{
  "summary": "H2 can use shipped spt public APIs on the two existing trusted nodes: dedicated script-backed harness adapter and two broker-hosted HFENDULEAM perches, each genuinely controlled by an ENLYZEAM rc process. No cargo or fabricated helper/controller records are required. Baseline code has explicit spaced-path tokenization, no owner wait in prompt polling, and second-audience scope-conflict mechanisms. Field execution, installed broker/brain provenance, and admission remain parent-owned; none were executed by this scout.",
  "files": [
    {
      "path": "crates/spt/src/cli.rs:3995-4075",
      "description": "endpoint create only mints; start launches, go launches and attaches. Also send --force-native at 99-158."
    },
    {
      "path": "crates/spt/src/api/startup.rs:1099-1205",
      "description": "Real post-spawn bind, session identity and broker-PTY online predicate; no psyche_init needed."
    },
    {
      "path": "crates/spt-daemon/src/harnesshost.rs:150-193",
      "description": "Tokenized session command and translator command argv; permits installed PowerShell interpreter scripts without compiled fixture binaries."
    },
    {
      "path": "crates/spt/src/api/mod.rs:474-529,648-661,747-792",
      "description": "now-signal flags, session proof, and USER_INPUT state dispatch before downstream work."
    },
    {
      "path": "crates/spt/src/api/nowsignal.rs:705-751,1085-1135,1149-1210",
      "description": "Helper gather/delta identities; pathless early return; bounded receipt acknowledgment, then immediate signal gathering."
    },
    {
      "path": "crates/spt-daemon/src/broker.rs:9023-9118",
      "description": "Real remote-controller snapshot, session authentication, physical delivery exclusion, asynchronous owner request/reply and helper persistence."
    },
    {
      "path": "crates/spt/src/rc.rs:3048-3150",
      "description": "Owner audience comes from established rc target; worker performs actual owner daemon AddInputReference requests."
    },
    {
      "path": "crates/spt-store/src/helperline.rs:133-175",
      "description": "Baseline whitespace tokenizer loses space-bearing quoted paths."
    },
    {
      "path": "crates/spt-store/src/serving.rs:281-333",
      "description": "Owner reference reuse and INPUT_PATH_SCOPE_CONFLICT for another audience; original deadline preserved."
    },
    {
      "path": "crates/spt-daemon/src/webproxy.rs:177-194",
      "description": "Important evidence ceiling: WEB audience enforcement is node-granular, not a distinction between two endpoints on HFENDULEAM."
    },
    {
      "path": "docs-site/src/harness-contract/manifest.md:431-545",
      "description": "Idle physical-delivery translation protocol, mandatory commit, and absence-of-translator spooling behavior."
    },
    {
      "path": "crates/spt/tests/dummy_harness_e2e.rs:76-239",
      "description": "Existing real daemon → endpoint create/start → broker PTY → rc fixture pattern, including keeping controller stdin open. Its psyche prerequisite commentary is stale relative to current cmd_bind."
    },
    {
      "path": "crates/spt/tests/webserve_cross_node_e2e.rs:1-45",
      "description": "Isolation/routing pitfalls: private homes and identities; same-host labels and gossip cannot stand in for the required physical hosts."
    },
    {
      "path": "crates/spt-daemon/tests/twohost_web.rs:1-44",
      "description": "Older two-host helper fixture exercises Gateway user-msg/ServeFor, NOT remote-rc USER_INPUT receipt acceptance."
    },
    {
      "path": "docs/INPUT-PROVENANCE-CONTRACT.md:403-503",
      "description": "Current §8 supersedes historical token/adapter obligations; physical peer delivery and hook-cost field evidence remain pending."
    },
    {
      "path": "docs/adr/0058-attachments-are-pull-model.md:81-122",
      "description": "Amendment 2 receipt-seat authority and pending real field obligation."
    },
    {
      "path": "docs-site/src/serving/attachments.md:128-175",
      "description": "Published baseline asynchronous notice, repeated-payload semantics, missing-precondition silence, and pending acceptance."
