﻿2026-07-06T06:24:02.6047347Z ##[group]Run ./traceable-reqs lint || true
2026-07-06T06:24:02.6047497Z [36;1m./traceable-reqs lint || true[0m
2026-07-06T06:24:02.6061687Z shell: /usr/bin/bash -e {0}
2026-07-06T06:24:02.6061855Z ##[endgroup]
2026-07-06T06:24:02.6397110Z Requirement quality findings (478); 418 requirements queued for agent review:
2026-07-06T06:24:02.6398441Z   [must] requirement_quality REQ-ADAPTER-ADD-SURFACE-ERRORS criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6399263Z   [must] requirement_quality REQ-ADAPTER-ADD-SURFACE-ERRORS criterion=length — title is 77 words; want 3..=25
2026-07-06T06:24:02.6400117Z   [must] requirement_quality REQ-ADAPTER-FLOOR-ENFORCE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6400732Z   [must] requirement_quality REQ-ADAPTER-FLOOR-ENFORCE criterion=length — title is 368 words; want 3..=25
2026-07-06T06:24:02.6401560Z   [must] requirement_quality REQ-ADAPTER-GH-TRANSPORT criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6402621Z   [must] requirement_quality REQ-ADAPTER-GH-TRANSPORT criterion=length — title is 62 words; want 3..=25
2026-07-06T06:24:02.6403446Z   [must] requirement_quality REQ-ADAPTER-LIVE-UPDATE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6404050Z   [must] requirement_quality REQ-ADAPTER-LIVE-UPDATE criterion=length — title is 168 words; want 3..=25
2026-07-06T06:24:02.6404722Z   [must] requirement_quality REQ-ADAPTER-MULTIPLATFORM-SPT criterion=length — title is 123 words; want 3..=25
2026-07-06T06:24:02.6405357Z   [must] requirement_quality REQ-ADAPTER-PROOF-DIR-OVERRIDE criterion=length — title is 76 words; want 3..=25
2026-07-06T06:24:02.6406211Z   [must] requirement_quality REQ-ADAPTER-TRANSLATE-PROOF criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6406843Z   [must] requirement_quality REQ-ADAPTER-TRANSLATE-PROOF criterion=length — title is 182 words; want 3..=25
2026-07-06T06:24:02.6407614Z   [must] requirement_quality REQ-ADAPTER-UPDATE-INPLACE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6408033Z   [must] requirement_quality REQ-ADAPTER-UPDATE-INPLACE criterion=length — title is 82 words; want 3..=25
2026-07-06T06:24:02.6408367Z   [must] requirement_quality REQ-ADAPTER-UPDATE-MESSAGE criterion=length — title is 64 words; want 3..=25
2026-07-06T06:24:02.6408682Z   [must] requirement_quality REQ-ADAPTER-UPDATE-POST criterion=length — title is 124 words; want 3..=25
2026-07-06T06:24:02.6409177Z   [must] requirement_quality REQ-ADAPTER-VERSION-CMD criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6409483Z   [must] requirement_quality REQ-ADAPTER-VERSION-CMD criterion=length — title is 59 words; want 3..=25
2026-07-06T06:24:02.6409856Z   [must] requirement_quality REQ-API-1 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6410227Z   [must] requirement_quality REQ-API-4 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6410490Z   [must] requirement_quality REQ-API-4 criterion=length — title is 67 words; want 3..=25
2026-07-06T06:24:02.6410801Z   [must] requirement_quality REQ-API-ENDPOINT-INFO criterion=length — title is 138 words; want 3..=25
2026-07-06T06:24:02.6411220Z   [must] requirement_quality REQ-BIND-HONEST-SELF-STAMP criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6411539Z   [must] requirement_quality REQ-BIND-HONEST-SELF-STAMP criterion=length — title is 182 words; want 3..=25
2026-07-06T06:24:02.6411988Z   [must] requirement_quality REQ-BOUNDARY-ROTATION-CREDENTIAL criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6412338Z   [must] requirement_quality REQ-BOUNDARY-ROTATION-CREDENTIAL criterion=length — title is 53 words; want 3..=25
2026-07-06T06:24:02.6413056Z   [must] requirement_quality REQ-BROKER-ATTACH-JOURNAL-RESILIENT criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6413423Z   [must] requirement_quality REQ-BROKER-ATTACH-JOURNAL-RESILIENT criterion=length — title is 120 words; want 3..=25
2026-07-06T06:24:02.6413844Z   [must] requirement_quality REQ-BROKER-SCREEN-GRID criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6414154Z   [must] requirement_quality REQ-BROKER-SCREEN-GRID criterion=length — title is 126 words; want 3..=25
2026-07-06T06:24:02.6414411Z   [must] requirement_quality REQ-CLI-1 criterion=length — title is 97 words; want 3..=25
2026-07-06T06:24:02.6414668Z   [must] requirement_quality REQ-CLI-2 criterion=length — title is 37 words; want 3..=25
2026-07-06T06:24:02.6414921Z   [must] requirement_quality REQ-CLI-3 criterion=length — title is 37 words; want 3..=25
2026-07-06T06:24:02.6415282Z   [must] requirement_quality REQ-CLI-4 criterion=length — title is 89 words; want 3..=25
2026-07-06T06:24:02.6415621Z   [must] requirement_quality REQ-CLI-BROKEN-PIPE-TOLERANT criterion=length — title is 78 words; want 3..=25
2026-07-06T06:24:02.6416031Z   [must] requirement_quality REQ-CLI-HELP-MARKDOWN criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6416336Z   [must] requirement_quality REQ-CLI-HELP-MARKDOWN criterion=length — title is 156 words; want 3..=25
2026-07-06T06:24:02.6416594Z   [must] requirement_quality REQ-CLI-JSON criterion=length — title is 95 words; want 3..=25
2026-07-06T06:24:02.6417009Z   [must] requirement_quality REQ-CLI-OUTPUT-MARKDOWN criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6417322Z   [must] requirement_quality REQ-CLI-OUTPUT-MARKDOWN criterion=length — title is 199 words; want 3..=25
2026-07-06T06:24:02.6417702Z   [must] requirement_quality REQ-CLI-WIN-VT-ENABLE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6418007Z   [must] requirement_quality REQ-CLI-WIN-VT-ENABLE criterion=length — title is 110 words; want 3..=25
2026-07-06T06:24:02.6418268Z   [must] requirement_quality REQ-CONSENT-1 criterion=length — title is 41 words; want 3..=25
2026-07-06T06:24:02.6418526Z   [must] requirement_quality REQ-CONSENT-2 criterion=length — title is 37 words; want 3..=25
2026-07-06T06:24:02.6418794Z   [must] requirement_quality REQ-CONSENT-3 criterion=length — title is 82 words; want 3..=25
2026-07-06T06:24:02.6419266Z   [must] requirement_quality REQ-CONTROLLER-LIVENESS-REAP criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6419596Z   [must] requirement_quality REQ-CONTROLLER-LIVENESS-REAP criterion=length — title is 370 words; want 3..=25
2026-07-06T06:24:02.6419935Z   [must] requirement_quality REQ-CONV-1 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6420194Z   [must] requirement_quality REQ-CONV-1 criterion=length — title is 73 words; want 3..=25
2026-07-06T06:24:02.6420439Z   [must] requirement_quality REQ-CONV-2 criterion=length — title is 47 words; want 3..=25
2026-07-06T06:24:02.6420750Z   [must] requirement_quality REQ-CRC-SWAP-OLD-DISPLACE criterion=length — title is 125 words; want 3..=25
2026-07-06T06:24:02.6421107Z   [must] requirement_quality REQ-DAEMON-5 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6421342Z   [must] requirement_quality REQ-DAEMON-5 criterion=length — title is 64 words; want 3..=25
2026-07-06T06:24:02.6421699Z   [must] requirement_quality REQ-DAEMON-6 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6421942Z   [must] requirement_quality REQ-DAEMON-6 criterion=length — title is 84 words; want 3..=25
2026-07-06T06:24:02.6422285Z   [must] requirement_quality REQ-DAEMON-7 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6422670Z   [must] requirement_quality REQ-DAEMON-7 criterion=length — title is 62 words; want 3..=25
2026-07-06T06:24:02.6422917Z   [must] requirement_quality REQ-DAEMON-8 criterion=length — title is 44 words; want 3..=25
2026-07-06T06:24:02.6423265Z   [must] requirement_quality REQ-DAEMON-9 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6423513Z   [must] requirement_quality REQ-DAEMON-9 criterion=length — title is 114 words; want 3..=25
2026-07-06T06:24:02.6423922Z   [must] requirement_quality REQ-DAEMON-STATUS-JSON-TRUTH criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6424242Z   [must] requirement_quality REQ-DAEMON-STATUS-JSON-TRUTH criterion=length — title is 73 words; want 3..=25
2026-07-06T06:24:02.6424618Z   [must] requirement_quality REQ-DIGEST-CURSOR criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6424995Z   [must] requirement_quality REQ-DIGEST-CURSOR criterion=length — title is 181 words; want 3..=25
2026-07-06T06:24:02.6425406Z   [must] requirement_quality REQ-DIGEST-FETCHER-STRATEGY criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6425719Z   [must] requirement_quality REQ-DIGEST-FETCHER-STRATEGY criterion=length — title is 167 words; want 3..=25
2026-07-06T06:24:02.6426100Z   [must] requirement_quality REQ-DIGEST-PROFILE-ENV criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6426391Z   [must] requirement_quality REQ-DIGEST-PROFILE-ENV criterion=length — title is 96 words; want 3..=25
2026-07-06T06:24:02.6426720Z   [must] requirement_quality REQ-DOC-ENDPOINT-DROP-RESOLUTION criterion=length — title is 57 words; want 3..=25
2026-07-06T06:24:02.6427116Z   [must] requirement_quality REQ-DOCS-NO-INTERNAL-CODES criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6427430Z   [must] requirement_quality REQ-DOCS-NO-INTERNAL-CODES criterion=length — title is 84 words; want 3..=25
2026-07-06T06:24:02.6427839Z   [must] requirement_quality REQ-EFFECTIVE-INSTANCE-STATE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6428156Z   [must] requirement_quality REQ-EFFECTIVE-INSTANCE-STATE criterion=length — title is 160 words; want 3..=25
2026-07-06T06:24:02.6428504Z   [must] requirement_quality REQ-ELEVATE-1 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6428786Z   [must] requirement_quality REQ-ELEVATE-1 criterion=length — title is 121 words; want 3..=25
2026-07-06T06:24:02.6429153Z   [must] requirement_quality REQ-ENDPOINT-LIST-MERGE-LOCAL criterion=length — title is 95 words; want 3..=25
2026-07-06T06:24:02.6429501Z   [must] requirement_quality REQ-ENDPOINT-LIST-NODE-GROUPED criterion=length — title is 213 words; want 3..=25
2026-07-06T06:24:02.6429826Z   [must] requirement_quality REQ-ENDPOINT-LIST-NODE-IDENT criterion=length — title is 57 words; want 3..=25
2026-07-06T06:24:02.6430227Z   [must] requirement_quality REQ-ENDPOINT-LIST-PALETTE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6430532Z   [must] requirement_quality REQ-ENDPOINT-LIST-PALETTE criterion=length — title is 106 words; want 3..=25
2026-07-06T06:24:02.6430840Z   [must] requirement_quality REQ-ENDPOINT-LIST-PROJECT-COL criterion=length — title is 79 words; want 3..=25
2026-07-06T06:24:02.6431167Z   [must] requirement_quality REQ-ENDPOINT-LIST-RENDER-POLISH criterion=length — title is 122 words; want 3..=25
2026-07-06T06:24:02.6431482Z   [must] requirement_quality REQ-ENDPOINT-LIST-REST-FILTER criterion=length — title is 110 words; want 3..=25
2026-07-06T06:24:02.6431859Z   [must] requirement_quality REQ-ENDPOINT-PURGE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6432254Z   [must] requirement_quality REQ-ENDPOINT-PURGE criterion=length — title is 220 words; want 3..=25
2026-07-06T06:24:02.6432540Z   [must] requirement_quality REQ-ENDPOINT-STOP-OFFLINE criterion=length — title is 58 words; want 3..=25
2026-07-06T06:24:02.6432945Z   [must] requirement_quality REQ-ENDPOINT-UNBOUND-ATTACH criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6433254Z   [must] requirement_quality REQ-ENDPOINT-UNBOUND-ATTACH criterion=length — title is 122 words; want 3..=25
2026-07-06T06:24:02.6433600Z   [must] requirement_quality REQ-EP-6 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6433834Z   [must] requirement_quality REQ-EP-6 criterion=length — title is 58 words; want 3..=25
2026-07-06T06:24:02.6434078Z   [must] requirement_quality REQ-EP-7 criterion=length — title is 68 words; want 3..=25
2026-07-06T06:24:02.6434330Z   [must] requirement_quality REQ-EP-8 criterion=length — title is 114 words; want 3..=25
2026-07-06T06:24:02.6434792Z   [must] requirement_quality REQ-EP-9 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6435031Z   [must] requirement_quality REQ-EP-9 criterion=length — title is 76 words; want 3..=25
2026-07-06T06:24:02.6435435Z   [must] requirement_quality REQ-GOSSIP-ADAPTER-PROJECTS criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6435750Z   [must] requirement_quality REQ-GOSSIP-ADAPTER-PROJECTS criterion=length — title is 82 words; want 3..=25
2026-07-06T06:24:02.6436136Z   [must] requirement_quality REQ-GOSSIP-CONTROLLED-ANY criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6436431Z   [must] requirement_quality REQ-GOSSIP-CONTROLLED-ANY criterion=length — title is 92 words; want 3..=25
2026-07-06T06:24:02.6436760Z   [must] requirement_quality REQ-GOSSIP-CONTROLLED-CROSS-NODE criterion=length — title is 108 words; want 3..=25
2026-07-06T06:24:02.6437214Z   [must] requirement_quality REQ-HAZARD-ADAPTER-APPLY-SILENT-NOOP criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6437563Z   [must] requirement_quality REQ-HAZARD-ADAPTER-APPLY-SILENT-NOOP criterion=length — title is 199 words; want 3..=25
2026-07-06T06:24:02.6437920Z   [must] requirement_quality REQ-HAZARD-ADAPTER-PROFILE-STAMP-CLOBBER criterion=length — title is 114 words; want 3..=25
2026-07-06T06:24:02.6438248Z   [must] requirement_quality REQ-HAZARD-ATOMIC-TMP-COLLISION criterion=length — title is 29 words; want 3..=25
2026-07-06T06:24:02.6438645Z   [must] requirement_quality REQ-HAZARD-ATTACH-WEDGE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6439017Z   [must] requirement_quality REQ-HAZARD-ATTACH-WEDGE criterion=length — title is 244 words; want 3..=25
2026-07-06T06:24:02.6439432Z   [must] requirement_quality REQ-HAZARD-BIND-CWD-UNSET criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6439733Z   [must] requirement_quality REQ-HAZARD-BIND-CWD-UNSET criterion=length — title is 130 words; want 3..=25
2026-07-06T06:24:02.6440162Z   [must] requirement_quality REQ-HAZARD-BOUNDARY-READY-STRAND criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6440495Z   [must] requirement_quality REQ-HAZARD-BOUNDARY-READY-STRAND criterion=length — title is 175 words; want 3..=25
2026-07-06T06:24:02.6440915Z   [must] requirement_quality REQ-HAZARD-BRAIN-RESPAWN-PATH criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6441234Z   [must] requirement_quality REQ-HAZARD-BRAIN-RESPAWN-PATH criterion=length — title is 119 words; want 3..=25
2026-07-06T06:24:02.6441699Z   [must] requirement_quality REQ-HAZARD-BRAIN-RESTART-LIFECYCLE-REHYDRATE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6442189Z   [must] requirement_quality REQ-HAZARD-BRAIN-RESTART-LIFECYCLE-REHYDRATE criterion=length — title is 125 words; want 3..=25
2026-07-06T06:24:02.6442623Z   [must] requirement_quality REQ-HAZARD-BRAIN-RESTART-PSYCHE-DUP criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6442973Z   [must] requirement_quality REQ-HAZARD-BRAIN-RESTART-PSYCHE-DUP criterion=length — title is 199 words; want 3..=25
2026-07-06T06:24:02.6443401Z   [must] requirement_quality REQ-HAZARD-BROKER-FLOOR-LOCK-POISON criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6443734Z   [must] requirement_quality REQ-HAZARD-BROKER-FLOOR-LOCK-POISON criterion=length — title is 333 words; want 3..=25
2026-07-06T06:24:02.6444164Z   [must] requirement_quality REQ-HAZARD-BROKER-PROCESS-ISOLATION criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6444604Z   [must] requirement_quality REQ-HAZARD-BROKER-PROCESS-ISOLATION criterion=length — title is 114 words; want 3..=25
2026-07-06T06:24:02.6445024Z   [must] requirement_quality REQ-HAZARD-BROKER-QUIC-DEADLINE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6445357Z   [must] requirement_quality REQ-HAZARD-BROKER-QUIC-DEADLINE criterion=length — title is 162 words; want 3..=25
2026-07-06T06:24:02.6445786Z   [must] requirement_quality REQ-HAZARD-BROKER-SEED-WIRE-SKEW criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6446111Z   [must] requirement_quality REQ-HAZARD-BROKER-SEED-WIRE-SKEW criterion=length — title is 193 words; want 3..=25
2026-07-06T06:24:02.6446435Z   [must] requirement_quality REQ-HAZARD-CONFLICT-BOTH-PRESERVED criterion=length — title is 29 words; want 3..=25
2026-07-06T06:24:02.6446877Z   [must] requirement_quality REQ-HAZARD-CONTROL-STAMP-CONVERGENCE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6447235Z   [must] requirement_quality REQ-HAZARD-CONTROL-STAMP-CONVERGENCE criterion=length — title is 193 words; want 3..=25
2026-07-06T06:24:02.6447658Z   [must] requirement_quality REQ-HAZARD-CONTROL-STAMP-LIFETIME criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6447992Z   [must] requirement_quality REQ-HAZARD-CONTROL-STAMP-LIFETIME criterion=length — title is 100 words; want 3..=25
2026-07-06T06:24:02.6448404Z   [must] requirement_quality REQ-HAZARD-CONTROLLER-GAP-RESUME criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6448733Z   [must] requirement_quality REQ-HAZARD-CONTROLLER-GAP-RESUME criterion=length — title is 297 words; want 3..=25
2026-07-06T06:24:02.6449687Z   [must] requirement_quality REQ-HAZARD-CONTROLLER-IRRECOVERABLE-BEHIND criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6450327Z   [must] requirement_quality REQ-HAZARD-CONTROLLER-IRRECOVERABLE-BEHIND criterion=length — title is 134 words; want 3..=25
2026-07-06T06:24:02.6450888Z   [must] requirement_quality REQ-HAZARD-CONTROLLER-RETAKE-FLOOR criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6451328Z   [must] requirement_quality REQ-HAZARD-CONTROLLER-RETAKE-FLOOR criterion=length — title is 184 words; want 3..=25
2026-07-06T06:24:02.6451903Z   [must] requirement_quality REQ-HAZARD-CONTROLLER-WRITER-REORDER criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6452345Z   [must] requirement_quality REQ-HAZARD-CONTROLLER-WRITER-REORDER criterion=length — title is 643 words; want 3..=25
2026-07-06T06:24:02.6452759Z   [must] requirement_quality REQ-HAZARD-DAEMON-SCHED-NONBLOCKING criterion=length — title is 32 words; want 3..=25
2026-07-06T06:24:02.6453508Z   [must] requirement_quality REQ-HAZARD-DAEMON-STOP-BARRIER criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6453923Z   [must] requirement_quality REQ-HAZARD-DAEMON-STOP-BARRIER criterion=length — title is 80 words; want 3..=25
2026-07-06T06:24:02.6454441Z   [must] requirement_quality REQ-HAZARD-DAEMON-STOP-REAP criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6454811Z   [must] requirement_quality REQ-HAZARD-DAEMON-STOP-REAP criterion=length — title is 90 words; want 3..=25
2026-07-06T06:24:02.6455297Z   [must] requirement_quality REQ-HAZARD-DEAD-REC-PID criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6455664Z   [must] requirement_quality REQ-HAZARD-DEAD-REC-PID criterion=length — title is 175 words; want 3..=25
2026-07-06T06:24:02.6456175Z   [must] requirement_quality REQ-HAZARD-DEFERRED-MANIFEST criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6456705Z   [must] requirement_quality REQ-HAZARD-DEFERRED-MANIFEST criterion=length — title is 112 words; want 3..=25
2026-07-06T06:24:02.6457227Z   [must] requirement_quality REQ-HAZARD-DELIVERY-STARVATION criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6457623Z   [must] requirement_quality REQ-HAZARD-DELIVERY-STARVATION criterion=length — title is 99 words; want 3..=25
2026-07-06T06:24:02.6458077Z   [must] requirement_quality REQ-HAZARD-DETACHED-DAEMON-STDIO criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6458420Z   [must] requirement_quality REQ-HAZARD-DETACHED-DAEMON-STDIO criterion=length — title is 255 words; want 3..=25
2026-07-06T06:24:02.6458739Z   [must] requirement_quality REQ-HAZARD-DETACHED-PIPE-INHERIT criterion=length — title is 52 words; want 3..=25
2026-07-06T06:24:02.6459303Z   [must] requirement_quality REQ-HAZARD-DRIVEN-BY-IDLE-REMOTE-EVICT criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6459668Z   [must] requirement_quality REQ-HAZARD-DRIVEN-BY-IDLE-REMOTE-EVICT criterion=length — title is 232 words; want 3..=25
2026-07-06T06:24:02.6460094Z   [must] requirement_quality REQ-HAZARD-DRIVEN-BY-SELFHEAL criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6460418Z   [must] requirement_quality REQ-HAZARD-DRIVEN-BY-SELFHEAL criterion=length — title is 77 words; want 3..=25
2026-07-06T06:24:02.6460858Z   [must] requirement_quality REQ-HAZARD-EFFECT-JOURNAL-PTY-WEDGE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6461201Z   [must] requirement_quality REQ-HAZARD-EFFECT-JOURNAL-PTY-WEDGE criterion=length — title is 440 words; want 3..=25
2026-07-06T06:24:02.6461615Z   [must] requirement_quality REQ-HAZARD-ELEVATED-DAEMON-SPAWN criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6461954Z   [must] requirement_quality REQ-HAZARD-ELEVATED-DAEMON-SPAWN criterion=length — title is 58 words; want 3..=25
2026-07-06T06:24:02.6462401Z   [must] requirement_quality REQ-HAZARD-ENDPOINT-RUN-ATTACH-OUTPUT criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6462756Z   [must] requirement_quality REQ-HAZARD-ENDPOINT-RUN-ATTACH-OUTPUT criterion=length — title is 228 words; want 3..=25
2026-07-06T06:24:02.6463153Z   [must] requirement_quality REQ-HAZARD-ENV-SUBST criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6463444Z   [must] requirement_quality REQ-HAZARD-ENV-SUBST criterion=length — title is 168 words; want 3..=25
2026-07-06T06:24:02.6463863Z   [must] requirement_quality REQ-HAZARD-ENVELOPE-CR-LINESAFE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6472648Z   [must] requirement_quality REQ-HAZARD-ENVELOPE-CR-LINESAFE criterion=length — title is 73 words; want 3..=25
2026-07-06T06:24:02.6473326Z   [must] requirement_quality REQ-HAZARD-ENVELOPE-PARSER-SAFE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6473636Z   [must] requirement_quality REQ-HAZARD-EPOCH-RESET criterion=length — title is 60 words; want 3..=25
2026-07-06T06:24:02.6474399Z   [must] requirement_quality REQ-HAZARD-GEN-START-NOW criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6474742Z   [must] requirement_quality REQ-HAZARD-HOSTED-LIVENESS-RECONCILE criterion=length — title is 175 words; want 3..=25
2026-07-06T06:24:02.6475196Z   [must] requirement_quality REQ-HAZARD-IDLE-SILENT-NONDELIVERY criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6475542Z   [must] requirement_quality REQ-HAZARD-IDLE-SILENT-NONDELIVERY criterion=length — title is 436 words; want 3..=25
2026-07-06T06:24:02.6476188Z   [must] requirement_quality REQ-HAZARD-INJECT-CONTROL-COEXIST criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6476517Z   [must] requirement_quality REQ-HAZARD-INJECT-CONTROL-COEXIST criterion=length — title is 340 words; want 3..=25
2026-07-06T06:24:02.6476923Z   [must] requirement_quality REQ-HAZARD-INJECT-WORKER-POISON criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6477243Z   [must] requirement_quality REQ-HAZARD-INJECT-WORKER-POISON criterion=length — title is 136 words; want 3..=25
2026-07-06T06:24:02.6477671Z   [must] requirement_quality REQ-HAZARD-INPUT-ACK-BACKPRESSURE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6477995Z   [must] requirement_quality REQ-HAZARD-INPUT-ACK-BACKPRESSURE criterion=length — title is 343 words; want 3..=25
2026-07-06T06:24:02.6478305Z   [must] requirement_quality REQ-HAZARD-INSTANT-UNDERFLOW criterion=length — title is 30 words; want 3..=25
2026-07-06T06:24:02.6478672Z   [must] requirement_quality REQ-HAZARD-LIVEHOST-BOOT-LIVENESS-GATE criterion=length — title is 122 words; want 3..=25
2026-07-06T06:24:02.6479269Z   [must] requirement_quality REQ-HAZARD-LIVEHOST-BOOT-RACE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6479607Z   [must] requirement_quality REQ-HAZARD-LIVEHOST-BOOT-RACE criterion=length — title is 158 words; want 3..=25
2026-07-06T06:24:02.6480026Z   [must] requirement_quality REQ-HAZARD-LIVEHOST-NONRESIDENT criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6480346Z   [must] requirement_quality REQ-HAZARD-LIVEHOST-NONRESIDENT criterion=length — title is 171 words; want 3..=25
2026-07-06T06:24:02.6480640Z   [must] requirement_quality REQ-HAZARD-PAIR-RATE-LIMIT criterion=length — title is 37 words; want 3..=25
2026-07-06T06:24:02.6480948Z   [must] requirement_quality REQ-HAZARD-PAIR-SEED-ROTATION criterion=length — title is 33 words; want 3..=25
2026-07-06T06:24:02.6481368Z   [must] requirement_quality REQ-HAZARD-PAIR-TRANSCRIPT-BIND criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6481782Z   [must] requirement_quality REQ-HAZARD-PSYCHE-OUTBOUND-PROXY criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6482102Z   [must] requirement_quality REQ-HAZARD-PSYCHE-OUTBOUND-PROXY criterion=length — title is 27 words; want 3..=25
2026-07-06T06:24:02.6482549Z   [must] requirement_quality REQ-HAZARD-PSYCHE-RESIDENCY-EXPECTATION criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6482908Z   [must] requirement_quality REQ-HAZARD-PSYCHE-RESIDENCY-EXPECTATION criterion=length — title is 130 words; want 3..=25
2026-07-06T06:24:02.6483328Z   [must] requirement_quality REQ-HAZARD-PTY-INPUT-WRITER-WEDGE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6483906Z   [must] requirement_quality REQ-HAZARD-PTY-INPUT-WRITER-WEDGE criterion=length — title is 287 words; want 3..=25
2026-07-06T06:24:02.6484311Z   [must] requirement_quality REQ-HAZARD-PUMP-IPC-DEADLINE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6484626Z   [must] requirement_quality REQ-HAZARD-PUMP-IPC-DEADLINE criterion=length — title is 38 words; want 3..=25
2026-07-06T06:24:02.6485031Z   [must] requirement_quality REQ-HAZARD-RC-ATTACH-FAILFAST criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6485350Z   [must] requirement_quality REQ-HAZARD-RC-ATTACH-FAILFAST criterion=length — title is 163 words; want 3..=25
2026-07-06T06:24:02.6485765Z   [must] requirement_quality REQ-HAZARD-RC-ATTACH-ONLINE-RACE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6486092Z   [must] requirement_quality REQ-HAZARD-RC-ATTACH-ONLINE-RACE criterion=length — title is 184 words; want 3..=25
2026-07-06T06:24:02.6486563Z   [must] requirement_quality REQ-HAZARD-RC-EOF criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6486835Z   [must] requirement_quality REQ-HAZARD-RC-EOF criterion=length — title is 208 words; want 3..=25
2026-07-06T06:24:02.6487250Z   [must] requirement_quality REQ-HAZARD-RC-INPUT-KEY-ENCODING criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6487578Z   [must] requirement_quality REQ-HAZARD-RC-INPUT-KEY-ENCODING criterion=length — title is 222 words; want 3..=25
2026-07-06T06:24:02.6487979Z   [must] requirement_quality REQ-HAZARD-REGISTRY-GHOST-ROWS criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6488298Z   [must] requirement_quality REQ-HAZARD-REGISTRY-GHOST-ROWS criterion=length — title is 152 words; want 3..=25
2026-07-06T06:24:02.6488637Z   [must] requirement_quality REQ-HAZARD-ROLLBACK-STATE-COMPAT criterion=length — title is 72 words; want 3..=25
2026-07-06T06:24:02.6489109Z   [must] requirement_quality REQ-HAZARD-ROSTER-GHOST criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6489748Z   [must] requirement_quality REQ-HAZARD-ROSTER-GHOST criterion=length — title is 116 words; want 3..=25
2026-07-06T06:24:02.6490276Z   [must] requirement_quality REQ-HAZARD-SEEDMAP-CONNECT-UNBOUNDED criterion=length — title is 171 words; want 3..=25
2026-07-06T06:24:02.6490786Z   [must] requirement_quality REQ-HAZARD-SELF-ELEVATE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6491157Z   [must] requirement_quality REQ-HAZARD-SELF-ELEVATE criterion=length — title is 101 words; want 3..=25
2026-07-06T06:24:02.6491680Z   [must] requirement_quality REQ-HAZARD-SESSION-PIN-WEDGE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6492095Z   [must] requirement_quality REQ-HAZARD-SESSION-PIN-WEDGE criterion=length — title is 320 words; want 3..=25
2026-07-06T06:24:02.6492514Z   [must] requirement_quality REQ-HAZARD-SPOOL-SENTINEL-CREATE-FAIL criterion=length — title is 84 words; want 3..=25
2026-07-06T06:24:02.6493072Z   [must] requirement_quality REQ-HAZARD-STOP-PATH-PSYCHE-ORPHAN-REAP criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6493507Z   [must] requirement_quality REQ-HAZARD-STOP-PATH-PSYCHE-ORPHAN-REAP criterion=length — title is 120 words; want 3..=25
2026-07-06T06:24:02.6494015Z   [must] requirement_quality REQ-HAZARD-STORE-INIT-RACE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6494394Z   [must] requirement_quality REQ-HAZARD-STORE-INIT-RACE criterion=length — title is 149 words; want 3..=25
2026-07-06T06:24:02.6494770Z   [must] requirement_quality REQ-HAZARD-SUDO-SECURE-PATH criterion=length — title is 43 words; want 3..=25
2026-07-06T06:24:02.6495538Z   [must] requirement_quality REQ-HAZARD-TEMPLATE-ARGV-FILL criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6495939Z   [must] requirement_quality REQ-HAZARD-TEMPLATE-ARGV-FILL criterion=length — title is 166 words; want 3..=25
2026-07-06T06:24:02.6496330Z   [must] requirement_quality REQ-HAZARD-THRASH-GUARD-BLIND criterion=length — title is 62 words; want 3..=25
2026-07-06T06:24:02.6496908Z   [must] requirement_quality REQ-HAZARD-TRANSLATE-FAULT-PERMANENT-DEATH criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6497361Z   [must] requirement_quality REQ-HAZARD-TRANSLATE-FAULT-PERMANENT-DEATH criterion=length — title is 91 words; want 3..=25
2026-07-06T06:24:02.6497767Z   [must] requirement_quality REQ-HAZARD-UNHOST-PSYCHE-REAP criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6498195Z   [must] requirement_quality REQ-HAZARD-UNHOST-PSYCHE-REAP criterion=length — title is 161 words; want 3..=25
2026-07-06T06:24:02.6498611Z   [must] requirement_quality REQ-HAZARD-VIEWER-CLOSE-DETACH criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6498911Z   [must] requirement_quality REQ-HAZARD-VIEWER-CLOSE-DETACH criterion=length — title is 437 words; want 3..=25
2026-07-06T06:24:02.6499388Z   [must] requirement_quality REQ-HAZARD-VIEWER-ISOLATION criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6499693Z   [must] requirement_quality REQ-HAZARD-VIEWER-ISOLATION criterion=length — title is 118 words; want 3..=25
2026-07-06T06:24:02.6500121Z   [must] requirement_quality REQ-HAZARD-VIEWER-RING-ROLL-SNAP criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6500440Z   [must] requirement_quality REQ-HAZARD-VIEWER-RING-ROLL-SNAP criterion=length — title is 167 words; want 3..=25
2026-07-06T06:24:02.6500970Z   [must] requirement_quality REQ-HAZARD-VIEWER-STARVE-UNDER-CONTROLLER-BACKPRESSURE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6501384Z   [must] requirement_quality REQ-HAZARD-VIEWER-STARVE-UNDER-CONTROLLER-BACKPRESSURE criterion=length — title is 235 words; want 3..=25
2026-07-06T06:24:02.6501694Z   [must] requirement_quality REQ-HAZARD-WAN-ORIGIN-AUTH criterion=length — title is 37 words; want 3..=25
2026-07-06T06:24:02.6502129Z   [must] requirement_quality REQ-HAZARD-WIN-PTY-PROGRAM-RESOLVE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6502473Z   [must] requirement_quality REQ-HAZARD-WIN-PTY-PROGRAM-RESOLVE criterion=length — title is 96 words; want 3..=25
2026-07-06T06:24:02.6502778Z   [must] requirement_quality REQ-HAZARD-WMI-DAEMON-WINDOW criterion=length — title is 101 words; want 3..=25
2026-07-06T06:24:02.6503049Z   [must] requirement_quality REQ-HOST-RUN-1 criterion=length — title is 88 words; want 3..=25
2026-07-06T06:24:02.6503303Z   [must] requirement_quality REQ-HOST-RUN-2 criterion=length — title is 97 words; want 3..=25
2026-07-06T06:24:02.6503556Z   [must] requirement_quality REQ-INST-15 criterion=length — title is 32 words; want 3..=25
2026-07-06T06:24:02.6503908Z   [must] requirement_quality REQ-INSTALL-10 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6504162Z   [must] requirement_quality REQ-INSTALL-10 criterion=length — title is 58 words; want 3..=25
2026-07-06T06:24:02.6504410Z   [must] requirement_quality REQ-INSTALL-11 criterion=length — title is 78 words; want 3..=25
2026-07-06T06:24:02.6504674Z   [must] requirement_quality REQ-INSTALL-12 criterion=length — title is 116 words; want 3..=25
2026-07-06T06:24:02.6505031Z   [must] requirement_quality REQ-INSTALL-13 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6505403Z   [must] requirement_quality REQ-INSTALL-13 criterion=length — title is 131 words; want 3..=25
2026-07-06T06:24:02.6505655Z   [must] requirement_quality REQ-INSTALL-2 criterion=length — title is 2 word(s); want 3..=25
2026-07-06T06:24:02.6506013Z   [must] requirement_quality REQ-INSTALL-6 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6506265Z   [must] requirement_quality REQ-INSTALL-6 criterion=length — title is 56 words; want 3..=25
2026-07-06T06:24:02.6506604Z   [must] requirement_quality REQ-INSTALL-7 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6506852Z   [must] requirement_quality REQ-INSTALL-7 criterion=length — title is 50 words; want 3..=25
2026-07-06T06:24:02.6507094Z   [must] requirement_quality REQ-INSTALL-8 criterion=length — title is 55 words; want 3..=25
2026-07-06T06:24:02.6507435Z   [must] requirement_quality REQ-INSTALL-9 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6507783Z   [must] requirement_quality REQ-INSTALL-9 criterion=length — title is 62 words; want 3..=25
2026-07-06T06:24:02.6508159Z   [must] requirement_quality REQ-JOIN-DIAGNOSTICS criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6508450Z   [must] requirement_quality REQ-JOIN-DIAGNOSTICS criterion=length — title is 137 words; want 3..=25
2026-07-06T06:24:02.6508727Z   [must] requirement_quality REQ-JOIN-TWO-PHASE criterion=length — title is 161 words; want 3..=25
