Amendment II). While one of these is installed, [`OutputLog::append`] still\n*919|/// assigns a `seq` and RINGS every chunk — the ring stays the scrollback/resume\n 920|/// authority for raw history — but delivery to the controller and the viewers is\n 921|/// SUPPRESSED (a skip, never a block: the drain runs at full PTY speed, hazard\n*922|/// 7.12 intact), and the chunk is held back from `grid.advance`, tagged with the\n 923|/// geometry it was emitted under. [`OutputLog::commit_resize`] /\n 924|/// [`OutputLog::abort_resize`] then replay the held segments into the grid at\n 925|/// their own geometries and substitute ONE synthesized sync frame to every\n...\n 939|    /// The geometry (and epoch) in force when the barrier closed — where the grid\n*940|    /// still is, and what a rollback returns to.\n 941|    from: (u16, u16),\n 942|    from_epoch: u64,\n 943|    /// The requested target geometry (and the epoch it opens).\n...\n 1044|    /// of replaying the whole ring from 0. **Viewer writes NEVER move it**\n*1045|    /// (REQ-RCVIEW-1: the brain-resume cursor tracks the controller only).\n 1046|    ///\n 1047|    /// **Advanced only on a successful socket write** (`Ok`), and **monotonic**\n 1048|    /// (never decreases) — see [`advanced_cursor`]. Both invariants are\n...\n 1064|    /// instead of the raw ring, so replaying an alt-screen TUI into a fresh terminal\n*1065|    /// no longer corrupts scrollback. Single-writer (the one drain thread), mirroring\n 1066|    /// the ring's single producer.\n 1067|    grid: ScreenGrid,\n 1068|    /// The grid's GEOMETRY EPOCH (REQ-RC-RESIZE-GEOMETRY-EPOCH): monotonic, bumped\n...\n 1099|    /// teardown. The ring deliberately keeps the suppressed raw bytes (it is the\n*1100|    /// scrollback authority), so a resume asking BELOW this floor would replay\n*1101|    /// mixed-geometry corruption straight back onto a live terminal; instead it\n 1102|    /// is served the cold-attach shape ([`repaint_initial`]: sync repaint + skip\n 1103|    /// to live). At-least-once holds in effect — the repaint supersedes the\n 1104|    /// skipped range. `0` until a transition has ever torn down (no boundary to\n...\n 1109|/// The post-write resume cursor (pure — the D4-1 unit kernel, mirroring\n*1110|/// `brainproc::consumer_gate`/`next_backoff`): advance to `seq + 1` **only** on a\n 1111|/// successful write, and **monotonically** (never below `current`). A failed\n 1112|/// write (`write_ok == false`) leaves the cursor untouched, and a re-send of an\n 1113|/// already-delivered `seq` (an `attach(sub, 0)` rewind, `seq + 1 <= current`)\n...\n 1473|    /// ring torn — an over-cap ring (interrupted prune), a last seq not below\n*1474|    /// `next_seq`, or a non-monotonic front/back — and serving those bytes blind\n 1475|    /// risks garbage to a subscriber. Cheap-check the ring invariants (counts within\n 1476|    /// cap, indices ordered and below `next_seq`); on ANY violation RESET the ring\n 1477|    /// EMPTY (+ loud log) — `next_seq` is left intact so cursors never rewind, and the\n*1478|    /// lost scrollback self-heals on the next PTY output + repaint. Returns `true`\n 1479|    /// iff it reset. A coherent ring (the common case — most panics fire OUTSIDE the\n 1480|    /// ring mutation, poisoning the lock while the buffer stays intact) is untouched.\n 1481|    // [impl->REQ-HAZARD-BROKER-FLOOR-LOCK-POISON]\n...\n 1483|        let within_cap = self.ring.len() <= self.cap_chunks;\n*1484|        let last_below_next = match self.ring.back() {\n 1485|            Some(&(last, _)) => last < self.next_seq,\n 1486|            None => true,\n 1487|        };\n*1488|        let ordered = match (self.ring.front(), self.ring.back()) {\n*1489|            (Some(&(front, _)), Some(&(back, _))) => front <= back,\n 1490|            _ => true,\n 1491|        };\n 1492|        if within_cap && last_below_next && ordered {\n...\n 1498|            \"broker: session {} output ring was torn by a poison-recover \\\n*1499|             (had {had} chunks, next_seq {}); reset to empty — scrollback self-heals \\\n 1500|             on the next output [REQ-HAZARD-BROKER-FLOOR-LOCK-POISON]\",\n 1501|            self.session_id, self.next_seq\n 1502|        );\n...\n 1513|    /// Concatenate ring bytes at or after `from_seq` — the output PRODUCED since a\n*1514|    /// snapshot, used to confirm a typed payload's head echoed back (integrity,\n 1515|    /// Layer 2; readiness Layer 1 gates on `high_water` alone — the probe's own\n 1516|    /// echo is a DSR query the drain strips before append, REQ-DSR-SINGLE-CPR).\n 1517|    /// Best-effort: bytes pruned out of the bounded ring are simply absent (the\n...\n 1531|        self.next_seq += 1;\n*1532|        self.ring.push_back((seq, bytes.to_vec()));\n 1533|        while self.ring.len() > self.cap_chunks {\n 1534|            self.ring.pop_front();\n 1535|        }\n...\n 1618|    /// `SessionInfo.controller_by == None` is ambiguous between empty and\n*1619|    /// local). `None` = no controller at all. The `SharedSend` rides along for\n 1620|    /// the bounded direct-write degrade the exit fan-out uses.\n 1621|    // [impl->REQ-SEAL-NO-CEREMONY-SURFACE]\n*1622|    fn ceremony_surface(&self) -> Option<(SyncSender<CtrlMsg>, SharedSend, u64, bool)> {\n 1623|        self.controller\n 1624|            .as_ref()\n 1625|            .map(|c| (c.tx.clone(), Arc::clone(&c.send), c.send.id(), c.seal_ceremony))\n...\n 1630|    /// seated (Controller / TookControl / the idempotent replay all qualify;\n*1631|    /// a Busy refusal or a viewer fallback must not touch someone else's\n 1632|    /// seat). Runs AFTER the ladder so the ladder stays capability-blind.\n 1633|    // [impl->REQ-SEAL-NO-CEREMONY-SURFACE]\n 1634|    fn stamp_controller_seal_ceremony(&mut self, conn: u64, seal_ceremony: bool) {\n...\n 1684|        // A local IPC subscribe carries no origin and is this node by\n*1685|        // construction; a local `rc` arrives over the in-process loopback conn\n 1686|        // stamped with our OWN handshake-proven id, so both spellings of \"here\"\n 1687|        // must answer the same.\n 1688|        let from_this_node = match by {\n...\n 1815|            // here would let anyone on the box ratchet the human toward a\n*1816|            // backoff by replaying a dead ticket.\n 1817|            // [impl->REQ-ER-BRINGUP-SPAWNS-SESSION]\n 1818|            AdmitTicket::Unredeemed => {\n 1819|                return SeatGate::Refused(\n...\n 1874|/// a credential the gate did not itself verify\") is untouched. What travels is\n*1875|/// the broker's own verdict, keyed by an id a caller can only echo back.\n 1876|///\n 1877|/// The SESSION LABEL travels for a reason that is not convenience: the grant is\n 1878|/// keyed on the session it empowers, and at bring-up time the engine room's\n...\n 1995|    // configuration, not a failed guess, so it must not spend a unit of the\n*1996|    // attempt budget the human needs to get back to the controls.\n 1997|    // `classify_bringup` still rules on it; it simply rules over a ledger\n 1998|    // nothing loaded (`default()` is not a claim about the file — the\n 1999|    // NoAdapter arm ignores the attempt entirely, and nothing is persisted).\n...\n 2014|    // attempt bound's business. Keeping that input a bool is what stops #102\n*2015|    // from touching the backoff schedule at all.\n 2016|    //\n 2017|    // What the presentation type adds is orthogonal (releases#197): an ABSENT\n 2018|    // code is not a failed guess at all, so it must not spend a unit of the\n...\n 2157|/// several stores, and the seat resolver that calls this runs under the lock the\n*2158|/// output drain needs. Fire-and-forget with a LOUD stderr fallback — silence is\n 2159|/// the one thing brute force is buying, so a failure to alert must not itself be\n*2160|/// quiet. The ledger's own backoff gates this path, so it cannot be sprayed.\n 2161|///\n 2162|/// Free-standing because the gate it belongs to is now asked by a caller with no\n 2163|/// session (the bring-up verb): an alert that only fired for one of the two\n...\n 2203|/// A single immediate attempt would therefore miss intermittently and leave the\n*2204|/// row pending forever — the defect back, just rarer and harder to see. So this\n 2205|/// polls the eligibility predicate under a bound and drives once it holds.\n 2206|///\n 2207|/// **Never a refusal, loud on failure** (clause 4, the denial-of-governance\n...\n 2407|    /// the admin bring-up's empowerment (releases#102), spool the briefing that\n*2408|    /// states it, and hand back the operator-facing sentence for the reply.\n 2409|    ///\n 2410|    /// **Why this is not done at the gate, which is where the credential is\n 2411|    /// known.** Two things happen between the gate and a resolved seat, and both\n...\n 2479|        // the endpoint keeps running between attachments — so a human who\n*2480|        // detaches and comes back to the SAME live session is re-handed a\n 2481|        // posture statement they already read, while nothing about the session\n 2482|        // is new. A FRESH session — a new bring-up, or a daemon restart that\n 2483|        // re-hosts one — starts a new log and briefs exactly as before.\n...\n 2560|    /// several stores, and this resolver runs under the lock the output drain\n*2561|    /// needs. Fire-and-forget with a LOUD stderr fallback — silence is the one\n 2562|    /// thing brute force is buying, so a failure to alert must not itself be\n*2563|    /// quiet. The ledger's own backoff gates this path, so it cannot be sprayed.\n 2564|    /// Controller-bound authority (ADR-0052 §3a): a seat change or release\n 2565|    /// DROPS every empowerment the engine room's session holds.\n 2566|    ///\n...\n 2591|\n*2592|    fn become_controller(&mut self, sub: SharedSend, by: Option<String>, from_seq: u64, attach_gen: u64) {\n 2593|        // Drop the prior controller sink first (its writer's live loop ends when\n 2594|        // tx drops), and bump the generation so (a) an in-flight deadline-evict\n 2595|        // for the old controller can't unseat this one and (b) a prior writer\n...\n 2835|    /// socket write for at least `deadline` (the brain-subscriber conn suspended /\n*2836|    /// black-holed). An IDLE controller (writer parked on `rx.recv()`, nothing to\n 2837|    /// write) reads NOT stalled: its [`ControllerSink::write_blocked_since`] is `None`.\n 2838|    /// Pure over the injected `now` + `deadline` so the unit tests it with no thread.\n 2839|    // [impl->REQ-HAZARD-BROKER-VIEWER-BRAIN-DECOUPLE]\n...\n 2852|    /// it (REQ-UPDATE-PROMOTE-DRAINED). A killed OLD brain generation whose local\n*2853|    /// controller conn is black-holed reads wedged here until the W2 stall-evict\n 2854|    /// releases it (or the conn EOFs); a cleanly-closed conn is simply absent. A\n 2855|    /// REMOTE operator's wedged conn (`by: Some`) is the W2 stall-evict concern, NOT\n 2856|    /// an old-gen brain conn, so it is EXCLUDED — a stuck remote viewer must never\n...\n 2885|            \"BRAIN_SUBSCRIBER_STALL_EVICT:{} conn={conn} {} — controller writer blocked > {}ms \\\n*2886|             on a suspended/black-holed brain conn; detached, driven_by released \\\n 2887|             [REQ-HAZARD-BROKER-VIEWER-BRAIN-DECOUPLE]\",\n 2888|            self.session_id,\n 2889|            crate::conn::log_stamp(),\n...\n 2907|    /// live queue. The drain thread fans live frames in via `try_send`.\n*2908|    fn add_viewer(&mut self, sub: SharedSend, from_seq: u64, by: Option<&str>) {\n 2909|        let vid = self.next_viewer_id;\n 2910|        self.next_viewer_id += 1;\n 2911|        // Attribution (F-039 legs b+d): viewer role fact + attach record.\n...\n 2984|        &mut self,\n*2985|        sub: SharedSend,\n 2986|        from_seq: u64,\n 2987|        intent: AttachIntent,\n 2988|        by: Option<String>,\n...\n 3001|        &mut self,\n*3002|        sub: SharedSend,\n 3003|        from_seq: u64,\n 3004|        intent: AttachIntent,\n 3005|        by: Option<String>,\n...\n 3084|        &mut self,\n*3085|        sub: SharedSend,\n 3086|        from_seq: u64,\n 3087|        intent: AttachIntent,\n 3088|        by: Option<String>,\n...\n 3117|        &mut self,\n*3118|        sub: SharedSend,\n 3119|        from_seq: u64,\n 3120|        intent: AttachIntent,\n 3121|        by: Option<String>,\n...\n 3153|        // W2 decouple (REQ-HAZARD-BROKER-VIEWER-BRAIN-DECOUPLE): a controller WEDGED\n*3154|        // on a suspended/black-holed brain conn past BRAIN_WRITE_DEADLINE is\n 3155|        // stall-evicted HERE — the take/reattach self-heals against broker truth\n 3156|        // without waiting for new output (the output-driven mark_controller_gone\n 3157|        // never fires on an idle session). Inline stamp: this path already writes the\n...\n 3176|            //   gen <  incumbent (nonzero)  → a REPLAYED stale Request (an\n*3177|            //     unfinished backlog row whose viewport died raw) — refused\n*3178|            //     busy; the ladder never runs backwards.\n 3179|            //   gen >  incumbent (nonzero)  → the LIVE replacement viewport,\n 3180|            //     Control or Take alike: loud+fenced SUPERSESSION via the full\n 3181|            //     W2 revoke (terminal Displaced + fence moves with the slot) —\n...\n 3255|            // The LOCAL brain re-attaching while a REMOTE controls — never steal;\n*3256|            // fall back to a silent viewer (gate #7 for the local-resume path).\n 3257|            // `by` is None on this arm by construction, so the sink retains no node.\n 3258|            self.add_viewer(sub, from_seq, None);\n 3259|            self.stamp_viewer_count();\n...\n 3294|    /// (REQ-RC-RESIZE-GEOMETRY-EPOCH). From here until commit/abort every appended\n*3295|    /// chunk is held back from the grid and tagged with the geometry it was emitted\n*3296|    /// under. Returns the geometry the grid is currently at (the rollback target).\n 3297|    ///\n 3298|    /// A second concurrent transition is REFUSED rather than queued: the caller is\n 3299|    /// the session's controller (resize is controller-exclusive), so two overlapping\n...\n 3391|    /// transition landed on, concatenated with the `deferred` non-grid bytes the\n*3392|    /// capture-mode replay collected (leg 5: untracked stateful toggles,\n 3393|    /// one-shots and child→client queries, verbatim in emission order) — pushed\n 3394|    /// to every attached sink under the caller's single lock acquisition,\n 3395|    /// substituting for everything delivery suppressed.\n...\n 3459|    /// CAPTURE MODE (the one parser authority — never a second scanner over raw\n*3460|    /// bytes): every sequence the grid does not track is re-encoded into the\n 3461|    /// returned buffer, verbatim in emission order, for the sync frame to flush\n 3462|    /// (REQ-RC-RESIZE-PRESENTATION-BARRIER leg 5 — the non-grid bytes a bare\n 3463|    /// repaint would silently drop).\n...\n 3546|    // [impl->REQ-SERVE-OWNERSHIP-GENERATION]\n*3547|    fn detach_if_gen(&mut self, sub: &SharedSend, gen: Option<u64>) {\n 3548|        if let (Some(g), Some(c)) = (gen, self.controller.as_ref()) {\n 3549|            if c.attach_gen != g {\n 3550|                // Stale generation: never clears the (newer) controller.\n...\n 3561|\n*3562|    fn detach_if(&mut self, sub: &SharedSend) {\n 3563|        let is_ctrl = self\n 3564|            .controller\n 3565|            .as_ref()\n...\n 3716|    /// Whether `sub` is the current controller (the resize-exclusivity check).\n*3717|    fn is_controller(&self, sub: &SharedSend) -> bool {\n 3718|        self.controller\n 3719|            .as_ref()\n 3720|            .is_some_and(|c| Arc::ptr_eq(&c.send, sub))\n...\n 3757|fn viewer_writer(\n*3758|    send: SharedSend,\n 3759|    session_id: u64,\n 3760|    initial: Vec<Envelope>,\n 3761|    rx: Receiver<Envelope>,\n...\n 3767|    struct ExitNote {\n*3768|        send: SharedSend,\n 3769|        session_id: u64,\n 3770|        reason: &'static str,\n 3771|    }\n...\n 3872|struct ExitFanout {\n*3873|    controller: Option<(SyncSender<CtrlMsg>, SharedSend)>,\n*3874|    viewers: Vec<(SyncSender<Envelope>, SharedSend)>,\n 3875|}\n 3876|\n 3877|/// How long the exit waiter re-tries a Full sink queue before degrading to the\n...\n 3882|/// Bounded enqueue-behind-output: retry a Full queue up to\n*3883|/// [`EXIT_ENQUEUE_DEADLINE`], then fall back to the direct bounded conn write\n 3884|/// (the pre-W3 behavior, now the loud DEGRADE instead of the default).\n 3885|/// [impl->REQ-BROKER-OUTPUT-BEFORE-EXIT]\n*3886|fn enqueue_exit_bounded<T>(tx: &SyncSender<T>, mut msg: T, sink: &SharedSend, frame: &Envelope) {\n 3887|    let deadline = Instant::now() + EXIT_ENQUEUE_DEADLINE;\n 3888|    loop {\n 3889|        match tx.try_send(msg) {\n...\n 3929|/// (`seq > cursor` — a frame the drain dropped while the controller channel was Full,\n*3930|/// the b4 backpressure) FREEZES the cursor at last-contiguous, so a re-attaching\n 3931|/// brain's `resume_seq` never skips a dropped chunk (a high-watermark jump PAST the\n 3932|/// gap would be a not-exactly-once / non-gapless resume = a B2 violation). An\n 3933|/// already-delivered `seq` (`seq < cursor`, a rewind re-send) is a no-op. A single CAS,\n...\n 3944|/// cursor on each success), then drain live [`CtrlMsg`]s with a BLOCKING socket\n*3945|/// write each — so a backed-up controller blocks ONLY this thread, never the\n 3946|/// session drain (which used to write the controller inline under the log lock).\n 3947|/// A failed write (dead operator) ends the thread; the drain's next bounded\n 3948|/// send then sees `Disconnected` and detaches the row. `Output` advances\n...\n 3956|    sid: u64,\n*3957|    send: SharedSend,\n 3958|    initial: Vec<(u64, Vec<u8>)>,\n 3959|    // Whether `initial` is a synthesized repaint batch (rides the wire-flag —\n 3960|    // the consumer baselines its pseudo-seq jump) vs a raw ring slice\n...\n 3989|    // (same-lease) replacements never set the marker, so gate-#7 stays silent.\n*3990|    let emit_revoke_if_marked = |send: &SharedSend| {\n 3991|        let by = revoked_by.lock().ok().and_then(|mut g| g.take());\n 3992|        if let Some(by) = by {\n 3993|            let _ = send.write(&displaced_envelope(sid, &by));\n...\n 4074|        // a superseded writer's channel holds only its pre-supersede output\n*4075|        // backlog (seq the consumer dedups via snap-above). The loop ends\n 4076|        // naturally when `tx` drops — and a REVOKED replacement then emits the\n*4077|        // terminal `Displaced` below, BEHIND this drained backlog (order\n 4078|        // preserved), instead of racing it through the live queue. The reorder\n 4079|        // hazard is the INITIAL-BATCH replay, gated above.\n 4080|        mark_blocked(true);\n...\n 4253|    /// the next accepted enqueue (heal-on-resume). Mirrored to the perch's\n*4254|    /// `input_backpressure` so the operator sees the drop.\n*4255|    backpressure: AtomicBool,\n 4256|    /// The owning endpoint (the spawn's label; empty = unlabeled / raw test) —\n*4257|    /// the perch whose `input_backpressure` this stamps. Empty ⇒ nowhere to record.\n 4258|    endpoint: String,\n 4259|    /// The writer thread handle (held for ownership; the thread drains until the\n 4260|    /// last `tx` clone drops at session teardown, then exits).\n...\n 4274|            deliveries,\n*4275|            backpressure: AtomicBool::new(false),\n 4276|            endpoint,\n 4277|            _writer: writer,\n 4278|        })\n...\n 4302|            Ok(()) => {\n*4303|                // Heal: input is flowing again — clear a prior backpressure stamp.\n*4304|                if self.backpressure.swap(false, Ordering::AcqRel) {\n*4305|                    self.stamp_backpressure(false);\n 4306|                }\n 4307|                true\n 4308|            }\n...\n 4311|                // DROP + surface, but stamp only on the rising edge.\n*4312|                if !self.backpressure.swap(true, Ordering::AcqRel) {\n*4313|                    self.stamp_backpressure(true);\n 4314|                }\n 4315|                false\n 4316|            }\n...\n 4324|\n*4325|    /// Mirror the input-backpressure signal to the perch's `info.json` (the\n 4326|    /// broker is the single writer). Best-effort: a session served without a\n 4327|    /// perch (raw broker tests) has nowhere to record.\n*4328|    fn stamp_backpressure(&self, dropping: bool) {\n 4329|        if self.endpoint.is_empty() {\n 4330|            return;\n 4331|        }\n 4332|        let perch = resolve_perch_path(&self.endpoint, ParentHint::Infer);\n*4333|        let _ = spt_store::info::set_input_backpressure(&perch, dropping);\n 4334|    }\n 4335|}\n 4336|\n...\n 4396|/// leave the ring torn (a bumped `next_seq` past the ring, an over-cap ring from an\n*4397|/// interrupted prune, a non-monotonic front/back), and replaying those bytes to a\n 4398|/// subscriber risks garbage. So ONLY on the recovered (poisoned) branch, run\n 4399|/// [`OutputLog::clamp_or_reset`]: cheap-check the ring invariants and RESET it empty\n*4400|/// (+ loud log) on any violation. Lost scrollback self-heals on the next PTY output +\n 4401|/// repaint — strictly better than a permanent wedge (fail-fast reintroduces the very\n 4402|/// wedge B-1 kills) or a torn serve (blind recover). The healthy `Ok` path is a pure\n 4403|/// lock — no clamp, no cost on the hot append path.\n...\n 4525|        // UNCOALESCED: the count IS the news past the third failure, and the\n*4526|        // ledger's backoff already bounds how fast this path can fire.\n 4527|        None,\n 4528|        None,\n 4529|        &policy,\n...\n 4539|// [impl->REQ-SEAL-CEREMONY-TOTP]\n*4540|fn reply_seal_ceremony(send: &SharedSend, outcome: &str, detail: String, token: Option<String>) {\n 4541|    let payload = serde_json::to_value(SealCeremonyReply {\n 4542|        outcome: outcome.to_string(),\n 4543|        detail,\n...\n 4640|/// — the seal sibling of [`alert_bringup_brute_force`], same shape: off the\n*4641|/// dispatch thread, fire-and-forget with a LOUD stderr fallback (silence is\n 4642|/// the one thing brute force is buying), rate-bounded by the seal ledger's\n*4643|/// own backoff.\n 4644|// [impl->REQ-SEAL-CEREMONY-TOTP]\n 4645|fn alert_seal_ceremony_brute_force(subnet: &str, failures: u32) {\n 4646|    let subnet = subnet.to_string();\n...\n 4837|        // query itself no longer reaches the ring); the CPR written to the\n*4838|        // child's input then echoes back as output and advances the ring one\n 4839|        // hop later, well within the poll cadence. A re-render works the same\n 4840|        // as before; a non-echoing ConPTY stays unobservable (the latch).\n 4841|        input.enqueue_record(InputRecord::probe(INJECT_SETTLE_PROBE.to_vec()));\n...\n 4870|/// Layer 2 (REQ-INJECT-MULTILINE-INTEGRITY): after a `{commit}`, wait a bounded window\n*4871|/// for the typed payload's HEAD to echo back on the session ring (bytes produced since\n 4872|/// `seq_start`), then verify. A swallowed head means the prefix never appears. Empty\n 4873|/// payload (keys-only sequence) is vacuously verified with no wait.\n 4874|///\n...\n 4908|\n*4909|/// Layer 3 (REQ-INJECT-MULTILINE-INTEGRITY, the ruling's named fallback under the\n 4910|/// settle-gate): enqueue payload text in bounded chunks rather than one write, so no\n 4911|/// single huge write races the terminal's input coalescer. Order is preserved (single\n 4912|/// FIFO, single writer). The reader is already confirmed live by the settle-gate before\n...\n 5075|    // delivery. So an adapter that KNOWS its harness echoes declares the capability\n*5076|    // (parallel to the ruling's \"bracketed-paste where the harness declares it\"); Layer 1\n 5077|    // (the settle-gate) is the UNCONDITIONAL root fix. The int gate also forces it on\n 5078|    // (`SPT_INJECT_FORCE_ECHO_MISS`) to exercise the re-drive/spool wiring on any platform.\n 5079|    // AMBIENT env can NOT arm this: both vars are scrubbed at daemon startup\n...\n 5135|                    committed = true;\n*5136|                    // Layer 2: verify the typed head echoed back — ONLY where the terminal\n 5137|                    // demonstrably echoes (else a non-echoing PTY's incidental output would\n 5138|                    // false-read head-loss). Where it does not echo, Layer 1 stands alone.\n 5139|                    if !echo_capable || echo_verify_after(&log, seq_start, &sent_text) {\n...\n 5169|        if integrity_lost {\n*5170|            // Layer 2 fallback: the typed head never echoed, even after a re-drive.\n 5171|            // A live-SENT inject leaves no spool copy, so convert the silent+unrecoverable\n 5172|            // truncation into recoverable+loud — re-spool the envelope (idle-eligible,\n 5173|            // poll-fed) with a distinct integrity marker. NOT a binary fault (the binary\n...\n 5225|                // A repeat miss of an already-respooled envelope (e.g. the checkpoint\n*5226|                // duplicate FIRE looping back on a later drain): DEAD-LETTER it loud —\n 5227|                // do NOT respool again (never a silent drop; it still counts as a\n 5228|                // strike), REQ-HAZARD-IDLE-SILENT-NONDELIVERY posture.\n 5229|                spt_proto::emit_line_err!(\n...\n 5346|    /// when net is still being brought up (REQ-DAEMON-9 boot-race self-heal):\n*5347|    /// a `OnceLock` so the background net-retry can ATTACH the host after bind\n 5348|    /// without a relock on the hot effect-dispatch read path (`.get()` is\n 5349|    /// lock-free). Settable exactly once — the first host wins.\n 5350|    net: std::sync::OnceLock<NetHost>,\n...\n 5374|    /// write-stomp this REQ kills). An id is claimed for the duration of one spawn;\n*5375|    /// a duplicate wake for a claimed-or-already-live endpoint stands down (no-op ack).\n 5376|    wake_inflight: Mutex<HashMap<String, WakeClaim>>,\n 5377|    /// Monotonic claim generation (#235). Handed to each claim so a taken-over\n 5378|    /// holder's late RAII drop cannot release its successor's claim.\n...\n 5451|    /// worth covering is exactly the window the bring-up will wait through. A\n*5452|    /// failed spawn writes nothing back and its entry simply expires.\n 5453|    // [impl->REQ-ER-BRINGUP-INFLIGHT-LEDGER]\n 5454|    bringups_in_flight: Mutex<HashMap<String, Instant>>,\n 5455|    /// The PENDING seal ceremonies (WAX-SEAL W2, releases#21), keyed by the\n...\n 5469|/// overlay, the throttle ledger and the abort sweep are ONE machinery; the\n*5470|/// purpose decides only the admit arm. Tracked daemon-side on the pending\n 5471|/// entry — nothing about it rides the attach wire, which is what lets an N-1\n 5472|/// rc client host an enrollment ceremony unchanged (the brief's own text\n 5473|/// carries the ENROLL framing).\n...\n 5483|        pubkey_hex: String,\n*5484|        /// The seam backend that minted the keypair (e.g. `hello-kcm-rs256`).\n*5485|        backend_kind: String,\n 5486|    },\n 5487|}\n 5488|\n...\n 5519|    /// The requester's reply channel (the blocked `seal_ceremony` caller).\n*5520|    requester: SharedSend,\n 5521|    /// The requester conn's id — the conn-death abort key.\n 5522|    requester_conn: u64,\n 5523|    /// The controller conn's id at ceremony open — the detach abort key, and\n...\n 5710|    /// Attach a network host to a broker that was bound net-less (REQ-DAEMON-9):\n*5711|    /// the boot-race self-heal path calls this once the background retry brings\n 5712|    /// the net endpoint up, after which the dispatcher + peer pump are spawned.\n 5713|    /// Idempotent by `OnceLock` — a second attach is a no-op returning `false`\n 5714|    /// (the first host wins); the hot read path (`net()`) never blocks on it.\n...\n 5850|        };\n*5851|        // A real (immediately-abandoned) socket pair for the sink's SharedSend\n 5852|        // identity — nothing ever writes to it (the fixture invariant), so the\n 5853|        // dropped peer is irrelevant; the stall signal is the injected\n 5854|        // `write_blocked_since`, not a real socket block.\n...\n 5870|        let (_recv, send_half) = server.split();\n*5871|        let send: SharedSend = Arc::new(BrokerConn::new(send_half, brain_write_deadline()));\n 5872|        let (tx, rx) = sync_channel::<CtrlMsg>(CONTROLLER_CHANNEL_DEPTH);\n 5873|        // Drain-forever (never a socket write, never finishes while tx lives):\n 5874|        // stays un-reapable as a live-but-wedged writer even under child output.\n...\n 5944|    /// drives its handler to EOF cleanup within the write bound — without the\n*5945|    /// black-holed client dropping its end.\n 5946|    // [impl->REQ-HAZARD-SHAREDSEND-NO-BLOCKING-WRITE-UNDER-LOCK]\n 5947|    pub fn conn_handler_count(&self) -> usize {\n 5948|        self.conn_handlers.load(Ordering::Acquire)\n...\n 5995|    /// trip) promotes a ready update candidate only once this reads `false`: an OLD\n*5996|    /// generation whose local controller conn is black-holed reads wedged until the W2\n 5997|    /// stall-evict releases it, so `brain.ready` inside the 15 s window can no longer\n 5998|    /// promote onto a still-frozen control plane (the 22:47 false-promote). A cleanly-\n 5999|    /// closed old conn is simply absent → `false` at once (the normal fast promote).\n...\n 6066|        // [impl->REQ-HAZARD-SHAREDSEND-NO-BLOCKING-WRITE-UNDER-LOCK]\n*6067|        let send: SharedSend = Arc::new(BrokerConn::new(send, brain_write_deadline()));\n 6068|        // Base attribution fact (F-039 leg b): broker clients are brains; role\n 6069|        // facts (controller/viewer/presence/stream subscriber) accrete at the\n 6070|        // attach sites. [impl->REQ-CONN-POISON-ATTRIBUTION]\n...\n 6199|                KIND_NET_DIAL_LOOPBACK => {\n*6200|                    if let Err(msg) = self.dispatch_net_dial_loopback(&send) {\n 6201|                        send_error(&send, &msg);\n 6202|                    }\n 6203|                }\n...\n 6225|                KIND_NET_STREAM_OPEN => match self.dispatch_net_stream_open(env, &send) {\n*6226|                    // ConnectionBound open → track for the conn-exit sweep\n 6227|                    // (a journaled replay returns the SAME id — dedup keeps\n 6228|                    // the sweep list exact).\n 6229|                    // [impl->REQ-STREAM-LEASE-CLASSES]\n...\n 6233|                },\n*6234|                KIND_NET_STREAM_SEND => {\n 6235|                    if let Err(msg) = self.dispatch_net_stream_send(env, &send) {\n 6236|                        send_error(&send, &msg);\n 6237|                    }\n...\n 6254|                    // below, byte-identical (the stable KH-2.3 wire fact the\n*6255|                    // dispatcher's fallback gate keys on). Never set in\n 6256|                    // production.\n 6257|                    if std::env::var(\"SPT_TEST_STREAM_OPENER_UNSUPPORTED\").is_ok() {\n 6258|                        send_error(&send, &format!(\"unknown command kind {:?}\", env.kind));\n...\n 6486|    // [impl->REQ-HAZARD-DAEMON-SCHED-NONBLOCKING]\n*6487|    fn dispatch_spawn(&self, env: Envelope, send: &SharedSend) -> Result<u64, String> {\n 6488|        let req: SpawnReq =\n 6489|            serde_json::from_value(env.payload).map_err(|e| format!(\"bad spawn payload: {e}\"))?;\n 6490|        self.dispatch_spawn_policy(req, send, false)\n...\n 6499|    // [impl->REQ-SPAWN-FRESH-TRUTHFUL]\n*6500|    fn dispatch_spawn_fresh(&self, env: Envelope, send: &SharedSend) -> Result<Option<u64>, String> {\n 6501|        let req: SpawnReq =\n 6502|            serde_json::from_value(env.payload).map_err(|e| format!(\"bad spawn payload: {e}\"))?;\n 6503|        self.dispatch_spawn_policy(req, send, true)\n...\n 6521|    // [impl->REQ-ER-BRINGUP-SPAWNS-SESSION]\n*6522|    fn dispatch_bring_up(&self, env: Envelope, send: &SharedSend) -> Result<(), String> {\n 6523|        self.dispatch_bring_up_within(env, send, BRINGUP_READY_WAIT)\n 6524|    }\n 6525|\n...\n 6537|        env: Envelope,\n*6538|        send: &SharedSend,\n 6539|        ready_wait: Duration,\n 6540|    ) -> Result<(), String> {\n 6541|        let req: BringUpReq = serde_json::from_value(env.payload)\n...\n 6753|                    // this cwd literally and a missing directory fails the spawn, so\n*6754|                    // the fallback has to be the `None` this call used to pass, i.e.\n 6755|                    // exactly the pre-#178 behaviour rather than a new failure mode.\n 6756|                    spt_proto::emit_line_err!(\n 6757|                        \"ER_CWD_PROVISION_FAIL:{endpoint}: {} ({e}) — launching without the \\\n...\n 6780|        // actually needs. Polled rather than signalled because the session is\n*6781|        // registered by the spawn's own conn handler, which has no channel back\n 6782|        // to this one.\n 6783|        let deadline = Instant::now() + ready_wait;\n 6784|        loop {\n...\n 6884|    // [impl->REQ-SEAL-NO-CEREMONY-SURFACE]\n*6885|    fn dispatch_seal_ceremony(&self, env: Envelope, send: &SharedSend) -> Result<(), String> {\n 6886|        let req: SealCeremonyReq = serde_json::from_value(env.payload)\n 6887|            .map_err(|e| format!(\"bad seal-ceremony payload: {e}\"))?;\n 6888|        let refuse = |outcome: &str, detail: String| {\n...\n 6989|        offers: MintOffers,\n*6990|        send: &SharedSend,\n 6991|    ) -> Result<(), String> {\n 6992|        // THE SURFACE (operator ruling 4). Session first, then the seat.\n 6993|        let Some(session_id) = self.session_for_endpoint(endpoint) else {\n...\n 7097|    // [impl->REQ-SEAL-ENROLL-VERB]\n*7098|    fn dispatch_seal_enroll(&self, env: Envelope, send: &SharedSend) -> Result<(), String> {\n 7099|        let req: SealEnrollReq = serde_json::from_value(env.payload)\n 7100|            .map_err(|e| format!(\"bad seal-enroll payload: {e}\"))?;\n 7101|        let refuse = |outcome: &str, detail: String| {\n...\n 7147|                     or revocation needs an operator ruling.\",\n*7148|                    req.subnet, held.pubkey_hex, held.backend_kind\n 7149|                ),\n 7150|            );\n 7151|        }\n...\n 7164|             subnet: {}\\n\\\n*7165|             backend: {}\\n\\\n 7166|             pubkey-sha256: {fingerprint}\\n\\\n 7167|             A member-or-admin code of '{}' admits this enrollment; Esc cancels.\",\n*7168|            req.subnet, req.backend_kind, req.subnet\n 7169|        );\n 7170|        debug_assert!(\n 7171|            brief.chars().count() <= SEAL_CEREMONY_CONTENT_MAX_CHARS,\n...\n 7180|                pubkey_hex: req.pubkey_hex.clone(),\n*7181|                backend_kind: req.backend_kind.clone(),\n 7182|            },\n 7183|            // An enrollment ceremony IS an enrollment: neither mint-path\n 7184|            // offer is meaningful on its overlay.\n...\n 7202|        env: Envelope,\n*7203|        send: &SharedSend,\n 7204|    ) -> Result<(), String> {\n 7205|        use spt_store::engineroom as er;\n 7206|        let req: SealCeremonyCodeReq = serde_json::from_value(env.payload)\n...\n 7241|        // would let a broken client shut the gate a human needs), and every\n*7242|        // failed proof leaves the ceremony PENDING: the overlay falls back\n 7243|        // to TOTP code entry on the same overlay.\n 7244|        // [impl->REQ-SEAL-CEREMONY-FIDO2]\n 7245|        if let Some(sig_hex) = &req.signature_hex {\n...\n 7313|            );\n*7314|            if let Err(e) = spt_store::enroll::verify_backend_signature(\n*7315|                &enrollment.backend_kind,\n 7316|                &enrollment.pubkey_hex,\n 7317|                &payload,\n 7318|                sig_hex,\n 7319|            ) {\n*7320|                refuse_proof(format!(\"{e} — fall back to the TOTP code.\"));\n 7321|                return Ok(());\n 7322|            }\n 7323|            // Verified: mint with the pinned spellings and end the ceremony.\n...\n 7427|                } else if let (Some(pk), Some(bk)) =\n*7428|                    (&req.enroll_pubkey_hex, &req.enroll_backend_kind)\n 7429|                {\n 7430|                    // [impl->REQ-SEAL-ENROLL-SHORTCUT-E]\n 7431|                    self.mint_ceremony_seal_enrolling(req.ceremony_id, now, pk, bk)\n...\n 7617|        pubkey_hex: &str,\n*7618|        backend_kind: &str,\n 7619|    ) -> (&'static str, String, Option<String>) {\n 7620|        let (subnet, endpoint, content) = {\n 7621|            let pending = recover(&self.ceremonies);\n...\n 7653|            &subnet,\n*7654|            backend_kind,\n 7655|            now,\n 7656|        ) {\n 7657|            Ok(_) => {}\n...\n 7744|                \"seal {} minted by {minter}; authenticator enrolled for node {node} x \\\n*7745|                 subnet '{subnet}' ({backend_kind}).\",\n 7746|                record.token\n 7747|            ),\n 7748|            Some(record.token),\n...\n 7765|    ) -> (&'static str, String, Option<String>) {\n*7766|        let (subnet, pubkey_hex, backend_kind) = {\n 7767|            let pending = recover(&self.ceremonies);\n 7768|            let Some(p) = pending.get(&ceremony_id) else {\n 7769|                return (\n...\n 7776|                pubkey_hex,\n*7777|                backend_kind,\n 7778|            } = &p.purpose\n 7779|            else {\n 7780|                return (\n...\n 7785|            };\n*7786|            (p.subnet.clone(), pubkey_hex.clone(), backend_kind.clone())\n 7787|        };\n 7788|        let node = match spt_store::nodeid::load_or_create() {\n 7789|            Ok(id) => spt_net::net::registry::key_prefix(&id.public_key().to_hex()),\n...\n 7807|            &subnet,\n*7808|            &backend_kind,\n 7809|            now,\n 7810|        ) {\n 7811|            Ok(r) => r,\n...\n 7838|        spt_proto::emit_line_err!(\n*7839|            \"SEAL_ENROLL_MINTED: ceremony={ceremony_id} node={node} subnet={} backend={}\",\n*7840|            record.subnet, record.backend_kind\n 7841|        );\n 7842|        (\n 7843|            SEAL_CEREMONY_ADMITTED,\n...\n 7845|                \"{SEAL_ENROLLED}\\npubkey_hex: {}\\nnode: {}\\nsubnet: {}\\nenrolled_at: {}\\n\\\n*7846|                 backend_kind: {}\",\n 7847|                record.pubkey_hex, record.node, record.subnet, record.enrolled_at,\n*7848|                record.backend_kind\n 7849|            ),\n 7850|            None,\n 7851|        )\n...\n 8087|        req: SpawnReq,\n*8088|        send: &SharedSend,\n 8089|        fresh: bool,\n 8090|    ) -> Result<Option<u64>, String> {\n 8091|        // releases#199 instrument, BROKER SIDE. The launch-path stamps say when the\n...\n 8286|                                    // do not drop HostedSession/PTY resources or call\n*8287|                                    // dispatch_teardown as a fallback after refusal.\n 8288|                                    return Err(format!(\n 8289|                                        \"SPAWN_ZOMBIE_REAP_DECLINE:{}: session {sid}: {reason}\",\n 8290|                                        req.endpoint\n...\n 8341|                            \"SPAWN_DEDUP:{}: endpoint already has a live session {sid} — \\\n*8342|                             single-flight wake no-op ack [REQ-SPAWN-COLLISION-GUARD-LIVE-DUP]\",\n 8343|                            req.endpoint\n 8344|                        );\n 8345|                        let frame = Envelope::new(\n...\n 8444|        // (W1 / REQ-HAZARD-INJECT-CONTROL-COEXIST). The controller write is no\n*8445|        // longer inline under the log lock, so a backed-up controller can never\n 8446|        // wedge the session; a fully-stalled controller is detached after the\n 8447|        // deadline (bounded wedge, never permanent).\n 8448|        let log_drain = Arc::clone(&log);\n...\n 8556|            // about to vanish (the relatch the W2 int leg caught live). The\n*8557|            // removed entry hands back the DRAIN handle the ordering below needs.\n 8558|            let removed = recover(&sessions_exit).remove(&id);\n 8559|            // releases#199 instrument, THE FOURTH CANDIDATE the A/B/C set did not\n 8560|            // name: a harness that spawns and dies immediately produces a row that\n...\n 8749|    /// self-kick guard.\n*8750|    fn dispatch_subscribe(&self, env: Envelope, send: &SharedSend) -> Result<u64, String> {\n 8751|        let req: SubscribeReq = serde_json::from_value(env.payload)\n 8752|            .map_err(|e| format!(\"bad subscribe payload: {e}\"))?;\n 8753|        // Clone the log Arc out from under the sessions lock, then resolve under\n...\n 8762|        // post-removal subscribe gets a prompt \"no such session\" error — both\n*8763|        // non-silent. The rc-side status-gate (a) + first-event backstop (b) cover\n 8764|        // the rest.\n 8765|        let log = {\n 8766|            let sessions = recover(&self.sessions);\n...\n 8814|    /// a no-op if a newer controller already took over, or the session is gone.\n*8815|    fn dispatch_unsubscribe(&self, env: Envelope, send: &SharedSend) -> Result<(), String> {\n 8816|        let req: UnsubscribeReq = serde_json::from_value(env.payload)\n 8817|            .map_err(|e| format!(\"bad unsubscribe payload: {e}\"))?;\n 8818|        let log = {\n...\n 8840|    /// `(session_id, op_id)` after a brain crash is deduped (the PTY is not\n*8841|    /// written twice), and either outcome — fresh apply or dedup — is acked back\n 8842|    /// with an [`crate::msg::KIND_APPLIED`] frame so the brain can retire the\n 8843|    /// effect (B5 / KNOWN-HAZARDS 7.2). Without an `op_id` it is the legacy\n*8844|    /// direct write (no dedup, no ack).\n 8845|    // [impl->REQ-HAZARD-RESTART-IDEMPOTENT]\n*8846|    fn dispatch_input(&self, env: Envelope, send: &SharedSend) -> Result<(), String> {\n 8847|        let req: InputReq =\n 8848|            serde_json::from_value(env.payload).map_err(|e| format!(\"bad input payload: {e}\"))?;\n 8849|        let bytes = decode_bytes(&req.data_b64).map_err(|e| format!(\"bad input base64: {e}\"))?;\n...\n 8880|        // Layer C: when a (non-faulted) translation binary is attached, fire a\n*8881|        // CONTENT-FREE `{type:input}` ping so the binary can track operator idleness\n 8882|        // — best-effort, never carries the keystroke bytes (doyle gate #1, privacy).\n 8883|        if let Some(tr) = &translation {\n 8884|            if !tr.faulted.load(Ordering::Relaxed) {\n...\n 8910|                        // Buffer-or-ENQUEUE INSIDE the journal effect so the op is\n\n[Showing lines 1-916 of 1042 (50.0KB limit). Use :917 to continue]"}],"details":{"scopePath":"crates/spt-daemon/src/broker.rs","searchPath":"C:\\Users\\decid\\Documents\\projects\\spt-core\\crates\\spt-daemon\\src\\broker.rs","cwd":"C:\\Users\\decid\\Documents\\projects\\spt-core","matchCount":200,"fileCount":1,"files":["crates/spt-daemon/src/broker.rs"],"fileMatches":[{"path":"crates/spt-daemon/src/broker.rs","count":200}],"truncated":true,"perFileLimitReached":200,"displayContent":"   69│    KIND_NET_STATUS, KIND_NET_STATUS_REPLY, KIND_NET_STREAMS, KIND_NET_STREAMS_REPLY,\n  *70│    KIND_NET_STREAM_OPEN, KIND_NET_STREAM_OPENED, KIND_NET_STREAM_OPENER, KIND_NET_STREAM_OPENER_REPLY, KIND_NET_STREAM_RETIRE, KIND_NET_STREAM_RETIRED, KIND_NET_STREAM_SEND, KIND_NET_STREAM_SUBSCRIBE,\n   71│    KIND_NET_STREAM_UNSUBSCRIBE, KIND_NET_STREAM_UNSUBSCRIBED,\n   72│    KIND_MET_MEMBER, KIND_PAIR_CODE_SUBMIT, KIND_PAIR_JOIN, KIND_PAIR_JOINED, KIND_PAIR_MEET, KIND_RESIZE, KIND_SESSIONS, KIND_SESSIONS_REPLY, KIND_SPAWN,\n   73│    BringUpReq, BroughtUpReply, BRING_UP_ADMITTED, BRING_UP_ADMIT_PREFIX, BRING_UP_ALREADY_LIVE, BRING_UP_REFUSED, KIND_BRING_UP, KIND_BROUGHT_UP,\n     │...\n   86│/// The shared, serialized send side of one brain connection. Output frames,\n  *87│/// replay frames, command acks, and exit/error events all write through this.\n   88│/// `pub(crate)`: the net host's stream logs (D4b) live-send through the same\n   89│/// handle under the same gate discipline. Round-4\n   90│/// (REQ-HAZARD-SHAREDSEND-NO-BLOCKING-WRITE-UNDER-LOCK): no longer a raw\n     │...\n   93│/// matching stays `Arc::ptr_eq`.\n  *94│pub(crate) type SharedSend = Arc<BrokerConn>;\n   95│\n   96│/// Default bounded output-log depth (chunks). Large enough that a brain restart\n   97│/// window never evicts unreplayed output in practice; the bound is what keeps a\n     │...\n  125│/// thread `try_send`s output frames into `tx` (a bounded queue); a dedicated\n *126│/// `writer` thread does the BLOCKING socket write, so a wedged viewer backs up\n  127│/// only its own queue — never the drain. When the queue overflows the sink is\n  128│/// dropped (the `tx` closes → the writer ends) and removed from the map.\n  129│struct ViewerSink {\n     │...\n  133│    /// (a dropped brain connection removes its viewer rows); never written here.\n *134│    send: SharedSend,\n  135│    /// The viewer's ORIGIN NODE hex, when it presented one (`None` for a local\n  136│    /// viewer that carries no node identity) — RETAINED for attachment-frame\n  137│    /// composition ONLY (releases#44, REQ-ATTACH-LINK-PUSH).\n     │...\n  165│/// merely-slow controller DROPS chunks + falls behind the ring, and only a channel\n *166│/// that stays full for [`CONTROLLER_WRITE_DEADLINE`] (tracked via\n  167│/// [`ControllerSink::last_ok`]) is detached. Generous so a momentary slow consumer\n  168│/// never trips the deadline.\n  169│const CONTROLLER_CHANNEL_DEPTH: usize = 4096;\n     │...\n  173│/// (W1, refined by b4 / REQ-HAZARD-VIEWER-STARVE-UNDER-CONTROLLER-BACKPRESSURE). This\n *174│/// BOUNDS the wedge: a backed-up controller falls behind for at most this long before\n  175│/// eviction — never forever (the v0.12.x root) — and the drain NEVER blocks or sleeps\n  176│/// (a single off-lock `try_send` per chunk; see [`OutputLog::append`]). A live but\n  177│/// merely slow operator lands a frame before this elapses (resetting `last_ok`) and is\n     │...\n  210│/// How long a controller's writer thread may sit BLOCKED inside a single socket\n *211│/// write — the brain subscriber suspended / black-holed — before a take/reattach\n  212│/// or the `KIND_SESSIONS` reap stall-evicts it (LIFECYCLE-TRUTH W2,\n  213│/// REQ-HAZARD-BROKER-VIEWER-BRAIN-DECOUPLE). Distinct from and 3× longer than\n  214│/// [`CONTROLLER_WRITE_DEADLINE`] on PURPOSE (doyle ruling Q1): that 5 s bound\n     │...\n  320│    // every claim read stalled, so every duplicate wake takes over and the double-create\n *321│    // this function exists to prevent comes back at scale. Compiled out of release\n  322│    // entirely, parsed once, and floored so that even in a debug build it cannot be\n  323│    // driven below a value the gate could mistake for a wedge on a healthy holder.\n  324│    #[cfg(debug_assertions)]\n     │...\n  437│/// An error forbids both kill and forced de-tabling: dropping session resources\n *438│/// is teardown too, not a safe fallback for an identity we could not establish.\n  439│// [impl->REQ-BROKER-ZOMBIE-IDENTITY]\n  440│fn reap_zombie_root(\n  441│    pid: Option<u32>,\n     │...\n  472│/// PURE resolution of the two liveness probes for [`session_is_zombie`], so the\n *473│/// NO-SNAPSHOT arm is unit-testable WITHOUT a platform that lacks a process\n  474│/// table (the W1 `unconfirmed_verdict` injection shape).\n  475│///\n  476│/// The table WINS wherever it speaks — that is the Windows fix, since a\n     │...\n  478│/// handle probe is sound: no-table implies unix implies no handle blind spot,\n *479│/// so the two conditions cannot both fail and the fallback is EXACT.\n  480│// [impl->REQ-LIVENESS-ORACLE-SOUND]\n  481│fn resolve_wrapper_alive(table_says: Option<bool>, handle_says: impl FnOnce() -> bool) -> bool {\n  482│    table_says.unwrap_or_else(handle_says)\n     │...\n  493│    // root that is NOT adapter-labeled was claimed LIVE indefinitely.\n *494│    // NO-SNAPSHOT FALLS BACK, and the fallback is EXACT rather than a\n  495│    // compromise: the handle blind spot is Windows-only (`kill(pid,0)` answers\n  496│    // about the process, not about a handle the caller holds, and Linux demotes\n  497│    // a /proc zombie), while Windows ALWAYS has a process table. So \"no table\"\n     │...\n  672│/// budget shape: consecutive-failures bounded, healthy-run resets). Mirrors the\n *673│/// psyche crash-loop backoff's bounded give-up.\n  674│const TRANSLATE_RESPAWN_BUDGET: u32 = 3;\n  675│\n  676│/// The effective respawn budget. Production is the const above; the int gate tunes\n     │...\n  694│// after typing → re-drive once → LOUD spool (silent+unrecoverable → recoverable+loud);\n *695│// (3) chunked-paced write under the gate (bracketed-paste deferred — the binary owns\n  696│// the key/text interleave, not a clean wrap seam; F-019 found it moot for CC submit).\n  697│\n  698│/// The settle-gate deadline (Layer 1): how long the worker probes a PTY for a\n     │...\n  724│/// The echo-verify wait (Layer 2): how long the worker waits after a `{commit}` for\n *725│/// the typed payload's head to echo back on the session ring before declaring a\n  726│/// verify MISS (round-trip + XON-resume latency bound).\n  727│const INJECT_ECHO_VERIFY_DEADLINE: Duration = Duration::from_millis(1200);\n  728│\n     │...\n  749│\n *750│/// Chunk size for the paced text write (Layer 3, the ruling's named fallback where\n *751│/// bracketed-paste is not declared): a large payload is enqueued in bounded chunks\n  752│/// rather than one write, so no single huge write races the terminal's coalescer.\n  753│/// Layered UNDER the settle-gate (the reader is already confirmed live before the\n  754│/// first chunk). The int gate tunes it via `SPT_INJECT_TEXT_CHUNK`.\n     │...\n  763│\n *764│/// Does `haystack` contain `needle` as a contiguous subslice? (Small, allocation-free\n  765│/// — the echo-verify head match over concatenated ring bytes.)\n *766│fn contains_subslice(haystack: &[u8], needle: &[u8]) -> bool {\n  767│    if needle.is_empty() {\n  768│        return true;\n  769│    }\n *770│    if needle.len() > haystack.len() {\n  771│        return false;\n  772│    }\n *773│    haystack.windows(needle.len()).any(|w| w == needle)\n  774│}\n  775│\n  776│/// Pure echo-verify decision (Layer 2, REQ-INJECT-MULTILINE-INTEGRITY): did the\n *777│/// typed payload's HEAD echo back? Compare a bounded prefix of `sent_text` against\n  778│/// the PTY echo captured since the sequence began. A TUI re-renders typed text so the\n  779│/// leading bytes appear in output; a swallowed head means the prefix is ABSENT. An\n  780│/// empty payload (a keys-only sequence — no echoable text) is vacuously verified.\n     │...\n  823│/// Symmetric with [`ViewerSink`] — a dedicated writer thread does the BLOCKING\n *824│/// socket write so a backed-up controller can never stall the session drain\n  825│/// thread (the v0.12.x wedge: the controller write was inline on the drain,\n  826│/// holding `Mutex<OutputLog>`). Unlike a viewer it is AUTHORITATIVE: its writer\n  827│/// advances `delivered_through` on each successful write, and it is never evicted\n     │...\n  833│    /// for the `exit`-frame fan-out ([`OutputLog::all_sinks`]).\n *834│    send: SharedSend,\n  835│    /// The controller's ATTACH GENERATION (ADR-0038 Amendment fix 6,\n  836│    /// REQ-SERVE-OWNERSHIP-GENERATION): operator-minted wall-ms from the wire\n  837│    /// Request (`0` = local / N-1). A same-identity re-take with an OLDER\n     │...\n  873│    /// `Some(Instant::now())` immediately BEFORE it enters a blocking `write_frame`\n *874│    /// and back to `None` the instant the write returns. A reader\n  875│    /// ([`OutputLog::controller_stalled`]) sees a `Some` older than\n *876│    /// [`BRAIN_WRITE_DEADLINE`] as a writer WEDGED on a suspended/black-holed brain\n  877│    /// conn and stall-evicts it — the signal `last_ok` (channel-handoff time) cannot\n  878│    /// give: an IDLE controller (writer parked on `rx.recv()`, `None` here) and a\n  879│    /// BLOCKED one (writer stuck in the socket write, `Some` here) both leave\n     │...\n  900│\n *901│/// One run of held-back output inside a resize transition, tagged with the\n  902│/// GEOMETRY (and its epoch) the bytes were EMITTED under\n  903│/// (REQ-RC-RESIZE-GEOMETRY-EPOCH). The grid replays each segment at its OWN\n  904│/// geometry, which is the whole content of \"every byte is parsed at the geometry\n     │...\n  918│/// Amendment II). While one of these is installed, [`OutputLog::append`] still\n *919│/// assigns a `seq` and RINGS every chunk — the ring stays the scrollback/resume\n  920│/// authority for raw history — but delivery to the controller and the viewers is\n  921│/// SUPPRESSED (a skip, never a block: the drain runs at full PTY speed, hazard\n *922│/// 7.12 intact), and the chunk is held back from `grid.advance`, tagged with the\n  923│/// geometry it was emitted under. [`OutputLog::commit_resize`] /\n  924│/// [`OutputLog::abort_resize`] then replay the held segments into the grid at\n  925│/// their own geometries and substitute ONE synthesized sync frame to every\n     │...\n  939│    /// The geometry (and epoch) in force when the barrier closed — where the grid\n *940│    /// still is, and what a rollback returns to.\n  941│    from: (u16, u16),\n  942│    from_epoch: u64,\n  943│    /// The requested target geometry (and the epoch it opens).\n     │...\n 1044│    /// of replaying the whole ring from 0. **Viewer writes NEVER move it**\n*1045│    /// (REQ-RCVIEW-1: the brain-resume cursor tracks the controller only).\n 1046│    ///\n 1047│    /// **Advanced only on a successful socket write** (`Ok`), and **monotonic**\n 1048│    /// (never decreases) — see [`advanced_cursor`]. Both invariants are\n     │...\n 1064│    /// instead of the raw ring, so replaying an alt-screen TUI into a fresh terminal\n*1065│    /// no longer corrupts scrollback. Single-writer (the one drain thread), mirroring\n 1066│    /// the ring's single producer.\n 1067│    grid: ScreenGrid,\n 1068│    /// The grid's GEOMETRY EPOCH (REQ-RC-RESIZE-GEOMETRY-EPOCH): monotonic, bumped\n     │...\n 1099│    /// teardown. The ring deliberately keeps the suppressed raw bytes (it is the\n*1100│    /// scrollback authority), so a resume asking BELOW this floor would replay\n*1101│    /// mixed-geometry corruption straight back onto a live terminal; instead it\n 1102│    /// is served the cold-attach shape ([`repaint_initial`]: sync repaint + skip\n 1103│    /// to live). At-least-once holds in effect — the repaint supersedes the\n 1104│    /// skipped range. `0` until a transition has ever torn down (no boundary to\n     │...\n 1109│/// The post-write resume cursor (pure — the D4-1 unit kernel, mirroring\n*1110│/// `brainproc::consumer_gate`/`next_backoff`): advance to `seq + 1` **only** on a\n 1111│/// successful write, and **monotonically** (never below `current`). A failed\n 1112│/// write (`write_ok == false`) leaves the cursor untouched, and a re-send of an\n 1113│/// already-delivered `seq` (an `attach(sub, 0)` rewind, `seq + 1 <= current`)\n     │...\n 1473│    /// ring torn — an over-cap ring (interrupted prune), a last seq not below\n*1474│    /// `next_seq`, or a non-monotonic front/back — and serving those bytes blind\n 1475│    /// risks garbage to a subscriber. Cheap-check the ring invariants (counts within\n 1476│    /// cap, indices ordered and below `next_seq`); on ANY violation RESET the ring\n 1477│    /// EMPTY (+ loud log) — `next_seq` is left intact so cursors never rewind, and the\n*1478│    /// lost scrollback self-heals on the next PTY output + repaint. Returns `true`\n 1479│    /// iff it reset. A coherent ring (the common case — most panics fire OUTSIDE the\n 1480│    /// ring mutation, poisoning the lock while the buffer stays intact) is untouched.\n 1481│    // [impl->REQ-HAZARD-BROKER-FLOOR-LOCK-POISON]\n     │...\n 1483│        let within_cap = self.ring.len() <= self.cap_chunks;\n*1484│        let last_below_next = match self.ring.back() {\n 1485│            Some(&(last, _)) => last < self.next_seq,\n 1486│            None => true,\n 1487│        };\n*1488│        let ordered = match (self.ring.front(), self.ring.back()) {\n*1489│            (Some(&(front, _)), Some(&(back, _))) => front <= back,\n 1490│            _ => true,\n 1491│        };\n 1492│        if within_cap && last_below_next && ordered {\n     │...\n 1498│            \"broker: session {} output ring was torn by a poison-recover \\\n*1499│             (had {had} chunks, next_seq {}); reset to empty — scrollback self-heals \\\n 1500│             on the next output [REQ-HAZARD-BROKER-FLOOR-LOCK-POISON]\",\n 1501│            self.session_id, self.next_seq\n 1502│        );\n     │...\n 1513│    /// Concatenate ring bytes at or after `from_seq` — the output PRODUCED since a\n*1514│    /// snapshot, used to confirm a typed payload's head echoed back (integrity,\n 1515│    /// Layer 2; readiness Layer 1 gates on `high_water` alone — the probe's own\n 1516│    /// echo is a DSR query the drain strips before append, REQ-DSR-SINGLE-CPR).\n 1517│    /// Best-effort: bytes pruned out of the bounded ring are simply absent (the\n     │...\n 1531│        self.next_seq += 1;\n*1532│        self.ring.push_back((seq, bytes.to_vec()));\n 1533│        while self.ring.len() > self.cap_chunks {\n 1534│            self.ring.pop_front();\n 1535│        }\n     │...\n 1618│    /// `SessionInfo.controller_by == None` is ambiguous between empty and\n*1619│    /// local). `None` = no controller at all. The `SharedSend` rides along for\n 1620│    /// the bounded direct-write degrade the exit fan-out uses.\n 1621│    // [impl->REQ-SEAL-NO-CEREMONY-SURFACE]\n*1622│    fn ceremony_surface(&self) -> Option<(SyncSender<CtrlMsg>, SharedSend, u64, bool)> {\n 1623│        self.controller\n 1624│            .as_ref()\n 1625│            .map(|c| (c.tx.clone(), Arc::clone(&c.send), c.send.id(), c.seal_ceremony))\n     │...\n 1630│    /// seated (Controller / TookControl / the idempotent replay all qualify;\n*1631│    /// a Busy refusal or a viewer fallback must not touch someone else's\n 1632│    /// seat). Runs AFTER the ladder so the ladder stays capability-blind.\n 1633│    // [impl->REQ-SEAL-NO-CEREMONY-SURFACE]\n 1634│    fn stamp_controller_seal_ceremony(&mut self, conn: u64, seal_ceremony: bool) {\n     │...\n 1684│        // A local IPC subscribe carries no origin and is this node by\n*1685│        // construction; a local `rc` arrives over the in-process loopback conn\n 1686│        // stamped with our OWN handshake-proven id, so both spellings of \"here\"\n 1687│        // must answer the same.\n 1688│        let from_this_node = match by {\n     │...\n 1815│            // here would let anyone on the box ratchet the human toward a\n*1816│            // backoff by replaying a dead ticket.\n 1817│            // [impl->REQ-ER-BRINGUP-SPAWNS-SESSION]\n 1818│            AdmitTicket::Unredeemed => {\n 1819│                return SeatGate::Refused(\n     │...\n 1874│/// a credential the gate did not itself verify\") is untouched. What travels is\n*1875│/// the broker's own verdict, keyed by an id a caller can only echo back.\n 1876│///\n 1877│/// The SESSION LABEL travels for a reason that is not convenience: the grant is\n 1878│/// keyed on the session it empowers, and at bring-up time the engine room's\n     │...\n 1995│    // configuration, not a failed guess, so it must not spend a unit of the\n*1996│    // attempt budget the human needs to get back to the controls.\n 1997│    // `classify_bringup` still rules on it; it simply rules over a ledger\n 1998│    // nothing loaded (`default()` is not a claim about the file — the\n 1999│    // NoAdapter arm ignores the attempt entirely, and nothing is persisted).\n     │...\n 2014│    // attempt bound's business. Keeping that input a bool is what stops #102\n*2015│    // from touching the backoff schedule at all.\n 2016│    //\n 2017│    // What the presentation type adds is orthogonal (releases#197): an ABSENT\n 2018│    // code is not a failed guess at all, so it must not spend a unit of the\n     │...\n 2157│/// several stores, and the seat resolver that calls this runs under the lock the\n*2158│/// output drain needs. Fire-and-forget with a LOUD stderr fallback — silence is\n 2159│/// the one thing brute force is buying, so a failure to alert must not itself be\n*2160│/// quiet. The ledger's own backoff gates this path, so it cannot be sprayed.\n 2161│///\n 2162│/// Free-standing because the gate it belongs to is now asked by a caller with no\n 2163│/// session (the bring-up verb): an alert that only fired for one of the two\n     │...\n 2203│/// A single immediate attempt would therefore miss intermittently and leave the\n*2204│/// row pending forever — the defect back, just rarer and harder to see. So this\n 2205│/// polls the eligibility predicate under a bound and drives once it holds.\n 2206│///\n 2207│/// **Never a refusal, loud on failure** (clause 4, the denial-of-governance\n     │...\n 2407│    /// the admin bring-up's empowerment (releases#102), spool the briefing that\n*2408│    /// states it, and hand back the operator-facing sentence for the reply.\n 2409│    ///\n 2410│    /// **Why this is not done at the gate, which is where the credential is\n 2411│    /// known.** Two things happen between the gate and a resolved seat, and both\n     │...\n 2479│        // the endpoint keeps running between attachments — so a human who\n*2480│        // detaches and comes back to the SAME live session is re-handed a\n 2481│        // posture statement they already read, while nothing about the session\n 2482│        // is new. A FRESH session — a new bring-up, or a daemon restart that\n 2483│        // re-hosts one — starts a new log and briefs exactly as before.\n     │...\n 2560│    /// several stores, and this resolver runs under the lock the output drain\n*2561│    /// needs. Fire-and-forget with a LOUD stderr fallback — silence is the one\n 2562│    /// thing brute force is buying, so a failure to alert must not itself be\n*2563│    /// quiet. The ledger's own backoff gates this path, so it cannot be sprayed.\n 2564│    /// Controller-bound authority (ADR-0052 §3a): a seat change or release\n 2565│    /// DROPS every empowerment the engine room's session holds.\n 2566│    ///\n     │...\n 2591│\n*2592│    fn become_controller(&mut self, sub: SharedSend, by: Option<String>, from_seq: u64, attach_gen: u64) {\n 2593│        // Drop the prior controller sink first (its writer's live loop ends when\n 2594│        // tx drops), and bump the generation so (a) an in-flight deadline-evict\n 2595│        // for the old controller can't unseat this one and (b) a prior writer\n     │...\n 2835│    /// socket write for at least `deadline` (the brain-subscriber conn suspended /\n*2836│    /// black-holed). An IDLE controller (writer parked on `rx.recv()`, nothing to\n 2837│    /// write) reads NOT stalled: its [`ControllerSink::write_blocked_since`] is `None`.\n 2838│    /// Pure over the injected `now` + `deadline` so the unit tests it with no thread.\n 2839│    // [impl->REQ-HAZARD-BROKER-VIEWER-BRAIN-DECOUPLE]\n     │...\n 2852│    /// it (REQ-UPDATE-PROMOTE-DRAINED). A killed OLD brain generation whose local\n*2853│    /// controller conn is black-holed reads wedged here until the W2 stall-evict\n 2854│    /// releases it (or the conn EOFs); a cleanly-closed conn is simply absent. A\n 2855│    /// REMOTE operator's wedged conn (`by: Some`) is the W2 stall-evict concern, NOT\n 2856│    /// an old-gen brain conn, so it is EXCLUDED — a stuck remote viewer must never\n     │...\n 2885│            \"BRAIN_SUBSCRIBER_STALL_EVICT:{} conn={conn} {} — controller writer blocked > {}ms \\\n*2886│             on a suspended/black-holed brain conn; detached, driven_by released \\\n 2887│             [REQ-HAZARD-BROKER-VIEWER-BRAIN-DECOUPLE]\",\n 2888│            self.session_id,\n 2889│            crate::conn::log_stamp(),\n     │...\n 2907│    /// live queue. The drain thread fans live frames in via `try_send`.\n*2908│    fn add_viewer(&mut self, sub: SharedSend, from_seq: u64, by: Option<&str>) {\n 2909│        let vid = self.next_viewer_id;\n 2910│        self.next_viewer_id += 1;\n 2911│        // Attribution (F-039 legs b+d): viewer role fact + attach record.\n     │...\n 2984│        &mut self,\n*2985│        sub: SharedSend,\n 2986│        from_seq: u64,\n 2987│        intent: AttachIntent,\n 2988│        by: Option<String>,\n     │...\n 3001│        &mut self,\n*3002│        sub: SharedSend,\n 3003│        from_seq: u64,\n 3004│        intent: AttachIntent,\n 3005│        by: Option<String>,\n     │...\n 3084│        &mut self,\n*3085│        sub: SharedSend,\n 3086│        from_seq: u64,\n 3087│        intent: AttachIntent,\n 3088│        by: Option<String>,\n     │...\n 3117│        &mut self,\n*3118│        sub: SharedSend,\n 3119│        from_seq: u64,\n 3120│        intent: AttachIntent,\n 3121│        by: Option<String>,\n     │...\n 3153│        // W2 decouple (REQ-HAZARD-BROKER-VIEWER-BRAIN-DECOUPLE): a controller WEDGED\n*3154│        // on a suspended/black-holed brain conn past BRAIN_WRITE_DEADLINE is\n 3155│        // stall-evicted HERE — the take/reattach self-heals against broker truth\n 3156│        // without waiting for new output (the output-driven mark_controller_gone\n 3157│        // never fires on an idle session). Inline stamp: this path already writes the\n     │...\n 3176│            //   gen <  incumbent (nonzero)  → a REPLAYED stale Request (an\n*3177│            //     unfinished backlog row whose viewport died raw) — refused\n*3178│            //     busy; the ladder never runs backwards.\n 3179│            //   gen >  incumbent (nonzero)  → the LIVE replacement viewport,\n 3180│            //     Control or Take alike: loud+fenced SUPERSESSION via the full\n 3181│            //     W2 revoke (terminal Displaced + fence moves with the slot) —\n     │...\n 3255│            // The LOCAL brain re-attaching while a REMOTE controls — never steal;\n*3256│            // fall back to a silent viewer (gate #7 for the local-resume path).\n 3257│            // `by` is None on this arm by construction, so the sink retains no node.\n 3258│            self.add_viewer(sub, from_seq, None);\n 3259│            self.stamp_viewer_count();\n     │...\n 3294│    /// (REQ-RC-RESIZE-GEOMETRY-EPOCH). From here until commit/abort every appended\n*3295│    /// chunk is held back from the grid and tagged with the geometry it was emitted\n*3296│    /// under. Returns the geometry the grid is currently at (the rollback target).\n 3297│    ///\n 3298│    /// A second concurrent transition is REFUSED rather than queued: the caller is\n 3299│    /// the session's controller (resize is controller-exclusive), so two overlapping\n     │...\n 3391│    /// transition landed on, concatenated with the `deferred` non-grid bytes the\n*3392│    /// capture-mode replay collected (leg 5: untracked stateful toggles,\n 3393│    /// one-shots and child→client queries, verbatim in emission order) — pushed\n 3394│    /// to every attached sink under the caller's single lock acquisition,\n 3395│    /// substituting for everything delivery suppressed.\n     │...\n 3459│    /// CAPTURE MODE (the one parser authority — never a second scanner over raw\n*3460│    /// bytes): every sequence the grid does not track is re-encoded into the\n 3461│    /// returned buffer, verbatim in emission order, for the sync frame to flush\n 3462│    /// (REQ-RC-RESIZE-PRESENTATION-BARRIER leg 5 — the non-grid bytes a bare\n 3463│    /// repaint would silently drop).\n     │...\n 3546│    // [impl->REQ-SERVE-OWNERSHIP-GENERATION]\n*3547│    fn detach_if_gen(&mut self, sub: &SharedSend, gen: Option<u64>) {\n 3548│        if let (Some(g), Some(c)) = (gen, self.controller.as_ref()) {\n 3549│            if c.attach_gen != g {\n 3550│                // Stale generation: never clears the (newer) controller.\n     │...\n 3561│\n*3562│    fn detach_if(&mut self, sub: &SharedSend) {\n 3563│        let is_ctrl = self\n 3564│            .controller\n 3565│            .as_ref()\n     │...\n 3716│    /// Whether `sub` is the current controller (the resize-exclusivity check).\n*3717│    fn is_controller(&self, sub: &SharedSend) -> bool {\n 3718│        self.controller\n 3719│            .as_ref()\n 3720│            .is_some_and(|c| Arc::ptr_eq(&c.send, sub))\n     │...\n 3757│fn viewer_writer(\n*3758│    send: SharedSend,\n 3759│    session_id: u64,\n 3760│    initial: Vec<Envelope>,\n 3761│    rx: Receiver<Envelope>,\n     │...\n 3767│    struct ExitNote {\n*3768│        send: SharedSend,\n 3769│        session_id: u64,\n 3770│        reason: &'static str,\n 3771│    }\n     │...\n 3872│struct ExitFanout {\n*3873│    controller: Option<(SyncSender<CtrlMsg>, SharedSend)>,\n*3874│    viewers: Vec<(SyncSender<Envelope>, SharedSend)>,\n 3875│}\n 3876│\n 3877│/// How long the exit waiter re-tries a Full sink queue before degrading to the\n     │...\n 3882│/// Bounded enqueue-behind-output: retry a Full queue up to\n*3883│/// [`EXIT_ENQUEUE_DEADLINE`], then fall back to the direct bounded conn write\n 3884│/// (the pre-W3 behavior, now the loud DEGRADE instead of the default).\n 3885│/// [impl->REQ-BROKER-OUTPUT-BEFORE-EXIT]\n*3886│fn enqueue_exit_bounded<T>(tx: &SyncSender<T>, mut msg: T, sink: &SharedSend, frame: &Envelope) {\n 3887│    let deadline = Instant::now() + EXIT_ENQUEUE_DEADLINE;\n 3888│    loop {\n 3889│        match tx.try_send(msg) {\n     │...\n 3929│/// (`seq > cursor` — a frame the drain dropped while the controller channel was Full,\n*3930│/// the b4 backpressure) FREEZES the cursor at last-contiguous, so a re-attaching\n 3931│/// brain's `resume_seq` never skips a dropped chunk (a high-watermark jump PAST the\n 3932│/// gap would be a not-exactly-once / non-gapless resume = a B2 violation). An\n 3933│/// already-delivered `seq` (`seq < cursor`, a rewind re-send) is a no-op. A single CAS,\n     │...\n 3944│/// cursor on each success), then drain live [`CtrlMsg`]s with a BLOCKING socket\n*3945│/// write each — so a backed-up controller blocks ONLY this thread, never the\n 3946│/// session drain (which used to write the controller inline under the log lock).\n 3947│/// A failed write (dead operator) ends the thread; the drain's next bounded\n 3948│/// send then sees `Disconnected` and detaches the row. `Output` advances\n     │...\n 3956│    sid: u64,\n*3957│    send: SharedSend,\n 3958│    initial: Vec<(u64, Vec<u8>)>,\n 3959│    // Whether `initial` is a synthesized repaint batch (rides the wire-flag —\n 3960│    // the consumer baselines its pseudo-seq jump) vs a raw ring slice\n     │...\n 3989│    // (same-lease) replacements never set the marker, so gate-#7 stays silent.\n*3990│    let emit_revoke_if_marked = |send: &SharedSend| {\n 3991│        let by = revoked_by.lock().ok().and_then(|mut g| g.take());\n 3992│        if let Some(by) = by {\n 3993│            let _ = send.write(&displaced_envelope(sid, &by));\n     │...\n 4074│        // a superseded writer's channel holds only its pre-supersede output\n*4075│        // backlog (seq the consumer dedups via snap-above). The loop ends\n 4076│        // naturally when `tx` drops — and a REVOKED replacement then emits the\n*4077│        // terminal `Displaced` below, BEHIND this drained backlog (order\n 4078│        // preserved), instead of racing it through the live queue. The reorder\n 4079│        // hazard is the INITIAL-BATCH replay, gated above.\n 4080│        mark_blocked(true);\n     │...\n 4253│    /// the next accepted enqueue (heal-on-resume). Mirrored to the perch's\n*4254│    /// `input_backpressure` so the operator sees the drop.\n*4255│    backpressure: AtomicBool,\n 4256│    /// The owning endpoint (the spawn's label; empty = unlabeled / raw test) —\n*4257│    /// the perch whose `input_backpressure` this stamps. Empty ⇒ nowhere to record.\n 4258│    endpoint: String,\n 4259│    /// The writer thread handle (held for ownership; the thread drains until the\n 4260│    /// last `tx` clone drops at session teardown, then exits).\n     │...\n 4274│            deliveries,\n*4275│            backpressure: AtomicBool::new(false),\n 4276│            endpoint,\n 4277│            _writer: writer,\n 4278│        })\n     │...\n 4302│            Ok(()) => {\n*4303│                // Heal: input is flowing again — clear a prior backpressure stamp.\n*4304│                if self.backpressure.swap(false, Ordering::AcqRel) {\n*4305│                    self.stamp_backpressure(false);\n 4306│                }\n 4307│                true\n 4308│            }\n     │...\n 4311│                // DROP + surface, but stamp only on the rising edge.\n*4312│                if !self.backpressure.swap(true, Ordering::AcqRel) {\n*4313│                    self.stamp_backpressure(true);\n 4314│                }\n 4315│                false\n 4316│            }\n     │...\n 4324│\n*4325│    /// Mirror the input-backpressure signal to the perch's `info.json` (the\n 4326│    /// broker is the single writer). Best-effort: a session served without a\n 4327│    /// perch (raw broker tests) has nowhere to record.\n*4328│    fn stamp_backpressure(&self, dropping: bool) {\n 4329│        if self.endpoint.is_empty() {\n 4330│            return;\n 4331│        }\n 4332│        let perch = resolve_perch_path(&self.endpoint, ParentHint::Infer);\n*4333│        let _ = spt_store::info::set_input_backpressure(&perch, dropping);\n 4334│    }\n 4335│}\n 4336│\n     │...\n 4396│/// leave the ring torn (a bumped `next_seq` past the ring, an over-cap ring from an\n*4397│/// interrupted prune, a non-monotonic front/back), and replaying those bytes to a\n 4398│/// subscriber risks garbage. So ONLY on the recovered (poisoned) branch, run\n 4399│/// [`OutputLog::clamp_or_reset`]: cheap-check the ring invariants and RESET it empty\n*4400│/// (+ loud log) on any violation. Lost scrollback self-heals on the next PTY output +\n 4401│/// repaint — strictly better than a permanent wedge (fail-fast reintroduces the very\n 4402│/// wedge B-1 kills) or a torn serve (blind recover). The healthy `Ok` path is a pure\n 4403│/// lock — no clamp, no cost on the hot append path.\n     │...\n 4525│        // UNCOALESCED: the count IS the news past the third failure, and the\n*4526│        // ledger's backoff already bounds how fast this path can fire.\n 4527│        None,\n 4528│        None,\n 4529│        &policy,\n     │...\n 4539│// [impl->REQ-SEAL-CEREMONY-TOTP]\n*4540│fn reply_seal_ceremony(send: &SharedSend, outcome: &str, detail: String, token: Option<String>) {\n 4541│    let payload = serde_json::to_value(SealCeremonyReply {\n 4542│        outcome: outcome.to_string(),\n 4543│        detail,\n     │...\n 4640│/// — the seal sibling of [`alert_bringup_brute_force`], same shape: off the\n*4641│/// dispatch thread, fire-and-forget with a LOUD stderr fallback (silence is\n 4642│/// the one thing brute force is buying), rate-bounded by the seal ledger's\n*4643│/// own backoff.\n 4644│// [impl->REQ-SEAL-CEREMONY-TOTP]\n 4645│fn alert_seal_ceremony_brute_force(subnet: &str, failures: u32) {\n 4646│    let subnet = subnet.to_string();\n     │...\n 4837│        // query itself no longer reaches the ring); the CPR written to the\n*4838│        // child's input then echoes back as output and advances the ring one\n 4839│        // hop later, well within the poll cadence. A re-render works the same\n 4840│        // as before; a non-echoing ConPTY stays unobservable (the latch).\n 4841│        input.enqueue_record(InputRecord::probe(INJECT_SETTLE_PROBE.to_vec()));\n     │...\n 4870│/// Layer 2 (REQ-INJECT-MULTILINE-INTEGRITY): after a `{commit}`, wait a bounded window\n*4871│/// for the typed payload's HEAD to echo back on the session ring (bytes produced since\n 4872│/// `seq_start`), then verify. A swallowed head means the prefix never appears. Empty\n 4873│/// payload (keys-only sequence) is vacuously verified with no wait.\n 4874│///\n     │...\n 4908│\n*4909│/// Layer 3 (REQ-INJECT-MULTILINE-INTEGRITY, the ruling's named fallback under the\n 4910│/// settle-gate): enqueue payload text in bounded chunks rather than one write, so no\n 4911│/// single huge write races the terminal's input coalescer. Order is preserved (single\n 4912│/// FIFO, single writer). The reader is already confirmed live by the settle-gate before\n     │...\n 5075│    // delivery. So an adapter that KNOWS its harness echoes declares the capability\n*5076│    // (parallel to the ruling's \"bracketed-paste where the harness declares it\"); Layer 1\n 5077│    // (the settle-gate) is the UNCONDITIONAL root fix. The int gate also forces it on\n 5078│    // (`SPT_INJECT_FORCE_ECHO_MISS`) to exercise the re-drive/spool wiring on any platform.\n 5079│    // AMBIENT env can NOT arm this: both vars are scrubbed at daemon startup\n     │...\n 5135│                    committed = true;\n*5136│                    // Layer 2: verify the typed head echoed back — ONLY where the terminal\n 5137│                    // demonstrably echoes (else a non-echoing PTY's incidental output would\n 5138│                    // false-read head-loss). Where it does not echo, Layer 1 stands alone.\n 5139│                    if !echo_capable || echo_verify_after(&log, seq_start, &sent_text) {\n     │...\n 5169│        if integrity_lost {\n*5170│            // Layer 2 fallback: the typed head never echoed, even after a re-drive.\n 5171│            // A live-SENT inject leaves no spool copy, so convert the silent+unrecoverable\n 5172│            // truncation into recoverable+loud — re-spool the envelope (idle-eligible,\n 5173│            // poll-fed) with a distinct integrity marker. NOT a binary fault (the binary\n     │...\n 5225│                // A repeat miss of an already-respooled envelope (e.g. the checkpoint\n*5226│                // duplicate FIRE looping back on a later drain): DEAD-LETTER it loud —\n 5227│                // do NOT respool again (never a silent drop; it still counts as a\n 5228│                // strike), REQ-HAZARD-IDLE-SILENT-NONDELIVERY posture.\n 5229│                spt_proto::emit_line_err!(\n     │...\n 5346│    /// when net is still being brought up (REQ-DAEMON-9 boot-race self-heal):\n*5347│    /// a `OnceLock` so the background net-retry can ATTACH the host after bind\n 5348│    /// without a relock on the hot effect-dispatch read path (`.get()` is\n 5349│    /// lock-free). Settable exactly once — the first host wins.\n 5350│    net: std::sync::OnceLock<NetHost>,\n     │...\n 5374│    /// write-stomp this REQ kills). An id is claimed for the duration of one spawn;\n*5375│    /// a duplicate wake for a claimed-or-already-live endpoint stands down (no-op ack).\n 5376│    wake_inflight: Mutex<HashMap<String, WakeClaim>>,\n 5377│    /// Monotonic claim generation (#235). Handed to each claim so a taken-over\n 5378│    /// holder's late RAII drop cannot release its successor's claim.\n     │...\n 5451│    /// worth covering is exactly the window the bring-up will wait through. A\n*5452│    /// failed spawn writes nothing back and its entry simply expires.\n 5453│    // [impl->REQ-ER-BRINGUP-INFLIGHT-LEDGER]\n 5454│    bringups_in_flight: Mutex<HashMap<String, Instant>>,\n 5455│    /// The PENDING seal ceremonies (WAX-SEAL W2, releases#21), keyed by the\n     │...\n 5469│/// overlay, the throttle ledger and the abort sweep are ONE machinery; the\n*5470│/// purpose decides only the admit arm. Tracked daemon-side on the pending\n 5471│/// entry — nothing about it rides the attach wire, which is what lets an N-1\n 5472│/// rc client host an enrollment ceremony unchanged (the brief's own text\n 5473│/// carries the ENROLL framing).\n     │...\n 5483│        pubkey_hex: String,\n*5484│        /// The seam backend that minted the keypair (e.g. `hello-kcm-rs256`).\n*5485│        backend_kind: String,\n 5486│    },\n 5487│}\n 5488│\n     │...\n 5519│    /// The requester's reply channel (the blocked `seal_ceremony` caller).\n*5520│    requester: SharedSend,\n 5521│    /// The requester conn's id — the conn-death abort key.\n 5522│    requester_conn: u64,\n 5523│    /// The controller conn's id at ceremony open — the detach abort key, and\n     │...\n 5710│    /// Attach a network host to a broker that was bound net-less (REQ-DAEMON-9):\n*5711│    /// the boot-race self-heal path calls this once the background retry brings\n 5712│    /// the net endpoint up, after which the dispatcher + peer pump are spawned.\n 5713│    /// Idempotent by `OnceLock` — a second attach is a no-op returning `false`\n 5714│    /// (the first host wins); the hot read path (`net()`) never blocks on it.\n     │...\n 5850│        };\n*5851│        // A real (immediately-abandoned) socket pair for the sink's SharedSend\n 5852│        // identity — nothing ever writes to it (the fixture invariant), so the\n 5853│        // dropped peer is irrelevant; the stall signal is the injected\n 5854│        // `write_blocked_since`, not a real socket block.\n     │...\n 5870│        let (_recv, send_half) = server.split();\n*5871│        let send: SharedSend = Arc::new(BrokerConn::new(send_half, brain_write_deadline()));\n 5872│        let (tx, rx) = sync_channel::<CtrlMsg>(CONTROLLER_CHANNEL_DEPTH);\n 5873│        // Drain-forever (never a socket write, never finishes while tx lives):\n 5874│        // stays un-reapable as a live-but-wedged writer even under child output.\n     │...\n 5944│    /// drives its handler to EOF cleanup within the write bound — without the\n*5945│    /// black-holed client dropping its end.\n 5946│    // [impl->REQ-HAZARD-SHAREDSEND-NO-BLOCKING-WRITE-UNDER-LOCK]\n 5947│    pub fn conn_handler_count(&self) -> usize {\n 5948│        self.conn_handlers.load(Ordering::Acquire)\n     │...\n 5995│    /// trip) promotes a ready update candidate only once this reads `false`: an OLD\n*5996│    /// generation whose local controller conn is black-holed reads wedged until the W2\n 5997│    /// stall-evict releases it, so `brain.ready` inside the 15 s window can no longer\n 5998│    /// promote onto a still-frozen control plane (the 22:47 false-promote). A cleanly-\n 5999│    /// closed old conn is simply absent → `false` at once (the normal fast promote).\n     │...\n 6066│        // [impl->REQ-HAZARD-SHAREDSEND-NO-BLOCKING-WRITE-UNDER-LOCK]\n*6067│        let send: SharedSend = Arc::new(BrokerConn::new(send, brain_write_deadline()));\n 6068│        // Base attribution fact (F-039 leg b): broker clients are brains; role\n 6069│        // facts (controller/viewer/presence/stream subscriber) accrete at the\n 6070│        // attach sites. [impl->REQ-CONN-POISON-ATTRIBUTION]\n     │...\n 6199│                KIND_NET_DIAL_LOOPBACK => {\n*6200│                    if let Err(msg) = self.dispatch_net_dial_loopback(&send) {\n 6201│                        send_error(&send, &msg);\n 6202│                    }\n 6203│                }\n     │...\n 6225│                KIND_NET_STREAM_OPEN => match self.dispatch_net_stream_open(env, &send) {\n*6226│                    // ConnectionBound open → track for the conn-exit sweep\n 6227│                    // (a journaled replay returns the SAME id — dedup keeps\n 6228│                    // the sweep list exact).\n 6229│                    // [impl->REQ-STREAM-LEASE-CLASSES]\n     │...\n 6233│                },\n*6234│                KIND_NET_STREAM_SEND => {\n 6235│                    if let Err(msg) = self.dispatch_net_stream_send(env, &send) {\n 6236│                        send_error(&send, &msg);\n 6237│                    }\n     │...\n 6254│                    // below, byte-identical (the stable KH-2.3 wire fact the\n*6255│                    // dispatcher's fallback gate keys on). Never set in\n 6256│                    // production.\n 6257│                    if std::env::var(\"SPT_TEST_STREAM_OPENER_UNSUPPORTED\").is_ok() {\n 6258│                        send_error(&send, &format!(\"unknown command kind {:?}\", env.kind));\n     │...\n 6486│    // [impl->REQ-HAZARD-DAEMON-SCHED-NONBLOCKING]\n*6487│    fn dispatch_spawn(&self, env: Envelope, send: &SharedSend) -> Result<u64, String> {\n 6488│        let req: SpawnReq =\n 6489│            serde_json::from_value(env.payload).map_err(|e| format!(\"bad spawn payload: {e}\"))?;\n 6490│        self.dispatch_spawn_policy(req, send, false)\n     │...\n 6499│    // [impl->REQ-SPAWN-FRESH-TRUTHFUL]\n*6500│    fn dispatch_spawn_fresh(&self, env: Envelope, send: &SharedSend) -> Result<Option<u64>, String> {\n 6501│        let req: SpawnReq =\n 6502│            serde_json::from_value(env.payload).map_err(|e| format!(\"bad spawn payload: {e}\"))?;\n 6503│        self.dispatch_spawn_policy(req, send, true)\n     │...\n 6521│    // [impl->REQ-ER-BRINGUP-SPAWNS-SESSION]\n*6522│    fn dispatch_bring_up(&self, env: Envelope, send: &SharedSend) -> Result<(), String> {\n 6523│        self.dispatch_bring_up_within(env, send, BRINGUP_READY_WAIT)\n 6524│    }\n 6525│\n     │...\n 6537│        env: Envelope,\n*6538│        send: &SharedSend,\n 6539│        ready_wait: Duration,\n 6540│    ) -> Result<(), String> {\n 6541│        let req: BringUpReq = serde_json::from_value(env.payload)\n     │...\n 6753│                    // this cwd literally and a missing directory fails the spawn, so\n*6754│                    // the fallback has to be the `None` this call used to pass, i.e.\n 6755│                    // exactly the pre-#178 behaviour rather than a new failure mode.\n 6756│                    spt_proto::emit_line_err!(\n 6757│                        \"ER_CWD_PROVISION_FAIL:{endpoint}: {} ({e}) — launching without the \\\n     │...\n 6780│        // actually needs. Polled rather than signalled because the session is\n*6781│        // registered by the spawn's own conn handler, which has no channel back\n 6782│        // to this one.\n 6783│        let deadline = Instant::now() + ready_wait;\n 6784│        loop {\n     │...\n 6884│    // [impl->REQ-SEAL-NO-CEREMONY-SURFACE]\n*6885│    fn dispatch_seal_ceremony(&self, env: Envelope, send: &SharedSend) -> Result<(), String> {\n 6886│        let req: SealCeremonyReq = serde_json::from_value(env.payload)\n 6887│            .map_err(|e| format!(\"bad seal-ceremony payload: {e}\"))?;\n 6888│        let refuse = |outcome: &str, detail: String| {\n     │...\n 6989│        offers: MintOffers,\n*6990│        send: &SharedSend,\n 6991│    ) -> Result<(), String> {\n 6992│        // THE SURFACE (operator ruling 4). Session first, then the seat.\n 6993│        let Some(session_id) = self.session_for_endpoint(endpoint) else {\n     │...\n 7097│    // [impl->REQ-SEAL-ENROLL-VERB]\n*7098│    fn dispatch_seal_enroll(&self, env: Envelope, send: &SharedSend) -> Result<(), String> {\n 7099│        let req: SealEnrollReq = serde_json::from_value(env.payload)\n 7100│            .map_err(|e| format!(\"bad seal-enroll payload: {e}\"))?;\n 7101│        let refuse = |outcome: &str, detail: String| {\n     │...\n 7147│                     or revocation needs an operator ruling.\",\n*7148│                    req.subnet, held.pubkey_hex, held.backend_kind\n 7149│                ),\n 7150│            );\n 7151│        }\n     │...\n 7164│             subnet: {}\\n\\\n*7165│             backend: {}\\n\\\n 7166│             pubkey-sha256: {fingerprint}\\n\\\n 7167│             A member-or-admin code of '{}' admits this enrollment; Esc cancels.\",\n*7168│            req.subnet, req.backend_kind, req.subnet\n 7169│        );\n 7170│        debug_assert!(\n 7171│            brief.chars().count() <= SEAL_CEREMONY_CONTENT_MAX_CHARS,\n     │...\n 7180│                pubkey_hex: req.pubkey_hex.clone(),\n*7181│                backend_kind: req.backend_kind.clone(),\n 7182│            },\n 7183│            // An enrollment ceremony IS an enrollment: neither mint-path\n 7184│            // offer is meaningful on its overlay.\n     │...\n 7202│        env: Envelope,\n*7203│        send: &SharedSend,\n 7204│    ) -> Result<(), String> {\n 7205│        use spt_store::engineroom as er;\n 7206│        let req: SealCeremonyCodeReq = serde_json::from_value(env.payload)\n     │...\n 7241│        // would let a broken client shut the gate a human needs), and every\n*7242│        // failed proof leaves the ceremony PENDING: the overlay falls back\n 7243│        // to TOTP code entry on the same overlay.\n 7244│        // [impl->REQ-SEAL-CEREMONY-FIDO2]\n 7245│        if let Some(sig_hex) = &req.signature_hex {\n     │...\n 7313│            );\n*7314│            if let Err(e) = spt_store::enroll::verify_backend_signature(\n*7315│                &enrollment.backend_kind,\n 7316│                &enrollment.pubkey_hex,\n 7317│                &payload,\n 7318│                sig_hex,\n 7319│            ) {\n*7320│                refuse_proof(format!(\"{e} — fall back to the TOTP code.\"));\n 7321│                return Ok(());\n 7322│            }\n 7323│            // Verified: mint with the pinned spellings and end the ceremony.\n     │...\n 7427│                } else if let (Some(pk), Some(bk)) =\n*7428│                    (&req.enroll_pubkey_hex, &req.enroll_backend_kind)\n 7429│                {\n 7430│                    // [impl->REQ-SEAL-ENROLL-SHORTCUT-E]\n 7431│                    self.mint_ceremony_seal_enrolling(req.ceremony_id, now, pk, bk)\n     │...\n 7617│        pubkey_hex: &str,\n*7618│        backend_kind: &str,\n 7619│    ) -> (&'static str, String, Option<String>) {\n 7620│        let (subnet, endpoint, content) = {\n 7621│            let pending = recover(&self.ceremonies);\n     │...\n 7653│            &subnet,\n*7654│            backend_kind,\n 7655│            now,\n 7656│        ) {\n 7657│            Ok(_) => {}\n     │...\n 7744│                \"seal {} minted by {minter}; authenticator enrolled for node {node} x \\\n*7745│                 subnet '{subnet}' ({backend_kind}).\",\n 7746│                record.token\n 7747│            ),\n 7748│            Some(record.token),\n     │...\n 7765│    ) -> (&'static str, String, Option<String>) {\n*7766│        let (subnet, pubkey_hex, backend_kind) = {\n 7767│            let pending = recover(&self.ceremonies);\n 7768│            let Some(p) = pending.get(&ceremony_id) else {\n 7769│                return (\n     │...\n 7776│                pubkey_hex,\n*7777│                backend_kind,\n 7778│            } = &p.purpose\n 7779│            else {\n 7780│                return (\n     │...\n 7785│            };\n*7786│            (p.subnet.clone(), pubkey_hex.clone(), backend_kind.clone())\n 7787│        };\n 7788│        let node = match spt_store::nodeid::load_or_create() {\n 7789│            Ok(id) => spt_net::net::registry::key_prefix(&id.public_key().to_hex()),\n     │...\n 7807│            &subnet,\n*7808│            &backend_kind,\n 7809│            now,\n 7810│        ) {\n 7811│            Ok(r) => r,\n     │...\n 7838│        spt_proto::emit_line_err!(\n*7839│            \"SEAL_ENROLL_MINTED: ceremony={ceremony_id} node={node} subnet={} backend={}\",\n*7840│            record.subnet, record.backend_kind\n 7841│        );\n 7842│        (\n 7843│            SEAL_CEREMONY_ADMITTED,\n     │...\n 7845│                \"{SEAL_ENROLLED}\\npubkey_hex: {}\\nnode: {}\\nsubnet: {}\\nenrolled_at: {}\\n\\\n*7846│                 backend_kind: {}\",\n 7847│                record.pubkey_hex, record.node, record.subnet, record.enrolled_at,\n*7848│                record.backend_kind\n 7849│            ),\n 7850│            None,\n 7851│        )\n     │...\n 8087│        req: SpawnReq,\n*8088│        send: &SharedSend,\n 8089│        fresh: bool,\n 8090│    ) -> Result<Option<u64>, String> {\n 8091│        // releases#199 instrument, BROKER SIDE. The launch-path stamps say when the\n     │...\n 8286│                                    // do not drop HostedSession/PTY resources or call\n*8287│                                    // dispatch_teardown as a fallback after refusal.\n 8288│                                    return Err(format!(\n 8289│                                        \"SPAWN_ZOMBIE_REAP_DECLINE:{}: session {sid}: {reason}\",\n 8290│                                        req.endpoint\n     │...\n 8341│                            \"SPAWN_DEDUP:{}: endpoint already has a live session {sid} — \\\n*8342│                             single-flight wake no-op ack [REQ-SPAWN-COLLISION-GUARD-LIVE-DUP]\",\n 8343│                            req.endpoint\n 8344│                        );\n 8345│                        let frame = Envelope::new(\n     │...\n 8444│        // (W1 / REQ-HAZARD-INJECT-CONTROL-COEXIST). The controller write is no\n*8445│        // longer inline under the log lock, so a backed-up controller can never\n 8446│        // wedge the session; a fully-stalled controller is detached after the\n 8447│        // deadline (bounded wedge, never permanent).\n 8448│        let log_drain = Arc::clone(&log);\n     │...\n 8556│            // about to vanish (the relatch the W2 int leg caught live). The\n*8557│            // removed entry hands back the DRAIN handle the ordering below needs.\n 8558│            let removed = recover(&sessions_exit).remove(&id);\n 8559│            // releases#199 instrument, THE FOURTH CANDIDATE the A/B/C set did not\n 8560│            // name: a harness that spawns and dies immediately produces a row that\n     │...\n 8749│    /// self-kick guard.\n*8750│    fn dispatch_subscribe(&self, env: Envelope, send: &SharedSend) -> Result<u64, String> {\n 8751│        let req: SubscribeReq = serde_json::from_value(env.payload)\n 8752│            .map_err(|e| format!(\"bad subscribe payload: {e}\"))?;\n 8753│        // Clone the log Arc out from under the sessions lock, then resolve under\n     │...\n 8762│        // post-removal subscribe gets a prompt \"no such session\" error — both\n*8763│        // non-silent. The rc-side status-gate (a) + first-event backstop (b) cover\n 8764│        // the rest.\n 8765│        let log = {\n 8766│            let sessions = recover(&self.sessions);\n     │...\n 8814│    /// a no-op if a newer controller already took over, or the session is gone.\n*8815│    fn dispatch_unsubscribe(&self, env: Envelope, send: &SharedSend) -> Result<(), String> {\n 8816│        let req: UnsubscribeReq = serde_json::from_value(env.payload)\n 8817│            .map_err(|e| format!(\"bad unsubscribe payload: {e}\"))?;\n 8818│        let log = {\n     │...\n 8840│    /// `(session_id, op_id)` after a brain crash is deduped (the PTY is not\n*8841│    /// written twice), and either outcome — fresh apply or dedup — is acked back\n 8842│    /// with an [`crate::msg::KIND_APPLIED`] frame so the brain can retire the\n 8843│    /// effect (B5 / KNOWN-HAZARDS 7.2). Without an `op_id` it is the legacy\n*8844│    /// direct write (no dedup, no ack).\n 8845│    // [impl->REQ-HAZARD-RESTART-IDEMPOTENT]\n*8846│    fn dispatch_input(&self, env: Envelope, send: &SharedSend) -> Result<(), String> {\n 8847│        let req: InputReq =\n 8848│            serde_json::from_value(env.payload).map_err(|e| format!(\"bad input payload: {e}\"))?;\n 8849│        let bytes = decode_bytes(&req.data_b64).map_err(|e| format!(\"bad input base64: {e}\"))?;\n     │...\n 8880│        // Layer C: when a (non-faulted) translation binary is attached, fire a\n*8881│        // CONTENT-FREE `{type:input}` ping so the binary can track operator idleness\n 8882│        // — best-effort, never carries the keystroke bytes (doyle gate #1, privacy).\n 8883│        if let Some(tr) = &translation {\n 8884│            if !tr.faulted.load(Ordering::Relaxed) {\n     │...\n 8910│                        // Buffer-or-ENQUEUE INSIDE the journal effect so the op is\n*8911│                        // still recorded applied + acked (dedup-safe) whether the byte\n 8912│                        // buffers (inject floor held), enqueues, or is dropped under\n*8913│                        // backpressure. The effect is now the non-blocking enqueue —\n 8914│                        // PtyWrite is ephemeral, so Applied-at-enqueue is sound\n*8915│                        // (V0.13.0-P0 design); the ack means \"accepted + ordered + will\n 8916│                        // land,\" and rc does not gate on landing.\n 8917│                        if !buffered(&bytes) {\n 8918│                            input.enqueue(bytes.clone());\n     │...\n 8924│                // (REQ-HAZARD-INPUT-ACK-BACKPRESSURE). The fire-and-forward\n*8925│                // operator/rc path sends `ack=false`: writing the ack back onto the\n 8926│                // same brain↔broker conn it is flooding with input fills the return\n 8927│                // direction and deadlocks the per-conn handler (the wedge). With no\n*8928│                // ack the handler never writes back while servicing the flood, so it\n*8929│                // always drains. The acked path (`shellchan`, one-at-a-time) still\n 8930│                // gets its `KIND_APPLIED`. Dedup is unaffected either way (the\n*8931│                // applied-set is the exactly-once anchor, not the ack frame).\n 8932│                // [impl->REQ-HAZARD-INPUT-ACK-BACKPRESSURE]\n*8933│                if req.ack {\n 8934│                    send_frame(\n 8935│                        send,\n 8936│                        &applied_envelope(req.session_id, op, outcome == Outcome::Applied),\n     │...\n 9085│    // [impl->REQ-INPUT-PROVENANCE-ACCEPTANCE-REPORT]\n*9086│    fn dispatch_input_paths_reply(&self, env: Envelope, send: &SharedSend) -> Result<(), String> {\n 9087│        let reply: spt_net::net::attach::InputPathReply = serde_json::from_value(env.payload)\n 9088│            .map_err(|e| format!(\"bad input paths reply: {e}\"))?;\n 9089│        let books: Vec<_> = {\n     │...\n 9124│    /// Replies [`KIND_ENDPOINT_INJECTED`] with `delivered` so the caller knows\n*9125│    /// whether to fall back to the spool.\n 9126│    ///\n 9127│    /// Idle delivery is translation-binary-ONLY (ADR-0022 amendment): a working\n 9128│    /// (non-faulted) binary OWNS the choreography (the envelope is queued to its\n     │...\n 9135│    // [impl->REQ-MSG-IDLE-TRANSLATION-BINARY]\n*9136│    fn dispatch_endpoint_input(&self, env: Envelope, send: &SharedSend) -> Result<(), String> {\n 9137│        let req: EndpointInputReq = serde_json::from_value(env.payload)\n 9138│            .map_err(|e| format!(\"bad endpoint-input payload: {e}\"))?;\n 9139│        let bytes =\n     │...\n 9165│                //     injects mid-turn, atomic via the InjectFloor. The no-binary\n*9166│                //     fallback (spool vs binary-or-nothing drop) is the CALLER's\n 9167│                //     prefer/force decision; the broker just reports delivered=false.\n 9168│                let idle = spt_store::perch::resolve_idle_file(\n 9169│                    &req.endpoint,\n     │...\n 9175│                // route to the binary (idle window or a native send) and the attached\n*9176│                // binary faulted, try to rebuild it BEFORE falling back to spool. The\n 9177│                // rebuild is bounded by the give-up budget (loud when exhausted).\n 9178│                if (idle || req.native)\n 9179│                    && matches!(&translation, Some(tr) if tr.faulted.load(Ordering::Relaxed))\n     │...\n 9211│                // A native caller ignores the hint and decides spool-vs-drop by its\n*9212│                // prefer/force flag. Raw `payload + \\r` is NOT a fallback (it does not\n 9213│                // submit on a modern TUI — the F-019 silent pseudo-delivery); the\n 9214│                // inbound is never lost (spooled, poll-fed) and the miss is LOUD.\n 9215│                // [impl->REQ-MSG-IDLE-TRANSLATION-BINARY]\n     │...\n 9244│    /// and pushes a `size` frame to every viewer (the letterbox feed).\n*9245│    fn dispatch_resize(&self, env: Envelope, send: &SharedSend) -> Result<(), String> {\n 9246│        let req: ResizeReq =\n 9247│            serde_json::from_value(env.payload).map_err(|e| format!(\"bad resize payload: {e}\"))?;\n 9248│        let (session, log) = {\n     │...\n 9269│        // surface resize, and replay the held output at the geometry it was EMITTED\n*9270│        // under. A FAILED surface resize rolls back — grid geometry, stored size and\n 9271│        // epoch untouched, held output replayed at the old geometry.\n 9272│        // [impl->REQ-RC-RESIZE-GEOMETRY-EPOCH]\n 9273│        begin_resize_serialized(&log, req.rows, req.cols)?;\n     │...\n 9291│    // [impl->REQ-RC-HITCH-DISCRIMINATOR]\n*9292│    fn dispatch_net_reactor_diag(&self, send: &SharedSend) {\n 9293│        let host = self.net.get();\n 9294│        let reply = serde_json::json!({\n 9295│            \"diagnostic\": \"rc-hitch\",\n     │...\n 9309│    // [impl->REQ-DAEMON-2]\n*9310│    fn dispatch_net_status(&self, send: &SharedSend) {\n 9311│        let reply = match self.net.get() {\n 9312│            Some(host) => {\n 9313│                // Physical bounded-lifetime gauges (ADR-0040, KH 7.44): rows\n     │...\n 9350│    // [impl->REQ-STATUS-LIVE-SUPERVISOR-PID]\n*9351│    fn dispatch_broker_image(&self, send: &SharedSend) {\n 9352│        // Daemon::run serves the broker and runs spawn_brain_supervisor on\n 9353│        // threads in this process; only the supervised brain is a child process.\n 9354│        let pid = std::process::id();\n     │...\n 9382│    // [impl->REQ-UPDATE-RUNNING-IMAGE-SURFACE]\n*9383│    fn dispatch_coordinator_image_announce(&self, env: Envelope, send: &SharedSend) {\n 9384│        let supervised = crate::brainproc::supervised_generation();\n 9385│        let accepted = match serde_json::from_value::<CoordinatorImageAnnounce>(env.payload) {\n 9386│            Ok(a) if coordinator_announce_accepted(a.generation, supervised) => {\n     │...\n 9406│    // [impl->REQ-UPDATE-RUNNING-IMAGE-SURFACE]\n*9407│    fn dispatch_coordinator_image(&self, send: &SharedSend) {\n 9408│        let version = recorded_coordinator_image(\n 9409│            self.coordinator_image\n 9410│                .lock()\n     │...\n 9426│    // [impl->REQ-HAZARD-BROKER-VIEWER-BRAIN-DECOUPLE]\n*9427│    fn dispatch_stall_evicts(&self, send: &SharedSend) {\n 9428│        let (count, last_ms) = stall_evict_stats();\n 9429│        let frame = Envelope::new(\n 9430│            KIND_STALL_EVICTS_REPLY,\n     │...\n 9438│    /// supervisor's restart signal so it cycles the brain child onto the swapped\n*9439│    /// binary with `start-reason=update`, then ack. `honored` reflects whether a\n 9440│    /// supervisor is wired (a bare test broker has none → accepted-but-unhonored).\n 9441│    /// The broker — which observes every respawn — stamps the `update` reason,\n 9442│    /// keeping planned-vs-crash authoritative on this side (V2).\n     │...\n 9444│    // [impl->REQ-UPD-3]\n*9445│    fn dispatch_brain_restart(&self, send: &SharedSend) {\n 9446│        let honored = match self.brain_restart.get() {\n 9447│            Some(signal) => {\n 9448│                signal.request();\n     │...\n 9472│    // [impl->REQ-HAZARD-RESTART-IDEMPOTENT]\n*9473│    fn dispatch_net_dial(&self, env: Envelope, send: &SharedSend) -> Result<(), String> {\n 9474│        let req: NetDialReq = serde_json::from_value(env.payload)\n 9475│            .map_err(|e| format!(\"bad net-dial payload: {e}\"))?;\n 9476│        let host = self","missingPaths":["crates/spt-daemon/src/net"],"truncation":{"content":" 69|    KIND_NET_STATUS, KIND_NET_STATUS_REPLY, KIND_NET_STREAMS, KIND_NET_STREAMS_REPLY,\n*70|    KIND_NET_STREAM_OPEN, KIND_NET_STREAM_OPENED, KIND_NET_STREAM_OPENER, KIND_NET_STREAM_OPENER_REPLY, KIND_NET_STREAM_RETIRE, KIND_NET_STREAM_RETIRED, KIND_NET_STREAM_SEND, KIND_NET_STREAM_SUBSCRIBE,\n 71|    KIND_NET_STREAM_UNSUBSCRIBE, KIND_NET_STREAM_UNSUBSCRIBED,\n 72|    KIND_MET_MEMBER, KIND_PAIR_CODE_SUBMIT, KIND_PAIR_JOIN, KIND_PAIR_JOINED, KIND_PAIR_MEET, KIND_RESIZE, KIND_SESSIONS, KIND_SESSIONS_REPLY, KIND_SPAWN,\n 73|    BringUpReq, BroughtUpReply, BRING_UP_ADMITTED, BRING_UP_ADMIT_PREFIX, BRING_UP_ALREADY_LIVE, BRING_UP_REFUSED, KIND_BRING_UP, KIND_BROUGHT_UP,\n...\n 86|/// The shared, serialized send side of one brain connection. Output frames,\n*87|/// replay frames, command acks, and exit/error events all write through this.\n 88|/// `pub(crate)`: the net host's stream logs (D4b) live-send through the same\n 89|/// handle under the same gate discipline. Round-4\n 90|/// (REQ-HAZARD-SHAREDSEND-NO-BLOCKING-WRITE-UNDER-LOCK): no longer a raw\n...\n 93|/// matching stays `Arc::ptr_eq`.\n*94|pub(crate) type SharedSend = Arc<BrokerConn>;\n 95|\n 96|/// Default bounded output-log depth (chunks). Large enough that a brain restart\n 97|/// window never evicts unreplayed output in practice; the bound is what keeps a\n...\n 125|/// thread `try_send`s output frames into `tx` (a bounded queue); a dedicated\n*126|/// `writer` thread does the BLOCKING socket write, so a wedged viewer backs up\n 127|/// only its own queue — never the drain. When the queue overflows the sink is\n 128|/// dropped (the `tx` closes → the writer ends) and removed from the map.\n 129|struct ViewerSink {\n...\n 133|    /// (a dropped brain connection removes its viewer rows); never written here.\n*134|    send: SharedSend,\n 135|    /// The viewer's ORIGIN NODE hex, when it presented one (`None` for a local\n 136|    /// viewer that carries no node identity) — RETAINED for attachment-frame\n 137|    /// composition ONLY (releases#44, REQ-ATTACH-LINK-PUSH).\n...\n 165|/// merely-slow controller DROPS chunks + falls behind the ring, and only a channel\n*166|/// that stays full for [`CONTROLLER_WRITE_DEADLINE`] (tracked via\n 167|/// [`ControllerSink::last_ok`]) is detached. Generous so a momentary slow consumer\n 168|/// never trips the deadline.\n 169|const CONTROLLER_CHANNEL_DEPTH: usize = 4096;\n...\n 173|/// (W1, refined by b4 / REQ-HAZARD-VIEWER-STARVE-UNDER-CONTROLLER-BACKPRESSURE). This\n*174|/// BOUNDS the wedge: a backed-up controller falls behind for at most this long before\n 175|/// eviction — never forever (the v0.12.x root) — and the drain NEVER blocks or sleeps\n 176|/// (a single off-lock `try_send` per chunk; see [`OutputLog::append`]). A live but\n 177|/// merely slow operator lands a frame before this elapses (resetting `last_ok`) and is\n...\n 210|/// How long a controller's writer thread may sit BLOCKED inside a single socket\n*211|/// write — the brain subscriber suspended / black-holed — before a take/reattach\n 212|/// or the `KIND_SESSIONS` reap stall-evicts it (LIFECYCLE-TRUTH W2,\n 213|/// REQ-HAZARD-BROKER-VIEWER-BRAIN-DECOUPLE). Distinct from and 3× longer than\n 214|/// [`CONTROLLER_WRITE_DEADLINE`] on PURPOSE (doyle ruling Q1): that 5 s bound\n...\n 320|    // every claim read stalled, so every duplicate wake takes over and the double-create\n*321|    // this function exists to prevent comes back at scale. Compiled out of release\n 322|    // entirely, parsed once, and floored so that even in a debug build it cannot be\n 323|    // driven below a value the gate could mistake for a wedge on a healthy holder.