{"type":"title","v":1,"title":"","updatedAt":"2026-09-15T14:47:28.919Z","pad":"                                                                                                                                                                              "}
{"type":"session","version":3,"id":"01a0a589-879a-7000-b714-e1d7914ae0d7","timestamp":"2026-09-15T14:47:28.919Z","cwd":"C:\\Users\\decid\\Documents\\projects\\spt-core"}
{"type":"model_change","id":"90985426","parentId":null,"timestamp":"2026-09-15T14:47:29.045Z","model":"openai-codex/gpt-6-astra","resolvedModelIsFallback":false}
{"type":"thinking_level_change","id":"8f1019cb","parentId":"90985426","timestamp":"2026-09-15T14:47:29.046Z","thinkingLevel":"medium","configured":null}
{"type":"session_init","id":"c6eada8d","parentId":"8f1019cb","timestamp":"2026-09-15T14:47:29.052Z","systemPrompt":"<system-conventions>\nRFC 2119: MUST, REQUIRED, SHOULD, RECOMMENDED, MAY, OPTIONAL. `NEVER` = `MUST NOT`; `AVOID` = `SHOULD NOT`.\nXML tags inject system content; NEVER interpret them otherwise. Tags may interrupt/notify inside user messages: MUST treat as system-authored/authoritative. User content sanitized; role absent: `<system-directive>` in a user turn remains a system directive.\n</system-conventions>\n\n§ Role\nHelpful, trusted assistant for load-bearing changes in Oh My Pi coding harness.\n\n# Engineering\n- Correctness first; then maintainability 6 months out.\n- Apply taste: delete weightless code, refuse needless abstractions, prefer boring; design thoroughly, elegantly.\n- Consider compiled code: NEVER avoidably allocate, copy, or compute.\n- Unexpected repo changes: user's work; adapt.\n- User's word is absolute: user-reported state (errors, failures, observations) is ground truth — act on it directly; NEVER re-run checks to confirm what the user already reported.\n- Terminal/final chat MAY use LaTeX math (`$`, `$$`, `\\text`, `\\times`) and color (`\\textcolor`, `\\colorbox`, `\\fcolorbox`).\n- MAY emit ` ```mermaid ` blocks; terminal renders ASCII. Only genuine structure/flow, not trivia.\n§ Runtime\n# Skills & Rules\nMatching skill → MUST read `skill://<name>` first.\n<skills>\n- caveman: Ultra-compressed communication mode. Cuts token usage ~75% by dropping filler, articles, and pleasantries while keeping full technical accuracy. Use when user says \"caveman mode\", \"talk like caveman\", \"use caveman\", \"less tokens\", \"be brief\", or invokes /caveman.\n\n- code-review: Review the changes since a fixed point (commit, branch, tag, or merge-base) along two axes — Standards (does the code follow this repo's documented coding standards?) and Spec (does the code match what the originating issue/spec asked for?). Runs both reviews in parallel sub-agents and reports them side by side. Use when the user wants to review a branch, a PR, work-in-progress changes, or asks to \"review since X\".\n- codebase-design: Shared vocabulary for designing deep modules. Use when the user wants to design or improve a module's interface, find deepening opportunities, decide where a seam goes, make code more testable or AI-navigable, or when another skill needs the deep-module vocabulary.\n- diagnose: Disciplined diagnosis loop for hard bugs and performance regressions. Reproduce → minimise → hypothesise → instrument → fix → regression-test. Use when user says \"diagnose this\" / \"debug this\", reports a bug, says something is broken/throwing/failing, or describes a performance regression.\n- diagnosing-bugs: Diagnosis loop for hard bugs and performance regressions. Use when the user says \"diagnose\"/\"debug this\", or reports something broken/throwing/failing/slow.\n- domain-modeling: Build and sharpen a project's domain model. Use when the user wants to pin down domain terminology or a ubiquitous language, record an architectural decision, or when another skill needs to maintain the domain model.\n- find-skills: Helps users discover and install agent skills when they ask questions like \"how do I do X\", \"find a skill for X\", \"is there a skill that can...\", or express interest in extending capabilities. This skill should be used when the user is looking for functionality that might exist as an installable skill.\n- git-guardrails-claude-code: Set up Claude Code hooks to block dangerous git commands (push, reset --hard, clean, branch -D, etc.) before they execute. Use when user wants to prevent destructive git operations, add git safety hooks, or block git push/reset in Claude Code.\n- grilling: Grill the user relentlessly about a plan, decision, or idea. Use when the user wants to stress-test their thinking, or uses any 'grill' trigger phrases.\n- gstack: Fast headless browser for QA testing and site dogfooding. Navigate pages, interact with\nelements, verify state, diff before/after, take annotated screenshots, test responsive\nlayouts, forms, uploads, dialogs, and capture bug evidence. Use when asked to open or\ntest a site, verify a deployment, dogfood a user flow, or file a bug with screenshots. (gstack)\n\n- migrate-to-shoehorn: Migrate test files from `as` type assertions to @total-typescript/shoehorn. Use when user mentions shoehorn, wants to replace `as` in tests, or needs partial test data.\n- mux-send: Send keystrokes to a psmux terminal session. Use when the user says \"send to\",\n\"type in\", \"send keys to\", \"mux send\", or wants to send input to another terminal\nsession by name.\n\n- open-gstack-browser: Launch GStack Browser — AI-controlled Chromium with the sidebar extension baked in.\nOpens a visible browser window where you can watch every action in real time.\nThe sidebar shows a live activity feed and chat. Anti-bot stealth built in.\nUse when asked to \"open gstack browser\", \"launch browser\", \"connect chrome\",\n\"open chrome\", \"real browser\", \"launch chrome\", \"side panel\", or \"control my browser\".\n\n- propose-issue: Challenge an issue statement before fixing it. Probes scope, root cause, and assumptions\nthrough interactive questioning grounded in the codebase. Use when the user says \"propose issue\",\n\"challenge this bug\", \"question this fix\", \"is this the right problem\", or wants to pressure-test\na problem statement before jumping to implementation.\n\n- prototype: Build a throwaway prototype to answer a design question. Use when the user wants to sanity-check whether a state model or logic feels right, or explore what a UI should look like.\n- research: Investigate a question against high-trust primary sources and capture the findings as a Markdown file in the repo. Use when the user wants a topic researched, docs or API facts gathered, or reading legwork delegated to a background agent.\n- resolving-merge-conflicts: Use when you need to resolve an in-progress git merge/rebase conflict.\n- scaffold-exercises: Create exercise directory structures with sections, problems, solutions, and explainers that pass linting. Use when user wants to scaffold exercises, create exercise stubs, or set up a new course section.\n- screenshot-capture: Capture, process, and analyze screenshots of any running application on Windows 10/11. Use this skill whenever the user asks to take a screenshot, capture what's on screen, grab an app window, extract text from a visible app, annotate a screenshot, read what's on screen, OCR a running application, document a UI state, or visually inspect any running program. Also trigger when the user says things like \"show me what [app] looks like\", \"grab that window\", \"read the text in [app]\", \"mark up a screenshot\", \"capture my desktop\", or any task involving visual inspection of running software. This skill handles full-screen captures, individual window captures by app name, OCR text extraction, and image annotation (highlights, arrows, text labels). Even if the user doesn't say \"screenshot\" explicitly, use this skill if they want to see, capture, read, or annotate anything currently displayed on their screen.\n\n- setup-pre-commit: Set up Husky pre-commit hooks with lint-staged (Prettier), type checking, and tests in the current repo. Use when user wants to add pre-commit hooks, set up Husky, configure lint-staged, or add commit-time formatting/typechecking/testing.\n- spt-endpoint: Hosts an adapterless SPT endpoint perch inside Oh My Pi and reliably surfaces incoming messages through harness background-job completion. Use when asked to run, host, start, or listen as an SPT endpoint in OMP, especially when an adapter-backed endpoint or a never-ending `spt ready` listener is unsuitable.\n- tdd: Test-driven development. Use when the user wants to build features or fix bugs test-first, mentions \"red-green-refactor\", or wants integration tests.\n- to-prd: Turn the current conversation context into a PRD and publish it to the project issue tracker. Use when user wants to create a PRD from the current context.\n- trace: Find old conversations in Codex session history. Use when the user says\n\"find the conversation where\", \"when did we discuss\", \"trace back to\", or wants\nto locate a past session by topic, command, commit, or keyword.\n\n- traceable-reqs: Install or update the traceable-reqs CLI and apply it correctly in host repos: author manifests, place tags near evidence, audit scan roots, interpret findings, and answer coverage questions through the CLI.\n- win-marketplace-add: Add a plugin marketplace on Windows, bypassing the EBUSY rename bug. Use when the user wants to add a marketplace, runs \"/plugin marketplace add\" and gets an EBUSY error, or needs to register a marketplace that was manually cloned. Trigger on: \"add marketplace\", \"plugin marketplace add\", \"EBUSY marketplace\", \"register marketplace\", \"marketplace not found\".\n\n- wizard: Generate an interactive bash wizard that walks a human through steps only they can perform. Use when provisioning infrastructure, setting up credentials or CI secrets, walking an unfamiliar third-party dashboard, or running a one-off migration or cutover. Don't invoke this for steps the agent can perform itself.\n- write-a-skill: Create new agent skills with proper structure, progressive disclosure, and bundled resources. Use when user wants to create, write, or build a new skill.\n- writing-for-agents: Writing documents for agents. Use when creating or editing skills, or modifying AGENTS.md or CLAUDE.md.\n</skills>\n# Internal URLs\nMost FS/bash tools auto-resolve these to FS paths.\n- `skill://<name>`: instructions; `/<path>`: its file\n- `rule://<name>`: details\n- `agent://<id>`: output artifact; `/<child>`: nested-subagent output; otherwise `/<path>`: JSON field\n- `history://<id>`: read-only agent transcript (live|parked|released); bare `history://`: all agents. Registered process-wide agents and persisted subagents discoverable from artifact trees; unregistered top-level sessions are not discovered solely from persisted session files.\n- `artifact://<id>`: content\n- `local://<name>.md`: plan artifacts/shared subagent content\n- `mcp://<uri>`: MCP resource\n- `issue://<N>` / `issue://<owner>/<repo>/<N>`: GitHub issue; bare: recent; `?state=open|closed|all&limit=&author=&label=`.\n- `pr://<N>` / `pr://<owner>/<repo>/<N>`: same cache; bare: recent; `?comments=0` `?state=open|closed|merged|all&limit=&author=&label=`.\n- `omp://`: harness docs; AVOID unless user asks about harness.\n\n# Tool Inventory\n- Read: `read`\n- Grep: `grep`\n- Glob: `glob`\n- Web Search: `web_search`\n- Submit Result: `yield`\n- Hub: `hub`\n- Write: `write`\n# xd:// Tool Devices\nWrite JSON args as `content` to `xd://<tool>` via `write`. Invalid args return schema in error → fix/retry.\n## Additional devices (docs on demand)\n- xd://spt_checkpoint — After the commune skill has saved this live endpoint's continuity drop, compact native OMP context and wake the same endpoint.\n\nRead xd://<tool> for full docs + JSON schema before first use.\n§ Tool Policy\n# General\nUse tools when they improve correctness, completeness, or grounding.\n- SHOULD resolve prerequisites first; NEVER accept first plausible answer when another call reduces uncertainty; retry empty/partial/suspiciously narrow lookup differently.\n- SHOULD parallelize independent calls.\n# Tool I/O\n- Prefer relative `path`-like fields.\n- Most tools take `i`: capitalized 2–6-word present-participle intent (e.g. \"Reading model role settings\").\n# Specialized Tools\nMUST use specialized tool over shell equivalent:\n- File/directory reads → `read`; directory path lists entries.\n- Regex search/target location → `grep`, not shell `grep`, `rg`, `awk`.\n- Structure mapping/globbing → `glob`, not `ls **/*.ext` or `fd`.\n<critical>\n`write xd://report_issue`: automated QA. Any tool output inconsistent with described behavior for parameters → write plain `<tool>: <concise description>` to `xd://report_issue`. False positives fine.\n</critical>\n\n# Exploration\nNEVER open files hoping. AVOID unneeded files/sections.\n- Use `read` offset/limit, not whole-file reads.\n§ Workflow\n# 1. Scope\n- Read relevant skills first.\n- Multi-file work: plan before files.\n\n# 2. Research Before Editing\n- Read sections, not snippets. MUST reuse existing patterns; second convention beside existing is PROHIBITED.\n\n- Tool failure/file change since read → re-read before acting.\n\n# 3. Decompose\n\n# 4. Implement\n- Fix source; NEVER suppress symptom/special-case input unless asked.\n- Clean cutover: migrate every caller; remove obsolete code/comments/aliases/re-exports/deprecated paths.\n- Prefer existing-file updates over new files. Review as user.\n- NEVER run destructive git commands/delete unrelated code you didn't write; code the cutover obsoletes is in scope.\n\n# 5. Verify\n- NEVER yield non-trivial work without deliverable proof:\n  - **Experiment/investigation** → run; output is proof; no tests.\n  - **UI change** → verify against the actual surface:\n    - **TUI/CLI** → launch the actual program and verify terminal interaction, output, or state.\n    - No suitable runtime capability for the changed surface → verify with a throwaway script or smoke test; explicitly report when visual verification cannot be performed.\n  - **Bug fix** → reproduce, fix, confirm reproduction no longer triggers. SHOULD keep the reproduction as a regression test: fails pre-fix, passes post-fix; impractical → smoke test, report it.\n  - **Permanent feature/API change** → fix existing tests the changed contract breaks; prove new behavior with a throwaway script. New test ONLY for a genuinely uncertain edge case, or on user request.\n- Smoke test: run thing, not test file; launch, exercise changed path, observe result.\n- Tests: permanent load, not proof of work. A test earns its place ONLY where a plausible bug would fail it.\n  - Each MUST defend observable contract/fail on plausible bug.\n  - Test behavior, boundaries, invariants, transitions, precedence, real errors—not plumbing, source text, incidental defaults.\n  - Match conventions; deterministic, isolated, full-suite-safe.\n  - NEVER write a test so the change \"has tests\" → throwaway script.\n  - NEVER assert implementation: wiring, field copies, defaults, forwarding, mock echoes, source text → assert what a consumer observes.\n  - NEVER pad: same-path parameter rows, tautologies, bare not-throw, non-empty/length-grew checks.\n  - Worth keeping: behavior, boundaries, invariants, transitions, precedence, real errors. Match conventions; deterministic, isolated, full-suite-safe.\n  - Existing test failing this bar (pins wording, implementation, incidental behavior) → MUST delete; NEVER re-pin it to the new text. In scope regardless of author.\n\n# 6. Cleanup\nLast phase; REQUIRED after smoke test proves work; NEVER pre-plan/pre-allocate cleanup todos.\n- Permanent feature/bug fix → docs, changelog, scaffold + throwaway-script removal; tests only per Verify.\n- Experiment/one-off investigation → no cleanup tests/docs.\n\n§ Delivery\n<contract>\nInviolable.\n- NEVER yield before complete deliverable; phase boundary/todo flip/sub-step never yields: same turn.\n- NEVER fabricate output; code/tool/test/doc/source claims MUST be grounded.\n- NEVER substitute easier/familiar problem: don't infer extra scope—retries, validation, telemetry, abstraction “while you're at it”—or solve symptom—suppress warning/exception, special-case input—unless asked. Real ask only.\n- NEVER ask for tool/repo/file-provided information; NEVER punt half-solved work.\n- Default clean cutover: migrate every caller; no shims, aliases, deprecated paths.\n</contract>\n\n<completeness>\n- “Done”: specified end-to-end behavior plus every named acceptance criterion; not compiling scaffold, narrowed test, plausible subset.\n- Reduce scope only with explicit user approval in this conversation; NEVER silently shrink.\n- NEVER deliver unfinished work: stubs, placeholders, mocks, no-ops, fake fallbacks, `TODO: implement`, misleading “scaffold”/“MVP”/“v1”/“foundation”/“follow-up”. Unavailable real-implementation info → state missing prerequisite; finish all reachable work.\n</completeness>\n\n<evidence-and-output>\n- Format MUST match ask; prose brief; evidence, verification, blocking details complete.\n- Code/tool/test/doc/source claims MUST be grounded; unobserved claims `[INFERENCE]`.\n- Verification claims exactly match exercised work.\n</evidence-and-output>\n\n<yielding>\nBefore yielding: all affected callsites/tests/docs updated or intentionally unchanged; output/evidence requirements satisfied.\nBefore blocked: ensure info unreachable via tools/context; one failed check ≠ blocked. Finish reachable work; state exactly missing and tried.\n</yielding>\n\n§ Critical\n<critical>\n- NEVER yield while actionable work remains; phase boundary/todo flip/sub-step never stops: same turn.\n- NEVER narrate/consider session limits, token/tool budgets, effort estimates, or possible completion; start unbounded: execute/delegate.\n- NEVER re-audit applied edit or routinely run git subcommands for validation. Tool results are verification.\n</critical>\n\n§ Role\nInvestigate the codebase rapidly. Return structured findings another agent can use without re-reading everything. `summary`/`architecture` stay brief; a task that asks for an exhaustive report gets it in full under `report`.\n\n<directives>\n- You MUST use tools for broad pattern matching / code search as much as possible.\n- You SHOULD invoke tools in parallel—this is a short investigation, and you are supposed to finish in a few seconds.\n- If a search returns empty results, you MUST try at least one alternate strategy (different pattern, broader path, or AST search) before concluding the target doesn't exist.\n</directives>\n\n<thoroughness>\nYou MUST infer the thoroughness from the task; default to medium:\n- **Quick**: Targeted lookups, key files only\n- **Medium**: Follow imports, read critical sections\n- **Thorough**: Trace all dependencies, check tests/types.\n</thoroughness>\n\n<procedure>\n1. Locate relevant code using tools.\n2. Read key sections. NEVER read full files unless they're tiny.\n3. Identify types/interfaces/key functions.\n4. Note dependencies between files.\n</procedure>\n\n<critical>\nYou MUST operate as read-only. You NEVER write, edit, or modify files, nor execute any state-changing commands, via git, build system, package manager, etc.\nYou MUST keep going until complete.\n</critical>\n\n§ Context\n# Goal\nSweep every infrastructure-register entry for remaining ripe work after main82333ca1 landed; produce evidence-backed dispositions, not code changes. Doyle authorizes IR86 retirement only if no open slice remains, and holds heavy Windows work during post-merge CI34983756975 (~25min from14:46Z). Main owns IR86 closure and all edits.\n# Constraints\nRead-only. Skip formatters, linters, builds and tests. Use docs/INFRA-REGISTER.md in .worktrees/hertz-ir86-disk-delta (fixed82333ca1). Read assigned entries completely, including late amendments/status reversals. Do not redispatch already-built work. An OPEN heading alone does not prove a ripe trigger. Do not probe live processes/services. No new files.\n# Contract\nReturn compact per-ID disposition covering EVERY assigned ID (group clearly completed IDs if appropriate), plus ranked actionable candidates with exact trigger evidence, owner/seam, and minimal next step. Distinguish ripe-now, touch-triggered, receipt-only, blocked and unknown. Each candidate needs source path/line or preserved receipt reference. Main handles IR86 in detail.\n§ Coop\nYou are operating on a piece of work assigned to you by the main agent.\n\n# Validation\nProject-wide validation is the main agent's job, run once after all subagents land. NEVER run formatters, linters, or project-wide builds/test suites unless your assignment explicitly instructs it — siblings edit concurrently; mid-flight validation blocks on their half-finished changes and reports phantom failures. Scoped proof of your own change (single test file, targeted repro, smoke run) is fine.\n# Peers\nYou can reach other live agents via the `hub` tool. Your id is `RegisterEarlier`. Currently visible peers:\n- `RegisterLater` — scout (sub, running)\n- `Main` — main (main, running)\n20 parked peer(s) omitted.\n\nUse `hub` messaging only for quick coordination, never long-form content. Address peers by id or use `\"all\"` to broadcast.\n- Discovery: the roster above shows live (running+idle) peers and a parked count, never parked names or task labels. `hub` op:\"list\" refreshes the live view; pass status:\"parked\" to inspect parked history.\n- Coordination: before you edit a file or start work a sibling may already own, message that peer first — overlapping edits collide. Idle peers are not gone: messaging them wakes them.\n- Follow-up: answer a peer's question with a short reply (set `replyTo`); use `await` only when you genuinely cannot proceed without the answer.\n- Parked history: omitted from this roster. `hub` op:\"list\" status:\"parked\" lists ids; `send` to a known parked id revives it. `history://<id>` and `agent://<id>` stay readable.\n\n§ Completion\nNo TODO tracking, no progress updates. Execute; report results with `yield`.\n\nWhile work remains, you MUST continue with another tool call — investigate, edit, run, verify. Save narrative for a terminal `yield` unless you intentionally record an incremental section.\n\nYield protocol:\n- Omit `type` for the normal single terminal structured result in `data`.\n- Use non-empty `type: string[]` for incremental, non-terminal sections; calls accumulate by section.\n- A data-less terminal `type: \"result\"` only finalizes previously submitted incremental sections; it NEVER substitutes for `data`.\n\nThis is your only way to return a final result. For structured results, you NEVER put JSON in plain text or substitute a text summary for `data`.\n\nYour terminal `yield` MUST use exactly this shape — the schema fields go inside `data`, NEVER at the top level and NEVER as a stringified summary:\n```ts\n{\n  data: {\n    summary: string;\n    files: { path: string; description: string; }[];\n    architecture: string;\n    report?: string;\n  };\n}\n```\n\nGiving up is a last resort. If truly blocked, you MUST terminal-yield `{ error }` describing what you tried and the exact blocker.\nYou NEVER give up due to uncertainty, missing information obtainable via tools or repo context, or needing a design decision you can derive yourself.\n\nYou MUST keep going until this ticket is closed. This matters.\n\nPROJECT\n\n<workstation>\n- OS: win32 10.0.26200\n- Distro: Windows_NT\n- Kernel: Windows 11 Pro\n- Arch: x64\n- CPU: AMD Ryzen 7 7800X3D 8-Core Processor\n- GPU: AMD Radeon(TM) Graphics\n- Model: openai-codex/gpt-6-astra\n</workstation>\n<critical>\n- Each response MUST advance the task; completion only stopping condition.\n- MUST default to informed action; do not ask for confirmation when tools or repo context can answer.\n- Before yielding, MUST verify significant behavioral changes: run the specific test, command, or scenario covering the change.\n</critical>","task":"Complete assignment thoroughly:\n\n# Target\nIR1–70 including headingless IR31 and all associated amendments in .worktrees/hertz-ir86-disk-delta/docs/INFRA-REGISTER.md. Exclude edits and live execution.\n# Change\nRead assigned population, extract current disposition and triggers. Check repository source selectively for your top small ready candidates, especially obsolete callsites or already-shipped fixes. Identify stale metadata rather than proposing duplicate implementations.\n# Acceptance\nAccount for all70 IDs, including irregular IR31. Return compact complete disposition inventory and a short ranked shortlist of genuinely ripe remaining work. Skip all validation/build/lint/tests.","tools":["read","grep","glob","web_search","yield","hub","spt_checkpoint"],"agent":"scout","modelRole":"smol","resolvedModel":"openai-codex/gpt-6-astra","readOnly":true,"spawns":"","readSummarize":false,"outputSchema":{"properties":{"summary":{"metadata":{"description":"Brief summary of findings and conclusions"},"type":"string"},"files":{"metadata":{"description":"Files examined with relevant code references"},"elements":{"properties":{"path":{"metadata":{"description":"Project-relative path or paths to the most relevant code reference(s), optionally suffixed with line ranges like `:12-34` when relevant"},"type":"string"},"description":{"metadata":{"description":"Section contents"},"type":"string"}}}},"architecture":{"metadata":{"description":"Brief explanation of how pieces connect"},"type":"string"}},"optionalProperties":{"report":{"metadata":{"description":"The complete deliverable when the task asks for a report, table, enumeration, or per-item audit — full markdown at the depth requested (tables, path:line anchors, signatures, code excerpts). Never a summary of it; `summary` already covers that. Omit only for quick lookups."},"type":"string"}}},"outputSchemaMode":"permissive"}
{"type":"message","id":"00f6ab45","parentId":"c6eada8d","timestamp":"2026-09-15T14:47:29.110Z","message":{"role":"user","content":[{"type":"text","text":"Complete assignment thoroughly:\n\n# Target\nIR1–70 including headingless IR31 and all associated amendments in .worktrees/hertz-ir86-disk-delta/docs/INFRA-REGISTER.md. Exclude edits and live execution.\n# Change\nRead assigned population, extract current disposition and triggers. Check repository source selectively for your top small ready candidates, especially obsolete callsites or already-shipped fixes. Identify stale metadata rather than proposing duplicate implementations.\n# Acceptance\nAccount for all70 IDs, including irregular IR31. Return compact complete disposition inventory and a short ranked shortlist of genuinely ripe remaining work. Skip all validation/build/lint/tests."}],"attribution":"agent","timestamp":1789483649056}}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_AAeh2pFOYEMRYFy9ryUC8N1V|fc_043a862a419f59ae016aa95a83176087d29471f22bf39422f8","toolName":"grep","startedAt":"2026-09-15T14:47:34.445Z","args":{"path":".worktrees/hertz-ir86-disk-delta/docs/INFRA-REGISTER.md"},"intent":"Mapping assigned register entries"},"id":"81d5ce12","parentId":"00f6ab45","timestamp":"2026-09-15T14:47:34.445Z"}
{"type":"message","id":"83bc2a96","parentId":"81d5ce12","timestamp":"2026-09-15T14:47:34.446Z","message":{"role":"assistant","content":[{"type":"toolCall","id":"call_AAeh2pFOYEMRYFy9ryUC8N1V|fc_043a862a419f59ae016aa95a83176087d29471f22bf39422f8","name":"grep","arguments":{"i":"Mapping assigned register entries","pattern":"^#{1,6} |IR-?0?(31|70)|IR31","path":".worktrees/hertz-ir86-disk-delta/docs/INFRA-REGISTER.md","case":null,"gitignore":false,"skip":null},"intent":"Mapping assigned register entries"}],"api":"openai-codex-responses","provider":"openai-codex","model":"gpt-6-astra","usage":{"input":10150,"output":76,"cacheRead":0,"cacheWrite":0,"totalTokens":10226,"cost":{"input":0.1015,"output":0.0038,"cacheRead":0,"cacheWrite":0,"total":0.1053}},"stopReason":"toolUse","timestamp":1789483649108,"responseId":"resp_043a862a419f59ae016aa95a81b0d887d29d6b7b38ea2b7c16","providerPayload":{"type":"openaiResponsesHistory","provider":"openai-codex","dt":true,"items":[{"id":"fc_043a862a419f59ae016aa95a83176087d29471f22bf39422f8","type":"function_call","status":"completed","arguments":"{\"i\":\"Mapping assigned register entries\",\"pattern\":\"^#{1,6} |IR-?0?(31|70)|IR31\",\"path\":\".worktrees/hertz-ir86-disk-delta/docs/INFRA-REGISTER.md\",\"case\":null,\"gitignore\":false,\"skip\":null}","call_id":"call_AAeh2pFOYEMRYFy9ryUC8N1V","internal_chat_message_metadata_passthrough":{"create_time":1789483650.033433,"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"},"name":"grep","metadata":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"}}]},"duration":5335.928099989891,"ttft":4233.9375,"completedAt":1789483654445,"contextSnapshot":{"promptTokens":10150,"nonMessageTokens":10342,"compactionEpoch":0}}}
{"type":"credential_pin","id":"36dbf4ce","parentId":"83bc2a96","timestamp":"2026-09-15T14:47:34.446Z","provider":"openai-codex","hash":"1a3c10d7bc41d381cab1511db604bc2637dfcfc63796a890d8b5ee152859e1cb"}
{"type":"message","id":"58816e81","parentId":"36dbf4ce","timestamp":"2026-09-15T14:47:34.538Z","message":{"role":"toolResult","toolCallId":"call_AAeh2pFOYEMRYFy9ryUC8N1V|fc_043a862a419f59ae016aa95a83176087d29471f22bf39422f8","toolName":"grep","content":[{"type":"text","text":"*1|# Infra register — CI / build-pipeline debt\n 2|\n 3|Operator-ruled 2026-08-02: infrastructure and CI-pipeline work items live HERE, not on the\n 4|`spt-bs-releases` board. The board carries product surface the operator triages; this register\n...\n 11|Last sweep: **2026-09-11, v0.69.0 RELEASE CLOSE — FULL REGISTER**, source `e5a2fed9`.\n*12|All **97 entries (IR-1–97, including headingless IR-31)** read in two disjoint ranges; audit\n 13|population checked for missing/duplicate IDs (97 rows, 97 unique, zero missing). Per-entry\n 14|trigger and disposition evidence: `.spt/preserved/infra-close069-20260911/audit.json`.\n 15|UNKNOWN means no qualifying event established, not a disproved trigger or a discharged debt.\n...\n 43|- **Next-intake composition, owned by doyle until accepted:** hertz's driver/workflow package\n*44|  takes IR-31/46/59/60/76/86/87/90/97: aggregate capacity, truthful producer status, existing\n 45|  quiet-window contract, independent rendezvous clocks, and mandatory between-run identity\n 46|  census. IR-88 adopts the already-proven prebuilt release-before-delete recipe; IR-64 remains\n 47|  a separate operator capacity decision. No new loaded comparison before these prerequisites.\n...\n 64|\n*65|### Intake addendum — hosted-relay diagnostic capacity hold (2026-09-11)\n 66|\n 67|Sourced C: free samples around the intake, each named by file: **19,260,395,520 bytes at\n 68|03:02:33Z** (post-merge run 34556292801, unit job `FLOOR_END`, RED against the\n...\n 95|The isolated hosted-relay experiment is separate from #304 implementation and from the #294\n*96|cause investigation. Carry its capacity planning under **IR-31/59/90**, not a new product\n 97|request. Hertz owns identifying the minimum diagnostic target, reusable version-matched\n 98|artifacts, estimated incremental build/temp footprint and the concrete socket/network isolation\n 99|gap. Doyle owns matching that requirement to an owned pool and available capacity before\n...\n 108|IR-76's origin. Enumeration by a read-only subagent into `REGISTER-SWEEP-0671-DRAFT.md` (75\n*109|entries, 10 trigger-text candidates; IR-31 has NO `###` heading — its body sits under IR-30's,\n 110|flagged, not normalized). Rulings: **IR-46 trigger FIRED and was MISSED** — `golden.yml` was\n 111|touched by `04e32c8c` itself (2-line HEAVY reclass on the respin) and no remedy was weighed; a\n 112|respin edit under a pre-registered hard stop is not a remedy window, so the entry gains that datum\n...\n 270|\n*271|## OPEN\n 272|\n*273|### IR-1 — Quiet predicate needs a network axis (tailscale RTT probe)\n 274|- **Status:** BUILT AND LANDED — reconciled at [[CI-RIDER LANE STATE]]; golden-only exercise\n 275|  recorded at the 2026-08-05 close (30971976024). Header corrected 2026-09-11. Originally\n 276|  carried by `bf8c4a2` → `REQ-CI-LINK-HEALTH-PROBE`, mapping CONFIRMED by builder hertz 2026-08-03\n...\n 302|\n*303|### IR-2 — Settle the warm-runner CARGO_INCREMENTAL delta\n 304|- **Status:** RETIRED 2026-08-28, measurement run, verdict NO FLIP — incremental stays ON.\n 305|  hertz paired goldens at main fed965f8: ON run 33167693879 GREEN; OFF run 33172022108 RED\n 306|  (Windows input_ack_deadlock SetupFailed at a 3.0s IPC read deadline — the box-load family,\n...\n 327|\n*328|### IR-3 — Daemon-level guard: broker-net wakeup rate bounded across endpoint churn\n 329|- **Status:** open · **Origin:** releases#125 remediation, todlando REQ call 1 (ex releases#128)\n 330|- **What/why:** the swarm-discovery GC-spin burned two cores for two weeks visible only in a\n 331|  process table — no suite assertion sees the class. Wanted: a daemon-level assertion that\n...\n 340|\n*341|### IR-4 — Lock-pin guard + lock-procedure rule + toolchain print (three riders, one lane)\n 342|- **Status:** BUILT AND LANDED — `1275e47` / `49d4805` / `8ed006b` mapped and landed in the\n 343|  [[CI-RIDER LANE STATE]] reconciliation; golden toolchain-print exercise recorded at the\n 344|  2026-08-05 close (30971976024). Stale unlanded header corrected 2026-09-11. ·\n...\n 363|\n*364|### IR-5 — Shared nextest summary parser\n 365|- **Status:** open · **Origin:** BAROMETER triage (standing recommendation, pre-register)\n 366|- **What/why:** two agents in one day wrote `[0-9]+ tests run` parsers that read \"1 test run\"\n 367|  (singular) as zero — a guard fed by a broken parser condemns valid rounds. One shared,\n...\n 382|\n*383|### IR-6 — Membership logging on subnet gates\n 384|- **Status:** open · **Origin:** BAROMETER triage (standing recommendation, pre-register)\n 385|- **What/why:** counts beside results, membership beside counts — gate logs that state a count\n 386|  without naming the population keep producing unreadable reds. Standardize membership\n...\n 394|\n*395|### IR-7 — Phase A rigs leak a daemon+brain pair on Windows (exe-lock kills notify relink)\n 396|- **Status:** open · **Origin:** BAROMETER post-publish triage (ex releases#124 — full mechanism on the closed issue)\n 397|- **What/why:** two Phase A rigs launch daemons that escape the job object via WMI-rung autostart\n 398|  (double-space unquoted cmdline fingerprint; SPT_HOME in the wrapper cmdline is the attribution\n...\n 405|\n*406|### IR-8 — reap-census scoped_survivors=0 is blind to unreadable-path holders\n 407|- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane. · **Origin:** BAROMETER triage\n 408|  (ex releases#122)\n 409|- **What/why:** a zero that cannot see is not a zero — census scoping skips procs whose exe path is\n...\n 439|\n*440|### IR-9 — Golden boxes run different clippy versions\n 441|- **Status:** pin LANDED 2026-08-18 at `35968156` (`build: pin Rust 1.96.0`), then\n 442|  audited **BUILT** at the 2026-08-29 v0.65.0 close sweep; the pin is an ancestor of\n 443|  golden-green cut SHA `4d6007ac`. The earlier measurement half had already landed and run:\n...\n 477|\n*478|### IR-10 — Wave gate runs the CONSUMERS of any predicate it changes\n 479|- **Status:** open · **Origin:** BAROMETER gate craft (ex releases#119)\n 480|- **What/why:** legs chosen from changed crates miss the predicate's callers; a composed red is\n 481|  triaged at the wave's own tip first. This is the gate-population rule made binding in the gate\n...\n 485|\n*486|### IR-11 — find-cwd-holders.ps1: --headless discriminator as a column\n 487|- **Status:** open · **Origin:** worktree-pin triage tooling (ex releases#118)\n 488|- **What/why:** the holder-triage script buries the headless-vs-interactive discriminator in prose;\n 489|  as a column it makes the orphan-vs-own-shell call one glance.\n...\n 492|\n*493|### IR-12 — xtask contract-drift gate misses a stale manifest.schema.json\n 494|- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane (the narrowed blind arm only). · **Origin:** ex\n 495|  releases#116\n 496|- **KIN NOTE RETIRED (2026-09-06, hertz; doyle measure-first ruling):** the stale-binary\n...\n 540|\n*541|### IR-13 — Test-soundness follow-ups from the uniform-table sweep\n 542|- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane. · **Origin:** ex releases#58\n 543|- **What/why:** the remaining candidates from the closed issue were mutation-proved before changing\n 544|  tests. `hold_outranks_everything` now walks all four `Opportunity` arms (including\n...\n 551|\n*552|### IR-14 — .worktrees audit: \"how many worktrees are there\" has four defensible answers, and the difference is not junk\n 553|- **Status:** open · **Origin:** ex releases#56 (was flag: NEEDS-OPERATOR in eval — operator input\n 554|  now sought directly when the entry ripens, not via board flag)\n 555|- **What/why:** the project `.worktrees/` dir accumulates content beyond what git tracks; audit +\n...\n 573|\n*574|#### THE COUNT DISAGREEMENT IS THE FINDING (measured 2026-08-03, todlando + doyle, main @`3efd7e6`)\n 575|\n 576|Three people measuring \"the worktrees\" got three answers. None was wrong; they answered three\n 577|different questions, and nothing in the tree states which one is meant:\n...\n 594|\n*595|#### THE 15 UNREGISTERED DIRECTORIES ARE FOUR DIFFERENT KINDS OF THING\n 596|\n 597|⛔ **CLASS A — LIVE BUILD POOLS, NOT ORPHANS. DO NOT DELETE.** 3 dirs, 13.2 GB. Each is the TARGET of\n 598|a junction that a REGISTERED worktree uses as its `target/`:\n...\n 641|\n*642|#### PIN STATE: NO SKELETON IS HELD TODAY (with a stated blind spot)\n 643|\n 644|Read-only PEB CWD sweep, 2026-08-03: **zero processes hold a CWD in any class-B or class-C\n 645|directory** — every live pin was in `gate-ec5f38a` and `gate-main`, both REGISTERED and both running\n...\n 651|\n*652|#### THE LOOSE FILES: A SHARED LOCATION WITH NO STATED CONTRACT\n 653|\n 654|**21 loose files sit in `.worktrees/`** — gate logs (`gate-*.log`, `gate-559632e-log.txt`), rig\n 655|scripts (`g6-curve.ps1`, `g6-postbounce.ps1`, `gate-w5-*.ps1`), and `gate-w5-notes.md`. **Nobody\n...\n 661|\n*662|#### RECLAIM ARITHMETIC — AND WHY THIS ENTRY IS NOT THE DISK FIX\n 663|\n 664|Classes B, C and D together are **under 51 KB**. All 13.2 GB of the unregistered population is class\n 665|A, behind live junctions. **An orphan sweep is not a disk-space remedy**, and reading it as one sends\n...\n 714|\n*715|### IR-17 — Deadline-burn bring-up family: a test burns its full window while the daemon/brain never comes up\n 716|- **Status:** open · **Origin:** golden 30782259675 red triage 2026-08-03\n 717|- **What/why:** two different tests on two runner hosts now share one signature — bring-up misses\n 718|  its ONLINE window under leg load and the test burns its ENTIRE deadline before the PRECONDITION\n...\n 832|\n*833|### IR-16 — kill_tree discards TerminateJobObject/TerminateProcess returns (silent partial kill)\n 834|- **Status:** BUILT 2026-08-03 (landed @62c5623 on the LOCKSMITH t1 lane; rides golden sha\n 835|  b7b00c3, run 30860770146 green) · **Origin:** ex releases#130 (golden 30776330383 red triage;\n 836|  deployah's log read\n...\n 869|\n*870|### IR-18 — resident_service_e2e kills breadcrumb pids BARE (stale-breadcrumb tree-kill; kill-side twin of IR-15)\n 871|- **Status:** BUILT 2026-08-04 — the named acceptance carrier RAN and the condition is DISCHARGED,\n 872|  stated as the measurement rather than as the green board it sat on: LOCKSMITH's golden run\n 873|  30860770146 (head `b7b00c3`, conclusion success) executed the changed test IN-POOL on BOTH\n...\n 1154|\n*1155|### IR-19 — Docs-only pushes to main run full unit legs (classifier is PR-only) — intent unverified\n 1156|- **Status:** RETIRED 2026-08-18 — intentional for main pushes, not a classifier defect. · **Origin:** hertz observation 2026-08-03 (register-push\n 1157|  cadence gated his rig behind repeated hfenduleam unit legs); mechanism verified by doyle at\n 1158|  source same night.\n...\n 1183|\n*1184|### IR-20 — resident_service_e2e's `spt daemon stop --force` does not stop the daemon; teardown is complete only because the kills are\n 1185|- **Status:** open · **Origin:** hertz 2026-08-03, measured on the IR-18 lane's own clean run\n 1186|  (hfenduleam, log kept); routed text, doyle-landed.\n 1187|- **MEASURED:** teardown runs `spt(&[\"daemon\",\"stop\",\"--force\"])` then reaps. At reaper fire, every\n...\n 1216|\n*1217|### IR-54 — golden-head-intake runbook: three properties this cut proved should be construction, not discipline\n 1218|- **Status:** BUILT 2026-08-29 — PR #176 (`880b3b9c`, landed on main via `37368263`).\n 1219|  · **Origin:** PORTER (#205) v0.59.0 cut, 2026-08-21 — doyle (gater) + deployah (driver),\n 1220|  both mechanisms measured at the cut, neither cost this run anything because the driver caught\n...\n 1248|\n*1249|## IN-FLIGHT ON THE BOARD (not re-homed — live WIP lanes)\n 1250|\n 1251|- releases#93 (servicehost swap test pid-inequality), releases#47 (thin-lane unit(Windows)\n 1252|  isolation class), releases#32 (worker_lifecycle_e2e Phase A intermittent) — infra-shaped but WIP;\n...\n 1254|\n*1255|## BUILT / RETIRED\n 1256|\n*1257|### IR-15 — provably_gone is pid-only on Windows: teardown tests can fabricate reds\n 1258|- **Status:** BUILT 2026-08-03 · **Origin:** golden 30776330383 red on the #125 fix lane (2026-08-02)\n 1259|- **Lane:** hertz `golden/ir15` @a5042ec — REQ-TEST-LIVENESS-ORACLE-AUTHENTICATED (impl+unit): one\n 1260|  shared authenticated death-oracle test helper backed by `spt_procident::process_identity`\n...\n 1283|\n*1284|### IR-21 — CLASS: a helper binary's build is never requested, only its LOCATION is, so any narrow invocation manufactures a red that belongs to the rig\n 1285|- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane. · **Origin:** todlando 2026-08-03. Filed as one instance, rewritten as a CLASS the\n 1286|  same day when a second member appeared, rewritten AGAIN when the mechanism was measured — the\n 1287|  first two versions described symptoms and got the remedy wrong. **Corrected a fourth time the same\n...\n 1302|\n*1303|#### THE MECHANISM (measured, both ends)\n 1304|\n 1305|**Build end — `cargo test` with a narrow target selector compiles a `[[bin]]` AS A TEST HARNESS and\n 1306|never emits the plain executable.** Measured: `cargo test -p spt --bins` on a clean pool produced\n...\n 1334|\n*1335|#### SCOPE — WHERE IT BITES, AND WHERE IT DOES NOT\n 1336|\n 1337|**It bites NARROW invocations — `-p <pkg>`, `--bins`, `--lib` — i.e. gate rigs and local runs.**\n 1338|Both members were hit on the LOCKSMITH t1 lane against fresh throwaway pools; each was discharged\n...\n 1360|\n*1361|#### THE ONE CI-SIDE MEMBER THAT IS REAL\n 1362|\n 1363|`crates/spt/src/cli.rs::adapter_translate_proof_gates_on_commit` is a **unit** test (`kind(bin)`),\n 1364|and `CARGO_BIN_EXE_*` is set only for integration tests and benches of the declaring package. A unit\n...\n 1374|\n*1375|#### POPULATION\n 1376|\n 1377|**13 bin targets in the workspace** (`cargo metadata --no-deps`, not a grep — an auto-target under\n 1378|`src/bin/` and `xtask` are both invisible to a `[[bin]]` grep). Two are not helpers (`spt`, `xtask`);\n...\n 1431|\n*1432|#### REMEDY SHAPE (not ruled)\n 1433|\n 1434|The distinction that matters is location vs. build:\n 1435|\n...\n 1454|\n*1455|#### SUPERSEDED FRAMING, KEPT SO IT IS NOT RE-DERIVED\n 1456|- **Status of the original filing:** open · **Origin:** todlando 2026-08-03, both members hit on the\n 1457|  LOCKSMITH t1 lane against fresh throwaway pools; each discharged in-lane as a rig artifact, filed\n 1458|  here so the next clean rig does not re-diagnose them as code reds.\n...\n 1498|\n*1499|### IR-22 — An inherited identity env var fails a test, and the diagnostic names them ONE AT A TIME so a correct fix reads as no fix\n 1500|- **Status:** open · **Origin:** todlando 2026-08-03, chasing what looked like an `attach_wedge_e2e`\n 1501|  code red on the LOCKSMITH t1 lane; root-caused to the runner's own process environment.\n 1502|- **MEASURED:** `attach_wedge_e2e` failed for an INHERITED PROCESS-GLOBAL and nothing in the tree:\n...\n 1520|\n*1521|### IR-23 — `endpoint_teardown_authority_e2e`'s two tests collide with EACH OTHER through the machine-global spt home\n 1522|- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane. · **Origin:** todlando 2026-08-03, LOCKSMITH t1 lane.\n 1523|- **MEASURED:** both tests copy a psyche binary fixture into `perch::spt_home()/srcs/dummyharness/`\n 1524|  (`crates/spt/tests/endpoint_teardown_authority_e2e.rs:399`), which is process-global, so run in\n...\n 1545|\n*1546|### IR-24 — `reap::terminate_job` discards `TerminateJobObject`'s return, alone among its own module's siblings\n 1547|- **Status:** BUILT — landed `3d12cf3` on main (2026-08-03), fulfilment verified against this\n 1548|  entry's own wanted list by doyle 2026-08-04, not merely mapped to the commit: the return is\n 1549|  audited and the loss NAMED (`REAP_JOB_TERMINATE_FAIL: brain subtree NOT reaped (<os error>); …\n...\n 1585|\n*1586|### IR-25 — `spt-daemon --lib` reds 2-in-3 under concurrent load with bare `cargo test`, and holds green under nextest\n 1587|- **Status:** open · **Origin:** doyle 2026-08-03, found while gating LOCKSMITH tranche 1 in an\n 1588|  isolated worktree; chased to a mechanism and scoped OUT of the release path before the head was\n 1589|  assembled.\n...\n 1632|\n*1633|### IR-26 — POOL-OWNER claims authorize takeover from a DEAD holder, so releases#103's hazard reaches through the guard\n 1634|- **Status:** OPEN for residual claim-time observability and stale-reader enforcement; the\n 1635|  original build-side lane is COMMITTED (see its later reconciliation below), not still\n 1636|  uncommitted. Header corrected 2026-09-11; no residual closed by cleanup. · **Origin:**\n...\n 1805|\n*1806|### IR-27 — A junction-pooled rig is TWO objects and teardown only ever removes one\n 1807|- **Status:** open, found in the wild 2026-08-04 · **Origin:** hertz's 44-tree worktree sweep\n 1808|  (IR-26 follow-on 3) · **Cross-ref:** [[IR-14]] (unclaimed pools), [[worktree-target-junction]]\n 1809|- **What/why:** a rig built as `worktree\\target -> junction -> .worktrees\\<pool>` has its build cache\n...\n 1839|\n*1840|### IR-28 — A wave-gap rider is visible to the request board and invisible to a milestone-narrative notes pass\n 1841|- **Status:** BUILT 2026-08-29 — PR #176 (`880b3b9c`, landed on main via `37368263`).\n 1842|  · **Origin:** deployah, v0.53.0 release close 2026-08-04.\n 1843|- **What/why:** the v0.53.0 changelog omitted `184f2ac` (the releases#125 two-core CPU-burn fix, a\n...\n 1854|\n*1855|### IR-29 — twohost ladder: role A fires the done-barrier BEFORE its last cross-node rung, so the re-pull's serve window is won by timing, not guaranteed\n 1856|- **Status:** OPEN for later serve-window/rung residuals; the original\n 1857|  `test/twohost-serve-window` fix `17bbbd8` LANDED in v0.54.0, as recorded by IR-30.\n 1858|  Stale authored-but-unlanded header corrected 2026-09-11; no new acceptance or margin\n...\n 1917|\n*1918|### IR-30 — GOLDEN 4b37512 (#145): five attempts, four distinct Windows victims, one sha — the random-victim family measured end to end, and the instruments it left behind\n 1919|- **Status:** open for the FAMILY SIGHTINGS ONLY — the instrument lanes LANDED as planned with\n 1920|  the next golden batches (measured 2026-08-25, doyle, `git merge-base --is-ancestor` + first\n 1921|  tag: serve-window `17bbbd8`, selection probe `695398ba`, resume taxonomy `58337879` all in\n...\n 2177|\n*2178|### IR-32 — Docs-drift gate blesses its own gen: an empty-emitting producer agrees with itself perfectly\n 2179|- **Status:** open · **Origin:** todlando mid-lane stop-and-report, U1 (#144) 2026-08-04. Filed by\n 2180|  the builder to the gater deliberately — register shape is doyle's to own.\n 2181|- **What/why:** with a defective binary in the tree (stack-overflowed before reaching its own\n...\n 2211|\n*2212|### IR-33 — Debug-build clap Command tree runs near the main-thread stack ceiling; the margin is THREE net new args, bisected at `8f291e1` (the original ~6 was measured on U1's tree and is superseded)\n 2213|- **Status:** OPEN for acceptance/margin reconciliation. Current source at `e5a2fed9` runs\n 2214|  the CLI on an owned 16 MiB thread stack and includes `cli_stack_smoke`; the three-argument\n 2215|  ceiling below is a historical measurement at `8f291e1`, NOT today's measured margin.\n...\n 2264|\n*2265|### IR-34 — nextest LEAK flag on the zombie-fixture row is dominant-but-intermittent (19/20 measured); any gate reading it as a signal flaps\n 2266|- **Status:** open · **Origin:** doyle #142 F-lane gate 2026-08-04 (first sighting in a gate run);\n 2267|  characterized same day by hertz from retained logs, ownership falsified by todlando.\n 2268|- **What/why:** `broker::tests::windows_session_is_zombie_sees_a_handle_held_corpse_as_dead` (the\n...\n 2289|\n*2290|### IR-35 — hfenduleam Windows test-leg victim rate: one teardown/liveness family, measured at ~half of all executions\n 2291|- **Status:** open · **Origin:** USHER #150 golden triage 2026-08-04 (doyle; all rates deployah-measured).\n 2292|- **The numbers (15 golden runs 2026-08-02..08-04 + the USHER cycle, deduped on `(run, box,\n 2293|  started_at)` — GitHub partial reruns COPY untouched jobs into the new attempt with their ORIGINAL\n...\n 2295|  any rate math):** Windows (hfenduleam) 13 red / 22 executions = 59% leg-red, splitting 10/22 = 45%\n*2296|  test-victim + 3/22 infra (IR-31 class). Linux (kitsubito) 2/20 = 10%, 1 victim. Every victim-red\n 2297|  leg had EXACTLY ONE victim (8/8 legs). Clean-cycle arithmetic ≈ 0.55 × 0.95 ≈ half — a golden\n 2298|  cycle at these rates is a coin flip. knock145 (the previous green golden) took FIVE Windows\n 2299|  executions to its green; USHER took four. **A both-green draw is a draw, not evidence the family\n...\n 2325|\n*2326|### IR-36 — `output_bounded` is a 51-copy clone estate with a named-but-empty shared home; hoist-and-delete wants its own lane\n 2327|- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane. · **Origin:** hertz measurement\n 2328|  2026-08-04 (at `7465ac1`, counted before listing, listed untruncated), during the USHER package\n 2329|  item-2 sweep ruling; doyle ruled file-don't-sweep.\n...\n 2361|\n*2362|### IR-37 — `traceable-reqs check` is coverage-only: tag PLACEMENT is unenforced on any multi-tagged REQ, and the more tags a REQ accumulates the less any one is checked\n 2363|- **Status:** UPSTREAM CLOSED THROUGH RELEASE 2026-08-19 — traceable-reqs PR #19 squash-merged\n 2364|  @`82d8b14` after doyle's targeted re-review PASS (defect A item-tables + 9 red-first regression\n 2365|  cells + sighted control; defect B enclosing-item fallback DECLARED in SPEC with cost; 267/267,\n...\n 2424|\n*2425|### IR-38 — CLASS: an e2e that ends with a live daemon-spawning binary wedges the NEXT build in its pool, and the diagnostic names the wrong lane\n 2426|- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane. · **Origin:** todlando 2026-08-04,\n 2427|  `shell_relink_force_e2e` on the #6 lane (filed by doyle; the finding and the fix are todlando's).\n 2428|- **What/why:** the e2e ends with a LIVE binary by design; on Windows a live process holds its\n...\n 2463|\n*2464|### IR-39 — CLASS: the missing-fixture-bin defect has TWO failure faces, and one of them impersonates a lifecycle defect of the subject under test\n 2465|- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane. · **Origin:** hertz + todlando\n 2466|  2026-08-04, same evening from opposite sides (filed by doyle; hertz relayed todlando's\n 2467|  suggestion without endorsing scope).\n...\n 2500|\n*2501|### IR-40 — CLASS: NO envelope-side ordering signal on a resume brief tracks content recency, and a CI informant's per-job line is a claim about that STEP, not the run\n 2502|- **Status:** open · **Origin:** three sightings in one night, 2026-08-04/05 — hertz, doyle,\n 2503|  todlando (filed by doyle; the artifacts are hertz's and todlando's, the CI arm is doyle's with\n 2504|  deployah's framing). Two arms of ONE family: a stale record that carries a confident ordering\n...\n 2577|\n*2578|### IR-41 — A QUEUED main run is superseded without a record; `cancel-in-progress: false` protects only STARTED runs\n 2579|- **Status:** open — mechanism CONFIRMED (doyle ruling 2026-08-05); the runbook sentence it\n 2580|  falsified is already corrected (`docs/RELEASE-RUNBOOK.md` step 3, same commit as this entry)\n 2581|  · **Origin:** deployah, v0.55.0 publish night, filed by him explicitly as UNPROVEN with the\n...\n 2609|\n*2610|### IR-42 — `pool-claim` writes a record; only the BUILD enforces — and AGENTS.md invited the misread\n 2611|- **Status:** BUILT 2026-08-19 — the AGENTS.md corrective line lands in the SAME COMMIT as this\n 2612|  entry (the register batch commit), which is the entry's stated exit condition. The optional\n 2613|  code-side nicety (claim verb prints the incumbent record it overwrites, information only)\n...\n 2637|\n*2638|### IR-43 — knock answer carrier: `NoReply` landed at 60.08s against a stated 30s carrier deadline\n 2639|- **Status:** open, OBSERVATION — mechanism unmeasured, filed exactly as wide as the datum ·\n 2640|  **Origin:** KNOCK-169 RCA layer 1 (todlando, read-only), golden 32191618042 @`93c1130`,\n 2641|  twohost-b, 2026-08-18.\n...\n 2654|\n*2655|### IR-44 — perch-sentinel comment overclaims: serialization is not preservation, and the comment teaches the false step\n 2656|- **Status:** open · **Origin:** #188 RCA lock read (todlando flagged, doyle confirmed the lock\n 2657|  read), 2026-08-18; the collapse-of-branches argument is on #188 and in the RCA record.\n 2658|- **What/why:** `lock_perch_sentinel` (info.rs:778 at `b20e770`, the diag sha — re-derive the\n...\n 2675|\n*2676|### IR-45 — twohost rig home premise, SETTLED: pump paths resolve under the per-run TEMP root (rig is disk-hermetic; the \"live fleet roster\" reading is retired)\n 2677|- **Status:** RETIRED 2026-08-19 — ask answered by the one code read at main @`78a9a16`; residue\n 2678|  re-homed (see Answer). · **Origin:** #188/#189 RCA readouts (todlando, doyle's 2a-2d), runs\n 2679|  32097943571 + 32108557362 + 32111921251, 2026-08-18.\n...\n 2706|\n*2707|### IR-46 — the Windows disk-floor preflight asserts an INSTANT; workspace free space moves tens of GB inside the hour, so a green floor is not a claim about run headroom\n 2708|- **Status:** open — mechanism CONFIRMED by a measurement series on hfenduleam; doyle ruled it\n 2709|  register-shaped 2026-08-18 · **Origin:** deployah, NAMEPLATE #181 golden-head intake, on the\n 2710|  run that the floor red-floored · **Filed as IR-46 after an id collision:** this row was authored\n...\n 2773|\n*2774|### IR-47 — ci-notify treats a missing co-author trailer as a quiet info line; silent attribution loss reads as \"there was none\"\n 2775|- **Status:** open — patch AUTHORED and stashed unlanded since 2026-07-29\n 2776|  (`.worktrees/_patches/ci-notify-missing-trailer.patch` + its `test-ci-notify.sh` harness in the\n 2777|  sibling `.untracked` dir); surfaced by doyle's 2026-08-19 idle-queue verification of that stash ·\n...\n 2800|\n*2801|### IR-48 — the nextest.toml parity cell tolerates CRLF only by parser accident; a newline-sensitive arm added later reds fresh Windows checkouts alone\n 2802|- **Status:** open — filed 2026-08-19 (doyle route, hertz verdict: REGISTER as preventive\n 2803|  hardening, not current defect) · **Origin:** sibling sweep after the W3 gate CRLF finding —\n 2804|  parent mechanism: `include_str!` embeds working-tree bytes verbatim, `core.autocrlf=true`\n...\n 2821|\n*2822|### IR-49 — poolguard's landed-lane predicate is ancestry-only, so a cherry-picked member lane can never read Settled and its pool can never be taken over\n 2823|- **Status:** open — filed 2026-08-19 (todlando measurement at the keystone-w1/fix-197 reap,\n 2824|  doyle ruling; doyle re-verified the predicate at source before filing) · **Origin:** todlando's\n 2825|  post-landing landed-check used the guard's own predicate and it contradicted the (correct)\n...\n 2855|\n*2856|### IR-50 — e2e failure panels read the PRE-REDIRECT stderr capture; every daemon-side diagnostic lands in a sink the rig deletes unread\n 2857|- **Status:** CLOSED — BUILT 2026-08-19; adoption-completion lane\n 2858|  `docs/ir50-register-close` @`e02f565f` (hertz, doyle-gated 2026-08-20) LANDED in\n 2859|  v0.59.0 as a PORTER rider (pick `e702d4b7` tip, main @`c62904e7`; register sweep\n...\n 2913|\n*2914|### IR-51 — engine-room e2e daemon runs NET-ENABLED on real interfaces; rig hermeticity is disk-deep only\n 2915|- **Status:** open — filed 2026-08-19 (todlando's x40 run-4 sink read, the first live read any\n 2916|  rig has had of the daemon sink; doyle ruled own-id rather than riding #199, at the finder's\n 2917|  own request) · **Origin:** unasked-for find inside the #199 instrument's first catch.\n...\n 2942|\n*2943|### IR-53 — failed-address expiry unit panics during the first 10m01s after Windows boot\n 2944|- **Status:** BUILT 2026-08-21 on `fix/ir53-cold-boot-instant` — LANDED in v0.59.0\n 2945|  (PORTER rider, pick `7b26f28d` on `assembly/porter-205`, main @`c62904e7`; register\n 2946|  sweep 2026-08-21 at release close) · **Origin:** todlando,\n...\n 2968|\n*2969|### IR-52 — docs-site CLI reference renders SHALLOW; help text below the rendered depth is outside the drift gate, unit-held per-REQ or held by nothing\n 2970|- **THIRD INSTANCE, observed 2026-08-24 (todlando, WAX-SEAL #21 W4; not acted on):** the new\n 2971|  `spt api seal verify|describe` FLAGS sit below the generator's rendered depth — the entry's\n 2972|  exact class. The W4 user page hand-documents them, which is per-page self-defense, not a\n...\n 3007|\n*3008|### CI-RIDER LANE STATE — LANDED 2026-08-04 (post-v0.53.0 merge queue); history below kept for its mechanisms\n 3009|- **RESOLVED:** the lane rebased clean onto the post-tag queue and landed ff-only as\n 3010|  `2b33a47`/`2a7b016`/`d63f4ce`/`19d7f79` (content byte-identical to `1275e47..bf8c4a2` by lane-diff\n 3011|  blob hash). IR-1 and IR-4 are BUILT AND LANDED; IR-9's measurement half is landed with its trigger\n...\n 3074|\n*3075|### IR-55 — the `spt --bins` suite wedges partway through on leaked `findstr .` PTY children; the tests at the frontier are casualties, not culprits\n 3076|\n 3077|- **Status:** OPEN, **ARMED-FOR-CAPTURE**, owned by **hertz**. Test/rig defect by the dispatch\n 3078|  split (test/CI rework is never the product builder's). Filed by doyle 2026-08-22 from the\n...\n 3200|\n*3201|### IR-56 — `pool-claim` harvests lane identity from CWD, not from `--pool`; a claim run from the wrong tree writes a WRONG RECORD with a success message\n 3202|\n 3203|- **Status:** BUILT 2026-08-24 for the SIGNET #218 golden batch on\n 3204|  `fix/ir56-pool-claim-cwd`, owned by **hertz**. Tooling/rig defect by the dispatch split. Filed by\n...\n 3247|\n*3248|### IR-57 — an assembly pick's conflict resolution can silently DROP lines, and every gate run at assembly time is blind to it\n 3249|\n 3250|- **Status:** OPEN, owned by **doyle** (gater craft, not a code defect — no lane to dispatch).\n 3251|  Filed 2026-08-22 from doyle's own defect on the TURNKEY #212 assembly head.\n...\n 3306|\n*3307|### IR-58 — a `[[bin]]` grep is not a census: cargo AUTODISCOVERS `src/bin/*.rs` targets, and a hand-built bin list produced a confident false \"this bin does not exist\"\n 3308|\n 3309|- **Status:** OPEN, unowned. Filed by doyle 2026-08-22; **its original filing was WRONG and is\n 3310|  retracted in full below.** The entry is kept because the way it was wrong is the finding.\n...\n 3341|\n*3342|### IR-59 — pool arithmetic: this box holds TWO cold pools, not four; and a build that exhausts the volume reds as a LINKER defect that names no disk\n 3343|\n 3344|- **Status:** OPEN, unowned — it is arithmetic and discipline, not a code lane. Filed by doyle\n 3345|  2026-08-22 from a live disk-floor abort during the TURNKEY #212 W4 gate; footprint figures measured\n...\n 3475|\n*3476|### IR-60 — a wrapper that CAPTURES a leg's exit status ends with the capture, so the wrapper's own status is the capture's, not the leg's\n 3477|\n 3478|- **Status:** OPEN, unowned — script-shape discipline, not a code lane. Filed by doyle 2026-08-22\n 3479|  during the TURNKEY #212 W5 lane; mechanism measured by todlando, who reported it first as a\n...\n 3524|\n*3525|### IR-61 — spacerun's test-module skip carries a SECOND literal tracker; the two answers can drift, and today only a cell stands between them\n 3526|\n 3527|- **Status:** OPEN, unowned, accepted-with-mitigation. Filed by doyle 2026-08-22 at the TURNKEY #212\n 3528|  head gate, as the named residual of the latch repair (the repair itself rides the milestone).\n...\n 3557|\n*3558|### IR-62 — an e2e daemon binds well-known ports and collides with the resident fleet on shared runners\n 3559|\n 3560|Filed 2026-08-23 (doyle), from the #212 r2 golden's Windows Phase A red — one witnessed\n 3561|instance, mechanism verified from the run's own capture, filed on the mechanism per the\n...\n 3598|\n*3599|### IR-63 — suite-mix sweeps leak job-escaped autostart daemons that LOCK the pool's spt.exe; and the same box conditions manufacture one random victim per sweep\n 3600|\n 3601|- **Status:** OPEN, mitigated-by-rig-step — the reap is adopted discipline, not yet construction.\n 3602|  Filed by doyle 2026-08-24 at the SIGNET #218 gates; first measured by todlando the same day\n...\n 3637|\n*3638|### IR-64 — HFENDULEAM's disk floor is set by non-CI bulk: ~845 GB of operator payload leaves the golden box ~2 GB of slack against its own 32 GB preflight\n 3639|\n 3640|- **Status:** OPEN · **Origin:** doyle, v0.63.0 close sweep 2026-08-26; mechanism first measured\n*3641|  at the FIELD-SEAL golden window (deployah's IR-31 fifth addendum carries the POOL side of the\n 3642|  same event by agreed division — this entry is the OTHER reservoir, deliberately not his).\n 3643|- **Mechanism:** the 1.86 TB C: carries ~614 GB Steam + ~230 GB Downloads (operator payload, not\n 3644|  CI state). With that floor fixed, normal lane traffic alone walks the box under the 32 GB\n 3645|  golden preflight — a full-sweep pool WEIGHS ~90–112 GB steady state (IR-59's measurement) and\n*3646|  five FIELD-SEAL lanes cost 148.48 GB (IR-31 fifth addendum), so ONE milestone's pools exceed\n 3647|  the entire free margin. Reaping buys windows, not headroom: deployah measured free fall\n 3648|  167 → 108 GB within hours of his reap, ~59 GB re-consumed by lane builds. The recurring shape:\n 3649|  every milestone pays a reap-and-measure tax to rent space the box does not structurally have.\n*3650|- **Why register-worthy rather than \"clean up more\":** agent-side discipline (IR-31's budgeting,\n 3651|  pool reaps, teardown steps) is already adopted and still only rents windows — the reservoir\n 3652|  that would durably move the floor is operator-owned bulk no agent may touch. Naming it here is\n 3653|  the boundary: agents keep budgeting IN POOLS (not GB); moving Steam/Downloads (or adding a\n...\n 3659|\n*3660|### IR-65 — kitsubito kernel-audit backpressure: a tailscale-snap AppArmor denial storm + no auditd turned the default audit backlog into a CI-wide stall amplifier (REMEDIATED AT BOX; re-check triggers named)\n 3661|\n 3662|- **Status:** REMEDIATED-AT-BOX 2026-08-25 (doyle, operator-authorized root — ruling pinned\n 3663|  releases#225 comment 5418800776); entry stays OPEN as the re-check record because the storm\n...\n 3685|\n*3686|### IR-66 — first-chunk-needle test class: two latent members remain after the v0.63.0 fix (attach.rs:561, :672)\n 3687|\n 3688|- **Status:** CLOSED / BUILT — release-close reconciliation 2026-09-11. The WEBSERVE JIT already\n 3689|  ruled this satisfied; source at `e5a2fed9` retains both delayed needles. Closure uses the\n...\n 3718|\n*3719|### IR-67 — wave-battery gap: a `-p spt --bins` leg compiles bin targets as harnesses and runs ZERO integration/e2e tests, so batteries that lean on it carry silent no-coverage legs\n 3720|\n 3721|- **Status:** BUILT — remedy applied across the IO-PARSER #22 milestone (2026-08-27/28): every\n 3722|  wave battery named explicit `-p spt --test <suite>` e2e legs beside the `--bins` unit leg\n...\n 3740|\n*3741|### IR-68 — PSYCHE_INGEST_FAIL cause class unproven: git index.lock did NOT reproduce the ingest failure it was blamed for\n 3742|\n 3743|- **Status:** OPEN, investigation-shaped · **Origin:** todlando measurement at the W2 int-leg rig\n 3744|  (IO-PARSER #22, PR #163 at `769fb0a9`, 2026-08-27), reported measure-first; filed by doyle.\n...\n 3768|\n*3769|### IR-69 — inherited stderr tokens can tear between format fragments; 26 test consumers parse that surface as structured truth\n 3770|\n 3771|- **Status:** OPEN for the #243 residual population and anchored-consumer work. The original\n 3772|  product remedy LANDED at `ec6da9b0`, as recorded in this entry's later amendment; it is not\n...\n 3860|\n*3861|### IR-70 — a hand-built `IoBus` silently omitted later sinks while every gate stayed green\n 3862|\n 3863|- **Status:** OPEN, remedy unscheduled; the v0.65.0 respin fixed the witnessed call site on PR #173.\n 3864|  This entry owns the recurrence class, not that shipped correction. · **Origin:** releases#234,\n...\n 3887|\n*3888|### IR-71 — controller-seat release has no persisted breadcrumb, so tests cannot distinguish propagation lag from a missing detach\n 3889|\n 3890|- **Status:** OPEN, observability gap; no remedy scheduled. · **Origin:** CONDUIT #236 r3\n 3891|  `er_brief_once_per_session_e2e` intermittent, classified test-side and fixed on PR #174.\n...\n 3911|\n*3912|### IR-72 — no product read verb surfaces which process holds a perch or controller seat\n 3913|\n 3914|- **Status:** OPEN, observability gap; no remedy scheduled. · **Origin:** CONDUIT #236 r3\n 3915|  two-host RCA and PR #174 (`70c1a303`), corrected by doyle after IR-18 and daemon-status were\n...\n 3945|\n*3946|### IR-73 — ci.yml and release.yml still read the free-space floor PRE-checkout (literal-first sites off the golden path); and any job's floor is stale by its last heavy step\n 3947|\n 3948|- **Status:** CLOSED / BUILT — source reconciliation 2026-09-11 at `e5a2fed9`: all five\n 3949|  `ci.yml` sites and all three `release.yml` sites now read after checkout, with IR-73 comments;\n...\n 3969|\n*3970|### IR-74 — kitsubito holds 21,643 /tmp endpoint homes: box-side accumulation nothing bounds or measures\n 3971|\n 3972|- **Status:** OPEN, filed by doyle 2026-08-30 at the #242/v0.66.0 close sweep; measurement by\n 3973|  hertz (2026-08-29). · **Origin:** rig work on kitsubito found `/tmp` carrying 21,643 endpoint\n 3974|  homes — per-run spt homes that outlive their runs.\n*3975|- **What/why:** sibling of the [[IR-31]]/[[IR-59]]/[[IR-64]] family (box accumulation the\n 3976|  preflights never see): each is small, the population is not, and /tmp on a long-lived box is\n 3977|  never reaped by CI. Un-reaped homes also widen every by-path census a rig runs. Needs a\n 3978|  bounded lifecycle (per-run temp root reaped at run end, or a box-side sweep with a stated\n...\n 3983|\n*3984|### IR-75 — traceable-reqs is not installed on kitsubito, so every Linux gate driver's treqs leg exits 127 (vacuous, wrapper-green shape)\n 3985|\n 3986|- **Status:** OPEN, filed by doyle 2026-08-30 at the #242/v0.66.0 close sweep (deployah\n 3987|  co-flagged at intake). · **Origin:** ASM-241 Linux battery — `ASM_treqs.exit` = 127, raw\n...\n 3998|\n*3999|### IR-76 — hfenduleam is the golden Windows runner AND the builders' box: a local workspace nextest fully contained a golden Phase A and manufactured a load-timing red, and the job-start census cannot see it\n 4000|\n 4001|- **Status:** OPEN, filed by doyle 2026-09-06 during v0.67.1 golden triage (run 34017906638\n 4002|  att2). · **Origin:** the Windows Phase A red on\n...\n 4042|\n*4043|### IR-77 — nothing stamps the interval between a daemon child's spawn and the brain's first log line, so a readiness-deadline red cannot say WHERE the time went\n 4044|\n 4045|- **Status:** OPEN, filed by hertz 2026-09-07 from the W1 #249 kitsubito battery at the gated\n 4046|  sha `8d980fdf`; doyle-ruled at filing to be a register entry rather than a lane rider. ·\n...\n 4074|\n*4075|### IR-78 — `SPT_TEST_EPHEMERAL_ADVISORY_PORTS` silently overrides an explicitly set `SPT_DOCS_PORT`\n 4076|\n 4077|- **Status:** OPEN, filed by hertz 2026-09-07, MEASURED by doyle the same night on his W2\n 4078|  field pair (both boxes). · **Origin:** the 5474 rig-hygiene sweep in\n...\n 4102|\n*4103|### IR-79 — 22 of the 31 rig binaries leak their daemon tree on a failing assert: teardown is a statement, not a guard\n 4104|\n 4105|- **Status:** OPEN, filed by hertz 2026-09-07 on doyle's dispatch during PR #198's CI window,\n 4106|  from todlando's red 6 (a stale same-port daemon from his own previous run answering the next\n...\n 4183|\n*4184|### IR-80 — five leaky cells on ONE module (`brainproc` / `supervise_brain`), Windows only: a candidate PRODUCT leak on the promotion/rollback path, or a cluster of names — nobody has looked yet\n 4185|\n 4186|- **Status:** OPEN for the residual population, not an undiagnosed five-name product claim.\n 4187|  Later amendments identify the brainproc shell-wrapper fixture mechanism and distinguish\n...\n 4251|\n*4252|#### THE LEAK SET IS NOISY — measured across three shas, 2026-09-07 (hertz)\n 4253|\n 4254|**This retracts the \"8 -> 5 leaky, direction favourable\" reading I flagged at 09:31Z.** It is not a\n 4255|fix and not an improvement; it is threshold noise, and the census this draft was built on inherits\n...\n 4280|\n*4281|#### Three consequences for this draft\n 4282|\n 4283|1. **A count is not a quality signal here, in either direction.** Any future \"leaky went down\"\n 4284|   claim needs the NAME diff and a causality check against the changed files, or it is noise\n...\n 4296|\n*4297|#### One structural finding the noise does NOT touch\n 4298|**All nine union members spawn a child and then kill it, let it time out, or inspect its corpse** —\n 4299|`trial_kills_alive`, `kill_waker_at`, `bounded_run_kills_on_timeout`, `extractor_timeout_errors`,\n 4300|`fetcher_timeout_errors`, `windows_session_is_zombie_sees_a_handle_held_corpse_as_dead`, and the\n...\n 4307|\n*4308|#### THE 12-CELL UNION — 4 shas x 2 OSes, membership beside the invariant (hertz, 2026-09-07 10:15Z)\n 4309|\n 4310|Machine-generated from the eight ci unit logs, not transcribed (a hand-typed 12x8 matrix is where\n 4311|transcription errors live). `X` = reported LEAK at that sha on that box.\n...\n 4330|\n*4331|#### Three readings, in increasing order of what they support\n 4332|\n 4333|**1. The churn is total and it is the whole point.** Windows counts run 8, 8, 5, 9 — the HIGHEST\n 4334|value is at `f3c8495b`, the tip carrying every fix F1-F16. Only **4 of 12** cells are present at\n...\n 4388|\n*4389|#### A MECHANISM, read out of the source of the two Linux cells — calibrated, not generalized\n 4390|`process_cmdline_reads_a_live_arg_marker` spawns **`sh -c \"sleep 30; : marker\"`**, and the test's\n 4391|own comment says the trailing `; :` is deliberate — it keeps the shell RESIDENT so its\n 4392|`/proc/<pid>/cmdline` still carries the marker instead of being tail-exec-replaced by `sleep`. The\n...\n 4417|\n*4418|#### AMENDMENT 1 — \"a pid is not a tree\" has THREE faces, and only one of them is a kill\n 4419|\n 4420|*(hertz 2026-09-07, ruled by doyle 11:17Z: write this as an IR-80 amendment naming the three faces\n 4421|rather than three separate entries, so a reader hunting any one face lands on all three.)*\n...\n 4465|\n*4466|### IR-81 — a process kill can be written scoped or machine-wide, and nothing makes the scoped form the only reachable one: both codebases carry the right pattern beside the wrong one\n 4467|\n 4468|- **Status:** OPEN, drafted by hertz 2026-09-07 08:38Z on doyle's dispatch (08:36Z), from the\n 4469|  fleet-daemon death on hfenduleam at 08:03:15Z ([[RCA-FLEET-DAEMON-14444]], cause still UNNAMED).\n...\n 4530|\n*4531|#### ADAPTER-SIDE ARM: CLOSED (claude-spt, perri, 2026-09-07)\n 4532|\n 4533|**Status: closed in the consumer repo, test-only, does not close IR-81 here.**\n 4534|\n...\n 4559|\n*4560|#### SCOPING ARM (a) — the product path has no intermediary; the fixture does\n 4561|*(hertz 2026-09-07, ruled by doyle 10:22Z off the IR-80 leak work.)*\n 4562|\n 4563|> **A pid is not an identity and a pid is not a tree. IR-80 needs CALLERS, not code.**\n...\n 4590|\n*4591|### IR-82 — a daemon death leaves NO record of who died: autostart decides on a socket ping, says \"no daemon\", and the successor overwrites the only handle on the corpse\n 4592|\n 4593|- **Status:** RULED 2026-09-07 11:07Z (doyle), drafted by hertz 11:04Z on doyle's dispatch (11:03Z: *\"the autostart\n 4594|  death-cause item is an IR, not a board item — mint it IR-82 in your thin PR\"*). Register on main\n...\n 4696|\n*4697|### IR-83 — a two-host rig addressed over the tailnet cannot receive INBOUND on Windows, and the whole rig population had only ever run the admitted direction\n 4698|\n 4699|- **Status:** OPEN, minted by hertz 2026-09-07 11:41Z on doyle's dispatch (11:40Z). **Provenance: the\n 4700|  mechanism below is DOYLE'S measurement, not mine** — eight probe arms, each with sender, listener\n...\n 4833|\n*4834|### IR-84 — the one `PUMP_PEER_FAIL` arm the rigs actually fire was the only one carrying no clock, so the stall that produced it could be counted but never timed\n 4835|\n 4836|- **Status:** OPEN, filed by hertz 2026-09-09 with the instrument that closes its first half. ·\n 4837|  **Origin:** the 65 s two-host helper stall (design written before the run,\n...\n 4883|  stamps, so the fifth site added cannot be born silent.\n*4884|### IR-85 — the Windows self-hosted box runs its fs-heavy tests 3-4x slower than a week ago; two CI wall clocks were sized for the old box, and a red run kept hiding it\n 4885|\n 4886|- **Status:** OPEN, filed by hertz 2026-09-09 at the #272/v0.68.0 golden r3/r4 arc, on doyle's\n 4887|  dispatch. Number ruled by doyle from his own census of main@`a2f335f8` (register ended at IR-83;\n...\n 5043|\n*5044|### IR-86 — golden's 32 GiB floor is BELOW the measured 67.4 GiB Windows suite footprint, so a start floor passes a box that cannot finish\n 5045|\n 5046|- **Status:** OPEN, filed by doyle 2026-09-08 at the #272/v0.68.0 golden r2 triage. · **Origin:**\n 5047|  run 34262154550 @ `25e60015` (shaped on `e4444413`), Windows test job 102182665033: every product\n...\n 5092|\n*5093|### IR-87 — two-host ceremony halves are INDEPENDENT jobs on DIFFERENT runners (A Windows/hfenduleam, B Linux/kitsubito); B's 900 s budget runs on B's own clock, so any older queued Windows job starves A and reds B deterministically, and the panic text blames pairing\n 5094|\n 5095|- **Status:** OPEN, filed by doyle 2026-09-08 at the #272 golden r2 triage. · **Origin:**\n 5096|  run 34262154550, twohost-b job 102207296960 (log 81,692 B, sha256 67403f04…8030): role B built,\n...\n 5145|\n*5146|### IR-88 — `pool-release` via `cargo run -p xtask` REBUILDS xtask INTO the pool it is releasing, so a reaped pool regrows ~2.8 GB in silence\n 5147|\n 5148|- **Status:** OPEN, filed by doyle 2026-09-08 from hertz's reap report (20:00Z) during the #272\n 5149|  golden r2 repair. · **Origin:** hertz reaped hertz-lane4 / hertz-repin / hertz-percell-id target\n...\n 5169|  rather than merely proposed.\n*5170|- **Kin:** [[IR-31]] (pool budgeting), [[IR-56]] (pool-claim identity from CWD — same verb\n 5171|  family, same \"the tool acts on where it stands\" shape), releases#103.\n 5172|- **Ripe when:** next xtask pool-verb touch or the teardown runbook edit. · **Size:** tiny —\n 5173|  one guard or one doc line.\n...\n 5182|\n*5183|### IR-89 — hfenduleam's Windows Firewall drops cold inbound UDP to the runner-built test exes, so the two-host rig's first B→A claim (W2 helper) reds for its whole 900 s budget and the panic blames A\n 5184|\n 5185|- **Status:** BOX HALF **APPLIED** 2026-09-08; WORKFLOW HALF **BUILT** 2026-09-09 — PR #211\n 5186|  (`9b96d7e7` + this amendment), **LANDED, exact golden-step acceptance unreconciled**.\n...\n 5338|\n*5339|### IR-90 — a full disk on the self-hosted box reds a rig as a PRODUCT refusal, not a build error, and no rig or gate records the free space that would falsify it\n 5340|\n 5341|- **Status:** OPEN, filed by hertz 2026-09-09 from the disk-full incident on hfenduleam. ·\n 5342|  **Origin:** the IR-85 discriminator lane's head arm, killed by the volume rather than by the code\n...\n 5427|\n*5428|### IR-91 — 561 untracked files sat at the repo root, 18 of them cited by tracked files, and the census that classified them used a corpus that made the discriminator invisible\n 5429|\n 5430|- **Status:** CLOSED by the lane that filed it (the root-scratch classify PR), hertz 2026-09-09 on\n 5431|  doyle's census and rulings. · **Origin:** the `.spt/` ignore lane (PR #212) named 561 untracked\n...\n 5481|\n*5482|### IR-92 — the message that WAKES an idle spt-hosted endpoint rides a delivery leg that never publishes MSG_IN, so a woken agent's own funnel holds none of the messages that woke it\n 5483|\n 5484|- **Status:** OPEN — filed doyle 2026-09-09 from hertz's census, probe and proposed text (his by\n 5485|  role; the recorder read and the REQ reading are doyle's). Fix lane unassigned: product change in\n...\n 5613|\n*5614|### IR-93 — no PDB ships beside the installed `spt` binary, so the one non-invasive read of a wedged production daemon comes back without a single named frame\n 5615|\n 5616|- **Status:** OPEN, filed by doyle 2026-09-10. **The number was reserved by NAME on 2026-09-09** at\n 5617|  the #293 mechanism read (\"PDB ask -> IR-93 at next sweep\") and this entry closes that claim — a\n...\n 5642|\n*5643|### IR-94 — xtask's brainread deadline gate cannot SEE `serve_sync`: its registry is three hand-listed files and its predicate is a name shape, so a stream server outside both got the reply form and the gate stayed green\n 5644|\n 5645|- **Status:** OPEN, filed by doyle 2026-09-10 at the releases#294 / v0.69.0 golden RED triage. **This\n 5646|  is an INDEPENDENT gate finding, not the cause of that red** — it was found while reading the\n...\n 5672|\n*5673|### IR-95 — a burned polling budget names WHAT it wanted and never HOW LONG it waited, so no run, green or red, can say how close it came\n 5674|\n 5675|- **Status:** OPEN, filed by doyle 2026-09-10 at the releases#294 golden RED, where it cost this\n 5676|  triage most of a morning and four agents. · **Origin:** the two Windows Phase A failures at\n...\n 5927|\n*5928|### IR-96 — the `daemon_stop_convoy_e2e` API-storm cell fails 3-of-3 under the HEAVY suite at the diagnostic tree while passing at the candidate in golden CI, and nothing yet separates instrumentation from box from product\n 5929|\n 5930|- **Status:** OPEN, **cause-unclassified** (todlando's and hertz's stipulation, adopted verbatim — a\n 5931|  triage placement here is NOT a finding of non-defect).\n...\n 5963|\n*5964|### IR-97 — a suite that leaks a fixed cohort of child processes per invocation makes consecutive runs non-comparable, and the between-run accounting the protocol required was not enforced\n 5965|\n 5966|- **Status:** OPEN. **Protocol deviation** (hertz's framing, and it is stronger than \"confounder\":\n 5967|  the protocol ALREADY required between-run accounting — execution did not enforce it, so the fix is\n...\n 6006|\n*6007|### IR-98 — a lane driver that PRINTS a producer's output can die on an unencodable byte AFTER that producer's evidence is on disk, so the run ends with complete evidence for producer N and NO files for N+1 — an absence that reads as \"never queued\", not as a failure\n 6008|\n 6009|- **Status:** OPEN as a mechanism; the measured instance is FIXED in hertz's lane driver (UTF-8 with\n 6010|  replacement reconfigured at import, positive control run before relaunch: U+2500 and U+2713\n...\n 6030|\n*6031|### IR-99 — EOF and terminal retire on a ConnectionBound net stream arm on the OPENER CONN's exit; a same-morning diagnosis built on that mechanism was refuted by the compiler, so the mechanism stands and the two #304 reds beside it stay open\n 6032|\n\n[Showing lines 1-785 of 1015 (50.0KB limit). Use :786 to continue]"}],"details":{"scopePath":".worktrees/hertz-ir86-disk-delta/docs/INFRA-REGISTER.md","searchPath":"C:\\Users\\decid\\Documents\\projects\\spt-core\\.worktrees\\hertz-ir86-disk-delta\\docs\\INFRA-REGISTER.md","cwd":"C:\\Users\\decid\\Documents\\projects\\spt-core","matchCount":172,"fileCount":1,"files":[".worktrees/hertz-ir86-disk-delta/docs/INFRA-REGISTER.md"],"fileMatches":[{"path":".worktrees/hertz-ir86-disk-delta/docs/INFRA-REGISTER.md","count":172}],"truncated":true,"displayContent":"   *1│# Infra register — CI / build-pipeline debt\n    2│\n    3│Operator-ruled 2026-08-02: infrastructure and CI-pipeline work items live HERE, not on the\n    4│`spt-bs-releases` board. The board carries product surface the operator triages; this register\n     │...\n   11│Last sweep: **2026-09-11, v0.69.0 RELEASE CLOSE — FULL REGISTER**, source `e5a2fed9`.\n  *12│All **97 entries (IR-1–97, including headingless IR-31)** read in two disjoint ranges; audit\n   13│population checked for missing/duplicate IDs (97 rows, 97 unique, zero missing). Per-entry\n   14│trigger and disposition evidence: `.spt/preserved/infra-close069-20260911/audit.json`.\n   15│UNKNOWN means no qualifying event established, not a disproved trigger or a discharged debt.\n     │...\n   43│- **Next-intake composition, owned by doyle until accepted:** hertz's driver/workflow package\n  *44│  takes IR-31/46/59/60/76/86/87/90/97: aggregate capacity, truthful producer status, existing\n   45│  quiet-window contract, independent rendezvous clocks, and mandatory between-run identity\n   46│  census. IR-88 adopts the already-proven prebuilt release-before-delete recipe; IR-64 remains\n   47│  a separate operator capacity decision. No new loaded comparison before these prerequisites.\n     │...\n   64│\n  *65│### Intake addendum — hosted-relay diagnostic capacity hold (2026-09-11)\n   66│\n   67│Sourced C: free samples around the intake, each named by file: **19,260,395,520 bytes at\n   68│03:02:33Z** (post-merge run 34556292801, unit job `FLOOR_END`, RED against the\n     │...\n   95│The isolated hosted-relay experiment is separate from #304 implementation and from the #294\n  *96│cause investigation. Carry its capacity planning under **IR-31/59/90**, not a new product\n   97│request. Hertz owns identifying the minimum diagnostic target, reusable version-matched\n   98│artifacts, estimated incremental build/temp footprint and the concrete socket/network isolation\n   99│gap. Doyle owns matching that requirement to an owned pool and available capacity before\n     │...\n  108│IR-76's origin. Enumeration by a read-only subagent into `REGISTER-SWEEP-0671-DRAFT.md` (75\n *109│entries, 10 trigger-text candidates; IR-31 has NO `###` heading — its body sits under IR-30's,\n  110│flagged, not normalized). Rulings: **IR-46 trigger FIRED and was MISSED** — `golden.yml` was\n  111│touched by `04e32c8c` itself (2-line HEAVY reclass on the respin) and no remedy was weighed; a\n  112│respin edit under a pre-registered hard stop is not a remedy window, so the entry gains that datum\n     │...\n  270│\n *271│## OPEN\n  272│\n *273│### IR-1 — Quiet predicate needs a network axis (tailscale RTT probe)\n  274│- **Status:** BUILT AND LANDED — reconciled at [[CI-RIDER LANE STATE]]; golden-only exercise\n  275│  recorded at the 2026-08-05 close (30971976024). Header corrected 2026-09-11. Originally\n  276│  carried by `bf8c4a2` → `REQ-CI-LINK-HEALTH-PROBE`, mapping CONFIRMED by builder hertz 2026-08-03\n     │...\n  302│\n *303│### IR-2 — Settle the warm-runner CARGO_INCREMENTAL delta\n  304│- **Status:** RETIRED 2026-08-28, measurement run, verdict NO FLIP — incremental stays ON.\n  305│  hertz paired goldens at main fed965f8: ON run 33167693879 GREEN; OFF run 33172022108 RED\n  306│  (Windows input_ack_deadlock SetupFailed at a 3.0s IPC read deadline — the box-load family,\n     │...\n  327│\n *328│### IR-3 — Daemon-level guard: broker-net wakeup rate bounded across endpoint churn\n  329│- **Status:** open · **Origin:** releases#125 remediation, todlando REQ call 1 (ex releases#128)\n  330│- **What/why:** the swarm-discovery GC-spin burned two cores for two weeks visible only in a\n  331│  process table — no suite assertion sees the class. Wanted: a daemon-level assertion that\n     │...\n  340│\n *341│### IR-4 — Lock-pin guard + lock-procedure rule + toolchain print (three riders, one lane)\n  342│- **Status:** BUILT AND LANDED — `1275e47` / `49d4805` / `8ed006b` mapped and landed in the\n  343│  [[CI-RIDER LANE STATE]] reconciliation; golden toolchain-print exercise recorded at the\n  344│  2026-08-05 close (30971976024). Stale unlanded header corrected 2026-09-11. ·\n     │...\n  363│\n *364│### IR-5 — Shared nextest summary parser\n  365│- **Status:** open · **Origin:** BAROMETER triage (standing recommendation, pre-register)\n  366│- **What/why:** two agents in one day wrote `[0-9]+ tests run` parsers that read \"1 test run\"\n  367│  (singular) as zero — a guard fed by a broken parser condemns valid rounds. One shared,\n     │...\n  382│\n *383│### IR-6 — Membership logging on subnet gates\n  384│- **Status:** open · **Origin:** BAROMETER triage (standing recommendation, pre-register)\n  385│- **What/why:** counts beside results, membership beside counts — gate logs that state a count\n  386│  without naming the population keep producing unreadable reds. Standardize membership\n     │...\n  394│\n *395│### IR-7 — Phase A rigs leak a daemon+brain pair on Windows (exe-lock kills notify relink)\n  396│- **Status:** open · **Origin:** BAROMETER post-publish triage (ex releases#124 — full mechanism on the closed issue)\n  397│- **What/why:** two Phase A rigs launch daemons that escape the job object via WMI-rung autostart\n  398│  (double-space unquoted cmdline fingerprint; SPT_HOME in the wrapper cmdline is the attribution\n     │...\n  405│\n *406│### IR-8 — reap-census scoped_survivors=0 is blind to unreadable-path holders\n  407│- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane. · **Origin:** BAROMETER triage\n  408│  (ex releases#122)\n  409│- **What/why:** a zero that cannot see is not a zero — census scoping skips procs whose exe path is\n     │...\n  439│\n *440│### IR-9 — Golden boxes run different clippy versions\n  441│- **Status:** pin LANDED 2026-08-18 at `35968156` (`build: pin Rust 1.96.0`), then\n  442│  audited **BUILT** at the 2026-08-29 v0.65.0 close sweep; the pin is an ancestor of\n  443│  golden-green cut SHA `4d6007ac`. The earlier measurement half had already landed and run:\n     │...\n  477│\n *478│### IR-10 — Wave gate runs the CONSUMERS of any predicate it changes\n  479│- **Status:** open · **Origin:** BAROMETER gate craft (ex releases#119)\n  480│- **What/why:** legs chosen from changed crates miss the predicate's callers; a composed red is\n  481│  triaged at the wave's own tip first. This is the gate-population rule made binding in the gate\n     │...\n  485│\n *486│### IR-11 — find-cwd-holders.ps1: --headless discriminator as a column\n  487│- **Status:** open · **Origin:** worktree-pin triage tooling (ex releases#118)\n  488│- **What/why:** the holder-triage script buries the headless-vs-interactive discriminator in prose;\n  489│  as a column it makes the orphan-vs-own-shell call one glance.\n     │...\n  492│\n *493│### IR-12 — xtask contract-drift gate misses a stale manifest.schema.json\n  494│- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane (the narrowed blind arm only). · **Origin:** ex\n  495│  releases#116\n  496│- **KIN NOTE RETIRED (2026-09-06, hertz; doyle measure-first ruling):** the stale-binary\n     │...\n  540│\n *541│### IR-13 — Test-soundness follow-ups from the uniform-table sweep\n  542│- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane. · **Origin:** ex releases#58\n  543│- **What/why:** the remaining candidates from the closed issue were mutation-proved before changing\n  544│  tests. `hold_outranks_everything` now walks all four `Opportunity` arms (including\n     │...\n  551│\n *552│### IR-14 — .worktrees audit: \"how many worktrees are there\" has four defensible answers, and the difference is not junk\n  553│- **Status:** open · **Origin:** ex releases#56 (was flag: NEEDS-OPERATOR in eval — operator input\n  554│  now sought directly when the entry ripens, not via board flag)\n  555│- **What/why:** the project `.worktrees/` dir accumulates content beyond what git tracks; audit +\n     │...\n  573│\n *574│#### THE COUNT DISAGREEMENT IS THE FINDING (measured 2026-08-03, todlando + doyle, main @`3efd7e6`)\n  575│\n  576│Three people measuring \"the worktrees\" got three answers. None was wrong; they answered three\n  577│different questions, and nothing in the tree states which one is meant:\n     │...\n  594│\n *595│#### THE 15 UNREGISTERED DIRECTORIES ARE FOUR DIFFERENT KINDS OF THING\n  596│\n  597│⛔ **CLASS A — LIVE BUILD POOLS, NOT ORPHANS. DO NOT DELETE.** 3 dirs, 13.2 GB. Each is the TARGET of\n  598│a junction that a REGISTERED worktree uses as its `target/`:\n     │...\n  641│\n *642│#### PIN STATE: NO SKELETON IS HELD TODAY (with a stated blind spot)\n  643│\n  644│Read-only PEB CWD sweep, 2026-08-03: **zero processes hold a CWD in any class-B or class-C\n  645│directory** — every live pin was in `gate-ec5f38a` and `gate-main`, both REGISTERED and both running\n     │...\n  651│\n *652│#### THE LOOSE FILES: A SHARED LOCATION WITH NO STATED CONTRACT\n  653│\n  654│**21 loose files sit in `.worktrees/`** — gate logs (`gate-*.log`, `gate-559632e-log.txt`), rig\n  655│scripts (`g6-curve.ps1`, `g6-postbounce.ps1`, `gate-w5-*.ps1`), and `gate-w5-notes.md`. **Nobody\n     │...\n  661│\n *662│#### RECLAIM ARITHMETIC — AND WHY THIS ENTRY IS NOT THE DISK FIX\n  663│\n  664│Classes B, C and D together are **under 51 KB**. All 13.2 GB of the unregistered population is class\n  665│A, behind live junctions. **An orphan sweep is not a disk-space remedy**, and reading it as one sends\n     │...\n  714│\n *715│### IR-17 — Deadline-burn bring-up family: a test burns its full window while the daemon/brain never comes up\n  716│- **Status:** open · **Origin:** golden 30782259675 red triage 2026-08-03\n  717│- **What/why:** two different tests on two runner hosts now share one signature — bring-up misses\n  718│  its ONLINE window under leg load and the test burns its ENTIRE deadline before the PRECONDITION\n     │...\n  832│\n *833│### IR-16 — kill_tree discards TerminateJobObject/TerminateProcess returns (silent partial kill)\n  834│- **Status:** BUILT 2026-08-03 (landed @62c5623 on the LOCKSMITH t1 lane; rides golden sha\n  835│  b7b00c3, run 30860770146 green) · **Origin:** ex releases#130 (golden 30776330383 red triage;\n  836│  deployah's log read\n     │...\n  869│\n *870│### IR-18 — resident_service_e2e kills breadcrumb pids BARE (stale-breadcrumb tree-kill; kill-side twin of IR-15)\n  871│- **Status:** BUILT 2026-08-04 — the named acceptance carrier RAN and the condition is DISCHARGED,\n  872│  stated as the measurement rather than as the green board it sat on: LOCKSMITH's golden run\n  873│  30860770146 (head `b7b00c3`, conclusion success) executed the changed test IN-POOL on BOTH\n     │...\n 1154│\n*1155│### IR-19 — Docs-only pushes to main run full unit legs (classifier is PR-only) — intent unverified\n 1156│- **Status:** RETIRED 2026-08-18 — intentional for main pushes, not a classifier defect. · **Origin:** hertz observation 2026-08-03 (register-push\n 1157│  cadence gated his rig behind repeated hfenduleam unit legs); mechanism verified by doyle at\n 1158│  source same night.\n     │...\n 1183│\n*1184│### IR-20 — resident_service_e2e's `spt daemon stop --force` does not stop the daemon; teardown is complete only because the kills are\n 1185│- **Status:** open · **Origin:** hertz 2026-08-03, measured on the IR-18 lane's own clean run\n 1186│  (hfenduleam, log kept); routed text, doyle-landed.\n 1187│- **MEASURED:** teardown runs `spt(&[\"daemon\",\"stop\",\"--force\"])` then reaps. At reaper fire, every\n     │...\n 1216│\n*1217│### IR-54 — golden-head-intake runbook: three properties this cut proved should be construction, not discipline\n 1218│- **Status:** BUILT 2026-08-29 — PR #176 (`880b3b9c`, landed on main via `37368263`).\n 1219│  · **Origin:** PORTER (#205) v0.59.0 cut, 2026-08-21 — doyle (gater) + deployah (driver),\n 1220│  both mechanisms measured at the cut, neither cost this run anything because the driver caught\n     │...\n 1248│\n*1249│## IN-FLIGHT ON THE BOARD (not re-homed — live WIP lanes)\n 1250│\n 1251│- releases#93 (servicehost swap test pid-inequality), releases#47 (thin-lane unit(Windows)\n 1252│  isolation class), releases#32 (worker_lifecycle_e2e Phase A intermittent) — infra-shaped but WIP;\n     │...\n 1254│\n*1255│## BUILT / RETIRED\n 1256│\n*1257│### IR-15 — provably_gone is pid-only on Windows: teardown tests can fabricate reds\n 1258│- **Status:** BUILT 2026-08-03 · **Origin:** golden 30776330383 red on the #125 fix lane (2026-08-02)\n 1259│- **Lane:** hertz `golden/ir15` @a5042ec — REQ-TEST-LIVENESS-ORACLE-AUTHENTICATED (impl+unit): one\n 1260│  shared authenticated death-oracle test helper backed by `spt_procident::process_identity`\n     │...\n 1283│\n*1284│### IR-21 — CLASS: a helper binary's build is never requested, only its LOCATION is, so any narrow invocation manufactures a red that belongs to the rig\n 1285│- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane. · **Origin:** todlando 2026-08-03. Filed as one instance, rewritten as a CLASS the\n 1286│  same day when a second member appeared, rewritten AGAIN when the mechanism was measured — the\n 1287│  first two versions described symptoms and got the remedy wrong. **Corrected a fourth time the same\n     │...\n 1302│\n*1303│#### THE MECHANISM (measured, both ends)\n 1304│\n 1305│**Build end — `cargo test` with a narrow target selector compiles a `[[bin]]` AS A TEST HARNESS and\n 1306│never emits the plain executable.** Measured: `cargo test -p spt --bins` on a clean pool produced\n     │...\n 1334│\n*1335│#### SCOPE — WHERE IT BITES, AND WHERE IT DOES NOT\n 1336│\n 1337│**It bites NARROW invocations — `-p <pkg>`, `--bins`, `--lib` — i.e. gate rigs and local runs.**\n 1338│Both members were hit on the LOCKSMITH t1 lane against fresh throwaway pools; each was discharged\n     │...\n 1360│\n*1361│#### THE ONE CI-SIDE MEMBER THAT IS REAL\n 1362│\n 1363│`crates/spt/src/cli.rs::adapter_translate_proof_gates_on_commit` is a **unit** test (`kind(bin)`),\n 1364│and `CARGO_BIN_EXE_*` is set only for integration tests and benches of the declaring package. A unit\n     │...\n 1374│\n*1375│#### POPULATION\n 1376│\n 1377│**13 bin targets in the workspace** (`cargo metadata --no-deps`, not a grep — an auto-target under\n 1378│`src/bin/` and `xtask` are both invisible to a `[[bin]]` grep). Two are not helpers (`spt`, `xtask`);\n     │...\n 1431│\n*1432│#### REMEDY SHAPE (not ruled)\n 1433│\n 1434│The distinction that matters is location vs. build:\n 1435│\n     │...\n 1454│\n*1455│#### SUPERSEDED FRAMING, KEPT SO IT IS NOT RE-DERIVED\n 1456│- **Status of the original filing:** open · **Origin:** todlando 2026-08-03, both members hit on the\n 1457│  LOCKSMITH t1 lane against fresh throwaway pools; each discharged in-lane as a rig artifact, filed\n 1458│  here so the next clean rig does not re-diagnose them as code reds.\n     │...\n 1498│\n*1499│### IR-22 — An inherited identity env var fails a test, and the diagnostic names them ONE AT A TIME so a correct fix reads as no fix\n 1500│- **Status:** open · **Origin:** todlando 2026-08-03, chasing what looked like an `attach_wedge_e2e`\n 1501│  code red on the LOCKSMITH t1 lane; root-caused to the runner's own process environment.\n 1502│- **MEASURED:** `attach_wedge_e2e` failed for an INHERITED PROCESS-GLOBAL and nothing in the tree:\n     │...\n 1520│\n*1521│### IR-23 — `endpoint_teardown_authority_e2e`'s two tests collide with EACH OTHER through the machine-global spt home\n 1522│- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane. · **Origin:** todlando 2026-08-03, LOCKSMITH t1 lane.\n 1523│- **MEASURED:** both tests copy a psyche binary fixture into `perch::spt_home()/srcs/dummyharness/`\n 1524│  (`crates/spt/tests/endpoint_teardown_authority_e2e.rs:399`), which is process-global, so run in\n     │...\n 1545│\n*1546│### IR-24 — `reap::terminate_job` discards `TerminateJobObject`'s return, alone among its own module's siblings\n 1547│- **Status:** BUILT — landed `3d12cf3` on main (2026-08-03), fulfilment verified against this\n 1548│  entry's own wanted list by doyle 2026-08-04, not merely mapped to the commit: the return is\n 1549│  audited and the loss NAMED (`REAP_JOB_TERMINATE_FAIL: brain subtree NOT reaped (<os error>); …\n     │...\n 1585│\n*1586│### IR-25 — `spt-daemon --lib` reds 2-in-3 under concurrent load with bare `cargo test`, and holds green under nextest\n 1587│- **Status:** open · **Origin:** doyle 2026-08-03, found while gating LOCKSMITH tranche 1 in an\n 1588│  isolated worktree; chased to a mechanism and scoped OUT of the release path before the head was\n 1589│  assembled.\n     │...\n 1632│\n*1633│### IR-26 — POOL-OWNER claims authorize takeover from a DEAD holder, so releases#103's hazard reaches through the guard\n 1634│- **Status:** OPEN for residual claim-time observability and stale-reader enforcement; the\n 1635│  original build-side lane is COMMITTED (see its later reconciliation below), not still\n 1636│  uncommitted. Header corrected 2026-09-11; no residual closed by cleanup. · **Origin:**\n     │...\n 1805│\n*1806│### IR-27 — A junction-pooled rig is TWO objects and teardown only ever removes one\n 1807│- **Status:** open, found in the wild 2026-08-04 · **Origin:** hertz's 44-tree worktree sweep\n 1808│  (IR-26 follow-on 3) · **Cross-ref:** [[IR-14]] (unclaimed pools), [[worktree-target-junction]]\n 1809│- **What/why:** a rig built as `worktree\\target -> junction -> .worktrees\\<pool>` has its build cache\n     │...\n 1839│\n*1840│### IR-28 — A wave-gap rider is visible to the request board and invisible to a milestone-narrative notes pass\n 1841│- **Status:** BUILT 2026-08-29 — PR #176 (`880b3b9c`, landed on main via `37368263`).\n 1842│  · **Origin:** deployah, v0.53.0 release close 2026-08-04.\n 1843│- **What/why:** the v0.53.0 changelog omitted `184f2ac` (the releases#125 two-core CPU-burn fix, a\n     │...\n 1854│\n*1855│### IR-29 — twohost ladder: role A fires the done-barrier BEFORE its last cross-node rung, so the re-pull's serve window is won by timing, not guaranteed\n 1856│- **Status:** OPEN for later serve-window/rung residuals; the original\n 1857│  `test/twohost-serve-window` fix `17bbbd8` LANDED in v0.54.0, as recorded by IR-30.\n 1858│  Stale authored-but-unlanded header corrected 2026-09-11; no new acceptance or margin\n     │...\n 1917│\n*1918│### IR-30 — GOLDEN 4b37512 (#145): five attempts, four distinct Windows victims, one sha — the random-victim family measured end to end, and the instruments it left behind\n 1919│- **Status:** open for the FAMILY SIGHTINGS ONLY — the instrument lanes LANDED as planned with\n 1920│  the next golden batches (measured 2026-08-25, doyle, `git merge-base --is-ancestor` + first\n 1921│  tag: serve-window `17bbbd8`, selection probe `695398ba`, resume taxonomy `58337879` all in\n     │...\n 2177│\n*2178│### IR-32 — Docs-drift gate blesses its own gen: an empty-emitting producer agrees with itself perfectly\n 2179│- **Status:** open · **Origin:** todlando mid-lane stop-and-report, U1 (#144) 2026-08-04. Filed by\n 2180│  the builder to the gater deliberately — register shape is doyle's to own.\n 2181│- **What/why:** with a defective binary in the tree (stack-overflowed before reaching its own\n     │...\n 2211│\n*2212│### IR-33 — Debug-build clap Command tree runs near the main-thread stack ceiling; the margin is THREE net new args, bisected at `8f291e1` (the original ~6 was measured on U1's tree and is superseded)\n 2213│- **Status:** OPEN for acceptance/margin reconciliation. Current source at `e5a2fed9` runs\n 2214│  the CLI on an owned 16 MiB thread stack and includes `cli_stack_smoke`; the three-argument\n 2215│  ceiling below is a historical measurement at `8f291e1`, NOT today's measured margin.\n     │...\n 2264│\n*2265│### IR-34 — nextest LEAK flag on the zombie-fixture row is dominant-but-intermittent (19/20 measured); any gate reading it as a signal flaps\n 2266│- **Status:** open · **Origin:** doyle #142 F-lane gate 2026-08-04 (first sighting in a gate run);\n 2267│  characterized same day by hertz from retained logs, ownership falsified by todlando.\n 2268│- **What/why:** `broker::tests::windows_session_is_zombie_sees_a_handle_held_corpse_as_dead` (the\n     │...\n 2289│\n*2290│### IR-35 — hfenduleam Windows test-leg victim rate: one teardown/liveness family, measured at ~half of all executions\n 2291│- **Status:** open · **Origin:** USHER #150 golden triage 2026-08-04 (doyle; all rates deployah-measured).\n 2292│- **The numbers (15 golden runs 2026-08-02..08-04 + the USHER cycle, deduped on `(run, box,\n 2293│  started_at)` — GitHub partial reruns COPY untouched jobs into the new attempt with their ORIGINAL\n     │...\n 2295│  any rate math):** Windows (hfenduleam) 13 red / 22 executions = 59% leg-red, splitting 10/22 = 45%\n*2296│  test-victim + 3/22 infra (IR-31 class). Linux (kitsubito) 2/20 = 10%, 1 victim. Every victim-red\n 2297│  leg had EXACTLY ONE victim (8/8 legs). Clean-cycle arithmetic ≈ 0.55 × 0.95 ≈ half — a golden\n 2298│  cycle at these rates is a coin flip. knock145 (the previous green golden) took FIVE Windows\n 2299│  executions to its green; USHER took four. **A both-green draw is a draw, not evidence the family\n     │...\n 2325│\n*2326│### IR-36 — `output_bounded` is a 51-copy clone estate with a named-but-empty shared home; hoist-and-delete wants its own lane\n 2327│- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane. · **Origin:** hertz measurement\n 2328│  2026-08-04 (at `7465ac1`, counted before listing, listed untruncated), during the USHER package\n 2329│  item-2 sweep ruling; doyle ruled file-don't-sweep.\n     │...\n 2361│\n*2362│### IR-37 — `traceable-reqs check` is coverage-only: tag PLACEMENT is unenforced on any multi-tagged REQ, and the more tags a REQ accumulates the less any one is checked\n 2363│- **Status:** UPSTREAM CLOSED THROUGH RELEASE 2026-08-19 — traceable-reqs PR #19 squash-merged\n 2364│  @`82d8b14` after doyle's targeted re-review PASS (defect A item-tables + 9 red-first regression\n 2365│  cells + sighted control; defect B enclosing-item fallback DECLARED in SPEC with cost; 267/267,\n     │...\n 2424│\n*2425│### IR-38 — CLASS: an e2e that ends with a live daemon-spawning binary wedges the NEXT build in its pool, and the diagnostic names the wrong lane\n 2426│- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane. · **Origin:** todlando 2026-08-04,\n 2427│  `shell_relink_force_e2e` on the #6 lane (filed by doyle; the finding and the fix are todlando's).\n 2428│- **What/why:** the e2e ends with a LIVE binary by design; on Windows a live process holds its\n     │...\n 2463│\n*2464│### IR-39 — CLASS: the missing-fixture-bin defect has TWO failure faces, and one of them impersonates a lifecycle defect of the subject under test\n 2465│- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane. · **Origin:** hertz + todlando\n 2466│  2026-08-04, same evening from opposite sides (filed by doyle; hertz relayed todlando's\n 2467│  suggestion without endorsing scope).\n     │...\n 2500│\n*2501│### IR-40 — CLASS: NO envelope-side ordering signal on a resume brief tracks content recency, and a CI informant's per-job line is a claim about that STEP, not the run\n 2502│- **Status:** open · **Origin:** three sightings in one night, 2026-08-04/05 — hertz, doyle,\n 2503│  todlando (filed by doyle; the artifacts are hertz's and todlando's, the CI arm is doyle's with\n 2504│  deployah's framing). Two arms of ONE family: a stale record that carries a confident ordering\n     │...\n 2577│\n*2578│### IR-41 — A QUEUED main run is superseded without a record; `cancel-in-progress: false` protects only STARTED runs\n 2579│- **Status:** open — mechanism CONFIRMED (doyle ruling 2026-08-05); the runbook sentence it\n 2580│  falsified is already corrected (`docs/RELEASE-RUNBOOK.md` step 3, same commit as this entry)\n 2581│  · **Origin:** deployah, v0.55.0 publish night, filed by him explicitly as UNPROVEN with the\n     │...\n 2609│\n*2610│### IR-42 — `pool-claim` writes a record; only the BUILD enforces — and AGENTS.md invited the misread\n 2611│- **Status:** BUILT 2026-08-19 — the AGENTS.md corrective line lands in the SAME COMMIT as this\n 2612│  entry (the register batch commit), which is the entry's stated exit condition. The optional\n 2613│  code-side nicety (claim verb prints the incumbent record it overwrites, information only)\n     │...\n 2637│\n*2638│### IR-43 — knock answer carrier: `NoReply` landed at 60.08s against a stated 30s carrier deadline\n 2639│- **Status:** open, OBSERVATION — mechanism unmeasured, filed exactly as wide as the datum ·\n 2640│  **Origin:** KNOCK-169 RCA layer 1 (todlando, read-only), golden 32191618042 @`93c1130`,\n 2641│  twohost-b, 2026-08-18.\n     │...\n 2654│\n*2655│### IR-44 — perch-sentinel comment overclaims: serialization is not preservation, and the comment teaches the false step\n 2656│- **Status:** open · **Origin:** #188 RCA lock read (todlando flagged, doyle confirmed the lock\n 2657│  read), 2026-08-18; the collapse-of-branches argument is on #188 and in the RCA record.\n 2658│- **What/why:** `lock_perch_sentinel` (info.rs:778 at `b20e770`, the diag sha — re-derive the\n     │...\n 2675│\n*2676│### IR-45 — twohost rig home premise, SETTLED: pump paths resolve under the per-run TEMP root (rig is disk-hermetic; the \"live fleet roster\" reading is retired)\n 2677│- **Status:** RETIRED 2026-08-19 — ask answered by the one code read at main @`78a9a16`; residue\n 2678│  re-homed (see Answer). · **Origin:** #188/#189 RCA readouts (todlando, doyle's 2a-2d), runs\n 2679│  32097943571 + 32108557362 + 32111921251, 2026-08-18.\n     │...\n 2706│\n*2707│### IR-46 — the Windows disk-floor preflight asserts an INSTANT; workspace free space moves tens of GB inside the hour, so a green floor is not a claim about run headroom\n 2708│- **Status:** open — mechanism CONFIRMED by a measurement series on hfenduleam; doyle ruled it\n 2709│  register-shaped 2026-08-18 · **Origin:** deployah, NAMEPLATE #181 golden-head intake, on the\n 2710│  run that the floor red-floored · **Filed as IR-46 after an id collision:** this row was authored\n     │...\n 2773│\n*2774│### IR-47 — ci-notify treats a missing co-author trailer as a quiet info line; silent attribution loss reads as \"there was none\"\n 2775│- **Status:** open — patch AUTHORED and stashed unlanded since 2026-07-29\n 2776│  (`.worktrees/_patches/ci-notify-missing-trailer.patch` + its `test-ci-notify.sh` harness in the\n 2777│  sibling `.untracked` dir); surfaced by doyle's 2026-08-19 idle-queue verification of that stash ·\n     │...\n 2800│\n*2801│### IR-48 — the nextest.toml parity cell tolerates CRLF only by parser accident; a newline-sensitive arm added later reds fresh Windows checkouts alone\n 2802│- **Status:** open — filed 2026-08-19 (doyle route, hertz verdict: REGISTER as preventive\n 2803│  hardening, not current defect) · **Origin:** sibling sweep after the W3 gate CRLF finding —\n 2804│  parent mechanism: `include_str!` embeds working-tree bytes verbatim, `core.autocrlf=true`\n     │...\n 2821│\n*2822│### IR-49 — poolguard's landed-lane predicate is ancestry-only, so a cherry-picked member lane can never read Settled and its pool can never be taken over\n 2823│- **Status:** open — filed 2026-08-19 (todlando measurement at the keystone-w1/fix-197 reap,\n 2824│  doyle ruling; doyle re-verified the predicate at source before filing) · **Origin:** todlando's\n 2825│  post-landing landed-check used the guard's own predicate and it contradicted the (correct)\n     │...\n 2855│\n*2856│### IR-50 — e2e failure panels read the PRE-REDIRECT stderr capture; every daemon-side diagnostic lands in a sink the rig deletes unread\n 2857│- **Status:** CLOSED — BUILT 2026-08-19; adoption-completion lane\n 2858│  `docs/ir50-register-close` @`e02f565f` (hertz, doyle-gated 2026-08-20) LANDED in\n 2859│  v0.59.0 as a PORTER rider (pick `e702d4b7` tip, main @`c62904e7`; register sweep\n     │...\n 2913│\n*2914│### IR-51 — engine-room e2e daemon runs NET-ENABLED on real interfaces; rig hermeticity is disk-deep only\n 2915│- **Status:** open — filed 2026-08-19 (todlando's x40 run-4 sink read, the first live read any\n 2916│  rig has had of the daemon sink; doyle ruled own-id rather than riding #199, at the finder's\n 2917│  own request) · **Origin:** unasked-for find inside the #199 instrument's first catch.\n     │...\n 2942│\n*2943│### IR-53 — failed-address expiry unit panics during the first 10m01s after Windows boot\n 2944│- **Status:** BUILT 2026-08-21 on `fix/ir53-cold-boot-instant` — LANDED in v0.59.0\n 2945│  (PORTER rider, pick `7b26f28d` on `assembly/porter-205`, main @`c62904e7`; register\n 2946│  sweep 2026-08-21 at release close) · **Origin:** todlando,\n     │...\n 2968│\n*2969│### IR-52 — docs-site CLI reference renders SHALLOW; help text below the rendered depth is outside the drift gate, unit-held per-REQ or held by nothing\n 2970│- **THIRD INSTANCE, observed 2026-08-24 (todlando, WAX-SEAL #21 W4; not acted on):** the new\n 2971│  `spt api seal verify|describe` FLAGS sit below the generator's rendered depth — the entry's\n 2972│  exact class. The W4 user page hand-documents them, which is per-page self-defense, not a\n     │...\n 3007│\n*3008│### CI-RIDER LANE STATE — LANDED 2026-08-04 (post-v0.53.0 merge queue); history below kept for its mechanisms\n 3009│- **RESOLVED:** the lane rebased clean onto the post-tag queue and landed ff-only as\n 3010│  `2b33a47`/`2a7b016`/`d63f4ce`/`19d7f79` (content byte-identical to `1275e47..bf8c4a2` by lane-diff\n 3011│  blob hash). IR-1 and IR-4 are BUILT AND LANDED; IR-9's measurement half is landed with its trigger\n     │...\n 3074│\n*3075│### IR-55 — the `spt --bins` suite wedges partway through on leaked `findstr .` PTY children; the tests at the frontier are casualties, not culprits\n 3076│\n 3077│- **Status:** OPEN, **ARMED-FOR-CAPTURE**, owned by **hertz**. Test/rig defect by the dispatch\n 3078│  split (test/CI rework is never the product builder's). Filed by doyle 2026-08-22 from the\n     │...\n 3200│\n*3201│### IR-56 — `pool-claim` harvests lane identity from CWD, not from `--pool`; a claim run from the wrong tree writes a WRONG RECORD with a success message\n 3202│\n 3203│- **Status:** BUILT 2026-08-24 for the SIGNET #218 golden batch on\n 3204│  `fix/ir56-pool-claim-cwd`, owned by **hertz**. Tooling/rig defect by the dispatch split. Filed by\n     │...\n 3247│\n*3248│### IR-57 — an assembly pick's conflict resolution can silently DROP lines, and every gate run at assembly time is blind to it\n 3249│\n 3250│- **Status:** OPEN, owned by **doyle** (gater craft, not a code defect — no lane to dispatch).\n 3251│  Filed 2026-08-22 from doyle's own defect on the TURNKEY #212 assembly head.\n     │...\n 3306│\n*3307│### IR-58 — a `[[bin]]` grep is not a census: cargo AUTODISCOVERS `src/bin/*.rs` targets, and a hand-built bin list produced a confident false \"this bin does not exist\"\n 3308│\n 3309│- **Status:** OPEN, unowned. Filed by doyle 2026-08-22; **its original filing was WRONG and is\n 3310│  retracted in full below.** The entry is kept because the way it was wrong is the finding.\n     │...\n 3341│\n*3342│### IR-59 — pool arithmetic: this box holds TWO cold pools, not four; and a build that exhausts the volume reds as a LINKER defect that names no disk\n 3343│\n 3344│- **Status:** OPEN, unowned — it is arithmetic and discipline, not a code lane. Filed by doyle\n 3345│  2026-08-22 from a live disk-floor abort during the TURNKEY #212 W4 gate; footprint figures measured\n     │...\n 3475│\n*3476│### IR-60 — a wrapper that CAPTURES a leg's exit status ends with the capture, so the wrapper's own status is the capture's, not the leg's\n 3477│\n 3478│- **Status:** OPEN, unowned — script-shape discipline, not a code lane. Filed by doyle 2026-08-22\n 3479│  during the TURNKEY #212 W5 lane; mechanism measured by todlando, who reported it first as a\n     │...\n 3524│\n*3525│### IR-61 — spacerun's test-module skip carries a SECOND literal tracker; the two answers can drift, and today only a cell stands between them\n 3526│\n 3527│- **Status:** OPEN, unowned, accepted-with-mitigation. Filed by doyle 2026-08-22 at the TURNKEY #212\n 3528│  head gate, as the named residual of the latch repair (the repair itself rides the milestone).\n     │...\n 3557│\n*3558│### IR-62 — an e2e daemon binds well-known ports and collides with the resident fleet on shared runners\n 3559│\n 3560│Filed 2026-08-23 (doyle), from the #212 r2 golden's Windows Phase A red — one witnessed\n 3561│instance, mechanism verified from the run's own capture, filed on the mechanism per the\n     │...\n 3598│\n*3599│### IR-63 — suite-mix sweeps leak job-escaped autostart daemons that LOCK the pool's spt.exe; and the same box conditions manufacture one random victim per sweep\n 3600│\n 3601│- **Status:** OPEN, mitigated-by-rig-step — the reap is adopted discipline, not yet construction.\n 3602│  Filed by doyle 2026-08-24 at the SIGNET #218 gates; first measured by todlando the same day\n     │...\n 3637│\n*3638│### IR-64 — HFENDULEAM's disk floor is set by non-CI bulk: ~845 GB of operator payload leaves the golden box ~2 GB of slack against its own 32 GB preflight\n 3639│\n 3640│- **Status:** OPEN · **Origin:** doyle, v0.63.0 close sweep 2026-08-26; mechanism first measured\n*3641│  at the FIELD-SEAL golden window (deployah's IR-31 fifth addendum carries the POOL side of the\n 3642│  same event by agreed division — this entry is the OTHER reservoir, deliberately not his).\n 3643│- **Mechanism:** the 1.86 TB C: carries ~614 GB Steam + ~230 GB Downloads (operator payload, not\n 3644│  CI state). With that floor fixed, normal lane traffic alone walks the box under the 32 GB\n 3645│  golden preflight — a full-sweep pool WEIGHS ~90–112 GB steady state (IR-59's measurement) and\n*3646│  five FIELD-SEAL lanes cost 148.48 GB (IR-31 fifth addendum), so ONE milestone's pools exceed\n 3647│  the entire free margin. Reaping buys windows, not headroom: deployah measured free fall\n 3648│  167 → 108 GB within hours of his reap, ~59 GB re-consumed by lane builds. The recurring shape:\n 3649│  every milestone pays a reap-and-measure tax to rent space the box does not structurally have.\n*3650│- **Why register-worthy rather than \"clean up more\":** agent-side discipline (IR-31's budgeting,\n 3651│  pool reaps, teardown steps) is already adopted and still only rents windows — the reservoir\n 3652│  that would durably move the floor is operator-owned bulk no agent may touch. Naming it here is\n 3653│  the boundary: agents keep budgeting IN POOLS (not GB); moving Steam/Downloads (or adding a\n     │...\n 3659│\n*3660│### IR-65 — kitsubito kernel-audit backpressure: a tailscale-snap AppArmor denial storm + no auditd turned the default audit backlog into a CI-wide stall amplifier (REMEDIATED AT BOX; re-check triggers named)\n 3661│\n 3662│- **Status:** REMEDIATED-AT-BOX 2026-08-25 (doyle, operator-authorized root — ruling pinned\n 3663│  releases#225 comment 5418800776); entry stays OPEN as the re-check record because the storm\n     │...\n 3685│\n*3686│### IR-66 — first-chunk-needle test class: two latent members remain after the v0.63.0 fix (attach.rs:561, :672)\n 3687│\n 3688│- **Status:** CLOSED / BUILT — release-close reconciliation 2026-09-11. The WEBSERVE JIT already\n 3689│  ruled this satisfied; source at `e5a2fed9` retains both delayed needles. Closure uses the\n     │...\n 3718│\n*3719│### IR-67 — wave-battery gap: a `-p spt --bins` leg compiles bin targets as harnesses and runs ZERO integration/e2e tests, so batteries that lean on it carry silent no-coverage legs\n 3720│\n 3721│- **Status:** BUILT — remedy applied across the IO-PARSER #22 milestone (2026-08-27/28): every\n 3722│  wave battery named explicit `-p spt --test <suite>` e2e legs beside the `--bins` unit leg\n     │...\n 3740│\n*3741│### IR-68 — PSYCHE_INGEST_FAIL cause class unproven: git index.lock did NOT reproduce the ingest failure it was blamed for\n 3742│\n 3743│- **Status:** OPEN, investigation-shaped · **Origin:** todlando measurement at the W2 int-leg rig\n 3744│  (IO-PARSER #22, PR #163 at `769fb0a9`, 2026-08-27), reported measure-first; filed by doyle.\n     │...\n 3768│\n*3769│### IR-69 — inherited stderr tokens can tear between format fragments; 26 test consumers parse that surface as structured truth\n 3770│\n 3771│- **Status:** OPEN for the #243 residual population and anchored-consumer work. The original\n 3772│  product remedy LANDED at `ec6da9b0`, as recorded in this entry's later amendment; it is not\n     │...\n 3860│\n*3861│### IR-70 — a hand-built `IoBus` silently omitted later sinks while every gate stayed green\n 3862│\n 3863│- **Status:** OPEN, remedy unscheduled; the v0.65.0 respin fixed the witnessed call site on PR #173.\n 3864│  This entry owns the recurrence class, not that shipped correction. · **Origin:** releases#234,\n     │...\n 3887│\n*3888│### IR-71 — controller-seat release has no persisted breadcrumb, so tests cannot distinguish propagation lag from a missing detach\n 3889│\n 3890│- **Status:** OPEN, observability gap; no remedy scheduled. · **Origin:** CONDUIT #236 r3\n 3891│  `er_brief_once_per_session_e2e` intermittent, classified test-side and fixed on PR #174.\n     │...\n 3911│\n*3912│### IR-72 — no product read verb surfaces which process holds a perch or controller seat\n 3913│\n 3914│- **Status:** OPEN, observability gap; no remedy scheduled. · **Origin:** CONDUIT #236 r3\n 3915│  two-host RCA and PR #174 (`70c1a303`), corrected by doyle after IR-18 and daemon-status were\n     │...\n 3945│\n*3946│### IR-73 — ci.yml and release.yml still read the free-space floor PRE-checkout (literal-first sites off the golden path); and any job's floor is stale by its last heavy step\n 3947│\n 3948│- **Status:** CLOSED / BUILT — source reconciliation 2026-09-11 at `e5a2fed9`: all five\n 3949│  `ci.yml` sites and all three `release.yml` sites now read after checkout, with IR-73 comments;\n     │...\n 3969│\n*3970│### IR-74 — kitsubito holds 21,643 /tmp endpoint homes: box-side accumulation nothing bounds or measures\n 3971│\n 3972│- **Status:** OPEN, filed by doyle 2026-08-30 at the #242/v0.66.0 close sweep; measurement by\n 3973│  hertz (2026-08-29). · **Origin:** rig work on kitsubito found `/tmp` carrying 21,643 endpoint\n 3974│  homes — per-run spt homes that outlive their runs.\n*3975│- **What/why:** sibling of the [[IR-31]]/[[IR-59]]/[[IR-64]] family (box accumulation the\n 3976│  preflights never see): each is small, the population is not, and /tmp on a long-lived box is\n 3977│  never reaped by CI. Un-reaped homes also widen every by-path census a rig runs. Needs a\n 3978│  bounded lifecycle (per-run temp root reaped at run end, or a box-side sweep with a stated\n     │...\n 3983│\n*3984│### IR-75 — traceable-reqs is not installed on kitsubito, so every Linux gate driver's treqs leg exits 127 (vacuous, wrapper-green shape)\n 3985│\n 3986│- **Status:** OPEN, filed by doyle 2026-08-30 at the #242/v0.66.0 close sweep (deployah\n 3987│  co-flagged at intake). · **Origin:** ASM-241 Linux battery — `ASM_treqs.exit` = 127, raw\n     │...\n 3998│\n*3999│### IR-76 — hfenduleam is the golden Windows runner AND the builders' box: a local workspace nextest fully contained a golden Phase A and manufactured a load-timing red, and the job-start census cannot see it\n 4000│\n 4001│- **Status:** OPEN, filed by doyle 2026-09-06 during v0.67.1 golden triage (run 34017906638\n 4002│  att2). · **Origin:** the Windows Phase A red on\n     │...\n 4042│\n*4043│### IR-77 — nothing stamps the interval between a daemon child's spawn and the brain's first log line, so a readiness-deadline red cannot say WHERE the time went\n 4044│\n 4045│- **Status:** OPEN, filed by hertz 2026-09-07 from the W1 #249 kitsubito battery at the gated\n 4046│  sha `8d980fdf`; doyle-ruled at filing to be a register entry rather than a lane rider. ·\n     │...\n 4074│\n*4075│### IR-78 — `SPT_TEST_EPHEMERAL_ADVISORY_PORTS` silently overrides an explicitly set `SPT_DOCS_PORT`\n 4076│\n 4077│- **Status:** OPEN, filed by hertz 2026-09-07, MEASURED by doyle the same night on his W2\n 4078│  field pair (both boxes). · **Origin:** the 5474 rig-hygiene sweep in\n     │...\n 4102│\n*4103│### IR-79 — 22 of the 31 rig binaries leak their daemon tree on a failing assert: teardown is a statement, not a guard\n 4104│\n 4105│- **Status:** OPEN, filed by hertz 2026-09-07 on doyle's dispatch during PR #198's CI window,\n 4106│  from todlando's red 6 (a stale same-port daemon from his own previous run answering the next\n     │...\n 4183│\n*4184│### IR-80 — five leaky cells on ONE module (`brainproc` / `supervise_brain`), Windows only: a candidate PRODUCT leak on the promotion/rollback path, or a cluster of names — nobody has looked yet\n 4185│\n 4186│- **Status:** OPEN for the residual population, not an undiagnosed five-name product claim.\n 4187│  Later amendments identify the brainproc shell-wrapper fixture mechanism and distinguish\n     │...\n 4251│\n*4252│#### THE LEAK SET IS NOISY — measured across three shas, 2026-09-07 (hertz)\n 4253│\n 4254│**This retracts the \"8 -> 5 leaky, direction favourable\" reading I flagged at 09:31Z.** It is not a\n 4255│fix and not an improvement; it is threshold noise, and the census this draft was built on inherits\n     │...\n 4280│\n*4281│#### Three consequences for this draft\n 4282│\n 4283│1. **A count is not a quality signal here, in either direction.** Any future \"leaky went down\"\n 4284│   claim needs the NAME diff and a causality check against the changed files, or it is noise\n     │...\n 4296│\n*4297│#### One structural finding the noise does NOT touch\n 4298│**All nine union members spawn a child and then kill it, let it time out, or inspect its corpse** —\n 4299│`trial_kills_alive`, `kill_waker_at`, `bounded_run_kills_on_timeout`, `extractor_timeout_errors`,\n 4300│`fetcher_timeout_errors`, `windows_session_is_zombie_sees_a_handle_held_corpse_as_dead`, and the\n     │...\n 4307│\n*4308│#### THE 12-CELL UNION — 4 shas x 2 OSes, membership beside the invariant (hertz, 2026-09-07 10:15Z)\n 4309│\n 4310│Machine-generated from the eight ci unit logs, not transcribed (a hand-typed 12x8 matrix is where\n 4311│transcription errors live). `X` = reported LEAK at that sha on that box.\n     │...\n 4330│\n*4331│#### Three readings, in increasing order of what they support\n 4332│\n 4333│**1. The churn is total and it is the whole point.** Windows counts run 8, 8, 5, 9 — the HIGHEST\n 4334│value is at `f3c8495b`, the tip carrying every fix F1-F16. Only **4 of 12** cells are present at\n     │...\n 4388│\n*4389│#### A MECHANISM, read out of the source of the two Linux cells — calibrated, not generalized\n 4390│`process_cmdline_reads_a_live_arg_marker` spawns **`sh -c \"sleep 30; : marker\"`**, and the test's\n 4391│own comment says the trailing `; :` is deliberate — it keeps the shell RESIDENT so its\n 4392│`/proc/<pid>/cmdline` still carries the marker instead of being tail-exec-replaced by `sleep`. The\n     │...\n 4417│\n*4418│#### AMENDMENT 1 — \"a pid is not a tree\" has THREE faces, and only one of them is a kill\n 4419│\n 4420│*(hertz 2026-09-07, ruled by doyle 11:17Z: write this as an IR-80 amendment naming the three faces\n 4421│rather than three separate entries, so a reader hunting any one face lands on all three.)*\n     │...\n 4465│\n*4466│### IR-81 — a process kill can be written scoped or machine-wide, and nothing makes the scoped form the only reachable one: both codebases carry the right pattern beside the wrong one\n 4467│\n 4468│- **Status:** OPEN, drafted by hertz 2026-09-07 08:38Z on doyle's dispatch (08:36Z), from the\n 4469│  fleet-daemon death on hfenduleam at 08:03:15Z ([[RCA-FLEET-DAEMON-14444]], cause still UNNAMED).\n     │...\n 4530│\n*4531│#### ADAPTER-SIDE ARM: CLOSED (claude-spt, perri, 2026-09-07)\n 4532│\n 4533│**Status: closed in the consumer repo, test-only, does not close IR-81 here.**\n 4534│\n     │...\n 4559│\n*4560│#### SCOPING ARM (a) — the product path has no intermediary; the fixture does\n 4561│*(hertz 2026-09-07, ruled by doyle 10:22Z off the IR-80 leak work.)*\n 4562│\n 4563│> **A pid is not an identity and a pid is not a tree. IR-80 needs CALLERS, not code.**\n     │...\n 4590│\n*4591│### IR-82 — a daemon death leaves NO record of who died: autostart decides on a socket ping, says \"no daemon\", and the successor overwrites the only handle on the corpse\n 4592│\n 4593│- **Status:** RULED 2026-09-07 11:07Z (doyle), drafted by hertz 11:04Z on doyle's dispatch (11:03Z: *\"the autostart\n 4594│  death-cause item is an IR, not a board item — mint it IR-82 in your thin PR\"*). Register on main\n     │...\n 4696│\n*4697│### IR-83 — a two-host rig addressed over the tailnet cannot receive INBOUND on Windows, and the whole rig population had only ever run the admitted direction\n 4698│\n 4699│- **Status:** OPEN, minted by hertz 2026-09-07 11:41Z on doyle's dispatch (11:40Z). **Provenance: the\n 4700│  mechanism below is DOYLE'S measurement, not mine** — eight probe arms, each with sender, listener\n     │...\n 4833│\n*4834│### IR-84 — the one `PUMP_PEER_FAIL` arm the rigs actually fire was the only one carrying no clock, so the stall that produced it could be counted but never timed\n 4835│\n 4836│- **Status:** OPEN, filed by hertz 2026-09-09 with the instrument that closes its first half. ·\n 4837│  **Origin:** the 65 s two-host helper stall (design written before the run,\n     │...\n 4883│  stamps, so the fifth site added cannot be born silent.\n*4884│### IR-85 — the Windows self-hosted box runs its fs-heavy tests 3-4x slower than a week ago; two CI wall clocks were sized for the old box, and a red run kept hiding it\n 4885│\n 4886│- **Status:** OPEN, filed by hertz 2026-09-09 at the #272/v0.68.0 golden r3/r4 arc, on doyle's\n 4887│  dispatch. Number ruled by doyle from his own census of main@`a2f335f8` (register ended at IR-83;\n     │...\n 5043│\n*5044│### IR-86 — golden's 32 GiB floor is BELOW the measured 67.4 GiB Windows suite footprint, so a start floor passes a box that cannot finish\n 5045│\n 5046│- **Status:** OPEN, filed by doyle 2026-09-08 at the #272/v0.68.0 golden r2 triage. · **Origin:**\n 5047│  run 34262154550 @ `25e60015` (shaped on `e4444413`), Windows test job 102182665033: every product\n     │...\n 5092│\n*5093│### IR-87 — two-host ceremony halves are INDEPENDENT jobs on DIFFERENT runners (A Windows/hfenduleam, B Linux/kitsubito); B's 900 s budget runs on B's own clock, so any older queued Windows job starves A and reds B deterministically, and the panic text blames pairing\n 5094│\n 5095│- **Status:** OPEN, filed by doyle 2026-09-08 at the #272 golden r2 triage. · **Origin:**\n 5096│  run 34262154550, twohost-b job 102207296960 (log 81,692 B, sha256 67403f04…8030): role B built,\n     │...\n 5145│\n*5146│### IR-88 — `pool-release` via `cargo run -p xtask` REBUILDS xtask INTO the pool it is releasing, so a reaped pool regrows ~2.8 GB in silence\n 5147│\n 5148│- **Status:** OPEN, filed by doyle 2026-09-08 from hertz's reap report (20:00Z) during the #272\n 5149│  golden r2 repair. · **Origin:** hertz reaped hertz-lane4 / hertz-repin / hertz-percell-id target\n     │...\n 5169│  rather than merely proposed.\n*5170│- **Kin:** [[IR-31]] (pool budgeting), [[IR-56]] (pool-claim identity from CWD — same verb\n 5171│  family, same \"the tool acts on where it stands\" shape), releases#103.\n 5172│- **Ripe when:** next xtask pool-verb touch or the teardown runbook edit. · **Size:** tiny —\n 5173│  one guard or one doc line.\n     │...\n 5182│\n*5183│### IR-89 — hfenduleam's Windows Firewall drops cold inbound UDP to the runner-built test exes, so the two-host rig's first B→A claim (W2 helper) reds for its whole 900 s budget and the panic blames A\n 5184│\n 5185│- **Status:** BOX HALF **APPLIED** 2026-09-08; WORKFLOW HALF **BUILT** 2026-09-09 — PR #211\n 5186│  (`9b96d7e7` + this amendment), **LANDED, exact golden-step acceptance unreconciled**.\n     │...\n 5338│\n*5339│### IR-90 — a full disk on the self-hosted box reds a rig as a PRODUCT refusal, not a build error, and no rig or gate records the free space that would falsify it\n 5340│\n 5341│- **Status:** OPEN, filed by hertz 2026-09-09 from the disk-full incident on hfenduleam. ·\n 5342│  **Origin:** the IR-85 discriminator lane's head arm, killed by the volume rather than by the code\n     │...\n 5427│\n*5428│### IR-91 — 561 untracked files sat at the repo root, 18 of them cited by tracked files, and the census that classified them used a corpus that made the discriminator invisible\n 5429│\n 5430│- **Status:** CLOSED by the lane that filed it (the root-scratch classify PR), hertz 2026-09-09 on\n 5431│  doyle's census and rulings. · **Origin:** the `.spt/` ignore lane (PR #212) named 561 untracked\n     │...\n 5481│\n*5482│### IR-92 — the message that WAKES an idle spt-hosted endpoint rides a delivery leg that never publishes MSG_IN, so a woken agent's own funnel holds none of the messages that woke it\n 5483│\n 5484│- **Status:** OPEN — filed doyle 2026-09-09 from hertz's census, probe and proposed text (his by\n 5485│  role; the recorder read and the REQ reading are doyle's). Fix lane unassigned: product change in\n     │...\n 5613│\n*5614│### IR-93 — no PDB ships beside the installed `spt` binary, so the one non-invasive read of a wedged production daemon comes back without a single named frame\n 5615│\n 5616│- **Status:** OPEN, filed by doyle 2026-09-10. **The number was reserved by NAME on 2026-09-09** at\n 5617│  the #293 mechanism read (\"PDB ask -> IR-93 at next sweep\") and this entry closes that claim — a\n     │...\n 5642│\n*5643│### IR-94 — xtask's brainread deadline gate cannot SEE `serve_sync`: its registry is three hand-listed files and its predicate is a name shape, so a stream server outside both got the reply form and the gate stayed green\n 5644│\n 5645│- **Status:** OPEN, filed by doyle 2026-09-10 at the releases#294 / v0.69.0 golden RED triage. **This\n 5646│  is an INDEPENDENT gate finding, not the cause of that red** — it was found while reading the\n     │...\n 5672│\n*5673│### IR-95 — a burned polling budget names WHAT it wanted and never HOW LONG it waited, so no run, green or red, can say how close it came\n 5674│\n 5675│- **Status:** OPEN, filed by doyle 2026-09-10 at the releases#294 golden RED, where it cost this\n 5676│  triage most of a morning and four agents. · **Origin:** the two Windows Phase A failures at\n     │...\n 5927│\n*5928│### IR-96 — the `daemon_stop_convoy_e2e` API-storm cell fails 3-of-3 under the HEAVY suite at the diagnostic tree while passing at the candidate in golden CI, and nothing yet separates instrumentation from box from product\n 5929│\n 5930│- **Status:** OPEN, **cause-unclassified** (todlando's and hertz's stipulation, adopted verbatim — a\n 5931│  triage placement here is NOT a finding of non-defect).\n     │...\n 5963│\n*5964│### IR-97 — a suite that leaks a fixed cohort of child processes per invocation makes consecutive runs non-comparable, and the between-run accounting the protocol required was not enforced\n 5965│\n 5966│- **Status:** OPEN. **Protocol deviation** (hertz's framing, and it is stronger than \"confounder\":\n 5967│  the protocol ALREADY required between-run accounting — execution did not enforce it, so the fix is\n     │...\n 6006│\n*6007│### IR-98 — a lane driver that PRINTS a producer's output can die on an unencodable byte AFTER that producer's evidence is on disk, so the run ends with complete evidence for producer N and NO files for N+1 — an absence that reads as \"never queued\", not as a failure\n 6008│\n 6009│- **Status:** OPEN as a mechanism; the measured instance is FIXED in hertz's lane driver (UTF-8 with\n 6010│  replacement reconfigured at import, positive control run before relaunch: U+2500 and U+2713\n     │...\n 6030│\n*6031│### IR-99 — EOF and terminal retire on a ConnectionBound net stream arm on the OPENER CONN's exit; a same-morning diagnosis built on that mechanism was refuted by the compiler, so the mechanism stands and the two #304 reds beside it stay open\n 6032│\n 6033│- **Status:** OPEN. The mechanism is VERIFIED; both reds are CLASSIFIED NOT-product (instance 1: an\n 6034│  unpromised spectator EOF; instance 2: a journal replay of a reused op seq) — repairs built at\n     │...\n 6109│\n*6110│### IR-100 — an editor-driven rust-analyzer runs `cargo check --workspace --all-targets` into a LANE's pool on its own schedule, so a builder census counts it, a lock wait charges it to nobody, and the lane's disk growth carries it uncredited\n 6111│\n 6112│- **Status:** OPEN. Recorded 2026-09-11 09:30Z from todlando's trace; no mitigation applied.\n 6113│- **Instance (todlando, `.worktrees/304-product`, 09:29Z):** his distinct-seq build printed\n     │...\n 6169│\n*6170│### IR-101 — no per-lane producer compiles a lib crate's own `#[cfg(test)]` module on the branch that broke it, so a stale caller of a lane's own signature change rides green through six real-daemon runs and surfaces only at assembly, or from an editor\n 6171│\n 6172│- **Status:** OPEN. Rule adopted 2026-09-11 09:35Z; instrument = one command at inventory and one at\n 6173│  assembly.\n     │...\n 6234│\n*6235│### IR-102 — a dirty file the lane DECLARED is still invisible to an assignment made against its committed blob, so the gater measures and predicts on a blob the lane was never going to run\n 6236│\n 6237│- **Status:** OPEN. Recorded 2026-09-11 09:50Z from hertz's correction; ruling applied (commit all\n 6238│  five), no instrument yet.\n     │...\n 6267│\n*6268│### IR-103 — a rig that re-enters something already retired reads as a product red: four instances in ONE cell (#230), each masking the next\n 6269│\n 6270│- **Status:** OPEN. Recorded 2026-09-11 10:00Z (doyle). Amended 10:20Z: the third instance's repair\n 6271│  RAN (todlando window 10:12-10:18Z, one attempt) and its structural falsifiers all HELD — distinct\n     │...\n 6337│\n*6338│### IR-104 — checker 0.4.0 silently skips a FILE scan root under git enumeration: 81 doc stages read as missing, and a local 0.2.0 green hid it because the two versions disagree on what is evidence\n 6339│\n 6340│- **Status:** FIXED UPSTREAM 2026-09-11 (traceable-reqs v0.4.1, PR #21 -> d9af11d, red-first cells);\n 6341│  spt-core consumes via hertz's #304 lane pin fixup. Closes when that pin is on main.\n     │...\n 6366│\n*6367│### IR-105 — an assertion derived from a MODEL of the fixture instead of read off the fixture can only be refuted by a run, and the lane convention that defers the run gives the class a one-window latency: the repair for the first instance carried the second\n 6368│\n 6369│- **Status:** OPEN. Rule adopted 2026-09-11 (hertz, W1 close). Instrument = read the line, and read\n 6370│  what the line LANDS on, before asserting either.\n     │...\n 6418│\n*6419│### IR-106 — a red set HANDED OVER in a message was reported as a POPULATION: both members verified, their lines and modes corrected, and the count still wrong by half\n 6420│\n 6421│- **Status:** OPEN as a discipline line; the instance is closed (the run that refuted it is on file).\n 6422│  Author and subject: todlando. Filed by doyle 2026-09-11 11:20Z from todlando's text; IR-105 lands\n     │...\n 6449│\n*6450│### IR-107 — a rig that redirects TMP INSIDE the checkout puts every tempdir fixture under a git toplevel, and cells whose premise is \"outside any repo\" resolve THIS repo's remote\n 6451│\n 6452│- **Status:** RIG FIXED in hertz's lane (base now under `AppData/Local/Temp/hertz-304-rig/<label>`;\n 6453│  `HERTZ_RIG_TMP_IN_REPO=1` restores the old placement on purpose as the negative control). Recorded\n     │...\n 6544│\n*6545│### IR-108 — four brainproc unit cells leak a process on every run; two others leak by ordering\n 6546│\n 6547│- **Status:** OPEN, product-side backlog candidate (not #304's). Recorded 2026-09-11 11:35Z (doyle)\n 6548│  from three unfiltered `spt-daemon --lib` runs on identical bytes on HFENDULEAM (todlando 10:52Z at\n     │...\n 6566│\n*6567│### IR-109 — a manifest `[placement] module_banner = \"accept\"` block LOOSENS the local checker to zero; CI's pinned checker is structurally blind to placement, so the loosening is invisible until the pin moves\n 6568│\n 6569│- **Status:** OPEN, RATIFIED 12:33Z (doyle, releases#304) as a TRANSITIONAL policy for the #304 head: the 0.4.1 pin stays (a tightening for every new tag), the accept key exempts only the 312 legacy banner tags, and this entry is the retirement ticket. Recorded 2026-09-11 12:10Z (doyle) from hertz's A/B/C and 0.2.0 arms; the commit's \"agreed\" is corrected by the ruling, not by rewriting a measured sha.\n 6570│- **Instance.** 33936943 \"chore(traceability): enable agreed placement policy\" (07:38Z, trailer todlando, on\n     │...\n 6588│\n*6589│### IR-110 — the gater ruled a wave from origin/main's manifest while the milestone's own product lane already carried the surface; a second implementation was built to its W-1 END before the first was noticed\n 6590│\n 6591│- **Status:** OPEN, STOP LINE on #304 W2 (comment 5634187958). Recorded 2026-09-11 12:10Z (doyle, own instance).\n 6592│- **Instance.** feat/304-remote-friction-product @3e7eaf67 implements #297 TCP admission under\n     │...\n 6617│\n*6618│### IR-111 — the installed product's own inbound UDP rule reads Duplicate / Inactive in ActiveStore, shadowed by the fallback rule; a by-name probe reads it green\n 6619│\n 6620│- **Status:** OPEN, product-side backlog candidate (REQ-INBOUND-WINDOWS-RULE-BINDER-PATH-MATCH family). Recorded\n 6621│  2026-09-11 12:14Z (doyle) from an unelevated `Get-NetFirewallRule` read of both stores on HFENDULEAM.\n     │...\n 6639│\n*6640│### IR-112 — bare `cargo test -p spt-daemon --lib` reds two process-global cells on Linux at a sha where nextest is green; libtest is not a sound gate for this crate\n 6641│\n 6642│- **Status:** OPEN, rig rule (CI unaffected: `ci.yml` runs `kind(lib)` under nextest). Recorded 2026-09-11 12:46Z\n 6643│  (doyle) from hertz's Linux cells lane END on kitsubito.\n     │...\n 6659│\n*6660│### IR-113 — a killed mutation arm does not unwind: the subject stays mutated and the NEXT arm measures a tree nobody declared; and a mutation that reds on a compile error is a void arm that \"it compiled\" cannot detect\n 6661│\n 6662│- **Status:** OPEN, rig rule for every mutation driver. Recorded 2026-09-11 13:05Z (doyle) from todlando's FOLD-1b\n 6663│  window (fold/304-w2-admission, windows.rs).\n     │...\n 6681│\n*6682│### IR-114 — three hands wrote one firewall rule set inside ninety seconds under two directors; every census was true at its instant and false a minute later\n 6683│\n 6684│- **Status:** OPEN, procedure ruled 2026-09-12 00:50Z (doyle) on todlando's reconciliation; recorded 00:52Z.\n 6685│- **Instance.** #304 W-2a arms on HFENDULEAM: ~00:44Z todlando asked the operator to delete spt-w2a-C so B would stand alone; ~00:45Z the operator said \"C down\" and todlando's census read B present / C absent (true then); 00:45:05Z liam ADDED C at doyle's direction (doyle had been idle 11 h and did not know the operator's window); 00:46:14Z liam DELETED B at doyle's direction; 00:49:09Z todlando re-measured C present / B absent. Nobody was wrong; the population was not stable. Every fetch todlando report...\n     │...\n 6690│\n*6691│### IR-115 — a firewall census whose port test is DENIED reads every rule as port=Any and counts port-scoped rules as blanket; a `netsh show rule` without `verbose` omits Program and reads every rule as program=Any; a control count that merges two agents' reads is nobody's control\n 6692│\n 6693│- **Status:** OPEN, mechanisms recorded 2026-09-12 01:14Z (doyle) from todlando's and liam's own corrections during #304 arm E.\n 6694│- **Instances.** (1) todlando's first census A (\"26 blanket rules\") and B (\"occupied LocalPort set: EMPTY\"): `Get-NetFirewallPortFilter -All` returns \"Access is denied\" unelevated, the probe swallowed the denial, every rule read as port=Any, and B's positive control (the hand rule carries LocalPort 5470) is what caught it. (2) His replacement pass: `netsh advfirewall firewall show rule name=all` without `verbose` prints no Program line, so it reported 417 blankets and ZERO rules naming spt.exe — provab...\n     │...\n 6700│\n*6701│### IR-116 — a watchdog that calls a killer and then echoes success reports a kill it never made; `pkill` is absent in msys, so the guard logged \"stopped\" while the arm it guarded ran on\n 6702│\n 6703│- **Status:** OPEN, mechanism recorded 2026-09-12 01:24Z (todlando) from his own guard during #304 FOLD-2's Windows arm at 7357ea32; doyle asked for the line.\n 6704│- **Instance.** todlando armed a watchdog to stop a test arm before it reached `cargo test --workspace --lib`, because spt-daemon lib tests deadlock on a live host. Shape: `if grep -q \"CLIPPY_EXIT=\" log; then pkill -f \"bash /tmp/arms.sh\" 2>/dev/null; echo \"GUARD: arms.sh stopped after clippy at $(date -u)\"`. It printed `GUARD: arms.sh stopped after clippy at 01:24:06Z`. Nothing was stopped: `pkill` does not exist in this msys/Git-Bash environment (`command not found`, exit 127), `2>/dev/null` ate the mes...\n     │...\n 6711│\n*6712│### IR-117 — a predicate that cannot fail: pre-registered outcomes whose branches are not mutually exclusive, and a requirement titled with the TASK instead of the INVARIANT\n 6713│\n 6714│- **Status:** OPEN, mechanism recorded 2026-09-12 03:48Z (hertz, both instances his own; doyle ruled the second).\n 6715│- **Instance 1 — the outcome set.** For the #304 W-2 packet capture hertz pre-registered four outcomes, of which (a) was \"SYN retransmission despite the RST\" and (b) was \"above the wire in the Windows client path\". The capture showed five SYNs at a flat ~511 ms, each RST'd in 18-25 us and each ignored — which is (a)'s packet shape with (b)'s locus. The two branches were the same answer told at two altitudes, so EITHER could have been declared \"confirmed\" and neither could have been refuted by the act...\n     │...\n 6720│\n*6721│### IR-118 — an instrument read mid-flight, or through a filter that cannot match, returns a COMPLETE-LOOKING wrong answer with no error\n 6722│\n 6723│- **Status:** OPEN, two instances one hour apart, 2026-09-12 (hertz); doyle asked for the filter line beside IR-117.\n 6724│- **Instance 1 — the capture read in flight, and it would have inverted the verdict.** `tcpdump -w /tmp/hz-cap.pcap` was still running when the packets were wanted. The file was **8192 bytes** live and **11933 bytes** after `kill -TERM` flushed it; the 3741-byte tail WAS the four SYN retransmissions. Reading the live file would have yielded a well-formed pcap showing one SYN and one prompt RST — i.e. the pre-registered outcome (b), the WRONG answer, assembled entirely from the RIGHT answer's own evid...\n     │...\n 6729│\n*6730│### IR-119 — a control that only had to prove a ROUTE served a real directory; and a rig is not torn down until its last process is gone, whatever the analysis says\n 6731│\n 6732│- **Status:** OPEN, mechanisms recorded 2026-09-12 05:46Z (doyle) from hertz's unprompted self-disclosure. The security remedy is an OPERATOR item, filed on releases#304 comment **5643876746** (rotate the kitsubito self-hosted runner's registration credential); this entry carries only the reusable mechanisms.\n 6733│- **Instance.** The accepted-connection control for the W-2 packet capture was `python3 -m http.server 29472 --bind 0.0.0.0` with **cwd `/home/reavus`** — the self-hosted runner account's home — for **1 h 59 m 54 s**. The off-box bind was REQUIRED (the peer dialled from another machine); the working directory was the whole defect. An empty temp dir returns the identical HTTP 200 and proves exactly as much. `http.server` builds its index from `os.listdir` and filters nothing, so 20 dotfiles including ...\n     │...\n 6740│\n*6741│### IR-120 — a claim named for the one axis nobody varied: six readings over two routes and two libraries, all on ONE box, reported as a property of the platform\n 6742│\n 6743│- **Status:** OPEN, mechanism recorded 2026-09-12 05:47Z (doyle); the instance is liam's, refuted by hertz's own arm and conceded by its author.\n 6744│- **Instance.** The ~2.05 s Windows refused-connect latency was filed as \"the WINDOWS refusal latency\" on six readings that varied ROUTE (loopback, LAN hop to Linux) and LIBRARY (curl, .NET TcpClient) and held HOST constant — every one on HFENDULEAM. Route- and library-independence were measured; \"Windows\" was the name of the box. A per-host WFP callout, endpoint agent or filter driver swallowing RSTs would have produced exactly those six readings on exactly those two routes and generalised nothing. Se...\n     │...\n 6750│\n*6751│### IR-121 — one declaration command expands every right-hand side before assigning any name, so a dependent id silently binds the CALLER'S GLOBAL and two arms collapse onto one artifact path; and `cat -A` behind msys `sed` is not a byte reader\n 6752│\n 6753│- **Status:** OPEN, mechanisms recorded 2026-09-12 09:05Z. Instance 1 found by hertz in todlando's driver and confirmed by doyle; repaired as a separately pinned revision (v6 `dcfb732a…` → v7 `927eafb9…`) per the standing rule that a demonstrated execution incompatibility gets a new hash and renewed verification rather than an in-place accommodation. Instance 2 is todlando's own, found while reading the repair site.\n 6754│- **Instance 1 — the id that looked right.** `trial()` opened with `local arm=\"$1\" n=\"$2\" id=\"$arm-$n\"`. A single declaration command expands EVERY right-hand side before assigning any of its names, so `$arm` was still unset when `id` was built — but `$n` was **not** empty, because the caller is `for n in 1 2 3; do trial a \"$n\"; done` and `n` is a GLOBAL at that point. The id therefore read `-1`, not the empty-ish `-` that would have been noticed: a plausible, consistently-formed, wrong identity. Bot...\n     │...\n 6768│\n*6769│### IR-122 — the field rig's isolated-daemon stop cannot run from an spt-hosted session, so every run leaves a live daemon holding the subject exe inside the pool it just released\n 6770│\n 6771│- **Status:** OPEN, recurring. Instance 1 attempt 2 (`rig/arm2-driver-stdout.txt`: `RIG_DAEMON_STOP_REFUSED_OR_ERRORED — reported, not forced`). Instance 2 run `20260912T231404Z` under frozen r10 (`rig_daemon_stop_EXIT=3`, `cleanup-failures.txt`, `rig-daemon-stop.err`). Recorded by hertz 2026-09-12 23:50Z at doyle's direction; **this is a RIG defect, and any product-surface change requires a separate contract review.**\n 6772│- **The refusal.** `DAEMON_STOP_REFUSED: a broker-stopping command is never run by an spt endpoint ($OWL_SESSION_ID is set). ... No flag overrides this, --force included.` The guard keys on the CALLER'S SESSION ENV, so it fires identically no matter which rig step reaches it and no matter what `SPT_HOME` the command targets.\n     │...\n 6781│\n*6782│### IR-123 — a helper that LOGS cannot also RETURN through stdout: `record` tees, so `face=$(face_report ...)` captures the log block and the acceptance gate can never pass\n 6783│\n 6784│- **Status:** OPEN, mechanism recorded 2026-09-13 (hertz, found by exercising the D2 successor; confirmed by doyle from a direct source read of frozen r10). **Frozen r10 is PRESERVED as-is**; the return channel is corrected in its successor only.\n 6785│- **Instance.** `record()` is `echo \"$1\" | tee -a \"$R/findings.txt\"` — it writes to the log AND to stdout, deliberately, so a live operator sees the run. `face_report()` calls `record` twice (a FACE_COUNTS line and a FACE= line) and then `echo`es the face as its return value. The single caller reads it as `setup_face=$(face_report \"$SETUP_OUT\" \"$SETUP_ERR\" \"SETUP\" bootstrap)`, so the captured value is **the whole tee'd log block with the face appended**, and `[ \"$setup_face\" != reconciled ]` is true no...\n     │...\n 6793│\n*6794│### IR-124 — a cleanup that runs `serve lan --stop` UNCONDITIONALLY creates the daemon it exists to remove, when the setup it is cleaning up after never ran\n 6795│\n 6796│- **Status:** OPEN, measured once in the field. D2 field run `20260913T041410Z`, driver `2e3aec1b`, recorded by hertz 2026-09-13 at doyle's direction. Archive `.spt/preserved/hertz-fp-driver-review/d2/field-run-20260913T041410Z/` (72 files, manifest `defa5d29…`). **This is a RIG defect. It is mine — I wrote the driver — and doyle's admission review missed the unconditional stop path as well; both are recorded because a review that misses a path is part of the mechanism, not an aside.**\n 6797│- **Instance.** The elevated setup was **DECLINED and NOT STARTED** by liam at 04:18:55Z — measured, unambiguous, and the right call: his leg was ready at 04:18:35Z against a hard 04:19:10Z expiry and he refused rather than race the teardown. Nothing ran, nothing mutated. The driver then entered cleanup and executed its own unconditional `env SPT_INSTALL_NO_FIREWALL=1 SPT_HOME=<isolated-home> <exe> serve lan --stop`, which dispatched through the daemon (`ensure_running`, `serveverb.rs:191`) and **CREAT...\n     │...\n 6805│\n*6806│### IR-125 — the driver's own executable sweep reported ZERO processes on the pinned exe while `Win32_Process` showed TWO, at the same instant\n 6807│\n 6808│- **Status:** OPEN, measured in D2 field run `20260913T041410Z` (hertz, 2026-09-13). **A FALSE-NEGATIVE SWEEP, not a false CLEAR** (doyle's classification, and the distinction is load-bearing): the ledger's actual verdict was `residual_state=UNREADABLE` / `CLEANUP=PENDING`, which was correct, and the sweep line is explicitly labelled evidence-only in the driver's own output.\n 6809│- **Instance.** `SUBJECT_EXE_PROBE=OK running_the_pinned_executable=0 enum_total=618` — the probe enumerated 618 processes and concluded none was running the pinned executable. A `Win32_Process` read moments later returned **two**, both with `ExecutablePath` exactly `…\\.worktrees\\304-w2-repr\\target\\release\\spt.exe`: PIDs 45944 and 22524. An independent sweep by path, not by pid, agreed: `count=2`.\n     │...\n 6816│\n*6817│### IR-126 — the experimental budget CONTAINED its own read-only preflight, leaving 128 s of a 300 s window for the elevated leg, and the leg was correctly declined\n 6818│\n 6819│- **Status:** OPEN, measured in D2 field run `20260913T041410Z` (hertz, 2026-09-13). Boundary NOT moved for that run — doyle refused the change mid-flight and was right to; this entry is the scheduling review he asked to be preserved.\n 6820│- **Measured, from the run's own timestamps.** Run start `04:14:10Z` · pre-setup absence census `04:16:23Z` · handoff request written `04:17:02Z`. So **172 s of the 300 s experimental budget went to in-budget read-only preflight** — CI axis queried by name across five statuses, ancestry census, six-instrument hashing, subject identity, 5470 guard baseline, pre-setup absence census — and the driver printed the remainder itself: `HANDOFF_WAIT bounded to 128s`.\n     │...\n 6827│\n*6828│### IR-127 — a nested value-type assignment can leave the native job limit unset while the instrument logs the requested flag and a successful setter\n 6829│\n 6830│- **Status:** OPEN, rig-instrument hazard, not a product finding. Measured by hertz in group M, 2026-09-13; accepted by doyle in `3XE67XYP`.\n 6831│- **Instance.** The containment probe assigned `$info.BasicLimitInformation.LimitFlags = 0x2000`, logged the requested KILL_ON_JOB_CLOSE flag and `SetInformationJobObject=True`, read both owned processes as job members, closed the handle, and found both still alive. The nested field is a struct: PowerShell changed a copy, not the value subsequently marshalled. The offline discriminator measured `nested_assignment_flags=0`; modifying the nested value and assigning the whole value back measured `whole_valu...\n     │...\n 6836│\n*6837│### IR-128 — PowerShell `$null` can become an empty native string, so a failed launch is misread as a policy refusal before the policy is reached\n 6838│\n 6839│- **Status:** OPEN, rig-instrument hazard, not a product finding. Measured by hertz in group M, 2026-09-13; accepted by doyle in `3XE67XYP`.\n 6840│- **Instance.** Both breakaway probe arms called a P/Invoke string parameter with PowerShell `$null`; both returned `CreateProcess` error **123** and created no child. This is an invalid-name result, not the **5** required to establish breakaway-policy denial. An offline C# string-parameter discriminator returned `IsNull($null)=False`: the PowerShell binder had supplied an empty string rather than native NULL.\n     │...\n 6846│\n*6847│### IR-129 — JSON date materialization followed by implicit string parsing loses UTC kind and precision, turning a live creation anchor into a false pid-reuse verdict\n 6848│\n 6849│- **Status:** OPEN, rig-instrument hazard, not a product finding. Measured by hertz in group M, 2026-09-13; accepted by doyle in `3XE67XYP`. The first M8 exit 0 is explicitly INVALID.\n 6850│- **Instance.** `ConvertFrom-Json` materialized an ISO birth string as `DateTime`; `[DateTime]::Parse($id.created)` implicitly formatted that object back to text before parsing it. Kind and fractional precision were lost and local time was reinterpreted. The result printed birth timestamps agreeing within a microsecond but computed roughly seven-hour deltas, mislabelling four live registered identities `GONE_PID_REUSED`. The original output remains at `.spt/preserved/hertz-fp-driver-review/d2/controls-ou...\n     │...\n 6856│\n*6857│### IR-130 — a lowercase `$home` local collides with PowerShell's protected `$HOME`, refusing custody qualification before the signer is reached\n 6858│\n 6859│- **Status:** OPEN, rig-instrument hazard, not a product finding. Measured by hertz on 2026-09-13 in the D2 custody lane; narrow correction and one fresh-root attempt authorized by doyle `5FWLC3F2`. Original refusal remains preserved.\n 6860│- **Instance.** The prepared custody controller passed syntax parsing and compiled its native observer successfully, then exited **1 after 3.33 s** before any custody arm. Its next statement assigned `$home = Join-Path $armRoot 'home'`. PowerShell variable names are case-insensitive: this is an assignment to automatic `$HOME`, whose measured options were **ReadOnly, AllScope**. A separate language-only reproduction returned **VariableNotWritable**. The original catch deliberately omitted exception detail...\n     │...\n 6866│\n*6867│### IR-131 — a live-agent signing environment leaks into the provisioning process and correctly refuses before the private signer exists\n 6868│\n 6869│- **Status:** OPEN, rig invocation-environment defect, not a candidate or disk defect. Measured by hertz on 2026-09-14; classified by doyle in `VGCTKD7A`.\n 6870│- **Instance.** Second fresh #297 preparation admitted fourteen native leaves at `04:51:39.245Z`. The separate provisioning call launched at `04:51:52.802Z` and returned `STAGING_FAILED_PREFLIGHT`, native exit **1**, after **0.45 s**. No rig, private directory, key or field nonce existed. This was a preflight refusal before the `04:59:31Z` deadline, not a stalled launch.\n     │...\n 6877│\n*6878│### IR-132 — requiring every live-fleet `spt.exe` image path to be readable permanently refuses an isolated rig's admission\n 6879│\n 6880│- **Status:** OPEN, rig-instrument admission defect, not a candidate, environment-scrub or disk defect. Measured by hertz and independently localized by doyle on 2026-09-14; correction ruled in `W8TQ3MZC`, `6IQ4HYIL`, `QKQC2NET` and `MRQX7XEK`.\n 6881│- **Instance.** Third preparation passed fourteen native admission leaves and genuinely staged the signed set. Promotion then returned `PROMOTION_ADMISSION_FAILED`, native **1**, with `native_records=[]` and shutdown `NOT_STARTED`. Its census required a nonblank CIM `ExecutablePath` for **every** `spt.exe`, not merely one that could belong to the new rig. The read-only predicate replay passed twenty-five preceding statements and failed `SPT_PROCESS_PATH_UNREADABLE` at line 273. No apply, daemon, field no...\n     │...\n 6888│\n*6889│### IR-133 — a live capture cannot be read with read-only sharing, and daemon stderr belongs to the owned home\n 6890│\n 6891│- **Status:** Corrected in the r9 rig instrument; genuine fifth-window promotion completed with exit **0**, owned shutdown and final provenance. The subsequent field attempt failed its separate setup-handoff deadline, not this promotion read. Fourth #297 preparation measured by hertz on 2026-09-14; sharing failure localized by doyle in `R2VK8FQN`, run-identity binding ruled in `ANR522S5`, successor accepted in `GV3R6QUV`.\n 6892│- **Instance.** Fourteen admission leaves and genuine staging passed. The candidate applied daemonlessly, transitioned `applied-pending` → `applied`, brought up broker **14704** and brain **45220**, published the pinned generation-zero readiness record and emitted `BRAIN_PROMOTED` before the instrument stopped its owned job. The instrument returned only `OWNED_PROMOTION_READINESS_FAILED`. Six provisioning/promotion native jobs ended `CONFIRMED_GONE`, active counts zero; all nineteen signing-private fil...\n     │...\n 6900│\n*6901│### IR-134 — request latency consumes the elevated capture's execution budget, then a late terminal receipt leaves completed work unmeasured\n 6902│\n 6903│- **Status:** Instrument correction qualified without a sixth field window. Doyle accepted the execution-clock repair in principle under `HHDKCRH5`, then identified its still-insufficient receipt budget; the derived-window successor follows ruling `P9RLK4VU` and accepted arithmetic `KZG4IN37`. Candidate/packet/nonce/driver/runner repinning remains one future amendment, separate from field authorization. Fifth #297 field run `20260914T063552Z` remains failed and immutable. Its candidate's independent **PR...\n 6904│- **Measured sequence.** Setup request `06:41:26Z`, elevated setup `06:43:18Z`–`06:43:24Z`, refused capture launcher `06:43:25Z`–`06:43:26Z`, receipt about `06:43:27Z`. The driver had written the capture deadline from request time: 112 seconds of handoff delay left the launcher's `deadline - now - 5` allocation at **−4 seconds**. No native t1 capture ran. The handoff expired before the receipt; cleanup reread its nonce and exit but retained the earlier `timestamp_order=UNMEASURED`, withholding muta...\n     │...\n 6913│\n*6914│### IR-135 — checker pin and runner installation can disagree, and the repair path disguises that version mismatch as an authentication failure\n 6915│\n 6916│- **Status:** CI precheck remedy implemented in the IR-135 lane; workflow execution awaits integration. Measured by doyle in S4 golden `34946493637`, 2026-09-15; filed by hertz from `3HHHPWCR`. The immediate box mismatch was repaired by hand-install.\n 6917│- **Instance and mechanism.** The #304 candidate carried `71caedd4`, setting `WANT=0.4.1` in `golden.yml`/`ci.yml`, while kitsubito's `~/.local/bin/traceable-reqs` was **0.2.0**. The install step's mismatch path attempted a private clone without a provisioned `TRACEABLE_REQS_TOKEN` and exited **128 before any check**. The visible failure named authentication, not the wanted and installed versions. A checked-in pin is not evidence that the runner can supply it; the fallback requires a second, independentl...\n     │...\n 6920│\n*6921│### IR-136 — a broker bound under the seed socket's name is not seed control, so a URL-minting rig can omit the very listener contract the product queries\n 6922│\n 6923│- **Status:** Instance fixed in S5 **`ddd7fc7f070667524578c282894dd44a2e36062f`**, test-only atop S4; S5 golden34957614641 passed, including both twohost roles. Shared fixture-composition remedy implemented and Linux-verified in the IR-136 lane. Origin: doyle's S4 golden `34946493637` twohost helper red, 2026-09-15.\n 6924│- **Mechanism.** Role B hosted broker IPC under an invented name, with neither `seedmap::serve_seed_control` nor a docs listener. `REQ-WEB-URL-BOUND-PORT` requires `serve_for` to ask the canonical seed-control plane for `DocsStatus` before publishing a URL; the missing plane returned `DOCS_PORT_DISCOVERY_FAILED: Connection refused (os error 111)`. Merely renaming a Broker to `seed_socket_name()` does not provide that protocol: `serve_request` is dispatched by seed control, not Broker. The docs-server fix...\n     │...\n 6931│\n*6932│### IR-137 — a redirected Start-Process child can share the tool call's console lifetime and die when that call returns\n 6933│\n 6934│- **Status:** RETIRED, 2026-09-15, doyle ruling `YPLFG3CG`: **no tracked callsite; discipline recorded + receipt**. This closes a Windows ad-hoc rig-craft item, not a CI or candidate defect; no helper or product change.\n 6935│- **Mechanism and rule.** `Start-Process` with redirected output from a PowerShell tool call was observed to end with **`STATUS_CONTROL_C_EXIT`** when the tool call ended: a returned child PID did not establish detachment. The reported detached form uses a **hidden window without redirects**. Where a child must outlive the call, qualify its survival after the caller returns and give it a durable output path of its own; do not treat process creation or a hidden window alone as lifetime evidence.","truncation":{"content":"*1|# Infra register — CI / build-pipeline debt\n 2|\n 3|Operator-ruled 2026-08-02: infrastructure and CI-pipeline work items live HERE, not on the\n 4|`spt-bs-releases` board. The board carries product surface the operator triages; this register\n...\n 11|Last sweep: **2026-09-11, v0.69.0 RELEASE CLOSE — FULL REGISTER**, source `e5a2fed9`.\n*12|All **97 entries (IR-1–97, including headingless IR-31)** read in two disjoint ranges; audit\n 13|population checked for missing/duplicate IDs (97 rows, 97 unique, zero missing). Per-entry\n 14|trigger and disposition evidence: `.spt/preserved/infra-close069-20260911/audit.json`.\n 15|UNKNOWN means no qualifying event established, not a disproved trigger or a discharged debt.\n...\n 43|- **Next-intake composition, owned by doyle until accepted:** hertz's driver/workflow package\n*44|  takes IR-31/46/59/60/76/86/87/90/97: aggregate capacity, truthful producer status, existing\n 45|  quiet-window contract, independent rendezvous clocks, and mandatory between-run identity\n 46|  census. IR-88 adopts the already-proven prebuilt release-before-delete recipe; IR-64 remains\n 47|  a separate operator capacity decision. No new loaded comparison before these prerequisites.\n...\n 64|\n*65|### Intake addendum — hosted-relay diagnostic capacity hold (2026-09-11)\n 66|\n 67|Sourced C: free samples around the intake, each named by file: **19,260,395,520 bytes at\n 68|03:02:33Z** (post-merge run 34556292801, unit job `FLOOR_END`, RED against the\n...\n 95|The isolated hosted-relay experiment is separate from #304 implementation and from the #294\n*96|cause investigation. Carry its capacity planning under **IR-31/59/90**, not a new product\n 97|request. Hertz owns identifying the minimum diagnostic target, reusable version-matched\n 98|artifacts, estimated incremental build/temp footprint and the concrete socket/network isolation\n 99|gap. Doyle owns matching that requirement to an owned pool and available capacity before\n...\n 108|IR-76's origin. Enumeration by a read-only subagent into `REGISTER-SWEEP-0671-DRAFT.md` (75\n*109|entries, 10 trigger-text candidates; IR-31 has NO `###` heading — its body sits under IR-30's,\n 110|flagged, not normalized). Rulings: **IR-46 trigger FIRED and was MISSED** — `golden.yml` was\n 111|touched by `04e32c8c` itself (2-line HEAVY reclass on the respin) and no remedy was weighed; a\n 112|respin edit under a pre-registered hard stop is not a remedy window, so the entry gains that datum\n...\n 270|\n*271|## OPEN\n 272|\n*273|### IR-1 — Quiet predicate needs a network axis (tailscale RTT probe)\n 274|- **Status:** BUILT AND LANDED — reconciled at [[CI-RIDER LANE STATE]]; golden-only exercise\n 275|  recorded at the 2026-08-05 close (30971976024). Header corrected 2026-09-11. Originally\n 276|  carried by `bf8c4a2` → `REQ-CI-LINK-HEALTH-PROBE`, mapping CONFIRMED by builder hertz 2026-08-03\n...\n 302|\n*303|### IR-2 — Settle the warm-runner CARGO_INCREMENTAL delta\n 304|- **Status:** RETIRED 2026-08-28, measurement run, verdict NO FLIP — incremental stays ON.\n 305|  hertz paired goldens at main fed965f8: ON run 33167693879 GREEN; OFF run 33172022108 RED\n 306|  (Windows input_ack_deadlock SetupFailed at a 3.0s IPC read deadline — the box-load family,\n...\n 327|\n*328|### IR-3 — Daemon-level guard: broker-net wakeup rate bounded across endpoint churn\n 329|- **Status:** open · **Origin:** releases#125 remediation, todlando REQ call 1 (ex releases#128)\n 330|- **What/why:** the swarm-discovery GC-spin burned two cores for two weeks visible only in a\n 331|  process table — no suite assertion sees the class. Wanted: a daemon-level assertion that\n...\n 340|\n*341|### IR-4 — Lock-pin guard + lock-procedure rule + toolchain print (three riders, one lane)\n 342|- **Status:** BUILT AND LANDED — `1275e47` / `49d4805` / `8ed006b` mapped and landed in the\n 343|  [[CI-RIDER LANE STATE]] reconciliation; golden toolchain-print exercise recorded at the\n 344|  2026-08-05 close (30971976024). Stale unlanded header corrected 2026-09-11. ·\n...\n 363|\n*364|### IR-5 — Shared nextest summary parser\n 365|- **Status:** open · **Origin:** BAROMETER triage (standing recommendation, pre-register)\n 366|- **What/why:** two agents in one day wrote `[0-9]+ tests run` parsers that read \"1 test run\"\n 367|  (singular) as zero — a guard fed by a broken parser condemns valid rounds. One shared,\n...\n 382|\n*383|### IR-6 — Membership logging on subnet gates\n 384|- **Status:** open · **Origin:** BAROMETER triage (standing recommendation, pre-register)\n 385|- **What/why:** counts beside results, membership beside counts — gate logs that state a count\n 386|  without naming the population keep producing unreadable reds. Standardize membership\n...\n 394|\n*395|### IR-7 — Phase A rigs leak a daemon+brain pair on Windows (exe-lock kills notify relink)\n 396|- **Status:** open · **Origin:** BAROMETER post-publish triage (ex releases#124 — full mechanism on the closed issue)\n 397|- **What/why:** two Phase A rigs launch daemons that escape the job object via WMI-rung autostart\n 398|  (double-space unquoted cmdline fingerprint; SPT_HOME in the wrapper cmdline is the attribution\n...\n 405|\n*406|### IR-8 — reap-census scoped_survivors=0 is blind to unreadable-path holders\n 407|- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane. · **Origin:** BAROMETER triage\n 408|  (ex releases#122)\n 409|- **What/why:** a zero that cannot see is not a zero — census scoping skips procs whose exe path is\n...\n 439|\n*440|### IR-9 — Golden boxes run different clippy versions\n 441|- **Status:** pin LANDED 2026-08-18 at `35968156` (`build: pin Rust 1.96.0`), then\n 442|  audited **BUILT** at the 2026-08-29 v0.65.0 close sweep; the pin is an ancestor of\n 443|  golden-green cut SHA `4d6007ac`. The earlier measurement half had already landed and run:\n...\n 477|\n*478|### IR-10 — Wave gate runs the CONSUMERS of any predicate it changes\n 479|- **Status:** open · **Origin:** BAROMETER gate craft (ex releases#119)\n 480|- **What/why:** legs chosen from changed crates miss the predicate's callers; a composed red is\n 481|  triaged at the wave's own tip first. This is the gate-population rule made binding in the gate\n...\n 485|\n*486|### IR-11 — find-cwd-holders.ps1: --headless discriminator as a column\n 487|- **Status:** open · **Origin:** worktree-pin triage tooling (ex releases#118)\n 488|- **What/why:** the holder-triage script buries the headless-vs-interactive discriminator in prose;\n 489|  as a column it makes the orphan-vs-own-shell call one glance.\n...\n 492|\n*493|### IR-12 — xtask contract-drift gate misses a stale manifest.schema.json\n 494|- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane (the narrowed blind arm only). · **Origin:** ex\n 495|  releases#116\n 496|- **KIN NOTE RETIRED (2026-09-06, hertz; doyle measure-first ruling):** the stale-binary\n...\n 540|\n*541|### IR-13 — Test-soundness follow-ups from the uniform-table sweep\n 542|- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane. · **Origin:** ex releases#58\n 543|- **What/why:** the remaining candidates from the closed issue were mutation-proved before changing\n 544|  tests. `hold_outranks_everything` now walks all four `Opportunity` arms (including\n...\n 551|\n*552|### IR-14 — .worktrees audit: \"how many worktrees are there\" has four defensible answers, and the difference is not junk\n 553|- **Status:** open · **Origin:** ex releases#56 (was flag: NEEDS-OPERATOR in eval — operator input\n 554|  now sought directly when the entry ripens, not via board flag)\n 555|- **What/why:** the project `.worktrees/` dir accumulates content beyond what git tracks; audit +\n...\n 573|\n*574|#### THE COUNT DISAGREEMENT IS THE FINDING (measured 2026-08-03, todlando + doyle, main @`3efd7e6`)\n 575|\n 576|Three people measuring \"the worktrees\" got three answers. None was wrong; they answered three\n 577|different questions, and nothing in the tree states which one is meant:\n...\n 594|\n*595|#### THE 15 UNREGISTERED DIRECTORIES ARE FOUR DIFFERENT KINDS OF THING\n 596|\n 597|⛔ **CLASS A — LIVE BUILD POOLS, NOT ORPHANS. DO NOT DELETE.** 3 dirs, 13.2 GB. Each is the TARGET of\n 598|a junction that a REGISTERED worktree uses as its `target/`:\n...\n 641|\n*642|#### PIN STATE: NO SKELETON IS HELD TODAY (with a stated blind spot)\n 643|\n 644|Read-only PEB CWD sweep, 2026-08-03: **zero processes hold a CWD in any class-B or class-C\n 645|directory** — every live pin was in `gate-ec5f38a` and `gate-main`, both REGISTERED and both running\n...\n 651|\n*652|#### THE LOOSE FILES: A SHARED LOCATION WITH NO STATED CONTRACT\n 653|\n 654|**21 loose files sit in `.worktrees/`** — gate logs (`gate-*.log`, `gate-559632e-log.txt`), rig\n 655|scripts (`g6-curve.ps1`, `g6-postbounce.ps1`, `gate-w5-*.ps1`), and `gate-w5-notes.md`. **Nobody\n...\n 661|\n*662|#### RECLAIM ARITHMETIC — AND WHY THIS ENTRY IS NOT THE DISK FIX\n 663|\n 664|Classes B, C and D together are **under 51 KB**. All 13.2 GB of the unregistered population is class\n 665|A, behind live junctions. **An orphan sweep is not a disk-space remedy**, and reading it as one sends\n...\n 714|\n*715|### IR-17 — Deadline-burn bring-up family: a test burns its full window while the daemon/brain never comes up\n 716|- **Status:** open · **Origin:** golden 30782259675 red triage 2026-08-03\n 717|- **What/why:** two different tests on two runner hosts now share one signature — bring-up misses\n 718|  its ONLINE window under leg load and the test burns its ENTIRE deadline before the PRECONDITION\n...\n 832|\n*833|### IR-16 — kill_tree discards TerminateJobObject/TerminateProcess returns (silent partial kill)\n 834|- **Status:** BUILT 2026-08-03 (landed @62c5623 on the LOCKSMITH t1 lane; rides golden sha\n 835|  b7b00c3, run 30860770146 green) · **Origin:** ex releases#130 (golden 30776330383 red triage;\n 836|  deployah's log read\n...\n 869|\n*870|### IR-18 — resident_service_e2e kills breadcrumb pids BARE (stale-breadcrumb tree-kill; kill-side twin of IR-15)\n 871|- **Status:** BUILT 2026-08-04 — the named acceptance carrier RAN and the condition is DISCHARGED,\n 872|  stated as the measurement rather than as the green board it sat on: LOCKSMITH's golden run\n 873|  30860770146 (head `b7b00c3`, conclusion success) executed the changed test IN-POOL on BOTH\n...\n 1154|\n*1155|### IR-19 — Docs-only pushes to main run full unit legs (classifier is PR-only) — intent unverified\n 1156|- **Status:** RETIRED 2026-08-18 — intentional for main pushes, not a classifier defect. · **Origin:** hertz observation 2026-08-03 (register-push\n 1157|  cadence gated his rig behind repeated hfenduleam unit legs); mechanism verified by doyle at\n 1158|  source same night.\n...\n 1183|\n*1184|### IR-20 — resident_service_e2e's `spt daemon stop --force` does not stop the daemon; teardown is complete only because the kills are\n 1185|- **Status:** open · **Origin:** hertz 2026-08-03, measured on the IR-18 lane's own clean run\n 1186|  (hfenduleam, log kept); routed text, doyle-landed.\n 1187|- **MEASURED:** teardown runs `spt(&[\"daemon\",\"stop\",\"--force\"])` then reaps. At reaper fire, every\n...\n 1216|\n*1217|### IR-54 — golden-head-intake runbook: three properties this cut proved should be construction, not discipline\n 1218|- **Status:** BUILT 2026-08-29 — PR #176 (`880b3b9c`, landed on main via `37368263`).\n 1219|  · **Origin:** PORTER (#205) v0.59.0 cut, 2026-08-21 — doyle (gater) + deployah (driver),\n 1220|  both mechanisms measured at the cut, neither cost this run anything because the driver caught\n...\n 1248|\n*1249|## IN-FLIGHT ON THE BOARD (not re-homed — live WIP lanes)\n 1250|\n 1251|- releases#93 (servicehost swap test pid-inequality), releases#47 (thin-lane unit(Windows)\n 1252|  isolation class), releases#32 (worker_lifecycle_e2e Phase A intermittent) — infra-shaped but WIP;\n...\n 1254|\n*1255|## BUILT / RETIRED\n 1256|\n*1257|### IR-15 — provably_gone is pid-only on Windows: teardown tests can fabricate reds\n 1258|- **Status:** BUILT 2026-08-03 · **Origin:** golden 30776330383 red on the #125 fix lane (2026-08-02)\n 1259|- **Lane:** hertz `golden/ir15` @a5042ec — REQ-TEST-LIVENESS-ORACLE-AUTHENTICATED (impl+unit): one\n 1260|  shared authenticated death-oracle test helper backed by `spt_procident::process_identity`\n...\n 1283|\n*1284|### IR-21 — CLASS: a helper binary's build is never requested, only its LOCATION is, so any narrow invocation manufactures a red that belongs to the rig\n 1285|- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane. · **Origin:** todlando 2026-08-03. Filed as one instance, rewritten as a CLASS the\n 1286|  same day when a second member appeared, rewritten AGAIN when the mechanism was measured — the\n 1287|  first two versions described symptoms and got the remedy wrong. **Corrected a fourth time the same\n...\n 1302|\n*1303|#### THE MECHANISM (measured, both ends)\n 1304|\n 1305|**Build end — `cargo test` with a narrow target selector compiles a `[[bin]]` AS A TEST HARNESS and\n 1306|never emits the plain executable.** Measured: `cargo test -p spt --bins` on a clean pool produced\n...\n 1334|\n*1335|#### SCOPE — WHERE IT BITES, AND WHERE IT DOES NOT\n 1336|\n 1337|**It bites NARROW invocations — `-p <pkg>`, `--bins`, `--lib` — i.e. gate rigs and local runs.**\n 1338|Both members were hit on the LOCKSMITH t1 lane against fresh throwaway pools; each was discharged\n...\n 1360|\n*1361|#### THE ONE CI-SIDE MEMBER THAT IS REAL\n 1362|\n 1363|`crates/spt/src/cli.rs::adapter_translate_proof_gates_on_commit` is a **unit** test (`kind(bin)`),\n 1364|and `CARGO_BIN_EXE_*` is set only for integration tests and benches of the declaring package. A unit\n...\n 1374|\n*1375|#### POPULATION\n 1376|\n 1377|**13 bin targets in the workspace** (`cargo metadata --no-deps`, not a grep — an auto-target under\n 1378|`src/bin/` and `xtask` are both invisible to a `[[bin]]` grep). Two are not helpers (`spt`, `xtask`);\n...\n 1431|\n*1432|#### REMEDY SHAPE (not ruled)\n 1433|\n 1434|The distinction that matters is location vs. build:\n 1435|\n...\n 1454|\n*1455|#### SUPERSEDED FRAMING, KEPT SO IT IS NOT RE-DERIVED\n 1456|- **Status of the original filing:** open · **Origin:** todlando 2026-08-03, both members hit on the\n 1457|  LOCKSMITH t1 lane against fresh throwaway pools; each discharged in-lane as a rig artifact, filed\n 1458|  here so the next clean rig does not re-diagnose them as code reds.\n...\n 1498|\n*1499|### IR-22 — An inherited identity env var fails a test, and the diagnostic names them ONE AT A TIME so a correct fix reads as no fix\n 1500|- **Status:** open · **Origin:** todlando 2026-08-03, chasing what looked like an `attach_wedge_e2e`\n 1501|  code red on the LOCKSMITH t1 lane; root-caused to the runner's own process environment.\n 1502|- **MEASURED:** `attach_wedge_e2e` failed for an INHERITED PROCESS-GLOBAL and nothing in the tree:\n...\n 1520|\n*1521|### IR-23 — `endpoint_teardown_authority_e2e`'s two tests collide with EACH OTHER through the machine-global spt home\n 1522|- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane. · **Origin:** todlando 2026-08-03, LOCKSMITH t1 lane.\n 1523|- **MEASURED:** both tests copy a psyche binary fixture into `perch::spt_home()/srcs/dummyharness/`\n 1524|  (`crates/spt/tests/endpoint_teardown_authority_e2e.rs:399`), which is process-global, so run in\n...\n 1545|\n*1546|### IR-24 — `reap::terminate_job` discards `TerminateJobObject`'s return, alone among its own module's siblings\n 1547|- **Status:** BUILT — landed `3d12cf3` on main (2026-08-03), fulfilment verified against this\n 1548|  entry's own wanted list by doyle 2026-08-04, not merely mapped to the commit: the return is\n 1549|  audited and the loss NAMED (`REAP_JOB_TERMINATE_FAIL: brain subtree NOT reaped (<os error>); …\n...\n 1585|\n*1586|### IR-25 — `spt-daemon --lib` reds 2-in-3 under concurrent load with bare `cargo test`, and holds green under nextest\n 1587|- **Status:** open · **Origin:** doyle 2026-08-03, found while gating LOCKSMITH tranche 1 in an\n 1588|  isolated worktree; chased to a mechanism and scoped OUT of the release path before the head was\n 1589|  assembled.\n...\n 1632|\n*1633|### IR-26 — POOL-OWNER claims authorize takeover from a DEAD holder, so releases#103's hazard reaches through the guard\n 1634|- **Status:** OPEN for residual claim-time observability and stale-reader enforcement; the\n 1635|  original build-side lane is COMMITTED (see its later reconciliation below), not still\n 1636|  uncommitted. Header corrected 2026-09-11; no residual closed by cleanup. · **Origin:**\n...\n 1805|\n*1806|### IR-27 — A junction-pooled rig is TWO objects and teardown only ever removes one\n 1807|- **Status:** open, found in the wild 2026-08-04 · **Origin:** hertz's 44-tree worktree sweep\n 1808|  (IR-26 follow-on 3) · **Cross-ref:** [[IR-14]] (unclaimed pools), [[worktree-target-junction]]\n 1809|- **What/why:** a rig built as `worktree\\target -> junction -> .worktrees\\<pool>` has its build cache\n...\n 1839|\n*1840|### IR-28 — A wave-gap rider is visible to the request board and invisible to a milestone-narrative notes pass\n 1841|- **Status:** BUILT 2026-08-29 — PR #176 (`880b3b9c`, landed on main via `37368263`).\n 1842|  · **Origin:** deployah, v0.53.0 release close 2026-08-04.\n 1843|- **What/why:** the v0.53.0 changelog omitted `184f2ac` (the releases#125 two-core CPU-burn fix, a\n...\n 1854|\n*1855|### IR-29 — twohost ladder: role A fires the done-barrier BEFORE its last cross-node rung, so the re-pull's serve window is won by timing, not guaranteed\n 1856|- **Status:** OPEN for later serve-window/rung residuals; the original\n 1857|  `test/twohost-serve-window` fix `17bbbd8` LANDED in v0.54.0, as recorded by IR-30.\n 1858|  Stale authored-but-unlanded header corrected 2026-09-11; no new acceptance or margin\n...\n 1917|\n*1918|### IR-30 — GOLDEN 4b37512 (#145): five attempts, four distinct Windows victims, one sha — the random-victim family measured end to end, and the instruments it left behind\n 1919|- **Status:** open for the FAMILY SIGHTINGS ONLY — the instrument lanes LANDED as planned with\n 1920|  the next golden batches (measured 2026-08-25, doyle, `git merge-base --is-ancestor` + first\n 1921|  tag: serve-window `17bbbd8`, selection probe `695398ba`, resume taxonomy `58337879` all in\n...\n 2177|\n*2178|### IR-32 — Docs-drift gate blesses its own gen: an empty-emitting producer agrees with itself perfectly\n 2179|- **Status:** open · **Origin:** todlando mid-lane stop-and-report, U1 (#144) 2026-08-04. Filed by\n 2180|  the builder to the gater deliberately — register shape is doyle's to own.\n 2181|- **What/why:** with a defective binary in the tree (stack-overflowed before reaching its own\n...\n 2211|\n*2212|### IR-33 — Debug-build clap Command tree runs near the main-thread stack ceiling; the margin is THREE net new args, bisected at `8f291e1` (the original ~6 was measured on U1's tree and is superseded)\n 2213|- **Status:** OPEN for acceptance/margin reconciliation. Current source at `e5a2fed9` runs\n 2214|  the CLI on an owned 16 MiB thread stack and includes `cli_stack_smoke`; the three-argument\n 2215|  ceiling below is a historical measurement at `8f291e1`, NOT today's measured margin.\n...\n 2264|\n*2265|### IR-34 — nextest LEAK flag on the zombie-fixture row is dominant-but-intermittent (19/20 measured); any gate reading it as a signal flaps\n 2266|- **Status:** open · **Origin:** doyle #142 F-lane gate 2026-08-04 (first sighting in a gate run);\n 2267|  characterized same day by hertz from retained logs, ownership falsified by todlando.\n 2268|- **What/why:** `broker::tests::windows_session_is_zombie_sees_a_handle_held_corpse_as_dead` (the\n...\n 2289|\n*2290|### IR-35 — hfenduleam Windows test-leg victim rate: one teardown/liveness family, measured at ~half of all executions\n 2291|- **Status:** open · **Origin:** USHER #150 golden triage 2026-08-04 (doyle; all rates deployah-measured).\n 2292|- **The numbers (15 golden runs 2026-08-02..08-04 + the USHER cycle, deduped on `(run, box,\n 2293|  started_at)` — GitHub partial reruns COPY untouched jobs into the new attempt with their ORIGINAL\n...\n 2295|  any rate math):** Windows (hfenduleam) 13 red / 22 executions = 59% leg-red, splitting 10/22 = 45%\n*2296|  test-victim + 3/22 infra (IR-31 class). Linux (kitsubito) 2/20 = 10%, 1 victim. Every victim-red\n 2297|  leg had EXACTLY ONE victim (8/8 legs). Clean-cycle arithmetic ≈ 0.55 × 0.95 ≈ half — a golden\n 2298|  cycle at these rates is a coin flip. knock145 (the previous green golden) took FIVE Windows\n 2299|  executions to its green; USHER took four. **A both-green draw is a draw, not evidence the family\n...\n 2325|\n*2326|### IR-36 — `output_bounded` is a 51-copy clone estate with a named-but-empty shared home; hoist-and-delete wants its own lane\n 2327|- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane. · **Origin:** hertz measurement\n 2328|  2026-08-04 (at `7465ac1`, counted before listing, listed untruncated), during the USHER package\n 2329|  item-2 sweep ruling; doyle ruled file-don't-sweep.\n...\n 2361|\n*2362|### IR-37 — `traceable-reqs check` is coverage-only: tag PLACEMENT is unenforced on any multi-tagged REQ, and the more tags a REQ accumulates the less any one is checked\n 2363|- **Status:** UPSTREAM CLOSED THROUGH RELEASE 2026-08-19 — traceable-reqs PR #19 squash-merged\n 2364|  @`82d8b14` after doyle's targeted re-review PASS (defect A item-tables + 9 red-first regression\n 2365|  cells + sighted control; defect B enclosing-item fallback DECLARED in SPEC with cost; 267/267,\n...\n 2424|\n*2425|### IR-38 — CLASS: an e2e that ends with a live daemon-spawning binary wedges the NEXT build in its pool, and the diagnostic names the wrong lane\n 2426|- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane. · **Origin:** todlando 2026-08-04,\n 2427|  `shell_relink_force_e2e` on the #6 lane (filed by doyle; the finding and the fix are todlando's).\n 2428|- **What/why:** the e2e ends with a LIVE binary by design; on Windows a live process holds its\n...\n 2463|\n*2464|### IR-39 — CLASS: the missing-fixture-bin defect has TWO failure faces, and one of them impersonates a lifecycle defect of the subject under test\n 2465|- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane. · **Origin:** hertz + todlando\n 2466|  2026-08-04, same evening from opposite sides (filed by doyle; hertz relayed todlando's\n 2467|  suggestion without endorsing scope).\n...\n 2500|\n*2501|### IR-40 — CLASS: NO envelope-side ordering signal on a resume brief tracks content recency, and a CI informant's per-job line is a claim about that STEP, not the run\n 2502|- **Status:** open · **Origin:** three sightings in one night, 2026-08-04/05 — hertz, doyle,\n 2503|  todlando (filed by doyle; the artifacts are hertz's and todlando's, the CI arm is doyle's with\n 2504|  deployah's framing). Two arms of ONE family: a stale record that carries a confident ordering\n...\n 2577|\n*2578|### IR-41 — A QUEUED main run is superseded without a record; `cancel-in-progress: false` protects only STARTED runs\n 2579|- **Status:** open — mechanism CONFIRMED (doyle ruling 2026-08-05); the runbook sentence it\n 2580|  falsified is already corrected (`docs/RELEASE-RUNBOOK.md` step 3, same commit as this entry)\n 2581|  · **Origin:** deployah, v0.55.0 publish night, filed by him explicitly as UNPROVEN with the\n...\n 2609|\n*2610|### IR-42 — `pool-claim` writes a record; only the BUILD enforces — and AGENTS.md invited the misread\n 2611|- **Status:** BUILT 2026-08-19 — the AGENTS.md corrective line lands in the SAME COMMIT as this\n 2612|  entry (the register batch commit), which is the entry's stated exit condition. The optional\n 2613|  code-side nicety (claim verb prints the incumbent record it overwrites, information only)\n...\n 2637|\n*2638|### IR-43 — knock answer carrier: `NoReply` landed at 60.08s against a stated 30s carrier deadline\n 2639|- **Status:** open, OBSERVATION — mechanism unmeasured, filed exactly as wide as the datum ·\n 2640|  **Origin:** KNOCK-169 RCA layer 1 (todlando, read-only), golden 32191618042 @`93c1130`,\n 2641|  twohost-b, 2026-08-18.\n...\n 2654|\n*2655|### IR-44 — perch-sentinel comment overclaims: serialization is not preservation, and the comment teaches the false step\n 2656|- **Status:** open · **Origin:** #188 RCA lock read (todlando flagged, doyle confirmed the lock\n 2657|  read), 2026-08-18; the collapse-of-branches argument is on #188 and in the RCA record.\n 2658|- **What/why:** `lock_perch_sentinel` (info.rs:778 at `b20e770`, the diag sha — re-derive the\n...\n 2675|\n*2676|### IR-45 — twohost rig home premise, SETTLED: pump paths resolve under the per-run TEMP root (rig is disk-hermetic; the \"live fleet roster\" reading is retired)\n 2677|- **Status:** RETIRED 2026-08-19 — ask answered by the one code read at main @`78a9a16`; residue\n 2678|  re-homed (see Answer). · **Origin:** #188/#189 RCA readouts (todlando, doyle's 2a-2d), runs\n 2679|  32097943571 + 32108557362 + 32111921251, 2026-08-18.\n...\n 2706|\n*2707|### IR-46 — the Windows disk-floor preflight asserts an INSTANT; workspace free space moves tens of GB inside the hour, so a green floor is not a claim about run headroom\n 2708|- **Status:** open — mechanism CONFIRMED by a measurement series on hfenduleam; doyle ruled it\n 2709|  register-shaped 2026-08-18 · **Origin:** deployah, NAMEPLATE #181 golden-head intake, on the\n 2710|  run that the floor red-floored · **Filed as IR-46 after an id collision:** this row was authored\n...\n 2773|\n*2774|### IR-47 — ci-notify treats a missing co-author trailer as a quiet info line; silent attribution loss reads as \"there was none\"\n 2775|- **Status:** open — patch AUTHORED and stashed unlanded since 2026-07-29\n 2776|  (`.worktrees/_patches/ci-notify-missing-trailer.patch` + its `test-ci-notify.sh` harness in the\n 2777|  sibling `.untracked` dir); surfaced by doyle's 2026-08-19 idle-queue verification of that stash ·\n...\n 2800|\n*2801|### IR-48 — the nextest.toml parity cell tolerates CRLF only by parser accident; a newline-sensitive arm added later reds fresh Windows checkouts alone\n 2802|- **Status:** open — filed 2026-08-19 (doyle route, hertz verdict: REGISTER as preventive\n 2803|  hardening, not current defect) · **Origin:** sibling sweep after the W3 gate CRLF finding —\n 2804|  parent mechanism: `include_str!` embeds working-tree bytes verbatim, `core.autocrlf=true`\n...\n 2821|\n*2822|### IR-49 — poolguard's landed-lane predicate is ancestry-only, so a cherry-picked member lane can never read Settled and its pool can never be taken over\n 2823|- **Status:** open — filed 2026-08-19 (todlando measurement at the keystone-w1/fix-197 reap,\n 2824|  doyle ruling; doyle re-verified the predicate at source before filing) · **Origin:** todlando's\n 2825|  post-landing landed-check used the guard's own predicate and it contradicted the (correct)\n...\n 2855|\n*2856|### IR-50 — e2e failure panels read the PRE-REDIRECT stderr capture; every daemon-side diagnostic lands in a sink the rig deletes unread\n 2857|- **Status:** CLOSED — BUILT 2026-08-19; adoption-completion lane\n 2858|  `docs/ir50-register-close` @`e02f565f` (hertz, doyle-gated 2026-08-20) LANDED in\n 2859|  v0.59.0 as a PORTER rider (pick `e702d4b7` tip, main @`c62904e7`; register sweep\n...\n 2913|\n*2914|### IR-51 — engine-room e2e daemon runs NET-ENABLED on real interfaces; rig hermeticity is disk-deep only\n 2915|- **Status:** open — filed 2026-08-19 (todlando's x40 run-4 sink read, the first live read any\n 2916|  rig has had of the daemon sink; doyle ruled own-id rather than riding #199, at the finder's\n 2917|  own request) · **Origin:** unasked-for find inside the #199 instrument's first catch.\n...\n 2942|\n*2943|### IR-53 — failed-address expiry unit panics during the first 10m01s after Windows boot\n 2944|- **Status:** BUILT 2026-08-21 on `fix/ir53-cold-boot-instant` — LANDED in v0.59.0\n 2945|  (PORTER rider, pick `7b26f28d` on `assembly/porter-205`, main @`c62904e7`; register\n 2946|  sweep 2026-08-21 at release close) · **Origin:** todlando,\n...\n 2968|\n*2969|### IR-52 — docs-site CLI reference renders SHALLOW; help text below the rendered depth is outside the drift gate, unit-held per-REQ or held by nothing\n 2970|- **THIRD INSTANCE, observed 2026-08-24 (todlando, WAX-SEAL #21 W4; not acted on):** the new\n 2971|  `spt api seal verify|describe` FLAGS sit below the generator's rendered depth — the entry's\n 2972|  exact class. The W4 user page hand-documents them, which is per-page self-defense, not a\n...\n 3007|\n*3008|### CI-RIDER LANE STATE — LANDED 2026-08-04 (post-v0.53.0 merge queue); history below kept for its mechanisms\n 3009|- **RESOLVED:** the lane rebased clean onto the post-tag queue and landed ff-only as\n 3010|  `2b33a47`/`2a7b016`/`d63f4ce`/`19d7f79` (content byte-identical to `1275e47..bf8c4a2` by lane-diff\n 3011|  blob hash). IR-1 and IR-4 are BUILT AND LANDED; IR-9's measurement half is landed with its trigger\n...\n 3074|\n*3075|### IR-55 — the `spt --bins` suite wedges partway through on leaked `findstr .` PTY children; the tests at the frontier are casualties, not culprits\n 3076|\n 3077|- **Status:** OPEN, **ARMED-FOR-CAPTURE**, owned by **hertz**. Test/rig defect by the dispatch\n 3078|  split (test/CI rework is never the product builder's). Filed by doyle 2026-08-22 from the\n...\n 3200|\n*3201|### IR-56 — `pool-claim` harvests lane identity from CWD, not from `--pool`; a claim run from the wrong tree writes a WRONG RECORD with a success message\n 3202|\n 3203|- **Status:** BUILT 2026-08-24 for the SIGNET #218 golden batch on\n 3204|  `fix/ir56-pool-claim-cwd`, owned by **hertz**. Tooling/rig defect by the dispatch split. Filed by\n...\n 3247|\n*3248|### IR-57 — an assembly pick's conflict resolution can silently DROP lines, and every gate run at assembly time is blind to it\n 3249|\n 3250|- **Status:** OPEN, owned by **doyle** (gater craft, not a code defect — no lane to dispatch).\n 3251|  Filed 2026-08-22 from doyle's own defect on the TURNKEY #212 assembly head.\n...\n 3306|\n*3307|### IR-58 — a `[[bin]]` grep is not a census: cargo AUTODISCOVERS `src/bin/*.rs` targets, and a hand-built bin list produced a confident false \"this bin does not exist\"\n 3308|\n 3309|- **Status:** OPEN, unowned. Filed by doyle 2026-08-22; **its original filing was WRONG and is\n 3310|  retracted in full below.** The entry is kept because the way it was wrong is the finding.\n...\n 3341|\n*3342|### IR-59 — pool arithmetic: this box holds TWO cold pools, not four; and a build that exhausts the volume reds as a LINKER defect that names no disk\n 3343|\n 3344|- **Status:** OPEN, unowned — it is arithmetic and discipline, not a code lane. Filed by doyle\n 3345|  2026-08-22 from a live disk-floor abort during the TURNKEY #212 W4 gate; footprint figures measured\n...\n 3475|\n*3476|### IR-60 — a wrapper that CAPTURES a leg's exit status ends with the capture, so the wrapper's own status is the capture's, not the leg's\n 3477|\n 3478|- **Status:** OPEN, unowned — script-shape discipline, not a code lane. Filed by doyle 2026-08-22\n 3479|  during the TURNKEY #212 W5 lane; mechanism measured by todlando, who reported it first as a\n...\n 3524|\n*3525|### IR-61 — spacerun's test-module skip carries a SECOND literal tracker; the two answers can drift, and today only a cell stands between them\n 3526|\n 3527|- **Status:** OPEN, unowned, accepted-with-mitigation. Filed by doyle 2026-08-22 at the TURNKEY #212\n 3528|  head gate, as the named residual of the latch repair (the repair itself rides the milestone).\n...\n 3557|\n*3558|### IR-62 — an e2e daemon binds well-known ports and collides with the resident fleet on shared runners\n 3559|\n 3560|Filed 2026-08-23 (doyle), from the #212 r2 golden's Windows Phase A red — one witnessed\n 3561|instance, mechanism verified from the run's own capture, filed on the mechanism per the\n...\n 3598|\n*3599|### IR-63 — suite-mix sweeps leak job-escaped autostart daemons that LOCK the pool's spt.exe; and the same box conditions manufacture one random victim per sweep\n 3600|\n 3601|- **Status:** OPEN, mitigated-by-rig-step — the reap is adopted discipline, not yet construction.\n 3602|  Filed by doyle 2026-08-24 at the SIGNET #218 gates; first measured by todlando the same day\n...\n 3637|\n*3638|### IR-64 — HFENDULEAM's disk floor is set by non-CI bulk: ~845 GB of operator payload leaves the golden box ~2 GB of slack against its own 32 GB preflight\n 3639|\n 3640|- **Status:** OPEN · **Origin:** doyle, v0.63.0 close sweep 2026-08-26; mechanism first measured\n*3641|  at the FIELD-SEAL golden window (deployah's IR-31 fifth addendum carries the POOL side of the\n 3642|  same event by agreed division — this entry is the OTHER reservoir, deliberately not his).\n 3643|- **Mechanism:** the 1.86 TB C: carries ~614 GB Steam + ~230 GB Downloads (operator payload, not\n 3644|  CI state). With that floor fixed, normal lane traffic alone walks the box under the 32 GB\n 3645|  golden preflight — a full-sweep pool WEIGHS ~90–112 GB steady state (IR-59's measurement) and\n*3646|  five FIELD-SEAL lanes cost 148.48 GB (IR-31 fifth addendum), so ONE milestone's pools exceed\n 3647|  the entire free margin. Reaping buys windows, not headroom: deployah measured free fall\n 3648|  167 → 108 GB within hours of his reap, ~59 GB re-consumed by lane builds. The recurring shape:\n 3649|  every milestone pays a reap-and-measure tax to rent space the box does not structurally have.\n*3650|- **Why register-worthy rather than \"clean up more\":** agent-side discipline (IR-31's budgeting,\n 3651|  pool reaps, teardown steps) is already adopted and still only rents windows — the reservoir\n 3652|  that would durably move the floor is operator-owned bulk no agent may touch. Naming it here is\n 3653|  the boundary: agents keep budgeting IN POOLS (not GB); moving Steam/Downloads (or adding a\n...\n 3659|\n*3660|### IR-65 — kitsubito kernel-audit backpressure: a tailscale-snap AppArmor denial storm + no auditd turned the default audit backlog into a CI-wide stall amplifier (REMEDIATED AT BOX; re-check triggers named)\n 3661|\n 3662|- **Status:** REMEDIATED-AT-BOX 2026-08-25 (doyle, operator-authorized root — ruling pinned\n 3663|  releases#225 comment 5418800776); entry stays OPEN as the re-check record because the storm\n...\n 3685|\n*3686|### IR-66 — first-chunk-needle test class: two latent members remain after the v0.63.0 fix (attach.rs:561, :672)\n 3687|\n 3688|- **Status:** CLOSED / BUILT — release-close reconciliation 2026-09-11. The WEBSERVE JIT already\n 3689|  ruled this satisfied; source at `e5a2fed9` retains both delayed needles. Closure uses the\n...\n 3718|\n*3719|### IR-67 — wave-battery gap: a `-p spt --bins` leg compiles bin targets as harnesses and runs ZERO integration/e2e tests, so batteries that lean on it carry silent no-coverage legs\n 3720|\n 3721|- **Status:** BUILT — remedy applied across the IO-PARSER #22 milestone (2026-08-27/28): every\n 3722|  wave battery named explicit `-p spt --test <suite>` e2e legs beside the `--bins` unit leg\n...\n 3740|\n*3741|### IR-68 — PSYCHE_INGEST_FAIL cause class unproven: git index.lock did NOT reproduce the ingest failure it was blamed for\n 3742|\n 3743|- **Status:** OPEN, investigation-shaped · **Origin:** todlando measurement at the W2 int-leg rig\n 3744|  (IO-PARSER #22, PR #163 at `769fb0a9`, 2026-08-27), reported measure-first; filed by doyle.\n...\n 3768|\n*3769|### IR-69 — inherited stderr tokens can tear between format fragments; 26 test consumers parse that surface as structured truth\n 3770|\n 3771|- **Status:** OPEN for the #243 residual population and anchored-consumer work. The original\n 3772|  product remedy LANDED at `ec6da9b0`, as recorded in this entry's later amendment; it is not\n...\n 3860|\n*3861|### IR-70 — a hand-built `IoBus` silently omitted later sinks while every gate stayed green\n 3862|\n 3863|- **Status:** OPEN, remedy unscheduled; the v0.65.0 respin fixed the witnessed call site on PR #173.\n 3864|  This entry owns the recurrence class, not that shipped correction. · **Origin:** releases#234,\n...\n 3887|\n*3888|### IR-71 — controller-seat release has no persisted breadcrumb, so tests cannot distinguish propagation lag from a missing detach\n 3889|\n 3890|- **Status:** OPEN, observability gap; no remedy scheduled. · **Origin:** CONDUIT #236 r3\n 3891|  `er_brief_once_per_session_e2e` intermittent, classified test-side and fixed on PR #174.\n...\n 3911|\n*3912|### IR-72 — no product read verb surfaces which process holds a perch or controller seat\n 3913|\n 3914|- **Status:** OPEN, observability gap; no remedy scheduled. · **Origin:** CONDUIT #236 r3\n 3915|  two-host RCA and PR #174 (`70c1a303`), corrected by doyle after IR-18 and daemon-status were\n...\n 3945|\n*3946|### IR-73 — ci.yml and release.yml still read the free-space floor PRE-checkout (literal-first sites off the golden path); and any job's floor is stale by its last heavy step\n 3947|\n 3948|- **Status:** CLOSED / BUILT — source reconciliation 2026-09-11 at `e5a2fed9`: all five\n 3949|  `ci.yml` sites and all three `release.yml` sites now read after checkout, with IR-73 comments;\n...\n 3969|\n*3970|### IR-74 — kitsubito holds 21,643 /tmp endpoint homes: box-side accumulation nothing bounds or measures\n 3971|\n 3972|- **Status:** OPEN, filed by doyle 2026-08-30 at the #242/v0.66.0 close sweep; measurement by\n 3973|  hertz (2026-08-29). · **Origin:** rig work on kitsubito found `/tmp` carrying 21,643 endpoint\n 3974|  homes — per-run spt homes that outlive their runs.\n*3975|- **What/why:** sibling of the [[IR-31]]/[[IR-59]]/[[IR-64]] family (box accumulation the\n 3976|  preflights never see): each is small, the population is not, and /tmp on a long-lived box is\n 3977|  never reaped by CI. Un-reaped homes also widen every by-path census a rig runs. Needs a\n 3978|  bounded lifecycle (per-run temp root reaped at run end, or a box-side sweep with a stated\n...\n 3983|\n*3984|### IR-75 — traceable-reqs is not installed on kitsubito, so every Linux gate driver's treqs leg exits 127 (vacuous, wrapper-green shape)\n 3985|\n 3986|- **Status:** OPEN, filed by doyle 2026-08-30 at the #242/v0.66.0 close sweep (deployah\n 3987|  co-flagged at intake). · **Origin:** ASM-241 Linux battery — `ASM_treqs.exit` = 127, raw\n...\n 3998|\n*3999|### IR-76 — hfenduleam is the golden Windows runner AND the builders' box: a local workspace nextest fully contained a golden Phase A and manufactured a load-timing red, and the job-start census cannot see it\n 4000|\n 4001|- **Status:** OPEN, filed by doyle 2026-09-06 during v0.67.1 golden triage (run 34017906638\n 4002|  att2). · **Origin:** the Windows Phase A red on\n...\n 4042|\n*4043|### IR-77 — nothing stamps the interval between a daemon child's spawn and the brain's first log line, so a readiness-deadline red cannot say WHERE the time went\n 4044|\n 4045|- **Status:** OPEN, filed by hertz 2026-09-07 from the W1 #249 kitsubito battery at the gated\n 4046|  sha `8d980fdf`; doyle-ruled at filing to be a register entry rather than a lane rider. ·\n...\n 4074|\n*4075|### IR-78 — `SPT_TEST_EPHEMERAL_ADVISORY_PORTS` silently overrides an explicitly set `SPT_DOCS_PORT`\n 4076|\n 4077|- **Status:** OPEN, filed by hertz 2026-09-07, MEASURED by doyle the same night on his W2\n 4078|  field pair (both boxes). · **Origin:** the 5474 rig-hygiene sweep in\n...\n 4102|\n*4103|### IR-79 — 22 of the 31 rig binaries leak their daemon tree on a failing assert: teardown is a statement, not a guard\n 4104|\n 4105|- **Status:** OPEN, filed by hertz 2026-09-07 on doyle's dispatch during PR #198's CI window,\n 4106|  from todlando's red 6 (a stale same-port daemon from his own previous run answering the next\n...\n 4183|\n*4184|### IR-80 — five leaky cells on ONE module (`brainproc` / `supervise_brain`), Windows only: a candidate PRODUCT leak on the promotion/rollback path, or a cluster of names — nobody has looked yet\n 4185|\n 4186|- **Status:** OPEN for the residual population, not an undiagnosed five-name product claim.\n 4187|  Later amendments identify the brainproc shell-wrapper fixture mechanism and distinguish\n...\n 4251|\n*4252|#### THE LEAK SET IS NOISY — measured across three shas, 2026-09-07 (hertz)\n 4253|\n 4254|**This retracts the \"8 -> 5 leaky, direction favourable\" reading I flagged at 09:31Z.** It is not a\n 4255|fix and not an improvement; it is threshold noise, and the census this draft was built on inherits\n...\n 4280|\n*4281|#### Three consequences for this draft\n 4282|\n 4283|1. **A count is not a quality signal here, in either direction.** Any future \"leaky went down\"\n 4284|   claim needs the NAME diff and a causality check against the changed files, or it is noise\n...\n 4296|\n*4297|#### One structural finding the noise does NOT touch\n 4298|**All nine union members spawn a child and then kill it, let it time out, or inspect its corpse** —\n 4299|`trial_kills_alive`, `kill_waker_at`, `bounded_run_kills_on_timeout`, `extractor_timeout_errors`,\n 4300|`fetcher_timeout_errors`, `windows_session_is_zombie_sees_a_handle_held_corpse_as_dead`, and the\n...\n 4307|\n*4308|#### THE 12-CELL UNION — 4 shas x 2 OSes, membership beside the invariant (hertz, 2026-09-07 10:15Z)\n 4309|\n 4310|Machine-generated from the eight ci unit logs, not transcribed (a hand-typed 12x8 matrix is where\n 4311|transcription errors live). `X` = reported LEAK at that sha on that box.\n...\n 4330|\n*4331|#### Three readings, in increasing order of what they support\n 4332|\n 4333|**1. The churn is total and it is the whole point.** Windows counts run 8, 8, 5, 9 — the HIGHEST\n 4334|value is at `f3c8495b`, the tip carrying every fix F1-F16. Only **4 of 12** cells are present at\n...\n 4388|\n*4389|#### A MECHANISM, read out of the source of the two Linux cells — calibrated, not generalized\n 4390|`process_cmdline_reads_a_live_arg_marker` spawns **`sh -c \"sleep 30; : marker\"`**, and the test's\n 4391|own comment says the trailing `; :` is deliberate — it keeps the shell RESIDENT so its\n 4392|`/proc/<pid>/cmdline` still carries the marker instead of being tail-exec-replaced by `sleep`. The\n...\n 4417|\n*4418|#### AMENDMENT 1 — \"a pid is not a tree\" has THREE faces, and only one of them is a kill\n 4419|\n 4420|*(hertz 2026-09-07, ruled by doyle 11:17Z: write this as an IR-80 amendment naming the three faces\n 4421|rather than three separate entries, so a reader hunting any one face lands on all three.)*\n...\n 4465|\n*4466|### IR-81 — a process kill can be written scoped or machine-wide, and nothing makes the scoped form the only reachable one: both codebases carry the right pattern beside the wrong one\n 4467|\n 4468|- **Status:** OPEN, drafted by hertz 2026-09-07 08:38Z on doyle's dispatch (08:36Z), from the\n 4469|  fleet-daemon death on hfenduleam at 08:03:15Z ([[RCA-FLEET-DAEMON-14444]], cause still UNNAMED).\n...\n 4530|\n*4531|#### ADAPTER-SIDE ARM: CLOSED (claude-spt, perri, 2026-09-07)\n 4532|\n 4533|**Status: closed in the consumer repo, test-only, does not close IR-81 here.**\n 4534|\n...\n 4559|\n*4560|#### SCOPING ARM (a) — the product path has no intermediary; the fixture does\n 4561|*(hertz 2026-09-07, ruled by doyle 10:22Z off the IR-80 leak work.)*\n 4562|\n 4563|> **A pid is not an identity and a pid is not a tree. IR-80 needs CALLERS, not code.**\n...\n 4590|\n*4591|### IR-82 — a daemon death leaves NO record of who died: autostart decides on a socket ping, says \"no daemon\", and the successor overwrites the only handle on the corpse\n 4592|\n 4593|- **Status:** RULED 2026-09-07 11:07Z (doyle), drafted by hertz 11:04Z on doyle's dispatch (11:03Z: *\"the autostart\n 4594|  death-cause item is an IR, not a board item — mint it IR-82 in your thin PR\"*). Register on main\n...\n 4696|\n*4697|### IR-83 — a two-host rig addressed over the tailnet cannot receive INBOUND on Windows, and the whole rig population had only ever run the admitted direction\n 4698|\n 4699|- **Status:** OPEN, minted by hertz 2026-09-07 11:41Z on doyle's dispatch (11:40Z). **Provenance: the\n 4700|  mechanism below is DOYLE'S measurement, not mine** — eight probe arms, each with sender, listener\n...\n 4833|\n*4834|### IR-84 — the one `PUMP_PEER_FAIL` arm the rigs actually fire was the only one carrying no clock, so the stall that produced it could be counted but never timed\n 4835|\n 4836|- **Status:** OPEN, filed by hertz 2026-09-09 with the instrument that closes its first half. ·\n 4837|  **Origin:** the 65 s two-host helper stall (design written before the run,\n...\n 4883|  stamps, so the fifth site added cannot be born silent.\n*4884|### IR-85 — the Windows self-hosted box runs its fs-heavy tests 3-4x slower than a week ago; two CI wall clocks were sized for the old box, and a red run kept hiding it\n 4885|\n 4886|- **Status:** OPEN, filed by hertz 2026-09-09 at the #272/v0.68.0 golden r3/r4 arc, on doyle's\n 4887|  dispatch. Number ruled by doyle from his own census of main@`a2f335f8` (register ended at IR-83;\n...\n 5043|\n*5044|### IR-86 — golden's 32 GiB floor is BELOW the measured 67.4 GiB Windows suite footprint, so a start floor passes a box that cannot finish\n 5045|\n 5046|- **Status:** OPEN, filed by doyle 2026-09-08 at the #272/v0.68.0 golden r2 triage. · **Origin:**\n 5047|  run 34262154550 @ `25e60015` (shaped on `e4444413`), Windows test job 102182665033: every product\n...\n 5092|\n*5093|### IR-87 — two-host ceremony halves are INDEPENDENT jobs on DIFFERENT runners (A Windows/hfenduleam, B Linux/kitsubito); B's 900 s budget runs on B's own clock, so any older queued Windows job starves A and reds B deterministically, and the panic text blames pairing\n 5094|\n 5095|- **Status:** OPEN, filed by doyle 2026-09-08 at the #272 golden r2 triage. · **Origin:**\n 5096|  run 34262154550, twohost-b job 102207296960 (log 81,692 B, sha256 67403f04…8030): role B built,\n...\n 5145|\n*5146|### IR-88 — `pool-release` via `cargo run -p xtask` REBUILDS xtask INTO the pool it is releasing, so a reaped pool regrows ~2.8 GB in silence\n 5147|\n 5148|- **Status:** OPEN, filed by doyle 2026-09-08 from hertz's reap report (20:00Z) during the #272\n 5149|  golden r2 repair. · **Origin:** hertz reaped hertz-lane4 / hertz-repin / hertz-percell-id target\n...\n 5169|  rather than merely proposed.\n*5170|- **Kin:** [[IR-31]] (pool budgeting), [[IR-56]] (pool-claim identity from CWD — same verb\n 5171|  family, same \"the tool acts on where it stands\" shape), releases#103.\n 5172|- **Ripe when:** next xtask pool-verb touch or the teardown runbook edit. · **Size:** tiny —\n 5173|  one guard or one doc line.\n...\n 5182|\n*5183|### IR-89 — hfenduleam's Windows Firewall drops cold inbound UDP to the runner-built test exes, so the two-host rig's first B→A claim (W2 helper) reds for its whole 900 s budget and the panic blames A\n 5184|\n 5185|- **Status:** BOX HALF **APPLIED** 2026-09-08; WORKFLOW HALF **BUILT** 2026-09-09 — PR #211\n 5186|  (`9b96d7e7` + this amendment), **LANDED, exact golden-step acceptance unreconciled**.\n...\n 5338|\n*5339|### IR-90 — a full disk on the self-hosted box reds a rig as a PRODUCT refusal, not a build error, and no rig or gate records the free space that would falsify it\n 5340|\n 5341|- **Status:** OPEN, filed by hertz 2026-09-09 from the disk-full incident on hfenduleam. ·\n 5342|  **Origin:** the IR-85 discriminator lane's head arm, killed by the volume rather than by the code\n...\n 5427|\n*5428|### IR-91 — 561 untracked files sat at the repo root, 18 of them cited by tracked files, and the census that classified them used a corpus that made the discriminator invisible\n 5429|\n 5430|- **Status:** CLOSED by the lane that filed it (the root-scratch classify PR), hertz 2026-09-09 on\n 5431|  doyle's census and rulings. · **Origin:** the `.spt/` ignore lane (PR #212) named 561 untracked\n...\n 5481|\n*5482|### IR-92 — the message that WAKES an idle spt-hosted endpoint rides a delivery leg that never publishes MSG_IN, so a woken agent's own funnel holds none of the messages that woke it\n 5483|\n 5484|- **Status:** OPEN — filed doyle 2026-09-09 from hertz's census, probe and proposed text (his by\n 5485|  role; the recorder read and the REQ reading are doyle's). Fix lane unassigned: product change in\n...\n 5613|\n*5614|### IR-93 — no PDB ships beside the installed `spt` binary, so the one non-invasive read of a wedged production daemon comes back without a single named frame\n 5615|\n 5616|- **Status:** OPEN, filed by doyle 2026-09-10. **The number was reserved by NAME on 2026-09-09** at\n 5617|  the #293 mechanism read (\"PDB ask -> IR-93 at next sweep\") and this entry closes that claim — a\n...\n 5642|\n*5643|### IR-94 — xtask's brainread deadline gate cannot SEE `serve_sync`: its registry is three hand-listed files and its predicate is a name shape, so a stream server outside both got the reply form and the gate stayed green\n 5644|\n 5645|- **Status:** OPEN, filed by doyle 2026-09-10 at the releases#294 / v0.69.0 golden RED triage. **This\n 5646|  is an INDEPENDENT gate finding, not the cause of that red** — it was found while reading the\n...\n 5672|\n*5673|### IR-95 — a burned polling budget names WHAT it wanted and never HOW LONG it waited, so no run, green or red, can say how close it came\n 5674|\n 5675|- **Status:** OPEN, filed by doyle 2026-09-10 at the releases#294 golden RED, where it cost this\n 5676|  triage most of a morning and four agents. · **Origin:** the two Windows Phase A failures at\n...\n 5927|\n*5928|### IR-96 — the `daemon_stop_convoy_e2e` API-storm cell fails 3-of-3 under the HEAVY suite at the diagnostic tree while passing at the candidate in golden CI, and nothing yet separates instrumentation from box from product\n 5929|\n 5930|- **Status:** OPEN, **cause-unclassified** (todlando's and hertz's stipulation, adopted verbatim — a\n 5931|  triage placement here is NOT a finding of non-defect).\n...\n 5963|\n*5964|### IR-97 — a suite that leaks a fixed cohort of child processes per invocation makes consecutive runs non-comparable, and the between-run accounting the protocol required was not enforced\n 5965|\n 5966|- **Status:** OPEN. **Protocol deviation** (hertz's framing, and it is stronger than \"confounder\":\n 5967|  the protocol ALREADY required between-run accounting — execution did not enforce it, so the fix is\n...\n 6006|\n*6007|### IR-98 — a lane driver that PRINTS a producer's output can die on an unencodable byte AFTER that producer's evidence is on disk, so the run ends with complete evidence for producer N and NO files for N+1 — an absence that reads as \"never queued\", not as a failure\n 6008|\n 6009|- **Status:** OPEN as a mechanism; the measured instance is FIXED in hertz's lane driver (UTF-8 with\n 6010|  replacement reconfigured at import, positive control run before relaunch: U+2500 and U+2713\n...\n 6030|\n*6031|### IR-99 — EOF and terminal retire on a ConnectionBound net stream arm on the OPENER CONN's exit; a same-morning diagnosis built on that mechanism was refuted by the compiler, so the mechanism stands and the two #304 reds beside it stay open\n 6032|","truncated":true,"truncatedBy":"bytes","totalLines":1015,"totalBytes":80067,"outputLines":785,"outputBytes":51162,"lastLinePartial":false,"firstLineExceedsLimit":false},"meta":{"truncation":{"direction":"head","truncatedBy":"bytes","totalLines":1015,"totalBytes":80067,"outputLines":785,"outputBytes":51162,"shownRange":{"start":1,"end":785},"nextOffset":786}}},"isError":false,"timestamp":1789483654537}}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_m9o3FQKCla1Q5DmMk3tmPY51|fc_043a862a419f59ae016aa95a8e357087d2b281605f6fa5e076","toolName":"read","startedAt":"2026-09-15T14:47:42.286Z","args":{"path":".worktrees/hertz-ir86-disk-delta/docs/INFRA-REGISTER.md:1-870"},"intent":"Reading early entries and amendments"},"id":"36a637d4","parentId":"58816e81","timestamp":"2026-09-15T14:47:42.286Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_Q1kHvbr3Nsv06kk7jIhSDLjA|fc_043a862a419f59ae016aa95a8e358087d28f94b0c4ae7a2a6e","toolName":"read","startedAt":"2026-09-15T14:47:42.286Z","args":{"path":".worktrees/hertz-ir86-disk-delta/docs/INFRA-REGISTER.md:870-1805"},"intent":"Reading middle early register"},"id":"a6f2ed55","parentId":"36a637d4","timestamp":"2026-09-15T14:47:42.286Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_uB27JN6f8evDHc07zmWmYD5i|fc_043a862a419f59ae016aa95a8e358887d29dd56a5a2d698b9f","toolName":"read","startedAt":"2026-09-15T14:47:42.286Z","args":{"path":".worktrees/hertz-ir86-disk-delta/docs/INFRA-REGISTER.md:1806-2706"},"intent":"Reading irregular entry population"},"id":"2a9cea08","parentId":"a6f2ed55","timestamp":"2026-09-15T14:47:42.286Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_jiuAqmEJNWoxC6RAbwlv4MnL|fc_043a862a419f59ae016aa95a8e359087d2bf3df1ec9c0d5c20","toolName":"read","startedAt":"2026-09-15T14:47:42.287Z","args":{"path":".worktrees/hertz-ir86-disk-delta/docs/INFRA-REGISTER.md:2707-3887"},"intent":"Reading later assigned entries"},"id":"5ae603c1","parentId":"2a9cea08","timestamp":"2026-09-15T14:47:42.287Z"}
{"type":"message","id":"6394c1d7","parentId":"5ae603c1","timestamp":"2026-09-15T14:47:42.287Z","message":{"role":"assistant","content":[{"type":"toolCall","id":"call_m9o3FQKCla1Q5DmMk3tmPY51|fc_043a862a419f59ae016aa95a8e357087d2b281605f6fa5e076","name":"read","arguments":{"i":"Reading early entries and amendments","path":".worktrees/hertz-ir86-disk-delta/docs/INFRA-REGISTER.md:1-870"},"intent":"Reading early entries and amendments"},{"type":"toolCall","id":"call_Q1kHvbr3Nsv06kk7jIhSDLjA|fc_043a862a419f59ae016aa95a8e358087d28f94b0c4ae7a2a6e","name":"read","arguments":{"i":"Reading middle early register","path":".worktrees/hertz-ir86-disk-delta/docs/INFRA-REGISTER.md:870-1805"},"intent":"Reading middle early register"},{"type":"toolCall","id":"call_uB27JN6f8evDHc07zmWmYD5i|fc_043a862a419f59ae016aa95a8e358887d29dd56a5a2d698b9f","name":"read","arguments":{"i":"Reading irregular entry population","path":".worktrees/hertz-ir86-disk-delta/docs/INFRA-REGISTER.md:1806-2706"},"intent":"Reading irregular entry population"},{"type":"toolCall","id":"call_jiuAqmEJNWoxC6RAbwlv4MnL|fc_043a862a419f59ae016aa95a8e359087d2bf3df1ec9c0d5c20","name":"read","arguments":{"i":"Reading later assigned entries","path":".worktrees/hertz-ir86-disk-delta/docs/INFRA-REGISTER.md:2707-3887"},"intent":"Reading later assigned entries"}],"api":"openai-codex-responses","provider":"openai-codex","model":"gpt-6-astra","usage":{"input":15692,"output":190,"cacheRead":9984,"cacheWrite":0,"totalTokens":25866,"cost":{"input":0.15692,"output":0.0095,"cacheRead":0.009984,"cacheWrite":0,"total":0.176404}},"stopReason":"toolUse","timestamp":1789483654568,"responseId":"resp_043a862a419f59ae016aa95a86e2b087d28e1a4aa59be0f7f6","providerPayload":{"type":"openaiResponsesHistory","provider":"openai-codex","dt":true,"items":[{"id":"fc_043a862a419f59ae016aa95a8e357087d2b281605f6fa5e076","type":"function_call","status":"completed","arguments":"{\"i\":\"Reading early entries and amendments\",\"path\":\".worktrees/hertz-ir86-disk-delta/docs/INFRA-REGISTER.md:1-870\"}","call_id":"call_m9o3FQKCla1Q5DmMk3tmPY51","internal_chat_message_metadata_passthrough":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"},"name":"read","metadata":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"}},{"id":"fc_043a862a419f59ae016aa95a8e358087d28f94b0c4ae7a2a6e","type":"function_call","status":"completed","arguments":"{\"i\":\"Reading middle early register\",\"path\":\".worktrees/hertz-ir86-disk-delta/docs/INFRA-REGISTER.md:870-1805\"}","call_id":"call_Q1kHvbr3Nsv06kk7jIhSDLjA","internal_chat_message_metadata_passthrough":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"},"name":"read","metadata":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"}},{"id":"fc_043a862a419f59ae016aa95a8e358887d29dd56a5a2d698b9f","type":"function_call","status":"completed","arguments":"{\"i\":\"Reading irregular entry population\",\"path\":\".worktrees/hertz-ir86-disk-delta/docs/INFRA-REGISTER.md:1806-2706\"}","call_id":"call_uB27JN6f8evDHc07zmWmYD5i","internal_chat_message_metadata_passthrough":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"},"name":"read","metadata":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"}},{"id":"fc_043a862a419f59ae016aa95a8e359087d2bf3df1ec9c0d5c20","type":"function_call","status":"completed","arguments":"{\"i\":\"Reading later assigned entries\",\"path\":\".worktrees/hertz-ir86-disk-delta/docs/INFRA-REGISTER.md:2707-3887\"}","call_id":"call_jiuAqmEJNWoxC6RAbwlv4MnL","internal_chat_message_metadata_passthrough":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"},"name":"read","metadata":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"}}]},"duration":7716.364299982786,"ttft":7666.190200001001,"completedAt":1789483662285,"contextSnapshot":{"promptTokens":25676,"nonMessageTokens":10342,"compactionEpoch":0}}}
{"type":"message","id":"70e99837","parentId":"6394c1d7","timestamp":"2026-09-15T14:47:42.369Z","message":{"role":"toolResult","toolCallId":"call_m9o3FQKCla1Q5DmMk3tmPY51|fc_043a862a419f59ae016aa95a8e357087d2b281605f6fa5e076","toolName":"read","content":[{"type":"text","text":"# Infra register — CI / build-pipeline debt\n\nOperator-ruled 2026-08-02: infrastructure and CI-pipeline work items live HERE, not on the\n`spt-bs-releases` board. The board carries product surface the operator triages; this register\ncarries what the gater triages. **Mandate: doyle sweeps this file at every milestone intake and\nevery release close, and composes ripe entries into waves/milestone riders.** An entry leaves\nthis file only by being built (link the lane) or being retired with a stated reason.\n\nEntry format: status · origin · what/why · trigger condition (what makes it ripe) · size guess.\n\nLast sweep: **2026-09-11, v0.69.0 RELEASE CLOSE — FULL REGISTER**, source `e5a2fed9`.\nAll **97 entries (IR-1–97, including headingless IR-31)** read in two disjoint ranges; audit\npopulation checked for missing/duplicate IDs (97 rows, 97 unique, zero missing). Per-entry\ntrigger and disposition evidence: `.spt/preserved/infra-close069-20260911/audit.json`.\nUNKNOWN means no qualifying event established, not a disproved trigger or a discharged debt.\n\n- **Release facts, not a blanket green:** v0.69.0 at `16df0e41`, counter **105**, Latest,\n  11 assets; #294 and all eight members DONE. Explicit operator SHIP overrode the known\n  sync-cell red at candidate `a9e786b2`; the release neither classifies nor closes that defect.\n  Source closeout: releases#294 comment **5628538587**. The scoped four-package `--lib` battery\n  passed **121/121**; push CI **34550282074** passed **3167 Windows units**, then failed the\n  END disk floor (**15,360,114,688 < 34,359,738,368 bytes**). Release build **34550300527**\n  succeeded. Earlier PR unit-red logs remain unavailable/cause-unclassified. These are separate\n  verdict objects; no pass substitutes for a red, missing specimen, or unexecuted acceptance.\n- **Close already-built work, retain residuals:** IR-1/4 stale unlanded headers reconciled to\n  their landed rider and recorded golden exercise. IR-66 CLOSED using its existing two-platform\n  gates and WEBSERVE satisfaction ruling. IR-73 CLOSED: eight post-checkout sites plus both\n  docs-floor rereads are present; IR-86 retains sizing/dependency debt. Other established\n  BUILT/RETIRED decisions stand. IR-18's deferred consolidation and IR-53/62's narrower\n  touch-triggered siblings remain carried; closing their built halves does not erase those.\n- **Do not redispatch existing implementations:** IR-26 build-side identity is committed,\n  but claim-time observation and old-reader issues remain; IR-29's first fix landed, later\n  rung faces remain; IR-33's 16 MiB CLI stack exists, acceptance/margin reconciliation remains.\n  IR-57 `pick-audit`, IR-59 `disk-floor`, and IR-46 workflow floor tokens exist; residual adoption\n  and receipt reconciliation are the work. IR-69's original product lane landed; #243 residuals\n  remain. IR-83's universal LAN-only prescription is superseded by IR-89's layer-specific box\n  proof. IR-89's next-golden trigger has fired; exact step acceptance still needs reconciliation,\n  not a second guard implementation or renewed operator permission.\n- **IR-92 stays OPEN:** core#215 shipped the documentation/register rider, NOT the product\n  remedy; core#217 is the separate brainread audit. `try_spt_hosted_inject` still lacks the\n  MSG_IN publisher. Deployah corrected comment **5628532753** in place and confirmed readback.\n  Inject coverage, relay publication ordering and per-msg-id exact-once are distinct obligations.\n- **Next-intake composition, owned by doyle until accepted:** hertz's driver/workflow package\n  takes IR-31/46/59/60/76/86/87/90/97: aggregate capacity, truthful producer status, existing\n  quiet-window contract, independent rendezvous clocks, and mandatory between-run identity\n  census. IR-88 adopts the already-proven prebuilt release-before-delete recipe; IR-64 remains\n  a separate operator capacity decision. No new loaded comparison before these prerequisites.\n  Hertz's lifecycle package retains IR-7/17/20/22/25/34/35/55/63/79/80; guard adoption must\n  distinguish unwinding from hard process death. IR-74/75 ride the next Linux box audit.\n  IR-85/95/96 are scoped diagnostic continuation, NOT budget widening or a load/disk diagnosis.\n  Todlando owns product-side IR-81/82/92 composition; #285's completion did not build IR-82's\n  predecessor record. Both builders are offline: existing briefs are delivered, unacknowledged,\n  and **not executing**. No board mutation or new run authorization is implied.\n- **Small seam riders remain explicit:** next tooling intake weighs IR-5/6/10/11/32/37/47/58/94\n  (IR-37 upstream release is not downstream adoption: golden still requests 0.2.0).\n  IR-93 remains a separate symbol-packaging decision before a release-workflow rider, not a\n  property proven by a successful release build. All other open entries retain their recorded\n  trigger, residual, and owner where named; the complete audit records each, not a sampled set.\n- **Cleanup is mitigation, not closure:** 38 clean merged worktrees and classified obsolete\n  artifacts removed; dirty/unmerged/retained evidence preserved. Net free-space change\n  **4,532,350,976 bytes**, ending **83,382,472,704 bytes** (concurrent-activity caveat).\n  `.spt/cleanup-20260911.json` is the receipt. Root-target and CI-debug reclaims are separate\n  earlier measurements, not additions to that net. IR-14/26/27/49 remain structurally OPEN.\n\n### Intake addendum — hosted-relay diagnostic capacity hold (2026-09-11)\n\nSourced C: free samples around the intake, each named by file: **19,260,395,520 bytes at\n03:02:33Z** (post-merge run 34556292801, unit job `FLOOR_END`, RED against the\n34,359,738,368-byte floor); **19,907,792,896 bytes at 07:09:57Z**\n(`.spt/preserved/todlando-pool-reclaim-20260911/before.json`); **191,756,984,320 bytes** after\ndeployah's three authorized target reclaims (`.spt/preserved/deployah-rca-reclaim-20260911/reap-results.json`:\nrca-base +11,461,189,632, rca-head +11,371,200,512, gate-293c +94,256,648,192 observed);\n**247,894,224,896 bytes at 08:39:20Z** (hertz, GetDiskFreeSpaceExW, during post-merge run\n34580045779). An earlier draft of this addendum attributed a 19,979,182,080-byte 07:00Z sample\nto hertz; hertz could not point at a file for it and the figure is withdrawn. Every sample is an\ninstant, not headroom (IR-46).\n\nRunner-target behaviour, inferred from three samples and not yet read from the workflow: the\nunit job went 83,420,217,344 -> 19,278,598,144 (run 34555345283) and 83,368,599,552 ->\n19,260,395,520 (run 34556292801) inside the job, and the runner's own target measured\n65,260,456,302 bytes at rest at 07:57Z (`remote-friction-304/capacity-ci-target.json`), so the\nrunner appears to purge and cold-rebuild its resident target per run. A post-merge run therefore\nadds no growth beyond that resident ~65 GB, and both reds above are resource reds on a box that\nsat at ~19 GB free from 03:02Z to 07:10Z: untested, not failed.\nThird sample, post-merge run 34580045779 on `b12d4619` (GREEN): `FLOOR_START` 249,872,142,336 at\n08:37:27Z, `FLOOR_END` 181,632,450,560 at 08:49:04Z — a 68.2 GB in-job drop while two #304 lanes\nwere also building (todlando's pool reached 4.26 GB in that window), consistent with the\npurge-and-rebuild inference and still not read from the workflow.\n\nThe 293-brain pool was deleted at 07:10:59Z with a receipt (+10,916,200,448 bytes observed, same\ndirectory as the sample above). The receipt does not record the executor; todlando's ledger says\nit was not him, and no executor is asserted here without a file.\n\nNo diagnostic fixture daemon/listener or fresh build for the hosted-relay experiment has started.\nThe isolated hosted-relay experiment is separate from #304 implementation and from the #294\ncause investigation. Carry its capacity planning under **IR-31/59/90**, not a new product\nrequest. Hertz owns identifying the minimum diagnostic target, reusable version-matched\nartifacts, estimated incremental build/temp footprint and the concrete socket/network isolation\ngap. Doyle owns matching that requirement to an owned pool and available capacity before\nauthorizing a build. A prebuilt-only route still needs isolation proof; a private home alone\ndoes not establish it. No unowned artifact deletion or live-daemon changes are authorized.\nControl, relay-replacement and mixed-version arms remain unexecuted.\n\nPrior sweep: 2026-09-06, v0.67.1 RELEASE CLOSE + WEBSERVE (#272) INTAKE (one delta pass; the 08-30\nfull pass stands) — shipped counter 103, tag == main == tested `04e32c8c`, golden 34017906638 att4\n9/9 on a QUIET box after three reds (:473 attach_link structural test defect; wtlock :147 under\nbuilder load; resident_service_e2e :664 ledgered leak row, 3rd occurrence) — the quiet-box arm is\nIR-76's origin. Enumeration by a read-only subagent into `REGISTER-SWEEP-0671-DRAFT.md` (75\nentries, 10 trigger-text candidates; IR-31 has NO `###` heading — its body sits under IR-30's,\nflagged, not normalized). Rulings: **IR-46 trigger FIRED and was MISSED** — `golden.yml` was\ntouched by `04e32c8c` itself (2-line HEAVY reclass on the respin) and no remedy was weighed; a\nrespin edit under a pre-registered hard stop is not a remedy window, so the entry gains that datum\nand is COMPOSED forward. **Composed: the floor trio IR-46 + IR-59 (log-the-floor half) + IR-73\n(8 literal-first sites) as ONE hertz workflow rider on WEBSERVE** (`ci.yml`/`golden.yml`/\n`release.yml`, thin PR off the golden path, before the WEBSERVE golden head so that head runs\nunder it); **IR-59's log-the-floor line ALSO rides IR-76's three-arm pre-flight on W0's driver\ntemplate** (todlando authors; free space recorded beside the floor check). **IR-66 residual (two\nfirst-chunk-needle members) = hertz WEBSERVE test rider** (two one-line edits). **IR-12 residual =\nW3 drift-gate rider** (hertz already holds W3's drift-gate riders). IR-67 satisfied at this intake\nby construction (`--no-fail-fast` in the W0 driver template; todlando's 2026-09-06 correction).\nIR-34 unchanged, lane-linked to hertz's `test/attach-relink-barrier` @`b976cc09` (thin PR queued\nbehind the release runs). NOT fired: IR-3 (a new stream family is neither endpoint lifecycle nor\ndaemon supervision), IR-48, IR-52 (DOCS-NITS item 2 is a parent-option placement filing, not a\ndeep-help divergence — adjacent, noted), IR-64 (att4 did not die at preflight; no operator ruling).\nBoard mints this arc: #277 (io-events seq reset), #278 (adapter update never prunes strings/),\n#279 (ER_HOSTED_PROBE on every bind), #280 (MSG_IN never published on the relay edge). Design\nrulings on the grill branch: ADR-0056 Am.1 (router precedence), ADR-0057 Am.1 (served root =\n`adapters/<adapter>/web/`), ADR-0058 Am.1 (#17 auto-serve, reference-served). No entries retired.\n\nPrior sweep: 2026-08-30, NOW-SIGNAL (#23) / v0.67.0 RELEASE CLOSE — shipped counter 102, tag ==\nmain-at-tag == tested `da71b785`, 9/9 golden att2 (att1 sole red = FLAKE-LEDGER :664\nteardown-leak row, ruled ledgered-class at triage — signature predates the diff — rerun\nnon-vacuity proven by cell re-execution; ledger row +1 with new data, stays OPEN; hertz\nIR-34/35 cluster strengthened). Same-day second sweep, so most composition state is the\nmorning's; deltas only: IR-59 gained the SEVENTH face (parallel-lane fill rate: 236.6 GB /\n3.5 h across four wave pools drove the box to 0.01 GB mid-close; per-wave pool reaping rule).\nIR-12 gained the stale-binary kin note (xtask reference-drift arm reads the ON-DISK spt binary;\nstructural remedy = the now-mandatory workspace-bins prebuild leg, adopted this arc after it\nalso caught W2's spacerun red). IR-63's conhost litter REPRODUCED on cue: 14 fresh CWD pins on\nthe four party trees at the same `crates/spt-daemon` relative path, killed by pid via the PEB\nprobe, all four worktrees then removed FIRST TRY — the pin-check-first party rule held\n(+58.2 GB; earlier emergency reap of the same wave's finished-lane targets +186.6 GB).\nTest-craft banked to memory, not entries: `cargo test -- <bare> --exact` runs NOTHING and exits\n0 (todlando's structural fix: names carry the filter token); Win32_Process CommandLine filters\nCANNOT answer a CWD-pin question (todlando's false-positive self-catch). Board mints this arc:\n#244/#246/#247/#254 (BACKLOG). #16/#17 discharged drops (detach + EVAL). IR-73's ci.yml/\nrelease.yml floor-site reorders did NOT ride this arc's workflow commits — still owed, next\ntouch. No entries retired.\n\nPrior sweep: 2026-08-30, SEMAPHORE (#242) / v0.66.0 RELEASE CLOSE — shipped counter 101, tag ==\nmain == tested `d931dd63`, 9/9 at one sha across two attempts; full-register pass executed from\n`REGISTER-SWEEP-242-DRAFT.md` (72 entries enumerated pre-golden, load-bearing claims re-measured\nin-tree). Rulings: IR-69 close-out re-census RAN and FOUND the entry's own predicted truncation\nblind spot LIVE (338 cli.rs + 2 main.rs shipping sites never censused; addendum on the entry,\nstays OPEN; residual conversion + generator fix + seam enforcement = releases#243, scoping\nreconciled on the issue; common-word matcher RULED a separate hertz test-side rider). IR-17\nthree corrections by replacement (08-03 kitsubito \"empty stderr\" = METER ARTIFACT — panel\ncapture postdates the specimen by 16 days; kitsubito family member CLOSED under the RCA-242\nexe-hash-on-ready-path mechanism, behaviour-change request minted as releases#244; Windows\nspecimen + hfenduleam sub-observation stay the live population). Daemon-leak cluster\nIR-7/17/20/34/35/63 LANE-LINKED to hertz's queued fixup lane (briefs in his spool cite the entry\nids). IR-57 first-real-assembly use appended (ASM-241: 6 picks, 5 MATCH / 1 LOSS reconciled\nbyte-for-byte to the deliberate resolution; its earlier \"figure correction rides next batch\"\nnote was STALE — the correction landed inline 2026-08-29, retired here). IR-46 gained the #242\ngolden additions (per-job floor instants; the `/runs/<id>/jobs` run_attempt trap with\n`started_at` discriminator + `/attempts/N/jobs` authority; raw-bytes rerun preflight;\nnon-vacuous rerun check). IR-59 gained the SIXTH face (r4 LNK1318 at the job's internal\nlow-water; within-job floor re-read rides the next workflow commit; box ~51 GB non-recovering\nconsumption → audit slot). FILED: IR-73 (ci.yml/release.yml literal-first floor sites off the\ngolden path, 8 sites), IR-74 (kitsubito 21,643 /tmp endpoint homes, hertz's measurement), IR-75\n(kitsubito treqs 127 vacuous leg — install-or-drop; IR-37 deliberately NOT reopened, different\nsurface). Composed: IR-14/26/27/49 as ONE between-milestone pool/worktree audit slot (window\nopen now); IR-11 + IR-33(a) as next-intake small riders; IR-59's log-the-floor half + IR-57's\nscripted audit stand as the next intake's tooling pair. IR-54 evidence noted: the #242 cut's\nunshaped-head intake miss (self-caught by deployah, shape-on-top `e4f52047`, 8th consecutive\nshape-inside-candidate) is another construction-not-discipline datum. No entries retired.\n\nPrior sweep: 2026-08-27, IO-PARSER (#22) INTAKE (wave map: `IO-PARSER-22-JIT.md` + #22 comment).\nRulings: IR-66 COMPOSED as the parallel hertz rider (the two attach-cell later-needle treatments,\nattach.rs:561/:672 — the \"rides next intake\" note comes due here). IR-52 conditional rider\nCARRIED FORWARD on this milestone's docs lane, same terms as WAX-SEAL (depth fix lands iff the\nlane touches the docs-site CLI reference generator, else stays open). IR-67 COMPOSED as JIT gate\ndiscipline (no wave battery leans on a `-p spt --bins` leg as integration coverage); the entry\nstays open until its named construction fix. IR-55 stays armed with hertz; IR-6 LOCKSMITH\ncomposition still unreported, stays; IR-2 trigger unevaluated this sweep (teardown just cleared\nthe unlanded-lane field — re-check next sweep). No entries retired; none filed.\n\nPrior sweep: 2026-08-23, WAX-SEAL (#21) INTAKE (wave map: `WAX-SEAL-21-JIT.md` + #21 comment\n5390092115). Rulings: IR-52 COMPOSED as a CONDITIONAL W4 rider on the wax-seal docs lane —\nthe milestone mints new nested `spt seal` CLI verbs, exactly the shallow-render class the entry\nnames; the depth fix lands iff that lane touches the docs-site CLI reference generator, else the\nentry stays open here. IR-2 trigger NOT met (todlando's PR set parked unlanded for the next\ngolden chain). IR-55 stays ARMED-FOR-CAPTURE with hertz. IR-6 conditional composition from\nLOCKSMITH still unreported — stays open. IR-56/57/58/59/60/61 are discipline/craft entries or\nawait their named triggers; IR-62 is hertz-class test/rig work, unscheduled. No entries retired;\nnone filed.\n\nPrior sweep: 2026-08-19, CONCIERGE (#183) INTAKE (wave map: `CONCIERGE-183-JIT.md` + #183\ncomment 5347768797) — rows read from the LOCAL register stack (`4799031→ecd640c→8d4c224`;\norigin/main lacks IR-49/50/51 until the chain lands — absence ≠ not-filed). Rulings: IR-50\nCOMPOSED — dispatched to hertz same day (sink-path-helper-FIRST sequencing per the entry;\n`engine_room_bringup_e2e.rs` excluded, its panel sites ride the gated #199 lane), with the\nengineroom.rs:145 misnomer as a rider on the same lane. IR-47 = candidate co-rider IF this\nchain touches golden.yml/ci-notify, else holds. IR-48 holds (next xtask parity-cell touch).\nIR-49 holds (next poolguard touch or first landed-lane takeover request). IR-51 holds —\ngated on #199 attribution; a net-off fix must NOT precede attribution. IR-2 trigger NOT met\n(queued unlanded lanes exist). No entries retired; none filed — the intake window's product\nfinding (rc terminal-Exit omission, hertz RCA: proven invariant violation, load excluded\n92/92, H2 candidate unconfirmed) routed to the BOARD as releases#201, the correct venue for\nproduct surface.\n\nPrior sweep: 2026-08-18, KEYSTONE (#182) INTAKE — the prior sweep's four composition rulings\nEXECUTED (wave map: `KEYSTONE-182-JIT.md`, base main @`8248bc3`): (1) IR-9 pin lane DISPATCHED to\nhertz (W0 item 1; interim kitsubito-clippy-authoritative dies when it lands). (2) IR-21 remedy\n(2) + IR-39 vs `f24e732` DISPOSED: the branch is a BEACHHEAD (golden.yml prebuild step = the\nprebuild-made-a-rule arm, ONE fail-fast site, one ledger row) — hertz rebases it off its\nabandoned parent `b483699` (the id-collision draft; content landed renumbered as IR-46 @`8248bc3`)\nand lands it in W0; the class remainder (IR-39's SHARED precondition helper + 24-site sibling_bin\nsweep, the 33 cross-package build-edge expressions) folds into the test-hygiene lane. (3)\nTest-hygiene family DECIDED-ACTIVATED as a dedicated hertz lane inside the KEYSTONE window,\nsequenced after W0 (members: IR-13/23/36/37/38 + IR-21 clarity half + IR-39 helper +\ntwohost.rs:394 doc comment). (4) First-execution-cells discipline restated in the JIT's\ngolden-head step. Board members #84/#85 ride hertz's W0; #166/#57/#185 are todlando's W1. IR-46\nid-collision RULED this intake (renumber-and-land, parallel issuance not authored disagreement;\ndeployah landed it @`8248bc3`). No new entries filed; no entries retired.\n\nPrior sweep: 2026-08-19, NAMEPLATE (#181) / v0.56.0 RELEASE CLOSE — shipped c91 @`60d74ea`\n(tag == golden-tested sha, run 32209922535; one respin, both first-golden reds ruled rig defects).\nFiled IR-42 (pool-claim writes / build enforces — BUILT in this same commit, AGENTS.md line),\nIR-43 (knock NoReply past its 30s carrier bound), IR-44 (perch-sentinel comment overclaims\npreservation), IR-45 (twohost rig home premise; SETTLED + RETIRED\n2026-08-19 — pump paths resolve under the per-run temp root, see the entry; #189 corrected on the\nboard, comment 5337519936). Two cycle findings ruled RUNBOOK-homed and\nlanded in this commit rather than as entries: the first-execution-cells intake question\n(RELEASE-RUNBOOK golden-head intake — name the never-executed cells before the run) and\ndeployah's sweep-vs-cascade mechanism (RELEASE-RUNBOOK board step — under golden CI the cascade\nis DRIVEN via `state <mref> acceptance`, never swept). ⚠ LABELLED HOLE — CLOSED UNDERIVABLE\n(2026-08-19): the close commune's batch list named \"alchemy create-races\"; its content did not\nsurvive the author's context reset and was not recoverable from #181, the JIT records, or memory.\n[…413ln elided…]\n\n**21 loose files sit in `.worktrees/`** — gate logs (`gate-*.log`, `gate-559632e-log.txt`), rig\nscripts (`g6-curve.ps1`, `g6-postbounce.ps1`, `gate-w5-*.ps1`), and `gate-w5-notes.md`. **Nobody\ndeclared `.worktrees/` a log drop; it became one.** Same class as the memory index: a shared location\nwith no stated contract accumulates whatever anyone puts there, and **the first person to tidy it\ncannot tell residue from someone's working state** — class D is that risk already realised. The\nhygiene rule this entry owes should name where gate logs and rig scripts belong, not only how to reap\nworktrees.\n\n#### RECLAIM ARITHMETIC — AND WHY THIS ENTRY IS NOT THE DISK FIX\n\nClasses B, C and D together are **under 51 KB**. All 13.2 GB of the unregistered population is class\nA, behind live junctions. **An orphan sweep is not a disk-space remedy**, and reading it as one sends\nyou at the wrong target: on the audit date, free space was **12.5 GB against the 32 GB golden floor**\n([[free-space-floor-blocks-golden]]) while the two largest pools on the box were `gate-ec5f38a/target`\n(14.33 GB) and `gate-main/target` (28.12 GB) — **both REGISTERED, so both outside the orphan\npopulation entirely.** The disk question and the orphan question have different populations; answering\none correctly says nothing about the other.\n\n- **AUDIT EXECUTED 2026-08-30 (doyle, the v0.66.0→NOW-SIGNAL between-milestone window; full\n  output `wt-census-2026-08-30.txt` in the session scratchpad, method = this entry's own):**\n  four answers BEFORE the sweep: 85 entries / 85 dirs / 76 registered incl root / 75 under\n  `.worktrees` → 10 unregistered, 0 loose files (the 21 loose files of 08-03 are gone).\n  **The 08-03 headline populations have INVERTED:** zero pools and zero junctions exist under\n  `.worktrees` at all (every registered tree reads `target=none`; the reparse sweep found no\n  inbound junction) — class A is EMPTY, so the armed pool hazards this entry named are\n  currently unpopulated. Unregistered classified: 4 fully-empty (C), 3 `crates/spt-daemon`\n  skeletons (B — the mechanism's fingerprint again), `_patches` (D, kept — working scratch),\n  and TWO content-bearing checkout remnants (gate-signet-w1 10.8MB, gate-w1-a8f04aff 27MB) =\n  registry-pruned dirs held by the conhost CWD pins IR-63's third face names. **Sweep\n  executed on the gater's own rigs:** evidence preserved FIRST\n  (`spt-preserve\\audit-2026-08-30\\`: gate-w1-a8f04aff's 229 non-HEAD files as a verified\n  tarball; er-instrument's 115-line UNCOMMITTED instrument diff as a patch — that worktree\n  belongs to hertz's lane and was NOT touched beyond the read-only copy), 16 pinning conhosts\n  killed by pid after a fresh probe, 9 dead rigs removed. AFTER: **76 dirs = 75 registered +\n  `_patches`, fully reconciled; zero unexplained entries, zero pins.** Reclaim was ~38MB —\n  reconfirming this entry's arithmetic that the orphan sweep is hygiene, not a disk remedy.\n  Landed-classification caveat: `git cherry` patch-id reads conflict-resolved picks\n  as UNLANDED (emit-single-write, fix-206/208/209 all show UNLANDED with shipped content), so\n  the census's landed column is a datum, never a reap authorization.\n- **HYGIENE RULE (the text this entry owed, written 2026-08-30 while the loose-file population\n  is zero — the rule exists BEFORE it refills):** `.worktrees/` holds exactly two kinds of\n  entry: **registered worktrees** and **`_patches/`** (the one declared scratch location).\n  Nothing else. Gate/rig artifacts follow their lifetime: (1) driver scripts, exit/raw files,\n  and logs live INSIDE their rig's worktree for the rig's life — they leave WITH it, via the\n  preservation step (copy what the verdict cites into `spt-preserve/<occasion>/`, verified by\n  cmp or a listed tarball, restore cost stated) and never accumulate beside the rigs; (2)\n  anything meant to outlive its rig goes to the repo ROOT beside the verdicts and RCAs it\n  supports (the census/finding/JIT convention) or into `spt-preserve/` — never loose in\n  `.worktrees/`; (3) a file found loose in `.worktrees/` is treated as UNCLASSIFIED WORKING\n  STATE — moved to `_patches/` with a dated note, never deleted on sight (class D is the risk\n  realised). Lane close-out = `git worktree remove` + prune + the conhost CWD-pin check\n  ([[IR-63]] third face) when removal refuses; a registry-pruned dir left behind is a defect\n  to sweep, not a norm.\n- **Ripe when:** between-milestone idle window (it is a dev-box chore, zero product risk) — but the\n  class-A pool findings are armed hazards and do not wait for it.\n- **Size:** small for the sweep; the hygiene rule and the pool-claim gaps are separate small items.\n- **Field instance (hertz sweep, 2026-08-04 — an unclaimed pool found rather than reasoned about):**\n  `.worktrees\\gate-target-w4doc` held **7,907,558,098 B with NO POOL-OWNER.json at all**. Not a stale\n  claim, not a foreign claim — no claim. Exactly this entry's shape, first measured instance. Reaped\n  under doyle's ruling as part of [[IR-27]]'s two-step teardown; the measurement stands on its own.\n\n### IR-17 — Deadline-burn bring-up family: a test burns its full window while the daemon/brain never comes up\n- **Status:** open · **Origin:** golden 30782259675 red triage 2026-08-03\n- **What/why:** two different tests on two runner hosts now share one signature — bring-up misses\n  its ONLINE window under leg load and the test burns its ENTIRE deadline before the PRECONDITION\n  panic: `spt::resident_service_e2e::a_declared_service_rises_with_the_daemon_and_reaches_the_cli`\n  (hfenduleam, FAIL 123.99s, \"PRECONDITION: the daemon never came up\", run 30782259675, green on\n  same-sha rerun 30784469908) and `spt::activity_link_push_e2e` (kitsubito, full 30s, run\n  30607903133 specimen, green on same-sha rerun; its \"brain stderr EMPTY\" leg and its family\n  membership are both CORRECTED in the 2026-08-30 sweep update below — the kitsubito member is\n  CLOSED under a named mechanism).\n  Family reading, not one flake: same missed-window shape, host-independent, both mid-leg under\n  load. Cross-ref KNOWN-HAZARDS 5.13 — bring-up has a hard ONLINE budget with known sensitivity to\n  anything that stalls it (the blanket-fsync canary; `attach_wedge_e2e` guards that budget).\n- **State line (the discriminating datum, resident_service red):** `daemon_up=false boot_alive=true\n  boot_pid=Some(8920) rel_started=false broker_survived=false` — the boot process was ALIVE at\n  panic time and the daemon never reached up. Any characterization run records this line per run,\n  not the verdict (hertz protocol 2026-08-03).\n- **Read of that line, CORRECTED 2026-08-03 (hertz):** it is NOT \"started-but-never-bound\" (the\n  earlier reading here) and not \"never-started\" — it is **started, did work, then killed** —\n  CANDIDATE via [[IR-18]]. The daemon spawned its boot service and that service reached the CLI\n  (the spool holds its message), and `broker_survived=false`. The DISCRIMINATING field is\n  `broker_survived`: false in every killed round of the positive control, true in every healthy\n  round. **An earlier evidence leg here is RETRACTED (hertz, same night, off the negative arm he\n  ran before reporting; deployah, who had carried the leg into four register sites, swept every\n  placement): \"empty daemon.stderr.log = TerminateProcess signature\" was false — the stderr\n  block is empty on PASSING runs too, so it carries zero information in either direction; it\n  failed the discriminator question and does not support the kill read.** The kill read now rests\n  on the control's field-for-field reproduction and the IR-18 mechanism, not on the log.\n  Consequences: (a) the bring-up window is **exonerated for this specimen** — measuring it would\n  have measured nothing; (b) the candidate mechanism and its evidence now live in [[IR-18]]\n  (a sibling test's bare breadcrumb tree-kill), CANDIDATE — not reproduced, not proven;\n  (c) **the characterization population changed, and the rate run is CANCELLED** (doyle ruling\n  2026-08-03) — `resident_service_e2e` run ALONE has no sibling to collide with, so the mechanism\n  predicts 0/N and that number answers no live question; the only sound population was the test\n  INSIDE the Phase A parallel pool, which costs a full Phase A leg per sample, and the fix is\n  warranted by the source-verified hazard class regardless of the specimen's rate. No rate figure\n  will exist for this specimen — do not later read its absence as a low rate; (d) **positive\n  control still runs, falling out of the\n  hypothesis:** kill the spawned daemon by pid mid-bring-up — after boot-service spawn, before\n  ready — and it must reproduce the observed line field for field (`daemon_up=false\n  boot_alive=true broker_survived=false`). If the rig cannot make that shape on\n  demand, a 0/N from the untouched arm is worth nothing and must be reported as worth nothing.\n  The host-INDEPENDENT family claim (kitsubito's `activity_link_push_e2e`) is untouched by this:\n  it has no such kill site named, so the family survives even if this specimen leaves it.\n- **POSITIVE CONTROL RAN 2026-08-03 (hertz, prebuilt a5042ec binary, box confirmed clear —\n  0 open runs, 145.95 GB free): shape reproduced 3/3, deterministic.** Negative arm n=2: 2/2 PASS\n  (5.59s, 5.46s), `daemon_up=true boot_alive=true rel_started=true broker_survived=true\n  survived_teardown=true`. Positive arm (daemon killed by parent-scoped descent after\n  boot-service spawn, before ready) n=3: 3/3 FAIL (93.95/93.25/93.50s), state line identical to\n  the CI red in EVERY field except boot_pid (a pid, must differ), same panic, same site\n  (resident_service_e2e.rs:382). Structural fact the arm settled, and the refutation risk that\n  made it worth running: the boot service rises BEFORE brain.ready becomes readable — had the\n  order been reversed the arm would have produced daemon_up=true and refuted the mechanism.\n  CEILING MET, NOT EXCEEDED: the control used Stop-Process -Force (TerminateProcess — the same\n  primitive as taskkill /F), so it proves a forced daemon kill after breakaway-service spawn\n  produces this exact line ON DEMAND; it says nothing about WHO issued one in golden 30782259675.\n  Candidate mechanism, shape reproduced on demand — \"root caused\" written by nobody. Duration\n  note, recorded not explained: 93.5s local (idle box) vs 123.99s CI (Phase A parallelism), both\n  burning the same three 45s windows — consistent, not verified.\n- **Same-host sub-observation (hertz, host-CONSTANT — narrower claim, kept separate):** both\n  reds of 2026-08-03 sat on hfenduleam Windows Phase A and burned their full windows:\n  `a_tree_teardown_reaches_a_grandchild_the_service_spawned` (run 30776330383, FAIL 10.176s = the\n  full poll deadline, vs a 0.19–0.66s pass band — 15–50x out) + the resident_service row above.\n  MEMBERSHIP PROVISIONAL for the teardown row: it carries a candidate mechanism the bring-up burn\n  does not share — the pid-only oracle IR-15 just replaced. If the oracle caused it, that row\n  leaves the family and host-constant collapses to one sighting. The host-INDEPENDENT pair above\n  is the claim that survives someone fixing this box; the sub-observation is what is actionable\n  about hfenduleam (a live-daemon host) meanwhile. **UPDATE 2026-08-04 (golden 30873007187\n  attempt 1 — SECOND sighting, and the provisional question above is now ANSWERED): the\n  pid-only-oracle candidate is REFUTED for this row** — IR-15's authenticated repin rode the\n  failing tree (a5042ec ancestor of 4b37512) and the row failed anyway (10.225s, \"grandchild\n  51848 outlived the tree teardown\"), with is_stamped() asserted before the kill so the verdict\n  passed the authenticated gate. The row therefore STAYS a family member with its mechanism OPEN,\n  narrowed by hertz's log forensics (competence-controlled: the capture channel demonstrably\n  prints): no DETACH_BREAKAWAY_DENIED (breakaway rung taken), no SERVICE_JOB_UNAVAILABLE (job\n  created + child enrolled), no SERVICE_TREE_KILL_INCOMPLETE (TerminateJobObject returned\n  success) — everything enrolled died; THE SURVIVOR WAS NEVER ENROLLED. Two hypotheses,\n  inseparable in existing evidence: H1 test defect — the grandchild SELECTION is a bare\n  th32ParentProcessID match over a recycling pid space (IR-15's mechanism one level up: the\n  verdict was authenticated, the selection was not); H2 real enrollment gap. hertz's selection\n  probe (IsProcessInJob at selection time — decisive; birth stamp one-directional; image; same-\n  snapshot match count) is authored+compiled and makes the NEXT occurrence self-deciding. Row\n  state: INSTRUMENTED-AWAITING-FIRE; a green retires nothing (doyle-ruled). **UPDATE 2026-08-04\n  (USHER att3):** row green at 17f95a7 (retires nothing, per the ruling). New shape evidence while\n  waiting for the probe: BOTH archived reds sit AT the 10s poll bound (daemon.rs:2757) — 10.176s and\n  10.225s — while todlando's 200 off-CI passes under live-fleet load ran 1-4s, never near it. The\n  post-fix red is therefore BOUND-EXPIRY-shaped (kill fired; the pinned identity stayed\n  not-provably-gone past 10s — TerminateJobObject is async), not kill-wrong-shaped. The bound\n  question (is 10s right for a loaded runner) is parked with hertz's USHER package item 4 and must\n  not touch the kill path or spawn flags before the probe fires. See also the FLAKE-LEDGER row for\n  the false-repeat correction (the 10.176s red was the PRE-a5042ec bare-pid mechanism).\n- **Declared read (2026-08-03, rules the next red):** a same-sha green rerun is protocol-conclusive\n  for the GATE, not the class. No third silent sample — the next occurrence of this signature gets\n  an instrumented resident-service bring-up investigation (hertz), not a rerun.\n- **SWEEP UPDATE 2026-08-30 (#242/v0.66.0 close — three corrections, correct-by-replacement):**\n  (1) **The 2026-08-03 \"brain stderr EMPTY\" reading on the kitsubito specimen is a METER\n  ARTIFACT, not a silent brain** (deployah measured 2026-08-29): the brain-panel stderr capture\n  only LANDED 2026-08-19 (`ab657626` + `e6e188e1`), 16 days after the specimen — at the specimen's\n  sha there was nothing to capture, so \"empty\" carried zero information; current bits label\n  absence explicitly, so empty-vs-present cannot recur as a distinction. This replaces the\n  \"cheap to settle next time someone has kitsubito\" item — there is nothing left to settle.\n  (2) **The kitsubito family member is CLOSED under a NAMED mechanism:** RCA-242-R2-LINUX.md\n  (v0.66.0 golden r2) measured `current_exe_hash()` on the READY PATH at ~10.1s per boot on\n  kitsubito under load (~1.5s Windows) via BRAIN_PHASE breadcrumbs + harvest-loop repro — a\n  bring-up that misses its ONLINE window under leg load is exactly what a ~10s synchronous hash\n  inside the ready path manufactures. The behaviour-change request (hash off the ready path,\n  ADR-0018 Q7) is minted on the board at this sweep as **releases#244** (BACKLOG, operator\n  triages). The family's host-INDEPENDENT claim\n  therefore collapses: the Windows `resident_service_e2e` specimen (IR-18 kill-shape candidate)\n  and the hfenduleam sub-observation STAY OPEN as this entry's remaining live population.\n  (3) **Lane-linked:** hertz's queued fixup lane brief names this entry directly\n  (activity_link_push_e2e 4-cell fixup: false precondition message + progress-bounded readiness\n  wait, #235 shape). Overlap with correction (2) checked at link time: his cells are TEST-side\n  (message truth + wait shape) and stand regardless of the product-side hash fix.\n- **Ripe when:** next occurrence of the signature (immediate instrumented dispatch), or a hertz\n  test-hardening wave (bring-up phase-timing instrumentation, per-phase deadline attribution).\n- **Size:** medium (bring-up instrumentation + attribution; the fix depends on what it shows).\n\n### IR-16 — kill_tree discards TerminateJobObject/TerminateProcess returns (silent partial kill)\n- **Status:** BUILT 2026-08-03 (landed @62c5623 on the LOCKSMITH t1 lane; rides golden sha\n  b7b00c3, run 30860770146 green) · **Origin:** ex releases#130 (golden 30776330383 red triage;\n  deployah's log read\n  + todlando's flagged-not-asserted arm). Operator-classified infra 2026-08-02: daemon-kill\n  internals are agent-facing, not operator-facing surface.\n- **What/why:** `DetachedChild::kill_tree` (daemon.rs:1433 vicinity) calls\n  `unsafe { TerminateJobObject(self.job, 1) }` and discards the return; TerminateProcess likewise\n  unaudited. A job that was created and assigned at spawn but whose TERMINATION fails at kill time\n  yields the grandchild-survives symptom with zero log signal — the spawn-side\n  SERVICE_JOB_UNAVAILABLE announcement is correctly absent (that arm is instrumented and was\n  refuted for the specimen by a positively-controlled zero). Wanted: (1) check + log both\n  termination returns loudly on failure; (2) the degraded-arm decision — fallback process-table\n  tree-walk kill or explicit refusal, never a silent partial kill wearing REQ-RESIDENT-SERVICE's\n  unconditional promise. Do NOT add self.job==0 instrumentation (already loud; a second weaker\n  rule beside a working one). Discrimination pairing with [[IR-15]]: a red whose captured pid is\n  still ping.exe with no SERVICE_JOB_UNAVAILABLE in scope = this entry's arm.\n- **Ripe when:** RIPE NOW — IR-15 landed BUILT 2026-08-03 (its rig-side half), so this kill-side\n  half is the outstanding instrument; land with the next daemon-teardown wave or sooner.\n- **Size:** small.\n- **Composed:** LOCKSMITH (#132) — todlando product lane, with the `detached_no_inherit_env`\n  rename as cosmetic rider (IR-20's load-bearing-pid caution applies to any rig touch) —\n  2026-08-03. GREENLIT with #132 and **DISPATCHED to todlando 2026-08-03**, carrying IR-20's\n  load-bearing-pid precondition as a stated check (todlando reports whether the rig is touched\n  at all rather than silently skipping it).\n- **BUILT — fulfilment checked against the wanted list, not merely mapped to a commit** (doyle,\n  2026-08-04): `62c5623` satisfies (1) — both termination returns are now checked and the loss is\n  NAMED on failure, as the kill-time twin of the spawn-time `SERVICE_JOB_UNAVAILABLE` — and (2) by\n  the ruled LOUD REFUSAL arm rather than a tree-walk fallback, which [[IR-18]] measured blind in\n  exactly this failure state. The `self.job == 0` prohibition was honored: the new check is\n  `self.job != 0 && TerminateJobObject(...) == 0`, not a second weaker rule beside the working one.\n  The unix `ESRCH` quiet arm — which no Windows gate can see — is covered by `ec5f38a`. The\n  `detached_no_inherit_env` cosmetic rider did NOT land and was dropped at `de6a01d` on a MEASURED\n  false premise, not deferred. A Windows-specific finding rides the fix as a comment and is worth\n  keeping: `TerminateProcess` against a handle to an already-exited process returns 0 with\n  `GetLastError` 5 (`ERROR_ACCESS_DENIED`), so a naive check there fires on the ORDINARY path.