2026-07-06T06:24:02.6509142Z   [must] requirement_quality REQ-KICK-1 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6509390Z   [must] requirement_quality REQ-KICK-1 criterion=length — title is 133 words; want 3..=25
2026-07-06T06:24:02.6509743Z   [must] requirement_quality REQ-MANIFEST-1 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6510014Z   [must] requirement_quality REQ-MANIFEST-3 criterion=length — title is 26 words; want 3..=25
2026-07-06T06:24:02.6510267Z   [must] requirement_quality REQ-MANIFEST-4 criterion=length — title is 31 words; want 3..=25
2026-07-06T06:24:02.6510524Z   [must] requirement_quality REQ-MANIFEST-5 criterion=length — title is 132 words; want 3..=25
2026-07-06T06:24:02.6510781Z   [must] requirement_quality REQ-MANIFEST-6 criterion=length — title is 84 words; want 3..=25
2026-07-06T06:24:02.6511038Z   [must] requirement_quality REQ-MANIFEST-7 criterion=length — title is 120 words; want 3..=25
2026-07-06T06:24:02.6511296Z   [must] requirement_quality REQ-MANIFEST-8 criterion=length — title is 77 words; want 3..=25
2026-07-06T06:24:02.6511682Z   [must] requirement_quality REQ-MANIFEST-NODE-KEY criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6511973Z   [must] requirement_quality REQ-MANIFEST-NODE-KEY criterion=length — title is 187 words; want 3..=25
2026-07-06T06:24:02.6512358Z   [must] requirement_quality REQ-MANIFEST-SUBST criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6512632Z   [must] requirement_quality REQ-MANIFEST-SUBST criterion=length — title is 121 words; want 3..=25
2026-07-06T06:24:02.6512881Z   [must] requirement_quality REQ-MESH-1 criterion=length — title is 86 words; want 3..=25
2026-07-06T06:24:02.6513215Z   [must] requirement_quality REQ-MESH-2 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6513458Z   [must] requirement_quality REQ-MESH-2 criterion=length — title is 120 words; want 3..=25
2026-07-06T06:24:02.6513797Z   [must] requirement_quality REQ-MESH-3 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6514040Z   [must] requirement_quality REQ-MESH-3 criterion=length — title is 86 words; want 3..=25
2026-07-06T06:24:02.6514512Z   [must] requirement_quality REQ-MESH-4 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6514764Z   [must] requirement_quality REQ-MESH-4 criterion=length — title is 99 words; want 3..=25
2026-07-06T06:24:02.6515107Z   [must] requirement_quality REQ-MESH-5 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6515349Z   [must] requirement_quality REQ-MESH-5 criterion=length — title is 72 words; want 3..=25
2026-07-06T06:24:02.6515682Z   [must] requirement_quality REQ-MESH-6 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6515920Z   [must] requirement_quality REQ-MESH-6 criterion=length — title is 56 words; want 3..=25
2026-07-06T06:24:02.6516259Z   [must] requirement_quality REQ-MIGRATE-1 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6516496Z   [must] requirement_quality REQ-MSG-4 criterion=length — title is 31 words; want 3..=25
2026-07-06T06:24:02.6516826Z   [must] requirement_quality REQ-MSG-5 criterion=length — title is 38 words; want 3..=25
2026-07-06T06:24:02.6517059Z   [must] requirement_quality REQ-MSG-6 criterion=length — title is 65 words; want 3..=25
2026-07-06T06:24:02.6517440Z   [must] requirement_quality REQ-MSG-CLI-ORIGIN criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6517726Z   [must] requirement_quality REQ-MSG-CLI-ORIGIN criterion=length — title is 107 words; want 3..=25
2026-07-06T06:24:02.6518095Z   [must] requirement_quality REQ-MSG-DELIVERY-AXES criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6518381Z   [must] requirement_quality REQ-MSG-DELIVERY-AXES criterion=length — title is 291 words; want 3..=25
2026-07-06T06:24:02.6518748Z   [must] requirement_quality REQ-MSG-ENVELOPE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6519097Z   [must] requirement_quality REQ-MSG-ENVELOPE criterion=length — title is 153 words; want 3..=25
2026-07-06T06:24:02.6519498Z   [must] requirement_quality REQ-MSG-IDLE-EDGE-DRAIN criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6519799Z   [must] requirement_quality REQ-MSG-IDLE-EDGE-DRAIN criterion=length — title is 121 words; want 3..=25
2026-07-06T06:24:02.6520221Z   [must] requirement_quality REQ-MSG-IDLE-TRANSLATION-BINARY criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6520545Z   [must] requirement_quality REQ-MSG-IDLE-TRANSLATION-BINARY criterion=length — title is 269 words; want 3..=25
2026-07-06T06:24:02.6520955Z   [must] requirement_quality REQ-MSG-SELF-DETECT-ANCESTRY criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6521265Z   [must] requirement_quality REQ-MSG-SELF-DETECT-ANCESTRY criterion=length — title is 153 words; want 3..=25
2026-07-06T06:24:02.6521656Z   [must] requirement_quality REQ-NET-FAMILY-GATE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6521937Z   [must] requirement_quality REQ-NET-FAMILY-GATE criterion=length — title is 118 words; want 3..=25
2026-07-06T06:24:02.6522334Z   [must] requirement_quality REQ-OPID-MINTER-NAMESPACE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6522634Z   [must] requirement_quality REQ-OPID-MINTER-NAMESPACE criterion=length — title is 337 words; want 3..=25
2026-07-06T06:24:02.6523018Z   [must] requirement_quality REQ-OPID-TRACING-RETRY criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6523298Z   [must] requirement_quality REQ-OPID-TRACING-RETRY criterion=length — title is 222 words; want 3..=25
2026-07-06T06:24:02.6523641Z   [must] requirement_quality REQ-PAIR-8 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6523995Z   [must] requirement_quality REQ-PAIR-8 criterion=length — title is 67 words; want 3..=25
2026-07-06T06:24:02.6524385Z   [must] requirement_quality REQ-PEER-PUMP-CHURN-STALL criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6524681Z   [must] requirement_quality REQ-PEER-PUMP-CHURN-STALL criterion=length — title is 97 words; want 3..=25
2026-07-06T06:24:02.6525033Z   [must] requirement_quality REQ-PICKER-1 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6525291Z   [must] requirement_quality REQ-PICKER-1 criterion=length — title is 156 words; want 3..=25
2026-07-06T06:24:02.6525550Z   [must] requirement_quality REQ-PICKER-2 criterion=length — title is 77 words; want 3..=25
2026-07-06T06:24:02.6525800Z   [must] requirement_quality REQ-PICKER-3 criterion=length — title is 120 words; want 3..=25
2026-07-06T06:24:02.6526146Z   [must] requirement_quality REQ-PICKER-4 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6526504Z   [must] requirement_quality REQ-PICKER-4 criterion=length — title is 84 words; want 3..=25
2026-07-06T06:24:02.6526852Z   [must] requirement_quality REQ-PICKER-5 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6527104Z   [must] requirement_quality REQ-PICKER-5 criterion=length — title is 147 words; want 3..=25
2026-07-06T06:24:02.6527525Z   [must] requirement_quality REQ-PICKER-ADAPTER-DESCRIPTION criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6527844Z   [must] requirement_quality REQ-PICKER-ADAPTER-DESCRIPTION criterion=length — title is 64 words; want 3..=25
2026-07-06T06:24:02.6528224Z   [must] requirement_quality REQ-PICKER-BACK-NAV criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6528490Z   [must] requirement_quality REQ-PICKER-BACK-NAV criterion=length — title is 140 words; want 3..=25
2026-07-06T06:24:02.6528917Z   [must] requirement_quality REQ-PICKER-CHANGE-ADAPTER-FLOW criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6529381Z   [must] requirement_quality REQ-PICKER-CHANGE-ADAPTER-FLOW criterion=length — title is 117 words; want 3..=25
2026-07-06T06:24:02.6529776Z   [must] requirement_quality REQ-PICKER-CHOOSE-DEDUP-ALL criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6530072Z   [must] requirement_quality REQ-PICKER-CHOOSE-DEDUP-ALL criterion=length — title is 72 words; want 3..=25
2026-07-06T06:24:02.6530415Z   [must] requirement_quality REQ-PICKER-CONTROL-LINE-STATUS-GATE criterion=length — title is 71 words; want 3..=25
2026-07-06T06:24:02.6530825Z   [must] requirement_quality REQ-PICKER-CONTROLLED-LOCAL criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6531129Z   [must] requirement_quality REQ-PICKER-CONTROLLED-LOCAL criterion=length — title is 95 words; want 3..=25
2026-07-06T06:24:02.6531458Z   [must] requirement_quality REQ-PICKER-CURRENT-DIR-LABEL criterion=length — title is 114 words; want 3..=25
2026-07-06T06:24:02.6531849Z   [must] requirement_quality REQ-PICKER-FORK-LABEL-CWD criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6532154Z   [must] requirement_quality REQ-PICKER-FORK-LABEL-CWD criterion=length — title is 58 words; want 3..=25
2026-07-06T06:24:02.6532444Z   [must] requirement_quality REQ-PICKER-HISTORY-FRESH criterion=length — title is 51 words; want 3..=25
2026-07-06T06:24:02.6532769Z   [must] requirement_quality REQ-PICKER-HISTORY-FRESH criterion=tbd-todo — title contains placeholder marker 'TBD'
2026-07-06T06:24:02.6533108Z   [must] requirement_quality REQ-PICKER-KEY-GATE-LAUNCH-CAPABLE criterion=length — title is 89 words; want 3..=25
2026-07-06T06:24:02.6533398Z   [must] requirement_quality REQ-PICKER-NODE-GROUPING criterion=length — title is 73 words; want 3..=25
2026-07-06T06:24:02.6533815Z   [must] requirement_quality REQ-PICKER-OFFLINE-NO-VIEW criterion=length — title is 46 words; want 3..=25
2026-07-06T06:24:02.6534110Z   [must] requirement_quality REQ-PICKER-ONLINE-ACTION criterion=length — title is 74 words; want 3..=25
2026-07-06T06:24:02.6534434Z   [must] requirement_quality REQ-PICKER-ONLINE-ACTION criterion=tbd-todo — title contains placeholder marker 'TBD'
2026-07-06T06:24:02.6534764Z   [must] requirement_quality REQ-PICKER-PROJECT-DISPLAY-NAME criterion=length — title is 103 words; want 3..=25
2026-07-06T06:24:02.6535088Z   [must] requirement_quality REQ-PICKER-PROJECT-HISTORY-TRUTH criterion=length — title is 128 words; want 3..=25
2026-07-06T06:24:02.6535494Z   [must] requirement_quality REQ-PICKER-PURGE-SHORTCUT criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6535800Z   [must] requirement_quality REQ-PICKER-PURGE-SHORTCUT criterion=length — title is 180 words; want 3..=25
2026-07-06T06:24:02.6536293Z   [must] requirement_quality REQ-PICKER-REMOTE-WAKE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6536587Z   [must] requirement_quality REQ-PICKER-REMOTE-WAKE criterion=length — title is 296 words; want 3..=25
2026-07-06T06:24:02.6537001Z   [must] requirement_quality REQ-PICKER-RESUME-CONTEXT-PANEL criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6537330Z   [must] requirement_quality REQ-PICKER-RESUME-CONTEXT-PANEL criterion=length — title is 53 words; want 3..=25
2026-07-06T06:24:02.6537760Z   [must] requirement_quality REQ-PICKER-SHORTCUT-LABEL-FILENAME criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6538089Z   [must] requirement_quality REQ-PICKER-SHORTCUT-LABEL-FILENAME criterion=length — title is 75 words; want 3..=25
2026-07-06T06:24:02.6538414Z   [must] requirement_quality REQ-PICKER-START-PROJECT-CHOICE criterion=length — title is 87 words; want 3..=25
2026-07-06T06:24:02.6538808Z   [must] requirement_quality REQ-PICKER-UX-V013 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6539167Z   [must] requirement_quality REQ-PICKER-UX-V013 criterion=length — title is 86 words; want 3..=25
2026-07-06T06:24:02.6539468Z   [must] requirement_quality REQ-PICKER-WINDOW-TITLE criterion=length — title is 68 words; want 3..=25
2026-07-06T06:24:02.6539811Z   [must] requirement_quality REQ-PRES-1 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6540060Z   [must] requirement_quality REQ-PRES-1 criterion=length — title is 48 words; want 3..=25
2026-07-06T06:24:02.6540483Z   [must] requirement_quality REQ-PRESENCE-CONTROL-REAP-ON-EXIT criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6540813Z   [must] requirement_quality REQ-PRESENCE-CONTROL-REAP-ON-EXIT criterion=length — title is 139 words; want 3..=25
2026-07-06T06:24:02.6541123Z   [must] requirement_quality REQ-PRESENCE-LIVENESS-TRUTH criterion=length — title is 215 words; want 3..=25
2026-07-06T06:24:02.6541572Z   [must] requirement_quality REQ-PSYCHE-CONTEXT-FILE-INDIRECTION criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6541900Z   [must] requirement_quality REQ-PSYCHE-CONTEXT-FILE-INDIRECTION criterion=length — title is 206 words; want 3..=25
2026-07-06T06:24:02.6542342Z   [must] requirement_quality REQ-PSYCHE-CRASHLOOP-BACKOFF-SHUTDOWN criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6542675Z   [must] requirement_quality REQ-PSYCHE-CRASHLOOP-BACKOFF-SHUTDOWN criterion=length — title is 90 words; want 3..=25
2026-07-06T06:24:02.6543081Z   [must] requirement_quality REQ-PSYCHE-EPHEMERAL-DRIVER criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6543502Z   [must] requirement_quality REQ-PSYCHE-EPHEMERAL-DRIVER criterion=length — title is 146 words; want 3..=25
2026-07-06T06:24:02.6543934Z   [must] requirement_quality REQ-PSYCHE-LEGACY-RESIDENT-SWEEP criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6544261Z   [must] requirement_quality REQ-PSYCHE-LEGACY-RESIDENT-SWEEP criterion=length — title is 282 words; want 3..=25
2026-07-06T06:24:02.6544670Z   [must] requirement_quality REQ-PSYCHE-NESTED-RESOLUTION criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6544984Z   [must] requirement_quality REQ-PSYCHE-NESTED-RESOLUTION criterion=length — title is 147 words; want 3..=25
2026-07-06T06:24:02.6545373Z   [must] requirement_quality REQ-PSYCHE-SID-CUSTODY criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6545663Z   [must] requirement_quality REQ-PSYCHE-SID-CUSTODY criterion=length — title is 134 words; want 3..=25
2026-07-06T06:24:02.6546021Z   [must] requirement_quality REQ-RC-1 criterion=length — title is 94 words; want 3..=25
2026-07-06T06:24:02.6546416Z   [must] requirement_quality REQ-RC-CROSS-NODE-ATTACH criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6546717Z   [must] requirement_quality REQ-RC-CROSS-NODE-ATTACH criterion=length — title is 95 words; want 3..=25
2026-07-06T06:24:02.6547076Z   [must] requirement_quality REQ-RC-IDENTITY criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6547353Z   [must] requirement_quality REQ-RC-IDENTITY criterion=length — title is 122 words; want 3..=25
2026-07-06T06:24:02.6547739Z   [must] requirement_quality REQ-RC-IDMARKER-DISABLE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6548034Z   [must] requirement_quality REQ-RC-IDMARKER-DISABLE criterion=length — title is 73 words; want 3..=25
2026-07-06T06:24:02.6548439Z   [must] requirement_quality REQ-RC-KEY-VT-TRANSLATE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6548729Z   [must] requirement_quality REQ-RC-KEY-VT-TRANSLATE criterion=length — title is 249 words; want 3..=25
2026-07-06T06:24:02.6549184Z   [must] requirement_quality REQ-RC-MOUSE-FORWARD criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6549468Z   [must] requirement_quality REQ-RC-MOUSE-FORWARD criterion=length — title is 218 words; want 3..=25
2026-07-06T06:24:02.6549838Z   [must] requirement_quality REQ-RC-RECONNECT criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6550109Z   [must] requirement_quality REQ-RC-RECONNECT criterion=length — title is 244 words; want 3..=25
2026-07-06T06:24:02.6550472Z   [must] requirement_quality REQ-RC-WIN-PASTE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6550868Z   [must] requirement_quality REQ-RC-WIN-PASTE criterion=length — title is 226 words; want 3..=25
2026-07-06T06:24:02.6551249Z   [must] requirement_quality REQ-RC-WIN-VT-OUTPUT criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6551526Z   [must] requirement_quality REQ-RC-WIN-VT-OUTPUT criterion=length — title is 150 words; want 3..=25
2026-07-06T06:24:02.6551878Z   [must] requirement_quality REQ-RCVIEW-1 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6552132Z   [must] requirement_quality REQ-RCVIEW-1 criterion=length — title is 197 words; want 3..=25
2026-07-06T06:24:02.6552513Z   [must] requirement_quality REQ-READY-AGENT-RESUME criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6552798Z   [must] requirement_quality REQ-READY-AGENT-RESUME criterion=length — title is 165 words; want 3..=25
2026-07-06T06:24:02.6553283Z   [must] requirement_quality REQ-REST-VERB-ROUTING criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6553574Z   [must] requirement_quality REQ-REST-VERB-ROUTING criterion=length — title is 326 words; want 3..=25
2026-07-06T06:24:02.6554014Z   [must] requirement_quality REQ-RESUME-ADAPTER-FOLLOWS-SESSION criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6554353Z   [must] requirement_quality REQ-RESUME-ADAPTER-FOLLOWS-SESSION criterion=length — title is 275 words; want 3..=25
2026-07-06T06:24:02.6554746Z   [must] requirement_quality REQ-RESUME-CONTEXT-PULL criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6555045Z   [must] requirement_quality REQ-RESUME-CONTEXT-PULL criterion=length — title is 460 words; want 3..=25
2026-07-06T06:24:02.6555350Z   [must] requirement_quality REQ-RESUME-HARNESS-SESSION-ID criterion=length — title is 128 words; want 3..=25
2026-07-06T06:24:02.6555670Z   [must] requirement_quality REQ-RESUME-REAP-PRIOR-HARNESS criterion=length — title is 54 words; want 3..=25
2026-07-06T06:24:02.6555980Z   [must] requirement_quality REQ-RESUME-ROW-PER-PROJECT criterion=length — title is 59 words; want 3..=25
2026-07-06T06:24:02.6556257Z   [must] requirement_quality REQ-RUN-EMPTY-CREATE criterion=length — title is 63 words; want 3..=25
2026-07-06T06:24:02.6556647Z   [must] requirement_quality REQ-RUN-ID-REUSES-ADAPTER criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6556943Z   [must] requirement_quality REQ-RUN-ID-REUSES-ADAPTER criterion=length — title is 174 words; want 3..=25
2026-07-06T06:24:02.6557342Z   [must] requirement_quality REQ-RUN-MULTISUBNET-HOME criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6557641Z   [must] requirement_quality REQ-RUN-MULTISUBNET-HOME criterion=length — title is 120 words; want 3..=25
2026-07-06T06:24:02.6558040Z   [must] requirement_quality REQ-RUN-NO-DUP-SESSION criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6558331Z   [must] requirement_quality REQ-RUN-NO-DUP-SESSION criterion=length — title is 137 words; want 3..=25
2026-07-06T06:24:02.6558698Z   [must] requirement_quality REQ-RUN-PICKER criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6559037Z   [must] requirement_quality REQ-RUN-PICKER criterion=length — title is 203 words; want 3..=25
2026-07-06T06:24:02.6559439Z   [must] requirement_quality REQ-RUN-PICKER-HOME criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6559725Z   [must] requirement_quality REQ-RUN-PICKER-HOME criterion=length — title is 156 words; want 3..=25
2026-07-06T06:24:02.6560085Z   [must] requirement_quality REQ-RUN-SHORTCUT criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6560480Z   [must] requirement_quality REQ-RUN-SHORTCUT criterion=length — title is 226 words; want 3..=25
2026-07-06T06:24:02.6560737Z   [must] requirement_quality REQ-SEAM-SPAWN criterion=length — title is 2 word(s); want 3..=25
2026-07-06T06:24:02.6561151Z   [must] requirement_quality REQ-SELF-DETECT-PARENT-PID criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6561461Z   [must] requirement_quality REQ-SELF-DETECT-PARENT-PID criterion=length — title is 224 words; want 3..=25
2026-07-06T06:24:02.6561847Z   [must] requirement_quality REQ-SEND-REPLYTO-REMOVE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6562143Z   [must] requirement_quality REQ-SEND-REPLYTO-REMOVE criterion=length — title is 60 words; want 3..=25
2026-07-06T06:24:02.6562520Z   [must] requirement_quality REQ-SEND-SPT-HOSTED criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6562938Z   [must] requirement_quality REQ-SEND-SPT-HOSTED criterion=length — title is 169 words; want 3..=25
2026-07-06T06:24:02.6563354Z   [must] requirement_quality REQ-SESSION-ADAPTER-RECORDED criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6563669Z   [must] requirement_quality REQ-SESSION-ADAPTER-RECORDED criterion=length — title is 205 words; want 3..=25
2026-07-06T06:24:02.6564078Z   [must] requirement_quality REQ-SESSION-RESUME-TEMPLATE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6564387Z   [must] requirement_quality REQ-SESSION-RESUME-TEMPLATE criterion=length — title is 287 words; want 3..=25
2026-07-06T06:24:02.6564836Z   [must] requirement_quality REQ-SESSIONS-LOG-ENDPOINT-ATTRIBUTION criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6565178Z   [must] requirement_quality REQ-SESSIONS-LOG-ENDPOINT-ATTRIBUTION criterion=length — title is 120 words; want 3..=25
2026-07-06T06:24:02.6565452Z   [must] requirement_quality REQ-SHELL-1 criterion=length — title is 36 words; want 3..=25
2026-07-06T06:24:02.6565710Z   [must] requirement_quality REQ-SHELL-2 criterion=length — title is 49 words; want 3..=25
2026-07-06T06:24:02.6565953Z   [must] requirement_quality REQ-SHELL-3 criterion=length — title is 80 words; want 3..=25
2026-07-06T06:24:02.6566311Z   [must] requirement_quality REQ-SHELL-4 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6566545Z   [must] requirement_quality REQ-SHELL-4 criterion=length — title is 84 words; want 3..=25
2026-07-06T06:24:02.6566793Z   [must] requirement_quality REQ-SHELL-5 criterion=length — title is 49 words; want 3..=25
2026-07-06T06:24:02.6567141Z   [must] requirement_quality REQ-START-5 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6567398Z   [must] requirement_quality REQ-START-5 criterion=length — title is 129 words; want 3..=25
2026-07-06T06:24:02.6567660Z   [must] requirement_quality REQ-STORE-1 criterion=length — title is 34 words; want 3..=25
2026-07-06T06:24:02.6567983Z   [must] requirement_quality REQ-STORE-CONTEXT-BRANCH-FILL criterion=length — title is 73 words; want 3..=25
2026-07-06T06:24:02.6568238Z   [must] requirement_quality REQ-SUBNET-5 criterion=length — title is 52 words; want 3..=25
2026-07-06T06:24:02.6568586Z   [must] requirement_quality REQ-SUBNET-6 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6568845Z   [must] requirement_quality REQ-SUBNET-6 criterion=length — title is 38 words; want 3..=25
2026-07-06T06:24:02.6569545Z   [must] requirement_quality REQ-SUBNET-7 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6569979Z   [must] requirement_quality REQ-SUBNET-7 criterion=length — title is 75 words; want 3..=25
2026-07-06T06:24:02.6570531Z   [must] requirement_quality REQ-SUBNET-8 criterion=length — title is 53 words; want 3..=25
2026-07-06T06:24:02.6570943Z   [must] requirement_quality REQ-SUBNET-COUNT-ROUTABLE criterion=length — title is 78 words; want 3..=25
2026-07-06T06:24:02.6571463Z   [must] requirement_quality REQ-SUBNET-DISPLAY-PARITY criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6571848Z   [must] requirement_quality REQ-SUBNET-DISPLAY-PARITY criterion=length — title is 166 words; want 3..=25
2026-07-06T06:24:02.6572294Z   [must] requirement_quality REQ-TERM-5 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6572608Z   [must] requirement_quality REQ-TERM-5 criterion=length — title is 71 words; want 3..=25
2026-07-06T06:24:02.6573046Z   [must] requirement_quality REQ-TERM-6 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6573337Z   [must] requirement_quality REQ-TERM-6 criterion=length — title is 53 words; want 3..=25
2026-07-06T06:24:02.6573900Z   [must] requirement_quality REQ-TERM-7 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6574195Z   [must] requirement_quality REQ-TERM-7 criterion=length — title is 55 words; want 3..=25
2026-07-06T06:24:02.6574752Z   [must] requirement_quality REQ-TRANSLATE-BINARY-LIVENESS-DECAY criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6575178Z   [must] requirement_quality REQ-TRANSLATE-BINARY-LIVENESS-DECAY criterion=length — title is 94 words; want 3..=25
2026-07-06T06:24:02.6575667Z   [must] requirement_quality REQ-TRANSLATE-COMMAND criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6576031Z   [must] requirement_quality REQ-TRANSLATE-COMMAND criterion=length — title is 137 words; want 3..=25
2026-07-06T06:24:02.6576580Z   [must] requirement_quality REQ-TRANSLATE-COMMIT-MISS-TOLERANCE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6577014Z   [must] requirement_quality REQ-TRANSLATE-COMMIT-MISS-TOLERANCE criterion=length — title is 131 words; want 3..=25
2026-07-06T06:24:02.6577448Z   [must] requirement_quality REQ-UPD-6 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6577749Z   [must] requirement_quality REQ-UPD-6 criterion=length — title is 32 words; want 3..=25
2026-07-06T06:24:02.6578129Z   [must] requirement_quality REQ-UPD-7 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6578360Z   [must] requirement_quality REQ-UPD-7 criterion=length — title is 88 words; want 3..=25
2026-07-06T06:24:02.6578710Z   [must] requirement_quality REQ-UPD-8 criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6579023Z   [must] requirement_quality REQ-UPD-8 criterion=length — title is 115 words; want 3..=25
2026-07-06T06:24:02.6579295Z   [must] requirement_quality REQ-UPD-9 criterion=length — title is 110 words; want 3..=25
2026-07-06T06:24:02.6579729Z   [must] requirement_quality REQ-UPDATE-APPLY-ALREADY-APPLIED criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6580057Z   [must] requirement_quality REQ-UPDATE-APPLY-ALREADY-APPLIED criterion=length — title is 120 words; want 3..=25
2026-07-06T06:24:02.6580491Z   [must] requirement_quality REQ-UPDATE-APPLY-RESTART-NOTICE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6580820Z   [must] requirement_quality REQ-UPDATE-APPLY-RESTART-NOTICE criterion=length — title is 81 words; want 3..=25
2026-07-06T06:24:02.6581133Z   [must] requirement_quality REQ-UPDATE-FETCH-APPLY-FLAG criterion=length — title is 123 words; want 3..=25
2026-07-06T06:24:02.6581552Z   [must] requirement_quality REQ-UPDATE-FETCH-CURRENT-UX criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6581962Z   [must] requirement_quality REQ-UPDATE-FETCH-CURRENT-UX criterion=length — title is 134 words; want 3..=25
2026-07-06T06:24:02.6582399Z   [must] requirement_quality REQ-UPDATE-RUNNING-IMAGE-SURFACE criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6582728Z   [must] requirement_quality REQ-UPDATE-RUNNING-IMAGE-SURFACE criterion=length — title is 166 words; want 3..=25
2026-07-06T06:24:02.6583164Z   [must] requirement_quality REQ-VIEWER-SKIP-TO-LIVE-ON-EVICT criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6583493Z   [must] requirement_quality REQ-VIEWER-SKIP-TO-LIVE-ON-EVICT criterion=length — title is 227 words; want 3..=25
2026-07-06T06:24:02.6583770Z   [must] requirement_quality REQ-WAKE-RESUME-LEG criterion=length — title is 274 words; want 3..=25
2026-07-06T06:24:02.6584034Z   [must] requirement_quality REQ-WAKE-WAIT criterion=length — title is 89 words; want 3..=25
2026-07-06T06:24:02.6584536Z   [must] requirement_quality REQ-WAN-SEND-DELIVERY criterion=contains-and — title contains ' and ' — may smuggle multiple capabilities
2026-07-06T06:24:02.6584836Z   [must] requirement_quality REQ-WAN-SEND-DELIVERY criterion=length — title is 117 words; want 3..=25
2026-07-06T06:24:02.6585146Z   [must] requirement_quality REQ-WAN-SPT-HOSTED-DELIVERY criterion=length — title is 156 words; want 3..=25
2026-07-06T06:24:02.6585399Z   [must] requirement_quality REQ-WHOAMI-1 criterion=length — title is 76 words; want 3..=25
2026-07-06T06:24:02.6585718Z   [must] requirement_quality REQ-XTASK-SPT-BIN-TARGET-DIR criterion=length — title is 98 words; want 3..=25
2026-07-06T06:24:02.6585756Z 
2026-07-06T06:24:02.6585917Z # Requirement quality review
2026-07-06T06:24:02.6585952Z 
2026-07-06T06:24:02.6586147Z You are reviewing 418 requirement(s) from `traceable-reqs.toml` against a quality
2026-07-06T06:24:02.6586346Z rubric. Deterministic checks (length, contains-and, tbd-todo, duplicate-titles,
2026-07-06T06:24:02.6586539Z trailing-etc) have already run and surfaced as `requirement_quality` findings on
2026-07-06T06:24:02.6586677Z this command's output. Your task is the rubric items below.
2026-07-06T06:24:02.6586707Z 
2026-07-06T06:24:02.6586797Z ## Rubric
2026-07-06T06:24:02.6586830Z 
2026-07-06T06:24:02.6587093Z - **singular** — describes one capability; no smuggled "and"/"or" across distinct actions.
2026-07-06T06:24:02.6587322Z - **verifiable** — states an observable behavior a test or reviewer could confirm.
2026-07-06T06:24:02.6587530Z - **atomic** — cannot be split into two requirements without losing meaning.
2026-07-06T06:24:02.6587684Z - **active-voice** — clear subject and active verb.
2026-07-06T06:24:02.6587717Z 
2026-07-06T06:24:02.6587942Z If a criterion is borderline or doesn't apply, abstain — only emit findings for
2026-07-06T06:24:02.6588022Z clear concerns.
2026-07-06T06:24:02.6588046Z 
2026-07-06T06:24:02.6588141Z ## Requirements
2026-07-06T06:24:02.6588179Z 
2026-07-06T06:24:02.6588271Z ### REQ-ARCH-1
2026-07-06T06:24:02.6588374Z - Title: Many small acyclically-layered crates
2026-07-06T06:24:02.6588470Z - Required stages: impl
2026-07-06T06:24:02.6588504Z 
2026-07-06T06:24:02.6588581Z ### REQ-ARCH-2
2026-07-06T06:24:02.6588737Z - Title: Public SDK surface is spt-proto, spt-runtime, spt-msg
2026-07-06T06:24:02.6588828Z - Required stages: impl
2026-07-06T06:24:02.6588858Z 
2026-07-06T06:24:02.6589037Z ### REQ-ARCH-3
2026-07-06T06:24:02.6589218Z - Title: Wire-protocol version independent of crate semver, N-1 compat window
2026-07-06T06:24:02.6589331Z - Required stages: impl, unit
2026-07-06T06:24:02.6589359Z 
2026-07-06T06:24:02.6589435Z ### REQ-ARCH-4
2026-07-06T06:24:02.6589579Z - Title: Copy-verbatim the commodity layer from the sister project
2026-07-06T06:24:02.6589674Z - Required stages: impl, unit
2026-07-06T06:24:02.6589706Z 
2026-07-06T06:24:02.6589787Z ### REQ-DAEMON-1
2026-07-06T06:24:02.6590035Z - Title: One per-machine spt-daemon owning all per-machine state
2026-07-06T06:24:02.6590136Z - Required stages: impl, unit, int
2026-07-06T06:24:02.6590170Z 
2026-07-06T06:24:02.6590250Z ### REQ-DAEMON-2
2026-07-06T06:24:02.6590364Z - Title: Broker/brain split for seamless self-update
2026-07-06T06:24:02.6590460Z - Required stages: impl, unit, int
2026-07-06T06:24:02.6590489Z 
2026-07-06T06:24:02.6590574Z ### REQ-DAEMON-3
2026-07-06T06:24:02.6590698Z - Title: Any api invocation auto-starts the daemon if absent
2026-07-06T06:24:02.6590795Z - Required stages: impl, unit, int
2026-07-06T06:24:02.6590824Z 
2026-07-06T06:24:02.6590894Z ### REQ-DAEMON-4
2026-07-06T06:24:02.6591003Z - Title: Honor every KNOWN-HAZARDS invariant
2026-07-06T06:24:02.6591100Z - Required stages: impl, unit, int
2026-07-06T06:24:02.6591129Z 
2026-07-06T06:24:02.6591218Z ### REQ-STORE-1
2026-07-06T06:24:02.6592068Z - Title: spt-store::BranchStore (git branch as versioned KV; commit=checkpoint/tip=resume, atomic multi-key, merge-native sync) is the substrate for coarse/durable/audited state (context, registry snapshot+distribution, daemon checkpoint); hot paths (B5 fsync journal) + indexed queries (SQLite spool) excluded (ADR-0011)
2026-07-06T06:24:02.6592273Z - Required stages: impl, unit
2026-07-06T06:24:02.6592307Z 
2026-07-06T06:24:02.6592397Z ### REQ-MANIFEST-1
2026-07-06T06:24:02.6592564Z - Title: Per-adapter manifest with adapter_name and min_spt_core_version
2026-07-06T06:24:02.6592654Z - Required stages: doc, impl, unit
2026-07-06T06:24:02.6592688Z 
2026-07-06T06:24:02.6592775Z ### REQ-MANIFEST-2
2026-07-06T06:24:02.6593250Z - Title: Adapter profiles — sparse leaf-replace overlays (shipped + local), composite <adapter>:<profile> addressing, shadow-refusal, tighten-only consent floors
2026-07-06T06:24:02.6593337Z - Required stages: doc, impl, unit
2026-07-06T06:24:02.6593371Z 
2026-07-06T06:24:02.6593461Z ### REQ-MANIFEST-3
2026-07-06T06:24:02.6594053Z - Title: Adapter strings — [strings] KV tree, dot-path get-string resolving through the profile leaf-replace overlay, set-string editing a local profile's [strings] only; data-only (nothing executes a string)
2026-07-06T06:24:02.6594156Z - Required stages: doc, impl, unit
2026-07-06T06:24:02.6594185Z 
2026-07-06T06:24:02.6594262Z ### REQ-MANIFEST-4
2026-07-06T06:24:02.6594938Z - Title: Keyword hints — [[hints]] {keywords (literal/regex), text}; spt api hint --session emits at most one matched hint per message, once per session (seen-set), declaration-order first match; profiles overlay [[hints]] by leaf-replace
2026-07-06T06:24:02.6595034Z - Required stages: doc, impl, unit
2026-07-06T06:24:02.6595062Z 
2026-07-06T06:24:02.6595147Z ### REQ-MANIFEST-5
2026-07-06T06:24:02.6597944Z - Title: File-backed adapter [strings] (M12-W3-T3.1): a [strings] dot-path value MAY be an inline-table FILE POINTER `key = { file = "rel/path" }` resolved to the file's contents at get-string time, keeping large bodies (skill-instructions, hint text) out of the manifest. A value-position table with a `file` key IS the pointer form (reserved — cannot double as data). Per-adapter aux storage `adapters/<adapter>/strings/`; pointers resolve relative to it with CONTAINMENT (reject `..`/absolute escaping the dir). UPDATE-SAFETY: a LOCAL profile's file-pointers resolve relative to the user-owned local-profile dir (NOT adapter-shipped strings/, which adapter updates overwrite), or the local profile inlines. Validate-at-register (fail-fast on a bad/escaping/missing pointer) + LAZY read at get-string (live file edits reflect, no re-register) + skip-diagnostics on missing-at-read (no hard-crash, mirrors [digest]). Rides the same leaf-replace profile overlay as the rest of [strings].