\n 324|    #[cfg(debug_assertions)]\n...\n 437|/// An error forbids both kill and forced de-tabling: dropping session resources\n*438|/// is teardown too, not a safe fallback for an identity we could not establish.\n 439|// [impl->REQ-BROKER-ZOMBIE-IDENTITY]\n 440|fn reap_zombie_root(\n 441|    pid: Option<u32>,\n...\n 472|/// PURE resolution of the two liveness probes for [`session_is_zombie`], so the\n*473|/// NO-SNAPSHOT arm is unit-testable WITHOUT a platform that lacks a process\n 474|/// table (the W1 `unconfirmed_verdict` injection shape).\n 475|///\n 476|/// The table WINS wherever it speaks — that is the Windows fix, since a\n...\n 478|/// handle probe is sound: no-table implies unix implies no handle blind spot,\n*479|/// so the two conditions cannot both fail and the fallback is EXACT.\n 480|// [impl->REQ-LIVENESS-ORACLE-SOUND]\n 481|fn resolve_wrapper_alive(table_says: Option<bool>, handle_says: impl FnOnce() -> bool) -> bool {\n 482|    table_says.unwrap_or_else(handle_says)\n...\n 493|    // root that is NOT adapter-labeled was claimed LIVE indefinitely.\n*494|    // NO-SNAPSHOT FALLS BACK, and the fallback is EXACT rather than a\n 495|    // compromise: the handle blind spot is Windows-only (`kill(pid,0)` answers\n 496|    // about the process, not about a handle the caller holds, and Linux demotes\n 497|    // a /proc zombie), while Windows ALWAYS has a process table. So \"no table\"\n...\n 672|/// budget shape: consecutive-failures bounded, healthy-run resets). Mirrors the\n*673|/// psyche crash-loop backoff's bounded give-up.\n 674|const TRANSLATE_RESPAWN_BUDGET: u32 = 3;\n 675|\n 676|/// The effective respawn budget. Production is the const above; the int gate tunes\n...\n 694|// after typing → re-drive once → LOUD spool (silent+unrecoverable → recoverable+loud);\n*695|// (3) chunked-paced write under the gate (bracketed-paste deferred — the binary owns\n 696|// the key/text interleave, not a clean wrap seam; F-019 found it moot for CC submit).\n 697|\n 698|/// The settle-gate deadline (Layer 1): how long the worker probes a PTY for a\n...\n 724|/// The echo-verify wait (Layer 2): how long the worker waits after a `{commit}` for\n*725|/// the typed payload's head to echo back on the session ring before declaring a\n 726|/// verify MISS (round-trip + XON-resume latency bound).\n 727|const INJECT_ECHO_VERIFY_DEADLINE: Duration = Duration::from_millis(1200);\n 728|\n...\n 749|\n*750|/// Chunk size for the paced text write (Layer 3, the ruling's named fallback where\n*751|/// bracketed-paste is not declared): a large payload is enqueued in bounded chunks\n 752|/// rather than one write, so no single huge write races the terminal's coalescer.\n 753|/// Layered UNDER the settle-gate (the reader is already confirmed live before the\n 754|/// first chunk). The int gate tunes it via `SPT_INJECT_TEXT_CHUNK`.\n...\n 763|\n*764|/// Does `haystack` contain `needle` as a contiguous subslice? (Small, allocation-free\n 765|/// — the echo-verify head match over concatenated ring bytes.)\n*766|fn contains_subslice(haystack: &[u8], needle: &[u8]) -> bool {\n 767|    if needle.is_empty() {\n 768|        return true;\n 769|    }\n*770|    if needle.len() > haystack.len() {\n 771|        return false;\n 772|    }\n*773|    haystack.windows(needle.len()).any(|w| w == needle)\n 774|}\n 775|\n 776|/// Pure echo-verify decision (Layer 2, REQ-INJECT-MULTILINE-INTEGRITY): did the\n*777|/// typed payload's HEAD echo back? Compare a bounded prefix of `sent_text` against\n 778|/// the PTY echo captured since the sequence began. A TUI re-renders typed text so the\n 779|/// leading bytes appear in output; a swallowed head means the prefix is ABSENT. An\n 780|/// empty payload (a keys-only sequence — no echoable text) is vacuously verified.\n...\n 823|/// Symmetric with [`ViewerSink`] — a dedicated writer thread does the BLOCKING\n*824|/// socket write so a backed-up controller can never stall the session drain\n 825|/// thread (the v0.12.x wedge: the controller write was inline on the drain,\n 826|/// holding `Mutex<OutputLog>`). Unlike a viewer it is AUTHORITATIVE: its writer\n 827|/// advances `delivered_through` on each successful write, and it is never evicted\n...\n 833|    /// for the `exit`-frame fan-out ([`OutputLog::all_sinks`]).\n*834|    send: SharedSend,\n 835|    /// The controller's ATTACH GENERATION (ADR-0038 Amendment fix 6,\n 836|    /// REQ-SERVE-OWNERSHIP-GENERATION): operator-minted wall-ms from the wire\n 837|    /// Request (`0` = local / N-1). A same-identity re-take with an OLDER\n...\n 873|    /// `Some(Instant::now())` immediately BEFORE it enters a blocking `write_frame`\n*874|    /// and back to `None` the instant the write returns. A reader\n 875|    /// ([`OutputLog::controller_stalled`]) sees a `Some` older than\n*876|    /// [`BRAIN_WRITE_DEADLINE`] as a writer WEDGED on a suspended/black-holed brain\n 877|    /// conn and stall-evicts it — the signal `last_ok` (channel-handoff time) cannot\n 878|    /// give: an IDLE controller (writer parked on `rx.recv()`, `None` here) and a\n 879|    /// BLOCKED one (writer stuck in the socket write, `Some` here) both leave\n...\n 900|\n*901|/// One run of held-back output inside a resize transition, tagged with the\n 902|/// GEOMETRY (and its epoch) the bytes were EMITTED under\n 903|/// (REQ-RC-RESIZE-GEOMETRY-EPOCH). The grid replays each segment at its OWN\n 904|/// geometry, which is the whole content of \"every byte is parsed at the geometry\n...\n 918|/// Amendment II). While one of these is installed, [`OutputLog::append`] still\n*919|/// assigns a `seq` and RINGS every chunk — the ring stays the scrollback/resume\n 920|/// authority for raw history — but delivery to the controller and the viewers is\n 921|/// SUPPRESSED (a skip, never a block: the drain runs at full PTY speed, hazard\n*922|/// 7.12 intact), and the chunk is held back from `grid.advance`, tagged with the\n 923|/// geometry it was emitted under. [`OutputLog::commit_resize`] /\n 924|/// [`OutputLog::abort_resize`] then replay the held segments into the grid at\n 925|/// their own geometries and substitute ONE synthesized sync frame to every\n...\n 939|    /// The geometry (and epoch) in force when the barrier closed — where the grid\n*940|    /// still is, and what a rollback returns to.\n 941|    from: (u16, u16),\n 942|    from_epoch: u64,\n 943|    /// The requested target geometry (and the epoch it opens).\n...\n 1044|    /// of replaying the whole ring from 0. **Viewer writes NEVER move it**\n*1045|    /// (REQ-RCVIEW-1: the brain-resume cursor tracks the controller only).\n 1046|    ///\n 1047|    /// **Advanced only on a successful socket write** (`Ok`), and **monotonic**\n 1048|    /// (never decreases) — see [`advanced_cursor`]. Both invariants are\n...\n 1064|    /// instead of the raw ring, so replaying an alt-screen TUI into a fresh terminal\n*1065|    /// no longer corrupts scrollback. Single-writer (the one drain thread), mirroring\n 1066|    /// the ring's single producer.\n 1067|    grid: ScreenGrid,\n 1068|    /// The grid's GEOMETRY EPOCH (REQ-RC-RESIZE-GEOMETRY-EPOCH): monotonic, bumped\n...\n 1099|    /// teardown. The ring deliberately keeps the suppressed raw bytes (it is the\n*1100|    /// scrollback authority), so a resume asking BELOW this floor would replay\n*1101|    /// mixed-geometry corruption straight back onto a live terminal; instead it\n 1102|    /// is served the cold-attach shape ([`repaint_initial`]: sync repaint + skip\n 1103|    /// to live). At-least-once holds in effect — the repaint supersedes the\n 1104|    /// skipped range. `0` until a transition has ever torn down (no boundary to\n...\n 1109|/// The post-write resume cursor (pure — the D4-1 unit kernel, mirroring\n*1110|/// `brainproc::consumer_gate`/`next_backoff`): advance to `seq + 1` **only** on a\n 1111|/// successful write, and **monotonically** (never below `current`). A failed\n 1112|/// write (`write_ok == false`) leaves the cursor untouched, and a re-send of an\n 1113|/// already-delivered `seq` (an `attach(sub, 0)` rewind, `seq + 1 <= current`)\n...\n 1473|    /// ring torn — an over-cap ring (interrupted prune), a last seq not below\n*1474|    /// `next_seq`, or a non-monotonic front/back — and serving those bytes blind\n 1475|    /// risks garbage to a subscriber. Cheap-check the ring invariants (counts within\n 1476|    /// cap, indices ordered and below `next_seq`); on ANY violation RESET the ring\n 1477|    /// EMPTY (+ loud log) — `next_seq` is left intact so cursors never rewind, and the\n*1478|    /// lost scrollback self-heals on the next PTY output + repaint. Returns `true`\n 1479|    /// iff it reset. A coherent ring (the common case — most panics fire OUTSIDE the\n 1480|    /// ring mutation, poisoning the lock while the buffer stays intact) is untouched.\n 1481|    // [impl->REQ-HAZARD-BROKER-FLOOR-LOCK-POISON]\n...\n 1483|        let within_cap = self.ring.len() <= self.cap_chunks;\n*1484|        let last_below_next = match self.ring.back() {\n 1485|            Some(&(last, _)) => last < self.next_seq,\n 1486|            None => true,\n 1487|        };\n*1488|        let ordered = match (self.ring.front(), self.ring.back()) {\n*1489|            (Some(&(front, _)), Some(&(back, _))) => front <= back,\n 1490|            _ => true,\n 1491|        };\n 1492|        if within_cap && last_below_next && ordered {\n...\n 1498|            \"broker: session {} output ring was torn by a poison-recover \\\n*1499|             (had {had} chunks, next_seq {}); reset to empty — scrollback self-heals \\\n 1500|             on the next output [REQ-HAZARD-BROKER-FLOOR-LOCK-POISON]\",\n 1501|            self.session_id, self.next_seq\n 1502|        );\n...\n 1513|    /// Concatenate ring bytes at or after `from_seq` — the output PRODUCED since a\n*1514|    /// snapshot, used to confirm a typed payload's head echoed back (integrity,\n 1515|    /// Layer 2; readiness Layer 1 gates on `high_water` alone — the probe's own\n 1516|    /// echo is a DSR query the drain strips before append, REQ-DSR-SINGLE-CPR).\n 1517|    /// Best-effort: bytes pruned out of the bounded ring are simply absent (the\n...\n 1531|        self.next_seq += 1;\n*1532|        self.ring.push_back((seq, bytes.to_vec()));\n 1533|        while self.ring.len() > self.cap_chunks {\n 1534|            self.ring.pop_front();\n 1535|        }\n...\n 1618|    /// `SessionInfo.controller_by == None` is ambiguous between empty and\n*1619|    /// local). `None` = no controller at all. The `SharedSend` rides along for\n 1620|    /// the bounded direct-write degrade the exit fan-out uses.\n 1621|    // [impl->REQ-SEAL-NO-CEREMONY-SURFACE]\n*1622|    fn ceremony_surface(&self) -> Option<(SyncSender<CtrlMsg>, SharedSend, u64, bool)> {\n 1623|        self.controller\n 1624|            .as_ref()\n 1625|            .map(|c| (c.tx.clone(), Arc::clone(&c.send), c.send.id(), c.seal_ceremony))\n...\n 1630|    /// seated (Controller / TookControl / the idempotent replay all qualify;\n*1631|    /// a Busy refusal or a viewer fallback must not touch someone else's\n 1632|    /// seat). Runs AFTER the ladder so the ladder stays capability-blind.\n 1633|    // [impl->REQ-SEAL-NO-CEREMONY-SURFACE]\n 1634|    fn stamp_controller_seal_ceremony(&mut self, conn: u64, seal_ceremony: bool) {\n...\n 1684|        // A local IPC subscribe carries no origin and is this node by\n*1685|        // construction; a local `rc` arrives over the in-process loopback conn\n 1686|        // stamped with our OWN handshake-proven id, so both spellings of \"here\"\n 1687|        // must answer the same.\n 1688|        let from_this_node = match by {\n...\n 1815|            // here would let anyone on the box ratchet the human toward a\n*1816|            // backoff by replaying a dead ticket.\n 1817|            // [impl->REQ-ER-BRINGUP-SPAWNS-SESSION]\n 1818|            AdmitTicket::Unredeemed => {\n 1819|                return SeatGate::Refused(\n...\n 1874|/// a credential the gate did not itself verify\") is untouched. What travels is\n*1875|/// the broker's own verdict, keyed by an id a caller can only echo back.\n 1876|///\n 1877|/// The SESSION LABEL travels for a reason that is not convenience: the grant is\n 1878|/// keyed on the session it empowers, and at bring-up time the engine room's\n...\n 1995|    // configuration, not a failed guess, so it must not spend a unit of the\n*1996|    // attempt budget the human needs to get back to the controls.\n 1997|    // `classify_bringup` still rules on it; it simply rules over a ledger\n 1998|    // nothing loaded (`default()` is not a claim about the file — the\n 1999|    // NoAdapter arm ignores the attempt entirely, and nothing is persisted).\n...\n 2014|    // attempt bound's business. Keeping that input a bool is what stops #102\n*2015|    // from touching the backoff schedule at all.\n 2016|    //\n 2017|    // What the presentation type adds is orthogonal (releases#197): an ABSENT\n 2018|    // code is not a failed guess at all, so it must not spend a unit of the\n...\n 2157|/// several stores, and the seat resolver that calls this runs under the lock the\n*2158|/// output drain needs. Fire-and-forget with a LOUD stderr fallback — silence is\n 2159|/// the one thing brute force is buying, so a failure to alert must not itself be\n*2160|/// quiet. The ledger's own backoff gates this path, so it cannot be sprayed.\n 2161|///\n 2162|/// Free-standing because the gate it belongs to is now asked by a caller with no\n 2163|/// session (the bring-up verb): an alert that only fired for one of the two\n...\n 2203|/// A single immediate attempt would therefore miss intermittently and leave the\n*2204|/// row pending forever — the defect back, just rarer and harder to see. So this\n 2205|/// polls the eligibility predicate under a bound and drives once it holds.\n 2206|///\n 2207|/// **Never a refusal, loud on failure** (clause 4, the denial-of-governance\n...\n 2407|    /// the admin bring-up's empowerment (releases#102), spool the briefing that\n*2408|    /// states it, and hand back the operator-facing sentence for the reply.\n 2409|    ///\n 2410|    /// **Why this is not done at the gate, which is where the credential is\n 2411|    /// known.** Two things happen between the gate and a resolved seat, and both\n...\n 2479|        // the endpoint keeps running between attachments — so a human who\n*2480|        // detaches and comes back to the SAME live session is re-handed a\n 2481|        // posture statement they already read, while nothing about the session\n 2482|        // is new. A FRESH session — a new bring-up, or a daemon restart that\n 2483|        // re-hosts one — starts a new log and briefs exactly as before.\n...\n 2560|    /// several stores, and this resolver runs under the lock the output drain\n*2561|    /// needs. Fire-and-forget with a LOUD stderr fallback — silence is the one\n 2562|    /// thing brute force is buying, so a failure to alert must not itself be\n*2563|    /// quiet. The ledger's own backoff gates this path, so it cannot be sprayed.\n 2564|    /// Controller-bound authority (ADR-0052 §3a): a seat change or release\n 2565|    /// DROPS every empowerment the engine room's session holds.\n 2566|    ///\n...\n 2591|\n*2592|    fn become_controller(&mut self, sub: SharedSend, by: Option<String>, from_seq: u64, attach_gen: u64) {\n 2593|        // Drop the prior controller sink first (its writer's live loop ends when\n 2594|        // tx drops), and bump the generation so (a) an in-flight deadline-evict\n 2595|        // for the old controller can't unseat this one and (b) a prior writer\n...\n 2835|    /// socket write for at least `deadline` (the brain-subscriber conn suspended /\n*2836|    /// black-holed). An IDLE controller (writer parked on `rx.recv()`, nothing to\n 2837|    /// write) reads NOT stalled: its [`ControllerSink::write_blocked_since`] is `None`.\n 2838|    /// Pure over the injected `now` + `deadline` so the unit tests it with no thread.\n 2839|    // [impl->REQ-HAZARD-BROKER-VIEWER-BRAIN-DECOUPLE]\n...\n 2852|    /// it (REQ-UPDATE-PROMOTE-DRAINED). A killed OLD brain generation whose local\n*2853|    /// controller conn is black-holed reads wedged here until the W2 stall-evict\n 2854|    /// releases it (or the conn EOFs); a cleanly-closed conn is simply absent. A\n 2855|    /// REMOTE operator's wedged conn (`by: Some`) is the W2 stall-evict concern, NOT\n 2856|    /// an old-gen brain conn, so it is EXCLUDED — a stuck remote viewer must never\n...\n 2885|            \"BRAIN_SUBSCRIBER_STALL_EVICT:{} conn={conn} {} — controller writer blocked > {}ms \\\n*2886|             on a suspended/black-holed brain conn; detached, driven_by released \\\n 2887|             [REQ-HAZARD-BROKER-VIEWER-BRAIN-DECOUPLE]\",\n 2888|            self.session_id,\n 2889|            crate::conn::log_stamp(),\n...\n 2907|    /// live queue. The drain thread fans live frames in via `try_send`.\n*2908|    fn add_viewer(&mut self, sub: SharedSend, from_seq: u64, by: Option<&str>) {\n 2909|        let vid = self.next_viewer_id;\n 2910|        self.next_viewer_id += 1;\n 2911|        // Attribution (F-039 legs b+d): viewer role fact + attach record.\n...\n 2984|        &mut self,\n*2985|        sub: SharedSend,\n 2986|        from_seq: u64,\n 2987|        intent: AttachIntent,\n 2988|        by: Option<String>,\n...\n 3001|        &mut self,\n*3002|        sub: SharedSend,\n 3003|        from_seq: u64,\n 3004|        intent: AttachIntent,\n 3005|        by: Option<String>,\n...\n 3084|        &mut self,\n*3085|        sub: SharedSend,\n 3086|        from_seq: u64,\n 3087|        intent: AttachIntent,\n 3088|        by: Option<String>,\n...\n 3117|        &mut self,\n*3118|        sub: SharedSend,\n 3119|        from_seq: u64,\n 3120|        intent: AttachIntent,\n 3121|        by: Option<String>,\n...\n 3153|        // W2 decouple (REQ-HAZARD-BROKER-VIEWER-BRAIN-DECOUPLE): a controller WEDGED\n*3154|        // on a suspended/black-holed brain conn past BRAIN_WRITE_DEADLINE is\n 3155|        // stall-evicted HERE — the take/reattach self-heals against broker truth\n 3156|        // without waiting for new output (the output-driven mark_controller_gone\n 3157|        // never fires on an idle session). Inline stamp: this path already writes the\n...\n 3176|            //   gen <  incumbent (nonzero)  → a REPLAYED stale Request (an\n*3177|            //     unfinished backlog row whose viewport died raw) — refused\n*3178|            //     busy; the ladder never runs backwards.\n 3179|            //   gen >  incumbent (nonzero)  → the LIVE replacement viewport,\n 3180|            //     Control or Take alike: loud+fenced SUPERSESSION via the full\n 3181|            //     W2 revoke (terminal Displaced + fence moves with the slot) —\n...\n 3255|            // The LOCAL brain re-attaching while a REMOTE controls — never steal;\n*3256|            // fall back to a silent viewer (gate #7 for the local-resume path).\n 3257|            // `by` is None on this arm by construction, so the sink retains no node.\n 3258|            self.add_viewer(sub, from_seq, None);\n 3259|            self.stamp_viewer_count();\n...\n 3294|    /// (REQ-RC-RESIZE-GEOMETRY-EPOCH). From here until commit/abort every appended\n*3295|    /// chunk is held back from the grid and tagged with the geometry it was emitted\n*3296|    /// under. Returns the geometry the grid is currently at (the rollback target).\n 3297|    ///\n 3298|    /// A second concurrent transition is REFUSED rather than queued: the caller is\n 3299|    /// the session's controller (resize is controller-exclusive), so two overlapping\n...\n 3391|    /// transition landed on, concatenated with the `deferred` non-grid bytes the\n*3392|    /// capture-mode replay collected (leg 5: untracked stateful toggles,\n 3393|    /// one-shots and child→client queries, verbatim in emission order) — pushed\n 3394|    /// to every attached sink under the caller's single lock acquisition,\n 3395|    /// substituting for everything delivery suppressed.\n...\n 3459|    /// CAPTURE MODE (the one parser authority — never a second scanner over raw\n*3460|    /// bytes): every sequence the grid does not track is re-encoded into the\n 3461|    /// returned buffer, verbatim in emission order, for the sync frame to flush\n 3462|    /// (REQ-RC-RESIZE-PRESENTATION-BARRIER leg 5 — the non-grid bytes a bare\n 3463|    /// repaint would silently drop).\n...\n 3546|    // [impl->REQ-SERVE-OWNERSHIP-GENERATION]\n*3547|    fn detach_if_gen(&mut self, sub: &SharedSend, gen: Option<u64>) {\n 3548|        if let (Some(g), Some(c)) = (gen, self.controller.as_ref()) {\n 3549|            if c.attach_gen != g {\n 3550|                // Stale generation: never clears the (newer) controller.\n...\n 3561|\n*3562|    fn detach_if(&mut self, sub: &SharedSend) {\n 3563|        let is_ctrl = self\n 3564|            .controller\n 3565|            .as_ref()\n...\n 3716|    /// Whether `sub` is the current controller (the resize-exclusivity check).\n*3717|    fn is_controller(&self, sub: &SharedSend) -> bool {\n 3718|        self.controller\n 3719|            .as_ref()\n 3720|            .is_some_and(|c| Arc::ptr_eq(&c.send, sub))\n...\n 3757|fn viewer_writer(\n*3758|    send: SharedSend,\n 3759|    session_id: u64,\n 3760|    initial: Vec<Envelope>,\n 3761|    rx: Receiver<Envelope>,\n...\n 3767|    struct ExitNote {\n*3768|        send: SharedSend,\n 3769|        session_id: u64,\n 3770|        reason: &'static str,\n 3771|    }\n...\n 3872|struct ExitFanout {\n*3873|    controller: Option<(SyncSender<CtrlMsg>, SharedSend)>,\n*3874|    viewers: Vec<(SyncSender<Envelope>, SharedSend)>,\n 3875|}\n 3876|\n 3877|/// How long the exit waiter re-tries a Full sink queue before degrading to the\n...\n 3882|/// Bounded enqueue-behind-output: retry a Full queue up to\n*3883|/// [`EXIT_ENQUEUE_DEADLINE`], then fall back to the direct bounded conn write\n 3884|/// (the pre-W3 behavior, now the loud DEGRADE instead of the default).\n 3885|/// [impl->REQ-BROKER-OUTPUT-BEFORE-EXIT]\n*3886|fn enqueue_exit_bounded<T>(tx: &SyncSender<T>, mut msg: T, sink: &SharedSend, frame: &Envelope) {\n 3887|    let deadline = Instant::now() + EXIT_ENQUEUE_DEADLINE;\n 3888|    loop {\n 3889|        match tx.try_send(msg) {\n...\n 3929|/// (`seq > cursor` — a frame the drain dropped while the controller channel was Full,\n*3930|/// the b4 backpressure) FREEZES the cursor at last-contiguous, so a re-attaching\n 3931|/// brain's `resume_seq` never skips a dropped chunk (a high-watermark jump PAST the\n 3932|/// gap would be a not-exactly-once / non-gapless resume = a B2 violation). An\n 3933|/// already-delivered `seq` (`seq < cursor`, a rewind re-send) is a no-op. A single CAS,\n...\n 3944|/// cursor on each success), then drain live [`CtrlMsg`]s with a BLOCKING socket\n*3945|/// write each — so a backed-up controller blocks ONLY this thread, never the\n 3946|/// session drain (which used to write the controller inline under the log lock).\n 3947|/// A failed write (dead operator) ends the thread; the drain's next bounded\n 3948|/// send then sees `Disconnected` and detaches the row. `Output` advances\n...\n 3956|    sid: u64,\n*3957|    send: SharedSend,\n 3958|    initial: Vec<(u64, Vec<u8>)>,\n 3959|    // Whether `initial` is a synthesized repaint batch (rides the wire-flag —\n 3960|    // the consumer baselines its pseudo-seq jump) vs a raw ring slice\n...\n 3989|    // (same-lease) replacements never set the marker, so gate-#7 stays silent.\n*3990|    let emit_revoke_if_marked = |send: &SharedSend| {\n 3991|        let by = revoked_by.lock().ok().and_then(|mut g| g.take());\n 3992|        if let Some(by) = by {\n 3993|            let _ = send.write(&displaced_envelope(sid, &by));\n...\n 4074|        // a superseded writer's channel holds only its pre-supersede output\n*4075|        // backlog (seq the consumer dedups via snap-above). The loop ends\n 4076|        // naturally when `tx` drops — and a REVOKED replacement then emits the\n*4077|        // terminal `Displaced` below, BEHIND this drained backlog (order\n 4078|        // preserved), instead of racing it through the live queue. The reorder\n 4079|        // hazard is the INITIAL-BATCH replay, gated above.\n 4080|        mark_blocked(true);\n...\n 4253|    /// the next accepted enqueue (heal-on-resume). Mirrored to the perch's\n*4254|    /// `input_backpressure` so the operator sees the drop.\n*4255|    backpressure: AtomicBool,\n 4256|    /// The owning endpoint (the spawn's label; empty = unlabeled / raw test) —\n*4257|    /// the perch whose `input_backpressure` this stamps. Empty ⇒ nowhere to record.\n 4258|    endpoint: String,\n 4259|    /// The writer thread handle (held for ownership; the thread drains until the\n 4260|    /// last `tx` clone drops at session teardown, then exits).\n...\n 4274|            deliveries,\n*4275|            backpressure: AtomicBool::new(false),\n 4276|            endpoint,\n 4277|            _writer: writer,\n 4278|        })\n...\n 4302|            Ok(()) => {\n*4303|                // Heal: input is flowing again — clear a prior backpressure stamp.\n*4304|                if self.backpressure.swap(false, Ordering::AcqRel) {\n*4305|                    self.stamp_backpressure(false);\n 4306|                }\n 4307|                true\n 4308|            }\n...\n 4311|                // DROP + surface, but stamp only on the rising edge.\n*4312|                if !self.backpressure.swap(true, Ordering::AcqRel) {\n*4313|                    self.stamp_backpressure(true);\n 4314|                }\n 4315|                false\n 4316|            }\n...\n 4324|\n*4325|    /// Mirror the input-backpressure signal to the perch's `info.json` (the\n 4326|    /// broker is the single writer). Best-effort: a session served without a\n 4327|    /// perch (raw broker tests) has nowhere to record.\n*4328|    fn stamp_backpressure(&self, dropping: bool) {\n 4329|        if self.endpoint.is_empty() {\n 4330|            return;\n 4331|        }\n 4332|        let perch = resolve_perch_path(&self.endpoint, ParentHint::Infer);\n*4333|        let _ = spt_store::info::set_input_backpressure(&perch, dropping);\n 4334|    }\n 4335|}\n 4336|\n...\n 4396|/// leave the ring torn (a bumped `next_seq` past the ring, an over-cap ring from an\n*4397|/// interrupted prune, a non-monotonic front/back), and replaying those bytes to a\n 4398|/// subscriber risks garbage. So ONLY on the recovered (poisoned) branch, run\n 4399|/// [`OutputLog::clamp_or_reset`]: cheap-check the ring invariants and RESET it empty\n*4400|/// (+ loud log) on any violation. Lost scrollback self-heals on the next PTY output +\n 4401|/// repaint — strictly better than a permanent wedge (fail-fast reintroduces the very\n 4402|/// wedge B-1 kills) or a torn serve (blind recover). The healthy `Ok` path is a pure\n 4403|/// lock — no clamp, no cost on the hot append path.\n...\n 4525|        // UNCOALESCED: the count IS the news past the third failure, and the\n*4526|        // ledger's backoff already bounds how fast this path can fire.\n 4527|        None,\n 4528|        None,\n 4529|        &policy,\n...\n 4539|// [impl->REQ-SEAL-CEREMONY-TOTP]\n*4540|fn reply_seal_ceremony(send: &SharedSend, outcome: &str, detail: String, token: Option<String>) {\n 4541|    let payload = serde_json::to_value(SealCeremonyReply {\n 4542|        outcome: outcome.to_string(),\n 4543|        detail,\n...\n 4640|/// — the seal sibling of [`alert_bringup_brute_force`], same shape: off the\n*4641|/// dispatch thread, fire-and-forget with a LOUD stderr fallback (silence is\n 4642|/// the one thing brute force is buying), rate-bounded by the seal ledger's\n*4643|/// own backoff.\n 4644|// [impl->REQ-SEAL-CEREMONY-TOTP]\n 4645|fn alert_seal_ceremony_brute_force(subnet: &str, failures: u32) {\n 4646|    let subnet = subnet.to_string();\n...\n 4837|        // query itself no longer reaches the ring); the CPR written to the\n*4838|        // child's input then echoes back as output and advances the ring one\n 4839|        // hop later, well within the poll cadence. A re-render works the same\n 4840|        // as before; a non-echoing ConPTY stays unobservable (the latch).\n 4841|        input.enqueue_record(InputRecord::probe(INJECT_SETTLE_PROBE.to_vec()));\n...\n 4870|/// Layer 2 (REQ-INJECT-MULTILINE-INTEGRITY): after a `{commit}`, wait a bounded window\n*4871|/// for the typed payload's HEAD to echo back on the session ring (bytes produced since\n 4872|/// `seq_start`), then verify. A swallowed head means the prefix never appears. Empty\n 4873|/// payload (keys-only sequence) is vacuously verified with no wait.\n 4874|///\n...\n 4908|\n*4909|/// Layer 3 (REQ-INJECT-MULTILINE-INTEGRITY, the ruling's named fallback under the\n 4910|/// settle-gate): enqueue payload text in bounded chunks rather than one write, so no\n 4911|/// single huge write races the terminal's input coalescer. Order is preserved (single\n 4912|/// FIFO, single writer). The reader is already confirmed live by the settle-gate before\n...\n 5075|    // delivery. So an adapter that KNOWS its harness echoes declares the capability\n*5076|    // (parallel to the ruling's \"bracketed-paste where the harness declares it\"); Layer 1\n 5077|    // (the settle-gate) is the UNCONDITIONAL root fix. The int gate also forces it on\n 5078|    // (`SPT_INJECT_FORCE_ECHO_MISS`) to exercise the re-drive/spool wiring on any platform.\n 5079|    // AMBIENT env can NOT arm this: both vars are scrubbed at daemon startup\n...\n 5135|                    committed = true;\n*5136|                    // Layer 2: verify the typed head echoed back — ONLY where the terminal\n 5137|                    // demonstrably echoes (else a non-echoing PTY's incidental output would\n 5138|                    // false-read head-loss). Where it does not echo, Layer 1 stands alone.\n 5139|                    if !echo_capable || echo_verify_after(&log, seq_start, &sent_text) {\n...\n 5169|        if integrity_lost {\n*5170|            // Layer 2 fallback: the typed head never echoed, even after a re-drive.\n 5171|            // A live-SENT inject leaves no spool copy, so convert the silent+unrecoverable\n 5172|            // truncation into recoverable+loud — re-spool the envelope (idle-eligible,\n 5173|            // poll-fed) with a distinct integrity marker. NOT a binary fault (the binary\n...\n 5225|                // A repeat miss of an already-respooled envelope (e.g. the checkpoint\n*5226|                // duplicate FIRE looping back on a later drain): DEAD-LETTER it loud —\n 5227|                // do NOT respool again (never a silent drop; it still counts as a\n 5228|                // strike), REQ-HAZARD-IDLE-SILENT-NONDELIVERY posture.\n 5229|                spt_proto::emit_line_err!(\n...\n 5346|    /// when net is still being brought up (REQ-DAEMON-9 boot-race self-heal):\n*5347|    /// a `OnceLock` so the background net-retry can ATTACH the host after bind\n 5348|    /// without a relock on the hot effect-dispatch read path (`.get()` is\n 5349|    /// lock-free). Settable exactly once — the first host wins.\n 5350|    net: std::sync::OnceLock<NetHost>,\n...\n 5374|    /// write-stomp this REQ kills). An id is claimed for the duration of one spawn;\n*5375|    /// a duplicate wake for a claimed-or-already-live endpoint stands down (no-op ack).\n 5376|    wake_inflight: Mutex<HashMap<String, WakeClaim>>,\n 5377|    /// Monotonic claim generation (#235). Handed to each claim so a taken-over\n 5378|    /// holder's late RAII drop cannot release its successor's claim.\n...\n 5451|    /// worth covering is exactly the window the bring-up will wait through. A\n*5452|    /// failed spawn writes nothing back and its entry simply expires.\n 5453|    // [impl->REQ-ER-BRINGUP-INFLIGHT-LEDGER]\n 5454|    bringups_in_flight: Mutex<HashMap<String, Instant>>,\n 5455|    /// The PENDING seal ceremonies (WAX-SEAL W2, releases#21), keyed by the\n...\n 5469|/// overlay, the throttle ledger and the abort sweep are ONE machinery; the\n*5470|/// purpose decides only the admit arm. Tracked daemon-side on the pending\n 5471|/// entry — nothing about it rides the attach wire, which is what lets an N-1\n 5472|/// rc client host an enrollment ceremony unchanged (the brief's own text\n 5473|/// carries the ENROLL framing).\n...\n 5483|        pubkey_hex: String,\n*5484|        /// The seam backend that minted the keypair (e.g. `hello-kcm-rs256`).\n*5485|        backend_kind: String,\n 5486|    },\n 5487|}\n 5488|\n...\n 5519|    /// The requester's reply channel (the blocked `seal_ceremony` caller).\n*5520|    requester: SharedSend,\n 5521|    /// The requester conn's id — the conn-death abort key.\n 5522|    requester_conn: u64,\n 5523|    /// The controller conn's id at ceremony open — the detach abort key, and\n...\n 5710|    /// Attach a network host to a broker that was bound net-less (REQ-DAEMON-9):\n*5711|    /// the boot-race self-heal path calls this once the background retry brings\n 5712|    /// the net endpoint up, after which the dispatcher + peer pump are spawned.\n 5713|    /// Idempotent by `OnceLock` — a second attach is a no-op returning `false`\n 5714|    /// (the first host wins); the hot read path (`net()`) never blocks on it.\n...\n 5850|        };\n*5851|        // A real (immediately-abandoned) socket pair for the sink's SharedSend\n 5852|        // identity — nothing ever writes to it (the fixture invariant), so the\n 5853|        // dropped peer is irrelevant; the stall signal is the injected\n 5854|        // `write_blocked_since`, not a real socket block.\n...\n 5870|        let (_recv, send_half) = server.split();\n*5871|        let send: SharedSend = Arc::new(BrokerConn::new(send_half, brain_write_deadline()));\n 5872|        let (tx, rx) = sync_channel::<CtrlMsg>(CONTROLLER_CHANNEL_DEPTH);\n 5873|        // Drain-forever (never a socket write, never finishes while tx lives):\n 5874|        // stays un-reapable as a live-but-wedged writer even under child output.\n...\n 5944|    /// drives its handler to EOF cleanup within the write bound — without the\n*5945|    /// black-holed client dropping its end.\n 5946|    // [impl->REQ-HAZARD-SHAREDSEND-NO-BLOCKING-WRITE-UNDER-LOCK]\n 5947|    pub fn conn_handler_count(&self) -> usize {\n 5948|        self.conn_handlers.load(Ordering::Acquire)\n...\n 5995|    /// trip) promotes a ready update candidate only once this reads `false`: an OLD\n*5996|    /// generation whose local controller conn is black-holed reads wedged until the W2\n 5997|    /// stall-evict releases it, so `brain.ready` inside the 15 s window can no longer\n 5998|    /// promote onto a still-frozen control plane (the 22:47 false-promote). A cleanly-\n 5999|    /// closed old conn is simply absent → `false` at once (the normal fast promote).\n...\n 6066|        // [impl->REQ-HAZARD-SHAREDSEND-NO-BLOCKING-WRITE-UNDER-LOCK]\n*6067|        let send: SharedSend = Arc::new(BrokerConn::new(send, brain_write_deadline()));\n 6068|        // Base attribution fact (F-039 leg b): broker clients are brains; role\n 6069|        // facts (controller/viewer/presence/stream subscriber) accrete at the\n 6070|        // attach sites. [impl->REQ-CONN-POISON-ATTRIBUTION]\n...\n 6199|                KIND_NET_DIAL_LOOPBACK => {\n*6200|                    if let Err(msg) = self.dispatch_net_dial_loopback(&send) {\n 6201|                        send_error(&send, &msg);\n 6202|                    }\n 6203|                }\n...\n 6225|                KIND_NET_STREAM_OPEN => match self.dispatch_net_stream_open(env, &send) {\n*6226|                    // ConnectionBound open → track for the conn-exit sweep\n 6227|                    // (a journaled replay returns the SAME id — dedup keeps\n 6228|                    // the sweep list exact).\n 6229|                    // [impl->REQ-STREAM-LEASE-CLASSES]\n...\n 6233|                },\n*6234|                KIND_NET_STREAM_SEND => {\n 6235|                    if let Err(msg) = self.dispatch_net_stream_send(env, &send) {\n 6236|                        send_error(&send, &msg);\n 6237|                    }\n...\n 6254|                    // below, byte-identical (the stable KH-2.3 wire fact the\n*6255|                    // dispatcher's fallback gate keys on). Never set in\n 6256|                    // production.\n 6257|                    if std::env::var(\"SPT_TEST_STREAM_OPENER_UNSUPPORTED\").is_ok() {\n 6258|                        send_error(&send, &format!(\"unknown command kind {:?}\", env.kind));\n...\n 6486|    // [impl->REQ-HAZARD-DAEMON-SCHED-NONBLOCKING]\n*6487|    fn dispatch_spawn(&self, env: Envelope, send: &SharedSend) -> Result<u64, String> {\n 6488|        let req: SpawnReq =\n 6489|            serde_json::from_value(env.payload).map_err(|e| format!(\"bad spawn payload: {e}\"))?;\n 6490|        self.dispatch_spawn_policy(req, send, false)\n...\n 6499|    // [impl->REQ-SPAWN-FRESH-TRUTHFUL]\n*6500|    fn dispatch_spawn_fresh(&self, env: Envelope, send: &SharedSend) -> Result<Option<u64>, String> {\n 6501|        let req: SpawnReq =\n 6502|            serde_json::from_value(env.payload).map_err(|e| format!(\"bad spawn payload: {e}\"))?;\n 6503|        self.dispatch_spawn_policy(req, send, true)\n...\n 6521|    // [impl->REQ-ER-BRINGUP-SPAWNS-SESSION]\n*6522|    fn dispatch_bring_up(&self, env: Envelope, send: &SharedSend) -> Result<(), String> {\n 6523|        self.dispatch_bring_up_within(env, send, BRINGUP_READY_WAIT)\n 6524|    }\n 6525|\n...\n 6537|        env: Envelope,\n*6538|        send: &SharedSend,\n 6539|        ready_wait: Duration,\n 6540|    ) -> Result<(), String> {\n 6541|        let req: BringUpReq = serde_json::from_value(env.payload)\n...\n 6753|                    // this cwd literally and a missing directory fails the spawn, so\n*6754|                    // the fallback has to be the `None` this call used to pass, i.e.\n 6755|                    // exactly the pre-#178 behaviour rather than a new failure mode.\n 6756|                    spt_proto::emit_line_err!(\n 6757|                        \"ER_CWD_PROVISION_FAIL:{endpoint}: {} ({e}) — launching without the \\\n...\n 6780|        // actually needs. Polled rather than signalled because the session is\n*6781|        // registered by the spawn's own conn handler, which has no channel back\n 6782|        // to this one.\n 6783|        let deadline = Instant::now() + ready_wait;\n 6784|        loop {\n...\n 6884|    // [impl->REQ-SEAL-NO-CEREMONY-SURFACE]\n*6885|    fn dispatch_seal_ceremony(&self, env: Envelope, send: &SharedSend) -> Result<(), String> {\n 6886|        let req: SealCeremonyReq = serde_json::from_value(env.payload)\n 6887|            .map_err(|e| format!(\"bad seal-ceremony payload: {e}\"))?;\n 6888|        let refuse = |outcome: &str, detail: String| {\n...\n 6989|        offers: MintOffers,\n*6990|        send: &SharedSend,\n 6991|    ) -> Result<(), String> {\n 6992|        // THE SURFACE (operator ruling 4). Session first, then the seat.\n 6993|        let Some(session_id) = self.session_for_endpoint(endpoint) else {\n...\n 7097|    // [impl->REQ-SEAL-ENROLL-VERB]\n*7098|    fn dispatch_seal_enroll(&self, env: Envelope, send: &SharedSend) -> Result<(), String> {\n 7099|        let req: SealEnrollReq = serde_json::from_value(env.payload)\n 7100|            .map_err(|e| format!(\"bad seal-enroll payload: {e}\"))?;\n 7101|        let refuse = |outcome: &str, detail: String| {\n...\n 7147|                     or revocation needs an operator ruling.\",\n*7148|                    req.subnet, held.pubkey_hex, held.backend_kind\n 7149|                ),\n 7150|            );\n 7151|        }\n...\n 7164|             subnet: {}\\n\\\n*7165|             backend: {}\\n\\\n 7166|             pubkey-sha256: {fingerprint}\\n\\\n 7167|             A member-or-admin code of '{}' admits this enrollment; Esc cancels.\",\n*7168|            req.subnet, req.backend_kind, req.subnet\n 7169|        );\n 7170|        debug_assert!(\n 7171|            brief.chars().count() <= SEAL_CEREMONY_CONTENT_MAX_CHARS,\n...\n 7180|                pubkey_hex: req.pubkey_hex.clone(),\n*7181|                backend_kind: req.backend_kind.clone(),\n 7182|            },\n 7183|            // An enrollment ceremony IS an enrollment: neither mint-path\n 7184|            // offer is meaningful on its overlay.\n...\n 7202|        env: Envelope,\n*7203|        send: &SharedSend,\n 7204|    ) -> Result<(), String> {\n 7205|        use spt_store::engineroom as er;\n 7206|        let req: SealCeremonyCodeReq = serde_json::from_value(env.payload)\n...\n 7241|        // would let a broken client shut the gate a human needs), and every\n*7242|        // failed proof leaves the ceremony PENDING: the overlay falls back\n 7243|        // to TOTP code entry on the same overlay.\n 7244|        // [impl->REQ-SEAL-CEREMONY-FIDO2]\n 7245|        if let Some(sig_hex) = &req.signature_hex {\n...\n 7313|            );\n*7314|            if let Err(e) = spt_store::enroll::verify_backend_signature(\n*7315|                &enrollment.backend_kind,\n 7316|                &enrollment.pubkey_hex,\n 7317|                &payload,\n 7318|                sig_hex,\n 7319|            ) {\n*7320|                refuse_proof(format!(\"{e} — fall back to the TOTP code.\"));\n 7321|                return Ok(());\n 7322|            }\n 7323|            // Verified: mint with the pinned spellings and end the ceremony.\n...\n 7427|                } else if let (Some(pk), Some(bk)) =\n*7428|                    (&req.enroll_pubkey_hex, &req.enroll_backend_kind)\n 7429|                {\n 7430|                    // [impl->REQ-SEAL-ENROLL-SHORTCUT-E]\n 7431|                    self.mint_ceremony_seal_enrolling(req.ceremony_id, now, pk, bk)\n...\n 7617|        pubkey_hex: &str,\n*7618|        backend_kind: &str,\n 7619|    ) -> (&'static str, String, Option<String>) {\n 7620|        let (subnet, endpoint, content) = {\n 7621|            let pending = recover(&self.ceremonies);\n...\n 7653|            &subnet,\n*7654|            backend_kind,\n 7655|            now,\n 7656|        ) {\n 7657|            Ok(_) => {}\n...\n 7744|                \"seal {} minted by {minter}; authenticator enrolled for node {node} x \\\n*7745|                 subnet '{subnet}' ({backend_kind}).\",\n 7746|                record.token\n 7747|            ),\n 7748|            Some(record.token),\n...\n 7765|    ) -> (&'static str, String, Option<String>) {\n*7766|        let (subnet, pubkey_hex, backend_kind) = {\n 7767|            let pending = recover(&self.ceremonies);\n 7768|            let Some(p) = pending.get(&ceremony_id) else {\n 7769|                return (\n...\n 7776|                pubkey_hex,\n*7777|                backend_kind,\n 7778|            } = &p.purpose\n 7779|            else {\n 7780|                return (\n...\n 7785|            };\n*7786|            (p.subnet.clone(), pubkey_hex.clone(), backend_kind.clone())\n 7787|        };\n 7788|        let node = match spt_store::nodeid::load_or_create() {\n 7789|            Ok(id) => spt_net::net::registry::key_prefix(&id.public_key().to_hex()),\n...\n 7807|            &subnet,\n*7808|            &backend_kind,\n 7809|            now,\n 7810|        ) {\n 7811|            Ok(r) => r,\n...\n 7838|        spt_proto::emit_line_err!(\n*7839|            \"SEAL_ENROLL_MINTED: ceremony={ceremony_id} node={node} subnet={} backend={}\",\n*7840|            record.subnet, record.backend_kind\n 7841|        );\n 7842|        (\n 7843|            SEAL_CEREMONY_ADMITTED,\n...\n 7845|                \"{SEAL_ENROLLED}\\npubkey_hex: {}\\nnode: {}\\nsubnet: {}\\nenrolled_at: {}\\n\\\n*7846|                 backend_kind: {}\",\n 7847|                record.pubkey_hex, record.node, record.subnet, record.enrolled_at,\n*7848|                record.backend_kind\n 7849|            ),\n 7850|            None,\n 7851|        )\n...\n 8087|        req: SpawnReq,\n*8088|        send: &SharedSend,\n 8089|        fresh: bool,\n 8090|    ) -> Result<Option<u64>, String> {\n 8091|        // releases#199 instrument, BROKER SIDE. The launch-path stamps say when the\n...\n 8286|                                    // do not drop HostedSession/PTY resources or call\n*8287|                                    // dispatch_teardown as a fallback after refusal.\n 8288|                                    return Err(format!(\n 8289|                                        \"SPAWN_ZOMBIE_REAP_DECLINE:{}: session {sid}: {reason}\",\n 8290|                                        req.endpoint\n...\n 8341|                            \"SPAWN_DEDUP:{}: endpoint already has a live session {sid} — \\\n*8342|                             single-flight wake no-op ack [REQ-SPAWN-COLLISION-GUARD-LIVE-DUP]\",\n 8343|                            req.endpoint\n 8344|                        );\n 8345|                        let frame = Envelope::new(\n...\n 8444|        // (W1 / REQ-HAZARD-INJECT-CONTROL-COEXIST). The controller write is no\n*8445|        // longer inline under the log lock, so a backed-up controller can never\n 8446|        // wedge the session; a fully-stalled controller is detached after the\n 8447|        // deadline (bounded wedge, never permanent).\n 8448|        let log_drain = Arc::clone(&log);\n...\n 8556|            // about to vanish (the relatch the W2 int leg caught live). The\n*8557|            // removed entry hands back the DRAIN handle the ordering below needs.\n 8558|            let removed = recover(&sessions_exit).remove(&id);\n 8559|            // releases#199 instrument, THE FOURTH CANDIDATE the A/B/C set did not\n 8560|            // name: a harness that spawns and dies immediately produces a row that\n...\n 8749|    /// self-kick guard.\n*8750|    fn dispatch_subscribe(&self, env: Envelope, send: &SharedSend) -> Result<u64, String> {\n 8751|        let req: SubscribeReq = serde_json::from_value(env.payload)\n 8752|            .map_err(|e| format!(\"bad subscribe payload: {e}\"))?;\n 8753|        // Clone the log Arc out from under the sessions lock, then resolve under\n...\n 8762|        // post-removal subscribe gets a prompt \"no such session\" error — both\n*8763|        // non-silent. The rc-side status-gate (a) + first-event backstop (b) cover\n 8764|        // the rest.\n 8765|        let log = {\n 8766|            let sessions = recover(&self.sessions);\n...\n 8814|    /// a no-op if a newer controller already took over, or the session is gone.\n*8815|    fn dispatch_unsubscribe(&self, env: Envelope, send: &SharedSend) -> Result<(), String> {\n 8816|        let req: UnsubscribeReq = serde_json::from_value(env.payload)\n 8817|            .map_err(|e| format!(\"bad unsubscribe payload: {e}\"))?;\n 8818|        let log = {\n...\n 8840|    /// `(session_id, op_id)` after a brain crash is deduped (the PTY is not\n*8841|    /// written twice), and either outcome — fresh apply or dedup — is acked back\n 8842|    /// with an [`crate::msg::KIND_APPLIED`] frame so the brain can retire the\n 8843|    /// effect (B5 / KNOWN-HAZARDS 7.2). Without an `op_id` it is the legacy\n*8844|    /// direct write (no dedup, no ack).\n 8845|    // [impl->REQ-HAZARD-RESTART-IDEMPOTENT]\n*8846|    fn dispatch_input(&self, env: Envelope, send: &SharedSend) -> Result<(), String> {\n 8847|        let req: InputReq =\n 8848|            serde_json::from_value(env.payload).map_err(|e| format!(\"bad input payload: {e}\"))?;\n 8849|        let bytes = decode_bytes(&req.data_b64).map_err(|e| format!(\"bad input base64: {e}\"))?;\n...\n 8880|        // Layer C: when a (non-faulted) translation binary is attached, fire a\n*8881|        // CONTENT-FREE `{type:input}` ping so the binary can track operator idleness\n 8882|        // — best-effort, never carries the keystroke bytes (doyle gate #1, privacy).\n 8883|        if let Some(tr) = &translation {\n 8884|            if !tr.faulted.load(Ordering::Relaxed) {\n...\n 8910|                        // Buffer-or-ENQUEUE INSIDE the journal effect so the op is","truncated":true,"truncatedBy":"bytes","totalLines":1042,"totalBytes":58651,"outputLines":916,"outputBytes":51155,"lastLinePartial":false,"firstLineExceedsLimit":false},"meta":{"truncation":{"direction":"head","truncatedBy":"bytes","totalLines":1042,"totalBytes":58651,"outputLines":916,"outputBytes":51155,"shownRange":{"start":1,"end":916},"nextOffset":917}}},"isError":false,"timestamp":1789523993594}}
{"type":"message","id":"74393b6d","parentId":"1dc9d9ea","timestamp":"2026-09-16T01:59:53.599Z","message":{"role":"toolResult","toolCallId":"call_PzinZ2BL9gjPiP5GqsBTc9tM|fc_09b01b5279447709016aa9f8197dc487d296f092885681c7ba","toolName":"grep","content":[{"type":"text","text":" 20|PUMP_IPC_READER: spawned\n*21|CONN_LIFECYCLE: conn=6 role=brain presence-subscriber wall_ms=1789523749512 mono_ms=2582 first_write=none event=presence-sub-attach from_seq=18446744073709551615 [REQ-CONN-POISON-ATTRIBUTION]\n 22|EPOCH_FAST_FORWARD:0->1: our fleet-replicated roster row holds lease 0 — jumping past it so our own advertisements are admitted again (KNOWN-HAZARDS 7.60) [REQ-ROSTER-SELF-LEASE-HEAL]\n 23|ACCESS_STORE_MINTED C:\\Users\\decid\\Documents\\projects\\spt-core\\.spt\\preserved\\307\\hertz-w1bc\\w1c-run1\\home-w1c\\identity\\trust\\access.json — no access store was present at first load in this process, so an EMPTY baseline was written (everything open that the chain leaves open). If this node had access rules, they are GONE: the store was removed while the daemon was down, and this mint replaced it. Re-apply them (`spt endpoint access ...`); a restart cannot tell a wipe from a first boot.\n 24|SPAWN_PHASE:w1crig phase=received t_ms=0 fresh=true\n...\n 28|SPAWN_PHASE:w1crig phase=input_writer t_ms=1192\n*29|CONN_LIFECYCLE: conn=13 role=brain controller session=1 endpoint=w1crig by=local wall_ms=1789523754005 mono_ms=7076 first_write=none event=controller-attach session=1 from_seq=0 [REQ-CONN-POISON-ATTRIBUTION]\n 30|SPAWN_PHASE:w1crig phase=log_ready t_ms=1204\n 31|SPAWN_PHASE:w1crig phase=drain_armed t_ms=1204\n 32|SPAWN_PHASE:w1crig phase=waiter_armed t_ms=1204\n...\n 37|CONN_LIFECYCLE: conn=13 role=brain controller session=1 endpoint=w1crig by=local wall_ms=1789523754032 mono_ms=7102 first_write_wall_ms=1789523754018 first_write_mono_ms=7088 event=session-detach session=1 was_controller=true viewers_dropped=0 [REQ-CONN-POISON-ATTRIBUTION]\n*38|CONN_LIFECYCLE: conn=15 role=brain stream-subscriber stream=2 wall_ms=1789523756051 mono_ms=9122 first_write_wall_ms=1789523756007 first_write_mono_ms=9077 event=stream-sub-attach stream=2 from_seq=0 [REQ-CONN-POISON-ATTRIBUTION]\n*39|CONN_LIFECYCLE: conn=17 role=brain stream-subscriber stream=1 wall_ms=1789523756142 mono_ms=9213 first_write_wall_ms=1789523756142 first_write_mono_ms=9213 event=stream-sub-attach stream=1 from_seq=0 [REQ-CONN-POISON-ATTRIBUTION]\n 40|ATTACH_INTENT_CHOSEN: site=serve_dispatch session=1 intent=control from_seq=0 gen=1789523756051 coded=false\n*41|CONN_LIFECYCLE: conn=17 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523756143 mono_ms=9214 first_write_wall_ms=1789523756142 first_write_mono_ms=9213 event=controller-attach session=1 from_seq=0 [REQ-CONN-POISON-ATTRIBUTION]\n 42|ATTACH_INTENT_CHOSEN: site=serve_dispatch session=1 intent=control from_seq=0 gen=1789523756051 coded=false\n*43|SUBSCRIBE_DECISION: session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf conn=17 intent=control old_by=- old_gen=0 req_gen=1789523756051 decision=controller\n*44|SUBSCRIBE_DECISION: session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf conn=17 intent=control old_by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf old_gen=1789523756051 req_gen=1789523756051 decision=idempotent\n*45|BRAIN_UPDATE_RESTART: planned restart — cycling brain onto the swapped binary\n*46|CONTROLLER_SLOT_CLOSED:1 conn=17 cause=detach wall_ms=1789523803471 mono_ms=56541 — the controller slot was occupied and is now empty [REQ-REFRESH-WAIT-ATTRIBUTION]\n*47|CONN_WRITE_RETIRED: conn=17 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523803471 mono_ms=56541 first_write_wall_ms=1789523756142 first_write_mono_ms=9213 — organic write failure (BrokenPipe: The pipe is being closed. (os error 232)); physical broker conn poisoned + retired, never reused (same retire behavior as POISONED — only the failure class differs) [REQ-CONN-POISON-DIAL-SCOPE]\n*48|CONN_LIFECYCLE: conn=17 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523803471 mono_ms=56541 first_write_wall_ms=1789523756142 first_write_mono_ms=9213 event=writer-exit role=controller session=1 reason=write-failed kind=BrokenPipe [REQ-CONN-POISON-ATTRIBUTION]\n 49|BRAIN_RESTART: planned update respawn (generation 1)\n 50|=== spt brain stderr — generation 1 — pid 53752 ===\n 51|BRAIN_UP: connected to broker spt-daemon-broker-573ad82e70ef3afe.sock (pid 53752, generation 1, start-reason update)\n 52|BRAIN_PHASE:announce done in 0ms\n*53|CONN_LIFECYCLE: conn=17 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523803573 mono_ms=56643 first_write_wall_ms=1789523756142 first_write_mono_ms=9213 event=session-detach session=1 was_controller=true viewers_dropped=0 [REQ-CONN-POISON-ATTRIBUTION]\n*54|CONN_LIFECYCLE: conn=17 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523803573 mono_ms=56643 first_write_wall_ms=1789523756142 first_write_mono_ms=9213 event=transport-close poisoned=true timed_out=false [REQ-CONN-POISON-ATTRIBUTION]\n 55|BRAIN_RESUMED: re-established 1 session cursor(s): [1]\n 56|BRAIN_PHASE:resume done in 69ms\n 57|BRAIN_PHASE:ready written in 1894ms (exe-hash 1893ms, computed=true) path C:\\Users\\decid\\Documents\\projects\\spt-core\\.spt\\preserved\\307\\hertz-w1bc\\w1c-run1\\home-w1c\\brain.ready\n...\n 63|PUMP_IPC_READER: spawned\n*64|CONN_LIFECYCLE: conn=68 role=brain presence-subscriber wall_ms=1789523805974 mono_ms=59045 first_write=none event=presence-sub-attach from_seq=18446744073709551615 [REQ-CONN-POISON-ATTRIBUTION]\n*65|CONN_LIFECYCLE: conn=70 role=brain stream-subscriber stream=1 wall_ms=1789523805975 mono_ms=59046 first_write_wall_ms=1789523805975 first_write_mono_ms=59046 event=stream-sub-attach stream=1 from_seq=0 [REQ-CONN-POISON-ATTRIBUTION]\n 66|ATTACH_INTENT_CHOSEN: site=serve_dispatch session=1 intent=control from_seq=0 gen=1789523756051 coded=false\n*67|CONN_LIFECYCLE: conn=70 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523805976 mono_ms=59047 first_write_wall_ms=1789523805975 first_write_mono_ms=59046 event=controller-attach session=1 from_seq=0 [REQ-CONN-POISON-ATTRIBUTION]\n 68|ATTACH_INTENT_CHOSEN: site=serve_dispatch session=1 intent=control from_seq=0 gen=1789523756051 coded=false\n*69|SUBSCRIBE_DECISION: session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf conn=70 intent=control old_by=- old_gen=0 req_gen=1789523756051 decision=controller\n*70|SUBSCRIBE_DECISION: session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf conn=70 intent=control old_by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf old_gen=1789523756051 req_gen=1789523756051 decision=idempotent\n 71|CONN_LIFECYCLE_SUMMARY: scope=broker-ipc wall_ms=1789523807721 mono_ms=60792 interval_ms=60674 starts=47 closes=63 [REQ-CONN-HEALTHY-LIFECYCLE-BOUNDED]\n*72|CONN_WRITE_POISONED: conn=70 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523821012 mono_ms=74082 first_write_wall_ms=1789523805975 first_write_mono_ms=59046 — physical broker conn retired: a write exceeded its 15000ms bound; in-flight I/O aborted, conn never reused [REQ-HAZARD-SHAREDSEND-NO-BLOCKING-WRITE-UNDER-LOCK]\n*73|CONN_LIFECYCLE: conn=70 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523821012 mono_ms=74082 first_write_wall_ms=1789523805975 first_write_mono_ms=59046 event=stream-sub-writer-poison live write failed [REQ-CONN-POISON-ATTRIBUTION]\n*74|BRAIN_SUBSCRIBER_STALL_EVICT:1 conn=70 wall_ms=1789523821012 mono_ms=74082 — controller conn write exceeded its bound; physical conn poisoned + retired (writer released, EOF cleanup follows) [REQ-HAZARD-BROKER-VIEWER-BRAIN-DECOUPLE]\n*75|CONTROLLER_SLOT_CLOSED:1 conn=70 cause=detach wall_ms=1789523821012 mono_ms=74083 — the controller slot was occupied and is now empty [REQ-REFRESH-WAIT-ATTRIBUTION]\n*76|CONN_LIFECYCLE: conn=70 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523821012 mono_ms=74083 first_write_wall_ms=1789523805975 first_write_mono_ms=59046 event=writer-exit role=controller session=1 reason=write-failed kind=TimedOut [REQ-CONN-POISON-ATTRIBUTION]\n 77|DISPATCH:1:Failed(\"No process is on the other end of the pipe. (os error 233)\")\n*78|DISPATCH_EV: gen=1789523805974 stream=1 family=Attach attempt=0 conn=1 event=worker-outcome detail=Failed(\"No process is on the other end of the pipe. (os error 233)\") elapsed_ms=15037 endpoint=-\n*79|CONN_LIFECYCLE: conn=70 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523821028 mono_ms=74099 first_write_wall_ms=1789523805975 first_write_mono_ms=59046 event=session-detach session=1 was_controller=true viewers_dropped=0 [REQ-CONN-POISON-ATTRIBUTION]\n*80|CONN_LIFECYCLE: conn=70 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523821028 mono_ms=74099 first_write_wall_ms=1789523805975 first_write_mono_ms=59046 event=transport-close poisoned=true timed_out=true [REQ-CONN-POISON-ATTRIBUTION]\n*81|CONN_LIFECYCLE: conn=88 role=brain stream-subscriber stream=1 wall_ms=1789523821556 mono_ms=74627 first_write_wall_ms=1789523821556 first_write_mono_ms=74627 event=stream-sub-attach stream=1 from_seq=0 [REQ-CONN-POISON-ATTRIBUTION]\n 82|ATTACH_INTENT_CHOSEN: site=serve_dispatch session=1 intent=control from_seq=0 gen=1789523756051 coded=false\n*83|CONN_LIFECYCLE: conn=88 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523821557 mono_ms=74628 first_write_wall_ms=1789523821556 first_write_mono_ms=74627 event=controller-attach session=1 from_seq=0 [REQ-CONN-POISON-ATTRIBUTION]\n 84|ATTACH_INTENT_CHOSEN: site=serve_dispatch session=1 intent=control from_seq=0 gen=1789523756051 coded=false\n*85|SUBSCRIBE_DECISION: session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf conn=88 intent=control old_by=- old_gen=0 req_gen=1789523756051 decision=controller\n*86|SUBSCRIBE_DECISION: session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf conn=88 intent=control old_by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf old_gen=1789523756051 req_gen=1789523756051 decision=idempotent\n*87|CONN_WRITE_POISONED: conn=88 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523836597 mono_ms=89667 first_write_wall_ms=1789523821556 first_write_mono_ms=74627 — physical broker conn retired: a write exceeded its 15000ms bound; in-flight I/O aborted, conn never reused [REQ-HAZARD-SHAREDSEND-NO-BLOCKING-WRITE-UNDER-LOCK]\n*88|CONN_LIFECYCLE: conn=88 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523836597 mono_ms=89668 first_write_wall_ms=1789523821556 first_write_mono_ms=74627 event=stream-sub-writer-poison live write failed [REQ-CONN-POISON-ATTRIBUTION]\n*89|BRAIN_SUBSCRIBER_STALL_EVICT:1 conn=88 wall_ms=1789523836597 mono_ms=89668 — controller conn write exceeded its bound; physical conn poisoned + retired (writer released, EOF cleanup follows) [REQ-HAZARD-BROKER-VIEWER-BRAIN-DECOUPLE]\n*90|CONTROLLER_SLOT_CLOSED:1 conn=88 cause=detach wall_ms=1789523836597 mono_ms=89668 — the controller slot was occupied and is now empty [REQ-REFRESH-WAIT-ATTRIBUTION]\n*91|CONN_LIFECYCLE: conn=88 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523836597 mono_ms=89668 first_write_wall_ms=1789523821556 first_write_mono_ms=74627 event=writer-exit role=controller session=1 reason=write-failed kind=TimedOut [REQ-CONN-POISON-ATTRIBUTION]\n 92|DISPATCH:1:Failed(\"No process is on the other end of the pipe. (os error 233)\")\n*93|DISPATCH_EV: gen=1789523805974 stream=1 family=Attach attempt=1 conn=1 event=worker-outcome detail=Failed(\"No process is on the other end of the pipe. (os error 233)\") elapsed_ms=15041 endpoint=-\n*94|CONN_LIFECYCLE: conn=88 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523836612 mono_ms=89683 first_write_wall_ms=1789523821556 first_write_mono_ms=74627 event=session-detach session=1 was_controller=true viewers_dropped=0 [REQ-CONN-POISON-ATTRIBUTION]\n*95|CONN_LIFECYCLE: conn=88 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523836612 mono_ms=89683 first_write_wall_ms=1789523821556 first_write_mono_ms=74627 event=transport-close poisoned=true timed_out=true [REQ-CONN-POISON-ATTRIBUTION]\n*96|CONN_LIFECYCLE: conn=104 role=brain stream-subscriber stream=1 wall_ms=1789523837637 mono_ms=90707 first_write_wall_ms=1789523837637 first_write_mono_ms=90707 event=stream-sub-attach stream=1 from_seq=0 [REQ-CONN-POISON-ATTRIBUTION]\n 97|ATTACH_INTENT_CHOSEN: site=serve_dispatch session=1 intent=control from_seq=0 gen=1789523756051 coded=false\n*98|CONN_LIFECYCLE: conn=104 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523837637 mono_ms=90708 first_write_wall_ms=1789523837637 first_write_mono_ms=90707 event=controller-attach session=1 from_seq=0 [REQ-CONN-POISON-ATTRIBUTION]\n 99|ATTACH_INTENT_CHOSEN: site=serve_dispatch session=1 intent=control from_seq=0 gen=1789523756051 coded=false\n*100|SUBSCRIBE_DECISION: session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf conn=104 intent=control old_by=- old_gen=0 req_gen=1789523756051 decision=controller\n*101|SUBSCRIBE_DECISION: session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf conn=104 intent=control old_by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf old_gen=1789523756051 req_gen=1789523756051 decision=idempotent\n*102|CONN_WRITE_POISONED: conn=104 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523852688 mono_ms=105759 first_write_wall_ms=1789523837637 first_write_mono_ms=90707 — physical broker conn retired: a write exceeded its 15000ms bound; in-flight I/O aborted, conn never reused [REQ-HAZARD-SHAREDSEND-NO-BLOCKING-WRITE-UNDER-LOCK]\n*103|CONN_LIFECYCLE: conn=104 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523852688 mono_ms=105759 first_write_wall_ms=1789523837637 first_write_mono_ms=90707 event=stream-sub-writer-poison live write failed [REQ-CONN-POISON-ATTRIBUTION]\n*104|BRAIN_SUBSCRIBER_STALL_EVICT:1 conn=104 wall_ms=1789523852688 mono_ms=105759 — controller conn write exceeded its bound; physical conn poisoned + retired (writer released, EOF cleanup follows) [REQ-HAZARD-BROKER-VIEWER-BRAIN-DECOUPLE]\n*105|CONTROLLER_SLOT_CLOSED:1 conn=104 cause=detach wall_ms=1789523852688 mono_ms=105759 — the controller slot was occupied and is now empty [REQ-REFRESH-WAIT-ATTRIBUTION]\n*106|CONN_LIFECYCLE: conn=104 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523852688 mono_ms=105759 first_write_wall_ms=1789523837637 first_write_mono_ms=90707 event=writer-exit role=controller session=1 reason=write-failed kind=TimedOut [REQ-CONN-POISON-ATTRIBUTION]\n 107|DISPATCH:1:Failed(\"No process is on the other end of the pipe. (os error 233)\")\n*108|DISPATCH_EV: gen=1789523805974 stream=1 family=Attach attempt=2 conn=1 event=worker-outcome detail=Failed(\"No process is on the other end of the pipe. (os error 233)\") elapsed_ms=15052 endpoint=-\n*109|CONN_LIFECYCLE: conn=104 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523852704 mono_ms=105774 first_write_wall_ms=1789523837637 first_write_mono_ms=90707 event=session-detach session=1 was_controller=true viewers_dropped=0 [REQ-CONN-POISON-ATTRIBUTION]\n*110|CONN_LIFECYCLE: conn=104 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523852704 mono_ms=105775 first_write_wall_ms=1789523837637 first_write_mono_ms=90707 event=transport-close poisoned=true timed_out=true [REQ-CONN-POISON-ATTRIBUTION]\n 111|CONN_LIFECYCLE_SUMMARY: scope=broker-ipc wall_ms=1789523869521 mono_ms=122592 interval_ms=61799 starts=40 closes=59 [REQ-CONN-HEALTHY-LIFECYCLE-BOUNDED]\n 112|CONN_LIFECYCLE_SUMMARY: scope=broker-ipc wall_ms=1789523930868 mono_ms=183938 interval_ms=61346 starts=35 closes=53 [REQ-CONN-HEALTHY-LIFECYCLE-BOUNDED]\n*113|BRAIN_UPDATE_RESTART: planned restart — cycling brain onto the swapped binary\n 114|BRAIN_RESTART: planned update respawn (generation 2)\n 115|=== spt brain stderr — generation 2 — pid 35888 ===\n 116|BRAIN_UP: connected to broker spt-daemon-broker-573ad82e70ef3afe.sock (pid 35888, generation 2, start-reason update)\n...\n 126|PUMP_IPC_READER: spawned\n*127|CONN_LIFECYCLE: conn=197 role=brain presence-subscriber wall_ms=1789523936910 mono_ms=189981 first_write=none event=presence-sub-attach from_seq=18446744073709551615 [REQ-CONN-POISON-ATTRIBUTION]\n*128|CONN_LIFECYCLE: conn=201 role=brain stream-subscriber stream=1 wall_ms=1789523936922 mono_ms=189993 first_write_wall_ms=1789523936922 first_write_mono_ms=189993 event=stream-sub-attach stream=1 from_seq=0 [REQ-CONN-POISON-ATTRIBUTION]\n 129|ATTACH_INTENT_CHOSEN: site=serve_dispatch session=1 intent=control from_seq=0 gen=1789523756051 coded=false\n*130|CONN_LIFECYCLE: conn=201 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523936923 mono_ms=189994 first_write_wall_ms=1789523936922 first_write_mono_ms=189993 event=controller-attach session=1 from_seq=0 [REQ-CONN-POISON-ATTRIBUTION]\n 131|ATTACH_INTENT_CHOSEN: site=serve_dispatch session=1 intent=control from_seq=0 gen=1789523756051 coded=false\n 132|SUBSCRIBE_DECISION: session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf conn=201 intent=control old_by=- old_gen=0 req_gen=1789523756051 decision=controller\n 133|SUBSCRIBE_DECISION: session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf conn=201 intent=control old_by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf old_gen=1789523756051 req_gen=1789523756051 decision=idempotent\n*134|CONN_WRITE_POISONED: conn=201 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523951971 mono_ms=205042 first_write_wall_ms=1789523936922 first_write_mono_ms=189993 — physical broker conn retired: a write exceeded its 15000ms bound; in-flight I/O aborted, conn never reused [REQ-HAZARD-SHAREDSEND-NO-BLOCKING-WRITE-UNDER-LOCK]\n 135|CONN_LIFECYCLE: conn=201 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523951971 mono_ms=205042 first_write_wall_ms=1789523936922 first_write_mono_ms=189993 event=stream-sub-writer-poison live write failed [REQ-CONN-POISON-ATTRIBUTION]\n*136|BRAIN_SUBSCRIBER_STALL_EVICT:1 conn=201 wall_ms=1789523951971 mono_ms=205042 — controller conn write exceeded its bound; physical conn poisoned + retired (writer released, EOF cleanup follows) [REQ-HAZARD-BROKER-VIEWER-BRAIN-DECOUPLE]\n 137|CONN_LIFECYCLE: conn=201 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523951971 mono_ms=205042 first_write_wall_ms=1789523936922 first_write_mono_ms=189993 event=writer-exit role=controller session=1 reason=write-failed kind=TimedOut [REQ-CONN-POISON-ATTRIBUTION]\n 138|CONTROLLER_SLOT_CLOSED:1 conn=201 cause=detach wall_ms=1789523951972 mono_ms=205042 — the controller slot was occupied and is now empty [REQ-REFRESH-WAIT-ATTRIBUTION]\n 139|DISPATCH:1:Failed(\"No process is on the other end of the pipe. (os error 233)\")\n*140|DISPATCH_EV: gen=1789523936906 stream=1 family=Attach attempt=0 conn=1 event=worker-outcome detail=Failed(\"No process is on the other end of the pipe. (os error 233)\") elapsed_ms=15060 endpoint=-\n 141|CONN_LIFECYCLE: conn=201 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523951989 mono_ms=205060 first_write_wall_ms=1789523936922 first_write_mono_ms=189993 event=session-detach session=1 was_controller=true viewers_dropped=0 [REQ-CONN-POISON-ATTRIBUTION]\n 142|CONN_LIFECYCLE: conn=201 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523951990 mono_ms=205060 first_write_wall_ms=1789523936922 first_write_mono_ms=189993 event=transport-close poisoned=true timed_out=true [REQ-CONN-POISON-ATTRIBUTION]\n*143|CONN_LIFECYCLE: conn=219 role=brain stream-subscriber stream=1 wall_ms=1789523952492 mono_ms=205563 first_write_wall_ms=1789523952492 first_write_mono_ms=205563 event=stream-sub-attach stream=1 from_seq=0 [REQ-CONN-POISON-ATTRIBUTION]\n 144|ATTACH_INTENT_CHOSEN: site=serve_dispatch session=1 intent=control from_seq=0 gen=1789523756051 coded=false\n*145|CONN_LIFECYCLE: conn=219 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523952493 mono_ms=205564 first_write_wall_ms=1789523952492 first_write_mono_ms=205563 event=controller-attach session=1 from_seq=0 [REQ-CONN-POISON-ATTRIBUTION]\n 146|ATTACH_INTENT_CHOSEN: site=serve_dispatch session=1 intent=control from_seq=0 gen=1789523756051 coded=false\n 147|SUBSCRIBE_DECISION: session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf conn=219 intent=control old_by=- old_gen=0 req_gen=1789523756051 decision=controller\n 148|SUBSCRIBE_DECISION: session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf conn=219 intent=control old_by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf old_gen=1789523756051 req_gen=1789523756051 decision=idempotent\n*149|CONN_WRITE_POISONED: conn=219 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523967530 mono_ms=220601 first_write_wall_ms=1789523952492 first_write_mono_ms=205563 — physical broker conn retired: a write exceeded its 15000ms bound; in-flight I/O aborted, conn never reused [REQ-HAZARD-SHAREDSEND-NO-BLOCKING-WRITE-UNDER-LOCK]\n 150|CONN_LIFECYCLE: conn=219 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523967530 mono_ms=220601 first_write_wall_ms=1789523952492 first_write_mono_ms=205563 event=stream-sub-writer-poison live write failed [REQ-CONN-POISON-ATTRIBUTION]\n*151|BRAIN_SUBSCRIBER_STALL_EVICT:1 conn=219 wall_ms=1789523967530 mono_ms=220601 — controller conn write exceeded its bound; physical conn poisoned + retired (writer released, EOF cleanup follows) [REQ-HAZARD-BROKER-VIEWER-BRAIN-DECOUPLE]\n 152|CONTROLLER_SLOT_CLOSED:1 conn=219 cause=detach wall_ms=1789523967530 mono_ms=220601 — the controller slot was occupied and is now empty [REQ-REFRESH-WAIT-ATTRIBUTION]\n 153|CONN_LIFECYCLE: conn=219 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523967530 mono_ms=220601 first_write_wall_ms=1789523952492 first_write_mono_ms=205563 event=writer-exit role=controller session=1 reason=write-failed kind=TimedOut [REQ-CONN-POISON-ATTRIBUTION]\n 154|DISPATCH:1:Failed(\"No process is on the other end of the pipe. (os error 233)\")\n*155|DISPATCH_EV: gen=1789523936906 stream=1 family=Attach attempt=1 conn=1 event=worker-outcome detail=Failed(\"No process is on the other end of the pipe. (os error 233)\") elapsed_ms=15038 endpoint=-\n 156|CONN_LIFECYCLE: conn=219 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523967549 mono_ms=220620 first_write_wall_ms=1789523952492 first_write_mono_ms=205563 event=session-detach session=1 was_controller=true viewers_dropped=0 [REQ-CONN-POISON-ATTRIBUTION]\n 157|CONN_LIFECYCLE: conn=219 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523967549 mono_ms=220620 first_write_wall_ms=1789523952492 first_write_mono_ms=205563 event=transport-close poisoned=true timed_out=true [REQ-CONN-POISON-ATTRIBUTION]\n*158|CONN_LIFECYCLE: conn=240 role=brain stream-subscriber stream=1 wall_ms=1789523968581 mono_ms=221652 first_write_wall_ms=1789523968581 first_write_mono_ms=221651 event=stream-sub-attach stream=1 from_seq=0 [REQ-CONN-POISON-ATTRIBUTION]\n 159|ATTACH_INTENT_CHOSEN: site=serve_dispatch session=1 intent=control from_seq=0 gen=1789523756051 coded=false\n*160|CONN_LIFECYCLE: conn=240 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523968581 mono_ms=221652 first_write_wall_ms=1789523968581 first_write_mono_ms=221651 event=controller-attach session=1 from_seq=0 [REQ-CONN-POISON-ATTRIBUTION]\n 161|ATTACH_INTENT_CHOSEN: site=serve_dispatch session=1 intent=control from_seq=0 gen=1789523756051 coded=false\n 162|SUBSCRIBE_DECISION: session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf conn=240 intent=control old_by=- old_gen=0 req_gen=1789523756051 decision=controller\n 163|SUBSCRIBE_DECISION: session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf conn=240 intent=control old_by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf old_gen=1789523756051 req_gen=1789523756051 decision=idempotent\n 164|STREAM_CONNBOUND_RETIRE:2: opener conn exited — FIN + terminal retire\n*165|CONN_WRITE_POISONED: conn=240 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523983623 mono_ms=236694 first_write_wall_ms=1789523968581 first_write_mono_ms=221651 — physical broker conn retired: a write exceeded its 15000ms bound; in-flight I/O aborted, conn never reused [REQ-HAZARD-SHAREDSEND-NO-BLOCKING-WRITE-UNDER-LOCK]\n 166|CONN_LIFECYCLE: conn=240 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523983623 mono_ms=236694 first_write_wall_ms=1789523968581 first_write_mono_ms=221651 event=stream-sub-writer-poison live write failed [REQ-CONN-POISON-ATTRIBUTION]\n*167|BRAIN_SUBSCRIBER_STALL_EVICT:1 conn=240 wall_ms=1789523983623 mono_ms=236694 — controller conn write exceeded its bound; physical conn poisoned + retired (writer released, EOF cleanup follows) [REQ-HAZARD-BROKER-VIEWER-BRAIN-DECOUPLE]\n 168|CONTROLLER_SLOT_CLOSED:1 conn=240 cause=detach wall_ms=1789523983623 mono_ms=236694 — the controller slot was occupied and is now empty [REQ-REFRESH-WAIT-ATTRIBUTION]\n 169|CONN_LIFECYCLE: conn=240 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523983623 mono_ms=236694 first_write_wall_ms=1789523968581 first_write_mono_ms=221651 event=writer-exit role=controller session=1 reason=write-failed kind=TimedOut [REQ-CONN-POISON-ATTRIBUTION]\n 170|DISPATCH:1:Failed(\"No process is on the other end of the pipe. (os error 233)\")\n*171|DISPATCH_EV: gen=1789523936906 stream=1 family=Attach attempt=2 conn=1 event=worker-outcome detail=Failed(\"No process is on the other end of the pipe. (os error 233)\") elapsed_ms=15043 endpoint=-\n 172|CONN_LIFECYCLE: conn=240 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523984702 mono_ms=237773 first_write_wall_ms=1789523968581 first_write_mono_ms=221651 event=session-detach session=1 was_controller=true viewers_dropped=0 [REQ-CONN-POISON-ATTRIBUTION]\n 173|CONN_LIFECYCLE: conn=240 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523984702 mono_ms=237773 first_write_wall_ms=1789523968581 first_write_mono_ms=221651 event=transport-close poisoned=true timed_out=true [REQ-CONN-POISON-ATTRIBUTION]"}],"details":{"scopePath":".spt/preserved/307/hertz-w1bc/w1c-run1/home-w1c/logs/daemon.stderr.log","searchPath":"C:\\Users\\decid\\Documents\\projects\\spt-core\\.spt\\preserved\\307\\hertz-w1bc\\w1c-run1\\home-w1c\\logs\\daemon.stderr.log","cwd":"C:\\Users\\decid\\Documents\\projects\\spt-core","matchCount":67,"fileCount":1,"files":[".spt/preserved/307/hertz-w1bc/w1c-run1/home-w1c/logs/daemon.stderr.log"],"fileMatches":[{"path":".spt/preserved/307/hertz-w1bc/w1c-run1/home-w1c/logs/daemon.stderr.log","count":67}],"truncated":false,"displayContent":"  20│PUMP_IPC_READER: spawned\n *21│CONN_LIFECYCLE: conn=6 role=brain presence-subscriber wall_ms=1789523749512 mono_ms=2582 first_write=none event=presence-sub-attach from_seq=18446744073709551615 [REQ-CONN-POISON-ATTRIBUTION]\n  22│EPOCH_FAST_FORWARD:0->1: our fleet-replicated roster row holds lease 0 — jumping past it so our own advertisements are admitted again (KNOWN-HAZARDS 7.60) [REQ-ROSTER-SELF-LEASE-HEAL]\n  23│ACCESS_STORE_MINTED C:\\Users\\decid\\Documents\\projects\\spt-core\\.spt\\preserved\\307\\hertz-w1bc\\w1c-run1\\home-w1c\\identity\\trust\\access.json — no access store was present at first load in this process, so an EMPTY baseline was written (everything open that the chain leaves open). If this node had access rules, they are GONE: the store was removed while the daemon was down, and this mint replaced it. Re-apply them (`spt endpoint access ...`); a restart cannot tell a wipe from a first boot.\n  24│SPAWN_PHASE:w1crig phase=received t_ms=0 fresh=true\n    │...\n  28│SPAWN_PHASE:w1crig phase=input_writer t_ms=1192\n *29│CONN_LIFECYCLE: conn=13 role=brain controller session=1 endpoint=w1crig by=local wall_ms=1789523754005 mono_ms=7076 first_write=none event=controller-attach session=1 from_seq=0 [REQ-CONN-POISON-ATTRIBUTION]\n  30│SPAWN_PHASE:w1crig phase=log_ready t_ms=1204\n  31│SPAWN_PHASE:w1crig phase=drain_armed t_ms=1204\n  32│SPAWN_PHASE:w1crig phase=waiter_armed t_ms=1204\n    │...\n  37│CONN_LIFECYCLE: conn=13 role=brain controller session=1 endpoint=w1crig by=local wall_ms=1789523754032 mono_ms=7102 first_write_wall_ms=1789523754018 first_write_mono_ms=7088 event=session-detach session=1 was_controller=true viewers_dropped=0 [REQ-CONN-POISON-ATTRIBUTION]\n *38│CONN_LIFECYCLE: conn=15 role=brain stream-subscriber stream=2 wall_ms=1789523756051 mono_ms=9122 first_write_wall_ms=1789523756007 first_write_mono_ms=9077 event=stream-sub-attach stream=2 from_seq=0 [REQ-CONN-POISON-ATTRIBUTION]\n *39│CONN_LIFECYCLE: conn=17 role=brain stream-subscriber stream=1 wall_ms=1789523756142 mono_ms=9213 first_write_wall_ms=1789523756142 first_write_mono_ms=9213 event=stream-sub-attach stream=1 from_seq=0 [REQ-CONN-POISON-ATTRIBUTION]\n  40│ATTACH_INTENT_CHOSEN: site=serve_dispatch session=1 intent=control from_seq=0 gen=1789523756051 coded=false\n *41│CONN_LIFECYCLE: conn=17 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523756143 mono_ms=9214 first_write_wall_ms=1789523756142 first_write_mono_ms=9213 event=controller-attach session=1 from_seq=0 [REQ-CONN-POISON-ATTRIBUTION]\n  42│ATTACH_INTENT_CHOSEN: site=serve_dispatch session=1 intent=control from_seq=0 gen=1789523756051 coded=false\n *43│SUBSCRIBE_DECISION: session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf conn=17 intent=control old_by=- old_gen=0 req_gen=1789523756051 decision=controller\n *44│SUBSCRIBE_DECISION: session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf conn=17 intent=control old_by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf old_gen=1789523756051 req_gen=1789523756051 decision=idempotent\n *45│BRAIN_UPDATE_RESTART: planned restart — cycling brain onto the swapped binary\n *46│CONTROLLER_SLOT_CLOSED:1 conn=17 cause=detach wall_ms=1789523803471 mono_ms=56541 — the controller slot was occupied and is now empty [REQ-REFRESH-WAIT-ATTRIBUTION]\n *47│CONN_WRITE_RETIRED: conn=17 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523803471 mono_ms=56541 first_write_wall_ms=1789523756142 first_write_mono_ms=9213 — organic write failure (BrokenPipe: The pipe is being closed. (os error 232)); physical broker conn poisoned + retired, never reused (same retire behavior as POISONED — only the failure class differs) [REQ-CONN-POISON-DIAL-SCOPE]\n *48│CONN_LIFECYCLE: conn=17 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523803471 mono_ms=56541 first_write_wall_ms=1789523756142 first_write_mono_ms=9213 event=writer-exit role=controller session=1 reason=write-failed kind=BrokenPipe [REQ-CONN-POISON-ATTRIBUTION]\n  49│BRAIN_RESTART: planned update respawn (generation 1)\n  50│=== spt brain stderr — generation 1 — pid 53752 ===\n  51│BRAIN_UP: connected to broker spt-daemon-broker-573ad82e70ef3afe.sock (pid 53752, generation 1, start-reason update)\n  52│BRAIN_PHASE:announce done in 0ms\n *53│CONN_LIFECYCLE: conn=17 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523803573 mono_ms=56643 first_write_wall_ms=1789523756142 first_write_mono_ms=9213 event=session-detach session=1 was_controller=true viewers_dropped=0 [REQ-CONN-POISON-ATTRIBUTION]\n *54│CONN_LIFECYCLE: conn=17 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523803573 mono_ms=56643 first_write_wall_ms=1789523756142 first_write_mono_ms=9213 event=transport-close poisoned=true timed_out=false [REQ-CONN-POISON-ATTRIBUTION]\n  55│BRAIN_RESUMED: re-established 1 session cursor(s): [1]\n  56│BRAIN_PHASE:resume done in 69ms\n  57│BRAIN_PHASE:ready written in 1894ms (exe-hash 1893ms, computed=true) path C:\\Users\\decid\\Documents\\projects\\spt-core\\.spt\\preserved\\307\\hertz-w1bc\\w1c-run1\\home-w1c\\brain.ready\n    │...\n  63│PUMP_IPC_READER: spawned\n *64│CONN_LIFECYCLE: conn=68 role=brain presence-subscriber wall_ms=1789523805974 mono_ms=59045 first_write=none event=presence-sub-attach from_seq=18446744073709551615 [REQ-CONN-POISON-ATTRIBUTION]\n *65│CONN_LIFECYCLE: conn=70 role=brain stream-subscriber stream=1 wall_ms=1789523805975 mono_ms=59046 first_write_wall_ms=1789523805975 first_write_mono_ms=59046 event=stream-sub-attach stream=1 from_seq=0 [REQ-CONN-POISON-ATTRIBUTION]\n  66│ATTACH_INTENT_CHOSEN: site=serve_dispatch session=1 intent=control from_seq=0 gen=1789523756051 coded=false\n *67│CONN_LIFECYCLE: conn=70 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523805976 mono_ms=59047 first_write_wall_ms=1789523805975 first_write_mono_ms=59046 event=controller-attach session=1 from_seq=0 [REQ-CONN-POISON-ATTRIBUTION]\n  68│ATTACH_INTENT_CHOSEN: site=serve_dispatch session=1 intent=control from_seq=0 gen=1789523756051 coded=false\n *69│SUBSCRIBE_DECISION: session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf conn=70 intent=control old_by=- old_gen=0 req_gen=1789523756051 decision=controller\n *70│SUBSCRIBE_DECISION: session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf conn=70 intent=control old_by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf old_gen=1789523756051 req_gen=1789523756051 decision=idempotent\n  71│CONN_LIFECYCLE_SUMMARY: scope=broker-ipc wall_ms=1789523807721 mono_ms=60792 interval_ms=60674 starts=47 closes=63 [REQ-CONN-HEALTHY-LIFECYCLE-BOUNDED]\n *72│CONN_WRITE_POISONED: conn=70 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523821012 mono_ms=74082 first_write_wall_ms=1789523805975 first_write_mono_ms=59046 — physical broker conn retired: a write exceeded its 15000ms bound; in-flight I/O aborted, conn never reused [REQ-HAZARD-SHAREDSEND-NO-BLOCKING-WRITE-UNDER-LOCK]\n *73│CONN_LIFECYCLE: conn=70 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523821012 mono_ms=74082 first_write_wall_ms=1789523805975 first_write_mono_ms=59046 event=stream-sub-writer-poison live write failed [REQ-CONN-POISON-ATTRIBUTION]\n *74│BRAIN_SUBSCRIBER_STALL_EVICT:1 conn=70 wall_ms=1789523821012 mono_ms=74082 — controller conn write exceeded its bound; physical conn poisoned + retired (writer released, EOF cleanup follows) [REQ-HAZARD-BROKER-VIEWER-BRAIN-DECOUPLE]\n *75│CONTROLLER_SLOT_CLOSED:1 conn=70 cause=detach wall_ms=1789523821012 mono_ms=74083 — the controller slot was occupied and is now empty [REQ-REFRESH-WAIT-ATTRIBUTION]\n *76│CONN_LIFECYCLE: conn=70 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523821012 mono_ms=74083 first_write_wall_ms=1789523805975 first_write_mono_ms=59046 event=writer-exit role=controller session=1 reason=write-failed kind=TimedOut [REQ-CONN-POISON-ATTRIBUTION]\n  77│DISPATCH:1:Failed(\"No process is on the other end of the pipe. (os error 233)\")\n *78│DISPATCH_EV: gen=1789523805974 stream=1 family=Attach attempt=0 conn=1 event=worker-outcome detail=Failed(\"No process is on the other end of the pipe. (os error 233)\") elapsed_ms=15037 endpoint=-\n *79│CONN_LIFECYCLE: conn=70 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523821028 mono_ms=74099 first_write_wall_ms=1789523805975 first_write_mono_ms=59046 event=session-detach session=1 was_controller=true viewers_dropped=0 [REQ-CONN-POISON-ATTRIBUTION]\n *80│CONN_LIFECYCLE: conn=70 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523821028 mono_ms=74099 first_write_wall_ms=1789523805975 first_write_mono_ms=59046 event=transport-close poisoned=true timed_out=true [REQ-CONN-POISON-ATTRIBUTION]\n *81│CONN_LIFECYCLE: conn=88 role=brain stream-subscriber stream=1 wall_ms=1789523821556 mono_ms=74627 first_write_wall_ms=1789523821556 first_write_mono_ms=74627 event=stream-sub-attach stream=1 from_seq=0 [REQ-CONN-POISON-ATTRIBUTION]\n  82│ATTACH_INTENT_CHOSEN: site=serve_dispatch session=1 intent=control from_seq=0 gen=1789523756051 coded=false\n *83│CONN_LIFECYCLE: conn=88 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523821557 mono_ms=74628 first_write_wall_ms=1789523821556 first_write_mono_ms=74627 event=controller-attach session=1 from_seq=0 [REQ-CONN-POISON-ATTRIBUTION]\n  84│ATTACH_INTENT_CHOSEN: site=serve_dispatch session=1 intent=control from_seq=0 gen=1789523756051 coded=false\n *85│SUBSCRIBE_DECISION: session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf conn=88 intent=control old_by=- old_gen=0 req_gen=1789523756051 decision=controller\n *86│SUBSCRIBE_DECISION: session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf conn=88 intent=control old_by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf old_gen=1789523756051 req_gen=1789523756051 decision=idempotent\n *87│CONN_WRITE_POISONED: conn=88 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523836597 mono_ms=89667 first_write_wall_ms=1789523821556 first_write_mono_ms=74627 — physical broker conn retired: a write exceeded its 15000ms bound; in-flight I/O aborted, conn never reused [REQ-HAZARD-SHAREDSEND-NO-BLOCKING-WRITE-UNDER-LOCK]\n *88│CONN_LIFECYCLE: conn=88 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523836597 mono_ms=89668 first_write_wall_ms=1789523821556 first_write_mono_ms=74627 event=stream-sub-writer-poison live write failed [REQ-CONN-POISON-ATTRIBUTION]\n *89│BRAIN_SUBSCRIBER_STALL_EVICT:1 conn=88 wall_ms=1789523836597 mono_ms=89668 — controller conn write exceeded its bound; physical conn poisoned + retired (writer released, EOF cleanup follows) [REQ-HAZARD-BROKER-VIEWER-BRAIN-DECOUPLE]\n *90│CONTROLLER_SLOT_CLOSED:1 conn=88 cause=detach wall_ms=1789523836597 mono_ms=89668 — the controller slot was occupied and is now empty [REQ-REFRESH-WAIT-ATTRIBUTION]\n *91│CONN_LIFECYCLE: conn=88 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523836597 mono_ms=89668 first_write_wall_ms=1789523821556 first_write_mono_ms=74627 event=writer-exit role=controller session=1 reason=write-failed kind=TimedOut [REQ-CONN-POISON-ATTRIBUTION]\n  92│DISPATCH:1:Failed(\"No process is on the other end of the pipe. (os error 233)\")\n *93│DISPATCH_EV: gen=1789523805974 stream=1 family=Attach attempt=1 conn=1 event=worker-outcome detail=Failed(\"No process is on the other end of the pipe. (os error 233)\") elapsed_ms=15041 endpoint=-\n *94│CONN_LIFECYCLE: conn=88 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523836612 mono_ms=89683 first_write_wall_ms=1789523821556 first_write_mono_ms=74627 event=session-detach session=1 was_controller=true viewers_dropped=0 [REQ-CONN-POISON-ATTRIBUTION]\n *95│CONN_LIFECYCLE: conn=88 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523836612 mono_ms=89683 first_write_wall_ms=1789523821556 first_write_mono_ms=74627 event=transport-close poisoned=true timed_out=true [REQ-CONN-POISON-ATTRIBUTION]\n *96│CONN_LIFECYCLE: conn=104 role=brain stream-subscriber stream=1 wall_ms=1789523837637 mono_ms=90707 first_write_wall_ms=1789523837637 first_write_mono_ms=90707 event=stream-sub-attach stream=1 from_seq=0 [REQ-CONN-POISON-ATTRIBUTION]\n  97│ATTACH_INTENT_CHOSEN: site=serve_dispatch session=1 intent=control from_seq=0 gen=1789523756051 coded=false\n *98│CONN_LIFECYCLE: conn=104 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523837637 mono_ms=90708 first_write_wall_ms=1789523837637 first_write_mono_ms=90707 event=controller-attach session=1 from_seq=0 [REQ-CONN-POISON-ATTRIBUTION]\n  99│ATTACH_INTENT_CHOSEN: site=serve_dispatch session=1 intent=control from_seq=0 gen=1789523756051 coded=false\n*100│SUBSCRIBE_DECISION: session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf conn=104 intent=control old_by=- old_gen=0 req_gen=1789523756051 decision=controller\n*101│SUBSCRIBE_DECISION: session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf conn=104 intent=control old_by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf old_gen=1789523756051 req_gen=1789523756051 decision=idempotent\n*102│CONN_WRITE_POISONED: conn=104 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523852688 mono_ms=105759 first_write_wall_ms=1789523837637 first_write_mono_ms=90707 — physical broker conn retired: a write exceeded its 15000ms bound; in-flight I/O aborted, conn never reused [REQ-HAZARD-SHAREDSEND-NO-BLOCKING-WRITE-UNDER-LOCK]\n*103│CONN_LIFECYCLE: conn=104 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523852688 mono_ms=105759 first_write_wall_ms=1789523837637 first_write_mono_ms=90707 event=stream-sub-writer-poison live write failed [REQ-CONN-POISON-ATTRIBUTION]\n*104│BRAIN_SUBSCRIBER_STALL_EVICT:1 conn=104 wall_ms=1789523852688 mono_ms=105759 — controller conn write exceeded its bound; physical conn poisoned + retired (writer released, EOF cleanup follows) [REQ-HAZARD-BROKER-VIEWER-BRAIN-DECOUPLE]\n*105│CONTROLLER_SLOT_CLOSED:1 conn=104 cause=detach wall_ms=1789523852688 mono_ms=105759 — the controller slot was occupied and is now empty [REQ-REFRESH-WAIT-ATTRIBUTION]\n*106│CONN_LIFECYCLE: conn=104 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523852688 mono_ms=105759 first_write_wall_ms=1789523837637 first_write_mono_ms=90707 event=writer-exit role=controller session=1 reason=write-failed kind=TimedOut [REQ-CONN-POISON-ATTRIBUTION]\n 107│DISPATCH:1:Failed(\"No process is on the other end of the pipe. (os error 233)\")\n*108│DISPATCH_EV: gen=1789523805974 stream=1 family=Attach attempt=2 conn=1 event=worker-outcome detail=Failed(\"No process is on the other end of the pipe. (os error 233)\") elapsed_ms=15052 endpoint=-\n*109│CONN_LIFECYCLE: conn=104 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523852704 mono_ms=105774 first_write_wall_ms=1789523837637 first_write_mono_ms=90707 event=session-detach session=1 was_controller=true viewers_dropped=0 [REQ-CONN-POISON-ATTRIBUTION]\n*110│CONN_LIFECYCLE: conn=104 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523852704 mono_ms=105775 first_write_wall_ms=1789523837637 first_write_mono_ms=90707 event=transport-close poisoned=true timed_out=true [REQ-CONN-POISON-ATTRIBUTION]\n 111│CONN_LIFECYCLE_SUMMARY: scope=broker-ipc wall_ms=1789523869521 mono_ms=122592 interval_ms=61799 starts=40 closes=59 [REQ-CONN-HEALTHY-LIFECYCLE-BOUNDED]\n 112│CONN_LIFECYCLE_SUMMARY: scope=broker-ipc wall_ms=1789523930868 mono_ms=183938 interval_ms=61346 starts=35 closes=53 [REQ-CONN-HEALTHY-LIFECYCLE-BOUNDED]\n*113│BRAIN_UPDATE_RESTART: planned restart — cycling brain onto the swapped binary\n 114│BRAIN_RESTART: planned update respawn (generation 2)\n 115│=== spt brain stderr — generation 2 — pid 35888 ===\n 116│BRAIN_UP: connected to broker spt-daemon-broker-573ad82e70ef3afe.sock (pid 35888, generation 2, start-reason update)\n    │...\n 126│PUMP_IPC_READER: spawned\n*127│CONN_LIFECYCLE: conn=197 role=brain presence-subscriber wall_ms=1789523936910 mono_ms=189981 first_write=none event=presence-sub-attach from_seq=18446744073709551615 [REQ-CONN-POISON-ATTRIBUTION]\n*128│CONN_LIFECYCLE: conn=201 role=brain stream-subscriber stream=1 wall_ms=1789523936922 mono_ms=189993 first_write_wall_ms=1789523936922 first_write_mono_ms=189993 event=stream-sub-attach stream=1 from_seq=0 [REQ-CONN-POISON-ATTRIBUTION]\n 129│ATTACH_INTENT_CHOSEN: site=serve_dispatch session=1 intent=control from_seq=0 gen=1789523756051 coded=false\n*130│CONN_LIFECYCLE: conn=201 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523936923 mono_ms=189994 first_write_wall_ms=1789523936922 first_write_mono_ms=189993 event=controller-attach session=1 from_seq=0 [REQ-CONN-POISON-ATTRIBUTION]\n 131│ATTACH_INTENT_CHOSEN: site=serve_dispatch session=1 intent=control from_seq=0 gen=1789523756051 coded=false\n 132│SUBSCRIBE_DECISION: session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf conn=201 intent=control old_by=- old_gen=0 req_gen=1789523756051 decision=controller\n 133│SUBSCRIBE_DECISION: session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf conn=201 intent=control old_by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf old_gen=1789523756051 req_gen=1789523756051 decision=idempotent\n*134│CONN_WRITE_POISONED: conn=201 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523951971 mono_ms=205042 first_write_wall_ms=1789523936922 first_write_mono_ms=189993 — physical broker conn retired: a write exceeded its 15000ms bound; in-flight I/O aborted, conn never reused [REQ-HAZARD-SHAREDSEND-NO-BLOCKING-WRITE-UNDER-LOCK]\n 135│CONN_LIFECYCLE: conn=201 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523951971 mono_ms=205042 first_write_wall_ms=1789523936922 first_write_mono_ms=189993 event=stream-sub-writer-poison live write failed [REQ-CONN-POISON-ATTRIBUTION]\n*136│BRAIN_SUBSCRIBER_STALL_EVICT:1 conn=201 wall_ms=1789523951971 mono_ms=205042 — controller conn write exceeded its bound; physical conn poisoned + retired (writer released, EOF cleanup follows) [REQ-HAZARD-BROKER-VIEWER-BRAIN-DECOUPLE]\n 137│CONN_LIFECYCLE: conn=201 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523951971 mono_ms=205042 first_write_wall_ms=1789523936922 first_write_mono_ms=189993 event=writer-exit role=controller session=1 reason=write-failed kind=TimedOut [REQ-CONN-POISON-ATTRIBUTION]\n 138│CONTROLLER_SLOT_CLOSED:1 conn=201 cause=detach wall_ms=1789523951972 mono_ms=205042 — the controller slot was occupied and is now empty [REQ-REFRESH-WAIT-ATTRIBUTION]\n 139│DISPATCH:1:Failed(\"No process is on the other end of the pipe. (os error 233)\")\n*140│DISPATCH_EV: gen=1789523936906 stream=1 family=Attach attempt=0 conn=1 event=worker-outcome detail=Failed(\"No process is on the other end of the pipe. (os error 233)\") elapsed_ms=15060 endpoint=-\n 141│CONN_LIFECYCLE: conn=201 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523951989 mono_ms=205060 first_write_wall_ms=1789523936922 first_write_mono_ms=189993 event=session-detach session=1 was_controller=true viewers_dropped=0 [REQ-CONN-POISON-ATTRIBUTION]\n 142│CONN_LIFECYCLE: conn=201 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523951990 mono_ms=205060 first_write_wall_ms=1789523936922 first_write_mono_ms=189993 event=transport-close poisoned=true timed_out=true [REQ-CONN-POISON-ATTRIBUTION]\n*143│CONN_LIFECYCLE: conn=219 role=brain stream-subscriber stream=1 wall_ms=1789523952492 mono_ms=205563 first_write_wall_ms=1789523952492 first_write_mono_ms=205563 event=stream-sub-attach stream=1 from_seq=0 [REQ-CONN-POISON-ATTRIBUTION]\n 144│ATTACH_INTENT_CHOSEN: site=serve_dispatch session=1 intent=control from_seq=0 gen=1789523756051 coded=false\n*145│CONN_LIFECYCLE: conn=219 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523952493 mono_ms=205564 first_write_wall_ms=1789523952492 first_write_mono_ms=205563 event=controller-attach session=1 from_seq=0 [REQ-CONN-POISON-ATTRIBUTION]\n 146│ATTACH_INTENT_CHOSEN: site=serve_dispatch session=1 intent=control from_seq=0 gen=1789523756051 coded=false\n 147│SUBSCRIBE_DECISION: session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf conn=219 intent=control old_by=- old_gen=0 req_gen=1789523756051 decision=controller\n 148│SUBSCRIBE_DECISION: session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf conn=219 intent=control old_by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf old_gen=1789523756051 req_gen=1789523756051 decision=idempotent\n*149│CONN_WRITE_POISONED: conn=219 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523967530 mono_ms=220601 first_write_wall_ms=1789523952492 first_write_mono_ms=205563 — physical broker conn retired: a write exceeded its 15000ms bound; in-flight I/O aborted, conn never reused [REQ-HAZARD-SHAREDSEND-NO-BLOCKING-WRITE-UNDER-LOCK]\n 150│CONN_LIFECYCLE: conn=219 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523967530 mono_ms=220601 first_write_wall_ms=1789523952492 first_write_mono_ms=205563 event=stream-sub-writer-poison live write failed [REQ-CONN-POISON-ATTRIBUTION]\n*151│BRAIN_SUBSCRIBER_STALL_EVICT:1 conn=219 wall_ms=1789523967530 mono_ms=220601 — controller conn write exceeded its bound; physical conn poisoned + retired (writer released, EOF cleanup follows) [REQ-HAZARD-BROKER-VIEWER-BRAIN-DECOUPLE]\n 152│CONTROLLER_SLOT_CLOSED:1 conn=219 cause=detach wall_ms=1789523967530 mono_ms=220601 — the controller slot was occupied and is now empty [REQ-REFRESH-WAIT-ATTRIBUTION]\n 153│CONN_LIFECYCLE: conn=219 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523967530 mono_ms=220601 first_write_wall_ms=1789523952492 first_write_mono_ms=205563 event=writer-exit role=controller session=1 reason=write-failed kind=TimedOut [REQ-CONN-POISON-ATTRIBUTION]\n 154│DISPATCH:1:Failed(\"No process is on the other end of the pipe. (os error 233)\")\n*155│DISPATCH_EV: gen=1789523936906 stream=1 family=Attach attempt=1 conn=1 event=worker-outcome detail=Failed(\"No process is on the other end of the pipe. (os error 233)\") elapsed_ms=15038 endpoint=-\n 156│CONN_LIFECYCLE: conn=219 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523967549 mono_ms=220620 first_write_wall_ms=1789523952492 first_write_mono_ms=205563 event=session-detach session=1 was_controller=true viewers_dropped=0 [REQ-CONN-POISON-ATTRIBUTION]\n 157│CONN_LIFECYCLE: conn=219 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523967549 mono_ms=220620 first_write_wall_ms=1789523952492 first_write_mono_ms=205563 event=transport-close poisoned=true timed_out=true [REQ-CONN-POISON-ATTRIBUTION]\n*158│CONN_LIFECYCLE: conn=240 role=brain stream-subscriber stream=1 wall_ms=1789523968581 mono_ms=221652 first_write_wall_ms=1789523968581 first_write_mono_ms=221651 event=stream-sub-attach stream=1 from_seq=0 [REQ-CONN-POISON-ATTRIBUTION]\n 159│ATTACH_INTENT_CHOSEN: site=serve_dispatch session=1 intent=control from_seq=0 gen=1789523756051 coded=false\n*160│CONN_LIFECYCLE: conn=240 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523968581 mono_ms=221652 first_write_wall_ms=1789523968581 first_write_mono_ms=221651 event=controller-attach session=1 from_seq=0 [REQ-CONN-POISON-ATTRIBUTION]\n 161│ATTACH_INTENT_CHOSEN: site=serve_dispatch session=1 intent=control from_seq=0 gen=1789523756051 coded=false\n 162│SUBSCRIBE_DECISION: session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf conn=240 intent=control old_by=- old_gen=0 req_gen=1789523756051 decision=controller\n 163│SUBSCRIBE_DECISION: session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf conn=240 intent=control old_by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf old_gen=1789523756051 req_gen=1789523756051 decision=idempotent\n 164│STREAM_CONNBOUND_RETIRE:2: opener conn exited — FIN + terminal retire\n*165│CONN_WRITE_POISONED: conn=240 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523983623 mono_ms=236694 first_write_wall_ms=1789523968581 first_write_mono_ms=221651 — physical broker conn retired: a write exceeded its 15000ms bound; in-flight I/O aborted, conn never reused [REQ-HAZARD-SHAREDSEND-NO-BLOCKING-WRITE-UNDER-LOCK]\n 166│CONN_LIFECYCLE: conn=240 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523983623 mono_ms=236694 first_write_wall_ms=1789523968581 first_write_mono_ms=221651 event=stream-sub-writer-poison live write failed [REQ-CONN-POISON-ATTRIBUTION]\n*167│BRAIN_SUBSCRIBER_STALL_EVICT:1 conn=240 wall_ms=1789523983623 mono_ms=236694 — controller conn write exceeded its bound; physical conn poisoned + retired (writer released, EOF cleanup follows) [REQ-HAZARD-BROKER-VIEWER-BRAIN-DECOUPLE]\n 168│CONTROLLER_SLOT_CLOSED:1 conn=240 cause=detach wall_ms=1789523983623 mono_ms=236694 — the controller slot was occupied and is now empty [REQ-REFRESH-WAIT-ATTRIBUTION]\n 169│CONN_LIFECYCLE: conn=240 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523983623 mono_ms=236694 first_write_wall_ms=1789523968581 first_write_mono_ms=221651 event=writer-exit role=controller session=1 reason=write-failed kind=TimedOut [REQ-CONN-POISON-ATTRIBUTION]\n 170│DISPATCH:1:Failed(\"No process is on the other end of the pipe. (os error 233)\")\n*171│DISPATCH_EV: gen=1789523936906 stream=1 family=Attach attempt=2 conn=1 event=worker-outcome detail=Failed(\"No process is on the other end of the pipe. (os error 233)\") elapsed_ms=15043 endpoint=-\n 172│CONN_LIFECYCLE: conn=240 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523984702 mono_ms=237773 first_write_wall_ms=1789523968581 first_write_mono_ms=221651 event=session-detach session=1 was_controller=true viewers_dropped=0 [REQ-CONN-POISON-ATTRIBUTION]\n 173│CONN_LIFECYCLE: conn=240 role=brain stream-subscriber stream=1 controller session=1 endpoint=w1crig by=c96d58a2b4533a6b067bef2e90d5a47db9afcb0a4df1f71678531bed53e033cf wall_ms=1789523984702 mono_ms=237773 first_write_wall_ms=1789523968581 first_write_mono_ms=221651 event=transport-close poisoned=true timed_out=true [REQ-CONN-POISON-ATTRIBUTION]"},"isError":false,"timestamp":1789523993599}}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_PS0PFtqjxq9UZdISwwwPq3hJ|fc_09b01b5279447709016aa9f81b5ecc87d2b802de771bdd9859","toolName":"glob","startedAt":"2026-09-16T01:59:59.628Z","args":{"path":"crates/spt-daemon/src/*net*;crates/spt-daemon/src/net/**/*"},"intent":"Locating network host source"},"id":"e29ac6d2","parentId":"74393b6d","timestamp":"2026-09-16T01:59:59.628Z"}
{"type":"message","id":"0b6d526f","parentId":"e29ac6d2","timestamp":"2026-09-16T01:59:59.628Z","message":{"role":"assistant","content":[{"type":"toolCall","id":"call_PS0PFtqjxq9UZdISwwwPq3hJ|fc_09b01b5279447709016aa9f81b5ecc87d2b802de771bdd9859","name":"glob","arguments":{"i":"Locating network host source","path":"crates/spt-daemon/src/*net*;crates/spt-daemon/src/net/**/*","hidden":true,"gitignore":true,"limit":40},"intent":"Locating network host source"}],"api":"openai-codex-responses","provider":"openai-codex","model":"gpt-6-astra","usage":{"input":29075,"output":57,"cacheRead":38016,"cacheWrite":0,"totalTokens":67148,"cost":{"input":0.29075,"output":0.00285,"cacheRead":0.038016,"cacheWrite":0,"total":0.331616}},"stopReason":"toolUse","timestamp":1789523993627,"responseId":"resp_09b01b5279447709016aa9f819f4e887d2be4c408d44dc3bb8","providerPayload":{"type":"openaiResponsesHistory","provider":"openai-codex","dt":true,"items":[{"id":"fc_09b01b5279447709016aa9f81b5ecc87d2b802de771bdd9859","type":"function_call","status":"completed","arguments":"{\"i\":\"Locating network host source\",\"path\":\"crates/spt-daemon/src/*net*;crates/spt-daemon/src/net/**/*\",\"hidden\":true,\"gitignore\":true,\"limit\":40}","call_id":"call_PS0PFtqjxq9UZdISwwwPq3hJ","internal_chat_message_metadata_passthrough":{"create_time":1789523994.172336,"turn_id":"a464097d-3a78-4a75-9ebb-a53f309aa685"},"name":"glob","metadata":{"turn_id":"a464097d-3a78-4a75-9ebb-a53f309aa685"}}]},"duration":5999.818900000071,"ttft":1775.5389000000432,"completedAt":1789523999627,"contextSnapshot":{"promptTokens":67091,"nonMessageTokens":10480,"compactionEpoch":0}}}
{"type":"message","id":"954098d3","parentId":"0b6d526f","timestamp":"2026-09-16T01:59:59.636Z","message":{"role":"toolResult","toolCallId":"call_PS0PFtqjxq9UZdISwwwPq3hJ|fc_09b01b5279447709016aa9f81b5ecc87d2b802de771bdd9859","toolName":"glob","content":[{"type":"text","text":"# crates/spt-daemon/src/\nnethost.rs\n\nSkipped missing paths: crates/spt-daemon/src/net/**/*"}],"details":{"scopePath":"crates/spt-daemon/src","fileCount":1,"files":["crates/spt-daemon/src/nethost.rs"],"truncated":false,"cwd":"C:\\Users\\decid\\Documents\\projects\\spt-core","missingPaths":["crates/spt-daemon/src/net/**/*"]},"isError":false,"timestamp":1789523999636}}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_SLUIrflXvjMsZjhf8RwI4KfV|fc_09b01b5279447709016aa9f82bb11c87d2af01b9e210f8d92b","toolName":"grep","startedAt":"2026-09-16T02:00:11.773Z","args":{"path":"crates/spt-daemon/src/nethost.rs"},"intent":"Locating stream waits and locks"},"id":"2bc5e69f","parentId":"954098d3","timestamp":"2026-09-16T02:00:11.773Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_w6Oyg8OpwngH12l13l9ZI1Re|fc_09b01b5279447709016aa9f82bb12c87d2bb97e6da4711c5ce","toolName":"grep","startedAt":"2026-09-16T02:00:11.773Z","args":{"path":"crates/spt-daemon/tests/attach.rs;crates/spt-daemon/tests/attach_idempotent_replay.rs;crates/spt-daemon/tests/redispatch_stall.rs;crates/spt-daemon/tests/redispatch.rs"},"intent":"Locating tests for replay pressure"},"id":"b3f642d5","parentId":"2bc5e69f","timestamp":"2026-09-16T02:00:11.773Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_i0IQUAawhElXkfR7lvdzvQ8U|fc_09b01b5279447709016aa9f82bb13487d29581ac49eb5cbbea","toolName":"grep","startedAt":"2026-09-16T02:00:11.773Z","args":{"path":"crates/spt-daemon/src/brain.rs;crates/spt-daemon/src/resting.rs;crates/spt-daemon/src/broker.rs"},"intent":"Locating brain sends and rest wait"},"id":"9a1b13f2","parentId":"b3f642d5","timestamp":"2026-09-16T02:00:11.773Z"}
{"type":"message","id":"8228b9a7","parentId":"9a1b13f2","timestamp":"2026-09-16T02:00:11.773Z","message":{"role":"assistant","content":[{"type":"toolCall","id":"call_SLUIrflXvjMsZjhf8RwI4KfV|fc_09b01b5279447709016aa9f82bb11c87d2af01b9e210f8d92b","name":"grep","arguments":{"i":"Locating stream waits and locks","pattern":"fn .*stream|fn subscribe|recv\\(|block_on|send_stream|ack|SharedSend","path":"crates/spt-daemon/src/nethost.rs","case":true,"gitignore":true,"skip":null},"intent":"Locating stream waits and locks"},{"type":"toolCall","id":"call_w6Oyg8OpwngH12l13l9ZI1Re|fc_09b01b5279447709016aa9f82bb12c87d2bb97e6da4711c5ce","name":"grep","arguments":{"i":"Locating tests for replay pressure","pattern":"^fn |^async fn |pending_input|replay|restart|backpressure","path":"crates/spt-daemon/tests/attach.rs;crates/spt-daemon/tests/attach_idempotent_replay.rs;crates/spt-daemon/tests/redispatch_stall.rs;crates/spt-daemon/tests/redispatch.rs","case":true,"gitignore":true,"skip":null},"intent":"Locating tests for replay pressure"},{"type":"toolCall","id":"call_i0IQUAawhElXkfR7lvdzvQ8U|fc_09b01b5279447709016aa9f82bb13487d29581ac49eb5cbbea","name":"grep","arguments":{"i":"Locating brain sends and rest wait","pattern":"fn send\\(|fn subscribe_with|fn daemon_rest_event|fn dispatch_net_stream_send","path":"crates/spt-daemon/src/brain.rs;crates/spt-daemon/src/resting.rs;crates/spt-daemon/src/broker.rs","case":true,"gitignore":true,"skip":null},"intent":"Locating brain sends and rest wait"}],"api":"openai-codex-responses","provider":"openai-codex","model":"gpt-6-astra","usage":{"input":239,"output":285,"cacheRead":66944,"cacheWrite":0,"totalTokens":67468,"cost":{"input":0.00239,"output":0.01425,"cacheRead":0.066944,"cacheWrite":0,"total":0.083584}},"stopReason":"toolUse","timestamp":1789523999660,"responseId":"resp_09b01b5279447709016aa9f81ff67c87d28fd0b10ef0651d72","providerPayload":{"type":"openaiResponsesHistory","provider":"openai-codex","dt":true,"items":[{"id":"fc_09b01b5279447709016aa9f82bb11c87d2af01b9e210f8d92b","type":"function_call","status":"completed","arguments":"{\"i\":\"Locating stream waits and locks\",\"pattern\":\"fn .*stream|fn subscribe|recv\\\\(|block_on|send_stream|ack|SharedSend\",\"path\":\"crates/spt-daemon/src/nethost.rs\",\"case\":true,\"gitignore\":true,\"skip\":null}","call_id":"call_SLUIrflXvjMsZjhf8RwI4KfV","internal_chat_message_metadata_passthrough":{"turn_id":"a464097d-3a78-4a75-9ebb-a53f309aa685"},"name":"grep","metadata":{"turn_id":"a464097d-3a78-4a75-9ebb-a53f309aa685"}},{"id":"fc_09b01b5279447709016aa9f82bb12c87d2bb97e6da4711c5ce","type":"function_call","status":"completed","arguments":"{\"i\":\"Locating tests for replay pressure\",\"pattern\":\"^fn |^async fn |pending_input|replay|restart|backpressure\",\"path\":\"crates/spt-daemon/tests/attach.rs;crates/spt-daemon/tests/attach_idempotent_replay.rs;crates/spt-daemon/tests/redispatch_stall.rs;crates/spt-daemon/tests/redispatch.rs\",\"case\":true,\"gitignore\":true,\"skip\":null}","call_id":"call_w6Oyg8OpwngH12l13l9ZI1Re","internal_chat_message_metadata_passthrough":{"turn_id":"a464097d-3a78-4a75-9ebb-a53f309aa685"},"name":"grep","metadata":{"turn_id":"a464097d-3a78-4a75-9ebb-a53f309aa685"}},{"id":"fc_09b01b5279447709016aa9f82bb13487d29581ac49eb5cbbea","type":"function_call","status":"completed","arguments":"{\"i\":\"Locating brain sends and rest wait\",\"pattern\":\"fn send\\\\(|fn subscribe_with|fn daemon_rest_event|fn dispatch_net_stream_send\",\"path\":\"crates/spt-daemon/src/brain.rs;crates/spt-daemon/src/resting.rs;crates/spt-daemon/src/broker.rs\",\"case\":true,\"gitignore\":true,\"skip\":null}","call_id":"call_i0IQUAawhElXkfR7lvdzvQ8U","internal_chat_message_metadata_passthrough":{"turn_id":"a464097d-3a78-4a75-9ebb-a53f309aa685"},"name":"grep","metadata":{"turn_id":"a464097d-3a78-4a75-9ebb-a53f309aa685"}}]},"duration":12111.05520000006,"ttft":12058.861500000115,"completedAt":1789524011772,"contextSnapshot":{"promptTokens":67183,"nonMessageTokens":10480,"compactionEpoch":0}}}