    }
  ],
  "architecture": "Receiver API report → receiver broker authenticates session and snapshots actual remote controller → request travels existing authenticated rc stream → ENLYZEAM rc derives audience from its established target → owner daemon registers live reference → reply travels same stream → receiver broker appends helper record → now-signal gathers and persists session delta. Peer exclusion is based on physical core PTY writes, not message-shaped text or inbox arrival.",
  "report": "## Scope and evidence\nRead-only source reconnaissance only: no commands, builds, tests, remote access, node lifecycle actions, or edits. Read JIT-PLAN whole and relevant repository/contract instructions. No LSP was exposed. Source references describe the inspected tree, not independently verified installed binary behavior. Parent reports ENLYZEAM Windows PowerShell 5.1, spt 0.71.0, SHA-256 BC277E6C9F0486E8B2A643A38CADE6751685F05838C11FAFD22D8DAC71D0C182; that is parent-supplied evidence, not scout measurement.\n\n## Safest admitted construction on existing trusted nodes\nUse the EXISTING active SPT_HOME on each node, but create a unique adapter name, E1/E2 endpoint IDs, private fixture cwd and capture directory. This is resource isolation within the existing trust domain, NOT independent home/trust isolation. Do not copy node identity, subnet material, live perch files, helper records, or controller state. Do not start/stop/refresh existing daemons, take an operator's controller, register autostart, or touch extension-owned hertz lifecycle.\n\nA dedicated script-backed harness is a real public protocol client, not a mock of core: core still launches its actual PTY, seats the real remote rc, handles real IPC and WAN traffic, registers the actual owner file, physically injects peer text, and produces the observable signal. It needs no LLM. The harness must read actual PTY submissions, not manufacture the delivered input from the sender's source file.\n\nMinimal manifest shape (parent must implement the scripts, not empty placeholder commands):\n- [adapter]: unique name, kind=\"harness\", version=\"1\", min_spt_core_version=\"0\".\n- [session.self].command: absolute powershell.exe -NoProfile -File <fixture-session.ps1> with endpoint {id}, session {session_id}, absolute admitted spt executable, adapter name, and capture directory arguments. Templates tokenize before substitution (harnesshost.rs:150-155).\n- [message-idle-translation-binary].command: absolute powershell.exe -NoProfile -File <fixture-translate.ps1>. Use command, not path-with-arguments; command argv is supported at harnesshost.rs:180-191 and runtime manifest validation.\n- Omit psyche_init, service, update hooks, and autostart. Actual cmd_bind earns online from controllable==Some(true), not psyche_init (startup.rs:1176-1197); old dummy fixture commentary is misleading here.\n- Translator consumes real init/event/input JSON-lines. For an event it writes the actual received envelope as one text command, then enter, then commit, flushing stdout; protocol stdout must contain no diagnostics. Capture translation input/output privately. No fake message/helper ledger writes.\n- Session script binds itself, continuously reads PTY submissions, preserves the submitted bytes, invokes the shipped state/poll hook path, saves each exact stdout/stderr with monotonic timestamps and correlation ID, then returns idle. It must distinguish terminal DSR probes/choreography from submitted text without editing the actual payload it reports. This reader behavior is a genuine fixture precondition on Windows ConPTY, not something source reconnaissance proves.\n\n## Concrete public command sequence\nAll commands below are parent-owned future actions, not executed here. Use explicit admitted executable and matching home everywhere; do not inherit another endpoint's OWL_SESSION_ID/SPT_AGENT_ID/SPT_ENDPOINT_ID into the driver.\n1. Admission/readiness: capture both node identities, active homes, subnet membership, node status, actual executable paths/hash/sidecars and live broker/brain provenance. Check same shared subnet and RC_ATTACH/DISCOVER/MSG/WEB policy, not merely successful SSH. Hash fixture scripts/manifest too. Version 0.71.0 alone cannot establish b33aedcae51fa5ffa840ef1b36c9989a25884bdc. Signed provenance types are release.rs:98-130 (artifact_sha256, git_commit/git_dirty/build_host/build_timestamp_ms). A matching CLI hash does not prove already-running broker/brain or rc images match.\n2. HFENDULEAM: `spt adapter add <fixture-directory>`; `spt endpoint create <E1> --adapter <unique-adapter> --cwd <private-dir> --subnet <existing-shared-subnet>`; `spt endpoint start <E1>`. Repeat for E2. create only mints in cli.rs:3995; generated CLI prose incorrectly says it also starts. Avoid receiver-side `spt go E1` because it attaches a local controller.