2026-07-06T06:24:02.6598048Z - Required stages: doc, impl, unit
2026-07-06T06:24:02.6598081Z 
2026-07-06T06:24:02.6598173Z ### REQ-MANIFEST-6
2026-07-06T06:24:02.6600276Z - Title: Cross-adapter fallback target addressing (M12-W3-T3.2): a cross-adapter fallback target is addressed as `<adapter>:<profile>` (not just a bare adapter_name), resolved through the one composite-addressing resolver (registry::resolve_option) at every adapter-option read site so a fallback may select a shipped/local profile (e.g. a `ccs` profile). CONTEXT.md §cross-adapter-fallback reconciled ("ccs is a profile; cross-adapter fallback may target <adapter>:<profile>"). Contract-only this milestone: the node-wide fallback SETTING + its rate-limit invocation are deferred to the consuming milestone (the runtime path does not exist yet); this REQ guarantees the ADDRESSING resolves.
2026-07-06T06:24:02.6600477Z - Required stages: doc, unit
2026-07-06T06:24:02.6600510Z 
2026-07-06T06:24:02.6600600Z ### REQ-MANIFEST-7
2026-07-06T06:24:02.6603525Z - Title: Adapter-declared shortcut basename (M12-W2 follow-on): an optional `[adapter] shortcut_basename` manifest field names the basename the `spt endpoint run` picker bakes into the generated `<basename>-<id>` launcher shortcut (REQ-RUN-SHORTCUT). Absent ⇒ the harness-agnostic default `spt` (→ `spt-<id>`); an adapter sets it to brand its shortcuts (claude-spt → `cc` → `cc-<id>`), so the Claude-Code-ness lives in the PUBLISHED adapter manifest, never hardcoded in spt-core. The picker reads it from the RESOLVED manifest of the selected adapter (registry::resolve_option), falling back to `spt` when absent/empty/unresolvable. Additive + N-1-safe (serde-default Option, omitted from serialization when absent; old manifests parse clean); manifest.schema.json regenerated from the derive (ADR-0001, CI drift-gated). Documented in docs/MANIFEST.md `[adapter]` section + the claude-spt worked example — the adapter-author contract perri builds spt-claude-code against.
2026-07-06T06:24:02.6603759Z - Required stages: doc, impl, unit
2026-07-06T06:24:02.6603792Z 
2026-07-06T06:24:02.6603877Z ### REQ-MANIFEST-8
2026-07-06T06:24:02.6605985Z - Title: [adapter] host_binaries declares the harness executable basenames a kind="harness" adapter hosts agents inside (e.g. host_binaries = ["claude"]); bind-time pid→exe-basename match (case-insensitive, .exe-stripped) over the seed's parent_pid selects the candidate adapter set; zero matches → a friendly error naming the binary + the --adapter escape hatch. Additive + N-1-safe: optional Vec<String>, #[serde(default, skip_serializing_if = "Vec::is_empty")] (omitted-serialized like shortcut_basename, old manifests parse clean); manifest.schema.json regenerated from the derive (ADR-0001, CI drift-gated). The match-key for ADR-0021 adapter-agnostic bind-time resolution. (v0.9.0)
2026-07-06T06:24:02.6606108Z - Required stages: doc, impl, unit, int
2026-07-06T06:24:02.6606142Z 
2026-07-06T06:24:02.6606237Z ### REQ-SEAM-SPAWN
2026-07-06T06:24:02.6606328Z - Title: spawn-session seam
2026-07-06T06:24:02.6606427Z - Required stages: impl, unit
2026-07-06T06:24:02.6606457Z 
2026-07-06T06:24:02.6606533Z ### REQ-SEAM-POSTSPAWN
2026-07-06T06:24:02.6606662Z - Title: post-spawn / api bind seam with boot nonce
2026-07-06T06:24:02.6606752Z - Required stages: impl, unit
2026-07-06T06:24:02.6606776Z 
2026-07-06T06:24:02.6606867Z ### REQ-SEAM-PSYCHE
2026-07-06T06:24:02.6606995Z - Title: spawn-psyche seam (fresh + resume templates)
2026-07-06T06:24:02.6607096Z - Required stages: impl, unit, int
2026-07-06T06:24:02.6607130Z 
2026-07-06T06:24:02.6607210Z ### REQ-SEAM-HISTORY
2026-07-06T06:24:02.6607376Z - Title: History subsystem (fetcher / locate-normalize / native store)
2026-07-06T06:24:02.6607466Z - Required stages: impl, unit, int
2026-07-06T06:24:02.6607494Z 
2026-07-06T06:24:02.6607584Z ### REQ-SEAM-ACTIVITY
2026-07-06T06:24:02.6607745Z - Title: Activity/idle reported via api sentinels, not PTY quiescence
2026-07-06T06:24:02.6607837Z - Required stages: impl, unit
2026-07-06T06:24:02.6607865Z 
2026-07-06T06:24:02.6607950Z ### REQ-SEAM-INJECT
2026-07-06T06:24:02.6608089Z - Title: inject-input methods configurable per activity-state
2026-07-06T06:24:02.6608189Z - Required stages: impl, unit
2026-07-06T06:24:02.6608218Z 
2026-07-06T06:24:02.6608312Z ### REQ-SEAM-RESUME
2026-07-06T06:24:02.6608466Z - Title: resume-session seam (fresh-with-preload / continue-existing)
2026-07-06T06:24:02.6608641Z - Required stages: 
2026-07-06T06:24:02.6608670Z 
2026-07-06T06:24:02.6608752Z ### REQ-SEAM-CAPABILITY
2026-07-06T06:24:02.6608880Z - Title: Hostable endpoint-types capability declaration
2026-07-06T06:24:02.6609048Z - Required stages: impl, unit
2026-07-06T06:24:02.6609071Z 
2026-07-06T06:24:02.6609157Z ### REQ-SEAM-UPDATE
2026-07-06T06:24:02.6609319Z - Title: Adapter-update avenue (file-pull / delegated command)
2026-07-06T06:24:02.6609420Z - Required stages: impl, unit
2026-07-06T06:24:02.6609453Z 
2026-07-06T06:24:02.6609548Z ### REQ-API-1
2026-07-06T06:24:02.6609697Z - Title: api prefix and adapter_name on every machinery invocation
2026-07-06T06:24:02.6609800Z - Required stages: impl, unit, int
2026-07-06T06:24:02.6609824Z 
2026-07-06T06:24:02.6609905Z ### REQ-API-2
2026-07-06T06:24:02.6610092Z - Title: The api subcommand surface (bind/listen/poll/state/worker/boundary/...)
2026-07-06T06:24:02.6610185Z - Required stages: impl, unit, int
2026-07-06T06:24:02.6610219Z 
2026-07-06T06:24:02.6610414Z ### REQ-API-3
2026-07-06T06:24:02.6610535Z - Title: commune/signoff are file-drops, not commands
2026-07-06T06:24:02.6610632Z - Required stages: impl, unit, int
2026-07-06T06:24:02.6610665Z 
2026-07-06T06:24:02.6610751Z ### REQ-API-4
2026-07-06T06:24:02.6612181Z - Title: api resolves the adapter manifest (+ profile + install dir) from `--adapter name:profile` via the registry when `--manifest` is omitted; `--manifest` becomes an optional OVERRIDE (unregistered / local-dev manifests). Removes the require-both-flags redundancy — a registered adapter's live bringup / digest / capability needs only `--adapter` — and yields the precise install dir (the record's source_dir) rather than the --manifest parent, closing the copy-mode psyche-binary edge (v0.8.0)
2026-07-06T06:24:02.6612287Z - Required stages: doc, impl, unit
2026-07-06T06:24:02.6612316Z 
2026-07-06T06:24:02.6612395Z ### REQ-START-1
2026-07-06T06:24:02.6612578Z - Title: Adapters never resolve SPT_HOME; binary on PATH; api bridging only
2026-07-06T06:24:02.6612691Z - Required stages: impl, unit
2026-07-06T06:24:02.6612714Z 
2026-07-06T06:24:02.6612800Z ### REQ-START-2
2026-07-06T06:24:02.6612924Z - Title: Harness-hosted startup: api seed then listen
2026-07-06T06:24:02.6613022Z - Required stages: impl, unit, int
2026-07-06T06:24:02.6613055Z 
2026-07-06T06:24:02.6613136Z ### REQ-START-3
2026-07-06T06:24:02.6613289Z - Title: spt-hosted startup: spawn-session then api bind (no file)
2026-07-06T06:24:02.6613384Z - Required stages: impl, unit, int
2026-07-06T06:24:02.6613417Z 
2026-07-06T06:24:02.6613498Z ### REQ-START-4
2026-07-06T06:24:02.6613618Z - Title: Adapter-injected env aliases (SPT/OWL/LIVE)
2026-07-06T06:24:02.6613703Z - Required stages: impl, unit
2026-07-06T06:24:02.6613741Z 
2026-07-06T06:24:02.6613823Z ### REQ-START-5
2026-07-06T06:24:02.6616521Z - Title: Adapter-agnostic harness-hosted seed + bind-time adapter/profile resolution (ADR-0021): `api seed` carries only parent_pid + session_id (+ optional cwd), no --adapter — a pure "a harness session exists at this pid" record; --adapter becomes an OPTIONAL override across the whole api group (an explicit name[:profile] for adapter dev, never required). Omitted, listen/poll resolve the owning adapter/profile AT BIND as a pure read against the live registry — never a seed-time snapshot that can drift: seed parent_pid → exe basename → host_binaries candidate set (REQ-MANIFEST-8) → active-profile pointer (REQ-INSTALL-12) primary, else greatest-registered_at_ms candidate base profile (name-asc tie) → friendly zero-match error. Covers BOTH LiveAgent (listen) and ReadyAgent (poll) bringup. Restores legacy parity: `$LIVE start <id>` → `$SPT listen <id>` with no mandatory --adapter, one generic SessionStart hook per harness binary. (v0.9.0)
2026-07-06T06:24:02.6616635Z - Required stages: doc, impl, unit, int
2026-07-06T06:24:02.6616668Z 
2026-07-06T06:24:02.6616741Z ### REQ-EP-1
2026-07-06T06:24:02.6616864Z - Title: Day-one endpoint types; open type system
2026-07-06T06:24:02.6617061Z - Required stages: impl, unit
2026-07-06T06:24:02.6617093Z 
2026-07-06T06:24:02.6617179Z ### REQ-EP-2
2026-07-06T06:24:02.6617322Z - Title: Agent endpoints vs Shells distinction in the type model
2026-07-06T06:24:02.6617422Z - Required stages: impl, unit
2026-07-06T06:24:02.6617451Z 
2026-07-06T06:24:02.6617522Z ### REQ-EP-3
2026-07-06T06:24:02.6617675Z - Title: Messaging payloads carry typed operation commands + file blobs
2026-07-06T06:24:02.6617775Z - Required stages: impl, unit
2026-07-06T06:24:02.6617798Z 
2026-07-06T06:24:02.6617874Z ### REQ-EP-4
2026-07-06T06:24:02.6618002Z - Title: PresenceChannel broker endpoint (seam day-one)
2026-07-06T06:24:02.6618083Z - Required stages: impl, unit
2026-07-06T06:24:02.6618111Z 
2026-07-06T06:24:02.6618196Z ### REQ-EP-5
2026-07-06T06:24:02.6618816Z - Title: Concrete shell instantiation model: spawn-mints-instance (vs relink/online), registered-on-node permission + broadcast-is-discovery, per-shell require_approval gate, max_instances_per_owner + over_cap, instance aliasing, discovery scope
2026-07-06T06:24:02.6619059Z - Required stages: impl, unit, int
2026-07-06T06:24:02.6619087Z 
2026-07-06T06:24:02.6619173Z ### REQ-EP-6
2026-07-06T06:24:02.6620572Z - Title: Gateway type acceptance: a Gateway-typed perch binds (api bind --type, open type system — un-hardcode the live_agent default), advertises/addressable like any endpoint, owns shells (owner validation not agent-family-gated), subscribes to digests, and is the user-msg identity gate's user-backed origin (REQ-MSG-5); in-tree mock-gateway fixture (R-DOCS-2 pattern, no downstream adapter code). Cross-node WAN Gateway-origin (registry endpoint_type trust) tracked by REQ-MSG-6
2026-07-06T06:24:02.6620675Z - Required stages: doc, impl, unit
2026-07-06T06:24:02.6620703Z 
2026-07-06T06:24:02.6620784Z ### REQ-EP-7
2026-07-06T06:24:02.6622378Z - Title: Durable live-role.md: a per-agent broad-purpose statement in tracked/agents/<id>/ beside live-context.md (replicates with the mind on the same a-<id> branch); renders FIRST at start-transition context injection (role -> live-context -> project-context); SOLE writer `spt endpoint role --overwrite <file>` — mechanical no-automated-writer guarantee (echo-commune ingest / signoff / Psyche reconcile structurally exclude it). The user-backed-origin hard gate on the writer is a deferred later tightening (rides the user-msg identity plumbing)
2026-07-06T06:24:02.6622485Z - Required stages: doc, impl, unit
2026-07-06T06:24:02.6622518Z 
2026-07-06T06:24:02.6622598Z ### REQ-EP-8
2026-07-06T06:24:02.6625337Z - Title: AlwaysOnEndpoint: a resident, addressable, mindless endpoint whose adapter binary the daemon supervises continuously — register-triggered by an adapter-option's `[always-on]` manifest section, one supervised binary per `<adapter>[:profile]`, running independent of agent liveness. It self-manages its `#`-addressed channel endpoints via the existing `api bind` (one connection fronts many). The SECOND class of spt-core-boot-launched third-party binary (after the shell wake-watcher); supervision reuses the wake-watcher scaffolding (backoff / give-up latch / one-per-instance lock / orphan-kill / brain-side reconcile) MINUS the offline-only flip — always online, never resting (no dormant/suspended states). Two-way: agents message it; it may call `endpoint wake <id>`, target-side authorized (REQ-INST-3/6 wake resolution + access whitelist + shell_wake_spawn_anywhere — no caller-ownership gate). First consumer downstream: spt-discord.
2026-07-06T06:24:02.6625433Z - Required stages: 
2026-07-06T06:24:02.6625461Z 
2026-07-06T06:24:02.6625546Z ### REQ-EP-9
2026-07-06T06:24:02.6627067Z - Title: `#` always-on address sigil: a reserved LEADING sigil marking an AlwaysOnEndpoint, extending the REQ-INST-10 grammar to `[subnet:]#id[@node]`. Mandatory + bijective — `#name` ⟺ always-on endpoint, bare `name` ⟺ agent endpoint — so the router resolves endpoint class from the address alone, before any registry lookup. Sits ABOVE REQ-HAZARD-ID-CHARSET: the address parser strips the single leading `#` before id validation, so the bare/stored id stays charset-clean and a mid-id `#` remains rejected (the charset contract is unchanged).
2026-07-06T06:24:02.6627272Z - Required stages: 
2026-07-06T06:24:02.6627301Z 
2026-07-06T06:24:02.6627381Z ### REQ-INST-1
2026-07-06T06:24:02.6627524Z - Title: endpoint ID vs instance split (adapter-agnostic ID)
2026-07-06T06:24:02.6627606Z - Required stages: 
2026-07-06T06:24:02.6627640Z 
2026-07-06T06:24:02.6627719Z ### REQ-INST-2
2026-07-06T06:24:02.6627820Z - Title: Per-node files, synced Psyche mind
2026-07-06T06:24:02.6627916Z - Required stages: impl, unit
2026-07-06T06:24:02.6627945Z 
2026-07-06T06:24:02.6628034Z ### REQ-INST-3
2026-07-06T06:24:02.6628158Z - Title: Dormant (warm) / suspended (cold) resting states
2026-07-06T06:24:02.6628250Z - Required stages: doc, impl, unit
2026-07-06T06:24:02.6628279Z 
2026-07-06T06:24:02.6628363Z ### REQ-INST-4
2026-07-06T06:24:02.6628514Z - Title: active to dormant/suspended fires a transition echo commune
2026-07-06T06:24:02.6628615Z - Required stages: impl, unit
2026-07-06T06:24:02.6628737Z 
2026-07-06T06:24:02.6628827Z ### REQ-INST-5
2026-07-06T06:24:02.6629066Z - Title: Two-tier context sync (live to all, project to same-project)
2026-07-06T06:24:02.6629156Z - Required stages: impl, unit, int
2026-07-06T06:24:02.6629189Z 
2026-07-06T06:24:02.6629295Z ### REQ-INST-6
2026-07-06T06:24:02.6629461Z - Title: Deferred messages not delivered to dormant/suspended instances
2026-07-06T06:24:02.6629562Z - Required stages: impl, unit, int
2026-07-06T06:24:02.6629591Z 
2026-07-06T06:24:02.6629671Z ### REQ-INST-7
2026-07-06T06:24:02.6629810Z - Title: Subnet registry + bare-id resolution policy
2026-07-06T06:24:02.6629891Z - Required stages: impl, unit, int
2026-07-06T06:24:02.6629919Z 
2026-07-06T06:24:02.6630000Z ### REQ-INST-8
2026-07-06T06:24:02.6630139Z - Title: Remote-control mode distinct from local operation
2026-07-06T06:24:02.6630239Z - Required stages: impl, unit, int
2026-07-06T06:24:02.6630272Z 
2026-07-06T06:24:02.6630363Z ### REQ-INST-9
2026-07-06T06:24:02.6630530Z - Title: Multi-subnet membership (same-user N subnets; cross-user seam)
2026-07-06T06:24:02.6630629Z - Required stages: impl, unit
2026-07-06T06:24:02.6630653Z 
2026-07-06T06:24:02.6630734Z ### REQ-INST-10
2026-07-06T06:24:02.6630930Z - Title: Qualified addressing [subnet:]id[@node] + ambiguity forces qualification
2026-07-06T06:24:02.6631026Z - Required stages: impl, unit
2026-07-06T06:24:02.6631059Z 
2026-07-06T06:24:02.6631146Z ### REQ-INST-11
2026-07-06T06:24:02.6631334Z - Title: spt rename <id> rippled to all instances (collision-checked, 6.5-reconciled)
2026-07-06T06:24:02.6631425Z - Required stages: impl, unit
2026-07-06T06:24:02.6631459Z 
2026-07-06T06:24:02.6631548Z ### REQ-INST-12
2026-07-06T06:24:02.6631804Z - Title: Endpoint visibility per-(endpoint,subnet): excluded semantics, OR-of-defaults + override, gates sync
2026-07-06T06:24:02.6631909Z - Required stages: impl, unit
2026-07-06T06:24:02.6631943Z 
2026-07-06T06:24:02.6632023Z ### REQ-INST-13
2026-07-06T06:24:02.6632186Z - Title: Subnet-exclusive sync + per-endpoint subnet-membership list
2026-07-06T06:24:02.6632281Z - Required stages: impl, unit
2026-07-06T06:24:02.6632313Z 
2026-07-06T06:24:02.6632391Z ### REQ-INST-14
2026-07-06T06:24:02.6632735Z - Title: Resource advertisement (subnet resource registry): free-text blurb, both-authored, registry projection, visibility/whitelist-gated
2026-07-06T06:24:02.6632834Z - Required stages: doc, impl, unit
2026-07-06T06:24:02.6632867Z 
2026-07-06T06:24:02.6632957Z ### REQ-INST-15
2026-07-06T06:24:02.6633611Z - Title: Immutable home subnet (assigned at creation: auto-if-one/ask-if-many) + spt fork (cross-subnet clone to a new identity, copy-then-diverge, not re-home); adapter chosen at creation from registered hostable adapters, changed only via launch/resume-under-new (ADR-0010)
2026-07-06T06:24:02.6633712Z - Required stages: doc, impl, unit
2026-07-06T06:24:02.6633746Z 
2026-07-06T06:24:02.6633826Z ### REQ-REACH-1
2026-07-06T06:24:02.6633958Z - Title: Off-node remote-drive detection + file transfer
2026-07-06T06:24:02.6634175Z - Required stages: impl, unit, int
2026-07-06T06:24:02.6634208Z 
2026-07-06T06:24:02.6634299Z ### REQ-REACH-2
2026-07-06T06:24:02.6634444Z - Title: Remote command execution (deferred, consent-gated)
2026-07-06T06:24:02.6634523Z - Required stages: 
2026-07-06T06:24:02.6634556Z 
2026-07-06T06:24:02.6634633Z ### REQ-MSG-1
2026-07-06T06:24:02.6635029Z - Title: Local message delivery: TCP-first to a registered address, spool fallback when offline; id->address via registry (stale-clean first); reply routing (__REPLY_TO__)
2026-07-06T06:24:02.6635125Z - Required stages: impl, unit, int
2026-07-06T06:24:02.6635157Z 
2026-07-06T06:24:02.6635243Z ### REQ-MSG-2
2026-07-06T06:24:02.6635491Z - Title: spt binary CLI surface: send/ring/ready(+--once)/list/stop/whoami, stable arg shapes + exit codes
2026-07-06T06:24:02.6635587Z - Required stages: impl, unit
2026-07-06T06:24:02.6635621Z 
2026-07-06T06:24:02.6635692Z ### REQ-MSG-3
2026-07-06T06:24:02.6636044Z - Title: Ready-agent lifecycle: register perch (info.json + listener + registry address) on ready, drain spooled backlog on startup, clean teardown
2026-07-06T06:24:02.6636250Z - Required stages: impl, unit, int
2026-07-06T06:24:02.6636279Z 
2026-07-06T06:24:02.6636368Z ### REQ-MSG-4
2026-07-06T06:24:02.6637130Z - Title: Listener stream stdout emits EVENT envelope lines (sister-format, ADR-0001): parse the __REPLY_TO__ frame, pass pre-formed typed envelopes through verbatim (no double-wrap), compose <EVENT type="msg" from=…> otherwise, chunk oversized lines into EVENT-PART
2026-07-06T06:24:02.6637236Z - Required stages: impl, unit, int
2026-07-06T06:24:02.6637260Z 
2026-07-06T06:24:02.6637350Z ### REQ-MSG-ENVELOPE
2026-07-06T06:24:02.6640984Z - Title: The <EVENT type="msg" from=…>body</EVENT> envelope (spt-proto::event, the ADR-0001 grammar) is the SOLE canonical arriving-message format at EVERY harness arriving-message surface on an AGENT perch — api listen AND api poll/worker-poll, byte-identical (reverses REQ-MSG-4's 'hook drains keep the raw frame by contract'). SCOPE CARVE-OUT: the shell-command relay (api poll <shell-id> --link, cmd_poll_shell) is a distinct internal transport carrying RAW MAC'd stamped frames the shell child consumes verbatim — NOT an arriving-message surface, deliberately EXEMPT from <EVENT> composition (notify_shell_e2e guards this boundary). __REPLY_TO__ — mis-elevated during the clean-room port to a fake ADR-0001 'stable wire format' (spt-msg/wire.rs, lib.rs) — is REMOVED entirely (spool format_row, the spt-msg TCP frame, emit parse_frame); (from, body) carried structurally, <EVENT> composed once at the delivery boundary. No legacy sister-interop (spt-core never required it). Reply-correlation rebinds onto the structural from / <EVENT from=…> attribute (ADR-0009 access-gate + ADR-0012 Psyche/spt-live reply-target). Self-delimiting by construction → finding F-002 (non-self-delimiting multi-message poll) dissolves. ADR-0020.
2026-07-06T06:24:02.6641109Z - Required stages: doc, impl, unit, int
2026-07-06T06:24:02.6641147Z 
2026-07-06T06:24:02.6641233Z ### REQ-MSG-5
2026-07-06T06:24:02.6641904Z - Title: user-msg envelope kind + daemon identity gate: a Gateway endpoint / the local user's CLI author user-msg (the user's authority); agent-family senders re-stamped to plain msg; identity-gated never payload-trusted (KH 7.3/7.5); wire-additive (N-1 receivers tolerate the new type)
2026-07-06T06:24:02.6642009Z - Required stages: doc, impl, unit
2026-07-06T06:24:02.6642042Z 
2026-07-06T06:24:02.6642126Z ### REQ-MSG-6
2026-07-06T06:24:02.6643629Z - Title: cross-node Gateway user-msg honored via advertised endpoint_type: a user-msg from a Gateway-typed origin survives the receive_wan funnel as user-msg (vs the fail-closed re-stamp), keyed on the QUIC-handshake-proven origin node (never wire `from`). Trust boundary = subnet membership (operator-ratified 2026-06-13); no defense against an in-subnet member forging the type. Instance.endpoint_type is an additive serde-default field extending REQ-INST-7's data model. Absent/unknown type → re-stamp (N-1 rollout grace)
2026-07-06T06:24:02.6643842Z - Required stages: doc, impl, unit
2026-07-06T06:24:02.6643871Z 
2026-07-06T06:24:02.6643962Z ### REQ-NODE-IDENTITY
2026-07-06T06:24:02.6644171Z - Title: Ed25519 identity primitive: keypair, detached sign/verify, stable pubkey<->hex
2026-07-06T06:24:02.6644272Z - Required stages: impl, unit
2026-07-06T06:24:02.6644301Z 
2026-07-06T06:24:02.6644376Z ### REQ-NET-1
2026-07-06T06:24:02.6644532Z - Title: WAN messaging first-class, behind default-on net feature flag
2026-07-06T06:24:02.6644633Z - Required stages: impl, unit, int
2026-07-06T06:24:02.6644661Z 
2026-07-06T06:24:02.6644736Z ### REQ-NET-2
2026-07-06T06:24:02.6644893Z - Title: n0 relay default + self-host knob + plain-language disclosure
2026-07-06T06:24:02.6644994Z - Required stages: impl
2026-07-06T06:24:02.6645022Z 
2026-07-06T06:24:02.6645102Z ### REQ-NET-3
2026-07-06T06:24:02.6645256Z - Title: Cross-node Psyche sync over P2P replaces gh-repo-sync
2026-07-06T06:24:02.6645351Z - Required stages: impl, unit
2026-07-06T06:24:02.6645479Z 
2026-07-06T06:24:02.6645561Z ### REQ-PAIR-1
2026-07-06T06:24:02.6645661Z - Title: TOTP-seeded SPAKE2 pairing
2026-07-06T06:24:02.6645750Z - Required stages: impl, unit, int
2026-07-06T06:24:02.6645779Z 
2026-07-06T06:24:02.6645866Z ### REQ-PAIR-2
2026-07-06T06:24:02.6645989Z - Title: Local trust store with TOFU + warn-on-change
2026-07-06T06:24:02.6646084Z - Required stages: 
2026-07-06T06:24:02.6646114Z 
2026-07-06T06:24:02.6646195Z ### REQ-PAIR-3
2026-07-06T06:24:02.6646328Z - Title: Fetch current pairing code from any paired node
2026-07-06T06:24:02.6646414Z - Required stages: impl, unit
2026-07-06T06:24:02.6646452Z 
2026-07-06T06:24:02.6646534Z ### REQ-PAIR-4
2026-07-06T06:24:02.6646642Z - Title: Subnet naming on first pairing
2026-07-06T06:24:02.6646724Z - Required stages: impl, unit
2026-07-06T06:24:02.6646757Z 
2026-07-06T06:24:02.6646844Z ### REQ-PAIR-5
2026-07-06T06:24:02.6647121Z - Title: Multi-subnet pairing: subnet-name discovery input, create-new-names-up-front, rendezvous-token hashing
2026-07-06T06:24:02.6647220Z - Required stages: impl, unit, int
2026-07-06T06:24:02.6647253Z 
2026-07-06T06:24:02.6647333Z ### REQ-PAIR-6
2026-07-06T06:24:02.6647573Z - Title: Elevation-gated per-subnet code fetch (UAC/root or elevated agent; else authenticator app)
2026-07-06T06:24:02.6647657Z - Required stages: impl, unit
2026-07-06T06:24:02.6647695Z 
2026-07-06T06:24:02.6647781Z ### REQ-PAIR-7
2026-07-06T06:24:02.6647929Z - Title: Subnet icon (inline image metadata, GUI-only consumer)
2026-07-06T06:24:02.6648019Z - Required stages: 
2026-07-06T06:24:02.6648048Z 
2026-07-06T06:24:02.6648130Z ### REQ-SUBNET-1
2026-07-06T06:24:02.6648421Z - Title: spt subnet noun namespace: status view (bare + status [NAME] [--nodes]), create (QR/otpauth), show-code; spt pair deleted
2026-07-06T06:24:02.6648525Z - Required stages: impl, unit
2026-07-06T06:24:02.6648559Z 
2026-07-06T06:24:02.6648639Z ### REQ-SUBNET-2
2026-07-06T06:24:02.6648854Z - Title: Guided join e2e: spt subnet join CLI initiator + always-on daemon pairing responder
2026-07-06T06:24:02.6649022Z - Required stages: impl, unit, int
2026-07-06T06:24:02.6649060Z 
2026-07-06T06:24:02.6649145Z ### REQ-SUBNET-3
2026-07-06T06:24:02.6649394Z - Title: Node labels: hostname-default, gossiped, addressable in @node qualifiers (refuse-on-ambiguity)
2026-07-06T06:24:02.6649492Z - Required stages: impl, unit
2026-07-06T06:24:02.6649521Z 
2026-07-06T06:24:02.6649616Z ### REQ-SUBNET-4
2026-07-06T06:24:02.6649862Z - Title: Subnet membership mutations elevation-gated (create = seed reveal; join = trust-boundary enrollment)
2026-07-06T06:24:02.6649971Z - Required stages: impl, unit
2026-07-06T06:24:02.6649995Z 
2026-07-06T06:24:02.6650077Z ### REQ-DOCS-6
2026-07-06T06:24:02.6650368Z - Title: spt how-to <topic>: in-binary task-oriented agent instructions (anti-drift; quickstart prompts point agents at it)
2026-07-06T06:24:02.6650467Z - Required stages: impl, unit, int
2026-07-06T06:24:02.6650500Z 
2026-07-06T06:24:02.6650692Z ### REQ-SEC-1
2026-07-06T06:24:02.6651059Z - Title: Per-endpoint access whitelist: origin-node gate, stateful-firewall (reply/outbound exempt), node-now/user-later, outer gate before grants
2026-07-06T06:24:02.6651144Z - Required stages: impl, unit
2026-07-06T06:24:02.6651168Z 
2026-07-06T06:24:02.6651254Z ### REQ-NOTIF-1
2026-07-06T06:24:02.6651584Z - Title: Notification primitive: per-subnet replicated spool, seen/dismissed, resurface-at-boundary, subsumes update+consent prompts
2026-07-06T06:24:02.6651683Z - Required stages: impl, unit, int
2026-07-06T06:24:02.6651716Z 
2026-07-06T06:24:02.6651802Z ### REQ-NOTIF-2
2026-07-06T06:24:02.6652040Z - Title: spt notify (agent-issued subnet notif) + notif_command manifest seam (harness + shell adapters)
2026-07-06T06:24:02.6652146Z - Required stages: doc, impl, unit, int
2026-07-06T06:24:02.6652174Z 
2026-07-06T06:24:02.6652252Z ### REQ-UPD-1
2026-07-06T06:24:02.6652360Z - Title: Peer-propagated update over P2P
2026-07-06T06:24:02.6652454Z - Required stages: impl, unit, int
2026-07-06T06:24:02.6652574Z 
2026-07-06T06:24:02.6652649Z ### REQ-UPD-2
2026-07-06T06:24:02.6652776Z - Title: All binaries signature-verified before handoff
2026-07-06T06:24:02.6652872Z - Required stages: impl, unit
2026-07-06T06:24:02.6652901Z 
2026-07-06T06:24:02.6652982Z ### REQ-UPD-3
2026-07-06T06:24:02.6653138Z - Title: No endpoint process terminates/suspends during self-update
2026-07-06T06:24:02.6653240Z - Required stages: impl, unit, int
2026-07-06T06:24:02.6653268Z 
2026-07-06T06:24:02.6653349Z ### REQ-UPD-4
2026-07-06T06:24:02.6653521Z - Title: Update gated on user confirmation by default; opt-in full-auto
2026-07-06T06:24:02.6653602Z - Required stages: impl, unit
2026-07-06T06:24:02.6653635Z 
2026-07-06T06:24:02.6653720Z ### REQ-UPD-5
2026-07-06T06:24:02.6653850Z - Title: spt-core ripple-updates registered adapters
2026-07-06T06:24:02.6653940Z - Required stages: impl, unit
2026-07-06T06:24:02.6653973Z 
2026-07-06T06:24:02.6654054Z ### REQ-UPD-6
2026-07-06T06:24:02.6654833Z - Title: Platform-targeted update sets and debug rollout: signed multi-platform update metadata, recipient platform selection, channel-scoped monotonic counters, debug-channel opt-in via release-key overlay, local staging plus pull-based peer propagation, and maintainer-only convergence tooling (ADR-0016)
2026-07-06T06:24:02.6654941Z - Required stages: doc, impl, unit, int
2026-07-06T06:24:02.6654969Z 
2026-07-06T06:24:02.6655054Z ### REQ-UPD-7
2026-07-06T06:24:02.6656998Z - Title: Origin-source update bootstrap (`spt update fetch`): pull the latest signed release directly from the GitHub release origin (`SaberMage/spt-releases`) — the per-platform artifact + its `<asset>.release.json` SignedRelease metadata — and stage it through the EXISTING verify→stage pipeline (the same `plan_verified` gate: two-key signature + channel + monotonic rollback floor + SHA-256), after which the normal consent-notif / `spt update apply` flow is unchanged. Closes the peer-only-discovery gap (REQ-UPD-1): a first-in-fleet / isolated node can update with no peer to pull from. The signed-release anchor keeps the GitHub transport untrusted-but-verified.
2026-07-06T06:24:02.6657108Z - Required stages: impl, unit
2026-07-06T06:24:02.6657141Z 
2026-07-06T06:24:02.6657217Z ### REQ-UPD-8
2026-07-06T06:24:02.6659710Z - Title: Platform-safe `spt update fetch` + apply platform-guard (v0.3.1 cross-OS brick fix): `spt update fetch` stages the signed multi-platform `SignedUpdateSet` (`update-set.json` + every platform artifact it names), never a platform-blind single `SignedRelease`, so local apply selects `current_platform()` and P2P re-serve lets each peer select ITS own platform. Defense-in-depth: `apply_staged` REFUSES a staged single-release artifact unless it is platform-stamped for THIS node (an unstamped pre-v0.3.2 single, or a single stamped for another OS, fail-safe refuses — the guard that alone prevents the v0.3.1 brick where a Linux ELF was applied as `spt.exe`). UX: a friendly post-apply message (`Updated spt-core to vX.Y.Z.` + changelog URL) driven by an additive `product_version` metadata field, with a release-counter fallback when absent.
2026-07-06T06:24:02.6659911Z - Required stages: impl, unit
2026-07-06T06:24:02.6659945Z 
2026-07-06T06:24:02.6660020Z ### REQ-UPD-9
2026-07-06T06:24:02.6662497Z - Title: `gh_release` adapter [update] avenue (optional signing): an adapter declares `[update] avenue = "gh_release", repo = "user/repo"` (+ optional `asset`, default `adapter.spt`; + optional Ed25519 `signing_key`); spt-core's ripple compares the repo's LATEST GitHub release version against the installed adapter version and, when newer, auto-updates by fetching the release `.spt` archive (the REQ-INSTALL-9 `--release` fetch primitive) → verifies the `.spt` against `signing_key` if declared, else HTTPS+GitHub first-acquisition trust → re-extracts + re-registers the adapter root. Lets a harness adapter ship updates from its own GitHub releases with NO signing tooling or plugin coupling (removes the perri file_pull/delegated avenue blockers). Acquisition-trust mirrors `--release` + the installer first-fetch; does not alter spt-core self-update (REQ-UPD-1..8).