{"type":"message","id":"c81f1d2e","parentId":"8228b9a7","timestamp":"2026-09-16T02:00:11.786Z","message":{"role":"toolResult","toolCallId":"call_SLUIrflXvjMsZjhf8RwI4KfV|fc_09b01b5279447709016aa9f82bb11c87d2af01b9e210f8d92b","toolName":"grep","content":[{"type":"text","text":" 16|//! (`spt-broker-net`): QUIC objects live in structures only the runtime's tasks\n*17|//! and the host's own `block_on` bridges touch, and the runtime drops with the\n 18|//! host (broker teardown stops all net tasks). Spike #3's broker binary proved\n 19|//! exactly this shape — a broker-owned endpoint surviving brain kill/restart.\n 20|//!\n...\n 43|\n*44|use crate::broker::SharedSend;\n 45|\n 46|use crate::effect::Minter;\n 47|use crate::seedproofx::{prove_membership, MembershipSource, RosterExchange};\n...\n 59|/// Broker-side QUIC-op deadline (REQ-HAZARD-BROKER-QUIC-DEADLINE), in ms. Each\n*60|/// brain-waiting QUIC await — `dial` / `open_stream` / `send_stream` — is bounded\n*61|/// by this so a black-holed or dead peer fails PROMPTLY with an ORDINARY error\n 62|/// the broker replies, never an unbounded await that wedges the single-threaded\n 63|/// pump (the B-half of REQ-HAZARD-PUMP-IPC-DEADLINE; the 2.2h hfenduleam wedge).\n 64|/// Chosen at **10s**: comfortably above any legitimate LAN/relay connect +\n...\n 71|/// frame's IPC transit + the brain's read scheduling. Test-overridable via\n*72|/// [`NetHost::set_quic_op_timeout`] so the hermetic black-hole tests fail fast.\n 73|const BROKER_QUIC_OP_TIMEOUT_MS: u64 = 10_000;\n 74|\n 75|/// Bounded concurrent-dial cap (PUMP-TRUTH W2, REQ-PUMP-PEER-ISOLATION, G4): a\n...\n 95|    /// Socket bind scope: [`BindScope::All`] in production;\n*96|    /// [`BindScope::Loopback`] in hermetic tests (no real interface touched,\n 97|    /// no per-test-binary Windows firewall prompt).\n 98|    pub scope: BindScope,\n 99|    /// Live source of this node's subnet credentials for the connect-time\n...\n 143|/// fixes 2+3, REQ-STREAMLOG-SUBSCRIBER-DISCIPLINE): frames ENQUEUE under the\n*144|/// log mutex; the conn I/O — the deadline-bounded `SharedSend::write` that can\n 145|/// take 15s against a wedged conn — runs on this seat's OWN writer thread,\n 146|/// OUTSIDE every lock. The field stall was exactly the old shape's serial\n 147|/// replay-under-mutex against a poisoned conn (33 windows, all ~15s).\n...\n 154|struct SubscriberSeat {\n*155|    sub: SharedSend,\n 156|    tx: std::sync::mpsc::SyncSender<Envelope>,\n 157|    /// Writer thread exited (failure or clean drain) — the seat is fully gone\n 158|    /// and a replacement may install (the no-reinstall-until-gone rule,\n...\n 169|impl SubscriberSeat {\n*170|    /// Install a seat: spawn its writer thread and hand back the handle.\n 171|    /// `replay` is the attach snapshot, moved in UNDER the log mutex (a\n 172|    /// memory move, never conn I/O): the writer drains it COMPLETELY before\n 173|    /// touching the live queue, so replay-then-live seq order holds by\n...\n 189|    fn install(\n*190|        sub: SharedSend,\n 191|        replay: Vec<Envelope>,\n 192|        lease: Option<Arc<StreamLease>>,\n 193|        label: &str,\n...\n 224|                // Then live frames, same halt discipline.\n*225|                while let Ok(frame) = rx.recv() {\n 226|                    if writer_sub.write(&frame).is_err() {\n 227|                        poison(\"live write failed\");\n 228|                        break;\n...\n 270|    /// Whether this seat belongs to `sub` (detach correlation).\n*271|    fn is(&self, sub: &SharedSend) -> bool {\n 272|        Arc::ptr_eq(&self.sub, sub)\n 273|    }\n 274|\n...\n 283|/// mechanism): canceled when the stream's subscriber seat POISONS, which\n*284|/// makes every later `send_stream` on the stream refuse — the paired\n 285|/// serve/wire worker discovers the cancellation at its next forward and\n 286|/// terminates instead of feeding an orphan leg forever.\n 287|// [impl->REQ-STREAMLOG-SUBSCRIBER-DISCIPLINE]\n...\n 319|\n*320|/// Transport backing a held connection. A real `Quic` connection (the only\n*321|/// kind an inbound handshake can produce), or a broker-minted `Loopback` —\n 322|/// an in-process connection with NO iroh handshake whose identity IS this node,\n*323|/// established BY CONSTRUCTION. A loopback conn can ONLY be minted broker-side\n*324|/// via [`NetHost::dial_loopback`]; it can never arise from an inbound handshake\n 325|/// (a remote always presents its own key and cannot claim to be us). This is\n 326|/// what lets a LOCAL `spt rc` ride the byte-identical `serve_attach` pump (M12\n 327|/// W1.5, B1) — QUIC self-dial is refused by iroh (\"Connecting to ourself is not\n*328|/// supported\"), so local attach rides a broker loopback conn instead.\n 329|enum ConnKind {\n 330|    /// A real QUIC connection — kept alive by ownership here; dropping it closes\n 331|    /// the connection. Cloned (cheap handle) for stream opens.\n 332|    Quic(Connection),\n*333|    /// A broker-minted in-process loopback (no iroh handle, no handshake). Its\n 334|    /// streams are minted eagerly in cross-wired pairs by [`NetHost::open_stream`];\n 335|    /// there is no accept loop and no closed-watcher (it lives for the host).\n*336|    Loopback,\n 337|}\n 338|\n*339|/// One live connection the broker holds (QUIC or loopback).\n 340|struct ConnEntry {\n*341|    /// The transport backing this connection.\n 342|    kind: ConnKind,\n 343|    /// The remote node's stable name (hex pubkey). For QUIC, proven by the\n*344|    /// handshake; for loopback, THIS node's own id (the broker-minted identity).\n 345|    remote_id_hex: String,\n 346|    /// The subnets the peer proved current-epoch seed-knowledge of at connect\n 347|    /// (Mesh-D2, REQ-MESH-1). Empty when seed-proof is disabled (`membership:\n...\n 383|    finished: bool,\n*384|    /// **Retentive backpressure cap** (M11-W3, REQ-SHELL-4), in chunks; `0` ⇒ not\n 385|    /// retentive (ordinary bounded-overwrite stream). A shell-tunnel stream must\n 386|    /// NOT drop bytes — CONTEXT:262 \"tunneled protocols cannot drop frames, so\n 387|    /// congestion surfaces as lag, never loss.\" So a retentive log never cap-evicts\n...\n 401|impl StreamLog {\n*402|    fn new(stream_id: u64, cap_chunks: usize) -> Self {\n 403|        StreamLog {\n 404|            stream_id,\n 405|            next_seq: 0,\n...\n 431|\n*432|    /// Mark this log retentive with backpressure `cap` (chunks). Idempotent set.\n 433|    fn set_retentive(&mut self, cap: usize) {\n 434|        self.retentive_cap = cap;\n 435|    }\n...\n 466|        self.next_seq += 1;\n*467|        self.ring.push_back((seq, bytes.to_vec()));\n 468|        if self.retentive_cap == 0 {\n 469|            while self.ring.len() > self.cap_chunks {\n 470|                self.ring.pop_front();\n...\n 502|    /// Drain every undrained chunk in order (the shell-tunnel recv cursor, W3).\n*503|    /// Pops the whole ring front-to-back (FIFO by `seq`) and concatenates the\n 504|    /// bytes — chunk boundaries are arbitrary read-pump splits, irrelevant to an\n 505|    /// opaque byte stream. Lossless + ordered: a byte leaves the ring only here,\n 506|    /// once. Returns `(bytes, finished)`; `finished` reflects a clean/torn end so\n...\n 544|    // [impl->REQ-STREAMLOG-SUBSCRIBER-DISCIPLINE]\n*545|    fn begin_attach(&mut self, sub: SharedSend, from_seq: u64) -> io::Result<usize> {\n 546|        if let Some(prior) = &self.subscriber {\n 547|            // No-reinstall-until-gone applies to the POISON class only\n 548|            // (REQ-DISPATCH-FALLBACK-CIRCUIT): a wedged writer may sit in a\n...\n 590|        // One poison never dead-ends the stream (T5 recovery): the next\n*591|        // generation's mint IS the renewal; `send_stream` reads this current\n 592|        // Arc, old workers' handles stay theirs (C2 consumes via\n 593|        // [`NetHost::stream_lease`]).\n 594|        // [impl->REQ-STREAMLOG-SUBSCRIBER-DISCIPLINE]\n...\n 610|    // [impl->REQ-SEAT-LIFETIME-BOUNDED]\n*611|    fn take_seat_if(&mut self, sub: &SharedSend) -> Option<SubscriberSeat> {\n 612|        if self.subscriber.as_ref().is_some_and(|cur| cur.is(sub)) {\n 613|            self.subscriber.take()\n 614|        } else {\n...\n 620|    /// not unsubscribe a newer brain).\n*621|    fn detach_if(&mut self, sub: &SharedSend) {\n 622|        if let Some(cur) = &self.subscriber {\n 623|            if cur.is(sub) {\n 624|                self.subscriber = None;\n...\n 672|    /// A `connected` event carrying the connection's OBSERVED remote address\n*673|    /// (REQ-CONV-1): the async-dial write-back seed the blocking `net-dialed`\n 674|    /// reply used to carry — now it rides the presence stream so the pump seeds\n 675|    /// `peer-addrs.json` from a non-blocking dial the same way.\n 676|    // [impl->REQ-CONV-1]\n...\n 720|        self.next_seq += 1;\n*721|        self.ring.push_back(ev.clone());\n 722|        while self.ring.len() > self.cap_events {\n 723|            self.ring.pop_front();\n 724|        }\n...\n 744|    // [impl->REQ-STREAMLOG-SUBSCRIBER-DISCIPLINE]\n*745|    fn begin_attach(&mut self, sub: SharedSend, from_seq: u64) -> io::Result<usize> {\n 746|        if let Some(prior) = &self.subscriber {\n 747|            // Poison-class only (see StreamLog::begin_attach): a healthy\n 748|            // prior presence subscriber is displaced by the newer brain.\n...\n 775|    /// not unsubscribe a newer brain).\n*776|    fn detach_if(&mut self, sub: &SharedSend) {\n 777|        if let Some(cur) = &self.subscriber {\n 778|            if cur.is(sub) {\n 779|                self.subscriber = None;\n...\n 788|/// write end of an in-process duplex). That is the M12 W1.5 one-pump invariant\n*789|/// made structural: a loopback attach and a cross-node attach diverge at this\n 790|/// leaf and nowhere above it.\n 791|enum SendHalf {\n 792|    Quic(SendStream),\n*793|    Loopback(WriteHalf<DuplexStream>),\n 794|}\n 795|\n 796|impl SendHalf {\n...\n 803|                .map_err(|e| io::Error::other(e.to_string())),\n*804|            SendHalf::Loopback(w) => w.write_all(bytes).await,\n 805|        }\n 806|    }\n 807|\n...\n 812|            SendHalf::Quic(s) => s.finish().map_err(|e| io::Error::other(e.to_string())),\n*813|            SendHalf::Loopback(w) => w.shutdown().await,\n 814|        }\n 815|    }\n 816|}\n...\n 818|/// A stream's read half — fed into the single read pump in [`register_stream`].\n*819|/// QUIC reads via quinn's chunk API; loopback via the read end of the duplex.\n 820|/// Both append to the same [`StreamLog`], so the subscriber (and everything\n 821|/// above it) cannot tell the transports apart.\n 822|enum RecvHalf {\n 823|    Quic(RecvStream),\n*824|    Loopback(ReadHalf<DuplexStream>),\n 825|}\n 826|\n*827|/// One live stream the broker holds (QUIC or loopback): the send half (brain\n 828|/// writes ride it over IPC) + the sequenced read log.\n 829|struct StreamEntry {\n 830|    conn_id: u64,\n...\n 838|    /// The send half, serialized behind an async mutex (writes happen on the\n*839|    /// host's runtime via `block_on`).\n 840|    send: tokio::sync::Mutex<SendHalf>,\n 841|    log: Arc<Mutex<StreamLog>>,\n 842|    /// Wakes the read pump when a retentive (tunnel) stream's ring drains below\n*843|    /// its backpressure cap (M11-W3, REQ-SHELL-4) — see [`StreamLog::retentive_cap`].\n 844|    /// Unused by ordinary (non-retentive) streams.\n 845|    room: Arc<tokio::sync::Notify>,\n 846|    /// Retired = invisible to dispatch eligibility (ADR-0038 A), NOT torn down:\n...\n 901|/// acceptor. Must run inside the host's runtime context (the accept loop, or a\n*902|/// `block_on` future) — it spawns tasks.\n 903|/// The connection's OBSERVED remote address as opaque seed JSON (REQ-CONV-1):\n 904|/// the path address string, or `null` when id-only / path-less (nothing worth\n*905|/// seeding over discovery). Shared by [`register_conn`]'s presence write-back\n 906|/// and [`NetHost::conn_remote_addr_json`] so both seed identically.\n 907|// [impl->REQ-CONV-1]\n 908|fn observed_addr_json(conn: &Connection) -> serde_json::Value {\n...\n 969|    /// the observed addr). The caller bounds this await (the blocking dial via\n*970|    /// `bounded_block_on`; the submit via its own `timeout`). `stage` names the\n 971|    /// pipeline stage the dial is in (ADR-0039 Decision 5) — a stage-local\n 972|    /// error and the caller's outer timeout both read it, so the failure token\n 973|    /// says WHERE the dial died instead of collapsing six stages into one.\n...\n 1031|    // `connected` event can never race behind its own `disconnected` (D4c). The\n*1032|    // event carries the OBSERVED remote addr (REQ-CONV-1 seed write-back) so a\n 1033|    // non-blocking submit-dial seeds `peer-addrs.json` like the blocking reply\n 1034|    // did (id-only / path-less → `null`, nothing worth seeding).\n 1035|    let observed = observed_addr_json(&conn);\n...\n 1099|/// from [`NetHost::open_stream`]).\n*1100|fn register_stream(\n 1101|    shared: &Arc<NetShared>,\n 1102|    conn_id: u64,\n 1103|    remote_id_hex: &str,\n...\n 1128|    // replayable either way. The transport differs only at this read leaf\n*1129|    // (QUIC chunk API vs the loopback duplex's `AsyncRead`); both append to the\n 1130|    // same `StreamLog`, so nothing above the pump can tell them apart.\n 1131|    //\n*1132|    // Backpressure (M11-W3, REQ-SHELL-4): a retentive (tunnel) log never evicts,\n 1133|    // so before pulling the next chunk the pump WAITS while the undrained ring is\n 1134|    // at its `retentive_cap`. The unread bytes stay in the transport's buffer, so\n*1135|    // QUIC stream flow-control (or the loopback duplex's bounded buffer) lags the\n 1136|    // SENDER — \"lag, never loss\" (CONTEXT:262). A `drain` wakes `room`. Ordinary\n 1137|    // streams have `retentive_cap == 0`, so this gate is a no-op for them.\n 1138|    tokio::spawn(async move {\n...\n 1149|            },\n*1150|            RecvHalf::Loopback(mut recv) => {\n 1151|                let mut buf = vec![0u8; STREAM_READ_CHUNK];\n 1152|                loop {\n 1153|                    await_ring_room(&log, &room).await;\n...\n 1168|\n*1169|/// Backpressure gate for a retentive (tunnel) read pump: park until the undrained\n 1170|/// ring has room below `retentive_cap`, woken by a `drain` on `room`. A no-op for\n 1171|/// an ordinary stream (`retentive_cap == 0`). Holds no lock across the await.\n 1172|// [impl->REQ-SHELL-4]\n...\n 1213|    roster: Arc<Mutex<Option<RosterExchange>>>,\n*1214|    /// The broker's single in-process loopback connection (M12 W1.5, B1),\n*1215|    /// minted lazily on the first [`Self::dial_loopback`] and reused thereafter\n 1216|    /// — a local `spt rc` needs exactly one. `Some(conn_id)` once minted; the\n 1217|    /// row lives for the host (no handshake to lose, no closed-watcher).\n*1218|    loopback_conn: Mutex<Option<u64>>,\n*1219|    /// Serializes [`Self::open_loopback_pair`] (M11-W3) so the peer-row discovery\n*1220|    /// (a before/after diff on the loopback conn's inbound rows) sees exactly the\n*1221|    /// one row this open minted — concurrent pair-opens on the shared loopback conn\n 1222|    /// would otherwise race the diff.\n*1223|    loopback_pair_lock: Mutex<()>,\n 1224|    /// The broker-side QUIC-op deadline in ms (REQ-HAZARD-BROKER-QUIC-DEADLINE),\n*1225|    /// default [`BROKER_QUIC_OP_TIMEOUT_MS`]; the hermetic black-hole tests lower\n 1226|    /// it via [`Self::set_quic_op_timeout`]. Interior-mutable so the setter takes\n 1227|    /// `&self`, like the live host's other post-`start` knobs (`set_roster_exchange`).\n 1228|    quic_op_timeout_ms: AtomicU64,\n...\n 1242|    /// runtime task stamps epoch-ms here every ~25ms. If the 2 workers are\n*1243|    /// MONOPOLIZED (a non-yielding dead-peer connect that never awaits back to\n 1244|    /// the scheduler) the stamp goes STALE — the DIRECT worker-starvation\n 1245|    /// discriminator the round-3 rig asserts on. A fresh stamp under a dead-peer\n 1246|    /// burst PROVES the QUIC awaits yield cleanly (⇒ the 2-worker-starvation\n...\n 1280|    pub fn start(cfg: NetConfig) -> io::Result<NetHost> {\n*1281|        // Hermeticity guard (REQ-PAIR-8): a loopback-scoped endpoint is the\n 1282|        // \"no network reached\" promise — the ceremony clock's lazy NTP query\n 1283|        // must honor it (tests must never probe a real NTP server). Real\n 1284|        // scopes keep the decision-18 offset correction.\n*1285|        spt_net::net::pairing::ntp::set_enabled(!matches!(cfg.scope, BindScope::Loopback));\n 1286|        let runtime = tokio::runtime::Builder::new_multi_thread()\n 1287|            .worker_threads(2)\n 1288|            .thread_name(\"spt-broker-net\")\n...\n 1291|        let endpoint = runtime\n*1292|            .block_on(NetEndpoint::bind_scoped(\n 1293|                &cfg.identity,\n 1294|                cfg.relay.clone(),\n 1295|                cfg.discovery,\n...\n 1353|                                    &self_addr,\n*1354|                                    &DialStage::new(), // accept side: stage untracked\n 1355|                                )\n 1356|                                .await\n 1357|                                {\n...\n 1406|            roster,\n*1407|            loopback_conn: Mutex::new(None),\n*1408|            loopback_pair_lock: Mutex::new(()),\n 1409|            quic_op_timeout_ms: AtomicU64::new(BROKER_QUIC_OP_TIMEOUT_MS),\n 1410|            dial_semaphore: Arc::new(tokio::sync::Semaphore::new(PUMP_DIAL_CONCURRENCY)),\n 1411|            active_dial_tasks: Arc::new(AtomicUsize::new(0)),\n...\n 1441|    /// Production keeps the [`BROKER_QUIC_OP_TIMEOUT_MS`] default; the hermetic\n*1442|    /// black-hole tests set a short bound so a dead-peer await fails fast instead\n 1443|    /// of pinning the test for ~10s. Off [`NetConfig`] by design (mirrors\n 1444|    /// [`Self::set_roster_exchange`]) — the many hermetic test configs need no change.\n 1445|    // [impl->REQ-HAZARD-BROKER-QUIC-DEADLINE]\n...\n 1452|    /// (REQ-HAZARD-BROKER-QUIC-DEADLINE) — the B-half of REQ-HAZARD-PUMP-IPC-\n*1453|    /// DEADLINE. A brain-waiting QUIC await against a black-holed/dead peer must\n 1454|    /// fail PROMPTLY with an ORDINARY error the broker replies, never the\n 1455|    /// unbounded await that wedged the single-threaded pump for 2.2h. On elapse\n 1456|    /// the future is DROPPED — cancelling the in-flight connect / stream op, so\n...\n 1468|    // [impl->REQ-HAZARD-BROKER-QUIC-DEADLINE]\n*1469|    fn bounded_block_on<F, T>(&self, fut: F) -> io::Result<T>\n 1470|    where\n 1471|        F: std::future::Future<Output = io::Result<T>>,\n 1472|    {\n 1473|        let dur = self.quic_op_timeout();\n*1474|        self.runtime.handle().block_on(async move {\n 1475|            match tokio::time::timeout(dur, fut).await {\n 1476|                Ok(inner) => inner,\n 1477|                Err(_elapsed) => Err(io::Error::other(format!(\n...\n 1496|        let endpoint = Arc::clone(&self.endpoint);\n*1497|        self.runtime.handle().block_on(async move {\n 1498|            crate::pairhost::join_ceremony(&endpoint, subnet, code, responder_addr).await\n 1499|        })\n 1500|    }\n...\n 1512|        let endpoint = Arc::clone(&self.endpoint);\n*1513|        self.runtime.handle().block_on(async move {\n 1514|            crate::pairhost::meet_seed_holder(&endpoint, subnet, verbose).await\n 1515|        })\n 1516|    }\n...\n 1539|    /// tasks currently on the 2-worker net runtime. The starvation rig reads this\n*1540|    /// to correlate a dead-peer burst with loopback-drain health.\n 1541|    pub fn active_dial_tasks(&self) -> usize {\n 1542|        self.active_dial_tasks.load(Ordering::Relaxed)\n 1543|    }\n...\n 1567|        // Bounded (REQ-HAZARD-BROKER-QUIC-DEADLINE): the `connect` + `prove_membership`\n*1568|        // awaits are the exact unbounded sites a dead peer black-holes — wrap\n 1569|        // them so a non-responsive peer fails as an ordinary error within the bound.\n*1570|        self.bounded_block_on(async move {\n 1571|            // Q2 caveat: the blocking dial acquires a permit from the SAME\n 1572|            // semaphore as `submit_dial`, so the concurrency cap bounds every dial\n 1573|            // source (never bypassed). `acquire_owned` errs only on a closed\n...\n 1638|                    // Ordinary per-peer failure rides the presence stream — the pump\n*1639|                    // backs THIS peer off and moves on; the round is never poisoned.\n 1640|                    // The reason is stage-attributed (REQ-PUMP-STAGE-TRUTH).\n 1641|                    shared.presence.lock().unwrap().append_dial_failed(\n 1642|                        &remote_id_hex,\n...\n 1713|    /// connection's current path addresses) as opaque JSON — the address-\n*1714|    /// seeding write-back the `net-dialed` reply carries (M8 decision 20,\n 1715|    /// REQ-CONV-1). `null` when the conn is gone, path-less, or fails to\n 1716|    /// serialize: the seed is an optimization, never an error path.\n 1717|    // [impl->REQ-CONV-1]\n...\n 1721|            match conns.get(&conn_id) {\n*1722|                // A loopback conn has no path to observe — nothing to seed.\n 1723|                Some(e) => match &e.kind {\n 1724|                    ConnKind::Quic(c) => c.clone(),\n*1725|                    ConnKind::Loopback => return serde_json::Value::Null,\n 1726|                },\n 1727|                None => return serde_json::Value::Null,\n 1728|            }\n...\n 1732|\n*1733|    /// Mint (or reuse) the broker's single in-process loopback connection\n 1734|    /// (M12 W1.5, B1) and return `(conn_id, remote_id_hex)` — `remote_id_hex` is\n 1735|    /// THIS node's own id, so a stream served over it gates same-node (access\n 1736|    /// short-circuit Allow). The conn carries NO iroh handshake: its identity is\n...\n 1742|    // [impl->REQ-RC-1]\n*1743|    pub fn dial_loopback(&self) -> (u64, String) {\n 1744|        let remote_id_hex = self.local_id.to_hex();\n*1745|        let mut slot = self.loopback_conn.lock().unwrap();\n 1746|        if let Some(id) = *slot {\n 1747|            return (id, remote_id_hex);\n 1748|        }\n...\n 1752|            ConnEntry {\n*1753|                kind: ConnKind::Loopback,\n 1754|                remote_id_hex: remote_id_hex.clone(),\n 1755|                proven_subnets: HashSet::new(),\n 1756|            },\n...\n 1765|    ///\n*1766|    /// On a [`ConnKind::Loopback`] conn there is no peer to accept the stream,\n 1767|    /// so the open mints a CROSS-WIRED PAIR in-process: an operator row\n 1768|    /// (`initiated_locally = true`, the returned id) and a peer row\n 1769|    /// (`initiated_locally = false`) the inbound dispatcher claims and serves via\n...\n 1776|    // [impl->REQ-RC-1]\n*1777|    pub fn open_stream(\n 1778|        &self,\n 1779|        conn_id: u64,\n 1780|        lifetime: crate::msg::StreamLifetime,\n 1781|    ) -> io::Result<u64> {\n*1782|        enum Backing {\n 1783|            Quic(Connection),\n*1784|            Loopback,\n 1785|        }\n*1786|        let (backing, remote_id_hex) = {\n 1787|            let conns = self.shared.conns.lock().unwrap();\n 1788|            let e = conns.get(&conn_id).ok_or_else(|| {\n 1789|                io::Error::new(io::ErrorKind::NotFound, format!(\"no such conn {conn_id}\"))\n 1790|            })?;\n*1791|            let backing = match &e.kind {\n*1792|                ConnKind::Quic(c) => Backing::Quic(c.clone()),\n*1793|                ConnKind::Loopback => Backing::Loopback,\n 1794|            };\n*1795|            (backing, e.remote_id_hex.clone())\n 1796|        };\n 1797|        let shared = Arc::clone(&self.shared);\n*1798|        match backing {\n*1799|            // Bounded (REQ-HAZARD-BROKER-QUIC-DEADLINE): `open_bi` on a black-holed\n 1800|            // peer can block on stream flow-control credit the dead peer never grants.\n*1801|            Backing::Quic(conn) => self.bounded_block_on(async move {\n 1802|                let (send, recv) = conn\n 1803|                    .open_bi()\n 1804|                    .await\n...\n 1816|            // Bounded like the QUIC arm (REQ-BROKER-ATTACH-JOURNAL-RESILIENT, bug\n*1817|            // #16): the loopback open is all in-memory and normally returns\n 1818|            // instantly, but a SICK NetHost runtime (saturated/wedged after a\n 1819|            // self-update brain-respawn) would otherwise hang this journaled op with\n 1820|            // no deadline — killing the per-conn reply thread so every attach\n 1821|            // silently deadlines (\"brain IPC read deadline elapsed\") while\n*1822|            // non-journaled ops keep working. `bounded_block_on` turns that into a\n 1823|            // prompt ordinary error frame; the bound never bites a healthy runtime.\n 1824|            // [impl->REQ-BROKER-ATTACH-JOURNAL-RESILIENT]\n*1825|            Backing::Loopback => self.bounded_block_on(async move {\n 1826|                // One duplex carries BOTH directions: operator writes reach the\n 1827|                // peer's read pump and vice-versa. Split each end into a read +\n 1828|                // write half so each row owns exactly its leg.\n...\n 1838|                    &remote_id_hex,\n*1839|                    SendHalf::Loopback(peer_w),\n*1840|                    RecvHalf::Loopback(peer_r),\n 1841|                    false,\n 1842|                    crate::msg::StreamLifetime::Durable,\n 1843|                );\n...\n 1847|                    &remote_id_hex,\n*1848|                    SendHalf::Loopback(op_w),\n*1849|                    RecvHalf::Loopback(op_r),\n 1850|                    true,\n 1851|                    lifetime,\n 1852|                ))\n...\n 1858|    /// `apply_once` closure — same discipline as [`Self::record_dial_op`]).\n*1859|    pub fn record_stream_op(&self, minter: Minter, op_id: u64, stream_id: u64) {\n 1860|        self.stream_ops\n 1861|            .lock()\n 1862|            .unwrap()\n...\n 1866|    /// The stream a journaled open `(minter, op_id)` minted, if still held.\n*1867|    pub fn stream_op_id(&self, minter: Minter, op_id: u64) -> Option<u64> {\n 1868|        self.stream_ops\n 1869|            .lock()\n 1870|            .unwrap()\n...\n 1875|    /// A held stream's `(conn_id, remote_id_hex)`.\n*1876|    pub fn stream_conn(&self, stream_id: u64) -> Option<(u64, String)> {\n 1877|        self.shared\n 1878|            .streams\n 1879|            .lock()\n...\n 1887|    // [impl->REQ-DAEMON-2]\n*1888|    pub fn send_stream(&self, stream_id: u64, bytes: &[u8], finish: bool) -> io::Result<()> {\n 1889|        let entry = {\n 1890|            let streams = self.shared.streams.lock().unwrap();\n 1891|            Arc::clone(streams.get(&stream_id).ok_or_else(|| {\n...\n 1909|        // Bounded (REQ-HAZARD-BROKER-QUIC-DEADLINE): `write_all` / `finish` on a\n*1910|        // black-holed QUIC stream blocks on flow-control the dead peer never grants.\n*1911|        // Loopback (in-process) never hangs, so the bound is a no-op for it.\n*1912|        self.bounded_block_on(async move {\n 1913|            let mut send = entry.send.lock().await;\n 1914|            if !bytes.is_empty() {\n 1915|                send.write_all(&bytes).await?;\n...\n 1926|    // [impl->REQ-STREAMLOG-SUBSCRIBER-DISCIPLINE]\n*1927|    pub fn stream_lease(&self, stream_id: u64) -> Option<Arc<StreamLease>> {\n 1928|        let streams = self.shared.streams.lock().unwrap();\n 1929|        streams\n 1930|            .get(&stream_id)\n...\n 1937|    /// enumeration is exactly what a future dispatcher generation would replay.\n*1938|    pub fn stream_infos(&self) -> Vec<NetStreamInfo> {\n 1939|        self.stream_infos_filtered(true)\n 1940|    }\n 1941|\n...\n 1948|    /// client-side guard (double-filter harmless, N-1 compatible both ways).\n*1949|    /// In-process introspection (tests, the loopback-pair diff) keeps the\n 1950|    /// unfiltered [`Self::stream_infos`].\n 1951|    // [impl->REQ-STREAM-INFOS-SERVER-FILTER]\n*1952|    pub fn dispatch_stream_infos(&self) -> Vec<NetStreamInfo> {\n 1953|        self.stream_infos_filtered(false)\n 1954|    }\n 1955|\n*1956|    fn stream_infos_filtered(&self, include_local: bool) -> Vec<NetStreamInfo> {\n 1957|        let streams = self.shared.streams.lock().unwrap();\n 1958|        streams\n 1959|            .iter()\n...\n 1983|    // [impl->REQ-SEAT-LIFETIME-BOUNDED]\n*1984|    pub fn stream_counts(&self) -> (u64, u64) {\n 1985|        let streams = self.shared.streams.lock().unwrap();\n 1986|        let rows = streams.len() as u64;\n 1987|        let seats = streams\n...\n 2004|    // [impl->REQ-REDISPATCH-FINISHED-RETIRE]\n*2005|    pub fn retire_stream(&self, stream_id: u64) -> bool {\n 2006|        let Some(entry) = self\n 2007|            .shared\n 2008|            .streams\n...\n 2052|    // [impl->REQ-SEAT-LIFETIME-BOUNDED]\n*2053|    pub fn retire_stream_terminal(&self, stream_id: u64) -> bool {\n 2054|        let Some(entry) = self.shared.streams.lock().unwrap().remove(&stream_id) else {\n 2055|            return false;\n 2056|        };\n...\n 2075|    // [impl->REQ-STREAM-OPENER-DURABLE]\n*2076|    pub fn stream_opener(&self, stream_id: u64) -> Option<Option<Vec<u8>>> {\n 2077|        let entry = Arc::clone(self.shared.streams.lock().unwrap().get(&stream_id)?);\n 2078|        // A retired row answers no-such-stream: classification exists only to\n 2079|        // serve, and a retired exchange must never be served again.\n...\n 2086|\n*2087|    /// Mark a held stream **retentive** with backpressure `cap` chunks (M11-W3,\n 2088|    /// REQ-SHELL-4): its read log stops evicting (no byte loss) and its read pump\n 2089|    /// lags the sender once the undrained ring reaches `cap` (no unbounded growth).\n 2090|    /// Used for shell-tunnel streams; ordinary streams stay bounded-overwrite.\n...\n 2092|    // [impl->REQ-SHELL-4]\n*2093|    pub fn mark_stream_retentive(&self, stream_id: u64, cap: usize) {\n 2094|        if let Some(e) = self.shared.streams.lock().unwrap().get(&stream_id) {\n 2095|            e.log.lock().unwrap().set_retentive(cap);\n 2096|        }\n...\n 2100|    /// pops the whole ring in order, concatenated, and wakes the read pump (which\n*2101|    /// may have been lagging the sender at the backpressure cap). Returns\n 2102|    /// `(bytes, finished)`; `finished` ⇒ the read side ended (the poller closes).\n 2103|    /// `None` ⇒ no such stream. Empty bytes + `finished == false` ⇒ nothing pending.\n 2104|    // [impl->REQ-SHELL-4]\n*2105|    pub fn drain_stream(&self, stream_id: u64) -> Option<(Vec<u8>, bool)> {\n 2106|        let entry = Arc::clone(self.shared.streams.lock().unwrap().get(&stream_id)?);\n 2107|        let drained = entry.log.lock().unwrap().drain();\n*2108|        // The drain freed ring room — wake a pump that was backpressure-parked.\n 2109|        entry.room.notify_one();\n 2110|        Some(drained)\n 2111|    }\n...\n 2113|    /// A held stream's current undrained ring depth in chunks (test introspection\n*2114|    /// for the retentive backpressure bound). `None` ⇒ no such stream.\n 2115|    #[cfg(test)]\n*2116|    fn ring_len(&self, stream_id: u64) -> Option<usize> {\n 2117|        self.shared\n 2118|            .streams\n 2119|            .lock()\n...\n 2125|    /// Inbound (peer-initiated) stream rows currently held on `conn_id` — the\n*2126|    /// candidate set [`Self::open_loopback_pair`] diffs to find the peer it just\n 2127|    /// minted.\n 2128|    fn inbound_rows_on(&self, conn_id: u64) -> HashSet<u64> {\n 2129|        self.shared\n...\n 2138|\n*2139|    /// Open a same-node loopback tunnel stream PAIR (M11-W3, REQ-SHELL-4) and\n 2140|    /// return `(owner_stream, shell_stream)` — the operator row the owner side\n*2141|    /// drives and the cross-wired peer row the shell side drives. The loopback\n 2142|    /// `open_stream` mints both rows in-process (one `duplex` wires them, so a\n 2143|    /// write to either send appears on the other's read log). Serialized so the\n 2144|    /// before/after diff sees exactly the one peer row this open minted.\n 2145|    // [impl->REQ-SHELL-4]\n*2146|    pub fn open_loopback_pair(&self) -> io::Result<(u64, u64)> {\n*2147|        let _guard = self.loopback_pair_lock.lock().unwrap();\n*2148|        let (conn_id, _) = self.dial_loopback();\n 2149|        let before = self.inbound_rows_on(conn_id);\n 2150|        let owner_stream = self.open_stream(conn_id, crate::msg::StreamLifetime::Durable)?;\n 2151|        let shell_stream = self\n...\n 2155|            .next()\n*2156|            .ok_or_else(|| io::Error::other(\"loopback peer row not registered\"))?;\n 2157|        Ok((owner_stream, shell_stream))\n 2158|    }\n 2159|\n...\n 2162|    // [impl->REQ-DAEMON-2]\n*2163|    pub(crate) fn subscribe_stream(\n 2164|        &self,\n 2165|        stream_id: u64,\n*2166|        sub: SharedSend,\n 2167|        from_seq: u64,\n 2168|    ) -> io::Result<()> {\n 2169|        let log = {\n...\n 2199|    // [impl->REQ-SEAT-LIFETIME-BOUNDED]\n*2200|    pub(crate) fn unsubscribe_stream(&self, stream_id: u64, sub: &SharedSend) -> bool {\n 2201|        let log = {\n 2202|            let streams = self.shared.streams.lock().unwrap();\n 2203|            streams.get(&stream_id).map(|e| Arc::clone(&e.log))\n...\n 2220|    /// disconnect cleanup; the stream + its ring persist).\n*2221|    pub(crate) fn detach_stream_sub(&self, stream_id: u64, sub: &SharedSend) {\n 2222|        let log = {\n 2223|            let streams = self.shared.streams.lock().unwrap();\n 2224|            streams.get(&stream_id).map(|e| Arc::clone(&e.log))\n...\n 2233|    // [impl->REQ-EP-4]\n*2234|    pub(crate) fn subscribe_presence(&self, sub: SharedSend, from_seq: u64) {\n 2235|        // Same atomic install-with-replay discipline as subscribe_stream\n 2236|        // (the PresenceLog mirror): the seat's writer drains the replay\n 2237|        // before any live event, conn I/O outside the mutex. A replay write\n...\n 2250|    /// disconnect cleanup; the log + its ring persist).\n*2251|    pub(crate) fn detach_presence_sub(&self, sub: &SharedSend) {\n 2252|        self.shared.presence.lock().unwrap().detach_if(sub);\n 2253|    }\n 2254|\n...\n 2259|        let endpoint = Arc::clone(&self.endpoint);\n*2260|        self.runtime.handle().block_on(async move {\n 2261|            endpoint.close().await;\n 2262|        });\n 2263|    }\n...\n 2272|    /// closes), forcing the peer onto its QUIC idle timeout. That is the\n*2273|    /// sleeping-laptop / QUIC-stack-dead netsplit the transport-death rig\n 2274|    /// needs, and it stages it with no elevation, no firewall and no FFI.\n 2275|    ///\n 2276|    /// [`Self::start`] builds the runtime with `worker_threads(2)`, which is\n...\n 2344|            discovery: LocalDiscovery::Off,\n*2345|            scope: BindScope::Loopback,\n 2346|            membership: None,\n 2347|        }\n 2348|    }\n...\n 2418|    // [unit->REQ-DAEMON-2] a broker-owned host dials a second in-process host\n*2419|    // over hermetic loopback QUIC; both sides register the connection — the\n 2420|    // dialer in its table, the acceptor via its accept loop.\n 2421|    #[test]\n*2422|    fn two_hosts_dial_over_loopback() {\n 2423|        let a = NetHost::start(hermetic(&Identity::generate())).expect(\"host a\");\n 2424|        let b_id = Identity::generate();\n 2425|        let b = NetHost::start(hermetic(&b_id)).expect(\"host b\");\n...\n 2450|\n*2451|    // [unit->REQ-RC-1] the broker loopback conn (M12 W1.5, B1): `dial_loopback`\n 2452|    // mints a REUSED singleton whose origin is this node's OWN id, and\n 2453|    // `open_stream` on it cross-wires a PAIR in-process — an operator row and a\n 2454|    // peer row (the one the dispatcher serves) — with the operator's writes\n...\n 2456|    #[test]\n*2457|    fn loopback_conn_is_a_reused_singleton_that_cross_wires_a_stream_pair() {\n 2458|        let id = Identity::generate();\n 2459|        let host = NetHost::start(hermetic(&id)).expect(\"host start\");\n 2460|\n 2461|        // Singleton: reused, own-node origin (never a foreign/handshake id).\n*2462|        let (c1, hex1) = host.dial_loopback();\n*2463|        let (c2, hex2) = host.dial_loopback();\n*2464|        assert_eq!(c1, c2, \"the loopback conn is a reused singleton\");\n 2465|        assert_eq!(\n 2466|            hex1,\n 2467|            id.public_key().to_hex(),\n*2468|            \"loopback origin is THIS node's own id (broker-minted)\"\n 2469|        );\n 2470|        assert_eq!(hex2, hex1);\n*2471|        assert_eq!(host.conn_count(), 1, \"one loopback conn held\");\n 2472|\n 2473|        // open_stream mints the cross-wired pair: operator row + peer row.\n*2474|        let op_stream = host.open_stream(c1, crate::msg::StreamLifetime::Durable).expect(\"open loopback stream\");\n 2475|        let infos = host.stream_infos();\n 2476|        assert_eq!(infos.len(), 2, \"operator + peer rows\");\n 2477|        let op = infos\n...\n 2493|        // pump (its log advances) — entirely in-process, no QUIC.\n*2494|        host.send_stream(op_stream, b\"ping\", false)\n 2495|            .expect(\"write operator side\");\n 2496|        let peer_id = peer.stream_id;\n 2497|        let mut crossed = false;\n...\n 2522|        let host = NetHost::start(hermetic(&Identity::generate())).expect(\"host\");\n*2523|        let (conn, _) = host.dial_loopback();\n 2524|\n 2525|        let cb_stream = host\n 2526|            .open_stream(conn, crate::msg::StreamLifetime::ConnectionBound)\n...\n 2590|\n*2591|    // [unit->REQ-SHELL-4] the loopback tunnel pair under BACKPRESSURE (M11-W3,\n 2592|    // doyle gate condition): a retentive shell-side stream that is not drained while\n 2593|    // the owner keeps writing must NOT lose bytes AND must NOT grow unbounded — the\n 2594|    // read pump lags the sender at the cap. After the reader catches up, every byte\n...\n 2596|    #[test]\n*2597|    fn loopback_tunnel_backpressures_without_loss() {\n 2598|        use std::sync::atomic::{AtomicUsize, Ordering as AtOrd};\n 2599|        let id = Identity::generate();\n 2600|        let host = Arc::new(NetHost::start(hermetic(&id)).expect(\"host start\"));\n*2601|        let (owner, shell) = host.open_loopback_pair().expect(\"open tunnel pair\");\n 2602|        const CAP: usize = 4;\n 2603|        host.mark_stream_retentive(owner, CAP);\n 2604|        host.mark_stream_retentive(shell, CAP);\n...\n 2617|                for f in &frames {\n*2618|                    host.send_stream(owner, f, false).expect(\"send\");\n 2619|                    sent.fetch_add(1, AtOrd::Relaxed);\n 2620|                }\n*2621|                host.send_stream(owner, &[], true).expect(\"finish\");\n 2622|            })\n 2623|        };\n 2624|\n*2625|        // Let the pump fill the shell ring to the cap and PARK (backpressure).\n 2626|        let mut peak = 0usize;\n 2627|        for _ in 0..200 {\n 2628|            if let Some(d) = host.ring_len(shell) {\n...\n 2632|            if sent.load(AtOrd::Relaxed) >= N {\n*2633|                break; // (shouldn't reach N while we never drain — backpressure)\n 2634|            }\n 2635|        }\n 2636|        assert!(peak > 0, \"the pump delivered some frames to the shell ring\");\n...\n 2638|            host.ring_len(shell).unwrap() <= CAP,\n*2639|            \"the retentive ring never exceeds the backpressure cap (bounded)\"\n 2640|        );\n 2641|        assert!(\n 2642|            sent.load(AtOrd::Relaxed) < N,\n*2643|            \"the un-drained consumer lags the sender (backpressure engaged, not all sent)\"\n 2644|        );\n 2645|\n 2646|        // Now drain to completion — the sender unblocks, every byte arrives in order.\n...\n 2662|        assert_eq!(got.len(), expected.len(), \"no byte lost or duplicated\");\n*2663|        assert_eq!(got, expected, \"byte-exact, in order, under backpressure\");\n 2664|    }\n 2665|\n 2666|    // [unit->REQ-HAZARD-BROKER-QUIC-DEADLINE] the broker-side QUIC-op bound (the\n*2667|    // B-half of REQ-HAZARD-PUMP-IPC-DEADLINE): `bounded_block_on` returns a PROMPT,\n 2668|    // ORDINARY (non-`TimedOut`) error on a never-completing op — so the broker can\n 2669|    // REPLY an error frame instead of leaving the single-threaded pump wedged on a\n 2670|    // dead peer — while a ready op passes through untouched (the happy path is\n...\n 2672|    #[test]\n*2673|    fn bounded_block_on_cuts_a_never_completing_op_with_an_ordinary_error() {\n 2674|        let host = NetHost::start(hermetic(&Identity::generate())).expect(\"host start\");\n 2675|        host.set_quic_op_timeout(Duration::from_millis(150));\n 2676|\n*2677|        // A never-completing await (the black-holed-peer shape) fails at the bound.\n 2678|        let started = std::time::Instant::now();\n 2679|        let err = host\n*2680|            .bounded_block_on(std::future::pending::<io::Result<()>>())\n 2681|            .expect_err(\"a never-completing op must error, never block forever\");\n 2682|        let elapsed = started.elapsed();\n 2683|        assert_ne!(\n...\n 2699|        let v: u64 = host\n*2700|            .bounded_block_on(async { Ok(7u64) })\n 2701|            .expect(\"a ready op passes through\");\n 2702|        assert_eq!(v, 7, \"the bound is transparent to a completing op\");\n 2703|    }\n...\n 2734|    #[test]\n*2735|    fn opener_capture_gives_up_bounded_on_a_newline_less_stream() {\n 2736|        let mut log = StreamLog::new(8, 4);\n 2737|        log.append(&vec![b'x'; OPENER_PIN_MAX + 1]);\n 2738|        assert_eq!(log.opener_line(), None, \"over the cap without a newline: gave up\");\n...\n 2752|        let host = NetHost::start(hermetic(&Identity::generate())).expect(\"host start\");\n*2753|        let (owner, shell) = host.open_loopback_pair().expect(\"open pair\");\n*2754|        host.send_stream(owner, b\"{\\\"kind\\\":\\\"request\\\",\\\"session_id\\\":1}\\n\", false)\n 2755|            .expect(\"send opener\");\n 2756|        // The pump is async — wait for the shell row to hold the opener.\n 2757|        let mut pinned = None;\n...\n 2785|    // worker's reply send is fire-and-forget (brain returns before the broker\n*2786|    // processes the envelope), so the acked retire on its own conn can be\n 2787|    // processed FIRST. Pre-fix, retire removed the entry: the late send hit\n 2788|    // no-such-stream (or the drop reset the never-finished send half) and the\n 2789|    // requester got torn-EOF instead of its reply (wansend NoReply, CI red\n...\n 2793|        let host = NetHost::start(hermetic(&Identity::generate())).expect(\"host start\");\n*2794|        let (owner, shell) = host.open_loopback_pair().expect(\"open pair\");\n 2795|        // The requester's one-shot request: write + FIN (the rest/sync shape —\n 2796|        // the row is born finished on the serving side).\n*2797|        host.send_stream(\n 2798|            owner,\n 2799|            b\"{\\\"kind\\\":\\\"request\\\",\\\"endpoint\\\":\\\"e\\\",\\\"event\\\":\\\"suspend\\\"}\\n\",\n 2800|            true,\n...\n 2807|        // The worker's reply lands AFTER retirement and must still deliver.\n*2808|        host.send_stream(shell, b\"{\\\"kind\\\":\\\"reply\\\",\\\"outcome\\\":\\\"edge\\\"}\\n\", true)\n 2809|            .expect(\"a retired row still accepts the in-flight reply\");\n 2810|        let mut got = Vec::new();\n 2811|        let mut finished = false;\n...\n 2832|    #[test]\n*2833|    fn conn_close_sweeps_its_stream_rows() {\n 2834|        let a = NetHost::start(hermetic(&Identity::generate())).expect(\"host a\");\n 2835|        let b = NetHost::start(hermetic(&Identity::generate())).expect(\"host b\");\n 2836|        let (conn_id, _) = a.dial(b.addr()).expect(\"dial\");\n 2837|        let sid = a.open_stream(conn_id, crate::msg::StreamLifetime::Durable).expect(\"open stream\");\n*2838|        a.send_stream(sid, b\"{\\\"hello\\\":1}\\n\", false).expect(\"send\");\n 2839|        // B's acceptor registers the peer row (async — poll).\n 2840|        let mut saw = false;\n 2841|        for _ in 0..400 {\n...\n 2869|    /// A connected local-socket pair whose SERVER send half wraps as the\n*2870|    /// `SharedSend` a subscriber seat writes through — `controller_socket_pair`'s\n 2871|    /// idiom (broker.rs) with a caller-chosen write bound.\n 2872|    fn seat_socket_pair(\n 2873|        bound: Duration,\n 2874|    ) -> (\n*2875|        SharedSend,\n 2876|        interprocess::local_socket::Stream,\n 2877|        interprocess::local_socket::RecvHalf,\n 2878|    ) {\n...\n 3153|        // ...and the SUCCESSOR's lease stays live — its serve leg keeps\n*3154|        // forwarding (send_stream reads this current Arc).\n 3155|        assert!(\n 3156|            !lease_b.is_canceled(),\n 3157|            \"the displaced writer's death must never cancel the successor's lease\"\n...\n 3202|    // seam (Amendment fix 4): a canceled lease makes every later\n*3203|    // `send_stream` refuse with the \"lease canceled\" answer (the SeatBlocked\n 3204|    // classification string) — the paired serve/wire worker discovers the\n 3205|    // cancellation at its next forward and terminates, never feeding an\n 3206|    // orphan leg forever.\n 3207|    #[test]\n*3208|    fn send_stream_refuses_on_a_canceled_lease() {\n 3209|        let host = NetHost::start(hermetic(&Identity::generate())).expect(\"host start\");\n*3210|        let (owner, _shell) = host.open_loopback_pair().expect(\"open pair\");\n 3211|        let lease = host.stream_lease(owner).expect(\"lease handle\");\n 3212|        assert!(!lease.is_canceled());\n*3213|        host.send_stream(owner, b\"ok\", false).expect(\"a live lease serves\");\n 3214|\n 3215|        lease.cancel();\n 3216|        let err = host\n*3217|            .send_stream(owner, b\"nope\", false)\n 3218|            .expect_err(\"a canceled lease refuses the forward\");\n 3219|        assert!(err.to_string().contains(\"lease canceled\"), \"{err}\");\n 3220|    }\n...\n 3229|    #[test]\n*3230|    fn dispatch_stream_infos_excludes_local_and_retired_rows_server_side() {\n 3231|        let host = NetHost::start(hermetic(&Identity::generate())).expect(\"host start\");\n*3232|        let (owner, shell) = host.open_loopback_pair().expect(\"open pair\");\n*3233|        host.send_stream(owner, b\"{\\\"subnet\\\":\\\"s\\\",\\\"instance\\\":{}}\\n\", false)\n 3234|            .expect(\"bytes onto the peer row\");\n 3235|\n 3236|        // Full introspection: both rows. Dispatch view: the peer row only.\n...\n 3269|        let host = NetHost::start(hermetic(&Identity::generate())).expect(\"host start\");\n*3270|        let (owner, shell) = host.open_loopback_pair().expect(\"open pair\");\n 3271|        let _ = shell;\n 3272|\n 3273|        let (a, _ca, _ra) = seat_socket_pair(Duration::from_secs(5));\n...\n 3315|        // the retired_row_still_flushes_a_late_reply contract above).\n*3316|        let (owner, shell) = host.open_loopback_pair().expect(\"pair 1\");\n 3317|        let (sub, _c, _r) = seat_socket_pair(Duration::from_secs(5));\n 3318|        host.subscribe_stream(shell, Arc::clone(&sub), 0).expect(\"subscribe\");\n 3319|        let (rows_before, seats_before) = host.stream_counts();"}],"details":{"scopePath":"crates/spt-daemon/src/nethost.rs","searchPath":"C:\\Users\\decid\\Documents\\projects\\spt-core\\crates\\spt-daemon\\src\\nethost.rs","cwd":"C:\\Users\\decid\\Documents\\projects\\spt-core","matchCount":194,"fileCount":1,"files":["crates/spt-daemon/src/nethost.rs"],"fileMatches":[{"path":"crates/spt-daemon/src/nethost.rs","count":194}],"truncated":false,"displayContent":"   16│//! (`spt-broker-net`): QUIC objects live in structures only the runtime's tasks\n  *17│//! and the host's own `block_on` bridges touch, and the runtime drops with the\n   18│//! host (broker teardown stops all net tasks). Spike #3's broker binary proved\n   19│//! exactly this shape — a broker-owned endpoint surviving brain kill/restart.\n   20│//!\n     │...\n   43│\n  *44│use crate::broker::SharedSend;\n   45│\n   46│use crate::effect::Minter;\n   47│use crate::seedproofx::{prove_membership, MembershipSource, RosterExchange};\n     │...\n   59│/// Broker-side QUIC-op deadline (REQ-HAZARD-BROKER-QUIC-DEADLINE), in ms. Each\n  *60│/// brain-waiting QUIC await — `dial` / `open_stream` / `send_stream` — is bounded\n  *61│/// by this so a black-holed or dead peer fails PROMPTLY with an ORDINARY error\n   62│/// the broker replies, never an unbounded await that wedges the single-threaded\n   63│/// pump (the B-half of REQ-HAZARD-PUMP-IPC-DEADLINE; the 2.2h hfenduleam wedge).\n   64│/// Chosen at **10s**: comfortably above any legitimate LAN/relay connect +\n     │...\n   71│/// frame's IPC transit + the brain's read scheduling. Test-overridable via\n  *72│/// [`NetHost::set_quic_op_timeout`] so the hermetic black-hole tests fail fast.\n   73│const BROKER_QUIC_OP_TIMEOUT_MS: u64 = 10_000;\n   74│\n   75│/// Bounded concurrent-dial cap (PUMP-TRUTH W2, REQ-PUMP-PEER-ISOLATION, G4): a\n     │...\n   95│    /// Socket bind scope: [`BindScope::All`] in production;\n  *96│    /// [`BindScope::Loopback`] in hermetic tests (no real interface touched,\n   97│    /// no per-test-binary Windows firewall prompt).\n   98│    pub scope: BindScope,\n   99│    /// Live source of this node's subnet credentials for the connect-time\n     │...\n  143│/// fixes 2+3, REQ-STREAMLOG-SUBSCRIBER-DISCIPLINE): frames ENQUEUE under the\n *144│/// log mutex; the conn I/O — the deadline-bounded `SharedSend::write` that can\n  145│/// take 15s against a wedged conn — runs on this seat's OWN writer thread,\n  146│/// OUTSIDE every lock. The field stall was exactly the old shape's serial\n  147│/// replay-under-mutex against a poisoned conn (33 windows, all ~15s).\n     │...\n  154│struct SubscriberSeat {\n *155│    sub: SharedSend,\n  156│    tx: std::sync::mpsc::SyncSender<Envelope>,\n  157│    /// Writer thread exited (failure or clean drain) — the seat is fully gone\n  158│    /// and a replacement may install (the no-reinstall-until-gone rule,\n     │...\n  169│impl SubscriberSeat {\n *170│    /// Install a seat: spawn its writer thread and hand back the handle.\n  171│    /// `replay` is the attach snapshot, moved in UNDER the log mutex (a\n  172│    /// memory move, never conn I/O): the writer drains it COMPLETELY before\n  173│    /// touching the live queue, so replay-then-live seq order holds by\n     │...\n  189│    fn install(\n *190│        sub: SharedSend,\n  191│        replay: Vec<Envelope>,\n  192│        lease: Option<Arc<StreamLease>>,\n  193│        label: &str,\n     │...\n  224│                // Then live frames, same halt discipline.\n *225│                while let Ok(frame) = rx.recv() {\n  226│                    if writer_sub.write(&frame).is_err() {\n  227│                        poison(\"live write failed\");\n  228│                        break;\n     │...\n  270│    /// Whether this seat belongs to `sub` (detach correlation).\n *271│    fn is(&self, sub: &SharedSend) -> bool {\n  272│        Arc::ptr_eq(&self.sub, sub)\n  273│    }\n  274│\n     │...\n  283│/// mechanism): canceled when the stream's subscriber seat POISONS, which\n *284│/// makes every later `send_stream` on the stream refuse — the paired\n  285│/// serve/wire worker discovers the cancellation at its next forward and\n  286│/// terminates instead of feeding an orphan leg forever.\n  287│// [impl->REQ-STREAMLOG-SUBSCRIBER-DISCIPLINE]\n     │...\n  319│\n *320│/// Transport backing a held connection. A real `Quic` connection (the only\n *321│/// kind an inbound handshake can produce), or a broker-minted `Loopback` —\n  322│/// an in-process connection with NO iroh handshake whose identity IS this node,\n *323│/// established BY CONSTRUCTION. A loopback conn can ONLY be minted broker-side\n *324│/// via [`NetHost::dial_loopback`]; it can never arise from an inbound handshake\n  325│/// (a remote always presents its own key and cannot claim to be us). This is\n  326│/// what lets a LOCAL `spt rc` ride the byte-identical `serve_attach` pump (M12\n  327│/// W1.5, B1) — QUIC self-dial is refused by iroh (\"Connecting to ourself is not\n *328│/// supported\"), so local attach rides a broker loopback conn instead.\n  329│enum ConnKind {\n  330│    /// A real QUIC connection — kept alive by ownership here; dropping it closes\n  331│    /// the connection. Cloned (cheap handle) for stream opens.\n  332│    Quic(Connection),\n *333│    /// A broker-minted in-process loopback (no iroh handle, no handshake). Its\n  334│    /// streams are minted eagerly in cross-wired pairs by [`NetHost::open_stream`];\n  335│    /// there is no accept loop and no closed-watcher (it lives for the host).\n *336│    Loopback,\n  337│}\n  338│\n *339│/// One live connection the broker holds (QUIC or loopback).\n  340│struct ConnEntry {\n *341│    /// The transport backing this connection.\n  342│    kind: ConnKind,\n  343│    /// The remote node's stable name (hex pubkey). For QUIC, proven by the\n *344│    /// handshake; for loopback, THIS node's own id (the broker-minted identity).\n  345│    remote_id_hex: String,\n  346│    /// The subnets the peer proved current-epoch seed-knowledge of at connect\n  347│    /// (Mesh-D2, REQ-MESH-1). Empty when seed-proof is disabled (`membership:\n     │...\n  383│    finished: bool,\n *384│    /// **Retentive backpressure cap** (M11-W3, REQ-SHELL-4), in chunks; `0` ⇒ not\n  385│    /// retentive (ordinary bounded-overwrite stream). A shell-tunnel stream must\n  386│    /// NOT drop bytes — CONTEXT:262 \"tunneled protocols cannot drop frames, so\n  387│    /// congestion surfaces as lag, never loss.\" So a retentive log never cap-evicts\n     │...\n  401│impl StreamLog {\n *402│    fn new(stream_id: u64, cap_chunks: usize) -> Self {\n  403│        StreamLog {\n  404│            stream_id,\n  405│            next_seq: 0,\n     │...\n  431│\n *432│    /// Mark this log retentive with backpressure `cap` (chunks). Idempotent set.\n  433│    fn set_retentive(&mut self, cap: usize) {\n  434│        self.retentive_cap = cap;\n  435│    }\n     │...\n  466│        self.next_seq += 1;\n *467│        self.ring.push_back((seq, bytes.to_vec()));\n  468│        if self.retentive_cap == 0 {\n  469│            while self.ring.len() > self.cap_chunks {\n  470│                self.ring.pop_front();\n     │...\n  502│    /// Drain every undrained chunk in order (the shell-tunnel recv cursor, W3).\n *503│    /// Pops the whole ring front-to-back (FIFO by `seq`) and concatenates the\n  504│    /// bytes — chunk boundaries are arbitrary read-pump splits, irrelevant to an\n  505│    /// opaque byte stream. Lossless + ordered: a byte leaves the ring only here,\n  506│    /// once. Returns `(bytes, finished)`; `finished` reflects a clean/torn end so\n     │...\n  544│    // [impl->REQ-STREAMLOG-SUBSCRIBER-DISCIPLINE]\n *545│    fn begin_attach(&mut self, sub: SharedSend, from_seq: u64) -> io::Result<usize> {\n  546│        if let Some(prior) = &self.subscriber {\n  547│            // No-reinstall-until-gone applies to the POISON class only\n  548│            // (REQ-DISPATCH-FALLBACK-CIRCUIT): a wedged writer may sit in a\n     │...\n  590│        // One poison never dead-ends the stream (T5 recovery): the next\n *591│        // generation's mint IS the renewal; `send_stream` reads this current\n  592│        // Arc, old workers' handles stay theirs (C2 consumes via\n  593│        // [`NetHost::stream_lease`]).\n  594│        // [impl->REQ-STREAMLOG-SUBSCRIBER-DISCIPLINE]\n     │...\n  610│    // [impl->REQ-SEAT-LIFETIME-BOUNDED]\n *611│    fn take_seat_if(&mut self, sub: &SharedSend) -> Option<SubscriberSeat> {\n  612│        if self.subscriber.as_ref().is_some_and(|cur| cur.is(sub)) {\n  613│            self.subscriber.take()\n  614│        } else {\n     │...\n  620│    /// not unsubscribe a newer brain).\n *621│    fn detach_if(&mut self, sub: &SharedSend) {\n  622│        if let Some(cur) = &self.subscriber {\n  623│            if cur.is(sub) {\n  624│                self.subscriber = None;\n     │...\n  672│    /// A `connected` event carrying the connection's OBSERVED remote address\n *673│    /// (REQ-CONV-1): the async-dial write-back seed the blocking `net-dialed`\n  674│    /// reply used to carry — now it rides the presence stream so the pump seeds\n  675│    /// `peer-addrs.json` from a non-blocking dial the same way.\n  676│    // [impl->REQ-CONV-1]\n     │...\n  720│        self.next_seq += 1;\n *721│        self.ring.push_back(ev.clone());\n  722│        while self.ring.len() > self.cap_events {\n  723│            self.ring.pop_front();\n  724│        }\n     │...\n  744│    // [impl->REQ-STREAMLOG-SUBSCRIBER-DISCIPLINE]\n *745│    fn begin_attach(&mut self, sub: SharedSend, from_seq: u64) -> io::Result<usize> {\n  746│        if let Some(prior) = &self.subscriber {\n  747│            // Poison-class only (see StreamLog::begin_attach): a healthy\n  748│            // prior presence subscriber is displaced by the newer brain.\n     │...\n  775│    /// not unsubscribe a newer brain).\n *776│    fn detach_if(&mut self, sub: &SharedSend) {\n  777│        if let Some(cur) = &self.subscriber {\n  778│            if cur.is(sub) {\n  779│                self.subscriber = None;\n     │...\n  788│/// write end of an in-process duplex). That is the M12 W1.5 one-pump invariant\n *789│/// made structural: a loopback attach and a cross-node attach diverge at this\n  790│/// leaf and nowhere above it.\n  791│enum SendHalf {\n  792│    Quic(SendStream),\n *793│    Loopback(WriteHalf<DuplexStream>),\n  794│}\n  795│\n  796│impl SendHalf {\n     │...\n  803│                .map_err(|e| io::Error::other(e.to_string())),\n *804│            SendHalf::Loopback(w) => w.write_all(bytes).await,\n  805│        }\n  806│    }\n  807│\n     │...\n  812│            SendHalf::Quic(s) => s.finish().map_err(|e| io::Error::other(e.to_string())),\n *813│            SendHalf::Loopback(w) => w.shutdown().await,\n  814│        }\n  815│    }\n  816│}\n     │...\n  818│/// A stream's read half — fed into the single read pump in [`register_stream`].\n *819│/// QUIC reads via quinn's chunk API; loopback via the read end of the duplex.\n  820│/// Both append to the same [`StreamLog`], so the subscriber (and everything\n  821│/// above it) cannot tell the transports apart.\n  822│enum RecvHalf {\n  823│    Quic(RecvStream),\n *824│    Loopback(ReadHalf<DuplexStream>),\n  825│}\n  826│\n *827│/// One live stream the broker holds (QUIC or loopback): the send half (brain\n  828│/// writes ride it over IPC) + the sequenced read log.\n  829│struct StreamEntry {\n  830│    conn_id: u64,\n     │...\n  838│    /// The send half, serialized behind an async mutex (writes happen on the\n *839│    /// host's runtime via `block_on`).\n  840│    send: tokio::sync::Mutex<SendHalf>,\n  841│    log: Arc<Mutex<StreamLog>>,\n  842│    /// Wakes the read pump when a retentive (tunnel) stream's ring drains below\n *843│    /// its backpressure cap (M11-W3, REQ-SHELL-4) — see [`StreamLog::retentive_cap`].\n  844│    /// Unused by ordinary (non-retentive) streams.\n  845│    room: Arc<tokio::sync::Notify>,\n  846│    /// Retired = invisible to dispatch eligibility (ADR-0038 A), NOT torn down:\n     │...\n  901│/// acceptor. Must run inside the host's runtime context (the accept loop, or a\n *902│/// `block_on` future) — it spawns tasks.\n  903│/// The connection's OBSERVED remote address as opaque seed JSON (REQ-CONV-1):\n  904│/// the path address string, or `null` when id-only / path-less (nothing worth\n *905│/// seeding over discovery). Shared by [`register_conn`]'s presence write-back\n  906│/// and [`NetHost::conn_remote_addr_json`] so both seed identically.\n  907│// [impl->REQ-CONV-1]\n  908│fn observed_addr_json(conn: &Connection) -> serde_json::Value {\n     │...\n  969│    /// the observed addr). The caller bounds this await (the blocking dial via\n *970│    /// `bounded_block_on`; the submit via its own `timeout`). `stage` names the\n  971│    /// pipeline stage the dial is in (ADR-0039 Decision 5) — a stage-local\n  972│    /// error and the caller's outer timeout both read it, so the failure token\n  973│    /// says WHERE the dial died instead of collapsing six stages into one.\n     │...\n 1031│    // `connected` event can never race behind its own `disconnected` (D4c). The\n*1032│    // event carries the OBSERVED remote addr (REQ-CONV-1 seed write-back) so a\n 1033│    // non-blocking submit-dial seeds `peer-addrs.json` like the blocking reply\n 1034│    // did (id-only / path-less → `null`, nothing worth seeding).\n 1035│    let observed = observed_addr_json(&conn);\n     │...\n 1099│/// from [`NetHost::open_stream`]).\n*1100│fn register_stream(\n 1101│    shared: &Arc<NetShared>,\n 1102│    conn_id: u64,\n 1103│    remote_id_hex: &str,\n     │...\n 1128│    // replayable either way. The transport differs only at this read leaf\n*1129│    // (QUIC chunk API vs the loopback duplex's `AsyncRead`); both append to the\n 1130│    // same `StreamLog`, so nothing above the pump can tell them apart.\n 1131│    //\n*1132│    // Backpressure (M11-W3, REQ-SHELL-4): a retentive (tunnel) log never evicts,\n 1133│    // so before pulling the next chunk the pump WAITS while the undrained ring is\n 1134│    // at its `retentive_cap`. The unread bytes stay in the transport's buffer, so\n*1135│    // QUIC stream flow-control (or the loopback duplex's bounded buffer) lags the\n 1136│    // SENDER — \"lag, never loss\" (CONTEXT:262). A `drain` wakes `room`. Ordinary\n 1137│    // streams have `retentive_cap == 0`, so this gate is a no-op for them.\n 1138│    tokio::spawn(async move {\n     │...\n 1149│            },\n*1150│            RecvHalf::Loopback(mut recv) => {\n 1151│                let mut buf = vec![0u8; STREAM_READ_CHUNK];\n 1152│                loop {\n 1153│                    await_ring_room(&log, &room).await;\n     │...\n 1168│\n*1169│/// Backpressure gate for a retentive (tunnel) read pump: park until the undrained\n 1170│/// ring has room below `retentive_cap`, woken by a `drain` on `room`. A no-op for\n 1171│/// an ordinary stream (`retentive_cap == 0`). Holds no lock across the await.\n 1172│// [impl->REQ-SHELL-4]\n     │...\n 1213│    roster: Arc<Mutex<Option<RosterExchange>>>,\n*1214│    /// The broker's single in-process loopback connection (M12 W1.5, B1),\n*1215│    /// minted lazily on the first [`Self::dial_loopback`] and reused thereafter\n 1216│    /// — a local `spt rc` needs exactly one. `Some(conn_id)` once minted; the\n 1217│    /// row lives for the host (no handshake to lose, no closed-watcher).\n*1218│    loopback_conn: Mutex<Option<u64>>,\n*1219│    /// Serializes [`Self::open_loopback_pair`] (M11-W3) so the peer-row discovery\n*1220│    /// (a before/after diff on the loopback conn's inbound rows) sees exactly the\n*1221│    /// one row this open minted — concurrent pair-opens on the shared loopback conn\n 1222│    /// would otherwise race the diff.\n*1223│    loopback_pair_lock: Mutex<()>,\n 1224│    /// The broker-side QUIC-op deadline in ms (REQ-HAZARD-BROKER-QUIC-DEADLINE),\n*1225│    /// default [`BROKER_QUIC_OP_TIMEOUT_MS`]; the hermetic black-hole tests lower\n 1226│    /// it via [`Self::set_quic_op_timeout`]. Interior-mutable so the setter takes\n 1227│    /// `&self`, like the live host's other post-`start` knobs (`set_roster_exchange`).\n 1228│    quic_op_timeout_ms: AtomicU64,\n     │...\n 1242│    /// runtime task stamps epoch-ms here every ~25ms. If the 2 workers are\n*1243│    /// MONOPOLIZED (a non-yielding dead-peer connect that never awaits back to\n 1244│    /// the scheduler) the stamp goes STALE — the DIRECT worker-starvation\n 1245│    /// discriminator the round-3 rig asserts on. A fresh stamp under a dead-peer\n 1246│    /// burst PROVES the QUIC awaits yield cleanly (⇒ the 2-worker-starvation\n     │...\n 1280│    pub fn start(cfg: NetConfig) -> io::Result<NetHost> {\n*1281│        // Hermeticity guard (REQ-PAIR-8): a loopback-scoped endpoint is the\n 1282│        // \"no network reached\" promise — the ceremony clock's lazy NTP query\n 1283│        // must honor it (tests must never probe a real NTP server). Real\n 1284│        // scopes keep the decision-18 offset correction.\n*1285│        spt_net::net::pairing::ntp::set_enabled(!matches!(cfg.scope, BindScope::Loopback));\n 1286│        let runtime = tokio::runtime::Builder::new_multi_thread()\n 1287│            .worker_threads(2)\n 1288│            .thread_name(\"spt-broker-net\")\n     │...\n 1291│        let endpoint = runtime\n*1292│            .block_on(NetEndpoint::bind_scoped(\n 1293│                &cfg.identity,\n 1294│                cfg.relay.clone(),\n 1295│                cfg.discovery,\n     │...\n 1353│                                    &self_addr,\n*1354│                                    &DialStage::new(), // accept side: stage untracked\n 1355│                                )\n 1356│                                .await\n 1357│                                {\n     │...\n 1406│            roster,\n*1407│            loopback_conn: Mutex::new(None),\n*1408│            loopback_pair_lock: Mutex::new(()),\n 1409│            quic_op_timeout_ms: AtomicU64::new(BROKER_QUIC_OP_TIMEOUT_MS),\n 1410│            dial_semaphore: Arc::new(tokio::sync::Semaphore::new(PUMP_DIAL_CONCURRENCY)),\n 1411│            active_dial_tasks: Arc::new(AtomicUsize::new(0)),\n     │...\n 1441│    /// Production keeps the [`BROKER_QUIC_OP_TIMEOUT_MS`] default; the hermetic\n*1442│    /// black-hole tests set a short bound so a dead-peer await fails fast instead\n 1443│    /// of pinning the test for ~10s. Off [`NetConfig`] by design (mirrors\n 1444│    /// [`Self::set_roster_exchange`]) — the many hermetic test configs need no change.\n 1445│    // [impl->REQ-HAZARD-BROKER-QUIC-DEADLINE]\n     │...\n 1452│    /// (REQ-HAZARD-BROKER-QUIC-DEADLINE) — the B-half of REQ-HAZARD-PUMP-IPC-\n*1453│    /// DEADLINE. A brain-waiting QUIC await against a black-holed/dead peer must\n 1454│    /// fail PROMPTLY with an ORDINARY error the broker replies, never the\n 1455│    /// unbounded await that wedged the single-threaded pump for 2.2h. On elapse\n 1456│    /// the future is DROPPED — cancelling the in-flight connect / stream op, so\n     │...\n 1468│    // [impl->REQ-HAZARD-BROKER-QUIC-DEADLINE]\n*1469│    fn bounded_block_on<F, T>(&self, fut: F) -> io::Result<T>\n 1470│    where\n 1471│        F: std::future::Future<Output = io::Result<T>>,\n 1472│    {\n 1473│        let dur = self.quic_op_timeout();\n*1474│        self.runtime.handle().block_on(async move {\n 1475│            match tokio::time::timeout(dur, fut).await {\n 1476│                Ok(inner) => inner,\n 1477│                Err(_elapsed) => Err(io::Error::other(format!(\n     │...\n 1496│        let endpoint = Arc::clone(&self.endpoint);\n*1497│        self.runtime.handle().block_on(async move {\n 1498│            crate::pairhost::join_ceremony(&endpoint, subnet, code, responder_addr).await\n 1499│        })\n 1500│    }\n     │...\n 1512│        let endpoint = Arc::clone(&self.endpoint);\n*1513│        self.runtime.handle().block_on(async move {\n 1514│            crate::pairhost::meet_seed_holder(&endpoint, subnet, verbose).await\n 1515│        })\n 1516│    }\n     │...\n 1539│    /// tasks currently on the 2-worker net runtime. The starvation rig reads this\n*1540│    /// to correlate a dead-peer burst with loopback-drain health.\n 1541│    pub fn active_dial_tasks(&self) -> usize {\n 1542│        self.active_dial_tasks.load(Ordering::Relaxed)\n 1543│    }\n     │...\n 1567│        // Bounded (REQ-HAZARD-BROKER-QUIC-DEADLINE): the `connect` + `prove_membership`\n*1568│        // awaits are the exact unbounded sites a dead peer black-holes — wrap\n 1569│        // them so a non-responsive peer fails as an ordinary error within the bound.\n*1570│        self.bounded_block_on(async move {\n 1571│            // Q2 caveat: the blocking dial acquires a permit from the SAME\n 1572│            // semaphore as `submit_dial`, so the concurrency cap bounds every dial\n 1573│            // source (never bypassed). `acquire_owned` errs only on a closed\n     │...\n 1638│                    // Ordinary per-peer failure rides the presence stream — the pump\n*1639│                    // backs THIS peer off and moves on; the round is never poisoned.\n 1640│                    // The reason is stage-attributed (REQ-PUMP-STAGE-TRUTH).\n 1641│                    shared.presence.lock().unwrap().append_dial_failed(\n 1642│                        &remote_id_hex,\n     │...\n 1713│    /// connection's current path addresses) as opaque JSON — the address-\n*1714│    /// seeding write-back the `net-dialed` reply carries (M8 decision 20,\n 1715│    /// REQ-CONV-1). `null` when the conn is gone, path-less, or fails to\n 1716│    /// serialize: the seed is an optimization, never an error path.\n 1717│    // [impl->REQ-CONV-1]\n     │...\n 1721│            match conns.get(&conn_id) {\n*1722│                // A loopback conn has no path to observe — nothing to seed.\n 1723│                Some(e) => match &e.kind {\n 1724│                    ConnKind::Quic(c) => c.clone(),\n*1725│                    ConnKind::Loopback => return serde_json::Value::Null,\n 1726│                },\n 1727│                None => return serde_json::Value::Null,\n 1728│            }\n     │...\n 1732│\n*1733│    /// Mint (or reuse) the broker's single in-process loopback connection\n 1734│    /// (M12 W1.5, B1) and return `(conn_id, remote_id_hex)` — `remote_id_hex` is\n 1735│    /// THIS node's own id, so a stream served over it gates same-node (access\n 1736│    /// short-circuit Allow). The conn carries NO iroh handshake: its identity is\n     │...\n 1742│    // [impl->REQ-RC-1]\n*1743│    pub fn dial_loopback(&self) -> (u64, String) {\n 1744│        let remote_id_hex = self.local_id.to_hex();\n*1745│        let mut slot = self.loopback_conn.lock().unwrap();\n 1746│        if let Some(id) = *slot {\n 1747│            return (id, remote_id_hex);\n 1748│        }\n     │...\n 1752│            ConnEntry {\n*1753│                kind: ConnKind::Loopback,\n 1754│                remote_id_hex: remote_id_hex.clone(),\n 1755│                proven_subnets: HashSet::new(),\n 1756│            },\n     │...\n 1765│    ///\n*1766│    /// On a [`ConnKind::Loopback`] conn there is no peer to accept the stream,\n 1767│    /// so the open mints a CROSS-WIRED PAIR in-process: an operator row\n 1768│    /// (`initiated_locally = true`, the returned id) and a peer row\n 1769│    /// (`initiated_locally = false`) the inbound dispatcher claims and serves via\n     │...\n 1776│    // [impl->REQ-RC-1]\n*1777│    pub fn open_stream(\n 1778│        &self,\n 1779│        conn_id: u64,\n 1780│        lifetime: crate::msg::StreamLifetime,\n 1781│    ) -> io::Result<u64> {\n*1782│        enum Backing {\n 1783│            Quic(Connection),\n*1784│            Loopback,\n 1785│        }\n*1786│        let (backing, remote_id_hex) = {\n 1787│            let conns = self.shared.conns.lock().unwrap();\n 1788│            let e = conns.get(&conn_id).ok_or_else(|| {\n 1789│                io::Error::new(io::ErrorKind::NotFound, format!(\"no such conn {conn_id}\"))\n 1790│            })?;\n*1791│            let backing = match &e.kind {\n*1792│                ConnKind::Quic(c) => Backing::Quic(c.clone()),\n*1793│                ConnKind::Loopback => Backing::Loopback,\n 1794│            };\n*1795│            (backing, e.remote_id_hex.clone())\n 1796│        };\n 1797│        let shared = Arc::clone(&self.shared);\n*1798│        match backing {\n*1799│            // Bounded (REQ-HAZARD-BROKER-QUIC-DEADLINE): `open_bi` on a black-holed\n 1800│            // peer can block on stream flow-control credit the dead peer never grants.\n*1801│            Backing::Quic(conn) => self.bounded_block_on(async move {\n 1802│                let (send, recv) = conn\n 1803│                    .open_bi()\n 1804│                    .await\n     │...\n 1816│            // Bounded like the QUIC arm (REQ-BROKER-ATTACH-JOURNAL-RESILIENT, bug\n*1817│            // #16): the loopback open is all in-memory and normally returns\n 1818│            // instantly, but a SICK NetHost runtime (saturated/wedged after a\n 1819│            // self-update brain-respawn) would otherwise hang this journaled op with\n 1820│            // no deadline — killing the per-conn reply thread so every attach\n 1821│            // silently deadlines (\"brain IPC read deadline elapsed\") while\n*1822│            // non-journaled ops keep working. `bounded_block_on` turns that into a\n 1823│            // prompt ordinary error frame; the bound never bites a healthy runtime.\n 1824│            // [impl->REQ-BROKER-ATTACH-JOURNAL-RESILIENT]\n*1825│            Backing::Loopback => self.bounded_block_on(async move {\n 1826│                // One duplex carries BOTH directions: operator writes reach the\n 1827│                // peer's read pump and vice-versa. Split each end into a read +\n 1828│                // write half so each row owns exactly its leg.\n     │...\n 1838│                    &remote_id_hex,\n*1839│                    SendHalf::Loopback(peer_w),\n*1840│                    RecvHalf::Loopback(peer_r),\n 1841│                    false,\n 1842│                    crate::msg::StreamLifetime::Durable,\n 1843│                );\n     │...\n 1847│                    &remote_id_hex,\n*1848│                    SendHalf::Loopback(op_w),\n*1849│                    RecvHalf::Loopback(op_r),\n 1850│                    true,\n 1851│                    lifetime,\n 1852│                ))\n     │...\n 1858│    /// `apply_once` closure — same discipline as [`Self::record_dial_op`]).\n*1859│    pub fn record_stream_op(&self, minter: Minter, op_id: u64, stream_id: u64) {\n 1860│        self.stream_ops\n 1861│            .lock()\n 1862│            .unwrap()\n     │...\n 1866│    /// The stream a journaled open `(minter, op_id)` minted, if still held.\n*1867│    pub fn stream_op_id(&self, minter: Minter, op_id: u64) -> Option<u64> {\n 1868│        self.stream_ops\n 1869│            .lock()\n 1870│            .unwrap()\n     │...\n 1875│    /// A held stream's `(conn_id, remote_id_hex)`.\n*1876│    pub fn stream_conn(&self, stream_id: u64) -> Option<(u64, String)> {\n 1877│        self.shared\n 1878│            .streams\n 1879│            .lock()\n     │...\n 1887│    // [impl->REQ-DAEMON-2]\n*1888│    pub fn send_stream(&self, stream_id: u64, bytes: &[u8], finish: bool) -> io::Result<()> {\n 1889│        let entry = {\n 1890│            let streams = self.shared.streams.lock().unwrap();\n 1891│            Arc::clone(streams.get(&stream_id).ok_or_else(|| {\n     │...\n 1909│        // Bounded (REQ-HAZARD-BROKER-QUIC-DEADLINE): `write_all` / `finish` on a\n*1910│        // black-holed QUIC stream blocks on flow-control the dead peer never grants.\n*1911│        // Loopback (in-process) never hangs, so the bound is a no-op for it.\n*1912│        self.bounded_block_on(async move {\n 1913│            let mut send = entry.send.lock().await;\n 1914│            if !bytes.is_empty() {\n 1915│                send.write_all(&bytes).await?;\n     │...\n 1926│    // [impl->REQ-STREAMLOG-SUBSCRIBER-DISCIPLINE]\n*1927│    pub fn stream_lease(&self, stream_id: u64) -> Option<Arc<StreamLease>> {\n 1928│        let streams = self.shared.streams.lock().unwrap();\n 1929│        streams\n 1930│            .get(&stream_id)\n     │...\n 1937│    /// enumeration is exactly what a future dispatcher generation would replay.\n*1938│    pub fn stream_infos(&self) -> Vec<NetStreamInfo> {\n 1939│        self.stream_infos_filtered(true)\n 1940│    }\n 1941│\n     │...\n 1948│    /// client-side guard (double-filter harmless, N-1 compatible both ways).\n*1949│    /// In-process introspection (tests, the loopback-pair diff) keeps the\n 1950│    /// unfiltered [`Self::stream_infos`].\n 1951│    // [impl->REQ-STREAM-INFOS-SERVER-FILTER]\n*1952│    pub fn dispatch_stream_infos(&self) -> Vec<NetStreamInfo> {\n 1953│        self.stream_infos_filtered(false)\n 1954│    }\n 1955│\n*1956│    fn stream_infos_filtered(&self, include_local: bool) -> Vec<NetStreamInfo> {\n 1957│        let streams = self.shared.streams.lock().unwrap();\n 1958│        streams\n 1959│            .iter()\n     │...\n 1983│    // [impl->REQ-SEAT-LIFETIME-BOUNDED]\n*1984│    pub fn stream_counts(&self) -> (u64, u64) {\n 1985│        let streams = self.shared.streams.lock().unwrap();\n 1986│        let rows = streams.len() as u64;\n 1987│        let seats = streams\n     │...\n 2004│    // [impl->REQ-REDISPATCH-FINISHED-RETIRE]\n*2005│    pub fn retire_stream(&self, stream_id: u64) -> bool {\n 2006│        let Some(entry) = self\n 2007│            .shared\n 2008│            .streams\n     │...\n 2052│    // [impl->REQ-SEAT-LIFETIME-BOUNDED]\n*2053│    pub fn retire_stream_terminal(&self, stream_id: u64) -> bool {\n 2054│        let Some(entry) = self.shared.streams.lock().unwrap().remove(&stream_id) else {\n 2055│            return false;\n 2056│        };\n     │...\n 2075│    // [impl->REQ-STREAM-OPENER-DURABLE]\n*2076│    pub fn stream_opener(&self, stream_id: u64) -> Option<Option<Vec<u8>>> {\n 2077│        let entry = Arc::clone(self.shared.streams.lock().unwrap().get(&stream_id)?);\n 2078│        // A retired row answers no-such-stream: classification exists only to\n 2079│        // serve, and a retired exchange must never be served again.\n     │...\n 2086│\n*2087│    /// Mark a held stream **retentive** with backpressure `cap` chunks (M11-W3,\n 2088│    /// REQ-SHELL-4): its read log stops evicting (no byte loss) and its read pump\n 2089│    /// lags the sender once the undrained ring reaches `cap` (no unbounded growth).\n 2090│    /// Used for shell-tunnel streams; ordinary streams stay bounded-overwrite.\n     │...\n 2092│    // [impl->REQ-SHELL-4]\n*2093│    pub fn mark_stream_retentive(&self, stream_id: u64, cap: usize) {\n 2094│        if let Some(e) = self.shared.streams.lock().unwrap().get(&stream_id) {\n 2095│            e.log.lock().unwrap().set_retentive(cap);\n 2096│        }\n     │...\n 2100│    /// pops the whole ring in order, concatenated, and wakes the read pump (which\n*2101│    /// may have been lagging the sender at the backpressure cap). Returns\n 2102│    /// `(bytes, finished)`; `finished` ⇒ the read side ended (the poller closes).\n 2103│    /// `None` ⇒ no such stream. Empty bytes + `finished == false` ⇒ nothing pending.\n 2104│    // [impl->REQ-SHELL-4]\n*2105│    pub fn drain_stream(&self, stream_id: u64) -> Option<(Vec<u8>, bool)> {\n 2106│        let entry = Arc::clone(self.shared.streams.lock().unwrap().get(&stream_id)?);\n 2107│        let drained = entry.log.lock().unwrap().drain();\n*2108│        // The drain freed ring room — wake a pump that was backpressure-parked.\n 2109│        entry.room.notify_one();\n 2110│        Some(drained)\n 2111│    }\n     │...\n 2113│    /// A held stream's current undrained ring depth in chunks (test introspection\n*2114│    /// for the retentive backpressure bound). `None` ⇒ no such stream.\n 2115│    #[cfg(test)]\n*2116│    fn ring_len(&self, stream_id: u64) -> Option<usize> {\n 2117│        self.shared\n 2118│            .streams\n 2119│            .lock()\n     │...\n 2125│    /// Inbound (peer-initiated) stream rows currently held on `conn_id` — the\n*2126│    /// candidate set [`Self::open_loopback_pair`] diffs to find the peer it just\n 2127│    /// minted.\n 2128│    fn inbound_rows_on(&self, conn_id: u64) -> HashSet<u64> {\n 2129│        self.shared\n     │...\n 2138│\n*2139│    /// Open a same-node loopback tunnel stream PAIR (M11-W3, REQ-SHELL-4) and\n 2140│    /// return `(owner_stream, shell_stream)` — the operator row the owner side\n*2141│    /// drives and the cross-wired peer row the shell side drives. The loopback\n 2142│    /// `open_stream` mints both rows in-process (one `duplex` wires them, so a\n 2143│    /// write to either send appears on the other's read log). Serialized so the\n 2144│    /// before/after diff sees exactly the one peer row this open minted.\n 2145│    // [impl->REQ-SHELL-4]\n*2146│    pub fn open_loopback_pair(&self) -> io::Result<(u64, u64)> {\n*2147│        let _guard = self.loopback_pair_lock.lock().unwrap();\n*2148│        let (conn_id, _) = self.dial_loopback();\n 2149│        let before = self.inbound_rows_on(conn_id);\n 2150│        let owner_stream = self.open_stream(conn_id, crate::msg::StreamLifetime::Durable)?;\n 2151│        let shell_stream = self\n     │...\n 2155│            .next()\n*2156│            .ok_or_else(|| io::Error::other(\"loopback peer row not registered\"))?;\n 2157│        Ok((owner_stream, shell_stream))\n 2158│    }\n 2159│\n     │...\n 2162│    // [impl->REQ-DAEMON-2]\n*2163│    pub(crate) fn subscribe_stream(\n 2164│        &self,\n 2165│        stream_id: u64,\n*2166│        sub: SharedSend,\n 2167│        from_seq: u64,\n 2168│    ) -> io::Result<()> {\n 2169│        let log = {\n     │...\n 2199│    // [impl->REQ-SEAT-LIFETIME-BOUNDED]\n*2200│    pub(crate) fn unsubscribe_stream(&self, stream_id: u64, sub: &SharedSend) -> bool {\n 2201│        let log = {\n 2202│            let streams = self.shared.streams.lock().unwrap();\n 2203│            streams.get(&stream_id).map(|e| Arc::clone(&e.log))\n     │...\n 2220│    /// disconnect cleanup; the stream + its ring persist).\n*2221│    pub(crate) fn detach_stream_sub(&self, stream_id: u64, sub: &SharedSend) {\n 2222│        let log = {\n 2223│            let streams = self.shared.streams.lock().unwrap();\n 2224│            streams.get(&stream_id).map(|e| Arc::clone(&e.log))\n     │...\n 2233│    // [impl->REQ-EP-4]\n*2234│    pub(crate) fn subscribe_presence(&self, sub: SharedSend, from_seq: u64) {\n 2235│        // Same atomic install-with-replay discipline as subscribe_stream\n 2236│        // (the PresenceLog mirror): the seat's writer drains the replay\n 2237│        // before any live event, conn I/O outside the mutex. A replay write\n     │...\n 2250│    /// disconnect cleanup; the log + its ring persist).\n*2251│    pub(crate) fn detach_presence_sub(&self, sub: &SharedSend) {\n 2252│        self.shared.presence.lock().unwrap().detach_if(sub);\n 2253│    }\n 2254│\n     │...\n 2259│        let endpoint = Arc::clone(&self.endpoint);\n*2260│        self.runtime.handle().block_on(async move {\n 2261│            endpoint.close().await;\n 2262│        });\n 2263│    }\n     │...\n 2272│    /// closes), forcing the peer onto its QUIC idle timeout. That is the\n*2273│    /// sleeping-laptop / QUIC-stack-dead netsplit the transport-death rig\n 2274│    /// needs, and it stages it with no elevation, no firewall and no FFI.\n 2275│    ///\n 2276│    /// [`Self::start`] builds the runtime with `worker_threads(2)`, which is\n     │...\n 2344│            discovery: LocalDiscovery::Off,\n*2345│            scope: BindScope::Loopback,\n 2346│            membership: None,\n 2347│        }\n 2348│    }\n     │...\n 2418│    // [unit->REQ-DAEMON-2] a broker-owned host dials a second in-process host\n*2419│    // over hermetic loopback QUIC; both sides register the connection — the\n 2420│    // dialer in its table, the acceptor via its accept loop.\n 2421│    #[test]\n*2422│    fn two_hosts_dial_over_loopback() {\n 2423│        let a = NetHost::start(hermetic(&Identity::generate())).expect(\"host a\");\n 2424│        let b_id = Identity::generate();\n 2425│        let b = NetHost::start(hermetic(&b_id)).expect(\"host b\");\n     │...\n 2450│\n*2451│    // [unit->REQ-RC-1] the broker loopback conn (M12 W1.5, B1): `dial_loopback`\n 2452│    // mints a REUSED singleton whose origin is this node's OWN id, and\n 2453│    // `open_stream` on it cross-wires a PAIR in-process — an operator row and a\n 2454│    // peer row (the one the dispatcher serves) — with the operator's writes\n     │...\n 2456│    #[test]\n*2457│    fn loopback_conn_is_a_reused_singleton_that_cross_wires_a_stream_pair() {\n 2458│        let id = Identity::generate();\n 2459│        let host = NetHost::start(hermetic(&id)).expect(\"host start\");\n 2460│\n 2461│        // Singleton: reused, own-node origin (never a foreign/handshake id).\n*2462│        let (c1, hex1) = host.dial_loopback();\n*2463│        let (c2, hex2) = host.dial_loopback();\n*2464│        assert_eq!(c1, c2, \"the loopback conn is a reused singleton\");\n 2465│        assert_eq!(\n 2466│            hex1,\n 2467│            id.public_key().to_hex(),\n*2468│            \"loopback origin is THIS node's own id (broker-minted)\"\n 2469│        );\n 2470│        assert_eq!(hex2, hex1);\n*2471│        assert_eq!(host.conn_count(), 1, \"one loopback conn held\");\n 2472│\n 2473│        // open_stream mints the cross-wired pair: operator row + peer row.\n*2474│        let op_stream = host.open_stream(c1, crate::msg::StreamLifetime::Durable).expect(\"open loopback stream\");\n 2475│        let infos = host.stream_infos();\n 2476│        assert_eq!(infos.len(), 2, \"operator + peer rows\");\n 2477│        let op = infos\n     │...\n 2493│        // pump (its log advances) — entirely in-process, no QUIC.\n*2494│        host.send_stream(op_stream, b\"ping\", false)\n 2495│            .expect(\"write operator side\");\n 2496│        let peer_id = peer.stream_id;\n 2497│        let mut crossed = false;\n     │...\n 2522│        let host = NetHost::start(hermetic(&Identity::generate())).expect(\"host\");\n*2523│        let (conn, _) = host.dial_loopback();\n 2524│\n 2525│        let cb_stream = host\n 2526│            .open_stream(conn, crate::msg::StreamLifetime::ConnectionBound)\n     │...\n 2590│\n*2591│    // [unit->REQ-SHELL-4] the loopback tunnel pair under BACKPRESSURE (M11-W3,\n 2592│    // doyle gate condition): a retentive shell-side stream that is not drained while\n 2593│    // the owner keeps writing must NOT lose bytes AND must NOT grow unbounded — the\n 2594│    // read pump lags the sender at the cap. After the reader catches up, every byte\n     │...\n 2596│    #[test]\n*2597│    fn loopback_tunnel_backpressures_without_loss() {\n 2598│        use std::sync::atomic::{AtomicUsize, Ordering as AtOrd};\n 2599│        let id = Identity::generate();\n 2600│        let host = Arc::new(NetHost::start(hermetic(&id)).expect(\"host start\"));\n*2601│        let (owner, shell) = host.open_loopback_pair().expect(\"open tunnel pair\");\n 2602│        const CAP: usize = 4;\n 2603│        host.mark_stream_retentive(owner, CAP);\n 2604│        host.mark_stream_retentive(shell, CAP);\n     │...\n 2617│                for f in &frames {\n*2618│                    host.send_stream(owner, f, false).expect(\"send\");\n 2619│                    sent.fetch_add(1, AtOrd::Relaxed);\n 2620│                }\n*2621│                host.send_stream(owner, &[], true).expect(\"finish\");\n 2622│            })\n 2623│        };\n 2624│\n*2625│        // Let the pump fill the shell ring to the cap and PARK (backpressure).\n 2626│        let mut peak = 0usize;\n 2627│        for _ in 0..200 {\n 2628│            if let Some(d) = host.ring_len(shell) {\n     │...\n 2632│            if sent.load(AtOrd::Relaxed) >= N {\n*2633│                break; // (shouldn't reach N while we never drain — backpressure)\n 2634│            }\n 2635│        }\n 2636│        assert!(peak > 0, \"the pump delivered some frames to the shell ring\");\n     │...\n 2638│            host.ring_len(shell).unwrap() <= CAP,\n*2639│            \"the retentive ring never exceeds the backpressure cap (bounded)\"\n 2640│        );\n 2641│        assert!(\n 2642│            sent.load(AtOrd::Relaxed) < N,\n*2643│            \"the un-drained consumer lags the sender (backpressure engaged, not all sent)\"\n 2644│        );\n 2645│\n 2646│        // Now drain to completion — the sender unblocks, every byte arrives in order.\n     │...\n 2662│        assert_eq!(got.len(), expected.len(), \"no byte lost or duplicated\");\n*2663│        assert_eq!(got, expected, \"byte-exact, in order, under backpressure\");\n 2664│    }\n 2665│\n 2666│    // [unit->REQ-HAZARD-BROKER-QUIC-DEADLINE] the broker-side QUIC-op bound (the\n*2667│    // B-half of REQ-HAZARD-PUMP-IPC-DEADLINE): `bounded_block_on` returns a PROMPT,\n 2668│    // ORDINARY (non-`TimedOut`) error on a never-completing op — so the broker can\n 2669│    // REPLY an error frame instead of leaving the single-threaded pump wedged on a\n 2670│    // dead peer — while a ready op passes through untouched (the happy path is\n     │...\n 2672│    #[test]\n*2673│    fn bounded_block_on_cuts_a_never_completing_op_with_an_ordinary_error() {\n 2674│        let host = NetHost::start(hermetic(&Identity::generate())).expect(\"host start\");\n 2675│        host.set_quic_op_timeout(Duration::from_millis(150));\n 2676│\n*2677│        // A never-completing await (the black-holed-peer shape) fails at the bound.\n 2678│        let started = std::time::Instant::now();\n 2679│        let err = host\n*2680│            .bounded_block_on(std::future::pending::<io::Result<()>>())\n 2681│            .expect_err(\"a never-completing op must error, never block forever\");\n 2682│        let elapsed = started.elapsed();\n 2683│        assert_ne!(\n     │...\n 2699│        let v: u64 = host\n*2700│            .bounded_block_on(async { Ok(7u64) })\n 2701│            .expect(\"a ready op passes through\");\n 2702│        assert_eq!(v, 7, \"the bound is transparent to a completing op\");\n 2703│    }\n     │...\n 2734│    #[test]\n*2735│    fn opener_capture_gives_up_bounded_on_a_newline_less_stream() {\n 2736│        let mut log = StreamLog::new(8, 4);\n 2737│        log.append(&vec![b'x'; OPENER_PIN_MAX + 1]);\n 2738│        assert_eq!(log.opener_line(), None, \"over the cap without a newline: gave up\");\n     │...\n 2752│        let host = NetHost::start(hermetic(&Identity::generate())).expect(\"host start\");\n*2753│        let (owner, shell) = host.open_loopback_pair().expect(\"open pair\");\n*2754│        host.send_stream(owner, b\"{\\\"kind\\\":\\\"request\\\",\\\"session_id\\\":1}\\n\", false)\n 2755│            .expect(\"send opener\");\n 2756│        // The pump is async — wait for the shell row to hold the opener.\n 2757│        let mut pinned = None;\n     │...\n 2785│    // worker's reply send is fire-and-forget (brain returns before the broker\n*2786│    // processes the envelope), so the acked retire on its own conn can be\n 2787│    // processed FIRST. Pre-fix, retire removed the entry: the late send hit\n 2788│    // no-such-stream (or the drop reset the never-finished send half) and the\n 2789│    // requester got torn-EOF instead of its reply (wansend NoReply, CI red\n     │...\n 2793│        let host = NetHost::start(hermetic(&Identity::generate())).expect(\"host start\");\n*2794│        let (owner, shell) = host.open_loopback_pair().expect(\"open pair\");\n 2795│        // The requester's one-shot request: write + FIN (the rest/sync shape —\n 2796│        // the row is born finished on the serving side).\n*2797│        host.send_stream(\n 2798│            owner,\n 2799│            b\"{\\\"kind\\\":\\\"request\\\",\\\"endpoint\\\":\\\"e\\\",\\\"event\\\":\\\"suspend\\\"}\\n\",\n 2800│            true,\n     │...\n 2807│        // The worker's reply lands AFTER retirement and must still deliver.\n*2808│        host.send_stream(shell, b\"{\\\"kind\\\":\\\"reply\\\",\\\"outcome\\\":\\\"edge\\\"}\\n\", true)\n 2809│            .expect(\"a retired row still accepts the in-flight reply\");\n 2810│        let mut got = Vec::new();\n 2811│        let mut finished = false;\n     │...\n 2832│    #[test]\n*2833│    fn conn_close_sweeps_its_stream_rows() {\n 2834│        let a = NetHost::start(hermetic(&Identity::generate())).expect(\"host a\");\n 2835│        let b = NetHost::start(hermetic(&Identity::generate())).expect(\"host b\");\n 2836│        let (conn_id, _) = a.dial(b.addr()).expect(\"dial\");\n 2837│        let sid = a.open_stream(conn_id, crate::msg::StreamLifetime::Durable).expect(\"open stream\");\n*2838│        a.send_stream(sid, b\"{\\\"hello\\\":1}\\n\", false).expect(\"send\");\n 2839│        // B's acceptor registers the peer row (async — poll).\n 2840│        let mut saw = false;\n 2841│        for _ in 0..400 {\n     │...\n 2869│    /// A connected local-socket pair whose SERVER send half wraps as the\n*2870│    /// `SharedSend` a subscriber seat writes through — `controller_socket_pair`'s\n 2871│    /// idiom (broker.rs) with a caller-chosen write bound.\n 2872│    fn seat_socket_pair(\n 2873│        bound: Duration,\n 2874│    ) -> (\n*2875│        SharedSend,\n 2876│        interprocess::local_socket::Stream,\n 2877│        interprocess::local_socket::RecvHalf,\n 2878│    ) {\n     │...\n 3153│        // ...and the SUCCESSOR's lease stays live — its serve leg keeps\n*3154│        // forwarding (send_stream reads this current Arc).\n 3155│        assert!(\n 3156│            !lease_b.is_canceled(),\n 3157│            \"the displaced writer's death must never cancel the successor's lease\"\n     │...\n 3202│    // seam (Amendment fix 4): a canceled lease makes every later\n*3203│    // `send_stream` refuse with the \"lease canceled\" answer (the SeatBlocked\n 3204│    // classification string) — the paired serve/wire worker discovers the\n 3205│    // cancellation at its next forward and terminates, never feeding an\n 3206│    // orphan leg forever.\n 3207│    #[test]\n*3208│    fn send_stream_refuses_on_a_canceled_lease() {\n 3209│        let host = NetHost::start(hermetic(&Identity::generate())).expect(\"host start\");\n*3210│        let (owner, _shell) = host.open_loopback_pair().expect(\"open pair\");\n 3211│        let lease = host.stream_lease(owner).expect(\"lease handle\");\n 3212│        assert!(!lease.is_canceled());\n*3213│        host.send_stream(owner, b\"ok\", false).expect(\"a live lease serves\");\n 3214│\n 3215│        lease.cancel();\n 3216│        let err = host\n*3217│            .send_stream(owner, b\"nope\", false)\n 3218│            .expect_err(\"a canceled lease refuses the forward\");\n 3219│        assert!(err.to_string().contains(\"lease canceled\"), \"{err}\");\n 3220│    }\n     │...\n 3229│    #[test]\n*3230│    fn dispatch_stream_infos_excludes_local_and_retired_rows_server_side() {\n 3231│        let host = NetHost::start(hermetic(&Identity::generate())).expect(\"host start\");\n*3232│        let (owner, shell) = host.open_loopback_pair().expect(\"open pair\");\n*3233│        host.send_stream(owner, b\"{\\\"subnet\\\":\\\"s\\\",\\\"instance\\\":{}}\\n\", false)\n 3234│            .expect(\"bytes onto the peer row\");\n 3235│\n 3236│        // Full introspection: both rows. Dispatch view: the peer row only.\n     │...\n 3269│        let host = NetHost::start(hermetic(&Identity::generate())).expect(\"host start\");\n*3270│        let (owner, shell) = host.open_loopback_pair().expect(\"open pair\");\n 3271│        let _ = shell;\n 3272│\n 3273│        let (a, _ca, _ra) = seat_socket_pair(Duration::from_secs(5));\n     │...\n 3315│        // the retired_row_still_flushes_a_late_reply contract above).\n*3316│        let (owner, shell) = host.open_loopback_pair().expect(\"pair 1\");\n 3317│        let (sub, _c, _r) = seat_socket_pair(Duration::from_secs(5));\n 3318│        host.subscribe_stream(shell, Arc::clone(&sub), 0).expect(\"subscribe\");\n 3319│        let (rows_before, seats_before) = host.stream_counts();"},"isError":false,"timestamp":1789524011785}}
{"type":"message","id":"29c9bcdf","parentId":"c81f1d2e","timestamp":"2026-09-16T02:00:11.787Z","message":{"role":"toolResult","toolCallId":"call_i0IQUAawhElXkfR7lvdzvQ8U|fc_09b01b5279447709016aa9f82bb13487d29581ac49eb5cbbea","toolName":"grep","content":[{"type":"text","text":"# crates/spt-daemon/src/\n## brain.rs\n 2510|    #[allow(clippy::too_many_arguments)]\n*2511|    fn subscribe_with(\n 2512|        &mut self,\n 2513|        session_id: u64,\n 2514|        from_seq: u64,\n...\n 2553|\n*2554|    fn send(&mut self, kind: &str, payload: serde_json::Value) -> io::Result<()> {\n 2555|        let env = Envelope::new(kind, payload);\n 2556|        match &mut self.conn {\n 2557|            BrainConn::Whole(stream) => write_frame(stream, &env),\n## resting.rs\n 401|// [impl->REQ-INST-3]\n*402|pub fn daemon_rest_event(\n 403|    id: &str,\n 404|    event: RestEvent,\n 405|    node_auto_suspend_ms: Option<u64>,\n...\n 415|// [impl->REQ-ENDPOINT-CYCLE-HONEST]\n*416|pub fn daemon_rest_event_with_liveness(\n 417|    id: &str,\n 418|    event: RestEvent,\n 419|    node_auto_suspend_ms: Option<u64>,\n...\n 1211|    #[test]\n*1212|    fn daemon_rest_event_arms_gate_at_rest_edge_only() {\n 1213|        use spt_store::info::set_status;\n 1214|        use spt_store::liveness::STATUS_ONLINE;\n 1215|\n## broker.rs\n 9825|    // [impl->REQ-HAZARD-RESTART-IDEMPOTENT]\n*9826|    fn dispatch_net_stream_send(&self, env: Envelope, send: &SharedSend) -> Result<(), String> {\n 9827|        let req: NetStreamSendReq = serde_json::from_value(env.payload)\n 9828|            .map_err(|e| format!(\"bad net-stream-send payload: {e}\"))?;\n 9829|        let bytes ="}],"details":{"scopePath":"crates/spt-daemon/src/brain.rs, crates/spt-daemon/src/resting.rs, crates/spt-daemon/src/broker.rs","searchPath":"C:\\Users\\decid\\Documents\\projects\\spt-core\\crates\\spt-daemon\\src","cwd":"C:\\Users\\decid\\Documents\\projects\\spt-core","matchCount":6,"fileCount":3,"files":["crates/spt-daemon/src/brain.rs","crates/spt-daemon/src/resting.rs","crates/spt-daemon/src/broker.rs"],"fileMatches":[{"path":"crates/spt-daemon/src/brain.rs","count":2},{"path":"crates/spt-daemon/src/resting.rs","count":3},{"path":"crates/spt-daemon/src/broker.rs","count":1}],"truncated":false,"displayContent":"# crates/spt-daemon/src/\n## brain.rs\n 2510│    #[allow(clippy::too_many_arguments)]\n*2511│    fn subscribe_with(\n 2512│        &mut self,\n 2513│        session_id: u64,\n 2514│        from_seq: u64,\n     │...\n 2553│\n*2554│    fn send(&mut self, kind: &str, payload: serde_json::Value) -> io::Result<()> {\n 2555│        let env = Envelope::new(kind, payload);\n 2556│        match &mut self.conn {\n 2557│            BrainConn::Whole(stream) => write_frame(stream, &env),\n## resting.rs\n  401│// [impl->REQ-INST-3]\n *402│pub fn daemon_rest_event(\n  403│    id: &str,\n  404│    event: RestEvent,\n  405│    node_auto_suspend_ms: Option<u64>,\n     │...\n  415│// [impl->REQ-ENDPOINT-CYCLE-HONEST]\n *416│pub fn daemon_rest_event_with_liveness(\n  417│    id: &str,\n  418│    event: RestEvent,\n  419│    node_auto_suspend_ms: Option<u64>,\n     │...\n 1211│    #[test]\n*1212│    fn daemon_rest_event_arms_gate_at_rest_edge_only() {\n 1213│        use spt_store::info::set_status;\n 1214│        use spt_store::liveness::STATUS_ONLINE;\n 1215│\n## broker.rs\n 9825│    // [impl->REQ-HAZARD-RESTART-IDEMPOTENT]\n*9826│    fn dispatch_net_stream_send(&self, env: Envelope, send: &SharedSend) -> Result<(), String> {\n 9827│        let req: NetStreamSendReq = serde_json::from_value(env.payload)\n 9828│            .map_err(|e| format!(\"bad net-stream-send payload: {e}\"))?;\n 9829│        let bytes ="},"isError":false,"timestamp":1789524011787}}