\n\n### IR-18 — resident_service_e2e kills breadcrumb pids BARE (stale-breadcrumb tree-kill; kill-side twin of IR-15)\n- **Status:** BUILT 2026-08-04 — the named acceptance carrier RAN and the condition is DISCHARGED,\n  stated as the measurement rather than as the green board it sat on: LOCKSMITH's golden run\n  30860770146 (head `b7b00c3`, conclusion success) executed the changed test IN-POOL on BOTH\n…\n  reproduction\n…\n\n…\n\n…\n- **Discipline and receipt.** [Windows ad-hoc rig launch discipline](GOLDEN-CI.md#windows-ad-hoc-rigs-that-outlive-the-tool-call) states the shape, child-owned durable output and post-return PID/birth/output qualification. Preserved harmless-child receipt: `.spt/preserved/hertz-ir137-caller-return/receipt.json`, SHA256 **`e1c9b207544e6313eac5421ebb692786ec18b3a165756b451bff3a704899b178`**. Both valid arms survived under **OMP**, wrote post-return events and exited0; an initial observer-handshake timeout is excluded. All3probe children ended and native handles closed. This does not reproduce the **Claude Code** failure; the host boundary stays explicit. Reopen only for a newly owned callsite or contrary evidence, not to build an unused helper.\n\n[Showing lines 1-239 and 653-881 of 881; 413 middle lines (31.9KB) elided. Use :874 to continue. Read artifact://729 for full output]"}],"details":{"truncation":{"content":"# Infra register — CI / build-pipeline debt\r\n\r\nOperator-ruled 2026-08-02: infrastructure and CI-pipeline work items live HERE, not on the\r\n`spt-bs-releases` board. The board carries product surface the operator triages; this register\r\ncarries what the gater triages. **Mandate: doyle sweeps this file at every milestone intake and\r\nevery release close, and composes ripe entries into waves/milestone riders.** An entry leaves\r\nthis file only by being built (link the lane) or being retired with a stated reason.\r\n\r\nEntry format: status · origin · what/why · trigger condition (what makes it ripe) · size guess.\r\n\r\nLast sweep: **2026-09-11, v0.69.0 RELEASE CLOSE — FULL REGISTER**, source `e5a2fed9`.\r\nAll **97 entries (IR-1–97, including headingless IR-31)** read in two disjoint ranges; audit\r\npopulation checked for missing/duplicate IDs (97 rows, 97 unique, zero missing). Per-entry\r\ntrigger and disposition evidence: `.spt/preserved/infra-close069-20260911/audit.json`.\r\nUNKNOWN means no qualifying event established, not a disproved trigger or a discharged debt.\r\n\r\n- **Release facts, not a blanket green:** v0.69.0 at `16df0e41`, counter **105**, Latest,\r\n  11 assets; #294 and all eight members DONE. Explicit operator SHIP overrode the known\r\n  sync-cell red at candidate `a9e786b2`; the release neither classifies nor closes that defect.\r\n  Source closeout: releases#294 comment **5628538587**. The scoped four-package `--lib` battery\r\n  passed **121/121**; push CI **34550282074** passed **3167 Windows units**, then failed the\r\n  END disk floor (**15,360,114,688 < 34,359,738,368 bytes**). Release build **34550300527**\r\n  succeeded. Earlier PR unit-red logs remain unavailable/cause-unclassified. These are separate\r\n  verdict objects; no pass substitutes for a red, missing specimen, or unexecuted acceptance.\r\n- **Close already-built work, retain residuals:** IR-1/4 stale unlanded headers reconciled to\r\n  their landed rider and recorded golden exercise. IR-66 CLOSED using its existing two-platform\r\n  gates and WEBSERVE satisfaction ruling. IR-73 CLOSED: eight post-checkout sites plus both\r\n  docs-floor rereads are present; IR-86 retains sizing/dependency debt. Other established\r\n  BUILT/RETIRED decisions stand. IR-18's deferred consolidation and IR-53/62's narrower\r\n  touch-triggered siblings remain carried; closing their built halves does not erase those.\r\n- **Do not redispatch existing implementations:** IR-26 build-side identity is committed,\r\n  but claim-time observation and old-reader issues remain; IR-29's first fix landed, later\r\n  rung faces remain; IR-33's 16 MiB CLI stack exists, acceptance/margin reconciliation remains.\r\n  IR-57 `pick-audit`, IR-59 `disk-floor`, and IR-46 workflow floor tokens exist; residual adoption\r\n  and receipt reconciliation are the work. IR-69's original product lane landed; #243 residuals\r\n  remain. IR-83's universal LAN-only prescription is superseded by IR-89's layer-specific box\r\n  proof. IR-89's next-golden trigger has fired; exact step acceptance still needs reconciliation,\r\n  not a second guard implementation or renewed operator permission.\r\n- **IR-92 stays OPEN:** core#215 shipped the documentation/register rider, NOT the product\r\n  remedy; core#217 is the separate brainread audit. `try_spt_hosted_inject` still lacks the\r\n  MSG_IN publisher. Deployah corrected comment **5628532753** in place and confirmed readback.\r\n  Inject coverage, relay publication ordering and per-msg-id exact-once are distinct obligations.\r\n- **Next-intake composition, owned by doyle until accepted:** hertz's driver/workflow package\r\n  takes IR-31/46/59/60/76/86/87/90/97: aggregate capacity, truthful producer status, existing\r\n  quiet-window contract, independent rendezvous clocks, and mandatory between-run identity\r\n  census. IR-88 adopts the already-proven prebuilt release-before-delete recipe; IR-64 remains\r\n  a separate operator capacity decision. No new loaded comparison before these prerequisites.\r\n  Hertz's lifecycle package retains IR-7/17/20/22/25/34/35/55/63/79/80; guard adoption must\r\n  distinguish unwinding from hard process death. IR-74/75 ride the next Linux box audit.\r\n  IR-85/95/96 are scoped diagnostic continuation, NOT budget widening or a load/disk diagnosis.\r\n  Todlando owns product-side IR-81/82/92 composition; #285's completion did not build IR-82's\r\n  predecessor record. Both builders are offline: existing briefs are delivered, unacknowledged,\r\n  and **not executing**. No board mutation or new run authorization is implied.\r\n- **Small seam riders remain explicit:** next tooling intake weighs IR-5/6/10/11/32/37/47/58/94\r\n  (IR-37 upstream release is not downstream adoption: golden still requests 0.2.0).\r\n  IR-93 remains a separate symbol-packaging decision before a release-workflow rider, not a\r\n  property proven by a successful release build. All other open entries retain their recorded\r\n  trigger, residual, and owner where named; the complete audit records each, not a sampled set.\r\n- **Cleanup is mitigation, not closure:** 38 clean merged worktrees and classified obsolete\r\n  artifacts removed; dirty/unmerged/retained evidence preserved. Net free-space change\r\n  **4,532,350,976 bytes**, ending **83,382,472,704 bytes** (concurrent-activity caveat).\r\n  `.spt/cleanup-20260911.json` is the receipt. Root-target and CI-debug reclaims are separate\r\n  earlier measurements, not additions to that net. IR-14/26/27/49 remain structurally OPEN.\r\n\r\n### Intake addendum — hosted-relay diagnostic capacity hold (2026-09-11)\r\n\r\nSourced C: free samples around the intake, each named by file: **19,260,395,520 bytes at\r\n03:02:33Z** (post-merge run 34556292801, unit job `FLOOR_END`, RED against the\r\n34,359,738,368-byte floor); **19,907,792,896 bytes at 07:09:57Z**\r\n(`.spt/preserved/todlando-pool-reclaim-20260911/before.json`); **191,756,984,320 bytes** after\r\ndeployah's three authorized target reclaims (`.spt/preserved/deployah-rca-reclaim-20260911/reap-results.json`:\r\nrca-base +11,461,189,632, rca-head +11,371,200,512, gate-293c +94,256,648,192 observed);\r\n**247,894,224,896 bytes at 08:39:20Z** (hertz, GetDiskFreeSpaceExW, during post-merge run\r\n34580045779). An earlier draft of this addendum attributed a 19,979,182,080-byte 07:00Z sample\r\nto hertz; hertz could not point at a file for it and the figure is withdrawn. Every sample is an\r\ninstant, not headroom (IR-46).\r\n\r\nRunner-target behaviour, inferred from three samples and not yet read from the workflow: the\r\nunit job went 83,420,217,344 -> 19,278,598,144 (run 34555345283) and 83,368,599,552 ->\r\n19,260,395,520 (run 34556292801) inside the job, and the runner's own target measured\r\n65,260,456,302 bytes at rest at 07:57Z (`remote-friction-304/capacity-ci-target.json`), so the\r\nrunner appears to purge and cold-rebuild its resident target per run. A post-merge run therefore\r\nadds no growth beyond that resident ~65 GB, and both reds above are resource reds on a box that\r\nsat at ~19 GB free from 03:02Z to 07:10Z: untested, not failed.\r\nThird sample, post-merge run 34580045779 on `b12d4619` (GREEN): `FLOOR_START` 249,872,142,336 at\r\n08:37:27Z, `FLOOR_END` 181,632,450,560 at 08:49:04Z — a 68.2 GB in-job drop while two #304 lanes\r\nwere also building (todlando's pool reached 4.26 GB in that window), consistent with the\r\npurge-and-rebuild inference and still not read from the workflow.\r\n\r\nThe 293-brain pool was deleted at 07:10:59Z with a receipt (+10,916,200,448 bytes observed, same\r\ndirectory as the sample above). The receipt does not record the executor; todlando's ledger says\r\nit was not him, and no executor is asserted here without a file.\r\n\r\nNo diagnostic fixture daemon/listener or fresh build for the hosted-relay experiment has started.\r\nThe isolated hosted-relay experiment is separate from #304 implementation and from the #294\r\ncause investigation. Carry its capacity planning under **IR-31/59/90**, not a new product\r\nrequest. Hertz owns identifying the minimum diagnostic target, reusable version-matched\r\nartifacts, estimated incremental build/temp footprint and the concrete socket/network isolation\r\ngap. Doyle owns matching that requirement to an owned pool and available capacity before\r\nauthorizing a build. A prebuilt-only route still needs isolation proof; a private home alone\r\ndoes not establish it. No unowned artifact deletion or live-daemon changes are authorized.\r\nControl, relay-replacement and mixed-version arms remain unexecuted.\r\n\r\nPrior sweep: 2026-09-06, v0.67.1 RELEASE CLOSE + WEBSERVE (#272) INTAKE (one delta pass; the 08-30\r\nfull pass stands) — shipped counter 103, tag == main == tested `04e32c8c`, golden 34017906638 att4\r\n9/9 on a QUIET box after three reds (:473 attach_link structural test defect; wtlock :147 under\r\nbuilder load; resident_service_e2e :664 ledgered leak row, 3rd occurrence) — the quiet-box arm is\r\nIR-76's origin. Enumeration by a read-only subagent into `REGISTER-SWEEP-0671-DRAFT.md` (75\r\nentries, 10 trigger-text candidates; IR-31 has NO `###` heading — its body sits under IR-30's,\r\nflagged, not normalized). Rulings: **IR-46 trigger FIRED and was MISSED** — `golden.yml` was\r\ntouched by `04e32c8c` itself (2-line HEAVY reclass on the respin) and no remedy was weighed; a\r\nrespin edit under a pre-registered hard stop is not a remedy window, so the entry gains that datum\r\nand is COMPOSED forward. **Composed: the floor trio IR-46 + IR-59 (log-the-floor half) + IR-73\r\n(8 literal-first sites) as ONE hertz workflow rider on WEBSERVE** (`ci.yml`/`golden.yml`/\r\n`release.yml`, thin PR off the golden path, before the WEBSERVE golden head so that head runs\r\nunder it); **IR-59's log-the-floor line ALSO rides IR-76's three-arm pre-flight on W0's driver\r\ntemplate** (todlando authors; free space recorded beside the floor check). **IR-66 residual (two\r\nfirst-chunk-needle members) = hertz WEBSERVE test rider** (two one-line edits). **IR-12 residual =\r\nW3 drift-gate rider** (hertz already holds W3's drift-gate riders). IR-67 satisfied at this intake\r\nby construction (`--no-fail-fast` in the W0 driver template; todlando's 2026-09-06 correction).\r\nIR-34 unchanged, lane-linked to hertz's `test/attach-relink-barrier` @`b976cc09` (thin PR queued\r\nbehind the release runs). NOT fired: IR-3 (a new stream family is neither endpoint lifecycle nor\r\ndaemon supervision), IR-48, IR-52 (DOCS-NITS item 2 is a parent-option placement filing, not a\r\ndeep-help divergence — adjacent, noted), IR-64 (att4 did not die at preflight; no operator ruling).\r\nBoard mints this arc: #277 (io-events seq reset), #278 (adapter update never prunes strings/),\r\n#279 (ER_HOSTED_PROBE on every bind), #280 (MSG_IN never published on the relay edge). Design\r\nrulings on the grill branch: ADR-0056 Am.1 (router precedence), ADR-0057 Am.1 (served root =\r\n`adapters/<adapter>/web/`), ADR-0058 Am.1 (#17 auto-serve, reference-served). No entries retired.\r\n\r\nPrior sweep: 2026-08-30, NOW-SIGNAL (#23) / v0.67.0 RELEASE CLOSE — shipped counter 102, tag ==\r\nmain-at-tag == tested `da71b785`, 9/9 golden att2 (att1 sole red = FLAKE-LEDGER :664\r\nteardown-leak row, ruled ledgered-class at triage — signature predates the diff — rerun\r\nnon-vacuity proven by cell re-execution; ledger row +1 with new data, stays OPEN; hertz\r\nIR-34/35 cluster strengthened). Same-day second sweep, so most composition state is the\r\nmorning's; deltas only: IR-59 gained the SEVENTH face (parallel-lane fill rate: 236.6 GB /\r\n3.5 h across four wave pools drove the box to 0.01 GB mid-close; per-wave pool reaping rule).\r\nIR-12 gained the stale-binary kin note (xtask reference-drift arm reads the ON-DISK spt binary;\r\nstructural remedy = the now-mandatory workspace-bins prebuild leg, adopted this arc after it\r\nalso caught W2's spacerun red). IR-63's conhost litter REPRODUCED on cue: 14 fresh CWD pins on\r\nthe four party trees at the same `crates/spt-daemon` relative path, killed by pid via the PEB\r\nprobe, all four worktrees then removed FIRST TRY — the pin-check-first party rule held\r\n(+58.2 GB; earlier emergency reap of the same wave's finished-lane targets +186.6 GB).\r\nTest-craft banked to memory, not entries: `cargo test -- <bare> --exact` runs NOTHING and exits\r\n0 (todlando's structural fix: names carry the filter token); Win32_Process CommandLine filters\r\nCANNOT answer a CWD-pin question (todlando's false-positive self-catch). Board mints this arc:\r\n#244/#246/#247/#254 (BACKLOG). #16/#17 discharged drops (detach + EVAL). IR-73's ci.yml/\r\nrelease.yml floor-site reorders did NOT ride this arc's workflow commits — still owed, next\r\ntouch. No entries retired.\r\n\r\nPrior sweep: 2026-08-30, SEMAPHORE (#242) / v0.66.0 RELEASE CLOSE — shipped counter 101, tag ==\r\nmain == tested `d931dd63`, 9/9 at one sha across two attempts; full-register pass executed from\r\n`REGISTER-SWEEP-242-DRAFT.md` (72 entries enumerated pre-golden, load-bearing claims re-measured\r\nin-tree). Rulings: IR-69 close-out re-census RAN and FOUND the entry's own predicted truncation\r\nblind spot LIVE (338 cli.rs + 2 main.rs shipping sites never censused; addendum on the entry,\r\nstays OPEN; residual conversion + generator fix + seam enforcement = releases#243, scoping\r\nreconciled on the issue; common-word matcher RULED a separate hertz test-side rider). IR-17\r\nthree corrections by replacement (08-03 kitsubito \"empty stderr\" = METER ARTIFACT — panel\r\ncapture postdates the specimen by 16 days; kitsubito family member CLOSED under the RCA-242\r\nexe-hash-on-ready-path mechanism, behaviour-change request minted as releases#244; Windows\r\nspecimen + hfenduleam sub-observation stay the live population). Daemon-leak cluster\r\nIR-7/17/20/34/35/63 LANE-LINKED to hertz's queued fixup lane (briefs in his spool cite the entry\r\nids). IR-57 first-real-assembly use appended (ASM-241: 6 picks, 5 MATCH / 1 LOSS reconciled\r\nbyte-for-byte to the deliberate resolution; its earlier \"figure correction rides next batch\"\r\nnote was STALE — the correction landed inline 2026-08-29, retired here). IR-46 gained the #242\r\ngolden additions (per-job floor instants; the `/runs/<id>/jobs` run_attempt trap with\r\n`started_at` discriminator + `/attempts/N/jobs` authority; raw-bytes rerun preflight;\r\nnon-vacuous rerun check). IR-59 gained the SIXTH face (r4 LNK1318 at the job's internal\r\nlow-water; within-job floor re-read rides the next workflow commit; box ~51 GB non-recovering\r\nconsumption → audit slot). FILED: IR-73 (ci.yml/release.yml literal-first floor sites off the\r\ngolden path, 8 sites), IR-74 (kitsubito 21,643 /tmp endpoint homes, hertz's measurement), IR-75\r\n(kitsubito treqs 127 vacuous leg — install-or-drop; IR-37 deliberately NOT reopened, different\r\nsurface). Composed: IR-14/26/27/49 as ONE between-milestone pool/worktree audit slot (window\r\nopen now); IR-11 + IR-33(a) as next-intake small riders; IR-59's log-the-floor half + IR-57's\r\nscripted audit stand as the next intake's tooling pair. IR-54 evidence noted: the #242 cut's\r\nunshaped-head intake miss (self-caught by deployah, shape-on-top `e4f52047`, 8th consecutive\r\nshape-inside-candidate) is another construction-not-discipline datum. No entries retired.\r\n\r\nPrior sweep: 2026-08-27, IO-PARSER (#22) INTAKE (wave map: `IO-PARSER-22-JIT.md` + #22 comment).\r\nRulings: IR-66 COMPOSED as the parallel hertz rider (the two attach-cell later-needle treatments,\r\nattach.rs:561/:672 — the \"rides next intake\" note comes due here). IR-52 conditional rider\r\nCARRIED FORWARD on this milestone's docs lane, same terms as WAX-SEAL (depth fix lands iff the\r\nlane touches the docs-site CLI reference generator, else stays open). IR-67 COMPOSED as JIT gate\r\ndiscipline (no wave battery leans on a `-p spt --bins` leg as integration coverage); the entry\r\nstays open until its named construction fix. IR-55 stays armed with hertz; IR-6 LOCKSMITH\r\ncomposition still unreported, stays; IR-2 trigger unevaluated this sweep (teardown just cleared\r\nthe unlanded-lane field — re-check next sweep). No entries retired; none filed.\r\n\r\nPrior sweep: 2026-08-23, WAX-SEAL (#21) INTAKE (wave map: `WAX-SEAL-21-JIT.md` + #21 comment\r\n5390092115). Rulings: IR-52 COMPOSED as a CONDITIONAL W4 rider on the wax-seal docs lane —\r\nthe milestone mints new nested `spt seal` CLI verbs, exactly the shallow-render class the entry\r\nnames; the depth fix lands iff that lane touches the docs-site CLI reference generator, else the\r\nentry stays open here. IR-2 trigger NOT met (todlando's PR set parked unlanded for the next\r\ngolden chain). IR-55 stays ARMED-FOR-CAPTURE with hertz. IR-6 conditional composition from\r\nLOCKSMITH still unreported — stays open. IR-56/57/58/59/60/61 are discipline/craft entries or\r\nawait their named triggers; IR-62 is hertz-class test/rig work, unscheduled. No entries retired;\r\nnone filed.\r\n\r\nPrior sweep: 2026-08-19, CONCIERGE (#183) INTAKE (wave map: `CONCIERGE-183-JIT.md` + #183\r\ncomment 5347768797) — rows read from the LOCAL register stack (`4799031→ecd640c→8d4c224`;\r\norigin/main lacks IR-49/50/51 until the chain lands — absence ≠ not-filed). Rulings: IR-50\r\nCOMPOSED — dispatched to hertz same day (sink-path-helper-FIRST sequencing per the entry;\r\n`engine_room_bringup_e2e.rs` excluded, its panel sites ride the gated #199 lane), with the\r\nengineroom.rs:145 misnomer as a rider on the same lane. IR-47 = candidate co-rider IF this\r\nchain touches golden.yml/ci-notify, else holds. IR-48 holds (next xtask parity-cell touch).\r\nIR-49 holds (next poolguard touch or first landed-lane takeover request). IR-51 holds —\r\ngated on #199 attribution; a net-off fix must NOT precede attribution. IR-2 trigger NOT met\r\n(queued unlanded lanes exist). No entries retired; none filed — the intake window's product\r\nfinding (rc terminal-Exit omission, hertz RCA: proven invariant violation, load excluded\r\n92/92, H2 candidate unconfirmed) routed to the BOARD as releases#201, the correct venue for\r\nproduct surface.\r\n\r\nPrior sweep: 2026-08-18, KEYSTONE (#182) INTAKE — the prior sweep's four composition rulings\r\nEXECUTED (wave map: `KEYSTONE-182-JIT.md`, base main @`8248bc3`): (1) IR-9 pin lane DISPATCHED to\r\nhertz (W0 item 1; interim kitsubito-clippy-authoritative dies when it lands). (2) IR-21 remedy\r\n(2) + IR-39 vs `f24e732` DISPOSED: the branch is a BEACHHEAD (golden.yml prebuild step = the\r\nprebuild-made-a-rule arm, ONE fail-fast site, one ledger row) — hertz rebases it off its\r\nabandoned parent `b483699` (the id-collision draft; content landed renumbered as IR-46 @`8248bc3`)\r\nand lands it in W0; the class remainder (IR-39's SHARED precondition helper + 24-site sibling_bin\r\nsweep, the 33 cross-package build-edge expressions) folds into the test-hygiene lane. (3)\r\nTest-hygiene family DECIDED-ACTIVATED as a dedicated hertz lane inside the KEYSTONE window,\r\nsequenced after W0 (members: IR-13/23/36/37/38 + IR-21 clarity half + IR-39 helper +\r\ntwohost.rs:394 doc comment). (4) First-execution-cells discipline restated in the JIT's\r\ngolden-head step. Board members #84/#85 ride hertz's W0; #166/#57/#185 are todlando's W1. IR-46\r\nid-collision RULED this intake (renumber-and-land, parallel issuance not authored disagreement;\r\ndeployah landed it @`8248bc3`). No new entries filed; no entries retired.\r\n\r\nPrior sweep: 2026-08-19, NAMEPLATE (#181) / v0.56.0 RELEASE CLOSE — shipped c91 @`60d74ea`\r\n(tag == golden-tested sha, run 32209922535; one respin, both first-golden reds ruled rig defects).\r\nFiled IR-42 (pool-claim writes / build enforces — BUILT in this same commit, AGENTS.md line),\r\nIR-43 (knock NoReply past its 30s carrier bound), IR-44 (perch-sentinel comment overclaims\r\npreservation), IR-45 (twohost rig home premise; SETTLED + RETIRED\r\n2026-08-19 — pump paths resolve under the per-run temp root, see the entry; #189 corrected on the\r\nboard, comment 5337519936). Two cycle findings ruled RUNBOOK-homed and\r\nlanded in this commit rather than as entries: the first-execution-cells intake question\r\n(RELEASE-RUNBOOK golden-head intake — name the never-executed cells before the run) and\r\ndeployah's sweep-vs-cascade mechanism (RELEASE-RUNBOOK board step — under golden CI the cascade\r\nis DRIVEN via `state <mref> acceptance`, never swept). ⚠ LABELLED HOLE — CLOSED UNDERIVABLE\r\n(2026-08-19): the close commune's batch list named \"alchemy create-races\"; its content did not\r\nsurvive the author's context reset and was not recoverable from #181, the JIT records, or memory.\r\nDeployah answered the query: he ran ZERO create ops at the cut (could not have witnessed a create\r\nrace), a fresh probe over the milestone window shows no duplicate mints (the 4-issues-in-2s batch\r\nmint is batching, not duplication), and the only surviving trace is doyle's own pre-reset message\r\nnaming the item as already-known — a pointer, not a sighting. Item DROPPED; the hole stands as\r\nthe record. Deployah's sweep-vs-cascade ship-path trap (#181 comment 5337402639, runbook-homed\r\nabove) is explicitly NOT this item's content — do not fold it in. Composition: IR-9's pin lane\r\n(`rust-toolchain.toml` @ 1.96.0) goes to hertz AT KEYSTONE #182 INTAKE per the 2026-08-05\r\nruling; IR-21 remedy (2) + IR-39's precondition helper compose with hertz's standing\r\nfixture-prebuild-hardening branch `f24e732` — disposition at the same intake; the test-hygiene\r\nfamily (IR-13/23/36/37/38 + IR-21's clarity half) stays the dedicated post-batch lane candidate,\r\ndecision at intake; IR-29's proving run + IR-30's instrument lanes ride the next golden batch.\r\nIR-2's trigger explicitly NOT met (queued unlanded lanes exist: IR-29/IR-30 instruments,\r\nfour-arm refusal eprintln, f24e732). IR-14 hygiene movement: `.worktrees/nameplate-asm-2bd36f1`\r\nreaped this sweep (+66.98 GB by FS delta 120.53→187.51; claim `gate-w7-courtesy` base `fd3dc5a`\r\nin main = finished lane; zero inbound reparse points) — stale-lane audit itself still open.\r\n\r\nPrior sweep: 2026-08-05, LOCKSMITH tranche-2 (#141) CLOSE — golden run 30971976024 green on all 9\r\njobs, main ff'd to `0a25b77`, v0.55.0. IR-40 filed (stale-resume-brief + early-informant class).\r\nIR-9's decision trigger FIRED 2026-08-05: doyle read the runner-account versions off this run's\r\n`test` legs and RULED — pin in-repo via `rust-toolchain.toml` @ 1.96.0, kitsubito's clippy leg\r\nauthoritative in the interim; pin lane to hertz at next intake (see the entry). IR-41 filed the\r\nsame night (queued main run superseded without a record; runbook step 3 corrected in the same\r\ncommit). IR-1/IR-4's golden-only steps (link probe both boxes, toolchain\r\nprint both legs) had their FIRST EXERCISE here, discharging the \"unexercised until a golden run\"\r\ncaveat at the CI-RIDER LANE STATE foot section. IR-35's re-measure rode the batch (`c65b838`).\r\nOwlery-noun thin lane SCOPED and dispatched to hertz for the next batch (class A only, two sites;\r\nclass B on-disk rename is an explicit non-goal — see IR-40's kin discipline for why the boundary is\r\nwritten into the brief rather than left to judgement).\r\n\r\n---\r\n\r\n## OPEN\r\n\r\n### IR-1 — Quiet predicate needs a network axis (tailscale RTT probe)\r\n- **Status:** BUILT AND LANDED — reconciled at [[CI-RIDER LANE STATE]]; golden-only exercise\r\n  recorded at the 2026-08-05 close (30971976024). Header corrected 2026-09-11. Originally\r\n  carried by `bf8c4a2` → `REQ-CI-LINK-HEALTH-PROBE`, mapping CONFIRMED by builder hertz 2026-08-03\r\n  (by content: tailscale ping ×5, med/max RTT rows into the bench ledger, three arms\r\n  success/NO-REPLY/UNAVAILABLE, always exit 0 — instrument, not gate). NOTE `bf8c4a2` is NOT\r\n  single-purpose: it also corrects the free-space preflight floor read\r\n  (`REQ-CI-FREE-SPACE-PREFLIGHT`, the ci-runner-has-no-warm-target shape) — no 1:1 commit→IR map\r\n  for this commit · **Origin:** golden/bench-wiring red triage 2026-08-02 (ex releases#126)\r\n- **What/why:** the shared-runner quiet predicate (zero non-terminal runs + no local\r\n  cargo/rustc/nextest by parent chain) is process-shaped; both axes passed on a box whose only\r\n  link was degrading (321s for a 1s checkout, bidirectional 10s QUIC dial timeouts). A tailscale\r\n  RTT probe to the peer box before two-host rendezvous, carried in the bench ledger, would have\r\n  called run 30771155390's red in seconds. Evidence: the arm-1 count table (PUMP_PEER_FAIL\r\n  a 0→3→0, b 8→22→8 across green/red/rerun).\r\n- **Permanent, not stopgap:** operator-confirmed 2026-08-02 that kitsubito cannot be provided\r\n  ethernet — wifi-only indefinitely, so the link cannot be hardened and the predicate must see\r\n  link health.\r\n- **Ripe when:** next CI-touching wave, or the next network-shaped golden red — whichever first.\r\n- **Size:** small (one probe step + ledger row + predicate doc).\r\n- **Composed:** LOCKSMITH (#132) CI-rider cluster, hertz thin lane — 2026-08-03. GREENLIT with\r\n  #132 and **DISPATCHED to hertz 2026-08-03** (direct brief; the register is the spec, there is no\r\n  board issue). Leaves the register only when the lane lands or the entry is retired.\r\n- **FIRST FIELD USE, and it DISCRIMINATED (2026-08-04, golden 30873007187 attempt 1):** the probe\r\n  (landed via the rider lane, riding `4b37512`) read 4–7ms RTT healthy on both twohost legs\r\n  minutes before both legs redded — REFUTING the degraded-link read for that red and steering\r\n  triage to the real mechanism (the [[IR-29]] serve-window race) instead of a link chase. The\r\n  instrument's first catch was a correct NEGATIVE — exactly the call run 30771155390 needed and\r\n  could not make.\r\n\r\n### IR-2 — Settle the warm-runner CARGO_INCREMENTAL delta\r\n- **Status:** RETIRED 2026-08-28, measurement run, verdict NO FLIP — incremental stays ON.\r\n  hertz paired goldens at main fed965f8: ON run 33167693879 GREEN; OFF run 33172022108 RED\r\n  (Windows input_ack_deadlock SetupFailed at a 3.0s IPC read deadline — the box-load family,\r\n  discarded with the leg). Disk: OFF target 7.49 GB vs ON 11.40 GB = 3.91 GB / 34.3% saved\r\n  (smaller than the entry's 5.65 GB cold figure). Timing NOT causal-quality: sequential runs in\r\n  one persistent workspace let OFF inherit ON's cache (order contamination dominates the\r\n  apparent OFF speedups); Windows build-spt-bin +3.8%, Linux -5.1%. Retire reasoning: the\r\n  DECISION is answerable now — OFF produced no green golden, the timing question needs 4+\r\n  counterbalanced fresh-cache windows to answer cleanly, and the disk motivation has weakened\r\n  (box at ~148 GB free under the teardown discipline; the LNK1318 pressure era predates it).\r\n  Runs/artifacts preserved on the record. Reopen only if runner disk pressure returns as a\r\n  recurring floor-class red.\r\n- **Was:** open · **Origin:** #103/#108 bench-wiring lane 2026-08-02 (ex releases#127)\r\n- **What/why:** the #103 measurement (−29.8% wall, −5.65 GB/target, n=3) is COLD-build only.\r\n  Golden's runner `_work` target persists warm, where incremental is exactly what keeps it cheap;\r\n  CARGO_INCREMENTAL=0 was applied only to the genuine cold build (n1-gate pinned old-broker\r\n  cache) + local rig recipes (docs/GOLDEN-CI.md). Open question: does incremental still pay on\r\n  the warm runner, weighed against 5.65 GB/target on a box with LNK1318 free-space history?\r\n- **Method (hertz):** one full golden each way on a quiet box, outside a milestone, compared\r\n  per-step from the bench ledger.\r\n- **Ripe when:** a quiet between-milestone window with no queued lanes (the measurement burns\r\n  two golden windows).\r\n- **Size:** medium (two proving runs + verdict + possible leg flips).\r\n\r\n### IR-3 — Daemon-level guard: broker-net wakeup rate bounded across endpoint churn\r\n- **Status:** open · **Origin:** releases#125 remediation, todlando REQ call 1 (ex releases#128)\r\n- **What/why:** the swarm-discovery GC-spin burned two cores for two weeks visible only in a\r\n  process table — no suite assertion sees the class. Wanted: a daemon-level assertion that\r\n  broker-net workers stay quiescent across repeated endpoint create/destroy churn.\r\n- **Design constraint (pre-ruled):** assert on WAKEUP RATE / voluntary ctxt-switch delta over\r\n  the churn window, NOT %CPU — CPU thresholds flake under CI load; the defect signature\r\n  (~100 Hz per orphan loop) is load-independent. Mint the REQ at activation.\r\n- **Near-product:** this is runtime-defect visibility, the most product-adjacent entry here —\r\n  a candidate rider on any daemon-lifecycle milestone.\r\n- **Ripe when:** the next milestone touching spt-net endpoint lifecycle or daemon supervision.\r\n- **Size:** medium (churn harness + counter plumbing + flake-safe assertion).\r\n\r\n### IR-4 — Lock-pin guard + lock-procedure rule + toolchain print (three riders, one lane)\r\n- **Status:** BUILT AND LANDED — `1275e47` / `49d4805` / `8ed006b` mapped and landed in the\r\n  [[CI-RIDER LANE STATE]] reconciliation; golden toolchain-print exercise recorded at the\r\n  2026-08-05 close (30971976024). Stale unlanded header corrected 2026-09-11. ·\r\n  **Origin:** releases#125 fix-lane intake hold (ex releases#129 + riders)\r\n- **What/why, three parts that land together:**\r\n  1. **xtask check leg:** assert Cargo.lock resolves swarm-discovery to git rev\r\n     `89a2200d54a4e3cab2f46cc75ebff49a1fb07614` while the patch is load-bearing; the check's\r\n     message states its own drop condition (upstream ships a post-PR#27 release AND iroh's pin\r\n     reaches it). Without it, stanza removal or a routine iroh bump silently returns the lock to\r\n     the spinning crate and nothing reds.\r\n  2. **Procedure rule for lock-touching lanes** (docs): targeted `cargo update -p <crate>` only,\r\n     never full re-resolve; count changed `[[package]]` blocks AND diff per-block edges (set-identical\r\n     hid 8 windows-sys edge movers at acaaa4f); two resolutions disagreeing = toolchain drift —\r\n     stop and compare against CI before shipping either lock; hand-edited lock acceptable iff\r\n     `cargo check --workspace --locked` passes.\r\n  3. **Toolchain-version print step in golden** (cargo/rustc versions, both OS legs): the acaaa4f\r\n     comparison against CI was impossible because no run log prints a version. One-grep audit.\r\n- **Ripe when:** next CI-touching wave; part 1 sooner if any iroh bump is proposed.\r\n- **Size:** small-medium (one xtask leg, one docs section, one workflow step).\r\n- **Composed:** LOCKSMITH (#132) CI-rider cluster, hertz thin lane — 2026-08-03. GREENLIT with\r\n  #132 and **DISPATCHED to hertz 2026-08-03** (all three parts land together).\r\n\r\n### IR-5 — Shared nextest summary parser\r\n- **Status:** open · **Origin:** BAROMETER triage (standing recommendation, pre-register)\r\n- **What/why:** two agents in one day wrote `[0-9]+ tests run` parsers that read \"1 test run\"\r\n  (singular) as zero — a guard fed by a broken parser condemns valid rounds. One shared,\r\n  singular-aware parser (single-source discriminant) for every consumer of nextest summaries.\r\n- **Ripe-when REWORDED 2026-08-04 (todlando audit): the old trigger was unfireable as worded.** At\r\n  `b7b00c3` the in-tree population of nextest-SUMMARY parsers is ZERO — the two scripts that read\r\n  nextest output (`g6-curve.ps1:83-90` per-test lines, `g6-postbounce.ps1:44` display-only grep)\r\n  neither parse counts nor carry the defect, so \"next wave touching any gate script that reads\r\n  nextest output\" could fire on a non-defective script while the real population (agent-authored\r\n  throwaway parsers, which never enter the tree) stays out of reach. New trigger: **the next time\r\n  anyone — agent or lane — needs a nextest summary COUNT**, the shared parser is built FIRST and the\r\n  need consumes it; rig briefs should name it so throwaways stop being authored.\r\n- **Size:** small.\r\n- **Composed:** LOCKSMITH (#132) CI-rider cluster, CONDITIONAL — lands iff the hertz thin lane\r\n  touches gate scripts; otherwise stays open here. 2026-08-03. Carried in hertz's 2026-08-03\r\n  dispatch brief as a **conditional** rider. **Condition NOT MET**, answered by the file-set\r\n  audit at [[CI-RIDER LANE STATE]]; remains open for its next count-consuming use.\r\n\r\n### IR-6 — Membership logging on subnet gates\r\n- **Status:** open · **Origin:** BAROMETER triage (standing recommendation, pre-register)\r\n- **What/why:** counts beside results, membership beside counts — gate logs that state a count\r\n  without naming the population keep producing unreadable reds. Standardize membership\r\n  enumeration in gate output.\r\n- **Ripe when:** next wave touching gate scripts / CI legs that report counts.\r\n- **Size:** small.\r\n- **Composed:** LOCKSMITH (#132) CI-rider cluster, CONDITIONAL — lands iff the hertz thin lane\r\n  touches gate scripts; otherwise stays open here. 2026-08-03. Carried in hertz's 2026-08-03\r\n  dispatch brief as a **conditional** rider. **Condition NOT MET**, answered by the file-set\r\n  audit at [[CI-RIDER LANE STATE]]; new LINK output complied, existing gate-output estate remains.\r\n\r\n### IR-7 — Phase A rigs leak a daemon+brain pair on Windows (exe-lock kills notify relink)\r\n- **Status:** open · **Origin:** BAROMETER post-publish triage (ex releases#124 — full mechanism on the closed issue)\r\n- **What/why:** two Phase A rigs launch daemons that escape the job object via WMI-rung autostart\r\n  (double-space unquoted cmdline fingerprint; SPT_HOME in the wrapper cmdline is the attribution\r\n  key); the leaked pair holds target/debug/spt.exe and kills every golden job reaching the notify\r\n  relink. CI reaps as tourniquet (fa6e597); in-job test launch is the fix.\r\n- **LANE-LINKED 2026-08-30 (#242 close sweep):** hertz's queued daemon-leak fixup lane carries\r\n  this entry (brief cites IR-7/17/20/34/35/63); leaves the register when that lane lands.\r\n- **Ripe when:** next wave touching the Phase A rigs or daemon autostart path.\r\n- **Size:** medium.\r\n\r\n### IR-8 — reap-census scoped_survivors=0 is blind to unreadable-path holders\r\n- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane. · **Origin:** BAROMETER triage\r\n  (ex releases#122)\r\n- **What/why:** a zero that cannot see is not a zero — census scoping skips procs whose exe path is\r\n  unreadable, so the survivors count can report clean while a holder lives. Needs a positive control\r\n  / explicit unreadable bucket in the verdict line (unreadable_path count exists; the ZERO must\r\n  refuse when it is nonzero).\r\n- **Defining specimen (golden 30782259675, hfenduleam test job, 2026-08-03):**\r\n  `CI-REAP summary: killed=5 kill_failed=1 scoped_survivors=0` — an admitted kill failure printed\r\n  beside a zero-survivors claim on the same verdict line. The held image surfaced one step later:\r\n  run-scoped tmp cleanup denied 5/5 attempts on `...\\relshell\\svcmock.exe` (2nd appearance of the\r\n  svcmock hold; 1st @7a3c08c, pre-kill-auth). hertz's addendum: an image-held survivor also blocks\r\n  WRITES to the exe path — the same class manufactures build/relink access-denied reds that mask as\r\n  build problems, not just cleanup warnings. Not per-run: the same-sha green rerun's leg read\r\n  `kill_failed=0 scoped_survivors=0` throughout (hertz, 30784469908) — intermittent sighting,\r\n  second of its class, not a deterministic fixture property.\r\n- **The Linux twin is strictly worse (todlando audit 2026-08-04, vs `b7b00c3`):** `reap-census.sh`\r\n  has NO `kill_failed` anywhere (0 occurrences vs 2 in the `.ps1`) — its kill loop increments\r\n  `killed` only in the success branch with no else, so a failed kill increments nothing and prints\r\n  nothing. The specimen that made this class VISIBLE on Windows would be INVISIBLE on Linux.\r\n  Population precision so this is not overclaimed: ESRCH is benign (already gone; the kill-time\r\n  re-resolve makes it the common case); the vanishing case is EPERM against another account's\r\n  process. The `.sh` `scoped_survivors` DOES come from a post-reap census re-measure, so survivors\r\n  are measured — the hole is failed kills and the unreadable bucket, not the survivor count.\r\n  Windows precision from the same audit: `unreadable_path` IS on the CI-CENSUS line (:157) but the\r\n  CI-REAP verdict line (:243, :246) still carries only killed/kill_failed/scoped_survivors — the\r\n  zero still does not refuse, exactly this entry's ask.\r\n- **Built evidence:** both verdict lines now carry `unreadable_path`; any nonzero unreadable\r\n  family population renders `scoped_survivors=UNPROVEN` rather than a false zero. Linux also\r\n  counts and reports failed kills. The shared predicate is mutation-pinned by\r\n  `reap-census-selftest.sh`; the PowerShell implementation parses cleanly.\r\n- **Ripe when:** next census/reap script wave (natural pair with IR-7's lane) — now BOTH platforms.\r\n- **Size:** small.\r\n\r\n### IR-9 — Golden boxes run different clippy versions\r\n- **Status:** pin LANDED 2026-08-18 at `35968156` (`build: pin Rust 1.96.0`), then\r\n  audited **BUILT** at the 2026-08-29 v0.65.0 close sweep; the pin is an ancestor of\r\n  golden-green cut SHA `4d6007ac`. The earlier measurement half had already landed and run:\r\n  the toolchain print (`8ed006b` → `REQ-CI-TOOLCHAIN-VERSION-PRINT`) exercised both legs of\r\n  golden run 30971976024 (`test` jobs 92198170694/92198170700 — scoped to `test`, not n1-gate;\r\n  grep token `TOOLCHAIN `). Runner-account facts, read by doyle 2026-08-05: hfenduleam\r\n  `cargo/rustc 1.93.0` + `clippy 0.1.93`, kitsubito `cargo/rustc 1.96.0` +\r\n  `clippy 0.1.96`; `stable (default)` on both proved the skew would otherwise decay silently.\r\n- **RULING (doyle, 2026-08-05, on the runner-account facts as the 2026-08-03 hold required):**\r\n  (1) align-by-event REJECTED — with both boxes on unpinned stable, alignment decays silently;\r\n  the skew is a mechanism and the fix must be one too. (2) declare-one-leg REJECTED as the\r\n  terminal state — it repairs lint authority but leaves the legs resolving with different cargo\r\n  versions, and the acaaa4f lock-attribution question this family started from is a resolver\r\n  question. (3) **PIN IN-REPO: `rust-toolchain.toml`, `channel = \"1.96.0\"`** — both runner\r\n  accounts already resolve their toolchain through rustup (witnessed by the `active=` line), so\r\n  the pin self-applies with zero per-box maintenance, and the judge's version becomes a property\r\n  of the TESTED SHA — the same object golden CI already guarantees. Bumps become reviewed lane\r\n  commits, tested by the golden run they ride; the hfenduleam leg proves 1.96.0 on the pin\r\n  lane's own run. (4) INTERIM until the pin lands: kitsubito's clippy leg is AUTHORITATIVE for\r\n  lint disputes — not because newer is stricter (skew direction stays unasserted) but because\r\n  1.96 is the version the pin names, so interim and terminal rulings agree.\r\n  · **Origin:** BAROMETER (ex releases#121); re-confirmed on the #125 fix lane\r\n  (builder's Windows clippy vs kitsubito's rust-1.96.0 lints); see [[CI-RIDER LANE STATE]]\r\n- **What/why:** a Windows-clean lane can land a lint that only reds on the Linux leg — toolchain\r\n  skew makes local clippy evidence non-transferable. Align versions or declare the authoritative\r\n  leg. Natural companion to IR-4's toolchain-version print step.\r\n- **Built evidence / fulfilment check:** `rust-toolchain.toml` contains\r\n  `channel = \"1.96.0\"` and rode the tested cut. A source sweep at close found no CI or pool\r\n  machinery keyed to a box-default toolchain **path**: golden invokes `cargo`, `rustc`, `clippy`,\r\n  and `rustup show active-toolchain` through PATH; pool ownership keys on source-tree/lane identity,\r\n  not rustup installation paths. `release.yml`'s `$HOME/.cargo/bin/mdbook` is an installed tool\r\n  location, not a Rust toolchain selector; its builds still invoke PATH-resolved `cargo`.\r\n- **Size:** built.\r\n- **Composed:** LOCKSMITH (#132) CI-rider cluster (rides IR-4's toolchain-version print step) —\r\n  2026-08-03. GREENLIT with #132 and **DISPATCHED to hertz 2026-08-03**; that dispatch delivered\r\n  the measurement half (landed via [[CI-RIDER LANE STATE]], first exercised on run 30971976024).\r\n\r\n### IR-10 — Wave gate runs the CONSUMERS of any predicate it changes\r\n- **Status:** open · **Origin:** BAROMETER gate craft (ex releases#119)\r\n- **What/why:** legs chosen from changed crates miss the predicate's callers; a composed red is\r\n  triaged at the wave's own tip first. This is the gate-population rule made binding in the gate\r\n  runbook + scripts rather than living in memory.\r\n- **Ripe when:** next gate-runbook/docs wave.\r\n- **Size:** small (docs + gate-script checklist).\r\n\r\n### IR-11 — find-cwd-holders.ps1: --headless discriminator as a column\r\n- **Status:** open · **Origin:** worktree-pin triage tooling (ex releases#118)\r\n- **What/why:** the holder-triage script buries the headless-vs-interactive discriminator in prose;\r\n  as a column it makes the orphan-vs-own-shell call one glance.\r\n- **Ripe when:** any rig-tooling wave; trivial rider.\r\n- **Size:** tiny.\r\n\r\n### IR-12 — xtask contract-drift gate misses a stale manifest.schema.json\r\n- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane (the narrowed blind arm only). · **Origin:** ex\r\n  releases#116\r\n- **KIN NOTE RETIRED (2026-09-06, hertz; doyle measure-first ruling):** the stale-binary\r\n  premise was a rig artifact, not a reproduced product hole. At `9f809f8d`, in isolated Linux\r\n  worktree `hertz-ir12-mutation`, build `spt` once, mutate only its root CLI help string, do not\r\n  rebuild, then run `cargo run -p xtask -- check` alone: **exit 1**, combined output **3435 bytes**,\r\n  ending `xtask check: docs-site/src/cli/reference.md drifted from the binary's --help` (followed\r\n  by the regeneration instruction). The binary hash changed during check; the stale input was\r\n  rebuilt by `gen(true)` → `spt_bin` → `cargo build -q -p spt --bin spt` before comparison.\r\n  `CARGO_TARGET_DIR=UNSET`, `SPT_BLESS=UNSET`; Cargo's metadata target and xtask's read path both\r\n  resolve to this worktree's `target/debug/spt`. Source mutation was restored byte-for-byte.\r\n  Acceptance files: `~/spt-evidence/ir12-mutation-20260906/{check.exit,check.raw,env.txt}` on kitsubito.\r\n  The original rig mechanism remains unproven (old-mtime restoration or two target directories\r\n  are candidates, not findings). No product fix or permanent test added. IR-12 leaves the\r\n  register at the WEBSERVE close sweep.\r\n  The mandatory workspace-bins prebuild leg stays in every gate driver on its own merit (caught W2's spacerun red the night it was adopted); it is no longer justified by this note.\r\n- **What/why (corrected — the consequence sentence was false at `b7b00c3`):** the literal claim\r\n  holds — `xtask check` does not regenerate-and-compare the schema — but staleness does NOT \"ship a\r\n  wrong public contract silently\": `checked_in_schema_is_current`\r\n  (crates/spt-runtime/src/manifest.rs:2363, `int->REQ-DOCS-5`, landed `be4e46c` 2026-06-05, BEFORE\r\n  this entry's last sweep — docs lagging code) asserts full content equality of the checked-in\r\n  `manifest.schema.json` against what the derives generate, CRLF-normalised, `SPT_BLESS=1` as the\r\n  regenerate path. It is REACHED (lib unit test; ci.yml:114 runs `-E kind(lib)+kind(bin)` on push;\r\n  golden Phase A re-runs the workspace). Exactly ONE schema file exists in the tree; `docs_bundle`\r\n  (xtask main.rs:609-618) COPIES it at build time, so no second stored copy can drift. Chain closes:\r\n  derives → checked-in (unit-gated) → bundle (copied, not stored).\r\n- **What remains open, and the entry narrows to it:** `check_llms_links` (xtask main.rs:521)\r\n  hardcodes `manifest.schema.json` and `llms-full.txt` as always-existing, so the link check can\r\n  never see them MISSING — a blind arm, not a drift hole.\r\n- **The discrimination is now PROVEN, not presumed (todlando 2026-08-04, burn-the-build arms in\r\n  isolated worktree ir12-mutation @`11169c1`, env verified clear of `SPT_BLESS` FIRST — set, the\r\n  test short-circuits into a WRITE and a mutation arm silently self-heals green; that env check is\r\n  now part of the rig recipe):** arm 0 baseline PASS by NAME (1 test run); arm 1 semantic single\r\n  byte (title `…manifest`→`…manifesX`, length unchanged, scripted edit with match-count refusal)\r\n  REDS at manifest.rs:2374 exit 100 — \"manifest.schema.json drifted from the derives — regenerate\r\n  with SPT_BLESS=1\", with the mutated token appearing exactly once in 96,248 B of assertion output\r\n  so the byte is provably the only delta; arm 2 whitespace-only (CRLF→LF, 1014 endings) PASSES —\r\n  and arm 0 is itself the stronger normalisation proof, since the on-disk file is CRLF while the\r\n  generated string is LF, so an unmutated PASS is only possible because the test normalises; arm 3\r\n  restore re-measured PASS at the pristine sha256. `checked_in_schema_is_current` is a REAL gate.\r\n- **Built evidence:** `check_llms_links` resolves stored root assets to their\r\n  real source paths and runs the `llms-full.txt` generator instead of returning\r\n  hardcoded `true`. A unit cell proves a missing schema and install script are\r\n  refused, then accepted only after the real source file exists.\r\n- **Ripe when:** next xtask/docs-gate wave (now sized to the blind arm only).\r\n- **Size:** tiny.\r\n\r\n### IR-13 — Test-soundness follow-ups from the uniform-table sweep\r\n- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane. · **Origin:** ex releases#58\r\n- **What/why:** the remaining candidates from the closed issue were mutation-proved before changing\r\n  tests. `hold_outranks_everything` now walks all four `Opportunity` arms (including\r\n  `HoldRelease`); changing held+release to start reds on that arm. Pure walk tests cover all four\r\n  `QuiesceOutcome` arms and all five `EffectKind` arms; making `KillUnconfirmed` clear or\r\n  `Registry` ephemeral reds independently. The join test now binds all six `JoinFail` variants to\r\n  both hold retention and the emitted failure class/retry payload; misclassifying `WrongCode`\r\n  reds. The access candidates had already landed in the W4 follow-up and its dead-seam removal,\r\n  so the hygiene lane does not manufacture a second test vocabulary beside them.\r\n\r\n### IR-14 — .worktrees audit: \"how many worktrees are there\" has four defensible answers, and the difference is not junk\r\n- **Status:** open · **Origin:** ex releases#56 (was flag: NEEDS-OPERATOR in eval — operator input\r\n  now sought directly when the entry ripens, not via board flag)\r\n- **What/why:** the project `.worktrees/` dir accumulates content beyond what git tracks; audit +\r\n  reap recipe + a hygiene rule for lane close-out. Teardown discipline per docs and memory (classify\r\n  before delete, outbound links first).\r\n- **Release-close cleanup, 2026-09-11 (doyle, operator-requested):** removed **38 registered\r\n  worktree copies** whose heads were ancestors of released `16df0e41`, with no tracked changes,\r\n  untracked files, ignored files, target trees, or inbound links from the project-wide reparse\r\n  census. Branches and commits were retained; seven stale worktree registrations were repaired\r\n  with Git before ordinary, non-forced removal. This count is removals, NOT a census of all\r\n  remaining work. Dirty/unmerged/evidence-bearing lanes and the sync diagnostic trees stayed.\r\n  The broader home/Documents/projects cleanup also removed the reproducible N-1 checkout and\r\n  its separately classified target, an old release download, and generated scratch artifacts:\r\n  net free-space increase **4,532,350,976 bytes (4.22 GiB)**, ending at **83,382,472,704 bytes\r\n  (77.66 GiB)**. Concurrent machine activity makes this a net volume delta, not the sum of file\r\n  lengths. Receipt: `.spt/cleanup-20260911.json`. One cleanup discharges this audit instance,\r\n  not the recurring hygiene requirement; IR-14/26/27/49 are not closed by deletion.\r\n- ⚠ **The header of this entry previously read \"14 untracked orphan dirs vs 25 git-tracked\". Both\r\n  numbers were stale AND UNDATED**, so nobody could tell drift from error. Every count below is dated\r\n  and carries its command.\r\n\r\n#### THE COUNT DISAGREEMENT IS THE FINDING (measured 2026-08-03, todlando + doyle, main @`3efd7e6`)\r\n\r\nThree people measuring \"the worktrees\" got three answers. None was wrong; they answered three\r\ndifferent questions, and nothing in the tree states which one is meant:\r\n\r\n| answer | question it actually answers | command |\r\n|---|---|---|\r\n| **73** | all ENTRIES under `.worktrees/` | `ls -A .worktrees \\| wc -l` |\r\n| **52** | DIRECTORIES under `.worktrees/` | `ls -dA .worktrees/*/` |\r\n| **38** | registered worktrees INCLUDING the root checkout | `git worktree list` |\r\n| **37** | registered worktrees under `.worktrees/` | above, minus the root |\r\n\r\n**52 − 37 = 15 unregistered directories.** The 73 − 52 = **21 loose FILES** are covered below.\r\n\r\n**A count is only as good as its question.** Treat \"how many worktrees\" as under-specified until the\r\nanswer names its population — the same defect that made a naive `grep -rn` from the project root\r\ninflate a code count by **34.9×** (426 tracked `.rs` vs 14865 on disk excluding all `target/`), and\r\nmade that grep run past 120s while `git ls-files | xargs grep` returned instantly. **Scan roots and\r\npopulation definitions are the same class of error.** Use `git grep` / `git ls-files` for tracked\r\ncontent and `git worktree list --porcelain` for worktrees.\r\n\r\n#### THE 15 UNREGISTERED DIRECTORIES ARE FOUR DIFFERENT KINDS OF THING\r\n\r\n⛔ **CLASS A — LIVE BUILD POOLS, NOT ORPHANS. DO NOT DELETE.** 3 dirs, 13.2 GB. Each is the TARGET of\r\na junction that a REGISTERED worktree uses as its `target/`:\r\n\r\n| dir | inbound junction from | size | claim |\r\n|---|---|---|---|\r\n| `gate-target` | assembly-doorbell, doorbell-w1, doorbell-w2, doorbell-w3 | EMPTY | none |\r\n| `gate-target-render` | golden-render | 5.84 GB | `POOL-OWNER.json` → golden-render |\r\n| `gate-target-w4doc` | w4-cli-doc | 7.36 GB | none |\r\n\r\n**These are exactly the directories that read as obviously junk** — no `.git`, no source, leftover\r\nnames — and deleting one destroys a registered worktree's build pool and leaves a dangling junction.\r\n**Polarity was checked BEFORE classification, which is what caught it:** all 15 top-level dirs are\r\nREAL directories, none is itself a reparse point; the six junctions are **INBOUND**, at\r\n`<registered-worktree>/target`. See [[worktree-target-junction]], [[gate-worktree-target-disk]].\r\n\r\nTwo findings inside class A, neither of them a deletion question:\r\n- **`gate-target` has FOUR registered trees junctioned into ONE pool, with no `POOL-OWNER.json` at\r\n  all** — so nothing would refuse a second LIVE lane there. That is releases#103's exact hazard\r\n  sitting armed. The pool is also empty: someone reclaimed it and left four junctions aimed at a hole.\r\n- **`gate-target-render`'s `POOL-OWNER.json` carries only `owner_tree` and `written_by` — no pid and\r\n  no birth stamp.** A claim that cannot distinguish a live lane from a finished one is missing the one\r\n  property the claim mechanism exists to provide.\r\n\r\n**CLASS B — EMPTIED SKELETONS, ONE UNIFORM SHAPE.** 8 dirs, **0 files**: `acl-core`, `engine-room`,\r\n`ff-fastfollow`, `gate-23d5ceb`, `gate-ff`, `golden-a`, `golden-b`, `w2b-sender-stamp`. Every one is\r\nexactly `crates/spt-daemon/` and nothing else. **Eight independent removals stopping at the SAME\r\nrelative path is a mechanism, not litter.**\r\n\r\n**MECHANISM CORROBORATED LIVE, 2026-08-03:** a read-only PEB sweep of process CWDs during a running\r\n`spt-daemon` suite found ~20 processes — `spt_daemon-<hash>` test harnesses, `PING`, `cmd` — whose\r\nCWD was **exactly `<worktree>/crates/spt-daemon/`**, the precise path all eight skeletons froze at. A\r\n`git worktree remove` racing a straggler there deletes everything else and leaves that chain pinned.\r\nThe processes churn fast (all 17 sampled pids were gone within 30s, one already showing **pid reuse**\r\n— see [[pid-reuse-across-reboot]] for why a pid alone is never an identity), so the pin is a race, not\r\na steady state, and it recurs on every daemon-suite worktree.\r\n\r\n**CLASS C — FULLY EMPTY, no inbound junction.** 3 dirs, 0 bytes: `gate-41`, `gate-559632e`,\r\n`release-runbook-main-advance`. Class B with even the chain gone.\r\n\r\n**CLASS D — DELIBERATE SCRATCH, NOT RESIDUE.** 1 dir, 12 files, 50 KB: `_patches` — three `.patch`\r\nfiles with their `.untracked` manifests, plus `ir18-gate-logs/`. Modified the day before the audit,\r\ni.e. someone's working state.\r\n\r\n3 + 8 + 3 + 1 = 15.\r\n\r\n#### PIN STATE: NO SKELETON IS HELD TODAY (with a stated blind spot)\r\n\r\nRead-only PEB CWD sweep, 2026-08-03: **zero processes hold a CWD in any class-B or class-C\r\ndirectory** — every live pin was in `gate-ec5f38a` and `gate-main`, both REGISTERED and both running\r\nrigs at the time. So removal of B and C would succeed today; nothing is retrying it.\r\n\r\n⚠ **The sweep read 412 of 593 processes; 181 were unreadable** (elevated/system, no\r\n`PROCESS_VM_READ`). The no-pin result therefore holds over the READABLE population only. Cheap to\r\nre-run elevated before acting — [[absence-needs-sibling-probe]].\r\n\r\n#### THE LOOSE FILES: A SHARED LOCATION WITH NO STATED CONTRACT\r\n\r\n**21 loose files sit in `.worktrees/`** — gate logs (`gate-*.log`, `gate-559632e-log.txt`), rig\r\nscripts (`g6-curve.ps1`, `g6-postbounce.ps1`, `gate-w5-*.ps1`), and `gate-w5-notes.md`. **Nobody\r\ndeclared `.worktrees/` a log drop; it became one.** Same class as the memory index: a shared location\r\nwith no stated contract accumulates whatever anyone puts there, and **the first person to tidy it\r\ncannot tell residue from someone's working state** — class D is that risk already realised. The\r\nhygiene rule this entry owes should name where gate logs and rig scripts belong, not only how to reap\r\nworktrees.\r\n\r\n#### RECLAIM ARITHMETIC — AND WHY THIS ENTRY IS NOT THE DISK FIX\r\n\r\nClasses B, C and D together are **under 51 KB**. All 13.2 GB of the unregistered population is class\r\nA, behind live junctions. **An orphan sweep is not a disk-space remedy**, and reading it as one sends\r\nyou at the wrong target: on the audit date, free space was **12.5 GB against the 32 GB golden floor**\r\n([[free-space-floor-blocks-golden]]) while the two largest pools on the box were `gate-ec5f38a/target`\r\n(14.33 GB) and `gate-main/target` (28.12 GB) — **both REGISTERED, so both outside the orphan\r\npopulation entirely.** The disk question and the orphan question have different populations; answering\r\none correctly says nothing about the other.\r\n\r\n- **AUDIT EXECUTED 2026-08-30 (doyle, the v0.66.0→NOW-SIGNAL between-milestone window; full\r\n  output `wt-census-2026-08-30.txt` in the session scratchpad, method = this entry's own):**\r\n  four answers BEFORE the sweep: 85 entries / 85 dirs / 76 registered incl root / 75 under\r\n  `.worktrees` → 10 unregistered, 0 loose files (the 21 loose files of 08-03 are gone).\r\n  **The 08-03 headline populations have INVERTED:** zero pools and zero junctions exist under\r\n  `.worktrees` at all (every registered tree reads `target=none`; the reparse sweep found no\r\n  inbound junction) — class A is EMPTY, so the armed pool hazards this entry named are\r\n  currently unpopulated. Unregistered classified: 4 fully-empty (C), 3 `crates/spt-daemon`\r\n  skeletons (B — the mechanism's fingerprint again), `_patches` (D, kept — working scratch),\r\n  and TWO content-bearing checkout remnants (gate-signet-w1 10.8MB, gate-w1-a8f04aff 27MB) =\r\n  registry-pruned dirs held by the conhost CWD pins IR-63's third face names. **Sweep\r\n  executed on the gater's own rigs:** evidence preserved FIRST\r\n  (`spt-preserve\\audit-2026-08-30\\`: gate-w1-a8f04aff's 229 non-HEAD files as a verified\r\n  tarball; er-instrument's 115-line UNCOMMITTED instrument diff as a patch — that worktree\r\n  belongs to hertz's lane and was NOT touched beyond the read-only copy), 16 pinning conhosts\r\n  killed by pid after a fresh probe, 9 dead rigs removed. AFTER: **76 dirs = 75 registered +\r\n  `_patches`, fully reconciled; zero unexplained entries, zero pins.** Reclaim was ~38MB —\r\n  reconfirming this entry's arithmetic that the orphan sweep is hygiene, not a disk remedy.\r\n  Landed-classification caveat: `git cherry` patch-id reads conflict-resolved picks\r\n  as UNLANDED (emit-single-write, fix-206/208/209 all show UNLANDED with shipped content), so\r\n  the census's landed column is a datum, never a reap authorization.\r\n- **HYGIENE RULE (the text this entry owed, written 2026-08-30 while the loose-file population\r\n  is zero — the rule exists BEFORE it refills):** `.worktrees/` holds exactly two kinds of\r\n  entry: **registered worktrees** and **`_patches/`** (the one declared scratch location).\r\n  Nothing else. Gate/rig artifacts follow their lifetime: (1) driver scripts, exit/raw files,\r\n  and logs live INSIDE their rig's worktree for the rig's life — they leave WITH it, via the\r\n  preservation step (copy what the verdict cites into `spt-preserve/<occasion>/`, verified by\r\n  cmp or a listed tarball, restore cost stated) and never accumulate beside the rigs; (2)\r\n  anything meant to outlive its rig goes to the repo ROOT beside the verdicts and RCAs it\r\n  supports (the census/finding/JIT convention) or into `spt-preserve/` — never loose in\r\n  `.worktrees/`; (3) a file found loose in `.worktrees/` is treated as UNCLASSIFIED WORKING\r\n  STATE — moved to `_patches/` with a dated note, never deleted on sight (class D is the risk\r\n  realised). Lane close-out = `git worktree remove` + prune + the conhost CWD-pin check\r\n  ([[IR-63]] third face) when removal refuses; a registry-pruned dir left behind is a defect\r\n  to sweep, not a norm.\r\n- **Ripe when:** between-milestone idle window (it is a dev-box chore, zero product risk) — but the\r\n  class-A pool findings are armed hazards and do not wait for it.\r\n- **Size:** small for the sweep; the hygiene rule and the pool-claim gaps are separate small items.\r\n- **Field instance (hertz sweep, 2026-08-04 — an unclaimed pool found rather than reasoned about):**\r\n  `.worktrees\\gate-target-w4doc` held **7,907,558,098 B with NO POOL-OWNER.json at all**. Not a stale\r\n  claim, not a foreign claim — no claim. Exactly this entry's shape, first measured instance. Reaped\r\n  under doyle's ruling as part of [[IR-27]]'s two-step teardown; the measurement stands on its own.\r\n\r\n### IR-17 — Deadline-burn bring-up family: a test burns its full window while the daemon/brain never comes up\r\n- **Status:** open · **Origin:** golden 30782259675 red triage 2026-08-03\r\n- **What/why:** two different tests on two runner hosts now share one signature — bring-up misses\r\n  its ONLINE window under leg load and the test burns its ENTIRE deadline before the PRECONDITION\r\n  panic: `spt::resident_service_e2e::a_declared_service_rises_with_the_daemon_and_reaches_the_cli`\r\n  (hfenduleam, FAIL 123.99s, \"PRECONDITION: the daemon never came up\", run 30782259675, green on\r\n  same-sha rerun 30784469908) and `spt::activity_link_push_e2e` (kitsubito, full 30s, run\r\n  30607903133 specimen, green on same-sha rerun; its \"brain stderr EMPTY\" leg and its family\r\n  membership are both CORRECTED in the 2026-08-30 sweep update below — the kitsubito member is\r\n  CLOSED under a named mechanism).\r\n  Family reading, not one flake: same missed-window shape, host-independent, both mid-leg under\r\n  load. Cross-ref KNOWN-HAZARDS 5.13 — bring-up has a hard ONLINE budget with known sensitivity to\r\n  anything that stalls it (the blanket-fsync canary; `attach_wedge_e2e` guards that budget).\r\n- **State line (the discriminating datum, resident_service red):** `daemon_up=false boot_alive=true\r\n  boot_pid=Some(8920) rel_started=false broker_survived=false` — the boot process was ALIVE at\r\n  panic time and the daemon never reached up. Any characterization run records this line per run,\r\n  not the verdict (hertz protocol 2026-08-03).\r\n- **Read of that line, CORRECTED 2026-08-03 (hertz):** it is NOT \"started-but-never-bound\" (the\r\n  earlier reading here) and not \"never-started\" — it is **started, did work, then killed** —\r\n  CANDIDATE via [[IR-18]]. The daemon spawned its boot service and that service reached the CLI\r\n  (the spool holds its message), and `broker_survived=false`. The DISCRIMINATING field is\r\n  `broker_survived`: false in every killed round of the positive control, true in every healthy\r\n  round. **An earlier evidence leg here is RETRACTED (hertz, same night, off the negative arm he\r\n  ran before reporting; deployah, who had carried the leg into four register sites, swept every\r\n  placement): \"empty daemon.stderr.log = TerminateProcess signature\" was false — the stderr\r\n  block is empty on PASSING runs too, so it carries zero information in either direction; it\r\n  failed the discriminator question and does not support the kill read.** The kill read now rests\r\n  on the control's field-for-field reproduction and the IR-18 mechanism, not on the log.\r\n  Consequences: (a) the bring-up window is **exonerated for this specimen** — measuring it would\r\n  have measured nothing; (b) the candidate mechanism and its evidence now live in [[IR-18]]\r\n  (a sibling test's bare breadcrumb tree-kill), CANDIDATE — not reproduced, not proven;\r\n  (c) **the characterization population changed, and the rate run is CANCELLED** (doyle ruling\r\n  2026-08-03) — `resident_service_e2e` run ALONE has no sibling to collide with, so the mechanism\r\n  predicts 0/N and that number answers no live question; the only sound population was the test\r\n  INSIDE the Phase A parallel pool, which costs a full Phase A leg per sample, and the fix is\r\n  warranted by the source-verified hazard class regardless of the specimen's rate. No rate figure\r\n  will exist for this specimen — do not later read its absence as a low rate; (d) **positive\r\n  control still runs, falling out of the\r\n  hypothesis:** kill the spawned daemon by pid mid-bring-up — after boot-service spawn, before\r\n  ready — and it must reproduce the observed line field for field (`daemon_up=false\r\n  boot_alive=true broker_survived=false`). If the rig cannot make that shape on\r\n  demand, a 0/N from the untouched arm is worth nothing and must be reported as worth nothing.\r\n  The host-INDEPENDENT family claim (kitsubito's `activity_link_push_e2e`) is untouched by this:\r\n  it has no such kill site named, so the family survives even if this specimen leaves it.\r\n- **POSITIVE CONTROL RAN 2026-08-03 (hertz, prebuilt a5042ec binary, box confirmed clear —\r\n  0 open runs, 145.95 GB free): shape reproduced 3/3, deterministic.** Negative arm n=2: 2/2 PASS\r\n  (5.59s, 5.46s), `daemon_up=true boot_alive=true rel_started=true broker_survived=true\r\n  survived_teardown=true`. Positive arm (daemon killed by parent-scoped descent after\r\n  boot-service spawn, before ready) n=3: 3/3 FAIL (93.95/93.25/93.50s), state line identical to\r\n  the CI red in EVERY field except boot_pid (a pid, must differ), same panic, same site\r\n  (resident_service_e2e.rs:382). Structural fact the arm settled, and the refutation risk that\r\n  made it worth running: the boot service rises BEFORE brain.ready becomes readable — had the\r\n  order been reversed the arm would have produced daemon_up=true and refuted the mechanism.\r\n  CEILING MET, NOT EXCEEDED: the control used Stop-Process -Force (TerminateProcess — the same\r\n  primitive as taskkill /F), so it proves a forced daemon kill after breakaway-service spawn\r\n  produces this exact line ON DEMAND; it says nothing about WHO issued one in golden 30782259675.\r\n  Candidate mechanism, shape reproduced on demand — \"root caused\" written by nobody. Duration\r\n  note, recorded not explained: 93.5s local (idle box) vs 123.99s CI (Phase A parallelism), both\r\n  burning the same three 45s windows — consistent, not verified.\r\n- **Same-host sub-observation (hertz, host-CONSTANT — narrower claim, kept separate):** both\r\n  reds of 2026-08-03 sat on hfenduleam Windows Phase A and burned their full windows:\r\n  `a_tree_teardown_reaches_a_grandchild_the_service_spawned` (run 30776330383, FAIL 10.176s = the\r\n  full poll deadline, vs a 0.19–0.66s pass band — 15–50x out) + the resident_service row above.\r\n  MEMBERSHIP PROVISIONAL for the teardown row: it carries a candidate mechanism the bring-up burn\r\n  does not share — the pid-only oracle IR-15 just replaced. If the oracle caused it, that row\r\n  leaves the family and host-constant collapses to one sighting. The host-INDEPENDENT pair above\r\n  is the claim that survives someone fixing this box; the sub-observation is what is actionable\r\n  about hfenduleam (a live-daemon host) meanwhile. **UPDATE 2026-08-04 (golden 30873007187\r\n  attempt 1 — SECOND sighting, and the provisional question above is now ANSWERED): the\r\n  pid-only-oracle candidate is REFUTED for this row** — IR-15's authenticated repin rode the\r\n  failing tree (a5042ec ancestor of 4b37512) and the row failed anyway (10.225s, \"grandchild\r\n  51848 outlived the tree teardown\"), with is_stamped() asserted before the kill so the verdict\r\n  passed the authenticated gate. The row therefore STAYS a family member with its mechanism OPEN,\r\n  narrowed by hertz's log forensics (competence-controlled: the capture channel demonstrably\r\n  prints): no DETACH_BREAKAWAY_DENIED (breakaway rung taken), no SERVICE_JOB_UNAVAILABLE (job\r\n  created + child enrolled), no SERVICE_TREE_KILL_INCOMPLETE (TerminateJobObject returned\r\n  success) — everything enrolled died; THE SURVIVOR WAS NEVER ENROLLED. Two hypotheses,\r\n  inseparable in existing evidence: H1 test defect — the grandchild SELECTION is a bare\r\n  th32ParentProcessID match over a recycling pid space (IR-15's mechanism one level up: the\r\n  verdict was authenticated, the selection was not); H2 real enrollment gap. hertz's selection\r\n  probe (IsProcessInJob at selection time — decisive; birth stamp one-directional; image; same-\r\n  snapshot match count) is authored+compiled and makes the NEXT occurrence self-deciding. Row\r\n  state: INSTRUMENTED-AWAITING-FIRE; a green retires nothing (doyle-ruled). **UPDATE 2026-08-04\r\n  (USHER att3):** row green at 17f95a7 (retires nothing, per the ruling). New shape evidence while\r\n  waiting for the probe: BOTH archived reds sit AT the 10s poll bound (daemon.rs:2757) — 10.176s and\r\n  10.225s — while todlando's 200 off-CI passes under live-fleet load ran 1-4s, never near it. The\r\n  post-fix red is therefore BOUND-EXPIRY-shaped (kill fired; the pinned identity stayed\r\n  not-provably-gone past 10s — TerminateJobObject is async), not kill-wrong-shaped. The bound\r\n  question (is 10s right for a loaded runner) is parked with hertz's USHER package item 4 and must\r\n  not touch the kill path or spawn flags before the probe fires. See also the FLAKE-LEDGER row for\r\n  the false-repeat correction (the 10.176s red was the PRE-a5042ec bare-pid mechanism).\r\n- **Declared read (2026-08-03, rules the next red):** a same-sha green rerun is protocol-conclusive\r\n  for the GATE, not the class. No third silent sample — the next occurrence of this signature gets\r\n  an instrumented resident-service bring-up investigation (hertz), not a rerun.\r\n- **SWEEP UPDATE 2026-08-30 (#242/v0.66.0 close — three corrections, correct-by-replacement):**\r\n  (1) **The 2026-08-03 \"brain stderr EMPTY\" reading on the kitsubito specimen is a METER\r\n  ARTIFACT, not a silent brain** (deployah measured 2026-08-29): the brain-panel stderr capture\r\n  only LANDED 2026-08-19 (`ab657626` + `e6e188e1`), 16 days after the specimen — at the specimen's\r\n  sha there was nothing to capture, so \"empty\" carried zero information; current bits label\r\n  absence explicitly, so empty-vs-present cannot recur as a distinction. This replaces the\r\n  \"cheap to settle next time someone has kitsubito\" item — there is nothing left to settle.\r\n  (2) **The kitsubito family member is CLOSED under a NAMED mechanism:** RCA-242-R2-LINUX.md\r\n  (v0.66.0 golden r2) measured `current_exe_hash()` on the READY PATH at ~10.1s per boot on\r\n  kitsubito under load (~1.5s Windows) via BRAIN_PHASE breadcrumbs + harvest-loop repro — a\r\n  bring-up that misses its ONLINE window under leg load is exactly what a ~10s synchronous hash\r\n  inside the ready path manufactures. The behaviour-change request (hash off the ready path,\r\n  ADR-0018 Q7) is minted on the board at this sweep as **releases#244** (BACKLOG, operator\r\n  triages). The family's host-INDEPENDENT claim\r\n  therefore collapses: the Windows `resident_service_e2e` specimen (IR-18 kill-shape candidate)\r\n  and the hfenduleam sub-observation STAY OPEN as this entry's remaining live population.\r\n  (3) **Lane-linked:** hertz's queued fixup lane brief names this entry directly\r\n  (activity_link_push_e2e 4-cell fixup: false precondition message + progress-bounded readiness\r\n  wait, #235 shape). Overlap with correction (2) checked at link time: his cells are TEST-side\r\n  (message truth + wait shape) and stand regardless of the product-side hash fix.\r\n- **Ripe when:** next occurrence of the signature (immediate instrumented dispatch), or a hertz\r\n  test-hardening wave (bring-up phase-timing instrumentation, per-phase deadline attribution).\r\n- **Size:** medium (bring-up instrumentation + attribution; the fix depends on what it shows).\r\n\r\n### IR-16 — kill_tree discards TerminateJobObject/TerminateProcess returns (silent partial kill)\r\n- **Status:** BUILT 2026-08-03 (landed @62c5623 on the LOCKSMITH t1 lane; rides golden sha\r\n  b7b00c3, run 30860770146 green) · **Origin:** ex releases#130 (golden 30776330383 red triage;\r\n  deployah's log read\r\n  + todlando's flagged-not-asserted arm). Operator-classified infra 2026-08-02: daemon-kill\r\n  internals are agent-facing, not operator-facing surface.\r\n- **What/why:** `DetachedChild::kill_tree` (daemon.rs:1433 vicinity) calls\r\n  `unsafe { TerminateJobObject(self.job, 1) }` and discards the return; TerminateProcess likewise\r\n  unaudited. A job that was created and assigned at spawn but whose TERMINATION fails at kill time\r\n  yields the grandchild-survives symptom with zero log signal — the spawn-side\r\n  SERVICE_JOB_UNAVAILABLE announcement is correctly absent (that arm is instrumented and was\r\n  refuted for the specimen by a positively-controlled zero). Wanted: (1) check + log both\r\n  termination returns loudly on failure; (2) the degraded-arm decision — fallback process-table\r\n  tree-walk kill or explicit refusal, never a silent partial kill wearing REQ-RESIDENT-SERVICE's\r\n  unconditional promise. Do NOT add self.job==0 instrumentation (already loud; a second weaker\r\n  rule beside a working one). Discrimination pairing with [[IR-15]]: a red whose captured pid is\r\n  still ping.exe with no SERVICE_JOB_UNAVAILABLE in scope = this entry's arm.\r\n- **Ripe when:** RIPE NOW — IR-15 landed BUILT 2026-08-03 (its rig-side half), so this kill-side\r\n  half is the outstanding instrument; land with the next daemon-teardown wave or sooner.\r\n- **Size:** small.\r\n- **Composed:** LOCKSMITH (#132) — todlando product lane, with the `detached_no_inherit_env`\r\n  rename as cosmetic rider (IR-20's load-bearing-pid caution applies to any rig touch) —\r\n  2026-08-03. GREENLIT with #132 and **DISPATCHED to todlando 2026-08-03**, carrying IR-20's\r\n  load-bearing-pid precondition as a stated check (todlando reports whether the rig is touched\r\n  at all rather than silently skipping it).\r\n- **BUILT — fulfilment checked against the wanted list, not merely mapped to a commit** (doyle,\r\n  2026-08-04): `62c5623` satisfies (1) — both termination returns are now checked and the loss is\r\n  NAMED on failure, as the kill-time twin of the spawn-time `SERVICE_JOB_UNAVAILABLE` — and (2) by\r\n  the ruled LOUD REFUSAL arm rather than a tree-walk fallback, which [[IR-18]] measured blind in\r\n  exactly this failure state. The `self.job == 0` prohibition was honored: the new check is\r\n  `self.job != 0 && TerminateJobObject(...) == 0`, not a second weaker rule beside the working one.\r\n  The unix `ESRCH` quiet arm — which no Windows gate can see — is covered by `ec5f38a`. The\r\n  `detached_no_inherit_env` cosmetic rider did NOT land and was dropped at `de6a01d` on a MEASURED\r\n  false premise, not deferred. A Windows-specific finding rides the fix as a comment and is worth\r\n  keeping: `TerminateProcess` against a handle to an already-exited process returns 0 with\r\n  `GetLastError` 5 (`ERROR_ACCESS_DENIED`), so a naive check there fires on the ORDINARY path.\r\n\r\n### IR-18 — resident_service_e2e kills breadcrumb pids BARE (stale-breadcrumb tree-kill; kill-side twin of IR-15)\r\n- **Status:** BUILT 2026-08-04 — the named acceptance carrier RAN and the condition is DISCHARGED,\r\n  stated as the measurement rather than as the green board it sat on: LOCKSMITH's golden run\r\n  30860770146 (head `b7b00c3`, conclusion success) executed the changed test IN-POOL on BOTH\r","truncated":true,"truncatedBy":"lines","totalLines":6937,"totalBytes":72740,"outputLines":873,"outputBytes":72740,"lastLinePartial":false,"firstLineExceedsLimit":false},"totalLines":6937,"displayContent":{"text":"# Infra register — CI / build-pipeline debt\r\n\r\nOperator-ruled 2026-08-02: infrastructure and CI-pipeline work items live HERE, not on the\r\n`spt-bs-releases` board. The board carries product surface the operator triages; this register\r\ncarries what the gater triages. **Mandate: doyle sweeps this file at every milestone intake and\r\nevery release close, and composes ripe entries into waves/milestone riders.** An entry leaves\r\nthis file only by being built (link the lane) or being retired with a stated reason.\r\n\r\nEntry format: status · origin · what/why · trigger condition (what makes it ripe) · size guess.\r\n\r\nLast sweep: **2026-09-11, v0.69.0 RELEASE CLOSE — FULL REGISTER**, source `e5a2fed9`.\r\nAll **97 entries (IR-1–97, including headingless IR-31)** read in two disjoint ranges; audit\r\npopulation checked for missing/duplicate IDs (97 rows, 97 unique, zero missing). Per-entry\r\ntrigger and disposition evidence: `.spt/preserved/infra-close069-20260911/audit.json`.\r\nUNKNOWN means no qualifying event established, not a disproved trigger or a discharged debt.\r\n\r\n- **Release facts, not a blanket green:** v0.69.0 at `16df0e41`, counter **105**, Latest,\r\n  11 assets; #294 and all eight members DONE. Explicit operator SHIP overrode the known\r\n  sync-cell red at candidate `a9e786b2`; the release neither classifies nor closes that defect.\r\n  Source closeout: releases#294 comment **5628538587**. The scoped four-package `--lib` battery\r\n  passed **121/121**; push CI **34550282074** passed **3167 Windows units**, then failed the\r\n  END disk floor (**15,360,114,688 < 34,359,738,368 bytes**). Release build **34550300527**\r\n  succeeded. Earlier PR unit-red logs remain unavailable/cause-unclassified. These are separate\r\n  verdict objects; no pass substitutes for a red, missing specimen, or unexecuted acceptance.\r\n- **Close already-built work, retain residuals:** IR-1/4 stale unlanded headers reconciled to\r\n  their landed rider and recorded golden exercise. IR-66 CLOSED using its existing two-platform\r\n  gates and WEBSERVE satisfaction ruling. IR-73 CLOSED: eight post-checkout sites plus both\r\n  docs-floor rereads are present; IR-86 retains sizing/dependency debt. Other established\r\n  BUILT/RETIRED decisions stand. IR-18's deferred consolidation and IR-53/62's narrower\r\n  touch-triggered siblings remain carried; closing their built halves does not erase those.\r\n- **Do not redispatch existing implementations:** IR-26 build-side identity is committed,\r\n  but claim-time observation and old-reader issues remain; IR-29's first fix landed, later\r\n  rung faces remain; IR-33's 16 MiB CLI stack exists, acceptance/margin reconciliation remains.\r\n  IR-57 `pick-audit`, IR-59 `disk-floor`, and IR-46 workflow floor tokens exist; residual adoption\r\n  and receipt reconciliation are the work. IR-69's original product lane landed; #243 residuals\r\n  remain. IR-83's universal LAN-only prescription is superseded by IR-89's layer-specific box\r\n  proof. IR-89's next-golden trigger has fired; exact step acceptance still needs reconciliation,\r\n  not a second guard implementation or renewed operator permission.\r\n- **IR-92 stays OPEN:** core#215 shipped the documentation/register rider, NOT the product\r\n  remedy; core#217 is the separate brainread audit. `try_spt_hosted_inject` still lacks the\r\n  MSG_IN publisher. Deployah corrected comment **5628532753** in place and confirmed readback.\r\n  Inject coverage, relay publication ordering and per-msg-id exact-once are distinct obligations.\r\n- **Next-intake composition, owned by doyle until accepted:** hertz's driver/workflow package\r\n  takes IR-31/46/59/60/76/86/87/90/97: aggregate capacity, truthful producer status, existing\r\n  quiet-window contract, independent rendezvous clocks, and mandatory between-run identity\r\n  census. IR-88 adopts the already-proven prebuilt release-before-delete recipe; IR-64 remains\r\n  a separate operator capacity decision. No new loaded comparison before these prerequisites.\r\n  Hertz's lifecycle package retains IR-7/17/20/22/25/34/35/55/63/79/80; guard adoption must\r\n  distinguish unwinding from hard process death. IR-74/75 ride the next Linux box audit.\r\n  IR-85/95/96 are scoped diagnostic continuation, NOT budget widening or a load/disk diagnosis.\r\n  Todlando owns product-side IR-81/82/92 composition; #285's completion did not build IR-82's\r\n  predecessor record. Both builders are offline: existing briefs are delivered, unacknowledged,\r\n  and **not executing**. No board mutation or new run authorization is implied.\r\n- **Small seam riders remain explicit:** next tooling intake weighs IR-5/6/10/11/32/37/47/58/94\r\n  (IR-37 upstream release is not downstream adoption: golden still requests 0.2.0).\r\n  IR-93 remains a separate symbol-packaging decision before a release-workflow rider, not a\r\n  property proven by a successful release build. All other open entries retain their recorded\r\n  trigger, residual, and owner where named; the complete audit records each, not a sampled set.\r\n- **Cleanup is mitigation, not closure:** 38 clean merged worktrees and classified obsolete\r\n  artifacts removed; dirty/unmerged/retained evidence preserved. Net free-space change\r\n  **4,532,350,976 bytes**, ending **83,382,472,704 bytes** (concurrent-activity caveat).\r\n  `.spt/cleanup-20260911.json` is the receipt. Root-target and CI-debug reclaims are separate\r\n  earlier measurements, not additions to that net. IR-14/26/27/49 remain structurally OPEN.\r\n\r\n### Intake addendum — hosted-relay diagnostic capacity hold (2026-09-11)\r\n\r\nSourced C: free samples around the intake, each named by file: **19,260,395,520 bytes at\r\n03:02:33Z** (post-merge run 34556292801, unit job `FLOOR_END`, RED against the\r\n34,359,738,368-byte floor); **19,907,792,896 bytes at 07:09:57Z**\r\n(`.spt/preserved/todlando-pool-reclaim-20260911/before.json`); **191,756,984,320 bytes** after\r\ndeployah's three authorized target reclaims (`.spt/preserved/deployah-rca-reclaim-20260911/reap-results.json`:\r\nrca-base +11,461,189,632, rca-head +11,371,200,512, gate-293c +94,256,648,192 observed);\r\n**247,894,224,896 bytes at 08:39:20Z** (hertz, GetDiskFreeSpaceExW, during post-merge run\r\n34580045779). An earlier draft of this addendum attributed a 19,979,182,080-byte 07:00Z sample\r\nto hertz; hertz could not point at a file for it and the figure is withdrawn. Every sample is an\r\ninstant, not headroom (IR-46).\r\n\r\nRunner-target behaviour, inferred from three samples and not yet read from the workflow: the\r\nunit job went 83,420,217,344 -> 19,278,598,144 (run 34555345283) and 83,368,599,552 ->\r\n19,260,395,520 (run 34556292801) inside the job, and the runner's own target measured\r\n65,260,456,302 bytes at rest at 07:57Z (`remote-friction-304/capacity-ci-target.json`), so the\r\nrunner appears to purge and cold-rebuild its resident target per run. A post-merge run therefore\r\nadds no growth beyond that resident ~65 GB, and both reds above are resource reds on a box that\r\nsat at ~19 GB free from 03:02Z to 07:10Z: untested, not failed.\r\nThird sample, post-merge run 34580045779 on `b12d4619` (GREEN): `FLOOR_START` 249,872,142,336 at\r\n08:37:27Z, `FLOOR_END` 181,632,450,560 at 08:49:04Z — a 68.2 GB in-job drop while two #304 lanes\r\nwere also building (todlando's pool reached 4.26 GB in that window), consistent with the\r\npurge-and-rebuild inference and still not read from the workflow.\r\n\r\nThe 293-brain pool was deleted at 07:10:59Z with a receipt (+10,916,200,448 bytes observed, same\r\ndirectory as the sample above). The receipt does not record the executor; todlando's ledger says\r\nit was not him, and no executor is asserted here without a file.\r\n\r\nNo diagnostic fixture daemon/listener or fresh build for the hosted-relay experiment has started.\r\nThe isolated hosted-relay experiment is separate from #304 implementation and from the #294\r\ncause investigation. Carry its capacity planning under **IR-31/59/90**, not a new product\r\nrequest. Hertz owns identifying the minimum diagnostic target, reusable version-matched\r\nartifacts, estimated incremental build/temp footprint and the concrete socket/network isolation\r\ngap. Doyle owns matching that requirement to an owned pool and available capacity before\r\nauthorizing a build. A prebuilt-only route still needs isolation proof; a private home alone\r\ndoes not establish it. No unowned artifact deletion or live-daemon changes are authorized.\r\nControl, relay-replacement and mixed-version arms remain unexecuted.\r\n\r\nPrior sweep: 2026-09-06, v0.67.1 RELEASE CLOSE + WEBSERVE (#272) INTAKE (one delta pass; the 08-30\r\nfull pass stands) — shipped counter 103, tag == main == tested `04e32c8c`, golden 34017906638 att4\r\n9/9 on a QUIET box after three reds (:473 attach_link structural test defect; wtlock :147 under\r\nbuilder load; resident_service_e2e :664 ledgered leak row, 3rd occurrence) — the quiet-box arm is\r\nIR-76's origin. Enumeration by a read-only subagent into `REGISTER-SWEEP-0671-DRAFT.md` (75\r\nentries, 10 trigger-text candidates; IR-31 has NO `###` heading — its body sits under IR-30's,\r\nflagged, not normalized). Rulings: **IR-46 trigger FIRED and was MISSED** — `golden.yml` was\r\ntouched by `04e32c8c` itself (2-line HEAVY reclass on the respin) and no remedy was weighed; a\r\nrespin edit under a pre-registered hard stop is not a remedy window, so the entry gains that datum\r\nand is COMPOSED forward. **Composed: the floor trio IR-46 + IR-59 (log-the-floor half) + IR-73\r\n(8 literal-first sites) as ONE hertz workflow rider on WEBSERVE** (`ci.yml`/`golden.yml`/\r\n`release.yml`, thin PR off the golden path, before the WEBSERVE golden head so that head runs\r\nunder it); **IR-59's log-the-floor line ALSO rides IR-76's three-arm pre-flight on W0's driver\r\ntemplate** (todlando authors; free space recorded beside the floor check). **IR-66 residual (two\r\nfirst-chunk-needle members) = hertz WEBSERVE test rider** (two one-line edits). **IR-12 residual =\r\nW3 drift-gate rider** (hertz already holds W3's drift-gate riders). IR-67 satisfied at this intake\r\nby construction (`--no-fail-fast` in the W0 driver template; todlando's 2026-09-06 correction).\r\nIR-34 unchanged, lane-linked to hertz's `test/attach-relink-barrier` @`b976cc09` (thin PR queued\r\nbehind the release runs). NOT fired: IR-3 (a new stream family is neither endpoint lifecycle nor\r\ndaemon supervision), IR-48, IR-52 (DOCS-NITS item 2 is a parent-option placement filing, not a\r\ndeep-help divergence — adjacent, noted), IR-64 (att4 did not die at preflight; no operator ruling).\r\nBoard mints this arc: #277 (io-events seq reset), #278 (adapter update never prunes strings/),\r\n#279 (ER_HOSTED_PROBE on every bind), #280 (MSG_IN never published on the relay edge). Design\r\nrulings on the grill branch: ADR-0056 Am.1 (router precedence), ADR-0057 Am.1 (served root =\r\n`adapters/<adapter>/web/`), ADR-0058 Am.1 (#17 auto-serve, reference-served). No entries retired.\r\n\r\nPrior sweep: 2026-08-30, NOW-SIGNAL (#23) / v0.67.0 RELEASE CLOSE — shipped counter 102, tag ==\r\nmain-at-tag == tested `da71b785`, 9/9 golden att2 (att1 sole red = FLAKE-LEDGER :664\r\nteardown-leak row, ruled ledgered-class at triage — signature predates the diff — rerun\r\nnon-vacuity proven by cell re-execution; ledger row +1 with new data, stays OPEN; hertz\r\nIR-34/35 cluster strengthened). Same-day second sweep, so most composition state is the\r\nmorning's; deltas only: IR-59 gained the SEVENTH face (parallel-lane fill rate: 236.6 GB /\r\n3.5 h across four wave pools drove the box to 0.01 GB mid-close; per-wave pool reaping rule).\r\nIR-12 gained the stale-binary kin note (xtask reference-drift arm reads the ON-DISK spt binary;\r\nstructural remedy = the now-mandatory workspace-bins prebuild leg, adopted this arc after it\r\nalso caught W2's spacerun red). IR-63's conhost litter REPRODUCED on cue: 14 fresh CWD pins on\r\nthe four party trees at the same `crates/spt-daemon` relative path, killed by pid via the PEB\r\nprobe, all four worktrees then removed FIRST TRY — the pin-check-first party rule held\r\n(+58.2 GB; earlier emergency reap of the same wave's finished-lane targets +186.6 GB).\r\nTest-craft banked to memory, not entries: `cargo test -- <bare> --exact` runs NOTHING and exits\r\n0 (todlando's structural fix: names carry the filter token); Win32_Process CommandLine filters\r\nCANNOT answer a CWD-pin question (todlando's false-positive self-catch). Board mints this arc:\r\n#244/#246/#247/#254 (BACKLOG). #16/#17 discharged drops (detach + EVAL). IR-73's ci.yml/\r\nrelease.yml floor-site reorders did NOT ride this arc's workflow commits — still owed, next\r\ntouch. No entries retired.\r\n\r\nPrior sweep: 2026-08-30, SEMAPHORE (#242) / v0.66.0 RELEASE CLOSE — shipped counter 101, tag ==\r\nmain == tested `d931dd63`, 9/9 at one sha across two attempts; full-register pass executed from\r\n`REGISTER-SWEEP-242-DRAFT.md` (72 entries enumerated pre-golden, load-bearing claims re-measured\r\nin-tree). Rulings: IR-69 close-out re-census RAN and FOUND the entry's own predicted truncation\r\nblind spot LIVE (338 cli.rs + 2 main.rs shipping sites never censused; addendum on the entry,\r\nstays OPEN; residual conversion + generator fix + seam enforcement = releases#243, scoping\r\nreconciled on the issue; common-word matcher RULED a separate hertz test-side rider). IR-17\r\nthree corrections by replacement (08-03 kitsubito \"empty stderr\" = METER ARTIFACT — panel\r\ncapture postdates the specimen by 16 days; kitsubito family member CLOSED under the RCA-242\r\nexe-hash-on-ready-path mechanism, behaviour-change request minted as releases#244; Windows\r\nspecimen + hfenduleam sub-observation stay the live population). Daemon-leak cluster\r\nIR-7/17/20/34/35/63 LANE-LINKED to hertz's queued fixup lane (briefs in his spool cite the entry\r\nids). IR-57 first-real-assembly use appended (ASM-241: 6 picks, 5 MATCH / 1 LOSS reconciled\r\nbyte-for-byte to the deliberate resolution; its earlier \"figure correction rides next batch\"\r\nnote was STALE — the correction landed inline 2026-08-29, retired here). IR-46 gained the #242\r\ngolden additions (per-job floor instants; the `/runs/<id>/jobs` run_attempt trap with\r\n`started_at` discriminator + `/attempts/N/jobs` authority; raw-bytes rerun preflight;\r\nnon-vacuous rerun check). IR-59 gained the SIXTH face (r4 LNK1318 at the job's internal\r\nlow-water; within-job floor re-read rides the next workflow commit; box ~51 GB non-recovering\r\nconsumption → audit slot). FILED: IR-73 (ci.yml/release.yml literal-first floor sites off the\r\ngolden path, 8 sites), IR-74 (kitsubito 21,643 /tmp endpoint homes, hertz's measurement), IR-75\r\n(kitsubito treqs 127 vacuous leg — install-or-drop; IR-37 deliberately NOT reopened, different\r\nsurface). Composed: IR-14/26/27/49 as ONE between-milestone pool/worktree audit slot (window\r\nopen now); IR-11 + IR-33(a) as next-intake small riders; IR-59's log-the-floor half + IR-57's\r\nscripted audit stand as the next intake's tooling pair. IR-54 evidence noted: the #242 cut's\r\nunshaped-head intake miss (self-caught by deployah, shape-on-top `e4f52047`, 8th consecutive\r\nshape-inside-candidate) is another construction-not-discipline datum. No entries retired.\r\n\r\nPrior sweep: 2026-08-27, IO-PARSER (#22) INTAKE (wave map: `IO-PARSER-22-JIT.md` + #22 comment).\r\nRulings: IR-66 COMPOSED as the parallel hertz rider (the two attach-cell later-needle treatments,\r\nattach.rs:561/:672 — the \"rides next intake\" note comes due here). IR-52 conditional rider\r\nCARRIED FORWARD on this milestone's docs lane, same terms as WAX-SEAL (depth fix lands iff the\r\nlane touches the docs-site CLI reference generator, else stays open). IR-67 COMPOSED as JIT gate\r\ndiscipline (no wave battery leans on a `-p spt --bins` leg as integration coverage); the entry\r\nstays open until its named construction fix. IR-55 stays armed with hertz; IR-6 LOCKSMITH\r\ncomposition still unreported, stays; IR-2 trigger unevaluated this sweep (teardown just cleared\r\nthe unlanded-lane field — re-check next sweep). No entries retired; none filed.\r\n\r\nPrior sweep: 2026-08-23, WAX-SEAL (#21) INTAKE (wave map: `WAX-SEAL-21-JIT.md` + #21 comment\r\n5390092115). Rulings: IR-52 COMPOSED as a CONDITIONAL W4 rider on the wax-seal docs lane —\r\nthe milestone mints new nested `spt seal` CLI verbs, exactly the shallow-render class the entry\r\nnames; the depth fix lands iff that lane touches the docs-site CLI reference generator, else the\r\nentry stays open here. IR-2 trigger NOT met (todlando's PR set parked unlanded for the next\r\ngolden chain). IR-55 stays ARMED-FOR-CAPTURE with hertz. IR-6 conditional composition from\r\nLOCKSMITH still unreported — stays open. IR-56/57/58/59/60/61 are discipline/craft entries or\r\nawait their named triggers; IR-62 is hertz-class test/rig work, unscheduled. No entries retired;\r\nnone filed.\r\n\r\nPrior sweep: 2026-08-19, CONCIERGE (#183) INTAKE (wave map: `CONCIERGE-183-JIT.md` + #183\r\ncomment 5347768797) — rows read from the LOCAL register stack (`4799031→ecd640c→8d4c224`;\r\norigin/main lacks IR-49/50/51 until the chain lands — absence ≠ not-filed). Rulings: IR-50\r\nCOMPOSED — dispatched to hertz same day (sink-path-helper-FIRST sequencing per the entry;\r\n`engine_room_bringup_e2e.rs` excluded, its panel sites ride the gated #199 lane), with the\r\nengineroom.rs:145 misnomer as a rider on the same lane. IR-47 = candidate co-rider IF this\r\nchain touches golden.yml/ci-notify, else holds. IR-48 holds (next xtask parity-cell touch).\r\nIR-49 holds (next poolguard touch or first landed-lane takeover request). IR-51 holds —\r\ngated on #199 attribution; a net-off fix must NOT precede attribution. IR-2 trigger NOT met\r\n(queued unlanded lanes exist). No entries retired; none filed — the intake window's product\r\nfinding (rc terminal-Exit omission, hertz RCA: proven invariant violation, load excluded\r\n92/92, H2 candidate unconfirmed) routed to the BOARD as releases#201, the correct venue for\r\nproduct surface.\r\n\r\nPrior sweep: 2026-08-18, KEYSTONE (#182) INTAKE — the prior sweep's four composition rulings\r\nEXECUTED (wave map: `KEYSTONE-182-JIT.md`, base main @`8248bc3`): (1) IR-9 pin lane DISPATCHED to\r\nhertz (W0 item 1; interim kitsubito-clippy-authoritative dies when it lands). (2) IR-21 remedy\r\n(2) + IR-39 vs `f24e732` DISPOSED: the branch is a BEACHHEAD (golden.yml prebuild step = the\r\nprebuild-made-a-rule arm, ONE fail-fast site, one ledger row) — hertz rebases it off its\r\nabandoned parent `b483699` (the id-collision draft; content landed renumbered as IR-46 @`8248bc3`)\r\nand lands it in W0; the class remainder (IR-39's SHARED precondition helper + 24-site sibling_bin\r\nsweep, the 33 cross-package build-edge expressions) folds into the test-hygiene lane. (3)\r\nTest-hygiene family DECIDED-ACTIVATED as a dedicated hertz lane inside the KEYSTONE window,\r\nsequenced after W0 (members: IR-13/23/36/37/38 + IR-21 clarity half + IR-39 helper +\r\ntwohost.rs:394 doc comment). (4) First-execution-cells discipline restated in the JIT's\r\ngolden-head step. Board members #84/#85 ride hertz's W0; #166/#57/#185 are todlando's W1. IR-46\r\nid-collision RULED this intake (renumber-and-land, parallel issuance not authored disagreement;\r\ndeployah landed it @`8248bc3`). No new entries filed; no entries retired.\r\n\r\nPrior sweep: 2026-08-19, NAMEPLATE (#181) / v0.56.0 RELEASE CLOSE — shipped c91 @`60d74ea`\r\n(tag == golden-tested sha, run 32209922535; one respin, both first-golden reds ruled rig defects).\r\nFiled IR-42 (pool-claim writes / build enforces — BUILT in this same commit, AGENTS.md line),\r\nIR-43 (knock NoReply past its 30s carrier bound), IR-44 (perch-sentinel comment overclaims\r\npreservation), IR-45 (twohost rig home premise; SETTLED + RETIRED\r\n2026-08-19 — pump paths resolve under the per-run temp root, see the entry; #189 corrected on the\r\nboard, comment 5337519936). Two cycle findings ruled RUNBOOK-homed and\r\nlanded in this commit rather than as entries: the first-execution-cells intake question\r\n(RELEASE-RUNBOOK golden-head intake — name the never-executed cells before the run) and\r\ndeployah's sweep-vs-cascade mechanism (RELEASE-RUNBOOK board step — under golden CI the cascade\r\nis DRIVEN via `state <mref> acceptance`, never swept). ⚠ LABELLED HOLE — CLOSED UNDERIVABLE\r\n(2026-08-19): the close commune's batch list named \"alchemy create-races\"; its content did not\r\nsurvive the author's context reset and was not recoverable from #181, the JIT records, or memory.\r\nDeployah answered the query: he ran ZERO create ops at the cut (could not have witnessed a create\r\nrace), a fresh probe over the milestone window shows no duplicate mints (the 4-issues-in-2s batch\r\nmint is batching, not duplication), and the only surviving trace is doyle's own pre-reset message\r\nnaming the item as already-known — a pointer, not a sighting. Item DROPPED; the hole stands as\r\nthe record. Deployah's sweep-vs-cascade ship-path trap (#181 comment 5337402639, runbook-homed\r\nabove) is explicitly NOT this item's content — do not fold it in. Composition: IR-9's pin lane\r\n(`rust-toolchain.toml` @ 1.96.0) goes to hertz AT KEYSTONE #182 INTAKE per the 2026-08-05\r\nruling; IR-21 remedy (2) + IR-39's precondition helper compose with hertz's standing\r\nfixture-prebuild-hardening branch `f24e732` — disposition at the same intake; the test-hygiene\r\nfamily (IR-13/23/36/37/38 + IR-21's clarity half) stays the dedicated post-batch lane candidate,\r\ndecision at intake; IR-29's proving run + IR-30's instrument lanes ride the next golden batch.\r\nIR-2's trigger explicitly NOT met (queued unlanded lanes exist: IR-29/IR-30 instruments,\r\nfour-arm refusal eprintln, f24e732). IR-14 hygiene movement: `.worktrees/nameplate-asm-2bd36f1`\r\nreaped this sweep (+66.98 GB by FS delta 120.53→187.51; claim `gate-w7-courtesy` base `fd3dc5a`\r\nin main = finished lane; zero inbound reparse points) — stale-lane audit itself still open.\r\n\r\nPrior sweep: 2026-08-05, LOCKSMITH tranche-2 (#141) CLOSE — golden run 30971976024 green on all 9\r\njobs, main ff'd to `0a25b77`, v0.55.0. IR-40 filed (stale-resume-brief + early-informant class).\r\nIR-9's decision trigger FIRED 2026-08-05: doyle read the runner-account versions off this run's\r\n`test` legs and RULED — pin in-repo via `rust-toolchain.toml` @ 1.96.0, kitsubito's clippy leg\r\nauthoritative in the interim; pin lane to hertz at next intake (see the entry). IR-41 filed the\r\nsame night (queued main run superseded without a record; runbook step 3 corrected in the same\r\ncommit). IR-1/IR-4's golden-only steps (link probe both boxes, toolchain\r\nprint both legs) had their FIRST EXERCISE here, discharging the \"unexercised until a golden run\"\r\ncaveat at the CI-RIDER LANE STATE foot section. IR-35's re-measure rode the batch (`c65b838`).\r\nOwlery-noun thin lane SCOPED and dispatched to hertz for the next batch (class A only, two sites;\r\nclass B on-disk rename is an explicit non-goal — see IR-40's kin discipline for why the boundary is\r\nwritten into the brief rather than left to judgement).\r\n\r\n---\r\n\r\n## OPEN\r\n\r\n### IR-1 — Quiet predicate needs a network axis (tailscale RTT probe)\r\n- **Status:** BUILT AND LANDED — reconciled at [[CI-RIDER LANE STATE]]; golden-only exercise\r\n  recorded at the 2026-08-05 close (30971976024). Header corrected 2026-09-11. Originally\r\n  carried by `bf8c4a2` → `REQ-CI-LINK-HEALTH-PROBE`, mapping CONFIRMED by builder hertz 2026-08-03\r\n  (by content: tailscale ping ×5, med/max RTT rows into the bench ledger, three arms\r\n  success/NO-REPLY/UNAVAILABLE, always exit 0 — instrument, not gate). NOTE `bf8c4a2` is NOT\r\n  single-purpose: it also corrects the free-space preflight floor read\r\n  (`REQ-CI-FREE-SPACE-PREFLIGHT`, the ci-runner-has-no-warm-target shape) — no 1:1 commit→IR map\r\n  for this commit · **Origin:** golden/bench-wiring red triage 2026-08-02 (ex releases#126)\r\n- **What/why:** the shared-runner quiet predicate (zero non-terminal runs + no local\r\n  cargo/rustc/nextest by parent chain) is process-shaped; both axes passed on a box whose only\r\n  link was degrading (321s for a 1s checkout, bidirectional 10s QUIC dial timeouts). A tailscale\r\n  RTT probe to the peer box before two-host rendezvous, carried in the bench ledger, would have\r\n  called run 30771155390's red in seconds. Evidence: the arm-1 count table (PUMP_PEER_FAIL\r\n  a 0→3→0, b 8→22→8 across green/red/rerun).\r\n- **Permanent, not stopgap:** operator-confirmed 2026-08-02 that kitsubito cannot be provided\r\n  ethernet — wifi-only indefinitely, so the link cannot be hardened and the predicate must see\r\n  link health.\r\n- **Ripe when:** next CI-touching wave, or the next network-shaped golden red — whichever first.\r\n- **Size:** small (one probe step + ledger row + predicate doc).\r\n- **Composed:** LOCKSMITH (#132) CI-rider cluster, hertz thin lane — 2026-08-03. GREENLIT with\r\n  #132 and **DISPATCHED to hertz 2026-08-03** (direct brief; the register is the spec, there is no\r\n  board issue). Leaves the register only when the lane lands or the entry is retired.\r\n- **FIRST FIELD USE, and it DISCRIMINATED (2026-08-04, golden 30873007187 attempt 1):** the probe\r\n  (landed via the rider lane, riding `4b37512`) read 4–7ms RTT healthy on both twohost legs\r\n  minutes before both legs redded — REFUTING the degraded-link read for that red and steering\r\n  triage to the real mechanism (the [[IR-29]] serve-window race) instead of a link chase. The\r\n  instrument's first catch was a correct NEGATIVE — exactly the call run 30771155390 needed and\r\n  could not make.\r\n\r\n### IR-2 — Settle the warm-runner CARGO_INCREMENTAL delta\r\n- **Status:** RETIRED 2026-08-28, measurement run, verdict NO FLIP — incremental stays ON.\r\n  hertz paired goldens at main fed965f8: ON run 33167693879 GREEN; OFF run 33172022108 RED\r\n  (Windows input_ack_deadlock SetupFailed at a 3.0s IPC read deadline — the box-load family,\r\n  discarded with the leg). Disk: OFF target 7.49 GB vs ON 11.40 GB = 3.91 GB / 34.3% saved\r\n  (smaller than the entry's 5.65 GB cold figure). Timing NOT causal-quality: sequential runs in\r\n  one persistent workspace let OFF inherit ON's cache (order contamination dominates the\r\n  apparent OFF speedups); Windows build-spt-bin +3.8%, Linux -5.1%. Retire reasoning: the\r\n  DECISION is answerable now — OFF produced no green golden, the timing question needs 4+\r\n  counterbalanced fresh-cache windows to answer cleanly, and the disk motivation has weakened\r\n  (box at ~148 GB free under the teardown discipline; the LNK1318 pressure era predates it).\r\n  Runs/artifacts preserved on the record. Reopen only if runner disk pressure returns as a\r\n  recurring floor-class red.\r\n- **Was:** open · **Origin:** #103/#108 bench-wiring lane 2026-08-02 (ex releases#127)\r\n- **What/why:** the #103 measurement (−29.8% wall, −5.65 GB/target, n=3) is COLD-build only.\r\n  Golden's runner `_work` target persists warm, where incremental is exactly what keeps it cheap;\r\n  CARGO_INCREMENTAL=0 was applied only to the genuine cold build (n1-gate pinned old-broker\r\n  cache) + local rig recipes (docs/GOLDEN-CI.md). Open question: does incremental still pay on\r\n  the warm runner, weighed against 5.65 GB/target on a box with LNK1318 free-space history?\r\n- **Method (hertz):** one full golden each way on a quiet box, outside a milestone, compared\r\n  per-step from the bench ledger.\r\n- **Ripe when:** a quiet between-milestone window with no queued lanes (the measurement burns\r\n  two golden windows).\r\n- **Size:** medium (two proving runs + verdict + possible leg flips).\r\n\r\n### IR-3 — Daemon-level guard: broker-net wakeup rate bounded across endpoint churn\r\n- **Status:** open · **Origin:** releases#125 remediation, todlando REQ call 1 (ex releases#128)\r\n- **What/why:** the swarm-discovery GC-spin burned two cores for two weeks visible only in a\r\n  process table — no suite assertion sees the class. Wanted: a daemon-level assertion that\r\n  broker-net workers stay quiescent across repeated endpoint create/destroy churn.\r\n- **Design constraint (pre-ruled):** assert on WAKEUP RATE / voluntary ctxt-switch delta over\r\n  the churn window, NOT %CPU — CPU thresholds flake under CI load; the defect signature\r\n  (~100 Hz per orphan loop) is load-independent. Mint the REQ at activation.\r\n- **Near-product:** this is runtime-defect visibility, the most product-adjacent entry here —\r\n  a candidate rider on any daemon-lifecycle milestone.\r\n- **Ripe when:** the next milestone touching spt-net endpoint lifecycle or daemon supervision.\r\n- **Size:** medium (churn harness + counter plumbing + flake-safe assertion).\r\n\r\n### IR-4 — Lock-pin guard + lock-procedure rule + toolchain print (three riders, one lane)\r\n- **Status:** BUILT AND LANDED — `1275e47` / `49d4805` / `8ed006b` mapped and landed in the\r\n  [[CI-RIDER LANE STATE]] reconciliation; golden toolchain-print exercise recorded at the\r\n  2026-08-05 close (30971976024). Stale unlanded header corrected 2026-09-11. ·\r\n  **Origin:** releases#125 fix-lane intake hold (ex releases#129 + riders)\r\n- **What/why, three parts that land together:**\r\n  1. **xtask check leg:** assert Cargo.lock resolves swarm-discovery to git rev\r\n     `89a2200d54a4e3cab2f46cc75ebff49a1fb07614` while the patch is load-bearing; the check's\r\n     message states its own drop condition (upstream ships a post-PR#27 release AND iroh's pin\r\n     reaches it). Without it, stanza removal or a routine iroh bump silently returns the lock to\r\n     the spinning crate and nothing reds.\r\n  2. **Procedure rule for lock-touching lanes** (docs): targeted `cargo update -p <crate>` only,\r\n     never full re-resolve; count changed `[[package]]` blocks AND diff per-block edges (set-identical\r\n     hid 8 windows-sys edge movers at acaaa4f); two resolutions disagreeing = toolchain drift —\r\n     stop and compare against CI before shipping either lock; hand-edited lock acceptable iff\r\n     `cargo check --workspace --locked` passes.\r\n  3. **Toolchain-version print step in golden** (cargo/rustc versions, both OS legs): the acaaa4f\r\n     comparison against CI was impossible because no run log prints a version. One-grep audit.\r\n- **Ripe when:** next CI-touching wave; part 1 sooner if any iroh bump is proposed.\r\n- **Size:** small-medium (one xtask leg, one docs section, one workflow step).\r\n- **Composed:** LOCKSMITH (#132) CI-rider cluster, hertz thin lane — 2026-08-03. GREENLIT with\r\n  #132 and **DISPATCHED to hertz 2026-08-03** (all three parts land together).\r\n\r\n### IR-5 — Shared nextest summary parser\r\n- **Status:** open · **Origin:** BAROMETER triage (standing recommendation, pre-register)\r\n- **What/why:** two agents in one day wrote `[0-9]+ tests run` parsers that read \"1 test run\"\r\n  (singular) as zero — a guard fed by a broken parser condemns valid rounds. One shared,\r\n  singular-aware parser (single-source discriminant) for every consumer of nextest summaries.\r\n- **Ripe-when REWORDED 2026-08-04 (todlando audit): the old trigger was unfireable as worded.** At\r\n  `b7b00c3` the in-tree population of nextest-SUMMARY parsers is ZERO — the two scripts that read\r\n  nextest output (`g6-curve.ps1:83-90` per-test lines, `g6-postbounce.ps1:44` display-only grep)\r\n  neither parse counts nor carry the defect, so \"next wave touching any gate script that reads\r\n  nextest output\" could fire on a non-defective script while the real population (agent-authored\r\n  throwaway parsers, which never enter the tree) stays out of reach. New trigger: **the next time\r\n  anyone — agent or lane — needs a nextest summary COUNT**, the shared parser is built FIRST and the\r\n  need consumes it; rig briefs should name it so throwaways stop being authored.\r\n- **Size:** small.\r\n- **Composed:** LOCKSMITH (#132) CI-rider cluster, CONDITIONAL — lands iff the hertz thin lane\r\n  touches gate scripts; otherwise stays open here. 2026-08-03. Carried in hertz's 2026-08-03\r\n  dispatch brief as a **conditional** rider. **Condition NOT MET**, answered by the file-set\r\n  audit at [[CI-RIDER LANE STATE]]; remains open for its next count-consuming use.\r\n\r\n### IR-6 — Membership logging on subnet gates\r\n- **Status:** open · **Origin:** BAROMETER triage (standing recommendation, pre-register)\r\n- **What/why:** counts beside results, membership beside counts — gate logs that state a count\r\n  without naming the population keep producing unreadable reds. Standardize membership\r\n  enumeration in gate output.\r\n- **Ripe when:** next wave touching gate scripts / CI legs that report counts.\r\n- **Size:** small.\r\n- **Composed:** LOCKSMITH (#132) CI-rider cluster, CONDITIONAL — lands iff the hertz thin lane\r\n  touches gate scripts; otherwise stays open here. 2026-08-03. Carried in hertz's 2026-08-03\r\n  dispatch brief as a **conditional** rider. **Condition NOT MET**, answered by the file-set\r\n  audit at [[CI-RIDER LANE STATE]]; new LINK output complied, existing gate-output estate remains.\r\n\r\n### IR-7 — Phase A rigs leak a daemon+brain pair on Windows (exe-lock kills notify relink)\r\n- **Status:** open · **Origin:** BAROMETER post-publish triage (ex releases#124 — full mechanism on the closed issue)\r\n- **What/why:** two Phase A rigs launch daemons that escape the job object via WMI-rung autostart\r\n  (double-space unquoted cmdline fingerprint; SPT_HOME in the wrapper cmdline is the attribution\r\n  key); the leaked pair holds target/debug/spt.exe and kills every golden job reaching the notify\r\n  relink. CI reaps as tourniquet (fa6e597); in-job test launch is the fix.\r\n- **LANE-LINKED 2026-08-30 (#242 close sweep):** hertz's queued daemon-leak fixup lane carries\r\n  this entry (brief cites IR-7/17/20/34/35/63); leaves the register when that lane lands.\r\n- **Ripe when:** next wave touching the Phase A rigs or daemon autostart path.\r\n- **Size:** medium.\r\n\r\n### IR-8 — reap-census scoped_survivors=0 is blind to unreadable-path holders\r\n- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane. · **Origin:** BAROMETER triage\r\n  (ex releases#122)\r\n- **What/why:** a zero that cannot see is not a zero — census scoping skips procs whose exe path is\r\n  unreadable, so the survivors count can report clean while a holder lives. Needs a positive control\r\n  / explicit unreadable bucket in the verdict line (unreadable_path count exists; the ZERO must\r\n  refuse when it is nonzero).\r\n- **Defining specimen (golden 30782259675, hfenduleam test job, 2026-08-03):**\r\n  `CI-REAP summary: killed=5 kill_failed=1 scoped_survivors=0` — an admitted kill failure printed\r\n  beside a zero-survivors claim on the same verdict line. The held image surfaced one step later:\r\n  run-scoped tmp cleanup denied 5/5 attempts on `...\\relshell\\svcmock.exe` (2nd appearance of the\r\n  svcmock hold; 1st @7a3c08c, pre-kill-auth). hertz's addendum: an image-held survivor also blocks\r\n  WRITES to the exe path — the same class manufactures build/relink access-denied reds that mask as\r\n  build problems, not just cleanup warnings. Not per-run: the same-sha green rerun's leg read\r\n  `kill_failed=0 scoped_survivors=0` throughout (hertz, 30784469908) — intermittent sighting,\r\n  second of its class, not a deterministic fixture property.\r\n- **The Linux twin is strictly worse (todlando audit 2026-08-04, vs `b7b00c3`):** `reap-census.sh`\r\n  has NO `kill_failed` anywhere (0 occurrences vs 2 in the `.ps1`) — its kill loop increments\r\n  `killed` only in the success branch with no else, so a failed kill increments nothing and prints\r\n  nothing. The specimen that made this class VISIBLE on Windows would be INVISIBLE on Linux.\r\n  Population precision so this is not overclaimed: ESRCH is benign (already gone; the kill-time\r\n  re-resolve makes it the common case); the vanishing case is EPERM against another account's\r\n  process. The `.sh` `scoped_survivors` DOES come from a post-reap census re-measure, so survivors\r\n  are measured — the hole is failed kills and the unreadable bucket, not the survivor count.\r\n  Windows precision from the same audit: `unreadable_path` IS on the CI-CENSUS line (:157) but the\r\n  CI-REAP verdict line (:243, :246) still carries only killed/kill_failed/scoped_survivors — the\r\n  zero still does not refuse, exactly this entry's ask.\r\n- **Built evidence:** both verdict lines now carry `unreadable_path`; any nonzero unreadable\r\n  family population renders `scoped_survivors=UNPROVEN` rather than a false zero. Linux also\r\n  counts and reports failed kills. The shared predicate is mutation-pinned by\r\n  `reap-census-selftest.sh`; the PowerShell implementation parses cleanly.\r\n- **Ripe when:** next census/reap script wave (natural pair with IR-7's lane) — now BOTH platforms.\r\n- **Size:** small.\r\n\r\n### IR-9 — Golden boxes run different clippy versions\r\n- **Status:** pin LANDED 2026-08-18 at `35968156` (`build: pin Rust 1.96.0`), then\r\n  audited **BUILT** at the 2026-08-29 v0.65.0 close sweep; the pin is an ancestor of\r\n  golden-green cut SHA `4d6007ac`. The earlier measurement half had already landed and run:\r\n  the toolchain print (`8ed006b` → `REQ-CI-TOOLCHAIN-VERSION-PRINT`) exercised both legs of\r\n  golden run 30971976024 (`test` jobs 92198170694/92198170700 — scoped to `test`, not n1-gate;\r\n  grep token `TOOLCHAIN `). Runner-account facts, read by doyle 2026-08-05: hfenduleam\r\n  `cargo/rustc 1.93.0` + `clippy 0.1.93`, kitsubito `cargo/rustc 1.96.0` +\r\n  `clippy 0.1.96`; `stable (default)` on both proved the skew would otherwise decay silently.\r\n- **RULING (doyle, 2026-08-05, on the runner-account facts as the 2026-08-03 hold required):**\r\n  (1) align-by-event REJECTED — with both boxes on unpinned stable, alignment decays silently;\r\n  the skew is a mechanism and the fix must be one too. (2) declare-one-leg REJECTED as the\r\n  terminal state — it repairs lint authority but leaves the legs resolving with different cargo\r\n  versions, and the acaaa4f lock-attribution question this family started from is a resolver\r\n  question. (3) **PIN IN-REPO: `rust-toolchain.toml`, `channel = \"1.96.0\"`** — both runner\r\n  accounts already resolve their toolchain through rustup (witnessed by the `active=` line), so\r\n  the pin self-applies with zero per-box maintenance, and the judge's version becomes a property\r\n  of the TESTED SHA — the same object golden CI already guarantees. Bumps become reviewed lane\r\n  commits, tested by the golden run they ride; the hfenduleam leg proves 1.96.0 on the pin\r\n  lane's own run. (4) INTERIM until the pin lands: kitsubito's clippy leg is AUTHORITATIVE for\r\n  lint disputes — not because newer is stricter (skew direction stays unasserted) but because\r\n  1.96 is the version the pin names, so interim and terminal rulings agree.\r\n  · **Origin:** BAROMETER (ex releases#121); re-confirmed on the #125 fix lane\r\n  (builder's Windows clippy vs kitsubito's rust-1.96.0 lints); see [[CI-RIDER LANE STATE]]\r\n- **What/why:** a Windows-clean lane can land a lint that only reds on the Linux leg — toolchain\r\n  skew makes local clippy evidence non-transferable. Align versions or declare the authoritative\r\n  leg. Natural companion to IR-4's toolchain-version print step.\r\n- **Built evidence / fulfilment check:** `rust-toolchain.toml` contains\r\n  `channel = \"1.96.0\"` and rode the tested cut. A source sweep at close found no CI or pool\r\n  machinery keyed to a box-default toolchain **path**: golden invokes `cargo`, `rustc`, `clippy`,\r\n  and `rustup show active-toolchain` through PATH; pool ownership keys on source-tree/lane identity,\r\n  not rustup installation paths. `release.yml`'s `$HOME/.cargo/bin/mdbook` is an installed tool\r\n  location, not a Rust toolchain selector; its builds still invoke PATH-resolved `cargo`.\r\n- **Size:** built.\r\n- **Composed:** LOCKSMITH (#132) CI-rider cluster (rides IR-4's toolchain-version print step) —\r\n  2026-08-03. GREENLIT with #132 and **DISPATCHED to hertz 2026-08-03**; that dispatch delivered\r\n  the measurement half (landed via [[CI-RIDER LANE STATE]], first exercised on run 30971976024).\r\n\r\n### IR-10 — Wave gate runs the CONSUMERS of any predicate it changes\r\n- **Status:** open · **Origin:** BAROMETER gate craft (ex releases#119)\r\n- **What/why:** legs chosen from changed crates miss the predicate's callers; a composed red is\r\n  triaged at the wave's own tip first. This is the gate-population rule made binding in the gate\r\n  runbook + scripts rather than living in memory.\r\n- **Ripe when:** next gate-runbook/docs wave.\r\n- **Size:** small (docs + gate-script checklist).\r\n\r\n### IR-11 — find-cwd-holders.ps1: --headless discriminator as a column\r\n- **Status:** open · **Origin:** worktree-pin triage tooling (ex releases#118)\r\n- **What/why:** the holder-triage script buries the headless-vs-interactive discriminator in prose;\r\n  as a column it makes the orphan-vs-own-shell call one glance.\r\n- **Ripe when:** any rig-tooling wave; trivial rider.\r\n- **Size:** tiny.\r\n\r\n### IR-12 — xtask contract-drift gate misses a stale manifest.schema.json\r\n- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane (the narrowed blind arm only). · **Origin:** ex\r\n  releases#116\r\n- **KIN NOTE RETIRED (2026-09-06, hertz; doyle measure-first ruling):** the stale-binary\r\n  premise was a rig artifact, not a reproduced product hole. At `9f809f8d`, in isolated Linux\r\n  worktree `hertz-ir12-mutation`, build `spt` once, mutate only its root CLI help string, do not\r\n  rebuild, then run `cargo run -p xtask -- check` alone: **exit 1**, combined output **3435 bytes**,\r\n  ending `xtask check: docs-site/src/cli/reference.md drifted from the binary's --help` (followed\r\n  by the regeneration instruction). The binary hash changed during check; the stale input was\r\n  rebuilt by `gen(true)` → `spt_bin` → `cargo build -q -p spt --bin spt` before comparison.\r\n  `CARGO_TARGET_DIR=UNSET`, `SPT_BLESS=UNSET`; Cargo's metadata target and xtask's read path both\r\n  resolve to this worktree's `target/debug/spt`. Source mutation was restored byte-for-byte.\r\n  Acceptance files: `~/spt-evidence/ir12-mutation-20260906/{check.exit,check.raw,env.txt}` on kitsubito.\r\n  The original rig mechanism remains unproven (old-mtime restoration or two target directories\r\n  are candidates, not findings). No product fix or permanent test added. IR-12 leaves the\r\n  register at the WEBSERVE close sweep.\r\n  The mandatory workspace-bins prebuild leg stays in every gate driver on its own merit (caught W2's spacerun red the night it was adopted); it is no longer justified by this note.\r\n- **What/why (corrected — the consequence sentence was false at `b7b00c3`):** the literal claim\r\n  holds — `xtask check` does not regenerate-and-compare the schema — but staleness does NOT \"ship a\r\n  wrong public contract silently\": `checked_in_schema_is_current`\r\n  (crates/spt-runtime/src/manifest.rs:2363, `int->REQ-DOCS-5`, landed `be4e46c` 2026-06-05, BEFORE\r\n  this entry's last sweep — docs lagging code) asserts full content equality of the checked-in\r\n  `manifest.schema.json` against what the derives generate, CRLF-normalised, `SPT_BLESS=1` as the\r\n  regenerate path. It is REACHED (lib unit test; ci.yml:114 runs `-E kind(lib)+kind(bin)` on push;\r\n  golden Phase A re-runs the workspace). Exactly ONE schema file exists in the tree; `docs_bundle`\r\n  (xtask main.rs:609-618) COPIES it at build time, so no second stored copy can drift. Chain closes:\r\n  derives → checked-in (unit-gated) → bundle (copied, not stored).\r\n- **What remains open, and the entry narrows to it:** `check_llms_links` (xtask main.rs:521)\r\n  hardcodes `manifest.schema.json` and `llms-full.txt` as always-existing, so the link check can\r\n  never see them MISSING — a blind arm, not a drift hole.\r\n- **The discrimination is now PROVEN, not presumed (todlando 2026-08-04, burn-the-build arms in\r\n  isolated worktree ir12-mutation @`11169c1`, env verified clear of `SPT_BLESS` FIRST — set, the\r\n  test short-circuits into a WRITE and a mutation arm silently self-heals green; that env check is\r\n  now part of the rig recipe):** arm 0 baseline PASS by NAME (1 test run); arm 1 semantic single\r\n  byte (title `…manifest`→`…manifesX`, length unchanged, scripted edit with match-count refusal)\r\n  REDS at manifest.rs:2374 exit 100 — \"manifest.schema.json drifted from the derives — regenerate\r\n  with SPT_BLESS=1\", with the mutated token appearing exactly once in 96,248 B of assertion output\r\n  so the byte is provably the only delta; arm 2 whitespace-only (CRLF→LF, 1014 endings) PASSES —\r\n  and arm 0 is itself the stronger normalisation proof, since the on-disk file is CRLF while the\r\n  generated string is LF, so an unmutated PASS is only possible because the test normalises; arm 3\r\n  restore re-measured PASS at the pristine sha256. `checked_in_schema_is_current` is a REAL gate.\r\n- **Built evidence:** `check_llms_links` resolves stored root assets to their\r\n  real source paths and runs the `llms-full.txt` generator instead of returning\r\n  hardcoded `true`. A unit cell proves a missing schema and install script are\r\n  refused, then accepted only after the real source file exists.\r\n- **Ripe when:** next xtask/docs-gate wave (now sized to the blind arm only).\r\n- **Size:** tiny.\r\n\r\n### IR-13 — Test-soundness follow-ups from the uniform-table sweep\r\n- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane. · **Origin:** ex releases#58\r\n- **What/why:** the remaining candidates from the closed issue were mutation-proved before changing\r\n  tests. `hold_outranks_everything` now walks all four `Opportunity` arms (including\r\n  `HoldRelease`); changing held+release to start reds on that arm. Pure walk tests cover all four\r\n  `QuiesceOutcome` arms and all five `EffectKind` arms; making `KillUnconfirmed` clear or\r\n  `Registry` ephemeral reds independently. The join test now binds all six `JoinFail` variants to\r\n  both hold retention and the emitted failure class/retry payload; misclassifying `WrongCode`\r\n  reds. The access candidates had already landed in the W4 follow-up and its dead-seam removal,\r\n  so the hygiene lane does not manufacture a second test vocabulary beside them.\r\n\r\n### IR-14 — .worktrees audit: \"how many worktrees are there\" has four defensible answers, and the difference is not junk\r\n- **Status:** open · **Origin:** ex releases#56 (was flag: NEEDS-OPERATOR in eval — operator input\r\n  now sought directly when the entry ripens, not via board flag)\r\n- **What/why:** the project `.worktrees/` dir accumulates content beyond what git tracks; audit +\r\n  reap recipe + a hygiene rule for lane close-out. Teardown discipline per docs and memory (classify\r\n  before delete, outbound links first).\r\n- **Release-close cleanup, 2026-09-11 (doyle, operator-requested):** removed **38 registered\r\n  worktree copies** whose heads were ancestors of released `16df0e41`, with no tracked changes,\r\n  untracked files, ignored files, target trees, or inbound links from the project-wide reparse\r\n  census. Branches and commits were retained; seven stale worktree registrations were repaired\r\n  with Git before ordinary, non-forced removal. This count is removals, NOT a census of all\r\n  remaining work. Dirty/unmerged/evidence-bearing lanes and the sync diagnostic trees stayed.\r\n  The broader home/Documents/projects cleanup also removed the reproducible N-1 checkout and\r\n  its separately classified target, an old release download, and generated scratch artifacts:\r\n  net free-space increase **4,532,350,976 bytes (4.22 GiB)**, ending at **83,382,472,704 bytes\r\n  (77.66 GiB)**. Concurrent machine activity makes this a net volume delta, not the sum of file\r\n  lengths. Receipt: `.spt/cleanup-20260911.json`. One cleanup discharges this audit instance,\r\n  not the recurring hygiene requirement; IR-14/26/27/49 are not closed by deletion.\r\n- ⚠ **The header of this entry previously read \"14 untracked orphan dirs vs 25 git-tracked\". Both\r\n  numbers were stale AND UNDATED**, so nobody could tell drift from error. Every count below is dated\r\n  and carries its command.\r\n\r\n#### THE COUNT DISAGREEMENT IS THE FINDING (measured 2026-08-03, todlando + doyle, main @`3efd7e6`)\r\n\r\nThree people measuring \"the worktrees\" got three answers. None was wrong; they answered three\r\ndifferent questions, and nothing in the tree states which one is meant:\r\n\r\n| answer | question it actually answers | command |\r\n|---|---|---|\r\n| **73** | all ENTRIES under `.worktrees/` | `ls -A .worktrees \\| wc -l` |\r\n| **52** | DIRECTORIES under `.worktrees/` | `ls -dA .worktrees/*/` |\r\n| **38** | registered worktrees INCLUDING the root checkout | `git worktree list` |\r\n| **37** | registered worktrees under `.worktrees/` | above, minus the root |\r\n\r\n**52 − 37 = 15 unregistered directories.** The 73 − 52 = **21 loose FILES** are covered below.\r\n\r\n**A count is only as good as its question.** Treat \"how many worktrees\" as under-specified until the\r\nanswer names its population — the same defect that made a naive `grep -rn` from the project root\r\ninflate a code count by **34.9×** (426 tracked `.rs` vs 14865 on disk excluding all `target/`), and\r\nmade that grep run past 120s while `git ls-files | xargs grep` returned instantly. **Scan roots and\r\npopulation definitions are the same class of error.** Use `git grep` / `git ls-files` for tracked\r\ncontent and `git worktree list --porcelain` for worktrees.\r\n\r\n#### THE 15 UNREGISTERED DIRECTORIES ARE FOUR DIFFERENT KINDS OF THING\r\n\r\n⛔ **CLASS A — LIVE BUILD POOLS, NOT ORPHANS. DO NOT DELETE.** 3 dirs, 13.2 GB. Each is the TARGET of\r\na junction that a REGISTERED worktree uses as its `target/`:\r\n\r\n| dir | inbound junction from | size | claim |\r\n|---|---|---|---|\r\n| `gate-target` | assembly-doorbell, doorbell-w1, doorbell-w2, doorbell-w3 | EMPTY | none |\r\n| `gate-target-render` | golden-render | 5.84 GB | `POOL-OWNER.json` → golden-render |\r\n| `gate-target-w4doc` | w4-cli-doc | 7.36 GB | none |\r\n\r\n**These are exactly the directories that read as obviously junk** — no `.git`, no source, leftover\r\nnames — and deleting one destroys a registered worktree's build pool and leaves a dangling junction.\r\n**Polarity was checked BEFORE classification, which is what caught it:** all 15 top-level dirs are\r\nREAL directories, none is itself a reparse point; the six junctions are **INBOUND**, at\r\n`<registered-worktree>/target`. See [[worktree-target-junction]], [[gate-worktree-target-disk]].\r\n\r\nTwo findings inside class A, neither of them a deletion question:\r\n- **`gate-target` has FOUR registered trees junctioned into ONE pool, with no `POOL-OWNER.json` at\r\n  all** — so nothing would refuse a second LIVE lane there. That is releases#103's exact hazard\r\n  sitting armed. The pool is also empty: someone reclaimed it and left four junctions aimed at a hole.\r\n- **`gate-target-render`'s `POOL-OWNER.json` carries only `owner_tree` and `written_by` — no pid and\r\n  no birth stamp.** A claim that cannot distinguish a live lane from a finished one is missing the one\r\n  property the claim mechanism exists to provide.\r\n\r\n**CLASS B — EMPTIED SKELETONS, ONE UNIFORM SHAPE.** 8 dirs, **0 files**: `acl-core`, `engine-room`,\r\n`ff-fastfollow`, `gate-23d5ceb`, `gate-ff`, `golden-a`, `golden-b`, `w2b-sender-stamp`. Every one is\r\nexactly `crates/spt-daemon/` and nothing else. **Eight independent removals stopping at the SAME\r\nrelative path is a mechanism, not litter.**\r\n\r\n**MECHANISM CORROBORATED LIVE, 2026-08-03:** a read-only PEB sweep of process CWDs during a running\r\n`spt-daemon` suite found ~20 processes — `spt_daemon-<hash>` test harnesses, `PING`, `cmd` — whose\r\nCWD was **exactly `<worktree>/crates/spt-daemon/`**, the precise path all eight skeletons froze at. A\r\n`git worktree remove` racing a straggler there deletes everything else and leaves that chain pinned.\r\nThe processes churn fast (all 17 sampled pids were gone within 30s, one already showing **pid reuse**\r\n— see [[pid-reuse-across-reboot]] for why a pid alone is never an identity), so the pin is a race, not\r\na steady state, and it recurs on every daemon-suite worktree.\r\n\r\n**CLASS C — FULLY EMPTY, no inbound junction.** 3 dirs, 0 bytes: `gate-41`, `gate-559632e`,\r\n`release-runbook-main-advance`. Class B with even the chain gone.\r\n\r\n**CLASS D — DELIBERATE SCRATCH, NOT RESIDUE.** 1 dir, 12 files, 50 KB: `_patches` — three `.patch`\r\nfiles with their `.untracked` manifests, plus `ir18-gate-logs/`. Modified the day before the audit,\r\ni.e. someone's working state.\r\n\r\n3 + 8 + 3 + 1 = 15.\r\n\r\n#### PIN STATE: NO SKELETON IS HELD TODAY (with a stated blind spot)\r\n\r\nRead-only PEB CWD sweep, 2026-08-03: **zero processes hold a CWD in any class-B or class-C\r\ndirectory** — every live pin was in `gate-ec5f38a` and `gate-main`, both REGISTERED and both running\r\nrigs at the time. So removal of B and C would succeed today; nothing is retrying it.\r\n\r\n⚠ **The sweep read 412 of 593 processes; 181 were unreadable** (elevated/system, no\r\n`PROCESS_VM_READ`). The no-pin result therefore holds over the READABLE population only. Cheap to\r\nre-run elevated before acting — [[absence-needs-sibling-probe]].\r\n\r\n#### THE LOOSE FILES: A SHARED LOCATION WITH NO STATED CONTRACT\r\n\r\n**21 loose files sit in `.worktrees/`** — gate logs (`gate-*.log`, `gate-559632e-log.txt`), rig\r\nscripts (`g6-curve.ps1`, `g6-postbounce.ps1`, `gate-w5-*.ps1`), and `gate-w5-notes.md`. **Nobody\r\ndeclared `.worktrees/` a log drop; it became one.** Same class as the memory index: a shared location\r\nwith no stated contract accumulates whatever anyone puts there, and **the first person to tidy it\r\ncannot tell residue from someone's working state** — class D is that risk already realised. The\r\nhygiene rule this entry owes should name where gate logs and rig scripts belong, not only how to reap\r\nworktrees.\r\n\r\n#### RECLAIM ARITHMETIC — AND WHY THIS ENTRY IS NOT THE DISK FIX\r\n\r\nClasses B, C and D together are **under 51 KB**. All 13.2 GB of the unregistered population is class\r\nA, behind live junctions. **An orphan sweep is not a disk-space remedy**, and reading it as one sends\r\nyou at the wrong target: on the audit date, free space was **12.5 GB against the 32 GB golden floor**\r\n([[free-space-floor-blocks-golden]]) while the two largest pools on the box were `gate-ec5f38a/target`\r\n(14.33 GB) and `gate-main/target` (28.12 GB) — **both REGISTERED, so both outside the orphan\r\npopulation entirely.** The disk question and the orphan question have different populations; answering\r\none correctly says nothing about the other.\r\n\r\n- **AUDIT EXECUTED 2026-08-30 (doyle, the v0.66.0→NOW-SIGNAL between-milestone window; full\r\n  output `wt-census-2026-08-30.txt` in the session scratchpad, method = this entry's own):**\r\n  four answers BEFORE the sweep: 85 entries / 85 dirs / 76 registered incl root / 75 under\r\n  `.worktrees` → 10 unregistered, 0 loose files (the 21 loose files of 08-03 are gone).\r\n  **The 08-03 headline populations have INVERTED:** zero pools and zero junctions exist under\r\n  `.worktrees` at all (every registered tree reads `target=none`; the reparse sweep found no\r\n  inbound junction) — class A is EMPTY, so the armed pool hazards this entry named are\r\n  currently unpopulated. Unregistered classified: 4 fully-empty (C), 3 `crates/spt-daemon`\r\n  skeletons (B — the mechanism's fingerprint again), `_patches` (D, kept — working scratch),\r\n  and TWO content-bearing checkout remnants (gate-signet-w1 10.8MB, gate-w1-a8f04aff 27MB) =\r\n  registry-pruned dirs held by the conhost CWD pins IR-63's third face names. **Sweep\r\n  executed on the gater's own rigs:** evidence preserved FIRST\r\n  (`spt-preserve\\audit-2026-08-30\\`: gate-w1-a8f04aff's 229 non-HEAD files as a verified\r\n  tarball; er-instrument's 115-line UNCOMMITTED instrument diff as a patch — that worktree\r\n  belongs to hertz's lane and was NOT touched beyond the read-only copy), 16 pinning conhosts\r\n  killed by pid after a fresh probe, 9 dead rigs removed. AFTER: **76 dirs = 75 registered +\r\n  `_patches`, fully reconciled; zero unexplained entries, zero pins.** Reclaim was ~38MB —\r\n  reconfirming this entry's arithmetic that the orphan sweep is hygiene, not a disk remedy.\r\n  Landed-classification caveat: `git cherry` patch-id reads conflict-resolved picks\r\n  as UNLANDED (emit-single-write, fix-206/208/209 all show UNLANDED with shipped content), so\r\n  the census's landed column is a datum, never a reap authorization.\r\n- **HYGIENE RULE (the text this entry owed, written 2026-08-30 while the loose-file population\r\n  is zero — the rule exists BEFORE it refills):** `.worktrees/` holds exactly two kinds of\r\n  entry: **registered worktrees** and **`_patches/`** (the one declared scratch location).\r\n  Nothing else. Gate/rig artifacts follow their lifetime: (1) driver scripts, exit/raw files,\r\n  and logs live INSIDE their rig's worktree for the rig's life — they leave WITH it, via the\r\n  preservation step (copy what the verdict cites into `spt-preserve/<occasion>/`, verified by\r\n  cmp or a listed tarball, restore cost stated) and never accumulate beside the rigs; (2)\r\n  anything meant to outlive its rig goes to the repo ROOT beside the verdicts and RCAs it\r\n  supports (the census/finding/JIT convention) or into `spt-preserve/` — never loose in\r\n  `.worktrees/`; (3) a file found loose in `.worktrees/` is treated as UNCLASSIFIED WORKING\r\n  STATE — moved to `_patches/` with a dated note, never deleted on sight (class D is the risk\r\n  realised). Lane close-out = `git worktree remove` + prune + the conhost CWD-pin check\r\n  ([[IR-63]] third face) when removal refuses; a registry-pruned dir left behind is a defect\r\n  to sweep, not a norm.\r\n- **Ripe when:** between-milestone idle window (it is a dev-box chore, zero product risk) — but the\r\n  class-A pool findings are armed hazards and do not wait for it.\r\n- **Size:** small for the sweep; the hygiene rule and the pool-claim gaps are separate small items.\r\n- **Field instance (hertz sweep, 2026-08-04 — an unclaimed pool found rather than reasoned about):**\r\n  `.worktrees\\gate-target-w4doc` held **7,907,558,098 B with NO POOL-OWNER.json at all**. Not a stale\r\n  claim, not a foreign claim — no claim. Exactly this entry's shape, first measured instance. Reaped\r\n  under doyle's ruling as part of [[IR-27]]'s two-step teardown; the measurement stands on its own.\r\n\r\n### IR-17 — Deadline-burn bring-up family: a test burns its full window while the daemon/brain never comes up\r\n- **Status:** open · **Origin:** golden 30782259675 red triage 2026-08-03\r\n- **What/why:** two different tests on two runner hosts now share one signature — bring-up misses\r\n  its ONLINE window under leg load and the test burns its ENTIRE deadline before the PRECONDITION\r\n  panic: `spt::resident_service_e2e::a_declared_service_rises_with_the_daemon_and_reaches_the_cli`\r\n  (hfenduleam, FAIL 123.99s, \"PRECONDITION: the daemon never came up\", run 30782259675, green on\r\n  same-sha rerun 30784469908) and `spt::activity_link_push_e2e` (kitsubito, full 30s, run\r\n  30607903133 specimen, green on same-sha rerun; its \"brain stderr EMPTY\" leg and its family\r\n  membership are both CORRECTED in the 2026-08-30 sweep update below — the kitsubito member is\r\n  CLOSED under a named mechanism).\r\n  Family reading, not one flake: same missed-window shape, host-independent, both mid-leg under\r\n  load. Cross-ref KNOWN-HAZARDS 5.13 — bring-up has a hard ONLINE budget with known sensitivity to\r\n  anything that stalls it (the blanket-fsync canary; `attach_wedge_e2e` guards that budget).\r\n- **State line (the discriminating datum, resident_service red):** `daemon_up=false boot_alive=true\r\n  boot_pid=Some(8920) rel_started=false broker_survived=false` — the boot process was ALIVE at\r\n  panic time and the daemon never reached up. Any characterization run records this line per run,\r\n  not the verdict (hertz protocol 2026-08-03).\r\n- **Read of that line, CORRECTED 2026-08-03 (hertz):** it is NOT \"started-but-never-bound\" (the\r\n  earlier reading here) and not \"never-started\" — it is **started, did work, then killed** —\r\n  CANDIDATE via [[IR-18]]. The daemon spawned its boot service and that service reached the CLI\r\n  (the spool holds its message), and `broker_survived=false`. The DISCRIMINATING field is\r\n  `broker_survived`: false in every killed round of the positive control, true in every healthy\r\n  round. **An earlier evidence leg here is RETRACTED (hertz, same night, off the negative arm he\r\n  ran before reporting; deployah, who had carried the leg into four register sites, swept every\r\n  placement): \"empty daemon.stderr.log = TerminateProcess signature\" was false — the stderr\r\n  block is empty on PASSING runs too, so it carries zero information in either direction; it\r\n  failed the discriminator question and does not support the kill read.** The kill read now rests\r\n  on the control's field-for-field reproduction and the IR-18 mechanism, not on the log.\r\n  Consequences: (a) the bring-up window is **exonerated for this specimen** — measuring it would\r\n  have measured nothing; (b) the candidate mechanism and its evidence now live in [[IR-18]]\r\n  (a sibling test's bare breadcrumb tree-kill), CANDIDATE — not reproduced, not proven;\r\n  (c) **the characterization population changed, and the rate run is CANCELLED** (doyle ruling\r\n  2026-08-03) — `resident_service_e2e` run ALONE has no sibling to collide with, so the mechanism\r\n  predicts 0/N and that number answers no live question; the only sound population was the test\r\n  INSIDE the Phase A parallel pool, which costs a full Phase A leg per sample, and the fix is\r\n  warranted by the source-verified hazard class regardless of the specimen's rate. No rate figure\r\n  will exist for this specimen — do not later read its absence as a low rate; (d) **positive\r\n  control still runs, falling out of the\r\n  hypothesis:** kill the spawned daemon by pid mid-bring-up — after boot-service spawn, before\r\n  ready — and it must reproduce the observed line field for field (`daemon_up=false\r\n  boot_alive=true broker_survived=false`). If the rig cannot make that shape on\r\n  demand, a 0/N from the untouched arm is worth nothing and must be reported as worth nothing.\r\n  The host-INDEPENDENT family claim (kitsubito's `activity_link_push_e2e`) is untouched by this:\r\n  it has no such kill site named, so the family survives even if this specimen leaves it.\r\n- **POSITIVE CONTROL RAN 2026-08-03 (hertz, prebuilt a5042ec binary, box confirmed clear —\r\n  0 open runs, 145.95 GB free): shape reproduced 3/3, deterministic.** Negative arm n=2: 2/2 PASS\r\n  (5.59s, 5.46s), `daemon_up=true boot_alive=true rel_started=true broker_survived=true\r\n  survived_teardown=true`. Positive arm (daemon killed by parent-scoped descent after\r\n  boot-service spawn, before ready) n=3: 3/3 FAIL (93.95/93.25/93.50s), state line identical to\r\n  the CI red in EVERY field except boot_pid (a pid, must differ), same panic, same site\r\n  (resident_service_e2e.rs:382). Structural fact the arm settled, and the refutation risk that\r\n  made it worth running: the boot service rises BEFORE brain.ready becomes readable — had the\r\n  order been reversed the arm would have produced daemon_up=true and refuted the mechanism.\r\n  CEILING MET, NOT EXCEEDED: the control used Stop-Process -Force (TerminateProcess — the same\r\n  primitive as taskkill /F), so it proves a forced daemon kill after breakaway-service spawn\r\n  produces this exact line ON DEMAND; it says nothing about WHO issued one in golden 30782259675.\r\n  Candidate mechanism, shape reproduced on demand — \"root caused\" written by nobody. Duration\r\n  note, recorded not explained: 93.5s local (idle box) vs 123.99s CI (Phase A parallelism), both\r\n  burning the same three 45s windows — consistent, not verified.\r\n- **Same-host sub-observation (hertz, host-CONSTANT — narrower claim, kept separate):** both\r\n  reds of 2026-08-03 sat on hfenduleam Windows Phase A and burned their full windows:\r\n  `a_tree_teardown_reaches_a_grandchild_the_service_spawned` (run 30776330383, FAIL 10.176s = the\r\n  full poll deadline, vs a 0.19–0.66s pass band — 15–50x out) + the resident_service row above.\r\n  MEMBERSHIP PROVISIONAL for the teardown row: it carries a candidate mechanism the bring-up burn\r\n  does not share — the pid-only oracle IR-15 just replaced. If the oracle caused it, that row\r\n  leaves the family and host-constant collapses to one sighting. The host-INDEPENDENT pair above\r\n  is the claim that survives someone fixing this box; the sub-observation is what is actionable\r\n  about hfenduleam (a live-daemon host) meanwhile. **UPDATE 2026-08-04 (golden 30873007187\r\n  attempt 1 — SECOND sighting, and the provisional question above is now ANSWERED): the\r\n  pid-only-oracle candidate is REFUTED for this row** — IR-15's authenticated repin rode the\r\n  failing tree (a5042ec ancestor of 4b37512) and the row failed anyway (10.225s, \"grandchild\r\n  51848 outlived the tree teardown\"), with is_stamped() asserted before the kill so the verdict\r\n  passed the authenticated gate. The row therefore STAYS a family member with its mechanism OPEN,\r\n  narrowed by hertz's log forensics (competence-controlled: the capture channel demonstrably\r\n  prints): no DETACH_BREAKAWAY_DENIED (breakaway rung taken), no SERVICE_JOB_UNAVAILABLE (job\r\n  created + child enrolled), no SERVICE_TREE_KILL_INCOMPLETE (TerminateJobObject returned\r\n  success) — everything enrolled died; THE SURVIVOR WAS NEVER ENROLLED. Two hypotheses,\r\n  inseparable in existing evidence: H1 test defect — the grandchild SELECTION is a bare\r\n  th32ParentProcessID match over a recycling pid space (IR-15's mechanism one level up: the\r\n  verdict was authenticated, the selection was not); H2 real enrollment gap. hertz's selection\r\n  probe (IsProcessInJob at selection time — decisive; birth stamp one-directional; image; same-\r\n  snapshot match count) is authored+compiled and makes the NEXT occurrence self-deciding. Row\r\n  state: INSTRUMENTED-AWAITING-FIRE; a green retires nothing (doyle-ruled). **UPDATE 2026-08-04\r\n  (USHER att3):** row green at 17f95a7 (retires nothing, per the ruling). New shape evidence while\r\n  waiting for the probe: BOTH archived reds sit AT the 10s poll bound (daemon.rs:2757) — 10.176s and\r\n  10.225s — while todlando's 200 off-CI passes under live-fleet load ran 1-4s, never near it. The\r\n  post-fix red is therefore BOUND-EXPIRY-shaped (kill fired; the pinned identity stayed\r\n  not-provably-gone past 10s — TerminateJobObject is async), not kill-wrong-shaped. The bound\r\n  question (is 10s right for a loaded runner) is parked with hertz's USHER package item 4 and must\r\n  not touch the kill path or spawn flags before the probe fires. See also the FLAKE-LEDGER row for\r\n  the false-repeat correction (the 10.176s red was the PRE-a5042ec bare-pid mechanism).\r\n- **Declared read (2026-08-03, rules the next red):** a same-sha green rerun is protocol-conclusive\r\n  for the GATE, not the class. No third silent sample — the next occurrence of this signature gets\r\n  an instrumented resident-service bring-up investigation (hertz), not a rerun.\r\n- **SWEEP UPDATE 2026-08-30 (#242/v0.66.0 close — three corrections, correct-by-replacement):**\r\n  (1) **The 2026-08-03 \"brain stderr EMPTY\" reading on the kitsubito specimen is a METER\r\n  ARTIFACT, not a silent brain** (deployah measured 2026-08-29): the brain-panel stderr capture\r\n  only LANDED 2026-08-19 (`ab657626` + `e6e188e1`), 16 days after the specimen — at the specimen's\r\n  sha there was nothing to capture, so \"empty\" carried zero information; current bits label\r\n  absence explicitly, so empty-vs-present cannot recur as a distinction. This replaces the\r\n  \"cheap to settle next time someone has kitsubito\" item — there is nothing left to settle.\r\n  (2) **The kitsubito family member is CLOSED under a NAMED mechanism:** RCA-242-R2-LINUX.md\r\n  (v0.66.0 golden r2) measured `current_exe_hash()` on the READY PATH at ~10.1s per boot on\r\n  kitsubito under load (~1.5s Windows) via BRAIN_PHASE breadcrumbs + harvest-loop repro — a\r\n  bring-up that misses its ONLINE window under leg load is exactly what a ~10s synchronous hash\r\n  inside the ready path manufactures. The behaviour-change request (hash off the ready path,\r\n  ADR-0018 Q7) is minted on the board at this sweep as **releases#244** (BACKLOG, operator\r\n  triages). The family's host-INDEPENDENT claim\r\n  therefore collapses: the Windows `resident_service_e2e` specimen (IR-18 kill-shape candidate)\r\n  and the hfenduleam sub-observation STAY OPEN as this entry's remaining live population.\r\n  (3) **Lane-linked:** hertz's queued fixup lane brief names this entry directly\r\n  (activity_link_push_e2e 4-cell fixup: false precondition message + progress-bounded readiness\r\n  wait, #235 shape). Overlap with correction (2) checked at link time: his cells are TEST-side\r\n  (message truth + wait shape) and stand regardless of the product-side hash fix.\r\n- **Ripe when:** next occurrence of the signature (immediate instrumented dispatch), or a hertz\r\n  test-hardening wave (bring-up phase-timing instrumentation, per-phase deadline attribution).\r\n- **Size:** medium (bring-up instrumentation + attribution; the fix depends on what it shows).\r\n\r\n### IR-16 — kill_tree discards TerminateJobObject/TerminateProcess returns (silent partial kill)\r\n- **Status:** BUILT 2026-08-03 (landed @62c5623 on the LOCKSMITH t1 lane; rides golden sha\r\n  b7b00c3, run 30860770146 green) · **Origin:** ex releases#130 (golden 30776330383 red triage;\r\n  deployah's log read\r\n  + todlando's flagged-not-asserted arm). Operator-classified infra 2026-08-02: daemon-kill\r\n  internals are agent-facing, not operator-facing surface.\r\n- **What/why:** `DetachedChild::kill_tree` (daemon.rs:1433 vicinity) calls\r\n  `unsafe { TerminateJobObject(self.job, 1) }` and discards the return; TerminateProcess likewise\r\n  unaudited. A job that was created and assigned at spawn but whose TERMINATION fails at kill time\r\n  yields the grandchild-survives symptom with zero log signal — the spawn-side\r\n  SERVICE_JOB_UNAVAILABLE announcement is correctly absent (that arm is instrumented and was\r\n  refuted for the specimen by a positively-controlled zero). Wanted: (1) check + log both\r\n  termination returns loudly on failure; (2) the degraded-arm decision — fallback process-table\r\n  tree-walk kill or explicit refusal, never a silent partial kill wearing REQ-RESIDENT-SERVICE's\r\n  unconditional promise. Do NOT add self.job==0 instrumentation (already loud; a second weaker\r\n  rule beside a working one). Discrimination pairing with [[IR-15]]: a red whose captured pid is\r\n  still ping.exe with no SERVICE_JOB_UNAVAILABLE in scope = this entry's arm.\r\n- **Ripe when:** RIPE NOW — IR-15 landed BUILT 2026-08-03 (its rig-side half), so this kill-side\r\n  half is the outstanding instrument; land with the next daemon-teardown wave or sooner.\r\n- **Size:** small.\r\n- **Composed:** LOCKSMITH (#132) — todlando product lane, with the `detached_no_inherit_env`\r\n  rename as cosmetic rider (IR-20's load-bearing-pid caution applies to any rig touch) —\r\n  2026-08-03. GREENLIT with #132 and **DISPATCHED to todlando 2026-08-03**, carrying IR-20's\r\n  load-bearing-pid precondition as a stated check (todlando reports whether the rig is touched\r\n  at all rather than silently skipping it).\r\n- **BUILT — fulfilment checked against the wanted list, not merely mapped to a commit** (doyle,\r\n  2026-08-04): `62c5623` satisfies (1) — both termination returns are now checked and the loss is\r\n  NAMED on failure, as the kill-time twin of the spawn-time `SERVICE_JOB_UNAVAILABLE` — and (2) by\r\n  the ruled LOUD REFUSAL arm rather than a tree-walk fallback, which [[IR-18]] measured blind in\r\n  exactly this failure state. The `self.job == 0` prohibition was honored: the new check is\r\n  `self.job != 0 && TerminateJobObject(...) == 0`, not a second weaker rule beside the working one.\r\n  The unix `ESRCH` quiet arm — which no Windows gate can see — is covered by `ec5f38a`. The\r\n  `detached_no_inherit_env` cosmetic rider did NOT land and was dropped at `de6a01d` on a MEASURED\r\n  false premise, not deferred. A Windows-specific finding rides the fix as a comment and is worth\r\n  keeping: `TerminateProcess` against a handle to an already-exited process returns 0 with\r\n  `GetLastError` 5 (`ERROR_ACCESS_DENIED`), so a naive check there fires on the ORDINARY path.\r\n\r\n### IR-18 — resident_service_e2e kills breadcrumb pids BARE (stale-breadcrumb tree-kill; kill-side twin of IR-15)\r\n- **Status:** BUILT 2026-08-04 — the named acceptance carrier RAN and the condition is DISCHARGED,\r\n  stated as the measurement rather than as the green board it sat on: LOCKSMITH's golden run\r\n  30860770146 (head `b7b00c3`, conclusion success) executed the changed test IN-POOL on BOTH\r\n…\n  reproduction\n…\n\n…\n\n…\n- **Discipline and receipt.** [Windows ad-hoc rig launch discipline](GOLDEN-CI.md#windows-ad-hoc-rigs-that-outlive-the-tool-call) states the shape, child-owned durable output and post-return PID/birth/output qualification. Preserved harmless-child receipt: `.spt/preserved/hertz-ir137-caller-return/receipt.json`, SHA256 **`e1c9b207544e6313eac5421ebb692786ec18b3a165756b451bff3a704899b178`**. Both valid arms survived under **OMP**, wrote post-return events and exited0; an initial observer-handshake timeout is excluded. All3probe children ended and native handles closed. This does not reproduce the **Claude Code** failure; the host boundary stays explicit. Reopen only for a newly owned callsite or contrary evidence, not to build an unused helper.","startLine":1,"lineNumbers":[1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95,96,97,98,99,100,101,102,103,104,105,106,107,108,109,110,111,112,113,114,115,116,117,118,119,120,121,122,123,124,125,126,127,128,129,130,131,132,133,134,135,136,137,138,139,140,141,142,143,144,145,146,147,148,149,150,151,152,153,154,155,156,157,158,159,160,161,162,163,164,165,166,167,168,169,170,171,172,173,174,175,176,177,178,179,180,181,182,183,184,185,186,187,188,189,190,191,192,193,194,195,196,197,198,199,200,201,202,203,204,205,206,207,208,209,210,211,212,213,214,215,216,217,218,219,220,221,222,223,224,225,226,227,228,229,230,231,232,233,234,235,236,237,238,239,240,241,242,243,244,245,246,247,248,249,250,251,252,253,254,255,256,257,258,259,260,261,262,263,264,265,266,267,268,269,270,271,272,273,274,275,276,277,278,279,280,281,282,283,284,285,286,287,288,289,290,291,292,293,294,295,296,297,298,299,300,301,302,303,304,305,306,307,308,309,310,311,312,313,314,315,316,317,318,319,320,321,322,323,324,325,326,327,328,329,330,331,332,333,334,335,336,337,338,339,340,341,342,343,344,345,346,347,348,349,350,351,352,353,354,355,356,357,358,359,360,361,362,363,364,365,366,367,368,369,370,371,372,373,374,375,376,377,378,379,380,381,382,383,384,385,386,387,388,389,390,391,392,393,394,395,396,397,398,399,400,401,402,403,404,405,406,407,408,409,410,411,412,413,414,415,416,417,418,419,420,421,422,423,424,425,426,427,428,429,430,431,432,433,434,435,436,437,438,439,440,441,442,443,444,445,446,447,448,449,450,451,452,453,454,455,456,457,458,459,460,461,462,463,464,465,466,467,468,469,470,471,472,473,474,475,476,477,478,479,480,481,482,483,484,485,486,487,488,489,490,491,492,493,494,495,496,497,498,499,500,501,502,503,504,505,506,507,508,509,510,511,512,513,514,515,516,517,518,519,520,521,522,523,524,525,526,527,528,529,530,531,532,533,534,535,536,537,538,539,540,541,542,543,544,545,546,547,548,549,550,551,552,553,554,555,556,557,558,559,560,561,562,563,564,565,566,567,568,569,570,571,572,573,574,575,576,577,578,579,580,581,582,583,584,585,586,587,588,589,590,591,592,593,594,595,596,597,598,599,600,601,602,603,604,605,606,607,608,609,610,611,612,613,614,615,616,617,618,619,620,621,622,623,624,625,626,627,628,629,630,631,632,633,634,635,636,637,638,639,640,641,642,643,644,645,646,647,648,649,650,651,652,653,654,655,656,657,658,659,660,661,662,663,664,665,666,667,668,669,670,671,672,673,674,675,676,677,678,679,680,681,682,683,684,685,686,687,688,689,690,691,692,693,694,695,696,697,698,699,700,701,702,703,704,705,706,707,708,709,710,711,712,713,714,715,716,717,718,719,720,721,722,723,724,725,726,727,728,729,730,731,732,733,734,735,736,737,738,739,740,741,742,743,744,745,746,747,748,749,750,751,752,753,754,755,756,757,758,759,760,761,762,763,764,765,766,767,768,769,770,771,772,773,774,775,776,777,778,779,780,781,782,783,784,785,786,787,788,789,790,791,792,793,794,795,796,797,798,799,800,801,802,803,804,805,806,807,808,809,810,811,812,813,814,815,816,817,818,819,820,821,822,823,824,825,826,827,828,829,830,831,832,833,834,835,836,837,838,839,840,841,842,843,844,845,846,847,848,849,850,851,852,853,854,855,856,857,858,859,860,861,862,863,864,865,866,867,868,869,870,871,872,873,null,882,null,1154,null,1248,null,6937]},"fileSize":676479,"meta":{"source":{"type":"path","value":"C:\\Users\\decid\\Documents\\projects\\spt-core\\.worktrees\\hertz-ir86-disk-delta\\docs\\INFRA-REGISTER.md"},"truncation":{"direction":"middle","truncatedBy":"middle","totalLines":881,"totalBytes":73526,"outputLines":469,"outputBytes":40905,"maxBytes":40960,"headRange":{"start":1,"end":239},"tailRange":{"start":653,"end":881},"elidedLines":413,"elidedBytes":32643,"artifactId":"729","nextOffset":874}}},"isError":false,"timestamp":1789483662368}}
{"type":"message","id":"bea905aa","parentId":"70e99837","timestamp":"2026-09-15T14:47:42.417Z","message":{"role":"toolResult","toolCallId":"call_Q1kHvbr3Nsv06kk7jIhSDLjA|fc_043a862a419f59ae016aa95a8e358087d28f94b0c4ae7a2a6e","toolName":"read","content":[{"type":"text","text":"## OPEN\n…\n### IR-16 — kill_tree discards TerminateJobObject/TerminateProcess returns (silent partial kill)\n- **Status:** BUILT 2026-08-03 (landed @62c5623 on the LOCKSMITH t1 lane; rides golden sha\n…\n- **BUILT — fulfilment checked against the wanted list, not merely mapped to a commit** (doyle,\n…\n\n### IR-18 — resident_service_e2e kills breadcrumb pids BARE (stale-breadcrumb tree-kill; kill-side twin of IR-15)\n- **Status:** BUILT 2026-08-04 — the named acceptance carrier RAN and the condition is DISCHARGED,\n  stated as the measurement rather than as the green board it sat on: LOCKSMITH's golden run\n  30860770146 (head `b7b00c3`, conclusion success) executed the changed test IN-POOL on BOTH\n  platforms — `spt::resident_service_e2e a_declared_service_rises_with_the_daemon_and_reaches_the_cli`\n  PASS 17.773s (100/2637) on hfenduleam/Windows and PASS 17.895s (1364/2616) on kitsubito/Linux.\n  The pool was checked for the test rather than inferred from the job colour, because a green leg\n  that never ran the test is a competence-controlled zero, not an acquittal; `resident_service_e2e`\n  contains exactly ONE `#[test]`, so the test that ran IS the test the lane rewrote (229 lines of\n  that file changed in `6e1a962`). No red returned to doyle. `.worktrees/ir18` is released for\n  teardown by this verdict · **Origin:** hertz\n  characterization of the [[IR-17]] resident_service red, 2026-08-03 — CANDIDATE mechanism, NOT a\n  reproduction\n- **Lane:** hertz `fix/ir18-authenticated-teardown` — MERGED to main @6e1a962 (PR #142; gated at\n  b48e35b, rebased 6e1a962 on 1e520b4 with zero code delta — doyle re-derived `git diff -- crates/`\n  empty across the rebase, so the gate verdict and local behavioral evidence transfer). Gated by\n  doyle: full diff review (one blocking finding — the scope_lost assert condition contradicted its\n  own guard ruling — fixed and delta-verified at one line), mutation-proven locally both\n  directions (B: forced boot_pid=None → population sweep names the leak no per-pid check sees,\n  FAIL 101; A: wrong expected_exe → REFUSED-foreign-image reds loudly on the derivation check).\n  EVIDENCE SPLIT, stated so the check marks cannot carry it (hertz's absent-leg callout): lane CI\n  30792210008 was 5/5 green per job but ci.yml's test leg is kind(lib)+kind(bin) — the changed\n  integration test NEVER RAN there (verified by log grep, 0 hits / 3023 lines); CI proved\n  compile-everywhere (clippy all-targets = the pool-population check for a common/ module),\n  traceability, lib/bin clean. The BEHAVIORAL evidence is local: three clean runs (all verdicts\n  Killed, population empty) + the two mutation reds. reap.rs diff additive-only (zero deleted\n  lines, verified) — cross-test risk bounded to compilation, which CI covered. Evidence custody:\n  gate + mutation logs at `.worktrees/_patches/ir18-gate-logs/` (5 files); `.worktrees/ir18` is\n  KEPT deliberately until the golden verdict (NOT an orphan — do not reap; a Phase A red wants the\n  tree and logs in place, not rebuilt); its pool claim is released.\n- **What/why:** `crates/spt/tests/resident_service_e2e.rs:46` defines its own reaper —\n  `taskkill /PID <pid> /F /T`: bare pid, force, whole TREE, no identity check — and feeds it three\n  BREADCRUMB-derived pids in cleanup (`boot_pid`, `rel_service_pid` at :360, and the pid read out\n  of `brain.ready` at :363). The suite already ships the authenticated tool other tests use and\n  this one does not: `common::reap::authenticated_kill(label, pid, expected_exe, observed)` at\n  `crates/spt/tests/common/reap.rs:116`. Inside the Phase A parallel pool on a pid-churning box\n  this is the KNOWN-HAZARDS stale-breadcrumb tree-kill class, live and **symmetric**: this test can\n  take a sibling's daemon and a sibling can take this test's. Same defect [[IR-15]] just fixed, on\n  the other side — IR-15 authenticated the READ (is the thing I pinned gone?), the KILL is still\n  bare pid. Kill what you pinned, not the number it happens to hold.\n- **Verified at source by deployah 2026-08-03** (relayed claims re-derived, all held): the bare\n  kill, its three breadcrumb feeds, the shipped-but-unused authenticated helper, and the\n  `CREATE_BREAKAWAY_FROM_JOB` spawn (`daemon.rs:1300`).\n- **Evidence rating — why it is a candidate and not a cause:** it predicts every field of the one\n  observed state line. The daemon is killed after spawning its boot service and before binding:\n  `broker_survived=false` (the discriminating field — false in every killed control round, true in\n  every healthy one) + `boot_alive=true boot_pid=Some(8920)` with the service's message in the\n  spool. (The \"empty stderr = silent death\" leg that originally sat here is RETRACTED — see\n  [[IR-17]]'s control record; stderr is empty on healthy runs too and discriminates nothing.)\n  The service outlives its daemon because `detached_no_inherit_env` spawns it\n  `CREATE_BREAKAWAY_FROM_JOB`, so it is NOT in the daemon's job and a daemon kill ORPHANS it\n  rather than reaping it — plausibly also the five denied `svcmock.exe` attempts in that job's\n  reap summary. **The [[IR-17]] positive control (2026-08-03) reproduced the shape 3/3\n  deterministically with a forced kill at that window — establishing the SHAPE on demand, not the\n  AGENT: nothing identifies who issued a kill in golden 30782259675.** The bare-pid tree-kill from\n  a concurrent test remains the candidate agent, on the source-verified hazard class and reap.rs's\n  documented prior casualty. **Not reproduced in the wild. Not proven. \"Root caused\" is not\n  written here by anyone.** The [[IR-17]] rate run is cancelled, so no rate will ever back this —\n  the fix stands on the source-verified hazard class alone. THE DEFECT IN MINIATURE, observed as a\n  side effect of the control (hertz 2026-08-03): the three killed rounds leaked 12 processes\n  (6 svcmock + 6 spt.exe, two services per round) and the test's own teardown reaped NONE — when\n  the daemon dies, `rel_pid` is `None` so that service is never even a kill target, and the\n  breakaway child outlives everything. A teardown that leaks two processes per round currently\n  PASSES: the concrete case for `target_gone` as the gate's positive half. (Leak cleaned scoped,\n  each pid re-authenticated by image-path prefix + creation window at kill time, not from the\n  minute-old enumeration.) ONE LAYER DEEPER (deployah, same night, at source): the reap loop\n  (:359) is `[boot_pid, rel_service_pid].into_iter().flatten()` — `.flatten()` DROPS None, and\n  `mock_pid` (:100-106) collapses absent/permission-denied/IO-error/garbage into that None via\n  `.ok()?`/`.ok()` — the reap.rs:59-63 collapse in a THIRD location, inside this very test. So the\n  leak is both \"service never started\" AND \"pid unreadable, therefore never a kill target\":\n  absence of knowledge read as absence of target, in a teardown, again.\n- **GATE SPEC AMENDED PRE-BUILD (deployah found the hole, doyle-ruled 2026-08-03 — read this\n  BEFORE building the lane):** the two halves as first specified (trap-class-absent +\n  `target_gone` per pid) both operate on pids we HAVE — a process whose pid is None is invisible\n  to BOTH, so the specified gate PASSES hertz's own control-run leak (12 processes, 6+6, 2/round,\n  teardown reaped none). A gate its own reproduction case passes is not yet an instrument. THIRD\n  HALF, REQUIRED: a POPULATION assertion at teardown — zero surviving staged-service or\n  test-owned spt processes, by selectors external to the pid bookkeeping. SELECTOR RESPELLED\n  (hertz 2026-08-03, doyle-approved — the first spelling, \"parent-pid descent from the test\n  process\", would have caught ZERO of the 12: teardown kills the daemon before any check runs, the\n  BFS over the current (pid,ppid) table breaks at the dead middle hop, and descendants(test_pid)\n  returns empty exactly in the leak case — an absence read as a clean, the shape the lane exists\n  to kill; the control's own cleanup is the evidence, it had to use image+creation-window because\n  descent was already broken). THE TWO SELECTORS AS BUILT: (1) svcmock half by IMAGE PATH —\n  stage_adapter copies the service binary under this run's unique tempdir home, so \"any pid whose\n  exe_path canonicalizes under home\" names every staged service this run started and nothing else\n  on the box; no bookkeeping, immune to reuse and broken chains. (2) spt.exe half by SEEDED\n  descent + image — image alone is forbidden (target/debug/spt.exe is shared with concurrent\n  tests and live perches: the machine-wide selector class); seed with the ancestor set captured\n  WHILE ALIVE ({test, broker from the Child handle, brain from brain.ready — none via mock_pid}),\n  union descendants, keep only exe_path==spt_bin. Reuse exposure on seeds is assertion-only (a\n  red, never a kill) and the image filter closes it. Both halves catch the 12-leak conformance\n  case; the first spelling caught none of it. PLUS THE [[IR-8]] BUCKET, REQUIRED (deployah,\n  same night — the third instance of that sentence tonight, this time inside our own instrument):\n  both selectors match on IMAGE PATH, and an exe path that cannot be READ yields no match — a\n  leaked svcmock holding an unreadable path is invisible to both halves and the count comes back a\n  zero that cannot see. Not hypothetical: IR-8's defining specimen is 5/5-denied on this exact\n  image, on this box. So the population assertion counts unreadable-path processes as their OWN\n  bucket and the zero-survivors claim REFUSES when that bucket is nonzero — zero seen AND zero\n  unseeable, or the assertion states it could not see. Built in from the start, not retrofitted\n  (may land in the lane's second commit at hertz's discretion; the requirement is that it lands in\n  the lane). This instantiates IR-8's remedy test-side; the CI reap-census script half of IR-8\n  stays open.\n- **Fix (thin lane, hertz — doyle-ruled 2026-08-03):** adopt `authenticated_kill` at all three\n  sites. (Board #131's `CREATE_NO_WINDOW` rider is DROPPED from this lane — hertz falsified the\n  filed remedy at source 2026-08-03: daemon.rs has exactly ONE CreateProcessW (:1187) and\n  BASE_FLAGS (:1105) already carries 0x0800_0000 = CREATE_NO_WINDOW on both rungs including the\n  ACCESS_DENIED fallback (which drops only BREAKAWAY), so the specified edit ORs an already-set\n  bit — a bit-for-bit identical flag word that would close a board item while its symptom, if\n  real, continues. #131 handed back to board triage with the finding and a candidate direction:\n  DETACHED_PROCESS gives the service no console, so a console child the SERVICE spawns flagless\n  allocates a NEW visible window — the grandchild, not the daemon's spawn, is the candidate\n  surface; wants its own diagnosis from an observed window. ~~The `detached_no_inherit_env` rename\n  (\"detached\" actually means breakaway-from-job) is a candidate cosmetic rider on [[IR-16]]'s\n  product lane~~ — **RENAME DROPPED 2026-08-03, ITS PREMISE MEASURED FALSE** (todlando, on the\n  IR-16 lane; doyle re-verified at source before ruling). \"detached\" is ACCURATE: `BASE_FLAGS`\n  (daemon.rs:1103-1105) is `DETACHED_PROCESS | CREATE_NEW_PROCESS_GROUP | CREATE_NO_WINDOW`, and\n  `0x0000_0008` IS DETACHED_PROCESS — the function sets BOTH postures and the name states one of\n  them. The name is not wrong, it is INCOMPLETE (silent about `CREATE_BREAKAWAY_FROM_JOB`, which\n  arrives as `extra_flags` at daemon.rs:1506), so renaming on the stated premise would have traded\n  an accurate word for one that drops a flag the function really sets. Independently fatal: the\n  premise, if true, covers the sibling `detached_no_inherit` equally — 17 references across\n  daemon.rs/deelevate.rs/shellhost.rs — and renaming one of two siblings of ONE posture leaves the\n  tree MORE inconsistent, not less. **What lands instead:** one doc-comment line on EACH function\n  naming the full effective flag word, which fixes the real complaint (neither name says breakaway)\n  without touching a call site. Kept here rather than deleted because this entry was the claim's\n  only home, and a reader who found the rename gone with no reason would re-derive it.) PER-PID GROUND TRUTH for expected_exe (hertz — SELF-CORRECTED\n  at source before it ever landed; his first derivation, \"Copy runs from adapters_dir(), Pointer\n  runs from srcs/\", was WRONG and registration mode is NOT the discriminator): servicehost.rs:1328\n  takes `install_dir` from `record.source_dir` on the Started arm for EVERY service, Copy and\n  Pointer alike, and Copy copies only the manifest + strings/ (registry.rs:395-404), never a\n  binary — `adapters_dir()` holds no executable in either mode. BOTH services run from their OWN\n  staged src dir: `staged_bin(<adapter's staged src dir>, \"svcmock\")`. The trap survives with a\n  different mechanism: two adapters staged into two DIFFERENT source dirs are two different files\n  on disk, so one expected_exe still cannot serve both. A lane that trusted the mode split would\n  derive a path with no binary at it. How it was caught, kept because it is the reusable part: not\n  by rereading the mode table but by finding where install_dir is COMPUTED instead of trusting an\n  already-published inference — the mode split was true of MANIFESTS and had been generalized to\n  BINARIES without checking the consumer; and the derivation-asserted-at-observe() instrument\n  would have caught it at runtime regardless — the instrument did its job before it ever ran,\n  argued against its own author. SCOPE_LOST RULED A GUARD, NOT A FINDING (hertz design change,\n  doyle-approved): a seed pid recycled before the sweep makes the sweep DECLINE that subtree\n  loudly, not fail — failing would turn ordinary pid churn on a busy runner into a red against a\n  clean teardown (the IR-15 false-red class re-minted inside its own fix); coverage holds without\n  it because the staged services are caught by image-path-under-home and the daemon + brain by NEW\n  direct per-pid target_gone checks (their pids this test never loses) — the ancestry half is\n  reach, not load-bearing. `unreadable` stays FATAL as ruled.\n  Sequencing: positive control\n  first (it is the instrument that could still refute the mechanism), then the lane. Does NOT ride\n  [[IR-16]] (doyle-ruled same day): that is the product-side kill_tree audit and stays a separate\n  lane under the dispatch split; the two cross-ref, they do not merge.\n- **Lane trap, flagged before build (hertz 2026-08-03 — the false-clean shape):** `expected_exe`\n  differs PER PID. `boot_pid` and `rel_service_pid` run the staged svcmock image, NOT spt.exe —\n  passing spt_bin for those refuses every kill as foreign-image and LEAKS both services while the\n  reap reads hardened. Only `brain.ready`'s pid takes spt_bin. Also: `observe()` boot_pid at :210\n  while it is provably ours, so the reuse check has creation-time teeth instead of degrading to\n  image+ancestry.\n- **Gate the lane on killing, not on refusing (deployah 2026-08-03; REFINED by hertz same night\n  from reap.rs's own contract):** the hardened version fails safe in the WRONG direction —\n  refuse-everything leaks both services while printing exactly the reap line a reviewer wants to\n  see, strictly worse than the bare kill it replaces and invisible in the same log. But a BLANKET\n  zero-REFUSED gate is wrong too: reap.rs's module doc (:18–20) states refusal is the CORRECT\n  happy-path outcome when the test already stopped its daemon (`Refused(\"gone\")` — leak insurance,\n  not primary teardown), so the blanket gate reds healthy runs, someone loosens it to go green, and\n  the loosened version is exactly the one blind to foreign-image — the detector dies by\n  maintenance, wearing a green. The refusal reasons split, and only one class is a defect:\n  SOUND (expected): `gone`, `reused`, `breadcrumb-moved`, `self`, `ancestor` — target provably not\n  there. TRAP (the false-clean state): `foreign-image`, `unreadable-image`, `unproven-identity` —\n  something WAS there and authentication declined; `foreign-image` is precisely what a wrong\n  per-pid expected_exe produces on every pid, every run. THE GATE: in the arm that must kill,\n  assert no verdict in the trap class — structurally on the returned `Verdict` (Killed |\n  Refused(&'static str), stable tokens by design, reap.rs:48), not by scraping output; the\n  `REAP[label]: … verdict=` line stays as CI-log forensics. The gate's comment MUST say\n  `Refused(\"gone\")` is expected, or the next reader \"fixes\" it. Positive counterpart that actually\n  proves the reap: assert `target_gone(pid, expected_exe, observed)` (reap.rs:215 — no-knowledge\n  never read as death) per service pid; bare-liveness \"no survivors\" is the false-clean named above.\n  TOKEN SET VERIFIED COMPLETE-PLUS-ONE (deployah, refuse() sites enumerated at source): the eight\n  tokens above sit at :128 self, :132 ancestor, :136 breadcrumb-moved, :146 gone, :149\n  unproven-identity, :155 reused, :166 unreadable-image, :172 foreign-image — each in the right\n  class — and there is a NINTH neither list held: `Refused(\"no-breadcrumb\")` at :243, returned\n  before authenticated_kill is reached. Doyle-ruled 2026-08-03, both halves: (1) `no-breadcrumb`\n  classifies SOUND — **SCOPED (deployah source-read, same night): it is two states wearing one\n  name.** `breadcrumb_daemon_pid` (reap.rs:59–63) collapses file-absent, permission-denied, any IO\n  error, AND a husked/unparseable partial write into one `None` via two `.ok()`s — so the token is\n  ABSENCE OF KNOWLEDGE, not proof of absence, and it is SOUND only because the calling test has\n  already asserted its daemon stopped. Every other SOUND token carries positive proof; a LIVE\n  daemon whose pid file is unreadable or husked emits the identical token and leaks wearing\n  \"nothing to reap\" — the helper's one fail-open path inside a fail-closed design (its own module\n  doc: no-knowledge is never read as death), and the same sentence as [[IR-8]]: a zero that cannot\n  see is not a zero. CORRECT REMEDY (doyle-ruled, deferred — not this lane, unreachable from this\n  test's pids): split at source into `no-breadcrumb` (absent) vs `unreadable-breadcrumb` (TRAP,\n  beside unreadable-image) — IR-8's unreadable-bucket fix in a second location; land the pair in\n  the census/reap wave IR-8 already names, one remedy for two entries. Precondition on the split\n  (hertz): common/reap.rs compiles into EVERY spt integration test binary, so enumerate the callers\n  that actually REACH `reap_breadcrumb_daemon` before the token split lands — those are the tests\n  whose teardown semantics change; own lane, not a rider. ENUMERATION DONE (deployah, same night,\n  read-only): 21 caller tests, every one passing &spt_bin as expected_exe (the per-pid trap is\n  specific to resident_service_e2e's svcmock pids — it does not generalize to this population);\n  20 callers fire-and-forget the Verdict; the one value-assertion, reaper_guard.rs:192-196, pins\n  `Refused(\"no-breadcrumb\")` for an ABSENT breadcrumb only — absent KEEPS the token under the\n  split, so that assertion survives unchanged (:183's stale-pid check is the loose\n  `matches!(Refused(_))`). The split is ADDITIVE: one source split, one new token, zero caller\n  rewrites. THE GAP THAT LET THE COLLAPSE HIDE: reaper_guard covers eight refusal shapes but has\n  NO test for an unreadable or malformed daemon.pid — the one state where absence-of-knowledge\n  reads as absence-of-target is the one state without a conformance test; (b) ships with exactly\n  that evidence (a garbage daemon.pid and an unreadable one, each asserting the new token).\n  ASSIGNED: deployah owns the (b) lane (doyle-ruled 2026-08-03), SEQUENCED AFTER hertz's IR-18\n  lane — the exhaustive panic-catch-all lands first, so the new token arrives forced-classified\n  per this entry's own design, and the (b) lane classifies it TRAP in the same change. SCOPE\n  RE-RULED (2026-08-03, on deployah's third-site find): the collapse now has THREE known sites\n  (reap.rs:59-63, resident_service_e2e's mock_pid :100-106, and the shape wherever a test reads a\n[…520ln elided…]\n\n- **Three DIFFERENT victims across two loaded runs**, all process/timing-shaped, all PRESENT AT MAIN\n  and green there: `servicehost::…a_service_that_ignores_the_stop_marker_is_force_killed_and_confirmed_dead`\n  (panics `ForceKilled must MEAN the owned child is gone` right after `SERVICE_KILL_UNCONFIRMED`),\n  `applyhost::…broker_reports_its_compiled_image_version_over_ipc`, and\n  `daemon::…a_tree_teardown_reaches_a_grandchild_the_service_spawned`.\n- **MECHANISM: in-process thread interference, not product code.** Bare `cargo test` runs a crate's\n  tests as threads in ONE process. The lane's five new tests are process-spawning kill-tree tests;\n  under load they starve confirm windows of NEIGHBOURING tests that were always marginal. Removing\n  exactly those five flips 2-of-3-red to 0-of-3-green at the same sha, in the same binary, at the\n  same durations — one of the green runs sits at 117s, precisely a duration that had produced two\n  failures with them present.\n- **IT DOES NOT REACH GOLDEN.** nextest gives every test its own process, and golden runs nextest.\n  The population is GATE RIGS AND LOCAL RUNS — the same population as [[IR-21]], reached by a\n  different mechanism, which is why these are two entries and not one.\n- ⚠ **The instrument switch is the whole finding.** Measured with bare `cargo test`, this reads as a\n  lane blocker; measured with the tool CI actually runs, it is a rig-scoped nuisance. Anyone\n  re-opening this must state WHICH instrument produced their observation before quoting a verdict.\n  The same tool gap acquitted [[IR-21]]'s golden question the same day.\n- ⚠ **The pre-existing fragility is NOT thereby closed.** Those three tests were marginal before this\n  lane and the lane only exposed them; \"make the new tests quieter\" would re-hide a real weakness.\n  Hardening them is test-side work (hertz's lane by the dispatch split), not the builder's.\n- **Two rig defects of the gater's, recorded because they nearly cost the verdict:** (1) a first\n  re-run at rest came back 4/4 green and proves NOTHING — a sequential idle probe cannot express a\n  load-sensitive failure, so that is a competence-controlled zero, not an acquittal; (2) the first\n  baseline attempt ran its two arms UNSYNCHRONISED (the load generator finished while the measured\n  arm was still on run 1), which would have compared a loaded lane against an idle main and read as\n  \"the lane broke it\". A discriminator whose arms ran under different conditions cannot discriminate.\n- **Ripe when:** alongside [[IR-21]] on the next gate-rig or CI-touching wave, or immediately if\n  anyone starts gating on bare `cargo test` on a loaded box. **Size:** small to document the rig\n  rule (gate with nextest); medium to harden the three marginal tests.\n\n### IR-26 — POOL-OWNER claims authorize takeover from a DEAD holder, so releases#103's hazard reaches through the guard\n- **Status:** OPEN for residual claim-time observability and stale-reader enforcement; the\n  original build-side lane is COMMITTED (see its later reconciliation below), not still\n  uncommitted. Header corrected 2026-09-11; no residual closed by cleanup. · **Origin:**\n  hertz 2026-08-03/04, found by its own test rather than by reading, and\n  reported unfiled for composition. Composition ruling is doyle's, 2026-08-04.\n- **What/why:** a POOL-OWNER claim named a holder pid; lane liveness was read from whether that pid\n  was alive. hertz MEASURED the failure on this box: **3 of 3 claims had dead holders while one of\n  those lanes was live** — so the guard authorized exactly the interleaving takeover releases#103\n  exists to prevent. The remedy records the lane's GIT IDENTITY (branch + the base sha it carried at\n  claim time) and reads lane state from ancestry: in flight while the tip is not contained in\n  `origin/main`; settled once merged, once the branch is gone, or once the branch no longer carries\n  the claimed base (the branch-level twin of a recycled pid). Holder pid demotes to advisory — a\n  LIVE holder still refuses, a dead one no longer authorizes.\n- **The strongest finding in it, and it is a filter-competence one:** without the base anchor, a\n  missing branch read as \"settled, branch gone\" **out of a directory that was not a repository at\n  all**. An unanchored Settled verdict is a clean zero produced by a filter that cannot express the\n  question. A Settled verdict now requires the base object to be present in the reading repo;\n  unanchored is UNKNOWN. Sibling of [[zero-match-filter-reads-as-absent]] in the pool domain.\n- ⚠ **POLARITY, stated rather than buried:** the new arm (dead holder + unlanded lane => REFUSE)\n  converts a false-TAKEOVER into a false-REFUSAL. That is the better failure but not a free one, and\n  its triggering case is not exotic — it is an agent going down mid-lane, which happened to hertz\n  itself this same batch and cost [[IR-1]]/[[IR-4]]/[[IR-9]] their landing. **The open gating\n  question, put to hertz 2026-08-04 and NOT yet answered:** from the refusal state, does\n  `pool-release` still clear a claim whose holder is dead and whose lane is unlanded, or does the new\n  arm refuse that too? A guard whose only escape is the blanket `SPT_POOL_UNCHECKED=1` trains people\n  onto the blanket override. The refusal must NAME the remedy, not only the witness, and the remedy\n  must be exercised FROM the refusal state rather than reasoned about ([[remedy-must-run-from-refusal-state]]).\n  If the answer is \"it refuses\", that is a design change and returns to doyle before the lane lands.\n- **COMMITTED 2026-08-04 (was uncommitted when first measured):** `ci/poolowner-lane-claim` =\n  `8ce40d9` (the change) + `98cfafe` (the remedy fix below), both off `b7b00c3`. The original\n  measurement found ZERO commits and six modified files in `.worktrees/hertz-poolowner`, i.e. every\n  reported number had been measured against a tree no git object captured; the builder committed on\n  being told. Recorded because the near-loss is the lesson, not the correction.\n- **THE REMEDY DID NOT RUN — measured from the refusal state, which is the only place the question\n  can be asked.** The refusal named its witness AND a command, and executing that command verbatim\n  failed with the IDENTICAL `SPT_POOL_FOREIGN` block that printed it: **xtask depends on spt-store,\n  so every command that builds the tool goes through the pool being refused.** This is the same dead\n  end the unclaimed-foreign arm already hit in the field and fixed by leading its line with the\n  hatch — adding a second refusal arm re-broke it immediately. FIXED at `98cfafe`: the in-flight\n  remedy now leads with the hatch and names `pool-claim`, the command that actually resolves\n  ownership. Full chain re-measured on hfenduleam: refuse → verbatim remedy fails → hatch-prefixed\n  form succeeds → build proceeds.\n- **Answer to \"does `pool-release` clear a dead-holder + unlanded claim\", two-part:** it DOES — it\n  never consults the verdict, it rewrites `lane=None` — **but it is NOT the exit**, because after\n  release the same build is refused again on the pre-existing unclaimed-foreign arm (\"no lane has\n  claimed this pool\"). Release moves you from one refusal to another. `pool-claim` is the exit.\n- **The guard is a POPULATION, not a row** (builder's generalization, adopted by doyle as the\n  standard for this class): one test poses all three refusal arms and asserts that any remedy naming\n  a command leads with the hatch, PLUS membership — three posed, three refused — so no arm passes by\n  never being reached. The rule had been learned once already and the next arm added broke it, which\n  is the definition of something that needs a population test rather than a better comment. 26/26.\n- ⚠⚠ **FLEET PROPERTY — the rig refuted itself, and this is the entry's most important line.** The\n  first arm did NOT refuse, it TOOK OVER: the arriving worktree was at `b7b00c3`, so the build script\n  that ran was ITS OWN, pre-identity. **Enforcement code comes from the ARRIVING tree, never from\n  the claim.** So until this lands everywhere, an old tree still takes a live lane's pool, and the\n  guard is only ever as new as the tree that arrives. Found by measurement; reasoning would have\n  reported a refusal the rig never produced.\n- **RULING on the fleet property (doyle 2026-08-04) — a stamp VERSION LINE is REFUSED, and not on\n  taste: it cannot work.** The tree that must refuse is the OLD one, and an old build script does not\n  read a new stamp field because it does not know the field exists. You cannot make a stale enforcer\n  honor a new rule by writing something new into the record it enforces against — **the reader is\n  the problem, not the record.** A version line would help only a CURRENT tree explain itself while\n  doing nothing to the population it is aimed at, i.e. it would retire the worry without retiring the\n  risk. Ruled instead, in priority order: **(1)** land it and state the migration window honestly —\n  the arm protects a lane only when the ARRIVING tree carries the change, coverage grows as trees\n  turn over, never retroactive; **(2)** NAME THE LOSS YOU CANNOT PREVENT ([[IR-16]]'s pattern) — the\n  claiming side may be able to notice afterwards that its pool was taken and say so loudly, turning\n  silent artifact corruption into a named event; scope separately and MEASURE whether the claiming\n  side can observe it at all before committing; **(3)** SHRINK THE POPULATION — old enforcers are old\n  trees, this box carries ~45 worktrees and most are stale, so reaping them is real mitigation and\n  cheaper than code. (2) and (3) do NOT ride this lane.\n- **The unanchored row, as asked:** `a_claim_from_another_repository_reads_unknown_not_settled` was\n  RED before the base-object requirement existed. Verbatim: `left: Settled { reason: \"lane branch\n  build/lane-x no longer exists\" }  right: Unknown`, out of a tempdir that was not a repository at\n  all. It fails without the requirement and passes with it — a real negative control, not a row that\n  only ever passed.\n- **Builder's evidence (as reported, against that uncommitted tree):** spt-poolguard 25/25 with 7 new\n  rows, one per precedence cell, two carrying their own negative control; pool_guard_canary 3/3;\n  `cargo check -p xtask -p spt-store --all-targets` clean; clippy clean on the three touched crates;\n  `traceable-reqs check` exit 0 at 745/745 with new `REQ-POOL-LANE-IDENTITY` complete at doc+impl+unit.\n- **Composed:** its OWN thin lane, riding the same next golden batch as the CI-rider cluster but NOT\n  merged into it (doyle ruling 2026-08-04). A red must stay attributable: the riders change what the\n  pipeline measures, this changes a build-time REFUSAL, and a guard whose failure mode is refusing\n  builds is the worst thing to make inseparable from a pipeline change. IR-14's four-trees-into-one-\n  unclaimed-pool finding stays OUT of this lane and stays IR-14's, on the same ground [[IR-24]] was\n  kept out of [[IR-16]] — folding it in settles its question in passing.\n- **Ripe when:** next CI/infra batch, gated on the polarity question above being answered first.\n  **Size:** small once the remedy question is settled.\n- **FALSE-LIVE, first specimen of the blocking polarity (hertz sweep, measured 2026-08-04):**\n  `.worktrees\\hertz-ci-riders\\target\\POOL-OWNER.json` named `holder_pid 31380` with\n  `holder_started_at 134302739211259713` = 2026-08-03 16:38:41. Pid 31380 on that box at read time was\n  `claude.exe -n \"doyle @ HFENDULEAM (spt-core/)\"`, created 17:31:11, FILETIME 134302770715019370.\n  Same boot, ~52 minutes apart, stamps MISMATCH. The claiming process died and the OS reissued its pid\n  to the gater's own session. Every previously measured recycle produced a false-DEAD (reads free\n  while the lane is live — the corrupting direction); this one produces a **false-LIVE**: a bare-pid\n  guard reads the claim as held by a running holder and refuses, naming doyle as the holder of hertz's\n  pool — the blocking direction, first time caught. The `holder_started_at` arm shipped in `8ce40d9`\n  discriminates it correctly — that field caught defending, not asserted to defend\n  ([[stable-anchor-is-not-a-recycling-defense]]).\n- **The mirror image, same box, same hour:** `.worktrees\\ir24-reap\\target` named `holder_pid 33612`,\n  DEAD — while that lane was genuinely LIVE, with `cargo clippy -q -p spt-daemon --lib --tests`\n  (pid 22452) running under todlando's session as it was read. Two claims, opposite errors, inside one\n  hour: liveness misreads in BOTH directions on the same box in the same hour. Holder liveness has no\n  sound polarity as a lane-state oracle. Ancestry decides ([[pool-claim-holder-death-is-not-lane-state]]).\n- **THE BARE-CLAIM GAP — a claim the stamp arm cannot adjudicate at all.** The main checkout's own pool\n  (`<root>\\target`, 72,001,016,671 B = 67.06 GiB) carries\n  `{\"owner_tree\": \"...\\\\spt-core\", \"written_by\": \"spt-poolguard\"}` — no `lane_label`, no `holder_pid`,\n  no `holder_started_at`, no `lane_branch`, no `lane_base`. `read_owner` maps that to `lane: None`, so\n  every arm the lane-identity work added is unreachable for it: it cannot be read as in-flight,\n  settled, or recycled. **FIVE of the eight** claims found on this box are this shape — `<root>\\target`,\n  `<root>\\target-seam` (below), `gate-target-render`, `ir21-xtask\\target`, `locksmith-t1\\target` —\n  against three carrying a lane identity (`hertz-ci-riders`, `hertz-poolowner`, `ir24-reap`). A claim\n  written by a plain build rather than by `pool-claim` is structurally un-adjudicable, and it is the\n  MAJORITY shape in the field. Whatever IR-26 does next has to say what an identity-less claim means —\n  \"the stamp arm handles it\" is false for most claims that actually exist.\n- **The fifth bare claim was invisible to the first inventory, and the miss is its own lesson:**\n  `<root>\\target-seam`, **52.06 GiB**, real dir, gitignored on its own line (`/target-seam`, added\n  `5ae68f8`, v0.12.1 era), created 2026-06-18, last written 2026-08-02 — nothing in the tracked tree\n  references it (grep over rs/toml/md/yml/ps1/sh: zero hits outside this file). The inventory predicate\n  was \"a directory named `target` inside a worktree\"; a second root-level pool under a different name\n  is not expressible in that filter, so it returned a clean zero that was reported as a population\n  ([[verdict-from-probe-competence]] in the field). Corrects the earlier \"72 GB root pool is the\n  biggest object by 9x\": the two root pools are 67.06 + 52.06 = 119.1 GiB of a 133.43 GiB box pool\n  total, so the 44-tree sweep covered ~61% of pool bytes, not the population. **Ruling (doyle,\n  2026-08-04): target-seam stands for now** — free space is ~115 GB against the 32 GB golden floor, so\n  there is no pressure; it was written to yesterday, so \"cold\" is one day deep and its writer is\n  unidentified. It becomes a reap candidate at the next free-space squeeze, after a fresh last-write\n  check and identification of what wrote it on 08-02 — reaping a pool whose writer you cannot name is\n  how the v0.51.0 fabricated-red class starts.\n- **CLAIM-OBSERVABILITY, MEASURED (hertz, 2026-08-04, three-arm rig with competence control):** a\n  displaced claimant CANNOT distinguish takeover from never-claimed — the two states are byte-identical\n  on disk (arm 1 vs arm 2 identical; arm 3 proves the rig separates states that differ, so the null is\n  real). The takeover is silent on BOTH sides: the taker's `pool-claim` prints ordinary success naming\n  no prior owner. Mechanism at `b75258d`: `pool_claim` never calls `read_owner` — it constructs its own\n  `PoolOwner` and `fs::write`s unconditionally. The displaced lane's only channel is its next build's\n  refusal, which reports a STATE (\"this pool belongs to B\"), never a transition, and arrives pull-only\n  and arbitrarily late while interleaved-artifact harm is already underway. Labelled holes: measured\n  against the origin/main xtask binary (lane-tip carry is a source read, not a measurement);\n  pool-sweep-as-channel not exercised; single-process holder pid in all arms.\n- **Bootstrap property, not a defect (hertz, measured 2026-08-03 while claiming pools for the lanes\n  3-4 rebases):** a lane DELIVERING claim-identity cannot claim its own pool WITH that identity until\n  it lands — the prebuilt origin/main `xtask.exe` writes old-shaped stamps (owner_tree, lane_label,\n  holder pid+stamp; no lane_branch, no lane_base). Enforcer turnover surfacing at CLAIM time rather\n  than build time: coverage grows only as trees turn over. Recorded because it reads as a bug the\n  first time someone meets it in the field. Related lane-craft fact from the same queue: a rebase\n  changes SHAS necessarily but hunk OFFSETS only incidentally — todlando's main.rs hunks stayed at\n  @20/@53/@70 across the f2e4516→2f427b2 rebase; treat pre-rebase overlap measurements as stale by\n  construction and re-measure, but expect the geometry to usually hold.\n- **Bootstrap property FIELD INSTANCE, main checkout (todlando 2026-08-04, IR-12 rig):** the\n  prebuilt `target/debug/xtask.exe` in the MAIN checkout pool was stale against main's own source\n  at `11169c1` — it printed `(holder pid …, born …)` and wrote a FLAT identity-less claim\n  (owner_tree/lane_label/holder_pid/holder_started_at/written_by) where main's source\n  (main.rs:2282) prints `(branch …, base …; advisory holder pid …)` and writes the nested lane.\n  A lane claimed with a stale tool records NO git identity and demotes its own adjudication back\n  to the refused bare-pid predicate. DETECTION that worked and is the reusable part: read the\n  claim line the tool PRINTS against the source just read — a mismatch names the stale enforcer\n  before it writes. REMEDY at claim time: rebuild xtask FROM THE LANE'S WORKTREE before\n  `pool-claim` (which the protocol's claim-from-your-own-worktree rule already implies; this\n  instance is why it is load-bearing and not ceremony).\n- **RULING (doyle, 2026-08-04) — the claim path must run the same guard the build path runs, and a\n  takeover becomes an event.** The documented design already says a finished lane is \"taken over\n  loudly, not refused\"; a silent unconditional overwrite violates the spelling the protocol shipped\n  under. Remedy, both halves, one small lane: (ii) `pool-claim` reads the prior owner before writing —\n  prior lane LIVE (ancestry + stamp arm, never bare pid) ⇒ refuse exactly as build.rs would; prior\n  lane finished ⇒ proceed AND announce the displacement, naming the displaced lane in the success\n  line; plus (i) a `displaced` field (prior owner + takeover stamp) rides the new claim, so the fact\n  survives in the artifact the late-reading claimant already reads. The identity-less bare claim\n  (majority field shape, above) must be handled explicitly by the same change: a bare claim carries no\n  lane to adjudicate, so takeover of a bare claim always proceeds-and-announces, and the announcement\n  names the claim as identity-less — never silently, never refused. Ripe: next CI/infra batch, same\n  lane as or beside the IR-26 remedy. Size: small.\n\n### IR-27 — A junction-pooled rig is TWO objects and teardown only ever removes one\n- **Status:** open, found in the wild 2026-08-04 · **Origin:** hertz's 44-tree worktree sweep\n  (IR-26 follow-on 3) · **Cross-ref:** [[IR-14]] (unclaimed pools), [[worktree-target-junction]]\n…\n\n…\n- **Discipline and receipt.** [Windows ad-hoc rig launch discipline](GOLDEN-CI.md#windows-ad-hoc-rigs-that-outlive-the-tool-call) states the shape, child-owned durable output and post-return PID/birth/output qualification. Preserved harmless-child receipt: `.spt/preserved/hertz-ir137-caller-return/receipt.json`, SHA256 **`e1c9b207544e6313eac5421ebb692786ec18b3a165756b451bff3a704899b178`**. Both valid arms survived under **OMP**, wrote post-return events and exited0; an initial observer-handshake timeout is excluded. All3probe children ended and native handles closed. This does not reproduce the **Claude Code** failure; the host boundary stays explicit. Reopen only for a newly owned callsite or contrary evidence, not to build an unused helper.\n\n[Showing lines 1-219 and 740-951 of 951; 520 middle lines (41.5KB) elided. Use :1809 to continue. Read artifact://728 for full output]"}],"details":{"truncation":{"content":"\r\n### IR-18 — resident_service_e2e kills breadcrumb pids BARE (stale-breadcrumb tree-kill; kill-side twin of IR-15)\r\n- **Status:** BUILT 2026-08-04 — the named acceptance carrier RAN and the condition is DISCHARGED,\r\n  stated as the measurement rather than as the green board it sat on: LOCKSMITH's golden run\r\n  30860770146 (head `b7b00c3`, conclusion success) executed the changed test IN-POOL on BOTH\r\n  platforms — `spt::resident_service_e2e a_declared_service_rises_with_the_daemon_and_reaches_the_cli`\r\n  PASS 17.773s (100/2637) on hfenduleam/Windows and PASS 17.895s (1364/2616) on kitsubito/Linux.\r\n  The pool was checked for the test rather than inferred from the job colour, because a green leg\r\n  that never ran the test is a competence-controlled zero, not an acquittal; `resident_service_e2e`\r\n  contains exactly ONE `#[test]`, so the test that ran IS the test the lane rewrote (229 lines of\r\n  that file changed in `6e1a962`). No red returned to doyle. `.worktrees/ir18` is released for\r\n  teardown by this verdict · **Origin:** hertz\r\n  characterization of the [[IR-17]] resident_service red, 2026-08-03 — CANDIDATE mechanism, NOT a\r\n  reproduction\r\n- **Lane:** hertz `fix/ir18-authenticated-teardown` — MERGED to main @6e1a962 (PR #142; gated at\r\n  b48e35b, rebased 6e1a962 on 1e520b4 with zero code delta — doyle re-derived `git diff -- crates/`\r\n  empty across the rebase, so the gate verdict and local behavioral evidence transfer). Gated by\r\n  doyle: full diff review (one blocking finding — the scope_lost assert condition contradicted its\r\n  own guard ruling — fixed and delta-verified at one line), mutation-proven locally both\r\n  directions (B: forced boot_pid=None → population sweep names the leak no per-pid check sees,\r\n  FAIL 101; A: wrong expected_exe → REFUSED-foreign-image reds loudly on the derivation check).\r\n  EVIDENCE SPLIT, stated so the check marks cannot carry it (hertz's absent-leg callout): lane CI\r\n  30792210008 was 5/5 green per job but ci.yml's test leg is kind(lib)+kind(bin) — the changed\r\n  integration test NEVER RAN there (verified by log grep, 0 hits / 3023 lines); CI proved\r\n  compile-everywhere (clippy all-targets = the pool-population check for a common/ module),\r\n  traceability, lib/bin clean. The BEHAVIORAL evidence is local: three clean runs (all verdicts\r\n  Killed, population empty) + the two mutation reds. reap.rs diff additive-only (zero deleted\r\n  lines, verified) — cross-test risk bounded to compilation, which CI covered. Evidence custody:\r\n  gate + mutation logs at `.worktrees/_patches/ir18-gate-logs/` (5 files); `.worktrees/ir18` is\r\n  KEPT deliberately until the golden verdict (NOT an orphan — do not reap; a Phase A red wants the\r\n  tree and logs in place, not rebuilt); its pool claim is released.\r\n- **What/why:** `crates/spt/tests/resident_service_e2e.rs:46` defines its own reaper —\r\n  `taskkill /PID <pid> /F /T`: bare pid, force, whole TREE, no identity check — and feeds it three\r\n  BREADCRUMB-derived pids in cleanup (`boot_pid`, `rel_service_pid` at :360, and the pid read out\r\n  of `brain.ready` at :363). The suite already ships the authenticated tool other tests use and\r\n  this one does not: `common::reap::authenticated_kill(label, pid, expected_exe, observed)` at\r\n  `crates/spt/tests/common/reap.rs:116`. Inside the Phase A parallel pool on a pid-churning box\r\n  this is the KNOWN-HAZARDS stale-breadcrumb tree-kill class, live and **symmetric**: this test can\r\n  take a sibling's daemon and a sibling can take this test's. Same defect [[IR-15]] just fixed, on\r\n  the other side — IR-15 authenticated the READ (is the thing I pinned gone?), the KILL is still\r\n  bare pid. Kill what you pinned, not the number it happens to hold.\r\n- **Verified at source by deployah 2026-08-03** (relayed claims re-derived, all held): the bare\r\n  kill, its three breadcrumb feeds, the shipped-but-unused authenticated helper, and the\r\n  `CREATE_BREAKAWAY_FROM_JOB` spawn (`daemon.rs:1300`).\r\n- **Evidence rating — why it is a candidate and not a cause:** it predicts every field of the one\r\n  observed state line. The daemon is killed after spawning its boot service and before binding:\r\n  `broker_survived=false` (the discriminating field — false in every killed control round, true in\r\n  every healthy one) + `boot_alive=true boot_pid=Some(8920)` with the service's message in the\r\n  spool. (The \"empty stderr = silent death\" leg that originally sat here is RETRACTED — see\r\n  [[IR-17]]'s control record; stderr is empty on healthy runs too and discriminates nothing.)\r\n  The service outlives its daemon because `detached_no_inherit_env` spawns it\r\n  `CREATE_BREAKAWAY_FROM_JOB`, so it is NOT in the daemon's job and a daemon kill ORPHANS it\r\n  rather than reaping it — plausibly also the five denied `svcmock.exe` attempts in that job's\r\n  reap summary. **The [[IR-17]] positive control (2026-08-03) reproduced the shape 3/3\r\n  deterministically with a forced kill at that window — establishing the SHAPE on demand, not the\r\n  AGENT: nothing identifies who issued a kill in golden 30782259675.** The bare-pid tree-kill from\r\n  a concurrent test remains the candidate agent, on the source-verified hazard class and reap.rs's\r\n  documented prior casualty. **Not reproduced in the wild. Not proven. \"Root caused\" is not\r\n  written here by anyone.** The [[IR-17]] rate run is cancelled, so no rate will ever back this —\r\n  the fix stands on the source-verified hazard class alone. THE DEFECT IN MINIATURE, observed as a\r\n  side effect of the control (hertz 2026-08-03): the three killed rounds leaked 12 processes\r\n  (6 svcmock + 6 spt.exe, two services per round) and the test's own teardown reaped NONE — when\r\n  the daemon dies, `rel_pid` is `None` so that service is never even a kill target, and the\r\n  breakaway child outlives everything. A teardown that leaks two processes per round currently\r\n  PASSES: the concrete case for `target_gone` as the gate's positive half. (Leak cleaned scoped,\r\n  each pid re-authenticated by image-path prefix + creation window at kill time, not from the\r\n  minute-old enumeration.) ONE LAYER DEEPER (deployah, same night, at source): the reap loop\r\n  (:359) is `[boot_pid, rel_service_pid].into_iter().flatten()` — `.flatten()` DROPS None, and\r\n  `mock_pid` (:100-106) collapses absent/permission-denied/IO-error/garbage into that None via\r\n  `.ok()?`/`.ok()` — the reap.rs:59-63 collapse in a THIRD location, inside this very test. So the\r\n  leak is both \"service never started\" AND \"pid unreadable, therefore never a kill target\":\r\n  absence of knowledge read as absence of target, in a teardown, again.\r\n- **GATE SPEC AMENDED PRE-BUILD (deployah found the hole, doyle-ruled 2026-08-03 — read this\r\n  BEFORE building the lane):** the two halves as first specified (trap-class-absent +\r\n  `target_gone` per pid) both operate on pids we HAVE — a process whose pid is None is invisible\r\n  to BOTH, so the specified gate PASSES hertz's own control-run leak (12 processes, 6+6, 2/round,\r\n  teardown reaped none). A gate its own reproduction case passes is not yet an instrument. THIRD\r\n  HALF, REQUIRED: a POPULATION assertion at teardown — zero surviving staged-service or\r\n  test-owned spt processes, by selectors external to the pid bookkeeping. SELECTOR RESPELLED\r\n  (hertz 2026-08-03, doyle-approved — the first spelling, \"parent-pid descent from the test\r\n  process\", would have caught ZERO of the 12: teardown kills the daemon before any check runs, the\r\n  BFS over the current (pid,ppid) table breaks at the dead middle hop, and descendants(test_pid)\r\n  returns empty exactly in the leak case — an absence read as a clean, the shape the lane exists\r\n  to kill; the control's own cleanup is the evidence, it had to use image+creation-window because\r\n  descent was already broken). THE TWO SELECTORS AS BUILT: (1) svcmock half by IMAGE PATH —\r\n  stage_adapter copies the service binary under this run's unique tempdir home, so \"any pid whose\r\n  exe_path canonicalizes under home\" names every staged service this run started and nothing else\r\n  on the box; no bookkeeping, immune to reuse and broken chains. (2) spt.exe half by SEEDED\r\n  descent + image — image alone is forbidden (target/debug/spt.exe is shared with concurrent\r\n  tests and live perches: the machine-wide selector class); seed with the ancestor set captured\r\n  WHILE ALIVE ({test, broker from the Child handle, brain from brain.ready — none via mock_pid}),\r\n  union descendants, keep only exe_path==spt_bin. Reuse exposure on seeds is assertion-only (a\r\n  red, never a kill) and the image filter closes it. Both halves catch the 12-leak conformance\r\n  case; the first spelling caught none of it. PLUS THE [[IR-8]] BUCKET, REQUIRED (deployah,\r\n  same night — the third instance of that sentence tonight, this time inside our own instrument):\r\n  both selectors match on IMAGE PATH, and an exe path that cannot be READ yields no match — a\r\n  leaked svcmock holding an unreadable path is invisible to both halves and the count comes back a\r\n  zero that cannot see. Not hypothetical: IR-8's defining specimen is 5/5-denied on this exact\r\n  image, on this box. So the population assertion counts unreadable-path processes as their OWN\r\n  bucket and the zero-survivors claim REFUSES when that bucket is nonzero — zero seen AND zero\r\n  unseeable, or the assertion states it could not see. Built in from the start, not retrofitted\r\n  (may land in the lane's second commit at hertz's discretion; the requirement is that it lands in\r\n  the lane). This instantiates IR-8's remedy test-side; the CI reap-census script half of IR-8\r\n  stays open.\r\n- **Fix (thin lane, hertz — doyle-ruled 2026-08-03):** adopt `authenticated_kill` at all three\r\n  sites. (Board #131's `CREATE_NO_WINDOW` rider is DROPPED from this lane — hertz falsified the\r\n  filed remedy at source 2026-08-03: daemon.rs has exactly ONE CreateProcessW (:1187) and\r\n  BASE_FLAGS (:1105) already carries 0x0800_0000 = CREATE_NO_WINDOW on both rungs including the\r\n  ACCESS_DENIED fallback (which drops only BREAKAWAY), so the specified edit ORs an already-set\r\n  bit — a bit-for-bit identical flag word that would close a board item while its symptom, if\r\n  real, continues. #131 handed back to board triage with the finding and a candidate direction:\r\n  DETACHED_PROCESS gives the service no console, so a console child the SERVICE spawns flagless\r\n  allocates a NEW visible window — the grandchild, not the daemon's spawn, is the candidate\r\n  surface; wants its own diagnosis from an observed window. ~~The `detached_no_inherit_env` rename\r\n  (\"detached\" actually means breakaway-from-job) is a candidate cosmetic rider on [[IR-16]]'s\r\n  product lane~~ — **RENAME DROPPED 2026-08-03, ITS PREMISE MEASURED FALSE** (todlando, on the\r\n  IR-16 lane; doyle re-verified at source before ruling). \"detached\" is ACCURATE: `BASE_FLAGS`\r\n  (daemon.rs:1103-1105) is `DETACHED_PROCESS | CREATE_NEW_PROCESS_GROUP | CREATE_NO_WINDOW`, and\r\n  `0x0000_0008` IS DETACHED_PROCESS — the function sets BOTH postures and the name states one of\r\n  them. The name is not wrong, it is INCOMPLETE (silent about `CREATE_BREAKAWAY_FROM_JOB`, which\r\n  arrives as `extra_flags` at daemon.rs:1506), so renaming on the stated premise would have traded\r\n  an accurate word for one that drops a flag the function really sets. Independently fatal: the\r\n  premise, if true, covers the sibling `detached_no_inherit` equally — 17 references across\r\n  daemon.rs/deelevate.rs/shellhost.rs — and renaming one of two siblings of ONE posture leaves the\r\n  tree MORE inconsistent, not less. **What lands instead:** one doc-comment line on EACH function\r\n  naming the full effective flag word, which fixes the real complaint (neither name says breakaway)\r\n  without touching a call site. Kept here rather than deleted because this entry was the claim's\r\n  only home, and a reader who found the rename gone with no reason would re-derive it.) PER-PID GROUND TRUTH for expected_exe (hertz — SELF-CORRECTED\r\n  at source before it ever landed; his first derivation, \"Copy runs from adapters_dir(), Pointer\r\n  runs from srcs/\", was WRONG and registration mode is NOT the discriminator): servicehost.rs:1328\r\n  takes `install_dir` from `record.source_dir` on the Started arm for EVERY service, Copy and\r\n  Pointer alike, and Copy copies only the manifest + strings/ (registry.rs:395-404), never a\r\n  binary — `adapters_dir()` holds no executable in either mode. BOTH services run from their OWN\r\n  staged src dir: `staged_bin(<adapter's staged src dir>, \"svcmock\")`. The trap survives with a\r\n  different mechanism: two adapters staged into two DIFFERENT source dirs are two different files\r\n  on disk, so one expected_exe still cannot serve both. A lane that trusted the mode split would\r\n  derive a path with no binary at it. How it was caught, kept because it is the reusable part: not\r\n  by rereading the mode table but by finding where install_dir is COMPUTED instead of trusting an\r\n  already-published inference — the mode split was true of MANIFESTS and had been generalized to\r\n  BINARIES without checking the consumer; and the derivation-asserted-at-observe() instrument\r\n  would have caught it at runtime regardless — the instrument did its job before it ever ran,\r\n  argued against its own author. SCOPE_LOST RULED A GUARD, NOT A FINDING (hertz design change,\r\n  doyle-approved): a seed pid recycled before the sweep makes the sweep DECLINE that subtree\r\n  loudly, not fail — failing would turn ordinary pid churn on a busy runner into a red against a\r\n  clean teardown (the IR-15 false-red class re-minted inside its own fix); coverage holds without\r\n  it because the staged services are caught by image-path-under-home and the daemon + brain by NEW\r\n  direct per-pid target_gone checks (their pids this test never loses) — the ancestry half is\r\n  reach, not load-bearing. `unreadable` stays FATAL as ruled.\r\n  Sequencing: positive control\r\n  first (it is the instrument that could still refute the mechanism), then the lane. Does NOT ride\r\n  [[IR-16]] (doyle-ruled same day): that is the product-side kill_tree audit and stays a separate\r\n  lane under the dispatch split; the two cross-ref, they do not merge.\r\n- **Lane trap, flagged before build (hertz 2026-08-03 — the false-clean shape):** `expected_exe`\r\n  differs PER PID. `boot_pid` and `rel_service_pid` run the staged svcmock image, NOT spt.exe —\r\n  passing spt_bin for those refuses every kill as foreign-image and LEAKS both services while the\r\n  reap reads hardened. Only `brain.ready`'s pid takes spt_bin. Also: `observe()` boot_pid at :210\r\n  while it is provably ours, so the reuse check has creation-time teeth instead of degrading to\r\n  image+ancestry.\r\n- **Gate the lane on killing, not on refusing (deployah 2026-08-03; REFINED by hertz same night\r\n  from reap.rs's own contract):** the hardened version fails safe in the WRONG direction —\r\n  refuse-everything leaks both services while printing exactly the reap line a reviewer wants to\r\n  see, strictly worse than the bare kill it replaces and invisible in the same log. But a BLANKET\r\n  zero-REFUSED gate is wrong too: reap.rs's module doc (:18–20) states refusal is the CORRECT\r\n  happy-path outcome when the test already stopped its daemon (`Refused(\"gone\")` — leak insurance,\r\n  not primary teardown), so the blanket gate reds healthy runs, someone loosens it to go green, and\r\n  the loosened version is exactly the one blind to foreign-image — the detector dies by\r\n  maintenance, wearing a green. The refusal reasons split, and only one class is a defect:\r\n  SOUND (expected): `gone`, `reused`, `breadcrumb-moved`, `self`, `ancestor` — target provably not\r\n  there. TRAP (the false-clean state): `foreign-image`, `unreadable-image`, `unproven-identity` —\r\n  something WAS there and authentication declined; `foreign-image` is precisely what a wrong\r\n  per-pid expected_exe produces on every pid, every run. THE GATE: in the arm that must kill,\r\n  assert no verdict in the trap class — structurally on the returned `Verdict` (Killed |\r\n  Refused(&'static str), stable tokens by design, reap.rs:48), not by scraping output; the\r\n  `REAP[label]: … verdict=` line stays as CI-log forensics. The gate's comment MUST say\r\n  `Refused(\"gone\")` is expected, or the next reader \"fixes\" it. Positive counterpart that actually\r\n  proves the reap: assert `target_gone(pid, expected_exe, observed)` (reap.rs:215 — no-knowledge\r\n  never read as death) per service pid; bare-liveness \"no survivors\" is the false-clean named above.\r\n  TOKEN SET VERIFIED COMPLETE-PLUS-ONE (deployah, refuse() sites enumerated at source): the eight\r\n  tokens above sit at :128 self, :132 ancestor, :136 breadcrumb-moved, :146 gone, :149\r\n  unproven-identity, :155 reused, :166 unreadable-image, :172 foreign-image — each in the right\r\n  class — and there is a NINTH neither list held: `Refused(\"no-breadcrumb\")` at :243, returned\r\n  before authenticated_kill is reached. Doyle-ruled 2026-08-03, both halves: (1) `no-breadcrumb`\r\n  classifies SOUND — **SCOPED (deployah source-read, same night): it is two states wearing one\r\n  name.** `breadcrumb_daemon_pid` (reap.rs:59–63) collapses file-absent, permission-denied, any IO\r\n  error, AND a husked/unparseable partial write into one `None` via two `.ok()`s — so the token is\r\n  ABSENCE OF KNOWLEDGE, not proof of absence, and it is SOUND only because the calling test has\r\n  already asserted its daemon stopped. Every other SOUND token carries positive proof; a LIVE\r\n  daemon whose pid file is unreadable or husked emits the identical token and leaks wearing\r\n  \"nothing to reap\" — the helper's one fail-open path inside a fail-closed design (its own module\r\n  doc: no-knowledge is never read as death), and the same sentence as [[IR-8]]: a zero that cannot\r\n  see is not a zero. CORRECT REMEDY (doyle-ruled, deferred — not this lane, unreachable from this\r\n  test's pids): split at source into `no-breadcrumb` (absent) vs `unreadable-breadcrumb` (TRAP,\r\n  beside unreadable-image) — IR-8's unreadable-bucket fix in a second location; land the pair in\r\n  the census/reap wave IR-8 already names, one remedy for two entries. Precondition on the split\r\n  (hertz): common/reap.rs compiles into EVERY spt integration test binary, so enumerate the callers\r\n  that actually REACH `reap_breadcrumb_daemon` before the token split lands — those are the tests\r\n  whose teardown semantics change; own lane, not a rider. ENUMERATION DONE (deployah, same night,\r\n  read-only): 21 caller tests, every one passing &spt_bin as expected_exe (the per-pid trap is\r\n  specific to resident_service_e2e's svcmock pids — it does not generalize to this population);\r\n  20 callers fire-and-forget the Verdict; the one value-assertion, reaper_guard.rs:192-196, pins\r\n  `Refused(\"no-breadcrumb\")` for an ABSENT breadcrumb only — absent KEEPS the token under the\r\n  split, so that assertion survives unchanged (:183's stale-pid check is the loose\r\n  `matches!(Refused(_))`). The split is ADDITIVE: one source split, one new token, zero caller\r\n  rewrites. THE GAP THAT LET THE COLLAPSE HIDE: reaper_guard covers eight refusal shapes but has\r\n  NO test for an unreadable or malformed daemon.pid — the one state where absence-of-knowledge\r\n  reads as absence-of-target is the one state without a conformance test; (b) ships with exactly\r\n  that evidence (a garbage daemon.pid and an unreadable one, each asserting the new token).\r\n  ASSIGNED: deployah owns the (b) lane (doyle-ruled 2026-08-03), SEQUENCED AFTER hertz's IR-18\r\n  lane — the exhaustive panic-catch-all lands first, so the new token arrives forced-classified\r\n  per this entry's own design, and the (b) lane classifies it TRAP in the same change. SCOPE\r\n  RE-RULED (2026-08-03, on deployah's third-site find): the collapse now has THREE known sites\r\n  (reap.rs:59-63, resident_service_e2e's mock_pid :100-106, and the shape wherever a test reads a\r\n  self-written pid file) — so (b) lands ONE shared read-a-pid-breadcrumb helper that distinguishes\r\n  absent from unreadable ONCE, adopted at the enumerated sites, not a per-site token split; the\r\n  single-source-discriminant rule, applied before a fourth site mints itself.\r\n  **THIRD SITE CONFIRMED AT SOURCE (deployah, read-only 2026-08-04) — it was a predicted SHAPE and\r\n  is now an address:** `crates/spt/tests/resident_service_e2e.rs:136-137`, `brain_ready`, which\r\n  `.ok()?`s BOTH the read and the JSON parse — two collapses in two lines, the self-written-pid-file\r\n  shape this entry predicted. What makes it the worst of the three rather than the third of three:\r\n  its output feeds `brain_seed`, a population-sweep SEED, so an unreadable `brain.ready` silently\r\n  drops a whole subtree from the sweep. The other two sites lose one pid; this one degrades the very\r\n  instrument that is supposed to cover them, and it does so while the sweep still reports clean —\r\n  [[IR-8]]'s sentence again, now inside the instrument rather than beside it. The (b) lane's helper\r\n  therefore has to be adopted at this site to be worth landing at all. Still deployah's,\r\n  still after hertz's lane; hertz's lane does NOT wait for it (the population assertion covers the\r\n  leak class independent of pid bookkeeping — that is its virtue). (b) INTAKE ITEM (doyle gate on\r\n  the IR-18 lane, 2026-08-03, deferred there deliberately): the lane's verdict-gate SOUND-arm\r\n  comment reads \"provably not there\", which overclaims for `no-breadcrumb` (absence-of-knowledge,\r\n  not proof — the scoped reading belongs at that arm); comment-only, and (b) rewrites that arm\r\n  when `unreadable-breadcrumb` splits out, so it lands there rather than costing a solo respin.\r\n  SECOND (b) INTAKE ITEM (hertz self-noted at re-gate, doyle-ruled deferred): cleanliness is\r\n  currently stated at THREE sites (two asserts + `is_clean`) — the drift that produced the\r\n  scope_lost condition bug (a failed edit followed by a narrower successful one replaced the\r\n  message but not the condition; the artifact of that failure mode IS message/code disagreement).\r\n  (b) consolidates to conditions derived from one source, weighing the two-message diagnostic\r\n  split it would cost. The\r\n  exhaustive panic-catch-all match is what makes the split safe to do later: the new token lands\r\n  loud on first fire in every consuming gate, forced to be classified, never silently passed. Until then the scoped reading above is the\r\n  gate's contract — and the LANE BUILDER writes that scoped reading into the match's SOUND-arm\r\n  comment (the sketch's \"nothing to read is nothing to kill\" is the exact inference the source\r\n  forbids; the comment must not teach the false step); (2) the gate closes over the\r\n  token set — SPELLED BUILDABLY (hertz correction 2026-08-03; the earlier \"no wildcard arm\" wording\r\n  is an instruction rustc rejects, since the refusal reason is a `&'static str` (:55) and a string\r\n  match always requires a catch-all): the match names the six SOUND tokens as a pass arm, the three\r\n  TRAP tokens as a panic arm, and the REQUIRED catch-all arm is not a wildcard PASS — it panics\r\n  naming the unknown token (\"unclassified reap refusal token — classify it in this match\"), so\r\n  upstream drift announces itself the first run it fires instead of sliding into a silent pass.\r\n  Runtime fail-closed, not compile-time: compile-time closure needs the reason to become an enum in\r\n  common/reap.rs, an upstream change touching every consumer — ruled NOT smuggled into this lane\r\n  (candidate for its own thin lane if ever wanted; doyle concurs runtime fail-closed is\r\n  proportionate). Direction of the default, kept in the record: a missed trap state is an invisible\r\n  leak wearing the reap line a reviewer wants to see; an unclassified harmless token is a loud red\r\n  costing one edit. Cheap and loud beats silent and wrong. (Count hygiene, hertz self-flagged: a\r\n  single-line grep for the refuse() sites returns five of nine — three wrap across lines; the nine\r\n  stands on reading, not the grep. The sweep-count trap in miniature.)\r\n- **Prior observed instance of the class, in-tree (hertz 2026-08-03 — stated to understate):**\r\n  reap.rs:3–11 documents the measurement and a casualty: pid reuse on the Windows gate box at\r\n  2.2s minimum / p50 11.7s under a Phase-A battery, and a concurrent test process killed by a bare\r\n  kill on a stale breadcrumb pid, dying with bare exit 1 and no panic — the observed\r\n  `worker_lifecycle_e2e` red in golden job 90742055246 (that test's intermittent class is board\r\n  releases#32, still in-flight). Different test, different job — it does NOT reproduce this entry's\r\n  specimen and promotes nothing; what it settles is that the class is real IN THIS SUITE with a\r\n  named victim, and the authenticated reaper is the remedy someone already built for it —\r\n  resident_service_e2e simply never adopted it. Two shape-predictions it supplies, made before this\r\n  specimen existed: the p50 11.7s reuse window is short against this test's 45s waits and ~124s\r\n  runtime (window wide open). (A second claimed match — \"bare-exit-1-no-panic matches the empty\r\n  daemon.stderr.log\" — is RETRACTED as a category error, hertz+deployah 2026-08-03: reap.rs's\r\n  phrase describes the VICTIM TEST PROCESS dying, not a daemon's log; two processes, two\r\n  artifacts.) Predictions, not proof; the specimen stays CANDIDATE — shape since reproduced on\r\n  demand, agent unidentified (see the control record above).\r\n- **Rig near-miss, caught before first execution (hertz 2026-08-03) — kept as design justification,\r\n  not an anecdote:** the positive-control arm's first draft selected its victim machine-wide\r\n  (`Win32_Process Name='spt.exe'` + cmdline match `daemon run`, then force-kill). hfenduleam is the\r\n  Windows CI runner as well as a dev box, so that filter matches CI's own test daemons: run while a\r\n  leg was live, it would have force-killed a running job's daemon and reported the result as a\r\n  measurement — fabricating a red in someone else's job, the exact class this entry documents.\r\n  Corrected to a parent-scoped selector (daemon = child of the test pid; service = child of that\r\n  daemon); `CREATE_BREAKAWAY_FROM_JOB` does not weaken parent-id attribution, since breakaway leaves\r\n  the JOB, not the parent record — which is also why the orphaned svcmock stays attributable to the\r\n  daemon that spawned it. **The load bought the catch** (blocked on the box ⇒ re-read instead of\r\n  ran). Bearing on the fix: the INSTRUMENT built to study a bare-selector reaper was itself written\r\n  with a bare selector. The remedy therefore cannot be \"be careful\" — the authenticated path must be\r\n  the only one within reach in this suite.\r\n- **Ripe when:** RIPE NOW, and not gated on the rate run that was cancelled.\r\n- **Size:** small.\r\n\r\n### IR-19 — Docs-only pushes to main run full unit legs (classifier is PR-only) — intent unverified\r\n- **Status:** RETIRED 2026-08-18 — intentional for main pushes, not a classifier defect. · **Origin:** hertz observation 2026-08-03 (register-push\r\n  cadence gated his rig behind repeated hfenduleam unit legs); mechanism verified by doyle at\r\n  source same night.\r\n- **What/why:** `ci.yml`'s `changes` job classifies docs-only diffs ONLY for `pull_request` events\r\n  — push events hardcode `code=true` (ci.yml:45–48, an explicit branch, not a fallthrough), so\r\n  every docs-only push to main spins both full unit legs. Tonight: five register docs pushes each\r\n  queued a Windows unit leg on hfenduleam; concurrency kept one running + one pending (main is\r\n  never cancelled in-progress, pending runs supersede — the recorded behavior matches ci.yml:9–13).\r\n  FINDING SETTLED (deployah, same night, from the workflow): this is not intent — it is a scope\r\n  the classifier never had; the `*.md` / `traceable-reqs.toml` case arms are only ever REACHED on\r\n  pull_request (the early-return precedes them), and golden.yml's own hardcoded `code=true` is\r\n  unrelated (golden triggers only on golden/**). REMEDY STILL OPEN on a named tension: extending\r\n  the classifier to pushes leaves a docs-only main TIP with no run of its own — fine if\r\n  tested-sha==merged-sha means \"the code at this sha was tested\" (it was, at the last code sha),\r\n  not fine if any gate or reader takes \"main tip has a green run\" as the check. One person reads\r\n  the consuming gates before any remedy (doyle, at the next CI-touching wave) — three assuming is\r\n  how this class ships.\r\n- **Resolution:** the consuming contract already answers the held question:\r\n  `REQ-CI-DOCS-ONLY-THIN` is PR-only and explicitly says ADR-0050 supersedes\r\n  it for main pushes. Main-tip evidence remains full by design; no classifier\r\n  branch was widened.\r\n- **Interim rule (doyle, same night):** batch register edits into one push instead of landing them\r\n  as they occur — the cadence is a real gate on whoever is queued behind the runner.\r\n- **Ripe when:** next CI-touching wave, after the intent question is answered on the REQ record.\r\n- **Size:** small (one conditional, if the answer is \"extend\").\r\n- **Composed:** LOCKSMITH (#132) — doyle reads the consuming gates during the batch's CI-touching\r\n  wave (the intent question), BEFORE any classifier remedy. 2026-08-03.\r\n\r\n### IR-20 — resident_service_e2e's `spt daemon stop --force` does not stop the daemon; teardown is complete only because the kills are\r\n- **Status:** open · **Origin:** hertz 2026-08-03, measured on the IR-18 lane's own clean run\r\n  (hfenduleam, log kept); routed text, doyle-landed.\r\n- **MEASURED:** teardown runs `spt(&[\"daemon\",\"stop\",\"--force\"])` then reaps. At reaper fire, every\r\n  target was still ALIVE and every verdict was `Killed`, not `gone` — verdicts=[boot Killed,\r\n  rel Killed, brain Killed]; the brain's kill line names it `(child process of PID 46896)` — the\r\n  daemon — so the daemon was still resident too and was taken down by the `Child` handle, not the\r\n  stop. A stop that worked would have left the reaper `gone`. This rules OUT the innocent reading\r\n  (stop doesn't manage services): the stop did not reach the DAEMON either.\r\n- **NOT ESTABLISHED — two rungs, neither discriminated:** (1) the rig seeds a `doyle` perch with\r\n  `std::process::id()`, satisfying `ceremony_agent_ground`'s pid-ancestry rung for every child of\r\n  the harness; (2) the rig never scrubs `OWL_SESSION_ID`/`SPT_AGENT_ID`/`SPT_ENDPOINT_ID` from its\r\n  teardown commands, and the measuring run launched from a live agent session, so the env rung was\r\n  live too. `--force` overrides neither. The stop's output is discarded at the call site\r\n  (`let _ = spt(...)`) — no diagnostic names a denial, and no claim is made that one fired.\r\n  Settling it is one run with the stop's stderr captured — on the CI runner AS WELL AS the dev box,\r\n  since the rungs fire on different machines.\r\n- **Why it matters beyond this rig:** REQ-TEST-RIG-DAEMON-TEARDOWN-PROVEN's own failure shape\r\n  inside a rig that passes — teardown completeness rested entirely on breadcrumb kills that were,\r\n  until IR-18, bare `taskkill /F /T` on unauthenticated pids; the most trustworthy-LOOKING\r\n  component (an explicit `--force` stop) was doing nothing while the least trustworthy one did all\r\n  the work. Exactly why the population gate exists rather than per-pid checks alone.\r\n- **Remedy caution (the sentence that must not drop):** the prescribed fix (seed pid 0, scrub the\r\n  three markers — REQ-TEST-RIG-DAEMON-TEARDOWN-PROVEN's own gate) is NOT free here: this rig's\r\n  `doyle` perch pid is load-bearing for the shell bind-by-token legs, so the two remedies are not\r\n  interchangeable — a lane taking this must check which legs depend on the pid before changing it,\r\n  or it fixes the stop and breaks the REQ-INSTALL-11 legs the rig exists for. Kin:\r\n  REQ-BROKER-STOP-ENDPOINT-DENY (the refusal being worked around).\r\n- **LANE-LINKED 2026-08-30 (#242 close sweep):** hertz's queued daemon-leak fixup lane carries\r\n  this entry (brief cites IR-7/17/20/34/35/63); leaves the register when that lane lands.\r\n- **Ripe when:** a hertz test-hardening wave, or alongside the (b) helper lane's touch of this rig.\r\n- **Size:** small (stderr-captured discrimination run × two machines, then the scoped remedy).\r\n\r\n### IR-54 — golden-head-intake runbook: three properties this cut proved should be construction, not discipline\r\n- **Status:** BUILT 2026-08-29 — PR #176 (`880b3b9c`, landed on main via `37368263`).\r\n  · **Origin:** PORTER (#205) v0.59.0 cut, 2026-08-21 — doyle (gater) + deployah (driver),\r\n  both mechanisms measured at the cut, neither cost this run anything because the driver caught\r\n  them by hand. Filed at the release-close register sweep.\r\n- **What/why (three runbook amendments, one lane):**\r\n  1. **Release-shaping at ASSEMBLY intake, not post-golden.** The head arrived code-complete\r\n     but not release-shaped (no version bump, stale CHANGELOG top section) — 5 of the last 6\r\n     cuts. v0.59.0 fixed it by authoring version material BEFORE the golden run, which is what\r\n     produced the four-name shape (ruled sha == main tip == golden ref == tag == `c62904e7`,\r\n     first time in six cuts; the previous five each argued a post-golden delta inert). Amend\r\n     `docs/golden-head-intake` so the gater's assembly checklist asks the release-shaping\r\n     question at intake and the driver never authors on top.\r\n  2. **Never-executed-cells list is a hand-off artifact.** The runbook makes it a\r\n     gater-compiles / driver-re-checks item; PORTER's handoff omitted it and the driver had to\r\n     ask. Name it in the assembly checklist beside the greenlit-form delta: which new cells'\r\n     first CI execution is this golden, and where each HAS executed (lane gate / assembled\r\n     head) — it converts a golden red from an RCA into a lookup.\r\n  3. **Lockfile-refresh rule states the PROPERTY, not the command.** Step 1 prescribes\r\n     `cargo metadata --offline`; the driver used `cargo update --workspace --offline` and\r\n     proved the actual rule by diff (workspace members only, third-party pins untouched —\r\n     14 first-party line pairs, 90 third-party unchanged). The property is the rule and the\r\n     diff is its evidence (the standing by-diff rule exists because counting misread v0.39.4\r\n     and v0.41.0 in opposite directions — and the `windows-sys` 0.59.0 collision was LIVE at\r\n     this cut, the exact condition where counting fabricates a 15th \"first-party\" bump);\r\n     demote the command to an example vehicle.\r\n- **Built evidence:** `docs/RELEASE-RUNBOOK.md` now asks the release-shaping question at assembly\r\n  intake, makes the never-executed-cells list part of the hand-off itself, and states lock refresh\r\n  as a diff-proven property with commands demoted to example vehicles. PR #176 passed\r\n  `traceable-reqs check`; the v0.65.0 cut had already exercised the release-shaped-head rule.\r\n- **Size:** small (one runbook doc lane; no code).\r\n\r\n## IN-FLIGHT ON THE BOARD (not re-homed — live WIP lanes)\r\n\r\n- releases#93 (servicehost swap test pid-inequality), releases#47 (thin-lane unit(Windows)\r\n  isolation class), releases#32 (worker_lifecycle_e2e Phase A intermittent) — infra-shaped but WIP;\r\n  a live lane is never re-homed mid-flight. When each closes, any residue lands here as a new entry.\r\n\r\n## BUILT / RETIRED\r\n\r\n### IR-15 — provably_gone is pid-only on Windows: teardown tests can fabricate reds\r\n- **Status:** BUILT 2026-08-03 · **Origin:** golden 30776330383 red on the #125 fix lane (2026-08-02)\r\n- **Lane:** hertz `golden/ir15` @a5042ec — REQ-TEST-LIVENESS-ORACLE-AUTHENTICATED (impl+unit): one\r\n  shared authenticated death-oracle test helper backed by `spt_procident::process_identity`\r\n  (identity pinned at find time, re-verified at assert), both pid-only polling sites repinned\r\n  (daemon.rs teardown test; endpoint_lifecycle.rs relay_pid). Ruled polarity held: Absent⇒gone,\r\n  Present(same start)⇒not gone, Present(different)⇒gone, Unproven⇒NOT gone, missing-stamp\r\n  degrades to pid-only loudly — every unknown errs toward the recoverable red, zero new\r\n  false-green paths. Linux caveat documented in the helper (10ms jiffies: Present(different) is\r\n  narrowing, not decisive; same-tick reuse errs red, safe).\r\n- **Golden:** run 30782259675 red on `resident_service_e2e` bring-up — delta exonerated (unrelated\r\n  family, now [[IR-17]]; same job minted [[IR-8]]'s defining specimen). Same-sha rerun 30784469908\r\n  GREEN; main ff'd to a5042ec.\r\n- **A/B discriminator (hertz):** 80/80 green both arms, quiet + churn phases; churn arm\r\n  positive-controlled (pid-allocator wrap observed <400ms, so reuse pressure was REAL in the churn\r\n  arm); rule-of-three bounds the original flake at ~7.5%/run/sha. Specimen 30776330383 remains\r\n  not-reproduced, cause unidentified — the repin removes the false-red MECHANISM; it does not\r\n  adjudicate the specimen. [[IR-16]]'s kill-side arm (TerminateJobObject return discarded) stays\r\n  a live discriminating instrument for any recurrence — and since 2026-08-03 it is no longer the\r\n  only one: [[IR-18]] (the test's OWN bare breadcrumb tree-kill) is the second kill-side candidate,\r\n  test-side rather than product-side. A recurrence must discriminate between them, not assume\r\n  either: IR-16's arm is a job whose termination silently half-fails (survivor still holds the\r\n  captured image); IR-18's is a victim killed by a bare pid it no longer owns —\r\n  `broker_survived=false` with the boot service still ALIVE and its message spooled. (An earlier\r\n  spelling of IR-18's signature here said \"empty stderr\"; retracted — empty stderr is present on\r\n  healthy runs and discriminates nothing.)\r\n\r\n### IR-21 — CLASS: a helper binary's build is never requested, only its LOCATION is, so any narrow invocation manufactures a red that belongs to the rig\r\n- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane. · **Origin:** todlando 2026-08-03. Filed as one instance, rewritten as a CLASS the\r\n  same day when a second member appeared, rewritten AGAIN when the mechanism was measured — the\r\n  first two versions described symptoms and got the remedy wrong. **Corrected a fourth time the same\r\n  day**: remedy (1) claimed the 11 same-package sites were missing a build edge, and todlando\r\n  falsified that by measurement while executing it (replicated independently by doyle). The error was\r\n  doyle's to carry — it was ruled on, not just written. The general rule that refutes it was already\r\n  in this entry's own CI-member section; diagnosing a class does not inoculate you against drawing\r\n  its opposite consequence one section later.\r\n- **Numbers below re-derived on `main` @`3efd7e6` over `git ls-files` (tracked files only). Each\r\n  carries its command; re-run rather than cite.**\r\n- ⚠ **Scan-root hazard, measured 2026-08-03 and worse than first reported:** a naive recursive\r\n  `grep -r` from the project root inflates by **~35×**, not the ~5× an earlier draft of this entry\r\n  claimed — 426 tracked `.rs` against 14,865 on disk with `target/` excluded, because `.worktrees/`\r\n  holds full copies of the tree. **And the unscoped grep does not COMPLETE** (still running at a\r\n  120s timeout while `git ls-files` returns instantly), so the failure mode is not only a wrong\r\n  number but a command that reads as hung on a tree where dozens of worktrees are normal. Use\r\n  `git grep` or `git ls-files | xargs grep`; both are scoped to tracked files by construction.\r\n\r\n#### THE MECHANISM (measured, both ends)\r\n\r\n**Build end — `cargo test` with a narrow target selector compiles a `[[bin]]` AS A TEST HARNESS and\r\nnever emits the plain executable.** Measured: `cargo test -p spt --bins` on a clean pool produced\r\nfive executables, every one hash-suffixed under `target/<profile>/deps/`, and ZERO plain exes in\r\n`target/<profile>/`. The bin was built. The file the test looks for was not written.\r\n\r\n**Consumer end — the resolver borrows a guaranteed binary's path to locate an unguaranteed one.**\r\nAll 29 copies of `sibling_bin` in `crates/spt/tests/` reduce to two textual variants (22 + 7) of one\r\nbody:\r\n\r\n```rust\r\nfn sibling_bin(name: &str) -> PathBuf {\r\n    PathBuf::from(env!(\"CARGO_BIN_EXE_spt\"))\r\n        .with_file_name(format!(\"{name}{}\", std::env::consts::EXE_SUFFIX))\r\n}\r\n```\r\n\r\n`CARGO_BIN_EXE_spt` is used **only as a directory anchor**. Cargo therefore sees a dependency on\r\n`spt` and on nothing else; the `{name}` half is a string join it cannot observe. The dependency edge\r\ndoes not exist at any level a build system could act on — which is why \"use the wider command\" is\r\nnot the fix and why the failure is invisible on a warm pool where some earlier run happened to leave\r\nthe file behind.\r\n\r\nThe unit-test resolver at `crates/spt/src/cli.rs:25601` reaches the SAME directory from a different\r\nanchor (`current_exe()` → `deps/` → parent) for the same reason: its own doc comment records that\r\nunit tests get no `CARGO_BIN_EXE_*` at all.\r\n\r\n**That mechanism explains both original members at once, including the polarity inversion that made\r\nthem look like different bugs:** whether `cargo test -p spt` or `cargo test -p spt --bins` happens\r\nto leave a plain exe behind is incidental to a dependency neither command was told about.\r\n\r\n#### SCOPE — WHERE IT BITES, AND WHERE IT DOES NOT\r\n\r\n**It bites NARROW invocations — `-p <pkg>`, `--bins`, `--lib` — i.e. gate rigs and local runs.**\r\nBoth members were hit on the LOCKSMITH t1 lane against fresh throwaway pools; each was discharged\r\nin-lane as a rig artifact. That is the whole field population to date.\r\n\r\n**GOLDEN IS ACQUITTED, and the acquittal is measured rather than assumed.** `cargo test --workspace\r\n--no-run` emits all 13 plain binaries — mock-session, mock-shell, capture-player,\r\nconsole-mode-probe, service_fixture and the rest — so a workspace build produces the cross-package\r\nhelpers by construction. Confirmed under nextest, the tool CI actually runs, with a real compile.\r\n\r\n⚠ **The measurement that establishes this is not the obvious one.** Deleting the plain exe and\r\nwatching it reappear is NOT evidence of a rebuild: cargo's uplift restores a hardlink from an intact\r\n`deps/` artifact, with link count 3 and an UNCHANGED mtime, which looks exactly like a build and\r\nsays nothing about a pool that never had the file — and a pool that never had it is the only kind a\r\nrig runs on. The sound probe removes the plain exe AND both `deps/` artifacts, confirms all three\r\nabsent, then watches the target actually recompile (mock-adapter, 5.77s, fresh mtime). The first two\r\nattempts were setup, not measurement.\r\n\r\n⚠ **The suspicion this acquits is structurally well-founded, so record the answer, not just the\r\nverdict.** `twohost-a`/`twohost-b` are `needs: test`, so the only mock-adapter prebuild runs AFTER\r\nthe phases that use it; `target/` is gitignored, so checkout never cleans it on a persistent\r\nself-hosted workdir. Every precondition for artifact leakage is present — the build simply does not\r\nneed it. The next person who reads that job graph will form the same hypothesis; this is the answer\r\nwaiting for them.\r\n\r\n#### THE ONE CI-SIDE MEMBER THAT IS REAL\r\n\r\n`crates/spt/src/cli.rs::adapter_translate_proof_gates_on_commit` is a **unit** test (`kind(bin)`),\r\nand `CARGO_BIN_EXE_*` is set only for integration tests and benches of the declaring package. A unit\r\nconsumer therefore CANNOT express the dependency through the env var at all — it has no choice but\r\nto resolve by path. That is why `.github/workflows/ci.yml:105-106` carries a hand-written\r\n`cargo build -p spt --bin translate_proof_fixture` before the unit lane, with a comment\r\n(`ci.yml:102-104`) stating this exact mechanism.\r\n\r\n**Deleting that step would red the unit lane on a clean pool, and it would read as a code red.**\r\nSomebody already hit this class, fixed their own leg correctly, and never turned it into a rule —\r\nthe comment at `ci.yml:102` is IR-21 written a milestone early, in the one place only its author\r\nwould find it.\r\n\r\n#### POPULATION\r\n\r\n**13 bin targets in the workspace** (`cargo metadata --no-deps`, not a grep — an auto-target under\r\n`src/bin/` and `xtask` are both invisible to a `[[bin]]` grep). Two are not helpers (`spt`, `xtask`);\r\nthe other **11 are test helpers**, across three packages:\r\n\r\n| package | helpers |\r\n|---|---|\r\n| `adapters/mock` | mock-session, mock-shell, capture-player, console-mode-probe |\r\n| `crates/spt-daemon` | dispatch_fixture, service_fixture, summarizer_fixture, xlate_choreo_fixture (⚠ this row was mis-\"corrected\" 2026-08-22 to claim `xlate_choreo_fixture` no longer existed — IT DOES, as an AUTODISCOVERED `src/bin/` target with no `[[bin]]` stanza; the original row was right and merely predated `summarizer_fixture`. See IR-58) |\r\n| `crates/spt` | translate_proof_fixture, post_step_fixture, gh_fixture, git_fixture |\r\n\r\n**44 literal `sibling_bin(\"…\")` call sites**, all in `crates/spt/tests/`, served by **29 copied\r\nresolvers**. Split by whether the BUILD IS ALREADY GUARANTEED — which is not the same question as\r\nwhether the env var is available, and an earlier version of this entry conflated the two:\r\n\r\n| class | sites | detail | build guaranteed? |\r\n|---|---|---|---|\r\n| **cross-package** | **33** | mock-session 26, mock-shell 6, service_fixture 1 | **NO — the hazard members** |\r\n| **same-package** | **11** | translate_proof_fixture 7, git_fixture 2, post_step_fixture 1, gh_fixture 1 | **YES — already, by construction** |\r\n\r\n⚠ **MEASURED TWICE, and it falsifies what this entry said on 2026-08-03 before this revision:** cargo\r\nbuilds **every bin target of a package whenever it builds ANY integration test of that package** —\r\nthat same act is what sets `CARGO_BIN_EXE_*` in the first place. So the 11 same-package sites were\r\nnever unexpressed in a way that could bite, and the hazard population is **33 cross-package sites\r\nplus the one unit-test member = 34**, not 44.\r\n\r\n- **Probe 1 (todlando, root pool):** deleted all four `translate_proof_fixture` artifacts (both\r\n  hash-suffixed harness exes, the `deps/` plain exe, the uplifted plain exe), confirmed absent, then\r\n  built ONE UNRELATED and UNMODIFIED integration test of the same package —\r\n  `cargo test -p spt --test attach_wedge_e2e --no-run`, exit 0, 14.45s. Both plain exes returned with\r\n  fresh mtimes; the hash-suffixed harness exes stayed absent, which is what distinguishes a bin\r\n  DEPENDENCY build from a `--bins` harness build.\r\n- **Probe 2 (doyle, `.worktrees/gate-ec5f38a` pool, independent replication with a different fixture\r\n  and a different probe test):** deleted `gh_fixture`'s plain exe, its `deps/` plain exe AND its\r\n  hash-suffixed harness exe, confirmed all three absent, then built `--test json_emit --no-run`\r\n  (exit 0) — a test that never names `gh_fixture`. The plain pair returned at a FRESH mtime (09:13\r\n  against the 09:00 it carried before), so this is a real build and not the hardlink uplift this\r\n  entry warns about elsewhere; the harness exe stayed absent.\r\n- **Neither probe needs a baseline arm:** the probe test is unmodified and references nothing under\r\n  edit, so what it measures is cargo's behaviour, not anyone's change.\r\n- **Corroborated by this entry's own field data:** neither original member was a same-package\r\n  integration site — member 1 is a UNIT test, member 2 is CROSS-package. The class never had a\r\n  same-package integration member, and the CI-member section below already stated the governing rule\r\n  (`CARGO_BIN_EXE_*` is set only for integration tests and benches of the declaring package) one\r\n  section before the remedy drew the opposite consequence from it.\r\n\r\nCommand: `git ls-files '*.rs' | xargs grep -hon 'sibling_bin(\"[a-z_-]*\"' | sed 's/.*sibling_bin(\"//;\r\ns/\"//' | sort | uniq -c`.\r\n\r\n⚠ An earlier report gave 48 sites and a 6/11/37 split. Take the table above: it counts only literal\r\ncall sites in tracked files and it ships its command. The 11 is the same 11 in both counts.\r\n\r\n**The LOCATION half of this class is already closed** by `crates/spt-term/tests/support/fixture_bin.rs`\r\n— a shared resolver rather than 29 copies. It does not close the BUILD half, and should not be\r\nmistaken for having done so.\r\n\r\n#### REMEDY SHAPE (not ruled)\r\n\r\nThe distinction that matters is location vs. build:\r\n\r\n1. **The 11 same-package sites are NOT hazard members and need no build fix.** Their build edge\r\n   already exists (see the two probes in POPULATION above); `env!(\"CARGO_BIN_EXE_<name>\")` for the\r\n   fixture itself would add nothing to it. Converting them is a **CLARITY** change, worth doing on\r\n   its own smaller merits — the path becomes the one cargo actually emitted rather than a string-join\r\n   of a directory anchor and `EXE_SUFFIX`, five copies of `sibling_bin` stop existing (29 → 24), and\r\n   it completes a migration already paid for: `crates/spt/tests/fixtures/translate_proof_fixture.rs:7-12`\r\n   records that the fixture was re-homed into `spt` precisely to obtain\r\n   `CARGO_BIN_EXE_translate_proof_fixture`, and then all 7 call sites resolved by path anyway. **It is\r\n   not a build fix and must not be filed as one.**\r\n2. **The 33 cross-package sites cannot**, by cargo's design. Their options are an asserted build in\r\n   the test's own setup, a `dev-dependencies` artifact dependency, or an explicit documented\r\n   prebuild — the ci.yml:106 shape, made a rule instead of a local fix.\r\n3. **Standardising on one wider invocation is NOT a remedy.** It changes which pools happen to work;\r\n   it does not create the dependency edge, and the two original members had opposite polarity under\r\n   exactly that theory.\r\n4. Collapsing the 29 resolver copies is worth doing on the `fixture_bin.rs` model, but on its own it\r\n   makes the class HARDER to see — one shared resolver still anchored on `CARGO_BIN_EXE_spt` hides\r\n   the 33 genuinely unexpressed dependencies among its 44 call sites behind one function.\r\n\r\n#### SUPERSEDED FRAMING, KEPT SO IT IS NOT RE-DERIVED\r\n- **Status of the original filing:** open · **Origin:** todlando 2026-08-03, both members hit on the\r\n  LOCKSMITH t1 lane against fresh throwaway pools; each discharged in-lane as a rig artifact, filed\r\n  here so the next clean rig does not re-diagnose them as code reds.\r\n- The first two versions of this entry framed the class as \"the rig's command does not build what\r\n  the test needs\" and proposed standardising on a wider invocation. **Both are superseded by the\r\n  measured mechanism above** — the dependency is not under-expressed, it is INEXPRESSIBLE in the\r\n  form these call sites use, so no choice of invocation creates it. Kept only as the two FIELD\r\n  MEASUREMENTS that produced the class, which remain true:\r\n- **MEMBER 1 — MEASURED:** `cli::tests::adapter_translate_proof_gates_on_commit` failed on the\r\n  first `cargo test -p spt --bins` run. Its fixture binary `translate_proof_fixture` (a\r\n  `tests/`-homed `[[bin]]`) was ABSENT from the pool — `ls` on the path returned No such file.\r\n  Building it explicitly and re-running the IDENTICAL command PASSED, after which the full `--bins`\r\n  suite passed 584/585 with only the releases#117 probe red (that one RED by design). So the\r\n  discriminator is the fixture's presence, not the tree: same command, same sha, red then green\r\n  across one `cargo build` of the fixture.\r\n- **MEMBER 2 — MEASURED:** `cargo test -p spt` does not build `mock-adapter --bin mock-session`, so\r\n  `attach_wedge_e2e` panics `\"the dummy-harness program must be built\"`. Note the polarity is\r\n  INVERTED against member 1 — there the narrower `--bins` was the defective invocation and\r\n  `cargo test -p spt` the correct one; here `cargo test -p spt` is itself insufficient. So the\r\n  class is NOT \"use the wider command\"; it is that the dependency is not expressed to the build at\r\n  all, and which invocation happens to work is incidental.\r\n- **What/why (still true):** on a WARM pool the helper is already there from some earlier run and\r\n  the test passes, so the defect is invisible exactly where most people work and fires only on a\r\n  clean pool — i.e. on a GATE RIG, which is the one place a false red costs the most.\r\n- **The sweep this entry once called its first step HAS BEEN RUN** (todlando 2026-08-03) and its\r\n  result is the POPULATION section above. It is no longer outstanding.\r\n\r\n- **Why it is register debt and not a lane bug:** nothing in the product is wrong. The gap is\r\n  between what a test needs built and what the rig's command builds, and the fix belongs to the\r\n  tests' declarations, not to whoever is running a gate that day. Sibling rule:\r\n  [[gate-clean-target-not-incremental]].\r\n- **Built evidence:** golden now names every cross-package fixture prebuild\r\n  (`mock-session`, `mock-shell`, `capture-player`, `console-mode-probe`,\r\n  `service_fixture`) explicitly; `xtask binedge-check` reports zero missing\r\n  edges. All 29 local `sibling_bin` resolvers collapsed into\r\n  `tests/common/mod.rs`; the shared precondition names the missing fixture and\r\n  its package-correct build command before any product timeout.\r\n- **Ripe when:** the next gate-rig or CI-touching wave. Cheap, and it pays for itself the first time\r\n  it stops someone chasing a phantom red on a clean pool.\r\n- **Size:** remedy (1) is small AND optional — it buys clarity and subtraction, never a build edge;\r\n  medium for (2), which is a design call before it is an edit and is the only remedy that closes the\r\n  class.\r\n\r\n### IR-22 — An inherited identity env var fails a test, and the diagnostic names them ONE AT A TIME so a correct fix reads as no fix\r\n- **Status:** open · **Origin:** todlando 2026-08-03, chasing what looked like an `attach_wedge_e2e`\r\n  code red on the LOCKSMITH t1 lane; root-caused to the runner's own process environment.\r\n- **MEASURED:** `attach_wedge_e2e` failed for an INHERITED PROCESS-GLOBAL and nothing in the tree:\r\n  the daemon-stop refusal fired on the running session's own identity env. It named\r\n  `$OWL_SESSION_ID`; clearing that made it name `$SPT_ENDPOINT_ID`. With `OWL_SESSION_ID`,\r\n  `SPT_ENDPOINT_ID`, `SPT_AGENT_ID` and `SPT_SESSION_ID` all cleared: exit 0, 1 passed.\r\n- **The finding is the DIAGNOSTIC SHAPE, not the env hygiene.** Naming one variable at a time means\r\n  a correct partial fix produces an identical-looking failure, so the natural reading of \"I cleared\r\n  it and it still fails\" is that the clearing did not work — when in fact each step was right and\r\n  the message had simply moved on to the next name. A refusal that can only ever name one member of\r\n  a set it is checking teaches the person debugging it the wrong lesson. Compare the same class in\r\n  [[IR-15]]/[[IR-18]] terms: the instrument is competent and the report is not.\r\n- **Why it matters beyond one test:** any agent running suites from a live spt session carries these\r\n  vars, so this fires for every builder on a perched session and for nobody running from a bare\r\n  shell — which is precisely the split between how builders work and how CI runs.\r\n- **Candidate remedies (not ruled):** have the refusal name EVERY identity var it found set, in one\r\n  line, rather than the first; and/or have the affected tests clear the identity set in their own\r\n  setup so a perched session is not a special environment. The first is the one that pays off\r\n  outside this test.\r\n- **Ripe when:** next CI/test-hygiene wave. **Size:** small.\r\n\r\n### IR-23 — `endpoint_teardown_authority_e2e`'s two tests collide with EACH OTHER through the machine-global spt home\r\n- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane. · **Origin:** todlando 2026-08-03, LOCKSMITH t1 lane.\r\n- **MEASURED:** both tests copy a psyche binary fixture into `perch::spt_home()/srcs/dummyharness/`\r\n  (`crates/spt/tests/endpoint_teardown_authority_e2e.rs:399`), which is process-global, so run in\r\n  parallel inside one binary each holds the file the other wants: `os error 32`, \"used by another\r\n  process\". **Signature: WHICH of the two fails alternates between runs.** Under\r\n  `--test-threads=1`: 2 passed, exit 0 — and the wall clock drops from 182s to 14s.\r\n- **What/why:** two defects in one, and they should not be conflated. (1) The tests are not\r\n  isolated from each other. (2) The staging path is the MACHINE-GLOBAL spt home rather than the\r\n  test's own temp home — on a box that is also a CI runner, so the blast radius is not confined to\r\n  the suite. (2) is the one worth fixing; (1) is a symptom of it.\r\n- **Note on why this is not already caught:** the standing rule is that integration tests run\r\n  through nextest, which gives each test its own process and hides the collision entirely. So this\r\n  is latent on the sanctioned path and only bites the bare `cargo test` path — the rule is working\r\n  and masking a real defect at the same time, which is why the entry exists rather than a shrug.\r\n- **Candidate remedy (not ruled):** stage the fixture into the test's own temp home. Sweep for\r\n  siblings first — any other test writing under `perch::spt_home()` rather than a temp home shares\r\n  the shape, and nobody has counted them.\r\n- **Built evidence:** adapter source, manifest registration, and psyche fixture\r\n  staging now use the rig TempDir. The two process-global resolver users are\r\n  explicitly serialized, and the bare `cargo test` path passes both cells with\r\n  `--test-threads=2` in 13.82s after the declared fixture prebuild.\r\n- **Ripe when:** next test-hygiene wave; the 182s -> 14s figure makes it pay for itself on the\r\n  bare path. **Size:** small per test, unknown until the sweep.\r\n\r\n### IR-24 — `reap::terminate_job` discards `TerminateJobObject`'s return, alone among its own module's siblings\r\n- **Status:** BUILT — landed `3d12cf3` on main (2026-08-03), fulfilment verified against this\r\n  entry's own wanted list by doyle 2026-08-04, not merely mapped to the commit: the return is\r\n  audited and the loss NAMED (`REAP_JOB_TERMINATE_FAIL: brain subtree NOT reaped (<os error>); …\r\n  the daemon holds no other handle to reach them` — which also ANSWERS the cost-of-loss question\r\n  this entry said nobody had written down); the \"first thing to check\" was checked and the ruling\r\n  came out OPPOSITE to IR-16's site in one respect, documented as measured asymmetry in the doc\r\n  comment: `TerminateJobObject` has NO ordinary failing path (zero only for a broken handle) so a\r\n  zero is a real loss, while `TerminateProcess` fails `ERROR_ACCESS_DENIED` on the ordinary\r\n  already-exited path and is deliberately NOT checked — the premise is unit-PINNED both directions\r\n  (`terminate_job_return_discriminates_broken_handle_from_ordinary_states`, cfg(windows), with a\r\n  memberless-job false-positive arm). No `job != 0` re-check (second-weaker-rule prohibition\r\n  honored, same as IR-16). Golden evidence: rides `4b37512` (run 30873007187 attempt 5, 9/9\r\n  green; the premise unit observed PASS in-pool on the Windows leg, Linux leg green — the\r\n  cross-platform quiet-`ESRCH` concern stays with `ec5f38a`'s coverage as before). Path\r\n  correction to this entry's MEASURED line: the site is `crates/spt-daemon/src/reap.rs` (brain\r\n  subtree reaper), not `crates/spt/src/reap.rs` as first filed ·\r\n  **Origin:** todlando 2026-08-03, swept while building [[IR-16]]; deliberately\r\n  NOT folded into that lane (doyle ruling, same day) and filed instead.\r\n- **MEASURED:** `crates/spt/src/reap.rs:207-211` calls `TerminateJobObject` and discards the result,\r\n  the identical shape [[IR-16]] closed at `spt-daemon`'s `kill_tree`. Its own module's\r\n  create/assign siblings at `:178` and `:202` ARE instrumented, so this call is the odd one out\r\n  where it lives — the module already decided that these returns are worth reading.\r\n- **Why it was NOT folded into IR-16:** different subject. IR-16's site is a SUPERVISED SERVICE's\r\n  teardown, where the loss is \"a supervised service's descendants survive\" and the promise it\r\n  breaks is `REQ-RESIDENT-SERVICE`'s tree claim. This site is the BRAIN SUBTREE's kill-on-close\r\n  job, which has its own lifetime, its own caller and its own answer to \"what does a failed\r\n  termination cost here\" — and that answer has not been written down by anyone. Folding it in would\r\n  have meant settling that question in passing, inside a commit about the supervisor, which is how a\r\n  second ruling gets smuggled into a lane scoped to one.\r\n- **What it needs that IR-16's fix does not supply:** IR-16 ruled a LOUD REFUSAL (option B) on the\r\n  ground that the alternative — a process-table tree-walk fallback — is measured blind in exactly\r\n  that failure state ([[IR-18]]: descent breaks at the dead middle hop) and would trade a silent\r\n  loss for a false clean. Whether the same reasoning holds here depends on whether this site kills\r\n  its direct process in the same breath, which is what makes the middle hop dead by construction\r\n  there. **That is the first thing to check, and it is not assumed.**\r\n- **Ripe when:** any wave touching reap/teardown; it inherits IR-16's vocabulary and its\r\n  discrimination note, so the second one is cheaper than the first. **Size:** small, once the\r\n  cost-of-loss question is answered for this subject.\r\n\r\n### IR-25 — `spt-daemon --lib` reds 2-in-3 under concurrent load with bare `cargo test`, and holds green under nextest\r\n- **Status:** open · **Origin:** doyle 2026-08-03, found while gating LOCKSMITH tranche 1 in an\r\n  isolated worktree; chased to a mechanism and scoped OUT of the release path before the head was\r\n  assembled.\r\n- **MEASURED, four arms, same box, same hour, matched load** (a second `cargo test -p spt-store\r\n  --lib` loop running throughout; `spt-store` itself stayed green in every round, so the box was not\r\n  generically failing):\r\n\r\n  | tree | instrument | result |\r\n  |---|---|---|\r\n  | lane `ec5f38a` | `cargo test --lib`, at rest | 821/821 ×4 |\r\n  | lane `ec5f38a` | `cargo test --lib`, under load | **2 of 3 RED** (142s, 117s) |\r\n  | lane `ec5f38a` minus its 5 new tests | `cargo test --lib`, under load | 3 of 3 green (117s, 84s, 105s) |\r\n  | main `932e14b` | `cargo test --lib`, under load | 3 of 3 green (97s, 119s, 104s) |\r\n  | lane `ec5f38a` | **`cargo nextest run`, under load** | **3 of 3 green, 821/821** (88s, 85s, 72s) |\r\n\r\n- **Three DIFFERENT victims across two loaded runs**, all process/timing-shaped, all PRESENT AT MAIN\r\n  and green there: `servicehost::…a_service_that_ignores_the_stop_marker_is_force_killed_and_confirmed_dead`\r\n  (panics `ForceKilled must MEAN the owned child is gone` right after `SERVICE_KILL_UNCONFIRMED`),\r\n  `applyhost::…broker_reports_its_compiled_image_version_over_ipc`, and\r\n  `daemon::…a_tree_teardown_reaches_a_grandchild_the_service_spawned`.\r\n- **MECHANISM: in-process thread interference, not product code.** Bare `cargo test` runs a crate's\r\n  tests as threads in ONE process. The lane's five new tests are process-spawning kill-tree tests;\r\n  under load they starve confirm windows of NEIGHBOURING tests that were always marginal. Removing\r\n  exactly those five flips 2-of-3-red to 0-of-3-green at the same sha, in the same binary, at the\r\n  same durations — one of the green runs sits at 117s, precisely a duration that had produced two\r\n  failures with them present.\r\n- **IT DOES NOT REACH GOLDEN.** nextest gives every test its own process, and golden runs nextest.\r\n  The population is GATE RIGS AND LOCAL RUNS — the same population as [[IR-21]], reached by a\r\n  different mechanism, which is why these are two entries and not one.