\n3. Inside each broker-spawned harness: `spt api --adapter <unique-adapter> bind <E> --set-session-id <SID>`; then `spt api state idle <E> --session-id <SID>`. Keep SID/capability output private; never publish raw bind credentials. No direct info.json/controller editing.\n4. ENLYZEAM: run `spt rc <E1>@hfenduleam` as a retained real process. Keep stdin open and drain stdout/stderr continuously; piped EOF detaches (dummy_harness_e2e.rs:209-222). No --view and no --take. Attach E2 in its own process for second-audience cell. Check `spt api endpoint-info <E>` / `spt api driven-by <E> --session-id <SID>` plus live attachment receipt to establish controller node, not just historical disk text.\n5. Actual submitted input report on HFENDULEAM: `spt api state busy <E> --session-id <SID> --payload-file <exact-captured-UTF8-file>`. The public stdin equivalent is --payload-stdin. A token-only state invocation cannot borrow disk SID for provenance; explicit session proof is required. Payload files avoid PowerShell 5.1 pipeline encoding/newline surprises.\n6. Prompt-submit poll: immediately invoke `spt api now-signal <E> --session <same-SID> --user-input <same-exact-text> --spec-file <private-spec.json>` and retain its stdout as THE prompt-associated result before marking the prompt delivered/processed. Spec may be {\"only\":[\"FILE_ACCESS_HELPER\"]}; do not cap max_lines=1, which would conceal duplication. now-signal itself reports user_input; calling state and now-signal mirrors both existing report entry points and tests real duplicate custody. Distinguish a poll-only submission variant when measuring W2's owner wait, because earlier state processing can give the async owner a head start.\n7. ENLYZEAM: `spt serve list --json` before/after each cell; inspect entry id/path/origin/audience/registered_at_ms/ttl_ms. HFENDULEAM: run the actual offered `spt fetch <url> <private-destination>` and compare bytes. Fetch strips the URL authority and uses the receiving node's local listener (fetchverb.rs:57-92,224-228), so do not curl ENLYZEAM's literal localhost URL on HFENDULEAM.\n\n## Five cells, with RED versus invalid rig\n1. Spaced path: create a unique readable owner-only file in a space-bearing absolute path; send a real rc submission quoting the full path. Positive no-space control through same E/SID/controller must first work. Require offered URL, exact full owner registry path, fetched bytes equal. Baseline tokenizer split_whitespace at helperline.rs:144 can offer a fragment or miss; absence with no valid remote control/source readability is PRECONDITION, not RED. Also ensure any prefix fragment is not accidentally another existing served file/directory.\n2. Exactly one line: use a unique no-space path independent of cell 1; one actual input submission exercising the normal state+now-signal sequence. Count identical fetch lines in first prompt output and later observation polls, as well as inspect helper records read-only. Exactly one overall new notice is required; zero is not dedup success. Existing gather keys msg_id/path, not emitted URL (nowsignal.rs:742-749), so two genuine records may yield duplicate lines. Do not inject helper records to force RED. Duplicate may not reproduce on every baseline run; report observed PASS if it does not.\n3. With-prompt: use another fresh no-space path and capture the first synchronous prompt-submit now-signal stdout before the harness's prompt-consumed marker. Require the helper line there. Later appearance after an empty first poll is RED only with a subsequently confirmed successful owner registration/reply and valid seat/session. Baseline report waits for broker acknowledgment only; gathering does not await owner registration (api/mod.rs:657-661, broker.rs:9065-9086). Do not add a sleep before first poll or count eventual delivery as PASS. Latency may permit a lucky baseline pass; repeat honestly rather than fabricating failure.\n4. Second endpoint/audience: retain the exact live E1-registered owner path/entry/URL and original deadline; seat real ENLYZEAM rc on E2 with distinct SID, then submit that same path. E2 must get its own line with existing URL; owner list must show audience admitting both without a second registry entry or renewed deadline. Baseline serving.rs:301-308 explicitly refuses different audience with INPUT_PATH_SCOPE_CONFLICT. Prove E2 works using a separate fresh-path positive first; otherwise missing E2 session/seat/gossip is PRECONDITION. IMPORTANT: WEB currently admits nodes hosting an audience endpoint, not authenticated endpoint callers (webproxy.rs:177-194). Both endpoints on HFENDULEAM may fetch despite absent audience widening; fetch success alone cannot pass this cell.