{"type":"message","id":"4c53f97d","parentId":"29c9bcdf","timestamp":"2026-09-16T02:00:11.799Z","message":{"role":"toolResult","toolCallId":"call_w6Oyg8OpwngH12l13l9ZI1Re|fc_09b01b5279447709016aa9f82bb12c87d2bb97e6da4711c5ce","toolName":"grep","content":[{"type":"text","text":"# crates/spt-daemon/tests/\n## attach.rs\n 13|//!   on the stream table's handshake-proven `remote_id_hex`;\n*14|//! - **restart survival** (REQ-HAZARD-RESTART-IDEMPOTENT): A's brain dies\n 15|//!   mid-attach; the broker keeps the QUIC stream, the session, the output\n 16|//!   log, and the effect journal. The successor brain re-serves the SAME\n*17|//!   stream from seq 0 — the worst-case stale cursor: the replayed input\n 18|//!   dedups at the PTY-write journal (typed exactly once), re-transmitted\n 19|//!   output dedups at B's render cursor (rendered exactly once) — including\n 20|//!   input B sent INTO the dead window.\n...\n 47|/// the endpoint perch's `driven_by` marker without ever touching a real home.\n*48|fn init_home() -> TestHome {\n 49|    TestHome::new()\n 50|}\n 51|\n 52|static SEQ: AtomicU32 = AtomicU32::new(0);\n*53|fn unique_name() -> String {\n 54|    let n = SEQ.fetch_add(1, Ordering::Relaxed);\n 55|    format!(\"spt-daemon-d5b-{}-{}.sock\", std::process::id(), n)\n 56|}\n 57|\n*58|fn hermetic() -> NetConfig {\n 59|    NetConfig {\n 60|        identity: Identity::generate(),\n 61|        relay: RelayPolicy::Disabled,\n...\n 67|\n*68|fn net_broker(name: &str, dir: &std::path::Path) -> Arc<Broker> {\n 69|    let host = NetHost::start(hermetic()).expect(\"net host start\");\n 70|    let broker =\n 71|        Broker::bind_in_with_net(name, dir.join(\"effects.log\"), Some(host)).expect(\"bind broker\");\n...\n 78|\n*79|fn connect_retry(name: &str) -> Brain {\n 80|    for _ in 0..300 {\n 81|        if let Ok(b) = Brain::cold_start(name, 1) {\n 82|            return b;\n...\n 90|/// actually expire, retried over broker start-up the same way.\n*91|fn connect_retry_pump(name: &str, io_timeout: Duration) -> Brain {\n 92|    for _ in 0..300 {\n 93|        if let Ok(b) =\n 94|            Brain::cold_start_pump(name, 1, io_timeout, spt_daemon::brain::PumpTrace::Stderr)\n...\n 102|\n*103|fn echo_spawn_req() -> SpawnReq {\n 104|    #[cfg(unix)]\n 105|    let (program, args) = (\"cat\".to_string(), Vec::<String>::new());\n 106|    #[cfg(windows)]\n...\n 138|/// same id twice is ONE stream served twice, never two streams sharing a number.\n*139|fn wait_for_stream(brain: &mut Brain, served: &[u64]) -> (u64, String) {\n 140|    for _ in 0..400 {\n 141|        let reply = brain.net_streams().expect(\"net-streams\");\n 142|        if let Some(s) = reply\n...\n 168|#[allow(clippy::too_many_arguments)]\n*169|fn attach_drive_detach(\n 170|    operator: &mut Brain,\n 171|    target_broker: &str,\n 172|    mut target: Brain,\n...\n 243|/// the rendered-through cursor (last accepted seq + 1).\n*244|fn render_until(\n 245|    brain: &mut Brain,\n 246|    stream_id: u64,\n 247|    decoder: &mut AttachDecoder,\n...\n 263|                        if seq < *next_seq {\n*264|                            continue; // replay duplicate — dedup by cursor\n 265|                        }\n 266|                        // #6 (ADR-0031): the initial batch is now a single synthesized\n 267|                        // repaint at pseudo-seq `log.next_seq - 1`, so the FIRST frame a\n...\n 286|/// Count non-overlapping occurrences of `needle` in `hay`.\n*287|fn count(hay: &[u8], needle: &[u8]) -> usize {\n 288|    if needle.is_empty() || hay.len() < needle.len() {\n 289|        return 0;\n 290|    }\n...\n 310|#[test]\n*311|fn loopback_self_dial_is_refused_local_uses_fallback_transport() {\n 312|    let _home = init_home();\n 313|    let dir = tempfile::tempdir().expect(\"tempdir\");\n 314|    let name = unique_name();\n...\n 338|#[test]\n*339|fn spt_hosted_bringup_then_cross_node_attach_drives_the_pty() {\n 340|    let _home = init_home();\n 341|    let dir = tempfile::tempdir().expect(\"tempdir\");\n 342|    let (name_a, name_b) = (unique_name(), unique_name());\n...\n 437|#[test]\n*438|fn remote_attach_drives_a_real_pty_cross_daemon() {\n 439|    let _home = init_home();\n 440|    let dir = tempfile::tempdir().expect(\"tempdir\");\n 441|    let (name_a, name_b) = (unique_name(), unique_name());\n...\n 493|#[test]\n*494|fn local_attach_via_loopback_conn_rides_the_same_pump() {\n 495|    let _home = init_home();\n 496|    let dir = tempfile::tempdir().expect(\"tempdir\");\n 497|    let name = unique_name();\n...\n 533|\n*534|// [unit->REQ-HAZARD-ENDPOINT-RUN-ATTACH-OUTPUT] the replay-vs-forward deadlock pin:\n 535|// when the session's OutputLog ring is ALREADY NON-EMPTY at attach (an\n 536|// already-producing session — exactly the endpoint-run shape, whose transient\n*537|// cold-start spawn conn drops after `Spawned`), `become_controller` replays MANY\n 538|// frames into the SERVING brain while `serve_attach` must forward each back to the\n 539|// operator. Before the two-conn split both rode ONE broker IPC connection, so the\n## attach_idempotent_replay.rs\n 7|//! breadcrumbs on an authorized same-seam `daemon refresh` (which FALSIFIED the\n*8|//! presumed gen+1 mechanism): during post-cycle dispatcher replay the broker\n 9|//! processed the SAME conn / SAME identity / SAME generation subscribe twice,\n 10|//! 15 ms apart. ADR-0044's equal-generation rung classified that \"same lease,\n 11|//! silent re-take\" — correct — but re-take was `become_controller`, which\n...\n 13|//! synthesizes a fresh initial batch. Designed for a dead seat after a\n*14|//! dispatcher restart, it also fired against the same LIVE conn: the lease\n*15|//! killed its own writer and re-replayed history at the viewport.\n 16|//!\n 17|//! ## What this rig proves\n 18|//!\n...\n 20|//! then re-issues the IDENTICAL subscribe (same session, from_seq, intent, gen,\n*21|//! identity) — the dispatcher's double-serve. After that replay:\n 22|//!\n 23|//! 1. the seat still answers `Controller` (the wire vocabulary is unchanged —\n 24|//!    `idempotent` rides the breadcrumb only, so an N-1 peer sees what it\n 25|//!    always saw);\n*26|//! 2. NO history is re-delivered — a second initial batch would replay the\n 27|//!    bytes the viewport already has (the visible half of the field freeze);\n*28|//! 3. the ORIGINAL writer is still live: input sent AFTER the replay still\n 29|//!    echoes back on the same conn. A dropped seat's writer is\n 30|//!    channel-closed, and the viewport stops until a manual detach+re-attach.\n 31|//!\n...\n 45|//! The discriminating RED evidence is the unit matrix\n*46|//! (`broker::tests::equal_generation_same_conn_is_an_idempotent_replay`), which\n 47|//! asserts the seat's SINK IDENTITY and the unmoved `controller_epoch` and reds\n 48|//! immediately when the discriminator is removed — with the broker's own\n 49|//! breadcrumbs naming the mechanism: `controller-replaced ... new_conn=2` on\n...\n 53|//! The DIFFERENT-conn successor (ADR-0038 fix 6) is covered by\n*54|//! `controller_lease::equal_lease_replay_stays_silent_and_never_self_displaces`\n 55|//! and the redispatch/brain_swap suites — this rig must not be read as\n 56|//! narrowing that path.\n 57|//!\n...\n 64|//! only while echo #2 is still in flight — a live-stream byte with NO relation\n*65|//! to any replay. Measured on kitsubito (2026-07-23): a replay-removed control\n 66|//! arm reds this leg 12/13 serial and 93/120 under load, catching that echo #2\n 67|//! in the absence window; the shipped leg was serial-green ONLY because the\n*68|//! replay's `read_outcome` happened to discard echo #2 while awaiting\n 69|//! `Subscribed`, a coincidence load breaks. Hence the anchor drains to\n*70|//! quiescence BEFORE the replay (`drain_quiet`) and the post-replay window uses\n 71|//! the CAPTURING outcome read (`read_outcome_capturing`) — so the absence check\n 72|//! observes exactly what a viewport would, never a swallowed byte.\n 73|//!\n...\n 89|\n*90|fn init_home() -> TestHome {\n 91|    TestHome::new()\n 92|}\n 93|\n 94|static SEQ: AtomicU32 = AtomicU32::new(0);\n*95|fn unique_name() -> String {\n 96|    format!(\n*97|        \"spt-daemon-idemreplay-{}-{}.sock\",\n 98|        std::process::id(),\n 99|        SEQ.fetch_add(1, Ordering::Relaxed)\n 100|    )\n...\n 102|\n*103|fn connect_retry(name: &str) -> Brain {\n 104|    for _ in 0..300 {\n 105|        if let Ok(b) = Brain::cold_start(name, 1) {\n 106|            return b;\n...\n 114|/// key) so the real PTY submits and echoes them.\n*115|fn echo_spawn_req(endpoint: &str) -> SpawnReq {\n 116|    #[cfg(unix)]\n 117|    let (program, args) = (\"cat\".to_string(), Vec::<String>::new());\n 118|    #[cfg(windows)]\n...\n 133|\n*134|fn contains(hay: &[u8], needle: &[u8]) -> bool {\n 135|    hay.windows(needle.len()).any(|w| w == needle)\n 136|}\n 137|\n...\n 139|/// returning everything read.\n*140|fn pump_until(brain: &mut Brain, needle: &[u8], budget: Duration) -> Vec<u8> {\n 141|    let deadline = Instant::now() + budget;\n 142|    let mut seen = Vec::new();\n 143|    while Instant::now() < deadline {\n...\n 159|/// ends empty is the point).\n*160|fn collect_for(brain: &mut Brain, window: Duration) -> Vec<u8> {\n 161|    let deadline = Instant::now() + window;\n 162|    let mut seen = Vec::new();\n 163|    while Instant::now() < deadline {\n...\n 175|/// otherwise be indistinguishable from an absence.\n*176|fn read_outcome(brain: &mut Brain) -> SubscribeOutcome {\n 177|    let deadline = Instant::now() + Duration::from_secs(20);\n 178|    while Instant::now() < deadline {\n 179|        match brain.read_event_until(Some(deadline)) {\n## redispatch_stall.rs\n 4|//! retries × the broad `Err(_)` opener fallback manufacturing throwaway peek\n*5|//! subscribers whose `StreamLog::attach` replayed the whole ring UNDER the\n 6|//! per-stream mutex against wedged conns — serial 15s bounded-write poison\n 7|//! windows (33 observed, all 15,000-15,154ms).\n 8|//!\n...\n 10|//! through the production broker subscribe path — gate ruling 1):\n*11|//!   - T1+T3 `wedged_subscriber_...`: replay + live fan-out halt bounded at\n 12|//!     the first failed write; the producer stays FLAT (never a serial poison\n*13|//!     composition); recovery replays gapless from the cursor.\n 14|//!   - T2 `opener_transient_...`: a transport-class opener failure requeues\n 15|//!     bounded and NEVER creates a peek subscriber (pre-fix: each retry\n*16|//!     subscribed + replayed against the conn).\n 17|//!   - T4 `poisoned_subscriber_cancels_...`: subscriber poison cancels the\n 18|//!     stream's serve lease — the paired forwarding leg terminates at its\n 19|//!     next send; a new subscriber generation renews and serves again.\n...\n 24|//!     (raw-close viewport, no FIN — the shape finished-row retirement cannot\n*25|//!     see) replayed by a fresh generation neither takes nor clears the live\n 26|//!     replacement controller (ownership/generation validation).\n 27|//!   - T7 `old_broker_fallback_...`: mixed-image N-1 with REAL\n 28|//!     traffic-carrying streams (doyle rider: handshake-only insufficient) —\n...\n 59|\n*60|fn init_home() -> TestHome {\n 61|    TestHome::new()\n 62|}\n 63|\n 64|static SEQ: AtomicU32 = AtomicU32::new(0);\n*65|fn unique_name() -> String {\n 66|    let n = SEQ.fetch_add(1, Ordering::Relaxed);\n 67|    format!(\"spt-daemon-rdstall-{}-{}.sock\", std::process::id(), n)\n 68|}\n 69|\n*70|fn hermetic() -> NetConfig {\n 71|    NetConfig {\n 72|        identity: Identity::generate(),\n 73|        relay: RelayPolicy::Disabled,\n...\n 79|\n*80|fn net_broker(name: &str, dir: &std::path::Path) -> Arc<Broker> {\n 81|    let host = NetHost::start(hermetic()).expect(\"net host start\");\n 82|    let broker =\n 83|        Broker::bind_in_with_net(name, dir.join(\"effects.log\"), Some(host)).expect(\"bind broker\");\n...\n 90|\n*91|fn connect_retry(name: &str) -> Brain {\n 92|    for _ in 0..300 {\n 93|        if let Ok(b) = Brain::cold_start(name, 1) {\n 94|            return b;\n...\n 100|\n*101|fn echo_spawn_req(endpoint: &str) -> SpawnReq {\n 102|    #[cfg(unix)]\n 103|    let (program, args) = (\"cat\".to_string(), Vec::<String>::new());\n 104|    #[cfg(windows)]\n...\n 152|/// The A-side peer-stream ids, via a probe brain.\n*153|fn peer_stream_ids(probe: &mut Brain) -> Vec<u64> {\n 154|    probe\n 155|        .net_streams()\n 156|        .expect(\"net-streams\")\n...\n 165|/// helper, verbatim). Returns whether an EOF for the stream arrived.\n*166|fn render_until(\n 167|    operator: &mut Brain,\n 168|    stream_id: u64,\n 169|    decoder: &mut AttachDecoder,\n...\n 212|\n*213|fn screen_of(viewport: &[u8]) -> String {\n 214|    let mut screen = ScreenGrid::new(24, 80);\n 215|    screen.advance(viewport);\n 216|    String::from_utf8_lossy(&screen.render_repaint()).into_owned()\n...\n 220|/// opener line. Returns (operator brain, B-side stream id, A-side stream id).\n*221|fn open_traffic_stream(\n 222|    _name_a: &str,\n 223|    name_b: &str,\n 224|    probe: &mut Brain,\n...\n 259|/// no-reinstall drain window (\"subscriber busy\" surfaces as an Error event),\n*260|/// then accumulate the replay until `want_bytes` bytes arrived. Asserts DENSE\n 261|/// seq contiguity from 0 (gapless) and returns the bytes.\n*262|fn drain_gapless(name_a: &str, sid_a: u64, want_bytes: usize, deadline: Duration) -> Vec<u8> {\n 263|    let end = Instant::now() + deadline;\n 264|    'attach: loop {\n 265|        assert!(\n...\n 288|                        seq, next,\n*289|                        \"the recovery replay must be DENSE from 0 — a gap means the \\\n 290|                         overflow/poison lost retained bytes\"\n 291|                    );\n 292|                    next += 1;\n...\n 321|// [int->REQ-STREAMLOG-SUBSCRIBER-DISCIPLINE]\n*322|// T1 (poisoned-replay halt) + T3 (producer latency flat), one incident on the\n 323|// production broker subscribe path: a REAL subscriber conn that attaches with\n*324|// a full ring and never reads — its seat's replay wedges on the named-pipe\n 325|// write, fails at the (shrunk, 400ms) bounded deadline, and HALTS: the seat\n 326|// is removed, later appends never re-feed it, and the PRODUCER — B's ack'd\n## redispatch.rs\n 5|//! exactly like a production brain death). NO manual re-serve anywhere: the\n*6|//! pre-fix e2e (`attach_survives_target_brain_restart_exactly_once`)\n 7|//! hand-stepped a known stream and bypassed exactly the rediscovery/\n 8|//! classification seam that was broken in the field.\n 9|//!\n 10|//! - D1: a FINISHED historical Attach + a CURRENT active Attach, same\n*11|//!   endpoint/origin; restart the dispatcher generation only → the\n 12|//!   historical stream neither takes nor clears the current controller\n*13|//!   (post-restart input still renders; no EOF; no replay-storm log line;\n 14|//!   the retired row left the broker's enumeration).\n 15|//! - D2: an ACTIVE Attach whose opener rolled out of the bounded ring;\n*16|//!   restart the dispatcher → durable classification (the pinned opener)\n 17|//!   resumes the SAME operator stream.\n 18|//! - D3: ONE injected transient worker-start failure → the claim requeues\n 19|//!   and the retry serves the stream (no permanent abandonment, no\n...\n 44|/// Acquire a scoped temp home for one complete test body.\n*45|fn init_home() -> TestHome {\n 46|    TestHome::new()\n 47|}\n 48|\n 49|static SEQ: AtomicU32 = AtomicU32::new(0);\n*50|fn unique_name() -> String {\n 51|    let n = SEQ.fetch_add(1, Ordering::Relaxed);\n 52|    format!(\"spt-daemon-rdsp-{}-{}.sock\", std::process::id(), n)\n 53|}\n 54|\n*55|fn hermetic() -> NetConfig {\n 56|    NetConfig {\n 57|        identity: Identity::generate(),\n 58|        relay: RelayPolicy::Disabled,\n...\n 64|\n*65|fn net_broker(name: &str, dir: &std::path::Path) -> Arc<Broker> {\n 66|    let host = NetHost::start(hermetic()).expect(\"net host start\");\n 67|    let broker =\n 68|        Broker::bind_in_with_net(name, dir.join(\"effects.log\"), Some(host)).expect(\"bind broker\");\n...\n 75|\n*76|fn connect_retry(name: &str) -> Brain {\n 77|    for _ in 0..300 {\n 78|        if let Ok(b) = Brain::cold_start(name, 1) {\n 79|            return b;\n...\n 85|\n*86|fn echo_spawn_req(endpoint: &str) -> SpawnReq {\n 87|    #[cfg(unix)]\n 88|    let (program, args) = (\"cat\".to_string(), Vec::<String>::new());\n 89|    #[cfg(windows)]\n...\n 106|/// production `run_dispatch_loop` against `broker_name`. Killed = brain death\n*107|/// (worker conns drop). Stderr lands in `log` for replay-storm assertions.\n 108|struct Generation {\n 109|    child: Child,\n 110|    log: std::path::PathBuf,\n...\n 138|/// The A-side (target broker) peer-stream ids, via a probe brain.\n*139|fn peer_stream_ids(probe: &mut Brain) -> Vec<u64> {\n 140|    probe\n 141|        .net_streams()\n 142|        .expect(\"net-streams\")\n...\n 149|\n*150|/// Render the operator's viewport (dedup `Output` by seq — replays after a\n*151|/// generation restart re-transmit and are dropped at this cursor; a re-serve's\n 152|/// synthesized repaint may jump FORWARD, which is accepted and baselined)\n 153|/// until `needle` appears in the accumulated bytes, or panic at the deadline.\n 154|/// Returns `true` if an EOF for the stream arrived while rendering (the\n 155|/// steal-clears-controller symptom D1 must NOT see).\n*156|fn render_until(\n 157|    operator: &mut Brain,\n 158|    stream_id: u64,\n 159|    decoder: &mut AttachDecoder,\n...\n 184|                        if seq < *cursor {\n*185|                            continue; // replay duplicate — dedup at the render cursor\n 186|                        }\n 187|                        *cursor = seq + 1;\n 188|                        buf.extend_from_slice(\n...\n 202|\n*203|fn screen_of(viewport: &[u8]) -> String {\n 204|    let mut screen = ScreenGrid::new(24, 80);\n 205|    screen.advance(viewport);\n 206|    String::from_utf8_lossy(&screen.render_repaint()).into_owned()\n...\n 211|// active Attach on the same endpoint/origin; only the dispatcher generation\n*212|// restarts. The historical stream must neither take nor clear the current\n*213|// controller: post-restart input still renders (the frozen-PTY symptom is\n*214|// the failure), the operator sees NO EOF (the replayed-EOF detach is the"}],"details":{"scopePath":"crates/spt-daemon/tests/attach.rs, crates/spt-daemon/tests/attach_idempotent_replay.rs, crates/spt-daemon/tests/redispatch_stall.rs, crates/spt-daemon/tests/redispatch.rs","searchPath":"C:\\Users\\decid\\Documents\\projects\\spt-core\\crates\\spt-daemon\\tests","cwd":"C:\\Users\\decid\\Documents\\projects\\spt-core","matchCount":80,"fileCount":4,"files":["crates/spt-daemon/tests/attach.rs","crates/spt-daemon/tests/attach_idempotent_replay.rs","crates/spt-daemon/tests/redispatch_stall.rs","crates/spt-daemon/tests/redispatch.rs"],"fileMatches":[{"path":"crates/spt-daemon/tests/attach.rs","count":20},{"path":"crates/spt-daemon/tests/attach_idempotent_replay.rs","count":20},{"path":"crates/spt-daemon/tests/redispatch_stall.rs","count":20},{"path":"crates/spt-daemon/tests/redispatch.rs","count":20}],"truncated":true,"perFileLimitReached":20,"displayContent":"# crates/spt-daemon/tests/\n## attach.rs\n  13│//!   on the stream table's handshake-proven `remote_id_hex`;\n *14│//! - **restart survival** (REQ-HAZARD-RESTART-IDEMPOTENT): A's brain dies\n  15│//!   mid-attach; the broker keeps the QUIC stream, the session, the output\n  16│//!   log, and the effect journal. The successor brain re-serves the SAME\n *17│//!   stream from seq 0 — the worst-case stale cursor: the replayed input\n  18│//!   dedups at the PTY-write journal (typed exactly once), re-transmitted\n  19│//!   output dedups at B's render cursor (rendered exactly once) — including\n  20│//!   input B sent INTO the dead window.\n    │...\n  47│/// the endpoint perch's `driven_by` marker without ever touching a real home.\n *48│fn init_home() -> TestHome {\n  49│    TestHome::new()\n  50│}\n  51│\n  52│static SEQ: AtomicU32 = AtomicU32::new(0);\n *53│fn unique_name() -> String {\n  54│    let n = SEQ.fetch_add(1, Ordering::Relaxed);\n  55│    format!(\"spt-daemon-d5b-{}-{}.sock\", std::process::id(), n)\n  56│}\n  57│\n *58│fn hermetic() -> NetConfig {\n  59│    NetConfig {\n  60│        identity: Identity::generate(),\n  61│        relay: RelayPolicy::Disabled,\n    │...\n  67│\n *68│fn net_broker(name: &str, dir: &std::path::Path) -> Arc<Broker> {\n  69│    let host = NetHost::start(hermetic()).expect(\"net host start\");\n  70│    let broker =\n  71│        Broker::bind_in_with_net(name, dir.join(\"effects.log\"), Some(host)).expect(\"bind broker\");\n    │...\n  78│\n *79│fn connect_retry(name: &str) -> Brain {\n  80│    for _ in 0..300 {\n  81│        if let Ok(b) = Brain::cold_start(name, 1) {\n  82│            return b;\n    │...\n  90│/// actually expire, retried over broker start-up the same way.\n *91│fn connect_retry_pump(name: &str, io_timeout: Duration) -> Brain {\n  92│    for _ in 0..300 {\n  93│        if let Ok(b) =\n  94│            Brain::cold_start_pump(name, 1, io_timeout, spt_daemon::brain::PumpTrace::Stderr)\n    │...\n 102│\n*103│fn echo_spawn_req() -> SpawnReq {\n 104│    #[cfg(unix)]\n 105│    let (program, args) = (\"cat\".to_string(), Vec::<String>::new());\n 106│    #[cfg(windows)]\n    │...\n 138│/// same id twice is ONE stream served twice, never two streams sharing a number.\n*139│fn wait_for_stream(brain: &mut Brain, served: &[u64]) -> (u64, String) {\n 140│    for _ in 0..400 {\n 141│        let reply = brain.net_streams().expect(\"net-streams\");\n 142│        if let Some(s) = reply\n    │...\n 168│#[allow(clippy::too_many_arguments)]\n*169│fn attach_drive_detach(\n 170│    operator: &mut Brain,\n 171│    target_broker: &str,\n 172│    mut target: Brain,\n    │...\n 243│/// the rendered-through cursor (last accepted seq + 1).\n*244│fn render_until(\n 245│    brain: &mut Brain,\n 246│    stream_id: u64,\n 247│    decoder: &mut AttachDecoder,\n    │...\n 263│                        if seq < *next_seq {\n*264│                            continue; // replay duplicate — dedup by cursor\n 265│                        }\n 266│                        // #6 (ADR-0031): the initial batch is now a single synthesized\n 267│                        // repaint at pseudo-seq `log.next_seq - 1`, so the FIRST frame a\n    │...\n 286│/// Count non-overlapping occurrences of `needle` in `hay`.\n*287│fn count(hay: &[u8], needle: &[u8]) -> usize {\n 288│    if needle.is_empty() || hay.len() < needle.len() {\n 289│        return 0;\n 290│    }\n    │...\n 310│#[test]\n*311│fn loopback_self_dial_is_refused_local_uses_fallback_transport() {\n 312│    let _home = init_home();\n 313│    let dir = tempfile::tempdir().expect(\"tempdir\");\n 314│    let name = unique_name();\n    │...\n 338│#[test]\n*339│fn spt_hosted_bringup_then_cross_node_attach_drives_the_pty() {\n 340│    let _home = init_home();\n 341│    let dir = tempfile::tempdir().expect(\"tempdir\");\n 342│    let (name_a, name_b) = (unique_name(), unique_name());\n    │...\n 437│#[test]\n*438│fn remote_attach_drives_a_real_pty_cross_daemon() {\n 439│    let _home = init_home();\n 440│    let dir = tempfile::tempdir().expect(\"tempdir\");\n 441│    let (name_a, name_b) = (unique_name(), unique_name());\n    │...\n 493│#[test]\n*494│fn local_attach_via_loopback_conn_rides_the_same_pump() {\n 495│    let _home = init_home();\n 496│    let dir = tempfile::tempdir().expect(\"tempdir\");\n 497│    let name = unique_name();\n    │...\n 533│\n*534│// [unit->REQ-HAZARD-ENDPOINT-RUN-ATTACH-OUTPUT] the replay-vs-forward deadlock pin:\n 535│// when the session's OutputLog ring is ALREADY NON-EMPTY at attach (an\n 536│// already-producing session — exactly the endpoint-run shape, whose transient\n*537│// cold-start spawn conn drops after `Spawned`), `become_controller` replays MANY\n 538│// frames into the SERVING brain while `serve_attach` must forward each back to the\n 539│// operator. Before the two-conn split both rode ONE broker IPC connection, so the\n## attach_idempotent_replay.rs\n   7│//! breadcrumbs on an authorized same-seam `daemon refresh` (which FALSIFIED the\n  *8│//! presumed gen+1 mechanism): during post-cycle dispatcher replay the broker\n   9│//! processed the SAME conn / SAME identity / SAME generation subscribe twice,\n  10│//! 15 ms apart. ADR-0044's equal-generation rung classified that \"same lease,\n  11│//! silent re-take\" — correct — but re-take was `become_controller`, which\n    │...\n  13│//! synthesizes a fresh initial batch. Designed for a dead seat after a\n *14│//! dispatcher restart, it also fired against the same LIVE conn: the lease\n *15│//! killed its own writer and re-replayed history at the viewport.\n  16│//!\n  17│//! ## What this rig proves\n  18│//!\n    │...\n  20│//! then re-issues the IDENTICAL subscribe (same session, from_seq, intent, gen,\n *21│//! identity) — the dispatcher's double-serve. After that replay:\n  22│//!\n  23│//! 1. the seat still answers `Controller` (the wire vocabulary is unchanged —\n  24│//!    `idempotent` rides the breadcrumb only, so an N-1 peer sees what it\n  25│//!    always saw);\n *26│//! 2. NO history is re-delivered — a second initial batch would replay the\n  27│//!    bytes the viewport already has (the visible half of the field freeze);\n *28│//! 3. the ORIGINAL writer is still live: input sent AFTER the replay still\n  29│//!    echoes back on the same conn. A dropped seat's writer is\n  30│//!    channel-closed, and the viewport stops until a manual detach+re-attach.\n  31│//!\n    │...\n  45│//! The discriminating RED evidence is the unit matrix\n *46│//! (`broker::tests::equal_generation_same_conn_is_an_idempotent_replay`), which\n  47│//! asserts the seat's SINK IDENTITY and the unmoved `controller_epoch` and reds\n  48│//! immediately when the discriminator is removed — with the broker's own\n  49│//! breadcrumbs naming the mechanism: `controller-replaced ... new_conn=2` on\n    │...\n  53│//! The DIFFERENT-conn successor (ADR-0038 fix 6) is covered by\n *54│//! `controller_lease::equal_lease_replay_stays_silent_and_never_self_displaces`\n  55│//! and the redispatch/brain_swap suites — this rig must not be read as\n  56│//! narrowing that path.\n  57│//!\n    │...\n  64│//! only while echo #2 is still in flight — a live-stream byte with NO relation\n *65│//! to any replay. Measured on kitsubito (2026-07-23): a replay-removed control\n  66│//! arm reds this leg 12/13 serial and 93/120 under load, catching that echo #2\n  67│//! in the absence window; the shipped leg was serial-green ONLY because the\n *68│//! replay's `read_outcome` happened to discard echo #2 while awaiting\n  69│//! `Subscribed`, a coincidence load breaks. Hence the anchor drains to\n *70│//! quiescence BEFORE the replay (`drain_quiet`) and the post-replay window uses\n  71│//! the CAPTURING outcome read (`read_outcome_capturing`) — so the absence check\n  72│//! observes exactly what a viewport would, never a swallowed byte.\n  73│//!\n    │...\n  89│\n *90│fn init_home() -> TestHome {\n  91│    TestHome::new()\n  92│}\n  93│\n  94│static SEQ: AtomicU32 = AtomicU32::new(0);\n *95│fn unique_name() -> String {\n  96│    format!(\n *97│        \"spt-daemon-idemreplay-{}-{}.sock\",\n  98│        std::process::id(),\n  99│        SEQ.fetch_add(1, Ordering::Relaxed)\n 100│    )\n    │...\n 102│\n*103│fn connect_retry(name: &str) -> Brain {\n 104│    for _ in 0..300 {\n 105│        if let Ok(b) = Brain::cold_start(name, 1) {\n 106│            return b;\n    │...\n 114│/// key) so the real PTY submits and echoes them.\n*115│fn echo_spawn_req(endpoint: &str) -> SpawnReq {\n 116│    #[cfg(unix)]\n 117│    let (program, args) = (\"cat\".to_string(), Vec::<String>::new());\n 118│    #[cfg(windows)]\n    │...\n 133│\n*134│fn contains(hay: &[u8], needle: &[u8]) -> bool {\n 135│    hay.windows(needle.len()).any(|w| w == needle)\n 136│}\n 137│\n    │...\n 139│/// returning everything read.\n*140│fn pump_until(brain: &mut Brain, needle: &[u8], budget: Duration) -> Vec<u8> {\n 141│    let deadline = Instant::now() + budget;\n 142│    let mut seen = Vec::new();\n 143│    while Instant::now() < deadline {\n    │...\n 159│/// ends empty is the point).\n*160│fn collect_for(brain: &mut Brain, window: Duration) -> Vec<u8> {\n 161│    let deadline = Instant::now() + window;\n 162│    let mut seen = Vec::new();\n 163│    while Instant::now() < deadline {\n    │...\n 175│/// otherwise be indistinguishable from an absence.\n*176│fn read_outcome(brain: &mut Brain) -> SubscribeOutcome {\n 177│    let deadline = Instant::now() + Duration::from_secs(20);\n 178│    while Instant::now() < deadline {\n 179│        match brain.read_event_until(Some(deadline)) {\n## redispatch_stall.rs\n   4│//! retries × the broad `Err(_)` opener fallback manufacturing throwaway peek\n  *5│//! subscribers whose `StreamLog::attach` replayed the whole ring UNDER the\n   6│//! per-stream mutex against wedged conns — serial 15s bounded-write poison\n   7│//! windows (33 observed, all 15,000-15,154ms).\n   8│//!\n    │...\n  10│//! through the production broker subscribe path — gate ruling 1):\n *11│//!   - T1+T3 `wedged_subscriber_...`: replay + live fan-out halt bounded at\n  12│//!     the first failed write; the producer stays FLAT (never a serial poison\n *13│//!     composition); recovery replays gapless from the cursor.\n  14│//!   - T2 `opener_transient_...`: a transport-class opener failure requeues\n  15│//!     bounded and NEVER creates a peek subscriber (pre-fix: each retry\n *16│//!     subscribed + replayed against the conn).\n  17│//!   - T4 `poisoned_subscriber_cancels_...`: subscriber poison cancels the\n  18│//!     stream's serve lease — the paired forwarding leg terminates at its\n  19│//!     next send; a new subscriber generation renews and serves again.\n    │...\n  24│//!     (raw-close viewport, no FIN — the shape finished-row retirement cannot\n *25│//!     see) replayed by a fresh generation neither takes nor clears the live\n  26│//!     replacement controller (ownership/generation validation).\n  27│//!   - T7 `old_broker_fallback_...`: mixed-image N-1 with REAL\n  28│//!     traffic-carrying streams (doyle rider: handshake-only insufficient) —\n    │...\n  59│\n *60│fn init_home() -> TestHome {\n  61│    TestHome::new()\n  62│}\n  63│\n  64│static SEQ: AtomicU32 = AtomicU32::new(0);\n *65│fn unique_name() -> String {\n  66│    let n = SEQ.fetch_add(1, Ordering::Relaxed);\n  67│    format!(\"spt-daemon-rdstall-{}-{}.sock\", std::process::id(), n)\n  68│}\n  69│\n *70│fn hermetic() -> NetConfig {\n  71│    NetConfig {\n  72│        identity: Identity::generate(),\n  73│        relay: RelayPolicy::Disabled,\n    │...\n  79│\n *80│fn net_broker(name: &str, dir: &std::path::Path) -> Arc<Broker> {\n  81│    let host = NetHost::start(hermetic()).expect(\"net host start\");\n  82│    let broker =\n  83│        Broker::bind_in_with_net(name, dir.join(\"effects.log\"), Some(host)).expect(\"bind broker\");\n    │...\n  90│\n *91│fn connect_retry(name: &str) -> Brain {\n  92│    for _ in 0..300 {\n  93│        if let Ok(b) = Brain::cold_start(name, 1) {\n  94│            return b;\n    │...\n 100│\n*101│fn echo_spawn_req(endpoint: &str) -> SpawnReq {\n 102│    #[cfg(unix)]\n 103│    let (program, args) = (\"cat\".to_string(), Vec::<String>::new());\n 104│    #[cfg(windows)]\n    │...\n 152│/// The A-side peer-stream ids, via a probe brain.\n*153│fn peer_stream_ids(probe: &mut Brain) -> Vec<u64> {\n 154│    probe\n 155│        .net_streams()\n 156│        .expect(\"net-streams\")\n    │...\n 165│/// helper, verbatim). Returns whether an EOF for the stream arrived.\n*166│fn render_until(\n 167│    operator: &mut Brain,\n 168│    stream_id: u64,\n 169│    decoder: &mut AttachDecoder,\n    │...\n 212│\n*213│fn screen_of(viewport: &[u8]) -> String {\n 214│    let mut screen = ScreenGrid::new(24, 80);\n 215│    screen.advance(viewport);\n 216│    String::from_utf8_lossy(&screen.render_repaint()).into_owned()\n    │...\n 220│/// opener line. Returns (operator brain, B-side stream id, A-side stream id).\n*221│fn open_traffic_stream(\n 222│    _name_a: &str,\n 223│    name_b: &str,\n 224│    probe: &mut Brain,\n    │...\n 259│/// no-reinstall drain window (\"subscriber busy\" surfaces as an Error event),\n*260│/// then accumulate the replay until `want_bytes` bytes arrived. Asserts DENSE\n 261│/// seq contiguity from 0 (gapless) and returns the bytes.\n*262│fn drain_gapless(name_a: &str, sid_a: u64, want_bytes: usize, deadline: Duration) -> Vec<u8> {\n 263│    let end = Instant::now() + deadline;\n 264│    'attach: loop {\n 265│        assert!(\n    │...\n 288│                        seq, next,\n*289│                        \"the recovery replay must be DENSE from 0 — a gap means the \\\n 290│                         overflow/poison lost retained bytes\"\n 291│                    );\n 292│                    next += 1;\n    │...\n 321│// [int->REQ-STREAMLOG-SUBSCRIBER-DISCIPLINE]\n*322│// T1 (poisoned-replay halt) + T3 (producer latency flat), one incident on the\n 323│// production broker subscribe path: a REAL subscriber conn that attaches with\n*324│// a full ring and never reads — its seat's replay wedges on the named-pipe\n 325│// write, fails at the (shrunk, 400ms) bounded deadline, and HALTS: the seat\n 326│// is removed, later appends never re-feed it, and the PRODUCER — B's ack'd\n## redispatch.rs\n   5│//! exactly like a production brain death). NO manual re-serve anywhere: the\n  *6│//! pre-fix e2e (`attach_survives_target_brain_restart_exactly_once`)\n   7│//! hand-stepped a known stream and bypassed exactly the rediscovery/\n   8│//! classification seam that was broken in the field.\n   9│//!\n  10│//! - D1: a FINISHED historical Attach + a CURRENT active Attach, same\n *11│//!   endpoint/origin; restart the dispatcher generation only → the\n  12│//!   historical stream neither takes nor clears the current controller\n *13│//!   (post-restart input still renders; no EOF; no replay-storm log line;\n  14│//!   the retired row left the broker's enumeration).\n  15│//! - D2: an ACTIVE Attach whose opener rolled out of the bounded ring;\n *16│//!   restart the dispatcher → durable classification (the pinned opener)\n  17│//!   resumes the SAME operator stream.\n  18│//! - D3: ONE injected transient worker-start failure → the claim requeues\n  19│//!   and the retry serves the stream (no permanent abandonment, no\n    │...\n  44│/// Acquire a scoped temp home for one complete test body.\n *45│fn init_home() -> TestHome {\n  46│    TestHome::new()\n  47│}\n  48│\n  49│static SEQ: AtomicU32 = AtomicU32::new(0);\n *50│fn unique_name() -> String {\n  51│    let n = SEQ.fetch_add(1, Ordering::Relaxed);\n  52│    format!(\"spt-daemon-rdsp-{}-{}.sock\", std::process::id(), n)\n  53│}\n  54│\n *55│fn hermetic() -> NetConfig {\n  56│    NetConfig {\n  57│        identity: Identity::generate(),\n  58│        relay: RelayPolicy::Disabled,\n    │...\n  64│\n *65│fn net_broker(name: &str, dir: &std::path::Path) -> Arc<Broker> {\n  66│    let host = NetHost::start(hermetic()).expect(\"net host start\");\n  67│    let broker =\n  68│        Broker::bind_in_with_net(name, dir.join(\"effects.log\"), Some(host)).expect(\"bind broker\");\n    │...\n  75│\n *76│fn connect_retry(name: &str) -> Brain {\n  77│    for _ in 0..300 {\n  78│        if let Ok(b) = Brain::cold_start(name, 1) {\n  79│            return b;\n    │...\n  85│\n *86│fn echo_spawn_req(endpoint: &str) -> SpawnReq {\n  87│    #[cfg(unix)]\n  88│    let (program, args) = (\"cat\".to_string(), Vec::<String>::new());\n  89│    #[cfg(windows)]\n    │...\n 106│/// production `run_dispatch_loop` against `broker_name`. Killed = brain death\n*107│/// (worker conns drop). Stderr lands in `log` for replay-storm assertions.\n 108│struct Generation {\n 109│    child: Child,\n 110│    log: std::path::PathBuf,\n    │...\n 138│/// The A-side (target broker) peer-stream ids, via a probe brain.\n*139│fn peer_stream_ids(probe: &mut Brain) -> Vec<u64> {\n 140│    probe\n 141│        .net_streams()\n 142│        .expect(\"net-streams\")\n    │...\n 149│\n*150│/// Render the operator's viewport (dedup `Output` by seq — replays after a\n*151│/// generation restart re-transmit and are dropped at this cursor; a re-serve's\n 152│/// synthesized repaint may jump FORWARD, which is accepted and baselined)\n 153│/// until `needle` appears in the accumulated bytes, or panic at the deadline.\n 154│/// Returns `true` if an EOF for the stream arrived while rendering (the\n 155│/// steal-clears-controller symptom D1 must NOT see).\n*156│fn render_until(\n 157│    operator: &mut Brain,\n 158│    stream_id: u64,\n 159│    decoder: &mut AttachDecoder,\n    │...\n 184│                        if seq < *cursor {\n*185│                            continue; // replay duplicate — dedup at the render cursor\n 186│                        }\n 187│                        *cursor = seq + 1;\n 188│                        buf.extend_from_slice(\n    │...\n 202│\n*203│fn screen_of(viewport: &[u8]) -> String {\n 204│    let mut screen = ScreenGrid::new(24, 80);\n 205│    screen.advance(viewport);\n 206│    String::from_utf8_lossy(&screen.render_repaint()).into_owned()\n    │...\n 211│// active Attach on the same endpoint/origin; only the dispatcher generation\n*212│// restarts. The historical stream must neither take nor clear the current\n*213│// controller: post-restart input still renders (the frozen-PTY symptom is\n*214│// the failure), the operator sees NO EOF (the replayed-EOF detach is the"},"isError":false,"timestamp":1789524011799}}
{"type":"custom_message","customType":"irc:incoming","content":"<irc>\nIncoming IRC message from agent `ControllerDrainRca`:\n\nVerified conn17/70/88/104 all session1 stream1 by=c96d… attach_gen1789523756051; all SLOT_CLOSED cause=detach. Eviction token for 70/88/104 comes note_controller_write_retired (broker3824), not logical stall_evict: paired stream-sub-writer-poison + TimedOut shared gate. old_gen_drained excludes all by:Some even local-loopback RC. Need your narrow wait mechanism/discriminators, no replay implementation investigation overlap.\n\nSent while waiting/working. Active interruptible wait stopped early for immediate reading.\n\nIf response expected, reply via `hub` (`op: \"send\"`, `to: \"ControllerDrainRca\"`); may finish current step first. No one replies on your behalf.\n</irc>","display":true,"details":{"id":"158149a751ae71bb","from":"ControllerDrainRca","message":"Verified conn17/70/88/104 all session1 stream1 by=c96d… attach_gen1789523756051; all SLOT_CLOSED cause=detach. Eviction token for 70/88/104 comes note_controller_write_retired (broker3824), not logical stall_evict: paired stream-sub-writer-poison + TimedOut shared gate. old_gen_drained excludes all by:Some even local-loopback RC. Need your narrow wait mechanism/discriminators, no replay implementation investigation overlap."},"attribution":"agent","id":"6a0f5124","parentId":"4c53f97d","timestamp":"2026-09-16T02:00:04.166Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_wXoc9bvJjHcTeI6wRPYPLiCy|fc_09b01b5279447709016aa9f83801d087d2a5c2e882115bc95b","toolName":"read","startedAt":"2026-09-16T02:00:24.086Z","args":{"path":"crates/spt-daemon/src/nethost.rs:189-242,545-602,1888-1923"},"intent":"Reading replay and write ordering"},"id":"d5b3079c","parentId":"6a0f5124","timestamp":"2026-09-16T02:00:24.086Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_C02cdtZRFMs0FWUeZ4rKZr4F|fc_09b01b5279447709016aa9f83801e087d2b6aebc3808629068","toolName":"read","startedAt":"2026-09-16T02:00:24.086Z","args":{"path":"crates/spt-daemon/src/brain.rs:1063-1185,2511-2572"},"intent":"Reading brain output and sends"},"id":"b7b9e8d9","parentId":"d5b3079c","timestamp":"2026-09-16T02:00:24.086Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_Fqj8AKLRKtJg6cx8qmf3QQDv|fc_09b01b5279447709016aa9f83801e887d2800f3354a7b733fa","toolName":"read","startedAt":"2026-09-16T02:00:24.086Z","args":{"path":"crates/spt-daemon/src/broker.rs:9826-9886,8890-8952"},"intent":"Reading stream send and input ack"},"id":"30900775","parentId":"b7b9e8d9","timestamp":"2026-09-16T02:00:24.086Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_EtaADSAKpmKzZYwCzVeEvdej|fc_09b01b5279447709016aa9f83801ec87d2bbab72c09c4d0fdb","toolName":"read","startedAt":"2026-09-16T02:00:24.086Z","args":{"path":"crates/spt-daemon/src/resting.rs:402-470"},"intent":"Reading rest wake persistence"},"id":"eb180639","parentId":"30900775","timestamp":"2026-09-16T02:00:24.086Z"}
{"type":"message","id":"308342b3","parentId":"eb180639","timestamp":"2026-09-16T02:00:24.087Z","message":{"role":"assistant","content":[{"type":"thinking","thinking":"**Checking read-output acknowledgment**"},{"type":"toolCall","id":"call_wXoc9bvJjHcTeI6wRPYPLiCy|fc_09b01b5279447709016aa9f83801d087d2a5c2e882115bc95b","name":"read","arguments":{"i":"Reading replay and write ordering","path":"crates/spt-daemon/src/nethost.rs:189-242,545-602,1888-1923"},"intent":"Reading replay and write ordering"},{"type":"toolCall","id":"call_C02cdtZRFMs0FWUeZ4rKZr4F|fc_09b01b5279447709016aa9f83801e087d2b6aebc3808629068","name":"read","arguments":{"i":"Reading brain output and sends","path":"crates/spt-daemon/src/brain.rs:1063-1185,2511-2572"},"intent":"Reading brain output and sends"},{"type":"toolCall","id":"call_Fqj8AKLRKtJg6cx8qmf3QQDv|fc_09b01b5279447709016aa9f83801e887d2800f3354a7b733fa","name":"read","arguments":{"i":"Reading stream send and input ack","path":"crates/spt-daemon/src/broker.rs:9826-9886,8890-8952"},"intent":"Reading stream send and input ack"},{"type":"toolCall","id":"call_EtaADSAKpmKzZYwCzVeEvdej|fc_09b01b5279447709016aa9f83801ec87d2bbab72c09c4d0fdb","name":"read","arguments":{"i":"Reading rest wake persistence","path":"crates/spt-daemon/src/resting.rs:402-470"},"intent":"Reading rest wake persistence"},{"type":"toolCall","id":"call_BuApIczVqfAXrzcG9KoQjsbY|fc_09b01b5279447709016aa9f83801f887d2a3582ff39541b842","name":"read","arguments":{"i":"Reading retry classification","path":"crates/spt-daemon/src/dispatch.rs:373-386,503-552"},"intent":"Reading retry classification"}],"api":"openai-codex-responses","provider":"openai-codex","model":"gpt-6-astra","usage":{"input":19594,"output":247,"cacheRead":67072,"cacheWrite":0,"totalTokens":86913,"reasoningTokens":26,"cost":{"input":0.19594,"output":0.01235,"cacheRead":0.06707199999999999,"cacheWrite":0,"total":0.275362}},"stopReason":"toolUse","timestamp":1789524011827,"responseId":"resp_09b01b5279447709016aa9f82c0e1087d2b781bdf8c95c7280","providerPayload":{"type":"openaiResponsesHistory","provider":"openai-codex","dt":true,"items":[{"id":"rs_09b01b5279447709016aa9f82e2f8c87d2baa03ce4d687e0b3","type":"reasoning","content":[],"encrypted_content":"gAAAAABqqfg48rOfa71dhX1JDOyfoscH3Zem3Ue2fjAAoe7HVi20H9dQk0H8zUsbjF6kPC2IRefIUS7Ibp0tR5gHPqB_FaoE8FuxlOlWkrXH21J8enbF-2aXJEFYfE05jyjzww53a4JWZ5yfwY3MjUA7IalGkGErv7oq4kRlFnIHFgJA0cjL6m6_R0NvJ0-qejWW0aPpzR5jB5RvU33qOrUnz6C9eETCQq68qkUwPWK4R1CKajqdatJEP_55l_PgE8osrCXwXIZ8MQQxvYkqAvrXFJMJBTp4ql0zQOpL8S8EjUre8FqbQvfNN3snaXmv2NWg8Si8uSJDIHKwkNGkTdU-SZwO_NZWa_ejiKmJ5dVk8ctt1st_Bh7k2T_NT0LlHIBeSiEB08uhK5vTolmZlpnjGqnwkVqIw9Ip00LK3gq9QpUtOGFLAFGgVfrHHx9NXf3DGCz0uYixIfgX8ZDUZCPfpnsQGrYXRPkv3UVhI0p62AAAqYdXd49uRps_xuUkp8TtB9DDrKDTFgcnUp7DZRslJG370RtYKbmKXq80r4U1BG9KVPMxFdj_MsYb6XagGGIEO3-ef4COtNM_rpiOE5S80EHtZnjCD3yqL1-a336lErdvM8HfLPEtvM8NcaCaUqQ73sk3NYDrCDiJdP9RC3tOALubulTMDYi_foAY42nEUjuSTPgaO-7qWo1UPlrRckG6uIq6N1PC1YxfIXrEXzbR69LPgC_t_BKs4LGmk15u7svw1ux-YB2KctY52clj1snVjajC_cwwdxBTMIl3FzKYGThV6XPfvQ1T_m9DW9_1xBmShtJhdG134bbh38pKamhFw8w7CZcZsMxYRNKqT5Gadasw1fm0rDae_bS_fA1F21AuZvQS9XWns6sCRr3hB6t90jrNFnNe7EX1PICQCNIOsR_oadY69C_3rhzTF2lJH3Tj-TkIp1FXJAVKEg7iRtohR0OD2WHQYfkZAUlmfS69OqLOHqpcH1PyfW2WkjBZLkNH69HT7I4D8VdzjaOqzZQnADANDScuLsNOwVdjBQwVMktAOjSlMLJRuJ3uKmn8MPW_zYvRh0M72LTmA-_mcYBrYHY3uETEsIHow8vrP5H-I7BSawjQ8THvtqyDKebJLp8NZRY2YO1JMzvSH1_q5Onu-JnkYknBNuTPaEDgdFW8SjUFc98_yISR0VTaFPnKAhweJCDp1rriO7Da9X3aFmJW-zjHIZQ_Nsw0gkxbK03J53n-6jJoDIOlZxsu3nqyrizIPUYUlXbBkE_sohtlKpYdLRms9V1NaI2aEA7F06ygwleTmL2Q98TUVmW2f_Nsd4h-0QoGUiUDuYnwm3DXk-EdNxJ-Kd_E5LVp3Gkd71mfQ_yH8bPPW-v697yzkLUi4wNpGyItR0-82-D8SPfi7IoefDZ947DQBFqiokvuvUsv_JFkdgik54s6-JG9n_6a2ilhaXpHvxc=","internal_chat_message_metadata_passthrough":{"turn_id":"f878fb4b-0d9a-4a17-adc6-f6c9f4deeea0"},"summary":[{"type":"summary_text","text":"**Checking read-output acknowledgment**"}],"metadata":{"turn_id":"f878fb4b-0d9a-4a17-adc6-f6c9f4deeea0"}},{"id":"fc_09b01b5279447709016aa9f83801d087d2a5c2e882115bc95b","type":"function_call","status":"completed","arguments":"{\"i\":\"Reading replay and write ordering\",\"path\":\"crates/spt-daemon/src/nethost.rs:189-242,545-602,1888-1923\"}","call_id":"call_wXoc9bvJjHcTeI6wRPYPLiCy","internal_chat_message_metadata_passthrough":{"turn_id":"f878fb4b-0d9a-4a17-adc6-f6c9f4deeea0"},"name":"read","metadata":{"turn_id":"f878fb4b-0d9a-4a17-adc6-f6c9f4deeea0"}},{"id":"fc_09b01b5279447709016aa9f83801e087d2b6aebc3808629068","type":"function_call","status":"completed","arguments":"{\"i\":\"Reading brain output and sends\",\"path\":\"crates/spt-daemon/src/brain.rs:1063-1185,2511-2572\"}","call_id":"call_C02cdtZRFMs0FWUeZ4rKZr4F","internal_chat_message_metadata_passthrough":{"turn_id":"f878fb4b-0d9a-4a17-adc6-f6c9f4deeea0"},"name":"read","metadata":{"turn_id":"f878fb4b-0d9a-4a17-adc6-f6c9f4deeea0"}},{"id":"fc_09b01b5279447709016aa9f83801e887d2800f3354a7b733fa","type":"function_call","status":"completed","arguments":"{\"i\":\"Reading stream send and input ack\",\"path\":\"crates/spt-daemon/src/broker.rs:9826-9886,8890-8952\"}","call_id":"call_Fqj8AKLRKtJg6cx8qmf3QQDv","internal_chat_message_metadata_passthrough":{"turn_id":"f878fb4b-0d9a-4a17-adc6-f6c9f4deeea0"},"name":"read","metadata":{"turn_id":"f878fb4b-0d9a-4a17-adc6-f6c9f4deeea0"}},{"id":"fc_09b01b5279447709016aa9f83801ec87d2bbab72c09c4d0fdb","type":"function_call","status":"completed","arguments":"{\"i\":\"Reading rest wake persistence\",\"path\":\"crates/spt-daemon/src/resting.rs:402-470\"}","call_id":"call_EtaADSAKpmKzZYwCzVeEvdej","internal_chat_message_metadata_passthrough":{"turn_id":"f878fb4b-0d9a-4a17-adc6-f6c9f4deeea0"},"name":"read","metadata":{"turn_id":"f878fb4b-0d9a-4a17-adc6-f6c9f4deeea0"}},{"id":"fc_09b01b5279447709016aa9f83801f887d2a3582ff39541b842","type":"function_call","status":"completed","arguments":"{\"i\":\"Reading retry classification\",\"path\":\"crates/spt-daemon/src/dispatch.rs:373-386,503-552\"}","call_id":"call_BuApIczVqfAXrzcG9KoQjsbY","internal_chat_message_metadata_passthrough":{"turn_id":"f878fb4b-0d9a-4a17-adc6-f6c9f4deeea0"},"name":"read","metadata":{"turn_id":"f878fb4b-0d9a-4a17-adc6-f6c9f4deeea0"}}]},"duration":12256.062200000044,"ttft":2384.726800000062,"completedAt":1789524024084,"contextSnapshot":{"promptTokens":86666,"nonMessageTokens":10480,"compactionEpoch":0}}}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_BuApIczVqfAXrzcG9KoQjsbY|fc_09b01b5279447709016aa9f83801f887d2a3582ff39541b842","toolName":"read","startedAt":"2026-09-16T02:00:24.087Z","args":{"path":"crates/spt-daemon/src/dispatch.rs:373-386,503-552"},"intent":"Reading retry classification"},"id":"ca7571b2","parentId":"308342b3","timestamp":"2026-09-16T02:00:24.087Z"}
{"type":"message","id":"5de80a4a","parentId":"ca7571b2","timestamp":"2026-09-16T02:00:24.105Z","message":{"role":"toolResult","toolCallId":"call_wXoc9bvJjHcTeI6wRPYPLiCy|fc_09b01b5279447709016aa9f83801d087d2a5c2e882115bc95b","toolName":"read","content":[{"type":"text","text":"    fn install(\n        sub: SharedSend,\n        replay: Vec<Envelope>,\n        lease: Option<Arc<StreamLease>>,\n        label: &str,\n    ) -> SubscriberSeat {\n        let (tx, rx) = std::sync::mpsc::sync_channel::<Envelope>(SUBSCRIBER_QUEUE_CAP);\n        let done = Arc::new(std::sync::atomic::AtomicBool::new(false));\n        let poisoned = Arc::new(std::sync::atomic::AtomicBool::new(false));\n        let writer_sub = Arc::clone(&sub);\n        let writer_done = Arc::clone(&done);\n        let writer_poisoned = Arc::clone(&poisoned);\n        // NAMED (ADR-0040 decision 7): the hertz field census found ~546 of\n        // 589 broker threads unnamed — nearly all parked seat writers. A\n        // census must attribute, not infer.\n        // [impl->REQ-SEAT-LIFETIME-BOUNDED]\n        let writer = std::thread::Builder::new()\n            .name(format!(\"sub-writer-{label}\"))\n            .spawn(move || {\n                let poison = |halt_reason: &str| {\n                    writer_poisoned.store(true, Ordering::Release);\n                    if let Some(l) = &lease {\n                        l.cancel();\n                    }\n                    writer_sub.lifecycle_event(\"stream-sub-writer-poison\", halt_reason);\n                };\n                // Replay first — halt at the first failed write (Amendment\n                // fix 2), never iterate past a poisoned conn.\n                for frame in replay {\n                    if writer_sub.write(&frame).is_err() {\n                        poison(\"replay write failed\");\n                        writer_done.store(true, Ordering::Release);\n                        return;\n                    }\n                }\n                // Then live frames, same halt discipline.\n                while let Ok(frame) = rx.recv() {\n                    if writer_sub.write(&frame).is_err() {\n                        poison(\"live write failed\");\n                        break;\n                    }\n                }\n                writer_done.store(true, Ordering::Release);\n            })\n            .expect(\"spawn seat writer thread\");\n        SubscriberSeat {\n            sub,\n            tx,\n            done,\n            poisoned,\n            writer: Some(writer),\n        }\n    }\n\n…\n    fn begin_attach(&mut self, sub: SharedSend, from_seq: u64) -> io::Result<usize> {\n        if let Some(prior) = &self.subscriber {\n            // No-reinstall-until-gone applies to the POISON class only\n            // (REQ-DISPATCH-FALLBACK-CIRCUIT): a wedged writer may sit in a\n            // 15s bounded write — installing a replacement now would hand the\n            // retry machinery a fresh replay victim. A HEALTHY prior seat is\n            // DISPLACED as before (the newer-brain-takes-over contract).\n            if prior.poisoned.load(Ordering::Acquire) && !prior.gone() && !prior.is(&sub) {\n                return Err(io::Error::new(\n                    io::ErrorKind::WouldBlock,\n                    format!(\n                        \"stream {} subscriber busy: prior subscriber still draining\",\n                        self.stream_id\n                    ),\n                ));\n            }\n            // Healthy displacement, prior fully gone, or same sub re-attach.\n            self.subscriber = None;\n        }\n        // Attribution (F-039 legs b+d): stream-subscriber role fact + attach\n        // record — this is one of the two RCA-pinned shared-carrier classes.\n        // [impl->REQ-CONN-POISON-ATTRIBUTION]\n        sub.describe(&format!(\"stream-subscriber stream={}\", self.stream_id));\n        sub.lifecycle_event(\n            \"stream-sub-attach\",\n            &format!(\"stream={} from_seq={from_seq}\", self.stream_id),\n        );\n        let mut replay: Vec<Envelope> = self\n            .ring\n            .iter()\n            .filter(|(s, _)| *s >= from_seq)\n            .map(|(seq, bytes)| net_stream_data_envelope(self.stream_id, *seq, bytes))\n            .collect();\n        if self.finished {\n            replay.push(net_stream_eof_envelope(self.stream_id, self.next_seq));\n        }\n        // Mint a FRESH lease at EVERY install (Amendment fix 4 + gate round 1\n        // on the fix PR): each subscriber generation gets its OWN Arc, and a\n        // prior writer — poisoned OR healthily displaced — holds only its own\n        // generation's handle. Renewal-on-canceled alone was WRONG: a healthy\n        // brain-swap displacement left the displaced writer and the successor\n        // SHARING one Arc, so the displaced writer's eventual queued-frame\n        // write failure (its conn dying — every daemon refresh) canceled the\n        // SUCCESSOR's lease: a spurious serve-kill + breaker trip per\n        // displaced stream on exactly the post-refresh path this wave calms.\n        // One poison never dead-ends the stream (T5 recovery): the next\n        // generation's mint IS the renewal; `send_stream` reads this current\n        // Arc, old workers' handles stay theirs (C2 consumes via\n        // [`NetHost::stream_lease`]).\n        // [impl->REQ-STREAMLOG-SUBSCRIBER-DISCIPLINE]\n        self.lease = Arc::new(StreamLease::default());\n        let replay_len = replay.len();\n        self.subscriber = Some(SubscriberSeat::install(\n            sub,\n            replay,\n            Some(Arc::clone(&self.lease)),\n            &format!(\"s{}\", self.stream_id),\n        ));\n…\n    }\n…\n    pub fn send_stream(&self, stream_id: u64, bytes: &[u8], finish: bool) -> io::Result<()> {\n        let entry = {\n            let streams = self.shared.streams.lock().unwrap();\n            Arc::clone(streams.get(&stream_id).ok_or_else(|| {\n                io::Error::new(\n                    io::ErrorKind::NotFound,\n                    format!(\"no such stream {stream_id}\"),\n                )\n            })?)\n        };\n        // Serve-lease gate (ADR-0038 Amendment fix 4): a stream whose\n        // subscriber POISONED has its lease canceled — refusing the send here\n        // is what terminates the paired serve/wire worker at its next\n        // forward instead of leaving an orphan forwarding leg running.\n        // [impl->REQ-STREAMLOG-SUBSCRIBER-DISCIPLINE]\n        if entry.log.lock().unwrap().lease.is_canceled() {\n            return Err(io::Error::other(format!(\n                \"stream {stream_id} lease canceled (subscriber poisoned) — serve leg terminated\"\n            )));\n        }\n        let bytes = bytes.to_vec();\n        // Bounded (REQ-HAZARD-BROKER-QUIC-DEADLINE): `write_all` / `finish` on a\n        // black-holed QUIC stream blocks on flow-control the dead peer never grants.\n        // Loopback (in-process) never hangs, so the bound is a no-op for it.\n        self.bounded_block_on(async move {\n            let mut send = entry.send.lock().await;\n            if !bytes.is_empty() {\n                send.write_all(&bytes).await?;\n            }\n            if finish {\n                send.finish().await?;\n            }\n            Ok(())\n        })\n    }\n"}],"details":{"displayContent":{"text":"    fn install(\n        sub: SharedSend,\n        replay: Vec<Envelope>,\n        lease: Option<Arc<StreamLease>>,\n        label: &str,\n    ) -> SubscriberSeat {\n        let (tx, rx) = std::sync::mpsc::sync_channel::<Envelope>(SUBSCRIBER_QUEUE_CAP);\n        let done = Arc::new(std::sync::atomic::AtomicBool::new(false));\n        let poisoned = Arc::new(std::sync::atomic::AtomicBool::new(false));\n        let writer_sub = Arc::clone(&sub);\n        let writer_done = Arc::clone(&done);\n        let writer_poisoned = Arc::clone(&poisoned);\n        // NAMED (ADR-0040 decision 7): the hertz field census found ~546 of\n        // 589 broker threads unnamed — nearly all parked seat writers. A\n        // census must attribute, not infer.\n        // [impl->REQ-SEAT-LIFETIME-BOUNDED]\n        let writer = std::thread::Builder::new()\n            .name(format!(\"sub-writer-{label}\"))\n            .spawn(move || {\n                let poison = |halt_reason: &str| {\n                    writer_poisoned.store(true, Ordering::Release);\n                    if let Some(l) = &lease {\n                        l.cancel();\n                    }\n                    writer_sub.lifecycle_event(\"stream-sub-writer-poison\", halt_reason);\n                };\n                // Replay first — halt at the first failed write (Amendment\n                // fix 2), never iterate past a poisoned conn.\n                for frame in replay {\n                    if writer_sub.write(&frame).is_err() {\n                        poison(\"replay write failed\");\n                        writer_done.store(true, Ordering::Release);\n                        return;\n                    }\n                }\n                // Then live frames, same halt discipline.\n                while let Ok(frame) = rx.recv() {\n                    if writer_sub.write(&frame).is_err() {\n                        poison(\"live write failed\");\n                        break;\n                    }\n                }\n                writer_done.store(true, Ordering::Release);\n            })\n            .expect(\"spawn seat writer thread\");\n        SubscriberSeat {\n            sub,\n            tx,\n            done,\n            poisoned,\n            writer: Some(writer),\n        }\n    }\n\n…\n    fn begin_attach(&mut self, sub: SharedSend, from_seq: u64) -> io::Result<usize> {\n        if let Some(prior) = &self.subscriber {\n            // No-reinstall-until-gone applies to the POISON class only\n            // (REQ-DISPATCH-FALLBACK-CIRCUIT): a wedged writer may sit in a\n            // 15s bounded write — installing a replacement now would hand the\n            // retry machinery a fresh replay victim. A HEALTHY prior seat is\n            // DISPLACED as before (the newer-brain-takes-over contract).\n            if prior.poisoned.load(Ordering::Acquire) && !prior.gone() && !prior.is(&sub) {\n                return Err(io::Error::new(\n                    io::ErrorKind::WouldBlock,\n                    format!(\n                        \"stream {} subscriber busy: prior subscriber still draining\",\n                        self.stream_id\n                    ),\n                ));\n            }\n            // Healthy displacement, prior fully gone, or same sub re-attach.\n            self.subscriber = None;\n        }\n        // Attribution (F-039 legs b+d): stream-subscriber role fact + attach\n        // record — this is one of the two RCA-pinned shared-carrier classes.\n        // [impl->REQ-CONN-POISON-ATTRIBUTION]\n        sub.describe(&format!(\"stream-subscriber stream={}\", self.stream_id));\n        sub.lifecycle_event(\n            \"stream-sub-attach\",\n            &format!(\"stream={} from_seq={from_seq}\", self.stream_id),\n        );\n        let mut replay: Vec<Envelope> = self\n            .ring\n            .iter()\n            .filter(|(s, _)| *s >= from_seq)\n            .map(|(seq, bytes)| net_stream_data_envelope(self.stream_id, *seq, bytes))\n            .collect();\n        if self.finished {\n            replay.push(net_stream_eof_envelope(self.stream_id, self.next_seq));\n        }\n        // Mint a FRESH lease at EVERY install (Amendment fix 4 + gate round 1\n        // on the fix PR): each subscriber generation gets its OWN Arc, and a\n        // prior writer — poisoned OR healthily displaced — holds only its own\n        // generation's handle. Renewal-on-canceled alone was WRONG: a healthy\n        // brain-swap displacement left the displaced writer and the successor\n        // SHARING one Arc, so the displaced writer's eventual queued-frame\n        // write failure (its conn dying — every daemon refresh) canceled the\n        // SUCCESSOR's lease: a spurious serve-kill + breaker trip per\n        // displaced stream on exactly the post-refresh path this wave calms.\n        // One poison never dead-ends the stream (T5 recovery): the next\n        // generation's mint IS the renewal; `send_stream` reads this current\n        // Arc, old workers' handles stay theirs (C2 consumes via\n        // [`NetHost::stream_lease`]).\n        // [impl->REQ-STREAMLOG-SUBSCRIBER-DISCIPLINE]\n        self.lease = Arc::new(StreamLease::default());\n        let replay_len = replay.len();\n        self.subscriber = Some(SubscriberSeat::install(\n            sub,\n            replay,\n            Some(Arc::clone(&self.lease)),\n            &format!(\"s{}\", self.stream_id),\n        ));\n…\n    }\n…\n    pub fn send_stream(&self, stream_id: u64, bytes: &[u8], finish: bool) -> io::Result<()> {\n        let entry = {\n            let streams = self.shared.streams.lock().unwrap();\n            Arc::clone(streams.get(&stream_id).ok_or_else(|| {\n                io::Error::new(\n                    io::ErrorKind::NotFound,\n                    format!(\"no such stream {stream_id}\"),\n                )\n            })?)\n        };\n        // Serve-lease gate (ADR-0038 Amendment fix 4): a stream whose\n        // subscriber POISONED has its lease canceled — refusing the send here\n        // is what terminates the paired serve/wire worker at its next\n        // forward instead of leaving an orphan forwarding leg running.\n        // [impl->REQ-STREAMLOG-SUBSCRIBER-DISCIPLINE]\n        if entry.log.lock().unwrap().lease.is_canceled() {\n            return Err(io::Error::other(format!(\n                \"stream {stream_id} lease canceled (subscriber poisoned) — serve leg terminated\"\n            )));\n        }\n        let bytes = bytes.to_vec();\n        // Bounded (REQ-HAZARD-BROKER-QUIC-DEADLINE): `write_all` / `finish` on a\n        // black-holed QUIC stream blocks on flow-control the dead peer never grants.\n        // Loopback (in-process) never hangs, so the bound is a no-op for it.\n        self.bounded_block_on(async move {\n            let mut send = entry.send.lock().await;\n            if !bytes.is_empty() {\n                send.write_all(&bytes).await?;\n            }\n            if finish {\n                send.finish().await?;\n            }\n            Ok(())\n        })\n    }\n","startLine":189,"lineNumbers":[189,190,191,192,193,194,195,196,197,198,199,200,201,202,203,204,205,206,207,208,209,210,211,212,213,214,215,216,217,218,219,220,221,222,223,224,225,226,227,228,229,230,231,232,233,234,235,236,237,238,239,240,241,242,null,545,546,547,548,549,550,551,552,553,554,555,556,557,558,559,560,561,562,563,564,565,566,567,568,569,570,571,572,573,574,575,576,577,578,579,580,581,582,583,584,585,586,587,588,589,590,591,592,593,594,595,596,597,598,599,600,601,602,null,604,null,1888,1889,1890,1891,1892,1893,1894,1895,1896,1897,1898,1899,1900,1901,1902,1903,1904,1905,1906,1907,1908,1909,1910,1911,1912,1913,1914,1915,1916,1917,1918,1919,1920,1921,1922,1923]},"fileSize":160950,"meta":{"source":{"type":"path","value":"C:\\Users\\decid\\Documents\\projects\\spt-core\\crates\\spt-daemon\\src\\nethost.rs"}}},"isError":false,"timestamp":1789524024105}}
{"type":"message","id":"7b81e4b2","parentId":"5de80a4a","timestamp":"2026-09-16T02:00:24.113Z","message":{"role":"toolResult","toolCallId":"call_EtaADSAKpmKzZYwCzVeEvdej|fc_09b01b5279447709016aa9f83801ec87d2bbab72c09c4d0fdb","toolName":"read","content":[{"type":"text","text":"// [impl->REQ-INST-3]\npub fn daemon_rest_event(\n    id: &str,\n    event: RestEvent,\n    node_auto_suspend_ms: Option<u64>,\n) -> Result<Option<EdgeReport>, String> {\n    daemon_rest_event_with_liveness(id, event, node_auto_suspend_ms, None)\n}\n\n/// [`daemon_rest_event`] with the ONE-liveness-authority override (ADR-0041\n/// decision 6): the SHUTDOWN verb passes `Some(true)` when the broker holds a\n/// genuinely-live (non-zombie) session for `id`, so its Suspend edge answers\n/// from the same truth `endpoint run`'s dup-guard consults — never a NO_EDGE\n/// about an endpoint the run verb calls ALREADY_LIVE.\n// [impl->REQ-ENDPOINT-CYCLE-HONEST]\npub fn daemon_rest_event_with_liveness(\n    id: &str,\n    event: RestEvent,\n    node_auto_suspend_ms: Option<u64>,\n    alive_hint: Option<bool>,\n) -> Result<Option<EdgeReport>, String> {\n    let perch_path = perch::resolve_perch_path(id, ParentHint::Infer);\n    let report = apply_event_with_liveness(\n        &perch_path,\n        event,\n        node_auto_suspend_ms,\n        now_ms(),\n        || {\n            arm_transition_echo(id);\n            Ok(())\n        },\n        || fire_wake_effects(id),\n        alive_hint,\n    )?;\n    if let Some(r) = report {\n        cascade_shells_on_edge(id, &r);\n        // A real rest edge changes the advertised state — wake the pump's\n        // registry leg so peers render it within seconds, not a cadence\n        // (M8 decision 15, REQ-CONV-2).\n        // [impl->REQ-CONV-2]\n        crate::registryhost::request_advertise_now();\n    }\n    Ok(report)\n}\n\n/// The shell leg of a rest edge (M5-D4a, REQ-SHELL-2): owner → suspended\n/// closes its online shells (per-shell ephemeral/persistent divergence);\n/// owner → active relaunches its `persistent` offline shells. Shared by both\n/// transition hosts ([`daemon_rest_event`] + `BrainLifecycle::rest_event`),\n/// best-effort beside the echo gate + wake effects — a shell failure is loud\n/// on stderr but never wedges the (already persisted) rest state. An edge\n/// whose echo errs skips the cascade with the early return; the D4b\n/// reconciler is the catch-up for that rare gap.\n// [impl->REQ-SHELL-2]\npub(crate) fn cascade_shells_on_edge(owner: &str, report: &EdgeReport) {\n    let to_suspended = report.to == RestState::Suspended;\n    let to_active = report.to == RestState::Active && report.from != RestState::Active;\n    if !to_suspended && !to_active {\n        return;\n    }\n    let adapters_dir = spt_store::perch::adapters_dir();\n    let registered = spt_runtime::registry::registered(&adapters_dir);\n    for failure in crate::shellhost::cascade_owner_edge(\n        &perch::owlery_dir(),\n        owner,\n        &registered,\n        &adapters_dir,\n        to_suspended,\n        to_active,\n    ) {\n        spt_proto::emit_line_err!(\"SHELL_CASCADE_WARN:{owner}: {failure}\");\n    }\n}\n\n[Showing lines 401-473 of 1467. Use :474 to continue]"}],"details":{"truncation":{"content":"// [impl->REQ-INST-3]\r\npub fn daemon_rest_event(\r\n    id: &str,\r\n    event: RestEvent,\r\n    node_auto_suspend_ms: Option<u64>,\r\n) -> Result<Option<EdgeReport>, String> {\r\n    daemon_rest_event_with_liveness(id, event, node_auto_suspend_ms, None)\r\n}\r\n\r\n/// [`daemon_rest_event`] with the ONE-liveness-authority override (ADR-0041\r\n/// decision 6): the SHUTDOWN verb passes `Some(true)` when the broker holds a\r\n/// genuinely-live (non-zombie) session for `id`, so its Suspend edge answers\r\n/// from the same truth `endpoint run`'s dup-guard consults — never a NO_EDGE\r\n/// about an endpoint the run verb calls ALREADY_LIVE.\r\n// [impl->REQ-ENDPOINT-CYCLE-HONEST]\r\npub fn daemon_rest_event_with_liveness(\r\n    id: &str,\r\n    event: RestEvent,\r\n    node_auto_suspend_ms: Option<u64>,\r\n    alive_hint: Option<bool>,\r\n) -> Result<Option<EdgeReport>, String> {\r\n    let perch_path = perch::resolve_perch_path(id, ParentHint::Infer);\r\n    let report = apply_event_with_liveness(\r\n        &perch_path,\r\n        event,\r\n        node_auto_suspend_ms,\r\n        now_ms(),\r\n        || {\r\n            arm_transition_echo(id);\r\n            Ok(())\r\n        },\r\n        || fire_wake_effects(id),\r\n        alive_hint,\r\n    )?;\r\n    if let Some(r) = report {\r\n        cascade_shells_on_edge(id, &r);\r\n        // A real rest edge changes the advertised state — wake the pump's\r\n        // registry leg so peers render it within seconds, not a cadence\r\n        // (M8 decision 15, REQ-CONV-2).\r\n        // [impl->REQ-CONV-2]\r\n        crate::registryhost::request_advertise_now();\r\n    }\r\n    Ok(report)\r\n}\r\n\r\n/// The shell leg of a rest edge (M5-D4a, REQ-SHELL-2): owner → suspended\r\n/// closes its online shells (per-shell ephemeral/persistent divergence);\r\n/// owner → active relaunches its `persistent` offline shells. Shared by both\r\n/// transition hosts ([`daemon_rest_event`] + `BrainLifecycle::rest_event`),\r\n/// best-effort beside the echo gate + wake effects — a shell failure is loud\r\n/// on stderr but never wedges the (already persisted) rest state. An edge\r\n/// whose echo errs skips the cascade with the early return; the D4b\r\n/// reconciler is the catch-up for that rare gap.\r\n// [impl->REQ-SHELL-2]\r\npub(crate) fn cascade_shells_on_edge(owner: &str, report: &EdgeReport) {\r\n    let to_suspended = report.to == RestState::Suspended;\r\n    let to_active = report.to == RestState::Active && report.from != RestState::Active;\r\n    if !to_suspended && !to_active {\r\n        return;\r\n    }\r\n    let adapters_dir = spt_store::perch::adapters_dir();\r\n    let registered = spt_runtime::registry::registered(&adapters_dir);\r\n    for failure in crate::shellhost::cascade_owner_edge(\r\n        &perch::owlery_dir(),\r\n        owner,\r\n        &registered,\r\n        &adapters_dir,\r\n        to_suspended,\r\n        to_active,\r\n    ) {\r\n        spt_proto::emit_line_err!(\"SHELL_CASCADE_WARN:{owner}: {failure}\");\r\n    }\r\n}\r","truncated":true,"truncatedBy":"lines","totalLines":1067,"totalBytes":2907,"outputLines":73,"outputBytes":2907,"lastLinePartial":false,"firstLineExceedsLimit":false},"totalLines":1467,"displayContent":{"text":"// [impl->REQ-INST-3]\r\npub fn daemon_rest_event(\r\n    id: &str,\r\n    event: RestEvent,\r\n    node_auto_suspend_ms: Option<u64>,\r\n) -> Result<Option<EdgeReport>, String> {\r\n    daemon_rest_event_with_liveness(id, event, node_auto_suspend_ms, None)\r\n}\r\n\r\n/// [`daemon_rest_event`] with the ONE-liveness-authority override (ADR-0041\r\n/// decision 6): the SHUTDOWN verb passes `Some(true)` when the broker holds a\r\n/// genuinely-live (non-zombie) session for `id`, so its Suspend edge answers\r\n/// from the same truth `endpoint run`'s dup-guard consults — never a NO_EDGE\r\n/// about an endpoint the run verb calls ALREADY_LIVE.\r\n// [impl->REQ-ENDPOINT-CYCLE-HONEST]\r\npub fn daemon_rest_event_with_liveness(\r\n    id: &str,\r\n    event: RestEvent,\r\n    node_auto_suspend_ms: Option<u64>,\r\n    alive_hint: Option<bool>,\r\n) -> Result<Option<EdgeReport>, String> {\r\n    let perch_path = perch::resolve_perch_path(id, ParentHint::Infer);\r\n    let report = apply_event_with_liveness(\r\n        &perch_path,\r\n        event,\r\n        node_auto_suspend_ms,\r\n        now_ms(),\r\n        || {\r\n            arm_transition_echo(id);\r\n            Ok(())\r\n        },\r\n        || fire_wake_effects(id),\r\n        alive_hint,\r\n    )?;\r\n    if let Some(r) = report {\r\n        cascade_shells_on_edge(id, &r);\r\n        // A real rest edge changes the advertised state — wake the pump's\r\n        // registry leg so peers render it within seconds, not a cadence\r\n        // (M8 decision 15, REQ-CONV-2).\r\n        // [impl->REQ-CONV-2]\r\n        crate::registryhost::request_advertise_now();\r\n    }\r\n    Ok(report)\r\n}\r\n\r\n/// The shell leg of a rest edge (M5-D4a, REQ-SHELL-2): owner → suspended\r\n/// closes its online shells (per-shell ephemeral/persistent divergence);\r\n/// owner → active relaunches its `persistent` offline shells. Shared by both\r\n/// transition hosts ([`daemon_rest_event`] + `BrainLifecycle::rest_event`),\r\n/// best-effort beside the echo gate + wake effects — a shell failure is loud\r\n/// on stderr but never wedges the (already persisted) rest state. An edge\r\n/// whose echo errs skips the cascade with the early return; the D4b\r\n/// reconciler is the catch-up for that rare gap.\r\n// [impl->REQ-SHELL-2]\r\npub(crate) fn cascade_shells_on_edge(owner: &str, report: &EdgeReport) {\r\n    let to_suspended = report.to == RestState::Suspended;\r\n    let to_active = report.to == RestState::Active && report.from != RestState::Active;\r\n    if !to_suspended && !to_active {\r\n        return;\r\n    }\r\n    let adapters_dir = spt_store::perch::adapters_dir();\r\n    let registered = spt_runtime::registry::registered(&adapters_dir);\r\n    for failure in crate::shellhost::cascade_owner_edge(\r\n        &perch::owlery_dir(),\r\n        owner,\r\n        &registered,\r\n        &adapters_dir,\r\n        to_suspended,\r\n        to_active,\r\n    ) {\r\n        spt_proto::emit_line_err!(\"SHELL_CASCADE_WARN:{owner}: {failure}\");\r\n    }\r\n}\r","startLine":401,"lineNumbers":[401,402,403,404,405,406,407,408,409,410,411,412,413,414,415,416,417,418,419,420,421,422,423,424,425,426,427,428,429,430,431,432,433,434,435,436,437,438,439,440,441,442,443,444,445,446,447,448,449,450,451,452,453,454,455,456,457,458,459,460,461,462,463,464,465,466,467,468,469,470,471,472,473]},"fileSize":64088,"meta":{"source":{"type":"path","value":"C:\\Users\\decid\\Documents\\projects\\spt-core\\crates\\spt-daemon\\src\\resting.rs"},"truncation":{"direction":"head","truncatedBy":"lines","totalLines":1467,"totalBytes":2907,"outputLines":73,"outputBytes":2907,"shownRange":{"start":401,"end":473},"nextOffset":474}}},"isError":false,"timestamp":1789524024113}}
{"type":"message","id":"d4e5fb2b","parentId":"7b81e4b2","timestamp":"2026-09-16T02:00:24.116Z","message":{"role":"toolResult","toolCallId":"call_C02cdtZRFMs0FWUeZ4rKZr4F|fc_09b01b5279447709016aa9f83801e087d2b6aebc3808629068","toolName":"read","content":[{"type":"text","text":"    pub fn read_event_until(&mut self, deadline: Option<Instant>) -> io::Result<BrokerEvent> {\n        loop {\n            let env = self.read_frame_until(deadline)?;\n            match env.kind.as_str() {\n                KIND_OUTPUT => {\n                    let ev: OutputEvent = serde_json::from_value(env.payload)\n                        .map_err(|e| io::Error::new(io::ErrorKind::InvalidData, e))?;\n                    // A **resume-mode** brain (the per-session map is populated by\n                    // `resume_sessions`) routes EVERY session through the map —\n                    // including a freshly-spawned or first-seen one, which seeds\n                    // itself at its first `seq` via `entry().or_insert` (D4-2b,\n                    // doyle amendment 5: this closes the mixed-mode gap where N≥2\n                    // fresh spawns would otherwise share the single `next_seq` and\n                    // silently drop the later sessions' seq-0 output). The broker's\n                    // `Mutex<OutputLog>`-held wire order guarantees first-sight of a\n                    // new session IS seq 0, so the seed == 0 for a spawn; a resumed\n                    // session already holds its `resume_seq` seed (the `entry`\n                    // returns it, so the boundary-dedup still applies). Discipline:\n                    // **dedup-below + snap-above, NO reject-gap** — drop an\n                    // already-delivered seq (the at-least-once boundary re-send),\n                    // accept-and-snap everything `>= cursor` (the contiguous case\n                    // AND a post-eviction ring-floor jump, which the broker's\n                    // non-reordering replay makes the only legitimate forward jump).\n                    if !self.session_cursors.is_empty() {\n                        let cursor = self.session_cursors.entry(ev.session_id).or_insert(ev.seq);\n                        if ev.seq < *cursor {\n                            // Replay duplicate / boundary re-send — dedup. A FLAGGED\n                            // backward frame (a replayed old sync frame) dedups the\n                            // same way: NEVER a backward baseline — a rewind would\n                            // re-accept replayed frames (the wire-flag ruling's\n                            // forward-only pin, REQ-RC-RESIZE-PRESENTATION-BARRIER).\n                            continue;\n                        }\n                        *cursor = ev.seq + 1;\n                        let bytes = decode_bytes(&ev.data_b64)\n                            .map_err(|e| io::Error::new(io::ErrorKind::InvalidData, e))?;\n                        return Ok(BrokerEvent::Output {\n                            session_id: ev.session_id,\n                            seq: ev.seq,\n                            bytes,\n                        });\n                    }\n                    // Legacy single-session path (map empty — a pure spawn/drive\n                    // seat): strict accept-next / drop-dup / reject-gap on the one\n                    // `next_seq` cursor, byte-for-byte unchanged.\n                    //\n                    // #6 (ADR-0031): a COLD attach's FIRST output frame is a\n                    // clean-screen repaint at pseudo-seq `broker.next_seq - 1` (a\n                    // forward jump from the requested `from_seq == 0`). Adopt that seq\n                    // as the baseline instead of reject-gapping it — the repaint IS\n                    // the complete current screen, nothing prior is owed. Consumed\n                    // once per (cold) attach; every subsequent LIVE frame then takes\n                    // the strict reject-gap below (a b4 drop still re-fetches — B2).\n                    if self.baseline_next_output {\n                        self.next_seq = ev.seq;\n                        self.baseline_next_output = false;\n                    }\n                    if ev.seq < self.next_seq {\n                        // Already processed — a replay duplicate; dedup. A FLAGGED\n                        // backward frame dedups identically (forward-only pin: a\n                        // backward baseline would rewind the cursor under replayed\n                        // frames and exactly-once dies).\n                        continue;\n                    }\n                    if ev.seq > self.next_seq {\n                        // A FLAGGED forward jump is the broker declaring \"this\n                        // synthesized frame SUPERSEDES everything before its seq\"\n                        // (the resize commit/abort sync frame, a below-floor resume\n                        // repaint — REQ-RC-RESIZE-PRESENTATION-BARRIER, doyle\n                        // wire-flag ruling 2026-07-21). Accept + baseline: B2-sound,\n                        // not a B2 exception — the supersession is explicit and\n                        // broker-authored, nothing is silently skipped. An UNFLAGGED\n                        // jump keeps the strict reject-gap byte-for-byte (a b4 drop\n                        // still re-fetches from the floor).\n                        // [impl->REQ-RC-RESIZE-PRESENTATION-BARRIER]\n                        if !ev.sync {\n                            return Err(io::Error::new(\n                                io::ErrorKind::InvalidData,\n                                format!(\"output gap: got seq {} want {}\", ev.seq, self.next_seq),\n                            ));\n                        }\n                    }\n                    self.next_seq = ev.seq + 1;\n                    let bytes = decode_bytes(&ev.data_b64)\n                        .map_err(|e| io::Error::new(io::ErrorKind::InvalidData, e))?;\n                    return Ok(BrokerEvent::Output {\n                        session_id: ev.session_id,\n                        seq: ev.seq,\n                        bytes,\n                    });\n                }\n                KIND_SPAWN_CONFLICT => {\n                    let ev: SpawnConflict = serde_json::from_value(env.payload)\n                        .map_err(|e| io::Error::new(io::ErrorKind::InvalidData, e))?;\n                    return Ok(BrokerEvent::SpawnConflict {\n                        endpoint: ev.endpoint,\n                        session_id: ev.session_id,\n                    });\n                }\n                // [impl->REQ-ER-BRINGUP-SPAWNS-SESSION]\n                KIND_BROUGHT_UP => {\n                    let ev: BroughtUpReply = serde_json::from_value(env.payload)\n                        .map_err(|e| io::Error::new(io::ErrorKind::InvalidData, e))?;\n                    return Ok(BrokerEvent::BroughtUp {\n                        outcome: ev.outcome,\n                        detail: ev.detail,\n                        session_id: ev.session_id,\n                        admit: ev.admit,\n                    });\n                }\n                // [impl->REQ-SEAL-CEREMONY-TOTP]\n                KIND_SEAL_CEREMONY_REPLY => {\n                    let ev: SealCeremonyReply = serde_json::from_value(env.payload)\n                        .map_err(|e| io::Error::new(io::ErrorKind::InvalidData, e))?;\n                    return Ok(BrokerEvent::SealCeremonyDone {\n                        outcome: ev.outcome,\n                        detail: ev.detail,\n                        token: ev.token,\n                    });\n                }\n                // [impl->REQ-SEAL-CEREMONY-RC-CLIENT]\n                KIND_SEAL_CEREMONY_OPEN => {\n                    let ev: SealCeremonyOpenEvent = serde_json::from_value(env.payload)\n                        .map_err(|e| io::Error::new(io::ErrorKind::InvalidData, e))?;\n…\n                }\n…\n            }\n        }\n    }\n…\n    fn subscribe_with(\n        &mut self,\n        session_id: u64,\n        from_seq: u64,\n        intent: AttachIntent,\n        gen: u64,\n        by: Option<String>,\n        code: Option<String>,\n        seal_ceremony: bool,\n    ) -> io::Result<()> {\n        // P1c (operator-stream boundary, kitsubito RACEDIAG): a resume-mode brain\n        // (seeded map) that subscribes from `from_seq` must RESET this session's\n        // dedup cursor to `from_seq` — the broker's replay from `from_seq` is then\n        // re-delivered (and the operator's render cursor dedups the overlap),\n        // never lost. WHY THIS, NOT just `read_event`'s `or_insert`: on a re-serve,\n        // `serve_attach` may CONSUME a handoff-replay frame at the K boundary\n        // BEFORE it is `attached` (the frame is dropped by the `if attached` gate\n        // but the snap-above cursor still advanced past K); `attach_as(sid, 0)`\n        // then re-subscribes from 0, and without this reset the broker's re-send of\n        // seq K arrives below the advanced cursor and is deduped → seq K never\n        // reaches the operator viewport → a forward gap. Resetting to `from_seq`\n        // makes the re-subscribe re-deliver everything from its floor. A cold-start\n        // brain (empty map — e.g. the production dispatch serve brain) keeps the\n        // legacy `next_seq` path; this only arms in resume mode.\n        // [impl->REQ-HAZARD-CONTROLLER-WRITER-REORDER]\n        if !self.session_cursors.is_empty() {\n            self.session_cursors.insert(session_id, from_seq);\n        }\n        self.send(\n            KIND_SUBSCRIBE,\n            serde_json::to_value(SubscribeReq {\n                session_id,\n                from_seq,\n                intent,\n                by,\n                gen,\n                code,\n                seal_ceremony,\n            })\n            .expect(\"SubscribeReq serializes\"),\n        )\n    }\n\n    fn send(&mut self, kind: &str, payload: serde_json::Value) -> io::Result<()> {\n        let env = Envelope::new(kind, payload);\n        match &mut self.conn {\n            BrainConn::Whole(stream) => write_frame(stream, &env),\n            BrainConn::Split { send, .. } => write_frame(send, &env),\n        }\n    }\n\n    /// Read one framed [`Envelope`], bounded by an optional wall-clock\n    /// `deadline`. The carrier dispatch (REQ-HAZARD-PUMP-IPC-DEADLINE):\n    ///\n    /// - [`BrainConn::Whole`] — the ordinary blocking client. `None` is the\n    ///   ordinary blocking [`read_frame`]. `Some(deadline)` is REFUSED BY NAME\n    ///   (releases#190): this carrier reads the frame inline, so there is no\n    ///   thread to hand a deadline to and a timeout would have to abandon a\n    ///   half-read frame — a desynced carrier, which is exactly why the pump\n    ///   carrier was SPLIT instead of given a socket timeout. Pre-fix this arm\n    ///   dropped the parameter on the floor, so a caller that asked for a\n    ///   bounded read silently got an unbounded one; the defect was the"}],"details":{"displayContent":{"text":"    pub fn read_event_until(&mut self, deadline: Option<Instant>) -> io::Result<BrokerEvent> {\n        loop {\n            let env = self.read_frame_until(deadline)?;\n            match env.kind.as_str() {\n                KIND_OUTPUT => {\n                    let ev: OutputEvent = serde_json::from_value(env.payload)\n                        .map_err(|e| io::Error::new(io::ErrorKind::InvalidData, e))?;\n                    // A **resume-mode** brain (the per-session map is populated by\n                    // `resume_sessions`) routes EVERY session through the map —\n                    // including a freshly-spawned or first-seen one, which seeds\n                    // itself at its first `seq` via `entry().or_insert` (D4-2b,\n                    // doyle amendment 5: this closes the mixed-mode gap where N≥2\n                    // fresh spawns would otherwise share the single `next_seq` and\n                    // silently drop the later sessions' seq-0 output). The broker's\n                    // `Mutex<OutputLog>`-held wire order guarantees first-sight of a\n                    // new session IS seq 0, so the seed == 0 for a spawn; a resumed\n                    // session already holds its `resume_seq` seed (the `entry`\n                    // returns it, so the boundary-dedup still applies). Discipline:\n                    // **dedup-below + snap-above, NO reject-gap** — drop an\n                    // already-delivered seq (the at-least-once boundary re-send),\n                    // accept-and-snap everything `>= cursor` (the contiguous case\n                    // AND a post-eviction ring-floor jump, which the broker's\n                    // non-reordering replay makes the only legitimate forward jump).\n                    if !self.session_cursors.is_empty() {\n                        let cursor = self.session_cursors.entry(ev.session_id).or_insert(ev.seq);\n                        if ev.seq < *cursor {\n                            // Replay duplicate / boundary re-send — dedup. A FLAGGED\n                            // backward frame (a replayed old sync frame) dedups the\n                            // same way: NEVER a backward baseline — a rewind would\n                            // re-accept replayed frames (the wire-flag ruling's\n                            // forward-only pin, REQ-RC-RESIZE-PRESENTATION-BARRIER).\n                            continue;\n                        }\n                        *cursor = ev.seq + 1;\n                        let bytes = decode_bytes(&ev.data_b64)\n                            .map_err(|e| io::Error::new(io::ErrorKind::InvalidData, e))?;\n                        return Ok(BrokerEvent::Output {\n                            session_id: ev.session_id,\n                            seq: ev.seq,\n                            bytes,\n                        });\n                    }\n                    // Legacy single-session path (map empty — a pure spawn/drive\n                    // seat): strict accept-next / drop-dup / reject-gap on the one\n                    // `next_seq` cursor, byte-for-byte unchanged.\n                    //\n                    // #6 (ADR-0031): a COLD attach's FIRST output frame is a\n                    // clean-screen repaint at pseudo-seq `broker.next_seq - 1` (a\n                    // forward jump from the requested `from_seq == 0`). Adopt that seq\n                    // as the baseline instead of reject-gapping it — the repaint IS\n                    // the complete current screen, nothing prior is owed. Consumed\n                    // once per (cold) attach; every subsequent LIVE frame then takes\n                    // the strict reject-gap below (a b4 drop still re-fetches — B2).\n                    if self.baseline_next_output {\n                        self.next_seq = ev.seq;\n                        self.baseline_next_output = false;\n                    }\n                    if ev.seq < self.next_seq {\n                        // Already processed — a replay duplicate; dedup. A FLAGGED\n                        // backward frame dedups identically (forward-only pin: a\n                        // backward baseline would rewind the cursor under replayed\n                        // frames and exactly-once dies).\n                        continue;\n                    }\n                    if ev.seq > self.next_seq {\n                        // A FLAGGED forward jump is the broker declaring \"this\n                        // synthesized frame SUPERSEDES everything before its seq\"\n                        // (the resize commit/abort sync frame, a below-floor resume\n                        // repaint — REQ-RC-RESIZE-PRESENTATION-BARRIER, doyle\n                        // wire-flag ruling 2026-07-21). Accept + baseline: B2-sound,\n                        // not a B2 exception — the supersession is explicit and\n                        // broker-authored, nothing is silently skipped. An UNFLAGGED\n                        // jump keeps the strict reject-gap byte-for-byte (a b4 drop\n                        // still re-fetches from the floor).\n                        // [impl->REQ-RC-RESIZE-PRESENTATION-BARRIER]\n                        if !ev.sync {\n                            return Err(io::Error::new(\n                                io::ErrorKind::InvalidData,\n                                format!(\"output gap: got seq {} want {}\", ev.seq, self.next_seq),\n                            ));\n                        }\n                    }\n                    self.next_seq = ev.seq + 1;\n                    let bytes = decode_bytes(&ev.data_b64)\n                        .map_err(|e| io::Error::new(io::ErrorKind::InvalidData, e))?;\n                    return Ok(BrokerEvent::Output {\n                        session_id: ev.session_id,\n                        seq: ev.seq,\n                        bytes,\n                    });\n                }\n                KIND_SPAWN_CONFLICT => {\n                    let ev: SpawnConflict = serde_json::from_value(env.payload)\n                        .map_err(|e| io::Error::new(io::ErrorKind::InvalidData, e))?;\n                    return Ok(BrokerEvent::SpawnConflict {\n                        endpoint: ev.endpoint,\n                        session_id: ev.session_id,\n                    });\n                }\n                // [impl->REQ-ER-BRINGUP-SPAWNS-SESSION]\n                KIND_BROUGHT_UP => {\n                    let ev: BroughtUpReply = serde_json::from_value(env.payload)\n                        .map_err(|e| io::Error::new(io::ErrorKind::InvalidData, e))?;\n                    return Ok(BrokerEvent::BroughtUp {\n                        outcome: ev.outcome,\n                        detail: ev.detail,\n                        session_id: ev.session_id,\n                        admit: ev.admit,\n                    });\n                }\n                // [impl->REQ-SEAL-CEREMONY-TOTP]\n                KIND_SEAL_CEREMONY_REPLY => {\n                    let ev: SealCeremonyReply = serde_json::from_value(env.payload)\n                        .map_err(|e| io::Error::new(io::ErrorKind::InvalidData, e))?;\n                    return Ok(BrokerEvent::SealCeremonyDone {\n                        outcome: ev.outcome,\n                        detail: ev.detail,\n                        token: ev.token,\n                    });\n                }\n                // [impl->REQ-SEAL-CEREMONY-RC-CLIENT]\n                KIND_SEAL_CEREMONY_OPEN => {\n                    let ev: SealCeremonyOpenEvent = serde_json::from_value(env.payload)\n                        .map_err(|e| io::Error::new(io::ErrorKind::InvalidData, e))?;\n…\n                }\n…\n            }\n        }\n    }\n…\n    fn subscribe_with(\n        &mut self,\n        session_id: u64,\n        from_seq: u64,\n        intent: AttachIntent,\n        gen: u64,\n        by: Option<String>,\n        code: Option<String>,\n        seal_ceremony: bool,\n    ) -> io::Result<()> {\n        // P1c (operator-stream boundary, kitsubito RACEDIAG): a resume-mode brain\n        // (seeded map) that subscribes from `from_seq` must RESET this session's\n        // dedup cursor to `from_seq` — the broker's replay from `from_seq` is then\n        // re-delivered (and the operator's render cursor dedups the overlap),\n        // never lost. WHY THIS, NOT just `read_event`'s `or_insert`: on a re-serve,\n        // `serve_attach` may CONSUME a handoff-replay frame at the K boundary\n        // BEFORE it is `attached` (the frame is dropped by the `if attached` gate\n        // but the snap-above cursor still advanced past K); `attach_as(sid, 0)`\n        // then re-subscribes from 0, and without this reset the broker's re-send of\n        // seq K arrives below the advanced cursor and is deduped → seq K never\n        // reaches the operator viewport → a forward gap. Resetting to `from_seq`\n        // makes the re-subscribe re-deliver everything from its floor. A cold-start\n        // brain (empty map — e.g. the production dispatch serve brain) keeps the\n        // legacy `next_seq` path; this only arms in resume mode.\n        // [impl->REQ-HAZARD-CONTROLLER-WRITER-REORDER]\n        if !self.session_cursors.is_empty() {\n            self.session_cursors.insert(session_id, from_seq);\n        }\n        self.send(\n            KIND_SUBSCRIBE,\n            serde_json::to_value(SubscribeReq {\n                session_id,\n                from_seq,\n                intent,\n                by,\n                gen,\n                code,\n                seal_ceremony,\n            })\n            .expect(\"SubscribeReq serializes\"),\n        )\n    }\n\n    fn send(&mut self, kind: &str, payload: serde_json::Value) -> io::Result<()> {\n        let env = Envelope::new(kind, payload);\n        match &mut self.conn {\n            BrainConn::Whole(stream) => write_frame(stream, &env),\n            BrainConn::Split { send, .. } => write_frame(send, &env),\n        }\n    }\n\n    /// Read one framed [`Envelope`], bounded by an optional wall-clock\n    /// `deadline`. The carrier dispatch (REQ-HAZARD-PUMP-IPC-DEADLINE):\n    ///\n    /// - [`BrainConn::Whole`] — the ordinary blocking client. `None` is the\n    ///   ordinary blocking [`read_frame`]. `Some(deadline)` is REFUSED BY NAME\n    ///   (releases#190): this carrier reads the frame inline, so there is no\n    ///   thread to hand a deadline to and a timeout would have to abandon a\n    ///   half-read frame — a desynced carrier, which is exactly why the pump\n    ///   carrier was SPLIT instead of given a socket timeout. Pre-fix this arm\n    ///   dropped the parameter on the floor, so a caller that asked for a\n    ///   bounded read silently got an unbounded one; the defect was the","startLine":1063,"lineNumbers":[1063,1064,1065,1066,1067,1068,1069,1070,1071,1072,1073,1074,1075,1076,1077,1078,1079,1080,1081,1082,1083,1084,1085,1086,1087,1088,1089,1090,1091,1092,1093,1094,1095,1096,1097,1098,1099,1100,1101,1102,1103,1104,1105,1106,1107,1108,1109,1110,1111,1112,1113,1114,1115,1116,1117,1118,1119,1120,1121,1122,1123,1124,1125,1126,1127,1128,1129,1130,1131,1132,1133,1134,1135,1136,1137,1138,1139,1140,1141,1142,1143,1144,1145,1146,1147,1148,1149,1150,1151,1152,1153,1154,1155,1156,1157,1158,1159,1160,1161,1162,1163,1164,1165,1166,1167,1168,1169,1170,1171,1172,1173,1174,1175,1176,1177,1178,1179,1180,1181,1182,1183,1184,1185,1186,null,1197,null,1376,1377,1378,null,2511,2512,2513,2514,2515,2516,2517,2518,2519,2520,2521,2522,2523,2524,2525,2526,2527,2528,2529,2530,2531,2532,2533,2534,2535,2536,2537,2538,2539,2540,2541,2542,2543,2544,2545,2546,2547,2548,2549,2550,2551,2552,2553,2554,2555,2556,2557,2558,2559,2560,2561,2562,2563,2564,2565,2566,2567,2568,2569,2570,2571,2572]},"fileSize":171079,"meta":{"source":{"type":"path","value":"C:\\Users\\decid\\Documents\\projects\\spt-core\\crates\\spt-daemon\\src\\brain.rs"}}},"isError":false,"timestamp":1789524024115}}
{"type":"message","id":"fc2664f7","parentId":"d4e5fb2b","timestamp":"2026-09-16T02:00:24.121Z","message":{"role":"toolResult","toolCallId":"call_Fqj8AKLRKtJg6cx8qmf3QQDv|fc_09b01b5279447709016aa9f83801e887d2800f3354a7b733fa","toolName":"read","content":[{"type":"text","text":"    fn dispatch_input(&self, env: Envelope, send: &SharedSend) -> Result<(), String> {\n…\n        // commits — so a stash/restore choreography can't be clobbered. Returns\n        // true when buffered (the caller must NOT write the PTY now).\n        let buffered = |bytes: &[u8]| -> bool {\n            translation\n                .as_ref()\n                .is_some_and(|tr| lock_floor(&tr.floor).buffer_if_held(bytes))\n        };\n        match req.op_id {\n            Some(op) => {\n                // Materialize the minter at the decode seam: an untagged (older)\n                // sender ⇒ Legacy; a live producer stamped its real tag (ADR-0034).\n                let minter = req.minter.unwrap_or(Minter::Legacy);\n                let key = EffectKey {\n                    class: req.session_id,\n                    minter,\n                    op,\n                };\n                let outcome = self\n                    .journal\n                    .apply_once(key, EffectKind::PtyWrite, || {\n                        // Buffer-or-ENQUEUE INSIDE the journal effect so the op is\n                        // still recorded applied + acked (dedup-safe) whether the byte\n                        // buffers (inject floor held), enqueues, or is dropped under\n                        // backpressure. The effect is now the non-blocking enqueue —\n                        // PtyWrite is ephemeral, so Applied-at-enqueue is sound\n                        // (V0.13.0-P0 design); the ack means \"accepted + ordered + will\n                        // land,\" and rc does not gate on landing.\n                        if !buffered(&bytes) {\n                            input.enqueue(bytes.clone());\n                        }\n                        Ok(())\n                    })\n                    .map_err(|e| format!(\"input enqueue failed: {e}\"))?;\n                // Ack exactly-once — but ONLY when the caller requested it\n                // (REQ-HAZARD-INPUT-ACK-BACKPRESSURE). The fire-and-forward\n                // operator/rc path sends `ack=false`: writing the ack back onto the\n                // same brain↔broker conn it is flooding with input fills the return\n                // direction and deadlocks the per-conn handler (the wedge). With no\n                // ack the handler never writes back while servicing the flood, so it\n                // always drains. The acked path (`shellchan`, one-at-a-time) still\n                // gets its `KIND_APPLIED`. Dedup is unaffected either way (the\n                // applied-set is the exactly-once anchor, not the ack frame).\n                // [impl->REQ-HAZARD-INPUT-ACK-BACKPRESSURE]\n                if req.ack {\n                    send_frame(\n                        send,\n                        &applied_envelope(req.session_id, op, outcome == Outcome::Applied),\n                    );\n                }\n                Ok(())\n            }\n            None => {\n                if !buffered(&bytes) {\n                    input.enqueue(bytes);\n                }\n                Ok(())\n            }\n        }\n    }\n\n    /// Attempt a BOUNDED eager respawn of a FAULTED translation binary (F029 C-1,\n    /// REQ-HAZARD-TRANSLATE-FAULT-PERMANENT-DEATH) and return the endpoint's live\n    /// translation (the rebuilt one on success, or the existing faulted/`None` one\n…\n    fn dispatch_net_stream_send(&self, env: Envelope, send: &SharedSend) -> Result<(), String> {\n        let req: NetStreamSendReq = serde_json::from_value(env.payload)\n            .map_err(|e| format!(\"bad net-stream-send payload: {e}\"))?;\n        let bytes =\n            decode_bytes(&req.data_b64).map_err(|e| format!(\"bad net-stream-send base64: {e}\"))?;\n        let host = self.net.get().ok_or(\"net disabled\")?;\n        match req.op_id {\n            None => host\n                .send_stream(req.stream_id, &bytes, req.finish)\n                .map_err(|e| e.to_string()),\n            Some(op) => {\n                let minter = req.minter.unwrap_or(Minter::Legacy);\n                let key = EffectKey {\n                    class: NET_EFFECT_SESSION,\n                    minter,\n                    op,\n                };\n                let outcome = self\n                    .journal\n                    .apply_once(key, EffectKind::NetSend, || {\n                        host.send_stream(req.stream_id, &bytes, req.finish)\n                    })\n                    .map_err(|e| format!(\"net-stream-send failed: {e}\"))?;\n                let frame = Envelope::new(\n                    KIND_NET_SENT,\n                    serde_json::to_value(NetSent {\n                        stream_id: req.stream_id,\n                        op_id: op,\n                        applied_now: outcome == Outcome::Applied,\n                    })\n                    .expect(\"NetSent serializes\"),\n                );\n                send_frame(send, &frame);\n                Ok(())\n            }\n        }\n    }\n\n    /// List every stream the broker holds (D4b) — the query a re-attaching\n    /// brain uses to find streams that arrived while it was down.\n    fn dispatch_net_streams(&self, send: &SharedSend) -> Result<(), String> {\n        let host = self.net.get().ok_or(\"net disabled\")?;\n        // SERVER-SIDE eligibility filter (ADR-0040 decision 2): locally-\n        // initiated rows never cross the IPC — the dispatcher only ever\n        // skipped them client-side, and serializing the full local history\n        // every 100ms poll was the O(history) enumeration cost of KH 7.44.\n        // [impl->REQ-STREAM-INFOS-SERVER-FILTER]\n        let frame = Envelope::new(\n            KIND_NET_STREAMS_REPLY,\n            serde_json::to_value(NetStreamsReply {\n                streams: host.dispatch_stream_infos(),\n            })\n            .expect(\"NetStreamsReply serializes\"),\n        );\n        send_frame(send, &frame);\n        Ok(())\n    }\n\n    /// Release the calling connection's subscriber seat on a stream (ADR-0040\n    /// decision 5) — seat removed, writer thread stopped and joined, cursor\n    /// dropped caller-side. Identity-checked: only the caller's own seat."}],"details":{"displayContent":{"text":"    fn dispatch_input(&self, env: Envelope, send: &SharedSend) -> Result<(), String> {\n…\n        // commits — so a stash/restore choreography can't be clobbered. Returns\n        // true when buffered (the caller must NOT write the PTY now).\n        let buffered = |bytes: &[u8]| -> bool {\n            translation\n                .as_ref()\n                .is_some_and(|tr| lock_floor(&tr.floor).buffer_if_held(bytes))\n        };\n        match req.op_id {\n            Some(op) => {\n                // Materialize the minter at the decode seam: an untagged (older)\n                // sender ⇒ Legacy; a live producer stamped its real tag (ADR-0034).\n                let minter = req.minter.unwrap_or(Minter::Legacy);\n                let key = EffectKey {\n                    class: req.session_id,\n                    minter,\n                    op,\n                };\n                let outcome = self\n                    .journal\n                    .apply_once(key, EffectKind::PtyWrite, || {\n                        // Buffer-or-ENQUEUE INSIDE the journal effect so the op is\n                        // still recorded applied + acked (dedup-safe) whether the byte\n                        // buffers (inject floor held), enqueues, or is dropped under\n                        // backpressure. The effect is now the non-blocking enqueue —\n                        // PtyWrite is ephemeral, so Applied-at-enqueue is sound\n                        // (V0.13.0-P0 design); the ack means \"accepted + ordered + will\n                        // land,\" and rc does not gate on landing.\n                        if !buffered(&bytes) {\n                            input.enqueue(bytes.clone());\n                        }\n                        Ok(())\n                    })\n                    .map_err(|e| format!(\"input enqueue failed: {e}\"))?;\n                // Ack exactly-once — but ONLY when the caller requested it\n                // (REQ-HAZARD-INPUT-ACK-BACKPRESSURE). The fire-and-forward\n                // operator/rc path sends `ack=false`: writing the ack back onto the\n                // same brain↔broker conn it is flooding with input fills the return\n                // direction and deadlocks the per-conn handler (the wedge). With no\n                // ack the handler never writes back while servicing the flood, so it\n                // always drains. The acked path (`shellchan`, one-at-a-time) still\n                // gets its `KIND_APPLIED`. Dedup is unaffected either way (the\n                // applied-set is the exactly-once anchor, not the ack frame).\n                // [impl->REQ-HAZARD-INPUT-ACK-BACKPRESSURE]\n                if req.ack {\n                    send_frame(\n                        send,\n                        &applied_envelope(req.session_id, op, outcome == Outcome::Applied),\n                    );\n                }\n                Ok(())\n            }\n            None => {\n                if !buffered(&bytes) {\n                    input.enqueue(bytes);\n                }\n                Ok(())\n            }\n        }\n    }\n\n    /// Attempt a BOUNDED eager respawn of a FAULTED translation binary (F029 C-1,\n    /// REQ-HAZARD-TRANSLATE-FAULT-PERMANENT-DEATH) and return the endpoint's live\n    /// translation (the rebuilt one on success, or the existing faulted/`None` one\n…\n    fn dispatch_net_stream_send(&self, env: Envelope, send: &SharedSend) -> Result<(), String> {\n        let req: NetStreamSendReq = serde_json::from_value(env.payload)\n            .map_err(|e| format!(\"bad net-stream-send payload: {e}\"))?;\n        let bytes =\n            decode_bytes(&req.data_b64).map_err(|e| format!(\"bad net-stream-send base64: {e}\"))?;\n        let host = self.net.get().ok_or(\"net disabled\")?;\n        match req.op_id {\n            None => host\n                .send_stream(req.stream_id, &bytes, req.finish)\n                .map_err(|e| e.to_string()),\n            Some(op) => {\n                let minter = req.minter.unwrap_or(Minter::Legacy);\n                let key = EffectKey {\n                    class: NET_EFFECT_SESSION,\n                    minter,\n                    op,\n                };\n                let outcome = self\n                    .journal\n                    .apply_once(key, EffectKind::NetSend, || {\n                        host.send_stream(req.stream_id, &bytes, req.finish)\n                    })\n                    .map_err(|e| format!(\"net-stream-send failed: {e}\"))?;\n                let frame = Envelope::new(\n                    KIND_NET_SENT,\n                    serde_json::to_value(NetSent {\n                        stream_id: req.stream_id,\n                        op_id: op,\n                        applied_now: outcome == Outcome::Applied,\n                    })\n                    .expect(\"NetSent serializes\"),\n                );\n                send_frame(send, &frame);\n                Ok(())\n            }\n        }\n    }\n\n    /// List every stream the broker holds (D4b) — the query a re-attaching\n    /// brain uses to find streams that arrived while it was down.\n    fn dispatch_net_streams(&self, send: &SharedSend) -> Result<(), String> {\n        let host = self.net.get().ok_or(\"net disabled\")?;\n        // SERVER-SIDE eligibility filter (ADR-0040 decision 2): locally-\n        // initiated rows never cross the IPC — the dispatcher only ever\n        // skipped them client-side, and serializing the full local history\n        // every 100ms poll was the O(history) enumeration cost of KH 7.44.\n        // [impl->REQ-STREAM-INFOS-SERVER-FILTER]\n        let frame = Envelope::new(\n            KIND_NET_STREAMS_REPLY,\n            serde_json::to_value(NetStreamsReply {\n                streams: host.dispatch_stream_infos(),\n            })\n            .expect(\"NetStreamsReply serializes\"),\n        );\n        send_frame(send, &frame);\n        Ok(())\n    }\n\n    /// Release the calling connection's subscriber seat on a stream (ADR-0040\n    /// decision 5) — seat removed, writer thread stopped and joined, cursor\n    /// dropped caller-side. Identity-checked: only the caller's own seat.","startLine":8846,"lineNumbers":[8846,null,8890,8891,8892,8893,8894,8895,8896,8897,8898,8899,8900,8901,8902,8903,8904,8905,8906,8907,8908,8909,8910,8911,8912,8913,8914,8915,8916,8917,8918,8919,8920,8921,8922,8923,8924,8925,8926,8927,8928,8929,8930,8931,8932,8933,8934,8935,8936,8937,8938,8939,8940,8941,8942,8943,8944,8945,8946,8947,8948,8949,8950,8951,8952,null,9826,9827,9828,9829,9830,9831,9832,9833,9834,9835,9836,9837,9838,9839,9840,9841,9842,9843,9844,9845,9846,9847,9848,9849,9850,9851,9852,9853,9854,9855,9856,9857,9858,9859,9860,9861,9862,9863,9864,9865,9866,9867,9868,9869,9870,9871,9872,9873,9874,9875,9876,9877,9878,9879,9880,9881,9882,9883,9884,9885,9886]},"fileSize":877537,"meta":{"source":{"type":"path","value":"C:\\Users\\decid\\Documents\\projects\\spt-core\\crates\\spt-daemon\\src\\broker.rs"}}},"isError":false,"timestamp":1789524024121}}
{"type":"message","id":"b37b53d1","parentId":"fc2664f7","timestamp":"2026-09-16T02:00:24.133Z","message":{"role":"toolResult","toolCallId":"call_BuApIczVqfAXrzcG9KoQjsbY|fc_09b01b5279447709016aa9f83801f887d2a3582ff39541b842","toolName":"read","content":[{"type":"text","text":"fn classify_failure(msg: &str) -> FailClass {\n    if msg.contains(\"subscriber busy\")\n        || msg.contains(\"replay halted\")\n        || msg.contains(\"lease canceled\")\n    {\n        FailClass::SeatBlocked\n    } else {\n        FailClass::Transient\n    }\n}\n\n/// Whether an opener-query error is the OLD broker's unknown-verb answer —\n/// the ONLY error class that may fall back to the ring peek (ADR-0038\n/// Amendment fix 1). `send_error` on an unknown kind replies exactly\n…\nfn outcome_transition(\n    outcome: &DispatchOutcome,\n    family: Option<StreamFamily>,\n    attempts: u32,\n    now: Instant,\n    breaker_window: Duration,\n) -> (ClaimState, bool) {\n    match outcome {\n        DispatchOutcome::Served(_) | DispatchOutcome::Unknown => (ClaimState::Terminal, false),\n        DispatchOutcome::Failed(msg) => match classify_failure(msg) {\n            FailClass::SeatBlocked if family_is_one_way(family) => {\n                let attempts = attempts + 1;\n                if attempts >= ONEWAY_POISON_STRIKES {\n                    (ClaimState::Terminal, true)\n                } else {\n                    (\n                        ClaimState::Retry {\n                            attempts,\n                            next_at: now + breaker_window,\n                        },\n                        false,\n                    )\n                }\n            }\n            FailClass::SeatBlocked => (\n                ClaimState::Retry {\n                    attempts,\n                    next_at: now + breaker_window,\n                },\n                false,\n            ),\n            FailClass::Transient => {\n                let attempts = attempts + 1;\n                if attempts >= MAX_DISPATCH_ATTEMPTS {\n                    (ClaimState::Terminal, family_is_one_way(family))\n                } else {\n                    (\n                        ClaimState::Retry {\n                            attempts,\n                            next_at: now + retry_backoff(attempts),\n                        },\n                        false,\n                    )\n                }\n            }\n        },\n    }\n}\n\n/// PURE lifecycle+family discriminator (gate round 1, ADR-0038 Decision 1's"}],"details":{"displayContent":{"text":"fn classify_failure(msg: &str) -> FailClass {\n    if msg.contains(\"subscriber busy\")\n        || msg.contains(\"replay halted\")\n        || msg.contains(\"lease canceled\")\n    {\n        FailClass::SeatBlocked\n    } else {\n        FailClass::Transient\n    }\n}\n\n/// Whether an opener-query error is the OLD broker's unknown-verb answer —\n/// the ONLY error class that may fall back to the ring peek (ADR-0038\n/// Amendment fix 1). `send_error` on an unknown kind replies exactly\n…\nfn outcome_transition(\n    outcome: &DispatchOutcome,\n    family: Option<StreamFamily>,\n    attempts: u32,\n    now: Instant,\n    breaker_window: Duration,\n) -> (ClaimState, bool) {\n    match outcome {\n        DispatchOutcome::Served(_) | DispatchOutcome::Unknown => (ClaimState::Terminal, false),\n        DispatchOutcome::Failed(msg) => match classify_failure(msg) {\n            FailClass::SeatBlocked if family_is_one_way(family) => {\n                let attempts = attempts + 1;\n                if attempts >= ONEWAY_POISON_STRIKES {\n                    (ClaimState::Terminal, true)\n                } else {\n                    (\n                        ClaimState::Retry {\n                            attempts,\n                            next_at: now + breaker_window,\n                        },\n                        false,\n                    )\n                }\n            }\n            FailClass::SeatBlocked => (\n                ClaimState::Retry {\n                    attempts,\n                    next_at: now + breaker_window,\n                },\n                false,\n            ),\n            FailClass::Transient => {\n                let attempts = attempts + 1;\n                if attempts >= MAX_DISPATCH_ATTEMPTS {\n                    (ClaimState::Terminal, family_is_one_way(family))\n                } else {\n                    (\n                        ClaimState::Retry {\n                            attempts,\n                            next_at: now + retry_backoff(attempts),\n                        },\n                        false,\n                    )\n                }\n            }\n        },\n    }\n}\n\n/// PURE lifecycle+family discriminator (gate round 1, ADR-0038 Decision 1's","startLine":373,"lineNumbers":[373,374,375,376,377,378,379,380,381,382,383,384,385,386,null,503,504,505,506,507,508,509,510,511,512,513,514,515,516,517,518,519,520,521,522,523,524,525,526,527,528,529,530,531,532,533,534,535,536,537,538,539,540,541,542,543,544,545,546,547,548,549,550,551,552]},"fileSize":171439,"meta":{"source":{"type":"path","value":"C:\\Users\\decid\\Documents\\projects\\spt-core\\crates\\spt-daemon\\src\\dispatch.rs"}}},"isError":false,"timestamp":1789524024133}}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_mciEqRPD0iYGo46jSaUAHTZq|fc_09b01b5279447709016aa9f844650c87d2b26effcd1a36119e","toolName":"read","startedAt":"2026-09-16T02:00:36.490Z","args":{"path":"crates/spt-daemon/src/broker.rs:8750-8810"},"intent":"Reading subscribe reply ordering"},"id":"d8c498f6","parentId":"b37b53d1","timestamp":"2026-09-16T02:00:36.490Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_SRrwAo3nbRckkPI00IjWLEZH|fc_09b01b5279447709016aa9f844651c87d2a58ca8a8c8e0357e","toolName":"grep","startedAt":"2026-09-16T02:00:36.490Z","args":{"path":"crates/spt-daemon/tests/attach.rs:534-1600;crates/spt-daemon/tests/redispatch.rs:300-720;crates/spt-daemon/tests/redispatch_stall.rs:320-800"},"intent":"Locating concrete replay tests"},"id":"47ead570","parentId":"d8c498f6","timestamp":"2026-09-16T02:00:36.490Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_mDtCI8ulgnow8pwjeemF6ORi|fc_09b01b5279447709016aa9f844652087d28e020b4f773b68eb","toolName":"read","startedAt":"2026-09-16T02:00:36.490Z","args":{"path":".spt/preserved/307/hertz-w1bc/rig.py"},"intent":"Reading rig input sizes"},"id":"f1f3a03a","parentId":"47ead570","timestamp":"2026-09-16T02:00:36.490Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_40lTjtsW510AWGVWYnenqPm7|fc_09b01b5279447709016aa9f844652887d2874f6df36158249b","toolName":"read","startedAt":"2026-09-16T02:00:36.490Z","args":{"path":".spt/preserved/307/hertz-w1bc/w1c-run1/events.jsonl:1-12"},"intent":"Reading W1c event anchors"},"id":"c9464a16","parentId":"f1f3a03a","timestamp":"2026-09-16T02:00:36.490Z"}