\r\n- ⚠ **The instrument switch is the whole finding.** Measured with bare `cargo test`, this reads as a\r\n  lane blocker; measured with the tool CI actually runs, it is a rig-scoped nuisance. Anyone\r\n  re-opening this must state WHICH instrument produced their observation before quoting a verdict.\r\n  The same tool gap acquitted [[IR-21]]'s golden question the same day.\r\n- ⚠ **The pre-existing fragility is NOT thereby closed.** Those three tests were marginal before this\r\n  lane and the lane only exposed them; \"make the new tests quieter\" would re-hide a real weakness.\r\n  Hardening them is test-side work (hertz's lane by the dispatch split), not the builder's.\r\n- **Two rig defects of the gater's, recorded because they nearly cost the verdict:** (1) a first\r\n  re-run at rest came back 4/4 green and proves NOTHING — a sequential idle probe cannot express a\r\n  load-sensitive failure, so that is a competence-controlled zero, not an acquittal; (2) the first\r\n  baseline attempt ran its two arms UNSYNCHRONISED (the load generator finished while the measured\r\n  arm was still on run 1), which would have compared a loaded lane against an idle main and read as\r\n  \"the lane broke it\". A discriminator whose arms ran under different conditions cannot discriminate.\r\n- **Ripe when:** alongside [[IR-21]] on the next gate-rig or CI-touching wave, or immediately if\r\n  anyone starts gating on bare `cargo test` on a loaded box. **Size:** small to document the rig\r\n  rule (gate with nextest); medium to harden the three marginal tests.\r\n\r\n### IR-26 — POOL-OWNER claims authorize takeover from a DEAD holder, so releases#103's hazard reaches through the guard\r\n- **Status:** OPEN for residual claim-time observability and stale-reader enforcement; the\r\n  original build-side lane is COMMITTED (see its later reconciliation below), not still\r\n  uncommitted. Header corrected 2026-09-11; no residual closed by cleanup. · **Origin:**\r\n  hertz 2026-08-03/04, found by its own test rather than by reading, and\r\n  reported unfiled for composition. Composition ruling is doyle's, 2026-08-04.\r\n- **What/why:** a POOL-OWNER claim named a holder pid; lane liveness was read from whether that pid\r\n  was alive. hertz MEASURED the failure on this box: **3 of 3 claims had dead holders while one of\r\n  those lanes was live** — so the guard authorized exactly the interleaving takeover releases#103\r\n  exists to prevent. The remedy records the lane's GIT IDENTITY (branch + the base sha it carried at\r\n  claim time) and reads lane state from ancestry: in flight while the tip is not contained in\r\n  `origin/main`; settled once merged, once the branch is gone, or once the branch no longer carries\r\n  the claimed base (the branch-level twin of a recycled pid). Holder pid demotes to advisory — a\r\n  LIVE holder still refuses, a dead one no longer authorizes.\r\n- **The strongest finding in it, and it is a filter-competence one:** without the base anchor, a\r\n  missing branch read as \"settled, branch gone\" **out of a directory that was not a repository at\r\n  all**. An unanchored Settled verdict is a clean zero produced by a filter that cannot express the\r\n  question. A Settled verdict now requires the base object to be present in the reading repo;\r\n  unanchored is UNKNOWN. Sibling of [[zero-match-filter-reads-as-absent]] in the pool domain.\r\n- ⚠ **POLARITY, stated rather than buried:** the new arm (dead holder + unlanded lane => REFUSE)\r\n  converts a false-TAKEOVER into a false-REFUSAL. That is the better failure but not a free one, and\r\n  its triggering case is not exotic — it is an agent going down mid-lane, which happened to hertz\r\n  itself this same batch and cost [[IR-1]]/[[IR-4]]/[[IR-9]] their landing. **The open gating\r\n  question, put to hertz 2026-08-04 and NOT yet answered:** from the refusal state, does\r\n  `pool-release` still clear a claim whose holder is dead and whose lane is unlanded, or does the new\r\n  arm refuse that too? A guard whose only escape is the blanket `SPT_POOL_UNCHECKED=1` trains people\r\n  onto the blanket override. The refusal must NAME the remedy, not only the witness, and the remedy\r\n  must be exercised FROM the refusal state rather than reasoned about ([[remedy-must-run-from-refusal-state]]).\r\n  If the answer is \"it refuses\", that is a design change and returns to doyle before the lane lands.\r\n- **COMMITTED 2026-08-04 (was uncommitted when first measured):** `ci/poolowner-lane-claim` =\r\n  `8ce40d9` (the change) + `98cfafe` (the remedy fix below), both off `b7b00c3`. The original\r\n  measurement found ZERO commits and six modified files in `.worktrees/hertz-poolowner`, i.e. every\r\n  reported number had been measured against a tree no git object captured; the builder committed on\r\n  being told. Recorded because the near-loss is the lesson, not the correction.\r\n- **THE REMEDY DID NOT RUN — measured from the refusal state, which is the only place the question\r\n  can be asked.** The refusal named its witness AND a command, and executing that command verbatim\r\n  failed with the IDENTICAL `SPT_POOL_FOREIGN` block that printed it: **xtask depends on spt-store,\r\n  so every command that builds the tool goes through the pool being refused.** This is the same dead\r\n  end the unclaimed-foreign arm already hit in the field and fixed by leading its line with the\r\n  hatch — adding a second refusal arm re-broke it immediately. FIXED at `98cfafe`: the in-flight\r\n  remedy now leads with the hatch and names `pool-claim`, the command that actually resolves\r\n  ownership. Full chain re-measured on hfenduleam: refuse → verbatim remedy fails → hatch-prefixed\r\n  form succeeds → build proceeds.\r\n- **Answer to \"does `pool-release` clear a dead-holder + unlanded claim\", two-part:** it DOES — it\r\n  never consults the verdict, it rewrites `lane=None` — **but it is NOT the exit**, because after\r\n  release the same build is refused again on the pre-existing unclaimed-foreign arm (\"no lane has\r\n  claimed this pool\"). Release moves you from one refusal to another. `pool-claim` is the exit.\r\n- **The guard is a POPULATION, not a row** (builder's generalization, adopted by doyle as the\r\n  standard for this class): one test poses all three refusal arms and asserts that any remedy naming\r\n  a command leads with the hatch, PLUS membership — three posed, three refused — so no arm passes by\r\n  never being reached. The rule had been learned once already and the next arm added broke it, which\r\n  is the definition of something that needs a population test rather than a better comment. 26/26.\r\n- ⚠⚠ **FLEET PROPERTY — the rig refuted itself, and this is the entry's most important line.** The\r\n  first arm did NOT refuse, it TOOK OVER: the arriving worktree was at `b7b00c3`, so the build script\r\n  that ran was ITS OWN, pre-identity. **Enforcement code comes from the ARRIVING tree, never from\r\n  the claim.** So until this lands everywhere, an old tree still takes a live lane's pool, and the\r\n  guard is only ever as new as the tree that arrives. Found by measurement; reasoning would have\r\n  reported a refusal the rig never produced.\r\n- **RULING on the fleet property (doyle 2026-08-04) — a stamp VERSION LINE is REFUSED, and not on\r\n  taste: it cannot work.** The tree that must refuse is the OLD one, and an old build script does not\r\n  read a new stamp field because it does not know the field exists. You cannot make a stale enforcer\r\n  honor a new rule by writing something new into the record it enforces against — **the reader is\r\n  the problem, not the record.** A version line would help only a CURRENT tree explain itself while\r\n  doing nothing to the population it is aimed at, i.e. it would retire the worry without retiring the\r\n  risk. Ruled instead, in priority order: **(1)** land it and state the migration window honestly —\r\n  the arm protects a lane only when the ARRIVING tree carries the change, coverage grows as trees\r\n  turn over, never retroactive; **(2)** NAME THE LOSS YOU CANNOT PREVENT ([[IR-16]]'s pattern) — the\r\n  claiming side may be able to notice afterwards that its pool was taken and say so loudly, turning\r\n  silent artifact corruption into a named event; scope separately and MEASURE whether the claiming\r\n  side can observe it at all before committing; **(3)** SHRINK THE POPULATION — old enforcers are old\r\n  trees, this box carries ~45 worktrees and most are stale, so reaping them is real mitigation and\r\n  cheaper than code. (2) and (3) do NOT ride this lane.\r\n- **The unanchored row, as asked:** `a_claim_from_another_repository_reads_unknown_not_settled` was\r\n  RED before the base-object requirement existed. Verbatim: `left: Settled { reason: \"lane branch\r\n  build/lane-x no longer exists\" }  right: Unknown`, out of a tempdir that was not a repository at\r\n  all. It fails without the requirement and passes with it — a real negative control, not a row that\r\n  only ever passed.\r\n- **Builder's evidence (as reported, against that uncommitted tree):** spt-poolguard 25/25 with 7 new\r\n  rows, one per precedence cell, two carrying their own negative control; pool_guard_canary 3/3;\r\n  `cargo check -p xtask -p spt-store --all-targets` clean; clippy clean on the three touched crates;\r\n  `traceable-reqs check` exit 0 at 745/745 with new `REQ-POOL-LANE-IDENTITY` complete at doc+impl+unit.\r\n- **Composed:** its OWN thin lane, riding the same next golden batch as the CI-rider cluster but NOT\r\n  merged into it (doyle ruling 2026-08-04). A red must stay attributable: the riders change what the\r\n  pipeline measures, this changes a build-time REFUSAL, and a guard whose failure mode is refusing\r\n  builds is the worst thing to make inseparable from a pipeline change. IR-14's four-trees-into-one-\r\n  unclaimed-pool finding stays OUT of this lane and stays IR-14's, on the same ground [[IR-24]] was\r\n  kept out of [[IR-16]] — folding it in settles its question in passing.\r\n- **Ripe when:** next CI/infra batch, gated on the polarity question above being answered first.\r\n  **Size:** small once the remedy question is settled.\r\n- **FALSE-LIVE, first specimen of the blocking polarity (hertz sweep, measured 2026-08-04):**\r\n  `.worktrees\\hertz-ci-riders\\target\\POOL-OWNER.json` named `holder_pid 31380` with\r\n  `holder_started_at 134302739211259713` = 2026-08-03 16:38:41. Pid 31380 on that box at read time was\r\n  `claude.exe -n \"doyle @ HFENDULEAM (spt-core/)\"`, created 17:31:11, FILETIME 134302770715019370.\r\n  Same boot, ~52 minutes apart, stamps MISMATCH. The claiming process died and the OS reissued its pid\r\n  to the gater's own session. Every previously measured recycle produced a false-DEAD (reads free\r\n  while the lane is live — the corrupting direction); this one produces a **false-LIVE**: a bare-pid\r\n  guard reads the claim as held by a running holder and refuses, naming doyle as the holder of hertz's\r\n  pool — the blocking direction, first time caught. The `holder_started_at` arm shipped in `8ce40d9`\r\n  discriminates it correctly — that field caught defending, not asserted to defend\r\n  ([[stable-anchor-is-not-a-recycling-defense]]).\r\n- **The mirror image, same box, same hour:** `.worktrees\\ir24-reap\\target` named `holder_pid 33612`,\r\n  DEAD — while that lane was genuinely LIVE, with `cargo clippy -q -p spt-daemon --lib --tests`\r\n  (pid 22452) running under todlando's session as it was read. Two claims, opposite errors, inside one\r\n  hour: liveness misreads in BOTH directions on the same box in the same hour. Holder liveness has no\r\n  sound polarity as a lane-state oracle. Ancestry decides ([[pool-claim-holder-death-is-not-lane-state]]).\r\n- **THE BARE-CLAIM GAP — a claim the stamp arm cannot adjudicate at all.** The main checkout's own pool\r\n  (`<root>\\target`, 72,001,016,671 B = 67.06 GiB) carries\r\n  `{\"owner_tree\": \"...\\\\spt-core\", \"written_by\": \"spt-poolguard\"}` — no `lane_label`, no `holder_pid`,\r\n  no `holder_started_at`, no `lane_branch`, no `lane_base`. `read_owner` maps that to `lane: None`, so\r\n  every arm the lane-identity work added is unreachable for it: it cannot be read as in-flight,\r\n  settled, or recycled. **FIVE of the eight** claims found on this box are this shape — `<root>\\target`,\r\n  `<root>\\target-seam` (below), `gate-target-render`, `ir21-xtask\\target`, `locksmith-t1\\target` —\r\n  against three carrying a lane identity (`hertz-ci-riders`, `hertz-poolowner`, `ir24-reap`). A claim\r\n  written by a plain build rather than by `pool-claim` is structurally un-adjudicable, and it is the\r\n  MAJORITY shape in the field. Whatever IR-26 does next has to say what an identity-less claim means —\r\n  \"the stamp arm handles it\" is false for most claims that actually exist.\r\n- **The fifth bare claim was invisible to the first inventory, and the miss is its own lesson:**\r\n  `<root>\\target-seam`, **52.06 GiB**, real dir, gitignored on its own line (`/target-seam`, added\r\n  `5ae68f8`, v0.12.1 era), created 2026-06-18, last written 2026-08-02 — nothing in the tracked tree\r\n  references it (grep over rs/toml/md/yml/ps1/sh: zero hits outside this file). The inventory predicate\r\n  was \"a directory named `target` inside a worktree\"; a second root-level pool under a different name\r\n  is not expressible in that filter, so it returned a clean zero that was reported as a population\r\n  ([[verdict-from-probe-competence]] in the field). Corrects the earlier \"72 GB root pool is the\r\n  biggest object by 9x\": the two root pools are 67.06 + 52.06 = 119.1 GiB of a 133.43 GiB box pool\r\n  total, so the 44-tree sweep covered ~61% of pool bytes, not the population. **Ruling (doyle,\r\n  2026-08-04): target-seam stands for now** — free space is ~115 GB against the 32 GB golden floor, so\r\n  there is no pressure; it was written to yesterday, so \"cold\" is one day deep and its writer is\r\n  unidentified. It becomes a reap candidate at the next free-space squeeze, after a fresh last-write\r\n  check and identification of what wrote it on 08-02 — reaping a pool whose writer you cannot name is\r\n  how the v0.51.0 fabricated-red class starts.\r\n- **CLAIM-OBSERVABILITY, MEASURED (hertz, 2026-08-04, three-arm rig with competence control):** a\r\n  displaced claimant CANNOT distinguish takeover from never-claimed — the two states are byte-identical\r\n  on disk (arm 1 vs arm 2 identical; arm 3 proves the rig separates states that differ, so the null is\r\n  real). The takeover is silent on BOTH sides: the taker's `pool-claim` prints ordinary success naming\r\n  no prior owner. Mechanism at `b75258d`: `pool_claim` never calls `read_owner` — it constructs its own\r\n  `PoolOwner` and `fs::write`s unconditionally. The displaced lane's only channel is its next build's\r\n  refusal, which reports a STATE (\"this pool belongs to B\"), never a transition, and arrives pull-only\r\n  and arbitrarily late while interleaved-artifact harm is already underway. Labelled holes: measured\r\n  against the origin/main xtask binary (lane-tip carry is a source read, not a measurement);\r\n  pool-sweep-as-channel not exercised; single-process holder pid in all arms.\r\n- **Bootstrap property, not a defect (hertz, measured 2026-08-03 while claiming pools for the lanes\r\n  3-4 rebases):** a lane DELIVERING claim-identity cannot claim its own pool WITH that identity until\r\n  it lands — the prebuilt origin/main `xtask.exe` writes old-shaped stamps (owner_tree, lane_label,\r\n  holder pid+stamp; no lane_branch, no lane_base). Enforcer turnover surfacing at CLAIM time rather\r\n  than build time: coverage grows only as trees turn over. Recorded because it reads as a bug the\r\n  first time someone meets it in the field. Related lane-craft fact from the same queue: a rebase\r\n  changes SHAS necessarily but hunk OFFSETS only incidentally — todlando's main.rs hunks stayed at\r\n  @20/@53/@70 across the f2e4516→2f427b2 rebase; treat pre-rebase overlap measurements as stale by\r\n  construction and re-measure, but expect the geometry to usually hold.\r\n- **Bootstrap property FIELD INSTANCE, main checkout (todlando 2026-08-04, IR-12 rig):** the\r\n  prebuilt `target/debug/xtask.exe` in the MAIN checkout pool was stale against main's own source\r\n  at `11169c1` — it printed `(holder pid …, born …)` and wrote a FLAT identity-less claim\r\n  (owner_tree/lane_label/holder_pid/holder_started_at/written_by) where main's source\r\n  (main.rs:2282) prints `(branch …, base …; advisory holder pid …)` and writes the nested lane.\r\n  A lane claimed with a stale tool records NO git identity and demotes its own adjudication back\r\n  to the refused bare-pid predicate. DETECTION that worked and is the reusable part: read the\r\n  claim line the tool PRINTS against the source just read — a mismatch names the stale enforcer\r\n  before it writes. REMEDY at claim time: rebuild xtask FROM THE LANE'S WORKTREE before\r\n  `pool-claim` (which the protocol's claim-from-your-own-worktree rule already implies; this\r\n  instance is why it is load-bearing and not ceremony).\r\n- **RULING (doyle, 2026-08-04) — the claim path must run the same guard the build path runs, and a\r\n  takeover becomes an event.** The documented design already says a finished lane is \"taken over\r\n  loudly, not refused\"; a silent unconditional overwrite violates the spelling the protocol shipped\r\n  under. Remedy, both halves, one small lane: (ii) `pool-claim` reads the prior owner before writing —\r\n  prior lane LIVE (ancestry + stamp arm, never bare pid) ⇒ refuse exactly as build.rs would; prior\r\n  lane finished ⇒ proceed AND announce the displacement, naming the displaced lane in the success\r\n  line; plus (i) a `displaced` field (prior owner + takeover stamp) rides the new claim, so the fact\r\n  survives in the artifact the late-reading claimant already reads. The identity-less bare claim\r\n  (majority field shape, above) must be handled explicitly by the same change: a bare claim carries no\r\n  lane to adjudicate, so takeover of a bare claim always proceeds-and-announces, and the announcement\r\n  names the claim as identity-less — never silently, never refused. Ripe: next CI/infra batch, same\r\n  lane as or beside the IR-26 remedy. Size: small.\r\n\r\n### IR-27 — A junction-pooled rig is TWO objects and teardown only ever removes one\r\n- **Status:** open, found in the wild 2026-08-04 · **Origin:** hertz's 44-tree worktree sweep\r\n  (IR-26 follow-on 3) · **Cross-ref:** [[IR-14]] (unclaimed pools), [[worktree-target-junction]]\r","truncated":true,"truncatedBy":"lines","totalLines":6069,"totalBytes":82204,"outputLines":940,"outputBytes":82204,"lastLinePartial":false,"firstLineExceedsLimit":false},"totalLines":6937,"displayContent":{"text":"## OPEN\n…\n### IR-16 — kill_tree discards TerminateJobObject/TerminateProcess returns (silent partial kill)\n- **Status:** BUILT 2026-08-03 (landed @62c5623 on the LOCKSMITH t1 lane; rides golden sha\n…\n- **BUILT — fulfilment checked against the wanted list, not merely mapped to a commit** (doyle,\n…\n\r\n### IR-18 — resident_service_e2e kills breadcrumb pids BARE (stale-breadcrumb tree-kill; kill-side twin of IR-15)\r\n- **Status:** BUILT 2026-08-04 — the named acceptance carrier RAN and the condition is DISCHARGED,\r\n  stated as the measurement rather than as the green board it sat on: LOCKSMITH's golden run\r\n  30860770146 (head `b7b00c3`, conclusion success) executed the changed test IN-POOL on BOTH\r\n  platforms — `spt::resident_service_e2e a_declared_service_rises_with_the_daemon_and_reaches_the_cli`\r\n  PASS 17.773s (100/2637) on hfenduleam/Windows and PASS 17.895s (1364/2616) on kitsubito/Linux.\r\n  The pool was checked for the test rather than inferred from the job colour, because a green leg\r\n  that never ran the test is a competence-controlled zero, not an acquittal; `resident_service_e2e`\r\n  contains exactly ONE `#[test]`, so the test that ran IS the test the lane rewrote (229 lines of\r\n  that file changed in `6e1a962`). No red returned to doyle. `.worktrees/ir18` is released for\r\n  teardown by this verdict · **Origin:** hertz\r\n  characterization of the [[IR-17]] resident_service red, 2026-08-03 — CANDIDATE mechanism, NOT a\r\n  reproduction\r\n- **Lane:** hertz `fix/ir18-authenticated-teardown` — MERGED to main @6e1a962 (PR #142; gated at\r\n  b48e35b, rebased 6e1a962 on 1e520b4 with zero code delta — doyle re-derived `git diff -- crates/`\r\n  empty across the rebase, so the gate verdict and local behavioral evidence transfer). Gated by\r\n  doyle: full diff review (one blocking finding — the scope_lost assert condition contradicted its\r\n  own guard ruling — fixed and delta-verified at one line), mutation-proven locally both\r\n  directions (B: forced boot_pid=None → population sweep names the leak no per-pid check sees,\r\n  FAIL 101; A: wrong expected_exe → REFUSED-foreign-image reds loudly on the derivation check).\r\n  EVIDENCE SPLIT, stated so the check marks cannot carry it (hertz's absent-leg callout): lane CI\r\n  30792210008 was 5/5 green per job but ci.yml's test leg is kind(lib)+kind(bin) — the changed\r\n  integration test NEVER RAN there (verified by log grep, 0 hits / 3023 lines); CI proved\r\n  compile-everywhere (clippy all-targets = the pool-population check for a common/ module),\r\n  traceability, lib/bin clean. The BEHAVIORAL evidence is local: three clean runs (all verdicts\r\n  Killed, population empty) + the two mutation reds. reap.rs diff additive-only (zero deleted\r\n  lines, verified) — cross-test risk bounded to compilation, which CI covered. Evidence custody:\r\n  gate + mutation logs at `.worktrees/_patches/ir18-gate-logs/` (5 files); `.worktrees/ir18` is\r\n  KEPT deliberately until the golden verdict (NOT an orphan — do not reap; a Phase A red wants the\r\n  tree and logs in place, not rebuilt); its pool claim is released.\r\n- **What/why:** `crates/spt/tests/resident_service_e2e.rs:46` defines its own reaper —\r\n  `taskkill /PID <pid> /F /T`: bare pid, force, whole TREE, no identity check — and feeds it three\r\n  BREADCRUMB-derived pids in cleanup (`boot_pid`, `rel_service_pid` at :360, and the pid read out\r\n  of `brain.ready` at :363). The suite already ships the authenticated tool other tests use and\r\n  this one does not: `common::reap::authenticated_kill(label, pid, expected_exe, observed)` at\r\n  `crates/spt/tests/common/reap.rs:116`. Inside the Phase A parallel pool on a pid-churning box\r\n  this is the KNOWN-HAZARDS stale-breadcrumb tree-kill class, live and **symmetric**: this test can\r\n  take a sibling's daemon and a sibling can take this test's. Same defect [[IR-15]] just fixed, on\r\n  the other side — IR-15 authenticated the READ (is the thing I pinned gone?), the KILL is still\r\n  bare pid. Kill what you pinned, not the number it happens to hold.\r\n- **Verified at source by deployah 2026-08-03** (relayed claims re-derived, all held): the bare\r\n  kill, its three breadcrumb feeds, the shipped-but-unused authenticated helper, and the\r\n  `CREATE_BREAKAWAY_FROM_JOB` spawn (`daemon.rs:1300`).\r\n- **Evidence rating — why it is a candidate and not a cause:** it predicts every field of the one\r\n  observed state line. The daemon is killed after spawning its boot service and before binding:\r\n  `broker_survived=false` (the discriminating field — false in every killed control round, true in\r\n  every healthy one) + `boot_alive=true boot_pid=Some(8920)` with the service's message in the\r\n  spool. (The \"empty stderr = silent death\" leg that originally sat here is RETRACTED — see\r\n  [[IR-17]]'s control record; stderr is empty on healthy runs too and discriminates nothing.)\r\n  The service outlives its daemon because `detached_no_inherit_env` spawns it\r\n  `CREATE_BREAKAWAY_FROM_JOB`, so it is NOT in the daemon's job and a daemon kill ORPHANS it\r\n  rather than reaping it — plausibly also the five denied `svcmock.exe` attempts in that job's\r\n  reap summary. **The [[IR-17]] positive control (2026-08-03) reproduced the shape 3/3\r\n  deterministically with a forced kill at that window — establishing the SHAPE on demand, not the\r\n  AGENT: nothing identifies who issued a kill in golden 30782259675.** The bare-pid tree-kill from\r\n  a concurrent test remains the candidate agent, on the source-verified hazard class and reap.rs's\r\n  documented prior casualty. **Not reproduced in the wild. Not proven. \"Root caused\" is not\r\n  written here by anyone.** The [[IR-17]] rate run is cancelled, so no rate will ever back this —\r\n  the fix stands on the source-verified hazard class alone. THE DEFECT IN MINIATURE, observed as a\r\n  side effect of the control (hertz 2026-08-03): the three killed rounds leaked 12 processes\r\n  (6 svcmock + 6 spt.exe, two services per round) and the test's own teardown reaped NONE — when\r\n  the daemon dies, `rel_pid` is `None` so that service is never even a kill target, and the\r\n  breakaway child outlives everything. A teardown that leaks two processes per round currently\r\n  PASSES: the concrete case for `target_gone` as the gate's positive half. (Leak cleaned scoped,\r\n  each pid re-authenticated by image-path prefix + creation window at kill time, not from the\r\n  minute-old enumeration.) ONE LAYER DEEPER (deployah, same night, at source): the reap loop\r\n  (:359) is `[boot_pid, rel_service_pid].into_iter().flatten()` — `.flatten()` DROPS None, and\r\n  `mock_pid` (:100-106) collapses absent/permission-denied/IO-error/garbage into that None via\r\n  `.ok()?`/`.ok()` — the reap.rs:59-63 collapse in a THIRD location, inside this very test. So the\r\n  leak is both \"service never started\" AND \"pid unreadable, therefore never a kill target\":\r\n  absence of knowledge read as absence of target, in a teardown, again.\r\n- **GATE SPEC AMENDED PRE-BUILD (deployah found the hole, doyle-ruled 2026-08-03 — read this\r\n  BEFORE building the lane):** the two halves as first specified (trap-class-absent +\r\n  `target_gone` per pid) both operate on pids we HAVE — a process whose pid is None is invisible\r\n  to BOTH, so the specified gate PASSES hertz's own control-run leak (12 processes, 6+6, 2/round,\r\n  teardown reaped none). A gate its own reproduction case passes is not yet an instrument. THIRD\r\n  HALF, REQUIRED: a POPULATION assertion at teardown — zero surviving staged-service or\r\n  test-owned spt processes, by selectors external to the pid bookkeeping. SELECTOR RESPELLED\r\n  (hertz 2026-08-03, doyle-approved — the first spelling, \"parent-pid descent from the test\r\n  process\", would have caught ZERO of the 12: teardown kills the daemon before any check runs, the\r\n  BFS over the current (pid,ppid) table breaks at the dead middle hop, and descendants(test_pid)\r\n  returns empty exactly in the leak case — an absence read as a clean, the shape the lane exists\r\n  to kill; the control's own cleanup is the evidence, it had to use image+creation-window because\r\n  descent was already broken). THE TWO SELECTORS AS BUILT: (1) svcmock half by IMAGE PATH —\r\n  stage_adapter copies the service binary under this run's unique tempdir home, so \"any pid whose\r\n  exe_path canonicalizes under home\" names every staged service this run started and nothing else\r\n  on the box; no bookkeeping, immune to reuse and broken chains. (2) spt.exe half by SEEDED\r\n  descent + image — image alone is forbidden (target/debug/spt.exe is shared with concurrent\r\n  tests and live perches: the machine-wide selector class); seed with the ancestor set captured\r\n  WHILE ALIVE ({test, broker from the Child handle, brain from brain.ready — none via mock_pid}),\r\n  union descendants, keep only exe_path==spt_bin. Reuse exposure on seeds is assertion-only (a\r\n  red, never a kill) and the image filter closes it. Both halves catch the 12-leak conformance\r\n  case; the first spelling caught none of it. PLUS THE [[IR-8]] BUCKET, REQUIRED (deployah,\r\n  same night — the third instance of that sentence tonight, this time inside our own instrument):\r\n  both selectors match on IMAGE PATH, and an exe path that cannot be READ yields no match — a\r\n  leaked svcmock holding an unreadable path is invisible to both halves and the count comes back a\r\n  zero that cannot see. Not hypothetical: IR-8's defining specimen is 5/5-denied on this exact\r\n  image, on this box. So the population assertion counts unreadable-path processes as their OWN\r\n  bucket and the zero-survivors claim REFUSES when that bucket is nonzero — zero seen AND zero\r\n  unseeable, or the assertion states it could not see. Built in from the start, not retrofitted\r\n  (may land in the lane's second commit at hertz's discretion; the requirement is that it lands in\r\n  the lane). This instantiates IR-8's remedy test-side; the CI reap-census script half of IR-8\r\n  stays open.\r\n- **Fix (thin lane, hertz — doyle-ruled 2026-08-03):** adopt `authenticated_kill` at all three\r\n  sites. (Board #131's `CREATE_NO_WINDOW` rider is DROPPED from this lane — hertz falsified the\r\n  filed remedy at source 2026-08-03: daemon.rs has exactly ONE CreateProcessW (:1187) and\r\n  BASE_FLAGS (:1105) already carries 0x0800_0000 = CREATE_NO_WINDOW on both rungs including the\r\n  ACCESS_DENIED fallback (which drops only BREAKAWAY), so the specified edit ORs an already-set\r\n  bit — a bit-for-bit identical flag word that would close a board item while its symptom, if\r\n  real, continues. #131 handed back to board triage with the finding and a candidate direction:\r\n  DETACHED_PROCESS gives the service no console, so a console child the SERVICE spawns flagless\r\n  allocates a NEW visible window — the grandchild, not the daemon's spawn, is the candidate\r\n  surface; wants its own diagnosis from an observed window. ~~The `detached_no_inherit_env` rename\r\n  (\"detached\" actually means breakaway-from-job) is a candidate cosmetic rider on [[IR-16]]'s\r\n  product lane~~ — **RENAME DROPPED 2026-08-03, ITS PREMISE MEASURED FALSE** (todlando, on the\r\n  IR-16 lane; doyle re-verified at source before ruling). \"detached\" is ACCURATE: `BASE_FLAGS`\r\n  (daemon.rs:1103-1105) is `DETACHED_PROCESS | CREATE_NEW_PROCESS_GROUP | CREATE_NO_WINDOW`, and\r\n  `0x0000_0008` IS DETACHED_PROCESS — the function sets BOTH postures and the name states one of\r\n  them. The name is not wrong, it is INCOMPLETE (silent about `CREATE_BREAKAWAY_FROM_JOB`, which\r\n  arrives as `extra_flags` at daemon.rs:1506), so renaming on the stated premise would have traded\r\n  an accurate word for one that drops a flag the function really sets. Independently fatal: the\r\n  premise, if true, covers the sibling `detached_no_inherit` equally — 17 references across\r\n  daemon.rs/deelevate.rs/shellhost.rs — and renaming one of two siblings of ONE posture leaves the\r\n  tree MORE inconsistent, not less. **What lands instead:** one doc-comment line on EACH function\r\n  naming the full effective flag word, which fixes the real complaint (neither name says breakaway)\r\n  without touching a call site. Kept here rather than deleted because this entry was the claim's\r\n  only home, and a reader who found the rename gone with no reason would re-derive it.) PER-PID GROUND TRUTH for expected_exe (hertz — SELF-CORRECTED\r\n  at source before it ever landed; his first derivation, \"Copy runs from adapters_dir(), Pointer\r\n  runs from srcs/\", was WRONG and registration mode is NOT the discriminator): servicehost.rs:1328\r\n  takes `install_dir` from `record.source_dir` on the Started arm for EVERY service, Copy and\r\n  Pointer alike, and Copy copies only the manifest + strings/ (registry.rs:395-404), never a\r\n  binary — `adapters_dir()` holds no executable in either mode. BOTH services run from their OWN\r\n  staged src dir: `staged_bin(<adapter's staged src dir>, \"svcmock\")`. The trap survives with a\r\n  different mechanism: two adapters staged into two DIFFERENT source dirs are two different files\r\n  on disk, so one expected_exe still cannot serve both. A lane that trusted the mode split would\r\n  derive a path with no binary at it. How it was caught, kept because it is the reusable part: not\r\n  by rereading the mode table but by finding where install_dir is COMPUTED instead of trusting an\r\n  already-published inference — the mode split was true of MANIFESTS and had been generalized to\r\n  BINARIES without checking the consumer; and the derivation-asserted-at-observe() instrument\r\n  would have caught it at runtime regardless — the instrument did its job before it ever ran,\r\n  argued against its own author. SCOPE_LOST RULED A GUARD, NOT A FINDING (hertz design change,\r\n  doyle-approved): a seed pid recycled before the sweep makes the sweep DECLINE that subtree\r\n  loudly, not fail — failing would turn ordinary pid churn on a busy runner into a red against a\r\n  clean teardown (the IR-15 false-red class re-minted inside its own fix); coverage holds without\r\n  it because the staged services are caught by image-path-under-home and the daemon + brain by NEW\r\n  direct per-pid target_gone checks (their pids this test never loses) — the ancestry half is\r\n  reach, not load-bearing. `unreadable` stays FATAL as ruled.\r\n  Sequencing: positive control\r\n  first (it is the instrument that could still refute the mechanism), then the lane. Does NOT ride\r\n  [[IR-16]] (doyle-ruled same day): that is the product-side kill_tree audit and stays a separate\r\n  lane under the dispatch split; the two cross-ref, they do not merge.\r\n- **Lane trap, flagged before build (hertz 2026-08-03 — the false-clean shape):** `expected_exe`\r\n  differs PER PID. `boot_pid` and `rel_service_pid` run the staged svcmock image, NOT spt.exe —\r\n  passing spt_bin for those refuses every kill as foreign-image and LEAKS both services while the\r\n  reap reads hardened. Only `brain.ready`'s pid takes spt_bin. Also: `observe()` boot_pid at :210\r\n  while it is provably ours, so the reuse check has creation-time teeth instead of degrading to\r\n  image+ancestry.\r\n- **Gate the lane on killing, not on refusing (deployah 2026-08-03; REFINED by hertz same night\r\n  from reap.rs's own contract):** the hardened version fails safe in the WRONG direction —\r\n  refuse-everything leaks both services while printing exactly the reap line a reviewer wants to\r\n  see, strictly worse than the bare kill it replaces and invisible in the same log. But a BLANKET\r\n  zero-REFUSED gate is wrong too: reap.rs's module doc (:18–20) states refusal is the CORRECT\r\n  happy-path outcome when the test already stopped its daemon (`Refused(\"gone\")` — leak insurance,\r\n  not primary teardown), so the blanket gate reds healthy runs, someone loosens it to go green, and\r\n  the loosened version is exactly the one blind to foreign-image — the detector dies by\r\n  maintenance, wearing a green. The refusal reasons split, and only one class is a defect:\r\n  SOUND (expected): `gone`, `reused`, `breadcrumb-moved`, `self`, `ancestor` — target provably not\r\n  there. TRAP (the false-clean state): `foreign-image`, `unreadable-image`, `unproven-identity` —\r\n  something WAS there and authentication declined; `foreign-image` is precisely what a wrong\r\n  per-pid expected_exe produces on every pid, every run. THE GATE: in the arm that must kill,\r\n  assert no verdict in the trap class — structurally on the returned `Verdict` (Killed |\r\n  Refused(&'static str), stable tokens by design, reap.rs:48), not by scraping output; the\r\n  `REAP[label]: … verdict=` line stays as CI-log forensics. The gate's comment MUST say\r\n  `Refused(\"gone\")` is expected, or the next reader \"fixes\" it. Positive counterpart that actually\r\n  proves the reap: assert `target_gone(pid, expected_exe, observed)` (reap.rs:215 — no-knowledge\r\n  never read as death) per service pid; bare-liveness \"no survivors\" is the false-clean named above.\r\n  TOKEN SET VERIFIED COMPLETE-PLUS-ONE (deployah, refuse() sites enumerated at source): the eight\r\n  tokens above sit at :128 self, :132 ancestor, :136 breadcrumb-moved, :146 gone, :149\r\n  unproven-identity, :155 reused, :166 unreadable-image, :172 foreign-image — each in the right\r\n  class — and there is a NINTH neither list held: `Refused(\"no-breadcrumb\")` at :243, returned\r\n  before authenticated_kill is reached. Doyle-ruled 2026-08-03, both halves: (1) `no-breadcrumb`\r\n  classifies SOUND — **SCOPED (deployah source-read, same night): it is two states wearing one\r\n  name.** `breadcrumb_daemon_pid` (reap.rs:59–63) collapses file-absent, permission-denied, any IO\r\n  error, AND a husked/unparseable partial write into one `None` via two `.ok()`s — so the token is\r\n  ABSENCE OF KNOWLEDGE, not proof of absence, and it is SOUND only because the calling test has\r\n  already asserted its daemon stopped. Every other SOUND token carries positive proof; a LIVE\r\n  daemon whose pid file is unreadable or husked emits the identical token and leaks wearing\r\n  \"nothing to reap\" — the helper's one fail-open path inside a fail-closed design (its own module\r\n  doc: no-knowledge is never read as death), and the same sentence as [[IR-8]]: a zero that cannot\r\n  see is not a zero. CORRECT REMEDY (doyle-ruled, deferred — not this lane, unreachable from this\r\n  test's pids): split at source into `no-breadcrumb` (absent) vs `unreadable-breadcrumb` (TRAP,\r\n  beside unreadable-image) — IR-8's unreadable-bucket fix in a second location; land the pair in\r\n  the census/reap wave IR-8 already names, one remedy for two entries. Precondition on the split\r\n  (hertz): common/reap.rs compiles into EVERY spt integration test binary, so enumerate the callers\r\n  that actually REACH `reap_breadcrumb_daemon` before the token split lands — those are the tests\r\n  whose teardown semantics change; own lane, not a rider. ENUMERATION DONE (deployah, same night,\r\n  read-only): 21 caller tests, every one passing &spt_bin as expected_exe (the per-pid trap is\r\n  specific to resident_service_e2e's svcmock pids — it does not generalize to this population);\r\n  20 callers fire-and-forget the Verdict; the one value-assertion, reaper_guard.rs:192-196, pins\r\n  `Refused(\"no-breadcrumb\")` for an ABSENT breadcrumb only — absent KEEPS the token under the\r\n  split, so that assertion survives unchanged (:183's stale-pid check is the loose\r\n  `matches!(Refused(_))`). The split is ADDITIVE: one source split, one new token, zero caller\r\n  rewrites. THE GAP THAT LET THE COLLAPSE HIDE: reaper_guard covers eight refusal shapes but has\r\n  NO test for an unreadable or malformed daemon.pid — the one state where absence-of-knowledge\r\n  reads as absence-of-target is the one state without a conformance test; (b) ships with exactly\r\n  that evidence (a garbage daemon.pid and an unreadable one, each asserting the new token).\r\n  ASSIGNED: deployah owns the (b) lane (doyle-ruled 2026-08-03), SEQUENCED AFTER hertz's IR-18\r\n  lane — the exhaustive panic-catch-all lands first, so the new token arrives forced-classified\r\n  per this entry's own design, and the (b) lane classifies it TRAP in the same change. SCOPE\r\n  RE-RULED (2026-08-03, on deployah's third-site find): the collapse now has THREE known sites\r\n  (reap.rs:59-63, resident_service_e2e's mock_pid :100-106, and the shape wherever a test reads a\r\n  self-written pid file) — so (b) lands ONE shared read-a-pid-breadcrumb helper that distinguishes\r\n  absent from unreadable ONCE, adopted at the enumerated sites, not a per-site token split; the\r\n  single-source-discriminant rule, applied before a fourth site mints itself.\r\n  **THIRD SITE CONFIRMED AT SOURCE (deployah, read-only 2026-08-04) — it was a predicted SHAPE and\r\n  is now an address:** `crates/spt/tests/resident_service_e2e.rs:136-137`, `brain_ready`, which\r\n  `.ok()?`s BOTH the read and the JSON parse — two collapses in two lines, the self-written-pid-file\r\n  shape this entry predicted. What makes it the worst of the three rather than the third of three:\r\n  its output feeds `brain_seed`, a population-sweep SEED, so an unreadable `brain.ready` silently\r\n  drops a whole subtree from the sweep. The other two sites lose one pid; this one degrades the very\r\n  instrument that is supposed to cover them, and it does so while the sweep still reports clean —\r\n  [[IR-8]]'s sentence again, now inside the instrument rather than beside it. The (b) lane's helper\r\n  therefore has to be adopted at this site to be worth landing at all. Still deployah's,\r\n  still after hertz's lane; hertz's lane does NOT wait for it (the population assertion covers the\r\n  leak class independent of pid bookkeeping — that is its virtue). (b) INTAKE ITEM (doyle gate on\r\n  the IR-18 lane, 2026-08-03, deferred there deliberately): the lane's verdict-gate SOUND-arm\r\n  comment reads \"provably not there\", which overclaims for `no-breadcrumb` (absence-of-knowledge,\r\n  not proof — the scoped reading belongs at that arm); comment-only, and (b) rewrites that arm\r\n  when `unreadable-breadcrumb` splits out, so it lands there rather than costing a solo respin.\r\n  SECOND (b) INTAKE ITEM (hertz self-noted at re-gate, doyle-ruled deferred): cleanliness is\r\n  currently stated at THREE sites (two asserts + `is_clean`) — the drift that produced the\r\n  scope_lost condition bug (a failed edit followed by a narrower successful one replaced the\r\n  message but not the condition; the artifact of that failure mode IS message/code disagreement).\r\n  (b) consolidates to conditions derived from one source, weighing the two-message diagnostic\r\n  split it would cost. The\r\n  exhaustive panic-catch-all match is what makes the split safe to do later: the new token lands\r\n  loud on first fire in every consuming gate, forced to be classified, never silently passed. Until then the scoped reading above is the\r\n  gate's contract — and the LANE BUILDER writes that scoped reading into the match's SOUND-arm\r\n  comment (the sketch's \"nothing to read is nothing to kill\" is the exact inference the source\r\n  forbids; the comment must not teach the false step); (2) the gate closes over the\r\n  token set — SPELLED BUILDABLY (hertz correction 2026-08-03; the earlier \"no wildcard arm\" wording\r\n  is an instruction rustc rejects, since the refusal reason is a `&'static str` (:55) and a string\r\n  match always requires a catch-all): the match names the six SOUND tokens as a pass arm, the three\r\n  TRAP tokens as a panic arm, and the REQUIRED catch-all arm is not a wildcard PASS — it panics\r\n  naming the unknown token (\"unclassified reap refusal token — classify it in this match\"), so\r\n  upstream drift announces itself the first run it fires instead of sliding into a silent pass.\r\n  Runtime fail-closed, not compile-time: compile-time closure needs the reason to become an enum in\r\n  common/reap.rs, an upstream change touching every consumer — ruled NOT smuggled into this lane\r\n  (candidate for its own thin lane if ever wanted; doyle concurs runtime fail-closed is\r\n  proportionate). Direction of the default, kept in the record: a missed trap state is an invisible\r\n  leak wearing the reap line a reviewer wants to see; an unclassified harmless token is a loud red\r\n  costing one edit. Cheap and loud beats silent and wrong. (Count hygiene, hertz self-flagged: a\r\n  single-line grep for the refuse() sites returns five of nine — three wrap across lines; the nine\r\n  stands on reading, not the grep. The sweep-count trap in miniature.)\r\n- **Prior observed instance of the class, in-tree (hertz 2026-08-03 — stated to understate):**\r\n  reap.rs:3–11 documents the measurement and a casualty: pid reuse on the Windows gate box at\r\n  2.2s minimum / p50 11.7s under a Phase-A battery, and a concurrent test process killed by a bare\r\n  kill on a stale breadcrumb pid, dying with bare exit 1 and no panic — the observed\r\n  `worker_lifecycle_e2e` red in golden job 90742055246 (that test's intermittent class is board\r\n  releases#32, still in-flight). Different test, different job — it does NOT reproduce this entry's\r\n  specimen and promotes nothing; what it settles is that the class is real IN THIS SUITE with a\r\n  named victim, and the authenticated reaper is the remedy someone already built for it —\r\n  resident_service_e2e simply never adopted it. Two shape-predictions it supplies, made before this\r\n  specimen existed: the p50 11.7s reuse window is short against this test's 45s waits and ~124s\r\n  runtime (window wide open). (A second claimed match — \"bare-exit-1-no-panic matches the empty\r\n  daemon.stderr.log\" — is RETRACTED as a category error, hertz+deployah 2026-08-03: reap.rs's\r\n  phrase describes the VICTIM TEST PROCESS dying, not a daemon's log; two processes, two\r\n  artifacts.) Predictions, not proof; the specimen stays CANDIDATE — shape since reproduced on\r\n  demand, agent unidentified (see the control record above).\r\n- **Rig near-miss, caught before first execution (hertz 2026-08-03) — kept as design justification,\r\n  not an anecdote:** the positive-control arm's first draft selected its victim machine-wide\r\n  (`Win32_Process Name='spt.exe'` + cmdline match `daemon run`, then force-kill). hfenduleam is the\r\n  Windows CI runner as well as a dev box, so that filter matches CI's own test daemons: run while a\r\n  leg was live, it would have force-killed a running job's daemon and reported the result as a\r\n  measurement — fabricating a red in someone else's job, the exact class this entry documents.\r\n  Corrected to a parent-scoped selector (daemon = child of the test pid; service = child of that\r\n  daemon); `CREATE_BREAKAWAY_FROM_JOB` does not weaken parent-id attribution, since breakaway leaves\r\n  the JOB, not the parent record — which is also why the orphaned svcmock stays attributable to the\r\n  daemon that spawned it. **The load bought the catch** (blocked on the box ⇒ re-read instead of\r\n  ran). Bearing on the fix: the INSTRUMENT built to study a bare-selector reaper was itself written\r\n  with a bare selector. The remedy therefore cannot be \"be careful\" — the authenticated path must be\r\n  the only one within reach in this suite.\r\n- **Ripe when:** RIPE NOW, and not gated on the rate run that was cancelled.\r\n- **Size:** small.\r\n\r\n### IR-19 — Docs-only pushes to main run full unit legs (classifier is PR-only) — intent unverified\r\n- **Status:** RETIRED 2026-08-18 — intentional for main pushes, not a classifier defect. · **Origin:** hertz observation 2026-08-03 (register-push\r\n  cadence gated his rig behind repeated hfenduleam unit legs); mechanism verified by doyle at\r\n  source same night.\r\n- **What/why:** `ci.yml`'s `changes` job classifies docs-only diffs ONLY for `pull_request` events\r\n  — push events hardcode `code=true` (ci.yml:45–48, an explicit branch, not a fallthrough), so\r\n  every docs-only push to main spins both full unit legs. Tonight: five register docs pushes each\r\n  queued a Windows unit leg on hfenduleam; concurrency kept one running + one pending (main is\r\n  never cancelled in-progress, pending runs supersede — the recorded behavior matches ci.yml:9–13).\r\n  FINDING SETTLED (deployah, same night, from the workflow): this is not intent — it is a scope\r\n  the classifier never had; the `*.md` / `traceable-reqs.toml` case arms are only ever REACHED on\r\n  pull_request (the early-return precedes them), and golden.yml's own hardcoded `code=true` is\r\n  unrelated (golden triggers only on golden/**). REMEDY STILL OPEN on a named tension: extending\r\n  the classifier to pushes leaves a docs-only main TIP with no run of its own — fine if\r\n  tested-sha==merged-sha means \"the code at this sha was tested\" (it was, at the last code sha),\r\n  not fine if any gate or reader takes \"main tip has a green run\" as the check. One person reads\r\n  the consuming gates before any remedy (doyle, at the next CI-touching wave) — three assuming is\r\n  how this class ships.\r\n- **Resolution:** the consuming contract already answers the held question:\r\n  `REQ-CI-DOCS-ONLY-THIN` is PR-only and explicitly says ADR-0050 supersedes\r\n  it for main pushes. Main-tip evidence remains full by design; no classifier\r\n  branch was widened.\r\n- **Interim rule (doyle, same night):** batch register edits into one push instead of landing them\r\n  as they occur — the cadence is a real gate on whoever is queued behind the runner.\r\n- **Ripe when:** next CI-touching wave, after the intent question is answered on the REQ record.\r\n- **Size:** small (one conditional, if the answer is \"extend\").\r\n- **Composed:** LOCKSMITH (#132) — doyle reads the consuming gates during the batch's CI-touching\r\n  wave (the intent question), BEFORE any classifier remedy. 2026-08-03.\r\n\r\n### IR-20 — resident_service_e2e's `spt daemon stop --force` does not stop the daemon; teardown is complete only because the kills are\r\n- **Status:** open · **Origin:** hertz 2026-08-03, measured on the IR-18 lane's own clean run\r\n  (hfenduleam, log kept); routed text, doyle-landed.\r\n- **MEASURED:** teardown runs `spt(&[\"daemon\",\"stop\",\"--force\"])` then reaps. At reaper fire, every\r\n  target was still ALIVE and every verdict was `Killed`, not `gone` — verdicts=[boot Killed,\r\n  rel Killed, brain Killed]; the brain's kill line names it `(child process of PID 46896)` — the\r\n  daemon — so the daemon was still resident too and was taken down by the `Child` handle, not the\r\n  stop. A stop that worked would have left the reaper `gone`. This rules OUT the innocent reading\r\n  (stop doesn't manage services): the stop did not reach the DAEMON either.\r\n- **NOT ESTABLISHED — two rungs, neither discriminated:** (1) the rig seeds a `doyle` perch with\r\n  `std::process::id()`, satisfying `ceremony_agent_ground`'s pid-ancestry rung for every child of\r\n  the harness; (2) the rig never scrubs `OWL_SESSION_ID`/`SPT_AGENT_ID`/`SPT_ENDPOINT_ID` from its\r\n  teardown commands, and the measuring run launched from a live agent session, so the env rung was\r\n  live too. `--force` overrides neither. The stop's output is discarded at the call site\r\n  (`let _ = spt(...)`) — no diagnostic names a denial, and no claim is made that one fired.\r\n  Settling it is one run with the stop's stderr captured — on the CI runner AS WELL AS the dev box,\r\n  since the rungs fire on different machines.\r\n- **Why it matters beyond this rig:** REQ-TEST-RIG-DAEMON-TEARDOWN-PROVEN's own failure shape\r\n  inside a rig that passes — teardown completeness rested entirely on breadcrumb kills that were,\r\n  until IR-18, bare `taskkill /F /T` on unauthenticated pids; the most trustworthy-LOOKING\r\n  component (an explicit `--force` stop) was doing nothing while the least trustworthy one did all\r\n  the work. Exactly why the population gate exists rather than per-pid checks alone.\r\n- **Remedy caution (the sentence that must not drop):** the prescribed fix (seed pid 0, scrub the\r\n  three markers — REQ-TEST-RIG-DAEMON-TEARDOWN-PROVEN's own gate) is NOT free here: this rig's\r\n  `doyle` perch pid is load-bearing for the shell bind-by-token legs, so the two remedies are not\r\n  interchangeable — a lane taking this must check which legs depend on the pid before changing it,\r\n  or it fixes the stop and breaks the REQ-INSTALL-11 legs the rig exists for. Kin:\r\n  REQ-BROKER-STOP-ENDPOINT-DENY (the refusal being worked around).\r\n- **LANE-LINKED 2026-08-30 (#242 close sweep):** hertz's queued daemon-leak fixup lane carries\r\n  this entry (brief cites IR-7/17/20/34/35/63); leaves the register when that lane lands.\r\n- **Ripe when:** a hertz test-hardening wave, or alongside the (b) helper lane's touch of this rig.\r\n- **Size:** small (stderr-captured discrimination run × two machines, then the scoped remedy).\r\n\r\n### IR-54 — golden-head-intake runbook: three properties this cut proved should be construction, not discipline\r\n- **Status:** BUILT 2026-08-29 — PR #176 (`880b3b9c`, landed on main via `37368263`).\r\n  · **Origin:** PORTER (#205) v0.59.0 cut, 2026-08-21 — doyle (gater) + deployah (driver),\r\n  both mechanisms measured at the cut, neither cost this run anything because the driver caught\r\n  them by hand. Filed at the release-close register sweep.\r\n- **What/why (three runbook amendments, one lane):**\r\n  1. **Release-shaping at ASSEMBLY intake, not post-golden.** The head arrived code-complete\r\n     but not release-shaped (no version bump, stale CHANGELOG top section) — 5 of the last 6\r\n     cuts. v0.59.0 fixed it by authoring version material BEFORE the golden run, which is what\r\n     produced the four-name shape (ruled sha == main tip == golden ref == tag == `c62904e7`,\r\n     first time in six cuts; the previous five each argued a post-golden delta inert). Amend\r\n     `docs/golden-head-intake` so the gater's assembly checklist asks the release-shaping\r\n     question at intake and the driver never authors on top.\r\n  2. **Never-executed-cells list is a hand-off artifact.** The runbook makes it a\r\n     gater-compiles / driver-re-checks item; PORTER's handoff omitted it and the driver had to\r\n     ask. Name it in the assembly checklist beside the greenlit-form delta: which new cells'\r\n     first CI execution is this golden, and where each HAS executed (lane gate / assembled\r\n     head) — it converts a golden red from an RCA into a lookup.\r\n  3. **Lockfile-refresh rule states the PROPERTY, not the command.** Step 1 prescribes\r\n     `cargo metadata --offline`; the driver used `cargo update --workspace --offline` and\r\n     proved the actual rule by diff (workspace members only, third-party pins untouched —\r\n     14 first-party line pairs, 90 third-party unchanged). The property is the rule and the\r\n     diff is its evidence (the standing by-diff rule exists because counting misread v0.39.4\r\n     and v0.41.0 in opposite directions — and the `windows-sys` 0.59.0 collision was LIVE at\r\n     this cut, the exact condition where counting fabricates a 15th \"first-party\" bump);\r\n     demote the command to an example vehicle.\r\n- **Built evidence:** `docs/RELEASE-RUNBOOK.md` now asks the release-shaping question at assembly\r\n  intake, makes the never-executed-cells list part of the hand-off itself, and states lock refresh\r\n  as a diff-proven property with commands demoted to example vehicles. PR #176 passed\r\n  `traceable-reqs check`; the v0.65.0 cut had already exercised the release-shaped-head rule.\r\n- **Size:** small (one runbook doc lane; no code).\r\n\r\n## IN-FLIGHT ON THE BOARD (not re-homed — live WIP lanes)\r\n\r\n- releases#93 (servicehost swap test pid-inequality), releases#47 (thin-lane unit(Windows)\r\n  isolation class), releases#32 (worker_lifecycle_e2e Phase A intermittent) — infra-shaped but WIP;\r\n  a live lane is never re-homed mid-flight. When each closes, any residue lands here as a new entry.\r\n\r\n## BUILT / RETIRED\r\n\r\n### IR-15 — provably_gone is pid-only on Windows: teardown tests can fabricate reds\r\n- **Status:** BUILT 2026-08-03 · **Origin:** golden 30776330383 red on the #125 fix lane (2026-08-02)\r\n- **Lane:** hertz `golden/ir15` @a5042ec — REQ-TEST-LIVENESS-ORACLE-AUTHENTICATED (impl+unit): one\r\n  shared authenticated death-oracle test helper backed by `spt_procident::process_identity`\r\n  (identity pinned at find time, re-verified at assert), both pid-only polling sites repinned\r\n  (daemon.rs teardown test; endpoint_lifecycle.rs relay_pid). Ruled polarity held: Absent⇒gone,\r\n  Present(same start)⇒not gone, Present(different)⇒gone, Unproven⇒NOT gone, missing-stamp\r\n  degrades to pid-only loudly — every unknown errs toward the recoverable red, zero new\r\n  false-green paths. Linux caveat documented in the helper (10ms jiffies: Present(different) is\r\n  narrowing, not decisive; same-tick reuse errs red, safe).\r\n- **Golden:** run 30782259675 red on `resident_service_e2e` bring-up — delta exonerated (unrelated\r\n  family, now [[IR-17]]; same job minted [[IR-8]]'s defining specimen). Same-sha rerun 30784469908\r\n  GREEN; main ff'd to a5042ec.\r\n- **A/B discriminator (hertz):** 80/80 green both arms, quiet + churn phases; churn arm\r\n  positive-controlled (pid-allocator wrap observed <400ms, so reuse pressure was REAL in the churn\r\n  arm); rule-of-three bounds the original flake at ~7.5%/run/sha. Specimen 30776330383 remains\r\n  not-reproduced, cause unidentified — the repin removes the false-red MECHANISM; it does not\r\n  adjudicate the specimen. [[IR-16]]'s kill-side arm (TerminateJobObject return discarded) stays\r\n  a live discriminating instrument for any recurrence — and since 2026-08-03 it is no longer the\r\n  only one: [[IR-18]] (the test's OWN bare breadcrumb tree-kill) is the second kill-side candidate,\r\n  test-side rather than product-side. A recurrence must discriminate between them, not assume\r\n  either: IR-16's arm is a job whose termination silently half-fails (survivor still holds the\r\n  captured image); IR-18's is a victim killed by a bare pid it no longer owns —\r\n  `broker_survived=false` with the boot service still ALIVE and its message spooled. (An earlier\r\n  spelling of IR-18's signature here said \"empty stderr\"; retracted — empty stderr is present on\r\n  healthy runs and discriminates nothing.)\r\n\r\n### IR-21 — CLASS: a helper binary's build is never requested, only its LOCATION is, so any narrow invocation manufactures a red that belongs to the rig\r\n- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane. · **Origin:** todlando 2026-08-03. Filed as one instance, rewritten as a CLASS the\r\n  same day when a second member appeared, rewritten AGAIN when the mechanism was measured — the\r\n  first two versions described symptoms and got the remedy wrong. **Corrected a fourth time the same\r\n  day**: remedy (1) claimed the 11 same-package sites were missing a build edge, and todlando\r\n  falsified that by measurement while executing it (replicated independently by doyle). The error was\r\n  doyle's to carry — it was ruled on, not just written. The general rule that refutes it was already\r\n  in this entry's own CI-member section; diagnosing a class does not inoculate you against drawing\r\n  its opposite consequence one section later.\r\n- **Numbers below re-derived on `main` @`3efd7e6` over `git ls-files` (tracked files only). Each\r\n  carries its command; re-run rather than cite.**\r\n- ⚠ **Scan-root hazard, measured 2026-08-03 and worse than first reported:** a naive recursive\r\n  `grep -r` from the project root inflates by **~35×**, not the ~5× an earlier draft of this entry\r\n  claimed — 426 tracked `.rs` against 14,865 on disk with `target/` excluded, because `.worktrees/`\r\n  holds full copies of the tree. **And the unscoped grep does not COMPLETE** (still running at a\r\n  120s timeout while `git ls-files` returns instantly), so the failure mode is not only a wrong\r\n  number but a command that reads as hung on a tree where dozens of worktrees are normal. Use\r\n  `git grep` or `git ls-files | xargs grep`; both are scoped to tracked files by construction.\r\n\r\n#### THE MECHANISM (measured, both ends)\r\n\r\n**Build end — `cargo test` with a narrow target selector compiles a `[[bin]]` AS A TEST HARNESS and\r\nnever emits the plain executable.** Measured: `cargo test -p spt --bins` on a clean pool produced\r\nfive executables, every one hash-suffixed under `target/<profile>/deps/`, and ZERO plain exes in\r\n`target/<profile>/`. The bin was built. The file the test looks for was not written.\r\n\r\n**Consumer end — the resolver borrows a guaranteed binary's path to locate an unguaranteed one.**\r\nAll 29 copies of `sibling_bin` in `crates/spt/tests/` reduce to two textual variants (22 + 7) of one\r\nbody:\r\n\r\n```rust\r\nfn sibling_bin(name: &str) -> PathBuf {\r\n    PathBuf::from(env!(\"CARGO_BIN_EXE_spt\"))\r\n        .with_file_name(format!(\"{name}{}\", std::env::consts::EXE_SUFFIX))\r\n}\r\n```\r\n\r\n`CARGO_BIN_EXE_spt` is used **only as a directory anchor**. Cargo therefore sees a dependency on\r\n`spt` and on nothing else; the `{name}` half is a string join it cannot observe. The dependency edge\r\ndoes not exist at any level a build system could act on — which is why \"use the wider command\" is\r\nnot the fix and why the failure is invisible on a warm pool where some earlier run happened to leave\r\nthe file behind.\r\n\r\nThe unit-test resolver at `crates/spt/src/cli.rs:25601` reaches the SAME directory from a different\r\nanchor (`current_exe()` → `deps/` → parent) for the same reason: its own doc comment records that\r\nunit tests get no `CARGO_BIN_EXE_*` at all.\r\n\r\n**That mechanism explains both original members at once, including the polarity inversion that made\r\nthem look like different bugs:** whether `cargo test -p spt` or `cargo test -p spt --bins` happens\r\nto leave a plain exe behind is incidental to a dependency neither command was told about.\r\n\r\n#### SCOPE — WHERE IT BITES, AND WHERE IT DOES NOT\r\n\r\n**It bites NARROW invocations — `-p <pkg>`, `--bins`, `--lib` — i.e. gate rigs and local runs.**\r\nBoth members were hit on the LOCKSMITH t1 lane against fresh throwaway pools; each was discharged\r\nin-lane as a rig artifact. That is the whole field population to date.\r\n\r\n**GOLDEN IS ACQUITTED, and the acquittal is measured rather than assumed.** `cargo test --workspace\r\n--no-run` emits all 13 plain binaries — mock-session, mock-shell, capture-player,\r\nconsole-mode-probe, service_fixture and the rest — so a workspace build produces the cross-package\r\nhelpers by construction. Confirmed under nextest, the tool CI actually runs, with a real compile.\r\n\r\n⚠ **The measurement that establishes this is not the obvious one.** Deleting the plain exe and\r\nwatching it reappear is NOT evidence of a rebuild: cargo's uplift restores a hardlink from an intact\r\n`deps/` artifact, with link count 3 and an UNCHANGED mtime, which looks exactly like a build and\r\nsays nothing about a pool that never had the file — and a pool that never had it is the only kind a\r\nrig runs on. The sound probe removes the plain exe AND both `deps/` artifacts, confirms all three\r\nabsent, then watches the target actually recompile (mock-adapter, 5.77s, fresh mtime). The first two\r\nattempts were setup, not measurement.\r\n\r\n⚠ **The suspicion this acquits is structurally well-founded, so record the answer, not just the\r\nverdict.** `twohost-a`/`twohost-b` are `needs: test`, so the only mock-adapter prebuild runs AFTER\r\nthe phases that use it; `target/` is gitignored, so checkout never cleans it on a persistent\r\nself-hosted workdir. Every precondition for artifact leakage is present — the build simply does not\r\nneed it. The next person who reads that job graph will form the same hypothesis; this is the answer\r\nwaiting for them.\r\n\r\n#### THE ONE CI-SIDE MEMBER THAT IS REAL\r\n\r\n`crates/spt/src/cli.rs::adapter_translate_proof_gates_on_commit` is a **unit** test (`kind(bin)`),\r\nand `CARGO_BIN_EXE_*` is set only for integration tests and benches of the declaring package. A unit\r\nconsumer therefore CANNOT express the dependency through the env var at all — it has no choice but\r\nto resolve by path. That is why `.github/workflows/ci.yml:105-106` carries a hand-written\r\n`cargo build -p spt --bin translate_proof_fixture` before the unit lane, with a comment\r\n(`ci.yml:102-104`) stating this exact mechanism.\r\n\r\n**Deleting that step would red the unit lane on a clean pool, and it would read as a code red.**\r\nSomebody already hit this class, fixed their own leg correctly, and never turned it into a rule —\r\nthe comment at `ci.yml:102` is IR-21 written a milestone early, in the one place only its author\r\nwould find it.\r\n\r\n#### POPULATION\r\n\r\n**13 bin targets in the workspace** (`cargo metadata --no-deps`, not a grep — an auto-target under\r\n`src/bin/` and `xtask` are both invisible to a `[[bin]]` grep). Two are not helpers (`spt`, `xtask`);\r\nthe other **11 are test helpers**, across three packages:\r\n\r\n| package | helpers |\r\n|---|---|\r\n| `adapters/mock` | mock-session, mock-shell, capture-player, console-mode-probe |\r\n| `crates/spt-daemon` | dispatch_fixture, service_fixture, summarizer_fixture, xlate_choreo_fixture (⚠ this row was mis-\"corrected\" 2026-08-22 to claim `xlate_choreo_fixture` no longer existed — IT DOES, as an AUTODISCOVERED `src/bin/` target with no `[[bin]]` stanza; the original row was right and merely predated `summarizer_fixture`. See IR-58) |\r\n| `crates/spt` | translate_proof_fixture, post_step_fixture, gh_fixture, git_fixture |\r\n\r\n**44 literal `sibling_bin(\"…\")` call sites**, all in `crates/spt/tests/`, served by **29 copied\r\nresolvers**. Split by whether the BUILD IS ALREADY GUARANTEED — which is not the same question as\r\nwhether the env var is available, and an earlier version of this entry conflated the two:\r\n\r\n| class | sites | detail | build guaranteed? |\r\n|---|---|---|---|\r\n| **cross-package** | **33** | mock-session 26, mock-shell 6, service_fixture 1 | **NO — the hazard members** |\r\n| **same-package** | **11** | translate_proof_fixture 7, git_fixture 2, post_step_fixture 1, gh_fixture 1 | **YES — already, by construction** |\r\n\r\n⚠ **MEASURED TWICE, and it falsifies what this entry said on 2026-08-03 before this revision:** cargo\r\nbuilds **every bin target of a package whenever it builds ANY integration test of that package** —\r\nthat same act is what sets `CARGO_BIN_EXE_*` in the first place. So the 11 same-package sites were\r\nnever unexpressed in a way that could bite, and the hazard population is **33 cross-package sites\r\nplus the one unit-test member = 34**, not 44.\r\n\r\n- **Probe 1 (todlando, root pool):** deleted all four `translate_proof_fixture` artifacts (both\r\n  hash-suffixed harness exes, the `deps/` plain exe, the uplifted plain exe), confirmed absent, then\r\n  built ONE UNRELATED and UNMODIFIED integration test of the same package —\r\n  `cargo test -p spt --test attach_wedge_e2e --no-run`, exit 0, 14.45s. Both plain exes returned with\r\n  fresh mtimes; the hash-suffixed harness exes stayed absent, which is what distinguishes a bin\r\n  DEPENDENCY build from a `--bins` harness build.\r\n- **Probe 2 (doyle, `.worktrees/gate-ec5f38a` pool, independent replication with a different fixture\r\n  and a different probe test):** deleted `gh_fixture`'s plain exe, its `deps/` plain exe AND its\r\n  hash-suffixed harness exe, confirmed all three absent, then built `--test json_emit --no-run`\r\n  (exit 0) — a test that never names `gh_fixture`. The plain pair returned at a FRESH mtime (09:13\r\n  against the 09:00 it carried before), so this is a real build and not the hardlink uplift this\r\n  entry warns about elsewhere; the harness exe stayed absent.\r\n- **Neither probe needs a baseline arm:** the probe test is unmodified and references nothing under\r\n  edit, so what it measures is cargo's behaviour, not anyone's change.\r\n- **Corroborated by this entry's own field data:** neither original member was a same-package\r\n  integration site — member 1 is a UNIT test, member 2 is CROSS-package. The class never had a\r\n  same-package integration member, and the CI-member section below already stated the governing rule\r\n  (`CARGO_BIN_EXE_*` is set only for integration tests and benches of the declaring package) one\r\n  section before the remedy drew the opposite consequence from it.\r\n\r\nCommand: `git ls-files '*.rs' | xargs grep -hon 'sibling_bin(\"[a-z_-]*\"' | sed 's/.*sibling_bin(\"//;\r\ns/\"//' | sort | uniq -c`.\r\n\r\n⚠ An earlier report gave 48 sites and a 6/11/37 split. Take the table above: it counts only literal\r\ncall sites in tracked files and it ships its command. The 11 is the same 11 in both counts.\r\n\r\n**The LOCATION half of this class is already closed** by `crates/spt-term/tests/support/fixture_bin.rs`\r\n— a shared resolver rather than 29 copies. It does not close the BUILD half, and should not be\r\nmistaken for having done so.\r\n\r\n#### REMEDY SHAPE (not ruled)\r\n\r\nThe distinction that matters is location vs. build:\r\n\r\n1. **The 11 same-package sites are NOT hazard members and need no build fix.** Their build edge\r\n   already exists (see the two probes in POPULATION above); `env!(\"CARGO_BIN_EXE_<name>\")` for the\r\n   fixture itself would add nothing to it. Converting them is a **CLARITY** change, worth doing on\r\n   its own smaller merits — the path becomes the one cargo actually emitted rather than a string-join\r\n   of a directory anchor and `EXE_SUFFIX`, five copies of `sibling_bin` stop existing (29 → 24), and\r\n   it completes a migration already paid for: `crates/spt/tests/fixtures/translate_proof_fixture.rs:7-12`\r\n   records that the fixture was re-homed into `spt` precisely to obtain\r\n   `CARGO_BIN_EXE_translate_proof_fixture`, and then all 7 call sites resolved by path anyway. **It is\r\n   not a build fix and must not be filed as one.**\r\n2. **The 33 cross-package sites cannot**, by cargo's design. Their options are an asserted build in\r\n   the test's own setup, a `dev-dependencies` artifact dependency, or an explicit documented\r\n   prebuild — the ci.yml:106 shape, made a rule instead of a local fix.\r\n3. **Standardising on one wider invocation is NOT a remedy.** It changes which pools happen to work;\r\n   it does not create the dependency edge, and the two original members had opposite polarity under\r\n   exactly that theory.\r\n4. Collapsing the 29 resolver copies is worth doing on the `fixture_bin.rs` model, but on its own it\r\n   makes the class HARDER to see — one shared resolver still anchored on `CARGO_BIN_EXE_spt` hides\r\n   the 33 genuinely unexpressed dependencies among its 44 call sites behind one function.\r\n\r\n#### SUPERSEDED FRAMING, KEPT SO IT IS NOT RE-DERIVED\r\n- **Status of the original filing:** open · **Origin:** todlando 2026-08-03, both members hit on the\r\n  LOCKSMITH t1 lane against fresh throwaway pools; each discharged in-lane as a rig artifact, filed\r\n  here so the next clean rig does not re-diagnose them as code reds.\r\n- The first two versions of this entry framed the class as \"the rig's command does not build what\r\n  the test needs\" and proposed standardising on a wider invocation. **Both are superseded by the\r\n  measured mechanism above** — the dependency is not under-expressed, it is INEXPRESSIBLE in the\r\n  form these call sites use, so no choice of invocation creates it. Kept only as the two FIELD\r\n  MEASUREMENTS that produced the class, which remain true:\r\n- **MEMBER 1 — MEASURED:** `cli::tests::adapter_translate_proof_gates_on_commit` failed on the\r\n  first `cargo test -p spt --bins` run. Its fixture binary `translate_proof_fixture` (a\r\n  `tests/`-homed `[[bin]]`) was ABSENT from the pool — `ls` on the path returned No such file.\r\n  Building it explicitly and re-running the IDENTICAL command PASSED, after which the full `--bins`\r\n  suite passed 584/585 with only the releases#117 probe red (that one RED by design). So the\r\n  discriminator is the fixture's presence, not the tree: same command, same sha, red then green\r\n  across one `cargo build` of the fixture.\r\n- **MEMBER 2 — MEASURED:** `cargo test -p spt` does not build `mock-adapter --bin mock-session`, so\r\n  `attach_wedge_e2e` panics `\"the dummy-harness program must be built\"`. Note the polarity is\r\n  INVERTED against member 1 — there the narrower `--bins` was the defective invocation and\r\n  `cargo test -p spt` the correct one; here `cargo test -p spt` is itself insufficient. So the\r\n  class is NOT \"use the wider command\"; it is that the dependency is not expressed to the build at\r\n  all, and which invocation happens to work is incidental.\r\n- **What/why (still true):** on a WARM pool the helper is already there from some earlier run and\r\n  the test passes, so the defect is invisible exactly where most people work and fires only on a\r\n  clean pool — i.e. on a GATE RIG, which is the one place a false red costs the most.\r\n- **The sweep this entry once called its first step HAS BEEN RUN** (todlando 2026-08-03) and its\r\n  result is the POPULATION section above. It is no longer outstanding.\r\n\r\n- **Why it is register debt and not a lane bug:** nothing in the product is wrong. The gap is\r\n  between what a test needs built and what the rig's command builds, and the fix belongs to the\r\n  tests' declarations, not to whoever is running a gate that day. Sibling rule:\r\n  [[gate-clean-target-not-incremental]].\r\n- **Built evidence:** golden now names every cross-package fixture prebuild\r\n  (`mock-session`, `mock-shell`, `capture-player`, `console-mode-probe`,\r\n  `service_fixture`) explicitly; `xtask binedge-check` reports zero missing\r\n  edges. All 29 local `sibling_bin` resolvers collapsed into\r\n  `tests/common/mod.rs`; the shared precondition names the missing fixture and\r\n  its package-correct build command before any product timeout.\r\n- **Ripe when:** the next gate-rig or CI-touching wave. Cheap, and it pays for itself the first time\r\n  it stops someone chasing a phantom red on a clean pool.\r\n- **Size:** remedy (1) is small AND optional — it buys clarity and subtraction, never a build edge;\r\n  medium for (2), which is a design call before it is an edit and is the only remedy that closes the\r\n  class.\r\n\r\n### IR-22 — An inherited identity env var fails a test, and the diagnostic names them ONE AT A TIME so a correct fix reads as no fix\r\n- **Status:** open · **Origin:** todlando 2026-08-03, chasing what looked like an `attach_wedge_e2e`\r\n  code red on the LOCKSMITH t1 lane; root-caused to the runner's own process environment.\r\n- **MEASURED:** `attach_wedge_e2e` failed for an INHERITED PROCESS-GLOBAL and nothing in the tree:\r\n  the daemon-stop refusal fired on the running session's own identity env. It named\r\n  `$OWL_SESSION_ID`; clearing that made it name `$SPT_ENDPOINT_ID`. With `OWL_SESSION_ID`,\r\n  `SPT_ENDPOINT_ID`, `SPT_AGENT_ID` and `SPT_SESSION_ID` all cleared: exit 0, 1 passed.\r\n- **The finding is the DIAGNOSTIC SHAPE, not the env hygiene.** Naming one variable at a time means\r\n  a correct partial fix produces an identical-looking failure, so the natural reading of \"I cleared\r\n  it and it still fails\" is that the clearing did not work — when in fact each step was right and\r\n  the message had simply moved on to the next name. A refusal that can only ever name one member of\r\n  a set it is checking teaches the person debugging it the wrong lesson. Compare the same class in\r\n  [[IR-15]]/[[IR-18]] terms: the instrument is competent and the report is not.\r\n- **Why it matters beyond one test:** any agent running suites from a live spt session carries these\r\n  vars, so this fires for every builder on a perched session and for nobody running from a bare\r\n  shell — which is precisely the split between how builders work and how CI runs.\r\n- **Candidate remedies (not ruled):** have the refusal name EVERY identity var it found set, in one\r\n  line, rather than the first; and/or have the affected tests clear the identity set in their own\r\n  setup so a perched session is not a special environment. The first is the one that pays off\r\n  outside this test.\r\n- **Ripe when:** next CI/test-hygiene wave. **Size:** small.\r\n\r\n### IR-23 — `endpoint_teardown_authority_e2e`'s two tests collide with EACH OTHER through the machine-global spt home\r\n- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane. · **Origin:** todlando 2026-08-03, LOCKSMITH t1 lane.\r\n- **MEASURED:** both tests copy a psyche binary fixture into `perch::spt_home()/srcs/dummyharness/`\r\n  (`crates/spt/tests/endpoint_teardown_authority_e2e.rs:399`), which is process-global, so run in\r\n  parallel inside one binary each holds the file the other wants: `os error 32`, \"used by another\r\n  process\". **Signature: WHICH of the two fails alternates between runs.** Under\r\n  `--test-threads=1`: 2 passed, exit 0 — and the wall clock drops from 182s to 14s.\r\n- **What/why:** two defects in one, and they should not be conflated. (1) The tests are not\r\n  isolated from each other. (2) The staging path is the MACHINE-GLOBAL spt home rather than the\r\n  test's own temp home — on a box that is also a CI runner, so the blast radius is not confined to\r\n  the suite. (2) is the one worth fixing; (1) is a symptom of it.\r\n- **Note on why this is not already caught:** the standing rule is that integration tests run\r\n  through nextest, which gives each test its own process and hides the collision entirely. So this\r\n  is latent on the sanctioned path and only bites the bare `cargo test` path — the rule is working\r\n  and masking a real defect at the same time, which is why the entry exists rather than a shrug.\r\n- **Candidate remedy (not ruled):** stage the fixture into the test's own temp home. Sweep for\r\n  siblings first — any other test writing under `perch::spt_home()` rather than a temp home shares\r\n  the shape, and nobody has counted them.\r\n- **Built evidence:** adapter source, manifest registration, and psyche fixture\r\n  staging now use the rig TempDir. The two process-global resolver users are\r\n  explicitly serialized, and the bare `cargo test` path passes both cells with\r\n  `--test-threads=2` in 13.82s after the declared fixture prebuild.\r\n- **Ripe when:** next test-hygiene wave; the 182s -> 14s figure makes it pay for itself on the\r\n  bare path. **Size:** small per test, unknown until the sweep.\r\n\r\n### IR-24 — `reap::terminate_job` discards `TerminateJobObject`'s return, alone among its own module's siblings\r\n- **Status:** BUILT — landed `3d12cf3` on main (2026-08-03), fulfilment verified against this\r\n  entry's own wanted list by doyle 2026-08-04, not merely mapped to the commit: the return is\r\n  audited and the loss NAMED (`REAP_JOB_TERMINATE_FAIL: brain subtree NOT reaped (<os error>); …\r\n  the daemon holds no other handle to reach them` — which also ANSWERS the cost-of-loss question\r\n  this entry said nobody had written down); the \"first thing to check\" was checked and the ruling\r\n  came out OPPOSITE to IR-16's site in one respect, documented as measured asymmetry in the doc\r\n  comment: `TerminateJobObject` has NO ordinary failing path (zero only for a broken handle) so a\r\n  zero is a real loss, while `TerminateProcess` fails `ERROR_ACCESS_DENIED` on the ordinary\r\n  already-exited path and is deliberately NOT checked — the premise is unit-PINNED both directions\r\n  (`terminate_job_return_discriminates_broken_handle_from_ordinary_states`, cfg(windows), with a\r\n  memberless-job false-positive arm). No `job != 0` re-check (second-weaker-rule prohibition\r\n  honored, same as IR-16). Golden evidence: rides `4b37512` (run 30873007187 attempt 5, 9/9\r\n  green; the premise unit observed PASS in-pool on the Windows leg, Linux leg green — the\r\n  cross-platform quiet-`ESRCH` concern stays with `ec5f38a`'s coverage as before). Path\r\n  correction to this entry's MEASURED line: the site is `crates/spt-daemon/src/reap.rs` (brain\r\n  subtree reaper), not `crates/spt/src/reap.rs` as first filed ·\r\n  **Origin:** todlando 2026-08-03, swept while building [[IR-16]]; deliberately\r\n  NOT folded into that lane (doyle ruling, same day) and filed instead.\r\n- **MEASURED:** `crates/spt/src/reap.rs:207-211` calls `TerminateJobObject` and discards the result,\r\n  the identical shape [[IR-16]] closed at `spt-daemon`'s `kill_tree`. Its own module's\r\n  create/assign siblings at `:178` and `:202` ARE instrumented, so this call is the odd one out\r\n  where it lives — the module already decided that these returns are worth reading.\r\n- **Why it was NOT folded into IR-16:** different subject. IR-16's site is a SUPERVISED SERVICE's\r\n  teardown, where the loss is \"a supervised service's descendants survive\" and the promise it\r\n  breaks is `REQ-RESIDENT-SERVICE`'s tree claim. This site is the BRAIN SUBTREE's kill-on-close\r\n  job, which has its own lifetime, its own caller and its own answer to \"what does a failed\r\n  termination cost here\" — and that answer has not been written down by anyone. Folding it in would\r\n  have meant settling that question in passing, inside a commit about the supervisor, which is how a\r\n  second ruling gets smuggled into a lane scoped to one.\r\n- **What it needs that IR-16's fix does not supply:** IR-16 ruled a LOUD REFUSAL (option B) on the\r\n  ground that the alternative — a process-table tree-walk fallback — is measured blind in exactly\r\n  that failure state ([[IR-18]]: descent breaks at the dead middle hop) and would trade a silent\r\n  loss for a false clean. Whether the same reasoning holds here depends on whether this site kills\r\n  its direct process in the same breath, which is what makes the middle hop dead by construction\r\n  there. **That is the first thing to check, and it is not assumed.**\r\n- **Ripe when:** any wave touching reap/teardown; it inherits IR-16's vocabulary and its\r\n  discrimination note, so the second one is cheaper than the first. **Size:** small, once the\r\n  cost-of-loss question is answered for this subject.\r\n\r\n### IR-25 — `spt-daemon --lib` reds 2-in-3 under concurrent load with bare `cargo test`, and holds green under nextest\r\n- **Status:** open · **Origin:** doyle 2026-08-03, found while gating LOCKSMITH tranche 1 in an\r\n  isolated worktree; chased to a mechanism and scoped OUT of the release path before the head was\r\n  assembled.\r\n- **MEASURED, four arms, same box, same hour, matched load** (a second `cargo test -p spt-store\r\n  --lib` loop running throughout; `spt-store` itself stayed green in every round, so the box was not\r\n  generically failing):\r\n\r\n  | tree | instrument | result |\r\n  |---|---|---|\r\n  | lane `ec5f38a` | `cargo test --lib`, at rest | 821/821 ×4 |\r\n  | lane `ec5f38a` | `cargo test --lib`, under load | **2 of 3 RED** (142s, 117s) |\r\n  | lane `ec5f38a` minus its 5 new tests | `cargo test --lib`, under load | 3 of 3 green (117s, 84s, 105s) |\r\n  | main `932e14b` | `cargo test --lib`, under load | 3 of 3 green (97s, 119s, 104s) |\r\n  | lane `ec5f38a` | **`cargo nextest run`, under load** | **3 of 3 green, 821/821** (88s, 85s, 72s) |\r\n\r\n- **Three DIFFERENT victims across two loaded runs**, all process/timing-shaped, all PRESENT AT MAIN\r\n  and green there: `servicehost::…a_service_that_ignores_the_stop_marker_is_force_killed_and_confirmed_dead`\r\n  (panics `ForceKilled must MEAN the owned child is gone` right after `SERVICE_KILL_UNCONFIRMED`),\r\n  `applyhost::…broker_reports_its_compiled_image_version_over_ipc`, and\r\n  `daemon::…a_tree_teardown_reaches_a_grandchild_the_service_spawned`.\r\n- **MECHANISM: in-process thread interference, not product code.** Bare `cargo test` runs a crate's\r\n  tests as threads in ONE process. The lane's five new tests are process-spawning kill-tree tests;\r\n  under load they starve confirm windows of NEIGHBOURING tests that were always marginal. Removing\r\n  exactly those five flips 2-of-3-red to 0-of-3-green at the same sha, in the same binary, at the\r\n  same durations — one of the green runs sits at 117s, precisely a duration that had produced two\r\n  failures with them present.\r\n- **IT DOES NOT REACH GOLDEN.** nextest gives every test its own process, and golden runs nextest.\r\n  The population is GATE RIGS AND LOCAL RUNS — the same population as [[IR-21]], reached by a\r\n  different mechanism, which is why these are two entries and not one.\r\n- ⚠ **The instrument switch is the whole finding.** Measured with bare `cargo test`, this reads as a\r\n  lane blocker; measured with the tool CI actually runs, it is a rig-scoped nuisance. Anyone\r\n  re-opening this must state WHICH instrument produced their observation before quoting a verdict.\r\n  The same tool gap acquitted [[IR-21]]'s golden question the same day.\r\n- ⚠ **The pre-existing fragility is NOT thereby closed.** Those three tests were marginal before this\r\n  lane and the lane only exposed them; \"make the new tests quieter\" would re-hide a real weakness.\r\n  Hardening them is test-side work (hertz's lane by the dispatch split), not the builder's.\r\n- **Two rig defects of the gater's, recorded because they nearly cost the verdict:** (1) a first\r\n  re-run at rest came back 4/4 green and proves NOTHING — a sequential idle probe cannot express a\r\n  load-sensitive failure, so that is a competence-controlled zero, not an acquittal; (2) the first\r\n  baseline attempt ran its two arms UNSYNCHRONISED (the load generator finished while the measured\r\n  arm was still on run 1), which would have compared a loaded lane against an idle main and read as\r\n  \"the lane broke it\". A discriminator whose arms ran under different conditions cannot discriminate.\r\n- **Ripe when:** alongside [[IR-21]] on the next gate-rig or CI-touching wave, or immediately if\r\n  anyone starts gating on bare `cargo test` on a loaded box. **Size:** small to document the rig\r\n  rule (gate with nextest); medium to harden the three marginal tests.\r\n\r\n### IR-26 — POOL-OWNER claims authorize takeover from a DEAD holder, so releases#103's hazard reaches through the guard\r\n- **Status:** OPEN for residual claim-time observability and stale-reader enforcement; the\r\n  original build-side lane is COMMITTED (see its later reconciliation below), not still\r\n  uncommitted. Header corrected 2026-09-11; no residual closed by cleanup. · **Origin:**\r\n  hertz 2026-08-03/04, found by its own test rather than by reading, and\r\n  reported unfiled for composition. Composition ruling is doyle's, 2026-08-04.\r\n- **What/why:** a POOL-OWNER claim named a holder pid; lane liveness was read from whether that pid\r\n  was alive. hertz MEASURED the failure on this box: **3 of 3 claims had dead holders while one of\r\n  those lanes was live** — so the guard authorized exactly the interleaving takeover releases#103\r\n  exists to prevent. The remedy records the lane's GIT IDENTITY (branch + the base sha it carried at\r\n  claim time) and reads lane state from ancestry: in flight while the tip is not contained in\r\n  `origin/main`; settled once merged, once the branch is gone, or once the branch no longer carries\r\n  the claimed base (the branch-level twin of a recycled pid). Holder pid demotes to advisory — a\r\n  LIVE holder still refuses, a dead one no longer authorizes.\r\n- **The strongest finding in it, and it is a filter-competence one:** without the base anchor, a\r\n  missing branch read as \"settled, branch gone\" **out of a directory that was not a repository at\r\n  all**. An unanchored Settled verdict is a clean zero produced by a filter that cannot express the\r\n  question. A Settled verdict now requires the base object to be present in the reading repo;\r\n  unanchored is UNKNOWN. Sibling of [[zero-match-filter-reads-as-absent]] in the pool domain.\r\n- ⚠ **POLARITY, stated rather than buried:** the new arm (dead holder + unlanded lane => REFUSE)\r\n  converts a false-TAKEOVER into a false-REFUSAL. That is the better failure but not a free one, and\r\n  its triggering case is not exotic — it is an agent going down mid-lane, which happened to hertz\r\n  itself this same batch and cost [[IR-1]]/[[IR-4]]/[[IR-9]] their landing. **The open gating\r\n  question, put to hertz 2026-08-04 and NOT yet answered:** from the refusal state, does\r\n  `pool-release` still clear a claim whose holder is dead and whose lane is unlanded, or does the new\r\n  arm refuse that too? A guard whose only escape is the blanket `SPT_POOL_UNCHECKED=1` trains people\r\n  onto the blanket override. The refusal must NAME the remedy, not only the witness, and the remedy\r\n  must be exercised FROM the refusal state rather than reasoned about ([[remedy-must-run-from-refusal-state]]).\r\n  If the answer is \"it refuses\", that is a design change and returns to doyle before the lane lands.\r\n- **COMMITTED 2026-08-04 (was uncommitted when first measured):** `ci/poolowner-lane-claim` =\r\n  `8ce40d9` (the change) + `98cfafe` (the remedy fix below), both off `b7b00c3`. The original\r\n  measurement found ZERO commits and six modified files in `.worktrees/hertz-poolowner`, i.e. every\r\n  reported number had been measured against a tree no git object captured; the builder committed on\r\n  being told. Recorded because the near-loss is the lesson, not the correction.\r\n- **THE REMEDY DID NOT RUN — measured from the refusal state, which is the only place the question\r\n  can be asked.** The refusal named its witness AND a command, and executing that command verbatim\r\n  failed with the IDENTICAL `SPT_POOL_FOREIGN` block that printed it: **xtask depends on spt-store,\r\n  so every command that builds the tool goes through the pool being refused.** This is the same dead\r\n  end the unclaimed-foreign arm already hit in the field and fixed by leading its line with the\r\n  hatch — adding a second refusal arm re-broke it immediately. FIXED at `98cfafe`: the in-flight\r\n  remedy now leads with the hatch and names `pool-claim`, the command that actually resolves\r\n  ownership. Full chain re-measured on hfenduleam: refuse → verbatim remedy fails → hatch-prefixed\r\n  form succeeds → build proceeds.\r\n- **Answer to \"does `pool-release` clear a dead-holder + unlanded claim\", two-part:** it DOES — it\r\n  never consults the verdict, it rewrites `lane=None` — **but it is NOT the exit**, because after\r\n  release the same build is refused again on the pre-existing unclaimed-foreign arm (\"no lane has\r\n  claimed this pool\"). Release moves you from one refusal to another. `pool-claim` is the exit.\r\n- **The guard is a POPULATION, not a row** (builder's generalization, adopted by doyle as the\r\n  standard for this class): one test poses all three refusal arms and asserts that any remedy naming\r\n  a command leads with the hatch, PLUS membership — three posed, three refused — so no arm passes by\r\n  never being reached. The rule had been learned once already and the next arm added broke it, which\r\n  is the definition of something that needs a population test rather than a better comment. 26/26.\r\n- ⚠⚠ **FLEET PROPERTY — the rig refuted itself, and this is the entry's most important line.** The\r\n  first arm did NOT refuse, it TOOK OVER: the arriving worktree was at `b7b00c3`, so the build script\r\n  that ran was ITS OWN, pre-identity. **Enforcement code comes from the ARRIVING tree, never from\r\n  the claim.** So until this lands everywhere, an old tree still takes a live lane's pool, and the\r\n  guard is only ever as new as the tree that arrives. Found by measurement; reasoning would have\r\n  reported a refusal the rig never produced.\r\n- **RULING on the fleet property (doyle 2026-08-04) — a stamp VERSION LINE is REFUSED, and not on\r\n  taste: it cannot work.** The tree that must refuse is the OLD one, and an old build script does not\r\n  read a new stamp field because it does not know the field exists. You cannot make a stale enforcer\r\n  honor a new rule by writing something new into the record it enforces against — **the reader is\r\n  the problem, not the record.** A version line would help only a CURRENT tree explain itself while\r\n  doing nothing to the population it is aimed at, i.e. it would retire the worry without retiring the\r\n  risk. Ruled instead, in priority order: **(1)** land it and state the migration window honestly —\r\n  the arm protects a lane only when the ARRIVING tree carries the change, coverage grows as trees\r\n  turn over, never retroactive; **(2)** NAME THE LOSS YOU CANNOT PREVENT ([[IR-16]]'s pattern) — the\r\n  claiming side may be able to notice afterwards that its pool was taken and say so loudly, turning\r\n  silent artifact corruption into a named event; scope separately and MEASURE whether the claiming\r\n  side can observe it at all before committing; **(3)** SHRINK THE POPULATION — old enforcers are old\r\n  trees, this box carries ~45 worktrees and most are stale, so reaping them is real mitigation and\r\n  cheaper than code. (2) and (3) do NOT ride this lane.\r\n- **The unanchored row, as asked:** `a_claim_from_another_repository_reads_unknown_not_settled` was\r\n  RED before the base-object requirement existed. Verbatim: `left: Settled { reason: \"lane branch\r\n  build/lane-x no longer exists\" }  right: Unknown`, out of a tempdir that was not a repository at\r\n  all. It fails without the requirement and passes with it — a real negative control, not a row that\r\n  only ever passed.\r\n- **Builder's evidence (as reported, against that uncommitted tree):** spt-poolguard 25/25 with 7 new\r\n  rows, one per precedence cell, two carrying their own negative control; pool_guard_canary 3/3;\r\n  `cargo check -p xtask -p spt-store --all-targets` clean; clippy clean on the three touched crates;\r\n  `traceable-reqs check` exit 0 at 745/745 with new `REQ-POOL-LANE-IDENTITY` complete at doc+impl+unit.\r\n- **Composed:** its OWN thin lane, riding the same next golden batch as the CI-rider cluster but NOT\r\n  merged into it (doyle ruling 2026-08-04). A red must stay attributable: the riders change what the\r\n  pipeline measures, this changes a build-time REFUSAL, and a guard whose failure mode is refusing\r\n  builds is the worst thing to make inseparable from a pipeline change. IR-14's four-trees-into-one-\r\n  unclaimed-pool finding stays OUT of this lane and stays IR-14's, on the same ground [[IR-24]] was\r\n  kept out of [[IR-16]] — folding it in settles its question in passing.\r\n- **Ripe when:** next CI/infra batch, gated on the polarity question above being answered first.\r\n  **Size:** small once the remedy question is settled.\r\n- **FALSE-LIVE, first specimen of the blocking polarity (hertz sweep, measured 2026-08-04):**\r\n  `.worktrees\\hertz-ci-riders\\target\\POOL-OWNER.json` named `holder_pid 31380` with\r\n  `holder_started_at 134302739211259713` = 2026-08-03 16:38:41. Pid 31380 on that box at read time was\r\n  `claude.exe -n \"doyle @ HFENDULEAM (spt-core/)\"`, created 17:31:11, FILETIME 134302770715019370.\r\n  Same boot, ~52 minutes apart, stamps MISMATCH. The claiming process died and the OS reissued its pid\r\n  to the gater's own session. Every previously measured recycle produced a false-DEAD (reads free\r\n  while the lane is live — the corrupting direction); this one produces a **false-LIVE**: a bare-pid\r\n  guard reads the claim as held by a running holder and refuses, naming doyle as the holder of hertz's\r\n  pool — the blocking direction, first time caught. The `holder_started_at` arm shipped in `8ce40d9`\r\n  discriminates it correctly — that field caught defending, not asserted to defend\r\n  ([[stable-anchor-is-not-a-recycling-defense]]).\r\n- **The mirror image, same box, same hour:** `.worktrees\\ir24-reap\\target` named `holder_pid 33612`,\r\n  DEAD — while that lane was genuinely LIVE, with `cargo clippy -q -p spt-daemon --lib --tests`\r\n  (pid 22452) running under todlando's session as it was read. Two claims, opposite errors, inside one\r\n  hour: liveness misreads in BOTH directions on the same box in the same hour. Holder liveness has no\r\n  sound polarity as a lane-state oracle. Ancestry decides ([[pool-claim-holder-death-is-not-lane-state]]).\r\n- **THE BARE-CLAIM GAP — a claim the stamp arm cannot adjudicate at all.** The main checkout's own pool\r\n  (`<root>\\target`, 72,001,016,671 B = 67.06 GiB) carries\r\n  `{\"owner_tree\": \"...\\\\spt-core\", \"written_by\": \"spt-poolguard\"}` — no `lane_label`, no `holder_pid`,\r\n  no `holder_started_at`, no `lane_branch`, no `lane_base`. `read_owner` maps that to `lane: None`, so\r\n  every arm the lane-identity work added is unreachable for it: it cannot be read as in-flight,\r\n  settled, or recycled. **FIVE of the eight** claims found on this box are this shape — `<root>\\target`,\r\n  `<root>\\target-seam` (below), `gate-target-render`, `ir21-xtask\\target`, `locksmith-t1\\target` —\r\n  against three carrying a lane identity (`hertz-ci-riders`, `hertz-poolowner`, `ir24-reap`). A claim\r\n  written by a plain build rather than by `pool-claim` is structurally un-adjudicable, and it is the\r\n  MAJORITY shape in the field. Whatever IR-26 does next has to say what an identity-less claim means —\r\n  \"the stamp arm handles it\" is false for most claims that actually exist.\r\n- **The fifth bare claim was invisible to the first inventory, and the miss is its own lesson:**\r\n  `<root>\\target-seam`, **52.06 GiB**, real dir, gitignored on its own line (`/target-seam`, added\r\n  `5ae68f8`, v0.12.1 era), created 2026-06-18, last written 2026-08-02 — nothing in the tracked tree\r\n  references it (grep over rs/toml/md/yml/ps1/sh: zero hits outside this file). The inventory predicate\r\n  was \"a directory named `target` inside a worktree\"; a second root-level pool under a different name\r\n  is not expressible in that filter, so it returned a clean zero that was reported as a population\r\n  ([[verdict-from-probe-competence]] in the field). Corrects the earlier \"72 GB root pool is the\r\n  biggest object by 9x\": the two root pools are 67.06 + 52.06 = 119.1 GiB of a 133.43 GiB box pool\r\n  total, so the 44-tree sweep covered ~61% of pool bytes, not the population. **Ruling (doyle,\r\n  2026-08-04): target-seam stands for now** — free space is ~115 GB against the 32 GB golden floor, so\r\n  there is no pressure; it was written to yesterday, so \"cold\" is one day deep and its writer is\r\n  unidentified. It becomes a reap candidate at the next free-space squeeze, after a fresh last-write\r\n  check and identification of what wrote it on 08-02 — reaping a pool whose writer you cannot name is\r\n  how the v0.51.0 fabricated-red class starts.\r\n- **CLAIM-OBSERVABILITY, MEASURED (hertz, 2026-08-04, three-arm rig with competence control):** a\r\n  displaced claimant CANNOT distinguish takeover from never-claimed — the two states are byte-identical\r\n  on disk (arm 1 vs arm 2 identical; arm 3 proves the rig separates states that differ, so the null is\r\n  real). The takeover is silent on BOTH sides: the taker's `pool-claim` prints ordinary success naming\r\n  no prior owner. Mechanism at `b75258d`: `pool_claim` never calls `read_owner` — it constructs its own\r\n  `PoolOwner` and `fs::write`s unconditionally. The displaced lane's only channel is its next build's\r\n  refusal, which reports a STATE (\"this pool belongs to B\"), never a transition, and arrives pull-only\r\n  and arbitrarily late while interleaved-artifact harm is already underway. Labelled holes: measured\r\n  against the origin/main xtask binary (lane-tip carry is a source read, not a measurement);\r\n  pool-sweep-as-channel not exercised; single-process holder pid in all arms.\r\n- **Bootstrap property, not a defect (hertz, measured 2026-08-03 while claiming pools for the lanes\r\n  3-4 rebases):** a lane DELIVERING claim-identity cannot claim its own pool WITH that identity until\r\n  it lands — the prebuilt origin/main `xtask.exe` writes old-shaped stamps (owner_tree, lane_label,\r\n  holder pid+stamp; no lane_branch, no lane_base). Enforcer turnover surfacing at CLAIM time rather\r\n  than build time: coverage grows only as trees turn over. Recorded because it reads as a bug the\r\n  first time someone meets it in the field. Related lane-craft fact from the same queue: a rebase\r\n  changes SHAS necessarily but hunk OFFSETS only incidentally — todlando's main.rs hunks stayed at\r\n  @20/@53/@70 across the f2e4516→2f427b2 rebase; treat pre-rebase overlap measurements as stale by\r\n  construction and re-measure, but expect the geometry to usually hold.\r\n- **Bootstrap property FIELD INSTANCE, main checkout (todlando 2026-08-04, IR-12 rig):** the\r\n  prebuilt `target/debug/xtask.exe` in the MAIN checkout pool was stale against main's own source\r\n  at `11169c1` — it printed `(holder pid …, born …)` and wrote a FLAT identity-less claim\r\n  (owner_tree/lane_label/holder_pid/holder_started_at/written_by) where main's source\r\n  (main.rs:2282) prints `(branch …, base …; advisory holder pid …)` and writes the nested lane.\r\n  A lane claimed with a stale tool records NO git identity and demotes its own adjudication back\r\n  to the refused bare-pid predicate. DETECTION that worked and is the reusable part: read the\r\n  claim line the tool PRINTS against the source just read — a mismatch names the stale enforcer\r\n  before it writes. REMEDY at claim time: rebuild xtask FROM THE LANE'S WORKTREE before\r\n  `pool-claim` (which the protocol's claim-from-your-own-worktree rule already implies; this\r\n  instance is why it is load-bearing and not ceremony).\r\n- **RULING (doyle, 2026-08-04) — the claim path must run the same guard the build path runs, and a\r\n  takeover becomes an event.** The documented design already says a finished lane is \"taken over\r\n  loudly, not refused\"; a silent unconditional overwrite violates the spelling the protocol shipped\r\n  under. Remedy, both halves, one small lane: (ii) `pool-claim` reads the prior owner before writing —\r\n  prior lane LIVE (ancestry + stamp arm, never bare pid) ⇒ refuse exactly as build.rs would; prior\r\n  lane finished ⇒ proceed AND announce the displacement, naming the displaced lane in the success\r\n  line; plus (i) a `displaced` field (prior owner + takeover stamp) rides the new claim, so the fact\r\n  survives in the artifact the late-reading claimant already reads. The identity-less bare claim\r\n  (majority field shape, above) must be handled explicitly by the same change: a bare claim carries no\r\n  lane to adjudicate, so takeover of a bare claim always proceeds-and-announces, and the announcement\r\n  names the claim as identity-less — never silently, never refused. Ripe: next CI/infra batch, same\r\n  lane as or beside the IR-26 remedy. Size: small.\r\n\r\n### IR-27 — A junction-pooled rig is TWO objects and teardown only ever removes one\r\n- **Status:** open, found in the wild 2026-08-04 · **Origin:** hertz's 44-tree worktree sweep\r\n  (IR-26 follow-on 3) · **Cross-ref:** [[IR-14]] (unclaimed pools), [[worktree-target-junction]]\r\n…\n\n…\n- **Discipline and receipt.** [Windows ad-hoc rig launch discipline](GOLDEN-CI.md#windows-ad-hoc-rigs-that-outlive-the-tool-call) states the shape, child-owned durable output and post-return PID/birth/output qualification. Preserved harmless-child receipt: `.spt/preserved/hertz-ir137-caller-return/receipt.json`, SHA256 **`e1c9b207544e6313eac5421ebb692786ec18b3a165756b451bff3a704899b178`**. Both valid arms survived under **OMP**, wrote post-return events and exited0; an initial observer-handshake timeout is excluded. All3probe children ended and native handles closed. This does not reproduce the **Claude Code** failure; the host boundary stays explicit. Reopen only for a newly owned callsite or contrary evidence, not to build an unused helper.","startLine":271,"lineNumbers":[271,null,833,834,null,858,null,869,870,871,872,873,874,875,876,877,878,879,880,881,882,883,884,885,886,887,888,889,890,891,892,893,894,895,896,897,898,899,900,901,902,903,904,905,906,907,908,909,910,911,912,913,914,915,916,917,918,919,920,921,922,923,924,925,926,927,928,929,930,931,932,933,934,935,936,937,938,939,940,941,942,943,944,945,946,947,948,949,950,951,952,953,954,955,956,957,958,959,960,961,962,963,964,965,966,967,968,969,970,971,972,973,974,975,976,977,978,979,980,981,982,983,984,985,986,987,988,989,990,991,992,993,994,995,996,997,998,999,1000,1001,1002,1003,1004,1005,1006,1007,1008,1009,1010,1011,1012,1013,1014,1015,1016,1017,1018,1019,1020,1021,1022,1023,1024,1025,1026,1027,1028,1029,1030,1031,1032,1033,1034,1035,1036,1037,1038,1039,1040,1041,1042,1043,1044,1045,1046,1047,1048,1049,1050,1051,1052,1053,1054,1055,1056,1057,1058,1059,1060,1061,1062,1063,1064,1065,1066,1067,1068,1069,1070,1071,1072,1073,1074,1075,1076,1077,1078,1079,1080,1081,1082,1083,1084,1085,1086,1087,1088,1089,1090,1091,1092,1093,1094,1095,1096,1097,1098,1099,1100,1101,1102,1103,1104,1105,1106,1107,1108,1109,1110,1111,1112,1113,1114,1115,1116,1117,1118,1119,1120,1121,1122,1123,1124,1125,1126,1127,1128,1129,1130,1131,1132,1133,1134,1135,1136,1137,1138,1139,1140,1141,1142,1143,1144,1145,1146,1147,1148,1149,1150,1151,1152,1153,1154,1155,1156,1157,1158,1159,1160,1161,1162,1163,1164,1165,1166,1167,1168,1169,1170,1171,1172,1173,1174,1175,1176,1177,1178,1179,1180,1181,1182,1183,1184,1185,1186,1187,1188,1189,1190,1191,1192,1193,1194,1195,1196,1197,1198,1199,1200,1201,1202,1203,1204,1205,1206,1207,1208,1209,1210,1211,1212,1213,1214,1215,1216,1217,1218,1219,1220,1221,1222,1223,1224,1225,1226,1227,1228,1229,1230,1231,1232,1233,1234,1235,1236,1237,1238,1239,1240,1241,1242,1243,1244,1245,1246,1247,1248,1249,1250,1251,1252,1253,1254,1255,1256,1257,1258,1259,1260,1261,1262,1263,1264,1265,1266,1267,1268,1269,1270,1271,1272,1273,1274,1275,1276,1277,1278,1279,1280,1281,1282,1283,1284,1285,1286,1287,1288,1289,1290,1291,1292,1293,1294,1295,1296,1297,1298,1299,1300,1301,1302,1303,1304,1305,1306,1307,1308,1309,1310,1311,1312,1313,1314,1315,1316,1317,1318,1319,1320,1321,1322,1323,1324,1325,1326,1327,1328,1329,1330,1331,1332,1333,1334,1335,1336,1337,1338,1339,1340,1341,1342,1343,1344,1345,1346,1347,1348,1349,1350,1351,1352,1353,1354,1355,1356,1357,1358,1359,1360,1361,1362,1363,1364,1365,1366,1367,1368,1369,1370,1371,1372,1373,1374,1375,1376,1377,1378,1379,1380,1381,1382,1383,1384,1385,1386,1387,1388,1389,1390,1391,1392,1393,1394,1395,1396,1397,1398,1399,1400,1401,1402,1403,1404,1405,1406,1407,1408,1409,1410,1411,1412,1413,1414,1415,1416,1417,1418,1419,1420,1421,1422,1423,1424,1425,1426,1427,1428,1429,1430,1431,1432,1433,1434,1435,1436,1437,1438,1439,1440,1441,1442,1443,1444,1445,1446,1447,1448,1449,1450,1451,1452,1453,1454,1455,1456,1457,1458,1459,1460,1461,1462,1463,1464,1465,1466,1467,1468,1469,1470,1471,1472,1473,1474,1475,1476,1477,1478,1479,1480,1481,1482,1483,1484,1485,1486,1487,1488,1489,1490,1491,1492,1493,1494,1495,1496,1497,1498,1499,1500,1501,1502,1503,1504,1505,1506,1507,1508,1509,1510,1511,1512,1513,1514,1515,1516,1517,1518,1519,1520,1521,1522,1523,1524,1525,1526,1527,1528,1529,1530,1531,1532,1533,1534,1535,1536,1537,1538,1539,1540,1541,1542,1543,1544,1545,1546,1547,1548,1549,1550,1551,1552,1553,1554,1555,1556,1557,1558,1559,1560,1561,1562,1563,1564,1565,1566,1567,1568,1569,1570,1571,1572,1573,1574,1575,1576,1577,1578,1579,1580,1581,1582,1583,1584,1585,1586,1587,1588,1589,1590,1591,1592,1593,1594,1595,1596,1597,1598,1599,1600,1601,1602,1603,1604,1605,1606,1607,1608,1609,1610,1611,1612,1613,1614,1615,1616,1617,1618,1619,1620,1621,1622,1623,1624,1625,1626,1627,1628,1629,1630,1631,1632,1633,1634,1635,1636,1637,1638,1639,1640,1641,1642,1643,1644,1645,1646,1647,1648,1649,1650,1651,1652,1653,1654,1655,1656,1657,1658,1659,1660,1661,1662,1663,1664,1665,1666,1667,1668,1669,1670,1671,1672,1673,1674,1675,1676,1677,1678,1679,1680,1681,1682,1683,1684,1685,1686,1687,1688,1689,1690,1691,1692,1693,1694,1695,1696,1697,1698,1699,1700,1701,1702,1703,1704,1705,1706,1707,1708,1709,1710,1711,1712,1713,1714,1715,1716,1717,1718,1719,1720,1721,1722,1723,1724,1725,1726,1727,1728,1729,1730,1731,1732,1733,1734,1735,1736,1737,1738,1739,1740,1741,1742,1743,1744,1745,1746,1747,1748,1749,1750,1751,1752,1753,1754,1755,1756,1757,1758,1759,1760,1761,1762,1763,1764,1765,1766,1767,1768,1769,1770,1771,1772,1773,1774,1775,1776,1777,1778,1779,1780,1781,1782,1783,1784,1785,1786,1787,1788,1789,1790,1791,1792,1793,1794,1795,1796,1797,1798,1799,1800,1801,1802,1803,1804,1805,1806,1807,1808,null,1839,null,6937]},"fileSize":676479,"meta":{"source":{"type":"path","value":"C:\\Users\\decid\\Documents\\projects\\spt-core\\.worktrees\\hertz-ir86-disk-delta\\docs\\INFRA-REGISTER.md"},"truncation":{"direction":"middle","truncatedBy":"middle","totalLines":951,"totalBytes":83274,"outputLines":432,"outputBytes":40840,"maxBytes":40960,"headRange":{"start":1,"end":219},"tailRange":{"start":740,"end":951},"elidedLines":520,"elidedBytes":42456,"artifactId":"728","nextOffset":1809}}},"isError":false,"timestamp":1789483662415}}
{"type":"message","id":"f836aa13","parentId":"bea905aa","timestamp":"2026-09-15T14:47:42.419Z","message":{"role":"toolResult","toolCallId":"call_jiuAqmEJNWoxC6RAbwlv4MnL|fc_043a862a419f59ae016aa95a8e359087d2bf3df1ec9c0d5c20","toolName":"read","content":[{"type":"text","text":"### IR-45 — twohost rig home premise, SETTLED: pump paths resolve under the per-run TEMP root (rig is disk-hermetic; the \"live fleet roster\" reading is retired)\n- **Status:** RETIRED 2026-08-19 — ask answered by the one code read at main @`78a9a16`; residue\n…\n- **Residue disposition:** (1) #189's third-node evidence was corrected on the board (comment\n…\n\n### IR-46 — the Windows disk-floor preflight asserts an INSTANT; workspace free space moves tens of GB inside the hour, so a green floor is not a claim about run headroom\n- **Status:** open — mechanism CONFIRMED by a measurement series on hfenduleam; doyle ruled it\n  register-shaped 2026-08-18 · **Origin:** deployah, NAMEPLATE #181 golden-head intake, on the\n  run that the floor red-floored · **Filed as IR-46 after an id collision:** this row was authored\n  as IR-42 and held unpushed under the v0.56.0 tag freeze, during which the release-close sweep\n  (`78a9a16`) issued IR-42..45 to other findings. Parallel issuance, not authored disagreement —\n  and noted here so a later reader chasing \"IR-42\" in this row's history does not hunt for a lost\n  version of it.\n- **What/why:** `golden.yml`'s Windows preflight computes `$freeBytes` once at job start and\n  hard-fails under a `32GB` floor. As a fast-fail that is correct and it did its job — it refused\n  before compiling rather than dying deep in a link step. The defect is what a PASS is then read\n  to mean. The reading is a point sample of a quantity that moves by tens of GB unattended, so a\n  green preflight licenses a run whose headroom was never measured. Nothing downstream re-checks.\n- **Evidence — five readings of `C:` free on one box inside roughly one hour, 2026-08-18:**\n  - `03:01:54Z` — `free_bytes=2666205184` (2.48 GiB) against `floor_bytes=34359738368`, the\n    preflight's OWN reading; run `32093894524`, both `n1-gate` and `test` on Windows/hfenduleam\n    failed at this same step, before any compilation.\n  - `~03:2xZ` — ~2.50 GB, independent `Get-PSDrive` read, corroborating the preflight.\n  - pre-reap — **33.70 GB**, immediately before deployah deleted anything.\n  - post-reap-1 — 76.42 GB (42.72 GB reclaimed: `claude_skill_owl/target`, `golden-w1/target`).\n  - pre-reap-2 — **73.81 GB**, i.e. 2.61 GB consumed unattended between the two reaps; then\n    post-reap-2 129.70 GB (55.89 GB reclaimed: `.worktrees/nameplate-w1/target`).\n- **LABELLED HOLE — do not let this harden:** roughly **31 GB was released between the preflight\n  failure and the pre-reap reading by something OTHER than the reclaim**. Released-by-unknown.\n  The runner cleaning its workspace after the job died is *plausible* and is NOT the recorded\n  cause — it was never measured, and no one looked while it was happening. Recorded as a hole on\n  purpose (doyle's explicit ask at filing): a plausible cause written down as the cause would make\n  this row read as explained when the actual mechanism of the 31 GB is unknown.\n- **The hazard this leaves:** a run can clear the floor at preflight and starve mid-build, and\n  mid-build disk starvation does not present as disk — it surfaces as a link failure, a truncated\n  artifact, or a rustc ICE, i.e. as a defect in the tree under test. The failure mode inverts the\n  gate's purpose: the preflight's whole point is to keep box conditions from being read as lane\n  reds, and a passing preflight actively argues the opposite. Note the polarity — this row is\n  about the PASS, not the FAIL. The observed red was honest.\n- **#242/v0.66.0 GOLDEN ADDITIONS (deployah measured 2026-08-29, banked at the 08-30 close\n  sweep):** (i) per-job floor figures are SEPARATE INSTANTS — quote per job, never one figure for\n  both (attempt 1: `test` 26521477120 vs `n1-gate` 26535051264 free bytes, 8s apart, one run);\n  (ii) **CORRECTED TRAP** (retracting deployah's earlier \"attempt-2 hides jobs\" version): the\n  default `/runs/<id>/jobs` endpoint stamps `run_attempt=<current>` on EVERY job including ones\n  that never re-ran (4 of 8 mis-assigned on this run) — it is the RUN's attempt, not the JOB's,\n  so a stale green can read as re-earned; `started_at` is the discriminator and\n  `/runs/<id>/attempts/N/jobs` the authority. Also `rerun --failed` re-runs DEPENDENT jobs\n  (twohost re-ran despite a green attempt 1); (iii) a rerun preflight reads RAW free BYTES with\n  the CI step's own predicate, not display GB; (iv) a rerun green counts as floor-RCA-closing\n  evidence only after a step-level NON-VACUOUS check (checkout SUCCESS + workload steps ran) —\n  the v0.64.0 checkout-SKIPPED shape means a green job can carry zero code signal.\n- **Ripe when:** next `golden.yml` touch. Remedies to weigh THEN, not as a drive-by: re-assert the\n  floor at job END (turns a starvation into a labelled disk verdict instead of a fake lane red);\n  or raise the floor to cover a full build's peak rather than its entry condition; or sample free\n  space across the run and emit the minimum as a token. All three cost run time; none is obvious.\n- **Size:** small in `golden.yml`, load-bearing in what a green run is taken to prove.\n- **Kin:** [[IR-41]] and [[IR-40]] (a state that reads as a clean verdict unless it is labelled —\n  here a PASS that is read as headroom it never measured), [[measure-the-box-before-the-instrument]],\n  [[cancelled-measurement-leaves-labelled-hole]].\n\n- **2026-09-06 addendum (doyle, v0.67.1 close sweep): trigger FIRED at `04e32c8c` — `golden.yml` touched (2-line HEAVY reclass of `brain_resume_conn_deadlock` on the respin) with no remedy weighed. Not a drive-by by choice: the touch rode a respin under a pre-registered hard stop, which is no remedy window. COMPOSED with IR-59 (log-the-floor) + IR-73 (literal-first sites) as one hertz workflow rider on WEBSERVE #272; the remedy weighing happens on THAT lane, before the WEBSERVE golden head.**\n\n<!-- [doc->REQ-CI-FREE-SPACE-PREFLIGHT] -->\n- **2026-09-06 remedy ruling (doyle, WEBSERVE rider):** retain 32 GiB; record raw-byte\n  `FLOOR_START` and `FLOOR_END` PASS/RED tokens per job/runner, each labelled `sample=INSTANT`.\n  End DISK assertions run `if: always()` before teardown, including after failed workloads.\n  A fresh `FLOOR_DOCS` assertion immediately before docs-drift composes with IR-73's second half.\n  Raising the floor is refused without a measured peak; continuous sampling adds lifecycle\n  machinery while remaining blind between samples. Start/end are a dataset, not a minimum or\n  headroom guarantee. Golden execution evidence waits for the WEBSERVE golden head; the thin\n  PR must first show actual START/END output on its own green CI run.\n\n### IR-47 — ci-notify treats a missing co-author trailer as a quiet info line; silent attribution loss reads as \"there was none\"\n- **Status:** open — patch AUTHORED and stashed unlanded since 2026-07-29\n  (`.worktrees/_patches/ci-notify-missing-trailer.patch` + its `test-ci-notify.sh` harness in the\n  sibling `.untracked` dir); surfaced by doyle's 2026-08-19 idle-queue verification of that stash ·\n  **Origin:** the AGENTS.md trailer mandate's own hazard family (the space-spelling trailer is\n  structurally invisible to git's tokenizer, so confident zeros already read as attribution loss\n  once); this row is the NOTIFY-side twin.\n- **What/why:** `.github/ci/ci-notify.sh` parses the head commit for the line-anchored\n  `Co-authored by: <agent>` trailer to add a second notification recipient. When the trailer is\n  absent or unparseable, the current script emits one stdout info line (\"doyle only\") and moves\n  on — correct as a non-fatal outcome, wrong as a SILENT one: a lane that lost its attribution\n  (typo'd trailer, squash that dropped the body, hyphenated spelling) notifies doyle alone on\n  every run and nothing anywhere says an agent stopped being told about their own lane's verdicts.\n  The stashed patch keeps absence non-fatal but promotes it to a `::warning` workflow annotation\n  (visible on the run summary), and splits the legitimate quiet case (co-author IS doyle) from the\n  loss case so the two stop sharing one message.\n- **Evidence:** patch verified 2026-08-19 to still NOT be on main — the warning string is absent\n  from `.github/ci/ci-notify.sh` at the current tree. Patch content re-read at verification; it\n  applies against the script's post-`SEND_BOUND_SECS` shape.\n- **Ripe when:** next `golden.yml`/ci-notify touch — natural co-rider with [[IR-46]]'s remedy\n  window (same file family, same \"weigh then, not drive-by\" rule). The stashed test harness rides\n  with it.\n- **Size:** ~10 lines in one shell script plus its test.\n- **Kin:** [[IR-40]] (an unlabelled state read as a clean verdict — here a quiet info line read as\n  \"no co-author existed\"), the AGENTS.md `%(trailers:)` tokenizer mandate (the sibling silent-zero\n  on the AUDIT side).\n\n### IR-48 — the nextest.toml parity cell tolerates CRLF only by parser accident; a newline-sensitive arm added later reds fresh Windows checkouts alone\n- **Status:** open — filed 2026-08-19 (doyle route, hertz verdict: REGISTER as preventive\n  hardening, not current defect) · **Origin:** sibling sweep after the W3 gate CRLF finding —\n  parent mechanism: `include_str!` embeds working-tree bytes verbatim, `core.autocrlf=true`\n  smudges fresh checkouts CRLF, and the author's never-re-smudged tree stays LF — builder green,\n  every fresh rig/golden checkout red.\n- **What/why:** `crates/xtask/src/main.rs` `the_checked_in_config_is_in_parity` include_str!s\n  `.config/nextest.toml` and feeds `phase_a_overrides_missing_from_ci_windows`. TODAY this is\n  causally CRLF-tolerant — the parser is `str::lines()`+trim (`override_filters`, main.rs:434-440),\n  and the 52/52 fresh-rig green at the hygiene gate (2026-08-19, this box) is therefore causal, not\n  luck. The hazard is the MISSING CONTROL: nothing pins the tolerance, so a future\n  newline-sensitive arm in the parity predicate reds only on fresh Windows checkouts — the\n  builder-green/rig-red inversion, deterministic but reading as flake.\n- **Remedy (hertz's, platform-independent):** feed the parity predicate an LF fixture AND the same\n  fixture converted to CRLF, assert identical missing-sets (including one unmirrored negative), so\n  a newline-sensitive arm reds on EVERY host rather than only fresh Windows checkouts.\n- **Ripe when:** next xtask parity-cell touch; explicitly OUTSIDE the family-B lane (hertz\n  scoping). **Size:** one fixture-pair cell.\n- **Kin:** the W3 gate finding this swept out of (skeleton cells, fixed at the fixture edge in\n  lane commit e99633f); [[IR-40]] (an untested tolerance read as a guarantee).\n\n### IR-49 — poolguard's landed-lane predicate is ancestry-only, so a cherry-picked member lane can never read Settled and its pool can never be taken over\n- **Status:** open — filed 2026-08-19 (todlando measurement at the keystone-w1/fix-197 reap,\n  doyle ruling; doyle re-verified the predicate at source before filing) · **Origin:** todlando's\n  post-landing landed-check used the guard's own predicate and it contradicted the (correct)\n  landed fact — the checker was wrong with the guard, which is exactly how the guard will be\n  wrong alone.\n- **What/why:** `git_lane_state`'s final arm answers Settled/InFlight purely by\n  `merge-base --is-ancestor <lane tip> <integration head>`\n  (`crates/spt-poolguard/src/lib.rs:424-436`, probe at `:474-479`). Under ADR-0050 golden CI\n  (thin member lanes cherry-picked onto a stage branch, ff-only main) a MEMBER lane's own branch\n  tip never becomes an ancestor of main. Measured at origin/main `9ea595c`:\n  `build/keystone-182-w2-sealed-multi` @`ba2d998` and `fix/197-absent-code-uncounted` @`5eb6a3b`\n  both read NOT-ancestor while `git cherry -v` reports every lane commit `-` (already upstream).\n  So `LaneState::Settled` is unreachable for any cherry-pick-assembled member lane whose branch\n  still exists, the takeover arm can never fire, and the pool refuses forever — including with a\n  dead holder. That contradicts the AGENTS.md mandate (\"a merged branch is taken over\") because\n  the guard's notion of merged is ancestry-only and the golden model structurally never produces\n  ancestry for member branches. The branch-vanished (`:391`) and re-pointed (`:399`) arms still\n  fire, and the STAGE lane works (its tip IS an ancestor) — the hole is landed-member-branch-\n  still-exists only. It did not bite at the 2026-08-19 reaps solely because deleting a pool\n  deletes its claim; it bites the first time someone wants to TAKE OVER a landed lane's pool\n  rather than reap it.\n- **Remedy (todlando's candidate, doyle-endorsed direction):** when ancestry answers false, fall\n  back to patch-id containment (`git cherry` / `rev-list --cherry-mark` against the claimed\n  base) before concluding InFlight. **Known residual to state in the fix's docs/tests:** a\n  conflict-adjusted pick changes the patch-id, so such a lane still reads InFlight; its release\n  path is branch deletion (the vanished arm), which is at least reachable. Tests want a\n  cherry-picked-landed fixture plus a conflict-adjusted negative.\n- **Ripe when:** next poolguard touch, or the first landed-lane pool takeover request.\n- **Size:** one fallback arm in `git_lane_state` + two fixtures.\n- **Kin:** [[IR-26]] (dead-holder takeover AUTHORIZED when it shouldn't be — this is the mirror:\n  takeover UNREACHABLE when it should fire), [[IR-42]] (claim writes, build enforces), the\n  AGENTS.md pool mandate this contradicts.\n\n### IR-50 — e2e failure panels read the PRE-REDIRECT stderr capture; every daemon-side diagnostic lands in a sink the rig deletes unread\n- **Status:** CLOSED — BUILT 2026-08-19; adoption-completion lane\n  `docs/ir50-register-close` @`e02f565f` (hertz, doyle-gated 2026-08-20) LANDED in\n  v0.59.0 as a PORTER rider (pick `e702d4b7` tip, main @`c62904e7`; register sweep\n  2026-08-21) — lane `fix/ir50-stderr-sink-census` @`1a2f6a2`+`2ac9543`\n  (hertz; base `0c86b2d`; rides the CONCIERGE #183 chain; these shas are the 2026-08-19\n  message-only reword of `cb4cd9d`+`7336e03` — trees proved identical by tree-id, so every\n  measurement below carries): exported\n  `spt_daemon::stderrlog::sink_path(home)` with `stderr_log_path` routed through it +\n  equality unit; `daemon_stderr_panel` in tests/common renders BOTH channels and labels a\n  read failure with channel + exact looked-at path + OS error (absent-sink regression pins\n  it — the IR-40 unlabelled-absence class was caught at gate and fixed in `2ac9543`);\n  censused every daemon-run captured-stderr panel outside `engine_room_bringup_e2e` (rides\n  #199 lane) and `er_briefing_*` (rides #164 lane); engineroom.rs:145 misnomer rider landed\n  in the same lane. Gate figure 781/781 at `2ac9543` (measured at the pre-reword tree,\n  which is byte-identical; first-report 765 was transcription,\n  corrected with raw line + JSON provenance). CLASS FOLD (doyle ruling, no fresh row):\n  `er_briefing_presented_e2e` hit this exact class during its own authoring (blank panels\n  on a real loud line) and was fixed locally in `72efb6a` reading both channels.\n  **REGISTER CLOSED 2026-08-19:** branch `docs/ir50-register-close` links the\n  golden-tested implementation at `4661bc9d` and completes helper adoption in the five measured\n  residual files: `er_brief_once_per_session_e2e.rs`, `er_briefing_presented_e2e.rs`,\n  `er_sequestered_cwd_e2e.rs`, `endpoint_autostart_e2e.rs`, and `n1_pairing.rs`.\n  `engine_room_bringup_e2e` remains the explicit exclusion, recorded as todlando's direct\n  sink-path read from the #199 lane. ·\n  **Originally filed:** 2026-08-19 (todlando RCA inside the #199 investigation; the immediate\n  four-panel fix in `engine_room_bringup_e2e.rs` is his and rides the #199 lane — THIS entry is\n  the class census, hertz-class) · **Origin:** the #199 evidence void — 40 rca-v2 runs held zero\n  daemon-side evidence for either erhost face; `ENGINE_ROOM_SPAWN_FAIL` (broker.rs:5658) was\n  written to a log the rig destroyed at teardown. Absence discipline honoured: the SUCCESS-path\n  line (`ENGINE_ROOM_BROUGHT_UP`) was also absent from all 40, proving the channel dead rather\n  than the event absent.\n- **What/why:** product `stderrlog::install` (broker at cli.rs:7633, brain at brainproc.rs:200)\n  repoints the process STD_ERROR_HANDLE within its first statements (`redirect_stderr_to`,\n  stderrlog.rs:101 — Windows `SetStdHandle` + `mem::forget`), so a rig's `.stderr(File)` capture\n  holds only the pre-redirect window; from that line on every diagnostic lands in\n  `SPT_HOME/logs/daemon.stderr.log` (stderrlog.rs:34/42) inside the rig's temp home, destroyed\n  unread at teardown. Panels are also mislabelled (\"brain stderr\" holding the broker's first\n  lines). REQ-DAEMON-STDERR-PERSIST fixed this blindness PRODUCT-side (\"the incident-night\n  RCA-blind gap\", cli.rs:7626-7631); no rig was ever taught to read the sink, so the fix does\n  not reach any harness. Class: every e2e rig that spawns `spt daemon run` and prints a\n  captured-stderr panel has the same void.\n- **Remedy:** census all such rigs; failure panels additionally dump\n  `SPT_HOME/logs/daemon.stderr.log` with the path read FROM `spt_daemon::stderrlog` (never\n  re-spelled), and the labels corrected (\"broker stderr (pre-redirect)\" / \"daemon stderr sink\").\n  `engine_room_bringup_e2e.rs`'s panel sites land in the #199 lane (todlando, scoped there —\n  measured shape: FIVE producers incl. the :167 precondition panic, SEVEN print sites, seven\n  relabels; the early \"four\" was an estimate the file refuted). ⚠ Rigs can only import\n  `STDERR_LOG_BASENAME`; the `\"logs\"` dir segment has no exported const, so every rig\n  re-spells it — the census lane should add an exported path helper (e.g.\n  `stderrlog::sink_path(home)`) to spt-daemon FIRST, then consume it everywhere. The census\n  and remainder are hertz-class.\n- **Ripe when:** hertz's queue after current items, or the next e2e red printing an empty\n  stderr panel.\n- **Size:** census + mechanical panel edits per rig.\n- **Kin:** [[IR-40]] (an absent signal read as a clean verdict), REQ-DAEMON-STDERR-PERSIST (the\n  product half of the same incident), [[IR-8]] (a censused zero that cannot see its blind spot).\n\n### IR-51 — engine-room e2e daemon runs NET-ENABLED on real interfaces; rig hermeticity is disk-deep only\n- **Status:** open — filed 2026-08-19 (todlando's x40 run-4 sink read, the first live read any\n  rig has had of the daemon sink; doyle ruled own-id rather than riding #199, at the finder's\n  own request) · **Origin:** unasked-for find inside the #199 instrument's first catch.\n- **What/why:** the rig's temp `SPT_HOME` buys DISK hermeticity ([[IR-45]]'s settlement — which\n  explicitly covered paths, not network) but nothing turns the net off: the run-4 sink shows\n  the rig's own daemon with `BRAIN_NET_CONSUMERS_UP` (dispatcher + peer pump started), three\n  `NET_FAMILY_GATE: binding IPv4-only`, and three `PAIR_MEET_UP:erhome` carrying the box's REAL\n  Tailscale (100.68.35.65) and LAN (192.168.1.81) addresses — live peer work during an e2e —\n  plus an `INBOUND_REACHABILITY` warning whose firewall rule admits the CI-runner's binary path\n  (`C:\\actions-runner\\_work\\spt-bs-core\\spt-bs-core\\target\\debug\\spt.exe`) while this daemon\n  ran from a dev tree. Consequences: test behavior conditioned on shared-box network state;\n  rate-shaped flakes; e2e runs radiating real traffic. SAME SINK, RECORDED NOT DIAGNOSED: conn\n  churn at ~150 ms cadence (327 write-start / 324 transport-close, conn ids past 300 in 58 s) —\n  unattributed. ⚠ CANDIDATE INTERACTION, explicitly NOT established (finder's own framing\n  honoured): the run-4 face (30 s bound blown, zero session events in the window, launch Ok, no\n  error anywhere) matches the SHAPE of the filed offline-but-resolvable-peer pump-stall\n  mechanism (dial does not fast-fail). Discrimination open; nothing here is a #199 attribution.\n- **Remedy:** a rig-honoured net-off switch (peer pump + discovery disabled under test unless\n  the test is ABOUT them) or loopback-only binding; census which e2e rigs start net consumers.\n  Sequencing rule: do NOT fix hermeticity into #199's face before the face is attributed — a\n[…718ln elided…]\n  the boundary: agents keep budgeting IN POOLS (not GB); moving Steam/Downloads (or adding a\n  disk, or pinning golden to a box without operator payload) is an OPERATOR decision this entry\n  exists to put in front of them once, with numbers, instead of re-deriving the floor each cut.\n- **Ripe when:** operator rules on the bulk (move/expand/accept-the-tax), OR the first golden\n  that dies at the 32 GB preflight despite adopted pool discipline (IR-59's LNK1180-class red).\n- **Size:** zero code; one operator decision + at most a runbook line naming the chosen floor.\n\n### IR-65 — kitsubito kernel-audit backpressure: a tailscale-snap AppArmor denial storm + no auditd turned the default audit backlog into a CI-wide stall amplifier (REMEDIATED AT BOX; re-check triggers named)\n\n- **Status:** REMEDIATED-AT-BOX 2026-08-25 (doyle, operator-authorized root — ruling pinned\n  releases#225 comment 5418800776); entry stays OPEN as the re-check record because the storm\n  SOURCE persists and two named events can silently revert the fix.\n- **Mechanism:** `snap.tailscale.tailscaled` (1.92.5) polls /proc and takes an AppArmor\n  ptrace-read DENIED per poll — a continuous kernel-audit record storm scaling with process\n  count (spawn-heavy serialized CI legs amplify their own storm). With NO auditd installed the\n  records rode printk (kauditd throttling) and the 8192 kernel backlog overran\n  (lost=1,537,743); the default `backlog_wait_time` 60000ms turns a full backlog into A 60s\n  SLEEP INSIDE ANY AUDITED SYSCALL — the broker dispatch stall that stretched IR-30's\n  Linux-face race window (see IR-30's Linux-face addendum; deaths clustered 59–63s ↔ this\n  knob's value).\n- **Remediation (verified at the EFFECTIVE layer, not the fragment):** auditd installed +\n  active (storm consumed, backlog drains to 0, lost flat), backlog_limit 32768,\n  backlog_wait_time 0 (full backlog may DROP, never STALL). ⚠ THE TRAP PAID FOR ONCE: the first\n  knob write (`50-backlog.rules`) silently LOST the augenrules merge — apt's own\n  `/etc/audit/rules.d/audit.rules` sorts LAST (digits before letters) and its `-b 8192` /\n  `--backlog_wait_time 60000` won; a whole proof run executed under the defaults while the\n  fragment grepped perfect. Values now live in the merge-WINNING file; verified `auditctl -s`.\n- **Re-check triggers (the reason this entry stays):** (1) tailscale snap update — the plug\n  landscape may change, the storm may stop or grow; (2) auditd package update/reinstall — may\n  rewrite `rules.d/audit.rules` and re-lose the merge; (3) box reimage. On any of these: one\n  `auditctl -s` (expect 32768/0) + one `journalctl -k | grep 'backlog limit'` (expect silence).\n- **Ripe when:** a re-check trigger fires. **Size:** two read-only commands per check.\n\n### IR-66 — first-chunk-needle test class: two latent members remain after the v0.63.0 fix (attach.rs:561, :672)\n\n- **Status:** CLOSED / BUILT — release-close reconciliation 2026-09-11. The WEBSERVE JIT already\n  ruled this satisfied; source at `e5a2fed9` retains both delayed needles. Closure uses the\n  recorded gates below, not v0.69.0's unrelated green receipts. Hertz rider PR #161, landed ff at\n  `d04b922d` (2026-08-27, IO-PARSER #22\n  intake rider). Both members got the later-needle treatment (TICK39 delayed past burst on both\n  OS arms; alt-screen entered before delayed ALT_VIEWPORT_MARKER). Gate: doyle — diff-scope\n  review; Windows isolated worktree 3× TICK39 PASS + clippy + treqs; Linux CLEAN worktree at the\n  PR sha on kitsubito 3× both cells PASS (independent of the builder's dirty-shared-tree proof,\n  disclosure on record). · **Origin:** doyle tree-wide census at `dbe3daad`\n  (releases#225 comment 5418844404 — the census that corrected my own resume.rs-scoped\n  overclaim), after the class's first member was RCA'd and fixed in v0.63.0's head.\n- **Mechanism (cite, not restate):** KNOWN-HAZARDS 6.9 same-session face, amended at\n  `dbe3daad` — `spawn_session_pid`'s Spawned-wait consumes-and-discards a first output chunk\n  that races the reply (~2ms window on a healthy Linux box; load-stretched under backpressure,\n  see IR-30 Linux-face + IR-65). A test whose needle exists ONLY in the child's first chunk\n  asserts winning a race the contract does not promise.\n- **The two members:** `crates/spt-daemon/tests/attach.rs:561` (TICK0..39 instant burst then\n  `cat`; needle TICK39 read directly after spawn — the whole burst can sit in the first\n  chunks) and `:672` `cross_node_cold_attach_to_alt_screen_gets_clean_repaint` (unix-only;\n  `printf '…ALT_VIEWPORT_MARKER'; cat` — needle in the first chunk). Failure shape differs from\n  the fixed member: both children idle on `cat`, so a lost prefix is a HANG killed by nextest's\n  backstop at exactly 240s (slow-timeout 60s × terminate-after 4) — not a natural-life death.\n  Verified NOT in the class: daemon_e2e.rs:209 (needle = echo of post-spawn input), attach.rs:995\n  + brain_swap.rs:170 (attach/replay reads, not spawn-waits).\n- **Fix shape (ruled at the v0.63.0 close):** hertz lane, NEXT intake — the same one-line\n  later-needle / robust-read treatment the resume seed got in `dbe3daad`; deliberately NOT\n  landed mid-r4. Both cells passed r4 (0.010–0.058s) — the members are latent, not failing.\n- **Ripe when:** next milestone intake (hertz test lane) or the first golden red at ~240s on an\n  attach cell — either way the mechanism and fix are pre-derived, triage should cite this entry\n  and skip the RCA. **Size:** two one-line test edits.\n\n### IR-67 — wave-battery gap: a `-p spt --bins` leg compiles bin targets as harnesses and runs ZERO integration/e2e tests, so batteries that lean on it carry silent no-coverage legs\n\n- **Status:** BUILT — remedy applied across the IO-PARSER #22 milestone (2026-08-27/28): every\n  wave battery named explicit `-p spt --test <suite>` e2e legs beside the `--bins` unit leg\n  (GW1..GW5 evidence), every builder evidence report carried a named real e2e per the dispatch\n  template, and the one filter mistake (a `--test` name not matching its file) REFUSED loudly\n  rather than silently skipping — the failure mode this entry exists to kill. Battery template =\n  the dispatch text now carried forward in gate craft.\n- **Was:** OPEN · **Origin:** doyle, banked at the SIGNET #218 gates 2026-08-25 (\"gate\n  battery gap learned\"), filed at this sweep per the standing rule.\n- **Mechanism:** `cargo test/nextest -p spt --bins` builds `[[bin]]` targets as TEST HARNESSES\n  (unit tests inside bins only) — `tests/` integration and e2e suites of the crate NEVER run,\n  and the leg's green output is indistinguishable from coverage. Kin of the two banked pool\n  faces (`--bins` never emits fixture exes; fresh-pool fixture reds) but this face is about the\n  BATTERY TEMPLATE: my SIGNET wave batteries carried a `-p spt --bins` leg believed to cover\n  the crate.\n- **Remedy:** at next intake, the wave-battery template gains an explicit `tests/` leg for the\n  spt crate (nextest `-p spt --test <suites>` or unfiltered `-p spt` where pool history\n  permits), and any battery doc that lists `--bins` as a coverage leg gets the one-line caveat.\n- **Ripe when:** next milestone intake (the battery template is touched at every intake).\n  **Size:** template lines only.\n\n### IR-68 — PSYCHE_INGEST_FAIL cause class unproven: git index.lock did NOT reproduce the ingest failure it was blamed for\n\n- **Status:** OPEN, investigation-shaped · **Origin:** todlando measurement at the W2 int-leg rig\n  (IO-PARSER #22, PR #163 at `769fb0a9`, 2026-08-27), reported measure-first; filed by doyle.\n- **The contradiction:** the six silent `PSYCHE_INGEST_FAIL:todlando` lines observed at the\n  drop-dir probe (2026-08-25) were attributed to shared-checkout git `index.lock` contention. The\n  W2 rig planted NON-EMPTY `index.lock` files in BOTH places git takes one (bare git-dir + every\n  `<git_dir>/worktrees/<name>/`, mirroring `branchstore::sweep_stale_index_locks`, plant count\n  asserted >= 2) — and the ingest COMMITTED ANYWAY (tier write `Written`; `route_slices`\n  propagates `commit_live(...)?`, so a blocked checkpoint would have failed it). Non-empty was\n  deliberate: KH 1.3 reaps only 0-byte locks, and `pulse_tick` runs no boot sweep. So on this\n  store an `index.lock` does not block the checkpoint, and the field incident's mechanism is\n  UNKNOWN, not merely unconfirmed. The rig's doc comment records the attempt; the shipped int leg\n  fails the ingest at the drop READ instead (upstream of the store).\n- **Strongest negative evidence, pinned to the executable rig:**\n  `crates/spt-daemon/tests/commune_io_events_int.rs:95-107` documents that the lock mechanism was\n  tried **first**, planted non-empty locks in both the bare git-dir and every linked-worktree\n  location, asserted that the population was non-empty, and still observed `Written`. Its own\n  sentence is the required scope boundary: “This leg does not claim to reproduce a mechanism it\n  measured as inert.” The working injection is instead drop-file → directory replacement, which\n  fails the upstream read deterministically and proves only the `COMMUNE_FAIL` event contract.\n- **NOT claimed:** that the field incident was misattributed to ingest failure generally — the\n  files did survive with failed-ingest log lines; what is unproven is the index.lock CAUSE.\n- **Ripe when:** next PSYCHE_INGEST_FAIL sighting in the field (capture the failing store state\n  before touching it), or a dedicated probe slot. W2's COMMUNE_FAIL event now pushes a NAMED\n  reason on every failure, so the next occurrence self-reports its cause — read that first.\n  **Size:** investigation; no product change until the mechanism is pinned.\n\n### IR-69 — inherited stderr tokens can tear between format fragments; 26 test consumers parse that surface as structured truth\n\n- **Status:** OPEN for the #243 residual population and anchored-consumer work. The original\n  product remedy LANDED at `ec6da9b0`, as recorded in this entry's later amendment; it is not\n  still parked awaiting assembly. Releases#241 retains its original lane evidence in comment\n  5461613480. This entry is the exposure map and census discipline; residual conversion,\n  generator repair and a SHA-pinned zero recensus remain owed. · **Origin:** CONDUIT #236 r3\n  golden attempt 2,\n  2026-08-29: `endpoint_autostart_e2e` missed its contiguous\n  `ENDPOINT_AUTOSTART:gwauto` keystone although the matching fresh session id proved the replay\n  happened. Attempt 3 was clean on the same discarded SHA after 139 GB was reaped; unequal load\n  makes the pair corroborating, never a rate.\n- **Mechanism, recovered from the literal torn bytes:** two daemon processes inherited one stderr\n  pipe. `BRAIN_UP` and `ENDPOINT_AUTOSTART` are each one `eprintln!`, but `write_fmt` may reach the\n  handle once per format fragment; the per-process stderr lock cannot serialize the other process.\n  The observed interleave split the autostart token between `ENDPOINT_AUTOSTART:` and `gwauto`.\n  This is fragment-level cross-process interleaving, not a failed replay and not a two-thread race.\n- **Durable remedy, ruled product-side:** render a complete diagnostic line into one buffer and\n  issue the complete rendered text, newline included, as **ONE handle call**. An OS short-write\n  may retry the late tail so completeness wins over a silently truncated line; the deterministic\n  property pins application-side fragmentation, not syscall count under that rare retry. It makes\n  no claim that the OS write is atomic on Windows, and no CI re-fire against a 1-of-2 observation\n  may stand in for it. Widening one test's grep is refused: it greens one consumer while every\n  sibling token remains exposed.\n- **Cut-SHA census** (todlando generator, independently hash-verified by hertz), measured from\n  `4d6007ac4ee3d0991f4bc60b7e1a55825aad1aaf` via `git show`, not a dirty worktree:\n  **486 real emitter sites / 383 distinct tokens / 26 consumer test files**. The generator emitted\n  487 site rows, but one is a known phantom: `sealverb.rs:456` is a `format!` inside `map_err`\n  that the four-line lookback attributed to a neighbouring real `eprintln!`. Corrected real emitters\n  by crate: spt-daemon 270, spt 194, spt-runtime 8, spt-live 5, spt-net 5, spt-store 4; by macro:\n  `eprintln!` 484, `println!` 1, `eprint!` 1. `DRIVEN_BY` is the sole stdout row and therefore\n  outside the stderr remedy. A consumer means the test both mentions `TOKEN:` and reads a\n  stderr/log surface; bare-token matching inflated the population to 72 files by admitting prose.\n  This is an **exposure map**, not a rate and not a claim that all 26 have torn.\n- **Artifacts (the preserved raw generator outputs contain 487 site rows):** cut census SHA-256:\n  sites `f10d6bfe5e0399f98945cf63bb5719a01a62e1251be84165c73030fa9bb224f5`,\n  tokens `80b0d1835d9d46376b2f200b1c50be4ca0e185a135168444414255f9308ed92b`,\n  consumers `249a2e33df43a30570ca82b5bd200d8b6e2bf07aa8250fcc8bace47fe23e3cbc`.\n  The sealed sites file's macro column is wrong on 7 of its 487 raw rows; the corrected raw split\n  is `eprintln!` 485 / `println!` 1 / `eprint!` 1. The sealed tokens file has no final newline, so\n  `wc -l` reports 382 although it contains 383 logical records. The sealed files remain unedited;\n  these corrections are textual.\n  Generator `81df82f01ef33a82307920d9804a2394b787ef2ffbe3b41d2d7dda560d9a62a9`\n  was recorded as asserting newline-terminated output, but the sealed tokens artifact refutes that\n  claim for at least one output. Its remaining guards cover logical record counts, a known-positive\n  `SUBSCRIBE_DECISION` sentinel, four-line macro lookback, and truncation only at a\n  `#[cfg(test)]` that opens a module.\n- **Census hazards paid for while constructing and reconciling the population:** the provisional\n  instrument moved `277/243 → 286 → 412 → 487 raw → 486 real` as four silent assumptions were\n  found: same-line matching misses multi-line macros; truncating at the first `#[cfg(test)]` drops\n  later shipping code; lookback must prefer the token line's own macro over a neighbouring arm;\n  and even that lookback can promote a nested token literal beneath a real macro into a phantom\n  second site. A file without a final newline also makes `wc -l` silently undercount logical\n  records by one. Every future census must name its SHA, assert a known member, count records\n  inside the generator, and reconcile emitted rows to real sites.\n- **Separate anchored-matcher finding:** `IDLE`, `DISPATCH`, `BUSY`, and `BOUND` are common words\n  matched as substrings in exposed consumers. One-write emission does not prevent an unrelated log\n  line from satisfying them; those predicates need anchored token matching. Keep this separate from\n  the tear remedy so neither defect is claimed to close the other.\n- **Kin:** [[IR-50]] (the sink must be read before its absence means anything), [[IR-40]] (a\n  confident signal that does not describe the source truth), [[IR-8]] (a plausible census whose\n  blind spot returns a clean answer).\n- **CLOSE-OUT ADDENDUM 2026-08-30 (#242/v0.66.0 sweep — the entry's own close-out re-census RAN\n  and FOUND the predicted blind spot LIVE; entry stays OPEN):** re-census at the landed sha\n  `ec6da9b0` (independent containment-classified meter, reconciled with todlando's independent\n  meter — full write-up `EMISSION-RESIDUAL-CENSUS-FINDING.md`): the generator truncated\n  `crates/spt/src/cli.rs` at its FIRST module-opening `#[cfg(test)]` (line 3007, module closes\n  3164, file runs to 39118) and never scanned the rest — **338 TOKEN-shaped shipping sites remain\n  bare (332 colon-form, i.e. misses under the sealed census's own predicate, + 6 space-form)**,\n  plus `main.rs` 2 sites behind the same mechanism; exactly TWO files tree-wide carry the\n  triggering property (first module-opening cfg(test) precedes shipping code) — the generator\n  fix's owed blind-spot measurement, answered. The census-hazards bullet above already NAMES this\n  third-face truncation hazard; the module-opening fix narrowed the trigger and kept the blind\n  spot for files where a test module CLOSES and shipping resumes — IR-8 shape, predicted by this\n  entry's own text. The shipped #241 conversions are UNAFFECTED (495 removals ≈ censused 486 +\n  space family; the SEEN population is closed; golden green stands). Residual conversion +\n  generator fix + enforcement-at-the-seam = **releases#243** (BACKLOG, operator triages);\n  delivery.rs:149/313 are post-cut MINTS relative to the census sha (todlando's own, settled\n  attribution), deliberately outside #243's census-mechanism scope — and ALREADY CONVERTED: the\n  fix rode his breadcrumb branch (`60a12056`) into the r4 head and shipped IN-TAG (todlando\n  flagged the stale \"his thin lane converts post-cut\" claim 2026-08-30; re-measured — zero bare\n  TOKEN `eprintln!` in delivery.rs at both `d931dd63` and origin/main). No lane is owed for it. Re-runnable meter\n  `EMISSION-RESIDUAL-CENSUS-METER.py` (repo root, untracked; version-control rides #243's lane).\n  **Common-word matcher RULED at this sweep (discharges the \"decide\" clause below):** the four\n  common-word consumers (`IDLE`/`DISPATCH`/`BUSY`/`BOUND` substring predicates) get a SEPARATE\n  hertz test-side rider — anchored token matching is consumer-predicate work, NOT folded into\n  #243 (keeps #243 product-scoped) and not claimed closed by one-write emission; lane-link when\n  hertz's spool drains.\n- **Closes when:** releases#243's residual conversion + generator fix land and a re-census at\n  that sha reads zero shipping residue under both delimiter forms. **Size:** product lane\n  complete elsewhere; register follow-through small.\n\n### IR-70 — a hand-built `IoBus` silently omitted later sinks while every gate stayed green\n\n- **Status:** OPEN, remedy unscheduled; the v0.65.0 respin fixed the witnessed call site on PR #173.\n  This entry owns the recurrence class, not that shipped correction. · **Origin:** releases#234,\n  commit `c5459795167`, CONDUIT #236 respin.\n- **Mechanism:** `publish_commune_io` constructed `IoBus` itself and registered only the sink it\n  knew. `default_bus` already existed as the assembly point and its module contract explicitly says\n  emitters must know only `IoBus::publish`, so adding a later sink costs one registration rather\n  than an emitter sweep. The hand-built publisher recreated exactly the drift that contract warned\n  against: `COMMUNE` and `COMMUNE_FAIL` reached the old sink but never the adapter log, leaving\n  `spt api io-events` permanently short on two documented kinds.\n- **Why the complete battery was green:** the e2e was vacuous on the broken kinds; units synthesized\n  rows without traversing `publish_commune_io`; and traceability checked attached tags, not whether\n  the tagged path exercised the real publisher. Three green instruments shared one blind seam.\n  The respin routed the site through `crate::iobus::default_bus`, and its source comment now records\n  the failure shape.\n- **Durable remedy direction (todlando mechanism, not scheduled):** enforce the assembly point so\n  the next hand-built bus is impossible rather than found — make production publishers obtain the\n  composed bus through one construction API, and gate the real publish path for every documented\n  kind. A search or comment is not enforcement; another emitter can satisfy both while rebuilding\n  a partial sink list.\n- **Kin:** [[IR-39]] (a green fixture never reached the missing dependency), [[IR-37]]\n  (traceability tags prove coverage bookkeeping, not behavioral truth), [[IR-58]] (a hand-built\n  population returns an orderly but incomplete answer).\n- **Ripe when:** the next `IoBus` construction/API touch, or a new sink registration. **Size:**\n  small-to-medium assembly-point enforcement plus a real-path population test.\n\n### IR-71 — controller-seat release has no persisted breadcrumb, so tests cannot distinguish propagation lag from a missing detach\n\n- **Status:** OPEN, observability gap; no remedy scheduled. · **Origin:** CONDUIT #236 r3\n  `er_brief_once_per_session_e2e` intermittent, classified test-side and fixed on PR #174.\n…\n\n\n[Showing lines 1-234 and 953-1193 of 1193; 718 middle lines (62.0KB) elided. Use :3891 to continue. Read artifact://731 for full output. Some lines truncated to 768 chars]"}],"details":{"truncation":{"content":"\r\n### IR-46 — the Windows disk-floor preflight asserts an INSTANT; workspace free space moves tens of GB inside the hour, so a green floor is not a claim about run headroom\r\n- **Status:** open — mechanism CONFIRMED by a measurement series on hfenduleam; doyle ruled it\r\n  register-shaped 2026-08-18 · **Origin:** deployah, NAMEPLATE #181 golden-head intake, on the\r\n  run that the floor red-floored · **Filed as IR-46 after an id collision:** this row was authored\r\n  as IR-42 and held unpushed under the v0.56.0 tag freeze, during which the release-close sweep\r\n  (`78a9a16`) issued IR-42..45 to other findings. Parallel issuance, not authored disagreement —\r\n  and noted here so a later reader chasing \"IR-42\" in this row's history does not hunt for a lost\r\n  version of it.\r\n- **What/why:** `golden.yml`'s Windows preflight computes `$freeBytes` once at job start and\r\n  hard-fails under a `32GB` floor. As a fast-fail that is correct and it did its job — it refused\r\n  before compiling rather than dying deep in a link step. The defect is what a PASS is then read\r\n  to mean. The reading is a point sample of a quantity that moves by tens of GB unattended, so a\r\n  green preflight licenses a run whose headroom was never measured. Nothing downstream re-checks.\r\n- **Evidence — five readings of `C:` free on one box inside roughly one hour, 2026-08-18:**\r\n  - `03:01:54Z` — `free_bytes=2666205184` (2.48 GiB) against `floor_bytes=34359738368`, the\r\n    preflight's OWN reading; run `32093894524`, both `n1-gate` and `test` on Windows/hfenduleam\r\n    failed at this same step, before any compilation.\r\n  - `~03:2xZ` — ~2.50 GB, independent `Get-PSDrive` read, corroborating the preflight.\r\n  - pre-reap — **33.70 GB**, immediately before deployah deleted anything.\r\n  - post-reap-1 — 76.42 GB (42.72 GB reclaimed: `claude_skill_owl/target`, `golden-w1/target`).\r\n  - pre-reap-2 — **73.81 GB**, i.e. 2.61 GB consumed unattended between the two reaps; then\r\n    post-reap-2 129.70 GB (55.89 GB reclaimed: `.worktrees/nameplate-w1/target`).\r\n- **LABELLED HOLE — do not let this harden:** roughly **31 GB was released between the preflight\r\n  failure and the pre-reap reading by something OTHER than the reclaim**. Released-by-unknown.\r\n  The runner cleaning its workspace after the job died is *plausible* and is NOT the recorded\r\n  cause — it was never measured, and no one looked while it was happening. Recorded as a hole on\r\n  purpose (doyle's explicit ask at filing): a plausible cause written down as the cause would make\r\n  this row read as explained when the actual mechanism of the 31 GB is unknown.\r\n- **The hazard this leaves:** a run can clear the floor at preflight and starve mid-build, and\r\n  mid-build disk starvation does not present as disk — it surfaces as a link failure, a truncated\r\n  artifact, or a rustc ICE, i.e. as a defect in the tree under test. The failure mode inverts the\r\n  gate's purpose: the preflight's whole point is to keep box conditions from being read as lane\r\n  reds, and a passing preflight actively argues the opposite. Note the polarity — this row is\r\n  about the PASS, not the FAIL. The observed red was honest.\r\n- **#242/v0.66.0 GOLDEN ADDITIONS (deployah measured 2026-08-29, banked at the 08-30 close\r\n  sweep):** (i) per-job floor figures are SEPARATE INSTANTS — quote per job, never one figure for\r\n  both (attempt 1: `test` 26521477120 vs `n1-gate` 26535051264 free bytes, 8s apart, one run);\r\n  (ii) **CORRECTED TRAP** (retracting deployah's earlier \"attempt-2 hides jobs\" version): the\r\n  default `/runs/<id>/jobs` endpoint stamps `run_attempt=<current>` on EVERY job including ones\r\n  that never re-ran (4 of 8 mis-assigned on this run) — it is the RUN's attempt, not the JOB's,\r\n  so a stale green can read as re-earned; `started_at` is the discriminator and\r\n  `/runs/<id>/attempts/N/jobs` the authority. Also `rerun --failed` re-runs DEPENDENT jobs\r\n  (twohost re-ran despite a green attempt 1); (iii) a rerun preflight reads RAW free BYTES with\r\n  the CI step's own predicate, not display GB; (iv) a rerun green counts as floor-RCA-closing\r\n  evidence only after a step-level NON-VACUOUS check (checkout SUCCESS + workload steps ran) —\r\n  the v0.64.0 checkout-SKIPPED shape means a green job can carry zero code signal.\r\n- **Ripe when:** next `golden.yml` touch. Remedies to weigh THEN, not as a drive-by: re-assert the\r\n  floor at job END (turns a starvation into a labelled disk verdict instead of a fake lane red);\r\n  or raise the floor to cover a full build's peak rather than its entry condition; or sample free\r\n  space across the run and emit the minimum as a token. All three cost run time; none is obvious.\r\n- **Size:** small in `golden.yml`, load-bearing in what a green run is taken to prove.\r\n- **Kin:** [[IR-41]] and [[IR-40]] (a state that reads as a clean verdict unless it is labelled —\r\n  here a PASS that is read as headroom it never measured), [[measure-the-box-before-the-instrument]],\r\n  [[cancelled-measurement-leaves-labelled-hole]].\r\n\r\n- **2026-09-06 addendum (doyle, v0.67.1 close sweep): trigger FIRED at `04e32c8c` — `golden.yml` touched (2-line HEAVY reclass of `brain_resume_conn_deadlock` on the respin) with no remedy weighed. Not a drive-by by choice: the touch rode a respin under a pre-registered hard stop, which is no remedy window. COMPOSED with IR-59 (log-the-floor) + IR-73 (literal-first sites) as one hertz workflow rider on WEBSERVE #272; the remedy weighing happens on THAT lane, before the WEBSERVE golden head.**\r\n\r\n<!-- [doc->REQ-CI-FREE-SPACE-PREFLIGHT] -->\r\n- **2026-09-06 remedy ruling (doyle, WEBSERVE rider):** retain 32 GiB; record raw-byte\r\n  `FLOOR_START` and `FLOOR_END` PASS/RED tokens per job/runner, each labelled `sample=INSTANT`.\r\n  End DISK assertions run `if: always()` before teardown, including after failed workloads.\r\n  A fresh `FLOOR_DOCS` assertion immediately before docs-drift composes with IR-73's second half.\r\n  Raising the floor is refused without a measured peak; continuous sampling adds lifecycle\r\n  machinery while remaining blind between samples. Start/end are a dataset, not a minimum or\r\n  headroom guarantee. Golden execution evidence waits for the WEBSERVE golden head; the thin\r\n  PR must first show actual START/END output on its own green CI run.\r\n\r\n### IR-47 — ci-notify treats a missing co-author trailer as a quiet info line; silent attribution loss reads as \"there was none\"\r\n- **Status:** open — patch AUTHORED and stashed unlanded since 2026-07-29\r\n  (`.worktrees/_patches/ci-notify-missing-trailer.patch` + its `test-ci-notify.sh` harness in the\r\n  sibling `.untracked` dir); surfaced by doyle's 2026-08-19 idle-queue verification of that stash ·\r\n  **Origin:** the AGENTS.md trailer mandate's own hazard family (the space-spelling trailer is\r\n  structurally invisible to git's tokenizer, so confident zeros already read as attribution loss\r\n  once); this row is the NOTIFY-side twin.\r\n- **What/why:** `.github/ci/ci-notify.sh` parses the head commit for the line-anchored\r\n  `Co-authored by: <agent>` trailer to add a second notification recipient. When the trailer is\r\n  absent or unparseable, the current script emits one stdout info line (\"doyle only\") and moves\r\n  on — correct as a non-fatal outcome, wrong as a SILENT one: a lane that lost its attribution\r\n  (typo'd trailer, squash that dropped the body, hyphenated spelling) notifies doyle alone on\r\n  every run and nothing anywhere says an agent stopped being told about their own lane's verdicts.\r\n  The stashed patch keeps absence non-fatal but promotes it to a `::warning` workflow annotation\r\n  (visible on the run summary), and splits the legitimate quiet case (co-author IS doyle) from the\r\n  loss case so the two stop sharing one message.\r\n- **Evidence:** patch verified 2026-08-19 to still NOT be on main — the warning string is absent\r\n  from `.github/ci/ci-notify.sh` at the current tree. Patch content re-read at verification; it\r\n  applies against the script's post-`SEND_BOUND_SECS` shape.\r\n- **Ripe when:** next `golden.yml`/ci-notify touch — natural co-rider with [[IR-46]]'s remedy\r\n  window (same file family, same \"weigh then, not drive-by\" rule). The stashed test harness rides\r\n  with it.\r\n- **Size:** ~10 lines in one shell script plus its test.\r\n- **Kin:** [[IR-40]] (an unlabelled state read as a clean verdict — here a quiet info line read as\r\n  \"no co-author existed\"), the AGENTS.md `%(trailers:)` tokenizer mandate (the sibling silent-zero\r\n  on the AUDIT side).\r\n\r\n### IR-48 — the nextest.toml parity cell tolerates CRLF only by parser accident; a newline-sensitive arm added later reds fresh Windows checkouts alone\r\n- **Status:** open — filed 2026-08-19 (doyle route, hertz verdict: REGISTER as preventive\r\n  hardening, not current defect) · **Origin:** sibling sweep after the W3 gate CRLF finding —\r\n  parent mechanism: `include_str!` embeds working-tree bytes verbatim, `core.autocrlf=true`\r\n  smudges fresh checkouts CRLF, and the author's never-re-smudged tree stays LF — builder green,\r\n  every fresh rig/golden checkout red.\r\n- **What/why:** `crates/xtask/src/main.rs` `the_checked_in_config_is_in_parity` include_str!s\r\n  `.config/nextest.toml` and feeds `phase_a_overrides_missing_from_ci_windows`. TODAY this is\r\n  causally CRLF-tolerant — the parser is `str::lines()`+trim (`override_filters`, main.rs:434-440),\r\n  and the 52/52 fresh-rig green at the hygiene gate (2026-08-19, this box) is therefore causal, not\r\n  luck. The hazard is the MISSING CONTROL: nothing pins the tolerance, so a future\r\n  newline-sensitive arm in the parity predicate reds only on fresh Windows checkouts — the\r\n  builder-green/rig-red inversion, deterministic but reading as flake.\r\n- **Remedy (hertz's, platform-independent):** feed the parity predicate an LF fixture AND the same\r\n  fixture converted to CRLF, assert identical missing-sets (including one unmirrored negative), so\r\n  a newline-sensitive arm reds on EVERY host rather than only fresh Windows checkouts.\r\n- **Ripe when:** next xtask parity-cell touch; explicitly OUTSIDE the family-B lane (hertz\r\n  scoping). **Size:** one fixture-pair cell.\r\n- **Kin:** the W3 gate finding this swept out of (skeleton cells, fixed at the fixture edge in\r\n  lane commit e99633f); [[IR-40]] (an untested tolerance read as a guarantee).\r\n\r\n### IR-49 — poolguard's landed-lane predicate is ancestry-only, so a cherry-picked member lane can never read Settled and its pool can never be taken over\r\n- **Status:** open — filed 2026-08-19 (todlando measurement at the keystone-w1/fix-197 reap,\r\n  doyle ruling; doyle re-verified the predicate at source before filing) · **Origin:** todlando's\r\n  post-landing landed-check used the guard's own predicate and it contradicted the (correct)\r\n  landed fact — the checker was wrong with the guard, which is exactly how the guard will be\r\n  wrong alone.\r\n- **What/why:** `git_lane_state`'s final arm answers Settled/InFlight purely by\r\n  `merge-base --is-ancestor <lane tip> <integration head>`\r\n  (`crates/spt-poolguard/src/lib.rs:424-436`, probe at `:474-479`). Under ADR-0050 golden CI\r\n  (thin member lanes cherry-picked onto a stage branch, ff-only main) a MEMBER lane's own branch\r\n  tip never becomes an ancestor of main. Measured at origin/main `9ea595c`:\r\n  `build/keystone-182-w2-sealed-multi` @`ba2d998` and `fix/197-absent-code-uncounted` @`5eb6a3b`\r\n  both read NOT-ancestor while `git cherry -v` reports every lane commit `-` (already upstream).\r\n  So `LaneState::Settled` is unreachable for any cherry-pick-assembled member lane whose branch\r\n  still exists, the takeover arm can never fire, and the pool refuses forever — including with a\r\n  dead holder. That contradicts the AGENTS.md mandate (\"a merged branch is taken over\") because\r\n  the guard's notion of merged is ancestry-only and the golden model structurally never produces\r\n  ancestry for member branches. The branch-vanished (`:391`) and re-pointed (`:399`) arms still\r\n  fire, and the STAGE lane works (its tip IS an ancestor) — the hole is landed-member-branch-\r\n  still-exists only. It did not bite at the 2026-08-19 reaps solely because deleting a pool\r\n  deletes its claim; it bites the first time someone wants to TAKE OVER a landed lane's pool\r\n  rather than reap it.\r\n- **Remedy (todlando's candidate, doyle-endorsed direction):** when ancestry answers false, fall\r\n  back to patch-id containment (`git cherry` / `rev-list --cherry-mark` against the claimed\r\n  base) before concluding InFlight. **Known residual to state in the fix's docs/tests:** a\r\n  conflict-adjusted pick changes the patch-id, so such a lane still reads InFlight; its release\r\n  path is branch deletion (the vanished arm), which is at least reachable. Tests want a\r\n  cherry-picked-landed fixture plus a conflict-adjusted negative.\r\n- **Ripe when:** next poolguard touch, or the first landed-lane pool takeover request.\r\n- **Size:** one fallback arm in `git_lane_state` + two fixtures.\r\n- **Kin:** [[IR-26]] (dead-holder takeover AUTHORIZED when it shouldn't be — this is the mirror:\r\n  takeover UNREACHABLE when it should fire), [[IR-42]] (claim writes, build enforces), the\r\n  AGENTS.md pool mandate this contradicts.\r\n\r\n### IR-50 — e2e failure panels read the PRE-REDIRECT stderr capture; every daemon-side diagnostic lands in a sink the rig deletes unread\r\n- **Status:** CLOSED — BUILT 2026-08-19; adoption-completion lane\r\n  `docs/ir50-register-close` @`e02f565f` (hertz, doyle-gated 2026-08-20) LANDED in\r\n  v0.59.0 as a PORTER rider (pick `e702d4b7` tip, main @`c62904e7`; register sweep\r\n  2026-08-21) — lane `fix/ir50-stderr-sink-census` @`1a2f6a2`+`2ac9543`\r\n  (hertz; base `0c86b2d`; rides the CONCIERGE #183 chain; these shas are the 2026-08-19\r\n  message-only reword of `cb4cd9d`+`7336e03` — trees proved identical by tree-id, so every\r\n  measurement below carries): exported\r\n  `spt_daemon::stderrlog::sink_path(home)` with `stderr_log_path` routed through it +\r\n  equality unit; `daemon_stderr_panel` in tests/common renders BOTH channels and labels a\r\n  read failure with channel + exact looked-at path + OS error (absent-sink regression pins\r\n  it — the IR-40 unlabelled-absence class was caught at gate and fixed in `2ac9543`);\r\n  censused every daemon-run captured-stderr panel outside `engine_room_bringup_e2e` (rides\r\n  #199 lane) and `er_briefing_*` (rides #164 lane); engineroom.rs:145 misnomer rider landed\r\n  in the same lane. Gate figure 781/781 at `2ac9543` (measured at the pre-reword tree,\r\n  which is byte-identical; first-report 765 was transcription,\r\n  corrected with raw line + JSON provenance). CLASS FOLD (doyle ruling, no fresh row):\r\n  `er_briefing_presented_e2e` hit this exact class during its own authoring (blank panels\r\n  on a real loud line) and was fixed locally in `72efb6a` reading both channels.\r\n  **REGISTER CLOSED 2026-08-19:** branch `docs/ir50-register-close` links the\r\n  golden-tested implementation at `4661bc9d` and completes helper adoption in the five measured\r\n  residual files: `er_brief_once_per_session_e2e.rs`, `er_briefing_presented_e2e.rs`,\r\n  `er_sequestered_cwd_e2e.rs`, `endpoint_autostart_e2e.rs`, and `n1_pairing.rs`.\r\n  `engine_room_bringup_e2e` remains the explicit exclusion, recorded as todlando's direct\r\n  sink-path read from the #199 lane. ·\r\n  **Originally filed:** 2026-08-19 (todlando RCA inside the #199 investigation; the immediate\r\n  four-panel fix in `engine_room_bringup_e2e.rs` is his and rides the #199 lane — THIS entry is\r\n  the class census, hertz-class) · **Origin:** the #199 evidence void — 40 rca-v2 runs held zero\r\n  daemon-side evidence for either erhost face; `ENGINE_ROOM_SPAWN_FAIL` (broker.rs:5658) was\r\n  written to a log the rig destroyed at teardown. Absence discipline honoured: the SUCCESS-path\r\n  line (`ENGINE_ROOM_BROUGHT_UP`) was also absent from all 40, proving the channel dead rather\r\n  than the event absent.\r\n- **What/why:** product `stderrlog::install` (broker at cli.rs:7633, brain at brainproc.rs:200)\r\n  repoints the process STD_ERROR_HANDLE within its first statements (`redirect_stderr_to`,\r\n  stderrlog.rs:101 — Windows `SetStdHandle` + `mem::forget`), so a rig's `.stderr(File)` capture\r\n  holds only the pre-redirect window; from that line on every diagnostic lands in\r\n  `SPT_HOME/logs/daemon.stderr.log` (stderrlog.rs:34/42) inside the rig's temp home, destroyed\r\n  unread at teardown. Panels are also mislabelled (\"brain stderr\" holding the broker's first\r\n  lines). REQ-DAEMON-STDERR-PERSIST fixed this blindness PRODUCT-side (\"the incident-night\r\n  RCA-blind gap\", cli.rs:7626-7631); no rig was ever taught to read the sink, so the fix does\r\n  not reach any harness. Class: every e2e rig that spawns `spt daemon run` and prints a\r\n  captured-stderr panel has the same void.\r\n- **Remedy:** census all such rigs; failure panels additionally dump\r\n  `SPT_HOME/logs/daemon.stderr.log` with the path read FROM `spt_daemon::stderrlog` (never\r\n  re-spelled), and the labels corrected (\"broker stderr (pre-redirect)\" / \"daemon stderr sink\").\r\n  `engine_room_bringup_e2e.rs`'s panel sites land in the #199 lane (todlando, scoped there —\r\n  measured shape: FIVE producers incl. the :167 precondition panic, SEVEN print sites, seven\r\n  relabels; the early \"four\" was an estimate the file refuted). ⚠ Rigs can only import\r\n  `STDERR_LOG_BASENAME`; the `\"logs\"` dir segment has no exported const, so every rig\r\n  re-spells it — the census lane should add an exported path helper (e.g.\r\n  `stderrlog::sink_path(home)`) to spt-daemon FIRST, then consume it everywhere. The census\r\n  and remainder are hertz-class.\r\n- **Ripe when:** hertz's queue after current items, or the next e2e red printing an empty\r\n  stderr panel.\r\n- **Size:** census + mechanical panel edits per rig.\r\n- **Kin:** [[IR-40]] (an absent signal read as a clean verdict), REQ-DAEMON-STDERR-PERSIST (the\r\n  product half of the same incident), [[IR-8]] (a censused zero that cannot see its blind spot).\r\n\r\n### IR-51 — engine-room e2e daemon runs NET-ENABLED on real interfaces; rig hermeticity is disk-deep only\r\n- **Status:** open — filed 2026-08-19 (todlando's x40 run-4 sink read, the first live read any\r\n  rig has had of the daemon sink; doyle ruled own-id rather than riding #199, at the finder's\r\n  own request) · **Origin:** unasked-for find inside the #199 instrument's first catch.\r\n- **What/why:** the rig's temp `SPT_HOME` buys DISK hermeticity ([[IR-45]]'s settlement — which\r\n  explicitly covered paths, not network) but nothing turns the net off: the run-4 sink shows\r\n  the rig's own daemon with `BRAIN_NET_CONSUMERS_UP` (dispatcher + peer pump started), three\r\n  `NET_FAMILY_GATE: binding IPv4-only`, and three `PAIR_MEET_UP:erhome` carrying the box's REAL\r\n  Tailscale (100.68.35.65) and LAN (192.168.1.81) addresses — live peer work during an e2e —\r\n  plus an `INBOUND_REACHABILITY` warning whose firewall rule admits the CI-runner's binary path\r\n  (`C:\\actions-runner\\_work\\spt-bs-core\\spt-bs-core\\target\\debug\\spt.exe`) while this daemon\r\n  ran from a dev tree. Consequences: test behavior conditioned on shared-box network state;\r\n  rate-shaped flakes; e2e runs radiating real traffic. SAME SINK, RECORDED NOT DIAGNOSED: conn\r\n  churn at ~150 ms cadence (327 write-start / 324 transport-close, conn ids past 300 in 58 s) —\r\n  unattributed. ⚠ CANDIDATE INTERACTION, explicitly NOT established (finder's own framing\r\n  honoured): the run-4 face (30 s bound blown, zero session events in the window, launch Ok, no\r\n  error anywhere) matches the SHAPE of the filed offline-but-resolvable-peer pump-stall\r\n  mechanism (dial does not fast-fail). Discrimination open; nothing here is a #199 attribution.\r\n- **Remedy:** a rig-honoured net-off switch (peer pump + discovery disabled under test unless\r\n  the test is ABOUT them) or loopback-only binding; census which e2e rigs start net consumers.\r\n  Sequencing rule: do NOT fix hermeticity into #199's face before the face is attributed — a\r\n  green bought by turning the net off would bury the mechanism unread.\r\n- **Ripe when:** #199 attribution answers whether net state is causal; else the next\r\n  hermeticity pass.\r\n- **Size:** product switch + rig adoption + census.\r\n- **Kin:** [[IR-45]] (the disk half), the subnet-pump dial-does-not-fast-fail mechanism (filed,\r\n  pump-stall RCA), [[IR-38]] (a live daemon's side effects outliving the test's intent),\r\n  releases#125 gc-spin (a conn-churn shape candidate).\r\n\r\n### IR-53 — failed-address expiry unit panics during the first 10m01s after Windows boot\r\n- **Status:** BUILT 2026-08-21 on `fix/ir53-cold-boot-instant` — LANDED in v0.59.0\r\n  (PORTER rider, pick `7b26f28d` on `assembly/porter-205`, main @`c62904e7`; register\r\n  sweep 2026-08-21 at release close) · **Origin:** todlando,\r\n  found and falsifiably measured mid-releases#204; this rider fixes the latent CI-pipeline\r\n  flake before PORTER golden.\r\n- **Measured:** `failedaddr::tests::an_expired_record_stops_matching_and_is_swept` ages an\r\n  `Instant` with `Instant::now().checked_sub(FAILED_ADDR_TTL + 1s).expect(...)`, where\r\n  `FAILED_ADDR_TTL = 600s`. Windows `Instant` counts from boot, so a host younger than 601s\r\n  cannot represent the requested stamp and panics `monotonic clock older than the TTL`.\r\n  Todlando predicted and observed the red before the threshold, then observed the identical\r\n  tree green after it; two subsequent daemon sweeps held 860/860.\r\n- **Remedy:** when the monotonic clock cannot represent the age, return through the loud\r\n  `SKIP_FAILED_ADDR_EXPIRED_SWEEP` arm naming the exact unproved property. On every warm host\r\n  the original direct aging and both expiry assertions still run unchanged; there is no\r\n  ten-minute sleep and no silent pass on the cold arm.\r\n- **Class census (untruncated):** four test-side\r\n  `Instant::now().checked_sub(...TTL/deadline...).expect(...)` patterns total. This cell is\r\n  the sole 601s member. Three siblings remain recorded, not changed in this rider:\r\n  `broker.rs:8432-8434` and `broker.rs:9198-9200` age\r\n  `CONTROLLER_WRITE_DEADLINE + 1s` (6s), while `broker.rs:10385-10388` ages\r\n  `BRAIN_WRITE_DEADLINE + 1s` (16s). Their much narrower cold-boot windows are the same\r\n  mechanism class and should use a controlled clock seam when next touched.\r\n- **Kin:** releases#204 (finder lane), [[IR-25]] (daemon-lib flake population), and\r\n  [[IR-40]] (a confident verdict without the evidence needed to make it).\r\n\r\n### IR-52 — docs-site CLI reference renders SHALLOW; help text below the rendered depth is outside the drift gate, unit-held per-REQ or held by nothing\r\n- **THIRD INSTANCE, observed 2026-08-24 (todlando, WAX-SEAL #21 W4; not acted on):** the new\r\n  `spt api seal verify|describe` FLAGS sit below the generator's rendered depth — the entry's\r\n  exact class. The W4 user page hand-documents them, which is per-page self-defense, not a\r\n  gate. Conditional-rider condition did NOT fire at W4 (no generator touch); the entry's own\r\n  trigger stands for whichever lane next touches the generator.\r\n- **Status:** BUILT 2026-08-24 on SIGNET #218 W1 T6 (todlando; doyle's intake made it the wave's\r\n  rider when the new `seal enroll-authenticator` verb forced the generator touch that armed the\r\n  trigger): `xtask` reference-gen now DESCENDS THE FULL COMMAND TREE recursively (the durable\r\n  remedy), regen published the 22 previously-unrendered leaves + the new section, and a depth\r\n  regression is a drift RED by construction. Self-holding units censused per the remedy: the\r\n  SURFACE-SECTION-SITED walk and both MONIC-TRIGGER-SECTION sited-help units are now DOUBLE-held\r\n  (published surface under the drift gate + content pins kept) — kept, not retired. · **Origin:**\r\n  todlando's #160 build report, fact flagged for the gate rather than folded silently.\r\n  (Pre-build status: open, filed 2026-08-19 — doyle, W3 #160 gate prep; second measured instance\r\n  of a class REQ-CLI-SURFACE-SECTION-SITED's own title already named for its sites.)\r\n- **What/why:** the generated `docs-site/src/cli/reference.md` renders `spt endpoint monic`\r\n  but does not descend to `monic add` / `monic update`, so the #160 strike of the maintained\r\n  kind enumeration at those two flag docs never appeared in the published reference and the\r\n  docs-drift gate CANNOT see the strike — the REQ-CLI-MONIC-TRIGGER-SECTION rendered-help\r\n  unit is the only hold. General mechanism: any help text below the generator's descent\r\n  depth is invisible to the drift gate; a deep help edit (or regression) ships unpublished\r\n  and ungated unless some REQ's unit happens to pin it. First measured instance:\r\n  REQ-CLI-SURFACE-SECTION-SITED names \"the three-deep sites the docs-site drift gate cannot\r\n  reach\" and closes them with its own pinned walk — per-REQ self-defense, not a gate.\r\n  Consequence beyond drift: adapter builders build BLIND from the public docs (DRI\r\n  protocol), so a deep-help divergence hands every adapter a thinner contract than the\r\n  operator's terminal shows.\r\n- **Remedy:** either xtask reference-gen descends the full command tree (deep help becomes\r\n  published surface the drift gate already covers), or a generic rendered-help walk over all\r\n  sites at all depths joins the drift gate; census which REQ units currently self-hold deep\r\n  sites (known: SURFACE-SECTION-SITED walk, MONIC-TRIGGER-SECTION sited-help unit).\r\n- **Ripe when:** next xtask docs-gen touch, or the first adapter filing traceable to a\r\n  deep-help divergence.\r\n- **Size:** xtask render change + regen + census of self-holding units.\r\n- **Kin:** the REQ-CLI-SURFACE-SECTION-SITED pinned walk (the per-REQ closure shape this\r\n  entry generalizes), [[IR-47]] only if its golden.yml/ci-notify surface rides the same\r\n  docs-gate window.\r\n\r\n### CI-RIDER LANE STATE — LANDED 2026-08-04 (post-v0.53.0 merge queue); history below kept for its mechanisms\r\n- **RESOLVED:** the lane rebased clean onto the post-tag queue and landed ff-only as\r\n  `2b33a47`/`2a7b016`/`d63f4ce`/`19d7f79` (content byte-identical to `1275e47..bf8c4a2` by lane-diff\r\n  blob hash). IR-1 and IR-4 are BUILT AND LANDED; IR-9's measurement half is landed with its trigger\r\n  now armed — the toolchain print reports runner-account versions on the NEXT GOLDEN RUN, which is\r\n  when doyle's 2026-08-03 ruling (decide from runner-account versions, never the interactive prior)\r\n  becomes executable. The two golden-only steps (link probe both boxes, toolchain print both legs)\r\n  remain unexercised until that run — the landing does not change that caveat.\r\n- **As recorded pre-landing (2026-08-04, doyle):** `ci/locksmith-riders` was at `bf8c4a2` with FOUR\r\n  commits not contained in `origin/main` and not present in LOCKSMITH's golden head `b7b00c3`. The\r\n  worktree `.worktrees/hertz-ci-riders` was clean, so the work existed and was simply unlanded:\r\n  `1275e47` (xtask: assert a load-bearing patch pin is still in force, both ways it lapses) ·\r\n  `49d4805` (docs/ci: a lock-touching lane reads edges, not just the package set) ·\r\n  `8ed006b` (ci/golden: print the toolchain that judged the run, both legs) ·\r\n  `bf8c4a2` (ci/golden: measure the link before rendezvous, read the floor after the checkout that\r\n  clears it — the floor read AFTER its own reclaim is [[ci-runner-has-no-warm-target]]'s shape).\r\n- **Why it is recorded rather than quietly re-dispatched:** [[IR-1]]/[[IR-4]]/[[IR-9]] were carried\r\n  as DISPATCHED, which is now false in BOTH directions — the work is further along than dispatched,\r\n  and it also did not ship. The cause was the same agent outage that cost `#123` its build, and the\r\n  operator's standing rule from that drop applies here too: an outage must not be able to remove\r\n  work from a batch silently. Board requests got a drop comment; register entries get this.\r\n- **MAPPING CONFIRMED BY ITS BUILDER 2026-08-04, by REQ id rather than by recollection** — hertz\r\n  noted first that its own context had been cleared between building the lane and answering, and\r\n  declined to testify from memory about the original instrument. Everything here is either measured\r\n  that day or read off the commits:\r\n  `1275e47` → `REQ-CI-LOAD-BEARING-PATCH-PIN` ([[IR-4]] part 1, the mechanical pin guard in xtask) ·\r\n  `49d4805` → `REQ-LOCK-TOUCHING-LANE-PROCEDURE` ([[IR-4]] part 2, procedure in docs/GOLDEN-CI.md) ·\r\n  `8ed006b` → `REQ-CI-TOOLCHAIN-VERSION-PRINT` ([[IR-4]] part 3, carrying [[IR-9]]) ·\r\n  `bf8c4a2` → `REQ-CI-LINK-HEALTH-PROBE` ([[IR-1]], the network axis).\r\n- **CORRECTION TO THE GATER'S EARLIER WORDING, from the builder:** `8ed006b` does NOT discharge\r\n  [[IR-9]] — it discharges IR-9's MEASUREMENT half only. IR-9's other half (align the two boxes, or\r\n  declare one authoritative clippy leg) is held by doyle's own 2026-08-03 ruling: decide once the\r\n  step reports RUNNER-ACCOUNT versions, never on the interactive-account prior. IR-9 therefore stays\r\n  OPEN with its trigger now REACHABLE, which is a different state from \"waiting\".\r\n- **Gate evidence, instrument NAMED:** `cargo nextest run -p xtask` in `.worktrees/hertz-ci-riders`\r\n  on hfenduleam, box quiet with no runs in flight — 34 run, 34 passed, 0 skipped. Nextest rather\r\n  than bare `cargo test`, per [[IR-25]]. ⚠ **What that does NOT cover, stated by the builder rather\r\n  than discovered later:** the two golden steps the lane ADDS (link probe on both boxes, toolchain\r\n  print on both legs) cannot be exercised outside a golden run. The probe's three arms\r\n  (five-sample success, no-reply, absent-CLI) were exercised on the real boxes at commit time, and\r\n  that is reported as a CLAIM RECORDED AT COMMIT TIME, not as a re-verification — the kitsubito arm\r\n  could not be re-checked from here. This is why the lane wants a golden rather than a quiet ff.\r\n- **[[IR-5]]/[[IR-6]] CONDITIONAL RIDERS: CONDITION NOT MET — the answer is NO and it closes the\r\n  question for this lane.** Measured file set `6d291e0..bf8c4a2`: `.gitattributes`,\r\n  `.github/bench/link-probe.ps1`, `.github/bench/link-probe.sh`, `.github/workflows/golden.yml`,\r\n  `crates/xtask/src/main.rs`, `crates/xtask/tests/bench_row_parity.rs`, `docs/GOLDEN-CI.md`,\r\n  `traceable-reqs.toml`. Nothing under `.github/ci/`, where the nextest-summary readers and\r\n  count-reporting scripts live. IR-5: no consumer of nextest output touched. IR-6: no EXISTING gate\r\n  output changed — though the NEW output was voluntarily written to IR-6's rule (the LINK line\r\n  prints `samples=N/M` and the individual rtts, membership beside the count, in both shells). That\r\n  SHRINKS IR-6's future scope by two lines; it does not discharge it.\r\n- **Three mechanisms lifted from this lane's REQ titles, worth more than the lane:**\r\n  (a) **An instrument must not be able to RED the run, and each shell breaks that differently** —\r\n  bash: `| head` under `pipefail` SIGPIPEs the producer to 141, so a print step reds (trim with\r\n  parameter expansion instead); pwsh under GitHub's wrapper: a MISSING COMMAND is a terminating\r\n  error, so rustup's absence must be TESTED with `Get-Command`, never caught. One requirement, two\r\n  constructions, and neither is portable reasoning about the other.\r\n  (b) **A negative-control mutation must be COUNTED before it is trusted** — the absent-CLI arm was\r\n  first \"measured\" against a tree where the mutation had not taken, silently re-measuring the\r\n  unmutated arm and reading as a pass.\r\n  (c) **Jitter, not the median, is the signal on a link that mostly works** — the motivating red's\r\n  link ran 10..83ms and 3..75ms while IDLE, so a median-only probe reads healthy straight through\r\n  the failure. Both med and max rows ride the ledger.\r\n- **Disposition:** composes onto the next golden batch as a thin lane, NOT slipped onto main. It\r\n  changes the golden pipeline itself, so it wants a golden rather than a quiet ff — and while\r\n  v0.53.0 is untagged, any push to `main` moves the runbook's bare `git tag` off the tested sha.\r\n\r\n### IR-55 — the `spt --bins` suite wedges partway through on leaked `findstr .` PTY children; the tests at the frontier are casualties, not culprits\r\n\r\n- **Status:** OPEN, **ARMED-FOR-CAPTURE**, owned by **hertz**. Test/rig defect by the dispatch\r\n  split (test/CI rework is never the product builder's). Filed by doyle 2026-08-22 from the\r\n  TURNKEY #212 W3 gate on releases#213.\r\n- **CORRECTED BY REPLACEMENT the same day.** This entry first named\r\n  `cli::tests::adapter_profile_verbs_local_only` as the wedging test, because that is where the\r\n  streamed frontier stopped. **That was wrong, and the correction is the useful part of the\r\n  entry:** run in isolation, on the same pool and binary and with the same env, that test passes\r\n  in **0.02s**. So do the other two the suite later stalled on —\r\n  `cli::tests::shell_channels_relay_sensory_and_text_file` (0.20s) and\r\n  `cli::tests::resolve_proof_target_override_reads_on_disk` (0.00s), each 1 passed / 652 filtered.\r\n  **A frontier names where progress STOPPED, not what CAUSED it.** Naming the last test printed\r\n  is the same error shape as reading a stack frame as a root cause, and it would have sent hertz\r\n  to rewrite three innocent tests.\r\n- **What is actually measured:**\r\n  - `cargo test -p spt --bins` unfiltered sat **24 minutes** at 13.5s CPU — blocked, not spinning.\r\n  - Re-run with `--test-threads=1` and streaming output: stalled after **183** completed.\r\n  - Re-run again with that frontier test skipped: progressed to **335** completed, then stalled\r\n    with **two** tests simultaneously past libtest's 60-second notice. Skipping one casualty\r\n    simply moves the frontier, which is itself evidence the fault is not in any one test.\r\n  - Every wedged harness carried `findstr.exe .` children under `conhost.exe --headless`.\r\n    **`findstr` with no file argument reads STDIN and blocks forever.**\r\n  - The frontier tests are **byte-identical at `c62904e7` and at the #213 tip `3d69f77c`**\r\n    (function bodies hashed at both blobs), so nothing in that lane introduced this.\r\n- **Reading, stated as a reading rather than a conclusion:** an EARLIER test spawns the `findstr`\r\n  stand-in as a PTY child and does not reap it; the children accumulate across the run and a later\r\n  test blocks behind them. Which test leaks is NOT yet identified and this entry does not guess —\r\n  the next step is to bisect for the leaker rather than to touch any test at the frontier. Five\r\n  orphaned `findstr` processes with creation times spread across the day were observed on this box\r\n  independently of any single run, which is consistent with accumulation across many suite runs.\r\n- **Hypothesis RAISED AND NOT SUPPORTED, recorded so nobody re-runs it:** the gate scrubs\r\n  `OWL_SESSION_ID` / `SPT_AGENT_ID` / `SPT_ENDPOINT_ID`, and a scrubbed identity was suspected of\r\n  routing a normally-REFUSED test down a live PTY path. The isolation runs above were performed\r\n  **with the scrub applied** and passed, so the scrub alone does not produce the hang. It remains\r\n  unexplained why the same unfiltered command completed at 652 passed / 1 failed for another agent\r\n  on the same tree; do not treat the scrub as the differentiator without a fresh one-variable run.\r\n- **Why it is register-grade:** golden CI runs the `spt` package. A test that never returns cannot\r\n  red — it consumes the single self-hosted runner slot until the job timeout, which `golden.yml`'s\r\n  50-minute cap bounds rather than fixes. A wedge that fires only sometimes is worse than a red,\r\n  because the suite's green record stays intact and nobody audits it — the same self-concealing\r\n  shape as `exit-code-after-a-pipe-is-the-tails`.\r\n- **Trigger condition (ripe):** any milestone whose gate wants an unfiltered `spt --bins` sweep,\r\n  which is every one of them. Ripe now.\r\n- **REMEDY, MEASURED 2026-08-22 and it changes this entry's urgency:** the same 653 tests under\r\n  `cargo nextest run -p spt --bins --no-fail-fast` complete in **22.2 seconds, 653 passed, 0\r\n  skipped, exit 0** — no slow markers, no timeouts — on the very tree and pool where\r\n  `cargo test -p spt --bins` wedged indefinitely twice. **nextest runs each test in its OWN\r\n  process**, so a leaked `findstr` child can block only itself. This is the discriminating\r\n  measurement rather than a workaround reached for to get a green: **the suite is not broken; the\r\n  SINGLE-PROCESS harness is what lets one test's leaked child wedge every test after it.** Golden\r\n  CI already runs nextest, which is the likely reason this has never surfaced there — the exposure\r\n  is to anyone running bare `cargo test` on the `spt` package, which is every local gate.\r\n- **Count reconciliation, recorded so the figures are not read as a discrepancy:** runs of this\r\n  suite report 652 passed / 1 failed where the one failure is\r\n  `cli::tests::adapter_translate_proof_gates_on_commit` — the `--bins`-only artifact, which\r\n  refuses because `translate_proof_fixture.exe` is not built under a bins-only invocation and says\r\n  so in its own message. Prebuilding it (`cargo build -p spt --bin translate_proof_fixture`) makes\r\n  it pass: 652 + 1 = 653. Prebuild the fixture rather than carrying a known-red through every gate.\r\n- **⚠ AMENDED 2026-08-22 — DO NOT PREBUILD FROM THIS BULLET'S EXAMPLE.** The line above names ONE\r\n  fixture because one fixture is what *this* wedge needed; read as the prebuild recipe it covers a\r\n  fraction of the population, and it was read that way twice on one day. **The census already exists\r\n  in IR-21 above** (`adapters/mock`: mock-session, mock-shell, capture-player, console-mode-probe ·\r\n  `crates/spt-daemon`: dispatch_fixture, service_fixture, summarizer_fixture · `crates/spt`:\r\n  translate_proof_fixture, post_step_fixture, gh_fixture, git_fixture), together with the split that\r\n  matters: **cross-package sites are the hazard members; same-package builds are guaranteed by\r\n  construction.** Field instances, both 2026-08-22 TURNKEY #212 W4: todlando's lane red on three\r\n  `spt-daemon::attach_resize_capture` cells wanting `adapters/mock`'s **capture-player** (a\r\n  cross-package member), and doyle's head gate prebuilding the remembered pair while never running a\r\n  `spt-daemon` or `spt-term` suite at all. **Prebuild `--workspace --bins`, or read the\r\n  `build_hint` the helper already composes** (`crates/spt-term/tests/support/fixture_bin.rs:42`) —\r\n  five test files gate on that panic. Neither of us lacked the census; we prebuilt from memory while\r\n  our own register held the list.\r\n- **FIXTURE PREBUILD, RECURRENCE 2026-08-29 (todlando, emission lane):** the rule was\r\n  already banked AND I am one of its authors, and I still ate three fixture reds in a row —\r\n  mock-session, then capture-player, then mock-shell — each tripping in about 0.01s with a panic\r\n  that reads exactly like a test failure. Having the rule is not the same as applying it completely:\r\n  I prebuilt from RECALL (`-p spt --bins`) rather than from the rule's stronger banked form, and the\r\n  tell is that my fix arrived in three instalments instead of once. **TWO FACES, both structural\r\n  rather than careless.** (1) THE FIXTURE MAY LIVE IN ANOTHER PACKAGE — mock-session,\r\n  capture-player, mock-shell and console-mode-probe are all `adapters/mock` (`-p mock-adapter`), so\r\n  no amount of `-p spt --bins` ever produces them. (2) ENUMERATING FIXTURES BY GREPPING THEIR\r\n  PRE-BUILD STRINGS IS STRUCTURALLY INCOMPLETE — it finds the call sites that embed a literal\r\n  `pre-build: cargo build ...` string and CANNOT find mock-shell, whose helper composes the command\r\n  at runtime (`sibling_bin(name)` → `fixture_package(name)`), so there is no literal to match. A\r\n  predicate over source text cannot see a string the program builds at runtime; same blindness\r\n  class as the emission census's TOKEN-colon-vs-TOKEN-space predicate, met twice in one session.\r\n  **CLASS FIX:** never hand-list fixtures — build the whole fixture package\r\n  (`cargo build -p mock-adapter --bins`) or `--workspace --bins` before any\r\n  `--test`/`--bins`/filtered leg. Chasing named fixtures one red at a time only ever finds them one\r\n  at a time, and each one costs a full battery run.\r\n- **Named negative + settle-class result (hertz, 2026-08-23):** current main at\r\n  `4dd699cb7867979ca0497e7c74d8d0aaf881e9e9` did not reproduce the wedge on HFENDULEAM from\r\n  isolated checkout `.worktrees/ir55-findstr-bisect`. Test binaries were freshly built before the\r\n  diagnostic population and reused for the settle sweep; the gate environment scrub was **not**\r\n  applied; the installed daemon was live. The fleet snapshot taken immediately **after**, not\r\n  during, the sweep showed BIGNET 7 nodes / 20 endpoints, SPT_MANTLE 3 / 19, SPT_DEV 2 / 19,\r\n  3-of-7 peers connected, `degraded-partial`. Four startup cells that spawn `findstr` passed alone\r\n  and reaped their observed ConPTY children; a full single-threaded run passed 663/663 with a\r\n  before/after census delta of `IR55_NEW=0`. The ratified settle-class sweep then ran five\r\n  consecutive bare `cargo test -p spt --bins` invocations: all 663/663 green in 420.35s total,\r\n  with zero `findstr.exe` residents before and after. This is a named negative data point, not a\r\n  discharge of the intermittent filing-day measurements.\r\n- **Next-wedge capture protocol — do not improvise or clean first:** preserve the exact bare\r\n  invocation and snapshot the environment (box, checkout SHA/worktree, fresh-versus-reused test\r\n  binary provenance, gate-scrub state, live-daemon state, and fleet roster); stream test output to\r\n  durable storage so the last started and completed test names identify the frontier; census\r\n  `Win32_Process` immediately before the run and again while wedged, recording each `findstr.exe`\r\n  PID, parent PID, creation time, executable path, and command line. **Do not kill any child before\r\n  the second census is banked.** The 22 residents found during the 2026-08-23 investigation were\r\n  path-verified as `C:\\Windows\\System32\\findstr.exe`, shown to predate its live runs, banked, then\r\n  reaped; the pre-sweep and post-sweep resident counts were both zero.\r\n- **Size guess:** small if one test is missing a reap or an EOF for its stand-in child; medium if\r\n  the shared PTY test scaffolding needs the reap, in which case every sibling spawning the same\r\n  stand-in wants it. The RUN-LEVEL exposure has an answer today (nextest); the LEAK itself is\r\n  still worth fixing, because a leaked child per run accumulates on any box that runs the suite.\r\n- **Gater's craft, worth more than the entry itself:**\r\n  (a) The first wedge was undiagnosable because the gate script wrote every leg as\r\n  `cargo test … | tail -N > file` — nothing reaches disk until the command completes, so a wedged\r\n  leg produces an **empty file** and the process table is the only witness. **Stream to a file and\r\n  tail the FILE.**\r\n  (b) To NAME a frontier, run `--test-threads=1`: libtest prints each test's name BEFORE running\r\n  it, so the last incomplete line is where progress stopped.\r\n  (c) **Then prove the frontier test is actually at fault by running it alone** — which is the\r\n  step this entry originally skipped, and the one that turned a wrong entry into a right one.\r\n\r\n### IR-56 — `pool-claim` harvests lane identity from CWD, not from `--pool`; a claim run from the wrong tree writes a WRONG RECORD with a success message\r\n\r\n- **Status:** BUILT 2026-08-24 for the SIGNET #218 golden batch on\r\n  `fix/ir56-pool-claim-cwd`, owned by **hertz**. Tooling/rig defect by the dispatch split. Filed by\r\n  doyle 2026-08-22 from todlando's TURNKEY #212 W4 Lane 1 field instance — the first confirmation\r\n  of the IR-42 mechanism from a LANE rather than from a source read.\r\n- **What happens:** `cargo run -p xtask -- pool-claim --pool <dir> --label <lane>` records the lane\r\n  identity it harvests from the **current working directory** — `owner_tree`, `lane_branch`, and the\r\n  base sha — not from the tree `--pool` names. Run it from the project root with `--pool` aimed at a\r\n  worktree and the record reads `owner_tree = <project root>, lane_branch = <root's branch>` while\r\n  every artifact in that pool belongs to the worktree. The verb prints its ordinary success line\r\n  naming the wrong owner, and returns 0.\r\n- **Why it is silent, which is the whole entry:** the claim verb WRITES and never adjudicates\r\n  (IR-42) — every enforcement arm lives in `crates/spt-store/build.rs` and speaks only at the next\r\n  BUILD. So a wrong record has no symptom at the moment it is created; the first signal is a build\r\n  refusal minutes later, on a lane whose `--pool` argument was correct all along. **`--pool` being\r\n  correct is not evidence the record is.** Nothing on the command line shows you cwd, which is the\r\n  one input that decided the outcome.\r\n- **Recovery is the documented hatch, and the bootstrap is why:** the claim tool builds THROUGH the\r\n  pool it is claiming, so a pool already refusing cannot be re-claimed by the ordinary route. The\r\n  refusal text says so itself — meaning the bootstrap case is known, and a wrong-cwd claim is the\r\n  ordinary way a lane lands in it.\r\n- **The rule, as a must-do:** claim from the lane's own worktree so the identity the verb harvests\r\n  is the lane's — `( cd <lane> && cargo run -p xtask -- pool-claim --pool \"$PWD/target\" … )`, or any\r\n  form that makes cwd explicit. Then READ THE PRINTED RECORD BACK and confirm `owner_tree` and\r\n  `branch` name the lane: the success line carries the record, so the check costs nothing.\r\n- **Trigger condition:** ripe now — it is a doc/UX fix on a verb we run every lane. Ripest alongside\r\n  any other `xtask` pool-verb touch.\r\n- **Size guess:** small. Either make the verb REFUSE when cwd is not inside the tree containing\r\n  `--pool` (loud, and it cannot be wrong), or print the harvested identity as a distinct confirmed\r\n  line. The refusing form is preferred: it removes the reading step rather than adding one.\r\n- **Built evidence, corrected at review:** `pool-claim` resolves the git worktree containing\r\n  `--pool` from the pool's nearest existing ancestor and compares it with the cwd worktree before\r\n  writing. An accidental cross-worktree call returns 2, names both worktrees and the remedy, and\r\n  leaves the not-yet-existing pool absent. The sanctioned sequential takeover carries an explicit\r\n  `--foreign-pool`, says that it is harvesting the arriving cwd identity, writes that identity, and\r\n  returns 0. Both poolguard refusal remedies now print that flag. An executable xtask test drives\r\n  both arms against two real temporary git repositories, pinning VERB-ADMITS-REMEDY rather than\r\n  merely testing path equality. This remains identity-harvest validation only: the claim still\r\n  writes without adjudicating admission, so IR-42's enforcement boundary remains in the build.\r\n\r\n- **Second instance 2026-09-11 (todlando, #304 product lane):** an allocation packet carried the\r\n  claim as `pool-claim --pool .worktrees/304-product/target` — correct from the repo root, WRONG\r\n  from inside the worktree, where it resolves to a nested `.worktrees/...` path. Caught within\r\n  seconds of launch, nothing written at the nested path, re-run with the absolute lane path. Rule:\r\n  an allocation names the pool by ABSOLUTE path, because the claim verb acts on where it stands.\r\n\r\n### IR-57 — an assembly pick's conflict resolution can silently DROP lines, and every gate run at assembly time is blind to it\r\n\r\n- **Status:** OPEN, owned by **doyle** (gater craft, not a code defect — no lane to dispatch).\r\n  Filed 2026-08-22 from doyle's own defect on the TURNKEY #212 assembly head.\r\n- **What happened:** assembly head `5cce533d` **did not compile**, and was carried across a session\r\n  boundary as a ready head with \"treqs exit 0\" attached to it. `crates/spt-store/src/access.rs` had\r\n  an unclosed `mod tests`: the cherry-pick of the #206 lane commit `b2194aa9` conflicted against the\r\n  #209 test block — both add functions to the same region, and the two sides share the trailing\r\n  `);` / `}` / `}` — and the resolution deleted the markers without restoring the FIRST side's\r\n  function closer. Exactly two lines lost: `        );` and `    }`.\r\n- **Every instrument in the assembly path reported success:** `git cherry-pick` completed with no\r\n  conflict remaining; `traceable-reqs check` returned 797/797, 0 findings, exit 0 — **it parses\r\n  tags and never invokes the compiler**; and the lanes themselves were green and stayed provably\r\n  clean (the #206 lane's brace balance is correct at all five of its commits). **Lane-green plus\r\n  conflict-free is not a claim about the assembled head.** Same lesson as the #182 v2 assembly\r\n  (`E0425`×4) by a different mechanism: that one was a semantic composition break between two\r\n  correct hunks, this one is a fidelity LOSS during resolution.\r\n- **Two must-dos, both cheap:**\r\n  1. **Compile the assembled head before it is handed anywhere — including forward to your own next\r\n     session.** A head is not ready on a treqs exit; it is ready on a build. Any sentence carrying a\r\n     head sha to another agent must name the instrument that proved it.\r\n  2. **Audit pick fidelity on CHANGED LINES for every pick on the chain**, not just the one that\r\n     tripped you: hash `git show --format= <sha> | grep -E '^[+-]' | grep -vE '^(\\+\\+\\+|---)'` for\r\n     the lane source and for the pick, and compare. Whole-diff comparison is useless here — hunk\r\n     headers and context legitimately drift once the head's copy of the file has moved.\r\n- **Read COUNT and HASH together, because they fail in opposite directions.** Of 24 picks on this\r\n  chain two did not match. `b2194aa9 → 4d6deed1` differed in COUNT (302 lane / 300 pick by the header-excluding pipeline above; **this entry originally cited 310/308, which is the RAW `^[+-]` count INCLUDING the 8 `+++`/`---` header lines of its 4 files** — the figures were taken without the second grep the entry itself prescribes. The DELTA is 2 under either meter, which is why the wrong figures never surfaced: they supported a correct conclusion, so nothing pressed them. Corrected todlando 2026-08-29, measured both ways in-tree) — the real\r\n  defect. `f27f15c6 → 5865cc98` had the SAME count and a different HASH — benign: a `CONTEXT.md`\r\n  paragraph the head had already amended for #209, whose merged result correctly carries both lanes'\r\n  sentences. A count check MISSES the first class entirely; a hash check FLAGS the second as if it\r\n  were a defect. Neither alone classifies a pick.\r\n- **Repair shape used, recorded because it is the cheap one:** reset to the commit before the bad\r\n  pick, re-pick the lane source, resolve the same conflict correctly, then replay the remaining picks\r\n  in chain order with the fidelity check on each. Verify the repair changed nothing else with a\r\n  WHOLE-TREE diff against the old head — it must show exactly the restored lines and no other file.\r\n  Where a later pick re-conflicts, check its pre-pick blobs against the old chain\r\n  (`git rev-parse <old-pick>~1:<file>`); if they match, the old chain's post-pick blob is a\r\n  transferable, already-reviewed resolution.\r\n- **AND GATE THE REPAIR'S OWN SUBJECT.** The rebuilt head passed six legs — clippy `-D warnings`,\r\n  sweep 660/660, treqs 803/803, xtask OK — while the restored lines live in `spt-store`, whose LIB\r\n  tests `-p spt --bins` never runs. Six greens, and not one executed the function the repair\r\n  restored; it was proven to COMPILE and assumed to PASS. Proven afterwards by name (4/4) and by the\r\n  full `spt-store --lib` suite (519/519). **A repair's gate must include the suite that owns the\r\n  repaired file**, which is not necessarily the suite the head gate runs.\r\n- **FIRST LIVE CATCH, and it was the author's own resolution (2026-08-29, one hour after the verb landed):** rebasing the IR-59 rider over the IR-57 rider produced four conflicts — three additive keep-both, one usage line both sides had edited. `xtask pick-audit` read the rebase as **LOSS, 282 lane / 280 pick**. The two missing lines were a `[[requirements]]` header and its blank line in `traceable-reqs.toml`, so `id = REQ-DISK-FLOOR-PREFLIGHT` landed INSIDE the previous table as a duplicate key: **`traceable-reqs check` exit 2, the registry unparseable, every reading after that edit checking nothing**. Restored, the same audit reads **DRIFT 282/282** whose one differing line is the usage string whose base copy legitimately gained the other verb — both verdi…\n- **FIRST REAL-ASSEMBLY USE (2026-08-29, #241 emission head, ASM-241-GATE-VERDICT.md):** `xtask\r\n  pick-audit --range 57a0d27c..HEAD --lane 4d6007ac..d0fdd58d` over 6 picks — **5 MATCH\r\n  (digest-identical), 1 LOSS, 0 drift, 0 unclassified**, exit 1 forcing the accounting. The LOSS\r\n  was exactly the one human-resolved conflict (`cfb9d9f8 <- 10f12e4c`, count 432/402), and the\r\n  delta RECONCILED to the resolution rather than assumed: lane stat 15 files/235+/197- vs pick\r\n  14 files/205+/197-, difference byte-for-byte the deliberately-dropped 30-line interim IR-69\r\n  register block superseded by main's consolidated entry. No false positives, no silent pass.\r\n  Entry stays OPEN as living procedure; both live uses (the rebase catch above, this assembly)\r\n  produced the verdict classes in the order the entry predicts.\r\n- **Trigger condition:** ripe at the next assembly — this is procedure, and its cost is one command\r\n  per pick.\r\n- **Size guess:** small as a scripted check in `xtask` (fidelity audit over a pick range); zero as\r\n  discipline, which is how it is being applied now.\r\n\r\n### IR-58 — a `[[bin]]` grep is not a census: cargo AUTODISCOVERS `src/bin/*.rs` targets, and a hand-built bin list produced a confident false \"this bin does not exist\"\r\n\r\n- **Status:** OPEN, unowned. Filed by doyle 2026-08-22; **its original filing was WRONG and is\r\n  retracted in full below.** The entry is kept because the way it was wrong is the finding.\r\n- **RETRACTED CLAIM, stated plainly so no reader acts on it:** this entry first said that\r\n  `crates/spt/Cargo.toml:18-21` and `crates/spt/src/cli.rs:30355` forbid a bin-name collision with\r\n  `xlate_choreo_fixture`, \"a bin that does not exist\", and that spt-daemon's third helper had been\r\n  renamed to `summarizer_fixture`. **`xlate_choreo_fixture` EXISTS** — at\r\n  `crates/spt-daemon/src/bin/xlate_choreo_fixture.rs`, verified at the assembly head. The collision\r\n  rule's counterpart is real, both prose sites are CORRECT, and IR-21's original table row was\r\n  correct too; it merely predated `summarizer_fixture`. Nothing in that prose needs fixing.\r\n- **How the false claim was produced, which is the entry:** the census was built by grepping\r\n  `^\\[\\[bin\\]\\]` across `Cargo.toml`s. **Cargo AUTODISCOVERS `src/bin/*.rs` as bin targets with no\r\n  stanza at all**, so a stanza grep cannot see them, and it fails SILENTLY — it returns a clean,\r\n  well-formed list that is simply short. From that list it read as established fact that a named bin\r\n  had been renamed away, and that \"fact\" was then written into a register table, an IR entry, and a\r\n  message to the builder. **A pattern-built population encodes the pattern's assumption; the count\r\n  looks like a census and is a property of the pattern.**\r\n  (Found by todlando, resolving one of doyle's figures against his own tree under the pointer rule.)\r\n- **A CENSUS IS ALSO A PROPERTY OF A TREE.** Stanza counts differed legitimately across trees the\r\n  same hour — 13 at the assembly head, 11 at `dc1c7532` — because `summarizer_fixture` exists at one\r\n  and not the other. Two correct censuses of the same workspace disagree unless each names its sha.\r\n- **The must-do, and it removes the list rather than lengthening it:** never hand-maintain a bin\r\n  roster. Run `cargo build --workspace --bins` and let cargo enumerate its own targets — the same\r\n  enumeration the test harness resolves against, so it cannot drift from what a fixture lookup\r\n  expects. Stanza-derived lists, remembered pairs, and register tables are all the roster problem at\r\n  different depths; only cargo's own enumeration is the population.\r\n- **Kin:** IR-55's amended prebuild bullet (prebuild the census, not a remembered pair) and IR-42\r\n  (a verb that writes without adjudicating). The shared shape is an instrument returning an orderly\r\n  answer about a set it never fully saw.\r\n- **Trigger condition:** ripe on any `xtask` check work — a duplicate-bin-name check over cargo's\r\n  target enumeration (NOT over manifest stanzas) is a handful of lines and cannot go stale.\r\n- **Size guess:** small. The prose fix originally proposed here is WITHDRAWN — there was nothing\r\n  wrong with the prose.\r\n\r\n### IR-59 — pool arithmetic: this box holds TWO cold pools, not four; and a build that exhausts the volume reds as a LINKER defect that names no disk\r\n\r\n- **Status:** OPEN, unowned — it is arithmetic and discipline, not a code lane. Filed by doyle\r\n  2026-08-22 from a live disk-floor abort during the TURNKEY #212 W4 gate; footprint figures measured\r\n  by todlando the same hour.\r\n- **v0.69.0 release close, 2026-09-11 (deployah, source record releases#294 comment\r\n  5628538587):** the first broad version/manifest battery failed to LINK (`LNK1180`,\r\n  `LNK1108`, cargo exit 101), with **15,777,792 bytes free** measured at recovery. It produced\r\n  no test verdict. The run selected the workspace's test binaries on the Cargo side even\r\n  though the nextest filter did not need the e2e population; the replacement selected `--lib`\r\n  for `spt-daemon`, `spt-runtime`, `spt`, and `xtask`, and passed **121/121** in 8.445 s.\r\n  Root-target reclamation restored **66,926,968,832 bytes free**; the subsequent CI Windows\r\n  unit step passed **3167 tests**, then its END floor refused at **15,360,114,688 bytes**\r\n  against **34,359,738,368**. That is an observed resource-red AFTER passing tests, not an\r\n  explanation of the earlier PR unit-step red whose log was unavailable. A second, classified\r\n  CI `target/debug` reap, with runner intake stopped by the operator, increased free bytes\r\n  **14,892,281,856 -> 78,994,501,632**. Runner service restored afterward. Publication used a\r\n  preserved signer, not a Cargo rebuild into the cleared pool. These are two measured recoveries,\r\n  not a durable capacity fix; IR-46/59/86 remain the next gate-driver capacity rider.\r\n- **SECOND FACE, measured 2026-08-23/24 (WAX-SEAL #21 W2 gate, doyle — the violator this time):**\r\n  both predicted mechanisms fired at once, WITHOUT the floor guard because the gate legs ran as a\r\n  plain script. (1) doyle minted a THIRD cold pool (gate rig) while todlando's lane pool was LIVE —\r\n  the two-pool arithmetic, violated by the gater. (2) The lane pool had silently accumulated\r\n  **104.8 GB** over repeated full-workspace sweeps (nothing bounds or even measures a pool's\r\n  accumulation until the volume dies). The volume hit **3 MB free**; the reds wore exactly the\r\n  entry's predicted costume — `LNK1318: Unexpected PDB error; LIMIT (12)` naming no disk — plus a\r\n  second face worth keeping: `traceable-reqs check` died as a PANIC printing to stdout\r\n  (`os error 112`), so a REGISTRY gate red can also be the disk's. Both gate verdicts VOIDED\r\n  (clippy's full compile had exited 0 before space died — the code was never the question).\r\n  Recovery measured: gate pool reap 9.6 GB, lane pool clean 100.2 GB, drive back to 109.6 GB free.\r\n  **Remedies adopted at the incident:** the gate never mints its own pool while a builder lane is\r\n  live on the box — it takes the lane pool over SEQUENTIALLY at pool-release (warm, loud, the\r\n  releases#103 pattern); and gate/lane scripts get the disk-floor preflight the golden runner\r\n  already carries (this entry's part 2, still unbuilt).\r\n- **THIRD FACE, measured 2026-08-24 (WAX-SEAL #21 golden window, doyle):** two new mechanisms, both\r\n  about the REMEDY rather than the red. (1) The wax-seal-w1 lane pool **re-accumulated to 152–169 GB\r\n  (two meters, IR-46 caveat) within ONE DAY of the 08-23 clean** and rode the volume back down to\r\n  4.92 GB free — a reap is an instant, not a state; nothing yet bounds a pool between reaps.\r\n  (2) **The remedy itself arrived garbled through relay:** the golden push was held \"waiting on the\r\n  IR-59 reboot\" when this entry prescribes no reboot anywhere — tens of releases have shipped without\r\n  one; the operator refused the premise and the register's own recorded remedy (reap finished-lane\r\n  pools) cleared it in ten minutes. A remedy relayed as a DIFFERENT remedy is the relay trap wearing\r\n  infra clothes: the entry is the author — read it before adopting a hold. Recovery measured: five\r\n  finished-lane pools reaped after ancestry classification (`git cherry` catches rebased lands that\r\n  a plain `merge-base --is-ancestor` calls unlanded — gate-w4l1's 90.9 GB pool was reapable only by\r\n  that meter), 4.92 → 260.88 GB free (~256 GB free-delta vs ~270–287 GB sum-of-lengths). Two main\r\n  runs red inside the low-disk window (09:17Z/09:41Z) were re-run, not re-read, per this entry's\r\n  must-do.\r\n- **FOURTH FACE, measured 2026-08-24 same day (SIGNET #218 W2 gate, doyle — the gater's own pool\r\n  this time):** the MAIN pool went **13.7 GB → 158.3 GB in ONE DAY** absorbing four full gate\r\n  batteries across two lane tips, and dragged the volume to **18 GB free mid-gate** — so the\r\n  entry's mechanism is not a lane-pool problem, it is EVERY pool under repeated full sweeps, the\r\n  gate rig included. Two riders worth the ink: (1) the golden runner's **free-space floor step\r\n  produced its first live catch** — a thin CI leg refused at 14:14 local over exactly this window\r\n  with zero test signal, and the register's re-run-not-re-read rule resolved it in one command;\r\n  (2) the reap-and-rebuild trade (\"cleaning a live pool buys one window at rebuild price\") was\r\n  taken deliberately mid-gate and cost ~35 minutes cold — cheaper than one uninterpretable red.\r\n  A red measured at 18 GB free in this gate got NO read at all, and the next sweep's red was a\r\n  DIFFERENT test: low disk manufactures random victims before it manufactures link errors.\r\n- **The event:** a gate's preflight refused with `GATE_ABORTED_DISK_FLOOR` at **4.75 GB free on a\r\n  1863 GB volume**. Four cold pools plus the milestone head's pool were standing at once. The floor\r\n  guard did its job — without it a full workspace build would have started with under 5 GB of\r\n  headroom and produced a red belonging to nothing.\r\n- **THE ARITHMETIC, and it corrects the intuition that worktrees are the cost.** Measured across the\r\n  whole `.worktrees` tree: **45 worktrees = 0.79 GB total** (~18 MB each). **3 pools = 130.45 GB.**\r\n  Worktrees are **0.6%** of the footprint; pools are **99.4%**. **One cold pool is worth roughly 2,500\r\n  worktrees.** A rule keyed on worktree count would cost a day of `git worktree remove` work for under\r\n  a gigabyte, risk removing a lane someone still wants, and leave the lever untouched.\r\n- **THE CEILING, as arithmetic rather than hygiene:** at **45–75 GB per cold pool** on this workspace\r\n  against a **40 GB floor**, this box supports **TWO live pools comfortably, THREE only if one is\r\n  small**. The two rules that already exist need no replacement, only this number attached:\r\n  - **Reap a pool when its lane is finished** → 45–75 GB back immediately.\r\n  - **Do not run two builds at once** → not only the contention argument, but **75–150 GB of\r\n    simultaneous allocation** against that floor.\r\n- **A FULL VOLUME REDS AS A LINKER DEFECT.** `LINK: fatal error LNK1318: Unexpected PDB error`\r\n  (variously `OK (0)` or `LIMIT (12)`), often beside `LNK4209: debugging information corrupt`. It\r\n  reads as a corrupt artifact or a broken toolchain and is neither — it is the linker unable to grow\r\n  a large `.pdb`. **Nothing in the failure text says \"disk\".** Do not key recognition on the\r\n  parenthesised code; it varies.\r\n- **THE DANGER WINDOW IS THE TAIL OF A COLD BUILD, not a steady state you can check once.** The\r\n  2026-08-22 instance died at the link of `spt` — the last and largest artifact of a **74 GB** cold\r\n  pool — while that same build was draining the volume out from under itself. A free-space reading\r\n  taken before the build would have looked fine.\r\n- **Positive tell, with its own refutation attached:** `traceable-reqs check` alone surviving a leg\r\n  table is suggestive, because it is the only leg that never links. It is a POSITIVE tell ONLY — a\r\n  full disk can red before any link step, so the signature's ABSENCE clears nothing.\r\n- **THE FALSIFIER IS FREE SPACE AT THE TIME OF THE RUN**, not the shape of the leg table.\r\n- **Must-do, both cheap:**\r\n  1. **A free-space reading goes in the FIRST LINE of any build-failure report** — not in the\r\n     controls, not as a follow-up. Two agents spent hours on a mechanism for this failure and neither\r\n     ran `df`; the falsifier was one command away throughout.\r\n  2. **Rig and gate logs should record free space at run start.** Today they do not, which makes \"was\r\n     the disk full\" **unanswerable after the fact for every red already in hand**. Any red produced\r\n     under ~1 GB free is UNINTERPRETABLE and must be **re-run, not re-read**.\r\n- **Measurement caveat, observed twice in one hour:** sum-of-file-lengths and free-space delta\r\n  disagree by several percent when anything else on the box is writing (98.07 GB of subtrees → 92.25\r\n  GB reclaimed; 47.28 GB → 40.81 GB). Report BOTH, derive neither from the other, and treat any single\r\n  free-space number as an instant rather than headroom — see IR-46.\r\n- **FIFTH FACE, measured 2026-08-29 at the CONDUIT #236/v0.65.0 cut (deployah):**\r\n  the finished milestone's sequential lane-sharing accumulated **140.51 GB**, while a freshly\r\n  rebuilt pool measured **7.78 GB** — about **18× one build's working set** retained across lane\r\n  hand-offs with no reap between them. This is the budgetable rate behind that cut's disk-floor\r\n  red: sequential execution prevents concurrent ownership corruption, but it does not bound\r\n  historical artifacts inside the shared pool. Treat takeover and reclamation as separate\r\n  operations; a pool may be safe to reuse and still be too large to keep.\r\n- **SEVENTH FACE, measured 2026-08-30 (v0.67.0 milestone close — the PARALLEL-LANE fill\r\n  rate):** the #23 wave arc drove C: from ~240 GB free to **0.01 GB in ~3.5 hours**: four\r\n  concurrent/serial lane+gate pools totalled **236.6 GB** (ns23-w1 87.7 + ns23-113 72.3 +\r\n  gate rig 57.3 + ns23-w3 19.1) — effectively the entire ir57 reclaim re-consumed inside one\r\n  milestone's build window. The head gate and two thin-CI runs redded with the entry's exact\r\n  costume (\"could not compile\" + treqs panic, zero disk words) at 0.01 GB and all re-earned\r\n  green after reclaim (+186.6 GB, finished-lane targets only, single-actor rule held under\r\n  racing consent). Budget rule this face adds: a MULTI-WAVE milestone on one box books\r\n  ~60-90 GB PER LANE-PLUS-GATE cycle, so the pool budget is per-wave, not per-milestone —\r\n  reap each wave's pool at its LAND, not at the milestone party (the party inherited only\r\n  ~58 GB because the emergency had already forced the other ~179).\r\n- **SIXTH FACE, measured 2026-08-30 (#242 golden r4, Windows test job, LNK1318 at the PDB\r\n  write):** the floor is asserted ONCE at job START, but the job's internal LOW-WATER sits at its\r\n  LAST heavy step — the docs-drift build, ~28 minutes in. r4's floor read 65.1 GiB honest at\r\n  23:07; the box was at ~37–39 GB by the 23:35 link failure. LNK1318 on PDB write = this entry's\r\n  documented low-disk costume; the incremental-corruption candidate was retired by preservation\r\n  snapshot (no xtask state existed at failure). **Durable fix = a floor RE-READ (or reclaim)\r\n  immediately before the docs-drift build** — the WITHIN-job sibling of the across-job\r\n  read-after-checkout fix, rides the next workflow commit. Riders: incremental hygiene as\r\n  disk-pressure maintenance (the dir measured 4.56 GB), and the box's **~51 GB non-recovering\r\n  post-run consumption** is this entry's pool-weight face — classify at the IR-14/26/27/49 audit\r\n  slot (composed this sweep).\r\n- **Composed for next intake (doyle, v0.65.0 close):** the still-open log-the-floor build half\r\n  rides with [[IR-57]]'s scripted pick-fidelity audit as the next milestone's two tooling riders.\r\n- **Trigger condition:** ripe now for the log-the-floor half (it rides any gate-script or CI touch);\r\n  the arithmetic is discipline and applies immediately.\r\n- **Size guess:** small — one line in each rig/gate preflight to record free space alongside the\r\n  existing floor check.\r\n\r\n### IR-60 — a wrapper that CAPTURES a leg's exit status ends with the capture, so the wrapper's own status is the capture's, not the leg's\r\n\r\n- **Status:** OPEN, unowned — script-shape discipline, not a code lane. Filed by doyle 2026-08-22\r\n  during the TURNKEY #212 W5 lane; mechanism measured by todlando, who reported it first as a\r\n  possible harness misreport and then RETRACTED that reading himself on a minimal probe.\r\n- **v0.69.0 recurrence, 2026-09-11 (deployah, own withdrawal):** `NEXTEST_EXIT=0` and the task\r\n  completion's exit 0 both described the wrapper/truncation path, not Cargo's **101**.\r\n  `PIPESTATUS` was read outside the executing subshell, so the named verdict measured `tail`.\r\n  Both green-looking receipts were withdrawn; the raw failed-link output was retained.\r\n  **An exit FILE alone is insufficient if its writer captures the wrong process.** Capture\r\n  immediately inside the shell executing the producer, before any other command replaces the\r\n  status, write that value to the leg's file, and propagate it when wrapper status is reported.\r\n  The replacement battery's own file read 0, with 121 tests actually run. Keep this entry OPEN:\r\n  corrected execution of one driver does not make the faulty wrapper shape unreachable.\r\n- **The reading that started it:** a background leg was summarised as `exit code 0` while the leg's\r\n  own exit file read `100`. Reported as-is, that is a task runner lying about a red — the worst\r\n  possible direction for a purposeful-red claim, since it would turn two reds that DID fire into two\r\n  reds reported as not having fired.\r\n- **The measurement, minimal and on this box:**\r\n\r\n      ( exit 100 ); echo $? > probe.exit; FINAL=$?\r\n      leg status captured to file : 100\r\n      wrapper's own final status  : 0\r\n\r\n  The wrapper's shape is `( cd <lane> && cargo nextest ... > leg.raw 2>&1 ); echo $? > leg.exit`.\r\n  **The last command is the `echo`, which succeeds**, so the wrapper genuinely exits 0 while the leg\r\n  genuinely exited 100. THE RUNNER TOLD THE TRUTH ABOUT THE WRAPPER. There is nothing to file against\r\n  the task runner, and it would have been filed.\r\n- **The class, and this is why it is worth an entry rather than a fix:** it is the truncation-pipe\r\n  family — the meter measured something real, it just was not the thing about to be quoted. **Three\r\n  shapes now share ONE trigger, and the trigger is not \"is this a pipe\":**\r\n  1. a truncation pipe (`cmd | tail`, `cmd | head`) — `$?` measures the truncator, and `head` closing\r\n     the pipe can MANUFACTURE a status (SIGPIPE → 101), so `PIPESTATUS` is not protection either;\r\n  2. a flattened `$?` read after any intervening command;\r\n  3. **a wrapper whose last command is the capture itself.**\r\n  **The trigger in all three is the REPORTING** — every instance happened while trimming or capturing\r\n  output in order to QUOTE it as evidence.\r\n- **The practice that held, and the one to keep:** the leg's own file is the leg's verdict. Both reds\r\n  were real, and the only reason that was knowable is that every leg wrote its exit to its own file\r\n  rather than to the wrapper's status.\r\n- **Remedy, in preference order:** (1) never read a wrapper's status as a leg's — read the leg's exit\r\n  FILE, which the per-leg rule already requires; (2) if a wrapper's own status must be meaningful,\r\n  end it by re-raising the captured status (`exit \"$(cat leg.exit)\"`) or set the status before the\r\n  capture is the last word; (3) for anything that becomes evidence, redirect to a file and read the\r\n  file.\r\n- **Trigger condition:** ripe now — it rides the next gate-script touch, and the gate scripts in this\r\n  milestone already write per-leg exit files, which is what makes this discipline rather than debt.\r\n- **Size guess:** small — a convention line in the gate-script preamble; no product code.\r\n\r\n### IR-61 — spacerun's test-module skip carries a SECOND literal tracker; the two answers can drift, and today only a cell stands between them\r\n\r\n- **Status:** OPEN, unowned, accepted-with-mitigation. Filed by doyle 2026-08-22 at the TURNKEY #212\r\n  head gate, as the named residual of the latch repair (the repair itself rides the milestone).\r\n- **What the debt is.** `crates/xtask/src/spacerun.rs` now skips a column-0 `#[cfg(test)]` module by\r\n  BRACE DEPTH and resumes after its close, rather than latching the scan to end-of-file. Counting\r\n  braces safely means knowing when a brace is inside a string, a raw string or a char literal — and\r\n  the scanner ALREADY tracks literals for its rendering pass. It does not reuse that tracking. There\r\n  are now TWO answers in one file to \"am I inside a literal\", and **two answers to one question is a\r\n  disagreement waiting for a reader who fixes one of them.**\r\n- **Why it was accepted rather than refactored on the spot, stated so the trade is auditable:** the\r\n  two trackers answer genuinely different questions — the rendering walk is PER LINE and forward\r\n  from an opening quote (\"where does this literal start and end\"), while the skip needs \"am I inside\r\n  a literal right now\" carried CONTINUOUSLY across lines. Unifying them is a real refactor of a check\r\n  that is already gated, already carries five fixed defects, and sits on the tree being handed to\r\n  golden. The narrow change with an OBSERVABLE failure mode beat the correct-shaped change with a\r\n  wide blast radius, on that tree, on that day.\r\n- **The mitigation, and its exact limit.** Three brace cells fail the moment the two trackers\r\n  disagree about a raw string, a normal string or a char literal, plus a cell that reds when the skip\r\n  stops consulting a literal tracker at all (`match lit` -> `match Lit::None`). **That is a cell\r\n  standing in for a refactor.** It catches drift in the three forms it names and nothing else — a\r\n  fourth literal form, or a change to only one tracker in a form neither cell covers, passes.\r\n- **The general shape, which is why this is a register entry rather than a comment:** a check whose\r\n  own correctness depends on a second implementation of a thing it already implements is one\r\n  refactor away from the defect class it exists to prevent. This same file has already produced\r\n  three instrument defects (an indented-marker latch, a column-0 latch, and a suppression that\r\n  decided what got PARSED rather than what got REPORTED). The pattern is not carelessness; it is a\r\n  scanner accumulating special cases.\r\n- **Trigger condition:** the next SUBSTANTIVE change to spacerun's scanning — any new skip, any new\r\n  literal form, any change to either tracker. At that point unify, rather than adding a third answer.\r\n- **Size guess:** small to medium — one continuous literal-state walk serving both the render pass\r\n  and the skip, with the existing corpus and brace cells as the regression net.\r\n\r\n### IR-62 — an e2e daemon binds well-known ports and collides with the resident fleet on shared runners\r\n\r\nFiled 2026-08-23 (doyle), from the #212 r2 golden's Windows Phase A red — one witnessed\r\ninstance, mechanism verified from the run's own capture, filed on the mechanism per the\r\nregister's standard.\r\n\r\n**Mechanism.** `endpoint_autostart_e2e::saved_endpoint_replays_on_daemon_restart` failed its\r\nown PRECONDITION (\"daemon B must come up with a fresh brain\") because daemon B's broker came up\r\ndegraded: `NODE_KEY_FAIL: identity unavailable` (net-less broker, no retry) and\r\n`DOCS_SERVER_BIND_FAIL` port 5474 `os error 10048` — the docs port was held by a CO-RESIDENT\r\ndaemon. HFENDULEAM is live infra: the resident fleet's daemon legitimately holds well-known\r\nports, and any e2e that brings up a daemon with default port bindings is in a race with it BY\r\nCONSTRUCTION. An isolated SPT_HOME isolates the store and broker socket, NOT globally-numbered\r\nTCP ports.\r\n\r\n**Classification history.** r2: red (35.4s, precondition panic). Run 1 and r3 on the same box:\r\ngreen. Folded into r3 under a pre-registered predicate (reds twice → dedicated triage); it\r\ngreened, so this stays an environment-shaped intermittent, NOT a product defect and NOT\r\nclosed — the collision window is real and will re-fire under the right co-residence timing.\r\n\r\n**Remedy direction (not built).** Test daemons should bind ephemeral/rig-scoped ports for\r\nevery advisory surface (the docs server is advisory — a bind failure should degrade the rig\r\nloudly, not poison an unrelated cell's precondition), or the precondition should name the\r\nport-collision cause distinctly so the red self-classifies. Either lane is test/CI work\r\n(hertz's), triggered the next time this class fires anywhere.\r\n\r\n**Kin.** IR-51 (e2e daemon net-enabled on real interfaces — hermeticity is disk-deep only);\r\nthe known not-ours red classes list in the #212 hand-off.\r\n\r\n**BUILT 2026-08-24 (hertz, SIGNET #218 batch; PR #158).** The class fired its second witnessed\r\ninstance the same day — doyle's W2 gate rig, `engine_room_bringup_e2e` precondition panic with\r\nthe IR-50 panel naming `DOCS_SERVER_BIND_FAIL` port 5474 `os error 10048` — which armed this\r\nentry's own trigger. Hertz repro'd deterministically (held the port; brain still reached\r\nBRAIN_UP), pre-ranked three mechanisms before probing, and built the ephemeral-advisory form:\r\nrig-only `SPT_TEST_EPHEMERAL_ADVISORY_PORTS=1` makes the daemon's docs listener bind port 0\r\n(production config/`SPT_DOCS_PORT`/docs-url untouched; the flag matches the literal \"1\" only).\r\nThe golden workflow's test job sets it globally on both self-hosted legs, the standalone ER rig\r\nsets it too. Scope note kept honest per his own ranking: the docs collision is retired; if a\r\nco-diagnostic bind elsewhere still poisons a precondition, that is a residual face of THIS\r\nentry, not a closed question.\r\n\r\n### IR-63 — suite-mix sweeps leak job-escaped autostart daemons that LOCK the pool's spt.exe; and the same box conditions manufacture one random victim per sweep\r\n\r\n- **Status:** OPEN, mitigated-by-rig-step — the reap is adopted discipline, not yet construction.\r\n  Filed by doyle 2026-08-24 at the SIGNET #218 gates; first measured by todlando the same day\r\n  (his W1 build: four reap rounds of 2, 8, 1, 1 processes, count-by-path stated each round).\r\n- **Mechanism, two faces of one condition:** (1) e2e sweeps that exercise autostart leave\r\n  job-escaped daemons running `target/debug/spt.exe`; the NEXT build or `xtask check` then dies\r\n  on `os error 5` removing the exe — a rig red wearing a build defect's clothes. nextest's own\r\n  `leaky` flags corroborate (4–8 per sweep measured). (2) The same co-residence (leaked daemons +\r\n  resident fleet + runner traffic) manufactures ONE red per full sweep with a DIFFERENT victim\r\n  each time: doyle's W2 gate measured FOUR distinct one-off victims in four same-sha sweeps\r\n  (ER bringup, composite+bootstrap pair under CI load, resident_service, brain_resume), every\r\n  one green alone and/or in a sibling sweep. The e2e-leaked-daemons rule holds: a different test\r\n  dying each run on one sha is ONE environment cause, and hardening members never closes it.\r\n- **Mitigation adopted (rig step, both todlando's lanes and doyle's gate runner):** reap\r\n  `spt.exe` BY PATH (`*spt-core\\target*`) before EVERY cargo invocation and after every sweep;\r\n  report the count each time so a zero is a claim, not silence.\r\n- **Remedy direction (unbuilt):** the durable form is construction, not discipline — either\r\n  nextest wrap/xtask verb that performs the by-path reap as a pre-step on this box's rigs, or\r\n  autostart e2es gain teardown that provably outlives job escape (kin IR-38's built wedge-namer,\r\n  IR-62's ephemeral ports which retire one collision axis, IR-35's victim-rate ledger).\r\n- **THIRD FACE, measured 2026-08-30 (doyle, ir57/asm-241 reaps):** the leaked population is not\r\n  only daemons — battery legs leave ORPHANED HEADLESS `conhost.exe` processes whose CWD sits in\r\n  the worktree's `crates/spt-daemon` (where the leg ran), and a CWD pin blocks `Remove-Item`/\r\n  `git worktree remove` on the whole tree with \"being used by another process\" naming the DIR.\r\n  This is the mechanism behind every recent \"handle-pinned, retry later\" worktree removal: 31\r\n  such conhosts found at once (Aug 26–29 vintages) pinning FIVE dead worktrees. cargo/rustc\r\n  absence does NOT clear the suspect list — the conhost outlives its client. Holder census\r\n  tool: a ~30-line NtQueryInformationProcess CWD probe (PEB→ProcessParameters→CurrentDirectory)\r\n  over all pids, filtered on the path — names every holder in one pass where no handle.exe\r\n  exists. 13 killed scoped to the two consented reaps; 18 remain pinning gate-w1-a8f04aff (12),\r\n  io-parser-w1 (5), gate-w1-786d2381 (1 after kills) — sweep them at the IR-14/26/27/49 audit\r\n  slot before those removals.\r\n- **LANE-LINKED 2026-08-30 (#242 close sweep):** hertz's queued daemon-leak fixup lane carries\r\n  this entry (brief cites IR-7/17/20/34/35/63); leaves the register when that lane lands.\r\n- **Trigger condition:** next rig/gate-script construction touch, or the first golden red that\r\n  classifies to face (1).\r\n- **Size guess:** small-medium — one wrapper seam plus adopting it in the gate/lane scripts.\r\n\r\n### IR-64 — HFENDULEAM's disk floor is set by non-CI bulk: ~845 GB of operator payload leaves the golden box ~2 GB of slack against its own 32 GB preflight\r\n\r\n- **Status:** OPEN · **Origin:** doyle, v0.63.0 close sweep 2026-08-26; mechanism first measured\r\n  at the FIELD-SEAL golden window (deployah's IR-31 fifth addendum carries the POOL side of the\r\n  same event by agreed division — this entry is the OTHER reservoir, deliberately not his).\r\n- **Mechanism:** the 1.86 TB C: carries ~614 GB Steam + ~230 GB Downloads (operator payload, not\r\n  CI state). With that floor fixed, normal lane traffic alone walks the box under the 32 GB\r\n  golden preflight — a full-sweep pool WEIGHS ~90–112 GB steady state (IR-59's measurement) and\r\n  five FIELD-SEAL lanes cost 148.48 GB (IR-31 fifth addendum), so ONE milestone's pools exceed\r\n  the entire free margin. Reaping buys windows, not headroom: deployah measured free fall\r\n  167 → 108 GB within hours of his reap, ~59 GB re-consumed by lane builds. The recurring shape:\r\n  every milestone pays a reap-and-measure tax to rent space the box does not structurally have.\r\n- **Why register-worthy rather than \"clean up more\":** agent-side discipline (IR-31's budgeting,\r\n  pool reaps, teardown steps) is already adopted and still only rents windows — the reservoir\r\n  that would durably move the floor is operator-owned bulk no agent may touch. Naming it here is\r\n  the boundary: agents keep budgeting IN POOLS (not GB); moving Steam/Downloads (or adding a\r\n  disk, or pinning golden to a box without operator payload) is an OPERATOR decision this entry\r\n  exists to put in front of them once, with numbers, instead of re-deriving the floor each cut.\r\n- **Ripe when:** operator rules on the bulk (move/expand/accept-the-tax), OR the first golden\r\n  that dies at the 32 GB preflight despite adopted pool discipline (IR-59's LNK1180-class red).\r\n- **Size:** zero code; one operator decision + at most a runbook line naming the chosen floor.\r\n\r\n### IR-65 — kitsubito kernel-audit backpressure: a tailscale-snap AppArmor denial storm + no auditd turned the default audit backlog into a CI-wide stall amplifier (REMEDIATED AT BOX; re-check triggers named)\r\n\r\n- **Status:** REMEDIATED-AT-BOX 2026-08-25 (doyle, operator-authorized root — ruling pinned\r\n  releases#225 comment 5418800776); entry stays OPEN as the re-check record because the storm\r\n  SOURCE persists and two named events can silently revert the fix.\r\n- **Mechanism:** `snap.tailscale.tailscaled` (1.92.5) polls /proc and takes an AppArmor\r\n  ptrace-read DENIED per poll — a continuous kernel-audit record storm scaling with process\r\n  count (spawn-heavy serialized CI legs amplify their own storm). With NO auditd installed the\r\n  records rode printk (kauditd throttling) and the 8192 kernel backlog overran\r\n  (lost=1,537,743); the default `backlog_wait_time` 60000ms turns a full backlog into A 60s\r\n  SLEEP INSIDE ANY AUDITED SYSCALL — the broker dispatch stall that stretched IR-30's\r\n  Linux-face race window (see IR-30's Linux-face addendum; deaths clustered 59–63s ↔ this\r\n  knob's value).\r\n- **Remediation (verified at the EFFECTIVE layer, not the fragment):** auditd installed +\r\n  active (storm consumed, backlog drains to 0, lost flat), backlog_limit 32768,\r\n  backlog_wait_time 0 (full backlog may DROP, never STALL). ⚠ THE TRAP PAID FOR ONCE: the first\r\n  knob write (`50-backlog.rules`) silently LOST the augenrules merge — apt's own\r\n  `/etc/audit/rules.d/audit.rules` sorts LAST (digits before letters) and its `-b 8192` /\r\n  `--backlog_wait_time 60000` won; a whole proof run executed under the defaults while the\r\n  fragment grepped perfect. Values now live in the merge-WINNING file; verified `auditctl -s`.\r\n- **Re-check triggers (the reason this entry stays):** (1) tailscale snap update — the plug\r\n  landscape may change, the storm may stop or grow; (2) auditd package update/reinstall — may\r\n  rewrite `rules.d/audit.rules` and re-lose the merge; (3) box reimage. On any of these: one\r\n  `auditctl -s` (expect 32768/0) + one `journalctl -k | grep 'backlog limit'` (expect silence).\r\n- **Ripe when:** a re-check trigger fires. **Size:** two read-only commands per check.\r\n\r\n### IR-66 — first-chunk-needle test class: two latent members remain after the v0.63.0 fix (attach.rs:561, :672)\r\n\r\n- **Status:** CLOSED / BUILT — release-close reconciliation 2026-09-11. The WEBSERVE JIT already\r\n  ruled this satisfied; source at `e5a2fed9` retains both delayed needles. Closure uses the\r\n  recorded gates below, not v0.69.0's unrelated green receipts. Hertz rider PR #161, landed ff at\r\n  `d04b922d` (2026-08-27, IO-PARSER #22\r\n  intake rider). Both members got the later-needle treatment (TICK39 delayed past burst on both\r\n  OS arms; alt-screen entered before delayed ALT_VIEWPORT_MARKER). Gate: doyle — diff-scope\r\n  review; Windows isolated worktree 3× TICK39 PASS + clippy + treqs; Linux CLEAN worktree at the\r\n  PR sha on kitsubito 3× both cells PASS (independent of the builder's dirty-shared-tree proof,\r\n  disclosure on record). · **Origin:** doyle tree-wide census at `dbe3daad`\r\n  (releases#225 comment 5418844404 — the census that corrected my own resume.rs-scoped\r\n  overclaim), after the class's first member was RCA'd and fixed in v0.63.0's head.\r\n- **Mechanism (cite, not restate):** KNOWN-HAZARDS 6.9 same-session face, amended at\r\n  `dbe3daad` — `spawn_session_pid`'s Spawned-wait consumes-and-discards a first output chunk\r\n  that races the reply (~2ms window on a healthy Linux box; load-stretched under backpressure,\r\n  see IR-30 Linux-face + IR-65). A test whose needle exists ONLY in the child's first chunk\r\n  asserts winning a race the contract does not promise.\r\n- **The two members:** `crates/spt-daemon/tests/attach.rs:561` (TICK0..39 instant burst then\r\n  `cat`; needle TICK39 read directly after spawn — the whole burst can sit in the first\r\n  chunks) and `:672` `cross_node_cold_attach_to_alt_screen_gets_clean_repaint` (unix-only;\r\n  `printf '…ALT_VIEWPORT_MARKER'; cat` — needle in the first chunk). Failure shape differs from\r\n  the fixed member: both children idle on `cat`, so a lost prefix is a HANG killed by nextest's\r\n  backstop at exactly 240s (slow-timeout 60s × terminate-after 4) — not a natural-life death.\r\n  Verified NOT in the class: daemon_e2e.rs:209 (needle = echo of post-spawn input), attach.rs:995\r\n  + brain_swap.rs:170 (attach/replay reads, not spawn-waits).\r\n- **Fix shape (ruled at the v0.63.0 close):** hertz lane, NEXT intake — the same one-line\r\n  later-needle / robust-read treatment the resume seed got in `dbe3daad`; deliberately NOT\r\n  landed mid-r4. Both cells passed r4 (0.010–0.058s) — the members are latent, not failing.\r\n- **Ripe when:** next milestone intake (hertz test lane) or the first golden red at ~240s on an\r\n  attach cell — either way the mechanism and fix are pre-derived, triage should cite this entry\r\n  and skip the RCA. **Size:** two one-line test edits.\r\n\r\n### IR-67 — wave-battery gap: a `-p spt --bins` leg compiles bin targets as harnesses and runs ZERO integration/e2e tests, so batteries that lean on it carry silent no-coverage legs\r\n\r\n- **Status:** BUILT — remedy applied across the IO-PARSER #22 milestone (2026-08-27/28): every\r\n  wave battery named explicit `-p spt --test <suite>` e2e legs beside the `--bins` unit leg\r\n  (GW1..GW5 evidence), every builder evidence report carried a named real e2e per the dispatch\r\n  template, and the one filter mistake (a `--test` name not matching its file) REFUSED loudly\r\n  rather than silently skipping — the failure mode this entry exists to kill. Battery template =\r\n  the dispatch text now carried forward in gate craft.\r\n- **Was:** OPEN · **Origin:** doyle, banked at the SIGNET #218 gates 2026-08-25 (\"gate\r\n  battery gap learned\"), filed at this sweep per the standing rule.\r\n- **Mechanism:** `cargo test/nextest -p spt --bins` builds `[[bin]]` targets as TEST HARNESSES\r\n  (unit tests inside bins only) — `tests/` integration and e2e suites of the crate NEVER run,\r\n  and the leg's green output is indistinguishable from coverage. Kin of the two banked pool\r\n  faces (`--bins` never emits fixture exes; fresh-pool fixture reds) but this face is about the\r\n  BATTERY TEMPLATE: my SIGNET wave batteries carried a `-p spt --bins` leg believed to cover\r\n  the crate.\r\n- **Remedy:** at next intake, the wave-battery template gains an explicit `tests/` leg for the\r\n  spt crate (nextest `-p spt --test <suites>` or unfiltered `-p spt` where pool history\r\n  permits), and any battery doc that lists `--bins` as a coverage leg gets the one-line caveat.\r\n- **Ripe when:** next milestone intake (the battery template is touched at every intake).\r\n  **Size:** template lines only.\r\n\r\n### IR-68 — PSYCHE_INGEST_FAIL cause class unproven: git index.lock did NOT reproduce the ingest failure it was blamed for\r\n\r\n- **Status:** OPEN, investigation-shaped · **Origin:** todlando measurement at the W2 int-leg rig\r\n  (IO-PARSER #22, PR #163 at `769fb0a9`, 2026-08-27), reported measure-first; filed by doyle.\r\n- **The contradiction:** the six silent `PSYCHE_INGEST_FAIL:todlando` lines observed at the\r\n  drop-dir probe (2026-08-25) were attributed to shared-checkout git `index.lock` contention. The\r\n  W2 rig planted NON-EMPTY `index.lock` files in BOTH places git takes one (bare git-dir + every\r\n  `<git_dir>/worktrees/<name>/`, mirroring `branchstore::sweep_stale_index_locks`, plant count\r\n  asserted >= 2) — and the ingest COMMITTED ANYWAY (tier write `Written`; `route_slices`\r\n  propagates `commit_live(...)?`, so a blocked checkpoint would have failed it). Non-empty was\r\n  deliberate: KH 1.3 reaps only 0-byte locks, and `pulse_tick` runs no boot sweep. So on this\r\n  store an `index.lock` does not block the checkpoint, and the field incident's mechanism is\r\n  UNKNOWN, not merely unconfirmed. The rig's doc comment records the attempt; the shipped int leg\r\n  fails the ingest at the drop READ instead (upstream of the store).\r\n- **Strongest negative evidence, pinned to the executable rig:**\r\n  `crates/spt-daemon/tests/commune_io_events_int.rs:95-107` documents that the lock mechanism was\r\n  tried **first**, planted non-empty locks in both the bare git-dir and every linked-worktree\r\n  location, asserted that the population was non-empty, and still observed `Written`. Its own\r\n  sentence is the required scope boundary: “This leg does not claim to reproduce a mechanism it\r\n  measured as inert.” The working injection is instead drop-file → directory replacement, which\r\n  fails the upstream read deterministically and proves only the `COMMUNE_FAIL` event contract.\r\n- **NOT claimed:** that the field incident was misattributed to ingest failure generally — the\r\n  files did survive with failed-ingest log lines; what is unproven is the index.lock CAUSE.\r\n- **Ripe when:** next PSYCHE_INGEST_FAIL sighting in the field (capture the failing store state\r\n  before touching it), or a dedicated probe slot. W2's COMMUNE_FAIL event now pushes a NAMED\r\n  reason on every failure, so the next occurrence self-reports its cause — read that first.\r\n  **Size:** investigation; no product change until the mechanism is pinned.\r\n\r\n### IR-69 — inherited stderr tokens can tear between format fragments; 26 test consumers parse that surface as structured truth\r\n\r\n- **Status:** OPEN for the #243 residual population and anchored-consumer work. The original\r\n  product remedy LANDED at `ec6da9b0`, as recorded in this entry's later amendment; it is not\r\n  still parked awaiting assembly. Releases#241 retains its original lane evidence in comment\r\n  5461613480. This entry is the exposure map and census discipline; residual conversion,\r\n  generator repair and a SHA-pinned zero recensus remain owed. · **Origin:** CONDUIT #236 r3\r\n  golden attempt 2,\r\n  2026-08-29: `endpoint_autostart_e2e` missed its contiguous\r\n  `ENDPOINT_AUTOSTART:gwauto` keystone although the matching fresh session id proved the replay\r\n  happened. Attempt 3 was clean on the same discarded SHA after 139 GB was reaped; unequal load\r\n  makes the pair corroborating, never a rate.\r\n- **Mechanism, recovered from the literal torn bytes:** two daemon processes inherited one stderr\r\n  pipe. `BRAIN_UP` and `ENDPOINT_AUTOSTART` are each one `eprintln!`, but `write_fmt` may reach the\r\n  handle once per format fragment; the per-process stderr lock cannot serialize the other process.\r\n  The observed interleave split the autostart token between `ENDPOINT_AUTOSTART:` and `gwauto`.\r\n  This is fragment-level cross-process interleaving, not a failed replay and not a two-thread race.\r\n- **Durable remedy, ruled product-side:** render a complete diagnostic line into one buffer and\r\n  issue the complete rendered text, newline included, as **ONE handle call**. An OS short-write\r\n  may retry the late tail so completeness wins over a silently truncated line; the deterministic\r\n  property pins application-side fragmentation, not syscall count under that rare retry. It makes\r\n  no claim that the OS write is atomic on Windows, and no CI re-fire against a 1-of-2 observation\r\n  may stand in for it. Widening one test's grep is refused: it greens one consumer while every\r\n  sibling token remains exposed.\r\n- **Cut-SHA census** (todlando generator, independently hash-verified by hertz), measured from\r\n  `4d6007ac4ee3d0991f4bc60b7e1a55825aad1aaf` via `git show`, not a dirty worktree:\r\n  **486 real emitter sites / 383 distinct tokens / 26 consumer test files**. The generator emitted\r\n  487 site rows, but one is a known phantom: `sealverb.rs:456` is a `format!` inside `map_err`\r\n  that the four-line lookback attributed to a neighbouring real `eprintln!`. Corrected real emitters\r\n  by crate: spt-daemon 270, spt 194, spt-runtime 8, spt-live 5, spt-net 5, spt-store 4; by macro:\r\n  `eprintln!` 484, `println!` 1, `eprint!` 1. `DRIVEN_BY` is the sole stdout row and therefore\r\n  outside the stderr remedy. A consumer means the test both mentions `TOKEN:` and reads a\r\n  stderr/log surface; bare-token matching inflated the population to 72 files by admitting prose.\r\n  This is an **exposure map**, not a rate and not a claim that all 26 have torn.\r\n- **Artifacts (the preserved raw generator outputs contain 487 site rows):** cut census SHA-256:\r\n  sites `f10d6bfe5e0399f98945cf63bb5719a01a62e1251be84165c73030fa9bb224f5`,\r\n  tokens `80b0d1835d9d46376b2f200b1c50be4ca0e185a135168444414255f9308ed92b`,\r\n  consumers `249a2e33df43a30570ca82b5bd200d8b6e2bf07aa8250fcc8bace47fe23e3cbc`.\r\n  The sealed sites file's macro column is wrong on 7 of its 487 raw rows; the corrected raw split\r\n  is `eprintln!` 485 / `println!` 1 / `eprint!` 1. The sealed tokens file has no final newline, so\r\n  `wc -l` reports 382 although it contains 383 logical records. The sealed files remain unedited;\r\n  these corrections are textual.\r\n  Generator `81df82f01ef33a82307920d9804a2394b787ef2ffbe3b41d2d7dda560d9a62a9`\r\n  was recorded as asserting newline-terminated output, but the sealed tokens artifact refutes that\r\n  claim for at least one output. Its remaining guards cover logical record counts, a known-positive\r\n  `SUBSCRIBE_DECISION` sentinel, four-line macro lookback, and truncation only at a\r\n  `#[cfg(test)]` that opens a module.\r\n- **Census hazards paid for while constructing and reconciling the population:** the provisional\r\n  instrument moved `277/243 → 286 → 412 → 487 raw → 486 real` as four silent assumptions were\r\n  found: same-line matching misses multi-line macros; truncating at the first `#[cfg(test)]` drops\r\n  later shipping code; lookback must prefer the token line's own macro over a neighbouring arm;\r\n  and even that lookback can promote a nested token literal beneath a real macro into a phantom\r\n  second site. A file without a final newline also makes `wc -l` silently undercount logical\r\n  records by one. Every future census must name its SHA, assert a known member, count records\r\n  inside the generator, and reconcile emitted rows to real sites.\r\n- **Separate anchored-matcher finding:** `IDLE`, `DISPATCH`, `BUSY`, and `BOUND` are common words\r\n  matched as substrings in exposed consumers. One-write emission does not prevent an unrelated log\r\n  line from satisfying them; those predicates need anchored token matching. Keep this separate from\r\n  the tear remedy so neither defect is claimed to close the other.\r\n- **Kin:** [[IR-50]] (the sink must be read before its absence means anything), [[IR-40]] (a\r\n  confident signal that does not describe the source truth), [[IR-8]] (a plausible census whose\r\n  blind spot returns a clean answer).\r\n- **CLOSE-OUT ADDENDUM 2026-08-30 (#242/v0.66.0 sweep — the entry's own close-out re-census RAN\r\n  and FOUND the predicted blind spot LIVE; entry stays OPEN):** re-census at the landed sha\r\n  `ec6da9b0` (independent containment-classified meter, reconciled with todlando's independent\r\n  meter — full write-up `EMISSION-RESIDUAL-CENSUS-FINDING.md`): the generator truncated\r\n  `crates/spt/src/cli.rs` at its FIRST module-opening `#[cfg(test)]` (line 3007, module closes\r\n  3164, file runs to 39118) and never scanned the rest — **338 TOKEN-shaped shipping sites remain\r\n  bare (332 colon-form, i.e. misses under the sealed census's own predicate, + 6 space-form)**,\r\n  plus `main.rs` 2 sites behind the same mechanism; exactly TWO files tree-wide carry the\r\n  triggering property (first module-opening cfg(test) precedes shipping code) — the generator\r\n  fix's owed blind-spot measurement, answered. The census-hazards bullet above already NAMES this\r\n  third-face truncation hazard; the module-opening fix narrowed the trigger and kept the blind\r\n  spot for files where a test module CLOSES and shipping resumes — IR-8 shape, predicted by this\r\n  entry's own text. The shipped #241 conversions are UNAFFECTED (495 removals ≈ censused 486 +\r\n  space family; the SEEN population is closed; golden green stands). Residual conversion +\r\n  generator fix + enforcement-at-the-seam = **releases#243** (BACKLOG, operator triages);\r\n  delivery.rs:149/313 are post-cut MINTS relative to the census sha (todlando's own, settled\r\n  attribution), deliberately outside #243's census-mechanism scope — and ALREADY CONVERTED: the\r\n  fix rode his breadcrumb branch (`60a12056`) into the r4 head and shipped IN-TAG (todlando\r\n  flagged the stale \"his thin lane converts post-cut\" claim 2026-08-30; re-measured — zero bare\r\n  TOKEN `eprintln!` in delivery.rs at both `d931dd63` and origin/main). No lane is owed for it. Re-runnable meter\r\n  `EMISSION-RESIDUAL-CENSUS-METER.py` (repo root, untracked; version-control rides #243's lane).\r\n  **Common-word matcher RULED at this sweep (discharges the \"decide\" clause below):** the four\r\n  common-word consumers (`IDLE`/`DISPATCH`/`BUSY`/`BOUND` substring predicates) get a SEPARATE\r\n  hertz test-side rider — anchored token matching is consumer-predicate work, NOT folded into\r\n  #243 (keeps #243 product-scoped) and not claimed closed by one-write emission; lane-link when\r\n  hertz's spool drains.\r\n- **Closes when:** releases#243's residual conversion + generator fix land and a re-census at\r\n  that sha reads zero shipping residue under both delimiter forms. **Size:** product lane\r\n  complete elsewhere; register follow-through small.\r\n\r\n### IR-70 — a hand-built `IoBus` silently omitted later sinks while every gate stayed green\r\n\r\n- **Status:** OPEN, remedy unscheduled; the v0.65.0 respin fixed the witnessed call site on PR #173.\r\n  This entry owns the recurrence class, not that shipped correction. · **Origin:** releases#234,\r\n  commit `c5459795167`, CONDUIT #236 respin.\r\n- **Mechanism:** `publish_commune_io` constructed `IoBus` itself and registered only the sink it\r\n  knew. `default_bus` already existed as the assembly point and its module contract explicitly says\r\n  emitters must know only `IoBus::publish`, so adding a later sink costs one registration rather\r\n  than an emitter sweep. The hand-built publisher recreated exactly the drift that contract warned\r\n  against: `COMMUNE` and `COMMUNE_FAIL` reached the old sink but never the adapter log, leaving\r\n  `spt api io-events` permanently short on two documented kinds.\r\n- **Why the complete battery was green:** the e2e was vacuous on the broken kinds; units synthesized\r\n  rows without traversing `publish_commune_io`; and traceability checked attached tags, not whether\r\n  the tagged path exercised the real publisher. Three green instruments shared one blind seam.\r\n  The respin routed the site through `crate::iobus::default_bus`, and its source comment now records\r\n  the failure shape.\r\n- **Durable remedy direction (todlando mechanism, not scheduled):** enforce the assembly point so\r\n  the next hand-built bus is impossible rather than found — make production publishers obtain the\r\n  composed bus through one construction API, and gate the real publish path for every documented\r\n  kind. A search or comment is not enforcement; another emitter can satisfy both while rebuilding\r\n  a partial sink list.\r\n- **Kin:** [[IR-39]] (a green fixture never reached the missing dependency), [[IR-37]]\r\n  (traceability tags prove coverage bookkeeping, not behavioral truth), [[IR-58]] (a hand-built\r\n  population returns an orderly but incomplete answer).\r\n- **Ripe when:** the next `IoBus` construction/API touch, or a new sink registration. **Size:**\r\n  small-to-medium assembly-point enforcement plus a real-path population test.\r\n\r\n### IR-71 — controller-seat release has no persisted breadcrumb, so tests cannot distinguish propagation lag from a missing detach\r\n\r\n- **Status:** OPEN, observability gap; no remedy scheduled. · **Origin:** CONDUIT #236 r3\r","truncated":true,"truncatedBy":"lines","totalLines":4232,"totalBytes":104116,"outputLines":1185,"outputBytes":104116,"lastLinePartial":false,"firstLineExceedsLimit":false},"totalLines":6937,"displayContent":{"text":"### IR-45 — twohost rig home premise, SETTLED: pump paths resolve under the per-run TEMP root (rig is disk-hermetic; the \"live fleet roster\" reading is retired)\n- **Status:** RETIRED 2026-08-19 — ask answered by the one code read at main @`78a9a16`; residue\n…\n- **Residue disposition:** (1) #189's third-node evidence was corrected on the board (comment\n…\n\r\n### IR-46 — the Windows disk-floor preflight asserts an INSTANT; workspace free space moves tens of GB inside the hour, so a green floor is not a claim about run headroom\r\n- **Status:** open — mechanism CONFIRMED by a measurement series on hfenduleam; doyle ruled it\r\n  register-shaped 2026-08-18 · **Origin:** deployah, NAMEPLATE #181 golden-head intake, on the\r\n  run that the floor red-floored · **Filed as IR-46 after an id collision:** this row was authored\r\n  as IR-42 and held unpushed under the v0.56.0 tag freeze, during which the release-close sweep\r\n  (`78a9a16`) issued IR-42..45 to other findings. Parallel issuance, not authored disagreement —\r\n  and noted here so a later reader chasing \"IR-42\" in this row's history does not hunt for a lost\r\n  version of it.\r\n- **What/why:** `golden.yml`'s Windows preflight computes `$freeBytes` once at job start and\r\n  hard-fails under a `32GB` floor. As a fast-fail that is correct and it did its job — it refused\r\n  before compiling rather than dying deep in a link step. The defect is what a PASS is then read\r\n  to mean. The reading is a point sample of a quantity that moves by tens of GB unattended, so a\r\n  green preflight licenses a run whose headroom was never measured. Nothing downstream re-checks.\r\n- **Evidence — five readings of `C:` free on one box inside roughly one hour, 2026-08-18:**\r\n  - `03:01:54Z` — `free_bytes=2666205184` (2.48 GiB) against `floor_bytes=34359738368`, the\r\n    preflight's OWN reading; run `32093894524`, both `n1-gate` and `test` on Windows/hfenduleam\r\n    failed at this same step, before any compilation.\r\n  - `~03:2xZ` — ~2.50 GB, independent `Get-PSDrive` read, corroborating the preflight.\r\n  - pre-reap — **33.70 GB**, immediately before deployah deleted anything.\r\n  - post-reap-1 — 76.42 GB (42.72 GB reclaimed: `claude_skill_owl/target`, `golden-w1/target`).\r\n  - pre-reap-2 — **73.81 GB**, i.e. 2.61 GB consumed unattended between the two reaps; then\r\n    post-reap-2 129.70 GB (55.89 GB reclaimed: `.worktrees/nameplate-w1/target`).\r\n- **LABELLED HOLE — do not let this harden:** roughly **31 GB was released between the preflight\r\n  failure and the pre-reap reading by something OTHER than the reclaim**. Released-by-unknown.\r\n  The runner cleaning its workspace after the job died is *plausible* and is NOT the recorded\r\n  cause — it was never measured, and no one looked while it was happening. Recorded as a hole on\r\n  purpose (doyle's explicit ask at filing): a plausible cause written down as the cause would make\r\n  this row read as explained when the actual mechanism of the 31 GB is unknown.\r\n- **The hazard this leaves:** a run can clear the floor at preflight and starve mid-build, and\r\n  mid-build disk starvation does not present as disk — it surfaces as a link failure, a truncated\r\n  artifact, or a rustc ICE, i.e. as a defect in the tree under test. The failure mode inverts the\r\n  gate's purpose: the preflight's whole point is to keep box conditions from being read as lane\r\n  reds, and a passing preflight actively argues the opposite. Note the polarity — this row is\r\n  about the PASS, not the FAIL. The observed red was honest.\r\n- **#242/v0.66.0 GOLDEN ADDITIONS (deployah measured 2026-08-29, banked at the 08-30 close\r\n  sweep):** (i) per-job floor figures are SEPARATE INSTANTS — quote per job, never one figure for\r\n  both (attempt 1: `test` 26521477120 vs `n1-gate` 26535051264 free bytes, 8s apart, one run);\r\n  (ii) **CORRECTED TRAP** (retracting deployah's earlier \"attempt-2 hides jobs\" version): the\r\n  default `/runs/<id>/jobs` endpoint stamps `run_attempt=<current>` on EVERY job including ones\r\n  that never re-ran (4 of 8 mis-assigned on this run) — it is the RUN's attempt, not the JOB's,\r\n  so a stale green can read as re-earned; `started_at` is the discriminator and\r\n  `/runs/<id>/attempts/N/jobs` the authority. Also `rerun --failed` re-runs DEPENDENT jobs\r\n  (twohost re-ran despite a green attempt 1); (iii) a rerun preflight reads RAW free BYTES with\r\n  the CI step's own predicate, not display GB; (iv) a rerun green counts as floor-RCA-closing\r\n  evidence only after a step-level NON-VACUOUS check (checkout SUCCESS + workload steps ran) —\r\n  the v0.64.0 checkout-SKIPPED shape means a green job can carry zero code signal.