2026-07-06T06:24:02.6662701Z - Required stages: doc, impl, unit
2026-07-06T06:24:02.6662735Z 
2026-07-06T06:24:02.6662817Z ### REQ-TERM-1
2026-07-06T06:24:02.6662963Z - Title: Process-supervisor terminal wrapper hosting broker PTYs
2026-07-06T06:24:02.6663047Z - Required stages: impl, unit
2026-07-06T06:24:02.6663081Z 
2026-07-06T06:24:02.6663167Z ### REQ-TERM-2
2026-07-06T06:24:02.6663322Z - Title: session-surface abstraction; send-keys + send-line injection
2026-07-06T06:24:02.6663413Z - Required stages: impl, unit
2026-07-06T06:24:02.6663441Z 
2026-07-06T06:24:02.6663523Z ### REQ-TERM-3
2026-07-06T06:24:02.6663646Z - Title: Byte-stream remote terminal streaming for v1
2026-07-06T06:24:02.6663742Z - Required stages: impl, unit
2026-07-06T06:24:02.6663776Z 
2026-07-06T06:24:02.6663857Z ### REQ-TERM-4
2026-07-06T06:24:02.6664304Z - Title: Live activity buffer (session digest): projection of normalized session logs, snapshot-pull (spt endpoint digest) + structured-delta-stream contract + api digest-entry push
2026-07-06T06:24:02.6664410Z - Required stages: impl, unit, int
2026-07-06T06:24:02.6664439Z 
2026-07-06T06:24:02.6664529Z ### REQ-TERM-5
2026-07-06T06:24:02.6665989Z - Title: Adapter-declared digest extractor seam: a `[digest]` manifest section declaring an imperative extractor (native harness log -> the {role,text,tool,ts} contract; defaults to the [history] source files with an own-source escape hatch), `api digest-entry` push fallback, register-time validation of the section, adapter-declared presentation defaults (window depth, arg-truncation, sprint-collapse) that any consumer may override, and a `spt adapter digest-proof` author tool plus runtime skip-diagnostics (no silent drop). Reverses M9's no-manifest-seam stance; no declarative DSL.
2026-07-06T06:24:02.6666090Z - Required stages: doc, impl, unit, int
2026-07-06T06:24:02.6666124Z 
2026-07-06T06:24:02.6666208Z ### REQ-TERM-6
2026-07-06T06:24:02.6667234Z - Title: Thread-spanning digest across session boundaries: a per-endpoint session ledger (`<perch>/sessions.log`) appended at first bind and by `api boundary` on `/clear`|`/compact` session rotation, the digest enumerating the last K sessions so its rolling window bridges a boundary, and a distinctive in-timeline boundary marker (DigestEntry::Boundary). The digest follows the live-agent thread, not a single session.
2026-07-06T06:24:02.6667339Z - Required stages: impl, unit, int
2026-07-06T06:24:02.6667372Z 
2026-07-06T06:24:02.6667463Z ### REQ-TERM-7
2026-07-06T06:24:02.6668573Z - Title: Two-origin digest merge: spt-owned context-injection entries (psyche_download | echo_mirror | owl_message) appended by spt to the endpoint `digest.log`, timestamp-interleaved with the adapter's extracted activity records into one ordered timeline, via a distinct context-injection record category. Data model only this milestone; GUI collapse/expand and the echo-reads-digest delta loop are deferred to the surfaces that consume them.
2026-07-06T06:24:02.6668767Z - Required stages: impl, unit, int
2026-07-06T06:24:02.6668796Z 
2026-07-06T06:24:02.6668888Z ### REQ-FRONT-1
2026-07-06T06:24:02.6669130Z - Title: Day-one launcher/manager frontend (list/launch/attach/init)
2026-07-06T06:24:02.6669226Z - Required stages: 
2026-07-06T06:24:02.6669265Z 
2026-07-06T06:24:02.6669341Z ### REQ-HOST-RUN-1
2026-07-06T06:24:02.6671644Z - Title: spt-hosted harness bringup: `spt endpoint run` spawns an adapter's `[session.self]` command template into a broker-held PTY (the spawn-session seam, brain.rs spawn_session_pid — same broker path shellhost.rs launch_shell_brokered_in uses for shells, now for kind="harness" self-role), registers the perch under the given endpoint id, returns the id. Reverses today's harness-hosted-only launch (external launcher → `api bind`). Non-interactive flag set (--adapter <a[:profile]> --id <id> --create --resume <session> --attach|--start|--view) covers every terminal action of the W2 interactive picker so shortcuts (cc-<id>) bake fully non-interactive launches; composite adapter:profile resolves via registry::resolve_option leaf-replace overlay.
2026-07-06T06:24:02.6671854Z - Required stages: impl, unit, int
2026-07-06T06:24:02.6671883Z 
2026-07-06T06:24:02.6671963Z ### REQ-RC-1
2026-07-06T06:24:02.6677665Z - Title: `spt rc <id>` — user CLI attaching a local terminal to a broker-held PTY, reusing the cross-node attach machinery (attach.rs request_attach → send_attach_input pump, spt-net AttachRecord codec); local attach is the degenerate single-node case of the cross-node path (rides REQ-TERM-3 byte-stream streaming). Read-only `--view` (watch, no stdin forwarded). Clean detach that does NOT terminate the broker-held session (KNOWN-HAZARDS: PTY ownership stays with the broker; no termination on detach). Explicit detach keybind that cannot collide with harness passthrough input (legacy capsule used a ctrl-b prefix); documented. ConPTY DSR auto-answer in the attach reader (hazard 5.5).
2026-07-06T06:24:02.6677798Z - Required stages: impl, unit, int
2026-07-06T06:24:02.6677827Z 
2026-07-06T06:24:02.6677923Z ### REQ-HOST-RUN-2
2026-07-06T06:24:02.6679652Z - Title: Project-scoped working directory for spt-hosted bringup: `spt endpoint run` lands the broker-spawned harness PTY in the user's PROJECT cwd, not the daemon's, via an additive `SpawnReq.cwd` field carried through the broker PTY spawn (portable-pty CommandBuilder cwd). N-1-safe wire change (additive, defaulted). Required because the consumer (Claude Code) is project-scoped: broker-inherited cwd = the daemon's cwd = the wrong `.claude`, wrong session history, wrong digest source; `cc <id>` at a project root MUST land the harness in that project. W1 ships broker-inherited cwd as a bringup-proof shortcut only; this REQ must land before the M12 gate (doyle, 2026-06-14).
2026-07-06T06:24:02.6679753Z - Required stages: impl, unit, int
2026-07-06T06:24:02.6679777Z 
2026-07-06T06:24:02.6679877Z ### REQ-RUN-PICKER
2026-07-06T06:24:02.6684557Z - Title: Interactive `spt endpoint run` picker (ratatui TUI): bare `spt endpoint run` (no --adapter/--id) enters an in-process picker (flags-present = the REQ-HOST-RUN-1 non-interactive path, untouched). Layer 1 picks kind (Create new | Pick existing). Create-new: choose a registered kind="harness" adapter with its shipped+local profiles tree-nested (registry::registered / manifest.profiles / local_profile_names) → enter a charset-validated id → start. Pick-existing: category select (left/right) over [<cwd-project> | Local node | Subnet], endpoints grouped + alphabetically sorted per category, a status square per endpoint (online green ■ / offline gray ▢ — the blue "attached" tri-state + Kick are DEFERRED to a broker attach-presence slice, M12-W2-RULING Q1), type-to-filter (`/`, nucleo-matcher), a pinned keybind legend, and a right-half two-pane description (harness adapter:profile · best-effort project history newest→oldest from the contextstore p-<project> branches, empty-if-none · `spt endpoint description`). Confirm layer offers status-dependent options — Attach/Start/View (rc pump / cmd_endpoint_run) · Instantiate-locally (remote) · Change-harness-adapter (offline) · Fork (cmd_fork) · Resume-from-history (offline+LOCAL only; enumerate spt_store::sessions::last_k, titles `<project> @ <ts> (…id5)`, feed session_id → cmd_endpoint_run --resume). A single action enum is the source of truth so a future tap-mode (phone PTY) layers on without re-coupling to keybinds. EVERY terminal action routes through cmd_endpoint_run / existing CLI fns — no second bringup path.
2026-07-06T06:24:02.6684828Z - Required stages: doc, impl, unit
2026-07-06T06:24:02.6684852Z 
2026-07-06T06:24:02.6684939Z ### REQ-RUN-SHORTCUT
2026-07-06T06:24:02.6689621Z - Title: `<basename>-<id>` launcher shortcut generation (picker `s` keybind, M12-W2-T2.4): from any pre-start options set the picker writes/updates a `<basename>-<id>` launcher at the project root baking the current selection's non-interactive `spt endpoint run` flags (terminal actions only: adapter[:profile] + id + (create|resume) + (start|attach|view); Kick/Instantiate/Change-adapter/Fork are interactive-only, not bakeable). BASENAME IS A PARAMETER (operator rev. 2026-06-14): harness-agnostic spt-core defaults to `spt` (→ `spt-<id>`); an adapter/flow OVERRIDES it (spt-claude-code → `cc`), so spt-core NEVER bakes `cc` (a harness name) into itself. The basename must be a DISTINCT token, never bare `spt` (a `spt.cmd` would shadow the real `spt.exe` only under cmd.exe cwd-first search, silently no-op in PowerShell/Unix, and self-recurse). The script is the CURRENT OS's native form — `.cmd` on Windows (NOT `.ps1`: default PATHEXT excludes `.ps1` so a bare/ext-less name never resolves one; `.cmd` is PATHEXT-resolvable), POSIX `sh` (+chmod +x) on Unix (a single portable form can't be both). The generated header documents the invocation reality (cmd.exe bare `<name>` in the project dir / PowerShell `.\<name>` / Unix `./<name>`; a truly-bare basename on PATH = a PATH-installed launcher, `/spt:setup`'s job). Overwrite is SENTINEL-guarded: the generator writes + checks a generated-by header marker — it overwrites its own prior output freely, but REFUSES + warns if a same-named file lacks the sentinel (never clobber a user file). Requires the additive `--create` flag on `Run{}` (the default-fresh made explicit; N-1-safe).
2026-07-06T06:24:02.6689836Z - Required stages: doc, impl, unit
2026-07-06T06:24:02.6689869Z 
2026-07-06T06:24:02.6689955Z ### REQ-RUN-PICKER-HOME
2026-07-06T06:24:02.6693375Z - Title: Home-subnet selection LAYER in the `spt endpoint run` ratatui Create-new picker (v0.14.1; the deferred half of REQ-RUN-MULTISUBNET-HOME's interactive path — ADR-0026 §3 'the interactive picker lists subnets MRU-ordered'). On a MULTI-SUBNET node the Create-new flow gains a `CreateHome` screen (CreateAdapter → CreateId → CreateHome → Confirm) that lists the node's MEMBER subnets MRU-ordered (reusing recent_home::mru_preference + order_by_mru), default cursor = MRU head; the chosen subnet rides Outcome::Run{subnet} into cmd_endpoint_run's --subnet, so decide_run_home resolves Home directly and the post-TUI `Ok to proceed? Y/n` confirm NEVER fires for the picker path. Single-subnet / local-only nodes SKIP the layer (assign_home auto-homes; CreateId → Confirm unchanged). The CLI / flagged `endpoint run` path KEEPS the decide_run_home Y/n confirm + the non-interactive MULTI_SUBNET_HOME refuse (operator: the confirm stays useful for CLI-only bringup, just not in the TUI). Esc backs CreateHome → CreateId; Enter selects → Confirm. Pure front-end invariant preserved: the layer only collects --subnet, routes through the one bringup core.
2026-07-06T06:24:02.6693494Z - Required stages: doc, impl, unit
2026-07-06T06:24:02.6693524Z 
2026-07-06T06:24:02.6693609Z ### REQ-ELEVATE-1
2026-07-06T06:24:02.6696890Z - Title: Cross-platform self-elevating re-launch for privilege-gated commands: a pure decision seam `decide_elevation_path(os, elevation, interactive_tty, has_display, has_pkexec, has_term_emulator) -> ElevatePath{AlreadyElevated, InlineSudo, UacWindow, Pkexec, TerminalEmulator, PrintHint}` selecting how to re-acquire privilege, and the per-OS impure launchers it dispatches — Windows UAC console (ShellExecuteW `runas` on the abs-exe + verbatim argv; the elevated child does the work, prints 'You can close this window', and pauses for a keypress; the original prints 'Elevated terminal launched…' and exits 0; NEVER pipes the child's stdout back across the privilege boundary), Linux desktop pkexec (preferred, native polkit GUI auth) else x-terminal-emulator -e sudo (fallback list x-terminal-emulator→gnome-terminal→konsole→xterm), the existing interactive-TTY inline sudo, and the headless/no-path floor that prints the absolute-path command. Reused by every gated command (not subnet-specific). Generalizes should_auto_elevate.
2026-07-06T06:24:02.6697102Z - Required stages: doc, impl, unit
2026-07-06T06:24:02.6697134Z 
2026-07-06T06:24:02.6697224Z ### REQ-WHOAMI-1
2026-07-06T06:24:02.6698771Z - Title: `spt whoami` is a thin ALIAS for `spt endpoint list` (full output: the SELF pin + the subnet roster) — the standalone bare-id command is dropped (the `id=$(spt whoami)` capture was never a real pattern: env vars don't persist between agent tool calls). The one new render: the `endpoint list` SELF pin carries the Self endpoint's authored `endpoint description` (info::read_info(...).resources) when present, inline after the liveness state. whoami stays a top-level hot-path verb (parse unchanged, REQ-MSG-9).
2026-07-06T06:24:02.6699029Z - Required stages: doc, impl, unit
2026-07-06T06:24:02.6699052Z 
2026-07-06T06:24:02.6699138Z ### REQ-RCVIEW-1
2026-07-06T06:24:02.6703469Z - Title: Remote-attach controller/viewer model (CONTEXT.md:317): a session's broker OutputLog serves ONE interactive controller (input + EXCLUSIVE PTY resize; its viewport sets the size, sent on attach + every window change via crossterm Event::Resize) plus ANY NUMBER of read-only `--view` attachers (output-only, no input, no resize; client-side letterbox — center+pad when larger, clip+1-line indicator when smaller; only the local ctrl-b d detach chord). Attach intent is three-valued (`Viewer | Control | Take`, wire-default Control): Control to a FREE endpoint becomes controller, Control to a CONTROLLED endpoint is REFUSED with guidance (`--view`/`--take`) — never auto-viewer, never silent-displace. Wire adds (additive, N-1 skip-unknown): `Request.intent`, `Resize{rows,cols}` (controller-only), `Size{rows,cols}` (→viewer), `Displaced{by}` (→displaced controller). The brain-resume cursor (delivered_through, ADR-0018) tracks the CONTROLLER ONLY; viewers replay from their own from_seq and never move it. Dormancy keys on the controller ONLY: controller attach wakes / controller detach goes dormant (even with viewers present); viewer attach/detach is wake-neutral and may watch a dormant endpoint as-is. v1: viewing is gated identically to driving — a viewer runs the same access_check(Unsolicited) as a controller (watching reveals full session contents = a real disclosure); a lighter distinct watch-gate is deferred to cross-subnet/finer-consent (CONTEXT.md:317 'driving ≠ watching' = the future seam).
2026-07-06T06:24:02.6703588Z - Required stages: doc, impl, unit, int
2026-07-06T06:24:02.6703620Z 
2026-07-06T06:24:02.6703706Z ### REQ-KICK-1
2026-07-06T06:24:02.6706106Z - Title: Explicit, loud controller displacement: `spt rc kick <target>` / `--take` (Take intent) kicks the incumbent controller and becomes controller; the displaced controller receives a LOUD `Displaced{by}` notice and is FULLY DETACHED (not demoted to a viewer). A default attach to a controlled endpoint is NEVER a silent displace (it is the Control busy-refusal). An old (N-1) rc omits intent → Control, so it can drive a free endpoint but CANNOT `--take` — it can never silently steal, and gets a clean busy-refusal instead. Taking control rides the same access_check(endpoint, origin, Unsolicited) as a normal control attach (if you may drive, you may take — no elevated kick policy). The picker surfaces 'Kick <node> and attach' (Take) only on a controlled (blue ■) endpoint, via the existing attach dispatch (single-bringup-path: intent is a parameter).
2026-07-06T06:24:02.6706317Z - Required stages: doc, impl, unit, int
2026-07-06T06:24:02.6706345Z 
2026-07-06T06:24:02.6706430Z ### REQ-PICKER-1
2026-07-06T06:24:02.6710013Z - Title: The picker renders a FOUR-state endpoint status (extending the W2 online/offline duality): the list-item square AND a color-coded STATUS line at the top of the pick-existing right-side details both show — gray OFFLINE; green ONLINE (online + PTY-controllable spt-hosted, not controlled); amber 'ONLINE - HARNESS ONLY' (online but NOT broker-PTY-controllable = harness-hosted, no broker PTY seat — today mis-shows green); blue 'ONLINE + CONTROLLED' (online + driven_by.is_some()). Derived on EndpointRow from {offline | controllable | driven_by} with precedence offline→gray, else driven_by→blue, else !controllable→amber, else green (driven_by outranks harness-only; mutually exclusive in practice — a harness-only endpoint has no broker PTY to control). The controllable discriminator is a NEW InfoJson.controllable: Option<bool> (serde-default, N-1-safe), stamped at the establish seam — cmd_listen (harness-hosted relay, no broker PTY) → Some(false); cmd_bind live_agent (spt-hosted broker PTY) → Some(true); absent → not-controllable (amber) default (harness-hosted is the common mis-reported case; one bind self-corrects). Store-projection-only (no live daemon query — doyle ruling). (v0.10.0)
2026-07-06T06:24:02.6710242Z - Required stages: impl, unit
2026-07-06T06:24:02.6710270Z 
2026-07-06T06:24:02.6710351Z ### REQ-PICKER-2
2026-07-06T06:24:02.6712148Z - Title: The picker's project-history loader reads the git-backed context store, not the bare working tree: data.rs project_history_for enumerates an endpoint's projects via the BranchStore branch set (the context store keeps per-project context in git branches — contextstore::project_branch(project_id), checked out to projects/<project>/<id>/ only on-demand) instead of raw std::fs::read_dir over the empty working tree (which returned empty for ALL rows incl wall-a — the operator bug). Ordered newest→oldest by branch commit recency; degrades to empty (informational pane), never fails. (v0.10.0)
2026-07-06T06:24:02.6712258Z - Required stages: impl, unit
2026-07-06T06:24:02.6712286Z 
2026-07-06T06:24:02.6712368Z ### REQ-PICKER-3
2026-07-06T06:24:02.6714748Z - Title: A self-owned subnet row reconciles its status to the LIVE roster: a Subnet-category row whose endpoint_id overlaps a local (is_local) roster id is self-owned (this node hosts it), so its status square is OVERRIDDEN with the live roster status — the WAN registry snapshot (wansend::load_snapshots) is a periodically-advertised, independently-stale projection, while the local roster (p.alive) is ground truth for an endpoint this node hosts. One status square per endpoint (CONTEXT.md:348-350 — nothing licenses opposite squares for one endpoint across its Local vs Subnet listings). A reconcile pass in data.rs after the local_rows + subnet_rows gather; BOTH category listings are preserved (Local + Subnet are legitimately distinct views — you are in your own subnet), only the STATUS is unified. (v0.10.0)
2026-07-06T06:24:02.6714858Z - Required stages: impl, unit
2026-07-06T06:24:02.6714886Z 
2026-07-06T06:24:02.6714978Z ### REQ-PICKER-4
2026-07-06T06:24:02.6716823Z - Title: The picker's Subnet category renders the canonical node LABEL, not bare key-hex: a subnet row's node renders as 'LABEL (keyprefix…)' (e.g. 'HFENDULEAM (bcead52b…)') per CONTEXT.md:650 + Instance.node_label, NOT the raw node key-hex (SPT_DEV:14efb80cb… — a picker-only regression because resource_projection→ResourceRow drops node_label, so data.rs subnet_rows uses the raw row.node). Thread node_label into the picker subnet path (ResourceRow gains node_label, or subnet_rows looks it up via the registry's node_labels) and REUSE the one canonical render (format!("{l} ({}…)", key_prefix) — cli.rs / wansend.rs), never a re-implementation. (v0.10.0)
2026-07-06T06:24:02.6716929Z - Required stages: impl, unit
2026-07-06T06:24:02.6717058Z 
2026-07-06T06:24:02.6717153Z ### REQ-PICKER-5
2026-07-06T06:24:02.6720230Z - Title: `spt endpoint list` (bare/subnet view) renders an ALIGNED table with canonical node labels: cmd_endpoint_list prints subnet rows with `\t` TAB separators (cli.rs:~1651-1662) so variable-width endpoint_ids snap fields to different tab-stops → a RAGGED status column (operator screenshot: X/help statuses misaligned vs rt-*/sptc-*/wall-a); and it calls the node renderer with no label → bare key-hex for every row (SAME ResourceRow-drops-node_label root as REQ-PICKER-4). FIX: max-width per-column padding (mirror render_node_rows' pad, pad by char count not byte len — '…' is multibyte) replacing the tabs, and render the node via the shared node_label_display now that ResourceRow carries node_label (REQ-PICKER-4). Extract a pure row-formatter seam so the alignment+label is unit-testable. ALSO: the bare list is the SUBNET view (a just-run LOCAL perch is invisible cross-subnet until the next advertise tick), so emit a `--local` hint line so a freshly-run endpoint isn't perceived as lost. (v0.10.0; operator-flagged + doyle dispatch 2026-06-17)
2026-07-06T06:24:02.6720431Z - Required stages: impl, unit
2026-07-06T06:24:02.6720464Z 
2026-07-06T06:24:02.6720558Z ### REQ-SEND-SPT-HOSTED
2026-07-06T06:24:02.6724126Z - Title: An inbound `spt send` is DELIVERED to an spt-hosted endpoint (brought up via `spt endpoint run` → `api bind`, broker holds its PTY, NO `api listen` relay). Today cmd_bind→establish_perch (api/startup.rs ~441) writes info.json + ready marker + controllable=Some(true) but registers NO message-listener / NO address, so deliver.rs resolve_address→None→spool (deliver.rs:132-140) and the message NEVER reaches the live PTY — the endpoint reads 'online' (ready marker) yet `spt send` silently SPOOLS ('online but not deliverable' lie). Per CONTEXT:187-188 the daemon owns the PTY and delivers, manifest-configurable per activity-state (direct PTY injection / relay / HTTP). FIX: route an inbound send for an spt-hosted target through the daemon → broker InputReq → session.write_input PTY-inject (broker.rs dispatch_input/write_input ~988-1022), the same path the brain uses; the live-delivery handshake must report Sent (not Queued) and stop the spool-only fallback for a broker-hosted, PTY-resident endpoint. Detection is local: controllable==Some(true) + spt-hosted state + resolve_address==None. = the spt-core HALF of the wall-b finding (perri owns the adapter half: bind-hook fired-zero-perch + the missing endpoint-run int test). (post-v0.10.0)
2026-07-06T06:24:02.6724240Z - Required stages: impl, unit, int
2026-07-06T06:24:02.6724274Z 
2026-07-06T06:24:02.6724355Z ### REQ-HAZARD-RC-EOF
2026-07-06T06:24:02.6728147Z - Title: A severed broker stream during a live rc session surfaces GRACEFULLY, never as a raw io error that crashes the PTY. The rc read-loop (rc.rs:352-362) continues only on WouldBlock/TimedOut; ANY other read_event_until error — including UnexpectedEof 'failed to fill whole buffer' — returns Err → RC_FAIL → the PTY 'crashes' from the user's view. Confirmed trigger: a deliberate `spt daemon stop` (broker bounce) severs an active rc (perri stopped the daemon to release owlery watch handles). Same severed-broker-stream EOF class as the v0.9.1 seed fix (seed_fail_message) and the listener-death case — spt-core must classify a broker-gone EOF and (a) surface a CLEAR actionable message ('daemon stopped/restarted — re-run / reconnect'), never the raw buffer error, and ideally (b) AUTO-REATTACH to the same session on the fresh broker (the broker is the daemon-lifetime anchor; it returns on the next `spt api` call). FOLD two side-observations: (1) `spt daemon stop` SILENTLY drops active rc/live sessions — warn ('N active session(s) will drop') or graceful-detach on stop; (2) the daemon holds owlery WATCH HANDLES on perch dirs so a torn-down perch dir stays 'Device busy' until a full daemon stop releases them (perri's rt-* cleanup) — a torn-down perch's handle should release without a daemon stop. doyle Finding C, root-caused. (post-v0.10.0)
2026-07-06T06:24:02.6728357Z - Required stages: impl, unit
2026-07-06T06:24:02.6728386Z 
2026-07-06T06:24:02.6728486Z ### REQ-HAZARD-DEFERRED-MANIFEST
2026-07-06T06:24:02.6730823Z - Title: A pointer-mode (delegated / GhReleaseManaged) adapter whose binary/manifest is not yet extracted is reported with a CLEAR diagnostic, never silently dropped. Today such an adapter reads its manifest LIVE from source_dir (registry.rs manifest_dir ~146/149); a deferred / un-extracted install makes load_manifest fail → registered() (~410, filter_map(.ok())) SILENTLY DROPS the row → downstream ADAPTER_UNRESOLVED + a cryptic os-error-2 on `spt adapter use`. FIX: surface a clear diagnostic at the resolver + at `adapter use` (name the adapter + the deferred/missing-manifest cause + the fix), not a silent filter-drop and not a bare os-error-2; consider an eager manifest copy at register time so host_binaries survive before the binary download completes. doyle Finding A. (post-v0.10.0)
2026-07-06T06:24:02.6731029Z - Required stages: impl, unit
2026-07-06T06:24:02.6731062Z 
2026-07-06T06:24:02.6731157Z ### REQ-HAZARD-ENV-SUBST
2026-07-06T06:24:02.6734485Z - Title: `spt endpoint run` HONORS manifest [env.<VAR>] direction=inject values (with {key} substitution) on the spt-hosted spawn. Today only the [session.self] command ARGV is {id}-substituted; the [env] inject value is NEITHER substituted NOR applied — manifest.schema.json promises EnvVar.value = 'Value to inject (with substitution)' but prepare_harness_spawn fills only argv and SpawnReq carries no env, so a [env.SPT_ENDPOINT_ID].value='{id}' arrives EMPTY. A FLAGLESS harness (bare `claude`, no argv slot for {id}) then routes the id via [env] → empty → SessionStart sees empty $SPT_ENDPOINT_ID → seeds-by-PPID instead of binding → ZERO perch → NO_PERCH (the actual wall-b bind blocker; perri hard-repro'd). SILENT failure (empty inject, no error). FIX (doyle ruled a): fill every [env] inject value from the SAME {key} catalog as argv/role (mirror F-009 TEMPLATE fill, whole-string fill_template for an env value), thread it through SpawnReq.env → the broker sets it on the spawned PTY child. Correctness fix — schema already promises it, NO manifest change, NO new binary. PAIRS with REQ-SEND-SPT-HOSTED to make endpoint run fully work. doyle F-013. (post-v0.10.0)
2026-07-06T06:24:02.6734606Z - Required stages: impl, unit, int
2026-07-06T06:24:02.6734638Z 
2026-07-06T06:24:02.6734733Z ### REQ-HAZARD-ROSTER-GHOST
2026-07-06T06:24:02.6737097Z - Title: A LOCAL subnet roster entry whose backing perch is erased does NOT keep advertising Active (no phantom perch-less endpoint). `api session-end <id> --erase` removes the perch (owlery dir gone) but the subnet roster (identity/registry/<subnet>.json) keeps the endpoint's instance row ACTIVE with no backing perch; `endpoint stop` says 'address unregistered' yet the line persists; no CLI verb forgets a roster entry, and a hand-edit is re-added by the single-writer daemon advertiser. FIX: daemon-side self-heal — the advertiser DROPS/forgets a LOCAL roster entry whose backing perch no longer exists (stops advertising it Active), and/or a `forget`/evict verb; verify whether the epoch lease eventually evicts it (slow-self-heal) vs a real leak and scope accordingly. doyle secondary finding (perri). (post-v0.10.0)
2026-07-06T06:24:02.6737195Z - Required stages: impl, unit
2026-07-06T06:24:02.6737224Z 
2026-07-06T06:24:02.6737329Z ### REQ-WAN-SPT-HOSTED-DELIVERY
2026-07-06T06:24:02.6740917Z - Title: A WAN-ARRIVED `spt send` is DELIVERED to an spt-hosted endpoint (broker holds its PTY, NO api-listen relay), not spooled-forever. Today receive_wan (spt-daemon/wan.rs:271-276) tries deliver_tcp (the harness-hosted relay leg) then falls to spool — it has NO spt-hosted broker-inject leg, which exists ONLY in local cmd_send (REQ-SEND-SPT-HOSTED, Brain::inject_endpoint → KIND_ENDPOINT_INPUT → broker dispatch_endpoint_input → translation-binary idle-inject). So a WAN arrival to an idle spt-hosted perch with a live translation binary ALWAYS sleeps in spool until an adapter hook polls (F-023: perch verifiably idle 7min, binary healthy, zero injection). FIX: factor cmd_send's spt-hosted delivery leg into a SHARED fn; receive_wan calls it after the replay-check (wan_seen_at) + restamp (restamp_wan_user_msg), BEFORE the spool fallback. Claim discipline UNCHANGED: inject delivered=true → wan_mark_seen_at then return the existing 'delivered' wire token (no wire change); delivered=false → the existing spool-with-claim transaction. v0.14.3 LAW: the shared leg is translation-binary-ONLY, NO raw-PTY fallback — a no-binary arrival SPOOLS LOUD, never writes the PTY. (F-023, BUILD-F023-WANIDLE)
2026-07-06T06:24:02.6741135Z - Required stages: impl, unit, int
2026-07-06T06:24:02.6741168Z 
2026-07-06T06:24:02.6741265Z ### REQ-MSG-IDLE-EDGE-DRAIN
2026-07-06T06:24:02.6743632Z - Title: On an endpoint's ACTIVE→IDLE transition the daemon DRAINS its pending spool (deferred AND non-deferred) through the same shared spt-hosted inject leg — closing the SECOND F-023 gap: no idle-edge drain exists anywhere, so an spt-hosted endpoint (which has no api-listen relay to wake it) strands BOTH message classes ('ACTIVE → spool deferred for hook-poll' and 'IDLE+no-binary → non-deferred for a relay that does not exist'). FIX: on the state ACTIVE→IDLE edge, offer the pending spool through the shared inject leg; REUSE the hook-poll drain's take/ack machinery so a concurrent `api poll` cannot double-deliver — ONE drain path, TWO triggers (hook-poll + idle-edge). v0.14.3 LAW holds on BOTH triggers: translation-binary-ONLY, a no-binary idle drain SPOOLS LOUD, never writes the PTY. (F-023, BUILD-F023-WANIDLE)
2026-07-06T06:24:02.6743834Z - Required stages: impl, unit, int
2026-07-06T06:24:02.6743857Z 
2026-07-06T06:24:02.6743961Z ### REQ-HAZARD-DELIVERY-STARVATION
2026-07-06T06:24:02.6745971Z - Title: A message that has REACHED a node's spool (WAN-arrived or locally spooled-while-active) is NEVER dependent on an adapter HOOK-POLL cadence for its eventual delivery to an spt-hosted (relay-less) endpoint — the daemon itself drives delivery on the events it owns (WAN ingress + the ACTIVE→IDLE edge). Hazard class: delivery starvation. Without this, cross-node and post-active messages to an spt-hosted perch strand indefinitely whenever the adapter's hooks are quiet (idle session, no user turns), presenting as 'sent but never lands' with a healthy binary and an idle perch (F-023). Guarded by REQ-WAN-SPT-HOSTED-DELIVERY (WAN ingress leg) + REQ-MSG-IDLE-EDGE-DRAIN (idle-edge drain). (F-023)
2026-07-06T06:24:02.6746066Z - Required stages: doc, int
2026-07-06T06:24:02.6746100Z 
2026-07-06T06:24:02.6746195Z ### REQ-MSG-CLI-ORIGIN
2026-07-06T06:24:02.6748004Z - Title: A bare non-perch CLI `spt send` (no owning perch to name as origin) stamps from = `cli@<node-label>` at compose time (bare `cli` when no node label is known — never a dangling `cli@`), and WAN ingress renders an EMPTY from as the origin node DISPLAY (`node_label_display(origin_node, None)` = the QUIC-proven origin node's key-prefix; never blank) — a delivered message NEVER shows a blank sender. Scoped to `spt send`: a from-less send is LEGAL (stamped, never refused), while `spt ring` keeps its NO_SELF refusal (a ring needs a routable self for the reply leg; `cli@<node>` is a display origin, not a perch address). (F-024C item 3, doyle ruled)
2026-07-06T06:24:02.6748113Z - Required stages: impl, unit
2026-07-06T06:24:02.6748146Z 
2026-07-06T06:24:02.6748242Z ### REQ-HAZARD-SESSION-PIN-WEDGE
2026-07-06T06:24:02.6754879Z - Title: A perch PINNED to a DEAD session-id self-heals instead of wedging forever. authenticate() (spt/src/api/auth.rs:78) gates api poll/state/boundary on proof-sid == info.json.session_id; if ONE boundary rotation is lost (transient env corruption kills the /clear-era hook), the perch stays pinned to the dead sid and EVERY id-scoped hook call refuses — INCLUDING boundary itself (it presents the new sid), a permanent strand (ready:false, stale .idle, drain no-ops, WAN spool sleeps forever; AUTH_REFUSED is stderr-only = invisible inside a hook). FIX: authenticate() gains a DEAD-OWNER fallback — when the sid MISMATCHES AND the perch's recorded pid is dead (proc::is_process_alive==false), ACCEPT the caller's sid and RE-PIN (rotate session_id + log SESSION_REPIN loud). Same trust model as establish_perch's conflict gate (api/startup.rs:207-210), which already allows rebind exactly when owner_alive==false (an orphaned perch accepts a new LOCAL owner). A LIVE-owner mismatch STILL refuses (squat protection UNCHANGED). ADDITIVE to token auth — the existing token-auth recovery path is UNTOUCHED; the new branch fires only on (no token) AND (sid mismatch) AND (owner dead). COVERAGE SPLIT (explicit, perri clean-room 2026-07-02 — the wedge latches on /clear even in a CLEAN env, so the corruption domino was sufficient but NOT necessary): the dead-owner re-pin rescues CRASHED/DEAD sessions ONLY; a LIVE-pid rotation (/clear, /compact — same process, new sid) is CORRECTLY refused without the departed session's prior-sid proof and MUST NOT be widened to live owners. The live-rotation contract is adapter-side: the adapter PERSISTS the prior sid across rotation and PRESENTS it as boundary proof (perri's state-file pattern = the reference); a silent boundary skip on an unresolvable id, or a boundary call with NO auth proof, strands the perch (perri's court). Core rescues only the dead-owner orphan; live-rotation proof is the harness-contract's job (see the harness-contract boundary section, which cross-refs this hazard). PARKED (not this wave, logged): pid-ancestry self-proving rotation (core walks the caller's real ancestry vs info.json.pid) — needs an ADR + Windows parent-spoof caveats. (F-024C, F024C-AUTHWEDGE-ADDENDUM + F024D-DOCSCOPE)
2026-07-06T06:24:02.6755217Z - Required stages: doc, impl, unit
2026-07-06T06:24:02.6755250Z 
2026-07-06T06:24:02.6755360Z ### REQ-HAZARD-STORE-INIT-RACE
2026-07-06T06:24:02.6758311Z - Title: Concurrent first-touch of ONE fresh BranchStore must ALL succeed, never a hard error. BranchStore::open_or_init (spt-store/src/branchstore.rs:47) is a TOCTOU: it gates on HEAD.exists() then runs a NON-ATOMIC init (`git init --bare` + `git config core.autocrlf false` + best-effort worktree.useRelativePaths). Two processes that both observe !HEAD.exists() on one fresh store race the `git config` step, which takes git's per-repo config.lock — the loser fails with 'could not lock config file …/config: File exists', an io::Error that strands the caller (the G3-gate pump.rs:442 flake, doyle-ledgered). FIX: make init race-tolerant — `git init --bare` is idempotent, and `git config` is idempotent (same bytes), so tolerate a concurrent winner (open-after-lose: if init errors but HEAD now exists, proceed as opened) and retry a transient config.lock collision a bounded number of times so the required core.autocrlf=false is guaranteed set. N concurrent open_or_init on ONE fresh dir must ALL return Ok. (F-025 wave, doyle Item 2)
2026-07-06T06:24:02.6758429Z - Required stages: doc, impl, unit
2026-07-06T06:24:02.6758459Z 
2026-07-06T06:24:02.6758569Z ### REQ-HAZARD-SPOOL-SENTINEL-CREATE-FAIL
2026-07-06T06:24:02.6760467Z - Title: A persistent failure to (re)create the spool has-messages sentinel is SURFACED, never silently swallowed. touch_has_messages (spt-store/src/spool.rs:147) does `let _ = File::create(...)` — a live field defect on ENLYZEAM left a stale .has-messages (2026-06-29) beside a fresh spool.db insert (06:59:17Z) in ONE directory, i.e. the create silently failed while rows accumulated (suspected read-only-attrib / share-lock). FIX: on File::create failure emit a LOUD-ONCE-per-perch stderr diagnostic naming the concrete io::Error (self-identifying regardless of kind); do NOT make it fatal (spool writes still proceed). (F-024C item 2, doyle)
2026-07-06T06:24:02.6760580Z - Required stages: impl, unit
2026-07-06T06:24:02.6760608Z 
2026-07-06T06:24:02.6760708Z ### REQ-MANIFEST-NODE-KEY
2026-07-06T06:24:02.6764906Z - Title: A new session-scoped manifest fill key `{node}` resolves to THIS node's advertised label — available wherever the session-scoped keys ({id}/{session_id}/{session_name}) populate: BOTH topologies' spawn-prep catalogs (harnesshost.rs:111-118 self-spawn guaranteed-fill + lifecycle.rs:280 base lifecycle keys, at minimum [session.self] and [session.resume]) AND lazy [strings] eligibility (ADR-0029 family). VALUE (design-true per CONTEXT §node label / REQ-SUBNET-3): the node's ADVERTISED LABEL — the same value node_label_display renders — read from the label store (NodeLabel, registry.rs:118/220, OS-hostname default re-checked at daemon startup), NOT the pubkey and NOT a fresh gethostname at fill time when the store already holds the refreshed label; fall back to the OS hostname only if no label is known. perri's concrete use: templating `--remote-control {id}--{node}` in the claude-spt launch/resume commands. CAVEAT (documented in the manifest.md key-table row AND here): SINGLE-TOKEN fills only — tokenize-then-fill (REQ post-F-009) cannot produce a space-carrying argv element, so composite display names like `<id> @ <node>` remain adapter-shim territory (claude-spt v0.10.3's launch shim stays the reference for those); {node} COMPLEMENTS the shim for tokenizable args, it does not replace it. Origin: perri fill-catalog-gap finding 2026-07-02, operator-promoted into BUILD-F023-WANIDLE (additive, independent of the delivery legs). (NODEKEY-FOLD)
2026-07-06T06:24:02.6765221Z - Required stages: doc, impl, unit
2026-07-06T06:24:02.6765255Z 
2026-07-06T06:24:02.6765353Z ### REQ-HAZARD-HOSTED-LIVENESS-RECONCILE
2026-07-06T06:24:02.6769357Z - Title: B2 KEYSTONE: a daemon-hosted (spt-hosted) endpoint's info.json status is RECONCILED to real liveness, not left latched online. The broker exit-waiter (broker.rs:889-910) reaps its in-mem session table + emits ExitEvent but NEVER touches info.json; lifecycle::mark_offline only fires on Psyche teardown — so a dead/exited harness (operator closed the tab) stays status=online forever (is_perch_alive returns ONLINE for daemon-hosted, liveness.rs:80-93). FIX (doyle ruled PULL-PRIMARY — the live-status analog of REQ-HAZARD-ROSTER-GHOST): the livehost reconcile loop (reconcile_once livehost.rs:226-313) queries the broker's live session set (KIND_SESSIONS) each tick and, for any status=online live_agent perch PAST the boot grace whose endpoint has NO live broker session, marks it offline (lifecycle::mark_offline → status=offline → is_perch_alive=false). GATED on spt-hosted (controllable==Some(true)) so a HARNESS-HOSTED relay live agent (api listen, legitimately online with no broker session) is NEVER mis-marked. Crash-robust + self-healing on the next tick (clear-on-event is not crash-robust alone). PUSH (brain ExitEvent→mark_offline) is an OPTIONAL fast-path only if the daemon brain is reliably subscribed to all hosted sessions; correctness rides the pull. Broker stays stateless (ADR-0004 §B — brain owns the info.json write). (v0.12.0)
2026-07-06T06:24:02.6769477Z - Required stages: impl, unit, int
2026-07-06T06:24:02.6769505Z 
2026-07-06T06:24:02.6769609Z ### REQ-HAZARD-RC-ATTACH-FAILFAST
2026-07-06T06:24:02.6772868Z - Title: B1: `spt rc <id>` to a DEAD or non-streaming session fails fast with a clear message, never an INFINITE blank screen. Today rc.rs run_attach (209-231) + pump spawns PUMP_IPC_READER and blocks: the poll times out each slice but the stream never produces output, so the operator sees a permanent blank (operator: fresh wall-f attached, closed tab, then `spt rc wall-f` HUNG — the broker still resolved a session for it). FIX: (a) once B2 lands, gate attach on is_online/status — an offline endpoint yields a clean 'endpoint offline, start it' not an attach; (b) fail-fast — if the attach-open ack / first output does not arrive within a bound, surface a clear message, never an infinite blank; (c) the broker EOFs the attach stream when the session's child is dead, so rc's existing PumpEnd::BrokerGone graceful path (REQ-HAZARD-RC-EOF) catches it. PIN the exact sub-mechanism with a repro test FIRST (dead-session-lingers-in-broker vs reaped-but-rc-waits vs alive-resting-no-wake — the wall-f Windows tab-close: child alive-silent vs dead-not-reaped). (v0.12.0)
2026-07-06T06:24:02.6773087Z - Required stages: impl, unit, int
2026-07-06T06:24:02.6773120Z 
2026-07-06T06:24:02.6773222Z ### REQ-ENDPOINT-STOP-OFFLINE
2026-07-06T06:24:02.6774474Z - Title: H3: `spt endpoint stop <id>` marks the endpoint OFFLINE (alive=false), not merely de-readied. cmd_stop (cli.rs:2994-3010) removes the ready marker + unregisters the address but does NOT set status offline, so a stopped daemon-hosted endpoint still reports alive=true (status=online latch). FIX: add set_status(perch, STATUS_OFFLINE) to cmd_stop — folds with B2 (same setter). Unit: stop → is_perch_alive=false / alive=false. (v0.12.0)
2026-07-06T06:24:02.6774570Z - Required stages: impl, unit
2026-07-06T06:24:02.6774603Z 
2026-07-06T06:24:02.6774702Z ### REQ-HAZARD-DAEMON-STOP-BARRIER
2026-07-06T06:24:02.6776404Z - Title: B3: `spt daemon stop` then an immediate `spt daemon start` does NOT race — stop fully completes before it returns. Today request_stop (seedmap.rs:240-255) returns on the KIND_STOPPING ack (sent seedmap.rs:174-176) BEFORE the seed socket unbinds, so a following is_running ping (daemon.rs:375) wins the exit window and start reports ALREADY_RUNNING (operator: daemon stop → STOPPED then start → ALREADY_RUNNING). FIX: unbind/stop-gate the seed socket BEFORE acking KIND_STOPPING, OR request_stop waits for a ping-to-fail before returning. Unit: stop then immediate is_running()==false. (v0.12.0)
2026-07-06T06:24:02.6776607Z - Required stages: impl, unit
2026-07-06T06:24:02.6776635Z 
2026-07-06T06:24:02.6776735Z ### REQ-HAZARD-SEEDMAP-CONNECT-UNBOUNDED
2026-07-06T06:24:02.6780184Z - Title: SEED (doyle-filed, 2026-07-05, from the REQ-HAZARD-DAEMON-STOP-BARRIER B2 fix): the PRODUCTION seedmap connect callers (put / take / is_running) inherit the SAME interprocess WaitNamedPipeW-forever hazard the stop path just bounded — a Windows named-pipe connect to a name that EXISTS but has NO accepting instance parks in NMPWAIT_WAIT_FOREVER, so a slow / half-dead seed daemon could wedge a live `api seed` / `api listen` / `daemon start`. UPDATE (2026-07-05, doyle reversed the stop-path scope-guard): request_stop's OWN initial connect became load-bearing (a stop-guard re-dialing an already-dying name parked forever, resurrecting the convoy) → it is now bounded via connect_bounded under REQ-HAZARD-DAEMON-STOP-BARRIER (every dial on the STOP path is bounded). REMAINING deferred here = the put / take / is_running production clients. FIX (deferred, needs its own ruling): a shared bounded seed-control connect for those — but a 2s-style cap on a legitimately slow daemon-start connect is a real behavior change (a slow-but-fine start could become a spurious failure), so the timeout + degrade semantics need design first. NOT built — activate when scoped.