{"type":"message","id":"8d821446","parentId":"c9464a16","timestamp":"2026-09-16T02:00:36.491Z","message":{"role":"assistant","content":[{"type":"thinking","thinking":"**Checking subscription reply order**"},{"type":"toolCall","id":"call_mciEqRPD0iYGo46jSaUAHTZq|fc_09b01b5279447709016aa9f844650c87d2b26effcd1a36119e","name":"read","arguments":{"i":"Reading subscribe reply ordering","path":"crates/spt-daemon/src/broker.rs:8750-8810"},"intent":"Reading subscribe reply ordering"},{"type":"toolCall","id":"call_SRrwAo3nbRckkPI00IjWLEZH|fc_09b01b5279447709016aa9f844651c87d2a58ca8a8c8e0357e","name":"grep","arguments":{"i":"Locating concrete replay tests","pattern":"^fn .*|pending_input|ack_backpressure","path":"crates/spt-daemon/tests/attach.rs:534-1600;crates/spt-daemon/tests/redispatch.rs:300-720;crates/spt-daemon/tests/redispatch_stall.rs:320-800","case":true,"gitignore":true,"skip":null},"intent":"Locating concrete replay tests"},{"type":"toolCall","id":"call_mDtCI8ulgnow8pwjeemF6ORi|fc_09b01b5279447709016aa9f844652087d28e020b4f773b68eb","name":"read","arguments":{"i":"Reading rig input sizes","path":".spt/preserved/307/hertz-w1bc/rig.py"},"intent":"Reading rig input sizes"},{"type":"toolCall","id":"call_40lTjtsW510AWGVWYnenqPm7|fc_09b01b5279447709016aa9f844652887d2874f6df36158249b","name":"read","arguments":{"i":"Reading W1c event anchors","path":".spt/preserved/307/hertz-w1bc/w1c-run1/events.jsonl:1-12"},"intent":"Reading W1c event anchors"}],"api":"openai-codex-responses","provider":"openai-codex","model":"gpt-6-astra","usage":{"input":6615,"output":274,"cacheRead":86528,"cacheWrite":0,"totalTokens":93417,"reasoningTokens":42,"cost":{"input":0.06615,"output":0.0137,"cacheRead":0.086528,"cacheWrite":0,"total":0.166378}},"stopReason":"toolUse","timestamp":1789524024168,"responseId":"resp_09b01b5279447709016aa9f838680087d2a1e2cfc7673a023c","providerPayload":{"type":"openaiResponsesHistory","provider":"openai-codex","dt":true,"items":[{"id":"rs_09b01b5279447709016aa9f839823887d2ab2cf844f26608ac","type":"reasoning","content":[],"encrypted_content":"gAAAAABqqfhETa-_B5HfKSFgli1vxdj-fATvV-zEdx_YH-0e-JS68ptpOMnv_SVKa-SJBEm67yjYTCsSbHW8ogdZv_OHdQFm9Sjn1erCXAi2mHVyuGhpWLeCaCuQMPw2iwd_7-RXVz-8MMn4f_sW3pyqxS4chSuNr1MzXxPCZD6vphG0HETbGLjtoCuwsfZuO8fY2N0nkmivuJZsn0jm52R372FFjwz15iAppy7YHOxxKvoIGszZjAgOtz81YbAKE9Kj2LTBhSLzfT8QTh1QyR08u-uAXE_22MY0m1EaIJh6_C4nhjAAtgya98Rror-tXoNvBOMVWd_F-m9bkTzgDNRwymixOnHVkkPJlG2fUuviH6VeuxvXf4kQoWjCayZeTYPS0KmY27-KkjiUh8n4i5ityGmks2_G8I0e4vkDNLVl1PAatWxpnA5uR7Y3iCxeAwp_fFlFgvpRe-9oMU00RIBZytvcCWMIloovqCctO3bymEoBrhglG5g0G4JMc8uu_ned92yyqxZmX31dWiNT3czm8TSROj5jy0HoG_6e-uiZavNArnvLk9DSEdyUb03s0GVKmh4yDYEVnovHgaSBoj4o-6wILvcSh-O5pKjipU5Va-b27J841v0iVdH38C1w758KAcGOuISFMn6PcskLejA-0ui27oVumdqg_cO1FSgP9ve0hUSW76KQwOzFdSRObvjEpNYwcIYF3NCwDwwny8UIgXFOtQr2-cngCW3pMBq7MliKeH93xzTKWwcjy-MB9ET7meZfcKxm8agJdYr-OKkiS2hOTt9u8HVTtJVZ7zM295g2tbhKDkRK0pSTTnnaGvWGQMh8qg1gEltBKo0KMtmumGy3TSRJw0IXrE-76TXMDGDXtFQhM9BOFDh59gkxbRgD_GVcTFo6MhHHuR3rq2v65ytKv9GdhY9Hoga_X9mGXoZICIBcTMFF0BKCKi4HSgyaLXDQ-gn09ben4eSC9sjw0N0_XFjTEC8ou4dDdTUL4wa6bWcO77eKXKYcQPjiOk-vF139uUAsOVDFIFDxa_D2uP_UbmM9M2Nwpu31myLdiwTMqf2p7w1hBq5KLzEiSVRmx87ECE2ajnN6uuAu0m7MQj__HL4JKlaBfrTpVT0I8jzGr2EJg2I9fNlSYnzfL0wINuZKuE-7whQeghJoYVwLoWN5FSEB3iK_5V6ICCUb1TguR1xRMcX-jJ3MJ84wvVnmGeop8teWJwB_sFheYUa5Ln8hDxh6U99X-E8_f9UxWfFdumcIEZoWyEANNG8qDdUT9-yEWI8kcaA4R9S-w6Z_GEzYJzAer43CQvKkzMobai_WrVYwq0F8u56jAbxcbKZAB0O0vzZRqnHnoBdVJkb8j8JlTdW2levCq7JukmWHnLdBu9muScjLv-2mETcpIAVoA1dypltAv30vIymPhNSODtfILNvDPT9lLa85l3eXFQnoB7Vxn7Vr0YiNkx8ava-MX1sJ_m6C0kBpiMDfQI6Gl5GsFWijTDoBXAlsa8wwFAGhxj5PyTKOxhUzG3CO48VInHfDDh6tssa_lQKRFe861sL2HJQgFJPdp_2ujP_8EXPkXe8VNTk=","internal_chat_message_metadata_passthrough":{"turn_id":"f878fb4b-0d9a-4a17-adc6-f6c9f4deeea0"},"summary":[{"type":"summary_text","text":"**Checking subscription reply order**"}],"metadata":{"turn_id":"f878fb4b-0d9a-4a17-adc6-f6c9f4deeea0"}},{"id":"fc_09b01b5279447709016aa9f844650c87d2b26effcd1a36119e","type":"function_call","status":"completed","arguments":"{\"i\":\"Reading subscribe reply ordering\",\"path\":\"crates/spt-daemon/src/broker.rs:8750-8810\"}","call_id":"call_mciEqRPD0iYGo46jSaUAHTZq","internal_chat_message_metadata_passthrough":{"turn_id":"f878fb4b-0d9a-4a17-adc6-f6c9f4deeea0"},"name":"read","metadata":{"turn_id":"f878fb4b-0d9a-4a17-adc6-f6c9f4deeea0"}},{"id":"fc_09b01b5279447709016aa9f844651c87d2a58ca8a8c8e0357e","type":"function_call","status":"completed","arguments":"{\"i\":\"Locating concrete replay tests\",\"pattern\":\"^fn .*|pending_input|ack_backpressure\",\"path\":\"crates/spt-daemon/tests/attach.rs:534-1600;crates/spt-daemon/tests/redispatch.rs:300-720;crates/spt-daemon/tests/redispatch_stall.rs:320-800\",\"case\":true,\"gitignore\":true,\"skip\":null}","call_id":"call_SRrwAo3nbRckkPI00IjWLEZH","internal_chat_message_metadata_passthrough":{"turn_id":"f878fb4b-0d9a-4a17-adc6-f6c9f4deeea0"},"name":"grep","metadata":{"turn_id":"f878fb4b-0d9a-4a17-adc6-f6c9f4deeea0"}},{"id":"fc_09b01b5279447709016aa9f844652087d28e020b4f773b68eb","type":"function_call","status":"completed","arguments":"{\"i\":\"Reading rig input sizes\",\"path\":\".spt/preserved/307/hertz-w1bc/rig.py\"}","call_id":"call_mDtCI8ulgnow8pwjeemF6ORi","internal_chat_message_metadata_passthrough":{"turn_id":"f878fb4b-0d9a-4a17-adc6-f6c9f4deeea0"},"name":"read","metadata":{"turn_id":"f878fb4b-0d9a-4a17-adc6-f6c9f4deeea0"}},{"id":"fc_09b01b5279447709016aa9f844652887d2874f6df36158249b","type":"function_call","status":"completed","arguments":"{\"i\":\"Reading W1c event anchors\",\"path\":\".spt/preserved/307/hertz-w1bc/w1c-run1/events.jsonl:1-12\"}","call_id":"call_40lTjtsW510AWGVWYnenqPm7","internal_chat_message_metadata_passthrough":{"turn_id":"f878fb4b-0d9a-4a17-adc6-f6c9f4deeea0"},"name":"read","metadata":{"turn_id":"f878fb4b-0d9a-4a17-adc6-f6c9f4deeea0"}}]},"duration":12320.147799999919,"ttft":1368.2360000000335,"completedAt":1789524036489,"contextSnapshot":{"promptTokens":93143,"nonMessageTokens":10480,"compactionEpoch":0}}}
{"type":"message","id":"ab17ccba","parentId":"8d821446","timestamp":"2026-09-16T02:00:36.498Z","message":{"role":"toolResult","toolCallId":"call_mciEqRPD0iYGo46jSaUAHTZq|fc_09b01b5279447709016aa9f844650c87d2b26effcd1a36119e","toolName":"read","content":[{"type":"text","text":"    /// self-kick guard.\n    fn dispatch_subscribe(&self, env: Envelope, send: &SharedSend) -> Result<u64, String> {\n        let req: SubscribeReq = serde_json::from_value(env.payload)\n            .map_err(|e| format!(\"bad subscribe payload: {e}\"))?;\n        // Clone the log Arc out from under the sessions lock, then resolve under\n        // the log lock — never hold both locks at once.\n        //\n        // NOTE (REQ-HAZARD-RC-ATTACH-FAILFAST): a `session.try_wait()` dead-child\n        // fast-detect MUST NOT live here — `try_wait` locks the same child mutex\n        // the per-session exit-waiter holds for the WHOLE life of a live child\n        // (`PtySession::wait`, broker.rs exit-waiter), so it deadlocks every live\n        // attach. The dead-not-reaped case needs no fast-detect: the exit-waiter\n        // already broadcasts an `Exit` frame to all attached sinks on reap, and a\n        // post-removal subscribe gets a prompt \"no such session\" error — both\n        // non-silent. The rc-side status-gate (a) + first-event backstop (b) cover\n        // the rest.\n        let log = {\n            let sessions = recover(&self.sessions);\n            let h = sessions\n                .get(&req.session_id)\n                .ok_or_else(|| format!(\"no such session {}\", req.session_id))?;\n            Arc::clone(&h.log)\n        };\n        // A bring-up this broker just admitted seats its controller without\n        // re-presenting the code, ONCE, for the session it spawned. The reason\n        // is a race, not a discount: the bounded wait for the harness can\n        // outlive the ±1 TOTP window, so the same gate that admitted a code\n        // moments ago can refuse it here — gate-admits-then-attach-refuses,\n        // which is the defect this wave closes, rebuilt one seam later.\n        //\n        // Read off the presented SECRET, not off this connection: the subscribe\n        // that seats an rc attach is sent by the dispatcher's own conn, never\n        // the one that asked for the bring-up (dispatch.rs `connect` →\n        // attach.rs `attach_as_coded`), so a conn-keyed admit could never be\n        // redeemed. The ticket rides the code field the operator's code already\n        // rides, which is the one pipe that does cross this seam.\n        // [impl->REQ-ER-BRINGUP-SPAWNS-SESSION]\n        let ticket = self.redeem_bringup_admit(req.code.as_deref(), req.session_id);\n        let (outcome, seat_note) = recover_log(&log).resolve_subscribe_gated(\n            Arc::clone(send),\n            req.from_seq,\n            req.intent,\n            req.by,\n            req.gen,\n            // The bring-up code the operator presented, for the ONE endpoint whose\n            // seat resolver demands one (ADR-0052 decision 2).\n            // [impl->REQ-ER-BRINGUP-TOTP-GATE]\n            req.code,\n            ticket,\n            // The W2 seal-ceremony capability this client declared.\n            // [impl->REQ-SEAL-NO-CEREMONY-SURFACE]\n            req.seal_ceremony,\n        );\n        send_frame(\n            send,\n            &subscribed_envelope(req.session_id, outcome, seat_note),\n        );\n        Ok(req.session_id)\n    }\n\n    /// Release this connection's controller/viewer role on a session\n    /// (REQ-RCVIEW-1): clears the controller slot iff this is the controller\n    /// (re-stamping `driven_by`) and removes any viewer rows it owns\n    /// (re-stamping `viewer_count`). The explicit detach a `serve_attach` worker\n    /// sends when its viewport ends, so the markers clear promptly. Idempotent —\n\n[Showing lines 8749-8813 of 16852. Use :8814 to continue]"}],"details":{"truncation":{"content":"    /// self-kick guard.\r\n    fn dispatch_subscribe(&self, env: Envelope, send: &SharedSend) -> Result<u64, String> {\r\n        let req: SubscribeReq = serde_json::from_value(env.payload)\r\n            .map_err(|e| format!(\"bad subscribe payload: {e}\"))?;\r\n        // Clone the log Arc out from under the sessions lock, then resolve under\r\n        // the log lock — never hold both locks at once.\r\n        //\r\n        // NOTE (REQ-HAZARD-RC-ATTACH-FAILFAST): a `session.try_wait()` dead-child\r\n        // fast-detect MUST NOT live here — `try_wait` locks the same child mutex\r\n        // the per-session exit-waiter holds for the WHOLE life of a live child\r\n        // (`PtySession::wait`, broker.rs exit-waiter), so it deadlocks every live\r\n        // attach. The dead-not-reaped case needs no fast-detect: the exit-waiter\r\n        // already broadcasts an `Exit` frame to all attached sinks on reap, and a\r\n        // post-removal subscribe gets a prompt \"no such session\" error — both\r\n        // non-silent. The rc-side status-gate (a) + first-event backstop (b) cover\r\n        // the rest.\r\n        let log = {\r\n            let sessions = recover(&self.sessions);\r\n            let h = sessions\r\n                .get(&req.session_id)\r\n                .ok_or_else(|| format!(\"no such session {}\", req.session_id))?;\r\n            Arc::clone(&h.log)\r\n        };\r\n        // A bring-up this broker just admitted seats its controller without\r\n        // re-presenting the code, ONCE, for the session it spawned. The reason\r\n        // is a race, not a discount: the bounded wait for the harness can\r\n        // outlive the ±1 TOTP window, so the same gate that admitted a code\r\n        // moments ago can refuse it here — gate-admits-then-attach-refuses,\r\n        // which is the defect this wave closes, rebuilt one seam later.\r\n        //\r\n        // Read off the presented SECRET, not off this connection: the subscribe\r\n        // that seats an rc attach is sent by the dispatcher's own conn, never\r\n        // the one that asked for the bring-up (dispatch.rs `connect` →\r\n        // attach.rs `attach_as_coded`), so a conn-keyed admit could never be\r\n        // redeemed. The ticket rides the code field the operator's code already\r\n        // rides, which is the one pipe that does cross this seam.\r\n        // [impl->REQ-ER-BRINGUP-SPAWNS-SESSION]\r\n        let ticket = self.redeem_bringup_admit(req.code.as_deref(), req.session_id);\r\n        let (outcome, seat_note) = recover_log(&log).resolve_subscribe_gated(\r\n            Arc::clone(send),\r\n            req.from_seq,\r\n            req.intent,\r\n            req.by,\r\n            req.gen,\r\n            // The bring-up code the operator presented, for the ONE endpoint whose\r\n            // seat resolver demands one (ADR-0052 decision 2).\r\n            // [impl->REQ-ER-BRINGUP-TOTP-GATE]\r\n            req.code,\r\n            ticket,\r\n            // The W2 seal-ceremony capability this client declared.\r\n            // [impl->REQ-SEAL-NO-CEREMONY-SURFACE]\r\n            req.seal_ceremony,\r\n        );\r\n        send_frame(\r\n            send,\r\n            &subscribed_envelope(req.session_id, outcome, seat_note),\r\n        );\r\n        Ok(req.session_id)\r\n    }\r\n\r\n    /// Release this connection's controller/viewer role on a session\r\n    /// (REQ-RCVIEW-1): clears the controller slot iff this is the controller\r\n    /// (re-stamping `driven_by`) and removes any viewer rows it owns\r\n    /// (re-stamping `viewer_count`). The explicit detach a `serve_attach` worker\r\n    /// sends when its viewport ends, so the markers clear promptly. Idempotent —\r","truncated":true,"truncatedBy":"lines","totalLines":8104,"totalBytes":3613,"outputLines":65,"outputBytes":3613,"lastLinePartial":false,"firstLineExceedsLimit":false},"totalLines":16852,"displayContent":{"text":"    /// self-kick guard.\r\n    fn dispatch_subscribe(&self, env: Envelope, send: &SharedSend) -> Result<u64, String> {\r\n        let req: SubscribeReq = serde_json::from_value(env.payload)\r\n            .map_err(|e| format!(\"bad subscribe payload: {e}\"))?;\r\n        // Clone the log Arc out from under the sessions lock, then resolve under\r\n        // the log lock — never hold both locks at once.\r\n        //\r\n        // NOTE (REQ-HAZARD-RC-ATTACH-FAILFAST): a `session.try_wait()` dead-child\r\n        // fast-detect MUST NOT live here — `try_wait` locks the same child mutex\r\n        // the per-session exit-waiter holds for the WHOLE life of a live child\r\n        // (`PtySession::wait`, broker.rs exit-waiter), so it deadlocks every live\r\n        // attach. The dead-not-reaped case needs no fast-detect: the exit-waiter\r\n        // already broadcasts an `Exit` frame to all attached sinks on reap, and a\r\n        // post-removal subscribe gets a prompt \"no such session\" error — both\r\n        // non-silent. The rc-side status-gate (a) + first-event backstop (b) cover\r\n        // the rest.\r\n        let log = {\r\n            let sessions = recover(&self.sessions);\r\n            let h = sessions\r\n                .get(&req.session_id)\r\n                .ok_or_else(|| format!(\"no such session {}\", req.session_id))?;\r\n            Arc::clone(&h.log)\r\n        };\r\n        // A bring-up this broker just admitted seats its controller without\r\n        // re-presenting the code, ONCE, for the session it spawned. The reason\r\n        // is a race, not a discount: the bounded wait for the harness can\r\n        // outlive the ±1 TOTP window, so the same gate that admitted a code\r\n        // moments ago can refuse it here — gate-admits-then-attach-refuses,\r\n        // which is the defect this wave closes, rebuilt one seam later.\r\n        //\r\n        // Read off the presented SECRET, not off this connection: the subscribe\r\n        // that seats an rc attach is sent by the dispatcher's own conn, never\r\n        // the one that asked for the bring-up (dispatch.rs `connect` →\r\n        // attach.rs `attach_as_coded`), so a conn-keyed admit could never be\r\n        // redeemed. The ticket rides the code field the operator's code already\r\n        // rides, which is the one pipe that does cross this seam.\r\n        // [impl->REQ-ER-BRINGUP-SPAWNS-SESSION]\r\n        let ticket = self.redeem_bringup_admit(req.code.as_deref(), req.session_id);\r\n        let (outcome, seat_note) = recover_log(&log).resolve_subscribe_gated(\r\n            Arc::clone(send),\r\n            req.from_seq,\r\n            req.intent,\r\n            req.by,\r\n            req.gen,\r\n            // The bring-up code the operator presented, for the ONE endpoint whose\r\n            // seat resolver demands one (ADR-0052 decision 2).\r\n            // [impl->REQ-ER-BRINGUP-TOTP-GATE]\r\n            req.code,\r\n            ticket,\r\n            // The W2 seal-ceremony capability this client declared.\r\n            // [impl->REQ-SEAL-NO-CEREMONY-SURFACE]\r\n            req.seal_ceremony,\r\n        );\r\n        send_frame(\r\n            send,\r\n            &subscribed_envelope(req.session_id, outcome, seat_note),\r\n        );\r\n        Ok(req.session_id)\r\n    }\r\n\r\n    /// Release this connection's controller/viewer role on a session\r\n    /// (REQ-RCVIEW-1): clears the controller slot iff this is the controller\r\n    /// (re-stamping `driven_by`) and removes any viewer rows it owns\r\n    /// (re-stamping `viewer_count`). The explicit detach a `serve_attach` worker\r\n    /// sends when its viewport ends, so the markers clear promptly. Idempotent —\r","startLine":8749,"lineNumbers":[8749,8750,8751,8752,8753,8754,8755,8756,8757,8758,8759,8760,8761,8762,8763,8764,8765,8766,8767,8768,8769,8770,8771,8772,8773,8774,8775,8776,8777,8778,8779,8780,8781,8782,8783,8784,8785,8786,8787,8788,8789,8790,8791,8792,8793,8794,8795,8796,8797,8798,8799,8800,8801,8802,8803,8804,8805,8806,8807,8808,8809,8810,8811,8812,8813]},"fileSize":877537,"meta":{"source":{"type":"path","value":"C:\\Users\\decid\\Documents\\projects\\spt-core\\crates\\spt-daemon\\src\\broker.rs"},"truncation":{"direction":"head","truncatedBy":"lines","totalLines":16852,"totalBytes":3613,"outputLines":65,"outputBytes":3613,"shownRange":{"start":8749,"end":8813},"nextOffset":8814}}},"isError":false,"timestamp":1789524036498}}
{"type":"message","id":"d74bce61","parentId":"ab17ccba","timestamp":"2026-09-16T02:00:36.501Z","message":{"role":"toolResult","toolCallId":"call_mDtCI8ulgnow8pwjeemF6ORi|fc_09b01b5279447709016aa9f844652087d28e020b4f773b68eb","toolName":"read","content":[{"type":"text","text":"\"\"\"#307 evidence-only isolated-home driver. Run under retained native job launcher.\"\"\"\nimport argparse\nimport ctypes\nfrom ctypes import wintypes\nimport datetime\nimport hashlib\nimport json\nimport os\nfrom pathlib import Path\nimport re\nimport shutil\nimport subprocess\nimport sys\nimport threading\nimport time\nimport traceback\n\nimport psutil\n\nBASE = Path(__file__).resolve().parent\nPERCH_ENV = ('OWL_SESSION_ID', 'SPT_AGENT_ID', 'SPT_ENDPOINT_ID', 'SPT_SESSION_NAME',\n             'SPT_SESSION_ID', 'SPT_ADAPTER', 'SPT_HOST_PID', 'SPT_INJECT_VERIFY_ECHO')\nk32 = ctypes.WinDLL('kernel32', use_last_error=True)\nk32.CreateFileW.argtypes = [wintypes.LPCWSTR, wintypes.DWORD, wintypes.DWORD, ctypes.c_void_p,\n                           wintypes.DWORD, wintypes.DWORD, wintypes.HANDLE]\nk32.CreateFileW.restype = wintypes.HANDLE\nk32.GetNamedPipeServerProcessId.argtypes = [wintypes.HANDLE, ctypes.POINTER(wintypes.ULONG)]\nk32.GetNamedPipeServerProcessId.restype = wintypes.BOOL\nk32.CloseHandle.argtypes = [wintypes.HANDLE]\nk32.GetProcessId.argtypes = [wintypes.HANDLE]\nk32.GetProcessId.restype = wintypes.DWORD\nINVALID_HANDLE = ctypes.c_void_p(-1).value\n\n\ndef now_ms():\n    return time.time_ns() // 1000000\n\n\ndef sha(path):\n    with Path(path).open('rb') as f:\n        return hashlib.file_digest(f, 'sha256').hexdigest()\n\n\ndef save(path, data):\n    Path(path).write_text(json.dumps(data, indent=2) + '\\n', encoding='utf-8')\n\n\ndef pipe_pid(name):\n    handle = k32.CreateFileW('\\\\\\\\.\\\\pipe\\\\' + name, 0xC0000000, 0, None, 3, 0x40000000, None)\n    if handle == INVALID_HANDLE:\n        return {'error': ctypes.get_last_error()}\n    try:\n        pid = wintypes.ULONG()\n        if not k32.GetNamedPipeServerProcessId(handle, ctypes.byref(pid)):\n            return {'error': ctypes.get_last_error()}\n        return {'pid': pid.value}\n    finally:\n        k32.CloseHandle(handle)\n\n\nclass Rig:\n    def __init__(self, args):\n        self.args = args\n        self.out = Path(args.output).resolve()\n        self.out.mkdir(exist_ok=False)\n        self.home = self.out / ('home-' + args.lane)\n        self.started = time.monotonic()\n        self.deadline = self.started + 300\n        self.cleanup_deadline = None\n        self.events = (self.out / 'events.jsonl').open('a', encoding='utf-8', buffering=1)\n        self.lock = threading.Lock()\n        self.broker = None\n        self.rc = None\n        self.read_allowed = threading.Event()\n        self.read_allowed.set()\n        self.reader = None\n        self.trace_stop = threading.Event()\n        self.trace_reader = None\n        self.records = []\n        self.owned = {}\n        self.streams = []\n        self.phase = 'admission'\n        self.rc_number = 0\n        self.cmd_number = 0\n        self.backup = None\n        self.restored = False\n        self.ancestor_ids = {os.getpid(), *(p.pid for p in psutil.Process().parents())}\n        self.preexisting_spt = {p.pid for p in psutil.process_iter(['name'])\n                               if (p.info['name'] or '').lower() == 'spt.exe'}\n        self.resident = Path(os.environ['LOCALAPPDATA']) / 'spt-core'\n        assert not self.home.exists()\n        assert self.resident.resolve() not in self.home.parents\n        self.env = dict(os.environ)\n        removed = []\n        for key in list(self.env):\n            if key.startswith(('SPT_', 'OWL_', 'CLAUDE_')):\n                removed.append(key)\n                del self.env[key]\n        self.env.update(SPT_HOME=str(self.home), SPT_TEST_EPHEMERAL_ADVISORY_PORTS='1',\n                        SPT_INSTALL_NO_FIREWALL='1', SPT_PUMP_TRACE='1', PYTHONUNBUFFERED='1')\n        self.spt_source = Path(args.binary).resolve()\n        self.pin = args.sha256\n        assert sha(self.spt_source) == self.pin\n        self.bin_dir = self.out / 'bin'\n        self.bin_dir.mkdir()\n        self.spt = self.bin_dir / 'spt.exe'\n        shutil.copy2(self.spt_source, self.spt)\n        assert sha(self.spt) == self.pin\n        self.sockets = self.socket_names(self.env)\n        resident_env = {**self.env, 'SPT_HOME': str(self.resident)}\n        self.resident_sockets = self.socket_names(resident_env)\n        assert not set(self.sockets) & set(self.resident_sockets)\n        before = {name: pipe_pid(name) for name in self.sockets}\n        assert all(row.get('error') == 2 for row in before.values()), before\n        self.home.mkdir()\n        # Valid default config, required so the cadence backup has exact original bytes.\n        (self.home / 'daemon.json').write_bytes(b'{}\\n')\n        self.event('ADMITTED_HOME', home=str(self.home), explicit_env=self.env['SPT_HOME'],\n                   sockets=self.sockets, resident_sockets=self.resident_sockets,\n                   sockets_before=before, excluded_pids=sorted(self.preexisting_spt | self.ancestor_ids),\n                   source=str(self.spt_source), executable=str(self.spt), sha256=self.pin,\n                   removed_environment_names=removed, observation_bound_s=300, teardown_bound_s=120)\n\n    def socket_names(self, env):\n        r = subprocess.run([self.args.socket_helper], env=env, capture_output=True, text=True,\n                           timeout=10)\n        assert r.returncode == 0, r.stderr\n        lines = r.stdout.splitlines()\n        assert len(lines) == 3 and lines[0] == env['SPT_HOME'], lines\n        assert lines[1].startswith('spt-daemon-broker-') and lines[2].startswith('spt-daemon-seed-')\n        return lines[1:]\n\n    def event(self, kind, **data):\n        row = {'event': kind, 'at_ms': now_ms(), 'elapsed_s': time.monotonic() - self.started,\n               'phase': self.phase, 'box': os.environ.get('COMPUTERNAME'),\n               'route': 'hfenduleam-isolated-native-local', **data}\n        with self.lock:\n            self.events.write(json.dumps(row) + '\\n')\n        return row\n\n    def remaining(self):\n        return max(0, (self.cleanup_deadline or self.deadline) - time.monotonic())\n\n    def identify(self, pid, role):\n        proc = psutil.Process(pid)\n        row = {'pid': pid, 'birth': proc.create_time(), 'exe': proc.exe(), 'ppid': proc.ppid(),\n               'role': role, 'ancestors': [p.pid for p in proc.parents()]}\n        assert pid not in self.preexisting_spt | self.ancestor_ids, row\n        assert os.getpid() in row['ancestors'], row\n        self.owned[pid] = row\n        self.event('OWNED_PROCESS', **row)\n        return row\n\n    def guard(self, reason):\n        assert self.broker is not None and self.broker.poll() is None\n        expected = self.owned[self.broker.pid]\n        proc = psutil.Process(self.broker.pid)\n        assert proc.create_time() == expected['birth']\n        image = Path(proc.exe()).resolve()\n        # Same-byte apply may rename the still-running broker image to its owned aside.\n        assert image.parent == self.bin_dir and sha(image) == self.pin\n        assert k32.GetProcessId(int(self.broker._handle)) == self.broker.pid\n        assert self.broker.pid not in self.preexisting_spt | self.ancestor_ids\n        assert os.getpid() in [p.pid for p in proc.parents()]\n        assert self.env['SPT_HOME'] == str(self.home)\n        actual = self.socket_names(self.env)\n        assert actual == self.sockets and not set(actual) & set(self.resident_sockets)\n        endpoints = {name: pipe_pid(name) for name in actual}\n        assert all(row.get('pid') == self.broker.pid for row in endpoints.values()), endpoints\n        self.event('MUTATION_GUARD', reason=reason, home=self.env['SPT_HOME'],\n                   broker_pid=self.broker.pid, birth=expected['birth'], endpoints=endpoints,\n                   owned_handle_pid=k32.GetProcessId(int(self.broker._handle)))\n\n    def command(self, args, mutate=False, timeout=20, env_extra=None, executable=None):\n        if mutate:\n            self.guard(' '.join(args))\n        assert self.remaining() > 0, 'phase deadline exhausted before command'\n        env = {**self.env, **(env_extra or {})}\n        assert env['SPT_HOME'] == str(self.home)\n        argv = [str(executable or self.spt), *args]\n        # cmd parses its own command tail, not CRT argv quoting.\n        launch = (subprocess.list2cmdline(argv[:3]) + ' ' + argv[3]\n                  if Path(argv[0]).name.lower() == 'cmd.exe' else argv)\n        self.cmd_number += 1\n        num = self.cmd_number\n        self.event('COMMAND_START', command=num, argv=argv, home=env['SPT_HOME'])\n        began = time.monotonic()\n        result = subprocess.run(launch, env=env, cwd=self.out, capture_output=True, text=True,\n                                encoding='utf-8', errors='replace',\n                                timeout=min(timeout, max(.1, self.remaining())))\n        record = {'argv': argv, 'exit': result.returncode, 'stdout': result.stdout,\n                  'stderr': result.stderr, 'elapsed_ms': (time.monotonic()-began)*1000,\n                  'home': env['SPT_HOME']}\n        save(self.out / f'command-{num:03}.json', record)\n        self.event('COMMAND_END', command=num, exit=result.returncode,\n                   elapsed_ms=record['elapsed_ms'])\n        return result\n\n    def start(self):\n        self.phase = 'startup'\n        assert sha(self.spt) == self.pin\n        log = (self.out/'daemon.stderr.log').open('wb')\n        self.streams.append(log)\n        self.broker = subprocess.Popen([str(self.spt), 'daemon', 'run'], env=self.env,\n                                      cwd=self.out, stdin=subprocess.DEVNULL,\n                                      stdout=subprocess.DEVNULL, stderr=log,\n                                      creationflags=subprocess.CREATE_NO_WINDOW)\n        self.identify(self.broker.pid, 'broker')\n        def trace_output():\n            pending = ''\n            sink = self.home/'logs/daemon.stderr.log'\n            while not sink.exists() and not self.trace_stop.wait(.02):\n                pass\n            if self.trace_stop.is_set():\n                return\n            with sink.open('r',encoding='utf-8',errors='replace') as stream:\n                while not self.trace_stop.is_set():\n                    pending += stream.read(65536)\n                    lines = pending.split('\\n')\n                    pending = lines.pop()\n                    for line in lines:\n                        if any(token in line for token in ('BRAIN_','CONTROLLER_SLOT_CLOSED','SUBSCRIBE_DECISION','ENDPOINT_RUN')):\n                            self.event('DAEMON_TRACE',line=line)\n                    self.trace_stop.wait(.02)\n        self.trace_reader = threading.Thread(target=trace_output,daemon=True)\n        self.trace_reader.start()\n        end = min(self.deadline, time.monotonic() + 45)\n        while time.monotonic() < end:\n            if self.broker.poll() is not None:\n                raise RuntimeError('isolated daemon exited during startup')\n            ready = self.home/'brain.ready'\n            try:\n                state = json.loads(ready.read_text())\n                pid = state['pid']\n                brain = self.identify(pid, 'brain')\n                assert self.broker.pid in brain['ancestors']\n                self.guard('startup complete')\n                save(self.out/'brain-ready-start.json', state)\n                break\n            except (OSError, ValueError, KeyError, psutil.Error, AssertionError):\n                time.sleep(.2)\n        else:\n            raise RuntimeError('isolated daemon failed 45s startup admission')\n        print('ISOLATED_DAEMON_READY', flush=True)\n\n    def fixture(self):\n        self.guard('create disposable adapter files')\n        src = self.home/'srcs/evidencerig'\n        src.mkdir(parents=True)\n        drops = self.home/'drops'\n        drops.mkdir()\n        shutil.copy2(self.spt, src/'psychebin.exe')\n        mode = 'hitch' if self.args.lane == 'w1c' else 'refresh'\n        # The command template follows dummy_harness_e2e's existing contract.\n        quote = lambda x: '\"' + str(x).replace('\\\\', '/') + '\"'\n        cmd = (f'{quote(sys.executable)} -u {quote(BASE/\"generator.py\")} '\n               f'--spt {quote(self.spt)} --home {quote(self.home)} '\n               f'--id {{id}} --session-id {{session_id}} --mode {mode}')\n        manifest = ('[adapter]\\nname=\"evidencerig\"\\nkind=\"harness\"\\nversion=\"1\"\\n'\n                    'min_spt_core_version=\"0\"\\n\\n[session.self]\\ncommand=\\''+cmd+'\\'\\n\\n'\n                    '[session]\\ncommune_dir=\"'+drops.as_posix()+'\"\\nsignoff_dir=\"'+drops.as_posix()+'\"\\n\\n'\n                    '[session.psyche_init]\\ncommand=\\'psychebin ready {id}\\'\\ncwd=\"{psyche_dir}\"\\nkeys=[]\\n')\n        (src/'manifest.toml').write_text(manifest, encoding='utf-8')\n        for args in (['adapter','add',str(src)],\n                     ['endpoint','create',self.args.lane+'rig','--adapter','evidencerig'],\n                     ['endpoint','start',self.args.lane+'rig']):\n            r = self.command(args, mutate=True, timeout=35)\n            if r.returncode:\n                raise RuntimeError('fixture command refused: '+r.stderr)\n        self.attach()\n        end = min(self.deadline, time.monotonic()+15)\n        while time.monotonic() < end:\n            if any(row['kind']=='PROG' for row in self.records):\n                print('RIG_READY', flush=True)\n                return\n            time.sleep(.1)\n        raise RuntimeError('real RC progress not observed within attach bound')\n\n    def attach(self):\n        self.guard('rc attach')\n        self.rc_number += 1\n        err = (self.out/f'rc-{self.rc_number}.stderr.log').open('wb')\n        self.streams.append(err)\n        self.rc = subprocess.Popen([str(self.spt),'rc',self.args.lane+'rig'], env=self.env,\n                                   cwd=self.out, stdin=subprocess.PIPE, stdout=subprocess.PIPE,\n                                   stderr=err, creationflags=subprocess.CREATE_NO_WINDOW)\n        self.identify(self.rc.pid, 'rc-'+str(self.rc_number))\n        self.read_allowed.set()\n        child, number = self.rc, self.rc_number\n        def read_output():\n            acc = ''\n            raw = (self.out/f'rc-{number}.chunks.jsonl').open('a',encoding='utf-8',buffering=1)\n            parsed = (self.out/f'rc-{number}.progress.jsonl').open('a',encoding='utf-8',buffering=1)\n            try:\n                while True:\n                    self.read_allowed.wait()\n                    chunk = os.read(child.stdout.fileno(), 8192)\n                    if not chunk:\n                        break\n                    received = now_ms()\n…\n                        acc=acc[-8192:]\n…\n                parsed.close()\n…\n        self.reader.start()\n…\n        return confirmed and not errors\n\n[Showing lines 1-300 of 608. Use :301 to continue]"}],"details":{"truncation":{"content":"\"\"\"#307 evidence-only isolated-home driver. Run under retained native job launcher.\"\"\"\nimport argparse\nimport ctypes\nfrom ctypes import wintypes\nimport datetime\nimport hashlib\nimport json\nimport os\nfrom pathlib import Path\nimport re\nimport shutil\nimport subprocess\nimport sys\nimport threading\nimport time\nimport traceback\n\nimport psutil\n\nBASE = Path(__file__).resolve().parent\nPERCH_ENV = ('OWL_SESSION_ID', 'SPT_AGENT_ID', 'SPT_ENDPOINT_ID', 'SPT_SESSION_NAME',\n             'SPT_SESSION_ID', 'SPT_ADAPTER', 'SPT_HOST_PID', 'SPT_INJECT_VERIFY_ECHO')\nk32 = ctypes.WinDLL('kernel32', use_last_error=True)\nk32.CreateFileW.argtypes = [wintypes.LPCWSTR, wintypes.DWORD, wintypes.DWORD, ctypes.c_void_p,\n                           wintypes.DWORD, wintypes.DWORD, wintypes.HANDLE]\nk32.CreateFileW.restype = wintypes.HANDLE\nk32.GetNamedPipeServerProcessId.argtypes = [wintypes.HANDLE, ctypes.POINTER(wintypes.ULONG)]\nk32.GetNamedPipeServerProcessId.restype = wintypes.BOOL\nk32.CloseHandle.argtypes = [wintypes.HANDLE]\nk32.GetProcessId.argtypes = [wintypes.HANDLE]\nk32.GetProcessId.restype = wintypes.DWORD\nINVALID_HANDLE = ctypes.c_void_p(-1).value\n\n\ndef now_ms():\n    return time.time_ns() // 1000000\n\n\ndef sha(path):\n    with Path(path).open('rb') as f:\n        return hashlib.file_digest(f, 'sha256').hexdigest()\n\n\ndef save(path, data):\n    Path(path).write_text(json.dumps(data, indent=2) + '\\n', encoding='utf-8')\n\n\ndef pipe_pid(name):\n    handle = k32.CreateFileW('\\\\\\\\.\\\\pipe\\\\' + name, 0xC0000000, 0, None, 3, 0x40000000, None)\n    if handle == INVALID_HANDLE:\n        return {'error': ctypes.get_last_error()}\n    try:\n        pid = wintypes.ULONG()\n        if not k32.GetNamedPipeServerProcessId(handle, ctypes.byref(pid)):\n            return {'error': ctypes.get_last_error()}\n        return {'pid': pid.value}\n    finally:\n        k32.CloseHandle(handle)\n\n\nclass Rig:\n    def __init__(self, args):\n        self.args = args\n        self.out = Path(args.output).resolve()\n        self.out.mkdir(exist_ok=False)\n        self.home = self.out / ('home-' + args.lane)\n        self.started = time.monotonic()\n        self.deadline = self.started + 300\n        self.cleanup_deadline = None\n        self.events = (self.out / 'events.jsonl').open('a', encoding='utf-8', buffering=1)\n        self.lock = threading.Lock()\n        self.broker = None\n        self.rc = None\n        self.read_allowed = threading.Event()\n        self.read_allowed.set()\n        self.reader = None\n        self.trace_stop = threading.Event()\n        self.trace_reader = None\n        self.records = []\n        self.owned = {}\n        self.streams = []\n        self.phase = 'admission'\n        self.rc_number = 0\n        self.cmd_number = 0\n        self.backup = None\n        self.restored = False\n        self.ancestor_ids = {os.getpid(), *(p.pid for p in psutil.Process().parents())}\n        self.preexisting_spt = {p.pid for p in psutil.process_iter(['name'])\n                               if (p.info['name'] or '').lower() == 'spt.exe'}\n        self.resident = Path(os.environ['LOCALAPPDATA']) / 'spt-core'\n        assert not self.home.exists()\n        assert self.resident.resolve() not in self.home.parents\n        self.env = dict(os.environ)\n        removed = []\n        for key in list(self.env):\n            if key.startswith(('SPT_', 'OWL_', 'CLAUDE_')):\n                removed.append(key)\n                del self.env[key]\n        self.env.update(SPT_HOME=str(self.home), SPT_TEST_EPHEMERAL_ADVISORY_PORTS='1',\n                        SPT_INSTALL_NO_FIREWALL='1', SPT_PUMP_TRACE='1', PYTHONUNBUFFERED='1')\n        self.spt_source = Path(args.binary).resolve()\n        self.pin = args.sha256\n        assert sha(self.spt_source) == self.pin\n        self.bin_dir = self.out / 'bin'\n        self.bin_dir.mkdir()\n        self.spt = self.bin_dir / 'spt.exe'\n        shutil.copy2(self.spt_source, self.spt)\n        assert sha(self.spt) == self.pin\n        self.sockets = self.socket_names(self.env)\n        resident_env = {**self.env, 'SPT_HOME': str(self.resident)}\n        self.resident_sockets = self.socket_names(resident_env)\n        assert not set(self.sockets) & set(self.resident_sockets)\n        before = {name: pipe_pid(name) for name in self.sockets}\n        assert all(row.get('error') == 2 for row in before.values()), before\n        self.home.mkdir()\n        # Valid default config, required so the cadence backup has exact original bytes.\n        (self.home / 'daemon.json').write_bytes(b'{}\\n')\n        self.event('ADMITTED_HOME', home=str(self.home), explicit_env=self.env['SPT_HOME'],\n                   sockets=self.sockets, resident_sockets=self.resident_sockets,\n                   sockets_before=before, excluded_pids=sorted(self.preexisting_spt | self.ancestor_ids),\n                   source=str(self.spt_source), executable=str(self.spt), sha256=self.pin,\n                   removed_environment_names=removed, observation_bound_s=300, teardown_bound_s=120)\n\n    def socket_names(self, env):\n        r = subprocess.run([self.args.socket_helper], env=env, capture_output=True, text=True,\n                           timeout=10)\n        assert r.returncode == 0, r.stderr\n        lines = r.stdout.splitlines()\n        assert len(lines) == 3 and lines[0] == env['SPT_HOME'], lines\n        assert lines[1].startswith('spt-daemon-broker-') and lines[2].startswith('spt-daemon-seed-')\n        return lines[1:]\n\n    def event(self, kind, **data):\n        row = {'event': kind, 'at_ms': now_ms(), 'elapsed_s': time.monotonic() - self.started,\n               'phase': self.phase, 'box': os.environ.get('COMPUTERNAME'),\n               'route': 'hfenduleam-isolated-native-local', **data}\n        with self.lock:\n            self.events.write(json.dumps(row) + '\\n')\n        return row\n\n    def remaining(self):\n        return max(0, (self.cleanup_deadline or self.deadline) - time.monotonic())\n\n    def identify(self, pid, role):\n        proc = psutil.Process(pid)\n        row = {'pid': pid, 'birth': proc.create_time(), 'exe': proc.exe(), 'ppid': proc.ppid(),\n               'role': role, 'ancestors': [p.pid for p in proc.parents()]}\n        assert pid not in self.preexisting_spt | self.ancestor_ids, row\n        assert os.getpid() in row['ancestors'], row\n        self.owned[pid] = row\n        self.event('OWNED_PROCESS', **row)\n        return row\n\n    def guard(self, reason):\n        assert self.broker is not None and self.broker.poll() is None\n        expected = self.owned[self.broker.pid]\n        proc = psutil.Process(self.broker.pid)\n        assert proc.create_time() == expected['birth']\n        image = Path(proc.exe()).resolve()\n        # Same-byte apply may rename the still-running broker image to its owned aside.\n        assert image.parent == self.bin_dir and sha(image) == self.pin\n        assert k32.GetProcessId(int(self.broker._handle)) == self.broker.pid\n        assert self.broker.pid not in self.preexisting_spt | self.ancestor_ids\n        assert os.getpid() in [p.pid for p in proc.parents()]\n        assert self.env['SPT_HOME'] == str(self.home)\n        actual = self.socket_names(self.env)\n        assert actual == self.sockets and not set(actual) & set(self.resident_sockets)\n        endpoints = {name: pipe_pid(name) for name in actual}\n        assert all(row.get('pid') == self.broker.pid for row in endpoints.values()), endpoints\n        self.event('MUTATION_GUARD', reason=reason, home=self.env['SPT_HOME'],\n                   broker_pid=self.broker.pid, birth=expected['birth'], endpoints=endpoints,\n                   owned_handle_pid=k32.GetProcessId(int(self.broker._handle)))\n\n    def command(self, args, mutate=False, timeout=20, env_extra=None, executable=None):\n        if mutate:\n            self.guard(' '.join(args))\n        assert self.remaining() > 0, 'phase deadline exhausted before command'\n        env = {**self.env, **(env_extra or {})}\n        assert env['SPT_HOME'] == str(self.home)\n        argv = [str(executable or self.spt), *args]\n        # cmd parses its own command tail, not CRT argv quoting.\n        launch = (subprocess.list2cmdline(argv[:3]) + ' ' + argv[3]\n                  if Path(argv[0]).name.lower() == 'cmd.exe' else argv)\n        self.cmd_number += 1\n        num = self.cmd_number\n        self.event('COMMAND_START', command=num, argv=argv, home=env['SPT_HOME'])\n        began = time.monotonic()\n        result = subprocess.run(launch, env=env, cwd=self.out, capture_output=True, text=True,\n                                encoding='utf-8', errors='replace',\n                                timeout=min(timeout, max(.1, self.remaining())))\n        record = {'argv': argv, 'exit': result.returncode, 'stdout': result.stdout,\n                  'stderr': result.stderr, 'elapsed_ms': (time.monotonic()-began)*1000,\n                  'home': env['SPT_HOME']}\n        save(self.out / f'command-{num:03}.json', record)\n        self.event('COMMAND_END', command=num, exit=result.returncode,\n                   elapsed_ms=record['elapsed_ms'])\n        return result\n\n    def start(self):\n        self.phase = 'startup'\n        assert sha(self.spt) == self.pin\n        log = (self.out/'daemon.stderr.log').open('wb')\n        self.streams.append(log)\n        self.broker = subprocess.Popen([str(self.spt), 'daemon', 'run'], env=self.env,\n                                      cwd=self.out, stdin=subprocess.DEVNULL,\n                                      stdout=subprocess.DEVNULL, stderr=log,\n                                      creationflags=subprocess.CREATE_NO_WINDOW)\n        self.identify(self.broker.pid, 'broker')\n        def trace_output():\n            pending = ''\n            sink = self.home/'logs/daemon.stderr.log'\n            while not sink.exists() and not self.trace_stop.wait(.02):\n                pass\n            if self.trace_stop.is_set():\n                return\n            with sink.open('r',encoding='utf-8',errors='replace') as stream:\n                while not self.trace_stop.is_set():\n                    pending += stream.read(65536)\n                    lines = pending.split('\\n')\n                    pending = lines.pop()\n                    for line in lines:\n                        if any(token in line for token in ('BRAIN_','CONTROLLER_SLOT_CLOSED','SUBSCRIBE_DECISION','ENDPOINT_RUN')):\n                            self.event('DAEMON_TRACE',line=line)\n                    self.trace_stop.wait(.02)\n        self.trace_reader = threading.Thread(target=trace_output,daemon=True)\n        self.trace_reader.start()\n        end = min(self.deadline, time.monotonic() + 45)\n        while time.monotonic() < end:\n            if self.broker.poll() is not None:\n                raise RuntimeError('isolated daemon exited during startup')\n            ready = self.home/'brain.ready'\n            try:\n                state = json.loads(ready.read_text())\n                pid = state['pid']\n                brain = self.identify(pid, 'brain')\n                assert self.broker.pid in brain['ancestors']\n                self.guard('startup complete')\n                save(self.out/'brain-ready-start.json', state)\n                break\n            except (OSError, ValueError, KeyError, psutil.Error, AssertionError):\n                time.sleep(.2)\n        else:\n            raise RuntimeError('isolated daemon failed 45s startup admission')\n        print('ISOLATED_DAEMON_READY', flush=True)\n\n    def fixture(self):\n        self.guard('create disposable adapter files')\n        src = self.home/'srcs/evidencerig'\n        src.mkdir(parents=True)\n        drops = self.home/'drops'\n        drops.mkdir()\n        shutil.copy2(self.spt, src/'psychebin.exe')\n        mode = 'hitch' if self.args.lane == 'w1c' else 'refresh'\n        # The command template follows dummy_harness_e2e's existing contract.\n        quote = lambda x: '\"' + str(x).replace('\\\\', '/') + '\"'\n        cmd = (f'{quote(sys.executable)} -u {quote(BASE/\"generator.py\")} '\n               f'--spt {quote(self.spt)} --home {quote(self.home)} '\n               f'--id {{id}} --session-id {{session_id}} --mode {mode}')\n        manifest = ('[adapter]\\nname=\"evidencerig\"\\nkind=\"harness\"\\nversion=\"1\"\\n'\n                    'min_spt_core_version=\"0\"\\n\\n[session.self]\\ncommand=\\''+cmd+'\\'\\n\\n'\n                    '[session]\\ncommune_dir=\"'+drops.as_posix()+'\"\\nsignoff_dir=\"'+drops.as_posix()+'\"\\n\\n'\n                    '[session.psyche_init]\\ncommand=\\'psychebin ready {id}\\'\\ncwd=\"{psyche_dir}\"\\nkeys=[]\\n')\n        (src/'manifest.toml').write_text(manifest, encoding='utf-8')\n        for args in (['adapter','add',str(src)],\n                     ['endpoint','create',self.args.lane+'rig','--adapter','evidencerig'],\n                     ['endpoint','start',self.args.lane+'rig']):\n            r = self.command(args, mutate=True, timeout=35)\n            if r.returncode:\n                raise RuntimeError('fixture command refused: '+r.stderr)\n        self.attach()\n        end = min(self.deadline, time.monotonic()+15)\n        while time.monotonic() < end:\n            if any(row['kind']=='PROG' for row in self.records):\n                print('RIG_READY', flush=True)\n                return\n            time.sleep(.1)\n        raise RuntimeError('real RC progress not observed within attach bound')\n\n    def attach(self):\n        self.guard('rc attach')\n        self.rc_number += 1\n        err = (self.out/f'rc-{self.rc_number}.stderr.log').open('wb')\n        self.streams.append(err)\n        self.rc = subprocess.Popen([str(self.spt),'rc',self.args.lane+'rig'], env=self.env,\n                                   cwd=self.out, stdin=subprocess.PIPE, stdout=subprocess.PIPE,\n                                   stderr=err, creationflags=subprocess.CREATE_NO_WINDOW)\n        self.identify(self.rc.pid, 'rc-'+str(self.rc_number))\n        self.read_allowed.set()\n        child, number = self.rc, self.rc_number\n        def read_output():\n            acc = ''\n            raw = (self.out/f'rc-{number}.chunks.jsonl').open('a',encoding='utf-8',buffering=1)\n            parsed = (self.out/f'rc-{number}.progress.jsonl').open('a',encoding='utf-8',buffering=1)\n            try:\n                while True:\n                    self.read_allowed.wait()\n                    chunk = os.read(child.stdout.fileno(), 8192)\n                    if not chunk:\n                        break\n                    received = now_ms()","truncated":true,"truncatedBy":"lines","totalLines":608,"totalBytes":14348,"outputLines":300,"outputBytes":14348,"lastLinePartial":false,"firstLineExceedsLimit":false},"totalLines":608,"displayContent":{"text":"\"\"\"#307 evidence-only isolated-home driver. Run under retained native job launcher.\"\"\"\nimport argparse\nimport ctypes\nfrom ctypes import wintypes\nimport datetime\nimport hashlib\nimport json\nimport os\nfrom pathlib import Path\nimport re\nimport shutil\nimport subprocess\nimport sys\nimport threading\nimport time\nimport traceback\n\nimport psutil\n\nBASE = Path(__file__).resolve().parent\nPERCH_ENV = ('OWL_SESSION_ID', 'SPT_AGENT_ID', 'SPT_ENDPOINT_ID', 'SPT_SESSION_NAME',\n             'SPT_SESSION_ID', 'SPT_ADAPTER', 'SPT_HOST_PID', 'SPT_INJECT_VERIFY_ECHO')\nk32 = ctypes.WinDLL('kernel32', use_last_error=True)\nk32.CreateFileW.argtypes = [wintypes.LPCWSTR, wintypes.DWORD, wintypes.DWORD, ctypes.c_void_p,\n                           wintypes.DWORD, wintypes.DWORD, wintypes.HANDLE]\nk32.CreateFileW.restype = wintypes.HANDLE\nk32.GetNamedPipeServerProcessId.argtypes = [wintypes.HANDLE, ctypes.POINTER(wintypes.ULONG)]\nk32.GetNamedPipeServerProcessId.restype = wintypes.BOOL\nk32.CloseHandle.argtypes = [wintypes.HANDLE]\nk32.GetProcessId.argtypes = [wintypes.HANDLE]\nk32.GetProcessId.restype = wintypes.DWORD\nINVALID_HANDLE = ctypes.c_void_p(-1).value\n\n\ndef now_ms():\n    return time.time_ns() // 1000000\n\n\ndef sha(path):\n    with Path(path).open('rb') as f:\n        return hashlib.file_digest(f, 'sha256').hexdigest()\n\n\ndef save(path, data):\n    Path(path).write_text(json.dumps(data, indent=2) + '\\n', encoding='utf-8')\n\n\ndef pipe_pid(name):\n    handle = k32.CreateFileW('\\\\\\\\.\\\\pipe\\\\' + name, 0xC0000000, 0, None, 3, 0x40000000, None)\n    if handle == INVALID_HANDLE:\n        return {'error': ctypes.get_last_error()}\n    try:\n        pid = wintypes.ULONG()\n        if not k32.GetNamedPipeServerProcessId(handle, ctypes.byref(pid)):\n            return {'error': ctypes.get_last_error()}\n        return {'pid': pid.value}\n    finally:\n        k32.CloseHandle(handle)\n\n\nclass Rig:\n    def __init__(self, args):\n        self.args = args\n        self.out = Path(args.output).resolve()\n        self.out.mkdir(exist_ok=False)\n        self.home = self.out / ('home-' + args.lane)\n        self.started = time.monotonic()\n        self.deadline = self.started + 300\n        self.cleanup_deadline = None\n        self.events = (self.out / 'events.jsonl').open('a', encoding='utf-8', buffering=1)\n        self.lock = threading.Lock()\n        self.broker = None\n        self.rc = None\n        self.read_allowed = threading.Event()\n        self.read_allowed.set()\n        self.reader = None\n        self.trace_stop = threading.Event()\n        self.trace_reader = None\n        self.records = []\n        self.owned = {}\n        self.streams = []\n        self.phase = 'admission'\n        self.rc_number = 0\n        self.cmd_number = 0\n        self.backup = None\n        self.restored = False\n        self.ancestor_ids = {os.getpid(), *(p.pid for p in psutil.Process().parents())}\n        self.preexisting_spt = {p.pid for p in psutil.process_iter(['name'])\n                               if (p.info['name'] or '').lower() == 'spt.exe'}\n        self.resident = Path(os.environ['LOCALAPPDATA']) / 'spt-core'\n        assert not self.home.exists()\n        assert self.resident.resolve() not in self.home.parents\n        self.env = dict(os.environ)\n        removed = []\n        for key in list(self.env):\n            if key.startswith(('SPT_', 'OWL_', 'CLAUDE_')):\n                removed.append(key)\n                del self.env[key]\n        self.env.update(SPT_HOME=str(self.home), SPT_TEST_EPHEMERAL_ADVISORY_PORTS='1',\n                        SPT_INSTALL_NO_FIREWALL='1', SPT_PUMP_TRACE='1', PYTHONUNBUFFERED='1')\n        self.spt_source = Path(args.binary).resolve()\n        self.pin = args.sha256\n        assert sha(self.spt_source) == self.pin\n        self.bin_dir = self.out / 'bin'\n        self.bin_dir.mkdir()\n        self.spt = self.bin_dir / 'spt.exe'\n        shutil.copy2(self.spt_source, self.spt)\n        assert sha(self.spt) == self.pin\n        self.sockets = self.socket_names(self.env)\n        resident_env = {**self.env, 'SPT_HOME': str(self.resident)}\n        self.resident_sockets = self.socket_names(resident_env)\n        assert not set(self.sockets) & set(self.resident_sockets)\n        before = {name: pipe_pid(name) for name in self.sockets}\n        assert all(row.get('error') == 2 for row in before.values()), before\n        self.home.mkdir()\n        # Valid default config, required so the cadence backup has exact original bytes.\n        (self.home / 'daemon.json').write_bytes(b'{}\\n')\n        self.event('ADMITTED_HOME', home=str(self.home), explicit_env=self.env['SPT_HOME'],\n                   sockets=self.sockets, resident_sockets=self.resident_sockets,\n                   sockets_before=before, excluded_pids=sorted(self.preexisting_spt | self.ancestor_ids),\n                   source=str(self.spt_source), executable=str(self.spt), sha256=self.pin,\n                   removed_environment_names=removed, observation_bound_s=300, teardown_bound_s=120)\n\n    def socket_names(self, env):\n        r = subprocess.run([self.args.socket_helper], env=env, capture_output=True, text=True,\n                           timeout=10)\n        assert r.returncode == 0, r.stderr\n        lines = r.stdout.splitlines()\n        assert len(lines) == 3 and lines[0] == env['SPT_HOME'], lines\n        assert lines[1].startswith('spt-daemon-broker-') and lines[2].startswith('spt-daemon-seed-')\n        return lines[1:]\n\n    def event(self, kind, **data):\n        row = {'event': kind, 'at_ms': now_ms(), 'elapsed_s': time.monotonic() - self.started,\n               'phase': self.phase, 'box': os.environ.get('COMPUTERNAME'),\n               'route': 'hfenduleam-isolated-native-local', **data}\n        with self.lock:\n            self.events.write(json.dumps(row) + '\\n')\n        return row\n\n    def remaining(self):\n        return max(0, (self.cleanup_deadline or self.deadline) - time.monotonic())\n\n    def identify(self, pid, role):\n        proc = psutil.Process(pid)\n        row = {'pid': pid, 'birth': proc.create_time(), 'exe': proc.exe(), 'ppid': proc.ppid(),\n               'role': role, 'ancestors': [p.pid for p in proc.parents()]}\n        assert pid not in self.preexisting_spt | self.ancestor_ids, row\n        assert os.getpid() in row['ancestors'], row\n        self.owned[pid] = row\n        self.event('OWNED_PROCESS', **row)\n        return row\n\n    def guard(self, reason):\n        assert self.broker is not None and self.broker.poll() is None\n        expected = self.owned[self.broker.pid]\n        proc = psutil.Process(self.broker.pid)\n        assert proc.create_time() == expected['birth']\n        image = Path(proc.exe()).resolve()\n        # Same-byte apply may rename the still-running broker image to its owned aside.\n        assert image.parent == self.bin_dir and sha(image) == self.pin\n        assert k32.GetProcessId(int(self.broker._handle)) == self.broker.pid\n        assert self.broker.pid not in self.preexisting_spt | self.ancestor_ids\n        assert os.getpid() in [p.pid for p in proc.parents()]\n        assert self.env['SPT_HOME'] == str(self.home)\n        actual = self.socket_names(self.env)\n        assert actual == self.sockets and not set(actual) & set(self.resident_sockets)\n        endpoints = {name: pipe_pid(name) for name in actual}\n        assert all(row.get('pid') == self.broker.pid for row in endpoints.values()), endpoints\n        self.event('MUTATION_GUARD', reason=reason, home=self.env['SPT_HOME'],\n                   broker_pid=self.broker.pid, birth=expected['birth'], endpoints=endpoints,\n                   owned_handle_pid=k32.GetProcessId(int(self.broker._handle)))\n\n    def command(self, args, mutate=False, timeout=20, env_extra=None, executable=None):\n        if mutate:\n            self.guard(' '.join(args))\n        assert self.remaining() > 0, 'phase deadline exhausted before command'\n        env = {**self.env, **(env_extra or {})}\n        assert env['SPT_HOME'] == str(self.home)\n        argv = [str(executable or self.spt), *args]\n        # cmd parses its own command tail, not CRT argv quoting.\n        launch = (subprocess.list2cmdline(argv[:3]) + ' ' + argv[3]\n                  if Path(argv[0]).name.lower() == 'cmd.exe' else argv)\n        self.cmd_number += 1\n        num = self.cmd_number\n        self.event('COMMAND_START', command=num, argv=argv, home=env['SPT_HOME'])\n        began = time.monotonic()\n        result = subprocess.run(launch, env=env, cwd=self.out, capture_output=True, text=True,\n                                encoding='utf-8', errors='replace',\n                                timeout=min(timeout, max(.1, self.remaining())))\n        record = {'argv': argv, 'exit': result.returncode, 'stdout': result.stdout,\n                  'stderr': result.stderr, 'elapsed_ms': (time.monotonic()-began)*1000,\n                  'home': env['SPT_HOME']}\n        save(self.out / f'command-{num:03}.json', record)\n        self.event('COMMAND_END', command=num, exit=result.returncode,\n                   elapsed_ms=record['elapsed_ms'])\n        return result\n\n    def start(self):\n        self.phase = 'startup'\n        assert sha(self.spt) == self.pin\n        log = (self.out/'daemon.stderr.log').open('wb')\n        self.streams.append(log)\n        self.broker = subprocess.Popen([str(self.spt), 'daemon', 'run'], env=self.env,\n                                      cwd=self.out, stdin=subprocess.DEVNULL,\n                                      stdout=subprocess.DEVNULL, stderr=log,\n                                      creationflags=subprocess.CREATE_NO_WINDOW)\n        self.identify(self.broker.pid, 'broker')\n        def trace_output():\n            pending = ''\n            sink = self.home/'logs/daemon.stderr.log'\n            while not sink.exists() and not self.trace_stop.wait(.02):\n                pass\n            if self.trace_stop.is_set():\n                return\n            with sink.open('r',encoding='utf-8',errors='replace') as stream:\n                while not self.trace_stop.is_set():\n                    pending += stream.read(65536)\n                    lines = pending.split('\\n')\n                    pending = lines.pop()\n                    for line in lines:\n                        if any(token in line for token in ('BRAIN_','CONTROLLER_SLOT_CLOSED','SUBSCRIBE_DECISION','ENDPOINT_RUN')):\n                            self.event('DAEMON_TRACE',line=line)\n                    self.trace_stop.wait(.02)\n        self.trace_reader = threading.Thread(target=trace_output,daemon=True)\n        self.trace_reader.start()\n        end = min(self.deadline, time.monotonic() + 45)\n        while time.monotonic() < end:\n            if self.broker.poll() is not None:\n                raise RuntimeError('isolated daemon exited during startup')\n            ready = self.home/'brain.ready'\n            try:\n                state = json.loads(ready.read_text())\n                pid = state['pid']\n                brain = self.identify(pid, 'brain')\n                assert self.broker.pid in brain['ancestors']\n                self.guard('startup complete')\n                save(self.out/'brain-ready-start.json', state)\n                break\n            except (OSError, ValueError, KeyError, psutil.Error, AssertionError):\n                time.sleep(.2)\n        else:\n            raise RuntimeError('isolated daemon failed 45s startup admission')\n        print('ISOLATED_DAEMON_READY', flush=True)\n\n    def fixture(self):\n        self.guard('create disposable adapter files')\n        src = self.home/'srcs/evidencerig'\n        src.mkdir(parents=True)\n        drops = self.home/'drops'\n        drops.mkdir()\n        shutil.copy2(self.spt, src/'psychebin.exe')\n        mode = 'hitch' if self.args.lane == 'w1c' else 'refresh'\n        # The command template follows dummy_harness_e2e's existing contract.\n        quote = lambda x: '\"' + str(x).replace('\\\\', '/') + '\"'\n        cmd = (f'{quote(sys.executable)} -u {quote(BASE/\"generator.py\")} '\n               f'--spt {quote(self.spt)} --home {quote(self.home)} '\n               f'--id {{id}} --session-id {{session_id}} --mode {mode}')\n        manifest = ('[adapter]\\nname=\"evidencerig\"\\nkind=\"harness\"\\nversion=\"1\"\\n'\n                    'min_spt_core_version=\"0\"\\n\\n[session.self]\\ncommand=\\''+cmd+'\\'\\n\\n'\n                    '[session]\\ncommune_dir=\"'+drops.as_posix()+'\"\\nsignoff_dir=\"'+drops.as_posix()+'\"\\n\\n'\n                    '[session.psyche_init]\\ncommand=\\'psychebin ready {id}\\'\\ncwd=\"{psyche_dir}\"\\nkeys=[]\\n')\n        (src/'manifest.toml').write_text(manifest, encoding='utf-8')\n        for args in (['adapter','add',str(src)],\n                     ['endpoint','create',self.args.lane+'rig','--adapter','evidencerig'],\n                     ['endpoint','start',self.args.lane+'rig']):\n            r = self.command(args, mutate=True, timeout=35)\n            if r.returncode:\n                raise RuntimeError('fixture command refused: '+r.stderr)\n        self.attach()\n        end = min(self.deadline, time.monotonic()+15)\n        while time.monotonic() < end:\n            if any(row['kind']=='PROG' for row in self.records):\n                print('RIG_READY', flush=True)\n                return\n            time.sleep(.1)\n        raise RuntimeError('real RC progress not observed within attach bound')\n\n    def attach(self):\n        self.guard('rc attach')\n        self.rc_number += 1\n        err = (self.out/f'rc-{self.rc_number}.stderr.log').open('wb')\n        self.streams.append(err)\n        self.rc = subprocess.Popen([str(self.spt),'rc',self.args.lane+'rig'], env=self.env,\n                                   cwd=self.out, stdin=subprocess.PIPE, stdout=subprocess.PIPE,\n                                   stderr=err, creationflags=subprocess.CREATE_NO_WINDOW)\n        self.identify(self.rc.pid, 'rc-'+str(self.rc_number))\n        self.read_allowed.set()\n        child, number = self.rc, self.rc_number\n        def read_output():\n            acc = ''\n            raw = (self.out/f'rc-{number}.chunks.jsonl').open('a',encoding='utf-8',buffering=1)\n            parsed = (self.out/f'rc-{number}.progress.jsonl').open('a',encoding='utf-8',buffering=1)\n            try:\n                while True:\n                    self.read_allowed.wait()\n                    chunk = os.read(child.stdout.fileno(), 8192)\n                    if not chunk:\n                        break\n                    received = now_ms()\n…\n                        acc=acc[-8192:]\n…\n                parsed.close()\n…\n        self.reader.start()\n…\n        return confirmed and not errors","startLine":1,"lineNumbers":[1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95,96,97,98,99,100,101,102,103,104,105,106,107,108,109,110,111,112,113,114,115,116,117,118,119,120,121,122,123,124,125,126,127,128,129,130,131,132,133,134,135,136,137,138,139,140,141,142,143,144,145,146,147,148,149,150,151,152,153,154,155,156,157,158,159,160,161,162,163,164,165,166,167,168,169,170,171,172,173,174,175,176,177,178,179,180,181,182,183,184,185,186,187,188,189,190,191,192,193,194,195,196,197,198,199,200,201,202,203,204,205,206,207,208,209,210,211,212,213,214,215,216,217,218,219,220,221,222,223,224,225,226,227,228,229,230,231,232,233,234,235,236,237,238,239,240,241,242,243,244,245,246,247,248,249,250,251,252,253,254,255,256,257,258,259,260,261,262,263,264,265,266,267,268,269,270,271,272,273,274,275,276,277,278,279,280,281,282,283,284,285,286,287,288,289,290,291,292,293,294,295,296,297,298,299,300,null,326,null,331,null,333,null,575]},"fileSize":29362,"meta":{"source":{"type":"path","value":"C:\\Users\\decid\\Documents\\projects\\spt-core\\.spt\\preserved\\307\\hertz-w1bc\\rig.py"},"truncation":{"direction":"head","truncatedBy":"lines","totalLines":608,"totalBytes":14348,"outputLines":300,"outputBytes":14348,"shownRange":{"start":1,"end":300},"nextOffset":301}}},"isError":false,"timestamp":1789524036501}}
{"type":"message","id":"37cf6ca9","parentId":"d74bce61","timestamp":"2026-09-16T02:00:36.512Z","message":{"role":"toolResult","toolCallId":"call_40lTjtsW510AWGVWYnenqPm7|fc_09b01b5279447709016aa9f844652887d2874f6df36158249b","toolName":"read","content":[{"type":"text","text":"{\"event\": \"ADMITTED_HOME\", \"at_ms\": 1789523745637, \"elapsed_s\": 2.2969999999622814, \"phase\": \"admission\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"explicit_env\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"sockets\": [\"spt-daemon-broker-573ad82e70ef3afe.sock\", \"spt-daemon-seed-573ad82e70ef3afe.sock\"], \"resident_sockets\": [\"spt-daemon-broker-78bf18a9fd96fdc6.sock\", \"spt-daemon-seed-78bf18a9fd96fdc6.sock\"], \"sockets_before\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"error\": 2}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"error\": 2}}, \"excluded_pids\": [6180, 652…\n{\"event\": \"OWNED_PROCESS\", \"at_ms\": 1789523746957, \"elapsed_s\": 3.6089999999967404, \"phase\": \"startup\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"pid\": 39904, \"birth\": 1789523746.8315127, \"exe\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\", \"ppid\": 6180, \"role\": \"broker\", \"ancestors\": [6180, 45312, 46812, 55908, 26356, 30608, 35552]}\n{\"event\": \"OWNED_PROCESS\", \"at_ms\": 1789523749293, \"elapsed_s\": 5.952999999979511, \"phase\": \"startup\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"pid\": 22860, \"birth\": 1789523747.011789, \"exe\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\", \"ppid\": 39904, \"role\": \"brain\", \"ancestors\": [39904, 6180, 45312, 46812, 55908, 26356, 30608, 35552]}\n{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523749597, \"elapsed_s\": 6.25, \"phase\": \"startup\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"startup complete\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"owned_handle_pid\": 39904}\n{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523750035, \"elapsed_s\": 6.686999999976251, \"phase\": \"startup\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"create disposable adapter files\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"owned_handle_pid\": 39904}\n{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523750437, \"elapsed_s\": 7.0939999999827705, \"phase\": \"startup\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"adapter add C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\\\\srcs\\\\evidencerig\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"owned_handle_pid\": 39904}\n{\"event\": \"COMMAND_START\", \"at_ms\": 1789523750437, \"elapsed_s\": 7.0939999999827705, \"phase\": \"startup\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 1, \"argv\": [\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\", \"adapter\", \"add\", \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\\\\srcs\\\\evidencerig\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n{\"event\": \"COMMAND_END\", \"at_ms\": 1789523750542, \"elapsed_s\": 7.202999999979511, \"phase\": \"startup\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 1, \"exit\": 0, \"elapsed_ms\": 108.99999999674037}\n{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523750839, \"elapsed_s\": 7.5, \"phase\": \"startup\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"endpoint create w1crig --adapter evidencerig\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"owned_handle_pid\": 39904}\n{\"event\": \"COMMAND_START\", \"at_ms\": 1789523750840, \"elapsed_s\": 7.5, \"phase\": \"startup\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 2, \"argv\": [\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\", \"endpoint\", \"create\", \"w1crig\", \"--adapter\", \"evidencerig\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n{\"event\": \"COMMAND_END\", \"at_ms\": 1789523752187, \"elapsed_s\": 8.84399999998277, \"phase\": \"startup\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 2, \"exit\": 0, \"elapsed_ms\": 1343.9999999827705}\n{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523752479, \"elapsed_s\": 9.139999999955762, \"phase\": \"startup\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"endpoint start w1crig\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"owned_handle_pid\": 39904}\n{\"event\": \"COMMAND_START\", \"at_ms\": 1789523752479, \"elapsed_s\": 9.139999999955762, \"phase\": \"startup\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 3, \"argv\": [\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\", \"endpoint\", \"start\", \"w1crig\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n{\"event\": \"COMMAND_END\", \"at_ms\": 1789523754022, \"elapsed_s\": 10.686999999976251, \"phase\": \"startup\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 3, \"exit\": 0, \"elapsed_ms\": 1547.000000020489}\n{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523755435, \"elapsed_s\": 12.09399999998277, \"phase\": \"startup\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc attach\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"owned_handle_pid\": 39904}\n\n[Showing lines 1-15 of 568. Use :16 to continue. Some lines truncated to 768 chars]"}],"details":{"truncation":{"content":"{\"event\": \"ADMITTED_HOME\", \"at_ms\": 1789523745637, \"elapsed_s\": 2.2969999999622814, \"phase\": \"admission\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"explicit_env\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"sockets\": [\"spt-daemon-broker-573ad82e70ef3afe.sock\", \"spt-daemon-seed-573ad82e70ef3afe.sock\"], \"resident_sockets\": [\"spt-daemon-broker-78bf18a9fd96fdc6.sock\", \"spt-daemon-seed-78bf18a9fd96fdc6.sock\"], \"sockets_before\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"error\": 2}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"error\": 2}}, \"excluded_pids\": [6180, 652…\n{\"event\": \"OWNED_PROCESS\", \"at_ms\": 1789523746957, \"elapsed_s\": 3.6089999999967404, \"phase\": \"startup\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"pid\": 39904, \"birth\": 1789523746.8315127, \"exe\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\", \"ppid\": 6180, \"role\": \"broker\", \"ancestors\": [6180, 45312, 46812, 55908, 26356, 30608, 35552]}\r\n{\"event\": \"OWNED_PROCESS\", \"at_ms\": 1789523749293, \"elapsed_s\": 5.952999999979511, \"phase\": \"startup\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"pid\": 22860, \"birth\": 1789523747.011789, \"exe\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\", \"ppid\": 39904, \"role\": \"brain\", \"ancestors\": [39904, 6180, 45312, 46812, 55908, 26356, 30608, 35552]}\r\n{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523749597, \"elapsed_s\": 6.25, \"phase\": \"startup\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"startup complete\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"owned_handle_pid\": 39904}\r\n{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523750035, \"elapsed_s\": 6.686999999976251, \"phase\": \"startup\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"create disposable adapter files\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"owned_handle_pid\": 39904}\r\n{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523750437, \"elapsed_s\": 7.0939999999827705, \"phase\": \"startup\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"adapter add C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\\\\srcs\\\\evidencerig\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"owned_handle_pid\": 39904}\r\n{\"event\": \"COMMAND_START\", \"at_ms\": 1789523750437, \"elapsed_s\": 7.0939999999827705, \"phase\": \"startup\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 1, \"argv\": [\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\", \"adapter\", \"add\", \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\\\\srcs\\\\evidencerig\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\r\n{\"event\": \"COMMAND_END\", \"at_ms\": 1789523750542, \"elapsed_s\": 7.202999999979511, \"phase\": \"startup\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 1, \"exit\": 0, \"elapsed_ms\": 108.99999999674037}\r\n{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523750839, \"elapsed_s\": 7.5, \"phase\": \"startup\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"endpoint create w1crig --adapter evidencerig\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"owned_handle_pid\": 39904}\r\n{\"event\": \"COMMAND_START\", \"at_ms\": 1789523750840, \"elapsed_s\": 7.5, \"phase\": \"startup\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 2, \"argv\": [\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\", \"endpoint\", \"create\", \"w1crig\", \"--adapter\", \"evidencerig\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\r\n{\"event\": \"COMMAND_END\", \"at_ms\": 1789523752187, \"elapsed_s\": 8.84399999998277, \"phase\": \"startup\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 2, \"exit\": 0, \"elapsed_ms\": 1343.9999999827705}\r\n{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523752479, \"elapsed_s\": 9.139999999955762, \"phase\": \"startup\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"endpoint start w1crig\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"owned_handle_pid\": 39904}\r\n{\"event\": \"COMMAND_START\", \"at_ms\": 1789523752479, \"elapsed_s\": 9.139999999955762, \"phase\": \"startup\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 3, \"argv\": [\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\", \"endpoint\", \"start\", \"w1crig\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\r\n{\"event\": \"COMMAND_END\", \"at_ms\": 1789523754022, \"elapsed_s\": 10.686999999976251, \"phase\": \"startup\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 3, \"exit\": 0, \"elapsed_ms\": 1547.000000020489}\r\n{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523755435, \"elapsed_s\": 12.09399999998277, \"phase\": \"startup\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc attach\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"owned_handle_pid\": 39904}\r","truncated":true,"truncatedBy":"lines","totalLines":568,"totalBytes":7698,"outputLines":15,"outputBytes":7698,"lastLinePartial":false,"firstLineExceedsLimit":false},"totalLines":568,"displayContent":{"text":"{\"event\": \"ADMITTED_HOME\", \"at_ms\": 1789523745637, \"elapsed_s\": 2.2969999999622814, \"phase\": \"admission\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"explicit_env\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"sockets\": [\"spt-daemon-broker-573ad82e70ef3afe.sock\", \"spt-daemon-seed-573ad82e70ef3afe.sock\"], \"resident_sockets\": [\"spt-daemon-broker-78bf18a9fd96fdc6.sock\", \"spt-daemon-seed-78bf18a9fd96fdc6.sock\"], \"sockets_before\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"error\": 2}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"error\": 2}}, \"excluded_pids\": [6180, 652…\n{\"event\": \"OWNED_PROCESS\", \"at_ms\": 1789523746957, \"elapsed_s\": 3.6089999999967404, \"phase\": \"startup\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"pid\": 39904, \"birth\": 1789523746.8315127, \"exe\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\", \"ppid\": 6180, \"role\": \"broker\", \"ancestors\": [6180, 45312, 46812, 55908, 26356, 30608, 35552]}\r\n{\"event\": \"OWNED_PROCESS\", \"at_ms\": 1789523749293, \"elapsed_s\": 5.952999999979511, \"phase\": \"startup\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"pid\": 22860, \"birth\": 1789523747.011789, \"exe\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\", \"ppid\": 39904, \"role\": \"brain\", \"ancestors\": [39904, 6180, 45312, 46812, 55908, 26356, 30608, 35552]}\r\n{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523749597, \"elapsed_s\": 6.25, \"phase\": \"startup\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"startup complete\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"owned_handle_pid\": 39904}\r\n{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523750035, \"elapsed_s\": 6.686999999976251, \"phase\": \"startup\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"create disposable adapter files\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"owned_handle_pid\": 39904}\r\n{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523750437, \"elapsed_s\": 7.0939999999827705, \"phase\": \"startup\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"adapter add C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\\\\srcs\\\\evidencerig\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"owned_handle_pid\": 39904}\r\n{\"event\": \"COMMAND_START\", \"at_ms\": 1789523750437, \"elapsed_s\": 7.0939999999827705, \"phase\": \"startup\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 1, \"argv\": [\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\", \"adapter\", \"add\", \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\\\\srcs\\\\evidencerig\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\r\n{\"event\": \"COMMAND_END\", \"at_ms\": 1789523750542, \"elapsed_s\": 7.202999999979511, \"phase\": \"startup\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 1, \"exit\": 0, \"elapsed_ms\": 108.99999999674037}\r\n{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523750839, \"elapsed_s\": 7.5, \"phase\": \"startup\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"endpoint create w1crig --adapter evidencerig\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"owned_handle_pid\": 39904}\r\n{\"event\": \"COMMAND_START\", \"at_ms\": 1789523750840, \"elapsed_s\": 7.5, \"phase\": \"startup\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 2, \"argv\": [\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\", \"endpoint\", \"create\", \"w1crig\", \"--adapter\", \"evidencerig\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\r\n{\"event\": \"COMMAND_END\", \"at_ms\": 1789523752187, \"elapsed_s\": 8.84399999998277, \"phase\": \"startup\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 2, \"exit\": 0, \"elapsed_ms\": 1343.9999999827705}\r\n{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523752479, \"elapsed_s\": 9.139999999955762, \"phase\": \"startup\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"endpoint start w1crig\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"owned_handle_pid\": 39904}\r\n{\"event\": \"COMMAND_START\", \"at_ms\": 1789523752479, \"elapsed_s\": 9.139999999955762, \"phase\": \"startup\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 3, \"argv\": [\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\", \"endpoint\", \"start\", \"w1crig\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\r\n{\"event\": \"COMMAND_END\", \"at_ms\": 1789523754022, \"elapsed_s\": 10.686999999976251, \"phase\": \"startup\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 3, \"exit\": 0, \"elapsed_ms\": 1547.000000020489}\r\n{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523755435, \"elapsed_s\": 12.09399999998277, \"phase\": \"startup\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc attach\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"owned_handle_pid\": 39904}\r","startLine":1,"lineNumbers":[1,2,3,4,5,6,7,8,9,10,11,12,13,14,15]},"fileSize":218423,"meta":{"source":{"type":"path","value":"C:\\Users\\decid\\Documents\\projects\\spt-core\\.spt\\preserved\\307\\hertz-w1bc\\w1c-run1\\events.jsonl"},"truncation":{"direction":"head","truncatedBy":"lines","totalLines":568,"totalBytes":7698,"outputLines":15,"outputBytes":7698,"shownRange":{"start":1,"end":15},"nextOffset":16},"limits":{"columnTruncated":{"maxColumn":768}}}},"isError":false,"timestamp":1789524036512}}
{"type":"message","id":"fd727d29","parentId":"37cf6ca9","timestamp":"2026-09-16T02:00:36.524Z","message":{"role":"toolResult","toolCallId":"call_SRrwAo3nbRckkPI00IjWLEZH|fc_09b01b5279447709016aa9f844651c87d2a58ca8a8c8e0357e","toolName":"grep","content":[{"type":"text","text":"# crates/spt-daemon/tests/\n## attach.rs\n 546|#[test]\n*547|fn loopback_attach_to_a_prepopulated_ring_delivers_without_deadlock() {\n 548|    let _home = init_home();\n 549|    let dir = tempfile::tempdir().expect(\"tempdir\");\n 550|    let name = unique_name();\n...\n 668|#[test]\n*669|fn cross_node_cold_attach_to_alt_screen_gets_clean_repaint() {\n 670|    let _home = init_home();\n 671|    let dir = tempfile::tempdir().expect(\"tempdir\");\n 672|    let name = unique_name();\n...\n 808|#[test]\n*809|fn broker_spawns_the_pty_child_in_the_requested_cwd() {\n 810|    let _home = init_home();\n 811|    let dir = tempfile::tempdir().expect(\"tempdir\");\n 812|    let proj = dir.path().join(\"the-project-root\");\n...\n 866|#[test]\n*867|fn attach_survives_target_brain_restart_exactly_once() {\n 868|    let _home = init_home();\n 869|    let dir = tempfile::tempdir().expect(\"tempdir\");\n 870|    let (name_a, name_b) = (unique_name(), unique_name());\n...\n 1040|#[test]\n*1041|fn attach_registers_remote_drive_detection() {\n 1042|    let _home = init_home();\n 1043|    let dir = tempfile::tempdir().expect(\"tempdir\");\n 1044|    let (name_a, name_b) = (unique_name(), unique_name());\n...\n 1173|/// sid). The spawner is the broker's by=None local controller placeholder.\n*1174|fn labeled_session(home: &TestHome, label: &str) -> (Arc<Broker>, String, Brain, u64) {\n 1175|    let name = unique_name();\n 1176|    let broker = net_broker(&name, &home.path().join(label));\n 1177|    let mut spawner = connect_retry(&name);\n...\n 1188|/// replayed output / size frames), returning the resolved role.\n*1189|fn read_outcome(brain: &mut Brain) -> SubscribeOutcome {\n 1190|    let deadline = brain.call_deadline();\n 1191|    for _ in 0..2000 {\n 1192|        match brain.read_event_until(deadline).expect(\"event\") {\n...\n 1205|#[test]\n*1206|fn controller_viewer_matrix_and_loud_take() {\n 1207|    let _home = init_home();\n 1208|    let (_broker, name, _spawner, sid) = labeled_session(&_home, \"cv-matrix\");\n 1209|\n...\n 1269|#[test]\n*1270|fn same_origin_re_subscribe_does_not_displace() {\n 1271|    let _home = init_home();\n 1272|    let (_broker, name, _spawner, sid) = labeled_session(&_home, \"cv-gate7\");\n 1273|\n...\n 1329|#[test]\n*1330|fn resize_is_controller_exclusive() {\n 1331|    let _home = init_home();\n 1332|    let (_broker, name, _spawner, sid) = labeled_session(&_home, \"cv-resize\");\n 1333|\n...\n 1417|#[test]\n*1418|fn wedged_viewer_does_not_stall_controller() {\n 1419|    let _home = init_home();\n 1420|    let (_broker, name, _spawner, sid) = labeled_session(&_home, \"cv-isolation\");\n 1421|\n...\n 1506|\n*1507|fn fresh_viewer_sees_ring_burst(name: &str, sid: u64) -> bool {\n 1508|    let mut probe = Brain::cold_start_pump(\n 1509|        name,\n 1510|        1,\n...\n 1534|/// deadline (the viewer rides a pump conn so the per-slice timeout is honored).\n*1535|fn viewer_reads_marker_no_displace(brain: &mut Brain, needle: &[u8]) -> bool {\n 1536|    let mut got = Vec::new();\n 1537|    let deadline = std::time::Instant::now() + Duration::from_secs(15);\n 1538|    while std::time::Instant::now() < deadline {\n...\n 1560|#[test]\n*1561|fn controller_restart_with_viewer_no_displace_and_viewer_survives() {\n 1562|    let _home = init_home();\n 1563|    let (_broker, name, _spawner, sid) = labeled_session(&_home, \"cv-gate7-combined\");\n 1564|\n## redispatch.rs\n 365|#[test]\n*366|fn finished_unretired_attach_is_skipped_and_drained_not_replayed() {\n 367|    let _home = init_home();\n 368|    let dir = tempfile::tempdir().expect(\"tempdir\");\n 369|    let (name_a, name_b) = (unique_name(), unique_name());\n...\n 503|#[test]\n*504|fn finished_pending_sync_request_still_serves_across_generation_start() {\n 505|    let _home = init_home();\n 506|    let dir = tempfile::tempdir().expect(\"tempdir\");\n 507|    let (name_a, name_b) = (unique_name(), unique_name());\n...\n 578|#[test]\n*579|fn opener_evicted_active_stream_resumes_after_dispatcher_restart() {\n 580|    let _home = init_home();\n 581|    // Shrink the ring BEFORE the broker starts (read once at NetShared::new).\n 582|    // nextest = one process per test: no cross-test env bleed.\n...\n 688|#[test]\n*689|fn transient_worker_start_failure_recovers_via_claim_retry() {\n 690|    let _home = init_home();\n 691|    let dir = tempfile::tempdir().expect(\"tempdir\");\n 692|    let (name_a, name_b) = (unique_name(), unique_name());\n## redispatch_stall.rs\n 331|#[test]\n*332|fn wedged_subscriber_never_stalls_the_producer_and_recovery_replays_gapless() {\n 333|    let _home = init_home();\n 334|    // Shrink the bounded write so the poison window is 400ms, not 15s — the\n 335|    // knob grants wall-clock only, never relaxes an assertion (the\n...\n 414|#[test]\n*415|fn poisoned_subscriber_cancels_the_paired_forwarding_leg_then_recovery_serves() {\n 416|    let _home = init_home();\n 417|    std::env::set_var(\"SPT_BRAIN_WRITE_DEADLINE_MS\", \"400\");\n 418|    let dir = tempfile::tempdir().expect(\"tempdir\");\n...\n 545|#[test]\n*546|fn opener_transient_is_bounded_requeue_never_a_peek_subscriber() {\n 547|    let _home = init_home();\n 548|    let dir = tempfile::tempdir().expect(\"tempdir\");\n 549|    let (name_a, name_b) = (unique_name(), unique_name());\n...\n 606|#[test]\n*607|fn seat_blocked_failure_trips_the_breaker_and_the_stream_recovers() {\n 608|    let _home = init_home();\n 609|    let dir = tempfile::tempdir().expect(\"tempdir\");\n 610|    let (name_a, name_b) = (unique_name(), unique_name());\n...\n 687|#[test]\n*688|fn stale_unfinished_attach_replay_neither_takes_nor_clears_the_replacement_controller() {\n 689|    let _home = init_home();\n 690|    let dir = tempfile::tempdir().expect(\"tempdir\");\n 691|    let (name_a, name_b) = (unique_name(), unique_name());"}],"details":{"scopePath":"crates/spt-daemon/tests/attach.rs, crates/spt-daemon/tests/redispatch.rs, crates/spt-daemon/tests/redispatch_stall.rs","searchPath":"C:\\Users\\decid\\Documents\\projects\\spt-core\\crates\\spt-daemon\\tests","cwd":"C:\\Users\\decid\\Documents\\projects\\spt-core","matchCount":23,"fileCount":3,"files":["crates/spt-daemon/tests/attach.rs","crates/spt-daemon/tests/redispatch.rs","crates/spt-daemon/tests/redispatch_stall.rs"],"fileMatches":[{"path":"crates/spt-daemon/tests/attach.rs","count":14},{"path":"crates/spt-daemon/tests/redispatch.rs","count":4},{"path":"crates/spt-daemon/tests/redispatch_stall.rs","count":5}],"truncated":false,"displayContent":"# crates/spt-daemon/tests/\n## attach.rs\n  546│#[test]\n *547│fn loopback_attach_to_a_prepopulated_ring_delivers_without_deadlock() {\n  548│    let _home = init_home();\n  549│    let dir = tempfile::tempdir().expect(\"tempdir\");\n  550│    let name = unique_name();\n     │...\n  668│#[test]\n *669│fn cross_node_cold_attach_to_alt_screen_gets_clean_repaint() {\n  670│    let _home = init_home();\n  671│    let dir = tempfile::tempdir().expect(\"tempdir\");\n  672│    let name = unique_name();\n     │...\n  808│#[test]\n *809│fn broker_spawns_the_pty_child_in_the_requested_cwd() {\n  810│    let _home = init_home();\n  811│    let dir = tempfile::tempdir().expect(\"tempdir\");\n  812│    let proj = dir.path().join(\"the-project-root\");\n     │...\n  866│#[test]\n *867│fn attach_survives_target_brain_restart_exactly_once() {\n  868│    let _home = init_home();\n  869│    let dir = tempfile::tempdir().expect(\"tempdir\");\n  870│    let (name_a, name_b) = (unique_name(), unique_name());\n     │...\n 1040│#[test]\n*1041│fn attach_registers_remote_drive_detection() {\n 1042│    let _home = init_home();\n 1043│    let dir = tempfile::tempdir().expect(\"tempdir\");\n 1044│    let (name_a, name_b) = (unique_name(), unique_name());\n     │...\n 1173│/// sid). The spawner is the broker's by=None local controller placeholder.\n*1174│fn labeled_session(home: &TestHome, label: &str) -> (Arc<Broker>, String, Brain, u64) {\n 1175│    let name = unique_name();\n 1176│    let broker = net_broker(&name, &home.path().join(label));\n 1177│    let mut spawner = connect_retry(&name);\n     │...\n 1188│/// replayed output / size frames), returning the resolved role.\n*1189│fn read_outcome(brain: &mut Brain) -> SubscribeOutcome {\n 1190│    let deadline = brain.call_deadline();\n 1191│    for _ in 0..2000 {\n 1192│        match brain.read_event_until(deadline).expect(\"event\") {\n     │...\n 1205│#[test]\n*1206│fn controller_viewer_matrix_and_loud_take() {\n 1207│    let _home = init_home();\n 1208│    let (_broker, name, _spawner, sid) = labeled_session(&_home, \"cv-matrix\");\n 1209│\n     │...\n 1269│#[test]\n*1270│fn same_origin_re_subscribe_does_not_displace() {\n 1271│    let _home = init_home();\n 1272│    let (_broker, name, _spawner, sid) = labeled_session(&_home, \"cv-gate7\");\n 1273│\n     │...\n 1329│#[test]\n*1330│fn resize_is_controller_exclusive() {\n 1331│    let _home = init_home();\n 1332│    let (_broker, name, _spawner, sid) = labeled_session(&_home, \"cv-resize\");\n 1333│\n     │...\n 1417│#[test]\n*1418│fn wedged_viewer_does_not_stall_controller() {\n 1419│    let _home = init_home();\n 1420│    let (_broker, name, _spawner, sid) = labeled_session(&_home, \"cv-isolation\");\n 1421│\n     │...\n 1506│\n*1507│fn fresh_viewer_sees_ring_burst(name: &str, sid: u64) -> bool {\n 1508│    let mut probe = Brain::cold_start_pump(\n 1509│        name,\n 1510│        1,\n     │...\n 1534│/// deadline (the viewer rides a pump conn so the per-slice timeout is honored).\n*1535│fn viewer_reads_marker_no_displace(brain: &mut Brain, needle: &[u8]) -> bool {\n 1536│    let mut got = Vec::new();\n 1537│    let deadline = std::time::Instant::now() + Duration::from_secs(15);\n 1538│    while std::time::Instant::now() < deadline {\n     │...\n 1560│#[test]\n*1561│fn controller_restart_with_viewer_no_displace_and_viewer_survives() {\n 1562│    let _home = init_home();\n 1563│    let (_broker, name, _spawner, sid) = labeled_session(&_home, \"cv-gate7-combined\");\n 1564│\n## redispatch.rs\n 365│#[test]\n*366│fn finished_unretired_attach_is_skipped_and_drained_not_replayed() {\n 367│    let _home = init_home();\n 368│    let dir = tempfile::tempdir().expect(\"tempdir\");\n 369│    let (name_a, name_b) = (unique_name(), unique_name());\n    │...\n 503│#[test]\n*504│fn finished_pending_sync_request_still_serves_across_generation_start() {\n 505│    let _home = init_home();\n 506│    let dir = tempfile::tempdir().expect(\"tempdir\");\n 507│    let (name_a, name_b) = (unique_name(), unique_name());\n    │...\n 578│#[test]\n*579│fn opener_evicted_active_stream_resumes_after_dispatcher_restart() {\n 580│    let _home = init_home();\n 581│    // Shrink the ring BEFORE the broker starts (read once at NetShared::new).\n 582│    // nextest = one process per test: no cross-test env bleed.\n    │...\n 688│#[test]\n*689│fn transient_worker_start_failure_recovers_via_claim_retry() {\n 690│    let _home = init_home();\n 691│    let dir = tempfile::tempdir().expect(\"tempdir\");\n 692│    let (name_a, name_b) = (unique_name(), unique_name());\n## redispatch_stall.rs\n 331│#[test]\n*332│fn wedged_subscriber_never_stalls_the_producer_and_recovery_replays_gapless() {\n 333│    let _home = init_home();\n 334│    // Shrink the bounded write so the poison window is 400ms, not 15s — the\n 335│    // knob grants wall-clock only, never relaxes an assertion (the\n    │...\n 414│#[test]\n*415│fn poisoned_subscriber_cancels_the_paired_forwarding_leg_then_recovery_serves() {\n 416│    let _home = init_home();\n 417│    std::env::set_var(\"SPT_BRAIN_WRITE_DEADLINE_MS\", \"400\");\n 418│    let dir = tempfile::tempdir().expect(\"tempdir\");\n    │...\n 545│#[test]\n*546│fn opener_transient_is_bounded_requeue_never_a_peek_subscriber() {\n 547│    let _home = init_home();\n 548│    let dir = tempfile::tempdir().expect(\"tempdir\");\n 549│    let (name_a, name_b) = (unique_name(), unique_name());\n    │...\n 606│#[test]\n*607│fn seat_blocked_failure_trips_the_breaker_and_the_stream_recovers() {\n 608│    let _home = init_home();\n 609│    let dir = tempfile::tempdir().expect(\"tempdir\");\n 610│    let (name_a, name_b) = (unique_name(), unique_name());\n    │...\n 687│#[test]\n*688│fn stale_unfinished_attach_replay_neither_takes_nor_clears_the_replacement_controller() {\n 689│    let _home = init_home();\n 690│    let dir = tempfile::tempdir().expect(\"tempdir\");\n 691│    let (name_a, name_b) = (unique_name(), unique_name());"},"isError":false,"timestamp":1789524036524}}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_acyRMEoRMelFSuwDtCZx2rlw|fc_09b01b5279447709016aa9f849892087d2aae583a326f6c570","toolName":"hub","startedAt":"2026-09-16T02:00:44.889Z","intent":"Sharing consumer discriminators"},"id":"5dabeb84","parentId":"fd727d29","timestamp":"2026-09-16T02:00:44.889Z"}
{"type":"message","id":"930ab83a","parentId":"5dabeb84","timestamp":"2026-09-16T02:00:44.890Z","message":{"role":"assistant","content":[{"type":"thinking","thinking":"**Checking synchronous resize replay**"},{"type":"toolCall","id":"call_acyRMEoRMelFSuwDtCZx2rlw|fc_09b01b5279447709016aa9f849892087d2aae583a326f6c570","name":"hub","arguments":{"i":"Sharing consumer discriminators","op":"send","to":"ControllerDrainRca","message":"Consumer has no ack-wait in normal attach: net_stream_subscribe + attach_as are send-only; confirmed input send_effect_no_ack, BUT pending_input flushed on Subscribed via send_effect(ack=true) attach.rs754-755. Replay from ring floor=0 replays all old Input, pre-role buffered; batch sends without reads can fill inbound pipe while per-conn broker blocks replying Applied on shared send. Snapshot may forward before Subscribed (attached gate, not role). Candidate only; actual replay counts/interleave not captured. Also stream-sub-writer-poison says LIVE write failed, so that writer already finished replay, excluding stuck replay-write itself. Failure os233 classified Transient, 3 attempts terminal, not SeatBlocked breaker (dispatch373-383,503-545)."},"intent":"Sharing consumer discriminators"}],"api":"openai-codex-responses","provider":"openai-codex","model":"gpt-6-astra","usage":{"input":9191,"output":216,"cacheRead":93056,"cacheWrite":0,"totalTokens":102463,"reasoningTokens":20,"cost":{"input":0.09191,"output":0.0108,"cacheRead":0.093056,"cacheWrite":0,"total":0.195766}},"stopReason":"toolUse","timestamp":1789524036531,"responseId":"resp_09b01b5279447709016aa9f844e39087d2b79b057ea797caed","providerPayload":{"type":"openaiResponsesHistory","provider":"openai-codex","dt":true,"items":[{"id":"rs_09b01b5279447709016aa9f8465b7487d2ab637c3394444db8","type":"reasoning","content":[],"encrypted_content":"gAAAAABqqfhJWUQYRaoztCQYdXuCoJDdTQ1iEysN-0VqJN2Ifnn58RwgSTa73ymD-_umfuw5iBbV1Q8I2ZkUYdCqBFyT6WMHzUcjd-wY76Ya1SLCOHApKlt15vYlyQosER2tIPLZdp0xFMP8WeEVG4nHgMnsgSPbpPMi-c1Z_ysSed0nqoP397Xen1B16HfCIe2X1ASkObW0J42MwQ7XGzeL2ChPxuZC2nUnAPSoSOQ-f9rDtrNtC9I-ygC2HxLFqd5y1k7it8htOnf_bTl81iDxZPOufJdsPeHV8Cp0seAMjRgS9Vwv-t00BFZf-4AZj7IESpxm-pShmPA5ou3y-t0bmRI5Zc-k24w5WIKnAnjRMMx7Fu0nODAb1tDGPXRnJr2iFP-Dc8gfYZaI5jjvvmFKQ43iR7njXX9IZogf8-fMQ5tcCL9HiKmoFdJcyt8xO3GiuyCPJiTF7XBpRcBdoYNVxzdJSYYjwQWLQZJJrDrBtrcdsdmVsLGtnrVJHnEDEhdl5cW5WhfBsZGzXhtKsaIGVroutxpGCbUWVtSrYiB0XZQPW1EYQF91-d4lz2tlZ3vBmHzVCqiv2takVBCiJdLO4RaqxFO2dPkmtObQewR9iDapvvDNjnG0rFrQcUlTzhshx78yIvWECjO3flLK9FvJqBH_OnXE0p5lHW5ynzoR0GgkaAthPMZegpIwLH_nLCN9rqgwJ-ZVGstboyR0bFYHnP5RhjlLigMNb-IxhZ3CgplILeanMWAdiKJTHdeRZzOpFFlsPP8Qj9Q1HgAmOivus_r9nSk329boCOJkZYxEwL-686ykZP88diB4DLY-sD66V-xiTsPNRiNeBVUDDDmPxzSnipe83Fjxx0pdbAAEYSeezIUgUxqD4eJ2grDYVmtm5jGU7ZkWcAUZkN31tAjKTdlLS0_bXClVw9c0Oj8wDlXI10NsKqPQzVDeVf0gd6uhhtq3b-A8IxXO4NUxVjYYKW1_3M7d6lQ22pAxuBRKme1Ymb3fPqM09oc8VdcY2xHjkdV9o4DcOCRgZkh6499rDr0jUmuYuZ-NEGTxCAE7N6x88FRsmkSD02s44d8nSpsm5_eLFiDN9uz80vhZ2iep1uC8WPYAilMe4rIuq1w-I7GXmTUpUkdntserYUkpXRipMzAZ9ueew3Dvtuf44vjvYwTqJT1bxHbLxwWSla19r2BMvIMpeWMyOmppIW_yGp5ki43xYfYzb2B96qJc5YhoafJBLVkjateaJeJxm30eK-tlo8Z4nYHNo64c5W2SP-bD2uG9QXL9fvwymNY6FgCpzrhKT4_MJcjtJxiZGvCOE9BFbYe37PJaqbAaUkiDYX-YsaFpgRi7Yczd5tXr3zi1sobWqMPVpFPoT9mrF_25rFkbRSWGVhZDOdgs5D_rLvNUJyE6R22M","internal_chat_message_metadata_passthrough":{"turn_id":"f878fb4b-0d9a-4a17-adc6-f6c9f4deeea0"},"summary":[{"type":"summary_text","text":"**Checking synchronous resize replay**"}],"metadata":{"turn_id":"f878fb4b-0d9a-4a17-adc6-f6c9f4deeea0"}},{"id":"fc_09b01b5279447709016aa9f849892087d2aae583a326f6c570","type":"function_call","status":"completed","arguments":"{\"i\":\"Sharing consumer discriminators\",\"op\":\"send\",\"to\":\"ControllerDrainRca\",\"message\":\"Consumer has no ack-wait in normal attach: net_stream_subscribe + attach_as are send-only; confirmed input send_effect_no_ack, BUT pending_input flushed on Subscribed via send_effect(ack=true) attach.rs754-755. Replay from ring floor=0 replays all old Input, pre-role buffered; batch sends without reads can fill inbound pipe while per-conn broker blocks replying Applied on shared send. Snapshot may forward before Subscribed (attached gate, not role). Candidate only; actual replay counts/interleave not captured. Also stream-sub-writer-poison says LIVE write failed, so that writer already finished replay, excluding stuck replay-write itself. Failure os233 classified Transient, 3 attempts terminal, not SeatBlocked breaker (dispatch373-383,503-545).\"}","call_id":"call_acyRMEoRMelFSuwDtCZx2rlw","internal_chat_message_metadata_passthrough":{"create_time":1789524037.107506,"turn_id":"f878fb4b-0d9a-4a17-adc6-f6c9f4deeea0"},"name":"hub","metadata":{"turn_id":"f878fb4b-0d9a-4a17-adc6-f6c9f4deeea0"}}]},"duration":8355.41370000015,"ttft":1853.1792999999598,"completedAt":1789524044888,"contextSnapshot":{"promptTokens":102247,"nonMessageTokens":10480,"compactionEpoch":0}}}
{"type":"message","id":"526923db","parentId":"930ab83a","timestamp":"2026-09-16T02:00:44.891Z","message":{"role":"toolResult","toolCallId":"call_acyRMEoRMelFSuwDtCZx2rlw|fc_09b01b5279447709016aa9f849892087d2aae583a326f6c570","toolName":"hub","content":[{"type":"text","text":"Delivered to 1 peer(s):\n- ControllerDrainRca: injected"}],"details":{"op":"send","from":"AttachReplayRca","to":"ControllerDrainRca","receipts":[{"to":"ControllerDrainRca","outcome":"injected"}]},"isError":false,"timestamp":1789524044890}}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_mpg4WB9jh7DAN279J5eGBn7L|fc_09b01b5279447709016aa9f8570d1887d28bb07b9d6809effe","toolName":"read","startedAt":"2026-09-16T02:00:55.122Z","args":{"path":"crates/spt-daemon/tests/attach.rs:867-1032;"},"intent":"Reading replay test traffic bounds"},"id":"c47e0ac6","parentId":"526923db","timestamp":"2026-09-16T02:00:55.122Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_gfFePTfwuk8glhzxvsd5uoIL|fc_09b01b5279447709016aa9f8570d2c87d2babf790e016b9835","toolName":"read","startedAt":"2026-09-16T02:00:55.123Z","args":{"path":"crates/spt-daemon/tests/redispatch.rs:579-678"},"intent":"Reading production redispatch scenario"},"id":"4429e491","parentId":"c47e0ac6","timestamp":"2026-09-16T02:00:55.123Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_DLwVZ031NfLOp8DpD5MKgF8y|fc_09b01b5279447709016aa9f8570d3887d28100592b128fd51c","toolName":"grep","startedAt":"2026-09-16T02:00:55.123Z","args":{"path":"crates/spt-net/src/net/attach.rs"},"intent":"Locating decoder and input batching"},"id":"7df3a928","parentId":"4429e491","timestamp":"2026-09-16T02:00:55.123Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_8GQNPPKP9sEaA6rFa7MKVy87|fc_09b01b5279447709016aa9f8570d3c87d2b1e71699f3895bf2","toolName":"grep","startedAt":"2026-09-16T02:00:55.123Z","args":{"path":".spt/preserved/307/hertz-w1bc/w1c-run1/events.jsonl"},"intent":"Locating saved input and canary evidence"},"id":"03d78533","parentId":"7df3a928","timestamp":"2026-09-16T02:00:55.123Z"}
{"type":"message","id":"f92790c8","parentId":"03d78533","timestamp":"2026-09-16T02:00:55.123Z","message":{"role":"assistant","content":[{"type":"toolCall","id":"call_mpg4WB9jh7DAN279J5eGBn7L|fc_09b01b5279447709016aa9f8570d1887d28bb07b9d6809effe","name":"read","arguments":{"i":"Reading replay test traffic bounds","path":"crates/spt-daemon/tests/attach.rs:867-1032;"},"intent":"Reading replay test traffic bounds"},{"type":"toolCall","id":"call_gfFePTfwuk8glhzxvsd5uoIL|fc_09b01b5279447709016aa9f8570d2c87d2babf790e016b9835","name":"read","arguments":{"i":"Reading production redispatch scenario","path":"crates/spt-daemon/tests/redispatch.rs:579-678"},"intent":"Reading production redispatch scenario"},{"type":"toolCall","id":"call_DLwVZ031NfLOp8DpD5MKgF8y|fc_09b01b5279447709016aa9f8570d3887d28100592b128fd51c","name":"grep","arguments":{"i":"Locating decoder and input batching","pattern":"fn push|struct AttachDecoder","path":"crates/spt-net/src/net/attach.rs","case":true,"gitignore":true,"skip":null},"intent":"Locating decoder and input batching"},{"type":"toolCall","id":"call_8GQNPPKP9sEaA6rFa7MKVy87|fc_09b01b5279447709016aa9f8570d3c87d2b1e71699f3895bf2","name":"grep","arguments":{"i":"Locating saved input and canary evidence","pattern":"INPUT_SENT|022|CANARY|canary|CADENCE|READER","path":".spt/preserved/307/hertz-w1bc/w1c-run1/events.jsonl","case":true,"gitignore":false,"skip":null},"intent":"Locating saved input and canary evidence"}],"api":"openai-codex-responses","provider":"openai-codex","model":"gpt-6-astra","usage":{"input":344,"output":221,"cacheRead":102144,"cacheWrite":0,"totalTokens":102709,"cost":{"input":0.0034400000000000003,"output":0.01105,"cacheRead":0.102144,"cacheWrite":0,"total":0.116634}},"stopReason":"toolUse","timestamp":1789524044900,"responseId":"resp_09b01b5279447709016aa9f84d611887d2a2e61eeeb2654599","providerPayload":{"type":"openaiResponsesHistory","provider":"openai-codex","dt":true,"items":[{"id":"fc_09b01b5279447709016aa9f8570d1887d28bb07b9d6809effe","type":"function_call","status":"completed","arguments":"{\"i\":\"Reading replay test traffic bounds\",\"path\":\"crates/spt-daemon/tests/attach.rs:867-1032;\"}","call_id":"call_mpg4WB9jh7DAN279J5eGBn7L","internal_chat_message_metadata_passthrough":{"turn_id":"f878fb4b-0d9a-4a17-adc6-f6c9f4deeea0"},"name":"read","metadata":{"turn_id":"f878fb4b-0d9a-4a17-adc6-f6c9f4deeea0"}},{"id":"fc_09b01b5279447709016aa9f8570d2c87d2babf790e016b9835","type":"function_call","status":"completed","arguments":"{\"i\":\"Reading production redispatch scenario\",\"path\":\"crates/spt-daemon/tests/redispatch.rs:579-678\"}","call_id":"call_gfFePTfwuk8glhzxvsd5uoIL","internal_chat_message_metadata_passthrough":{"turn_id":"f878fb4b-0d9a-4a17-adc6-f6c9f4deeea0"},"name":"read","metadata":{"turn_id":"f878fb4b-0d9a-4a17-adc6-f6c9f4deeea0"}},{"id":"fc_09b01b5279447709016aa9f8570d3887d28100592b128fd51c","type":"function_call","status":"completed","arguments":"{\"i\":\"Locating decoder and input batching\",\"pattern\":\"fn push|struct AttachDecoder\",\"path\":\"crates/spt-net/src/net/attach.rs\",\"case\":true,\"gitignore\":true,\"skip\":null}","call_id":"call_DLwVZ031NfLOp8DpD5MKgF8y","internal_chat_message_metadata_passthrough":{"turn_id":"f878fb4b-0d9a-4a17-adc6-f6c9f4deeea0"},"name":"grep","metadata":{"turn_id":"f878fb4b-0d9a-4a17-adc6-f6c9f4deeea0"}},{"id":"fc_09b01b5279447709016aa9f8570d3c87d2b1e71699f3895bf2","type":"function_call","status":"completed","arguments":"{\"i\":\"Locating saved input and canary evidence\",\"pattern\":\"INPUT_SENT|022|CANARY|canary|CADENCE|READER\",\"path\":\".spt/preserved/307/hertz-w1bc/w1c-run1/events.jsonl\",\"case\":true,\"gitignore\":false,\"skip\":null}","call_id":"call_8GQNPPKP9sEaA6rFa7MKVy87","internal_chat_message_metadata_passthrough":{"turn_id":"f878fb4b-0d9a-4a17-adc6-f6c9f4deeea0"},"name":"grep","metadata":{"turn_id":"f878fb4b-0d9a-4a17-adc6-f6c9f4deeea0"}}]},"duration":10220.180700000143,"ttft":10178.327300000004,"completedAt":1789524055121,"contextSnapshot":{"promptTokens":102488,"nonMessageTokens":10480,"compactionEpoch":0}}}
{"type":"message","id":"3e01aa28","parentId":"f92790c8","timestamp":"2026-09-16T02:00:55.130Z","message":{"role":"toolResult","toolCallId":"call_DLwVZ031NfLOp8DpD5MKgF8y|fc_09b01b5279447709016aa9f8570d3887d28100592b128fd51c","toolName":"grep","content":[{"type":"text","text":"No matches found"}],"details":{"scopePath":"crates/spt-net/src/net/attach.rs","searchPath":"C:\\Users\\decid\\Documents\\projects\\spt-core\\crates\\spt-net\\src\\net\\attach.rs","cwd":"C:\\Users\\decid\\Documents\\projects\\spt-core","matchCount":0,"fileCount":0,"files":[],"truncated":false},"isError":false,"useless":true,"timestamp":1789524055129}}