\r\n- **Ripe when:** next `golden.yml` touch. Remedies to weigh THEN, not as a drive-by: re-assert the\r\n  floor at job END (turns a starvation into a labelled disk verdict instead of a fake lane red);\r\n  or raise the floor to cover a full build's peak rather than its entry condition; or sample free\r\n  space across the run and emit the minimum as a token. All three cost run time; none is obvious.\r\n- **Size:** small in `golden.yml`, load-bearing in what a green run is taken to prove.\r\n- **Kin:** [[IR-41]] and [[IR-40]] (a state that reads as a clean verdict unless it is labelled —\r\n  here a PASS that is read as headroom it never measured), [[measure-the-box-before-the-instrument]],\r\n  [[cancelled-measurement-leaves-labelled-hole]].\r\n\r\n- **2026-09-06 addendum (doyle, v0.67.1 close sweep): trigger FIRED at `04e32c8c` — `golden.yml` touched (2-line HEAVY reclass of `brain_resume_conn_deadlock` on the respin) with no remedy weighed. Not a drive-by by choice: the touch rode a respin under a pre-registered hard stop, which is no remedy window. COMPOSED with IR-59 (log-the-floor) + IR-73 (literal-first sites) as one hertz workflow rider on WEBSERVE #272; the remedy weighing happens on THAT lane, before the WEBSERVE golden head.**\r\n\r\n<!-- [doc->REQ-CI-FREE-SPACE-PREFLIGHT] -->\r\n- **2026-09-06 remedy ruling (doyle, WEBSERVE rider):** retain 32 GiB; record raw-byte\r\n  `FLOOR_START` and `FLOOR_END` PASS/RED tokens per job/runner, each labelled `sample=INSTANT`.\r\n  End DISK assertions run `if: always()` before teardown, including after failed workloads.\r\n  A fresh `FLOOR_DOCS` assertion immediately before docs-drift composes with IR-73's second half.\r\n  Raising the floor is refused without a measured peak; continuous sampling adds lifecycle\r\n  machinery while remaining blind between samples. Start/end are a dataset, not a minimum or\r\n  headroom guarantee. Golden execution evidence waits for the WEBSERVE golden head; the thin\r\n  PR must first show actual START/END output on its own green CI run.\r\n\r\n### IR-47 — ci-notify treats a missing co-author trailer as a quiet info line; silent attribution loss reads as \"there was none\"\r\n- **Status:** open — patch AUTHORED and stashed unlanded since 2026-07-29\r\n  (`.worktrees/_patches/ci-notify-missing-trailer.patch` + its `test-ci-notify.sh` harness in the\r\n  sibling `.untracked` dir); surfaced by doyle's 2026-08-19 idle-queue verification of that stash ·\r\n  **Origin:** the AGENTS.md trailer mandate's own hazard family (the space-spelling trailer is\r\n  structurally invisible to git's tokenizer, so confident zeros already read as attribution loss\r\n  once); this row is the NOTIFY-side twin.\r\n- **What/why:** `.github/ci/ci-notify.sh` parses the head commit for the line-anchored\r\n  `Co-authored by: <agent>` trailer to add a second notification recipient. When the trailer is\r\n  absent or unparseable, the current script emits one stdout info line (\"doyle only\") and moves\r\n  on — correct as a non-fatal outcome, wrong as a SILENT one: a lane that lost its attribution\r\n  (typo'd trailer, squash that dropped the body, hyphenated spelling) notifies doyle alone on\r\n  every run and nothing anywhere says an agent stopped being told about their own lane's verdicts.\r\n  The stashed patch keeps absence non-fatal but promotes it to a `::warning` workflow annotation\r\n  (visible on the run summary), and splits the legitimate quiet case (co-author IS doyle) from the\r\n  loss case so the two stop sharing one message.\r\n- **Evidence:** patch verified 2026-08-19 to still NOT be on main — the warning string is absent\r\n  from `.github/ci/ci-notify.sh` at the current tree. Patch content re-read at verification; it\r\n  applies against the script's post-`SEND_BOUND_SECS` shape.\r\n- **Ripe when:** next `golden.yml`/ci-notify touch — natural co-rider with [[IR-46]]'s remedy\r\n  window (same file family, same \"weigh then, not drive-by\" rule). The stashed test harness rides\r\n  with it.\r\n- **Size:** ~10 lines in one shell script plus its test.\r\n- **Kin:** [[IR-40]] (an unlabelled state read as a clean verdict — here a quiet info line read as\r\n  \"no co-author existed\"), the AGENTS.md `%(trailers:)` tokenizer mandate (the sibling silent-zero\r\n  on the AUDIT side).\r\n\r\n### IR-48 — the nextest.toml parity cell tolerates CRLF only by parser accident; a newline-sensitive arm added later reds fresh Windows checkouts alone\r\n- **Status:** open — filed 2026-08-19 (doyle route, hertz verdict: REGISTER as preventive\r\n  hardening, not current defect) · **Origin:** sibling sweep after the W3 gate CRLF finding —\r\n  parent mechanism: `include_str!` embeds working-tree bytes verbatim, `core.autocrlf=true`\r\n  smudges fresh checkouts CRLF, and the author's never-re-smudged tree stays LF — builder green,\r\n  every fresh rig/golden checkout red.\r\n- **What/why:** `crates/xtask/src/main.rs` `the_checked_in_config_is_in_parity` include_str!s\r\n  `.config/nextest.toml` and feeds `phase_a_overrides_missing_from_ci_windows`. TODAY this is\r\n  causally CRLF-tolerant — the parser is `str::lines()`+trim (`override_filters`, main.rs:434-440),\r\n  and the 52/52 fresh-rig green at the hygiene gate (2026-08-19, this box) is therefore causal, not\r\n  luck. The hazard is the MISSING CONTROL: nothing pins the tolerance, so a future\r\n  newline-sensitive arm in the parity predicate reds only on fresh Windows checkouts — the\r\n  builder-green/rig-red inversion, deterministic but reading as flake.\r\n- **Remedy (hertz's, platform-independent):** feed the parity predicate an LF fixture AND the same\r\n  fixture converted to CRLF, assert identical missing-sets (including one unmirrored negative), so\r\n  a newline-sensitive arm reds on EVERY host rather than only fresh Windows checkouts.\r\n- **Ripe when:** next xtask parity-cell touch; explicitly OUTSIDE the family-B lane (hertz\r\n  scoping). **Size:** one fixture-pair cell.\r\n- **Kin:** the W3 gate finding this swept out of (skeleton cells, fixed at the fixture edge in\r\n  lane commit e99633f); [[IR-40]] (an untested tolerance read as a guarantee).\r\n\r\n### IR-49 — poolguard's landed-lane predicate is ancestry-only, so a cherry-picked member lane can never read Settled and its pool can never be taken over\r\n- **Status:** open — filed 2026-08-19 (todlando measurement at the keystone-w1/fix-197 reap,\r\n  doyle ruling; doyle re-verified the predicate at source before filing) · **Origin:** todlando's\r\n  post-landing landed-check used the guard's own predicate and it contradicted the (correct)\r\n  landed fact — the checker was wrong with the guard, which is exactly how the guard will be\r\n  wrong alone.\r\n- **What/why:** `git_lane_state`'s final arm answers Settled/InFlight purely by\r\n  `merge-base --is-ancestor <lane tip> <integration head>`\r\n  (`crates/spt-poolguard/src/lib.rs:424-436`, probe at `:474-479`). Under ADR-0050 golden CI\r\n  (thin member lanes cherry-picked onto a stage branch, ff-only main) a MEMBER lane's own branch\r\n  tip never becomes an ancestor of main. Measured at origin/main `9ea595c`:\r\n  `build/keystone-182-w2-sealed-multi` @`ba2d998` and `fix/197-absent-code-uncounted` @`5eb6a3b`\r\n  both read NOT-ancestor while `git cherry -v` reports every lane commit `-` (already upstream).\r\n  So `LaneState::Settled` is unreachable for any cherry-pick-assembled member lane whose branch\r\n  still exists, the takeover arm can never fire, and the pool refuses forever — including with a\r\n  dead holder. That contradicts the AGENTS.md mandate (\"a merged branch is taken over\") because\r\n  the guard's notion of merged is ancestry-only and the golden model structurally never produces\r\n  ancestry for member branches. The branch-vanished (`:391`) and re-pointed (`:399`) arms still\r\n  fire, and the STAGE lane works (its tip IS an ancestor) — the hole is landed-member-branch-\r\n  still-exists only. It did not bite at the 2026-08-19 reaps solely because deleting a pool\r\n  deletes its claim; it bites the first time someone wants to TAKE OVER a landed lane's pool\r\n  rather than reap it.\r\n- **Remedy (todlando's candidate, doyle-endorsed direction):** when ancestry answers false, fall\r\n  back to patch-id containment (`git cherry` / `rev-list --cherry-mark` against the claimed\r\n  base) before concluding InFlight. **Known residual to state in the fix's docs/tests:** a\r\n  conflict-adjusted pick changes the patch-id, so such a lane still reads InFlight; its release\r\n  path is branch deletion (the vanished arm), which is at least reachable. Tests want a\r\n  cherry-picked-landed fixture plus a conflict-adjusted negative.\r\n- **Ripe when:** next poolguard touch, or the first landed-lane pool takeover request.\r\n- **Size:** one fallback arm in `git_lane_state` + two fixtures.\r\n- **Kin:** [[IR-26]] (dead-holder takeover AUTHORIZED when it shouldn't be — this is the mirror:\r\n  takeover UNREACHABLE when it should fire), [[IR-42]] (claim writes, build enforces), the\r\n  AGENTS.md pool mandate this contradicts.\r\n\r\n### IR-50 — e2e failure panels read the PRE-REDIRECT stderr capture; every daemon-side diagnostic lands in a sink the rig deletes unread\r\n- **Status:** CLOSED — BUILT 2026-08-19; adoption-completion lane\r\n  `docs/ir50-register-close` @`e02f565f` (hertz, doyle-gated 2026-08-20) LANDED in\r\n  v0.59.0 as a PORTER rider (pick `e702d4b7` tip, main @`c62904e7`; register sweep\r\n  2026-08-21) — lane `fix/ir50-stderr-sink-census` @`1a2f6a2`+`2ac9543`\r\n  (hertz; base `0c86b2d`; rides the CONCIERGE #183 chain; these shas are the 2026-08-19\r\n  message-only reword of `cb4cd9d`+`7336e03` — trees proved identical by tree-id, so every\r\n  measurement below carries): exported\r\n  `spt_daemon::stderrlog::sink_path(home)` with `stderr_log_path` routed through it +\r\n  equality unit; `daemon_stderr_panel` in tests/common renders BOTH channels and labels a\r\n  read failure with channel + exact looked-at path + OS error (absent-sink regression pins\r\n  it — the IR-40 unlabelled-absence class was caught at gate and fixed in `2ac9543`);\r\n  censused every daemon-run captured-stderr panel outside `engine_room_bringup_e2e` (rides\r\n  #199 lane) and `er_briefing_*` (rides #164 lane); engineroom.rs:145 misnomer rider landed\r\n  in the same lane. Gate figure 781/781 at `2ac9543` (measured at the pre-reword tree,\r\n  which is byte-identical; first-report 765 was transcription,\r\n  corrected with raw line + JSON provenance). CLASS FOLD (doyle ruling, no fresh row):\r\n  `er_briefing_presented_e2e` hit this exact class during its own authoring (blank panels\r\n  on a real loud line) and was fixed locally in `72efb6a` reading both channels.\r\n  **REGISTER CLOSED 2026-08-19:** branch `docs/ir50-register-close` links the\r\n  golden-tested implementation at `4661bc9d` and completes helper adoption in the five measured\r\n  residual files: `er_brief_once_per_session_e2e.rs`, `er_briefing_presented_e2e.rs`,\r\n  `er_sequestered_cwd_e2e.rs`, `endpoint_autostart_e2e.rs`, and `n1_pairing.rs`.\r\n  `engine_room_bringup_e2e` remains the explicit exclusion, recorded as todlando's direct\r\n  sink-path read from the #199 lane. ·\r\n  **Originally filed:** 2026-08-19 (todlando RCA inside the #199 investigation; the immediate\r\n  four-panel fix in `engine_room_bringup_e2e.rs` is his and rides the #199 lane — THIS entry is\r\n  the class census, hertz-class) · **Origin:** the #199 evidence void — 40 rca-v2 runs held zero\r\n  daemon-side evidence for either erhost face; `ENGINE_ROOM_SPAWN_FAIL` (broker.rs:5658) was\r\n  written to a log the rig destroyed at teardown. Absence discipline honoured: the SUCCESS-path\r\n  line (`ENGINE_ROOM_BROUGHT_UP`) was also absent from all 40, proving the channel dead rather\r\n  than the event absent.\r\n- **What/why:** product `stderrlog::install` (broker at cli.rs:7633, brain at brainproc.rs:200)\r\n  repoints the process STD_ERROR_HANDLE within its first statements (`redirect_stderr_to`,\r\n  stderrlog.rs:101 — Windows `SetStdHandle` + `mem::forget`), so a rig's `.stderr(File)` capture\r\n  holds only the pre-redirect window; from that line on every diagnostic lands in\r\n  `SPT_HOME/logs/daemon.stderr.log` (stderrlog.rs:34/42) inside the rig's temp home, destroyed\r\n  unread at teardown. Panels are also mislabelled (\"brain stderr\" holding the broker's first\r\n  lines). REQ-DAEMON-STDERR-PERSIST fixed this blindness PRODUCT-side (\"the incident-night\r\n  RCA-blind gap\", cli.rs:7626-7631); no rig was ever taught to read the sink, so the fix does\r\n  not reach any harness. Class: every e2e rig that spawns `spt daemon run` and prints a\r\n  captured-stderr panel has the same void.\r\n- **Remedy:** census all such rigs; failure panels additionally dump\r\n  `SPT_HOME/logs/daemon.stderr.log` with the path read FROM `spt_daemon::stderrlog` (never\r\n  re-spelled), and the labels corrected (\"broker stderr (pre-redirect)\" / \"daemon stderr sink\").\r\n  `engine_room_bringup_e2e.rs`'s panel sites land in the #199 lane (todlando, scoped there —\r\n  measured shape: FIVE producers incl. the :167 precondition panic, SEVEN print sites, seven\r\n  relabels; the early \"four\" was an estimate the file refuted). ⚠ Rigs can only import\r\n  `STDERR_LOG_BASENAME`; the `\"logs\"` dir segment has no exported const, so every rig\r\n  re-spells it — the census lane should add an exported path helper (e.g.\r\n  `stderrlog::sink_path(home)`) to spt-daemon FIRST, then consume it everywhere. The census\r\n  and remainder are hertz-class.\r\n- **Ripe when:** hertz's queue after current items, or the next e2e red printing an empty\r\n  stderr panel.\r\n- **Size:** census + mechanical panel edits per rig.\r\n- **Kin:** [[IR-40]] (an absent signal read as a clean verdict), REQ-DAEMON-STDERR-PERSIST (the\r\n  product half of the same incident), [[IR-8]] (a censused zero that cannot see its blind spot).\r\n\r\n### IR-51 — engine-room e2e daemon runs NET-ENABLED on real interfaces; rig hermeticity is disk-deep only\r\n- **Status:** open — filed 2026-08-19 (todlando's x40 run-4 sink read, the first live read any\r\n  rig has had of the daemon sink; doyle ruled own-id rather than riding #199, at the finder's\r\n  own request) · **Origin:** unasked-for find inside the #199 instrument's first catch.\r\n- **What/why:** the rig's temp `SPT_HOME` buys DISK hermeticity ([[IR-45]]'s settlement — which\r\n  explicitly covered paths, not network) but nothing turns the net off: the run-4 sink shows\r\n  the rig's own daemon with `BRAIN_NET_CONSUMERS_UP` (dispatcher + peer pump started), three\r\n  `NET_FAMILY_GATE: binding IPv4-only`, and three `PAIR_MEET_UP:erhome` carrying the box's REAL\r\n  Tailscale (100.68.35.65) and LAN (192.168.1.81) addresses — live peer work during an e2e —\r\n  plus an `INBOUND_REACHABILITY` warning whose firewall rule admits the CI-runner's binary path\r\n  (`C:\\actions-runner\\_work\\spt-bs-core\\spt-bs-core\\target\\debug\\spt.exe`) while this daemon\r\n  ran from a dev tree. Consequences: test behavior conditioned on shared-box network state;\r\n  rate-shaped flakes; e2e runs radiating real traffic. SAME SINK, RECORDED NOT DIAGNOSED: conn\r\n  churn at ~150 ms cadence (327 write-start / 324 transport-close, conn ids past 300 in 58 s) —\r\n  unattributed. ⚠ CANDIDATE INTERACTION, explicitly NOT established (finder's own framing\r\n  honoured): the run-4 face (30 s bound blown, zero session events in the window, launch Ok, no\r\n  error anywhere) matches the SHAPE of the filed offline-but-resolvable-peer pump-stall\r\n  mechanism (dial does not fast-fail). Discrimination open; nothing here is a #199 attribution.\r\n- **Remedy:** a rig-honoured net-off switch (peer pump + discovery disabled under test unless\r\n  the test is ABOUT them) or loopback-only binding; census which e2e rigs start net consumers.\r\n  Sequencing rule: do NOT fix hermeticity into #199's face before the face is attributed — a\r\n  green bought by turning the net off would bury the mechanism unread.\r\n- **Ripe when:** #199 attribution answers whether net state is causal; else the next\r\n  hermeticity pass.\r\n- **Size:** product switch + rig adoption + census.\r\n- **Kin:** [[IR-45]] (the disk half), the subnet-pump dial-does-not-fast-fail mechanism (filed,\r\n  pump-stall RCA), [[IR-38]] (a live daemon's side effects outliving the test's intent),\r\n  releases#125 gc-spin (a conn-churn shape candidate).\r\n\r\n### IR-53 — failed-address expiry unit panics during the first 10m01s after Windows boot\r\n- **Status:** BUILT 2026-08-21 on `fix/ir53-cold-boot-instant` — LANDED in v0.59.0\r\n  (PORTER rider, pick `7b26f28d` on `assembly/porter-205`, main @`c62904e7`; register\r\n  sweep 2026-08-21 at release close) · **Origin:** todlando,\r\n  found and falsifiably measured mid-releases#204; this rider fixes the latent CI-pipeline\r\n  flake before PORTER golden.\r\n- **Measured:** `failedaddr::tests::an_expired_record_stops_matching_and_is_swept` ages an\r\n  `Instant` with `Instant::now().checked_sub(FAILED_ADDR_TTL + 1s).expect(...)`, where\r\n  `FAILED_ADDR_TTL = 600s`. Windows `Instant` counts from boot, so a host younger than 601s\r\n  cannot represent the requested stamp and panics `monotonic clock older than the TTL`.\r\n  Todlando predicted and observed the red before the threshold, then observed the identical\r\n  tree green after it; two subsequent daemon sweeps held 860/860.\r\n- **Remedy:** when the monotonic clock cannot represent the age, return through the loud\r\n  `SKIP_FAILED_ADDR_EXPIRED_SWEEP` arm naming the exact unproved property. On every warm host\r\n  the original direct aging and both expiry assertions still run unchanged; there is no\r\n  ten-minute sleep and no silent pass on the cold arm.\r\n- **Class census (untruncated):** four test-side\r\n  `Instant::now().checked_sub(...TTL/deadline...).expect(...)` patterns total. This cell is\r\n  the sole 601s member. Three siblings remain recorded, not changed in this rider:\r\n  `broker.rs:8432-8434` and `broker.rs:9198-9200` age\r\n  `CONTROLLER_WRITE_DEADLINE + 1s` (6s), while `broker.rs:10385-10388` ages\r\n  `BRAIN_WRITE_DEADLINE + 1s` (16s). Their much narrower cold-boot windows are the same\r\n  mechanism class and should use a controlled clock seam when next touched.\r\n- **Kin:** releases#204 (finder lane), [[IR-25]] (daemon-lib flake population), and\r\n  [[IR-40]] (a confident verdict without the evidence needed to make it).\r\n\r\n### IR-52 — docs-site CLI reference renders SHALLOW; help text below the rendered depth is outside the drift gate, unit-held per-REQ or held by nothing\r\n- **THIRD INSTANCE, observed 2026-08-24 (todlando, WAX-SEAL #21 W4; not acted on):** the new\r\n  `spt api seal verify|describe` FLAGS sit below the generator's rendered depth — the entry's\r\n  exact class. The W4 user page hand-documents them, which is per-page self-defense, not a\r\n  gate. Conditional-rider condition did NOT fire at W4 (no generator touch); the entry's own\r\n  trigger stands for whichever lane next touches the generator.\r\n- **Status:** BUILT 2026-08-24 on SIGNET #218 W1 T6 (todlando; doyle's intake made it the wave's\r\n  rider when the new `seal enroll-authenticator` verb forced the generator touch that armed the\r\n  trigger): `xtask` reference-gen now DESCENDS THE FULL COMMAND TREE recursively (the durable\r\n  remedy), regen published the 22 previously-unrendered leaves + the new section, and a depth\r\n  regression is a drift RED by construction. Self-holding units censused per the remedy: the\r\n  SURFACE-SECTION-SITED walk and both MONIC-TRIGGER-SECTION sited-help units are now DOUBLE-held\r\n  (published surface under the drift gate + content pins kept) — kept, not retired. · **Origin:**\r\n  todlando's #160 build report, fact flagged for the gate rather than folded silently.\r\n  (Pre-build status: open, filed 2026-08-19 — doyle, W3 #160 gate prep; second measured instance\r\n  of a class REQ-CLI-SURFACE-SECTION-SITED's own title already named for its sites.)\r\n- **What/why:** the generated `docs-site/src/cli/reference.md` renders `spt endpoint monic`\r\n  but does not descend to `monic add` / `monic update`, so the #160 strike of the maintained\r\n  kind enumeration at those two flag docs never appeared in the published reference and the\r\n  docs-drift gate CANNOT see the strike — the REQ-CLI-MONIC-TRIGGER-SECTION rendered-help\r\n  unit is the only hold. General mechanism: any help text below the generator's descent\r\n  depth is invisible to the drift gate; a deep help edit (or regression) ships unpublished\r\n  and ungated unless some REQ's unit happens to pin it. First measured instance:\r\n  REQ-CLI-SURFACE-SECTION-SITED names \"the three-deep sites the docs-site drift gate cannot\r\n  reach\" and closes them with its own pinned walk — per-REQ self-defense, not a gate.\r\n  Consequence beyond drift: adapter builders build BLIND from the public docs (DRI\r\n  protocol), so a deep-help divergence hands every adapter a thinner contract than the\r\n  operator's terminal shows.\r\n- **Remedy:** either xtask reference-gen descends the full command tree (deep help becomes\r\n  published surface the drift gate already covers), or a generic rendered-help walk over all\r\n  sites at all depths joins the drift gate; census which REQ units currently self-hold deep\r\n  sites (known: SURFACE-SECTION-SITED walk, MONIC-TRIGGER-SECTION sited-help unit).\r\n- **Ripe when:** next xtask docs-gen touch, or the first adapter filing traceable to a\r\n  deep-help divergence.\r\n- **Size:** xtask render change + regen + census of self-holding units.\r\n- **Kin:** the REQ-CLI-SURFACE-SECTION-SITED pinned walk (the per-REQ closure shape this\r\n  entry generalizes), [[IR-47]] only if its golden.yml/ci-notify surface rides the same\r\n  docs-gate window.\r\n\r\n### CI-RIDER LANE STATE — LANDED 2026-08-04 (post-v0.53.0 merge queue); history below kept for its mechanisms\r\n- **RESOLVED:** the lane rebased clean onto the post-tag queue and landed ff-only as\r\n  `2b33a47`/`2a7b016`/`d63f4ce`/`19d7f79` (content byte-identical to `1275e47..bf8c4a2` by lane-diff\r\n  blob hash). IR-1 and IR-4 are BUILT AND LANDED; IR-9's measurement half is landed with its trigger\r\n  now armed — the toolchain print reports runner-account versions on the NEXT GOLDEN RUN, which is\r\n  when doyle's 2026-08-03 ruling (decide from runner-account versions, never the interactive prior)\r\n  becomes executable. The two golden-only steps (link probe both boxes, toolchain print both legs)\r\n  remain unexercised until that run — the landing does not change that caveat.\r\n- **As recorded pre-landing (2026-08-04, doyle):** `ci/locksmith-riders` was at `bf8c4a2` with FOUR\r\n  commits not contained in `origin/main` and not present in LOCKSMITH's golden head `b7b00c3`. The\r\n  worktree `.worktrees/hertz-ci-riders` was clean, so the work existed and was simply unlanded:\r\n  `1275e47` (xtask: assert a load-bearing patch pin is still in force, both ways it lapses) ·\r\n  `49d4805` (docs/ci: a lock-touching lane reads edges, not just the package set) ·\r\n  `8ed006b` (ci/golden: print the toolchain that judged the run, both legs) ·\r\n  `bf8c4a2` (ci/golden: measure the link before rendezvous, read the floor after the checkout that\r\n  clears it — the floor read AFTER its own reclaim is [[ci-runner-has-no-warm-target]]'s shape).\r\n- **Why it is recorded rather than quietly re-dispatched:** [[IR-1]]/[[IR-4]]/[[IR-9]] were carried\r\n  as DISPATCHED, which is now false in BOTH directions — the work is further along than dispatched,\r\n  and it also did not ship. The cause was the same agent outage that cost `#123` its build, and the\r\n  operator's standing rule from that drop applies here too: an outage must not be able to remove\r\n  work from a batch silently. Board requests got a drop comment; register entries get this.\r\n- **MAPPING CONFIRMED BY ITS BUILDER 2026-08-04, by REQ id rather than by recollection** — hertz\r\n  noted first that its own context had been cleared between building the lane and answering, and\r\n  declined to testify from memory about the original instrument. Everything here is either measured\r\n  that day or read off the commits:\r\n  `1275e47` → `REQ-CI-LOAD-BEARING-PATCH-PIN` ([[IR-4]] part 1, the mechanical pin guard in xtask) ·\r\n  `49d4805` → `REQ-LOCK-TOUCHING-LANE-PROCEDURE` ([[IR-4]] part 2, procedure in docs/GOLDEN-CI.md) ·\r\n  `8ed006b` → `REQ-CI-TOOLCHAIN-VERSION-PRINT` ([[IR-4]] part 3, carrying [[IR-9]]) ·\r\n  `bf8c4a2` → `REQ-CI-LINK-HEALTH-PROBE` ([[IR-1]], the network axis).\r\n- **CORRECTION TO THE GATER'S EARLIER WORDING, from the builder:** `8ed006b` does NOT discharge\r\n  [[IR-9]] — it discharges IR-9's MEASUREMENT half only. IR-9's other half (align the two boxes, or\r\n  declare one authoritative clippy leg) is held by doyle's own 2026-08-03 ruling: decide once the\r\n  step reports RUNNER-ACCOUNT versions, never on the interactive-account prior. IR-9 therefore stays\r\n  OPEN with its trigger now REACHABLE, which is a different state from \"waiting\".\r\n- **Gate evidence, instrument NAMED:** `cargo nextest run -p xtask` in `.worktrees/hertz-ci-riders`\r\n  on hfenduleam, box quiet with no runs in flight — 34 run, 34 passed, 0 skipped. Nextest rather\r\n  than bare `cargo test`, per [[IR-25]]. ⚠ **What that does NOT cover, stated by the builder rather\r\n  than discovered later:** the two golden steps the lane ADDS (link probe on both boxes, toolchain\r\n  print on both legs) cannot be exercised outside a golden run. The probe's three arms\r\n  (five-sample success, no-reply, absent-CLI) were exercised on the real boxes at commit time, and\r\n  that is reported as a CLAIM RECORDED AT COMMIT TIME, not as a re-verification — the kitsubito arm\r\n  could not be re-checked from here. This is why the lane wants a golden rather than a quiet ff.\r\n- **[[IR-5]]/[[IR-6]] CONDITIONAL RIDERS: CONDITION NOT MET — the answer is NO and it closes the\r\n  question for this lane.** Measured file set `6d291e0..bf8c4a2`: `.gitattributes`,\r\n  `.github/bench/link-probe.ps1`, `.github/bench/link-probe.sh`, `.github/workflows/golden.yml`,\r\n  `crates/xtask/src/main.rs`, `crates/xtask/tests/bench_row_parity.rs`, `docs/GOLDEN-CI.md`,\r\n  `traceable-reqs.toml`. Nothing under `.github/ci/`, where the nextest-summary readers and\r\n  count-reporting scripts live. IR-5: no consumer of nextest output touched. IR-6: no EXISTING gate\r\n  output changed — though the NEW output was voluntarily written to IR-6's rule (the LINK line\r\n  prints `samples=N/M` and the individual rtts, membership beside the count, in both shells). That\r\n  SHRINKS IR-6's future scope by two lines; it does not discharge it.\r\n- **Three mechanisms lifted from this lane's REQ titles, worth more than the lane:**\r\n  (a) **An instrument must not be able to RED the run, and each shell breaks that differently** —\r\n  bash: `| head` under `pipefail` SIGPIPEs the producer to 141, so a print step reds (trim with\r\n  parameter expansion instead); pwsh under GitHub's wrapper: a MISSING COMMAND is a terminating\r\n  error, so rustup's absence must be TESTED with `Get-Command`, never caught. One requirement, two\r\n  constructions, and neither is portable reasoning about the other.\r\n  (b) **A negative-control mutation must be COUNTED before it is trusted** — the absent-CLI arm was\r\n  first \"measured\" against a tree where the mutation had not taken, silently re-measuring the\r\n  unmutated arm and reading as a pass.\r\n  (c) **Jitter, not the median, is the signal on a link that mostly works** — the motivating red's\r\n  link ran 10..83ms and 3..75ms while IDLE, so a median-only probe reads healthy straight through\r\n  the failure. Both med and max rows ride the ledger.\r\n- **Disposition:** composes onto the next golden batch as a thin lane, NOT slipped onto main. It\r\n  changes the golden pipeline itself, so it wants a golden rather than a quiet ff — and while\r\n  v0.53.0 is untagged, any push to `main` moves the runbook's bare `git tag` off the tested sha.\r\n\r\n### IR-55 — the `spt --bins` suite wedges partway through on leaked `findstr .` PTY children; the tests at the frontier are casualties, not culprits\r\n\r\n- **Status:** OPEN, **ARMED-FOR-CAPTURE**, owned by **hertz**. Test/rig defect by the dispatch\r\n  split (test/CI rework is never the product builder's). Filed by doyle 2026-08-22 from the\r\n  TURNKEY #212 W3 gate on releases#213.\r\n- **CORRECTED BY REPLACEMENT the same day.** This entry first named\r\n  `cli::tests::adapter_profile_verbs_local_only` as the wedging test, because that is where the\r\n  streamed frontier stopped. **That was wrong, and the correction is the useful part of the\r\n  entry:** run in isolation, on the same pool and binary and with the same env, that test passes\r\n  in **0.02s**. So do the other two the suite later stalled on —\r\n  `cli::tests::shell_channels_relay_sensory_and_text_file` (0.20s) and\r\n  `cli::tests::resolve_proof_target_override_reads_on_disk` (0.00s), each 1 passed / 652 filtered.\r\n  **A frontier names where progress STOPPED, not what CAUSED it.** Naming the last test printed\r\n  is the same error shape as reading a stack frame as a root cause, and it would have sent hertz\r\n  to rewrite three innocent tests.\r\n- **What is actually measured:**\r\n  - `cargo test -p spt --bins` unfiltered sat **24 minutes** at 13.5s CPU — blocked, not spinning.\r\n  - Re-run with `--test-threads=1` and streaming output: stalled after **183** completed.\r\n  - Re-run again with that frontier test skipped: progressed to **335** completed, then stalled\r\n    with **two** tests simultaneously past libtest's 60-second notice. Skipping one casualty\r\n    simply moves the frontier, which is itself evidence the fault is not in any one test.\r\n  - Every wedged harness carried `findstr.exe .` children under `conhost.exe --headless`.\r\n    **`findstr` with no file argument reads STDIN and blocks forever.**\r\n  - The frontier tests are **byte-identical at `c62904e7` and at the #213 tip `3d69f77c`**\r\n    (function bodies hashed at both blobs), so nothing in that lane introduced this.\r\n- **Reading, stated as a reading rather than a conclusion:** an EARLIER test spawns the `findstr`\r\n  stand-in as a PTY child and does not reap it; the children accumulate across the run and a later\r\n  test blocks behind them. Which test leaks is NOT yet identified and this entry does not guess —\r\n  the next step is to bisect for the leaker rather than to touch any test at the frontier. Five\r\n  orphaned `findstr` processes with creation times spread across the day were observed on this box\r\n  independently of any single run, which is consistent with accumulation across many suite runs.\r\n- **Hypothesis RAISED AND NOT SUPPORTED, recorded so nobody re-runs it:** the gate scrubs\r\n  `OWL_SESSION_ID` / `SPT_AGENT_ID` / `SPT_ENDPOINT_ID`, and a scrubbed identity was suspected of\r\n  routing a normally-REFUSED test down a live PTY path. The isolation runs above were performed\r\n  **with the scrub applied** and passed, so the scrub alone does not produce the hang. It remains\r\n  unexplained why the same unfiltered command completed at 652 passed / 1 failed for another agent\r\n  on the same tree; do not treat the scrub as the differentiator without a fresh one-variable run.\r\n- **Why it is register-grade:** golden CI runs the `spt` package. A test that never returns cannot\r\n  red — it consumes the single self-hosted runner slot until the job timeout, which `golden.yml`'s\r\n  50-minute cap bounds rather than fixes. A wedge that fires only sometimes is worse than a red,\r\n  because the suite's green record stays intact and nobody audits it — the same self-concealing\r\n  shape as `exit-code-after-a-pipe-is-the-tails`.\r\n- **Trigger condition (ripe):** any milestone whose gate wants an unfiltered `spt --bins` sweep,\r\n  which is every one of them. Ripe now.\r\n- **REMEDY, MEASURED 2026-08-22 and it changes this entry's urgency:** the same 653 tests under\r\n  `cargo nextest run -p spt --bins --no-fail-fast` complete in **22.2 seconds, 653 passed, 0\r\n  skipped, exit 0** — no slow markers, no timeouts — on the very tree and pool where\r\n  `cargo test -p spt --bins` wedged indefinitely twice. **nextest runs each test in its OWN\r\n  process**, so a leaked `findstr` child can block only itself. This is the discriminating\r\n  measurement rather than a workaround reached for to get a green: **the suite is not broken; the\r\n  SINGLE-PROCESS harness is what lets one test's leaked child wedge every test after it.** Golden\r\n  CI already runs nextest, which is the likely reason this has never surfaced there — the exposure\r\n  is to anyone running bare `cargo test` on the `spt` package, which is every local gate.\r\n- **Count reconciliation, recorded so the figures are not read as a discrepancy:** runs of this\r\n  suite report 652 passed / 1 failed where the one failure is\r\n  `cli::tests::adapter_translate_proof_gates_on_commit` — the `--bins`-only artifact, which\r\n  refuses because `translate_proof_fixture.exe` is not built under a bins-only invocation and says\r\n  so in its own message. Prebuilding it (`cargo build -p spt --bin translate_proof_fixture`) makes\r\n  it pass: 652 + 1 = 653. Prebuild the fixture rather than carrying a known-red through every gate.\r\n- **⚠ AMENDED 2026-08-22 — DO NOT PREBUILD FROM THIS BULLET'S EXAMPLE.** The line above names ONE\r\n  fixture because one fixture is what *this* wedge needed; read as the prebuild recipe it covers a\r\n  fraction of the population, and it was read that way twice on one day. **The census already exists\r\n  in IR-21 above** (`adapters/mock`: mock-session, mock-shell, capture-player, console-mode-probe ·\r\n  `crates/spt-daemon`: dispatch_fixture, service_fixture, summarizer_fixture · `crates/spt`:\r\n  translate_proof_fixture, post_step_fixture, gh_fixture, git_fixture), together with the split that\r\n  matters: **cross-package sites are the hazard members; same-package builds are guaranteed by\r\n  construction.** Field instances, both 2026-08-22 TURNKEY #212 W4: todlando's lane red on three\r\n  `spt-daemon::attach_resize_capture` cells wanting `adapters/mock`'s **capture-player** (a\r\n  cross-package member), and doyle's head gate prebuilding the remembered pair while never running a\r\n  `spt-daemon` or `spt-term` suite at all. **Prebuild `--workspace --bins`, or read the\r\n  `build_hint` the helper already composes** (`crates/spt-term/tests/support/fixture_bin.rs:42`) —\r\n  five test files gate on that panic. Neither of us lacked the census; we prebuilt from memory while\r\n  our own register held the list.\r\n- **FIXTURE PREBUILD, RECURRENCE 2026-08-29 (todlando, emission lane):** the rule was\r\n  already banked AND I am one of its authors, and I still ate three fixture reds in a row —\r\n  mock-session, then capture-player, then mock-shell — each tripping in about 0.01s with a panic\r\n  that reads exactly like a test failure. Having the rule is not the same as applying it completely:\r\n  I prebuilt from RECALL (`-p spt --bins`) rather than from the rule's stronger banked form, and the\r\n  tell is that my fix arrived in three instalments instead of once. **TWO FACES, both structural\r\n  rather than careless.** (1) THE FIXTURE MAY LIVE IN ANOTHER PACKAGE — mock-session,\r\n  capture-player, mock-shell and console-mode-probe are all `adapters/mock` (`-p mock-adapter`), so\r\n  no amount of `-p spt --bins` ever produces them. (2) ENUMERATING FIXTURES BY GREPPING THEIR\r\n  PRE-BUILD STRINGS IS STRUCTURALLY INCOMPLETE — it finds the call sites that embed a literal\r\n  `pre-build: cargo build ...` string and CANNOT find mock-shell, whose helper composes the command\r\n  at runtime (`sibling_bin(name)` → `fixture_package(name)`), so there is no literal to match. A\r\n  predicate over source text cannot see a string the program builds at runtime; same blindness\r\n  class as the emission census's TOKEN-colon-vs-TOKEN-space predicate, met twice in one session.\r\n  **CLASS FIX:** never hand-list fixtures — build the whole fixture package\r\n  (`cargo build -p mock-adapter --bins`) or `--workspace --bins` before any\r\n  `--test`/`--bins`/filtered leg. Chasing named fixtures one red at a time only ever finds them one\r\n  at a time, and each one costs a full battery run.\r\n- **Named negative + settle-class result (hertz, 2026-08-23):** current main at\r\n  `4dd699cb7867979ca0497e7c74d8d0aaf881e9e9` did not reproduce the wedge on HFENDULEAM from\r\n  isolated checkout `.worktrees/ir55-findstr-bisect`. Test binaries were freshly built before the\r\n  diagnostic population and reused for the settle sweep; the gate environment scrub was **not**\r\n  applied; the installed daemon was live. The fleet snapshot taken immediately **after**, not\r\n  during, the sweep showed BIGNET 7 nodes / 20 endpoints, SPT_MANTLE 3 / 19, SPT_DEV 2 / 19,\r\n  3-of-7 peers connected, `degraded-partial`. Four startup cells that spawn `findstr` passed alone\r\n  and reaped their observed ConPTY children; a full single-threaded run passed 663/663 with a\r\n  before/after census delta of `IR55_NEW=0`. The ratified settle-class sweep then ran five\r\n  consecutive bare `cargo test -p spt --bins` invocations: all 663/663 green in 420.35s total,\r\n  with zero `findstr.exe` residents before and after. This is a named negative data point, not a\r\n  discharge of the intermittent filing-day measurements.\r\n- **Next-wedge capture protocol — do not improvise or clean first:** preserve the exact bare\r\n  invocation and snapshot the environment (box, checkout SHA/worktree, fresh-versus-reused test\r\n  binary provenance, gate-scrub state, live-daemon state, and fleet roster); stream test output to\r\n  durable storage so the last started and completed test names identify the frontier; census\r\n  `Win32_Process` immediately before the run and again while wedged, recording each `findstr.exe`\r\n  PID, parent PID, creation time, executable path, and command line. **Do not kill any child before\r\n  the second census is banked.** The 22 residents found during the 2026-08-23 investigation were\r\n  path-verified as `C:\\Windows\\System32\\findstr.exe`, shown to predate its live runs, banked, then\r\n  reaped; the pre-sweep and post-sweep resident counts were both zero.\r\n- **Size guess:** small if one test is missing a reap or an EOF for its stand-in child; medium if\r\n  the shared PTY test scaffolding needs the reap, in which case every sibling spawning the same\r\n  stand-in wants it. The RUN-LEVEL exposure has an answer today (nextest); the LEAK itself is\r\n  still worth fixing, because a leaked child per run accumulates on any box that runs the suite.\r\n- **Gater's craft, worth more than the entry itself:**\r\n  (a) The first wedge was undiagnosable because the gate script wrote every leg as\r\n  `cargo test … | tail -N > file` — nothing reaches disk until the command completes, so a wedged\r\n  leg produces an **empty file** and the process table is the only witness. **Stream to a file and\r\n  tail the FILE.**\r\n  (b) To NAME a frontier, run `--test-threads=1`: libtest prints each test's name BEFORE running\r\n  it, so the last incomplete line is where progress stopped.\r\n  (c) **Then prove the frontier test is actually at fault by running it alone** — which is the\r\n  step this entry originally skipped, and the one that turned a wrong entry into a right one.\r\n\r\n### IR-56 — `pool-claim` harvests lane identity from CWD, not from `--pool`; a claim run from the wrong tree writes a WRONG RECORD with a success message\r\n\r\n- **Status:** BUILT 2026-08-24 for the SIGNET #218 golden batch on\r\n  `fix/ir56-pool-claim-cwd`, owned by **hertz**. Tooling/rig defect by the dispatch split. Filed by\r\n  doyle 2026-08-22 from todlando's TURNKEY #212 W4 Lane 1 field instance — the first confirmation\r\n  of the IR-42 mechanism from a LANE rather than from a source read.\r\n- **What happens:** `cargo run -p xtask -- pool-claim --pool <dir> --label <lane>` records the lane\r\n  identity it harvests from the **current working directory** — `owner_tree`, `lane_branch`, and the\r\n  base sha — not from the tree `--pool` names. Run it from the project root with `--pool` aimed at a\r\n  worktree and the record reads `owner_tree = <project root>, lane_branch = <root's branch>` while\r\n  every artifact in that pool belongs to the worktree. The verb prints its ordinary success line\r\n  naming the wrong owner, and returns 0.\r\n- **Why it is silent, which is the whole entry:** the claim verb WRITES and never adjudicates\r\n  (IR-42) — every enforcement arm lives in `crates/spt-store/build.rs` and speaks only at the next\r\n  BUILD. So a wrong record has no symptom at the moment it is created; the first signal is a build\r\n  refusal minutes later, on a lane whose `--pool` argument was correct all along. **`--pool` being\r\n  correct is not evidence the record is.** Nothing on the command line shows you cwd, which is the\r\n  one input that decided the outcome.\r\n- **Recovery is the documented hatch, and the bootstrap is why:** the claim tool builds THROUGH the\r\n  pool it is claiming, so a pool already refusing cannot be re-claimed by the ordinary route. The\r\n  refusal text says so itself — meaning the bootstrap case is known, and a wrong-cwd claim is the\r\n  ordinary way a lane lands in it.\r\n- **The rule, as a must-do:** claim from the lane's own worktree so the identity the verb harvests\r\n  is the lane's — `( cd <lane> && cargo run -p xtask -- pool-claim --pool \"$PWD/target\" … )`, or any\r\n  form that makes cwd explicit. Then READ THE PRINTED RECORD BACK and confirm `owner_tree` and\r\n  `branch` name the lane: the success line carries the record, so the check costs nothing.\r\n- **Trigger condition:** ripe now — it is a doc/UX fix on a verb we run every lane. Ripest alongside\r\n  any other `xtask` pool-verb touch.\r\n- **Size guess:** small. Either make the verb REFUSE when cwd is not inside the tree containing\r\n  `--pool` (loud, and it cannot be wrong), or print the harvested identity as a distinct confirmed\r\n  line. The refusing form is preferred: it removes the reading step rather than adding one.\r\n- **Built evidence, corrected at review:** `pool-claim` resolves the git worktree containing\r\n  `--pool` from the pool's nearest existing ancestor and compares it with the cwd worktree before\r\n  writing. An accidental cross-worktree call returns 2, names both worktrees and the remedy, and\r\n  leaves the not-yet-existing pool absent. The sanctioned sequential takeover carries an explicit\r\n  `--foreign-pool`, says that it is harvesting the arriving cwd identity, writes that identity, and\r\n  returns 0. Both poolguard refusal remedies now print that flag. An executable xtask test drives\r\n  both arms against two real temporary git repositories, pinning VERB-ADMITS-REMEDY rather than\r\n  merely testing path equality. This remains identity-harvest validation only: the claim still\r\n  writes without adjudicating admission, so IR-42's enforcement boundary remains in the build.\r\n\r\n- **Second instance 2026-09-11 (todlando, #304 product lane):** an allocation packet carried the\r\n  claim as `pool-claim --pool .worktrees/304-product/target` — correct from the repo root, WRONG\r\n  from inside the worktree, where it resolves to a nested `.worktrees/...` path. Caught within\r\n  seconds of launch, nothing written at the nested path, re-run with the absolute lane path. Rule:\r\n  an allocation names the pool by ABSOLUTE path, because the claim verb acts on where it stands.\r\n\r\n### IR-57 — an assembly pick's conflict resolution can silently DROP lines, and every gate run at assembly time is blind to it\r\n\r\n- **Status:** OPEN, owned by **doyle** (gater craft, not a code defect — no lane to dispatch).\r\n  Filed 2026-08-22 from doyle's own defect on the TURNKEY #212 assembly head.\r\n- **What happened:** assembly head `5cce533d` **did not compile**, and was carried across a session\r\n  boundary as a ready head with \"treqs exit 0\" attached to it. `crates/spt-store/src/access.rs` had\r\n  an unclosed `mod tests`: the cherry-pick of the #206 lane commit `b2194aa9` conflicted against the\r\n  #209 test block — both add functions to the same region, and the two sides share the trailing\r\n  `);` / `}` / `}` — and the resolution deleted the markers without restoring the FIRST side's\r\n  function closer. Exactly two lines lost: `        );` and `    }`.\r\n- **Every instrument in the assembly path reported success:** `git cherry-pick` completed with no\r\n  conflict remaining; `traceable-reqs check` returned 797/797, 0 findings, exit 0 — **it parses\r\n  tags and never invokes the compiler**; and the lanes themselves were green and stayed provably\r\n  clean (the #206 lane's brace balance is correct at all five of its commits). **Lane-green plus\r\n  conflict-free is not a claim about the assembled head.** Same lesson as the #182 v2 assembly\r\n  (`E0425`×4) by a different mechanism: that one was a semantic composition break between two\r\n  correct hunks, this one is a fidelity LOSS during resolution.\r\n- **Two must-dos, both cheap:**\r\n  1. **Compile the assembled head before it is handed anywhere — including forward to your own next\r\n     session.** A head is not ready on a treqs exit; it is ready on a build. Any sentence carrying a\r\n     head sha to another agent must name the instrument that proved it.\r\n  2. **Audit pick fidelity on CHANGED LINES for every pick on the chain**, not just the one that\r\n     tripped you: hash `git show --format= <sha> | grep -E '^[+-]' | grep -vE '^(\\+\\+\\+|---)'` for\r\n     the lane source and for the pick, and compare. Whole-diff comparison is useless here — hunk\r\n     headers and context legitimately drift once the head's copy of the file has moved.\r\n- **Read COUNT and HASH together, because they fail in opposite directions.** Of 24 picks on this\r\n  chain two did not match. `b2194aa9 → 4d6deed1` differed in COUNT (302 lane / 300 pick by the header-excluding pipeline above; **this entry originally cited 310/308, which is the RAW `^[+-]` count INCLUDING the 8 `+++`/`---` header lines of its 4 files** — the figures were taken without the second grep the entry itself prescribes. The DELTA is 2 under either meter, which is why the wrong figures never surfaced: they supported a correct conclusion, so nothing pressed them. Corrected todlando 2026-08-29, measured both ways in-tree) — the real\r\n  defect. `f27f15c6 → 5865cc98` had the SAME count and a different HASH — benign: a `CONTEXT.md`\r\n  paragraph the head had already amended for #209, whose merged result correctly carries both lanes'\r\n  sentences. A count check MISSES the first class entirely; a hash check FLAGS the second as if it\r\n  were a defect. Neither alone classifies a pick.\r\n- **Repair shape used, recorded because it is the cheap one:** reset to the commit before the bad\r\n  pick, re-pick the lane source, resolve the same conflict correctly, then replay the remaining picks\r\n  in chain order with the fidelity check on each. Verify the repair changed nothing else with a\r\n  WHOLE-TREE diff against the old head — it must show exactly the restored lines and no other file.\r\n  Where a later pick re-conflicts, check its pre-pick blobs against the old chain\r\n  (`git rev-parse <old-pick>~1:<file>`); if they match, the old chain's post-pick blob is a\r\n  transferable, already-reviewed resolution.\r\n- **AND GATE THE REPAIR'S OWN SUBJECT.** The rebuilt head passed six legs — clippy `-D warnings`,\r\n  sweep 660/660, treqs 803/803, xtask OK — while the restored lines live in `spt-store`, whose LIB\r\n  tests `-p spt --bins` never runs. Six greens, and not one executed the function the repair\r\n  restored; it was proven to COMPILE and assumed to PASS. Proven afterwards by name (4/4) and by the\r\n  full `spt-store --lib` suite (519/519). **A repair's gate must include the suite that owns the\r\n  repaired file**, which is not necessarily the suite the head gate runs.\r\n- **FIRST LIVE CATCH, and it was the author's own resolution (2026-08-29, one hour after the verb landed):** rebasing the IR-59 rider over the IR-57 rider produced four conflicts — three additive keep-both, one usage line both sides had edited. `xtask pick-audit` read the rebase as **LOSS, 282 lane / 280 pick**. The two missing lines were a `[[requirements]]` header and its blank line in `traceable-reqs.toml`, so `id = REQ-DISK-FLOOR-PREFLIGHT` landed INSIDE the previous table as a duplicate key: **`traceable-reqs check` exit 2, the registry unparseable, every reading after that edit checking nothing**. Restored, the same audit reads **DRIFT 282/282** whose one differing line is the usage string whose base copy legitimately gained the other verb — both verdi…\n- **FIRST REAL-ASSEMBLY USE (2026-08-29, #241 emission head, ASM-241-GATE-VERDICT.md):** `xtask\r\n  pick-audit --range 57a0d27c..HEAD --lane 4d6007ac..d0fdd58d` over 6 picks — **5 MATCH\r\n  (digest-identical), 1 LOSS, 0 drift, 0 unclassified**, exit 1 forcing the accounting. The LOSS\r\n  was exactly the one human-resolved conflict (`cfb9d9f8 <- 10f12e4c`, count 432/402), and the\r\n  delta RECONCILED to the resolution rather than assumed: lane stat 15 files/235+/197- vs pick\r\n  14 files/205+/197-, difference byte-for-byte the deliberately-dropped 30-line interim IR-69\r\n  register block superseded by main's consolidated entry. No false positives, no silent pass.\r\n  Entry stays OPEN as living procedure; both live uses (the rebase catch above, this assembly)\r\n  produced the verdict classes in the order the entry predicts.\r\n- **Trigger condition:** ripe at the next assembly — this is procedure, and its cost is one command\r\n  per pick.\r\n- **Size guess:** small as a scripted check in `xtask` (fidelity audit over a pick range); zero as\r\n  discipline, which is how it is being applied now.\r\n\r\n### IR-58 — a `[[bin]]` grep is not a census: cargo AUTODISCOVERS `src/bin/*.rs` targets, and a hand-built bin list produced a confident false \"this bin does not exist\"\r\n\r\n- **Status:** OPEN, unowned. Filed by doyle 2026-08-22; **its original filing was WRONG and is\r\n  retracted in full below.** The entry is kept because the way it was wrong is the finding.\r\n- **RETRACTED CLAIM, stated plainly so no reader acts on it:** this entry first said that\r\n  `crates/spt/Cargo.toml:18-21` and `crates/spt/src/cli.rs:30355` forbid a bin-name collision with\r\n  `xlate_choreo_fixture`, \"a bin that does not exist\", and that spt-daemon's third helper had been\r\n  renamed to `summarizer_fixture`. **`xlate_choreo_fixture` EXISTS** — at\r\n  `crates/spt-daemon/src/bin/xlate_choreo_fixture.rs`, verified at the assembly head. The collision\r\n  rule's counterpart is real, both prose sites are CORRECT, and IR-21's original table row was\r\n  correct too; it merely predated `summarizer_fixture`. Nothing in that prose needs fixing.\r\n- **How the false claim was produced, which is the entry:** the census was built by grepping\r\n  `^\\[\\[bin\\]\\]` across `Cargo.toml`s. **Cargo AUTODISCOVERS `src/bin/*.rs` as bin targets with no\r\n  stanza at all**, so a stanza grep cannot see them, and it fails SILENTLY — it returns a clean,\r\n  well-formed list that is simply short. From that list it read as established fact that a named bin\r\n  had been renamed away, and that \"fact\" was then written into a register table, an IR entry, and a\r\n  message to the builder. **A pattern-built population encodes the pattern's assumption; the count\r\n  looks like a census and is a property of the pattern.**\r\n  (Found by todlando, resolving one of doyle's figures against his own tree under the pointer rule.)\r\n- **A CENSUS IS ALSO A PROPERTY OF A TREE.** Stanza counts differed legitimately across trees the\r\n  same hour — 13 at the assembly head, 11 at `dc1c7532` — because `summarizer_fixture` exists at one\r\n  and not the other. Two correct censuses of the same workspace disagree unless each names its sha.\r\n- **The must-do, and it removes the list rather than lengthening it:** never hand-maintain a bin\r\n  roster. Run `cargo build --workspace --bins` and let cargo enumerate its own targets — the same\r\n  enumeration the test harness resolves against, so it cannot drift from what a fixture lookup\r\n  expects. Stanza-derived lists, remembered pairs, and register tables are all the roster problem at\r\n  different depths; only cargo's own enumeration is the population.\r\n- **Kin:** IR-55's amended prebuild bullet (prebuild the census, not a remembered pair) and IR-42\r\n  (a verb that writes without adjudicating). The shared shape is an instrument returning an orderly\r\n  answer about a set it never fully saw.\r\n- **Trigger condition:** ripe on any `xtask` check work — a duplicate-bin-name check over cargo's\r\n  target enumeration (NOT over manifest stanzas) is a handful of lines and cannot go stale.\r\n- **Size guess:** small. The prose fix originally proposed here is WITHDRAWN — there was nothing\r\n  wrong with the prose.\r\n\r\n### IR-59 — pool arithmetic: this box holds TWO cold pools, not four; and a build that exhausts the volume reds as a LINKER defect that names no disk\r\n\r\n- **Status:** OPEN, unowned — it is arithmetic and discipline, not a code lane. Filed by doyle\r\n  2026-08-22 from a live disk-floor abort during the TURNKEY #212 W4 gate; footprint figures measured\r\n  by todlando the same hour.\r\n- **v0.69.0 release close, 2026-09-11 (deployah, source record releases#294 comment\r\n  5628538587):** the first broad version/manifest battery failed to LINK (`LNK1180`,\r\n  `LNK1108`, cargo exit 101), with **15,777,792 bytes free** measured at recovery. It produced\r\n  no test verdict. The run selected the workspace's test binaries on the Cargo side even\r\n  though the nextest filter did not need the e2e population; the replacement selected `--lib`\r\n  for `spt-daemon`, `spt-runtime`, `spt`, and `xtask`, and passed **121/121** in 8.445 s.\r\n  Root-target reclamation restored **66,926,968,832 bytes free**; the subsequent CI Windows\r\n  unit step passed **3167 tests**, then its END floor refused at **15,360,114,688 bytes**\r\n  against **34,359,738,368**. That is an observed resource-red AFTER passing tests, not an\r\n  explanation of the earlier PR unit-step red whose log was unavailable. A second, classified\r\n  CI `target/debug` reap, with runner intake stopped by the operator, increased free bytes\r\n  **14,892,281,856 -> 78,994,501,632**. Runner service restored afterward. Publication used a\r\n  preserved signer, not a Cargo rebuild into the cleared pool. These are two measured recoveries,\r\n  not a durable capacity fix; IR-46/59/86 remain the next gate-driver capacity rider.\r\n- **SECOND FACE, measured 2026-08-23/24 (WAX-SEAL #21 W2 gate, doyle — the violator this time):**\r\n  both predicted mechanisms fired at once, WITHOUT the floor guard because the gate legs ran as a\r\n  plain script. (1) doyle minted a THIRD cold pool (gate rig) while todlando's lane pool was LIVE —\r\n  the two-pool arithmetic, violated by the gater. (2) The lane pool had silently accumulated\r\n  **104.8 GB** over repeated full-workspace sweeps (nothing bounds or even measures a pool's\r\n  accumulation until the volume dies). The volume hit **3 MB free**; the reds wore exactly the\r\n  entry's predicted costume — `LNK1318: Unexpected PDB error; LIMIT (12)` naming no disk — plus a\r\n  second face worth keeping: `traceable-reqs check` died as a PANIC printing to stdout\r\n  (`os error 112`), so a REGISTRY gate red can also be the disk's. Both gate verdicts VOIDED\r\n  (clippy's full compile had exited 0 before space died — the code was never the question).\r\n  Recovery measured: gate pool reap 9.6 GB, lane pool clean 100.2 GB, drive back to 109.6 GB free.\r\n  **Remedies adopted at the incident:** the gate never mints its own pool while a builder lane is\r\n  live on the box — it takes the lane pool over SEQUENTIALLY at pool-release (warm, loud, the\r\n  releases#103 pattern); and gate/lane scripts get the disk-floor preflight the golden runner\r\n  already carries (this entry's part 2, still unbuilt).\r\n- **THIRD FACE, measured 2026-08-24 (WAX-SEAL #21 golden window, doyle):** two new mechanisms, both\r\n  about the REMEDY rather than the red. (1) The wax-seal-w1 lane pool **re-accumulated to 152–169 GB\r\n  (two meters, IR-46 caveat) within ONE DAY of the 08-23 clean** and rode the volume back down to\r\n  4.92 GB free — a reap is an instant, not a state; nothing yet bounds a pool between reaps.\r\n  (2) **The remedy itself arrived garbled through relay:** the golden push was held \"waiting on the\r\n  IR-59 reboot\" when this entry prescribes no reboot anywhere — tens of releases have shipped without\r\n  one; the operator refused the premise and the register's own recorded remedy (reap finished-lane\r\n  pools) cleared it in ten minutes. A remedy relayed as a DIFFERENT remedy is the relay trap wearing\r\n  infra clothes: the entry is the author — read it before adopting a hold. Recovery measured: five\r\n  finished-lane pools reaped after ancestry classification (`git cherry` catches rebased lands that\r\n  a plain `merge-base --is-ancestor` calls unlanded — gate-w4l1's 90.9 GB pool was reapable only by\r\n  that meter), 4.92 → 260.88 GB free (~256 GB free-delta vs ~270–287 GB sum-of-lengths). Two main\r\n  runs red inside the low-disk window (09:17Z/09:41Z) were re-run, not re-read, per this entry's\r\n  must-do.\r\n- **FOURTH FACE, measured 2026-08-24 same day (SIGNET #218 W2 gate, doyle — the gater's own pool\r\n  this time):** the MAIN pool went **13.7 GB → 158.3 GB in ONE DAY** absorbing four full gate\r\n  batteries across two lane tips, and dragged the volume to **18 GB free mid-gate** — so the\r\n  entry's mechanism is not a lane-pool problem, it is EVERY pool under repeated full sweeps, the\r\n  gate rig included. Two riders worth the ink: (1) the golden runner's **free-space floor step\r\n  produced its first live catch** — a thin CI leg refused at 14:14 local over exactly this window\r\n  with zero test signal, and the register's re-run-not-re-read rule resolved it in one command;\r\n  (2) the reap-and-rebuild trade (\"cleaning a live pool buys one window at rebuild price\") was\r\n  taken deliberately mid-gate and cost ~35 minutes cold — cheaper than one uninterpretable red.\r\n  A red measured at 18 GB free in this gate got NO read at all, and the next sweep's red was a\r\n  DIFFERENT test: low disk manufactures random victims before it manufactures link errors.\r\n- **The event:** a gate's preflight refused with `GATE_ABORTED_DISK_FLOOR` at **4.75 GB free on a\r\n  1863 GB volume**. Four cold pools plus the milestone head's pool were standing at once. The floor\r\n  guard did its job — without it a full workspace build would have started with under 5 GB of\r\n  headroom and produced a red belonging to nothing.\r\n- **THE ARITHMETIC, and it corrects the intuition that worktrees are the cost.** Measured across the\r\n  whole `.worktrees` tree: **45 worktrees = 0.79 GB total** (~18 MB each). **3 pools = 130.45 GB.**\r\n  Worktrees are **0.6%** of the footprint; pools are **99.4%**. **One cold pool is worth roughly 2,500\r\n  worktrees.** A rule keyed on worktree count would cost a day of `git worktree remove` work for under\r\n  a gigabyte, risk removing a lane someone still wants, and leave the lever untouched.\r\n- **THE CEILING, as arithmetic rather than hygiene:** at **45–75 GB per cold pool** on this workspace\r\n  against a **40 GB floor**, this box supports **TWO live pools comfortably, THREE only if one is\r\n  small**. The two rules that already exist need no replacement, only this number attached:\r\n  - **Reap a pool when its lane is finished** → 45–75 GB back immediately.\r\n  - **Do not run two builds at once** → not only the contention argument, but **75–150 GB of\r\n    simultaneous allocation** against that floor.\r\n- **A FULL VOLUME REDS AS A LINKER DEFECT.** `LINK: fatal error LNK1318: Unexpected PDB error`\r\n  (variously `OK (0)` or `LIMIT (12)`), often beside `LNK4209: debugging information corrupt`. It\r\n  reads as a corrupt artifact or a broken toolchain and is neither — it is the linker unable to grow\r\n  a large `.pdb`. **Nothing in the failure text says \"disk\".** Do not key recognition on the\r\n  parenthesised code; it varies.\r\n- **THE DANGER WINDOW IS THE TAIL OF A COLD BUILD, not a steady state you can check once.** The\r\n  2026-08-22 instance died at the link of `spt` — the last and largest artifact of a **74 GB** cold\r\n  pool — while that same build was draining the volume out from under itself. A free-space reading\r\n  taken before the build would have looked fine.\r\n- **Positive tell, with its own refutation attached:** `traceable-reqs check` alone surviving a leg\r\n  table is suggestive, because it is the only leg that never links. It is a POSITIVE tell ONLY — a\r\n  full disk can red before any link step, so the signature's ABSENCE clears nothing.\r\n- **THE FALSIFIER IS FREE SPACE AT THE TIME OF THE RUN**, not the shape of the leg table.\r\n- **Must-do, both cheap:**\r\n  1. **A free-space reading goes in the FIRST LINE of any build-failure report** — not in the\r\n     controls, not as a follow-up. Two agents spent hours on a mechanism for this failure and neither\r\n     ran `df`; the falsifier was one command away throughout.\r\n  2. **Rig and gate logs should record free space at run start.** Today they do not, which makes \"was\r\n     the disk full\" **unanswerable after the fact for every red already in hand**. Any red produced\r\n     under ~1 GB free is UNINTERPRETABLE and must be **re-run, not re-read**.\r\n- **Measurement caveat, observed twice in one hour:** sum-of-file-lengths and free-space delta\r\n  disagree by several percent when anything else on the box is writing (98.07 GB of subtrees → 92.25\r\n  GB reclaimed; 47.28 GB → 40.81 GB). Report BOTH, derive neither from the other, and treat any single\r\n  free-space number as an instant rather than headroom — see IR-46.\r\n- **FIFTH FACE, measured 2026-08-29 at the CONDUIT #236/v0.65.0 cut (deployah):**\r\n  the finished milestone's sequential lane-sharing accumulated **140.51 GB**, while a freshly\r\n  rebuilt pool measured **7.78 GB** — about **18× one build's working set** retained across lane\r\n  hand-offs with no reap between them. This is the budgetable rate behind that cut's disk-floor\r\n  red: sequential execution prevents concurrent ownership corruption, but it does not bound\r\n  historical artifacts inside the shared pool. Treat takeover and reclamation as separate\r\n  operations; a pool may be safe to reuse and still be too large to keep.\r\n- **SEVENTH FACE, measured 2026-08-30 (v0.67.0 milestone close — the PARALLEL-LANE fill\r\n  rate):** the #23 wave arc drove C: from ~240 GB free to **0.01 GB in ~3.5 hours**: four\r\n  concurrent/serial lane+gate pools totalled **236.6 GB** (ns23-w1 87.7 + ns23-113 72.3 +\r\n  gate rig 57.3 + ns23-w3 19.1) — effectively the entire ir57 reclaim re-consumed inside one\r\n  milestone's build window. The head gate and two thin-CI runs redded with the entry's exact\r\n  costume (\"could not compile\" + treqs panic, zero disk words) at 0.01 GB and all re-earned\r\n  green after reclaim (+186.6 GB, finished-lane targets only, single-actor rule held under\r\n  racing consent). Budget rule this face adds: a MULTI-WAVE milestone on one box books\r\n  ~60-90 GB PER LANE-PLUS-GATE cycle, so the pool budget is per-wave, not per-milestone —\r\n  reap each wave's pool at its LAND, not at the milestone party (the party inherited only\r\n  ~58 GB because the emergency had already forced the other ~179).\r\n- **SIXTH FACE, measured 2026-08-30 (#242 golden r4, Windows test job, LNK1318 at the PDB\r\n  write):** the floor is asserted ONCE at job START, but the job's internal LOW-WATER sits at its\r\n  LAST heavy step — the docs-drift build, ~28 minutes in. r4's floor read 65.1 GiB honest at\r\n  23:07; the box was at ~37–39 GB by the 23:35 link failure. LNK1318 on PDB write = this entry's\r\n  documented low-disk costume; the incremental-corruption candidate was retired by preservation\r\n  snapshot (no xtask state existed at failure). **Durable fix = a floor RE-READ (or reclaim)\r\n  immediately before the docs-drift build** — the WITHIN-job sibling of the across-job\r\n  read-after-checkout fix, rides the next workflow commit. Riders: incremental hygiene as\r\n  disk-pressure maintenance (the dir measured 4.56 GB), and the box's **~51 GB non-recovering\r\n  post-run consumption** is this entry's pool-weight face — classify at the IR-14/26/27/49 audit\r\n  slot (composed this sweep).\r\n- **Composed for next intake (doyle, v0.65.0 close):** the still-open log-the-floor build half\r\n  rides with [[IR-57]]'s scripted pick-fidelity audit as the next milestone's two tooling riders.\r\n- **Trigger condition:** ripe now for the log-the-floor half (it rides any gate-script or CI touch);\r\n  the arithmetic is discipline and applies immediately.\r\n- **Size guess:** small — one line in each rig/gate preflight to record free space alongside the\r\n  existing floor check.\r\n\r\n### IR-60 — a wrapper that CAPTURES a leg's exit status ends with the capture, so the wrapper's own status is the capture's, not the leg's\r\n\r\n- **Status:** OPEN, unowned — script-shape discipline, not a code lane. Filed by doyle 2026-08-22\r\n  during the TURNKEY #212 W5 lane; mechanism measured by todlando, who reported it first as a\r\n  possible harness misreport and then RETRACTED that reading himself on a minimal probe.\r\n- **v0.69.0 recurrence, 2026-09-11 (deployah, own withdrawal):** `NEXTEST_EXIT=0` and the task\r\n  completion's exit 0 both described the wrapper/truncation path, not Cargo's **101**.\r\n  `PIPESTATUS` was read outside the executing subshell, so the named verdict measured `tail`.\r\n  Both green-looking receipts were withdrawn; the raw failed-link output was retained.\r\n  **An exit FILE alone is insufficient if its writer captures the wrong process.** Capture\r\n  immediately inside the shell executing the producer, before any other command replaces the\r\n  status, write that value to the leg's file, and propagate it when wrapper status is reported.\r\n  The replacement battery's own file read 0, with 121 tests actually run. Keep this entry OPEN:\r\n  corrected execution of one driver does not make the faulty wrapper shape unreachable.\r\n- **The reading that started it:** a background leg was summarised as `exit code 0` while the leg's\r\n  own exit file read `100`. Reported as-is, that is a task runner lying about a red — the worst\r\n  possible direction for a purposeful-red claim, since it would turn two reds that DID fire into two\r\n  reds reported as not having fired.\r\n- **The measurement, minimal and on this box:**\r\n\r\n      ( exit 100 ); echo $? > probe.exit; FINAL=$?\r\n      leg status captured to file : 100\r\n      wrapper's own final status  : 0\r\n\r\n  The wrapper's shape is `( cd <lane> && cargo nextest ... > leg.raw 2>&1 ); echo $? > leg.exit`.\r\n  **The last command is the `echo`, which succeeds**, so the wrapper genuinely exits 0 while the leg\r\n  genuinely exited 100. THE RUNNER TOLD THE TRUTH ABOUT THE WRAPPER. There is nothing to file against\r\n  the task runner, and it would have been filed.\r\n- **The class, and this is why it is worth an entry rather than a fix:** it is the truncation-pipe\r\n  family — the meter measured something real, it just was not the thing about to be quoted. **Three\r\n  shapes now share ONE trigger, and the trigger is not \"is this a pipe\":**\r\n  1. a truncation pipe (`cmd | tail`, `cmd | head`) — `$?` measures the truncator, and `head` closing\r\n     the pipe can MANUFACTURE a status (SIGPIPE → 101), so `PIPESTATUS` is not protection either;\r\n  2. a flattened `$?` read after any intervening command;\r\n  3. **a wrapper whose last command is the capture itself.**\r\n  **The trigger in all three is the REPORTING** — every instance happened while trimming or capturing\r\n  output in order to QUOTE it as evidence.\r\n- **The practice that held, and the one to keep:** the leg's own file is the leg's verdict. Both reds\r\n  were real, and the only reason that was knowable is that every leg wrote its exit to its own file\r\n  rather than to the wrapper's status.\r\n- **Remedy, in preference order:** (1) never read a wrapper's status as a leg's — read the leg's exit\r\n  FILE, which the per-leg rule already requires; (2) if a wrapper's own status must be meaningful,\r\n  end it by re-raising the captured status (`exit \"$(cat leg.exit)\"`) or set the status before the\r\n  capture is the last word; (3) for anything that becomes evidence, redirect to a file and read the\r\n  file.\r\n- **Trigger condition:** ripe now — it rides the next gate-script touch, and the gate scripts in this\r\n  milestone already write per-leg exit files, which is what makes this discipline rather than debt.\r\n- **Size guess:** small — a convention line in the gate-script preamble; no product code.\r\n\r\n### IR-61 — spacerun's test-module skip carries a SECOND literal tracker; the two answers can drift, and today only a cell stands between them\r\n\r\n- **Status:** OPEN, unowned, accepted-with-mitigation. Filed by doyle 2026-08-22 at the TURNKEY #212\r\n  head gate, as the named residual of the latch repair (the repair itself rides the milestone).\r\n- **What the debt is.** `crates/xtask/src/spacerun.rs` now skips a column-0 `#[cfg(test)]` module by\r\n  BRACE DEPTH and resumes after its close, rather than latching the scan to end-of-file. Counting\r\n  braces safely means knowing when a brace is inside a string, a raw string or a char literal — and\r\n  the scanner ALREADY tracks literals for its rendering pass. It does not reuse that tracking. There\r\n  are now TWO answers in one file to \"am I inside a literal\", and **two answers to one question is a\r\n  disagreement waiting for a reader who fixes one of them.**\r\n- **Why it was accepted rather than refactored on the spot, stated so the trade is auditable:** the\r\n  two trackers answer genuinely different questions — the rendering walk is PER LINE and forward\r\n  from an opening quote (\"where does this literal start and end\"), while the skip needs \"am I inside\r\n  a literal right now\" carried CONTINUOUSLY across lines. Unifying them is a real refactor of a check\r\n  that is already gated, already carries five fixed defects, and sits on the tree being handed to\r\n  golden. The narrow change with an OBSERVABLE failure mode beat the correct-shaped change with a\r\n  wide blast radius, on that tree, on that day.\r\n- **The mitigation, and its exact limit.** Three brace cells fail the moment the two trackers\r\n  disagree about a raw string, a normal string or a char literal, plus a cell that reds when the skip\r\n  stops consulting a literal tracker at all (`match lit` -> `match Lit::None`). **That is a cell\r\n  standing in for a refactor.** It catches drift in the three forms it names and nothing else — a\r\n  fourth literal form, or a change to only one tracker in a form neither cell covers, passes.\r\n- **The general shape, which is why this is a register entry rather than a comment:** a check whose\r\n  own correctness depends on a second implementation of a thing it already implements is one\r\n  refactor away from the defect class it exists to prevent. This same file has already produced\r\n  three instrument defects (an indented-marker latch, a column-0 latch, and a suppression that\r\n  decided what got PARSED rather than what got REPORTED). The pattern is not carelessness; it is a\r\n  scanner accumulating special cases.\r\n- **Trigger condition:** the next SUBSTANTIVE change to spacerun's scanning — any new skip, any new\r\n  literal form, any change to either tracker. At that point unify, rather than adding a third answer.\r\n- **Size guess:** small to medium — one continuous literal-state walk serving both the render pass\r\n  and the skip, with the existing corpus and brace cells as the regression net.\r\n\r\n### IR-62 — an e2e daemon binds well-known ports and collides with the resident fleet on shared runners\r\n\r\nFiled 2026-08-23 (doyle), from the #212 r2 golden's Windows Phase A red — one witnessed\r\ninstance, mechanism verified from the run's own capture, filed on the mechanism per the\r\nregister's standard.\r\n\r\n**Mechanism.** `endpoint_autostart_e2e::saved_endpoint_replays_on_daemon_restart` failed its\r\nown PRECONDITION (\"daemon B must come up with a fresh brain\") because daemon B's broker came up\r\ndegraded: `NODE_KEY_FAIL: identity unavailable` (net-less broker, no retry) and\r\n`DOCS_SERVER_BIND_FAIL` port 5474 `os error 10048` — the docs port was held by a CO-RESIDENT\r\ndaemon. HFENDULEAM is live infra: the resident fleet's daemon legitimately holds well-known\r\nports, and any e2e that brings up a daemon with default port bindings is in a race with it BY\r\nCONSTRUCTION. An isolated SPT_HOME isolates the store and broker socket, NOT globally-numbered\r\nTCP ports.\r\n\r\n**Classification history.** r2: red (35.4s, precondition panic). Run 1 and r3 on the same box:\r\ngreen. Folded into r3 under a pre-registered predicate (reds twice → dedicated triage); it\r\ngreened, so this stays an environment-shaped intermittent, NOT a product defect and NOT\r\nclosed — the collision window is real and will re-fire under the right co-residence timing.\r\n\r\n**Remedy direction (not built).** Test daemons should bind ephemeral/rig-scoped ports for\r\nevery advisory surface (the docs server is advisory — a bind failure should degrade the rig\r\nloudly, not poison an unrelated cell's precondition), or the precondition should name the\r\nport-collision cause distinctly so the red self-classifies. Either lane is test/CI work\r\n(hertz's), triggered the next time this class fires anywhere.\r\n\r\n**Kin.** IR-51 (e2e daemon net-enabled on real interfaces — hermeticity is disk-deep only);\r\nthe known not-ours red classes list in the #212 hand-off.\r\n\r\n**BUILT 2026-08-24 (hertz, SIGNET #218 batch; PR #158).** The class fired its second witnessed\r\ninstance the same day — doyle's W2 gate rig, `engine_room_bringup_e2e` precondition panic with\r\nthe IR-50 panel naming `DOCS_SERVER_BIND_FAIL` port 5474 `os error 10048` — which armed this\r\nentry's own trigger. Hertz repro'd deterministically (held the port; brain still reached\r\nBRAIN_UP), pre-ranked three mechanisms before probing, and built the ephemeral-advisory form:\r\nrig-only `SPT_TEST_EPHEMERAL_ADVISORY_PORTS=1` makes the daemon's docs listener bind port 0\r\n(production config/`SPT_DOCS_PORT`/docs-url untouched; the flag matches the literal \"1\" only).\r\nThe golden workflow's test job sets it globally on both self-hosted legs, the standalone ER rig\r\nsets it too. Scope note kept honest per his own ranking: the docs collision is retired; if a\r\nco-diagnostic bind elsewhere still poisons a precondition, that is a residual face of THIS\r\nentry, not a closed question.\r\n\r\n### IR-63 — suite-mix sweeps leak job-escaped autostart daemons that LOCK the pool's spt.exe; and the same box conditions manufacture one random victim per sweep\r\n\r\n- **Status:** OPEN, mitigated-by-rig-step — the reap is adopted discipline, not yet construction.\r\n  Filed by doyle 2026-08-24 at the SIGNET #218 gates; first measured by todlando the same day\r\n  (his W1 build: four reap rounds of 2, 8, 1, 1 processes, count-by-path stated each round).\r\n- **Mechanism, two faces of one condition:** (1) e2e sweeps that exercise autostart leave\r\n  job-escaped daemons running `target/debug/spt.exe`; the NEXT build or `xtask check` then dies\r\n  on `os error 5` removing the exe — a rig red wearing a build defect's clothes. nextest's own\r\n  `leaky` flags corroborate (4–8 per sweep measured). (2) The same co-residence (leaked daemons +\r\n  resident fleet + runner traffic) manufactures ONE red per full sweep with a DIFFERENT victim\r\n  each time: doyle's W2 gate measured FOUR distinct one-off victims in four same-sha sweeps\r\n  (ER bringup, composite+bootstrap pair under CI load, resident_service, brain_resume), every\r\n  one green alone and/or in a sibling sweep. The e2e-leaked-daemons rule holds: a different test\r\n  dying each run on one sha is ONE environment cause, and hardening members never closes it.\r\n- **Mitigation adopted (rig step, both todlando's lanes and doyle's gate runner):** reap\r\n  `spt.exe` BY PATH (`*spt-core\\target*`) before EVERY cargo invocation and after every sweep;\r\n  report the count each time so a zero is a claim, not silence.\r\n- **Remedy direction (unbuilt):** the durable form is construction, not discipline — either\r\n  nextest wrap/xtask verb that performs the by-path reap as a pre-step on this box's rigs, or\r\n  autostart e2es gain teardown that provably outlives job escape (kin IR-38's built wedge-namer,\r\n  IR-62's ephemeral ports which retire one collision axis, IR-35's victim-rate ledger).\r\n- **THIRD FACE, measured 2026-08-30 (doyle, ir57/asm-241 reaps):** the leaked population is not\r\n  only daemons — battery legs leave ORPHANED HEADLESS `conhost.exe` processes whose CWD sits in\r\n  the worktree's `crates/spt-daemon` (where the leg ran), and a CWD pin blocks `Remove-Item`/\r\n  `git worktree remove` on the whole tree with \"being used by another process\" naming the DIR.\r\n  This is the mechanism behind every recent \"handle-pinned, retry later\" worktree removal: 31\r\n  such conhosts found at once (Aug 26–29 vintages) pinning FIVE dead worktrees. cargo/rustc\r\n  absence does NOT clear the suspect list — the conhost outlives its client. Holder census\r\n  tool: a ~30-line NtQueryInformationProcess CWD probe (PEB→ProcessParameters→CurrentDirectory)\r\n  over all pids, filtered on the path — names every holder in one pass where no handle.exe\r\n  exists. 13 killed scoped to the two consented reaps; 18 remain pinning gate-w1-a8f04aff (12),\r\n  io-parser-w1 (5), gate-w1-786d2381 (1 after kills) — sweep them at the IR-14/26/27/49 audit\r\n  slot before those removals.\r\n- **LANE-LINKED 2026-08-30 (#242 close sweep):** hertz's queued daemon-leak fixup lane carries\r\n  this entry (brief cites IR-7/17/20/34/35/63); leaves the register when that lane lands.\r\n- **Trigger condition:** next rig/gate-script construction touch, or the first golden red that\r\n  classifies to face (1).\r\n- **Size guess:** small-medium — one wrapper seam plus adopting it in the gate/lane scripts.\r\n\r\n### IR-64 — HFENDULEAM's disk floor is set by non-CI bulk: ~845 GB of operator payload leaves the golden box ~2 GB of slack against its own 32 GB preflight\r\n\r\n- **Status:** OPEN · **Origin:** doyle, v0.63.0 close sweep 2026-08-26; mechanism first measured\r\n  at the FIELD-SEAL golden window (deployah's IR-31 fifth addendum carries the POOL side of the\r\n  same event by agreed division — this entry is the OTHER reservoir, deliberately not his).\r\n- **Mechanism:** the 1.86 TB C: carries ~614 GB Steam + ~230 GB Downloads (operator payload, not\r\n  CI state). With that floor fixed, normal lane traffic alone walks the box under the 32 GB\r\n  golden preflight — a full-sweep pool WEIGHS ~90–112 GB steady state (IR-59's measurement) and\r\n  five FIELD-SEAL lanes cost 148.48 GB (IR-31 fifth addendum), so ONE milestone's pools exceed\r\n  the entire free margin. Reaping buys windows, not headroom: deployah measured free fall\r\n  167 → 108 GB within hours of his reap, ~59 GB re-consumed by lane builds. The recurring shape:\r\n  every milestone pays a reap-and-measure tax to rent space the box does not structurally have.\r\n- **Why register-worthy rather than \"clean up more\":** agent-side discipline (IR-31's budgeting,\r\n  pool reaps, teardown steps) is already adopted and still only rents windows — the reservoir\r\n  that would durably move the floor is operator-owned bulk no agent may touch. Naming it here is\r\n  the boundary: agents keep budgeting IN POOLS (not GB); moving Steam/Downloads (or adding a\r\n  disk, or pinning golden to a box without operator payload) is an OPERATOR decision this entry\r\n  exists to put in front of them once, with numbers, instead of re-deriving the floor each cut.\r\n- **Ripe when:** operator rules on the bulk (move/expand/accept-the-tax), OR the first golden\r\n  that dies at the 32 GB preflight despite adopted pool discipline (IR-59's LNK1180-class red).\r\n- **Size:** zero code; one operator decision + at most a runbook line naming the chosen floor.\r\n\r\n### IR-65 — kitsubito kernel-audit backpressure: a tailscale-snap AppArmor denial storm + no auditd turned the default audit backlog into a CI-wide stall amplifier (REMEDIATED AT BOX; re-check triggers named)\r\n\r\n- **Status:** REMEDIATED-AT-BOX 2026-08-25 (doyle, operator-authorized root — ruling pinned\r\n  releases#225 comment 5418800776); entry stays OPEN as the re-check record because the storm\r\n  SOURCE persists and two named events can silently revert the fix.\r\n- **Mechanism:** `snap.tailscale.tailscaled` (1.92.5) polls /proc and takes an AppArmor\r\n  ptrace-read DENIED per poll — a continuous kernel-audit record storm scaling with process\r\n  count (spawn-heavy serialized CI legs amplify their own storm). With NO auditd installed the\r\n  records rode printk (kauditd throttling) and the 8192 kernel backlog overran\r\n  (lost=1,537,743); the default `backlog_wait_time` 60000ms turns a full backlog into A 60s\r\n  SLEEP INSIDE ANY AUDITED SYSCALL — the broker dispatch stall that stretched IR-30's\r\n  Linux-face race window (see IR-30's Linux-face addendum; deaths clustered 59–63s ↔ this\r\n  knob's value).\r\n- **Remediation (verified at the EFFECTIVE layer, not the fragment):** auditd installed +\r\n  active (storm consumed, backlog drains to 0, lost flat), backlog_limit 32768,\r\n  backlog_wait_time 0 (full backlog may DROP, never STALL). ⚠ THE TRAP PAID FOR ONCE: the first\r\n  knob write (`50-backlog.rules`) silently LOST the augenrules merge — apt's own\r\n  `/etc/audit/rules.d/audit.rules` sorts LAST (digits before letters) and its `-b 8192` /\r\n  `--backlog_wait_time 60000` won; a whole proof run executed under the defaults while the\r\n  fragment grepped perfect. Values now live in the merge-WINNING file; verified `auditctl -s`.\r\n- **Re-check triggers (the reason this entry stays):** (1) tailscale snap update — the plug\r\n  landscape may change, the storm may stop or grow; (2) auditd package update/reinstall — may\r\n  rewrite `rules.d/audit.rules` and re-lose the merge; (3) box reimage. On any of these: one\r\n  `auditctl -s` (expect 32768/0) + one `journalctl -k | grep 'backlog limit'` (expect silence).\r\n- **Ripe when:** a re-check trigger fires. **Size:** two read-only commands per check.\r\n\r\n### IR-66 — first-chunk-needle test class: two latent members remain after the v0.63.0 fix (attach.rs:561, :672)\r\n\r\n- **Status:** CLOSED / BUILT — release-close reconciliation 2026-09-11. The WEBSERVE JIT already\r\n  ruled this satisfied; source at `e5a2fed9` retains both delayed needles. Closure uses the\r\n  recorded gates below, not v0.69.0's unrelated green receipts. Hertz rider PR #161, landed ff at\r\n  `d04b922d` (2026-08-27, IO-PARSER #22\r\n  intake rider). Both members got the later-needle treatment (TICK39 delayed past burst on both\r\n  OS arms; alt-screen entered before delayed ALT_VIEWPORT_MARKER). Gate: doyle — diff-scope\r\n  review; Windows isolated worktree 3× TICK39 PASS + clippy + treqs; Linux CLEAN worktree at the\r\n  PR sha on kitsubito 3× both cells PASS (independent of the builder's dirty-shared-tree proof,\r\n  disclosure on record). · **Origin:** doyle tree-wide census at `dbe3daad`\r\n  (releases#225 comment 5418844404 — the census that corrected my own resume.rs-scoped\r\n  overclaim), after the class's first member was RCA'd and fixed in v0.63.0's head.\r\n- **Mechanism (cite, not restate):** KNOWN-HAZARDS 6.9 same-session face, amended at\r\n  `dbe3daad` — `spawn_session_pid`'s Spawned-wait consumes-and-discards a first output chunk\r\n  that races the reply (~2ms window on a healthy Linux box; load-stretched under backpressure,\r\n  see IR-30 Linux-face + IR-65). A test whose needle exists ONLY in the child's first chunk\r\n  asserts winning a race the contract does not promise.\r\n- **The two members:** `crates/spt-daemon/tests/attach.rs:561` (TICK0..39 instant burst then\r\n  `cat`; needle TICK39 read directly after spawn — the whole burst can sit in the first\r\n  chunks) and `:672` `cross_node_cold_attach_to_alt_screen_gets_clean_repaint` (unix-only;\r\n  `printf '…ALT_VIEWPORT_MARKER'; cat` — needle in the first chunk). Failure shape differs from\r\n  the fixed member: both children idle on `cat`, so a lost prefix is a HANG killed by nextest's\r\n  backstop at exactly 240s (slow-timeout 60s × terminate-after 4) — not a natural-life death.\r\n  Verified NOT in the class: daemon_e2e.rs:209 (needle = echo of post-spawn input), attach.rs:995\r\n  + brain_swap.rs:170 (attach/replay reads, not spawn-waits).\r\n- **Fix shape (ruled at the v0.63.0 close):** hertz lane, NEXT intake — the same one-line\r\n  later-needle / robust-read treatment the resume seed got in `dbe3daad`; deliberately NOT\r\n  landed mid-r4. Both cells passed r4 (0.010–0.058s) — the members are latent, not failing.\r\n- **Ripe when:** next milestone intake (hertz test lane) or the first golden red at ~240s on an\r\n  attach cell — either way the mechanism and fix are pre-derived, triage should cite this entry\r\n  and skip the RCA. **Size:** two one-line test edits.\r\n\r\n### IR-67 — wave-battery gap: a `-p spt --bins` leg compiles bin targets as harnesses and runs ZERO integration/e2e tests, so batteries that lean on it carry silent no-coverage legs\r\n\r\n- **Status:** BUILT — remedy applied across the IO-PARSER #22 milestone (2026-08-27/28): every\r\n  wave battery named explicit `-p spt --test <suite>` e2e legs beside the `--bins` unit leg\r\n  (GW1..GW5 evidence), every builder evidence report carried a named real e2e per the dispatch\r\n  template, and the one filter mistake (a `--test` name not matching its file) REFUSED loudly\r\n  rather than silently skipping — the failure mode this entry exists to kill. Battery template =\r\n  the dispatch text now carried forward in gate craft.\r\n- **Was:** OPEN · **Origin:** doyle, banked at the SIGNET #218 gates 2026-08-25 (\"gate\r\n  battery gap learned\"), filed at this sweep per the standing rule.\r\n- **Mechanism:** `cargo test/nextest -p spt --bins` builds `[[bin]]` targets as TEST HARNESSES\r\n  (unit tests inside bins only) — `tests/` integration and e2e suites of the crate NEVER run,\r\n  and the leg's green output is indistinguishable from coverage. Kin of the two banked pool\r\n  faces (`--bins` never emits fixture exes; fresh-pool fixture reds) but this face is about the\r\n  BATTERY TEMPLATE: my SIGNET wave batteries carried a `-p spt --bins` leg believed to cover\r\n  the crate.\r\n- **Remedy:** at next intake, the wave-battery template gains an explicit `tests/` leg for the\r\n  spt crate (nextest `-p spt --test <suites>` or unfiltered `-p spt` where pool history\r\n  permits), and any battery doc that lists `--bins` as a coverage leg gets the one-line caveat.\r\n- **Ripe when:** next milestone intake (the battery template is touched at every intake).\r\n  **Size:** template lines only.\r\n\r\n### IR-68 — PSYCHE_INGEST_FAIL cause class unproven: git index.lock did NOT reproduce the ingest failure it was blamed for\r\n\r\n- **Status:** OPEN, investigation-shaped · **Origin:** todlando measurement at the W2 int-leg rig\r\n  (IO-PARSER #22, PR #163 at `769fb0a9`, 2026-08-27), reported measure-first; filed by doyle.\r\n- **The contradiction:** the six silent `PSYCHE_INGEST_FAIL:todlando` lines observed at the\r\n  drop-dir probe (2026-08-25) were attributed to shared-checkout git `index.lock` contention. The\r\n  W2 rig planted NON-EMPTY `index.lock` files in BOTH places git takes one (bare git-dir + every\r\n  `<git_dir>/worktrees/<name>/`, mirroring `branchstore::sweep_stale_index_locks`, plant count\r\n  asserted >= 2) — and the ingest COMMITTED ANYWAY (tier write `Written`; `route_slices`\r\n  propagates `commit_live(...)?`, so a blocked checkpoint would have failed it). Non-empty was\r\n  deliberate: KH 1.3 reaps only 0-byte locks, and `pulse_tick` runs no boot sweep. So on this\r\n  store an `index.lock` does not block the checkpoint, and the field incident's mechanism is\r\n  UNKNOWN, not merely unconfirmed. The rig's doc comment records the attempt; the shipped int leg\r\n  fails the ingest at the drop READ instead (upstream of the store).\r\n- **Strongest negative evidence, pinned to the executable rig:**\r\n  `crates/spt-daemon/tests/commune_io_events_int.rs:95-107` documents that the lock mechanism was\r\n  tried **first**, planted non-empty locks in both the bare git-dir and every linked-worktree\r\n  location, asserted that the population was non-empty, and still observed `Written`. Its own\r\n  sentence is the required scope boundary: “This leg does not claim to reproduce a mechanism it\r\n  measured as inert.” The working injection is instead drop-file → directory replacement, which\r\n  fails the upstream read deterministically and proves only the `COMMUNE_FAIL` event contract.\r\n- **NOT claimed:** that the field incident was misattributed to ingest failure generally — the\r\n  files did survive with failed-ingest log lines; what is unproven is the index.lock CAUSE.\r\n- **Ripe when:** next PSYCHE_INGEST_FAIL sighting in the field (capture the failing store state\r\n  before touching it), or a dedicated probe slot. W2's COMMUNE_FAIL event now pushes a NAMED\r\n  reason on every failure, so the next occurrence self-reports its cause — read that first.\r\n  **Size:** investigation; no product change until the mechanism is pinned.\r\n\r\n### IR-69 — inherited stderr tokens can tear between format fragments; 26 test consumers parse that surface as structured truth\r\n\r\n- **Status:** OPEN for the #243 residual population and anchored-consumer work. The original\r\n  product remedy LANDED at `ec6da9b0`, as recorded in this entry's later amendment; it is not\r\n  still parked awaiting assembly. Releases#241 retains its original lane evidence in comment\r\n  5461613480. This entry is the exposure map and census discipline; residual conversion,\r\n  generator repair and a SHA-pinned zero recensus remain owed. · **Origin:** CONDUIT #236 r3\r\n  golden attempt 2,\r\n  2026-08-29: `endpoint_autostart_e2e` missed its contiguous\r\n  `ENDPOINT_AUTOSTART:gwauto` keystone although the matching fresh session id proved the replay\r\n  happened. Attempt 3 was clean on the same discarded SHA after 139 GB was reaped; unequal load\r\n  makes the pair corroborating, never a rate.\r\n- **Mechanism, recovered from the literal torn bytes:** two daemon processes inherited one stderr\r\n  pipe. `BRAIN_UP` and `ENDPOINT_AUTOSTART` are each one `eprintln!`, but `write_fmt` may reach the\r\n  handle once per format fragment; the per-process stderr lock cannot serialize the other process.\r\n  The observed interleave split the autostart token between `ENDPOINT_AUTOSTART:` and `gwauto`.\r\n  This is fragment-level cross-process interleaving, not a failed replay and not a two-thread race.\r\n- **Durable remedy, ruled product-side:** render a complete diagnostic line into one buffer and\r\n  issue the complete rendered text, newline included, as **ONE handle call**. An OS short-write\r\n  may retry the late tail so completeness wins over a silently truncated line; the deterministic\r\n  property pins application-side fragmentation, not syscall count under that rare retry. It makes\r\n  no claim that the OS write is atomic on Windows, and no CI re-fire against a 1-of-2 observation\r\n  may stand in for it. Widening one test's grep is refused: it greens one consumer while every\r\n  sibling token remains exposed.\r\n- **Cut-SHA census** (todlando generator, independently hash-verified by hertz), measured from\r\n  `4d6007ac4ee3d0991f4bc60b7e1a55825aad1aaf` via `git show`, not a dirty worktree:\r\n  **486 real emitter sites / 383 distinct tokens / 26 consumer test files**. The generator emitted\r\n  487 site rows, but one is a known phantom: `sealverb.rs:456` is a `format!` inside `map_err`\r\n  that the four-line lookback attributed to a neighbouring real `eprintln!`. Corrected real emitters\r\n  by crate: spt-daemon 270, spt 194, spt-runtime 8, spt-live 5, spt-net 5, spt-store 4; by macro:\r\n  `eprintln!` 484, `println!` 1, `eprint!` 1. `DRIVEN_BY` is the sole stdout row and therefore\r\n  outside the stderr remedy. A consumer means the test both mentions `TOKEN:` and reads a\r\n  stderr/log surface; bare-token matching inflated the population to 72 files by admitting prose.\r\n  This is an **exposure map**, not a rate and not a claim that all 26 have torn.\r\n- **Artifacts (the preserved raw generator outputs contain 487 site rows):** cut census SHA-256:\r\n  sites `f10d6bfe5e0399f98945cf63bb5719a01a62e1251be84165c73030fa9bb224f5`,\r\n  tokens `80b0d1835d9d46376b2f200b1c50be4ca0e185a135168444414255f9308ed92b`,\r\n  consumers `249a2e33df43a30570ca82b5bd200d8b6e2bf07aa8250fcc8bace47fe23e3cbc`.\r\n  The sealed sites file's macro column is wrong on 7 of its 487 raw rows; the corrected raw split\r\n  is `eprintln!` 485 / `println!` 1 / `eprint!` 1. The sealed tokens file has no final newline, so\r\n  `wc -l` reports 382 although it contains 383 logical records. The sealed files remain unedited;\r\n  these corrections are textual.\r\n  Generator `81df82f01ef33a82307920d9804a2394b787ef2ffbe3b41d2d7dda560d9a62a9`\r\n  was recorded as asserting newline-terminated output, but the sealed tokens artifact refutes that\r\n  claim for at least one output. Its remaining guards cover logical record counts, a known-positive\r\n  `SUBSCRIBE_DECISION` sentinel, four-line macro lookback, and truncation only at a\r\n  `#[cfg(test)]` that opens a module.\r\n- **Census hazards paid for while constructing and reconciling the population:** the provisional\r\n  instrument moved `277/243 → 286 → 412 → 487 raw → 486 real` as four silent assumptions were\r\n  found: same-line matching misses multi-line macros; truncating at the first `#[cfg(test)]` drops\r\n  later shipping code; lookback must prefer the token line's own macro over a neighbouring arm;\r\n  and even that lookback can promote a nested token literal beneath a real macro into a phantom\r\n  second site. A file without a final newline also makes `wc -l` silently undercount logical\r\n  records by one. Every future census must name its SHA, assert a known member, count records\r\n  inside the generator, and reconcile emitted rows to real sites.\r\n- **Separate anchored-matcher finding:** `IDLE`, `DISPATCH`, `BUSY`, and `BOUND` are common words\r\n  matched as substrings in exposed consumers. One-write emission does not prevent an unrelated log\r\n  line from satisfying them; those predicates need anchored token matching. Keep this separate from\r\n  the tear remedy so neither defect is claimed to close the other.\r\n- **Kin:** [[IR-50]] (the sink must be read before its absence means anything), [[IR-40]] (a\r\n  confident signal that does not describe the source truth), [[IR-8]] (a plausible census whose\r\n  blind spot returns a clean answer).\r\n- **CLOSE-OUT ADDENDUM 2026-08-30 (#242/v0.66.0 sweep — the entry's own close-out re-census RAN\r\n  and FOUND the predicted blind spot LIVE; entry stays OPEN):** re-census at the landed sha\r\n  `ec6da9b0` (independent containment-classified meter, reconciled with todlando's independent\r\n  meter — full write-up `EMISSION-RESIDUAL-CENSUS-FINDING.md`): the generator truncated\r\n  `crates/spt/src/cli.rs` at its FIRST module-opening `#[cfg(test)]` (line 3007, module closes\r\n  3164, file runs to 39118) and never scanned the rest — **338 TOKEN-shaped shipping sites remain\r\n  bare (332 colon-form, i.e. misses under the sealed census's own predicate, + 6 space-form)**,\r\n  plus `main.rs` 2 sites behind the same mechanism; exactly TWO files tree-wide carry the\r\n  triggering property (first module-opening cfg(test) precedes shipping code) — the generator\r\n  fix's owed blind-spot measurement, answered. The census-hazards bullet above already NAMES this\r\n  third-face truncation hazard; the module-opening fix narrowed the trigger and kept the blind\r\n  spot for files where a test module CLOSES and shipping resumes — IR-8 shape, predicted by this\r\n  entry's own text. The shipped #241 conversions are UNAFFECTED (495 removals ≈ censused 486 +\r\n  space family; the SEEN population is closed; golden green stands). Residual conversion +\r\n  generator fix + enforcement-at-the-seam = **releases#243** (BACKLOG, operator triages);\r\n  delivery.rs:149/313 are post-cut MINTS relative to the census sha (todlando's own, settled\r\n  attribution), deliberately outside #243's census-mechanism scope — and ALREADY CONVERTED: the\r\n  fix rode his breadcrumb branch (`60a12056`) into the r4 head and shipped IN-TAG (todlando\r\n  flagged the stale \"his thin lane converts post-cut\" claim 2026-08-30; re-measured — zero bare\r\n  TOKEN `eprintln!` in delivery.rs at both `d931dd63` and origin/main). No lane is owed for it. Re-runnable meter\r\n  `EMISSION-RESIDUAL-CENSUS-METER.py` (repo root, untracked; version-control rides #243's lane).\r\n  **Common-word matcher RULED at this sweep (discharges the \"decide\" clause below):** the four\r\n  common-word consumers (`IDLE`/`DISPATCH`/`BUSY`/`BOUND` substring predicates) get a SEPARATE\r\n  hertz test-side rider — anchored token matching is consumer-predicate work, NOT folded into\r\n  #243 (keeps #243 product-scoped) and not claimed closed by one-write emission; lane-link when\r\n  hertz's spool drains.\r\n- **Closes when:** releases#243's residual conversion + generator fix land and a re-census at\r\n  that sha reads zero shipping residue under both delimiter forms. **Size:** product lane\r\n  complete elsewhere; register follow-through small.\r\n\r\n### IR-70 — a hand-built `IoBus` silently omitted later sinks while every gate stayed green\r\n\r\n- **Status:** OPEN, remedy unscheduled; the v0.65.0 respin fixed the witnessed call site on PR #173.\r\n  This entry owns the recurrence class, not that shipped correction. · **Origin:** releases#234,\r\n  commit `c5459795167`, CONDUIT #236 respin.\r\n- **Mechanism:** `publish_commune_io` constructed `IoBus` itself and registered only the sink it\r\n  knew. `default_bus` already existed as the assembly point and its module contract explicitly says\r\n  emitters must know only `IoBus::publish`, so adding a later sink costs one registration rather\r\n  than an emitter sweep. The hand-built publisher recreated exactly the drift that contract warned\r\n  against: `COMMUNE` and `COMMUNE_FAIL` reached the old sink but never the adapter log, leaving\r\n  `spt api io-events` permanently short on two documented kinds.\r\n- **Why the complete battery was green:** the e2e was vacuous on the broken kinds; units synthesized\r\n  rows without traversing `publish_commune_io`; and traceability checked attached tags, not whether\r\n  the tagged path exercised the real publisher. Three green instruments shared one blind seam.\r\n  The respin routed the site through `crate::iobus::default_bus`, and its source comment now records\r\n  the failure shape.\r\n- **Durable remedy direction (todlando mechanism, not scheduled):** enforce the assembly point so\r\n  the next hand-built bus is impossible rather than found — make production publishers obtain the\r\n  composed bus through one construction API, and gate the real publish path for every documented\r\n  kind. A search or comment is not enforcement; another emitter can satisfy both while rebuilding\r\n  a partial sink list.\r\n- **Kin:** [[IR-39]] (a green fixture never reached the missing dependency), [[IR-37]]\r\n  (traceability tags prove coverage bookkeeping, not behavioral truth), [[IR-58]] (a hand-built\r\n  population returns an orderly but incomplete answer).\r\n- **Ripe when:** the next `IoBus` construction/API touch, or a new sink registration. **Size:**\r\n  small-to-medium assembly-point enforcement plus a real-path population test.\r\n\r\n### IR-71 — controller-seat release has no persisted breadcrumb, so tests cannot distinguish propagation lag from a missing detach\r\n\r\n- **Status:** OPEN, observability gap; no remedy scheduled. · **Origin:** CONDUIT #236 r3\r\n  `er_brief_once_per_session_e2e` intermittent, classified test-side and fixed on PR #174.\n…\n","startLine":2676,"lineNumbers":[2676,2677,null,2701,null,2706,2707,2708,2709,2710,2711,2712,2713,2714,2715,2716,2717,2718,2719,2720,2721,2722,2723,2724,2725,2726,2727,2728,2729,2730,2731,2732,2733,2734,2735,2736,2737,2738,2739,2740,2741,2742,2743,2744,2745,2746,2747,2748,2749,2750,2751,2752,2753,2754,2755,2756,2757,2758,2759,2760,2761,2762,2763,2764,2765,2766,2767,2768,2769,2770,2771,2772,2773,2774,2775,2776,2777,2778,2779,2780,2781,2782,2783,2784,2785,2786,2787,2788,2789,2790,2791,2792,2793,2794,2795,2796,2797,2798,2799,2800,2801,2802,2803,2804,2805,2806,2807,2808,2809,2810,2811,2812,2813,2814,2815,2816,2817,2818,2819,2820,2821,2822,2823,2824,2825,2826,2827,2828,2829,2830,2831,2832,2833,2834,2835,2836,2837,2838,2839,2840,2841,2842,2843,2844,2845,2846,2847,2848,2849,2850,2851,2852,2853,2854,2855,2856,2857,2858,2859,2860,2861,2862,2863,2864,2865,2866,2867,2868,2869,2870,2871,2872,2873,2874,2875,2876,2877,2878,2879,2880,2881,2882,2883,2884,2885,2886,2887,2888,2889,2890,2891,2892,2893,2894,2895,2896,2897,2898,2899,2900,2901,2902,2903,2904,2905,2906,2907,2908,2909,2910,2911,2912,2913,2914,2915,2916,2917,2918,2919,2920,2921,2922,2923,2924,2925,2926,2927,2928,2929,2930,2931,2932,2933,2934,2935,2936,2937,2938,2939,2940,2941,2942,2943,2944,2945,2946,2947,2948,2949,2950,2951,2952,2953,2954,2955,2956,2957,2958,2959,2960,2961,2962,2963,2964,2965,2966,2967,2968,2969,2970,2971,2972,2973,2974,2975,2976,2977,2978,2979,2980,2981,2982,2983,2984,2985,2986,2987,2988,2989,2990,2991,2992,2993,2994,2995,2996,2997,2998,2999,3000,3001,3002,3003,3004,3005,3006,3007,3008,3009,3010,3011,3012,3013,3014,3015,3016,3017,3018,3019,3020,3021,3022,3023,3024,3025,3026,3027,3028,3029,3030,3031,3032,3033,3034,3035,3036,3037,3038,3039,3040,3041,3042,3043,3044,3045,3046,3047,3048,3049,3050,3051,3052,3053,3054,3055,3056,3057,3058,3059,3060,3061,3062,3063,3064,3065,3066,3067,3068,3069,3070,3071,3072,3073,3074,3075,3076,3077,3078,3079,3080,3081,3082,3083,3084,3085,3086,3087,3088,3089,3090,3091,3092,3093,3094,3095,3096,3097,3098,3099,3100,3101,3102,3103,3104,3105,3106,3107,3108,3109,3110,3111,3112,3113,3114,3115,3116,3117,3118,3119,3120,3121,3122,3123,3124,3125,3126,3127,3128,3129,3130,3131,3132,3133,3134,3135,3136,3137,3138,3139,3140,3141,3142,3143,3144,3145,3146,3147,3148,3149,3150,3151,3152,3153,3154,3155,3156,3157,3158,3159,3160,3161,3162,3163,3164,3165,3166,3167,3168,3169,3170,3171,3172,3173,3174,3175,3176,3177,3178,3179,3180,3181,3182,3183,3184,3185,3186,3187,3188,3189,3190,3191,3192,3193,3194,3195,3196,3197,3198,3199,3200,3201,3202,3203,3204,3205,3206,3207,3208,3209,3210,3211,3212,3213,3214,3215,3216,3217,3218,3219,3220,3221,3222,3223,3224,3225,3226,3227,3228,3229,3230,3231,3232,3233,3234,3235,3236,3237,3238,3239,3240,3241,3242,3243,3244,3245,3246,3247,3248,3249,3250,3251,3252,3253,3254,3255,3256,3257,3258,3259,3260,3261,3262,3263,3264,3265,3266,3267,3268,3269,3270,3271,3272,3273,3274,3275,3276,3277,3278,3279,3280,3281,3282,3283,3284,3285,3286,3287,3288,3289,3290,3291,3292,3293,3294,3295,3296,3297,3298,3299,3300,3301,3302,3303,3304,3305,3306,3307,3308,3309,3310,3311,3312,3313,3314,3315,3316,3317,3318,3319,3320,3321,3322,3323,3324,3325,3326,3327,3328,3329,3330,3331,3332,3333,3334,3335,3336,3337,3338,3339,3340,3341,3342,3343,3344,3345,3346,3347,3348,3349,3350,3351,3352,3353,3354,3355,3356,3357,3358,3359,3360,3361,3362,3363,3364,3365,3366,3367,3368,3369,3370,3371,3372,3373,3374,3375,3376,3377,3378,3379,3380,3381,3382,3383,3384,3385,3386,3387,3388,3389,3390,3391,3392,3393,3394,3395,3396,3397,3398,3399,3400,3401,3402,3403,3404,3405,3406,3407,3408,3409,3410,3411,3412,3413,3414,3415,3416,3417,3418,3419,3420,3421,3422,3423,3424,3425,3426,3427,3428,3429,3430,3431,3432,3433,3434,3435,3436,3437,3438,3439,3440,3441,3442,3443,3444,3445,3446,3447,3448,3449,3450,3451,3452,3453,3454,3455,3456,3457,3458,3459,3460,3461,3462,3463,3464,3465,3466,3467,3468,3469,3470,3471,3472,3473,3474,3475,3476,3477,3478,3479,3480,3481,3482,3483,3484,3485,3486,3487,3488,3489,3490,3491,3492,3493,3494,3495,3496,3497,3498,3499,3500,3501,3502,3503,3504,3505,3506,3507,3508,3509,3510,3511,3512,3513,3514,3515,3516,3517,3518,3519,3520,3521,3522,3523,3524,3525,3526,3527,3528,3529,3530,3531,3532,3533,3534,3535,3536,3537,3538,3539,3540,3541,3542,3543,3544,3545,3546,3547,3548,3549,3550,3551,3552,3553,3554,3555,3556,3557,3558,3559,3560,3561,3562,3563,3564,3565,3566,3567,3568,3569,3570,3571,3572,3573,3574,3575,3576,3577,3578,3579,3580,3581,3582,3583,3584,3585,3586,3587,3588,3589,3590,3591,3592,3593,3594,3595,3596,3597,3598,3599,3600,3601,3602,3603,3604,3605,3606,3607,3608,3609,3610,3611,3612,3613,3614,3615,3616,3617,3618,3619,3620,3621,3622,3623,3624,3625,3626,3627,3628,3629,3630,3631,3632,3633,3634,3635,3636,3637,3638,3639,3640,3641,3642,3643,3644,3645,3646,3647,3648,3649,3650,3651,3652,3653,3654,3655,3656,3657,3658,3659,3660,3661,3662,3663,3664,3665,3666,3667,3668,3669,3670,3671,3672,3673,3674,3675,3676,3677,3678,3679,3680,3681,3682,3683,3684,3685,3686,3687,3688,3689,3690,3691,3692,3693,3694,3695,3696,3697,3698,3699,3700,3701,3702,3703,3704,3705,3706,3707,3708,3709,3710,3711,3712,3713,3714,3715,3716,3717,3718,3719,3720,3721,3722,3723,3724,3725,3726,3727,3728,3729,3730,3731,3732,3733,3734,3735,3736,3737,3738,3739,3740,3741,3742,3743,3744,3745,3746,3747,3748,3749,3750,3751,3752,3753,3754,3755,3756,3757,3758,3759,3760,3761,3762,3763,3764,3765,3766,3767,3768,3769,3770,3771,3772,3773,3774,3775,3776,3777,3778,3779,3780,3781,3782,3783,3784,3785,3786,3787,3788,3789,3790,3791,3792,3793,3794,3795,3796,3797,3798,3799,3800,3801,3802,3803,3804,3805,3806,3807,3808,3809,3810,3811,3812,3813,3814,3815,3816,3817,3818,3819,3820,3821,3822,3823,3824,3825,3826,3827,3828,3829,3830,3831,3832,3833,3834,3835,3836,3837,3838,3839,3840,3841,3842,3843,3844,3845,3846,3847,3848,3849,3850,3851,3852,3853,3854,3855,3856,3857,3858,3859,3860,3861,3862,3863,3864,3865,3866,3867,3868,3869,3870,3871,3872,3873,3874,3875,3876,3877,3878,3879,3880,3881,3882,3883,3884,3885,3886,3887,3888,3889,3890,3891,null,3911]},"fileSize":676479,"meta":{"source":{"type":"path","value":"C:\\Users\\decid\\Documents\\projects\\spt-core\\.worktrees\\hertz-ir86-disk-delta\\docs\\INFRA-REGISTER.md"},"truncation":{"direction":"middle","truncatedBy":"middle","totalLines":1193,"totalBytes":104412,"outputLines":476,"outputBytes":40902,"maxBytes":40960,"headRange":{"start":1,"end":234},"tailRange":{"start":953,"end":1193},"elidedLines":718,"elidedBytes":63532,"artifactId":"731","nextOffset":3891},"limits":{"columnTruncated":{"maxColumn":768}}}},"isError":false,"timestamp":1789483662418}}
{"type":"message","id":"ea39bce9","parentId":"f836aa13","timestamp":"2026-09-15T14:47:42.459Z","message":{"role":"toolResult","toolCallId":"call_uB27JN6f8evDHc07zmWmYD5i|fc_043a862a419f59ae016aa95a8e358887d29dd56a5a2d698b9f","toolName":"read","content":[{"type":"text","text":"### IR-26 — POOL-OWNER claims authorize takeover from a DEAD holder, so releases#103's hazard reaches through the guard\n- **Status:** OPEN for residual claim-time observability and stale-reader enforcement; the\n…\n- **RULING (doyle, 2026-08-04) — the claim path must run the same guard the build path runs, and a\n…\n\n### IR-27 — A junction-pooled rig is TWO objects and teardown only ever removes one\n- **Status:** open, found in the wild 2026-08-04 · **Origin:** hertz's 44-tree worktree sweep\n  (IR-26 follow-on 3) · **Cross-ref:** [[IR-14]] (unclaimed pools), [[worktree-target-junction]]\n- **What/why:** a rig built as `worktree\\target -> junction -> .worktrees\\<pool>` has its build cache\n  in a directory that is NOT the worktree and NOT in `git worktree list`. `git worktree remove` deletes\n  the junction and reports success; the pool survives with zero inbound links and nothing naming it.\n  Measured on this box: reaping `golden-render` and `w4-cli-doc` the obvious way would have reclaimed\n  ~26 MB of worktree and stranded **14.17 GB** of pool (`gate-target-render` 6,265,448,382 B +\n  `gate-target-w4doc` 7,907,558,098 B). Neither pool appears in any worktree listing.\n- **The second shape, same mechanism, already realised:** `.worktrees\\gate-target` was found at\n  **0 files / 0 bytes with FOUR live inbound junctions** (assembly-doorbell, doorbell-w1/w2/w3). Someone\n  had already reaped that pool and left four dangling-but-valid links behind. So the defect runs both\n  ways: remove the worktree and the pool is orphaned; remove the pool and the links are orphaned.\n  Either half alone leaves a lie on disk.\n- **Why it is not just \"be careful\":** the classification step people already know\n  (`Get-Item -Force` OUTBOUND, INBOUND reparse sweep) tells you HOW to delete an object you have\n  already decided to delete. It does not tell you that a second object exists. The missing thing is an\n  enumeration that reaches pools no worktree names.\n- **Remedy shape (CORRECTED by builder retraction, 2026-08-04 — the enumeration already exists and\n  shipped):** `xtask pool-sweep` (`c6515f1`, `REQ-POOL-GC-ORPHAN-RECLAIM`, ancestor of `b7b00c3` by\n  merge-base) walks the root for dirs AND links, counts inbound links over the whole sweep before\n  forming a verdict, classifies InUse/Owned/Orphaned, and reaps orphans on `--reap`. The gap is not\n  detection, it is TIMING: a junction-pooled tree's pool is `Owned` and not reclaimable right up to\n  the moment its worktree is removed, and `Orphaned` only after — so the reclaim always lands in a\n  LATER sweep, and nothing triggers one. `gate-target` (0 bytes, four dangling inbound links) is a\n  completed instance of that deferral. Remedy is a post-teardown pass or a teardown that runs the\n  sweep itself, not new enumeration. (An earlier draft of this entry proposed building the\n  enumeration; retracted by its author before ripening — the tool refuting it was one run away.)\n- **Ripe when:** next CI/infra batch. **Size:** small (one enumeration + report, no new policy).\n- **Discipline this cost, stated so it is not re-learned:** teardown must be TWO EXPLICIT STEPS per\n  junction-pooled tree — junction deleted AS A LINK (`Directory.Delete(path, recursive: false)`), then\n  the pool AS A TREE after an inbound sweep confirms it is linkless. Executed that way on 2026-08-04:\n  28 worktrees, 4 pools, 0 skipped, 0 pinned, 17.04 GiB measured on a box with concurrent writers.\n\n### IR-28 — A wave-gap rider is visible to the request board and invisible to a milestone-narrative notes pass\n- **Status:** BUILT 2026-08-29 — PR #176 (`880b3b9c`, landed on main via `37368263`).\n  · **Origin:** deployah, v0.53.0 release close 2026-08-04.\n- **What/why:** the v0.53.0 changelog omitted `184f2ac` (the releases#125 two-core CPU-burn fix, a\n  wave-gap rider that rode the commit range but was never LOCKSMITH scope) while the alchemy release\n  verb promoted #125 to DONE and named it publicly as shipped — two published surfaces contradicting\n  each other until the post-publish docs-only repair (`9841592`). The rule was already right (the\n  runbook audits the changelog against the COMMIT RANGE); the EXECUTION missed it, because a notes\n  pass written from the milestone narrative never enumerates the range. The mechanism, not the\n  incident: any rider is board-visible and narrative-invisible.\n- **Built evidence:** `docs/RELEASE-RUNBOOK.md` now requires a mechanical `vPREV..HEAD`\n  user-facing commit list, a changelog match beside every row, and an explicit accounting of every\n  unmatched row before the golden run. The repair precedent remains docs-only amend +\n  `gh release edit`, never retag. PR #176 passed `traceable-reqs check`.\n\n### IR-29 — twohost ladder: role A fires the done-barrier BEFORE its last cross-node rung, so the re-pull's serve window is won by timing, not guaranteed\n- **Status:** OPEN for later serve-window/rung residuals; the original\n  `test/twohost-serve-window` fix `17bbbd8` LANDED in v0.54.0, as recorded by IR-30.\n  Stale authored-but-unlanded header corrected 2026-09-11; no new acceptance or margin\n  measurement claimed. · **Origin:** golden\n  30873007187 attempt 1 red, doyle timeline triage + hertz source diagnosis 2026-08-04.\n- **SECOND FACE, measured 2026-08-24 (WAX-SEAL #21 W3 gate climb @ 035c3fe6, doyle):** the class\n  recurs on a NEW rung, and this face is UNWINNABLE rather than racy. The W3 seal rung S1 mints\n  on A ~0.3s before A's ladder completes (mint mono 80843ms, ladder end ~81150ms, walked from\n  the capture), while the seal pump worker's cadence is 500ms — the pusher exits before its\n  first eligible post-mint tick, so ZERO feed pushes ever fire (both logs hold zero seal-feed\n  lines) and role B burns its full 900s window on \"seal: A's record replicated into B's store\".\n  Full-re-presentation heals only while a pump is RESIDENT; the rig kills it. Product not\n  implicated (local legs + design review all green at the sha). Dispatched to hertz 2026-08-24\n  with two fix shapes (mint early with ~120 ticks of resident-pump margin, or a\n  reverse-confirmation barrier on A's done-push); the climb re-runs on his fix. Lesson for\n  future rungs, stated as construction: a rung whose delivery is CADENCED must not sit inside\n  the terminal margin of the process that pushes it.\n- **Mechanism (hertz falsified the gater's first spelling, kept because the correction is the\n  entry):** NOT \"B exits early\" and NOT a missing barrier. B's contract (twohost.rs:1116-1121,\n  \"hold until A finishes its side — done-file as the ladder's completion barrier\") is right and B\n  obeys it. A BREAKS it: A pushes done.txt (:1819-1832, payload literally \"ladder complete on A\")\n  then runs the ENTIRE leg-D digest rung including the re-pull assert (:1959) before its own\n  `stop.store` (:1966). B tears down exactly when A said it could; the re-pull then races B's\n  post-signal teardown. The panic's hint text (\"may be running a version without cross-node\n  digest\") is pre-authored and was NOT evidence of version skew.\n- **Margin series, six draws of one race (deployah, markers cited by TEXT and positive-controlled\n  against a known draw before producing an unknown one):** golden 30860770146 +60s · a1 −0.6s\n  (the RED) · a2 +59.4s · a3 +60s · a4 +59.59s · a5 +63.89s. BIMODAL, not drifting: greens\n  cluster within seconds, one collapse through zero. A green does not mean the window got safer;\n  sample count characterizes a bimodal race, not margin size — the slack is incidental, not\n  designed. Local load on hfenduleam during A's leg D eats the margin directly (role A runs\n  there; the done-file is already pushed), which is why builds hold through twohost legs.\n- **⚠ THE SERIES IS CLOSED AT SIX DRAWS — ITS DERIVATION IS UNRECOVERABLE, AND NO SEVENTH NUMBER\n  MAY BE ADDED (ruled by doyle 2026-08-05, at the tranche-2 golden).** Asked to extend it with a\n  draw from run 30971976024, deployah positive-controlled the markers FIRST and the control\n  REFUSED: grepping `margin|deadline|serve window|slack|headroom|budget` against a control run\n  known to carry good twohost evidence (30940180764) returned ZERO. Source confirms it —\n  **`margin` is not an emitted token anywhere**: absent from `.github/workflows/golden.yml`, and\n  every `crates/` hit is unrelated (terminal right-margins in broker/resize tests,\n  `ROUND_DRAIN_MARGIN` in `pump/mod.rs`). So the six figures were DERIVED from log timestamps\n  against a bound that was never written down, by a measurer whose context has since been cleared;\n  the gater who recorded them never held the formula either. **Consequence, stated so nobody\n  re-derives it:** any new figure computed from these logs would be a DIFFERENT quantity wearing\n  the same name, and would enter a series whose value is its bimodality — the one structure a\n  mismatched sample corrupts invisibly. This run therefore gets a LABELLED HOLE, not a number.\n  What IS reportable for it, with endpoints named rather than a name reused: **ladder span**, node\n  start → `TWOHOST role B: ladder complete` = **183.50s** on the batch vs **259.21s** on the\n  control. Marker parity established under an IDENTICAL expression on both sides (25 = 25, after a\n  first pass that compared two different greps and would have read as parity by coincidence).\n- **The fix this makes obvious:** the twohost margin must become an EMITTED token with its two\n  events named at the emit site, so the next draw is read rather than reconstructed. A derived\n  quantity whose formula lives only in a measurer's context is one context reset away from being\n  unfalsifiable — which is exactly what happened here.\n- **Fix shape (doyle-approved):** move the done-push block to AFTER leg D, immediately ahead of\n  A's stop — one honest barrier made true, no second completion signal (a redundant pair is how\n  the next ordering bug lands after the SECOND one). `int->REQ-REACH-1` travels with the block.\n- **Cascade note, so a future triage does not count it:** in a1, twohost-b's gated-CLI red\n  (twohost_cli.rs:189, 910s) was the CASCADE — role-A's gated driver step SKIPPED after the\n  ladder death, so B waited for a row never produced. A red that postdates its carrier leg's\n  failure carries zero information about its own subject.\n- **Ripe when:** proving run at the next two-host window. **Size:** landed-sized already.\n\n### IR-30 — GOLDEN 4b37512 (#145): five attempts, four distinct Windows victims, one sha — the random-victim family measured end to end, and the instruments it left behind\n- **Status:** open for the FAMILY SIGHTINGS ONLY — the instrument lanes LANDED as planned with\n  the next golden batches (measured 2026-08-25, doyle, `git merge-base --is-ancestor` + first\n  tag: serve-window `17bbbd8`, selection probe `695398ba`, resume taxonomy `58337879` all in\n  **v0.54.0** (USHER, merge `390204a3` et al.); attach-intent re-aim `37afa571` in **v0.55.0**).\n  Any later record citing these as \"authored-unlanded riders\" (the v0.63.0 FIELD-SEAL plan did,\n  carried forward from this ledger) is stale — this row is the correction. The #145 gate itself\n  CONCLUDED GREEN attempt 5, main ff'd, tested==merged · **Origin:** doyle, night of 2026-08-04,\n  run 30873007187 attempts 1-5.\n- **The record:** four reds, four DIFFERENT daemon-spawning tests, Windows leg only, Linux green\n  at the same sha every attempt: a1 `daemon::tests::a_tree_teardown_reaches_a_grandchild…`\n  (10.225s full deadline, 2nd golden sighting — see [[IR-17]]'s updated sub-observation); a2\n  `registry_lifecycle::multichunk_feed_applies_with_exactly_one_snapshot_write` (0-vs-1 at\n  mono_ms 77, THIRD sighting of the 2026-07-22 seed; hertz source-named the window: converge\n  polls rows landed at merge, assert reads `snapshot_writes` incremented in `write_snapshots`,\n  unjoined-thread gap between — predicts under-count only, matching all sightings; quiet-arm\n  control 40/40 PASS 0 leaky on a still box); a3 `brain_split::broker_survives_brain_kill…`\n  (\"supervisor did not respawn the brain\", 32.8s window burn; characterization queued); a4\n  `resume_no_control_steal_e2e::brain_respawn_keeps_every_session_controller…` — UNDER the\n  ruled quiesce-partial window with a measured-clean box, and its panic NAMED A MECHANISM ITS\n  OWN DATA CONTRADICTS (pre-authored Failure-A text; gained=[0,15,17] through ONE\n  resume_sessions while a steal displaces the SET; session 0 already 4x behind BEFORE the\n  window; the rig's child-liveness immunity was a COMMENT nothing measured). Every red\n  lane-independent by per-row delta test run fresh each time, never transferred.\n- **Instruments authored off it (all thin test/obs lanes off `11169c1`, compiled where stated;\n  ALL LANDED — v0.54.0/v0.55.0, see Status):** hertz `test/twohost-serve-window` @`17bbbd8`\n  ([[IR-29]]); hertz grandchild SELECTION probe (+166/-8 daemon.rs test-mod: IsProcessInJob at\n  selection time — decisive H1/H2 splitter, birth-stamp one-directional, image, same-snapshot\n  match COUNT; compiled + deliberate-break positive control); hertz `test/resume-steal-taxonomy`\n  (+109/-6: producer counter `Broker::session_output_seq` bracketing the consumer window,\n  authenticated child pin at t1 BEFORE teardown — read at assert time would convict the rig of\n  its own cleanup — three-way verdict PRECONDITION / measured-Failure-A-with-producer-story /\n  absent-producer-is-its-own-story); todlando `obs/resume-attach-intent` @`9c9e6c5`\n  — **a DEAD-PATH emit that never fired in production; removed 2026-08-04.** The\n  `RESUME_ATTACH_INTENT` breadcrumb sat in `resume_sessions`, which has had NO production\n  caller since `03c7109` (2026-07-09): the daemon's respawn path is `run_brain` ->\n  `resume_session_cursors`, cursor-only, no attach. Its absence from a field log therefore read\n  as \"no resume happened\" when it meant \"uncalled function\" — a clean-zero manufactory aimed at\n  the very #123 hunt it was built to serve. **Do not hunt for this token.** The instrument now\n  lives at the choosers the daemon actually executes, as `ATTACH_INTENT_CHOSEN` with a distinct\n  `site=` per chooser (`gap_resume` | `serve_request` | `shell_channel`), carrying the emit\n  discipline this one always had — intent bound once, logged and passed from that same binding,\n  wildcard-free label. No REQ, per the OBS-rider precedent.\n  - _Corrected 2026-08-04 (todlando, in the re-aim rider lane): this row previously described\n    the breadcrumb as a live instrument — \"intent bound once, logged and passed from the same\n    binding, per-call epoch makes set-vs-one readable off the log\". That sentence was true\n    about the emit's CONSTRUCTION and false about its REACH, and a reader consulting this\n    register during the #123 hunt would have been sent after a token that cannot fire.\n    Replaced rather than annotated, per the register's correction convention; the superseded\n    wording lives in git._\n- **Rulings that outlive the night:** a green retires NO intermittent row — grandchild and the\n  a4 row are INSTRUMENTED-AWAITING-FIRE, the next occurrence carries its own verdict; the\n  environmental family's leg 3 (runner off the fleet host) stays operator-ruled NON-OPTION\n  (\"stop proposing it\") — sightings accumulate in the family record, evidence files itself,\n  re-asking is direction; the quiesce-partial window is the sanctioned tool and it WORKED as a\n  discriminator (a4's red under quiesce is what forced the rig-soundness finding).\n- **Instrument notes minted on the way, cheap to lose:** (a) `gh run view --log` refuses for a\n  COMPLETED attempt while any later attempt is live (gates on the RUN) — recover per-job with\n  `gh api repos/<o>/<r>/actions/jobs/<id>/logs`; (b) a process-census RESIDENT COUNT is not\n  trendable (23→17→15 in 90s of inbox-poll CLI churn) — the CLASSIFICATION is the measurement,\n  the count is noise; (c) nextest's per-run LEAKY count is a free process-leakage series already\n  in every log (a1=12/a3=10/a4=13, and the multichunk row alone leaks 0/40 — the leaks are the\n  row's NEIGHBOURS); (d) diagnostic-token greps derive from the FAILING FRAME's own emit sites,\n  never from the register entry discussing the symptom — the gater's own\n  `REAP_JOB_TERMINATE_FAIL` zero over a path that emits `SERVICE_TREE_KILL_INCOMPLETE` was VOID,\n  and the emit sites document their own vocabulary (tree_kill_incomplete_line's doc names its\n  grep-partner); (e) **\"golden green ⇒ box free\" is FALSE — the ff-push that concludes a golden\n  STARTS the automatic post-merge ci run on the same box** (hertz, measured to the second:\n  Runner.Worker up 00:13:02 local = run 30886843672 job start 07:13:02Z, ~2min after the ff), so\n  the box empties after the POST-MERGE run, not after the golden; the box has a fourth actor no\n  agent steps off, woken by every main push (todlando's spelling), and post-golden sequencing\n  must gate on `gh run view --json jobs` of the post-merge run before any timing-sensitive work.\n- **Ripe when:** ~~instrument lanes land~~ (DONE, v0.54.0/v0.55.0); family sightings stay until\n  the family record closes them — the entry now waits on FIRES, not landings. **Size:** nothing\n  left to build; the next family sighting carries its own verdict via the landed instruments.\n- **LINUX-FACE SIGHTING + ITS RESOLUTION (doyle, v0.63.0 FIELD-SEAL goldens r1-r3 + proof runs,\n  2026-08-25 — the family's first measured MECHANISM, and it is environmental-amplifier ×\n  latent-test-defect, not a product fault):** three goldens, three DISTINCT kitsubito victims,\n  8/9 green each, victims migrating across same-sha reruns (r2/r3), every red a LONG death\n  (9.9s/59.4s/62.7s) of a fast cell — the family signature on the OTHER OS. Root-caused to ONE\n  window whose WIDTH varies with load: the brain's `spawn_session_pid` Spawned-wait\n  consumes-and-discards output racing ahead of the reply (KNOWN-HAZARDS 6.9, same-session face,\n  amended at `dbe3daad`); the broker execs the PTY child ~2ms BEFORE writing `Spawned`, so a\n  fast first chunk can be eaten. Under kitsubito's then-active kernel-audit backpressure\n  (see the kitsubito-audit entry below) the broker DISPATCH thread could stall arbitrarily in\n  that gap — the ~2ms window stretched to seconds, swallowing ANY marker prefix of ANY\n  spawn-wait test: random victims, long deaths, spawn-intensity × serialization scaling\n  (deployah's measured pair), migration across reruns. Box remediation narrowed the window back\n  to ~2ms, leaving exactly one knife-edge victim (a first-chunk needle, near-deterministic red,\n  62.7s natural-life death), fixed test-side in `dbe3daad` (v0.63.0's head). Full RCA + the\n  observer-effect instrument record: releases#225 comments 5417343026/5418844404.\n  **Standing lesson for the family:** an environmental slowdown is an accidental mitigation —\n  REMEDIATING a box can EXPOSE latent knife-edge races (the storm had hidden this one for\n  releases). And a \"random victim family\" should be tested against ONE window with\n  load-dependent width before positing per-victim mechanisms. The Windows face above remains\n  open on its own instruments; the two faces now have one shared candidate SHAPE (a race window\n  amplified by box load) with different windows.\n- **Status:** open · **Origin:** measured box event, HFENDULEAM 2026-08-04 ~05:00 local, during\n  USHER lane concurrency (hertz mechanism statement + both agents' reclaim arithmetic).\n- **What/why:** the box hit **0.00 bytes free** mid-build. Failure signatures it manufactured\n  look like toolchain or code defects, not disk: `rustc-LLVM ERROR: IO failure on output stream:\n  no space on device`, `LNK1318: Unexpected PDB error; LIMIT (12)`, `LNK1108: cannot write file`\n  — a red wearing a linker's face (doyle's U2 gate rig ate exactly this; verdict legs already\n  green survived, the suite leg had to be re-run). Contributions measured, not inferred: hertz\n  ~70 GB across four lane targets (er-seams **42.66 GB** cold `--workspace --tests`,\n  selection-probe 25.80, poolowner 1.03, ci-riders 0.91), doyle gate rig 15 GB cold full build.\n  Reclaim arithmetic reconciles both and neither alone: 0.00 → 25.47 GB (hertz reaps\n[…451ln elided…]\n  what this entry carries is the DIAGNOSTIC asymmetry.\n- **Ask:** a fixture-bin existence precondition that NAMES the missing exe and its build recipe\n  wherever a rig consumes one — `sibling_bin` (and the shared\n  `crates/spt-term/tests/support/fixture_bin.rs` resolver already carries the recipe string as an\n  argument, the shape to copy) refuses with the artifact + recipe instead of letting the consuming\n  test fail downstream in its own vocabulary.\n- **Kin:** [[IR-21]] (wrong-lane-diagnostic family: the failure names the wrong actor), the\n  cargo-builds-package-bins-for-integration-tests rule (cross-package row is the only unguaranteed\n  build), golden.yml's dedicated fixture prebuild step.\n- **Ripe when:** the test-hygiene lane (IR-13/IR-23/IR-36/IR-38 family) — same sweep population;\n  or standalone small if that lane keeps slipping.\n- **Size:** small — one shared helper + a sweep of local `sibling_bin` resolver copies (24 known).\n- **Addendum (doyle, 2026-08-04 late): third and fourth sightings inside 24 h.** Face 1 twice\n  more the same evening — todlando's teach-lane leg set (his own translate_proof_fixture, caught\n  by his prebuild), and doyle's cold gate rig for the same lane (first-pass spt-bins red at\n  136/611, correctly withheld from the lane verdict as rig evidence, fixed by `cargo build -p spt\n  --bins` + rerun 611/611). Four sightings in one day across three agents and both faces: the\n  ripeness condition (\"the test-hygiene lane keeps slipping\") is under measurable pressure — the\n  prebuild remedy is being re-derived per-rig per-agent, which is the recurring cost the shared\n  precondition helper exists to delete.\n- **Built evidence:** all 29 file-local `sibling_bin` resolvers now route through one shared\n  precondition. A missing fixture names its path and the package-correct `cargo build -p <owner>\n  --bin <name>` recovery command before product assertions or timeout paths run; a focused\n  negative test pins that diagnostic.\n\n### IR-40 — CLASS: NO envelope-side ordering signal on a resume brief tracks content recency, and a CI informant's per-job line is a claim about that STEP, not the run\n- **Status:** open · **Origin:** three sightings in one night, 2026-08-04/05 — hertz, doyle,\n  todlando (filed by doyle; the artifacts are hertz's and todlando's, the CI arm is doyle's with\n  deployah's framing). Two arms of ONE family: a stale record that carries a confident ordering\n  signal, and a status claim that arrives before the thing it describes.\n\n- **ARM A — resume briefs. What/why:** a session can receive TWO start-of-session briefs, and the\n  one routed LATER can carry the STALER project-context. Measured on hertz's pair (same node id):\n  routed_at_ms `1785897407373` > `1785896642480`, spill-filename epoch `1785897764588` >\n  `1785896658159`, and vector sequence `1242529/1242531` > `1241542/1241544` — **all three\n  monotonic orderings rank the staler-content brief as newer.** todlando's pair is the NEGATIVE\n  arm: his later brief (`…1785897765196`, routed `…577476`, vector `1242756/7`) genuinely WAS the\n  fresher one, so the same heuristic happened to pick right.\n- **The finding is UNCORRELATED, not inverted** — and that is the whole entry. An inverted signal\n  is usable once you know to flip it; an uncorrelated one reads as reliable until the pair where it\n  costs you. Neither agent could have known which pair he held without checking content against\n  measurement. **Do not name routed_at_ms specifically** — naming the stamp invites the repair that\n  fails (\"the timestamp is unreliable, use the sequence number\"). The vector is the most dangerous\n  of the three: a stamp looks like a clock and invites suspicion, a sequence number looks like an\n  ordering and does not.\n- **Visible failure mode if a brief is obeyed as instructed** (hertz's, measured): re-open\n  `releases#123` — work already ruled closed — and under-report his own claimed-pool count by one,\n  the row sitting under a live gate. doyle's own sighting the same night: a brief describing main\n  @`92b2482` with a teach lane \"mid-flight\" hours after every lane had gated.\n- **PRE-REFUSED DISCRIMINATOR, recorded so it is not rediscovered as a finding:** file SIZE ranks\n  the fresher brief correctly on BOTH pairs (hertz 16308 > 12649; todlando 14138 > 10418) — 2 of 2,\n  the only signal surviving both samples. **Do not use it.** Size measures RICHNESS, not recency;\n  the two correlated only because todlando's thin brief was a correction fragment, and hertz's\n  STALER brief was a full 12649-byte dump. Two full dumps hours apart go flat or inverted. Handed\n  over pre-refused by its own finder.\n- **ARM B — CI informants (doyle, 2026-08-05, run 30971976024).** `CI-KITSUBITO` sent\n  \"CI SUCCESS … sha 0a25b77\" while the run was measurably `status=in_progress` with\n  `conclusion=\"\"` — the EMPTY STRING, not `success`. The informant fires from a per-job `notify`\n  step, and at send time `notify` itself had no conclusion. All eight substantive jobs were green,\n  so the line was **right in the end but EARLY**. deployah's framing, kept verbatim in kind: *an\n  informant line that is right in the end but early is worse than one that is simply wrong, because\n  a wrong signal gets distrusted while an early-but-correct one gets promoted to the conclusion.*\n  todlando's sentence is the one to keep at the point of use: **a per-job notify step's message is\n  a claim about that STEP, not about the RUN.**\n- **ARM B MECHANISM — hertz, source read 2026-08-05, zero box cost. It is NOT a race; it fires\n  early on EVERY run, and the entry above understated it.** `notify` is a job INSIDE the run\n  (`golden.yml:1138`), and a job cannot observe its own run's conclusion — so `conclusion: \"\"` is\n  not a timing artifact, it is **the only value that can exist when the informant speaks. The\n  informant has never once made a statement about a run conclusion.** What `ci-notify.sh` actually\n  asserts is narrower and worth naming exactly: a verdict computed PURELY from six `needs` results\n  (changes, traceability, test, n1-gate, twohost-a, twohost-b — the two matrices collapse to one\n  result each) being neither failure nor cancelled. Nothing more.\n  **The blind spot is exactly ONE job: `notify` itself, the 9th — it cannot appear in its own\n  `needs` list. And that one job has a WITNESSED red path**, documented in the script's own header\n  (2026-07-27, twice on kitsubito): verdict computed, then `spt send` HUNG ~5 minutes until the\n  job's own 5-minute budget cancelled it, and that cancellation reddened the run. So *\"informant\n  says SUCCESS, run concludes FAILURE\"* is a real observed sequence, not a hypothetical. The 30s\n  `SEND_BOUND_SECS` added since bounds the hang but does not close the class — it makes the\n  informant's own failure FAST rather than impossible.\n  ⇒ The informant's SUCCESS covers 8 of 9 jobs and is blind to the 9th, and the 9th is the only one\n  with an observed failure mode that reds the run. This is why the ff predicate is the run's\n  conclusion field and never the informant line.\n- **RECOVERY, and it is the same for both arms: never rank the claims — re-derive from the source\n  object.** For briefs, hertz's four falsifiers are the method (main sha, claimed-pool count, lane\n  tip, issue state) and they work because each is a content claim checkable in ONE command against\n  a source NEITHER brief controls. For CI, read the RUN's own `conclusion` field, and prefer\n  independent reads of the run object (`gh run watch --exit-status` polls the run, so its exit is a\n  second measurement rather than an echo of `notify`). On the batch this was caught in, three\n  sources agreed with the informant excluded from all three before main was fast-forwarded.\n- **Standing rule this entry exists to enforce:** a resume brief's RULINGS are durable; its STATE\n  is a HYPOTHESIS to re-derive before acting.\n- **Kin:** [[IR-21]] and [[IR-39]] (the diagnostic names the wrong actor / the wrong subject),\n  [[IR-32]] (a gate that cannot see its own blind spot), [[IR-34]] (an intermittent marker read as\n  a signal).\n- **Ripe when:** the next commune/psyche-tier touch for arm A (the routing layer is spt-core's own\n  `spool`/psyche ingest, so a remedy is in-repo, not upstream); for arm B, the next `golden.yml`\n  informant touch — the cheap fix is that the notify step names its own scope in the message body\n  (STEP vs RUN) rather than emitting a bare \"CI SUCCESS\".\n- **Size:** arm B small (message text + scope word in one workflow step). Arm A unsized —\n  establishing whether ANY durable content-recency signal can ride the envelope is the measurement,\n  and until it runs the answer is \"re-derive, do not rank.\"\n\n### IR-41 — A QUEUED main run is superseded without a record; `cancel-in-progress: false` protects only STARTED runs\n- **Status:** open — mechanism CONFIRMED (doyle ruling 2026-08-05); the runbook sentence it\n  falsified is already corrected (`docs/RELEASE-RUNBOOK.md` step 3, same commit as this entry)\n  · **Origin:** deployah, v0.55.0 publish night, filed by him explicitly as UNPROVEN with the\n  manual-cancel alternative not ruled out; confirmed by doyle on the run objects.\n- **What/why:** `ci.yml` sets `cancel-in-progress: false` on main and the runbook read that as\n  \"main's concurrency policy never cancels this run; that preserves the record.\" FALSE for the\n  queued phase: a concurrency group holds at most one running + one pending run, and a newer push\n  REPLACES the pending run regardless of the flag — the flag governs only whether a STARTED run\n  is cancelled. A superseded queued run leaves NO record: zero jobs, conclusion `cancelled`,\n  nothing measured about its sha.\n- **Evidence (all read off the run objects, not the informant):** run 30973909279 at `327f1f8`\n  (push, main) — created 04:01:08Z, **zero jobs ever started**, cancelled 04:03:49Z, ONE SECOND\n  after `e8805f7`'s run 30974041521 entered the group (created 04:03:48Z), while `0a25b77`'s run\n  30973770039 was still in flight (done 04:07:59Z). One-running-one-pending, newer push landed,\n  pending run died. The 1s coupling to an unrelated push is the discriminator against deployah's\n  own manual-cancel alternative — a human cancel co-timed to the second with a push it had no\n  view of is not a credible mechanism; supersession fires on exactly that trigger by design.\n- **The hole this leaves:** under a rapid push sequence, an intermediate sha on MAIN can have no\n  thin-CI verdict AT ALL, and the absence reads as nothing rather than as supersession. Anyone\n  auditing \"did sha X pass main CI\" gets a hole where the runbook promised a record. Absence of\n  a run is now a labelled state, not evidence about the sha.\n- **Ripe when:** next ci.yml/runbook touch. Candidate remedies to weigh THEN, not now: accept and\n  document (done — the runbook now carries the mechanism), or give main's group per-sha keys\n  (`group: ci-${{ github.sha }}`) so runs never share a group — at the cost of concurrent main\n  runs competing for the boxes, which is exactly what the group exists to prevent. The trade is\n  real; do not fold it into a drive-by.\n- **Size:** docs half DONE in this commit; ci.yml half small but load-bearing — needs its own\n  lane if taken.\n- **Kin:** [[IR-40]] (a record that is right-in-the-end-but-early vs a record that never comes to\n  exist — both read as clean states unless labelled), [[cancelled-measurement-leaves-labelled-hole]].\n\n### IR-42 — `pool-claim` writes a record; only the BUILD enforces — and AGENTS.md invited the misread\n- **Status:** BUILT 2026-08-19 — the AGENTS.md corrective line lands in the SAME COMMIT as this\n  entry (the register batch commit), which is the entry's stated exit condition. The optional\n  code-side nicety (claim verb prints the incumbent record it overwrites, information only)\n  remains unclaimed — a candidate rider on the IR-26 remedy lane, which already touches\n  `pool_claim`'s read-before-write path, NOT a reason to keep this entry open ·\n  **Origin:** doyle + todlando independently at source, 2026-08-19, during the #193 gate.\n- **Mechanism (source-verified):** `xtask pool-claim` (crates/xtask/src/main.rs:2232-2294 at the\n  read sha) parses its args, reads the lane's own git identity, builds a `PoolOwner` and calls\n  `spt_poolguard::write_owner` UNCONDITIONALLY (:2280) — no `read_owner`, no verdict, no\n  comparison against the incumbent claim anywhere in the function. Claiming is last-writer-wins\n  by construction: two lanes can each \"hold\" a pool in sequence with only the last write\n  surviving, and the displaced lane learns nothing at displacement time. All four enforcement\n  arms — `Refuse` (SPT_POOL_FOREIGN), `Takeover` (loud), `Unproven`, `HatchOpen` — live in\n  crates/spt-store/build.rs:31-113 and speak only at the next BUILD. (Same object [[IR-26]]'s\n  CLAIM-OBSERVABILITY measurement saw from the displaced side; this entry is the CLAIMING side\n  plus the doc that invited the misread.)\n- **Measured consequence:** 2026-08-19, doyle's gate claim over todlando's unlanded\n  redeem-echo-diag claim — no refusal, no notice (three sequential overwrites that session, one\n  over a lane with an unlanded commit). todlando then predicted from AGENTS.md's refusal\n  sentence that the gate's claim \"will be REFUSED\" — a false warning to a gater mid-run. The\n  refusal sentence sat directly under the \"Claim a pool at lane start\" instruction, inviting the\n  build-time semantics to be read onto the claim verb.\n- **Corrective landed:** the claim WRITES a record without adjudicating the incumbent lane;\n  predict **lane-identity** refusals from builds, never from `pool-claim`. The broader original\n  \"never refuses\" wording is superseded by IR-56's **addressing** guard (wrong-tree claims need\n  explicit `--foreign-pool`); that guard does not add incumbent-lane adjudication.\n\n### IR-43 — knock answer carrier: `NoReply` landed at 60.08s against a stated 30s carrier deadline\n- **Status:** open, OBSERVATION — mechanism unmeasured, filed exactly as wide as the datum ·\n  **Origin:** KNOCK-169 RCA layer 1 (todlando, read-only), golden 32191618042 @`93c1130`,\n  twohost-b, 2026-08-18.\n- **What/why:** B's `request_answer` yielded `NoReply` at 22:50:08.3605Z — 60.08s after A's\n  death — while the carrier deadline is stated at 30s. Recorded in the RCA as a side observation\n  with no claim; the cell's red itself was a CASCADE of A's earlier death (answerop.rs:73-81\n  produces the courtesy BEFORE returning, so the reply was never sent — that half is settled and\n  is NOT this entry). What this entry carries: a transport/liveness bound that reported at 2x its\n  stated value. Candidate shapes, neither asserted: two sequential 30s legs each honoring its own\n  bound (a composed wait wearing one bound's name), or a bound armed after a wait it does not\n  cover (the [[IR-30]] nethost.rs permit-wait shape: `sem.acquire_owned()` outside the timeout).\n- **Ask:** derive where the 30s is armed and what path yields a 60s `NoReply` — one code read\n  from the emit site, before any instrument.\n- **Ripe when:** next knock-carrier touch, or the next `NoReply`-shaped red — whichever first.\n- **Size:** small (code read; a token only if the read forks).\n\n### IR-44 — perch-sentinel comment overclaims: serialization is not preservation, and the comment teaches the false step\n- **Status:** open · **Origin:** #188 RCA lock read (todlando flagged, doyle confirmed the lock\n  read), 2026-08-18; the collapse-of-branches argument is on #188 and in the RCA record.\n- **What/why:** `lock_perch_sentinel` (info.rs:778 at `b20e770`, the diag sha — re-derive the\n  line on main before editing) takes a cross-process fs2 lock on a stable per-perch `.info.lock`\n  sentinel, and its comment claims it serializes \"ALL info.json writers so a whole-record write\n  and a locked RMW can never lose each other's update (`REQ-HAZARD-INFO-RMW-LOST-UPDATE`)\" —\n  TRUE for interleaving, FALSE for preservation. `write_info_unlocked` is module-private with\n  exactly three callers, all taking the sentinel first (bypass refuted by visibility), but every\n  caller of the public `write_info` composes its record BEFORE the lock is taken (:842) — **the\n  lock makes that write atomic; it cannot make it preserving.** Only `mutate_info` /\n  `establish_locked` read under the hold and can preserve. Measured field case: census write #1\n  (`twohost.rs:736`) clobbered `controlled` while correctly locked. A reader trusting the\n  comment infers lost-update immunity the funnel does not provide — the #188 hunt burned a\n  branch on exactly that inference before the collapse argument killed it.\n- **Ask:** respell the comment — serializes writers; a composed `write_info` is atomic, never\n  preserving; preservation requires `mutate_info`/`establish_locked` — and weigh whether\n  `REQ-HAZARD-INFO-RMW-LOST-UPDATE`'s doc wording carries the same overclaim.\n- **Ripe when:** next spt-store/info.rs touch. **Size:** tiny (comment + possibly one REQ doc\n  line).\n\n### IR-45 — twohost rig home premise, SETTLED: pump paths resolve under the per-run TEMP root (rig is disk-hermetic; the \"live fleet roster\" reading is retired)\n- **Status:** RETIRED 2026-08-19 — ask answered by the one code read at main @`78a9a16`; residue\n  re-homed (see Answer). · **Origin:** #188/#189 RCA readouts (todlando, doyle's 2a-2d), runs\n  32097943571 + 32108557362 + 32111921251, 2026-08-18.\n- **What/why, two measured halves in tension:** (1) B's pump dialed a THIRD node 155-159 times\n  per run at kitsubito's OWN tailscale IP (`100.98.197.12`), different hex + different ephemeral\n  port each run — a short-lived local endpoint re-minting identity between runs, present in both\n  the golden and the diag run. Read at the time as: the rig uses the CANONICAL home\n  (`canonical_pump_paths` → `perch::spt_home()`), so B's roster is kitsubito's live fleet\n  roster — environmental coupling of a CI rig to host fleet state. (2) The ER perch measured in\n  the chain runs resolves under a per-run TEMP root\n  (`…/_temp/spt-test-tmp-<run>…/owlery/engine-room`), NOT the canonical home. Both measurements\n  stand; they answer different artifacts (pump roster vs perches), and nothing on record settles\n  which home the PUMP paths actually resolve. #189's third-node evidence and its\n  cache-leg-never-heals reading rest on that premise (the tension is filed on the #188 record as\n  an open question against #189).\n- **Answer (2026-08-19, code read at `78a9a16`, unambiguous — no run token needed):** both role\n  tests set `SPT_HOME` to a fresh per-run `TempDir` as their FIRST act (`twohost.rs:813-814` role\n  B, `:1501-1502` role A), before any store touch. `canonical_pump_paths` resolves every path via\n  `perch::spt_home()` (`twohost.rs:396-414`), which honors the `SPT_HOME` override first\n  (`perch.rs:34-41`); the pump's roster source `presence::registry_snapshot_dir()` →\n  `perch::identity_dir()` sits under the same root (`presence.rs:83-85`). The rig is\n  DISK-HERMETIC per run; both prior measurements reconcile (ER perch observed under the temp\n  root, pump paths resolve there too). The misleader was the helper's name + doc comment (\"real\n  homes, not test roots\"), which describe production path LAYOUT, not the resolved ROOT.\n- **Residue disposition:** (1) #189's third-node evidence was corrected on the board (comment\n  5337519936) — the roster row arrived at RUNTIME into a temp-rooted store, ingress mechanism\n  OPEN on #189, no longer explained-environmental. (2) KEYSTONE #182's hygiene lane repaired the\n  `twohost.rs:394` comment to say exactly what the helper does: production path layout rooted in\n  the process's fresh per-run `SPT_HOME`.\n\n### IR-46 — the Windows disk-floor preflight asserts an INSTANT; workspace free space moves tens of GB inside the hour, so a green floor is not a claim about run headroom\n- **Status:** open — mechanism CONFIRMED by a measurement series on hfenduleam; doyle ruled it\n  register-shaped 2026-08-18 · **Origin:** deployah, NAMEPLATE #181 golden-head intake, on the\n…\n  version of it.\n…\n\n…\n\n\n[Showing lines 1-225 and 677-916 of 916; 451 middle lines (39.1KB) elided. Use :2710 to continue. Read artifact://730 for full output]"}],"details":{"truncation":{"content":"\r\n### IR-27 — A junction-pooled rig is TWO objects and teardown only ever removes one\r\n- **Status:** open, found in the wild 2026-08-04 · **Origin:** hertz's 44-tree worktree sweep\r\n  (IR-26 follow-on 3) · **Cross-ref:** [[IR-14]] (unclaimed pools), [[worktree-target-junction]]\r\n- **What/why:** a rig built as `worktree\\target -> junction -> .worktrees\\<pool>` has its build cache\r\n  in a directory that is NOT the worktree and NOT in `git worktree list`. `git worktree remove` deletes\r\n  the junction and reports success; the pool survives with zero inbound links and nothing naming it.\r\n  Measured on this box: reaping `golden-render` and `w4-cli-doc` the obvious way would have reclaimed\r\n  ~26 MB of worktree and stranded **14.17 GB** of pool (`gate-target-render` 6,265,448,382 B +\r\n  `gate-target-w4doc` 7,907,558,098 B). Neither pool appears in any worktree listing.\r\n- **The second shape, same mechanism, already realised:** `.worktrees\\gate-target` was found at\r\n  **0 files / 0 bytes with FOUR live inbound junctions** (assembly-doorbell, doorbell-w1/w2/w3). Someone\r\n  had already reaped that pool and left four dangling-but-valid links behind. So the defect runs both\r\n  ways: remove the worktree and the pool is orphaned; remove the pool and the links are orphaned.\r\n  Either half alone leaves a lie on disk.\r\n- **Why it is not just \"be careful\":** the classification step people already know\r\n  (`Get-Item -Force` OUTBOUND, INBOUND reparse sweep) tells you HOW to delete an object you have\r\n  already decided to delete. It does not tell you that a second object exists. The missing thing is an\r\n  enumeration that reaches pools no worktree names.\r\n- **Remedy shape (CORRECTED by builder retraction, 2026-08-04 — the enumeration already exists and\r\n  shipped):** `xtask pool-sweep` (`c6515f1`, `REQ-POOL-GC-ORPHAN-RECLAIM`, ancestor of `b7b00c3` by\r\n  merge-base) walks the root for dirs AND links, counts inbound links over the whole sweep before\r\n  forming a verdict, classifies InUse/Owned/Orphaned, and reaps orphans on `--reap`. The gap is not\r\n  detection, it is TIMING: a junction-pooled tree's pool is `Owned` and not reclaimable right up to\r\n  the moment its worktree is removed, and `Orphaned` only after — so the reclaim always lands in a\r\n  LATER sweep, and nothing triggers one. `gate-target` (0 bytes, four dangling inbound links) is a\r\n  completed instance of that deferral. Remedy is a post-teardown pass or a teardown that runs the\r\n  sweep itself, not new enumeration. (An earlier draft of this entry proposed building the\r\n  enumeration; retracted by its author before ripening — the tool refuting it was one run away.)\r\n- **Ripe when:** next CI/infra batch. **Size:** small (one enumeration + report, no new policy).\r\n- **Discipline this cost, stated so it is not re-learned:** teardown must be TWO EXPLICIT STEPS per\r\n  junction-pooled tree — junction deleted AS A LINK (`Directory.Delete(path, recursive: false)`), then\r\n  the pool AS A TREE after an inbound sweep confirms it is linkless. Executed that way on 2026-08-04:\r\n  28 worktrees, 4 pools, 0 skipped, 0 pinned, 17.04 GiB measured on a box with concurrent writers.\r\n\r\n### IR-28 — A wave-gap rider is visible to the request board and invisible to a milestone-narrative notes pass\r\n- **Status:** BUILT 2026-08-29 — PR #176 (`880b3b9c`, landed on main via `37368263`).\r\n  · **Origin:** deployah, v0.53.0 release close 2026-08-04.\r\n- **What/why:** the v0.53.0 changelog omitted `184f2ac` (the releases#125 two-core CPU-burn fix, a\r\n  wave-gap rider that rode the commit range but was never LOCKSMITH scope) while the alchemy release\r\n  verb promoted #125 to DONE and named it publicly as shipped — two published surfaces contradicting\r\n  each other until the post-publish docs-only repair (`9841592`). The rule was already right (the\r\n  runbook audits the changelog against the COMMIT RANGE); the EXECUTION missed it, because a notes\r\n  pass written from the milestone narrative never enumerates the range. The mechanism, not the\r\n  incident: any rider is board-visible and narrative-invisible.\r\n- **Built evidence:** `docs/RELEASE-RUNBOOK.md` now requires a mechanical `vPREV..HEAD`\r\n  user-facing commit list, a changelog match beside every row, and an explicit accounting of every\r\n  unmatched row before the golden run. The repair precedent remains docs-only amend +\r\n  `gh release edit`, never retag. PR #176 passed `traceable-reqs check`.\r\n\r\n### IR-29 — twohost ladder: role A fires the done-barrier BEFORE its last cross-node rung, so the re-pull's serve window is won by timing, not guaranteed\r\n- **Status:** OPEN for later serve-window/rung residuals; the original\r\n  `test/twohost-serve-window` fix `17bbbd8` LANDED in v0.54.0, as recorded by IR-30.\r\n  Stale authored-but-unlanded header corrected 2026-09-11; no new acceptance or margin\r\n  measurement claimed. · **Origin:** golden\r\n  30873007187 attempt 1 red, doyle timeline triage + hertz source diagnosis 2026-08-04.\r\n- **SECOND FACE, measured 2026-08-24 (WAX-SEAL #21 W3 gate climb @ 035c3fe6, doyle):** the class\r\n  recurs on a NEW rung, and this face is UNWINNABLE rather than racy. The W3 seal rung S1 mints\r\n  on A ~0.3s before A's ladder completes (mint mono 80843ms, ladder end ~81150ms, walked from\r\n  the capture), while the seal pump worker's cadence is 500ms — the pusher exits before its\r\n  first eligible post-mint tick, so ZERO feed pushes ever fire (both logs hold zero seal-feed\r\n  lines) and role B burns its full 900s window on \"seal: A's record replicated into B's store\".\r\n  Full-re-presentation heals only while a pump is RESIDENT; the rig kills it. Product not\r\n  implicated (local legs + design review all green at the sha). Dispatched to hertz 2026-08-24\r\n  with two fix shapes (mint early with ~120 ticks of resident-pump margin, or a\r\n  reverse-confirmation barrier on A's done-push); the climb re-runs on his fix. Lesson for\r\n  future rungs, stated as construction: a rung whose delivery is CADENCED must not sit inside\r\n  the terminal margin of the process that pushes it.\r\n- **Mechanism (hertz falsified the gater's first spelling, kept because the correction is the\r\n  entry):** NOT \"B exits early\" and NOT a missing barrier. B's contract (twohost.rs:1116-1121,\r\n  \"hold until A finishes its side — done-file as the ladder's completion barrier\") is right and B\r\n  obeys it. A BREAKS it: A pushes done.txt (:1819-1832, payload literally \"ladder complete on A\")\r\n  then runs the ENTIRE leg-D digest rung including the re-pull assert (:1959) before its own\r\n  `stop.store` (:1966). B tears down exactly when A said it could; the re-pull then races B's\r\n  post-signal teardown. The panic's hint text (\"may be running a version without cross-node\r\n  digest\") is pre-authored and was NOT evidence of version skew.\r\n- **Margin series, six draws of one race (deployah, markers cited by TEXT and positive-controlled\r\n  against a known draw before producing an unknown one):** golden 30860770146 +60s · a1 −0.6s\r\n  (the RED) · a2 +59.4s · a3 +60s · a4 +59.59s · a5 +63.89s. BIMODAL, not drifting: greens\r\n  cluster within seconds, one collapse through zero. A green does not mean the window got safer;\r\n  sample count characterizes a bimodal race, not margin size — the slack is incidental, not\r\n  designed. Local load on hfenduleam during A's leg D eats the margin directly (role A runs\r\n  there; the done-file is already pushed), which is why builds hold through twohost legs.\r\n- **⚠ THE SERIES IS CLOSED AT SIX DRAWS — ITS DERIVATION IS UNRECOVERABLE, AND NO SEVENTH NUMBER\r\n  MAY BE ADDED (ruled by doyle 2026-08-05, at the tranche-2 golden).** Asked to extend it with a\r\n  draw from run 30971976024, deployah positive-controlled the markers FIRST and the control\r\n  REFUSED: grepping `margin|deadline|serve window|slack|headroom|budget` against a control run\r\n  known to carry good twohost evidence (30940180764) returned ZERO. Source confirms it —\r\n  **`margin` is not an emitted token anywhere**: absent from `.github/workflows/golden.yml`, and\r\n  every `crates/` hit is unrelated (terminal right-margins in broker/resize tests,\r\n  `ROUND_DRAIN_MARGIN` in `pump/mod.rs`). So the six figures were DERIVED from log timestamps\r\n  against a bound that was never written down, by a measurer whose context has since been cleared;\r\n  the gater who recorded them never held the formula either. **Consequence, stated so nobody\r\n  re-derives it:** any new figure computed from these logs would be a DIFFERENT quantity wearing\r\n  the same name, and would enter a series whose value is its bimodality — the one structure a\r\n  mismatched sample corrupts invisibly. This run therefore gets a LABELLED HOLE, not a number.\r\n  What IS reportable for it, with endpoints named rather than a name reused: **ladder span**, node\r\n  start → `TWOHOST role B: ladder complete` = **183.50s** on the batch vs **259.21s** on the\r\n  control. Marker parity established under an IDENTICAL expression on both sides (25 = 25, after a\r\n  first pass that compared two different greps and would have read as parity by coincidence).\r\n- **The fix this makes obvious:** the twohost margin must become an EMITTED token with its two\r\n  events named at the emit site, so the next draw is read rather than reconstructed. A derived\r\n  quantity whose formula lives only in a measurer's context is one context reset away from being\r\n  unfalsifiable — which is exactly what happened here.\r\n- **Fix shape (doyle-approved):** move the done-push block to AFTER leg D, immediately ahead of\r\n  A's stop — one honest barrier made true, no second completion signal (a redundant pair is how\r\n  the next ordering bug lands after the SECOND one). `int->REQ-REACH-1` travels with the block.\r\n- **Cascade note, so a future triage does not count it:** in a1, twohost-b's gated-CLI red\r\n  (twohost_cli.rs:189, 910s) was the CASCADE — role-A's gated driver step SKIPPED after the\r\n  ladder death, so B waited for a row never produced. A red that postdates its carrier leg's\r\n  failure carries zero information about its own subject.\r\n- **Ripe when:** proving run at the next two-host window. **Size:** landed-sized already.\r\n\r\n### IR-30 — GOLDEN 4b37512 (#145): five attempts, four distinct Windows victims, one sha — the random-victim family measured end to end, and the instruments it left behind\r\n- **Status:** open for the FAMILY SIGHTINGS ONLY — the instrument lanes LANDED as planned with\r\n  the next golden batches (measured 2026-08-25, doyle, `git merge-base --is-ancestor` + first\r\n  tag: serve-window `17bbbd8`, selection probe `695398ba`, resume taxonomy `58337879` all in\r\n  **v0.54.0** (USHER, merge `390204a3` et al.); attach-intent re-aim `37afa571` in **v0.55.0**).\r\n  Any later record citing these as \"authored-unlanded riders\" (the v0.63.0 FIELD-SEAL plan did,\r\n  carried forward from this ledger) is stale — this row is the correction. The #145 gate itself\r\n  CONCLUDED GREEN attempt 5, main ff'd, tested==merged · **Origin:** doyle, night of 2026-08-04,\r\n  run 30873007187 attempts 1-5.\r\n- **The record:** four reds, four DIFFERENT daemon-spawning tests, Windows leg only, Linux green\r\n  at the same sha every attempt: a1 `daemon::tests::a_tree_teardown_reaches_a_grandchild…`\r\n  (10.225s full deadline, 2nd golden sighting — see [[IR-17]]'s updated sub-observation); a2\r\n  `registry_lifecycle::multichunk_feed_applies_with_exactly_one_snapshot_write` (0-vs-1 at\r\n  mono_ms 77, THIRD sighting of the 2026-07-22 seed; hertz source-named the window: converge\r\n  polls rows landed at merge, assert reads `snapshot_writes` incremented in `write_snapshots`,\r\n  unjoined-thread gap between — predicts under-count only, matching all sightings; quiet-arm\r\n  control 40/40 PASS 0 leaky on a still box); a3 `brain_split::broker_survives_brain_kill…`\r\n  (\"supervisor did not respawn the brain\", 32.8s window burn; characterization queued); a4\r\n  `resume_no_control_steal_e2e::brain_respawn_keeps_every_session_controller…` — UNDER the\r\n  ruled quiesce-partial window with a measured-clean box, and its panic NAMED A MECHANISM ITS\r\n  OWN DATA CONTRADICTS (pre-authored Failure-A text; gained=[0,15,17] through ONE\r\n  resume_sessions while a steal displaces the SET; session 0 already 4x behind BEFORE the\r\n  window; the rig's child-liveness immunity was a COMMENT nothing measured). Every red\r\n  lane-independent by per-row delta test run fresh each time, never transferred.\r\n- **Instruments authored off it (all thin test/obs lanes off `11169c1`, compiled where stated;\r\n  ALL LANDED — v0.54.0/v0.55.0, see Status):** hertz `test/twohost-serve-window` @`17bbbd8`\r\n  ([[IR-29]]); hertz grandchild SELECTION probe (+166/-8 daemon.rs test-mod: IsProcessInJob at\r\n  selection time — decisive H1/H2 splitter, birth-stamp one-directional, image, same-snapshot\r\n  match COUNT; compiled + deliberate-break positive control); hertz `test/resume-steal-taxonomy`\r\n  (+109/-6: producer counter `Broker::session_output_seq` bracketing the consumer window,\r\n  authenticated child pin at t1 BEFORE teardown — read at assert time would convict the rig of\r\n  its own cleanup — three-way verdict PRECONDITION / measured-Failure-A-with-producer-story /\r\n  absent-producer-is-its-own-story); todlando `obs/resume-attach-intent` @`9c9e6c5`\r\n  — **a DEAD-PATH emit that never fired in production; removed 2026-08-04.** The\r\n  `RESUME_ATTACH_INTENT` breadcrumb sat in `resume_sessions`, which has had NO production\r\n  caller since `03c7109` (2026-07-09): the daemon's respawn path is `run_brain` ->\r\n  `resume_session_cursors`, cursor-only, no attach. Its absence from a field log therefore read\r\n  as \"no resume happened\" when it meant \"uncalled function\" — a clean-zero manufactory aimed at\r\n  the very #123 hunt it was built to serve. **Do not hunt for this token.** The instrument now\r\n  lives at the choosers the daemon actually executes, as `ATTACH_INTENT_CHOSEN` with a distinct\r\n  `site=` per chooser (`gap_resume` | `serve_request` | `shell_channel`), carrying the emit\r\n  discipline this one always had — intent bound once, logged and passed from that same binding,\r\n  wildcard-free label. No REQ, per the OBS-rider precedent.\r\n  - _Corrected 2026-08-04 (todlando, in the re-aim rider lane): this row previously described\r\n    the breadcrumb as a live instrument — \"intent bound once, logged and passed from the same\r\n    binding, per-call epoch makes set-vs-one readable off the log\". That sentence was true\r\n    about the emit's CONSTRUCTION and false about its REACH, and a reader consulting this\r\n    register during the #123 hunt would have been sent after a token that cannot fire.\r\n    Replaced rather than annotated, per the register's correction convention; the superseded\r\n    wording lives in git._\r\n- **Rulings that outlive the night:** a green retires NO intermittent row — grandchild and the\r\n  a4 row are INSTRUMENTED-AWAITING-FIRE, the next occurrence carries its own verdict; the\r\n  environmental family's leg 3 (runner off the fleet host) stays operator-ruled NON-OPTION\r\n  (\"stop proposing it\") — sightings accumulate in the family record, evidence files itself,\r\n  re-asking is direction; the quiesce-partial window is the sanctioned tool and it WORKED as a\r\n  discriminator (a4's red under quiesce is what forced the rig-soundness finding).\r\n- **Instrument notes minted on the way, cheap to lose:** (a) `gh run view --log` refuses for a\r\n  COMPLETED attempt while any later attempt is live (gates on the RUN) — recover per-job with\r\n  `gh api repos/<o>/<r>/actions/jobs/<id>/logs`; (b) a process-census RESIDENT COUNT is not\r\n  trendable (23→17→15 in 90s of inbox-poll CLI churn) — the CLASSIFICATION is the measurement,\r\n  the count is noise; (c) nextest's per-run LEAKY count is a free process-leakage series already\r\n  in every log (a1=12/a3=10/a4=13, and the multichunk row alone leaks 0/40 — the leaks are the\r\n  row's NEIGHBOURS); (d) diagnostic-token greps derive from the FAILING FRAME's own emit sites,\r\n  never from the register entry discussing the symptom — the gater's own\r\n  `REAP_JOB_TERMINATE_FAIL` zero over a path that emits `SERVICE_TREE_KILL_INCOMPLETE` was VOID,\r\n  and the emit sites document their own vocabulary (tree_kill_incomplete_line's doc names its\r\n  grep-partner); (e) **\"golden green ⇒ box free\" is FALSE — the ff-push that concludes a golden\r\n  STARTS the automatic post-merge ci run on the same box** (hertz, measured to the second:\r\n  Runner.Worker up 00:13:02 local = run 30886843672 job start 07:13:02Z, ~2min after the ff), so\r\n  the box empties after the POST-MERGE run, not after the golden; the box has a fourth actor no\r\n  agent steps off, woken by every main push (todlando's spelling), and post-golden sequencing\r\n  must gate on `gh run view --json jobs` of the post-merge run before any timing-sensitive work.\r\n- **Ripe when:** ~~instrument lanes land~~ (DONE, v0.54.0/v0.55.0); family sightings stay until\r\n  the family record closes them — the entry now waits on FIRES, not landings. **Size:** nothing\r\n  left to build; the next family sighting carries its own verdict via the landed instruments.\r\n- **LINUX-FACE SIGHTING + ITS RESOLUTION (doyle, v0.63.0 FIELD-SEAL goldens r1-r3 + proof runs,\r\n  2026-08-25 — the family's first measured MECHANISM, and it is environmental-amplifier ×\r\n  latent-test-defect, not a product fault):** three goldens, three DISTINCT kitsubito victims,\r\n  8/9 green each, victims migrating across same-sha reruns (r2/r3), every red a LONG death\r\n  (9.9s/59.4s/62.7s) of a fast cell — the family signature on the OTHER OS. Root-caused to ONE\r\n  window whose WIDTH varies with load: the brain's `spawn_session_pid` Spawned-wait\r\n  consumes-and-discards output racing ahead of the reply (KNOWN-HAZARDS 6.9, same-session face,\r\n  amended at `dbe3daad`); the broker execs the PTY child ~2ms BEFORE writing `Spawned`, so a\r\n  fast first chunk can be eaten. Under kitsubito's then-active kernel-audit backpressure\r\n  (see the kitsubito-audit entry below) the broker DISPATCH thread could stall arbitrarily in\r\n  that gap — the ~2ms window stretched to seconds, swallowing ANY marker prefix of ANY\r\n  spawn-wait test: random victims, long deaths, spawn-intensity × serialization scaling\r\n  (deployah's measured pair), migration across reruns. Box remediation narrowed the window back\r\n  to ~2ms, leaving exactly one knife-edge victim (a first-chunk needle, near-deterministic red,\r\n  62.7s natural-life death), fixed test-side in `dbe3daad` (v0.63.0's head). Full RCA + the\r\n  observer-effect instrument record: releases#225 comments 5417343026/5418844404.\r\n  **Standing lesson for the family:** an environmental slowdown is an accidental mitigation —\r\n  REMEDIATING a box can EXPOSE latent knife-edge races (the storm had hidden this one for\r\n  releases). And a \"random victim family\" should be tested against ONE window with\r\n  load-dependent width before positing per-victim mechanisms. The Windows face above remains\r\n  open on its own instruments; the two faces now have one shared candidate SHAPE (a race window\r\n  amplified by box load) with different windows.\r\n- **Status:** open · **Origin:** measured box event, HFENDULEAM 2026-08-04 ~05:00 local, during\r\n  USHER lane concurrency (hertz mechanism statement + both agents' reclaim arithmetic).\r\n- **What/why:** the box hit **0.00 bytes free** mid-build. Failure signatures it manufactured\r\n  look like toolchain or code defects, not disk: `rustc-LLVM ERROR: IO failure on output stream:\r\n  no space on device`, `LNK1318: Unexpected PDB error; LIMIT (12)`, `LNK1108: cannot write file`\r\n  — a red wearing a linker's face (doyle's U2 gate rig ate exactly this; verdict legs already\r\n  green survived, the suite leg had to be re-run). Contributions measured, not inferred: hertz\r\n  ~70 GB across four lane targets (er-seams **42.66 GB** cold `--workspace --tests`,\r\n  selection-probe 25.80, poolowner 1.03, ci-riders 0.91), doyle gate rig 15 GB cold full build.\r\n  Reclaim arithmetic reconciles both and neither alone: 0.00 → 25.47 GB (hertz reaps\r\n  selection-probe) → ~40 GB (doyle reaps rig). **The mechanism (hertz, ruled register-worthy):\r\n  every isolated lane worktree carries its OWN `target/`, so disk cost is multiplied by lane\r\n  count, while pool-claim — built to arbitrate a SHARED pool — sees none of it; a claim on\r\n  main's pool is ceremonial for a lane that never writes there. The tool we use to reason about\r\n  build-cache contention cannot see the resource that actually ran out.** Eight-plus worktrees\r\n  at 25–43 GB per cold full build is the shape of the next occurrence, and it will not announce\r\n  itself through pool-claim. Adjacent discipline failure the same night, named so the entry\r\n  carries it: a gater firing a cold full-workspace rig into a window with two live builder lanes\r\n  is the pre-flight question-1 failure (right-size the run) — targeted legs and warm pools\r\n  first.\r\n- **Remedy shape (sketch, not ruled):** (a) a box-level free-space floor as a RIG STEP at lane\r\n  start — the claim verb is the natural seat (print box free + du of known lane targets at\r\n  `pool-claim`, warn under a floor); kin to the CI-side `REQ-CI-FREE-SPACE-PREFLIGHT` (IR-1's\r\n  companion fix), which covers runners but not agent lane rigs; (b) teardown-on-gate-close is\r\n  already a rig step (the gate-target-disposal rule) — the gap is the AGGREGATE view across\r\n  lanes nobody owns; (c) possibly a `pool-census` xtask verb listing every `.worktrees/*/target`\r\n  with sizes, so the sweep is one command instead of a du walk each agent re-derives.\r\n- **Ripe when:** next CI/rig-touching wave, or the next ENOSPC-signature red — whichever first.\r\n- **Size:** small-medium (claim-verb print + floor; census verb optional).\r\n- **Field addendum (2026-08-04 second event, same day filed — ripeness condition met):** the box\r\n  fell under the CI runner's 32 GiB free-space floor twice more (12:31 main @9d65e65 docs-only,\r\n  12:50 PR core#144 @b110bc8) while todlando's F-lane built. Both Windows unit legs REFUSED with\r\n  `RESOURCE=disk drive=C:\\ free_bytes=…` — the `REQ-CI-FREE-SPACE-PREFLIGHT` floor did exactly its\r\n  job: a docs-only main red named the resource instead of wearing a linker's face, and triage was\r\n  one log read instead of an RCA. That is the instrument's first field catch; the CI side of this\r\n  entry is PROVEN. The agent-lane side stays open: local trough measured 8.8 GB free mid-F-lane.\r\n  Reclaim, measured before/after per the teardown rule: doyle reaped gated u1+u2 lane targets\r\n  (POOL-OWNER claims verified own+dead-holder, inbound reparse sweep clean, worktrees kept)\r\n  8.8 → 59.5 GB (+50.7); hertz reaped er-seams target (pool-release first, same discipline)\r\n  59.46 → 101.16 GB (+42.66). Refined mechanism statement (hertz, this event): the disk floor is a\r\n  per-BOX resource our per-POOL instrument is structurally blind to — pool-claim answers a\r\n  question about contention that is not the question the box ran out of.\r\n- **AXIS ADDENDUM (deployah, golden 30928816784 / USHER `fc7fad1`, 2026-08-04) — one floor reading\r\n  is a SNAPSHOT, and the swing is bigger than the margin you fire on.** Two facts this entry's\r\n  remedy (a) has to be built against, both measured rather than reasoned:\r\n  (1) **A pre-fire PROCESS census cannot see the floor at all.** Mine came back clean minutes before\r\n  the run — zero test-path `spt.exe` residents, zero `cargo`/`rustc`/`link`/`cl` — and both Windows\r\n  legs then died in the disk preflight (`drive=C:\\ free_bytes=26099576832 floor_bytes=34359738368`,\r\n  `RESOURCE=disk`, exit 1) with a 128-line log carrying ZERO `Compiling`/`PASS`/`FAIL`/`Summary`\r\n  lines: no test signal, and the merge chain never indicted. Both readings were TRUE at the same\r\n  instant — the gater's finished assembly gates were sitting on disk as a DIRECTORY, not running as\r\n  a process. A process-axis probe is blind to a finished build's cost by construction; \"re-check\r\n  closer to the fire\" would have changed nothing, because the axis was never read.\r\n  (2) **The floor number itself moves by tens of GB inside one run window.** Same box, same drive,\r\n  same run, pulled from its own logs: `16:22:55` test-Windows free=26099576832 REFUSED · `16:23:07`\r\n  n1-gate-Windows free=26096607232 REFUSED · `16:46:54` twohost-a free=71033049088 PASSED and then\r\n  ran 11 minutes to success. ~45 GB returned with NO deliberate teardown, and my own reading at\r\n  17:13:45Z was 61352714240 — ~10 GB BELOW what twohost-a saw 27 minutes earlier. The observed swing\r\n  amplitude EXCEEDED the margin I was about to fire on (25.14 GiB).\r\n  So the rule remedy (a) must encode: measure BOTH axes (process residents AND free space against\r\n  the workflow's own 32 GiB floor), and reclaim until the margin exceeds the observed SWING, not one\r\n  sample. Triage corollary, equally load-bearing: twohost-a runs the same preflight on the same C:\r\n  and PASSED, so a preflight refusal is a threshold event on a moving number — never evidence the\r\n  box cannot run the work, and never by itself a reason to indict a merge chain.\r\n- **THIRD ADDENDUM (deployah, v0.54.0 cut, 2026-08-04) — the sweep answers \"0 B reclaimable\"\r\n  TRUTHFULLY on a box that cannot run its own work, because the reclaimable population and the\r\n  owned-lane population are DISJOINT.** This hazard blocked a release twice before it was seen.\r\n  Both Windows legs at the shipped sha `86f0d84` refused at the guard before compiling anything —\r\n  `ci.yml` at `free_bytes=28167569408` (26.2 GiB) and `release.yml` at `27690885120` (25.8 GiB),\r\n  both against `floor_bytes=34359738368`. `assemble` skipped in consequence, so no draft release\r\n  existed: the release was hard-blocked on disk, not on code. Neither leg produced a test verdict,\r\n  so both are LABELLED HOLES, not reds (ruled recorded-and-proceed by doyle, the shipped-sha delta\r\n  being 5 files and zero `.rs`).\r\n  **The finding is not the disk.** `xtask pool-sweep --root .worktrees` reported, correctly,\r\n  `total 66.43 GB across 3 pool(s); 0 B reclaimable in this sweep's scope` while the box sat ~6 GB\r\n  under its own floor. The sweep is behaving as designed — it refuses to reap owned, live lanes.\r\n  But the floor reasons over an AGGREGATE the sweep is forbidden to touch, so the designed\r\n  instrument, run at the exact moment of refusal, tells an operator there is nothing to reclaim.\r\n  That is true and useless. The gap between \"the sweep is correct\" and \"the box can run work\" is\r\n  the defect; it is not fixed by making the sweep more aggressive.\r\n  **Aggregate measured under `.worktrees`** (real target bytes, junction-classified first): 87.79 GB\r\n  across 9 lanes — 2.7x the entire 32 GiB floor. Registered pools: `w1t2-relink-force` 54.67 GB,\r\n  `obs-resume-attach-intent` 10.18, `w1t2-subnet-status` 1.58. Carrying targets the sweep does not\r\n  count as claimed pools: `hertz-teardown-bound` 11.25, `hertz-liveresolve-diag` 4.83,\r\n  `hertz-psyche-bound` 4.19, `hertz-poolowner` 1.03, `hertz-ci-riders` 0.91.\r\n  **The 54.67 GB single lane is NOT waste** (doyle's classification, ratified at this filing): a\r\n  verb lane at that size is workspace-all-targets e2e cost. No lane is misbehaving. That is what\r\n  makes this structural rather than a cleanup task — every lane is individually justified and the\r\n  sum still exceeds the floor.\r\n  **Reclaim taken, and its boundary.** 82.12 GB, from `spt-core/target` — the release driver's OWN\r\n  main-checkout pool, NOT a lane; free 23.23 → 105.34 GB. Classified before removal per the\r\n  teardown rule: OUTBOUND `Get-Item -Force` reported a real directory rather than a reparse point,\r\n  the INBOUND sweep found zero reparse points aimed at it, `CARGO_TARGET_DIR` was unset (no env\r\n  aliasing), the target SUBTREE only was reaped, both sides measured.\r\n  **Snapshot behavior reproduced inside this measurement window**, corroborating the axis addendum\r\n  above at a smaller amplitude: free read 25.49 GB when first measured and 23.23 GB at the reap\r\n  minutes later — it drifted 2.26 GB DOWNWARD while the operator was deciding what to do about it.\r\n  **Priced side effect, for the next reader:** reaping the main pool took the prebuilt `xtask` with\r\n  it, so the next lane claim rebuilds it first — the lane-check shortcut is cold until then. It cost\r\n  a 2m11s cold rebuild inside this release's own publish step.\r\n  **What this does NOT license:** reaping another agent's owned lane to clear a floor. The sweep's\r\n  refusal is correct and stays. What is missing is an AGGREGATE-AWARE signal — the box knowing its\r\n  lanes sum past the floor *before* a run is dispatched into a guard that will decline it.\r\n- **FOURTH ADDENDUM (doyle, 2026-08-04 late evening — fourth event in one day, and the first\r\n  RULING on this entry).** C: hit **0.44 GB free** during doyle's lane-2 stack gate and todlando's\r\n  re-aim leg set. Signatures manufactured this time, all initially read as something else:\r\n  `os error 112` mid-rlib-archive surfacing as xtask \"building spt failed\" (exit 101); a\r\n  servicehost force-kill unit red at a sha gated GREEN on the same rig an hour earlier; todlando's\r\n  6-of-7 leg table red with `LNK1318` while only traceable-reqs survived. Both agents' verdicts\r\n  from the window were VOIDED and re-run, not re-read.\r\n  **Discriminator correction (hertz, ratified at this filing):** \"treqs alone survives\" is a\r\n  POSITIVE TELL, never a clearing test — a full disk reds BEFORE any link step (rustc writing\r\n  rlibs), and treqs can red for its own reasons; signature absence says NOTHING. The only\r\n  falsifier for \"this red was the disk\" is free space AT RUN TIME, and no log on the box recorded\r\n  it, which made every red from the window unanswerable after the fact.\r\n  **RULING (doyle):** every rig/gate script records `FREE-AT-START` / `FREE-AT-END` in its own\r\n  SUMMARY — one line each, the datum that makes a disk confound answerable post-hoc. Effective\r\n  immediately for hand-authored rigs; hertz builds it into the shared rig harness at next touch\r\n  (assigned, not unasked). This is remedy (a) narrowed to its cheapest load-bearing slice.\r\n  **Reclaim, all FS-delta-measured:** todlando +59.4 GB (obs-resume-attach-intent 8.56 +\r\n  w1t2-relink-force 50.83; 0.44 → 59.83), hertz +1.79 GB (ci-riders + poolowner; sum-of-lengths\r\n  said 1.94, the FS delta governs; 59.09 → 60.87), doyle +38.8 GB (w1t2-subnet-status +\r\n  w1t2-perch-gc + w1t3-node-verb targets; 60.75 → 99.54). Full discipline each: outbound\r\n  classification, inbound reparse sweep (zero), CARGO_TARGET_DIR confirmed unset, subtree-only.\r\n  **Mechanism sharpened by this event:** the standing swing IS the finished-lane population —\r\n  ~110 GB of pools belonging to lanes already GATED AND PUSHED, held for hours because disposal\r\n  fires at GATE close (a rig step) while nothing fires at LANE finish; a pushed lane awaiting\r\n  assembly holds its pool invisibly. Corollary corrections carried: todlando withdrew his\r\n  name-based pool census (10x off; ancestry, not directory names, classifies a pool as closed),\r\n  and hertz-selection-probe's worktree removal REFUSED Permission denied — IR-38's second holder\r\n  class recurring, left for retry rather than forced.\r\n\r\n- **FIFTH ADDENDUM (deployah, v0.63.0 FIELD-SEAL golden, 2026-08-25) — SCOPED DELIBERATELY TO ONE\r\n  CONSEQUENCE: reaping a pool UNCLAIMS its tree, and the next builder meets a refusal that is the\r\n  rule working.** (The disk-floor mechanism from the same event is doyle's to file at his\r\n  release-close sweep — one voice each, by division agreed in-window. This addendum stops at the\r\n  pool-claim consequence and deliberately does not restate the floor finding.)\r\n  Five FIELD-SEAL lane pools were reaped to clear the golden floor — gate rig `gate-222-ca30a79e`\r\n  plus lanes `fix-222`, `w2-seal-ux`, `w3-ingest`, `w4-exit-subject`; **148.48 GB measured by FS\r\n  delta**, free 1.37 → 149.84 GB, worktree checkouts kept, `main/target` untouched by ruling.\r\n  **The consequence to record:** `POOL-OWNER.json` lives INSIDE `target/`, so reaping the subtree\r\n  takes the claim with it. Those five trees are now **UNCLAIMED — which is fresh-not-foreign**, a\r\n  different state from the `SPT_POOL_FOREIGN` refusal. Whoever resumes one of those lanes (a hertz\r\n  fixup, a golden-red rebuild) must run `cargo run -p xtask -- pool-claim --pool <dir> --label\r\n  <lane>` **from that worktree** before the first build, or `crates/spt-store/build.rs` refuses.\r\n  **A refusal there is the rule working, not a defect** — filed precisely so a later reader does\r\n  not open an issue against the build script for behaving correctly. Naming it costs one line;\r\n  the alternative is an RCA against our own guard.\r\n  **Prediction-vs-meter, corroborating hertz's fourth-addendum note at ~75x its scale:** pre-reap\r\n  sum-of-lengths sizing predicted 163.9 GB; the FS delta paid 148.48 GB, a 15.4 GB shortfall left\r\n  UNEXPLAINED here rather than rationalized (allocation granularity, sparse/compressed extents and\r\n  concurrent writes all sit between the two meters). **The FS delta governs** — hertz ruled this at\r\n  1.94-vs-actual and it holds at three digits. Report the meter, never the estimate that agreed\r\n  with your plan.\r\n  **Discipline executed, for the audit trail:** outbound classification re-read AT REAP TIME (all\r\n  five real dirs, zero LinkType); inbound sweep over **2854** reparse points under `projects\\`\r\n  found zero aimed at any victim; `CARGO_TARGET_DIR` confirmed empty in process, **Machine and\r\n  User** scope (the arm that leaves no directory entry to notice afterwards); process census\r\n  RE-RUN at reap time rather than carried from a peer's snapshot — zero builders, zero processes\r\n  imaged out of a victim pool, both live `spt` images resolving to the installed path. The peer's\r\n  snapshot proved correct; it was re-run because a snapshot is not a standing property, which is\r\n  the reason it was offered with that caveat.\r\n\r\n### IR-32 — Docs-drift gate blesses its own gen: an empty-emitting producer agrees with itself perfectly\r\n- **Status:** open · **Origin:** todlando mid-lane stop-and-report, U1 (#144) 2026-08-04. Filed by\r\n  the builder to the gater deliberately — register shape is doyle's to own.\r\n- **What/why:** with a defective binary in the tree (stack-overflowed before reaching its own\r\n  code, empty stdout, non-fatal to the generator), `cargo run -p xtask -- gen` wrote\r\n  `docs-site/src/cli/reference.md` reduced to EIGHT lines — title, do-not-edit banner, empty code\r\n  fence — deleting 3193 lines of published CLI reference. `xtask check` then exited 0, because\r\n  the drift gate compares what the binary emits NOW against what the file holds, and gen had just\r\n  overwritten the file with exactly that emit. **A producer that emits nothing agrees with itself\r\n  perfectly.** Caught only because the builder grepped the regenerated page for his new flag\r\n  names and treated the clean zero as suspicious ([[zero-match-filter-reads-as-absent]] shape);\r\n  the gate itself would never have said a word, and the gutted public reference ships green.\r\n  The mechanism generalizes past the stack overflow that exposed it: ANY failure mode that makes\r\n  `spt --help` produce empty stdout while exiting non-fatally to the generator gets the same\r\n  green. Kin to [[cli-command-docs-drift]] (the gate this defeats) — the gate detects DRIFT\r\n  between binary and page, and is structurally blind to a page just regenerated from a broken\r\n  binary.\r\n- **Remedy shape (builder's sketch, sound; not yet ruled on seat):** a floor in `xtask gen` —\r\n  refuse to write a page whose help block is empty, or whose output is implausibly shorter than\r\n  the file it replaces — so the generator fails loudly instead of producing a stub the gate\r\n  blesses. Gen is the right seat: check runs in CI on a fresh emit too, so a check-side floor\r\n  alone still lets a local gen gut the working tree.\r\n- **Ripe when:** next docs-tooling or xtask-touching lane; SOONER if any lane regenerates the CLI\r\n  reference before the floor exists (a gate on that lane must assert page LENGTH, not gen's exit\r\n  code, until this is built).\r\n- **Size:** small (one refusal + a length-plausibility floor in gen).\r\n\r\n- **Kin instance 2026-09-11 (hertz, #304 lane, caught before launch):** the RUN expression for the\r\n  spt-daemon lib producer was still the 15-term webserve list after six #297 cases had been admitted\r\n  and inventoried at 21 terms. It would have executed 15 and reported against a 21-term inventory —\r\n  a subset quietly narrower than the thing it claims to discharge, with a count that reads fine.\r\n  Rule: a run filter is diffed TERM-FOR-TERM against the inventory it discharges before launch; a\r\n  matching case count is not that check.\r\n\r\n### IR-33 — Debug-build clap Command tree runs near the main-thread stack ceiling; the margin is THREE net new args, bisected at `8f291e1` (the original ~6 was measured on U1's tree and is superseded)\r\n- **Status:** OPEN for acceptance/margin reconciliation. Current source at `e5a2fed9` runs\r\n  the CLI on an owned 16 MiB thread stack and includes `cli_stack_smoke`; the three-argument\r\n  ceiling below is a historical measurement at `8f291e1`, NOT today's measured margin.\r\n  Do not redispatch an already-present sized-stack implementation. No fresh debug-run\r\n  acceptance is claimed by this source read (2026-09-11). · **Origin:** todlando U1 (#144)\r\n  2026-08-04, delta-tested mid-lane.\r\n- **What/why:** eight extra hidden bool args across the five knock seats grew the derive-built\r\n  Command tree past what the debug binary's main thread stack can construct: EVERY invocation\r\n  (`spt --version` included) died with `thread 'main' has overflowed its stack`, exit\r\n  -1073741571, before reaching any of its own code. Delta-tested, not assumed: the same command\r\n  on the main-pool binary from main printed normally. U1 repaired its own trigger (raw-argv\r\n  pre-scan for retired flags before clap parses; lane ends net +2 args) — but the CEILING\r\n  remains: the tree is now close enough that a handful of net new arguments in a debug build\r\n  reproduce a total binary outage — **and the handful is THREE, not six; see the correction\r\n  below before planning against this entry.** **#5's verb-surface rework is the next lane that adds\r\n  arguments and it is much bigger than U1** — this entry exists so #5 is planned knowing the\r\n  margin, not discovering it. Note the failure's face: it presents as a broken binary, and via\r\n  [[IR-32]] it presents as a silently gutted docs page — neither names the stack.\r\n- **CORRECTION — the margin is THREE, bisected at `8f291e1` (todlando's U3 lane\r\n  `build/usher-u3-verb-surface`, own pool, debug profile; filed by deployah 2026-08-04).** The\r\n  original ~6 was measured on U1's tree and was right when written; it is wrong now, and the\r\n  difference is the difference between \"plan carefully\" and \"one flag anywhere takes the binary\r\n  down\". N hidden bool args added to the ROOT `Cli` derive, tree restored from git between every\r\n  row, `--version` as the invocation (it carries no work of its own, so whatever it costs IS tree\r\n  construction):\r\n\r\n      N=0  exit 0                OK  (control — unmodified lane binary answers `spt 0.53.0`)\r\n      N=1  exit 0                OK\r\n      N=2  exit 0                OK\r\n      N=3  exit -1073741571      STACK-OVERFLOW\r\n      N=4 / N=6 / N=8            STACK-OVERFLOW\r\n\r\n  PLACEMENT DIFFERENTIAL, run because #5 adds args at `EndpointCmd` seats rather than at the root\r\n  and a root-only number could have measured the wrong thing: same N injected inside a NESTED\r\n  endpoint seat gives `SEAT N=2` OK, `SEAT N=3` STACK-OVERFLOW. **Identical ceiling — placement does\r\n  not move it**, so three is the number for the shape #5 actually builds. (Rig hazard worth keeping:\r\n  the first seat attempt produced a COMPILE error, E0027, because the dispatch destructures that\r\n  variant exhaustively — taken at face value it would have read as \"the seat is fine\". Both rows\r\n  above are from the fixed rig.) CONSEQUENCE FOR #5: the ratified MIN spelling ends net +2, i.e. it\r\n  would have shipped with ONE argument of headroom, and any later lane adding a single flag anywhere\r\n  in the tree would then take the whole binary down, `--version` included. Remedy (b) below stops\r\n  being \"buys headroom\" and becomes the precondition for #5 shipping safely.\r\n- **Remedy shape (sketch, not ruled):** (a) cheapest tooth — a debug-build smoke that runs\r\n  `spt --help` and asserts non-empty stdout + exit 0, which also backstops IR-32's trigger;\r\n  (b) raise the main thread stack for the binary (build config), buying headroom without\r\n  restructuring; (c) structural — box/flatten the derive tree so construction cost stops scaling\r\n  with arg count. (a) is a rider candidate for any lane; (b)/(c) want a real measurement of\r\n  where the ceiling sits before choosing.\r\n- **Ripe when:** #5 (U3 verb surface) PLANNING — this is a planning input, not just a build item;\r\n  the smoke tooth (a) is ripe for the next CI-touching lane regardless.\r\n- **Size:** small for (a); medium for (b)/(c) with the measurement.\r\n\r\n### IR-34 — nextest LEAK flag on the zombie-fixture row is dominant-but-intermittent (19/20 measured); any gate reading it as a signal flaps\r\n- **Status:** open · **Origin:** doyle #142 F-lane gate 2026-08-04 (first sighting in a gate run);\r\n  characterized same day by hertz from retained logs, ownership falsified by todlando.\r\n- **What/why:** `broker::tests::windows_session_is_zombie_sees_a_handle_held_corpse_as_dead` (the\r\n  ADR-0041 zombie-detection fixture, whose subject is a corpse process kept alive-looking by a HELD\r\n  HANDLE) flags nextest LEAK on most draws but not all — measured 19 LEAK of 20 on a tree carrying\r\n  no #142 content (`test/grandchild-selection-probe` @`695398b`, based on `4b37512`: lib arm 10/10\r\n  LEAK across 822-test runs; full-suite arm 9/10 across 1044-test runs). The single clean PASS\r\n  kills \"intrinsic therefore always\": leakiness is DOMINANT BUT INTERMITTENT. Consequences:\r\n  (1) a gate or reader that treats this row's LEAK as a defect signal flaps at roughly 1 in 20;\r\n  (2) one non-leaky run is NEVER evidence that something fixed it (kin:\r\n  [[intermittent-green-is-zero-information]]); (3) the verdict method that closed it is the\r\n  template — two independent legs, neither load-bearing alone: the suspect lane's diff grepped\r\n  zero hits on the row's subject (zombie / handle_held / OpenProcess / corpse), AND a 20-draw\r\n  baseline on a tree predating the suspect change. This entry exists so the next gater who sees\r\n  the flag reads one register line instead of running that RCA cold.\r\n- **Remedy shape (sketch, not ruled):** annotate the row as expected-leak in nextest config\r\n  (per-test `leak-timeout` override or documented allowlist) so the flag stops presenting as\r\n  signal; alternatively a fixture-side close of the held handle on the clean path if ADR-0041's\r\n  arrangement permits — hertz's call, test/CI lane.\r\n- **LANE-LINKED 2026-08-30 (#242 close sweep):** hertz's queued daemon-leak fixup lane carries\r\n  this entry (brief cites IR-7/17/20/34/35/63); leaves the register when that lane lands.\r\n- **Ripe when:** hertz's next nextest-config-touching lane; blocks nothing today.\r\n- **Size:** small.\r\n\r\n### IR-35 — hfenduleam Windows test-leg victim rate: one teardown/liveness family, measured at ~half of all executions\r\n- **Status:** open · **Origin:** USHER #150 golden triage 2026-08-04 (doyle; all rates deployah-measured).\r\n- **The numbers (15 golden runs 2026-08-02..08-04 + the USHER cycle, deduped on `(run, box,\r\n  started_at)` — GitHub partial reruns COPY untouched jobs into the new attempt with their ORIGINAL\r\n  `started_at` and carried conclusion, so a carried failure is the SAME observation; dedupe before\r\n  any rate math):** Windows (hfenduleam) 13 red / 22 executions = 59% leg-red, splitting 10/22 = 45%\r\n  test-victim + 3/22 infra (IR-31 class). Linux (kitsubito) 2/20 = 10%, 1 victim. Every victim-red\r\n  leg had EXACTLY ONE victim (8/8 legs). Clean-cycle arithmetic ≈ 0.55 × 0.95 ≈ half — a golden\r\n  cycle at these rates is a coin flip. knock145 (the previous green golden) took FIVE Windows\r\n  executions to its green; USHER took four. **A both-green draw is a draw, not evidence the family\r\n  closed.**\r\n- **The family:** 11 victim legs, 8 distinct tests, ONE cluster — process teardown / kill-reach /\r\n  respawn-controller survival, concentrated on hfenduleam. Per-victim dispositions live in the USHER\r\n  #150 triage ledger (releases#150 record). The only surviving cross-sha EXACT repeat after source\r\n  verification is `resume_no_control_steal_e2e` (:488, byte-identical @2138b16 + @4b37512) — and\r\n  both its reds PREDATE the post-#145 producer-side instrumentation, so what repeats is an AMBIGUOUS\r\n  observation (stolen controller vs starved child) twice; only a post-#145 red discriminates. The\r\n  `a_tree_teardown` pair was a FALSE repeat — two mechanisms wearing one assert string (see\r\n  FLAKE-LEDGER row; the counting lesson: assert-body identity must include the polled predicate's\r\n  SUBJECT).\r\n- **Off-CI discriminator (todlando 2026-08-04):** 0/400 (A 0/200 + B 0/200, interleaved,\r\n  `--test-threads 1`, filters positive-controlled, by-path sweeps every iteration) on the warm\r\n  d449ce5 pool UNDER live-fleet load (CPU 46-59%, 13-18 spt processes). Points the family at the\r\n  RUNNER ENVIRONMENT rather than a product race any Windows box expresses — not exoneration (absence\r\n  of reproduction is not proof of absence), but where the next hour goes. A-alone N=500 on the\r\n  instrumented tree ran post-close (result on releases#150).\r\n- **Remedy lanes already moving:** hertz 4-item test-rework package dispatched 2026-08-04 (psyche\r\n  bound split, live_resolve rig instrumentation, green-capture probe profile, resident_service/\r\n  teardown hardening); prod `wait_bounded` tree-kill-on-timeout filed to board as EVAL. This entry\r\n  is the RATE's home — it leaves the register when the operator has ruled on the rate (accept vs\r\n  hold-for-hertz) AND the hertz package has landed with a re-measured victim rate.\r\n- **LANE-LINKED 2026-08-30 (#242 close sweep):** hertz's queued daemon-leak fixup lane carries\r\n  this entry (brief cites IR-7/17/20/34/35/63); the rate re-measure rides that lane's landing.\r\n- **Ripe when:** operator brief at USHER close (immediate); re-measure after the hertz package lands.\r\n- **Size:** visibility entry + the re-measure; fix cost carried by the hertz package.\r\n\r\n### IR-36 — `output_bounded` is a 51-copy clone estate with a named-but-empty shared home; hoist-and-delete wants its own lane\r\n- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane. · **Origin:** hertz measurement\r\n  2026-08-04 (at `7465ac1`, counted before listing, listed untruncated), during the USHER package\r\n  item-2 sweep ruling; doyle ruled file-don't-sweep.\r\n- **What/why:** 51 `fn output_bounded` definitions under `crates/spt/tests` — 50 per-file copies\r\n  plus `tests/common/mod.rs:53`, which is NOT pub, has ZERO callers outside its own module, and\r\n  whose doc comment states outright that the estate's copies predate the shared module. The lossy\r\n  timeout arm (panic loses everything captured, names nothing) is in 38 sites across 36 files.\r\n  The copies have already drifted: two variants of the deadline expect-string exist in the estate\r\n  (`\"captured spt call must complete within its deadline\"` in common/mod.rs:60 vs the\r\n  no-deadline-clause spelling in per-file copies), so a grep keyed to either string undercounts.\r\n  The right fix is a hoist-and-delete refactor (make the common copy pub, adopt it estate-wide,\r\n  carry the item-2 diagnostic arm once) — a 50-file test-estate touch that must NOT ride golden\r\n  cadence as a rider or hide inside a scoped diagnostics item (ADR-0050 thin-lane rationale;\r\n  hertz's USHER item 2 stays scoped to live_resolve, which keeps ONE improved copy as the model).\r\n- **Built evidence:** one public owning helper replaced all 50 file-local\r\n  clones. It owns and tree-kills a timed-out child, waits for reap, drains both\r\n  pipes, and includes the deadline plus partial stdout/stderr in the panic.\r\n  A dedicated regression observes both diagnostics and proves the timed-out PID\r\n  is gone.\r\n- **Ripe when:** a dedicated post-batch test-hygiene lane (natural companion to IR-13's\r\n  mutation-proof loop and IR-23's home-collision fix — same hertz wave shape).\r\n- **Size:** medium by file count, small by risk (mechanical hoist; no assertion changes).\r\n- **Hygiene-lane scope addition (todlando, at #6, 2026-08-04):** a CI prebuild of\r\n  `cargo build -p mock-adapter --bin mock-shell` (derived from tracked `.github/` content) turns\r\n  SIX binedge baseline rows green at once instead of growing the burn-down list one consumer at a\r\n  time — belongs to this lane, not to any thin verb lane. [[IR-38]] (live-binary e2e reap sweep)\r\n  rides the same lane.\r\n- **Built evidence:** all 51 file-local definitions are gone; 158 call sites use the one public\r\n  `common::output_bounded`. The shared helper owns the child, kills and reaps its process tree on\r\n  timeout, drains both pipes, and reports partial stdout/stderr. `bounded_output_e2e` mutation-pins\r\n  both timeout ownership and retained diagnostics.\r\n- **Declared validation extra:** the lane's docs-link gate exposed that `llms_target_exists` treated\r\n  generated targets as absent before generation. Its small refactor + unit keeps source and\r\n  generated link targets distinct; it is deliberate validation fallout, not part of IR-36.\r\n\r\n### IR-37 — `traceable-reqs check` is coverage-only: tag PLACEMENT is unenforced on any multi-tagged REQ, and the more tags a REQ accumulates the less any one is checked\r\n- **Status:** UPSTREAM CLOSED THROUGH RELEASE 2026-08-19 — traceable-reqs PR #19 squash-merged\r\n  @`82d8b14` after doyle's targeted re-review PASS (defect A item-tables + 9 red-first regression\r\n  cells + sighted control; defect B enclosing-item fallback DECLARED in SPEC with cost; 267/267,\r\n  blind repros exit 0); v0.4.0 cut (version bump @`c9a8eb5`, tag pushed, 3 platform assets,\r\n  release notes authored; refs sent to hertz). REMAINING and dispatched to hertz post-#182-landing:\r\n  spt-core consumes v0.4.0 — CI version bump + placement config (enforce-on, module_banner=accept);\r\n  banner cleanup rides a later lane. Entry closes when the consume lane lands. · **Origin:** hertz\r\n  measurement 2026-08-04 (filed by doyle; the measurement is\r\n  hertz's), found when his own pre/post `check` comparison around a tag-adjacency fix came back\r\n  EXIT=0 on BOTH sides — the green he had cited beside the fix validated nothing.\r\n- **What/why:** measured on `test/teardown-bound-shape`: a `unit->REQ-RESIDENT-SERVICE` tag\r\n  SEPARATED from its `#[test]` fn (a const landed between tag block and fn — an AGENTS.md rule-1\r\n  violation) scores EXIT=0 identically to the fixed adjacency. Positive control explains the\r\n  mechanism: that REQ carries 57 unit tags across five files, so 56 other sites decide the\r\n  coverage verdict and no single tag's placement can turn it red. Consequence: AGENTS.md rule 1\r\n  (\"tag on or immediately above the real evidence\") is agent discipline only — drifted tags decay\r\n  silently while coverage stays green, and heavily-tagged REQs decay fastest. This is the\r\n  [[IR-32]] family shape (a gate that cannot see its own blind spot) applied to the traceability\r\n  gate itself.\r\n- **LIMIT, with falsifier (hertz's, verbatim in kind):** behaviour on a SINGLE-tagged REQ was NOT\r\n  established. Separating the only tag of a single-tagged REQ at the stage under test would settle\r\n  whether placement is unenforced outright (still exit 0 ⇒ the checker never reads adjacency) or\r\n  merely un-enforceable at scale (exit 1 ⇒ the checker sees absence, and only multi-tag redundancy\r\n  masks drift). Run that discriminator BEFORE designing any remedy — the two outcomes want\r\n  different fixes (a placement rule in the checker vs a per-tag-nearest-item heuristic).\r\n- **Transfer:** doyle accepted this lane's independent EXIT-0 remeasurement and confirmed it\r\n  matches todlando's settled 2026-08-04 discriminator. Upstream remedy: enforce adjacency for\r\n  each individual `doc`/`impl`/`unit`/`int` tag, with separated-tag negatives covering\r\n  single-tag, interposed-const, file-top-banner, and one-of-many displacement. This repo consumes\r\n  the released checker only.\r\n- **Close condition:** doyle reviews and merges the upstream lane, cuts the `traceable-reqs`\r\n  release, and spt-core consumes that release. Issue/branch/PR/commit refs append here when the\r\n  upstream lane lands.\r\n- **Size:** measurement complete; remedy scope is upstream-owned and dispatched.\r\n- **CONSUME LANE + REGRESSION (doyle, 2026-09-11):** hertz's #304 lane carries the consume (2072b467 ci.yml\r\n  WANT 0.4.0, c3b5feec golden.yml pin, 33936943 `[placement] enforce=on, module_banner=accept`).\r\n  Measured on his tip under 0.4.0: misplaced 9 (tags quoted in backticks in prose; fixed on main\r\n  dd0679dc) and 81 doc stages MISSING that 0.2.0 counted — a checker regression, not drift: 0.4.0's\r\n  git enumeration skipped a FILE root (`CONTEXT.md`), see [[IR-104]]. Fixed upstream as v0.4.1\r\n  (PR #21 -> d9af11d); the lane pins move to 0.4.1 in one fixup after hertz's window. Entry\r\n  closes when that fixup lands on main.\r\n- **DISCRIMINATOR RUN 2026-08-04 (todlando, authorized specimen on `build/w1t2-shell-relink-force`;\r\n  filed by doyle — the measurement is todlando's): the answer is the EXIT-0 ARM.** Single-tagged\r\n  int stage (`REQ-SHELL-RELINK-FORCE`), tag SEPARATED from its fn (parked at file top):\r\n  `traceable-reqs check` EXIT 0 and the REQ still reports `+int`. Tag reverted to adjacency:\r\n  EXIT 0, `+int`. Both exits redirect-read, no pipes. **Placement is UNENFORCED OUTRIGHT — the\r\n  checker never reads adjacency; multi-tag redundancy was never the mechanism, it only widened the\r\n  blind spot.** Remedy option (a) is the live one: a real placement rule in the checker (upstream\r\n  experimplate), not a per-tag-nearest-item heuristic. Measurement caveat, carried at the\r\n  measurer's own insistence: an intermediate probe printed `TAG_ADJACENT_AFTER_REVERT=0` and that\r\n  was the PROBE wrong (`grep -B 1` above the fn lands on `#[test]`, not the tag above it), not a\r\n  failed revert — the revert was verified directly (exactly one tag, above `#[test]`). The\r\n  discriminator result is the record; the intermediate zero is not.\r\n- **REMEDY DISPATCHED 2026-08-18 (doyle):** upstream lane opened in BigscreenVR/traceable-reqs\r\n  (the actual upstream remote; the checkout at `~/Documents/projects/traceable-reqs` tracks it —\r\n  \"experimplate\" above named the tool's origin project, not the repo) — checker-side placement\r\n  rule, default-on in `check`, positive controls all four stages + separated-tag negatives\r\n  including the single-tag displaced discriminator shape and the interposed-const shape.\r\n  Requested by hertz as the IR-37 prerequisite of his test-hygiene family lane (KEYSTONE #182).\r\n  spt-core consumes the upstream RELEASE only — no local shadow checker. Issue/branch/PR refs\r\n  land here when the lane reports.\r\n\r\n### IR-38 — CLASS: an e2e that ends with a live daemon-spawning binary wedges the NEXT build in its pool, and the diagnostic names the wrong lane\r\n- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane. · **Origin:** todlando 2026-08-04,\r\n  `shell_relink_force_e2e` on the #6 lane (filed by doyle; the finding and the fix are todlando's).\r\n- **What/why:** the e2e ends with a LIVE binary by design; on Windows a live process holds its\r\n  image open, so the NEXT cargo invocation in that target dir dies with\r\n  `failed to remove file target\\debug\\spt.exe: Access is denied (os error 5)` — surfacing as\r\n  exit 101 with NO test summary, because the failure names the BUILD and the FILE, never the test\r\n  that leaked the holder. Actual holders measured: two lane-local `spt daemon run --detached` +\r\n  `daemon brain` processes spawned under the test's temp SPT_HOME by a child CLI's\r\n  `ensure_running`, still alive from an earlier run. **Reap BY IMAGE PATH** — the fleet's other\r\n  eleven spt processes run from the installed binary; a name-based sweep takes your own daemon.\r\n  The live shell-spawn population is eleven e2e files. Nine already end through product teardown\r\n  or their authenticated home-scoped reap. The two intentionally live-at-success siblings now\r\n  kill and prove the final resident gone AFTER all identity/wake assertions:\r\n  `shell_relink_force_e2e` and `shell_stale_online_e2e`.\r\n- **Kin:** [[IR-7]] (phase-A daemon+brain pair leak), the exe-lock reap-by-path rule, and the\r\n  wrong-lane-diagnostic family ([[IR-21]]'s location-not-build class).\r\n- **SECOND HOLDER CLASS, measured 2026-08-04 (doyle, own gate rig):** an **ORPHANED CONHOST with an\r\n  inherited CWD** inside the test tree blocks `git worktree remove` with Permission-denied on a\r\n  DIRECTORY handle — invisible to any exe-path scan (conhost runs from System32; the parent that\r\n  spawned it was already dead). Found via `.github/ci/find-cwd-holders.ps1` (IR-11's instrument);\r\n  killed by pid after parent-dead classification; 34.78 GB reclaimed. Mechanism chain: the\r\n  windowless spawn path masks DETACHED_PROCESS off, the child owns a console, conhost inherits the\r\n  child's cwd and can OUTLIVE it. Boundary (hertz's, correct): this find and his field-4 companion\r\n  are the SAME MECHANISM FAMILY measured on DIFFERENT populations by different instruments — his\r\n  capture measured a ppid-match COUNT (floor 2, companion identity UNMEASURED, his stated limit),\r\n  and this conhost is the first FIELD identity evidence in the family, on THIS population. Do not\r\n  cite his row as identity data it never carried. (His box-wide accretion count 77→80 is a third\r\n  population again.) Teardown rule\r\n  addendum: a disposal leg must GATE on the removal's exit code (a rig that logs \"reclaimed 0.01\r\n  GB\" from a failed remove fabricates its own success) and sweep CWD HOLDERS, not only image\r\n  locks — two populations, either alone is a clean zero on the other.\r\n- **Ripe when:** the test-hygiene lane (IR-13/IR-23/IR-36 family) — sweep every e2e that ends\r\n  with a live spawning binary, apply the same reap-after-assertions shape.\r\n- **Size:** small per test; population unknown until swept.\r\n- **Built evidence:** focused runs of both live-at-success tests pass back-to-back in one target\r\n  pool, followed by a build invocation from that same pool; the second test's final kill is polled\r\n  to proven process death rather than treated as fire-and-forget.\r\n\r\n### IR-39 — CLASS: the missing-fixture-bin defect has TWO failure faces, and one of them impersonates a lifecycle defect of the subject under test\r\n- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane. · **Origin:** hertz + todlando\r\n  2026-08-04, same evening from opposite sides (filed by doyle; hertz relayed todlando's\r\n  suggestion without endorsing scope).\r\n- **What/why:** a rig whose narrowed build (`-p <pkg> --test <one>` / `-p spt --bin spt`) skips a\r\n  cross-package fixture bin fails in one of two ways depending on the consuming site.\r\n  Face 1 (cheap): `translate_proof_fixture` panics \"must be built: <path>\" — names the artifact\r\n  and the recipe, costs one build. Face 2 (expensive): `sibling_bin(\"mock-session\")` resolves to a\r\n  nonexistent exe, nothing spawns, and the test reds at a PRECONDITION assert whose message\r\n  (\"warm bring-up spawned=false\", left None / right Some(\"offline\")) reads as a lifecycle defect\r\n  of the subject — measured cost 186s + a triage inside a lent box window (hertz's F1 red arm,\r\n  attempt 1). The build gap itself is the known cross-package row of the fixture-bin population;\r\n  what this entry carries is the DIAGNOSTIC asymmetry.\r\n- **Ask:** a fixture-bin existence precondition that NAMES the missing exe and its build recipe\r\n  wherever a rig consumes one — `sibling_bin` (and the shared\r\n  `crates/spt-term/tests/support/fixture_bin.rs` resolver already carries the recipe string as an\r\n  argument, the shape to copy) refuses with the artifact + recipe instead of letting the consuming\r\n  test fail downstream in its own vocabulary.\r\n- **Kin:** [[IR-21]] (wrong-lane-diagnostic family: the failure names the wrong actor), the\r\n  cargo-builds-package-bins-for-integration-tests rule (cross-package row is the only unguaranteed\r\n  build), golden.yml's dedicated fixture prebuild step.\r\n- **Ripe when:** the test-hygiene lane (IR-13/IR-23/IR-36/IR-38 family) — same sweep population;\r\n  or standalone small if that lane keeps slipping.\r\n- **Size:** small — one shared helper + a sweep of local `sibling_bin` resolver copies (24 known).\r\n- **Addendum (doyle, 2026-08-04 late): third and fourth sightings inside 24 h.** Face 1 twice\r\n  more the same evening — todlando's teach-lane leg set (his own translate_proof_fixture, caught\r\n  by his prebuild), and doyle's cold gate rig for the same lane (first-pass spt-bins red at\r\n  136/611, correctly withheld from the lane verdict as rig evidence, fixed by `cargo build -p spt\r\n  --bins` + rerun 611/611). Four sightings in one day across three agents and both faces: the\r\n  ripeness condition (\"the test-hygiene lane keeps slipping\") is under measurable pressure — the\r\n  prebuild remedy is being re-derived per-rig per-agent, which is the recurring cost the shared\r\n  precondition helper exists to delete.\r\n- **Built evidence:** all 29 file-local `sibling_bin` resolvers now route through one shared\r\n  precondition. A missing fixture names its path and the package-correct `cargo build -p <owner>\r\n  --bin <name>` recovery command before product assertions or timeout paths run; a focused\r\n  negative test pins that diagnostic.\r\n\r\n### IR-40 — CLASS: NO envelope-side ordering signal on a resume brief tracks content recency, and a CI informant's per-job line is a claim about that STEP, not the run\r\n- **Status:** open · **Origin:** three sightings in one night, 2026-08-04/05 — hertz, doyle,\r\n  todlando (filed by doyle; the artifacts are hertz's and todlando's, the CI arm is doyle's with\r\n  deployah's framing). Two arms of ONE family: a stale record that carries a confident ordering\r\n  signal, and a status claim that arrives before the thing it describes.\r\n\r\n- **ARM A — resume briefs. What/why:** a session can receive TWO start-of-session briefs, and the\r\n  one routed LATER can carry the STALER project-context. Measured on hertz's pair (same node id):\r\n  routed_at_ms `1785897407373` > `1785896642480`, spill-filename epoch `1785897764588` >\r\n  `1785896658159`, and vector sequence `1242529/1242531` > `1241542/1241544` — **all three\r\n  monotonic orderings rank the staler-content brief as newer.** todlando's pair is the NEGATIVE\r\n  arm: his later brief (`…1785897765196`, routed `…577476`, vector `1242756/7`) genuinely WAS the\r\n  fresher one, so the same heuristic happened to pick right.\r\n- **The finding is UNCORRELATED, not inverted** — and that is the whole entry. An inverted signal\r\n  is usable once you know to flip it; an uncorrelated one reads as reliable until the pair where it\r\n  costs you. Neither agent could have known which pair he held without checking content against\r\n  measurement. **Do not name routed_at_ms specifically** — naming the stamp invites the repair that\r\n  fails (\"the timestamp is unreliable, use the sequence number\"). The vector is the most dangerous\r\n  of the three: a stamp looks like a clock and invites suspicion, a sequence number looks like an\r\n  ordering and does not.\r\n- **Visible failure mode if a brief is obeyed as instructed** (hertz's, measured): re-open\r\n  `releases#123` — work already ruled closed — and under-report his own claimed-pool count by one,\r\n  the row sitting under a live gate. doyle's own sighting the same night: a brief describing main\r\n  @`92b2482` with a teach lane \"mid-flight\" hours after every lane had gated.\r\n- **PRE-REFUSED DISCRIMINATOR, recorded so it is not rediscovered as a finding:** file SIZE ranks\r\n  the fresher brief correctly on BOTH pairs (hertz 16308 > 12649; todlando 14138 > 10418) — 2 of 2,\r\n  the only signal surviving both samples. **Do not use it.** Size measures RICHNESS, not recency;\r\n  the two correlated only because todlando's thin brief was a correction fragment, and hertz's\r\n  STALER brief was a full 12649-byte dump. Two full dumps hours apart go flat or inverted. Handed\r\n  over pre-refused by its own finder.\r\n- **ARM B — CI informants (doyle, 2026-08-05, run 30971976024).** `CI-KITSUBITO` sent\r\n  \"CI SUCCESS … sha 0a25b77\" while the run was measurably `status=in_progress` with\r\n  `conclusion=\"\"` — the EMPTY STRING, not `success`. The informant fires from a per-job `notify`\r\n  step, and at send time `notify` itself had no conclusion. All eight substantive jobs were green,\r\n  so the line was **right in the end but EARLY**. deployah's framing, kept verbatim in kind: *an\r\n  informant line that is right in the end but early is worse than one that is simply wrong, because\r\n  a wrong signal gets distrusted while an early-but-correct one gets promoted to the conclusion.*\r\n  todlando's sentence is the one to keep at the point of use: **a per-job notify step's message is\r\n  a claim about that STEP, not about the RUN.**\r\n- **ARM B MECHANISM — hertz, source read 2026-08-05, zero box cost. It is NOT a race; it fires\r\n  early on EVERY run, and the entry above understated it.** `notify` is a job INSIDE the run\r\n  (`golden.yml:1138`), and a job cannot observe its own run's conclusion — so `conclusion: \"\"` is\r\n  not a timing artifact, it is **the only value that can exist when the informant speaks. The\r\n  informant has never once made a statement about a run conclusion.** What `ci-notify.sh` actually\r\n  asserts is narrower and worth naming exactly: a verdict computed PURELY from six `needs` results\r\n  (changes, traceability, test, n1-gate, twohost-a, twohost-b — the two matrices collapse to one\r\n  result each) being neither failure nor cancelled. Nothing more.\r\n  **The blind spot is exactly ONE job: `notify` itself, the 9th — it cannot appear in its own\r\n  `needs` list. And that one job has a WITNESSED red path**, documented in the script's own header\r\n  (2026-07-27, twice on kitsubito): verdict computed, then `spt send` HUNG ~5 minutes until the\r\n  job's own 5-minute budget cancelled it, and that cancellation reddened the run. So *\"informant\r\n  says SUCCESS, run concludes FAILURE\"* is a real observed sequence, not a hypothetical. The 30s\r\n  `SEND_BOUND_SECS` added since bounds the hang but does not close the class — it makes the\r\n  informant's own failure FAST rather than impossible.\r\n  ⇒ The informant's SUCCESS covers 8 of 9 jobs and is blind to the 9th, and the 9th is the only one\r\n  with an observed failure mode that reds the run. This is why the ff predicate is the run's\r\n  conclusion field and never the informant line.\r\n- **RECOVERY, and it is the same for both arms: never rank the claims — re-derive from the source\r\n  object.** For briefs, hertz's four falsifiers are the method (main sha, claimed-pool count, lane\r\n  tip, issue state) and they work because each is a content claim checkable in ONE command against\r\n  a source NEITHER brief controls. For CI, read the RUN's own `conclusion` field, and prefer\r\n  independent reads of the run object (`gh run watch --exit-status` polls the run, so its exit is a\r\n  second measurement rather than an echo of `notify`). On the batch this was caught in, three\r\n  sources agreed with the informant excluded from all three before main was fast-forwarded.\r\n- **Standing rule this entry exists to enforce:** a resume brief's RULINGS are durable; its STATE\r\n  is a HYPOTHESIS to re-derive before acting.\r\n- **Kin:** [[IR-21]] and [[IR-39]] (the diagnostic names the wrong actor / the wrong subject),\r\n  [[IR-32]] (a gate that cannot see its own blind spot), [[IR-34]] (an intermittent marker read as\r\n  a signal).\r\n- **Ripe when:** the next commune/psyche-tier touch for arm A (the routing layer is spt-core's own\r\n  `spool`/psyche ingest, so a remedy is in-repo, not upstream); for arm B, the next `golden.yml`\r\n  informant touch — the cheap fix is that the notify step names its own scope in the message body\r\n  (STEP vs RUN) rather than emitting a bare \"CI SUCCESS\".\r\n- **Size:** arm B small (message text + scope word in one workflow step). Arm A unsized —\r\n  establishing whether ANY durable content-recency signal can ride the envelope is the measurement,\r\n  and until it runs the answer is \"re-derive, do not rank.\"\r\n\r\n### IR-41 — A QUEUED main run is superseded without a record; `cancel-in-progress: false` protects only STARTED runs\r\n- **Status:** open — mechanism CONFIRMED (doyle ruling 2026-08-05); the runbook sentence it\r\n  falsified is already corrected (`docs/RELEASE-RUNBOOK.md` step 3, same commit as this entry)\r\n  · **Origin:** deployah, v0.55.0 publish night, filed by him explicitly as UNPROVEN with the\r\n  manual-cancel alternative not ruled out; confirmed by doyle on the run objects.\r\n- **What/why:** `ci.yml` sets `cancel-in-progress: false` on main and the runbook read that as\r\n  \"main's concurrency policy never cancels this run; that preserves the record.\" FALSE for the\r\n  queued phase: a concurrency group holds at most one running + one pending run, and a newer push\r\n  REPLACES the pending run regardless of the flag — the flag governs only whether a STARTED run\r\n  is cancelled. A superseded queued run leaves NO record: zero jobs, conclusion `cancelled`,\r\n  nothing measured about its sha.\r\n- **Evidence (all read off the run objects, not the informant):** run 30973909279 at `327f1f8`\r\n  (push, main) — created 04:01:08Z, **zero jobs ever started**, cancelled 04:03:49Z, ONE SECOND\r\n  after `e8805f7`'s run 30974041521 entered the group (created 04:03:48Z), while `0a25b77`'s run\r\n  30973770039 was still in flight (done 04:07:59Z). One-running-one-pending, newer push landed,\r\n  pending run died. The 1s coupling to an unrelated push is the discriminator against deployah's\r\n  own manual-cancel alternative — a human cancel co-timed to the second with a push it had no\r\n  view of is not a credible mechanism; supersession fires on exactly that trigger by design.\r\n- **The hole this leaves:** under a rapid push sequence, an intermediate sha on MAIN can have no\r\n  thin-CI verdict AT ALL, and the absence reads as nothing rather than as supersession. Anyone\r\n  auditing \"did sha X pass main CI\" gets a hole where the runbook promised a record. Absence of\r\n  a run is now a labelled state, not evidence about the sha.\r\n- **Ripe when:** next ci.yml/runbook touch. Candidate remedies to weigh THEN, not now: accept and\r\n  document (done — the runbook now carries the mechanism), or give main's group per-sha keys\r\n  (`group: ci-${{ github.sha }}`) so runs never share a group — at the cost of concurrent main\r\n  runs competing for the boxes, which is exactly what the group exists to prevent. The trade is\r\n  real; do not fold it into a drive-by.\r\n- **Size:** docs half DONE in this commit; ci.yml half small but load-bearing — needs its own\r\n  lane if taken.\r\n- **Kin:** [[IR-40]] (a record that is right-in-the-end-but-early vs a record that never comes to\r\n  exist — both read as clean states unless labelled), [[cancelled-measurement-leaves-labelled-hole]].\r\n\r\n### IR-42 — `pool-claim` writes a record; only the BUILD enforces — and AGENTS.md invited the misread\r\n- **Status:** BUILT 2026-08-19 — the AGENTS.md corrective line lands in the SAME COMMIT as this\r\n  entry (the register batch commit), which is the entry's stated exit condition. The optional\r\n  code-side nicety (claim verb prints the incumbent record it overwrites, information only)\r\n  remains unclaimed — a candidate rider on the IR-26 remedy lane, which already touches\r\n  `pool_claim`'s read-before-write path, NOT a reason to keep this entry open ·\r\n  **Origin:** doyle + todlando independently at source, 2026-08-19, during the #193 gate.\r\n- **Mechanism (source-verified):** `xtask pool-claim` (crates/xtask/src/main.rs:2232-2294 at the\r\n  read sha) parses its args, reads the lane's own git identity, builds a `PoolOwner` and calls\r\n  `spt_poolguard::write_owner` UNCONDITIONALLY (:2280) — no `read_owner`, no verdict, no\r\n  comparison against the incumbent claim anywhere in the function. Claiming is last-writer-wins\r\n  by construction: two lanes can each \"hold\" a pool in sequence with only the last write\r\n  surviving, and the displaced lane learns nothing at displacement time. All four enforcement\r\n  arms — `Refuse` (SPT_POOL_FOREIGN), `Takeover` (loud), `Unproven`, `HatchOpen` — live in\r\n  crates/spt-store/build.rs:31-113 and speak only at the next BUILD. (Same object [[IR-26]]'s\r\n  CLAIM-OBSERVABILITY measurement saw from the displaced side; this entry is the CLAIMING side\r\n  plus the doc that invited the misread.)\r\n- **Measured consequence:** 2026-08-19, doyle's gate claim over todlando's unlanded\r\n  redeem-echo-diag claim — no refusal, no notice (three sequential overwrites that session, one\r\n  over a lane with an unlanded commit). todlando then predicted from AGENTS.md's refusal\r\n  sentence that the gate's claim \"will be REFUSED\" — a false warning to a gater mid-run. The\r\n  refusal sentence sat directly under the \"Claim a pool at lane start\" instruction, inviting the\r\n  build-time semantics to be read onto the claim verb.\r\n- **Corrective landed:** the claim WRITES a record without adjudicating the incumbent lane;\r\n  predict **lane-identity** refusals from builds, never from `pool-claim`. The broader original\r\n  \"never refuses\" wording is superseded by IR-56's **addressing** guard (wrong-tree claims need\r\n  explicit `--foreign-pool`); that guard does not add incumbent-lane adjudication.\r\n\r\n### IR-43 — knock answer carrier: `NoReply` landed at 60.08s against a stated 30s carrier deadline\r\n- **Status:** open, OBSERVATION — mechanism unmeasured, filed exactly as wide as the datum ·\r\n  **Origin:** KNOCK-169 RCA layer 1 (todlando, read-only), golden 32191618042 @`93c1130`,\r\n  twohost-b, 2026-08-18.\r\n- **What/why:** B's `request_answer` yielded `NoReply` at 22:50:08.3605Z — 60.08s after A's\r\n  death — while the carrier deadline is stated at 30s. Recorded in the RCA as a side observation\r\n  with no claim; the cell's red itself was a CASCADE of A's earlier death (answerop.rs:73-81\r\n  produces the courtesy BEFORE returning, so the reply was never sent — that half is settled and\r\n  is NOT this entry). What this entry carries: a transport/liveness bound that reported at 2x its\r\n  stated value. Candidate shapes, neither asserted: two sequential 30s legs each honoring its own\r\n  bound (a composed wait wearing one bound's name), or a bound armed after a wait it does not\r\n  cover (the [[IR-30]] nethost.rs permit-wait shape: `sem.acquire_owned()` outside the timeout).\r\n- **Ask:** derive where the 30s is armed and what path yields a 60s `NoReply` — one code read\r\n  from the emit site, before any instrument.\r\n- **Ripe when:** next knock-carrier touch, or the next `NoReply`-shaped red — whichever first.\r\n- **Size:** small (code read; a token only if the read forks).\r\n\r\n### IR-44 — perch-sentinel comment overclaims: serialization is not preservation, and the comment teaches the false step\r\n- **Status:** open · **Origin:** #188 RCA lock read (todlando flagged, doyle confirmed the lock\r\n  read), 2026-08-18; the collapse-of-branches argument is on #188 and in the RCA record.\r\n- **What/why:** `lock_perch_sentinel` (info.rs:778 at `b20e770`, the diag sha — re-derive the\r\n  line on main before editing) takes a cross-process fs2 lock on a stable per-perch `.info.lock`\r\n  sentinel, and its comment claims it serializes \"ALL info.json writers so a whole-record write\r\n  and a locked RMW can never lose each other's update (`REQ-HAZARD-INFO-RMW-LOST-UPDATE`)\" —\r\n  TRUE for interleaving, FALSE for preservation. `write_info_unlocked` is module-private with\r\n  exactly three callers, all taking the sentinel first (bypass refuted by visibility), but every\r\n  caller of the public `write_info` composes its record BEFORE the lock is taken (:842) — **the\r\n  lock makes that write atomic; it cannot make it preserving.** Only `mutate_info` /\r\n  `establish_locked` read under the hold and can preserve. Measured field case: census write #1\r\n  (`twohost.rs:736`) clobbered `controlled` while correctly locked. A reader trusting the\r\n  comment infers lost-update immunity the funnel does not provide — the #188 hunt burned a\r\n  branch on exactly that inference before the collapse argument killed it.\r\n- **Ask:** respell the comment — serializes writers; a composed `write_info` is atomic, never\r\n  preserving; preservation requires `mutate_info`/`establish_locked` — and weigh whether\r\n  `REQ-HAZARD-INFO-RMW-LOST-UPDATE`'s doc wording carries the same overclaim.\r\n- **Ripe when:** next spt-store/info.rs touch. **Size:** tiny (comment + possibly one REQ doc\r\n  line).\r\n\r\n### IR-45 — twohost rig home premise, SETTLED: pump paths resolve under the per-run TEMP root (rig is disk-hermetic; the \"live fleet roster\" reading is retired)\r\n- **Status:** RETIRED 2026-08-19 — ask answered by the one code read at main @`78a9a16`; residue\r\n  re-homed (see Answer). · **Origin:** #188/#189 RCA readouts (todlando, doyle's 2a-2d), runs\r\n  32097943571 + 32108557362 + 32111921251, 2026-08-18.\r\n- **What/why, two measured halves in tension:** (1) B's pump dialed a THIRD node 155-159 times\r\n  per run at kitsubito's OWN tailscale IP (`100.98.197.12`), different hex + different ephemeral\r\n  port each run — a short-lived local endpoint re-minting identity between runs, present in both\r\n  the golden and the diag run. Read at the time as: the rig uses the CANONICAL home\r\n  (`canonical_pump_paths` → `perch::spt_home()`), so B's roster is kitsubito's live fleet\r\n  roster — environmental coupling of a CI rig to host fleet state. (2) The ER perch measured in\r\n  the chain runs resolves under a per-run TEMP root\r\n  (`…/_temp/spt-test-tmp-<run>…/owlery/engine-room`), NOT the canonical home. Both measurements\r\n  stand; they answer different artifacts (pump roster vs perches), and nothing on record settles\r\n  which home the PUMP paths actually resolve. #189's third-node evidence and its\r\n  cache-leg-never-heals reading rest on that premise (the tension is filed on the #188 record as\r\n  an open question against #189).\r\n- **Answer (2026-08-19, code read at `78a9a16`, unambiguous — no run token needed):** both role\r\n  tests set `SPT_HOME` to a fresh per-run `TempDir` as their FIRST act (`twohost.rs:813-814` role\r\n  B, `:1501-1502` role A), before any store touch. `canonical_pump_paths` resolves every path via\r\n  `perch::spt_home()` (`twohost.rs:396-414`), which honors the `SPT_HOME` override first\r\n  (`perch.rs:34-41`); the pump's roster source `presence::registry_snapshot_dir()` →\r\n  `perch::identity_dir()` sits under the same root (`presence.rs:83-85`). The rig is\r\n  DISK-HERMETIC per run; both prior measurements reconcile (ER perch observed under the temp\r\n  root, pump paths resolve there too). The misleader was the helper's name + doc comment (\"real\r\n  homes, not test roots\"), which describe production path LAYOUT, not the resolved ROOT.\r\n- **Residue disposition:** (1) #189's third-node evidence was corrected on the board (comment\r\n  5337519936) — the roster row arrived at RUNTIME into a temp-rooted store, ingress mechanism\r\n  OPEN on #189, no longer explained-environmental. (2) KEYSTONE #182's hygiene lane repaired the\r\n  `twohost.rs:394` comment to say exactly what the helper does: production path layout rooted in\r\n  the process's fresh per-run `SPT_HOME`.\r\n\r\n### IR-46 — the Windows disk-floor preflight asserts an INSTANT; workspace free space moves tens of GB inside the hour, so a green floor is not a claim about run headroom\r\n- **Status:** open — mechanism CONFIRMED by a measurement series on hfenduleam; doyle ruled it\r\n  register-shaped 2026-08-18 · **Origin:** deployah, NAMEPLATE #181 golden-head intake, on the\r","truncated":true,"truncatedBy":"lines","totalLines":5133,"totalBytes":80587,"outputLines":905,"outputBytes":80587,"lastLinePartial":false,"firstLineExceedsLimit":false},"totalLines":6937,"displayContent":{"text":"### IR-26 — POOL-OWNER claims authorize takeover from a DEAD holder, so releases#103's hazard reaches through the guard\n- **Status:** OPEN for residual claim-time observability and stale-reader enforcement; the\n…\n- **RULING (doyle, 2026-08-04) — the claim path must run the same guard the build path runs, and a\n…\n\r\n### IR-27 — A junction-pooled rig is TWO objects and teardown only ever removes one\r\n- **Status:** open, found in the wild 2026-08-04 · **Origin:** hertz's 44-tree worktree sweep\r\n  (IR-26 follow-on 3) · **Cross-ref:** [[IR-14]] (unclaimed pools), [[worktree-target-junction]]\r\n- **What/why:** a rig built as `worktree\\target -> junction -> .worktrees\\<pool>` has its build cache\r\n  in a directory that is NOT the worktree and NOT in `git worktree list`. `git worktree remove` deletes\r\n  the junction and reports success; the pool survives with zero inbound links and nothing naming it.\r\n  Measured on this box: reaping `golden-render` and `w4-cli-doc` the obvious way would have reclaimed\r\n  ~26 MB of worktree and stranded **14.17 GB** of pool (`gate-target-render` 6,265,448,382 B +\r\n  `gate-target-w4doc` 7,907,558,098 B). Neither pool appears in any worktree listing.\r\n- **The second shape, same mechanism, already realised:** `.worktrees\\gate-target` was found at\r\n  **0 files / 0 bytes with FOUR live inbound junctions** (assembly-doorbell, doorbell-w1/w2/w3). Someone\r\n  had already reaped that pool and left four dangling-but-valid links behind. So the defect runs both\r\n  ways: remove the worktree and the pool is orphaned; remove the pool and the links are orphaned.\r\n  Either half alone leaves a lie on disk.\r\n- **Why it is not just \"be careful\":** the classification step people already know\r\n  (`Get-Item -Force` OUTBOUND, INBOUND reparse sweep) tells you HOW to delete an object you have\r\n  already decided to delete. It does not tell you that a second object exists. The missing thing is an\r\n  enumeration that reaches pools no worktree names.\r\n- **Remedy shape (CORRECTED by builder retraction, 2026-08-04 — the enumeration already exists and\r\n  shipped):** `xtask pool-sweep` (`c6515f1`, `REQ-POOL-GC-ORPHAN-RECLAIM`, ancestor of `b7b00c3` by\r\n  merge-base) walks the root for dirs AND links, counts inbound links over the whole sweep before\r\n  forming a verdict, classifies InUse/Owned/Orphaned, and reaps orphans on `--reap`. The gap is not\r\n  detection, it is TIMING: a junction-pooled tree's pool is `Owned` and not reclaimable right up to\r\n  the moment its worktree is removed, and `Orphaned` only after — so the reclaim always lands in a\r\n  LATER sweep, and nothing triggers one. `gate-target` (0 bytes, four dangling inbound links) is a\r\n  completed instance of that deferral. Remedy is a post-teardown pass or a teardown that runs the\r\n  sweep itself, not new enumeration. (An earlier draft of this entry proposed building the\r\n  enumeration; retracted by its author before ripening — the tool refuting it was one run away.)\r\n- **Ripe when:** next CI/infra batch. **Size:** small (one enumeration + report, no new policy).\r\n- **Discipline this cost, stated so it is not re-learned:** teardown must be TWO EXPLICIT STEPS per\r\n  junction-pooled tree — junction deleted AS A LINK (`Directory.Delete(path, recursive: false)`), then\r\n  the pool AS A TREE after an inbound sweep confirms it is linkless. Executed that way on 2026-08-04:\r\n  28 worktrees, 4 pools, 0 skipped, 0 pinned, 17.04 GiB measured on a box with concurrent writers.\r\n\r\n### IR-28 — A wave-gap rider is visible to the request board and invisible to a milestone-narrative notes pass\r\n- **Status:** BUILT 2026-08-29 — PR #176 (`880b3b9c`, landed on main via `37368263`).\r\n  · **Origin:** deployah, v0.53.0 release close 2026-08-04.\r\n- **What/why:** the v0.53.0 changelog omitted `184f2ac` (the releases#125 two-core CPU-burn fix, a\r\n  wave-gap rider that rode the commit range but was never LOCKSMITH scope) while the alchemy release\r\n  verb promoted #125 to DONE and named it publicly as shipped — two published surfaces contradicting\r\n  each other until the post-publish docs-only repair (`9841592`). The rule was already right (the\r\n  runbook audits the changelog against the COMMIT RANGE); the EXECUTION missed it, because a notes\r\n  pass written from the milestone narrative never enumerates the range. The mechanism, not the\r\n  incident: any rider is board-visible and narrative-invisible.\r\n- **Built evidence:** `docs/RELEASE-RUNBOOK.md` now requires a mechanical `vPREV..HEAD`\r\n  user-facing commit list, a changelog match beside every row, and an explicit accounting of every\r\n  unmatched row before the golden run. The repair precedent remains docs-only amend +\r\n  `gh release edit`, never retag. PR #176 passed `traceable-reqs check`.\r\n\r\n### IR-29 — twohost ladder: role A fires the done-barrier BEFORE its last cross-node rung, so the re-pull's serve window is won by timing, not guaranteed\r\n- **Status:** OPEN for later serve-window/rung residuals; the original\r\n  `test/twohost-serve-window` fix `17bbbd8` LANDED in v0.54.0, as recorded by IR-30.\r\n  Stale authored-but-unlanded header corrected 2026-09-11; no new acceptance or margin\r\n  measurement claimed. · **Origin:** golden\r\n  30873007187 attempt 1 red, doyle timeline triage + hertz source diagnosis 2026-08-04.\r\n- **SECOND FACE, measured 2026-08-24 (WAX-SEAL #21 W3 gate climb @ 035c3fe6, doyle):** the class\r\n  recurs on a NEW rung, and this face is UNWINNABLE rather than racy. The W3 seal rung S1 mints\r\n  on A ~0.3s before A's ladder completes (mint mono 80843ms, ladder end ~81150ms, walked from\r\n  the capture), while the seal pump worker's cadence is 500ms — the pusher exits before its\r\n  first eligible post-mint tick, so ZERO feed pushes ever fire (both logs hold zero seal-feed\r\n  lines) and role B burns its full 900s window on \"seal: A's record replicated into B's store\".\r\n  Full-re-presentation heals only while a pump is RESIDENT; the rig kills it. Product not\r\n  implicated (local legs + design review all green at the sha). Dispatched to hertz 2026-08-24\r\n  with two fix shapes (mint early with ~120 ticks of resident-pump margin, or a\r\n  reverse-confirmation barrier on A's done-push); the climb re-runs on his fix. Lesson for\r\n  future rungs, stated as construction: a rung whose delivery is CADENCED must not sit inside\r\n  the terminal margin of the process that pushes it.\r\n- **Mechanism (hertz falsified the gater's first spelling, kept because the correction is the\r\n  entry):** NOT \"B exits early\" and NOT a missing barrier. B's contract (twohost.rs:1116-1121,\r\n  \"hold until A finishes its side — done-file as the ladder's completion barrier\") is right and B\r\n  obeys it. A BREAKS it: A pushes done.txt (:1819-1832, payload literally \"ladder complete on A\")\r\n  then runs the ENTIRE leg-D digest rung including the re-pull assert (:1959) before its own\r\n  `stop.store` (:1966). B tears down exactly when A said it could; the re-pull then races B's\r\n  post-signal teardown. The panic's hint text (\"may be running a version without cross-node\r\n  digest\") is pre-authored and was NOT evidence of version skew.\r\n- **Margin series, six draws of one race (deployah, markers cited by TEXT and positive-controlled\r\n  against a known draw before producing an unknown one):** golden 30860770146 +60s · a1 −0.6s\r\n  (the RED) · a2 +59.4s · a3 +60s · a4 +59.59s · a5 +63.89s. BIMODAL, not drifting: greens\r\n  cluster within seconds, one collapse through zero. A green does not mean the window got safer;\r\n  sample count characterizes a bimodal race, not margin size — the slack is incidental, not\r\n  designed. Local load on hfenduleam during A's leg D eats the margin directly (role A runs\r\n  there; the done-file is already pushed), which is why builds hold through twohost legs.\r\n- **⚠ THE SERIES IS CLOSED AT SIX DRAWS — ITS DERIVATION IS UNRECOVERABLE, AND NO SEVENTH NUMBER\r\n  MAY BE ADDED (ruled by doyle 2026-08-05, at the tranche-2 golden).** Asked to extend it with a\r\n  draw from run 30971976024, deployah positive-controlled the markers FIRST and the control\r\n  REFUSED: grepping `margin|deadline|serve window|slack|headroom|budget` against a control run\r\n  known to carry good twohost evidence (30940180764) returned ZERO. Source confirms it —\r\n  **`margin` is not an emitted token anywhere**: absent from `.github/workflows/golden.yml`, and\r\n  every `crates/` hit is unrelated (terminal right-margins in broker/resize tests,\r\n  `ROUND_DRAIN_MARGIN` in `pump/mod.rs`). So the six figures were DERIVED from log timestamps\r\n  against a bound that was never written down, by a measurer whose context has since been cleared;\r\n  the gater who recorded them never held the formula either. **Consequence, stated so nobody\r\n  re-derives it:** any new figure computed from these logs would be a DIFFERENT quantity wearing\r\n  the same name, and would enter a series whose value is its bimodality — the one structure a\r\n  mismatched sample corrupts invisibly. This run therefore gets a LABELLED HOLE, not a number.\r\n  What IS reportable for it, with endpoints named rather than a name reused: **ladder span**, node\r\n  start → `TWOHOST role B: ladder complete` = **183.50s** on the batch vs **259.21s** on the\r\n  control. Marker parity established under an IDENTICAL expression on both sides (25 = 25, after a\r\n  first pass that compared two different greps and would have read as parity by coincidence).\r\n- **The fix this makes obvious:** the twohost margin must become an EMITTED token with its two\r\n  events named at the emit site, so the next draw is read rather than reconstructed. A derived\r\n  quantity whose formula lives only in a measurer's context is one context reset away from being\r\n  unfalsifiable — which is exactly what happened here.\r\n- **Fix shape (doyle-approved):** move the done-push block to AFTER leg D, immediately ahead of\r\n  A's stop — one honest barrier made true, no second completion signal (a redundant pair is how\r\n  the next ordering bug lands after the SECOND one). `int->REQ-REACH-1` travels with the block.\r\n- **Cascade note, so a future triage does not count it:** in a1, twohost-b's gated-CLI red\r\n  (twohost_cli.rs:189, 910s) was the CASCADE — role-A's gated driver step SKIPPED after the\r\n  ladder death, so B waited for a row never produced. A red that postdates its carrier leg's\r\n  failure carries zero information about its own subject.\r\n- **Ripe when:** proving run at the next two-host window. **Size:** landed-sized already.\r\n\r\n### IR-30 — GOLDEN 4b37512 (#145): five attempts, four distinct Windows victims, one sha — the random-victim family measured end to end, and the instruments it left behind\r\n- **Status:** open for the FAMILY SIGHTINGS ONLY — the instrument lanes LANDED as planned with\r\n  the next golden batches (measured 2026-08-25, doyle, `git merge-base --is-ancestor` + first\r\n  tag: serve-window `17bbbd8`, selection probe `695398ba`, resume taxonomy `58337879` all in\r\n  **v0.54.0** (USHER, merge `390204a3` et al.); attach-intent re-aim `37afa571` in **v0.55.0**).\r\n  Any later record citing these as \"authored-unlanded riders\" (the v0.63.0 FIELD-SEAL plan did,\r\n  carried forward from this ledger) is stale — this row is the correction. The #145 gate itself\r\n  CONCLUDED GREEN attempt 5, main ff'd, tested==merged · **Origin:** doyle, night of 2026-08-04,\r\n  run 30873007187 attempts 1-5.\r\n- **The record:** four reds, four DIFFERENT daemon-spawning tests, Windows leg only, Linux green\r\n  at the same sha every attempt: a1 `daemon::tests::a_tree_teardown_reaches_a_grandchild…`\r\n  (10.225s full deadline, 2nd golden sighting — see [[IR-17]]'s updated sub-observation); a2\r\n  `registry_lifecycle::multichunk_feed_applies_with_exactly_one_snapshot_write` (0-vs-1 at\r\n  mono_ms 77, THIRD sighting of the 2026-07-22 seed; hertz source-named the window: converge\r\n  polls rows landed at merge, assert reads `snapshot_writes` incremented in `write_snapshots`,\r\n  unjoined-thread gap between — predicts under-count only, matching all sightings; quiet-arm\r\n  control 40/40 PASS 0 leaky on a still box); a3 `brain_split::broker_survives_brain_kill…`\r\n  (\"supervisor did not respawn the brain\", 32.8s window burn; characterization queued); a4\r\n  `resume_no_control_steal_e2e::brain_respawn_keeps_every_session_controller…` — UNDER the\r\n  ruled quiesce-partial window with a measured-clean box, and its panic NAMED A MECHANISM ITS\r\n  OWN DATA CONTRADICTS (pre-authored Failure-A text; gained=[0,15,17] through ONE\r\n  resume_sessions while a steal displaces the SET; session 0 already 4x behind BEFORE the\r\n  window; the rig's child-liveness immunity was a COMMENT nothing measured). Every red\r\n  lane-independent by per-row delta test run fresh each time, never transferred.\r\n- **Instruments authored off it (all thin test/obs lanes off `11169c1`, compiled where stated;\r\n  ALL LANDED — v0.54.0/v0.55.0, see Status):** hertz `test/twohost-serve-window` @`17bbbd8`\r\n  ([[IR-29]]); hertz grandchild SELECTION probe (+166/-8 daemon.rs test-mod: IsProcessInJob at\r\n  selection time — decisive H1/H2 splitter, birth-stamp one-directional, image, same-snapshot\r\n  match COUNT; compiled + deliberate-break positive control); hertz `test/resume-steal-taxonomy`\r\n  (+109/-6: producer counter `Broker::session_output_seq` bracketing the consumer window,\r\n  authenticated child pin at t1 BEFORE teardown — read at assert time would convict the rig of\r\n  its own cleanup — three-way verdict PRECONDITION / measured-Failure-A-with-producer-story /\r\n  absent-producer-is-its-own-story); todlando `obs/resume-attach-intent` @`9c9e6c5`\r\n  — **a DEAD-PATH emit that never fired in production; removed 2026-08-04.** The\r\n  `RESUME_ATTACH_INTENT` breadcrumb sat in `resume_sessions`, which has had NO production\r\n  caller since `03c7109` (2026-07-09): the daemon's respawn path is `run_brain` ->\r\n  `resume_session_cursors`, cursor-only, no attach. Its absence from a field log therefore read\r\n  as \"no resume happened\" when it meant \"uncalled function\" — a clean-zero manufactory aimed at\r\n  the very #123 hunt it was built to serve. **Do not hunt for this token.** The instrument now\r\n  lives at the choosers the daemon actually executes, as `ATTACH_INTENT_CHOSEN` with a distinct\r\n  `site=` per chooser (`gap_resume` | `serve_request` | `shell_channel`), carrying the emit\r\n  discipline this one always had — intent bound once, logged and passed from that same binding,\r\n  wildcard-free label. No REQ, per the OBS-rider precedent.\r\n  - _Corrected 2026-08-04 (todlando, in the re-aim rider lane): this row previously described\r\n    the breadcrumb as a live instrument — \"intent bound once, logged and passed from the same\r\n    binding, per-call epoch makes set-vs-one readable off the log\". That sentence was true\r\n    about the emit's CONSTRUCTION and false about its REACH, and a reader consulting this\r\n    register during the #123 hunt would have been sent after a token that cannot fire.\r\n    Replaced rather than annotated, per the register's correction convention; the superseded\r\n    wording lives in git._\r\n- **Rulings that outlive the night:** a green retires NO intermittent row — grandchild and the\r\n  a4 row are INSTRUMENTED-AWAITING-FIRE, the next occurrence carries its own verdict; the\r\n  environmental family's leg 3 (runner off the fleet host) stays operator-ruled NON-OPTION\r\n  (\"stop proposing it\") — sightings accumulate in the family record, evidence files itself,\r\n  re-asking is direction; the quiesce-partial window is the sanctioned tool and it WORKED as a\r\n  discriminator (a4's red under quiesce is what forced the rig-soundness finding).\r\n- **Instrument notes minted on the way, cheap to lose:** (a) `gh run view --log` refuses for a\r\n  COMPLETED attempt while any later attempt is live (gates on the RUN) — recover per-job with\r\n  `gh api repos/<o>/<r>/actions/jobs/<id>/logs`; (b) a process-census RESIDENT COUNT is not\r\n  trendable (23→17→15 in 90s of inbox-poll CLI churn) — the CLASSIFICATION is the measurement,\r\n  the count is noise; (c) nextest's per-run LEAKY count is a free process-leakage series already\r\n  in every log (a1=12/a3=10/a4=13, and the multichunk row alone leaks 0/40 — the leaks are the\r\n  row's NEIGHBOURS); (d) diagnostic-token greps derive from the FAILING FRAME's own emit sites,\r\n  never from the register entry discussing the symptom — the gater's own\r\n  `REAP_JOB_TERMINATE_FAIL` zero over a path that emits `SERVICE_TREE_KILL_INCOMPLETE` was VOID,\r\n  and the emit sites document their own vocabulary (tree_kill_incomplete_line's doc names its\r\n  grep-partner); (e) **\"golden green ⇒ box free\" is FALSE — the ff-push that concludes a golden\r\n  STARTS the automatic post-merge ci run on the same box** (hertz, measured to the second:\r\n  Runner.Worker up 00:13:02 local = run 30886843672 job start 07:13:02Z, ~2min after the ff), so\r\n  the box empties after the POST-MERGE run, not after the golden; the box has a fourth actor no\r\n  agent steps off, woken by every main push (todlando's spelling), and post-golden sequencing\r\n  must gate on `gh run view --json jobs` of the post-merge run before any timing-sensitive work.\r\n- **Ripe when:** ~~instrument lanes land~~ (DONE, v0.54.0/v0.55.0); family sightings stay until\r\n  the family record closes them — the entry now waits on FIRES, not landings. **Size:** nothing\r\n  left to build; the next family sighting carries its own verdict via the landed instruments.\r\n- **LINUX-FACE SIGHTING + ITS RESOLUTION (doyle, v0.63.0 FIELD-SEAL goldens r1-r3 + proof runs,\r\n  2026-08-25 — the family's first measured MECHANISM, and it is environmental-amplifier ×\r\n  latent-test-defect, not a product fault):** three goldens, three DISTINCT kitsubito victims,\r\n  8/9 green each, victims migrating across same-sha reruns (r2/r3), every red a LONG death\r\n  (9.9s/59.4s/62.7s) of a fast cell — the family signature on the OTHER OS. Root-caused to ONE\r\n  window whose WIDTH varies with load: the brain's `spawn_session_pid` Spawned-wait\r\n  consumes-and-discards output racing ahead of the reply (KNOWN-HAZARDS 6.9, same-session face,\r\n  amended at `dbe3daad`); the broker execs the PTY child ~2ms BEFORE writing `Spawned`, so a\r\n  fast first chunk can be eaten. Under kitsubito's then-active kernel-audit backpressure\r\n  (see the kitsubito-audit entry below) the broker DISPATCH thread could stall arbitrarily in\r\n  that gap — the ~2ms window stretched to seconds, swallowing ANY marker prefix of ANY\r\n  spawn-wait test: random victims, long deaths, spawn-intensity × serialization scaling\r\n  (deployah's measured pair), migration across reruns. Box remediation narrowed the window back\r\n  to ~2ms, leaving exactly one knife-edge victim (a first-chunk needle, near-deterministic red,\r\n  62.7s natural-life death), fixed test-side in `dbe3daad` (v0.63.0's head). Full RCA + the\r\n  observer-effect instrument record: releases#225 comments 5417343026/5418844404.\r\n  **Standing lesson for the family:** an environmental slowdown is an accidental mitigation —\r\n  REMEDIATING a box can EXPOSE latent knife-edge races (the storm had hidden this one for\r\n  releases). And a \"random victim family\" should be tested against ONE window with\r\n  load-dependent width before positing per-victim mechanisms. The Windows face above remains\r\n  open on its own instruments; the two faces now have one shared candidate SHAPE (a race window\r\n  amplified by box load) with different windows.\r\n- **Status:** open · **Origin:** measured box event, HFENDULEAM 2026-08-04 ~05:00 local, during\r\n  USHER lane concurrency (hertz mechanism statement + both agents' reclaim arithmetic).\r\n- **What/why:** the box hit **0.00 bytes free** mid-build. Failure signatures it manufactured\r\n  look like toolchain or code defects, not disk: `rustc-LLVM ERROR: IO failure on output stream:\r\n  no space on device`, `LNK1318: Unexpected PDB error; LIMIT (12)`, `LNK1108: cannot write file`\r\n  — a red wearing a linker's face (doyle's U2 gate rig ate exactly this; verdict legs already\r\n  green survived, the suite leg had to be re-run). Contributions measured, not inferred: hertz\r\n  ~70 GB across four lane targets (er-seams **42.66 GB** cold `--workspace --tests`,\r\n  selection-probe 25.80, poolowner 1.03, ci-riders 0.91), doyle gate rig 15 GB cold full build.\r\n  Reclaim arithmetic reconciles both and neither alone: 0.00 → 25.47 GB (hertz reaps\r\n  selection-probe) → ~40 GB (doyle reaps rig). **The mechanism (hertz, ruled register-worthy):\r\n  every isolated lane worktree carries its OWN `target/`, so disk cost is multiplied by lane\r\n  count, while pool-claim — built to arbitrate a SHARED pool — sees none of it; a claim on\r\n  main's pool is ceremonial for a lane that never writes there. The tool we use to reason about\r\n  build-cache contention cannot see the resource that actually ran out.** Eight-plus worktrees\r\n  at 25–43 GB per cold full build is the shape of the next occurrence, and it will not announce\r\n  itself through pool-claim. Adjacent discipline failure the same night, named so the entry\r\n  carries it: a gater firing a cold full-workspace rig into a window with two live builder lanes\r\n  is the pre-flight question-1 failure (right-size the run) — targeted legs and warm pools\r\n  first.\r\n- **Remedy shape (sketch, not ruled):** (a) a box-level free-space floor as a RIG STEP at lane\r\n  start — the claim verb is the natural seat (print box free + du of known lane targets at\r\n  `pool-claim`, warn under a floor); kin to the CI-side `REQ-CI-FREE-SPACE-PREFLIGHT` (IR-1's\r\n  companion fix), which covers runners but not agent lane rigs; (b) teardown-on-gate-close is\r\n  already a rig step (the gate-target-disposal rule) — the gap is the AGGREGATE view across\r\n  lanes nobody owns; (c) possibly a `pool-census` xtask verb listing every `.worktrees/*/target`\r\n  with sizes, so the sweep is one command instead of a du walk each agent re-derives.\r\n- **Ripe when:** next CI/rig-touching wave, or the next ENOSPC-signature red — whichever first.\r\n- **Size:** small-medium (claim-verb print + floor; census verb optional).\r\n- **Field addendum (2026-08-04 second event, same day filed — ripeness condition met):** the box\r\n  fell under the CI runner's 32 GiB free-space floor twice more (12:31 main @9d65e65 docs-only,\r\n  12:50 PR core#144 @b110bc8) while todlando's F-lane built. Both Windows unit legs REFUSED with\r\n  `RESOURCE=disk drive=C:\\ free_bytes=…` — the `REQ-CI-FREE-SPACE-PREFLIGHT` floor did exactly its\r\n  job: a docs-only main red named the resource instead of wearing a linker's face, and triage was\r\n  one log read instead of an RCA. That is the instrument's first field catch; the CI side of this\r\n  entry is PROVEN. The agent-lane side stays open: local trough measured 8.8 GB free mid-F-lane.\r\n  Reclaim, measured before/after per the teardown rule: doyle reaped gated u1+u2 lane targets\r\n  (POOL-OWNER claims verified own+dead-holder, inbound reparse sweep clean, worktrees kept)\r\n  8.8 → 59.5 GB (+50.7); hertz reaped er-seams target (pool-release first, same discipline)\r\n  59.46 → 101.16 GB (+42.66). Refined mechanism statement (hertz, this event): the disk floor is a\r\n  per-BOX resource our per-POOL instrument is structurally blind to — pool-claim answers a\r\n  question about contention that is not the question the box ran out of.\r\n- **AXIS ADDENDUM (deployah, golden 30928816784 / USHER `fc7fad1`, 2026-08-04) — one floor reading\r\n  is a SNAPSHOT, and the swing is bigger than the margin you fire on.** Two facts this entry's\r\n  remedy (a) has to be built against, both measured rather than reasoned:\r\n  (1) **A pre-fire PROCESS census cannot see the floor at all.** Mine came back clean minutes before\r\n  the run — zero test-path `spt.exe` residents, zero `cargo`/`rustc`/`link`/`cl` — and both Windows\r\n  legs then died in the disk preflight (`drive=C:\\ free_bytes=26099576832 floor_bytes=34359738368`,\r\n  `RESOURCE=disk`, exit 1) with a 128-line log carrying ZERO `Compiling`/`PASS`/`FAIL`/`Summary`\r\n  lines: no test signal, and the merge chain never indicted. Both readings were TRUE at the same\r\n  instant — the gater's finished assembly gates were sitting on disk as a DIRECTORY, not running as\r\n  a process. A process-axis probe is blind to a finished build's cost by construction; \"re-check\r\n  closer to the fire\" would have changed nothing, because the axis was never read.\r\n  (2) **The floor number itself moves by tens of GB inside one run window.** Same box, same drive,\r\n  same run, pulled from its own logs: `16:22:55` test-Windows free=26099576832 REFUSED · `16:23:07`\r\n  n1-gate-Windows free=26096607232 REFUSED · `16:46:54` twohost-a free=71033049088 PASSED and then\r\n  ran 11 minutes to success. ~45 GB returned with NO deliberate teardown, and my own reading at\r\n  17:13:45Z was 61352714240 — ~10 GB BELOW what twohost-a saw 27 minutes earlier. The observed swing\r\n  amplitude EXCEEDED the margin I was about to fire on (25.14 GiB).\r\n  So the rule remedy (a) must encode: measure BOTH axes (process residents AND free space against\r\n  the workflow's own 32 GiB floor), and reclaim until the margin exceeds the observed SWING, not one\r\n  sample. Triage corollary, equally load-bearing: twohost-a runs the same preflight on the same C:\r\n  and PASSED, so a preflight refusal is a threshold event on a moving number — never evidence the\r\n  box cannot run the work, and never by itself a reason to indict a merge chain.\r\n- **THIRD ADDENDUM (deployah, v0.54.0 cut, 2026-08-04) — the sweep answers \"0 B reclaimable\"\r\n  TRUTHFULLY on a box that cannot run its own work, because the reclaimable population and the\r\n  owned-lane population are DISJOINT.** This hazard blocked a release twice before it was seen.\r\n  Both Windows legs at the shipped sha `86f0d84` refused at the guard before compiling anything —\r\n  `ci.yml` at `free_bytes=28167569408` (26.2 GiB) and `release.yml` at `27690885120` (25.8 GiB),\r\n  both against `floor_bytes=34359738368`. `assemble` skipped in consequence, so no draft release\r\n  existed: the release was hard-blocked on disk, not on code. Neither leg produced a test verdict,\r\n  so both are LABELLED HOLES, not reds (ruled recorded-and-proceed by doyle, the shipped-sha delta\r\n  being 5 files and zero `.rs`).\r\n  **The finding is not the disk.** `xtask pool-sweep --root .worktrees` reported, correctly,\r\n  `total 66.43 GB across 3 pool(s); 0 B reclaimable in this sweep's scope` while the box sat ~6 GB\r\n  under its own floor. The sweep is behaving as designed — it refuses to reap owned, live lanes.\r\n  But the floor reasons over an AGGREGATE the sweep is forbidden to touch, so the designed\r\n  instrument, run at the exact moment of refusal, tells an operator there is nothing to reclaim.\r\n  That is true and useless. The gap between \"the sweep is correct\" and \"the box can run work\" is\r\n  the defect; it is not fixed by making the sweep more aggressive.\r\n  **Aggregate measured under `.worktrees`** (real target bytes, junction-classified first): 87.79 GB\r\n  across 9 lanes — 2.7x the entire 32 GiB floor. Registered pools: `w1t2-relink-force` 54.67 GB,\r\n  `obs-resume-attach-intent` 10.18, `w1t2-subnet-status` 1.58. Carrying targets the sweep does not\r\n  count as claimed pools: `hertz-teardown-bound` 11.25, `hertz-liveresolve-diag` 4.83,\r\n  `hertz-psyche-bound` 4.19, `hertz-poolowner` 1.03, `hertz-ci-riders` 0.91.\r\n  **The 54.67 GB single lane is NOT waste** (doyle's classification, ratified at this filing): a\r\n  verb lane at that size is workspace-all-targets e2e cost. No lane is misbehaving. That is what\r\n  makes this structural rather than a cleanup task — every lane is individually justified and the\r\n  sum still exceeds the floor.\r\n  **Reclaim taken, and its boundary.