2026-07-06T06:24:02.6780295Z - Required stages: 
2026-07-06T06:24:02.6780327Z 
2026-07-06T06:24:02.6780427Z ### REQ-HAZARD-DAEMON-STOP-REAP
2026-07-06T06:24:02.6782189Z - Title: Breap: `spt daemon stop` REAPS the spt-hosted children it spawned — no orphaned psyche/harness processes. Today a stop leaves ~8 orphaned claude-spt-psyche.exe + spt.exe: Psyches are spawned DETACHED (runtime.rs:342-356, the Child is dropped — 'Detached' ~349) and the livehost stop flag Arc<AtomicBool> is NEVER raised (brainproc.rs:227-230 holds it 'for symmetry'). FIX: on stop, raise the livehost stop flag AND kill the spawned psyche/spt-hosted children — via a Windows job object / Unix process-group so the children die with the daemon (not detached-immortal). Folds with B3 (both the stop path). (v0.12.0)
2026-07-06T06:24:02.6782294Z - Required stages: impl, unit
2026-07-06T06:24:02.6782327Z 
2026-07-06T06:24:02.6782441Z ### REQ-HAZARD-LIVEHOST-BOOT-LIVENESS-GATE
2026-07-06T06:24:02.6784782Z - Title: B5: `spt daemon start` does NOT revive phantom Psyches for dead-but-online-latched perches. Today reconcile_once (livehost.rs:285) spawns a Psyche per status=online live_agent perch at boot WITHOUT verifying the harness child / {id}-psyche is actually alive — so a Cold start after an unclean stop revives N psyches for N dead-but-latched perches (3 psyches for 3 dead perches). FIX: gate the boot psyche-spawn on real child-liveness — a perch with NO live broker session (the B2 reconcile signal) is marked OFFLINE at boot instead of hosted, so a dead-harness perch is never revived. Shares the B2 reconcile loop (this is its boot-gate arm); composes with B2's honest latch. Also closes wall-a's psyche_host_error gap (residency-confirm does not run at boot tick-1, livehost.rs:395-441 / 257-263). (v0.12.0)
2026-07-06T06:24:02.6784996Z - Required stages: impl, unit, int
2026-07-06T06:24:02.6785024Z 
2026-07-06T06:24:02.6785158Z ### REQ-HAZARD-BRAIN-RESTART-LIFECYCLE-REHYDRATE
2026-07-06T06:24:02.6787687Z - Title: B4 (deepest): a bare brain restart (broker survives) REHYDRATES the live-agent lifecycle so post-restart endpoints are hosted + attachable. Today resume_sessions (brainproc.rs:186, brain.rs:797-809) re-subscribes to the broker's PTY sessions but ALL BrainLifecycle instances (lifecycle.rs:58-130; the ephemeral brain.rs:254-275) are LOST on restart → a post-restart live endpoint gets no livehost → its Psyche is never (re)hosted and new spawns die / can't attach until a FULL daemon reset (operator: perri's brain kill+restart wedged everything until a full daemon kill). FIX: on brain startup, rebuild a BrainLifecycle per resumed live-capable session — load the manifest from the adapter registry → instantiate → start the pulse — the rehydrate the resume no-op cannot do. Composes with B2 (the reconcile re-hosts from the honest on-disk status after rehydrate). (v0.12.0)
2026-07-06T06:24:02.6787886Z - Required stages: 
2026-07-06T06:24:02.6787921Z 
2026-07-06T06:24:02.6788030Z ### REQ-HAZARD-BRAIN-RESTART-PSYCHE-DUP
2026-07-06T06:24:02.6791766Z - Title: A bare brain restart leaves EXACTLY ONE `{id}-psyche` process per endpoint — no duplicate. On an abrupt brain death stop_host never runs (the LiveSet + owned child handles die with the brain) and Breap's job/group only reaps at DAEMON stop, so the PRIOR brain's Psyche stays ALIVE; the respawned brain's reconcile re-hosts a SECOND Psyche and overwrites the `{id}-psyche` perch pid, leaving the old one untracked + alive = a duplicate that lingers until daemon-stop (the operator's 'brain kill+restart wedged everything'). FIX: at brain start, BEFORE the first reconcile re-hosts, reap any pre-existing `{id}-psyche` orphan — ID-SPECIFICALLY (recycle-safe on the shared box, where sibling agents share the `claude` basename): scoped-kill the recorded pid ONLY IF it is alive AND its exe basename == the adapter's psyche program (normalize_basename) AND its COMMAND LINE contains the full psyche id `<id>-psyche` (baked via {id}); a sibling never carries THIS id, and any unreadable signal FAILS SAFE (decline to reap — a missed dup is bounded by Breap, a wrong-kill is catastrophic). CAVEAT: the cmdline carries `<id>-psyche` only when the adapter's psyche_init.command uses {id} (the norm); a non-{id} adapter safely MISSES the reap (today's behavior, Breap bounds it) — never a wrong-kill. (v0.12.0)
2026-07-06T06:24:02.6791884Z - Required stages: 
2026-07-06T06:24:02.6791917Z 
2026-07-06T06:24:02.6792018Z ### REQ-HAZARD-UNHOST-PSYCHE-REAP
2026-07-06T06:24:02.6795137Z - Title: On un-host, the detached `{id}-psyche` HARNESS PROCESS is reaped — not just its in-brain pulse-driver thread. Today stop_host (livehost.rs:203) trips the HostedLife stop flag + JOINS the driver thread, but the Psyche is a detached harness process (spawn_psyche → ManifestRuntime detached spawn, runtime.rs:341-356; its pid is untracked in HostedLife though stamped on the `{id}-psyche` perch, where residency-confirm already reads it). So endpoint-stop / mid-life agent-death / a B2/B5 offline-then-unhost leaves the psyche process ORPHANED, alive until the next daemon-stop (where Breap's job/group reaps the whole brain subtree). The Psyche STAYS a harness process by design (CONTEXT.md 97/203/251 — headless harness session, its own perch) — the fix does NOT move it in-brain; it SCOPED-kills the `{id}-psyche` pid on un-host (never machine-wide — shared box). Track the pid in HostedLife at host_one (cleanest) or read the `{id}-psyche` perch pid at stop_host. Composes with H3 (endpoint stop → offline → reconcile un-host → reap) and B2/B5 (the offline arms that trigger un-host). (v0.12.0)
2026-07-06T06:24:02.6795371Z - Required stages: 
2026-07-06T06:24:02.6795404Z 
2026-07-06T06:24:02.6795489Z ### REQ-ENDPOINT-PURGE
2026-07-06T06:24:02.6800277Z - Title: `spt endpoint purge <id>` fully removes an endpoint AND every record keyed on it — the formal teardown devs/CI need for clean test setup/reset. NOT consent-gated (a local dev/test op — no peer consent). OFFLINE-ONLY: refuses while the endpoint is online / daemon-hosted (deleting records out from under a live host risks the daemon re-creating or re-hosting mid-purge); `--force` STOPS it first (endpoint stop → wait for the daemon reconcile to un-host + reap the Psyche) THEN purges. Confirms interactively unless `--yes` (the CI path). Refuses purging the CALLER's OWN running id. All LOCAL — purge reaches only THIS node's records; a remote endpoint's records can't be touched, and its subnet-registry rows decay via the epoch-lease eviction (REQ-HAZARD-REGISTRY-DECAY). Removes: (1) the perch dir TREE recursively — owlery/<id>/ incl every nested {id}-psyche / {id}-w* / shells child (info.json, ready marker, sessions.log ledger, spool.db, inbox, .idle/.more-done sentinels, auth token); (2) the registry address (registry::unregister_address); (3) the context store — ContextStore::remove_endpoint(id): the a-<id> branch+worktree + the <id>/ rows from every p-<project> branch (the same fn `fork --delete-source` already uses); (4) node-local trust rows keyed on the id — access.json + visibility.json. Reuse-heavy: it is `fork --delete-source` generalized (recursive perch remove + unregister + remove_endpoint) + the trust-record cleanup; `endpoint rename` already enumerates the same record set + uses the same offline-only gate. (v0.12.0)
2026-07-06T06:24:02.6800500Z - Required stages: doc, impl, unit, int
2026-07-06T06:24:02.6800538Z 
2026-07-06T06:24:02.6800637Z ### REQ-READY-AGENT-RESUME
2026-07-06T06:24:02.6804091Z - Title: An offline ReadyAgent shows in `spt endpoint run`'s picker Resume-from-history and resumes correctly — closing the gap that today only LiveAgents do. ROOT: a harness-hosted ready bind (ReadyAgent::start_homed, ready.rs) writes info.json DIRECTLY and never appends the session ledger (unlike the shared establish_perch:250 live path), so a ready agent — though it has a session_id — produces ZERO ledger rows → the picker's offline+local Resume-from-history (which gates on ledger rows) never offers it. FIX (1): ledger the ready bind (ReadyAgent::start_homed → sessions::append Boot, mirroring establish_perch). FIX (2): `spt endpoint run --resume <session>` honors the adapter MANIFEST's endpoint TYPE — a ReadyAgent manifest (no [session.psyche_init]) resumes as a ready endpoint (poll listener, NO psyche-host); a LiveAgent (with psyche_init) as live. NO new bringup mode + NO picker changes (operator 2026-06-18): `spt endpoint run` is the spt-hosted ENDPOINT bringup for BOTH types, the type IS the adapter-manifest's concern (psyche-host already keys on psyche_init presence) — so (2) likely already holds; VERIFY at code, build only the residual. (v0.12.0)
2026-07-06T06:24:02.6804210Z - Required stages: doc, impl, unit, int
2026-07-06T06:24:02.6804244Z 
2026-07-06T06:24:02.6804343Z ### REQ-PICKER-ADAPTER-DESCRIPTION
2026-07-06T06:24:02.6805692Z - Title: The Create-new adapter-CHOICE screen of `spt endpoint run`'s picker shows a right-hand Description panel (like the Pick-existing endpoint picker's two-pane) surfacing per-adapter detail: install date, last-updated, adapter TYPE / the endpoint types it hosts, and the adapter description — so the user can see WHAT each adapter is before choosing it (today the selector lists bare names). DEFERRED fast-follow to v0.12.0 (operator 2026-06-18). (post-v0.12.0)
2026-07-06T06:24:02.6805777Z - Required stages: 
2026-07-06T06:24:02.6805811Z 
2026-07-06T06:24:02.6806021Z ### REQ-HAZARD-VIEWER-ISOLATION
2026-07-06T06:24:02.6808113Z - Title: A slow / dead / hostile VIEWER must NEVER stall the controller, the PTY child, or the session drain thread. The broker drain fans output to the controller on the authoritative blocking bounded path (advances delivered_through) but to each viewer via a bounded per-viewer channel with a dedicated writer thread; the drain `try_send`s under the log lock and a viewer whose bounded queue OVERFLOWS (can't keep up) is EVICTED (queue dropped, writer thread ends, removed from the viewers map) — the drain thread NEVER touches a viewer socket, so no viewer write can backpressure or block it. A soft viewer cap bounds the thread count. Viewer eviction never perturbs the controller stream, the delivered_through cursor, or the child.
2026-07-06T06:24:02.6808216Z - Required stages: unit, int
2026-07-06T06:24:02.6808249Z 
2026-07-06T06:24:02.6808334Z ### REQ-INSTALL-1
2026-07-06T06:24:02.6808507Z - Title: Two install paths; signed one-line script; OS-service registration
2026-07-06T06:24:02.6808687Z - Required stages: doc, impl, int
2026-07-06T06:24:02.6808721Z 
2026-07-06T06:24:02.6808798Z ### REQ-INSTALL-2
2026-07-06T06:24:02.6808926Z - Title: Marketplace-repackaging-friendly install
2026-07-06T06:24:02.6809098Z - Required stages: doc
2026-07-06T06:24:02.6809132Z 
2026-07-06T06:24:02.6809221Z ### REQ-INSTALL-3
2026-07-06T06:24:02.6809346Z - Title: Idempotent + interactive-optional first run
2026-07-06T06:24:02.6809451Z - Required stages: impl, int
2026-07-06T06:24:02.6809484Z 
2026-07-06T06:24:02.6809574Z ### REQ-INSTALL-4
2026-07-06T06:24:02.6810160Z - Title: Adapter registration lifecycle: spt adapter add (--github, manifest-first, install-is-first-update) + soft-deregister remove + optional manifest uninstall template; node-local registered-adapter set self-update ripples over
2026-07-06T06:24:02.6810266Z - Required stages: impl, unit
2026-07-06T06:24:02.6810290Z 
2026-07-06T06:24:02.6810372Z ### REQ-MIGRATE-1
2026-07-06T06:24:02.6810533Z - Title: Auto-detect and migrate a legacy claude_skill_owl install
2026-07-06T06:24:02.6810615Z - Required stages: 
2026-07-06T06:24:02.6810649Z 
2026-07-06T06:24:02.6810729Z ### REQ-INFRA-1
2026-07-06T06:24:02.6810884Z - Title: GitHub issue tracking for v1; tangled.org as migration target
2026-07-06T06:24:02.6810975Z - Required stages: 
2026-07-06T06:24:02.6811004Z 
2026-07-06T06:24:02.6811088Z ### REQ-INSTALL-5
2026-07-06T06:24:02.6811530Z - Title: Non-interactive install path: the canonical one-liner doubles as every adapter's pack-in on-demand install (no second mechanism); sha256-verified fetch; user-PATH registration
2026-07-06T06:24:02.6811637Z - Required stages: impl, int
2026-07-06T06:24:02.6811670Z 
2026-07-06T06:24:02.6811746Z ### REQ-INSTALL-9
2026-07-06T06:24:02.6812929Z - Title: Adapter add from a GitHub release archive: `spt adapter add --release <user/repo> [--tag <tag>] [--asset <name>]` fetches a `.spt` tar asset over HTTPS+GitHub trust, extracts it to the durable adapters/_github home, and registers the root — ships built binaries source-free and versioned (the distribution path for an adapter whose dev repo is a monorepo subdir, where --github root-only clone does not fit)
2026-07-06T06:24:02.6813042Z - Required stages: doc, impl, unit
2026-07-06T06:24:02.6813071Z 
2026-07-06T06:24:02.6813157Z ### REQ-INSTALL-10
2026-07-06T06:24:02.6814378Z - Title: Windows at-logon autostart runs the daemon in the background with no persistent window: the scheduled task launches `spt daemon start` (which spawn_detaches a console-less DETACHED_PROCESS daemon and exits) rather than the foreground `spt daemon run` — Task Scheduler's interactive ONLOGON launch of a long-lived console process otherwise leaves a visible console window for the daemon's whole lifetime (v0.7.4)
2026-07-06T06:24:02.6814479Z - Required stages: impl, unit
2026-07-06T06:24:02.6814513Z 
2026-07-06T06:24:02.6814608Z ### REQ-INSTALL-11
2026-07-06T06:24:02.6816342Z - Title: Adapter command templates resolve their program against the adapter's install dir BEFORE PATH: a `.spt`-shipped binary (dropped to adapters/_github/<safe>/ by --release/--github acquisition, or kept in the source_dir under copy-mode where only manifest+strings/ are copied to adapters/<name>) runs without any PATH placement — a bare-name template token (e.g. `claude-spt-digest ...`) is rewritten to <install_dir>/<program>(.exe on Windows) when that file exists, else left bare for the PATH fallback. Makes a `.spt` self-contained (closes the --release bundled-binary gap perri confirmed) (v0.7.4)
2026-07-06T06:24:02.6816562Z - Required stages: doc, impl, unit
2026-07-06T06:24:02.6816590Z 
2026-07-06T06:24:02.6816685Z ### REQ-INSTALL-12
2026-07-06T06:24:02.6819344Z - Title: Durable active-profile pointer for bind-time profile selection (ADR-0021): adapters/active-profiles.toml at the registry ROOT (sibling to the per-adapter <name>/ dirs, so adapter add/update/remove — which only rewrite a <name>/ subdir — can never clobber it), a flat host_binary → "adapter[:profile]" map. Read at bind as the PRIMARY profile selector; unset → the registered_at_ms fallback (REQ-START-5). Written ONLY by `spt adapter use <adapter>[:profile]` (resolves the adapter's host_binaries → sets each binary→adapter[:profile]); `spt adapter use --clear <adapter|binary>` drops. NEVER auto-written by install/update/adapter add (that is precisely what would let an update silently flip the active profile). A stale pointer (uninstalled adapter / deleted profile) self-heals: ignored, fall back, warn once. Pruned on adapter remove. Atomic write (spt_store atomic). (v0.9.0)
2026-07-06T06:24:02.6819557Z - Required stages: doc, impl, unit, int
2026-07-06T06:24:02.6819591Z 
2026-07-06T06:24:02.6819692Z ### REQ-INSTALL-13
2026-07-06T06:24:02.6822483Z - Title: Adapter add is non-destructive & idempotent-safe (F-018): `spt adapter add --github|--release` REFUSES when the target `_github/<safe>` home already backs an ACTIVE registered record — emitting an actionable code (ADAPTER_ADD_ALREADY_REGISTERED) that routes to `spt adapter update <name>` (refresh in place) or `spt adapter remove <name>` then re-add (replace) — instead of clobbering the live install (the perri footgun: `add --github` over a `--release` pointer git-cloned a source tree over the extracted built binaries → registered pointer dangled → cryptic `os error 2`). And when it DOES (re)populate the home it STAGES-THEN-SWAPS (clone/extract to a sibling staging dir, swap into place only on success) so a failed fetch/clone never strands the previously-extracted manifest+binaries as a dangling pointer (the os-2 / DeferredManifest class). Mirrors the safe stage-then-swap `adapter update` already uses (REQ-UPD-9, apply_release_crc_swap). (v0.14.1)
2026-07-06T06:24:02.6822601Z - Required stages: doc, impl, unit
2026-07-06T06:24:02.6822626Z 
2026-07-06T06:24:02.6822710Z ### REQ-REL-1
2026-07-06T06:24:02.6823069Z - Title: spt-releases publish-target repo: README public face, licensing split, Pages docs at the permanent lapse-proof canonical URL (ADR-0014)
2026-07-06T06:24:02.6823155Z - Required stages: doc, impl
2026-07-06T06:24:02.6823193Z 
2026-07-06T06:24:02.6823277Z ### REQ-REL-2
2026-07-06T06:24:02.6823732Z - Title: Release asset set consumable by the self-updater: platform binaries, SHA256SUMS, SignedRelease metadata, manifest schema, mock-adapter zip; tag-triggered cross-repo pipeline
2026-07-06T06:24:02.6823832Z - Required stages: impl, int
2026-07-06T06:24:02.6823866Z 
2026-07-06T06:24:02.6823954Z ### REQ-REL-3
2026-07-06T06:24:02.6824357Z - Title: Two-key release-signing trust anchor: primary + offline never-used recovery, both pubkeys embedded in the binary's trusted set, manual local signing (ADR-0015)
2026-07-06T06:24:02.6824453Z - Required stages: impl, unit
2026-07-06T06:24:02.6824486Z 
2026-07-06T06:24:02.6824567Z ### REQ-DOCS-1
2026-07-06T06:24:02.6824754Z - Title: Dual-audience docs (human + AI dev-agent), markdown once / two depths
2026-07-06T06:24:02.6824849Z - Required stages: doc, impl
2026-07-06T06:24:02.6824882Z 
2026-07-06T06:24:02.6824972Z ### REQ-DOCS-2
2026-07-06T06:24:02.6825230Z - Title: Sub-10-minute runnable killer quickstart per audience
2026-07-06T06:24:02.6825330Z - Required stages: doc, int
2026-07-06T06:24:02.6825364Z 
2026-07-06T06:24:02.6825454Z ### REQ-DOCS-3
2026-07-06T06:24:02.6825630Z - Title: Diátaxis structure; one canonical way to do X
2026-07-06T06:24:02.6825732Z - Required stages: doc
2026-07-06T06:24:02.6825765Z 
2026-07-06T06:24:02.6825850Z ### REQ-DOCS-4
2026-07-06T06:24:02.6826032Z - Title: Agent-consumable layer (llms.txt, manifest schema, MCP, CLI help)
2026-07-06T06:24:02.6826126Z - Required stages: doc, impl, unit
2026-07-06T06:24:02.6826154Z 
2026-07-06T06:24:02.6826241Z ### REQ-DOCS-5
2026-07-06T06:24:02.6826422Z - Title: Anti-drift: rustdoc/schema/exports/CLI-help generated + CI-checked
2026-07-06T06:24:02.6826517Z - Required stages: impl, int
2026-07-06T06:24:02.6826546Z 
2026-07-06T06:24:02.6826662Z ### REQ-HAZARD-GRACE-BEFORE-SIGNOFF
2026-07-06T06:24:02.6826831Z - Title: Grace-period wait completes before composing INIT_SIGNOFF (1.1)
2026-07-06T06:24:02.6827003Z - Required stages: impl, unit
2026-07-06T06:24:02.6827037Z 
2026-07-06T06:24:02.6827136Z ### REQ-HAZARD-INFO-JSON-TORN-READ
2026-07-06T06:24:02.6827279Z - Title: State-file reads tolerate concurrent writes (1.2)
2026-07-06T06:24:02.6827375Z - Required stages: impl, unit
2026-07-06T06:24:02.6827404Z 
2026-07-06T06:24:02.6827513Z ### REQ-HAZARD-STALE-INDEX-LOCK
2026-07-06T06:24:02.6827633Z - Title: Sweep stale lockfiles on daemon boot (1.3)
2026-07-06T06:24:02.6827728Z - Required stages: impl, unit
2026-07-06T06:24:02.6827756Z 
2026-07-06T06:24:02.6827856Z ### REQ-HAZARD-DEFERRED-DRAIN
2026-07-06T06:24:02.6828023Z - Title: Deferred spool rows excluded from the event-stream drain (1.4)
2026-07-06T06:24:02.6828123Z - Required stages: impl, unit
2026-07-06T06:24:02.6828156Z 
2026-07-06T06:24:02.6828248Z ### REQ-HAZARD-WORKER-PATH
2026-07-06T06:24:02.6828414Z - Title: Single source of truth for Worker/Psyche perch location (1.5)
2026-07-06T06:24:02.6828500Z - Required stages: impl, unit
2026-07-06T06:24:02.6828529Z 
2026-07-06T06:24:02.6828643Z ### REQ-HAZARD-PARENT-PID-PREFER
2026-07-06T06:24:02.6828815Z - Title: Prefer stable parent PID / broker handle over ephemeral PID (2.1)
2026-07-06T06:24:02.6828907Z - Required stages: 
2026-07-06T06:24:02.6828935Z 
2026-07-06T06:24:02.6829152Z ### REQ-HAZARD-STDIN-SESSION-ID
2026-07-06T06:24:02.6829266Z - Title: Stdin session_id precedence over env (2.2)
2026-07-06T06:24:02.6829360Z - Required stages: 
2026-07-06T06:24:02.6829393Z 
2026-07-06T06:24:02.6829493Z ### REQ-HAZARD-HANDOFF-ARGV-COMPAT
2026-07-06T06:24:02.6829647Z - Title: Broker/brain IPC + handoff argv version-tolerant (2.3)
2026-07-06T06:24:02.6829746Z - Required stages: impl, unit
2026-07-06T06:24:02.6829774Z 
2026-07-06T06:24:02.6829875Z ### REQ-HAZARD-GEN-START-NOW
2026-07-06T06:24:02.6830013Z - Title: gen_start = now() on cold-start and handoff (2.4)
2026-07-06T06:24:02.6830112Z - Required stages: impl, int
2026-07-06T06:24:02.6830142Z 
2026-07-06T06:24:02.6830256Z ### REQ-HAZARD-EPHEMERAL-CLEANUP
2026-07-06T06:24:02.6830399Z - Title: Ephemeral perch cleanup on every ring exit path (3.1)
2026-07-06T06:24:02.6830505Z - Required stages: impl, unit
2026-07-06T06:24:02.6830538Z 
2026-07-06T06:24:02.6830642Z ### REQ-HAZARD-STALE-SIGNOFF-SENTINEL
2026-07-06T06:24:02.6830805Z - Title: Stale signoff sentinel does not kill a fresh start (3.2)
2026-07-06T06:24:02.6830890Z - Required stages: impl, unit
2026-07-06T06:24:02.6830919Z 
2026-07-06T06:24:02.6831024Z ### REQ-HAZARD-ECHO-BEFORE-SIGNOFF
2026-07-06T06:24:02.6831196Z - Title: Echo-commune fires before INIT_SIGNOFF on orphan teardown (3.3)
2026-07-06T06:24:02.6831300Z - Required stages: impl, unit
2026-07-06T06:24:02.6831329Z 
2026-07-06T06:24:02.6831445Z ### REQ-HAZARD-ENVELOPE-DECODE-ORDER
2026-07-06T06:24:02.6831581Z - Title: Envelope decode order, ampersand decoded last (4.1)
2026-07-06T06:24:02.6831686Z - Required stages: impl, unit
2026-07-06T06:24:02.6831716Z 
2026-07-06T06:24:02.6831816Z ### REQ-HAZARD-ENVELOPE-CR-LINESAFE
2026-07-06T06:24:02.6833682Z - Title: Envelope CR-linesafety (4.1): the line-framed EVENT codec must neutralize raw carriage returns — `event_body_escape` folds CRLF/lone-CR to the codec's representable linebreak (`\n`→`<br>`) BEFORE framing, so a body carrying `\r` (Windows `echo`/CRLF text crossing nodes) cannot survive into the single-line envelope and trigger a receiver terminal CR→col0 overwrite that corrupts the frame. Robustness on unrepresentable input, NOT a wire-format change (decoder untouched, amp-last invariant held). Belt-and-suspenders: `spt send`/`ring` also trim stdin (parity with `notify`).