{"type":"message","id":"4477effc","parentId":"3e01aa28","timestamp":"2026-09-16T02:00:55.141Z","message":{"role":"toolResult","toolCallId":"call_8GQNPPKP9sEaA6rFa7MKVy87|fc_09b01b5279447709016aa9f8570d3c87d2b1e71699f3895bf2","toolName":"grep","content":[{"type":"text","text":" 13|{\"event\": \"COMMAND_START\", \"at_ms\": 1789523752479, \"elapsed_s\": 9.139999999955762, \"phase\": \"startup\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 3, \"argv\": [\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\", \"endpoint\", \"start\", \"w1crig\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n*14|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523754022, \"elapsed_s\": 10.686999999976251, \"phase\": \"startup\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 3, \"exit\": 0, \"elapsed_ms\": 1547.000000020489}\n 15|{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523755435, \"elapsed_s\": 12.09399999998277, \"phase\": \"startup\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc attach\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"owned_handle_pid\": 39...\n 16|{\"event\": \"OWNED_PROCESS\", \"at_ms\": 1789523756024, \"elapsed_s\": 12.686999999976251, \"phase\": \"startup\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"pid\": 58116, \"birth\": 1789523755.8826158, \"exe\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\", \"ppid\": 6180, \"role\": \"rc-1\", \"ancestors\": [6180, 45312, 46812, 55908, 26356, 30608, 35552]}\n 17|{\"event\": \"COMMAND_START\", \"at_ms\": 1789523756226, \"elapsed_s\": 12.889999999955762, \"phase\": \"startup\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 4, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n*18|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523756502, \"elapsed_s\": 13.155999999959022, \"phase\": \"startup\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 4, \"exit\": 0, \"elapsed_ms\": 266.00000000325963}\n*19|{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523756502, \"elapsed_s\": 13.155999999959022, \"phase\": \"startup\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523756487, \"net_enabled\": true, \"net_canary_age_ms\": 11, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 2}\n*20|{\"event\": \"PHASE_START\", \"at_ms\": 1789523756502, \"elapsed_s\": 13.155999999959022, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"requested_s\": 45}\n*21|{\"event\": \"COMMAND_START\", \"at_ms\": 1789523756502, \"elapsed_s\": 13.155999999959022, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 5, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n 22|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523756576, \"elapsed_s\": 13.23399999999674, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 5, \"exit\": 0, \"elapsed_ms\": 78.00000003771856}\n*23|{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523756576, \"elapsed_s\": 13.23399999999674, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523756566, \"net_enabled\": true, \"net_canary_age_ms\": 15, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 24|{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523756904, \"elapsed_s\": 13.561999999976251, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-baseline-000\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"own...\n*25|{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523756904, \"elapsed_s\": 13.561999999976251, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-baseline-000\", \"rc\": 1}\n 26|{\"event\": \"COMMAND_START\", \"at_ms\": 1789523757905, \"elapsed_s\": 14.561999999976251, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 6, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n 27|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523758214, \"elapsed_s\": 14.875, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 6, \"exit\": 0, \"elapsed_ms\": 313.0000000237487}\n*28|{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523758214, \"elapsed_s\": 14.875, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523758203, \"net_enabled\": true, \"net_canary_age_ms\": 2, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 1}\n 29|{\"event\": \"COMMAND_START\", \"at_ms\": 1789523759215, \"elapsed_s\": 15.875, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 7, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n 30|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523759688, \"elapsed_s\": 16.34399999998277, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 7, \"exit\": 0, \"elapsed_ms\": 468.99999998277053}\n*31|{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523759688, \"elapsed_s\": 16.34399999998277, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523759681, \"net_enabled\": true, \"net_canary_age_ms\": 5, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 32|{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523760591, \"elapsed_s\": 17.25, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-baseline-002\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"owned_handle_pid...\n*33|{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523760591, \"elapsed_s\": 17.25, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-baseline-002\", \"rc\": 1}\n 34|{\"event\": \"COMMAND_START\", \"at_ms\": 1789523761592, \"elapsed_s\": 18.25, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 8, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n 35|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523761823, \"elapsed_s\": 18.48399999999674, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 8, \"exit\": 0, \"elapsed_ms\": 233.99999999674037}\n*36|{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523761823, \"elapsed_s\": 18.48399999999674, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523761815, \"net_enabled\": true, \"net_canary_age_ms\": 14, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 37|{\"event\": \"COMMAND_START\", \"at_ms\": 1789523762824, \"elapsed_s\": 19.48399999999674, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 9, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n 38|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523762981, \"elapsed_s\": 19.639999999955762, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 9, \"exit\": 0, \"elapsed_ms\": 155.9999999590218}\n*39|{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523762981, \"elapsed_s\": 19.639999999955762, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523762972, \"net_enabled\": true, \"net_canary_age_ms\": 21, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 40|{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523763112, \"elapsed_s\": 19.764999999955762, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-baseline-004\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"own...\n*41|{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523763113, \"elapsed_s\": 19.764999999955762, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-baseline-004\", \"rc\": 1}\n 42|{\"event\": \"COMMAND_START\", \"at_ms\": 1789523764113, \"elapsed_s\": 20.764999999955762, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 10, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n*43|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523764250, \"elapsed_s\": 20.905999999959022, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 10, \"exit\": 0, \"elapsed_ms\": 141.00000000325963}\n*44|{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523764250, \"elapsed_s\": 20.905999999959022, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523764241, \"net_enabled\": true, \"net_canary_age_ms\": 13, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n*45|{\"event\": \"COMMAND_START\", \"at_ms\": 1789523765250, \"elapsed_s\": 21.905999999959022, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 11, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n 46|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523766114, \"elapsed_s\": 22.764999999955762, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 11, \"exit\": 0, \"elapsed_ms\": 344.0000000409782}\n*47|{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523766115, \"elapsed_s\": 22.780999999959022, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523765586, \"net_enabled\": true, \"net_canary_age_ms\": 10, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 48|{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523766466, \"elapsed_s\": 23.125, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-baseline-006\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"owned_handle_pi...\n*49|{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523766466, \"elapsed_s\": 23.125, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-baseline-006\", \"rc\": 1}\n 50|{\"event\": \"COMMAND_START\", \"at_ms\": 1789523767467, \"elapsed_s\": 24.125, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 12, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n 51|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523768192, \"elapsed_s\": 24.84399999998277, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 12, \"exit\": 0, \"elapsed_ms\": 718.9999999827705}\n*52|{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523768192, \"elapsed_s\": 24.84399999998277, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523768186, \"net_enabled\": true, \"net_canary_age_ms\": 9, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 53|{\"event\": \"COMMAND_START\", \"at_ms\": 1789523769193, \"elapsed_s\": 25.85899999999674, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 13, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n 54|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523770386, \"elapsed_s\": 27.04699999996228, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 13, \"exit\": 0, \"elapsed_ms\": 1187.999999965541}\n*55|{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523770386, \"elapsed_s\": 27.04699999996228, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523770381, \"net_enabled\": true, \"net_canary_age_ms\": 5, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 56|{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523771266, \"elapsed_s\": 27.92199999996228, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-baseline-008\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"owne...\n*57|{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523771266, \"elapsed_s\": 27.92199999996228, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-baseline-008\", \"rc\": 1}\n 58|{\"event\": \"COMMAND_START\", \"at_ms\": 1789523772266, \"elapsed_s\": 28.92199999996228, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 14, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n 59|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523772644, \"elapsed_s\": 29.29699999996228, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 14, \"exit\": 0, \"elapsed_ms\": 375.0}\n*60|{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523772644, \"elapsed_s\": 29.29699999996228, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523772622, \"net_enabled\": true, \"net_canary_age_ms\": 22, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 1}\n 61|{\"event\": \"COMMAND_START\", \"at_ms\": 1789523773645, \"elapsed_s\": 30.29699999996228, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 15, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n 62|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523773688, \"elapsed_s\": 30.34399999998277, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 15, \"exit\": 0, \"elapsed_ms\": 47.0000000204891}\n*63|{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523773688, \"elapsed_s\": 30.34399999998277, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523773682, \"net_enabled\": true, \"net_canary_age_ms\": 5, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n*64|{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523774121, \"elapsed_s\": 30.780999999959022, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-baseline-010\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"own...\n*65|{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523774121, \"elapsed_s\": 30.780999999959022, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-baseline-010\", \"rc\": 1}\n*66|{\"event\": \"COMMAND_START\", \"at_ms\": 1789523775122, \"elapsed_s\": 31.780999999959022, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 16, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n 67|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523775609, \"elapsed_s\": 32.26499999995576, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 16, \"exit\": 0, \"elapsed_ms\": 483.99999999674037}\n*68|{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523775609, \"elapsed_s\": 32.26499999995576, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523775601, \"net_enabled\": true, \"net_canary_age_ms\": 0, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 69|{\"event\": \"COMMAND_START\", \"at_ms\": 1789523776610, \"elapsed_s\": 33.26499999995576, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 17, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n 70|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523776763, \"elapsed_s\": 33.42199999996228, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 17, \"exit\": 0, \"elapsed_ms\": 157.00000000651926}\n*71|{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523776763, \"elapsed_s\": 33.42199999996228, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523776758, \"net_enabled\": true, \"net_canary_age_ms\": 8, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 72|{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523777051, \"elapsed_s\": 33.70299999997951, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-baseline-012\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"owne...\n*73|{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523777051, \"elapsed_s\": 33.70299999997951, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-baseline-012\", \"rc\": 1}\n 74|{\"event\": \"COMMAND_START\", \"at_ms\": 1789523778051, \"elapsed_s\": 34.70299999997951, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 18, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n 75|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523778961, \"elapsed_s\": 35.625, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 18, \"exit\": 0, \"elapsed_ms\": 922.0000000204891}\n*76|{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523778961, \"elapsed_s\": 35.625, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523778956, \"net_enabled\": true, \"net_canary_age_ms\": 6, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 77|{\"event\": \"COMMAND_START\", \"at_ms\": 1789523779963, \"elapsed_s\": 36.625, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 19, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n 78|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523783935, \"elapsed_s\": 40.59399999998277, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 19, \"exit\": 0, \"elapsed_ms\": 3968.9999999827705}\n*79|{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523783936, \"elapsed_s\": 40.59399999998277, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523783925, \"net_enabled\": true, \"net_canary_age_ms\": 24, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 1}\n 80|{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523784371, \"elapsed_s\": 41.03099999995902, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-baseline-014\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"owne...\n*81|{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523784371, \"elapsed_s\": 41.03099999995902, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-baseline-014\", \"rc\": 1}\n 82|{\"event\": \"COMMAND_START\", \"at_ms\": 1789523785380, \"elapsed_s\": 42.03099999995902, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 20, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n 83|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523785798, \"elapsed_s\": 42.45299999997951, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 20, \"exit\": 0, \"elapsed_ms\": 422.0000000204891}\n*84|{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523785798, \"elapsed_s\": 42.45299999997951, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523785780, \"net_enabled\": true, \"net_canary_age_ms\": 4, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 1}\n 85|{\"event\": \"COMMAND_START\", \"at_ms\": 1789523786798, \"elapsed_s\": 43.45299999997951, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 21, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n 86|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523787134, \"elapsed_s\": 43.79699999996228, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 21, \"exit\": 0, \"elapsed_ms\": 343.99999998277053}\n*87|{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523787134, \"elapsed_s\": 43.79699999996228, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523787127, \"net_enabled\": true, \"net_canary_age_ms\": 2, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 88|{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523787527, \"elapsed_s\": 44.18699999997625, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-baseline-016\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"owne...\n*89|{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523787527, \"elapsed_s\": 44.18699999997625, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-baseline-016\", \"rc\": 1}\n 90|{\"event\": \"COMMAND_START\", \"at_ms\": 1789523788527, \"elapsed_s\": 45.18699999997625, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 22, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n 91|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523788731, \"elapsed_s\": 45.38999999995576, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 22, \"exit\": 0, \"elapsed_ms\": 202.9999999795109}\n*92|{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523788731, \"elapsed_s\": 45.38999999995576, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523788724, \"net_enabled\": true, \"net_canary_age_ms\": 22, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 93|{\"event\": \"COMMAND_START\", \"at_ms\": 1789523789732, \"elapsed_s\": 46.38999999995576, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 23, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n 94|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523790682, \"elapsed_s\": 47.34399999998277, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 23, \"exit\": 0, \"elapsed_ms\": 954.0000000270084}\n*95|{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523790682, \"elapsed_s\": 47.34399999998277, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523790675, \"net_enabled\": true, \"net_canary_age_ms\": 24, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 96|{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523791290, \"elapsed_s\": 47.95299999997951, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-baseline-018\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"owne...\n*97|{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523791290, \"elapsed_s\": 47.95299999997951, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-baseline-018\", \"rc\": 1}\n 98|{\"event\": \"COMMAND_START\", \"at_ms\": 1789523792291, \"elapsed_s\": 48.95299999997951, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 24, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n 99|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523793899, \"elapsed_s\": 50.56199999997625, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 24, \"exit\": 0, \"elapsed_ms\": 1608.9999999967404}\n*100|{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523793900, \"elapsed_s\": 50.56199999997625, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523793865, \"net_enabled\": true, \"net_canary_age_ms\": 14, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 14}\n 101|{\"event\": \"COMMAND_START\", \"at_ms\": 1789523794900, \"elapsed_s\": 51.56199999997625, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 25, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n 102|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523795202, \"elapsed_s\": 51.85899999999674, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 25, \"exit\": 0, \"elapsed_ms\": 297.0000000204891}\n*103|{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523795202, \"elapsed_s\": 51.85899999999674, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523795193, \"net_enabled\": true, \"net_canary_age_ms\": 17, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 1}\n 104|{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523795664, \"elapsed_s\": 52.32799999997951, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-baseline-020\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"owne...\n*105|{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523795664, \"elapsed_s\": 52.32799999997951, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-baseline-020\", \"rc\": 1}\n 106|{\"event\": \"COMMAND_START\", \"at_ms\": 1789523796665, \"elapsed_s\": 53.32799999997951, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 26, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n 107|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523796945, \"elapsed_s\": 53.60899999999674, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 26, \"exit\": 0, \"elapsed_ms\": 281.00000001722947}\n*108|{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523796945, \"elapsed_s\": 53.60899999999674, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523796934, \"net_enabled\": true, \"net_canary_age_ms\": 8, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 109|{\"event\": \"COMMAND_START\", \"at_ms\": 1789523797946, \"elapsed_s\": 54.60899999999674, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 27, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n 110|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523799031, \"elapsed_s\": 55.68699999997625, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 27, \"exit\": 0, \"elapsed_ms\": 1077.999999979511}\n*111|{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523799031, \"elapsed_s\": 55.68699999997625, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523799025, \"net_enabled\": true, \"net_canary_age_ms\": 24, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n*112|{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523800503, \"elapsed_s\": 57.15599999995902, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-baseline-022\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"owne...\n*113|{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523800503, \"elapsed_s\": 57.15599999995902, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-baseline-022\", \"rc\": 1}\n 114|{\"event\": \"PHASE_END\", \"at_ms\": 1789523801504, \"elapsed_s\": 58.15599999995902, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"requested_s\": 45, \"actual_s\": 45.0, \"truncated\": false}\n 115|{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523802030, \"elapsed_s\": 58.68699999997625, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"backup and set isolated cadence\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}},...\n 116|{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523802481, \"elapsed_s\": 59.13999999995576, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"node refresh\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"owned_handle_pid\"...\n...\n 121|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523802610, \"elapsed_s\": 59.26499999995576, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 29, \"exit\": 0, \"elapsed_ms\": 61.999999976251274}\n*122|{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523802610, \"elapsed_s\": 59.26499999995576, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523802605, \"net_enabled\": true, \"net_canary_age_ms\": 4, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 123|{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523802757, \"elapsed_s\": 59.42199999996228, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-cadence-priming-000\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": ...\n*124|{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523802757, \"elapsed_s\": 59.42199999996228, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-cadence-priming-000\", \"rc\": 1}\n 125|{\"event\": \"COMMAND_START\", \"at_ms\": 1789523803758, \"elapsed_s\": 60.42199999996228, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 30, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\h...\n 126|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523803798, \"elapsed_s\": 60.45299999997951, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 30, \"exit\": 0, \"elapsed_ms\": 31.000000017229468}\n*127|{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523803798, \"elapsed_s\": 60.45299999997951, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523803794, \"net_enabled\": true, \"net_canary_age_ms\": 18, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 128|{\"event\": \"COMMAND_START\", \"at_ms\": 1789523804800, \"elapsed_s\": 61.45299999997951, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 31, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\h...\n 129|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523804957, \"elapsed_s\": 61.60899999999674, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 31, \"exit\": 0, \"elapsed_ms\": 156.00000001722947}\n*130|{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523804957, \"elapsed_s\": 61.60899999999674, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523804941, \"net_enabled\": true, \"net_canary_age_ms\": 15, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 5}\n 131|{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523805269, \"elapsed_s\": 61.92199999996228, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-cadence-priming-002\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": ...\n*132|{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523805269, \"elapsed_s\": 61.92199999996228, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-cadence-priming-002\", \"rc\": 1}\n 133|{\"event\": \"COMMAND_START\", \"at_ms\": 1789523806270, \"elapsed_s\": 62.92199999996228, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 32, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\h...\n 134|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523806507, \"elapsed_s\": 63.17199999996228, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 32, \"exit\": 0, \"elapsed_ms\": 250.0}\n*135|{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523806507, \"elapsed_s\": 63.17199999996228, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523806499, \"net_enabled\": true, \"net_canary_age_ms\": 23, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 136|{\"event\": \"COMMAND_START\", \"at_ms\": 1789523807507, \"elapsed_s\": 64.17199999996228, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 33, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\h...\n 137|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523807739, \"elapsed_s\": 64.38999999995576, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 33, \"exit\": 0, \"elapsed_ms\": 217.99999999348074}\n*138|{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523807739, \"elapsed_s\": 64.38999999995576, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523807721, \"net_enabled\": true, \"net_canary_age_ms\": 19, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 139|{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523808108, \"elapsed_s\": 64.76499999995576, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-cadence-priming-004\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": ...\n*140|{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523808108, \"elapsed_s\": 64.76499999995576, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-cadence-priming-004\", \"rc\": 1}\n 141|{\"event\": \"COMMAND_START\", \"at_ms\": 1789523809108, \"elapsed_s\": 65.76499999995576, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 34, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\h...\n 142|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523809185, \"elapsed_s\": 65.84399999998277, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 34, \"exit\": 0, \"elapsed_ms\": 79.00000002700835}\n*143|{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523809185, \"elapsed_s\": 65.84399999998277, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523809180, \"net_enabled\": true, \"net_canary_age_ms\": 4, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 144|{\"event\": \"COMMAND_START\", \"at_ms\": 1789523810186, \"elapsed_s\": 66.84399999998277, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 35, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\h...\n 145|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523810588, \"elapsed_s\": 67.25, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 35, \"exit\": 0, \"elapsed_ms\": 406.00000001722947}\n*146|{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523810588, \"elapsed_s\": 67.25, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523810583, \"net_enabled\": true, \"net_canary_age_ms\": 7, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 147|{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523810876, \"elapsed_s\": 67.53099999995902, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-cadence-priming-006\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": ...\n*148|{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523810876, \"elapsed_s\": 67.53099999995902, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-cadence-priming-006\", \"rc\": 1}\n 149|{\"event\": \"COMMAND_START\", \"at_ms\": 1789523811876, \"elapsed_s\": 68.53099999995902, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 36, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\h...\n 150|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523813010, \"elapsed_s\": 69.67199999996228, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 36, \"exit\": 0, \"elapsed_ms\": 1141.0000000032596}\n*151|{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523813010, \"elapsed_s\": 69.67199999996228, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523813004, \"net_enabled\": true, \"net_canary_age_ms\": 4, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 152|{\"event\": \"PHASE_END\", \"at_ms\": 1789523813010, \"elapsed_s\": 69.67199999996228, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"requested_s\": 10, \"actual_s\": 10.46899999998277, \"truncated\": false}\n\n[Showing lines 1-137 of 516 (49.9KB limit). Use :138 to continue. Some lines truncated to 512 chars]"}],"details":{"scopePath":".spt/preserved/307/hertz-w1bc/w1c-run1/events.jsonl","searchPath":"C:\\Users\\decid\\Documents\\projects\\spt-core\\.spt\\preserved\\307\\hertz-w1bc\\w1c-run1\\events.jsonl","cwd":"C:\\Users\\decid\\Documents\\projects\\spt-core","matchCount":200,"fileCount":1,"files":[".spt/preserved/307/hertz-w1bc/w1c-run1/events.jsonl"],"fileMatches":[{"path":".spt/preserved/307/hertz-w1bc/w1c-run1/events.jsonl","count":200}],"truncated":true,"perFileLimitReached":200,"displayContent":"  13│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523752479, \"elapsed_s\": 9.139999999955762, \"phase\": \"startup\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 3, \"argv\": [\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\", \"endpoint\", \"start\", \"w1crig\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n *14│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523754022, \"elapsed_s\": 10.686999999976251, \"phase\": \"startup\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 3, \"exit\": 0, \"elapsed_ms\": 1547.000000020489}\n  15│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523755435, \"elapsed_s\": 12.09399999998277, \"phase\": \"startup\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc attach\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"owned_handle_pid\": 39...\n  16│{\"event\": \"OWNED_PROCESS\", \"at_ms\": 1789523756024, \"elapsed_s\": 12.686999999976251, \"phase\": \"startup\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"pid\": 58116, \"birth\": 1789523755.8826158, \"exe\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\", \"ppid\": 6180, \"role\": \"rc-1\", \"ancestors\": [6180, 45312, 46812, 55908, 26356, 30608, 35552]}\n  17│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523756226, \"elapsed_s\": 12.889999999955762, \"phase\": \"startup\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 4, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n *18│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523756502, \"elapsed_s\": 13.155999999959022, \"phase\": \"startup\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 4, \"exit\": 0, \"elapsed_ms\": 266.00000000325963}\n *19│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523756502, \"elapsed_s\": 13.155999999959022, \"phase\": \"startup\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523756487, \"net_enabled\": true, \"net_canary_age_ms\": 11, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 2}\n *20│{\"event\": \"PHASE_START\", \"at_ms\": 1789523756502, \"elapsed_s\": 13.155999999959022, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"requested_s\": 45}\n *21│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523756502, \"elapsed_s\": 13.155999999959022, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 5, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n  22│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523756576, \"elapsed_s\": 13.23399999999674, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 5, \"exit\": 0, \"elapsed_ms\": 78.00000003771856}\n *23│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523756576, \"elapsed_s\": 13.23399999999674, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523756566, \"net_enabled\": true, \"net_canary_age_ms\": 15, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n  24│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523756904, \"elapsed_s\": 13.561999999976251, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-baseline-000\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"own...\n *25│{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523756904, \"elapsed_s\": 13.561999999976251, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-baseline-000\", \"rc\": 1}\n  26│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523757905, \"elapsed_s\": 14.561999999976251, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 6, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n  27│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523758214, \"elapsed_s\": 14.875, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 6, \"exit\": 0, \"elapsed_ms\": 313.0000000237487}\n *28│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523758214, \"elapsed_s\": 14.875, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523758203, \"net_enabled\": true, \"net_canary_age_ms\": 2, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 1}\n  29│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523759215, \"elapsed_s\": 15.875, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 7, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n  30│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523759688, \"elapsed_s\": 16.34399999998277, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 7, \"exit\": 0, \"elapsed_ms\": 468.99999998277053}\n *31│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523759688, \"elapsed_s\": 16.34399999998277, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523759681, \"net_enabled\": true, \"net_canary_age_ms\": 5, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n  32│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523760591, \"elapsed_s\": 17.25, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-baseline-002\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"owned_handle_pid...\n *33│{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523760591, \"elapsed_s\": 17.25, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-baseline-002\", \"rc\": 1}\n  34│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523761592, \"elapsed_s\": 18.25, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 8, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n  35│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523761823, \"elapsed_s\": 18.48399999999674, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 8, \"exit\": 0, \"elapsed_ms\": 233.99999999674037}\n *36│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523761823, \"elapsed_s\": 18.48399999999674, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523761815, \"net_enabled\": true, \"net_canary_age_ms\": 14, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n  37│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523762824, \"elapsed_s\": 19.48399999999674, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 9, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n  38│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523762981, \"elapsed_s\": 19.639999999955762, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 9, \"exit\": 0, \"elapsed_ms\": 155.9999999590218}\n *39│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523762981, \"elapsed_s\": 19.639999999955762, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523762972, \"net_enabled\": true, \"net_canary_age_ms\": 21, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n  40│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523763112, \"elapsed_s\": 19.764999999955762, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-baseline-004\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"own...\n *41│{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523763113, \"elapsed_s\": 19.764999999955762, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-baseline-004\", \"rc\": 1}\n  42│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523764113, \"elapsed_s\": 20.764999999955762, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 10, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n *43│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523764250, \"elapsed_s\": 20.905999999959022, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 10, \"exit\": 0, \"elapsed_ms\": 141.00000000325963}\n *44│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523764250, \"elapsed_s\": 20.905999999959022, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523764241, \"net_enabled\": true, \"net_canary_age_ms\": 13, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n *45│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523765250, \"elapsed_s\": 21.905999999959022, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 11, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n  46│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523766114, \"elapsed_s\": 22.764999999955762, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 11, \"exit\": 0, \"elapsed_ms\": 344.0000000409782}\n *47│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523766115, \"elapsed_s\": 22.780999999959022, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523765586, \"net_enabled\": true, \"net_canary_age_ms\": 10, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n  48│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523766466, \"elapsed_s\": 23.125, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-baseline-006\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"owned_handle_pi...\n *49│{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523766466, \"elapsed_s\": 23.125, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-baseline-006\", \"rc\": 1}\n  50│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523767467, \"elapsed_s\": 24.125, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 12, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n  51│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523768192, \"elapsed_s\": 24.84399999998277, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 12, \"exit\": 0, \"elapsed_ms\": 718.9999999827705}\n *52│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523768192, \"elapsed_s\": 24.84399999998277, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523768186, \"net_enabled\": true, \"net_canary_age_ms\": 9, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n  53│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523769193, \"elapsed_s\": 25.85899999999674, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 13, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n  54│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523770386, \"elapsed_s\": 27.04699999996228, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 13, \"exit\": 0, \"elapsed_ms\": 1187.999999965541}\n *55│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523770386, \"elapsed_s\": 27.04699999996228, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523770381, \"net_enabled\": true, \"net_canary_age_ms\": 5, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n  56│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523771266, \"elapsed_s\": 27.92199999996228, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-baseline-008\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"owne...\n *57│{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523771266, \"elapsed_s\": 27.92199999996228, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-baseline-008\", \"rc\": 1}\n  58│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523772266, \"elapsed_s\": 28.92199999996228, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 14, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n  59│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523772644, \"elapsed_s\": 29.29699999996228, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 14, \"exit\": 0, \"elapsed_ms\": 375.0}\n *60│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523772644, \"elapsed_s\": 29.29699999996228, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523772622, \"net_enabled\": true, \"net_canary_age_ms\": 22, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 1}\n  61│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523773645, \"elapsed_s\": 30.29699999996228, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 15, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n  62│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523773688, \"elapsed_s\": 30.34399999998277, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 15, \"exit\": 0, \"elapsed_ms\": 47.0000000204891}\n *63│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523773688, \"elapsed_s\": 30.34399999998277, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523773682, \"net_enabled\": true, \"net_canary_age_ms\": 5, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n *64│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523774121, \"elapsed_s\": 30.780999999959022, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-baseline-010\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"own...\n *65│{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523774121, \"elapsed_s\": 30.780999999959022, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-baseline-010\", \"rc\": 1}\n *66│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523775122, \"elapsed_s\": 31.780999999959022, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 16, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n  67│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523775609, \"elapsed_s\": 32.26499999995576, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 16, \"exit\": 0, \"elapsed_ms\": 483.99999999674037}\n *68│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523775609, \"elapsed_s\": 32.26499999995576, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523775601, \"net_enabled\": true, \"net_canary_age_ms\": 0, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n  69│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523776610, \"elapsed_s\": 33.26499999995576, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 17, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n  70│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523776763, \"elapsed_s\": 33.42199999996228, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 17, \"exit\": 0, \"elapsed_ms\": 157.00000000651926}\n *71│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523776763, \"elapsed_s\": 33.42199999996228, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523776758, \"net_enabled\": true, \"net_canary_age_ms\": 8, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n  72│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523777051, \"elapsed_s\": 33.70299999997951, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-baseline-012\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"owne...\n *73│{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523777051, \"elapsed_s\": 33.70299999997951, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-baseline-012\", \"rc\": 1}\n  74│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523778051, \"elapsed_s\": 34.70299999997951, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 18, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n  75│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523778961, \"elapsed_s\": 35.625, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 18, \"exit\": 0, \"elapsed_ms\": 922.0000000204891}\n *76│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523778961, \"elapsed_s\": 35.625, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523778956, \"net_enabled\": true, \"net_canary_age_ms\": 6, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n  77│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523779963, \"elapsed_s\": 36.625, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 19, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n  78│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523783935, \"elapsed_s\": 40.59399999998277, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 19, \"exit\": 0, \"elapsed_ms\": 3968.9999999827705}\n *79│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523783936, \"elapsed_s\": 40.59399999998277, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523783925, \"net_enabled\": true, \"net_canary_age_ms\": 24, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 1}\n  80│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523784371, \"elapsed_s\": 41.03099999995902, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-baseline-014\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"owne...\n *81│{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523784371, \"elapsed_s\": 41.03099999995902, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-baseline-014\", \"rc\": 1}\n  82│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523785380, \"elapsed_s\": 42.03099999995902, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 20, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n  83│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523785798, \"elapsed_s\": 42.45299999997951, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 20, \"exit\": 0, \"elapsed_ms\": 422.0000000204891}\n *84│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523785798, \"elapsed_s\": 42.45299999997951, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523785780, \"net_enabled\": true, \"net_canary_age_ms\": 4, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 1}\n  85│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523786798, \"elapsed_s\": 43.45299999997951, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 21, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n  86│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523787134, \"elapsed_s\": 43.79699999996228, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 21, \"exit\": 0, \"elapsed_ms\": 343.99999998277053}\n *87│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523787134, \"elapsed_s\": 43.79699999996228, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523787127, \"net_enabled\": true, \"net_canary_age_ms\": 2, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n  88│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523787527, \"elapsed_s\": 44.18699999997625, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-baseline-016\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"owne...\n *89│{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523787527, \"elapsed_s\": 44.18699999997625, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-baseline-016\", \"rc\": 1}\n  90│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523788527, \"elapsed_s\": 45.18699999997625, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 22, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n  91│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523788731, \"elapsed_s\": 45.38999999995576, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 22, \"exit\": 0, \"elapsed_ms\": 202.9999999795109}\n *92│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523788731, \"elapsed_s\": 45.38999999995576, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523788724, \"net_enabled\": true, \"net_canary_age_ms\": 22, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n  93│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523789732, \"elapsed_s\": 46.38999999995576, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 23, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n  94│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523790682, \"elapsed_s\": 47.34399999998277, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 23, \"exit\": 0, \"elapsed_ms\": 954.0000000270084}\n *95│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523790682, \"elapsed_s\": 47.34399999998277, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523790675, \"net_enabled\": true, \"net_canary_age_ms\": 24, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n  96│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523791290, \"elapsed_s\": 47.95299999997951, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-baseline-018\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"owne...\n *97│{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523791290, \"elapsed_s\": 47.95299999997951, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-baseline-018\", \"rc\": 1}\n  98│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523792291, \"elapsed_s\": 48.95299999997951, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 24, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n  99│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523793899, \"elapsed_s\": 50.56199999997625, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 24, \"exit\": 0, \"elapsed_ms\": 1608.9999999967404}\n*100│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523793900, \"elapsed_s\": 50.56199999997625, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523793865, \"net_enabled\": true, \"net_canary_age_ms\": 14, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 14}\n 101│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523794900, \"elapsed_s\": 51.56199999997625, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 25, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n 102│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523795202, \"elapsed_s\": 51.85899999999674, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 25, \"exit\": 0, \"elapsed_ms\": 297.0000000204891}\n*103│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523795202, \"elapsed_s\": 51.85899999999674, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523795193, \"net_enabled\": true, \"net_canary_age_ms\": 17, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 1}\n 104│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523795664, \"elapsed_s\": 52.32799999997951, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-baseline-020\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"owne...\n*105│{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523795664, \"elapsed_s\": 52.32799999997951, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-baseline-020\", \"rc\": 1}\n 106│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523796665, \"elapsed_s\": 53.32799999997951, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 26, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n 107│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523796945, \"elapsed_s\": 53.60899999999674, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 26, \"exit\": 0, \"elapsed_ms\": 281.00000001722947}\n*108│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523796945, \"elapsed_s\": 53.60899999999674, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523796934, \"net_enabled\": true, \"net_canary_age_ms\": 8, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 109│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523797946, \"elapsed_s\": 54.60899999999674, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 27, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n 110│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523799031, \"elapsed_s\": 55.68699999997625, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 27, \"exit\": 0, \"elapsed_ms\": 1077.999999979511}\n*111│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523799031, \"elapsed_s\": 55.68699999997625, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523799025, \"net_enabled\": true, \"net_canary_age_ms\": 24, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n*112│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523800503, \"elapsed_s\": 57.15599999995902, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-baseline-022\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"owne...\n*113│{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523800503, \"elapsed_s\": 57.15599999995902, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-baseline-022\", \"rc\": 1}\n 114│{\"event\": \"PHASE_END\", \"at_ms\": 1789523801504, \"elapsed_s\": 58.15599999995902, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"requested_s\": 45, \"actual_s\": 45.0, \"truncated\": false}\n 115│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523802030, \"elapsed_s\": 58.68699999997625, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"backup and set isolated cadence\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}},...\n 116│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523802481, \"elapsed_s\": 59.13999999995576, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"node refresh\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"owned_handle_pid\"...\n    │...\n 121│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523802610, \"elapsed_s\": 59.26499999995576, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 29, \"exit\": 0, \"elapsed_ms\": 61.999999976251274}\n*122│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523802610, \"elapsed_s\": 59.26499999995576, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523802605, \"net_enabled\": true, \"net_canary_age_ms\": 4, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 123│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523802757, \"elapsed_s\": 59.42199999996228, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-cadence-priming-000\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": ...\n*124│{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523802757, \"elapsed_s\": 59.42199999996228, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-cadence-priming-000\", \"rc\": 1}\n 125│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523803758, \"elapsed_s\": 60.42199999996228, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 30, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\h...\n 126│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523803798, \"elapsed_s\": 60.45299999997951, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 30, \"exit\": 0, \"elapsed_ms\": 31.000000017229468}\n*127│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523803798, \"elapsed_s\": 60.45299999997951, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523803794, \"net_enabled\": true, \"net_canary_age_ms\": 18, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 128│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523804800, \"elapsed_s\": 61.45299999997951, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 31, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\h...\n 129│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523804957, \"elapsed_s\": 61.60899999999674, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 31, \"exit\": 0, \"elapsed_ms\": 156.00000001722947}\n*130│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523804957, \"elapsed_s\": 61.60899999999674, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523804941, \"net_enabled\": true, \"net_canary_age_ms\": 15, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 5}\n 131│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523805269, \"elapsed_s\": 61.92199999996228, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-cadence-priming-002\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": ...\n*132│{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523805269, \"elapsed_s\": 61.92199999996228, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-cadence-priming-002\", \"rc\": 1}\n 133│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523806270, \"elapsed_s\": 62.92199999996228, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 32, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\h...\n 134│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523806507, \"elapsed_s\": 63.17199999996228, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 32, \"exit\": 0, \"elapsed_ms\": 250.0}\n*135│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523806507, \"elapsed_s\": 63.17199999996228, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523806499, \"net_enabled\": true, \"net_canary_age_ms\": 23, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 136│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523807507, \"elapsed_s\": 64.17199999996228, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 33, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\h...\n 137│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523807739, \"elapsed_s\": 64.38999999995576, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 33, \"exit\": 0, \"elapsed_ms\": 217.99999999348074}\n*138│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523807739, \"elapsed_s\": 64.38999999995576, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523807721, \"net_enabled\": true, \"net_canary_age_ms\": 19, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 139│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523808108, \"elapsed_s\": 64.76499999995576, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-cadence-priming-004\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": ...\n*140│{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523808108, \"elapsed_s\": 64.76499999995576, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-cadence-priming-004\", \"rc\": 1}\n 141│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523809108, \"elapsed_s\": 65.76499999995576, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 34, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\h...\n 142│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523809185, \"elapsed_s\": 65.84399999998277, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 34, \"exit\": 0, \"elapsed_ms\": 79.00000002700835}\n*143│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523809185, \"elapsed_s\": 65.84399999998277, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523809180, \"net_enabled\": true, \"net_canary_age_ms\": 4, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 144│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523810186, \"elapsed_s\": 66.84399999998277, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 35, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\h...\n 145│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523810588, \"elapsed_s\": 67.25, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 35, \"exit\": 0, \"elapsed_ms\": 406.00000001722947}\n*146│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523810588, \"elapsed_s\": 67.25, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523810583, \"net_enabled\": true, \"net_canary_age_ms\": 7, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 147│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523810876, \"elapsed_s\": 67.53099999995902, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-cadence-priming-006\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": ...\n*148│{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523810876, \"elapsed_s\": 67.53099999995902, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-cadence-priming-006\", \"rc\": 1}\n 149│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523811876, \"elapsed_s\": 68.53099999995902, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 36, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\h...\n 150│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523813010, \"elapsed_s\": 69.67199999996228, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 36, \"exit\": 0, \"elapsed_ms\": 1141.0000000032596}\n*151│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523813010, \"elapsed_s\": 69.67199999996228, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523813004, \"net_enabled\": true, \"net_canary_age_ms\": 4, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 152│{\"event\": \"PHASE_END\", \"at_ms\": 1789523813010, \"elapsed_s\": 69.67199999996228, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"requested_s\": 10, \"actual_s\": 10.46899999998277, \"truncated\": false}\n 153│{\"event\": \"PHASE_START\", \"at_ms\": 1789523813010, \"elapsed_s\": 69.67199999996228, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"requested_s\": 120}\n 154│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523813010, \"elapsed_s\": 69.67199999996228, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 37, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\ho...\n 155│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523814544, \"elapsed_s\": 71.20299999997951, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 37, \"exit\": 0, \"elapsed_ms\": 1531.0000000172295}\n*156│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523814544, \"elapsed_s\": 71.20299999997951, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523814527, \"net_enabled\": true, \"net_canary_age_ms\": 26, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 9}\n 157│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523814642, \"elapsed_s\": 71.29699999996228, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-cadence-600000-000\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39...\n*158│{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523814642, \"elapsed_s\": 71.29699999996228, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-cadence-600000-000\", \"rc\": 1}\n 159│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523815643, \"elapsed_s\": 72.29699999996228, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 38, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\ho...\n 160│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523815845, \"elapsed_s\": 72.5, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 38, \"exit\": 0, \"elapsed_ms\": 203.00000003771856}\n*161│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523815845, \"elapsed_s\": 72.5, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523815830, \"net_enabled\": true, \"net_canary_age_ms\": 5, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 162│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523816846, \"elapsed_s\": 73.5, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 39, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n 163│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523817131, \"elapsed_s\": 73.79699999996228, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 39, \"exit\": 0, \"elapsed_ms\": 296.99999996228144}\n*164│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523817131, \"elapsed_s\": 73.79699999996228, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523817119, \"net_enabled\": true, \"net_canary_age_ms\": 18, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 1}\n 165│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523817244, \"elapsed_s\": 73.90599999995902, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-cadence-600000-002\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39...\n*166│{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523817244, \"elapsed_s\": 73.90599999995902, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-cadence-600000-002\", \"rc\": 1}\n 167│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523818245, \"elapsed_s\": 74.90599999995902, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 40, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\ho...\n 168│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523818317, \"elapsed_s\": 74.96899999998277, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 40, \"exit\": 0, \"elapsed_ms\": 63.000000023748726}\n*169│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523818317, \"elapsed_s\": 74.96899999998277, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523818311, \"net_enabled\": true, \"net_canary_age_ms\": 10, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 170│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523819318, \"elapsed_s\": 75.98399999999674, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 41, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\ho...\n 171│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523819641, \"elapsed_s\": 76.29699999996228, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 41, \"exit\": 0, \"elapsed_ms\": 312.99999996554106}\n*172│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523819641, \"elapsed_s\": 76.29699999996228, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523819631, \"net_enabled\": true, \"net_canary_age_ms\": 5, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 173│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523820032, \"elapsed_s\": 76.68699999997625, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-cadence-600000-004\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39...\n*174│{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523820032, \"elapsed_s\": 76.68699999997625, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-cadence-600000-004\", \"rc\": 1}\n 175│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523821033, \"elapsed_s\": 77.68699999997625, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 42, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\ho...\n 176│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523821749, \"elapsed_s\": 78.40599999995902, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 42, \"exit\": 0, \"elapsed_ms\": 718.9999999827705}\n*177│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523821749, \"elapsed_s\": 78.40599999995902, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523821743, \"net_enabled\": true, \"net_canary_age_ms\": 17, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 178│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523822750, \"elapsed_s\": 79.40599999995902, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 43, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\ho...\n 179│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523823613, \"elapsed_s\": 80.26499999995576, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 43, \"exit\": 0, \"elapsed_ms\": 858.9999999967404}\n*180│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523823613, \"elapsed_s\": 80.26499999995576, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523823607, \"net_enabled\": true, \"net_canary_age_ms\": 6, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 181│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523823900, \"elapsed_s\": 80.56199999997625, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-cadence-600000-006\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39...\n*182│{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523823900, \"elapsed_s\": 80.56199999997625, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-cadence-600000-006\", \"rc\": 1}\n 183│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523824900, \"elapsed_s\": 81.56199999997625, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 44, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\ho...\n 184│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523826304, \"elapsed_s\": 82.96899999998277, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 44, \"exit\": 0, \"elapsed_ms\": 1407.0000000065193}\n*185│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523826304, \"elapsed_s\": 82.96899999998277, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523826288, \"net_enabled\": true, \"net_canary_age_ms\": 12, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 186│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523827304, \"elapsed_s\": 83.96899999998277, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 45, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\ho...\n 187│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523827647, \"elapsed_s\": 84.31199999997625, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 45, \"exit\": 0, \"elapsed_ms\": 342.99999999348074}\n*188│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523827647, \"elapsed_s\": 84.31199999997625, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523827639, \"net_enabled\": true, \"net_canary_age_ms\": 13, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 189│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523827776, \"elapsed_s\": 84.43699999997625, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-cadence-600000-008\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39...\n*190│{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523827776, \"elapsed_s\": 84.43699999997625, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-cadence-600000-008\", \"rc\": 1}\n 191│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523828777, \"elapsed_s\": 85.43699999997625, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 46, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\ho...\n 192│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523828815, \"elapsed_s\": 85.46899999998277, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 46, \"exit\": 0, \"elapsed_ms\": 32.00000000651926}\n*193│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523828815, \"elapsed_s\": 85.46899999998277, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523828810, \"net_enabled\": true, \"net_canary_age_ms\": 9, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 194│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523829815, \"elapsed_s\": 86.46899999998277, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 47, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\ho...\n 195│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523830115, \"elapsed_s\": 86.78099999995902, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 47, \"exit\": 0, \"elapsed_ms\": 311.9999999762513}\n*196│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523830115, \"elapsed_s\": 86.78099999995902, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523830103, \"net_enabled\": true, \"net_canary_age_ms\": 3, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 197│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523830458, \"elapsed_s\": 87.10899999999674, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-cadence-600000-010\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39...\n*198│{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523830458, \"elapsed_s\": 87.10899999999674, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-cadence-600000-010\", \"rc\": 1}\n 199│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523831458, \"elapsed_s\": 88.125, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 48, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n 200│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523831761, \"elapsed_s\": 88.42199999996228, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 48, \"exit\": 0, \"elapsed_ms\": 296.99999996228144}\n*201│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523831761, \"elapsed_s\": 88.42199999996228, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523831757, \"net_enabled\": true, \"net_canary_age_ms\": 6, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 202│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523832763, \"elapsed_s\": 89.42199999996228, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 49, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\ho...\n 203│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523833081, \"elapsed_s\": 89.73399999999674, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 49, \"exit\": 0, \"elapsed_ms\": 312.00000003445894}\n*204│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523833081, \"elapsed_s\": 89.73399999999674, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523833073, \"net_enabled\": true, \"net_canary_age_ms\": 22, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 205│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523833390, \"elapsed_s\": 90.04699999996228, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-cadence-600000-012\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39...\n*206│{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523833390, \"elapsed_s\": 90.04699999996228, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-cadence-600000-012\", \"rc\": 1}\n 207│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523834391, \"elapsed_s\": 91.04699999996228, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 50, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\ho...\n 208│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523835852, \"elapsed_s\": 92.51499999995576, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 50, \"exit\": 0, \"elapsed_ms\": 1467.9999999934807}\n*209│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523835852, \"elapsed_s\": 92.51499999995576, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523835847, \"net_enabled\": true, \"net_canary_age_ms\": 21, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 210│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523836853, \"elapsed_s\": 93.51499999995576, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 51, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\ho...\n 211│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523839552, \"elapsed_s\": 96.21899999998277, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 51, \"exit\": 0, \"elapsed_ms\": 2688.0000000237487}\n*212│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523839552, \"elapsed_s\": 96.21899999998277, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523839546, \"net_enabled\": true, \"net_canary_age_ms\": 20, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 213│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523839992, \"elapsed_s\": 96.65599999995902, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-cadence-600000-014\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39...\n*214│{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523839992, \"elapsed_s\": 96.65599999995902, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-cadence-600000-014\", \"rc\": 1}\n 215│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523840993, \"elapsed_s\": 97.65599999995902, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 52, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\ho...\n 216│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523841033, \"elapsed_s\": 97.68699999997625, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 52, \"exit\": 0, \"elapsed_ms\": 31.000000017229468}\n*217│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523841033, \"elapsed_s\": 97.68699999997625, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523841028, \"net_enabled\": true, \"net_canary_age_ms\": 2, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 218│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523842034, \"elapsed_s\": 98.68699999997625, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 53, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\ho...\n 219│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523842099, \"elapsed_s\": 98.76499999995576, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 53, \"exit\": 0, \"elapsed_ms\": 63.000000023748726}\n*220│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523842099, \"elapsed_s\": 98.76499999995576, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523842092, \"net_enabled\": true, \"net_canary_age_ms\": 15, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 221│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523842432, \"elapsed_s\": 99.09399999998277, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-cadence-600000-016\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39...\n*222│{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523842432, \"elapsed_s\": 99.09399999998277, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-cadence-600000-016\", \"rc\": 1}\n 223│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523843432, \"elapsed_s\": 100.09399999998277, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 54, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\h...\n 224│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523843724, \"elapsed_s\": 100.38999999995576, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 54, \"exit\": 0, \"elapsed_ms\": 281.00000001722947}\n*225│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523843725, \"elapsed_s\": 100.38999999995576, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523843717, \"net_enabled\": true, \"net_canary_age_ms\": 16, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 226│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523844725, \"elapsed_s\": 101.38999999995576, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 55, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\h...\n 227│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523844979, \"elapsed_s\": 101.63999999995576, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 55, \"exit\": 0, \"elapsed_ms\": 250.0}\n*228│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523844979, \"elapsed_s\": 101.63999999995576, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523844972, \"net_enabled\": true, \"net_canary_age_ms\": 21, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 229│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523845260, \"elapsed_s\": 101.92199999996228, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-cadence-600000-018\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 3...\n*230│{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523845260, \"elapsed_s\": 101.92199999996228, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-cadence-600000-018\", \"rc\": 1}\n 231│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523846261, \"elapsed_s\": 102.92199999996228, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 56, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\h...\n 232│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523847645, \"elapsed_s\": 104.29699999996228, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 56, \"exit\": 0, \"elapsed_ms\": 1375.0}\n*233│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523847645, \"elapsed_s\": 104.29699999996228, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523847640, \"net_enabled\": true, \"net_canary_age_ms\": 14, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 234│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523848646, \"elapsed_s\": 105.31199999997625, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 57, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\h...\n 235│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523849985, \"elapsed_s\": 106.63999999995576, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 57, \"exit\": 0, \"elapsed_ms\": 1327.999999979511}\n*236│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523849985, \"elapsed_s\": 106.63999999995576, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523849965, \"net_enabled\": true, \"net_canary_age_ms\": 14, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 1}\n 237│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523850319, \"elapsed_s\": 106.98399999999674, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-cadence-600000-020\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 3...\n*238│{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523850319, \"elapsed_s\": 106.98399999999674, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-cadence-600000-020\", \"rc\": 1}\n 239│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523851320, \"elapsed_s\": 107.98399999999674, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 58, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\h...\n 240│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523851562, \"elapsed_s\": 108.21899999998277, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 58, \"exit\": 0, \"elapsed_ms\": 234.99999998603016}\n*241│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523851562, \"elapsed_s\": 108.21899999998277, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523851555, \"net_enabled\": true, \"net_canary_age_ms\": 5, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 242│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523852564, \"elapsed_s\": 109.21899999998277, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 59, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\h...\n 243│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523852747, \"elapsed_s\": 109.40599999995902, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 59, \"exit\": 0, \"elapsed_ms\": 186.99999997625127}\n*244│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523852747, \"elapsed_s\": 109.40599999995902, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523852740, \"net_enabled\": true, \"net_canary_age_ms\": 15, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n*245│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523852852, \"elapsed_s\": 109.51499999995576, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-cadence-600000-022\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 3...\n*246│{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523852852, \"elapsed_s\": 109.51499999995576, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-cadence-600000-022\", \"rc\": 1}\n 247│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523853853, \"elapsed_s\": 110.51499999995576, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 60, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\h...\n 248│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523853891, \"elapsed_s\": 110.54699999996228, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 60, \"exit\": 0, \"elapsed_ms\": 32.00000000651926}\n*249│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523853891, \"elapsed_s\": 110.54699999996228, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523853887, \"net_enabled\": true, \"net_canary_age_ms\": 11, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 250│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523854893, \"elapsed_s\": 111.54699999996228, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 61, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\h...\n 251│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523855037, \"elapsed_s\": 111.70299999997951, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 61, \"exit\": 0, \"elapsed_ms\": 156.00000001722947}\n*252│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523855038, \"elapsed_s\": 111.70299999997951, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523855032, \"net_enabled\": true, \"net_canary_age_ms\": 7, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 253│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523855322, \"elapsed_s\": 111.98399999999674, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-cadence-600000-024\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 3...\n*254│{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523855322, \"elapsed_s\": 111.98399999999674, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-cadence-600000-024\", \"rc\": 1}\n 255│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523856323, \"elapsed_s\": 112.98399999999674, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 62, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\h...\n 256│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523856901, \"elapsed_s\": 113.56199999997625, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 62, \"exit\": 0, \"elapsed_ms\": 577.9999999795109}\n*257│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523856901, \"elapsed_s\": 113.56199999997625, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523856895, \"net_enabled\": true, \"net_canary_age_ms\": 19, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 258│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523857901, \"elapsed_s\": 114.56199999997625, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 63, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\h...\n 259│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523859388, \"elapsed_s\": 116.04699999996228, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 63, \"exit\": 0, \"elapsed_ms\": 1484.9999999860302}\n*260│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523859388, \"elapsed_s\": 116.04699999996228, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523859372, \"net_enabled\": true, \"net_canary_age_ms\": 20, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 1}\n 261│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523859774, \"elapsed_s\": 116.43699999997625, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-cadence-600000-026\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 3...\n*262│{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523859774, \"elapsed_s\": 116.43699999997625, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-cadence-600000-026\", \"rc\": 1}\n 263│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523860775, \"elapsed_s\": 117.43699999997625, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 64, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\h...\n 264│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523861140, \"elapsed_s\": 117.79699999996228, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 64, \"exit\": 0, \"elapsed_ms\": 359.99999998603016}\n*265│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523861140, \"elapsed_s\": 117.79699999996228, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523861135, \"net_enabled\": true, \"net_canary_age_ms\": 9, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 266│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523862141, \"elapsed_s\": 118.79699999996228, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 65, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\h...\n 267│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523862246, \"elapsed_s\": 118.90599999995902, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 65, \"exit\": 0, \"elapsed_ms\": 108.99999999674037}\n*268│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523862246, \"elapsed_s\": 118.90599999995902, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523862240, \"net_enabled\": true, \"net_canary_age_ms\": 14, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 269│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523862373, \"elapsed_s\": 119.03099999995902, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-cadence-600000-028\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 3...\n*270│{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523862374, \"elapsed_s\": 119.03099999995902, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-cadence-600000-028\", \"rc\": 1}\n 271│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523863374, \"elapsed_s\": 120.03099999995902, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 66, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\h...\n 272│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523863412, \"elapsed_s\": 120.07799999997951, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 66, \"exit\": 0, \"elapsed_ms\": 31.000000017229468}\n*273│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523863412, \"elapsed_s\": 120.07799999997951, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523863407, \"net_enabled\": true, \"net_canary_age_ms\": 6, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 274│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523864413, \"elapsed_s\": 121.07799999997951, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 67, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\h...\n 275│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523864536, \"elapsed_s\": 121.18699999997625, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 67, \"exit\": 0, \"elapsed_ms\": 108.99999999674037}\n*276│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523864536, \"elapsed_s\": 121.18699999997625, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523864529, \"net_enabled\": true, \"net_canary_age_ms\": 4, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 1}\n 277│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523864826, \"elapsed_s\": 121.48399999999674, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-cadence-600000-030\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 3...\n*278│{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523864826, \"elapsed_s\": 121.48399999999674, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-cadence-600000-030\", \"rc\": 1}\n 279│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523865828, \"elapsed_s\": 122.48399999999674, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 68, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\h...\n 280│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523866366, \"elapsed_s\": 123.03099999995902, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 68, \"exit\": 0, \"elapsed_ms\": 546.9999999622814}\n*281│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523866366, \"elapsed_s\": 123.03099999995902, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523866362, \"net_enabled\": true, \"net_canary_age_ms\": 11, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 282│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523867367, \"elapsed_s\": 124.03099999995902, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 69, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\h...\n 283│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523869525, \"elapsed_s\": 126.18699999997625, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 69, \"exit\": 0, \"elapsed_ms\": 2156.0000000172295}\n*284│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523869525, \"elapsed_s\": 126.18699999997625, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523869521, \"net_enabled\": true, \"net_canary_age_ms\": 20, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 285│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523870640, \"elapsed_s\": 127.29699999996228, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-cadence-600000-032\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 3...\n*286│{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523870640, \"elapsed_s\": 127.29699999996228, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-cadence-600000-032\", \"rc\": 1}\n 287│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523871642, \"elapsed_s\": 128.29699999996228, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 70, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\h...\n 288│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523871889, \"elapsed_s\": 128.54699999996228, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 70, \"exit\": 0, \"elapsed_ms\": 250.0}\n*289│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523871889, \"elapsed_s\": 128.54699999996228, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523871881, \"net_enabled\": true, \"net_canary_age_ms\": 5, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 290│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523872890, \"elapsed_s\": 129.54699999996228, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 71, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\h...\n 291│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523872929, \"elapsed_s\": 129.59399999998277, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 71, \"exit\": 0, \"elapsed_ms\": 47.0000000204891}\n*292│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523872929, \"elapsed_s\": 129.59399999998277, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523872924, \"net_enabled\": true, \"net_canary_age_ms\": 23, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 293│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523873205, \"elapsed_s\": 129.85899999999674, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-cadence-600000-034\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 3...\n*294│{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523873205, \"elapsed_s\": 129.85899999999674, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-cadence-600000-034\", \"rc\": 1}\n 295│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523874205, \"elapsed_s\": 130.85899999999674, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 72, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\h...\n 296│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523874247, \"elapsed_s\": 130.90599999995902, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 72, \"exit\": 0, \"elapsed_ms\": 46.999999962281436}\n*297│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523874247, \"elapsed_s\": 130.90599999995902, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523874241, \"net_enabled\": true, \"net_canary_age_ms\": 16, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 298│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523875248, \"elapsed_s\": 131.90599999995902, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 73, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\h...\n 299│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523875288, \"elapsed_s\": 131.9529999999795, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 73, \"exit\": 0, \"elapsed_ms\": 47.0000000204891}\n*300│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523875288, \"elapsed_s\": 131.9529999999795, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523875284, \"net_enabled\": true, \"net_canary_age_ms\": 8, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 301│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523875651, \"elapsed_s\": 132.31199999997625, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-cadence-600000-036\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 3...\n*302│{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523875651, \"elapsed_s\": 132.31199999997625, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-cadence-600000-036\", \"rc\": 1}\n 303│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523876652, \"elapsed_s\": 133.31199999997625, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 74, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\h...\n 304│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523876793, \"elapsed_s\": 133.4529999999795, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 74, \"exit\": 0, \"elapsed_ms\": 141.00000000325963}\n*305│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523876793, \"elapsed_s\": 133.4529999999795, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523876786, \"net_enabled\": true, \"net_canary_age_ms\": 10, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 306│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523877794, \"elapsed_s\": 134.4529999999795, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 75, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\ho...\n 307│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523878153, \"elapsed_s\": 134.81199999997625, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 75, \"exit\": 0, \"elapsed_ms\": 358.99999999674037}\n*308│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523878153, \"elapsed_s\": 134.81199999997625, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523878144, \"net_enabled\": true, \"net_canary_age_ms\": 18, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 309│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523878430, \"elapsed_s\": 135.09399999998277, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-cadence-600000-038\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 3...\n*310│{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523878430, \"elapsed_s\": 135.09399999998277, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-cadence-600000-038\", \"rc\": 1}\n 311│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523879431, \"elapsed_s\": 136.09399999998277, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 76, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\h...\n 312│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523879472, \"elapsed_s\": 136.125, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 76, \"exit\": 0, \"elapsed_ms\": 31.000000017229468}\n*313│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523879472, \"elapsed_s\": 136.125, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523879467, \"net_enabled\": true, \"net_canary_age_ms\": 17, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 314│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523880473, \"elapsed_s\": 137.125, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 77, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n 315│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523881346, \"elapsed_s\": 138.0, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 77, \"exit\": 0, \"elapsed_ms\": 875.0}\n*316│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523881346, \"elapsed_s\": 138.0, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523881339, \"net_enabled\": true, \"net_canary_age_ms\": 12, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 317│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523881633, \"elapsed_s\": 138.29699999996228, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-cadence-600000-040\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 3...\n*318│{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523881633, \"elapsed_s\": 138.29699999996228, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-cadence-600000-040\", \"rc\": 1}\n 319│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523882634, \"elapsed_s\": 139.29699999996228, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 78, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\h...\n 320│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523884771, \"elapsed_s\": 141.43699999997625, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 78, \"exit\": 0, \"elapsed_ms\": 2125.0}\n*321│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523884771, \"elapsed_s\": 141.43699999997625, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523884766, \"net_enabled\": true, \"net_canary_age_ms\": 16, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 322│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523885772, \"elapsed_s\": 142.43699999997625, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 79, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\h...\n 323│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523886264, \"elapsed_s\": 142.92199999996228, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 79, \"exit\": 0, \"elapsed_ms\": 484.99999998603016}\n*324│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523886264, \"elapsed_s\": 142.92199999996228, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523886251, \"net_enabled\": true, \"net_canary_age_ms\": 0, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 2}\n 325│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523886393, \"elapsed_s\": 143.04699999996228, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-cadence-600000-042\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 3...\n*326│{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523886394, \"elapsed_s\": 143.04699999996228, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-cadence-600000-042\", \"rc\": 1}\n 327│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523887394, \"elapsed_s\": 144.04699999996228, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 80, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\h...\n 328│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523887483, \"elapsed_s\": 144.13999999995576, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 80, \"exit\": 0, \"elapsed_ms\": 92.99999999348074}\n*329│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523887483, \"elapsed_s\": 144.13999999995576, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523887475, \"net_enabled\": true, \"net_canary_age_ms\": 23, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 330│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523888484, \"elapsed_s\": 145.13999999995576, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 81, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\h...\n 331│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523888798, \"elapsed_s\": 145.4529999999795, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 81, \"exit\": 0, \"elapsed_ms\": 313.0000000237487}\n*332│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523888798, \"elapsed_s\": 145.4529999999795, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523888792, \"net_enabled\": true, \"net_canary_age_ms\": 17, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 333│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523888927, \"elapsed_s\": 145.59399999998277, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-cadence-600000-044\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 3...\n*334│{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523888928, \"elapsed_s\": 145.59399999998277, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-cadence-600000-044\", \"rc\": 1}\n 335│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523889929, \"elapsed_s\": 146.59399999998277, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 82, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\h...\n 336│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523890751, \"elapsed_s\": 147.40599999995902, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 82, \"exit\": 0, \"elapsed_ms\": 811.9999999762513}\n*337│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523890751, \"elapsed_s\": 147.40599999995902, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523890743, \"net_enabled\": true, \"net_canary_age_ms\": 18, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 338│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523891752, \"elapsed_s\": 148.40599999995902, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 83, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\h...\n 339│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523892875, \"elapsed_s\": 149.53099999995902, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 83, \"exit\": 0, \"elapsed_ms\": 1125.0}\n*340│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523892875, \"elapsed_s\": 149.53099999995902, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523892871, \"net_enabled\": true, \"net_canary_age_ms\": 20, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 341│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523893728, \"elapsed_s\": 150.38999999995576, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-cadence-600000-046\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 3...\n*342│{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523893728, \"elapsed_s\": 150.38999999995576, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-cadence-600000-046\", \"rc\": 1}\n 343│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523894728, \"elapsed_s\": 151.38999999995576, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 84, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\h...\n 344│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523894778, \"elapsed_s\": 151.43699999997625, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 84, \"exit\": 0, \"elapsed_ms\": 47.0000000204891}\n*345│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523894779, \"elapsed_s\": 151.43699999997625, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523894771, \"net_enabled\": true, \"net_canary_age_ms\": 21, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 346│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523895779, \"elapsed_s\": 152.43699999997625, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 85, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\h...\n 347│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523895817, \"elapsed_s\": 152.46899999998277, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 85, \"exit\": 0, \"elapsed_ms\": 32.00000000651926}\n*348│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523895817, \"elapsed_s\": 152.46899999998277, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523895812, \"net_enabled\": true, \"net_canary_age_ms\": 12, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 349│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523896180, \"elapsed_s\": 152.84399999998277, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-cadence-600000-048\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 3...\n*350│{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523896181, \"elapsed_s\": 152.84399999998277, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-cadence-600000-048\", \"rc\": 1}\n 351│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523897182, \"elapsed_s\": 153.84399999998277, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 86, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\h...