\n5. Physically delivered PEER causes no serve: keep E1 remote rc controller seated. Use an owner-readable UNIQUE no-space sentinel path not previously mentioned in USER_INPUT, not already served. From real E2 peer context issue `spt send <E1> --force-native` with the path-bearing body on stdin; explicit --from E2 is available, but run it from the actual bound E2 harness context and retain normal msg classification. Do not use --user-msg or --attachment. --force-native avoids quiet poll/spool fallback, but send acknowledgment is still not physical-write proof. Retain actual translator event and resulting harness-received bytes, then report THOSE bytes via session-authenticated state/prompt poll. Core broker should decline with `payload matches core-written PTY delivery bytes` (broker.rs:9062-9063), offer no line, and leave owner registry absent for sentinel. Observe after the owner-reply bound as well as immediately; independently prove live owner route before and after with distinct positive paths. Peer traffic merely queued/polled, viewer-only seat, lost controller, no translator, wrong SID, owner file missing, or delivery-in-progress/unavailable named decline are invalid/inconclusive for this arm, not green. Do not substitute sender body for translated envelope: matching is exact or ASCII-edge-trimmed, not interior normalization/message parsing.\n\n## Timing support for product W2\n- No-path fast path is report_user_input_with at nowsignal.rs:1099-1109: extractor gate precedes report allocation/thread/broker IPC. api state and now-signal both call it. Whole API command still has existing daemon/gather overhead, so total command time is NOT proof of zero total IPC. Product requirement concerns added helper work.\n- Parent can collect n>=10 fresh no-space owner registrations with monotonic timestamp before synchronous report/prompt poll and first receiver helper-record/line visibility after real owner reply. Use unique payload/path per sample to avoid measuring dedup. Keep first prompt output separate from subsequent observations. This yields end-to-end owner registration roundtrip plus polling observation error, NOT raw network RTT; record poll interval and instrumentation overhead. Also record both state and poll durations to avoid hiding work before poll. Report sample vector, median, high percentile/max and load; W2 chooses bound from measurements, not the existing arbitrary 500ms acknowledgment or 10s owner timeout. Both endpoints are on real named hosts, not loopback approximations.\n- Measure no-path hook durations separately with equal spec and warm state. Source proves no helper IPC/wait branch; an absolute timing number cannot prove a counterfactual zero regression without matched before/after builds. Public CLI does not expose a dedicated precise owner-roundtrip timer; receiver arrival is available without new cargo instrumentation.\n\n## Isolation alternative and teardown\nFresh per-host SPT_HOME genuinely separates IPC: endpoint.rs:1-38 hashes home into sockets. But it also creates a new node identity and requires real elevated public `subnet create`/`subnet join` admission; never clone installed trust. Private HTTP ports must agree between configuration and listener: webserve_attachment_e2e.rs:45-54,97-128 describes SPT_DOCS_PORT versus SPT_TEST_EPHEMERAL_ADVISORY_PORTS mismatch. This alternative is not necessary for the parent's existing-trusted-node direction and should not be silently substituted.\n\nParent owns teardown ledger. Detach/close only owned E1/E2 rc clients, stop only created E1/E2 via `spt endpoint stop <E>`, preserve sanitized captures, remove only helper-served IDs proven to reference run-owned files via `spt serve rm <id>`, then `spt endpoint purge <E> --yes` and `spt adapter remove <unique-name>`. No blanket serve cleanup, daemon stop, trust pruning, machine-wide process killing, or operator endpoint changes. Fixture source files/private payloads can be removed only after evidence capture and owned serve removal; removing registry references does not delete user files.\n\n## Existing support and genuine prerequisites\nUse installed spt CLI/help and the above source-backed protocol. Existing dummy_harness_e2e is structural guidance, not an acceptance executable to run; its mock-session binary is not guaranteed installed and must not trigger a cargo build. twohost_web's old Gateway helper and cross-node tests cannot establish this rc receipt leg. `spt adapter translate-proof` checks translator emission only and cannot replace physical core PTY proof. Required remaining admission facts: actual receiver and owner running component provenance against b33aedca; existing shared subnet/access availability; approved unique adapter/perches; durable PowerShell PTY/JSON-line capture implementation; controller process supervision on ENLYZEAM without borrowing its operator session; readable unique owner fixtures and available receiver capture directory. None of those missing runtime facts is established by source inspection or the parent's CLI version/hash alone."
}