2026-07-06T06:24:02.6833786Z - Required stages: impl, unit
2026-07-06T06:24:02.6833815Z 
2026-07-06T06:24:02.6833914Z ### REQ-HAZARD-ENVELOPE-PARSER-SAFE
2026-07-06T06:24:02.6834083Z - Title: Two-slice envelope parser is panic-free and tolerant (4.2)
2026-07-06T06:24:02.6834176Z - Required stages: impl, unit
2026-07-06T06:24:02.6834206Z 
2026-07-06T06:24:02.6834317Z ### REQ-HAZARD-EVENTPART-REASSEMBLY
2026-07-06T06:24:02.6834614Z - Title: EVENT-PART split/reassembly is byte-exact; orphan parts dropped silently
2026-07-06T06:24:02.6834715Z - Required stages: impl, unit
2026-07-06T06:24:02.6834747Z 
2026-07-06T06:24:02.6834841Z ### REQ-HAZARD-ID-CHARSET
2026-07-06T06:24:02.6835086Z - Title: Addressable-id charset reserves :/@ delimiters; validated at every creation seam (4.6)
2026-07-06T06:24:02.6835189Z - Required stages: impl, unit
2026-07-06T06:24:02.6835217Z 
2026-07-06T06:24:02.6835324Z ### REQ-HAZARD-REGISTRY-STALE-CLEAN
2026-07-06T06:24:02.6835503Z - Title: Stale registry entries degrade to fallback, never hard-fail (4.3)
2026-07-06T06:24:02.6835600Z - Required stages: impl, unit
2026-07-06T06:24:02.6835633Z 
2026-07-06T06:24:02.6835743Z ### REQ-HAZARD-REGISTRY-CONCURRENT
2026-07-06T06:24:02.6835967Z - Title: Concurrent SQLite openers (registry/spool) must not fail with 'database is locked' (4.7)
2026-07-06T06:24:02.6836061Z - Required stages: impl, unit
2026-07-06T06:24:02.6836096Z 
2026-07-06T06:24:02.6836205Z ### REQ-HAZARD-REGISTRY-DIR-CREATE
2026-07-06T06:24:02.6836554Z - Title: SQLite store opens create their parent dir themselves — a fresh-home registry op must not SQLITE_CANTOPEN (4.9)
2026-07-06T06:24:02.6836663Z - Required stages: doc, impl, unit
2026-07-06T06:24:02.6836691Z 
2026-07-06T06:24:02.6836791Z ### REQ-HAZARD-REGISTRY-EPOCH-LEASE
2026-07-06T06:24:02.6837217Z - Title: Registry merge ordered by per-node monotonic epoch, never wall-clock — a stale Active can't clobber a newer Offline (4.8, red-team #8)
2026-07-06T06:24:02.6837302Z - Required stages: impl, unit
2026-07-06T06:24:02.6837325Z 
2026-07-06T06:24:02.6837434Z ### REQ-HAZARD-DEFERRED-SURVIVE-DRAIN
2026-07-06T06:24:02.6837544Z - Title: Deferred rows survive poll drain (4.4)
2026-07-06T06:24:02.6837645Z - Required stages: impl, unit
2026-07-06T06:24:02.6837673Z 
2026-07-06T06:24:02.6837777Z ### REQ-HAZARD-INBOX-NO-DOUBLE
2026-07-06T06:24:02.6837902Z - Title: No double-delivery via legacy inbox (4.5)
2026-07-06T06:24:02.6838011Z - Required stages: impl, unit
2026-07-06T06:24:02.6838044Z 
2026-07-06T06:24:02.6838145Z ### REQ-HAZARD-WINDOWS-PID-RECYCLE
2026-07-06T06:24:02.6838298Z - Title: Windows PID-recycling false positives guarded (5.1)
2026-07-06T06:24:02.6838397Z - Required stages: impl, unit
2026-07-06T06:24:02.6838430Z 
2026-07-06T06:24:02.6838532Z ### REQ-HAZARD-EBUSY-RENAME
2026-07-06T06:24:02.6838678Z - Title: tmp-write + atomic-rename + retry on Windows EBUSY (5.2)
2026-07-06T06:24:02.6838769Z - Required stages: impl, unit
2026-07-06T06:24:02.6838798Z 
2026-07-06T06:24:02.6838907Z ### REQ-HAZARD-PERCH-RECORD-POWER-LOSS
2026-07-06T06:24:02.6839505Z - Title: Authoritative/identity records fsync data before the rename (5.13): a hard reset must not resurrect a full-length NUL-filled record — SCOPED, not a blanket fsync
2026-07-06T06:24:02.6839603Z - Required stages: impl, unit
2026-07-06T06:24:02.6839636Z 
2026-07-06T06:24:02.6839741Z ### REQ-HAZARD-ATOMIC-TMP-COLLISION
2026-07-06T06:24:02.6840164Z - Title: Concurrent atomic writers to the same target must not share a tmp name (5.15): a fixed tmp sibling makes one writer's rename consume the other's staged file (os-error-2 loser)
2026-07-06T06:24:02.6840368Z - Required stages: impl, unit
2026-07-06T06:24:02.6840406Z 
2026-07-06T06:24:02.6840507Z ### REQ-HAZARD-INFO-RMW-LOST-UPDATE
2026-07-06T06:24:02.6840897Z - Title: Concurrent info.json writers must serialize under the per-perch lock (5.16): an unlocked whole-record write racing a locked RMW is a silent lost update
2026-07-06T06:24:02.6840992Z - Required stages: impl, unit
2026-07-06T06:24:02.6841022Z 
2026-07-06T06:24:02.6841131Z ### REQ-HAZARD-CORRUPT-PERCH-COHERENCE
2026-07-06T06:24:02.6841522Z - Title: Corrupt (present-but-unparseable) info.json is NOT absent: liveness/status readers agree a destroyed record is neither alive nor Active (counter-39 #2)
2026-07-06T06:24:02.6841626Z - Required stages: impl, unit
2026-07-06T06:24:02.6841661Z 
2026-07-06T06:24:02.6841756Z ### REQ-HAZARD-SUBPROCESS-TIMEOUT
2026-07-06T06:24:02.6841894Z - Title: Every harness/git subprocess has a timeout (5.3)
2026-07-06T06:24:02.6842090Z - Required stages: impl, unit
2026-07-06T06:24:02.6842118Z 
2026-07-06T06:24:02.6842213Z ### REQ-HAZARD-UNC-PATH-STRIP
2026-07-06T06:24:02.6842362Z - Title: Strip Windows UNC prefix on serialized paths (5.4)
2026-07-06T06:24:02.6842451Z - Required stages: impl, unit
2026-07-06T06:24:02.6842485Z 
2026-07-06T06:24:02.6842593Z ### REQ-HAZARD-SINGLE-PATH-SOURCE
2026-07-06T06:24:02.6842764Z - Title: Single path/registry source of truth; no layout ambiguity (6.1)
2026-07-06T06:24:02.6842853Z - Required stages: impl, unit
2026-07-06T06:24:02.6842881Z 
2026-07-06T06:24:02.6842973Z ### REQ-HAZARD-SOFT-CLEANUP
2026-07-06T06:24:02.6843154Z - Title: Soft-cleanup preserves state, removes only the ready marker (6.2)
2026-07-06T06:24:02.6843254Z - Required stages: impl, unit
2026-07-06T06:24:02.6843283Z 
2026-07-06T06:24:02.6843383Z ### REQ-HAZARD-CASCADE-WIPE-GUARD
2026-07-06T06:24:02.6843549Z - Title: No hard-delete of a parent hosting non-empty children (6.3)
2026-07-06T06:24:02.6843650Z - Required stages: impl, unit
2026-07-06T06:24:02.6843679Z 
2026-07-06T06:24:02.6843793Z ### REQ-HAZARD-DROP-FILE-SINGLE-WRITER
2026-07-06T06:24:02.6843927Z - Title: Drop files are daemon-owned single-writer (6.4)
2026-07-06T06:24:02.6844031Z - Required stages: impl, unit
2026-07-06T06:24:02.6844055Z 
2026-07-06T06:24:02.6844164Z ### REQ-HAZARD-DIRECT-WRITE-PRECEDENCE
2026-07-06T06:24:02.6844365Z - Title: Direct-write precedence marker (with node id) guards stale overwrite (6.5)
2026-07-06T06:24:02.6844461Z - Required stages: impl, unit
2026-07-06T06:24:02.6844494Z 
2026-07-06T06:24:02.6844600Z ### REQ-HAZARD-CONFLICT-BOTH-PRESERVED
2026-07-06T06:24:02.6845136Z - Title: A surfaced concurrent context pair is durably preserved (both versions, tracked artifacts) until a strictly dominating write clears it; no reconcile failure path discards an unmerged version (6.6, ADR-0013)
2026-07-06T06:24:02.6845232Z - Required stages: impl, unit
2026-07-06T06:24:02.6845265Z 
2026-07-06T06:24:02.6845382Z ### REQ-HAZARD-DETACHED-PIPE-INHERIT
2026-07-06T06:24:02.6846431Z - Title: Windows detached long-lived children must not inherit a captured caller's pipe: every detach-spawn of an immortal child (daemon, shell binary) runs bInheritHandles=FALSE, or a caller capturing output anywhere up the process chain hangs forever on a pipe that never EOFs — std-handle flag stripping is NOT sufficient (grandparent strays still flow) (5.6)
2026-07-06T06:24:02.6846527Z - Required stages: impl, unit
2026-07-06T06:24:02.6846551Z 
2026-07-06T06:24:02.6846646Z ### REQ-HAZARD-CONPTY-DSR
2026-07-06T06:24:02.6846847Z - Title: ConPTY reader must auto-answer DSR (ESC[6n) or all child output stalls (5.5)
2026-07-06T06:24:02.6846936Z - Required stages: impl, unit
2026-07-06T06:24:02.6846961Z 
2026-07-06T06:24:02.6847075Z ### REQ-HAZARD-WIN-PTY-PROGRAM-RESOLVE
2026-07-06T06:24:02.6848905Z - Title: Native-PTY spawn must resolve a bare program name with PATHEXT precedence and run a non-PE target through its interpreter: portable-pty's own `which` takes the FIRST PATH match — an extensionless shebang shim (e.g. a node CLI `ccs` shipped beside `ccs.cmd`) — and CreateProcessW then rejects the non-PE file with os error 193 ('not a valid Win32 application'); spt-term resolves the program itself (PATHEXT order prefers .EXE over .CMD; .cmd/.bat → cmd.exe /d /c, .ps1 → powershell -NoProfile -File) so a bare harness/shell [session.self] command actually launches on Windows. Unix is a passthrough (execve honours the shebang).
2026-07-06T06:24:02.6849220Z - Required stages: doc, impl, unit, int
2026-07-06T06:24:02.6849248Z 
2026-07-06T06:24:02.6849354Z ### REQ-HAZARD-CHILD-CONSOLE-FLASH
2026-07-06T06:24:02.6849764Z - Title: Console-subsystem children of the console-less daemon spawn with CREATE_NO_WINDOW, or each spawn flashes a visible blank window on the user's desktop (5.8)
2026-07-06T06:24:02.6849863Z - Required stages: impl, unit
2026-07-06T06:24:02.6849901Z 
2026-07-06T06:24:02.6850007Z ### REQ-HAZARD-INSTANT-UNDERFLOW
2026-07-06T06:24:02.6850661Z - Title: Scheduling never subtracts a Duration from Instant::now() (underflow-panics on a host booted more recently than the offset); 'due now / never run' is Option<Instant>=None gated on forward duration_since only (5.9)
2026-07-06T06:24:02.6850748Z - Required stages: impl, unit
2026-07-06T06:24:02.6850776Z 
2026-07-06T06:24:02.6850885Z ### REQ-HAZARD-PUMP-IPC-DEADLINE
2026-07-06T06:24:02.6851686Z - Title: The single-threaded peer pump's brain-IPC reads are deadline-bounded (PUMP_PEER_IO_TIMEOUT, total-wait per call); a TimedOut read POISONS the client and escalates to a SUPERVISED RESTART, never a per-peer retry — a black-holed peer must never wedge the whole pump
2026-07-06T06:24:02.6851805Z - Required stages: doc, impl, unit
2026-07-06T06:24:02.6851834Z 
2026-07-06T06:24:02.6851949Z ### REQ-HAZARD-BROKER-QUIC-DEADLINE
2026-07-06T06:24:02.6854972Z - Title: The broker bounds every brain-waiting QUIC op (dial / open_stream / send_stream) so a black-holed or dead peer fails PROMPTLY with an ORDINARY error the broker REPLIES, never an unbounded await. The bound (< the brain's 30s PUMP_PEER_IO_TIMEOUT so the BROKER fires first) surfaces to the pump as a normal broker error reply → peer_outcome's non-TimedOut arm → drop conn + redial next tick, the round CONTINUES and the heartbeat keeps advancing — it must NEVER manifest as the brain's own read-deadline (the A-half poison → supervised-restart path REQ-HAZARD-PUMP-IPC-DEADLINE guards). Exactly-once is preserved: a timed-out journaled op fails INSIDE its apply_once closure so no phantom conn_id/stream_id is recorded and a fresh tick re-dials cleanly. The happy path is unchanged (a live peer completes with zero added latency; the bound only bites a non-responsive peer). This is the ROOT-cause cure for the 2.2h hfenduleam pump wedge — a dead roster peer whose QUIC path the broker awaited unbounded — recurring on hfenduleam 2026-06-16.
2026-07-06T06:24:02.6855112Z - Required stages: doc, impl, unit, int
2026-07-06T06:24:02.6855151Z 
2026-07-06T06:24:02.6855268Z ### REQ-HAZARD-BROKER-SEED-WIRE-SKEW
2026-07-06T06:24:02.6858868Z - Title: A daemon-state wire-format change (e.g. the v0.9.0 adapter-agnostic Seed) does NOT take effect until a DELIBERATE full broker restart: the broker serves the seed-control channel and is RESIDENT across a brain-only self-update (ADR-0004 no-terminate-during-update forbids auto-killing it), so a NEW-version CLI talking to a still-resident OLD broker fails the seed handshake — the old broker cannot deserialize the new Seed (its formerly-required `adapter` field is gone) and drops the conn without an ack, which surfaces to the CLI as a raw UnexpectedEof 'failed to fill whole buffer'. spt-core must (a) surface an ACTIONABLE diagnostic on that seed-ack EOF (name the stale-broker cause + the `spt daemon stop` fix — the broker restarts on the next api call), never the cryptic io error; and (b) document the operational rule (a deliberate broker restart is required on any daemon-state wire change — NOT automatic) + the FORWARD discipline (daemon-state/Seed schema changes stay additive + serde-default so a resident OLD broker tolerates a NEW CLI across a brain-only update; note this would NOT have rescued 0.9.0 itself, since the old broker's `adapter` was a required field). perri PREP-4 FINDING 1 (v0.9.0 CLI vs stale 0.8.x broker).
2026-07-06T06:24:02.6859159Z - Required stages: doc, impl, unit
2026-07-06T06:24:02.6859202Z 
2026-07-06T06:24:02.6859304Z ### REQ-HAZARD-SUDO-SECURE-PATH
2026-07-06T06:24:02.6860156Z - Title: Elevation guidance on Unix names the binary's ABSOLUTE path under sudo (a user-local install ~/.local/bin · ~/.cargo/bin is not on sudo's secure_path, so bare `sudo spt` dies 'command not found'); gated commands auto-elevate on an interactive TTY, else print the runnable hint (5.10)
2026-07-06T06:24:02.6860257Z - Required stages: impl, unit
2026-07-06T06:24:02.6860291Z 
2026-07-06T06:24:02.6860389Z ### REQ-HAZARD-SELF-ELEVATE
2026-07-06T06:24:02.6862543Z - Title: Self-elevation (REQ-ELEVATE-1) re-runs the EXACT original invocation with the binary's ABSOLUTE exe path — never widening privilege scope, never adding/altering args, never via a PATH-resolved bare name, never via a shell-interpolated command string (argv-array only, no `sh -c`); the elevated child drops state back to the user (composes with the 5.7 de-elevation) and NEVER re-elevates (loop-safe: decide_elevation_path returns AlreadyElevated whenever the process is already Elevated, on every OS). The user's UAC/polkit/sudo prompt is the only consent gate — we never bypass it; the print-hint floor prints the absolute-path command too. The unprivileged parent never depends on (pipes/captures) the privileged child's stdout.
2026-07-06T06:24:02.6862771Z - Required stages: unit
2026-07-06T06:24:02.6862800Z 
2026-07-06T06:24:02.6862904Z ### REQ-HAZARD-LOCAL-API-AUTH
2026-07-06T06:24:02.6863091Z - Title: Every local `api` mutation authenticated to an endpoint/session (codex #13)
2026-07-06T06:24:02.6863191Z - Required stages: impl, unit
2026-07-06T06:24:02.6863228Z 
2026-07-06T06:24:02.6863338Z ### REQ-BOUNDARY-ROTATION-CREDENTIAL
2026-07-06T06:24:02.6864646Z - Title: api boundary's rotation credential is designed, documented, and eventually anchor-proven (ADR-0032): the proof is the DEPARTED session's (prior sid / token) — --to-session-id is payload, never proof; the published surface documents the adapter prior-sid persistence pattern + loud-refusal requirement; the design-true end-state additionally accepts an OS-verified parent_pid-anchor ancestry proof making adapter sid-state optional
2026-07-06T06:24:02.6864752Z - Required stages: doc
2026-07-06T06:24:02.6864780Z 
2026-07-06T06:24:02.6864885Z ### REQ-HAZARD-RESTART-IDEMPOTENT
2026-07-06T06:24:02.6865147Z - Title: Idempotent/exactly-once delivery across brain restart at every broker boundary (codex #14)
2026-07-06T06:24:02.6865247Z - Required stages: impl, unit, int
2026-07-06T06:24:02.6865290Z 
2026-07-06T06:24:02.6865391Z ### REQ-HAZARD-UPDATE-ROLLBACK
2026-07-06T06:24:02.6865628Z - Title: Self-update rejects version rollback; metadata expiry + adapter content signing (codex #5)
2026-07-06T06:24:02.6865734Z - Required stages: impl, unit
2026-07-06T06:24:02.6865767Z 
2026-07-06T06:24:02.6865876Z ### REQ-HAZARD-DAEMON-HOSTED-LIVENESS
2026-07-06T06:24:02.6866271Z - Title: Daemon-hosted perches (Psyche, spt-hosted Self) derive liveness from the daemon endpoint table + info.json status, never is_process_alive(info.pid) (2.5)
2026-07-06T06:24:02.6866371Z - Required stages: impl, unit, int
2026-07-06T06:24:02.6866395Z 
2026-07-06T06:24:02.6866503Z ### REQ-HAZARD-BROKER-PROCESS-ISOLATION
2026-07-06T06:24:02.6869176Z - Title: Broker and brain are separate processes: the broker runs as its own long-lived per-machine process that survives every brain restart, so a routine (brain-only) self-update restarts the brain onto the swapped binary while every hosted endpoint (PTY child, live QUIC conn, listening socket) stays untouched at the PROCESS level. The in-process-thread broker (daemon.rs:165-170) is a regression that silently unrealizes REQ-UPD-3 — apply degrades to an in-process Brain::handoff no-op and new code does not run until an unrelated restart (KNOWN-HAZARDS 6.7). Evidence must prove process-level survival (SPIKE-01/03 productionized as int: PTY child + live QUIC survive a brain-PROCESS restart onto a swapped binary), re-pointing the regression-masked in-process int tags currently on REQ-DAEMON-2 / REQ-UPD-3 (ADR-0018).
2026-07-06T06:24:02.6869400Z - Required stages: doc, impl, unit, int
2026-07-06T06:24:02.6869433Z 
2026-07-06T06:24:02.6869544Z ### REQ-HAZARD-ROLLBACK-STATE-COMPAT
2026-07-06T06:24:02.6871185Z - Title: A brain must not irreversibly migrate durable state before update ready-promotion: the readiness-gated auto-rollback (ADR-0018 Q7) spawns the N-1 binary against durable state the new brain may have written, so every pre-ready write must stay N-1-readable (schema migrations gated behind ready-promotion, or written N-1-tolerant/additive). Else the first in-place schema migration silently bricks rollback (KNOWN-HAZARDS 6.8). Free now — a 2026-06-09 audit confirmed zero state-migration code exists; unmintable retroactively once a migration ships.
2026-07-06T06:24:02.6871392Z - Required stages: doc, impl, unit
2026-07-06T06:24:02.6871416Z 
2026-07-06T06:24:02.6871517Z ### REQ-HAZARD-BRAIN-RESPAWN-PATH
2026-07-06T06:24:02.6873937Z - Title: The broker respawns the brain onto the APPLIED bytes, not the renamed old binary: the candidate-binary default is the canonical exe path captured ONCE at broker start, never a per-spawn std::env::current_exe() — on Linux current_exe (readlink /proc/self/exe) is inode-tracking and follows the `apply` rename (spt -> spt.old-N), so a resident broker would respawn the brain onto OLD bytes while recording `applied` (Windows GetModuleFileName is path-at-start, so Windows was green; ADR-0018 Q3 silently assumed path-string semantics). Backstop: promotion gates on bytes — a trial promotes only if brain.ready exe_hash == the staged artifact hash for this platform, else auto-rollback + loud notif (readiness != new-bytes was the false-success that recorded applied:8 over a v0.4.0 brain on kitsubito, 2026-06-11). KNOWN-HAZARDS 6.11.
2026-07-06T06:24:02.6874062Z - Required stages: doc, impl, unit, int
2026-07-06T06:24:02.6874090Z 
2026-07-06T06:24:02.6874198Z ### REQ-HAZARD-PSYCHE-OUTBOUND-PROXY
2026-07-06T06:24:02.6875007Z - Title: Psyche outbound captured + sanitized: the live-Psyche turn driver captures stdout (never Stdio::null), and the daemon strips/re-stamps Psyche-supplied from=/target and constrains routing (reply→__REPLY_TO__ sender, notify→own user/subnet) (7.3)
2026-07-06T06:24:02.6875111Z - Required stages: impl, unit
2026-07-06T06:24:02.6875144Z 
2026-07-06T06:24:02.6875254Z ### REQ-HAZARD-DAEMON-SCHED-NONBLOCKING
2026-07-06T06:24:02.6875878Z - Title: Per-agent pulse/psyche/echo-commune scheduling must not serialize across agents: each agent's bounded LLM call (echo-commune summarizer, Psyche turn) runs off the shared scheduler so one slow/hung call cannot stall another agent's tick (7.4)
2026-07-06T06:24:02.6875984Z - Required stages: impl, unit
2026-07-06T06:24:02.6876017Z 
2026-07-06T06:24:02.6876131Z ### REQ-HAZARD-PAIR-TRANSCRIPT-BIND
2026-07-06T06:24:02.6876760Z - Title: Pairing transcript binds roles, both node pubkeys, subnet ID, seed epoch, TOTP time-step, and confirmation MACs — or unknown-key-share/reflection/wrong-subnet/replay pairing remain possible (ADR-0005 #12)
2026-07-06T06:24:02.6876850Z - Required stages: impl, unit
2026-07-06T06:24:02.6876883Z 
2026-07-06T06:24:02.6876983Z ### REQ-HAZARD-PAIR-SEED-ROTATION
2026-07-06T06:24:02.6877487Z - Title: Removing a node rotates the subnet seed (epoch bump) so an old node/old seed cannot rejoin; trust-store delete alone is NOT revocation because the seed is replicated to every trusted node (ADR-0005 #10)
2026-07-06T06:24:02.6877588Z - Required stages: impl, unit
2026-07-06T06:24:02.6877616Z 
2026-07-06T06:24:02.6877715Z ### REQ-HAZARD-PAIR-RATE-LIMIT
2026-07-06T06:24:02.6878574Z - Title: Subnet-global pairing rate limit: one active ceremony per subnet, shared attempt counter, exponential backoff — a public pre-trust relay + multiple seed-holders otherwise enables distributed SPAKE2 guessing (and ±1 TOTP window triples the valid-password space) (ADR-0005 #11)
2026-07-06T06:24:02.6878765Z - Required stages: impl, unit
2026-07-06T06:24:02.6878799Z 
2026-07-06T06:24:02.6878894Z ### REQ-HAZARD-WAN-ORIGIN-AUTH
2026-07-06T06:24:02.6879765Z - Title: WAN-inbound origin is transport truth, never payload: the access gate's subject (ADR-0009 origin-node whitelist) is the QUIC handshake-proven remote node id from the broker's conn/stream table — a forged origin/node field inside record bytes is inert (7.5)
2026-07-06T06:24:02.6879866Z - Required stages: doc, impl, unit
2026-07-06T06:24:02.6879904Z 
2026-07-06T06:24:02.6879988Z ### REQ-CONSENT-1
2026-07-06T06:24:02.6880852Z - Title: Consent grant store: capability x subject-agent x target-node rows, enforced at the target node, subnet-settable (replicates as security material near the trust store), revocable; gated-capability ids (remote-exec, instantiate-anywhere) reserved-but-refusing; v1 consumers are the shell spawn gates (CONTEXT Consent & security gates)
2026-07-06T06:24:02.6881044Z - Required stages: impl, unit
2026-07-06T06:24:02.6881077Z 
2026-07-06T06:24:02.6881167Z ### REQ-CONSENT-2
2026-07-06T06:24:02.6881957Z - Title: Interactive consent escalation: an ungated high-risk action routes a consent prompt to the user's most-recently-active session; allow-once / allow-always (writes a grant) / deny; pre-consent flags (can_shutdown, shell_wake_spawn_anywhere) author grants via manifest/settings (CONTEXT Consent & security gates)
2026-07-06T06:24:02.6882062Z - Required stages: impl, unit
2026-07-06T06:24:02.6882086Z 
2026-07-06T06:24:02.6882179Z ### REQ-PRES-1
2026-07-06T06:24:02.6883485Z - Title: Presence resolution: the presence datum (last_active_node, last_active_endpoint, ts) gossiped subnet-wide via the agent-interaction heartbeat (rides registry distribution, visibility-gated) + one first-class most-recently-active resolution API consumed by notif first-fire, update-consent delivery, consent escalation, and shell wake resolution (M5 scope decision 1: resolution only — the PresenceChannel endpoint stays deferred)
2026-07-06T06:24:02.6883596Z - Required stages: impl, unit, int
2026-07-06T06:24:02.6883625Z 
2026-07-06T06:24:02.6883710Z ### REQ-SHELL-1
2026-07-06T06:24:02.6884560Z - Title: Shell hosting machinery: shell perch under the owner (type/owner/adapter_name/status/alias), broker-launched binary + api bind local-link handshake, the three channels (command durable, text+file durable + progress-queryable, sensory REST-only never spooled + dropped-unless-owner-live), owner exclusivity (CONTEXT Shell model)
2026-07-06T06:24:02.6884659Z - Required stages: impl, unit, int
2026-07-06T06:24:02.6884687Z 
2026-07-06T06:24:02.6884772Z ### REQ-SHELL-2
2026-07-06T06:24:02.6886196Z - Title: Shell sleep/wake: link-break always closes the binary (pre-close instruction + termination timeout), ephemeral teardown vs persistent offline/relink, wake_command wake-watcher (offline-only, exit-opcode supervision, exponential backoff + give-up), state-keyed wake resolution (dormant/suspended/active-elsewhere; no-reachable refuses — spawn-anywhere branch deferred), spt shutdown owner cascade + api owner-shutdown gated by can_shutdown (CONTEXT Shell sleep/wake)
2026-07-06T06:24:02.6886310Z - Required stages: impl, unit, int
2026-07-06T06:24:02.6886343Z 
2026-07-06T06:24:02.6886443Z ### REQ-HAZARD-ELEVATED-DAEMON-SPAWN
2026-07-06T06:24:02.6887712Z - Title: The daemon always runs unelevated in the invoking user's universe, regardless of which command spawns it: an elevated spawner de-elevates (Windows: UAC linked token via CreateProcessWithTokenW; Linux: drop to SUDO_UID/SUDO_GID + the invoker's HOME) — an elevated daemon's pipes deny unelevated clients (every later spt reads not-running→spawn→bind Access-denied) and a sudo'd daemon roots the user's state universe (5.7)
2026-07-06T06:24:02.6887814Z - Required stages: doc, impl, unit
2026-07-06T06:24:02.6887947Z 
2026-07-06T06:24:02.6888057Z ### REQ-HAZARD-REGISTRY-GHOST-ROWS
2026-07-06T06:24:02.6891216Z - Title: Registry rows must decay (no immortal rows) via TWO triggers: (a) NODE-SILENCE — evict rows whose author node has not been heard (admitted inbound feed) within the eviction window, so a vanished node's rows stop poisoning bare-id resolution with phantom AcrossNodes ambiguity; AND (b) per-row OFFLINE-TTL — evict rows that have been non-routable (Offline) beyond the per-row grace even while the author node is alive, because purge/erase leaves an immortal Offline row otherwise (ghost-heal re-advertises Offline ONCE with a fresh epoch, and whole-node eviction never fires for a still-alive author) so Offline ghost rows accumulate unbounded on a remote viewer under purge/erase churn (#2-secondary). Both keyed on RECEIVER-observed state (heard-map recency / a sticky receiver-observed offline_since, NOT the gossip epoch — an epoch-keyed clock would be reset by ghost-heal's fresh-epoch re-advertise); own rows never decay; a revived/re-flapped row re-inserts (or clears its offline_since) from its durable epoch within one pump cadence (4.10)
2026-07-06T06:24:02.6891431Z - Required stages: doc, impl, unit
2026-07-06T06:24:02.6891465Z 
2026-07-06T06:24:02.6891541Z ### REQ-CLI-1
2026-07-06T06:24:02.6893937Z - Title: spt endpoint noun namespace: absorbs fork/suspend/wake/shutdown/rename/stop/digest + access (ported 1:1: allow|revoke|open|list, decision 21) + description (ex-resources blurb; bare=show, set=author); merged endpoint list [--local|--subnet <name>] grouped by subnet with SELF pinned, --detail adding the ex-resources yellow-pages blurb projection; bare spt endpoint = the list (M8 decisions 1-2, 25). SUPERSEDED (F-025 item 3): the LISTING SHAPE now lives in REQ-ENDPOINT-LIST-NODE-GROUPED (node-grouped over unique instances, not grouped-by-subnet) + REQ-ENDPOINT-LIST-REST-FILTER (suspended-hidden + --show-all); the `--local` flag was dropped by REQ-ENDPOINT-LIST-MERGE-LOCAL (the list ALWAYS merges local). This REQ owns only the endpoint noun NAMESPACE + parse surface — not the render shape.
2026-07-06T06:24:02.6894046Z - Required stages: impl, unit
2026-07-06T06:24:02.6894069Z 
2026-07-06T06:24:02.6894151Z ### REQ-CLI-2
2026-07-06T06:24:02.6894824Z - Title: spt daemon noun: run|stop|status (hidden daemon verb becomes daemon run; agent-endpoint shutdown keeps its name under endpoint); daemon status renders the pump heartbeat (last-tick recency) so a half-dead daemon is never rendered implied-healthy (M8 decisions 5, 23)
2026-07-06T06:24:02.6894923Z - Required stages: impl, unit
2026-07-06T06:24:02.6894956Z 
2026-07-06T06:24:02.6895042Z ### REQ-CLI-3
2026-07-06T06:24:02.6895730Z - Title: Agent hot path stays flat across the M8 reorg: send/ring/ready/whoami/how-to unchanged; notify moves to subnet notify while notif stays top-level; breaking renames land clean with no deprecation shims (zero external CLI consumers pre-spt-claude-code) (M8 decisions 3-4, 9)
2026-07-06T06:24:02.6895840Z - Required stages: impl, unit
2026-07-06T06:24:02.6895874Z 
2026-07-06T06:24:02.6895963Z ### REQ-CLI-4
2026-07-06T06:24:02.6898008Z - Title: User-facing CLI output is human-readable: DIRECT-USER commands (e.g. adapter update/list/use) render friendly prose instead of raw CODE:RESULT markers — "claude-spt is up to date (0.2.0)." not "ADAPTER_UPDATE_UPTODATE:claude-spt: installed 0.2.0, latest 0.2.0". Strictly bounded to the direct-user surface: the adapter-PARSED bringup tokens (SEEDED/BOUND/READY/NO_SEED on seed/listen, which adapters grep) stay machine-parseable — humanization is additive (a human line beside the marker, or a --porcelain/--quiet split), never a silent rename of a dual-contract marker. The user-facing bringup composition belongs to the adapter (perri); this REQ owns only the direct-user CLI surface. (v0.9.0)
2026-07-06T06:24:02.6898108Z - Required stages: 
2026-07-06T06:24:02.6898140Z 
2026-07-06T06:24:02.6898221Z ### REQ-SUBNET-5
2026-07-06T06:24:02.6899384Z - Title: Per-subnet serve-state: spt subnet detach <NAME> [--save] / attach <NAME> [--save] — daemon keeps running, stops/starts advertising + connecting for that subnet (peer pump + responder selective); --save persists the startup default in daemon config; the all-attached banner gains per-subnet states (M8 decision 6, --save renamed from --auto per decision 25 session)
2026-07-06T06:24:02.6899590Z - Required stages: impl, unit, int
2026-07-06T06:24:02.6899624Z 
2026-07-06T06:24:02.6899704Z ### REQ-SUBNET-6
2026-07-06T06:24:02.6900361Z - Title: Trust lifecycle verbs, elevation-gated: spt subnet leave <NAME> (membership exit) and spt subnet prune <node> (removes a dead identity's trust + registry rows, killing its dead dials; trust mutation = security surface, REQ-PAIR-6 gate machinery) (M8 decisions 6-7)
2026-07-06T06:24:02.6900457Z - Required stages: impl, unit
2026-07-06T06:24:02.6900481Z 
2026-07-06T06:24:02.6900568Z ### REQ-SUBNET-7
2026-07-06T06:24:02.6902174Z - Title: Per-machine re-pair trust overwrite: registry rows carry a hashed stable machine identifier (OS machine id /etc/machine-id|MachineGuid, domain-separated SHA-256 before gossip, spt-minted persisted UUID fallback; additive serde-default field — old rows parse clean); a COMPLETED pairing ceremony presenting the same node label AND machine id as an existing trusted row evicts the superseded identity's trust + registry rows on the seed-holder and replicates the eviction; a gossiped claim alone never evicts trust (M8 decisions 13, 22)
2026-07-06T06:24:02.6902397Z - Required stages: impl, unit
2026-07-06T06:24:02.6902415Z 
2026-07-06T06:24:02.6902508Z ### REQ-SUBNET-8
2026-07-06T06:24:02.6903605Z - Title: Status render honesty: zero-subnet text is daemon-aware ('No subnets registered — this node is standalone.' + daemon-running-dependent blurb, never implying messaging works while the daemon is down); hint footer prints on bare spt subnet only (status drops it); a stalled pump is surfaced in subnet status, never rendered implied-healthy (M8 decisions 11-12, 23)
2026-07-06T06:24:02.6903699Z - Required stages: impl, unit
2026-07-06T06:24:02.6903724Z 
2026-07-06T06:24:02.6903820Z ### REQ-INSTALL-6
2026-07-06T06:24:02.6904973Z - Title: Linux elevation install leg: install.sh symlinks the binary into a sudo-reachable path (/usr/local/bin; graceful print-the-one-liner when unelevated) so sudo spt resolves; first sudo spt detects elevation and prompts ONCE for the default user account — thereafter any elevated daemon launch runs daemon + state under that account, never root (KH 5.7 interplay verified) (M8 decision 8)
2026-07-06T06:24:02.6905079Z - Required stages: impl, unit
2026-07-06T06:24:02.6905108Z 
2026-07-06T06:24:02.6905197Z ### REQ-INSTALL-7
2026-07-06T06:24:02.6906271Z - Title: Windows inbound reachability: the elevated install leg registers the inbound-UDP firewall rule (New-NetFirewallRule); the daemon self-detects blocked inbound and renders it as the no-connection state in subnet status + the coming-online banner (covers user-scope installs that skip the elevated leg — never a silent NO_SEED_HOLDER dead-end) (M8 root cause 3)
2026-07-06T06:24:02.6906382Z - Required stages: impl
2026-07-06T06:24:02.6906410Z 
2026-07-06T06:24:02.6906505Z ### REQ-INSTALL-8
2026-07-06T06:24:02.6907511Z - Title: OS-service registration (REQ-INSTALL-1's deferred third leg): Linux systemd USER service + loginctl enable-linger (linger rides the elevated install leg; daemon starts at boot pre-login, user universe per KH 5.7, systemctl --user managed); Windows scheduled task at-logon (interactive session, no stored credentials); a node is reachable after reboot without any manual spt invocation (M8 decision 17)
2026-07-06T06:24:02.6907598Z - Required stages: impl
2026-07-06T06:24:02.6907631Z 
2026-07-06T06:24:02.6907716Z ### REQ-CONV-1
2026-07-06T06:24:02.6909152Z - Title: Peer address seeding, both cold starts: durable peer-addrs.json (identity dir) maps peer pubkey → last-known dialable address; the pump's resolver consults it FIRST with id-only discovery fallback on miss or dial failure (a stale addr never strands a peer); written by the pairing ceremony (both sides, from the live connection) and by the pump on successful connect; post-join first sync and post-restart resync converge in seconds, not ~1 min (M8 decisions 14, 20)
2026-07-06T06:24:02.6909358Z - Required stages: impl, unit
2026-07-06T06:24:02.6909386Z 
2026-07-06T06:24:02.6909467Z ### REQ-CONV-2
2026-07-06T06:24:02.6910551Z - Title: Event-driven advertisement: endpoint online/offline transitions (ready-listener start/stop, rest-state transition, perch death) trigger an immediate advertise_local + peer push as a WAKE of the existing pump loop (no second advertisement path — epoch lease + visibility gates ride unchanged); the cadence stays the steady-state floor (M8 decision 15)
2026-07-06T06:24:02.6910645Z - Required stages: impl, unit
2026-07-06T06:24:02.6910679Z 
2026-07-06T06:24:02.6910765Z ### REQ-PAIR-8
2026-07-06T06:24:02.6911998Z - Title: NTP TOTP offset: the pairing ceremony queries NTP at ceremony time (both sides) and applies the derived offset to the TOTP calculation in-process only; system-clock fallback when NTP is unreachable (offline LAN pairing unaffected — NTP failure never blocks a pairing that succeeds today); never sets the OS clock; no background sync loop (M8 decision 18; field trigger: enlyzeam clock >1 min off exceeds the ±1 window)
2026-07-06T06:24:02.6912190Z - Required stages: impl, unit
2026-07-06T06:24:02.6912223Z 
2026-07-06T06:24:02.6912313Z ### REQ-DAEMON-5
2026-07-06T06:24:02.6913557Z - Title: Pump liveness: the peer pump writes a last-tick heartbeat consumed by daemon status / subnet status (decision 23 render legs in REQ-CLI-2/REQ-SUBNET-8); the daemon supervises the pump task — a panic is caught, logged loudly, and the pump restarts with capped backoff (≤5 min), so a 5.9-class death self-heals visibly instead of silently halving the daemon (M8 decision 23; field motivation: hfenduleam 2026-06-07 half-death)
2026-07-06T06:24:02.6913652Z - Required stages: impl, unit
2026-07-06T06:24:02.6913685Z 
2026-07-06T06:24:02.6913775Z ### REQ-DAEMON-6
2026-07-06T06:24:02.6915663Z - Title: Service-aware `daemon start`/`stop`: when an OS service manager has a registered spt-daemon for this user, `spt daemon start` and `spt daemon stop` drive THAT service (so stop doesn't IPC-kill a unit that auto-restart-fights for the broker socket — the kitsubito 2026-06-08 loop). `start` graduates from a `run` alias to a first-class background verb (ensure-up, idempotent, non-blocking); stop routes managed→manager, manual→IPC. Linux=systemd user unit (`systemctl --user start|stop|is-active spt-daemon`, detected by unit-file presence); Windows=no controllable manager (the logon task is boot-only), so start=detached spawn / stop=IPC.