** 82.12 GB, from `spt-core/target` — the release driver's OWN\r\n  main-checkout pool, NOT a lane; free 23.23 → 105.34 GB. Classified before removal per the\r\n  teardown rule: OUTBOUND `Get-Item -Force` reported a real directory rather than a reparse point,\r\n  the INBOUND sweep found zero reparse points aimed at it, `CARGO_TARGET_DIR` was unset (no env\r\n  aliasing), the target SUBTREE only was reaped, both sides measured.\r\n  **Snapshot behavior reproduced inside this measurement window**, corroborating the axis addendum\r\n  above at a smaller amplitude: free read 25.49 GB when first measured and 23.23 GB at the reap\r\n  minutes later — it drifted 2.26 GB DOWNWARD while the operator was deciding what to do about it.\r\n  **Priced side effect, for the next reader:** reaping the main pool took the prebuilt `xtask` with\r\n  it, so the next lane claim rebuilds it first — the lane-check shortcut is cold until then. It cost\r\n  a 2m11s cold rebuild inside this release's own publish step.\r\n  **What this does NOT license:** reaping another agent's owned lane to clear a floor. The sweep's\r\n  refusal is correct and stays. What is missing is an AGGREGATE-AWARE signal — the box knowing its\r\n  lanes sum past the floor *before* a run is dispatched into a guard that will decline it.\r\n- **FOURTH ADDENDUM (doyle, 2026-08-04 late evening — fourth event in one day, and the first\r\n  RULING on this entry).** C: hit **0.44 GB free** during doyle's lane-2 stack gate and todlando's\r\n  re-aim leg set. Signatures manufactured this time, all initially read as something else:\r\n  `os error 112` mid-rlib-archive surfacing as xtask \"building spt failed\" (exit 101); a\r\n  servicehost force-kill unit red at a sha gated GREEN on the same rig an hour earlier; todlando's\r\n  6-of-7 leg table red with `LNK1318` while only traceable-reqs survived. Both agents' verdicts\r\n  from the window were VOIDED and re-run, not re-read.\r\n  **Discriminator correction (hertz, ratified at this filing):** \"treqs alone survives\" is a\r\n  POSITIVE TELL, never a clearing test — a full disk reds BEFORE any link step (rustc writing\r\n  rlibs), and treqs can red for its own reasons; signature absence says NOTHING. The only\r\n  falsifier for \"this red was the disk\" is free space AT RUN TIME, and no log on the box recorded\r\n  it, which made every red from the window unanswerable after the fact.\r\n  **RULING (doyle):** every rig/gate script records `FREE-AT-START` / `FREE-AT-END` in its own\r\n  SUMMARY — one line each, the datum that makes a disk confound answerable post-hoc. Effective\r\n  immediately for hand-authored rigs; hertz builds it into the shared rig harness at next touch\r\n  (assigned, not unasked). This is remedy (a) narrowed to its cheapest load-bearing slice.\r\n  **Reclaim, all FS-delta-measured:** todlando +59.4 GB (obs-resume-attach-intent 8.56 +\r\n  w1t2-relink-force 50.83; 0.44 → 59.83), hertz +1.79 GB (ci-riders + poolowner; sum-of-lengths\r\n  said 1.94, the FS delta governs; 59.09 → 60.87), doyle +38.8 GB (w1t2-subnet-status +\r\n  w1t2-perch-gc + w1t3-node-verb targets; 60.75 → 99.54). Full discipline each: outbound\r\n  classification, inbound reparse sweep (zero), CARGO_TARGET_DIR confirmed unset, subtree-only.\r\n  **Mechanism sharpened by this event:** the standing swing IS the finished-lane population —\r\n  ~110 GB of pools belonging to lanes already GATED AND PUSHED, held for hours because disposal\r\n  fires at GATE close (a rig step) while nothing fires at LANE finish; a pushed lane awaiting\r\n  assembly holds its pool invisibly. Corollary corrections carried: todlando withdrew his\r\n  name-based pool census (10x off; ancestry, not directory names, classifies a pool as closed),\r\n  and hertz-selection-probe's worktree removal REFUSED Permission denied — IR-38's second holder\r\n  class recurring, left for retry rather than forced.\r\n\r\n- **FIFTH ADDENDUM (deployah, v0.63.0 FIELD-SEAL golden, 2026-08-25) — SCOPED DELIBERATELY TO ONE\r\n  CONSEQUENCE: reaping a pool UNCLAIMS its tree, and the next builder meets a refusal that is the\r\n  rule working.** (The disk-floor mechanism from the same event is doyle's to file at his\r\n  release-close sweep — one voice each, by division agreed in-window. This addendum stops at the\r\n  pool-claim consequence and deliberately does not restate the floor finding.)\r\n  Five FIELD-SEAL lane pools were reaped to clear the golden floor — gate rig `gate-222-ca30a79e`\r\n  plus lanes `fix-222`, `w2-seal-ux`, `w3-ingest`, `w4-exit-subject`; **148.48 GB measured by FS\r\n  delta**, free 1.37 → 149.84 GB, worktree checkouts kept, `main/target` untouched by ruling.\r\n  **The consequence to record:** `POOL-OWNER.json` lives INSIDE `target/`, so reaping the subtree\r\n  takes the claim with it. Those five trees are now **UNCLAIMED — which is fresh-not-foreign**, a\r\n  different state from the `SPT_POOL_FOREIGN` refusal. Whoever resumes one of those lanes (a hertz\r\n  fixup, a golden-red rebuild) must run `cargo run -p xtask -- pool-claim --pool <dir> --label\r\n  <lane>` **from that worktree** before the first build, or `crates/spt-store/build.rs` refuses.\r\n  **A refusal there is the rule working, not a defect** — filed precisely so a later reader does\r\n  not open an issue against the build script for behaving correctly. Naming it costs one line;\r\n  the alternative is an RCA against our own guard.\r\n  **Prediction-vs-meter, corroborating hertz's fourth-addendum note at ~75x its scale:** pre-reap\r\n  sum-of-lengths sizing predicted 163.9 GB; the FS delta paid 148.48 GB, a 15.4 GB shortfall left\r\n  UNEXPLAINED here rather than rationalized (allocation granularity, sparse/compressed extents and\r\n  concurrent writes all sit between the two meters). **The FS delta governs** — hertz ruled this at\r\n  1.94-vs-actual and it holds at three digits. Report the meter, never the estimate that agreed\r\n  with your plan.\r\n  **Discipline executed, for the audit trail:** outbound classification re-read AT REAP TIME (all\r\n  five real dirs, zero LinkType); inbound sweep over **2854** reparse points under `projects\\`\r\n  found zero aimed at any victim; `CARGO_TARGET_DIR` confirmed empty in process, **Machine and\r\n  User** scope (the arm that leaves no directory entry to notice afterwards); process census\r\n  RE-RUN at reap time rather than carried from a peer's snapshot — zero builders, zero processes\r\n  imaged out of a victim pool, both live `spt` images resolving to the installed path. The peer's\r\n  snapshot proved correct; it was re-run because a snapshot is not a standing property, which is\r\n  the reason it was offered with that caveat.\r\n\r\n### IR-32 — Docs-drift gate blesses its own gen: an empty-emitting producer agrees with itself perfectly\r\n- **Status:** open · **Origin:** todlando mid-lane stop-and-report, U1 (#144) 2026-08-04. Filed by\r\n  the builder to the gater deliberately — register shape is doyle's to own.\r\n- **What/why:** with a defective binary in the tree (stack-overflowed before reaching its own\r\n  code, empty stdout, non-fatal to the generator), `cargo run -p xtask -- gen` wrote\r\n  `docs-site/src/cli/reference.md` reduced to EIGHT lines — title, do-not-edit banner, empty code\r\n  fence — deleting 3193 lines of published CLI reference. `xtask check` then exited 0, because\r\n  the drift gate compares what the binary emits NOW against what the file holds, and gen had just\r\n  overwritten the file with exactly that emit. **A producer that emits nothing agrees with itself\r\n  perfectly.** Caught only because the builder grepped the regenerated page for his new flag\r\n  names and treated the clean zero as suspicious ([[zero-match-filter-reads-as-absent]] shape);\r\n  the gate itself would never have said a word, and the gutted public reference ships green.\r\n  The mechanism generalizes past the stack overflow that exposed it: ANY failure mode that makes\r\n  `spt --help` produce empty stdout while exiting non-fatally to the generator gets the same\r\n  green. Kin to [[cli-command-docs-drift]] (the gate this defeats) — the gate detects DRIFT\r\n  between binary and page, and is structurally blind to a page just regenerated from a broken\r\n  binary.\r\n- **Remedy shape (builder's sketch, sound; not yet ruled on seat):** a floor in `xtask gen` —\r\n  refuse to write a page whose help block is empty, or whose output is implausibly shorter than\r\n  the file it replaces — so the generator fails loudly instead of producing a stub the gate\r\n  blesses. Gen is the right seat: check runs in CI on a fresh emit too, so a check-side floor\r\n  alone still lets a local gen gut the working tree.\r\n- **Ripe when:** next docs-tooling or xtask-touching lane; SOONER if any lane regenerates the CLI\r\n  reference before the floor exists (a gate on that lane must assert page LENGTH, not gen's exit\r\n  code, until this is built).\r\n- **Size:** small (one refusal + a length-plausibility floor in gen).\r\n\r\n- **Kin instance 2026-09-11 (hertz, #304 lane, caught before launch):** the RUN expression for the\r\n  spt-daemon lib producer was still the 15-term webserve list after six #297 cases had been admitted\r\n  and inventoried at 21 terms. It would have executed 15 and reported against a 21-term inventory —\r\n  a subset quietly narrower than the thing it claims to discharge, with a count that reads fine.\r\n  Rule: a run filter is diffed TERM-FOR-TERM against the inventory it discharges before launch; a\r\n  matching case count is not that check.\r\n\r\n### IR-33 — Debug-build clap Command tree runs near the main-thread stack ceiling; the margin is THREE net new args, bisected at `8f291e1` (the original ~6 was measured on U1's tree and is superseded)\r\n- **Status:** OPEN for acceptance/margin reconciliation. Current source at `e5a2fed9` runs\r\n  the CLI on an owned 16 MiB thread stack and includes `cli_stack_smoke`; the three-argument\r\n  ceiling below is a historical measurement at `8f291e1`, NOT today's measured margin.\r\n  Do not redispatch an already-present sized-stack implementation. No fresh debug-run\r\n  acceptance is claimed by this source read (2026-09-11). · **Origin:** todlando U1 (#144)\r\n  2026-08-04, delta-tested mid-lane.\r\n- **What/why:** eight extra hidden bool args across the five knock seats grew the derive-built\r\n  Command tree past what the debug binary's main thread stack can construct: EVERY invocation\r\n  (`spt --version` included) died with `thread 'main' has overflowed its stack`, exit\r\n  -1073741571, before reaching any of its own code. Delta-tested, not assumed: the same command\r\n  on the main-pool binary from main printed normally. U1 repaired its own trigger (raw-argv\r\n  pre-scan for retired flags before clap parses; lane ends net +2 args) — but the CEILING\r\n  remains: the tree is now close enough that a handful of net new arguments in a debug build\r\n  reproduce a total binary outage — **and the handful is THREE, not six; see the correction\r\n  below before planning against this entry.** **#5's verb-surface rework is the next lane that adds\r\n  arguments and it is much bigger than U1** — this entry exists so #5 is planned knowing the\r\n  margin, not discovering it. Note the failure's face: it presents as a broken binary, and via\r\n  [[IR-32]] it presents as a silently gutted docs page — neither names the stack.\r\n- **CORRECTION — the margin is THREE, bisected at `8f291e1` (todlando's U3 lane\r\n  `build/usher-u3-verb-surface`, own pool, debug profile; filed by deployah 2026-08-04).** The\r\n  original ~6 was measured on U1's tree and was right when written; it is wrong now, and the\r\n  difference is the difference between \"plan carefully\" and \"one flag anywhere takes the binary\r\n  down\". N hidden bool args added to the ROOT `Cli` derive, tree restored from git between every\r\n  row, `--version` as the invocation (it carries no work of its own, so whatever it costs IS tree\r\n  construction):\r\n\r\n      N=0  exit 0                OK  (control — unmodified lane binary answers `spt 0.53.0`)\r\n      N=1  exit 0                OK\r\n      N=2  exit 0                OK\r\n      N=3  exit -1073741571      STACK-OVERFLOW\r\n      N=4 / N=6 / N=8            STACK-OVERFLOW\r\n\r\n  PLACEMENT DIFFERENTIAL, run because #5 adds args at `EndpointCmd` seats rather than at the root\r\n  and a root-only number could have measured the wrong thing: same N injected inside a NESTED\r\n  endpoint seat gives `SEAT N=2` OK, `SEAT N=3` STACK-OVERFLOW. **Identical ceiling — placement does\r\n  not move it**, so three is the number for the shape #5 actually builds. (Rig hazard worth keeping:\r\n  the first seat attempt produced a COMPILE error, E0027, because the dispatch destructures that\r\n  variant exhaustively — taken at face value it would have read as \"the seat is fine\". Both rows\r\n  above are from the fixed rig.) CONSEQUENCE FOR #5: the ratified MIN spelling ends net +2, i.e. it\r\n  would have shipped with ONE argument of headroom, and any later lane adding a single flag anywhere\r\n  in the tree would then take the whole binary down, `--version` included. Remedy (b) below stops\r\n  being \"buys headroom\" and becomes the precondition for #5 shipping safely.\r\n- **Remedy shape (sketch, not ruled):** (a) cheapest tooth — a debug-build smoke that runs\r\n  `spt --help` and asserts non-empty stdout + exit 0, which also backstops IR-32's trigger;\r\n  (b) raise the main thread stack for the binary (build config), buying headroom without\r\n  restructuring; (c) structural — box/flatten the derive tree so construction cost stops scaling\r\n  with arg count. (a) is a rider candidate for any lane; (b)/(c) want a real measurement of\r\n  where the ceiling sits before choosing.\r\n- **Ripe when:** #5 (U3 verb surface) PLANNING — this is a planning input, not just a build item;\r\n  the smoke tooth (a) is ripe for the next CI-touching lane regardless.\r\n- **Size:** small for (a); medium for (b)/(c) with the measurement.\r\n\r\n### IR-34 — nextest LEAK flag on the zombie-fixture row is dominant-but-intermittent (19/20 measured); any gate reading it as a signal flaps\r\n- **Status:** open · **Origin:** doyle #142 F-lane gate 2026-08-04 (first sighting in a gate run);\r\n  characterized same day by hertz from retained logs, ownership falsified by todlando.\r\n- **What/why:** `broker::tests::windows_session_is_zombie_sees_a_handle_held_corpse_as_dead` (the\r\n  ADR-0041 zombie-detection fixture, whose subject is a corpse process kept alive-looking by a HELD\r\n  HANDLE) flags nextest LEAK on most draws but not all — measured 19 LEAK of 20 on a tree carrying\r\n  no #142 content (`test/grandchild-selection-probe` @`695398b`, based on `4b37512`: lib arm 10/10\r\n  LEAK across 822-test runs; full-suite arm 9/10 across 1044-test runs). The single clean PASS\r\n  kills \"intrinsic therefore always\": leakiness is DOMINANT BUT INTERMITTENT. Consequences:\r\n  (1) a gate or reader that treats this row's LEAK as a defect signal flaps at roughly 1 in 20;\r\n  (2) one non-leaky run is NEVER evidence that something fixed it (kin:\r\n  [[intermittent-green-is-zero-information]]); (3) the verdict method that closed it is the\r\n  template — two independent legs, neither load-bearing alone: the suspect lane's diff grepped\r\n  zero hits on the row's subject (zombie / handle_held / OpenProcess / corpse), AND a 20-draw\r\n  baseline on a tree predating the suspect change. This entry exists so the next gater who sees\r\n  the flag reads one register line instead of running that RCA cold.\r\n- **Remedy shape (sketch, not ruled):** annotate the row as expected-leak in nextest config\r\n  (per-test `leak-timeout` override or documented allowlist) so the flag stops presenting as\r\n  signal; alternatively a fixture-side close of the held handle on the clean path if ADR-0041's\r\n  arrangement permits — hertz's call, test/CI lane.\r\n- **LANE-LINKED 2026-08-30 (#242 close sweep):** hertz's queued daemon-leak fixup lane carries\r\n  this entry (brief cites IR-7/17/20/34/35/63); leaves the register when that lane lands.\r\n- **Ripe when:** hertz's next nextest-config-touching lane; blocks nothing today.\r\n- **Size:** small.\r\n\r\n### IR-35 — hfenduleam Windows test-leg victim rate: one teardown/liveness family, measured at ~half of all executions\r\n- **Status:** open · **Origin:** USHER #150 golden triage 2026-08-04 (doyle; all rates deployah-measured).\r\n- **The numbers (15 golden runs 2026-08-02..08-04 + the USHER cycle, deduped on `(run, box,\r\n  started_at)` — GitHub partial reruns COPY untouched jobs into the new attempt with their ORIGINAL\r\n  `started_at` and carried conclusion, so a carried failure is the SAME observation; dedupe before\r\n  any rate math):** Windows (hfenduleam) 13 red / 22 executions = 59% leg-red, splitting 10/22 = 45%\r\n  test-victim + 3/22 infra (IR-31 class). Linux (kitsubito) 2/20 = 10%, 1 victim. Every victim-red\r\n  leg had EXACTLY ONE victim (8/8 legs). Clean-cycle arithmetic ≈ 0.55 × 0.95 ≈ half — a golden\r\n  cycle at these rates is a coin flip. knock145 (the previous green golden) took FIVE Windows\r\n  executions to its green; USHER took four. **A both-green draw is a draw, not evidence the family\r\n  closed.**\r\n- **The family:** 11 victim legs, 8 distinct tests, ONE cluster — process teardown / kill-reach /\r\n  respawn-controller survival, concentrated on hfenduleam. Per-victim dispositions live in the USHER\r\n  #150 triage ledger (releases#150 record). The only surviving cross-sha EXACT repeat after source\r\n  verification is `resume_no_control_steal_e2e` (:488, byte-identical @2138b16 + @4b37512) — and\r\n  both its reds PREDATE the post-#145 producer-side instrumentation, so what repeats is an AMBIGUOUS\r\n  observation (stolen controller vs starved child) twice; only a post-#145 red discriminates. The\r\n  `a_tree_teardown` pair was a FALSE repeat — two mechanisms wearing one assert string (see\r\n  FLAKE-LEDGER row; the counting lesson: assert-body identity must include the polled predicate's\r\n  SUBJECT).\r\n- **Off-CI discriminator (todlando 2026-08-04):** 0/400 (A 0/200 + B 0/200, interleaved,\r\n  `--test-threads 1`, filters positive-controlled, by-path sweeps every iteration) on the warm\r\n  d449ce5 pool UNDER live-fleet load (CPU 46-59%, 13-18 spt processes). Points the family at the\r\n  RUNNER ENVIRONMENT rather than a product race any Windows box expresses — not exoneration (absence\r\n  of reproduction is not proof of absence), but where the next hour goes. A-alone N=500 on the\r\n  instrumented tree ran post-close (result on releases#150).\r\n- **Remedy lanes already moving:** hertz 4-item test-rework package dispatched 2026-08-04 (psyche\r\n  bound split, live_resolve rig instrumentation, green-capture probe profile, resident_service/\r\n  teardown hardening); prod `wait_bounded` tree-kill-on-timeout filed to board as EVAL. This entry\r\n  is the RATE's home — it leaves the register when the operator has ruled on the rate (accept vs\r\n  hold-for-hertz) AND the hertz package has landed with a re-measured victim rate.\r\n- **LANE-LINKED 2026-08-30 (#242 close sweep):** hertz's queued daemon-leak fixup lane carries\r\n  this entry (brief cites IR-7/17/20/34/35/63); the rate re-measure rides that lane's landing.\r\n- **Ripe when:** operator brief at USHER close (immediate); re-measure after the hertz package lands.\r\n- **Size:** visibility entry + the re-measure; fix cost carried by the hertz package.\r\n\r\n### IR-36 — `output_bounded` is a 51-copy clone estate with a named-but-empty shared home; hoist-and-delete wants its own lane\r\n- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane. · **Origin:** hertz measurement\r\n  2026-08-04 (at `7465ac1`, counted before listing, listed untruncated), during the USHER package\r\n  item-2 sweep ruling; doyle ruled file-don't-sweep.\r\n- **What/why:** 51 `fn output_bounded` definitions under `crates/spt/tests` — 50 per-file copies\r\n  plus `tests/common/mod.rs:53`, which is NOT pub, has ZERO callers outside its own module, and\r\n  whose doc comment states outright that the estate's copies predate the shared module. The lossy\r\n  timeout arm (panic loses everything captured, names nothing) is in 38 sites across 36 files.\r\n  The copies have already drifted: two variants of the deadline expect-string exist in the estate\r\n  (`\"captured spt call must complete within its deadline\"` in common/mod.rs:60 vs the\r\n  no-deadline-clause spelling in per-file copies), so a grep keyed to either string undercounts.\r\n  The right fix is a hoist-and-delete refactor (make the common copy pub, adopt it estate-wide,\r\n  carry the item-2 diagnostic arm once) — a 50-file test-estate touch that must NOT ride golden\r\n  cadence as a rider or hide inside a scoped diagnostics item (ADR-0050 thin-lane rationale;\r\n  hertz's USHER item 2 stays scoped to live_resolve, which keeps ONE improved copy as the model).\r\n- **Built evidence:** one public owning helper replaced all 50 file-local\r\n  clones. It owns and tree-kills a timed-out child, waits for reap, drains both\r\n  pipes, and includes the deadline plus partial stdout/stderr in the panic.\r\n  A dedicated regression observes both diagnostics and proves the timed-out PID\r\n  is gone.\r\n- **Ripe when:** a dedicated post-batch test-hygiene lane (natural companion to IR-13's\r\n  mutation-proof loop and IR-23's home-collision fix — same hertz wave shape).\r\n- **Size:** medium by file count, small by risk (mechanical hoist; no assertion changes).\r\n- **Hygiene-lane scope addition (todlando, at #6, 2026-08-04):** a CI prebuild of\r\n  `cargo build -p mock-adapter --bin mock-shell` (derived from tracked `.github/` content) turns\r\n  SIX binedge baseline rows green at once instead of growing the burn-down list one consumer at a\r\n  time — belongs to this lane, not to any thin verb lane. [[IR-38]] (live-binary e2e reap sweep)\r\n  rides the same lane.\r\n- **Built evidence:** all 51 file-local definitions are gone; 158 call sites use the one public\r\n  `common::output_bounded`. The shared helper owns the child, kills and reaps its process tree on\r\n  timeout, drains both pipes, and reports partial stdout/stderr. `bounded_output_e2e` mutation-pins\r\n  both timeout ownership and retained diagnostics.\r\n- **Declared validation extra:** the lane's docs-link gate exposed that `llms_target_exists` treated\r\n  generated targets as absent before generation. Its small refactor + unit keeps source and\r\n  generated link targets distinct; it is deliberate validation fallout, not part of IR-36.\r\n\r\n### IR-37 — `traceable-reqs check` is coverage-only: tag PLACEMENT is unenforced on any multi-tagged REQ, and the more tags a REQ accumulates the less any one is checked\r\n- **Status:** UPSTREAM CLOSED THROUGH RELEASE 2026-08-19 — traceable-reqs PR #19 squash-merged\r\n  @`82d8b14` after doyle's targeted re-review PASS (defect A item-tables + 9 red-first regression\r\n  cells + sighted control; defect B enclosing-item fallback DECLARED in SPEC with cost; 267/267,\r\n  blind repros exit 0); v0.4.0 cut (version bump @`c9a8eb5`, tag pushed, 3 platform assets,\r\n  release notes authored; refs sent to hertz). REMAINING and dispatched to hertz post-#182-landing:\r\n  spt-core consumes v0.4.0 — CI version bump + placement config (enforce-on, module_banner=accept);\r\n  banner cleanup rides a later lane. Entry closes when the consume lane lands. · **Origin:** hertz\r\n  measurement 2026-08-04 (filed by doyle; the measurement is\r\n  hertz's), found when his own pre/post `check` comparison around a tag-adjacency fix came back\r\n  EXIT=0 on BOTH sides — the green he had cited beside the fix validated nothing.\r\n- **What/why:** measured on `test/teardown-bound-shape`: a `unit->REQ-RESIDENT-SERVICE` tag\r\n  SEPARATED from its `#[test]` fn (a const landed between tag block and fn — an AGENTS.md rule-1\r\n  violation) scores EXIT=0 identically to the fixed adjacency. Positive control explains the\r\n  mechanism: that REQ carries 57 unit tags across five files, so 56 other sites decide the\r\n  coverage verdict and no single tag's placement can turn it red. Consequence: AGENTS.md rule 1\r\n  (\"tag on or immediately above the real evidence\") is agent discipline only — drifted tags decay\r\n  silently while coverage stays green, and heavily-tagged REQs decay fastest. This is the\r\n  [[IR-32]] family shape (a gate that cannot see its own blind spot) applied to the traceability\r\n  gate itself.\r\n- **LIMIT, with falsifier (hertz's, verbatim in kind):** behaviour on a SINGLE-tagged REQ was NOT\r\n  established. Separating the only tag of a single-tagged REQ at the stage under test would settle\r\n  whether placement is unenforced outright (still exit 0 ⇒ the checker never reads adjacency) or\r\n  merely un-enforceable at scale (exit 1 ⇒ the checker sees absence, and only multi-tag redundancy\r\n  masks drift). Run that discriminator BEFORE designing any remedy — the two outcomes want\r\n  different fixes (a placement rule in the checker vs a per-tag-nearest-item heuristic).\r\n- **Transfer:** doyle accepted this lane's independent EXIT-0 remeasurement and confirmed it\r\n  matches todlando's settled 2026-08-04 discriminator. Upstream remedy: enforce adjacency for\r\n  each individual `doc`/`impl`/`unit`/`int` tag, with separated-tag negatives covering\r\n  single-tag, interposed-const, file-top-banner, and one-of-many displacement. This repo consumes\r\n  the released checker only.\r\n- **Close condition:** doyle reviews and merges the upstream lane, cuts the `traceable-reqs`\r\n  release, and spt-core consumes that release. Issue/branch/PR/commit refs append here when the\r\n  upstream lane lands.\r\n- **Size:** measurement complete; remedy scope is upstream-owned and dispatched.\r\n- **CONSUME LANE + REGRESSION (doyle, 2026-09-11):** hertz's #304 lane carries the consume (2072b467 ci.yml\r\n  WANT 0.4.0, c3b5feec golden.yml pin, 33936943 `[placement] enforce=on, module_banner=accept`).\r\n  Measured on his tip under 0.4.0: misplaced 9 (tags quoted in backticks in prose; fixed on main\r\n  dd0679dc) and 81 doc stages MISSING that 0.2.0 counted — a checker regression, not drift: 0.4.0's\r\n  git enumeration skipped a FILE root (`CONTEXT.md`), see [[IR-104]]. Fixed upstream as v0.4.1\r\n  (PR #21 -> d9af11d); the lane pins move to 0.4.1 in one fixup after hertz's window. Entry\r\n  closes when that fixup lands on main.\r\n- **DISCRIMINATOR RUN 2026-08-04 (todlando, authorized specimen on `build/w1t2-shell-relink-force`;\r\n  filed by doyle — the measurement is todlando's): the answer is the EXIT-0 ARM.** Single-tagged\r\n  int stage (`REQ-SHELL-RELINK-FORCE`), tag SEPARATED from its fn (parked at file top):\r\n  `traceable-reqs check` EXIT 0 and the REQ still reports `+int`. Tag reverted to adjacency:\r\n  EXIT 0, `+int`. Both exits redirect-read, no pipes. **Placement is UNENFORCED OUTRIGHT — the\r\n  checker never reads adjacency; multi-tag redundancy was never the mechanism, it only widened the\r\n  blind spot.** Remedy option (a) is the live one: a real placement rule in the checker (upstream\r\n  experimplate), not a per-tag-nearest-item heuristic. Measurement caveat, carried at the\r\n  measurer's own insistence: an intermediate probe printed `TAG_ADJACENT_AFTER_REVERT=0` and that\r\n  was the PROBE wrong (`grep -B 1` above the fn lands on `#[test]`, not the tag above it), not a\r\n  failed revert — the revert was verified directly (exactly one tag, above `#[test]`). The\r\n  discriminator result is the record; the intermediate zero is not.\r\n- **REMEDY DISPATCHED 2026-08-18 (doyle):** upstream lane opened in BigscreenVR/traceable-reqs\r\n  (the actual upstream remote; the checkout at `~/Documents/projects/traceable-reqs` tracks it —\r\n  \"experimplate\" above named the tool's origin project, not the repo) — checker-side placement\r\n  rule, default-on in `check`, positive controls all four stages + separated-tag negatives\r\n  including the single-tag displaced discriminator shape and the interposed-const shape.\r\n  Requested by hertz as the IR-37 prerequisite of his test-hygiene family lane (KEYSTONE #182).\r\n  spt-core consumes the upstream RELEASE only — no local shadow checker. Issue/branch/PR refs\r\n  land here when the lane reports.\r\n\r\n### IR-38 — CLASS: an e2e that ends with a live daemon-spawning binary wedges the NEXT build in its pool, and the diagnostic names the wrong lane\r\n- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane. · **Origin:** todlando 2026-08-04,\r\n  `shell_relink_force_e2e` on the #6 lane (filed by doyle; the finding and the fix are todlando's).\r\n- **What/why:** the e2e ends with a LIVE binary by design; on Windows a live process holds its\r\n  image open, so the NEXT cargo invocation in that target dir dies with\r\n  `failed to remove file target\\debug\\spt.exe: Access is denied (os error 5)` — surfacing as\r\n  exit 101 with NO test summary, because the failure names the BUILD and the FILE, never the test\r\n  that leaked the holder. Actual holders measured: two lane-local `spt daemon run --detached` +\r\n  `daemon brain` processes spawned under the test's temp SPT_HOME by a child CLI's\r\n  `ensure_running`, still alive from an earlier run. **Reap BY IMAGE PATH** — the fleet's other\r\n  eleven spt processes run from the installed binary; a name-based sweep takes your own daemon.\r\n  The live shell-spawn population is eleven e2e files. Nine already end through product teardown\r\n  or their authenticated home-scoped reap. The two intentionally live-at-success siblings now\r\n  kill and prove the final resident gone AFTER all identity/wake assertions:\r\n  `shell_relink_force_e2e` and `shell_stale_online_e2e`.\r\n- **Kin:** [[IR-7]] (phase-A daemon+brain pair leak), the exe-lock reap-by-path rule, and the\r\n  wrong-lane-diagnostic family ([[IR-21]]'s location-not-build class).\r\n- **SECOND HOLDER CLASS, measured 2026-08-04 (doyle, own gate rig):** an **ORPHANED CONHOST with an\r\n  inherited CWD** inside the test tree blocks `git worktree remove` with Permission-denied on a\r\n  DIRECTORY handle — invisible to any exe-path scan (conhost runs from System32; the parent that\r\n  spawned it was already dead). Found via `.github/ci/find-cwd-holders.ps1` (IR-11's instrument);\r\n  killed by pid after parent-dead classification; 34.78 GB reclaimed. Mechanism chain: the\r\n  windowless spawn path masks DETACHED_PROCESS off, the child owns a console, conhost inherits the\r\n  child's cwd and can OUTLIVE it. Boundary (hertz's, correct): this find and his field-4 companion\r\n  are the SAME MECHANISM FAMILY measured on DIFFERENT populations by different instruments — his\r\n  capture measured a ppid-match COUNT (floor 2, companion identity UNMEASURED, his stated limit),\r\n  and this conhost is the first FIELD identity evidence in the family, on THIS population. Do not\r\n  cite his row as identity data it never carried. (His box-wide accretion count 77→80 is a third\r\n  population again.) Teardown rule\r\n  addendum: a disposal leg must GATE on the removal's exit code (a rig that logs \"reclaimed 0.01\r\n  GB\" from a failed remove fabricates its own success) and sweep CWD HOLDERS, not only image\r\n  locks — two populations, either alone is a clean zero on the other.\r\n- **Ripe when:** the test-hygiene lane (IR-13/IR-23/IR-36 family) — sweep every e2e that ends\r\n  with a live spawning binary, apply the same reap-after-assertions shape.\r\n- **Size:** small per test; population unknown until swept.\r\n- **Built evidence:** focused runs of both live-at-success tests pass back-to-back in one target\r\n  pool, followed by a build invocation from that same pool; the second test's final kill is polled\r\n  to proven process death rather than treated as fire-and-forget.\r\n\r\n### IR-39 — CLASS: the missing-fixture-bin defect has TWO failure faces, and one of them impersonates a lifecycle defect of the subject under test\r\n- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane. · **Origin:** hertz + todlando\r\n  2026-08-04, same evening from opposite sides (filed by doyle; hertz relayed todlando's\r\n  suggestion without endorsing scope).\r\n- **What/why:** a rig whose narrowed build (`-p <pkg> --test <one>` / `-p spt --bin spt`) skips a\r\n  cross-package fixture bin fails in one of two ways depending on the consuming site.\r\n  Face 1 (cheap): `translate_proof_fixture` panics \"must be built: <path>\" — names the artifact\r\n  and the recipe, costs one build. Face 2 (expensive): `sibling_bin(\"mock-session\")` resolves to a\r\n  nonexistent exe, nothing spawns, and the test reds at a PRECONDITION assert whose message\r\n  (\"warm bring-up spawned=false\", left None / right Some(\"offline\")) reads as a lifecycle defect\r\n  of the subject — measured cost 186s + a triage inside a lent box window (hertz's F1 red arm,\r\n  attempt 1). The build gap itself is the known cross-package row of the fixture-bin population;\r\n  what this entry carries is the DIAGNOSTIC asymmetry.\r\n- **Ask:** a fixture-bin existence precondition that NAMES the missing exe and its build recipe\r\n  wherever a rig consumes one — `sibling_bin` (and the shared\r\n  `crates/spt-term/tests/support/fixture_bin.rs` resolver already carries the recipe string as an\r\n  argument, the shape to copy) refuses with the artifact + recipe instead of letting the consuming\r\n  test fail downstream in its own vocabulary.\r\n- **Kin:** [[IR-21]] (wrong-lane-diagnostic family: the failure names the wrong actor), the\r\n  cargo-builds-package-bins-for-integration-tests rule (cross-package row is the only unguaranteed\r\n  build), golden.yml's dedicated fixture prebuild step.\r\n- **Ripe when:** the test-hygiene lane (IR-13/IR-23/IR-36/IR-38 family) — same sweep population;\r\n  or standalone small if that lane keeps slipping.\r\n- **Size:** small — one shared helper + a sweep of local `sibling_bin` resolver copies (24 known).\r\n- **Addendum (doyle, 2026-08-04 late): third and fourth sightings inside 24 h.** Face 1 twice\r\n  more the same evening — todlando's teach-lane leg set (his own translate_proof_fixture, caught\r\n  by his prebuild), and doyle's cold gate rig for the same lane (first-pass spt-bins red at\r\n  136/611, correctly withheld from the lane verdict as rig evidence, fixed by `cargo build -p spt\r\n  --bins` + rerun 611/611). Four sightings in one day across three agents and both faces: the\r\n  ripeness condition (\"the test-hygiene lane keeps slipping\") is under measurable pressure — the\r\n  prebuild remedy is being re-derived per-rig per-agent, which is the recurring cost the shared\r\n  precondition helper exists to delete.\r\n- **Built evidence:** all 29 file-local `sibling_bin` resolvers now route through one shared\r\n  precondition. A missing fixture names its path and the package-correct `cargo build -p <owner>\r\n  --bin <name>` recovery command before product assertions or timeout paths run; a focused\r\n  negative test pins that diagnostic.\r\n\r\n### IR-40 — CLASS: NO envelope-side ordering signal on a resume brief tracks content recency, and a CI informant's per-job line is a claim about that STEP, not the run\r\n- **Status:** open · **Origin:** three sightings in one night, 2026-08-04/05 — hertz, doyle,\r\n  todlando (filed by doyle; the artifacts are hertz's and todlando's, the CI arm is doyle's with\r\n  deployah's framing). Two arms of ONE family: a stale record that carries a confident ordering\r\n  signal, and a status claim that arrives before the thing it describes.\r\n\r\n- **ARM A — resume briefs. What/why:** a session can receive TWO start-of-session briefs, and the\r\n  one routed LATER can carry the STALER project-context. Measured on hertz's pair (same node id):\r\n  routed_at_ms `1785897407373` > `1785896642480`, spill-filename epoch `1785897764588` >\r\n  `1785896658159`, and vector sequence `1242529/1242531` > `1241542/1241544` — **all three\r\n  monotonic orderings rank the staler-content brief as newer.** todlando's pair is the NEGATIVE\r\n  arm: his later brief (`…1785897765196`, routed `…577476`, vector `1242756/7`) genuinely WAS the\r\n  fresher one, so the same heuristic happened to pick right.\r\n- **The finding is UNCORRELATED, not inverted** — and that is the whole entry. An inverted signal\r\n  is usable once you know to flip it; an uncorrelated one reads as reliable until the pair where it\r\n  costs you. Neither agent could have known which pair he held without checking content against\r\n  measurement. **Do not name routed_at_ms specifically** — naming the stamp invites the repair that\r\n  fails (\"the timestamp is unreliable, use the sequence number\"). The vector is the most dangerous\r\n  of the three: a stamp looks like a clock and invites suspicion, a sequence number looks like an\r\n  ordering and does not.\r\n- **Visible failure mode if a brief is obeyed as instructed** (hertz's, measured): re-open\r\n  `releases#123` — work already ruled closed — and under-report his own claimed-pool count by one,\r\n  the row sitting under a live gate. doyle's own sighting the same night: a brief describing main\r\n  @`92b2482` with a teach lane \"mid-flight\" hours after every lane had gated.\r\n- **PRE-REFUSED DISCRIMINATOR, recorded so it is not rediscovered as a finding:** file SIZE ranks\r\n  the fresher brief correctly on BOTH pairs (hertz 16308 > 12649; todlando 14138 > 10418) — 2 of 2,\r\n  the only signal surviving both samples. **Do not use it.** Size measures RICHNESS, not recency;\r\n  the two correlated only because todlando's thin brief was a correction fragment, and hertz's\r\n  STALER brief was a full 12649-byte dump. Two full dumps hours apart go flat or inverted. Handed\r\n  over pre-refused by its own finder.\r\n- **ARM B — CI informants (doyle, 2026-08-05, run 30971976024).** `CI-KITSUBITO` sent\r\n  \"CI SUCCESS … sha 0a25b77\" while the run was measurably `status=in_progress` with\r\n  `conclusion=\"\"` — the EMPTY STRING, not `success`. The informant fires from a per-job `notify`\r\n  step, and at send time `notify` itself had no conclusion. All eight substantive jobs were green,\r\n  so the line was **right in the end but EARLY**. deployah's framing, kept verbatim in kind: *an\r\n  informant line that is right in the end but early is worse than one that is simply wrong, because\r\n  a wrong signal gets distrusted while an early-but-correct one gets promoted to the conclusion.*\r\n  todlando's sentence is the one to keep at the point of use: **a per-job notify step's message is\r\n  a claim about that STEP, not about the RUN.**\r\n- **ARM B MECHANISM — hertz, source read 2026-08-05, zero box cost. It is NOT a race; it fires\r\n  early on EVERY run, and the entry above understated it.** `notify` is a job INSIDE the run\r\n  (`golden.yml:1138`), and a job cannot observe its own run's conclusion — so `conclusion: \"\"` is\r\n  not a timing artifact, it is **the only value that can exist when the informant speaks. The\r\n  informant has never once made a statement about a run conclusion.** What `ci-notify.sh` actually\r\n  asserts is narrower and worth naming exactly: a verdict computed PURELY from six `needs` results\r\n  (changes, traceability, test, n1-gate, twohost-a, twohost-b — the two matrices collapse to one\r\n  result each) being neither failure nor cancelled. Nothing more.\r\n  **The blind spot is exactly ONE job: `notify` itself, the 9th — it cannot appear in its own\r\n  `needs` list. And that one job has a WITNESSED red path**, documented in the script's own header\r\n  (2026-07-27, twice on kitsubito): verdict computed, then `spt send` HUNG ~5 minutes until the\r\n  job's own 5-minute budget cancelled it, and that cancellation reddened the run. So *\"informant\r\n  says SUCCESS, run concludes FAILURE\"* is a real observed sequence, not a hypothetical. The 30s\r\n  `SEND_BOUND_SECS` added since bounds the hang but does not close the class — it makes the\r\n  informant's own failure FAST rather than impossible.\r\n  ⇒ The informant's SUCCESS covers 8 of 9 jobs and is blind to the 9th, and the 9th is the only one\r\n  with an observed failure mode that reds the run. This is why the ff predicate is the run's\r\n  conclusion field and never the informant line.\r\n- **RECOVERY, and it is the same for both arms: never rank the claims — re-derive from the source\r\n  object.** For briefs, hertz's four falsifiers are the method (main sha, claimed-pool count, lane\r\n  tip, issue state) and they work because each is a content claim checkable in ONE command against\r\n  a source NEITHER brief controls. For CI, read the RUN's own `conclusion` field, and prefer\r\n  independent reads of the run object (`gh run watch --exit-status` polls the run, so its exit is a\r\n  second measurement rather than an echo of `notify`). On the batch this was caught in, three\r\n  sources agreed with the informant excluded from all three before main was fast-forwarded.\r\n- **Standing rule this entry exists to enforce:** a resume brief's RULINGS are durable; its STATE\r\n  is a HYPOTHESIS to re-derive before acting.\r\n- **Kin:** [[IR-21]] and [[IR-39]] (the diagnostic names the wrong actor / the wrong subject),\r\n  [[IR-32]] (a gate that cannot see its own blind spot), [[IR-34]] (an intermittent marker read as\r\n  a signal).\r\n- **Ripe when:** the next commune/psyche-tier touch for arm A (the routing layer is spt-core's own\r\n  `spool`/psyche ingest, so a remedy is in-repo, not upstream); for arm B, the next `golden.yml`\r\n  informant touch — the cheap fix is that the notify step names its own scope in the message body\r\n  (STEP vs RUN) rather than emitting a bare \"CI SUCCESS\".\r\n- **Size:** arm B small (message text + scope word in one workflow step). Arm A unsized —\r\n  establishing whether ANY durable content-recency signal can ride the envelope is the measurement,\r\n  and until it runs the answer is \"re-derive, do not rank.\"\r\n\r\n### IR-41 — A QUEUED main run is superseded without a record; `cancel-in-progress: false` protects only STARTED runs\r\n- **Status:** open — mechanism CONFIRMED (doyle ruling 2026-08-05); the runbook sentence it\r\n  falsified is already corrected (`docs/RELEASE-RUNBOOK.md` step 3, same commit as this entry)\r\n  · **Origin:** deployah, v0.55.0 publish night, filed by him explicitly as UNPROVEN with the\r\n  manual-cancel alternative not ruled out; confirmed by doyle on the run objects.\r\n- **What/why:** `ci.yml` sets `cancel-in-progress: false` on main and the runbook read that as\r\n  \"main's concurrency policy never cancels this run; that preserves the record.\" FALSE for the\r\n  queued phase: a concurrency group holds at most one running + one pending run, and a newer push\r\n  REPLACES the pending run regardless of the flag — the flag governs only whether a STARTED run\r\n  is cancelled. A superseded queued run leaves NO record: zero jobs, conclusion `cancelled`,\r\n  nothing measured about its sha.\r\n- **Evidence (all read off the run objects, not the informant):** run 30973909279 at `327f1f8`\r\n  (push, main) — created 04:01:08Z, **zero jobs ever started**, cancelled 04:03:49Z, ONE SECOND\r\n  after `e8805f7`'s run 30974041521 entered the group (created 04:03:48Z), while `0a25b77`'s run\r\n  30973770039 was still in flight (done 04:07:59Z). One-running-one-pending, newer push landed,\r\n  pending run died. The 1s coupling to an unrelated push is the discriminator against deployah's\r\n  own manual-cancel alternative — a human cancel co-timed to the second with a push it had no\r\n  view of is not a credible mechanism; supersession fires on exactly that trigger by design.\r\n- **The hole this leaves:** under a rapid push sequence, an intermediate sha on MAIN can have no\r\n  thin-CI verdict AT ALL, and the absence reads as nothing rather than as supersession. Anyone\r\n  auditing \"did sha X pass main CI\" gets a hole where the runbook promised a record. Absence of\r\n  a run is now a labelled state, not evidence about the sha.\r\n- **Ripe when:** next ci.yml/runbook touch. Candidate remedies to weigh THEN, not now: accept and\r\n  document (done — the runbook now carries the mechanism), or give main's group per-sha keys\r\n  (`group: ci-${{ github.sha }}`) so runs never share a group — at the cost of concurrent main\r\n  runs competing for the boxes, which is exactly what the group exists to prevent. The trade is\r\n  real; do not fold it into a drive-by.\r\n- **Size:** docs half DONE in this commit; ci.yml half small but load-bearing — needs its own\r\n  lane if taken.\r\n- **Kin:** [[IR-40]] (a record that is right-in-the-end-but-early vs a record that never comes to\r\n  exist — both read as clean states unless labelled), [[cancelled-measurement-leaves-labelled-hole]].\r\n\r\n### IR-42 — `pool-claim` writes a record; only the BUILD enforces — and AGENTS.md invited the misread\r\n- **Status:** BUILT 2026-08-19 — the AGENTS.md corrective line lands in the SAME COMMIT as this\r\n  entry (the register batch commit), which is the entry's stated exit condition. The optional\r\n  code-side nicety (claim verb prints the incumbent record it overwrites, information only)\r\n  remains unclaimed — a candidate rider on the IR-26 remedy lane, which already touches\r\n  `pool_claim`'s read-before-write path, NOT a reason to keep this entry open ·\r\n  **Origin:** doyle + todlando independently at source, 2026-08-19, during the #193 gate.\r\n- **Mechanism (source-verified):** `xtask pool-claim` (crates/xtask/src/main.rs:2232-2294 at the\r\n  read sha) parses its args, reads the lane's own git identity, builds a `PoolOwner` and calls\r\n  `spt_poolguard::write_owner` UNCONDITIONALLY (:2280) — no `read_owner`, no verdict, no\r\n  comparison against the incumbent claim anywhere in the function. Claiming is last-writer-wins\r\n  by construction: two lanes can each \"hold\" a pool in sequence with only the last write\r\n  surviving, and the displaced lane learns nothing at displacement time. All four enforcement\r\n  arms — `Refuse` (SPT_POOL_FOREIGN), `Takeover` (loud), `Unproven`, `HatchOpen` — live in\r\n  crates/spt-store/build.rs:31-113 and speak only at the next BUILD. (Same object [[IR-26]]'s\r\n  CLAIM-OBSERVABILITY measurement saw from the displaced side; this entry is the CLAIMING side\r\n  plus the doc that invited the misread.)\r\n- **Measured consequence:** 2026-08-19, doyle's gate claim over todlando's unlanded\r\n  redeem-echo-diag claim — no refusal, no notice (three sequential overwrites that session, one\r\n  over a lane with an unlanded commit). todlando then predicted from AGENTS.md's refusal\r\n  sentence that the gate's claim \"will be REFUSED\" — a false warning to a gater mid-run. The\r\n  refusal sentence sat directly under the \"Claim a pool at lane start\" instruction, inviting the\r\n  build-time semantics to be read onto the claim verb.\r\n- **Corrective landed:** the claim WRITES a record without adjudicating the incumbent lane;\r\n  predict **lane-identity** refusals from builds, never from `pool-claim`. The broader original\r\n  \"never refuses\" wording is superseded by IR-56's **addressing** guard (wrong-tree claims need\r\n  explicit `--foreign-pool`); that guard does not add incumbent-lane adjudication.\r\n\r\n### IR-43 — knock answer carrier: `NoReply` landed at 60.08s against a stated 30s carrier deadline\r\n- **Status:** open, OBSERVATION — mechanism unmeasured, filed exactly as wide as the datum ·\r\n  **Origin:** KNOCK-169 RCA layer 1 (todlando, read-only), golden 32191618042 @`93c1130`,\r\n  twohost-b, 2026-08-18.\r\n- **What/why:** B's `request_answer` yielded `NoReply` at 22:50:08.3605Z — 60.08s after A's\r\n  death — while the carrier deadline is stated at 30s. Recorded in the RCA as a side observation\r\n  with no claim; the cell's red itself was a CASCADE of A's earlier death (answerop.rs:73-81\r\n  produces the courtesy BEFORE returning, so the reply was never sent — that half is settled and\r\n  is NOT this entry). What this entry carries: a transport/liveness bound that reported at 2x its\r\n  stated value. Candidate shapes, neither asserted: two sequential 30s legs each honoring its own\r\n  bound (a composed wait wearing one bound's name), or a bound armed after a wait it does not\r\n  cover (the [[IR-30]] nethost.rs permit-wait shape: `sem.acquire_owned()` outside the timeout).\r\n- **Ask:** derive where the 30s is armed and what path yields a 60s `NoReply` — one code read\r\n  from the emit site, before any instrument.\r\n- **Ripe when:** next knock-carrier touch, or the next `NoReply`-shaped red — whichever first.\r\n- **Size:** small (code read; a token only if the read forks).\r\n\r\n### IR-44 — perch-sentinel comment overclaims: serialization is not preservation, and the comment teaches the false step\r\n- **Status:** open · **Origin:** #188 RCA lock read (todlando flagged, doyle confirmed the lock\r\n  read), 2026-08-18; the collapse-of-branches argument is on #188 and in the RCA record.\r\n- **What/why:** `lock_perch_sentinel` (info.rs:778 at `b20e770`, the diag sha — re-derive the\r\n  line on main before editing) takes a cross-process fs2 lock on a stable per-perch `.info.lock`\r\n  sentinel, and its comment claims it serializes \"ALL info.json writers so a whole-record write\r\n  and a locked RMW can never lose each other's update (`REQ-HAZARD-INFO-RMW-LOST-UPDATE`)\" —\r\n  TRUE for interleaving, FALSE for preservation. `write_info_unlocked` is module-private with\r\n  exactly three callers, all taking the sentinel first (bypass refuted by visibility), but every\r\n  caller of the public `write_info` composes its record BEFORE the lock is taken (:842) — **the\r\n  lock makes that write atomic; it cannot make it preserving.** Only `mutate_info` /\r\n  `establish_locked` read under the hold and can preserve. Measured field case: census write #1\r\n  (`twohost.rs:736`) clobbered `controlled` while correctly locked. A reader trusting the\r\n  comment infers lost-update immunity the funnel does not provide — the #188 hunt burned a\r\n  branch on exactly that inference before the collapse argument killed it.\r\n- **Ask:** respell the comment — serializes writers; a composed `write_info` is atomic, never\r\n  preserving; preservation requires `mutate_info`/`establish_locked` — and weigh whether\r\n  `REQ-HAZARD-INFO-RMW-LOST-UPDATE`'s doc wording carries the same overclaim.\r\n- **Ripe when:** next spt-store/info.rs touch. **Size:** tiny (comment + possibly one REQ doc\r\n  line).\r\n\r\n### IR-45 — twohost rig home premise, SETTLED: pump paths resolve under the per-run TEMP root (rig is disk-hermetic; the \"live fleet roster\" reading is retired)\r\n- **Status:** RETIRED 2026-08-19 — ask answered by the one code read at main @`78a9a16`; residue\r\n  re-homed (see Answer). · **Origin:** #188/#189 RCA readouts (todlando, doyle's 2a-2d), runs\r\n  32097943571 + 32108557362 + 32111921251, 2026-08-18.\r\n- **What/why, two measured halves in tension:** (1) B's pump dialed a THIRD node 155-159 times\r\n  per run at kitsubito's OWN tailscale IP (`100.98.197.12`), different hex + different ephemeral\r\n  port each run — a short-lived local endpoint re-minting identity between runs, present in both\r\n  the golden and the diag run. Read at the time as: the rig uses the CANONICAL home\r\n  (`canonical_pump_paths` → `perch::spt_home()`), so B's roster is kitsubito's live fleet\r\n  roster — environmental coupling of a CI rig to host fleet state. (2) The ER perch measured in\r\n  the chain runs resolves under a per-run TEMP root\r\n  (`…/_temp/spt-test-tmp-<run>…/owlery/engine-room`), NOT the canonical home. Both measurements\r\n  stand; they answer different artifacts (pump roster vs perches), and nothing on record settles\r\n  which home the PUMP paths actually resolve. #189's third-node evidence and its\r\n  cache-leg-never-heals reading rest on that premise (the tension is filed on the #188 record as\r\n  an open question against #189).\r\n- **Answer (2026-08-19, code read at `78a9a16`, unambiguous — no run token needed):** both role\r\n  tests set `SPT_HOME` to a fresh per-run `TempDir` as their FIRST act (`twohost.rs:813-814` role\r\n  B, `:1501-1502` role A), before any store touch. `canonical_pump_paths` resolves every path via\r\n  `perch::spt_home()` (`twohost.rs:396-414`), which honors the `SPT_HOME` override first\r\n  (`perch.rs:34-41`); the pump's roster source `presence::registry_snapshot_dir()` →\r\n  `perch::identity_dir()` sits under the same root (`presence.rs:83-85`). The rig is\r\n  DISK-HERMETIC per run; both prior measurements reconcile (ER perch observed under the temp\r\n  root, pump paths resolve there too). The misleader was the helper's name + doc comment (\"real\r\n  homes, not test roots\"), which describe production path LAYOUT, not the resolved ROOT.\r\n- **Residue disposition:** (1) #189's third-node evidence was corrected on the board (comment\r\n  5337519936) — the roster row arrived at RUNTIME into a temp-rooted store, ingress mechanism\r\n  OPEN on #189, no longer explained-environmental. (2) KEYSTONE #182's hygiene lane repaired the\r\n  `twohost.rs:394` comment to say exactly what the helper does: production path layout rooted in\r\n  the process's fresh per-run `SPT_HOME`.\r\n\r\n### IR-46 — the Windows disk-floor preflight asserts an INSTANT; workspace free space moves tens of GB inside the hour, so a green floor is not a claim about run headroom\r\n- **Status:** open — mechanism CONFIRMED by a measurement series on hfenduleam; doyle ruled it\r\n  register-shaped 2026-08-18 · **Origin:** deployah, NAMEPLATE #181 golden-head intake, on the\r\n…\n  version of it.\n…\n\n…\n","startLine":1633,"lineNumbers":[1633,1634,null,1793,null,1805,1806,1807,1808,1809,1810,1811,1812,1813,1814,1815,1816,1817,1818,1819,1820,1821,1822,1823,1824,1825,1826,1827,1828,1829,1830,1831,1832,1833,1834,1835,1836,1837,1838,1839,1840,1841,1842,1843,1844,1845,1846,1847,1848,1849,1850,1851,1852,1853,1854,1855,1856,1857,1858,1859,1860,1861,1862,1863,1864,1865,1866,1867,1868,1869,1870,1871,1872,1873,1874,1875,1876,1877,1878,1879,1880,1881,1882,1883,1884,1885,1886,1887,1888,1889,1890,1891,1892,1893,1894,1895,1896,1897,1898,1899,1900,1901,1902,1903,1904,1905,1906,1907,1908,1909,1910,1911,1912,1913,1914,1915,1916,1917,1918,1919,1920,1921,1922,1923,1924,1925,1926,1927,1928,1929,1930,1931,1932,1933,1934,1935,1936,1937,1938,1939,1940,1941,1942,1943,1944,1945,1946,1947,1948,1949,1950,1951,1952,1953,1954,1955,1956,1957,1958,1959,1960,1961,1962,1963,1964,1965,1966,1967,1968,1969,1970,1971,1972,1973,1974,1975,1976,1977,1978,1979,1980,1981,1982,1983,1984,1985,1986,1987,1988,1989,1990,1991,1992,1993,1994,1995,1996,1997,1998,1999,2000,2001,2002,2003,2004,2005,2006,2007,2008,2009,2010,2011,2012,2013,2014,2015,2016,2017,2018,2019,2020,2021,2022,2023,2024,2025,2026,2027,2028,2029,2030,2031,2032,2033,2034,2035,2036,2037,2038,2039,2040,2041,2042,2043,2044,2045,2046,2047,2048,2049,2050,2051,2052,2053,2054,2055,2056,2057,2058,2059,2060,2061,2062,2063,2064,2065,2066,2067,2068,2069,2070,2071,2072,2073,2074,2075,2076,2077,2078,2079,2080,2081,2082,2083,2084,2085,2086,2087,2088,2089,2090,2091,2092,2093,2094,2095,2096,2097,2098,2099,2100,2101,2102,2103,2104,2105,2106,2107,2108,2109,2110,2111,2112,2113,2114,2115,2116,2117,2118,2119,2120,2121,2122,2123,2124,2125,2126,2127,2128,2129,2130,2131,2132,2133,2134,2135,2136,2137,2138,2139,2140,2141,2142,2143,2144,2145,2146,2147,2148,2149,2150,2151,2152,2153,2154,2155,2156,2157,2158,2159,2160,2161,2162,2163,2164,2165,2166,2167,2168,2169,2170,2171,2172,2173,2174,2175,2176,2177,2178,2179,2180,2181,2182,2183,2184,2185,2186,2187,2188,2189,2190,2191,2192,2193,2194,2195,2196,2197,2198,2199,2200,2201,2202,2203,2204,2205,2206,2207,2208,2209,2210,2211,2212,2213,2214,2215,2216,2217,2218,2219,2220,2221,2222,2223,2224,2225,2226,2227,2228,2229,2230,2231,2232,2233,2234,2235,2236,2237,2238,2239,2240,2241,2242,2243,2244,2245,2246,2247,2248,2249,2250,2251,2252,2253,2254,2255,2256,2257,2258,2259,2260,2261,2262,2263,2264,2265,2266,2267,2268,2269,2270,2271,2272,2273,2274,2275,2276,2277,2278,2279,2280,2281,2282,2283,2284,2285,2286,2287,2288,2289,2290,2291,2292,2293,2294,2295,2296,2297,2298,2299,2300,2301,2302,2303,2304,2305,2306,2307,2308,2309,2310,2311,2312,2313,2314,2315,2316,2317,2318,2319,2320,2321,2322,2323,2324,2325,2326,2327,2328,2329,2330,2331,2332,2333,2334,2335,2336,2337,2338,2339,2340,2341,2342,2343,2344,2345,2346,2347,2348,2349,2350,2351,2352,2353,2354,2355,2356,2357,2358,2359,2360,2361,2362,2363,2364,2365,2366,2367,2368,2369,2370,2371,2372,2373,2374,2375,2376,2377,2378,2379,2380,2381,2382,2383,2384,2385,2386,2387,2388,2389,2390,2391,2392,2393,2394,2395,2396,2397,2398,2399,2400,2401,2402,2403,2404,2405,2406,2407,2408,2409,2410,2411,2412,2413,2414,2415,2416,2417,2418,2419,2420,2421,2422,2423,2424,2425,2426,2427,2428,2429,2430,2431,2432,2433,2434,2435,2436,2437,2438,2439,2440,2441,2442,2443,2444,2445,2446,2447,2448,2449,2450,2451,2452,2453,2454,2455,2456,2457,2458,2459,2460,2461,2462,2463,2464,2465,2466,2467,2468,2469,2470,2471,2472,2473,2474,2475,2476,2477,2478,2479,2480,2481,2482,2483,2484,2485,2486,2487,2488,2489,2490,2491,2492,2493,2494,2495,2496,2497,2498,2499,2500,2501,2502,2503,2504,2505,2506,2507,2508,2509,2510,2511,2512,2513,2514,2515,2516,2517,2518,2519,2520,2521,2522,2523,2524,2525,2526,2527,2528,2529,2530,2531,2532,2533,2534,2535,2536,2537,2538,2539,2540,2541,2542,2543,2544,2545,2546,2547,2548,2549,2550,2551,2552,2553,2554,2555,2556,2557,2558,2559,2560,2561,2562,2563,2564,2565,2566,2567,2568,2569,2570,2571,2572,2573,2574,2575,2576,2577,2578,2579,2580,2581,2582,2583,2584,2585,2586,2587,2588,2589,2590,2591,2592,2593,2594,2595,2596,2597,2598,2599,2600,2601,2602,2603,2604,2605,2606,2607,2608,2609,2610,2611,2612,2613,2614,2615,2616,2617,2618,2619,2620,2621,2622,2623,2624,2625,2626,2627,2628,2629,2630,2631,2632,2633,2634,2635,2636,2637,2638,2639,2640,2641,2642,2643,2644,2645,2646,2647,2648,2649,2650,2651,2652,2653,2654,2655,2656,2657,2658,2659,2660,2661,2662,2663,2664,2665,2666,2667,2668,2669,2670,2671,2672,2673,2674,2675,2676,2677,2678,2679,2680,2681,2682,2683,2684,2685,2686,2687,2688,2689,2690,2691,2692,2693,2694,2695,2696,2697,2698,2699,2700,2701,2702,2703,2704,2705,2706,2707,2708,2709,null,2714,null,2763,null,2773]},"fileSize":676479,"meta":{"source":{"type":"path","value":"C:\\Users\\decid\\Documents\\projects\\spt-core\\.worktrees\\hertz-ir86-disk-delta\\docs\\INFRA-REGISTER.md"},"truncation":{"direction":"middle","truncatedBy":"middle","totalLines":916,"totalBytes":80940,"outputLines":466,"outputBytes":40922,"maxBytes":40960,"headRange":{"start":1,"end":225},"tailRange":{"start":677,"end":916},"elidedLines":451,"elidedBytes":40040,"artifactId":"730","nextOffset":2710}}},"isError":false,"timestamp":1789483662458}}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_M6nsOLkFuBapCxRPGQVNhf0v|fc_043a862a419f59ae016aa95a997a3c87d2bb61e8b686127680","toolName":"read","startedAt":"2026-09-15T14:47:53.552Z","args":{"path":".worktrees/hertz-ir86-disk-delta/docs/INFRA-REGISTER.md:240-450:raw"},"intent":"Recovering early register body"},"id":"e9162895","parentId":"ea39bce9","timestamp":"2026-09-15T14:47:53.552Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_yHXiGhAv8uX9BSXXRxkO8aTS|fc_043a862a419f59ae016aa95a997a4887d292e9456180f2d6d0","toolName":"read","startedAt":"2026-09-15T14:47:53.552Z","args":{"path":".worktrees/hertz-ir86-disk-delta/docs/INFRA-REGISTER.md:451-652:raw"},"intent":"Recovering early entry details"},"id":"465d4d6e","parentId":"e9162895","timestamp":"2026-09-15T14:47:53.552Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_x9ZED10mq4LwyCNlkpTdxb16|fc_043a862a419f59ae016aa95a997a5087d2b3a70c1bf92d893a","toolName":"read","startedAt":"2026-09-15T14:47:53.552Z","args":{"path":".worktrees/hertz-ir86-disk-delta/docs/INFRA-REGISTER.md:1080-1302:raw"},"intent":"Recovering teardown amendments"},"id":"a256e31f","parentId":"465d4d6e","timestamp":"2026-09-15T14:47:53.552Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_HyytcgDUHPCUuR4Z7aXGIIrK|fc_043a862a419f59ae016aa95a997a5487d29763e157cbac0748","toolName":"read","startedAt":"2026-09-15T14:47:53.553Z","args":{"path":".worktrees/hertz-ir86-disk-delta/docs/INFRA-REGISTER.md:1303-1585:raw"},"intent":"Recovering fixture mechanism census"},"id":"b0384513","parentId":"a256e31f","timestamp":"2026-09-15T14:47:53.553Z"}
{"type":"message","id":"cb612027","parentId":"b0384513","timestamp":"2026-09-15T14:47:53.553Z","message":{"role":"assistant","content":[{"type":"thinking","thinking":"**Preparing raw selectors**"},{"type":"toolCall","id":"call_M6nsOLkFuBapCxRPGQVNhf0v|fc_043a862a419f59ae016aa95a997a3c87d2bb61e8b686127680","name":"read","arguments":{"i":"Recovering early register body","path":".worktrees/hertz-ir86-disk-delta/docs/INFRA-REGISTER.md:240-450:raw"},"intent":"Recovering early register body"},{"type":"toolCall","id":"call_yHXiGhAv8uX9BSXXRxkO8aTS|fc_043a862a419f59ae016aa95a997a4887d292e9456180f2d6d0","name":"read","arguments":{"i":"Recovering early entry details","path":".worktrees/hertz-ir86-disk-delta/docs/INFRA-REGISTER.md:451-652:raw"},"intent":"Recovering early entry details"},{"type":"toolCall","id":"call_x9ZED10mq4LwyCNlkpTdxb16|fc_043a862a419f59ae016aa95a997a5087d2b3a70c1bf92d893a","name":"read","arguments":{"i":"Recovering teardown amendments","path":".worktrees/hertz-ir86-disk-delta/docs/INFRA-REGISTER.md:1080-1302:raw"},"intent":"Recovering teardown amendments"},{"type":"toolCall","id":"call_HyytcgDUHPCUuR4Z7aXGIIrK|fc_043a862a419f59ae016aa95a997a5487d29763e157cbac0748","name":"read","arguments":{"i":"Recovering fixture mechanism census","path":".worktrees/hertz-ir86-disk-delta/docs/INFRA-REGISTER.md:1303-1585:raw"},"intent":"Recovering fixture mechanism census"},{"type":"toolCall","id":"call_95qxfo6DVA4e8owaQvY2aZhI|fc_043a862a419f59ae016aa95a997a5c87d2b1c0b8285463a7f4","name":"read","arguments":{"i":"Recovering headingless capacity entry","path":".worktrees/hertz-ir86-disk-delta/docs/INFRA-REGISTER.md:2030-2264:raw"},"intent":"Recovering headingless capacity entry"},{"type":"toolCall","id":"call_ODgsGyoCktGuEGTJk1Vexe3k|fc_043a862a419f59ae016aa95a997a6087d2bf6782262dbc4273","name":"read","arguments":{"i":"Recovering parser and upstream entries","path":".worktrees/hertz-ir86-disk-delta/docs/INFRA-REGISTER.md:2265-2488:raw"},"intent":"Recovering parser and upstream entries"}],"api":"openai-codex-responses","provider":"openai-codex","model":"gpt-6-astra","usage":{"input":43341,"output":308,"cacheRead":25472,"cacheWrite":0,"totalTokens":69121,"reasoningTokens":13,"cost":{"input":0.43341,"output":0.0154,"cacheRead":0.025471999999999998,"cacheWrite":0,"total":0.47428200000000004}},"stopReason":"toolUse","timestamp":1789483662493,"responseId":"resp_043a862a419f59ae016aa95a8ec17087d2baa46f15ec6ddde9","providerPayload":{"type":"openaiResponsesHistory","provider":"openai-codex","dt":true,"items":[{"id":"rs_043a862a419f59ae016aa95a902dbc87d2827feab4c1564466","type":"reasoning","content":[],"encrypted_content":"gAAAAABqqVqZ_Vky4EqdkBLKKA8at9mvdeWBJ1GcTQ_SLdRMVIE38S6qyOyLwnWfdpQDJEbvuCA58bMCqcpeM8ZV4TSOs38YSLvvBrc6ZOooreWQDS7ZxeoE3HBV-GSqPgmZ_zS7w3029SsYHHtEGjSWqMJP-STsjBXBrJqaOLEDZp6jy73vKVVei3wYGbjFJVXESorkRFgha4OV7bXq1paXUZhWaqs88F9rLi1xl8TaYj35mf4MvIDiEs38m8TfG0SBTVh62CyGr3O3Vfom6uEg_lyvVYnmKJNnOgPJi2UDn8rN9wLGKrYikgQlNe5DdlN4eFY3iIvPRT_cxSrz1jdjfTjOw5kY1SPP6Fhq1ETZ9mHAWsmQ1MCLFAmW_6_3xdKm93LE7eQR9YrrKuFMm_oZCtTyYQsgBJ8E8EI72u2YjV5WXQz5E1Q7Xu_6RmrBRFDxQiqijRjNHrEtJi_kfbip1QDPi_KddRXmNBqGNE39jQO8IGdvpQWxI1qZ6_w7pxSkkhm5mzrwfbBY0K0D9w8CR5JlWDJ16hTOjAaV8_-6GpM14YwkN5G8I34gBYD11BE7hzm8msAIiK65eEaLKiuHvdyca9xMCefzzcy_-UEpGZUlFRydZfFjgeiVe0Ozl3X2FphBRPHWF2R3aL6N-VZOS8ivq3y3naL2OTsRnlqwZm7pa8RXJWsPXoYiCtAphLzpPMPUTPFtN5FmO7gdUEk3igrxf6e27De5_sodtAKD05Zd78Me99JI6y5S_d4NQ_XslUvOp0KHXsBKYfJaxH6vZMOyJGSOVqcTyg4w9MNVwEUn9ILqdf-2r0dNCaP8NE9Vyl6UEPg8QqYJd7GZE2wT5XwQbnwAz35DqqH2v_0Nc2ZtNfESCIfST57Ro2H2uMg4Skv3HakKJ6tN7lhGrYddmSe1IUjPQtsleVstHTRMSltgbvelwqxVTGqM_iRtmb-OQCSWTxQDL3jUTk5Tb_wSZQcYwW0_kpeE7zfrxq6TFAsjZNSd2Qa4iE1vzXZSpbO4tLUBQqSzRxi7OkSIiHiDwhqaDlRv6ksvmjwpbdg69XdxIprM9t8AGKC1ocdxqo96GOnImy_6AtjX9q4uc6PhryFrVG65Glx2xiDvnkf4SzGR3DDdn9Uw_tS28wCYG040ggzID0lCStHqld6cDnmBDpug2A9_cAfksOV8Zyhc-N5F1J0L0qwgvCLfGhK8F52iqaunjOhgBmXEFXhG-aRJovNSdPk0HhNKJ1mqhefXtxRGT2PmdposlOmQ8MwaEBTSzMRwCxUmFFI6QEkqF9RNwUkAjXLh_zxPpcvsyP6q9IIq75O4wqmMXTkiGUV-3-h3SwIAbzi-MsQhNdEzvTMDTjzOaxrr8g==","internal_chat_message_metadata_passthrough":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"},"summary":[{"type":"summary_text","text":"**Preparing raw selectors**"}],"metadata":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"}},{"id":"fc_043a862a419f59ae016aa95a997a3c87d2bb61e8b686127680","type":"function_call","status":"completed","arguments":"{\"i\":\"Recovering early register body\",\"path\":\".worktrees/hertz-ir86-disk-delta/docs/INFRA-REGISTER.md:240-450:raw\"}","call_id":"call_M6nsOLkFuBapCxRPGQVNhf0v","internal_chat_message_metadata_passthrough":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"},"name":"read","metadata":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"}},{"id":"fc_043a862a419f59ae016aa95a997a4887d292e9456180f2d6d0","type":"function_call","status":"completed","arguments":"{\"i\":\"Recovering early entry details\",\"path\":\".worktrees/hertz-ir86-disk-delta/docs/INFRA-REGISTER.md:451-652:raw\"}","call_id":"call_yHXiGhAv8uX9BSXXRxkO8aTS","internal_chat_message_metadata_passthrough":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"},"name":"read","metadata":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"}},{"id":"fc_043a862a419f59ae016aa95a997a5087d2b3a70c1bf92d893a","type":"function_call","status":"completed","arguments":"{\"i\":\"Recovering teardown amendments\",\"path\":\".worktrees/hertz-ir86-disk-delta/docs/INFRA-REGISTER.md:1080-1302:raw\"}","call_id":"call_x9ZED10mq4LwyCNlkpTdxb16","internal_chat_message_metadata_passthrough":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"},"name":"read","metadata":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"}},{"id":"fc_043a862a419f59ae016aa95a997a5487d29763e157cbac0748","type":"function_call","status":"completed","arguments":"{\"i\":\"Recovering fixture mechanism census\",\"path\":\".worktrees/hertz-ir86-disk-delta/docs/INFRA-REGISTER.md:1303-1585:raw\"}","call_id":"call_HyytcgDUHPCUuR4Z7aXGIIrK","internal_chat_message_metadata_passthrough":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"},"name":"read","metadata":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"}},{"id":"fc_043a862a419f59ae016aa95a997a5c87d2b1c0b8285463a7f4","type":"function_call","status":"completed","arguments":"{\"i\":\"Recovering headingless capacity entry\",\"path\":\".worktrees/hertz-ir86-disk-delta/docs/INFRA-REGISTER.md:2030-2264:raw\"}","call_id":"call_95qxfo6DVA4e8owaQvY2aZhI","internal_chat_message_metadata_passthrough":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"},"name":"read","metadata":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"}},{"id":"fc_043a862a419f59ae016aa95a997a6087d2bf6782262dbc4273","type":"function_call","status":"completed","arguments":"{\"i\":\"Recovering parser and upstream entries\",\"path\":\".worktrees/hertz-ir86-disk-delta/docs/INFRA-REGISTER.md:2265-2488:raw\"}","call_id":"call_ODgsGyoCktGuEGTJk1Vexe3k","internal_chat_message_metadata_passthrough":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"},"name":"read","metadata":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"}}]},"duration":11057.616599977016,"ttft":1744.8708999752998,"completedAt":1789483673551,"contextSnapshot":{"promptTokens":68813,"nonMessageTokens":10342,"compactionEpoch":0}}}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_95qxfo6DVA4e8owaQvY2aZhI|fc_043a862a419f59ae016aa95a997a5c87d2b1c0b8285463a7f4","toolName":"read","startedAt":"2026-09-15T14:47:53.553Z","args":{"path":".worktrees/hertz-ir86-disk-delta/docs/INFRA-REGISTER.md:2030-2264:raw"},"intent":"Recovering headingless capacity entry"},"id":"6015f09a","parentId":"cb612027","timestamp":"2026-09-15T14:47:53.553Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_ODgsGyoCktGuEGTJk1Vexe3k|fc_043a862a419f59ae016aa95a997a6087d2bf6782262dbc4273","toolName":"read","startedAt":"2026-09-15T14:47:53.553Z","args":{"path":".worktrees/hertz-ir86-disk-delta/docs/INFRA-REGISTER.md:2265-2488:raw"},"intent":"Recovering parser and upstream entries"},"id":"6fc091f2","parentId":"6015f09a","timestamp":"2026-09-15T14:47:53.553Z"}
{"type":"message","id":"b704c0bc","parentId":"6fc091f2","timestamp":"2026-09-15T14:47:53.569Z","message":{"role":"toolResult","toolCallId":"call_yHXiGhAv8uX9BSXXRxkO8aTS|fc_043a862a419f59ae016aa95a997a4887d292e9456180f2d6d0","toolName":"read","content":[{"type":"text","text":"  the skew is a mechanism and the fix must be one too. (2) declare-one-leg REJECTED as the\n  terminal state — it repairs lint authority but leaves the legs resolving with different cargo\n  versions, and the acaaa4f lock-attribution question this family started from is a resolver\n  question. (3) **PIN IN-REPO: `rust-toolchain.toml`, `channel = \"1.96.0\"`** — both runner\n  accounts already resolve their toolchain through rustup (witnessed by the `active=` line), so\n  the pin self-applies with zero per-box maintenance, and the judge's version becomes a property\n  of the TESTED SHA — the same object golden CI already guarantees. Bumps become reviewed lane\n  commits, tested by the golden run they ride; the hfenduleam leg proves 1.96.0 on the pin\n  lane's own run. (4) INTERIM until the pin lands: kitsubito's clippy leg is AUTHORITATIVE for\n  lint disputes — not because newer is stricter (skew direction stays unasserted) but because\n  1.96 is the version the pin names, so interim and terminal rulings agree.\n  · **Origin:** BAROMETER (ex releases#121); re-confirmed on the #125 fix lane\n  (builder's Windows clippy vs kitsubito's rust-1.96.0 lints); see [[CI-RIDER LANE STATE]]\n- **What/why:** a Windows-clean lane can land a lint that only reds on the Linux leg — toolchain\n  skew makes local clippy evidence non-transferable. Align versions or declare the authoritative\n  leg. Natural companion to IR-4's toolchain-version print step.\n- **Built evidence / fulfilment check:** `rust-toolchain.toml` contains\n  `channel = \"1.96.0\"` and rode the tested cut. A source sweep at close found no CI or pool\n  machinery keyed to a box-default toolchain **path**: golden invokes `cargo`, `rustc`, `clippy`,\n  and `rustup show active-toolchain` through PATH; pool ownership keys on source-tree/lane identity,\n  not rustup installation paths. `release.yml`'s `$HOME/.cargo/bin/mdbook` is an installed tool\n  location, not a Rust toolchain selector; its builds still invoke PATH-resolved `cargo`.\n- **Size:** built.\n- **Composed:** LOCKSMITH (#132) CI-rider cluster (rides IR-4's toolchain-version print step) —\n  2026-08-03. GREENLIT with #132 and **DISPATCHED to hertz 2026-08-03**; that dispatch delivered\n  the measurement half (landed via [[CI-RIDER LANE STATE]], first exercised on run 30971976024).\n\n### IR-10 — Wave gate runs the CONSUMERS of any predicate it changes\n- **Status:** open · **Origin:** BAROMETER gate craft (ex releases#119)\n- **What/why:** legs chosen from changed crates miss the predicate's callers; a composed red is\n  triaged at the wave's own tip first. This is the gate-population rule made binding in the gate\n  runbook + scripts rather than living in memory.\n- **Ripe when:** next gate-runbook/docs wave.\n- **Size:** small (docs + gate-script checklist).\n\n### IR-11 — find-cwd-holders.ps1: --headless discriminator as a column\n- **Status:** open · **Origin:** worktree-pin triage tooling (ex releases#118)\n- **What/why:** the holder-triage script buries the headless-vs-interactive discriminator in prose;\n  as a column it makes the orphan-vs-own-shell call one glance.\n- **Ripe when:** any rig-tooling wave; trivial rider.\n- **Size:** tiny.\n\n### IR-12 — xtask contract-drift gate misses a stale manifest.schema.json\n- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane (the narrowed blind arm only). · **Origin:** ex\n  releases#116\n- **KIN NOTE RETIRED (2026-09-06, hertz; doyle measure-first ruling):** the stale-binary\n  premise was a rig artifact, not a reproduced product hole. At `9f809f8d`, in isolated Linux\n  worktree `hertz-ir12-mutation`, build `spt` once, mutate only its root CLI help string, do not\n  rebuild, then run `cargo run -p xtask -- check` alone: **exit 1**, combined output **3435 bytes**,\n  ending `xtask check: docs-site/src/cli/reference.md drifted from the binary's --help` (followed\n  by the regeneration instruction). The binary hash changed during check; the stale input was\n  rebuilt by `gen(true)` → `spt_bin` → `cargo build -q -p spt --bin spt` before comparison.\n  `CARGO_TARGET_DIR=UNSET`, `SPT_BLESS=UNSET`; Cargo's metadata target and xtask's read path both\n  resolve to this worktree's `target/debug/spt`. Source mutation was restored byte-for-byte.\n  Acceptance files: `~/spt-evidence/ir12-mutation-20260906/{check.exit,check.raw,env.txt}` on kitsubito.\n  The original rig mechanism remains unproven (old-mtime restoration or two target directories\n  are candidates, not findings). No product fix or permanent test added. IR-12 leaves the\n  register at the WEBSERVE close sweep.\n  The mandatory workspace-bins prebuild leg stays in every gate driver on its own merit (caught W2's spacerun red the night it was adopted); it is no longer justified by this note.\n- **What/why (corrected — the consequence sentence was false at `b7b00c3`):** the literal claim\n  holds — `xtask check` does not regenerate-and-compare the schema — but staleness does NOT \"ship a\n  wrong public contract silently\": `checked_in_schema_is_current`\n  (crates/spt-runtime/src/manifest.rs:2363, `int->REQ-DOCS-5`, landed `be4e46c` 2026-06-05, BEFORE\n  this entry's last sweep — docs lagging code) asserts full content equality of the checked-in\n  `manifest.schema.json` against what the derives generate, CRLF-normalised, `SPT_BLESS=1` as the\n  regenerate path. It is REACHED (lib unit test; ci.yml:114 runs `-E kind(lib)+kind(bin)` on push;\n  golden Phase A re-runs the workspace). Exactly ONE schema file exists in the tree; `docs_bundle`\n  (xtask main.rs:609-618) COPIES it at build time, so no second stored copy can drift. Chain closes:\n  derives → checked-in (unit-gated) → bundle (copied, not stored).\n- **What remains open, and the entry narrows to it:** `check_llms_links` (xtask main.rs:521)\n  hardcodes `manifest.schema.json` and `llms-full.txt` as always-existing, so the link check can\n  never see them MISSING — a blind arm, not a drift hole.\n- **The discrimination is now PROVEN, not presumed (todlando 2026-08-04, burn-the-build arms in\n  isolated worktree ir12-mutation @`11169c1`, env verified clear of `SPT_BLESS` FIRST — set, the\n  test short-circuits into a WRITE and a mutation arm silently self-heals green; that env check is\n  now part of the rig recipe):** arm 0 baseline PASS by NAME (1 test run); arm 1 semantic single\n  byte (title `…manifest`→`…manifesX`, length unchanged, scripted edit with match-count refusal)\n  REDS at manifest.rs:2374 exit 100 — \"manifest.schema.json drifted from the derives — regenerate\n  with SPT_BLESS=1\", with the mutated token appearing exactly once in 96,248 B of assertion output\n  so the byte is provably the only delta; arm 2 whitespace-only (CRLF→LF, 1014 endings) PASSES —\n  and arm 0 is itself the stronger normalisation proof, since the on-disk file is CRLF while the\n  generated string is LF, so an unmutated PASS is only possible because the test normalises; arm 3\n  restore re-measured PASS at the pristine sha256. `checked_in_schema_is_current` is a REAL gate.\n- **Built evidence:** `check_llms_links` resolves stored root assets to their\n  real source paths and runs the `llms-full.txt` generator instead of returning\n  hardcoded `true`. A unit cell proves a missing schema and install script are\n  refused, then accepted only after the real source file exists.\n- **Ripe when:** next xtask/docs-gate wave (now sized to the blind arm only).\n- **Size:** tiny.\n\n### IR-13 — Test-soundness follow-ups from the uniform-table sweep\n- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane. · **Origin:** ex releases#58\n- **What/why:** the remaining candidates from the closed issue were mutation-proved before changing\n  tests. `hold_outranks_everything` now walks all four `Opportunity` arms (including\n  `HoldRelease`); changing held+release to start reds on that arm. Pure walk tests cover all four\n  `QuiesceOutcome` arms and all five `EffectKind` arms; making `KillUnconfirmed` clear or\n  `Registry` ephemeral reds independently. The join test now binds all six `JoinFail` variants to\n  both hold retention and the emitted failure class/retry payload; misclassifying `WrongCode`\n  reds. The access candidates had already landed in the W4 follow-up and its dead-seam removal,\n  so the hygiene lane does not manufacture a second test vocabulary beside them.\n\n### IR-14 — .worktrees audit: \"how many worktrees are there\" has four defensible answers, and the difference is not junk\n- **Status:** open · **Origin:** ex releases#56 (was flag: NEEDS-OPERATOR in eval — operator input\n  now sought directly when the entry ripens, not via board flag)\n- **What/why:** the project `.worktrees/` dir accumulates content beyond what git tracks; audit +\n  reap recipe + a hygiene rule for lane close-out. Teardown discipline per docs and memory (classify\n  before delete, outbound links first).\n- **Release-close cleanup, 2026-09-11 (doyle, operator-requested):** removed **38 registered\n  worktree copies** whose heads were ancestors of released `16df0e41`, with no tracked changes,\n  untracked files, ignored files, target trees, or inbound links from the project-wide reparse\n  census. Branches and commits were retained; seven stale worktree registrations were repaired\n  with Git before ordinary, non-forced removal. This count is removals, NOT a census of all\n  remaining work. Dirty/unmerged/evidence-bearing lanes and the sync diagnostic trees stayed.\n  The broader home/Documents/projects cleanup also removed the reproducible N-1 checkout and\n  its separately classified target, an old release download, and generated scratch artifacts:\n  net free-space increase **4,532,350,976 bytes (4.22 GiB)**, ending at **83,382,472,704 bytes\n  (77.66 GiB)**. Concurrent machine activity makes this a net volume delta, not the sum of file\n  lengths. Receipt: `.spt/cleanup-20260911.json`. One cleanup discharges this audit instance,\n  not the recurring hygiene requirement; IR-14/26/27/49 are not closed by deletion.\n- ⚠ **The header of this entry previously read \"14 untracked orphan dirs vs 25 git-tracked\". Both\n  numbers were stale AND UNDATED**, so nobody could tell drift from error. Every count below is dated\n  and carries its command.\n\n#### THE COUNT DISAGREEMENT IS THE FINDING (measured 2026-08-03, todlando + doyle, main @`3efd7e6`)\n\nThree people measuring \"the worktrees\" got three answers. None was wrong; they answered three\ndifferent questions, and nothing in the tree states which one is meant:\n\n| answer | question it actually answers | command |\n|---|---|---|\n| **73** | all ENTRIES under `.worktrees/` | `ls -A .worktrees \\| wc -l` |\n| **52** | DIRECTORIES under `.worktrees/` | `ls -dA .worktrees/*/` |\n| **38** | registered worktrees INCLUDING the root checkout | `git worktree list` |\n| **37** | registered worktrees under `.worktrees/` | above, minus the root |\n\n**52 − 37 = 15 unregistered directories.** The 73 − 52 = **21 loose FILES** are covered below.\n\n**A count is only as good as its question.** Treat \"how many worktrees\" as under-specified until the\nanswer names its population — the same defect that made a naive `grep -rn` from the project root\ninflate a code count by **34.9×** (426 tracked `.rs` vs 14865 on disk excluding all `target/`), and\nmade that grep run past 120s while `git ls-files | xargs grep` returned instantly. **Scan roots and\npopulation definitions are the same class of error.** Use `git grep` / `git ls-files` for tracked\ncontent and `git worktree list --porcelain` for worktrees.\n\n#### THE 15 UNREGISTERED DIRECTORIES ARE FOUR DIFFERENT KINDS OF THING\n\n⛔ **CLASS A — LIVE BUILD POOLS, NOT ORPHANS. DO NOT DELETE.** 3 dirs, 13.2 GB. Each is the TARGET of\na junction that a REGISTERED worktree uses as its `target/`:\n\n| dir | inbound junction from | size | claim |\n|---|---|---|---|\n| `gate-target` | assembly-doorbell, doorbell-w1, doorbell-w2, doorbell-w3 | EMPTY | none |\n| `gate-target-render` | golden-render | 5.84 GB | `POOL-OWNER.json` → golden-render |\n| `gate-target-w4doc` | w4-cli-doc | 7.36 GB | none |\n\n**These are exactly the directories that read as obviously junk** — no `.git`, no source, leftover\nnames — and deleting one destroys a registered worktree's build pool and leaves a dangling junction.\n**Polarity was checked BEFORE classification, which is what caught it:** all 15 top-level dirs are\nREAL directories, none is itself a reparse point; the six junctions are **INBOUND**, at\n`<registered-worktree>/target`. See [[worktree-target-junction]], [[gate-worktree-target-disk]].\n\nTwo findings inside class A, neither of them a deletion question:\n- **`gate-target` has FOUR registered trees junctioned into ONE pool, with no `POOL-OWNER.json` at\n  all** — so nothing would refuse a second LIVE lane there. That is releases#103's exact hazard\n  sitting armed. The pool is also empty: someone reclaimed it and left four junctions aimed at a hole.\n- **`gate-target-render`'s `POOL-OWNER.json` carries only `owner_tree` and `written_by` — no pid and\n  no birth stamp.** A claim that cannot distinguish a live lane from a finished one is missing the one\n  property the claim mechanism exists to provide.\n\n**CLASS B — EMPTIED SKELETONS, ONE UNIFORM SHAPE.** 8 dirs, **0 files**: `acl-core`, `engine-room`,\n`ff-fastfollow`, `gate-23d5ceb`, `gate-ff`, `golden-a`, `golden-b`, `w2b-sender-stamp`. Every one is\nexactly `crates/spt-daemon/` and nothing else. **Eight independent removals stopping at the SAME\nrelative path is a mechanism, not litter.**\n\n**MECHANISM CORROBORATED LIVE, 2026-08-03:** a read-only PEB sweep of process CWDs during a running\n`spt-daemon` suite found ~20 processes — `spt_daemon-<hash>` test harnesses, `PING`, `cmd` — whose\nCWD was **exactly `<worktree>/crates/spt-daemon/`**, the precise path all eight skeletons froze at. A\n`git worktree remove` racing a straggler there deletes everything else and leaves that chain pinned.\nThe processes churn fast (all 17 sampled pids were gone within 30s, one already showing **pid reuse**\n— see [[pid-reuse-across-reboot]] for why a pid alone is never an identity), so the pin is a race, not\na steady state, and it recurs on every daemon-suite worktree.\n\n**CLASS C — FULLY EMPTY, no inbound junction.** 3 dirs, 0 bytes: `gate-41`, `gate-559632e`,\n`release-runbook-main-advance`. Class B with even the chain gone.\n\n**CLASS D — DELIBERATE SCRATCH, NOT RESIDUE.** 1 dir, 12 files, 50 KB: `_patches` — three `.patch`\nfiles with their `.untracked` manifests, plus `ir18-gate-logs/`. Modified the day before the audit,\ni.e. someone's working state.\n\n3 + 8 + 3 + 1 = 15.\n\n#### PIN STATE: NO SKELETON IS HELD TODAY (with a stated blind spot)\n\nRead-only PEB CWD sweep, 2026-08-03: **zero processes hold a CWD in any class-B or class-C\ndirectory** — every live pin was in `gate-ec5f38a` and `gate-main`, both REGISTERED and both running\nrigs at the time. So removal of B and C would succeed today; nothing is retrying it.\n\n⚠ **The sweep read 412 of 593 processes; 181 were unreadable** (elevated/system, no\n`PROCESS_VM_READ`). The no-pin result therefore holds over the READABLE population only. Cheap to\nre-run elevated before acting — [[absence-needs-sibling-probe]].\n\n#### THE LOOSE FILES: A SHARED LOCATION WITH NO STATED CONTRACT\n\n[Showing lines 451-652 of 6938. Use :653 to continue]"}],"details":{"truncation":{"content":"  the skew is a mechanism and the fix must be one too. (2) declare-one-leg REJECTED as the\r\n  terminal state — it repairs lint authority but leaves the legs resolving with different cargo\r\n  versions, and the acaaa4f lock-attribution question this family started from is a resolver\r\n  question. (3) **PIN IN-REPO: `rust-toolchain.toml`, `channel = \"1.96.0\"`** — both runner\r\n  accounts already resolve their toolchain through rustup (witnessed by the `active=` line), so\r\n  the pin self-applies with zero per-box maintenance, and the judge's version becomes a property\r\n  of the TESTED SHA — the same object golden CI already guarantees. Bumps become reviewed lane\r\n  commits, tested by the golden run they ride; the hfenduleam leg proves 1.96.0 on the pin\r\n  lane's own run. (4) INTERIM until the pin lands: kitsubito's clippy leg is AUTHORITATIVE for\r\n  lint disputes — not because newer is stricter (skew direction stays unasserted) but because\r\n  1.96 is the version the pin names, so interim and terminal rulings agree.\r\n  · **Origin:** BAROMETER (ex releases#121); re-confirmed on the #125 fix lane\r\n  (builder's Windows clippy vs kitsubito's rust-1.96.0 lints); see [[CI-RIDER LANE STATE]]\r\n- **What/why:** a Windows-clean lane can land a lint that only reds on the Linux leg — toolchain\r\n  skew makes local clippy evidence non-transferable. Align versions or declare the authoritative\r\n  leg. Natural companion to IR-4's toolchain-version print step.\r\n- **Built evidence / fulfilment check:** `rust-toolchain.toml` contains\r\n  `channel = \"1.96.0\"` and rode the tested cut. A source sweep at close found no CI or pool\r\n  machinery keyed to a box-default toolchain **path**: golden invokes `cargo`, `rustc`, `clippy`,\r\n  and `rustup show active-toolchain` through PATH; pool ownership keys on source-tree/lane identity,\r\n  not rustup installation paths. `release.yml`'s `$HOME/.cargo/bin/mdbook` is an installed tool\r\n  location, not a Rust toolchain selector; its builds still invoke PATH-resolved `cargo`.\r\n- **Size:** built.\r\n- **Composed:** LOCKSMITH (#132) CI-rider cluster (rides IR-4's toolchain-version print step) —\r\n  2026-08-03. GREENLIT with #132 and **DISPATCHED to hertz 2026-08-03**; that dispatch delivered\r\n  the measurement half (landed via [[CI-RIDER LANE STATE]], first exercised on run 30971976024).\r\n\r\n### IR-10 — Wave gate runs the CONSUMERS of any predicate it changes\r\n- **Status:** open · **Origin:** BAROMETER gate craft (ex releases#119)\r\n- **What/why:** legs chosen from changed crates miss the predicate's callers; a composed red is\r\n  triaged at the wave's own tip first. This is the gate-population rule made binding in the gate\r\n  runbook + scripts rather than living in memory.\r\n- **Ripe when:** next gate-runbook/docs wave.\r\n- **Size:** small (docs + gate-script checklist).\r\n\r\n### IR-11 — find-cwd-holders.ps1: --headless discriminator as a column\r\n- **Status:** open · **Origin:** worktree-pin triage tooling (ex releases#118)\r\n- **What/why:** the holder-triage script buries the headless-vs-interactive discriminator in prose;\r\n  as a column it makes the orphan-vs-own-shell call one glance.\r\n- **Ripe when:** any rig-tooling wave; trivial rider.\r\n- **Size:** tiny.\r\n\r\n### IR-12 — xtask contract-drift gate misses a stale manifest.schema.json\r\n- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane (the narrowed blind arm only). · **Origin:** ex\r\n  releases#116\r\n- **KIN NOTE RETIRED (2026-09-06, hertz; doyle measure-first ruling):** the stale-binary\r\n  premise was a rig artifact, not a reproduced product hole. At `9f809f8d`, in isolated Linux\r\n  worktree `hertz-ir12-mutation`, build `spt` once, mutate only its root CLI help string, do not\r\n  rebuild, then run `cargo run -p xtask -- check` alone: **exit 1**, combined output **3435 bytes**,\r\n  ending `xtask check: docs-site/src/cli/reference.md drifted from the binary's --help` (followed\r\n  by the regeneration instruction). The binary hash changed during check; the stale input was\r\n  rebuilt by `gen(true)` → `spt_bin` → `cargo build -q -p spt --bin spt` before comparison.\r\n  `CARGO_TARGET_DIR=UNSET`, `SPT_BLESS=UNSET`; Cargo's metadata target and xtask's read path both\r\n  resolve to this worktree's `target/debug/spt`. Source mutation was restored byte-for-byte.\r\n  Acceptance files: `~/spt-evidence/ir12-mutation-20260906/{check.exit,check.raw,env.txt}` on kitsubito.\r\n  The original rig mechanism remains unproven (old-mtime restoration or two target directories\r\n  are candidates, not findings). No product fix or permanent test added. IR-12 leaves the\r\n  register at the WEBSERVE close sweep.\r\n  The mandatory workspace-bins prebuild leg stays in every gate driver on its own merit (caught W2's spacerun red the night it was adopted); it is no longer justified by this note.\r\n- **What/why (corrected — the consequence sentence was false at `b7b00c3`):** the literal claim\r\n  holds — `xtask check` does not regenerate-and-compare the schema — but staleness does NOT \"ship a\r\n  wrong public contract silently\": `checked_in_schema_is_current`\r\n  (crates/spt-runtime/src/manifest.rs:2363, `int->REQ-DOCS-5`, landed `be4e46c` 2026-06-05, BEFORE\r\n  this entry's last sweep — docs lagging code) asserts full content equality of the checked-in\r\n  `manifest.schema.json` against what the derives generate, CRLF-normalised, `SPT_BLESS=1` as the\r\n  regenerate path. It is REACHED (lib unit test; ci.yml:114 runs `-E kind(lib)+kind(bin)` on push;\r\n  golden Phase A re-runs the workspace). Exactly ONE schema file exists in the tree; `docs_bundle`\r\n  (xtask main.rs:609-618) COPIES it at build time, so no second stored copy can drift. Chain closes:\r\n  derives → checked-in (unit-gated) → bundle (copied, not stored).\r\n- **What remains open, and the entry narrows to it:** `check_llms_links` (xtask main.rs:521)\r\n  hardcodes `manifest.schema.json` and `llms-full.txt` as always-existing, so the link check can\r\n  never see them MISSING — a blind arm, not a drift hole.\r\n- **The discrimination is now PROVEN, not presumed (todlando 2026-08-04, burn-the-build arms in\r\n  isolated worktree ir12-mutation @`11169c1`, env verified clear of `SPT_BLESS` FIRST — set, the\r\n  test short-circuits into a WRITE and a mutation arm silently self-heals green; that env check is\r\n  now part of the rig recipe):** arm 0 baseline PASS by NAME (1 test run); arm 1 semantic single\r\n  byte (title `…manifest`→`…manifesX`, length unchanged, scripted edit with match-count refusal)\r\n  REDS at manifest.rs:2374 exit 100 — \"manifest.schema.json drifted from the derives — regenerate\r\n  with SPT_BLESS=1\", with the mutated token appearing exactly once in 96,248 B of assertion output\r\n  so the byte is provably the only delta; arm 2 whitespace-only (CRLF→LF, 1014 endings) PASSES —\r\n  and arm 0 is itself the stronger normalisation proof, since the on-disk file is CRLF while the\r\n  generated string is LF, so an unmutated PASS is only possible because the test normalises; arm 3\r\n  restore re-measured PASS at the pristine sha256. `checked_in_schema_is_current` is a REAL gate.\r\n- **Built evidence:** `check_llms_links` resolves stored root assets to their\r\n  real source paths and runs the `llms-full.txt` generator instead of returning\r\n  hardcoded `true`. A unit cell proves a missing schema and install script are\r\n  refused, then accepted only after the real source file exists.\r\n- **Ripe when:** next xtask/docs-gate wave (now sized to the blind arm only).\r\n- **Size:** tiny.\r\n\r\n### IR-13 — Test-soundness follow-ups from the uniform-table sweep\r\n- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane. · **Origin:** ex releases#58\r\n- **What/why:** the remaining candidates from the closed issue were mutation-proved before changing\r\n  tests. `hold_outranks_everything` now walks all four `Opportunity` arms (including\r\n  `HoldRelease`); changing held+release to start reds on that arm. Pure walk tests cover all four\r\n  `QuiesceOutcome` arms and all five `EffectKind` arms; making `KillUnconfirmed` clear or\r\n  `Registry` ephemeral reds independently. The join test now binds all six `JoinFail` variants to\r\n  both hold retention and the emitted failure class/retry payload; misclassifying `WrongCode`\r\n  reds. The access candidates had already landed in the W4 follow-up and its dead-seam removal,\r\n  so the hygiene lane does not manufacture a second test vocabulary beside them.\r\n\r\n### IR-14 — .worktrees audit: \"how many worktrees are there\" has four defensible answers, and the difference is not junk\r\n- **Status:** open · **Origin:** ex releases#56 (was flag: NEEDS-OPERATOR in eval — operator input\r\n  now sought directly when the entry ripens, not via board flag)\r\n- **What/why:** the project `.worktrees/` dir accumulates content beyond what git tracks; audit +\r\n  reap recipe + a hygiene rule for lane close-out. Teardown discipline per docs and memory (classify\r\n  before delete, outbound links first).\r\n- **Release-close cleanup, 2026-09-11 (doyle, operator-requested):** removed **38 registered\r\n  worktree copies** whose heads were ancestors of released `16df0e41`, with no tracked changes,\r\n  untracked files, ignored files, target trees, or inbound links from the project-wide reparse\r\n  census. Branches and commits were retained; seven stale worktree registrations were repaired\r\n  with Git before ordinary, non-forced removal. This count is removals, NOT a census of all\r\n  remaining work. Dirty/unmerged/evidence-bearing lanes and the sync diagnostic trees stayed.\r\n  The broader home/Documents/projects cleanup also removed the reproducible N-1 checkout and\r\n  its separately classified target, an old release download, and generated scratch artifacts:\r\n  net free-space increase **4,532,350,976 bytes (4.22 GiB)**, ending at **83,382,472,704 bytes\r\n  (77.66 GiB)**. Concurrent machine activity makes this a net volume delta, not the sum of file\r\n  lengths. Receipt: `.spt/cleanup-20260911.json`. One cleanup discharges this audit instance,\r\n  not the recurring hygiene requirement; IR-14/26/27/49 are not closed by deletion.\r\n- ⚠ **The header of this entry previously read \"14 untracked orphan dirs vs 25 git-tracked\". Both\r\n  numbers were stale AND UNDATED**, so nobody could tell drift from error. Every count below is dated\r\n  and carries its command.\r\n\r\n#### THE COUNT DISAGREEMENT IS THE FINDING (measured 2026-08-03, todlando + doyle, main @`3efd7e6`)\r\n\r\nThree people measuring \"the worktrees\" got three answers. None was wrong; they answered three\r\ndifferent questions, and nothing in the tree states which one is meant:\r\n\r\n| answer | question it actually answers | command |\r\n|---|---|---|\r\n| **73** | all ENTRIES under `.worktrees/` | `ls -A .worktrees \\| wc -l` |\r\n| **52** | DIRECTORIES under `.worktrees/` | `ls -dA .worktrees/*/` |\r\n| **38** | registered worktrees INCLUDING the root checkout | `git worktree list` |\r\n| **37** | registered worktrees under `.worktrees/` | above, minus the root |\r\n\r\n**52 − 37 = 15 unregistered directories.** The 73 − 52 = **21 loose FILES** are covered below.\r\n\r\n**A count is only as good as its question.** Treat \"how many worktrees\" as under-specified until the\r\nanswer names its population — the same defect that made a naive `grep -rn` from the project root\r\ninflate a code count by **34.9×** (426 tracked `.rs` vs 14865 on disk excluding all `target/`), and\r\nmade that grep run past 120s while `git ls-files | xargs grep` returned instantly. **Scan roots and\r\npopulation definitions are the same class of error.** Use `git grep` / `git ls-files` for tracked\r\ncontent and `git worktree list --porcelain` for worktrees.\r\n\r\n#### THE 15 UNREGISTERED DIRECTORIES ARE FOUR DIFFERENT KINDS OF THING\r\n\r\n⛔ **CLASS A — LIVE BUILD POOLS, NOT ORPHANS. DO NOT DELETE.** 3 dirs, 13.2 GB. Each is the TARGET of\r\na junction that a REGISTERED worktree uses as its `target/`:\r\n\r\n| dir | inbound junction from | size | claim |\r\n|---|---|---|---|\r\n| `gate-target` | assembly-doorbell, doorbell-w1, doorbell-w2, doorbell-w3 | EMPTY | none |\r\n| `gate-target-render` | golden-render | 5.84 GB | `POOL-OWNER.json` → golden-render |\r\n| `gate-target-w4doc` | w4-cli-doc | 7.36 GB | none |\r\n\r\n**These are exactly the directories that read as obviously junk** — no `.git`, no source, leftover\r\nnames — and deleting one destroys a registered worktree's build pool and leaves a dangling junction.\r\n**Polarity was checked BEFORE classification, which is what caught it:** all 15 top-level dirs are\r\nREAL directories, none is itself a reparse point; the six junctions are **INBOUND**, at\r\n`<registered-worktree>/target`. See [[worktree-target-junction]], [[gate-worktree-target-disk]].\r\n\r\nTwo findings inside class A, neither of them a deletion question:\r\n- **`gate-target` has FOUR registered trees junctioned into ONE pool, with no `POOL-OWNER.json` at\r\n  all** — so nothing would refuse a second LIVE lane there. That is releases#103's exact hazard\r\n  sitting armed. The pool is also empty: someone reclaimed it and left four junctions aimed at a hole.\r\n- **`gate-target-render`'s `POOL-OWNER.json` carries only `owner_tree` and `written_by` — no pid and\r\n  no birth stamp.** A claim that cannot distinguish a live lane from a finished one is missing the one\r\n  property the claim mechanism exists to provide.\r\n\r\n**CLASS B — EMPTIED SKELETONS, ONE UNIFORM SHAPE.** 8 dirs, **0 files**: `acl-core`, `engine-room`,\r\n`ff-fastfollow`, `gate-23d5ceb`, `gate-ff`, `golden-a`, `golden-b`, `w2b-sender-stamp`. Every one is\r\nexactly `crates/spt-daemon/` and nothing else. **Eight independent removals stopping at the SAME\r\nrelative path is a mechanism, not litter.**\r\n\r\n**MECHANISM CORROBORATED LIVE, 2026-08-03:** a read-only PEB sweep of process CWDs during a running\r\n`spt-daemon` suite found ~20 processes — `spt_daemon-<hash>` test harnesses, `PING`, `cmd` — whose\r\nCWD was **exactly `<worktree>/crates/spt-daemon/`**, the precise path all eight skeletons froze at. A\r\n`git worktree remove` racing a straggler there deletes everything else and leaves that chain pinned.\r\nThe processes churn fast (all 17 sampled pids were gone within 30s, one already showing **pid reuse**\r\n— see [[pid-reuse-across-reboot]] for why a pid alone is never an identity), so the pin is a race, not\r\na steady state, and it recurs on every daemon-suite worktree.\r\n\r\n**CLASS C — FULLY EMPTY, no inbound junction.** 3 dirs, 0 bytes: `gate-41`, `gate-559632e`,\r\n`release-runbook-main-advance`. Class B with even the chain gone.\r\n\r\n**CLASS D — DELIBERATE SCRATCH, NOT RESIDUE.** 1 dir, 12 files, 50 KB: `_patches` — three `.patch`\r\nfiles with their `.untracked` manifests, plus `ir18-gate-logs/`. Modified the day before the audit,\r\ni.e. someone's working state.\r\n\r\n3 + 8 + 3 + 1 = 15.\r\n\r\n#### PIN STATE: NO SKELETON IS HELD TODAY (with a stated blind spot)\r\n\r\nRead-only PEB CWD sweep, 2026-08-03: **zero processes hold a CWD in any class-B or class-C\r\ndirectory** — every live pin was in `gate-ec5f38a` and `gate-main`, both REGISTERED and both running\r\nrigs at the time. So removal of B and C would succeed today; nothing is retrying it.\r\n\r\n⚠ **The sweep read 412 of 593 processes; 181 were unreadable** (elevated/system, no\r\n`PROCESS_VM_READ`). The no-pin result therefore holds over the READABLE population only. Cheap to\r\nre-run elevated before acting — [[absence-needs-sibling-probe]].\r\n\r\n#### THE LOOSE FILES: A SHARED LOCATION WITH NO STATED CONTRACT\r","truncated":true,"truncatedBy":"lines","totalLines":6488,"totalBytes":15474,"outputLines":202,"outputBytes":15474,"lastLinePartial":false,"firstLineExceedsLimit":false},"totalLines":6938,"displayContent":{"text":"  the skew is a mechanism and the fix must be one too. (2) declare-one-leg REJECTED as the\r\n  terminal state — it repairs lint authority but leaves the legs resolving with different cargo\r\n  versions, and the acaaa4f lock-attribution question this family started from is a resolver\r\n  question. (3) **PIN IN-REPO: `rust-toolchain.toml`, `channel = \"1.96.0\"`** — both runner\r\n  accounts already resolve their toolchain through rustup (witnessed by the `active=` line), so\r\n  the pin self-applies with zero per-box maintenance, and the judge's version becomes a property\r\n  of the TESTED SHA — the same object golden CI already guarantees. Bumps become reviewed lane\r\n  commits, tested by the golden run they ride; the hfenduleam leg proves 1.96.0 on the pin\r\n  lane's own run. (4) INTERIM until the pin lands: kitsubito's clippy leg is AUTHORITATIVE for\r\n  lint disputes — not because newer is stricter (skew direction stays unasserted) but because\r\n  1.96 is the version the pin names, so interim and terminal rulings agree.\r\n  · **Origin:** BAROMETER (ex releases#121); re-confirmed on the #125 fix lane\r\n  (builder's Windows clippy vs kitsubito's rust-1.96.0 lints); see [[CI-RIDER LANE STATE]]\r\n- **What/why:** a Windows-clean lane can land a lint that only reds on the Linux leg — toolchain\r\n  skew makes local clippy evidence non-transferable. Align versions or declare the authoritative\r\n  leg. Natural companion to IR-4's toolchain-version print step.\r\n- **Built evidence / fulfilment check:** `rust-toolchain.toml` contains\r\n  `channel = \"1.96.0\"` and rode the tested cut. A source sweep at close found no CI or pool\r\n  machinery keyed to a box-default toolchain **path**: golden invokes `cargo`, `rustc`, `clippy`,\r\n  and `rustup show active-toolchain` through PATH; pool ownership keys on source-tree/lane identity,\r\n  not rustup installation paths. `release.yml`'s `$HOME/.cargo/bin/mdbook` is an installed tool\r\n  location, not a Rust toolchain selector; its builds still invoke PATH-resolved `cargo`.\r\n- **Size:** built.\r\n- **Composed:** LOCKSMITH (#132) CI-rider cluster (rides IR-4's toolchain-version print step) —\r\n  2026-08-03. GREENLIT with #132 and **DISPATCHED to hertz 2026-08-03**; that dispatch delivered\r\n  the measurement half (landed via [[CI-RIDER LANE STATE]], first exercised on run 30971976024).\r\n\r\n### IR-10 — Wave gate runs the CONSUMERS of any predicate it changes\r\n- **Status:** open · **Origin:** BAROMETER gate craft (ex releases#119)\r\n- **What/why:** legs chosen from changed crates miss the predicate's callers; a composed red is\r\n  triaged at the wave's own tip first. This is the gate-population rule made binding in the gate\r\n  runbook + scripts rather than living in memory.\r\n- **Ripe when:** next gate-runbook/docs wave.\r\n- **Size:** small (docs + gate-script checklist).\r\n\r\n### IR-11 — find-cwd-holders.ps1: --headless discriminator as a column\r\n- **Status:** open · **Origin:** worktree-pin triage tooling (ex releases#118)\r\n- **What/why:** the holder-triage script buries the headless-vs-interactive discriminator in prose;\r\n  as a column it makes the orphan-vs-own-shell call one glance.\r\n- **Ripe when:** any rig-tooling wave; trivial rider.\r\n- **Size:** tiny.\r\n\r\n### IR-12 — xtask contract-drift gate misses a stale manifest.schema.json\r\n- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane (the narrowed blind arm only). · **Origin:** ex\r\n  releases#116\r\n- **KIN NOTE RETIRED (2026-09-06, hertz; doyle measure-first ruling):** the stale-binary\r\n  premise was a rig artifact, not a reproduced product hole. At `9f809f8d`, in isolated Linux\r\n  worktree `hertz-ir12-mutation`, build `spt` once, mutate only its root CLI help string, do not\r\n  rebuild, then run `cargo run -p xtask -- check` alone: **exit 1**, combined output **3435 bytes**,\r\n  ending `xtask check: docs-site/src/cli/reference.md drifted from the binary's --help` (followed\r\n  by the regeneration instruction). The binary hash changed during check; the stale input was\r\n  rebuilt by `gen(true)` → `spt_bin` → `cargo build -q -p spt --bin spt` before comparison.\r\n  `CARGO_TARGET_DIR=UNSET`, `SPT_BLESS=UNSET`; Cargo's metadata target and xtask's read path both\r\n  resolve to this worktree's `target/debug/spt`. Source mutation was restored byte-for-byte.\r\n  Acceptance files: `~/spt-evidence/ir12-mutation-20260906/{check.exit,check.raw,env.txt}` on kitsubito.\r\n  The original rig mechanism remains unproven (old-mtime restoration or two target directories\r\n  are candidates, not findings). No product fix or permanent test added. IR-12 leaves the\r\n  register at the WEBSERVE close sweep.\r\n  The mandatory workspace-bins prebuild leg stays in every gate driver on its own merit (caught W2's spacerun red the night it was adopted); it is no longer justified by this note.\r\n- **What/why (corrected — the consequence sentence was false at `b7b00c3`):** the literal claim\r\n  holds — `xtask check` does not regenerate-and-compare the schema — but staleness does NOT \"ship a\r\n  wrong public contract silently\": `checked_in_schema_is_current`\r\n  (crates/spt-runtime/src/manifest.rs:2363, `int->REQ-DOCS-5`, landed `be4e46c` 2026-06-05, BEFORE\r\n  this entry's last sweep — docs lagging code) asserts full content equality of the checked-in\r\n  `manifest.schema.json` against what the derives generate, CRLF-normalised, `SPT_BLESS=1` as the\r\n  regenerate path. It is REACHED (lib unit test; ci.yml:114 runs `-E kind(lib)+kind(bin)` on push;\r\n  golden Phase A re-runs the workspace). Exactly ONE schema file exists in the tree; `docs_bundle`\r\n  (xtask main.rs:609-618) COPIES it at build time, so no second stored copy can drift. Chain closes:\r\n  derives → checked-in (unit-gated) → bundle (copied, not stored).\r\n- **What remains open, and the entry narrows to it:** `check_llms_links` (xtask main.rs:521)\r\n  hardcodes `manifest.schema.json` and `llms-full.txt` as always-existing, so the link check can\r\n  never see them MISSING — a blind arm, not a drift hole.\r\n- **The discrimination is now PROVEN, not presumed (todlando 2026-08-04, burn-the-build arms in\r\n  isolated worktree ir12-mutation @`11169c1`, env verified clear of `SPT_BLESS` FIRST — set, the\r\n  test short-circuits into a WRITE and a mutation arm silently self-heals green; that env check is\r\n  now part of the rig recipe):** arm 0 baseline PASS by NAME (1 test run); arm 1 semantic single\r\n  byte (title `…manifest`→`…manifesX`, length unchanged, scripted edit with match-count refusal)\r\n  REDS at manifest.rs:2374 exit 100 — \"manifest.schema.json drifted from the derives — regenerate\r\n  with SPT_BLESS=1\", with the mutated token appearing exactly once in 96,248 B of assertion output\r\n  so the byte is provably the only delta; arm 2 whitespace-only (CRLF→LF, 1014 endings) PASSES —\r\n  and arm 0 is itself the stronger normalisation proof, since the on-disk file is CRLF while the\r\n  generated string is LF, so an unmutated PASS is only possible because the test normalises; arm 3\r\n  restore re-measured PASS at the pristine sha256. `checked_in_schema_is_current` is a REAL gate.\r\n- **Built evidence:** `check_llms_links` resolves stored root assets to their\r\n  real source paths and runs the `llms-full.txt` generator instead of returning\r\n  hardcoded `true`. A unit cell proves a missing schema and install script are\r\n  refused, then accepted only after the real source file exists.\r\n- **Ripe when:** next xtask/docs-gate wave (now sized to the blind arm only).\r\n- **Size:** tiny.\r\n\r\n### IR-13 — Test-soundness follow-ups from the uniform-table sweep\r\n- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane. · **Origin:** ex releases#58\r\n- **What/why:** the remaining candidates from the closed issue were mutation-proved before changing\r\n  tests. `hold_outranks_everything` now walks all four `Opportunity` arms (including\r\n  `HoldRelease`); changing held+release to start reds on that arm. Pure walk tests cover all four\r\n  `QuiesceOutcome` arms and all five `EffectKind` arms; making `KillUnconfirmed` clear or\r\n  `Registry` ephemeral reds independently. The join test now binds all six `JoinFail` variants to\r\n  both hold retention and the emitted failure class/retry payload; misclassifying `WrongCode`\r\n  reds. The access candidates had already landed in the W4 follow-up and its dead-seam removal,\r\n  so the hygiene lane does not manufacture a second test vocabulary beside them.\r\n\r\n### IR-14 — .worktrees audit: \"how many worktrees are there\" has four defensible answers, and the difference is not junk\r\n- **Status:** open · **Origin:** ex releases#56 (was flag: NEEDS-OPERATOR in eval — operator input\r\n  now sought directly when the entry ripens, not via board flag)\r\n- **What/why:** the project `.worktrees/` dir accumulates content beyond what git tracks; audit +\r\n  reap recipe + a hygiene rule for lane close-out. Teardown discipline per docs and memory (classify\r\n  before delete, outbound links first).\r\n- **Release-close cleanup, 2026-09-11 (doyle, operator-requested):** removed **38 registered\r\n  worktree copies** whose heads were ancestors of released `16df0e41`, with no tracked changes,\r\n  untracked files, ignored files, target trees, or inbound links from the project-wide reparse\r\n  census. Branches and commits were retained; seven stale worktree registrations were repaired\r\n  with Git before ordinary, non-forced removal. This count is removals, NOT a census of all\r\n  remaining work. Dirty/unmerged/evidence-bearing lanes and the sync diagnostic trees stayed.\r\n  The broader home/Documents/projects cleanup also removed the reproducible N-1 checkout and\r\n  its separately classified target, an old release download, and generated scratch artifacts:\r\n  net free-space increase **4,532,350,976 bytes (4.22 GiB)**, ending at **83,382,472,704 bytes\r\n  (77.66 GiB)**. Concurrent machine activity makes this a net volume delta, not the sum of file\r\n  lengths. Receipt: `.spt/cleanup-20260911.json`. One cleanup discharges this audit instance,\r\n  not the recurring hygiene requirement; IR-14/26/27/49 are not closed by deletion.\r\n- ⚠ **The header of this entry previously read \"14 untracked orphan dirs vs 25 git-tracked\". Both\r\n  numbers were stale AND UNDATED**, so nobody could tell drift from error. Every count below is dated\r\n  and carries its command.\r\n\r\n#### THE COUNT DISAGREEMENT IS THE FINDING (measured 2026-08-03, todlando + doyle, main @`3efd7e6`)\r\n\r\nThree people measuring \"the worktrees\" got three answers. None was wrong; they answered three\r\ndifferent questions, and nothing in the tree states which one is meant:\r\n\r\n| answer | question it actually answers | command |\r\n|---|---|---|\r\n| **73** | all ENTRIES under `.worktrees/` | `ls -A .worktrees \\| wc -l` |\r\n| **52** | DIRECTORIES under `.worktrees/` | `ls -dA .worktrees/*/` |\r\n| **38** | registered worktrees INCLUDING the root checkout | `git worktree list` |\r\n| **37** | registered worktrees under `.worktrees/` | above, minus the root |\r\n\r\n**52 − 37 = 15 unregistered directories.** The 73 − 52 = **21 loose FILES** are covered below.\r\n\r\n**A count is only as good as its question.** Treat \"how many worktrees\" as under-specified until the\r\nanswer names its population — the same defect that made a naive `grep -rn` from the project root\r\ninflate a code count by **34.9×** (426 tracked `.rs` vs 14865 on disk excluding all `target/`), and\r\nmade that grep run past 120s while `git ls-files | xargs grep` returned instantly. **Scan roots and\r\npopulation definitions are the same class of error.** Use `git grep` / `git ls-files` for tracked\r\ncontent and `git worktree list --porcelain` for worktrees.\r\n\r\n#### THE 15 UNREGISTERED DIRECTORIES ARE FOUR DIFFERENT KINDS OF THING\r\n\r\n⛔ **CLASS A — LIVE BUILD POOLS, NOT ORPHANS. DO NOT DELETE.** 3 dirs, 13.2 GB. Each is the TARGET of\r\na junction that a REGISTERED worktree uses as its `target/`:\r\n\r\n| dir | inbound junction from | size | claim |\r\n|---|---|---|---|\r\n| `gate-target` | assembly-doorbell, doorbell-w1, doorbell-w2, doorbell-w3 | EMPTY | none |\r\n| `gate-target-render` | golden-render | 5.84 GB | `POOL-OWNER.json` → golden-render |\r\n| `gate-target-w4doc` | w4-cli-doc | 7.36 GB | none |\r\n\r\n**These are exactly the directories that read as obviously junk** — no `.git`, no source, leftover\r\nnames — and deleting one destroys a registered worktree's build pool and leaves a dangling junction.\r\n**Polarity was checked BEFORE classification, which is what caught it:** all 15 top-level dirs are\r\nREAL directories, none is itself a reparse point; the six junctions are **INBOUND**, at\r\n`<registered-worktree>/target`. See [[worktree-target-junction]], [[gate-worktree-target-disk]].\r\n\r\nTwo findings inside class A, neither of them a deletion question:\r\n- **`gate-target` has FOUR registered trees junctioned into ONE pool, with no `POOL-OWNER.json` at\r\n  all** — so nothing would refuse a second LIVE lane there. That is releases#103's exact hazard\r\n  sitting armed. The pool is also empty: someone reclaimed it and left four junctions aimed at a hole.\r\n- **`gate-target-render`'s `POOL-OWNER.json` carries only `owner_tree` and `written_by` — no pid and\r\n  no birth stamp.** A claim that cannot distinguish a live lane from a finished one is missing the one\r\n  property the claim mechanism exists to provide.\r\n\r\n**CLASS B — EMPTIED SKELETONS, ONE UNIFORM SHAPE.** 8 dirs, **0 files**: `acl-core`, `engine-room`,\r\n`ff-fastfollow`, `gate-23d5ceb`, `gate-ff`, `golden-a`, `golden-b`, `w2b-sender-stamp`. Every one is\r\nexactly `crates/spt-daemon/` and nothing else. **Eight independent removals stopping at the SAME\r\nrelative path is a mechanism, not litter.**\r\n\r\n**MECHANISM CORROBORATED LIVE, 2026-08-03:** a read-only PEB sweep of process CWDs during a running\r\n`spt-daemon` suite found ~20 processes — `spt_daemon-<hash>` test harnesses, `PING`, `cmd` — whose\r\nCWD was **exactly `<worktree>/crates/spt-daemon/`**, the precise path all eight skeletons froze at. A\r\n`git worktree remove` racing a straggler there deletes everything else and leaves that chain pinned.\r\nThe processes churn fast (all 17 sampled pids were gone within 30s, one already showing **pid reuse**\r\n— see [[pid-reuse-across-reboot]] for why a pid alone is never an identity), so the pin is a race, not\r\na steady state, and it recurs on every daemon-suite worktree.\r\n\r\n**CLASS C — FULLY EMPTY, no inbound junction.** 3 dirs, 0 bytes: `gate-41`, `gate-559632e`,\r\n`release-runbook-main-advance`. Class B with even the chain gone.\r\n\r\n**CLASS D — DELIBERATE SCRATCH, NOT RESIDUE.** 1 dir, 12 files, 50 KB: `_patches` — three `.patch`\r\nfiles with their `.untracked` manifests, plus `ir18-gate-logs/`. Modified the day before the audit,\r\ni.e. someone's working state.\r\n\r\n3 + 8 + 3 + 1 = 15.\r\n\r\n#### PIN STATE: NO SKELETON IS HELD TODAY (with a stated blind spot)\r\n\r\nRead-only PEB CWD sweep, 2026-08-03: **zero processes hold a CWD in any class-B or class-C\r\ndirectory** — every live pin was in `gate-ec5f38a` and `gate-main`, both REGISTERED and both running\r\nrigs at the time. So removal of B and C would succeed today; nothing is retrying it.\r\n\r\n⚠ **The sweep read 412 of 593 processes; 181 were unreadable** (elevated/system, no\r\n`PROCESS_VM_READ`). The no-pin result therefore holds over the READABLE population only. Cheap to\r\nre-run elevated before acting — [[absence-needs-sibling-probe]].\r\n\r\n#### THE LOOSE FILES: A SHARED LOCATION WITH NO STATED CONTRACT\r","startLine":451,"lineNumbers":[451,452,453,454,455,456,457,458,459,460,461,462,463,464,465,466,467,468,469,470,471,472,473,474,475,476,477,478,479,480,481,482,483,484,485,486,487,488,489,490,491,492,493,494,495,496,497,498,499,500,501,502,503,504,505,506,507,508,509,510,511,512,513,514,515,516,517,518,519,520,521,522,523,524,525,526,527,528,529,530,531,532,533,534,535,536,537,538,539,540,541,542,543,544,545,546,547,548,549,550,551,552,553,554,555,556,557,558,559,560,561,562,563,564,565,566,567,568,569,570,571,572,573,574,575,576,577,578,579,580,581,582,583,584,585,586,587,588,589,590,591,592,593,594,595,596,597,598,599,600,601,602,603,604,605,606,607,608,609,610,611,612,613,614,615,616,617,618,619,620,621,622,623,624,625,626,627,628,629,630,631,632,633,634,635,636,637,638,639,640,641,642,643,644,645,646,647,648,649,650,651,652]},"fileSize":676479,"meta":{"source":{"type":"path","value":"C:\\Users\\decid\\Documents\\projects\\spt-core\\.worktrees\\hertz-ir86-disk-delta\\docs\\INFRA-REGISTER.md"},"truncation":{"direction":"head","truncatedBy":"lines","totalLines":6938,"totalBytes":15474,"outputLines":202,"outputBytes":15474,"shownRange":{"start":451,"end":652},"nextOffset":653}}},"isError":false,"timestamp":1789483673568}}
{"type":"message","id":"ab8e7591","parentId":"b704c0bc","timestamp":"2026-09-15T14:47:53.574Z","message":{"role":"toolResult","toolCallId":"call_x9ZED10mq4LwyCNlkpTdxb16|fc_043a862a419f59ae016aa95a997a5087d2b3a70c1bf92d893a","toolName":"read","content":[{"type":"text","text":"  (reap.rs:59-63, resident_service_e2e's mock_pid :100-106, and the shape wherever a test reads a\n  self-written pid file) — so (b) lands ONE shared read-a-pid-breadcrumb helper that distinguishes\n  absent from unreadable ONCE, adopted at the enumerated sites, not a per-site token split; the\n  single-source-discriminant rule, applied before a fourth site mints itself.\n  **THIRD SITE CONFIRMED AT SOURCE (deployah, read-only 2026-08-04) — it was a predicted SHAPE and\n  is now an address:** `crates/spt/tests/resident_service_e2e.rs:136-137`, `brain_ready`, which\n  `.ok()?`s BOTH the read and the JSON parse — two collapses in two lines, the self-written-pid-file\n  shape this entry predicted. What makes it the worst of the three rather than the third of three:\n  its output feeds `brain_seed`, a population-sweep SEED, so an unreadable `brain.ready` silently\n  drops a whole subtree from the sweep. The other two sites lose one pid; this one degrades the very\n  instrument that is supposed to cover them, and it does so while the sweep still reports clean —\n  [[IR-8]]'s sentence again, now inside the instrument rather than beside it. The (b) lane's helper\n  therefore has to be adopted at this site to be worth landing at all. Still deployah's,\n  still after hertz's lane; hertz's lane does NOT wait for it (the population assertion covers the\n  leak class independent of pid bookkeeping — that is its virtue). (b) INTAKE ITEM (doyle gate on\n  the IR-18 lane, 2026-08-03, deferred there deliberately): the lane's verdict-gate SOUND-arm\n  comment reads \"provably not there\", which overclaims for `no-breadcrumb` (absence-of-knowledge,\n  not proof — the scoped reading belongs at that arm); comment-only, and (b) rewrites that arm\n  when `unreadable-breadcrumb` splits out, so it lands there rather than costing a solo respin.\n  SECOND (b) INTAKE ITEM (hertz self-noted at re-gate, doyle-ruled deferred): cleanliness is\n  currently stated at THREE sites (two asserts + `is_clean`) — the drift that produced the\n  scope_lost condition bug (a failed edit followed by a narrower successful one replaced the\n  message but not the condition; the artifact of that failure mode IS message/code disagreement).\n  (b) consolidates to conditions derived from one source, weighing the two-message diagnostic\n  split it would cost. The\n  exhaustive panic-catch-all match is what makes the split safe to do later: the new token lands\n  loud on first fire in every consuming gate, forced to be classified, never silently passed. Until then the scoped reading above is the\n  gate's contract — and the LANE BUILDER writes that scoped reading into the match's SOUND-arm\n  comment (the sketch's \"nothing to read is nothing to kill\" is the exact inference the source\n  forbids; the comment must not teach the false step); (2) the gate closes over the\n  token set — SPELLED BUILDABLY (hertz correction 2026-08-03; the earlier \"no wildcard arm\" wording\n  is an instruction rustc rejects, since the refusal reason is a `&'static str` (:55) and a string\n  match always requires a catch-all): the match names the six SOUND tokens as a pass arm, the three\n  TRAP tokens as a panic arm, and the REQUIRED catch-all arm is not a wildcard PASS — it panics\n  naming the unknown token (\"unclassified reap refusal token — classify it in this match\"), so\n  upstream drift announces itself the first run it fires instead of sliding into a silent pass.\n  Runtime fail-closed, not compile-time: compile-time closure needs the reason to become an enum in\n  common/reap.rs, an upstream change touching every consumer — ruled NOT smuggled into this lane\n  (candidate for its own thin lane if ever wanted; doyle concurs runtime fail-closed is\n  proportionate). Direction of the default, kept in the record: a missed trap state is an invisible\n  leak wearing the reap line a reviewer wants to see; an unclassified harmless token is a loud red\n  costing one edit. Cheap and loud beats silent and wrong. (Count hygiene, hertz self-flagged: a\n  single-line grep for the refuse() sites returns five of nine — three wrap across lines; the nine\n  stands on reading, not the grep. The sweep-count trap in miniature.)\n- **Prior observed instance of the class, in-tree (hertz 2026-08-03 — stated to understate):**\n  reap.rs:3–11 documents the measurement and a casualty: pid reuse on the Windows gate box at\n  2.2s minimum / p50 11.7s under a Phase-A battery, and a concurrent test process killed by a bare\n  kill on a stale breadcrumb pid, dying with bare exit 1 and no panic — the observed\n  `worker_lifecycle_e2e` red in golden job 90742055246 (that test's intermittent class is board\n  releases#32, still in-flight). Different test, different job — it does NOT reproduce this entry's\n  specimen and promotes nothing; what it settles is that the class is real IN THIS SUITE with a\n  named victim, and the authenticated reaper is the remedy someone already built for it —\n  resident_service_e2e simply never adopted it. Two shape-predictions it supplies, made before this\n  specimen existed: the p50 11.7s reuse window is short against this test's 45s waits and ~124s\n  runtime (window wide open). (A second claimed match — \"bare-exit-1-no-panic matches the empty\n  daemon.stderr.log\" — is RETRACTED as a category error, hertz+deployah 2026-08-03: reap.rs's\n  phrase describes the VICTIM TEST PROCESS dying, not a daemon's log; two processes, two\n  artifacts.) Predictions, not proof; the specimen stays CANDIDATE — shape since reproduced on\n  demand, agent unidentified (see the control record above).\n- **Rig near-miss, caught before first execution (hertz 2026-08-03) — kept as design justification,\n  not an anecdote:** the positive-control arm's first draft selected its victim machine-wide\n  (`Win32_Process Name='spt.exe'` + cmdline match `daemon run`, then force-kill). hfenduleam is the\n  Windows CI runner as well as a dev box, so that filter matches CI's own test daemons: run while a\n  leg was live, it would have force-killed a running job's daemon and reported the result as a\n  measurement — fabricating a red in someone else's job, the exact class this entry documents.\n  Corrected to a parent-scoped selector (daemon = child of the test pid; service = child of that\n  daemon); `CREATE_BREAKAWAY_FROM_JOB` does not weaken parent-id attribution, since breakaway leaves\n  the JOB, not the parent record — which is also why the orphaned svcmock stays attributable to the\n  daemon that spawned it. **The load bought the catch** (blocked on the box ⇒ re-read instead of\n  ran). Bearing on the fix: the INSTRUMENT built to study a bare-selector reaper was itself written\n  with a bare selector. The remedy therefore cannot be \"be careful\" — the authenticated path must be\n  the only one within reach in this suite.\n- **Ripe when:** RIPE NOW, and not gated on the rate run that was cancelled.\n- **Size:** small.\n\n### IR-19 — Docs-only pushes to main run full unit legs (classifier is PR-only) — intent unverified\n- **Status:** RETIRED 2026-08-18 — intentional for main pushes, not a classifier defect. · **Origin:** hertz observation 2026-08-03 (register-push\n  cadence gated his rig behind repeated hfenduleam unit legs); mechanism verified by doyle at\n  source same night.\n- **What/why:** `ci.yml`'s `changes` job classifies docs-only diffs ONLY for `pull_request` events\n  — push events hardcode `code=true` (ci.yml:45–48, an explicit branch, not a fallthrough), so\n  every docs-only push to main spins both full unit legs. Tonight: five register docs pushes each\n  queued a Windows unit leg on hfenduleam; concurrency kept one running + one pending (main is\n  never cancelled in-progress, pending runs supersede — the recorded behavior matches ci.yml:9–13).\n  FINDING SETTLED (deployah, same night, from the workflow): this is not intent — it is a scope\n  the classifier never had; the `*.md` / `traceable-reqs.toml` case arms are only ever REACHED on\n  pull_request (the early-return precedes them), and golden.yml's own hardcoded `code=true` is\n  unrelated (golden triggers only on golden/**). REMEDY STILL OPEN on a named tension: extending\n  the classifier to pushes leaves a docs-only main TIP with no run of its own — fine if\n  tested-sha==merged-sha means \"the code at this sha was tested\" (it was, at the last code sha),\n  not fine if any gate or reader takes \"main tip has a green run\" as the check. One person reads\n  the consuming gates before any remedy (doyle, at the next CI-touching wave) — three assuming is\n  how this class ships.\n- **Resolution:** the consuming contract already answers the held question:\n  `REQ-CI-DOCS-ONLY-THIN` is PR-only and explicitly says ADR-0050 supersedes\n  it for main pushes. Main-tip evidence remains full by design; no classifier\n  branch was widened.\n- **Interim rule (doyle, same night):** batch register edits into one push instead of landing them\n  as they occur — the cadence is a real gate on whoever is queued behind the runner.\n- **Ripe when:** next CI-touching wave, after the intent question is answered on the REQ record.\n- **Size:** small (one conditional, if the answer is \"extend\").\n- **Composed:** LOCKSMITH (#132) — doyle reads the consuming gates during the batch's CI-touching\n  wave (the intent question), BEFORE any classifier remedy. 2026-08-03.\n\n### IR-20 — resident_service_e2e's `spt daemon stop --force` does not stop the daemon; teardown is complete only because the kills are\n- **Status:** open · **Origin:** hertz 2026-08-03, measured on the IR-18 lane's own clean run\n  (hfenduleam, log kept); routed text, doyle-landed.\n- **MEASURED:** teardown runs `spt(&[\"daemon\",\"stop\",\"--force\"])` then reaps. At reaper fire, every\n  target was still ALIVE and every verdict was `Killed`, not `gone` — verdicts=[boot Killed,\n  rel Killed, brain Killed]; the brain's kill line names it `(child process of PID 46896)` — the\n  daemon — so the daemon was still resident too and was taken down by the `Child` handle, not the\n  stop. A stop that worked would have left the reaper `gone`. This rules OUT the innocent reading\n  (stop doesn't manage services): the stop did not reach the DAEMON either.\n- **NOT ESTABLISHED — two rungs, neither discriminated:** (1) the rig seeds a `doyle` perch with\n  `std::process::id()`, satisfying `ceremony_agent_ground`'s pid-ancestry rung for every child of\n  the harness; (2) the rig never scrubs `OWL_SESSION_ID`/`SPT_AGENT_ID`/`SPT_ENDPOINT_ID` from its\n  teardown commands, and the measuring run launched from a live agent session, so the env rung was\n  live too. `--force` overrides neither. The stop's output is discarded at the call site\n  (`let _ = spt(...)`) — no diagnostic names a denial, and no claim is made that one fired.\n  Settling it is one run with the stop's stderr captured — on the CI runner AS WELL AS the dev box,\n  since the rungs fire on different machines.\n- **Why it matters beyond this rig:** REQ-TEST-RIG-DAEMON-TEARDOWN-PROVEN's own failure shape\n  inside a rig that passes — teardown completeness rested entirely on breadcrumb kills that were,\n  until IR-18, bare `taskkill /F /T` on unauthenticated pids; the most trustworthy-LOOKING\n  component (an explicit `--force` stop) was doing nothing while the least trustworthy one did all\n  the work. Exactly why the population gate exists rather than per-pid checks alone.\n- **Remedy caution (the sentence that must not drop):** the prescribed fix (seed pid 0, scrub the\n  three markers — REQ-TEST-RIG-DAEMON-TEARDOWN-PROVEN's own gate) is NOT free here: this rig's\n  `doyle` perch pid is load-bearing for the shell bind-by-token legs, so the two remedies are not\n  interchangeable — a lane taking this must check which legs depend on the pid before changing it,\n  or it fixes the stop and breaks the REQ-INSTALL-11 legs the rig exists for. Kin:\n  REQ-BROKER-STOP-ENDPOINT-DENY (the refusal being worked around).\n- **LANE-LINKED 2026-08-30 (#242 close sweep):** hertz's queued daemon-leak fixup lane carries\n  this entry (brief cites IR-7/17/20/34/35/63); leaves the register when that lane lands.\n- **Ripe when:** a hertz test-hardening wave, or alongside the (b) helper lane's touch of this rig.\n- **Size:** small (stderr-captured discrimination run × two machines, then the scoped remedy).\n\n### IR-54 — golden-head-intake runbook: three properties this cut proved should be construction, not discipline\n- **Status:** BUILT 2026-08-29 — PR #176 (`880b3b9c`, landed on main via `37368263`).\n  · **Origin:** PORTER (#205) v0.59.0 cut, 2026-08-21 — doyle (gater) + deployah (driver),\n  both mechanisms measured at the cut, neither cost this run anything because the driver caught\n  them by hand. Filed at the release-close register sweep.\n- **What/why (three runbook amendments, one lane):**\n  1. **Release-shaping at ASSEMBLY intake, not post-golden.** The head arrived code-complete\n     but not release-shaped (no version bump, stale CHANGELOG top section) — 5 of the last 6\n     cuts. v0.59.0 fixed it by authoring version material BEFORE the golden run, which is what\n     produced the four-name shape (ruled sha == main tip == golden ref == tag == `c62904e7`,\n     first time in six cuts; the previous five each argued a post-golden delta inert). Amend\n     `docs/golden-head-intake` so the gater's assembly checklist asks the release-shaping\n     question at intake and the driver never authors on top.\n  2. **Never-executed-cells list is a hand-off artifact.** The runbook makes it a\n     gater-compiles / driver-re-checks item; PORTER's handoff omitted it and the driver had to\n     ask. Name it in the assembly checklist beside the greenlit-form delta: which new cells'\n     first CI execution is this golden, and where each HAS executed (lane gate / assembled\n     head) — it converts a golden red from an RCA into a lookup.\n  3. **Lockfile-refresh rule states the PROPERTY, not the command.** Step 1 prescribes\n     `cargo metadata --offline`; the driver used `cargo update --workspace --offline` and\n     proved the actual rule by diff (workspace members only, third-party pins untouched —\n     14 first-party line pairs, 90 third-party unchanged). The property is the rule and the\n     diff is its evidence (the standing by-diff rule exists because counting misread v0.39.4\n     and v0.41.0 in opposite directions — and the `windows-sys` 0.59.0 collision was LIVE at\n     this cut, the exact condition where counting fabricates a 15th \"first-party\" bump);\n     demote the command to an example vehicle.\n- **Built evidence:** `docs/RELEASE-RUNBOOK.md` now asks the release-shaping question at assembly\n  intake, makes the never-executed-cells list part of the hand-off itself, and states lock refresh\n  as a diff-proven property with commands demoted to example vehicles. PR #176 passed\n  `traceable-reqs check`; the v0.65.0 cut had already exercised the release-shaped-head rule.\n- **Size:** small (one runbook doc lane; no code).\n\n## IN-FLIGHT ON THE BOARD (not re-homed — live WIP lanes)\n\n- releases#93 (servicehost swap test pid-inequality), releases#47 (thin-lane unit(Windows)\n  isolation class), releases#32 (worker_lifecycle_e2e Phase A intermittent) — infra-shaped but WIP;\n  a live lane is never re-homed mid-flight. When each closes, any residue lands here as a new entry.\n\n## BUILT / RETIRED\n\n### IR-15 — provably_gone is pid-only on Windows: teardown tests can fabricate reds\n- **Status:** BUILT 2026-08-03 · **Origin:** golden 30776330383 red on the #125 fix lane (2026-08-02)\n- **Lane:** hertz `golden/ir15` @a5042ec — REQ-TEST-LIVENESS-ORACLE-AUTHENTICATED (impl+unit): one\n  shared authenticated death-oracle test helper backed by `spt_procident::process_identity`\n  (identity pinned at find time, re-verified at assert), both pid-only polling sites repinned\n  (daemon.rs teardown test; endpoint_lifecycle.rs relay_pid). Ruled polarity held: Absent⇒gone,\n  Present(same start)⇒not gone, Present(different)⇒gone, Unproven⇒NOT gone, missing-stamp\n  degrades to pid-only loudly — every unknown errs toward the recoverable red, zero new\n  false-green paths. Linux caveat documented in the helper (10ms jiffies: Present(different) is\n  narrowing, not decisive; same-tick reuse errs red, safe).\n- **Golden:** run 30782259675 red on `resident_service_e2e` bring-up — delta exonerated (unrelated\n  family, now [[IR-17]]; same job minted [[IR-8]]'s defining specimen). Same-sha rerun 30784469908\n  GREEN; main ff'd to a5042ec.\n- **A/B discriminator (hertz):** 80/80 green both arms, quiet + churn phases; churn arm\n  positive-controlled (pid-allocator wrap observed <400ms, so reuse pressure was REAL in the churn\n  arm); rule-of-three bounds the original flake at ~7.5%/run/sha. Specimen 30776330383 remains\n  not-reproduced, cause unidentified — the repin removes the false-red MECHANISM; it does not\n  adjudicate the specimen. [[IR-16]]'s kill-side arm (TerminateJobObject return discarded) stays\n  a live discriminating instrument for any recurrence — and since 2026-08-03 it is no longer the\n  only one: [[IR-18]] (the test's OWN bare breadcrumb tree-kill) is the second kill-side candidate,\n  test-side rather than product-side. A recurrence must discriminate between them, not assume\n  either: IR-16's arm is a job whose termination silently half-fails (survivor still holds the\n  captured image); IR-18's is a victim killed by a bare pid it no longer owns —\n  `broker_survived=false` with the boot service still ALIVE and its message spooled. (An earlier\n  spelling of IR-18's signature here said \"empty stderr\"; retracted — empty stderr is present on\n  healthy runs and discriminates nothing.)\n\n### IR-21 — CLASS: a helper binary's build is never requested, only its LOCATION is, so any narrow invocation manufactures a red that belongs to the rig\n- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane. · **Origin:** todlando 2026-08-03. Filed as one instance, rewritten as a CLASS the\n  same day when a second member appeared, rewritten AGAIN when the mechanism was measured — the\n  first two versions described symptoms and got the remedy wrong. **Corrected a fourth time the same\n  day**: remedy (1) claimed the 11 same-package sites were missing a build edge, and todlando\n  falsified that by measurement while executing it (replicated independently by doyle). The error was\n  doyle's to carry — it was ruled on, not just written. The general rule that refutes it was already\n  in this entry's own CI-member section; diagnosing a class does not inoculate you against drawing\n  its opposite consequence one section later.\n- **Numbers below re-derived on `main` @`3efd7e6` over `git ls-files` (tracked files only). Each\n  carries its command; re-run rather than cite.**\n- ⚠ **Scan-root hazard, measured 2026-08-03 and worse than first reported:** a naive recursive\n  `grep -r` from the project root inflates by **~35×**, not the ~5× an earlier draft of this entry\n  claimed — 426 tracked `.rs` against 14,865 on disk with `target/` excluded, because `.worktrees/`\n  holds full copies of the tree. **And the unscoped grep does not COMPLETE** (still running at a\n  120s timeout while `git ls-files` returns instantly), so the failure mode is not only a wrong\n  number but a command that reads as hung on a tree where dozens of worktrees are normal. Use\n  `git grep` or `git ls-files | xargs grep`; both are scoped to tracked files by construction.\n\n\n[Showing lines 1080-1302 of 6938. Use :1303 to continue]"}],"details":{"truncation":{"content":"  (reap.rs:59-63, resident_service_e2e's mock_pid :100-106, and the shape wherever a test reads a\r\n  self-written pid file) — so (b) lands ONE shared read-a-pid-breadcrumb helper that distinguishes\r\n  absent from unreadable ONCE, adopted at the enumerated sites, not a per-site token split; the\r\n  single-source-discriminant rule, applied before a fourth site mints itself.\r\n  **THIRD SITE CONFIRMED AT SOURCE (deployah, read-only 2026-08-04) — it was a predicted SHAPE and\r\n  is now an address:** `crates/spt/tests/resident_service_e2e.rs:136-137`, `brain_ready`, which\r\n  `.ok()?`s BOTH the read and the JSON parse — two collapses in two lines, the self-written-pid-file\r\n  shape this entry predicted. What makes it the worst of the three rather than the third of three:\r\n  its output feeds `brain_seed`, a population-sweep SEED, so an unreadable `brain.ready` silently\r\n  drops a whole subtree from the sweep. The other two sites lose one pid; this one degrades the very\r\n  instrument that is supposed to cover them, and it does so while the sweep still reports clean —\r\n  [[IR-8]]'s sentence again, now inside the instrument rather than beside it. The (b) lane's helper\r\n  therefore has to be adopted at this site to be worth landing at all. Still deployah's,\r\n  still after hertz's lane; hertz's lane does NOT wait for it (the population assertion covers the\r\n  leak class independent of pid bookkeeping — that is its virtue). (b) INTAKE ITEM (doyle gate on\r\n  the IR-18 lane, 2026-08-03, deferred there deliberately): the lane's verdict-gate SOUND-arm\r\n  comment reads \"provably not there\", which overclaims for `no-breadcrumb` (absence-of-knowledge,\r\n  not proof — the scoped reading belongs at that arm); comment-only, and (b) rewrites that arm\r\n  when `unreadable-breadcrumb` splits out, so it lands there rather than costing a solo respin.\r\n  SECOND (b) INTAKE ITEM (hertz self-noted at re-gate, doyle-ruled deferred): cleanliness is\r\n  currently stated at THREE sites (two asserts + `is_clean`) — the drift that produced the\r\n  scope_lost condition bug (a failed edit followed by a narrower successful one replaced the\r\n  message but not the condition; the artifact of that failure mode IS message/code disagreement).\r\n  (b) consolidates to conditions derived from one source, weighing the two-message diagnostic\r\n  split it would cost. The\r\n  exhaustive panic-catch-all match is what makes the split safe to do later: the new token lands\r\n  loud on first fire in every consuming gate, forced to be classified, never silently passed. Until then the scoped reading above is the\r\n  gate's contract — and the LANE BUILDER writes that scoped reading into the match's SOUND-arm\r\n  comment (the sketch's \"nothing to read is nothing to kill\" is the exact inference the source\r\n  forbids; the comment must not teach the false step); (2) the gate closes over the\r\n  token set — SPELLED BUILDABLY (hertz correction 2026-08-03; the earlier \"no wildcard arm\" wording\r\n  is an instruction rustc rejects, since the refusal reason is a `&'static str` (:55) and a string\r\n  match always requires a catch-all): the match names the six SOUND tokens as a pass arm, the three\r\n  TRAP tokens as a panic arm, and the REQUIRED catch-all arm is not a wildcard PASS — it panics\r\n  naming the unknown token (\"unclassified reap refusal token — classify it in this match\"), so\r\n  upstream drift announces itself the first run it fires instead of sliding into a silent pass.\r\n  Runtime fail-closed, not compile-time: compile-time closure needs the reason to become an enum in\r\n  common/reap.rs, an upstream change touching every consumer — ruled NOT smuggled into this lane\r\n  (candidate for its own thin lane if ever wanted; doyle concurs runtime fail-closed is\r\n  proportionate). Direction of the default, kept in the record: a missed trap state is an invisible\r\n  leak wearing the reap line a reviewer wants to see; an unclassified harmless token is a loud red\r\n  costing one edit. Cheap and loud beats silent and wrong. (Count hygiene, hertz self-flagged: a\r\n  single-line grep for the refuse() sites returns five of nine — three wrap across lines; the nine\r\n  stands on reading, not the grep. The sweep-count trap in miniature.)\r\n- **Prior observed instance of the class, in-tree (hertz 2026-08-03 — stated to understate):**\r\n  reap.rs:3–11 documents the measurement and a casualty: pid reuse on the Windows gate box at\r\n  2.2s minimum / p50 11.7s under a Phase-A battery, and a concurrent test process killed by a bare\r\n  kill on a stale breadcrumb pid, dying with bare exit 1 and no panic — the observed\r\n  `worker_lifecycle_e2e` red in golden job 90742055246 (that test's intermittent class is board\r\n  releases#32, still in-flight). Different test, different job — it does NOT reproduce this entry's\r\n  specimen and promotes nothing; what it settles is that the class is real IN THIS SUITE with a\r\n  named victim, and the authenticated reaper is the remedy someone already built for it —\r\n  resident_service_e2e simply never adopted it. Two shape-predictions it supplies, made before this\r\n  specimen existed: the p50 11.7s reuse window is short against this test's 45s waits and ~124s\r\n  runtime (window wide open). (A second claimed match — \"bare-exit-1-no-panic matches the empty\r\n  daemon.stderr.log\" — is RETRACTED as a category error, hertz+deployah 2026-08-03: reap.rs's\r\n  phrase describes the VICTIM TEST PROCESS dying, not a daemon's log; two processes, two\r\n  artifacts.) Predictions, not proof; the specimen stays CANDIDATE — shape since reproduced on\r\n  demand, agent unidentified (see the control record above).\r\n- **Rig near-miss, caught before first execution (hertz 2026-08-03) — kept as design justification,\r\n  not an anecdote:** the positive-control arm's first draft selected its victim machine-wide\r\n  (`Win32_Process Name='spt.exe'` + cmdline match `daemon run`, then force-kill). hfenduleam is the\r\n  Windows CI runner as well as a dev box, so that filter matches CI's own test daemons: run while a\r\n  leg was live, it would have force-killed a running job's daemon and reported the result as a\r\n  measurement — fabricating a red in someone else's job, the exact class this entry documents.\r\n  Corrected to a parent-scoped selector (daemon = child of the test pid; service = child of that\r\n  daemon); `CREATE_BREAKAWAY_FROM_JOB` does not weaken parent-id attribution, since breakaway leaves\r\n  the JOB, not the parent record — which is also why the orphaned svcmock stays attributable to the\r\n  daemon that spawned it. **The load bought the catch** (blocked on the box ⇒ re-read instead of\r\n  ran). Bearing on the fix: the INSTRUMENT built to study a bare-selector reaper was itself written\r\n  with a bare selector. The remedy therefore cannot be \"be careful\" — the authenticated path must be\r\n  the only one within reach in this suite.\r\n- **Ripe when:** RIPE NOW, and not gated on the rate run that was cancelled.\r\n- **Size:** small.\r\n\r\n### IR-19 — Docs-only pushes to main run full unit legs (classifier is PR-only) — intent unverified\r\n- **Status:** RETIRED 2026-08-18 — intentional for main pushes, not a classifier defect. · **Origin:** hertz observation 2026-08-03 (register-push\r\n  cadence gated his rig behind repeated hfenduleam unit legs); mechanism verified by doyle at\r\n  source same night.\r\n- **What/why:** `ci.yml`'s `changes` job classifies docs-only diffs ONLY for `pull_request` events\r\n  — push events hardcode `code=true` (ci.yml:45–48, an explicit branch, not a fallthrough), so\r\n  every docs-only push to main spins both full unit legs. Tonight: five register docs pushes each\r\n  queued a Windows unit leg on hfenduleam; concurrency kept one running + one pending (main is\r\n  never cancelled in-progress, pending runs supersede — the recorded behavior matches ci.yml:9–13).\r\n  FINDING SETTLED (deployah, same night, from the workflow): this is not intent — it is a scope\r\n  the classifier never had; the `*.md` / `traceable-reqs.toml` case arms are only ever REACHED on\r\n  pull_request (the early-return precedes them), and golden.yml's own hardcoded `code=true` is\r\n  unrelated (golden triggers only on golden/**). REMEDY STILL OPEN on a named tension: extending\r\n  the classifier to pushes leaves a docs-only main TIP with no run of its own — fine if\r\n  tested-sha==merged-sha means \"the code at this sha was tested\" (it was, at the last code sha),\r\n  not fine if any gate or reader takes \"main tip has a green run\" as the check. One person reads\r\n  the consuming gates before any remedy (doyle, at the next CI-touching wave) — three assuming is\r\n  how this class ships.\r\n- **Resolution:** the consuming contract already answers the held question:\r\n  `REQ-CI-DOCS-ONLY-THIN` is PR-only and explicitly says ADR-0050 supersedes\r\n  it for main pushes. Main-tip evidence remains full by design; no classifier\r\n  branch was widened.\r\n- **Interim rule (doyle, same night):** batch register edits into one push instead of landing them\r\n  as they occur — the cadence is a real gate on whoever is queued behind the runner.\r\n- **Ripe when:** next CI-touching wave, after the intent question is answered on the REQ record.\r\n- **Size:** small (one conditional, if the answer is \"extend\").\r\n- **Composed:** LOCKSMITH (#132) — doyle reads the consuming gates during the batch's CI-touching\r\n  wave (the intent question), BEFORE any classifier remedy. 2026-08-03.\r\n\r\n### IR-20 — resident_service_e2e's `spt daemon stop --force` does not stop the daemon; teardown is complete only because the kills are\r\n- **Status:** open · **Origin:** hertz 2026-08-03, measured on the IR-18 lane's own clean run\r\n  (hfenduleam, log kept); routed text, doyle-landed.\r\n- **MEASURED:** teardown runs `spt(&[\"daemon\",\"stop\",\"--force\"])` then reaps. At reaper fire, every\r\n  target was still ALIVE and every verdict was `Killed`, not `gone` — verdicts=[boot Killed,\r\n  rel Killed, brain Killed]; the brain's kill line names it `(child process of PID 46896)` — the\r\n  daemon — so the daemon was still resident too and was taken down by the `Child` handle, not the\r\n  stop. A stop that worked would have left the reaper `gone`. This rules OUT the innocent reading\r\n  (stop doesn't manage services): the stop did not reach the DAEMON either.\r\n- **NOT ESTABLISHED — two rungs, neither discriminated:** (1) the rig seeds a `doyle` perch with\r\n  `std::process::id()`, satisfying `ceremony_agent_ground`'s pid-ancestry rung for every child of\r\n  the harness; (2) the rig never scrubs `OWL_SESSION_ID`/`SPT_AGENT_ID`/`SPT_ENDPOINT_ID` from its\r\n  teardown commands, and the measuring run launched from a live agent session, so the env rung was\r\n  live too. `--force` overrides neither. The stop's output is discarded at the call site\r\n  (`let _ = spt(...)`) — no diagnostic names a denial, and no claim is made that one fired.\r\n  Settling it is one run with the stop's stderr captured — on the CI runner AS WELL AS the dev box,\r\n  since the rungs fire on different machines.\r\n- **Why it matters beyond this rig:** REQ-TEST-RIG-DAEMON-TEARDOWN-PROVEN's own failure shape\r\n  inside a rig that passes — teardown completeness rested entirely on breadcrumb kills that were,\r\n  until IR-18, bare `taskkill /F /T` on unauthenticated pids; the most trustworthy-LOOKING\r\n  component (an explicit `--force` stop) was doing nothing while the least trustworthy one did all\r\n  the work. Exactly why the population gate exists rather than per-pid checks alone.\r\n- **Remedy caution (the sentence that must not drop):** the prescribed fix (seed pid 0, scrub the\r\n  three markers — REQ-TEST-RIG-DAEMON-TEARDOWN-PROVEN's own gate) is NOT free here: this rig's\r\n  `doyle` perch pid is load-bearing for the shell bind-by-token legs, so the two remedies are not\r\n  interchangeable — a lane taking this must check which legs depend on the pid before changing it,\r\n  or it fixes the stop and breaks the REQ-INSTALL-11 legs the rig exists for. Kin:\r\n  REQ-BROKER-STOP-ENDPOINT-DENY (the refusal being worked around).\r\n- **LANE-LINKED 2026-08-30 (#242 close sweep):** hertz's queued daemon-leak fixup lane carries\r\n  this entry (brief cites IR-7/17/20/34/35/63); leaves the register when that lane lands.\r\n- **Ripe when:** a hertz test-hardening wave, or alongside the (b) helper lane's touch of this rig.\r\n- **Size:** small (stderr-captured discrimination run × two machines, then the scoped remedy).\r\n\r\n### IR-54 — golden-head-intake runbook: three properties this cut proved should be construction, not discipline\r\n- **Status:** BUILT 2026-08-29 — PR #176 (`880b3b9c`, landed on main via `37368263`).\r\n  · **Origin:** PORTER (#205) v0.59.0 cut, 2026-08-21 — doyle (gater) + deployah (driver),\r\n  both mechanisms measured at the cut, neither cost this run anything because the driver caught\r\n  them by hand. Filed at the release-close register sweep.\r\n- **What/why (three runbook amendments, one lane):**\r\n  1. **Release-shaping at ASSEMBLY intake, not post-golden.** The head arrived code-complete\r\n     but not release-shaped (no version bump, stale CHANGELOG top section) — 5 of the last 6\r\n     cuts. v0.59.0 fixed it by authoring version material BEFORE the golden run, which is what\r\n     produced the four-name shape (ruled sha == main tip == golden ref == tag == `c62904e7`,\r\n     first time in six cuts; the previous five each argued a post-golden delta inert). Amend\r\n     `docs/golden-head-intake` so the gater's assembly checklist asks the release-shaping\r\n     question at intake and the driver never authors on top.\r\n  2. **Never-executed-cells list is a hand-off artifact.** The runbook makes it a\r\n     gater-compiles / driver-re-checks item; PORTER's handoff omitted it and the driver had to\r\n     ask. Name it in the assembly checklist beside the greenlit-form delta: which new cells'\r\n     first CI execution is this golden, and where each HAS executed (lane gate / assembled\r\n     head) — it converts a golden red from an RCA into a lookup.\r\n  3. **Lockfile-refresh rule states the PROPERTY, not the command.** Step 1 prescribes\r\n     `cargo metadata --offline`; the driver used `cargo update --workspace --offline` and\r\n     proved the actual rule by diff (workspace members only, third-party pins untouched —\r\n     14 first-party line pairs, 90 third-party unchanged). The property is the rule and the\r\n     diff is its evidence (the standing by-diff rule exists because counting misread v0.39.4\r\n     and v0.41.0 in opposite directions — and the `windows-sys` 0.59.0 collision was LIVE at\r\n     this cut, the exact condition where counting fabricates a 15th \"first-party\" bump);\r\n     demote the command to an example vehicle.\r\n- **Built evidence:** `docs/RELEASE-RUNBOOK.md` now asks the release-shaping question at assembly\r\n  intake, makes the never-executed-cells list part of the hand-off itself, and states lock refresh\r\n  as a diff-proven property with commands demoted to example vehicles. PR #176 passed\r\n  `traceable-reqs check`; the v0.65.0 cut had already exercised the release-shaped-head rule.\r\n- **Size:** small (one runbook doc lane; no code).\r\n\r\n## IN-FLIGHT ON THE BOARD (not re-homed — live WIP lanes)\r\n\r\n- releases#93 (servicehost swap test pid-inequality), releases#47 (thin-lane unit(Windows)\r\n  isolation class), releases#32 (worker_lifecycle_e2e Phase A intermittent) — infra-shaped but WIP;\r\n  a live lane is never re-homed mid-flight. When each closes, any residue lands here as a new entry.\r\n\r\n## BUILT / RETIRED\r\n\r\n### IR-15 — provably_gone is pid-only on Windows: teardown tests can fabricate reds\r\n- **Status:** BUILT 2026-08-03 · **Origin:** golden 30776330383 red on the #125 fix lane (2026-08-02)\r\n- **Lane:** hertz `golden/ir15` @a5042ec — REQ-TEST-LIVENESS-ORACLE-AUTHENTICATED (impl+unit): one\r\n  shared authenticated death-oracle test helper backed by `spt_procident::process_identity`\r\n  (identity pinned at find time, re-verified at assert), both pid-only polling sites repinned\r\n  (daemon.rs teardown test; endpoint_lifecycle.rs relay_pid). Ruled polarity held: Absent⇒gone,\r\n  Present(same start)⇒not gone, Present(different)⇒gone, Unproven⇒NOT gone, missing-stamp\r\n  degrades to pid-only loudly — every unknown errs toward the recoverable red, zero new\r\n  false-green paths. Linux caveat documented in the helper (10ms jiffies: Present(different) is\r\n  narrowing, not decisive; same-tick reuse errs red, safe).\r\n- **Golden:** run 30782259675 red on `resident_service_e2e` bring-up — delta exonerated (unrelated\r\n  family, now [[IR-17]]; same job minted [[IR-8]]'s defining specimen). Same-sha rerun 30784469908\r\n  GREEN; main ff'd to a5042ec.\r\n- **A/B discriminator (hertz):** 80/80 green both arms, quiet + churn phases; churn arm\r\n  positive-controlled (pid-allocator wrap observed <400ms, so reuse pressure was REAL in the churn\r\n  arm); rule-of-three bounds the original flake at ~7.5%/run/sha. Specimen 30776330383 remains\r\n  not-reproduced, cause unidentified — the repin removes the false-red MECHANISM; it does not\r\n  adjudicate the specimen. [[IR-16]]'s kill-side arm (TerminateJobObject return discarded) stays\r\n  a live discriminating instrument for any recurrence — and since 2026-08-03 it is no longer the\r\n  only one: [[IR-18]] (the test's OWN bare breadcrumb tree-kill) is the second kill-side candidate,\r\n  test-side rather than product-side. A recurrence must discriminate between them, not assume\r\n  either: IR-16's arm is a job whose termination silently half-fails (survivor still holds the\r\n  captured image); IR-18's is a victim killed by a bare pid it no longer owns —\r\n  `broker_survived=false` with the boot service still ALIVE and its message spooled. (An earlier\r\n  spelling of IR-18's signature here said \"empty stderr\"; retracted — empty stderr is present on\r\n  healthy runs and discriminates nothing.)\r\n\r\n### IR-21 — CLASS: a helper binary's build is never requested, only its LOCATION is, so any narrow invocation manufactures a red that belongs to the rig\r\n- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane. · **Origin:** todlando 2026-08-03. Filed as one instance, rewritten as a CLASS the\r\n  same day when a second member appeared, rewritten AGAIN when the mechanism was measured — the\r\n  first two versions described symptoms and got the remedy wrong. **Corrected a fourth time the same\r\n  day**: remedy (1) claimed the 11 same-package sites were missing a build edge, and todlando\r\n  falsified that by measurement while executing it (replicated independently by doyle). The error was\r\n  doyle's to carry — it was ruled on, not just written. The general rule that refutes it was already\r\n  in this entry's own CI-member section; diagnosing a class does not inoculate you against drawing\r\n  its opposite consequence one section later.\r\n- **Numbers below re-derived on `main` @`3efd7e6` over `git ls-files` (tracked files only). Each\r\n  carries its command; re-run rather than cite.**\r\n- ⚠ **Scan-root hazard, measured 2026-08-03 and worse than first reported:** a naive recursive\r\n  `grep -r` from the project root inflates by **~35×**, not the ~5× an earlier draft of this entry\r\n  claimed — 426 tracked `.rs` against 14,865 on disk with `target/` excluded, because `.worktrees/`\r\n  holds full copies of the tree. **And the unscoped grep does not COMPLETE** (still running at a\r\n  120s timeout while `git ls-files` returns instantly), so the failure mode is not only a wrong\r\n  number but a command that reads as hung on a tree where dozens of worktrees are normal. Use\r\n  `git grep` or `git ls-files | xargs grep`; both are scoped to tracked files by construction.\r\n\r","truncated":true,"truncatedBy":"lines","totalLines":5859,"totalBytes":19707,"outputLines":223,"outputBytes":19707,"lastLinePartial":false,"firstLineExceedsLimit":false},"totalLines":6938,"displayContent":{"text":"  (reap.rs:59-63, resident_service_e2e's mock_pid :100-106, and the shape wherever a test reads a\r\n  self-written pid file) — so (b) lands ONE shared read-a-pid-breadcrumb helper that distinguishes\r\n  absent from unreadable ONCE, adopted at the enumerated sites, not a per-site token split; the\r\n  single-source-discriminant rule, applied before a fourth site mints itself.\r\n  **THIRD SITE CONFIRMED AT SOURCE (deployah, read-only 2026-08-04) — it was a predicted SHAPE and\r\n  is now an address:** `crates/spt/tests/resident_service_e2e.rs:136-137`, `brain_ready`, which\r\n  `.ok()?`s BOTH the read and the JSON parse — two collapses in two lines, the self-written-pid-file\r\n  shape this entry predicted. What makes it the worst of the three rather than the third of three:\r\n  its output feeds `brain_seed`, a population-sweep SEED, so an unreadable `brain.ready` silently\r\n  drops a whole subtree from the sweep. The other two sites lose one pid; this one degrades the very\r\n  instrument that is supposed to cover them, and it does so while the sweep still reports clean —\r\n  [[IR-8]]'s sentence again, now inside the instrument rather than beside it. The (b) lane's helper\r\n  therefore has to be adopted at this site to be worth landing at all. Still deployah's,\r\n  still after hertz's lane; hertz's lane does NOT wait for it (the population assertion covers the\r\n  leak class independent of pid bookkeeping — that is its virtue). (b) INTAKE ITEM (doyle gate on\r\n  the IR-18 lane, 2026-08-03, deferred there deliberately): the lane's verdict-gate SOUND-arm\r\n  comment reads \"provably not there\", which overclaims for `no-breadcrumb` (absence-of-knowledge,\r\n  not proof — the scoped reading belongs at that arm); comment-only, and (b) rewrites that arm\r\n  when `unreadable-breadcrumb` splits out, so it lands there rather than costing a solo respin.\r\n  SECOND (b) INTAKE ITEM (hertz self-noted at re-gate, doyle-ruled deferred): cleanliness is\r\n  currently stated at THREE sites (two asserts + `is_clean`) — the drift that produced the\r\n  scope_lost condition bug (a failed edit followed by a narrower successful one replaced the\r\n  message but not the condition; the artifact of that failure mode IS message/code disagreement).\r\n  (b) consolidates to conditions derived from one source, weighing the two-message diagnostic\r\n  split it would cost. The\r\n  exhaustive panic-catch-all match is what makes the split safe to do later: the new token lands\r\n  loud on first fire in every consuming gate, forced to be classified, never silently passed. Until then the scoped reading above is the\r\n  gate's contract — and the LANE BUILDER writes that scoped reading into the match's SOUND-arm\r\n  comment (the sketch's \"nothing to read is nothing to kill\" is the exact inference the source\r\n  forbids; the comment must not teach the false step); (2) the gate closes over the\r\n  token set — SPELLED BUILDABLY (hertz correction 2026-08-03; the earlier \"no wildcard arm\" wording\r\n  is an instruction rustc rejects, since the refusal reason is a `&'static str` (:55) and a string\r\n  match always requires a catch-all): the match names the six SOUND tokens as a pass arm, the three\r\n  TRAP tokens as a panic arm, and the REQUIRED catch-all arm is not a wildcard PASS — it panics\r\n  naming the unknown token (\"unclassified reap refusal token — classify it in this match\"), so\r\n  upstream drift announces itself the first run it fires instead of sliding into a silent pass.\r\n  Runtime fail-closed, not compile-time: compile-time closure needs the reason to become an enum in\r\n  common/reap.rs, an upstream change touching every consumer — ruled NOT smuggled into this lane\r\n  (candidate for its own thin lane if ever wanted; doyle concurs runtime fail-closed is\r\n  proportionate). Direction of the default, kept in the record: a missed trap state is an invisible\r\n  leak wearing the reap line a reviewer wants to see; an unclassified harmless token is a loud red\r\n  costing one edit. Cheap and loud beats silent and wrong. (Count hygiene, hertz self-flagged: a\r\n  single-line grep for the refuse() sites returns five of nine — three wrap across lines; the nine\r\n  stands on reading, not the grep. The sweep-count trap in miniature.)\r\n- **Prior observed instance of the class, in-tree (hertz 2026-08-03 — stated to understate):**\r\n  reap.rs:3–11 documents the measurement and a casualty: pid reuse on the Windows gate box at\r\n  2.2s minimum / p50 11.7s under a Phase-A battery, and a concurrent test process killed by a bare\r\n  kill on a stale breadcrumb pid, dying with bare exit 1 and no panic — the observed\r\n  `worker_lifecycle_e2e` red in golden job 90742055246 (that test's intermittent class is board\r\n  releases#32, still in-flight). Different test, different job — it does NOT reproduce this entry's\r\n  specimen and promotes nothing; what it settles is that the class is real IN THIS SUITE with a\r\n  named victim, and the authenticated reaper is the remedy someone already built for it —\r\n  resident_service_e2e simply never adopted it. Two shape-predictions it supplies, made before this\r\n  specimen existed: the p50 11.7s reuse window is short against this test's 45s waits and ~124s\r\n  runtime (window wide open). (A second claimed match — \"bare-exit-1-no-panic matches the empty\r\n  daemon.stderr.log\" — is RETRACTED as a category error, hertz+deployah 2026-08-03: reap.rs's\r\n  phrase describes the VICTIM TEST PROCESS dying, not a daemon's log; two processes, two\r\n  artifacts.) Predictions, not proof; the specimen stays CANDIDATE — shape since reproduced on\r\n  demand, agent unidentified (see the control record above).\r\n- **Rig near-miss, caught before first execution (hertz 2026-08-03) — kept as design justification,\r\n  not an anecdote:** the positive-control arm's first draft selected its victim machine-wide\r\n  (`Win32_Process Name='spt.exe'` + cmdline match `daemon run`, then force-kill). hfenduleam is the\r\n  Windows CI runner as well as a dev box, so that filter matches CI's own test daemons: run while a\r\n  leg was live, it would have force-killed a running job's daemon and reported the result as a\r\n  measurement — fabricating a red in someone else's job, the exact class this entry documents.\r\n  Corrected to a parent-scoped selector (daemon = child of the test pid; service = child of that\r\n  daemon); `CREATE_BREAKAWAY_FROM_JOB` does not weaken parent-id attribution, since breakaway leaves\r\n  the JOB, not the parent record — which is also why the orphaned svcmock stays attributable to the\r\n  daemon that spawned it. **The load bought the catch** (blocked on the box ⇒ re-read instead of\r\n  ran). Bearing on the fix: the INSTRUMENT built to study a bare-selector reaper was itself written\r\n  with a bare selector. The remedy therefore cannot be \"be careful\" — the authenticated path must be\r\n  the only one within reach in this suite.\r\n- **Ripe when:** RIPE NOW, and not gated on the rate run that was cancelled.\r\n- **Size:** small.\r\n\r\n### IR-19 — Docs-only pushes to main run full unit legs (classifier is PR-only) — intent unverified\r\n- **Status:** RETIRED 2026-08-18 — intentional for main pushes, not a classifier defect. · **Origin:** hertz observation 2026-08-03 (register-push\r\n  cadence gated his rig behind repeated hfenduleam unit legs); mechanism verified by doyle at\r\n  source same night.\r\n- **What/why:** `ci.yml`'s `changes` job classifies docs-only diffs ONLY for `pull_request` events\r\n  — push events hardcode `code=true` (ci.yml:45–48, an explicit branch, not a fallthrough), so\r\n  every docs-only push to main spins both full unit legs. Tonight: five register docs pushes each\r\n  queued a Windows unit leg on hfenduleam; concurrency kept one running + one pending (main is\r\n  never cancelled in-progress, pending runs supersede — the recorded behavior matches ci.yml:9–13).\r\n  FINDING SETTLED (deployah, same night, from the workflow): this is not intent — it is a scope\r\n  the classifier never had; the `*.md` / `traceable-reqs.toml` case arms are only ever REACHED on\r\n  pull_request (the early-return precedes them), and golden.yml's own hardcoded `code=true` is\r\n  unrelated (golden triggers only on golden/**). REMEDY STILL OPEN on a named tension: extending\r\n  the classifier to pushes leaves a docs-only main TIP with no run of its own — fine if\r\n  tested-sha==merged-sha means \"the code at this sha was tested\" (it was, at the last code sha),\r\n  not fine if any gate or reader takes \"main tip has a green run\" as the check. One person reads\r\n  the consuming gates before any remedy (doyle, at the next CI-touching wave) — three assuming is\r\n  how this class ships.\r\n- **Resolution:** the consuming contract already answers the held question:\r\n  `REQ-CI-DOCS-ONLY-THIN` is PR-only and explicitly says ADR-0050 supersedes\r\n  it for main pushes. Main-tip evidence remains full by design; no classifier\r\n  branch was widened.\r\n- **Interim rule (doyle, same night):** batch register edits into one push instead of landing them\r\n  as they occur — the cadence is a real gate on whoever is queued behind the runner.\r\n- **Ripe when:** next CI-touching wave, after the intent question is answered on the REQ record.\r\n- **Size:** small (one conditional, if the answer is \"extend\").\r\n- **Composed:** LOCKSMITH (#132) — doyle reads the consuming gates during the batch's CI-touching\r\n  wave (the intent question), BEFORE any classifier remedy. 2026-08-03.\r\n\r\n### IR-20 — resident_service_e2e's `spt daemon stop --force` does not stop the daemon; teardown is complete only because the kills are\r\n- **Status:** open · **Origin:** hertz 2026-08-03, measured on the IR-18 lane's own clean run\r\n  (hfenduleam, log kept); routed text, doyle-landed.\r\n- **MEASURED:** teardown runs `spt(&[\"daemon\",\"stop\",\"--force\"])` then reaps. At reaper fire, every\r\n  target was still ALIVE and every verdict was `Killed`, not `gone` — verdicts=[boot Killed,\r\n  rel Killed, brain Killed]; the brain's kill line names it `(child process of PID 46896)` — the\r\n  daemon — so the daemon was still resident too and was taken down by the `Child` handle, not the\r\n  stop. A stop that worked would have left the reaper `gone`. This rules OUT the innocent reading\r\n  (stop doesn't manage services): the stop did not reach the DAEMON either.\r\n- **NOT ESTABLISHED — two rungs, neither discriminated:** (1) the rig seeds a `doyle` perch with\r\n  `std::process::id()`, satisfying `ceremony_agent_ground`'s pid-ancestry rung for every child of\r\n  the harness; (2) the rig never scrubs `OWL_SESSION_ID`/`SPT_AGENT_ID`/`SPT_ENDPOINT_ID` from its\r\n  teardown commands, and the measuring run launched from a live agent session, so the env rung was\r\n  live too. `--force` overrides neither. The stop's output is discarded at the call site\r\n  (`let _ = spt(...)`) — no diagnostic names a denial, and no claim is made that one fired.\r\n  Settling it is one run with the stop's stderr captured — on the CI runner AS WELL AS the dev box,\r\n  since the rungs fire on different machines.\r\n- **Why it matters beyond this rig:** REQ-TEST-RIG-DAEMON-TEARDOWN-PROVEN's own failure shape\r\n  inside a rig that passes — teardown completeness rested entirely on breadcrumb kills that were,\r\n  until IR-18, bare `taskkill /F /T` on unauthenticated pids; the most trustworthy-LOOKING\r\n  component (an explicit `--force` stop) was doing nothing while the least trustworthy one did all\r\n  the work. Exactly why the population gate exists rather than per-pid checks alone.\r\n- **Remedy caution (the sentence that must not drop):** the prescribed fix (seed pid 0, scrub the\r\n  three markers — REQ-TEST-RIG-DAEMON-TEARDOWN-PROVEN's own gate) is NOT free here: this rig's\r\n  `doyle` perch pid is load-bearing for the shell bind-by-token legs, so the two remedies are not\r\n  interchangeable — a lane taking this must check which legs depend on the pid before changing it,\r\n  or it fixes the stop and breaks the REQ-INSTALL-11 legs the rig exists for. Kin:\r\n  REQ-BROKER-STOP-ENDPOINT-DENY (the refusal being worked around).\r\n- **LANE-LINKED 2026-08-30 (#242 close sweep):** hertz's queued daemon-leak fixup lane carries\r\n  this entry (brief cites IR-7/17/20/34/35/63); leaves the register when that lane lands.\r\n- **Ripe when:** a hertz test-hardening wave, or alongside the (b) helper lane's touch of this rig.\r\n- **Size:** small (stderr-captured discrimination run × two machines, then the scoped remedy).\r\n\r\n### IR-54 — golden-head-intake runbook: three properties this cut proved should be construction, not discipline\r\n- **Status:** BUILT 2026-08-29 — PR #176 (`880b3b9c`, landed on main via `37368263`).\r\n  · **Origin:** PORTER (#205) v0.59.0 cut, 2026-08-21 — doyle (gater) + deployah (driver),\r\n  both mechanisms measured at the cut, neither cost this run anything because the driver caught\r\n  them by hand. Filed at the release-close register sweep.\r\n- **What/why (three runbook amendments, one lane):**\r\n  1. **Release-shaping at ASSEMBLY intake, not post-golden.** The head arrived code-complete\r\n     but not release-shaped (no version bump, stale CHANGELOG top section) — 5 of the last 6\r\n     cuts. v0.59.0 fixed it by authoring version material BEFORE the golden run, which is what\r\n     produced the four-name shape (ruled sha == main tip == golden ref == tag == `c62904e7`,\r\n     first time in six cuts; the previous five each argued a post-golden delta inert). Amend\r\n     `docs/golden-head-intake` so the gater's assembly checklist asks the release-shaping\r\n     question at intake and the driver never authors on top.\r\n  2. **Never-executed-cells list is a hand-off artifact.** The runbook makes it a\r\n     gater-compiles / driver-re-checks item; PORTER's handoff omitted it and the driver had to\r\n     ask. Name it in the assembly checklist beside the greenlit-form delta: which new cells'\r\n     first CI execution is this golden, and where each HAS executed (lane gate / assembled\r\n     head) — it converts a golden red from an RCA into a lookup.\r\n  3. **Lockfile-refresh rule states the PROPERTY, not the command.** Step 1 prescribes\r\n     `cargo metadata --offline`; the driver used `cargo update --workspace --offline` and\r\n     proved the actual rule by diff (workspace members only, third-party pins untouched —\r\n     14 first-party line pairs, 90 third-party unchanged). The property is the rule and the\r\n     diff is its evidence (the standing by-diff rule exists because counting misread v0.39.4\r\n     and v0.41.0 in opposite directions — and the `windows-sys` 0.59.0 collision was LIVE at\r\n     this cut, the exact condition where counting fabricates a 15th \"first-party\" bump);\r\n     demote the command to an example vehicle.\r\n- **Built evidence:** `docs/RELEASE-RUNBOOK.md` now asks the release-shaping question at assembly\r\n  intake, makes the never-executed-cells list part of the hand-off itself, and states lock refresh\r\n  as a diff-proven property with commands demoted to example vehicles. PR #176 passed\r\n  `traceable-reqs check`; the v0.65.0 cut had already exercised the release-shaped-head rule.\r\n- **Size:** small (one runbook doc lane; no code).\r\n\r\n## IN-FLIGHT ON THE BOARD (not re-homed — live WIP lanes)\r\n\r\n- releases#93 (servicehost swap test pid-inequality), releases#47 (thin-lane unit(Windows)\r\n  isolation class), releases#32 (worker_lifecycle_e2e Phase A intermittent) — infra-shaped but WIP;\r\n  a live lane is never re-homed mid-flight. When each closes, any residue lands here as a new entry.\r\n\r\n## BUILT / RETIRED\r\n\r\n### IR-15 — provably_gone is pid-only on Windows: teardown tests can fabricate reds\r\n- **Status:** BUILT 2026-08-03 · **Origin:** golden 30776330383 red on the #125 fix lane (2026-08-02)\r\n- **Lane:** hertz `golden/ir15` @a5042ec — REQ-TEST-LIVENESS-ORACLE-AUTHENTICATED (impl+unit): one\r\n  shared authenticated death-oracle test helper backed by `spt_procident::process_identity`\r\n  (identity pinned at find time, re-verified at assert), both pid-only polling sites repinned\r\n  (daemon.rs teardown test; endpoint_lifecycle.rs relay_pid). Ruled polarity held: Absent⇒gone,\r\n  Present(same start)⇒not gone, Present(different)⇒gone, Unproven⇒NOT gone, missing-stamp\r\n  degrades to pid-only loudly — every unknown errs toward the recoverable red, zero new\r\n  false-green paths. Linux caveat documented in the helper (10ms jiffies: Present(different) is\r\n  narrowing, not decisive; same-tick reuse errs red, safe).\r\n- **Golden:** run 30782259675 red on `resident_service_e2e` bring-up — delta exonerated (unrelated\r\n  family, now [[IR-17]]; same job minted [[IR-8]]'s defining specimen). Same-sha rerun 30784469908\r\n  GREEN; main ff'd to a5042ec.\r\n- **A/B discriminator (hertz):** 80/80 green both arms, quiet + churn phases; churn arm\r\n  positive-controlled (pid-allocator wrap observed <400ms, so reuse pressure was REAL in the churn\r\n  arm); rule-of-three bounds the original flake at ~7.5%/run/sha. Specimen 30776330383 remains\r\n  not-reproduced, cause unidentified — the repin removes the false-red MECHANISM; it does not\r\n  adjudicate the specimen. [[IR-16]]'s kill-side arm (TerminateJobObject return discarded) stays\r\n  a live discriminating instrument for any recurrence — and since 2026-08-03 it is no longer the\r\n  only one: [[IR-18]] (the test's OWN bare breadcrumb tree-kill) is the second kill-side candidate,\r\n  test-side rather than product-side. A recurrence must discriminate between them, not assume\r\n  either: IR-16's arm is a job whose termination silently half-fails (survivor still holds the\r\n  captured image); IR-18's is a victim killed by a bare pid it no longer owns —\r\n  `broker_survived=false` with the boot service still ALIVE and its message spooled. (An earlier\r\n  spelling of IR-18's signature here said \"empty stderr\"; retracted — empty stderr is present on\r\n  healthy runs and discriminates nothing.)\r\n\r\n### IR-21 — CLASS: a helper binary's build is never requested, only its LOCATION is, so any narrow invocation manufactures a red that belongs to the rig\r\n- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane. · **Origin:** todlando 2026-08-03. Filed as one instance, rewritten as a CLASS the\r\n  same day when a second member appeared, rewritten AGAIN when the mechanism was measured — the\r\n  first two versions described symptoms and got the remedy wrong. **Corrected a fourth time the same\r\n  day**: remedy (1) claimed the 11 same-package sites were missing a build edge, and todlando\r\n  falsified that by measurement while executing it (replicated independently by doyle). The error was\r\n  doyle's to carry — it was ruled on, not just written. The general rule that refutes it was already\r\n  in this entry's own CI-member section; diagnosing a class does not inoculate you against drawing\r\n  its opposite consequence one section later.\r\n- **Numbers below re-derived on `main` @`3efd7e6` over `git ls-files` (tracked files only). Each\r\n  carries its command; re-run rather than cite.**\r\n- ⚠ **Scan-root hazard, measured 2026-08-03 and worse than first reported:** a naive recursive\r\n  `grep -r` from the project root inflates by **~35×**, not the ~5× an earlier draft of this entry\r\n  claimed — 426 tracked `.rs` against 14,865 on disk with `target/` excluded, because `.worktrees/`\r\n  holds full copies of the tree. **And the unscoped grep does not COMPLETE** (still running at a\r\n  120s timeout while `git ls-files` returns instantly), so the failure mode is not only a wrong\r\n  number but a command that reads as hung on a tree where dozens of worktrees are normal. Use\r\n  `git grep` or `git ls-files | xargs grep`; both are scoped to tracked files by construction.\r\n\r","startLine":1080,"lineNumbers":[1080,1081,1082,1083,1084,1085,1086,1087,1088,1089,1090,1091,1092,1093,1094,1095,1096,1097,1098,1099,1100,1101,1102,1103,1104,1105,1106,1107,1108,1109,1110,1111,1112,1113,1114,1115,1116,1117,1118,1119,1120,1121,1122,1123,1124,1125,1126,1127,1128,1129,1130,1131,1132,1133,1134,1135,1136,1137,1138,1139,1140,1141,1142,1143,1144,1145,1146,1147,1148,1149,1150,1151,1152,1153,1154,1155,1156,1157,1158,1159,1160,1161,1162,1163,1164,1165,1166,1167,1168,1169,1170,1171,1172,1173,1174,1175,1176,1177,1178,1179,1180,1181,1182,1183,1184,1185,1186,1187,1188,1189,1190,1191,1192,1193,1194,1195,1196,1197,1198,1199,1200,1201,1202,1203,1204,1205,1206,1207,1208,1209,1210,1211,1212,1213,1214,1215,1216,1217,1218,1219,1220,1221,1222,1223,1224,1225,1226,1227,1228,1229,1230,1231,1232,1233,1234,1235,1236,1237,1238,1239,1240,1241,1242,1243,1244,1245,1246,1247,1248,1249,1250,1251,1252,1253,1254,1255,1256,1257,1258,1259,1260,1261,1262,1263,1264,1265,1266,1267,1268,1269,1270,1271,1272,1273,1274,1275,1276,1277,1278,1279,1280,1281,1282,1283,1284,1285,1286,1287,1288,1289,1290,1291,1292,1293,1294,1295,1296,1297,1298,1299,1300,1301,1302]},"fileSize":676479,"meta":{"source":{"type":"path","value":"C:\\Users\\decid\\Documents\\projects\\spt-core\\.worktrees\\hertz-ir86-disk-delta\\docs\\INFRA-REGISTER.md"},"truncation":{"direction":"head","truncatedBy":"lines","totalLines":6938,"totalBytes":19707,"outputLines":223,"outputBytes":19707,"shownRange":{"start":1080,"end":1302},"nextOffset":1303}}},"isError":false,"timestamp":1789483673573}}
{"type":"message","id":"f2e105b0","parentId":"ab8e7591","timestamp":"2026-09-15T14:47:53.579Z","message":{"role":"toolResult","toolCallId":"call_M6nsOLkFuBapCxRPGQVNhf0v|fc_043a862a419f59ae016aa95a997a3c87d2bb61e8b686127680","toolName":"read","content":[{"type":"text","text":"Deployah answered the query: he ran ZERO create ops at the cut (could not have witnessed a create\nrace), a fresh probe over the milestone window shows no duplicate mints (the 4-issues-in-2s batch\nmint is batching, not duplication), and the only surviving trace is doyle's own pre-reset message\nnaming the item as already-known — a pointer, not a sighting. Item DROPPED; the hole stands as\nthe record. Deployah's sweep-vs-cascade ship-path trap (#181 comment 5337402639, runbook-homed\nabove) is explicitly NOT this item's content — do not fold it in. Composition: IR-9's pin lane\n(`rust-toolchain.toml` @ 1.96.0) goes to hertz AT KEYSTONE #182 INTAKE per the 2026-08-05\nruling; IR-21 remedy (2) + IR-39's precondition helper compose with hertz's standing\nfixture-prebuild-hardening branch `f24e732` — disposition at the same intake; the test-hygiene\nfamily (IR-13/23/36/37/38 + IR-21's clarity half) stays the dedicated post-batch lane candidate,\ndecision at intake; IR-29's proving run + IR-30's instrument lanes ride the next golden batch.\nIR-2's trigger explicitly NOT met (queued unlanded lanes exist: IR-29/IR-30 instruments,\nfour-arm refusal eprintln, f24e732). IR-14 hygiene movement: `.worktrees/nameplate-asm-2bd36f1`\nreaped this sweep (+66.98 GB by FS delta 120.53→187.51; claim `gate-w7-courtesy` base `fd3dc5a`\nin main = finished lane; zero inbound reparse points) — stale-lane audit itself still open.\n\nPrior sweep: 2026-08-05, LOCKSMITH tranche-2 (#141) CLOSE — golden run 30971976024 green on all 9\njobs, main ff'd to `0a25b77`, v0.55.0. IR-40 filed (stale-resume-brief + early-informant class).\nIR-9's decision trigger FIRED 2026-08-05: doyle read the runner-account versions off this run's\n`test` legs and RULED — pin in-repo via `rust-toolchain.toml` @ 1.96.0, kitsubito's clippy leg\nauthoritative in the interim; pin lane to hertz at next intake (see the entry). IR-41 filed the\nsame night (queued main run superseded without a record; runbook step 3 corrected in the same\ncommit). IR-1/IR-4's golden-only steps (link probe both boxes, toolchain\nprint both legs) had their FIRST EXERCISE here, discharging the \"unexercised until a golden run\"\ncaveat at the CI-RIDER LANE STATE foot section. IR-35's re-measure rode the batch (`c65b838`).\nOwlery-noun thin lane SCOPED and dispatched to hertz for the next batch (class A only, two sites;\nclass B on-disk rename is an explicit non-goal — see IR-40's kin discipline for why the boundary is\nwritten into the brief rather than left to judgement).\n\n---\n\n## OPEN\n\n### IR-1 — Quiet predicate needs a network axis (tailscale RTT probe)\n- **Status:** BUILT AND LANDED — reconciled at [[CI-RIDER LANE STATE]]; golden-only exercise\n  recorded at the 2026-08-05 close (30971976024). Header corrected 2026-09-11. Originally\n  carried by `bf8c4a2` → `REQ-CI-LINK-HEALTH-PROBE`, mapping CONFIRMED by builder hertz 2026-08-03\n  (by content: tailscale ping ×5, med/max RTT rows into the bench ledger, three arms\n  success/NO-REPLY/UNAVAILABLE, always exit 0 — instrument, not gate). NOTE `bf8c4a2` is NOT\n  single-purpose: it also corrects the free-space preflight floor read\n  (`REQ-CI-FREE-SPACE-PREFLIGHT`, the ci-runner-has-no-warm-target shape) — no 1:1 commit→IR map\n  for this commit · **Origin:** golden/bench-wiring red triage 2026-08-02 (ex releases#126)\n- **What/why:** the shared-runner quiet predicate (zero non-terminal runs + no local\n  cargo/rustc/nextest by parent chain) is process-shaped; both axes passed on a box whose only\n  link was degrading (321s for a 1s checkout, bidirectional 10s QUIC dial timeouts). A tailscale\n  RTT probe to the peer box before two-host rendezvous, carried in the bench ledger, would have\n  called run 30771155390's red in seconds. Evidence: the arm-1 count table (PUMP_PEER_FAIL\n  a 0→3→0, b 8→22→8 across green/red/rerun).\n- **Permanent, not stopgap:** operator-confirmed 2026-08-02 that kitsubito cannot be provided\n  ethernet — wifi-only indefinitely, so the link cannot be hardened and the predicate must see\n  link health.\n- **Ripe when:** next CI-touching wave, or the next network-shaped golden red — whichever first.\n- **Size:** small (one probe step + ledger row + predicate doc).\n- **Composed:** LOCKSMITH (#132) CI-rider cluster, hertz thin lane — 2026-08-03. GREENLIT with\n  #132 and **DISPATCHED to hertz 2026-08-03** (direct brief; the register is the spec, there is no\n  board issue). Leaves the register only when the lane lands or the entry is retired.\n- **FIRST FIELD USE, and it DISCRIMINATED (2026-08-04, golden 30873007187 attempt 1):** the probe\n  (landed via the rider lane, riding `4b37512`) read 4–7ms RTT healthy on both twohost legs\n  minutes before both legs redded — REFUTING the degraded-link read for that red and steering\n  triage to the real mechanism (the [[IR-29]] serve-window race) instead of a link chase. The\n  instrument's first catch was a correct NEGATIVE — exactly the call run 30771155390 needed and\n  could not make.\n\n### IR-2 — Settle the warm-runner CARGO_INCREMENTAL delta\n- **Status:** RETIRED 2026-08-28, measurement run, verdict NO FLIP — incremental stays ON.\n  hertz paired goldens at main fed965f8: ON run 33167693879 GREEN; OFF run 33172022108 RED\n  (Windows input_ack_deadlock SetupFailed at a 3.0s IPC read deadline — the box-load family,\n  discarded with the leg). Disk: OFF target 7.49 GB vs ON 11.40 GB = 3.91 GB / 34.3% saved\n  (smaller than the entry's 5.65 GB cold figure). Timing NOT causal-quality: sequential runs in\n  one persistent workspace let OFF inherit ON's cache (order contamination dominates the\n  apparent OFF speedups); Windows build-spt-bin +3.8%, Linux -5.1%. Retire reasoning: the\n  DECISION is answerable now — OFF produced no green golden, the timing question needs 4+\n  counterbalanced fresh-cache windows to answer cleanly, and the disk motivation has weakened\n  (box at ~148 GB free under the teardown discipline; the LNK1318 pressure era predates it).\n  Runs/artifacts preserved on the record. Reopen only if runner disk pressure returns as a\n  recurring floor-class red.\n- **Was:** open · **Origin:** #103/#108 bench-wiring lane 2026-08-02 (ex releases#127)\n- **What/why:** the #103 measurement (−29.8% wall, −5.65 GB/target, n=3) is COLD-build only.\n  Golden's runner `_work` target persists warm, where incremental is exactly what keeps it cheap;\n  CARGO_INCREMENTAL=0 was applied only to the genuine cold build (n1-gate pinned old-broker\n  cache) + local rig recipes (docs/GOLDEN-CI.md). Open question: does incremental still pay on\n  the warm runner, weighed against 5.65 GB/target on a box with LNK1318 free-space history?\n- **Method (hertz):** one full golden each way on a quiet box, outside a milestone, compared\n  per-step from the bench ledger.\n- **Ripe when:** a quiet between-milestone window with no queued lanes (the measurement burns\n  two golden windows).\n- **Size:** medium (two proving runs + verdict + possible leg flips).\n\n### IR-3 — Daemon-level guard: broker-net wakeup rate bounded across endpoint churn\n- **Status:** open · **Origin:** releases#125 remediation, todlando REQ call 1 (ex releases#128)\n- **What/why:** the swarm-discovery GC-spin burned two cores for two weeks visible only in a\n  process table — no suite assertion sees the class. Wanted: a daemon-level assertion that\n  broker-net workers stay quiescent across repeated endpoint create/destroy churn.\n- **Design constraint (pre-ruled):** assert on WAKEUP RATE / voluntary ctxt-switch delta over\n  the churn window, NOT %CPU — CPU thresholds flake under CI load; the defect signature\n  (~100 Hz per orphan loop) is load-independent. Mint the REQ at activation.\n- **Near-product:** this is runtime-defect visibility, the most product-adjacent entry here —\n  a candidate rider on any daemon-lifecycle milestone.\n- **Ripe when:** the next milestone touching spt-net endpoint lifecycle or daemon supervision.\n- **Size:** medium (churn harness + counter plumbing + flake-safe assertion).\n\n### IR-4 — Lock-pin guard + lock-procedure rule + toolchain print (three riders, one lane)\n- **Status:** BUILT AND LANDED — `1275e47` / `49d4805` / `8ed006b` mapped and landed in the\n  [[CI-RIDER LANE STATE]] reconciliation; golden toolchain-print exercise recorded at the\n  2026-08-05 close (30971976024). Stale unlanded header corrected 2026-09-11. ·\n  **Origin:** releases#125 fix-lane intake hold (ex releases#129 + riders)\n- **What/why, three parts that land together:**\n  1. **xtask check leg:** assert Cargo.lock resolves swarm-discovery to git rev\n     `89a2200d54a4e3cab2f46cc75ebff49a1fb07614` while the patch is load-bearing; the check's\n     message states its own drop condition (upstream ships a post-PR#27 release AND iroh's pin\n     reaches it). Without it, stanza removal or a routine iroh bump silently returns the lock to\n     the spinning crate and nothing reds.\n  2. **Procedure rule for lock-touching lanes** (docs): targeted `cargo update -p <crate>` only,\n     never full re-resolve; count changed `[[package]]` blocks AND diff per-block edges (set-identical\n     hid 8 windows-sys edge movers at acaaa4f); two resolutions disagreeing = toolchain drift —\n     stop and compare against CI before shipping either lock; hand-edited lock acceptable iff\n     `cargo check --workspace --locked` passes.\n  3. **Toolchain-version print step in golden** (cargo/rustc versions, both OS legs): the acaaa4f\n     comparison against CI was impossible because no run log prints a version. One-grep audit.\n- **Ripe when:** next CI-touching wave; part 1 sooner if any iroh bump is proposed.\n- **Size:** small-medium (one xtask leg, one docs section, one workflow step).\n- **Composed:** LOCKSMITH (#132) CI-rider cluster, hertz thin lane — 2026-08-03. GREENLIT with\n  #132 and **DISPATCHED to hertz 2026-08-03** (all three parts land together).\n\n### IR-5 — Shared nextest summary parser\n- **Status:** open · **Origin:** BAROMETER triage (standing recommendation, pre-register)\n- **What/why:** two agents in one day wrote `[0-9]+ tests run` parsers that read \"1 test run\"\n  (singular) as zero — a guard fed by a broken parser condemns valid rounds. One shared,\n  singular-aware parser (single-source discriminant) for every consumer of nextest summaries.\n- **Ripe-when REWORDED 2026-08-04 (todlando audit): the old trigger was unfireable as worded.** At\n  `b7b00c3` the in-tree population of nextest-SUMMARY parsers is ZERO — the two scripts that read\n  nextest output (`g6-curve.ps1:83-90` per-test lines, `g6-postbounce.ps1:44` display-only grep)\n  neither parse counts nor carry the defect, so \"next wave touching any gate script that reads\n  nextest output\" could fire on a non-defective script while the real population (agent-authored\n  throwaway parsers, which never enter the tree) stays out of reach. New trigger: **the next time\n  anyone — agent or lane — needs a nextest summary COUNT**, the shared parser is built FIRST and the\n  need consumes it; rig briefs should name it so throwaways stop being authored.\n- **Size:** small.\n- **Composed:** LOCKSMITH (#132) CI-rider cluster, CONDITIONAL — lands iff the hertz thin lane\n  touches gate scripts; otherwise stays open here. 2026-08-03. Carried in hertz's 2026-08-03\n  dispatch brief as a **conditional** rider. **Condition NOT MET**, answered by the file-set\n  audit at [[CI-RIDER LANE STATE]]; remains open for its next count-consuming use.\n\n### IR-6 — Membership logging on subnet gates\n- **Status:** open · **Origin:** BAROMETER triage (standing recommendation, pre-register)\n- **What/why:** counts beside results, membership beside counts — gate logs that state a count\n  without naming the population keep producing unreadable reds. Standardize membership\n  enumeration in gate output.\n- **Ripe when:** next wave touching gate scripts / CI legs that report counts.\n- **Size:** small.\n- **Composed:** LOCKSMITH (#132) CI-rider cluster, CONDITIONAL — lands iff the hertz thin lane\n  touches gate scripts; otherwise stays open here. 2026-08-03. Carried in hertz's 2026-08-03\n  dispatch brief as a **conditional** rider. **Condition NOT MET**, answered by the file-set\n  audit at [[CI-RIDER LANE STATE]]; new LINK output complied, existing gate-output estate remains.\n\n### IR-7 — Phase A rigs leak a daemon+brain pair on Windows (exe-lock kills notify relink)\n- **Status:** open · **Origin:** BAROMETER post-publish triage (ex releases#124 — full mechanism on the closed issue)\n- **What/why:** two Phase A rigs launch daemons that escape the job object via WMI-rung autostart\n  (double-space unquoted cmdline fingerprint; SPT_HOME in the wrapper cmdline is the attribution\n  key); the leaked pair holds target/debug/spt.exe and kills every golden job reaching the notify\n  relink. CI reaps as tourniquet (fa6e597); in-job test launch is the fix.\n- **LANE-LINKED 2026-08-30 (#242 close sweep):** hertz's queued daemon-leak fixup lane carries\n  this entry (brief cites IR-7/17/20/34/35/63); leaves the register when that lane lands.\n- **Ripe when:** next wave touching the Phase A rigs or daemon autostart path.\n- **Size:** medium.\n\n### IR-8 — reap-census scoped_survivors=0 is blind to unreadable-path holders\n- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane. · **Origin:** BAROMETER triage\n  (ex releases#122)\n- **What/why:** a zero that cannot see is not a zero — census scoping skips procs whose exe path is\n  unreadable, so the survivors count can report clean while a holder lives. Needs a positive control\n  / explicit unreadable bucket in the verdict line (unreadable_path count exists; the ZERO must\n  refuse when it is nonzero).\n- **Defining specimen (golden 30782259675, hfenduleam test job, 2026-08-03):**\n  `CI-REAP summary: killed=5 kill_failed=1 scoped_survivors=0` — an admitted kill failure printed\n  beside a zero-survivors claim on the same verdict line. The held image surfaced one step later:\n  run-scoped tmp cleanup denied 5/5 attempts on `...\\relshell\\svcmock.exe` (2nd appearance of the\n  svcmock hold; 1st @7a3c08c, pre-kill-auth). hertz's addendum: an image-held survivor also blocks\n  WRITES to the exe path — the same class manufactures build/relink access-denied reds that mask as\n  build problems, not just cleanup warnings. Not per-run: the same-sha green rerun's leg read\n  `kill_failed=0 scoped_survivors=0` throughout (hertz, 30784469908) — intermittent sighting,\n  second of its class, not a deterministic fixture property.\n- **The Linux twin is strictly worse (todlando audit 2026-08-04, vs `b7b00c3`):** `reap-census.sh`\n  has NO `kill_failed` anywhere (0 occurrences vs 2 in the `.ps1`) — its kill loop increments\n  `killed` only in the success branch with no else, so a failed kill increments nothing and prints\n  nothing. The specimen that made this class VISIBLE on Windows would be INVISIBLE on Linux.\n  Population precision so this is not overclaimed: ESRCH is benign (already gone; the kill-time\n  re-resolve makes it the common case); the vanishing case is EPERM against another account's\n  process. The `.sh` `scoped_survivors` DOES come from a post-reap census re-measure, so survivors\n  are measured — the hole is failed kills and the unreadable bucket, not the survivor count.\n  Windows precision from the same audit: `unreadable_path` IS on the CI-CENSUS line (:157) but the\n  CI-REAP verdict line (:243, :246) still carries only killed/kill_failed/scoped_survivors — the\n  zero still does not refuse, exactly this entry's ask.\n- **Built evidence:** both verdict lines now carry `unreadable_path`; any nonzero unreadable\n  family population renders `scoped_survivors=UNPROVEN` rather than a false zero. Linux also\n  counts and reports failed kills. The shared predicate is mutation-pinned by\n  `reap-census-selftest.sh`; the PowerShell implementation parses cleanly.\n- **Ripe when:** next census/reap script wave (natural pair with IR-7's lane) — now BOTH platforms.\n- **Size:** small.\n\n### IR-9 — Golden boxes run different clippy versions\n- **Status:** pin LANDED 2026-08-18 at `35968156` (`build: pin Rust 1.96.0`), then\n  audited **BUILT** at the 2026-08-29 v0.65.0 close sweep; the pin is an ancestor of\n  golden-green cut SHA `4d6007ac`. The earlier measurement half had already landed and run:\n  the toolchain print (`8ed006b` → `REQ-CI-TOOLCHAIN-VERSION-PRINT`) exercised both legs of\n  golden run 30971976024 (`test` jobs 92198170694/92198170700 — scoped to `test`, not n1-gate;\n  grep token `TOOLCHAIN `). Runner-account facts, read by doyle 2026-08-05: hfenduleam\n  `cargo/rustc 1.93.0` + `clippy 0.1.93`, kitsubito `cargo/rustc 1.96.0` +\n  `clippy 0.1.96`; `stable (default)` on both proved the skew would otherwise decay silently.\n- **RULING (doyle, 2026-08-05, on the runner-account facts as the 2026-08-03 hold required):**\n  (1) align-by-event REJECTED — with both boxes on unpinned stable, alignment decays silently;\n\n[Showing lines 240-450 of 6938. Use :451 to continue]"}],"details":{"truncation":{"content":"Deployah answered the query: he ran ZERO create ops at the cut (could not have witnessed a create\r\nrace), a fresh probe over the milestone window shows no duplicate mints (the 4-issues-in-2s batch\r\nmint is batching, not duplication), and the only surviving trace is doyle's own pre-reset message\r\nnaming the item as already-known — a pointer, not a sighting. Item DROPPED; the hole stands as\r\nthe record. Deployah's sweep-vs-cascade ship-path trap (#181 comment 5337402639, runbook-homed\r\nabove) is explicitly NOT this item's content — do not fold it in. Composition: IR-9's pin lane\r\n(`rust-toolchain.toml` @ 1.96.0) goes to hertz AT KEYSTONE #182 INTAKE per the 2026-08-05\r\nruling; IR-21 remedy (2) + IR-39's precondition helper compose with hertz's standing\r\nfixture-prebuild-hardening branch `f24e732` — disposition at the same intake; the test-hygiene\r\nfamily (IR-13/23/36/37/38 + IR-21's clarity half) stays the dedicated post-batch lane candidate,\r\ndecision at intake; IR-29's proving run + IR-30's instrument lanes ride the next golden batch.\r\nIR-2's trigger explicitly NOT met (queued unlanded lanes exist: IR-29/IR-30 instruments,\r\nfour-arm refusal eprintln, f24e732). IR-14 hygiene movement: `.worktrees/nameplate-asm-2bd36f1`\r\nreaped this sweep (+66.98 GB by FS delta 120.53→187.51; claim `gate-w7-courtesy` base `fd3dc5a`\r\nin main = finished lane; zero inbound reparse points) — stale-lane audit itself still open.\r\n\r\nPrior sweep: 2026-08-05, LOCKSMITH tranche-2 (#141) CLOSE — golden run 30971976024 green on all 9\r\njobs, main ff'd to `0a25b77`, v0.55.0. IR-40 filed (stale-resume-brief + early-informant class).\r\nIR-9's decision trigger FIRED 2026-08-05: doyle read the runner-account versions off this run's\r\n`test` legs and RULED — pin in-repo via `rust-toolchain.toml` @ 1.96.0, kitsubito's clippy leg\r\nauthoritative in the interim; pin lane to hertz at next intake (see the entry). IR-41 filed the\r\nsame night (queued main run superseded without a record; runbook step 3 corrected in the same\r\ncommit). IR-1/IR-4's golden-only steps (link probe both boxes, toolchain\r\nprint both legs) had their FIRST EXERCISE here, discharging the \"unexercised until a golden run\"\r\ncaveat at the CI-RIDER LANE STATE foot section. IR-35's re-measure rode the batch (`c65b838`).\r\nOwlery-noun thin lane SCOPED and dispatched to hertz for the next batch (class A only, two sites;\r\nclass B on-disk rename is an explicit non-goal — see IR-40's kin discipline for why the boundary is\r\nwritten into the brief rather than left to judgement).\r\n\r\n---\r\n\r\n## OPEN\r\n\r\n### IR-1 — Quiet predicate needs a network axis (tailscale RTT probe)\r\n- **Status:** BUILT AND LANDED — reconciled at [[CI-RIDER LANE STATE]]; golden-only exercise\r\n  recorded at the 2026-08-05 close (30971976024). Header corrected 2026-09-11. Originally\r\n  carried by `bf8c4a2` → `REQ-CI-LINK-HEALTH-PROBE`, mapping CONFIRMED by builder hertz 2026-08-03\r\n  (by content: tailscale ping ×5, med/max RTT rows into the bench ledger, three arms\r\n  success/NO-REPLY/UNAVAILABLE, always exit 0 — instrument, not gate). NOTE `bf8c4a2` is NOT\r\n  single-purpose: it also corrects the free-space preflight floor read\r\n  (`REQ-CI-FREE-SPACE-PREFLIGHT`, the ci-runner-has-no-warm-target shape) — no 1:1 commit→IR map\r\n  for this commit · **Origin:** golden/bench-wiring red triage 2026-08-02 (ex releases#126)\r\n- **What/why:** the shared-runner quiet predicate (zero non-terminal runs + no local\r\n  cargo/rustc/nextest by parent chain) is process-shaped; both axes passed on a box whose only\r\n  link was degrading (321s for a 1s checkout, bidirectional 10s QUIC dial timeouts). A tailscale\r\n  RTT probe to the peer box before two-host rendezvous, carried in the bench ledger, would have\r\n  called run 30771155390's red in seconds. Evidence: the arm-1 count table (PUMP_PEER_FAIL\r\n  a 0→3→0, b 8→22→8 across green/red/rerun).\r\n- **Permanent, not stopgap:** operator-confirmed 2026-08-02 that kitsubito cannot be provided\r\n  ethernet — wifi-only indefinitely, so the link cannot be hardened and the predicate must see\r\n  link health.\r\n- **Ripe when:** next CI-touching wave, or the next network-shaped golden red — whichever first.\r\n- **Size:** small (one probe step + ledger row + predicate doc).\r\n- **Composed:** LOCKSMITH (#132) CI-rider cluster, hertz thin lane — 2026-08-03. GREENLIT with\r\n  #132 and **DISPATCHED to hertz 2026-08-03** (direct brief; the register is the spec, there is no\r\n  board issue). Leaves the register only when the lane lands or the entry is retired.\r\n- **FIRST FIELD USE, and it DISCRIMINATED (2026-08-04, golden 30873007187 attempt 1):** the probe\r\n  (landed via the rider lane, riding `4b37512`) read 4–7ms RTT healthy on both twohost legs\r\n  minutes before both legs redded — REFUTING the degraded-link read for that red and steering\r\n  triage to the real mechanism (the [[IR-29]] serve-window race) instead of a link chase. The\r\n  instrument's first catch was a correct NEGATIVE — exactly the call run 30771155390 needed and\r\n  could not make.\r\n\r\n### IR-2 — Settle the warm-runner CARGO_INCREMENTAL delta\r\n- **Status:** RETIRED 2026-08-28, measurement run, verdict NO FLIP — incremental stays ON.\r\n  hertz paired goldens at main fed965f8: ON run 33167693879 GREEN; OFF run 33172022108 RED\r\n  (Windows input_ack_deadlock SetupFailed at a 3.0s IPC read deadline — the box-load family,\r\n  discarded with the leg). Disk: OFF target 7.49 GB vs ON 11.40 GB = 3.91 GB / 34.3% saved\r\n  (smaller than the entry's 5.65 GB cold figure). Timing NOT causal-quality: sequential runs in\r\n  one persistent workspace let OFF inherit ON's cache (order contamination dominates the\r\n  apparent OFF speedups); Windows build-spt-bin +3.8%, Linux -5.1%. Retire reasoning: the\r\n  DECISION is answerable now — OFF produced no green golden, the timing question needs 4+\r\n  counterbalanced fresh-cache windows to answer cleanly, and the disk motivation has weakened\r\n  (box at ~148 GB free under the teardown discipline; the LNK1318 pressure era predates it).\r\n  Runs/artifacts preserved on the record. Reopen only if runner disk pressure returns as a\r\n  recurring floor-class red.\r\n- **Was:** open · **Origin:** #103/#108 bench-wiring lane 2026-08-02 (ex releases#127)\r\n- **What/why:** the #103 measurement (−29.8% wall, −5.65 GB/target, n=3) is COLD-build only.\r\n  Golden's runner `_work` target persists warm, where incremental is exactly what keeps it cheap;\r\n  CARGO_INCREMENTAL=0 was applied only to the genuine cold build (n1-gate pinned old-broker\r\n  cache) + local rig recipes (docs/GOLDEN-CI.md). Open question: does incremental still pay on\r\n  the warm runner, weighed against 5.65 GB/target on a box with LNK1318 free-space history?\r\n- **Method (hertz):** one full golden each way on a quiet box, outside a milestone, compared\r\n  per-step from the bench ledger.\r\n- **Ripe when:** a quiet between-milestone window with no queued lanes (the measurement burns\r\n  two golden windows).\r\n- **Size:** medium (two proving runs + verdict + possible leg flips).\r\n\r\n### IR-3 — Daemon-level guard: broker-net wakeup rate bounded across endpoint churn\r\n- **Status:** open · **Origin:** releases#125 remediation, todlando REQ call 1 (ex releases#128)\r\n- **What/why:** the swarm-discovery GC-spin burned two cores for two weeks visible only in a\r\n  process table — no suite assertion sees the class. Wanted: a daemon-level assertion that\r\n  broker-net workers stay quiescent across repeated endpoint create/destroy churn.\r\n- **Design constraint (pre-ruled):** assert on WAKEUP RATE / voluntary ctxt-switch delta over\r\n  the churn window, NOT %CPU — CPU thresholds flake under CI load; the defect signature\r\n  (~100 Hz per orphan loop) is load-independent. Mint the REQ at activation.\r\n- **Near-product:** this is runtime-defect visibility, the most product-adjacent entry here —\r\n  a candidate rider on any daemon-lifecycle milestone.\r\n- **Ripe when:** the next milestone touching spt-net endpoint lifecycle or daemon supervision.\r\n- **Size:** medium (churn harness + counter plumbing + flake-safe assertion).\r\n\r\n### IR-4 — Lock-pin guard + lock-procedure rule + toolchain print (three riders, one lane)\r\n- **Status:** BUILT AND LANDED — `1275e47` / `49d4805` / `8ed006b` mapped and landed in the\r\n  [[CI-RIDER LANE STATE]] reconciliation; golden toolchain-print exercise recorded at the\r\n  2026-08-05 close (30971976024). Stale unlanded header corrected 2026-09-11. ·\r\n  **Origin:** releases#125 fix-lane intake hold (ex releases#129 + riders)\r\n- **What/why, three parts that land together:**\r\n  1. **xtask check leg:** assert Cargo.lock resolves swarm-discovery to git rev\r\n     `89a2200d54a4e3cab2f46cc75ebff49a1fb07614` while the patch is load-bearing; the check's\r\n     message states its own drop condition (upstream ships a post-PR#27 release AND iroh's pin\r\n     reaches it). Without it, stanza removal or a routine iroh bump silently returns the lock to\r\n     the spinning crate and nothing reds.\r\n  2. **Procedure rule for lock-touching lanes** (docs): targeted `cargo update -p <crate>` only,\r\n     never full re-resolve; count changed `[[package]]` blocks AND diff per-block edges (set-identical\r\n     hid 8 windows-sys edge movers at acaaa4f); two resolutions disagreeing = toolchain drift —\r\n     stop and compare against CI before shipping either lock; hand-edited lock acceptable iff\r\n     `cargo check --workspace --locked` passes.\r\n  3. **Toolchain-version print step in golden** (cargo/rustc versions, both OS legs): the acaaa4f\r\n     comparison against CI was impossible because no run log prints a version. One-grep audit.\r\n- **Ripe when:** next CI-touching wave; part 1 sooner if any iroh bump is proposed.\r\n- **Size:** small-medium (one xtask leg, one docs section, one workflow step).\r\n- **Composed:** LOCKSMITH (#132) CI-rider cluster, hertz thin lane — 2026-08-03. GREENLIT with\r\n  #132 and **DISPATCHED to hertz 2026-08-03** (all three parts land together).\r\n\r\n### IR-5 — Shared nextest summary parser\r\n- **Status:** open · **Origin:** BAROMETER triage (standing recommendation, pre-register)\r\n- **What/why:** two agents in one day wrote `[0-9]+ tests run` parsers that read \"1 test run\"\r\n  (singular) as zero — a guard fed by a broken parser condemns valid rounds. One shared,\r\n  singular-aware parser (single-source discriminant) for every consumer of nextest summaries.\r\n- **Ripe-when REWORDED 2026-08-04 (todlando audit): the old trigger was unfireable as worded.** At\r\n  `b7b00c3` the in-tree population of nextest-SUMMARY parsers is ZERO — the two scripts that read\r\n  nextest output (`g6-curve.ps1:83-90` per-test lines, `g6-postbounce.ps1:44` display-only grep)\r\n  neither parse counts nor carry the defect, so \"next wave touching any gate script that reads\r\n  nextest output\" could fire on a non-defective script while the real population (agent-authored\r\n  throwaway parsers, which never enter the tree) stays out of reach. New trigger: **the next time\r\n  anyone — agent or lane — needs a nextest summary COUNT**, the shared parser is built FIRST and the\r\n  need consumes it; rig briefs should name it so throwaways stop being authored.\r\n- **Size:** small.\r\n- **Composed:** LOCKSMITH (#132) CI-rider cluster, CONDITIONAL — lands iff the hertz thin lane\r\n  touches gate scripts; otherwise stays open here. 2026-08-03. Carried in hertz's 2026-08-03\r\n  dispatch brief as a **conditional** rider. **Condition NOT MET**, answered by the file-set\r\n  audit at [[CI-RIDER LANE STATE]]; remains open for its next count-consuming use.\r\n\r\n### IR-6 — Membership logging on subnet gates\r\n- **Status:** open · **Origin:** BAROMETER triage (standing recommendation, pre-register)\r\n- **What/why:** counts beside results, membership beside counts — gate logs that state a count\r\n  without naming the population keep producing unreadable reds. Standardize membership\r\n  enumeration in gate output.\r\n- **Ripe when:** next wave touching gate scripts / CI legs that report counts.\r\n- **Size:** small.\r\n- **Composed:** LOCKSMITH (#132) CI-rider cluster, CONDITIONAL — lands iff the hertz thin lane\r\n  touches gate scripts; otherwise stays open here. 2026-08-03. Carried in hertz's 2026-08-03\r\n  dispatch brief as a **conditional** rider. **Condition NOT MET**, answered by the file-set\r\n  audit at [[CI-RIDER LANE STATE]]; new LINK output complied, existing gate-output estate remains.\r\n\r\n### IR-7 — Phase A rigs leak a daemon+brain pair on Windows (exe-lock kills notify relink)\r\n- **Status:** open · **Origin:** BAROMETER post-publish triage (ex releases#124 — full mechanism on the closed issue)\r\n- **What/why:** two Phase A rigs launch daemons that escape the job object via WMI-rung autostart\r\n  (double-space unquoted cmdline fingerprint; SPT_HOME in the wrapper cmdline is the attribution\r\n  key); the leaked pair holds target/debug/spt.exe and kills every golden job reaching the notify\r\n  relink. CI reaps as tourniquet (fa6e597); in-job test launch is the fix.\r\n- **LANE-LINKED 2026-08-30 (#242 close sweep):** hertz's queued daemon-leak fixup lane carries\r\n  this entry (brief cites IR-7/17/20/34/35/63); leaves the register when that lane lands.\r\n- **Ripe when:** next wave touching the Phase A rigs or daemon autostart path.\r\n- **Size:** medium.\r\n\r\n### IR-8 — reap-census scoped_survivors=0 is blind to unreadable-path holders\r\n- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane. · **Origin:** BAROMETER triage\r\n  (ex releases#122)\r\n- **What/why:** a zero that cannot see is not a zero — census scoping skips procs whose exe path is\r\n  unreadable, so the survivors count can report clean while a holder lives. Needs a positive control\r\n  / explicit unreadable bucket in the verdict line (unreadable_path count exists; the ZERO must\r\n  refuse when it is nonzero).\r\n- **Defining specimen (golden 30782259675, hfenduleam test job, 2026-08-03):**\r\n  `CI-REAP summary: killed=5 kill_failed=1 scoped_survivors=0` — an admitted kill failure printed\r\n  beside a zero-survivors claim on the same verdict line. The held image surfaced one step later:\r\n  run-scoped tmp cleanup denied 5/5 attempts on `...\\relshell\\svcmock.exe` (2nd appearance of the\r\n  svcmock hold; 1st @7a3c08c, pre-kill-auth). hertz's addendum: an image-held survivor also blocks\r\n  WRITES to the exe path — the same class manufactures build/relink access-denied reds that mask as\r\n  build problems, not just cleanup warnings. Not per-run: the same-sha green rerun's leg read\r\n  `kill_failed=0 scoped_survivors=0` throughout (hertz, 30784469908) — intermittent sighting,\r\n  second of its class, not a deterministic fixture property.\r\n- **The Linux twin is strictly worse (todlando audit 2026-08-04, vs `b7b00c3`):** `reap-census.sh`\r\n  has NO `kill_failed` anywhere (0 occurrences vs 2 in the `.ps1`) — its kill loop increments\r\n  `killed` only in the success branch with no else, so a failed kill increments nothing and prints\r\n  nothing. The specimen that made this class VISIBLE on Windows would be INVISIBLE on Linux.\r\n  Population precision so this is not overclaimed: ESRCH is benign (already gone; the kill-time\r\n  re-resolve makes it the common case); the vanishing case is EPERM against another account's\r\n  process. The `.sh` `scoped_survivors` DOES come from a post-reap census re-measure, so survivors\r\n  are measured — the hole is failed kills and the unreadable bucket, not the survivor count.\r\n  Windows precision from the same audit: `unreadable_path` IS on the CI-CENSUS line (:157) but the\r\n  CI-REAP verdict line (:243, :246) still carries only killed/kill_failed/scoped_survivors — the\r\n  zero still does not refuse, exactly this entry's ask.\r\n- **Built evidence:** both verdict lines now carry `unreadable_path`; any nonzero unreadable\r\n  family population renders `scoped_survivors=UNPROVEN` rather than a false zero. Linux also\r\n  counts and reports failed kills. The shared predicate is mutation-pinned by\r\n  `reap-census-selftest.sh`; the PowerShell implementation parses cleanly.\r\n- **Ripe when:** next census/reap script wave (natural pair with IR-7's lane) — now BOTH platforms.\r\n- **Size:** small.\r\n\r\n### IR-9 — Golden boxes run different clippy versions\r\n- **Status:** pin LANDED 2026-08-18 at `35968156` (`build: pin Rust 1.96.0`), then\r\n  audited **BUILT** at the 2026-08-29 v0.65.0 close sweep; the pin is an ancestor of\r\n  golden-green cut SHA `4d6007ac`. The earlier measurement half had already landed and run:\r\n  the toolchain print (`8ed006b` → `REQ-CI-TOOLCHAIN-VERSION-PRINT`) exercised both legs of\r\n  golden run 30971976024 (`test` jobs 92198170694/92198170700 — scoped to `test`, not n1-gate;\r\n  grep token `TOOLCHAIN `). Runner-account facts, read by doyle 2026-08-05: hfenduleam\r\n  `cargo/rustc 1.93.0` + `clippy 0.1.93`, kitsubito `cargo/rustc 1.96.0` +\r\n  `clippy 0.1.96`; `stable (default)` on both proved the skew would otherwise decay silently.\r\n- **RULING (doyle, 2026-08-05, on the runner-account facts as the 2026-08-03 hold required):**\r\n  (1) align-by-event REJECTED — with both boxes on unpinned stable, alignment decays silently;\r","truncated":true,"truncatedBy":"lines","totalLines":6699,"totalBytes":17166,"outputLines":211,"outputBytes":17166,"lastLinePartial":false,"firstLineExceedsLimit":false},"totalLines":6938,"displayContent":{"text":"Deployah answered the query: he ran ZERO create ops at the cut (could not have witnessed a create\r\nrace), a fresh probe over the milestone window shows no duplicate mints (the 4-issues-in-2s batch\r\nmint is batching, not duplication), and the only surviving trace is doyle's own pre-reset message\r\nnaming the item as already-known — a pointer, not a sighting. Item DROPPED; the hole stands as\r\nthe record. Deployah's sweep-vs-cascade ship-path trap (#181 comment 5337402639, runbook-homed\r\nabove) is explicitly NOT this item's content — do not fold it in. Composition: IR-9's pin lane\r\n(`rust-toolchain.toml` @ 1.96.0) goes to hertz AT KEYSTONE #182 INTAKE per the 2026-08-05\r\nruling; IR-21 remedy (2) + IR-39's precondition helper compose with hertz's standing\r\nfixture-prebuild-hardening branch `f24e732` — disposition at the same intake; the test-hygiene\r\nfamily (IR-13/23/36/37/38 + IR-21's clarity half) stays the dedicated post-batch lane candidate,\r\ndecision at intake; IR-29's proving run + IR-30's instrument lanes ride the next golden batch.\r\nIR-2's trigger explicitly NOT met (queued unlanded lanes exist: IR-29/IR-30 instruments,\r\nfour-arm refusal eprintln, f24e732). IR-14 hygiene movement: `.worktrees/nameplate-asm-2bd36f1`\r\nreaped this sweep (+66.98 GB by FS delta 120.53→187.51; claim `gate-w7-courtesy` base `fd3dc5a`\r\nin main = finished lane; zero inbound reparse points) — stale-lane audit itself still open.\r\n\r\nPrior sweep: 2026-08-05, LOCKSMITH tranche-2 (#141) CLOSE — golden run 30971976024 green on all 9\r\njobs, main ff'd to `0a25b77`, v0.55.0. IR-40 filed (stale-resume-brief + early-informant class).\r\nIR-9's decision trigger FIRED 2026-08-05: doyle read the runner-account versions off this run's\r\n`test` legs and RULED — pin in-repo via `rust-toolchain.toml` @ 1.96.0, kitsubito's clippy leg\r\nauthoritative in the interim; pin lane to hertz at next intake (see the entry). IR-41 filed the\r\nsame night (queued main run superseded without a record; runbook step 3 corrected in the same\r\ncommit). IR-1/IR-4's golden-only steps (link probe both boxes, toolchain\r\nprint both legs) had their FIRST EXERCISE here, discharging the \"unexercised until a golden run\"\r\ncaveat at the CI-RIDER LANE STATE foot section. IR-35's re-measure rode the batch (`c65b838`).\r\nOwlery-noun thin lane SCOPED and dispatched to hertz for the next batch (class A only, two sites;\r\nclass B on-disk rename is an explicit non-goal — see IR-40's kin discipline for why the boundary is\r\nwritten into the brief rather than left to judgement).\r\n\r\n---\r\n\r\n## OPEN\r\n\r\n### IR-1 — Quiet predicate needs a network axis (tailscale RTT probe)\r\n- **Status:** BUILT AND LANDED — reconciled at [[CI-RIDER LANE STATE]]; golden-only exercise\r\n  recorded at the 2026-08-05 close (30971976024). Header corrected 2026-09-11. Originally\r\n  carried by `bf8c4a2` → `REQ-CI-LINK-HEALTH-PROBE`, mapping CONFIRMED by builder hertz 2026-08-03\r\n  (by content: tailscale ping ×5, med/max RTT rows into the bench ledger, three arms\r\n  success/NO-REPLY/UNAVAILABLE, always exit 0 — instrument, not gate). NOTE `bf8c4a2` is NOT\r\n  single-purpose: it also corrects the free-space preflight floor read\r\n  (`REQ-CI-FREE-SPACE-PREFLIGHT`, the ci-runner-has-no-warm-target shape) — no 1:1 commit→IR map\r\n  for this commit · **Origin:** golden/bench-wiring red triage 2026-08-02 (ex releases#126)\r\n- **What/why:** the shared-runner quiet predicate (zero non-terminal runs + no local\r\n  cargo/rustc/nextest by parent chain) is process-shaped; both axes passed on a box whose only\r\n  link was degrading (321s for a 1s checkout, bidirectional 10s QUIC dial timeouts). A tailscale\r\n  RTT probe to the peer box before two-host rendezvous, carried in the bench ledger, would have\r\n  called run 30771155390's red in seconds. Evidence: the arm-1 count table (PUMP_PEER_FAIL\r\n  a 0→3→0, b 8→22→8 across green/red/rerun).\r\n- **Permanent, not stopgap:** operator-confirmed 2026-08-02 that kitsubito cannot be provided\r\n  ethernet — wifi-only indefinitely, so the link cannot be hardened and the predicate must see\r\n  link health.\r\n- **Ripe when:** next CI-touching wave, or the next network-shaped golden red — whichever first.\r\n- **Size:** small (one probe step + ledger row + predicate doc).\r\n- **Composed:** LOCKSMITH (#132) CI-rider cluster, hertz thin lane — 2026-08-03. GREENLIT with\r\n  #132 and **DISPATCHED to hertz 2026-08-03** (direct brief; the register is the spec, there is no\r\n  board issue). Leaves the register only when the lane lands or the entry is retired.\r\n- **FIRST FIELD USE, and it DISCRIMINATED (2026-08-04, golden 30873007187 attempt 1):** the probe\r\n  (landed via the rider lane, riding `4b37512`) read 4–7ms RTT healthy on both twohost legs\r\n  minutes before both legs redded — REFUTING the degraded-link read for that red and steering\r\n  triage to the real mechanism (the [[IR-29]] serve-window race) instead of a link chase. The\r\n  instrument's first catch was a correct NEGATIVE — exactly the call run 30771155390 needed and\r\n  could not make.\r\n\r\n### IR-2 — Settle the warm-runner CARGO_INCREMENTAL delta\r\n- **Status:** RETIRED 2026-08-28, measurement run, verdict NO FLIP — incremental stays ON.\r\n  hertz paired goldens at main fed965f8: ON run 33167693879 GREEN; OFF run 33172022108 RED\r\n  (Windows input_ack_deadlock SetupFailed at a 3.0s IPC read deadline — the box-load family,\r\n  discarded with the leg). Disk: OFF target 7.49 GB vs ON 11.40 GB = 3.91 GB / 34.3% saved\r\n  (smaller than the entry's 5.65 GB cold figure). Timing NOT causal-quality: sequential runs in\r\n  one persistent workspace let OFF inherit ON's cache (order contamination dominates the\r\n  apparent OFF speedups); Windows build-spt-bin +3.8%, Linux -5.1%. Retire reasoning: the\r\n  DECISION is answerable now — OFF produced no green golden, the timing question needs 4+\r\n  counterbalanced fresh-cache windows to answer cleanly, and the disk motivation has weakened\r\n  (box at ~148 GB free under the teardown discipline; the LNK1318 pressure era predates it).\r\n  Runs/artifacts preserved on the record. Reopen only if runner disk pressure returns as a\r\n  recurring floor-class red.\r\n- **Was:** open · **Origin:** #103/#108 bench-wiring lane 2026-08-02 (ex releases#127)\r\n- **What/why:** the #103 measurement (−29.8% wall, −5.65 GB/target, n=3) is COLD-build only.\r\n  Golden's runner `_work` target persists warm, where incremental is exactly what keeps it cheap;\r\n  CARGO_INCREMENTAL=0 was applied only to the genuine cold build (n1-gate pinned old-broker\r\n  cache) + local rig recipes (docs/GOLDEN-CI.md). Open question: does incremental still pay on\r\n  the warm runner, weighed against 5.65 GB/target on a box with LNK1318 free-space history?\r\n- **Method (hertz):** one full golden each way on a quiet box, outside a milestone, compared\r\n  per-step from the bench ledger.\r\n- **Ripe when:** a quiet between-milestone window with no queued lanes (the measurement burns\r\n  two golden windows).\r\n- **Size:** medium (two proving runs + verdict + possible leg flips).\r\n\r\n### IR-3 — Daemon-level guard: broker-net wakeup rate bounded across endpoint churn\r\n- **Status:** open · **Origin:** releases#125 remediation, todlando REQ call 1 (ex releases#128)\r\n- **What/why:** the swarm-discovery GC-spin burned two cores for two weeks visible only in a\r\n  process table — no suite assertion sees the class. Wanted: a daemon-level assertion that\r\n  broker-net workers stay quiescent across repeated endpoint create/destroy churn.\r\n- **Design constraint (pre-ruled):** assert on WAKEUP RATE / voluntary ctxt-switch delta over\r\n  the churn window, NOT %CPU — CPU thresholds flake under CI load; the defect signature\r\n  (~100 Hz per orphan loop) is load-independent. Mint the REQ at activation.\r\n- **Near-product:** this is runtime-defect visibility, the most product-adjacent entry here —\r\n  a candidate rider on any daemon-lifecycle milestone.\r\n- **Ripe when:** the next milestone touching spt-net endpoint lifecycle or daemon supervision.\r\n- **Size:** medium (churn harness + counter plumbing + flake-safe assertion).\r\n\r\n### IR-4 — Lock-pin guard + lock-procedure rule + toolchain print (three riders, one lane)\r\n- **Status:** BUILT AND LANDED — `1275e47` / `49d4805` / `8ed006b` mapped and landed in the\r\n  [[CI-RIDER LANE STATE]] reconciliation; golden toolchain-print exercise recorded at the\r\n  2026-08-05 close (30971976024). Stale unlanded header corrected 2026-09-11. ·\r\n  **Origin:** releases#125 fix-lane intake hold (ex releases#129 + riders)\r\n- **What/why, three parts that land together:**\r\n  1. **xtask check leg:** assert Cargo.lock resolves swarm-discovery to git rev\r\n     `89a2200d54a4e3cab2f46cc75ebff49a1fb07614` while the patch is load-bearing; the check's\r\n     message states its own drop condition (upstream ships a post-PR#27 release AND iroh's pin\r\n     reaches it). Without it, stanza removal or a routine iroh bump silently returns the lock to\r\n     the spinning crate and nothing reds.\r\n  2. **Procedure rule for lock-touching lanes** (docs): targeted `cargo update -p <crate>` only,\r\n     never full re-resolve; count changed `[[package]]` blocks AND diff per-block edges (set-identical\r\n     hid 8 windows-sys edge movers at acaaa4f); two resolutions disagreeing = toolchain drift —\r\n     stop and compare against CI before shipping either lock; hand-edited lock acceptable iff\r\n     `cargo check --workspace --locked` passes.\r\n  3. **Toolchain-version print step in golden** (cargo/rustc versions, both OS legs): the acaaa4f\r\n     comparison against CI was impossible because no run log prints a version. One-grep audit.\r\n- **Ripe when:** next CI-touching wave; part 1 sooner if any iroh bump is proposed.\r\n- **Size:** small-medium (one xtask leg, one docs section, one workflow step).\r\n- **Composed:** LOCKSMITH (#132) CI-rider cluster, hertz thin lane — 2026-08-03. GREENLIT with\r\n  #132 and **DISPATCHED to hertz 2026-08-03** (all three parts land together).\r\n\r\n### IR-5 — Shared nextest summary parser\r\n- **Status:** open · **Origin:** BAROMETER triage (standing recommendation, pre-register)\r\n- **What/why:** two agents in one day wrote `[0-9]+ tests run` parsers that read \"1 test run\"\r\n  (singular) as zero — a guard fed by a broken parser condemns valid rounds. One shared,\r\n  singular-aware parser (single-source discriminant) for every consumer of nextest summaries.\r\n- **Ripe-when REWORDED 2026-08-04 (todlando audit): the old trigger was unfireable as worded.** At\r\n  `b7b00c3` the in-tree population of nextest-SUMMARY parsers is ZERO — the two scripts that read\r\n  nextest output (`g6-curve.ps1:83-90` per-test lines, `g6-postbounce.ps1:44` display-only grep)\r\n  neither parse counts nor carry the defect, so \"next wave touching any gate script that reads\r\n  nextest output\" could fire on a non-defective script while the real population (agent-authored\r\n  throwaway parsers, which never enter the tree) stays out of reach. New trigger: **the next time\r\n  anyone — agent or lane — needs a nextest summary COUNT**, the shared parser is built FIRST and the\r\n  need consumes it; rig briefs should name it so throwaways stop being authored.\r\n- **Size:** small.\r\n- **Composed:** LOCKSMITH (#132) CI-rider cluster, CONDITIONAL — lands iff the hertz thin lane\r\n  touches gate scripts; otherwise stays open here. 2026-08-03. Carried in hertz's 2026-08-03\r\n  dispatch brief as a **conditional** rider. **Condition NOT MET**, answered by the file-set\r\n  audit at [[CI-RIDER LANE STATE]]; remains open for its next count-consuming use.\r\n\r\n### IR-6 — Membership logging on subnet gates\r\n- **Status:** open · **Origin:** BAROMETER triage (standing recommendation, pre-register)\r\n- **What/why:** counts beside results, membership beside counts — gate logs that state a count\r\n  without naming the population keep producing unreadable reds. Standardize membership\r\n  enumeration in gate output.\r\n- **Ripe when:** next wave touching gate scripts / CI legs that report counts.\r\n- **Size:** small.\r\n- **Composed:** LOCKSMITH (#132) CI-rider cluster, CONDITIONAL — lands iff the hertz thin lane\r\n  touches gate scripts; otherwise stays open here. 2026-08-03. Carried in hertz's 2026-08-03\r\n  dispatch brief as a **conditional** rider. **Condition NOT MET**, answered by the file-set\r\n  audit at [[CI-RIDER LANE STATE]]; new LINK output complied, existing gate-output estate remains.\r\n\r\n### IR-7 — Phase A rigs leak a daemon+brain pair on Windows (exe-lock kills notify relink)\r\n- **Status:** open · **Origin:** BAROMETER post-publish triage (ex releases#124 — full mechanism on the closed issue)\r\n- **What/why:** two Phase A rigs launch daemons that escape the job object via WMI-rung autostart\r\n  (double-space unquoted cmdline fingerprint; SPT_HOME in the wrapper cmdline is the attribution\r\n  key); the leaked pair holds target/debug/spt.exe and kills every golden job reaching the notify\r\n  relink. CI reaps as tourniquet (fa6e597); in-job test launch is the fix.\r\n- **LANE-LINKED 2026-08-30 (#242 close sweep):** hertz's queued daemon-leak fixup lane carries\r\n  this entry (brief cites IR-7/17/20/34/35/63); leaves the register when that lane lands.\r\n- **Ripe when:** next wave touching the Phase A rigs or daemon autostart path.\r\n- **Size:** medium.\r\n\r\n### IR-8 — reap-census scoped_survivors=0 is blind to unreadable-path holders\r\n- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane. · **Origin:** BAROMETER triage\r\n  (ex releases#122)\r\n- **What/why:** a zero that cannot see is not a zero — census scoping skips procs whose exe path is\r\n  unreadable, so the survivors count can report clean while a holder lives. Needs a positive control\r\n  / explicit unreadable bucket in the verdict line (unreadable_path count exists; the ZERO must\r\n  refuse when it is nonzero).\r\n- **Defining specimen (golden 30782259675, hfenduleam test job, 2026-08-03):**\r\n  `CI-REAP summary: killed=5 kill_failed=1 scoped_survivors=0` — an admitted kill failure printed\r\n  beside a zero-survivors claim on the same verdict line. The held image surfaced one step later:\r\n  run-scoped tmp cleanup denied 5/5 attempts on `...\\relshell\\svcmock.exe` (2nd appearance of the\r\n  svcmock hold; 1st @7a3c08c, pre-kill-auth). hertz's addendum: an image-held survivor also blocks\r\n  WRITES to the exe path — the same class manufactures build/relink access-denied reds that mask as\r\n  build problems, not just cleanup warnings. Not per-run: the same-sha green rerun's leg read\r\n  `kill_failed=0 scoped_survivors=0` throughout (hertz, 30784469908) — intermittent sighting,\r\n  second of its class, not a deterministic fixture property.\r\n- **The Linux twin is strictly worse (todlando audit 2026-08-04, vs `b7b00c3`):** `reap-census.sh`\r\n  has NO `kill_failed` anywhere (0 occurrences vs 2 in the `.ps1`) — its kill loop increments\r\n  `killed` only in the success branch with no else, so a failed kill increments nothing and prints\r\n  nothing. The specimen that made this class VISIBLE on Windows would be INVISIBLE on Linux.\r\n  Population precision so this is not overclaimed: ESRCH is benign (already gone; the kill-time\r\n  re-resolve makes it the common case); the vanishing case is EPERM against another account's\r\n  process. The `.sh` `scoped_survivors` DOES come from a post-reap census re-measure, so survivors\r\n  are measured — the hole is failed kills and the unreadable bucket, not the survivor count.\r\n  Windows precision from the same audit: `unreadable_path` IS on the CI-CENSUS line (:157) but the\r\n  CI-REAP verdict line (:243, :246) still carries only killed/kill_failed/scoped_survivors — the\r\n  zero still does not refuse, exactly this entry's ask.\r\n- **Built evidence:** both verdict lines now carry `unreadable_path`; any nonzero unreadable\r\n  family population renders `scoped_survivors=UNPROVEN` rather than a false zero. Linux also\r\n  counts and reports failed kills. The shared predicate is mutation-pinned by\r\n  `reap-census-selftest.sh`; the PowerShell implementation parses cleanly.\r\n- **Ripe when:** next census/reap script wave (natural pair with IR-7's lane) — now BOTH platforms.\r\n- **Size:** small.\r\n\r\n### IR-9 — Golden boxes run different clippy versions\r\n- **Status:** pin LANDED 2026-08-18 at `35968156` (`build: pin Rust 1.96.0`), then\r\n  audited **BUILT** at the 2026-08-29 v0.65.0 close sweep; the pin is an ancestor of\r\n  golden-green cut SHA `4d6007ac`. The earlier measurement half had already landed and run:\r\n  the toolchain print (`8ed006b` → `REQ-CI-TOOLCHAIN-VERSION-PRINT`) exercised both legs of\r\n  golden run 30971976024 (`test` jobs 92198170694/92198170700 — scoped to `test`, not n1-gate;\r\n  grep token `TOOLCHAIN `). Runner-account facts, read by doyle 2026-08-05: hfenduleam\r\n  `cargo/rustc 1.93.0` + `clippy 0.1.93`, kitsubito `cargo/rustc 1.96.0` +\r\n  `clippy 0.1.96`; `stable (default)` on both proved the skew would otherwise decay silently.\r\n- **RULING (doyle, 2026-08-05, on the runner-account facts as the 2026-08-03 hold required):**\r\n  (1) align-by-event REJECTED — with both boxes on unpinned stable, alignment decays silently;\r","startLine":240,"lineNumbers":[240,241,242,243,244,245,246,247,248,249,250,251,252,253,254,255,256,257,258,259,260,261,262,263,264,265,266,267,268,269,270,271,272,273,274,275,276,277,278,279,280,281,282,283,284,285,286,287,288,289,290,291,292,293,294,295,296,297,298,299,300,301,302,303,304,305,306,307,308,309,310,311,312,313,314,315,316,317,318,319,320,321,322,323,324,325,326,327,328,329,330,331,332,333,334,335,336,337,338,339,340,341,342,343,344,345,346,347,348,349,350,351,352,353,354,355,356,357,358,359,360,361,362,363,364,365,366,367,368,369,370,371,372,373,374,375,376,377,378,379,380,381,382,383,384,385,386,387,388,389,390,391,392,393,394,395,396,397,398,399,400,401,402,403,404,405,406,407,408,409,410,411,412,413,414,415,416,417,418,419,420,421,422,423,424,425,426,427,428,429,430,431,432,433,434,435,436,437,438,439,440,441,442,443,444,445,446,447,448,449,450]},"fileSize":676479,"meta":{"source":{"type":"path","value":"C:\\Users\\decid\\Documents\\projects\\spt-core\\.worktrees\\hertz-ir86-disk-delta\\docs\\INFRA-REGISTER.md"},"truncation":{"direction":"head","truncatedBy":"lines","totalLines":6938,"totalBytes":17166,"outputLines":211,"outputBytes":17166,"shownRange":{"start":240,"end":450},"nextOffset":451}}},"isError":false,"timestamp":1789483673578}}