\n 352│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523897370, \"elapsed_s\": 154.03099999995902, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 86, \"exit\": 0, \"elapsed_ms\": 186.99999997625127}\n*353│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523897370, \"elapsed_s\": 154.03099999995902, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523897362, \"net_enabled\": true, \"net_canary_age_ms\": 11, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 354│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523898371, \"elapsed_s\": 155.03099999995902, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 87, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\h...\n 355│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523898436, \"elapsed_s\": 155.09399999998277, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 87, \"exit\": 0, \"elapsed_ms\": 63.000000023748726}\n*356│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523898436, \"elapsed_s\": 155.09399999998277, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523898430, \"net_enabled\": true, \"net_canary_age_ms\": 3, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 357│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523898711, \"elapsed_s\": 155.375, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-cadence-600000-050\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"ow...\n*358│{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523898711, \"elapsed_s\": 155.375, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-cadence-600000-050\", \"rc\": 1}\n 359│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523899711, \"elapsed_s\": 156.375, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 88, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n 360│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523900321, \"elapsed_s\": 156.98399999999674, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 88, \"exit\": 0, \"elapsed_ms\": 608.9999999967404}\n*361│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523900321, \"elapsed_s\": 156.98399999999674, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523900317, \"net_enabled\": true, \"net_canary_age_ms\": 16, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 362│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523901323, \"elapsed_s\": 157.98399999999674, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 89, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\h...\n 363│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523902368, \"elapsed_s\": 159.03099999995902, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 89, \"exit\": 0, \"elapsed_ms\": 1046.9999999622814}\n*364│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523902368, \"elapsed_s\": 159.03099999995902, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523902352, \"net_enabled\": true, \"net_canary_age_ms\": 1, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 1}\n 365│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523902755, \"elapsed_s\": 159.42199999996228, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-cadence-600000-052\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 3...\n*366│{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523902755, \"elapsed_s\": 159.42199999996228, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-cadence-600000-052\", \"rc\": 1}\n 367│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523903757, \"elapsed_s\": 160.42199999996228, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 90, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\h...\n 368│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523903957, \"elapsed_s\": 160.60899999999674, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 90, \"exit\": 0, \"elapsed_ms\": 187.00000003445894}\n*369│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523903957, \"elapsed_s\": 160.60899999999674, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523903949, \"net_enabled\": true, \"net_canary_age_ms\": 23, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 370│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523904958, \"elapsed_s\": 161.60899999999674, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 91, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\h...\n 371│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523905016, \"elapsed_s\": 161.67199999996228, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 91, \"exit\": 0, \"elapsed_ms\": 62.999999965541065}\n*372│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523905016, \"elapsed_s\": 161.67199999996228, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523905010, \"net_enabled\": true, \"net_canary_age_ms\": 10, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 373│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523905296, \"elapsed_s\": 161.9529999999795, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-cadence-600000-054\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39...\n*374│{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523905296, \"elapsed_s\": 161.9529999999795, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-cadence-600000-054\", \"rc\": 1}\n 375│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523906296, \"elapsed_s\": 162.9529999999795, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 92, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\ho...\n 376│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523906656, \"elapsed_s\": 163.31199999997625, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 92, \"exit\": 0, \"elapsed_ms\": 358.99999999674037}\n*377│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523906656, \"elapsed_s\": 163.31199999997625, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523906650, \"net_enabled\": true, \"net_canary_age_ms\": 25, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 378│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523907657, \"elapsed_s\": 164.31199999997625, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 93, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\h...\n 379│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523908534, \"elapsed_s\": 165.18699999997625, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 93, \"exit\": 0, \"elapsed_ms\": 875.0}\n*380│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523908534, \"elapsed_s\": 165.18699999997625, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523908529, \"net_enabled\": true, \"net_canary_age_ms\": 3, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 381│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523909112, \"elapsed_s\": 165.76499999995576, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-cadence-600000-056\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 3...\n*382│{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523909112, \"elapsed_s\": 165.76499999995576, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-cadence-600000-056\", \"rc\": 1}\n 383│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523910113, \"elapsed_s\": 166.76499999995576, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 94, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\h...\n 384│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523911820, \"elapsed_s\": 168.48399999999674, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 94, \"exit\": 0, \"elapsed_ms\": 1719.0000000409782}\n*385│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523911820, \"elapsed_s\": 168.48399999999674, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523911811, \"net_enabled\": true, \"net_canary_age_ms\": 10, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 386│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523912821, \"elapsed_s\": 169.48399999999674, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 95, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\h...\n 387│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523913099, \"elapsed_s\": 169.76499999995576, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 95, \"exit\": 0, \"elapsed_ms\": 266.00000000325963}\n*388│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523913099, \"elapsed_s\": 169.76499999995576, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523913090, \"net_enabled\": true, \"net_canary_age_ms\": 14, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 389│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523913416, \"elapsed_s\": 170.0779999999795, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-cadence-600000-058\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39...\n*390│{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523913416, \"elapsed_s\": 170.0779999999795, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-cadence-600000-058\", \"rc\": 1}\n 391│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523914416, \"elapsed_s\": 171.0779999999795, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 96, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\ho...\n 392│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523914534, \"elapsed_s\": 171.18699999997625, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 96, \"exit\": 0, \"elapsed_ms\": 108.99999999674037}\n*393│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523914534, \"elapsed_s\": 171.18699999997625, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523914527, \"net_enabled\": true, \"net_canary_age_ms\": 1, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 394│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523915535, \"elapsed_s\": 172.18699999997625, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 97, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\h...\n 395│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523916003, \"elapsed_s\": 172.65599999995902, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 97, \"exit\": 0, \"elapsed_ms\": 468.99999998277053}\n*396│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523916003, \"elapsed_s\": 172.65599999995902, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523915996, \"net_enabled\": true, \"net_canary_age_ms\": 20, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 397│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523916301, \"elapsed_s\": 172.9529999999795, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-cadence-600000-060\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39...\n*398│{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523916301, \"elapsed_s\": 172.9529999999795, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-cadence-600000-060\", \"rc\": 1}\n 399│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523917302, \"elapsed_s\": 173.96899999998277, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 98, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\h...\n 400│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523918784, \"elapsed_s\": 175.43699999997625, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 98, \"exit\": 0, \"elapsed_ms\": 1467.9999999934807}\n*401│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523918784, \"elapsed_s\": 175.43699999997625, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523918778, \"net_enabled\": true, \"net_canary_age_ms\": 3, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 402│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523919784, \"elapsed_s\": 176.43699999997625, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 99, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\h...\n 403│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523921723, \"elapsed_s\": 178.375, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 99, \"exit\": 0, \"elapsed_ms\": 1938.0000000237487}\n*404│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523921723, \"elapsed_s\": 178.375, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523921685, \"net_enabled\": true, \"net_canary_age_ms\": 9, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 1}\n 405│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523922096, \"elapsed_s\": 178.75, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-cadence-600000-062\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"own...\n*406│{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523922096, \"elapsed_s\": 178.75, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-cadence-600000-062\", \"rc\": 1}\n 407│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523923097, \"elapsed_s\": 179.75, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 100, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n 408│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523923361, \"elapsed_s\": 180.01499999995576, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 100, \"exit\": 0, \"elapsed_ms\": 264.9999999557622}\n*409│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523923361, \"elapsed_s\": 180.01499999995576, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523923356, \"net_enabled\": true, \"net_canary_age_ms\": 4, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 410│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523924363, \"elapsed_s\": 181.01499999995576, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 101, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\...\n 411│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523924414, \"elapsed_s\": 181.0779999999795, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 101, \"exit\": 0, \"elapsed_ms\": 63.000000023748726}\n*412│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523924414, \"elapsed_s\": 181.0779999999795, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523924407, \"net_enabled\": true, \"net_canary_age_ms\": 5, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 413│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523924494, \"elapsed_s\": 181.15599999995902, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-cadence-600000-064\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 3...\n*414│{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523924494, \"elapsed_s\": 181.15599999995902, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-cadence-600000-064\", \"rc\": 1}\n 415│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523925494, \"elapsed_s\": 182.15599999995902, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 102, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\...\n 416│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523926204, \"elapsed_s\": 182.85899999999674, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 102, \"exit\": 0, \"elapsed_ms\": 703.0000000377186}\n*417│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523926204, \"elapsed_s\": 182.85899999999674, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523926198, \"net_enabled\": true, \"net_canary_age_ms\": 22, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 418│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523927205, \"elapsed_s\": 183.85899999999674, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 103, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\...\n 419│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523928620, \"elapsed_s\": 185.28099999995902, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 103, \"exit\": 0, \"elapsed_ms\": 1421.9999999622814}\n*420│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523928620, \"elapsed_s\": 185.28099999995902, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523928614, \"net_enabled\": true, \"net_canary_age_ms\": 13, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 421│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523929499, \"elapsed_s\": 186.15599999995902, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-cadence-600000-066\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 3...\n*422│{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523929500, \"elapsed_s\": 186.15599999995902, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-cadence-600000-066\", \"rc\": 1}\n 423│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523930500, \"elapsed_s\": 187.15599999995902, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 104, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\...\n 424│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523930874, \"elapsed_s\": 187.53099999995902, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 104, \"exit\": 0, \"elapsed_ms\": 375.0}\n*425│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523930874, \"elapsed_s\": 187.53099999995902, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523930867, \"net_enabled\": true, \"net_canary_age_ms\": 17, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 426│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523931876, \"elapsed_s\": 188.53099999995902, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 105, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\...\n 427│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523931951, \"elapsed_s\": 188.60899999999674, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 105, \"exit\": 0, \"elapsed_ms\": 78.00000003771856}\n*428│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523931951, \"elapsed_s\": 188.60899999999674, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523931945, \"net_enabled\": true, \"net_canary_age_ms\": 19, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 429│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523932352, \"elapsed_s\": 189.01499999995576, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-cadence-600000-068\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 3...\n*430│{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523932352, \"elapsed_s\": 189.01499999995576, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-cadence-600000-068\", \"rc\": 1}\n 431│{\"event\": \"PHASE_END\", \"at_ms\": 1789523933010, \"elapsed_s\": 189.67199999996228, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"requested_s\": 120, \"actual_s\": 120.0, \"truncated\": false}\n 432│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523933285, \"elapsed_s\": 189.93699999997625, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"restore exact isolated daemon config bytes\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\"...\n 433│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523933669, \"elapsed_s\": 190.3279999999795, \"phase\": \"cadence-600000\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"node refresh\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"owned_handl...\n    │...\n 439│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523934090, \"elapsed_s\": 190.75, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 107, \"exit\": 0, \"elapsed_ms\": 360.0000000442378}\n*440│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523934090, \"elapsed_s\": 190.75, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523934084, \"net_enabled\": true, \"net_canary_age_ms\": 8, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 441│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523934457, \"elapsed_s\": 191.10899999999674, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-restored-000\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"own...\n*442│{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523934457, \"elapsed_s\": 191.10899999999674, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-restored-000\", \"rc\": 1}\n 443│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523935458, \"elapsed_s\": 192.10899999999674, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 108, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w...\n 444│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523936951, \"elapsed_s\": 193.60899999999674, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 108, \"exit\": 0, \"elapsed_ms\": 1500.0}\n*445│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523936951, \"elapsed_s\": 193.60899999999674, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523936945, \"net_enabled\": true, \"net_canary_age_ms\": 20, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 446│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523937952, \"elapsed_s\": 194.60899999999674, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 109, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w...\n 447│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523938138, \"elapsed_s\": 194.79699999996228, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 109, \"exit\": 0, \"elapsed_ms\": 187.99999996554106}\n*448│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523938138, \"elapsed_s\": 194.79699999996228, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523938122, \"net_enabled\": true, \"net_canary_age_ms\": 21, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 9}\n 449│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523938249, \"elapsed_s\": 194.90599999995902, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-restored-002\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"own...\n*450│{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523938249, \"elapsed_s\": 194.90599999995902, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-restored-002\", \"rc\": 1}\n 451│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523939250, \"elapsed_s\": 195.90599999995902, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 110, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w...\n 452│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523939573, \"elapsed_s\": 196.23399999999674, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 110, \"exit\": 0, \"elapsed_ms\": 328.00000003771856}\n*453│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523939573, \"elapsed_s\": 196.23399999999674, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523939560, \"net_enabled\": true, \"net_canary_age_ms\": 9, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 1}\n 454│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523940573, \"elapsed_s\": 197.23399999999674, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 111, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w...\n 455│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523940969, \"elapsed_s\": 197.625, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 111, \"exit\": 0, \"elapsed_ms\": 391.00000000325963}\n*456│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523940969, \"elapsed_s\": 197.625, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523940948, \"net_enabled\": true, \"net_canary_age_ms\": 23, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 5}\n 457│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523941113, \"elapsed_s\": 197.76499999995576, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-restored-004\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"own...\n*458│{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523941113, \"elapsed_s\": 197.76499999995576, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-restored-004\", \"rc\": 1}\n 459│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523942114, \"elapsed_s\": 198.76499999995576, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 112, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w...\n 460│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523942413, \"elapsed_s\": 199.0779999999795, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 112, \"exit\": 0, \"elapsed_ms\": 313.0000000237487}\n*461│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523942413, \"elapsed_s\": 199.0779999999795, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523942399, \"net_enabled\": true, \"net_canary_age_ms\": 22, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 462│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523943413, \"elapsed_s\": 200.0779999999795, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 113, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n 463│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523943674, \"elapsed_s\": 200.3279999999795, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 113, \"exit\": 0, \"elapsed_ms\": 250.0}\n*464│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523943674, \"elapsed_s\": 200.3279999999795, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523943666, \"net_enabled\": true, \"net_canary_age_ms\": 14, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 465│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523943779, \"elapsed_s\": 200.43699999997625, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-restored-006\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"own...\n*466│{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523943779, \"elapsed_s\": 200.43699999997625, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-restored-006\", \"rc\": 1}\n 467│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523944780, \"elapsed_s\": 201.43699999997625, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 114, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w...\n 468│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523944856, \"elapsed_s\": 201.51499999995576, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 114, \"exit\": 0, \"elapsed_ms\": 77.9999999795109}\n*469│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523944857, \"elapsed_s\": 201.51499999995576, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523944849, \"net_enabled\": true, \"net_canary_age_ms\": 24, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 1}\n 470│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523945857, \"elapsed_s\": 202.51499999995576, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 115, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w...\n 471│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523946247, \"elapsed_s\": 202.90599999995902, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 115, \"exit\": 0, \"elapsed_ms\": 391.00000000325963}\n*472│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523946247, \"elapsed_s\": 202.90599999995902, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523946237, \"net_enabled\": true, \"net_canary_age_ms\": 11, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 1}\n 473│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523946899, \"elapsed_s\": 203.56199999997625, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-restored-008\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"own...\n*474│{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523946899, \"elapsed_s\": 203.56199999997625, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-restored-008\", \"rc\": 1}\n 475│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523947900, \"elapsed_s\": 204.56199999997625, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 116, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w...\n*476│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523950228, \"elapsed_s\": 206.88999999995576, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 116, \"exit\": 0, \"elapsed_ms\": 2327.999999979511}\n*477│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523950228, \"elapsed_s\": 206.88999999995576, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523950221, \"net_enabled\": true, \"net_canary_age_ms\": 20, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 478│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523951229, \"elapsed_s\": 207.88999999995576, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 117, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w...\n 479│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523951444, \"elapsed_s\": 208.10899999999674, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 117, \"exit\": 0, \"elapsed_ms\": 219.0000000409782}\n*480│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523951444, \"elapsed_s\": 208.10899999999674, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523951421, \"net_enabled\": true, \"net_canary_age_ms\": 20, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 2}\n 481│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523951566, \"elapsed_s\": 208.21899999998277, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-restored-010\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"own...\n*482│{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523951566, \"elapsed_s\": 208.21899999998277, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-restored-010\", \"rc\": 1}\n 483│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523952567, \"elapsed_s\": 209.21899999998277, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 118, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w...\n 484│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523952849, \"elapsed_s\": 209.5, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 118, \"exit\": 0, \"elapsed_ms\": 281.00000001722947}\n*485│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523952849, \"elapsed_s\": 209.5, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523952817, \"net_enabled\": true, \"net_canary_age_ms\": 16, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 486│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523953849, \"elapsed_s\": 210.51499999995576, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 119, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w...\n 487│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523953892, \"elapsed_s\": 210.54699999996228, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 119, \"exit\": 0, \"elapsed_ms\": 32.00000000651926}\n*488│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523953892, \"elapsed_s\": 210.54699999996228, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523953886, \"net_enabled\": true, \"net_canary_age_ms\": 10, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 489│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523954254, \"elapsed_s\": 210.90599999995902, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-restored-012\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"own...\n*490│{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523954254, \"elapsed_s\": 210.90599999995902, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-restored-012\", \"rc\": 1}\n 491│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523955254, \"elapsed_s\": 211.90599999995902, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 120, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w...\n 492│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523955530, \"elapsed_s\": 212.18699999997625, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 120, \"exit\": 0, \"elapsed_ms\": 281.00000001722947}\n*493│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523955530, \"elapsed_s\": 212.18699999997625, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523955524, \"net_enabled\": true, \"net_canary_age_ms\": 23, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 494│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523956531, \"elapsed_s\": 213.18699999997625, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 121, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w...\n 495│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523956983, \"elapsed_s\": 213.63999999995576, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 121, \"exit\": 0, \"elapsed_ms\": 266.00000000325963}\n*496│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523956983, \"elapsed_s\": 213.63999999995576, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523956785, \"net_enabled\": true, \"net_canary_age_ms\": 10, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 497│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523957110, \"elapsed_s\": 213.76499999995576, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-restored-014\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"own...\n*498│{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523957110, \"elapsed_s\": 213.76499999995576, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-restored-014\", \"rc\": 1}\n 499│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523958111, \"elapsed_s\": 214.76499999995576, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 122, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w...\n 500│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523958451, \"elapsed_s\": 215.10899999999674, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 122, \"exit\": 0, \"elapsed_ms\": 344.0000000409782}\n*501│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523958451, \"elapsed_s\": 215.10899999999674, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523958443, \"net_enabled\": true, \"net_canary_age_ms\": 17, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 1}\n 502│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523959452, \"elapsed_s\": 216.10899999999674, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 123, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w...\n 503│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523959588, \"elapsed_s\": 216.25, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 123, \"exit\": 0, \"elapsed_ms\": 141.00000000325963}\n*504│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523959588, \"elapsed_s\": 216.25, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523959582, \"net_enabled\": true, \"net_canary_age_ms\": 6, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 505│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523959933, \"elapsed_s\": 216.59399999998277, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-restored-016\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"own...\n*506│{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523959933, \"elapsed_s\": 216.59399999998277, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-restored-016\", \"rc\": 1}\n 507│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523960934, \"elapsed_s\": 217.59399999998277, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 124, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w...\n 508│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523961634, \"elapsed_s\": 218.29699999996228, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 124, \"exit\": 0, \"elapsed_ms\": 702.9999999795109}\n*509│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523961634, \"elapsed_s\": 218.29699999996228, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523961628, \"net_enabled\": true, \"net_canary_age_ms\": 3, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 510│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523962635, \"elapsed_s\": 219.29699999996228, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 125, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w...\n 511│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523962908, \"elapsed_s\": 219.56199999997625, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 125, \"exit\": 0, \"elapsed_ms\": 265.00000001396984}\n*512│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523962908, \"elapsed_s\": 219.56199999997625, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523962901, \"net_enabled\": true, \"net_canary_age_ms\": 25, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 1}\n 513│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523962991, \"elapsed_s\": 219.65599999995902, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-restored-018\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"own...\n*514│{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523962991, \"elapsed_s\": 219.65599999995902, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-restored-018\", \"rc\": 1}\n 515│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523963992, \"elapsed_s\": 220.65599999995902, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 126, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w...\n 516│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523964038, \"elapsed_s\": 220.7029999999795, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 126, \"exit\": 0, \"elapsed_ms\": 47.0000000204891}\n*517│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523964038, \"elapsed_s\": 220.7029999999795, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523964031, \"net_enabled\": true, \"net_canary_age_ms\": 6, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 518│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523965038, \"elapsed_s\": 221.7029999999795, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 127, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n 519│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523965189, \"elapsed_s\": 221.84399999998277, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 127, \"exit\": 0, \"elapsed_ms\": 141.00000000325963}\n*520│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523965189, \"elapsed_s\": 221.84399999998277, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523965182, \"net_enabled\": true, \"net_canary_age_ms\": 5, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 521│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523965307, \"elapsed_s\": 221.96899999998277, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-restored-020\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"own...\n*522│{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523965307, \"elapsed_s\": 221.96899999998277, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-restored-020\", \"rc\": 1}\n 523│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523966307, \"elapsed_s\": 222.96899999998277, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 128, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w...\n 524│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523966529, \"elapsed_s\": 223.18699999997625, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 128, \"exit\": 0, \"elapsed_ms\": 217.99999999348074}\n*525│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523966529, \"elapsed_s\": 223.18699999997625, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523966515, \"net_enabled\": true, \"net_canary_age_ms\": 15, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 1}\n 526│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523967530, \"elapsed_s\": 224.18699999997625, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 129, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w...\n 527│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523967699, \"elapsed_s\": 224.35899999999674, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 129, \"exit\": 0, \"elapsed_ms\": 172.0000000204891}\n*528│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523967699, \"elapsed_s\": 224.35899999999674, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523967677, \"net_enabled\": true, \"net_canary_age_ms\": 2, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 2}\n*529│{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523967788, \"elapsed_s\": 224.4529999999795, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-restored-022\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"owne...\n*530│{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523967788, \"elapsed_s\": 224.4529999999795, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-restored-022\", \"rc\": 1}\n 531│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523968789, \"elapsed_s\": 225.4529999999795, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 130, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n 532│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523968928, \"elapsed_s\": 225.59399999998277, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 130, \"exit\": 0, \"elapsed_ms\": 125.0}\n*533│{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523968928, \"elapsed_s\": 225.59399999998277, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523968920, \"net_enabled\": true, \"net_canary_age_ms\": 19, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 534│{\"event\": \"COMMAND_START\", \"at_ms\": 1789523969928, \"elapsed_s\": 226.59399999998277, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 131, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w...\n 535│{\"event\": \"COMMAND_END\", \"at_ms\": 1789523970210, \"elapsed_s\": 226.875, \"phase\": \"restored\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 131, \"exit\": 0, \"elapsed_ms\": 281.00000001722947}","truncation":{"content":" 13|{\"event\": \"COMMAND_START\", \"at_ms\": 1789523752479, \"elapsed_s\": 9.139999999955762, \"phase\": \"startup\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 3, \"argv\": [\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\", \"endpoint\", \"start\", \"w1crig\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n*14|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523754022, \"elapsed_s\": 10.686999999976251, \"phase\": \"startup\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 3, \"exit\": 0, \"elapsed_ms\": 1547.000000020489}\n 15|{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523755435, \"elapsed_s\": 12.09399999998277, \"phase\": \"startup\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc attach\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"owned_handle_pid\": 39...\n 16|{\"event\": \"OWNED_PROCESS\", \"at_ms\": 1789523756024, \"elapsed_s\": 12.686999999976251, \"phase\": \"startup\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"pid\": 58116, \"birth\": 1789523755.8826158, \"exe\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\", \"ppid\": 6180, \"role\": \"rc-1\", \"ancestors\": [6180, 45312, 46812, 55908, 26356, 30608, 35552]}\n 17|{\"event\": \"COMMAND_START\", \"at_ms\": 1789523756226, \"elapsed_s\": 12.889999999955762, \"phase\": \"startup\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 4, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n*18|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523756502, \"elapsed_s\": 13.155999999959022, \"phase\": \"startup\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 4, \"exit\": 0, \"elapsed_ms\": 266.00000000325963}\n*19|{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523756502, \"elapsed_s\": 13.155999999959022, \"phase\": \"startup\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523756487, \"net_enabled\": true, \"net_canary_age_ms\": 11, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 2}\n*20|{\"event\": \"PHASE_START\", \"at_ms\": 1789523756502, \"elapsed_s\": 13.155999999959022, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"requested_s\": 45}\n*21|{\"event\": \"COMMAND_START\", \"at_ms\": 1789523756502, \"elapsed_s\": 13.155999999959022, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 5, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n 22|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523756576, \"elapsed_s\": 13.23399999999674, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 5, \"exit\": 0, \"elapsed_ms\": 78.00000003771856}\n*23|{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523756576, \"elapsed_s\": 13.23399999999674, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523756566, \"net_enabled\": true, \"net_canary_age_ms\": 15, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 24|{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523756904, \"elapsed_s\": 13.561999999976251, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-baseline-000\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"own...\n*25|{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523756904, \"elapsed_s\": 13.561999999976251, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-baseline-000\", \"rc\": 1}\n 26|{\"event\": \"COMMAND_START\", \"at_ms\": 1789523757905, \"elapsed_s\": 14.561999999976251, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 6, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n 27|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523758214, \"elapsed_s\": 14.875, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 6, \"exit\": 0, \"elapsed_ms\": 313.0000000237487}\n*28|{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523758214, \"elapsed_s\": 14.875, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523758203, \"net_enabled\": true, \"net_canary_age_ms\": 2, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 1}\n 29|{\"event\": \"COMMAND_START\", \"at_ms\": 1789523759215, \"elapsed_s\": 15.875, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 7, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n 30|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523759688, \"elapsed_s\": 16.34399999998277, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 7, \"exit\": 0, \"elapsed_ms\": 468.99999998277053}\n*31|{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523759688, \"elapsed_s\": 16.34399999998277, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523759681, \"net_enabled\": true, \"net_canary_age_ms\": 5, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 32|{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523760591, \"elapsed_s\": 17.25, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-baseline-002\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"owned_handle_pid...\n*33|{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523760591, \"elapsed_s\": 17.25, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-baseline-002\", \"rc\": 1}\n 34|{\"event\": \"COMMAND_START\", \"at_ms\": 1789523761592, \"elapsed_s\": 18.25, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 8, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n 35|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523761823, \"elapsed_s\": 18.48399999999674, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 8, \"exit\": 0, \"elapsed_ms\": 233.99999999674037}\n*36|{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523761823, \"elapsed_s\": 18.48399999999674, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523761815, \"net_enabled\": true, \"net_canary_age_ms\": 14, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 37|{\"event\": \"COMMAND_START\", \"at_ms\": 1789523762824, \"elapsed_s\": 19.48399999999674, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 9, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n 38|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523762981, \"elapsed_s\": 19.639999999955762, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 9, \"exit\": 0, \"elapsed_ms\": 155.9999999590218}\n*39|{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523762981, \"elapsed_s\": 19.639999999955762, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523762972, \"net_enabled\": true, \"net_canary_age_ms\": 21, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 40|{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523763112, \"elapsed_s\": 19.764999999955762, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-baseline-004\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"own...\n*41|{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523763113, \"elapsed_s\": 19.764999999955762, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-baseline-004\", \"rc\": 1}\n 42|{\"event\": \"COMMAND_START\", \"at_ms\": 1789523764113, \"elapsed_s\": 20.764999999955762, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 10, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n*43|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523764250, \"elapsed_s\": 20.905999999959022, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 10, \"exit\": 0, \"elapsed_ms\": 141.00000000325963}\n*44|{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523764250, \"elapsed_s\": 20.905999999959022, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523764241, \"net_enabled\": true, \"net_canary_age_ms\": 13, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n*45|{\"event\": \"COMMAND_START\", \"at_ms\": 1789523765250, \"elapsed_s\": 21.905999999959022, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 11, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n 46|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523766114, \"elapsed_s\": 22.764999999955762, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 11, \"exit\": 0, \"elapsed_ms\": 344.0000000409782}\n*47|{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523766115, \"elapsed_s\": 22.780999999959022, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523765586, \"net_enabled\": true, \"net_canary_age_ms\": 10, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 48|{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523766466, \"elapsed_s\": 23.125, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-baseline-006\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"owned_handle_pi...\n*49|{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523766466, \"elapsed_s\": 23.125, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-baseline-006\", \"rc\": 1}\n 50|{\"event\": \"COMMAND_START\", \"at_ms\": 1789523767467, \"elapsed_s\": 24.125, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 12, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n 51|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523768192, \"elapsed_s\": 24.84399999998277, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 12, \"exit\": 0, \"elapsed_ms\": 718.9999999827705}\n*52|{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523768192, \"elapsed_s\": 24.84399999998277, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523768186, \"net_enabled\": true, \"net_canary_age_ms\": 9, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 53|{\"event\": \"COMMAND_START\", \"at_ms\": 1789523769193, \"elapsed_s\": 25.85899999999674, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 13, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n 54|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523770386, \"elapsed_s\": 27.04699999996228, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 13, \"exit\": 0, \"elapsed_ms\": 1187.999999965541}\n*55|{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523770386, \"elapsed_s\": 27.04699999996228, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523770381, \"net_enabled\": true, \"net_canary_age_ms\": 5, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 56|{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523771266, \"elapsed_s\": 27.92199999996228, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-baseline-008\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"owne...\n*57|{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523771266, \"elapsed_s\": 27.92199999996228, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-baseline-008\", \"rc\": 1}\n 58|{\"event\": \"COMMAND_START\", \"at_ms\": 1789523772266, \"elapsed_s\": 28.92199999996228, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 14, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n 59|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523772644, \"elapsed_s\": 29.29699999996228, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 14, \"exit\": 0, \"elapsed_ms\": 375.0}\n*60|{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523772644, \"elapsed_s\": 29.29699999996228, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523772622, \"net_enabled\": true, \"net_canary_age_ms\": 22, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 1}\n 61|{\"event\": \"COMMAND_START\", \"at_ms\": 1789523773645, \"elapsed_s\": 30.29699999996228, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 15, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n 62|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523773688, \"elapsed_s\": 30.34399999998277, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 15, \"exit\": 0, \"elapsed_ms\": 47.0000000204891}\n*63|{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523773688, \"elapsed_s\": 30.34399999998277, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523773682, \"net_enabled\": true, \"net_canary_age_ms\": 5, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n*64|{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523774121, \"elapsed_s\": 30.780999999959022, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-baseline-010\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"own...\n*65|{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523774121, \"elapsed_s\": 30.780999999959022, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-baseline-010\", \"rc\": 1}\n*66|{\"event\": \"COMMAND_START\", \"at_ms\": 1789523775122, \"elapsed_s\": 31.780999999959022, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 16, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n 67|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523775609, \"elapsed_s\": 32.26499999995576, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 16, \"exit\": 0, \"elapsed_ms\": 483.99999999674037}\n*68|{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523775609, \"elapsed_s\": 32.26499999995576, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523775601, \"net_enabled\": true, \"net_canary_age_ms\": 0, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 69|{\"event\": \"COMMAND_START\", \"at_ms\": 1789523776610, \"elapsed_s\": 33.26499999995576, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 17, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n 70|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523776763, \"elapsed_s\": 33.42199999996228, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 17, \"exit\": 0, \"elapsed_ms\": 157.00000000651926}\n*71|{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523776763, \"elapsed_s\": 33.42199999996228, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523776758, \"net_enabled\": true, \"net_canary_age_ms\": 8, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 72|{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523777051, \"elapsed_s\": 33.70299999997951, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-baseline-012\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"owne...\n*73|{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523777051, \"elapsed_s\": 33.70299999997951, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-baseline-012\", \"rc\": 1}\n 74|{\"event\": \"COMMAND_START\", \"at_ms\": 1789523778051, \"elapsed_s\": 34.70299999997951, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 18, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n 75|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523778961, \"elapsed_s\": 35.625, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 18, \"exit\": 0, \"elapsed_ms\": 922.0000000204891}\n*76|{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523778961, \"elapsed_s\": 35.625, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523778956, \"net_enabled\": true, \"net_canary_age_ms\": 6, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 77|{\"event\": \"COMMAND_START\", \"at_ms\": 1789523779963, \"elapsed_s\": 36.625, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 19, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n 78|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523783935, \"elapsed_s\": 40.59399999998277, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 19, \"exit\": 0, \"elapsed_ms\": 3968.9999999827705}\n*79|{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523783936, \"elapsed_s\": 40.59399999998277, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523783925, \"net_enabled\": true, \"net_canary_age_ms\": 24, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 1}\n 80|{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523784371, \"elapsed_s\": 41.03099999995902, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-baseline-014\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"owne...\n*81|{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523784371, \"elapsed_s\": 41.03099999995902, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-baseline-014\", \"rc\": 1}\n 82|{\"event\": \"COMMAND_START\", \"at_ms\": 1789523785380, \"elapsed_s\": 42.03099999995902, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 20, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n 83|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523785798, \"elapsed_s\": 42.45299999997951, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 20, \"exit\": 0, \"elapsed_ms\": 422.0000000204891}\n*84|{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523785798, \"elapsed_s\": 42.45299999997951, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523785780, \"net_enabled\": true, \"net_canary_age_ms\": 4, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 1}\n 85|{\"event\": \"COMMAND_START\", \"at_ms\": 1789523786798, \"elapsed_s\": 43.45299999997951, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 21, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n 86|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523787134, \"elapsed_s\": 43.79699999996228, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 21, \"exit\": 0, \"elapsed_ms\": 343.99999998277053}\n*87|{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523787134, \"elapsed_s\": 43.79699999996228, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523787127, \"net_enabled\": true, \"net_canary_age_ms\": 2, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 88|{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523787527, \"elapsed_s\": 44.18699999997625, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-baseline-016\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"owne...\n*89|{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523787527, \"elapsed_s\": 44.18699999997625, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-baseline-016\", \"rc\": 1}\n 90|{\"event\": \"COMMAND_START\", \"at_ms\": 1789523788527, \"elapsed_s\": 45.18699999997625, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 22, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n 91|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523788731, \"elapsed_s\": 45.38999999995576, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 22, \"exit\": 0, \"elapsed_ms\": 202.9999999795109}\n*92|{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523788731, \"elapsed_s\": 45.38999999995576, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523788724, \"net_enabled\": true, \"net_canary_age_ms\": 22, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 93|{\"event\": \"COMMAND_START\", \"at_ms\": 1789523789732, \"elapsed_s\": 46.38999999995576, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 23, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n 94|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523790682, \"elapsed_s\": 47.34399999998277, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 23, \"exit\": 0, \"elapsed_ms\": 954.0000000270084}\n*95|{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523790682, \"elapsed_s\": 47.34399999998277, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523790675, \"net_enabled\": true, \"net_canary_age_ms\": 24, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 96|{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523791290, \"elapsed_s\": 47.95299999997951, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-baseline-018\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"owne...\n*97|{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523791290, \"elapsed_s\": 47.95299999997951, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-baseline-018\", \"rc\": 1}\n 98|{\"event\": \"COMMAND_START\", \"at_ms\": 1789523792291, \"elapsed_s\": 48.95299999997951, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 24, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n 99|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523793899, \"elapsed_s\": 50.56199999997625, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 24, \"exit\": 0, \"elapsed_ms\": 1608.9999999967404}\n*100|{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523793900, \"elapsed_s\": 50.56199999997625, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523793865, \"net_enabled\": true, \"net_canary_age_ms\": 14, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 14}\n 101|{\"event\": \"COMMAND_START\", \"at_ms\": 1789523794900, \"elapsed_s\": 51.56199999997625, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 25, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n 102|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523795202, \"elapsed_s\": 51.85899999999674, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 25, \"exit\": 0, \"elapsed_ms\": 297.0000000204891}\n*103|{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523795202, \"elapsed_s\": 51.85899999999674, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523795193, \"net_enabled\": true, \"net_canary_age_ms\": 17, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 1}\n 104|{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523795664, \"elapsed_s\": 52.32799999997951, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-baseline-020\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"owne...\n*105|{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523795664, \"elapsed_s\": 52.32799999997951, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-baseline-020\", \"rc\": 1}\n 106|{\"event\": \"COMMAND_START\", \"at_ms\": 1789523796665, \"elapsed_s\": 53.32799999997951, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 26, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n 107|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523796945, \"elapsed_s\": 53.60899999999674, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 26, \"exit\": 0, \"elapsed_ms\": 281.00000001722947}\n*108|{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523796945, \"elapsed_s\": 53.60899999999674, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523796934, \"net_enabled\": true, \"net_canary_age_ms\": 8, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 109|{\"event\": \"COMMAND_START\", \"at_ms\": 1789523797946, \"elapsed_s\": 54.60899999999674, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 27, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\"}\n 110|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523799031, \"elapsed_s\": 55.68699999997625, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 27, \"exit\": 0, \"elapsed_ms\": 1077.999999979511}\n*111|{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523799031, \"elapsed_s\": 55.68699999997625, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523799025, \"net_enabled\": true, \"net_canary_age_ms\": 24, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n*112|{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523800503, \"elapsed_s\": 57.15599999995902, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-baseline-022\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"owne...\n*113|{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523800503, \"elapsed_s\": 57.15599999995902, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-baseline-022\", \"rc\": 1}\n 114|{\"event\": \"PHASE_END\", \"at_ms\": 1789523801504, \"elapsed_s\": 58.15599999995902, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"requested_s\": 45, \"actual_s\": 45.0, \"truncated\": false}\n 115|{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523802030, \"elapsed_s\": 58.68699999997625, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"backup and set isolated cadence\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}},...\n 116|{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523802481, \"elapsed_s\": 59.13999999995576, \"phase\": \"baseline\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"node refresh\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": 39904}}, \"owned_handle_pid\"...\n...\n 121|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523802610, \"elapsed_s\": 59.26499999995576, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 29, \"exit\": 0, \"elapsed_ms\": 61.999999976251274}\n*122|{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523802610, \"elapsed_s\": 59.26499999995576, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523802605, \"net_enabled\": true, \"net_canary_age_ms\": 4, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 123|{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523802757, \"elapsed_s\": 59.42199999996228, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-cadence-priming-000\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": ...\n*124|{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523802757, \"elapsed_s\": 59.42199999996228, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-cadence-priming-000\", \"rc\": 1}\n 125|{\"event\": \"COMMAND_START\", \"at_ms\": 1789523803758, \"elapsed_s\": 60.42199999996228, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 30, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\h...\n 126|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523803798, \"elapsed_s\": 60.45299999997951, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 30, \"exit\": 0, \"elapsed_ms\": 31.000000017229468}\n*127|{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523803798, \"elapsed_s\": 60.45299999997951, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523803794, \"net_enabled\": true, \"net_canary_age_ms\": 18, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 128|{\"event\": \"COMMAND_START\", \"at_ms\": 1789523804800, \"elapsed_s\": 61.45299999997951, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 31, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\h...\n 129|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523804957, \"elapsed_s\": 61.60899999999674, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 31, \"exit\": 0, \"elapsed_ms\": 156.00000001722947}\n*130|{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523804957, \"elapsed_s\": 61.60899999999674, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523804941, \"net_enabled\": true, \"net_canary_age_ms\": 15, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 5}\n 131|{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523805269, \"elapsed_s\": 61.92199999996228, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-cadence-priming-002\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": ...\n*132|{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523805269, \"elapsed_s\": 61.92199999996228, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-cadence-priming-002\", \"rc\": 1}\n 133|{\"event\": \"COMMAND_START\", \"at_ms\": 1789523806270, \"elapsed_s\": 62.92199999996228, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 32, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\h...\n 134|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523806507, \"elapsed_s\": 63.17199999996228, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 32, \"exit\": 0, \"elapsed_ms\": 250.0}\n*135|{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523806507, \"elapsed_s\": 63.17199999996228, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523806499, \"net_enabled\": true, \"net_canary_age_ms\": 23, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 136|{\"event\": \"COMMAND_START\", \"at_ms\": 1789523807507, \"elapsed_s\": 64.17199999996228, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 33, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\h...\n 137|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523807739, \"elapsed_s\": 64.38999999995576, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 33, \"exit\": 0, \"elapsed_ms\": 217.99999999348074}\n*138|{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523807739, \"elapsed_s\": 64.38999999995576, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523807721, \"net_enabled\": true, \"net_canary_age_ms\": 19, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 139|{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523808108, \"elapsed_s\": 64.76499999995576, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-cadence-priming-004\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": ...\n*140|{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523808108, \"elapsed_s\": 64.76499999995576, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-cadence-priming-004\", \"rc\": 1}\n 141|{\"event\": \"COMMAND_START\", \"at_ms\": 1789523809108, \"elapsed_s\": 65.76499999995576, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 34, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\h...\n 142|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523809185, \"elapsed_s\": 65.84399999998277, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 34, \"exit\": 0, \"elapsed_ms\": 79.00000002700835}\n*143|{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523809185, \"elapsed_s\": 65.84399999998277, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523809180, \"net_enabled\": true, \"net_canary_age_ms\": 4, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 144|{\"event\": \"COMMAND_START\", \"at_ms\": 1789523810186, \"elapsed_s\": 66.84399999998277, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 35, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\h...\n 145|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523810588, \"elapsed_s\": 67.25, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 35, \"exit\": 0, \"elapsed_ms\": 406.00000001722947}\n*146|{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523810588, \"elapsed_s\": 67.25, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523810583, \"net_enabled\": true, \"net_canary_age_ms\": 7, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 147|{\"event\": \"MUTATION_GUARD\", \"at_ms\": 1789523810876, \"elapsed_s\": 67.53099999995902, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"reason\": \"rc input TAG-cadence-priming-006\", \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\home-w1c\", \"broker_pid\": 39904, \"birth\": 1789523746.8315127, \"endpoints\": {\"spt-daemon-broker-573ad82e70ef3afe.sock\": {\"pid\": 39904}, \"spt-daemon-seed-573ad82e70ef3afe.sock\": {\"pid\": ...\n*148|{\"event\": \"INPUT_SENT\", \"at_ms\": 1789523810876, \"elapsed_s\": 67.53099999995902, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"tag\": \"TAG-cadence-priming-006\", \"rc\": 1}\n 149|{\"event\": \"COMMAND_START\", \"at_ms\": 1789523811876, \"elapsed_s\": 68.53099999995902, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 36, \"argv\": [\"C:\\\\WINDOWS\\\\system32\\\\cmd.exe\", \"/d\", \"/c\", \"set SPT_RC_HITCH_DIAG=1&& \\\"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\bin\\\\spt.exe\\\" node status --json\"], \"home\": \"C:\\\\Users\\\\decid\\\\Documents\\\\projects\\\\spt-core\\\\.spt\\\\preserved\\\\307\\\\hertz-w1bc\\\\w1c-run1\\\\h...\n 150|{\"event\": \"COMMAND_END\", \"at_ms\": 1789523813010, \"elapsed_s\": 69.67199999996228, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"command\": 36, \"exit\": 0, \"elapsed_ms\": 1141.0000000032596}\n*151|{\"event\": \"HITCH_PROBE\", \"at_ms\": 1789523813010, \"elapsed_s\": 69.67199999996228, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"valid\": true, \"exit\": 0, \"diagnostic\": \"rc-hitch\", \"broker_pid\": 39904, \"broker_version\": \"0.70.0\", \"sampled_at_ms\": 1789523813004, \"net_enabled\": true, \"net_canary_age_ms\": 4, \"active_dial_tasks\": 0, \"query_elapsed_ms\": 0}\n 152|{\"event\": \"PHASE_END\", \"at_ms\": 1789523813010, \"elapsed_s\": 69.67199999996228, \"phase\": \"cadence-priming\", \"box\": \"HFENDULEAM\", \"route\": \"hfenduleam-isolated-native-local\", \"requested_s\": 10, \"actual_s\": 10.46899999998277, \"truncated\": false}","truncated":true,"truncatedBy":"bytes","totalLines":516,"totalBytes":194876,"outputLines":137,"outputBytes":51101,"lastLinePartial":false,"firstLineExceedsLimit":false},"linesTruncated":true,"meta":{"limits":{"columnTruncated":{"maxColumn":512}},"truncation":{"direction":"head","truncatedBy":"bytes","totalLines":516,"totalBytes":194876,"outputLines":137,"outputBytes":51101,"shownRange":{"start":1,"end":137},"nextOffset":138}}},"isError":false,"timestamp":1789524055140}}
{"type":"message","id":"4ccb73c8","parentId":"4477effc","timestamp":"2026-09-16T02:00:55.161Z","message":{"role":"toolResult","toolCallId":"call_gfFePTfwuk8glhzxvsd5uoIL|fc_09b01b5279447709016aa9f8570d2c87d2babf790e016b9835","toolName":"read","content":[{"type":"text","text":"#[test]\nfn opener_evicted_active_stream_resumes_after_dispatcher_restart() {\n    let _home = init_home();\n    // Shrink the ring BEFORE the broker starts (read once at NetShared::new).\n    // nextest = one process per test: no cross-test env bleed.\n    std::env::set_var(\"SPT_STREAM_RING_CHUNKS\", \"8\");\n    let dir = tempfile::tempdir().expect(\"tempdir\");\n    let (name_a, name_b) = (unique_name(), unique_name());\n    let _broker_a = net_broker(&name_a, &dir.path().join(\"a\"));\n    let _broker_b = net_broker(&name_b, &dir.path().join(\"b\"));\n\n    let mut probe = connect_retry(&name_a);\n    let sid = probe\n        .spawn_session(echo_spawn_req(\"rd2-ep\"))\n        .expect(\"spawn echo child\");\n    let a_addr = probe.net_status().expect(\"a status\").addr;\n\n    let gen1 = Generation::spawn(&name_a, dir.path().join(\"gen1.log\"), &[]);\n\n    let mut operator = connect_retry(&name_b);\n    let conn = operator\n        .net_dial(a_addr, Some(MintedOp::new(Minter::Cli, 1)))\n        .expect(\"dial\");\n    let s1 = request_attach(\n        &mut operator,\n        conn.conn_id,\n        sid,\n        0,\n        MintedOp::new(Minter::Rc, 2),\n        AttachIntent::Control,\n    )\n    .expect(\"request\");\n    operator.net_stream_subscribe(s1, 0).expect(\"subscribe\");\n    send_attach_input(&mut operator, s1, b\"MARK-A\\r\", 10).expect(\"input pre\");\n    let mut dec = AttachDecoder::new();\n    let (mut cur, mut view) = (0u64, Vec::new());\n    render_until(\n        &mut operator,\n        s1,\n        &mut dec,\n        &mut cur,\n        &mut view,\n        b\"MARK-A\",\n        Duration::from_secs(20),\n    );\n    let s1_a = *peer_stream_ids(&mut probe).first().expect(\"s1 row on A\");\n\n    // Roll the opener out of the (8-chunk) ring: enough spaced input records\n    // that the floor advances past seq 0.\n    for i in 0..40u64 {\n        send_attach_input(&mut operator, s1, format!(\"f{i}\\r\").as_bytes(), 20 + i)\n            .expect(\"flood input\");\n        thread::sleep(Duration::from_millis(10));\n    }\n    let end = Instant::now() + Duration::from_secs(20);\n    loop {\n        let rolled = probe\n            .net_streams()\n            .expect(\"net-streams\")\n            .streams\n            .iter()\n            .any(|s| s.stream_id == s1_a && s.floor_seq > 0);\n        if rolled {\n            break;\n        }\n        assert!(\n            Instant::now() < end,\n            \"the ring never rolled past the opener\"\n        );\n        thread::sleep(Duration::from_millis(50));\n    }\n    // The durable fact is still there — this is what gen2 will classify from.\n    let pinned = probe.net_stream_opener(s1_a).expect(\"opener query answers\");\n    assert!(\n        pinned.is_some(),\n        \"the opener stays pinned across the ring roll\"\n    );\n\n    // Restart the dispatcher generation; recovery must classify from the\n    // pinned opener (ring seq 0 is GONE) and resume THIS operator stream.\n    gen1.kill();\n    let gen2 = Generation::spawn(&name_a, dir.path().join(\"gen2.log\"), &[]);\n\n    send_attach_input(&mut operator, s1, b\"MARK-B\\r\", 100).expect(\"input post\");\n    let saw_eof = render_until(\n        &mut operator,\n        s1,\n        &mut dec,\n        &mut cur,\n        &mut view,\n        b\"MARK-B\",\n        Duration::from_secs(30),\n    );\n    assert!(!saw_eof, \"the resumed stream must not be torn down\");\n    let gen2_log = gen2.stderr_log();\n    assert!(\n        !gen2_log.contains(&format!(\"DISPATCH:{s1_a}:Unknown\")),\n        \"gen2 classified the rolled-opener stream Unknown — durable classification failed: {gen2_log}\"\n    );\n\n    gen2.kill();\n    let _ = probe.kill_session();\n}\n\n\n[Showing lines 578-681 of 747. Use :682 to continue]"}],"details":{"truncation":{"content":"#[test]\r\nfn opener_evicted_active_stream_resumes_after_dispatcher_restart() {\r\n    let _home = init_home();\r\n    // Shrink the ring BEFORE the broker starts (read once at NetShared::new).\r\n    // nextest = one process per test: no cross-test env bleed.\r\n    std::env::set_var(\"SPT_STREAM_RING_CHUNKS\", \"8\");\r\n    let dir = tempfile::tempdir().expect(\"tempdir\");\r\n    let (name_a, name_b) = (unique_name(), unique_name());\r\n    let _broker_a = net_broker(&name_a, &dir.path().join(\"a\"));\r\n    let _broker_b = net_broker(&name_b, &dir.path().join(\"b\"));\r\n\r\n    let mut probe = connect_retry(&name_a);\r\n    let sid = probe\r\n        .spawn_session(echo_spawn_req(\"rd2-ep\"))\r\n        .expect(\"spawn echo child\");\r\n    let a_addr = probe.net_status().expect(\"a status\").addr;\r\n\r\n    let gen1 = Generation::spawn(&name_a, dir.path().join(\"gen1.log\"), &[]);\r\n\r\n    let mut operator = connect_retry(&name_b);\r\n    let conn = operator\r\n        .net_dial(a_addr, Some(MintedOp::new(Minter::Cli, 1)))\r\n        .expect(\"dial\");\r\n    let s1 = request_attach(\r\n        &mut operator,\r\n        conn.conn_id,\r\n        sid,\r\n        0,\r\n        MintedOp::new(Minter::Rc, 2),\r\n        AttachIntent::Control,\r\n    )\r\n    .expect(\"request\");\r\n    operator.net_stream_subscribe(s1, 0).expect(\"subscribe\");\r\n    send_attach_input(&mut operator, s1, b\"MARK-A\\r\", 10).expect(\"input pre\");\r\n    let mut dec = AttachDecoder::new();\r\n    let (mut cur, mut view) = (0u64, Vec::new());\r\n    render_until(\r\n        &mut operator,\r\n        s1,\r\n        &mut dec,\r\n        &mut cur,\r\n        &mut view,\r\n        b\"MARK-A\",\r\n        Duration::from_secs(20),\r\n    );\r\n    let s1_a = *peer_stream_ids(&mut probe).first().expect(\"s1 row on A\");\r\n\r\n    // Roll the opener out of the (8-chunk) ring: enough spaced input records\r\n    // that the floor advances past seq 0.\r\n    for i in 0..40u64 {\r\n        send_attach_input(&mut operator, s1, format!(\"f{i}\\r\").as_bytes(), 20 + i)\r\n            .expect(\"flood input\");\r\n        thread::sleep(Duration::from_millis(10));\r\n    }\r\n    let end = Instant::now() + Duration::from_secs(20);\r\n    loop {\r\n        let rolled = probe\r\n            .net_streams()\r\n            .expect(\"net-streams\")\r\n            .streams\r\n            .iter()\r\n            .any(|s| s.stream_id == s1_a && s.floor_seq > 0);\r\n        if rolled {\r\n            break;\r\n        }\r\n        assert!(\r\n            Instant::now() < end,\r\n            \"the ring never rolled past the opener\"\r\n        );\r\n        thread::sleep(Duration::from_millis(50));\r\n    }\r\n    // The durable fact is still there — this is what gen2 will classify from.\r\n    let pinned = probe.net_stream_opener(s1_a).expect(\"opener query answers\");\r\n    assert!(\r\n        pinned.is_some(),\r\n        \"the opener stays pinned across the ring roll\"\r\n    );\r\n\r\n    // Restart the dispatcher generation; recovery must classify from the\r\n    // pinned opener (ring seq 0 is GONE) and resume THIS operator stream.\r\n    gen1.kill();\r\n    let gen2 = Generation::spawn(&name_a, dir.path().join(\"gen2.log\"), &[]);\r\n\r\n    send_attach_input(&mut operator, s1, b\"MARK-B\\r\", 100).expect(\"input post\");\r\n    let saw_eof = render_until(\r\n        &mut operator,\r\n        s1,\r\n        &mut dec,\r\n        &mut cur,\r\n        &mut view,\r\n        b\"MARK-B\",\r\n        Duration::from_secs(30),\r\n    );\r\n    assert!(!saw_eof, \"the resumed stream must not be torn down\");\r\n    let gen2_log = gen2.stderr_log();\r\n    assert!(\r\n        !gen2_log.contains(&format!(\"DISPATCH:{s1_a}:Unknown\")),\r\n        \"gen2 classified the rolled-opener stream Unknown — durable classification failed: {gen2_log}\"\r\n    );\r\n\r\n    gen2.kill();\r\n    let _ = probe.kill_session();\r\n}\r\n\r","truncated":true,"truncatedBy":"lines","totalLines":170,"totalBytes":3683,"outputLines":104,"outputBytes":3683,"lastLinePartial":false,"firstLineExceedsLimit":false},"totalLines":747,"displayContent":{"text":"#[test]\r\nfn opener_evicted_active_stream_resumes_after_dispatcher_restart() {\r\n    let _home = init_home();\r\n    // Shrink the ring BEFORE the broker starts (read once at NetShared::new).\r\n    // nextest = one process per test: no cross-test env bleed.\r\n    std::env::set_var(\"SPT_STREAM_RING_CHUNKS\", \"8\");\r\n    let dir = tempfile::tempdir().expect(\"tempdir\");\r\n    let (name_a, name_b) = (unique_name(), unique_name());\r\n    let _broker_a = net_broker(&name_a, &dir.path().join(\"a\"));\r\n    let _broker_b = net_broker(&name_b, &dir.path().join(\"b\"));\r\n\r\n    let mut probe = connect_retry(&name_a);\r\n    let sid = probe\r\n        .spawn_session(echo_spawn_req(\"rd2-ep\"))\r\n        .expect(\"spawn echo child\");\r\n    let a_addr = probe.net_status().expect(\"a status\").addr;\r\n\r\n    let gen1 = Generation::spawn(&name_a, dir.path().join(\"gen1.log\"), &[]);\r\n\r\n    let mut operator = connect_retry(&name_b);\r\n    let conn = operator\r\n        .net_dial(a_addr, Some(MintedOp::new(Minter::Cli, 1)))\r\n        .expect(\"dial\");\r\n    let s1 = request_attach(\r\n        &mut operator,\r\n        conn.conn_id,\r\n        sid,\r\n        0,\r\n        MintedOp::new(Minter::Rc, 2),\r\n        AttachIntent::Control,\r\n    )\r\n    .expect(\"request\");\r\n    operator.net_stream_subscribe(s1, 0).expect(\"subscribe\");\r\n    send_attach_input(&mut operator, s1, b\"MARK-A\\r\", 10).expect(\"input pre\");\r\n    let mut dec = AttachDecoder::new();\r\n    let (mut cur, mut view) = (0u64, Vec::new());\r\n    render_until(\r\n        &mut operator,\r\n        s1,\r\n        &mut dec,\r\n        &mut cur,\r\n        &mut view,\r\n        b\"MARK-A\",\r\n        Duration::from_secs(20),\r\n    );\r\n    let s1_a = *peer_stream_ids(&mut probe).first().expect(\"s1 row on A\");\r\n\r\n    // Roll the opener out of the (8-chunk) ring: enough spaced input records\r\n    // that the floor advances past seq 0.\r\n    for i in 0..40u64 {\r\n        send_attach_input(&mut operator, s1, format!(\"f{i}\\r\").as_bytes(), 20 + i)\r\n            .expect(\"flood input\");\r\n        thread::sleep(Duration::from_millis(10));\r\n    }\r\n    let end = Instant::now() + Duration::from_secs(20);\r\n    loop {\r\n        let rolled = probe\r\n            .net_streams()\r\n            .expect(\"net-streams\")\r\n            .streams\r\n            .iter()\r\n            .any(|s| s.stream_id == s1_a && s.floor_seq > 0);\r\n        if rolled {\r\n            break;\r\n        }\r\n        assert!(\r\n            Instant::now() < end,\r\n            \"the ring never rolled past the opener\"\r\n        );\r\n        thread::sleep(Duration::from_millis(50));\r\n    }\r\n    // The durable fact is still there — this is what gen2 will classify from.\r\n    let pinned = probe.net_stream_opener(s1_a).expect(\"opener query answers\");\r\n    assert!(\r\n        pinned.is_some(),\r\n        \"the opener stays pinned across the ring roll\"\r\n    );\r\n\r\n    // Restart the dispatcher generation; recovery must classify from the\r\n    // pinned opener (ring seq 0 is GONE) and resume THIS operator stream.\r\n    gen1.kill();\r\n    let gen2 = Generation::spawn(&name_a, dir.path().join(\"gen2.log\"), &[]);\r\n\r\n    send_attach_input(&mut operator, s1, b\"MARK-B\\r\", 100).expect(\"input post\");\r\n    let saw_eof = render_until(\r\n        &mut operator,\r\n        s1,\r\n        &mut dec,\r\n        &mut cur,\r\n        &mut view,\r\n        b\"MARK-B\",\r\n        Duration::from_secs(30),\r\n    );\r\n    assert!(!saw_eof, \"the resumed stream must not be torn down\");\r\n    let gen2_log = gen2.stderr_log();\r\n    assert!(\r\n        !gen2_log.contains(&format!(\"DISPATCH:{s1_a}:Unknown\")),\r\n        \"gen2 classified the rolled-opener stream Unknown — durable classification failed: {gen2_log}\"\r\n    );\r\n\r\n    gen2.kill();\r\n    let _ = probe.kill_session();\r\n}\r\n\r","startLine":578,"lineNumbers":[578,579,580,581,582,583,584,585,586,587,588,589,590,591,592,593,594,595,596,597,598,599,600,601,602,603,604,605,606,607,608,609,610,611,612,613,614,615,616,617,618,619,620,621,622,623,624,625,626,627,628,629,630,631,632,633,634,635,636,637,638,639,640,641,642,643,644,645,646,647,648,649,650,651,652,653,654,655,656,657,658,659,660,661,662,663,664,665,666,667,668,669,670,671,672,673,674,675,676,677,678,679,680,681]},"fileSize":28348,"meta":{"source":{"type":"path","value":"C:\\Users\\decid\\Documents\\projects\\spt-core\\crates\\spt-daemon\\tests\\redispatch.rs"},"truncation":{"direction":"head","truncatedBy":"lines","totalLines":747,"totalBytes":3683,"outputLines":104,"outputBytes":3683,"shownRange":{"start":578,"end":681},"nextOffset":682}}},"isError":false,"timestamp":1789524055160}}
{"type":"message","id":"3ae345f5","parentId":"4ccb73c8","timestamp":"2026-09-16T02:00:55.184Z","message":{"role":"toolResult","toolCallId":"call_mpg4WB9jh7DAN279J5eGBn7L|fc_09b01b5279447709016aa9f8570d1887d28bb07b9d6809effe","toolName":"read","content":[{"type":"text","text":"Note: interpreted as 1 paths: crates/spt-daemon/tests/attach.rs:867-1032\n\n#[test]\nfn attach_survives_target_brain_restart_exactly_once() {\n    let _home = init_home();\n    let dir = tempfile::tempdir().expect(\"tempdir\");\n    let (name_a, name_b) = (unique_name(), unique_name());\n    let _broker_a = net_broker(&name_a, &dir.path().join(\"a\"));\n    let _broker_b = net_broker(&name_b, &dir.path().join(\"b\"));\n\n    // Target A life 1: spawn the child; operator B dials + requests + types.\n    let mut life1 = connect_retry(&name_a);\n    let sid = life1\n        .spawn_session(echo_spawn_req())\n        .expect(\"spawn echo child\");\n    let a_addr = life1.net_status().expect(\"a status\").addr;\n\n    let mut operator = connect_retry(&name_b);\n    let conn = operator\n        .net_dial(a_addr, Some(MintedOp::new(Minter::Cli, 1)))\n        .expect(\"dial\");\n    let stream_b = request_attach(\n        &mut operator,\n        conn.conn_id,\n        sid,\n        0,\n        MintedOp::new(Minter::Rc, 2),\n        AttachIntent::Control,\n    )\n    .expect(\"request\");\n    operator\n        .net_stream_subscribe(stream_b, 0)\n        .expect(\"operator subscribe\");\n    send_attach_input(&mut operator, stream_b, b\"MARKER_ONE\\r\", 10).expect(\"input 1\");\n\n    // Life 1 serves manually (the serve loop's exact steps, stepped so the\n    // crash point is deterministic): handle the Request + input, pump output\n    // records until MARKER_ONE went onto the wire — then die.\n    let (stream_a, origin) = wait_for_stream(&mut life1, &[]);\n    life1\n        .net_stream_subscribe(stream_a, 0)\n        .expect(\"life1 subscribe\");\n    let mut decoder = AttachDecoder::new();\n    let mut sent: Vec<u8> = Vec::new(); // bytes life 1 pumped onto the wire\n    let deadline = life1.call_deadline();\n    'life1: loop {\n        match life1.read_event_until(deadline).expect(\"life1 event\") {\n            BrokerEvent::NetStreamData {\n                stream_id, bytes, ..\n            } if stream_id == stream_a => {\n                for rec in decoder.push(&bytes) {\n                    match rec {\n                        AttachRecord::Request {\n                            session_id,\n                            from_seq,\n                            ..\n                        } => {\n                            life1.attach(session_id, from_seq).expect(\"attach\");\n                        }\n                        AttachRecord::Input { data_b64, op_id } => {\n                            let b = decode_bytes(&data_b64).expect(\"b64\");\n                            life1\n                                .send_effect(MintedOp::new(Minter::Rc, op_id), &b)\n                                .expect(\"journaled input\");\n                        }\n                        _ => {}\n                    }\n                }\n            }\n            BrokerEvent::Output { seq, bytes, .. } => {\n                let line = ndjson::encode_line(&AttachRecord::Output {\n                    seq,\n                    data_b64: spt_daemon::msg::encode_bytes(&bytes),\n                });\n                life1\n                    .net_stream_send(stream_a, &line, None, false)\n                    .expect(\"output send\");\n                sent.extend_from_slice(&bytes);\n                if count(&sent, b\"MARKER_ONE\") >= 1 {\n                    break 'life1; // crash with the marker on the wire\n                }\n            }\n            BrokerEvent::Error { message } => panic!(\"life1 broker error: {message}\"),\n            _ => {}\n        }\n    }\n    let state = life1.snapshot();\n    drop(life1); // the crash — broker A, session, stream, journal all survive\n\n    // Into the DEAD window: B types the second marker (buffered by A's broker).\n    send_attach_input(&mut operator, stream_b, b\"MARKER_TWO\\r\", 11).expect(\"input 2\");\n\n    // Life 2: handoff, then re-serve the SAME stream from seq 0 — the\n    // worst-case replay. serve_attach re-handles the replayed Request (gate +\n    // re-attach from 0, so every output record re-transmits — B's render\n    // cursor drops the duplicates), replays MARKER_ONE's input (PTY-write\n    // journal dedups op 10 — typed once), and pumps the dead window's\n    // MARKER_TWO.\n    let mut life2 = Brain::handoff(&name_a, state, 2).expect(\"handoff\");\n    let origin2 = origin.clone();\n    let serve_broker = name_a.clone();\n    let server = thread::spawn(move || {\n        let outcome = serve_attach(\n            &mut life2,\n            &serve_broker,\n            stream_a,\n            \"ling\",\n            &origin2,\n            0,\n            None,\n            None,\n        )\n            .expect(\"re-serve\");\n        (outcome, life2)\n    });\n\n    // B renders through the dead-window marker, then detaches.\n    let mut op_decoder = AttachDecoder::new();\n    let (mut cursor, mut viewport) = (0u64, Vec::new());\n    render_until(\n        &mut operator,\n        stream_b,\n        &mut op_decoder,\n        &mut cursor,\n        &mut viewport,\n        b\"MARKER_TWO\",\n    );\n    operator\n        .net_stream_send(stream_b, &[], None, true)\n        .expect(\"detach\");\n    let (outcome, mut life2) = server.join().expect(\"serve thread\");\n    assert_eq!(outcome, AttachServeOutcome::Detached);\n\n    // Exactly-once, stated against the SCREEN MODEL (#6 / ADR-0031). Attach no\n    // longer replays the raw ring — the broker synthesizes a clean current-screen\n    // repaint — so the old \"remote wire byte-identical to the raw local log\" proxy\n    // no longer holds (that raw replay is exactly what #6 removed). Instead we feed\n    // the operator's ENTIRE received byte stream (early live frames + the\n    // re-serve's repaint + the dead-window frames) through a `ScreenGrid` and assert\n    // the resulting authoritative screen still shows BOTH markers. The screen is the\n    // idempotent truth: a GAP from the restart/replay (a lost record) would leave a\n    // marker off the final screen. MARKER_ONE proves the pre-crash output survived\n    // the handoff + re-serve; MARKER_TWO proves the dead-window buffered input was\n    // delivered after life 2 took over. Rendering (vs a raw substring scan) is what\n    // makes this robust to the mid-stream repaint's clear/repaint bytes.\n    let mut screen = ScreenGrid::new(24, 80);\n    screen.advance(&viewport);\n    let painted = String::from_utf8_lossy(&screen.render_repaint()).into_owned();\n    assert!(\n        painted.contains(\"MARKER_ONE\"),\n        \"the operator's rendered screen still shows the pre-crash marker across the \\\n         brain restart (no gap in the re-served output): {painted:?}\"\n    );\n    assert!(\n        painted.contains(\"MARKER_TWO\"),\n        \"the operator's rendered screen shows the dead-window marker delivered after \\\n         the handoff (buffered input survived the restart): {painted:?}\"\n    );\n\n    // Ground truth: the session's OWN authoritative screen (a fresh local attach →\n    // repaint) also carries both markers exactly-once at the source.\n    life2.attach(sid, 0).expect(\"local ground-truth attach\");\n    let mut local: Vec<u8> = Vec::new();\n    life2\n        .read_output_until(b\"MARKER_TWO\", &mut local)\n        .expect(\"local replay\");\n    assert!(count(&local, b\"MARKER_ONE\") >= 1 && count(&local, b\"MARKER_TWO\") >= 1);\n\n    life2.kill_session().expect(\"cleanup kill\");\n}\n\n// [unit->REQ-REACH-1] remote-drive detection is a daemon fact: serving a\n\n[Showing lines 866-1035 of 2144. Use :1036 to continue]"}],"details":{"notes":["Note: interpreted as 1 paths: crates/spt-daemon/tests/attach.rs:867-1032"],"displayReadTargets":["crates/spt-daemon/tests/attach.rs:867-1032"]},"isError":false,"timestamp":1789524055184}}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_JEu3ffY9bhznIp19XeEXgwYK|fc_09b01b5279447709016aa9f862296887d2bae9a7cff14f5b85","toolName":"grep","startedAt":"2026-09-16T02:01:06.253Z","args":{"path":"crates/spt-net/src/net/attach.rs"},"intent":"Resolving decoder implementation alias"},"id":"70be85ec","parentId":"3ae345f5","timestamp":"2026-09-16T02:01:06.253Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_emckm2p6ptZoCR7ITEqnQ4eG|fc_09b01b5279447709016aa9f862297887d2be78e3ff909ff9a6","toolName":"read","startedAt":"2026-09-16T02:01:06.253Z","args":{"path":"crates/spt-daemon/src/attach.rs:880-919"},"intent":"Reading output forwarding gate"},"id":"822260df","parentId":"70be85ec","timestamp":"2026-09-16T02:01:06.253Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_dfbOVOdXtdaA80wgPeo2R39t|fc_09b01b5279447709016aa9f862297c87d2b0a526ae8273fdb0","toolName":"read","startedAt":"2026-09-16T02:01:06.254Z","args":{"path":"crates/spt-daemon/tests/attach.rs:547-655"},"intent":"Reading prepopulated test assertions"},"id":"31e7d475","parentId":"822260df","timestamp":"2026-09-16T02:01:06.254Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_50QbuaFk7ZR8FoX35taowHLz|fc_09b01b5279447709016aa9f862298487d292c616e28737b752","toolName":"read","startedAt":"2026-09-16T02:01:06.254Z","args":{"path":"crates/spt-daemon/src/broker.rs:3170-3250"},"intent":"Reading broker idempotent subscribe"},"id":"5c3e413a","parentId":"31e7d475","timestamp":"2026-09-16T02:01:06.254Z"}
{"type":"message","id":"5eaf46ec","parentId":"5c3e413a","timestamp":"2026-09-16T02:01:06.254Z","message":{"role":"assistant","content":[{"type":"thinking","thinking":"**Adding alternate decoder reexport**"},{"type":"toolCall","id":"call_JEu3ffY9bhznIp19XeEXgwYK|fc_09b01b5279447709016aa9f862296887d2bae9a7cff14f5b85","name":"grep","arguments":{"i":"Resolving decoder implementation alias","pattern":"AttachDecoder|type .*Decoder","path":"crates/spt-net/src/net/attach.rs","case":true,"gitignore":true,"skip":null},"intent":"Resolving decoder implementation alias"},{"type":"toolCall","id":"call_emckm2p6ptZoCR7ITEqnQ4eG|fc_09b01b5279447709016aa9f862297887d2be78e3ff909ff9a6","name":"read","arguments":{"i":"Reading output forwarding gate","path":"crates/spt-daemon/src/attach.rs:880-919"},"intent":"Reading output forwarding gate"},{"type":"toolCall","id":"call_dfbOVOdXtdaA80wgPeo2R39t|fc_09b01b5279447709016aa9f862297c87d2b0a526ae8273fdb0","name":"read","arguments":{"i":"Reading prepopulated test assertions","path":"crates/spt-daemon/tests/attach.rs:547-655"},"intent":"Reading prepopulated test assertions"},{"type":"toolCall","id":"call_50QbuaFk7ZR8FoX35taowHLz|fc_09b01b5279447709016aa9f862298487d292c616e28737b752","name":"read","arguments":{"i":"Reading broker idempotent subscribe","path":"crates/spt-daemon/src/broker.rs:3170-3250"},"intent":"Reading broker idempotent subscribe"}],"api":"openai-codex-responses","provider":"openai-codex","model":"gpt-6-astra","usage":{"input":22414,"output":191,"cacheRead":102400,"cacheWrite":0,"totalTokens":125005,"reasoningTokens":11,"cost":{"input":0.22414,"output":0.009550000000000001,"cacheRead":0.10239999999999999,"cacheWrite":0,"total":0.33609}},"stopReason":"toolUse","timestamp":1789524055218,"responseId":"resp_09b01b5279447709016aa9f857713087d2988e38795aa25457","providerPayload":{"type":"openaiResponsesHistory","provider":"openai-codex","dt":true,"items":[{"id":"rs_09b01b5279447709016aa9f858c68887d2b5438fa19044251c","type":"reasoning","content":[],"encrypted_content":"gAAAAABqqfhi4yeB9bg6h-CtBHclufq8zpdSYn9aBZSRIO8DMyAkyyuUARNkqxldeWfu_y4mpdymiis64uAvl8-0a8_p6d3evfL8o57l2xg60yLmCejWx3x_e-NJy55zKyJc_tOBtbuoHTCacYVNA5Jpvzogb4XwkqfPVcNW1V9_kKm_3RwkfcaNxR240ZdH1bFmaEfvXOHF0M_zgX75ekRXZz9F1AfwOID71G420pBUHtIGw18JUPOfIXmbMnYCXvfjgm78pAyx9uVxs-vgeJkxlEZ385ksudPU0NYf8EA3Ds1KYUdGDSSCFehMBbo852sqCSzGU77jhumhSiXLjBli6AZWiPIzq2-6qLo6hQKdJeXkQpkZfpx8D_5uKiE0X7tz8gi_nLIxiFrEgKXSAbHskroQgEjWa6eQF84BPRuVir5yy_bJrVIjPCSv4fBkdgZKek-Bg1DOPWplcKpSpv8gz5FoB9infyCGcdsQnZeibs-UM3Ggwr3Za6ZQNBRKYev9SjidaS5wqH2wzAXFk-4E8pjXHZ4OicUs5MoGMDVYKV8keEUDDjBrgN-HqmqWt9LCaEiFNfIKpzLturfwnwmHj1cjlNj2TpZ6ZfZ6dQsKvj2SS0p2lwmMDMwBHdtWUrOp1y5EgmWtIQHWg-0KPiGEE9i33Gj3xQNXCSFs91bLkCOuSvfCgKsUtqABE71pkA5dX41Ol3dawTuwRkKjHeNdVnFUtj4DE0_pHLQ_d4SG9GvBmaebwl3abUYDIvT9-gSh3AlIyc5GE2SLzfh_PZomFYYnDz0N-7m91xnQRN4-wAezy60g66t_ZMVUi1-hV_9joiVAbqeeg7OiUPA8IePD9hWt08yW5Y7ANKDTySD2eTcn4M4eBuQPdn262jU5wKYYSa2OooxTn5XIHwMqSy6v1_KncMZ55MrY_IDsMOp7npJ6V2_p848GLq1bInatb-P3eTSmPPrycEX0k1L_qXK8YVZeuD2vi8C6kSz4zwphfuholI7ScviYbF560kMm2Nnh48FjGvN2pBEueQPKygFgcLwlHT3HA8fHULx0ZKPuEggTHX_UI8wIMhCOQ48mqt7ZQO8bDgHs7S1HmZUo68TbPQbDQB33DICYH3cfN_bEksgI0PTaKRryTdKzy20w19QKDjrgpYjhlal--dQTNLznR-WJvGCLuuDxT8hLD5TUGIsuAGy2FRloaR57IpzaBoggZGlZOJgtgqwFekhcnEJHTt0GBdmExUjUe0ilWP63ld4ZNl0Ul5ybvdfNY2nTjo_tTqCYUefAE4dRC20MuG8FGqT6v7feCQIyK6EciS3byVLFRIi2WjW1cg-xLn0kFN8YviD7NX_J","internal_chat_message_metadata_passthrough":{"turn_id":"f878fb4b-0d9a-4a17-adc6-f6c9f4deeea0"},"summary":[{"type":"summary_text","text":"**Adding alternate decoder reexport**"}],"metadata":{"turn_id":"f878fb4b-0d9a-4a17-adc6-f6c9f4deeea0"}},{"id":"fc_09b01b5279447709016aa9f862296887d2bae9a7cff14f5b85","type":"function_call","status":"completed","arguments":"{\"i\":\"Resolving decoder implementation alias\",\"pattern\":\"AttachDecoder|type .*Decoder\",\"path\":\"crates/spt-net/src/net/attach.rs\",\"case\":true,\"gitignore\":true,\"skip\":null}","call_id":"call_JEu3ffY9bhznIp19XeEXgwYK","internal_chat_message_metadata_passthrough":{"turn_id":"f878fb4b-0d9a-4a17-adc6-f6c9f4deeea0"},"name":"grep","metadata":{"turn_id":"f878fb4b-0d9a-4a17-adc6-f6c9f4deeea0"}},{"id":"fc_09b01b5279447709016aa9f862297887d2be78e3ff909ff9a6","type":"function_call","status":"completed","arguments":"{\"i\":\"Reading output forwarding gate\",\"path\":\"crates/spt-daemon/src/attach.rs:880-919\"}","call_id":"call_emckm2p6ptZoCR7ITEqnQ4eG","internal_chat_message_metadata_passthrough":{"turn_id":"f878fb4b-0d9a-4a17-adc6-f6c9f4deeea0"},"name":"read","metadata":{"turn_id":"f878fb4b-0d9a-4a17-adc6-f6c9f4deeea0"}},{"id":"fc_09b01b5279447709016aa9f862297c87d2b0a526ae8273fdb0","type":"function_call","status":"completed","arguments":"{\"i\":\"Reading prepopulated test assertions\",\"path\":\"crates/spt-daemon/tests/attach.rs:547-655\"}","call_id":"call_dfbOVOdXtdaA80wgPeo2R39t","internal_chat_message_metadata_passthrough":{"turn_id":"f878fb4b-0d9a-4a17-adc6-f6c9f4deeea0"},"name":"read","metadata":{"turn_id":"f878fb4b-0d9a-4a17-adc6-f6c9f4deeea0"}},{"id":"fc_09b01b5279447709016aa9f862298487d292c616e28737b752","type":"function_call","status":"completed","arguments":"{\"i\":\"Reading broker idempotent subscribe\",\"path\":\"crates/spt-daemon/src/broker.rs:3170-3250\"}","call_id":"call_50QbuaFk7ZR8FoX35taowHLz","internal_chat_message_metadata_passthrough":{"turn_id":"f878fb4b-0d9a-4a17-adc6-f6c9f4deeea0"},"name":"read","metadata":{"turn_id":"f878fb4b-0d9a-4a17-adc6-f6c9f4deeea0"}}]},"duration":11015.103899999987,"ttft":1582.439699999988,"completedAt":1789524066252,"contextSnapshot":{"promptTokens":124814,"nonMessageTokens":10480,"compactionEpoch":0}}}
{"type":"message","id":"9f6cce03","parentId":"5eaf46ec","timestamp":"2026-09-16T02:01:06.265Z","message":{"role":"toolResult","toolCallId":"call_emckm2p6ptZoCR7ITEqnQ4eG|fc_09b01b5279447709016aa9f862297887d2be78e3ff909ff9a6","toolName":"read","content":[{"type":"text","text":"pub fn serve_attach(\n…\n) -> io::Result<AttachServeOutcome> {\n…\n    loop {\n…\n        match event {\n…\n            BrokerEvent::NetStreamEof { stream_id: sid, .. } if sid == stream_id => {\n…\n                // marker (the clear-race the broker-single-writer model averts).\n                if role == Some(ServeRole::Controller) {\n                    // The driver detached — the endpoint rests warm (controller-\n                    // only; a viewer leaving is wake-neutral).\n                    feed_rest(endpoint, crate::resting::RestEvent::Detach);\n                }\n                if let Some(sid) = attached_session {\n                    let _ = brain.detach_session_gen(sid, Some(serve_gen)); // release ONLY our generation\n                }\n                return Ok(AttachServeOutcome::Detached);\n            }\n\n            // ── Session → wire: output and exit. ────────────────────────────\n            BrokerEvent::Output { seq, bytes, .. } if attached => {\n                let line = ndjson::encode_line(&AttachRecord::Output {\n                    seq,\n                    data_b64: encode_bytes(&bytes),\n                });\n                // Unjournaled by design (see module docs): `seq` rides inside\n                // the record, and the operator's render cursor is the dedup.\n                wire.net_stream_send(stream_id, &line, None, false)?;\n            }\n            BrokerEvent::Exit { code, .. } if attached => {\n                let line = ndjson::encode_line(&AttachRecord::Exit { code });\n                wire.net_stream_send(stream_id, &line, None, true)?;\n                if role == Some(ServeRole::Controller) {\n                    feed_rest(endpoint, crate::resting::RestEvent::Detach);\n                }\n                return Ok(AttachServeOutcome::Exited(code));\n            }\n\n            BrokerEvent::Error { message } => {\n                if role == Some(ServeRole::Controller) {\n                    feed_rest(endpoint, crate::resting::RestEvent::Detach);\n                }\n                return Err(io::Error::other(message));\n            }\n            // Applied/NetSent acks and unrelated events: not ours to handle.\n            _ => {}\n        }\n    }\n}\n\n/// Operator-side: open an attach stream on a dialed connection and send the\n\n[Showing lines 879-922 of 1159. Use :923 to continue]"}],"details":{"truncation":{"content":"                // marker (the clear-race the broker-single-writer model averts).\r\n                if role == Some(ServeRole::Controller) {\r\n                    // The driver detached — the endpoint rests warm (controller-\r\n                    // only; a viewer leaving is wake-neutral).\r\n                    feed_rest(endpoint, crate::resting::RestEvent::Detach);\r\n                }\r\n                if let Some(sid) = attached_session {\r\n                    let _ = brain.detach_session_gen(sid, Some(serve_gen)); // release ONLY our generation\r\n                }\r\n                return Ok(AttachServeOutcome::Detached);\r\n            }\r\n\r\n            // ── Session → wire: output and exit. ────────────────────────────\r\n            BrokerEvent::Output { seq, bytes, .. } if attached => {\r\n                let line = ndjson::encode_line(&AttachRecord::Output {\r\n                    seq,\r\n                    data_b64: encode_bytes(&bytes),\r\n                });\r\n                // Unjournaled by design (see module docs): `seq` rides inside\r\n                // the record, and the operator's render cursor is the dedup.\r\n                wire.net_stream_send(stream_id, &line, None, false)?;\r\n            }\r\n            BrokerEvent::Exit { code, .. } if attached => {\r\n                let line = ndjson::encode_line(&AttachRecord::Exit { code });\r\n                wire.net_stream_send(stream_id, &line, None, true)?;\r\n                if role == Some(ServeRole::Controller) {\r\n                    feed_rest(endpoint, crate::resting::RestEvent::Detach);\r\n                }\r\n                return Ok(AttachServeOutcome::Exited(code));\r\n            }\r\n\r\n            BrokerEvent::Error { message } => {\r\n                if role == Some(ServeRole::Controller) {\r\n                    feed_rest(endpoint, crate::resting::RestEvent::Detach);\r\n                }\r\n                return Err(io::Error::other(message));\r\n            }\r\n            // Applied/NetSent acks and unrelated events: not ours to handle.\r\n            _ => {}\r\n        }\r\n    }\r\n}\r\n\r\n/// Operator-side: open an attach stream on a dialed connection and send the\r","truncated":true,"truncatedBy":"lines","totalLines":281,"totalBytes":2190,"outputLines":44,"outputBytes":2190,"lastLinePartial":false,"firstLineExceedsLimit":false},"totalLines":1159,"displayContent":{"text":"pub fn serve_attach(\n…\n) -> io::Result<AttachServeOutcome> {\n…\n    loop {\n…\n        match event {\n…\n            BrokerEvent::NetStreamEof { stream_id: sid, .. } if sid == stream_id => {\n…\n                // marker (the clear-race the broker-single-writer model averts).\r\n                if role == Some(ServeRole::Controller) {\r\n                    // The driver detached — the endpoint rests warm (controller-\r\n                    // only; a viewer leaving is wake-neutral).\r\n                    feed_rest(endpoint, crate::resting::RestEvent::Detach);\r\n                }\r\n                if let Some(sid) = attached_session {\r\n                    let _ = brain.detach_session_gen(sid, Some(serve_gen)); // release ONLY our generation\r\n                }\r\n                return Ok(AttachServeOutcome::Detached);\r\n            }\r\n\r\n            // ── Session → wire: output and exit. ────────────────────────────\r\n            BrokerEvent::Output { seq, bytes, .. } if attached => {\r\n                let line = ndjson::encode_line(&AttachRecord::Output {\r\n                    seq,\r\n                    data_b64: encode_bytes(&bytes),\r\n                });\r\n                // Unjournaled by design (see module docs): `seq` rides inside\r\n                // the record, and the operator's render cursor is the dedup.\r\n                wire.net_stream_send(stream_id, &line, None, false)?;\r\n            }\r\n            BrokerEvent::Exit { code, .. } if attached => {\r\n                let line = ndjson::encode_line(&AttachRecord::Exit { code });\r\n                wire.net_stream_send(stream_id, &line, None, true)?;\r\n                if role == Some(ServeRole::Controller) {\r\n                    feed_rest(endpoint, crate::resting::RestEvent::Detach);\r\n                }\r\n                return Ok(AttachServeOutcome::Exited(code));\r\n            }\r\n\r\n            BrokerEvent::Error { message } => {\r\n                if role == Some(ServeRole::Controller) {\r\n                    feed_rest(endpoint, crate::resting::RestEvent::Detach);\r\n                }\r\n                return Err(io::Error::other(message));\r\n            }\r\n            // Applied/NetSent acks and unrelated events: not ours to handle.\r\n            _ => {}\r\n        }\r\n    }\r\n}\r\n\r\n/// Operator-side: open an attach stream on a dialed connection and send the\r","startLine":473,"lineNumbers":[473,null,482,null,573,null,611,null,873,null,879,880,881,882,883,884,885,886,887,888,889,890,891,892,893,894,895,896,897,898,899,900,901,902,903,904,905,906,907,908,909,910,911,912,913,914,915,916,917,918,919,920,921,922]},"fileSize":57673,"meta":{"source":{"type":"path","value":"C:\\Users\\decid\\Documents\\projects\\spt-core\\crates\\spt-daemon\\src\\attach.rs"},"truncation":{"direction":"head","truncatedBy":"lines","totalLines":1159,"totalBytes":2190,"outputLines":44,"outputBytes":2190,"shownRange":{"start":879,"end":922},"nextOffset":923}}},"isError":false,"timestamp":1789524066265}}