2026-07-06T06:24:02.6915771Z - Required stages: impl, unit
2026-07-06T06:24:02.6915801Z 
2026-07-06T06:24:02.6915891Z ### REQ-DAEMON-7
2026-07-06T06:24:02.6917238Z - Title: `daemon run` is foreground-consistent on every platform: the invoking process IS the daemon, blocks until signalled, never auto-detaches or respawns into an invisible background task. The detached/de-elevated background behavior lives ONLY in `start`. Windows: an ELEVATED `daemon run` refuses with guidance (use `start`, or an unelevated shell) instead of respawning detached/de-elevated and vanishing (KH 5.7 preserved — it still never serves elevated).
2026-07-06T06:24:02.6917347Z - Required stages: impl, unit
2026-07-06T06:24:02.6917380Z 
2026-07-06T06:24:02.6917465Z ### REQ-DAEMON-8
2026-07-06T06:24:02.6918385Z - Title: Internal auto-start prefers the service: `ensure_running` (any spt command's implicit daemon start, REQ-DAEMON-3) routes through the service-aware start path — when a manager has a registered service it starts THAT, never a competing manual `spawn_detached` daemon that would fight the service for the socket.
2026-07-06T06:24:02.6918487Z - Required stages: impl, unit
2026-07-06T06:24:02.6918511Z 
2026-07-06T06:24:02.6918591Z ### REQ-DAEMON-9
2026-07-06T06:24:02.6920938Z - Title: Net-bind boot-race resilience: a daemon that comes up net-less (NetHost::start failed — e.g. the systemd unit autostarted before the network/DNS stack was ready, `Failed to create an address lookup service`) must SELF-HEAL — retry the net bring-up in the background with capped backoff and, on success, attach net to the broker + spawn the dispatcher/peer-pump (which today are gated on `net_up` at boot and so never start, leaving the node silently unreachable until a manual restart — kitsubito 2026-06-08). Status surfaces the net-less state honestly (a net-less broker renders as 'no connection', not only a pump-STALLED line with a bogus pre-boot heartbeat age). The installer's autostart unit waits for the network (`Wants=/After=network-online.target`) as belt-and-suspenders.
2026-07-06T06:24:02.6921153Z - Required stages: impl, unit
2026-07-06T06:24:02.6921181Z 
2026-07-06T06:24:02.6921287Z ### REQ-HAZARD-LIVEHOST-BOOT-RACE
2026-07-06T06:24:02.6924863Z - Title: The brain's daemon-hosted Psyche lifecycle surfaces a host-FAILURE on the live perch (harness-diagnosable) and runs net-INDEPENDENTLY. When reconcile_once→host_one→spawn_psyche fails for a state=live_agent+status=online endpoint (e.g. the adapter's psyche binary absent from its install dir, REQ-INSTALL-11), the failure MUST be written to the perch info.json as a CURRENT-STATE field (reason + ts + attempt count; overwritten each 5s retry, CLEARED on successful host) and surfaced by `spt endpoint list`/status — never left as an eprintln on the brain's invisible stderr where a harness reading only perch state is blind. status=online stays authoritative (agent reachable; only the Psyche is missing — brain-restart rehydrate legitimately has online-without-Psyche windows), so this is a SEPARATE psyche-host-health field, never a status de-stamp. Net-independence is a locked-in invariant: spawn_live_host (brainproc.rs:230) reaches the reconcile and hosts the Psyche on a net-less/unpaired/peer-pump-STALLED node, proven by a REAL detached-daemon E2E (real broker→brain-child, real api seed+listen, real install-dir psyche binary). spt-core SURFACES the failure; the adapter owns fixing its packaging.
2026-07-06T06:24:02.6925082Z - Required stages: impl, unit
2026-07-06T06:24:02.6925111Z 
2026-07-06T06:24:02.6925217Z ### REQ-HAZARD-TEMPLATE-ARGV-FILL
2026-07-06T06:24:02.6929085Z - Title: Command-template substitution fills argv ELEMENTS, not a re-tokenized string: spt-core currently `fill_template`s {key} values INTO the command STRING and THEN `tokenize`s the filled string (runtime.rs:94/122), so a multi-word {key} value whitespace-SPLITS into multiple argv tokens unless the adapter hand-quotes the placeholder, and a value containing a `"` (or `;`) injects/breaks tokenization (shell-injection-adjacent). A filled value MUST become exactly ONE argv element regardless of spaces/quotes in the value. Fix: tokenize the TEMPLATE into argv FIRST, then `fill_template` EACH token, so a `{key}` slot resolves to a single element and the value never participates in tokenization (no whitespace-split, no quote/semicolon injection); preserve the missing-key / empty-command errors and `{{`/`}}` non-interpretation. perri's F-009 (v0.8.1 dogfood, argv-capture-confirmed): a multi-word `{psyche_prompt}` = "PSYCHE REVIVAL time: epoch-ms:… incoming event: (none)" arrived as argv[6..12] (7 stray tokens), the harness runner strict-parsed `--prompt` against the 2nd word, exited 2 within ~1s → phantom hosted perch. Applies to EVERY [session.<role>] template (psyche_init, extractor, notif, …); digest survives today only because its fills ({session_id}/{source}) are single-token.
2026-07-06T06:24:02.6929203Z - Required stages: impl, unit, int
2026-07-06T06:24:02.6929237Z 
2026-07-06T06:24:02.6929343Z ### REQ-HAZARD-LIVEHOST-NONRESIDENT
2026-07-06T06:24:02.6932604Z - Title: A daemon-hosted Psyche that spawns then EXITS IMMEDIATELY is a host failure, surfaced like a spawn failure (closes the v0.8.1 residual masking): the REQ-HAZARD-LIVEHOST-BOOT-RACE signal stamps `psyche_host_error` only when `spawn_psyche` returns Err, NOT when the detached spawn() returns Ok but the child dies within moments (e.g. a bad-argv child exiting 2 — the F-009 case). That leaves the residual 'online + no Psyche + no cause' gap: the nested `{id}-psyche` info.json is written status=online with a real-but-DEAD pid and the PARENT perch carries NO psyche_host_error (perri's F-010: tasklist showed 0 host procs across the window while info.json read online). The host MUST confirm RESIDENCY — a hosted child not alive (or whose `{id}-psyche` perch never re-registers / has a dead pid) within N seconds of spawn is treated as a host failure: stamp the parent perch `psyche_host_error{reason:"host not resident within <n>s (psyche perch missing/dead pid)"}` (and do not leave a phantom online nested perch). Closes the last masking gap the v0.8.1 fix left open. perri's F-010 (v0.8.1 dogfood). Sibling of REQ-HAZARD-LIVEHOST-BOOT-RACE.
2026-07-06T06:24:02.6932813Z - Required stages: 
2026-07-06T06:24:02.6932851Z 
2026-07-06T06:24:02.6932948Z ### REQ-HAZARD-EPOCH-RESET
2026-07-06T06:24:02.6934244Z - Title: Advertisement-epoch reset strands a node: peers' higher last-seen epoch drops the reset node's fresh advertisements as Stale until the counter outruns history. Common case (full reinstall/re-pair) is mitigated by REQ-SUBNET-7's ceremony eviction (peer-side epoch memory dies with the deleted row — acceptance-verified); the residual narrow slice (epoch file lost, identity kept) is documented, guard deferred to a field hit (4.11)
2026-07-06T06:24:02.6934435Z - Required stages: 
2026-07-06T06:24:02.6934469Z 
2026-07-06T06:24:02.6934555Z ### REQ-MESH-1
2026-07-06T06:24:02.6936610Z - Title: Membership proof (seed-proof): symmetric current-epoch seed-knowledge replaces is_trusted at EVERY inbound gate (registry apply, WAN receive, sync, notif, connection accept). MK = HKDF(seed, domain ‖ subnet_id ‖ seed_epoch); mutual channel-bound challenge-response at connect (transcript binds both handshake-proven node pubkeys, both nonces, subnet_id, seed_epoch, role); verified once per connection, cached on the broker ConnEntry, kept warm via QUIC keep-alive so re-proof is restart/partition/rotation-only. Exact-epoch match (re-seed is the sole N-1 exception). SECURITY INVARIANTS: channel-bound (no cross-connection replay), mutual, accepts a member it never paired (the mesh property).
2026-07-06T06:24:02.6936721Z - Required stages: impl, unit, int
2026-07-06T06:24:02.6936745Z 
2026-07-06T06:24:02.6936834Z ### REQ-MESH-2
2026-07-06T06:24:02.6939463Z - Title: Member roster: node-level union-merge grow-set (per member: pubkey, label, machine_id, last-known address, last-seen — NOT the seed), the discovery directory the mesh dials by. Seeded IN FULL at pairing (seed-holder hands joiner the whole current roster, incl. offline members — folds in deferred pairing-time hostname capture + post-join address seeding); each node authors its own entry stamped with its lease_epoch, merged strictly-greater-wins (the node_label lease); exchanged only over seed-proof'd member connections; forgery-inert (a fake entry names a pubkey that still can't seed-proof). Removal needs a TOMBSTONE — a per-pubkey revoked marker that propagates, dominates the entry, gates admission (seed-proof ∧ ¬tombstoned), and prevents reinsert; cleared by a completed re-pair of that pubkey. Persists through silence (offline member keeps its entry).
2026-07-06T06:24:02.6939578Z - Required stages: impl, unit, int
2026-07-06T06:24:02.6939603Z 
2026-07-06T06:24:02.6939698Z ### REQ-MESH-3
2026-07-06T06:24:02.6941319Z - Title: Mesh row fan-out: registry rows stay OWN-AUTHORED; the only change is the push target widens from directly-paired peers to ALL roster members (a wider DIRECT fan-out, never a third-party relay). Every row/message still arrives from its author over a handshake → KNOWN-HAZARDS 7.5 (origin = handshake node) and 4.10 (eviction lease: any future update comes from that node itself, alive) PRESERVED VERBATIM. Closes the staggered A→B→C repro: C (roster-seeded with A at pairing) initiates to A, seed-proof admits C unpaired, A learns C, both push directly.
2026-07-06T06:24:02.6941559Z - Required stages: impl, unit, int
2026-07-06T06:24:02.6941587Z 
2026-07-06T06:24:02.6941682Z ### REQ-MESH-4
2026-07-06T06:24:02.6943837Z - Title: Revoke + timeboxed seed rotation + re-seed grace: `spt subnet revoke <node>...` (list, elevation-gated, revoke-only) writes roster tombstones immediately, then schedules ONE seed rotation (re-mint seed, bump seed_epoch, push new seed CONFIDENTIALLY over member-auth'd TLS connections — never in roster/registry gossip — force-drop revokees) at the close of a coalescing window (default 1h); further revokes in the window join the same rotation (one epoch bump). `--force-rotate-seed` rotates immediately (compromised-node path). RE-SEED GRACE: a node proving the immediately-prior epoch (N-1) AND still on the roster gets a re-seed-only restricted connection (auto-heals a benign offliner); revoked/off-roster denied; ≥2 stale → re-pair.
2026-07-06T06:24:02.6943946Z - Required stages: impl, unit, int
2026-07-06T06:24:02.6943969Z 
2026-07-06T06:24:02.6944060Z ### REQ-MESH-5
2026-07-06T06:24:02.6945525Z - Title: Hard cutover from pairwise trust: delete peers.json + the is_trusted authorization path (no migration — expendable test fleet, re-pairs fresh under the new model, user decision 2026-06-08). Warn-on-change DEMOTED from a gate to an awareness notice anchored on machine_id (not label): 'machine M, last seen as K1, now presents K2' — fires the same event as the REQ-SUBNET-7 re-pair overwrite. The TrustStore/peers.json code and its call sites are removed, not left dead.
2026-07-06T06:24:02.6945639Z - Required stages: impl, unit
2026-07-06T06:24:02.6945669Z 
2026-07-06T06:24:02.6945760Z ### REQ-MESH-6
2026-07-06T06:24:02.6947000Z - Title: Concurrent liveness probes: `spt subnet status --nodes` fans out its offline/serve-probes (REQ-SUBNET-5) CONCURRENTLY — total wall-time bounded by the single-probe ceiling (~3s), never k×ceiling. The mesh makes a node see ALL members (many possibly offline), so a serial probe loop would be offline_count×3s. (Planning verifies the current REQ-SUBNET-5 probe loop's behavior and fixes it if serial.)
2026-07-06T06:24:02.6947118Z - Required stages: impl, unit
2026-07-06T06:24:02.6947146Z 
2026-07-06T06:24:02.6947232Z ### REQ-SHELL-3
2026-07-06T06:24:02.6949098Z - Title: Drive channel (owner->shell, REST-only, never-spooled, latest-wins): the owner->shell mirror of sensory for continuous real-time control (scroll/crank/stick/avatar) — a [shell.drive] manifest vocab + EVENT_TYPE_DRIVE frame, delivered to the ONLINE binary only via a single live slot (a new frame supersedes an undelivered one — no spool, no queue, no replay on relink), dropped-with-diagnostic if the shell is offline; cross-node rides the ephemeral link (REST class), never the durable shell spool. Commands = discrete+durable; drive = continuous+ephemeral (CONTEXT:260, minted 2026-06-11 Gateway grill).
2026-07-06T06:24:02.6949209Z - Required stages: impl, unit, int
2026-07-06T06:24:02.6949237Z 
2026-07-06T06:24:02.6949328Z ### REQ-SHELL-4
2026-07-06T06:24:02.6951083Z - Title: Shell tunnel (reliable-ordered opaque byte stream): an owner<->shell link may hold a long-lived, reliable-ordered, link-bound QUIC stream pair carrying opaque wire protocol traffic the channel taxonomy must NOT reinterpret (first consumer usbip URB) — manifest opt-in, not enveloped, not MAC-framed, not spooled; the link lifecycle governs it (a link-break closes the tunnel). Reliable-ordered ⇒ congestion surfaces as lag never loss ⇒ acceptable only on-LAN: the on-LAN posture is documented and the tunnel is NOT proven cross-WAN (CONTEXT:262, minted 2026-06-11 Gateway grill; doyle gate C2).
2026-07-06T06:24:02.6951208Z - Required stages: doc, impl, unit, int
2026-07-06T06:24:02.6951237Z 
2026-07-06T06:24:02.6951326Z ### REQ-CONSENT-3
2026-07-06T06:24:02.6953139Z - Title: Per-capability approval gates (class-keyed): the require_approval enum may ride INDIVIDUAL [shell.capabilities] entries — gating the dangerous ACT, not just the spawn — with an optional class_key scoping the grant qualifier finer than the capability id ((owner endpoint x device class x node); a remembered HID-class attach grant never authorizes a storage-class attach). Reuses the grant store + interactive escalation + tighten-only floor (REQ-CONSENT-1/2 plumbing). Spawn gates govern EXISTENCE; capability gates govern ACTS — an explicitly distinct invariant (CONTEXT:283, ratified 2026-06-11 Gateway grill).
2026-07-06T06:24:02.6953359Z - Required stages: doc, impl, unit, int
2026-07-06T06:24:02.6953387Z 
2026-07-06T06:24:02.6953477Z ### REQ-SHELL-5
2026-07-06T06:24:02.6954669Z - Title: Shell ownership is owner-type-agnostic: any non-Shell endpoint type may own/spawn/drive/command/link a shell (Gateway the named first) — control-exclusivity keys on the owner endpoint_id, NEVER on the owner's endpoint type. No ownership path (mint, launch, owner-from-link, cmd, drive, tunnel, sleep/wake, owner-shutdown) inspects the owner's type (CONTEXT:264, ratified 2026-06-11 Gateway grill).
2026-07-06T06:24:02.6954787Z - Required stages: doc, impl, unit, int
2026-07-06T06:24:02.6954916Z 
2026-07-06T06:24:02.6955027Z ### REQ-HAZARD-VIEWER-CLOSE-DETACH
2026-07-06T06:24:02.6964881Z - Title: A VIEW is independent from the endpoint: closing the tab/window where `spt endpoint run` was invoked must detach ONLY the `spt rc` attach pump — the daemon-hosted harness keeps running and stays re-attachable via `spt rc <id>`. ROOT (Windows, v0.12.0 real-harness defect): the daemon never breaks away from the launching terminal's Job Object. Windows Terminal / VS Code place the launched shell AND every descendant into a Job Object with JOB_OBJECT_LIMIT_KILL_ON_JOB_CLOSE; closing the tab drops the terminal's last job handle → the OS terminates every process still in that job. A child escapes only with CREATE_BREAKAWAY_FROM_JOB — used NOWHERE in the tree. Both daemon spawn paths (daemon.rs:707 detached_no_inherit = DETACHED_PROCESS|CREATE_NEW_PROCESS_GROUP|CREATE_NO_WINDOW; deelevate.rs:519 elevated = CREATE_NEW_CONSOLE|...) drop the CONSOLE but NOT job membership, so the daemon's freshly broker-spawned ConPTY harness subtree is reaped on tab-close. The ConPTY/pseudoconsole isolation itself is CORRECT (portable-pty builds the pseudoconsole in the daemon; no console signal / handle leak) — the leaking lifetime binding is the Job Object, not the console. FIX: add CREATE_BREAKAWAY_FROM_JOB to both daemon spawn paths AND pin each broker-spawned harness into a DAEMON-OWNED Job Object (mirror reap.rs/Breap) as backstop (survives even where a terminal sets SILENT_BREAKAWAY_OK=false). Unix: the daemon's own session detachment (new session, no controlling terminal) already keeps a closing terminal's SIGHUP off its children — verify, add a guard test, no code expected. FIX UPDATE (v0.12.1 L1.5, doyle re-scope operator-approved 2026-06-18): job-neutral daemon launch is now PRIMARY, breakaway DEMOTED to a fallback rung. ROOT reframed — the daemon INHERITS the terminal's Job because spawn_detached runs FROM the terminal-child CLI (DETACHED_PROCESS detaches the console, not the job); breakaway tried to claw back out but a job CAN deny it (the L1 finding). FIX: launch the cold-started daemon via a job-NEUTRAL creator so it is WmiPrvSE/Task-Scheduler-owned, OUTSIDE any terminal job from birth (why Task-Scheduler-autostarted daemons never had this bug). Launcher ladder (first-success-wins, daemon.rs spawn_detached → BOTH cold-start AND `spt daemon start`): (1) WMI Win32_Process.Create via ABSOLUTE powershell -EncodedCommand (KH 5.12 abs path; base64-UTF16LE dodges all quoting; success requires BOTH ReturnValue==0 AND a parsed ProcessId, else fall-through — never a silent launched), forwarding SPT_* env via a `cmd /c set … & start /b` wrapper because a WMI/scheduler child does NOT inherit transient shell env (verified — SPT_HOME would be lost, wrong universe); (2) schtasks one-shot (same env wrapper; best-effort fallback); (3) CREATE_BREAKAWAY_FROM_JOB (the L1 code, reordered below); (4) in-job last resort (logs DETACH_IN_JOB + tab-close caveat). detached_no_inherit (breakaway-then-in-job) is UNCHANGED for its other caller shellhost::launch_shell (a daemon-spawned shell is already job-neutral once the daemon is). The elevated deelevate path keeps its L1 breakaway for now (elevated-case WMI-reparent = FOLLOW-UP). (v0.12.1)
2026-07-06T06:24:02.6965229Z - Required stages: doc, impl, unit, int
2026-07-06T06:24:02.6965262Z 
2026-07-06T06:24:02.6965347Z ### REQ-HAZARD-ATTACH-WEDGE
2026-07-06T06:24:02.6970729Z - Title: A legitimately dead PTY child (real crash/kill) + an undrained operator pump must NOT wedge the broker for all other clients. ROOT (v0.12.0 real-harness defect): loopback attach output is a blocking write_all into a bounded 64KB tokio duplex (nethost.rs:1040,1090); when the operator's rc pump stops draining (tab closed) the buffer fills and write_all blocks forever (the 'loopback never hangs' assumption at nethost.rs:1103 is false), parking a worker in the 2-worker net runtime (nethost.rs:640); a couple of these saturate BOTH workers → every new attach / `endpoint run` stalls right after 'PUMP_IPC_READER: spawned' → 30s FIRST_EVENT_GRACE → 'no output / dead or wedged'; `daemon stop` cannot join the stuck workers. DISTINCT from the removed B1 path-(c) mutex deadlock. DISPOSITION = PROVE-DON'T-CHANGE (doyle GATE-PASS @e883f45, 2026-06-18): this ROOT is the SUPERSEDED v0.12.0 hypothesis — the post-L0 code ALREADY prevents the wedge, so NO fail-fast / worker-count code was added. serve_attach forwards fire-and-forget (net_stream_send op_id=None) and the broker-side send_stream is already BROKER-QUIC-DEADLINE-bounded (bounded_block_on, 10s); the loopback duplex is drained broker-INTERNALLY by the operator row's own read pump (RecvHalf::Loopback, retentive_cap==0 → evict-not-park) so a dead rc (a dropped IPC subscriber) never backs peer_w up; bounded_block_on parks the BROKER DISPATCH thread, not a net worker → no worker-pool exhaustion (full mechanism in the required_stages comment). Folds the status=online sub-check: a dead spt-hosted endpoint is marked OFFLINE within one reconcile tick on abrupt child death (broker exit-waiter reaps the session → B2 sees it absent) — PROVEN, no change. (v0.12.1)
2026-07-06T06:24:02.6970848Z - Required stages: int
2026-07-06T06:24:02.6970886Z 
2026-07-06T06:24:02.6970992Z ### REQ-PICKER-HISTORY-FRESH
2026-07-06T06:24:02.6972075Z - Title: The `spt endpoint run` picker shows project history for FRESH endpoints (operator-raised v0.12.0 real-harness finding). Symptom: a fresh endpoint shows no project history in the picker. ROOT TBD — investigate the project-history loader (v0.10.0 PICKER-2, picker/data.rs) before fixing: distinguish a real loader bug from 'fresh = no history yet' semantics. (v0.12.1)
2026-07-06T06:24:02.6972179Z - Required stages: impl, unit
2026-07-06T06:24:02.6972213Z 
2026-07-06T06:24:02.6972314Z ### REQ-PICKER-ONLINE-ACTION
2026-07-06T06:24:02.6973835Z - Title: The `spt endpoint run` picker shows the correct action for an ALREADY-ONLINE endpoint — Attach, NOT 'Start now' (operator-raised v0.12.0 real-harness finding). Symptom: the picker offers 'Start now' for endpoints that are already online. ROOT TBD — investigate the status→action mapping (v0.10.0 PICKER-1 four-state status, picker/model.rs): is it reading live/online state correctly, or rendering stale/wedged broker state (i.e. partly a symptom of the broker wedge / status=online latch)? Fix so online → Attach. (v0.12.1)
2026-07-06T06:24:02.6974054Z - Required stages: impl, unit
2026-07-06T06:24:02.6974087Z 
2026-07-06T06:24:02.6974179Z ### REQ-ENDPOINT-LIST-MERGE-LOCAL
2026-07-06T06:24:02.6975937Z - Title: `spt endpoint list` always merges this node's LOCAL (unadvertised) perches into the view; the `--local` flag is REMOVED (operator decision 2026-06-17). Rationale: `spt whoami` is a thin alias of `endpoint list` — a just-online agent running `whoami` must see its OWN perch, or it gets an omitted-self view ('chaos'). FIX: drop the `--local` flag + its `--detail` conflict test + the v0.10.0 REQ-PICKER-5 hint line (cli.rs:1678) + cmd_list_local; the bare list merges local perches into the subnet view; fix the whoami alias path accordingly. Run `cargo run -p xtask -- gen` (docs-drift, DEFAULT target). (v0.12.1)
2026-07-06T06:24:02.6976147Z - Required stages: doc, impl, unit
2026-07-06T06:24:02.6976180Z 
2026-07-06T06:24:02.6976294Z ### REQ-HAZARD-ENDPOINT-RUN-ATTACH-OUTPUT
2026-07-06T06:24:02.6981398Z - Title: A clean `spt rc` attach to a LIVE spt-hosted (`endpoint run`) harness must DELIVER the harness's PTY output. KEYSTONE — the operator's central 'attach shows no output' symptom, reproduced on the real dummy-harness fixture (v0.12.1 Wave 1) with NO death and NO wedge: bringup succeeds (online, harness pid alive + heartbeating, psyche hosted), the attach CONNECTS (PUMP_IPC_READER spawned, no RC_FAIL, holds the full window) — but receives EXACTLY 0 bytes over 10s of the harness's flushed [session.self] stdout. DISTINCT from REQ-HAZARD-VIEWER-CLOSE-DETACH (death) and REQ-HAZARD-ATTACH-WEDGE (dead-child backpressure): here the harness is ALIVE and the attach is a clean first subscribe. This BLOCKS the 'view is independent' invariant — re-attach is meaningless if a live endpoint-run harness shows nothing. KNOWN-GOOD (rules out 'no drain'): attach.rs `local_attach_via_loopback_conn_rides_the_same_pump` + `broker_spawns_the_pty_child_in_the_requested_cwd` prove the broker DOES drain+fan a `spawn_session` PTY child to a loopback attach over the SAME transport rc uses. Both spawn_session and endpoint-run's spawn_session_pid send KIND_SPAWN → the same dispatch_spawn (broker.rs:706/835) which starts the per-session drain+OutputLog — so the gap is NARROWER than 'no drain', endpoint-run-specific. Root candidates: (a) spawn_session_pid's SpawnReq stdio/env/cwd differs so the dummy's stdout isn't the captured ConPTY; (b) the harness stdout WRITE BLOCKS because the ConPTY buffer fills (drain not reading THIS pty) — explains alive-but-0-bytes; (c) ConPTY reader-park (KH 7.6) on this path; (d) `spt rc` resolve_session/subscribe for an endpoint-run session subscribes to the wrong/empty log. (v0.12.1)
2026-07-06T06:24:02.6981518Z - Required stages: impl, unit, int
2026-07-06T06:24:02.6981562Z 
2026-07-06T06:24:02.6981665Z ### REQ-CLI-HELP-MARKDOWN
2026-07-06T06:24:02.6984642Z - Title: `spt --help` (and every subcommand --help) renders the inline Markdown authored in the clap doc-comments as terminal styling, never as literal markers: `**bold**` → ANSI bold, `` `code` `` → ANSI cyan, `[text](url)` → `text`. The markers are STRIPPED either way — a raw `**` or backtick must NEVER reach the user (the operator-reported v0.12.0 defect: help text reads `**ctrl-b**` and stray backticks verbatim). Color/bold escapes are emitted ONLY when the help is going to a real terminal AND color is not suppressed (NO_COLOR unset · CLICOLOR != 0 · CLICOLOR_FORCE forces on); a pipe / redirect / CI / NO_COLOR falls back to strip-only (clean plaintext, zero escapes) so machine-readable help is byte-identical regardless of marker syntax. Pure transform over the clap-rendered help string at the single run()/bare_invocation chokepoint; preserves pre-existing ANSI (CSI sequences passed through untouched), never spans markers across a newline, leaves unmatched/empty markers literal, and does not alter the help layout. (v0.12.1)
2026-07-06T06:24:02.6984890Z - Required stages: impl, unit
2026-07-06T06:24:02.6984929Z 
2026-07-06T06:24:02.6985030Z ### REQ-HAZARD-WMI-DAEMON-WINDOW
2026-07-06T06:24:02.6987463Z - Title: `spt daemon start` launches the daemon with NO visible console window. REGRESSION (v0.12.1 L1.5): the WMI job-neutral launch (spawn_daemon_via_wmi) set CREATE_NO_WINDOW on the launching powershell but NOT on the Win32_Process.Create call — Win32_Process.Create does not inherit it, so the spawned cmd.exe env-forwarding wrapper popped a console window on every cold-start (violating REQ-INSTALL-10's v0.7.4 no-persistent-window invariant; the old detached_no_inherit path set DETACHED_PROCESS|CREATE_NO_WINDOW). FIX: pass a Win32_ProcessStartup with CreateFlags=DETACHED_PROCESS (0x8 — no console so no window; CREATE_NO_WINDOW 0x08000000 is NOT a valid Win32_ProcessStartup flag → ReturnValue 21 invalid-param, which is why the naive port fails) + ShowWindow=SW_HIDE(0) belt, via the ProcessStartupInformation argument. (v0.12.2)
2026-07-06T06:24:02.6987678Z - Required stages: impl, unit, int
2026-07-06T06:24:02.6987701Z 
2026-07-06T06:24:02.6987804Z ### REQ-CLI-OUTPUT-MARKDOWN
2026-07-06T06:24:02.6992331Z - Title: Human-prose COMMAND OUTPUT (not just `--help`) renders the inline Markdown authored in its source strings as terminal styling, never literal markers: `` `code` `` → ANSI cyan, `**bold**` → ANSI bold, `[text](url)` → `text`, markers STRIPPED either way. REQ-CLI-HELP-MARKDOWN only hooked the clap `--help` chokepoint, so command output still printed raw Markdown (audit: `spt how-to` topic text showed `# headers`/backticks, `spt subnet`/`subnet status` hint footers showed stray backticks, the daemon-status `not running` line, the `ENDPOINT_RUN_STARTED` attach hint, and the daemon's `SUBNET_DETACHED` startup line — 13 prose surfaces). The same line-bounded pure `helpfmt::render` is applied at each emit site, color-gated by the OUTPUT STREAM's own tty (`stdout_color` for print/println, the new `stderr_color` for eprintln). HARNESS-SAFETY (binding): color is tty-gated, so an adapter (piped / non-tty / NO_COLOR) gets STRIP mode = zero ANSI + markers removed; every dual-contract MACHINE token on a rendered line (`ENDPOINT_RUN_STARTED:`, `NO_SUCH_TOPIC:`, `SUBNET_DETACHED:`) carries NO Markdown markers, so it survives strip byte-intact — the adapter parse is never perturbed. Pure-machine output (the `<EVENT …>` envelope, bringup parse-tokens SEEDED/BOUND/READY/NO_SEED, `--json`, QR) is NEVER routed through the renderer. The one spt-daemon source string (`SUBNET_DETACHED`, the bin-local renderer is unreachable from the daemon crate) is authored marker-free instead. (v0.12.2)
2026-07-06T06:24:02.6992446Z - Required stages: impl, unit
2026-07-06T06:24:02.6992479Z 
2026-07-06T06:24:02.6992583Z ### REQ-HAZARD-INJECT-CONTROL-COEXIST
2026-07-06T06:24:02.7000072Z - Title: SPINE INVARIANT (v0.13.0 keystone): the broker must accept INJECTED keystrokes into an spt-hosted PTY (the v0.11.0 raw direct-inject today; the ADR-0022 translation-binary choreography tomorrow) WHILE a live `spt rc` controller is attached to the SAME PTY, without (a) the operator losing control, (b) the endpoint latching ONLINE+CONTROLLED, or (c) the broker wedging. The injection inlet is PERMANENT — spt-claude-code requires keystroke injection — so this is root-caused + fixed at the PTY-injection layer, IN STEP with the ADR-0022 delivery redesign that formalizes the inlet. REOPENS the wedge facet of REQ-HAZARD-ATTACH-WEDGE: the v0.12.1 prove-don't-change covered only DEAD-CHILD backpressure, NOT the injection trigger (operator's signal — one injected keystroke succeeds, the next wedges → the single-threaded broker parks on a blocking PTY/loopback write after injection-induced harness output). REPRO-FIRST on the real dummy-harness fixture (NO theory): instrument to nail the exact blocking call before any fix. Fix candidates: non-blocking/fail-fast PTY write, split input/output, bounded-evicting. Mechanism shared with W2 — spt-core owns EVERY PTY write and applies an injected sequence ATOMICALLY (controller input buffered during the sequence, flushed after) so a stash/restore can't be clobbered. CONFIRMED ROOT (doyle /diagnose 2026-06-19, code-grounded): Broker::append (broker.rs:205-227) fans each live output chunk to the CONTROLLER on a SYNCHRONOUS BLOCKING write_frame held inline in the session's drain thread (the 'authoritative, advances delivered_through' path, D4-1), while VIEWERS use a dedicated writer thread + bounded evicting sync_channel (add_viewer:273 / viewer_writer) that can never stall the drain. So a slow/backed-up controller socket — or the full 64KB loopback duplex (the ATTACH-WEDGE buffer) — BLOCKS the drain thread → output stalls → keystroke echoes stall (PERCEIVED input lag) → unrecoverable wedge when the consumer never drains. TRIGGERS ON NORMAL INTERACTIVE rc USE under heavy harness output (TUI redraw), NOT only message injection — same root, wider repro. FIX DIRECTION: move controller delivery off the drain thread onto a dedicated writer (the viewer_writer pattern) BUT preserve the authoritative cursor — block the WRITER thread (not the drain), bound the wedge (deadline → detach/mark-gone, never park forever), never silently evict the operator's authoritative view. (v0.13.0)
2026-07-06T06:24:02.7000430Z - Required stages: impl, unit, int
2026-07-06T06:24:02.7000463Z 
2026-07-06T06:24:02.7000619Z ### REQ-HAZARD-VIEWER-STARVE-UNDER-CONTROLLER-BACKPRESSURE
2026-07-06T06:24:02.7005849Z - Title: A SLOW controller must not starve a concurrent `rc --view` VIEWER. W1 (REQ-HAZARD-INJECT-CONTROL-COEXIST) moved the controller SOCKET WRITE off the drain thread onto controller_writer, but left the bounded HANDOFF (ControllerJob::deliver) as an INLINE try_send SLEEP-POLL on the drain (broker.rs:1450-1457 → deliver:669-685, up to CONTROLLER_WRITE_DEADLINE=5s). So when a controller drains slower than the PTY floods, its CONTROLLER_CHANNEL_DEPTH(4096) channel fills, deliver() polls inline, and the DRAIN THREAD is throttled to the controller's read rate → OutputLog::append's viewer fan-out (try_send) stops running → a concurrent VIEWER receives only the initial replay then nothing (root 'b4', warm forkpty: a_journaled c1=0/EVICT=0/got_output=FALSE; steady-state-near-full = no recovery; forkpty-only, floods harder than Windows ConPTY). The viewer-not-starved-by-a-busy-session property is legitimate (rc --view of a noisy session must show LIVE output). FIX: the controller becomes a SINGLE NON-BLOCKING try_send (like a viewer), done IN append() under the log lock; deliver()'s sleep-poll DELETED; the drain NEVER sleeps. ControllerSink gains a stateful last_ok deadline → a TRULY-stalled controller (continuous-Full past CONTROLLER_WRITE_DEADLINE) is evicted (bounded-wedge preserved); a slow-but-alive controller DROPS frames + falls behind the ring (resume-from-floor, the existing reconnect case). B2 GAPLESS-HANDOFF PRESERVED via a CONTIGUOUS delivered_through: controller_writer advances the cursor ONLY when the written seq == cursor (next expected); a gap from a drop FREEZES the cursor at last-contiguous so a re-attaching brain's resume_seq never skips a dropped chunk (a high-watermark advance past the gap would be a not-exactly-once resume = B2 violation, doyle's gate). (v0.13.0)
2026-07-06T06:24:02.7005981Z - Required stages: impl, unit, int
2026-07-06T06:24:02.7006010Z 
2026-07-06T06:24:02.7006121Z ### REQ-VIEWER-SKIP-TO-LIVE-ON-EVICT