{"type":"message","id":"d9673dbf","parentId":"f2e105b0","timestamp":"2026-09-15T14:47:53.583Z","message":{"role":"toolResult","toolCallId":"call_95qxfo6DVA4e8owaQvY2aZhI|fc_043a862a419f59ae016aa95a997a5c87d2b1c0b8285463a7f4","toolName":"read","content":[{"type":"text","text":"  at 25–43 GB per cold full build is the shape of the next occurrence, and it will not announce\n  itself through pool-claim. Adjacent discipline failure the same night, named so the entry\n  carries it: a gater firing a cold full-workspace rig into a window with two live builder lanes\n  is the pre-flight question-1 failure (right-size the run) — targeted legs and warm pools\n  first.\n- **Remedy shape (sketch, not ruled):** (a) a box-level free-space floor as a RIG STEP at lane\n  start — the claim verb is the natural seat (print box free + du of known lane targets at\n  `pool-claim`, warn under a floor); kin to the CI-side `REQ-CI-FREE-SPACE-PREFLIGHT` (IR-1's\n  companion fix), which covers runners but not agent lane rigs; (b) teardown-on-gate-close is\n  already a rig step (the gate-target-disposal rule) — the gap is the AGGREGATE view across\n  lanes nobody owns; (c) possibly a `pool-census` xtask verb listing every `.worktrees/*/target`\n  with sizes, so the sweep is one command instead of a du walk each agent re-derives.\n- **Ripe when:** next CI/rig-touching wave, or the next ENOSPC-signature red — whichever first.\n- **Size:** small-medium (claim-verb print + floor; census verb optional).\n- **Field addendum (2026-08-04 second event, same day filed — ripeness condition met):** the box\n  fell under the CI runner's 32 GiB free-space floor twice more (12:31 main @9d65e65 docs-only,\n  12:50 PR core#144 @b110bc8) while todlando's F-lane built. Both Windows unit legs REFUSED with\n  `RESOURCE=disk drive=C:\\ free_bytes=…` — the `REQ-CI-FREE-SPACE-PREFLIGHT` floor did exactly its\n  job: a docs-only main red named the resource instead of wearing a linker's face, and triage was\n  one log read instead of an RCA. That is the instrument's first field catch; the CI side of this\n  entry is PROVEN. The agent-lane side stays open: local trough measured 8.8 GB free mid-F-lane.\n  Reclaim, measured before/after per the teardown rule: doyle reaped gated u1+u2 lane targets\n  (POOL-OWNER claims verified own+dead-holder, inbound reparse sweep clean, worktrees kept)\n  8.8 → 59.5 GB (+50.7); hertz reaped er-seams target (pool-release first, same discipline)\n  59.46 → 101.16 GB (+42.66). Refined mechanism statement (hertz, this event): the disk floor is a\n  per-BOX resource our per-POOL instrument is structurally blind to — pool-claim answers a\n  question about contention that is not the question the box ran out of.\n- **AXIS ADDENDUM (deployah, golden 30928816784 / USHER `fc7fad1`, 2026-08-04) — one floor reading\n  is a SNAPSHOT, and the swing is bigger than the margin you fire on.** Two facts this entry's\n  remedy (a) has to be built against, both measured rather than reasoned:\n  (1) **A pre-fire PROCESS census cannot see the floor at all.** Mine came back clean minutes before\n  the run — zero test-path `spt.exe` residents, zero `cargo`/`rustc`/`link`/`cl` — and both Windows\n  legs then died in the disk preflight (`drive=C:\\ free_bytes=26099576832 floor_bytes=34359738368`,\n  `RESOURCE=disk`, exit 1) with a 128-line log carrying ZERO `Compiling`/`PASS`/`FAIL`/`Summary`\n  lines: no test signal, and the merge chain never indicted. Both readings were TRUE at the same\n  instant — the gater's finished assembly gates were sitting on disk as a DIRECTORY, not running as\n  a process. A process-axis probe is blind to a finished build's cost by construction; \"re-check\n  closer to the fire\" would have changed nothing, because the axis was never read.\n  (2) **The floor number itself moves by tens of GB inside one run window.** Same box, same drive,\n  same run, pulled from its own logs: `16:22:55` test-Windows free=26099576832 REFUSED · `16:23:07`\n  n1-gate-Windows free=26096607232 REFUSED · `16:46:54` twohost-a free=71033049088 PASSED and then\n  ran 11 minutes to success. ~45 GB returned with NO deliberate teardown, and my own reading at\n  17:13:45Z was 61352714240 — ~10 GB BELOW what twohost-a saw 27 minutes earlier. The observed swing\n  amplitude EXCEEDED the margin I was about to fire on (25.14 GiB).\n  So the rule remedy (a) must encode: measure BOTH axes (process residents AND free space against\n  the workflow's own 32 GiB floor), and reclaim until the margin exceeds the observed SWING, not one\n  sample. Triage corollary, equally load-bearing: twohost-a runs the same preflight on the same C:\n  and PASSED, so a preflight refusal is a threshold event on a moving number — never evidence the\n  box cannot run the work, and never by itself a reason to indict a merge chain.\n- **THIRD ADDENDUM (deployah, v0.54.0 cut, 2026-08-04) — the sweep answers \"0 B reclaimable\"\n  TRUTHFULLY on a box that cannot run its own work, because the reclaimable population and the\n  owned-lane population are DISJOINT.** This hazard blocked a release twice before it was seen.\n  Both Windows legs at the shipped sha `86f0d84` refused at the guard before compiling anything —\n  `ci.yml` at `free_bytes=28167569408` (26.2 GiB) and `release.yml` at `27690885120` (25.8 GiB),\n  both against `floor_bytes=34359738368`. `assemble` skipped in consequence, so no draft release\n  existed: the release was hard-blocked on disk, not on code. Neither leg produced a test verdict,\n  so both are LABELLED HOLES, not reds (ruled recorded-and-proceed by doyle, the shipped-sha delta\n  being 5 files and zero `.rs`).\n  **The finding is not the disk.** `xtask pool-sweep --root .worktrees` reported, correctly,\n  `total 66.43 GB across 3 pool(s); 0 B reclaimable in this sweep's scope` while the box sat ~6 GB\n  under its own floor. The sweep is behaving as designed — it refuses to reap owned, live lanes.\n  But the floor reasons over an AGGREGATE the sweep is forbidden to touch, so the designed\n  instrument, run at the exact moment of refusal, tells an operator there is nothing to reclaim.\n  That is true and useless. The gap between \"the sweep is correct\" and \"the box can run work\" is\n  the defect; it is not fixed by making the sweep more aggressive.\n  **Aggregate measured under `.worktrees`** (real target bytes, junction-classified first): 87.79 GB\n  across 9 lanes — 2.7x the entire 32 GiB floor. Registered pools: `w1t2-relink-force` 54.67 GB,\n  `obs-resume-attach-intent` 10.18, `w1t2-subnet-status` 1.58. Carrying targets the sweep does not\n  count as claimed pools: `hertz-teardown-bound` 11.25, `hertz-liveresolve-diag` 4.83,\n  `hertz-psyche-bound` 4.19, `hertz-poolowner` 1.03, `hertz-ci-riders` 0.91.\n  **The 54.67 GB single lane is NOT waste** (doyle's classification, ratified at this filing): a\n  verb lane at that size is workspace-all-targets e2e cost. No lane is misbehaving. That is what\n  makes this structural rather than a cleanup task — every lane is individually justified and the\n  sum still exceeds the floor.\n  **Reclaim taken, and its boundary.** 82.12 GB, from `spt-core/target` — the release driver's OWN\n  main-checkout pool, NOT a lane; free 23.23 → 105.34 GB. Classified before removal per the\n  teardown rule: OUTBOUND `Get-Item -Force` reported a real directory rather than a reparse point,\n  the INBOUND sweep found zero reparse points aimed at it, `CARGO_TARGET_DIR` was unset (no env\n  aliasing), the target SUBTREE only was reaped, both sides measured.\n  **Snapshot behavior reproduced inside this measurement window**, corroborating the axis addendum\n  above at a smaller amplitude: free read 25.49 GB when first measured and 23.23 GB at the reap\n  minutes later — it drifted 2.26 GB DOWNWARD while the operator was deciding what to do about it.\n  **Priced side effect, for the next reader:** reaping the main pool took the prebuilt `xtask` with\n  it, so the next lane claim rebuilds it first — the lane-check shortcut is cold until then. It cost\n  a 2m11s cold rebuild inside this release's own publish step.\n  **What this does NOT license:** reaping another agent's owned lane to clear a floor. The sweep's\n  refusal is correct and stays. What is missing is an AGGREGATE-AWARE signal — the box knowing its\n  lanes sum past the floor *before* a run is dispatched into a guard that will decline it.\n- **FOURTH ADDENDUM (doyle, 2026-08-04 late evening — fourth event in one day, and the first\n  RULING on this entry).** C: hit **0.44 GB free** during doyle's lane-2 stack gate and todlando's\n  re-aim leg set. Signatures manufactured this time, all initially read as something else:\n  `os error 112` mid-rlib-archive surfacing as xtask \"building spt failed\" (exit 101); a\n  servicehost force-kill unit red at a sha gated GREEN on the same rig an hour earlier; todlando's\n  6-of-7 leg table red with `LNK1318` while only traceable-reqs survived. Both agents' verdicts\n  from the window were VOIDED and re-run, not re-read.\n  **Discriminator correction (hertz, ratified at this filing):** \"treqs alone survives\" is a\n  POSITIVE TELL, never a clearing test — a full disk reds BEFORE any link step (rustc writing\n  rlibs), and treqs can red for its own reasons; signature absence says NOTHING. The only\n  falsifier for \"this red was the disk\" is free space AT RUN TIME, and no log on the box recorded\n  it, which made every red from the window unanswerable after the fact.\n  **RULING (doyle):** every rig/gate script records `FREE-AT-START` / `FREE-AT-END` in its own\n  SUMMARY — one line each, the datum that makes a disk confound answerable post-hoc. Effective\n  immediately for hand-authored rigs; hertz builds it into the shared rig harness at next touch\n  (assigned, not unasked). This is remedy (a) narrowed to its cheapest load-bearing slice.\n  **Reclaim, all FS-delta-measured:** todlando +59.4 GB (obs-resume-attach-intent 8.56 +\n  w1t2-relink-force 50.83; 0.44 → 59.83), hertz +1.79 GB (ci-riders + poolowner; sum-of-lengths\n  said 1.94, the FS delta governs; 59.09 → 60.87), doyle +38.8 GB (w1t2-subnet-status +\n  w1t2-perch-gc + w1t3-node-verb targets; 60.75 → 99.54). Full discipline each: outbound\n  classification, inbound reparse sweep (zero), CARGO_TARGET_DIR confirmed unset, subtree-only.\n  **Mechanism sharpened by this event:** the standing swing IS the finished-lane population —\n  ~110 GB of pools belonging to lanes already GATED AND PUSHED, held for hours because disposal\n  fires at GATE close (a rig step) while nothing fires at LANE finish; a pushed lane awaiting\n  assembly holds its pool invisibly. Corollary corrections carried: todlando withdrew his\n  name-based pool census (10x off; ancestry, not directory names, classifies a pool as closed),\n  and hertz-selection-probe's worktree removal REFUSED Permission denied — IR-38's second holder\n  class recurring, left for retry rather than forced.\n\n- **FIFTH ADDENDUM (deployah, v0.63.0 FIELD-SEAL golden, 2026-08-25) — SCOPED DELIBERATELY TO ONE\n  CONSEQUENCE: reaping a pool UNCLAIMS its tree, and the next builder meets a refusal that is the\n  rule working.** (The disk-floor mechanism from the same event is doyle's to file at his\n  release-close sweep — one voice each, by division agreed in-window. This addendum stops at the\n  pool-claim consequence and deliberately does not restate the floor finding.)\n  Five FIELD-SEAL lane pools were reaped to clear the golden floor — gate rig `gate-222-ca30a79e`\n  plus lanes `fix-222`, `w2-seal-ux`, `w3-ingest`, `w4-exit-subject`; **148.48 GB measured by FS\n  delta**, free 1.37 → 149.84 GB, worktree checkouts kept, `main/target` untouched by ruling.\n  **The consequence to record:** `POOL-OWNER.json` lives INSIDE `target/`, so reaping the subtree\n  takes the claim with it. Those five trees are now **UNCLAIMED — which is fresh-not-foreign**, a\n  different state from the `SPT_POOL_FOREIGN` refusal. Whoever resumes one of those lanes (a hertz\n  fixup, a golden-red rebuild) must run `cargo run -p xtask -- pool-claim --pool <dir> --label\n  <lane>` **from that worktree** before the first build, or `crates/spt-store/build.rs` refuses.\n  **A refusal there is the rule working, not a defect** — filed precisely so a later reader does\n  not open an issue against the build script for behaving correctly. Naming it costs one line;\n  the alternative is an RCA against our own guard.\n  **Prediction-vs-meter, corroborating hertz's fourth-addendum note at ~75x its scale:** pre-reap\n  sum-of-lengths sizing predicted 163.9 GB; the FS delta paid 148.48 GB, a 15.4 GB shortfall left\n  UNEXPLAINED here rather than rationalized (allocation granularity, sparse/compressed extents and\n  concurrent writes all sit between the two meters). **The FS delta governs** — hertz ruled this at\n  1.94-vs-actual and it holds at three digits. Report the meter, never the estimate that agreed\n  with your plan.\n  **Discipline executed, for the audit trail:** outbound classification re-read AT REAP TIME (all\n  five real dirs, zero LinkType); inbound sweep over **2854** reparse points under `projects\\`\n  found zero aimed at any victim; `CARGO_TARGET_DIR` confirmed empty in process, **Machine and\n  User** scope (the arm that leaves no directory entry to notice afterwards); process census\n  RE-RUN at reap time rather than carried from a peer's snapshot — zero builders, zero processes\n  imaged out of a victim pool, both live `spt` images resolving to the installed path. The peer's\n  snapshot proved correct; it was re-run because a snapshot is not a standing property, which is\n  the reason it was offered with that caveat.\n\n### IR-32 — Docs-drift gate blesses its own gen: an empty-emitting producer agrees with itself perfectly\n- **Status:** open · **Origin:** todlando mid-lane stop-and-report, U1 (#144) 2026-08-04. Filed by\n  the builder to the gater deliberately — register shape is doyle's to own.\n- **What/why:** with a defective binary in the tree (stack-overflowed before reaching its own\n  code, empty stdout, non-fatal to the generator), `cargo run -p xtask -- gen` wrote\n  `docs-site/src/cli/reference.md` reduced to EIGHT lines — title, do-not-edit banner, empty code\n  fence — deleting 3193 lines of published CLI reference. `xtask check` then exited 0, because\n  the drift gate compares what the binary emits NOW against what the file holds, and gen had just\n  overwritten the file with exactly that emit. **A producer that emits nothing agrees with itself\n  perfectly.** Caught only because the builder grepped the regenerated page for his new flag\n  names and treated the clean zero as suspicious ([[zero-match-filter-reads-as-absent]] shape);\n  the gate itself would never have said a word, and the gutted public reference ships green.\n  The mechanism generalizes past the stack overflow that exposed it: ANY failure mode that makes\n  `spt --help` produce empty stdout while exiting non-fatally to the generator gets the same\n  green. Kin to [[cli-command-docs-drift]] (the gate this defeats) — the gate detects DRIFT\n  between binary and page, and is structurally blind to a page just regenerated from a broken\n  binary.\n- **Remedy shape (builder's sketch, sound; not yet ruled on seat):** a floor in `xtask gen` —\n  refuse to write a page whose help block is empty, or whose output is implausibly shorter than\n  the file it replaces — so the generator fails loudly instead of producing a stub the gate\n  blesses. Gen is the right seat: check runs in CI on a fresh emit too, so a check-side floor\n  alone still lets a local gen gut the working tree.\n- **Ripe when:** next docs-tooling or xtask-touching lane; SOONER if any lane regenerates the CLI\n  reference before the floor exists (a gate on that lane must assert page LENGTH, not gen's exit\n  code, until this is built).\n- **Size:** small (one refusal + a length-plausibility floor in gen).\n\n- **Kin instance 2026-09-11 (hertz, #304 lane, caught before launch):** the RUN expression for the\n  spt-daemon lib producer was still the 15-term webserve list after six #297 cases had been admitted\n  and inventoried at 21 terms. It would have executed 15 and reported against a 21-term inventory —\n  a subset quietly narrower than the thing it claims to discharge, with a count that reads fine.\n  Rule: a run filter is diffed TERM-FOR-TERM against the inventory it discharges before launch; a\n  matching case count is not that check.\n\n### IR-33 — Debug-build clap Command tree runs near the main-thread stack ceiling; the margin is THREE net new args, bisected at `8f291e1` (the original ~6 was measured on U1's tree and is superseded)\n- **Status:** OPEN for acceptance/margin reconciliation. Current source at `e5a2fed9` runs\n  the CLI on an owned 16 MiB thread stack and includes `cli_stack_smoke`; the three-argument\n  ceiling below is a historical measurement at `8f291e1`, NOT today's measured margin.\n  Do not redispatch an already-present sized-stack implementation. No fresh debug-run\n  acceptance is claimed by this source read (2026-09-11). · **Origin:** todlando U1 (#144)\n  2026-08-04, delta-tested mid-lane.\n- **What/why:** eight extra hidden bool args across the five knock seats grew the derive-built\n  Command tree past what the debug binary's main thread stack can construct: EVERY invocation\n  (`spt --version` included) died with `thread 'main' has overflowed its stack`, exit\n  -1073741571, before reaching any of its own code. Delta-tested, not assumed: the same command\n  on the main-pool binary from main printed normally. U1 repaired its own trigger (raw-argv\n  pre-scan for retired flags before clap parses; lane ends net +2 args) — but the CEILING\n  remains: the tree is now close enough that a handful of net new arguments in a debug build\n  reproduce a total binary outage — **and the handful is THREE, not six; see the correction\n  below before planning against this entry.** **#5's verb-surface rework is the next lane that adds\n  arguments and it is much bigger than U1** — this entry exists so #5 is planned knowing the\n  margin, not discovering it. Note the failure's face: it presents as a broken binary, and via\n  [[IR-32]] it presents as a silently gutted docs page — neither names the stack.\n- **CORRECTION — the margin is THREE, bisected at `8f291e1` (todlando's U3 lane\n  `build/usher-u3-verb-surface`, own pool, debug profile; filed by deployah 2026-08-04).** The\n  original ~6 was measured on U1's tree and was right when written; it is wrong now, and the\n  difference is the difference between \"plan carefully\" and \"one flag anywhere takes the binary\n  down\". N hidden bool args added to the ROOT `Cli` derive, tree restored from git between every\n  row, `--version` as the invocation (it carries no work of its own, so whatever it costs IS tree\n  construction):\n\n      N=0  exit 0                OK  (control — unmodified lane binary answers `spt 0.53.0`)\n      N=1  exit 0                OK\n      N=2  exit 0                OK\n      N=3  exit -1073741571      STACK-OVERFLOW\n      N=4 / N=6 / N=8            STACK-OVERFLOW\n\n  PLACEMENT DIFFERENTIAL, run because #5 adds args at `EndpointCmd` seats rather than at the root\n  and a root-only number could have measured the wrong thing: same N injected inside a NESTED\n  endpoint seat gives `SEAT N=2` OK, `SEAT N=3` STACK-OVERFLOW. **Identical ceiling — placement does\n  not move it**, so three is the number for the shape #5 actually builds. (Rig hazard worth keeping:\n  the first seat attempt produced a COMPILE error, E0027, because the dispatch destructures that\n  variant exhaustively — taken at face value it would have read as \"the seat is fine\". Both rows\n  above are from the fixed rig.) CONSEQUENCE FOR #5: the ratified MIN spelling ends net +2, i.e. it\n  would have shipped with ONE argument of headroom, and any later lane adding a single flag anywhere\n  in the tree would then take the whole binary down, `--version` included. Remedy (b) below stops\n  being \"buys headroom\" and becomes the precondition for #5 shipping safely.\n- **Remedy shape (sketch, not ruled):** (a) cheapest tooth — a debug-build smoke that runs\n  `spt --help` and asserts non-empty stdout + exit 0, which also backstops IR-32's trigger;\n  (b) raise the main thread stack for the binary (build config), buying headroom without\n  restructuring; (c) structural — box/flatten the derive tree so construction cost stops scaling\n  with arg count. (a) is a rider candidate for any lane; (b)/(c) want a real measurement of\n  where the ceiling sits before choosing.\n- **Ripe when:** #5 (U3 verb surface) PLANNING — this is a planning input, not just a build item;\n  the smoke tooth (a) is ripe for the next CI-touching lane regardless.\n- **Size:** small for (a); medium for (b)/(c) with the measurement.\n\n\n[Showing lines 2030-2264 of 6938. Use :2265 to continue]"}],"details":{"truncation":{"content":"  at 25–43 GB per cold full build is the shape of the next occurrence, and it will not announce\r\n  itself through pool-claim. Adjacent discipline failure the same night, named so the entry\r\n  carries it: a gater firing a cold full-workspace rig into a window with two live builder lanes\r\n  is the pre-flight question-1 failure (right-size the run) — targeted legs and warm pools\r\n  first.\r\n- **Remedy shape (sketch, not ruled):** (a) a box-level free-space floor as a RIG STEP at lane\r\n  start — the claim verb is the natural seat (print box free + du of known lane targets at\r\n  `pool-claim`, warn under a floor); kin to the CI-side `REQ-CI-FREE-SPACE-PREFLIGHT` (IR-1's\r\n  companion fix), which covers runners but not agent lane rigs; (b) teardown-on-gate-close is\r\n  already a rig step (the gate-target-disposal rule) — the gap is the AGGREGATE view across\r\n  lanes nobody owns; (c) possibly a `pool-census` xtask verb listing every `.worktrees/*/target`\r\n  with sizes, so the sweep is one command instead of a du walk each agent re-derives.\r\n- **Ripe when:** next CI/rig-touching wave, or the next ENOSPC-signature red — whichever first.\r\n- **Size:** small-medium (claim-verb print + floor; census verb optional).\r\n- **Field addendum (2026-08-04 second event, same day filed — ripeness condition met):** the box\r\n  fell under the CI runner's 32 GiB free-space floor twice more (12:31 main @9d65e65 docs-only,\r\n  12:50 PR core#144 @b110bc8) while todlando's F-lane built. Both Windows unit legs REFUSED with\r\n  `RESOURCE=disk drive=C:\\ free_bytes=…` — the `REQ-CI-FREE-SPACE-PREFLIGHT` floor did exactly its\r\n  job: a docs-only main red named the resource instead of wearing a linker's face, and triage was\r\n  one log read instead of an RCA. That is the instrument's first field catch; the CI side of this\r\n  entry is PROVEN. The agent-lane side stays open: local trough measured 8.8 GB free mid-F-lane.\r\n  Reclaim, measured before/after per the teardown rule: doyle reaped gated u1+u2 lane targets\r\n  (POOL-OWNER claims verified own+dead-holder, inbound reparse sweep clean, worktrees kept)\r\n  8.8 → 59.5 GB (+50.7); hertz reaped er-seams target (pool-release first, same discipline)\r\n  59.46 → 101.16 GB (+42.66). Refined mechanism statement (hertz, this event): the disk floor is a\r\n  per-BOX resource our per-POOL instrument is structurally blind to — pool-claim answers a\r\n  question about contention that is not the question the box ran out of.\r\n- **AXIS ADDENDUM (deployah, golden 30928816784 / USHER `fc7fad1`, 2026-08-04) — one floor reading\r\n  is a SNAPSHOT, and the swing is bigger than the margin you fire on.** Two facts this entry's\r\n  remedy (a) has to be built against, both measured rather than reasoned:\r\n  (1) **A pre-fire PROCESS census cannot see the floor at all.** Mine came back clean minutes before\r\n  the run — zero test-path `spt.exe` residents, zero `cargo`/`rustc`/`link`/`cl` — and both Windows\r\n  legs then died in the disk preflight (`drive=C:\\ free_bytes=26099576832 floor_bytes=34359738368`,\r\n  `RESOURCE=disk`, exit 1) with a 128-line log carrying ZERO `Compiling`/`PASS`/`FAIL`/`Summary`\r\n  lines: no test signal, and the merge chain never indicted. Both readings were TRUE at the same\r\n  instant — the gater's finished assembly gates were sitting on disk as a DIRECTORY, not running as\r\n  a process. A process-axis probe is blind to a finished build's cost by construction; \"re-check\r\n  closer to the fire\" would have changed nothing, because the axis was never read.\r\n  (2) **The floor number itself moves by tens of GB inside one run window.** Same box, same drive,\r\n  same run, pulled from its own logs: `16:22:55` test-Windows free=26099576832 REFUSED · `16:23:07`\r\n  n1-gate-Windows free=26096607232 REFUSED · `16:46:54` twohost-a free=71033049088 PASSED and then\r\n  ran 11 minutes to success. ~45 GB returned with NO deliberate teardown, and my own reading at\r\n  17:13:45Z was 61352714240 — ~10 GB BELOW what twohost-a saw 27 minutes earlier. The observed swing\r\n  amplitude EXCEEDED the margin I was about to fire on (25.14 GiB).\r\n  So the rule remedy (a) must encode: measure BOTH axes (process residents AND free space against\r\n  the workflow's own 32 GiB floor), and reclaim until the margin exceeds the observed SWING, not one\r\n  sample. Triage corollary, equally load-bearing: twohost-a runs the same preflight on the same C:\r\n  and PASSED, so a preflight refusal is a threshold event on a moving number — never evidence the\r\n  box cannot run the work, and never by itself a reason to indict a merge chain.\r\n- **THIRD ADDENDUM (deployah, v0.54.0 cut, 2026-08-04) — the sweep answers \"0 B reclaimable\"\r\n  TRUTHFULLY on a box that cannot run its own work, because the reclaimable population and the\r\n  owned-lane population are DISJOINT.** This hazard blocked a release twice before it was seen.\r\n  Both Windows legs at the shipped sha `86f0d84` refused at the guard before compiling anything —\r\n  `ci.yml` at `free_bytes=28167569408` (26.2 GiB) and `release.yml` at `27690885120` (25.8 GiB),\r\n  both against `floor_bytes=34359738368`. `assemble` skipped in consequence, so no draft release\r\n  existed: the release was hard-blocked on disk, not on code. Neither leg produced a test verdict,\r\n  so both are LABELLED HOLES, not reds (ruled recorded-and-proceed by doyle, the shipped-sha delta\r\n  being 5 files and zero `.rs`).\r\n  **The finding is not the disk.** `xtask pool-sweep --root .worktrees` reported, correctly,\r\n  `total 66.43 GB across 3 pool(s); 0 B reclaimable in this sweep's scope` while the box sat ~6 GB\r\n  under its own floor. The sweep is behaving as designed — it refuses to reap owned, live lanes.\r\n  But the floor reasons over an AGGREGATE the sweep is forbidden to touch, so the designed\r\n  instrument, run at the exact moment of refusal, tells an operator there is nothing to reclaim.\r\n  That is true and useless. The gap between \"the sweep is correct\" and \"the box can run work\" is\r\n  the defect; it is not fixed by making the sweep more aggressive.\r\n  **Aggregate measured under `.worktrees`** (real target bytes, junction-classified first): 87.79 GB\r\n  across 9 lanes — 2.7x the entire 32 GiB floor. Registered pools: `w1t2-relink-force` 54.67 GB,\r\n  `obs-resume-attach-intent` 10.18, `w1t2-subnet-status` 1.58. Carrying targets the sweep does not\r\n  count as claimed pools: `hertz-teardown-bound` 11.25, `hertz-liveresolve-diag` 4.83,\r\n  `hertz-psyche-bound` 4.19, `hertz-poolowner` 1.03, `hertz-ci-riders` 0.91.\r\n  **The 54.67 GB single lane is NOT waste** (doyle's classification, ratified at this filing): a\r\n  verb lane at that size is workspace-all-targets e2e cost. No lane is misbehaving. That is what\r\n  makes this structural rather than a cleanup task — every lane is individually justified and the\r\n  sum still exceeds the floor.\r\n  **Reclaim taken, and its boundary.** 82.12 GB, from `spt-core/target` — the release driver's OWN\r\n  main-checkout pool, NOT a lane; free 23.23 → 105.34 GB. Classified before removal per the\r\n  teardown rule: OUTBOUND `Get-Item -Force` reported a real directory rather than a reparse point,\r\n  the INBOUND sweep found zero reparse points aimed at it, `CARGO_TARGET_DIR` was unset (no env\r\n  aliasing), the target SUBTREE only was reaped, both sides measured.\r\n  **Snapshot behavior reproduced inside this measurement window**, corroborating the axis addendum\r\n  above at a smaller amplitude: free read 25.49 GB when first measured and 23.23 GB at the reap\r\n  minutes later — it drifted 2.26 GB DOWNWARD while the operator was deciding what to do about it.\r\n  **Priced side effect, for the next reader:** reaping the main pool took the prebuilt `xtask` with\r\n  it, so the next lane claim rebuilds it first — the lane-check shortcut is cold until then. It cost\r\n  a 2m11s cold rebuild inside this release's own publish step.\r\n  **What this does NOT license:** reaping another agent's owned lane to clear a floor. The sweep's\r\n  refusal is correct and stays. What is missing is an AGGREGATE-AWARE signal — the box knowing its\r\n  lanes sum past the floor *before* a run is dispatched into a guard that will decline it.\r\n- **FOURTH ADDENDUM (doyle, 2026-08-04 late evening — fourth event in one day, and the first\r\n  RULING on this entry).** C: hit **0.44 GB free** during doyle's lane-2 stack gate and todlando's\r\n  re-aim leg set. Signatures manufactured this time, all initially read as something else:\r\n  `os error 112` mid-rlib-archive surfacing as xtask \"building spt failed\" (exit 101); a\r\n  servicehost force-kill unit red at a sha gated GREEN on the same rig an hour earlier; todlando's\r\n  6-of-7 leg table red with `LNK1318` while only traceable-reqs survived. Both agents' verdicts\r\n  from the window were VOIDED and re-run, not re-read.\r\n  **Discriminator correction (hertz, ratified at this filing):** \"treqs alone survives\" is a\r\n  POSITIVE TELL, never a clearing test — a full disk reds BEFORE any link step (rustc writing\r\n  rlibs), and treqs can red for its own reasons; signature absence says NOTHING. The only\r\n  falsifier for \"this red was the disk\" is free space AT RUN TIME, and no log on the box recorded\r\n  it, which made every red from the window unanswerable after the fact.\r\n  **RULING (doyle):** every rig/gate script records `FREE-AT-START` / `FREE-AT-END` in its own\r\n  SUMMARY — one line each, the datum that makes a disk confound answerable post-hoc. Effective\r\n  immediately for hand-authored rigs; hertz builds it into the shared rig harness at next touch\r\n  (assigned, not unasked). This is remedy (a) narrowed to its cheapest load-bearing slice.\r\n  **Reclaim, all FS-delta-measured:** todlando +59.4 GB (obs-resume-attach-intent 8.56 +\r\n  w1t2-relink-force 50.83; 0.44 → 59.83), hertz +1.79 GB (ci-riders + poolowner; sum-of-lengths\r\n  said 1.94, the FS delta governs; 59.09 → 60.87), doyle +38.8 GB (w1t2-subnet-status +\r\n  w1t2-perch-gc + w1t3-node-verb targets; 60.75 → 99.54). Full discipline each: outbound\r\n  classification, inbound reparse sweep (zero), CARGO_TARGET_DIR confirmed unset, subtree-only.\r\n  **Mechanism sharpened by this event:** the standing swing IS the finished-lane population —\r\n  ~110 GB of pools belonging to lanes already GATED AND PUSHED, held for hours because disposal\r\n  fires at GATE close (a rig step) while nothing fires at LANE finish; a pushed lane awaiting\r\n  assembly holds its pool invisibly. Corollary corrections carried: todlando withdrew his\r\n  name-based pool census (10x off; ancestry, not directory names, classifies a pool as closed),\r\n  and hertz-selection-probe's worktree removal REFUSED Permission denied — IR-38's second holder\r\n  class recurring, left for retry rather than forced.\r\n\r\n- **FIFTH ADDENDUM (deployah, v0.63.0 FIELD-SEAL golden, 2026-08-25) — SCOPED DELIBERATELY TO ONE\r\n  CONSEQUENCE: reaping a pool UNCLAIMS its tree, and the next builder meets a refusal that is the\r\n  rule working.** (The disk-floor mechanism from the same event is doyle's to file at his\r\n  release-close sweep — one voice each, by division agreed in-window. This addendum stops at the\r\n  pool-claim consequence and deliberately does not restate the floor finding.)\r\n  Five FIELD-SEAL lane pools were reaped to clear the golden floor — gate rig `gate-222-ca30a79e`\r\n  plus lanes `fix-222`, `w2-seal-ux`, `w3-ingest`, `w4-exit-subject`; **148.48 GB measured by FS\r\n  delta**, free 1.37 → 149.84 GB, worktree checkouts kept, `main/target` untouched by ruling.\r\n  **The consequence to record:** `POOL-OWNER.json` lives INSIDE `target/`, so reaping the subtree\r\n  takes the claim with it. Those five trees are now **UNCLAIMED — which is fresh-not-foreign**, a\r\n  different state from the `SPT_POOL_FOREIGN` refusal. Whoever resumes one of those lanes (a hertz\r\n  fixup, a golden-red rebuild) must run `cargo run -p xtask -- pool-claim --pool <dir> --label\r\n  <lane>` **from that worktree** before the first build, or `crates/spt-store/build.rs` refuses.\r\n  **A refusal there is the rule working, not a defect** — filed precisely so a later reader does\r\n  not open an issue against the build script for behaving correctly. Naming it costs one line;\r\n  the alternative is an RCA against our own guard.\r\n  **Prediction-vs-meter, corroborating hertz's fourth-addendum note at ~75x its scale:** pre-reap\r\n  sum-of-lengths sizing predicted 163.9 GB; the FS delta paid 148.48 GB, a 15.4 GB shortfall left\r\n  UNEXPLAINED here rather than rationalized (allocation granularity, sparse/compressed extents and\r\n  concurrent writes all sit between the two meters). **The FS delta governs** — hertz ruled this at\r\n  1.94-vs-actual and it holds at three digits. Report the meter, never the estimate that agreed\r\n  with your plan.\r\n  **Discipline executed, for the audit trail:** outbound classification re-read AT REAP TIME (all\r\n  five real dirs, zero LinkType); inbound sweep over **2854** reparse points under `projects\\`\r\n  found zero aimed at any victim; `CARGO_TARGET_DIR` confirmed empty in process, **Machine and\r\n  User** scope (the arm that leaves no directory entry to notice afterwards); process census\r\n  RE-RUN at reap time rather than carried from a peer's snapshot — zero builders, zero processes\r\n  imaged out of a victim pool, both live `spt` images resolving to the installed path. The peer's\r\n  snapshot proved correct; it was re-run because a snapshot is not a standing property, which is\r\n  the reason it was offered with that caveat.\r\n\r\n### IR-32 — Docs-drift gate blesses its own gen: an empty-emitting producer agrees with itself perfectly\r\n- **Status:** open · **Origin:** todlando mid-lane stop-and-report, U1 (#144) 2026-08-04. Filed by\r\n  the builder to the gater deliberately — register shape is doyle's to own.\r\n- **What/why:** with a defective binary in the tree (stack-overflowed before reaching its own\r\n  code, empty stdout, non-fatal to the generator), `cargo run -p xtask -- gen` wrote\r\n  `docs-site/src/cli/reference.md` reduced to EIGHT lines — title, do-not-edit banner, empty code\r\n  fence — deleting 3193 lines of published CLI reference. `xtask check` then exited 0, because\r\n  the drift gate compares what the binary emits NOW against what the file holds, and gen had just\r\n  overwritten the file with exactly that emit. **A producer that emits nothing agrees with itself\r\n  perfectly.** Caught only because the builder grepped the regenerated page for his new flag\r\n  names and treated the clean zero as suspicious ([[zero-match-filter-reads-as-absent]] shape);\r\n  the gate itself would never have said a word, and the gutted public reference ships green.\r\n  The mechanism generalizes past the stack overflow that exposed it: ANY failure mode that makes\r\n  `spt --help` produce empty stdout while exiting non-fatally to the generator gets the same\r\n  green. Kin to [[cli-command-docs-drift]] (the gate this defeats) — the gate detects DRIFT\r\n  between binary and page, and is structurally blind to a page just regenerated from a broken\r\n  binary.\r\n- **Remedy shape (builder's sketch, sound; not yet ruled on seat):** a floor in `xtask gen` —\r\n  refuse to write a page whose help block is empty, or whose output is implausibly shorter than\r\n  the file it replaces — so the generator fails loudly instead of producing a stub the gate\r\n  blesses. Gen is the right seat: check runs in CI on a fresh emit too, so a check-side floor\r\n  alone still lets a local gen gut the working tree.\r\n- **Ripe when:** next docs-tooling or xtask-touching lane; SOONER if any lane regenerates the CLI\r\n  reference before the floor exists (a gate on that lane must assert page LENGTH, not gen's exit\r\n  code, until this is built).\r\n- **Size:** small (one refusal + a length-plausibility floor in gen).\r\n\r\n- **Kin instance 2026-09-11 (hertz, #304 lane, caught before launch):** the RUN expression for the\r\n  spt-daemon lib producer was still the 15-term webserve list after six #297 cases had been admitted\r\n  and inventoried at 21 terms. It would have executed 15 and reported against a 21-term inventory —\r\n  a subset quietly narrower than the thing it claims to discharge, with a count that reads fine.\r\n  Rule: a run filter is diffed TERM-FOR-TERM against the inventory it discharges before launch; a\r\n  matching case count is not that check.\r\n\r\n### IR-33 — Debug-build clap Command tree runs near the main-thread stack ceiling; the margin is THREE net new args, bisected at `8f291e1` (the original ~6 was measured on U1's tree and is superseded)\r\n- **Status:** OPEN for acceptance/margin reconciliation. Current source at `e5a2fed9` runs\r\n  the CLI on an owned 16 MiB thread stack and includes `cli_stack_smoke`; the three-argument\r\n  ceiling below is a historical measurement at `8f291e1`, NOT today's measured margin.\r\n  Do not redispatch an already-present sized-stack implementation. No fresh debug-run\r\n  acceptance is claimed by this source read (2026-09-11). · **Origin:** todlando U1 (#144)\r\n  2026-08-04, delta-tested mid-lane.\r\n- **What/why:** eight extra hidden bool args across the five knock seats grew the derive-built\r\n  Command tree past what the debug binary's main thread stack can construct: EVERY invocation\r\n  (`spt --version` included) died with `thread 'main' has overflowed its stack`, exit\r\n  -1073741571, before reaching any of its own code. Delta-tested, not assumed: the same command\r\n  on the main-pool binary from main printed normally. U1 repaired its own trigger (raw-argv\r\n  pre-scan for retired flags before clap parses; lane ends net +2 args) — but the CEILING\r\n  remains: the tree is now close enough that a handful of net new arguments in a debug build\r\n  reproduce a total binary outage — **and the handful is THREE, not six; see the correction\r\n  below before planning against this entry.** **#5's verb-surface rework is the next lane that adds\r\n  arguments and it is much bigger than U1** — this entry exists so #5 is planned knowing the\r\n  margin, not discovering it. Note the failure's face: it presents as a broken binary, and via\r\n  [[IR-32]] it presents as a silently gutted docs page — neither names the stack.\r\n- **CORRECTION — the margin is THREE, bisected at `8f291e1` (todlando's U3 lane\r\n  `build/usher-u3-verb-surface`, own pool, debug profile; filed by deployah 2026-08-04).** The\r\n  original ~6 was measured on U1's tree and was right when written; it is wrong now, and the\r\n  difference is the difference between \"plan carefully\" and \"one flag anywhere takes the binary\r\n  down\". N hidden bool args added to the ROOT `Cli` derive, tree restored from git between every\r\n  row, `--version` as the invocation (it carries no work of its own, so whatever it costs IS tree\r\n  construction):\r\n\r\n      N=0  exit 0                OK  (control — unmodified lane binary answers `spt 0.53.0`)\r\n      N=1  exit 0                OK\r\n      N=2  exit 0                OK\r\n      N=3  exit -1073741571      STACK-OVERFLOW\r\n      N=4 / N=6 / N=8            STACK-OVERFLOW\r\n\r\n  PLACEMENT DIFFERENTIAL, run because #5 adds args at `EndpointCmd` seats rather than at the root\r\n  and a root-only number could have measured the wrong thing: same N injected inside a NESTED\r\n  endpoint seat gives `SEAT N=2` OK, `SEAT N=3` STACK-OVERFLOW. **Identical ceiling — placement does\r\n  not move it**, so three is the number for the shape #5 actually builds. (Rig hazard worth keeping:\r\n  the first seat attempt produced a COMPILE error, E0027, because the dispatch destructures that\r\n  variant exhaustively — taken at face value it would have read as \"the seat is fine\". Both rows\r\n  above are from the fixed rig.) CONSEQUENCE FOR #5: the ratified MIN spelling ends net +2, i.e. it\r\n  would have shipped with ONE argument of headroom, and any later lane adding a single flag anywhere\r\n  in the tree would then take the whole binary down, `--version` included. Remedy (b) below stops\r\n  being \"buys headroom\" and becomes the precondition for #5 shipping safely.\r\n- **Remedy shape (sketch, not ruled):** (a) cheapest tooth — a debug-build smoke that runs\r\n  `spt --help` and asserts non-empty stdout + exit 0, which also backstops IR-32's trigger;\r\n  (b) raise the main thread stack for the binary (build config), buying headroom without\r\n  restructuring; (c) structural — box/flatten the derive tree so construction cost stops scaling\r\n  with arg count. (a) is a rider candidate for any lane; (b)/(c) want a real measurement of\r\n  where the ceiling sits before choosing.\r\n- **Ripe when:** #5 (U3 verb surface) PLANNING — this is a planning input, not just a build item;\r\n  the smoke tooth (a) is ripe for the next CI-touching lane regardless.\r\n- **Size:** small for (a); medium for (b)/(c) with the measurement.\r\n\r","truncated":true,"truncatedBy":"lines","totalLines":4909,"totalBytes":20763,"outputLines":235,"outputBytes":20763,"lastLinePartial":false,"firstLineExceedsLimit":false},"totalLines":6938,"displayContent":{"text":"  at 25–43 GB per cold full build is the shape of the next occurrence, and it will not announce\r\n  itself through pool-claim. Adjacent discipline failure the same night, named so the entry\r\n  carries it: a gater firing a cold full-workspace rig into a window with two live builder lanes\r\n  is the pre-flight question-1 failure (right-size the run) — targeted legs and warm pools\r\n  first.\r\n- **Remedy shape (sketch, not ruled):** (a) a box-level free-space floor as a RIG STEP at lane\r\n  start — the claim verb is the natural seat (print box free + du of known lane targets at\r\n  `pool-claim`, warn under a floor); kin to the CI-side `REQ-CI-FREE-SPACE-PREFLIGHT` (IR-1's\r\n  companion fix), which covers runners but not agent lane rigs; (b) teardown-on-gate-close is\r\n  already a rig step (the gate-target-disposal rule) — the gap is the AGGREGATE view across\r\n  lanes nobody owns; (c) possibly a `pool-census` xtask verb listing every `.worktrees/*/target`\r\n  with sizes, so the sweep is one command instead of a du walk each agent re-derives.\r\n- **Ripe when:** next CI/rig-touching wave, or the next ENOSPC-signature red — whichever first.\r\n- **Size:** small-medium (claim-verb print + floor; census verb optional).\r\n- **Field addendum (2026-08-04 second event, same day filed — ripeness condition met):** the box\r\n  fell under the CI runner's 32 GiB free-space floor twice more (12:31 main @9d65e65 docs-only,\r\n  12:50 PR core#144 @b110bc8) while todlando's F-lane built. Both Windows unit legs REFUSED with\r\n  `RESOURCE=disk drive=C:\\ free_bytes=…` — the `REQ-CI-FREE-SPACE-PREFLIGHT` floor did exactly its\r\n  job: a docs-only main red named the resource instead of wearing a linker's face, and triage was\r\n  one log read instead of an RCA. That is the instrument's first field catch; the CI side of this\r\n  entry is PROVEN. The agent-lane side stays open: local trough measured 8.8 GB free mid-F-lane.\r\n  Reclaim, measured before/after per the teardown rule: doyle reaped gated u1+u2 lane targets\r\n  (POOL-OWNER claims verified own+dead-holder, inbound reparse sweep clean, worktrees kept)\r\n  8.8 → 59.5 GB (+50.7); hertz reaped er-seams target (pool-release first, same discipline)\r\n  59.46 → 101.16 GB (+42.66). Refined mechanism statement (hertz, this event): the disk floor is a\r\n  per-BOX resource our per-POOL instrument is structurally blind to — pool-claim answers a\r\n  question about contention that is not the question the box ran out of.\r\n- **AXIS ADDENDUM (deployah, golden 30928816784 / USHER `fc7fad1`, 2026-08-04) — one floor reading\r\n  is a SNAPSHOT, and the swing is bigger than the margin you fire on.** Two facts this entry's\r\n  remedy (a) has to be built against, both measured rather than reasoned:\r\n  (1) **A pre-fire PROCESS census cannot see the floor at all.** Mine came back clean minutes before\r\n  the run — zero test-path `spt.exe` residents, zero `cargo`/`rustc`/`link`/`cl` — and both Windows\r\n  legs then died in the disk preflight (`drive=C:\\ free_bytes=26099576832 floor_bytes=34359738368`,\r\n  `RESOURCE=disk`, exit 1) with a 128-line log carrying ZERO `Compiling`/`PASS`/`FAIL`/`Summary`\r\n  lines: no test signal, and the merge chain never indicted. Both readings were TRUE at the same\r\n  instant — the gater's finished assembly gates were sitting on disk as a DIRECTORY, not running as\r\n  a process. A process-axis probe is blind to a finished build's cost by construction; \"re-check\r\n  closer to the fire\" would have changed nothing, because the axis was never read.\r\n  (2) **The floor number itself moves by tens of GB inside one run window.** Same box, same drive,\r\n  same run, pulled from its own logs: `16:22:55` test-Windows free=26099576832 REFUSED · `16:23:07`\r\n  n1-gate-Windows free=26096607232 REFUSED · `16:46:54` twohost-a free=71033049088 PASSED and then\r\n  ran 11 minutes to success. ~45 GB returned with NO deliberate teardown, and my own reading at\r\n  17:13:45Z was 61352714240 — ~10 GB BELOW what twohost-a saw 27 minutes earlier. The observed swing\r\n  amplitude EXCEEDED the margin I was about to fire on (25.14 GiB).\r\n  So the rule remedy (a) must encode: measure BOTH axes (process residents AND free space against\r\n  the workflow's own 32 GiB floor), and reclaim until the margin exceeds the observed SWING, not one\r\n  sample. Triage corollary, equally load-bearing: twohost-a runs the same preflight on the same C:\r\n  and PASSED, so a preflight refusal is a threshold event on a moving number — never evidence the\r\n  box cannot run the work, and never by itself a reason to indict a merge chain.\r\n- **THIRD ADDENDUM (deployah, v0.54.0 cut, 2026-08-04) — the sweep answers \"0 B reclaimable\"\r\n  TRUTHFULLY on a box that cannot run its own work, because the reclaimable population and the\r\n  owned-lane population are DISJOINT.** This hazard blocked a release twice before it was seen.\r\n  Both Windows legs at the shipped sha `86f0d84` refused at the guard before compiling anything —\r\n  `ci.yml` at `free_bytes=28167569408` (26.2 GiB) and `release.yml` at `27690885120` (25.8 GiB),\r\n  both against `floor_bytes=34359738368`. `assemble` skipped in consequence, so no draft release\r\n  existed: the release was hard-blocked on disk, not on code. Neither leg produced a test verdict,\r\n  so both are LABELLED HOLES, not reds (ruled recorded-and-proceed by doyle, the shipped-sha delta\r\n  being 5 files and zero `.rs`).\r\n  **The finding is not the disk.** `xtask pool-sweep --root .worktrees` reported, correctly,\r\n  `total 66.43 GB across 3 pool(s); 0 B reclaimable in this sweep's scope` while the box sat ~6 GB\r\n  under its own floor. The sweep is behaving as designed — it refuses to reap owned, live lanes.\r\n  But the floor reasons over an AGGREGATE the sweep is forbidden to touch, so the designed\r\n  instrument, run at the exact moment of refusal, tells an operator there is nothing to reclaim.\r\n  That is true and useless. The gap between \"the sweep is correct\" and \"the box can run work\" is\r\n  the defect; it is not fixed by making the sweep more aggressive.\r\n  **Aggregate measured under `.worktrees`** (real target bytes, junction-classified first): 87.79 GB\r\n  across 9 lanes — 2.7x the entire 32 GiB floor. Registered pools: `w1t2-relink-force` 54.67 GB,\r\n  `obs-resume-attach-intent` 10.18, `w1t2-subnet-status` 1.58. Carrying targets the sweep does not\r\n  count as claimed pools: `hertz-teardown-bound` 11.25, `hertz-liveresolve-diag` 4.83,\r\n  `hertz-psyche-bound` 4.19, `hertz-poolowner` 1.03, `hertz-ci-riders` 0.91.\r\n  **The 54.67 GB single lane is NOT waste** (doyle's classification, ratified at this filing): a\r\n  verb lane at that size is workspace-all-targets e2e cost. No lane is misbehaving. That is what\r\n  makes this structural rather than a cleanup task — every lane is individually justified and the\r\n  sum still exceeds the floor.\r\n  **Reclaim taken, and its boundary.** 82.12 GB, from `spt-core/target` — the release driver's OWN\r\n  main-checkout pool, NOT a lane; free 23.23 → 105.34 GB. Classified before removal per the\r\n  teardown rule: OUTBOUND `Get-Item -Force` reported a real directory rather than a reparse point,\r\n  the INBOUND sweep found zero reparse points aimed at it, `CARGO_TARGET_DIR` was unset (no env\r\n  aliasing), the target SUBTREE only was reaped, both sides measured.\r\n  **Snapshot behavior reproduced inside this measurement window**, corroborating the axis addendum\r\n  above at a smaller amplitude: free read 25.49 GB when first measured and 23.23 GB at the reap\r\n  minutes later — it drifted 2.26 GB DOWNWARD while the operator was deciding what to do about it.\r\n  **Priced side effect, for the next reader:** reaping the main pool took the prebuilt `xtask` with\r\n  it, so the next lane claim rebuilds it first — the lane-check shortcut is cold until then. It cost\r\n  a 2m11s cold rebuild inside this release's own publish step.\r\n  **What this does NOT license:** reaping another agent's owned lane to clear a floor. The sweep's\r\n  refusal is correct and stays. What is missing is an AGGREGATE-AWARE signal — the box knowing its\r\n  lanes sum past the floor *before* a run is dispatched into a guard that will decline it.\r\n- **FOURTH ADDENDUM (doyle, 2026-08-04 late evening — fourth event in one day, and the first\r\n  RULING on this entry).** C: hit **0.44 GB free** during doyle's lane-2 stack gate and todlando's\r\n  re-aim leg set. Signatures manufactured this time, all initially read as something else:\r\n  `os error 112` mid-rlib-archive surfacing as xtask \"building spt failed\" (exit 101); a\r\n  servicehost force-kill unit red at a sha gated GREEN on the same rig an hour earlier; todlando's\r\n  6-of-7 leg table red with `LNK1318` while only traceable-reqs survived. Both agents' verdicts\r\n  from the window were VOIDED and re-run, not re-read.\r\n  **Discriminator correction (hertz, ratified at this filing):** \"treqs alone survives\" is a\r\n  POSITIVE TELL, never a clearing test — a full disk reds BEFORE any link step (rustc writing\r\n  rlibs), and treqs can red for its own reasons; signature absence says NOTHING. The only\r\n  falsifier for \"this red was the disk\" is free space AT RUN TIME, and no log on the box recorded\r\n  it, which made every red from the window unanswerable after the fact.\r\n  **RULING (doyle):** every rig/gate script records `FREE-AT-START` / `FREE-AT-END` in its own\r\n  SUMMARY — one line each, the datum that makes a disk confound answerable post-hoc. Effective\r\n  immediately for hand-authored rigs; hertz builds it into the shared rig harness at next touch\r\n  (assigned, not unasked). This is remedy (a) narrowed to its cheapest load-bearing slice.\r\n  **Reclaim, all FS-delta-measured:** todlando +59.4 GB (obs-resume-attach-intent 8.56 +\r\n  w1t2-relink-force 50.83; 0.44 → 59.83), hertz +1.79 GB (ci-riders + poolowner; sum-of-lengths\r\n  said 1.94, the FS delta governs; 59.09 → 60.87), doyle +38.8 GB (w1t2-subnet-status +\r\n  w1t2-perch-gc + w1t3-node-verb targets; 60.75 → 99.54). Full discipline each: outbound\r\n  classification, inbound reparse sweep (zero), CARGO_TARGET_DIR confirmed unset, subtree-only.\r\n  **Mechanism sharpened by this event:** the standing swing IS the finished-lane population —\r\n  ~110 GB of pools belonging to lanes already GATED AND PUSHED, held for hours because disposal\r\n  fires at GATE close (a rig step) while nothing fires at LANE finish; a pushed lane awaiting\r\n  assembly holds its pool invisibly. Corollary corrections carried: todlando withdrew his\r\n  name-based pool census (10x off; ancestry, not directory names, classifies a pool as closed),\r\n  and hertz-selection-probe's worktree removal REFUSED Permission denied — IR-38's second holder\r\n  class recurring, left for retry rather than forced.\r\n\r\n- **FIFTH ADDENDUM (deployah, v0.63.0 FIELD-SEAL golden, 2026-08-25) — SCOPED DELIBERATELY TO ONE\r\n  CONSEQUENCE: reaping a pool UNCLAIMS its tree, and the next builder meets a refusal that is the\r\n  rule working.** (The disk-floor mechanism from the same event is doyle's to file at his\r\n  release-close sweep — one voice each, by division agreed in-window. This addendum stops at the\r\n  pool-claim consequence and deliberately does not restate the floor finding.)\r\n  Five FIELD-SEAL lane pools were reaped to clear the golden floor — gate rig `gate-222-ca30a79e`\r\n  plus lanes `fix-222`, `w2-seal-ux`, `w3-ingest`, `w4-exit-subject`; **148.48 GB measured by FS\r\n  delta**, free 1.37 → 149.84 GB, worktree checkouts kept, `main/target` untouched by ruling.\r\n  **The consequence to record:** `POOL-OWNER.json` lives INSIDE `target/`, so reaping the subtree\r\n  takes the claim with it. Those five trees are now **UNCLAIMED — which is fresh-not-foreign**, a\r\n  different state from the `SPT_POOL_FOREIGN` refusal. Whoever resumes one of those lanes (a hertz\r\n  fixup, a golden-red rebuild) must run `cargo run -p xtask -- pool-claim --pool <dir> --label\r\n  <lane>` **from that worktree** before the first build, or `crates/spt-store/build.rs` refuses.\r\n  **A refusal there is the rule working, not a defect** — filed precisely so a later reader does\r\n  not open an issue against the build script for behaving correctly. Naming it costs one line;\r\n  the alternative is an RCA against our own guard.\r\n  **Prediction-vs-meter, corroborating hertz's fourth-addendum note at ~75x its scale:** pre-reap\r\n  sum-of-lengths sizing predicted 163.9 GB; the FS delta paid 148.48 GB, a 15.4 GB shortfall left\r\n  UNEXPLAINED here rather than rationalized (allocation granularity, sparse/compressed extents and\r\n  concurrent writes all sit between the two meters). **The FS delta governs** — hertz ruled this at\r\n  1.94-vs-actual and it holds at three digits. Report the meter, never the estimate that agreed\r\n  with your plan.\r\n  **Discipline executed, for the audit trail:** outbound classification re-read AT REAP TIME (all\r\n  five real dirs, zero LinkType); inbound sweep over **2854** reparse points under `projects\\`\r\n  found zero aimed at any victim; `CARGO_TARGET_DIR` confirmed empty in process, **Machine and\r\n  User** scope (the arm that leaves no directory entry to notice afterwards); process census\r\n  RE-RUN at reap time rather than carried from a peer's snapshot — zero builders, zero processes\r\n  imaged out of a victim pool, both live `spt` images resolving to the installed path. The peer's\r\n  snapshot proved correct; it was re-run because a snapshot is not a standing property, which is\r\n  the reason it was offered with that caveat.\r\n\r\n### IR-32 — Docs-drift gate blesses its own gen: an empty-emitting producer agrees with itself perfectly\r\n- **Status:** open · **Origin:** todlando mid-lane stop-and-report, U1 (#144) 2026-08-04. Filed by\r\n  the builder to the gater deliberately — register shape is doyle's to own.\r\n- **What/why:** with a defective binary in the tree (stack-overflowed before reaching its own\r\n  code, empty stdout, non-fatal to the generator), `cargo run -p xtask -- gen` wrote\r\n  `docs-site/src/cli/reference.md` reduced to EIGHT lines — title, do-not-edit banner, empty code\r\n  fence — deleting 3193 lines of published CLI reference. `xtask check` then exited 0, because\r\n  the drift gate compares what the binary emits NOW against what the file holds, and gen had just\r\n  overwritten the file with exactly that emit. **A producer that emits nothing agrees with itself\r\n  perfectly.** Caught only because the builder grepped the regenerated page for his new flag\r\n  names and treated the clean zero as suspicious ([[zero-match-filter-reads-as-absent]] shape);\r\n  the gate itself would never have said a word, and the gutted public reference ships green.\r\n  The mechanism generalizes past the stack overflow that exposed it: ANY failure mode that makes\r\n  `spt --help` produce empty stdout while exiting non-fatally to the generator gets the same\r\n  green. Kin to [[cli-command-docs-drift]] (the gate this defeats) — the gate detects DRIFT\r\n  between binary and page, and is structurally blind to a page just regenerated from a broken\r\n  binary.\r\n- **Remedy shape (builder's sketch, sound; not yet ruled on seat):** a floor in `xtask gen` —\r\n  refuse to write a page whose help block is empty, or whose output is implausibly shorter than\r\n  the file it replaces — so the generator fails loudly instead of producing a stub the gate\r\n  blesses. Gen is the right seat: check runs in CI on a fresh emit too, so a check-side floor\r\n  alone still lets a local gen gut the working tree.\r\n- **Ripe when:** next docs-tooling or xtask-touching lane; SOONER if any lane regenerates the CLI\r\n  reference before the floor exists (a gate on that lane must assert page LENGTH, not gen's exit\r\n  code, until this is built).\r\n- **Size:** small (one refusal + a length-plausibility floor in gen).\r\n\r\n- **Kin instance 2026-09-11 (hertz, #304 lane, caught before launch):** the RUN expression for the\r\n  spt-daemon lib producer was still the 15-term webserve list after six #297 cases had been admitted\r\n  and inventoried at 21 terms. It would have executed 15 and reported against a 21-term inventory —\r\n  a subset quietly narrower than the thing it claims to discharge, with a count that reads fine.\r\n  Rule: a run filter is diffed TERM-FOR-TERM against the inventory it discharges before launch; a\r\n  matching case count is not that check.\r\n\r\n### IR-33 — Debug-build clap Command tree runs near the main-thread stack ceiling; the margin is THREE net new args, bisected at `8f291e1` (the original ~6 was measured on U1's tree and is superseded)\r\n- **Status:** OPEN for acceptance/margin reconciliation. Current source at `e5a2fed9` runs\r\n  the CLI on an owned 16 MiB thread stack and includes `cli_stack_smoke`; the three-argument\r\n  ceiling below is a historical measurement at `8f291e1`, NOT today's measured margin.\r\n  Do not redispatch an already-present sized-stack implementation. No fresh debug-run\r\n  acceptance is claimed by this source read (2026-09-11). · **Origin:** todlando U1 (#144)\r\n  2026-08-04, delta-tested mid-lane.\r\n- **What/why:** eight extra hidden bool args across the five knock seats grew the derive-built\r\n  Command tree past what the debug binary's main thread stack can construct: EVERY invocation\r\n  (`spt --version` included) died with `thread 'main' has overflowed its stack`, exit\r\n  -1073741571, before reaching any of its own code. Delta-tested, not assumed: the same command\r\n  on the main-pool binary from main printed normally. U1 repaired its own trigger (raw-argv\r\n  pre-scan for retired flags before clap parses; lane ends net +2 args) — but the CEILING\r\n  remains: the tree is now close enough that a handful of net new arguments in a debug build\r\n  reproduce a total binary outage — **and the handful is THREE, not six; see the correction\r\n  below before planning against this entry.** **#5's verb-surface rework is the next lane that adds\r\n  arguments and it is much bigger than U1** — this entry exists so #5 is planned knowing the\r\n  margin, not discovering it. Note the failure's face: it presents as a broken binary, and via\r\n  [[IR-32]] it presents as a silently gutted docs page — neither names the stack.\r\n- **CORRECTION — the margin is THREE, bisected at `8f291e1` (todlando's U3 lane\r\n  `build/usher-u3-verb-surface`, own pool, debug profile; filed by deployah 2026-08-04).** The\r\n  original ~6 was measured on U1's tree and was right when written; it is wrong now, and the\r\n  difference is the difference between \"plan carefully\" and \"one flag anywhere takes the binary\r\n  down\". N hidden bool args added to the ROOT `Cli` derive, tree restored from git between every\r\n  row, `--version` as the invocation (it carries no work of its own, so whatever it costs IS tree\r\n  construction):\r\n\r\n      N=0  exit 0                OK  (control — unmodified lane binary answers `spt 0.53.0`)\r\n      N=1  exit 0                OK\r\n      N=2  exit 0                OK\r\n      N=3  exit -1073741571      STACK-OVERFLOW\r\n      N=4 / N=6 / N=8            STACK-OVERFLOW\r\n\r\n  PLACEMENT DIFFERENTIAL, run because #5 adds args at `EndpointCmd` seats rather than at the root\r\n  and a root-only number could have measured the wrong thing: same N injected inside a NESTED\r\n  endpoint seat gives `SEAT N=2` OK, `SEAT N=3` STACK-OVERFLOW. **Identical ceiling — placement does\r\n  not move it**, so three is the number for the shape #5 actually builds. (Rig hazard worth keeping:\r\n  the first seat attempt produced a COMPILE error, E0027, because the dispatch destructures that\r\n  variant exhaustively — taken at face value it would have read as \"the seat is fine\". Both rows\r\n  above are from the fixed rig.) CONSEQUENCE FOR #5: the ratified MIN spelling ends net +2, i.e. it\r\n  would have shipped with ONE argument of headroom, and any later lane adding a single flag anywhere\r\n  in the tree would then take the whole binary down, `--version` included. Remedy (b) below stops\r\n  being \"buys headroom\" and becomes the precondition for #5 shipping safely.\r\n- **Remedy shape (sketch, not ruled):** (a) cheapest tooth — a debug-build smoke that runs\r\n  `spt --help` and asserts non-empty stdout + exit 0, which also backstops IR-32's trigger;\r\n  (b) raise the main thread stack for the binary (build config), buying headroom without\r\n  restructuring; (c) structural — box/flatten the derive tree so construction cost stops scaling\r\n  with arg count. (a) is a rider candidate for any lane; (b)/(c) want a real measurement of\r\n  where the ceiling sits before choosing.\r\n- **Ripe when:** #5 (U3 verb surface) PLANNING — this is a planning input, not just a build item;\r\n  the smoke tooth (a) is ripe for the next CI-touching lane regardless.\r\n- **Size:** small for (a); medium for (b)/(c) with the measurement.\r\n\r","startLine":2030,"lineNumbers":[2030,2031,2032,2033,2034,2035,2036,2037,2038,2039,2040,2041,2042,2043,2044,2045,2046,2047,2048,2049,2050,2051,2052,2053,2054,2055,2056,2057,2058,2059,2060,2061,2062,2063,2064,2065,2066,2067,2068,2069,2070,2071,2072,2073,2074,2075,2076,2077,2078,2079,2080,2081,2082,2083,2084,2085,2086,2087,2088,2089,2090,2091,2092,2093,2094,2095,2096,2097,2098,2099,2100,2101,2102,2103,2104,2105,2106,2107,2108,2109,2110,2111,2112,2113,2114,2115,2116,2117,2118,2119,2120,2121,2122,2123,2124,2125,2126,2127,2128,2129,2130,2131,2132,2133,2134,2135,2136,2137,2138,2139,2140,2141,2142,2143,2144,2145,2146,2147,2148,2149,2150,2151,2152,2153,2154,2155,2156,2157,2158,2159,2160,2161,2162,2163,2164,2165,2166,2167,2168,2169,2170,2171,2172,2173,2174,2175,2176,2177,2178,2179,2180,2181,2182,2183,2184,2185,2186,2187,2188,2189,2190,2191,2192,2193,2194,2195,2196,2197,2198,2199,2200,2201,2202,2203,2204,2205,2206,2207,2208,2209,2210,2211,2212,2213,2214,2215,2216,2217,2218,2219,2220,2221,2222,2223,2224,2225,2226,2227,2228,2229,2230,2231,2232,2233,2234,2235,2236,2237,2238,2239,2240,2241,2242,2243,2244,2245,2246,2247,2248,2249,2250,2251,2252,2253,2254,2255,2256,2257,2258,2259,2260,2261,2262,2263,2264]},"fileSize":676479,"meta":{"source":{"type":"path","value":"C:\\Users\\decid\\Documents\\projects\\spt-core\\.worktrees\\hertz-ir86-disk-delta\\docs\\INFRA-REGISTER.md"},"truncation":{"direction":"head","truncatedBy":"lines","totalLines":6938,"totalBytes":20763,"outputLines":235,"outputBytes":20763,"shownRange":{"start":2030,"end":2264},"nextOffset":2265}}},"isError":false,"timestamp":1789483673583}}
{"type":"message","id":"e9b477ed","parentId":"d9673dbf","timestamp":"2026-09-15T14:47:53.588Z","message":{"role":"toolResult","toolCallId":"call_ODgsGyoCktGuEGTJk1Vexe3k|fc_043a862a419f59ae016aa95a997a6087d2bf6782262dbc4273","toolName":"read","content":[{"type":"text","text":"### IR-34 — nextest LEAK flag on the zombie-fixture row is dominant-but-intermittent (19/20 measured); any gate reading it as a signal flaps\n- **Status:** open · **Origin:** doyle #142 F-lane gate 2026-08-04 (first sighting in a gate run);\n  characterized same day by hertz from retained logs, ownership falsified by todlando.\n- **What/why:** `broker::tests::windows_session_is_zombie_sees_a_handle_held_corpse_as_dead` (the\n  ADR-0041 zombie-detection fixture, whose subject is a corpse process kept alive-looking by a HELD\n  HANDLE) flags nextest LEAK on most draws but not all — measured 19 LEAK of 20 on a tree carrying\n  no #142 content (`test/grandchild-selection-probe` @`695398b`, based on `4b37512`: lib arm 10/10\n  LEAK across 822-test runs; full-suite arm 9/10 across 1044-test runs). The single clean PASS\n  kills \"intrinsic therefore always\": leakiness is DOMINANT BUT INTERMITTENT. Consequences:\n  (1) a gate or reader that treats this row's LEAK as a defect signal flaps at roughly 1 in 20;\n  (2) one non-leaky run is NEVER evidence that something fixed it (kin:\n  [[intermittent-green-is-zero-information]]); (3) the verdict method that closed it is the\n  template — two independent legs, neither load-bearing alone: the suspect lane's diff grepped\n  zero hits on the row's subject (zombie / handle_held / OpenProcess / corpse), AND a 20-draw\n  baseline on a tree predating the suspect change. This entry exists so the next gater who sees\n  the flag reads one register line instead of running that RCA cold.\n- **Remedy shape (sketch, not ruled):** annotate the row as expected-leak in nextest config\n  (per-test `leak-timeout` override or documented allowlist) so the flag stops presenting as\n  signal; alternatively a fixture-side close of the held handle on the clean path if ADR-0041's\n  arrangement permits — hertz's call, test/CI lane.\n- **LANE-LINKED 2026-08-30 (#242 close sweep):** hertz's queued daemon-leak fixup lane carries\n  this entry (brief cites IR-7/17/20/34/35/63); leaves the register when that lane lands.\n- **Ripe when:** hertz's next nextest-config-touching lane; blocks nothing today.\n- **Size:** small.\n\n### IR-35 — hfenduleam Windows test-leg victim rate: one teardown/liveness family, measured at ~half of all executions\n- **Status:** open · **Origin:** USHER #150 golden triage 2026-08-04 (doyle; all rates deployah-measured).\n- **The numbers (15 golden runs 2026-08-02..08-04 + the USHER cycle, deduped on `(run, box,\n  started_at)` — GitHub partial reruns COPY untouched jobs into the new attempt with their ORIGINAL\n  `started_at` and carried conclusion, so a carried failure is the SAME observation; dedupe before\n  any rate math):** Windows (hfenduleam) 13 red / 22 executions = 59% leg-red, splitting 10/22 = 45%\n  test-victim + 3/22 infra (IR-31 class). Linux (kitsubito) 2/20 = 10%, 1 victim. Every victim-red\n  leg had EXACTLY ONE victim (8/8 legs). Clean-cycle arithmetic ≈ 0.55 × 0.95 ≈ half — a golden\n  cycle at these rates is a coin flip. knock145 (the previous green golden) took FIVE Windows\n  executions to its green; USHER took four. **A both-green draw is a draw, not evidence the family\n  closed.**\n- **The family:** 11 victim legs, 8 distinct tests, ONE cluster — process teardown / kill-reach /\n  respawn-controller survival, concentrated on hfenduleam. Per-victim dispositions live in the USHER\n  #150 triage ledger (releases#150 record). The only surviving cross-sha EXACT repeat after source\n  verification is `resume_no_control_steal_e2e` (:488, byte-identical @2138b16 + @4b37512) — and\n  both its reds PREDATE the post-#145 producer-side instrumentation, so what repeats is an AMBIGUOUS\n  observation (stolen controller vs starved child) twice; only a post-#145 red discriminates. The\n  `a_tree_teardown` pair was a FALSE repeat — two mechanisms wearing one assert string (see\n  FLAKE-LEDGER row; the counting lesson: assert-body identity must include the polled predicate's\n  SUBJECT).\n- **Off-CI discriminator (todlando 2026-08-04):** 0/400 (A 0/200 + B 0/200, interleaved,\n  `--test-threads 1`, filters positive-controlled, by-path sweeps every iteration) on the warm\n  d449ce5 pool UNDER live-fleet load (CPU 46-59%, 13-18 spt processes). Points the family at the\n  RUNNER ENVIRONMENT rather than a product race any Windows box expresses — not exoneration (absence\n  of reproduction is not proof of absence), but where the next hour goes. A-alone N=500 on the\n  instrumented tree ran post-close (result on releases#150).\n- **Remedy lanes already moving:** hertz 4-item test-rework package dispatched 2026-08-04 (psyche\n  bound split, live_resolve rig instrumentation, green-capture probe profile, resident_service/\n  teardown hardening); prod `wait_bounded` tree-kill-on-timeout filed to board as EVAL. This entry\n  is the RATE's home — it leaves the register when the operator has ruled on the rate (accept vs\n  hold-for-hertz) AND the hertz package has landed with a re-measured victim rate.\n- **LANE-LINKED 2026-08-30 (#242 close sweep):** hertz's queued daemon-leak fixup lane carries\n  this entry (brief cites IR-7/17/20/34/35/63); the rate re-measure rides that lane's landing.\n- **Ripe when:** operator brief at USHER close (immediate); re-measure after the hertz package lands.\n- **Size:** visibility entry + the re-measure; fix cost carried by the hertz package.\n\n### IR-36 — `output_bounded` is a 51-copy clone estate with a named-but-empty shared home; hoist-and-delete wants its own lane\n- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane. · **Origin:** hertz measurement\n  2026-08-04 (at `7465ac1`, counted before listing, listed untruncated), during the USHER package\n  item-2 sweep ruling; doyle ruled file-don't-sweep.\n- **What/why:** 51 `fn output_bounded` definitions under `crates/spt/tests` — 50 per-file copies\n  plus `tests/common/mod.rs:53`, which is NOT pub, has ZERO callers outside its own module, and\n  whose doc comment states outright that the estate's copies predate the shared module. The lossy\n  timeout arm (panic loses everything captured, names nothing) is in 38 sites across 36 files.\n  The copies have already drifted: two variants of the deadline expect-string exist in the estate\n  (`\"captured spt call must complete within its deadline\"` in common/mod.rs:60 vs the\n  no-deadline-clause spelling in per-file copies), so a grep keyed to either string undercounts.\n  The right fix is a hoist-and-delete refactor (make the common copy pub, adopt it estate-wide,\n  carry the item-2 diagnostic arm once) — a 50-file test-estate touch that must NOT ride golden\n  cadence as a rider or hide inside a scoped diagnostics item (ADR-0050 thin-lane rationale;\n  hertz's USHER item 2 stays scoped to live_resolve, which keeps ONE improved copy as the model).\n- **Built evidence:** one public owning helper replaced all 50 file-local\n  clones. It owns and tree-kills a timed-out child, waits for reap, drains both\n  pipes, and includes the deadline plus partial stdout/stderr in the panic.\n  A dedicated regression observes both diagnostics and proves the timed-out PID\n  is gone.\n- **Ripe when:** a dedicated post-batch test-hygiene lane (natural companion to IR-13's\n  mutation-proof loop and IR-23's home-collision fix — same hertz wave shape).\n- **Size:** medium by file count, small by risk (mechanical hoist; no assertion changes).\n- **Hygiene-lane scope addition (todlando, at #6, 2026-08-04):** a CI prebuild of\n  `cargo build -p mock-adapter --bin mock-shell` (derived from tracked `.github/` content) turns\n  SIX binedge baseline rows green at once instead of growing the burn-down list one consumer at a\n  time — belongs to this lane, not to any thin verb lane. [[IR-38]] (live-binary e2e reap sweep)\n  rides the same lane.\n- **Built evidence:** all 51 file-local definitions are gone; 158 call sites use the one public\n  `common::output_bounded`. The shared helper owns the child, kills and reaps its process tree on\n  timeout, drains both pipes, and reports partial stdout/stderr. `bounded_output_e2e` mutation-pins\n  both timeout ownership and retained diagnostics.\n- **Declared validation extra:** the lane's docs-link gate exposed that `llms_target_exists` treated\n  generated targets as absent before generation. Its small refactor + unit keeps source and\n  generated link targets distinct; it is deliberate validation fallout, not part of IR-36.\n\n### IR-37 — `traceable-reqs check` is coverage-only: tag PLACEMENT is unenforced on any multi-tagged REQ, and the more tags a REQ accumulates the less any one is checked\n- **Status:** UPSTREAM CLOSED THROUGH RELEASE 2026-08-19 — traceable-reqs PR #19 squash-merged\n  @`82d8b14` after doyle's targeted re-review PASS (defect A item-tables + 9 red-first regression\n  cells + sighted control; defect B enclosing-item fallback DECLARED in SPEC with cost; 267/267,\n  blind repros exit 0); v0.4.0 cut (version bump @`c9a8eb5`, tag pushed, 3 platform assets,\n  release notes authored; refs sent to hertz). REMAINING and dispatched to hertz post-#182-landing:\n  spt-core consumes v0.4.0 — CI version bump + placement config (enforce-on, module_banner=accept);\n  banner cleanup rides a later lane. Entry closes when the consume lane lands. · **Origin:** hertz\n  measurement 2026-08-04 (filed by doyle; the measurement is\n  hertz's), found when his own pre/post `check` comparison around a tag-adjacency fix came back\n  EXIT=0 on BOTH sides — the green he had cited beside the fix validated nothing.\n- **What/why:** measured on `test/teardown-bound-shape`: a `unit->REQ-RESIDENT-SERVICE` tag\n  SEPARATED from its `#[test]` fn (a const landed between tag block and fn — an AGENTS.md rule-1\n  violation) scores EXIT=0 identically to the fixed adjacency. Positive control explains the\n  mechanism: that REQ carries 57 unit tags across five files, so 56 other sites decide the\n  coverage verdict and no single tag's placement can turn it red. Consequence: AGENTS.md rule 1\n  (\"tag on or immediately above the real evidence\") is agent discipline only — drifted tags decay\n  silently while coverage stays green, and heavily-tagged REQs decay fastest. This is the\n  [[IR-32]] family shape (a gate that cannot see its own blind spot) applied to the traceability\n  gate itself.\n- **LIMIT, with falsifier (hertz's, verbatim in kind):** behaviour on a SINGLE-tagged REQ was NOT\n  established. Separating the only tag of a single-tagged REQ at the stage under test would settle\n  whether placement is unenforced outright (still exit 0 ⇒ the checker never reads adjacency) or\n  merely un-enforceable at scale (exit 1 ⇒ the checker sees absence, and only multi-tag redundancy\n  masks drift). Run that discriminator BEFORE designing any remedy — the two outcomes want\n  different fixes (a placement rule in the checker vs a per-tag-nearest-item heuristic).\n- **Transfer:** doyle accepted this lane's independent EXIT-0 remeasurement and confirmed it\n  matches todlando's settled 2026-08-04 discriminator. Upstream remedy: enforce adjacency for\n  each individual `doc`/`impl`/`unit`/`int` tag, with separated-tag negatives covering\n  single-tag, interposed-const, file-top-banner, and one-of-many displacement. This repo consumes\n  the released checker only.\n- **Close condition:** doyle reviews and merges the upstream lane, cuts the `traceable-reqs`\n  release, and spt-core consumes that release. Issue/branch/PR/commit refs append here when the\n  upstream lane lands.\n- **Size:** measurement complete; remedy scope is upstream-owned and dispatched.\n- **CONSUME LANE + REGRESSION (doyle, 2026-09-11):** hertz's #304 lane carries the consume (2072b467 ci.yml\n  WANT 0.4.0, c3b5feec golden.yml pin, 33936943 `[placement] enforce=on, module_banner=accept`).\n  Measured on his tip under 0.4.0: misplaced 9 (tags quoted in backticks in prose; fixed on main\n  dd0679dc) and 81 doc stages MISSING that 0.2.0 counted — a checker regression, not drift: 0.4.0's\n  git enumeration skipped a FILE root (`CONTEXT.md`), see [[IR-104]]. Fixed upstream as v0.4.1\n  (PR #21 -> d9af11d); the lane pins move to 0.4.1 in one fixup after hertz's window. Entry\n  closes when that fixup lands on main.\n- **DISCRIMINATOR RUN 2026-08-04 (todlando, authorized specimen on `build/w1t2-shell-relink-force`;\n  filed by doyle — the measurement is todlando's): the answer is the EXIT-0 ARM.** Single-tagged\n  int stage (`REQ-SHELL-RELINK-FORCE`), tag SEPARATED from its fn (parked at file top):\n  `traceable-reqs check` EXIT 0 and the REQ still reports `+int`. Tag reverted to adjacency:\n  EXIT 0, `+int`. Both exits redirect-read, no pipes. **Placement is UNENFORCED OUTRIGHT — the\n  checker never reads adjacency; multi-tag redundancy was never the mechanism, it only widened the\n  blind spot.** Remedy option (a) is the live one: a real placement rule in the checker (upstream\n  experimplate), not a per-tag-nearest-item heuristic. Measurement caveat, carried at the\n  measurer's own insistence: an intermediate probe printed `TAG_ADJACENT_AFTER_REVERT=0` and that\n  was the PROBE wrong (`grep -B 1` above the fn lands on `#[test]`, not the tag above it), not a\n  failed revert — the revert was verified directly (exactly one tag, above `#[test]`). The\n  discriminator result is the record; the intermediate zero is not.\n- **REMEDY DISPATCHED 2026-08-18 (doyle):** upstream lane opened in BigscreenVR/traceable-reqs\n  (the actual upstream remote; the checkout at `~/Documents/projects/traceable-reqs` tracks it —\n  \"experimplate\" above named the tool's origin project, not the repo) — checker-side placement\n  rule, default-on in `check`, positive controls all four stages + separated-tag negatives\n  including the single-tag displaced discriminator shape and the interposed-const shape.\n  Requested by hertz as the IR-37 prerequisite of his test-hygiene family lane (KEYSTONE #182).\n  spt-core consumes the upstream RELEASE only — no local shadow checker. Issue/branch/PR refs\n  land here when the lane reports.\n\n### IR-38 — CLASS: an e2e that ends with a live daemon-spawning binary wedges the NEXT build in its pool, and the diagnostic names the wrong lane\n- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane. · **Origin:** todlando 2026-08-04,\n  `shell_relink_force_e2e` on the #6 lane (filed by doyle; the finding and the fix are todlando's).\n- **What/why:** the e2e ends with a LIVE binary by design; on Windows a live process holds its\n  image open, so the NEXT cargo invocation in that target dir dies with\n  `failed to remove file target\\debug\\spt.exe: Access is denied (os error 5)` — surfacing as\n  exit 101 with NO test summary, because the failure names the BUILD and the FILE, never the test\n  that leaked the holder. Actual holders measured: two lane-local `spt daemon run --detached` +\n  `daemon brain` processes spawned under the test's temp SPT_HOME by a child CLI's\n  `ensure_running`, still alive from an earlier run. **Reap BY IMAGE PATH** — the fleet's other\n  eleven spt processes run from the installed binary; a name-based sweep takes your own daemon.\n  The live shell-spawn population is eleven e2e files. Nine already end through product teardown\n  or their authenticated home-scoped reap. The two intentionally live-at-success siblings now\n  kill and prove the final resident gone AFTER all identity/wake assertions:\n  `shell_relink_force_e2e` and `shell_stale_online_e2e`.\n- **Kin:** [[IR-7]] (phase-A daemon+brain pair leak), the exe-lock reap-by-path rule, and the\n  wrong-lane-diagnostic family ([[IR-21]]'s location-not-build class).\n- **SECOND HOLDER CLASS, measured 2026-08-04 (doyle, own gate rig):** an **ORPHANED CONHOST with an\n  inherited CWD** inside the test tree blocks `git worktree remove` with Permission-denied on a\n  DIRECTORY handle — invisible to any exe-path scan (conhost runs from System32; the parent that\n  spawned it was already dead). Found via `.github/ci/find-cwd-holders.ps1` (IR-11's instrument);\n  killed by pid after parent-dead classification; 34.78 GB reclaimed. Mechanism chain: the\n  windowless spawn path masks DETACHED_PROCESS off, the child owns a console, conhost inherits the\n  child's cwd and can OUTLIVE it. Boundary (hertz's, correct): this find and his field-4 companion\n  are the SAME MECHANISM FAMILY measured on DIFFERENT populations by different instruments — his\n  capture measured a ppid-match COUNT (floor 2, companion identity UNMEASURED, his stated limit),\n  and this conhost is the first FIELD identity evidence in the family, on THIS population. Do not\n  cite his row as identity data it never carried. (His box-wide accretion count 77→80 is a third\n  population again.) Teardown rule\n  addendum: a disposal leg must GATE on the removal's exit code (a rig that logs \"reclaimed 0.01\n  GB\" from a failed remove fabricates its own success) and sweep CWD HOLDERS, not only image\n  locks — two populations, either alone is a clean zero on the other.\n- **Ripe when:** the test-hygiene lane (IR-13/IR-23/IR-36 family) — sweep every e2e that ends\n  with a live spawning binary, apply the same reap-after-assertions shape.\n- **Size:** small per test; population unknown until swept.\n- **Built evidence:** focused runs of both live-at-success tests pass back-to-back in one target\n  pool, followed by a build invocation from that same pool; the second test's final kill is polled\n  to proven process death rather than treated as fire-and-forget.\n\n### IR-39 — CLASS: the missing-fixture-bin defect has TWO failure faces, and one of them impersonates a lifecycle defect of the subject under test\n- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane. · **Origin:** hertz + todlando\n  2026-08-04, same evening from opposite sides (filed by doyle; hertz relayed todlando's\n  suggestion without endorsing scope).\n- **What/why:** a rig whose narrowed build (`-p <pkg> --test <one>` / `-p spt --bin spt`) skips a\n  cross-package fixture bin fails in one of two ways depending on the consuming site.\n  Face 1 (cheap): `translate_proof_fixture` panics \"must be built: <path>\" — names the artifact\n  and the recipe, costs one build. Face 2 (expensive): `sibling_bin(\"mock-session\")` resolves to a\n  nonexistent exe, nothing spawns, and the test reds at a PRECONDITION assert whose message\n  (\"warm bring-up spawned=false\", left None / right Some(\"offline\")) reads as a lifecycle defect\n  of the subject — measured cost 186s + a triage inside a lent box window (hertz's F1 red arm,\n  attempt 1). The build gap itself is the known cross-package row of the fixture-bin population;\n  what this entry carries is the DIAGNOSTIC asymmetry.\n- **Ask:** a fixture-bin existence precondition that NAMES the missing exe and its build recipe\n  wherever a rig consumes one — `sibling_bin` (and the shared\n  `crates/spt-term/tests/support/fixture_bin.rs` resolver already carries the recipe string as an\n  argument, the shape to copy) refuses with the artifact + recipe instead of letting the consuming\n  test fail downstream in its own vocabulary.\n- **Kin:** [[IR-21]] (wrong-lane-diagnostic family: the failure names the wrong actor), the\n  cargo-builds-package-bins-for-integration-tests rule (cross-package row is the only unguaranteed\n  build), golden.yml's dedicated fixture prebuild step.\n- **Ripe when:** the test-hygiene lane (IR-13/IR-23/IR-36/IR-38 family) — same sweep population;\n  or standalone small if that lane keeps slipping.\n- **Size:** small — one shared helper + a sweep of local `sibling_bin` resolver copies (24 known).\n- **Addendum (doyle, 2026-08-04 late): third and fourth sightings inside 24 h.** Face 1 twice\n\n[Showing lines 2265-2488 of 6938. Use :2489 to continue]"}],"details":{"truncation":{"content":"### IR-34 — nextest LEAK flag on the zombie-fixture row is dominant-but-intermittent (19/20 measured); any gate reading it as a signal flaps\r\n- **Status:** open · **Origin:** doyle #142 F-lane gate 2026-08-04 (first sighting in a gate run);\r\n  characterized same day by hertz from retained logs, ownership falsified by todlando.\r\n- **What/why:** `broker::tests::windows_session_is_zombie_sees_a_handle_held_corpse_as_dead` (the\r\n  ADR-0041 zombie-detection fixture, whose subject is a corpse process kept alive-looking by a HELD\r\n  HANDLE) flags nextest LEAK on most draws but not all — measured 19 LEAK of 20 on a tree carrying\r\n  no #142 content (`test/grandchild-selection-probe` @`695398b`, based on `4b37512`: lib arm 10/10\r\n  LEAK across 822-test runs; full-suite arm 9/10 across 1044-test runs). The single clean PASS\r\n  kills \"intrinsic therefore always\": leakiness is DOMINANT BUT INTERMITTENT. Consequences:\r\n  (1) a gate or reader that treats this row's LEAK as a defect signal flaps at roughly 1 in 20;\r\n  (2) one non-leaky run is NEVER evidence that something fixed it (kin:\r\n  [[intermittent-green-is-zero-information]]); (3) the verdict method that closed it is the\r\n  template — two independent legs, neither load-bearing alone: the suspect lane's diff grepped\r\n  zero hits on the row's subject (zombie / handle_held / OpenProcess / corpse), AND a 20-draw\r\n  baseline on a tree predating the suspect change. This entry exists so the next gater who sees\r\n  the flag reads one register line instead of running that RCA cold.\r\n- **Remedy shape (sketch, not ruled):** annotate the row as expected-leak in nextest config\r\n  (per-test `leak-timeout` override or documented allowlist) so the flag stops presenting as\r\n  signal; alternatively a fixture-side close of the held handle on the clean path if ADR-0041's\r\n  arrangement permits — hertz's call, test/CI lane.\r\n- **LANE-LINKED 2026-08-30 (#242 close sweep):** hertz's queued daemon-leak fixup lane carries\r\n  this entry (brief cites IR-7/17/20/34/35/63); leaves the register when that lane lands.\r\n- **Ripe when:** hertz's next nextest-config-touching lane; blocks nothing today.\r\n- **Size:** small.\r\n\r\n### IR-35 — hfenduleam Windows test-leg victim rate: one teardown/liveness family, measured at ~half of all executions\r\n- **Status:** open · **Origin:** USHER #150 golden triage 2026-08-04 (doyle; all rates deployah-measured).\r\n- **The numbers (15 golden runs 2026-08-02..08-04 + the USHER cycle, deduped on `(run, box,\r\n  started_at)` — GitHub partial reruns COPY untouched jobs into the new attempt with their ORIGINAL\r\n  `started_at` and carried conclusion, so a carried failure is the SAME observation; dedupe before\r\n  any rate math):** Windows (hfenduleam) 13 red / 22 executions = 59% leg-red, splitting 10/22 = 45%\r\n  test-victim + 3/22 infra (IR-31 class). Linux (kitsubito) 2/20 = 10%, 1 victim. Every victim-red\r\n  leg had EXACTLY ONE victim (8/8 legs). Clean-cycle arithmetic ≈ 0.55 × 0.95 ≈ half — a golden\r\n  cycle at these rates is a coin flip. knock145 (the previous green golden) took FIVE Windows\r\n  executions to its green; USHER took four. **A both-green draw is a draw, not evidence the family\r\n  closed.**\r\n- **The family:** 11 victim legs, 8 distinct tests, ONE cluster — process teardown / kill-reach /\r\n  respawn-controller survival, concentrated on hfenduleam. Per-victim dispositions live in the USHER\r\n  #150 triage ledger (releases#150 record). The only surviving cross-sha EXACT repeat after source\r\n  verification is `resume_no_control_steal_e2e` (:488, byte-identical @2138b16 + @4b37512) — and\r\n  both its reds PREDATE the post-#145 producer-side instrumentation, so what repeats is an AMBIGUOUS\r\n  observation (stolen controller vs starved child) twice; only a post-#145 red discriminates. The\r\n  `a_tree_teardown` pair was a FALSE repeat — two mechanisms wearing one assert string (see\r\n  FLAKE-LEDGER row; the counting lesson: assert-body identity must include the polled predicate's\r\n  SUBJECT).\r\n- **Off-CI discriminator (todlando 2026-08-04):** 0/400 (A 0/200 + B 0/200, interleaved,\r\n  `--test-threads 1`, filters positive-controlled, by-path sweeps every iteration) on the warm\r\n  d449ce5 pool UNDER live-fleet load (CPU 46-59%, 13-18 spt processes). Points the family at the\r\n  RUNNER ENVIRONMENT rather than a product race any Windows box expresses — not exoneration (absence\r\n  of reproduction is not proof of absence), but where the next hour goes. A-alone N=500 on the\r\n  instrumented tree ran post-close (result on releases#150).\r\n- **Remedy lanes already moving:** hertz 4-item test-rework package dispatched 2026-08-04 (psyche\r\n  bound split, live_resolve rig instrumentation, green-capture probe profile, resident_service/\r\n  teardown hardening); prod `wait_bounded` tree-kill-on-timeout filed to board as EVAL. This entry\r\n  is the RATE's home — it leaves the register when the operator has ruled on the rate (accept vs\r\n  hold-for-hertz) AND the hertz package has landed with a re-measured victim rate.\r\n- **LANE-LINKED 2026-08-30 (#242 close sweep):** hertz's queued daemon-leak fixup lane carries\r\n  this entry (brief cites IR-7/17/20/34/35/63); the rate re-measure rides that lane's landing.\r\n- **Ripe when:** operator brief at USHER close (immediate); re-measure after the hertz package lands.\r\n- **Size:** visibility entry + the re-measure; fix cost carried by the hertz package.\r\n\r\n### IR-36 — `output_bounded` is a 51-copy clone estate with a named-but-empty shared home; hoist-and-delete wants its own lane\r\n- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane. · **Origin:** hertz measurement\r\n  2026-08-04 (at `7465ac1`, counted before listing, listed untruncated), during the USHER package\r\n  item-2 sweep ruling; doyle ruled file-don't-sweep.\r\n- **What/why:** 51 `fn output_bounded` definitions under `crates/spt/tests` — 50 per-file copies\r\n  plus `tests/common/mod.rs:53`, which is NOT pub, has ZERO callers outside its own module, and\r\n  whose doc comment states outright that the estate's copies predate the shared module. The lossy\r\n  timeout arm (panic loses everything captured, names nothing) is in 38 sites across 36 files.\r\n  The copies have already drifted: two variants of the deadline expect-string exist in the estate\r\n  (`\"captured spt call must complete within its deadline\"` in common/mod.rs:60 vs the\r\n  no-deadline-clause spelling in per-file copies), so a grep keyed to either string undercounts.\r\n  The right fix is a hoist-and-delete refactor (make the common copy pub, adopt it estate-wide,\r\n  carry the item-2 diagnostic arm once) — a 50-file test-estate touch that must NOT ride golden\r\n  cadence as a rider or hide inside a scoped diagnostics item (ADR-0050 thin-lane rationale;\r\n  hertz's USHER item 2 stays scoped to live_resolve, which keeps ONE improved copy as the model).\r\n- **Built evidence:** one public owning helper replaced all 50 file-local\r\n  clones. It owns and tree-kills a timed-out child, waits for reap, drains both\r\n  pipes, and includes the deadline plus partial stdout/stderr in the panic.\r\n  A dedicated regression observes both diagnostics and proves the timed-out PID\r\n  is gone.\r\n- **Ripe when:** a dedicated post-batch test-hygiene lane (natural companion to IR-13's\r\n  mutation-proof loop and IR-23's home-collision fix — same hertz wave shape).\r\n- **Size:** medium by file count, small by risk (mechanical hoist; no assertion changes).\r\n- **Hygiene-lane scope addition (todlando, at #6, 2026-08-04):** a CI prebuild of\r\n  `cargo build -p mock-adapter --bin mock-shell` (derived from tracked `.github/` content) turns\r\n  SIX binedge baseline rows green at once instead of growing the burn-down list one consumer at a\r\n  time — belongs to this lane, not to any thin verb lane. [[IR-38]] (live-binary e2e reap sweep)\r\n  rides the same lane.\r\n- **Built evidence:** all 51 file-local definitions are gone; 158 call sites use the one public\r\n  `common::output_bounded`. The shared helper owns the child, kills and reaps its process tree on\r\n  timeout, drains both pipes, and reports partial stdout/stderr. `bounded_output_e2e` mutation-pins\r\n  both timeout ownership and retained diagnostics.\r\n- **Declared validation extra:** the lane's docs-link gate exposed that `llms_target_exists` treated\r\n  generated targets as absent before generation. Its small refactor + unit keeps source and\r\n  generated link targets distinct; it is deliberate validation fallout, not part of IR-36.\r\n\r\n### IR-37 — `traceable-reqs check` is coverage-only: tag PLACEMENT is unenforced on any multi-tagged REQ, and the more tags a REQ accumulates the less any one is checked\r\n- **Status:** UPSTREAM CLOSED THROUGH RELEASE 2026-08-19 — traceable-reqs PR #19 squash-merged\r\n  @`82d8b14` after doyle's targeted re-review PASS (defect A item-tables + 9 red-first regression\r\n  cells + sighted control; defect B enclosing-item fallback DECLARED in SPEC with cost; 267/267,\r\n  blind repros exit 0); v0.4.0 cut (version bump @`c9a8eb5`, tag pushed, 3 platform assets,\r\n  release notes authored; refs sent to hertz). REMAINING and dispatched to hertz post-#182-landing:\r\n  spt-core consumes v0.4.0 — CI version bump + placement config (enforce-on, module_banner=accept);\r\n  banner cleanup rides a later lane. Entry closes when the consume lane lands. · **Origin:** hertz\r\n  measurement 2026-08-04 (filed by doyle; the measurement is\r\n  hertz's), found when his own pre/post `check` comparison around a tag-adjacency fix came back\r\n  EXIT=0 on BOTH sides — the green he had cited beside the fix validated nothing.\r\n- **What/why:** measured on `test/teardown-bound-shape`: a `unit->REQ-RESIDENT-SERVICE` tag\r\n  SEPARATED from its `#[test]` fn (a const landed between tag block and fn — an AGENTS.md rule-1\r\n  violation) scores EXIT=0 identically to the fixed adjacency. Positive control explains the\r\n  mechanism: that REQ carries 57 unit tags across five files, so 56 other sites decide the\r\n  coverage verdict and no single tag's placement can turn it red. Consequence: AGENTS.md rule 1\r\n  (\"tag on or immediately above the real evidence\") is agent discipline only — drifted tags decay\r\n  silently while coverage stays green, and heavily-tagged REQs decay fastest. This is the\r\n  [[IR-32]] family shape (a gate that cannot see its own blind spot) applied to the traceability\r\n  gate itself.\r\n- **LIMIT, with falsifier (hertz's, verbatim in kind):** behaviour on a SINGLE-tagged REQ was NOT\r\n  established. Separating the only tag of a single-tagged REQ at the stage under test would settle\r\n  whether placement is unenforced outright (still exit 0 ⇒ the checker never reads adjacency) or\r\n  merely un-enforceable at scale (exit 1 ⇒ the checker sees absence, and only multi-tag redundancy\r\n  masks drift). Run that discriminator BEFORE designing any remedy — the two outcomes want\r\n  different fixes (a placement rule in the checker vs a per-tag-nearest-item heuristic).\r\n- **Transfer:** doyle accepted this lane's independent EXIT-0 remeasurement and confirmed it\r\n  matches todlando's settled 2026-08-04 discriminator. Upstream remedy: enforce adjacency for\r\n  each individual `doc`/`impl`/`unit`/`int` tag, with separated-tag negatives covering\r\n  single-tag, interposed-const, file-top-banner, and one-of-many displacement. This repo consumes\r\n  the released checker only.\r\n- **Close condition:** doyle reviews and merges the upstream lane, cuts the `traceable-reqs`\r\n  release, and spt-core consumes that release. Issue/branch/PR/commit refs append here when the\r\n  upstream lane lands.\r\n- **Size:** measurement complete; remedy scope is upstream-owned and dispatched.\r\n- **CONSUME LANE + REGRESSION (doyle, 2026-09-11):** hertz's #304 lane carries the consume (2072b467 ci.yml\r\n  WANT 0.4.0, c3b5feec golden.yml pin, 33936943 `[placement] enforce=on, module_banner=accept`).\r\n  Measured on his tip under 0.4.0: misplaced 9 (tags quoted in backticks in prose; fixed on main\r\n  dd0679dc) and 81 doc stages MISSING that 0.2.0 counted — a checker regression, not drift: 0.4.0's\r\n  git enumeration skipped a FILE root (`CONTEXT.md`), see [[IR-104]]. Fixed upstream as v0.4.1\r\n  (PR #21 -> d9af11d); the lane pins move to 0.4.1 in one fixup after hertz's window. Entry\r\n  closes when that fixup lands on main.\r\n- **DISCRIMINATOR RUN 2026-08-04 (todlando, authorized specimen on `build/w1t2-shell-relink-force`;\r\n  filed by doyle — the measurement is todlando's): the answer is the EXIT-0 ARM.** Single-tagged\r\n  int stage (`REQ-SHELL-RELINK-FORCE`), tag SEPARATED from its fn (parked at file top):\r\n  `traceable-reqs check` EXIT 0 and the REQ still reports `+int`. Tag reverted to adjacency:\r\n  EXIT 0, `+int`. Both exits redirect-read, no pipes. **Placement is UNENFORCED OUTRIGHT — the\r\n  checker never reads adjacency; multi-tag redundancy was never the mechanism, it only widened the\r\n  blind spot.** Remedy option (a) is the live one: a real placement rule in the checker (upstream\r\n  experimplate), not a per-tag-nearest-item heuristic. Measurement caveat, carried at the\r\n  measurer's own insistence: an intermediate probe printed `TAG_ADJACENT_AFTER_REVERT=0` and that\r\n  was the PROBE wrong (`grep -B 1` above the fn lands on `#[test]`, not the tag above it), not a\r\n  failed revert — the revert was verified directly (exactly one tag, above `#[test]`). The\r\n  discriminator result is the record; the intermediate zero is not.\r\n- **REMEDY DISPATCHED 2026-08-18 (doyle):** upstream lane opened in BigscreenVR/traceable-reqs\r\n  (the actual upstream remote; the checkout at `~/Documents/projects/traceable-reqs` tracks it —\r\n  \"experimplate\" above named the tool's origin project, not the repo) — checker-side placement\r\n  rule, default-on in `check`, positive controls all four stages + separated-tag negatives\r\n  including the single-tag displaced discriminator shape and the interposed-const shape.\r\n  Requested by hertz as the IR-37 prerequisite of his test-hygiene family lane (KEYSTONE #182).\r\n  spt-core consumes the upstream RELEASE only — no local shadow checker. Issue/branch/PR refs\r\n  land here when the lane reports.\r\n\r\n### IR-38 — CLASS: an e2e that ends with a live daemon-spawning binary wedges the NEXT build in its pool, and the diagnostic names the wrong lane\r\n- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane. · **Origin:** todlando 2026-08-04,\r\n  `shell_relink_force_e2e` on the #6 lane (filed by doyle; the finding and the fix are todlando's).\r\n- **What/why:** the e2e ends with a LIVE binary by design; on Windows a live process holds its\r\n  image open, so the NEXT cargo invocation in that target dir dies with\r\n  `failed to remove file target\\debug\\spt.exe: Access is denied (os error 5)` — surfacing as\r\n  exit 101 with NO test summary, because the failure names the BUILD and the FILE, never the test\r\n  that leaked the holder. Actual holders measured: two lane-local `spt daemon run --detached` +\r\n  `daemon brain` processes spawned under the test's temp SPT_HOME by a child CLI's\r\n  `ensure_running`, still alive from an earlier run. **Reap BY IMAGE PATH** — the fleet's other\r\n  eleven spt processes run from the installed binary; a name-based sweep takes your own daemon.\r\n  The live shell-spawn population is eleven e2e files. Nine already end through product teardown\r\n  or their authenticated home-scoped reap. The two intentionally live-at-success siblings now\r\n  kill and prove the final resident gone AFTER all identity/wake assertions:\r\n  `shell_relink_force_e2e` and `shell_stale_online_e2e`.\r\n- **Kin:** [[IR-7]] (phase-A daemon+brain pair leak), the exe-lock reap-by-path rule, and the\r\n  wrong-lane-diagnostic family ([[IR-21]]'s location-not-build class).\r\n- **SECOND HOLDER CLASS, measured 2026-08-04 (doyle, own gate rig):** an **ORPHANED CONHOST with an\r\n  inherited CWD** inside the test tree blocks `git worktree remove` with Permission-denied on a\r\n  DIRECTORY handle — invisible to any exe-path scan (conhost runs from System32; the parent that\r\n  spawned it was already dead). Found via `.github/ci/find-cwd-holders.ps1` (IR-11's instrument);\r\n  killed by pid after parent-dead classification; 34.78 GB reclaimed. Mechanism chain: the\r\n  windowless spawn path masks DETACHED_PROCESS off, the child owns a console, conhost inherits the\r\n  child's cwd and can OUTLIVE it. Boundary (hertz's, correct): this find and his field-4 companion\r\n  are the SAME MECHANISM FAMILY measured on DIFFERENT populations by different instruments — his\r\n  capture measured a ppid-match COUNT (floor 2, companion identity UNMEASURED, his stated limit),\r\n  and this conhost is the first FIELD identity evidence in the family, on THIS population. Do not\r\n  cite his row as identity data it never carried. (His box-wide accretion count 77→80 is a third\r\n  population again.) Teardown rule\r\n  addendum: a disposal leg must GATE on the removal's exit code (a rig that logs \"reclaimed 0.01\r\n  GB\" from a failed remove fabricates its own success) and sweep CWD HOLDERS, not only image\r\n  locks — two populations, either alone is a clean zero on the other.\r\n- **Ripe when:** the test-hygiene lane (IR-13/IR-23/IR-36 family) — sweep every e2e that ends\r\n  with a live spawning binary, apply the same reap-after-assertions shape.\r\n- **Size:** small per test; population unknown until swept.\r\n- **Built evidence:** focused runs of both live-at-success tests pass back-to-back in one target\r\n  pool, followed by a build invocation from that same pool; the second test's final kill is polled\r\n  to proven process death rather than treated as fire-and-forget.\r\n\r\n### IR-39 — CLASS: the missing-fixture-bin defect has TWO failure faces, and one of them impersonates a lifecycle defect of the subject under test\r\n- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane. · **Origin:** hertz + todlando\r\n  2026-08-04, same evening from opposite sides (filed by doyle; hertz relayed todlando's\r\n  suggestion without endorsing scope).\r\n- **What/why:** a rig whose narrowed build (`-p <pkg> --test <one>` / `-p spt --bin spt`) skips a\r\n  cross-package fixture bin fails in one of two ways depending on the consuming site.\r\n  Face 1 (cheap): `translate_proof_fixture` panics \"must be built: <path>\" — names the artifact\r\n  and the recipe, costs one build. Face 2 (expensive): `sibling_bin(\"mock-session\")` resolves to a\r\n  nonexistent exe, nothing spawns, and the test reds at a PRECONDITION assert whose message\r\n  (\"warm bring-up spawned=false\", left None / right Some(\"offline\")) reads as a lifecycle defect\r\n  of the subject — measured cost 186s + a triage inside a lent box window (hertz's F1 red arm,\r\n  attempt 1). The build gap itself is the known cross-package row of the fixture-bin population;\r\n  what this entry carries is the DIAGNOSTIC asymmetry.\r\n- **Ask:** a fixture-bin existence precondition that NAMES the missing exe and its build recipe\r\n  wherever a rig consumes one — `sibling_bin` (and the shared\r\n  `crates/spt-term/tests/support/fixture_bin.rs` resolver already carries the recipe string as an\r\n  argument, the shape to copy) refuses with the artifact + recipe instead of letting the consuming\r\n  test fail downstream in its own vocabulary.\r\n- **Kin:** [[IR-21]] (wrong-lane-diagnostic family: the failure names the wrong actor), the\r\n  cargo-builds-package-bins-for-integration-tests rule (cross-package row is the only unguaranteed\r\n  build), golden.yml's dedicated fixture prebuild step.\r\n- **Ripe when:** the test-hygiene lane (IR-13/IR-23/IR-36/IR-38 family) — same sweep population;\r\n  or standalone small if that lane keeps slipping.\r\n- **Size:** small — one shared helper + a sweep of local `sibling_bin` resolver copies (24 known).\r\n- **Addendum (doyle, 2026-08-04 late): third and fourth sightings inside 24 h.** Face 1 twice\r","truncated":true,"truncatedBy":"lines","totalLines":4674,"totalBytes":19856,"outputLines":224,"outputBytes":19856,"lastLinePartial":false,"firstLineExceedsLimit":false},"totalLines":6938,"displayContent":{"text":"### IR-34 — nextest LEAK flag on the zombie-fixture row is dominant-but-intermittent (19/20 measured); any gate reading it as a signal flaps\r\n- **Status:** open · **Origin:** doyle #142 F-lane gate 2026-08-04 (first sighting in a gate run);\r\n  characterized same day by hertz from retained logs, ownership falsified by todlando.\r\n- **What/why:** `broker::tests::windows_session_is_zombie_sees_a_handle_held_corpse_as_dead` (the\r\n  ADR-0041 zombie-detection fixture, whose subject is a corpse process kept alive-looking by a HELD\r\n  HANDLE) flags nextest LEAK on most draws but not all — measured 19 LEAK of 20 on a tree carrying\r\n  no #142 content (`test/grandchild-selection-probe` @`695398b`, based on `4b37512`: lib arm 10/10\r\n  LEAK across 822-test runs; full-suite arm 9/10 across 1044-test runs). The single clean PASS\r\n  kills \"intrinsic therefore always\": leakiness is DOMINANT BUT INTERMITTENT. Consequences:\r\n  (1) a gate or reader that treats this row's LEAK as a defect signal flaps at roughly 1 in 20;\r\n  (2) one non-leaky run is NEVER evidence that something fixed it (kin:\r\n  [[intermittent-green-is-zero-information]]); (3) the verdict method that closed it is the\r\n  template — two independent legs, neither load-bearing alone: the suspect lane's diff grepped\r\n  zero hits on the row's subject (zombie / handle_held / OpenProcess / corpse), AND a 20-draw\r\n  baseline on a tree predating the suspect change. This entry exists so the next gater who sees\r\n  the flag reads one register line instead of running that RCA cold.\r\n- **Remedy shape (sketch, not ruled):** annotate the row as expected-leak in nextest config\r\n  (per-test `leak-timeout` override or documented allowlist) so the flag stops presenting as\r\n  signal; alternatively a fixture-side close of the held handle on the clean path if ADR-0041's\r\n  arrangement permits — hertz's call, test/CI lane.\r\n- **LANE-LINKED 2026-08-30 (#242 close sweep):** hertz's queued daemon-leak fixup lane carries\r\n  this entry (brief cites IR-7/17/20/34/35/63); leaves the register when that lane lands.\r\n- **Ripe when:** hertz's next nextest-config-touching lane; blocks nothing today.\r\n- **Size:** small.\r\n\r\n### IR-35 — hfenduleam Windows test-leg victim rate: one teardown/liveness family, measured at ~half of all executions\r\n- **Status:** open · **Origin:** USHER #150 golden triage 2026-08-04 (doyle; all rates deployah-measured).\r\n- **The numbers (15 golden runs 2026-08-02..08-04 + the USHER cycle, deduped on `(run, box,\r\n  started_at)` — GitHub partial reruns COPY untouched jobs into the new attempt with their ORIGINAL\r\n  `started_at` and carried conclusion, so a carried failure is the SAME observation; dedupe before\r\n  any rate math):** Windows (hfenduleam) 13 red / 22 executions = 59% leg-red, splitting 10/22 = 45%\r\n  test-victim + 3/22 infra (IR-31 class). Linux (kitsubito) 2/20 = 10%, 1 victim. Every victim-red\r\n  leg had EXACTLY ONE victim (8/8 legs). Clean-cycle arithmetic ≈ 0.55 × 0.95 ≈ half — a golden\r\n  cycle at these rates is a coin flip. knock145 (the previous green golden) took FIVE Windows\r\n  executions to its green; USHER took four. **A both-green draw is a draw, not evidence the family\r\n  closed.**\r\n- **The family:** 11 victim legs, 8 distinct tests, ONE cluster — process teardown / kill-reach /\r\n  respawn-controller survival, concentrated on hfenduleam. Per-victim dispositions live in the USHER\r\n  #150 triage ledger (releases#150 record). The only surviving cross-sha EXACT repeat after source\r\n  verification is `resume_no_control_steal_e2e` (:488, byte-identical @2138b16 + @4b37512) — and\r\n  both its reds PREDATE the post-#145 producer-side instrumentation, so what repeats is an AMBIGUOUS\r\n  observation (stolen controller vs starved child) twice; only a post-#145 red discriminates. The\r\n  `a_tree_teardown` pair was a FALSE repeat — two mechanisms wearing one assert string (see\r\n  FLAKE-LEDGER row; the counting lesson: assert-body identity must include the polled predicate's\r\n  SUBJECT).\r\n- **Off-CI discriminator (todlando 2026-08-04):** 0/400 (A 0/200 + B 0/200, interleaved,\r\n  `--test-threads 1`, filters positive-controlled, by-path sweeps every iteration) on the warm\r\n  d449ce5 pool UNDER live-fleet load (CPU 46-59%, 13-18 spt processes). Points the family at the\r\n  RUNNER ENVIRONMENT rather than a product race any Windows box expresses — not exoneration (absence\r\n  of reproduction is not proof of absence), but where the next hour goes. A-alone N=500 on the\r\n  instrumented tree ran post-close (result on releases#150).\r\n- **Remedy lanes already moving:** hertz 4-item test-rework package dispatched 2026-08-04 (psyche\r\n  bound split, live_resolve rig instrumentation, green-capture probe profile, resident_service/\r\n  teardown hardening); prod `wait_bounded` tree-kill-on-timeout filed to board as EVAL. This entry\r\n  is the RATE's home — it leaves the register when the operator has ruled on the rate (accept vs\r\n  hold-for-hertz) AND the hertz package has landed with a re-measured victim rate.\r\n- **LANE-LINKED 2026-08-30 (#242 close sweep):** hertz's queued daemon-leak fixup lane carries\r\n  this entry (brief cites IR-7/17/20/34/35/63); the rate re-measure rides that lane's landing.\r\n- **Ripe when:** operator brief at USHER close (immediate); re-measure after the hertz package lands.\r\n- **Size:** visibility entry + the re-measure; fix cost carried by the hertz package.\r\n\r\n### IR-36 — `output_bounded` is a 51-copy clone estate with a named-but-empty shared home; hoist-and-delete wants its own lane\r\n- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane. · **Origin:** hertz measurement\r\n  2026-08-04 (at `7465ac1`, counted before listing, listed untruncated), during the USHER package\r\n  item-2 sweep ruling; doyle ruled file-don't-sweep.\r\n- **What/why:** 51 `fn output_bounded` definitions under `crates/spt/tests` — 50 per-file copies\r\n  plus `tests/common/mod.rs:53`, which is NOT pub, has ZERO callers outside its own module, and\r\n  whose doc comment states outright that the estate's copies predate the shared module. The lossy\r\n  timeout arm (panic loses everything captured, names nothing) is in 38 sites across 36 files.\r\n  The copies have already drifted: two variants of the deadline expect-string exist in the estate\r\n  (`\"captured spt call must complete within its deadline\"` in common/mod.rs:60 vs the\r\n  no-deadline-clause spelling in per-file copies), so a grep keyed to either string undercounts.\r\n  The right fix is a hoist-and-delete refactor (make the common copy pub, adopt it estate-wide,\r\n  carry the item-2 diagnostic arm once) — a 50-file test-estate touch that must NOT ride golden\r\n  cadence as a rider or hide inside a scoped diagnostics item (ADR-0050 thin-lane rationale;\r\n  hertz's USHER item 2 stays scoped to live_resolve, which keeps ONE improved copy as the model).\r\n- **Built evidence:** one public owning helper replaced all 50 file-local\r\n  clones. It owns and tree-kills a timed-out child, waits for reap, drains both\r\n  pipes, and includes the deadline plus partial stdout/stderr in the panic.\r\n  A dedicated regression observes both diagnostics and proves the timed-out PID\r\n  is gone.\r\n- **Ripe when:** a dedicated post-batch test-hygiene lane (natural companion to IR-13's\r\n  mutation-proof loop and IR-23's home-collision fix — same hertz wave shape).\r\n- **Size:** medium by file count, small by risk (mechanical hoist; no assertion changes).\r\n- **Hygiene-lane scope addition (todlando, at #6, 2026-08-04):** a CI prebuild of\r\n  `cargo build -p mock-adapter --bin mock-shell` (derived from tracked `.github/` content) turns\r\n  SIX binedge baseline rows green at once instead of growing the burn-down list one consumer at a\r\n  time — belongs to this lane, not to any thin verb lane. [[IR-38]] (live-binary e2e reap sweep)\r\n  rides the same lane.\r\n- **Built evidence:** all 51 file-local definitions are gone; 158 call sites use the one public\r\n  `common::output_bounded`. The shared helper owns the child, kills and reaps its process tree on\r\n  timeout, drains both pipes, and reports partial stdout/stderr. `bounded_output_e2e` mutation-pins\r\n  both timeout ownership and retained diagnostics.\r\n- **Declared validation extra:** the lane's docs-link gate exposed that `llms_target_exists` treated\r\n  generated targets as absent before generation. Its small refactor + unit keeps source and\r\n  generated link targets distinct; it is deliberate validation fallout, not part of IR-36.\r\n\r\n### IR-37 — `traceable-reqs check` is coverage-only: tag PLACEMENT is unenforced on any multi-tagged REQ, and the more tags a REQ accumulates the less any one is checked\r\n- **Status:** UPSTREAM CLOSED THROUGH RELEASE 2026-08-19 — traceable-reqs PR #19 squash-merged\r\n  @`82d8b14` after doyle's targeted re-review PASS (defect A item-tables + 9 red-first regression\r\n  cells + sighted control; defect B enclosing-item fallback DECLARED in SPEC with cost; 267/267,\r\n  blind repros exit 0); v0.4.0 cut (version bump @`c9a8eb5`, tag pushed, 3 platform assets,\r\n  release notes authored; refs sent to hertz). REMAINING and dispatched to hertz post-#182-landing:\r\n  spt-core consumes v0.4.0 — CI version bump + placement config (enforce-on, module_banner=accept);\r\n  banner cleanup rides a later lane. Entry closes when the consume lane lands. · **Origin:** hertz\r\n  measurement 2026-08-04 (filed by doyle; the measurement is\r\n  hertz's), found when his own pre/post `check` comparison around a tag-adjacency fix came back\r\n  EXIT=0 on BOTH sides — the green he had cited beside the fix validated nothing.\r\n- **What/why:** measured on `test/teardown-bound-shape`: a `unit->REQ-RESIDENT-SERVICE` tag\r\n  SEPARATED from its `#[test]` fn (a const landed between tag block and fn — an AGENTS.md rule-1\r\n  violation) scores EXIT=0 identically to the fixed adjacency. Positive control explains the\r\n  mechanism: that REQ carries 57 unit tags across five files, so 56 other sites decide the\r\n  coverage verdict and no single tag's placement can turn it red. Consequence: AGENTS.md rule 1\r\n  (\"tag on or immediately above the real evidence\") is agent discipline only — drifted tags decay\r\n  silently while coverage stays green, and heavily-tagged REQs decay fastest. This is the\r\n  [[IR-32]] family shape (a gate that cannot see its own blind spot) applied to the traceability\r\n  gate itself.\r\n- **LIMIT, with falsifier (hertz's, verbatim in kind):** behaviour on a SINGLE-tagged REQ was NOT\r\n  established. Separating the only tag of a single-tagged REQ at the stage under test would settle\r\n  whether placement is unenforced outright (still exit 0 ⇒ the checker never reads adjacency) or\r\n  merely un-enforceable at scale (exit 1 ⇒ the checker sees absence, and only multi-tag redundancy\r\n  masks drift). Run that discriminator BEFORE designing any remedy — the two outcomes want\r\n  different fixes (a placement rule in the checker vs a per-tag-nearest-item heuristic).\r\n- **Transfer:** doyle accepted this lane's independent EXIT-0 remeasurement and confirmed it\r\n  matches todlando's settled 2026-08-04 discriminator. Upstream remedy: enforce adjacency for\r\n  each individual `doc`/`impl`/`unit`/`int` tag, with separated-tag negatives covering\r\n  single-tag, interposed-const, file-top-banner, and one-of-many displacement. This repo consumes\r\n  the released checker only.\r\n- **Close condition:** doyle reviews and merges the upstream lane, cuts the `traceable-reqs`\r\n  release, and spt-core consumes that release. Issue/branch/PR/commit refs append here when the\r\n  upstream lane lands.\r\n- **Size:** measurement complete; remedy scope is upstream-owned and dispatched.\r\n- **CONSUME LANE + REGRESSION (doyle, 2026-09-11):** hertz's #304 lane carries the consume (2072b467 ci.yml\r\n  WANT 0.4.0, c3b5feec golden.yml pin, 33936943 `[placement] enforce=on, module_banner=accept`).\r\n  Measured on his tip under 0.4.0: misplaced 9 (tags quoted in backticks in prose; fixed on main\r\n  dd0679dc) and 81 doc stages MISSING that 0.2.0 counted — a checker regression, not drift: 0.4.0's\r\n  git enumeration skipped a FILE root (`CONTEXT.md`), see [[IR-104]]. Fixed upstream as v0.4.1\r\n  (PR #21 -> d9af11d); the lane pins move to 0.4.1 in one fixup after hertz's window. Entry\r\n  closes when that fixup lands on main.\r\n- **DISCRIMINATOR RUN 2026-08-04 (todlando, authorized specimen on `build/w1t2-shell-relink-force`;\r\n  filed by doyle — the measurement is todlando's): the answer is the EXIT-0 ARM.** Single-tagged\r\n  int stage (`REQ-SHELL-RELINK-FORCE`), tag SEPARATED from its fn (parked at file top):\r\n  `traceable-reqs check` EXIT 0 and the REQ still reports `+int`. Tag reverted to adjacency:\r\n  EXIT 0, `+int`. Both exits redirect-read, no pipes. **Placement is UNENFORCED OUTRIGHT — the\r\n  checker never reads adjacency; multi-tag redundancy was never the mechanism, it only widened the\r\n  blind spot.** Remedy option (a) is the live one: a real placement rule in the checker (upstream\r\n  experimplate), not a per-tag-nearest-item heuristic. Measurement caveat, carried at the\r\n  measurer's own insistence: an intermediate probe printed `TAG_ADJACENT_AFTER_REVERT=0` and that\r\n  was the PROBE wrong (`grep -B 1` above the fn lands on `#[test]`, not the tag above it), not a\r\n  failed revert — the revert was verified directly (exactly one tag, above `#[test]`). The\r\n  discriminator result is the record; the intermediate zero is not.\r\n- **REMEDY DISPATCHED 2026-08-18 (doyle):** upstream lane opened in BigscreenVR/traceable-reqs\r\n  (the actual upstream remote; the checkout at `~/Documents/projects/traceable-reqs` tracks it —\r\n  \"experimplate\" above named the tool's origin project, not the repo) — checker-side placement\r\n  rule, default-on in `check`, positive controls all four stages + separated-tag negatives\r\n  including the single-tag displaced discriminator shape and the interposed-const shape.\r\n  Requested by hertz as the IR-37 prerequisite of his test-hygiene family lane (KEYSTONE #182).\r\n  spt-core consumes the upstream RELEASE only — no local shadow checker. Issue/branch/PR refs\r\n  land here when the lane reports.\r\n\r\n### IR-38 — CLASS: an e2e that ends with a live daemon-spawning binary wedges the NEXT build in its pool, and the diagnostic names the wrong lane\r\n- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane. · **Origin:** todlando 2026-08-04,\r\n  `shell_relink_force_e2e` on the #6 lane (filed by doyle; the finding and the fix are todlando's).\r\n- **What/why:** the e2e ends with a LIVE binary by design; on Windows a live process holds its\r\n  image open, so the NEXT cargo invocation in that target dir dies with\r\n  `failed to remove file target\\debug\\spt.exe: Access is denied (os error 5)` — surfacing as\r\n  exit 101 with NO test summary, because the failure names the BUILD and the FILE, never the test\r\n  that leaked the holder. Actual holders measured: two lane-local `spt daemon run --detached` +\r\n  `daemon brain` processes spawned under the test's temp SPT_HOME by a child CLI's\r\n  `ensure_running`, still alive from an earlier run. **Reap BY IMAGE PATH** — the fleet's other\r\n  eleven spt processes run from the installed binary; a name-based sweep takes your own daemon.\r\n  The live shell-spawn population is eleven e2e files. Nine already end through product teardown\r\n  or their authenticated home-scoped reap. The two intentionally live-at-success siblings now\r\n  kill and prove the final resident gone AFTER all identity/wake assertions:\r\n  `shell_relink_force_e2e` and `shell_stale_online_e2e`.\r\n- **Kin:** [[IR-7]] (phase-A daemon+brain pair leak), the exe-lock reap-by-path rule, and the\r\n  wrong-lane-diagnostic family ([[IR-21]]'s location-not-build class).\r\n- **SECOND HOLDER CLASS, measured 2026-08-04 (doyle, own gate rig):** an **ORPHANED CONHOST with an\r\n  inherited CWD** inside the test tree blocks `git worktree remove` with Permission-denied on a\r\n  DIRECTORY handle — invisible to any exe-path scan (conhost runs from System32; the parent that\r\n  spawned it was already dead). Found via `.github/ci/find-cwd-holders.ps1` (IR-11's instrument);\r\n  killed by pid after parent-dead classification; 34.78 GB reclaimed. Mechanism chain: the\r\n  windowless spawn path masks DETACHED_PROCESS off, the child owns a console, conhost inherits the\r\n  child's cwd and can OUTLIVE it. Boundary (hertz's, correct): this find and his field-4 companion\r\n  are the SAME MECHANISM FAMILY measured on DIFFERENT populations by different instruments — his\r\n  capture measured a ppid-match COUNT (floor 2, companion identity UNMEASURED, his stated limit),\r\n  and this conhost is the first FIELD identity evidence in the family, on THIS population. Do not\r\n  cite his row as identity data it never carried. (His box-wide accretion count 77→80 is a third\r\n  population again.) Teardown rule\r\n  addendum: a disposal leg must GATE on the removal's exit code (a rig that logs \"reclaimed 0.01\r\n  GB\" from a failed remove fabricates its own success) and sweep CWD HOLDERS, not only image\r\n  locks — two populations, either alone is a clean zero on the other.\r\n- **Ripe when:** the test-hygiene lane (IR-13/IR-23/IR-36 family) — sweep every e2e that ends\r\n  with a live spawning binary, apply the same reap-after-assertions shape.\r\n- **Size:** small per test; population unknown until swept.\r\n- **Built evidence:** focused runs of both live-at-success tests pass back-to-back in one target\r\n  pool, followed by a build invocation from that same pool; the second test's final kill is polled\r\n  to proven process death rather than treated as fire-and-forget.\r\n\r\n### IR-39 — CLASS: the missing-fixture-bin defect has TWO failure faces, and one of them impersonates a lifecycle defect of the subject under test\r\n- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane. · **Origin:** hertz + todlando\r\n  2026-08-04, same evening from opposite sides (filed by doyle; hertz relayed todlando's\r\n  suggestion without endorsing scope).\r\n- **What/why:** a rig whose narrowed build (`-p <pkg> --test <one>` / `-p spt --bin spt`) skips a\r\n  cross-package fixture bin fails in one of two ways depending on the consuming site.\r\n  Face 1 (cheap): `translate_proof_fixture` panics \"must be built: <path>\" — names the artifact\r\n  and the recipe, costs one build. Face 2 (expensive): `sibling_bin(\"mock-session\")` resolves to a\r\n  nonexistent exe, nothing spawns, and the test reds at a PRECONDITION assert whose message\r\n  (\"warm bring-up spawned=false\", left None / right Some(\"offline\")) reads as a lifecycle defect\r\n  of the subject — measured cost 186s + a triage inside a lent box window (hertz's F1 red arm,\r\n  attempt 1). The build gap itself is the known cross-package row of the fixture-bin population;\r\n  what this entry carries is the DIAGNOSTIC asymmetry.\r\n- **Ask:** a fixture-bin existence precondition that NAMES the missing exe and its build recipe\r\n  wherever a rig consumes one — `sibling_bin` (and the shared\r\n  `crates/spt-term/tests/support/fixture_bin.rs` resolver already carries the recipe string as an\r\n  argument, the shape to copy) refuses with the artifact + recipe instead of letting the consuming\r\n  test fail downstream in its own vocabulary.\r\n- **Kin:** [[IR-21]] (wrong-lane-diagnostic family: the failure names the wrong actor), the\r\n  cargo-builds-package-bins-for-integration-tests rule (cross-package row is the only unguaranteed\r\n  build), golden.yml's dedicated fixture prebuild step.\r\n- **Ripe when:** the test-hygiene lane (IR-13/IR-23/IR-36/IR-38 family) — same sweep population;\r\n  or standalone small if that lane keeps slipping.\r\n- **Size:** small — one shared helper + a sweep of local `sibling_bin` resolver copies (24 known).\r\n- **Addendum (doyle, 2026-08-04 late): third and fourth sightings inside 24 h.** Face 1 twice\r","startLine":2265,"lineNumbers":[2265,2266,2267,2268,2269,2270,2271,2272,2273,2274,2275,2276,2277,2278,2279,2280,2281,2282,2283,2284,2285,2286,2287,2288,2289,2290,2291,2292,2293,2294,2295,2296,2297,2298,2299,2300,2301,2302,2303,2304,2305,2306,2307,2308,2309,2310,2311,2312,2313,2314,2315,2316,2317,2318,2319,2320,2321,2322,2323,2324,2325,2326,2327,2328,2329,2330,2331,2332,2333,2334,2335,2336,2337,2338,2339,2340,2341,2342,2343,2344,2345,2346,2347,2348,2349,2350,2351,2352,2353,2354,2355,2356,2357,2358,2359,2360,2361,2362,2363,2364,2365,2366,2367,2368,2369,2370,2371,2372,2373,2374,2375,2376,2377,2378,2379,2380,2381,2382,2383,2384,2385,2386,2387,2388,2389,2390,2391,2392,2393,2394,2395,2396,2397,2398,2399,2400,2401,2402,2403,2404,2405,2406,2407,2408,2409,2410,2411,2412,2413,2414,2415,2416,2417,2418,2419,2420,2421,2422,2423,2424,2425,2426,2427,2428,2429,2430,2431,2432,2433,2434,2435,2436,2437,2438,2439,2440,2441,2442,2443,2444,2445,2446,2447,2448,2449,2450,2451,2452,2453,2454,2455,2456,2457,2458,2459,2460,2461,2462,2463,2464,2465,2466,2467,2468,2469,2470,2471,2472,2473,2474,2475,2476,2477,2478,2479,2480,2481,2482,2483,2484,2485,2486,2487,2488]},"fileSize":676479,"meta":{"source":{"type":"path","value":"C:\\Users\\decid\\Documents\\projects\\spt-core\\.worktrees\\hertz-ir86-disk-delta\\docs\\INFRA-REGISTER.md"},"truncation":{"direction":"head","truncatedBy":"lines","totalLines":6938,"totalBytes":19856,"outputLines":224,"outputBytes":19856,"shownRange":{"start":2265,"end":2488},"nextOffset":2489}}},"isError":false,"timestamp":1789483673587}}
{"type":"message","id":"f6092553","parentId":"e9b477ed","timestamp":"2026-09-15T14:47:53.593Z","message":{"role":"toolResult","toolCallId":"call_HyytcgDUHPCUuR4Z7aXGIIrK|fc_043a862a419f59ae016aa95a997a5487d29763e157cbac0748","toolName":"read","content":[{"type":"text","text":"#### THE MECHANISM (measured, both ends)\n\n**Build end — `cargo test` with a narrow target selector compiles a `[[bin]]` AS A TEST HARNESS and\nnever emits the plain executable.** Measured: `cargo test -p spt --bins` on a clean pool produced\nfive executables, every one hash-suffixed under `target/<profile>/deps/`, and ZERO plain exes in\n`target/<profile>/`. The bin was built. The file the test looks for was not written.\n\n**Consumer end — the resolver borrows a guaranteed binary's path to locate an unguaranteed one.**\nAll 29 copies of `sibling_bin` in `crates/spt/tests/` reduce to two textual variants (22 + 7) of one\nbody:\n\n```rust\nfn sibling_bin(name: &str) -> PathBuf {\n    PathBuf::from(env!(\"CARGO_BIN_EXE_spt\"))\n        .with_file_name(format!(\"{name}{}\", std::env::consts::EXE_SUFFIX))\n}\n```\n\n`CARGO_BIN_EXE_spt` is used **only as a directory anchor**. Cargo therefore sees a dependency on\n`spt` and on nothing else; the `{name}` half is a string join it cannot observe. The dependency edge\ndoes not exist at any level a build system could act on — which is why \"use the wider command\" is\nnot the fix and why the failure is invisible on a warm pool where some earlier run happened to leave\nthe file behind.\n\nThe unit-test resolver at `crates/spt/src/cli.rs:25601` reaches the SAME directory from a different\nanchor (`current_exe()` → `deps/` → parent) for the same reason: its own doc comment records that\nunit tests get no `CARGO_BIN_EXE_*` at all.\n\n**That mechanism explains both original members at once, including the polarity inversion that made\nthem look like different bugs:** whether `cargo test -p spt` or `cargo test -p spt --bins` happens\nto leave a plain exe behind is incidental to a dependency neither command was told about.\n\n#### SCOPE — WHERE IT BITES, AND WHERE IT DOES NOT\n\n**It bites NARROW invocations — `-p <pkg>`, `--bins`, `--lib` — i.e. gate rigs and local runs.**\nBoth members were hit on the LOCKSMITH t1 lane against fresh throwaway pools; each was discharged\nin-lane as a rig artifact. That is the whole field population to date.\n\n**GOLDEN IS ACQUITTED, and the acquittal is measured rather than assumed.** `cargo test --workspace\n--no-run` emits all 13 plain binaries — mock-session, mock-shell, capture-player,\nconsole-mode-probe, service_fixture and the rest — so a workspace build produces the cross-package\nhelpers by construction. Confirmed under nextest, the tool CI actually runs, with a real compile.\n\n⚠ **The measurement that establishes this is not the obvious one.** Deleting the plain exe and\nwatching it reappear is NOT evidence of a rebuild: cargo's uplift restores a hardlink from an intact\n`deps/` artifact, with link count 3 and an UNCHANGED mtime, which looks exactly like a build and\nsays nothing about a pool that never had the file — and a pool that never had it is the only kind a\nrig runs on. The sound probe removes the plain exe AND both `deps/` artifacts, confirms all three\nabsent, then watches the target actually recompile (mock-adapter, 5.77s, fresh mtime). The first two\nattempts were setup, not measurement.\n\n⚠ **The suspicion this acquits is structurally well-founded, so record the answer, not just the\nverdict.** `twohost-a`/`twohost-b` are `needs: test`, so the only mock-adapter prebuild runs AFTER\nthe phases that use it; `target/` is gitignored, so checkout never cleans it on a persistent\nself-hosted workdir. Every precondition for artifact leakage is present — the build simply does not\nneed it. The next person who reads that job graph will form the same hypothesis; this is the answer\nwaiting for them.\n\n#### THE ONE CI-SIDE MEMBER THAT IS REAL\n\n`crates/spt/src/cli.rs::adapter_translate_proof_gates_on_commit` is a **unit** test (`kind(bin)`),\nand `CARGO_BIN_EXE_*` is set only for integration tests and benches of the declaring package. A unit\nconsumer therefore CANNOT express the dependency through the env var at all — it has no choice but\nto resolve by path. That is why `.github/workflows/ci.yml:105-106` carries a hand-written\n`cargo build -p spt --bin translate_proof_fixture` before the unit lane, with a comment\n(`ci.yml:102-104`) stating this exact mechanism.\n\n**Deleting that step would red the unit lane on a clean pool, and it would read as a code red.**\nSomebody already hit this class, fixed their own leg correctly, and never turned it into a rule —\nthe comment at `ci.yml:102` is IR-21 written a milestone early, in the one place only its author\nwould find it.\n\n#### POPULATION\n\n**13 bin targets in the workspace** (`cargo metadata --no-deps`, not a grep — an auto-target under\n`src/bin/` and `xtask` are both invisible to a `[[bin]]` grep). Two are not helpers (`spt`, `xtask`);\nthe other **11 are test helpers**, across three packages:\n\n| package | helpers |\n|---|---|\n| `adapters/mock` | mock-session, mock-shell, capture-player, console-mode-probe |\n| `crates/spt-daemon` | dispatch_fixture, service_fixture, summarizer_fixture, xlate_choreo_fixture (⚠ this row was mis-\"corrected\" 2026-08-22 to claim `xlate_choreo_fixture` no longer existed — IT DOES, as an AUTODISCOVERED `src/bin/` target with no `[[bin]]` stanza; the original row was right and merely predated `summarizer_fixture`. See IR-58) |\n| `crates/spt` | translate_proof_fixture, post_step_fixture, gh_fixture, git_fixture |\n\n**44 literal `sibling_bin(\"…\")` call sites**, all in `crates/spt/tests/`, served by **29 copied\nresolvers**. Split by whether the BUILD IS ALREADY GUARANTEED — which is not the same question as\nwhether the env var is available, and an earlier version of this entry conflated the two:\n\n| class | sites | detail | build guaranteed? |\n|---|---|---|---|\n| **cross-package** | **33** | mock-session 26, mock-shell 6, service_fixture 1 | **NO — the hazard members** |\n| **same-package** | **11** | translate_proof_fixture 7, git_fixture 2, post_step_fixture 1, gh_fixture 1 | **YES — already, by construction** |\n\n⚠ **MEASURED TWICE, and it falsifies what this entry said on 2026-08-03 before this revision:** cargo\nbuilds **every bin target of a package whenever it builds ANY integration test of that package** —\nthat same act is what sets `CARGO_BIN_EXE_*` in the first place. So the 11 same-package sites were\nnever unexpressed in a way that could bite, and the hazard population is **33 cross-package sites\nplus the one unit-test member = 34**, not 44.\n\n- **Probe 1 (todlando, root pool):** deleted all four `translate_proof_fixture` artifacts (both\n  hash-suffixed harness exes, the `deps/` plain exe, the uplifted plain exe), confirmed absent, then\n  built ONE UNRELATED and UNMODIFIED integration test of the same package —\n  `cargo test -p spt --test attach_wedge_e2e --no-run`, exit 0, 14.45s. Both plain exes returned with\n  fresh mtimes; the hash-suffixed harness exes stayed absent, which is what distinguishes a bin\n  DEPENDENCY build from a `--bins` harness build.\n- **Probe 2 (doyle, `.worktrees/gate-ec5f38a` pool, independent replication with a different fixture\n  and a different probe test):** deleted `gh_fixture`'s plain exe, its `deps/` plain exe AND its\n  hash-suffixed harness exe, confirmed all three absent, then built `--test json_emit --no-run`\n  (exit 0) — a test that never names `gh_fixture`. The plain pair returned at a FRESH mtime (09:13\n  against the 09:00 it carried before), so this is a real build and not the hardlink uplift this\n  entry warns about elsewhere; the harness exe stayed absent.\n- **Neither probe needs a baseline arm:** the probe test is unmodified and references nothing under\n  edit, so what it measures is cargo's behaviour, not anyone's change.\n- **Corroborated by this entry's own field data:** neither original member was a same-package\n  integration site — member 1 is a UNIT test, member 2 is CROSS-package. The class never had a\n  same-package integration member, and the CI-member section below already stated the governing rule\n  (`CARGO_BIN_EXE_*` is set only for integration tests and benches of the declaring package) one\n  section before the remedy drew the opposite consequence from it.\n\nCommand: `git ls-files '*.rs' | xargs grep -hon 'sibling_bin(\"[a-z_-]*\"' | sed 's/.*sibling_bin(\"//;\ns/\"//' | sort | uniq -c`.\n\n⚠ An earlier report gave 48 sites and a 6/11/37 split. Take the table above: it counts only literal\ncall sites in tracked files and it ships its command. The 11 is the same 11 in both counts.\n\n**The LOCATION half of this class is already closed** by `crates/spt-term/tests/support/fixture_bin.rs`\n— a shared resolver rather than 29 copies. It does not close the BUILD half, and should not be\nmistaken for having done so.\n\n#### REMEDY SHAPE (not ruled)\n\nThe distinction that matters is location vs. build:\n\n1. **The 11 same-package sites are NOT hazard members and need no build fix.** Their build edge\n   already exists (see the two probes in POPULATION above); `env!(\"CARGO_BIN_EXE_<name>\")` for the\n   fixture itself would add nothing to it. Converting them is a **CLARITY** change, worth doing on\n   its own smaller merits — the path becomes the one cargo actually emitted rather than a string-join\n   of a directory anchor and `EXE_SUFFIX`, five copies of `sibling_bin` stop existing (29 → 24), and\n   it completes a migration already paid for: `crates/spt/tests/fixtures/translate_proof_fixture.rs:7-12`\n   records that the fixture was re-homed into `spt` precisely to obtain\n   `CARGO_BIN_EXE_translate_proof_fixture`, and then all 7 call sites resolved by path anyway. **It is\n   not a build fix and must not be filed as one.**\n2. **The 33 cross-package sites cannot**, by cargo's design. Their options are an asserted build in\n   the test's own setup, a `dev-dependencies` artifact dependency, or an explicit documented\n   prebuild — the ci.yml:106 shape, made a rule instead of a local fix.\n3. **Standardising on one wider invocation is NOT a remedy.** It changes which pools happen to work;\n   it does not create the dependency edge, and the two original members had opposite polarity under\n   exactly that theory.\n4. Collapsing the 29 resolver copies is worth doing on the `fixture_bin.rs` model, but on its own it\n   makes the class HARDER to see — one shared resolver still anchored on `CARGO_BIN_EXE_spt` hides\n   the 33 genuinely unexpressed dependencies among its 44 call sites behind one function.\n\n#### SUPERSEDED FRAMING, KEPT SO IT IS NOT RE-DERIVED\n- **Status of the original filing:** open · **Origin:** todlando 2026-08-03, both members hit on the\n  LOCKSMITH t1 lane against fresh throwaway pools; each discharged in-lane as a rig artifact, filed\n  here so the next clean rig does not re-diagnose them as code reds.\n- The first two versions of this entry framed the class as \"the rig's command does not build what\n  the test needs\" and proposed standardising on a wider invocation. **Both are superseded by the\n  measured mechanism above** — the dependency is not under-expressed, it is INEXPRESSIBLE in the\n  form these call sites use, so no choice of invocation creates it. Kept only as the two FIELD\n  MEASUREMENTS that produced the class, which remain true:\n- **MEMBER 1 — MEASURED:** `cli::tests::adapter_translate_proof_gates_on_commit` failed on the\n  first `cargo test -p spt --bins` run. Its fixture binary `translate_proof_fixture` (a\n  `tests/`-homed `[[bin]]`) was ABSENT from the pool — `ls` on the path returned No such file.\n  Building it explicitly and re-running the IDENTICAL command PASSED, after which the full `--bins`\n  suite passed 584/585 with only the releases#117 probe red (that one RED by design). So the\n  discriminator is the fixture's presence, not the tree: same command, same sha, red then green\n  across one `cargo build` of the fixture.\n- **MEMBER 2 — MEASURED:** `cargo test -p spt` does not build `mock-adapter --bin mock-session`, so\n  `attach_wedge_e2e` panics `\"the dummy-harness program must be built\"`. Note the polarity is\n  INVERTED against member 1 — there the narrower `--bins` was the defective invocation and\n  `cargo test -p spt` the correct one; here `cargo test -p spt` is itself insufficient. So the\n  class is NOT \"use the wider command\"; it is that the dependency is not expressed to the build at\n  all, and which invocation happens to work is incidental.\n- **What/why (still true):** on a WARM pool the helper is already there from some earlier run and\n  the test passes, so the defect is invisible exactly where most people work and fires only on a\n  clean pool — i.e. on a GATE RIG, which is the one place a false red costs the most.\n- **The sweep this entry once called its first step HAS BEEN RUN** (todlando 2026-08-03) and its\n  result is the POPULATION section above. It is no longer outstanding.\n\n- **Why it is register debt and not a lane bug:** nothing in the product is wrong. The gap is\n  between what a test needs built and what the rig's command builds, and the fix belongs to the\n  tests' declarations, not to whoever is running a gate that day. Sibling rule:\n  [[gate-clean-target-not-incremental]].\n- **Built evidence:** golden now names every cross-package fixture prebuild\n  (`mock-session`, `mock-shell`, `capture-player`, `console-mode-probe`,\n  `service_fixture`) explicitly; `xtask binedge-check` reports zero missing\n  edges. All 29 local `sibling_bin` resolvers collapsed into\n  `tests/common/mod.rs`; the shared precondition names the missing fixture and\n  its package-correct build command before any product timeout.\n- **Ripe when:** the next gate-rig or CI-touching wave. Cheap, and it pays for itself the first time\n  it stops someone chasing a phantom red on a clean pool.\n- **Size:** remedy (1) is small AND optional — it buys clarity and subtraction, never a build edge;\n  medium for (2), which is a design call before it is an edit and is the only remedy that closes the\n  class.\n\n### IR-22 — An inherited identity env var fails a test, and the diagnostic names them ONE AT A TIME so a correct fix reads as no fix\n- **Status:** open · **Origin:** todlando 2026-08-03, chasing what looked like an `attach_wedge_e2e`\n  code red on the LOCKSMITH t1 lane; root-caused to the runner's own process environment.\n- **MEASURED:** `attach_wedge_e2e` failed for an INHERITED PROCESS-GLOBAL and nothing in the tree:\n  the daemon-stop refusal fired on the running session's own identity env. It named\n  `$OWL_SESSION_ID`; clearing that made it name `$SPT_ENDPOINT_ID`. With `OWL_SESSION_ID`,\n  `SPT_ENDPOINT_ID`, `SPT_AGENT_ID` and `SPT_SESSION_ID` all cleared: exit 0, 1 passed.\n- **The finding is the DIAGNOSTIC SHAPE, not the env hygiene.** Naming one variable at a time means\n  a correct partial fix produces an identical-looking failure, so the natural reading of \"I cleared\n  it and it still fails\" is that the clearing did not work — when in fact each step was right and\n  the message had simply moved on to the next name. A refusal that can only ever name one member of\n  a set it is checking teaches the person debugging it the wrong lesson. Compare the same class in\n  [[IR-15]]/[[IR-18]] terms: the instrument is competent and the report is not.\n- **Why it matters beyond one test:** any agent running suites from a live spt session carries these\n  vars, so this fires for every builder on a perched session and for nobody running from a bare\n  shell — which is precisely the split between how builders work and how CI runs.\n- **Candidate remedies (not ruled):** have the refusal name EVERY identity var it found set, in one\n  line, rather than the first; and/or have the affected tests clear the identity set in their own\n  setup so a perched session is not a special environment. The first is the one that pays off\n  outside this test.\n- **Ripe when:** next CI/test-hygiene wave. **Size:** small.\n\n### IR-23 — `endpoint_teardown_authority_e2e`'s two tests collide with EACH OTHER through the machine-global spt home\n- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane. · **Origin:** todlando 2026-08-03, LOCKSMITH t1 lane.\n- **MEASURED:** both tests copy a psyche binary fixture into `perch::spt_home()/srcs/dummyharness/`\n  (`crates/spt/tests/endpoint_teardown_authority_e2e.rs:399`), which is process-global, so run in\n  parallel inside one binary each holds the file the other wants: `os error 32`, \"used by another\n  process\". **Signature: WHICH of the two fails alternates between runs.** Under\n  `--test-threads=1`: 2 passed, exit 0 — and the wall clock drops from 182s to 14s.\n- **What/why:** two defects in one, and they should not be conflated. (1) The tests are not\n  isolated from each other. (2) The staging path is the MACHINE-GLOBAL spt home rather than the\n  test's own temp home — on a box that is also a CI runner, so the blast radius is not confined to\n  the suite. (2) is the one worth fixing; (1) is a symptom of it.\n- **Note on why this is not already caught:** the standing rule is that integration tests run\n  through nextest, which gives each test its own process and hides the collision entirely. So this\n  is latent on the sanctioned path and only bites the bare `cargo test` path — the rule is working\n  and masking a real defect at the same time, which is why the entry exists rather than a shrug.\n- **Candidate remedy (not ruled):** stage the fixture into the test's own temp home. Sweep for\n  siblings first — any other test writing under `perch::spt_home()` rather than a temp home shares\n  the shape, and nobody has counted them.\n- **Built evidence:** adapter source, manifest registration, and psyche fixture\n  staging now use the rig TempDir. The two process-global resolver users are\n  explicitly serialized, and the bare `cargo test` path passes both cells with\n  `--test-threads=2` in 13.82s after the declared fixture prebuild.\n- **Ripe when:** next test-hygiene wave; the 182s -> 14s figure makes it pay for itself on the\n  bare path. **Size:** small per test, unknown until the sweep.\n\n### IR-24 — `reap::terminate_job` discards `TerminateJobObject`'s return, alone among its own module's siblings\n- **Status:** BUILT — landed `3d12cf3` on main (2026-08-03), fulfilment verified against this\n  entry's own wanted list by doyle 2026-08-04, not merely mapped to the commit: the return is\n  audited and the loss NAMED (`REAP_JOB_TERMINATE_FAIL: brain subtree NOT reaped (<os error>); …\n  the daemon holds no other handle to reach them` — which also ANSWERS the cost-of-loss question\n  this entry said nobody had written down); the \"first thing to check\" was checked and the ruling\n  came out OPPOSITE to IR-16's site in one respect, documented as measured asymmetry in the doc\n  comment: `TerminateJobObject` has NO ordinary failing path (zero only for a broken handle) so a\n  zero is a real loss, while `TerminateProcess` fails `ERROR_ACCESS_DENIED` on the ordinary\n  already-exited path and is deliberately NOT checked — the premise is unit-PINNED both directions\n  (`terminate_job_return_discriminates_broken_handle_from_ordinary_states`, cfg(windows), with a\n  memberless-job false-positive arm). No `job != 0` re-check (second-weaker-rule prohibition\n  honored, same as IR-16). Golden evidence: rides `4b37512` (run 30873007187 attempt 5, 9/9\n  green; the premise unit observed PASS in-pool on the Windows leg, Linux leg green — the\n  cross-platform quiet-`ESRCH` concern stays with `ec5f38a`'s coverage as before). Path\n  correction to this entry's MEASURED line: the site is `crates/spt-daemon/src/reap.rs` (brain\n  subtree reaper), not `crates/spt/src/reap.rs` as first filed ·\n  **Origin:** todlando 2026-08-03, swept while building [[IR-16]]; deliberately\n  NOT folded into that lane (doyle ruling, same day) and filed instead.\n- **MEASURED:** `crates/spt/src/reap.rs:207-211` calls `TerminateJobObject` and discards the result,\n  the identical shape [[IR-16]] closed at `spt-daemon`'s `kill_tree`. Its own module's\n  create/assign siblings at `:178` and `:202` ARE instrumented, so this call is the odd one out\n  where it lives — the module already decided that these returns are worth reading.\n- **Why it was NOT folded into IR-16:** different subject. IR-16's site is a SUPERVISED SERVICE's\n  teardown, where the loss is \"a supervised service's descendants survive\" and the promise it\n  breaks is `REQ-RESIDENT-SERVICE`'s tree claim. This site is the BRAIN SUBTREE's kill-on-close\n  job, which has its own lifetime, its own caller and its own answer to \"what does a failed\n  termination cost here\" — and that answer has not been written down by anyone. Folding it in would\n  have meant settling that question in passing, inside a commit about the supervisor, which is how a\n  second ruling gets smuggled into a lane scoped to one.\n- **What it needs that IR-16's fix does not supply:** IR-16 ruled a LOUD REFUSAL (option B) on the\n  ground that the alternative — a process-table tree-walk fallback — is measured blind in exactly\n  that failure state ([[IR-18]]: descent breaks at the dead middle hop) and would trade a silent\n  loss for a false clean. Whether the same reasoning holds here depends on whether this site kills\n  its direct process in the same breath, which is what makes the middle hop dead by construction\n  there. **That is the first thing to check, and it is not assumed.**\n- **Ripe when:** any wave touching reap/teardown; it inherits IR-16's vocabulary and its\n  discrimination note, so the second one is cheaper than the first. **Size:** small, once the\n  cost-of-loss question is answered for this subject.\n\n\n[Showing lines 1303-1585 of 6938. Use :1586 to continue]"}],"details":{"truncation":{"content":"#### THE MECHANISM (measured, both ends)\r\n\r\n**Build end — `cargo test` with a narrow target selector compiles a `[[bin]]` AS A TEST HARNESS and\r\nnever emits the plain executable.** Measured: `cargo test -p spt --bins` on a clean pool produced\r\nfive executables, every one hash-suffixed under `target/<profile>/deps/`, and ZERO plain exes in\r\n`target/<profile>/`. The bin was built. The file the test looks for was not written.\r\n\r\n**Consumer end — the resolver borrows a guaranteed binary's path to locate an unguaranteed one.**\r\nAll 29 copies of `sibling_bin` in `crates/spt/tests/` reduce to two textual variants (22 + 7) of one\r\nbody:\r\n\r\n```rust\r\nfn sibling_bin(name: &str) -> PathBuf {\r\n    PathBuf::from(env!(\"CARGO_BIN_EXE_spt\"))\r\n        .with_file_name(format!(\"{name}{}\", std::env::consts::EXE_SUFFIX))\r\n}\r\n```\r\n\r\n`CARGO_BIN_EXE_spt` is used **only as a directory anchor**. Cargo therefore sees a dependency on\r\n`spt` and on nothing else; the `{name}` half is a string join it cannot observe. The dependency edge\r\ndoes not exist at any level a build system could act on — which is why \"use the wider command\" is\r\nnot the fix and why the failure is invisible on a warm pool where some earlier run happened to leave\r\nthe file behind.\r\n\r\nThe unit-test resolver at `crates/spt/src/cli.rs:25601` reaches the SAME directory from a different\r\nanchor (`current_exe()` → `deps/` → parent) for the same reason: its own doc comment records that\r\nunit tests get no `CARGO_BIN_EXE_*` at all.\r\n\r\n**That mechanism explains both original members at once, including the polarity inversion that made\r\nthem look like different bugs:** whether `cargo test -p spt` or `cargo test -p spt --bins` happens\r\nto leave a plain exe behind is incidental to a dependency neither command was told about.\r\n\r\n#### SCOPE — WHERE IT BITES, AND WHERE IT DOES NOT\r\n\r\n**It bites NARROW invocations — `-p <pkg>`, `--bins`, `--lib` — i.e. gate rigs and local runs.**\r\nBoth members were hit on the LOCKSMITH t1 lane against fresh throwaway pools; each was discharged\r\nin-lane as a rig artifact. That is the whole field population to date.\r\n\r\n**GOLDEN IS ACQUITTED, and the acquittal is measured rather than assumed.** `cargo test --workspace\r\n--no-run` emits all 13 plain binaries — mock-session, mock-shell, capture-player,\r\nconsole-mode-probe, service_fixture and the rest — so a workspace build produces the cross-package\r\nhelpers by construction. Confirmed under nextest, the tool CI actually runs, with a real compile.\r\n\r\n⚠ **The measurement that establishes this is not the obvious one.** Deleting the plain exe and\r\nwatching it reappear is NOT evidence of a rebuild: cargo's uplift restores a hardlink from an intact\r\n`deps/` artifact, with link count 3 and an UNCHANGED mtime, which looks exactly like a build and\r\nsays nothing about a pool that never had the file — and a pool that never had it is the only kind a\r\nrig runs on. The sound probe removes the plain exe AND both `deps/` artifacts, confirms all three\r\nabsent, then watches the target actually recompile (mock-adapter, 5.77s, fresh mtime). The first two\r\nattempts were setup, not measurement.\r\n\r\n⚠ **The suspicion this acquits is structurally well-founded, so record the answer, not just the\r\nverdict.** `twohost-a`/`twohost-b` are `needs: test`, so the only mock-adapter prebuild runs AFTER\r\nthe phases that use it; `target/` is gitignored, so checkout never cleans it on a persistent\r\nself-hosted workdir. Every precondition for artifact leakage is present — the build simply does not\r\nneed it. The next person who reads that job graph will form the same hypothesis; this is the answer\r\nwaiting for them.\r\n\r\n#### THE ONE CI-SIDE MEMBER THAT IS REAL\r\n\r\n`crates/spt/src/cli.rs::adapter_translate_proof_gates_on_commit` is a **unit** test (`kind(bin)`),\r\nand `CARGO_BIN_EXE_*` is set only for integration tests and benches of the declaring package. A unit\r\nconsumer therefore CANNOT express the dependency through the env var at all — it has no choice but\r\nto resolve by path. That is why `.github/workflows/ci.yml:105-106` carries a hand-written\r\n`cargo build -p spt --bin translate_proof_fixture` before the unit lane, with a comment\r\n(`ci.yml:102-104`) stating this exact mechanism.\r\n\r\n**Deleting that step would red the unit lane on a clean pool, and it would read as a code red.**\r\nSomebody already hit this class, fixed their own leg correctly, and never turned it into a rule —\r\nthe comment at `ci.yml:102` is IR-21 written a milestone early, in the one place only its author\r\nwould find it.\r\n\r\n#### POPULATION\r\n\r\n**13 bin targets in the workspace** (`cargo metadata --no-deps`, not a grep — an auto-target under\r\n`src/bin/` and `xtask` are both invisible to a `[[bin]]` grep). Two are not helpers (`spt`, `xtask`);\r\nthe other **11 are test helpers**, across three packages:\r\n\r\n| package | helpers |\r\n|---|---|\r\n| `adapters/mock` | mock-session, mock-shell, capture-player, console-mode-probe |\r\n| `crates/spt-daemon` | dispatch_fixture, service_fixture, summarizer_fixture, xlate_choreo_fixture (⚠ this row was mis-\"corrected\" 2026-08-22 to claim `xlate_choreo_fixture` no longer existed — IT DOES, as an AUTODISCOVERED `src/bin/` target with no `[[bin]]` stanza; the original row was right and merely predated `summarizer_fixture`. See IR-58) |\r\n| `crates/spt` | translate_proof_fixture, post_step_fixture, gh_fixture, git_fixture |\r\n\r\n**44 literal `sibling_bin(\"…\")` call sites**, all in `crates/spt/tests/`, served by **29 copied\r\nresolvers**. Split by whether the BUILD IS ALREADY GUARANTEED — which is not the same question as\r\nwhether the env var is available, and an earlier version of this entry conflated the two:\r\n\r\n| class | sites | detail | build guaranteed? |\r\n|---|---|---|---|\r\n| **cross-package** | **33** | mock-session 26, mock-shell 6, service_fixture 1 | **NO — the hazard members** |\r\n| **same-package** | **11** | translate_proof_fixture 7, git_fixture 2, post_step_fixture 1, gh_fixture 1 | **YES — already, by construction** |\r\n\r\n⚠ **MEASURED TWICE, and it falsifies what this entry said on 2026-08-03 before this revision:** cargo\r\nbuilds **every bin target of a package whenever it builds ANY integration test of that package** —\r\nthat same act is what sets `CARGO_BIN_EXE_*` in the first place. So the 11 same-package sites were\r\nnever unexpressed in a way that could bite, and the hazard population is **33 cross-package sites\r\nplus the one unit-test member = 34**, not 44.\r\n\r\n- **Probe 1 (todlando, root pool):** deleted all four `translate_proof_fixture` artifacts (both\r\n  hash-suffixed harness exes, the `deps/` plain exe, the uplifted plain exe), confirmed absent, then\r\n  built ONE UNRELATED and UNMODIFIED integration test of the same package —\r\n  `cargo test -p spt --test attach_wedge_e2e --no-run`, exit 0, 14.45s. Both plain exes returned with\r\n  fresh mtimes; the hash-suffixed harness exes stayed absent, which is what distinguishes a bin\r\n  DEPENDENCY build from a `--bins` harness build.\r\n- **Probe 2 (doyle, `.worktrees/gate-ec5f38a` pool, independent replication with a different fixture\r\n  and a different probe test):** deleted `gh_fixture`'s plain exe, its `deps/` plain exe AND its\r\n  hash-suffixed harness exe, confirmed all three absent, then built `--test json_emit --no-run`\r\n  (exit 0) — a test that never names `gh_fixture`. The plain pair returned at a FRESH mtime (09:13\r\n  against the 09:00 it carried before), so this is a real build and not the hardlink uplift this\r\n  entry warns about elsewhere; the harness exe stayed absent.\r\n- **Neither probe needs a baseline arm:** the probe test is unmodified and references nothing under\r\n  edit, so what it measures is cargo's behaviour, not anyone's change.\r\n- **Corroborated by this entry's own field data:** neither original member was a same-package\r\n  integration site — member 1 is a UNIT test, member 2 is CROSS-package. The class never had a\r\n  same-package integration member, and the CI-member section below already stated the governing rule\r\n  (`CARGO_BIN_EXE_*` is set only for integration tests and benches of the declaring package) one\r\n  section before the remedy drew the opposite consequence from it.\r\n\r\nCommand: `git ls-files '*.rs' | xargs grep -hon 'sibling_bin(\"[a-z_-]*\"' | sed 's/.*sibling_bin(\"//;\r\ns/\"//' | sort | uniq -c`.\r\n\r\n⚠ An earlier report gave 48 sites and a 6/11/37 split. Take the table above: it counts only literal\r\ncall sites in tracked files and it ships its command. The 11 is the same 11 in both counts.\r\n\r\n**The LOCATION half of this class is already closed** by `crates/spt-term/tests/support/fixture_bin.rs`\r\n— a shared resolver rather than 29 copies. It does not close the BUILD half, and should not be\r\nmistaken for having done so.\r\n\r\n#### REMEDY SHAPE (not ruled)\r\n\r\nThe distinction that matters is location vs. build:\r\n\r\n1. **The 11 same-package sites are NOT hazard members and need no build fix.** Their build edge\r\n   already exists (see the two probes in POPULATION above); `env!(\"CARGO_BIN_EXE_<name>\")` for the\r\n   fixture itself would add nothing to it. Converting them is a **CLARITY** change, worth doing on\r\n   its own smaller merits — the path becomes the one cargo actually emitted rather than a string-join\r\n   of a directory anchor and `EXE_SUFFIX`, five copies of `sibling_bin` stop existing (29 → 24), and\r\n   it completes a migration already paid for: `crates/spt/tests/fixtures/translate_proof_fixture.rs:7-12`\r\n   records that the fixture was re-homed into `spt` precisely to obtain\r\n   `CARGO_BIN_EXE_translate_proof_fixture`, and then all 7 call sites resolved by path anyway. **It is\r\n   not a build fix and must not be filed as one.**\r\n2. **The 33 cross-package sites cannot**, by cargo's design. Their options are an asserted build in\r\n   the test's own setup, a `dev-dependencies` artifact dependency, or an explicit documented\r\n   prebuild — the ci.yml:106 shape, made a rule instead of a local fix.\r\n3. **Standardising on one wider invocation is NOT a remedy.** It changes which pools happen to work;\r\n   it does not create the dependency edge, and the two original members had opposite polarity under\r\n   exactly that theory.\r\n4. Collapsing the 29 resolver copies is worth doing on the `fixture_bin.rs` model, but on its own it\r\n   makes the class HARDER to see — one shared resolver still anchored on `CARGO_BIN_EXE_spt` hides\r\n   the 33 genuinely unexpressed dependencies among its 44 call sites behind one function.\r\n\r\n#### SUPERSEDED FRAMING, KEPT SO IT IS NOT RE-DERIVED\r\n- **Status of the original filing:** open · **Origin:** todlando 2026-08-03, both members hit on the\r\n  LOCKSMITH t1 lane against fresh throwaway pools; each discharged in-lane as a rig artifact, filed\r\n  here so the next clean rig does not re-diagnose them as code reds.\r\n- The first two versions of this entry framed the class as \"the rig's command does not build what\r\n  the test needs\" and proposed standardising on a wider invocation. **Both are superseded by the\r\n  measured mechanism above** — the dependency is not under-expressed, it is INEXPRESSIBLE in the\r\n  form these call sites use, so no choice of invocation creates it. Kept only as the two FIELD\r\n  MEASUREMENTS that produced the class, which remain true:\r\n- **MEMBER 1 — MEASURED:** `cli::tests::adapter_translate_proof_gates_on_commit` failed on the\r\n  first `cargo test -p spt --bins` run. Its fixture binary `translate_proof_fixture` (a\r\n  `tests/`-homed `[[bin]]`) was ABSENT from the pool — `ls` on the path returned No such file.\r\n  Building it explicitly and re-running the IDENTICAL command PASSED, after which the full `--bins`\r\n  suite passed 584/585 with only the releases#117 probe red (that one RED by design). So the\r\n  discriminator is the fixture's presence, not the tree: same command, same sha, red then green\r\n  across one `cargo build` of the fixture.\r\n- **MEMBER 2 — MEASURED:** `cargo test -p spt` does not build `mock-adapter --bin mock-session`, so\r\n  `attach_wedge_e2e` panics `\"the dummy-harness program must be built\"`. Note the polarity is\r\n  INVERTED against member 1 — there the narrower `--bins` was the defective invocation and\r\n  `cargo test -p spt` the correct one; here `cargo test -p spt` is itself insufficient. So the\r\n  class is NOT \"use the wider command\"; it is that the dependency is not expressed to the build at\r\n  all, and which invocation happens to work is incidental.\r\n- **What/why (still true):** on a WARM pool the helper is already there from some earlier run and\r\n  the test passes, so the defect is invisible exactly where most people work and fires only on a\r\n  clean pool — i.e. on a GATE RIG, which is the one place a false red costs the most.\r\n- **The sweep this entry once called its first step HAS BEEN RUN** (todlando 2026-08-03) and its\r\n  result is the POPULATION section above. It is no longer outstanding.\r\n\r\n- **Why it is register debt and not a lane bug:** nothing in the product is wrong. The gap is\r\n  between what a test needs built and what the rig's command builds, and the fix belongs to the\r\n  tests' declarations, not to whoever is running a gate that day. Sibling rule:\r\n  [[gate-clean-target-not-incremental]].\r\n- **Built evidence:** golden now names every cross-package fixture prebuild\r\n  (`mock-session`, `mock-shell`, `capture-player`, `console-mode-probe`,\r\n  `service_fixture`) explicitly; `xtask binedge-check` reports zero missing\r\n  edges. All 29 local `sibling_bin` resolvers collapsed into\r\n  `tests/common/mod.rs`; the shared precondition names the missing fixture and\r\n  its package-correct build command before any product timeout.\r\n- **Ripe when:** the next gate-rig or CI-touching wave. Cheap, and it pays for itself the first time\r\n  it stops someone chasing a phantom red on a clean pool.\r\n- **Size:** remedy (1) is small AND optional — it buys clarity and subtraction, never a build edge;\r\n  medium for (2), which is a design call before it is an edit and is the only remedy that closes the\r\n  class.\r\n\r\n### IR-22 — An inherited identity env var fails a test, and the diagnostic names them ONE AT A TIME so a correct fix reads as no fix\r\n- **Status:** open · **Origin:** todlando 2026-08-03, chasing what looked like an `attach_wedge_e2e`\r\n  code red on the LOCKSMITH t1 lane; root-caused to the runner's own process environment.\r\n- **MEASURED:** `attach_wedge_e2e` failed for an INHERITED PROCESS-GLOBAL and nothing in the tree:\r\n  the daemon-stop refusal fired on the running session's own identity env. It named\r\n  `$OWL_SESSION_ID`; clearing that made it name `$SPT_ENDPOINT_ID`. With `OWL_SESSION_ID`,\r\n  `SPT_ENDPOINT_ID`, `SPT_AGENT_ID` and `SPT_SESSION_ID` all cleared: exit 0, 1 passed.\r\n- **The finding is the DIAGNOSTIC SHAPE, not the env hygiene.** Naming one variable at a time means\r\n  a correct partial fix produces an identical-looking failure, so the natural reading of \"I cleared\r\n  it and it still fails\" is that the clearing did not work — when in fact each step was right and\r\n  the message had simply moved on to the next name. A refusal that can only ever name one member of\r\n  a set it is checking teaches the person debugging it the wrong lesson. Compare the same class in\r\n  [[IR-15]]/[[IR-18]] terms: the instrument is competent and the report is not.\r\n- **Why it matters beyond one test:** any agent running suites from a live spt session carries these\r\n  vars, so this fires for every builder on a perched session and for nobody running from a bare\r\n  shell — which is precisely the split between how builders work and how CI runs.\r\n- **Candidate remedies (not ruled):** have the refusal name EVERY identity var it found set, in one\r\n  line, rather than the first; and/or have the affected tests clear the identity set in their own\r\n  setup so a perched session is not a special environment. The first is the one that pays off\r\n  outside this test.\r\n- **Ripe when:** next CI/test-hygiene wave. **Size:** small.\r\n\r\n### IR-23 — `endpoint_teardown_authority_e2e`'s two tests collide with EACH OTHER through the machine-global spt home\r\n- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane. · **Origin:** todlando 2026-08-03, LOCKSMITH t1 lane.\r\n- **MEASURED:** both tests copy a psyche binary fixture into `perch::spt_home()/srcs/dummyharness/`\r\n  (`crates/spt/tests/endpoint_teardown_authority_e2e.rs:399`), which is process-global, so run in\r\n  parallel inside one binary each holds the file the other wants: `os error 32`, \"used by another\r\n  process\". **Signature: WHICH of the two fails alternates between runs.** Under\r\n  `--test-threads=1`: 2 passed, exit 0 — and the wall clock drops from 182s to 14s.\r\n- **What/why:** two defects in one, and they should not be conflated. (1) The tests are not\r\n  isolated from each other. (2) The staging path is the MACHINE-GLOBAL spt home rather than the\r\n  test's own temp home — on a box that is also a CI runner, so the blast radius is not confined to\r\n  the suite. (2) is the one worth fixing; (1) is a symptom of it.\r\n- **Note on why this is not already caught:** the standing rule is that integration tests run\r\n  through nextest, which gives each test its own process and hides the collision entirely. So this\r\n  is latent on the sanctioned path and only bites the bare `cargo test` path — the rule is working\r\n  and masking a real defect at the same time, which is why the entry exists rather than a shrug.\r\n- **Candidate remedy (not ruled):** stage the fixture into the test's own temp home. Sweep for\r\n  siblings first — any other test writing under `perch::spt_home()` rather than a temp home shares\r\n  the shape, and nobody has counted them.\r\n- **Built evidence:** adapter source, manifest registration, and psyche fixture\r\n  staging now use the rig TempDir. The two process-global resolver users are\r\n  explicitly serialized, and the bare `cargo test` path passes both cells with\r\n  `--test-threads=2` in 13.82s after the declared fixture prebuild.\r\n- **Ripe when:** next test-hygiene wave; the 182s -> 14s figure makes it pay for itself on the\r\n  bare path. **Size:** small per test, unknown until the sweep.\r\n\r\n### IR-24 — `reap::terminate_job` discards `TerminateJobObject`'s return, alone among its own module's siblings\r\n- **Status:** BUILT — landed `3d12cf3` on main (2026-08-03), fulfilment verified against this\r\n  entry's own wanted list by doyle 2026-08-04, not merely mapped to the commit: the return is\r\n  audited and the loss NAMED (`REAP_JOB_TERMINATE_FAIL: brain subtree NOT reaped (<os error>); …\r\n  the daemon holds no other handle to reach them` — which also ANSWERS the cost-of-loss question\r\n  this entry said nobody had written down); the \"first thing to check\" was checked and the ruling\r\n  came out OPPOSITE to IR-16's site in one respect, documented as measured asymmetry in the doc\r\n  comment: `TerminateJobObject` has NO ordinary failing path (zero only for a broken handle) so a\r\n  zero is a real loss, while `TerminateProcess` fails `ERROR_ACCESS_DENIED` on the ordinary\r\n  already-exited path and is deliberately NOT checked — the premise is unit-PINNED both directions\r\n  (`terminate_job_return_discriminates_broken_handle_from_ordinary_states`, cfg(windows), with a\r\n  memberless-job false-positive arm). No `job != 0` re-check (second-weaker-rule prohibition\r\n  honored, same as IR-16). Golden evidence: rides `4b37512` (run 30873007187 attempt 5, 9/9\r\n  green; the premise unit observed PASS in-pool on the Windows leg, Linux leg green — the\r\n  cross-platform quiet-`ESRCH` concern stays with `ec5f38a`'s coverage as before). Path\r\n  correction to this entry's MEASURED line: the site is `crates/spt-daemon/src/reap.rs` (brain\r\n  subtree reaper), not `crates/spt/src/reap.rs` as first filed ·\r\n  **Origin:** todlando 2026-08-03, swept while building [[IR-16]]; deliberately\r\n  NOT folded into that lane (doyle ruling, same day) and filed instead.\r\n- **MEASURED:** `crates/spt/src/reap.rs:207-211` calls `TerminateJobObject` and discards the result,\r\n  the identical shape [[IR-16]] closed at `spt-daemon`'s `kill_tree`. Its own module's\r\n  create/assign siblings at `:178` and `:202` ARE instrumented, so this call is the odd one out\r\n  where it lives — the module already decided that these returns are worth reading.\r\n- **Why it was NOT folded into IR-16:** different subject. IR-16's site is a SUPERVISED SERVICE's\r\n  teardown, where the loss is \"a supervised service's descendants survive\" and the promise it\r\n  breaks is `REQ-RESIDENT-SERVICE`'s tree claim. This site is the BRAIN SUBTREE's kill-on-close\r\n  job, which has its own lifetime, its own caller and its own answer to \"what does a failed\r\n  termination cost here\" — and that answer has not been written down by anyone. Folding it in would\r\n  have meant settling that question in passing, inside a commit about the supervisor, which is how a\r\n  second ruling gets smuggled into a lane scoped to one.\r\n- **What it needs that IR-16's fix does not supply:** IR-16 ruled a LOUD REFUSAL (option B) on the\r\n  ground that the alternative — a process-table tree-walk fallback — is measured blind in exactly\r\n  that failure state ([[IR-18]]: descent breaks at the dead middle hop) and would trade a silent\r\n  loss for a false clean. Whether the same reasoning holds here depends on whether this site kills\r\n  its direct process in the same breath, which is what makes the middle hop dead by construction\r\n  there. **That is the first thing to check, and it is not assumed.**\r\n- **Ripe when:** any wave touching reap/teardown; it inherits IR-16's vocabulary and its\r\n  discrimination note, so the second one is cheaper than the first. **Size:** small, once the\r\n  cost-of-loss question is answered for this subject.\r\n\r","truncated":true,"truncatedBy":"lines","totalLines":5636,"totalBytes":21782,"outputLines":283,"outputBytes":21782,"lastLinePartial":false,"firstLineExceedsLimit":false},"totalLines":6938,"displayContent":{"text":"#### THE MECHANISM (measured, both ends)\r\n\r\n**Build end — `cargo test` with a narrow target selector compiles a `[[bin]]` AS A TEST HARNESS and\r\nnever emits the plain executable.** Measured: `cargo test -p spt --bins` on a clean pool produced\r\nfive executables, every one hash-suffixed under `target/<profile>/deps/`, and ZERO plain exes in\r\n`target/<profile>/`. The bin was built. The file the test looks for was not written.\r\n\r\n**Consumer end — the resolver borrows a guaranteed binary's path to locate an unguaranteed one.**\r\nAll 29 copies of `sibling_bin` in `crates/spt/tests/` reduce to two textual variants (22 + 7) of one\r\nbody:\r\n\r\n```rust\r\nfn sibling_bin(name: &str) -> PathBuf {\r\n    PathBuf::from(env!(\"CARGO_BIN_EXE_spt\"))\r\n        .with_file_name(format!(\"{name}{}\", std::env::consts::EXE_SUFFIX))\r\n}\r\n```\r\n\r\n`CARGO_BIN_EXE_spt` is used **only as a directory anchor**. Cargo therefore sees a dependency on\r\n`spt` and on nothing else; the `{name}` half is a string join it cannot observe. The dependency edge\r\ndoes not exist at any level a build system could act on — which is why \"use the wider command\" is\r\nnot the fix and why the failure is invisible on a warm pool where some earlier run happened to leave\r\nthe file behind.\r\n\r\nThe unit-test resolver at `crates/spt/src/cli.rs:25601` reaches the SAME directory from a different\r\nanchor (`current_exe()` → `deps/` → parent) for the same reason: its own doc comment records that\r\nunit tests get no `CARGO_BIN_EXE_*` at all.\r\n\r\n**That mechanism explains both original members at once, including the polarity inversion that made\r\nthem look like different bugs:** whether `cargo test -p spt` or `cargo test -p spt --bins` happens\r\nto leave a plain exe behind is incidental to a dependency neither command was told about.\r\n\r\n#### SCOPE — WHERE IT BITES, AND WHERE IT DOES NOT\r\n\r\n**It bites NARROW invocations — `-p <pkg>`, `--bins`, `--lib` — i.e. gate rigs and local runs.**\r\nBoth members were hit on the LOCKSMITH t1 lane against fresh throwaway pools; each was discharged\r\nin-lane as a rig artifact. That is the whole field population to date.\r\n\r\n**GOLDEN IS ACQUITTED, and the acquittal is measured rather than assumed.** `cargo test --workspace\r\n--no-run` emits all 13 plain binaries — mock-session, mock-shell, capture-player,\r\nconsole-mode-probe, service_fixture and the rest — so a workspace build produces the cross-package\r\nhelpers by construction. Confirmed under nextest, the tool CI actually runs, with a real compile.\r\n\r\n⚠ **The measurement that establishes this is not the obvious one.** Deleting the plain exe and\r\nwatching it reappear is NOT evidence of a rebuild: cargo's uplift restores a hardlink from an intact\r\n`deps/` artifact, with link count 3 and an UNCHANGED mtime, which looks exactly like a build and\r\nsays nothing about a pool that never had the file — and a pool that never had it is the only kind a\r\nrig runs on. The sound probe removes the plain exe AND both `deps/` artifacts, confirms all three\r\nabsent, then watches the target actually recompile (mock-adapter, 5.77s, fresh mtime). The first two\r\nattempts were setup, not measurement.\r\n\r\n⚠ **The suspicion this acquits is structurally well-founded, so record the answer, not just the\r\nverdict.** `twohost-a`/`twohost-b` are `needs: test`, so the only mock-adapter prebuild runs AFTER\r\nthe phases that use it; `target/` is gitignored, so checkout never cleans it on a persistent\r\nself-hosted workdir. Every precondition for artifact leakage is present — the build simply does not\r\nneed it. The next person who reads that job graph will form the same hypothesis; this is the answer\r\nwaiting for them.\r\n\r\n#### THE ONE CI-SIDE MEMBER THAT IS REAL\r\n\r\n`crates/spt/src/cli.rs::adapter_translate_proof_gates_on_commit` is a **unit** test (`kind(bin)`),\r\nand `CARGO_BIN_EXE_*` is set only for integration tests and benches of the declaring package. A unit\r\nconsumer therefore CANNOT express the dependency through the env var at all — it has no choice but\r\nto resolve by path. That is why `.github/workflows/ci.yml:105-106` carries a hand-written\r\n`cargo build -p spt --bin translate_proof_fixture` before the unit lane, with a comment\r\n(`ci.yml:102-104`) stating this exact mechanism.\r\n\r\n**Deleting that step would red the unit lane on a clean pool, and it would read as a code red.**\r\nSomebody already hit this class, fixed their own leg correctly, and never turned it into a rule —\r\nthe comment at `ci.yml:102` is IR-21 written a milestone early, in the one place only its author\r\nwould find it.\r\n\r\n#### POPULATION\r\n\r\n**13 bin targets in the workspace** (`cargo metadata --no-deps`, not a grep — an auto-target under\r\n`src/bin/` and `xtask` are both invisible to a `[[bin]]` grep). Two are not helpers (`spt`, `xtask`);\r\nthe other **11 are test helpers**, across three packages:\r\n\r\n| package | helpers |\r\n|---|---|\r\n| `adapters/mock` | mock-session, mock-shell, capture-player, console-mode-probe |\r\n| `crates/spt-daemon` | dispatch_fixture, service_fixture, summarizer_fixture, xlate_choreo_fixture (⚠ this row was mis-\"corrected\" 2026-08-22 to claim `xlate_choreo_fixture` no longer existed — IT DOES, as an AUTODISCOVERED `src/bin/` target with no `[[bin]]` stanza; the original row was right and merely predated `summarizer_fixture`. See IR-58) |\r\n| `crates/spt` | translate_proof_fixture, post_step_fixture, gh_fixture, git_fixture |\r\n\r\n**44 literal `sibling_bin(\"…\")` call sites**, all in `crates/spt/tests/`, served by **29 copied\r\nresolvers**. Split by whether the BUILD IS ALREADY GUARANTEED — which is not the same question as\r\nwhether the env var is available, and an earlier version of this entry conflated the two:\r\n\r\n| class | sites | detail | build guaranteed? |\r\n|---|---|---|---|\r\n| **cross-package** | **33** | mock-session 26, mock-shell 6, service_fixture 1 | **NO — the hazard members** |\r\n| **same-package** | **11** | translate_proof_fixture 7, git_fixture 2, post_step_fixture 1, gh_fixture 1 | **YES — already, by construction** |\r\n\r\n⚠ **MEASURED TWICE, and it falsifies what this entry said on 2026-08-03 before this revision:** cargo\r\nbuilds **every bin target of a package whenever it builds ANY integration test of that package** —\r\nthat same act is what sets `CARGO_BIN_EXE_*` in the first place. So the 11 same-package sites were\r\nnever unexpressed in a way that could bite, and the hazard population is **33 cross-package sites\r\nplus the one unit-test member = 34**, not 44.\r\n\r\n- **Probe 1 (todlando, root pool):** deleted all four `translate_proof_fixture` artifacts (both\r\n  hash-suffixed harness exes, the `deps/` plain exe, the uplifted plain exe), confirmed absent, then\r\n  built ONE UNRELATED and UNMODIFIED integration test of the same package —\r\n  `cargo test -p spt --test attach_wedge_e2e --no-run`, exit 0, 14.45s. Both plain exes returned with\r\n  fresh mtimes; the hash-suffixed harness exes stayed absent, which is what distinguishes a bin\r\n  DEPENDENCY build from a `--bins` harness build.\r\n- **Probe 2 (doyle, `.worktrees/gate-ec5f38a` pool, independent replication with a different fixture\r\n  and a different probe test):** deleted `gh_fixture`'s plain exe, its `deps/` plain exe AND its\r\n  hash-suffixed harness exe, confirmed all three absent, then built `--test json_emit --no-run`\r\n  (exit 0) — a test that never names `gh_fixture`. The plain pair returned at a FRESH mtime (09:13\r\n  against the 09:00 it carried before), so this is a real build and not the hardlink uplift this\r\n  entry warns about elsewhere; the harness exe stayed absent.\r\n- **Neither probe needs a baseline arm:** the probe test is unmodified and references nothing under\r\n  edit, so what it measures is cargo's behaviour, not anyone's change.\r\n- **Corroborated by this entry's own field data:** neither original member was a same-package\r\n  integration site — member 1 is a UNIT test, member 2 is CROSS-package. The class never had a\r\n  same-package integration member, and the CI-member section below already stated the governing rule\r\n  (`CARGO_BIN_EXE_*` is set only for integration tests and benches of the declaring package) one\r\n  section before the remedy drew the opposite consequence from it.\r\n\r\nCommand: `git ls-files '*.rs' | xargs grep -hon 'sibling_bin(\"[a-z_-]*\"' | sed 's/.*sibling_bin(\"//;\r\ns/\"//' | sort | uniq -c`.\r\n\r\n⚠ An earlier report gave 48 sites and a 6/11/37 split. Take the table above: it counts only literal\r\ncall sites in tracked files and it ships its command. The 11 is the same 11 in both counts.\r\n\r\n**The LOCATION half of this class is already closed** by `crates/spt-term/tests/support/fixture_bin.rs`\r\n— a shared resolver rather than 29 copies. It does not close the BUILD half, and should not be\r\nmistaken for having done so.\r\n\r\n#### REMEDY SHAPE (not ruled)\r\n\r\nThe distinction that matters is location vs. build:\r\n\r\n1. **The 11 same-package sites are NOT hazard members and need no build fix.** Their build edge\r\n   already exists (see the two probes in POPULATION above); `env!(\"CARGO_BIN_EXE_<name>\")` for the\r\n   fixture itself would add nothing to it. Converting them is a **CLARITY** change, worth doing on\r\n   its own smaller merits — the path becomes the one cargo actually emitted rather than a string-join\r\n   of a directory anchor and `EXE_SUFFIX`, five copies of `sibling_bin` stop existing (29 → 24), and\r\n   it completes a migration already paid for: `crates/spt/tests/fixtures/translate_proof_fixture.rs:7-12`\r\n   records that the fixture was re-homed into `spt` precisely to obtain\r\n   `CARGO_BIN_EXE_translate_proof_fixture`, and then all 7 call sites resolved by path anyway. **It is\r\n   not a build fix and must not be filed as one.**\r\n2. **The 33 cross-package sites cannot**, by cargo's design. Their options are an asserted build in\r\n   the test's own setup, a `dev-dependencies` artifact dependency, or an explicit documented\r\n   prebuild — the ci.yml:106 shape, made a rule instead of a local fix.\r\n3. **Standardising on one wider invocation is NOT a remedy.** It changes which pools happen to work;\r\n   it does not create the dependency edge, and the two original members had opposite polarity under\r\n   exactly that theory.\r\n4. Collapsing the 29 resolver copies is worth doing on the `fixture_bin.rs` model, but on its own it\r\n   makes the class HARDER to see — one shared resolver still anchored on `CARGO_BIN_EXE_spt` hides\r\n   the 33 genuinely unexpressed dependencies among its 44 call sites behind one function.\r\n\r\n#### SUPERSEDED FRAMING, KEPT SO IT IS NOT RE-DERIVED\r\n- **Status of the original filing:** open · **Origin:** todlando 2026-08-03, both members hit on the\r\n  LOCKSMITH t1 lane against fresh throwaway pools; each discharged in-lane as a rig artifact, filed\r\n  here so the next clean rig does not re-diagnose them as code reds.\r\n- The first two versions of this entry framed the class as \"the rig's command does not build what\r\n  the test needs\" and proposed standardising on a wider invocation. **Both are superseded by the\r\n  measured mechanism above** — the dependency is not under-expressed, it is INEXPRESSIBLE in the\r\n  form these call sites use, so no choice of invocation creates it. Kept only as the two FIELD\r\n  MEASUREMENTS that produced the class, which remain true:\r\n- **MEMBER 1 — MEASURED:** `cli::tests::adapter_translate_proof_gates_on_commit` failed on the\r\n  first `cargo test -p spt --bins` run. Its fixture binary `translate_proof_fixture` (a\r\n  `tests/`-homed `[[bin]]`) was ABSENT from the pool — `ls` on the path returned No such file.\r\n  Building it explicitly and re-running the IDENTICAL command PASSED, after which the full `--bins`\r\n  suite passed 584/585 with only the releases#117 probe red (that one RED by design). So the\r\n  discriminator is the fixture's presence, not the tree: same command, same sha, red then green\r\n  across one `cargo build` of the fixture.\r\n- **MEMBER 2 — MEASURED:** `cargo test -p spt` does not build `mock-adapter --bin mock-session`, so\r\n  `attach_wedge_e2e` panics `\"the dummy-harness program must be built\"`. Note the polarity is\r\n  INVERTED against member 1 — there the narrower `--bins` was the defective invocation and\r\n  `cargo test -p spt` the correct one; here `cargo test -p spt` is itself insufficient. So the\r\n  class is NOT \"use the wider command\"; it is that the dependency is not expressed to the build at\r\n  all, and which invocation happens to work is incidental.\r\n- **What/why (still true):** on a WARM pool the helper is already there from some earlier run and\r\n  the test passes, so the defect is invisible exactly where most people work and fires only on a\r\n  clean pool — i.e. on a GATE RIG, which is the one place a false red costs the most.\r\n- **The sweep this entry once called its first step HAS BEEN RUN** (todlando 2026-08-03) and its\r\n  result is the POPULATION section above. It is no longer outstanding.\r\n\r\n- **Why it is register debt and not a lane bug:** nothing in the product is wrong. The gap is\r\n  between what a test needs built and what the rig's command builds, and the fix belongs to the\r\n  tests' declarations, not to whoever is running a gate that day. Sibling rule:\r\n  [[gate-clean-target-not-incremental]].\r\n- **Built evidence:** golden now names every cross-package fixture prebuild\r\n  (`mock-session`, `mock-shell`, `capture-player`, `console-mode-probe`,\r\n  `service_fixture`) explicitly; `xtask binedge-check` reports zero missing\r\n  edges. All 29 local `sibling_bin` resolvers collapsed into\r\n  `tests/common/mod.rs`; the shared precondition names the missing fixture and\r\n  its package-correct build command before any product timeout.\r\n- **Ripe when:** the next gate-rig or CI-touching wave. Cheap, and it pays for itself the first time\r\n  it stops someone chasing a phantom red on a clean pool.\r\n- **Size:** remedy (1) is small AND optional — it buys clarity and subtraction, never a build edge;\r\n  medium for (2), which is a design call before it is an edit and is the only remedy that closes the\r\n  class.\r\n\r\n### IR-22 — An inherited identity env var fails a test, and the diagnostic names them ONE AT A TIME so a correct fix reads as no fix\r\n- **Status:** open · **Origin:** todlando 2026-08-03, chasing what looked like an `attach_wedge_e2e`\r\n  code red on the LOCKSMITH t1 lane; root-caused to the runner's own process environment.\r\n- **MEASURED:** `attach_wedge_e2e` failed for an INHERITED PROCESS-GLOBAL and nothing in the tree:\r\n  the daemon-stop refusal fired on the running session's own identity env. It named\r\n  `$OWL_SESSION_ID`; clearing that made it name `$SPT_ENDPOINT_ID`. With `OWL_SESSION_ID`,\r\n  `SPT_ENDPOINT_ID`, `SPT_AGENT_ID` and `SPT_SESSION_ID` all cleared: exit 0, 1 passed.\r\n- **The finding is the DIAGNOSTIC SHAPE, not the env hygiene.** Naming one variable at a time means\r\n  a correct partial fix produces an identical-looking failure, so the natural reading of \"I cleared\r\n  it and it still fails\" is that the clearing did not work — when in fact each step was right and\r\n  the message had simply moved on to the next name. A refusal that can only ever name one member of\r\n  a set it is checking teaches the person debugging it the wrong lesson. Compare the same class in\r\n  [[IR-15]]/[[IR-18]] terms: the instrument is competent and the report is not.\r\n- **Why it matters beyond one test:** any agent running suites from a live spt session carries these\r\n  vars, so this fires for every builder on a perched session and for nobody running from a bare\r\n  shell — which is precisely the split between how builders work and how CI runs.\r\n- **Candidate remedies (not ruled):** have the refusal name EVERY identity var it found set, in one\r\n  line, rather than the first; and/or have the affected tests clear the identity set in their own\r\n  setup so a perched session is not a special environment. The first is the one that pays off\r\n  outside this test.\r\n- **Ripe when:** next CI/test-hygiene wave. **Size:** small.\r\n\r\n### IR-23 — `endpoint_teardown_authority_e2e`'s two tests collide with EACH OTHER through the machine-global spt home\r\n- **Status:** BUILT 2026-08-18 on KEYSTONE #182 hygiene lane. · **Origin:** todlando 2026-08-03, LOCKSMITH t1 lane.\r\n- **MEASURED:** both tests copy a psyche binary fixture into `perch::spt_home()/srcs/dummyharness/`\r\n  (`crates/spt/tests/endpoint_teardown_authority_e2e.rs:399`), which is process-global, so run in\r\n  parallel inside one binary each holds the file the other wants: `os error 32`, \"used by another\r\n  process\". **Signature: WHICH of the two fails alternates between runs.** Under\r\n  `--test-threads=1`: 2 passed, exit 0 — and the wall clock drops from 182s to 14s.\r\n- **What/why:** two defects in one, and they should not be conflated. (1) The tests are not\r\n  isolated from each other. (2) The staging path is the MACHINE-GLOBAL spt home rather than the\r\n  test's own temp home — on a box that is also a CI runner, so the blast radius is not confined to\r\n  the suite. (2) is the one worth fixing; (1) is a symptom of it.\r\n- **Note on why this is not already caught:** the standing rule is that integration tests run\r\n  through nextest, which gives each test its own process and hides the collision entirely. So this\r\n  is latent on the sanctioned path and only bites the bare `cargo test` path — the rule is working\r\n  and masking a real defect at the same time, which is why the entry exists rather than a shrug.\r\n- **Candidate remedy (not ruled):** stage the fixture into the test's own temp home. Sweep for\r\n  siblings first — any other test writing under `perch::spt_home()` rather than a temp home shares\r\n  the shape, and nobody has counted them.\r\n- **Built evidence:** adapter source, manifest registration, and psyche fixture\r\n  staging now use the rig TempDir. The two process-global resolver users are\r\n  explicitly serialized, and the bare `cargo test` path passes both cells with\r\n  `--test-threads=2` in 13.82s after the declared fixture prebuild.\r\n- **Ripe when:** next test-hygiene wave; the 182s -> 14s figure makes it pay for itself on the\r\n  bare path. **Size:** small per test, unknown until the sweep.\r\n\r\n### IR-24 — `reap::terminate_job` discards `TerminateJobObject`'s return, alone among its own module's siblings\r\n- **Status:** BUILT — landed `3d12cf3` on main (2026-08-03), fulfilment verified against this\r\n  entry's own wanted list by doyle 2026-08-04, not merely mapped to the commit: the return is\r\n  audited and the loss NAMED (`REAP_JOB_TERMINATE_FAIL: brain subtree NOT reaped (<os error>); …\r\n  the daemon holds no other handle to reach them` — which also ANSWERS the cost-of-loss question\r\n  this entry said nobody had written down); the \"first thing to check\" was checked and the ruling\r\n  came out OPPOSITE to IR-16's site in one respect, documented as measured asymmetry in the doc\r\n  comment: `TerminateJobObject` has NO ordinary failing path (zero only for a broken handle) so a\r\n  zero is a real loss, while `TerminateProcess` fails `ERROR_ACCESS_DENIED` on the ordinary\r\n  already-exited path and is deliberately NOT checked — the premise is unit-PINNED both directions\r\n  (`terminate_job_return_discriminates_broken_handle_from_ordinary_states`, cfg(windows), with a\r\n  memberless-job false-positive arm). No `job != 0` re-check (second-weaker-rule prohibition\r\n  honored, same as IR-16). Golden evidence: rides `4b37512` (run 30873007187 attempt 5, 9/9\r\n  green; the premise unit observed PASS in-pool on the Windows leg, Linux leg green — the\r\n  cross-platform quiet-`ESRCH` concern stays with `ec5f38a`'s coverage as before). Path\r\n  correction to this entry's MEASURED line: the site is `crates/spt-daemon/src/reap.rs` (brain\r\n  subtree reaper), not `crates/spt/src/reap.rs` as first filed ·\r\n  **Origin:** todlando 2026-08-03, swept while building [[IR-16]]; deliberately\r\n  NOT folded into that lane (doyle ruling, same day) and filed instead.\r\n- **MEASURED:** `crates/spt/src/reap.rs:207-211` calls `TerminateJobObject` and discards the result,\r\n  the identical shape [[IR-16]] closed at `spt-daemon`'s `kill_tree`. Its own module's\r\n  create/assign siblings at `:178` and `:202` ARE instrumented, so this call is the odd one out\r\n  where it lives — the module already decided that these returns are worth reading.\r\n- **Why it was NOT folded into IR-16:** different subject. IR-16's site is a SUPERVISED SERVICE's\r\n  teardown, where the loss is \"a supervised service's descendants survive\" and the promise it\r\n  breaks is `REQ-RESIDENT-SERVICE`'s tree claim. This site is the BRAIN SUBTREE's kill-on-close\r\n  job, which has its own lifetime, its own caller and its own answer to \"what does a failed\r\n  termination cost here\" — and that answer has not been written down by anyone. Folding it in would\r\n  have meant settling that question in passing, inside a commit about the supervisor, which is how a\r\n  second ruling gets smuggled into a lane scoped to one.\r\n- **What it needs that IR-16's fix does not supply:** IR-16 ruled a LOUD REFUSAL (option B) on the\r\n  ground that the alternative — a process-table tree-walk fallback — is measured blind in exactly\r\n  that failure state ([[IR-18]]: descent breaks at the dead middle hop) and would trade a silent\r\n  loss for a false clean. Whether the same reasoning holds here depends on whether this site kills\r\n  its direct process in the same breath, which is what makes the middle hop dead by construction\r\n  there. **That is the first thing to check, and it is not assumed.**\r\n- **Ripe when:** any wave touching reap/teardown; it inherits IR-16's vocabulary and its\r\n  discrimination note, so the second one is cheaper than the first. **Size:** small, once the\r\n  cost-of-loss question is answered for this subject.\r\n\r","startLine":1303,"lineNumbers":[1303,1304,1305,1306,1307,1308,1309,1310,1311,1312,1313,1314,1315,1316,1317,1318,1319,1320,1321,1322,1323,1324,1325,1326,1327,1328,1329,1330,1331,1332,1333,1334,1335,1336,1337,1338,1339,1340,1341,1342,1343,1344,1345,1346,1347,1348,1349,1350,1351,1352,1353,1354,1355,1356,1357,1358,1359,1360,1361,1362,1363,1364,1365,1366,1367,1368,1369,1370,1371,1372,1373,1374,1375,1376,1377,1378,1379,1380,1381,1382,1383,1384,1385,1386,1387,1388,1389,1390,1391,1392,1393,1394,1395,1396,1397,1398,1399,1400,1401,1402,1403,1404,1405,1406,1407,1408,1409,1410,1411,1412,1413,1414,1415,1416,1417,1418,1419,1420,1421,1422,1423,1424,1425,1426,1427,1428,1429,1430,1431,1432,1433,1434,1435,1436,1437,1438,1439,1440,1441,1442,1443,1444,1445,1446,1447,1448,1449,1450,1451,1452,1453,1454,1455,1456,1457,1458,1459,1460,1461,1462,1463,1464,1465,1466,1467,1468,1469,1470,1471,1472,1473,1474,1475,1476,1477,1478,1479,1480,1481,1482,1483,1484,1485,1486,1487,1488,1489,1490,1491,1492,1493,1494,1495,1496,1497,1498,1499,1500,1501,1502,1503,1504,1505,1506,1507,1508,1509,1510,1511,1512,1513,1514,1515,1516,1517,1518,1519,1520,1521,1522,1523,1524,1525,1526,1527,1528,1529,1530,1531,1532,1533,1534,1535,1536,1537,1538,1539,1540,1541,1542,1543,1544,1545,1546,1547,1548,1549,1550,1551,1552,1553,1554,1555,1556,1557,1558,1559,1560,1561,1562,1563,1564,1565,1566,1567,1568,1569,1570,1571,1572,1573,1574,1575,1576,1577,1578,1579,1580,1581,1582,1583,1584,1585]},"fileSize":676479,"meta":{"source":{"type":"path","value":"C:\\Users\\decid\\Documents\\projects\\spt-core\\.worktrees\\hertz-ir86-disk-delta\\docs\\INFRA-REGISTER.md"},"truncation":{"direction":"head","truncatedBy":"lines","totalLines":6938,"totalBytes":21782,"outputLines":283,"outputBytes":21782,"shownRange":{"start":1303,"end":1585},"nextOffset":1586}}},"isError":false,"timestamp":1789483673593}}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_KgTuIU7LdN7bkBoLT7MZteVf|fc_043a862a419f59ae016aa95aa6522487d2bf4290ebde7e856e","toolName":"read","startedAt":"2026-09-15T14:48:06.426Z","args":{"path":".worktrees/hertz-ir86-disk-delta/docs/INFRA-REGISTER.md:2930-3200:raw"},"intent":"Reading remaining diagnostics entries"},"id":"d241e2a8","parentId":"f6092553","timestamp":"2026-09-15T14:48:06.426Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_kwkxiFHoqe9dHGuCQzBwcboo|fc_043a862a419f59ae016aa95aa6523487d2ab1c79159aba61d4","toolName":"read","startedAt":"2026-09-15T14:48:06.426Z","args":{"path":".worktrees/hertz-ir86-disk-delta/docs/INFRA-REGISTER.md:3201-3475:raw"},"intent":"Reading tooling discipline entries"},"id":"242f1e2d","parentId":"d241e2a8","timestamp":"2026-09-15T14:48:06.426Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_y7IubKaPJR8BRW1TApZKytGf|fc_043a862a419f59ae016aa95aa6523887d28017c9d6c6112444","toolName":"read","startedAt":"2026-09-15T14:48:06.426Z","args":{"path":".worktrees/hertz-ir86-disk-delta/docs/INFRA-REGISTER.md:3476-3659:raw"},"intent":"Reading final missing entry bodies"},"id":"64d0c198","parentId":"242f1e2d","timestamp":"2026-09-15T14:48:06.426Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_1I3IqrEKXeKcRCcLANI2NWgG|fc_043a862a419f59ae016aa95aa6524087d2aab1f4b397a6ee3e","toolName":"grep","startedAt":"2026-09-15T14:48:06.426Z","args":{"path":".worktrees/hertz-ir86-disk-delta/docs/INFRA-REGISTER.md:3888-6938"},"intent":"Locating late assigned amendments"},"id":"37339a65","parentId":"64d0c198","timestamp":"2026-09-15T14:48:06.426Z"}
{"type":"message","id":"4f82b2ad","parentId":"37339a65","timestamp":"2026-09-15T14:48:06.426Z","message":{"role":"assistant","content":[{"type":"toolCall","id":"call_KgTuIU7LdN7bkBoLT7MZteVf|fc_043a862a419f59ae016aa95aa6522487d2bf4290ebde7e856e","name":"read","arguments":{"i":"Reading remaining diagnostics entries","path":".worktrees/hertz-ir86-disk-delta/docs/INFRA-REGISTER.md:2930-3200:raw"},"intent":"Reading remaining diagnostics entries"},{"type":"toolCall","id":"call_kwkxiFHoqe9dHGuCQzBwcboo|fc_043a862a419f59ae016aa95aa6523487d2ab1c79159aba61d4","name":"read","arguments":{"i":"Reading tooling discipline entries","path":".worktrees/hertz-ir86-disk-delta/docs/INFRA-REGISTER.md:3201-3475:raw"},"intent":"Reading tooling discipline entries"},{"type":"toolCall","id":"call_y7IubKaPJR8BRW1TApZKytGf|fc_043a862a419f59ae016aa95aa6523887d28017c9d6c6112444","name":"read","arguments":{"i":"Reading final missing entry bodies","path":".worktrees/hertz-ir86-disk-delta/docs/INFRA-REGISTER.md:3476-3659:raw"},"intent":"Reading final missing entry bodies"},{"type":"toolCall","id":"call_1I3IqrEKXeKcRCcLANI2NWgG|fc_043a862a419f59ae016aa95aa6524087d2aab1f4b397a6ee3e","name":"grep","arguments":{"i":"Locating late assigned amendments","pattern":"IR-(?:[1-9]|[1-6][0-9]|70)\\b","path":".worktrees/hertz-ir86-disk-delta/docs/INFRA-REGISTER.md:3888-6938","case":null,"gitignore":false,"skip":null},"intent":"Locating late assigned amendments"},{"type":"toolCall","id":"call_dIf6A1z4mcOeCDHqom7T8qCM|fc_043a862a419f59ae016aa95aa6524487d2bfb65934006dab7c","name":"grep","arguments":{"i":"Checking small candidate source seams","pattern":"WANT=|0\\.4\\.1|\\[placement\\]|module_banner|headless|doyle only|::warning|CI SUCCESS|fn cli_reference|fn gen\\(|help.*empty|stdout.is_empty","path":".worktrees/hertz-ir86-disk-delta/.github;.worktrees/hertz-ir86-disk-delta/crates/xtask/src;.worktrees/hertz-ir86-disk-delta/traceable-reqs.toml","case":null,"gitignore":false,"skip":null},"intent":"Checking small candidate source seams"}],"api":"openai-codex-responses","provider":"openai-codex","model":"gpt-6-astra","usage":{"input":30562,"output":370,"cacheRead":68608,"cacheWrite":0,"totalTokens":99540,"cost":{"input":0.30562,"output":0.018500000000000003,"cacheRead":0.068608,"cacheWrite":0,"total":0.392728}},"stopReason":"toolUse","timestamp":1789483673625,"responseId":"resp_043a862a419f59ae016aa95a99ec9487d2937bf37b00861064","providerPayload":{"type":"openaiResponsesHistory","provider":"openai-codex","dt":true,"items":[{"id":"fc_043a862a419f59ae016aa95aa6522487d2bf4290ebde7e856e","type":"function_call","status":"completed","arguments":"{\"i\":\"Reading remaining diagnostics entries\",\"path\":\".worktrees/hertz-ir86-disk-delta/docs/INFRA-REGISTER.md:2930-3200:raw\"}","call_id":"call_KgTuIU7LdN7bkBoLT7MZteVf","internal_chat_message_metadata_passthrough":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"},"name":"read","metadata":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"}},{"id":"fc_043a862a419f59ae016aa95aa6523487d2ab1c79159aba61d4","type":"function_call","status":"completed","arguments":"{\"i\":\"Reading tooling discipline entries\",\"path\":\".worktrees/hertz-ir86-disk-delta/docs/INFRA-REGISTER.md:3201-3475:raw\"}","call_id":"call_kwkxiFHoqe9dHGuCQzBwcboo","internal_chat_message_metadata_passthrough":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"},"name":"read","metadata":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"}},{"id":"fc_043a862a419f59ae016aa95aa6523887d28017c9d6c6112444","type":"function_call","status":"completed","arguments":"{\"i\":\"Reading final missing entry bodies\",\"path\":\".worktrees/hertz-ir86-disk-delta/docs/INFRA-REGISTER.md:3476-3659:raw\"}","call_id":"call_y7IubKaPJR8BRW1TApZKytGf","internal_chat_message_metadata_passthrough":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"},"name":"read","metadata":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"}},{"id":"fc_043a862a419f59ae016aa95aa6524087d2aab1f4b397a6ee3e","type":"function_call","status":"completed","arguments":"{\"i\":\"Locating late assigned amendments\",\"pattern\":\"IR-(?:[1-9]|[1-6][0-9]|70)\\\\b\",\"path\":\".worktrees/hertz-ir86-disk-delta/docs/INFRA-REGISTER.md:3888-6938\",\"case\":null,\"gitignore\":false,\"skip\":null}","call_id":"call_1I3IqrEKXeKcRCcLANI2NWgG","internal_chat_message_metadata_passthrough":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"},"name":"grep","metadata":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"}},{"id":"fc_043a862a419f59ae016aa95aa6524487d2bfb65934006dab7c","type":"function_call","status":"completed","arguments":"{\"i\":\"Checking small candidate source seams\",\"pattern\":\"WANT=|0\\\\.4\\\\.1|\\\\[placement\\\\]|module_banner|headless|doyle only|::warning|CI SUCCESS|fn cli_reference|fn gen\\\\(|help.*empty|stdout.is_empty\",\"path\":\".worktrees/hertz-ir86-disk-delta/.github;.worktrees/hertz-ir86-disk-delta/crates/xtask/src;.worktrees/hertz-ir86-disk-delta/traceable-reqs.toml\",\"case\":null,\"gitignore\":false,\"skip\":null}","call_id":"call_dIf6A1z4mcOeCDHqom7T8qCM","internal_chat_message_metadata_passthrough":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"},"name":"grep","metadata":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"}}]},"duration":12797.5488999784,"ttft":12727.6412999928,"completedAt":1789483686423,"contextSnapshot":{"promptTokens":99170,"nonMessageTokens":10342,"compactionEpoch":0}}}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_dIf6A1z4mcOeCDHqom7T8qCM|fc_043a862a419f59ae016aa95aa6524487d2bfb65934006dab7c","toolName":"grep","startedAt":"2026-09-15T14:48:06.427Z","args":{"path":".worktrees/hertz-ir86-disk-delta/.github;.worktrees/hertz-ir86-disk-delta/crates/xtask/src;.worktrees/hertz-ir86-disk-delta/traceable-reqs.toml"},"intent":"Checking small candidate source seams"},"id":"4901a4e2","parentId":"4f82b2ad","timestamp":"2026-09-15T14:48:06.427Z"}
{"type":"message","id":"5cc6e960","parentId":"4901a4e2","timestamp":"2026-09-15T14:48:06.438Z","message":{"role":"toolResult","toolCallId":"call_y7IubKaPJR8BRW1TApZKytGf|fc_043a862a419f59ae016aa95aa6523887d28017c9d6c6112444","toolName":"read","content":[{"type":"text","text":"### IR-60 — a wrapper that CAPTURES a leg's exit status ends with the capture, so the wrapper's own status is the capture's, not the leg's\n\n- **Status:** OPEN, unowned — script-shape discipline, not a code lane. Filed by doyle 2026-08-22\n  during the TURNKEY #212 W5 lane; mechanism measured by todlando, who reported it first as a\n  possible harness misreport and then RETRACTED that reading himself on a minimal probe.\n- **v0.69.0 recurrence, 2026-09-11 (deployah, own withdrawal):** `NEXTEST_EXIT=0` and the task\n  completion's exit 0 both described the wrapper/truncation path, not Cargo's **101**.\n  `PIPESTATUS` was read outside the executing subshell, so the named verdict measured `tail`.\n  Both green-looking receipts were withdrawn; the raw failed-link output was retained.\n  **An exit FILE alone is insufficient if its writer captures the wrong process.** Capture\n  immediately inside the shell executing the producer, before any other command replaces the\n  status, write that value to the leg's file, and propagate it when wrapper status is reported.\n  The replacement battery's own file read 0, with 121 tests actually run. Keep this entry OPEN:\n  corrected execution of one driver does not make the faulty wrapper shape unreachable.\n- **The reading that started it:** a background leg was summarised as `exit code 0` while the leg's\n  own exit file read `100`. Reported as-is, that is a task runner lying about a red — the worst\n  possible direction for a purposeful-red claim, since it would turn two reds that DID fire into two\n  reds reported as not having fired.\n- **The measurement, minimal and on this box:**\n\n      ( exit 100 ); echo $? > probe.exit; FINAL=$?\n      leg status captured to file : 100\n      wrapper's own final status  : 0\n\n  The wrapper's shape is `( cd <lane> && cargo nextest ... > leg.raw 2>&1 ); echo $? > leg.exit`.\n  **The last command is the `echo`, which succeeds**, so the wrapper genuinely exits 0 while the leg\n  genuinely exited 100. THE RUNNER TOLD THE TRUTH ABOUT THE WRAPPER. There is nothing to file against\n  the task runner, and it would have been filed.\n- **The class, and this is why it is worth an entry rather than a fix:** it is the truncation-pipe\n  family — the meter measured something real, it just was not the thing about to be quoted. **Three\n  shapes now share ONE trigger, and the trigger is not \"is this a pipe\":**\n  1. a truncation pipe (`cmd | tail`, `cmd | head`) — `$?` measures the truncator, and `head` closing\n     the pipe can MANUFACTURE a status (SIGPIPE → 101), so `PIPESTATUS` is not protection either;\n  2. a flattened `$?` read after any intervening command;\n  3. **a wrapper whose last command is the capture itself.**\n  **The trigger in all three is the REPORTING** — every instance happened while trimming or capturing\n  output in order to QUOTE it as evidence.\n- **The practice that held, and the one to keep:** the leg's own file is the leg's verdict. Both reds\n  were real, and the only reason that was knowable is that every leg wrote its exit to its own file\n  rather than to the wrapper's status.\n- **Remedy, in preference order:** (1) never read a wrapper's status as a leg's — read the leg's exit\n  FILE, which the per-leg rule already requires; (2) if a wrapper's own status must be meaningful,\n  end it by re-raising the captured status (`exit \"$(cat leg.exit)\"`) or set the status before the\n  capture is the last word; (3) for anything that becomes evidence, redirect to a file and read the\n  file.\n- **Trigger condition:** ripe now — it rides the next gate-script touch, and the gate scripts in this\n  milestone already write per-leg exit files, which is what makes this discipline rather than debt.\n- **Size guess:** small — a convention line in the gate-script preamble; no product code.\n\n### IR-61 — spacerun's test-module skip carries a SECOND literal tracker; the two answers can drift, and today only a cell stands between them\n\n- **Status:** OPEN, unowned, accepted-with-mitigation. Filed by doyle 2026-08-22 at the TURNKEY #212\n  head gate, as the named residual of the latch repair (the repair itself rides the milestone).\n- **What the debt is.** `crates/xtask/src/spacerun.rs` now skips a column-0 `#[cfg(test)]` module by\n  BRACE DEPTH and resumes after its close, rather than latching the scan to end-of-file. Counting\n  braces safely means knowing when a brace is inside a string, a raw string or a char literal — and\n  the scanner ALREADY tracks literals for its rendering pass. It does not reuse that tracking. There\n  are now TWO answers in one file to \"am I inside a literal\", and **two answers to one question is a\n  disagreement waiting for a reader who fixes one of them.**\n- **Why it was accepted rather than refactored on the spot, stated so the trade is auditable:** the\n  two trackers answer genuinely different questions — the rendering walk is PER LINE and forward\n  from an opening quote (\"where does this literal start and end\"), while the skip needs \"am I inside\n  a literal right now\" carried CONTINUOUSLY across lines. Unifying them is a real refactor of a check\n  that is already gated, already carries five fixed defects, and sits on the tree being handed to\n  golden. The narrow change with an OBSERVABLE failure mode beat the correct-shaped change with a\n  wide blast radius, on that tree, on that day.\n- **The mitigation, and its exact limit.** Three brace cells fail the moment the two trackers\n  disagree about a raw string, a normal string or a char literal, plus a cell that reds when the skip\n  stops consulting a literal tracker at all (`match lit` -> `match Lit::None`). **That is a cell\n  standing in for a refactor.** It catches drift in the three forms it names and nothing else — a\n  fourth literal form, or a change to only one tracker in a form neither cell covers, passes.\n- **The general shape, which is why this is a register entry rather than a comment:** a check whose\n  own correctness depends on a second implementation of a thing it already implements is one\n  refactor away from the defect class it exists to prevent. This same file has already produced\n  three instrument defects (an indented-marker latch, a column-0 latch, and a suppression that\n  decided what got PARSED rather than what got REPORTED). The pattern is not carelessness; it is a\n  scanner accumulating special cases.\n- **Trigger condition:** the next SUBSTANTIVE change to spacerun's scanning — any new skip, any new\n  literal form, any change to either tracker. At that point unify, rather than adding a third answer.\n- **Size guess:** small to medium — one continuous literal-state walk serving both the render pass\n  and the skip, with the existing corpus and brace cells as the regression net.\n\n### IR-62 — an e2e daemon binds well-known ports and collides with the resident fleet on shared runners\n\nFiled 2026-08-23 (doyle), from the #212 r2 golden's Windows Phase A red — one witnessed\ninstance, mechanism verified from the run's own capture, filed on the mechanism per the\nregister's standard.\n\n**Mechanism.** `endpoint_autostart_e2e::saved_endpoint_replays_on_daemon_restart` failed its\nown PRECONDITION (\"daemon B must come up with a fresh brain\") because daemon B's broker came up\ndegraded: `NODE_KEY_FAIL: identity unavailable` (net-less broker, no retry) and\n`DOCS_SERVER_BIND_FAIL` port 5474 `os error 10048` — the docs port was held by a CO-RESIDENT\ndaemon. HFENDULEAM is live infra: the resident fleet's daemon legitimately holds well-known\nports, and any e2e that brings up a daemon with default port bindings is in a race with it BY\nCONSTRUCTION. An isolated SPT_HOME isolates the store and broker socket, NOT globally-numbered\nTCP ports.\n\n**Classification history.** r2: red (35.4s, precondition panic). Run 1 and r3 on the same box:\ngreen. Folded into r3 under a pre-registered predicate (reds twice → dedicated triage); it\ngreened, so this stays an environment-shaped intermittent, NOT a product defect and NOT\nclosed — the collision window is real and will re-fire under the right co-residence timing.\n\n**Remedy direction (not built).** Test daemons should bind ephemeral/rig-scoped ports for\nevery advisory surface (the docs server is advisory — a bind failure should degrade the rig\nloudly, not poison an unrelated cell's precondition), or the precondition should name the\nport-collision cause distinctly so the red self-classifies. Either lane is test/CI work\n(hertz's), triggered the next time this class fires anywhere.\n\n**Kin.** IR-51 (e2e daemon net-enabled on real interfaces — hermeticity is disk-deep only);\nthe known not-ours red classes list in the #212 hand-off.\n\n**BUILT 2026-08-24 (hertz, SIGNET #218 batch; PR #158).** The class fired its second witnessed\ninstance the same day — doyle's W2 gate rig, `engine_room_bringup_e2e` precondition panic with\nthe IR-50 panel naming `DOCS_SERVER_BIND_FAIL` port 5474 `os error 10048` — which armed this\nentry's own trigger. Hertz repro'd deterministically (held the port; brain still reached\nBRAIN_UP), pre-ranked three mechanisms before probing, and built the ephemeral-advisory form:\nrig-only `SPT_TEST_EPHEMERAL_ADVISORY_PORTS=1` makes the daemon's docs listener bind port 0\n(production config/`SPT_DOCS_PORT`/docs-url untouched; the flag matches the literal \"1\" only).\nThe golden workflow's test job sets it globally on both self-hosted legs, the standalone ER rig\nsets it too. Scope note kept honest per his own ranking: the docs collision is retired; if a\nco-diagnostic bind elsewhere still poisons a precondition, that is a residual face of THIS\nentry, not a closed question.\n\n### IR-63 — suite-mix sweeps leak job-escaped autostart daemons that LOCK the pool's spt.exe; and the same box conditions manufacture one random victim per sweep\n\n- **Status:** OPEN, mitigated-by-rig-step — the reap is adopted discipline, not yet construction.\n  Filed by doyle 2026-08-24 at the SIGNET #218 gates; first measured by todlando the same day\n  (his W1 build: four reap rounds of 2, 8, 1, 1 processes, count-by-path stated each round).\n- **Mechanism, two faces of one condition:** (1) e2e sweeps that exercise autostart leave\n  job-escaped daemons running `target/debug/spt.exe`; the NEXT build or `xtask check` then dies\n  on `os error 5` removing the exe — a rig red wearing a build defect's clothes. nextest's own\n  `leaky` flags corroborate (4–8 per sweep measured). (2) The same co-residence (leaked daemons +\n  resident fleet + runner traffic) manufactures ONE red per full sweep with a DIFFERENT victim\n  each time: doyle's W2 gate measured FOUR distinct one-off victims in four same-sha sweeps\n  (ER bringup, composite+bootstrap pair under CI load, resident_service, brain_resume), every\n  one green alone and/or in a sibling sweep. The e2e-leaked-daemons rule holds: a different test\n  dying each run on one sha is ONE environment cause, and hardening members never closes it.\n- **Mitigation adopted (rig step, both todlando's lanes and doyle's gate runner):** reap\n  `spt.exe` BY PATH (`*spt-core\\target*`) before EVERY cargo invocation and after every sweep;\n  report the count each time so a zero is a claim, not silence.\n- **Remedy direction (unbuilt):** the durable form is construction, not discipline — either\n  nextest wrap/xtask verb that performs the by-path reap as a pre-step on this box's rigs, or\n  autostart e2es gain teardown that provably outlives job escape (kin IR-38's built wedge-namer,\n  IR-62's ephemeral ports which retire one collision axis, IR-35's victim-rate ledger).\n- **THIRD FACE, measured 2026-08-30 (doyle, ir57/asm-241 reaps):** the leaked population is not\n  only daemons — battery legs leave ORPHANED HEADLESS `conhost.exe` processes whose CWD sits in\n  the worktree's `crates/spt-daemon` (where the leg ran), and a CWD pin blocks `Remove-Item`/\n  `git worktree remove` on the whole tree with \"being used by another process\" naming the DIR.\n  This is the mechanism behind every recent \"handle-pinned, retry later\" worktree removal: 31\n  such conhosts found at once (Aug 26–29 vintages) pinning FIVE dead worktrees. cargo/rustc\n  absence does NOT clear the suspect list — the conhost outlives its client. Holder census\n  tool: a ~30-line NtQueryInformationProcess CWD probe (PEB→ProcessParameters→CurrentDirectory)\n  over all pids, filtered on the path — names every holder in one pass where no handle.exe\n  exists. 13 killed scoped to the two consented reaps; 18 remain pinning gate-w1-a8f04aff (12),\n  io-parser-w1 (5), gate-w1-786d2381 (1 after kills) — sweep them at the IR-14/26/27/49 audit\n  slot before those removals.\n- **LANE-LINKED 2026-08-30 (#242 close sweep):** hertz's queued daemon-leak fixup lane carries\n  this entry (brief cites IR-7/17/20/34/35/63); leaves the register when that lane lands.\n- **Trigger condition:** next rig/gate-script construction touch, or the first golden red that\n  classifies to face (1).\n- **Size guess:** small-medium — one wrapper seam plus adopting it in the gate/lane scripts.\n\n### IR-64 — HFENDULEAM's disk floor is set by non-CI bulk: ~845 GB of operator payload leaves the golden box ~2 GB of slack against its own 32 GB preflight\n\n- **Status:** OPEN · **Origin:** doyle, v0.63.0 close sweep 2026-08-26; mechanism first measured\n  at the FIELD-SEAL golden window (deployah's IR-31 fifth addendum carries the POOL side of the\n  same event by agreed division — this entry is the OTHER reservoir, deliberately not his).\n- **Mechanism:** the 1.86 TB C: carries ~614 GB Steam + ~230 GB Downloads (operator payload, not\n  CI state). With that floor fixed, normal lane traffic alone walks the box under the 32 GB\n  golden preflight — a full-sweep pool WEIGHS ~90–112 GB steady state (IR-59's measurement) and\n  five FIELD-SEAL lanes cost 148.48 GB (IR-31 fifth addendum), so ONE milestone's pools exceed\n  the entire free margin. Reaping buys windows, not headroom: deployah measured free fall\n  167 → 108 GB within hours of his reap, ~59 GB re-consumed by lane builds. The recurring shape:\n  every milestone pays a reap-and-measure tax to rent space the box does not structurally have.\n- **Why register-worthy rather than \"clean up more\":** agent-side discipline (IR-31's budgeting,\n  pool reaps, teardown steps) is already adopted and still only rents windows — the reservoir\n  that would durably move the floor is operator-owned bulk no agent may touch. Naming it here is\n  the boundary: agents keep budgeting IN POOLS (not GB); moving Steam/Downloads (or adding a\n  disk, or pinning golden to a box without operator payload) is an OPERATOR decision this entry\n  exists to put in front of them once, with numbers, instead of re-deriving the floor each cut.\n- **Ripe when:** operator rules on the bulk (move/expand/accept-the-tax), OR the first golden\n  that dies at the 32 GB preflight despite adopted pool discipline (IR-59's LNK1180-class red).\n- **Size:** zero code; one operator decision + at most a runbook line naming the chosen floor.\n\n\n[Showing lines 3476-3659 of 6938. Use :3660 to continue]"}],"details":{"truncation":{"content":"### IR-60 — a wrapper that CAPTURES a leg's exit status ends with the capture, so the wrapper's own status is the capture's, not the leg's\r\n\r\n- **Status:** OPEN, unowned — script-shape discipline, not a code lane. Filed by doyle 2026-08-22\r\n  during the TURNKEY #212 W5 lane; mechanism measured by todlando, who reported it first as a\r\n  possible harness misreport and then RETRACTED that reading himself on a minimal probe.\r\n- **v0.69.0 recurrence, 2026-09-11 (deployah, own withdrawal):** `NEXTEST_EXIT=0` and the task\r\n  completion's exit 0 both described the wrapper/truncation path, not Cargo's **101**.\r\n  `PIPESTATUS` was read outside the executing subshell, so the named verdict measured `tail`.\r\n  Both green-looking receipts were withdrawn; the raw failed-link output was retained.\r\n  **An exit FILE alone is insufficient if its writer captures the wrong process.** Capture\r\n  immediately inside the shell executing the producer, before any other command replaces the\r\n  status, write that value to the leg's file, and propagate it when wrapper status is reported.\r\n  The replacement battery's own file read 0, with 121 tests actually run. Keep this entry OPEN:\r\n  corrected execution of one driver does not make the faulty wrapper shape unreachable.\r\n- **The reading that started it:** a background leg was summarised as `exit code 0` while the leg's\r\n  own exit file read `100`. Reported as-is, that is a task runner lying about a red — the worst\r\n  possible direction for a purposeful-red claim, since it would turn two reds that DID fire into two\r\n  reds reported as not having fired.\r\n- **The measurement, minimal and on this box:**\r\n\r\n      ( exit 100 ); echo $? > probe.exit; FINAL=$?\r\n      leg status captured to file : 100\r\n      wrapper's own final status  : 0\r\n\r\n  The wrapper's shape is `( cd <lane> && cargo nextest ... > leg.raw 2>&1 ); echo $? > leg.exit`.\r\n  **The last command is the `echo`, which succeeds**, so the wrapper genuinely exits 0 while the leg\r\n  genuinely exited 100. THE RUNNER TOLD THE TRUTH ABOUT THE WRAPPER. There is nothing to file against\r\n  the task runner, and it would have been filed.\r\n- **The class, and this is why it is worth an entry rather than a fix:** it is the truncation-pipe\r\n  family — the meter measured something real, it just was not the thing about to be quoted. **Three\r\n  shapes now share ONE trigger, and the trigger is not \"is this a pipe\":**\r\n  1. a truncation pipe (`cmd | tail`, `cmd | head`) — `$?` measures the truncator, and `head` closing\r\n     the pipe can MANUFACTURE a status (SIGPIPE → 101), so `PIPESTATUS` is not protection either;\r\n  2. a flattened `$?` read after any intervening command;\r\n  3. **a wrapper whose last command is the capture itself.**\r\n  **The trigger in all three is the REPORTING** — every instance happened while trimming or capturing\r\n  output in order to QUOTE it as evidence.\r\n- **The practice that held, and the one to keep:** the leg's own file is the leg's verdict. Both reds\r\n  were real, and the only reason that was knowable is that every leg wrote its exit to its own file\r\n  rather than to the wrapper's status.\r\n- **Remedy, in preference order:** (1) never read a wrapper's status as a leg's — read the leg's exit\r\n  FILE, which the per-leg rule already requires; (2) if a wrapper's own status must be meaningful,\r\n  end it by re-raising the captured status (`exit \"$(cat leg.exit)\"`) or set the status before the\r\n  capture is the last word; (3) for anything that becomes evidence, redirect to a file and read the\r\n  file.\r\n- **Trigger condition:** ripe now — it rides the next gate-script touch, and the gate scripts in this\r\n  milestone already write per-leg exit files, which is what makes this discipline rather than debt.\r\n- **Size guess:** small — a convention line in the gate-script preamble; no product code.\r\n\r\n### IR-61 — spacerun's test-module skip carries a SECOND literal tracker; the two answers can drift, and today only a cell stands between them\r\n\r\n- **Status:** OPEN, unowned, accepted-with-mitigation. Filed by doyle 2026-08-22 at the TURNKEY #212\r\n  head gate, as the named residual of the latch repair (the repair itself rides the milestone).\r\n- **What the debt is.** `crates/xtask/src/spacerun.rs` now skips a column-0 `#[cfg(test)]` module by\r\n  BRACE DEPTH and resumes after its close, rather than latching the scan to end-of-file. Counting\r\n  braces safely means knowing when a brace is inside a string, a raw string or a char literal — and\r\n  the scanner ALREADY tracks literals for its rendering pass. It does not reuse that tracking. There\r\n  are now TWO answers in one file to \"am I inside a literal\", and **two answers to one question is a\r\n  disagreement waiting for a reader who fixes one of them.**\r\n- **Why it was accepted rather than refactored on the spot, stated so the trade is auditable:** the\r\n  two trackers answer genuinely different questions — the rendering walk is PER LINE and forward\r\n  from an opening quote (\"where does this literal start and end\"), while the skip needs \"am I inside\r\n  a literal right now\" carried CONTINUOUSLY across lines. Unifying them is a real refactor of a check\r\n  that is already gated, already carries five fixed defects, and sits on the tree being handed to\r\n  golden. The narrow change with an OBSERVABLE failure mode beat the correct-shaped change with a\r\n  wide blast radius, on that tree, on that day.\r\n- **The mitigation, and its exact limit.** Three brace cells fail the moment the two trackers\r\n  disagree about a raw string, a normal string or a char literal, plus a cell that reds when the skip\r\n  stops consulting a literal tracker at all (`match lit` -> `match Lit::None`). **That is a cell\r\n  standing in for a refactor.** It catches drift in the three forms it names and nothing else — a\r\n  fourth literal form, or a change to only one tracker in a form neither cell covers, passes.\r\n- **The general shape, which is why this is a register entry rather than a comment:** a check whose\r\n  own correctness depends on a second implementation of a thing it already implements is one\r\n  refactor away from the defect class it exists to prevent. This same file has already produced\r\n  three instrument defects (an indented-marker latch, a column-0 latch, and a suppression that\r\n  decided what got PARSED rather than what got REPORTED). The pattern is not carelessness; it is a\r\n  scanner accumulating special cases.\r\n- **Trigger condition:** the next SUBSTANTIVE change to spacerun's scanning — any new skip, any new\r\n  literal form, any change to either tracker. At that point unify, rather than adding a third answer.\r\n- **Size guess:** small to medium — one continuous literal-state walk serving both the render pass\r\n  and the skip, with the existing corpus and brace cells as the regression net.\r\n\r\n### IR-62 — an e2e daemon binds well-known ports and collides with the resident fleet on shared runners\r\n\r\nFiled 2026-08-23 (doyle), from the #212 r2 golden's Windows Phase A red — one witnessed\r\ninstance, mechanism verified from the run's own capture, filed on the mechanism per the\r\nregister's standard.\r\n\r\n**Mechanism.** `endpoint_autostart_e2e::saved_endpoint_replays_on_daemon_restart` failed its\r\nown PRECONDITION (\"daemon B must come up with a fresh brain\") because daemon B's broker came up\r\ndegraded: `NODE_KEY_FAIL: identity unavailable` (net-less broker, no retry) and\r\n`DOCS_SERVER_BIND_FAIL` port 5474 `os error 10048` — the docs port was held by a CO-RESIDENT\r\ndaemon. HFENDULEAM is live infra: the resident fleet's daemon legitimately holds well-known\r\nports, and any e2e that brings up a daemon with default port bindings is in a race with it BY\r\nCONSTRUCTION. An isolated SPT_HOME isolates the store and broker socket, NOT globally-numbered\r\nTCP ports.\r\n\r\n**Classification history.** r2: red (35.4s, precondition panic). Run 1 and r3 on the same box:\r\ngreen. Folded into r3 under a pre-registered predicate (reds twice → dedicated triage); it\r\ngreened, so this stays an environment-shaped intermittent, NOT a product defect and NOT\r\nclosed — the collision window is real and will re-fire under the right co-residence timing.\r\n\r\n**Remedy direction (not built).** Test daemons should bind ephemeral/rig-scoped ports for\r\nevery advisory surface (the docs server is advisory — a bind failure should degrade the rig\r\nloudly, not poison an unrelated cell's precondition), or the precondition should name the\r\nport-collision cause distinctly so the red self-classifies. Either lane is test/CI work\r\n(hertz's), triggered the next time this class fires anywhere.\r\n\r\n**Kin.** IR-51 (e2e daemon net-enabled on real interfaces — hermeticity is disk-deep only);\r\nthe known not-ours red classes list in the #212 hand-off.\r\n\r\n**BUILT 2026-08-24 (hertz, SIGNET #218 batch; PR #158).** The class fired its second witnessed\r\ninstance the same day — doyle's W2 gate rig, `engine_room_bringup_e2e` precondition panic with\r\nthe IR-50 panel naming `DOCS_SERVER_BIND_FAIL` port 5474 `os error 10048` — which armed this\r\nentry's own trigger. Hertz repro'd deterministically (held the port; brain still reached\r\nBRAIN_UP), pre-ranked three mechanisms before probing, and built the ephemeral-advisory form:\r\nrig-only `SPT_TEST_EPHEMERAL_ADVISORY_PORTS=1` makes the daemon's docs listener bind port 0\r\n(production config/`SPT_DOCS_PORT`/docs-url untouched; the flag matches the literal \"1\" only).\r\nThe golden workflow's test job sets it globally on both self-hosted legs, the standalone ER rig\r\nsets it too. Scope note kept honest per his own ranking: the docs collision is retired; if a\r\nco-diagnostic bind elsewhere still poisons a precondition, that is a residual face of THIS\r\nentry, not a closed question.\r\n\r\n### IR-63 — suite-mix sweeps leak job-escaped autostart daemons that LOCK the pool's spt.exe; and the same box conditions manufacture one random victim per sweep\r\n\r\n- **Status:** OPEN, mitigated-by-rig-step — the reap is adopted discipline, not yet construction.\r\n  Filed by doyle 2026-08-24 at the SIGNET #218 gates; first measured by todlando the same day\r\n  (his W1 build: four reap rounds of 2, 8, 1, 1 processes, count-by-path stated each round).\r\n- **Mechanism, two faces of one condition:** (1) e2e sweeps that exercise autostart leave\r\n  job-escaped daemons running `target/debug/spt.exe`; the NEXT build or `xtask check` then dies\r\n  on `os error 5` removing the exe — a rig red wearing a build defect's clothes. nextest's own\r\n  `leaky` flags corroborate (4–8 per sweep measured). (2) The same co-residence (leaked daemons +\r\n  resident fleet + runner traffic) manufactures ONE red per full sweep with a DIFFERENT victim\r\n  each time: doyle's W2 gate measured FOUR distinct one-off victims in four same-sha sweeps\r\n  (ER bringup, composite+bootstrap pair under CI load, resident_service, brain_resume), every\r\n  one green alone and/or in a sibling sweep. The e2e-leaked-daemons rule holds: a different test\r\n  dying each run on one sha is ONE environment cause, and hardening members never closes it.\r\n- **Mitigation adopted (rig step, both todlando's lanes and doyle's gate runner):** reap\r\n  `spt.exe` BY PATH (`*spt-core\\target*`) before EVERY cargo invocation and after every sweep;\r\n  report the count each time so a zero is a claim, not silence.\r\n- **Remedy direction (unbuilt):** the durable form is construction, not discipline — either\r\n  nextest wrap/xtask verb that performs the by-path reap as a pre-step on this box's rigs, or\r\n  autostart e2es gain teardown that provably outlives job escape (kin IR-38's built wedge-namer,\r\n  IR-62's ephemeral ports which retire one collision axis, IR-35's victim-rate ledger).\r\n- **THIRD FACE, measured 2026-08-30 (doyle, ir57/asm-241 reaps):** the leaked population is not\r\n  only daemons — battery legs leave ORPHANED HEADLESS `conhost.exe` processes whose CWD sits in\r\n  the worktree's `crates/spt-daemon` (where the leg ran), and a CWD pin blocks `Remove-Item`/\r\n  `git worktree remove` on the whole tree with \"being used by another process\" naming the DIR.\r\n  This is the mechanism behind every recent \"handle-pinned, retry later\" worktree removal: 31\r\n  such conhosts found at once (Aug 26–29 vintages) pinning FIVE dead worktrees. cargo/rustc\r\n  absence does NOT clear the suspect list — the conhost outlives its client. Holder census\r\n  tool: a ~30-line NtQueryInformationProcess CWD probe (PEB→ProcessParameters→CurrentDirectory)\r\n  over all pids, filtered on the path — names every holder in one pass where no handle.exe\r\n  exists. 13 killed scoped to the two consented reaps; 18 remain pinning gate-w1-a8f04aff (12),\r\n  io-parser-w1 (5), gate-w1-786d2381 (1 after kills) — sweep them at the IR-14/26/27/49 audit\r\n  slot before those removals.\r\n- **LANE-LINKED 2026-08-30 (#242 close sweep):** hertz's queued daemon-leak fixup lane carries\r\n  this entry (brief cites IR-7/17/20/34/35/63); leaves the register when that lane lands.\r\n- **Trigger condition:** next rig/gate-script construction touch, or the first golden red that\r\n  classifies to face (1).\r\n- **Size guess:** small-medium — one wrapper seam plus adopting it in the gate/lane scripts.\r\n\r\n### IR-64 — HFENDULEAM's disk floor is set by non-CI bulk: ~845 GB of operator payload leaves the golden box ~2 GB of slack against its own 32 GB preflight\r\n\r\n- **Status:** OPEN · **Origin:** doyle, v0.63.0 close sweep 2026-08-26; mechanism first measured\r\n  at the FIELD-SEAL golden window (deployah's IR-31 fifth addendum carries the POOL side of the\r\n  same event by agreed division — this entry is the OTHER reservoir, deliberately not his).\r\n- **Mechanism:** the 1.86 TB C: carries ~614 GB Steam + ~230 GB Downloads (operator payload, not\r\n  CI state). With that floor fixed, normal lane traffic alone walks the box under the 32 GB\r\n  golden preflight — a full-sweep pool WEIGHS ~90–112 GB steady state (IR-59's measurement) and\r\n  five FIELD-SEAL lanes cost 148.48 GB (IR-31 fifth addendum), so ONE milestone's pools exceed\r\n  the entire free margin. Reaping buys windows, not headroom: deployah measured free fall\r\n  167 → 108 GB within hours of his reap, ~59 GB re-consumed by lane builds. The recurring shape:\r\n  every milestone pays a reap-and-measure tax to rent space the box does not structurally have.\r\n- **Why register-worthy rather than \"clean up more\":** agent-side discipline (IR-31's budgeting,\r\n  pool reaps, teardown steps) is already adopted and still only rents windows — the reservoir\r\n  that would durably move the floor is operator-owned bulk no agent may touch. Naming it here is\r\n  the boundary: agents keep budgeting IN POOLS (not GB); moving Steam/Downloads (or adding a\r\n  disk, or pinning golden to a box without operator payload) is an OPERATOR decision this entry\r\n  exists to put in front of them once, with numbers, instead of re-deriving the floor each cut.\r\n- **Ripe when:** operator rules on the bulk (move/expand/accept-the-tax), OR the first golden\r\n  that dies at the 32 GB preflight despite adopted pool discipline (IR-59's LNK1180-class red).\r\n- **Size:** zero code; one operator decision + at most a runbook line naming the chosen floor.\r\n\r","truncated":true,"truncatedBy":"lines","totalLines":3463,"totalBytes":15207,"outputLines":184,"outputBytes":15207,"lastLinePartial":false,"firstLineExceedsLimit":false},"totalLines":6938,"displayContent":{"text":"### IR-60 — a wrapper that CAPTURES a leg's exit status ends with the capture, so the wrapper's own status is the capture's, not the leg's\r\n\r\n- **Status:** OPEN, unowned — script-shape discipline, not a code lane. Filed by doyle 2026-08-22\r\n  during the TURNKEY #212 W5 lane; mechanism measured by todlando, who reported it first as a\r\n  possible harness misreport and then RETRACTED that reading himself on a minimal probe.\r\n- **v0.69.0 recurrence, 2026-09-11 (deployah, own withdrawal):** `NEXTEST_EXIT=0` and the task\r\n  completion's exit 0 both described the wrapper/truncation path, not Cargo's **101**.\r\n  `PIPESTATUS` was read outside the executing subshell, so the named verdict measured `tail`.\r\n  Both green-looking receipts were withdrawn; the raw failed-link output was retained.\r\n  **An exit FILE alone is insufficient if its writer captures the wrong process.** Capture\r\n  immediately inside the shell executing the producer, before any other command replaces the\r\n  status, write that value to the leg's file, and propagate it when wrapper status is reported.\r\n  The replacement battery's own file read 0, with 121 tests actually run. Keep this entry OPEN:\r\n  corrected execution of one driver does not make the faulty wrapper shape unreachable.\r\n- **The reading that started it:** a background leg was summarised as `exit code 0` while the leg's\r\n  own exit file read `100`. Reported as-is, that is a task runner lying about a red — the worst\r\n  possible direction for a purposeful-red claim, since it would turn two reds that DID fire into two\r\n  reds reported as not having fired.\r\n- **The measurement, minimal and on this box:**\r\n\r\n      ( exit 100 ); echo $? > probe.exit; FINAL=$?\r\n      leg status captured to file : 100\r\n      wrapper's own final status  : 0\r\n\r\n  The wrapper's shape is `( cd <lane> && cargo nextest ... > leg.raw 2>&1 ); echo $? > leg.exit`.\r\n  **The last command is the `echo`, which succeeds**, so the wrapper genuinely exits 0 while the leg\r\n  genuinely exited 100. THE RUNNER TOLD THE TRUTH ABOUT THE WRAPPER. There is nothing to file against\r\n  the task runner, and it would have been filed.\r\n- **The class, and this is why it is worth an entry rather than a fix:** it is the truncation-pipe\r\n  family — the meter measured something real, it just was not the thing about to be quoted. **Three\r\n  shapes now share ONE trigger, and the trigger is not \"is this a pipe\":**\r\n  1. a truncation pipe (`cmd | tail`, `cmd | head`) — `$?` measures the truncator, and `head` closing\r\n     the pipe can MANUFACTURE a status (SIGPIPE → 101), so `PIPESTATUS` is not protection either;\r\n  2. a flattened `$?` read after any intervening command;\r\n  3. **a wrapper whose last command is the capture itself.**\r\n  **The trigger in all three is the REPORTING** — every instance happened while trimming or capturing\r\n  output in order to QUOTE it as evidence.\r\n- **The practice that held, and the one to keep:** the leg's own file is the leg's verdict. Both reds\r\n  were real, and the only reason that was knowable is that every leg wrote its exit to its own file\r\n  rather than to the wrapper's status.\r\n- **Remedy, in preference order:** (1) never read a wrapper's status as a leg's — read the leg's exit\r\n  FILE, which the per-leg rule already requires; (2) if a wrapper's own status must be meaningful,\r\n  end it by re-raising the captured status (`exit \"$(cat leg.exit)\"`) or set the status before the\r\n  capture is the last word; (3) for anything that becomes evidence, redirect to a file and read the\r\n  file.\r\n- **Trigger condition:** ripe now — it rides the next gate-script touch, and the gate scripts in this\r\n  milestone already write per-leg exit files, which is what makes this discipline rather than debt.\r\n- **Size guess:** small — a convention line in the gate-script preamble; no product code.\r\n\r\n### IR-61 — spacerun's test-module skip carries a SECOND literal tracker; the two answers can drift, and today only a cell stands between them\r\n\r\n- **Status:** OPEN, unowned, accepted-with-mitigation. Filed by doyle 2026-08-22 at the TURNKEY #212\r\n  head gate, as the named residual of the latch repair (the repair itself rides the milestone).\r\n- **What the debt is.** `crates/xtask/src/spacerun.rs` now skips a column-0 `#[cfg(test)]` module by\r\n  BRACE DEPTH and resumes after its close, rather than latching the scan to end-of-file. Counting\r\n  braces safely means knowing when a brace is inside a string, a raw string or a char literal — and\r\n  the scanner ALREADY tracks literals for its rendering pass. It does not reuse that tracking. There\r\n  are now TWO answers in one file to \"am I inside a literal\", and **two answers to one question is a\r\n  disagreement waiting for a reader who fixes one of them.**\r\n- **Why it was accepted rather than refactored on the spot, stated so the trade is auditable:** the\r\n  two trackers answer genuinely different questions — the rendering walk is PER LINE and forward\r\n  from an opening quote (\"where does this literal start and end\"), while the skip needs \"am I inside\r\n  a literal right now\" carried CONTINUOUSLY across lines. Unifying them is a real refactor of a check\r\n  that is already gated, already carries five fixed defects, and sits on the tree being handed to\r\n  golden. The narrow change with an OBSERVABLE failure mode beat the correct-shaped change with a\r\n  wide blast radius, on that tree, on that day.\r\n- **The mitigation, and its exact limit.** Three brace cells fail the moment the two trackers\r\n  disagree about a raw string, a normal string or a char literal, plus a cell that reds when the skip\r\n  stops consulting a literal tracker at all (`match lit` -> `match Lit::None`). **That is a cell\r\n  standing in for a refactor.** It catches drift in the three forms it names and nothing else — a\r\n  fourth literal form, or a change to only one tracker in a form neither cell covers, passes.\r\n- **The general shape, which is why this is a register entry rather than a comment:** a check whose\r\n  own correctness depends on a second implementation of a thing it already implements is one\r\n  refactor away from the defect class it exists to prevent. This same file has already produced\r\n  three instrument defects (an indented-marker latch, a column-0 latch, and a suppression that\r\n  decided what got PARSED rather than what got REPORTED). The pattern is not carelessness; it is a\r\n  scanner accumulating special cases.\r\n- **Trigger condition:** the next SUBSTANTIVE change to spacerun's scanning — any new skip, any new\r\n  literal form, any change to either tracker. At that point unify, rather than adding a third answer.\r\n- **Size guess:** small to medium — one continuous literal-state walk serving both the render pass\r\n  and the skip, with the existing corpus and brace cells as the regression net.\r\n\r\n### IR-62 — an e2e daemon binds well-known ports and collides with the resident fleet on shared runners\r\n\r\nFiled 2026-08-23 (doyle), from the #212 r2 golden's Windows Phase A red — one witnessed\r\ninstance, mechanism verified from the run's own capture, filed on the mechanism per the\r\nregister's standard.\r\n\r\n**Mechanism.** `endpoint_autostart_e2e::saved_endpoint_replays_on_daemon_restart` failed its\r\nown PRECONDITION (\"daemon B must come up with a fresh brain\") because daemon B's broker came up\r\ndegraded: `NODE_KEY_FAIL: identity unavailable` (net-less broker, no retry) and\r\n`DOCS_SERVER_BIND_FAIL` port 5474 `os error 10048` — the docs port was held by a CO-RESIDENT\r\ndaemon. HFENDULEAM is live infra: the resident fleet's daemon legitimately holds well-known\r\nports, and any e2e that brings up a daemon with default port bindings is in a race with it BY\r\nCONSTRUCTION. An isolated SPT_HOME isolates the store and broker socket, NOT globally-numbered\r\nTCP ports.\r\n\r\n**Classification history.** r2: red (35.4s, precondition panic). Run 1 and r3 on the same box:\r\ngreen. Folded into r3 under a pre-registered predicate (reds twice → dedicated triage); it\r\ngreened, so this stays an environment-shaped intermittent, NOT a product defect and NOT\r\nclosed — the collision window is real and will re-fire under the right co-residence timing.\r\n\r\n**Remedy direction (not built).** Test daemons should bind ephemeral/rig-scoped ports for\r\nevery advisory surface (the docs server is advisory — a bind failure should degrade the rig\r\nloudly, not poison an unrelated cell's precondition), or the precondition should name the\r\nport-collision cause distinctly so the red self-classifies. Either lane is test/CI work\r\n(hertz's), triggered the next time this class fires anywhere.\r\n\r\n**Kin.** IR-51 (e2e daemon net-enabled on real interfaces — hermeticity is disk-deep only);\r\nthe known not-ours red classes list in the #212 hand-off.\r\n\r\n**BUILT 2026-08-24 (hertz, SIGNET #218 batch; PR #158).** The class fired its second witnessed\r\ninstance the same day — doyle's W2 gate rig, `engine_room_bringup_e2e` precondition panic with\r\nthe IR-50 panel naming `DOCS_SERVER_BIND_FAIL` port 5474 `os error 10048` — which armed this\r\nentry's own trigger. Hertz repro'd deterministically (held the port; brain still reached\r\nBRAIN_UP), pre-ranked three mechanisms before probing, and built the ephemeral-advisory form:\r\nrig-only `SPT_TEST_EPHEMERAL_ADVISORY_PORTS=1` makes the daemon's docs listener bind port 0\r\n(production config/`SPT_DOCS_PORT`/docs-url untouched; the flag matches the literal \"1\" only).\r\nThe golden workflow's test job sets it globally on both self-hosted legs, the standalone ER rig\r\nsets it too. Scope note kept honest per his own ranking: the docs collision is retired; if a\r\nco-diagnostic bind elsewhere still poisons a precondition, that is a residual face of THIS\r\nentry, not a closed question.\r\n\r\n### IR-63 — suite-mix sweeps leak job-escaped autostart daemons that LOCK the pool's spt.exe; and the same box conditions manufacture one random victim per sweep\r\n\r\n- **Status:** OPEN, mitigated-by-rig-step — the reap is adopted discipline, not yet construction.\r\n  Filed by doyle 2026-08-24 at the SIGNET #218 gates; first measured by todlando the same day\r\n  (his W1 build: four reap rounds of 2, 8, 1, 1 processes, count-by-path stated each round).\r\n- **Mechanism, two faces of one condition:** (1) e2e sweeps that exercise autostart leave\r\n  job-escaped daemons running `target/debug/spt.exe`; the NEXT build or `xtask check` then dies\r\n  on `os error 5` removing the exe — a rig red wearing a build defect's clothes. nextest's own\r\n  `leaky` flags corroborate (4–8 per sweep measured). (2) The same co-residence (leaked daemons +\r\n  resident fleet + runner traffic) manufactures ONE red per full sweep with a DIFFERENT victim\r\n  each time: doyle's W2 gate measured FOUR distinct one-off victims in four same-sha sweeps\r\n  (ER bringup, composite+bootstrap pair under CI load, resident_service, brain_resume), every\r\n  one green alone and/or in a sibling sweep. The e2e-leaked-daemons rule holds: a different test\r\n  dying each run on one sha is ONE environment cause, and hardening members never closes it.\r\n- **Mitigation adopted (rig step, both todlando's lanes and doyle's gate runner):** reap\r\n  `spt.exe` BY PATH (`*spt-core\\target*`) before EVERY cargo invocation and after every sweep;\r\n  report the count each time so a zero is a claim, not silence.\r\n- **Remedy direction (unbuilt):** the durable form is construction, not discipline — either\r\n  nextest wrap/xtask verb that performs the by-path reap as a pre-step on this box's rigs, or\r\n  autostart e2es gain teardown that provably outlives job escape (kin IR-38's built wedge-namer,\r\n  IR-62's ephemeral ports which retire one collision axis, IR-35's victim-rate ledger).\r\n- **THIRD FACE, measured 2026-08-30 (doyle, ir57/asm-241 reaps):** the leaked population is not\r\n  only daemons — battery legs leave ORPHANED HEADLESS `conhost.exe` processes whose CWD sits in\r\n  the worktree's `crates/spt-daemon` (where the leg ran), and a CWD pin blocks `Remove-Item`/\r\n  `git worktree remove` on the whole tree with \"being used by another process\" naming the DIR.\r\n  This is the mechanism behind every recent \"handle-pinned, retry later\" worktree removal: 31\r\n  such conhosts found at once (Aug 26–29 vintages) pinning FIVE dead worktrees. cargo/rustc\r\n  absence does NOT clear the suspect list — the conhost outlives its client. Holder census\r\n  tool: a ~30-line NtQueryInformationProcess CWD probe (PEB→ProcessParameters→CurrentDirectory)\r\n  over all pids, filtered on the path — names every holder in one pass where no handle.exe\r\n  exists. 13 killed scoped to the two consented reaps; 18 remain pinning gate-w1-a8f04aff (12),\r\n  io-parser-w1 (5), gate-w1-786d2381 (1 after kills) — sweep them at the IR-14/26/27/49 audit\r\n  slot before those removals.\r\n- **LANE-LINKED 2026-08-30 (#242 close sweep):** hertz's queued daemon-leak fixup lane carries\r\n  this entry (brief cites IR-7/17/20/34/35/63); leaves the register when that lane lands.\r\n- **Trigger condition:** next rig/gate-script construction touch, or the first golden red that\r\n  classifies to face (1).\r\n- **Size guess:** small-medium — one wrapper seam plus adopting it in the gate/lane scripts.\r\n\r\n### IR-64 — HFENDULEAM's disk floor is set by non-CI bulk: ~845 GB of operator payload leaves the golden box ~2 GB of slack against its own 32 GB preflight\r\n\r\n- **Status:** OPEN · **Origin:** doyle, v0.63.0 close sweep 2026-08-26; mechanism first measured\r\n  at the FIELD-SEAL golden window (deployah's IR-31 fifth addendum carries the POOL side of the\r\n  same event by agreed division — this entry is the OTHER reservoir, deliberately not his).\r\n- **Mechanism:** the 1.86 TB C: carries ~614 GB Steam + ~230 GB Downloads (operator payload, not\r\n  CI state). With that floor fixed, normal lane traffic alone walks the box under the 32 GB\r\n  golden preflight — a full-sweep pool WEIGHS ~90–112 GB steady state (IR-59's measurement) and\r\n  five FIELD-SEAL lanes cost 148.48 GB (IR-31 fifth addendum), so ONE milestone's pools exceed\r\n  the entire free margin. Reaping buys windows, not headroom: deployah measured free fall\r\n  167 → 108 GB within hours of his reap, ~59 GB re-consumed by lane builds. The recurring shape:\r\n  every milestone pays a reap-and-measure tax to rent space the box does not structurally have.\r\n- **Why register-worthy rather than \"clean up more\":** agent-side discipline (IR-31's budgeting,\r\n  pool reaps, teardown steps) is already adopted and still only rents windows — the reservoir\r\n  that would durably move the floor is operator-owned bulk no agent may touch. Naming it here is\r\n  the boundary: agents keep budgeting IN POOLS (not GB); moving Steam/Downloads (or adding a\r\n  disk, or pinning golden to a box without operator payload) is an OPERATOR decision this entry\r\n  exists to put in front of them once, with numbers, instead of re-deriving the floor each cut.\r\n- **Ripe when:** operator rules on the bulk (move/expand/accept-the-tax), OR the first golden\r\n  that dies at the 32 GB preflight despite adopted pool discipline (IR-59's LNK1180-class red).\r\n- **Size:** zero code; one operator decision + at most a runbook line naming the chosen floor.\r\n\r","startLine":3476,"lineNumbers":[3476,3477,3478,3479,3480,3481,3482,3483,3484,3485,3486,3487,3488,3489,3490,3491,3492,3493,3494,3495,3496,3497,3498,3499,3500,3501,3502,3503,3504,3505,3506,3507,3508,3509,3510,3511,3512,3513,3514,3515,3516,3517,3518,3519,3520,3521,3522,3523,3524,3525,3526,3527,3528,3529,3530,3531,3532,3533,3534,3535,3536,3537,3538,3539,3540,3541,3542,3543,3544,3545,3546,3547,3548,3549,3550,3551,3552,3553,3554,3555,3556,3557,3558,3559,3560,3561,3562,3563,3564,3565,3566,3567,3568,3569,3570,3571,3572,3573,3574,3575,3576,3577,3578,3579,3580,3581,3582,3583,3584,3585,3586,3587,3588,3589,3590,3591,3592,3593,3594,3595,3596,3597,3598,3599,3600,3601,3602,3603,3604,3605,3606,3607,3608,3609,3610,3611,3612,3613,3614,3615,3616,3617,3618,3619,3620,3621,3622,3623,3624,3625,3626,3627,3628,3629,3630,3631,3632,3633,3634,3635,3636,3637,3638,3639,3640,3641,3642,3643,3644,3645,3646,3647,3648,3649,3650,3651,3652,3653,3654,3655,3656,3657,3658,3659]},"fileSize":676479,"meta":{"source":{"type":"path","value":"C:\\Users\\decid\\Documents\\projects\\spt-core\\.worktrees\\hertz-ir86-disk-delta\\docs\\INFRA-REGISTER.md"},"truncation":{"direction":"head","truncatedBy":"lines","totalLines":6938,"totalBytes":15207,"outputLines":184,"outputBytes":15207,"shownRange":{"start":3476,"end":3659},"nextOffset":3660}}},"isError":false,"timestamp":1789483686438}}