{"type":"message","id":"1196c748","parentId":"9f6cce03","timestamp":"2026-09-16T02:01:06.267Z","message":{"role":"toolResult","toolCallId":"call_dfbOVOdXtdaA80wgPeo2R39t|fc_09b01b5279447709016aa9f862297c87d2b0a526ae8273fdb0","toolName":"read","content":[{"type":"text","text":"#[test]\nfn loopback_attach_to_a_prepopulated_ring_delivers_without_deadlock() {\n    let _home = init_home();\n    let dir = tempfile::tempdir().expect(\"tempdir\");\n    let name = unique_name();\n    let _broker = net_broker(&name, &dir.path().join(\"solo\"));\n\n    // A child that emits a BURST of lines (many ring chunks) then blocks on stdin\n    // so it never exits before we attach. `TICK39` (the last line) proves the whole\n    // populated ring replayed + forwarded in order — not just the first chunk.\n    #[cfg(unix)]\n    let (program, args) = (\n        \"sh\".to_string(),\n        vec![\n            \"-c\".to_string(),\n            \"i=0; while [ $i -lt 39 ]; do echo TICK$i; i=$((i+1)); done; sleep 0.2; echo TICK39; cat\".to_string(),\n        ],\n    );\n    #[cfg(windows)]\n    let (program, args) = (\n        \"cmd\".to_string(),\n        vec![\n            \"/c\".to_string(),\n            \"(for /L %i in (0,1,38) do @echo TICK%i) & ping -n 2 127.0.0.1 >nul & echo TICK39 & findstr \\\".\\\"\".to_string(),\n        ],\n    );\n\n    // The SPAWNING conn drains the burst live into the ring, then we DROP it — so a\n    // fresh attach must replay the now non-empty ring (the endpoint-run shape).\n    let mut spawner = connect_retry(&name);\n    let sid = spawner\n        .spawn_session(SpawnReq {\n            program,\n            args,\n            rows: 24,\n            cols: 80,\n            endpoint: \"burst-ep\".into(),\n            cwd: None,\n            env: Default::default(),\n            translation_binary: None,\n            adapter: String::new(),\n            install_dir: None,\n        })\n        .expect(\"spawn burst child\");\n    let mut drained = Vec::new();\n    spawner\n        .read_output_until(b\"TICK39\", &mut drained)\n        .expect(\"the burst lands in the ring\");\n    drop(spawner); // spawn conn gone — a fresh attach must replay the populated ring\n\n    // A fresh operator attaches over loopback (the real `spt rc` transport).\n    let mut operator = connect_retry(&name);\n    let dialed = operator.net_dial_loopback().expect(\"loopback dial\");\n    let own_origin = dialed.remote_id_hex.clone();\n    let stream_b = request_attach(\n        &mut operator,\n        dialed.conn_id,\n        sid,\n        0,\n        MintedOp::new(Minter::Rc, 2),\n        AttachIntent::Control,\n    )\n    .expect(\"request\");\n    operator\n        .net_stream_subscribe(stream_b, 0)\n        .expect(\"operator subscribe\");\n\n    let mut target = connect_retry(&name);\n    let (stream_a, origin) = wait_for_stream(&mut target, &[]);\n    assert_eq!(origin, own_origin);\n    let serve_broker = name.clone();\n    let server = thread::spawn(move || {\n        serve_attach(\n            &mut target,\n            &serve_broker,\n            stream_a,\n            \"burst-ep\",\n            &origin,\n            0,\n            None,\n            None,\n        )\n        .expect(\"serve\")\n    });\n\n    // The operator must RENDER the full pre-populated ring through the LAST marker.\n    // This is exactly what the deadlock starved to ZERO bytes before the fix.\n    let mut decoder = AttachDecoder::new();\n    let (mut cursor, mut viewport) = (0u64, Vec::new());\n    render_until(\n        &mut operator,\n        stream_b,\n        &mut decoder,\n        &mut cursor,\n        &mut viewport,\n        b\"TICK39\",\n    );\n    assert!(\n        count(&viewport, b\"TICK39\") >= 1,\n        \"the full pre-populated ring replayed + forwarded to the operator (no deadlock)\"\n    );\n\n    operator\n        .net_stream_send(stream_b, &[], None, true)\n        .expect(\"detach\");\n    let _ = server.join().expect(\"serve thread\");\n}\n\n// THE #4×#6 INTERSECTION (REQ-BROKER-SCREEN-GRID × REQ-RC-CROSS-NODE-ATTACH),\n// the merge-danger seam: a CROSS-NODE cold attach BY ENDPOINT (#4's\n// `request_attach_endpoint` → the owning node resolves endpoint→session\n// server-side) to an ALREADY-RUNNING ALT-SCREEN session must receive the #6\n// CLEAN current-screen REPAINT — not the raw ring — end-to-end through\n\n[Showing lines 546-658 of 2144. Use :659 to continue]"}],"details":{"truncation":{"content":"#[test]\r\nfn loopback_attach_to_a_prepopulated_ring_delivers_without_deadlock() {\r\n    let _home = init_home();\r\n    let dir = tempfile::tempdir().expect(\"tempdir\");\r\n    let name = unique_name();\r\n    let _broker = net_broker(&name, &dir.path().join(\"solo\"));\r\n\r\n    // A child that emits a BURST of lines (many ring chunks) then blocks on stdin\r\n    // so it never exits before we attach. `TICK39` (the last line) proves the whole\r\n    // populated ring replayed + forwarded in order — not just the first chunk.\r\n    #[cfg(unix)]\r\n    let (program, args) = (\r\n        \"sh\".to_string(),\r\n        vec![\r\n            \"-c\".to_string(),\r\n            \"i=0; while [ $i -lt 39 ]; do echo TICK$i; i=$((i+1)); done; sleep 0.2; echo TICK39; cat\".to_string(),\r\n        ],\r\n    );\r\n    #[cfg(windows)]\r\n    let (program, args) = (\r\n        \"cmd\".to_string(),\r\n        vec![\r\n            \"/c\".to_string(),\r\n            \"(for /L %i in (0,1,38) do @echo TICK%i) & ping -n 2 127.0.0.1 >nul & echo TICK39 & findstr \\\".\\\"\".to_string(),\r\n        ],\r\n    );\r\n\r\n    // The SPAWNING conn drains the burst live into the ring, then we DROP it — so a\r\n    // fresh attach must replay the now non-empty ring (the endpoint-run shape).\r\n    let mut spawner = connect_retry(&name);\r\n    let sid = spawner\r\n        .spawn_session(SpawnReq {\r\n            program,\r\n            args,\r\n            rows: 24,\r\n            cols: 80,\r\n            endpoint: \"burst-ep\".into(),\r\n            cwd: None,\r\n            env: Default::default(),\r\n            translation_binary: None,\r\n            adapter: String::new(),\r\n            install_dir: None,\r\n        })\r\n        .expect(\"spawn burst child\");\r\n    let mut drained = Vec::new();\r\n    spawner\r\n        .read_output_until(b\"TICK39\", &mut drained)\r\n        .expect(\"the burst lands in the ring\");\r\n    drop(spawner); // spawn conn gone — a fresh attach must replay the populated ring\r\n\r\n    // A fresh operator attaches over loopback (the real `spt rc` transport).\r\n    let mut operator = connect_retry(&name);\r\n    let dialed = operator.net_dial_loopback().expect(\"loopback dial\");\r\n    let own_origin = dialed.remote_id_hex.clone();\r\n    let stream_b = request_attach(\r\n        &mut operator,\r\n        dialed.conn_id,\r\n        sid,\r\n        0,\r\n        MintedOp::new(Minter::Rc, 2),\r\n        AttachIntent::Control,\r\n    )\r\n    .expect(\"request\");\r\n    operator\r\n        .net_stream_subscribe(stream_b, 0)\r\n        .expect(\"operator subscribe\");\r\n\r\n    let mut target = connect_retry(&name);\r\n    let (stream_a, origin) = wait_for_stream(&mut target, &[]);\r\n    assert_eq!(origin, own_origin);\r\n    let serve_broker = name.clone();\r\n    let server = thread::spawn(move || {\r\n        serve_attach(\r\n            &mut target,\r\n            &serve_broker,\r\n            stream_a,\r\n            \"burst-ep\",\r\n            &origin,\r\n            0,\r\n            None,\r\n            None,\r\n        )\r\n        .expect(\"serve\")\r\n    });\r\n\r\n    // The operator must RENDER the full pre-populated ring through the LAST marker.\r\n    // This is exactly what the deadlock starved to ZERO bytes before the fix.\r\n    let mut decoder = AttachDecoder::new();\r\n    let (mut cursor, mut viewport) = (0u64, Vec::new());\r\n    render_until(\r\n        &mut operator,\r\n        stream_b,\r\n        &mut decoder,\r\n        &mut cursor,\r\n        &mut viewport,\r\n        b\"TICK39\",\r\n    );\r\n    assert!(\r\n        count(&viewport, b\"TICK39\") >= 1,\r\n        \"the full pre-populated ring replayed + forwarded to the operator (no deadlock)\"\r\n    );\r\n\r\n    operator\r\n        .net_stream_send(stream_b, &[], None, true)\r\n        .expect(\"detach\");\r\n    let _ = server.join().expect(\"serve thread\");\r\n}\r\n\r\n// THE #4×#6 INTERSECTION (REQ-BROKER-SCREEN-GRID × REQ-RC-CROSS-NODE-ATTACH),\r\n// the merge-danger seam: a CROSS-NODE cold attach BY ENDPOINT (#4's\r\n// `request_attach_endpoint` → the owning node resolves endpoint→session\r\n// server-side) to an ALREADY-RUNNING ALT-SCREEN session must receive the #6\r\n// CLEAN current-screen REPAINT — not the raw ring — end-to-end through\r","truncated":true,"truncatedBy":"lines","totalLines":1599,"totalBytes":4065,"outputLines":113,"outputBytes":4065,"lastLinePartial":false,"firstLineExceedsLimit":false},"totalLines":2144,"displayContent":{"text":"#[test]\r\nfn loopback_attach_to_a_prepopulated_ring_delivers_without_deadlock() {\r\n    let _home = init_home();\r\n    let dir = tempfile::tempdir().expect(\"tempdir\");\r\n    let name = unique_name();\r\n    let _broker = net_broker(&name, &dir.path().join(\"solo\"));\r\n\r\n    // A child that emits a BURST of lines (many ring chunks) then blocks on stdin\r\n    // so it never exits before we attach. `TICK39` (the last line) proves the whole\r\n    // populated ring replayed + forwarded in order — not just the first chunk.\r\n    #[cfg(unix)]\r\n    let (program, args) = (\r\n        \"sh\".to_string(),\r\n        vec![\r\n            \"-c\".to_string(),\r\n            \"i=0; while [ $i -lt 39 ]; do echo TICK$i; i=$((i+1)); done; sleep 0.2; echo TICK39; cat\".to_string(),\r\n        ],\r\n    );\r\n    #[cfg(windows)]\r\n    let (program, args) = (\r\n        \"cmd\".to_string(),\r\n        vec![\r\n            \"/c\".to_string(),\r\n            \"(for /L %i in (0,1,38) do @echo TICK%i) & ping -n 2 127.0.0.1 >nul & echo TICK39 & findstr \\\".\\\"\".to_string(),\r\n        ],\r\n    );\r\n\r\n    // The SPAWNING conn drains the burst live into the ring, then we DROP it — so a\r\n    // fresh attach must replay the now non-empty ring (the endpoint-run shape).\r\n    let mut spawner = connect_retry(&name);\r\n    let sid = spawner\r\n        .spawn_session(SpawnReq {\r\n            program,\r\n            args,\r\n            rows: 24,\r\n            cols: 80,\r\n            endpoint: \"burst-ep\".into(),\r\n            cwd: None,\r\n            env: Default::default(),\r\n            translation_binary: None,\r\n            adapter: String::new(),\r\n            install_dir: None,\r\n        })\r\n        .expect(\"spawn burst child\");\r\n    let mut drained = Vec::new();\r\n    spawner\r\n        .read_output_until(b\"TICK39\", &mut drained)\r\n        .expect(\"the burst lands in the ring\");\r\n    drop(spawner); // spawn conn gone — a fresh attach must replay the populated ring\r\n\r\n    // A fresh operator attaches over loopback (the real `spt rc` transport).\r\n    let mut operator = connect_retry(&name);\r\n    let dialed = operator.net_dial_loopback().expect(\"loopback dial\");\r\n    let own_origin = dialed.remote_id_hex.clone();\r\n    let stream_b = request_attach(\r\n        &mut operator,\r\n        dialed.conn_id,\r\n        sid,\r\n        0,\r\n        MintedOp::new(Minter::Rc, 2),\r\n        AttachIntent::Control,\r\n    )\r\n    .expect(\"request\");\r\n    operator\r\n        .net_stream_subscribe(stream_b, 0)\r\n        .expect(\"operator subscribe\");\r\n\r\n    let mut target = connect_retry(&name);\r\n    let (stream_a, origin) = wait_for_stream(&mut target, &[]);\r\n    assert_eq!(origin, own_origin);\r\n    let serve_broker = name.clone();\r\n    let server = thread::spawn(move || {\r\n        serve_attach(\r\n            &mut target,\r\n            &serve_broker,\r\n            stream_a,\r\n            \"burst-ep\",\r\n            &origin,\r\n            0,\r\n            None,\r\n            None,\r\n        )\r\n        .expect(\"serve\")\r\n    });\r\n\r\n    // The operator must RENDER the full pre-populated ring through the LAST marker.\r\n    // This is exactly what the deadlock starved to ZERO bytes before the fix.\r\n    let mut decoder = AttachDecoder::new();\r\n    let (mut cursor, mut viewport) = (0u64, Vec::new());\r\n    render_until(\r\n        &mut operator,\r\n        stream_b,\r\n        &mut decoder,\r\n        &mut cursor,\r\n        &mut viewport,\r\n        b\"TICK39\",\r\n    );\r\n    assert!(\r\n        count(&viewport, b\"TICK39\") >= 1,\r\n        \"the full pre-populated ring replayed + forwarded to the operator (no deadlock)\"\r\n    );\r\n\r\n    operator\r\n        .net_stream_send(stream_b, &[], None, true)\r\n        .expect(\"detach\");\r\n    let _ = server.join().expect(\"serve thread\");\r\n}\r\n\r\n// THE #4×#6 INTERSECTION (REQ-BROKER-SCREEN-GRID × REQ-RC-CROSS-NODE-ATTACH),\r\n// the merge-danger seam: a CROSS-NODE cold attach BY ENDPOINT (#4's\r\n// `request_attach_endpoint` → the owning node resolves endpoint→session\r\n// server-side) to an ALREADY-RUNNING ALT-SCREEN session must receive the #6\r\n// CLEAN current-screen REPAINT — not the raw ring — end-to-end through\r","startLine":546,"lineNumbers":[546,547,548,549,550,551,552,553,554,555,556,557,558,559,560,561,562,563,564,565,566,567,568,569,570,571,572,573,574,575,576,577,578,579,580,581,582,583,584,585,586,587,588,589,590,591,592,593,594,595,596,597,598,599,600,601,602,603,604,605,606,607,608,609,610,611,612,613,614,615,616,617,618,619,620,621,622,623,624,625,626,627,628,629,630,631,632,633,634,635,636,637,638,639,640,641,642,643,644,645,646,647,648,649,650,651,652,653,654,655,656,657,658]},"fileSize":89554,"meta":{"source":{"type":"path","value":"C:\\Users\\decid\\Documents\\projects\\spt-core\\crates\\spt-daemon\\tests\\attach.rs"},"truncation":{"direction":"head","truncatedBy":"lines","totalLines":2144,"totalBytes":4065,"outputLines":113,"outputBytes":4065,"shownRange":{"start":546,"end":658},"nextOffset":659}}},"isError":false,"timestamp":1789524066267}}
{"type":"message","id":"c5a693f4","parentId":"1196c748","timestamp":"2026-09-16T02:01:06.272Z","message":{"role":"toolResult","toolCallId":"call_50QbuaFk7ZR8FoX35taowHLz|fc_09b01b5279447709016aa9f862298487d292c616e28737b752","toolName":"read","content":[{"type":"text","text":"        if same_identity {\n…\n            // LEASE (ADR-0044 decision 1 + the 2026-07-18 ladder ruling over\n            // the ADR-0038 fix-6 generation): node identity alone is NEVER a\n            // lease — two same-node viewports are DISTINCT controllers,\n            // discriminated by their generations; within one identity the\n            // generation stays the LIFECYCLE discriminator.\n            //   gen == incumbent (nonzero)  → the SAME lease re-served after a\n            //     dispatcher restart — the fix-6 successor, silent (gate #7).\n            //   gen <  incumbent (nonzero)  → a REPLAYED stale Request (an\n            //     unfinished backlog row whose viewport died raw) — refused\n            //     busy; the ladder never runs backwards.\n            //   gen >  incumbent (nonzero)  → the LIVE replacement viewport,\n            //     Control or Take alike: loud+fenced SUPERSESSION via the full\n            //     W2 revoke (terminal Displaced + fence moves with the slot) —\n            //     never the silent sink swap that left the incumbent\n            //     input-capable but blind (the hertz split-brain), and never a\n            //     Busy that locks the replacement out behind a stale-replay\n            //     worker serving a zombie stream (the redispatch_stall T6\n            //     post-restart lockout).\n            //   0 on either side → local / N-1 legacy re-take, preserved.\n            // [impl->REQ-CONTROLLER-LEASE-IDENTITY]\n            // [impl->REQ-SERVE-OWNERSHIP-GENERATION]\n            let incumbent_gen = self.controller.as_ref().map_or(0, |c| c.attach_gen);\n            let incumbent_conn = self.controller.as_ref().map(|c| c.send.id());\n            // IDEMPOTENT REPLAY — the new leaf INSIDE the equal-generation rung\n            // (ADR-0047 decision 3, REQ-ATTACH-IDEMPOTENT-REPLAY). Same identity,\n            // same NONZERO generation, and the SAME CONNECTION as the incumbent\n            // seat means this is a replay of the establish we already honored, not\n            // a successor: the seat and its writer are PRESERVED, no\n            // `controller-replaced` fires, and no second initial batch is\n            // synthesized. Field bill (hertz v0.39.4 bug 4, pinned on an\n            // authorized same-seam `daemon refresh`): post-cycle dispatcher replay\n            // served ONE held attach twice on ONE conn 15 ms apart; the equal-gen\n            // rung classified it \"same lease, silent re-take\" — correct — but\n            // re-take was `become_controller`, which unconditionally drops the\n            // prior seat. Designed for a DEAD seat after a dispatcher restart, it\n            // fired against the same LIVE conn: the lease killed its own writer\n            // (channel-closed) and the rc viewport froze until a manual\n            // detach + re-attach. \"spt update freezes every attached PTY.\"\n            //\n            // Equal generation on a DIFFERENT conn keeps today's silent swap — that\n            // is the designed ADR-0038 fix-6 successor (the old seat is dead and the\n            // lease is being re-served on a fresh carrier), and it must not regress.\n            // [impl->REQ-ATTACH-IDEMPOTENT-REPLAY]\n            //\n            // The key includes `from_seq` because core itself re-subscribes on the\n            // SAME conn with the SAME generation for a legitimate reason: the\n            // controller GAP RESUME (REQ-HAZARD-CONTROLLER-GAP-RESUME,\n            // `read_controller_event_resuming`) re-fetches dropped frames from its\n            // frozen `delivered_through` floor. That request is NOT a replay of the\n            // establish — it asks for different bytes — and suppressing it would\n            // leave the gap unhealed and surface a false truncation. A replayed\n            // establish carries the from_seq it was first honored with; a re-fetch\n            // carries the floor it has since reached.\n            let incumbent_from = self.controller.as_ref().map_or(0, |c| c.establish_from_seq);\n            if gen != 0\n                && incumbent_gen == gen\n                && incumbent_conn == Some(sub.id())\n                && incumbent_from == from_seq\n            {\n                return (SubscribeOutcome::Controller, \"idempotent\");\n            }\n            if gen == 0 || incumbent_gen == 0 || gen == incumbent_gen {\n                // Same lease (or legacy) that is NOT a replay of the establish:\n                // a different conn (the fix-6 successor) or the SAME conn asking\n                // from a different floor (the gap-resume re-fetch above). Silent\n                // re-take either way, NEVER Displaced.\n                self.become_controller(sub, by, from_seq, gen);\n                return (SubscribeOutcome::Controller, \"controller\");\n            }\n            if gen < incumbent_gen {\n                return (\n                    SubscribeOutcome::BusyControlled {\n                        by: self.controller_by().unwrap_or_default().to_string(),\n                    },\n                    \"busy\",\n                );\n            }\n            // Strictly newer gen — loud+fenced supersession on BOTH intents.\n            self.mark_revoked(by.as_deref().unwrap_or(\"\"));\n            self.become_controller(sub, by, from_seq, gen);\n            return match intent {\n                AttachIntent::Take => (SubscribeOutcome::TookControl, \"took\"),\n                _ => (SubscribeOutcome::Controller, \"controller\"),\n            };\n        }\n\n[Showing lines 3169-3253 of 16852. Use :3254 to continue]"}],"details":{"truncation":{"content":"            // LEASE (ADR-0044 decision 1 + the 2026-07-18 ladder ruling over\r\n            // the ADR-0038 fix-6 generation): node identity alone is NEVER a\r\n            // lease — two same-node viewports are DISTINCT controllers,\r\n            // discriminated by their generations; within one identity the\r\n            // generation stays the LIFECYCLE discriminator.\r\n            //   gen == incumbent (nonzero)  → the SAME lease re-served after a\r\n            //     dispatcher restart — the fix-6 successor, silent (gate #7).\r\n            //   gen <  incumbent (nonzero)  → a REPLAYED stale Request (an\r\n            //     unfinished backlog row whose viewport died raw) — refused\r\n            //     busy; the ladder never runs backwards.\r\n            //   gen >  incumbent (nonzero)  → the LIVE replacement viewport,\r\n            //     Control or Take alike: loud+fenced SUPERSESSION via the full\r\n            //     W2 revoke (terminal Displaced + fence moves with the slot) —\r\n            //     never the silent sink swap that left the incumbent\r\n            //     input-capable but blind (the hertz split-brain), and never a\r\n            //     Busy that locks the replacement out behind a stale-replay\r\n            //     worker serving a zombie stream (the redispatch_stall T6\r\n            //     post-restart lockout).\r\n            //   0 on either side → local / N-1 legacy re-take, preserved.\r\n            // [impl->REQ-CONTROLLER-LEASE-IDENTITY]\r\n            // [impl->REQ-SERVE-OWNERSHIP-GENERATION]\r\n            let incumbent_gen = self.controller.as_ref().map_or(0, |c| c.attach_gen);\r\n            let incumbent_conn = self.controller.as_ref().map(|c| c.send.id());\r\n            // IDEMPOTENT REPLAY — the new leaf INSIDE the equal-generation rung\r\n            // (ADR-0047 decision 3, REQ-ATTACH-IDEMPOTENT-REPLAY). Same identity,\r\n            // same NONZERO generation, and the SAME CONNECTION as the incumbent\r\n            // seat means this is a replay of the establish we already honored, not\r\n            // a successor: the seat and its writer are PRESERVED, no\r\n            // `controller-replaced` fires, and no second initial batch is\r\n            // synthesized. Field bill (hertz v0.39.4 bug 4, pinned on an\r\n            // authorized same-seam `daemon refresh`): post-cycle dispatcher replay\r\n            // served ONE held attach twice on ONE conn 15 ms apart; the equal-gen\r\n            // rung classified it \"same lease, silent re-take\" — correct — but\r\n            // re-take was `become_controller`, which unconditionally drops the\r\n            // prior seat. Designed for a DEAD seat after a dispatcher restart, it\r\n            // fired against the same LIVE conn: the lease killed its own writer\r\n            // (channel-closed) and the rc viewport froze until a manual\r\n            // detach + re-attach. \"spt update freezes every attached PTY.\"\r\n            //\r\n            // Equal generation on a DIFFERENT conn keeps today's silent swap — that\r\n            // is the designed ADR-0038 fix-6 successor (the old seat is dead and the\r\n            // lease is being re-served on a fresh carrier), and it must not regress.\r\n            // [impl->REQ-ATTACH-IDEMPOTENT-REPLAY]\r\n            //\r\n            // The key includes `from_seq` because core itself re-subscribes on the\r\n            // SAME conn with the SAME generation for a legitimate reason: the\r\n            // controller GAP RESUME (REQ-HAZARD-CONTROLLER-GAP-RESUME,\r\n            // `read_controller_event_resuming`) re-fetches dropped frames from its\r\n            // frozen `delivered_through` floor. That request is NOT a replay of the\r\n            // establish — it asks for different bytes — and suppressing it would\r\n            // leave the gap unhealed and surface a false truncation. A replayed\r\n            // establish carries the from_seq it was first honored with; a re-fetch\r\n            // carries the floor it has since reached.\r\n            let incumbent_from = self.controller.as_ref().map_or(0, |c| c.establish_from_seq);\r\n            if gen != 0\r\n                && incumbent_gen == gen\r\n                && incumbent_conn == Some(sub.id())\r\n                && incumbent_from == from_seq\r\n            {\r\n                return (SubscribeOutcome::Controller, \"idempotent\");\r\n            }\r\n            if gen == 0 || incumbent_gen == 0 || gen == incumbent_gen {\r\n                // Same lease (or legacy) that is NOT a replay of the establish:\r\n                // a different conn (the fix-6 successor) or the SAME conn asking\r\n                // from a different floor (the gap-resume re-fetch above). Silent\r\n                // re-take either way, NEVER Displaced.\r\n                self.become_controller(sub, by, from_seq, gen);\r\n                return (SubscribeOutcome::Controller, \"controller\");\r\n            }\r\n            if gen < incumbent_gen {\r\n                return (\r\n                    SubscribeOutcome::BusyControlled {\r\n                        by: self.controller_by().unwrap_or_default().to_string(),\r\n                    },\r\n                    \"busy\",\r\n                );\r\n            }\r\n            // Strictly newer gen — loud+fenced supersession on BOTH intents.\r\n            self.mark_revoked(by.as_deref().unwrap_or(\"\"));\r\n            self.become_controller(sub, by, from_seq, gen);\r\n            return match intent {\r\n                AttachIntent::Take => (SubscribeOutcome::TookControl, \"took\"),\r\n                _ => (SubscribeOutcome::Controller, \"controller\"),\r\n            };\r\n        }\r","truncated":true,"truncatedBy":"lines","totalLines":13684,"totalBytes":5571,"outputLines":85,"outputBytes":5571,"lastLinePartial":false,"firstLineExceedsLimit":false},"totalLines":16852,"displayContent":{"text":"        if same_identity {\n…\n            // LEASE (ADR-0044 decision 1 + the 2026-07-18 ladder ruling over\r\n            // the ADR-0038 fix-6 generation): node identity alone is NEVER a\r\n            // lease — two same-node viewports are DISTINCT controllers,\r\n            // discriminated by their generations; within one identity the\r\n            // generation stays the LIFECYCLE discriminator.\r\n            //   gen == incumbent (nonzero)  → the SAME lease re-served after a\r\n            //     dispatcher restart — the fix-6 successor, silent (gate #7).\r\n            //   gen <  incumbent (nonzero)  → a REPLAYED stale Request (an\r\n            //     unfinished backlog row whose viewport died raw) — refused\r\n            //     busy; the ladder never runs backwards.\r\n            //   gen >  incumbent (nonzero)  → the LIVE replacement viewport,\r\n            //     Control or Take alike: loud+fenced SUPERSESSION via the full\r\n            //     W2 revoke (terminal Displaced + fence moves with the slot) —\r\n            //     never the silent sink swap that left the incumbent\r\n            //     input-capable but blind (the hertz split-brain), and never a\r\n            //     Busy that locks the replacement out behind a stale-replay\r\n            //     worker serving a zombie stream (the redispatch_stall T6\r\n            //     post-restart lockout).\r\n            //   0 on either side → local / N-1 legacy re-take, preserved.\r\n            // [impl->REQ-CONTROLLER-LEASE-IDENTITY]\r\n            // [impl->REQ-SERVE-OWNERSHIP-GENERATION]\r\n            let incumbent_gen = self.controller.as_ref().map_or(0, |c| c.attach_gen);\r\n            let incumbent_conn = self.controller.as_ref().map(|c| c.send.id());\r\n            // IDEMPOTENT REPLAY — the new leaf INSIDE the equal-generation rung\r\n            // (ADR-0047 decision 3, REQ-ATTACH-IDEMPOTENT-REPLAY). Same identity,\r\n            // same NONZERO generation, and the SAME CONNECTION as the incumbent\r\n            // seat means this is a replay of the establish we already honored, not\r\n            // a successor: the seat and its writer are PRESERVED, no\r\n            // `controller-replaced` fires, and no second initial batch is\r\n            // synthesized. Field bill (hertz v0.39.4 bug 4, pinned on an\r\n            // authorized same-seam `daemon refresh`): post-cycle dispatcher replay\r\n            // served ONE held attach twice on ONE conn 15 ms apart; the equal-gen\r\n            // rung classified it \"same lease, silent re-take\" — correct — but\r\n            // re-take was `become_controller`, which unconditionally drops the\r\n            // prior seat. Designed for a DEAD seat after a dispatcher restart, it\r\n            // fired against the same LIVE conn: the lease killed its own writer\r\n            // (channel-closed) and the rc viewport froze until a manual\r\n            // detach + re-attach. \"spt update freezes every attached PTY.\"\r\n            //\r\n            // Equal generation on a DIFFERENT conn keeps today's silent swap — that\r\n            // is the designed ADR-0038 fix-6 successor (the old seat is dead and the\r\n            // lease is being re-served on a fresh carrier), and it must not regress.\r\n            // [impl->REQ-ATTACH-IDEMPOTENT-REPLAY]\r\n            //\r\n            // The key includes `from_seq` because core itself re-subscribes on the\r\n            // SAME conn with the SAME generation for a legitimate reason: the\r\n            // controller GAP RESUME (REQ-HAZARD-CONTROLLER-GAP-RESUME,\r\n            // `read_controller_event_resuming`) re-fetches dropped frames from its\r\n            // frozen `delivered_through` floor. That request is NOT a replay of the\r\n            // establish — it asks for different bytes — and suppressing it would\r\n            // leave the gap unhealed and surface a false truncation. A replayed\r\n            // establish carries the from_seq it was first honored with; a re-fetch\r\n            // carries the floor it has since reached.\r\n            let incumbent_from = self.controller.as_ref().map_or(0, |c| c.establish_from_seq);\r\n            if gen != 0\r\n                && incumbent_gen == gen\r\n                && incumbent_conn == Some(sub.id())\r\n                && incumbent_from == from_seq\r\n            {\r\n                return (SubscribeOutcome::Controller, \"idempotent\");\r\n            }\r\n            if gen == 0 || incumbent_gen == 0 || gen == incumbent_gen {\r\n                // Same lease (or legacy) that is NOT a replay of the establish:\r\n                // a different conn (the fix-6 successor) or the SAME conn asking\r\n                // from a different floor (the gap-resume re-fetch above). Silent\r\n                // re-take either way, NEVER Displaced.\r\n                self.become_controller(sub, by, from_seq, gen);\r\n                return (SubscribeOutcome::Controller, \"controller\");\r\n            }\r\n            if gen < incumbent_gen {\r\n                return (\r\n                    SubscribeOutcome::BusyControlled {\r\n                        by: self.controller_by().unwrap_or_default().to_string(),\r\n                    },\r\n                    \"busy\",\r\n                );\r\n            }\r\n            // Strictly newer gen — loud+fenced supersession on BOTH intents.\r\n            self.mark_revoked(by.as_deref().unwrap_or(\"\"));\r\n            self.become_controller(sub, by, from_seq, gen);\r\n            return match intent {\r\n                AttachIntent::Take => (SubscribeOutcome::TookControl, \"took\"),\r\n                _ => (SubscribeOutcome::Controller, \"controller\"),\r\n            };\r\n        }\r","startLine":3167,"lineNumbers":[3167,null,3169,3170,3171,3172,3173,3174,3175,3176,3177,3178,3179,3180,3181,3182,3183,3184,3185,3186,3187,3188,3189,3190,3191,3192,3193,3194,3195,3196,3197,3198,3199,3200,3201,3202,3203,3204,3205,3206,3207,3208,3209,3210,3211,3212,3213,3214,3215,3216,3217,3218,3219,3220,3221,3222,3223,3224,3225,3226,3227,3228,3229,3230,3231,3232,3233,3234,3235,3236,3237,3238,3239,3240,3241,3242,3243,3244,3245,3246,3247,3248,3249,3250,3251,3252,3253]},"fileSize":877537,"meta":{"source":{"type":"path","value":"C:\\Users\\decid\\Documents\\projects\\spt-core\\crates\\spt-daemon\\src\\broker.rs"},"truncation":{"direction":"head","truncatedBy":"lines","totalLines":16852,"totalBytes":5571,"outputLines":85,"outputBytes":5571,"shownRange":{"start":3169,"end":3253},"nextOffset":3254}}},"isError":false,"timestamp":1789524066272}}
{"type":"message","id":"e93b5209","parentId":"c5a693f4","timestamp":"2026-09-16T02:01:06.274Z","message":{"role":"toolResult","toolCallId":"call_JEu3ffY9bhznIp19XeEXgwYK|fc_09b01b5279447709016aa9f862296887d2bae9a7cff14f5b85","toolName":"grep","content":[{"type":"text","text":" 369|/// [`AttachRecord`]s. One decoder per stream side.\n*370|pub type AttachDecoder = NdjsonDecoder<AttachRecord>;\n 371|\n 372|#[cfg(test)]\n 373|mod tests {\n...\n 458|\n*459|        let mut dec = AttachDecoder::new();\n 460|        assert_eq!(dec.push(&wire), records, \"all kinds round-trip in order\");\n 461|\n*462|        let mut dec = AttachDecoder::new();\n 463|        assert_eq!(\n 464|            dec.push(&with_junk),\n 465|            vec![records[0].clone(), records[3].clone()],\n...\n 477|    fn fido2_fields_are_additive_and_absent_decodes_as_plain_totp() {\n*478|        let mut dec = AttachDecoder::new();\n 479|        let old_wire = b\"{\\\"kind\\\":\\\"seal_ceremony\\\",\\\"ceremony_id\\\":7,\\\n 480|                         \\\"content_b64\\\":\\\"c2VhbCBtZQ==\\\",\\\"subnet\\\":\\\"bignet\\\"}\\n\\\n 481|                         {\\\"kind\\\":\\\"seal_ceremony_code\\\",\\\"ceremony_id\\\":7,\\\n...\n 558|        let line = r.encode_line();\n*559|        let mut dec = AttachDecoder::new();\n 560|        assert!(dec.push(&line[..line.len() / 2]).is_empty());\n 561|        assert_eq!(dec.push(&line[line.len() / 2..]), vec![r]);\n 562|    }\n...\n 569|    fn request_without_intent_defaults_to_control() {\n*570|        let mut dec = AttachDecoder::new();\n 571|        let legacy = b\"{\\\"kind\\\":\\\"request\\\",\\\"session_id\\\":7,\\\"from_seq\\\":0}\\n\";\n 572|        assert_eq!(\n 573|            dec.push(legacy),\n...\n 598|         gen: 0, code: None, seal_ceremony: false, client: None, };\n*599|        let mut dec = AttachDecoder::new();\n 600|        assert_eq!(dec.push(&remote.encode_line()), vec![remote.clone()]);\n 601|        assert!(\n 602|            String::from_utf8_lossy(&remote.encode_line()).contains(\"ling@gravity\"),\n...\n 617|        // And it still decodes (through the same shared decoder) to the local shape.\n*618|        let mut dec = AttachDecoder::new();\n 619|        assert_eq!(dec.push(&local.encode_line()), vec![local]);\n 620|    }\n 621|\n...\n 626|            let r = AttachRecord::Request { session_id: 1, from_seq: 0, intent, endpoint_id: None , gen: 0, code: None, seal_ceremony: false, client: None };\n*627|            let mut dec = AttachDecoder::new();\n 628|            assert_eq!(dec.push(&r.encode_line()), vec![r]);\n 629|        }\n 630|    }\n...\n 648|        };\n*649|        let mut dec = AttachDecoder::new();\n 650|        assert_eq!(dec.push(&coded.encode_line()), vec![coded.clone()]);\n 651|        assert!(String::from_utf8_lossy(&coded.encode_line()).contains(\"123456\"));\n 652|\n...\n 666|        );\n*667|        let mut dec = AttachDecoder::new();\n 668|        let legacy = b\"{\\\"kind\\\":\\\"request\\\",\\\"session_id\\\":7,\\\"from_seq\\\":0}\\n\";\n 669|        assert_eq!(\n 670|            dec.push(legacy),\n...\n 710|        );\n*711|        let mut dec = AttachDecoder::new();\n 712|        assert_eq!(dec.push(&coded.encode_line()), vec![coded]);\n*713|        let mut dec = AttachDecoder::new();\n 714|        assert_eq!(dec.push(&cancel.encode_line()), vec![cancel]);\n 715|    }\n 716|\n...\n 733|        };\n*734|        let mut dec = AttachDecoder::new();\n 735|        assert_eq!(dec.push(&capable.encode_line()), vec![capable.clone()]);\n 736|        assert!(String::from_utf8_lossy(&capable.encode_line()).contains(\"seal_ceremony\"));\n 737|\n...\n 751|        );\n*752|        let mut dec = AttachDecoder::new();\n 753|        let legacy = b\"{\\\"kind\\\":\\\"request\\\",\\\"session_id\\\":7,\\\"from_seq\\\":0}\\n\";\n 754|        assert_eq!(\n 755|            dec.push(legacy),\n...\n 773|        for r in [take, displaced] {\n*774|            let mut dec = AttachDecoder::new();\n 775|            assert_eq!(dec.push(&r.encode_line()), vec![r]);\n 776|        }\n 777|    }\n...\n 860|        };\n*861|        let mut dec = AttachDecoder::new();\n 862|        assert_eq!(dec.push(&identified.encode_line()), vec![identified.clone()]);\n 863|        let n_minus_one = AttachRecord::Request {\n 864|            session_id: 7,\n...\n 884|        };\n*885|        let mut dec = AttachDecoder::new();\n 886|        assert_eq!(dec.push(&policy.encode_line()), vec![policy.clone()]);\n 887|        let empty = AttachRecord::ClientPolicy { policies: Vec::new() };\n*888|        let mut dec = AttachDecoder::new();\n 889|        assert_eq!(\n 890|            dec.push(&empty.encode_line()),\n 891|            vec![empty],"}],"details":{"scopePath":"crates/spt-net/src/net/attach.rs","searchPath":"C:\\Users\\decid\\Documents\\projects\\spt-core\\crates\\spt-net\\src\\net\\attach.rs","cwd":"C:\\Users\\decid\\Documents\\projects\\spt-core","matchCount":19,"fileCount":1,"files":["crates/spt-net/src/net/attach.rs"],"fileMatches":[{"path":"crates/spt-net/src/net/attach.rs","count":19}],"truncated":false,"displayContent":" 369│/// [`AttachRecord`]s. One decoder per stream side.\n*370│pub type AttachDecoder = NdjsonDecoder<AttachRecord>;\n 371│\n 372│#[cfg(test)]\n 373│mod tests {\n    │...\n 458│\n*459│        let mut dec = AttachDecoder::new();\n 460│        assert_eq!(dec.push(&wire), records, \"all kinds round-trip in order\");\n 461│\n*462│        let mut dec = AttachDecoder::new();\n 463│        assert_eq!(\n 464│            dec.push(&with_junk),\n 465│            vec![records[0].clone(), records[3].clone()],\n    │...\n 477│    fn fido2_fields_are_additive_and_absent_decodes_as_plain_totp() {\n*478│        let mut dec = AttachDecoder::new();\n 479│        let old_wire = b\"{\\\"kind\\\":\\\"seal_ceremony\\\",\\\"ceremony_id\\\":7,\\\n 480│                         \\\"content_b64\\\":\\\"c2VhbCBtZQ==\\\",\\\"subnet\\\":\\\"bignet\\\"}\\n\\\n 481│                         {\\\"kind\\\":\\\"seal_ceremony_code\\\",\\\"ceremony_id\\\":7,\\\n    │...\n 558│        let line = r.encode_line();\n*559│        let mut dec = AttachDecoder::new();\n 560│        assert!(dec.push(&line[..line.len() / 2]).is_empty());\n 561│        assert_eq!(dec.push(&line[line.len() / 2..]), vec![r]);\n 562│    }\n    │...\n 569│    fn request_without_intent_defaults_to_control() {\n*570│        let mut dec = AttachDecoder::new();\n 571│        let legacy = b\"{\\\"kind\\\":\\\"request\\\",\\\"session_id\\\":7,\\\"from_seq\\\":0}\\n\";\n 572│        assert_eq!(\n 573│            dec.push(legacy),\n    │...\n 598│         gen: 0, code: None, seal_ceremony: false, client: None, };\n*599│        let mut dec = AttachDecoder::new();\n 600│        assert_eq!(dec.push(&remote.encode_line()), vec![remote.clone()]);\n 601│        assert!(\n 602│            String::from_utf8_lossy(&remote.encode_line()).contains(\"ling@gravity\"),\n    │...\n 617│        // And it still decodes (through the same shared decoder) to the local shape.\n*618│        let mut dec = AttachDecoder::new();\n 619│        assert_eq!(dec.push(&local.encode_line()), vec![local]);\n 620│    }\n 621│\n    │...\n 626│            let r = AttachRecord::Request { session_id: 1, from_seq: 0, intent, endpoint_id: None , gen: 0, code: None, seal_ceremony: false, client: None };\n*627│            let mut dec = AttachDecoder::new();\n 628│            assert_eq!(dec.push(&r.encode_line()), vec![r]);\n 629│        }\n 630│    }\n    │...\n 648│        };\n*649│        let mut dec = AttachDecoder::new();\n 650│        assert_eq!(dec.push(&coded.encode_line()), vec![coded.clone()]);\n 651│        assert!(String::from_utf8_lossy(&coded.encode_line()).contains(\"123456\"));\n 652│\n    │...\n 666│        );\n*667│        let mut dec = AttachDecoder::new();\n 668│        let legacy = b\"{\\\"kind\\\":\\\"request\\\",\\\"session_id\\\":7,\\\"from_seq\\\":0}\\n\";\n 669│        assert_eq!(\n 670│            dec.push(legacy),\n    │...\n 710│        );\n*711│        let mut dec = AttachDecoder::new();\n 712│        assert_eq!(dec.push(&coded.encode_line()), vec![coded]);\n*713│        let mut dec = AttachDecoder::new();\n 714│        assert_eq!(dec.push(&cancel.encode_line()), vec![cancel]);\n 715│    }\n 716│\n    │...\n 733│        };\n*734│        let mut dec = AttachDecoder::new();\n 735│        assert_eq!(dec.push(&capable.encode_line()), vec![capable.clone()]);\n 736│        assert!(String::from_utf8_lossy(&capable.encode_line()).contains(\"seal_ceremony\"));\n 737│\n    │...\n 751│        );\n*752│        let mut dec = AttachDecoder::new();\n 753│        let legacy = b\"{\\\"kind\\\":\\\"request\\\",\\\"session_id\\\":7,\\\"from_seq\\\":0}\\n\";\n 754│        assert_eq!(\n 755│            dec.push(legacy),\n    │...\n 773│        for r in [take, displaced] {\n*774│            let mut dec = AttachDecoder::new();\n 775│            assert_eq!(dec.push(&r.encode_line()), vec![r]);\n 776│        }\n 777│    }\n    │...\n 860│        };\n*861│        let mut dec = AttachDecoder::new();\n 862│        assert_eq!(dec.push(&identified.encode_line()), vec![identified.clone()]);\n 863│        let n_minus_one = AttachRecord::Request {\n 864│            session_id: 7,\n    │...\n 884│        };\n*885│        let mut dec = AttachDecoder::new();\n 886│        assert_eq!(dec.push(&policy.encode_line()), vec![policy.clone()]);\n 887│        let empty = AttachRecord::ClientPolicy { policies: Vec::new() };\n*888│        let mut dec = AttachDecoder::new();\n 889│        assert_eq!(\n 890│            dec.push(&empty.encode_line()),\n 891│            vec![empty],"},"isError":false,"timestamp":1789524066273}}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_Gvcgb0nreHr9Q77JvDaXzKiB|fc_09b01b5279447709016aa9f8700ee087d2a7463a4b96b643d4","toolName":"hub","startedAt":"2026-09-16T02:01:20.824Z","intent":"Reporting replay candidate and retry gap"},"id":"8b015db9","parentId":"e93b5209","timestamp":"2026-09-16T02:01:20.824Z"}
{"type":"message","id":"19d5cb13","parentId":"8b015db9","timestamp":"2026-09-16T02:01:20.825Z","message":{"role":"assistant","content":[{"type":"thinking","thinking":"**Waiting on resize broker**"},{"type":"toolCall","id":"call_Gvcgb0nreHr9Q77JvDaXzKiB|fc_09b01b5279447709016aa9f8700ee087d2a7463a4b96b643d4","name":"hub","arguments":{"i":"Reporting replay candidate and retry gap","op":"send","to":"Main","message":"Source-backed candidate: attach.rs754-755 still flushes replayed pending_input via ack=true send_effect, unlike normal no_ack at674; synchronous write-only batch on same receiving conn can stop drains while broker emits Applied (broker8930-8936) behind shared stream/controller output. Not proven; ~13 baseline tag submissions alone don't establish sufficient replay volume. Critical observed refinement: all replacement stream poisons say LIVE write failed, not replay failure => stream subscriber replay writer completed (nethost217-227). os233 outcomes do NOT trigger SeatBlocked breaker; dispatch373-383 +503-545 make attempts0/1/2 transient then terminal. Thus successful conn retirement + retry can reproduce consumer problem thrice then abandon stream. Full source report follows."},"intent":"Reporting replay candidate and retry gap"}],"api":"openai-codex-responses","provider":"openai-codex","model":"gpt-6-astra","usage":{"input":4282,"output":261,"cacheRead":124672,"cacheWrite":0,"totalTokens":129215,"reasoningTokens":71,"cost":{"input":0.042820000000000004,"output":0.01305,"cacheRead":0.12467199999999999,"cacheWrite":0,"total":0.18054199999999998}},"stopReason":"toolUse","timestamp":1789524066286,"responseId":"resp_09b01b5279447709016aa9f8627f2887d295cddf9cd5359afb","providerPayload":{"type":"openaiResponsesHistory","provider":"openai-codex","dt":true,"items":[{"id":"rs_09b01b5279447709016aa9f867719487d28cd9c46583881ba9","type":"reasoning","content":[],"encrypted_content":"gAAAAABqqfhwVWAxxX2SNIA8W0BE79IDNj4ML11TW0veqvJ-pm4-tqW-Eg3PQAIDsjFhX77zSSV8THc42GHBEuJe6SdxxK5wZcprwvTIlG5eko7BYkTFVoJREqRg6LvF0YSTx5V241AuKyif-g9aQd2r5Po9ImT3Xt4X23OmK8t1KfRUF7YPCXeX9y8MP-qJJdSNhqzjLFedcYRclMFt4f1c7i2P0VFLYta--kQ5TzFLml2cHtkWrCOUwS1Qnzkrmr_s4DWcSPEso_63J5y1M789smiXw7c0tWDv-8bhTCDe6uBsK2wwsG1At-zjwD_lkqw77N0ACE0hDIOaNIDJ2N2sSAMrp49SLXPandPop7SJbFPOcKbjhj-Tg6iNOtxN9iILGlnWuD9oTmBBp-vnuHOSww_VgOnQkPnqulmrmYqduVJiA4EaEADocebRHxfDcvOpZ6alwGjyCnI10VOoyUXQ_bHawbcGtIfIpdP4yv-LL7tbSH1WrUYX3EOBWhpTf0-KJEB-ViFbtMGiU-cYJVsQe_J570vqOetXTUse5O8_mESoyaA-eI16llthYUAF88vPzjDLli7I3tL7RCXNjXKwt1hKQiV9uUGHeQR5s6Lvz1Mbm4W8dFTt1F2Ev7qzAZ2pFkPcELjXWgohdTQs-0yryQvI0o4mniLkTEySdxOf3WB4abb9d-EJppamSydRR6YTKDUmQQ_x5y5Exajzt_6lW6xuSkXubGm36tbCr3KcNWLpaiG3e8DIHithTvpNE6nsMtmPcyo5xO78Ts8-EG4tZKU4HbhJyiS1nSelpy7Cf6BKxAW4aqMHo_prEuNUyS_JtwjqpdFJJssudtVvflBny36o1CjiimKWWfdWFDHPUtZdP9xczDXyKsKTSX5T2UDaONEJIdr-F1CS_8-uqJYRynW4im3Gc_jmV5g5IJ6mmWd8ffzX5ftrorqLPHIHw5pB5uTiv2QKuE-WoeGyTFdYc7dc42PLITgT3tuW_0caNh4X9iyCvyLYPBoR4C78oxE3mPPIn15pyt5Wy-Cw4m8mk99mt3i6yBr69TRh3vpHJVMfZSTxpdPQH0ri5-lotPfTw-cJYsdAQeco3mkfhPzNnEyLiQxy4kSjTnE1e6j886D0LHF31N9cJY4DOJ5zw7pVvlp5qtPVOl_OjT8BHPMJy8enxkvzX2evRd6LnOCALtfsnH-meXb3lozp0zS4ZqCwh6AYo-B6uxPjboAd89V0PaTO_ThtAE_FT6_potH-AXTj05Ey_n4Lam5etKUdbwH85jXGtyYTrzGZLTi08YcB321OEKGHO75f_MkoPl2e4HKgAmmiW68soBWS8s7yHzhKSF8JVDoEzacIbHuSmbwVPyhHKEz1j6rfPsnDbI0TBxk-QchcqCvq_RToPUPiuRWbVKc8aa-9HHK1Xc7wbvHMVJWkiERNC3Ha6nAN5rHulnE12Qb8pZXR-jKGRYUqn44iTyLRbceGqrxLwCiPxNm03xHKv2UUUrXZwc5ri0LPBWDn0typIdpAy2LymYTV7ZEAUD3r4KzI3OqsswvCguvBzlMwJ2q4NO14GZqhin4pt2UJNTMy6qhuA3AXX4HdXkE7s8v4rCtVmyzHv8DP6X7D9nCgjHnw43KH6oTCNDHqgGYOEeVFJ3Ghi6oTSE2VbQHTsHC4YGeKOS8W1cq6IozTDuy3Cz7tMP9rTGMscNThkkJYuDaLVdg=","internal_chat_message_metadata_passthrough":{"turn_id":"f878fb4b-0d9a-4a17-adc6-f6c9f4deeea0"},"summary":[{"type":"summary_text","text":"**Waiting on resize broker**"}],"metadata":{"turn_id":"f878fb4b-0d9a-4a17-adc6-f6c9f4deeea0"}},{"id":"fc_09b01b5279447709016aa9f8700ee087d2a7463a4b96b643d4","type":"function_call","status":"completed","arguments":"{\"i\":\"Reporting replay candidate and retry gap\",\"op\":\"send\",\"to\":\"Main\",\"message\":\"Source-backed candidate: attach.rs754-755 still flushes replayed pending_input via ack=true send_effect, unlike normal no_ack at674; synchronous write-only batch on same receiving conn can stop drains while broker emits Applied (broker8930-8936) behind shared stream/controller output. Not proven; ~13 baseline tag submissions alone don't establish sufficient replay volume. Critical observed refinement: all replacement stream poisons say LIVE write failed, not replay failure => stream subscriber replay writer completed (nethost217-227). os233 outcomes do NOT trigger SeatBlocked breaker; dispatch373-383 +503-545 make attempts0/1/2 transient then terminal. Thus successful conn retirement + retry can reproduce consumer problem thrice then abandon stream. Full source report follows.\"}","call_id":"call_Gvcgb0nreHr9Q77JvDaXzKiB","internal_chat_message_metadata_passthrough":{"create_time":1789524066.653444,"turn_id":"f878fb4b-0d9a-4a17-adc6-f6c9f4deeea0"},"name":"hub","metadata":{"turn_id":"f878fb4b-0d9a-4a17-adc6-f6c9f4deeea0"}}]},"duration":14535.629699999932,"ttft":5184.13599999994,"completedAt":1789524080823,"contextSnapshot":{"promptTokens":128954,"nonMessageTokens":10480,"compactionEpoch":0}}}
{"type":"message","id":"c656bd95","parentId":"19d5cb13","timestamp":"2026-09-16T02:01:20.827Z","message":{"role":"toolResult","toolCallId":"call_Gvcgb0nreHr9Q77JvDaXzKiB|fc_09b01b5279447709016aa9f8700ee087d2a7463a4b96b643d4","toolName":"hub","content":[{"type":"text","text":"Delivered to 1 peer(s):\n- Main: injected"}],"details":{"op":"send","from":"AttachReplayRca","to":"Main","receipts":[{"to":"Main","outcome":"injected"}]},"isError":false,"timestamp":1789524080826}}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_nUZ3dowOmxwQUnsbASgYuCdI|fc_09b01b5279447709016aa9f875178087d2a7e49607377c32ba","toolName":"yield","startedAt":"2026-09-16T02:03:18.429Z"},"id":"557174f5","parentId":"c656bd95","timestamp":"2026-09-16T02:03:18.429Z"}
{"type":"message","id":"a60da11a","parentId":"557174f5","timestamp":"2026-09-16T02:03:18.430Z","message":{"role":"assistant","content":[{"type":"toolCall","id":"call_nUZ3dowOmxwQUnsbASgYuCdI|fc_09b01b5279447709016aa9f875178087d2a7e49607377c32ba","name":"yield","arguments":{"type":null,"data":{"summary":"W1c proves replacement attach workers re-enter the existing stream, seat successfully, then lose their shared receiving carrier at the 15-second write bound. It does not identify the worker's blocked instruction. Strongest concrete consumer candidate is replay-input flushing with ack=true on the receiving connection; a separate outbound forwarding wait remains a competing candidate. The observed os233 failures take the ordinary three-attempt retry path, not the seat-blocked circuit breaker.","files":[{"path":"crates/spt-daemon/src/attach.rs","description":"Attach reconstruction, separate wire connection, replay handling, pending-input ack discrepancy, output forwarding."},{"path":"crates/spt-daemon/src/brain.rs","description":"Send-only versus request/reply APIs; blocking write_frame carrier; separate stream/session cursors."},{"path":"crates/spt-daemon/src/dispatch.rs","description":"Pinned opener classification, fresh worker creation, ring-floor subscription, failure classification and retry terminalization."},{"path":"crates/spt-daemon/src/nethost.rs","description":"Durable stream replay, independently renewed subscriber lease, replay-before-live writer, bounded send_stream bridge."},{"path":"crates/spt-daemon/src/broker.rs","description":"Subscribe reply ordering, input effect dedup and optional Applied acknowledgement, idempotent same-connection establish."},{"path":"crates/spt-daemon/tests/attach.rs","description":"Existing prepopulated-ring and manually orchestrated two-input restart scenarios."},{"path":"crates/spt-daemon/tests/redispatch.rs","description":"Real dispatcher-generation restart with an eight-chunk rolled stream ring."},{"path":"crates/spt-daemon/tests/redispatch_stall.rs","description":"Tests for deliberately wedged subscriber retirement, producer isolation, lease renewal, and classified retry."},{"path":".spt/preserved/307/hertz-w1bc/w1c-run1/home-w1c/logs/daemon.stderr.log","description":"Actual daemon evidence: initial retirement, successful replacement subscriptions, three timed poisons and os233 worker outcomes."},{"path":".spt/preserved/307/hertz-w1bc/w1c-run1/events.jsonl","description":"Input submission, refresh timing and fresh numeric network-canary observations."}],"architecture":"A dispatcher worker cold-starts its receiving Brain, subscribes to the existing inbound stream's retained floor, seeds the pinned Request, and subscribes to session output on that same IPC connection. A second Brain forwards output onto the held stream. Stream and controller writers share the receiving connection; the one serve thread alternates reading that connection and synchronously writing commands. NetHost owns durable stream history and generation-local subscriber leases independently of brain lifetimes.","report":"## Scope and evidence status\nRead-only investigation only: no edits, runtime commands, tests, builds, or live probes. No LSP tool was exposed; navigation used source search and line reads. Runtime facts below come from preserved artifacts or the supplied W1c observations, not a newly executed experiment. All causal mechanisms remain RCA CANDIDATES.\n\n## Observed W1c sequence\nActual log: `.spt/preserved/307/hertz-w1bc/w1c-run1/home-w1c/logs/daemon.stderr.log`.\n- Lines 45–54: planned brain restart; old controller conn17 closes at wall_ms1789523803471 with cause=detach; organic BrokenPipe retirement, then transport-close. This is not evidence that an old conn17 poison remained installed throughout the replacement attempts.\n- Lines 65–70: replacement conn70 subscribes stream1 from_seq=0 and seats session1. It processes the original generation1789523756051 Request twice: first decision=controller, then decision=idempotent. Conn88 repeats this at81–86; conn104 at96–101.\n- Lines72–80,87–95,102–110: each fresh connection times out at approximately15 seconds; stream-sub-writer-poison explicitly says `live write failed`; controller writer exits TimedOut; slot closes cause=detach; worker reports os233. Worker elapsed_ms values are15037,15041,15052, attempts0,1,2.\n- IMPORTANT discriminator: `live write failed` comes from nethost.rs225–227, reached only AFTER replay iteration217–223 completed. This rules against the narrower statement 'this subscriber writer is still blocked writing its initial replay'. It does NOT prove the brain application consumed all replay records: frames may have reached IPC buffers while application handling fell behind.\n- events.jsonl113 records baseline tag022 submission;114 ends the45-second baseline;116 onward starts refresh;135,138,143,146,151 show fresh numeric canaries and zero active dial tasks while conn70 is seated/stalling. Example135: canary_age23ms, active_dial_tasks0, query_elapsed0. The supplied child ledger/receipt observations establish that baseline input reached the child and subsequent live input did not. Submission events alone would not prove child receipt.\n- The supplied raw-output observation is that each replacement can produce a screen snapshot but no continuing live stream. No source claim below treats that snapshot as successful full-duplex recovery.\n\n## Exact replacement-worker path\n1. dispatch.rs702–709 establishes a new dispatcher connection and fresh claims map per generation. Existing broker-owned inbound streams are enumerated; locally initiated/empty rows are excluded at733–738.\n2. worker1034–1108 queries/classifies the opener, excludes finished Attach rows, then opens a fresh serving Brain. first_line927–948 prefers the broker-pinned opener; only explicit unknown-verb allows the older-broker replay-peek fallback. Thus ordinary transport failure does not intentionally manufacture a peek subscriber.\n3. Attach branch1177–1200 resolves endpoint/session BEFORE subscription. This avoids a sessions() request/reply consuming interleaved attach events. At1209–1219 it calls serve_attach with the table's floor_seq plus the pinned Request.\n4. attach.rs483 sends net_stream_subscribe. nethost.rs545–602 snapshots retained frames from the requested floor and installs a writer with a fresh lease. Its writer sends all replay frames, then live frames, in that order (217–227).\n5. attach.rs501 opens an independent wire Brain. At537–568 the pinned Request seeds the same handler used for wire Requests. handle_attach_request420–439 sends the session subscribe and sets attached=true. The replayed Request can trigger the same handler again at621–648.\n6. brain.rs1453–1479 sets session_id/cursor, enables cold-output baselining for from_seq0 and sends subscribe. It does not wait for Subscribed. subscribe_with2511–2551 and net_stream_subscribe2384–2395 are send-only.\n7. Broker dispatch_subscribe8790–8806 resolves the controller seat, then sends Subscribed on the same receiving SharedSend. The duplicate nonzero-generation establish on the SAME conn is idempotent at broker.rs3193–3230: it returns Controller without replacing the writer or producing a second initial batch. W1c's idempotent breadcrumbs show this prior fix's intended branch is reached.\n8. The serve loop reads via read_event_until or controller gap-resume (attach.rs570–610). Incoming stream Input before role confirmation is buffered(680–682); after Controller confirmation it is forwarded with send_effect_no_ack(671–677). Subscribed handling sets role then invokes feed_rest and flushes pending_input(734–755).\n9. Output forwarding is gated by attached, NOT confirmed role (attach.rs890–899). Therefore one cold snapshot can be forwarded before the Subscribed branch and its pending-input work finish. One snapshot does not establish that the worker reached a sustainable read loop.\n\n## Ranked candidates and distinguishing predictions\n### 1. Replay-input batch creates a receiving-connection write/read cycle — strongest concrete source discrepancy, not proven\nSource: attach.rs754–755 flushes every pending_input using `brain.send_effect(...)`; brain.rs921–923 selects ack=true. This differs from the confirmed-controller path's explicit no-ack operation at attach.rs674–677 / brain.rs934–935. Both are synchronous writes, not acknowledgement waits: send_effect_inner943–957 calls send, and send2554–2559 directly calls write_frame.\n\nBroker input dedups the old operator operation IDs but still sends Applied when ack=true (broker.rs8898–8936). Thus already-applied history is not necessarily traffic-free. A replacement can buffer historical Input before Subscribed, then issue a batch of request writes without returning to the receiving read loop. If its incoming IPC writes back up while the broker handler is blocked sending Applied or another reply behind stream/controller output, the worker cannot drain the receiving connection. Its independently fed stream/controller writers then hit the15-second carrier bound. A pre-Subscribed output snapshot remains compatible with this cycle.\n\nWhy refresh-specific: a cold initial attach has little historical input; replacement starts from retained stream floor0 again, not the previous worker's net_cursor. Every retry can reconstruct the same backlog. The broker's effect journal prevents double typing but does not prevent these replay requests or requested duplicate acknowledgements.\n\nCritical limitation: the artifacts examined do not expose pending_input length, acknowledgement count, pipe occupancy, or a worker stack. The roughly thirteen baseline tag submissions visible in events are NOT sufficient by themselves to prove that the batch fills a pipe; actual Input record fragmentation and scheduling matter. Do not label this established deadlock.\n\nFalsifiable predictions: during the stall, the worker is in write_frame reached from pending_input flush; broker handler is at an Applied reply or another receiving-conn reply; pending_input was nonempty; application read_event progress stops at that flush. If pending_input is empty on every attempt, or the worker is instead parked in outbound wire forwarding/read_event, this specific mechanism is false. In an authorized later trial, retaining equivalent PTY output but removing pre-refresh input history should weaken this candidate; a fresh operator stream with no history should distinguish it from a history-independent egress fault. These are predictions, not executed changes.\n\n### 2. A synchronous outbound forwarding write stops the sole receive loop — competing candidate\nattach.rs899 calls wire.net_stream_send(None); brain.rs2108–2120 writes its IPC command synchronously and returns without NetSent waiting. Broker dispatch_net_stream_send9832–9835 calls NetHost.send_stream directly; nethost.rs1912–1921 enters bounded_block_on, waits for the stream send mutex, then write_all/finish. The two-connection split removes the old same-handler output-forwarding cycle but does not make the serving thread itself asynchronous. If the wire connection's handler stops consuming commands, the serve thread can block on a subsequent wire write and cease reading its separate receiver. A snapshot can fit through before backlog develops.\n\nFresh canary is compatible with a yielding per-stream mutex/transport wait or ordinary blocking IPC on another thread. It argues against net-runtime-wide starvation, not against every individual stream wait. active_dial_tasks0 narrows away active dial congestion, not stream-send work.\n\nLimits: ordinary stream pumps are bounded-overwrite, not the retentive shell-tunnel wait (nethost.rs1132–1137); send_stream has a10-second async-operation timeout(nethost.rs59–73,1469–1479). Therefore an unbounded 'QUIC await' is not a supported claim here. The proposed cycle needs evidence of blocked wire IPC/handler, repeated bounded operations, or an error reply blocking the undrained wire side; current log attribution points to the receiving conn, not a demonstrated wire failure.\n\nPredictions: worker stack is at wire.net_stream_send/write_frame, pending-input flush already finished or never entered; wire handler is in send_stream or reporting its failure; no more read_event calls occur on conn70. A worker demonstrably continuing to read receiving events through the15-second window would falsify this simple sole-reader-stop model.\n\n### 3. Pure cursor/duplicate-establish explanation — lower-ranked and insufficient alone\nbrain.rs1311–1336 performs stream dedup/forward-gap rejection; attach_as_coded resets the session cursor to from_seq0 and baseline flag(1464–1471). A replayed opener invokes that reset even when the broker preserves the existing same-conn writer. That is worth correlating with decoded output, but a cursor mistake alone would ordinarily leave the worker reading/dropping events or produce an explicit stream/output gap, not a15-second non-draining carrier timeout. W1c has os233 after poison, not a logged gap. The old 'same Request replaces its own controller writer' account is specifically contradicted by decision=idempotent and broker3193–3230.\n\nPrediction: a pure cursor issue shows continued read_event throughput with discarded/misbaselined output, or an explicit gap error, rather than a stalled synchronous write. Treat it as a potential contributor only if those facts appear.\n\n## Replay and acknowledgement facts that prevent misleading RCA\n- There is no NetSent acknowledgement wait on ordinary attach output: op=None exits net_stream_send at2118–2120. The journaled wait loop2124–2130 does discard unrelated events, but it is NOT the normal forwarding branch.\n- send_effect(ack=true) is not a synchronous wait-for-Applied API. Its danger here is generated reply traffic and a write-only batch, not a hidden `recv(Applied)` call.\n- NetStreamData consumption advances the local cursor at brain1330, with no consumption acknowledgement in that branch. New dispatcher workers subscribe from retained floor(dispatch1215), not a persisted per-worker read cursor. Stream retention plus PTY effect dedup supports replay, but does not inherently bound replay-side request traffic.\n- A fresh StreamLease is minted on every subscriber installation(nethost580–600). Old-writer death should cancel only the old lease. 'The original conn17 failure permanently canceled all successor leases' is not supported by current source.\n- Module comments describing controller replay as inline/synchronous in attach.rs484–500 are historical context, not proof of current controller writer implementation. Do not rebuild that old mechanism merely from those comments.\n\n## Why prior fixes can be working without curing this W1c failure\n1. Physical connection poisoning bounds a non-draining carrier; the W1c logs show retirement and replacement, so it is containing each incident. It does not force the replacement serve thread to consume.\n2. Async StreamLog subscriber writers plus fail-first halt remove replay-under-log-lock producer stalls and serial writes past a dead conn(nethost189–242). LIVE failure in W1c demonstrates the replacement reached beyond replay writing; it does not demonstrate healthy application drain.\n3. Fresh leases prevent a predecessor's delayed failure canceling a successor(nethost580–600), but a successor can poison its OWN lease if it stops draining.\n4. Pinned opener fixes classification after ring roll; the two-conn split fixes a specific forwarding/receive-handler coupling; idempotent same-conn establish preserves the controller writer. None changes pending_input's ack=true flush or removes synchronous writes from the sole serve thread.\n5. Crucial retry mismatch: classify_failure(dispatch373–383) recognizes only 'subscriber busy', 'replay halted', 'lease canceled' as SeatBlocked. Observed `No process is on the other end of the pipe. (os error233)` matches none, so it is Transient. outcome_transition503–545 increments attempts, waits500ms then1000ms via349–350, and becomes Terminal at MAX_DISPATCH_ATTEMPTS3(343). W1c attempts0/1/2 and spacing match that path. The seat-blocked global breaker is NOT demonstrated by these failures. Consequently three successful carrier replacements can each hit the same consumer problem and then leave the active stream unclaimed for that dispatcher generation. The next dispatcher generation recreates its claims map, allowing the cycle again.\n\n## What matching tests cover, and what they do not establish\n- tests/attach.rs547–650: prepopulated PTY ring, fresh loopback attach, final TICK39 rendered, then detach. This checks initial screen delivery, not sustained recovery of an old stream carrying a substantial input history.\n- tests/attach.rs867–1032: restart exactly-once test hand-steps life1, submits one old and one dead-window input, then life2 serve_attach; its seed_request is None. It is useful edge-idempotency coverage but not the production pinned-opener-plus-replayed-opener ordering under real rc traffic.\n- tests/redispatch.rs579–678: production dispatcher restart after shrinking the stream ring to8 chunks and rolling the opener out with40 inputs. It verifies pinned classification and MARK-B input/output recovery, but deliberately removes the full old input history and original Request from retained replay. W1c instead logs floor0 and duplicate Request handling on every attempt.\n- tests/redispatch_stall.rs332,415,546,607 identify tests for deliberately wedged subscribers, lease cancellation, opener failure, and injected SeatBlocked retry. Those contracts can all hold while a reconstructed real attach consumer stalls itself; os233 is a different classification from the injected subscriber-busy case.\n- tests/attach_idempotent_replay.rs17–30 and broker3193–3230 address same-connection duplicate establish without re-synthesizing history. W1c's idempotent decision is evidence against claiming that previously fixed writer-replacement mechanism has been reproven here.\n\n## Bottom line\nThe strongest defensible RCA candidate is: refresh reconstructs the SAME held attach and retained input history; a synchronous operation in that replacement's sole consumer thread stops draining the shared stream/controller IPC carrier;15-second conn poison contains the damage, but ordinary os233 retries reconstruct the same conditions three times and then terminalize the claim. The pending-input ack=true batch is the most specific remaining source-backed suspect, not a proven cause. The missing discriminator is the receiving worker's exact blocked call plus pending-input/read progress, not another global canary. Nothing in this analysis answers Q3; a real signed pending trial remains separate."},"error":null}}],"api":"openai-codex-responses","provider":"openai-codex","model":"gpt-6-astra","usage":{"input":469,"output":3820,"cacheRead":128768,"cacheWrite":0,"totalTokens":133057,"cost":{"input":0.004690000000000001,"output":0.191,"cacheRead":0.128768,"cacheWrite":0,"total":0.324458}},"stopReason":"toolUse","timestamp":1789524080839,"responseId":"resp_09b01b5279447709016aa9f8711c4487d2bc8e2ec2b9ad6687","providerPayload":{"type":"openaiResponsesHistory","provider":"openai-codex","dt":true,"items":[{"id":"fc_09b01b5279447709016aa9f875178087d2a7e49607377c32ba","type":"function_call","status":"completed","arguments":"{\"type\":null,\"data\":{\"summary\":\"W1c proves replacement attach workers re-enter the existing stream, seat successfully, then lose their shared receiving carrier at the 15-second write bound. It does not identify the worker's blocked instruction. Strongest concrete consumer candidate is replay-input flushing with ack=true on the receiving connection; a separate outbound forwarding wait remains a competing candidate. The observed os233 failures take the ordinary three-attempt retry path, not the seat-blocked circuit breaker.\",\"files\":[{\"path\":\"crates/spt-daemon/src/attach.rs\",\"description\":\"Attach reconstruction, separate wire connection, replay handling, pending-input ack discrepancy, output forwarding.\"},{\"path\":\"crates/spt-daemon/src/brain.rs\",\"description\":\"Send-only versus request/reply APIs; blocking write_frame carrier; separate stream/session cursors.\"},{\"path\":\"crates/spt-daemon/src/dispatch.rs\",\"description\":\"Pinned opener classification, fresh worker creation, ring-floor subscription, failure classification and retry terminalization.\"},{\"path\":\"crates/spt-daemon/src/nethost.rs\",\"description\":\"Durable stream replay, independently renewed subscriber lease, replay-before-live writer, bounded send_stream bridge.\"},{\"path\":\"crates/spt-daemon/src/broker.rs\",\"description\":\"Subscribe reply ordering, input effect dedup and optional Applied acknowledgement, idempotent same-connection establish.\"},{\"path\":\"crates/spt-daemon/tests/attach.rs\",\"description\":\"Existing prepopulated-ring and manually orchestrated two-input restart scenarios.\"},{\"path\":\"crates/spt-daemon/tests/redispatch.rs\",\"description\":\"Real dispatcher-generation restart with an eight-chunk rolled stream ring.\"},{\"path\":\"crates/spt-daemon/tests/redispatch_stall.rs\",\"description\":\"Tests for deliberately wedged subscriber retirement, producer isolation, lease renewal, and classified retry.\"},{\"path\":\".spt/preserved/307/hertz-w1bc/w1c-run1/home-w1c/logs/daemon.stderr.log\",\"description\":\"Actual daemon evidence: initial retirement, successful replacement subscriptions, three timed poisons and os233 worker outcomes.\"},{\"path\":\".spt/preserved/307/hertz-w1bc/w1c-run1/events.jsonl\",\"description\":\"Input submission, refresh timing and fresh numeric network-canary observations.\"}],\"architecture\":\"A dispatcher worker cold-starts its receiving Brain, subscribes to the existing inbound stream's retained floor, seeds the pinned Request, and subscribes to session output on that same IPC connection. A second Brain forwards output onto the held stream. Stream and controller writers share the receiving connection; the one serve thread alternates reading that connection and synchronously writing commands. NetHost owns durable stream history and generation-local subscriber leases independently of brain lifetimes.\",\"report\":\"## Scope and evidence status\\nRead-only investigation only: no edits, runtime commands, tests, builds, or live probes. No LSP tool was exposed; navigation used source search and line reads. Runtime facts below come from preserved artifacts or the supplied W1c observations, not a newly executed experiment. All causal mechanisms remain RCA CANDIDATES.\\n\\n## Observed W1c sequence\\nActual log: `.spt/preserved/307/hertz-w1bc/w1c-run1/home-w1c/logs/daemon.stderr.log`.\\n- Lines 45–54: planned brain restart; old controller conn17 closes at wall_ms1789523803471 with cause=detach; organic BrokenPipe retirement, then transport-close. This is not evidence that an old conn17 poison remained installed throughout the replacement attempts.\\n- Lines 65–70: replacement conn70 subscribes stream1 from_seq=0 and seats session1. It processes the original generation1789523756051 Request twice: first decision=controller, then decision=idempotent. Conn88 repeats this at81–86; conn104 at96–101.\\n- Lines72–80,87–95,102–110: each fresh connection times out at approximately15 seconds; stream-sub-writer-poison explicitly says `live write failed`; controller writer exits TimedOut; slot closes cause=detach; worker reports os233. Worker elapsed_ms values are15037,15041,15052, attempts0,1,2.\\n- IMPORTANT discriminator: `live write failed` comes from nethost.rs225–227, reached only AFTER replay iteration217–223 completed. This rules against the narrower statement 'this subscriber writer is still blocked writing its initial replay'. It does NOT prove the brain application consumed all replay records: frames may have reached IPC buffers while application handling fell behind.\\n- events.jsonl113 records baseline tag022 submission;114 ends the45-second baseline;116 onward starts refresh;135,138,143,146,151 show fresh numeric canaries and zero active dial tasks while conn70 is seated/stalling. Example135: canary_age23ms, active_dial_tasks0, query_elapsed0. The supplied child ledger/receipt observations establish that baseline input reached the child and subsequent live input did not. Submission events alone would not prove child receipt.\\n- The supplied raw-output observation is that each replacement can produce a screen snapshot but no continuing live stream. No source claim below treats that snapshot as successful full-duplex recovery.\\n\\n## Exact replacement-worker path\\n1. dispatch.rs702–709 establishes a new dispatcher connection and fresh claims map per generation. Existing broker-owned inbound streams are enumerated; locally initiated/empty rows are excluded at733–738.\\n2. worker1034–1108 queries/classifies the opener, excludes finished Attach rows, then opens a fresh serving Brain. first_line927–948 prefers the broker-pinned opener; only explicit unknown-verb allows the older-broker replay-peek fallback. Thus ordinary transport failure does not intentionally manufacture a peek subscriber.\\n3. Attach branch1177–1200 resolves endpoint/session BEFORE subscription. This avoids a sessions() request/reply consuming interleaved attach events. At1209–1219 it calls serve_attach with the table's floor_seq plus the pinned Request.\\n4. attach.rs483 sends net_stream_subscribe. nethost.rs545–602 snapshots retained frames from the requested floor and installs a writer with a fresh lease. Its writer sends all replay frames, then live frames, in that order (217–227).\\n5. attach.rs501 opens an independent wire Brain. At537–568 the pinned Request seeds the same handler used for wire Requests. handle_attach_request420–439 sends the session subscribe and sets attached=true. The replayed Request can trigger the same handler again at621–648.\\n6. brain.rs1453–1479 sets session_id/cursor, enables cold-output baselining for from_seq0 and sends subscribe. It does not wait for Subscribed. subscribe_with2511–2551 and net_stream_subscribe2384–2395 are send-only.\\n7. Broker dispatch_subscribe8790–8806 resolves the controller seat, then sends Subscribed on the same receiving SharedSend. The duplicate nonzero-generation establish on the SAME conn is idempotent at broker.rs3193–3230: it returns Controller without replacing the writer or producing a second initial batch. W1c's idempotent breadcrumbs show this prior fix's intended branch is reached.\\n8. The serve loop reads via read_event_until or controller gap-resume (attach.rs570–610). Incoming stream Input before role confirmation is buffered(680–682); after Controller confirmation it is forwarded with send_effect_no_ack(671–677). Subscribed handling sets role then invokes feed_rest and flushes pending_input(734–755).\\n9. Output forwarding is gated by attached, NOT confirmed role (attach.rs890–899). Therefore one cold snapshot can be forwarded before the Subscribed branch and its pending-input work finish. One snapshot does not establish that the worker reached a sustainable read loop.\\n\\n## Ranked candidates and distinguishing predictions\\n### 1. Replay-input batch creates a receiving-connection write/read cycle — strongest concrete source discrepancy, not proven\\nSource: attach.rs754–755 flushes every pending_input using `brain.send_effect(...)`; brain.rs921–923 selects ack=true. This differs from the confirmed-controller path's explicit no-ack operation at attach.rs674–677 / brain.rs934–935. Both are synchronous writes, not acknowledgement waits: send_effect_inner943–957 calls send, and send2554–2559 directly calls write_frame.\\n\\nBroker input dedups the old operator operation IDs but still sends Applied when ack=true (broker.rs8898–8936). Thus already-applied history is not necessarily traffic-free. A replacement can buffer historical Input before Subscribed, then issue a batch of request writes without returning to the receiving read loop. If its incoming IPC writes back up while the broker handler is blocked sending Applied or another reply behind stream/controller output, the worker cannot drain the receiving connection. Its independently fed stream/controller writers then hit the15-second carrier bound. A pre-Subscribed output snapshot remains compatible with this cycle.\\n\\nWhy refresh-specific: a cold initial attach has little historical input; replacement starts from retained stream floor0 again, not the previous worker's net_cursor. Every retry can reconstruct the same backlog. The broker's effect journal prevents double typing but does not prevent these replay requests or requested duplicate acknowledgements.\\n\\nCritical limitation: the artifacts examined do not expose pending_input length, acknowledgement count, pipe occupancy, or a worker stack. The roughly thirteen baseline tag submissions visible in events are NOT sufficient by themselves to prove that the batch fills a pipe; actual Input record fragmentation and scheduling matter. Do not label this established deadlock.\\n\\nFalsifiable predictions: during the stall, the worker is in write_frame reached from pending_input flush; broker handler is at an Applied reply or another receiving-conn reply; pending_input was nonempty; application read_event progress stops at that flush. If pending_input is empty on every attempt, or the worker is instead parked in outbound wire forwarding/read_event, this specific mechanism is false. In an authorized later trial, retaining equivalent PTY output but removing pre-refresh input history should weaken this candidate; a fresh operator stream with no history should distinguish it from a history-independent egress fault. These are predictions, not executed changes.\\n\\n### 2. A synchronous outbound forwarding write stops the sole receive loop — competing candidate\\nattach.rs899 calls wire.net_stream_send(None); brain.rs2108–2120 writes its IPC command synchronously and returns without NetSent waiting. Broker dispatch_net_stream_send9832–9835 calls NetHost.send_stream directly; nethost.rs1912–1921 enters bounded_block_on, waits for the stream send mutex, then write_all/finish. The two-connection split removes the old same-handler output-forwarding cycle but does not make the serving thread itself asynchronous. If the wire connection's handler stops consuming commands, the serve thread can block on a subsequent wire write and cease reading its separate receiver. A snapshot can fit through before backlog develops.\\n\\nFresh canary is compatible with a yielding per-stream mutex/transport wait or ordinary blocking IPC on another thread. It argues against net-runtime-wide starvation, not against every individual stream wait. active_dial_tasks0 narrows away active dial congestion, not stream-send work.\\n\\nLimits: ordinary stream pumps are bounded-overwrite, not the retentive shell-tunnel wait (nethost.rs1132–1137); send_stream has a10-second async-operation timeout(nethost.rs59–73,1469–1479). Therefore an unbounded 'QUIC await' is not a supported claim here. The proposed cycle needs evidence of blocked wire IPC/handler, repeated bounded operations, or an error reply blocking the undrained wire side; current log attribution points to the receiving conn, not a demonstrated wire failure.\\n\\nPredictions: worker stack is at wire.net_stream_send/write_frame, pending-input flush already finished or never entered; wire handler is in send_stream or reporting its failure; no more read_event calls occur on conn70. A worker demonstrably continuing to read receiving events through the15-second window would falsify this simple sole-reader-stop model.\\n\\n### 3. Pure cursor/duplicate-establish explanation — lower-ranked and insufficient alone\\nbrain.rs1311–1336 performs stream dedup/forward-gap rejection; attach_as_coded resets the session cursor to from_seq0 and baseline flag(1464–1471). A replayed opener invokes that reset even when the broker preserves the existing same-conn writer. That is worth correlating with decoded output, but a cursor mistake alone would ordinarily leave the worker reading/dropping events or produce an explicit stream/output gap, not a15-second non-draining carrier timeout. W1c has os233 after poison, not a logged gap. The old 'same Request replaces its own controller writer' account is specifically contradicted by decision=idempotent and broker3193–3230.\\n\\nPrediction: a pure cursor issue shows continued read_event throughput with discarded/misbaselined output, or an explicit gap error, rather than a stalled synchronous write. Treat it as a potential contributor only if those facts appear.\\n\\n## Replay and acknowledgement facts that prevent misleading RCA\\n- There is no NetSent acknowledgement wait on ordinary attach output: op=None exits net_stream_send at2118–2120. The journaled wait loop2124–2130 does discard unrelated events, but it is NOT the normal forwarding branch.\\n- send_effect(ack=true) is not a synchronous wait-for-Applied API. Its danger here is generated reply traffic and a write-only batch, not a hidden `recv(Applied)` call.\\n- NetStreamData consumption advances the local cursor at brain1330, with no consumption acknowledgement in that branch. New dispatcher workers subscribe from retained floor(dispatch1215), not a persisted per-worker read cursor. Stream retention plus PTY effect dedup supports replay, but does not inherently bound replay-side request traffic.\\n- A fresh StreamLease is minted on every subscriber installation(nethost580–600). Old-writer death should cancel only the old lease. 'The original conn17 failure permanently canceled all successor leases' is not supported by current source.\\n- Module comments describing controller replay as inline/synchronous in attach.rs484–500 are historical context, not proof of current controller writer implementation. Do not rebuild that old mechanism merely from those comments.\\n\\n## Why prior fixes can be working without curing this W1c failure\\n1. Physical connection poisoning bounds a non-draining carrier; the W1c logs show retirement and replacement, so it is containing each incident. It does not force the replacement serve thread to consume.\\n2. Async StreamLog subscriber writers plus fail-first halt remove replay-under-log-lock producer stalls and serial writes past a dead conn(nethost189–242). LIVE failure in W1c demonstrates the replacement reached beyond replay writing; it does not demonstrate healthy application drain.\\n3. Fresh leases prevent a predecessor's delayed failure canceling a successor(nethost580–600), but a successor can poison its OWN lease if it stops draining.\\n4. Pinned opener fixes classification after ring roll; the two-conn split fixes a specific forwarding/receive-handler coupling; idempotent same-conn establish preserves the controller writer. None changes pending_input's ack=true flush or removes synchronous writes from the sole serve thread.\\n5. Crucial retry mismatch: classify_failure(dispatch373–383) recognizes only 'subscriber busy', 'replay halted', 'lease canceled' as SeatBlocked. Observed `No process is on the other end of the pipe. (os error233)` matches none, so it is Transient. outcome_transition503–545 increments attempts, waits500ms then1000ms via349–350, and becomes Terminal at MAX_DISPATCH_ATTEMPTS3(343). W1c attempts0/1/2 and spacing match that path. The seat-blocked global breaker is NOT demonstrated by these failures. Consequently three successful carrier replacements can each hit the same consumer problem and then leave the active stream unclaimed for that dispatcher generation. The next dispatcher generation recreates its claims map, allowing the cycle again.\\n\\n## What matching tests cover, and what they do not establish\\n- tests/attach.rs547–650: prepopulated PTY ring, fresh loopback attach, final TICK39 rendered, then detach. This checks initial screen delivery, not sustained recovery of an old stream carrying a substantial input history.\\n- tests/attach.rs867–1032: restart exactly-once test hand-steps life1, submits one old and one dead-window input, then life2 serve_attach; its seed_request is None. It is useful edge-idempotency coverage but not the production pinned-opener-plus-replayed-opener ordering under real rc traffic.\\n- tests/redispatch.rs579–678: production dispatcher restart after shrinking the stream ring to8 chunks and rolling the opener out with40 inputs. It verifies pinned classification and MARK-B input/output recovery, but deliberately removes the full old input history and original Request from retained replay. W1c instead logs floor0 and duplicate Request handling on every attempt.\\n- tests/redispatch_stall.rs332,415,546,607 identify tests for deliberately wedged subscribers, lease cancellation, opener failure, and injected SeatBlocked retry. Those contracts can all hold while a reconstructed real attach consumer stalls itself; os233 is a different classification from the injected subscriber-busy case.\\n- tests/attach_idempotent_replay.rs17–30 and broker3193–3230 address same-connection duplicate establish without re-synthesizing history. W1c's idempotent decision is evidence against claiming that previously fixed writer-replacement mechanism has been reproven here.\\n\\n## Bottom line\\nThe strongest defensible RCA candidate is: refresh reconstructs the SAME held attach and retained input history; a synchronous operation in that replacement's sole consumer thread stops draining the shared stream/controller IPC carrier;15-second conn poison contains the damage, but ordinary os233 retries reconstruct the same conditions three times and then terminalize the claim. The pending-input ack=true batch is the most specific remaining source-backed suspect, not a proven cause. The missing discriminator is the receiving worker's exact blocked call plus pending-input/read progress, not another global canary. Nothing in this analysis answers Q3; a real signed pending trial remains separate.\"},\"error\":null}","call_id":"call_nUZ3dowOmxwQUnsbASgYuCdI","internal_chat_message_metadata_passthrough":{"create_time":1789524081.774947,"turn_id":"f878fb4b-0d9a-4a17-adc6-f6c9f4deeea0"},"name":"yield","metadata":{"turn_id":"f878fb4b-0d9a-4a17-adc6-f6c9f4deeea0"}}]},"duration":117588.54360000021,"ttft":4286.662700000219,"completedAt":1789524198428,"contextSnapshot":{"promptTokens":129237,"nonMessageTokens":10480,"compactionEpoch":0}}}
{"type":"message","id":"aab1c0de","parentId":"a60da11a","timestamp":"2026-09-16T02:03:18.432Z","message":{"role":"toolResult","toolCallId":"call_nUZ3dowOmxwQUnsbASgYuCdI|fc_09b01b5279447709016aa9f875178087d2a7e49607377c32ba","toolName":"yield","content":[{"type":"text","text":"Result submitted."}],"details":{"data":{"summary":"W1c proves replacement attach workers re-enter the existing stream, seat successfully, then lose their shared receiving carrier at the 15-second write bound. It does not identify the worker's blocked instruction. Strongest concrete consumer candidate is replay-input flushing with ack=true on the receiving connection; a separate outbound forwarding wait remains a competing candidate. The observed os233 failures take the ordinary three-attempt retry path, not the seat-blocked circuit breaker.","files":[{"path":"crates/spt-daemon/src/attach.rs","description":"Attach reconstruction, separate wire connection, replay handling, pending-input ack discrepancy, output forwarding."},{"path":"crates/spt-daemon/src/brain.rs","description":"Send-only versus request/reply APIs; blocking write_frame carrier; separate stream/session cursors."},{"path":"crates/spt-daemon/src/dispatch.rs","description":"Pinned opener classification, fresh worker creation, ring-floor subscription, failure classification and retry terminalization."},{"path":"crates/spt-daemon/src/nethost.rs","description":"Durable stream replay, independently renewed subscriber lease, replay-before-live writer, bounded send_stream bridge."},{"path":"crates/spt-daemon/src/broker.rs","description":"Subscribe reply ordering, input effect dedup and optional Applied acknowledgement, idempotent same-connection establish."},{"path":"crates/spt-daemon/tests/attach.rs","description":"Existing prepopulated-ring and manually orchestrated two-input restart scenarios."},{"path":"crates/spt-daemon/tests/redispatch.rs","description":"Real dispatcher-generation restart with an eight-chunk rolled stream ring."},{"path":"crates/spt-daemon/tests/redispatch_stall.rs","description":"Tests for deliberately wedged subscriber retirement, producer isolation, lease renewal, and classified retry."},{"path":".spt/preserved/307/hertz-w1bc/w1c-run1/home-w1c/logs/daemon.stderr.log","description":"Actual daemon evidence: initial retirement, successful replacement subscriptions, three timed poisons and os233 worker outcomes."},{"path":".spt/preserved/307/hertz-w1bc/w1c-run1/events.jsonl","description":"Input submission, refresh timing and fresh numeric network-canary observations."}],"architecture":"A dispatcher worker cold-starts its receiving Brain, subscribes to the existing inbound stream's retained floor, seeds the pinned Request, and subscribes to session output on that same IPC connection. A second Brain forwards output onto the held stream. Stream and controller writers share the receiving connection; the one serve thread alternates reading that connection and synchronously writing commands. NetHost owns durable stream history and generation-local subscriber leases independently of brain lifetimes.","report":"## Scope and evidence status\nRead-only investigation only: no edits, runtime commands, tests, builds, or live probes. No LSP tool was exposed; navigation used source search and line reads. Runtime facts below come from preserved artifacts or the supplied W1c observations, not a newly executed experiment. All causal mechanisms remain RCA CANDIDATES.\n\n## Observed W1c sequence\nActual log: `.spt/preserved/307/hertz-w1bc/w1c-run1/home-w1c/logs/daemon.stderr.log`.\n- Lines 45–54: planned brain restart; old controller conn17 closes at wall_ms1789523803471 with cause=detach; organic BrokenPipe retirement, then transport-close. This is not evidence that an old conn17 poison remained installed throughout the replacement attempts.\n- Lines 65–70: replacement conn70 subscribes stream1 from_seq=0 and seats session1. It processes the original generation1789523756051 Request twice: first decision=controller, then decision=idempotent. Conn88 repeats this at81–86; conn104 at96–101.\n- Lines72–80,87–95,102–110: each fresh connection times out at approximately15 seconds; stream-sub-writer-poison explicitly says `live write failed`; controller writer exits TimedOut; slot closes cause=detach; worker reports os233. Worker elapsed_ms values are15037,15041,15052, attempts0,1,2.\n- IMPORTANT discriminator: `live write failed` comes from nethost.rs225–227, reached only AFTER replay iteration217–223 completed. This rules against the narrower statement 'this subscriber writer is still blocked writing its initial replay'. It does NOT prove the brain application consumed all replay records: frames may have reached IPC buffers while application handling fell behind.\n- events.jsonl113 records baseline tag022 submission;114 ends the45-second baseline;116 onward starts refresh;135,138,143,146,151 show fresh numeric canaries and zero active dial tasks while conn70 is seated/stalling. Example135: canary_age23ms, active_dial_tasks0, query_elapsed0. The supplied child ledger/receipt observations establish that baseline input reached the child and subsequent live input did not. Submission events alone would not prove child receipt.\n- The supplied raw-output observation is that each replacement can produce a screen snapshot but no continuing live stream. No source claim below treats that snapshot as successful full-duplex recovery.\n\n## Exact replacement-worker path\n1. dispatch.rs702–709 establishes a new dispatcher connection and fresh claims map per generation. Existing broker-owned inbound streams are enumerated; locally initiated/empty rows are excluded at733–738.\n2. worker1034–1108 queries/classifies the opener, excludes finished Attach rows, then opens a fresh serving Brain. first_line927–948 prefers the broker-pinned opener; only explicit unknown-verb allows the older-broker replay-peek fallback. Thus ordinary transport failure does not intentionally manufacture a peek subscriber.\n3. Attach branch1177–1200 resolves endpoint/session BEFORE subscription. This avoids a sessions() request/reply consuming interleaved attach events. At1209–1219 it calls serve_attach with the table's floor_seq plus the pinned Request.\n4. attach.rs483 sends net_stream_subscribe. nethost.rs545–602 snapshots retained frames from the requested floor and installs a writer with a fresh lease. Its writer sends all replay frames, then live frames, in that order (217–227).\n5. attach.rs501 opens an independent wire Brain. At537–568 the pinned Request seeds the same handler used for wire Requests. handle_attach_request420–439 sends the session subscribe and sets attached=true. The replayed Request can trigger the same handler again at621–648.\n6. brain.rs1453–1479 sets session_id/cursor, enables cold-output baselining for from_seq0 and sends subscribe. It does not wait for Subscribed. subscribe_with2511–2551 and net_stream_subscribe2384–2395 are send-only.\n7. Broker dispatch_subscribe8790–8806 resolves the controller seat, then sends Subscribed on the same receiving SharedSend. The duplicate nonzero-generation establish on the SAME conn is idempotent at broker.rs3193–3230: it returns Controller without replacing the writer or producing a second initial batch. W1c's idempotent breadcrumbs show this prior fix's intended branch is reached.\n8. The serve loop reads via read_event_until or controller gap-resume (attach.rs570–610). Incoming stream Input before role confirmation is buffered(680–682); after Controller confirmation it is forwarded with send_effect_no_ack(671–677). Subscribed handling sets role then invokes feed_rest and flushes pending_input(734–755).\n9. Output forwarding is gated by attached, NOT confirmed role (attach.rs890–899). Therefore one cold snapshot can be forwarded before the Subscribed branch and its pending-input work finish. One snapshot does not establish that the worker reached a sustainable read loop.\n\n## Ranked candidates and distinguishing predictions\n### 1. Replay-input batch creates a receiving-connection write/read cycle — strongest concrete source discrepancy, not proven\nSource: attach.rs754–755 flushes every pending_input using `brain.send_effect(...)`; brain.rs921–923 selects ack=true. This differs from the confirmed-controller path's explicit no-ack operation at attach.rs674–677 / brain.rs934–935. Both are synchronous writes, not acknowledgement waits: send_effect_inner943–957 calls send, and send2554–2559 directly calls write_frame.\n\nBroker input dedups the old operator operation IDs but still sends Applied when ack=true (broker.rs8898–8936). Thus already-applied history is not necessarily traffic-free. A replacement can buffer historical Input before Subscribed, then issue a batch of request writes without returning to the receiving read loop. If its incoming IPC writes back up while the broker handler is blocked sending Applied or another reply behind stream/controller output, the worker cannot drain the receiving connection. Its independently fed stream/controller writers then hit the15-second carrier bound. A pre-Subscribed output snapshot remains compatible with this cycle.\n\nWhy refresh-specific: a cold initial attach has little historical input; replacement starts from retained stream floor0 again, not the previous worker's net_cursor. Every retry can reconstruct the same backlog. The broker's effect journal prevents double typing but does not prevent these replay requests or requested duplicate acknowledgements.\n\nCritical limitation: the artifacts examined do not expose pending_input length, acknowledgement count, pipe occupancy, or a worker stack. The roughly thirteen baseline tag submissions visible in events are NOT sufficient by themselves to prove that the batch fills a pipe; actual Input record fragmentation and scheduling matter. Do not label this established deadlock.\n\nFalsifiable predictions: during the stall, the worker is in write_frame reached from pending_input flush; broker handler is at an Applied reply or another receiving-conn reply; pending_input was nonempty; application read_event progress stops at that flush. If pending_input is empty on every attempt, or the worker is instead parked in outbound wire forwarding/read_event, this specific mechanism is false. In an authorized later trial, retaining equivalent PTY output but removing pre-refresh input history should weaken this candidate; a fresh operator stream with no history should distinguish it from a history-independent egress fault. These are predictions, not executed changes.\n\n### 2. A synchronous outbound forwarding write stops the sole receive loop — competing candidate\nattach.rs899 calls wire.net_stream_send(None); brain.rs2108–2120 writes its IPC command synchronously and returns without NetSent waiting. Broker dispatch_net_stream_send9832–9835 calls NetHost.send_stream directly; nethost.rs1912–1921 enters bounded_block_on, waits for the stream send mutex, then write_all/finish. The two-connection split removes the old same-handler output-forwarding cycle but does not make the serving thread itself asynchronous. If the wire connection's handler stops consuming commands, the serve thread can block on a subsequent wire write and cease reading its separate receiver. A snapshot can fit through before backlog develops.\n\nFresh canary is compatible with a yielding per-stream mutex/transport wait or ordinary blocking IPC on another thread. It argues against net-runtime-wide starvation, not against every individual stream wait. active_dial_tasks0 narrows away active dial congestion, not stream-send work.\n\nLimits: ordinary stream pumps are bounded-overwrite, not the retentive shell-tunnel wait (nethost.rs1132–1137); send_stream has a10-second async-operation timeout(nethost.rs59–73,1469–1479). Therefore an unbounded 'QUIC await' is not a supported claim here. The proposed cycle needs evidence of blocked wire IPC/handler, repeated bounded operations, or an error reply blocking the undrained wire side; current log attribution points to the receiving conn, not a demonstrated wire failure.\n\nPredictions: worker stack is at wire.net_stream_send/write_frame, pending-input flush already finished or never entered; wire handler is in send_stream or reporting its failure; no more read_event calls occur on conn70. A worker demonstrably continuing to read receiving events through the15-second window would falsify this simple sole-reader-stop model.\n\n### 3. Pure cursor/duplicate-establish explanation — lower-ranked and insufficient alone\nbrain.rs1311–1336 performs stream dedup/forward-gap rejection; attach_as_coded resets the session cursor to from_seq0 and baseline flag(1464–1471). A replayed opener invokes that reset even when the broker preserves the existing same-conn writer. That is worth correlating with decoded output, but a cursor mistake alone would ordinarily leave the worker reading/dropping events or produce an explicit stream/output gap, not a15-second non-draining carrier timeout. W1c has os233 after poison, not a logged gap. The old 'same Request replaces its own controller writer' account is specifically contradicted by decision=idempotent and broker3193–3230.\n\nPrediction: a pure cursor issue shows continued read_event throughput with discarded/misbaselined output, or an explicit gap error, rather than a stalled synchronous write. Treat it as a potential contributor only if those facts appear.\n\n## Replay and acknowledgement facts that prevent misleading RCA\n- There is no NetSent acknowledgement wait on ordinary attach output: op=None exits net_stream_send at2118–2120. The journaled wait loop2124–2130 does discard unrelated events, but it is NOT the normal forwarding branch.\n- send_effect(ack=true) is not a synchronous wait-for-Applied API. Its danger here is generated reply traffic and a write-only batch, not a hidden `recv(Applied)` call.\n- NetStreamData consumption advances the local cursor at brain1330, with no consumption acknowledgement in that branch. New dispatcher workers subscribe from retained floor(dispatch1215), not a persisted per-worker read cursor. Stream retention plus PTY effect dedup supports replay, but does not inherently bound replay-side request traffic.\n- A fresh StreamLease is minted on every subscriber installation(nethost580–600). Old-writer death should cancel only the old lease. 'The original conn17 failure permanently canceled all successor leases' is not supported by current source.\n- Module comments describing controller replay as inline/synchronous in attach.rs484–500 are historical context, not proof of current controller writer implementation. Do not rebuild that old mechanism merely from those comments.\n\n## Why prior fixes can be working without curing this W1c failure\n1. Physical connection poisoning bounds a non-draining carrier; the W1c logs show retirement and replacement, so it is containing each incident. It does not force the replacement serve thread to consume.\n2. Async StreamLog subscriber writers plus fail-first halt remove replay-under-log-lock producer stalls and serial writes past a dead conn(nethost189–242). LIVE failure in W1c demonstrates the replacement reached beyond replay writing; it does not demonstrate healthy application drain.\n3. Fresh leases prevent a predecessor's delayed failure canceling a successor(nethost580–600), but a successor can poison its OWN lease if it stops draining.\n4. Pinned opener fixes classification after ring roll; the two-conn split fixes a specific forwarding/receive-handler coupling; idempotent same-conn establish preserves the controller writer. None changes pending_input's ack=true flush or removes synchronous writes from the sole serve thread.\n5. Crucial retry mismatch: classify_failure(dispatch373–383) recognizes only 'subscriber busy', 'replay halted', 'lease canceled' as SeatBlocked. Observed `No process is on the other end of the pipe. (os error233)` matches none, so it is Transient. outcome_transition503–545 increments attempts, waits500ms then1000ms via349–350, and becomes Terminal at MAX_DISPATCH_ATTEMPTS3(343). W1c attempts0/1/2 and spacing match that path. The seat-blocked global breaker is NOT demonstrated by these failures. Consequently three successful carrier replacements can each hit the same consumer problem and then leave the active stream unclaimed for that dispatcher generation. The next dispatcher generation recreates its claims map, allowing the cycle again.\n\n## What matching tests cover, and what they do not establish\n- tests/attach.rs547–650: prepopulated PTY ring, fresh loopback attach, final TICK39 rendered, then detach. This checks initial screen delivery, not sustained recovery of an old stream carrying a substantial input history.\n- tests/attach.rs867–1032: restart exactly-once test hand-steps life1, submits one old and one dead-window input, then life2 serve_attach; its seed_request is None. It is useful edge-idempotency coverage but not the production pinned-opener-plus-replayed-opener ordering under real rc traffic.\n- tests/redispatch.rs579–678: production dispatcher restart after shrinking the stream ring to8 chunks and rolling the opener out with40 inputs. It verifies pinned classification and MARK-B input/output recovery, but deliberately removes the full old input history and original Request from retained replay. W1c instead logs floor0 and duplicate Request handling on every attempt.\n- tests/redispatch_stall.rs332,415,546,607 identify tests for deliberately wedged subscribers, lease cancellation, opener failure, and injected SeatBlocked retry. Those contracts can all hold while a reconstructed real attach consumer stalls itself; os233 is a different classification from the injected subscriber-busy case.\n- tests/attach_idempotent_replay.rs17–30 and broker3193–3230 address same-connection duplicate establish without re-synthesizing history. W1c's idempotent decision is evidence against claiming that previously fixed writer-replacement mechanism has been reproven here.\n\n## Bottom line\nThe strongest defensible RCA candidate is: refresh reconstructs the SAME held attach and retained input history; a synchronous operation in that replacement's sole consumer thread stops draining the shared stream/controller IPC carrier;15-second conn poison contains the damage, but ordinary os233 retries reconstruct the same conditions three times and then terminalize the claim. The pending-input ack=true batch is the most specific remaining source-backed suspect, not a proven cause. The missing discriminator is the receiving worker's exact blocked call plus pending-input/read progress, not another global canary. Nothing in this analysis answers Q3; a real signed pending trial remains separate."},"status":"success"},"isError":false,"timestamp":1789524198431}}
{"type":"custom","customType":"session_exit","data":{"reason":"dispose","kind":"normal","recordedAt":"2026-09-16T02:10:18.464Z"},"id":"5adb9987","parentId":"aab1c0de","timestamp":"2026-09-16T02:10:18.464Z"}