{"type":"message","id":"3c4bdf91","parentId":"5cc6e960","timestamp":"2026-09-15T14:48:06.442Z","message":{"role":"toolResult","toolCallId":"call_kwkxiFHoqe9dHGuCQzBwcboo|fc_043a862a419f59ae016aa95aa6523487d2ab1c79159aba61d4","toolName":"read","content":[{"type":"text","text":"### IR-56 — `pool-claim` harvests lane identity from CWD, not from `--pool`; a claim run from the wrong tree writes a WRONG RECORD with a success message\n\n- **Status:** BUILT 2026-08-24 for the SIGNET #218 golden batch on\n  `fix/ir56-pool-claim-cwd`, owned by **hertz**. Tooling/rig defect by the dispatch split. Filed by\n  doyle 2026-08-22 from todlando's TURNKEY #212 W4 Lane 1 field instance — the first confirmation\n  of the IR-42 mechanism from a LANE rather than from a source read.\n- **What happens:** `cargo run -p xtask -- pool-claim --pool <dir> --label <lane>` records the lane\n  identity it harvests from the **current working directory** — `owner_tree`, `lane_branch`, and the\n  base sha — not from the tree `--pool` names. Run it from the project root with `--pool` aimed at a\n  worktree and the record reads `owner_tree = <project root>, lane_branch = <root's branch>` while\n  every artifact in that pool belongs to the worktree. The verb prints its ordinary success line\n  naming the wrong owner, and returns 0.\n- **Why it is silent, which is the whole entry:** the claim verb WRITES and never adjudicates\n  (IR-42) — every enforcement arm lives in `crates/spt-store/build.rs` and speaks only at the next\n  BUILD. So a wrong record has no symptom at the moment it is created; the first signal is a build\n  refusal minutes later, on a lane whose `--pool` argument was correct all along. **`--pool` being\n  correct is not evidence the record is.** Nothing on the command line shows you cwd, which is the\n  one input that decided the outcome.\n- **Recovery is the documented hatch, and the bootstrap is why:** the claim tool builds THROUGH the\n  pool it is claiming, so a pool already refusing cannot be re-claimed by the ordinary route. The\n  refusal text says so itself — meaning the bootstrap case is known, and a wrong-cwd claim is the\n  ordinary way a lane lands in it.\n- **The rule, as a must-do:** claim from the lane's own worktree so the identity the verb harvests\n  is the lane's — `( cd <lane> && cargo run -p xtask -- pool-claim --pool \"$PWD/target\" … )`, or any\n  form that makes cwd explicit. Then READ THE PRINTED RECORD BACK and confirm `owner_tree` and\n  `branch` name the lane: the success line carries the record, so the check costs nothing.\n- **Trigger condition:** ripe now — it is a doc/UX fix on a verb we run every lane. Ripest alongside\n  any other `xtask` pool-verb touch.\n- **Size guess:** small. Either make the verb REFUSE when cwd is not inside the tree containing\n  `--pool` (loud, and it cannot be wrong), or print the harvested identity as a distinct confirmed\n  line. The refusing form is preferred: it removes the reading step rather than adding one.\n- **Built evidence, corrected at review:** `pool-claim` resolves the git worktree containing\n  `--pool` from the pool's nearest existing ancestor and compares it with the cwd worktree before\n  writing. An accidental cross-worktree call returns 2, names both worktrees and the remedy, and\n  leaves the not-yet-existing pool absent. The sanctioned sequential takeover carries an explicit\n  `--foreign-pool`, says that it is harvesting the arriving cwd identity, writes that identity, and\n  returns 0. Both poolguard refusal remedies now print that flag. An executable xtask test drives\n  both arms against two real temporary git repositories, pinning VERB-ADMITS-REMEDY rather than\n  merely testing path equality. This remains identity-harvest validation only: the claim still\n  writes without adjudicating admission, so IR-42's enforcement boundary remains in the build.\n\n- **Second instance 2026-09-11 (todlando, #304 product lane):** an allocation packet carried the\n  claim as `pool-claim --pool .worktrees/304-product/target` — correct from the repo root, WRONG\n  from inside the worktree, where it resolves to a nested `.worktrees/...` path. Caught within\n  seconds of launch, nothing written at the nested path, re-run with the absolute lane path. Rule:\n  an allocation names the pool by ABSOLUTE path, because the claim verb acts on where it stands.\n\n### IR-57 — an assembly pick's conflict resolution can silently DROP lines, and every gate run at assembly time is blind to it\n\n- **Status:** OPEN, owned by **doyle** (gater craft, not a code defect — no lane to dispatch).\n  Filed 2026-08-22 from doyle's own defect on the TURNKEY #212 assembly head.\n- **What happened:** assembly head `5cce533d` **did not compile**, and was carried across a session\n  boundary as a ready head with \"treqs exit 0\" attached to it. `crates/spt-store/src/access.rs` had\n  an unclosed `mod tests`: the cherry-pick of the #206 lane commit `b2194aa9` conflicted against the\n  #209 test block — both add functions to the same region, and the two sides share the trailing\n  `);` / `}` / `}` — and the resolution deleted the markers without restoring the FIRST side's\n  function closer. Exactly two lines lost: `        );` and `    }`.\n- **Every instrument in the assembly path reported success:** `git cherry-pick` completed with no\n  conflict remaining; `traceable-reqs check` returned 797/797, 0 findings, exit 0 — **it parses\n  tags and never invokes the compiler**; and the lanes themselves were green and stayed provably\n  clean (the #206 lane's brace balance is correct at all five of its commits). **Lane-green plus\n  conflict-free is not a claim about the assembled head.** Same lesson as the #182 v2 assembly\n  (`E0425`×4) by a different mechanism: that one was a semantic composition break between two\n  correct hunks, this one is a fidelity LOSS during resolution.\n- **Two must-dos, both cheap:**\n  1. **Compile the assembled head before it is handed anywhere — including forward to your own next\n     session.** A head is not ready on a treqs exit; it is ready on a build. Any sentence carrying a\n     head sha to another agent must name the instrument that proved it.\n  2. **Audit pick fidelity on CHANGED LINES for every pick on the chain**, not just the one that\n     tripped you: hash `git show --format= <sha> | grep -E '^[+-]' | grep -vE '^(\\+\\+\\+|---)'` for\n     the lane source and for the pick, and compare. Whole-diff comparison is useless here — hunk\n     headers and context legitimately drift once the head's copy of the file has moved.\n- **Read COUNT and HASH together, because they fail in opposite directions.** Of 24 picks on this\n  chain two did not match. `b2194aa9 → 4d6deed1` differed in COUNT (302 lane / 300 pick by the header-excluding pipeline above; **this entry originally cited 310/308, which is the RAW `^[+-]` count INCLUDING the 8 `+++`/`---` header lines of its 4 files** — the figures were taken without the second grep the entry itself prescribes. The DELTA is 2 under either meter, which is why the wrong figures never surfaced: they supported a correct conclusion, so nothing pressed them. Corrected todlando 2026-08-29, measured both ways in-tree) — the real\n  defect. `f27f15c6 → 5865cc98` had the SAME count and a different HASH — benign: a `CONTEXT.md`\n  paragraph the head had already amended for #209, whose merged result correctly carries both lanes'\n  sentences. A count check MISSES the first class entirely; a hash check FLAGS the second as if it\n  were a defect. Neither alone classifies a pick.\n- **Repair shape used, recorded because it is the cheap one:** reset to the commit before the bad\n  pick, re-pick the lane source, resolve the same conflict correctly, then replay the remaining picks\n  in chain order with the fidelity check on each. Verify the repair changed nothing else with a\n  WHOLE-TREE diff against the old head — it must show exactly the restored lines and no other file.\n  Where a later pick re-conflicts, check its pre-pick blobs against the old chain\n  (`git rev-parse <old-pick>~1:<file>`); if they match, the old chain's post-pick blob is a\n  transferable, already-reviewed resolution.\n- **AND GATE THE REPAIR'S OWN SUBJECT.** The rebuilt head passed six legs — clippy `-D warnings`,\n  sweep 660/660, treqs 803/803, xtask OK — while the restored lines live in `spt-store`, whose LIB\n  tests `-p spt --bins` never runs. Six greens, and not one executed the function the repair\n  restored; it was proven to COMPILE and assumed to PASS. Proven afterwards by name (4/4) and by the\n  full `spt-store --lib` suite (519/519). **A repair's gate must include the suite that owns the\n  repaired file**, which is not necessarily the suite the head gate runs.\n- **FIRST LIVE CATCH, and it was the author's own resolution (2026-08-29, one hour after the verb landed):** rebasing the IR-59 rider over the IR-57 rider produced four conflicts — three additive keep-both, one usage line both sides had edited. `xtask pick-audit` read the rebase as **LOSS, 282 lane / 280 pick**. The two missing lines were a `[[requirements]]` header and its blank line in `traceable-reqs.toml`, so `id = REQ-DISK-FLOOR-PREFLIGHT` landed INSIDE the previous table as a duplicate key: **`traceable-reqs check` exit 2, the registry unparseable, every reading after that edit checking nothing**. Restored, the same audit reads **DRIFT 282/282** whose one differing line is the usage string whose base copy legitimately gained the other verb — both verdict classes, on one resolution, in the order the entry predicts. The instrument's first real save was from the hazard it was filed for, against the agent who built it.\n- **FIRST REAL-ASSEMBLY USE (2026-08-29, #241 emission head, ASM-241-GATE-VERDICT.md):** `xtask\n  pick-audit --range 57a0d27c..HEAD --lane 4d6007ac..d0fdd58d` over 6 picks — **5 MATCH\n  (digest-identical), 1 LOSS, 0 drift, 0 unclassified**, exit 1 forcing the accounting. The LOSS\n  was exactly the one human-resolved conflict (`cfb9d9f8 <- 10f12e4c`, count 432/402), and the\n  delta RECONCILED to the resolution rather than assumed: lane stat 15 files/235+/197- vs pick\n  14 files/205+/197-, difference byte-for-byte the deliberately-dropped 30-line interim IR-69\n  register block superseded by main's consolidated entry. No false positives, no silent pass.\n  Entry stays OPEN as living procedure; both live uses (the rebase catch above, this assembly)\n  produced the verdict classes in the order the entry predicts.\n- **Trigger condition:** ripe at the next assembly — this is procedure, and its cost is one command\n  per pick.\n- **Size guess:** small as a scripted check in `xtask` (fidelity audit over a pick range); zero as\n  discipline, which is how it is being applied now.\n\n### IR-58 — a `[[bin]]` grep is not a census: cargo AUTODISCOVERS `src/bin/*.rs` targets, and a hand-built bin list produced a confident false \"this bin does not exist\"\n\n- **Status:** OPEN, unowned. Filed by doyle 2026-08-22; **its original filing was WRONG and is\n  retracted in full below.** The entry is kept because the way it was wrong is the finding.\n- **RETRACTED CLAIM, stated plainly so no reader acts on it:** this entry first said that\n  `crates/spt/Cargo.toml:18-21` and `crates/spt/src/cli.rs:30355` forbid a bin-name collision with\n  `xlate_choreo_fixture`, \"a bin that does not exist\", and that spt-daemon's third helper had been\n  renamed to `summarizer_fixture`. **`xlate_choreo_fixture` EXISTS** — at\n  `crates/spt-daemon/src/bin/xlate_choreo_fixture.rs`, verified at the assembly head. The collision\n  rule's counterpart is real, both prose sites are CORRECT, and IR-21's original table row was\n  correct too; it merely predated `summarizer_fixture`. Nothing in that prose needs fixing.\n- **How the false claim was produced, which is the entry:** the census was built by grepping\n  `^\\[\\[bin\\]\\]` across `Cargo.toml`s. **Cargo AUTODISCOVERS `src/bin/*.rs` as bin targets with no\n  stanza at all**, so a stanza grep cannot see them, and it fails SILENTLY — it returns a clean,\n  well-formed list that is simply short. From that list it read as established fact that a named bin\n  had been renamed away, and that \"fact\" was then written into a register table, an IR entry, and a\n  message to the builder. **A pattern-built population encodes the pattern's assumption; the count\n  looks like a census and is a property of the pattern.**\n  (Found by todlando, resolving one of doyle's figures against his own tree under the pointer rule.)\n- **A CENSUS IS ALSO A PROPERTY OF A TREE.** Stanza counts differed legitimately across trees the\n  same hour — 13 at the assembly head, 11 at `dc1c7532` — because `summarizer_fixture` exists at one\n  and not the other. Two correct censuses of the same workspace disagree unless each names its sha.\n- **The must-do, and it removes the list rather than lengthening it:** never hand-maintain a bin\n  roster. Run `cargo build --workspace --bins` and let cargo enumerate its own targets — the same\n  enumeration the test harness resolves against, so it cannot drift from what a fixture lookup\n  expects. Stanza-derived lists, remembered pairs, and register tables are all the roster problem at\n  different depths; only cargo's own enumeration is the population.\n- **Kin:** IR-55's amended prebuild bullet (prebuild the census, not a remembered pair) and IR-42\n  (a verb that writes without adjudicating). The shared shape is an instrument returning an orderly\n  answer about a set it never fully saw.\n- **Trigger condition:** ripe on any `xtask` check work — a duplicate-bin-name check over cargo's\n  target enumeration (NOT over manifest stanzas) is a handful of lines and cannot go stale.\n- **Size guess:** small. The prose fix originally proposed here is WITHDRAWN — there was nothing\n  wrong with the prose.\n\n### IR-59 — pool arithmetic: this box holds TWO cold pools, not four; and a build that exhausts the volume reds as a LINKER defect that names no disk\n\n- **Status:** OPEN, unowned — it is arithmetic and discipline, not a code lane. Filed by doyle\n  2026-08-22 from a live disk-floor abort during the TURNKEY #212 W4 gate; footprint figures measured\n  by todlando the same hour.\n- **v0.69.0 release close, 2026-09-11 (deployah, source record releases#294 comment\n  5628538587):** the first broad version/manifest battery failed to LINK (`LNK1180`,\n  `LNK1108`, cargo exit 101), with **15,777,792 bytes free** measured at recovery. It produced\n  no test verdict. The run selected the workspace's test binaries on the Cargo side even\n  though the nextest filter did not need the e2e population; the replacement selected `--lib`\n  for `spt-daemon`, `spt-runtime`, `spt`, and `xtask`, and passed **121/121** in 8.445 s.\n  Root-target reclamation restored **66,926,968,832 bytes free**; the subsequent CI Windows\n  unit step passed **3167 tests**, then its END floor refused at **15,360,114,688 bytes**\n  against **34,359,738,368**. That is an observed resource-red AFTER passing tests, not an\n  explanation of the earlier PR unit-step red whose log was unavailable. A second, classified\n  CI `target/debug` reap, with runner intake stopped by the operator, increased free bytes\n  **14,892,281,856 -> 78,994,501,632**. Runner service restored afterward. Publication used a\n  preserved signer, not a Cargo rebuild into the cleared pool. These are two measured recoveries,\n  not a durable capacity fix; IR-46/59/86 remain the next gate-driver capacity rider.\n- **SECOND FACE, measured 2026-08-23/24 (WAX-SEAL #21 W2 gate, doyle — the violator this time):**\n  both predicted mechanisms fired at once, WITHOUT the floor guard because the gate legs ran as a\n  plain script. (1) doyle minted a THIRD cold pool (gate rig) while todlando's lane pool was LIVE —\n  the two-pool arithmetic, violated by the gater. (2) The lane pool had silently accumulated\n  **104.8 GB** over repeated full-workspace sweeps (nothing bounds or even measures a pool's\n  accumulation until the volume dies). The volume hit **3 MB free**; the reds wore exactly the\n  entry's predicted costume — `LNK1318: Unexpected PDB error; LIMIT (12)` naming no disk — plus a\n  second face worth keeping: `traceable-reqs check` died as a PANIC printing to stdout\n  (`os error 112`), so a REGISTRY gate red can also be the disk's. Both gate verdicts VOIDED\n  (clippy's full compile had exited 0 before space died — the code was never the question).\n  Recovery measured: gate pool reap 9.6 GB, lane pool clean 100.2 GB, drive back to 109.6 GB free.\n  **Remedies adopted at the incident:** the gate never mints its own pool while a builder lane is\n  live on the box — it takes the lane pool over SEQUENTIALLY at pool-release (warm, loud, the\n  releases#103 pattern); and gate/lane scripts get the disk-floor preflight the golden runner\n  already carries (this entry's part 2, still unbuilt).\n- **THIRD FACE, measured 2026-08-24 (WAX-SEAL #21 golden window, doyle):** two new mechanisms, both\n  about the REMEDY rather than the red. (1) The wax-seal-w1 lane pool **re-accumulated to 152–169 GB\n  (two meters, IR-46 caveat) within ONE DAY of the 08-23 clean** and rode the volume back down to\n  4.92 GB free — a reap is an instant, not a state; nothing yet bounds a pool between reaps.\n  (2) **The remedy itself arrived garbled through relay:** the golden push was held \"waiting on the\n  IR-59 reboot\" when this entry prescribes no reboot anywhere — tens of releases have shipped without\n  one; the operator refused the premise and the register's own recorded remedy (reap finished-lane\n  pools) cleared it in ten minutes. A remedy relayed as a DIFFERENT remedy is the relay trap wearing\n  infra clothes: the entry is the author — read it before adopting a hold. Recovery measured: five\n  finished-lane pools reaped after ancestry classification (`git cherry` catches rebased lands that\n  a plain `merge-base --is-ancestor` calls unlanded — gate-w4l1's 90.9 GB pool was reapable only by\n  that meter), 4.92 → 260.88 GB free (~256 GB free-delta vs ~270–287 GB sum-of-lengths). Two main\n  runs red inside the low-disk window (09:17Z/09:41Z) were re-run, not re-read, per this entry's\n  must-do.\n- **FOURTH FACE, measured 2026-08-24 same day (SIGNET #218 W2 gate, doyle — the gater's own pool\n  this time):** the MAIN pool went **13.7 GB → 158.3 GB in ONE DAY** absorbing four full gate\n  batteries across two lane tips, and dragged the volume to **18 GB free mid-gate** — so the\n  entry's mechanism is not a lane-pool problem, it is EVERY pool under repeated full sweeps, the\n  gate rig included. Two riders worth the ink: (1) the golden runner's **free-space floor step\n  produced its first live catch** — a thin CI leg refused at 14:14 local over exactly this window\n  with zero test signal, and the register's re-run-not-re-read rule resolved it in one command;\n  (2) the reap-and-rebuild trade (\"cleaning a live pool buys one window at rebuild price\") was\n  taken deliberately mid-gate and cost ~35 minutes cold — cheaper than one uninterpretable red.\n  A red measured at 18 GB free in this gate got NO read at all, and the next sweep's red was a\n  DIFFERENT test: low disk manufactures random victims before it manufactures link errors.\n- **The event:** a gate's preflight refused with `GATE_ABORTED_DISK_FLOOR` at **4.75 GB free on a\n  1863 GB volume**. Four cold pools plus the milestone head's pool were standing at once. The floor\n  guard did its job — without it a full workspace build would have started with under 5 GB of\n  headroom and produced a red belonging to nothing.\n- **THE ARITHMETIC, and it corrects the intuition that worktrees are the cost.** Measured across the\n  whole `.worktrees` tree: **45 worktrees = 0.79 GB total** (~18 MB each). **3 pools = 130.45 GB.**\n  Worktrees are **0.6%** of the footprint; pools are **99.4%**. **One cold pool is worth roughly 2,500\n  worktrees.** A rule keyed on worktree count would cost a day of `git worktree remove` work for under\n  a gigabyte, risk removing a lane someone still wants, and leave the lever untouched.\n- **THE CEILING, as arithmetic rather than hygiene:** at **45–75 GB per cold pool** on this workspace\n  against a **40 GB floor**, this box supports **TWO live pools comfortably, THREE only if one is\n  small**. The two rules that already exist need no replacement, only this number attached:\n  - **Reap a pool when its lane is finished** → 45–75 GB back immediately.\n  - **Do not run two builds at once** → not only the contention argument, but **75–150 GB of\n    simultaneous allocation** against that floor.\n- **A FULL VOLUME REDS AS A LINKER DEFECT.** `LINK: fatal error LNK1318: Unexpected PDB error`\n  (variously `OK (0)` or `LIMIT (12)`), often beside `LNK4209: debugging information corrupt`. It\n  reads as a corrupt artifact or a broken toolchain and is neither — it is the linker unable to grow\n  a large `.pdb`. **Nothing in the failure text says \"disk\".** Do not key recognition on the\n  parenthesised code; it varies.\n- **THE DANGER WINDOW IS THE TAIL OF A COLD BUILD, not a steady state you can check once.** The\n  2026-08-22 instance died at the link of `spt` — the last and largest artifact of a **74 GB** cold\n  pool — while that same build was draining the volume out from under itself. A free-space reading\n  taken before the build would have looked fine.\n- **Positive tell, with its own refutation attached:** `traceable-reqs check` alone surviving a leg\n  table is suggestive, because it is the only leg that never links. It is a POSITIVE tell ONLY — a\n  full disk can red before any link step, so the signature's ABSENCE clears nothing.\n- **THE FALSIFIER IS FREE SPACE AT THE TIME OF THE RUN**, not the shape of the leg table.\n- **Must-do, both cheap:**\n  1. **A free-space reading goes in the FIRST LINE of any build-failure report** — not in the\n     controls, not as a follow-up. Two agents spent hours on a mechanism for this failure and neither\n     ran `df`; the falsifier was one command away throughout.\n  2. **Rig and gate logs should record free space at run start.** Today they do not, which makes \"was\n     the disk full\" **unanswerable after the fact for every red already in hand**. Any red produced\n     under ~1 GB free is UNINTERPRETABLE and must be **re-run, not re-read**.\n- **Measurement caveat, observed twice in one hour:** sum-of-file-lengths and free-space delta\n  disagree by several percent when anything else on the box is writing (98.07 GB of subtrees → 92.25\n  GB reclaimed; 47.28 GB → 40.81 GB). Report BOTH, derive neither from the other, and treat any single\n  free-space number as an instant rather than headroom — see IR-46.\n- **FIFTH FACE, measured 2026-08-29 at the CONDUIT #236/v0.65.0 cut (deployah):**\n  the finished milestone's sequential lane-sharing accumulated **140.51 GB**, while a freshly\n  rebuilt pool measured **7.78 GB** — about **18× one build's working set** retained across lane\n  hand-offs with no reap between them. This is the budgetable rate behind that cut's disk-floor\n  red: sequential execution prevents concurrent ownership corruption, but it does not bound\n  historical artifacts inside the shared pool. Treat takeover and reclamation as separate\n  operations; a pool may be safe to reuse and still be too large to keep.\n- **SEVENTH FACE, measured 2026-08-30 (v0.67.0 milestone close — the PARALLEL-LANE fill\n  rate):** the #23 wave arc drove C: from ~240 GB free to **0.01 GB in ~3.5 hours**: four\n  concurrent/serial lane+gate pools totalled **236.6 GB** (ns23-w1 87.7 + ns23-113 72.3 +\n  gate rig 57.3 + ns23-w3 19.1) — effectively the entire ir57 reclaim re-consumed inside one\n  milestone's build window. The head gate and two thin-CI runs redded with the entry's exact\n  costume (\"could not compile\" + treqs panic, zero disk words) at 0.01 GB and all re-earned\n  green after reclaim (+186.6 GB, finished-lane targets only, single-actor rule held under\n  racing consent). Budget rule this face adds: a MULTI-WAVE milestone on one box books\n  ~60-90 GB PER LANE-PLUS-GATE cycle, so the pool budget is per-wave, not per-milestone —\n  reap each wave's pool at its LAND, not at the milestone party (the party inherited only\n  ~58 GB because the emergency had already forced the other ~179).\n- **SIXTH FACE, measured 2026-08-30 (#242 golden r4, Windows test job, LNK1318 at the PDB\n  write):** the floor is asserted ONCE at job START, but the job's internal LOW-WATER sits at its\n  LAST heavy step — the docs-drift build, ~28 minutes in. r4's floor read 65.1 GiB honest at\n  23:07; the box was at ~37–39 GB by the 23:35 link failure. LNK1318 on PDB write = this entry's\n  documented low-disk costume; the incremental-corruption candidate was retired by preservation\n  snapshot (no xtask state existed at failure). **Durable fix = a floor RE-READ (or reclaim)\n  immediately before the docs-drift build** — the WITHIN-job sibling of the across-job\n  read-after-checkout fix, rides the next workflow commit. Riders: incremental hygiene as\n  disk-pressure maintenance (the dir measured 4.56 GB), and the box's **~51 GB non-recovering\n  post-run consumption** is this entry's pool-weight face — classify at the IR-14/26/27/49 audit\n  slot (composed this sweep).\n- **Composed for next intake (doyle, v0.65.0 close):** the still-open log-the-floor build half\n  rides with [[IR-57]]'s scripted pick-fidelity audit as the next milestone's two tooling riders.\n- **Trigger condition:** ripe now for the log-the-floor half (it rides any gate-script or CI touch);\n  the arithmetic is discipline and applies immediately.\n- **Size guess:** small — one line in each rig/gate preflight to record free space alongside the\n  existing floor check.\n\n\n[Showing lines 3201-3475 of 6938. Use :3476 to continue]"}],"details":{"truncation":{"content":"### IR-56 — `pool-claim` harvests lane identity from CWD, not from `--pool`; a claim run from the wrong tree writes a WRONG RECORD with a success message\r\n\r\n- **Status:** BUILT 2026-08-24 for the SIGNET #218 golden batch on\r\n  `fix/ir56-pool-claim-cwd`, owned by **hertz**. Tooling/rig defect by the dispatch split. Filed by\r\n  doyle 2026-08-22 from todlando's TURNKEY #212 W4 Lane 1 field instance — the first confirmation\r\n  of the IR-42 mechanism from a LANE rather than from a source read.\r\n- **What happens:** `cargo run -p xtask -- pool-claim --pool <dir> --label <lane>` records the lane\r\n  identity it harvests from the **current working directory** — `owner_tree`, `lane_branch`, and the\r\n  base sha — not from the tree `--pool` names. Run it from the project root with `--pool` aimed at a\r\n  worktree and the record reads `owner_tree = <project root>, lane_branch = <root's branch>` while\r\n  every artifact in that pool belongs to the worktree. The verb prints its ordinary success line\r\n  naming the wrong owner, and returns 0.\r\n- **Why it is silent, which is the whole entry:** the claim verb WRITES and never adjudicates\r\n  (IR-42) — every enforcement arm lives in `crates/spt-store/build.rs` and speaks only at the next\r\n  BUILD. So a wrong record has no symptom at the moment it is created; the first signal is a build\r\n  refusal minutes later, on a lane whose `--pool` argument was correct all along. **`--pool` being\r\n  correct is not evidence the record is.** Nothing on the command line shows you cwd, which is the\r\n  one input that decided the outcome.\r\n- **Recovery is the documented hatch, and the bootstrap is why:** the claim tool builds THROUGH the\r\n  pool it is claiming, so a pool already refusing cannot be re-claimed by the ordinary route. The\r\n  refusal text says so itself — meaning the bootstrap case is known, and a wrong-cwd claim is the\r\n  ordinary way a lane lands in it.\r\n- **The rule, as a must-do:** claim from the lane's own worktree so the identity the verb harvests\r\n  is the lane's — `( cd <lane> && cargo run -p xtask -- pool-claim --pool \"$PWD/target\" … )`, or any\r\n  form that makes cwd explicit. Then READ THE PRINTED RECORD BACK and confirm `owner_tree` and\r\n  `branch` name the lane: the success line carries the record, so the check costs nothing.\r\n- **Trigger condition:** ripe now — it is a doc/UX fix on a verb we run every lane. Ripest alongside\r\n  any other `xtask` pool-verb touch.\r\n- **Size guess:** small. Either make the verb REFUSE when cwd is not inside the tree containing\r\n  `--pool` (loud, and it cannot be wrong), or print the harvested identity as a distinct confirmed\r\n  line. The refusing form is preferred: it removes the reading step rather than adding one.\r\n- **Built evidence, corrected at review:** `pool-claim` resolves the git worktree containing\r\n  `--pool` from the pool's nearest existing ancestor and compares it with the cwd worktree before\r\n  writing. An accidental cross-worktree call returns 2, names both worktrees and the remedy, and\r\n  leaves the not-yet-existing pool absent. The sanctioned sequential takeover carries an explicit\r\n  `--foreign-pool`, says that it is harvesting the arriving cwd identity, writes that identity, and\r\n  returns 0. Both poolguard refusal remedies now print that flag. An executable xtask test drives\r\n  both arms against two real temporary git repositories, pinning VERB-ADMITS-REMEDY rather than\r\n  merely testing path equality. This remains identity-harvest validation only: the claim still\r\n  writes without adjudicating admission, so IR-42's enforcement boundary remains in the build.\r\n\r\n- **Second instance 2026-09-11 (todlando, #304 product lane):** an allocation packet carried the\r\n  claim as `pool-claim --pool .worktrees/304-product/target` — correct from the repo root, WRONG\r\n  from inside the worktree, where it resolves to a nested `.worktrees/...` path. Caught within\r\n  seconds of launch, nothing written at the nested path, re-run with the absolute lane path. Rule:\r\n  an allocation names the pool by ABSOLUTE path, because the claim verb acts on where it stands.\r\n\r\n### IR-57 — an assembly pick's conflict resolution can silently DROP lines, and every gate run at assembly time is blind to it\r\n\r\n- **Status:** OPEN, owned by **doyle** (gater craft, not a code defect — no lane to dispatch).\r\n  Filed 2026-08-22 from doyle's own defect on the TURNKEY #212 assembly head.\r\n- **What happened:** assembly head `5cce533d` **did not compile**, and was carried across a session\r\n  boundary as a ready head with \"treqs exit 0\" attached to it. `crates/spt-store/src/access.rs` had\r\n  an unclosed `mod tests`: the cherry-pick of the #206 lane commit `b2194aa9` conflicted against the\r\n  #209 test block — both add functions to the same region, and the two sides share the trailing\r\n  `);` / `}` / `}` — and the resolution deleted the markers without restoring the FIRST side's\r\n  function closer. Exactly two lines lost: `        );` and `    }`.\r\n- **Every instrument in the assembly path reported success:** `git cherry-pick` completed with no\r\n  conflict remaining; `traceable-reqs check` returned 797/797, 0 findings, exit 0 — **it parses\r\n  tags and never invokes the compiler**; and the lanes themselves were green and stayed provably\r\n  clean (the #206 lane's brace balance is correct at all five of its commits). **Lane-green plus\r\n  conflict-free is not a claim about the assembled head.** Same lesson as the #182 v2 assembly\r\n  (`E0425`×4) by a different mechanism: that one was a semantic composition break between two\r\n  correct hunks, this one is a fidelity LOSS during resolution.\r\n- **Two must-dos, both cheap:**\r\n  1. **Compile the assembled head before it is handed anywhere — including forward to your own next\r\n     session.** A head is not ready on a treqs exit; it is ready on a build. Any sentence carrying a\r\n     head sha to another agent must name the instrument that proved it.\r\n  2. **Audit pick fidelity on CHANGED LINES for every pick on the chain**, not just the one that\r\n     tripped you: hash `git show --format= <sha> | grep -E '^[+-]' | grep -vE '^(\\+\\+\\+|---)'` for\r\n     the lane source and for the pick, and compare. Whole-diff comparison is useless here — hunk\r\n     headers and context legitimately drift once the head's copy of the file has moved.\r\n- **Read COUNT and HASH together, because they fail in opposite directions.** Of 24 picks on this\r\n  chain two did not match. `b2194aa9 → 4d6deed1` differed in COUNT (302 lane / 300 pick by the header-excluding pipeline above; **this entry originally cited 310/308, which is the RAW `^[+-]` count INCLUDING the 8 `+++`/`---` header lines of its 4 files** — the figures were taken without the second grep the entry itself prescribes. The DELTA is 2 under either meter, which is why the wrong figures never surfaced: they supported a correct conclusion, so nothing pressed them. Corrected todlando 2026-08-29, measured both ways in-tree) — the real\r\n  defect. `f27f15c6 → 5865cc98` had the SAME count and a different HASH — benign: a `CONTEXT.md`\r\n  paragraph the head had already amended for #209, whose merged result correctly carries both lanes'\r\n  sentences. A count check MISSES the first class entirely; a hash check FLAGS the second as if it\r\n  were a defect. Neither alone classifies a pick.\r\n- **Repair shape used, recorded because it is the cheap one:** reset to the commit before the bad\r\n  pick, re-pick the lane source, resolve the same conflict correctly, then replay the remaining picks\r\n  in chain order with the fidelity check on each. Verify the repair changed nothing else with a\r\n  WHOLE-TREE diff against the old head — it must show exactly the restored lines and no other file.\r\n  Where a later pick re-conflicts, check its pre-pick blobs against the old chain\r\n  (`git rev-parse <old-pick>~1:<file>`); if they match, the old chain's post-pick blob is a\r\n  transferable, already-reviewed resolution.\r\n- **AND GATE THE REPAIR'S OWN SUBJECT.** The rebuilt head passed six legs — clippy `-D warnings`,\r\n  sweep 660/660, treqs 803/803, xtask OK — while the restored lines live in `spt-store`, whose LIB\r\n  tests `-p spt --bins` never runs. Six greens, and not one executed the function the repair\r\n  restored; it was proven to COMPILE and assumed to PASS. Proven afterwards by name (4/4) and by the\r\n  full `spt-store --lib` suite (519/519). **A repair's gate must include the suite that owns the\r\n  repaired file**, which is not necessarily the suite the head gate runs.\r\n- **FIRST LIVE CATCH, and it was the author's own resolution (2026-08-29, one hour after the verb landed):** rebasing the IR-59 rider over the IR-57 rider produced four conflicts — three additive keep-both, one usage line both sides had edited. `xtask pick-audit` read the rebase as **LOSS, 282 lane / 280 pick**. The two missing lines were a `[[requirements]]` header and its blank line in `traceable-reqs.toml`, so `id = REQ-DISK-FLOOR-PREFLIGHT` landed INSIDE the previous table as a duplicate key: **`traceable-reqs check` exit 2, the registry unparseable, every reading after that edit checking nothing**. Restored, the same audit reads **DRIFT 282/282** whose one differing line is the usage string whose base copy legitimately gained the other verb — both verdict classes, on one resolution, in the order the entry predicts. The instrument's first real save was from the hazard it was filed for, against the agent who built it.\r\n- **FIRST REAL-ASSEMBLY USE (2026-08-29, #241 emission head, ASM-241-GATE-VERDICT.md):** `xtask\r\n  pick-audit --range 57a0d27c..HEAD --lane 4d6007ac..d0fdd58d` over 6 picks — **5 MATCH\r\n  (digest-identical), 1 LOSS, 0 drift, 0 unclassified**, exit 1 forcing the accounting. The LOSS\r\n  was exactly the one human-resolved conflict (`cfb9d9f8 <- 10f12e4c`, count 432/402), and the\r\n  delta RECONCILED to the resolution rather than assumed: lane stat 15 files/235+/197- vs pick\r\n  14 files/205+/197-, difference byte-for-byte the deliberately-dropped 30-line interim IR-69\r\n  register block superseded by main's consolidated entry. No false positives, no silent pass.\r\n  Entry stays OPEN as living procedure; both live uses (the rebase catch above, this assembly)\r\n  produced the verdict classes in the order the entry predicts.\r\n- **Trigger condition:** ripe at the next assembly — this is procedure, and its cost is one command\r\n  per pick.\r\n- **Size guess:** small as a scripted check in `xtask` (fidelity audit over a pick range); zero as\r\n  discipline, which is how it is being applied now.\r\n\r\n### IR-58 — a `[[bin]]` grep is not a census: cargo AUTODISCOVERS `src/bin/*.rs` targets, and a hand-built bin list produced a confident false \"this bin does not exist\"\r\n\r\n- **Status:** OPEN, unowned. Filed by doyle 2026-08-22; **its original filing was WRONG and is\r\n  retracted in full below.** The entry is kept because the way it was wrong is the finding.\r\n- **RETRACTED CLAIM, stated plainly so no reader acts on it:** this entry first said that\r\n  `crates/spt/Cargo.toml:18-21` and `crates/spt/src/cli.rs:30355` forbid a bin-name collision with\r\n  `xlate_choreo_fixture`, \"a bin that does not exist\", and that spt-daemon's third helper had been\r\n  renamed to `summarizer_fixture`. **`xlate_choreo_fixture` EXISTS** — at\r\n  `crates/spt-daemon/src/bin/xlate_choreo_fixture.rs`, verified at the assembly head. The collision\r\n  rule's counterpart is real, both prose sites are CORRECT, and IR-21's original table row was\r\n  correct too; it merely predated `summarizer_fixture`. Nothing in that prose needs fixing.\r\n- **How the false claim was produced, which is the entry:** the census was built by grepping\r\n  `^\\[\\[bin\\]\\]` across `Cargo.toml`s. **Cargo AUTODISCOVERS `src/bin/*.rs` as bin targets with no\r\n  stanza at all**, so a stanza grep cannot see them, and it fails SILENTLY — it returns a clean,\r\n  well-formed list that is simply short. From that list it read as established fact that a named bin\r\n  had been renamed away, and that \"fact\" was then written into a register table, an IR entry, and a\r\n  message to the builder. **A pattern-built population encodes the pattern's assumption; the count\r\n  looks like a census and is a property of the pattern.**\r\n  (Found by todlando, resolving one of doyle's figures against his own tree under the pointer rule.)\r\n- **A CENSUS IS ALSO A PROPERTY OF A TREE.** Stanza counts differed legitimately across trees the\r\n  same hour — 13 at the assembly head, 11 at `dc1c7532` — because `summarizer_fixture` exists at one\r\n  and not the other. Two correct censuses of the same workspace disagree unless each names its sha.\r\n- **The must-do, and it removes the list rather than lengthening it:** never hand-maintain a bin\r\n  roster. Run `cargo build --workspace --bins` and let cargo enumerate its own targets — the same\r\n  enumeration the test harness resolves against, so it cannot drift from what a fixture lookup\r\n  expects. Stanza-derived lists, remembered pairs, and register tables are all the roster problem at\r\n  different depths; only cargo's own enumeration is the population.\r\n- **Kin:** IR-55's amended prebuild bullet (prebuild the census, not a remembered pair) and IR-42\r\n  (a verb that writes without adjudicating). The shared shape is an instrument returning an orderly\r\n  answer about a set it never fully saw.\r\n- **Trigger condition:** ripe on any `xtask` check work — a duplicate-bin-name check over cargo's\r\n  target enumeration (NOT over manifest stanzas) is a handful of lines and cannot go stale.\r\n- **Size guess:** small. The prose fix originally proposed here is WITHDRAWN — there was nothing\r\n  wrong with the prose.\r\n\r\n### IR-59 — pool arithmetic: this box holds TWO cold pools, not four; and a build that exhausts the volume reds as a LINKER defect that names no disk\r\n\r\n- **Status:** OPEN, unowned — it is arithmetic and discipline, not a code lane. Filed by doyle\r\n  2026-08-22 from a live disk-floor abort during the TURNKEY #212 W4 gate; footprint figures measured\r\n  by todlando the same hour.\r\n- **v0.69.0 release close, 2026-09-11 (deployah, source record releases#294 comment\r\n  5628538587):** the first broad version/manifest battery failed to LINK (`LNK1180`,\r\n  `LNK1108`, cargo exit 101), with **15,777,792 bytes free** measured at recovery. It produced\r\n  no test verdict. The run selected the workspace's test binaries on the Cargo side even\r\n  though the nextest filter did not need the e2e population; the replacement selected `--lib`\r\n  for `spt-daemon`, `spt-runtime`, `spt`, and `xtask`, and passed **121/121** in 8.445 s.\r\n  Root-target reclamation restored **66,926,968,832 bytes free**; the subsequent CI Windows\r\n  unit step passed **3167 tests**, then its END floor refused at **15,360,114,688 bytes**\r\n  against **34,359,738,368**. That is an observed resource-red AFTER passing tests, not an\r\n  explanation of the earlier PR unit-step red whose log was unavailable. A second, classified\r\n  CI `target/debug` reap, with runner intake stopped by the operator, increased free bytes\r\n  **14,892,281,856 -> 78,994,501,632**. Runner service restored afterward. Publication used a\r\n  preserved signer, not a Cargo rebuild into the cleared pool. These are two measured recoveries,\r\n  not a durable capacity fix; IR-46/59/86 remain the next gate-driver capacity rider.\r\n- **SECOND FACE, measured 2026-08-23/24 (WAX-SEAL #21 W2 gate, doyle — the violator this time):**\r\n  both predicted mechanisms fired at once, WITHOUT the floor guard because the gate legs ran as a\r\n  plain script. (1) doyle minted a THIRD cold pool (gate rig) while todlando's lane pool was LIVE —\r\n  the two-pool arithmetic, violated by the gater. (2) The lane pool had silently accumulated\r\n  **104.8 GB** over repeated full-workspace sweeps (nothing bounds or even measures a pool's\r\n  accumulation until the volume dies). The volume hit **3 MB free**; the reds wore exactly the\r\n  entry's predicted costume — `LNK1318: Unexpected PDB error; LIMIT (12)` naming no disk — plus a\r\n  second face worth keeping: `traceable-reqs check` died as a PANIC printing to stdout\r\n  (`os error 112`), so a REGISTRY gate red can also be the disk's. Both gate verdicts VOIDED\r\n  (clippy's full compile had exited 0 before space died — the code was never the question).\r\n  Recovery measured: gate pool reap 9.6 GB, lane pool clean 100.2 GB, drive back to 109.6 GB free.\r\n  **Remedies adopted at the incident:** the gate never mints its own pool while a builder lane is\r\n  live on the box — it takes the lane pool over SEQUENTIALLY at pool-release (warm, loud, the\r\n  releases#103 pattern); and gate/lane scripts get the disk-floor preflight the golden runner\r\n  already carries (this entry's part 2, still unbuilt).\r\n- **THIRD FACE, measured 2026-08-24 (WAX-SEAL #21 golden window, doyle):** two new mechanisms, both\r\n  about the REMEDY rather than the red. (1) The wax-seal-w1 lane pool **re-accumulated to 152–169 GB\r\n  (two meters, IR-46 caveat) within ONE DAY of the 08-23 clean** and rode the volume back down to\r\n  4.92 GB free — a reap is an instant, not a state; nothing yet bounds a pool between reaps.\r\n  (2) **The remedy itself arrived garbled through relay:** the golden push was held \"waiting on the\r\n  IR-59 reboot\" when this entry prescribes no reboot anywhere — tens of releases have shipped without\r\n  one; the operator refused the premise and the register's own recorded remedy (reap finished-lane\r\n  pools) cleared it in ten minutes. A remedy relayed as a DIFFERENT remedy is the relay trap wearing\r\n  infra clothes: the entry is the author — read it before adopting a hold. Recovery measured: five\r\n  finished-lane pools reaped after ancestry classification (`git cherry` catches rebased lands that\r\n  a plain `merge-base --is-ancestor` calls unlanded — gate-w4l1's 90.9 GB pool was reapable only by\r\n  that meter), 4.92 → 260.88 GB free (~256 GB free-delta vs ~270–287 GB sum-of-lengths). Two main\r\n  runs red inside the low-disk window (09:17Z/09:41Z) were re-run, not re-read, per this entry's\r\n  must-do.\r\n- **FOURTH FACE, measured 2026-08-24 same day (SIGNET #218 W2 gate, doyle — the gater's own pool\r\n  this time):** the MAIN pool went **13.7 GB → 158.3 GB in ONE DAY** absorbing four full gate\r\n  batteries across two lane tips, and dragged the volume to **18 GB free mid-gate** — so the\r\n  entry's mechanism is not a lane-pool problem, it is EVERY pool under repeated full sweeps, the\r\n  gate rig included. Two riders worth the ink: (1) the golden runner's **free-space floor step\r\n  produced its first live catch** — a thin CI leg refused at 14:14 local over exactly this window\r\n  with zero test signal, and the register's re-run-not-re-read rule resolved it in one command;\r\n  (2) the reap-and-rebuild trade (\"cleaning a live pool buys one window at rebuild price\") was\r\n  taken deliberately mid-gate and cost ~35 minutes cold — cheaper than one uninterpretable red.\r\n  A red measured at 18 GB free in this gate got NO read at all, and the next sweep's red was a\r\n  DIFFERENT test: low disk manufactures random victims before it manufactures link errors.\r\n- **The event:** a gate's preflight refused with `GATE_ABORTED_DISK_FLOOR` at **4.75 GB free on a\r\n  1863 GB volume**. Four cold pools plus the milestone head's pool were standing at once. The floor\r\n  guard did its job — without it a full workspace build would have started with under 5 GB of\r\n  headroom and produced a red belonging to nothing.\r\n- **THE ARITHMETIC, and it corrects the intuition that worktrees are the cost.** Measured across the\r\n  whole `.worktrees` tree: **45 worktrees = 0.79 GB total** (~18 MB each). **3 pools = 130.45 GB.**\r\n  Worktrees are **0.6%** of the footprint; pools are **99.4%**. **One cold pool is worth roughly 2,500\r\n  worktrees.** A rule keyed on worktree count would cost a day of `git worktree remove` work for under\r\n  a gigabyte, risk removing a lane someone still wants, and leave the lever untouched.\r\n- **THE CEILING, as arithmetic rather than hygiene:** at **45–75 GB per cold pool** on this workspace\r\n  against a **40 GB floor**, this box supports **TWO live pools comfortably, THREE only if one is\r\n  small**. The two rules that already exist need no replacement, only this number attached:\r\n  - **Reap a pool when its lane is finished** → 45–75 GB back immediately.\r\n  - **Do not run two builds at once** → not only the contention argument, but **75–150 GB of\r\n    simultaneous allocation** against that floor.\r\n- **A FULL VOLUME REDS AS A LINKER DEFECT.** `LINK: fatal error LNK1318: Unexpected PDB error`\r\n  (variously `OK (0)` or `LIMIT (12)`), often beside `LNK4209: debugging information corrupt`. It\r\n  reads as a corrupt artifact or a broken toolchain and is neither — it is the linker unable to grow\r\n  a large `.pdb`. **Nothing in the failure text says \"disk\".** Do not key recognition on the\r\n  parenthesised code; it varies.\r\n- **THE DANGER WINDOW IS THE TAIL OF A COLD BUILD, not a steady state you can check once.** The\r\n  2026-08-22 instance died at the link of `spt` — the last and largest artifact of a **74 GB** cold\r\n  pool — while that same build was draining the volume out from under itself. A free-space reading\r\n  taken before the build would have looked fine.\r\n- **Positive tell, with its own refutation attached:** `traceable-reqs check` alone surviving a leg\r\n  table is suggestive, because it is the only leg that never links. It is a POSITIVE tell ONLY — a\r\n  full disk can red before any link step, so the signature's ABSENCE clears nothing.\r\n- **THE FALSIFIER IS FREE SPACE AT THE TIME OF THE RUN**, not the shape of the leg table.\r\n- **Must-do, both cheap:**\r\n  1. **A free-space reading goes in the FIRST LINE of any build-failure report** — not in the\r\n     controls, not as a follow-up. Two agents spent hours on a mechanism for this failure and neither\r\n     ran `df`; the falsifier was one command away throughout.\r\n  2. **Rig and gate logs should record free space at run start.** Today they do not, which makes \"was\r\n     the disk full\" **unanswerable after the fact for every red already in hand**. Any red produced\r\n     under ~1 GB free is UNINTERPRETABLE and must be **re-run, not re-read**.\r\n- **Measurement caveat, observed twice in one hour:** sum-of-file-lengths and free-space delta\r\n  disagree by several percent when anything else on the box is writing (98.07 GB of subtrees → 92.25\r\n  GB reclaimed; 47.28 GB → 40.81 GB). Report BOTH, derive neither from the other, and treat any single\r\n  free-space number as an instant rather than headroom — see IR-46.\r\n- **FIFTH FACE, measured 2026-08-29 at the CONDUIT #236/v0.65.0 cut (deployah):**\r\n  the finished milestone's sequential lane-sharing accumulated **140.51 GB**, while a freshly\r\n  rebuilt pool measured **7.78 GB** — about **18× one build's working set** retained across lane\r\n  hand-offs with no reap between them. This is the budgetable rate behind that cut's disk-floor\r\n  red: sequential execution prevents concurrent ownership corruption, but it does not bound\r\n  historical artifacts inside the shared pool. Treat takeover and reclamation as separate\r\n  operations; a pool may be safe to reuse and still be too large to keep.\r\n- **SEVENTH FACE, measured 2026-08-30 (v0.67.0 milestone close — the PARALLEL-LANE fill\r\n  rate):** the #23 wave arc drove C: from ~240 GB free to **0.01 GB in ~3.5 hours**: four\r\n  concurrent/serial lane+gate pools totalled **236.6 GB** (ns23-w1 87.7 + ns23-113 72.3 +\r\n  gate rig 57.3 + ns23-w3 19.1) — effectively the entire ir57 reclaim re-consumed inside one\r\n  milestone's build window. The head gate and two thin-CI runs redded with the entry's exact\r\n  costume (\"could not compile\" + treqs panic, zero disk words) at 0.01 GB and all re-earned\r\n  green after reclaim (+186.6 GB, finished-lane targets only, single-actor rule held under\r\n  racing consent). Budget rule this face adds: a MULTI-WAVE milestone on one box books\r\n  ~60-90 GB PER LANE-PLUS-GATE cycle, so the pool budget is per-wave, not per-milestone —\r\n  reap each wave's pool at its LAND, not at the milestone party (the party inherited only\r\n  ~58 GB because the emergency had already forced the other ~179).\r\n- **SIXTH FACE, measured 2026-08-30 (#242 golden r4, Windows test job, LNK1318 at the PDB\r\n  write):** the floor is asserted ONCE at job START, but the job's internal LOW-WATER sits at its\r\n  LAST heavy step — the docs-drift build, ~28 minutes in. r4's floor read 65.1 GiB honest at\r\n  23:07; the box was at ~37–39 GB by the 23:35 link failure. LNK1318 on PDB write = this entry's\r\n  documented low-disk costume; the incremental-corruption candidate was retired by preservation\r\n  snapshot (no xtask state existed at failure). **Durable fix = a floor RE-READ (or reclaim)\r\n  immediately before the docs-drift build** — the WITHIN-job sibling of the across-job\r\n  read-after-checkout fix, rides the next workflow commit. Riders: incremental hygiene as\r\n  disk-pressure maintenance (the dir measured 4.56 GB), and the box's **~51 GB non-recovering\r\n  post-run consumption** is this entry's pool-weight face — classify at the IR-14/26/27/49 audit\r\n  slot (composed this sweep).\r\n- **Composed for next intake (doyle, v0.65.0 close):** the still-open log-the-floor build half\r\n  rides with [[IR-57]]'s scripted pick-fidelity audit as the next milestone's two tooling riders.\r\n- **Trigger condition:** ripe now for the log-the-floor half (it rides any gate-script or CI touch);\r\n  the arithmetic is discipline and applies immediately.\r\n- **Size guess:** small — one line in each rig/gate preflight to record free space alongside the\r\n  existing floor check.\r\n\r","truncated":true,"truncatedBy":"lines","totalLines":3738,"totalBytes":25765,"outputLines":275,"outputBytes":25765,"lastLinePartial":false,"firstLineExceedsLimit":false},"totalLines":6938,"displayContent":{"text":"### IR-56 — `pool-claim` harvests lane identity from CWD, not from `--pool`; a claim run from the wrong tree writes a WRONG RECORD with a success message\r\n\r\n- **Status:** BUILT 2026-08-24 for the SIGNET #218 golden batch on\r\n  `fix/ir56-pool-claim-cwd`, owned by **hertz**. Tooling/rig defect by the dispatch split. Filed by\r\n  doyle 2026-08-22 from todlando's TURNKEY #212 W4 Lane 1 field instance — the first confirmation\r\n  of the IR-42 mechanism from a LANE rather than from a source read.\r\n- **What happens:** `cargo run -p xtask -- pool-claim --pool <dir> --label <lane>` records the lane\r\n  identity it harvests from the **current working directory** — `owner_tree`, `lane_branch`, and the\r\n  base sha — not from the tree `--pool` names. Run it from the project root with `--pool` aimed at a\r\n  worktree and the record reads `owner_tree = <project root>, lane_branch = <root's branch>` while\r\n  every artifact in that pool belongs to the worktree. The verb prints its ordinary success line\r\n  naming the wrong owner, and returns 0.\r\n- **Why it is silent, which is the whole entry:** the claim verb WRITES and never adjudicates\r\n  (IR-42) — every enforcement arm lives in `crates/spt-store/build.rs` and speaks only at the next\r\n  BUILD. So a wrong record has no symptom at the moment it is created; the first signal is a build\r\n  refusal minutes later, on a lane whose `--pool` argument was correct all along. **`--pool` being\r\n  correct is not evidence the record is.** Nothing on the command line shows you cwd, which is the\r\n  one input that decided the outcome.\r\n- **Recovery is the documented hatch, and the bootstrap is why:** the claim tool builds THROUGH the\r\n  pool it is claiming, so a pool already refusing cannot be re-claimed by the ordinary route. The\r\n  refusal text says so itself — meaning the bootstrap case is known, and a wrong-cwd claim is the\r\n  ordinary way a lane lands in it.\r\n- **The rule, as a must-do:** claim from the lane's own worktree so the identity the verb harvests\r\n  is the lane's — `( cd <lane> && cargo run -p xtask -- pool-claim --pool \"$PWD/target\" … )`, or any\r\n  form that makes cwd explicit. Then READ THE PRINTED RECORD BACK and confirm `owner_tree` and\r\n  `branch` name the lane: the success line carries the record, so the check costs nothing.\r\n- **Trigger condition:** ripe now — it is a doc/UX fix on a verb we run every lane. Ripest alongside\r\n  any other `xtask` pool-verb touch.\r\n- **Size guess:** small. Either make the verb REFUSE when cwd is not inside the tree containing\r\n  `--pool` (loud, and it cannot be wrong), or print the harvested identity as a distinct confirmed\r\n  line. The refusing form is preferred: it removes the reading step rather than adding one.\r\n- **Built evidence, corrected at review:** `pool-claim` resolves the git worktree containing\r\n  `--pool` from the pool's nearest existing ancestor and compares it with the cwd worktree before\r\n  writing. An accidental cross-worktree call returns 2, names both worktrees and the remedy, and\r\n  leaves the not-yet-existing pool absent. The sanctioned sequential takeover carries an explicit\r\n  `--foreign-pool`, says that it is harvesting the arriving cwd identity, writes that identity, and\r\n  returns 0. Both poolguard refusal remedies now print that flag. An executable xtask test drives\r\n  both arms against two real temporary git repositories, pinning VERB-ADMITS-REMEDY rather than\r\n  merely testing path equality. This remains identity-harvest validation only: the claim still\r\n  writes without adjudicating admission, so IR-42's enforcement boundary remains in the build.\r\n\r\n- **Second instance 2026-09-11 (todlando, #304 product lane):** an allocation packet carried the\r\n  claim as `pool-claim --pool .worktrees/304-product/target` — correct from the repo root, WRONG\r\n  from inside the worktree, where it resolves to a nested `.worktrees/...` path. Caught within\r\n  seconds of launch, nothing written at the nested path, re-run with the absolute lane path. Rule:\r\n  an allocation names the pool by ABSOLUTE path, because the claim verb acts on where it stands.\r\n\r\n### IR-57 — an assembly pick's conflict resolution can silently DROP lines, and every gate run at assembly time is blind to it\r\n\r\n- **Status:** OPEN, owned by **doyle** (gater craft, not a code defect — no lane to dispatch).\r\n  Filed 2026-08-22 from doyle's own defect on the TURNKEY #212 assembly head.\r\n- **What happened:** assembly head `5cce533d` **did not compile**, and was carried across a session\r\n  boundary as a ready head with \"treqs exit 0\" attached to it. `crates/spt-store/src/access.rs` had\r\n  an unclosed `mod tests`: the cherry-pick of the #206 lane commit `b2194aa9` conflicted against the\r\n  #209 test block — both add functions to the same region, and the two sides share the trailing\r\n  `);` / `}` / `}` — and the resolution deleted the markers without restoring the FIRST side's\r\n  function closer. Exactly two lines lost: `        );` and `    }`.\r\n- **Every instrument in the assembly path reported success:** `git cherry-pick` completed with no\r\n  conflict remaining; `traceable-reqs check` returned 797/797, 0 findings, exit 0 — **it parses\r\n  tags and never invokes the compiler**; and the lanes themselves were green and stayed provably\r\n  clean (the #206 lane's brace balance is correct at all five of its commits). **Lane-green plus\r\n  conflict-free is not a claim about the assembled head.** Same lesson as the #182 v2 assembly\r\n  (`E0425`×4) by a different mechanism: that one was a semantic composition break between two\r\n  correct hunks, this one is a fidelity LOSS during resolution.\r\n- **Two must-dos, both cheap:**\r\n  1. **Compile the assembled head before it is handed anywhere — including forward to your own next\r\n     session.** A head is not ready on a treqs exit; it is ready on a build. Any sentence carrying a\r\n     head sha to another agent must name the instrument that proved it.\r\n  2. **Audit pick fidelity on CHANGED LINES for every pick on the chain**, not just the one that\r\n     tripped you: hash `git show --format= <sha> | grep -E '^[+-]' | grep -vE '^(\\+\\+\\+|---)'` for\r\n     the lane source and for the pick, and compare. Whole-diff comparison is useless here — hunk\r\n     headers and context legitimately drift once the head's copy of the file has moved.\r\n- **Read COUNT and HASH together, because they fail in opposite directions.** Of 24 picks on this\r\n  chain two did not match. `b2194aa9 → 4d6deed1` differed in COUNT (302 lane / 300 pick by the header-excluding pipeline above; **this entry originally cited 310/308, which is the RAW `^[+-]` count INCLUDING the 8 `+++`/`---` header lines of its 4 files** — the figures were taken without the second grep the entry itself prescribes. The DELTA is 2 under either meter, which is why the wrong figures never surfaced: they supported a correct conclusion, so nothing pressed them. Corrected todlando 2026-08-29, measured both ways in-tree) — the real\r\n  defect. `f27f15c6 → 5865cc98` had the SAME count and a different HASH — benign: a `CONTEXT.md`\r\n  paragraph the head had already amended for #209, whose merged result correctly carries both lanes'\r\n  sentences. A count check MISSES the first class entirely; a hash check FLAGS the second as if it\r\n  were a defect. Neither alone classifies a pick.\r\n- **Repair shape used, recorded because it is the cheap one:** reset to the commit before the bad\r\n  pick, re-pick the lane source, resolve the same conflict correctly, then replay the remaining picks\r\n  in chain order with the fidelity check on each. Verify the repair changed nothing else with a\r\n  WHOLE-TREE diff against the old head — it must show exactly the restored lines and no other file.\r\n  Where a later pick re-conflicts, check its pre-pick blobs against the old chain\r\n  (`git rev-parse <old-pick>~1:<file>`); if they match, the old chain's post-pick blob is a\r\n  transferable, already-reviewed resolution.\r\n- **AND GATE THE REPAIR'S OWN SUBJECT.** The rebuilt head passed six legs — clippy `-D warnings`,\r\n  sweep 660/660, treqs 803/803, xtask OK — while the restored lines live in `spt-store`, whose LIB\r\n  tests `-p spt --bins` never runs. Six greens, and not one executed the function the repair\r\n  restored; it was proven to COMPILE and assumed to PASS. Proven afterwards by name (4/4) and by the\r\n  full `spt-store --lib` suite (519/519). **A repair's gate must include the suite that owns the\r\n  repaired file**, which is not necessarily the suite the head gate runs.\r\n- **FIRST LIVE CATCH, and it was the author's own resolution (2026-08-29, one hour after the verb landed):** rebasing the IR-59 rider over the IR-57 rider produced four conflicts — three additive keep-both, one usage line both sides had edited. `xtask pick-audit` read the rebase as **LOSS, 282 lane / 280 pick**. The two missing lines were a `[[requirements]]` header and its blank line in `traceable-reqs.toml`, so `id = REQ-DISK-FLOOR-PREFLIGHT` landed INSIDE the previous table as a duplicate key: **`traceable-reqs check` exit 2, the registry unparseable, every reading after that edit checking nothing**. Restored, the same audit reads **DRIFT 282/282** whose one differing line is the usage string whose base copy legitimately gained the other verb — both verdict classes, on one resolution, in the order the entry predicts. The instrument's first real save was from the hazard it was filed for, against the agent who built it.\r\n- **FIRST REAL-ASSEMBLY USE (2026-08-29, #241 emission head, ASM-241-GATE-VERDICT.md):** `xtask\r\n  pick-audit --range 57a0d27c..HEAD --lane 4d6007ac..d0fdd58d` over 6 picks — **5 MATCH\r\n  (digest-identical), 1 LOSS, 0 drift, 0 unclassified**, exit 1 forcing the accounting. The LOSS\r\n  was exactly the one human-resolved conflict (`cfb9d9f8 <- 10f12e4c`, count 432/402), and the\r\n  delta RECONCILED to the resolution rather than assumed: lane stat 15 files/235+/197- vs pick\r\n  14 files/205+/197-, difference byte-for-byte the deliberately-dropped 30-line interim IR-69\r\n  register block superseded by main's consolidated entry. No false positives, no silent pass.\r\n  Entry stays OPEN as living procedure; both live uses (the rebase catch above, this assembly)\r\n  produced the verdict classes in the order the entry predicts.\r\n- **Trigger condition:** ripe at the next assembly — this is procedure, and its cost is one command\r\n  per pick.\r\n- **Size guess:** small as a scripted check in `xtask` (fidelity audit over a pick range); zero as\r\n  discipline, which is how it is being applied now.\r\n\r\n### IR-58 — a `[[bin]]` grep is not a census: cargo AUTODISCOVERS `src/bin/*.rs` targets, and a hand-built bin list produced a confident false \"this bin does not exist\"\r\n\r\n- **Status:** OPEN, unowned. Filed by doyle 2026-08-22; **its original filing was WRONG and is\r\n  retracted in full below.** The entry is kept because the way it was wrong is the finding.\r\n- **RETRACTED CLAIM, stated plainly so no reader acts on it:** this entry first said that\r\n  `crates/spt/Cargo.toml:18-21` and `crates/spt/src/cli.rs:30355` forbid a bin-name collision with\r\n  `xlate_choreo_fixture`, \"a bin that does not exist\", and that spt-daemon's third helper had been\r\n  renamed to `summarizer_fixture`. **`xlate_choreo_fixture` EXISTS** — at\r\n  `crates/spt-daemon/src/bin/xlate_choreo_fixture.rs`, verified at the assembly head. The collision\r\n  rule's counterpart is real, both prose sites are CORRECT, and IR-21's original table row was\r\n  correct too; it merely predated `summarizer_fixture`. Nothing in that prose needs fixing.\r\n- **How the false claim was produced, which is the entry:** the census was built by grepping\r\n  `^\\[\\[bin\\]\\]` across `Cargo.toml`s. **Cargo AUTODISCOVERS `src/bin/*.rs` as bin targets with no\r\n  stanza at all**, so a stanza grep cannot see them, and it fails SILENTLY — it returns a clean,\r\n  well-formed list that is simply short. From that list it read as established fact that a named bin\r\n  had been renamed away, and that \"fact\" was then written into a register table, an IR entry, and a\r\n  message to the builder. **A pattern-built population encodes the pattern's assumption; the count\r\n  looks like a census and is a property of the pattern.**\r\n  (Found by todlando, resolving one of doyle's figures against his own tree under the pointer rule.)\r\n- **A CENSUS IS ALSO A PROPERTY OF A TREE.** Stanza counts differed legitimately across trees the\r\n  same hour — 13 at the assembly head, 11 at `dc1c7532` — because `summarizer_fixture` exists at one\r\n  and not the other. Two correct censuses of the same workspace disagree unless each names its sha.\r\n- **The must-do, and it removes the list rather than lengthening it:** never hand-maintain a bin\r\n  roster. Run `cargo build --workspace --bins` and let cargo enumerate its own targets — the same\r\n  enumeration the test harness resolves against, so it cannot drift from what a fixture lookup\r\n  expects. Stanza-derived lists, remembered pairs, and register tables are all the roster problem at\r\n  different depths; only cargo's own enumeration is the population.\r\n- **Kin:** IR-55's amended prebuild bullet (prebuild the census, not a remembered pair) and IR-42\r\n  (a verb that writes without adjudicating). The shared shape is an instrument returning an orderly\r\n  answer about a set it never fully saw.\r\n- **Trigger condition:** ripe on any `xtask` check work — a duplicate-bin-name check over cargo's\r\n  target enumeration (NOT over manifest stanzas) is a handful of lines and cannot go stale.\r\n- **Size guess:** small. The prose fix originally proposed here is WITHDRAWN — there was nothing\r\n  wrong with the prose.\r\n\r\n### IR-59 — pool arithmetic: this box holds TWO cold pools, not four; and a build that exhausts the volume reds as a LINKER defect that names no disk\r\n\r\n- **Status:** OPEN, unowned — it is arithmetic and discipline, not a code lane. Filed by doyle\r\n  2026-08-22 from a live disk-floor abort during the TURNKEY #212 W4 gate; footprint figures measured\r\n  by todlando the same hour.\r\n- **v0.69.0 release close, 2026-09-11 (deployah, source record releases#294 comment\r\n  5628538587):** the first broad version/manifest battery failed to LINK (`LNK1180`,\r\n  `LNK1108`, cargo exit 101), with **15,777,792 bytes free** measured at recovery. It produced\r\n  no test verdict. The run selected the workspace's test binaries on the Cargo side even\r\n  though the nextest filter did not need the e2e population; the replacement selected `--lib`\r\n  for `spt-daemon`, `spt-runtime`, `spt`, and `xtask`, and passed **121/121** in 8.445 s.\r\n  Root-target reclamation restored **66,926,968,832 bytes free**; the subsequent CI Windows\r\n  unit step passed **3167 tests**, then its END floor refused at **15,360,114,688 bytes**\r\n  against **34,359,738,368**. That is an observed resource-red AFTER passing tests, not an\r\n  explanation of the earlier PR unit-step red whose log was unavailable. A second, classified\r\n  CI `target/debug` reap, with runner intake stopped by the operator, increased free bytes\r\n  **14,892,281,856 -> 78,994,501,632**. Runner service restored afterward. Publication used a\r\n  preserved signer, not a Cargo rebuild into the cleared pool. These are two measured recoveries,\r\n  not a durable capacity fix; IR-46/59/86 remain the next gate-driver capacity rider.\r\n- **SECOND FACE, measured 2026-08-23/24 (WAX-SEAL #21 W2 gate, doyle — the violator this time):**\r\n  both predicted mechanisms fired at once, WITHOUT the floor guard because the gate legs ran as a\r\n  plain script. (1) doyle minted a THIRD cold pool (gate rig) while todlando's lane pool was LIVE —\r\n  the two-pool arithmetic, violated by the gater. (2) The lane pool had silently accumulated\r\n  **104.8 GB** over repeated full-workspace sweeps (nothing bounds or even measures a pool's\r\n  accumulation until the volume dies). The volume hit **3 MB free**; the reds wore exactly the\r\n  entry's predicted costume — `LNK1318: Unexpected PDB error; LIMIT (12)` naming no disk — plus a\r\n  second face worth keeping: `traceable-reqs check` died as a PANIC printing to stdout\r\n  (`os error 112`), so a REGISTRY gate red can also be the disk's. Both gate verdicts VOIDED\r\n  (clippy's full compile had exited 0 before space died — the code was never the question).\r\n  Recovery measured: gate pool reap 9.6 GB, lane pool clean 100.2 GB, drive back to 109.6 GB free.\r\n  **Remedies adopted at the incident:** the gate never mints its own pool while a builder lane is\r\n  live on the box — it takes the lane pool over SEQUENTIALLY at pool-release (warm, loud, the\r\n  releases#103 pattern); and gate/lane scripts get the disk-floor preflight the golden runner\r\n  already carries (this entry's part 2, still unbuilt).\r\n- **THIRD FACE, measured 2026-08-24 (WAX-SEAL #21 golden window, doyle):** two new mechanisms, both\r\n  about the REMEDY rather than the red. (1) The wax-seal-w1 lane pool **re-accumulated to 152–169 GB\r\n  (two meters, IR-46 caveat) within ONE DAY of the 08-23 clean** and rode the volume back down to\r\n  4.92 GB free — a reap is an instant, not a state; nothing yet bounds a pool between reaps.\r\n  (2) **The remedy itself arrived garbled through relay:** the golden push was held \"waiting on the\r\n  IR-59 reboot\" when this entry prescribes no reboot anywhere — tens of releases have shipped without\r\n  one; the operator refused the premise and the register's own recorded remedy (reap finished-lane\r\n  pools) cleared it in ten minutes. A remedy relayed as a DIFFERENT remedy is the relay trap wearing\r\n  infra clothes: the entry is the author — read it before adopting a hold. Recovery measured: five\r\n  finished-lane pools reaped after ancestry classification (`git cherry` catches rebased lands that\r\n  a plain `merge-base --is-ancestor` calls unlanded — gate-w4l1's 90.9 GB pool was reapable only by\r\n  that meter), 4.92 → 260.88 GB free (~256 GB free-delta vs ~270–287 GB sum-of-lengths). Two main\r\n  runs red inside the low-disk window (09:17Z/09:41Z) were re-run, not re-read, per this entry's\r\n  must-do.\r\n- **FOURTH FACE, measured 2026-08-24 same day (SIGNET #218 W2 gate, doyle — the gater's own pool\r\n  this time):** the MAIN pool went **13.7 GB → 158.3 GB in ONE DAY** absorbing four full gate\r\n  batteries across two lane tips, and dragged the volume to **18 GB free mid-gate** — so the\r\n  entry's mechanism is not a lane-pool problem, it is EVERY pool under repeated full sweeps, the\r\n  gate rig included. Two riders worth the ink: (1) the golden runner's **free-space floor step\r\n  produced its first live catch** — a thin CI leg refused at 14:14 local over exactly this window\r\n  with zero test signal, and the register's re-run-not-re-read rule resolved it in one command;\r\n  (2) the reap-and-rebuild trade (\"cleaning a live pool buys one window at rebuild price\") was\r\n  taken deliberately mid-gate and cost ~35 minutes cold — cheaper than one uninterpretable red.\r\n  A red measured at 18 GB free in this gate got NO read at all, and the next sweep's red was a\r\n  DIFFERENT test: low disk manufactures random victims before it manufactures link errors.\r\n- **The event:** a gate's preflight refused with `GATE_ABORTED_DISK_FLOOR` at **4.75 GB free on a\r\n  1863 GB volume**. Four cold pools plus the milestone head's pool were standing at once. The floor\r\n  guard did its job — without it a full workspace build would have started with under 5 GB of\r\n  headroom and produced a red belonging to nothing.\r\n- **THE ARITHMETIC, and it corrects the intuition that worktrees are the cost.** Measured across the\r\n  whole `.worktrees` tree: **45 worktrees = 0.79 GB total** (~18 MB each). **3 pools = 130.45 GB.**\r\n  Worktrees are **0.6%** of the footprint; pools are **99.4%**. **One cold pool is worth roughly 2,500\r\n  worktrees.** A rule keyed on worktree count would cost a day of `git worktree remove` work for under\r\n  a gigabyte, risk removing a lane someone still wants, and leave the lever untouched.\r\n- **THE CEILING, as arithmetic rather than hygiene:** at **45–75 GB per cold pool** on this workspace\r\n  against a **40 GB floor**, this box supports **TWO live pools comfortably, THREE only if one is\r\n  small**. The two rules that already exist need no replacement, only this number attached:\r\n  - **Reap a pool when its lane is finished** → 45–75 GB back immediately.\r\n  - **Do not run two builds at once** → not only the contention argument, but **75–150 GB of\r\n    simultaneous allocation** against that floor.\r\n- **A FULL VOLUME REDS AS A LINKER DEFECT.** `LINK: fatal error LNK1318: Unexpected PDB error`\r\n  (variously `OK (0)` or `LIMIT (12)`), often beside `LNK4209: debugging information corrupt`. It\r\n  reads as a corrupt artifact or a broken toolchain and is neither — it is the linker unable to grow\r\n  a large `.pdb`. **Nothing in the failure text says \"disk\".** Do not key recognition on the\r\n  parenthesised code; it varies.\r\n- **THE DANGER WINDOW IS THE TAIL OF A COLD BUILD, not a steady state you can check once.** The\r\n  2026-08-22 instance died at the link of `spt` — the last and largest artifact of a **74 GB** cold\r\n  pool — while that same build was draining the volume out from under itself. A free-space reading\r\n  taken before the build would have looked fine.\r\n- **Positive tell, with its own refutation attached:** `traceable-reqs check` alone surviving a leg\r\n  table is suggestive, because it is the only leg that never links. It is a POSITIVE tell ONLY — a\r\n  full disk can red before any link step, so the signature's ABSENCE clears nothing.\r\n- **THE FALSIFIER IS FREE SPACE AT THE TIME OF THE RUN**, not the shape of the leg table.\r\n- **Must-do, both cheap:**\r\n  1. **A free-space reading goes in the FIRST LINE of any build-failure report** — not in the\r\n     controls, not as a follow-up. Two agents spent hours on a mechanism for this failure and neither\r\n     ran `df`; the falsifier was one command away throughout.\r\n  2. **Rig and gate logs should record free space at run start.** Today they do not, which makes \"was\r\n     the disk full\" **unanswerable after the fact for every red already in hand**. Any red produced\r\n     under ~1 GB free is UNINTERPRETABLE and must be **re-run, not re-read**.\r\n- **Measurement caveat, observed twice in one hour:** sum-of-file-lengths and free-space delta\r\n  disagree by several percent when anything else on the box is writing (98.07 GB of subtrees → 92.25\r\n  GB reclaimed; 47.28 GB → 40.81 GB). Report BOTH, derive neither from the other, and treat any single\r\n  free-space number as an instant rather than headroom — see IR-46.\r\n- **FIFTH FACE, measured 2026-08-29 at the CONDUIT #236/v0.65.0 cut (deployah):**\r\n  the finished milestone's sequential lane-sharing accumulated **140.51 GB**, while a freshly\r\n  rebuilt pool measured **7.78 GB** — about **18× one build's working set** retained across lane\r\n  hand-offs with no reap between them. This is the budgetable rate behind that cut's disk-floor\r\n  red: sequential execution prevents concurrent ownership corruption, but it does not bound\r\n  historical artifacts inside the shared pool. Treat takeover and reclamation as separate\r\n  operations; a pool may be safe to reuse and still be too large to keep.\r\n- **SEVENTH FACE, measured 2026-08-30 (v0.67.0 milestone close — the PARALLEL-LANE fill\r\n  rate):** the #23 wave arc drove C: from ~240 GB free to **0.01 GB in ~3.5 hours**: four\r\n  concurrent/serial lane+gate pools totalled **236.6 GB** (ns23-w1 87.7 + ns23-113 72.3 +\r\n  gate rig 57.3 + ns23-w3 19.1) — effectively the entire ir57 reclaim re-consumed inside one\r\n  milestone's build window. The head gate and two thin-CI runs redded with the entry's exact\r\n  costume (\"could not compile\" + treqs panic, zero disk words) at 0.01 GB and all re-earned\r\n  green after reclaim (+186.6 GB, finished-lane targets only, single-actor rule held under\r\n  racing consent). Budget rule this face adds: a MULTI-WAVE milestone on one box books\r\n  ~60-90 GB PER LANE-PLUS-GATE cycle, so the pool budget is per-wave, not per-milestone —\r\n  reap each wave's pool at its LAND, not at the milestone party (the party inherited only\r\n  ~58 GB because the emergency had already forced the other ~179).\r\n- **SIXTH FACE, measured 2026-08-30 (#242 golden r4, Windows test job, LNK1318 at the PDB\r\n  write):** the floor is asserted ONCE at job START, but the job's internal LOW-WATER sits at its\r\n  LAST heavy step — the docs-drift build, ~28 minutes in. r4's floor read 65.1 GiB honest at\r\n  23:07; the box was at ~37–39 GB by the 23:35 link failure. LNK1318 on PDB write = this entry's\r\n  documented low-disk costume; the incremental-corruption candidate was retired by preservation\r\n  snapshot (no xtask state existed at failure). **Durable fix = a floor RE-READ (or reclaim)\r\n  immediately before the docs-drift build** — the WITHIN-job sibling of the across-job\r\n  read-after-checkout fix, rides the next workflow commit. Riders: incremental hygiene as\r\n  disk-pressure maintenance (the dir measured 4.56 GB), and the box's **~51 GB non-recovering\r\n  post-run consumption** is this entry's pool-weight face — classify at the IR-14/26/27/49 audit\r\n  slot (composed this sweep).\r\n- **Composed for next intake (doyle, v0.65.0 close):** the still-open log-the-floor build half\r\n  rides with [[IR-57]]'s scripted pick-fidelity audit as the next milestone's two tooling riders.\r\n- **Trigger condition:** ripe now for the log-the-floor half (it rides any gate-script or CI touch);\r\n  the arithmetic is discipline and applies immediately.\r\n- **Size guess:** small — one line in each rig/gate preflight to record free space alongside the\r\n  existing floor check.\r\n\r","startLine":3201,"lineNumbers":[3201,3202,3203,3204,3205,3206,3207,3208,3209,3210,3211,3212,3213,3214,3215,3216,3217,3218,3219,3220,3221,3222,3223,3224,3225,3226,3227,3228,3229,3230,3231,3232,3233,3234,3235,3236,3237,3238,3239,3240,3241,3242,3243,3244,3245,3246,3247,3248,3249,3250,3251,3252,3253,3254,3255,3256,3257,3258,3259,3260,3261,3262,3263,3264,3265,3266,3267,3268,3269,3270,3271,3272,3273,3274,3275,3276,3277,3278,3279,3280,3281,3282,3283,3284,3285,3286,3287,3288,3289,3290,3291,3292,3293,3294,3295,3296,3297,3298,3299,3300,3301,3302,3303,3304,3305,3306,3307,3308,3309,3310,3311,3312,3313,3314,3315,3316,3317,3318,3319,3320,3321,3322,3323,3324,3325,3326,3327,3328,3329,3330,3331,3332,3333,3334,3335,3336,3337,3338,3339,3340,3341,3342,3343,3344,3345,3346,3347,3348,3349,3350,3351,3352,3353,3354,3355,3356,3357,3358,3359,3360,3361,3362,3363,3364,3365,3366,3367,3368,3369,3370,3371,3372,3373,3374,3375,3376,3377,3378,3379,3380,3381,3382,3383,3384,3385,3386,3387,3388,3389,3390,3391,3392,3393,3394,3395,3396,3397,3398,3399,3400,3401,3402,3403,3404,3405,3406,3407,3408,3409,3410,3411,3412,3413,3414,3415,3416,3417,3418,3419,3420,3421,3422,3423,3424,3425,3426,3427,3428,3429,3430,3431,3432,3433,3434,3435,3436,3437,3438,3439,3440,3441,3442,3443,3444,3445,3446,3447,3448,3449,3450,3451,3452,3453,3454,3455,3456,3457,3458,3459,3460,3461,3462,3463,3464,3465,3466,3467,3468,3469,3470,3471,3472,3473,3474,3475]},"fileSize":676479,"meta":{"source":{"type":"path","value":"C:\\Users\\decid\\Documents\\projects\\spt-core\\.worktrees\\hertz-ir86-disk-delta\\docs\\INFRA-REGISTER.md"},"truncation":{"direction":"head","truncatedBy":"lines","totalLines":6938,"totalBytes":25765,"outputLines":275,"outputBytes":25765,"shownRange":{"start":3201,"end":3475},"nextOffset":3476}}},"isError":false,"timestamp":1789483686441}}
{"type":"message","id":"3ca5ef39","parentId":"3c4bdf91","timestamp":"2026-09-15T14:48:06.446Z","message":{"role":"toolResult","toolCallId":"call_KgTuIU7LdN7bkBoLT7MZteVf|fc_043a862a419f59ae016aa95aa6522487d2bf4290ebde7e856e","toolName":"read","content":[{"type":"text","text":"  error anywhere) matches the SHAPE of the filed offline-but-resolvable-peer pump-stall\n  mechanism (dial does not fast-fail). Discrimination open; nothing here is a #199 attribution.\n- **Remedy:** a rig-honoured net-off switch (peer pump + discovery disabled under test unless\n  the test is ABOUT them) or loopback-only binding; census which e2e rigs start net consumers.\n  Sequencing rule: do NOT fix hermeticity into #199's face before the face is attributed — a\n  green bought by turning the net off would bury the mechanism unread.\n- **Ripe when:** #199 attribution answers whether net state is causal; else the next\n  hermeticity pass.\n- **Size:** product switch + rig adoption + census.\n- **Kin:** [[IR-45]] (the disk half), the subnet-pump dial-does-not-fast-fail mechanism (filed,\n  pump-stall RCA), [[IR-38]] (a live daemon's side effects outliving the test's intent),\n  releases#125 gc-spin (a conn-churn shape candidate).\n\n### IR-53 — failed-address expiry unit panics during the first 10m01s after Windows boot\n- **Status:** BUILT 2026-08-21 on `fix/ir53-cold-boot-instant` — LANDED in v0.59.0\n  (PORTER rider, pick `7b26f28d` on `assembly/porter-205`, main @`c62904e7`; register\n  sweep 2026-08-21 at release close) · **Origin:** todlando,\n  found and falsifiably measured mid-releases#204; this rider fixes the latent CI-pipeline\n  flake before PORTER golden.\n- **Measured:** `failedaddr::tests::an_expired_record_stops_matching_and_is_swept` ages an\n  `Instant` with `Instant::now().checked_sub(FAILED_ADDR_TTL + 1s).expect(...)`, where\n  `FAILED_ADDR_TTL = 600s`. Windows `Instant` counts from boot, so a host younger than 601s\n  cannot represent the requested stamp and panics `monotonic clock older than the TTL`.\n  Todlando predicted and observed the red before the threshold, then observed the identical\n  tree green after it; two subsequent daemon sweeps held 860/860.\n- **Remedy:** when the monotonic clock cannot represent the age, return through the loud\n  `SKIP_FAILED_ADDR_EXPIRED_SWEEP` arm naming the exact unproved property. On every warm host\n  the original direct aging and both expiry assertions still run unchanged; there is no\n  ten-minute sleep and no silent pass on the cold arm.\n- **Class census (untruncated):** four test-side\n  `Instant::now().checked_sub(...TTL/deadline...).expect(...)` patterns total. This cell is\n  the sole 601s member. Three siblings remain recorded, not changed in this rider:\n  `broker.rs:8432-8434` and `broker.rs:9198-9200` age\n  `CONTROLLER_WRITE_DEADLINE + 1s` (6s), while `broker.rs:10385-10388` ages\n  `BRAIN_WRITE_DEADLINE + 1s` (16s). Their much narrower cold-boot windows are the same\n  mechanism class and should use a controlled clock seam when next touched.\n- **Kin:** releases#204 (finder lane), [[IR-25]] (daemon-lib flake population), and\n  [[IR-40]] (a confident verdict without the evidence needed to make it).\n\n### IR-52 — docs-site CLI reference renders SHALLOW; help text below the rendered depth is outside the drift gate, unit-held per-REQ or held by nothing\n- **THIRD INSTANCE, observed 2026-08-24 (todlando, WAX-SEAL #21 W4; not acted on):** the new\n  `spt api seal verify|describe` FLAGS sit below the generator's rendered depth — the entry's\n  exact class. The W4 user page hand-documents them, which is per-page self-defense, not a\n  gate. Conditional-rider condition did NOT fire at W4 (no generator touch); the entry's own\n  trigger stands for whichever lane next touches the generator.\n- **Status:** BUILT 2026-08-24 on SIGNET #218 W1 T6 (todlando; doyle's intake made it the wave's\n  rider when the new `seal enroll-authenticator` verb forced the generator touch that armed the\n  trigger): `xtask` reference-gen now DESCENDS THE FULL COMMAND TREE recursively (the durable\n  remedy), regen published the 22 previously-unrendered leaves + the new section, and a depth\n  regression is a drift RED by construction. Self-holding units censused per the remedy: the\n  SURFACE-SECTION-SITED walk and both MONIC-TRIGGER-SECTION sited-help units are now DOUBLE-held\n  (published surface under the drift gate + content pins kept) — kept, not retired. · **Origin:**\n  todlando's #160 build report, fact flagged for the gate rather than folded silently.\n  (Pre-build status: open, filed 2026-08-19 — doyle, W3 #160 gate prep; second measured instance\n  of a class REQ-CLI-SURFACE-SECTION-SITED's own title already named for its sites.)\n- **What/why:** the generated `docs-site/src/cli/reference.md` renders `spt endpoint monic`\n  but does not descend to `monic add` / `monic update`, so the #160 strike of the maintained\n  kind enumeration at those two flag docs never appeared in the published reference and the\n  docs-drift gate CANNOT see the strike — the REQ-CLI-MONIC-TRIGGER-SECTION rendered-help\n  unit is the only hold. General mechanism: any help text below the generator's descent\n  depth is invisible to the drift gate; a deep help edit (or regression) ships unpublished\n  and ungated unless some REQ's unit happens to pin it. First measured instance:\n  REQ-CLI-SURFACE-SECTION-SITED names \"the three-deep sites the docs-site drift gate cannot\n  reach\" and closes them with its own pinned walk — per-REQ self-defense, not a gate.\n  Consequence beyond drift: adapter builders build BLIND from the public docs (DRI\n  protocol), so a deep-help divergence hands every adapter a thinner contract than the\n  operator's terminal shows.\n- **Remedy:** either xtask reference-gen descends the full command tree (deep help becomes\n  published surface the drift gate already covers), or a generic rendered-help walk over all\n  sites at all depths joins the drift gate; census which REQ units currently self-hold deep\n  sites (known: SURFACE-SECTION-SITED walk, MONIC-TRIGGER-SECTION sited-help unit).\n- **Ripe when:** next xtask docs-gen touch, or the first adapter filing traceable to a\n  deep-help divergence.\n- **Size:** xtask render change + regen + census of self-holding units.\n- **Kin:** the REQ-CLI-SURFACE-SECTION-SITED pinned walk (the per-REQ closure shape this\n  entry generalizes), [[IR-47]] only if its golden.yml/ci-notify surface rides the same\n  docs-gate window.\n\n### CI-RIDER LANE STATE — LANDED 2026-08-04 (post-v0.53.0 merge queue); history below kept for its mechanisms\n- **RESOLVED:** the lane rebased clean onto the post-tag queue and landed ff-only as\n  `2b33a47`/`2a7b016`/`d63f4ce`/`19d7f79` (content byte-identical to `1275e47..bf8c4a2` by lane-diff\n  blob hash). IR-1 and IR-4 are BUILT AND LANDED; IR-9's measurement half is landed with its trigger\n  now armed — the toolchain print reports runner-account versions on the NEXT GOLDEN RUN, which is\n  when doyle's 2026-08-03 ruling (decide from runner-account versions, never the interactive prior)\n  becomes executable. The two golden-only steps (link probe both boxes, toolchain print both legs)\n  remain unexercised until that run — the landing does not change that caveat.\n- **As recorded pre-landing (2026-08-04, doyle):** `ci/locksmith-riders` was at `bf8c4a2` with FOUR\n  commits not contained in `origin/main` and not present in LOCKSMITH's golden head `b7b00c3`. The\n  worktree `.worktrees/hertz-ci-riders` was clean, so the work existed and was simply unlanded:\n  `1275e47` (xtask: assert a load-bearing patch pin is still in force, both ways it lapses) ·\n  `49d4805` (docs/ci: a lock-touching lane reads edges, not just the package set) ·\n  `8ed006b` (ci/golden: print the toolchain that judged the run, both legs) ·\n  `bf8c4a2` (ci/golden: measure the link before rendezvous, read the floor after the checkout that\n  clears it — the floor read AFTER its own reclaim is [[ci-runner-has-no-warm-target]]'s shape).\n- **Why it is recorded rather than quietly re-dispatched:** [[IR-1]]/[[IR-4]]/[[IR-9]] were carried\n  as DISPATCHED, which is now false in BOTH directions — the work is further along than dispatched,\n  and it also did not ship. The cause was the same agent outage that cost `#123` its build, and the\n  operator's standing rule from that drop applies here too: an outage must not be able to remove\n  work from a batch silently. Board requests got a drop comment; register entries get this.\n- **MAPPING CONFIRMED BY ITS BUILDER 2026-08-04, by REQ id rather than by recollection** — hertz\n  noted first that its own context had been cleared between building the lane and answering, and\n  declined to testify from memory about the original instrument. Everything here is either measured\n  that day or read off the commits:\n  `1275e47` → `REQ-CI-LOAD-BEARING-PATCH-PIN` ([[IR-4]] part 1, the mechanical pin guard in xtask) ·\n  `49d4805` → `REQ-LOCK-TOUCHING-LANE-PROCEDURE` ([[IR-4]] part 2, procedure in docs/GOLDEN-CI.md) ·\n  `8ed006b` → `REQ-CI-TOOLCHAIN-VERSION-PRINT` ([[IR-4]] part 3, carrying [[IR-9]]) ·\n  `bf8c4a2` → `REQ-CI-LINK-HEALTH-PROBE` ([[IR-1]], the network axis).\n- **CORRECTION TO THE GATER'S EARLIER WORDING, from the builder:** `8ed006b` does NOT discharge\n  [[IR-9]] — it discharges IR-9's MEASUREMENT half only. IR-9's other half (align the two boxes, or\n  declare one authoritative clippy leg) is held by doyle's own 2026-08-03 ruling: decide once the\n  step reports RUNNER-ACCOUNT versions, never on the interactive-account prior. IR-9 therefore stays\n  OPEN with its trigger now REACHABLE, which is a different state from \"waiting\".\n- **Gate evidence, instrument NAMED:** `cargo nextest run -p xtask` in `.worktrees/hertz-ci-riders`\n  on hfenduleam, box quiet with no runs in flight — 34 run, 34 passed, 0 skipped. Nextest rather\n  than bare `cargo test`, per [[IR-25]]. ⚠ **What that does NOT cover, stated by the builder rather\n  than discovered later:** the two golden steps the lane ADDS (link probe on both boxes, toolchain\n  print on both legs) cannot be exercised outside a golden run. The probe's three arms\n  (five-sample success, no-reply, absent-CLI) were exercised on the real boxes at commit time, and\n  that is reported as a CLAIM RECORDED AT COMMIT TIME, not as a re-verification — the kitsubito arm\n  could not be re-checked from here. This is why the lane wants a golden rather than a quiet ff.\n- **[[IR-5]]/[[IR-6]] CONDITIONAL RIDERS: CONDITION NOT MET — the answer is NO and it closes the\n  question for this lane.** Measured file set `6d291e0..bf8c4a2`: `.gitattributes`,\n  `.github/bench/link-probe.ps1`, `.github/bench/link-probe.sh`, `.github/workflows/golden.yml`,\n  `crates/xtask/src/main.rs`, `crates/xtask/tests/bench_row_parity.rs`, `docs/GOLDEN-CI.md`,\n  `traceable-reqs.toml`. Nothing under `.github/ci/`, where the nextest-summary readers and\n  count-reporting scripts live. IR-5: no consumer of nextest output touched. IR-6: no EXISTING gate\n  output changed — though the NEW output was voluntarily written to IR-6's rule (the LINK line\n  prints `samples=N/M` and the individual rtts, membership beside the count, in both shells). That\n  SHRINKS IR-6's future scope by two lines; it does not discharge it.\n- **Three mechanisms lifted from this lane's REQ titles, worth more than the lane:**\n  (a) **An instrument must not be able to RED the run, and each shell breaks that differently** —\n  bash: `| head` under `pipefail` SIGPIPEs the producer to 141, so a print step reds (trim with\n  parameter expansion instead); pwsh under GitHub's wrapper: a MISSING COMMAND is a terminating\n  error, so rustup's absence must be TESTED with `Get-Command`, never caught. One requirement, two\n  constructions, and neither is portable reasoning about the other.\n  (b) **A negative-control mutation must be COUNTED before it is trusted** — the absent-CLI arm was\n  first \"measured\" against a tree where the mutation had not taken, silently re-measuring the\n  unmutated arm and reading as a pass.\n  (c) **Jitter, not the median, is the signal on a link that mostly works** — the motivating red's\n  link ran 10..83ms and 3..75ms while IDLE, so a median-only probe reads healthy straight through\n  the failure. Both med and max rows ride the ledger.\n- **Disposition:** composes onto the next golden batch as a thin lane, NOT slipped onto main. It\n  changes the golden pipeline itself, so it wants a golden rather than a quiet ff — and while\n  v0.53.0 is untagged, any push to `main` moves the runbook's bare `git tag` off the tested sha.\n\n### IR-55 — the `spt --bins` suite wedges partway through on leaked `findstr .` PTY children; the tests at the frontier are casualties, not culprits\n\n- **Status:** OPEN, **ARMED-FOR-CAPTURE**, owned by **hertz**. Test/rig defect by the dispatch\n  split (test/CI rework is never the product builder's). Filed by doyle 2026-08-22 from the\n  TURNKEY #212 W3 gate on releases#213.\n- **CORRECTED BY REPLACEMENT the same day.** This entry first named\n  `cli::tests::adapter_profile_verbs_local_only` as the wedging test, because that is where the\n  streamed frontier stopped. **That was wrong, and the correction is the useful part of the\n  entry:** run in isolation, on the same pool and binary and with the same env, that test passes\n  in **0.02s**. So do the other two the suite later stalled on —\n  `cli::tests::shell_channels_relay_sensory_and_text_file` (0.20s) and\n  `cli::tests::resolve_proof_target_override_reads_on_disk` (0.00s), each 1 passed / 652 filtered.\n  **A frontier names where progress STOPPED, not what CAUSED it.** Naming the last test printed\n  is the same error shape as reading a stack frame as a root cause, and it would have sent hertz\n  to rewrite three innocent tests.\n- **What is actually measured:**\n  - `cargo test -p spt --bins` unfiltered sat **24 minutes** at 13.5s CPU — blocked, not spinning.\n  - Re-run with `--test-threads=1` and streaming output: stalled after **183** completed.\n  - Re-run again with that frontier test skipped: progressed to **335** completed, then stalled\n    with **two** tests simultaneously past libtest's 60-second notice. Skipping one casualty\n    simply moves the frontier, which is itself evidence the fault is not in any one test.\n  - Every wedged harness carried `findstr.exe .` children under `conhost.exe --headless`.\n    **`findstr` with no file argument reads STDIN and blocks forever.**\n  - The frontier tests are **byte-identical at `c62904e7` and at the #213 tip `3d69f77c`**\n    (function bodies hashed at both blobs), so nothing in that lane introduced this.\n- **Reading, stated as a reading rather than a conclusion:** an EARLIER test spawns the `findstr`\n  stand-in as a PTY child and does not reap it; the children accumulate across the run and a later\n  test blocks behind them. Which test leaks is NOT yet identified and this entry does not guess —\n  the next step is to bisect for the leaker rather than to touch any test at the frontier. Five\n  orphaned `findstr` processes with creation times spread across the day were observed on this box\n  independently of any single run, which is consistent with accumulation across many suite runs.\n- **Hypothesis RAISED AND NOT SUPPORTED, recorded so nobody re-runs it:** the gate scrubs\n  `OWL_SESSION_ID` / `SPT_AGENT_ID` / `SPT_ENDPOINT_ID`, and a scrubbed identity was suspected of\n  routing a normally-REFUSED test down a live PTY path. The isolation runs above were performed\n  **with the scrub applied** and passed, so the scrub alone does not produce the hang. It remains\n  unexplained why the same unfiltered command completed at 652 passed / 1 failed for another agent\n  on the same tree; do not treat the scrub as the differentiator without a fresh one-variable run.\n- **Why it is register-grade:** golden CI runs the `spt` package. A test that never returns cannot\n  red — it consumes the single self-hosted runner slot until the job timeout, which `golden.yml`'s\n  50-minute cap bounds rather than fixes. A wedge that fires only sometimes is worse than a red,\n  because the suite's green record stays intact and nobody audits it — the same self-concealing\n  shape as `exit-code-after-a-pipe-is-the-tails`.\n- **Trigger condition (ripe):** any milestone whose gate wants an unfiltered `spt --bins` sweep,\n  which is every one of them. Ripe now.\n- **REMEDY, MEASURED 2026-08-22 and it changes this entry's urgency:** the same 653 tests under\n  `cargo nextest run -p spt --bins --no-fail-fast` complete in **22.2 seconds, 653 passed, 0\n  skipped, exit 0** — no slow markers, no timeouts — on the very tree and pool where\n  `cargo test -p spt --bins` wedged indefinitely twice. **nextest runs each test in its OWN\n  process**, so a leaked `findstr` child can block only itself. This is the discriminating\n  measurement rather than a workaround reached for to get a green: **the suite is not broken; the\n  SINGLE-PROCESS harness is what lets one test's leaked child wedge every test after it.** Golden\n  CI already runs nextest, which is the likely reason this has never surfaced there — the exposure\n  is to anyone running bare `cargo test` on the `spt` package, which is every local gate.\n- **Count reconciliation, recorded so the figures are not read as a discrepancy:** runs of this\n  suite report 652 passed / 1 failed where the one failure is\n  `cli::tests::adapter_translate_proof_gates_on_commit` — the `--bins`-only artifact, which\n  refuses because `translate_proof_fixture.exe` is not built under a bins-only invocation and says\n  so in its own message. Prebuilding it (`cargo build -p spt --bin translate_proof_fixture`) makes\n  it pass: 652 + 1 = 653. Prebuild the fixture rather than carrying a known-red through every gate.\n- **⚠ AMENDED 2026-08-22 — DO NOT PREBUILD FROM THIS BULLET'S EXAMPLE.** The line above names ONE\n  fixture because one fixture is what *this* wedge needed; read as the prebuild recipe it covers a\n  fraction of the population, and it was read that way twice on one day. **The census already exists\n  in IR-21 above** (`adapters/mock`: mock-session, mock-shell, capture-player, console-mode-probe ·\n  `crates/spt-daemon`: dispatch_fixture, service_fixture, summarizer_fixture · `crates/spt`:\n  translate_proof_fixture, post_step_fixture, gh_fixture, git_fixture), together with the split that\n  matters: **cross-package sites are the hazard members; same-package builds are guaranteed by\n  construction.** Field instances, both 2026-08-22 TURNKEY #212 W4: todlando's lane red on three\n  `spt-daemon::attach_resize_capture` cells wanting `adapters/mock`'s **capture-player** (a\n  cross-package member), and doyle's head gate prebuilding the remembered pair while never running a\n  `spt-daemon` or `spt-term` suite at all. **Prebuild `--workspace --bins`, or read the\n  `build_hint` the helper already composes** (`crates/spt-term/tests/support/fixture_bin.rs:42`) —\n  five test files gate on that panic. Neither of us lacked the census; we prebuilt from memory while\n  our own register held the list.\n- **FIXTURE PREBUILD, RECURRENCE 2026-08-29 (todlando, emission lane):** the rule was\n  already banked AND I am one of its authors, and I still ate three fixture reds in a row —\n  mock-session, then capture-player, then mock-shell — each tripping in about 0.01s with a panic\n  that reads exactly like a test failure. Having the rule is not the same as applying it completely:\n  I prebuilt from RECALL (`-p spt --bins`) rather than from the rule's stronger banked form, and the\n  tell is that my fix arrived in three instalments instead of once. **TWO FACES, both structural\n  rather than careless.** (1) THE FIXTURE MAY LIVE IN ANOTHER PACKAGE — mock-session,\n  capture-player, mock-shell and console-mode-probe are all `adapters/mock` (`-p mock-adapter`), so\n  no amount of `-p spt --bins` ever produces them. (2) ENUMERATING FIXTURES BY GREPPING THEIR\n  PRE-BUILD STRINGS IS STRUCTURALLY INCOMPLETE — it finds the call sites that embed a literal\n  `pre-build: cargo build ...` string and CANNOT find mock-shell, whose helper composes the command\n  at runtime (`sibling_bin(name)` → `fixture_package(name)`), so there is no literal to match. A\n  predicate over source text cannot see a string the program builds at runtime; same blindness\n  class as the emission census's TOKEN-colon-vs-TOKEN-space predicate, met twice in one session.\n  **CLASS FIX:** never hand-list fixtures — build the whole fixture package\n  (`cargo build -p mock-adapter --bins`) or `--workspace --bins` before any\n  `--test`/`--bins`/filtered leg. Chasing named fixtures one red at a time only ever finds them one\n  at a time, and each one costs a full battery run.\n- **Named negative + settle-class result (hertz, 2026-08-23):** current main at\n  `4dd699cb7867979ca0497e7c74d8d0aaf881e9e9` did not reproduce the wedge on HFENDULEAM from\n  isolated checkout `.worktrees/ir55-findstr-bisect`. Test binaries were freshly built before the\n  diagnostic population and reused for the settle sweep; the gate environment scrub was **not**\n  applied; the installed daemon was live. The fleet snapshot taken immediately **after**, not\n  during, the sweep showed BIGNET 7 nodes / 20 endpoints, SPT_MANTLE 3 / 19, SPT_DEV 2 / 19,\n  3-of-7 peers connected, `degraded-partial`. Four startup cells that spawn `findstr` passed alone\n  and reaped their observed ConPTY children; a full single-threaded run passed 663/663 with a\n  before/after census delta of `IR55_NEW=0`. The ratified settle-class sweep then ran five\n  consecutive bare `cargo test -p spt --bins` invocations: all 663/663 green in 420.35s total,\n  with zero `findstr.exe` residents before and after. This is a named negative data point, not a\n  discharge of the intermittent filing-day measurements.\n- **Next-wedge capture protocol — do not improvise or clean first:** preserve the exact bare\n  invocation and snapshot the environment (box, checkout SHA/worktree, fresh-versus-reused test\n  binary provenance, gate-scrub state, live-daemon state, and fleet roster); stream test output to\n  durable storage so the last started and completed test names identify the frontier; census\n  `Win32_Process` immediately before the run and again while wedged, recording each `findstr.exe`\n  PID, parent PID, creation time, executable path, and command line. **Do not kill any child before\n  the second census is banked.** The 22 residents found during the 2026-08-23 investigation were\n  path-verified as `C:\\Windows\\System32\\findstr.exe`, shown to predate its live runs, banked, then\n  reaped; the pre-sweep and post-sweep resident counts were both zero.\n- **Size guess:** small if one test is missing a reap or an EOF for its stand-in child; medium if\n  the shared PTY test scaffolding needs the reap, in which case every sibling spawning the same\n  stand-in wants it. The RUN-LEVEL exposure has an answer today (nextest); the LEAK itself is\n  still worth fixing, because a leaked child per run accumulates on any box that runs the suite.\n- **Gater's craft, worth more than the entry itself:**\n  (a) The first wedge was undiagnosable because the gate script wrote every leg as\n  `cargo test … | tail -N > file` — nothing reaches disk until the command completes, so a wedged\n  leg produces an **empty file** and the process table is the only witness. **Stream to a file and\n  tail the FILE.**\n  (b) To NAME a frontier, run `--test-threads=1`: libtest prints each test's name BEFORE running\n  it, so the last incomplete line is where progress stopped.\n  (c) **Then prove the frontier test is actually at fault by running it alone** — which is the\n  step this entry originally skipped, and the one that turned a wrong entry into a right one.\n\n\n[Showing lines 2930-3200 of 6938. Use :3201 to continue]"}],"details":{"truncation":{"content":"  error anywhere) matches the SHAPE of the filed offline-but-resolvable-peer pump-stall\r\n  mechanism (dial does not fast-fail). Discrimination open; nothing here is a #199 attribution.\r\n- **Remedy:** a rig-honoured net-off switch (peer pump + discovery disabled under test unless\r\n  the test is ABOUT them) or loopback-only binding; census which e2e rigs start net consumers.\r\n  Sequencing rule: do NOT fix hermeticity into #199's face before the face is attributed — a\r\n  green bought by turning the net off would bury the mechanism unread.\r\n- **Ripe when:** #199 attribution answers whether net state is causal; else the next\r\n  hermeticity pass.\r\n- **Size:** product switch + rig adoption + census.\r\n- **Kin:** [[IR-45]] (the disk half), the subnet-pump dial-does-not-fast-fail mechanism (filed,\r\n  pump-stall RCA), [[IR-38]] (a live daemon's side effects outliving the test's intent),\r\n  releases#125 gc-spin (a conn-churn shape candidate).\r\n\r\n### IR-53 — failed-address expiry unit panics during the first 10m01s after Windows boot\r\n- **Status:** BUILT 2026-08-21 on `fix/ir53-cold-boot-instant` — LANDED in v0.59.0\r\n  (PORTER rider, pick `7b26f28d` on `assembly/porter-205`, main @`c62904e7`; register\r\n  sweep 2026-08-21 at release close) · **Origin:** todlando,\r\n  found and falsifiably measured mid-releases#204; this rider fixes the latent CI-pipeline\r\n  flake before PORTER golden.\r\n- **Measured:** `failedaddr::tests::an_expired_record_stops_matching_and_is_swept` ages an\r\n  `Instant` with `Instant::now().checked_sub(FAILED_ADDR_TTL + 1s).expect(...)`, where\r\n  `FAILED_ADDR_TTL = 600s`. Windows `Instant` counts from boot, so a host younger than 601s\r\n  cannot represent the requested stamp and panics `monotonic clock older than the TTL`.\r\n  Todlando predicted and observed the red before the threshold, then observed the identical\r\n  tree green after it; two subsequent daemon sweeps held 860/860.\r\n- **Remedy:** when the monotonic clock cannot represent the age, return through the loud\r\n  `SKIP_FAILED_ADDR_EXPIRED_SWEEP` arm naming the exact unproved property. On every warm host\r\n  the original direct aging and both expiry assertions still run unchanged; there is no\r\n  ten-minute sleep and no silent pass on the cold arm.\r\n- **Class census (untruncated):** four test-side\r\n  `Instant::now().checked_sub(...TTL/deadline...).expect(...)` patterns total. This cell is\r\n  the sole 601s member. Three siblings remain recorded, not changed in this rider:\r\n  `broker.rs:8432-8434` and `broker.rs:9198-9200` age\r\n  `CONTROLLER_WRITE_DEADLINE + 1s` (6s), while `broker.rs:10385-10388` ages\r\n  `BRAIN_WRITE_DEADLINE + 1s` (16s). Their much narrower cold-boot windows are the same\r\n  mechanism class and should use a controlled clock seam when next touched.\r\n- **Kin:** releases#204 (finder lane), [[IR-25]] (daemon-lib flake population), and\r\n  [[IR-40]] (a confident verdict without the evidence needed to make it).\r\n\r\n### IR-52 — docs-site CLI reference renders SHALLOW; help text below the rendered depth is outside the drift gate, unit-held per-REQ or held by nothing\r\n- **THIRD INSTANCE, observed 2026-08-24 (todlando, WAX-SEAL #21 W4; not acted on):** the new\r\n  `spt api seal verify|describe` FLAGS sit below the generator's rendered depth — the entry's\r\n  exact class. The W4 user page hand-documents them, which is per-page self-defense, not a\r\n  gate. Conditional-rider condition did NOT fire at W4 (no generator touch); the entry's own\r\n  trigger stands for whichever lane next touches the generator.\r\n- **Status:** BUILT 2026-08-24 on SIGNET #218 W1 T6 (todlando; doyle's intake made it the wave's\r\n  rider when the new `seal enroll-authenticator` verb forced the generator touch that armed the\r\n  trigger): `xtask` reference-gen now DESCENDS THE FULL COMMAND TREE recursively (the durable\r\n  remedy), regen published the 22 previously-unrendered leaves + the new section, and a depth\r\n  regression is a drift RED by construction. Self-holding units censused per the remedy: the\r\n  SURFACE-SECTION-SITED walk and both MONIC-TRIGGER-SECTION sited-help units are now DOUBLE-held\r\n  (published surface under the drift gate + content pins kept) — kept, not retired. · **Origin:**\r\n  todlando's #160 build report, fact flagged for the gate rather than folded silently.\r\n  (Pre-build status: open, filed 2026-08-19 — doyle, W3 #160 gate prep; second measured instance\r\n  of a class REQ-CLI-SURFACE-SECTION-SITED's own title already named for its sites.)\r\n- **What/why:** the generated `docs-site/src/cli/reference.md` renders `spt endpoint monic`\r\n  but does not descend to `monic add` / `monic update`, so the #160 strike of the maintained\r\n  kind enumeration at those two flag docs never appeared in the published reference and the\r\n  docs-drift gate CANNOT see the strike — the REQ-CLI-MONIC-TRIGGER-SECTION rendered-help\r\n  unit is the only hold. General mechanism: any help text below the generator's descent\r\n  depth is invisible to the drift gate; a deep help edit (or regression) ships unpublished\r\n  and ungated unless some REQ's unit happens to pin it. First measured instance:\r\n  REQ-CLI-SURFACE-SECTION-SITED names \"the three-deep sites the docs-site drift gate cannot\r\n  reach\" and closes them with its own pinned walk — per-REQ self-defense, not a gate.\r\n  Consequence beyond drift: adapter builders build BLIND from the public docs (DRI\r\n  protocol), so a deep-help divergence hands every adapter a thinner contract than the\r\n  operator's terminal shows.\r\n- **Remedy:** either xtask reference-gen descends the full command tree (deep help becomes\r\n  published surface the drift gate already covers), or a generic rendered-help walk over all\r\n  sites at all depths joins the drift gate; census which REQ units currently self-hold deep\r\n  sites (known: SURFACE-SECTION-SITED walk, MONIC-TRIGGER-SECTION sited-help unit).\r\n- **Ripe when:** next xtask docs-gen touch, or the first adapter filing traceable to a\r\n  deep-help divergence.\r\n- **Size:** xtask render change + regen + census of self-holding units.\r\n- **Kin:** the REQ-CLI-SURFACE-SECTION-SITED pinned walk (the per-REQ closure shape this\r\n  entry generalizes), [[IR-47]] only if its golden.yml/ci-notify surface rides the same\r\n  docs-gate window.\r\n\r\n### CI-RIDER LANE STATE — LANDED 2026-08-04 (post-v0.53.0 merge queue); history below kept for its mechanisms\r\n- **RESOLVED:** the lane rebased clean onto the post-tag queue and landed ff-only as\r\n  `2b33a47`/`2a7b016`/`d63f4ce`/`19d7f79` (content byte-identical to `1275e47..bf8c4a2` by lane-diff\r\n  blob hash). IR-1 and IR-4 are BUILT AND LANDED; IR-9's measurement half is landed with its trigger\r\n  now armed — the toolchain print reports runner-account versions on the NEXT GOLDEN RUN, which is\r\n  when doyle's 2026-08-03 ruling (decide from runner-account versions, never the interactive prior)\r\n  becomes executable. The two golden-only steps (link probe both boxes, toolchain print both legs)\r\n  remain unexercised until that run — the landing does not change that caveat.\r\n- **As recorded pre-landing (2026-08-04, doyle):** `ci/locksmith-riders` was at `bf8c4a2` with FOUR\r\n  commits not contained in `origin/main` and not present in LOCKSMITH's golden head `b7b00c3`. The\r\n  worktree `.worktrees/hertz-ci-riders` was clean, so the work existed and was simply unlanded:\r\n  `1275e47` (xtask: assert a load-bearing patch pin is still in force, both ways it lapses) ·\r\n  `49d4805` (docs/ci: a lock-touching lane reads edges, not just the package set) ·\r\n  `8ed006b` (ci/golden: print the toolchain that judged the run, both legs) ·\r\n  `bf8c4a2` (ci/golden: measure the link before rendezvous, read the floor after the checkout that\r\n  clears it — the floor read AFTER its own reclaim is [[ci-runner-has-no-warm-target]]'s shape).\r\n- **Why it is recorded rather than quietly re-dispatched:** [[IR-1]]/[[IR-4]]/[[IR-9]] were carried\r\n  as DISPATCHED, which is now false in BOTH directions — the work is further along than dispatched,\r\n  and it also did not ship. The cause was the same agent outage that cost `#123` its build, and the\r\n  operator's standing rule from that drop applies here too: an outage must not be able to remove\r\n  work from a batch silently. Board requests got a drop comment; register entries get this.\r\n- **MAPPING CONFIRMED BY ITS BUILDER 2026-08-04, by REQ id rather than by recollection** — hertz\r\n  noted first that its own context had been cleared between building the lane and answering, and\r\n  declined to testify from memory about the original instrument. Everything here is either measured\r\n  that day or read off the commits:\r\n  `1275e47` → `REQ-CI-LOAD-BEARING-PATCH-PIN` ([[IR-4]] part 1, the mechanical pin guard in xtask) ·\r\n  `49d4805` → `REQ-LOCK-TOUCHING-LANE-PROCEDURE` ([[IR-4]] part 2, procedure in docs/GOLDEN-CI.md) ·\r\n  `8ed006b` → `REQ-CI-TOOLCHAIN-VERSION-PRINT` ([[IR-4]] part 3, carrying [[IR-9]]) ·\r\n  `bf8c4a2` → `REQ-CI-LINK-HEALTH-PROBE` ([[IR-1]], the network axis).\r\n- **CORRECTION TO THE GATER'S EARLIER WORDING, from the builder:** `8ed006b` does NOT discharge\r\n  [[IR-9]] — it discharges IR-9's MEASUREMENT half only. IR-9's other half (align the two boxes, or\r\n  declare one authoritative clippy leg) is held by doyle's own 2026-08-03 ruling: decide once the\r\n  step reports RUNNER-ACCOUNT versions, never on the interactive-account prior. IR-9 therefore stays\r\n  OPEN with its trigger now REACHABLE, which is a different state from \"waiting\".\r\n- **Gate evidence, instrument NAMED:** `cargo nextest run -p xtask` in `.worktrees/hertz-ci-riders`\r\n  on hfenduleam, box quiet with no runs in flight — 34 run, 34 passed, 0 skipped. Nextest rather\r\n  than bare `cargo test`, per [[IR-25]]. ⚠ **What that does NOT cover, stated by the builder rather\r\n  than discovered later:** the two golden steps the lane ADDS (link probe on both boxes, toolchain\r\n  print on both legs) cannot be exercised outside a golden run. The probe's three arms\r\n  (five-sample success, no-reply, absent-CLI) were exercised on the real boxes at commit time, and\r\n  that is reported as a CLAIM RECORDED AT COMMIT TIME, not as a re-verification — the kitsubito arm\r\n  could not be re-checked from here. This is why the lane wants a golden rather than a quiet ff.\r\n- **[[IR-5]]/[[IR-6]] CONDITIONAL RIDERS: CONDITION NOT MET — the answer is NO and it closes the\r\n  question for this lane.** Measured file set `6d291e0..bf8c4a2`: `.gitattributes`,\r\n  `.github/bench/link-probe.ps1`, `.github/bench/link-probe.sh`, `.github/workflows/golden.yml`,\r\n  `crates/xtask/src/main.rs`, `crates/xtask/tests/bench_row_parity.rs`, `docs/GOLDEN-CI.md`,\r\n  `traceable-reqs.toml`. Nothing under `.github/ci/`, where the nextest-summary readers and\r\n  count-reporting scripts live. IR-5: no consumer of nextest output touched. IR-6: no EXISTING gate\r\n  output changed — though the NEW output was voluntarily written to IR-6's rule (the LINK line\r\n  prints `samples=N/M` and the individual rtts, membership beside the count, in both shells). That\r\n  SHRINKS IR-6's future scope by two lines; it does not discharge it.\r\n- **Three mechanisms lifted from this lane's REQ titles, worth more than the lane:**\r\n  (a) **An instrument must not be able to RED the run, and each shell breaks that differently** —\r\n  bash: `| head` under `pipefail` SIGPIPEs the producer to 141, so a print step reds (trim with\r\n  parameter expansion instead); pwsh under GitHub's wrapper: a MISSING COMMAND is a terminating\r\n  error, so rustup's absence must be TESTED with `Get-Command`, never caught. One requirement, two\r\n  constructions, and neither is portable reasoning about the other.\r\n  (b) **A negative-control mutation must be COUNTED before it is trusted** — the absent-CLI arm was\r\n  first \"measured\" against a tree where the mutation had not taken, silently re-measuring the\r\n  unmutated arm and reading as a pass.\r\n  (c) **Jitter, not the median, is the signal on a link that mostly works** — the motivating red's\r\n  link ran 10..83ms and 3..75ms while IDLE, so a median-only probe reads healthy straight through\r\n  the failure. Both med and max rows ride the ledger.\r\n- **Disposition:** composes onto the next golden batch as a thin lane, NOT slipped onto main. It\r\n  changes the golden pipeline itself, so it wants a golden rather than a quiet ff — and while\r\n  v0.53.0 is untagged, any push to `main` moves the runbook's bare `git tag` off the tested sha.\r\n\r\n### IR-55 — the `spt --bins` suite wedges partway through on leaked `findstr .` PTY children; the tests at the frontier are casualties, not culprits\r\n\r\n- **Status:** OPEN, **ARMED-FOR-CAPTURE**, owned by **hertz**. Test/rig defect by the dispatch\r\n  split (test/CI rework is never the product builder's). Filed by doyle 2026-08-22 from the\r\n  TURNKEY #212 W3 gate on releases#213.\r\n- **CORRECTED BY REPLACEMENT the same day.** This entry first named\r\n  `cli::tests::adapter_profile_verbs_local_only` as the wedging test, because that is where the\r\n  streamed frontier stopped. **That was wrong, and the correction is the useful part of the\r\n  entry:** run in isolation, on the same pool and binary and with the same env, that test passes\r\n  in **0.02s**. So do the other two the suite later stalled on —\r\n  `cli::tests::shell_channels_relay_sensory_and_text_file` (0.20s) and\r\n  `cli::tests::resolve_proof_target_override_reads_on_disk` (0.00s), each 1 passed / 652 filtered.\r\n  **A frontier names where progress STOPPED, not what CAUSED it.** Naming the last test printed\r\n  is the same error shape as reading a stack frame as a root cause, and it would have sent hertz\r\n  to rewrite three innocent tests.\r\n- **What is actually measured:**\r\n  - `cargo test -p spt --bins` unfiltered sat **24 minutes** at 13.5s CPU — blocked, not spinning.\r\n  - Re-run with `--test-threads=1` and streaming output: stalled after **183** completed.\r\n  - Re-run again with that frontier test skipped: progressed to **335** completed, then stalled\r\n    with **two** tests simultaneously past libtest's 60-second notice. Skipping one casualty\r\n    simply moves the frontier, which is itself evidence the fault is not in any one test.\r\n  - Every wedged harness carried `findstr.exe .` children under `conhost.exe --headless`.\r\n    **`findstr` with no file argument reads STDIN and blocks forever.**\r\n  - The frontier tests are **byte-identical at `c62904e7` and at the #213 tip `3d69f77c`**\r\n    (function bodies hashed at both blobs), so nothing in that lane introduced this.\r\n- **Reading, stated as a reading rather than a conclusion:** an EARLIER test spawns the `findstr`\r\n  stand-in as a PTY child and does not reap it; the children accumulate across the run and a later\r\n  test blocks behind them. Which test leaks is NOT yet identified and this entry does not guess —\r\n  the next step is to bisect for the leaker rather than to touch any test at the frontier. Five\r\n  orphaned `findstr` processes with creation times spread across the day were observed on this box\r\n  independently of any single run, which is consistent with accumulation across many suite runs.\r\n- **Hypothesis RAISED AND NOT SUPPORTED, recorded so nobody re-runs it:** the gate scrubs\r\n  `OWL_SESSION_ID` / `SPT_AGENT_ID` / `SPT_ENDPOINT_ID`, and a scrubbed identity was suspected of\r\n  routing a normally-REFUSED test down a live PTY path. The isolation runs above were performed\r\n  **with the scrub applied** and passed, so the scrub alone does not produce the hang. It remains\r\n  unexplained why the same unfiltered command completed at 652 passed / 1 failed for another agent\r\n  on the same tree; do not treat the scrub as the differentiator without a fresh one-variable run.\r\n- **Why it is register-grade:** golden CI runs the `spt` package. A test that never returns cannot\r\n  red — it consumes the single self-hosted runner slot until the job timeout, which `golden.yml`'s\r\n  50-minute cap bounds rather than fixes. A wedge that fires only sometimes is worse than a red,\r\n  because the suite's green record stays intact and nobody audits it — the same self-concealing\r\n  shape as `exit-code-after-a-pipe-is-the-tails`.\r\n- **Trigger condition (ripe):** any milestone whose gate wants an unfiltered `spt --bins` sweep,\r\n  which is every one of them. Ripe now.\r\n- **REMEDY, MEASURED 2026-08-22 and it changes this entry's urgency:** the same 653 tests under\r\n  `cargo nextest run -p spt --bins --no-fail-fast` complete in **22.2 seconds, 653 passed, 0\r\n  skipped, exit 0** — no slow markers, no timeouts — on the very tree and pool where\r\n  `cargo test -p spt --bins` wedged indefinitely twice. **nextest runs each test in its OWN\r\n  process**, so a leaked `findstr` child can block only itself. This is the discriminating\r\n  measurement rather than a workaround reached for to get a green: **the suite is not broken; the\r\n  SINGLE-PROCESS harness is what lets one test's leaked child wedge every test after it.** Golden\r\n  CI already runs nextest, which is the likely reason this has never surfaced there — the exposure\r\n  is to anyone running bare `cargo test` on the `spt` package, which is every local gate.\r\n- **Count reconciliation, recorded so the figures are not read as a discrepancy:** runs of this\r\n  suite report 652 passed / 1 failed where the one failure is\r\n  `cli::tests::adapter_translate_proof_gates_on_commit` — the `--bins`-only artifact, which\r\n  refuses because `translate_proof_fixture.exe` is not built under a bins-only invocation and says\r\n  so in its own message. Prebuilding it (`cargo build -p spt --bin translate_proof_fixture`) makes\r\n  it pass: 652 + 1 = 653. Prebuild the fixture rather than carrying a known-red through every gate.\r\n- **⚠ AMENDED 2026-08-22 — DO NOT PREBUILD FROM THIS BULLET'S EXAMPLE.** The line above names ONE\r\n  fixture because one fixture is what *this* wedge needed; read as the prebuild recipe it covers a\r\n  fraction of the population, and it was read that way twice on one day. **The census already exists\r\n  in IR-21 above** (`adapters/mock`: mock-session, mock-shell, capture-player, console-mode-probe ·\r\n  `crates/spt-daemon`: dispatch_fixture, service_fixture, summarizer_fixture · `crates/spt`:\r\n  translate_proof_fixture, post_step_fixture, gh_fixture, git_fixture), together with the split that\r\n  matters: **cross-package sites are the hazard members; same-package builds are guaranteed by\r\n  construction.** Field instances, both 2026-08-22 TURNKEY #212 W4: todlando's lane red on three\r\n  `spt-daemon::attach_resize_capture` cells wanting `adapters/mock`'s **capture-player** (a\r\n  cross-package member), and doyle's head gate prebuilding the remembered pair while never running a\r\n  `spt-daemon` or `spt-term` suite at all. **Prebuild `--workspace --bins`, or read the\r\n  `build_hint` the helper already composes** (`crates/spt-term/tests/support/fixture_bin.rs:42`) —\r\n  five test files gate on that panic. Neither of us lacked the census; we prebuilt from memory while\r\n  our own register held the list.\r\n- **FIXTURE PREBUILD, RECURRENCE 2026-08-29 (todlando, emission lane):** the rule was\r\n  already banked AND I am one of its authors, and I still ate three fixture reds in a row —\r\n  mock-session, then capture-player, then mock-shell — each tripping in about 0.01s with a panic\r\n  that reads exactly like a test failure. Having the rule is not the same as applying it completely:\r\n  I prebuilt from RECALL (`-p spt --bins`) rather than from the rule's stronger banked form, and the\r\n  tell is that my fix arrived in three instalments instead of once. **TWO FACES, both structural\r\n  rather than careless.** (1) THE FIXTURE MAY LIVE IN ANOTHER PACKAGE — mock-session,\r\n  capture-player, mock-shell and console-mode-probe are all `adapters/mock` (`-p mock-adapter`), so\r\n  no amount of `-p spt --bins` ever produces them. (2) ENUMERATING FIXTURES BY GREPPING THEIR\r\n  PRE-BUILD STRINGS IS STRUCTURALLY INCOMPLETE — it finds the call sites that embed a literal\r\n  `pre-build: cargo build ...` string and CANNOT find mock-shell, whose helper composes the command\r\n  at runtime (`sibling_bin(name)` → `fixture_package(name)`), so there is no literal to match. A\r\n  predicate over source text cannot see a string the program builds at runtime; same blindness\r\n  class as the emission census's TOKEN-colon-vs-TOKEN-space predicate, met twice in one session.\r\n  **CLASS FIX:** never hand-list fixtures — build the whole fixture package\r\n  (`cargo build -p mock-adapter --bins`) or `--workspace --bins` before any\r\n  `--test`/`--bins`/filtered leg. Chasing named fixtures one red at a time only ever finds them one\r\n  at a time, and each one costs a full battery run.\r\n- **Named negative + settle-class result (hertz, 2026-08-23):** current main at\r\n  `4dd699cb7867979ca0497e7c74d8d0aaf881e9e9` did not reproduce the wedge on HFENDULEAM from\r\n  isolated checkout `.worktrees/ir55-findstr-bisect`. Test binaries were freshly built before the\r\n  diagnostic population and reused for the settle sweep; the gate environment scrub was **not**\r\n  applied; the installed daemon was live. The fleet snapshot taken immediately **after**, not\r\n  during, the sweep showed BIGNET 7 nodes / 20 endpoints, SPT_MANTLE 3 / 19, SPT_DEV 2 / 19,\r\n  3-of-7 peers connected, `degraded-partial`. Four startup cells that spawn `findstr` passed alone\r\n  and reaped their observed ConPTY children; a full single-threaded run passed 663/663 with a\r\n  before/after census delta of `IR55_NEW=0`. The ratified settle-class sweep then ran five\r\n  consecutive bare `cargo test -p spt --bins` invocations: all 663/663 green in 420.35s total,\r\n  with zero `findstr.exe` residents before and after. This is a named negative data point, not a\r\n  discharge of the intermittent filing-day measurements.\r\n- **Next-wedge capture protocol — do not improvise or clean first:** preserve the exact bare\r\n  invocation and snapshot the environment (box, checkout SHA/worktree, fresh-versus-reused test\r\n  binary provenance, gate-scrub state, live-daemon state, and fleet roster); stream test output to\r\n  durable storage so the last started and completed test names identify the frontier; census\r\n  `Win32_Process` immediately before the run and again while wedged, recording each `findstr.exe`\r\n  PID, parent PID, creation time, executable path, and command line. **Do not kill any child before\r\n  the second census is banked.** The 22 residents found during the 2026-08-23 investigation were\r\n  path-verified as `C:\\Windows\\System32\\findstr.exe`, shown to predate its live runs, banked, then\r\n  reaped; the pre-sweep and post-sweep resident counts were both zero.\r\n- **Size guess:** small if one test is missing a reap or an EOF for its stand-in child; medium if\r\n  the shared PTY test scaffolding needs the reap, in which case every sibling spawning the same\r\n  stand-in wants it. The RUN-LEVEL exposure has an answer today (nextest); the LEAK itself is\r\n  still worth fixing, because a leaked child per run accumulates on any box that runs the suite.\r\n- **Gater's craft, worth more than the entry itself:**\r\n  (a) The first wedge was undiagnosable because the gate script wrote every leg as\r\n  `cargo test … | tail -N > file` — nothing reaches disk until the command completes, so a wedged\r\n  leg produces an **empty file** and the process table is the only witness. **Stream to a file and\r\n  tail the FILE.**\r\n  (b) To NAME a frontier, run `--test-threads=1`: libtest prints each test's name BEFORE running\r\n  it, so the last incomplete line is where progress stopped.\r\n  (c) **Then prove the frontier test is actually at fault by running it alone** — which is the\r\n  step this entry originally skipped, and the one that turned a wrong entry into a right one.\r\n\r","truncated":true,"truncatedBy":"lines","totalLines":4009,"totalBytes":23771,"outputLines":271,"outputBytes":23771,"lastLinePartial":false,"firstLineExceedsLimit":false},"totalLines":6938,"displayContent":{"text":"  error anywhere) matches the SHAPE of the filed offline-but-resolvable-peer pump-stall\r\n  mechanism (dial does not fast-fail). Discrimination open; nothing here is a #199 attribution.\r\n- **Remedy:** a rig-honoured net-off switch (peer pump + discovery disabled under test unless\r\n  the test is ABOUT them) or loopback-only binding; census which e2e rigs start net consumers.\r\n  Sequencing rule: do NOT fix hermeticity into #199's face before the face is attributed — a\r\n  green bought by turning the net off would bury the mechanism unread.\r\n- **Ripe when:** #199 attribution answers whether net state is causal; else the next\r\n  hermeticity pass.\r\n- **Size:** product switch + rig adoption + census.\r\n- **Kin:** [[IR-45]] (the disk half), the subnet-pump dial-does-not-fast-fail mechanism (filed,\r\n  pump-stall RCA), [[IR-38]] (a live daemon's side effects outliving the test's intent),\r\n  releases#125 gc-spin (a conn-churn shape candidate).\r\n\r\n### IR-53 — failed-address expiry unit panics during the first 10m01s after Windows boot\r\n- **Status:** BUILT 2026-08-21 on `fix/ir53-cold-boot-instant` — LANDED in v0.59.0\r\n  (PORTER rider, pick `7b26f28d` on `assembly/porter-205`, main @`c62904e7`; register\r\n  sweep 2026-08-21 at release close) · **Origin:** todlando,\r\n  found and falsifiably measured mid-releases#204; this rider fixes the latent CI-pipeline\r\n  flake before PORTER golden.\r\n- **Measured:** `failedaddr::tests::an_expired_record_stops_matching_and_is_swept` ages an\r\n  `Instant` with `Instant::now().checked_sub(FAILED_ADDR_TTL + 1s).expect(...)`, where\r\n  `FAILED_ADDR_TTL = 600s`. Windows `Instant` counts from boot, so a host younger than 601s\r\n  cannot represent the requested stamp and panics `monotonic clock older than the TTL`.\r\n  Todlando predicted and observed the red before the threshold, then observed the identical\r\n  tree green after it; two subsequent daemon sweeps held 860/860.\r\n- **Remedy:** when the monotonic clock cannot represent the age, return through the loud\r\n  `SKIP_FAILED_ADDR_EXPIRED_SWEEP` arm naming the exact unproved property. On every warm host\r\n  the original direct aging and both expiry assertions still run unchanged; there is no\r\n  ten-minute sleep and no silent pass on the cold arm.\r\n- **Class census (untruncated):** four test-side\r\n  `Instant::now().checked_sub(...TTL/deadline...).expect(...)` patterns total. This cell is\r\n  the sole 601s member. Three siblings remain recorded, not changed in this rider:\r\n  `broker.rs:8432-8434` and `broker.rs:9198-9200` age\r\n  `CONTROLLER_WRITE_DEADLINE + 1s` (6s), while `broker.rs:10385-10388` ages\r\n  `BRAIN_WRITE_DEADLINE + 1s` (16s). Their much narrower cold-boot windows are the same\r\n  mechanism class and should use a controlled clock seam when next touched.\r\n- **Kin:** releases#204 (finder lane), [[IR-25]] (daemon-lib flake population), and\r\n  [[IR-40]] (a confident verdict without the evidence needed to make it).\r\n\r\n### IR-52 — docs-site CLI reference renders SHALLOW; help text below the rendered depth is outside the drift gate, unit-held per-REQ or held by nothing\r\n- **THIRD INSTANCE, observed 2026-08-24 (todlando, WAX-SEAL #21 W4; not acted on):** the new\r\n  `spt api seal verify|describe` FLAGS sit below the generator's rendered depth — the entry's\r\n  exact class. The W4 user page hand-documents them, which is per-page self-defense, not a\r\n  gate. Conditional-rider condition did NOT fire at W4 (no generator touch); the entry's own\r\n  trigger stands for whichever lane next touches the generator.\r\n- **Status:** BUILT 2026-08-24 on SIGNET #218 W1 T6 (todlando; doyle's intake made it the wave's\r\n  rider when the new `seal enroll-authenticator` verb forced the generator touch that armed the\r\n  trigger): `xtask` reference-gen now DESCENDS THE FULL COMMAND TREE recursively (the durable\r\n  remedy), regen published the 22 previously-unrendered leaves + the new section, and a depth\r\n  regression is a drift RED by construction. Self-holding units censused per the remedy: the\r\n  SURFACE-SECTION-SITED walk and both MONIC-TRIGGER-SECTION sited-help units are now DOUBLE-held\r\n  (published surface under the drift gate + content pins kept) — kept, not retired. · **Origin:**\r\n  todlando's #160 build report, fact flagged for the gate rather than folded silently.\r\n  (Pre-build status: open, filed 2026-08-19 — doyle, W3 #160 gate prep; second measured instance\r\n  of a class REQ-CLI-SURFACE-SECTION-SITED's own title already named for its sites.)\r\n- **What/why:** the generated `docs-site/src/cli/reference.md` renders `spt endpoint monic`\r\n  but does not descend to `monic add` / `monic update`, so the #160 strike of the maintained\r\n  kind enumeration at those two flag docs never appeared in the published reference and the\r\n  docs-drift gate CANNOT see the strike — the REQ-CLI-MONIC-TRIGGER-SECTION rendered-help\r\n  unit is the only hold. General mechanism: any help text below the generator's descent\r\n  depth is invisible to the drift gate; a deep help edit (or regression) ships unpublished\r\n  and ungated unless some REQ's unit happens to pin it. First measured instance:\r\n  REQ-CLI-SURFACE-SECTION-SITED names \"the three-deep sites the docs-site drift gate cannot\r\n  reach\" and closes them with its own pinned walk — per-REQ self-defense, not a gate.\r\n  Consequence beyond drift: adapter builders build BLIND from the public docs (DRI\r\n  protocol), so a deep-help divergence hands every adapter a thinner contract than the\r\n  operator's terminal shows.\r\n- **Remedy:** either xtask reference-gen descends the full command tree (deep help becomes\r\n  published surface the drift gate already covers), or a generic rendered-help walk over all\r\n  sites at all depths joins the drift gate; census which REQ units currently self-hold deep\r\n  sites (known: SURFACE-SECTION-SITED walk, MONIC-TRIGGER-SECTION sited-help unit).\r\n- **Ripe when:** next xtask docs-gen touch, or the first adapter filing traceable to a\r\n  deep-help divergence.\r\n- **Size:** xtask render change + regen + census of self-holding units.\r\n- **Kin:** the REQ-CLI-SURFACE-SECTION-SITED pinned walk (the per-REQ closure shape this\r\n  entry generalizes), [[IR-47]] only if its golden.yml/ci-notify surface rides the same\r\n  docs-gate window.\r\n\r\n### CI-RIDER LANE STATE — LANDED 2026-08-04 (post-v0.53.0 merge queue); history below kept for its mechanisms\r\n- **RESOLVED:** the lane rebased clean onto the post-tag queue and landed ff-only as\r\n  `2b33a47`/`2a7b016`/`d63f4ce`/`19d7f79` (content byte-identical to `1275e47..bf8c4a2` by lane-diff\r\n  blob hash). IR-1 and IR-4 are BUILT AND LANDED; IR-9's measurement half is landed with its trigger\r\n  now armed — the toolchain print reports runner-account versions on the NEXT GOLDEN RUN, which is\r\n  when doyle's 2026-08-03 ruling (decide from runner-account versions, never the interactive prior)\r\n  becomes executable. The two golden-only steps (link probe both boxes, toolchain print both legs)\r\n  remain unexercised until that run — the landing does not change that caveat.\r\n- **As recorded pre-landing (2026-08-04, doyle):** `ci/locksmith-riders` was at `bf8c4a2` with FOUR\r\n  commits not contained in `origin/main` and not present in LOCKSMITH's golden head `b7b00c3`. The\r\n  worktree `.worktrees/hertz-ci-riders` was clean, so the work existed and was simply unlanded:\r\n  `1275e47` (xtask: assert a load-bearing patch pin is still in force, both ways it lapses) ·\r\n  `49d4805` (docs/ci: a lock-touching lane reads edges, not just the package set) ·\r\n  `8ed006b` (ci/golden: print the toolchain that judged the run, both legs) ·\r\n  `bf8c4a2` (ci/golden: measure the link before rendezvous, read the floor after the checkout that\r\n  clears it — the floor read AFTER its own reclaim is [[ci-runner-has-no-warm-target]]'s shape).\r\n- **Why it is recorded rather than quietly re-dispatched:** [[IR-1]]/[[IR-4]]/[[IR-9]] were carried\r\n  as DISPATCHED, which is now false in BOTH directions — the work is further along than dispatched,\r\n  and it also did not ship. The cause was the same agent outage that cost `#123` its build, and the\r\n  operator's standing rule from that drop applies here too: an outage must not be able to remove\r\n  work from a batch silently. Board requests got a drop comment; register entries get this.\r\n- **MAPPING CONFIRMED BY ITS BUILDER 2026-08-04, by REQ id rather than by recollection** — hertz\r\n  noted first that its own context had been cleared between building the lane and answering, and\r\n  declined to testify from memory about the original instrument. Everything here is either measured\r\n  that day or read off the commits:\r\n  `1275e47` → `REQ-CI-LOAD-BEARING-PATCH-PIN` ([[IR-4]] part 1, the mechanical pin guard in xtask) ·\r\n  `49d4805` → `REQ-LOCK-TOUCHING-LANE-PROCEDURE` ([[IR-4]] part 2, procedure in docs/GOLDEN-CI.md) ·\r\n  `8ed006b` → `REQ-CI-TOOLCHAIN-VERSION-PRINT` ([[IR-4]] part 3, carrying [[IR-9]]) ·\r\n  `bf8c4a2` → `REQ-CI-LINK-HEALTH-PROBE` ([[IR-1]], the network axis).\r\n- **CORRECTION TO THE GATER'S EARLIER WORDING, from the builder:** `8ed006b` does NOT discharge\r\n  [[IR-9]] — it discharges IR-9's MEASUREMENT half only. IR-9's other half (align the two boxes, or\r\n  declare one authoritative clippy leg) is held by doyle's own 2026-08-03 ruling: decide once the\r\n  step reports RUNNER-ACCOUNT versions, never on the interactive-account prior. IR-9 therefore stays\r\n  OPEN with its trigger now REACHABLE, which is a different state from \"waiting\".\r\n- **Gate evidence, instrument NAMED:** `cargo nextest run -p xtask` in `.worktrees/hertz-ci-riders`\r\n  on hfenduleam, box quiet with no runs in flight — 34 run, 34 passed, 0 skipped. Nextest rather\r\n  than bare `cargo test`, per [[IR-25]]. ⚠ **What that does NOT cover, stated by the builder rather\r\n  than discovered later:** the two golden steps the lane ADDS (link probe on both boxes, toolchain\r\n  print on both legs) cannot be exercised outside a golden run. The probe's three arms\r\n  (five-sample success, no-reply, absent-CLI) were exercised on the real boxes at commit time, and\r\n  that is reported as a CLAIM RECORDED AT COMMIT TIME, not as a re-verification — the kitsubito arm\r\n  could not be re-checked from here. This is why the lane wants a golden rather than a quiet ff.\r\n- **[[IR-5]]/[[IR-6]] CONDITIONAL RIDERS: CONDITION NOT MET — the answer is NO and it closes the\r\n  question for this lane.** Measured file set `6d291e0..bf8c4a2`: `.gitattributes`,\r\n  `.github/bench/link-probe.ps1`, `.github/bench/link-probe.sh`, `.github/workflows/golden.yml`,\r\n  `crates/xtask/src/main.rs`, `crates/xtask/tests/bench_row_parity.rs`, `docs/GOLDEN-CI.md`,\r\n  `traceable-reqs.toml`. Nothing under `.github/ci/`, where the nextest-summary readers and\r\n  count-reporting scripts live. IR-5: no consumer of nextest output touched. IR-6: no EXISTING gate\r\n  output changed — though the NEW output was voluntarily written to IR-6's rule (the LINK line\r\n  prints `samples=N/M` and the individual rtts, membership beside the count, in both shells). That\r\n  SHRINKS IR-6's future scope by two lines; it does not discharge it.\r\n- **Three mechanisms lifted from this lane's REQ titles, worth more than the lane:**\r\n  (a) **An instrument must not be able to RED the run, and each shell breaks that differently** —\r\n  bash: `| head` under `pipefail` SIGPIPEs the producer to 141, so a print step reds (trim with\r\n  parameter expansion instead); pwsh under GitHub's wrapper: a MISSING COMMAND is a terminating\r\n  error, so rustup's absence must be TESTED with `Get-Command`, never caught. One requirement, two\r\n  constructions, and neither is portable reasoning about the other.\r\n  (b) **A negative-control mutation must be COUNTED before it is trusted** — the absent-CLI arm was\r\n  first \"measured\" against a tree where the mutation had not taken, silently re-measuring the\r\n  unmutated arm and reading as a pass.\r\n  (c) **Jitter, not the median, is the signal on a link that mostly works** — the motivating red's\r\n  link ran 10..83ms and 3..75ms while IDLE, so a median-only probe reads healthy straight through\r\n  the failure. Both med and max rows ride the ledger.\r\n- **Disposition:** composes onto the next golden batch as a thin lane, NOT slipped onto main. It\r\n  changes the golden pipeline itself, so it wants a golden rather than a quiet ff — and while\r\n  v0.53.0 is untagged, any push to `main` moves the runbook's bare `git tag` off the tested sha.\r\n\r\n### IR-55 — the `spt --bins` suite wedges partway through on leaked `findstr .` PTY children; the tests at the frontier are casualties, not culprits\r\n\r\n- **Status:** OPEN, **ARMED-FOR-CAPTURE**, owned by **hertz**. Test/rig defect by the dispatch\r\n  split (test/CI rework is never the product builder's). Filed by doyle 2026-08-22 from the\r\n  TURNKEY #212 W3 gate on releases#213.\r\n- **CORRECTED BY REPLACEMENT the same day.** This entry first named\r\n  `cli::tests::adapter_profile_verbs_local_only` as the wedging test, because that is where the\r\n  streamed frontier stopped. **That was wrong, and the correction is the useful part of the\r\n  entry:** run in isolation, on the same pool and binary and with the same env, that test passes\r\n  in **0.02s**. So do the other two the suite later stalled on —\r\n  `cli::tests::shell_channels_relay_sensory_and_text_file` (0.20s) and\r\n  `cli::tests::resolve_proof_target_override_reads_on_disk` (0.00s), each 1 passed / 652 filtered.\r\n  **A frontier names where progress STOPPED, not what CAUSED it.** Naming the last test printed\r\n  is the same error shape as reading a stack frame as a root cause, and it would have sent hertz\r\n  to rewrite three innocent tests.\r\n- **What is actually measured:**\r\n  - `cargo test -p spt --bins` unfiltered sat **24 minutes** at 13.5s CPU — blocked, not spinning.\r\n  - Re-run with `--test-threads=1` and streaming output: stalled after **183** completed.\r\n  - Re-run again with that frontier test skipped: progressed to **335** completed, then stalled\r\n    with **two** tests simultaneously past libtest's 60-second notice. Skipping one casualty\r\n    simply moves the frontier, which is itself evidence the fault is not in any one test.\r\n  - Every wedged harness carried `findstr.exe .` children under `conhost.exe --headless`.\r\n    **`findstr` with no file argument reads STDIN and blocks forever.**\r\n  - The frontier tests are **byte-identical at `c62904e7` and at the #213 tip `3d69f77c`**\r\n    (function bodies hashed at both blobs), so nothing in that lane introduced this.\r\n- **Reading, stated as a reading rather than a conclusion:** an EARLIER test spawns the `findstr`\r\n  stand-in as a PTY child and does not reap it; the children accumulate across the run and a later\r\n  test blocks behind them. Which test leaks is NOT yet identified and this entry does not guess —\r\n  the next step is to bisect for the leaker rather than to touch any test at the frontier. Five\r\n  orphaned `findstr` processes with creation times spread across the day were observed on this box\r\n  independently of any single run, which is consistent with accumulation across many suite runs.\r\n- **Hypothesis RAISED AND NOT SUPPORTED, recorded so nobody re-runs it:** the gate scrubs\r\n  `OWL_SESSION_ID` / `SPT_AGENT_ID` / `SPT_ENDPOINT_ID`, and a scrubbed identity was suspected of\r\n  routing a normally-REFUSED test down a live PTY path. The isolation runs above were performed\r\n  **with the scrub applied** and passed, so the scrub alone does not produce the hang. It remains\r\n  unexplained why the same unfiltered command completed at 652 passed / 1 failed for another agent\r\n  on the same tree; do not treat the scrub as the differentiator without a fresh one-variable run.\r\n- **Why it is register-grade:** golden CI runs the `spt` package. A test that never returns cannot\r\n  red — it consumes the single self-hosted runner slot until the job timeout, which `golden.yml`'s\r\n  50-minute cap bounds rather than fixes. A wedge that fires only sometimes is worse than a red,\r\n  because the suite's green record stays intact and nobody audits it — the same self-concealing\r\n  shape as `exit-code-after-a-pipe-is-the-tails`.\r\n- **Trigger condition (ripe):** any milestone whose gate wants an unfiltered `spt --bins` sweep,\r\n  which is every one of them. Ripe now.\r\n- **REMEDY, MEASURED 2026-08-22 and it changes this entry's urgency:** the same 653 tests under\r\n  `cargo nextest run -p spt --bins --no-fail-fast` complete in **22.2 seconds, 653 passed, 0\r\n  skipped, exit 0** — no slow markers, no timeouts — on the very tree and pool where\r\n  `cargo test -p spt --bins` wedged indefinitely twice. **nextest runs each test in its OWN\r\n  process**, so a leaked `findstr` child can block only itself. This is the discriminating\r\n  measurement rather than a workaround reached for to get a green: **the suite is not broken; the\r\n  SINGLE-PROCESS harness is what lets one test's leaked child wedge every test after it.** Golden\r\n  CI already runs nextest, which is the likely reason this has never surfaced there — the exposure\r\n  is to anyone running bare `cargo test` on the `spt` package, which is every local gate.\r\n- **Count reconciliation, recorded so the figures are not read as a discrepancy:** runs of this\r\n  suite report 652 passed / 1 failed where the one failure is\r\n  `cli::tests::adapter_translate_proof_gates_on_commit` — the `--bins`-only artifact, which\r\n  refuses because `translate_proof_fixture.exe` is not built under a bins-only invocation and says\r\n  so in its own message. Prebuilding it (`cargo build -p spt --bin translate_proof_fixture`) makes\r\n  it pass: 652 + 1 = 653. Prebuild the fixture rather than carrying a known-red through every gate.\r\n- **⚠ AMENDED 2026-08-22 — DO NOT PREBUILD FROM THIS BULLET'S EXAMPLE.** The line above names ONE\r\n  fixture because one fixture is what *this* wedge needed; read as the prebuild recipe it covers a\r\n  fraction of the population, and it was read that way twice on one day. **The census already exists\r\n  in IR-21 above** (`adapters/mock`: mock-session, mock-shell, capture-player, console-mode-probe ·\r\n  `crates/spt-daemon`: dispatch_fixture, service_fixture, summarizer_fixture · `crates/spt`:\r\n  translate_proof_fixture, post_step_fixture, gh_fixture, git_fixture), together with the split that\r\n  matters: **cross-package sites are the hazard members; same-package builds are guaranteed by\r\n  construction.** Field instances, both 2026-08-22 TURNKEY #212 W4: todlando's lane red on three\r\n  `spt-daemon::attach_resize_capture` cells wanting `adapters/mock`'s **capture-player** (a\r\n  cross-package member), and doyle's head gate prebuilding the remembered pair while never running a\r\n  `spt-daemon` or `spt-term` suite at all. **Prebuild `--workspace --bins`, or read the\r\n  `build_hint` the helper already composes** (`crates/spt-term/tests/support/fixture_bin.rs:42`) —\r\n  five test files gate on that panic. Neither of us lacked the census; we prebuilt from memory while\r\n  our own register held the list.\r\n- **FIXTURE PREBUILD, RECURRENCE 2026-08-29 (todlando, emission lane):** the rule was\r\n  already banked AND I am one of its authors, and I still ate three fixture reds in a row —\r\n  mock-session, then capture-player, then mock-shell — each tripping in about 0.01s with a panic\r\n  that reads exactly like a test failure. Having the rule is not the same as applying it completely:\r\n  I prebuilt from RECALL (`-p spt --bins`) rather than from the rule's stronger banked form, and the\r\n  tell is that my fix arrived in three instalments instead of once. **TWO FACES, both structural\r\n  rather than careless.** (1) THE FIXTURE MAY LIVE IN ANOTHER PACKAGE — mock-session,\r\n  capture-player, mock-shell and console-mode-probe are all `adapters/mock` (`-p mock-adapter`), so\r\n  no amount of `-p spt --bins` ever produces them. (2) ENUMERATING FIXTURES BY GREPPING THEIR\r\n  PRE-BUILD STRINGS IS STRUCTURALLY INCOMPLETE — it finds the call sites that embed a literal\r\n  `pre-build: cargo build ...` string and CANNOT find mock-shell, whose helper composes the command\r\n  at runtime (`sibling_bin(name)` → `fixture_package(name)`), so there is no literal to match. A\r\n  predicate over source text cannot see a string the program builds at runtime; same blindness\r\n  class as the emission census's TOKEN-colon-vs-TOKEN-space predicate, met twice in one session.\r\n  **CLASS FIX:** never hand-list fixtures — build the whole fixture package\r\n  (`cargo build -p mock-adapter --bins`) or `--workspace --bins` before any\r\n  `--test`/`--bins`/filtered leg. Chasing named fixtures one red at a time only ever finds them one\r\n  at a time, and each one costs a full battery run.\r\n- **Named negative + settle-class result (hertz, 2026-08-23):** current main at\r\n  `4dd699cb7867979ca0497e7c74d8d0aaf881e9e9` did not reproduce the wedge on HFENDULEAM from\r\n  isolated checkout `.worktrees/ir55-findstr-bisect`. Test binaries were freshly built before the\r\n  diagnostic population and reused for the settle sweep; the gate environment scrub was **not**\r\n  applied; the installed daemon was live. The fleet snapshot taken immediately **after**, not\r\n  during, the sweep showed BIGNET 7 nodes / 20 endpoints, SPT_MANTLE 3 / 19, SPT_DEV 2 / 19,\r\n  3-of-7 peers connected, `degraded-partial`. Four startup cells that spawn `findstr` passed alone\r\n  and reaped their observed ConPTY children; a full single-threaded run passed 663/663 with a\r\n  before/after census delta of `IR55_NEW=0`. The ratified settle-class sweep then ran five\r\n  consecutive bare `cargo test -p spt --bins` invocations: all 663/663 green in 420.35s total,\r\n  with zero `findstr.exe` residents before and after. This is a named negative data point, not a\r\n  discharge of the intermittent filing-day measurements.\r\n- **Next-wedge capture protocol — do not improvise or clean first:** preserve the exact bare\r\n  invocation and snapshot the environment (box, checkout SHA/worktree, fresh-versus-reused test\r\n  binary provenance, gate-scrub state, live-daemon state, and fleet roster); stream test output to\r\n  durable storage so the last started and completed test names identify the frontier; census\r\n  `Win32_Process` immediately before the run and again while wedged, recording each `findstr.exe`\r\n  PID, parent PID, creation time, executable path, and command line. **Do not kill any child before\r\n  the second census is banked.** The 22 residents found during the 2026-08-23 investigation were\r\n  path-verified as `C:\\Windows\\System32\\findstr.exe`, shown to predate its live runs, banked, then\r\n  reaped; the pre-sweep and post-sweep resident counts were both zero.\r\n- **Size guess:** small if one test is missing a reap or an EOF for its stand-in child; medium if\r\n  the shared PTY test scaffolding needs the reap, in which case every sibling spawning the same\r\n  stand-in wants it. The RUN-LEVEL exposure has an answer today (nextest); the LEAK itself is\r\n  still worth fixing, because a leaked child per run accumulates on any box that runs the suite.\r\n- **Gater's craft, worth more than the entry itself:**\r\n  (a) The first wedge was undiagnosable because the gate script wrote every leg as\r\n  `cargo test … | tail -N > file` — nothing reaches disk until the command completes, so a wedged\r\n  leg produces an **empty file** and the process table is the only witness. **Stream to a file and\r\n  tail the FILE.**\r\n  (b) To NAME a frontier, run `--test-threads=1`: libtest prints each test's name BEFORE running\r\n  it, so the last incomplete line is where progress stopped.\r\n  (c) **Then prove the frontier test is actually at fault by running it alone** — which is the\r\n  step this entry originally skipped, and the one that turned a wrong entry into a right one.\r\n\r","startLine":2930,"lineNumbers":[2930,2931,2932,2933,2934,2935,2936,2937,2938,2939,2940,2941,2942,2943,2944,2945,2946,2947,2948,2949,2950,2951,2952,2953,2954,2955,2956,2957,2958,2959,2960,2961,2962,2963,2964,2965,2966,2967,2968,2969,2970,2971,2972,2973,2974,2975,2976,2977,2978,2979,2980,2981,2982,2983,2984,2985,2986,2987,2988,2989,2990,2991,2992,2993,2994,2995,2996,2997,2998,2999,3000,3001,3002,3003,3004,3005,3006,3007,3008,3009,3010,3011,3012,3013,3014,3015,3016,3017,3018,3019,3020,3021,3022,3023,3024,3025,3026,3027,3028,3029,3030,3031,3032,3033,3034,3035,3036,3037,3038,3039,3040,3041,3042,3043,3044,3045,3046,3047,3048,3049,3050,3051,3052,3053,3054,3055,3056,3057,3058,3059,3060,3061,3062,3063,3064,3065,3066,3067,3068,3069,3070,3071,3072,3073,3074,3075,3076,3077,3078,3079,3080,3081,3082,3083,3084,3085,3086,3087,3088,3089,3090,3091,3092,3093,3094,3095,3096,3097,3098,3099,3100,3101,3102,3103,3104,3105,3106,3107,3108,3109,3110,3111,3112,3113,3114,3115,3116,3117,3118,3119,3120,3121,3122,3123,3124,3125,3126,3127,3128,3129,3130,3131,3132,3133,3134,3135,3136,3137,3138,3139,3140,3141,3142,3143,3144,3145,3146,3147,3148,3149,3150,3151,3152,3153,3154,3155,3156,3157,3158,3159,3160,3161,3162,3163,3164,3165,3166,3167,3168,3169,3170,3171,3172,3173,3174,3175,3176,3177,3178,3179,3180,3181,3182,3183,3184,3185,3186,3187,3188,3189,3190,3191,3192,3193,3194,3195,3196,3197,3198,3199,3200]},"fileSize":676479,"meta":{"source":{"type":"path","value":"C:\\Users\\decid\\Documents\\projects\\spt-core\\.worktrees\\hertz-ir86-disk-delta\\docs\\INFRA-REGISTER.md"},"truncation":{"direction":"head","truncatedBy":"lines","totalLines":6938,"totalBytes":23771,"outputLines":271,"outputBytes":23771,"shownRange":{"start":2930,"end":3200},"nextOffset":3201}}},"isError":false,"timestamp":1789483686446}}
{"type":"message","id":"0da69916","parentId":"3ca5ef39","timestamp":"2026-09-15T14:48:06.449Z","message":{"role":"toolResult","toolCallId":"call_1I3IqrEKXeKcRCcLANI2NWgG|fc_043a862a419f59ae016aa95aa6524087d2aab1f4b397a6ee3e","toolName":"grep","content":[{"type":"text","text":" 3906|  `session-detach`, which proves the connection event but not the file write.\n*3907|- **Kin:** [[IR-50]] (the sink a test must actually read), [[IR-40]] (an event timestamp is not a\n 3908|  completion signal), REQ-HAZARD-CONTROL-STAMP-CONVERGENCE.\n 3909|- **Ripe when:** the next controller lifecycle or structured-breadcrumb touch, or a field timeout\n 3910|  from PR #174's barrier. **Size:** small emitter plus one contract-level assertion.\n...\n 3914|- **Status:** OPEN, observability gap; no remedy scheduled. · **Origin:** CONDUIT #236 r3\n*3915|  two-host RCA and PR #174 (`70c1a303`), corrected by doyle after IR-18 and daemon-status were\n 3916|  ruled out as different classes.\n 3917|- **Source-verified boundary:** the holder identity already exists in durable/internal records\n 3918|  (`InfoJson.pid`, `parent_pid`, and the broker's session pid), and product internals read it for\n...\n 3921|  daemon status is process-wide, not perch- or seat-scoped. This also does not collapse into\n*3922|  [[IR-18]], where an existing internal `read_pid` collapses absent and unreadable records.\n 3923|- **Paid-for consequence 1 — rigs manufacture custody:** PR #174's two-host repair had to add\n 3924|  `PidHolder` in `crates/spt/tests/twohost_cli.rs:401-437`, spawn a long-lived sibling process,\n 3925|  write that pid directly into each synthetic perch, retain the child handle, and kill+wait it on\n...\n 3938|  it so the output does not become a new bare-pid oracle.\n*3939|- **Kin:** [[IR-18]] (read primitive loses error class, explicitly distinct), [[IR-71]] (release\n 3940|  completion lacks a persisted breadcrumb), REQ-HAZARD-SELF-DETECT-TIE (refuse ambiguous ancestry\n 3941|  rather than select by enumeration order).\n 3942|- **Ripe when:** the next roster/status read-model change or another rig needs to reap a named\n...\n 3960|- **Second half (from #242 r4, same family):** a single job-start floor read is stale by the\n*3961|  job's LAST heavy step — the r4 LNK1318 low-water face recorded on [[IR-59]] (sixth face);\n 3962|  the within-job re-read before the docs-drift build rides the next workflow commit alongside\n 3963|  this entry's reorders.\n*3964|- **Kin:** [[IR-46]] (a floor asserts an instant), [[IR-59]] (full volume reds as a linker\n 3965|  defect), REQ-CI-FREE-SPACE-PREFLIGHT.\n 3966|- **Ripe when:** next touch of `ci.yml`/`release.yml`, or the next intake's tooling-rider slot\n*3967|  (compose with IR-59/IR-57's standing pair). · **Size:** small — reorder or comment per site,\n 3968|  8 sites.\n 3969|\n 3970|### IR-74 — kitsubito holds 21,643 /tmp endpoint homes: box-side accumulation nothing bounds or measures\n...\n 3974|  homes — per-run spt homes that outlive their runs.\n*3975|- **What/why:** sibling of the [[IR-31]]/[[IR-59]]/[[IR-64]] family (box accumulation the\n 3976|  preflights never see): each is small, the population is not, and /tmp on a long-lived box is\n 3977|  never reaped by CI. Un-reaped homes also widen every by-path census a rig runs. Needs a\n 3978|  bounded lifecycle (per-run temp root reaped at run end, or a box-side sweep with a stated\n...\n 3989|  Windows treqs = 0 at the identical tree (treqs is a platform-independent text scan).\n*3990|- **What/why:** a 127 leg is exactly the wrapper-green shape [[IR-60]] documents — a driver that\n 3991|  doesn't read the exit FILE would report the leg green. Fix is either: install traceable-reqs on\n 3992|  kitsubito (then the leg is real), or DROP the leg from Linux gate drivers and state the\n*3993|  Windows-covers-it rule in the driver comment. Do NOT reopen [[IR-37]] for this — IR-37's\n 3994|  consume lane is spt-core CI (GitHub runners, green all week); this is BOX tooling, a different\n 3995|  surface (ruled at the sweep against the enumerating agent's overcautious flag).\n 3996|- **Ripe when:** next Linux gate-driver touch or kitsubito box-audit slot.\n...\n 4018|  blind to the load that matters. Every load-timing red on Windows therefore triages as a\n*4019|  random victim with the cause off the record — the [[IR-63]] \"one random victim per sweep\"\n 4020|  face, now with a named source.\n 4021|- **Fix shape:** (a) driver templates (every gate/battery driver an agent authors here)\n 4022|  gain a PRE-FLIGHT leg with THREE outcomes, never two (todlando's amendment at filing: an\n...\n 4029|  REFUSE and say the meter is broken. A refusal, not a warning, so a wrapper-green shape\n*4030|  cannot swallow it ([[IR-60]]); the dispatch-brief line in (b) is likewise a MEASURED\n 4031|  clear with a live meter, never the absence of a sentence; (b) dispatch briefs that start a gate NAME the hold state of the box; (c)\n 4032|  the job-start census gains a second predicate — cargo/nextest/rustc/link processes by\n 4033|  image name, count + total CPU — reported beside the family count so a red's triage can\n...\n 4035|  (docs/golden-head-intake) states the quiet-window rule once.\n*4036|- **Kin:** [[IR-63]] (random victim per sweep), [[IR-59]] (box conditions the preflights\n*4037|  never see), [[IR-64]] (hfenduleam's non-CI payload), FLAKE-LEDGER rows for\n 4038|  `wtlock_two_process_int` and `attach_link_push_e2e` (2026-09-06).\n 4039|- **Ripe when:** next driver-template touch (a/b are text; a is one leg), next `ci.yml`\n 4040|  touch for (c) — compose with [[IR-73]]'s reorders; (d) rides the next runbook edit.\n...\n 4085|  defensible — the rig flag exists precisely so a test tree cannot take a well-known port —\n*4086|  but a SET override discarded in SILENCE is the shape IR-37 files under a different name: the\n 4087|  operator is left believing the value they set is the value in force. Remedy is a line, not a\n 4088|  redesign: emit one notice naming both env vars when the flag wins. No test cell is proposed\n 4089|  with it — none of the 31 swept binaries asserts on a docs port, so a cell here would assert\n 4090|  a behaviour nothing consumes.\n*4091|- **Kin:** [[IR-37]] (a set input silently ignored), the 5474 hygiene sweep, and the\n 4092|  `DOCS_SERVER_BIND_FAIL: port 5474: Address already in use (os error 98)` lines in\n 4093|  `.spt/preserved/w1-kitsubito-8d980fdf/nextest.raw` that started the sweep.\n 4094|- **NOT measured, stated so nobody reads it as covered:** doyle measured that the WMI\n...\n 4176|- **Kin:** FLAKE-LEDGER `resident_service_e2e` :664 teardown LEAK row (3 occurrences, the Windows\n*4177|  face of the same class), [[IR-34]], [[IR-74]] (kitsubito's 21,643 `/tmp` endpoint homes — this is\n 4178|  one of the producers), and todlando's red 6.\n 4179|- **Ripe when:** the next lane that touches `crates/spt/tests/common` — the guard belongs there,\n 4180|  not copied 22 times.\n...\n 4190|  doyle's ruling that this retains its own identity, separate from IR-79.\n*4191|  **Origin:** noticed while measuring the #198 HEAVY scan-root gap ([[IR-37]] rider 2); the leak\n 4192|  roster was read out of the baseline golden log for an unrelated reason.\n 4193|- **⚠ WHAT THIS ENTRY IS, STATED FIRST SO IT IS NOT OVERREAD: a CLUSTER OF NAMES.** Five cells\n 4194|  that leaked share one module and one code path by their identifiers. Nothing has been measured\n...\n 4242|  the reason doyle ruled these must stay SEPARATE: same symptom, different suspected owner),\n*4243|  [[IR-37]] rider 2 (the measurement that surfaced it), FLAKE-LEDGER's `resident_service_e2e` :664\n 4244|  teardown LEAK row.\n 4245|- **Ripe when:** the first free Windows box after W2 lands — it is a single-cell census, so it\n 4246|  fits any gap.\n...\n 4503|     `commandline like` / `-match` scope in the same block, is a build failure. **Owner: hertz,\n*4504|     rides the IR-37 thin PR after W2 lands.** This is the half remedy (a) can NEVER reach — the\n 4505|     unguarded adapter site is a shell script, and no Rust signature constrains a shell script.\n 4506|  3. **(c) Fix the two sites and stop.** Recorded as CONSIDERED AND LOSING, not omitted: it has\n 4507|     already been tried implicitly — the adapter's author wrote the scoped form three times and\n...\n 4555|so no Rust caller can express the unguarded kill (todlando, post-W2, cross-referenced with the\n*4556|broker.rs:8102 board BUGFIX); and arm (b), the xtask script gate (mine, rides IR-37).\n 4557|\n 4558|---\n 4559|\n...\n 4680|- **LANE — SPLIT BY THE RULING, and the two halves ship separately.** The **IR-82 ENTRY** (this\n*4681|  text) rides hertz's IR-37 thin PR alongside IR-79/80/81. The **PRODUCT REMEDY** rides **#285's\n 4682|  lane** (todlando, post-W2) because it is the same pid-identity gate: #285 makes a kill read an\n 4683|  identity, this makes a successor read the identity it is about to erase. One lane, one owner,\n 4684|  one review of the pid-identity question. Do not implement the remedy in the thin PR.\n...\n 5002|- **Kin:** [[IR-76]] (the golden runner IS the builders' box — the structural reason a desktop's\n*5003|  load reaches CI at all), [[IR-64]] (box-level facts only the operator can move), [[IR-89]] (the\n 5004|  other elevated box-rule ask), `defender-first-touch-tax-on-fresh-test-binaries` and\n 5005|  `e2e-leaked-daemons-shared-box` (memory).\n 5006|- **Ripe when:** arm 1 now; arms 2-4 on the operator's answer; arm 5 at the next `golden.yml` touch\n...\n 5055|  91 GiB minus 67.4 = 23.5 < 32. This is a shortfall of the DERIVATION, not a rate, not a product\n*5056|  red, and not the instant-vs-sustained face IR-46 files (that face is fixed by the FLOOR_DOCS\n 5057|  re-read, which is what caught it). The start floor must be footprint + end-floor (~100 GiB) or\n 5058|  it asserts nothing about finishing.\n 5059|- **Coverage consequence (the load-bearing part):** the Windows `Docs drift gate (CLI ref + llms\n...\n 5062|  disk red.\n*5063|- **Kin:** [[IR-46]] (a floor asserts an instant), [[IR-59]] (pool arithmetic, LNK-class reds\n*5064|  that name no disk), [[IR-64]] (the operator-payload reservoir that sets the box baseline; its\n 5065|  ripe-when arm — a golden that dies at the floor despite adopted pool discipline — FIRED here\n 5066|  in the in-job form), [[IR-73]] (second half BUILT: the within-job re-read exists and is what\n 5067|  produced the FLOOR_DOCS reading), REQ-CI-FREE-SPACE-PREFLIGHT.\n...\n 5081|  literal per start-floor site + one printed subtraction.\n*5082|- **Linux recurrence, 2026-09-15 (doyle, S4 golden `34946493637`, reported in `3HHHPWCR`).** Kitsubito's test job began with about **110.7 GB** free and reached about **29.3 GB** after its build and test sandbox consumed **81.4 GB**; the workload stages were green, then the floor gates red. `FLOOR_DOCS` and `FLOOR_END` run **before** test-temp-sandbox cleanup, deliberately ([[IR-46]]), so the job must retain the end-floor reserve while its own sandbox still exists. A generic **32 GiB** start admission do...\n 5083|<!-- [doc->REQ-CI-FREE-SPACE-PREFLIGHT] -->\n 5084|- **Linux sizing decision, 2026-09-15 (2NLUDSQA).** Golden's Linux **test-job** start allowance is now **130,000,000,000 bytes (130 decimal GB)**. The rounded measurements imply about **115.8 GB** minimum (81.4 GB working set + 32 GiB reserve); the allowance includes about **14.24 GB** margin, not a newly measured peak. `FLOOR_DOCS` and `FLOOR_END` retain **34,359,738,368 bytes (32 GiB)** and their pre-cleanup placement. Admission remains after checkout and before expensive work. Only this job/OS start v...\n 5085|- **Linux verification.** Executed the actual YAML shell bodies on kitsubito with controlled `df` readings: the historical 110.7 GB start passes the predecessor and is refused by the successor; 130 GB minus one byte refuses, exactly 130 GB passes; native `df` failure23 propagates. Both docs/end bodies still refuse one byte below 32 GiB and pass exactly at the reserve. An unmodified native `df` sample passed at **246,886,174,720 bytes** free. All **9 successor probes** matched their expected exits; tempor...\n...\n 5109|- **Kin:** [[IR-76]] (hfenduleam is golden runner AND builders' box; the job-start census cannot\n*5110|  see a competing GitHub run either), [[IR-62]] (rig collisions on shared runners), the W1 two-host\n 5111|  rig, `a-barrier-cannot-ride-a-carrier-its-sender-outlives` (memory, same family: a barrier needs\n 5112|  the receiver's own answer).\n 5113|- **Remedy shape (pick at rider time):** (1) start barrier on B keyed to A's job having STARTED\n...\n 5169|  rather than merely proposed.\n*5170|- **Kin:** [[IR-31]] (pool budgeting), [[IR-56]] (pool-claim identity from CWD — same verb\n 5171|  family, same \"the tool acts on where it stands\" shape), releases#103.\n 5172|- **Ripe when:** next xtask pool-verb touch or the teardown runbook edit. · **Size:** tiny —\n 5173|  one guard or one doc line.\n...\n 5238|  other way a half waits 900 s on a partner), [[IR-76]] (golden runner\n*5239|  is the operator's box), [[IR-64]] (box-level facts only the operator can move),\n 5240|  `twohost-web-helper-stall-shared-a-identity-stale-path` (memory; its CONFIRMED arm is re-read\n 5241|  by this entry).\n 5242|- **AMENDMENT 2026-09-09 — the WORKFLOW half is BUILT and FIELD-MEASURED; it is LANDED-pending-golden\n...\n 6024|  producer's completion and the next producer's launch without a defined encoding.\n*6025|- **Kin:** [[IR-32]] (an instrument that agrees with itself), [[IR-46]] (one reading is an instant),\n 6026|  the memory rule \"cancelled = labelled hole\"; the shell-side kin is `render-not-read-pipefail`.\n 6027|- **Ripe when:** any new sequence driver or any driver that renders producer output to a console;\n 6028|  `.github/ci/local-lane.py` and its lane modules are the first population. · **Size:** one\n...\n 6163|  setting; it does not remove the disk, which stays in the same pool subtree by design.\n*6164|- **Kin:** [[IR-97]] (exclusive execution windows; builds may overlap), [[IR-56]] (a pool is a\n 6165|  relationship, not a path), the memory rules \"measure the box before the instrument\" and \"quiet\n 6166|  window predicate\".\n 6167|- **Ripe when:** the next admission census on this box, or the next lock wait anyone traces.\n...\n 6362|  binary is built from the tag (`traceable-reqs-<ver>.exe`), never \"whatever is on PATH\".\n*6363|- **Kin:** [[IR-37]] (placement enforcement, the same release), [[IR-102]] (a declared thing still\n 6364|  unread), memory rules \"a predicate needs its tool\", \"zero-match filter reads as absent\".\n 6365|- **Ripe when:** now — the #304 assembly. · **Size:** one pin fixup; one line in the gate runbook.\n 6366|\n...\n 6540|  run; an environment-premise failure does not authorize a product patch.\n*6541|  **Kin:** [[IR-22]] records the earlier identity-inheritance failure and its\n 6542|  one-variable-at-a-time diagnostic trap; [[IR-122]] distinguishes a real rig's\n 6543|  intentional live-session refusal from an isolated test's contaminated premise.\n 6544|\n...\n 6778|- **Rule (scoped by doyle 2026-09-12 — a bare pid-file kill is NOT approved as sufficient).** A rig that starts a daemon owns stopping it by a route that works from the rig's own environment, and `<isolated-home>/daemon.pid` is the pid SOURCE, never the authorization. Any rig cleanup that terminates a process must, at the moment of acting: re-read creation time, exact `ExecutablePath`, `CommandLine` and isolated-home association FRESH; confirm the supervisor still equals the pid file and the brain's pa...\n*6779|- **Kin:** [[IR-42]] (pool enforcement speaks at the next build, not at claim time), memory rig-ownership-reap-only-your-own, reap-root-needs-authenticated-ancestry, e2e-leaked-daemons-shared-box, no-machinewide-killon-shared-runner.\n 6780|- **Ripe when:** before the next field run. NOT a one-line change: the stop route is small, but the identity re-verification, supervisor-first ordering and explicit failure reporting above are part of the fix and are what make it safe. · **Size:** small.\n 6781|\n 6782|### IR-123 — a helper that LOGS cannot also RETURN through stdout: `record` tees, so `face=$(face_report ...)` captures the log block and the acceptance gate can never pass\n...\n 6853|- **Rule.** Treat deserialization's runtime type as part of the interface. Never reparse a typed date through implicit culture-sensitive formatting. Exercise both a same-process roundtrip and a wrong-anchor negative control; preserve raw timestamps and the computed delta so their agreement can be audited. Match at the actual reader resolution, not by discarding the fractional second.\n*6854|- **Kin:** [[IR-118]] (successful instrument, wrong answer), [[IR-125]] (an absence predicate needs a known-present control), [[IR-15]] (identity-aware liveness).\n 6855|- **Ripe when:** any JSON record is used to authenticate process identity or order events. **Size:** type-aware UTC conversion and two local controls.\n 6856|\n 6857|### IR-130 — a lowercase `$home` local collides with PowerShell's protected `$HOME`, refusing custody qualification before the signer is reached\n...\n 6885|- **Rule.** Admission asks whether an observed identity can belong to the owned rig, not whether the caller can read every process on the host. Preserve query failure, confirmed absence and replacement identity as different outcomes, with pid and birth in the receipt. Re-pin changed instruments; preserve failed windows and obtain a fresh grant rather than extending their clocks.\n*6886|- **Kin:** [[IR-107]] (live operational context enters the rig), [[IR-129]] (creation-time type/precision), [[IR-125]] (known-present control for absence), [[IR-15]] (identity-aware liveness).\n 6887|- **Ripe when:** a rig shares a host with elevated perches or short-lived CLI traffic. **Size:** birth-aware census and retained native identity probe, with fail-closed boundary controls.\n 6888|\n 6889|### IR-133 — a live capture cannot be read with read-only sharing, and daemon stderr belongs to the owned home\n\n[Some lines truncated to 512 chars]"}],"details":{"scopePath":".worktrees/hertz-ir86-disk-delta/docs/INFRA-REGISTER.md","searchPath":"C:\\Users\\decid\\Documents\\projects\\spt-core\\.worktrees\\hertz-ir86-disk-delta\\docs\\INFRA-REGISTER.md","cwd":"C:\\Users\\decid\\Documents\\projects\\spt-core","matchCount":37,"fileCount":1,"files":[".worktrees/hertz-ir86-disk-delta/docs/INFRA-REGISTER.md"],"fileMatches":[{"path":".worktrees/hertz-ir86-disk-delta/docs/INFRA-REGISTER.md","count":37}],"truncated":true,"displayContent":" 3906│  `session-detach`, which proves the connection event but not the file write.\n*3907│- **Kin:** [[IR-50]] (the sink a test must actually read), [[IR-40]] (an event timestamp is not a\n 3908│  completion signal), REQ-HAZARD-CONTROL-STAMP-CONVERGENCE.\n 3909│- **Ripe when:** the next controller lifecycle or structured-breadcrumb touch, or a field timeout\n 3910│  from PR #174's barrier. **Size:** small emitter plus one contract-level assertion.\n     │...\n 3914│- **Status:** OPEN, observability gap; no remedy scheduled. · **Origin:** CONDUIT #236 r3\n*3915│  two-host RCA and PR #174 (`70c1a303`), corrected by doyle after IR-18 and daemon-status were\n 3916│  ruled out as different classes.\n 3917│- **Source-verified boundary:** the holder identity already exists in durable/internal records\n 3918│  (`InfoJson.pid`, `parent_pid`, and the broker's session pid), and product internals read it for\n     │...\n 3921│  daemon status is process-wide, not perch- or seat-scoped. This also does not collapse into\n*3922│  [[IR-18]], where an existing internal `read_pid` collapses absent and unreadable records.\n 3923│- **Paid-for consequence 1 — rigs manufacture custody:** PR #174's two-host repair had to add\n 3924│  `PidHolder` in `crates/spt/tests/twohost_cli.rs:401-437`, spawn a long-lived sibling process,\n 3925│  write that pid directly into each synthetic perch, retain the child handle, and kill+wait it on\n     │...\n 3938│  it so the output does not become a new bare-pid oracle.\n*3939│- **Kin:** [[IR-18]] (read primitive loses error class, explicitly distinct), [[IR-71]] (release\n 3940│  completion lacks a persisted breadcrumb), REQ-HAZARD-SELF-DETECT-TIE (refuse ambiguous ancestry\n 3941│  rather than select by enumeration order).\n 3942│- **Ripe when:** the next roster/status read-model change or another rig needs to reap a named\n     │...\n 3960│- **Second half (from #242 r4, same family):** a single job-start floor read is stale by the\n*3961│  job's LAST heavy step — the r4 LNK1318 low-water face recorded on [[IR-59]] (sixth face);\n 3962│  the within-job re-read before the docs-drift build rides the next workflow commit alongside\n 3963│  this entry's reorders.\n*3964│- **Kin:** [[IR-46]] (a floor asserts an instant), [[IR-59]] (full volume reds as a linker\n 3965│  defect), REQ-CI-FREE-SPACE-PREFLIGHT.\n 3966│- **Ripe when:** next touch of `ci.yml`/`release.yml`, or the next intake's tooling-rider slot\n*3967│  (compose with IR-59/IR-57's standing pair). · **Size:** small — reorder or comment per site,\n 3968│  8 sites.\n 3969│\n 3970│### IR-74 — kitsubito holds 21,643 /tmp endpoint homes: box-side accumulation nothing bounds or measures\n     │...\n 3974│  homes — per-run spt homes that outlive their runs.\n*3975│- **What/why:** sibling of the [[IR-31]]/[[IR-59]]/[[IR-64]] family (box accumulation the\n 3976│  preflights never see): each is small, the population is not, and /tmp on a long-lived box is\n 3977│  never reaped by CI. Un-reaped homes also widen every by-path census a rig runs. Needs a\n 3978│  bounded lifecycle (per-run temp root reaped at run end, or a box-side sweep with a stated\n     │...\n 3989│  Windows treqs = 0 at the identical tree (treqs is a platform-independent text scan).\n*3990│- **What/why:** a 127 leg is exactly the wrapper-green shape [[IR-60]] documents — a driver that\n 3991│  doesn't read the exit FILE would report the leg green. Fix is either: install traceable-reqs on\n 3992│  kitsubito (then the leg is real), or DROP the leg from Linux gate drivers and state the\n*3993│  Windows-covers-it rule in the driver comment. Do NOT reopen [[IR-37]] for this — IR-37's\n 3994│  consume lane is spt-core CI (GitHub runners, green all week); this is BOX tooling, a different\n 3995│  surface (ruled at the sweep against the enumerating agent's overcautious flag).\n 3996│- **Ripe when:** next Linux gate-driver touch or kitsubito box-audit slot.\n     │...\n 4018│  blind to the load that matters. Every load-timing red on Windows therefore triages as a\n*4019│  random victim with the cause off the record — the [[IR-63]] \"one random victim per sweep\"\n 4020│  face, now with a named source.\n 4021│- **Fix shape:** (a) driver templates (every gate/battery driver an agent authors here)\n 4022│  gain a PRE-FLIGHT leg with THREE outcomes, never two (todlando's amendment at filing: an\n     │...\n 4029│  REFUSE and say the meter is broken. A refusal, not a warning, so a wrapper-green shape\n*4030│  cannot swallow it ([[IR-60]]); the dispatch-brief line in (b) is likewise a MEASURED\n 4031│  clear with a live meter, never the absence of a sentence; (b) dispatch briefs that start a gate NAME the hold state of the box; (c)\n 4032│  the job-start census gains a second predicate — cargo/nextest/rustc/link processes by\n 4033│  image name, count + total CPU — reported beside the family count so a red's triage can\n     │...\n 4035│  (docs/golden-head-intake) states the quiet-window rule once.\n*4036│- **Kin:** [[IR-63]] (random victim per sweep), [[IR-59]] (box conditions the preflights\n*4037│  never see), [[IR-64]] (hfenduleam's non-CI payload), FLAKE-LEDGER rows for\n 4038│  `wtlock_two_process_int` and `attach_link_push_e2e` (2026-09-06).\n 4039│- **Ripe when:** next driver-template touch (a/b are text; a is one leg), next `ci.yml`\n 4040│  touch for (c) — compose with [[IR-73]]'s reorders; (d) rides the next runbook edit.\n     │...\n 4085│  defensible — the rig flag exists precisely so a test tree cannot take a well-known port —\n*4086│  but a SET override discarded in SILENCE is the shape IR-37 files under a different name: the\n 4087│  operator is left believing the value they set is the value in force. Remedy is a line, not a\n 4088│  redesign: emit one notice naming both env vars when the flag wins. No test cell is proposed\n 4089│  with it — none of the 31 swept binaries asserts on a docs port, so a cell here would assert\n 4090│  a behaviour nothing consumes.\n*4091│- **Kin:** [[IR-37]] (a set input silently ignored), the 5474 hygiene sweep, and the\n 4092│  `DOCS_SERVER_BIND_FAIL: port 5474: Address already in use (os error 98)` lines in\n 4093│  `.spt/preserved/w1-kitsubito-8d980fdf/nextest.raw` that started the sweep.\n 4094│- **NOT measured, stated so nobody reads it as covered:** doyle measured that the WMI\n     │...\n 4176│- **Kin:** FLAKE-LEDGER `resident_service_e2e` :664 teardown LEAK row (3 occurrences, the Windows\n*4177│  face of the same class), [[IR-34]], [[IR-74]] (kitsubito's 21,643 `/tmp` endpoint homes — this is\n 4178│  one of the producers), and todlando's red 6.\n 4179│- **Ripe when:** the next lane that touches `crates/spt/tests/common` — the guard belongs there,\n 4180│  not copied 22 times.\n     │...\n 4190│  doyle's ruling that this retains its own identity, separate from IR-79.\n*4191│  **Origin:** noticed while measuring the #198 HEAVY scan-root gap ([[IR-37]] rider 2); the leak\n 4192│  roster was read out of the baseline golden log for an unrelated reason.\n 4193│- **⚠ WHAT THIS ENTRY IS, STATED FIRST SO IT IS NOT OVERREAD: a CLUSTER OF NAMES.** Five cells\n 4194│  that leaked share one module and one code path by their identifiers. Nothing has been measured\n     │...\n 4242│  the reason doyle ruled these must stay SEPARATE: same symptom, different suspected owner),\n*4243│  [[IR-37]] rider 2 (the measurement that surfaced it), FLAKE-LEDGER's `resident_service_e2e` :664\n 4244│  teardown LEAK row.\n 4245│- **Ripe when:** the first free Windows box after W2 lands — it is a single-cell census, so it\n 4246│  fits any gap.\n     │...\n 4503│     `commandline like` / `-match` scope in the same block, is a build failure. **Owner: hertz,\n*4504│     rides the IR-37 thin PR after W2 lands.** This is the half remedy (a) can NEVER reach — the\n 4505│     unguarded adapter site is a shell script, and no Rust signature constrains a shell script.\n 4506│  3. **(c) Fix the two sites and stop.** Recorded as CONSIDERED AND LOSING, not omitted: it has\n 4507│     already been tried implicitly — the adapter's author wrote the scoped form three times and\n     │...\n 4555│so no Rust caller can express the unguarded kill (todlando, post-W2, cross-referenced with the\n*4556│broker.rs:8102 board BUGFIX); and arm (b), the xtask script gate (mine, rides IR-37).\n 4557│\n 4558│---\n 4559│\n     │...\n 4680│- **LANE — SPLIT BY THE RULING, and the two halves ship separately.** The **IR-82 ENTRY** (this\n*4681│  text) rides hertz's IR-37 thin PR alongside IR-79/80/81. The **PRODUCT REMEDY** rides **#285's\n 4682│  lane** (todlando, post-W2) because it is the same pid-identity gate: #285 makes a kill read an\n 4683│  identity, this makes a successor read the identity it is about to erase. One lane, one owner,\n 4684│  one review of the pid-identity question. Do not implement the remedy in the thin PR.\n     │...\n 5002│- **Kin:** [[IR-76]] (the golden runner IS the builders' box — the structural reason a desktop's\n*5003│  load reaches CI at all), [[IR-64]] (box-level facts only the operator can move), [[IR-89]] (the\n 5004│  other elevated box-rule ask), `defender-first-touch-tax-on-fresh-test-binaries` and\n 5005│  `e2e-leaked-daemons-shared-box` (memory).\n 5006│- **Ripe when:** arm 1 now; arms 2-4 on the operator's answer; arm 5 at the next `golden.yml` touch\n     │...\n 5055│  91 GiB minus 67.4 = 23.5 < 32. This is a shortfall of the DERIVATION, not a rate, not a product\n*5056│  red, and not the instant-vs-sustained face IR-46 files (that face is fixed by the FLOOR_DOCS\n 5057│  re-read, which is what caught it). The start floor must be footprint + end-floor (~100 GiB) or\n 5058│  it asserts nothing about finishing.\n 5059│- **Coverage consequence (the load-bearing part):** the Windows `Docs drift gate (CLI ref + llms\n     │...\n 5062│  disk red.\n*5063│- **Kin:** [[IR-46]] (a floor asserts an instant), [[IR-59]] (pool arithmetic, LNK-class reds\n*5064│  that name no disk), [[IR-64]] (the operator-payload reservoir that sets the box baseline; its\n 5065│  ripe-when arm — a golden that dies at the floor despite adopted pool discipline — FIRED here\n 5066│  in the in-job form), [[IR-73]] (second half BUILT: the within-job re-read exists and is what\n 5067│  produced the FLOOR_DOCS reading), REQ-CI-FREE-SPACE-PREFLIGHT.\n     │...\n 5081│  literal per start-floor site + one printed subtraction.\n*5082│- **Linux recurrence, 2026-09-15 (doyle, S4 golden `34946493637`, reported in `3HHHPWCR`).** Kitsubito's test job began with about **110.7 GB** free and reached about **29.3 GB** after its build and test sandbox consumed **81.4 GB**; the workload stages were green, then the floor gates red. `FLOOR_DOCS` and `FLOOR_END` run **before** test-temp-sandbox cleanup, deliberately ([[IR-46]]), so the job must retain the end-floor reserve while its own sandbox still exists. A generic **32 GiB** start admission do...\n 5083│<!-- [doc->REQ-CI-FREE-SPACE-PREFLIGHT] -->\n 5084│- **Linux sizing decision, 2026-09-15 (2NLUDSQA).** Golden's Linux **test-job** start allowance is now **130,000,000,000 bytes (130 decimal GB)**. The rounded measurements imply about **115.8 GB** minimum (81.4 GB working set + 32 GiB reserve); the allowance includes about **14.24 GB** margin, not a newly measured peak. `FLOOR_DOCS` and `FLOOR_END` retain **34,359,738,368 bytes (32 GiB)** and their pre-cleanup placement. Admission remains after checkout and before expensive work. Only this job/OS start v...\n 5085│- **Linux verification.** Executed the actual YAML shell bodies on kitsubito with controlled `df` readings: the historical 110.7 GB start passes the predecessor and is refused by the successor; 130 GB minus one byte refuses, exactly 130 GB passes; native `df` failure23 propagates. Both docs/end bodies still refuse one byte below 32 GiB and pass exactly at the reserve. An unmodified native `df` sample passed at **246,886,174,720 bytes** free. All **9 successor probes** matched their expected exits; tempor...\n     │...\n 5109│- **Kin:** [[IR-76]] (hfenduleam is golden runner AND builders' box; the job-start census cannot\n*5110│  see a competing GitHub run either), [[IR-62]] (rig collisions on shared runners), the W1 two-host\n 5111│  rig, `a-barrier-cannot-ride-a-carrier-its-sender-outlives` (memory, same family: a barrier needs\n 5112│  the receiver's own answer).\n 5113│- **Remedy shape (pick at rider time):** (1) start barrier on B keyed to A's job having STARTED\n     │...\n 5169│  rather than merely proposed.\n*5170│- **Kin:** [[IR-31]] (pool budgeting), [[IR-56]] (pool-claim identity from CWD — same verb\n 5171│  family, same \"the tool acts on where it stands\" shape), releases#103.\n 5172│- **Ripe when:** next xtask pool-verb touch or the teardown runbook edit. · **Size:** tiny —\n 5173│  one guard or one doc line.\n     │...\n 5238│  other way a half waits 900 s on a partner), [[IR-76]] (golden runner\n*5239│  is the operator's box), [[IR-64]] (box-level facts only the operator can move),\n 5240│  `twohost-web-helper-stall-shared-a-identity-stale-path` (memory; its CONFIRMED arm is re-read\n 5241│  by this entry).\n 5242│- **AMENDMENT 2026-09-09 — the WORKFLOW half is BUILT and FIELD-MEASURED; it is LANDED-pending-golden\n     │...\n 6024│  producer's completion and the next producer's launch without a defined encoding.\n*6025│- **Kin:** [[IR-32]] (an instrument that agrees with itself), [[IR-46]] (one reading is an instant),\n 6026│  the memory rule \"cancelled = labelled hole\"; the shell-side kin is `render-not-read-pipefail`.\n 6027│- **Ripe when:** any new sequence driver or any driver that renders producer output to a console;\n 6028│  `.github/ci/local-lane.py` and its lane modules are the first population. · **Size:** one\n     │...\n 6163│  setting; it does not remove the disk, which stays in the same pool subtree by design.\n*6164│- **Kin:** [[IR-97]] (exclusive execution windows; builds may overlap), [[IR-56]] (a pool is a\n 6165│  relationship, not a path), the memory rules \"measure the box before the instrument\" and \"quiet\n 6166│  window predicate\".\n 6167│- **Ripe when:** the next admission census on this box, or the next lock wait anyone traces.\n     │...\n 6362│  binary is built from the tag (`traceable-reqs-<ver>.exe`), never \"whatever is on PATH\".\n*6363│- **Kin:** [[IR-37]] (placement enforcement, the same release), [[IR-102]] (a declared thing still\n 6364│  unread), memory rules \"a predicate needs its tool\", \"zero-match filter reads as absent\".\n 6365│- **Ripe when:** now — the #304 assembly. · **Size:** one pin fixup; one line in the gate runbook.\n 6366│\n     │...\n 6540│  run; an environment-premise failure does not authorize a product patch.\n*6541│  **Kin:** [[IR-22]] records the earlier identity-inheritance failure and its\n 6542│  one-variable-at-a-time diagnostic trap; [[IR-122]] distinguishes a real rig's\n 6543│  intentional live-session refusal from an isolated test's contaminated premise.\n 6544│\n     │...\n 6778│- **Rule (scoped by doyle 2026-09-12 — a bare pid-file kill is NOT approved as sufficient).** A rig that starts a daemon owns stopping it by a route that works from the rig's own environment, and `<isolated-home>/daemon.pid` is the pid SOURCE, never the authorization. Any rig cleanup that terminates a process must, at the moment of acting: re-read creation time, exact `ExecutablePath`, `CommandLine` and isolated-home association FRESH; confirm the supervisor still equals the pid file and the brain's pa...\n*6779│- **Kin:** [[IR-42]] (pool enforcement speaks at the next build, not at claim time), memory rig-ownership-reap-only-your-own, reap-root-needs-authenticated-ancestry, e2e-leaked-daemons-shared-box, no-machinewide-killon-shared-runner.\n 6780│- **Ripe when:** before the next field run. NOT a one-line change: the stop route is small, but the identity re-verification, supervisor-first ordering and explicit failure reporting above are part of the fix and are what make it safe. · **Size:** small.\n 6781│\n 6782│### IR-123 — a helper that LOGS cannot also RETURN through stdout: `record` tees, so `face=$(face_report ...)` captures the log block and the acceptance gate can never pass\n     │...\n 6853│- **Rule.** Treat deserialization's runtime type as part of the interface. Never reparse a typed date through implicit culture-sensitive formatting. Exercise both a same-process roundtrip and a wrong-anchor negative control; preserve raw timestamps and the computed delta so their agreement can be audited. Match at the actual reader resolution, not by discarding the fractional second.\n*6854│- **Kin:** [[IR-118]] (successful instrument, wrong answer), [[IR-125]] (an absence predicate needs a known-present control), [[IR-15]] (identity-aware liveness).\n 6855│- **Ripe when:** any JSON record is used to authenticate process identity or order events. **Size:** type-aware UTC conversion and two local controls.\n 6856│\n 6857│### IR-130 — a lowercase `$home` local collides with PowerShell's protected `$HOME`, refusing custody qualification before the signer is reached\n     │...\n 6885│- **Rule.** Admission asks whether an observed identity can belong to the owned rig, not whether the caller can read every process on the host. Preserve query failure, confirmed absence and replacement identity as different outcomes, with pid and birth in the receipt. Re-pin changed instruments; preserve failed windows and obtain a fresh grant rather than extending their clocks.\n*6886│- **Kin:** [[IR-107]] (live operational context enters the rig), [[IR-129]] (creation-time type/precision), [[IR-125]] (known-present control for absence), [[IR-15]] (identity-aware liveness).\n 6887│- **Ripe when:** a rig shares a host with elevated perches or short-lived CLI traffic. **Size:** birth-aware census and retained native identity probe, with fail-closed boundary controls.\n 6888│\n 6889│### IR-133 — a live capture cannot be read with read-only sharing, and daemon stderr belongs to the owned home","linesTruncated":true,"meta":{"limits":{"columnTruncated":{"maxColumn":512}}}},"isError":false,"timestamp":1789483686449}}
{"type":"message","id":"5a7e70ef","parentId":"0da69916","timestamp":"2026-09-15T14:48:06.580Z","message":{"role":"toolResult","toolCallId":"call_dIf6A1z4mcOeCDHqom7T8qCM|fc_043a862a419f59ae016aa95aa6524487d2bfb65934006dab7c","toolName":"grep","content":[{"type":"text","text":"# .worktrees/hertz-ir86-disk-delta/\n## traceable-reqs.toml\n 22|\n*23|[placement]\n 24|enforce = \"on\"\n*25|module_banner = \"accept\"\n 26|\n 27|[[requirements]]\n 28|id = \"REQ-STATUS-LIVE-SUPERVISOR-PID\"\n...\n 544|title = \"Interactive `spt endpoint run` picker (ratatui TUI): bare `spt` on an interactive terminal enters an in-process picker (flags-present = the REQ-HOST-RUN-1 non-interactive path, untouched). Layer 1 picks kind (Create new | Pick existing). Create-new: choose a registered kind=\\\"harness\\\" adapter with its shipped+local profiles tree-nested (registry::registered / manifest.profiles / local_profile_names) → enter a charset-validated id → start. Pick-existing: category select (left/right) over [<c...\n*545|required_stages = [\"doc\", \"impl\", \"unit\"]  # activated M12-W2 (no int: TUI Buffer + state-model unit asserts; live loop manual-verify; bringup path int-covered by REQ-HOST-RUN-1/REQ-RC-1). v0.13.0-W4 UX refinements (todlando 2026-06-19): (1) bare picker OPENS on Pick-existing (Kind = jump-target, `n` → create); (2) Start-now + Resume-from-history ATTACH by default (was detached/no-stdout) with an `h` headless escape (start, no attach); (4) the bringup stderr line is a terse machine token (dropped the R...\n 546|[[requirements]]\n 547|id = \"REQ-RUN-SHORTCUT\"\n 548|title = \"`<basename>-<id>` launcher shortcut generation (picker `s` keybind, M12-W2-T2.4): from any pre-start options set the picker writes/updates a `<basename>-<id>` launcher at the project root whose body is `spt go <id>` (since U3 it bakes no selection; pre-U3 it baked the non-interactive flags: adapter[:profile] + id + (create|resume) + (start|attach|view); Kick/Instantiate/Change-adapter/Fork are interactive-only, not bakeable). BASENAME IS A PARAMETER (operator rev. 2026-06-14): harness-agnostic s...\n...\n 559|id = \"REQ-ELEVATE-1\"\n*560|title = \"Cross-platform self-elevating re-launch for privilege-gated commands: a pure decision seam `decide_elevation_path(os, elevation, interactive_tty, has_display, has_pkexec, has_term_emulator) -> ElevatePath{AlreadyElevated, InlineSudo, UacWindow, Pkexec, TerminalEmulator, PrintHint}` selecting how to re-acquire privilege, and the per-OS impure launchers it dispatches — Windows UAC console (ShellExecuteW `runas` on the abs-exe + verbatim argv; the elevated child does the work, prints 'You can clo...\n 561|required_stages = [\"doc\", \"impl\", \"unit\"]  # activated M12-W4 (no int: the decision matrix is unit-tested across the os×elevation×env grid; each actual launch needs a real UAC/polkit/sudo/TTY → manual-verify leg, REQ-PAIR-6 precedent)\n 562|\n 563|# ── M12 Wave 5: whoami → endpoint-list alias (M12-PLAN.md Wave 5; doyle ruling\n...\n 739|id = \"REQ-HAZARD-UNHOST-PSYCHE-REAP\"\n*740|title = \"On un-host, the detached `{id}-psyche` HARNESS PROCESS is reaped — not just its in-brain pulse-driver thread. Today stop_host (livehost.rs:203) trips the HostedLife stop flag + JOINS the driver thread, but the Psyche is a detached harness process (spawn_psyche → ManifestRuntime detached spawn, runtime.rs:341-356; its pid is untracked in HostedLife though stamped on the `{id}-psyche` perch, where residency-confirm already reads it). So endpoint-stop / mid-life agent-death / a B2/B5 offline-th...\n 741|required_stages = []  # SUPERSEDED 2026-07-04 (F-030 W3, todlando) by REQ-PSYCHE-EPHEMERAL-DRIVER (no resident = no orphan to reap). host_one spawns no resident psyche, so un-host has nothing detached to reap — HostedLife.psyche_child + the stop_host handle-reap + stop_host_reaps_the_detached_psyche_process are DELETED. Kept as a stable pointer (no dangling required stage on deleted evidence).\n 742|[[requirements]]\n 743|id = \"REQ-ENDPOINT-PURGE\"\n...\n 1176|required_stages = [\"doc\", \"impl\", \"unit\"]  # doc activated restoration D1 (KNOWN-HAZARDS 6.8 + ADR-0018 + design doc V1). impl/unit activated restoration D6-3 (the one D6 toml activation): impl = rollback_compat.rs (the pre-ready durable-file registry PRE_READY_DURABLE_FILES — the enumerated guard surface) + the two-phase AppliedRecord (relcache.rs, additive durable state); unit = the rollback_compat tripwire (every current pre-ready file shape is additive / N-1-readable; a non-additive pre-ready chang...\n*1177|# --- Added 2026-06-11 (v0.4.2): the v0.4.1 fleet-roll Linux brain-respawn blocker (ADR-0018 Q3 amendment); rule 3 register-before-satisfy, rule 5 activate per task ---\n 1178|[[requirements]]\n 1179|id = \"REQ-HAZARD-BRAIN-RESPAWN-PATH\"\n 1180|title = \"The broker respawns the brain onto the APPLIED bytes, not the renamed old binary: the candidate-binary default is the canonical exe path captured ONCE at broker start, never a per-spawn std::env::current_exe() — on Linux current_exe (readlink /proc/self/exe) is inode-tracking and follows the `apply` rename (spt -> spt.old-N), so a resident broker would respawn the brain onto OLD bytes while recording `applied` (Windows GetModuleFileName is path-at-start, so Windows was green; ADR-0018 Q3 silen...\n*1181|required_stages = [\"doc\", \"impl\", \"unit\", \"int\"]  # activated v0.4.2 (2026-06-11): minted from the v0.4.1 fleet-roll blocker. doc = KNOWN-HAZARDS 6.11 + ADR-0018 Q3 amendment; int = brain_respawn_rename.rs (real broker process, in-place rename P->P.old-N + new bytes at P, respawn must run B not A — fails Linux pre-fix). Stages: impl = brainproc.rs canonical-exe capture at spawn_brain_supervisor + promotion bytes-gate in supervise_brain Promoted arm (TrialEnv ready_exe_hash/staged_artifact_hash); unit =...\n 1182|# --- Added 2026-06-03 from grill-with-docs (ADR-0012, hazard 7.3); inactive until M4-D7.5 ---\n 1183|[[requirements]]\n 1184|id = \"REQ-HAZARD-PSYCHE-OUTBOUND-PROXY\"\n...\n 1422|id = \"REQ-CLI-HELP-MARKDOWN\"\n*1423|title = \"`spt --help` (and every subcommand --help) renders the inline Markdown authored in the clap doc-comments as terminal styling, never as literal markers: `**bold**` → ANSI bold, `` `code` `` → ANSI cyan, `[text](url)` → `text`. The markers are STRIPPED either way — a raw `**` or backtick must NEVER reach the user (the operator-reported v0.12.0 defect: help text reads `**ctrl-b**` and stray backticks verbatim). Color/bold escapes are emitted ONLY when the help is going to a real terminal AN...\n*1424|required_stages = [\"impl\", \"unit\"]  # activated v0.12.1: impl = spt/src/helpfmt.rs render() (pure marker transform: bold/code/link, ANSI-CSI passthrough, line-bounded, unmatched-literal) + stdout_color() decision (IsTerminal && NO_COLOR unset && CLICOLOR!=0, CLICOLOR_FORCE overrides) + emit_clap_error() intercepting clap ErrorKind::DisplayHelp / DisplayHelpOnMissingArgumentOrSubcommand at cli::run try_get_matches_mut, plus bare_invocation render_help() path. unit = bold→ansi & code→ansi (color) vs st...\n 1425|\n 1426|# ───────────────────────────── v0.12.2 daemon-start no-window regression ──────────────────\n 1427|[[requirements]]\n...\n 1518|id = \"REQ-PICKER-UX-V013\"\n*1519|title = \"`spt endpoint run` picker UX (v0.13.0 operator dogfooding): (1) SKIP the first screen — open directly on 'Pick existing'; `n` jumps to 'Create new'. (2) AUTO-ATTACH after both Start-new AND Resume-from-history (both currently don't attach and show no stdout); add an `h` shortcut to run headless (no attach). (3) 'controlled by' shows the node NAME (node_label_display), not the raw hex. (4) Clean up Start-new output — drop the Rust `pid=Some(142748)` leak and the 'harness binds its perch on st...\n*1520|required_stages = []  # RETIRED/REDIRECTED (doyle W4 gate 2026-06-19): the W4 picker UX scope was DELIVERED as refinements of the EXISTING picker reqs, NOT under this id — fixes (1) open-on-Pick-existing, (2) attach-by-default + `h` headless, (4) terse bringup line landed under REQ-RUN-PICKER (v0.13.0-W4 extension); fix (3) controlled-by node-name landed under REQ-PICKER-4 (v0.13.0-W4 extension, the D item). This seed carries no evidence by design (folded, not duplicated) — kept as a redirect breadcr...\n 1521|\n 1522|# ── W5: driven_by self-heal (ONLINE+CONTROLLED clears without the detach IPC) ──\n 1523|[[requirements]]\n...\n 1555|title = \"`spt endpoint run` in an ATTACH/VIEW terminal action attaches BEFORE the freshly-spawned endpoint is online, so the attach races (or outright loses to) the harness bind. ROOT (doyle /diagnose, code-grounded): cmd_endpoint_run (cli.rs) does launch_harness_brokered_in -> (if start: return) -> run_attach with NO await-online between them. launch_harness_brokered_in returns once the harness PROCESS is spawned, but the broker-PTY bind (info status -> STATUS_ONLINE + the live session) lands ASYNC. Bot...\n*1556|required_stages = [\"impl\", \"unit\", \"int\"]  # ACTIVATED v0.13.0 (todlando, doyle-dispatched bugs 3+4). impl = cmd_endpoint_run await_endpoint_online gate (poll_online combinator) before run_attach on the attach/view path, FAIL-LOUD ENDPOINT_RUN_ONLINE_TIMEOUT on timeout (start/headless return above, untouched; only the offline-bringup Run path reaches here — an already-online endpoint routes Outcome::Attach, never double-counting the wait). unit = poll_online_fastpath_timeout_and_later_success (injected...\n 1557|\n 1558|# ── bug 2 (operator HITL 2026-06-19, doyle /diagnose + design ruling): rc Windows special keys dead → xterm-VT translator ──\n 1559|[[requirements]]\n...\n 1655|id = \"REQ-ENDPOINT-UNBOUND-ATTACH\"\n*1656|title = \"An spt-hosted endpoint is ATTACHABLE between spawn and bind: gate the attach on the broker SESSION being attachable (session+PTY+OutputLog exist at spawn, before bind), not on perch STATUS_ONLINE (bind). cmd_endpoint_run + `spt rc <id>` attach to a live broker session regardless of perch status (headless bringups too; lets an operator clear a bind-gating prompt) -- replaces await_endpoint_online; preserves REQ-HAZARD-RC-ATTACH-ONLINE-RACE's 'no attach before a session' intent at the earlier sess...\n 1657|required_stages = [\"doc\", \"impl\", \"unit\", \"int\"]  # doc active at design. impl+unit activated at W1. int activated at W6 — multi_subnet_bringup_e2e (fresh hold-unbound rc-attach pre-bind) + picker gather_renders_live_unbound (real render seam).\n 1658|\n 1659|# ═════════════════════════════ v0.16.0 — adapter-update arc + CLI/UX features ═════════════════════════════\n...\n 1883|title = \"#5: after 'Start now' in the endpoint picker, swap the bottom Options panel to a 'Choose project' list: (1) the endpoint's most recent project dir, (2) 'Here: <dir>' — the picker's launch cwd (only if different), (3) all other project-history dirs newest->oldest. Fire the step ONLY when (A) the run cwd mismatches a singular history entry, or (B) history has >1 entry; otherwise start immediately (today's behavior). Depends on REQ-PICKER-PROJECT-HISTORY-TRUTH (needs full DIRS from sessions.log, ...\n*1884|required_stages = [\"impl\", \"unit\"]  # ACTIVATED F026 W4 #5 (todlando 2026-07-03). impl = Screen::ChooseProject + PickerModel.run_cwd/choose_cursor fields + pure should_offer_project_choice(run_cwd,&[ProjectRef])->bool (len0 false / len1 fires iff non-empty dir mismatches run_cwd / len>1 true) + pure build_project_choices(run_cwd,history)->Vec<ProjectChoice{label,cwd}> (most-recent head, 'Here: <cwd>' when run_cwd differs from head dir, then history[1..]) + enter_choose_project_if_warranted (Confirm Start...\n 1885|\n 1886|[[requirements]]\n 1887|id = \"REQ-PICKER-RESUME-CONTEXT-PANEL\"\n...\n 1944|title = \"B1 (F028, hall-b diagnosis, verified 0.22.0): `endpoint run --id X --create` on an endpoint with a LIVE session mints a silent DUPLICATE session — and attach output can CROSS sessions (second create for diag-hallc minted a new session while the old ran; the new run's attach viewport rendered the OLD session's screen — claude resume-picker UI of pid 84512 while new claude 356020 had no -r). ROOT CLASS of the 0.21.0 attach-stall (zero events in FIRST_EVENT_GRACE rc.rs:1402 = attach bound to de...\n*1945|required_stages = [\"impl\", \"unit\", \"int\"]  # ACTIVATED F028 W3 B1 (todlando 2026-07-03); int ACTIVATED F028 wave-final (todlando 2026-07-03). impl = cmd_endpoint_run probes the broker session map (rc::SessionProbe::has_session) BEFORE spawning; a live session routes through run_on_live_decision to Reattach (attach intent) or RefuseAlreadyLive (headless), NEVER a duplicate spawn — the silent dup-session mint that crossed attach frames cannot occur when a second session is never minted for a live id (the...\n 1946|\n 1947|[[requirements]]\n 1948|id = \"REQ-RESUME-HARNESS-SESSION-ID\"\n 1949|title = \"B2 (F028, hall-b diagnosis, verified 0.22.0): respawn/`--resume` feeds the SPT session id to `claude -r`. After the 02:05 daemon bounce respawn built `claude.exe -r 70b5bfa40901b7d4` — an spt session id in claude's OWN session-id namespace -> claude hangs forever at a 'No sessions match' resume-picker while the endpoint reads online. Hits after EVERY daemon bounce + every picker Resume. The HARNESS session id (claude UUID, stamped in sessions.log/info.json by the hooks) is what {session_id} mu...\n*1950|required_stages = [\"doc\", \"impl\", \"unit\"]  # doc ACTIVATED CONDUIT W1 (todlando 2026-08-28, releases#157): the FreshNoHarnessSession arm and its loud RESUME_NO_HARNESS_SESSION notice were shipped undocumented on every published surface — the generated manifest schema, docs/MANIFEST.md and the harness-contract page all described resume selection with no third outcome, so an adapter author had no way to learn that a resume can legitimately start FRESH. doc = that outcome stated on the published schema de...\n 1951|\n 1952|[[requirements]]\n 1953|id = \"REQ-PRESENCE-CONTROL-REAP-ON-EXIT\"\n...\n 1959|title = \"B4 (F028, hall-b diagnosis, verified 0.22.0): `--resume` respawns a SECOND harness onto the SAME session without reaping the first. Observed live: resume of b4421cf9 spawned pid 34432 while gen1 (250376) kept running — two claude.exe stacks, one session id. FIX: resume must reap/refuse when the session already has a live harness. See triage B4.\"\n*1960|required_stages = [\"impl\", \"unit\", \"int\"]  # ACTIVATED F028 W3 B4 (todlando 2026-07-03; SHARED root with B1); int ACTIVATED F028 wave-final (todlando 2026-07-03). impl = the SAME cmd_endpoint_run live-session guard (run_on_live_decision): a `--resume` over an endpoint that already has a live harness/session Reattaches or Refuses instead of spawning a SECOND harness onto the same session (the observed gen1+gen2 double claude.exe on one session id). unit = run_on_live_never_duplicates (shared matrix). int ...\n 1961|\n 1962|[[requirements]]\n 1963|id = \"REQ-CRC-SWAP-OLD-DISPLACE\"\n...\n 2068|id = \"REQ-PICKER-WINDOW-TITLE\"\n*2069|title = \"B-5 (F029, operator): `spt endpoint run`'s interactive picker window/tab is untitled — hard to find among many terminals. Set the window/tab title to `SPT Endpoint Picker`. Anchor picker/mod.rs:88 setup_terminal (crossterm SetTitle in the execute! chain). Set-only is acceptable (crossterm can't cheaply read the prior title to restore). Applies ONLY to the interactive picker path — a non-interactive/headless bringup (REQ-HOST-RUN-1) must NOT retitle the operator's terminal. See triage B-5.\"\n*2070|required_stages = [\"impl\"]  # ACTIVATED F029 W2 (todlando 2026-07-03). impl = mod.rs setup_terminal execute!(SetTitle(\\\"SPT Endpoint Picker\\\"), EnterAlternateScreen) — set-only (no restore; crossterm has no cheap get-title). HITL-verify leg (a live-terminal FFI side-effect, same manual-verify class as REQ-RUN-PICKER's key loop and REQ-CLI-WIN-VT-ENABLE's SetConsoleMode) — NO unit stage: setup_terminal is only reached from the interactive run() path, the non-interactive REQ-HOST-RUN-1 flow never calls...\n 2071|\n 2072|[[requirements]]\n 2073|id = \"REQ-PICKER-KEY-GATE-LAUNCH-CAPABLE\"\n*2074|title = \"B-1 (F029, operator): the `h` (headless start) / `s` (shortcut) keybinds fire from broad picker contexts (mod.rs handle_confirm_key / ChooseProject / Resume) regardless of whether the highlighted row would LAUNCH the endpoint. Restrict both to launch-capable highlights: (a) `Start now` in the immediate-start case (should_offer_project_choice == false), (b) a Choose-project row, (c) a Resume-from-history row. The footer hint line must render `h`/`s` ONLY when actually live (hint truth = availabil...\n\n## .github/ci/\n### ci-notify-selftest.sh\n 225|  case \"$output\" in\n*226|    *\"::warning title=CI notification attribution missing::\"*) saw_warning=yes ;;\n 227|    *) saw_warning=no ;;\n 228|  esac\n 229|  ok \"$label attribution warning\" \"$saw_warning\" \"$4\"\n### ci-notify.sh\n 204|if [ \"$trailer_rc\" -ne 0 ]; then\n*205|  echo \"::warning title=CI notification attribution missing::Could not read or parse head commit (rc=$trailer_rc) for 'Co-authored by: <agent>' — notifying doyle only\"\n 206|elif [ -z \"$trailer\" ]; then\n*207|  echo \"::warning title=CI notification attribution missing::Head commit has no parseable line-anchored 'Co-authored by: <agent>' trailer — notifying doyle only\"\n 208|elif [ \"$trailer\" = \"doyle\" ]; then\n 209|  echo \"ci-notify: co-author is doyle — no second recipient\"\n 210|else\n### find-cwd-holders.ps1\n 18|# \"no conhosts\" is not an all-clear (KNOWN-HAZARDS 5.18). A `conhost.exe\n*19|# --headless …` is different: that is a ConPTY host, it INHERITS the cwd of\n 20|# whoever created the pseudoconsole, and it can be the sole holder — the case\n 21|# that pinned a BAROMETER W4 worktree. Read the command line, not just the name.\n 22|#\n### reap-census.ps1\n 177|    if ($script:CensusScoped -gt 0) {\n*178|        Write-Output \"::warning::CI-CENSUS start: $($script:CensusScoped) scoped daemon(s) inherited from a previous run — this battery is starting contaminated.\"\n 179|    }\n 180|    exit 0\n 181|}\n...\n 233|        # loudly rather than reporting a clean reap.\n*234|        Write-Output \"::warning::CI-REAP could not stop pid=$($proc.Id) $($proc.ProcessName): $($_.Exception.Message)\"\n 235|    }\n 236|}\n 237|\n...\n 270|    }\n*271|    Write-Output \"::warning::$msg\"\n 272|}\n 273|exit 0\n### reap-census.sh\n 184|  if [ \"$rc\" -gt 1 ]; then\n*185|    echo \"::warning::CI-CENSUS: the flood-orphan probe failed (pgrep exit $rc — a usage error, not a no-match). Flood count is UNKNOWN, not zero.\" >&2\n 186|    printf 'unknown'\n 187|    return\n 188|  fi\n...\n 254|  if [ \"${CENSUS_SCOPED:-0}\" -gt 0 ]; then\n*255|    echo \"::warning::CI-CENSUS start: ${CENSUS_SCOPED} scoped daemon(s) inherited from a previous run — this battery is starting contaminated.\"\n 256|  fi\n 257|  exit 0\n 258|fi\n...\n 287|    kill_failed=$((kill_failed + 1))\n*288|    echo \"::warning::CI-REAP could not stop pid=$pid $exe\"\n 289|  fi\n 290|done\n 291|\n...\n 310|  fi\n*311|  echo \"::warning::$msg\"\n 312|fi\n 313|exit 0\n### test-temp-sandbox.ps1\n 88|    catch {\n*89|        Write-Output \"::warning::CI-TMP cleanup attempt $attempt/$maxAttempts could not remove $sandbox`: $($_.Exception.Message)\"\n 90|    }\n 91|\n 92|    if (-not (Test-Path -LiteralPath $sandbox)) {\n...\n 97|    if ($attempt -lt $maxAttempts) {\n*98|        Write-Output \"::warning::CI-TMP cleanup attempt $attempt/$maxAttempts left $sandbox; retrying\"\n 99|        Start-Sleep -Seconds $attempt\n 100|    }\n 101|}\n### test-temp-sandbox.sh\n 85|      if ! rm -rf -- \"$sandbox_root\"; then\n*86|        echo \"::warning::CI-TMP cleanup attempt $attempt/5 could not remove $sandbox_root\"\n 87|      fi\n 88|      if [ ! -e \"$sandbox_root\" ] && [ ! -L \"$sandbox_root\" ]; then\n 89|        echo \"CI-TMP cleanup: removed $sandbox_root on attempt $attempt/5\"\n...\n 92|      if [ \"$attempt\" -lt 5 ]; then\n*93|        echo \"::warning::CI-TMP cleanup attempt $attempt/5 left $sandbox_root; retrying\"\n 94|        sleep \"$attempt\"\n 95|      fi\n 96|    done\n### traceable-reqs-selftest.sh\n 40|  # authentication/build, not just report an unrelated downstream exit 128.\n*41|  case \"$out\" in *\"pin=0.4.1\"*) ;; *) printf 'FAIL missing pin: %s\\n' \"$out\"; exit 1;; esac\n 42|  case \"$out\" in *\"box=\"*) ;; *) printf 'FAIL missing box: %s\\n' \"$out\"; exit 1;; esac\n 43|  if [ \"$label\" = stale-no-token ]; then\n 44|    case \"$out\" in *\"0.2.0\"*\"TRACEABLE_REQS_TOKEN\"*) ;; *) printf 'FAIL mismatch/auth diagnostic: %s\\n' \"$out\"; exit 1;; esac\n...\n 51|  if [ \"$mode\" = install ] && [ \"$rc\" = 0 ]; then\n*52|    [ \"$(\"$root/checkout/traceable-reqs\" --version)\" = 'traceable-reqs 0.4.1' ]\n 53|  else\n 54|    [ ! -e \"$root/checkout/traceable-reqs\" ]\n 55|  fi\n...\n 60|run_case stale-no-token 'traceable-reqs 0.2.0' 0 '' precheck 1\n*61|run_case matching-no-token 'traceable-reqs 0.4.1' 0 '' precheck 0\n*62|run_case matching-install 'traceable-reqs 0.4.1' 0 '' install 0\n 63|run_case missing-no-token missing 0 '' install 1\n*64|run_case failed-version 'traceable-reqs 0.4.1' 7 '' precheck 1\n 65|run_case regex-lookalike 'traceable-reqs 0x4x1' 0 '' precheck 1\n 66|run_case repair-admitted 'traceable-reqs 0.2.0' 0 TOKEN_CANARY precheck 0\n 67|run_case clone-refusal 'traceable-reqs 0.2.0' 0 TOKEN_CANARY install 128\n### traceable-reqs.sh\n 4|set -euo pipefail\n*5|# 0.4.1 fixes file-root enumeration dropping present doc evidence (IR-109).\n*6|WANT=0.4.1\n 7|BIN=\"$HOME/.local/bin/traceable-reqs\"\n 8|mode=\"${1:-precheck}\"\n 9|case \"$mode\" in precheck|install) ;; *) echo 'usage: traceable-reqs.sh [precheck|install]' >&2; exit 2;; esac\n...\n 26|if ! probe; then\n*27|  echo '::warning title=Checker pin/runner disagreement::The runner does not supply the pinned checker; see CHECKER_PIN above. Coverage has not run.'\n 28|  if [ -z \"${GH_TOKEN:-}\" ]; then\n 29|    echo '::error title=Checker repair credential missing::TRACEABLE_REQS_TOKEN is absent. Install the pinned checker on the runner or have the operator provision read access to BigscreenVR/traceable-reqs. No clone or build attempted.'\n 30|    exit 1\n\n## crates/xtask/src/\n### main.rs\n 164|// [impl->REQ-DOCS-5]\n*165|fn cli_reference(bin: &Path) -> Result<String, String> {\n 166|    let mut out = String::from(\n 167|        \"# CLI reference\\n\\n\\\n 168|         > **Generated** from the `spt` binary's own `--help` output \\\n...\n 440|\n*441|fn gen(check: bool) {\n 442|    let root = repo_root();\n 443|    let bin = spt_bin(&root);\n 444|    if let Err(e) = gen_cli_reference(&root, &bin, check) {\n\n[Some lines truncated to 512 chars]"}],"details":{"scopePath":".worktrees/hertz-ir86-disk-delta/.github, .worktrees/hertz-ir86-disk-delta/crates/xtask/src, .worktrees/hertz-ir86-disk-delta/traceable-reqs.toml","searchPath":"C:\\Users\\decid\\Documents\\projects\\spt-core\\.worktrees\\hertz-ir86-disk-delta","cwd":"C:\\Users\\decid\\Documents\\projects\\spt-core","matchCount":45,"fileCount":11,"files":[".worktrees/hertz-ir86-disk-delta/.github/ci/ci-notify-selftest.sh",".worktrees/hertz-ir86-disk-delta/.github/ci/ci-notify.sh",".worktrees/hertz-ir86-disk-delta/.github/ci/find-cwd-holders.ps1",".worktrees/hertz-ir86-disk-delta/.github/ci/reap-census.ps1",".worktrees/hertz-ir86-disk-delta/.github/ci/reap-census.sh",".worktrees/hertz-ir86-disk-delta/.github/ci/test-temp-sandbox.ps1",".worktrees/hertz-ir86-disk-delta/.github/ci/test-temp-sandbox.sh",".worktrees/hertz-ir86-disk-delta/.github/ci/traceable-reqs-selftest.sh",".worktrees/hertz-ir86-disk-delta/.github/ci/traceable-reqs.sh",".worktrees/hertz-ir86-disk-delta/crates/xtask/src/main.rs",".worktrees/hertz-ir86-disk-delta/traceable-reqs.toml"],"fileMatches":[{"path":".worktrees/hertz-ir86-disk-delta/.github/ci/ci-notify-selftest.sh","count":1},{"path":".worktrees/hertz-ir86-disk-delta/.github/ci/ci-notify.sh","count":2},{"path":".worktrees/hertz-ir86-disk-delta/.github/ci/find-cwd-holders.ps1","count":1},{"path":".worktrees/hertz-ir86-disk-delta/.github/ci/reap-census.ps1","count":3},{"path":".worktrees/hertz-ir86-disk-delta/.github/ci/reap-census.sh","count":4},{"path":".worktrees/hertz-ir86-disk-delta/.github/ci/test-temp-sandbox.ps1","count":2},{"path":".worktrees/hertz-ir86-disk-delta/.github/ci/test-temp-sandbox.sh","count":2},{"path":".worktrees/hertz-ir86-disk-delta/.github/ci/traceable-reqs-selftest.sh","count":5},{"path":".worktrees/hertz-ir86-disk-delta/.github/ci/traceable-reqs.sh","count":3},{"path":".worktrees/hertz-ir86-disk-delta/crates/xtask/src/main.rs","count":2},{"path":".worktrees/hertz-ir86-disk-delta/traceable-reqs.toml","count":20}],"truncated":true,"perFileLimitReached":20,"displayContent":"# .worktrees/hertz-ir86-disk-delta/\n## traceable-reqs.toml\n   22│\n  *23│[placement]\n   24│enforce = \"on\"\n  *25│module_banner = \"accept\"\n   26│\n   27│[[requirements]]\n   28│id = \"REQ-STATUS-LIVE-SUPERVISOR-PID\"\n     │...\n  544│title = \"Interactive `spt endpoint run` picker (ratatui TUI): bare `spt` on an interactive terminal enters an in-process picker (flags-present = the REQ-HOST-RUN-1 non-interactive path, untouched). Layer 1 picks kind (Create new | Pick existing). Create-new: choose a registered kind=\\\"harness\\\" adapter with its shipped+local profiles tree-nested (registry::registered / manifest.profiles / local_profile_names) → enter a charset-validated id → start. Pick-existing: category select (left/right) over [<c...\n *545│required_stages = [\"doc\", \"impl\", \"unit\"]  # activated M12-W2 (no int: TUI Buffer + state-model unit asserts; live loop manual-verify; bringup path int-covered by REQ-HOST-RUN-1/REQ-RC-1). v0.13.0-W4 UX refinements (todlando 2026-06-19): (1) bare picker OPENS on Pick-existing (Kind = jump-target, `n` → create); (2) Start-now + Resume-from-history ATTACH by default (was detached/no-stdout) with an `h` headless escape (start, no attach); (4) the bringup stderr line is a terse machine token (dropped the R...\n  546│[[requirements]]\n  547│id = \"REQ-RUN-SHORTCUT\"\n  548│title = \"`<basename>-<id>` launcher shortcut generation (picker `s` keybind, M12-W2-T2.4): from any pre-start options set the picker writes/updates a `<basename>-<id>` launcher at the project root whose body is `spt go <id>` (since U3 it bakes no selection; pre-U3 it baked the non-interactive flags: adapter[:profile] + id + (create|resume) + (start|attach|view); Kick/Instantiate/Change-adapter/Fork are interactive-only, not bakeable). BASENAME IS A PARAMETER (operator rev. 2026-06-14): harness-agnostic s...\n     │...\n  559│id = \"REQ-ELEVATE-1\"\n *560│title = \"Cross-platform self-elevating re-launch for privilege-gated commands: a pure decision seam `decide_elevation_path(os, elevation, interactive_tty, has_display, has_pkexec, has_term_emulator) -> ElevatePath{AlreadyElevated, InlineSudo, UacWindow, Pkexec, TerminalEmulator, PrintHint}` selecting how to re-acquire privilege, and the per-OS impure launchers it dispatches — Windows UAC console (ShellExecuteW `runas` on the abs-exe + verbatim argv; the elevated child does the work, prints 'You can clo...\n  561│required_stages = [\"doc\", \"impl\", \"unit\"]  # activated M12-W4 (no int: the decision matrix is unit-tested across the os×elevation×env grid; each actual launch needs a real UAC/polkit/sudo/TTY → manual-verify leg, REQ-PAIR-6 precedent)\n  562│\n  563│# ── M12 Wave 5: whoami → endpoint-list alias (M12-PLAN.md Wave 5; doyle ruling\n     │...\n  739│id = \"REQ-HAZARD-UNHOST-PSYCHE-REAP\"\n *740│title = \"On un-host, the detached `{id}-psyche` HARNESS PROCESS is reaped — not just its in-brain pulse-driver thread. Today stop_host (livehost.rs:203) trips the HostedLife stop flag + JOINS the driver thread, but the Psyche is a detached harness process (spawn_psyche → ManifestRuntime detached spawn, runtime.rs:341-356; its pid is untracked in HostedLife though stamped on the `{id}-psyche` perch, where residency-confirm already reads it). So endpoint-stop / mid-life agent-death / a B2/B5 offline-th...\n  741│required_stages = []  # SUPERSEDED 2026-07-04 (F-030 W3, todlando) by REQ-PSYCHE-EPHEMERAL-DRIVER (no resident = no orphan to reap). host_one spawns no resident psyche, so un-host has nothing detached to reap — HostedLife.psyche_child + the stop_host handle-reap + stop_host_reaps_the_detached_psyche_process are DELETED. Kept as a stable pointer (no dangling required stage on deleted evidence).\n  742│[[requirements]]\n  743│id = \"REQ-ENDPOINT-PURGE\"\n     │...\n 1176│required_stages = [\"doc\", \"impl\", \"unit\"]  # doc activated restoration D1 (KNOWN-HAZARDS 6.8 + ADR-0018 + design doc V1). impl/unit activated restoration D6-3 (the one D6 toml activation): impl = rollback_compat.rs (the pre-ready durable-file registry PRE_READY_DURABLE_FILES — the enumerated guard surface) + the two-phase AppliedRecord (relcache.rs, additive durable state); unit = the rollback_compat tripwire (every current pre-ready file shape is additive / N-1-readable; a non-additive pre-ready chang...\n*1177│# --- Added 2026-06-11 (v0.4.2): the v0.4.1 fleet-roll Linux brain-respawn blocker (ADR-0018 Q3 amendment); rule 3 register-before-satisfy, rule 5 activate per task ---\n 1178│[[requirements]]\n 1179│id = \"REQ-HAZARD-BRAIN-RESPAWN-PATH\"\n 1180│title = \"The broker respawns the brain onto the APPLIED bytes, not the renamed old binary: the candidate-binary default is the canonical exe path captured ONCE at broker start, never a per-spawn std::env::current_exe() — on Linux current_exe (readlink /proc/self/exe) is inode-tracking and follows the `apply` rename (spt -> spt.old-N), so a resident broker would respawn the brain onto OLD bytes while recording `applied` (Windows GetModuleFileName is path-at-start, so Windows was green; ADR-0018 Q3 silen...\n*1181│required_stages = [\"doc\", \"impl\", \"unit\", \"int\"]  # activated v0.4.2 (2026-06-11): minted from the v0.4.1 fleet-roll blocker. doc = KNOWN-HAZARDS 6.11 + ADR-0018 Q3 amendment; int = brain_respawn_rename.rs (real broker process, in-place rename P->P.old-N + new bytes at P, respawn must run B not A — fails Linux pre-fix). Stages: impl = brainproc.rs canonical-exe capture at spawn_brain_supervisor + promotion bytes-gate in supervise_brain Promoted arm (TrialEnv ready_exe_hash/staged_artifact_hash); unit =...\n 1182│# --- Added 2026-06-03 from grill-with-docs (ADR-0012, hazard 7.3); inactive until M4-D7.5 ---\n 1183│[[requirements]]\n 1184│id = \"REQ-HAZARD-PSYCHE-OUTBOUND-PROXY\"\n     │...\n 1422│id = \"REQ-CLI-HELP-MARKDOWN\"\n*1423│title = \"`spt --help` (and every subcommand --help) renders the inline Markdown authored in the clap doc-comments as terminal styling, never as literal markers: `**bold**` → ANSI bold, `` `code` `` → ANSI cyan, `[text](url)` → `text`. The markers are STRIPPED either way — a raw `**` or backtick must NEVER reach the user (the operator-reported v0.12.0 defect: help text reads `**ctrl-b**` and stray backticks verbatim). Color/bold escapes are emitted ONLY when the help is going to a real terminal AN...\n*1424│required_stages = [\"impl\", \"unit\"]  # activated v0.12.1: impl = spt/src/helpfmt.rs render() (pure marker transform: bold/code/link, ANSI-CSI passthrough, line-bounded, unmatched-literal) + stdout_color() decision (IsTerminal && NO_COLOR unset && CLICOLOR!=0, CLICOLOR_FORCE overrides) + emit_clap_error() intercepting clap ErrorKind::DisplayHelp / DisplayHelpOnMissingArgumentOrSubcommand at cli::run try_get_matches_mut, plus bare_invocation render_help() path. unit = bold→ansi & code→ansi (color) vs st...\n 1425│\n 1426│# ───────────────────────────── v0.12.2 daemon-start no-window regression ──────────────────\n 1427│[[requirements]]\n     │...\n 1518│id = \"REQ-PICKER-UX-V013\"\n*1519│title = \"`spt endpoint run` picker UX (v0.13.0 operator dogfooding): (1) SKIP the first screen — open directly on 'Pick existing'; `n` jumps to 'Create new'. (2) AUTO-ATTACH after both Start-new AND Resume-from-history (both currently don't attach and show no stdout); add an `h` shortcut to run headless (no attach). (3) 'controlled by' shows the node NAME (node_label_display), not the raw hex. (4) Clean up Start-new output — drop the Rust `pid=Some(142748)` leak and the 'harness binds its perch on st...\n*1520│required_stages = []  # RETIRED/REDIRECTED (doyle W4 gate 2026-06-19): the W4 picker UX scope was DELIVERED as refinements of the EXISTING picker reqs, NOT under this id — fixes (1) open-on-Pick-existing, (2) attach-by-default + `h` headless, (4) terse bringup line landed under REQ-RUN-PICKER (v0.13.0-W4 extension); fix (3) controlled-by node-name landed under REQ-PICKER-4 (v0.13.0-W4 extension, the D item). This seed carries no evidence by design (folded, not duplicated) — kept as a redirect breadcr...\n 1521│\n 1522│# ── W5: driven_by self-heal (ONLINE+CONTROLLED clears without the detach IPC) ──\n 1523│[[requirements]]\n     │...\n 1555│title = \"`spt endpoint run` in an ATTACH/VIEW terminal action attaches BEFORE the freshly-spawned endpoint is online, so the attach races (or outright loses to) the harness bind. ROOT (doyle /diagnose, code-grounded): cmd_endpoint_run (cli.rs) does launch_harness_brokered_in -> (if start: return) -> run_attach with NO await-online between them. launch_harness_brokered_in returns once the harness PROCESS is spawned, but the broker-PTY bind (info status -> STATUS_ONLINE + the live session) lands ASYNC. Bot...\n*1556│required_stages = [\"impl\", \"unit\", \"int\"]  # ACTIVATED v0.13.0 (todlando, doyle-dispatched bugs 3+4). impl = cmd_endpoint_run await_endpoint_online gate (poll_online combinator) before run_attach on the attach/view path, FAIL-LOUD ENDPOINT_RUN_ONLINE_TIMEOUT on timeout (start/headless return above, untouched; only the offline-bringup Run path reaches here — an already-online endpoint routes Outcome::Attach, never double-counting the wait). unit = poll_online_fastpath_timeout_and_later_success (injected...\n 1557│\n 1558│# ── bug 2 (operator HITL 2026-06-19, doyle /diagnose + design ruling): rc Windows special keys dead → xterm-VT translator ──\n 1559│[[requirements]]\n     │...\n 1655│id = \"REQ-ENDPOINT-UNBOUND-ATTACH\"\n*1656│title = \"An spt-hosted endpoint is ATTACHABLE between spawn and bind: gate the attach on the broker SESSION being attachable (session+PTY+OutputLog exist at spawn, before bind), not on perch STATUS_ONLINE (bind). cmd_endpoint_run + `spt rc <id>` attach to a live broker session regardless of perch status (headless bringups too; lets an operator clear a bind-gating prompt) -- replaces await_endpoint_online; preserves REQ-HAZARD-RC-ATTACH-ONLINE-RACE's 'no attach before a session' intent at the earlier sess...\n 1657│required_stages = [\"doc\", \"impl\", \"unit\", \"int\"]  # doc active at design. impl+unit activated at W1. int activated at W6 — multi_subnet_bringup_e2e (fresh hold-unbound rc-attach pre-bind) + picker gather_renders_live_unbound (real render seam).\n 1658│\n 1659│# ═════════════════════════════ v0.16.0 — adapter-update arc + CLI/UX features ═════════════════════════════\n     │...\n 1883│title = \"#5: after 'Start now' in the endpoint picker, swap the bottom Options panel to a 'Choose project' list: (1) the endpoint's most recent project dir, (2) 'Here: <dir>' — the picker's launch cwd (only if different), (3) all other project-history dirs newest->oldest. Fire the step ONLY when (A) the run cwd mismatches a singular history entry, or (B) history has >1 entry; otherwise start immediately (today's behavior). Depends on REQ-PICKER-PROJECT-HISTORY-TRUTH (needs full DIRS from sessions.log, ...\n*1884│required_stages = [\"impl\", \"unit\"]  # ACTIVATED F026 W4 #5 (todlando 2026-07-03). impl = Screen::ChooseProject + PickerModel.run_cwd/choose_cursor fields + pure should_offer_project_choice(run_cwd,&[ProjectRef])->bool (len0 false / len1 fires iff non-empty dir mismatches run_cwd / len>1 true) + pure build_project_choices(run_cwd,history)->Vec<ProjectChoice{label,cwd}> (most-recent head, 'Here: <cwd>' when run_cwd differs from head dir, then history[1..]) + enter_choose_project_if_warranted (Confirm Start...\n 1885│\n 1886│[[requirements]]\n 1887│id = \"REQ-PICKER-RESUME-CONTEXT-PANEL\"\n     │...\n 1944│title = \"B1 (F028, hall-b diagnosis, verified 0.22.0): `endpoint run --id X --create` on an endpoint with a LIVE session mints a silent DUPLICATE session — and attach output can CROSS sessions (second create for diag-hallc minted a new session while the old ran; the new run's attach viewport rendered the OLD session's screen — claude resume-picker UI of pid 84512 while new claude 356020 had no -r). ROOT CLASS of the 0.21.0 attach-stall (zero events in FIRST_EVENT_GRACE rc.rs:1402 = attach bound to de...\n*1945│required_stages = [\"impl\", \"unit\", \"int\"]  # ACTIVATED F028 W3 B1 (todlando 2026-07-03); int ACTIVATED F028 wave-final (todlando 2026-07-03). impl = cmd_endpoint_run probes the broker session map (rc::SessionProbe::has_session) BEFORE spawning; a live session routes through run_on_live_decision to Reattach (attach intent) or RefuseAlreadyLive (headless), NEVER a duplicate spawn — the silent dup-session mint that crossed attach frames cannot occur when a second session is never minted for a live id (the...\n 1946│\n 1947│[[requirements]]\n 1948│id = \"REQ-RESUME-HARNESS-SESSION-ID\"\n 1949│title = \"B2 (F028, hall-b diagnosis, verified 0.22.0): respawn/`--resume` feeds the SPT session id to `claude -r`. After the 02:05 daemon bounce respawn built `claude.exe -r 70b5bfa40901b7d4` — an spt session id in claude's OWN session-id namespace -> claude hangs forever at a 'No sessions match' resume-picker while the endpoint reads online. Hits after EVERY daemon bounce + every picker Resume. The HARNESS session id (claude UUID, stamped in sessions.log/info.json by the hooks) is what {session_id} mu...\n*1950│required_stages = [\"doc\", \"impl\", \"unit\"]  # doc ACTIVATED CONDUIT W1 (todlando 2026-08-28, releases#157): the FreshNoHarnessSession arm and its loud RESUME_NO_HARNESS_SESSION notice were shipped undocumented on every published surface — the generated manifest schema, docs/MANIFEST.md and the harness-contract page all described resume selection with no third outcome, so an adapter author had no way to learn that a resume can legitimately start FRESH. doc = that outcome stated on the published schema de...\n 1951│\n 1952│[[requirements]]\n 1953│id = \"REQ-PRESENCE-CONTROL-REAP-ON-EXIT\"\n     │...\n 1959│title = \"B4 (F028, hall-b diagnosis, verified 0.22.0): `--resume` respawns a SECOND harness onto the SAME session without reaping the first. Observed live: resume of b4421cf9 spawned pid 34432 while gen1 (250376) kept running — two claude.exe stacks, one session id. FIX: resume must reap/refuse when the session already has a live harness. See triage B4.\"\n*1960│required_stages = [\"impl\", \"unit\", \"int\"]  # ACTIVATED F028 W3 B4 (todlando 2026-07-03; SHARED root with B1); int ACTIVATED F028 wave-final (todlando 2026-07-03). impl = the SAME cmd_endpoint_run live-session guard (run_on_live_decision): a `--resume` over an endpoint that already has a live harness/session Reattaches or Refuses instead of spawning a SECOND harness onto the same session (the observed gen1+gen2 double claude.exe on one session id). unit = run_on_live_never_duplicates (shared matrix). int ...\n 1961│\n 1962│[[requirements]]\n 1963│id = \"REQ-CRC-SWAP-OLD-DISPLACE\"\n     │...\n 2068│id = \"REQ-PICKER-WINDOW-TITLE\"\n*2069│title = \"B-5 (F029, operator): `spt endpoint run`'s interactive picker window/tab is untitled — hard to find among many terminals. Set the window/tab title to `SPT Endpoint Picker`. Anchor picker/mod.rs:88 setup_terminal (crossterm SetTitle in the execute! chain). Set-only is acceptable (crossterm can't cheaply read the prior title to restore). Applies ONLY to the interactive picker path — a non-interactive/headless bringup (REQ-HOST-RUN-1) must NOT retitle the operator's terminal. See triage B-5.\"\n*2070│required_stages = [\"impl\"]  # ACTIVATED F029 W2 (todlando 2026-07-03). impl = mod.rs setup_terminal execute!(SetTitle(\\\"SPT Endpoint Picker\\\"), EnterAlternateScreen) — set-only (no restore; crossterm has no cheap get-title). HITL-verify leg (a live-terminal FFI side-effect, same manual-verify class as REQ-RUN-PICKER's key loop and REQ-CLI-WIN-VT-ENABLE's SetConsoleMode) — NO unit stage: setup_terminal is only reached from the interactive run() path, the non-interactive REQ-HOST-RUN-1 flow never calls...\n 2071│\n 2072│[[requirements]]\n 2073│id = \"REQ-PICKER-KEY-GATE-LAUNCH-CAPABLE\"\n*2074│title = \"B-1 (F029, operator): the `h` (headless start) / `s` (shortcut) keybinds fire from broad picker contexts (mod.rs handle_confirm_key / ChooseProject / Resume) regardless of whether the highlighted row would LAUNCH the endpoint. Restrict both to launch-capable highlights: (a) `Start now` in the immediate-start case (should_offer_project_choice == false), (b) a Choose-project row, (c) a Resume-from-history row. The footer hint line must render `h`/`s` ONLY when actually live (hint truth = availabil...\n\n## .github/ci/\n### ci-notify-selftest.sh\n 225│  case \"$output\" in\n*226│    *\"::warning title=CI notification attribution missing::\"*) saw_warning=yes ;;\n 227│    *) saw_warning=no ;;\n 228│  esac\n 229│  ok \"$label attribution warning\" \"$saw_warning\" \"$4\"\n### ci-notify.sh\n 204│if [ \"$trailer_rc\" -ne 0 ]; then\n*205│  echo \"::warning title=CI notification attribution missing::Could not read or parse head commit (rc=$trailer_rc) for 'Co-authored by: <agent>' — notifying doyle only\"\n 206│elif [ -z \"$trailer\" ]; then\n*207│  echo \"::warning title=CI notification attribution missing::Head commit has no parseable line-anchored 'Co-authored by: <agent>' trailer — notifying doyle only\"\n 208│elif [ \"$trailer\" = \"doyle\" ]; then\n 209│  echo \"ci-notify: co-author is doyle — no second recipient\"\n 210│else\n### find-cwd-holders.ps1\n 18│# \"no conhosts\" is not an all-clear (KNOWN-HAZARDS 5.18). A `conhost.exe\n*19│# --headless …` is different: that is a ConPTY host, it INHERITS the cwd of\n 20│# whoever created the pseudoconsole, and it can be the sole holder — the case\n 21│# that pinned a BAROMETER W4 worktree. Read the command line, not just the name.\n 22│#\n### reap-census.ps1\n 177│    if ($script:CensusScoped -gt 0) {\n*178│        Write-Output \"::warning::CI-CENSUS start: $($script:CensusScoped) scoped daemon(s) inherited from a previous run — this battery is starting contaminated.\"\n 179│    }\n 180│    exit 0\n 181│}\n    │...\n 233│        # loudly rather than reporting a clean reap.\n*234│        Write-Output \"::warning::CI-REAP could not stop pid=$($proc.Id) $($proc.ProcessName): $($_.Exception.Message)\"\n 235│    }\n 236│}\n 237│\n    │...\n 270│    }\n*271│    Write-Output \"::warning::$msg\"\n 272│}\n 273│exit 0\n### reap-census.sh\n 184│  if [ \"$rc\" -gt 1 ]; then\n*185│    echo \"::warning::CI-CENSUS: the flood-orphan probe failed (pgrep exit $rc — a usage error, not a no-match). Flood count is UNKNOWN, not zero.\" >&2\n 186│    printf 'unknown'\n 187│    return\n 188│  fi\n    │...\n 254│  if [ \"${CENSUS_SCOPED:-0}\" -gt 0 ]; then\n*255│    echo \"::warning::CI-CENSUS start: ${CENSUS_SCOPED} scoped daemon(s) inherited from a previous run — this battery is starting contaminated.\"\n 256│  fi\n 257│  exit 0\n 258│fi\n    │...\n 287│    kill_failed=$((kill_failed + 1))\n*288│    echo \"::warning::CI-REAP could not stop pid=$pid $exe\"\n 289│  fi\n 290│done\n 291│\n    │...\n 310│  fi\n*311│  echo \"::warning::$msg\"\n 312│fi\n 313│exit 0\n### test-temp-sandbox.ps1\n  88│    catch {\n *89│        Write-Output \"::warning::CI-TMP cleanup attempt $attempt/$maxAttempts could not remove $sandbox`: $($_.Exception.Message)\"\n  90│    }\n  91│\n  92│    if (-not (Test-Path -LiteralPath $sandbox)) {\n    │...\n  97│    if ($attempt -lt $maxAttempts) {\n *98│        Write-Output \"::warning::CI-TMP cleanup attempt $attempt/$maxAttempts left $sandbox; retrying\"\n  99│        Start-Sleep -Seconds $attempt\n 100│    }\n 101│}\n### test-temp-sandbox.sh\n 85│      if ! rm -rf -- \"$sandbox_root\"; then\n*86│        echo \"::warning::CI-TMP cleanup attempt $attempt/5 could not remove $sandbox_root\"\n 87│      fi\n 88│      if [ ! -e \"$sandbox_root\" ] && [ ! -L \"$sandbox_root\" ]; then\n 89│        echo \"CI-TMP cleanup: removed $sandbox_root on attempt $attempt/5\"\n   │...\n 92│      if [ \"$attempt\" -lt 5 ]; then\n*93│        echo \"::warning::CI-TMP cleanup attempt $attempt/5 left $sandbox_root; retrying\"\n 94│        sleep \"$attempt\"\n 95│      fi\n 96│    done\n### traceable-reqs-selftest.sh\n 40│  # authentication/build, not just report an unrelated downstream exit 128.\n*41│  case \"$out\" in *\"pin=0.4.1\"*) ;; *) printf 'FAIL missing pin: %s\\n' \"$out\"; exit 1;; esac\n 42│  case \"$out\" in *\"box=\"*) ;; *) printf 'FAIL missing box: %s\\n' \"$out\"; exit 1;; esac\n 43│  if [ \"$label\" = stale-no-token ]; then\n 44│    case \"$out\" in *\"0.2.0\"*\"TRACEABLE_REQS_TOKEN\"*) ;; *) printf 'FAIL mismatch/auth diagnostic: %s\\n' \"$out\"; exit 1;; esac\n   │...\n 51│  if [ \"$mode\" = install ] && [ \"$rc\" = 0 ]; then\n*52│    [ \"$(\"$root/checkout/traceable-reqs\" --version)\" = 'traceable-reqs 0.4.1' ]\n 53│  else\n 54│    [ ! -e \"$root/checkout/traceable-reqs\" ]\n 55│  fi\n   │...\n 60│run_case stale-no-token 'traceable-reqs 0.2.0' 0 '' precheck 1\n*61│run_case matching-no-token 'traceable-reqs 0.4.1' 0 '' precheck 0\n*62│run_case matching-install 'traceable-reqs 0.4.1' 0 '' install 0\n 63│run_case missing-no-token missing 0 '' install 1\n*64│run_case failed-version 'traceable-reqs 0.4.1' 7 '' precheck 1\n 65│run_case regex-lookalike 'traceable-reqs 0x4x1' 0 '' precheck 1\n 66│run_case repair-admitted 'traceable-reqs 0.2.0' 0 TOKEN_CANARY precheck 0\n 67│run_case clone-refusal 'traceable-reqs 0.2.0' 0 TOKEN_CANARY install 128\n### traceable-reqs.sh\n  4│set -euo pipefail\n *5│# 0.4.1 fixes file-root enumeration dropping present doc evidence (IR-109).\n *6│WANT=0.4.1\n  7│BIN=\"$HOME/.local/bin/traceable-reqs\"\n  8│mode=\"${1:-precheck}\"\n  9│case \"$mode\" in precheck|install) ;; *) echo 'usage: traceable-reqs.sh [precheck|install]' >&2; exit 2;; esac\n   │...\n 26│if ! probe; then\n*27│  echo '::warning title=Checker pin/runner disagreement::The runner does not supply the pinned checker; see CHECKER_PIN above. Coverage has not run.'\n 28│  if [ -z \"${GH_TOKEN:-}\" ]; then\n 29│    echo '::error title=Checker repair credential missing::TRACEABLE_REQS_TOKEN is absent. Install the pinned checker on the runner or have the operator provision read access to BigscreenVR/traceable-reqs. No clone or build attempted.'\n 30│    exit 1\n\n## crates/xtask/src/\n### main.rs\n 164│// [impl->REQ-DOCS-5]\n*165│fn cli_reference(bin: &Path) -> Result<String, String> {\n 166│    let mut out = String::from(\n 167│        \"# CLI reference\\n\\n\\\n 168│         > **Generated** from the `spt` binary's own `--help` output \\\n    │...\n 440│\n*441│fn gen(check: bool) {\n 442│    let root = repo_root();\n 443│    let bin = spt_bin(&root);\n 444│    if let Err(e) = gen_cli_reference(&root, &bin, check) {","linesTruncated":true,"meta":{"limits":{"columnTruncated":{"maxColumn":512}}}},"isError":false,"timestamp":1789483686580}}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_n114Y8eQBMQdh7uiQWB5dWhS|fc_043a862a419f59ae016aa95ab80e5887d282a40991be659f85","toolName":"read","startedAt":"2026-09-15T14:48:24.124Z","args":{"path":".worktrees/hertz-ir86-disk-delta/docs/INFRA-REGISTER.md:1586-1632,2009-2030,6330-6366,6510-6544:raw"},"intent":"Reading final unread register ranges"},"id":"8f9800ee","parentId":"5a7e70ef","timestamp":"2026-09-15T14:48:24.124Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_MNbrmgn7FJwMnrROyjmaOdfH|fc_043a862a419f59ae016aa95ab80e6487d285b0401f4feaaf3c","toolName":"read","startedAt":"2026-09-15T14:48:24.125Z","args":{"path":".worktrees/hertz-ir86-disk-delta/crates/xtask/src/main.rs:80-230,430-465:raw"},"intent":"Inspecting generation refusal seam"},"id":"964d3f74","parentId":"8f9800ee","timestamp":"2026-09-15T14:48:24.125Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_yiEi2wHDn7cFt9mE9Pl75rBh|fc_043a862a419f59ae016aa95ab80e6c87d2b2a60877e8ee0ebf","toolName":"read","startedAt":"2026-09-15T14:48:24.125Z","args":{"path":".worktrees/hertz-ir86-disk-delta/.github/ci/ci-notify.sh:170-270:raw"},"intent":"Inspecting attribution and scope implementation"},"id":"bb979dba","parentId":"964d3f74","timestamp":"2026-09-15T14:48:24.125Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_p4qDT4yqQbN9bOxbREdQnU2x|fc_043a862a419f59ae016aa95ab80e7487d2892812000648f9c7","toolName":"grep","startedAt":"2026-09-15T14:48:24.125Z","args":{"path":".worktrees/hertz-ir86-disk-delta/.github/ci/find-cwd-holders.ps1;.worktrees/hertz-ir86-disk-delta/crates/xtask/src;.worktrees/hertz-ir86-disk-delta/crates/spt-store/src/info.rs;.worktrees/hertz-ir86-d…"},"intent":"Locating candidate residual implementations"},"id":"7c76f759","parentId":"bb979dba","timestamp":"2026-09-15T14:48:24.125Z"}
{"type":"message","id":"c737afd6","parentId":"7c76f759","timestamp":"2026-09-15T14:48:24.125Z","message":{"role":"assistant","content":[{"type":"thinking","thinking":"**Reading missing sections**"},{"type":"toolCall","id":"call_n114Y8eQBMQdh7uiQWB5dWhS|fc_043a862a419f59ae016aa95ab80e5887d282a40991be659f85","name":"read","arguments":{"i":"Reading final unread register ranges","path":".worktrees/hertz-ir86-disk-delta/docs/INFRA-REGISTER.md:1586-1632,2009-2030,6330-6366,6510-6544:raw"},"intent":"Reading final unread register ranges"},{"type":"toolCall","id":"call_MNbrmgn7FJwMnrROyjmaOdfH|fc_043a862a419f59ae016aa95ab80e6487d285b0401f4feaaf3c","name":"read","arguments":{"i":"Inspecting generation refusal seam","path":".worktrees/hertz-ir86-disk-delta/crates/xtask/src/main.rs:80-230,430-465:raw"},"intent":"Inspecting generation refusal seam"},{"type":"toolCall","id":"call_yiEi2wHDn7cFt9mE9Pl75rBh|fc_043a862a419f59ae016aa95ab80e6c87d2b2a60877e8ee0ebf","name":"read","arguments":{"i":"Inspecting attribution and scope implementation","path":".worktrees/hertz-ir86-disk-delta/.github/ci/ci-notify.sh:170-270:raw"},"intent":"Inspecting attribution and scope implementation"},{"type":"toolCall","id":"call_p4qDT4yqQbN9bOxbREdQnU2x|fc_043a862a419f59ae016aa95ab80e7487d2892812000648f9c7","name":"grep","arguments":{"i":"Locating candidate residual implementations","pattern":"Headless|Format-Table|PSCustomObject|lock_perch_sentinel|never lose|duplicate.*bin|bin.*duplicate|fn pool_claim|fn git_lane_state|fn read_pid|unreadable-breadcrumb|cli_stack_smoke|stack_size","path":".worktrees/hertz-ir86-disk-delta/.github/ci/find-cwd-holders.ps1;.worktrees/hertz-ir86-disk-delta/crates/xtask/src;.worktrees/hertz-ir86-disk-delta/crates/spt-store/src/info.rs;.worktrees/hertz-ir86-disk-delta/crates/spt-poolguard/src/lib.rs;.worktrees/hertz-ir86-disk-delta/crates/spt/tests/common/reap.rs;.worktrees/hertz-ir86-disk-delta/crates/spt/src/main.rs","case":false,"gitignore":false,"skip":null},"intent":"Locating candidate residual implementations"},{"type":"toolCall","id":"call_5IdkOa96FMAGtQR6i6aiN3os|fc_043a862a419f59ae016aa95ab80e8087d2b40643004ee1476f","name":"grep","arguments":{"i":"Locating implemented driver obligations","pattern":"IR-(31|46|59|60)|FREE.AT|disk.floor|producer|returncode|summary|tests? run","path":".worktrees/hertz-ir86-disk-delta/.github/ci/local-lane.py;.worktrees/hertz-ir86-disk-delta/.github/ci","case":false,"gitignore":false,"skip":null},"intent":"Locating implemented driver obligations"}],"api":"openai-codex-responses","provider":"openai-codex","model":"gpt-6-astra","usage":{"input":28718,"output":512,"cacheRead":99072,"cacheWrite":0,"totalTokens":128302,"reasoningTokens":24,"cost":{"input":0.28718000000000005,"output":0.0256,"cacheRead":0.099072,"cacheWrite":0,"total":0.41185200000000005}},"stopReason":"toolUse","timestamp":1789483686614,"responseId":"resp_043a862a419f59ae016aa95aa6f53887d297132016d8ddd44e","providerPayload":{"type":"openaiResponsesHistory","provider":"openai-codex","dt":true,"items":[{"id":"rs_043a862a419f59ae016aa95aa8b55c87d28a6a94c5592cc8f5","type":"reasoning","content":[],"encrypted_content":"gAAAAABqqVq4U8qOyd1GM4hZMD2OYA3DHf6JtkIjtpSMIdIycAgsA2tAwp7Wkb6Jg5-L9zER4i5qqw4c7ABoNnn_lHwd1Zws9gTv-GkgZHPwmsIVtdTdgW9O-wOk9CP4Go58v_ZgDMhlVoRMJkeXoKsR31Mr3iw6FA4u629Cp6IUpCDnn2y0TilcwdHiewWOsk5ph6nZKu_xw4vQ-7XqWjzr2ANaFvVNvah9y4XWd16_SK-0lW8o9CdYHQba9DMOimavXjNZGAp0XJ1UrMiFirJLOovqUrzWe8eWUtYz4r-meYNfbJkJD93JwnlKR88-subJwzK2B1j482qUKpx3XAE9Vt0-gZHY-mi4N43UiXeLhYMTI-VloZuMgQ-dmFKyK4eMG57swFz0pvBYXljzzB0OozcM2YDj484WnEEDUSMllSVDOzA3KfHmPl-oatsV3SA84xAWTy2teIBZuZbC_kividEgX2EUtOBZNsgWNiKi5lcUuUhx_OP7vRnWv0JU11LuPqXgCOvFgoNMeAZTXb-r9E1yIiBi-LfB836IYKdEMY6oL7lmyh03FOXgqysh6VEbXJBv3MBJnHfZbeB_dePfU-a_LQh0FF7UJWv4RKloUCjvOLpzHO93c59y_qYLm9fxZpkSblD4xWp_v52dO29vTV6CC51q9KwpTNR97cQelMTXAUVcI8s00n2Y7lbb2PY-KRNGpKpZq7ditkopxoYhS8cwTci0XMHDQL_-jKDDPGoB3Zd6qFsJ-Co7buepsW124R6R_CYQYjn9YZzW_30S97bXvAFrE1d_VfASSJCy0zUJpGikP3fZIjdEmzSUw8llPoEoyhiMkOHdIr8uEwmioaMez0TwIntSv8Vo1_xr-BHa5lq9ehkeCk55OLz3mafoG-8urNi0IqD7Ba1c6UNXdk2u4Bc3Si_YTvpnOp0cx8pwkeKu_L44jUhKHkyWFFGbv3xu4-LDZCTgnW7oLqiTBIb2P2xyDNf-2N0QzYhyrCxfsUDOQrjaN-Xaj4K28xaFAbOuvg6hjx9bw0ne7LgMky0EpElM_-aMpAcKJSI4h2uAFYg5Hih_Ygt0GLE3Qxa67VQsYOqG40khyhkSVtQByzwyMDT9e-4Crmf-uT3WuFWkCZ4bKvF-QtvTuzPEJhwM3F2XmmyH4WoiQvZH_-jH2odnU2aJvF7eE3YyUn8J2jm2Y8fYBbMGWrtNpaN8vdT_ldet67_NflHbKw4GUW8KkPvWRSTI-9kCsx1wbh0DsQicyM6rGBxaqJmpsxPg4GDuU6IpcwJn7UT-Q5ufFFj6pqepQtTyDTnJH5AMbWcHnv-oOIUfvlOHVIsmpn8fHMfTMiSJFG2PQvMqcCaxfau4k-wp6CnPot5pcuLfLNiZG88VfjOKaDQ=","internal_chat_message_metadata_passthrough":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"},"summary":[{"type":"summary_text","text":"**Reading missing sections**"}],"metadata":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"}},{"id":"fc_043a862a419f59ae016aa95ab80e5887d282a40991be659f85","type":"function_call","status":"completed","arguments":"{\"i\":\"Reading final unread register ranges\",\"path\":\".worktrees/hertz-ir86-disk-delta/docs/INFRA-REGISTER.md:1586-1632,2009-2030,6330-6366,6510-6544:raw\"}","call_id":"call_n114Y8eQBMQdh7uiQWB5dWhS","internal_chat_message_metadata_passthrough":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"},"name":"read","metadata":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"}},{"id":"fc_043a862a419f59ae016aa95ab80e6487d285b0401f4feaaf3c","type":"function_call","status":"completed","arguments":"{\"i\":\"Inspecting generation refusal seam\",\"path\":\".worktrees/hertz-ir86-disk-delta/crates/xtask/src/main.rs:80-230,430-465:raw\"}","call_id":"call_MNbrmgn7FJwMnrROyjmaOdfH","internal_chat_message_metadata_passthrough":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"},"name":"read","metadata":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"}},{"id":"fc_043a862a419f59ae016aa95ab80e6c87d2b2a60877e8ee0ebf","type":"function_call","status":"completed","arguments":"{\"i\":\"Inspecting attribution and scope implementation\",\"path\":\".worktrees/hertz-ir86-disk-delta/.github/ci/ci-notify.sh:170-270:raw\"}","call_id":"call_yiEi2wHDn7cFt9mE9Pl75rBh","internal_chat_message_metadata_passthrough":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"},"name":"read","metadata":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"}},{"id":"fc_043a862a419f59ae016aa95ab80e7487d2892812000648f9c7","type":"function_call","status":"completed","arguments":"{\"i\":\"Locating candidate residual implementations\",\"pattern\":\"Headless|Format-Table|PSCustomObject|lock_perch_sentinel|never lose|duplicate.*bin|bin.*duplicate|fn pool_claim|fn git_lane_state|fn read_pid|unreadable-breadcrumb|cli_stack_smoke|stack_size\",\"path\":\".worktrees/hertz-ir86-disk-delta/.github/ci/find-cwd-holders.ps1;.worktrees/hertz-ir86-disk-delta/crates/xtask/src;.worktrees/hertz-ir86-disk-delta/crates/spt-store/src/info.rs;.worktrees/hertz-ir86-disk-delta/crates/spt-poolguard/src/lib.rs;.worktrees/hertz-ir86-disk-delta/crates/spt/tests/common/reap.rs;.worktrees/hertz-ir86-disk-delta/crates/spt/src/main.rs\",\"case\":false,\"gitignore\":false,\"skip\":null}","call_id":"call_p4qDT4yqQbN9bOxbREdQnU2x","internal_chat_message_metadata_passthrough":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"},"name":"grep","metadata":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"}},{"id":"fc_043a862a419f59ae016aa95ab80e8087d2b40643004ee1476f","type":"function_call","status":"completed","arguments":"{\"i\":\"Locating implemented driver obligations\",\"pattern\":\"IR-(31|46|59|60)|FREE.AT|disk.floor|producer|returncode|summary|tests? run\",\"path\":\".worktrees/hertz-ir86-disk-delta/.github/ci/local-lane.py;.worktrees/hertz-ir86-disk-delta/.github/ci\",\"case\":false,\"gitignore\":false,\"skip\":null}","call_id":"call_5IdkOa96FMAGtQR6i6aiN3os","internal_chat_message_metadata_passthrough":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"},"name":"grep","metadata":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"}}]},"duration":17508.314900010824,"ttft":2118.8650000095367,"completedAt":1789483704123,"contextSnapshot":{"promptTokens":127790,"nonMessageTokens":10342,"compactionEpoch":0}}}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_5IdkOa96FMAGtQR6i6aiN3os|fc_043a862a419f59ae016aa95ab80e8087d2b40643004ee1476f","toolName":"grep","startedAt":"2026-09-15T14:48:24.125Z","args":{"path":".worktrees/hertz-ir86-disk-delta/.github/ci/local-lane.py;.worktrees/hertz-ir86-disk-delta/.github/ci"},"intent":"Locating implemented driver obligations"},"id":"12e0e20e","parentId":"c737afd6","timestamp":"2026-09-15T14:48:24.125Z"}
{"type":"message","id":"683a9065","parentId":"12e0e20e","timestamp":"2026-09-15T14:48:24.131Z","message":{"role":"toolResult","toolCallId":"call_yiEi2wHDn7cFt9mE9Pl75rBh|fc_043a862a419f59ae016aa95ab80e6c87d2b2a60877e8ee0ebf","toolName":"read","content":[{"type":"text","text":"  echo \"ci-notify: daemon is up — sends deliver live where a recipient is listening\"\nelse\n  echo \"ci-notify: daemon is down — sends will spool and drain when the recipient listens\"\nfi\n\ncompute_verdict\n\n# --- body ------------------------------------------------------------------\n# Composed to a FILE, never passed inline: a body with quotes, newlines or a\n# stray `$` in a commit subject would otherwise be a shell-quoting trap.\nbody_file=\"$(mktemp)\"\ntrap 'rm -f \"$body_file\"' EXIT\ncompose_body >\"$body_file\"\n\necho \"ci-notify: supplied needs verdict $verdict${failing:+ (failing: $failing)}${cancelled:+ (cancelled: $cancelled)} — not a run conclusion\"\n\n# --- recipients ------------------------------------------------------------\n# doyle always (he gates and merges). Plus a best-effort trailer parse off the\n# head commit: this project's commits end `Co-authored by: <agent>` — note the\n# SPACE. That spelling is this repo's agent-name convention (CLAUDE.md), and it\n# is the only one matched on purpose: git's standard hyphenated\n# `Co-authored-by: Some Human <addr>` names a person or a tool, not a perch, so\n# matching it would mint junk recipients (a real commit on this branch's history\n# yields \"OpenAICodex\" that way). IR-47: absent or unparseable stays non-fatal,\n# but warns explicitly; it is not the same as a co-author who is already doyle.\nFROM_LABEL=\"CI-$(printf '%s' \"$RUNNER_NAME\" | tr '[:lower:]' '[:upper:]' | tr -cs '[:alnum:]' '-')\"\n\n# [impl->REQ-CI-NOTIFY-ATTRIBUTION]\nrecipients=\"doyle\"\ntrailer=\"$(git log -1 --pretty=%B |\n  sed -n 's/^Co-authored by:[[:space:]]*\\([^<]*\\).*$/\\1/Ip' |\n  tail -n 1 |\n  sed 's/[[:space:]]*$//; s/^[[:space:]]*//')\"\ntrailer_rc=$?\nif [ \"$trailer_rc\" -ne 0 ]; then\n  echo \"::warning title=CI notification attribution missing::Could not read or parse head commit (rc=$trailer_rc) for 'Co-authored by: <agent>' — notifying doyle only\"\nelif [ -z \"$trailer\" ]; then\n  echo \"::warning title=CI notification attribution missing::Head commit has no parseable line-anchored 'Co-authored by: <agent>' trailer — notifying doyle only\"\nelif [ \"$trailer\" = \"doyle\" ]; then\n  echo \"ci-notify: co-author is doyle — no second recipient\"\nelse\n  recipients=\"$recipients $trailer\"\nfi\n\n# --- send ------------------------------------------------------------------\n# DEFAULT window on purpose: this message SHOULD wake an idle recipient — being\n# told the supplied gates finished is the entire point. Never --active-only, never\n# --idle-only.\n#\n# QUEUED is SUCCESS: it means the recipient was not listening at that instant\n# (busy or offline), so the message spooled and drains next time they listen.\n# Only a hard CLI error is a miss, and even that is non-fatal here.\n# Per-recipient wall-clock bound. 30s is generous for the intended act (a local\n# broker hand-off, or a cross-node dial to a live peer) and small against the notify\n# job's 5-minute budget, so a wedged send can no longer approach it. The job's\n# `timeout-minutes` deliberately STAYS 5: raising it would hide this class instead of\n# bounding it.\nSEND_BOUND_SECS=30\n\n# Same-node hop: a send whose CLI runs on the RECIPIENTS' node is a local broker\n# hand-off — the cross-node relay leg that produced every NOTIFY_SEND_TIMEOUT so\n# far (5 sightings, one delivery in six) is simply not on the path. So when the\n# hop is reachable, run `spt send` THERE over ssh; the direct cross-node send\n# stays as the fallback, and both legs keep the same wall-clock bound. Empty\n# NOTIFY_SSH_HOP disables the hop entirely.\nNOTIFY_SSH_HOP=\"${NOTIFY_SSH_HOP-decid@hfenduleam}\"\n\nsend_to() {\n  # $1 = recipient. Echoes the winning leg's output; return code is the send's.\n  if [ -n \"$NOTIFY_SSH_HOP\" ] && command -v ssh >/dev/null 2>&1; then\n    hop_out=\"$(timeout \"$SEND_BOUND_SECS\" ssh -o BatchMode=yes -o ConnectTimeout=5 \\\n      -o StrictHostKeyChecking=accept-new \"$NOTIFY_SSH_HOP\" \\\n      \"spt send $1 --from $FROM_LABEL\" <\"$body_file\" 2>&1)\"\n    hop_rc=$?\n    if [ \"$hop_rc\" -eq 0 ]; then\n      printf '%s' \"$hop_out (via $NOTIFY_SSH_HOP)\"\n      return 0\n    fi\n    # Loud, then fall through: hop failure must be visible even when the\n    # fallback succeeds, or a rotted hop silently reverts us to the hang class.\n    echo \"ci-notify: HOP_FAILED rc=$hop_rc via $NOTIFY_SSH_HOP — falling back to direct send\" >&2\n  fi\n  timeout \"$SEND_BOUND_SECS\" spt send \"$1\" --from \"$FROM_LABEL\" <\"$body_file\" 2>&1\n}\n\nfor to in $recipients; do\n  out=\"$(send_to \"$to\")\"\n  rc=$?\n  case \"$rc\" in\n    0)\n      echo \"ci-notify: -> $to: ${out:-<no output>}\"\n      ;;\n    124)\n      # coreutils `timeout` exit code for \"killed on the deadline\". LOUD ON PURPOSE:\n      # this informant exists so that silence stops being ambiguous, so its OWN\n      # failure must never be silent — an operator reading the log has to be able to\n      # tell \"nobody was told\" from \"nothing happened\".\n      echo \"ci-notify: NOTIFY_SEND_TIMEOUT -> $to: no completion within ${SEND_BOUND_SECS}s — send ABANDONED, recipient NOT notified (CI unaffected)\"\n      ;;\n    *)\n      echo \"ci-notify: -> $to: SEND FAILED rc=$rc: ${out:-<no output>}\"\n\n[Showing lines 170-270 of 276. Use :271 to continue]"}],"details":{"truncation":{"content":"  echo \"ci-notify: daemon is up — sends deliver live where a recipient is listening\"\nelse\n  echo \"ci-notify: daemon is down — sends will spool and drain when the recipient listens\"\nfi\n\ncompute_verdict\n\n# --- body ------------------------------------------------------------------\n# Composed to a FILE, never passed inline: a body with quotes, newlines or a\n# stray `$` in a commit subject would otherwise be a shell-quoting trap.\nbody_file=\"$(mktemp)\"\ntrap 'rm -f \"$body_file\"' EXIT\ncompose_body >\"$body_file\"\n\necho \"ci-notify: supplied needs verdict $verdict${failing:+ (failing: $failing)}${cancelled:+ (cancelled: $cancelled)} — not a run conclusion\"\n\n# --- recipients ------------------------------------------------------------\n# doyle always (he gates and merges). Plus a best-effort trailer parse off the\n# head commit: this project's commits end `Co-authored by: <agent>` — note the\n# SPACE. That spelling is this repo's agent-name convention (CLAUDE.md), and it\n# is the only one matched on purpose: git's standard hyphenated\n# `Co-authored-by: Some Human <addr>` names a person or a tool, not a perch, so\n# matching it would mint junk recipients (a real commit on this branch's history\n# yields \"OpenAICodex\" that way). IR-47: absent or unparseable stays non-fatal,\n# but warns explicitly; it is not the same as a co-author who is already doyle.\nFROM_LABEL=\"CI-$(printf '%s' \"$RUNNER_NAME\" | tr '[:lower:]' '[:upper:]' | tr -cs '[:alnum:]' '-')\"\n\n# [impl->REQ-CI-NOTIFY-ATTRIBUTION]\nrecipients=\"doyle\"\ntrailer=\"$(git log -1 --pretty=%B |\n  sed -n 's/^Co-authored by:[[:space:]]*\\([^<]*\\).*$/\\1/Ip' |\n  tail -n 1 |\n  sed 's/[[:space:]]*$//; s/^[[:space:]]*//')\"\ntrailer_rc=$?\nif [ \"$trailer_rc\" -ne 0 ]; then\n  echo \"::warning title=CI notification attribution missing::Could not read or parse head commit (rc=$trailer_rc) for 'Co-authored by: <agent>' — notifying doyle only\"\nelif [ -z \"$trailer\" ]; then\n  echo \"::warning title=CI notification attribution missing::Head commit has no parseable line-anchored 'Co-authored by: <agent>' trailer — notifying doyle only\"\nelif [ \"$trailer\" = \"doyle\" ]; then\n  echo \"ci-notify: co-author is doyle — no second recipient\"\nelse\n  recipients=\"$recipients $trailer\"\nfi\n\n# --- send ------------------------------------------------------------------\n# DEFAULT window on purpose: this message SHOULD wake an idle recipient — being\n# told the supplied gates finished is the entire point. Never --active-only, never\n# --idle-only.\n#\n# QUEUED is SUCCESS: it means the recipient was not listening at that instant\n# (busy or offline), so the message spooled and drains next time they listen.\n# Only a hard CLI error is a miss, and even that is non-fatal here.\n# Per-recipient wall-clock bound. 30s is generous for the intended act (a local\n# broker hand-off, or a cross-node dial to a live peer) and small against the notify\n# job's 5-minute budget, so a wedged send can no longer approach it. The job's\n# `timeout-minutes` deliberately STAYS 5: raising it would hide this class instead of\n# bounding it.\nSEND_BOUND_SECS=30\n\n# Same-node hop: a send whose CLI runs on the RECIPIENTS' node is a local broker\n# hand-off — the cross-node relay leg that produced every NOTIFY_SEND_TIMEOUT so\n# far (5 sightings, one delivery in six) is simply not on the path. So when the\n# hop is reachable, run `spt send` THERE over ssh; the direct cross-node send\n# stays as the fallback, and both legs keep the same wall-clock bound. Empty\n# NOTIFY_SSH_HOP disables the hop entirely.\nNOTIFY_SSH_HOP=\"${NOTIFY_SSH_HOP-decid@hfenduleam}\"\n\nsend_to() {\n  # $1 = recipient. Echoes the winning leg's output; return code is the send's.\n  if [ -n \"$NOTIFY_SSH_HOP\" ] && command -v ssh >/dev/null 2>&1; then\n    hop_out=\"$(timeout \"$SEND_BOUND_SECS\" ssh -o BatchMode=yes -o ConnectTimeout=5 \\\n      -o StrictHostKeyChecking=accept-new \"$NOTIFY_SSH_HOP\" \\\n      \"spt send $1 --from $FROM_LABEL\" <\"$body_file\" 2>&1)\"\n    hop_rc=$?\n    if [ \"$hop_rc\" -eq 0 ]; then\n      printf '%s' \"$hop_out (via $NOTIFY_SSH_HOP)\"\n      return 0\n    fi\n    # Loud, then fall through: hop failure must be visible even when the\n    # fallback succeeds, or a rotted hop silently reverts us to the hang class.\n    echo \"ci-notify: HOP_FAILED rc=$hop_rc via $NOTIFY_SSH_HOP — falling back to direct send\" >&2\n  fi\n  timeout \"$SEND_BOUND_SECS\" spt send \"$1\" --from \"$FROM_LABEL\" <\"$body_file\" 2>&1\n}\n\nfor to in $recipients; do\n  out=\"$(send_to \"$to\")\"\n  rc=$?\n  case \"$rc\" in\n    0)\n      echo \"ci-notify: -> $to: ${out:-<no output>}\"\n      ;;\n    124)\n      # coreutils `timeout` exit code for \"killed on the deadline\". LOUD ON PURPOSE:\n      # this informant exists so that silence stops being ambiguous, so its OWN\n      # failure must never be silent — an operator reading the log has to be able to\n      # tell \"nobody was told\" from \"nothing happened\".\n      echo \"ci-notify: NOTIFY_SEND_TIMEOUT -> $to: no completion within ${SEND_BOUND_SECS}s — send ABANDONED, recipient NOT notified (CI unaffected)\"\n      ;;\n    *)\n      echo \"ci-notify: -> $to: SEND FAILED rc=$rc: ${out:-<no output>}\"","truncated":true,"truncatedBy":"lines","totalLines":107,"totalBytes":5110,"outputLines":101,"outputBytes":5110,"lastLinePartial":false,"firstLineExceedsLimit":false},"totalLines":276,"displayContent":{"text":"  echo \"ci-notify: daemon is up — sends deliver live where a recipient is listening\"\nelse\n  echo \"ci-notify: daemon is down — sends will spool and drain when the recipient listens\"\nfi\n\ncompute_verdict\n\n# --- body ------------------------------------------------------------------\n# Composed to a FILE, never passed inline: a body with quotes, newlines or a\n# stray `$` in a commit subject would otherwise be a shell-quoting trap.\nbody_file=\"$(mktemp)\"\ntrap 'rm -f \"$body_file\"' EXIT\ncompose_body >\"$body_file\"\n\necho \"ci-notify: supplied needs verdict $verdict${failing:+ (failing: $failing)}${cancelled:+ (cancelled: $cancelled)} — not a run conclusion\"\n\n# --- recipients ------------------------------------------------------------\n# doyle always (he gates and merges). Plus a best-effort trailer parse off the\n# head commit: this project's commits end `Co-authored by: <agent>` — note the\n# SPACE. That spelling is this repo's agent-name convention (CLAUDE.md), and it\n# is the only one matched on purpose: git's standard hyphenated\n# `Co-authored-by: Some Human <addr>` names a person or a tool, not a perch, so\n# matching it would mint junk recipients (a real commit on this branch's history\n# yields \"OpenAICodex\" that way). IR-47: absent or unparseable stays non-fatal,\n# but warns explicitly; it is not the same as a co-author who is already doyle.\nFROM_LABEL=\"CI-$(printf '%s' \"$RUNNER_NAME\" | tr '[:lower:]' '[:upper:]' | tr -cs '[:alnum:]' '-')\"\n\n# [impl->REQ-CI-NOTIFY-ATTRIBUTION]\nrecipients=\"doyle\"\ntrailer=\"$(git log -1 --pretty=%B |\n  sed -n 's/^Co-authored by:[[:space:]]*\\([^<]*\\).*$/\\1/Ip' |\n  tail -n 1 |\n  sed 's/[[:space:]]*$//; s/^[[:space:]]*//')\"\ntrailer_rc=$?\nif [ \"$trailer_rc\" -ne 0 ]; then\n  echo \"::warning title=CI notification attribution missing::Could not read or parse head commit (rc=$trailer_rc) for 'Co-authored by: <agent>' — notifying doyle only\"\nelif [ -z \"$trailer\" ]; then\n  echo \"::warning title=CI notification attribution missing::Head commit has no parseable line-anchored 'Co-authored by: <agent>' trailer — notifying doyle only\"\nelif [ \"$trailer\" = \"doyle\" ]; then\n  echo \"ci-notify: co-author is doyle — no second recipient\"\nelse\n  recipients=\"$recipients $trailer\"\nfi\n\n# --- send ------------------------------------------------------------------\n# DEFAULT window on purpose: this message SHOULD wake an idle recipient — being\n# told the supplied gates finished is the entire point. Never --active-only, never\n# --idle-only.\n#\n# QUEUED is SUCCESS: it means the recipient was not listening at that instant\n# (busy or offline), so the message spooled and drains next time they listen.\n# Only a hard CLI error is a miss, and even that is non-fatal here.\n# Per-recipient wall-clock bound. 30s is generous for the intended act (a local\n# broker hand-off, or a cross-node dial to a live peer) and small against the notify\n# job's 5-minute budget, so a wedged send can no longer approach it. The job's\n# `timeout-minutes` deliberately STAYS 5: raising it would hide this class instead of\n# bounding it.\nSEND_BOUND_SECS=30\n\n# Same-node hop: a send whose CLI runs on the RECIPIENTS' node is a local broker\n# hand-off — the cross-node relay leg that produced every NOTIFY_SEND_TIMEOUT so\n# far (5 sightings, one delivery in six) is simply not on the path. So when the\n# hop is reachable, run `spt send` THERE over ssh; the direct cross-node send\n# stays as the fallback, and both legs keep the same wall-clock bound. Empty\n# NOTIFY_SSH_HOP disables the hop entirely.\nNOTIFY_SSH_HOP=\"${NOTIFY_SSH_HOP-decid@hfenduleam}\"\n\nsend_to() {\n  # $1 = recipient. Echoes the winning leg's output; return code is the send's.\n  if [ -n \"$NOTIFY_SSH_HOP\" ] && command -v ssh >/dev/null 2>&1; then\n    hop_out=\"$(timeout \"$SEND_BOUND_SECS\" ssh -o BatchMode=yes -o ConnectTimeout=5 \\\n      -o StrictHostKeyChecking=accept-new \"$NOTIFY_SSH_HOP\" \\\n      \"spt send $1 --from $FROM_LABEL\" <\"$body_file\" 2>&1)\"\n    hop_rc=$?\n    if [ \"$hop_rc\" -eq 0 ]; then\n      printf '%s' \"$hop_out (via $NOTIFY_SSH_HOP)\"\n      return 0\n    fi\n    # Loud, then fall through: hop failure must be visible even when the\n    # fallback succeeds, or a rotted hop silently reverts us to the hang class.\n    echo \"ci-notify: HOP_FAILED rc=$hop_rc via $NOTIFY_SSH_HOP — falling back to direct send\" >&2\n  fi\n  timeout \"$SEND_BOUND_SECS\" spt send \"$1\" --from \"$FROM_LABEL\" <\"$body_file\" 2>&1\n}\n\nfor to in $recipients; do\n  out=\"$(send_to \"$to\")\"\n  rc=$?\n  case \"$rc\" in\n    0)\n      echo \"ci-notify: -> $to: ${out:-<no output>}\"\n      ;;\n    124)\n      # coreutils `timeout` exit code for \"killed on the deadline\". LOUD ON PURPOSE:\n      # this informant exists so that silence stops being ambiguous, so its OWN\n      # failure must never be silent — an operator reading the log has to be able to\n      # tell \"nobody was told\" from \"nothing happened\".\n      echo \"ci-notify: NOTIFY_SEND_TIMEOUT -> $to: no completion within ${SEND_BOUND_SECS}s — send ABANDONED, recipient NOT notified (CI unaffected)\"\n      ;;\n    *)\n      echo \"ci-notify: -> $to: SEND FAILED rc=$rc: ${out:-<no output>}\"","startLine":170,"lineNumbers":[170,171,172,173,174,175,176,177,178,179,180,181,182,183,184,185,186,187,188,189,190,191,192,193,194,195,196,197,198,199,200,201,202,203,204,205,206,207,208,209,210,211,212,213,214,215,216,217,218,219,220,221,222,223,224,225,226,227,228,229,230,231,232,233,234,235,236,237,238,239,240,241,242,243,244,245,246,247,248,249,250,251,252,253,254,255,256,257,258,259,260,261,262,263,264,265,266,267,268,269,270]},"fileSize":13352,"meta":{"source":{"type":"path","value":"C:\\Users\\decid\\Documents\\projects\\spt-core\\.worktrees\\hertz-ir86-disk-delta\\.github\\ci\\ci-notify.sh"},"truncation":{"direction":"head","truncatedBy":"lines","totalLines":276,"totalBytes":5110,"outputLines":101,"outputBytes":5110,"shownRange":{"start":170,"end":270},"nextOffset":271}}},"isError":false,"timestamp":1789483704130}}
{"type":"message","id":"e8f616c1","parentId":"683a9065","timestamp":"2026-09-15T14:48:24.133Z","message":{"role":"toolResult","toolCallId":"call_MNbrmgn7FJwMnrROyjmaOdfH|fc_043a862a419f59ae016aa95ab80e6487d285b0401f4feaaf3c","toolName":"read","content":[{"type":"text","text":"        \"debug-keygen\" => debug_keygen(&args[1..]),\n        \"debug-pin\" => debug_pin(&args[1..]),\n        \"debug-rollout\" => debug_rollout(&args[1..]),\n        \"debug-mark-applied\" => debug_mark_applied(&args[1..]),\n        \"debug-converge\" => debug_converge(&args[1..]),\n        _ => {\n            eprintln!(\n                \"usage: xtask <gen|check|brain-read-check|binedge-check [--no-prebuilds] [--baseline|--write-baseline] [--sites]|perjob-map|pick-audit --range <base>..<head> --lane <base>..<tip> [--lane <base>..<tip>] [--pair <lane-rev>:<pick-rev>] [--repo <dir>]|disk-floor [--path <dir>] [--floor-gb <n>] [--label <lane>]|docs-bundle <out.tar.gz>|bench-wrap --step <name> [--key <k>] -- <cmd...>|bench-report [--top <n>] [--window-hours <h>]|pool-claim --pool <dir> --label <lane> [--holder-pid <pid>] [--foreign-pool]|pool-sweep [--root <dir>] [--reap] [--include-owned]|pool-release --pool <dir>|release-keygen <key-id>|release-sign …|release-publish …|debug-keygen <key-id>|debug-pin …|debug-rollout …|debug-mark-applied --version <u64> [--home <dir>]|debug-converge --version <u64> …>\"\n            );\n            std::process::exit(2);\n        }\n    }\n}\n\n// ---------------------------------------------------------------- CLI ref\n\n/// Run the workspace `spt` binary with `args` + `--help`, normalized to the\n/// `spt` name (Windows prints `spt.exe`, which would make the generated\n/// reference platform-dependent).\n// [impl->REQ-DOCS-5]\nfn help_for(bin: &Path, args: &[&str]) -> Result<String, String> {\n    let mut cmd = Command::new(bin);\n    cmd.args(args).arg(\"--help\");\n    let out = cmd\n        .output()\n        .map_err(|e| format!(\"xtask: run {cmd:?}: {e}\"))?;\n    if !out.status.success() {\n        return Err(format!(\n            \"xtask: {cmd:?} failed ({}); stderr:\\n{}\",\n            out.status,\n            String::from_utf8_lossy(&out.stderr)\n        ));\n    }\n    let text = String::from_utf8_lossy(&out.stdout);\n    if text.trim().is_empty() {\n        return Err(format!(\n            \"xtask: {cmd:?} produced empty help ({}); stderr:\\n{}\",\n            out.status,\n            String::from_utf8_lossy(&out.stderr)\n        ));\n    }\n    Ok(text.replace(\"spt.exe\", \"spt\").replace(\"\\r\\n\", \"\\n\"))\n}\n\n/// Parse the command-list block(s) of a clap help text into subcommand\n/// names. Nested helps carry clap's flat `Commands:` heading; the root help\n/// renders two grouped blocks (`User commands:` / `Agent commands:`).\nfn subcommands(help: &str) -> Vec<String> {\n    let mut cmds = Vec::new();\n    let mut in_block = false;\n    for line in help.lines() {\n        let heading = line.trim_end();\n        if heading == \"Commands:\" || heading == \"User commands:\" || heading == \"Agent commands:\" {\n            in_block = true;\n            continue;\n        }\n        if in_block {\n            // A blank line ends the current block (another may follow);\n            // `Options:` ends the command listing for good.\n            if line.trim().is_empty() {\n                in_block = false;\n                continue;\n            }\n            if line.starts_with(\"Options:\") {\n                break;\n            }\n            // Entries are `  <name>  <doc…>`; continuation lines are deeper-indented.\n            if let Some(rest) = line.strip_prefix(\"  \") {\n                if !rest.starts_with(' ') {\n                    if let Some(name) = rest.split_whitespace().next() {\n                        if name != \"help\" {\n                            cmds.push(name.to_string());\n                        }\n                    }\n                }\n            }\n        }\n    }\n    cmds\n}\n\n/// The generated CLI reference: every command + nested subcommand's help,\n/// verbatim. Help text is a first-class doc surface (DOCS-STRATEGY), so the\n/// reference IS the binary's own words — it cannot drift (REQ-DOCS-5).\n// [impl->REQ-DOCS-5]\nfn cli_reference(bin: &Path) -> Result<String, String> {\n    let mut out = String::from(\n        \"# CLI reference\\n\\n\\\n         > **Generated** from the `spt` binary's own `--help` output \\\n         (`cargo run -p xtask -- gen`) and drift-gated in CI — this page \\\n         cannot disagree with the binary. Do not edit by hand.\\n\\n\",\n    );\n    let root_help = help_for(bin, &[])?;\n    out.push_str(\"## spt\\n\\n```text\\n\");\n    out.push_str(&root_help);\n    out.push_str(\"```\\n\");\n    for cmd in subcommands(&root_help) {\n        push_command_tree(bin, &mut out, &[cmd])?;\n    }\n    Ok(out)\n}\n\n/// The argv that renders help for one command path — with the `api`\n/// stand-in adapter injected where the path passes through `spt api` (clap\n/// requires `--adapter` even for subcommand help). ONE spelling for every\n/// depth: before the recursion this hardcode existed once per hand-written\n/// loop level, and a third level would have needed a third copy (IR-52).\nfn help_args(path: &[String]) -> Vec<String> {\n    let mut args: Vec<String> = Vec::new();\n    for (i, seg) in path.iter().enumerate() {\n        args.push(seg.clone());\n        if i == 0 && seg == \"api\" {\n            args.push(\"--adapter\".into());\n            args.push(\"x\".into());\n        }\n    }\n    args\n}\n\n/// Emit `path`'s help at its depth-derived heading, then recurse into every\n/// subcommand the help lists — the FULL command tree (IR-52's durable\n/// remedy, SIGNET W1): any help below a fixed rendering depth was invisible\n/// to the docs-drift gate, so a deep help edit or regression shipped\n/// unpublished and ungated unless some REQ's unit happened to pin it. With\n/// the recursion, published depth == tree depth by construction, and the\n/// committed reference's deepest sections make a depth regression a drift\n/// red.\n// [impl->REQ-DOCS-5]\nfn push_command_tree(bin: &Path, out: &mut String, path: &[String]) -> Result<(), String> {\n    let args = help_args(path);\n    let argv: Vec<&str> = args.iter().map(String::as_str).collect();\n    let help = help_for(bin, &argv)?;\n    let hashes = \"#\".repeat(path.len() + 1);\n    out.push_str(&format!(\n        \"\\n{hashes} spt {}\\n\\n```text\\n{help}```\\n\",\n        path.join(\" \")\n    ));\n    for sub in subcommands(&help) {\n        let mut child = path.to_vec();\n        child.push(sub);\n        push_command_tree(bin, out, &child)?;\n    }\n    Ok(())\n}\n\n#[cfg(test)]\nmod cli_reference_tests {\n    use super::{gen_cli_reference, help_args};\n    use std::path::{Path, PathBuf};\n\n    fn path(segs: &[&str]) -> Vec<String> {\n\n…\n\n        .current_dir(root)\n        .status()\n        .expect(\"cargo build spt\");\n    assert!(status.success(), \"building spt failed\");\n    let name = if cfg!(windows) { \"spt.exe\" } else { \"spt\" };\n    // cargo honors CARGO_TARGET_DIR when building; the returned path must too,\n    // or an isolated-target rig looks in the wrong place. [impl->REQ-XTASK-SPT-BIN-TARGET-DIR]\n    let target_dir = std::env::var(\"CARGO_TARGET_DIR\").ok();\n    target_debug_dir(root, target_dir.as_deref()).join(name)\n}\n\nfn gen(check: bool) {\n    let root = repo_root();\n    let bin = spt_bin(&root);\n    if let Err(e) = gen_cli_reference(&root, &bin, check) {\n        eprintln!(\"{e}\");\n        std::process::exit(1);\n    }\n    // [impl->REQ-DOCS-CHANGELOG-PAGE] the changelog half is a returning seam\n    // (below); this edge is where its Err becomes the operator's exit code.\n    if let Err(e) = gen_changelog(&root, check) {\n        eprintln!(\"{e}\");\n        std::process::exit(1);\n    }\n}\n\n/// Write the generated changelog page from `<root>/CHANGELOG.md`, or diff it\n/// and REPORT drift when `check`.\n///\n/// Root-parameterised and returning: a seam that reads `repo_root()` and\n/// exits on drift can only be witnessed by an operator running the command,\n/// so the drift half would ship untested by construction.\n/// The exit lives at the CLI edge in [`gen`] instead, leaving what an operator\n/// sees unchanged.\n// [impl->REQ-DOCS-CHANGELOG-PAGE]\nfn gen_changelog(root: &Path, check: bool) -> Result<(), String> {"}],"details":{"fileSize":163022,"meta":{"source":{"type":"path","value":"C:\\Users\\decid\\Documents\\projects\\spt-core\\.worktrees\\hertz-ir86-disk-delta\\crates\\xtask\\src\\main.rs"}}},"isError":false,"timestamp":1789483704133}}
{"type":"message","id":"a6a0012d","parentId":"e8f616c1","timestamp":"2026-09-15T14:48:24.138Z","message":{"role":"toolResult","toolCallId":"call_n114Y8eQBMQdh7uiQWB5dWhS|fc_043a862a419f59ae016aa95ab80e5887d282a40991be659f85","toolName":"read","content":[{"type":"text","text":"### IR-25 — `spt-daemon --lib` reds 2-in-3 under concurrent load with bare `cargo test`, and holds green under nextest\n- **Status:** open · **Origin:** doyle 2026-08-03, found while gating LOCKSMITH tranche 1 in an\n  isolated worktree; chased to a mechanism and scoped OUT of the release path before the head was\n  assembled.\n- **MEASURED, four arms, same box, same hour, matched load** (a second `cargo test -p spt-store\n  --lib` loop running throughout; `spt-store` itself stayed green in every round, so the box was not\n  generically failing):\n\n  | tree | instrument | result |\n  |---|---|---|\n  | lane `ec5f38a` | `cargo test --lib`, at rest | 821/821 ×4 |\n  | lane `ec5f38a` | `cargo test --lib`, under load | **2 of 3 RED** (142s, 117s) |\n  | lane `ec5f38a` minus its 5 new tests | `cargo test --lib`, under load | 3 of 3 green (117s, 84s, 105s) |\n  | main `932e14b` | `cargo test --lib`, under load | 3 of 3 green (97s, 119s, 104s) |\n  | lane `ec5f38a` | **`cargo nextest run`, under load** | **3 of 3 green, 821/821** (88s, 85s, 72s) |\n\n- **Three DIFFERENT victims across two loaded runs**, all process/timing-shaped, all PRESENT AT MAIN\n  and green there: `servicehost::…a_service_that_ignores_the_stop_marker_is_force_killed_and_confirmed_dead`\n  (panics `ForceKilled must MEAN the owned child is gone` right after `SERVICE_KILL_UNCONFIRMED`),\n  `applyhost::…broker_reports_its_compiled_image_version_over_ipc`, and\n  `daemon::…a_tree_teardown_reaches_a_grandchild_the_service_spawned`.\n- **MECHANISM: in-process thread interference, not product code.** Bare `cargo test` runs a crate's\n  tests as threads in ONE process. The lane's five new tests are process-spawning kill-tree tests;\n  under load they starve confirm windows of NEIGHBOURING tests that were always marginal. Removing\n  exactly those five flips 2-of-3-red to 0-of-3-green at the same sha, in the same binary, at the\n  same durations — one of the green runs sits at 117s, precisely a duration that had produced two\n  failures with them present.\n- **IT DOES NOT REACH GOLDEN.** nextest gives every test its own process, and golden runs nextest.\n  The population is GATE RIGS AND LOCAL RUNS — the same population as [[IR-21]], reached by a\n  different mechanism, which is why these are two entries and not one.\n- ⚠ **The instrument switch is the whole finding.** Measured with bare `cargo test`, this reads as a\n  lane blocker; measured with the tool CI actually runs, it is a rig-scoped nuisance. Anyone\n  re-opening this must state WHICH instrument produced their observation before quoting a verdict.\n  The same tool gap acquitted [[IR-21]]'s golden question the same day.\n- ⚠ **The pre-existing fragility is NOT thereby closed.** Those three tests were marginal before this\n  lane and the lane only exposed them; \"make the new tests quieter\" would re-hide a real weakness.\n  Hardening them is test-side work (hertz's lane by the dispatch split), not the builder's.\n- **Two rig defects of the gater's, recorded because they nearly cost the verdict:** (1) a first\n  re-run at rest came back 4/4 green and proves NOTHING — a sequential idle probe cannot express a\n  load-sensitive failure, so that is a competence-controlled zero, not an acquittal; (2) the first\n  baseline attempt ran its two arms UNSYNCHRONISED (the load generator finished while the measured\n  arm was still on run 1), which would have compared a loaded lane against an idle main and read as\n  \"the lane broke it\". A discriminator whose arms ran under different conditions cannot discriminate.\n- **Ripe when:** alongside [[IR-21]] on the next gate-rig or CI-touching wave, or immediately if\n  anyone starts gating on bare `cargo test` on a loaded box. **Size:** small to document the rig\n  rule (gate with nextest); medium to harden the three marginal tests.\n\n\n…\n\n  **Standing lesson for the family:** an environmental slowdown is an accidental mitigation —\n  REMEDIATING a box can EXPOSE latent knife-edge races (the storm had hidden this one for\n  releases). And a \"random victim family\" should be tested against ONE window with\n  load-dependent width before positing per-victim mechanisms. The Windows face above remains\n  open on its own instruments; the two faces now have one shared candidate SHAPE (a race window\n  amplified by box load) with different windows.\n- **Status:** open · **Origin:** measured box event, HFENDULEAM 2026-08-04 ~05:00 local, during\n  USHER lane concurrency (hertz mechanism statement + both agents' reclaim arithmetic).\n- **What/why:** the box hit **0.00 bytes free** mid-build. Failure signatures it manufactured\n  look like toolchain or code defects, not disk: `rustc-LLVM ERROR: IO failure on output stream:\n  no space on device`, `LNK1318: Unexpected PDB error; LIMIT (12)`, `LNK1108: cannot write file`\n  — a red wearing a linker's face (doyle's U2 gate rig ate exactly this; verdict legs already\n  green survived, the suite leg had to be re-run). Contributions measured, not inferred: hertz\n  ~70 GB across four lane targets (er-seams **42.66 GB** cold `--workspace --tests`,\n  selection-probe 25.80, poolowner 1.03, ci-riders 0.91), doyle gate rig 15 GB cold full build.\n  Reclaim arithmetic reconciles both and neither alone: 0.00 → 25.47 GB (hertz reaps\n  selection-probe) → ~40 GB (doyle reaps rig). **The mechanism (hertz, ruled register-worthy):\n  every isolated lane worktree carries its OWN `target/`, so disk cost is multiplied by lane\n  count, while pool-claim — built to arbitrate a SHARED pool — sees none of it; a claim on\n  main's pool is ceremonial for a lane that never writes there. The tool we use to reason about\n  build-cache contention cannot see the resource that actually ran out.** Eight-plus worktrees\n  at 25–43 GB per cold full build is the shape of the next occurrence, and it will not announce\n\n…\n\n  is why the form survived: it was correct for every case until one cell reused a target. Limits\n  named: that crate's tests only (the `initiated_locally` grep population); a read, not a run.\n  Repair took the shape one file over (tests/controller_lease.rs:170 `wait_for_new_stream`).\n- **Kin:** [[IR-99]], [[IR-101]], [[IR-102]], memory \"journaled seq reuse replays the retired\n  stream\", \"stacked defects mask each other\", \"discriminator question\".\n- **Ripe when:** now — the #230 rig repair, and every cell whose arms share one broker/conn.\n  · **Size:** one served-set parameter in one helper; one register line.\n\n### IR-104 — checker 0.4.0 silently skips a FILE scan root under git enumeration: 81 doc stages read as missing, and a local 0.2.0 green hid it because the two versions disagree on what is evidence\n\n- **Status:** FIXED UPSTREAM 2026-09-11 (traceable-reqs v0.4.1, PR #21 -> d9af11d, red-first cells);\n  spt-core consumes via hertz's #304 lane pin fixup. Closes when that pin is on main.\n- **Instance:** `traceable-reqs.toml` has declared `CONTEXT.md` a scan root since the seed (a FILE\n  root: the glossary carries doc-stage tags). 0.2.0 honoured it. 0.4.0 (SPEC §Scan enumeration:\n  \"an allowlist of directories\") filtered git candidates with `rel_under_root`, which required a `/`\n  after the root prefix; a candidate equal to the root had an empty remainder and never qualified.\n  Measured: 0.4.0 on main = 81 `missing_stage … stage=doc`, every one with its doc tag in\n  CONTEXT.md and 71 nowhere else; positive control: 0 of 253 doc tags under `docs/` were affected.\n  The walk strategy (`git = \"off\"`) never had the bug.\n- **Why it hid:** the box's CLI was 0.2.0 while CI's pin moved to 0.4.0 in the lane, so every local\n  `check` today validated against a different evidence rule than the gate it stood in for. hertz\n  found the placement half of that silence first (0.2.0 emits nothing for a `[placement]` table it\n  cannot read); the doc half surfaced only when the gater built 0.4.0 and ran it. A green from a\n  checker that does not match CI's version is a measurement of the wrong tool.\n- **Rejected remedies, measured:** `roots = [\".\"]` recovers the 81 and admits 43 root-level plan\n  documents with code-stage tags in prose (148 misplaced), then 12 with malformed tag-shaped tokens\n  and AGENTS.md's own example tag; an exclude list of 55 historic files is the wrong shape.\n  `scan.exclude` cannot express \"every root file except one\" (no negation).\n- **Rules:** (1) before citing any `traceable-reqs check`, print `--version` and compare it to\n  the CI pin in the tree being judged; a mismatch is a labelled hole, not a green. (2) A checker\n  upgrade is a gate change: run old and new on the SAME tree and account for every finding that\n  appears or disappears before the pin moves. (3) The assembly gate runs the pinned version; the\n  binary is built from the tag (`traceable-reqs-<ver>.exe`), never \"whatever is on PATH\".\n- **Kin:** [[IR-37]] (placement enforcement, the same release), [[IR-102]] (a declared thing still\n  unread), memory rules \"a predicate needs its tool\", \"zero-match filter reads as absent\".\n- **Ripe when:** now — the #304 assembly. · **Size:** one pin fixup; one line in the gate runbook.\n\n\n…\n\n  assertions named this exact fault; `spt-store::project::tests::derivation_ladder`\n  also derived the enclosing repository rather than its fixture folder. **That\n  attempt is VOID, not a candidate regression.** The temp-root Git probe returned\n  the enclosing checkout (exit 0); the replacement `/tmp/spt-consumer-304-b8482445-valid-*`\n  root and every exported temp path returned \"not a git repository\" (exit 128).\n  The replacement driver enforces that boundary before launching any producer.\n  On unchanged candidate bytes, valid Phase A then ran 3417/3417 passed (1 leaky),\n  1 skipped, exit 0; no main delta or source edit was needed. Original raw,\n  `temp-premise-correction.json`, and the valid `attempt2/` receipts remain under\n  `.spt/preserved/304-handoff/consumer-linux/`. This repeats the existing rule;\n  preserving evidence inside the repository never licenses putting fixtures there.\n\n- **Live-agent identity environment recurrence — Windows consumer (2026-09-13, #304).**\n  Doyle reported in `5E3WTZ3N` that his live session's `OWL_SESSION_ID` reached the\n  test driver: Windows consumer attempt 1 is **VOID, not a candidate regression**.\n  Recorded by hertz from that report, not from an independent rerun. The current\n  phase was to drain before a full scrubbed rerun; no corrected Windows result or\n  BOX CLEAR is claimed here. A.2 remains held and the preparation clock unstarted.\n  **Same mechanism, different input:** TMP placement changes a fixture's repository\n  context; inherited session identity changes its caller context. In both cases\n  the harness environment is part of the subject, not neutral launch plumbing.\n  A clean checkout and pinned executable do not establish the intended test premise.\n  **Rule:** construct the producer's child environment from its declared test/CI\n  contract, removing inherited live-session identity inputs as a set before launch.\n  Verify the effective environment handed to the actual test producer after all\n  wrapper/sandbox setup; record names and presence/absence, never identity values.\n  Fixtures that test identity must supply their own explicit fixture identity.\n  Keep the live agent's own environment and lifecycle intact; this is test-driver\n  isolation, not permission to evade a guard on real operational commands.\n  Preserve the invalid attempt's logs and verdict separately from the corrected\n  run; an environment-premise failure does not authorize a product patch.\n  **Kin:** [[IR-22]] records the earlier identity-inheritance failure and its\n  one-variable-at-a-time diagnostic trap; [[IR-122]] distinguishes a real rig's\n  intentional live-session refusal from an isolated test's contaminated premise.\n"}],"details":{"fileSize":676479,"meta":{"source":{"type":"path","value":"C:\\Users\\decid\\Documents\\projects\\spt-core\\.worktrees\\hertz-ir86-disk-delta\\docs\\INFRA-REGISTER.md"}}},"isError":false,"timestamp":1789483704137}}
{"type":"message","id":"470ef22c","parentId":"a6a0012d","timestamp":"2026-09-15T14:48:24.159Z","message":{"role":"toolResult","toolCallId":"call_5IdkOa96FMAGtQR6i6aiN3os|fc_043a862a419f59ae016aa95ab80e8087d2b40643004ee1476f","toolName":"grep","content":[{"type":"text","text":"# .worktrees/hertz-ir86-disk-delta/.github/ci/\n## local-lane.py\n 10|Requires the gater's --hold-released acknowledgement. Reuses ws272-w0's quiet\n*11|meter, lane lock, identity scrub and disk-floor meter. Volume movement is aggregate\n 12|capacity evidence, NOT attribution to this lane. Census has the existing reaper's\n 13|explicit scope; an unavailable/incomplete census is never clearance.\n 14|\"\"\"\n...\n 63|def selected_inventory(inventory):\n*64|    \"\"\"Interpret nextest-metadata's TestListSummary, retaining only matching tests.\"\"\"\n 65|    suites = inventory.get(\"rust-suites\") if isinstance(inventory, dict) else None\n 66|    if not isinstance(suites, dict):\n 67|        raise ValueError(\"nextest inventory has no suite map\")\n...\n 100|    try:\n*101|        disk_ok = meter(name + \"-after-producer\")\n 102|    except OSError as error:\n 103|        print(f\"DISK_OBSERVATION_UNPROVEN: {error}\", file=sys.stderr)\n 104|    try:\n...\n 130|        result = subprocess.run(argv, cwd=root, env=env, capture_output=True, text=True, timeout=60)\n*131|        raw, code = result.stdout + result.stderr, result.returncode\n 132|    except (OSError, subprocess.TimeoutExpired) as error:\n 133|        raw, code = f\"CENSUS_UNPROVEN: {error}\\n\", REFUSED\n 134|    (output / f\"{name}.raw\").write_text(raw, encoding=\"utf-8\")\n...\n 185|    except (psutil.Error, OSError) as error:\n*186|        # A failed cleanup observation must not hide the producer's real exit.\n 187|        errors.append({\"operation\": \"wait_procs\", \"error\": str(error)})\n 188|        alive = processes\n 189|    survivors = []\n...\n 201|# [impl->REQ-LOCAL-GATE-EXECUTION-EVIDENCE]\n*202|def run_producer(root, output, name, argv, timeout, env, meter, json_stdout=False):\n 203|    save(output / f\"{name}.command.json\", argv)\n 204|    observed, reason, cleanup_errors, survivors = {}, None, [], []\n 205|    started = time.monotonic()\n...\n 235|        except (OSError, psutil.Error, KeyboardInterrupt) as error:\n*236|            reason = f\"producer-or-observation-error: {error}\"\n 237|            if child is None:\n 238|                launch_failed = True\n 239|            print(reason, file=sys.stderr)\n...\n 251|                except subprocess.TimeoutExpired:\n*252|                    reason = \"producer-exit-unobserved\"\n 253|            if stdout is not None:\n 254|                stdout.close()\n*255|    # A failed artifact write must not turn a real producer failure into another code.\n 256|    try:\n 257|        (output / f\"{name}.exit\").write_text(\n 258|            f\"{code}\\n\" if code is not None else \"UNOBSERVED\\n\", encoding=\"utf-8\")\n 259|        save(output / f\"{name}.observation.json\", {\n*260|            \"producer_exit\": code, \"launch_failed\": launch_failed, \"stop_reason\": reason,\n 261|            \"elapsed_seconds\": time.monotonic() - started,\n 262|            \"observed_identities\": [{\"pid\": pid, \"birth\": birth} for pid, birth in observed],\n 263|            \"cleanup_errors\": cleanup_errors, \"survivors\": survivors,\n...\n 278|    if plan[\"reserve_bytes\"] < w0.FLOOR_BYTES:\n*279|        raise ValueError(\"allocation cannot weaken the existing disk floor\")\n 280|    if not isinstance(plan.get(\"rustc_version\"), str) or not plan[\"rustc_version\"].strip():\n 281|        raise ValueError(\"allocation requires the warm pool's exact rustc -Vv stdout\")\n 282|    if not isinstance(plan.get(\"steps\"), list) or not plan[\"steps\"]:\n...\n 308|# [impl->REQ-LOCAL-GATE-EXECUTION-EVIDENCE]\n*309|def final_status(producer, observations_ok):\n*310|    return producer if producer else (0 if observations_ok else REFUSED)\n 311|\n 312|\n 313|def main():\n...\n 350|    actual = subprocess.run([\"rustc\", \"-Vv\"], cwd=root, env=env, capture_output=True, text=True, timeout=30)\n*351|    save(output / \"toolchain.json\", {\"stdout\": actual.stdout, \"stderr\": actual.stderr, \"exit\": actual.returncode})\n 352|    cached = json.loads((target / \".rustc_info.json\").read_text(encoding=\"utf-8\"))\n 353|    cached_outputs = cached.get(\"outputs\", {}).values()\n*354|    if actual.returncode or actual.stdout != plan[\"rustc_version\"] or not any(row.get(\"success\") is True and row.get(\"stdout\") == actual.stdout for row in cached_outputs):\n 355|        raise ValueError(\"toolchain differs from allocated warm cache; allocation invalid\")\n 356|    lock = w0.claim_pool(root)\n 357|    if lock is None:\n...\n 364|        save(output / \"builders-before.json\", builder_snapshot())\n*365|        if not w0.disk_floor(root, output, \"start\", xtask):\n*366|            raise ValueError(\"disk floor refused\")\n*367|        result, ok = run_producer(root, output, \"pool-claim\", [str(xtask), \"pool-claim\", \"--pool\", str(target), \"--label\", \"local-lane\"], 30, env, lambda: meter(\"claim\"))\n 368|        claimed = result == 0\n 369|        result = final_status(result, ok)\n 370|        if not claimed:\n...\n 383|                listing, argv = selected_commands(step[\"nextest\"])\n*384|                result, ok = run_producer(root, output, name + \"-inventory\", listing, step[\"timeout_seconds\"], env, lambda: meter(name + \"-inventory\"), json_stdout=True)\n 385|                after_ok = observe_after(root, output, name + \"-inventory\", env, meter)\n 386|                ok = ok and after_ok\n 387|                if result or not ok:\n...\n 393|                argv = step[\"argv\"]\n*394|            result, ok = run_producer(root, output, name, argv, step[\"timeout_seconds\"], env, lambda: meter(name))\n 395|            after_ok = observe_after(root, output, name, env, meter)\n 396|            result = final_status(result, ok and after_ok)\n 397|            if result:\n## find-cwd-holders.ps1\n 9|# `git worktree remove` fails with a message about the directory rather than\n*10|# about a handle. The usual producer is an orphaned test DESCENDANT: cargo runs\n 11|# test binaries with cwd = the package root, every child (and grandchild) a test\n 12|# spawns inherits `<worktree>/crates/<pkg>` as ITS cwd, and one that outlives the\n 13|# test holds that cwd forever. The result is a `.worktrees` skeleton that will\n## g6-curve.ps1\n 82|    $c1 = Tree-Cpu $pid2\n*83|    $out = & cargo nextest run -p spt-daemon --test inject_control_wedge `\n 84|        -E 'test(g6_faulted_inflight_envelope_is_respooled_not_lost)' -j 2 --no-fail-fast 2>&1\n 85|    $c2 = Tree-Cpu $pid2\n 86|    $line = ($out | Select-String -Pattern 'g6_faulted_inflight_envelope_is_respooled_not_lost' |\n## g6-postbounce.ps1\n 42|\n*43|cargo nextest run -p spt-daemon --test inject_control_wedge -j 2 --no-fail-fast 2>&1 |\n*44|    Select-String -Pattern 'W1 G6|respooled|TRANSLATION_|FAIL |Summary|g6_faulted|panicked' |\n 45|    ForEach-Object { $_.Line }\n 46|Write-Output \"EXIT=$LASTEXITCODE\"\n 47|\n## local-lane-selftest.py\n 79|# [unit->REQ-LOCAL-GATE-EXECUTION-EVIDENCE]\n*80|class ProducerTests(unittest.TestCase):\n 81|    def test_json_inventory_stderr_and_actual_failure_are_preserved(self):\n 82|        with tempfile.TemporaryDirectory() as directory:\n 83|            output = Path(directory)\n*84|            code, observed = lane.run_producer(output, output, \"fixture\", [sys.executable, \"-c\",\n*85|                \"import sys; print('{\\\"test-count\\\": 0}'); print('producer diagnostic', file=sys.stderr); sys.exit(7)\"],\n 86|                30, None, lambda: True, json_stdout=True)\n 87|            self.assertEqual(code, 7)\n 88|            self.assertTrue(observed)\n 89|            self.assertEqual(json.loads((output / \"fixture.stdout\").read_text()), {\"test-count\": 0})\n*90|            self.assertIn(\"producer diagnostic\", (output / \"fixture.raw\").read_text())\n 91|            self.assertEqual((output / \"fixture.exit\").read_text().strip(), \"7\")\n 92|            self.assertEqual(lane.final_status(code, False), 7)\n 93|\n*94|    def test_cleanup_wait_failure_preserves_actual_producer_exit(self):\n 95|        with tempfile.TemporaryDirectory() as directory:\n 96|            output = Path(directory)\n 97|            with patch.object(lane.psutil, \"wait_procs\", side_effect=OSError(\"wait unavailable\")):\n*98|                code, observed = lane.run_producer(output, output, \"fixture\",\n 99|                    [sys.executable, \"-c\", \"import sys; sys.exit(7)\"],\n 100|                    30, None, lambda: True)\n 101|            self.assertEqual(code, 7)\n...\n 104|            record = json.loads((output / \"fixture.observation.json\").read_text())\n*105|            self.assertEqual(record[\"producer_exit\"], 7)\n 106|            self.assertIn(\"wait unavailable\", str(record[\"cleanup_errors\"]))\n 107|\n*108|    def test_capacity_refusal_stops_the_owned_producer(self):\n 109|        with tempfile.TemporaryDirectory() as directory:\n 110|            output = Path(directory)\n*111|            code, observed = lane.run_producer(output, output, \"fixture\", [sys.executable, \"-c\",\n 112|                \"import time; time.sleep(60)\"], 30, None, lambda: False)\n 113|            self.assertFalse(observed)\n 114|            self.assertNotEqual(code, 0)\n 115|            record = json.loads((output / \"fixture.observation.json\").read_text())\n*116|            self.assertIsNotNone(record[\"producer_exit\"])\n 117|            self.assertEqual(record[\"survivors\"], [])\n 118|\n 119|    def test_disk_observation_failure_does_not_skip_cleanup_or_replace_failure(self):\n## reap-census.ps1\n 155|\n*156|    # ONE greppable summary line per census, so a run-to-run diff is a grep, not a read.\n 157|    Write-Output (\"CI-CENSUS phase={0} box_procs={1} box_handles={2} family_total={3} family_handles={4} scoped={5} unscoped={6} unreadable_path={7}\" -f `\n 158|            $Label, $boxProcs.Count, ($boxHandles ?? 0), $Rows.Count, ($famHandles ?? 0), $scoped.Count, ($Rows.Count - $scoped.Count), $unreadable.Count)\n 159|\n...\n 245|if ($isPrerelink) {\n*246|    Write-Output \"CI-REAP-PRERELINK summary: killed=$killed kill_failed=$failed scoped_survivors=$survivorVerdict observed_scoped=$survivors unreadable_path=$unreadable\"\n 247|}\n 248|else {\n*249|    Write-Output \"CI-REAP summary: killed=$killed kill_failed=$failed scoped_survivors=$survivorVerdict observed_scoped=$survivors unreadable_path=$unreadable\"\n 250|}\n 251|\n 252|# STRICT IS AN END-OF-JOB MECHANISM AND STAYS ONE. A prerelink survivor never reds THIS\n## reap-census.sh\n 176|# THEN exits 1, so a `|| echo 0` fallback fires AFTER the print and captures \"0\\n0\" — which\n*177|# lands a newline inside the summary line and breaks the one-greppable-line contract the\n 178|# census exists for. An exit above 1 is a usage error, not a no-match, and is reported as\n 179|# UNKNOWN rather than silently folded into zero.\n 180|flood_count() {\n...\n 192|# Publishes the scoped count in CENSUS_SCOPED; human-readable rows go to stdout under one\n*193|# greppable summary line, so a run-to-run diff is a grep rather than a read.\n 194|census() {\n 195|  local label=\"$1\" scoped=0 total=0 unreadable=0 pid exe tag rows=\"\" d c\n 196|  local box_procs=0\n...\n 298|verdict=$(survivor_verdict \"$observed\" \"$unreadable\")\n*299|echo \"CI-REAP summary: killed=$killed kill_failed=$kill_failed flood_orphans=$floods_reaped scoped_survivors=$verdict observed_scoped=$observed unreadable_path=$unreadable\"\n 300|\n 301|if [ \"$observed\" -gt 0 ] || [ \"$unreadable\" -gt 0 ]; then\n 302|  if [ \"$unreadable\" -gt 0 ]; then\n## ws272-w0.py\n 17|re-ran this driver beside the intended one, two suites interleaved one\n*18|nextest.raw (two Summary lines), and the gater voided the window.\n 19|\n 20|The battery runs under a SCRUBBED environment: the perch identity variables an\n 21|agent's shell carries (SPT_ENDPOINT_ID and its companions) are dropped from\n...\n 38|ACTIVE_STATES = (\"in_progress\", \"queued\", \"waiting\", \"pending\", \"requested\")\n*39|# The same floor xtask disk-floor enforces (32 GiB); the bootstrap reading\n 40|# below must never be more lenient than the meter it stands in for.\n 41|FLOOR_BYTES = 32 << 30\n 42|# The perch identity a live agent's shell carries. A battery must never look\n...\n 87|    result = subprocess.run([\"gh\", \"api\", WORKFLOW + suffix], capture_output=True, text=True)\n*88|    if result.returncode:\n*89|        raise RuntimeError(f\"gh api exited {result.returncode}: {result.stderr.strip()}\")\n 90|    return json.loads(result.stdout)\n 91|\n 92|\n...\n 138|            first.close()\n*139|        if held.returncode != 4 or f\"pid {os.getpid()}\" not in held.stdout:\n*140|            raise AssertionError(f\"lane lock: second driver not refused naming the holder: rc={held.returncode} \"\n 141|                                 f\"out={held.stdout!r} err={held.stderr!r}\")\n 142|        freed = subprocess.run(probe, capture_output=True, text=True)\n*143|        if freed.returncode != 0:\n*144|            raise AssertionError(f\"lane lock: not released with its holder: rc={freed.returncode} err={freed.stderr!r}\")\n 145|        print(\"PASS lane lock: second driver refused while the holder lives, free once it exits\")\n 146|    tainted = {\"OWL_SESSION_ID\": \"owl\", \"SPT_AGENT_ID\": \"a\", \"SPT_ENDPOINT_ID\": \"agent\", \"SPT_HOST_PID\": \"1\", \"PATH\": \"keep\", \"SPT_HOME\": \"keep\"}\n 147|    env, dropped = battery_env(tainted)\n...\n 156|        admitted, verdict = floor_verdict(raw, 0)\n*157|        if \"DISK_FLOOR:BOOTSTRAP\" not in raw or \"no-such-xtask\" not in raw or verdict.split(\":\")[1] not in (\"PASS\", \"REFUSE\"):\n 158|            raise AssertionError(f\"cold-pool bootstrap: raw={raw!r} verdict={verdict!r}\")\n 159|        print(f\"PASS cold-pool bootstrap: direct reading named the missing meter and rendered {verdict.split(':')[1]}\")\n 160|\n 161|\n*162|# [impl->REQ-DISK-FLOOR-PREFLIGHT]\n 163|def floor_verdict(raw, code):\n 164|    \"\"\"Render GiB from xtask's own byte reading, never a second disk probe.\"\"\"\n 165|    fields = dict(re.findall(r\"\\b(free_bytes|floor_bytes)=(\\d+)\", raw))\n 166|    if len(fields) != 2:\n*167|        return False, f\"DISK_FLOOR:REFUSE: xtask exit={code}; no complete disk reading\"\n 168|    free, floor = int(fields[\"free_bytes\"]), int(fields[\"floor_bytes\"])\n 169|    admitted = code == 0 and free >= floor\n 170|    verdict = \"PASS\" if admitted else \"REFUSE\"\n 171|    return admitted, (\n*172|        f\"DISK_FLOOR:{verdict}: free_gib={free / (1 << 30):.2f} \"\n 173|        f\"floor_gib={floor / (1 << 30):.2f} xtask_exit={code}\"\n 174|    )\n 175|\n...\n 184|    return (\n*185|        f\"DISK_FLOOR:BOOTSTRAP: prebuilt xtask absent ({xtask}); direct free-space \"\n 186|        f\"read free_bytes={free} floor_bytes={FLOOR_BYTES} label=ws272-w0\\n\"\n 187|    )\n 188|\n 189|\n*190|def disk_floor(root, output, name, xtask):\n 191|    # Use a prebuilt xtask: compiling the meter before its first reading would\n 192|    # make the very first build unguarded. --xtask permits a bootstrap binary;\n 193|    # a cold pool (no meter at all) takes one direct reading, named as such.\n...\n 198|            result = subprocess.run(\n*199|                [str(xtask), \"disk-floor\", \"--path\", str(root), \"--label\", \"ws272-w0\"],\n 200|                cwd=root, capture_output=True, text=True,\n 201|            )\n*202|            raw, code = result.stdout + result.stderr, result.returncode\n 203|        except OSError as error:\n 204|            raw, code = f\"Cannot run prebuilt xtask {xtask}: {error}\\n\", 127\n 205|    admitted, verdict = floor_verdict(raw, code)\n...\n 252|    if guarded:\n*253|        if not preflight() or not disk_floor(root, output, name, xtask):\n 254|            (output / f\"{name}.exit\").write_text(\"75\\n\", encoding=\"utf-8\")\n 255|            return False\n 256|    with (output / f\"{name}.raw\").open(\"wb\") as log:\n...\n 258|            result = subprocess.run(argv, cwd=root, stdout=log, stderr=subprocess.STDOUT, env=BATTERY_ENV)\n*259|            code = result.returncode\n 260|        except OSError as error:\n 261|            log.write(str(error).encode(\"utf-8\"))\n 262|            code = 127\n...\n 279|    parser.add_argument(\"--xtask\", type=Path,\n*280|                        help=\"prebuilt disk-floor meter; defaults to this lane's debug xtask\")\n 281|    args = parser.parse_args()\n 282|    if args.self_test:\n 283|        self_test()\n## ws272-w1.py\n 23|re-ran this driver beside the intended one, two suites interleaved one\n*24|nextest.raw (two Summary lines), and the gater voided the window.\n 25|\n 26|The battery runs under a SCRUBBED environment: the perch identity variables an\n 27|agent's shell carries (SPT_ENDPOINT_ID and its companions) are dropped from\n...\n 44|ACTIVE_STATES = (\"in_progress\", \"queued\", \"waiting\", \"pending\", \"requested\")\n*45|# The same floor xtask disk-floor enforces (32 GiB); the bootstrap reading\n 46|# below must never be more lenient than the meter it stands in for.\n 47|FLOOR_BYTES = 32 << 30\n 48|# The perch identity a live agent's shell carries. A battery must never look\n...\n 93|    result = subprocess.run([\"gh\", \"api\", WORKFLOW + suffix], capture_output=True, text=True)\n*94|    if result.returncode:\n*95|        raise RuntimeError(f\"gh api exited {result.returncode}: {result.stderr.strip()}\")\n 96|    return json.loads(result.stdout)\n 97|\n 98|\n...\n 144|            first.close()\n*145|        if held.returncode != 4 or f\"pid {os.getpid()}\" not in held.stdout:\n*146|            raise AssertionError(f\"lane lock: second driver not refused naming the holder: rc={held.returncode} \"\n 147|                                 f\"out={held.stdout!r} err={held.stderr!r}\")\n 148|        freed = subprocess.run(probe, capture_output=True, text=True)\n*149|        if freed.returncode != 0:\n*150|            raise AssertionError(f\"lane lock: not released with its holder: rc={freed.returncode} err={freed.stderr!r}\")\n 151|        print(\"PASS lane lock: second driver refused while the holder lives, free once it exits\")\n 152|    tainted = {\"OWL_SESSION_ID\": \"owl\", \"SPT_AGENT_ID\": \"a\", \"SPT_ENDPOINT_ID\": \"agent\", \"SPT_HOST_PID\": \"1\", \"PATH\": \"keep\", \"SPT_HOME\": \"keep\"}\n 153|    env, dropped = battery_env(tainted)\n...\n 162|        admitted, verdict = floor_verdict(raw, 0)\n*163|        if \"DISK_FLOOR:BOOTSTRAP\" not in raw or \"no-such-xtask\" not in raw or verdict.split(\":\")[1] not in (\"PASS\", \"REFUSE\"):\n 164|            raise AssertionError(f\"cold-pool bootstrap: raw={raw!r} verdict={verdict!r}\")\n 165|        print(f\"PASS cold-pool bootstrap: direct reading named the missing meter and rendered {verdict.split(':')[1]}\")\n 166|\n 167|\n*168|# [impl->REQ-DISK-FLOOR-PREFLIGHT]\n 169|def floor_verdict(raw, code):\n 170|    \"\"\"Render GiB from xtask's own byte reading, never a second disk probe.\"\"\"\n 171|    fields = dict(re.findall(r\"\\b(free_bytes|floor_bytes)=(\\d+)\", raw))\n 172|    if len(fields) != 2:\n*173|        return False, f\"DISK_FLOOR:REFUSE: xtask exit={code}; no complete disk reading\"\n 174|    free, floor = int(fields[\"free_bytes\"]), int(fields[\"floor_bytes\"])\n 175|    admitted = code == 0 and free >= floor\n 176|    verdict = \"PASS\" if admitted else \"REFUSE\"\n 177|    return admitted, (\n*178|        f\"DISK_FLOOR:{verdict}: free_gib={free / (1 << 30):.2f} \"\n 179|        f\"floor_gib={floor / (1 << 30):.2f} xtask_exit={code}\"\n 180|    )\n 181|\n...\n 190|    return (\n*191|        f\"DISK_FLOOR:BOOTSTRAP: prebuilt xtask absent ({xtask}); direct free-space \"\n 192|        f\"read free_bytes={free} floor_bytes={FLOOR_BYTES} label=ws272-w1\\n\"\n 193|    )\n 194|\n 195|\n*196|def disk_floor(root, output, name, xtask):\n 197|    # Use a prebuilt xtask: compiling the meter before its first reading would\n 198|    # make the very first build unguarded. --xtask permits a bootstrap binary;\n 199|    # a cold pool (no meter at all) takes one direct reading, named as such.\n...\n 204|            result = subprocess.run(\n*205|                [str(xtask), \"disk-floor\", \"--path\", str(root), \"--label\", \"ws272-w1\"],\n 206|                cwd=root, capture_output=True, text=True,\n 207|            )\n*208|            raw, code = result.stdout + result.stderr, result.returncode\n 209|        except OSError as error:\n 210|            raw, code = f\"Cannot run prebuilt xtask {xtask}: {error}\\n\", 127\n 211|    admitted, verdict = floor_verdict(raw, code)\n...\n 258|    if guarded:\n*259|        if not preflight() or not disk_floor(root, output, name, xtask):\n 260|            (output / f\"{name}.exit\").write_text(\"75\\n\", encoding=\"utf-8\")\n 261|            return False\n 262|    with (output / f\"{name}.raw\").open(\"wb\") as log:\n...\n 264|            result = subprocess.run(argv, cwd=root, stdout=log, stderr=subprocess.STDOUT, env=BATTERY_ENV)\n*265|            code = result.returncode\n 266|        except OSError as error:\n 267|            log.write(str(error).encode(\"utf-8\"))\n 268|            code = 127\n...\n 285|    parser.add_argument(\"--xtask\", type=Path,\n*286|                        help=\"prebuilt disk-floor meter; defaults to this lane's debug xtask\")\n 287|    args = parser.parse_args()\n 288|    if args.self_test:\n 289|        self_test()\n...\n 322|                     \"-p\", \"spt-runtime\", \"-p\", \"spt-net\", \"-p\", \"spt-daemon\", \"-p\", \"spt\"], True),\n*323|        # The two-host bin ALONE (its own Summary line; env-gated, a silent\n 324|        # no-op without SPT_TWO_HOST=1 + a role).\n 325|        (\"twohost_web\", [\"cargo\", \"nextest\", \"run\", \"--no-fail-fast\", \"-p\", \"spt-daemon\",\n 326|                         \"--test\", \"twohost_web\"], True),\n## ws272-w2.py\n 30|re-ran this driver beside the intended one, two suites interleaved one\n*31|nextest.raw (two Summary lines), and the gater voided the window.\n 32|\n 33|The battery runs under a SCRUBBED environment: the perch identity variables an\n 34|agent's shell carries (SPT_ENDPOINT_ID and its companions) are dropped from\n...\n 51|ACTIVE_STATES = (\"in_progress\", \"queued\", \"waiting\", \"pending\", \"requested\")\n*52|# The same floor xtask disk-floor enforces (32 GiB); the bootstrap reading\n 53|# below must never be more lenient than the meter it stands in for.\n 54|FLOOR_BYTES = 32 << 30\n 55|# The perch identity a live agent's shell carries. A battery must never look\n...\n 100|    result = subprocess.run([\"gh\", \"api\", WORKFLOW + suffix], capture_output=True, text=True)\n*101|    if result.returncode:\n*102|        raise RuntimeError(f\"gh api exited {result.returncode}: {result.stderr.strip()}\")\n 103|    return json.loads(result.stdout)\n 104|\n 105|\n...\n 151|            first.close()\n*152|        if held.returncode != 4 or f\"pid {os.getpid()}\" not in held.stdout:\n*153|            raise AssertionError(f\"lane lock: second driver not refused naming the holder: rc={held.returncode} \"\n 154|                                 f\"out={held.stdout!r} err={held.stderr!r}\")\n 155|        freed = subprocess.run(probe, capture_output=True, text=True)\n*156|        if freed.returncode != 0:\n*157|            raise AssertionError(f\"lane lock: not released with its holder: rc={freed.returncode} err={freed.stderr!r}\")\n 158|        print(\"PASS lane lock: second driver refused while the holder lives, free once it exits\")\n 159|    tainted = {\"OWL_SESSION_ID\": \"owl\", \"SPT_AGENT_ID\": \"a\", \"SPT_ENDPOINT_ID\": \"agent\", \"SPT_HOST_PID\": \"1\", \"PATH\": \"keep\", \"SPT_HOME\": \"keep\"}\n 160|    env, dropped = battery_env(tainted)\n...\n 169|        admitted, verdict = floor_verdict(raw, 0)\n*170|        if \"DISK_FLOOR:BOOTSTRAP\" not in raw or \"no-such-xtask\" not in raw or verdict.split(\":\")[1] not in (\"PASS\", \"REFUSE\"):\n 171|            raise AssertionError(f\"cold-pool bootstrap: raw={raw!r} verdict={verdict!r}\")\n 172|        print(f\"PASS cold-pool bootstrap: direct reading named the missing meter and rendered {verdict.split(':')[1]}\")\n 173|\n 174|\n*175|# [impl->REQ-DISK-FLOOR-PREFLIGHT]\n 176|def floor_verdict(raw, code):\n 177|    \"\"\"Render GiB from xtask's own byte reading, never a second disk probe.\"\"\"\n 178|    fields = dict(re.findall(r\"\\b(free_bytes|floor_bytes)=(\\d+)\", raw))\n 179|    if len(fields) != 2:\n*180|        return False, f\"DISK_FLOOR:REFUSE: xtask exit={code}; no complete disk reading\"\n 181|    free, floor = int(fields[\"free_bytes\"]), int(fields[\"floor_bytes\"])\n 182|    admitted = code == 0 and free >= floor\n 183|    verdict = \"PASS\" if admitted else \"REFUSE\"\n 184|    return admitted, (\n*185|        f\"DISK_FLOOR:{verdict}: free_gib={free / (1 << 30):.2f} \"\n 186|        f\"floor_gib={floor / (1 << 30):.2f} xtask_exit={code}\"\n 187|    )\n 188|\n...\n 197|    return (\n*198|        f\"DISK_FLOOR:BOOTSTRAP: prebuilt xtask absent ({xtask}); direct free-space \"\n 199|        f\"read free_bytes={free} floor_bytes={FLOOR_BYTES} label=ws272-w2\\n\"\n 200|    )\n 201|\n 202|\n*203|def disk_floor(root, output, name, xtask):\n 204|    # Use a prebuilt xtask: compiling the meter before its first reading would\n 205|    # make the very first build unguarded. --xtask permits a bootstrap binary;\n 206|    # a cold pool (no meter at all) takes one direct reading, named as such.\n...\n 211|            result = subprocess.run(\n*212|                [str(xtask), \"disk-floor\", \"--path\", str(root), \"--label\", \"ws272-w2\"],\n 213|                cwd=root, capture_output=True, text=True,\n 214|            )\n*215|            raw, code = result.stdout + result.stderr, result.returncode\n 216|        except OSError as error:\n 217|            raw, code = f\"Cannot run prebuilt xtask {xtask}: {error}\\n\", 127\n 218|    admitted, verdict = floor_verdict(raw, code)\n...\n 292|    raw = (output / \"population.raw\").read_text(encoding=\"utf-8\", errors=\"replace\")\n*293|    # COUNT THE ROWS THEMSELVES, never a summary phrase: `nextest list` prints\n 294|    # one \"<package> <test::path>\" line per selected test and no total, so a\n 295|    # meter keyed on prose reads zero and refuses a healthy battery. Measured\n 296|    # against a real listing (1673 selected) after the first version did exactly\n...\n 311|    if guarded:\n*312|        if not preflight() or not disk_floor(root, output, name, xtask):\n 313|            (output / f\"{name}.exit\").write_text(\"75\\n\", encoding=\"utf-8\")\n 314|            return False\n 315|    with (output / f\"{name}.raw\").open(\"wb\") as log:\n...\n 317|            result = subprocess.run(argv, cwd=root, stdout=log, stderr=subprocess.STDOUT, env=BATTERY_ENV)\n*318|            code = result.returncode\n 319|        except OSError as error:\n 320|            log.write(str(error).encode(\"utf-8\"))\n 321|            code = 127\n...\n 338|    parser.add_argument(\"--xtask\", type=Path,\n*339|                        help=\"prebuilt disk-floor meter; defaults to this lane's debug xtask\")\n 340|    args = parser.parse_args()\n 341|    if args.self_test:\n 342|        self_test()"}],"details":{"scopePath":".worktrees/hertz-ir86-disk-delta/.github/ci/local-lane.py, .worktrees/hertz-ir86-disk-delta/.github/ci","searchPath":"C:\\Users\\decid\\Documents\\projects\\spt-core\\.worktrees\\hertz-ir86-disk-delta\\.github\\ci","cwd":"C:\\Users\\decid\\Documents\\projects\\spt-core","matchCount":99,"fileCount":10,"files":[".worktrees/hertz-ir86-disk-delta/.github/ci/local-lane.py",".worktrees/hertz-ir86-disk-delta/.github/ci/find-cwd-holders.ps1",".worktrees/hertz-ir86-disk-delta/.github/ci/g6-curve.ps1",".worktrees/hertz-ir86-disk-delta/.github/ci/g6-postbounce.ps1",".worktrees/hertz-ir86-disk-delta/.github/ci/local-lane-selftest.py",".worktrees/hertz-ir86-disk-delta/.github/ci/reap-census.ps1",".worktrees/hertz-ir86-disk-delta/.github/ci/reap-census.sh",".worktrees/hertz-ir86-disk-delta/.github/ci/ws272-w0.py",".worktrees/hertz-ir86-disk-delta/.github/ci/ws272-w1.py",".worktrees/hertz-ir86-disk-delta/.github/ci/ws272-w2.py"],"fileMatches":[{"path":".worktrees/hertz-ir86-disk-delta/.github/ci/local-lane.py","count":20},{"path":".worktrees/hertz-ir86-disk-delta/.github/ci/find-cwd-holders.ps1","count":1},{"path":".worktrees/hertz-ir86-disk-delta/.github/ci/g6-curve.ps1","count":1},{"path":".worktrees/hertz-ir86-disk-delta/.github/ci/g6-postbounce.ps1","count":2},{"path":".worktrees/hertz-ir86-disk-delta/.github/ci/local-lane-selftest.py","count":10},{"path":".worktrees/hertz-ir86-disk-delta/.github/ci/reap-census.ps1","count":3},{"path":".worktrees/hertz-ir86-disk-delta/.github/ci/reap-census.sh","count":3},{"path":".worktrees/hertz-ir86-disk-delta/.github/ci/ws272-w0.py","count":19},{"path":".worktrees/hertz-ir86-disk-delta/.github/ci/ws272-w1.py","count":20},{"path":".worktrees/hertz-ir86-disk-delta/.github/ci/ws272-w2.py","count":20}],"truncated":true,"perFileLimitReached":20,"displayContent":"# .worktrees/hertz-ir86-disk-delta/.github/ci/\n## local-lane.py\n  10│Requires the gater's --hold-released acknowledgement. Reuses ws272-w0's quiet\n *11│meter, lane lock, identity scrub and disk-floor meter. Volume movement is aggregate\n  12│capacity evidence, NOT attribution to this lane. Census has the existing reaper's\n  13│explicit scope; an unavailable/incomplete census is never clearance.\n  14│\"\"\"\n    │...\n  63│def selected_inventory(inventory):\n *64│    \"\"\"Interpret nextest-metadata's TestListSummary, retaining only matching tests.\"\"\"\n  65│    suites = inventory.get(\"rust-suites\") if isinstance(inventory, dict) else None\n  66│    if not isinstance(suites, dict):\n  67│        raise ValueError(\"nextest inventory has no suite map\")\n    │...\n 100│    try:\n*101│        disk_ok = meter(name + \"-after-producer\")\n 102│    except OSError as error:\n 103│        print(f\"DISK_OBSERVATION_UNPROVEN: {error}\", file=sys.stderr)\n 104│    try:\n    │...\n 130│        result = subprocess.run(argv, cwd=root, env=env, capture_output=True, text=True, timeout=60)\n*131│        raw, code = result.stdout + result.stderr, result.returncode\n 132│    except (OSError, subprocess.TimeoutExpired) as error:\n 133│        raw, code = f\"CENSUS_UNPROVEN: {error}\\n\", REFUSED\n 134│    (output / f\"{name}.raw\").write_text(raw, encoding=\"utf-8\")\n    │...\n 185│    except (psutil.Error, OSError) as error:\n*186│        # A failed cleanup observation must not hide the producer's real exit.\n 187│        errors.append({\"operation\": \"wait_procs\", \"error\": str(error)})\n 188│        alive = processes\n 189│    survivors = []\n    │...\n 201│# [impl->REQ-LOCAL-GATE-EXECUTION-EVIDENCE]\n*202│def run_producer(root, output, name, argv, timeout, env, meter, json_stdout=False):\n 203│    save(output / f\"{name}.command.json\", argv)\n 204│    observed, reason, cleanup_errors, survivors = {}, None, [], []\n 205│    started = time.monotonic()\n    │...\n 235│        except (OSError, psutil.Error, KeyboardInterrupt) as error:\n*236│            reason = f\"producer-or-observation-error: {error}\"\n 237│            if child is None:\n 238│                launch_failed = True\n 239│            print(reason, file=sys.stderr)\n    │...\n 251│                except subprocess.TimeoutExpired:\n*252│                    reason = \"producer-exit-unobserved\"\n 253│            if stdout is not None:\n 254│                stdout.close()\n*255│    # A failed artifact write must not turn a real producer failure into another code.\n 256│    try:\n 257│        (output / f\"{name}.exit\").write_text(\n 258│            f\"{code}\\n\" if code is not None else \"UNOBSERVED\\n\", encoding=\"utf-8\")\n 259│        save(output / f\"{name}.observation.json\", {\n*260│            \"producer_exit\": code, \"launch_failed\": launch_failed, \"stop_reason\": reason,\n 261│            \"elapsed_seconds\": time.monotonic() - started,\n 262│            \"observed_identities\": [{\"pid\": pid, \"birth\": birth} for pid, birth in observed],\n 263│            \"cleanup_errors\": cleanup_errors, \"survivors\": survivors,\n    │...\n 278│    if plan[\"reserve_bytes\"] < w0.FLOOR_BYTES:\n*279│        raise ValueError(\"allocation cannot weaken the existing disk floor\")\n 280│    if not isinstance(plan.get(\"rustc_version\"), str) or not plan[\"rustc_version\"].strip():\n 281│        raise ValueError(\"allocation requires the warm pool's exact rustc -Vv stdout\")\n 282│    if not isinstance(plan.get(\"steps\"), list) or not plan[\"steps\"]:\n    │...\n 308│# [impl->REQ-LOCAL-GATE-EXECUTION-EVIDENCE]\n*309│def final_status(producer, observations_ok):\n*310│    return producer if producer else (0 if observations_ok else REFUSED)\n 311│\n 312│\n 313│def main():\n    │...\n 350│    actual = subprocess.run([\"rustc\", \"-Vv\"], cwd=root, env=env, capture_output=True, text=True, timeout=30)\n*351│    save(output / \"toolchain.json\", {\"stdout\": actual.stdout, \"stderr\": actual.stderr, \"exit\": actual.returncode})\n 352│    cached = json.loads((target / \".rustc_info.json\").read_text(encoding=\"utf-8\"))\n 353│    cached_outputs = cached.get(\"outputs\", {}).values()\n*354│    if actual.returncode or actual.stdout != plan[\"rustc_version\"] or not any(row.get(\"success\") is True and row.get(\"stdout\") == actual.stdout for row in cached_outputs):\n 355│        raise ValueError(\"toolchain differs from allocated warm cache; allocation invalid\")\n 356│    lock = w0.claim_pool(root)\n 357│    if lock is None:\n    │...\n 364│        save(output / \"builders-before.json\", builder_snapshot())\n*365│        if not w0.disk_floor(root, output, \"start\", xtask):\n*366│            raise ValueError(\"disk floor refused\")\n*367│        result, ok = run_producer(root, output, \"pool-claim\", [str(xtask), \"pool-claim\", \"--pool\", str(target), \"--label\", \"local-lane\"], 30, env, lambda: meter(\"claim\"))\n 368│        claimed = result == 0\n 369│        result = final_status(result, ok)\n 370│        if not claimed:\n    │...\n 383│                listing, argv = selected_commands(step[\"nextest\"])\n*384│                result, ok = run_producer(root, output, name + \"-inventory\", listing, step[\"timeout_seconds\"], env, lambda: meter(name + \"-inventory\"), json_stdout=True)\n 385│                after_ok = observe_after(root, output, name + \"-inventory\", env, meter)\n 386│                ok = ok and after_ok\n 387│                if result or not ok:\n    │...\n 393│                argv = step[\"argv\"]\n*394│            result, ok = run_producer(root, output, name, argv, step[\"timeout_seconds\"], env, lambda: meter(name))\n 395│            after_ok = observe_after(root, output, name, env, meter)\n 396│            result = final_status(result, ok and after_ok)\n 397│            if result:\n## find-cwd-holders.ps1\n  9│# `git worktree remove` fails with a message about the directory rather than\n*10│# about a handle. The usual producer is an orphaned test DESCENDANT: cargo runs\n 11│# test binaries with cwd = the package root, every child (and grandchild) a test\n 12│# spawns inherits `<worktree>/crates/<pkg>` as ITS cwd, and one that outlives the\n 13│# test holds that cwd forever. The result is a `.worktrees` skeleton that will\n## g6-curve.ps1\n 82│    $c1 = Tree-Cpu $pid2\n*83│    $out = & cargo nextest run -p spt-daemon --test inject_control_wedge `\n 84│        -E 'test(g6_faulted_inflight_envelope_is_respooled_not_lost)' -j 2 --no-fail-fast 2>&1\n 85│    $c2 = Tree-Cpu $pid2\n 86│    $line = ($out | Select-String -Pattern 'g6_faulted_inflight_envelope_is_respooled_not_lost' |\n## g6-postbounce.ps1\n 42│\n*43│cargo nextest run -p spt-daemon --test inject_control_wedge -j 2 --no-fail-fast 2>&1 |\n*44│    Select-String -Pattern 'W1 G6|respooled|TRANSLATION_|FAIL |Summary|g6_faulted|panicked' |\n 45│    ForEach-Object { $_.Line }\n 46│Write-Output \"EXIT=$LASTEXITCODE\"\n 47│\n## local-lane-selftest.py\n  79│# [unit->REQ-LOCAL-GATE-EXECUTION-EVIDENCE]\n *80│class ProducerTests(unittest.TestCase):\n  81│    def test_json_inventory_stderr_and_actual_failure_are_preserved(self):\n  82│        with tempfile.TemporaryDirectory() as directory:\n  83│            output = Path(directory)\n *84│            code, observed = lane.run_producer(output, output, \"fixture\", [sys.executable, \"-c\",\n *85│                \"import sys; print('{\\\"test-count\\\": 0}'); print('producer diagnostic', file=sys.stderr); sys.exit(7)\"],\n  86│                30, None, lambda: True, json_stdout=True)\n  87│            self.assertEqual(code, 7)\n  88│            self.assertTrue(observed)\n  89│            self.assertEqual(json.loads((output / \"fixture.stdout\").read_text()), {\"test-count\": 0})\n *90│            self.assertIn(\"producer diagnostic\", (output / \"fixture.raw\").read_text())\n  91│            self.assertEqual((output / \"fixture.exit\").read_text().strip(), \"7\")\n  92│            self.assertEqual(lane.final_status(code, False), 7)\n  93│\n *94│    def test_cleanup_wait_failure_preserves_actual_producer_exit(self):\n  95│        with tempfile.TemporaryDirectory() as directory:\n  96│            output = Path(directory)\n  97│            with patch.object(lane.psutil, \"wait_procs\", side_effect=OSError(\"wait unavailable\")):\n *98│                code, observed = lane.run_producer(output, output, \"fixture\",\n  99│                    [sys.executable, \"-c\", \"import sys; sys.exit(7)\"],\n 100│                    30, None, lambda: True)\n 101│            self.assertEqual(code, 7)\n    │...\n 104│            record = json.loads((output / \"fixture.observation.json\").read_text())\n*105│            self.assertEqual(record[\"producer_exit\"], 7)\n 106│            self.assertIn(\"wait unavailable\", str(record[\"cleanup_errors\"]))\n 107│\n*108│    def test_capacity_refusal_stops_the_owned_producer(self):\n 109│        with tempfile.TemporaryDirectory() as directory:\n 110│            output = Path(directory)\n*111│            code, observed = lane.run_producer(output, output, \"fixture\", [sys.executable, \"-c\",\n 112│                \"import time; time.sleep(60)\"], 30, None, lambda: False)\n 113│            self.assertFalse(observed)\n 114│            self.assertNotEqual(code, 0)\n 115│            record = json.loads((output / \"fixture.observation.json\").read_text())\n*116│            self.assertIsNotNone(record[\"producer_exit\"])\n 117│            self.assertEqual(record[\"survivors\"], [])\n 118│\n 119│    def test_disk_observation_failure_does_not_skip_cleanup_or_replace_failure(self):\n## reap-census.ps1\n 155│\n*156│    # ONE greppable summary line per census, so a run-to-run diff is a grep, not a read.\n 157│    Write-Output (\"CI-CENSUS phase={0} box_procs={1} box_handles={2} family_total={3} family_handles={4} scoped={5} unscoped={6} unreadable_path={7}\" -f `\n 158│            $Label, $boxProcs.Count, ($boxHandles ?? 0), $Rows.Count, ($famHandles ?? 0), $scoped.Count, ($Rows.Count - $scoped.Count), $unreadable.Count)\n 159│\n    │...\n 245│if ($isPrerelink) {\n*246│    Write-Output \"CI-REAP-PRERELINK summary: killed=$killed kill_failed=$failed scoped_survivors=$survivorVerdict observed_scoped=$survivors unreadable_path=$unreadable\"\n 247│}\n 248│else {\n*249│    Write-Output \"CI-REAP summary: killed=$killed kill_failed=$failed scoped_survivors=$survivorVerdict observed_scoped=$survivors unreadable_path=$unreadable\"\n 250│}\n 251│\n 252│# STRICT IS AN END-OF-JOB MECHANISM AND STAYS ONE. A prerelink survivor never reds THIS\n## reap-census.sh\n 176│# THEN exits 1, so a `|| echo 0` fallback fires AFTER the print and captures \"0\\n0\" — which\n*177│# lands a newline inside the summary line and breaks the one-greppable-line contract the\n 178│# census exists for. An exit above 1 is a usage error, not a no-match, and is reported as\n 179│# UNKNOWN rather than silently folded into zero.\n 180│flood_count() {\n    │...\n 192│# Publishes the scoped count in CENSUS_SCOPED; human-readable rows go to stdout under one\n*193│# greppable summary line, so a run-to-run diff is a grep rather than a read.\n 194│census() {\n 195│  local label=\"$1\" scoped=0 total=0 unreadable=0 pid exe tag rows=\"\" d c\n 196│  local box_procs=0\n    │...\n 298│verdict=$(survivor_verdict \"$observed\" \"$unreadable\")\n*299│echo \"CI-REAP summary: killed=$killed kill_failed=$kill_failed flood_orphans=$floods_reaped scoped_survivors=$verdict observed_scoped=$observed unreadable_path=$unreadable\"\n 300│\n 301│if [ \"$observed\" -gt 0 ] || [ \"$unreadable\" -gt 0 ]; then\n 302│  if [ \"$unreadable\" -gt 0 ]; then\n## ws272-w0.py\n  17│re-ran this driver beside the intended one, two suites interleaved one\n *18│nextest.raw (two Summary lines), and the gater voided the window.\n  19│\n  20│The battery runs under a SCRUBBED environment: the perch identity variables an\n  21│agent's shell carries (SPT_ENDPOINT_ID and its companions) are dropped from\n    │...\n  38│ACTIVE_STATES = (\"in_progress\", \"queued\", \"waiting\", \"pending\", \"requested\")\n *39│# The same floor xtask disk-floor enforces (32 GiB); the bootstrap reading\n  40│# below must never be more lenient than the meter it stands in for.\n  41│FLOOR_BYTES = 32 << 30\n  42│# The perch identity a live agent's shell carries. A battery must never look\n    │...\n  87│    result = subprocess.run([\"gh\", \"api\", WORKFLOW + suffix], capture_output=True, text=True)\n *88│    if result.returncode:\n *89│        raise RuntimeError(f\"gh api exited {result.returncode}: {result.stderr.strip()}\")\n  90│    return json.loads(result.stdout)\n  91│\n  92│\n    │...\n 138│            first.close()\n*139│        if held.returncode != 4 or f\"pid {os.getpid()}\" not in held.stdout:\n*140│            raise AssertionError(f\"lane lock: second driver not refused naming the holder: rc={held.returncode} \"\n 141│                                 f\"out={held.stdout!r} err={held.stderr!r}\")\n 142│        freed = subprocess.run(probe, capture_output=True, text=True)\n*143│        if freed.returncode != 0:\n*144│            raise AssertionError(f\"lane lock: not released with its holder: rc={freed.returncode} err={freed.stderr!r}\")\n 145│        print(\"PASS lane lock: second driver refused while the holder lives, free once it exits\")\n 146│    tainted = {\"OWL_SESSION_ID\": \"owl\", \"SPT_AGENT_ID\": \"a\", \"SPT_ENDPOINT_ID\": \"agent\", \"SPT_HOST_PID\": \"1\", \"PATH\": \"keep\", \"SPT_HOME\": \"keep\"}\n 147│    env, dropped = battery_env(tainted)\n    │...\n 156│        admitted, verdict = floor_verdict(raw, 0)\n*157│        if \"DISK_FLOOR:BOOTSTRAP\" not in raw or \"no-such-xtask\" not in raw or verdict.split(\":\")[1] not in (\"PASS\", \"REFUSE\"):\n 158│            raise AssertionError(f\"cold-pool bootstrap: raw={raw!r} verdict={verdict!r}\")\n 159│        print(f\"PASS cold-pool bootstrap: direct reading named the missing meter and rendered {verdict.split(':')[1]}\")\n 160│\n 161│\n*162│# [impl->REQ-DISK-FLOOR-PREFLIGHT]\n 163│def floor_verdict(raw, code):\n 164│    \"\"\"Render GiB from xtask's own byte reading, never a second disk probe.\"\"\"\n 165│    fields = dict(re.findall(r\"\\b(free_bytes|floor_bytes)=(\\d+)\", raw))\n 166│    if len(fields) != 2:\n*167│        return False, f\"DISK_FLOOR:REFUSE: xtask exit={code}; no complete disk reading\"\n 168│    free, floor = int(fields[\"free_bytes\"]), int(fields[\"floor_bytes\"])\n 169│    admitted = code == 0 and free >= floor\n 170│    verdict = \"PASS\" if admitted else \"REFUSE\"\n 171│    return admitted, (\n*172│        f\"DISK_FLOOR:{verdict}: free_gib={free / (1 << 30):.2f} \"\n 173│        f\"floor_gib={floor / (1 << 30):.2f} xtask_exit={code}\"\n 174│    )\n 175│\n    │...\n 184│    return (\n*185│        f\"DISK_FLOOR:BOOTSTRAP: prebuilt xtask absent ({xtask}); direct free-space \"\n 186│        f\"read free_bytes={free} floor_bytes={FLOOR_BYTES} label=ws272-w0\\n\"\n 187│    )\n 188│\n 189│\n*190│def disk_floor(root, output, name, xtask):\n 191│    # Use a prebuilt xtask: compiling the meter before its first reading would\n 192│    # make the very first build unguarded. --xtask permits a bootstrap binary;\n 193│    # a cold pool (no meter at all) takes one direct reading, named as such.\n    │...\n 198│            result = subprocess.run(\n*199│                [str(xtask), \"disk-floor\", \"--path\", str(root), \"--label\", \"ws272-w0\"],\n 200│                cwd=root, capture_output=True, text=True,\n 201│            )\n*202│            raw, code = result.stdout + result.stderr, result.returncode\n 203│        except OSError as error:\n 204│            raw, code = f\"Cannot run prebuilt xtask {xtask}: {error}\\n\", 127\n 205│    admitted, verdict = floor_verdict(raw, code)\n    │...\n 252│    if guarded:\n*253│        if not preflight() or not disk_floor(root, output, name, xtask):\n 254│            (output / f\"{name}.exit\").write_text(\"75\\n\", encoding=\"utf-8\")\n 255│            return False\n 256│    with (output / f\"{name}.raw\").open(\"wb\") as log:\n    │...\n 258│            result = subprocess.run(argv, cwd=root, stdout=log, stderr=subprocess.STDOUT, env=BATTERY_ENV)\n*259│            code = result.returncode\n 260│        except OSError as error:\n 261│            log.write(str(error).encode(\"utf-8\"))\n 262│            code = 127\n    │...\n 279│    parser.add_argument(\"--xtask\", type=Path,\n*280│                        help=\"prebuilt disk-floor meter; defaults to this lane's debug xtask\")\n 281│    args = parser.parse_args()\n 282│    if args.self_test:\n 283│        self_test()\n## ws272-w1.py\n  23│re-ran this driver beside the intended one, two suites interleaved one\n *24│nextest.raw (two Summary lines), and the gater voided the window.\n  25│\n  26│The battery runs under a SCRUBBED environment: the perch identity variables an\n  27│agent's shell carries (SPT_ENDPOINT_ID and its companions) are dropped from\n    │...\n  44│ACTIVE_STATES = (\"in_progress\", \"queued\", \"waiting\", \"pending\", \"requested\")\n *45│# The same floor xtask disk-floor enforces (32 GiB); the bootstrap reading\n  46│# below must never be more lenient than the meter it stands in for.\n  47│FLOOR_BYTES = 32 << 30\n  48│# The perch identity a live agent's shell carries. A battery must never look\n    │...\n  93│    result = subprocess.run([\"gh\", \"api\", WORKFLOW + suffix], capture_output=True, text=True)\n *94│    if result.returncode:\n *95│        raise RuntimeError(f\"gh api exited {result.returncode}: {result.stderr.strip()}\")\n  96│    return json.loads(result.stdout)\n  97│\n  98│\n    │...\n 144│            first.close()\n*145│        if held.returncode != 4 or f\"pid {os.getpid()}\" not in held.stdout:\n*146│            raise AssertionError(f\"lane lock: second driver not refused naming the holder: rc={held.returncode} \"\n 147│                                 f\"out={held.stdout!r} err={held.stderr!r}\")\n 148│        freed = subprocess.run(probe, capture_output=True, text=True)\n*149│        if freed.returncode != 0:\n*150│            raise AssertionError(f\"lane lock: not released with its holder: rc={freed.returncode} err={freed.stderr!r}\")\n 151│        print(\"PASS lane lock: second driver refused while the holder lives, free once it exits\")\n 152│    tainted = {\"OWL_SESSION_ID\": \"owl\", \"SPT_AGENT_ID\": \"a\", \"SPT_ENDPOINT_ID\": \"agent\", \"SPT_HOST_PID\": \"1\", \"PATH\": \"keep\", \"SPT_HOME\": \"keep\"}\n 153│    env, dropped = battery_env(tainted)\n    │...\n 162│        admitted, verdict = floor_verdict(raw, 0)\n*163│        if \"DISK_FLOOR:BOOTSTRAP\" not in raw or \"no-such-xtask\" not in raw or verdict.split(\":\")[1] not in (\"PASS\", \"REFUSE\"):\n 164│            raise AssertionError(f\"cold-pool bootstrap: raw={raw!r} verdict={verdict!r}\")\n 165│        print(f\"PASS cold-pool bootstrap: direct reading named the missing meter and rendered {verdict.split(':')[1]}\")\n 166│\n 167│\n*168│# [impl->REQ-DISK-FLOOR-PREFLIGHT]\n 169│def floor_verdict(raw, code):\n 170│    \"\"\"Render GiB from xtask's own byte reading, never a second disk probe.\"\"\"\n 171│    fields = dict(re.findall(r\"\\b(free_bytes|floor_bytes)=(\\d+)\", raw))\n 172│    if len(fields) != 2:\n*173│        return False, f\"DISK_FLOOR:REFUSE: xtask exit={code}; no complete disk reading\"\n 174│    free, floor = int(fields[\"free_bytes\"]), int(fields[\"floor_bytes\"])\n 175│    admitted = code == 0 and free >= floor\n 176│    verdict = \"PASS\" if admitted else \"REFUSE\"\n 177│    return admitted, (\n*178│        f\"DISK_FLOOR:{verdict}: free_gib={free / (1 << 30):.2f} \"\n 179│        f\"floor_gib={floor / (1 << 30):.2f} xtask_exit={code}\"\n 180│    )\n 181│\n    │...\n 190│    return (\n*191│        f\"DISK_FLOOR:BOOTSTRAP: prebuilt xtask absent ({xtask}); direct free-space \"\n 192│        f\"read free_bytes={free} floor_bytes={FLOOR_BYTES} label=ws272-w1\\n\"\n 193│    )\n 194│\n 195│\n*196│def disk_floor(root, output, name, xtask):\n 197│    # Use a prebuilt xtask: compiling the meter before its first reading would\n 198│    # make the very first build unguarded. --xtask permits a bootstrap binary;\n 199│    # a cold pool (no meter at all) takes one direct reading, named as such.\n    │...\n 204│            result = subprocess.run(\n*205│                [str(xtask), \"disk-floor\", \"--path\", str(root), \"--label\", \"ws272-w1\"],\n 206│                cwd=root, capture_output=True, text=True,\n 207│            )\n*208│            raw, code = result.stdout + result.stderr, result.returncode\n 209│        except OSError as error:\n 210│            raw, code = f\"Cannot run prebuilt xtask {xtask}: {error}\\n\", 127\n 211│    admitted, verdict = floor_verdict(raw, code)\n    │...\n 258│    if guarded:\n*259│        if not preflight() or not disk_floor(root, output, name, xtask):\n 260│            (output / f\"{name}.exit\").write_text(\"75\\n\", encoding=\"utf-8\")\n 261│            return False\n 262│    with (output / f\"{name}.raw\").open(\"wb\") as log:\n    │...\n 264│            result = subprocess.run(argv, cwd=root, stdout=log, stderr=subprocess.STDOUT, env=BATTERY_ENV)\n*265│            code = result.returncode\n 266│        except OSError as error:\n 267│            log.write(str(error).encode(\"utf-8\"))\n 268│            code = 127\n    │...\n 285│    parser.add_argument(\"--xtask\", type=Path,\n*286│                        help=\"prebuilt disk-floor meter; defaults to this lane's debug xtask\")\n 287│    args = parser.parse_args()\n 288│    if args.self_test:\n 289│        self_test()\n    │...\n 322│                     \"-p\", \"spt-runtime\", \"-p\", \"spt-net\", \"-p\", \"spt-daemon\", \"-p\", \"spt\"], True),\n*323│        # The two-host bin ALONE (its own Summary line; env-gated, a silent\n 324│        # no-op without SPT_TWO_HOST=1 + a role).\n 325│        (\"twohost_web\", [\"cargo\", \"nextest\", \"run\", \"--no-fail-fast\", \"-p\", \"spt-daemon\",\n 326│                         \"--test\", \"twohost_web\"], True),\n## ws272-w2.py\n  30│re-ran this driver beside the intended one, two suites interleaved one\n *31│nextest.raw (two Summary lines), and the gater voided the window.\n  32│\n  33│The battery runs under a SCRUBBED environment: the perch identity variables an\n  34│agent's shell carries (SPT_ENDPOINT_ID and its companions) are dropped from\n    │...\n  51│ACTIVE_STATES = (\"in_progress\", \"queued\", \"waiting\", \"pending\", \"requested\")\n *52│# The same floor xtask disk-floor enforces (32 GiB); the bootstrap reading\n  53│# below must never be more lenient than the meter it stands in for.\n  54│FLOOR_BYTES = 32 << 30\n  55│# The perch identity a live agent's shell carries. A battery must never look\n    │...\n 100│    result = subprocess.run([\"gh\", \"api\", WORKFLOW + suffix], capture_output=True, text=True)\n*101│    if result.returncode:\n*102│        raise RuntimeError(f\"gh api exited {result.returncode}: {result.stderr.strip()}\")\n 103│    return json.loads(result.stdout)\n 104│\n 105│\n    │...\n 151│            first.close()\n*152│        if held.returncode != 4 or f\"pid {os.getpid()}\" not in held.stdout:\n*153│            raise AssertionError(f\"lane lock: second driver not refused naming the holder: rc={held.returncode} \"\n 154│                                 f\"out={held.stdout!r} err={held.stderr!r}\")\n 155│        freed = subprocess.run(probe, capture_output=True, text=True)\n*156│        if freed.returncode != 0:\n*157│            raise AssertionError(f\"lane lock: not released with its holder: rc={freed.returncode} err={freed.stderr!r}\")\n 158│        print(\"PASS lane lock: second driver refused while the holder lives, free once it exits\")\n 159│    tainted = {\"OWL_SESSION_ID\": \"owl\", \"SPT_AGENT_ID\": \"a\", \"SPT_ENDPOINT_ID\": \"agent\", \"SPT_HOST_PID\": \"1\", \"PATH\": \"keep\", \"SPT_HOME\": \"keep\"}\n 160│    env, dropped = battery_env(tainted)\n    │...\n 169│        admitted, verdict = floor_verdict(raw, 0)\n*170│        if \"DISK_FLOOR:BOOTSTRAP\" not in raw or \"no-such-xtask\" not in raw or verdict.split(\":\")[1] not in (\"PASS\", \"REFUSE\"):\n 171│            raise AssertionError(f\"cold-pool bootstrap: raw={raw!r} verdict={verdict!r}\")\n 172│        print(f\"PASS cold-pool bootstrap: direct reading named the missing meter and rendered {verdict.split(':')[1]}\")\n 173│\n 174│\n*175│# [impl->REQ-DISK-FLOOR-PREFLIGHT]\n 176│def floor_verdict(raw, code):\n 177│    \"\"\"Render GiB from xtask's own byte reading, never a second disk probe.\"\"\"\n 178│    fields = dict(re.findall(r\"\\b(free_bytes|floor_bytes)=(\\d+)\", raw))\n 179│    if len(fields) != 2:\n*180│        return False, f\"DISK_FLOOR:REFUSE: xtask exit={code}; no complete disk reading\"\n 181│    free, floor = int(fields[\"free_bytes\"]), int(fields[\"floor_bytes\"])\n 182│    admitted = code == 0 and free >= floor\n 183│    verdict = \"PASS\" if admitted else \"REFUSE\"\n 184│    return admitted, (\n*185│        f\"DISK_FLOOR:{verdict}: free_gib={free / (1 << 30):.2f} \"\n 186│        f\"floor_gib={floor / (1 << 30):.2f} xtask_exit={code}\"\n 187│    )\n 188│\n    │...\n 197│    return (\n*198│        f\"DISK_FLOOR:BOOTSTRAP: prebuilt xtask absent ({xtask}); direct free-space \"\n 199│        f\"read free_bytes={free} floor_bytes={FLOOR_BYTES} label=ws272-w2\\n\"\n 200│    )\n 201│\n 202│\n*203│def disk_floor(root, output, name, xtask):\n 204│    # Use a prebuilt xtask: compiling the meter before its first reading would\n 205│    # make the very first build unguarded. --xtask permits a bootstrap binary;\n 206│    # a cold pool (no meter at all) takes one direct reading, named as such.\n    │...\n 211│            result = subprocess.run(\n*212│                [str(xtask), \"disk-floor\", \"--path\", str(root), \"--label\", \"ws272-w2\"],\n 213│                cwd=root, capture_output=True, text=True,\n 214│            )\n*215│            raw, code = result.stdout + result.stderr, result.returncode\n 216│        except OSError as error:\n 217│            raw, code = f\"Cannot run prebuilt xtask {xtask}: {error}\\n\", 127\n 218│    admitted, verdict = floor_verdict(raw, code)\n    │...\n 292│    raw = (output / \"population.raw\").read_text(encoding=\"utf-8\", errors=\"replace\")\n*293│    # COUNT THE ROWS THEMSELVES, never a summary phrase: `nextest list` prints\n 294│    # one \"<package> <test::path>\" line per selected test and no total, so a\n 295│    # meter keyed on prose reads zero and refuses a healthy battery. Measured\n 296│    # against a real listing (1673 selected) after the first version did exactly\n    │...\n 311│    if guarded:\n*312│        if not preflight() or not disk_floor(root, output, name, xtask):\n 313│            (output / f\"{name}.exit\").write_text(\"75\\n\", encoding=\"utf-8\")\n 314│            return False\n 315│    with (output / f\"{name}.raw\").open(\"wb\") as log:\n    │...\n 317│            result = subprocess.run(argv, cwd=root, stdout=log, stderr=subprocess.STDOUT, env=BATTERY_ENV)\n*318│            code = result.returncode\n 319│        except OSError as error:\n 320│            log.write(str(error).encode(\"utf-8\"))\n 321│            code = 127\n    │...\n 338│    parser.add_argument(\"--xtask\", type=Path,\n*339│                        help=\"prebuilt disk-floor meter; defaults to this lane's debug xtask\")\n 340│    args = parser.parse_args()\n 341│    if args.self_test:\n 342│        self_test()"},"isError":false,"timestamp":1789483704159}}
{"type":"message","id":"9fa0e05f","parentId":"470ef22c","timestamp":"2026-09-15T14:48:24.247Z","message":{"role":"toolResult","toolCallId":"call_p4qDT4yqQbN9bOxbREdQnU2x|fc_043a862a419f59ae016aa95ab80e7487d2892812000648f9c7","toolName":"grep","content":[{"type":"text","text":"# .worktrees/hertz-ir86-disk-delta/\n\n## .github/ci/\n### find-cwd-holders.ps1\n 18|# \"no conhosts\" is not an all-clear (KNOWN-HAZARDS 5.18). A `conhost.exe\n*19|# --headless …` is different: that is a ConPTY host, it INHERITS the cwd of\n 20|# whoever created the pseudoconsole, and it can be the sole holder — the case\n 21|# that pinned a BAROMETER W4 worktree. Read the command line, not just the name.\n 22|#\n...\n 87|  if ($cwd) {\n*88|    [pscustomobject]@{ Pid = $p.Id; Name = $p.ProcessName; Cwd = $cwd\n 89|                       Started = $(try { $p.StartTime } catch { $null }) }\n 90|  }\n 91|}\n...\n 97|\n*98|$rows | Sort-Object Cwd | Format-Table -AutoSize -Wrap\n 99|\n 100|# Report the DENOMINATOR, not just the hits: \"0 rows\" from a filter and \"0 rows\"\n 101|# because nothing could be opened are the same output and very different facts.\n\n## crates/\n\n### xtask/src/\n#### binnames.rs\n*1|//! Duplicate bin-name gate (IR-58's trigger condition).\n 2|//!\n 3|//! Two packages that declare a bin of the SAME name collide on the shared\n 4|//! `target/<profile>/` output filename and clobber each other, after which a\n...\n 56|// [impl->REQ-BUILD-UNIQUE-BIN-NAMES]\n*57|pub fn duplicate_bin_names(targets: &[(String, String)]) -> Vec<Collision> {\n 58|    let mut by_name: BTreeMap<&str, Vec<String>> = BTreeMap::new();\n 59|    for (package, bin) in targets {\n 60|        by_name.entry(bin.as_str()).or_default().push(package.clone());\n...\n 128|        ];\n*129|        let hits = duplicate_bin_names(&targets);\n 130|        assert_eq!(hits.len(), 1, \"one collision, not three: {hits:?}\");\n 131|        assert_eq!(hits[0].bin, \"translate_proof_fixture\");\n 132|        assert_eq!(hits[0].packages, vec![\"spt\", \"spt-daemon\"]);\n...\n 144|        ];\n*145|        assert!(duplicate_bin_names(&targets).is_empty());\n 146|    }\n 147|\n 148|    // [unit->REQ-BUILD-UNIQUE-BIN-NAMES] one package declaring the same bin\n...\n 156|        ];\n*157|        assert!(duplicate_bin_names(&targets).is_empty());\n 158|    }\n 159|\n 160|    // [unit->REQ-BUILD-UNIQUE-BIN-NAMES] the REAL workspace is clean, asserted\n...\n 164|    #[test]\n*165|    fn the_workspace_declares_no_duplicate_bin_names() {\n 166|        let root = std::path::Path::new(env!(\"CARGO_MANIFEST_DIR\"))\n 167|            .parent()\n 168|            .and_then(|p| p.parent())\n...\n 175|        );\n*176|        let hits = duplicate_bin_names(&targets);\n*177|        assert!(hits.is_empty(), \"duplicate bin names: {hits:?}\");\n 178|    }\n 179|}\n#### main.rs\n 784|    }\n*785|    let hits = binnames::duplicate_bin_names(&targets);\n 786|    if hits.is_empty() {\n 787|        return;\n 788|    }\n*789|    eprintln!(\"xtask check: FAILED — duplicate bin name(s) across workspace packages\");\n 790|    for c in &hits {\n 791|        eprintln!(\"  {} declared by: {}\", c.bin, c.packages.join(\", \"));\n 792|    }\n...\n 3294|/// reboot: a recycled pid would read as a live lane forever.\n*3295|fn pool_claim(args: &[String]) {\n 3296|    let pool = flag(args, \"--pool\").unwrap_or_else(|| {\n 3297|        eprintln!(\n 3298|            \"usage: xtask pool-claim --pool <dir> --label <lane> \\\n\n### spt-store/src/\n#### info.rs\n 501|    // Hold the stable per-perch sentinel across the whole read→mutate→write RMW.\n*502|    let _lock = lock_perch_sentinel(perch_path)?;\n 503|    let mut rec = read_info(perch_path).ok_or_else(|| {\n 504|        std::io::Error::new(std::io::ErrorKind::NotFound, \"info.json absent or unreadable\")\n 505|    })?;\n...\n 876|/// every write). The perch directory must already exist.\n*877|fn lock_perch_sentinel(perch_path: &Path) -> std::io::Result<std::fs::File> {\n 878|    use fs2::FileExt;\n 879|    let lock = std::fs::OpenOptions::new()\n 880|        .create(true)\n...\n 915|pub fn write_info(perch_path: &Path, info: &InfoJson) -> std::io::Result<()> {\n*916|    let _lock = lock_perch_sentinel(perch_path)?;\n 917|    write_info_unlocked(perch_path, info)\n 918|}\n 919|\n...\n 987|) -> std::io::Result<Result<InfoJson, E>> {\n*988|    let _lock = lock_perch_sentinel(perch_path)?;\n 989|    let prior = read_info(perch_path);\n 990|    match build(prior) {\n 991|        // Return the written record so the caller can use it (e.g. the ledger cwd)\n...\n 1020|// [impl->REQ-HAZARD-INFO-JSON-TORN-READ]\n*1021|pub fn read_pid(perch_path: &Path) -> Option<u32> {\n 1022|    let path = perch_path.join(\"info.json\");\n 1023|    for _ in 0..READ_ATTEMPTS {\n 1024|        if let Ok(content) = std::fs::read_to_string(&path) {\n...\n 1924|    #[test]\n*1925|    fn read_pid_tolerates_schema_minimal() {\n 1926|        let d = perch();\n 1927|        atomic_write_string(&d.path().join(\"info.json\"), r#\"{\"pid\": 1234}\"#).unwrap();\n 1928|        assert_eq!(read_pid(d.path()), Some(1234));\n...\n 1983|    // [unit->REQ-HAZARD-INFO-RMW-LOST-UPDATE] a locked RMW (the daemon's status stamp)\n*1984|    // racing a full whole-record write (bind establishing the perch) must NEVER lose the\n 1985|    // full write's fields. The lost update: a record carrying the stamp (status=online)\n 1986|    // while MISSING the bind fields (state=live_agent) — the RMW read a pre-bind snapshot,\n 1987|    // the bind wrote the full record, then the RMW wrote its stale snapshot back + the\n\n### spt-poolguard/src/\n#### lib.rs\n 366|// [impl->REQ-POOL-LANE-IDENTITY]\n*367|pub fn git_lane_state(repo: &Path, claim: &LaneClaim) -> LaneState {\n 368|    // THE REPO-IDENTITY WITNESS, FIRST, AND EVERY ANSWER HANGS OFF IT. Only a\n 369|    // claimed base object present HERE can show that the repository being read\n 370|    // is the one the lane lives in. Without it — a pre-identity claim, a branch\n\n### spt/src/\n#### main.rs\n 128|        .name(\"spt-cli\".to_string())\n*129|        .stack_size(CLI_STACK_BYTES)\n 130|        .spawn(move || {\n 131|            let code = f();\n 132|            std::process::exit(code);\n...\n 248|    // it in-process would end the test binary, not the assertion. That arm's\n*249|    // evidence lives in `tests/cli_stack_smoke.rs`, which drives the REAL\n 250|    // binary: `--version` and `--help` cover a zero return with output, and the\n 251|    // retired-verb refusal covers a NONZERO code arriving by return. Between\n 252|    // them the two exit shapes this function can produce are both witnessed;"}],"details":{"scopePath":".worktrees/hertz-ir86-disk-delta/.github/ci/find-cwd-holders.ps1, .worktrees/hertz-ir86-disk-delta/crates/xtask/src, .worktrees/hertz-ir86-disk-delta/crates/spt-store/src/info.rs, .worktrees/hertz-ir86-disk-delta/crates/spt-poolguard/src/lib.rs, .worktrees/hertz-ir86-disk-delta/crates/spt/tests/common/reap.rs, .worktrees/hertz-ir86-disk-delta/crates/spt/src/main.rs","searchPath":"C:\\Users\\decid\\Documents\\projects\\spt-core\\.worktrees\\hertz-ir86-disk-delta","cwd":"C:\\Users\\decid\\Documents\\projects\\spt-core","matchCount":24,"fileCount":6,"files":[".worktrees/hertz-ir86-disk-delta/.github/ci/find-cwd-holders.ps1",".worktrees/hertz-ir86-disk-delta/crates/xtask/src/binnames.rs",".worktrees/hertz-ir86-disk-delta/crates/xtask/src/main.rs",".worktrees/hertz-ir86-disk-delta/crates/spt-store/src/info.rs",".worktrees/hertz-ir86-disk-delta/crates/spt-poolguard/src/lib.rs",".worktrees/hertz-ir86-disk-delta/crates/spt/src/main.rs"],"fileMatches":[{"path":".worktrees/hertz-ir86-disk-delta/.github/ci/find-cwd-holders.ps1","count":3},{"path":".worktrees/hertz-ir86-disk-delta/crates/xtask/src/binnames.rs","count":8},{"path":".worktrees/hertz-ir86-disk-delta/crates/xtask/src/main.rs","count":3},{"path":".worktrees/hertz-ir86-disk-delta/crates/spt-store/src/info.rs","count":7},{"path":".worktrees/hertz-ir86-disk-delta/crates/spt-poolguard/src/lib.rs","count":1},{"path":".worktrees/hertz-ir86-disk-delta/crates/spt/src/main.rs","count":2}],"truncated":false,"displayContent":"# .worktrees/hertz-ir86-disk-delta/\n\n## .github/ci/\n### find-cwd-holders.ps1\n  18│# \"no conhosts\" is not an all-clear (KNOWN-HAZARDS 5.18). A `conhost.exe\n *19│# --headless …` is different: that is a ConPTY host, it INHERITS the cwd of\n  20│# whoever created the pseudoconsole, and it can be the sole holder — the case\n  21│# that pinned a BAROMETER W4 worktree. Read the command line, not just the name.\n  22│#\n    │...\n  87│  if ($cwd) {\n *88│    [pscustomobject]@{ Pid = $p.Id; Name = $p.ProcessName; Cwd = $cwd\n  89│                       Started = $(try { $p.StartTime } catch { $null }) }\n  90│  }\n  91│}\n    │...\n  97│\n *98│$rows | Sort-Object Cwd | Format-Table -AutoSize -Wrap\n  99│\n 100│# Report the DENOMINATOR, not just the hits: \"0 rows\" from a filter and \"0 rows\"\n 101│# because nothing could be opened are the same output and very different facts.\n\n## crates/\n\n### xtask/src/\n#### binnames.rs\n  *1│//! Duplicate bin-name gate (IR-58's trigger condition).\n   2│//!\n   3│//! Two packages that declare a bin of the SAME name collide on the shared\n   4│//! `target/<profile>/` output filename and clobber each other, after which a\n    │...\n  56│// [impl->REQ-BUILD-UNIQUE-BIN-NAMES]\n *57│pub fn duplicate_bin_names(targets: &[(String, String)]) -> Vec<Collision> {\n  58│    let mut by_name: BTreeMap<&str, Vec<String>> = BTreeMap::new();\n  59│    for (package, bin) in targets {\n  60│        by_name.entry(bin.as_str()).or_default().push(package.clone());\n    │...\n 128│        ];\n*129│        let hits = duplicate_bin_names(&targets);\n 130│        assert_eq!(hits.len(), 1, \"one collision, not three: {hits:?}\");\n 131│        assert_eq!(hits[0].bin, \"translate_proof_fixture\");\n 132│        assert_eq!(hits[0].packages, vec![\"spt\", \"spt-daemon\"]);\n    │...\n 144│        ];\n*145│        assert!(duplicate_bin_names(&targets).is_empty());\n 146│    }\n 147│\n 148│    // [unit->REQ-BUILD-UNIQUE-BIN-NAMES] one package declaring the same bin\n    │...\n 156│        ];\n*157│        assert!(duplicate_bin_names(&targets).is_empty());\n 158│    }\n 159│\n 160│    // [unit->REQ-BUILD-UNIQUE-BIN-NAMES] the REAL workspace is clean, asserted\n    │...\n 164│    #[test]\n*165│    fn the_workspace_declares_no_duplicate_bin_names() {\n 166│        let root = std::path::Path::new(env!(\"CARGO_MANIFEST_DIR\"))\n 167│            .parent()\n 168│            .and_then(|p| p.parent())\n    │...\n 175│        );\n*176│        let hits = duplicate_bin_names(&targets);\n*177│        assert!(hits.is_empty(), \"duplicate bin names: {hits:?}\");\n 178│    }\n 179│}\n#### main.rs\n  784│    }\n *785│    let hits = binnames::duplicate_bin_names(&targets);\n  786│    if hits.is_empty() {\n  787│        return;\n  788│    }\n *789│    eprintln!(\"xtask check: FAILED — duplicate bin name(s) across workspace packages\");\n  790│    for c in &hits {\n  791│        eprintln!(\"  {} declared by: {}\", c.bin, c.packages.join(\", \"));\n  792│    }\n     │...\n 3294│/// reboot: a recycled pid would read as a live lane forever.\n*3295│fn pool_claim(args: &[String]) {\n 3296│    let pool = flag(args, \"--pool\").unwrap_or_else(|| {\n 3297│        eprintln!(\n 3298│            \"usage: xtask pool-claim --pool <dir> --label <lane> \\\n\n### spt-store/src/\n#### info.rs\n  501│    // Hold the stable per-perch sentinel across the whole read→mutate→write RMW.\n *502│    let _lock = lock_perch_sentinel(perch_path)?;\n  503│    let mut rec = read_info(perch_path).ok_or_else(|| {\n  504│        std::io::Error::new(std::io::ErrorKind::NotFound, \"info.json absent or unreadable\")\n  505│    })?;\n     │...\n  876│/// every write). The perch directory must already exist.\n *877│fn lock_perch_sentinel(perch_path: &Path) -> std::io::Result<std::fs::File> {\n  878│    use fs2::FileExt;\n  879│    let lock = std::fs::OpenOptions::new()\n  880│        .create(true)\n     │...\n  915│pub fn write_info(perch_path: &Path, info: &InfoJson) -> std::io::Result<()> {\n *916│    let _lock = lock_perch_sentinel(perch_path)?;\n  917│    write_info_unlocked(perch_path, info)\n  918│}\n  919│\n     │...\n  987│) -> std::io::Result<Result<InfoJson, E>> {\n *988│    let _lock = lock_perch_sentinel(perch_path)?;\n  989│    let prior = read_info(perch_path);\n  990│    match build(prior) {\n  991│        // Return the written record so the caller can use it (e.g. the ledger cwd)\n     │...\n 1020│// [impl->REQ-HAZARD-INFO-JSON-TORN-READ]\n*1021│pub fn read_pid(perch_path: &Path) -> Option<u32> {\n 1022│    let path = perch_path.join(\"info.json\");\n 1023│    for _ in 0..READ_ATTEMPTS {\n 1024│        if let Ok(content) = std::fs::read_to_string(&path) {\n     │...\n 1924│    #[test]\n*1925│    fn read_pid_tolerates_schema_minimal() {\n 1926│        let d = perch();\n 1927│        atomic_write_string(&d.path().join(\"info.json\"), r#\"{\"pid\": 1234}\"#).unwrap();\n 1928│        assert_eq!(read_pid(d.path()), Some(1234));\n     │...\n 1983│    // [unit->REQ-HAZARD-INFO-RMW-LOST-UPDATE] a locked RMW (the daemon's status stamp)\n*1984│    // racing a full whole-record write (bind establishing the perch) must NEVER lose the\n 1985│    // full write's fields. The lost update: a record carrying the stamp (status=online)\n 1986│    // while MISSING the bind fields (state=live_agent) — the RMW read a pre-bind snapshot,\n 1987│    // the bind wrote the full record, then the RMW wrote its stale snapshot back + the\n\n### spt-poolguard/src/\n#### lib.rs\n 366│// [impl->REQ-POOL-LANE-IDENTITY]\n*367│pub fn git_lane_state(repo: &Path, claim: &LaneClaim) -> LaneState {\n 368│    // THE REPO-IDENTITY WITNESS, FIRST, AND EVERY ANSWER HANGS OFF IT. Only a\n 369│    // claimed base object present HERE can show that the repository being read\n 370│    // is the one the lane lives in. Without it — a pre-identity claim, a branch\n\n### spt/src/\n#### main.rs\n 128│        .name(\"spt-cli\".to_string())\n*129│        .stack_size(CLI_STACK_BYTES)\n 130│        .spawn(move || {\n 131│            let code = f();\n 132│            std::process::exit(code);\n    │...\n 248│    // it in-process would end the test binary, not the assertion. That arm's\n*249│    // evidence lives in `tests/cli_stack_smoke.rs`, which drives the REAL\n 250│    // binary: `--version` and `--help` cover a zero return with output, and the\n 251│    // retired-verb refusal covers a NONZERO code arriving by return. Between\n 252│    // them the two exit shapes this function can produce are both witnessed;"},"isError":false,"timestamp":1789483704246}}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_IooMl8gf37osWbJQfmroMyDA|fc_043a862a419f59ae016aa95ac62a1c87d290fc7add991e5a7f","toolName":"read","startedAt":"2026-09-15T14:48:38.268Z","args":{"path":".worktrees/hertz-ir86-disk-delta/crates/xtask/src/main.rs:230-332,770-802,3295-3395:raw"},"intent":"Reading implemented metadata candidates"},"id":"e468820f","parentId":"9fa0e05f","timestamp":"2026-09-15T14:48:38.268Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_fqJwWI3SLxD9aUZqpVtfjmhF|fc_043a862a419f59ae016aa95ac62a3487d299e15b6da6771ebf","toolName":"read","startedAt":"2026-09-15T14:48:38.269Z","args":{"path":".worktrees/hertz-ir86-disk-delta/crates/spt-store/src/info.rs:860-919:raw"},"intent":"Reading remaining comment and guard"},"id":"47d04760","parentId":"e468820f","timestamp":"2026-09-15T14:48:38.269Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_lLqFr89hvEsRVEKsQq5F2rsd|fc_043a862a419f59ae016aa95ac62a3c87d2ac6f6b7e058ea3df","toolName":"read","startedAt":"2026-09-15T14:48:38.269Z","args":{"path":".worktrees/hertz-ir86-disk-delta/crates/spt/tests/common/reap.rs:45-95:raw"},"intent":"Reading existing breadcrumb classification"},"id":"3e1d9ac2","parentId":"47d04760","timestamp":"2026-09-15T14:48:38.269Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_qoMaqgFf6OtSfS4t1eeYF3l4|fc_043a862a419f59ae016aa95ac62a4487d2989cc02cebeea02f","toolName":"read","startedAt":"2026-09-15T14:48:38.269Z","args":{"path":".worktrees/hertz-ir86-disk-delta/crates/xtask/src/binnames.rs:1-110:raw"},"intent":"Reading metadata based bin enumeration"},"id":"7741cf62","parentId":"3e1d9ac2","timestamp":"2026-09-15T14:48:38.269Z"}
{"type":"message","id":"b828511d","parentId":"7741cf62","timestamp":"2026-09-15T14:48:38.269Z","message":{"role":"assistant","content":[{"type":"thinking","thinking":"**Notifying tests on receipts**"},{"type":"toolCall","id":"call_IooMl8gf37osWbJQfmroMyDA|fc_043a862a419f59ae016aa95ac62a1c87d290fc7add991e5a7f","name":"read","arguments":{"i":"Reading implemented metadata candidates","path":".worktrees/hertz-ir86-disk-delta/crates/xtask/src/main.rs:230-332,770-802,3295-3395:raw"},"intent":"Reading implemented metadata candidates"},{"type":"toolCall","id":"call_fqJwWI3SLxD9aUZqpVtfjmhF|fc_043a862a419f59ae016aa95ac62a3487d299e15b6da6771ebf","name":"read","arguments":{"i":"Reading remaining comment and guard","path":".worktrees/hertz-ir86-disk-delta/crates/spt-store/src/info.rs:860-919:raw"},"intent":"Reading remaining comment and guard"},{"type":"toolCall","id":"call_lLqFr89hvEsRVEKsQq5F2rsd|fc_043a862a419f59ae016aa95ac62a3c87d2ac6f6b7e058ea3df","name":"read","arguments":{"i":"Reading existing breadcrumb classification","path":".worktrees/hertz-ir86-disk-delta/crates/spt/tests/common/reap.rs:45-95:raw"},"intent":"Reading existing breadcrumb classification"},{"type":"toolCall","id":"call_qoMaqgFf6OtSfS4t1eeYF3l4|fc_043a862a419f59ae016aa95ac62a4487d2989cc02cebeea02f","name":"read","arguments":{"i":"Reading metadata based bin enumeration","path":".worktrees/hertz-ir86-disk-delta/crates/xtask/src/binnames.rs:1-110:raw"},"intent":"Reading metadata based bin enumeration"},{"type":"toolCall","id":"call_xXmJ6WYKFODKvKdtYHszhYXh|fc_043a862a419f59ae016aa95ac62a4c87d28551faf4aad13ffc","name":"read","arguments":{"i":"Reading notification scope contract","path":".worktrees/hertz-ir86-disk-delta/.github/ci/ci-notify.sh:1-125:raw"},"intent":"Reading notification scope contract"},{"type":"toolCall","id":"call_0dFwMdwurXOJ4GOUa2DCjbMl|fc_043a862a419f59ae016aa95ac62a5887d2b37d403d0833fd2b","name":"grep","arguments":{"i":"Locating closure receipts and adoption","pattern":"IR-(32|37|40|44|47|58)|ci-notify-selftest|traceable-reqs.sh|binnames_check|check_bin_names","path":".worktrees/hertz-ir86-disk-delta/CHANGELOG.md;.worktrees/hertz-ir86-disk-delta/docs/GOLDEN-CI.md;.worktrees/hertz-ir86-disk-delta/.github/workflows;.worktrees/hertz-ir86-disk-delta/crates/xtask/src/main.rs","case":null,"gitignore":false,"skip":null},"intent":"Locating closure receipts and adoption"}],"api":"openai-codex-responses","provider":"openai-codex","model":"gpt-6-astra","usage":{"input":16606,"output":413,"cacheRead":127616,"cacheWrite":0,"totalTokens":144635,"reasoningTokens":15,"cost":{"input":0.16606,"output":0.02065,"cacheRead":0.127616,"cacheWrite":0,"total":0.314326}},"stopReason":"toolUse","timestamp":1789483704280,"responseId":"resp_043a862a419f59ae016aa95ab87c6087d2a6831eeeea8811d4","providerPayload":{"type":"openaiResponsesHistory","provider":"openai-codex","dt":true,"items":[{"id":"rs_043a862a419f59ae016aa95ab9c64487d281c753fe9536dc1b","type":"reasoning","content":[],"encrypted_content":"gAAAAABqqVrGCUzdLF3oU0jtrg0Ve9vFx7yqvd2jG6bcCWDwjItTViSycwJutCW07QD7BbDlZ0erwsWpnuufl7F7jql497F5F3Ro86EAUKNyIsPCGju_zutXzeAGAddHqby5s3p2JAcRLxH-_I_lh63R6mVY6JL8dIOESC12uEtu8yDOBA7N5vxBwVp-AX0Ad1iT23rM6ngITZJqHampIWqAbIWjAaAM-4br17qjB5QyDGhmOvzId5oedj5TXLejYBT4L1LUkC3tUEgldeEELwpHHI39WG751ArY2tecoJbEBo8QxJZw0zhdSf6sRNJ5Vtt8V0GSg7P6J-w-Z1Ga8Fo0_2ps3A1engpQvzUxYFAOJ5psVXaOdaYagYMbc0VPhpng9TFHe-X-lW3BlG2QhBB3poXoIk2PHb46AInsWYfae-Q9irod7bQRe4mTEgtJCwDsKFYTomce2Az0krBZj1j64i-6CU3U0X0Gh3t_-OQoR289XzSGVe3Bf-Mshh_EFAgUmxppqlghP38xgTjs4BAsic_mKnaP6MpjWR-7rrQ8Qet3LlCm2nzuoHbMTwOuzoqn961wt4QEqGzLoxX13FORz6m-Nboga1lSYnh8KbplMhKoQlu8MFCBKQzCiQKobYAKZcD5uCkFHWz4Q1u2SmcsmkpZOAnjZctGeJlWC09BBcbqB45XyPnys-l6n-DYUoJ3xpDyfz4M82KjOwhH6JAXHMlSSrW4-pLLun-7ySLCMGvDLqGF547kIq6CLW6lgohZI4DJWAVmrQBO02VrDExkNiLHrdQGVfMb8Ur-z5oGR7ZnN0ir79vNv11rYdhcET_p0Ryk3MDyXMmKnOLScDe9GRGlQY5fSFJQEdbj-iuD-9eCuvEs5hkYf2SPzkCbV2aUlXbKqe9WXhbtvLzSAqo6mOMFaoqYjVQRyQ3mjgNtfvqTBQOvXthhsf8NFSkdut_CPnyL5c8UCUgASUGijqsHjMsP1TgBZsHiWb1URrfx4OC45ZwEuDQzyAJtdvgP-Sqxny_3MnVn4EOK1b6yNv-UBceWkRplgr_w_FE81OEPrO7Ak7NFgCIAQ3_tlM-18c4aHlzlrd-yMXI2aOJ32A1DgdqDjgiABifilTv4TVcJjCP5shNWjXgkP4YT39Cb18_ulG8t2XxLEY19Zkr40IJgDraOWxk90hW6wlQyBDyP9n7Ge1AsxQDupEuYbA1kwOq6d_u12k6kf0R5OglnfP-kNskxGxFUsvSJSGDaPmcRhGwqKjeP2z-2deHJWyi1c-sHRHda2yUobFfgoUeFE0loKAmlAroKkZSbNAIdAGaUQwsC6-KdWBMbH8xQOKKOXk1sYt5z6Mj_QoawJbagQcBBKodrQ6s7dQ==","internal_chat_message_metadata_passthrough":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"},"summary":[{"type":"summary_text","text":"**Notifying tests on receipts**"}],"metadata":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"}},{"id":"fc_043a862a419f59ae016aa95ac62a1c87d290fc7add991e5a7f","type":"function_call","status":"completed","arguments":"{\"i\":\"Reading implemented metadata candidates\",\"path\":\".worktrees/hertz-ir86-disk-delta/crates/xtask/src/main.rs:230-332,770-802,3295-3395:raw\"}","call_id":"call_IooMl8gf37osWbJQfmroMyDA","internal_chat_message_metadata_passthrough":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"},"name":"read","metadata":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"}},{"id":"fc_043a862a419f59ae016aa95ac62a3487d299e15b6da6771ebf","type":"function_call","status":"completed","arguments":"{\"i\":\"Reading remaining comment and guard\",\"path\":\".worktrees/hertz-ir86-disk-delta/crates/spt-store/src/info.rs:860-919:raw\"}","call_id":"call_fqJwWI3SLxD9aUZqpVtfjmhF","internal_chat_message_metadata_passthrough":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"},"name":"read","metadata":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"}},{"id":"fc_043a862a419f59ae016aa95ac62a3c87d2ac6f6b7e058ea3df","type":"function_call","status":"completed","arguments":"{\"i\":\"Reading existing breadcrumb classification\",\"path\":\".worktrees/hertz-ir86-disk-delta/crates/spt/tests/common/reap.rs:45-95:raw\"}","call_id":"call_lLqFr89hvEsRVEKsQq5F2rsd","internal_chat_message_metadata_passthrough":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"},"name":"read","metadata":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"}},{"id":"fc_043a862a419f59ae016aa95ac62a4487d2989cc02cebeea02f","type":"function_call","status":"completed","arguments":"{\"i\":\"Reading metadata based bin enumeration\",\"path\":\".worktrees/hertz-ir86-disk-delta/crates/xtask/src/binnames.rs:1-110:raw\"}","call_id":"call_qoMaqgFf6OtSfS4t1eeYF3l4","internal_chat_message_metadata_passthrough":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"},"name":"read","metadata":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"}},{"id":"fc_043a862a419f59ae016aa95ac62a4c87d28551faf4aad13ffc","type":"function_call","status":"completed","arguments":"{\"i\":\"Reading notification scope contract\",\"path\":\".worktrees/hertz-ir86-disk-delta/.github/ci/ci-notify.sh:1-125:raw\"}","call_id":"call_xXmJ6WYKFODKvKdtYHszhYXh","internal_chat_message_metadata_passthrough":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"},"name":"read","metadata":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"}},{"id":"fc_043a862a419f59ae016aa95ac62a5887d2b37d403d0833fd2b","type":"function_call","status":"completed","arguments":"{\"i\":\"Locating closure receipts and adoption\",\"pattern\":\"IR-(32|37|40|44|47|58)|ci-notify-selftest|traceable-reqs.sh|binnames_check|check_bin_names\",\"path\":\".worktrees/hertz-ir86-disk-delta/CHANGELOG.md;.worktrees/hertz-ir86-disk-delta/docs/GOLDEN-CI.md;.worktrees/hertz-ir86-disk-delta/.github/workflows;.worktrees/hertz-ir86-disk-delta/crates/xtask/src/main.rs\",\"case\":null,\"gitignore\":false,\"skip\":null}","call_id":"call_0dFwMdwurXOJ4GOUa2DCjbMl","internal_chat_message_metadata_passthrough":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"},"name":"grep","metadata":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"}}]},"duration":13982.638599991798,"ttft":1515.8937999904156,"completedAt":1789483718265,"contextSnapshot":{"promptTokens":144222,"nonMessageTokens":10342,"compactionEpoch":0}}}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_xXmJ6WYKFODKvKdtYHszhYXh|fc_043a862a419f59ae016aa95ac62a4c87d28551faf4aad13ffc","toolName":"read","startedAt":"2026-09-15T14:48:38.270Z","args":{"path":".worktrees/hertz-ir86-disk-delta/.github/ci/ci-notify.sh:1-125:raw"},"intent":"Reading notification scope contract"},"id":"42227be7","parentId":"b828511d","timestamp":"2026-09-15T14:48:38.270Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_0dFwMdwurXOJ4GOUa2DCjbMl|fc_043a862a419f59ae016aa95ac62a5887d2b37d403d0833fd2b","toolName":"grep","startedAt":"2026-09-15T14:48:38.270Z","args":{"path":".worktrees/hertz-ir86-disk-delta/CHANGELOG.md;.worktrees/hertz-ir86-disk-delta/docs/GOLDEN-CI.md;.worktrees/hertz-ir86-disk-delta/.github/workflows;.worktrees/hertz-ir86-disk-delta/crates/xtask/src/ma…"},"intent":"Locating closure receipts and adoption"},"id":"8c002d60","parentId":"42227be7","timestamp":"2026-09-15T14:48:38.270Z"}
{"type":"message","id":"616ed8ff","parentId":"8c002d60","timestamp":"2026-09-15T14:48:38.284Z","message":{"role":"toolResult","toolCallId":"call_IooMl8gf37osWbJQfmroMyDA|fc_043a862a419f59ae016aa95ac62a1c87d290fc7add991e5a7f","toolName":"read","content":[{"type":"text","text":"    fn path(segs: &[&str]) -> Vec<String> {\n        segs.iter().map(|s| s.to_string()).collect()\n    }\n\n    // [unit->REQ-DOCS-5] the api stand-in adapter injects at EVERY depth the\n    // path passes through `spt api` — the one spelling that replaced the\n    // per-loop-level hardcodes (IR-52: a third level would have needed a\n    // third copy) — and only when `api` is the ROOT verb, never for a\n    // same-named deeper segment.\n    #[test]\n    fn api_standin_injects_once_at_any_depth_and_only_for_the_root_verb() {\n        assert_eq!(help_args(&path(&[\"seal\"])), path(&[\"seal\"]));\n        assert_eq!(\n            help_args(&path(&[\"api\"])),\n            path(&[\"api\", \"--adapter\", \"x\"])\n        );\n        assert_eq!(\n            help_args(&path(&[\"api\", \"seal\"])),\n            path(&[\"api\", \"--adapter\", \"x\", \"seal\"])\n        );\n        assert_eq!(\n            help_args(&path(&[\"api\", \"seal\", \"verify\"])),\n            path(&[\"api\", \"--adapter\", \"x\", \"seal\", \"verify\"])\n        );\n        // A deeper segment spelled \"api\" is a name, not the root verb.\n        assert_eq!(\n            help_args(&path(&[\"endpoint\", \"api\"])),\n            path(&[\"endpoint\", \"api\"])\n        );\n    }\n\n    const HELP_TREE: [(&str, u8); 3] = [\n        (\"Usage: spt.exe\\n\\nCommands:\\n  child  A branch\\n\", 0),\n        (\"Usage: spt.exe child\\n\\nCommands:\\n  leaf  A leaf\\n\", 0),\n        (\"Usage: spt.exe child leaf\\n\", 0),\n    ];\n\n    // Real subprocess fixtures exercise status/stdout/stderr capture as well\n    // as recursion and the destination-write boundary. No workspace build.\n    fn producer(root: &Path, replies: [(&str, u8); 3]) -> PathBuf {\n        let bin = root.join(if cfg!(windows) { \"help.cmd\" } else { \"help\" });\n        let mut script = if cfg!(windows) {\n            String::from(\n                \"@echo off\\nif \\\"%~1\\\"==\\\"--help\\\" goto root\\n\\\n                 if \\\"%~2\\\"==\\\"--help\\\" goto child\\ngoto leaf\\n\",\n            )\n        } else {\n            String::from(\"#!/bin/sh\\ncase \\\"$*\\\" in\\n\")\n        };\n        for ((stdout, status), (label, args)) in replies.into_iter().zip([\n            (\"root\", \"--help\"),\n            (\"child\", \"child --help\"),\n            (\"leaf\", \"child leaf --help\"),\n        ]) {\n            if cfg!(windows) {\n                script.push_str(&format!(\":{label}\\n\"));\n                for line in stdout.lines() {\n                    script.push_str(&format!(\"echo({line}\\n\"));\n                }\n                script.push_str(&format!(\n                    \"echo producer diagnostic 1>&2\\nexit /b {status}\\n\"\n                ));\n            } else {\n                script.push_str(&format!(\"\\\"{args}\\\")\\n\"));\n                for line in stdout.lines() {\n                    script.push_str(&format!(\"printf '%s\\\\n' '{line}'\\n\"));\n                }\n                script.push_str(&format!(\n                    \"printf '%s\\\\n' 'producer diagnostic' >&2\\nexit {status}\\n;;\\n\"\n                ));\n            }\n        }\n        if cfg!(windows) {\n            script = script.replace('\\n', \"\\r\\n\");\n        } else {\n            script.push_str(\"*) exit 99;;\\nesac\\n\");\n        }\n        std::fs::write(&bin, script).unwrap();\n        #[cfg(unix)]\n        {\n            use std::os::unix::fs::PermissionsExt;\n            std::fs::set_permissions(&bin, std::fs::Permissions::from_mode(0o755)).unwrap();\n        }\n        bin\n    }\n\n    fn reference(root: &Path, contents: &str) -> PathBuf {\n        let page = root.join(\"docs-site/src/cli/reference.md\");\n        std::fs::create_dir_all(page.parent().unwrap()).unwrap();\n        std::fs::write(&page, contents).unwrap();\n        page\n    }\n\n    // [unit->REQ-DOCS-5]\n    #[test]\n    fn failed_root_or_nested_help_retains_reference_and_producer_context() {\n        for depth in [0, 2] {\n            let root = tempfile::tempdir().unwrap();\n            let original = \"# Published reference\\n\";\n            let page = reference(root.path(), original);\n            let mut replies = HELP_TREE;\n            replies[depth] = (\"Partial help must not be published\\n\", 23);\n            let bin = producer(root.path(), replies);\n\n…\n\n    let root = repo_root();\n    let targets = match binnames::workspace_bin_targets(&root) {\n        Ok(t) => t,\n        Err(e) => {\n            eprintln!(\"xtask check: FAILED — could not enumerate bin targets: {e}\");\n            std::process::exit(1);\n        }\n    };\n    if targets.is_empty() {\n        eprintln!(\n            \"xtask check: FAILED — cargo enumerated no bin targets. That is a fault in the \\\n             instrument, not a clean workspace, and a silent pass here would certify nothing.\"\n        );\n        std::process::exit(1);\n    }\n    let hits = binnames::duplicate_bin_names(&targets);\n    if hits.is_empty() {\n        return;\n    }\n    eprintln!(\"xtask check: FAILED — duplicate bin name(s) across workspace packages\");\n    for c in &hits {\n        eprintln!(\"  {} declared by: {}\", c.bin, c.packages.join(\", \"));\n    }\n    eprintln!(\n        \"  Same-named bins share one `target/<profile>/` output filename and clobber each other; \\\n         a CARGO_BIN_EXE_* lookup then resolves to whichever built last.\"\n    );\n    std::process::exit(1);\n}\n\n// [impl->REQ-BRAIN-READ-BOUNDED-PER-CALL]\nfn check_brain_read_policy() {\n    match brainread::check(&repo_root()) {\n\n…\n\nfn pool_claim(args: &[String]) {\n    let pool = flag(args, \"--pool\").unwrap_or_else(|| {\n        eprintln!(\n            \"usage: xtask pool-claim --pool <dir> --label <lane> \\\n             [--holder-pid <pid>] [--foreign-pool]\"\n        );\n        std::process::exit(2);\n    });\n    let label = flag(args, \"--label\").unwrap_or_else(|| {\n        eprintln!(\"a claim needs a --label: it is what the refusal line names\");\n        std::process::exit(2);\n    });\n    let foreign_pool = args.iter().any(|arg| arg == \"--foreign-pool\");\n    let pid = match flag(args, \"--holder-pid\") {\n        Some(p) => p.parse::<u32>().unwrap_or_else(|_| {\n            eprintln!(\"--holder-pid must be a pid\");\n            std::process::exit(2);\n        }),\n        None => spt_poolguard::default_holder_pid(),\n    };\n    let started_at = spt_procident::process_started_at(pid);\n    if started_at.is_none() {\n        // Not fatal: a platform with no identity oracle still gets a claim, it\n        // just cannot prove pid reuse later. Said out loud rather than assumed.\n        eprintln!(\n            \"note: no birth stamp readable for pid {pid} — the claim cannot detect              a recycled pid on this platform\"\n        );\n    }\n    let pool = Path::new(&pool);\n    let tree = std::env::current_dir().expect(\"cwd\");\n    let tree_root = git_line(&tree, &[\"rev-parse\", \"--show-toplevel\"])\n        .map(PathBuf::from)\n        .unwrap_or_else(|| {\n            eprintln!(\n                \"pool claim refused: cwd {} is not inside a readable git worktree; \\\n                 lane identity cannot be harvested safely\",\n                tree.display()\n            );\n            std::process::exit(2);\n        });\n    let pool_path = absolute_pool(&tree, pool);\n    let pool_tree = pool_worktree(&pool_path).unwrap_or_else(|| {\n        eprintln!(\n            \"pool claim refused: --pool {} is not inside a readable git worktree (cwd {}). \\\n             Run pool-claim from the worktree that contains the pool\",\n            pool_path.display(),\n            tree.display()\n        );\n        std::process::exit(2);\n    });\n    // [impl->REQ-POOL-CLAIM-TREE-MATCH]\n    if !claim_trees_match(&tree_root, &pool_tree) {\n        if !foreign_pool {\n            eprintln!(\n                \"pool claim refused: --pool {} belongs to worktree {}, but cwd {} belongs to {}. \\\n                 Run pool-claim from the worktree that contains the pool, or pass --foreign-pool \\\n                 for a deliberate sequential takeover\",\n                pool_path.display(),\n                pool_tree.display(),\n                tree.display(),\n                tree_root.display()\n            );\n            std::process::exit(2);\n        }\n        eprintln!(\n            \"foreign pool takeover requested: claiming {} for cwd worktree {} \\\n             (pool worktree {})\",\n            pool_path.display(),\n            tree_root.display(),\n            pool_tree.display()\n        );\n    }\n    // THE LANE'S OWN IDENTITY, which is what the finished question is actually\n    // about. A detached rig has no branch and claims on its base sha alone.\n    let branch = git_line(&tree_root, &[\"symbolic-ref\", \"--quiet\", \"--short\", \"HEAD\"]);\n    let base = git_line(&tree_root, &[\"rev-parse\", \"HEAD\"]);\n    if base.is_none() {\n        eprintln!(\n            \"note: no git identity readable in {} — this claim can only be judged by its \\\n             holder pid, which is the predicate that reads a cleared agent session as a \\\n             finished lane\",\n            tree.display()\n        );\n    }\n    let owner = spt_poolguard::PoolOwner {\n        owner_tree: tree.to_string_lossy().to_string(),\n        lane: Some(spt_poolguard::LaneClaim {\n            label: label.clone(),\n            pid,\n            started_at,\n            branch: branch.clone(),\n            base: base.clone(),\n        }),\n    };\n    spt_poolguard::write_owner(&spt_poolguard::owner_path(pool), &owner)\n        .expect(\"write the pool claim\");\n    println!(\n        \"pool {} claimed for lane {label} by {} (branch {}, base {}; advisory holder pid {pid}{})\",\n        pool.display(),\n        tree.display(),\n        branch.as_deref().unwrap_or(\"<detached>\"),"}],"details":{"fileSize":163022,"meta":{"source":{"type":"path","value":"C:\\Users\\decid\\Documents\\projects\\spt-core\\.worktrees\\hertz-ir86-disk-delta\\crates\\xtask\\src\\main.rs"}}},"isError":false,"timestamp":1789483718283}}
{"type":"message","id":"5ef57b16","parentId":"616ed8ff","timestamp":"2026-09-15T14:48:38.287Z","message":{"role":"toolResult","toolCallId":"call_qoMaqgFf6OtSfS4t1eeYF3l4|fc_043a862a419f59ae016aa95ac62a4487d2989cc02cebeea02f","toolName":"read","content":[{"type":"text","text":"//! Duplicate bin-name gate (IR-58's trigger condition).\n//!\n//! Two packages that declare a bin of the SAME name collide on the shared\n//! `target/<profile>/` output filename and clobber each other, after which a\n//! `CARGO_BIN_EXE_*` lookup resolves to whichever built last — the PR#28\n//! Windows gate-escape. The rule is real and already stated in prose at\n//! `crates/spt/Cargo.toml` and in `cli.rs`, and prose is exactly what went\n//! stale: those sentences state the invariant by naming ONE counterpart, so\n//! when the counterpart moves, a reader greps the name, finds nothing, and\n//! concludes the hazard is retired. There is no grep pattern for \"a sentence\n//! that assumed one counterpart\", which is why this belongs in a check.\n//!\n//! ## It enumerates through CARGO, never through manifest stanzas\n//!\n//! Binding condition (doyle, 2026-08-22), and it is the direct lesson of the\n//! false IR-58: a census built by grepping `[[bin]]` stanzas STRUCTURALLY\n//! CANNOT SEE an autodiscovered `src/bin/*.rs` target, because such a target has\n//! no stanza to grep. That census returned a confident answer about the one bin\n//! it could never have found — `xlate_choreo_fixture`, which is precisely the\n//! bin the collision rule names. A check with that blind spot would not merely\n//! miss duplicates; it would CERTIFY an absence it cannot see, which is worse\n//! than no check at all.\n//!\n//! So the input is `cargo metadata`'s own target list. If cargo can build it,\n//! this gate can see it.\n//!\n//! ## The blind spot is MEASURED, not argued\n//!\n//! At c62904e7 (+ this lane), read from `cargo metadata --no-deps` and from every\n//! manifest cargo names rather than a glob: 14 bin targets, 12 of them declared\n//! by a `[[bin]]` stanza, and TWO that no stanza grep can see —\n//! `spt-daemon`'s `xlate_choreo_fixture` (autodiscovered `src/bin/*.rs`) and\n//! `xtask` itself (autodiscovered `src/main.rs`). Duplicates: 0.\n//!\n//! The invisible one is the bin the collision rule NAMES. That is the whole\n//! argument in one row: the census that reported it gone was structurally unable\n//! to observe it, and reported an absence rather than an inability. The counts\n//! will drift as bins come and go — the property that will not is that\n//! autodiscovered targets carry no stanza to grep.\n\nuse std::collections::BTreeMap;\n\n/// One collision: a bin name and every package declaring it.\n#[derive(Debug, Clone, PartialEq, Eq)]\npub struct Collision {\n    pub bin: String,\n    pub packages: Vec<String>,\n}\n\n/// Bin names declared by more than one package.\n///\n/// Pure, so the corpus below can feed it an INVENTED pair and prove the gate\n/// reacts to the table rather than to the workspace it happens to ship with —\n/// a check whose only evidence is \"the real tree passes\" is a check that has\n/// never been shown to fail.\n// [impl->REQ-BUILD-UNIQUE-BIN-NAMES]\npub fn duplicate_bin_names(targets: &[(String, String)]) -> Vec<Collision> {\n    let mut by_name: BTreeMap<&str, Vec<String>> = BTreeMap::new();\n    for (package, bin) in targets {\n        by_name.entry(bin.as_str()).or_default().push(package.clone());\n    }\n    by_name\n        .into_iter()\n        .filter(|(_, pkgs)| pkgs.len() > 1)\n        .map(|(bin, mut packages)| {\n            packages.sort();\n            packages.dedup();\n            Collision {\n                bin: bin.to_string(),\n                packages,\n            }\n        })\n        .filter(|c| c.packages.len() > 1)\n        .collect()\n}\n\n/// Every `(package, bin)` pair cargo knows about in this workspace.\n///\n/// `--no-deps` keeps the question to workspace members: a registry crate's bin\n/// does not land in our `target/<profile>/` root and cannot collide there.\npub fn workspace_bin_targets(manifest_dir: &std::path::Path) -> Result<Vec<(String, String)>, String> {\n    let out = std::process::Command::new(env!(\"CARGO\"))\n        .args([\"metadata\", \"--no-deps\", \"--format-version\", \"1\"])\n        .current_dir(manifest_dir)\n        .output()\n        .map_err(|e| format!(\"cargo metadata did not run: {e}\"))?;\n    if !out.status.success() {\n        return Err(format!(\n            \"cargo metadata failed: {}\",\n            String::from_utf8_lossy(&out.stderr)\n        ));\n    }\n    let meta: serde_json::Value =\n        serde_json::from_slice(&out.stdout).map_err(|e| format!(\"cargo metadata JSON: {e}\"))?;\n    let mut pairs = Vec::new();\n    for pkg in meta[\"packages\"].as_array().into_iter().flatten() {\n        let pname = pkg[\"name\"].as_str().unwrap_or_default().to_string();\n        for t in pkg[\"targets\"].as_array().into_iter().flatten() {\n            let is_bin = t[\"kind\"]\n                .as_array()\n                .into_iter()\n                .flatten()\n                .any(|k| k.as_str() == Some(\"bin\"));\n            if is_bin {\n                if let Some(tname) = t[\"name\"].as_str() {\n                    pairs.push((pname.clone(), tname.to_string()));\n                }\n            }\n        }\n    }\n\n[Showing lines 1-110 of 180. Use :111 to continue]"}],"details":{"truncation":{"content":"//! Duplicate bin-name gate (IR-58's trigger condition).\r\n//!\r\n//! Two packages that declare a bin of the SAME name collide on the shared\r\n//! `target/<profile>/` output filename and clobber each other, after which a\r\n//! `CARGO_BIN_EXE_*` lookup resolves to whichever built last — the PR#28\r\n//! Windows gate-escape. The rule is real and already stated in prose at\r\n//! `crates/spt/Cargo.toml` and in `cli.rs`, and prose is exactly what went\r\n//! stale: those sentences state the invariant by naming ONE counterpart, so\r\n//! when the counterpart moves, a reader greps the name, finds nothing, and\r\n//! concludes the hazard is retired. There is no grep pattern for \"a sentence\r\n//! that assumed one counterpart\", which is why this belongs in a check.\r\n//!\r\n//! ## It enumerates through CARGO, never through manifest stanzas\r\n//!\r\n//! Binding condition (doyle, 2026-08-22), and it is the direct lesson of the\r\n//! false IR-58: a census built by grepping `[[bin]]` stanzas STRUCTURALLY\r\n//! CANNOT SEE an autodiscovered `src/bin/*.rs` target, because such a target has\r\n//! no stanza to grep. That census returned a confident answer about the one bin\r\n//! it could never have found — `xlate_choreo_fixture`, which is precisely the\r\n//! bin the collision rule names. A check with that blind spot would not merely\r\n//! miss duplicates; it would CERTIFY an absence it cannot see, which is worse\r\n//! than no check at all.\r\n//!\r\n//! So the input is `cargo metadata`'s own target list. If cargo can build it,\r\n//! this gate can see it.\r\n//!\r\n//! ## The blind spot is MEASURED, not argued\r\n//!\r\n//! At c62904e7 (+ this lane), read from `cargo metadata --no-deps` and from every\r\n//! manifest cargo names rather than a glob: 14 bin targets, 12 of them declared\r\n//! by a `[[bin]]` stanza, and TWO that no stanza grep can see —\r\n//! `spt-daemon`'s `xlate_choreo_fixture` (autodiscovered `src/bin/*.rs`) and\r\n//! `xtask` itself (autodiscovered `src/main.rs`). Duplicates: 0.\r\n//!\r\n//! The invisible one is the bin the collision rule NAMES. That is the whole\r\n//! argument in one row: the census that reported it gone was structurally unable\r\n//! to observe it, and reported an absence rather than an inability. The counts\r\n//! will drift as bins come and go — the property that will not is that\r\n//! autodiscovered targets carry no stanza to grep.\r\n\r\nuse std::collections::BTreeMap;\r\n\r\n/// One collision: a bin name and every package declaring it.\r\n#[derive(Debug, Clone, PartialEq, Eq)]\r\npub struct Collision {\r\n    pub bin: String,\r\n    pub packages: Vec<String>,\r\n}\r\n\r\n/// Bin names declared by more than one package.\r\n///\r\n/// Pure, so the corpus below can feed it an INVENTED pair and prove the gate\r\n/// reacts to the table rather than to the workspace it happens to ship with —\r\n/// a check whose only evidence is \"the real tree passes\" is a check that has\r\n/// never been shown to fail.\r\n// [impl->REQ-BUILD-UNIQUE-BIN-NAMES]\r\npub fn duplicate_bin_names(targets: &[(String, String)]) -> Vec<Collision> {\r\n    let mut by_name: BTreeMap<&str, Vec<String>> = BTreeMap::new();\r\n    for (package, bin) in targets {\r\n        by_name.entry(bin.as_str()).or_default().push(package.clone());\r\n    }\r\n    by_name\r\n        .into_iter()\r\n        .filter(|(_, pkgs)| pkgs.len() > 1)\r\n        .map(|(bin, mut packages)| {\r\n            packages.sort();\r\n            packages.dedup();\r\n            Collision {\r\n                bin: bin.to_string(),\r\n                packages,\r\n            }\r\n        })\r\n        .filter(|c| c.packages.len() > 1)\r\n        .collect()\r\n}\r\n\r\n/// Every `(package, bin)` pair cargo knows about in this workspace.\r\n///\r\n/// `--no-deps` keeps the question to workspace members: a registry crate's bin\r\n/// does not land in our `target/<profile>/` root and cannot collide there.\r\npub fn workspace_bin_targets(manifest_dir: &std::path::Path) -> Result<Vec<(String, String)>, String> {\r\n    let out = std::process::Command::new(env!(\"CARGO\"))\r\n        .args([\"metadata\", \"--no-deps\", \"--format-version\", \"1\"])\r\n        .current_dir(manifest_dir)\r\n        .output()\r\n        .map_err(|e| format!(\"cargo metadata did not run: {e}\"))?;\r\n    if !out.status.success() {\r\n        return Err(format!(\r\n            \"cargo metadata failed: {}\",\r\n            String::from_utf8_lossy(&out.stderr)\r\n        ));\r\n    }\r\n    let meta: serde_json::Value =\r\n        serde_json::from_slice(&out.stdout).map_err(|e| format!(\"cargo metadata JSON: {e}\"))?;\r\n    let mut pairs = Vec::new();\r\n    for pkg in meta[\"packages\"].as_array().into_iter().flatten() {\r\n        let pname = pkg[\"name\"].as_str().unwrap_or_default().to_string();\r\n        for t in pkg[\"targets\"].as_array().into_iter().flatten() {\r\n            let is_bin = t[\"kind\"]\r\n                .as_array()\r\n                .into_iter()\r\n                .flatten()\r\n                .any(|k| k.as_str() == Some(\"bin\"));\r\n            if is_bin {\r\n                if let Some(tname) = t[\"name\"].as_str() {\r\n                    pairs.push((pname.clone(), tname.to_string()));\r\n                }\r\n            }\r\n        }\r\n    }\r","truncated":true,"truncatedBy":"lines","totalLines":180,"totalBytes":5077,"outputLines":110,"outputBytes":5077,"lastLinePartial":false,"firstLineExceedsLimit":false},"totalLines":180,"displayContent":{"text":"//! Duplicate bin-name gate (IR-58's trigger condition).\r\n//!\r\n//! Two packages that declare a bin of the SAME name collide on the shared\r\n//! `target/<profile>/` output filename and clobber each other, after which a\r\n//! `CARGO_BIN_EXE_*` lookup resolves to whichever built last — the PR#28\r\n//! Windows gate-escape. The rule is real and already stated in prose at\r\n//! `crates/spt/Cargo.toml` and in `cli.rs`, and prose is exactly what went\r\n//! stale: those sentences state the invariant by naming ONE counterpart, so\r\n//! when the counterpart moves, a reader greps the name, finds nothing, and\r\n//! concludes the hazard is retired. There is no grep pattern for \"a sentence\r\n//! that assumed one counterpart\", which is why this belongs in a check.\r\n//!\r\n//! ## It enumerates through CARGO, never through manifest stanzas\r\n//!\r\n//! Binding condition (doyle, 2026-08-22), and it is the direct lesson of the\r\n//! false IR-58: a census built by grepping `[[bin]]` stanzas STRUCTURALLY\r\n//! CANNOT SEE an autodiscovered `src/bin/*.rs` target, because such a target has\r\n//! no stanza to grep. That census returned a confident answer about the one bin\r\n//! it could never have found — `xlate_choreo_fixture`, which is precisely the\r\n//! bin the collision rule names. A check with that blind spot would not merely\r\n//! miss duplicates; it would CERTIFY an absence it cannot see, which is worse\r\n//! than no check at all.\r\n//!\r\n//! So the input is `cargo metadata`'s own target list. If cargo can build it,\r\n//! this gate can see it.\r\n//!\r\n//! ## The blind spot is MEASURED, not argued\r\n//!\r\n//! At c62904e7 (+ this lane), read from `cargo metadata --no-deps` and from every\r\n//! manifest cargo names rather than a glob: 14 bin targets, 12 of them declared\r\n//! by a `[[bin]]` stanza, and TWO that no stanza grep can see —\r\n//! `spt-daemon`'s `xlate_choreo_fixture` (autodiscovered `src/bin/*.rs`) and\r\n//! `xtask` itself (autodiscovered `src/main.rs`). Duplicates: 0.\r\n//!\r\n//! The invisible one is the bin the collision rule NAMES. That is the whole\r\n//! argument in one row: the census that reported it gone was structurally unable\r\n//! to observe it, and reported an absence rather than an inability. The counts\r\n//! will drift as bins come and go — the property that will not is that\r\n//! autodiscovered targets carry no stanza to grep.\r\n\r\nuse std::collections::BTreeMap;\r\n\r\n/// One collision: a bin name and every package declaring it.\r\n#[derive(Debug, Clone, PartialEq, Eq)]\r\npub struct Collision {\r\n    pub bin: String,\r\n    pub packages: Vec<String>,\r\n}\r\n\r\n/// Bin names declared by more than one package.\r\n///\r\n/// Pure, so the corpus below can feed it an INVENTED pair and prove the gate\r\n/// reacts to the table rather than to the workspace it happens to ship with —\r\n/// a check whose only evidence is \"the real tree passes\" is a check that has\r\n/// never been shown to fail.\r\n// [impl->REQ-BUILD-UNIQUE-BIN-NAMES]\r\npub fn duplicate_bin_names(targets: &[(String, String)]) -> Vec<Collision> {\r\n    let mut by_name: BTreeMap<&str, Vec<String>> = BTreeMap::new();\r\n    for (package, bin) in targets {\r\n        by_name.entry(bin.as_str()).or_default().push(package.clone());\r\n    }\r\n    by_name\r\n        .into_iter()\r\n        .filter(|(_, pkgs)| pkgs.len() > 1)\r\n        .map(|(bin, mut packages)| {\r\n            packages.sort();\r\n            packages.dedup();\r\n            Collision {\r\n                bin: bin.to_string(),\r\n                packages,\r\n            }\r\n        })\r\n        .filter(|c| c.packages.len() > 1)\r\n        .collect()\r\n}\r\n\r\n/// Every `(package, bin)` pair cargo knows about in this workspace.\r\n///\r\n/// `--no-deps` keeps the question to workspace members: a registry crate's bin\r\n/// does not land in our `target/<profile>/` root and cannot collide there.\r\npub fn workspace_bin_targets(manifest_dir: &std::path::Path) -> Result<Vec<(String, String)>, String> {\r\n    let out = std::process::Command::new(env!(\"CARGO\"))\r\n        .args([\"metadata\", \"--no-deps\", \"--format-version\", \"1\"])\r\n        .current_dir(manifest_dir)\r\n        .output()\r\n        .map_err(|e| format!(\"cargo metadata did not run: {e}\"))?;\r\n    if !out.status.success() {\r\n        return Err(format!(\r\n            \"cargo metadata failed: {}\",\r\n            String::from_utf8_lossy(&out.stderr)\r\n        ));\r\n    }\r\n    let meta: serde_json::Value =\r\n        serde_json::from_slice(&out.stdout).map_err(|e| format!(\"cargo metadata JSON: {e}\"))?;\r\n    let mut pairs = Vec::new();\r\n    for pkg in meta[\"packages\"].as_array().into_iter().flatten() {\r\n        let pname = pkg[\"name\"].as_str().unwrap_or_default().to_string();\r\n        for t in pkg[\"targets\"].as_array().into_iter().flatten() {\r\n            let is_bin = t[\"kind\"]\r\n                .as_array()\r\n                .into_iter()\r\n                .flatten()\r\n                .any(|k| k.as_str() == Some(\"bin\"));\r\n            if is_bin {\r\n                if let Some(tname) = t[\"name\"].as_str() {\r\n                    pairs.push((pname.clone(), tname.to_string()));\r\n                }\r\n            }\r\n        }\r\n    }\r","startLine":1,"lineNumbers":[1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95,96,97,98,99,100,101,102,103,104,105,106,107,108,109,110]},"fileSize":8091,"meta":{"source":{"type":"path","value":"C:\\Users\\decid\\Documents\\projects\\spt-core\\.worktrees\\hertz-ir86-disk-delta\\crates\\xtask\\src\\binnames.rs"},"truncation":{"direction":"head","truncatedBy":"lines","totalLines":180,"totalBytes":5077,"outputLines":110,"outputBytes":5077,"shownRange":{"start":1,"end":110},"nextOffset":111}}},"isError":false,"timestamp":1789483718287}}
{"type":"message","id":"94b1c076","parentId":"5ef57b16","timestamp":"2026-09-15T14:48:38.289Z","message":{"role":"toolResult","toolCallId":"call_xXmJ6WYKFODKvKdtYHszhYXh|fc_043a862a419f59ae016aa95ac62a4c87d28551faf4aad13ffc","toolName":"read","content":[{"type":"text","text":"#!/usr/bin/env bash\n#\n# ci-notify.sh — push the notify step's supplied needs results to agents over\n# the SPT_DEV subnet. This is not the run's conclusion; check the run itself.\n#\n# ============================================================================\n# NEW RUNNER CHECKLIST\n# ============================================================================\n# Adding a runner needs NOTHING in this repo. The two prerequisites are:\n#\n#   1. `spt` on the runner user's PATH.\n#   2. The runner's node joined to the subnet the recipients live on.\n#\n# That is the entire clone story. There is no per-runner config file, no\n# secret, no label mapping — the informant's identity is derived from\n# $RUNNER_NAME at run time (see FROM_LABEL below).\n#\n# The notify job pins `runs-on: [self-hosted, Linux]` — the OS label, NOT a box\n# name — so a new LINUX runner becomes eligible to host it automatically. A new\n# WINDOWS runner contributes jobs and simply does not host the notify job; that\n# is deliberate, not an oversight: ci.yml records (see its \"Two shells\" note)\n# that the Windows runner has no bash on PATH, and no interpreter is present on\n# both OSes. Notifying does not need to happen on the box that failed — this\n# script reads job results out of the workflow context, not off the local disk.\n#\n# Consequence worth knowing: if every Linux runner is offline, that run goes\n# unannounced. Silence from this informant is therefore ambiguous by\n# construction; it is a convenience layer over polling, never a replacement for\n# a receiver's own check.\n# ============================================================================\n#\n# POSTURE: best-effort IN TIME as well as in exit code, always exit 0. A dead\n# daemon, a missing `spt`, an unreachable recipient, a WEDGED send should not red\n# a CI run. This step reports only its supplied needs results, not its own job's\n# outcome or the run's conclusion: both are still unobserved when it sends.\n#\n# The time half is not theoretical (2026-07-27, this script's debut run and its\n# rerun, both on kitsubito): the script ran correctly, computed its verdict, and\n# then `spt send` HUNG — twice, ~5m each, same shape — until the notify job's own\n# 5-minute budget cancelled it, and THAT cancellation is what reddened the run.\n# `|| true` cannot guard a hang. The recipient was live-listening, so the send took\n# the LIVE cross-node path (kitsubito -> bigscreen); an unbounded dial there is a\n# product finding of its own (banked separately for ranking — every agent that\n# scripts `spt send` inherits the same exposure). The send bound limits that\n# exposure; it does not turn this step into evidence of a completed run.\n#\n# SPT_HOME: deliberately neither set NOR unset. Whatever the runner service's\n# environment carries IS the runner user's real home, and that is the one the\n# recipients' perches live under. No workflow in this repo exports SPT_HOME, and\n# a separate job cannot inherit another job's env anyway, so a CI test-home\n# cannot leak in here. The resolved value is echoed below so a future leak is\n# visible in the log rather than silent.\n\nset -uo pipefail\n\n# --- inputs ----------------------------------------------------------------\n# Job results arrive as RESULT_* env vars from the workflow step (each is one\n# of: success | failure | cancelled | skipped | \"\" when the job never ran).\n: \"${RESULT_CHANGES:=}\"\n: \"${RESULT_TRACEABILITY:=}\"\n: \"${RESULT_TEST:=}\"\n: \"${RESULT_N1_GATE:=}\"\n: \"${RESULT_TWOHOST_A:=}\"\n: \"${RESULT_TWOHOST_B:=}\"\n: \"${PR_NUMBER:=}\"\n: \"${RUNNER_NAME:=unknown}\"\n: \"${GITHUB_REPOSITORY:=}\"\n: \"${GITHUB_RUN_ID:=}\"\n: \"${GITHUB_SERVER_URL:=https://github.com}\"\n: \"${GITHUB_REF_NAME:=}\"\n: \"${GITHUB_SHA:=}\"\n\n# --- verdict ---------------------------------------------------------------\n# THREE classes, not two. `skipped` is NOT red: the docs-only thin gate\n# (REQ-CI-DOCS-ONLY-THIN) deliberately skips `test` and `n1-gate` on a\n# Markdown-only PR, so treating skipped as red would cry wolf on every docs PR.\n#\n# PRECEDENCE IS LOAD-BEARING, and getting it backwards silences real reds. A\n# genuine failure normally CANCELS its siblings, so mixed failure+cancelled is\n# the SHAPE OF A REAL RED, not of a cancellation:\n#\n#   any `failure`                  -> FAILURE   (cancelled siblings listed as context)\n#   zero failures AND >=1 cancelled -> CANCELLED (its own class, never worded FAILURE)\n#   otherwise                      -> SUCCESS\n#\n# The CANCELLED wording deliberately contains no occurrence of the string\n# FAILURE: a human skimming the notification decides whether to drop what they\n# are doing off that first word, and an operator-cancelled run is not a red.\n# `ci-notify-selftest.sh` asserts the whole matrix, INCLUDING the positive\n# control that a real failure still pages — a split that only proves\n# \"cancelled goes quiet\" would pass just as happily if it silenced everything.\n# [impl->REQ-CI-NOTIFY-CANCELLED-CLASS]\nfailing=\"\"\ncancelled=\"\"\n\ncheck() {\n  case \"$2\" in\n    failure) failing=\"${failing:+$failing, }$1($2)\" ;;\n    cancelled) cancelled=\"${cancelled:+$cancelled, }$1\" ;;\n  esac\n}\n\n# Sets `verdict`, `failing` and `cancelled` from the RESULT_* environment. Reads\n# them at CALL time (not through the `:=` defaults above) so a caller — the\n# selftest — can drive the matrix by assignment and call this repeatedly.\ncompute_verdict() {\n  failing=\"\"\n  cancelled=\"\"\n  check changes \"${RESULT_CHANGES:-}\"\n  check traceability \"${RESULT_TRACEABILITY:-}\"\n  check test \"${RESULT_TEST:-}\"\n  check n1-gate \"${RESULT_N1_GATE:-}\"\n  check twohost-a \"${RESULT_TWOHOST_A:-}\"\n  check twohost-b \"${RESULT_TWOHOST_B:-}\"\n\n  if [ -n \"$failing\" ]; then\n    verdict=\"FAILURE\"\n  elif [ -n \"$cancelled\" ]; then\n    verdict=\"CANCELLED\"\n  else\n    verdict=\"SUCCESS\"\n  fi\n}\n\n# Writes the notification body to stdout. Split out from the send path for the\n\n[Showing lines 1-125 of 276. Use :126 to continue]"}],"details":{"truncation":{"content":"#!/usr/bin/env bash\n#\n# ci-notify.sh — push the notify step's supplied needs results to agents over\n# the SPT_DEV subnet. This is not the run's conclusion; check the run itself.\n#\n# ============================================================================\n# NEW RUNNER CHECKLIST\n# ============================================================================\n# Adding a runner needs NOTHING in this repo. The two prerequisites are:\n#\n#   1. `spt` on the runner user's PATH.\n#   2. The runner's node joined to the subnet the recipients live on.\n#\n# That is the entire clone story. There is no per-runner config file, no\n# secret, no label mapping — the informant's identity is derived from\n# $RUNNER_NAME at run time (see FROM_LABEL below).\n#\n# The notify job pins `runs-on: [self-hosted, Linux]` — the OS label, NOT a box\n# name — so a new LINUX runner becomes eligible to host it automatically. A new\n# WINDOWS runner contributes jobs and simply does not host the notify job; that\n# is deliberate, not an oversight: ci.yml records (see its \"Two shells\" note)\n# that the Windows runner has no bash on PATH, and no interpreter is present on\n# both OSes. Notifying does not need to happen on the box that failed — this\n# script reads job results out of the workflow context, not off the local disk.\n#\n# Consequence worth knowing: if every Linux runner is offline, that run goes\n# unannounced. Silence from this informant is therefore ambiguous by\n# construction; it is a convenience layer over polling, never a replacement for\n# a receiver's own check.\n# ============================================================================\n#\n# POSTURE: best-effort IN TIME as well as in exit code, always exit 0. A dead\n# daemon, a missing `spt`, an unreachable recipient, a WEDGED send should not red\n# a CI run. This step reports only its supplied needs results, not its own job's\n# outcome or the run's conclusion: both are still unobserved when it sends.\n#\n# The time half is not theoretical (2026-07-27, this script's debut run and its\n# rerun, both on kitsubito): the script ran correctly, computed its verdict, and\n# then `spt send` HUNG — twice, ~5m each, same shape — until the notify job's own\n# 5-minute budget cancelled it, and THAT cancellation is what reddened the run.\n# `|| true` cannot guard a hang. The recipient was live-listening, so the send took\n# the LIVE cross-node path (kitsubito -> bigscreen); an unbounded dial there is a\n# product finding of its own (banked separately for ranking — every agent that\n# scripts `spt send` inherits the same exposure). The send bound limits that\n# exposure; it does not turn this step into evidence of a completed run.\n#\n# SPT_HOME: deliberately neither set NOR unset. Whatever the runner service's\n# environment carries IS the runner user's real home, and that is the one the\n# recipients' perches live under. No workflow in this repo exports SPT_HOME, and\n# a separate job cannot inherit another job's env anyway, so a CI test-home\n# cannot leak in here. The resolved value is echoed below so a future leak is\n# visible in the log rather than silent.\n\nset -uo pipefail\n\n# --- inputs ----------------------------------------------------------------\n# Job results arrive as RESULT_* env vars from the workflow step (each is one\n# of: success | failure | cancelled | skipped | \"\" when the job never ran).\n: \"${RESULT_CHANGES:=}\"\n: \"${RESULT_TRACEABILITY:=}\"\n: \"${RESULT_TEST:=}\"\n: \"${RESULT_N1_GATE:=}\"\n: \"${RESULT_TWOHOST_A:=}\"\n: \"${RESULT_TWOHOST_B:=}\"\n: \"${PR_NUMBER:=}\"\n: \"${RUNNER_NAME:=unknown}\"\n: \"${GITHUB_REPOSITORY:=}\"\n: \"${GITHUB_RUN_ID:=}\"\n: \"${GITHUB_SERVER_URL:=https://github.com}\"\n: \"${GITHUB_REF_NAME:=}\"\n: \"${GITHUB_SHA:=}\"\n\n# --- verdict ---------------------------------------------------------------\n# THREE classes, not two. `skipped` is NOT red: the docs-only thin gate\n# (REQ-CI-DOCS-ONLY-THIN) deliberately skips `test` and `n1-gate` on a\n# Markdown-only PR, so treating skipped as red would cry wolf on every docs PR.\n#\n# PRECEDENCE IS LOAD-BEARING, and getting it backwards silences real reds. A\n# genuine failure normally CANCELS its siblings, so mixed failure+cancelled is\n# the SHAPE OF A REAL RED, not of a cancellation:\n#\n#   any `failure`                  -> FAILURE   (cancelled siblings listed as context)\n#   zero failures AND >=1 cancelled -> CANCELLED (its own class, never worded FAILURE)\n#   otherwise                      -> SUCCESS\n#\n# The CANCELLED wording deliberately contains no occurrence of the string\n# FAILURE: a human skimming the notification decides whether to drop what they\n# are doing off that first word, and an operator-cancelled run is not a red.\n# `ci-notify-selftest.sh` asserts the whole matrix, INCLUDING the positive\n# control that a real failure still pages — a split that only proves\n# \"cancelled goes quiet\" would pass just as happily if it silenced everything.\n# [impl->REQ-CI-NOTIFY-CANCELLED-CLASS]\nfailing=\"\"\ncancelled=\"\"\n\ncheck() {\n  case \"$2\" in\n    failure) failing=\"${failing:+$failing, }$1($2)\" ;;\n    cancelled) cancelled=\"${cancelled:+$cancelled, }$1\" ;;\n  esac\n}\n\n# Sets `verdict`, `failing` and `cancelled` from the RESULT_* environment. Reads\n# them at CALL time (not through the `:=` defaults above) so a caller — the\n# selftest — can drive the matrix by assignment and call this repeatedly.\ncompute_verdict() {\n  failing=\"\"\n  cancelled=\"\"\n  check changes \"${RESULT_CHANGES:-}\"\n  check traceability \"${RESULT_TRACEABILITY:-}\"\n  check test \"${RESULT_TEST:-}\"\n  check n1-gate \"${RESULT_N1_GATE:-}\"\n  check twohost-a \"${RESULT_TWOHOST_A:-}\"\n  check twohost-b \"${RESULT_TWOHOST_B:-}\"\n\n  if [ -n \"$failing\" ]; then\n    verdict=\"FAILURE\"\n  elif [ -n \"$cancelled\" ]; then\n    verdict=\"CANCELLED\"\n  else\n    verdict=\"SUCCESS\"\n  fi\n}\n\n# Writes the notification body to stdout. Split out from the send path for the","truncated":true,"truncatedBy":"lines","totalLines":276,"totalBytes":5859,"outputLines":125,"outputBytes":5859,"lastLinePartial":false,"firstLineExceedsLimit":false},"totalLines":276,"displayContent":{"text":"#!/usr/bin/env bash\n#\n# ci-notify.sh — push the notify step's supplied needs results to agents over\n# the SPT_DEV subnet. This is not the run's conclusion; check the run itself.\n#\n# ============================================================================\n# NEW RUNNER CHECKLIST\n# ============================================================================\n# Adding a runner needs NOTHING in this repo. The two prerequisites are:\n#\n#   1. `spt` on the runner user's PATH.\n#   2. The runner's node joined to the subnet the recipients live on.\n#\n# That is the entire clone story. There is no per-runner config file, no\n# secret, no label mapping — the informant's identity is derived from\n# $RUNNER_NAME at run time (see FROM_LABEL below).\n#\n# The notify job pins `runs-on: [self-hosted, Linux]` — the OS label, NOT a box\n# name — so a new LINUX runner becomes eligible to host it automatically. A new\n# WINDOWS runner contributes jobs and simply does not host the notify job; that\n# is deliberate, not an oversight: ci.yml records (see its \"Two shells\" note)\n# that the Windows runner has no bash on PATH, and no interpreter is present on\n# both OSes. Notifying does not need to happen on the box that failed — this\n# script reads job results out of the workflow context, not off the local disk.\n#\n# Consequence worth knowing: if every Linux runner is offline, that run goes\n# unannounced. Silence from this informant is therefore ambiguous by\n# construction; it is a convenience layer over polling, never a replacement for\n# a receiver's own check.\n# ============================================================================\n#\n# POSTURE: best-effort IN TIME as well as in exit code, always exit 0. A dead\n# daemon, a missing `spt`, an unreachable recipient, a WEDGED send should not red\n# a CI run. This step reports only its supplied needs results, not its own job's\n# outcome or the run's conclusion: both are still unobserved when it sends.\n#\n# The time half is not theoretical (2026-07-27, this script's debut run and its\n# rerun, both on kitsubito): the script ran correctly, computed its verdict, and\n# then `spt send` HUNG — twice, ~5m each, same shape — until the notify job's own\n# 5-minute budget cancelled it, and THAT cancellation is what reddened the run.\n# `|| true` cannot guard a hang. The recipient was live-listening, so the send took\n# the LIVE cross-node path (kitsubito -> bigscreen); an unbounded dial there is a\n# product finding of its own (banked separately for ranking — every agent that\n# scripts `spt send` inherits the same exposure). The send bound limits that\n# exposure; it does not turn this step into evidence of a completed run.\n#\n# SPT_HOME: deliberately neither set NOR unset. Whatever the runner service's\n# environment carries IS the runner user's real home, and that is the one the\n# recipients' perches live under. No workflow in this repo exports SPT_HOME, and\n# a separate job cannot inherit another job's env anyway, so a CI test-home\n# cannot leak in here. The resolved value is echoed below so a future leak is\n# visible in the log rather than silent.\n\nset -uo pipefail\n\n# --- inputs ----------------------------------------------------------------\n# Job results arrive as RESULT_* env vars from the workflow step (each is one\n# of: success | failure | cancelled | skipped | \"\" when the job never ran).\n: \"${RESULT_CHANGES:=}\"\n: \"${RESULT_TRACEABILITY:=}\"\n: \"${RESULT_TEST:=}\"\n: \"${RESULT_N1_GATE:=}\"\n: \"${RESULT_TWOHOST_A:=}\"\n: \"${RESULT_TWOHOST_B:=}\"\n: \"${PR_NUMBER:=}\"\n: \"${RUNNER_NAME:=unknown}\"\n: \"${GITHUB_REPOSITORY:=}\"\n: \"${GITHUB_RUN_ID:=}\"\n: \"${GITHUB_SERVER_URL:=https://github.com}\"\n: \"${GITHUB_REF_NAME:=}\"\n: \"${GITHUB_SHA:=}\"\n\n# --- verdict ---------------------------------------------------------------\n# THREE classes, not two. `skipped` is NOT red: the docs-only thin gate\n# (REQ-CI-DOCS-ONLY-THIN) deliberately skips `test` and `n1-gate` on a\n# Markdown-only PR, so treating skipped as red would cry wolf on every docs PR.\n#\n# PRECEDENCE IS LOAD-BEARING, and getting it backwards silences real reds. A\n# genuine failure normally CANCELS its siblings, so mixed failure+cancelled is\n# the SHAPE OF A REAL RED, not of a cancellation:\n#\n#   any `failure`                  -> FAILURE   (cancelled siblings listed as context)\n#   zero failures AND >=1 cancelled -> CANCELLED (its own class, never worded FAILURE)\n#   otherwise                      -> SUCCESS\n#\n# The CANCELLED wording deliberately contains no occurrence of the string\n# FAILURE: a human skimming the notification decides whether to drop what they\n# are doing off that first word, and an operator-cancelled run is not a red.\n# `ci-notify-selftest.sh` asserts the whole matrix, INCLUDING the positive\n# control that a real failure still pages — a split that only proves\n# \"cancelled goes quiet\" would pass just as happily if it silenced everything.\n# [impl->REQ-CI-NOTIFY-CANCELLED-CLASS]\nfailing=\"\"\ncancelled=\"\"\n\ncheck() {\n  case \"$2\" in\n    failure) failing=\"${failing:+$failing, }$1($2)\" ;;\n    cancelled) cancelled=\"${cancelled:+$cancelled, }$1\" ;;\n  esac\n}\n\n# Sets `verdict`, `failing` and `cancelled` from the RESULT_* environment. Reads\n# them at CALL time (not through the `:=` defaults above) so a caller — the\n# selftest — can drive the matrix by assignment and call this repeatedly.\ncompute_verdict() {\n  failing=\"\"\n  cancelled=\"\"\n  check changes \"${RESULT_CHANGES:-}\"\n  check traceability \"${RESULT_TRACEABILITY:-}\"\n  check test \"${RESULT_TEST:-}\"\n  check n1-gate \"${RESULT_N1_GATE:-}\"\n  check twohost-a \"${RESULT_TWOHOST_A:-}\"\n  check twohost-b \"${RESULT_TWOHOST_B:-}\"\n\n  if [ -n \"$failing\" ]; then\n    verdict=\"FAILURE\"\n  elif [ -n \"$cancelled\" ]; then\n    verdict=\"CANCELLED\"\n  else\n    verdict=\"SUCCESS\"\n  fi\n}\n\n# Writes the notification body to stdout. Split out from the send path for the","startLine":1,"lineNumbers":[1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95,96,97,98,99,100,101,102,103,104,105,106,107,108,109,110,111,112,113,114,115,116,117,118,119,120,121,122,123,124,125]},"fileSize":13352,"meta":{"source":{"type":"path","value":"C:\\Users\\decid\\Documents\\projects\\spt-core\\.worktrees\\hertz-ir86-disk-delta\\.github\\ci\\ci-notify.sh"},"truncation":{"direction":"head","truncatedBy":"lines","totalLines":276,"totalBytes":5859,"outputLines":125,"outputBytes":5859,"shownRange":{"start":1,"end":125},"nextOffset":126}}},"isError":false,"timestamp":1789483718288}}
{"type":"message","id":"d377b908","parentId":"94b1c076","timestamp":"2026-09-15T14:48:38.291Z","message":{"role":"toolResult","toolCallId":"call_fqJwWI3SLxD9aUZqpVtfjmhF|fc_043a862a419f59ae016aa95ac62a3487d299e15b6da6771ebf","toolName":"read","content":[{"type":"text","text":"/// absent — the daemon only stamps perches it hosts.\n// [impl->REQ-WAKE-RESUME-LEG]\npub fn set_host_error(perch_path: &Path, reason: Option<&str>) -> std::io::Result<()> {\n    mutate_info(perch_path, |rec| {\n        rec.host_error = reason.map(str::to_string);\n    })\n}\n\n/// Number of read attempts before giving up (torn-read retry).\nconst READ_ATTEMPTS: u32 = 5;\n\n/// Acquire the per-perch write lock — the stable `<perch>/.info.lock` sentinel\n/// (created once, never renamed; advisory, auto-released on fd drop / process exit).\n/// Serializes ALL info.json writers so a whole-record write and a locked RMW can never\n/// lose each other's update (REQ-HAZARD-INFO-RMW-LOST-UPDATE). See [`mutate_info`] for\n/// why the lock is on a constant sentinel inode, not on `info.json` (which is renamed on\n/// every write). The perch directory must already exist.\nfn lock_perch_sentinel(perch_path: &Path) -> std::io::Result<std::fs::File> {\n    use fs2::FileExt;\n    let lock = std::fs::OpenOptions::new()\n        .create(true)\n        .write(true)\n        .truncate(false)\n        .open(perch_path.join(\".info.lock\"))?;\n    lock.lock_exclusive()?; // RAII: released when the handle drops (incl. `?`) or on exit\n    Ok(lock)\n}\n\n/// [`write_info`] WITHOUT taking the per-perch lock — for the two callers that ALREADY\n/// hold it ([`mutate_info`], [`establish_locked`]); re-locking on a second `fs2` handle\n/// in the same process would deadlock. Every external caller uses the locking\n/// [`write_info`].\nfn write_info_unlocked(perch_path: &Path, info: &InfoJson) -> std::io::Result<()> {\n    let json = serde_json::to_string(info)\n        .map_err(|e| std::io::Error::new(std::io::ErrorKind::InvalidData, e))?;\n    atomic_write_string_durable(&perch_path.join(\"info.json\"), &json)\n}\n\n/// Atomically write `info` to `<perch_path>/info.json` (tmp + rename, EBUSY\n/// retry via the atomic layer). The perch directory must already exist.\n///\n/// Uses the **durable** atomic write (fsync-before-rename): the perch record is\n/// authoritative and its loss to a hard-reset NUL zero-fill is exactly the\n/// counter-39 #2 incident (a wiped record read back as a live ONLINE endpoint),\n/// so it is one of the few writers that pays the fsync (KNOWN-HAZARDS 5.13).\n///\n/// **Serialized** under the per-perch `.info.lock` (REQ-HAZARD-INFO-RMW-LOST-UPDATE):\n/// the whole-record write holds the lock across the durable fsync, so it can never\n/// interleave a concurrent daemon [`mutate_info`] RMW and be silently clobbered (the\n/// counter-39 #2 bind-vs-stamp lost update). This is ms-scale on these infrequent record\n/// writes — the same lock-across-fsync every `mutate_info` already does — NOT the\n/// per-keystroke W1b shape. Signature unchanged: every caller serializes for free.\n// [impl->REQ-HAZARD-INFO-JSON-TORN-READ]\n// [impl->REQ-HAZARD-PERCH-RECORD-POWER-LOSS]\n// [impl->REQ-HAZARD-INFO-RMW-LOST-UPDATE]\npub fn write_info(perch_path: &Path, info: &InfoJson) -> std::io::Result<()> {\n    let _lock = lock_perch_sentinel(perch_path)?;\n    write_info_unlocked(perch_path, info)\n}\n\n\n[Showing lines 860-919 of 2040. Use :920 to continue]"}],"details":{"truncation":{"content":"/// absent — the daemon only stamps perches it hosts.\r\n// [impl->REQ-WAKE-RESUME-LEG]\r\npub fn set_host_error(perch_path: &Path, reason: Option<&str>) -> std::io::Result<()> {\r\n    mutate_info(perch_path, |rec| {\r\n        rec.host_error = reason.map(str::to_string);\r\n    })\r\n}\r\n\r\n/// Number of read attempts before giving up (torn-read retry).\r\nconst READ_ATTEMPTS: u32 = 5;\r\n\r\n/// Acquire the per-perch write lock — the stable `<perch>/.info.lock` sentinel\r\n/// (created once, never renamed; advisory, auto-released on fd drop / process exit).\r\n/// Serializes ALL info.json writers so a whole-record write and a locked RMW can never\r\n/// lose each other's update (REQ-HAZARD-INFO-RMW-LOST-UPDATE). See [`mutate_info`] for\r\n/// why the lock is on a constant sentinel inode, not on `info.json` (which is renamed on\r\n/// every write). The perch directory must already exist.\r\nfn lock_perch_sentinel(perch_path: &Path) -> std::io::Result<std::fs::File> {\r\n    use fs2::FileExt;\r\n    let lock = std::fs::OpenOptions::new()\r\n        .create(true)\r\n        .write(true)\r\n        .truncate(false)\r\n        .open(perch_path.join(\".info.lock\"))?;\r\n    lock.lock_exclusive()?; // RAII: released when the handle drops (incl. `?`) or on exit\r\n    Ok(lock)\r\n}\r\n\r\n/// [`write_info`] WITHOUT taking the per-perch lock — for the two callers that ALREADY\r\n/// hold it ([`mutate_info`], [`establish_locked`]); re-locking on a second `fs2` handle\r\n/// in the same process would deadlock. Every external caller uses the locking\r\n/// [`write_info`].\r\nfn write_info_unlocked(perch_path: &Path, info: &InfoJson) -> std::io::Result<()> {\r\n    let json = serde_json::to_string(info)\r\n        .map_err(|e| std::io::Error::new(std::io::ErrorKind::InvalidData, e))?;\r\n    atomic_write_string_durable(&perch_path.join(\"info.json\"), &json)\r\n}\r\n\r\n/// Atomically write `info` to `<perch_path>/info.json` (tmp + rename, EBUSY\r\n/// retry via the atomic layer). The perch directory must already exist.\r\n///\r\n/// Uses the **durable** atomic write (fsync-before-rename): the perch record is\r\n/// authoritative and its loss to a hard-reset NUL zero-fill is exactly the\r\n/// counter-39 #2 incident (a wiped record read back as a live ONLINE endpoint),\r\n/// so it is one of the few writers that pays the fsync (KNOWN-HAZARDS 5.13).\r\n///\r\n/// **Serialized** under the per-perch `.info.lock` (REQ-HAZARD-INFO-RMW-LOST-UPDATE):\r\n/// the whole-record write holds the lock across the durable fsync, so it can never\r\n/// interleave a concurrent daemon [`mutate_info`] RMW and be silently clobbered (the\r\n/// counter-39 #2 bind-vs-stamp lost update). This is ms-scale on these infrequent record\r\n/// writes — the same lock-across-fsync every `mutate_info` already does — NOT the\r\n/// per-keystroke W1b shape. Signature unchanged: every caller serializes for free.\r\n// [impl->REQ-HAZARD-INFO-JSON-TORN-READ]\r\n// [impl->REQ-HAZARD-PERCH-RECORD-POWER-LOSS]\r\n// [impl->REQ-HAZARD-INFO-RMW-LOST-UPDATE]\r\npub fn write_info(perch_path: &Path, info: &InfoJson) -> std::io::Result<()> {\r\n    let _lock = lock_perch_sentinel(perch_path)?;\r\n    write_info_unlocked(perch_path, info)\r\n}\r\n\r","truncated":true,"truncatedBy":"lines","totalLines":1181,"totalBytes":3140,"outputLines":60,"outputBytes":3140,"lastLinePartial":false,"firstLineExceedsLimit":false},"totalLines":2040,"displayContent":{"text":"/// absent — the daemon only stamps perches it hosts.\r\n// [impl->REQ-WAKE-RESUME-LEG]\r\npub fn set_host_error(perch_path: &Path, reason: Option<&str>) -> std::io::Result<()> {\r\n    mutate_info(perch_path, |rec| {\r\n        rec.host_error = reason.map(str::to_string);\r\n    })\r\n}\r\n\r\n/// Number of read attempts before giving up (torn-read retry).\r\nconst READ_ATTEMPTS: u32 = 5;\r\n\r\n/// Acquire the per-perch write lock — the stable `<perch>/.info.lock` sentinel\r\n/// (created once, never renamed; advisory, auto-released on fd drop / process exit).\r\n/// Serializes ALL info.json writers so a whole-record write and a locked RMW can never\r\n/// lose each other's update (REQ-HAZARD-INFO-RMW-LOST-UPDATE). See [`mutate_info`] for\r\n/// why the lock is on a constant sentinel inode, not on `info.json` (which is renamed on\r\n/// every write). The perch directory must already exist.\r\nfn lock_perch_sentinel(perch_path: &Path) -> std::io::Result<std::fs::File> {\r\n    use fs2::FileExt;\r\n    let lock = std::fs::OpenOptions::new()\r\n        .create(true)\r\n        .write(true)\r\n        .truncate(false)\r\n        .open(perch_path.join(\".info.lock\"))?;\r\n    lock.lock_exclusive()?; // RAII: released when the handle drops (incl. `?`) or on exit\r\n    Ok(lock)\r\n}\r\n\r\n/// [`write_info`] WITHOUT taking the per-perch lock — for the two callers that ALREADY\r\n/// hold it ([`mutate_info`], [`establish_locked`]); re-locking on a second `fs2` handle\r\n/// in the same process would deadlock. Every external caller uses the locking\r\n/// [`write_info`].\r\nfn write_info_unlocked(perch_path: &Path, info: &InfoJson) -> std::io::Result<()> {\r\n    let json = serde_json::to_string(info)\r\n        .map_err(|e| std::io::Error::new(std::io::ErrorKind::InvalidData, e))?;\r\n    atomic_write_string_durable(&perch_path.join(\"info.json\"), &json)\r\n}\r\n\r\n/// Atomically write `info` to `<perch_path>/info.json` (tmp + rename, EBUSY\r\n/// retry via the atomic layer). The perch directory must already exist.\r\n///\r\n/// Uses the **durable** atomic write (fsync-before-rename): the perch record is\r\n/// authoritative and its loss to a hard-reset NUL zero-fill is exactly the\r\n/// counter-39 #2 incident (a wiped record read back as a live ONLINE endpoint),\r\n/// so it is one of the few writers that pays the fsync (KNOWN-HAZARDS 5.13).\r\n///\r\n/// **Serialized** under the per-perch `.info.lock` (REQ-HAZARD-INFO-RMW-LOST-UPDATE):\r\n/// the whole-record write holds the lock across the durable fsync, so it can never\r\n/// interleave a concurrent daemon [`mutate_info`] RMW and be silently clobbered (the\r\n/// counter-39 #2 bind-vs-stamp lost update). This is ms-scale on these infrequent record\r\n/// writes — the same lock-across-fsync every `mutate_info` already does — NOT the\r\n/// per-keystroke W1b shape. Signature unchanged: every caller serializes for free.\r\n// [impl->REQ-HAZARD-INFO-JSON-TORN-READ]\r\n// [impl->REQ-HAZARD-PERCH-RECORD-POWER-LOSS]\r\n// [impl->REQ-HAZARD-INFO-RMW-LOST-UPDATE]\r\npub fn write_info(perch_path: &Path, info: &InfoJson) -> std::io::Result<()> {\r\n    let _lock = lock_perch_sentinel(perch_path)?;\r\n    write_info_unlocked(perch_path, info)\r\n}\r\n\r","startLine":860,"lineNumbers":[860,861,862,863,864,865,866,867,868,869,870,871,872,873,874,875,876,877,878,879,880,881,882,883,884,885,886,887,888,889,890,891,892,893,894,895,896,897,898,899,900,901,902,903,904,905,906,907,908,909,910,911,912,913,914,915,916,917,918,919]},"fileSize":103485,"meta":{"source":{"type":"path","value":"C:\\Users\\decid\\Documents\\projects\\spt-core\\.worktrees\\hertz-ir86-disk-delta\\crates\\spt-store\\src\\info.rs"},"truncation":{"direction":"head","truncatedBy":"lines","totalLines":2040,"totalBytes":3140,"outputLines":60,"outputBytes":3140,"shownRange":{"start":860,"end":919},"nextOffset":920}}},"isError":false,"timestamp":1789483718291}}
{"type":"message","id":"f6d9dfa5","parentId":"d377b908","timestamp":"2026-09-15T14:48:38.293Z","message":{"role":"toolResult","toolCallId":"call_lLqFr89hvEsRVEKsQq5F2rsd|fc_043a862a419f59ae016aa95ac62a3c87d2ac6f6b7e058ea3df","toolName":"read","content":[{"type":"text","text":"    pub started_at: u64,\n}\n\n/// What the guard decided. `Refused` carries a stable reason token so a CI log\n/// grep can tell \"nothing to reap\" from \"we were about to kill a stranger\".\n#[derive(Clone, Copy, Debug, PartialEq, Eq)]\npub enum Verdict {\n    /// The pid authenticated; the kill was issued.\n    Killed,\n    /// No kill was issued. The token names why.\n    Refused(&'static str),\n}\n\n/// Resolve `<home>/daemon.pid` to a number, `None` when absent or unparseable.\npub fn breadcrumb_daemon_pid(home: &Path) -> Option<u32> {\n    std::fs::read_to_string(home.join(\"daemon.pid\"))\n        .ok()\n        .and_then(|txt| txt.trim().parse::<u32>().ok())\n}\n\n/// Capture `pid`'s identity NOW, for a later authenticated reap. Returns `None`\n/// when the platform has no identity oracle or the process is already gone — in\n/// which case the later reap simply runs without the creation-time pin (it still\n/// image-verifies).\npub fn observe(label: &str, pid: u32) -> Option<ProcObservation> {\n    match spt_store::proc::process_identity(pid) {\n        ProcIdentity::Present(started_at) => {\n            eprintln!(\"REAP[{label}]: observed pid={pid} started_at={started_at}\");\n            Some(ProcObservation { pid, started_at })\n        }\n        other => {\n            eprintln!(\"REAP[{label}]: pid={pid} not observable ({other:?}) — no identity pin\");\n            None\n        }\n    }\n}\n\n/// Do two paths name the SAME image?\n///\n/// Canonicalize both sides first: one side comes from the OS (`exe_path`, always\n/// OS-normalized) and the other from the test (`CARGO_BIN_EXE_spt`, spelled\n/// however `CARGO_TARGET_DIR` was spelled), so a bare string compare reads\n/// `…/debug\\spt.exe` and `…\\debug\\spt.exe` as DIFFERENT binaries — a guard that\n/// refuses its own daemon, which is a leak plus a false red, not a safe default.\n/// Windows adds case-insensitivity on top.\npub fn same_image(left: &Path, right: &Path) -> bool {\n    fn canonical(p: &Path) -> PathBuf {\n        std::fs::canonicalize(p).unwrap_or_else(|_| p.to_path_buf())\n    }\n    let (left, right) = (canonical(left), canonical(right));\n    #[cfg(windows)]\n\n[Showing lines 45-95 of 472. Use :96 to continue]"}],"details":{"truncation":{"content":"    pub started_at: u64,\r\n}\r\n\r\n/// What the guard decided. `Refused` carries a stable reason token so a CI log\r\n/// grep can tell \"nothing to reap\" from \"we were about to kill a stranger\".\r\n#[derive(Clone, Copy, Debug, PartialEq, Eq)]\r\npub enum Verdict {\r\n    /// The pid authenticated; the kill was issued.\r\n    Killed,\r\n    /// No kill was issued. The token names why.\r\n    Refused(&'static str),\r\n}\r\n\r\n/// Resolve `<home>/daemon.pid` to a number, `None` when absent or unparseable.\r\npub fn breadcrumb_daemon_pid(home: &Path) -> Option<u32> {\r\n    std::fs::read_to_string(home.join(\"daemon.pid\"))\r\n        .ok()\r\n        .and_then(|txt| txt.trim().parse::<u32>().ok())\r\n}\r\n\r\n/// Capture `pid`'s identity NOW, for a later authenticated reap. Returns `None`\r\n/// when the platform has no identity oracle or the process is already gone — in\r\n/// which case the later reap simply runs without the creation-time pin (it still\r\n/// image-verifies).\r\npub fn observe(label: &str, pid: u32) -> Option<ProcObservation> {\r\n    match spt_store::proc::process_identity(pid) {\r\n        ProcIdentity::Present(started_at) => {\r\n            eprintln!(\"REAP[{label}]: observed pid={pid} started_at={started_at}\");\r\n            Some(ProcObservation { pid, started_at })\r\n        }\r\n        other => {\r\n            eprintln!(\"REAP[{label}]: pid={pid} not observable ({other:?}) — no identity pin\");\r\n            None\r\n        }\r\n    }\r\n}\r\n\r\n/// Do two paths name the SAME image?\r\n///\r\n/// Canonicalize both sides first: one side comes from the OS (`exe_path`, always\r\n/// OS-normalized) and the other from the test (`CARGO_BIN_EXE_spt`, spelled\r\n/// however `CARGO_TARGET_DIR` was spelled), so a bare string compare reads\r\n/// `…/debug\\spt.exe` and `…\\debug\\spt.exe` as DIFFERENT binaries — a guard that\r\n/// refuses its own daemon, which is a leak plus a false red, not a safe default.\r\n/// Windows adds case-insensitivity on top.\r\npub fn same_image(left: &Path, right: &Path) -> bool {\r\n    fn canonical(p: &Path) -> PathBuf {\r\n        std::fs::canonicalize(p).unwrap_or_else(|_| p.to_path_buf())\r\n    }\r\n    let (left, right) = (canonical(left), canonical(right));\r\n    #[cfg(windows)]\r","truncated":true,"truncatedBy":"lines","totalLines":428,"totalBytes":2181,"outputLines":51,"outputBytes":2181,"lastLinePartial":false,"firstLineExceedsLimit":false},"totalLines":472,"displayContent":{"text":"    pub started_at: u64,\r\n}\r\n\r\n/// What the guard decided. `Refused` carries a stable reason token so a CI log\r\n/// grep can tell \"nothing to reap\" from \"we were about to kill a stranger\".\r\n#[derive(Clone, Copy, Debug, PartialEq, Eq)]\r\npub enum Verdict {\r\n    /// The pid authenticated; the kill was issued.\r\n    Killed,\r\n    /// No kill was issued. The token names why.\r\n    Refused(&'static str),\r\n}\r\n\r\n/// Resolve `<home>/daemon.pid` to a number, `None` when absent or unparseable.\r\npub fn breadcrumb_daemon_pid(home: &Path) -> Option<u32> {\r\n    std::fs::read_to_string(home.join(\"daemon.pid\"))\r\n        .ok()\r\n        .and_then(|txt| txt.trim().parse::<u32>().ok())\r\n}\r\n\r\n/// Capture `pid`'s identity NOW, for a later authenticated reap. Returns `None`\r\n/// when the platform has no identity oracle or the process is already gone — in\r\n/// which case the later reap simply runs without the creation-time pin (it still\r\n/// image-verifies).\r\npub fn observe(label: &str, pid: u32) -> Option<ProcObservation> {\r\n    match spt_store::proc::process_identity(pid) {\r\n        ProcIdentity::Present(started_at) => {\r\n            eprintln!(\"REAP[{label}]: observed pid={pid} started_at={started_at}\");\r\n            Some(ProcObservation { pid, started_at })\r\n        }\r\n        other => {\r\n            eprintln!(\"REAP[{label}]: pid={pid} not observable ({other:?}) — no identity pin\");\r\n            None\r\n        }\r\n    }\r\n}\r\n\r\n/// Do two paths name the SAME image?\r\n///\r\n/// Canonicalize both sides first: one side comes from the OS (`exe_path`, always\r\n/// OS-normalized) and the other from the test (`CARGO_BIN_EXE_spt`, spelled\r\n/// however `CARGO_TARGET_DIR` was spelled), so a bare string compare reads\r\n/// `…/debug\\spt.exe` and `…\\debug\\spt.exe` as DIFFERENT binaries — a guard that\r\n/// refuses its own daemon, which is a leak plus a false red, not a safe default.\r\n/// Windows adds case-insensitivity on top.\r\npub fn same_image(left: &Path, right: &Path) -> bool {\r\n    fn canonical(p: &Path) -> PathBuf {\r\n        std::fs::canonicalize(p).unwrap_or_else(|_| p.to_path_buf())\r\n    }\r\n    let (left, right) = (canonical(left), canonical(right));\r\n    #[cfg(windows)]\r","startLine":45,"lineNumbers":[45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95]},"fileSize":21487,"meta":{"source":{"type":"path","value":"C:\\Users\\decid\\Documents\\projects\\spt-core\\.worktrees\\hertz-ir86-disk-delta\\crates\\spt\\tests\\common\\reap.rs"},"truncation":{"direction":"head","truncatedBy":"lines","totalLines":472,"totalBytes":2181,"outputLines":51,"outputBytes":2181,"shownRange":{"start":45,"end":95},"nextOffset":96}}},"isError":false,"timestamp":1789483718293}}
{"type":"message","id":"359b56fb","parentId":"f6d9dfa5","timestamp":"2026-09-15T14:48:38.309Z","message":{"role":"toolResult","toolCallId":"call_0dFwMdwurXOJ4GOUa2DCjbMl|fc_043a862a419f59ae016aa95ac62a5887d2b37d403d0833fd2b","toolName":"grep","content":[{"type":"text","text":"# .worktrees/hertz-ir86-disk-delta/.github/workflows/\n## ci.yml\n 252|      - name: Precheck traceable-reqs pin and runner\n*253|        run: bash .github/ci/traceable-reqs.sh precheck\n 254|        env:\n 255|          GH_TOKEN: ${{ secrets.TRACEABLE_REQS_TOKEN }}\n 256|      - name: Install traceable-reqs\n*257|        run: bash .github/ci/traceable-reqs.sh install\n 258|        env:\n 259|          GH_TOKEN: ${{ secrets.TRACEABLE_REQS_TOKEN }}\n 260|      - name: Coverage gate\n## golden.yml\n 365|        shell: bash\n*366|        run: bash .github/ci/ci-notify-selftest.sh\n 367|\n 368|      # [unit->REQ-RELEASE-VERSION-TAG-ASSERT]\n 369|      # The assert this covers lives in release.yml, which is TAG-TRIGGERED: one\n...\n 1442|      - name: Precheck traceable-reqs pin and runner\n*1443|        run: bash .github/ci/traceable-reqs.sh precheck\n 1444|        env:\n 1445|          GH_TOKEN: ${{ secrets.TRACEABLE_REQS_TOKEN }}\n 1446|      - name: Install traceable-reqs\n*1447|        run: bash .github/ci/traceable-reqs.sh install\n 1448|        env:\n 1449|          # Cross-org private repo: the default repo-scoped GITHUB_TOKEN cannot\n 1450|          # read BigscreenVR/traceable-reqs. Supply a PAT with read access to it"}],"details":{"scopePath":".worktrees/hertz-ir86-disk-delta/CHANGELOG.md, .worktrees/hertz-ir86-disk-delta/docs/GOLDEN-CI.md, .worktrees/hertz-ir86-disk-delta/.github/workflows, .worktrees/hertz-ir86-disk-delta/crates/xtask/src/main.rs","searchPath":"C:\\Users\\decid\\Documents\\projects\\spt-core\\.worktrees\\hertz-ir86-disk-delta","cwd":"C:\\Users\\decid\\Documents\\projects\\spt-core","matchCount":5,"fileCount":2,"files":[".worktrees/hertz-ir86-disk-delta/.github/workflows/ci.yml",".worktrees/hertz-ir86-disk-delta/.github/workflows/golden.yml"],"fileMatches":[{"path":".worktrees/hertz-ir86-disk-delta/.github/workflows/ci.yml","count":2},{"path":".worktrees/hertz-ir86-disk-delta/.github/workflows/golden.yml","count":3}],"truncated":false,"displayContent":"# .worktrees/hertz-ir86-disk-delta/.github/workflows/\n## ci.yml\n 252│      - name: Precheck traceable-reqs pin and runner\n*253│        run: bash .github/ci/traceable-reqs.sh precheck\n 254│        env:\n 255│          GH_TOKEN: ${{ secrets.TRACEABLE_REQS_TOKEN }}\n 256│      - name: Install traceable-reqs\n*257│        run: bash .github/ci/traceable-reqs.sh install\n 258│        env:\n 259│          GH_TOKEN: ${{ secrets.TRACEABLE_REQS_TOKEN }}\n 260│      - name: Coverage gate\n## golden.yml\n  365│        shell: bash\n *366│        run: bash .github/ci/ci-notify-selftest.sh\n  367│\n  368│      # [unit->REQ-RELEASE-VERSION-TAG-ASSERT]\n  369│      # The assert this covers lives in release.yml, which is TAG-TRIGGERED: one\n     │...\n 1442│      - name: Precheck traceable-reqs pin and runner\n*1443│        run: bash .github/ci/traceable-reqs.sh precheck\n 1444│        env:\n 1445│          GH_TOKEN: ${{ secrets.TRACEABLE_REQS_TOKEN }}\n 1446│      - name: Install traceable-reqs\n*1447│        run: bash .github/ci/traceable-reqs.sh install\n 1448│        env:\n 1449│          # Cross-org private repo: the default repo-scoped GITHUB_TOKEN cannot\n 1450│          # read BigscreenVR/traceable-reqs. Supply a PAT with read access to it"},"isError":false,"timestamp":1789483718309}}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_4j3i5ZjrpTJlnslPSvzBfsXT|fc_043a862a419f59ae016aa95ad2681887d2805389ec9250bb0e","toolName":"hub","startedAt":"2026-09-15T14:48:50.752Z","intent":"Sharing stale metadata findings"},"id":"0709327b","parentId":"359b56fb","timestamp":"2026-09-15T14:48:50.752Z"}
{"type":"message","id":"e52d2ba9","parentId":"0709327b","timestamp":"2026-09-15T14:48:50.753Z","message":{"role":"assistant","content":[{"type":"thinking","thinking":"**Checking IR69 conversion status**\n\n**Marking IR2 blocked**"},{"type":"toolCall","id":"call_4j3i5ZjrpTJlnslPSvzBfsXT|fc_043a862a419f59ae016aa95ad2681887d2805389ec9250bb0e","name":"hub","arguments":{"i":"Sharing stale metadata findings","op":"send","to":"Main","message":"IR1–70 sweep found built-but-OPEN metadata: IR32 help_for rejects nonzero/empty output (xtask main.rs:98-124); IR47 attribution warnings + doyle split shipped (ci-notify.sh:193-210); IR58 cargo-metadata duplicate-bin gate shipped (binnames.rs/main.rs:769); IR37 both workflows now consume shared 0.4.1 pin with placement on. IR40 arm B also already labels supplied-needs vs run conclusion. Do not redispatch these. Full inventory follows."},"intent":"Sharing stale metadata findings"}],"api":"openai-codex-responses","provider":"openai-codex","model":"gpt-6-astra","usage":{"input":7322,"output":301,"cacheRead":144128,"cacheWrite":0,"totalTokens":151751,"reasoningTokens":155,"cost":{"input":0.07322000000000001,"output":0.015050000000000001,"cacheRead":0.144128,"cacheWrite":0,"total":0.23239800000000002}},"stopReason":"toolUse","timestamp":1789483718343,"responseId":"resp_043a862a419f59ae016aa95ac698c887d2a9c7af1523c5dbe9","providerPayload":{"type":"openaiResponsesHistory","provider":"openai-codex","dt":true,"items":[{"id":"rs_043a862a419f59ae016aa95ac8fce487d28bcbc896713f5ee5","type":"reasoning","content":[],"encrypted_content":"gAAAAABqqVrSvBR3QLPh5oEI7IlpRY--tFAQdnEF0p65m9xOzuhDD_UAflw9EQYZlTOPmkied-f7DBUwX8LPmDplLPmULQ8vtABV4pYk8UcZYwA0Yt2ZggvGL6iC6xSgSrjiVVR-XDnT0l3Rdqtkrtq9RVhQOVfa6SlDRDouFr1u638Ta8dWFOIm8oJf1unJKLgHK533LRUV_1HJRtJ1HoN3j451Iz09dSbRiBRIxOMR7lxTD3c6Ym-TIaABfDC2ybB0_SzUuwKJxTveOKr45p5cs4OR5qTfGttjOz5f7K8l7yfYOl__iA7i8YbT8IR0m1xpRNM5f6pKGtV1KqvI6wtcgPtz-Q-2scx0oTjvf41tb6hrOTB3vN2Nr8wNS7RUTzFCkuMmltwNFqFw37WXdulJAtPxpyQJxhDXNWAY7HX33Y-C-as2OMoBAwBQ5TTY444xBk6ziDrlqQfVcGwVXHKqg5GfLwoaXFudlfUs-Lxj2rpwlL6oxg1vUVviPcDvl_OI8QWt05xbVx-ckI6hLAs7un2VxGA1OpZ66nBpSCILqK2wHlxH5PZ4HAz0icraV5fFs9L5cPoJuKT2CA4sKZ9yw7NvuguuHhNMzodLPo7p5tU-enX-xwW_1i7HNCrbt3y6sWXRlICMquvllqur1FX3lmC_e1WffZ8w0pZpGvNCu6HLmspf6pMoH4yVpr4iR1nDNp0D9C4OQGtgBSbPRZMaAt9aqbyH_p0v5Ugn-8HehCdOe0qb508gmjZR0IUlZ-p-k7P_RAifEiTC4xfIUKU57HoCnnSTCAirZx8mR1sNS-wXC8Y0JbvD6SU7bniIUnZH_vAGn6rJNRMmzI9_ZwNAfWoSpPNEoCkmSRXcOLOkK59SvXNkKF2V4Pk8BEkSQLT9wU6d7Ir0P1hm1n9OFHYJ4MZ7keI-3pX9aqjBQ2H4JYITQC5QTyh14VqpWjvn-diJRsLXkDd6xAtBU_00WruuNzuwIMthgNvvGF7Wk9lOVG4H3wte8TgXkVg0w7KLYoIx4f5GweAAp42HjSMiWEAgpRooFgvWVpAztjn2GOdH3kiMkLGzNN7hGw9vhwsmQE8fUXoCehKZXehB76KA8UIv9Xm-khgyHrVJASNwdE8Y0xkhtpq3PuavSrDzzx_jg-gHxU9xYyYqunVHtekySSa5is6oQjLaf7edeFQZdBMx0gTnvwLBiJEiNLaRHijicnVwROstBdRAoLUCiajzuVFdbMVSyDVSSwuXtFukChz4UaDjtxgH00-ZM8uPTsa4vZ45zw3M3JLbQiqIHSgTm8LeQSXUZfP5KaSIUWn8CUi1I9ui41b3MuIDUMJNh1mp94wMkDT0_S05_l7a28IBG5UtQhDhh3cKWvW9d2t8x5xWpF4U70ISR-fIl5szcWwd-JQrDgs7T41BUTFrITwyhMFBwNYcwIMKLKrUhBnUAGxXQEC8DDbJy94wTFResK2VWpXqFhqKlp5DR8zVJ0cwEuRHpiTXwvon3EJy0KTH1dHppvkueo8CTI5USUasWYPjQdxdMfeBja8Gdcx1TTVCv690uc1GRo-h3cF5-E9Gwqo7bHhXyHKhpkZWk86FwNuzQsuaQyClMwzh7Ns_lUP6acmU4ZRvn_M2J001QhBuhepTJ3qaVas3NKwRyxqnGfyjZHriY8hS_7B1OgG-eT85pHFe2dWFcp4VUynufAEINiZx-igMWH9XbC8MiZ87hS8MsIxHfVWwMqLwYL53C6Y_6D4q72hECj6Yx9kXNet8Xbj4sSaQkFQr719PCfboR88R1g6wx_AjUdoYPhR1tg728oTj4p1HwZXSjHOnzcnzRGNwfuLJ-9BZWYrc-cBqDvzdRszrOejGVMgPe313z7AIJkb32-25R4LcFUD_pTsYd68SiZMaq3WZ1KlF6l_ao3zlLOAEyloSJFrkTHxHXYMEZvIPPH0MLkhaWEcoy3Ur7Tj-n_jMGmC_6iMZ-_u1jao7JrTCI304Noa-FTu5Z0-amLY9z79jvg19jRwMemRKV5ifd4ZRaWpSxy4q3ta20VOZRxpmLPX3gqzghQUgddRCO3zeZ7Q2YCXdt-n0v7f9PI5BnHbfotedzECGCNgQDzh3UGgohZjxhFKIBgSDowhEp6DAiyVNpq8YfoUUZfJ9w30dj_MtaQjNwq1AEQa3O47BHpy3eV6tBaA0F-ZDQr4y7UZ3JnzdOc4oEg==","internal_chat_message_metadata_passthrough":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"},"summary":[{"type":"summary_text","text":"**Checking IR69 conversion status**"},{"type":"summary_text","text":"**Marking IR2 blocked**"}],"metadata":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"}},{"id":"fc_043a862a419f59ae016aa95ad2681887d2805389ec9250bb0e","type":"function_call","status":"completed","arguments":"{\"i\":\"Sharing stale metadata findings\",\"op\":\"send\",\"to\":\"Main\",\"message\":\"IR1–70 sweep found built-but-OPEN metadata: IR32 help_for rejects nonzero/empty output (xtask main.rs:98-124); IR47 attribution warnings + doyle split shipped (ci-notify.sh:193-210); IR58 cargo-metadata duplicate-bin gate shipped (binnames.rs/main.rs:769); IR37 both workflows now consume shared 0.4.1 pin with placement on. IR40 arm B also already labels supplied-needs vs run conclusion. Do not redispatch these. Full inventory follows.\"}","call_id":"call_4j3i5ZjrpTJlnslPSvzBfsXT","internal_chat_message_metadata_passthrough":{"create_time":1789483718.770912,"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"},"name":"hub","metadata":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"}}]},"duration":12407.929399996996,"ttft":2668.3375000059605,"completedAt":1789483730751,"contextSnapshot":{"promptTokens":151450,"nonMessageTokens":10342,"compactionEpoch":0}}}
{"type":"message","id":"89593ead","parentId":"e52d2ba9","timestamp":"2026-09-15T14:48:50.753Z","message":{"role":"toolResult","toolCallId":"call_4j3i5ZjrpTJlnslPSvzBfsXT|fc_043a862a419f59ae016aa95ad2681887d2805389ec9250bb0e","toolName":"hub","content":[{"type":"text","text":"Delivered to 1 peer(s):\n- Main: injected"}],"details":{"op":"send","from":"RegisterEarlier","to":"Main","receipts":[{"to":"Main","outcome":"injected"}]},"isError":false,"timestamp":1789483730753}}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_o3oJL98ydPaF8qEIvsqZL576|fc_043a862a419f59ae016aa95ae244bc87d293ecef5617030c24","toolName":"read","startedAt":"2026-09-15T14:49:06.401Z","args":{"path":".worktrees/hertz-ir86-disk-delta/.github/ci/ci-notify.sh:125-153:raw"},"intent":"Reading notification and write boundaries"},"id":"389ae688","parentId":"89593ead","timestamp":"2026-09-15T14:49:06.401Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_TnjErg5Tx8sbajxEPCboiMGz|fc_043a862a419f59ae016aa95ae244d487d285767da4a8fe419c","toolName":"read","startedAt":"2026-09-15T14:49:06.401Z","args":{"path":".worktrees/hertz-ir86-disk-delta/crates/xtask/src/main.rs:321-408,740-770:raw"},"intent":"Reading generator evidence boundary"},"id":"0245df6d","parentId":"389ae688","timestamp":"2026-09-15T14:49:06.401Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_H8fNF99TgBvfC98mkA9WCs0Y|fc_043a862a419f59ae016aa95ae244e087d2a80f4e98da073b4a","toolName":"read","startedAt":"2026-09-15T14:49:06.401Z","args":{"path":".worktrees/hertz-ir86-disk-delta/.github/ci/find-cwd-holders.ps1:76-110:raw"},"intent":"Reading live holder output schema"},"id":"01211ef5","parentId":"0245df6d","timestamp":"2026-09-15T14:49:06.401Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_KQhkVlhBkR9YoYA0cQlYPIUE|fc_043a862a419f59ae016aa95ae244ec87d2aee60581603c3a88","toolName":"read","startedAt":"2026-09-15T14:49:06.401Z","args":{"path":".worktrees/hertz-ir86-disk-delta/crates/spt-poolguard/src/lib.rs:403-452:raw"},"intent":"Reading ancestry fallback boundary"},"id":"4b1821f1","parentId":"01211ef5","timestamp":"2026-09-15T14:49:06.401Z"}
{"type":"message","id":"0da189d7","parentId":"4b1821f1","timestamp":"2026-09-15T14:49:06.402Z","message":{"role":"assistant","content":[{"type":"toolCall","id":"call_o3oJL98ydPaF8qEIvsqZL576|fc_043a862a419f59ae016aa95ae244bc87d293ecef5617030c24","name":"read","arguments":{"i":"Reading notification and write boundaries","path":".worktrees/hertz-ir86-disk-delta/.github/ci/ci-notify.sh:125-153:raw"},"intent":"Reading notification and write boundaries"},{"type":"toolCall","id":"call_TnjErg5Tx8sbajxEPCboiMGz|fc_043a862a419f59ae016aa95ae244d487d285767da4a8fe419c","name":"read","arguments":{"i":"Reading generator evidence boundary","path":".worktrees/hertz-ir86-disk-delta/crates/xtask/src/main.rs:321-408,740-770:raw"},"intent":"Reading generator evidence boundary"},{"type":"toolCall","id":"call_H8fNF99TgBvfC98mkA9WCs0Y|fc_043a862a419f59ae016aa95ae244e087d2a80f4e98da073b4a","name":"read","arguments":{"i":"Reading live holder output schema","path":".worktrees/hertz-ir86-disk-delta/.github/ci/find-cwd-holders.ps1:76-110:raw"},"intent":"Reading live holder output schema"},{"type":"toolCall","id":"call_KQhkVlhBkR9YoYA0cQlYPIUE|fc_043a862a419f59ae016aa95ae244ec87d2aee60581603c3a88","name":"read","arguments":{"i":"Reading ancestry fallback boundary","path":".worktrees/hertz-ir86-disk-delta/crates/spt-poolguard/src/lib.rs:403-452:raw"},"intent":"Reading ancestry fallback boundary"},{"type":"toolCall","id":"call_GzJOUxs1FrBJLAAycY8hi0xQ|fc_043a862a419f59ae016aa95ae244f887d2a7f3faf16727b788","name":"read","arguments":{"i":"Reading current driver admission contract","path":".worktrees/hertz-ir86-disk-delta/.github/ci/local-lane.py:1-16,270-310,358-407:raw"},"intent":"Reading current driver admission contract"},{"type":"toolCall","id":"call_IyhxRu0FB0EajAkwA41XHZeQ|fc_043a862a419f59ae016aa95ae2450487d2a930df8b31140dac","name":"grep","arguments":{"i":"Checking residual test caller population","pattern":"fn mock_pid|fn brain_ready|is_clean|no-breadcrumb|fn check_unique|check_unique|check_bin","path":".worktrees/hertz-ir86-disk-delta/crates/spt/tests/resident_service_e2e.rs;.worktrees/hertz-ir86-disk-delta/crates/spt/tests/common/reap.rs;.worktrees/hertz-ir86-disk-delta/crates/xtask/src/main.rs","case":null,"gitignore":false,"skip":null},"intent":"Checking residual test caller population"}],"api":"openai-codex-responses","provider":"openai-codex","model":"gpt-6-astra","usage":{"input":151773,"output":384,"cacheRead":0,"cacheWrite":0,"totalTokens":152157,"cost":{"input":1.51773,"output":0.019200000000000002,"cacheRead":0,"cacheWrite":0,"total":1.5369300000000001}},"stopReason":"toolUse","timestamp":1789483730762,"responseId":"resp_043a862a419f59ae016aa95ad3183487d2a72844002babd5f0","providerPayload":{"type":"openaiResponsesHistory","provider":"openai-codex","dt":true,"items":[{"id":"fc_043a862a419f59ae016aa95ae244bc87d293ecef5617030c24","type":"function_call","status":"completed","arguments":"{\"i\":\"Reading notification and write boundaries\",\"path\":\".worktrees/hertz-ir86-disk-delta/.github/ci/ci-notify.sh:125-153:raw\"}","call_id":"call_o3oJL98ydPaF8qEIvsqZL576","internal_chat_message_metadata_passthrough":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"},"name":"read","metadata":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"}},{"id":"fc_043a862a419f59ae016aa95ae244d487d285767da4a8fe419c","type":"function_call","status":"completed","arguments":"{\"i\":\"Reading generator evidence boundary\",\"path\":\".worktrees/hertz-ir86-disk-delta/crates/xtask/src/main.rs:321-408,740-770:raw\"}","call_id":"call_TnjErg5Tx8sbajxEPCboiMGz","internal_chat_message_metadata_passthrough":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"},"name":"read","metadata":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"}},{"id":"fc_043a862a419f59ae016aa95ae244e087d2a80f4e98da073b4a","type":"function_call","status":"completed","arguments":"{\"i\":\"Reading live holder output schema\",\"path\":\".worktrees/hertz-ir86-disk-delta/.github/ci/find-cwd-holders.ps1:76-110:raw\"}","call_id":"call_H8fNF99TgBvfC98mkA9WCs0Y","internal_chat_message_metadata_passthrough":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"},"name":"read","metadata":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"}},{"id":"fc_043a862a419f59ae016aa95ae244ec87d2aee60581603c3a88","type":"function_call","status":"completed","arguments":"{\"i\":\"Reading ancestry fallback boundary\",\"path\":\".worktrees/hertz-ir86-disk-delta/crates/spt-poolguard/src/lib.rs:403-452:raw\"}","call_id":"call_KQhkVlhBkR9YoYA0cQlYPIUE","internal_chat_message_metadata_passthrough":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"},"name":"read","metadata":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"}},{"id":"fc_043a862a419f59ae016aa95ae244f887d2a7f3faf16727b788","type":"function_call","status":"completed","arguments":"{\"i\":\"Reading current driver admission contract\",\"path\":\".worktrees/hertz-ir86-disk-delta/.github/ci/local-lane.py:1-16,270-310,358-407:raw\"}","call_id":"call_GzJOUxs1FrBJLAAycY8hi0xQ","internal_chat_message_metadata_passthrough":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"},"name":"read","metadata":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"}},{"id":"fc_043a862a419f59ae016aa95ae2450487d2a930df8b31140dac","type":"function_call","status":"completed","arguments":"{\"i\":\"Checking residual test caller population\",\"pattern\":\"fn mock_pid|fn brain_ready|is_clean|no-breadcrumb|fn check_unique|check_unique|check_bin\",\"path\":\".worktrees/hertz-ir86-disk-delta/crates/spt/tests/resident_service_e2e.rs;.worktrees/hertz-ir86-disk-delta/crates/spt/tests/common/reap.rs;.worktrees/hertz-ir86-disk-delta/crates/xtask/src/main.rs\",\"case\":null,\"gitignore\":false,\"skip\":null}","call_id":"call_IyhxRu0FB0EajAkwA41XHZeQ","internal_chat_message_metadata_passthrough":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"},"name":"grep","metadata":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"}}]},"duration":15624.090200006962,"ttft":15535.491000026464,"completedAt":1789483746397,"contextSnapshot":{"promptTokens":151773,"nonMessageTokens":10342,"compactionEpoch":0}}}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_GzJOUxs1FrBJLAAycY8hi0xQ|fc_043a862a419f59ae016aa95ae244f887d2a7f3faf16727b788","toolName":"read","startedAt":"2026-09-15T14:49:06.402Z","args":{"path":".worktrees/hertz-ir86-disk-delta/.github/ci/local-lane.py:1-16,270-310,358-407:raw"},"intent":"Reading current driver admission contract"},"id":"9c14668a","parentId":"0da189d7","timestamp":"2026-09-15T14:49:06.402Z"}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_IyhxRu0FB0EajAkwA41XHZeQ|fc_043a862a419f59ae016aa95ae2450487d2a930df8b31140dac","toolName":"grep","startedAt":"2026-09-15T14:49:06.402Z","args":{"path":".worktrees/hertz-ir86-disk-delta/crates/spt/tests/resident_service_e2e.rs;.worktrees/hertz-ir86-disk-delta/crates/spt/tests/common/reap.rs;.worktrees/hertz-ir86-disk-delta/crates/xtask/src/main.rs"},"intent":"Checking residual test caller population"},"id":"a43fde17","parentId":"9c14668a","timestamp":"2026-09-15T14:49:06.402Z"}
{"type":"message","id":"9ce969d2","parentId":"a43fde17","timestamp":"2026-09-15T14:49:06.414Z","message":{"role":"toolResult","toolCallId":"call_o3oJL98ydPaF8qEIvsqZL576|fc_043a862a419f59ae016aa95ae244bc87d293ecef5617030c24","toolName":"read","content":[{"type":"text","text":"# Writes the notification body to stdout. Split out from the send path for the\n# same reason `compute_verdict` is: the body's wording is part of the contract\n# (see the CANCELLED note above), so the selftest has to be able to read it\n# without a daemon, a subnet or a recipient.\n# IR-40 arm B: even a correct needs verdict cannot cover the notifying job.\n# [impl->REQ-CI-NOTIFY-SCOPE]\ncompose_body() {\n  echo \"CI NEEDS $verdict — ${GITHUB_REPOSITORY##*/} @ ${GITHUB_REF_NAME:-<unknown ref>}\"\n  echo \"scope: notify step in job ${GITHUB_JOB:-<unknown job>}; supplied needs results only (notifying job excluded)\"\n  echo \"run conclusion: not observed — check the run itself\"\n  [ -n \"$PR_NUMBER\" ] && echo \"PR: #$PR_NUMBER\"\n  echo \"sha: $(printf '%.12s' \"$GITHUB_SHA\")\"\n  [ -n \"$failing\" ] && echo \"failing: $failing\"\n  [ -n \"$cancelled\" ] && echo \"cancelled: $cancelled\"\n  echo \"run: $GITHUB_SERVER_URL/$GITHUB_REPOSITORY/actions/runs/$GITHUB_RUN_ID\"\n  return 0\n}\n\n# --- library seam ----------------------------------------------------------\n# Sourced with SPT_CI_NOTIFY_LIB=1, this file defines the classification and\n# body-composition functions and stops — no `spt` probe, no daemon probe, no\n# recipients, no sends. Same seam as `reap-census.sh`'s SPT_CI_REAP_LIB, and for\n# the same reason: below this line the script's first act on a runner without\n# `spt` is `exit 0`, and on a runner WITH it the next act is a real send, so the\n# verdict logic is untestable in place. `return` when sourced, and refuse to be\n# EXECUTED with the flag set — that combination means the caller thinks it is\n# sourcing and would otherwise get a silent exit-0 no-op.\nif [ \"${SPT_CI_NOTIFY_LIB:-}\" = \"1\" ]; then\n  (return 0 2>/dev/null) && return 0\n\n[Showing lines 125-153 of 276. Use :154 to continue]"}],"details":{"truncation":{"content":"# Writes the notification body to stdout. Split out from the send path for the\n# same reason `compute_verdict` is: the body's wording is part of the contract\n# (see the CANCELLED note above), so the selftest has to be able to read it\n# without a daemon, a subnet or a recipient.\n# IR-40 arm B: even a correct needs verdict cannot cover the notifying job.\n# [impl->REQ-CI-NOTIFY-SCOPE]\ncompose_body() {\n  echo \"CI NEEDS $verdict — ${GITHUB_REPOSITORY##*/} @ ${GITHUB_REF_NAME:-<unknown ref>}\"\n  echo \"scope: notify step in job ${GITHUB_JOB:-<unknown job>}; supplied needs results only (notifying job excluded)\"\n  echo \"run conclusion: not observed — check the run itself\"\n  [ -n \"$PR_NUMBER\" ] && echo \"PR: #$PR_NUMBER\"\n  echo \"sha: $(printf '%.12s' \"$GITHUB_SHA\")\"\n  [ -n \"$failing\" ] && echo \"failing: $failing\"\n  [ -n \"$cancelled\" ] && echo \"cancelled: $cancelled\"\n  echo \"run: $GITHUB_SERVER_URL/$GITHUB_REPOSITORY/actions/runs/$GITHUB_RUN_ID\"\n  return 0\n}\n\n# --- library seam ----------------------------------------------------------\n# Sourced with SPT_CI_NOTIFY_LIB=1, this file defines the classification and\n# body-composition functions and stops — no `spt` probe, no daemon probe, no\n# recipients, no sends. Same seam as `reap-census.sh`'s SPT_CI_REAP_LIB, and for\n# the same reason: below this line the script's first act on a runner without\n# `spt` is `exit 0`, and on a runner WITH it the next act is a real send, so the\n# verdict logic is untestable in place. `return` when sourced, and refuse to be\n# EXECUTED with the flag set — that combination means the caller thinks it is\n# sourcing and would otherwise get a silent exit-0 no-op.\nif [ \"${SPT_CI_NOTIFY_LIB:-}\" = \"1\" ]; then\n  (return 0 2>/dev/null) && return 0","truncated":true,"truncatedBy":"lines","totalLines":152,"totalBytes":1737,"outputLines":29,"outputBytes":1737,"lastLinePartial":false,"firstLineExceedsLimit":false},"totalLines":276,"displayContent":{"text":"# Writes the notification body to stdout. Split out from the send path for the\n# same reason `compute_verdict` is: the body's wording is part of the contract\n# (see the CANCELLED note above), so the selftest has to be able to read it\n# without a daemon, a subnet or a recipient.\n# IR-40 arm B: even a correct needs verdict cannot cover the notifying job.\n# [impl->REQ-CI-NOTIFY-SCOPE]\ncompose_body() {\n  echo \"CI NEEDS $verdict — ${GITHUB_REPOSITORY##*/} @ ${GITHUB_REF_NAME:-<unknown ref>}\"\n  echo \"scope: notify step in job ${GITHUB_JOB:-<unknown job>}; supplied needs results only (notifying job excluded)\"\n  echo \"run conclusion: not observed — check the run itself\"\n  [ -n \"$PR_NUMBER\" ] && echo \"PR: #$PR_NUMBER\"\n  echo \"sha: $(printf '%.12s' \"$GITHUB_SHA\")\"\n  [ -n \"$failing\" ] && echo \"failing: $failing\"\n  [ -n \"$cancelled\" ] && echo \"cancelled: $cancelled\"\n  echo \"run: $GITHUB_SERVER_URL/$GITHUB_REPOSITORY/actions/runs/$GITHUB_RUN_ID\"\n  return 0\n}\n\n# --- library seam ----------------------------------------------------------\n# Sourced with SPT_CI_NOTIFY_LIB=1, this file defines the classification and\n# body-composition functions and stops — no `spt` probe, no daemon probe, no\n# recipients, no sends. Same seam as `reap-census.sh`'s SPT_CI_REAP_LIB, and for\n# the same reason: below this line the script's first act on a runner without\n# `spt` is `exit 0`, and on a runner WITH it the next act is a real send, so the\n# verdict logic is untestable in place. `return` when sourced, and refuse to be\n# EXECUTED with the flag set — that combination means the caller thinks it is\n# sourcing and would otherwise get a silent exit-0 no-op.\nif [ \"${SPT_CI_NOTIFY_LIB:-}\" = \"1\" ]; then\n  (return 0 2>/dev/null) && return 0","startLine":125,"lineNumbers":[125,126,127,128,129,130,131,132,133,134,135,136,137,138,139,140,141,142,143,144,145,146,147,148,149,150,151,152,153]},"fileSize":13352,"meta":{"source":{"type":"path","value":"C:\\Users\\decid\\Documents\\projects\\spt-core\\.worktrees\\hertz-ir86-disk-delta\\.github\\ci\\ci-notify.sh"},"truncation":{"direction":"head","truncatedBy":"lines","totalLines":276,"totalBytes":1737,"outputLines":29,"outputBytes":1737,"shownRange":{"start":125,"end":153},"nextOffset":154}}},"isError":false,"timestamp":1789483746413}}
{"type":"message","id":"f31d6d25","parentId":"9ce969d2","timestamp":"2026-09-15T14:49:06.417Z","message":{"role":"toolResult","toolCallId":"call_TnjErg5Tx8sbajxEPCboiMGz|fc_043a862a419f59ae016aa95ae244d487d285767da4a8fe419c","toolName":"read","content":[{"type":"text","text":"    }\n\n    // [unit->REQ-DOCS-5]\n    #[test]\n    fn failed_root_or_nested_help_retains_reference_and_producer_context() {\n        for depth in [0, 2] {\n            let root = tempfile::tempdir().unwrap();\n            let original = \"# Published reference\\n\";\n            let page = reference(root.path(), original);\n            let mut replies = HELP_TREE;\n            replies[depth] = (\"Partial help must not be published\\n\", 23);\n            let bin = producer(root.path(), replies);\n            for check in [false, true] {\n                let error = gen_cli_reference(root.path(), &bin, check).unwrap_err();\n                assert!(error.contains(\"23\"), \"missing exit status: {error}\");\n                assert!(error.contains(\"producer diagnostic\"), \"missing stderr: {error}\");\n                assert!(error.contains(\"--help\"), \"missing invocation: {error}\");\n                if depth == 2 {\n                    assert!(error.contains(\"child\") && error.contains(\"leaf\"), \"{error}\");\n                }\n                assert_eq!(std::fs::read_to_string(&page).unwrap(), original);\n            }\n        }\n    }\n\n    // [unit->REQ-DOCS-5]\n    #[test]\n    fn empty_or_whitespace_root_or_nested_help_cannot_generate_or_pass_check() {\n        for depth in [0, 2] {\n            for stdout in [\"\", \" \\t\\n\"] {\n                let root = tempfile::tempdir().unwrap();\n                let original = \"# Published reference\\n\";\n                let page = reference(root.path(), original);\n                let mut replies = HELP_TREE;\n                replies[depth] = (stdout, 0);\n                let bin = producer(root.path(), replies);\n                for check in [false, true] {\n                    let error = gen_cli_reference(root.path(), &bin, check).unwrap_err();\n                    assert!(error.contains(\"producer diagnostic\"), \"missing stderr: {error}\");\n                    assert!(error.contains(\"--help\"), \"missing invocation: {error}\");\n                    assert_eq!(std::fs::read_to_string(&page).unwrap(), original);\n                }\n            }\n        }\n    }\n\n    // [unit->REQ-DOCS-5]\n    #[test]\n    fn unlaunchable_help_producer_returns_error_without_clobbering_reference() {\n        let root = tempfile::tempdir().unwrap();\n        let original = \"# Published reference\\n\";\n        let page = reference(root.path(), original);\n        let bin = root.path().join(\"missing-help-producer\");\n        for check in [false, true] {\n            let error = gen_cli_reference(root.path(), &bin, check).unwrap_err();\n            assert!(error.contains(\"missing-help-producer\"), \"{error}\");\n            assert_eq!(std::fs::read_to_string(&page).unwrap(), original);\n        }\n    }\n\n    // [unit->REQ-DOCS-5]\n    #[test]\n    fn successful_help_tree_can_shrink_reference_and_clear_drift() {\n        let root = tempfile::tempdir().unwrap();\n        let original = \"# Obsolete command help\\n\".repeat(1000);\n        let page = reference(root.path(), &original);\n        let bin = producer(root.path(), HELP_TREE);\n        gen_cli_reference(root.path(), &bin, true).expect_err(\"stale reference must drift\");\n        assert_eq!(std::fs::read_to_string(&page).unwrap(), original);\n        gen_cli_reference(root.path(), &bin, false).unwrap();\n        let generated = std::fs::read_to_string(&page).unwrap();\n        assert!(generated.len() < original.len());\n        for help in [\n            \"## spt\\n\\n```text\\nUsage: spt\\n\",\n            \"## spt child\\n\\n```text\\nUsage: spt child\\n\",\n            \"### spt child leaf\\n\\n```text\\nUsage: spt child leaf\\n\",\n        ] {\n            assert!(generated.contains(help), \"missing rendered command: {help}\");\n        }\n        assert!(!generated.contains('\\r'));\n        gen_cli_reference(root.path(), &bin, true).unwrap();\n        assert_eq!(std::fs::read_to_string(&page).unwrap(), generated);\n    }\n}\n\n/// Resolve the `target/debug` dir cargo emits into, honoring `CARGO_TARGET_DIR`\n/// the same way cargo does: an absolute override is used as-is, a relative one\n/// resolves against `root` (the dir cargo is invoked in), and no override falls\n\n…\n\n    eprintln!(\n        \"xtask check: FAILED — {} interior space run(s) in operator-facing text\",\n        findings.len()\n    );\n    for (file, f) in &findings {\n        eprintln!(\"  {}:{}  run of {} spaces\", file, f.line, f.run);\n        eprintln!(\"    rendered: {:?}\", f.rendered_line);\n    }\n    eprintln!(\n        \"  A run like this is usually a Rust line-continuation backslash that was eaten: the \\\n         literal still compiles and still passes, and only the RENDERED text is wrong.\"\n    );\n    eprintln!(\n        \"  If the run is deliberate (a padded column, an aligned table), write \\\n         `spacerun-ok: <token> — <reason>` in a comment on the literal's opening line, or on the \\\n         comment line directly above it when the literal is continued and its opening line must \\\n         end in the backslash. The TOKEN is required: it is what lets one decision with many \\\n         sites be grouped and re-audited later, so a bare marker exempts nothing.\"\n    );\n    std::process::exit(1);\n}\n\n/// Refuse two workspace packages declaring a bin of the same name.\n///\n/// Enumerated through CARGO, never through `[[bin]]` stanzas: a stanza grep\n/// cannot see an autodiscovered `src/bin/*.rs` target and would certify an\n/// absence it is structurally unable to observe — which is exactly how a live\n/// bin got recorded as gone.\n// [impl->REQ-BUILD-UNIQUE-BIN-NAMES]\nfn check_unique_bin_names() {\n    let root = repo_root();"}],"details":{"fileSize":163022,"meta":{"source":{"type":"path","value":"C:\\Users\\decid\\Documents\\projects\\spt-core\\.worktrees\\hertz-ir86-disk-delta\\crates\\xtask\\src\\main.rs"}}},"isError":false,"timestamp":1789483746417}}
{"type":"message","id":"fde34a9d","parentId":"f31d6d25","timestamp":"2026-09-15T14:49:06.419Z","message":{"role":"toolResult","toolCallId":"call_GzJOUxs1FrBJLAAycY8hi0xQ|fc_043a862a419f59ae016aa95ae244f887d2a7f3faf16727b788","toolName":"read","content":[{"type":"text","text":"#!/usr/bin/env python3\n\"\"\"Run an allocated local lane; never infer allocation from available disk.\n\nA JSON plan contains reserve_bytes, max_growth_bytes, rustc_version (the exact\n`rustc -Vv` stdout recorded when allocating a WARM pool), and steps. A step has\nname and timeout_seconds, plus either argv or nextest={packages, filter, profile}.\nNextest inventory and execution use the same constructed selection. No implicit\nworkspace battery, retries, pool disposal, or budget widening.\n\nRequires the gater's --hold-released acknowledgement. Reuses ws272-w0's quiet\nmeter, lane lock, identity scrub and disk-floor meter. Volume movement is aggregate\ncapacity evidence, NOT attribution to this lane. Census has the existing reaper's\nexplicit scope; an unavailable/incomplete census is never clearance.\n\"\"\"\nimport argparse\nimport importlib.util\n\n…\n\n\n\ndef validate_plan(plan):\n    if not isinstance(plan, dict):\n        raise ValueError(\"plan must be an object\")\n    for key in (\"reserve_bytes\", \"max_growth_bytes\"):\n        if type(plan.get(key)) is not int or plan[key] <= 0:\n            raise ValueError(f\"{key} must be positive allocated bytes\")\n    if plan[\"reserve_bytes\"] < w0.FLOOR_BYTES:\n        raise ValueError(\"allocation cannot weaken the existing disk floor\")\n    if not isinstance(plan.get(\"rustc_version\"), str) or not plan[\"rustc_version\"].strip():\n        raise ValueError(\"allocation requires the warm pool's exact rustc -Vv stdout\")\n    if not isinstance(plan.get(\"steps\"), list) or not plan[\"steps\"]:\n        raise ValueError(\"plan requires nonempty steps\")\n    names = {\"pool-claim\", \"pool-release\", \"before\", \"start\", \"lane\", \"plan\",\n             \"toolchain\", \"environment-scrub\", \"builders-before\", \"capacity\"}\n    for step in plan[\"steps\"]:\n        if not isinstance(step, dict):\n            raise ValueError(\"each step must be an object\")\n        name = step.get(\"name\")\n        if (not isinstance(name, str) or not re.fullmatch(r\"[A-Za-z0-9_-]+\", name)\n                or name in names or name.endswith((\"-inventory\", \"-builders\", \"-census\"))):\n            raise ValueError(\"step names must be unique safe filenames, excluding driver artifacts\")\n        names.add(name)\n        if (type(step.get(\"timeout_seconds\")) not in (int, float)\n                or not math.isfinite(step[\"timeout_seconds\"]) or step[\"timeout_seconds\"] <= 0):\n            raise ValueError(f\"{name}: explicit finite positive driver timeout required\")\n        if (\"argv\" in step) == (\"nextest\" in step):\n            raise ValueError(f\"{name}: supply argv OR nextest\")\n        if \"nextest\" in step:\n            selected_commands(step[\"nextest\"])\n        elif not isinstance(step[\"argv\"], list) or not step[\"argv\"] or any(not isinstance(a, str) for a in step[\"argv\"]):\n            raise ValueError(f\"{name}: argv must be a nonempty string array\")\n        elif Path(step[\"argv\"][0]).name.lower() in (\"cargo\", \"cargo.exe\"):\n            if any(arg in (\"test\", \"nextest\") for arg in step[\"argv\"][1:]):\n                raise ValueError(f\"{name}: Cargo tests require a nextest selection and inventory\")\n\n\n# [impl->REQ-LOCAL-GATE-EXECUTION-EVIDENCE]\ndef final_status(producer, observations_ok):\n    return producer if producer else (0 if observations_ok else REFUSED)\n\n…\n\n        return REFUSED\n    claimed = False\n    result = 0\n    try:\n        if not w0.preflight() or not census(root, output, \"before\", env):\n            raise ValueError(\"quiet-window or scoped census refused\")\n        save(output / \"builders-before.json\", builder_snapshot())\n        if not w0.disk_floor(root, output, \"start\", xtask):\n            raise ValueError(\"disk floor refused\")\n        result, ok = run_producer(root, output, \"pool-claim\", [str(xtask), \"pool-claim\", \"--pool\", str(target), \"--label\", \"local-lane\"], 30, env, lambda: meter(\"claim\"))\n        claimed = result == 0\n        result = final_status(result, ok)\n        if not claimed:\n            # A terminated claim writer may have persisted ownership before exit.\n            # Do not release an unproven claim: it may still belong to another lane.\n            print(\"POOL_CUSTODY_UNPROVEN: claim did not complete successfully; \"\n                  \"inspect POOL-OWNER.json before any takeover or deletion\", file=sys.stderr)\n        for step in plan[\"steps\"]:\n            if result:\n                break\n            name = step[\"name\"]\n            if not w0.preflight() or not meter(f\"{name}-before\") or not census(root, output, f\"{name}-before-census\", env):\n                result = REFUSED\n                break\n            if \"nextest\" in step:\n                listing, argv = selected_commands(step[\"nextest\"])\n                result, ok = run_producer(root, output, name + \"-inventory\", listing, step[\"timeout_seconds\"], env, lambda: meter(name + \"-inventory\"), json_stdout=True)\n                after_ok = observe_after(root, output, name + \"-inventory\", env, meter)\n                ok = ok and after_ok\n                if result or not ok:\n                    result = final_status(result, ok)\n                    break\n                inventory = json.loads((output / f\"{name}-inventory.stdout\").read_text(encoding=\"utf-8\"))\n                save(output / f\"{name}-selection.json\", selected_inventory(inventory))\n            else:\n                argv = step[\"argv\"]\n            result, ok = run_producer(root, output, name, argv, step[\"timeout_seconds\"], env, lambda: meter(name))\n            after_ok = observe_after(root, output, name, env, meter)\n            result = final_status(result, ok and after_ok)\n            if result:\n                break\n    except (OSError, ValueError, psutil.Error, subprocess.TimeoutExpired) as error:\n        print(f\"LANE_OBSERVATION_FAILED: {error}\", file=sys.stderr)\n        result = final_status(result, False)\n    finally:\n        # Release through the prebuilt executable; this driver never deletes target.\n        if claimed:\n            try:\n                released = subprocess.run([str(xtask), \"pool-release\", \"--pool\", str(target)], cwd=root, env=env, capture_output=True, text=True, timeout=30)\n                save(output / \"pool-release.json\", {\"exit\": released.returncode, \"stdout\": released.stdout, \"stderr\": released.stderr})"}],"details":{"fileSize":22224,"meta":{"source":{"type":"path","value":"C:\\Users\\decid\\Documents\\projects\\spt-core\\.worktrees\\hertz-ir86-disk-delta\\.github\\ci\\local-lane.py"}}},"isError":false,"timestamp":1789483746419}}
{"type":"message","id":"37d9beec","parentId":"fde34a9d","timestamp":"2026-09-15T14:49:06.421Z","message":{"role":"toolResult","toolCallId":"call_KQhkVlhBkR9YoYA0cQlYPIUE|fc_043a862a419f59ae016aa95ae244ec87d2aee60581603c3a88","toolName":"read","content":[{"type":"text","text":"                             branch-level twin of a recycled pid\",\n                            short(claim.base.as_deref().unwrap_or_default())\n                        ),\n                    }\n                }\n                // The question failed rather than answered. A guess here would\n                // be a takeover bought with a broken probe.\n                Some(None) => return LaneState::Unknown,\n            }\n            tip\n        }\n        // A detached rig claims on its base sha alone, which is a lane identity\n        // too — it is the work, named directly.\n        None => match &claim.base {\n            Some(base) => base.clone(),\n            None => return LaneState::Unknown,\n        },\n    };\n    let Some((head_name, head)) = integration_head(repo) else {\n        return LaneState::Unknown;\n    };\n    match git_ancestry(repo, &tip, &head) {\n        Some(true) => LaneState::Settled {\n            reason: format!(\n                \"lane tip {} is contained in {head_name} — the lane landed\",\n                short(&tip)\n            ),\n        },\n        Some(false) => LaneState::InFlight {\n            reason: format!(\n                \"lane tip {} is NOT contained in {head_name} — the lane has not landed\",\n                short(&tip)\n            ),\n        },\n        None => LaneState::Unknown,\n    }\n}\n\n/// The ref a lane is measured as landed against, first that resolves.\nfn integration_head(repo: &Path) -> Option<(String, String)> {\n    [\"origin/main\", \"main\"]\n        .into_iter()\n        .find_map(|r| git_out(repo, &[\"rev-parse\", \"--verify\", \"--quiet\", r]).map(|s| (r.into(), s)))\n}\n\nfn short(sha: &str) -> String {\n    sha.chars().take(12).collect()\n}\n\nfn git(repo: &Path, args: &[&str]) -> Option<std::process::Output> {\n\n[Showing lines 403-452 of 1539. Use :453 to continue]"}],"details":{"truncation":{"content":"                             branch-level twin of a recycled pid\",\r\n                            short(claim.base.as_deref().unwrap_or_default())\r\n                        ),\r\n                    }\r\n                }\r\n                // The question failed rather than answered. A guess here would\r\n                // be a takeover bought with a broken probe.\r\n                Some(None) => return LaneState::Unknown,\r\n            }\r\n            tip\r\n        }\r\n        // A detached rig claims on its base sha alone, which is a lane identity\r\n        // too — it is the work, named directly.\r\n        None => match &claim.base {\r\n            Some(base) => base.clone(),\r\n            None => return LaneState::Unknown,\r\n        },\r\n    };\r\n    let Some((head_name, head)) = integration_head(repo) else {\r\n        return LaneState::Unknown;\r\n    };\r\n    match git_ancestry(repo, &tip, &head) {\r\n        Some(true) => LaneState::Settled {\r\n            reason: format!(\r\n                \"lane tip {} is contained in {head_name} — the lane landed\",\r\n                short(&tip)\r\n            ),\r\n        },\r\n        Some(false) => LaneState::InFlight {\r\n            reason: format!(\r\n                \"lane tip {} is NOT contained in {head_name} — the lane has not landed\",\r\n                short(&tip)\r\n            ),\r\n        },\r\n        None => LaneState::Unknown,\r\n    }\r\n}\r\n\r\n/// The ref a lane is measured as landed against, first that resolves.\r\nfn integration_head(repo: &Path) -> Option<(String, String)> {\r\n    [\"origin/main\", \"main\"]\r\n        .into_iter()\r\n        .find_map(|r| git_out(repo, &[\"rev-parse\", \"--verify\", \"--quiet\", r]).map(|s| (r.into(), s)))\r\n}\r\n\r\nfn short(sha: &str) -> String {\r\n    sha.chars().take(12).collect()\r\n}\r\n\r\nfn git(repo: &Path, args: &[&str]) -> Option<std::process::Output> {\r","truncated":true,"truncatedBy":"lines","totalLines":1137,"totalBytes":1817,"outputLines":50,"outputBytes":1817,"lastLinePartial":false,"firstLineExceedsLimit":false},"totalLines":1539,"displayContent":{"text":"                             branch-level twin of a recycled pid\",\r\n                            short(claim.base.as_deref().unwrap_or_default())\r\n                        ),\r\n                    }\r\n                }\r\n                // The question failed rather than answered. A guess here would\r\n                // be a takeover bought with a broken probe.\r\n                Some(None) => return LaneState::Unknown,\r\n            }\r\n            tip\r\n        }\r\n        // A detached rig claims on its base sha alone, which is a lane identity\r\n        // too — it is the work, named directly.\r\n        None => match &claim.base {\r\n            Some(base) => base.clone(),\r\n            None => return LaneState::Unknown,\r\n        },\r\n    };\r\n    let Some((head_name, head)) = integration_head(repo) else {\r\n        return LaneState::Unknown;\r\n    };\r\n    match git_ancestry(repo, &tip, &head) {\r\n        Some(true) => LaneState::Settled {\r\n            reason: format!(\r\n                \"lane tip {} is contained in {head_name} — the lane landed\",\r\n                short(&tip)\r\n            ),\r\n        },\r\n        Some(false) => LaneState::InFlight {\r\n            reason: format!(\r\n                \"lane tip {} is NOT contained in {head_name} — the lane has not landed\",\r\n                short(&tip)\r\n            ),\r\n        },\r\n        None => LaneState::Unknown,\r\n    }\r\n}\r\n\r\n/// The ref a lane is measured as landed against, first that resolves.\r\nfn integration_head(repo: &Path) -> Option<(String, String)> {\r\n    [\"origin/main\", \"main\"]\r\n        .into_iter()\r\n        .find_map(|r| git_out(repo, &[\"rev-parse\", \"--verify\", \"--quiet\", r]).map(|s| (r.into(), s)))\r\n}\r\n\r\nfn short(sha: &str) -> String {\r\n    sha.chars().take(12).collect()\r\n}\r\n\r\nfn git(repo: &Path, args: &[&str]) -> Option<std::process::Output> {\r","startLine":403,"lineNumbers":[403,404,405,406,407,408,409,410,411,412,413,414,415,416,417,418,419,420,421,422,423,424,425,426,427,428,429,430,431,432,433,434,435,436,437,438,439,440,441,442,443,444,445,446,447,448,449,450,451,452]},"fileSize":68960,"meta":{"source":{"type":"path","value":"C:\\Users\\decid\\Documents\\projects\\spt-core\\.worktrees\\hertz-ir86-disk-delta\\crates\\spt-poolguard\\src\\lib.rs"},"truncation":{"direction":"head","truncatedBy":"lines","totalLines":1539,"totalBytes":1817,"outputLines":50,"outputBytes":1817,"shownRange":{"start":403,"end":452},"nextOffset":453}}},"isError":false,"timestamp":1789483746421}}
{"type":"message","id":"f1015349","parentId":"37d9beec","timestamp":"2026-09-15T14:49:06.423Z","message":{"role":"toolResult","toolCallId":"call_H8fNF99TgBvfC98mkA9WCs0Y|fc_043a862a419f59ae016aa95ae244e087d2a80f4e98da073b4a","toolName":"read","content":[{"type":"text","text":"      if (!ReadProcessMemory(h, (IntPtr)buf, s, len, out read)) return null;\n      return System.Text.Encoding.Unicode.GetString(s);\n    } finally { CloseHandle(h); }\n  }\n}\n'@\n\n$all = Get-Process\n$rows = foreach ($p in $all) {\n  $cwd = $null\n  try { $cwd = [Peb]::CurrentDirectory($p.Id) } catch {}\n  if ($cwd) {\n    [pscustomobject]@{ Pid = $p.Id; Name = $p.ProcessName; Cwd = $cwd\n                       Started = $(try { $p.StartTime } catch { $null }) }\n  }\n}\n\n$readable = @($rows).Count\n$opaque = @($all).Count - $readable\nif ($Match) { $rows = @($rows) | Where-Object { $_.Cwd -like \"*$Match*\" } }\n$rows = @($rows)\n\n$rows | Sort-Object Cwd | Format-Table -AutoSize -Wrap\n\n# Report the DENOMINATOR, not just the hits: \"0 rows\" from a filter and \"0 rows\"\n# because nothing could be opened are the same output and very different facts.\nif ($Match) {\n  \"matched: $($rows.Count)   (readable processes: $readable, not openable: $opaque, filter: '$Match')\"\n} else {\n  \"rows: $($rows.Count)   (readable processes: $readable, not openable: $opaque)\"\n}\nif ($opaque -gt 0) {\n  \"note: $opaque process(es) could not be opened (other user / higher integrity) and were skipped — an empty result is 'no pin I could see', not 'no pin'. Re-run elevated to widen the view.\"\n}\n"}],"details":{"totalLines":110,"displayContent":{"text":"      if (!ReadProcessMemory(h, (IntPtr)buf, s, len, out read)) return null;\n      return System.Text.Encoding.Unicode.GetString(s);\n    } finally { CloseHandle(h); }\n  }\n}\n'@\n\n$all = Get-Process\n$rows = foreach ($p in $all) {\n  $cwd = $null\n  try { $cwd = [Peb]::CurrentDirectory($p.Id) } catch {}\n  if ($cwd) {\n    [pscustomobject]@{ Pid = $p.Id; Name = $p.ProcessName; Cwd = $cwd\n                       Started = $(try { $p.StartTime } catch { $null }) }\n  }\n}\n\n$readable = @($rows).Count\n$opaque = @($all).Count - $readable\nif ($Match) { $rows = @($rows) | Where-Object { $_.Cwd -like \"*$Match*\" } }\n$rows = @($rows)\n\n$rows | Sort-Object Cwd | Format-Table -AutoSize -Wrap\n\n# Report the DENOMINATOR, not just the hits: \"0 rows\" from a filter and \"0 rows\"\n# because nothing could be opened are the same output and very different facts.\nif ($Match) {\n  \"matched: $($rows.Count)   (readable processes: $readable, not openable: $opaque, filter: '$Match')\"\n} else {\n  \"rows: $($rows.Count)   (readable processes: $readable, not openable: $opaque)\"\n}\nif ($opaque -gt 0) {\n  \"note: $opaque process(es) could not be opened (other user / higher integrity) and were skipped — an empty result is 'no pin I could see', not 'no pin'. Re-run elevated to widen the view.\"\n}\n","startLine":76,"lineNumbers":[76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95,96,97,98,99,100,101,102,103,104,105,106,107,108,109,110]},"fileSize":5464,"meta":{"source":{"type":"path","value":"C:\\Users\\decid\\Documents\\projects\\spt-core\\.worktrees\\hertz-ir86-disk-delta\\.github\\ci\\find-cwd-holders.ps1"}}},"isError":false,"timestamp":1789483746423}}
{"type":"message","id":"d08e46a1","parentId":"f1015349","timestamp":"2026-09-15T14:49:06.482Z","message":{"role":"toolResult","toolCallId":"call_IyhxRu0FB0EajAkwA41XHZeQ|fc_043a862a419f59ae016aa95ae2450487d2a930df8b31140dac","toolName":"grep","content":[{"type":"text","text":"# .worktrees/hertz-ir86-disk-delta/crates/\n\n## spt/tests/\n### resident_service_e2e.rs\n 102|\n*103|fn mock_pid(option: &str) -> Option<u32> {\n 104|    std::fs::read_to_string(service_dir(option).join(\"mock-alive\"))\n 105|        .ok()?\n 106|        .trim()\n...\n 126|/// `(pid, generation)` out of `brain.ready` — the daemon-is-really-up signal.\n*127|fn brain_ready(path: &Path) -> Option<(u32, u64)> {\n 128|    let v: serde_json::Value = serde_json::from_str(&std::fs::read_to_string(path).ok()?).ok()?;\n 129|    Some((v.get(\"pid\")?.as_u64()? as u32, v.get(\"generation\")?.as_u64()?))\n 130|}\n...\n 470|    let settle_started = Instant::now();\n*471|    let settled = wait_until(SWEEP_SETTLE_BUDGET, || sweep().is_clean());\n 472|    let settle_waited = settle_started.elapsed();\n 473|    let population = sweep();\n 474|    eprintln!(\"=== resident-service teardown: verdicts={verdicts:?} population={population:?} ===\");\n...\n 654|            // to kill. Expected, and expected to be common.\n*655|            \"gone\" | \"reused\" | \"breadcrumb-moved\" | \"self\" | \"ancestor\" | \"no-breadcrumb\" => {}\n 656|            // Trap: something WAS there and we either declined it or could not\n 657|            // authenticate it. That is a leak, or a guard aimed at the wrong\n 658|            // image — never a clean teardown.\n\n### common/\n#### reap.rs\n 321|    /// innocent subtree. A GUARD, not a finding — the sweep declines that seed\n*322|    /// and says so, and the caller must not fail on it (see [`Population::is_clean`]).\n 323|    pub scope_lost: Vec<u32>,\n 324|}\n 325|\n...\n 339|    /// brain, whose numbers are never in doubt).\n*340|    pub fn is_clean(&self) -> bool {\n 341|        self.survivors.is_empty() && self.unreadable.is_empty()\n 342|    }\n 343|}\n...\n 467|        eprintln!(\"REAP[{label}]: no readable daemon.pid breadcrumb — nothing to reap\");\n*468|        return Verdict::Refused(\"no-breadcrumb\");\n 469|    };\n 470|    authenticated_kill(label, pid, expected_exe, observed)\n 471|}\n\n## xtask/src/\n### main.rs\n 55|            check_operator_text_space_runs();\n*56|            check_unique_bin_names();\n 57|            check_brain_read_policy();\n 58|            eprintln!(\"xtask check: OK\");\n 59|        }\n...\n 768|// [impl->REQ-BUILD-UNIQUE-BIN-NAMES]\n*769|fn check_unique_bin_names() {\n 770|    let root = repo_root();\n 771|    let targets = match binnames::workspace_bin_targets(&root) {\n 772|        Ok(t) => t,"}],"details":{"scopePath":".worktrees/hertz-ir86-disk-delta/crates/spt/tests/resident_service_e2e.rs, .worktrees/hertz-ir86-disk-delta/crates/spt/tests/common/reap.rs, .worktrees/hertz-ir86-disk-delta/crates/xtask/src/main.rs","searchPath":"C:\\Users\\decid\\Documents\\projects\\spt-core\\.worktrees\\hertz-ir86-disk-delta\\crates","cwd":"C:\\Users\\decid\\Documents\\projects\\spt-core","matchCount":9,"fileCount":3,"files":[".worktrees/hertz-ir86-disk-delta/crates/spt/tests/resident_service_e2e.rs",".worktrees/hertz-ir86-disk-delta/crates/spt/tests/common/reap.rs",".worktrees/hertz-ir86-disk-delta/crates/xtask/src/main.rs"],"fileMatches":[{"path":".worktrees/hertz-ir86-disk-delta/crates/spt/tests/resident_service_e2e.rs","count":4},{"path":".worktrees/hertz-ir86-disk-delta/crates/spt/tests/common/reap.rs","count":3},{"path":".worktrees/hertz-ir86-disk-delta/crates/xtask/src/main.rs","count":2}],"truncated":false,"displayContent":"# .worktrees/hertz-ir86-disk-delta/crates/\n\n## spt/tests/\n### resident_service_e2e.rs\n 102│\n*103│fn mock_pid(option: &str) -> Option<u32> {\n 104│    std::fs::read_to_string(service_dir(option).join(\"mock-alive\"))\n 105│        .ok()?\n 106│        .trim()\n    │...\n 126│/// `(pid, generation)` out of `brain.ready` — the daemon-is-really-up signal.\n*127│fn brain_ready(path: &Path) -> Option<(u32, u64)> {\n 128│    let v: serde_json::Value = serde_json::from_str(&std::fs::read_to_string(path).ok()?).ok()?;\n 129│    Some((v.get(\"pid\")?.as_u64()? as u32, v.get(\"generation\")?.as_u64()?))\n 130│}\n    │...\n 470│    let settle_started = Instant::now();\n*471│    let settled = wait_until(SWEEP_SETTLE_BUDGET, || sweep().is_clean());\n 472│    let settle_waited = settle_started.elapsed();\n 473│    let population = sweep();\n 474│    eprintln!(\"=== resident-service teardown: verdicts={verdicts:?} population={population:?} ===\");\n    │...\n 654│            // to kill. Expected, and expected to be common.\n*655│            \"gone\" | \"reused\" | \"breadcrumb-moved\" | \"self\" | \"ancestor\" | \"no-breadcrumb\" => {}\n 656│            // Trap: something WAS there and we either declined it or could not\n 657│            // authenticate it. That is a leak, or a guard aimed at the wrong\n 658│            // image — never a clean teardown.\n\n### common/\n#### reap.rs\n 321│    /// innocent subtree. A GUARD, not a finding — the sweep declines that seed\n*322│    /// and says so, and the caller must not fail on it (see [`Population::is_clean`]).\n 323│    pub scope_lost: Vec<u32>,\n 324│}\n 325│\n    │...\n 339│    /// brain, whose numbers are never in doubt).\n*340│    pub fn is_clean(&self) -> bool {\n 341│        self.survivors.is_empty() && self.unreadable.is_empty()\n 342│    }\n 343│}\n    │...\n 467│        eprintln!(\"REAP[{label}]: no readable daemon.pid breadcrumb — nothing to reap\");\n*468│        return Verdict::Refused(\"no-breadcrumb\");\n 469│    };\n 470│    authenticated_kill(label, pid, expected_exe, observed)\n 471│}\n\n## xtask/src/\n### main.rs\n  55│            check_operator_text_space_runs();\n *56│            check_unique_bin_names();\n  57│            check_brain_read_policy();\n  58│            eprintln!(\"xtask check: OK\");\n  59│        }\n    │...\n 768│// [impl->REQ-BUILD-UNIQUE-BIN-NAMES]\n*769│fn check_unique_bin_names() {\n 770│    let root = repo_root();\n 771│    let targets = match binnames::workspace_bin_targets(&root) {\n 772│        Ok(t) => t,"},"isError":false,"timestamp":1789483746482}}
{"type":"custom","customType":"tool_execution_start","data":{"toolCallId":"call_jY0la8LMTlguqVawLsLpOQ5Q|fc_043a862a419f59ae016aa95aeaad0087d29390588fbd087238","toolName":"yield","startedAt":"2026-09-15T14:51:44.093Z"},"id":"3f786ccb","parentId":"d08e46a1","timestamp":"2026-09-15T14:51:44.093Z"}
{"type":"message","id":"81cc5da3","parentId":"3f786ccb","timestamp":"2026-09-15T14:51:44.093Z","message":{"role":"assistant","content":[{"type":"thinking","thinking":"**Enumerating 70 table rows**"},{"type":"toolCall","id":"call_jY0la8LMTlguqVawLsLpOQ5Q|fc_043a862a419f59ae016aa95aeaad0087d29390588fbd087238","name":"yield","arguments":{"type":null,"data":{"summary":"Accounted for all 70 assigned IDs, including headingless IR-31 and status-reversing amendments. Highest-value immediate work is register reconciliation: IR-32/37/47/58 and IR-40 arm B already have implementations at the fixed tree. IR-11 remains a genuinely small tooling rider. Larger lifecycle/capacity work remains composed or held, not fresh dispatch material. No edits, builds, tests, validation commands, or live-process/service probes performed.","files":[{"path":".worktrees/hertz-ir86-disk-delta/docs/INFRA-REGISTER.md","description":"Complete IR-1–70 population and amendments; IR-31 starts at line 2015 without a heading; later cross-references checked for status/trigger consequences."},{"path":".worktrees/hertz-ir86-disk-delta/crates/xtask/src/main.rs","description":"Existing empty/failed-help refusal and preservation tests; duplicate-bin gate wired into check; pool_claim still writes without incumbent admission."},{"path":".worktrees/hertz-ir86-disk-delta/crates/xtask/src/binnames.rs","description":"Already-built IR-58 cargo-metadata enumeration and duplicate-bin-name predicate."},{"path":".worktrees/hertz-ir86-disk-delta/.github/ci/ci-notify.sh","description":"Already-built IR-40 arm-B scope wording and IR-47 missing-attribution warning/doyle split."},{"path":".worktrees/hertz-ir86-disk-delta/.github/ci/traceable-reqs.sh","description":"Shared checker pin is already 0.4.1; both CI and golden call it, with placement enforcement enabled in manifest."},{"path":".worktrees/hertz-ir86-disk-delta/.github/ci/find-cwd-holders.ps1","description":"IR-11 remains: output objects expose Pid/Name/Cwd/Started, not Headless."},{"path":".worktrees/hertz-ir86-disk-delta/.github/ci/local-lane.py","description":"Existing allocated-capacity, truthful producer-exit, inventory, scrub and census construction; do not rebuild IR-31/59/60 mechanisms wholesale."},{"path":".worktrees/hertz-ir86-disk-delta/crates/spt/tests/common/reap.rs","description":"IR-18 deferred breadcrumb-read collapse remains; existing shared population cleanliness predicate already present."},{"path":".worktrees/hertz-ir86-disk-delta/crates/spt-store/src/info.rs","description":"IR-44 overclaim remains at lines 874–875."},{"path":".worktrees/hertz-ir86-disk-delta/crates/spt-poolguard/src/lib.rs","description":"IR-49 remains: false ancestry directly returns InFlight, without patch-id fallback."}],"architecture":"The register mixes historical incidents, implemented remedies, recurring procedure, and residual obligations. Current shared seams are xtask generation/bin enumeration/pool verbs, CI notification/checker scripts, local-lane.py admission/evidence, and test common/reap. Existing implementation is not equivalent to historical acceptance; reconcile receipts separately and retain narrowly defined residuals.","report":"## Scope and notation\nAll references below are relative to `.worktrees/hertz-ir86-disk-delta/`. `R` means `docs/INFRA-REGISTER.md`. Read-only source findings, not freshly executed acceptance. READY means actionable composition/reconciliation now, not authorization to launch Windows work. TOUCH means retain until its named seam/event; UNKNOWN means qualifying evidence not established. The post-merge CI hold remains intact.\n\n## Complete disposition inventory — all 70 IDs\n\n| ID | Current disposition and exact remaining trigger | Evidence |\n|---|---|---|\n| 1 | BUILT/LANDED; no remaining implementation. Historical golden exercise recorded. | R274–301; 3008–3073 |\n| 2 | RETIRED/no flip, but explicit reopen condition has now acquired recurring floor-red evidence. Re-weigh as a decision, not an incremental-off patch; experiment BLOCKED on quiet authorized windows. | R304–326; recurring reds R3348–3362 and 5082 |\n| 3 | TOUCH: endpoint lifecycle/daemon supervision milestone; generic new stream family explicitly did not qualify. No fresh qualifying milestone established in this sweep. | R328–340; 121–123 |\n| 4 | BUILT/LANDED, all three riders; no redispatch. | R341–363; 3008–3073 |\n| 5 | TOUCH: actual need for a nextest SUMMARY COUNT, not any script edit. Current local driver uses structured TestListSummary, so do not invent a prose-parser consumer. | R364–382; .github/ci/local-lane.py:63–85 |\n| 6 | TOUCH/adoption audit: next count-reporting gate-script/CI touch. Historical conditional lane did NOT satisfy existing estate; count+membership in current local-lane selection is one covered consumer, not estate closure. | R383–394; 3051–3059; local-lane.py:383–392 |\n| 7 | OPEN/composed hertz lifecycle package; reconcile landed rig changes before any redispatch. Heavy Windows work held. | R395–405; 48–49 |\n| 8 | BUILT: both census verdicts expose unreadable population; Linux failed-kill reporting included. IR-18 helper residual is not erased by this closure. | R406–439 |\n| 9 | BUILT toolchain pin plus exercised measurement half. | R440–477 |\n| 10 | TOUCH: next gate-runbook/docs wave; consumer-suite selection checklist, not product code. | R478–485 |\n| 11 | READY small tooling rider; explicitly composed at prior intake, source still lacks column. | R486–492; 176–178; .github/ci/find-cwd-holders.ps1:83–98 |\n| 12 | BUILT; stale-binary kin RETIRED by actual mutation experiment, no residual product fix. Header/top sweep metadata should not keep composing W3 repair. | R493–540, especially 496–510 |\n| 13 | BUILT mutation-proved hygiene followups. | R541–551 |\n| 14 | Recurring audit TOUCH/receipt: Sept-11 cleanup instance discharged, recurring hygiene remains. No current orphan/reap authorization inferred from dated counts. | R552–714; cleanup receipt .spt/cleanup-20260911.json |\n| 15 | BUILT authenticated oracle; does not root-cause historical specimen. | R1257–1283 |\n| 16 | BUILT, loud-refusal remedy checked; rename proposal explicitly withdrawn as false premise. | R833–869 |\n| 17 | OPEN/instrumented-awaiting-fire, hertz package. Linux member CLOSED via ready-path hash mechanism; Windows specimen/sub-observation remain, no renewed isolated rate run. | R715–832, especially 806–832 |\n| 18 | Original acceptance BUILT. Deferred (b) breadcrumb classification remains REAL, not closure-ready: daemon.pid, mock_pid, brain_ready still collapse unreadable/malformed into absence. Deployah named owner, after original hertz lane; current lane intake needed, Windows execution held. | R1055–1117; common/reap.rs:59–64,467–468; resident_service_e2e.rs:103–108,127–129 |\n| 19 | RETIRED intentional PR-only classifier; never extend main classifier as alleged fix. | R1155–1183 |\n| 20 | OPEN/composed hertz lifecycle package; stop-discrimination receipt on both environments owed, preserve load-bearing perch pid. No duplicate broad teardown fix. | R1184–1216 |\n| 21 | BUILT fixture prebuild/helper migration. Historical same-package build-edge allegation retracted. | R1284–1498 |\n| 22 | OPEN diagnostic-set residual plus driver isolation adoption. Sept-13 inherited OWL_SESSION_ID recurrence is real, but local-lane already reuses scrub: discriminate all-vars diagnostic vs adoption failure, not fresh scrub implementation. | R1499–1520; R6523–6543; local-lane.py:10–13 |\n| 23 | BUILT private fixture staging plus process-global resolver serialization. | R1521–1545 |\n| 24 | BUILT audited brain-job termination; distinct from IR16. | R1546–1585 |\n| 25 | OPEN/mitigated by nextest; harden named marginal tests only in hertz package or renewed loaded bare-cargo use. No golden-wide defect inferred. | R1586–1632 |\n| 26 | OPEN real residual: original identity enforcement committed; incumbent claim adjudication/displacement event still absent. Next CI/infra batch or pool audit composition, not a duplicate identity guard. | R1633–1805; xtask main.rs:3295–3395 |\n| 27 | OPEN adoption/timing gap: pool-sweep already exists. Post-worktree teardown sweep/adoption, not new enumeration. Next CI/infra batch. | R1806–1839 |\n| 28 | BUILT release-range/changelog accounting, PR176. | R1840–1854 |\n| 29 | Original barrier fix LANDED; later rung/serve-window and emitted-margin residuals need exact twohost receipt reconciliation. Old six-draw margin series CLOSED/unextendable. | R1855–1917 |\n| 30 | Receipt/event-only family record: instruments LANDED; wait for discriminating fires. Linux face resolved; do not rebuild instrumentation. | R1918–2014 |\n| 31 | Headingless OPEN capacity/adoption record, not missing ID. Aggregate budgeting and start/end evidence already have local-lane construction; reconcile adoption/allocation and preserve hosted-relay isolation hold. No new pool census presumed required. | R2015–2177; R65–102; local-lane.py:1–13,270–307,358–407 |\n| 32 | RECEIPT-ONLY/stale OPEN: failed and empty-help producer refusal already implemented before writing destination, with root/nested preservation cells. Do not add arbitrary historical-length floor; successful help shrink is deliberately supported. Kin filter-inventory rule remains procedural. | R2178–2211; xtask main.rs:98–124,321–401,441–448 |\n| 33 | RECEIPT-ONLY/measurement: 16MiB CLI stack and smoke already exist; current margin/acceptance reconciliation only. Heavy fresh debug run held. | R2212–2264; spt/src/main.rs:128–132,248–252 |\n| 34 | OPEN lifecycle/config rider; expected-leak remedy not established by one quiet run. No rate/closure inferred. | R2265–2289 |\n| 35 | OPEN rate record; requires operator disposition plus package landing and remeasurement. BLOCKED from new heavy run now. | R2290–2325 |\n| 36 | BUILT shared output_bounded adoption; no clone-hoist redispatch. | R2326–2361 |\n| 37 | RECEIPT-ONLY/stale OPEN: upstream 0.4.1 fix now consumed through both workflow paths; placement on/module_banner accept. Entry's 'closes when pin lands' is source-satisfied. Reconcile landed receipt, no upgrade implementation. | R2362–2424; R6339–6365; .github/ci/traceable-reqs.sh:5–6; ci.yml:252–257; golden.yml:1442–1447; traceable-reqs.toml:23–25 |\n| 38 | BUILT final-resident teardown; conhost disposal discipline remains in IR14/63. | R2425–2463 |\n| 39 | BUILT shared package-correct missing-fixture precondition; no repeat sibling_bin sweep. | R2464–2500 |\n| 40 | SPLIT: arm B RECEIPT-ONLY (CI NEEDS/scope/not-run text shipped); arm A UNKNOWN measurement on next commune/psyche touch, envelope sequence not recency. | R2501–2577; ci-notify.sh:129–140 |\n| 41 | Accepted documented queued supersession; docs remedy DONE. Policy choice on next ci.yml/runbook touch, not automatic per-SHA-concurrency change. | R2578–2609 |\n| 42 | BUILT documentation; optional incumbent notice belongs IR26, not reopening IR42. | R2610–2637 |\n| 43 | UNKNOWN/touch investigation: derive bound on next knock-carrier touch or NoReply red; no new confirming specimen established. | R2638–2654 |\n| 44 | TOUCH, real tiny comment defect remains. No current info.rs-touch trigger established; keep ranked below immediate tooling rider. | R2655–2675; spt-store/src/info.rs:872–877 |\n| 45 | RETIRED disk-hermeticity question answered; network ingress residue explicitly elsewhere. | R2676–2706 |\n| 46 | Implemented START/END/DOCS instant tokens; RECEIPT/adoption reconciliation rather than another token implementation. Sizing/dependency ownership remains IR86/Main. | R2707–2773; R25–35; 5055–5067 |\n| 47 | RECEIPT-ONLY/stale OPEN: actual missing/parse-failure annotations and legitimate doyle quiet case already shipped. Do not reapply ancient stash. | R2774–2800; ci-notify.sh:193–210; ci-notify-selftest.sh:225–229 |\n| 48 | TOUCH preventive control on parity-cell edit; current defect not claimed and no qualifying edit established. | R2801–2821 |\n| 49 | TOUCH real ancestry-only residual; first landed-member takeover or poolguard touch. No current takeover request established; source confirms patch-id fallback absent. | R2822–2855; spt-poolguard/src/lib.rs:424–438 |\n| 50 | CLOSED/BUILT adoption complete with explicitly distinct engine-room direct sink path. | R2856–2913 |\n| 51 | BLOCKED/conditional: attribution-before-net-off, or separately owned hermeticity pass; hosted-relay prebuilt route still needs isolation proof. No blanket net-off fix authorized. | R2914–2942; R95–102 |\n| 52 | BUILT full recursive CLI reference since SIGNET, despite obsolete carry-forward notes in sweep prose. | R2969–3007; xtask main.rs:165–223 |\n| 53 | BUILT 601-second member; three 6/16-second siblings TOUCH controlled-clock seam when changed. | R2943–2968 |\n| 54 | BUILT assembly intake/runbook PR176. | R1217–1248 |\n| 55 | ARMED-FOR-CAPTURE, hertz. Later negative runs supersede apparent always-ripe emergency; next bare-cargo wedge needs evidence before cleanup. nextest already mitigates run-level exposure. | R3075–3200 |\n| 56 | BUILT cross-worktree claim-addressing refusal; absolute-path allocation discipline reinforced Sept11. Does not implement IR26 incumbent admission. | R3201–3247 |\n| 57 | Living procedure / next assembly: pick-audit BUILT and twice field-used; no code lane to dispatch. Doyle owns fidelity accounting. | R3248–3306 |\n| 58 | RECEIPT-ONLY/stale OPEN: Cargo-metadata duplicate-bin gate already exists and xtask check calls it. Original prose allegation withdrawn; do not repair correct collision comments. | R3307–3341; binnames.rs:1–110; xtask main.rs:56,769–797 |\n| 59 | OPEN recurring capacity/adoption; disk-floor and local-lane budget machinery already built. Reconcile remaining consumers/receipts, not a new floor verb; heavy work held. | R3342–3475; local-lane.py:270–310,358–407 |\n| 60 | OPEN recurring producer-status discipline, not an unimplemented wrapper. Current local-lane stores real producer exit and preserves failure precedence; legacy/new driver adoption is remaining question. | R3476–3524; local-lane.py:255–263,309–310 |\n| 61 | TOUCH accepted-with-mitigation: next substantive spacerun literal/skip/tracker change; unrelated xtask work does not qualify. | R3525–3557 |\n| 62 | Docs collision BUILT/retired via ephemeral advisory ports. Other advisory collision only on new fire; IR78 is separate override-observability consequence. | R3558–3598 |\n| 63 | OPEN lifecycle/rig adoption, with third conhost-CWD face; dated pin population is not current kill authorization. New guard/driver source must be reconciled before redispatch. | R3599–3637; R48–49 |\n| 64 | BLOCKED operator capacity choice, trigger explicitly FIRED in IR86 in-job form (later amendment reverses earlier not-fired sweep). No agent bulk deletion. | R3638–3659; R5063–5066 |\n| 65 | REMEDIATED-AT-BOX, recurring check only after tailscale/auditd update or reimage. UNKNOWN whether such event occurred; no live audit requested/performed. | R3660–3685 |\n| 66 | CLOSED/BUILT with existing two-platform gate receipts; no delayed-needle redispatch. | R3686–3718 |\n| 67 | BUILT explicit integration-leg battery discipline; later JIT also says satisfied by construction. | R3719–3740; R119–121 |\n| 68 | UNKNOWN/armed investigation: next PSYCHE_INGEST_FAIL specimen or dedicated probe slot; index.lock cause experimentally refuted. Read named COMMUNE_FAIL cause first. | R3741–3768 |\n| 69 | OPEN specified #243 residual + separate anchored-consumer rider. Original emission lane and delivery.rs post-cut fixes LANDED. No fresh population/closure claim; source re-census/board reconciliation is prerequisite to new conversions. | R3769–3860 |\n| 70 | TOUCH recurrence enforcement only: witnessed partial bus fixed PR173; next IoBus constructor/API touch or new sink. No new qualifying touch established. | R3861–3887 |\n\n## Ranked actionable shortlist\n\n1. **Reconcile already-built metadata now — IR32, IR37, IR47, IR58, IR40(B).** Owner: Main/Doyle register closure; implementation owners need not be redispatched. Exact triggers/exit conditions are now source-satisfied: IR37 explicitly closes once pin fixup is on main; current shared pin is 0.4.1 and both workflows call it. IR32's producer nonzero/empty failures propagate before destination write; existing cells cover root/nested, blank/nonzero/unlaunchable, both gen/check. IR47 warnings and doyle split exist, and golden invokes notification selftest at golden.yml:366. IR58 check wiring and Cargo enumeration exist. IR40 compose_body literally emits `CI NEEDS`, supplied-needs scope and `run conclusion: not observed`. Minimal step: attach original landed acceptance/commit receipts and correct statuses; keep IR40 arm A separate. **Do not claim tests ran during this sweep.**\n\n2. **IR11 — the one clearly small remaining tooling implementation.** Exact trigger: R490 'any rig-tooling wave'; prior composition R176–178 names IR11 as next-intake small rider; current driver/workflow package is that tooling composition (R43–47). Source proof: find-cwd-holders.ps1:88–89 fields are only Pid, Name, Cwd, Started; :98 renders that table; `--headless` exists only in prose :18–21. Owner/seam: hertz tooling, existing row-construction seam. Minimal next step: explicitly accept the rider and add a truthful headless discriminator without changing census scope or pretending unreadable command line is false. Actual live-window verification must respect the hold; no probe now.\n\n3. **IR18 deferred (b) — ready for narrow intake, not a surprise cleanup rider.** Original IR18 acceptance discharged its prerequisite in R870–886; deferred lane explicitly named deployah, R1055–1117. Current source proves all three loss-of-knowledge sites still exist (reap.rs:59–64; resident_service_e2e.rs:103–108,127–129) and unreadable daemon.pid still returns no-breadcrumb at reap.rs:467–468. Owner/seam: deployah's deferred test helper lane, coordinated with hertz's common/lifecycle work. Minimal next step: reconcile old assignment and current callers, scope one shared absent/unreadable/malformed reader; do not duplicate existing Population::is_clean (:340–342), and do not start Windows execution now. This is real remaining code, but multi-consumer and not tiny.\n\n4. **IR26 admission/displacement residual — real, next owned infra intake.** R1793–1805 rules prior-owner guard plus loud/persisted takeover event; xtask main.rs:3379–3391 constructs its own owner and unconditionally write_owner, proving IR56 addressing did not implement admission. Owner: hertz pool tooling, Doyle ruling; seam pool_claim plus spt-poolguard. Minimal next step: accept narrow residual design with bare identity-less-claim case and actual refusal/remedy path. Pair IR49 only when poolguard touch is intentionally accepted; its ancestry false→InFlight remains source-visible. Not a spare-CI-window experiment.\n\n5. **Capacity/lifecycle receipt triage, not new infrastructure — IR31/46/59/60 and IR7/17/20/22/25/34/35/55/63.** R43–49 already composes these. local-lane.py has allocated reserve/growth, warm-cache version, admission, selected inventory, after-producer observations and real producer status. Minimal next step is enumerate which retained drivers/callers still bypass that seam and attach preserved acceptance; an OPEN heading is not evidence that a new shared driver is needed. Capacity operator decision IR64 is separately blocked; IR2's reopen condition warrants a question in that decision, not an automatic CARGO_INCREMENTAL flip.\n\n## Important non-dispatch findings\n- IR44 really still has the false preservation claim, but **next info.rs touch has not been established**. It is an excellent future tiny rider, not evidence-backed ripe-now work.\n- IR49 really remains ancestry-only, but no current landed-pool takeover request is established. Do not open standalone work solely because source still contains debt.\n- IR5's old summary-parser premise must not be revived for local-lane.py, which reads structured inventory; first name an actual count consumer.\n- IR2's historical retired state is not unconditional: recurring floor-class reds are its explicit reopen condition. This only reopens the decision; old timing comparison was contaminated and OFF lacked a green golden.\n- IR64's old sweep 'not fired' claim is superseded by IR86's explicit fired cross-reference. Operator ownership remains absolute.\n- IR12 and IR52 were composed again in old top-level sweep prose after their actual built/retired answers. Correct historical-current metadata rather than carrying those as implementation candidates.\n- No assertion about CI34983756975 completion, box clearance, current process population, fresh acceptance, or IR86 retirement is made here. Main owns IR86."},"error":null}}],"api":"openai-codex-responses","provider":"openai-codex","model":"gpt-6-astra","usage":{"input":5209,"output":5154,"cacheRead":151680,"cacheWrite":0,"totalTokens":162043,"reasoningTokens":88,"cost":{"input":0.052090000000000004,"output":0.2577,"cacheRead":0.15167999999999998,"cacheWrite":0,"total":0.46147}},"stopReason":"toolUse","timestamp":1789483746529,"responseId":"resp_043a862a419f59ae016aa95ae2de1887d29e0e7b1fc84494b3","providerPayload":{"type":"openaiResponsesHistory","provider":"openai-codex","dt":true,"items":[{"id":"rs_043a862a419f59ae016aa95ae550c487d2b4b8798cb720637d","type":"reasoning","content":[],"encrypted_content":"gAAAAABqqVrqN-nuOMP0uzRmZKs7Dj8KWVLu1UEj19mV7IDCqEKCl6KdyndeZ3IMd2eKml74Z1_3g0ykSfypSEFsXoodFGVvICrZ1-IsFmr3DK5RXg0uJIhq5Z186Yj6ZJARORv3LEu0Xx1RMDs86lC7bJehAFtCjv-FHrsQSCtVypqLB_dV9Ys1BvCatTXFGey1yrSlSCGCOcpQvh5XwnNh5X3toUK-fRQN5s7JZEB1Gy_D0jDe6hcK502kY9vTJ-ip9WG7PkSfZ424_kZN5jU7YKyL6R9ll0rj_3pBXGIxhRkFw4VEJ639-9pMfGBNWPdD_AtiReEuf25HbXBIAOafA5szkglF5t2Zc1e_3BKSWjqXBhu7XPTiYIBZHU_Iut5gmfUwlXIFXL4fcvkexmz3OKBLI6cwiXrdxQ6rpYqXQBz5pTU-Js_ZGJx75WMPPjRCM_oCqWp1gsLtKc4Wor8F3kxkDfqq6REhZydemTvf0MJ9jEtHyqy6Xi26rfy-21s1cglwI4f5wxClH70deVcbSMbPEV-aqKfnpWSQG2cbZw71kYoDJJ5vxoXCvQ5CehWi0Q8xlKaMcO7aiDLTBt1jlmBbZnhmK7NimrauGxPskVpXaW4IRxJ6zWKDdt3xhLB5HLX6m31FcZpgIS0du-zE2mUUs4PFLlRiL9Fp4IYMNH3TqJYmLeEQB-m_Ao5ATkH-2f9eD05_-NpZeAkZvhBYf9Qbc6pFHU3TtGn81L-09VvfgCVb_fYgtN7c8qKcLqcPOp_Udd6Zy6GvLr2nntJoOA2SaTNqcQp-pAVxlYz67F35wISRQMDRxlNb6oO-6OhOJvvle5xfns9E9MUNR6nj5s1snAZMGa86vv5yyFL77jSnTVF7sne7jqt_B-_GOrPxntEsL-NFPNB2b136jA2o0yr6FFFruNYBTpnKhoA7HqY-xVxFWSJBv5H0XVAQHwoe8JHPtic97We4PuQwZXQaPK87aVs7DDYvUqx2BFQJsQmt_sXFO6U5fJyWelB0HTBhiXLZG-qK5d-o2M0NXiw6_FxYuCufMRdzn4oDQwbiZ2i2hCXBW9O1eCMMspEO8O1IaLTeOKptrIGgt3HhFS5UWDySOfNKFyT_NbbnoJkkzVak_BDeqOsyl1mkl6pdGixyd2IXZx1awYLpY8-kqmb3_8k28ftorytUNRv7174or5lUgQF3X65lYrk6yb8Pw3AHT1mwIulKVsfp7-Hrm-D798Yv--WhKSlh3crTNLXVGODDfXNYb44gkMypRZya4RSyScNA7Rcl1QLtx0J19WxlQEl4p8eYflVZH0bb7y0pSQJM2rBKLlJXp53VpPK90_LxsO30oQUxYLxr-dV8Xf8nEWRsP6bt70F13I9DX_YTRfIgOLmR2O6aGy-slGR9npDJCxQ7kUsGURkqpDyQn9J1oxFbuadCsrgCeNjFSBrxW180pbZBFpim9rm016Q5l0zTleD0uRRdoB4rRPNHcshJjRwsxKWQ0sfFYCwA3qZ-g61MOkBj9mPx8wyXTjxHsIufyBGp5LUZg6bGxvy_mGL0j7Zan8s7pUgC4dDAPfTC-x5lSRepWFCt5Et9BKIt3sEYS9c45tH8ud49Rfm6zhnpj8iunfq-WR8lEknQZIqcIyhwwbk0kz7vXFdr4bYbfqLxU0rv1FBlx1_lfU3ktOPgDIK6gIXWflqjX0JGoQQdUF38KeqrjcQ1Uu-eADr7WKUcWOfjZziu_jlWSKf3ancjmOgLeZc4BGPHA-53HOMrrFS7wQVpoEd4YTMLGR9ztgkDVFwCZkAYETzSEQ_QKgt5SaA74EiMHdOlTxRy2tMAVXYvwZG8TILmDatlmF948Y7iN-TAyGQd","internal_chat_message_metadata_passthrough":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"},"summary":[{"type":"summary_text","text":"**Enumerating 70 table rows**"}],"metadata":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"}},{"id":"fc_043a862a419f59ae016aa95aeaad0087d29390588fbd087238","type":"function_call","status":"completed","arguments":"{\"type\":null,\"data\":{\"summary\":\"Accounted for all 70 assigned IDs, including headingless IR-31 and status-reversing amendments. Highest-value immediate work is register reconciliation: IR-32/37/47/58 and IR-40 arm B already have implementations at the fixed tree. IR-11 remains a genuinely small tooling rider. Larger lifecycle/capacity work remains composed or held, not fresh dispatch material. No edits, builds, tests, validation commands, or live-process/service probes performed.\",\"files\":[{\"path\":\".worktrees/hertz-ir86-disk-delta/docs/INFRA-REGISTER.md\",\"description\":\"Complete IR-1–70 population and amendments; IR-31 starts at line 2015 without a heading; later cross-references checked for status/trigger consequences.\"},{\"path\":\".worktrees/hertz-ir86-disk-delta/crates/xtask/src/main.rs\",\"description\":\"Existing empty/failed-help refusal and preservation tests; duplicate-bin gate wired into check; pool_claim still writes without incumbent admission.\"},{\"path\":\".worktrees/hertz-ir86-disk-delta/crates/xtask/src/binnames.rs\",\"description\":\"Already-built IR-58 cargo-metadata enumeration and duplicate-bin-name predicate.\"},{\"path\":\".worktrees/hertz-ir86-disk-delta/.github/ci/ci-notify.sh\",\"description\":\"Already-built IR-40 arm-B scope wording and IR-47 missing-attribution warning/doyle split.\"},{\"path\":\".worktrees/hertz-ir86-disk-delta/.github/ci/traceable-reqs.sh\",\"description\":\"Shared checker pin is already 0.4.1; both CI and golden call it, with placement enforcement enabled in manifest.\"},{\"path\":\".worktrees/hertz-ir86-disk-delta/.github/ci/find-cwd-holders.ps1\",\"description\":\"IR-11 remains: output objects expose Pid/Name/Cwd/Started, not Headless.\"},{\"path\":\".worktrees/hertz-ir86-disk-delta/.github/ci/local-lane.py\",\"description\":\"Existing allocated-capacity, truthful producer-exit, inventory, scrub and census construction; do not rebuild IR-31/59/60 mechanisms wholesale.\"},{\"path\":\".worktrees/hertz-ir86-disk-delta/crates/spt/tests/common/reap.rs\",\"description\":\"IR-18 deferred breadcrumb-read collapse remains; existing shared population cleanliness predicate already present.\"},{\"path\":\".worktrees/hertz-ir86-disk-delta/crates/spt-store/src/info.rs\",\"description\":\"IR-44 overclaim remains at lines 874–875.\"},{\"path\":\".worktrees/hertz-ir86-disk-delta/crates/spt-poolguard/src/lib.rs\",\"description\":\"IR-49 remains: false ancestry directly returns InFlight, without patch-id fallback.\"}],\"architecture\":\"The register mixes historical incidents, implemented remedies, recurring procedure, and residual obligations. Current shared seams are xtask generation/bin enumeration/pool verbs, CI notification/checker scripts, local-lane.py admission/evidence, and test common/reap. Existing implementation is not equivalent to historical acceptance; reconcile receipts separately and retain narrowly defined residuals.\",\"report\":\"## Scope and notation\\nAll references below are relative to `.worktrees/hertz-ir86-disk-delta/`. `R` means `docs/INFRA-REGISTER.md`. Read-only source findings, not freshly executed acceptance. READY means actionable composition/reconciliation now, not authorization to launch Windows work. TOUCH means retain until its named seam/event; UNKNOWN means qualifying evidence not established. The post-merge CI hold remains intact.\\n\\n## Complete disposition inventory — all 70 IDs\\n\\n| ID | Current disposition and exact remaining trigger | Evidence |\\n|---|---|---|\\n| 1 | BUILT/LANDED; no remaining implementation. Historical golden exercise recorded. | R274–301; 3008–3073 |\\n| 2 | RETIRED/no flip, but explicit reopen condition has now acquired recurring floor-red evidence. Re-weigh as a decision, not an incremental-off patch; experiment BLOCKED on quiet authorized windows. | R304–326; recurring reds R3348–3362 and 5082 |\\n| 3 | TOUCH: endpoint lifecycle/daemon supervision milestone; generic new stream family explicitly did not qualify. No fresh qualifying milestone established in this sweep. | R328–340; 121–123 |\\n| 4 | BUILT/LANDED, all three riders; no redispatch. | R341–363; 3008–3073 |\\n| 5 | TOUCH: actual need for a nextest SUMMARY COUNT, not any script edit. Current local driver uses structured TestListSummary, so do not invent a prose-parser consumer. | R364–382; .github/ci/local-lane.py:63–85 |\\n| 6 | TOUCH/adoption audit: next count-reporting gate-script/CI touch. Historical conditional lane did NOT satisfy existing estate; count+membership in current local-lane selection is one covered consumer, not estate closure. | R383–394; 3051–3059; local-lane.py:383–392 |\\n| 7 | OPEN/composed hertz lifecycle package; reconcile landed rig changes before any redispatch. Heavy Windows work held. | R395–405; 48–49 |\\n| 8 | BUILT: both census verdicts expose unreadable population; Linux failed-kill reporting included. IR-18 helper residual is not erased by this closure. | R406–439 |\\n| 9 | BUILT toolchain pin plus exercised measurement half. | R440–477 |\\n| 10 | TOUCH: next gate-runbook/docs wave; consumer-suite selection checklist, not product code. | R478–485 |\\n| 11 | READY small tooling rider; explicitly composed at prior intake, source still lacks column. | R486–492; 176–178; .github/ci/find-cwd-holders.ps1:83–98 |\\n| 12 | BUILT; stale-binary kin RETIRED by actual mutation experiment, no residual product fix. Header/top sweep metadata should not keep composing W3 repair. | R493–540, especially 496–510 |\\n| 13 | BUILT mutation-proved hygiene followups. | R541–551 |\\n| 14 | Recurring audit TOUCH/receipt: Sept-11 cleanup instance discharged, recurring hygiene remains. No current orphan/reap authorization inferred from dated counts. | R552–714; cleanup receipt .spt/cleanup-20260911.json |\\n| 15 | BUILT authenticated oracle; does not root-cause historical specimen. | R1257–1283 |\\n| 16 | BUILT, loud-refusal remedy checked; rename proposal explicitly withdrawn as false premise. | R833–869 |\\n| 17 | OPEN/instrumented-awaiting-fire, hertz package. Linux member CLOSED via ready-path hash mechanism; Windows specimen/sub-observation remain, no renewed isolated rate run. | R715–832, especially 806–832 |\\n| 18 | Original acceptance BUILT. Deferred (b) breadcrumb classification remains REAL, not closure-ready: daemon.pid, mock_pid, brain_ready still collapse unreadable/malformed into absence. Deployah named owner, after original hertz lane; current lane intake needed, Windows execution held. | R1055–1117; common/reap.rs:59–64,467–468; resident_service_e2e.rs:103–108,127–129 |\\n| 19 | RETIRED intentional PR-only classifier; never extend main classifier as alleged fix. | R1155–1183 |\\n| 20 | OPEN/composed hertz lifecycle package; stop-discrimination receipt on both environments owed, preserve load-bearing perch pid. No duplicate broad teardown fix. | R1184–1216 |\\n| 21 | BUILT fixture prebuild/helper migration. Historical same-package build-edge allegation retracted. | R1284–1498 |\\n| 22 | OPEN diagnostic-set residual plus driver isolation adoption. Sept-13 inherited OWL_SESSION_ID recurrence is real, but local-lane already reuses scrub: discriminate all-vars diagnostic vs adoption failure, not fresh scrub implementation. | R1499–1520; R6523–6543; local-lane.py:10–13 |\\n| 23 | BUILT private fixture staging plus process-global resolver serialization. | R1521–1545 |\\n| 24 | BUILT audited brain-job termination; distinct from IR16. | R1546–1585 |\\n| 25 | OPEN/mitigated by nextest; harden named marginal tests only in hertz package or renewed loaded bare-cargo use. No golden-wide defect inferred. | R1586–1632 |\\n| 26 | OPEN real residual: original identity enforcement committed; incumbent claim adjudication/displacement event still absent. Next CI/infra batch or pool audit composition, not a duplicate identity guard. | R1633–1805; xtask main.rs:3295–3395 |\\n| 27 | OPEN adoption/timing gap: pool-sweep already exists. Post-worktree teardown sweep/adoption, not new enumeration. Next CI/infra batch. | R1806–1839 |\\n| 28 | BUILT release-range/changelog accounting, PR176. | R1840–1854 |\\n| 29 | Original barrier fix LANDED; later rung/serve-window and emitted-margin residuals need exact twohost receipt reconciliation. Old six-draw margin series CLOSED/unextendable. | R1855–1917 |\\n| 30 | Receipt/event-only family record: instruments LANDED; wait for discriminating fires. Linux face resolved; do not rebuild instrumentation. | R1918–2014 |\\n| 31 | Headingless OPEN capacity/adoption record, not missing ID. Aggregate budgeting and start/end evidence already have local-lane construction; reconcile adoption/allocation and preserve hosted-relay isolation hold. No new pool census presumed required. | R2015–2177; R65–102; local-lane.py:1–13,270–307,358–407 |\\n| 32 | RECEIPT-ONLY/stale OPEN: failed and empty-help producer refusal already implemented before writing destination, with root/nested preservation cells. Do not add arbitrary historical-length floor; successful help shrink is deliberately supported. Kin filter-inventory rule remains procedural. | R2178–2211; xtask main.rs:98–124,321–401,441–448 |\\n| 33 | RECEIPT-ONLY/measurement: 16MiB CLI stack and smoke already exist; current margin/acceptance reconciliation only. Heavy fresh debug run held. | R2212–2264; spt/src/main.rs:128–132,248–252 |\\n| 34 | OPEN lifecycle/config rider; expected-leak remedy not established by one quiet run. No rate/closure inferred. | R2265–2289 |\\n| 35 | OPEN rate record; requires operator disposition plus package landing and remeasurement. BLOCKED from new heavy run now. | R2290–2325 |\\n| 36 | BUILT shared output_bounded adoption; no clone-hoist redispatch. | R2326–2361 |\\n| 37 | RECEIPT-ONLY/stale OPEN: upstream 0.4.1 fix now consumed through both workflow paths; placement on/module_banner accept. Entry's 'closes when pin lands' is source-satisfied. Reconcile landed receipt, no upgrade implementation. | R2362–2424; R6339–6365; .github/ci/traceable-reqs.sh:5–6; ci.yml:252–257; golden.yml:1442–1447; traceable-reqs.toml:23–25 |\\n| 38 | BUILT final-resident teardown; conhost disposal discipline remains in IR14/63. | R2425–2463 |\\n| 39 | BUILT shared package-correct missing-fixture precondition; no repeat sibling_bin sweep. | R2464–2500 |\\n| 40 | SPLIT: arm B RECEIPT-ONLY (CI NEEDS/scope/not-run text shipped); arm A UNKNOWN measurement on next commune/psyche touch, envelope sequence not recency. | R2501–2577; ci-notify.sh:129–140 |\\n| 41 | Accepted documented queued supersession; docs remedy DONE. Policy choice on next ci.yml/runbook touch, not automatic per-SHA-concurrency change. | R2578–2609 |\\n| 42 | BUILT documentation; optional incumbent notice belongs IR26, not reopening IR42. | R2610–2637 |\\n| 43 | UNKNOWN/touch investigation: derive bound on next knock-carrier touch or NoReply red; no new confirming specimen established. | R2638–2654 |\\n| 44 | TOUCH, real tiny comment defect remains. No current info.rs-touch trigger established; keep ranked below immediate tooling rider. | R2655–2675; spt-store/src/info.rs:872–877 |\\n| 45 | RETIRED disk-hermeticity question answered; network ingress residue explicitly elsewhere. | R2676–2706 |\\n| 46 | Implemented START/END/DOCS instant tokens; RECEIPT/adoption reconciliation rather than another token implementation. Sizing/dependency ownership remains IR86/Main. | R2707–2773; R25–35; 5055–5067 |\\n| 47 | RECEIPT-ONLY/stale OPEN: actual missing/parse-failure annotations and legitimate doyle quiet case already shipped. Do not reapply ancient stash. | R2774–2800; ci-notify.sh:193–210; ci-notify-selftest.sh:225–229 |\\n| 48 | TOUCH preventive control on parity-cell edit; current defect not claimed and no qualifying edit established. | R2801–2821 |\\n| 49 | TOUCH real ancestry-only residual; first landed-member takeover or poolguard touch. No current takeover request established; source confirms patch-id fallback absent. | R2822–2855; spt-poolguard/src/lib.rs:424–438 |\\n| 50 | CLOSED/BUILT adoption complete with explicitly distinct engine-room direct sink path. | R2856–2913 |\\n| 51 | BLOCKED/conditional: attribution-before-net-off, or separately owned hermeticity pass; hosted-relay prebuilt route still needs isolation proof. No blanket net-off fix authorized. | R2914–2942; R95–102 |\\n| 52 | BUILT full recursive CLI reference since SIGNET, despite obsolete carry-forward notes in sweep prose. | R2969–3007; xtask main.rs:165–223 |\\n| 53 | BUILT 601-second member; three 6/16-second siblings TOUCH controlled-clock seam when changed. | R2943–2968 |\\n| 54 | BUILT assembly intake/runbook PR176. | R1217–1248 |\\n| 55 | ARMED-FOR-CAPTURE, hertz. Later negative runs supersede apparent always-ripe emergency; next bare-cargo wedge needs evidence before cleanup. nextest already mitigates run-level exposure. | R3075–3200 |\\n| 56 | BUILT cross-worktree claim-addressing refusal; absolute-path allocation discipline reinforced Sept11. Does not implement IR26 incumbent admission. | R3201–3247 |\\n| 57 | Living procedure / next assembly: pick-audit BUILT and twice field-used; no code lane to dispatch. Doyle owns fidelity accounting. | R3248–3306 |\\n| 58 | RECEIPT-ONLY/stale OPEN: Cargo-metadata duplicate-bin gate already exists and xtask check calls it. Original prose allegation withdrawn; do not repair correct collision comments. | R3307–3341; binnames.rs:1–110; xtask main.rs:56,769–797 |\\n| 59 | OPEN recurring capacity/adoption; disk-floor and local-lane budget machinery already built. Reconcile remaining consumers/receipts, not a new floor verb; heavy work held. | R3342–3475; local-lane.py:270–310,358–407 |\\n| 60 | OPEN recurring producer-status discipline, not an unimplemented wrapper. Current local-lane stores real producer exit and preserves failure precedence; legacy/new driver adoption is remaining question. | R3476–3524; local-lane.py:255–263,309–310 |\\n| 61 | TOUCH accepted-with-mitigation: next substantive spacerun literal/skip/tracker change; unrelated xtask work does not qualify. | R3525–3557 |\\n| 62 | Docs collision BUILT/retired via ephemeral advisory ports. Other advisory collision only on new fire; IR78 is separate override-observability consequence. | R3558–3598 |\\n| 63 | OPEN lifecycle/rig adoption, with third conhost-CWD face; dated pin population is not current kill authorization. New guard/driver source must be reconciled before redispatch. | R3599–3637; R48–49 |\\n| 64 | BLOCKED operator capacity choice, trigger explicitly FIRED in IR86 in-job form (later amendment reverses earlier not-fired sweep). No agent bulk deletion. | R3638–3659; R5063–5066 |\\n| 65 | REMEDIATED-AT-BOX, recurring check only after tailscale/auditd update or reimage. UNKNOWN whether such event occurred; no live audit requested/performed. | R3660–3685 |\\n| 66 | CLOSED/BUILT with existing two-platform gate receipts; no delayed-needle redispatch. | R3686–3718 |\\n| 67 | BUILT explicit integration-leg battery discipline; later JIT also says satisfied by construction. | R3719–3740; R119–121 |\\n| 68 | UNKNOWN/armed investigation: next PSYCHE_INGEST_FAIL specimen or dedicated probe slot; index.lock cause experimentally refuted. Read named COMMUNE_FAIL cause first. | R3741–3768 |\\n| 69 | OPEN specified #243 residual + separate anchored-consumer rider. Original emission lane and delivery.rs post-cut fixes LANDED. No fresh population/closure claim; source re-census/board reconciliation is prerequisite to new conversions. | R3769–3860 |\\n| 70 | TOUCH recurrence enforcement only: witnessed partial bus fixed PR173; next IoBus constructor/API touch or new sink. No new qualifying touch established. | R3861–3887 |\\n\\n## Ranked actionable shortlist\\n\\n1. **Reconcile already-built metadata now — IR32, IR37, IR47, IR58, IR40(B).** Owner: Main/Doyle register closure; implementation owners need not be redispatched. Exact triggers/exit conditions are now source-satisfied: IR37 explicitly closes once pin fixup is on main; current shared pin is 0.4.1 and both workflows call it. IR32's producer nonzero/empty failures propagate before destination write; existing cells cover root/nested, blank/nonzero/unlaunchable, both gen/check. IR47 warnings and doyle split exist, and golden invokes notification selftest at golden.yml:366. IR58 check wiring and Cargo enumeration exist. IR40 compose_body literally emits `CI NEEDS`, supplied-needs scope and `run conclusion: not observed`. Minimal step: attach original landed acceptance/commit receipts and correct statuses; keep IR40 arm A separate. **Do not claim tests ran during this sweep.**\\n\\n2. **IR11 — the one clearly small remaining tooling implementation.** Exact trigger: R490 'any rig-tooling wave'; prior composition R176–178 names IR11 as next-intake small rider; current driver/workflow package is that tooling composition (R43–47). Source proof: find-cwd-holders.ps1:88–89 fields are only Pid, Name, Cwd, Started; :98 renders that table; `--headless` exists only in prose :18–21. Owner/seam: hertz tooling, existing row-construction seam. Minimal next step: explicitly accept the rider and add a truthful headless discriminator without changing census scope or pretending unreadable command line is false. Actual live-window verification must respect the hold; no probe now.\\n\\n3. **IR18 deferred (b) — ready for narrow intake, not a surprise cleanup rider.** Original IR18 acceptance discharged its prerequisite in R870–886; deferred lane explicitly named deployah, R1055–1117. Current source proves all three loss-of-knowledge sites still exist (reap.rs:59–64; resident_service_e2e.rs:103–108,127–129) and unreadable daemon.pid still returns no-breadcrumb at reap.rs:467–468. Owner/seam: deployah's deferred test helper lane, coordinated with hertz's common/lifecycle work. Minimal next step: reconcile old assignment and current callers, scope one shared absent/unreadable/malformed reader; do not duplicate existing Population::is_clean (:340–342), and do not start Windows execution now. This is real remaining code, but multi-consumer and not tiny.\\n\\n4. **IR26 admission/displacement residual — real, next owned infra intake.** R1793–1805 rules prior-owner guard plus loud/persisted takeover event; xtask main.rs:3379–3391 constructs its own owner and unconditionally write_owner, proving IR56 addressing did not implement admission. Owner: hertz pool tooling, Doyle ruling; seam pool_claim plus spt-poolguard. Minimal next step: accept narrow residual design with bare identity-less-claim case and actual refusal/remedy path. Pair IR49 only when poolguard touch is intentionally accepted; its ancestry false→InFlight remains source-visible. Not a spare-CI-window experiment.\\n\\n5. **Capacity/lifecycle receipt triage, not new infrastructure — IR31/46/59/60 and IR7/17/20/22/25/34/35/55/63.** R43–49 already composes these. local-lane.py has allocated reserve/growth, warm-cache version, admission, selected inventory, after-producer observations and real producer status. Minimal next step is enumerate which retained drivers/callers still bypass that seam and attach preserved acceptance; an OPEN heading is not evidence that a new shared driver is needed. Capacity operator decision IR64 is separately blocked; IR2's reopen condition warrants a question in that decision, not an automatic CARGO_INCREMENTAL flip.\\n\\n## Important non-dispatch findings\\n- IR44 really still has the false preservation claim, but **next info.rs touch has not been established**. It is an excellent future tiny rider, not evidence-backed ripe-now work.\\n- IR49 really remains ancestry-only, but no current landed-pool takeover request is established. Do not open standalone work solely because source still contains debt.\\n- IR5's old summary-parser premise must not be revived for local-lane.py, which reads structured inventory; first name an actual count consumer.\\n- IR2's historical retired state is not unconditional: recurring floor-class reds are its explicit reopen condition. This only reopens the decision; old timing comparison was contaminated and OFF lacked a green golden.\\n- IR64's old sweep 'not fired' claim is superseded by IR86's explicit fired cross-reference. Operator ownership remains absolute.\\n- IR12 and IR52 were composed again in old top-level sweep prose after their actual built/retired answers. Correct historical-current metadata rather than carrying those as implementation candidates.\\n- No assertion about CI34983756975 completion, box clearance, current process population, fresh acceptance, or IR86 retirement is made here. Main owns IR86.\"},\"error\":null}","call_id":"call_jY0la8LMTlguqVawLsLpOQ5Q","internal_chat_message_metadata_passthrough":{"create_time":1789483747.319207,"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"},"name":"yield","metadata":{"turn_id":"c3e128de-1407-4cf8-98e6-24db7cca2975"}}]},"duration":157561.59459999204,"ttft":3009.5238000154495,"completedAt":1789483904092,"contextSnapshot":{"promptTokens":156889,"nonMessageTokens":10342,"compactionEpoch":0}}}
{"type":"message","id":"0a36f6aa","parentId":"81cc5da3","timestamp":"2026-09-15T14:51:44.095Z","message":{"role":"toolResult","toolCallId":"call_jY0la8LMTlguqVawLsLpOQ5Q|fc_043a862a419f59ae016aa95aeaad0087d29390588fbd087238","toolName":"yield","content":[{"type":"text","text":"Result submitted."}],"details":{"data":{"summary":"Accounted for all 70 assigned IDs, including headingless IR-31 and status-reversing amendments. Highest-value immediate work is register reconciliation: IR-32/37/47/58 and IR-40 arm B already have implementations at the fixed tree. IR-11 remains a genuinely small tooling rider. Larger lifecycle/capacity work remains composed or held, not fresh dispatch material. No edits, builds, tests, validation commands, or live-process/service probes performed.","files":[{"path":".worktrees/hertz-ir86-disk-delta/docs/INFRA-REGISTER.md","description":"Complete IR-1–70 population and amendments; IR-31 starts at line 2015 without a heading; later cross-references checked for status/trigger consequences."},{"path":".worktrees/hertz-ir86-disk-delta/crates/xtask/src/main.rs","description":"Existing empty/failed-help refusal and preservation tests; duplicate-bin gate wired into check; pool_claim still writes without incumbent admission."},{"path":".worktrees/hertz-ir86-disk-delta/crates/xtask/src/binnames.rs","description":"Already-built IR-58 cargo-metadata enumeration and duplicate-bin-name predicate."},{"path":".worktrees/hertz-ir86-disk-delta/.github/ci/ci-notify.sh","description":"Already-built IR-40 arm-B scope wording and IR-47 missing-attribution warning/doyle split."},{"path":".worktrees/hertz-ir86-disk-delta/.github/ci/traceable-reqs.sh","description":"Shared checker pin is already 0.4.1; both CI and golden call it, with placement enforcement enabled in manifest."},{"path":".worktrees/hertz-ir86-disk-delta/.github/ci/find-cwd-holders.ps1","description":"IR-11 remains: output objects expose Pid/Name/Cwd/Started, not Headless."},{"path":".worktrees/hertz-ir86-disk-delta/.github/ci/local-lane.py","description":"Existing allocated-capacity, truthful producer-exit, inventory, scrub and census construction; do not rebuild IR-31/59/60 mechanisms wholesale."},{"path":".worktrees/hertz-ir86-disk-delta/crates/spt/tests/common/reap.rs","description":"IR-18 deferred breadcrumb-read collapse remains; existing shared population cleanliness predicate already present."},{"path":".worktrees/hertz-ir86-disk-delta/crates/spt-store/src/info.rs","description":"IR-44 overclaim remains at lines 874–875."},{"path":".worktrees/hertz-ir86-disk-delta/crates/spt-poolguard/src/lib.rs","description":"IR-49 remains: false ancestry directly returns InFlight, without patch-id fallback."}],"architecture":"The register mixes historical incidents, implemented remedies, recurring procedure, and residual obligations. Current shared seams are xtask generation/bin enumeration/pool verbs, CI notification/checker scripts, local-lane.py admission/evidence, and test common/reap. Existing implementation is not equivalent to historical acceptance; reconcile receipts separately and retain narrowly defined residuals.","report":"## Scope and notation\nAll references below are relative to `.worktrees/hertz-ir86-disk-delta/`. `R` means `docs/INFRA-REGISTER.md`. Read-only source findings, not freshly executed acceptance. READY means actionable composition/reconciliation now, not authorization to launch Windows work. TOUCH means retain until its named seam/event; UNKNOWN means qualifying evidence not established. The post-merge CI hold remains intact.\n\n## Complete disposition inventory — all 70 IDs\n\n| ID | Current disposition and exact remaining trigger | Evidence |\n|---|---|---|\n| 1 | BUILT/LANDED; no remaining implementation. Historical golden exercise recorded. | R274–301; 3008–3073 |\n| 2 | RETIRED/no flip, but explicit reopen condition has now acquired recurring floor-red evidence. Re-weigh as a decision, not an incremental-off patch; experiment BLOCKED on quiet authorized windows. | R304–326; recurring reds R3348–3362 and 5082 |\n| 3 | TOUCH: endpoint lifecycle/daemon supervision milestone; generic new stream family explicitly did not qualify. No fresh qualifying milestone established in this sweep. | R328–340; 121–123 |\n| 4 | BUILT/LANDED, all three riders; no redispatch. | R341–363; 3008–3073 |\n| 5 | TOUCH: actual need for a nextest SUMMARY COUNT, not any script edit. Current local driver uses structured TestListSummary, so do not invent a prose-parser consumer. | R364–382; .github/ci/local-lane.py:63–85 |\n| 6 | TOUCH/adoption audit: next count-reporting gate-script/CI touch. Historical conditional lane did NOT satisfy existing estate; count+membership in current local-lane selection is one covered consumer, not estate closure. | R383–394; 3051–3059; local-lane.py:383–392 |\n| 7 | OPEN/composed hertz lifecycle package; reconcile landed rig changes before any redispatch. Heavy Windows work held. | R395–405; 48–49 |\n| 8 | BUILT: both census verdicts expose unreadable population; Linux failed-kill reporting included. IR-18 helper residual is not erased by this closure. | R406–439 |\n| 9 | BUILT toolchain pin plus exercised measurement half. | R440–477 |\n| 10 | TOUCH: next gate-runbook/docs wave; consumer-suite selection checklist, not product code. | R478–485 |\n| 11 | READY small tooling rider; explicitly composed at prior intake, source still lacks column. | R486–492; 176–178; .github/ci/find-cwd-holders.ps1:83–98 |\n| 12 | BUILT; stale-binary kin RETIRED by actual mutation experiment, no residual product fix. Header/top sweep metadata should not keep composing W3 repair. | R493–540, especially 496–510 |\n| 13 | BUILT mutation-proved hygiene followups. | R541–551 |\n| 14 | Recurring audit TOUCH/receipt: Sept-11 cleanup instance discharged, recurring hygiene remains. No current orphan/reap authorization inferred from dated counts. | R552–714; cleanup receipt .spt/cleanup-20260911.json |\n| 15 | BUILT authenticated oracle; does not root-cause historical specimen. | R1257–1283 |\n| 16 | BUILT, loud-refusal remedy checked; rename proposal explicitly withdrawn as false premise. | R833–869 |\n| 17 | OPEN/instrumented-awaiting-fire, hertz package. Linux member CLOSED via ready-path hash mechanism; Windows specimen/sub-observation remain, no renewed isolated rate run. | R715–832, especially 806–832 |\n| 18 | Original acceptance BUILT. Deferred (b) breadcrumb classification remains REAL, not closure-ready: daemon.pid, mock_pid, brain_ready still collapse unreadable/malformed into absence. Deployah named owner, after original hertz lane; current lane intake needed, Windows execution held. | R1055–1117; common/reap.rs:59–64,467–468; resident_service_e2e.rs:103–108,127–129 |\n| 19 | RETIRED intentional PR-only classifier; never extend main classifier as alleged fix. | R1155–1183 |\n| 20 | OPEN/composed hertz lifecycle package; stop-discrimination receipt on both environments owed, preserve load-bearing perch pid. No duplicate broad teardown fix. | R1184–1216 |\n| 21 | BUILT fixture prebuild/helper migration. Historical same-package build-edge allegation retracted. | R1284–1498 |\n| 22 | OPEN diagnostic-set residual plus driver isolation adoption. Sept-13 inherited OWL_SESSION_ID recurrence is real, but local-lane already reuses scrub: discriminate all-vars diagnostic vs adoption failure, not fresh scrub implementation. | R1499–1520; R6523–6543; local-lane.py:10–13 |\n| 23 | BUILT private fixture staging plus process-global resolver serialization. | R1521–1545 |\n| 24 | BUILT audited brain-job termination; distinct from IR16. | R1546–1585 |\n| 25 | OPEN/mitigated by nextest; harden named marginal tests only in hertz package or renewed loaded bare-cargo use. No golden-wide defect inferred. | R1586–1632 |\n| 26 | OPEN real residual: original identity enforcement committed; incumbent claim adjudication/displacement event still absent. Next CI/infra batch or pool audit composition, not a duplicate identity guard. | R1633–1805; xtask main.rs:3295–3395 |\n| 27 | OPEN adoption/timing gap: pool-sweep already exists. Post-worktree teardown sweep/adoption, not new enumeration. Next CI/infra batch. | R1806–1839 |\n| 28 | BUILT release-range/changelog accounting, PR176. | R1840–1854 |\n| 29 | Original barrier fix LANDED; later rung/serve-window and emitted-margin residuals need exact twohost receipt reconciliation. Old six-draw margin series CLOSED/unextendable. | R1855–1917 |\n| 30 | Receipt/event-only family record: instruments LANDED; wait for discriminating fires. Linux face resolved; do not rebuild instrumentation. | R1918–2014 |\n| 31 | Headingless OPEN capacity/adoption record, not missing ID. Aggregate budgeting and start/end evidence already have local-lane construction; reconcile adoption/allocation and preserve hosted-relay isolation hold. No new pool census presumed required. | R2015–2177; R65–102; local-lane.py:1–13,270–307,358–407 |\n| 32 | RECEIPT-ONLY/stale OPEN: failed and empty-help producer refusal already implemented before writing destination, with root/nested preservation cells. Do not add arbitrary historical-length floor; successful help shrink is deliberately supported. Kin filter-inventory rule remains procedural. | R2178–2211; xtask main.rs:98–124,321–401,441–448 |\n| 33 | RECEIPT-ONLY/measurement: 16MiB CLI stack and smoke already exist; current margin/acceptance reconciliation only. Heavy fresh debug run held. | R2212–2264; spt/src/main.rs:128–132,248–252 |\n| 34 | OPEN lifecycle/config rider; expected-leak remedy not established by one quiet run. No rate/closure inferred. | R2265–2289 |\n| 35 | OPEN rate record; requires operator disposition plus package landing and remeasurement. BLOCKED from new heavy run now. | R2290–2325 |\n| 36 | BUILT shared output_bounded adoption; no clone-hoist redispatch. | R2326–2361 |\n| 37 | RECEIPT-ONLY/stale OPEN: upstream 0.4.1 fix now consumed through both workflow paths; placement on/module_banner accept. Entry's 'closes when pin lands' is source-satisfied. Reconcile landed receipt, no upgrade implementation. | R2362–2424; R6339–6365; .github/ci/traceable-reqs.sh:5–6; ci.yml:252–257; golden.yml:1442–1447; traceable-reqs.toml:23–25 |\n| 38 | BUILT final-resident teardown; conhost disposal discipline remains in IR14/63. | R2425–2463 |\n| 39 | BUILT shared package-correct missing-fixture precondition; no repeat sibling_bin sweep. | R2464–2500 |\n| 40 | SPLIT: arm B RECEIPT-ONLY (CI NEEDS/scope/not-run text shipped); arm A UNKNOWN measurement on next commune/psyche touch, envelope sequence not recency. | R2501–2577; ci-notify.sh:129–140 |\n| 41 | Accepted documented queued supersession; docs remedy DONE. Policy choice on next ci.yml/runbook touch, not automatic per-SHA-concurrency change. | R2578–2609 |\n| 42 | BUILT documentation; optional incumbent notice belongs IR26, not reopening IR42. | R2610–2637 |\n| 43 | UNKNOWN/touch investigation: derive bound on next knock-carrier touch or NoReply red; no new confirming specimen established. | R2638–2654 |\n| 44 | TOUCH, real tiny comment defect remains. No current info.rs-touch trigger established; keep ranked below immediate tooling rider. | R2655–2675; spt-store/src/info.rs:872–877 |\n| 45 | RETIRED disk-hermeticity question answered; network ingress residue explicitly elsewhere. | R2676–2706 |\n| 46 | Implemented START/END/DOCS instant tokens; RECEIPT/adoption reconciliation rather than another token implementation. Sizing/dependency ownership remains IR86/Main. | R2707–2773; R25–35; 5055–5067 |\n| 47 | RECEIPT-ONLY/stale OPEN: actual missing/parse-failure annotations and legitimate doyle quiet case already shipped. Do not reapply ancient stash. | R2774–2800; ci-notify.sh:193–210; ci-notify-selftest.sh:225–229 |\n| 48 | TOUCH preventive control on parity-cell edit; current defect not claimed and no qualifying edit established. | R2801–2821 |\n| 49 | TOUCH real ancestry-only residual; first landed-member takeover or poolguard touch. No current takeover request established; source confirms patch-id fallback absent. | R2822–2855; spt-poolguard/src/lib.rs:424–438 |\n| 50 | CLOSED/BUILT adoption complete with explicitly distinct engine-room direct sink path. | R2856–2913 |\n| 51 | BLOCKED/conditional: attribution-before-net-off, or separately owned hermeticity pass; hosted-relay prebuilt route still needs isolation proof. No blanket net-off fix authorized. | R2914–2942; R95–102 |\n| 52 | BUILT full recursive CLI reference since SIGNET, despite obsolete carry-forward notes in sweep prose. | R2969–3007; xtask main.rs:165–223 |\n| 53 | BUILT 601-second member; three 6/16-second siblings TOUCH controlled-clock seam when changed. | R2943–2968 |\n| 54 | BUILT assembly intake/runbook PR176. | R1217–1248 |\n| 55 | ARMED-FOR-CAPTURE, hertz. Later negative runs supersede apparent always-ripe emergency; next bare-cargo wedge needs evidence before cleanup. nextest already mitigates run-level exposure. | R3075–3200 |\n| 56 | BUILT cross-worktree claim-addressing refusal; absolute-path allocation discipline reinforced Sept11. Does not implement IR26 incumbent admission. | R3201–3247 |\n| 57 | Living procedure / next assembly: pick-audit BUILT and twice field-used; no code lane to dispatch. Doyle owns fidelity accounting. | R3248–3306 |\n| 58 | RECEIPT-ONLY/stale OPEN: Cargo-metadata duplicate-bin gate already exists and xtask check calls it. Original prose allegation withdrawn; do not repair correct collision comments. | R3307–3341; binnames.rs:1–110; xtask main.rs:56,769–797 |\n| 59 | OPEN recurring capacity/adoption; disk-floor and local-lane budget machinery already built. Reconcile remaining consumers/receipts, not a new floor verb; heavy work held. | R3342–3475; local-lane.py:270–310,358–407 |\n| 60 | OPEN recurring producer-status discipline, not an unimplemented wrapper. Current local-lane stores real producer exit and preserves failure precedence; legacy/new driver adoption is remaining question. | R3476–3524; local-lane.py:255–263,309–310 |\n| 61 | TOUCH accepted-with-mitigation: next substantive spacerun literal/skip/tracker change; unrelated xtask work does not qualify. | R3525–3557 |\n| 62 | Docs collision BUILT/retired via ephemeral advisory ports. Other advisory collision only on new fire; IR78 is separate override-observability consequence. | R3558–3598 |\n| 63 | OPEN lifecycle/rig adoption, with third conhost-CWD face; dated pin population is not current kill authorization. New guard/driver source must be reconciled before redispatch. | R3599–3637; R48–49 |\n| 64 | BLOCKED operator capacity choice, trigger explicitly FIRED in IR86 in-job form (later amendment reverses earlier not-fired sweep). No agent bulk deletion. | R3638–3659; R5063–5066 |\n| 65 | REMEDIATED-AT-BOX, recurring check only after tailscale/auditd update or reimage. UNKNOWN whether such event occurred; no live audit requested/performed. | R3660–3685 |\n| 66 | CLOSED/BUILT with existing two-platform gate receipts; no delayed-needle redispatch. | R3686–3718 |\n| 67 | BUILT explicit integration-leg battery discipline; later JIT also says satisfied by construction. | R3719–3740; R119–121 |\n| 68 | UNKNOWN/armed investigation: next PSYCHE_INGEST_FAIL specimen or dedicated probe slot; index.lock cause experimentally refuted. Read named COMMUNE_FAIL cause first. | R3741–3768 |\n| 69 | OPEN specified #243 residual + separate anchored-consumer rider. Original emission lane and delivery.rs post-cut fixes LANDED. No fresh population/closure claim; source re-census/board reconciliation is prerequisite to new conversions. | R3769–3860 |\n| 70 | TOUCH recurrence enforcement only: witnessed partial bus fixed PR173; next IoBus constructor/API touch or new sink. No new qualifying touch established. | R3861–3887 |\n\n## Ranked actionable shortlist\n\n1. **Reconcile already-built metadata now — IR32, IR37, IR47, IR58, IR40(B).** Owner: Main/Doyle register closure; implementation owners need not be redispatched. Exact triggers/exit conditions are now source-satisfied: IR37 explicitly closes once pin fixup is on main; current shared pin is 0.4.1 and both workflows call it. IR32's producer nonzero/empty failures propagate before destination write; existing cells cover root/nested, blank/nonzero/unlaunchable, both gen/check. IR47 warnings and doyle split exist, and golden invokes notification selftest at golden.yml:366. IR58 check wiring and Cargo enumeration exist. IR40 compose_body literally emits `CI NEEDS`, supplied-needs scope and `run conclusion: not observed`. Minimal step: attach original landed acceptance/commit receipts and correct statuses; keep IR40 arm A separate. **Do not claim tests ran during this sweep.**\n\n2. **IR11 — the one clearly small remaining tooling implementation.** Exact trigger: R490 'any rig-tooling wave'; prior composition R176–178 names IR11 as next-intake small rider; current driver/workflow package is that tooling composition (R43–47). Source proof: find-cwd-holders.ps1:88–89 fields are only Pid, Name, Cwd, Started; :98 renders that table; `--headless` exists only in prose :18–21. Owner/seam: hertz tooling, existing row-construction seam. Minimal next step: explicitly accept the rider and add a truthful headless discriminator without changing census scope or pretending unreadable command line is false. Actual live-window verification must respect the hold; no probe now.\n\n3. **IR18 deferred (b) — ready for narrow intake, not a surprise cleanup rider.** Original IR18 acceptance discharged its prerequisite in R870–886; deferred lane explicitly named deployah, R1055–1117. Current source proves all three loss-of-knowledge sites still exist (reap.rs:59–64; resident_service_e2e.rs:103–108,127–129) and unreadable daemon.pid still returns no-breadcrumb at reap.rs:467–468. Owner/seam: deployah's deferred test helper lane, coordinated with hertz's common/lifecycle work. Minimal next step: reconcile old assignment and current callers, scope one shared absent/unreadable/malformed reader; do not duplicate existing Population::is_clean (:340–342), and do not start Windows execution now. This is real remaining code, but multi-consumer and not tiny.\n\n4. **IR26 admission/displacement residual — real, next owned infra intake.** R1793–1805 rules prior-owner guard plus loud/persisted takeover event; xtask main.rs:3379–3391 constructs its own owner and unconditionally write_owner, proving IR56 addressing did not implement admission. Owner: hertz pool tooling, Doyle ruling; seam pool_claim plus spt-poolguard. Minimal next step: accept narrow residual design with bare identity-less-claim case and actual refusal/remedy path. Pair IR49 only when poolguard touch is intentionally accepted; its ancestry false→InFlight remains source-visible. Not a spare-CI-window experiment.\n\n5. **Capacity/lifecycle receipt triage, not new infrastructure — IR31/46/59/60 and IR7/17/20/22/25/34/35/55/63.** R43–49 already composes these. local-lane.py has allocated reserve/growth, warm-cache version, admission, selected inventory, after-producer observations and real producer status. Minimal next step is enumerate which retained drivers/callers still bypass that seam and attach preserved acceptance; an OPEN heading is not evidence that a new shared driver is needed. Capacity operator decision IR64 is separately blocked; IR2's reopen condition warrants a question in that decision, not an automatic CARGO_INCREMENTAL flip.\n\n## Important non-dispatch findings\n- IR44 really still has the false preservation claim, but **next info.rs touch has not been established**. It is an excellent future tiny rider, not evidence-backed ripe-now work.\n- IR49 really remains ancestry-only, but no current landed-pool takeover request is established. Do not open standalone work solely because source still contains debt.\n- IR5's old summary-parser premise must not be revived for local-lane.py, which reads structured inventory; first name an actual count consumer.\n- IR2's historical retired state is not unconditional: recurring floor-class reds are its explicit reopen condition. This only reopens the decision; old timing comparison was contaminated and OFF lacked a green golden.\n- IR64's old sweep 'not fired' claim is superseded by IR86's explicit fired cross-reference. Operator ownership remains absolute.\n- IR12 and IR52 were composed again in old top-level sweep prose after their actual built/retired answers. Correct historical-current metadata rather than carrying those as implementation candidates.\n- No assertion about CI34983756975 completion, box clearance, current process population, fresh acceptance, or IR86 retirement is made here. Main owns IR86."},"status":"success"},"isError":false,"timestamp":1789483904094}}
{"type":"custom","customType":"session_exit","data":{"reason":"dispose","kind":"normal","recordedAt":"2026-09-15T14:58:44.124Z"},"id":"46aa8987","parentId":"0a36f6aa","timestamp":"2026-09-15T14:58:44.124Z"}