2026-07-06T06:24:02.7011390Z - Title: A `rc --view` VIEWER that overflows its broker subscription queue and is EVICTED (OutputLog::append try_send Full → viewers.remove, REQ-HAZARD-VIEWER-ISOLATION session-protection) must SKIP TO LIVE, not die silently. ROOT (v0.13.0, b4 JIT item 2 = p0_paste + post-b4 a_journaled-Linux, ONE root): serve_attach forwards each frame (read_event→b64decode→re-encode AttachRecord→net_stream_send) SLOWER than the drain fans out under flood → its VIEWER_CHANNEL_DEPTH(256) channel overflows → the drain evicts (viewers.remove drops the ViewerSink → drops tx → viewer_writer's rx.recv() Err → the writer returns WRITING NOTHING) → serve_attach's brain.read_event() just STOPS getting Output (no EOF, no error) → serve_attach blocks forever → the operator receives nothing (attach_received_output=FALSE). Eviction-of-a-hopelessly-behind-viewer is CORRECT session-protection (keep it); SILENT+PERMANENT eviction is the bug. VIEWER-only → B2-SAFE (a viewer never advances delivered_through / is not authoritative / exposes no resume cursor). FIX (doyle-gated, skip-to-live = tail -f reconnect): (1) explicit broker→viewer EVICTION SIGNAL (KIND_VIEWER_EVICTED, written in the viewer_writer thread OFF the log lock, DISTINCT from session-exit EOF so serve must NOT tear down on it); (2) serve_attach re-subscribes from the CURRENT ring floor (skip-to-live, replays nothing, sees the next live burst) — resetting the cold serve-brain's next_seq so the post-eviction forward-jump replay is accepted (the legacy reject-gap path, brain.rs:618-626, would otherwise FATAL the forward jump); (3) HARD constraint NO evict→resubscribe busy-loop: serve_attach rate-limits re-subscribes (RESUBSCRIBE_INTERVAL) so under max-flood the operator sees intermittent LIVE bursts, never a CPU spin. (v0.13.0)
2026-07-06T06:24:02.7011716Z - Required stages: doc, impl, unit, int
2026-07-06T06:24:02.7011749Z 
2026-07-06T06:24:02.7011853Z ### REQ-HAZARD-VIEWER-RING-ROLL-SNAP
2026-07-06T06:24:02.7016041Z - Title: A read-only rc --view VIEWER whose serving brain falls behind the live ring under a hard flood and receives a FORWARD Output seq gap (the ring rolled frames out between reads, BEFORE any channel-overflow eviction → NO KIND_VIEWER_EVICTED marker) must SNAP TO LIVE (accept-and-advance via dedup-below + snap-above), NOT fatal with output gap (brain.rs:624/628 legacy reject-gap). ROOT (v0.13.0 forkpty, post-b4+skip-to-live): serve_attach subscribes a viewer via brain.attach_as(Viewer) leaving session_cursors EMPTY → the viewer serve-brain uses the LEGACY reject-gap → a PRE-eviction ring-roll forward-gap FATALS read_event → serve_attach returns → forwarding stops → attach_received_pty_output=FALSE (a_journaled / p0_paste / attach.rs:1071 wedged_viewer, Linux forkpty; Windows ConPTY floods slower → MASKED false-green). DISTINCT from REQ-VIEWER-SKIP-TO-LIVE-ON-EVICT (the POST-eviction re-subscribe-from-floor): this is PRE-eviction gap-tolerance while STILL subscribed. VIEWER-only → B2-SAFE (a viewer never advances delivered_through / is not authoritative); the CONTROLLER keeps strict reject-gap (exactly-once resume). FIX: arm snap-above at initial viewer attach (attach_as_viewer_snap = attach_as(Viewer) + session_cursors.insert(session_id, from_seq)); the two viewer-survival mechanisms COMPOSE — this tolerates pre-eviction ring-roll gaps, REQ-VIEWER-SKIP-TO-LIVE-ON-EVICT recovers post-eviction. (v0.13.0)
2026-07-06T06:24:02.7016171Z - Required stages: doc, impl, unit, int
2026-07-06T06:24:02.7016198Z 
2026-07-06T06:24:02.7016308Z ### REQ-HAZARD-CONTROLLER-GAP-RESUME
2026-07-06T06:24:02.7022742Z - Title: A serving CONTROLLER whose serve-brain hits a b4 drop-don't-block FORWARD output gap must RESUME-FROM-FLOOR (re-subscribe from delivered_through and re-fetch the dropped frames from the ring), NOT snap-above and NOT fatal. ROOT (v0.13.0 forkpty re-run, post-keystone): b4 made the controller a non-blocking try_send that DROPS frames when its bounded channel fills (a controller that falls behind its OWN echo under a hard flood), so the next read is a forward gap the strict reject-gap (brain.rs:624/628, B2 exactly-once) FATALS — wedged_viewer_does_not_stall_controller (attach.rs:1048) drove ctrl.read_event() raw and fataled on `output gap got 6134 want 4643`. Pre-b4 the inline sleep-poll BLOCKED the drain to the controller's rate (no drops, no gaps); this is a b4 SIDE-EFFECT, not a new class. A controller CANNOT snap (it is authoritative — advances delivered_through; skipping rolled frames = not-exactly-once = B2 violation), so REQ-HAZARD-VIEWER-RING-ROLL-SNAP does NOT apply. B2 INVARIANT (doyle, broker.rs:327-330): the ring trim is delivered_through-BLIND (`while ring.len() > cap_chunks { pop_front() }`), so re-fetch is exactly-once IFF tail - delivered_through <= cap_chunks (4096) — NOT guaranteed in general, but the common case (burst < ring; wedged_viewer ~1492 < 4096) holds. FIX: serve_attach catches the output-gap on the controller path (does not ?-propagate) and re-subscribes from Brain::controller_resume_floor (= delivered_through = the gap's `want`; NO mid-stream KIND_SESSIONS round-trip — sessions() loops on read_event and would re-fatal on the same gap + discard Output); the broker replays the dropped frames. The IRRECOVERABLE edge (floor unchanged across two resumes = ring rolled past delivered_through = frames gone) surfaces a MARKED truncation to the operator (never silent-skip = B2 lie, never spin) and ends cleanly — full graceful handling deferred to REQ-HAZARD-CONTROLLER-IRRECOVERABLE-BEHIND. Do NOT make the ring trim delivered_through-aware (that risks an unbounded ring under a stuck controller; the 5s eviction + 4096 ring is the practical bound). (v0.13.0)
2026-07-06T06:24:02.7023115Z - Required stages: impl, unit, int
2026-07-06T06:24:02.7023139Z 
2026-07-06T06:24:02.7023268Z ### REQ-HAZARD-CONTROLLER-IRRECOVERABLE-BEHIND
2026-07-06T06:24:02.7026073Z - Title: DEFERRED EDGE of REQ-HAZARD-CONTROLLER-GAP-RESUME: when a serving controller falls behind the live ring FURTHER than the ring holds (tail - delivered_through > cap_chunks, the ring trim being delivered_through-blind, broker.rs:327-330), the dropped frames have rolled OUT of the ring and an exactly-once re-fetch is IMPOSSIBLE. v0.13.0 DETECTS this (resume floor unchanged across two consecutive resumes) and surfaces a MARKED truncation notice to the operator then ends the attach cleanly — it never silent-skips (a B2 lie) and never spins. FULL graceful handling (a clearly-marked snap-with-data-loss that keeps the operator on the live tail, or a structured truncation record the rc renders distinctly, plus the controller-too-slow + ring-too-small backpressure/sizing policy) is DEFERRED — staging it needs a netsplit / deep-behind harness (the in-process loopback rig keeps up; wedged_viewer's gap is recoverable at ~1492 < 4096). (v0.13.0+)
2026-07-06T06:24:02.7026182Z - Required stages: 
2026-07-06T06:24:02.7026214Z 
2026-07-06T06:24:02.7026316Z ### REQ-MSG-IDLE-TRANSLATION-BINARY
2026-07-06T06:24:02.7032382Z - Title: spt-hosted idle message delivery via an adapter TRANSLATION BINARY (ADR-0022). New opt-in manifest section `[message-idle-translation-binary]` = a TABLE carrying a `path` scalar (doyle OPT-B ruling: modeled as a table, not a bare top-level scalar, so a preceding section cannot silently absorb it + N+1 extensible; spt-core does NOT deny_unknown_fields, so a future key degrades gracefully); spt-core LIFECYCLE-manages it (spawn when the endpoint comes up, terminate when it goes down). The binary is a PURE stdin→stdout filter; spt-core owns EVERY PTY write. stdin (JSON-lines): `{type:"init",endpoint_id,node}` first · `{type:"event",envelope:"<EVENT…>"}` per inbound message (ADR-0020 envelope) · `{type:"input"}` content-free ping on each operator keystroke (binary tracks user-idle for its own idle-gated buffering; PTY input content NOT duplicated). stdout (JSON-lines): keystroke-commands `{key:…}`/`{delay_ms:…}`/`{text:…}` (extensible). spt-core applies the emitted sequence to the broker PTY ATOMICALLY (the W1 coordination — REQ-HAZARD-INJECT-CONTROL-COEXIST). The daemon poll feed is the ONE idle substrate for both topologies (Q1=A): harness-hosted consumer = the Monitor child, spt-hosted consumer = this binary; spt-core PREFERS a perch's poll listener if one exists (so spt-hosted can run a listener AND keep `spt rc`). Idle-only; busy/mid-turn = adapter hook-injection. Closes the current grounding gap: `api bind` registers no listener port → a listener-less spt-hosted perch SPOOLS inbound (only spooling+adapter-poll works today) → this delivers real inbound into the PTY. AMENDED v0.14.3 (ADR-0022 amendment, raw-inject removal): idle delivery is translation-binary-ONLY — the v0.11.0 raw `{text:payload}{key:enter}` inject is NO LONGER a delivery path; with no working binary (absent/spawn-failed/faulted/worker-gone) the inbound SPOOLS (delivered=false, poll-fed, LOUD), never a raw PTY pseudo-write (which did not submit on a modern TUI — the silent degrade that masked F-019). See REQ-HAZARD-IDLE-SILENT-NONDELIVERY. (v0.13.0, amended v0.14.3)
2026-07-06T06:24:02.7032637Z - Required stages: doc, impl, unit, int
2026-07-06T06:24:02.7032666Z 
2026-07-06T06:24:02.7032766Z ### REQ-HAZARD-IDLE-SILENT-NONDELIVERY
2026-07-06T06:24:02.7042588Z - Title: An idle delivery to a session whose translation binary is in a FAILED STATE — absent (none declared), spawn-failed, FAULTED, or its inject-worker channel gone — must SPOOL (delivered=false), never raw-inject a pseudo-delivery reported as delivered. The GUARANTEE is the STEADY STATE (the failed-binary state), not every in-flight message (see the fault-transient carve-out below). ROOT (F-019 post-mortem, ADR-0022 amendment): the v0.11.0 path raw-injected `payload+\r` into the PTY whenever no working translation binary handled an inbound message (none declared, spawn-failed, FAULTED, or its inject-worker channel gone) AND acked `delivered=true` — but a bare `payload+\r` does NOT submit on a modern TUI (Claude Code), so the message was TYPED but never sent: a silent pseudo-delivery reported as success. That silent degrade-to-raw-inject is exactly what MASKED F-019 through a multi-hour black-box hunt. FIX (operator-ruled, doyle-scoped): idle delivery is translation-binary-ONLY — `dispatch_endpoint_input` with no working binary replies `endpoint_injected_envelope(ep, delivered=false)` (the caller `try_broker_inject`→`cmd_send` then falls through to `deliver::send` = SPOOL, poll-fed, never lost) and writes NOTHING to the PTY, LOUDLY (eprintln names the absent/faulted/worker-gone cause). A failed binary becomes a VISIBLE no-delivery (spooled + honest QUEUED report), never a confident-but-false 'Sent'. The raw-inject fallback (`input.enqueue`) is REMOVED from the no-binary, worker-dropped, AND post-fault paths. OUT OF SCOPE (doyle ruling, follow-up note only): broker-side auto-redrive of already-spooled inbound the instant a live-update binary spawns (ordering/exactly-once hazards; the poll substrate + subsequent sends cover re-delivery). NOT COVERED — the FAULT-TRANSIENT (the STATE-vs-transient precision): a delivery landing in the worker's commit window — BEFORE `event_rx` is dropped / `faulted` is set — can be optimistically enqueue-acked (`delivered=true` the instant `event_tx.send` succeeds) then DROPPED when the worker faults+returns. That is a SEPARATE, PRE-EXISTING hazard: raw-inject removal did not touch it (the old code dropped that queued event too) — v0.14.3 is a strict improvement that makes nothing worse. It is tracked for v0.15.0 under REQ-MSG-DELIVERY-AXES (the spool-centric delivery redesign: ack-on-SPOOL replaces ack-on-enqueue, which closes the optimistic-ack drop naturally). v0.14.3 guarantees only the steady FAILED state → spool (faulted is MONOTONIC — set once, never respawns — so it converges deterministically; the g2 gate asserts the steady state via bounded-retry-until-spool, not a single-shot ack). EPHEMERAL CARVE-OUT (v0.15.0 W3, ADR-0028): `--ephemeral` is the SOLE sender-opted-in exception — an ephemeral message MAY drop silently if it cannot deliver in its accepted window (at window-open with no live carrier, or at TTL). Every NON-ephemeral path still spools + reports `delivered=false` (the guarantee is unchanged for the default durable path). v0.15.0 realizes the ephemeral drop for the spt-hosted-binary no-carrier-at-window leg + TTL; the harness-relay no-live-listener leg is a documented partial (CONTEXT.md §persistence). KNOWN-HAZARDS class (rule 4). (v0.14.3; ephemeral carve-out v0.15.0)
2026-07-06T06:24:02.7042841Z - Required stages: doc, impl, unit, int
2026-07-06T06:24:02.7042865Z 
2026-07-06T06:24:02.7042951Z ### REQ-MSG-DELIVERY-AXES
2026-07-06T06:24:02.7049642Z - Title: Activity-gated inbound delivery + per-message send control as THREE ORTHOGONAL AXES plus opaque metadata (ADR-0028; grilled w/ operator 2026-06-23). SUBSTRATE (the legacy-SPT parity gap, scaffolded-but-unwired today: `delivery::is_idle` + `resolve_inject_methods` exist but the result is discarded `let _methods`, and `broker::dispatch_endpoint_input` injects unconditionally — its comment calls activity-gating 'a deferred follow wave'): an inbound message has an ACTIVE window (endpoint active → spool for the receiver's hook-poll, non-disruptive) and an IDLE window (idle/idle-transition → deliver immediately: translation binary spt-hosted → relay-poll either topology → spool, in fallback order). AXES (each composes; each defaults to its unrestricted value): (1) DELIVERY WINDOW — default (both, first-to-fire) | `--idle-only` (idle window; immediate if already idle) | `--active-only` (active window only, never wakes; the RENAMED `--deferred` — `deferred=1` spool column + `api poll --include-deferred` keep their names). (2) CHANNEL RESTRICTION — unrestricted | `--prefer-native` (translation binary if running else fall back) | `--force-native` (binary ONLY, no fallback/no spool-to-other-method). Native flags do NOT respect the binary's idle-gating: the WINDOW says when, the native flag says through-what (so `--force-native --active-only` = binary injects during the active window, mid-turn-safe via the existing InjectFloor). (3) PERSISTENCE — durable (default; spool until delivered or TTL) | `--ephemeral` (drop if undeliverable in the accepted window — at window-open with no live carrier, or at TTL, whichever first). METADATA (orthogonal): `--json-payload '<json>'` → a single attr-escaped `json="…"` envelope attr ALONGSIDE (not replacing) the body, pure verbatim passthrough across spool/TCP/WAN/EVENT-PART, parsed only by the receiving adapter; collision-proof by construction (structured data lives INSIDE the one `json` value, can never forge `from`/`type`); available to ANY sender (confers no spt-core authority). HAZARD: `--ephemeral` is the ONLY path permitted to drop silently — the sender-opted-in carve-out to REQ-HAZARD-IDLE-SILENT-NONDELIVERY (that hazard gains a '…unless --ephemeral' clause in v0.15.0). (v0.15.0)
2026-07-06T06:24:02.7049871Z - Required stages: doc, impl, unit, int
2026-07-06T06:24:02.7049904Z 
2026-07-06T06:24:02.7050001Z ### REQ-RESUME-CONTEXT-PULL
2026-07-06T06:24:02.7061365Z - Title: Adapter-callable resume-context pull verb + not-yet-synthesized commune/signoff drop append (legacy-SPT parity, operator-directed 2026-06-24). GAP: spt-core exposes NO verb for a harness adapter's SessionStart hook to pull an agent's resume context — `resume::download_psyche_context` (spt-live/src/resume.rs:88, composes <live-role>+<live-context>+<project-context> from the durable two-tier store) is INTERNAL with ZERO spt callers and no ApiCmd verb (api/mod.rs ApiCmd enum has none); resume.rs:9 documents the intended 'adapter pulls it in its SessionStart hook' path but it was NEVER wired. Result: a harness adapter cannot inject the agent's durable mind on resume at all (claude-spt today runs only `api boundary` session-rotation + an identity brief — the agent resumes WITHOUT its mind). TIER-1 SCOPE (operator-approved; Tier-2 = drift-stamp/<current>/drift-directive + <memformat> + Pulse-Log DEFERRED to a separate parity item, NOT v0.15.0 — the legacy download_payload [claude_skill_owl context.rs:344] is richer but memformat is roadmap-deferred + drift-stamp is an orthogonal cross-machine-drift feature). TWO PARTS: (1) EXPOSE `spt api psyche-download <id> [--session-id <sid>]` -> stdout = the composed brief, project_id resolved from the endpoint's bound cwd (info::read_info -> cwd -> project derive; NO --project arg), auth-gated like sibling id-scoped verbs (the `gated(&id,&auth,…)` pattern); empty store -> NO-CONTEXT on stderr (mirror legacy). The adapter SessionStart hook runs it + injects stdout as additionalContext. (2) APPEND any commune/signoff drop NOT YET SYNTHESIZED into the durable tiers as a distinct <pending-commune>/<pending-signoff> slice AFTER the durable slices. GATING (operator ruling): append while NOT-YET-SYNTHESIZED, NOT merely 'while the raw file is on disk' — in today's synchronous ingest (ingest_drops route_two_slice writes durable THEN deletes the file, lifecycle.rs:466 @ DEFAULT_PULSE_PERIOD 5s) the two coincide (a watched-dir drop IS pre-synthesis), so the v1 realization reads the manifest-declared session.commune_dir/signoff_dir (manifest.rs:208/210) for a present <id>-commune.md/<id>-signoff.md (COMMUNE_SUFFIX/SIGNOFF_SUFFIX, ingest.rs); the CONTRACT keys on synthesis-state so it stays correct when async Psyche synthesis lands (a consumed-but-not-yet-committed drop stays appended via a pending-synthesis staging set — forward hook). The agent-checkpoint trigger sentinel CHECKPOINT_SENTINEL=`!!checkpoint!!` (a FIXED spt-core constant — operator-specified, CONTEXT.md §fixed-constants, NOT adapter-configurable) is stripped at BOTH drop-body points via one shared `strip_checkpoint_markers` (remove every token, keep inter-marker text, collapse trivial whitespace): the PRE-synthesis pending-append (resume::append_pending) AND the POST-synthesis durable ingest (ingest::route_slices — the single choke covering route_two_slice + signoff.write_resume_commune; strip-then-empty-filter so a marker-only slice routes nowhere) — else the marker would persist PERMANENTLY in live-context.md once a checkpoint drop synthesizes + re-trigger once the adapter's checkpoint detection is live. PRESENTATION-ONLY: the append NEVER writes the durable store (spt-core remains sole store-writer, REQ-HAZARD-DROP-FILE-SINGLE-WRITER; mirror legacy's read-only/process_file_drop-sole-deleter discipline). SELF-CLEARING: once synthesis commits the <pending-*> slice vanishes — no duplication. CORE-OWNED (not adapter): an adapter-side raw-file read RACES spt-core's ingest-delete (TOCTOU, ingest.rs:161 removes the drop on pulse-consume); the fold MUST live in the single composer all resume pulls flow through. New public CLI verb -> docs-drift gate (xtask gen + reference.md no-internal-codes, cli-command-docs-drift). (v0.15.0 parity wave W5)
2026-07-06T06:24:02.7061701Z - Required stages: doc, impl, unit, int
2026-07-06T06:24:02.7061730Z 
2026-07-06T06:24:02.7061839Z ### REQ-ADAPTER-TRANSLATE-PROOF
2026-07-06T06:24:02.7066070Z - Title: `spt adapter translate-proof <adapter> --event <envelope> [--session <id>]` — the author-time EMIT-half proof tool for `[message-idle-translation-binary]` (ADR-0022), symmetric to `spt adapter digest-proof` (REQ-TERM-5). It spawns and feeds the adapter's declared translation binary EXACTLY as the daemon does at idle-delivery — running the REAL `spt_daemon::translation` driver VERBATIM (no protocol reimplementation): `TranslationChild::spawn` the binary, send the `{type:"init",endpoint_id,node}` line then the `{type:"event",envelope}` line, and read back the emitted `{key}`/`{text}`/`{delay_ms}`/`{commit}` keystroke-command stream — then prints it author-readable (each Key with its `key_to_bytes` rendering, Text quoted, Delay in ms, Commit marker) with counts. It fills the SAME `{id}`→option and `{session_id}`→(--session, else a placeholder) keys into the `--event` envelope the daemon fills at runtime, so an envelope that proofs here feeds faithfully live. EMIT-half ONLY: it proves the binary's spawn+feed+emit contract; it does NOT exercise the daemon's atomic PTY apply / controller-buffering (that stays covered by the W2 inject_control_wedge int gate) — `--help` says so. Exit codes mirror digest-proof: 0 ok, 1 on spawn-fail / zero commands / no-commit-or-output / unparseable, 2 when the adapter declares no `[message-idle-translation-binary]` section. The `TranslationChild` Drop does the bounded no-zombie reap. (v0.13.x)
2026-07-06T06:24:02.7066194Z - Required stages: doc, impl, unit, int
2026-07-06T06:24:02.7066223Z 
2026-07-06T06:24:02.7066324Z ### REQ-HAZARD-BIND-CWD-UNSET
2026-07-06T06:24:02.7068827Z - Title: A bound endpoint's `info.cwd` is SET at bind so a freshly-created perch appears under its own project tab. ROOT (found, v0.13.0): `info.cwd` is NEVER set on bind — `cmd_bind` (spt-hosted) and `bind_from_seed` (harness-hosted) never thread cwd into `establish_perch`/`rec.cwd`. FIX: `cmd_bind` reads its own `current_dir` (the broker spawned it in `project_cwd`); `bind_from_seed` passes `seed.cwd` (already captured at seed time, currently DISCARDED). DISTINCT from REQ-PICKER-HISTORY-FRESH (v0.12.1) — that unioned cwd-origin into picker MEMBERSHIP but tested merge_origin_project with a PROVIDED origin; it never asserted `info.cwd` is actually set on bind, so a real `endpoint run` perch still had an empty cwd and the union had nothing to union. This is the v0.12.1 P1 'appears under its own project right away' claim that was REFUTED in the changelog — delivered for real here. (v0.13.0)
2026-07-06T06:24:02.7069076Z - Required stages: impl, unit, int
2026-07-06T06:24:02.7069114Z 
2026-07-06T06:24:02.7069206Z ### REQ-PICKER-UX-V013
2026-07-06T06:24:02.7070772Z - Title: `spt endpoint run` picker UX (v0.13.0 operator dogfooding): (1) SKIP the first screen — open directly on 'Pick existing'; `n` jumps to 'Create new'. (2) AUTO-ATTACH after both Start-new AND Resume-from-history (both currently don't attach and show no stdout); add an `h` shortcut to run headless (no attach). (3) 'controlled by' shows the node NAME (node_label_display), not the raw hex. (4) Clean up Start-new output — drop the Rust `pid=Some(142748)` leak and the 'harness binds its perch on startup' internals; user-friendly, not a process log. (v0.13.0)
2026-07-06T06:24:02.7071001Z - Required stages: 
2026-07-06T06:24:02.7071029Z 
2026-07-06T06:24:02.7071135Z ### REQ-HAZARD-DRIVEN-BY-SELFHEAL
2026-07-06T06:24:02.7072647Z - Title: An spt-hosted endpoint's ONLINE+CONTROLLED state (`driven_by`) must CLEAR even when the detach IPC is lost — do NOT rely on the detach signal (same lesson as REQ-HAZARD-HOSTED-LIVENESS-RECONCILE B2): the reconcile loop clears `driven_by` when the endpoint has no live controller/session. Today a wedged or lost pump never delivers the detach, so the endpoint stays latched CONTROLLED forever. Composes with W1 (the wedge no longer blocks the detach) and rides the same pull-primary reconcile substrate as B2. (v0.13.0)
2026-07-06T06:24:02.7072752Z - Required stages: impl, unit, int
2026-07-06T06:24:02.7072777Z 
2026-07-06T06:24:02.7072900Z ### REQ-HAZARD-DRIVEN-BY-IDLE-REMOTE-EVICT
2026-07-06T06:24:02.7077601Z - Title: An spt-hosted endpoint driven by a REMOTE controller whose remote is gone but whose broker connection stays OPEN (a wedged/lost pump that never delivers the detach) AND whose session is IDLE (no output) stays latched ONLINE+CONTROLLED forever: the W1 drain-evict only fires on OUTPUT (CONTROLLER_WRITE_DEADLINE on a backed-up write), a clean disconnect self-heals via detach_if→clear_controller, but an idle session with a half-open/wedged controller connection produces neither signal. PROVED repro-first on a real broker (v0.13.0 W5, inject_control_wedge.rs w5_a2): controller_by STAYS Some(origin) and driven_by STAYS Some after the remote is abandoned without a clean EOF on an idle session — so the brain reconcile CANNOT detect it from KIND_SESSIONS controller_by (the broker still reports it controlled). FIX DIRECTION (doyle ruling 2026-06-19, broker-side single-writer — the broker owns driven_by/clear_controller): wire the EXISTING D4c NetPresence connection-disconnect event → clear_controller for any session whose controller identity == the dead origin (become_controller already stores Some(origin); presence events already exist — modest wiring, NOT a new probe). The liveness ORACLE is QUIC's own keepalive/idle-timeout: a presence-disconnect IS a real QUIC conn close, already tolerant of transient blips within the keepalive window, so NO heavy partition ADR is needed UNLESS the QUIC timeout proves too slow for the UX (then mint an ADR for a faster controller-heartbeat + its false-evict bound). Composes with W1 (output path) + W5 Gap B (no-session) — this is the third, idle-remote, leg. (v0.13.0 follow-up)
2026-07-06T06:24:02.7077847Z - Required stages: 
2026-07-06T06:24:02.7077886Z 
2026-07-06T06:24:02.7078000Z ### REQ-HAZARD-RC-INPUT-KEY-ENCODING
2026-07-06T06:24:02.7082552Z - Title: An `spt rc` session forwards the Backspace key as the VT DEL byte (0x7f), so the hosted TUI (Claude Code) deletes ONE character — never a whole word. SYMPTOM (operator dogfooding): Backspace in an rc session always behaves like ctrl+Backspace — deletes the entire last word. ROOT (doyle /diagnose, code-grounded, byte PENDING HITL confirm): rc is a RAW VERBATIM byte pump — spawn_stdin_reader (rc.rs:152) reads std::io::stdin() bytes under crossterm raw mode and forwards them unchanged (parse_stdin_chunk only intercepts the ctrl-b detach prefix); there is NO key-event encoding and NO 0x08↔0x7f normalization ANYWHERE in the tree (grep: zero SetConsoleMode / ENABLE_VIRTUAL_TERMINAL_INPUT). On Windows, crossterm enable_raw_mode does NOT set ENABLE_VIRTUAL_TERMINAL_INPUT, so the LEGACY console delivers ^H (0x08, ctrl+h) for Backspace instead of VT DEL (0x7f); Claude Code maps ^H → backward-kill-word → the observed whole-word delete. CONFIRM-FIRST (build the loop): an env-gated hexdump in spawn_stdin_reader (SPT_RC_DEBUG_KEYS) prints the forwarded byte; operator presses Backspace + ctrl+Backspace in a real rc session. FIX CANDIDATES: (a) enable ENABLE_VIRTUAL_TERMINAL_INPUT on the rc stdin console on Windows so the console emits proper VT (Backspace→0x7f, arrows/Home/End as CSI) — cleanest, fixes the whole key map not just Backspace; (b) narrow normalize bare 0x08→0x7f in the rc input path (riskier — a real ctrl+h is also 0x08). Prefer (a) unless it regresses other keys. Add a KNOWN-HAZARDS.md entry on landing. (v0.13.0)
2026-07-06T06:24:02.7082756Z - Required stages: impl, unit
2026-07-06T06:24:02.7082793Z 
2026-07-06T06:24:02.7082902Z ### REQ-HAZARD-EFFECT-JOURNAL-PTY-WEDGE
2026-07-06T06:24:02.7091969Z - Title: The effect journal serializes EVERY PTY effect under one mutex held ACROSS two fsyncs AND the blocking PTY write — so interactive input stutters and ultimately wedges the daemon hard. ROOT (doyle /diagnose, code-grounded + MEASURED on the operator's real Windows box, 2026-06-19): EffectJournal::apply_once (effect.rs:168-188) takes `inner.lock()` and holds it across `write_line(PENDING)` → `effect()` → `write_line(DONE)`, where write_line (effect.rs:235-239) does flush()+sync_all() (a full FlushFileBuffers) — so each effect pays TWO fsyncs under a GLOBAL lock, and the closure `effect()` (the actual PTY write, broker.rs:1257 EffectKind::PtyWrite via attach.rs:197 send_effect) runs while the lock is held. Two operator-visible facets, ONE root: (A) STUTTER/LAG — every keystroke is a PtyWrite effect = 2× sync_all serialized; measured fsync on %LOCALAPPDATA%\spt-core = median 6.5ms, spikes to 198ms (C: was recently at 100%), so ~13ms+ per keystroke best case, hundreds under contention → 'many but not all keypresses take 100s of ms, choppy, worsens with volume'. (B) HARD PERMANENT WEDGE — when a PtyWrite `effect()` blocks (ConPTY input buffer full / harness not draining stdin), the journal lock is held INDEFINITELY → the single-threaded inbound-stream dispatch (dispatch.rs serve_attach, which both applies input effects AND opens attaches) can never progress → EVERY subsequent attach (`spt rc --view`/`--take`) fails with 'attach request: brain IPC read deadline elapsed' (confirmed: two retries deadline identically; broker control-plane KIND queries still answer — different thread). This REFUTES the W2-deferred ruling that park-(b)/(c) is 'Windows-benign because ConPTY absorbs 4MiB' — on the real box the input path wedges regardless. DISTINCT from W1 (REQ-HAZARD-INJECT-CONTROL-COEXIST = the OUTPUT drain, correctly fixed @8b5583e; output uses broker.rs:1106 append, NOT the fsync journal). This is the INPUT/effect-journal path W1 never touched, and it is THE wedge the operator hits with --take/--view. FIX DIRECTION (candidates, repro-first — extend inject_control_wedge.rs to a REAL backed-up-PTY-consumer + a real rc-client attach assertion, the gap W1's gate missed): (1) do NOT hold the journal lock across effect() — reserve the key + fsync PENDING under lock, RELEASE, run effect(), re-acquire to fsync DONE + mark applied (preserve crash-idempotency via the per-key reservation, not a global hold); (2) bound/fail-fast the PtyWrite itself (the W2-deferred park bound — write_input must never block indefinitely, DSR-answer must not hold the writer mutex across a blocking write); (3) drop per-keystroke fsync on the interactive path — PtyWrite effects are EPHEMERAL (a keystroke lost on a broker crash is retyped; PTY state is not reconstructed from keystroke replay), so in-memory applied-set dedup suffices (the broker survives the brain — that IS the dedup anchor), with async/batched fsync or no-fsync for EffectKind::PtyWrite while durable kinds (NetSend/NetDial/Registry/Spool) keep their fsync. Combine (1)+(3) at minimum. Add a KNOWN-HAZARDS.md entry on landing. (v0.13.0)
2026-07-06T06:24:02.7092221Z - Required stages: impl, unit, int
2026-07-06T06:24:02.7092251Z 
2026-07-06T06:24:02.7092364Z ### REQ-HAZARD-RC-ATTACH-ONLINE-RACE
2026-07-06T06:24:02.7095998Z - Title: `spt endpoint run` in an ATTACH/VIEW terminal action attaches BEFORE the freshly-spawned endpoint is online, so the attach races (or outright loses to) the harness bind. ROOT (doyle /diagnose, code-grounded): cmd_endpoint_run (cli.rs) does launch_harness_brokered_in -> (if start: return) -> run_attach with NO await-online between them. launch_harness_brokered_in returns once the harness PROCESS is spawned, but the broker-PTY bind (info status -> STATUS_ONLINE + the live session) lands ASYNC. Both picker attach paths route here with start=false (RunMode::Attach -> cmd_endpoint_run start=false,view=false): Start-now catches the endpoint mid-bringup -> run_attach attempts + loses the handshake race; Resume-from-history catches it still fully OFFLINE -> run_attach's status-gate (REQ-HAZARD-RC-ATTACH-FAILFAST) short-circuits 'offline - nothing to attach' and NEVER attempts. SAME root, two faces (the W4 attach-by-default surfaced both; an online endpoint is unaffected - the picker returns Outcome::Attach, not Run). FIX: in cmd_endpoint_run, when the terminal action is attach/view (NOT start), AWAIT the endpoint online between launch_harness_brokered_in success and run_attach - poll spt_store::info read_info().status to STATUS_ONLINE with a bounded harness-boot deadline (~25s) at a tight interval; on online -> run_attach; on timeout -> ENDPOINT_RUN_ONLINE_TIMEOUT err (do NOT attach a dead bringup). (v0.13.0)
2026-07-06T06:24:02.7096127Z - Required stages: impl, unit, int
2026-07-06T06:24:02.7096155Z 
2026-07-06T06:24:02.7096249Z ### REQ-RC-KEY-VT-TRANSLATE
2026-07-06T06:24:02.7102018Z - Title: On Windows, `spt rc` translates CONSOLE KEY EVENTS to standard xterm VT so ALL keys reach the hosted harness — arrows/Home/End/PgUp/PgDn/Insert/Delete/F-keys, every modifier combo, Backspace/Ctrl+Backspace — not just the byte-emitting ones. ROOT (operator HITL, doyle /diagnose): `spt rc` reads raw STDIN BYTES (spawn_stdin_reader, std::io::stdin().read); on the Windows LEGACY console (no ENABLE_VIRTUAL_TERMINAL_INPUT) the special keys produce console KEY_EVENTs, NOT stdin bytes, so the byte-pump sees nothing → those keys are DEAD. Enabling ENABLE_VIRTUAL_TERMINAL_INPUT was rejected (W7 dc07c39): on Windows Terminal it yields harness-specific win32-input-mode + broke ctrl-b detach. FIX (agnostic, full fidelity): on Windows, replace the stdin byte-read with a crossterm EVENT source (crossterm 0.28 already a dep; the picker already reads events) and translate each KeyEvent → STANDARD xterm VT bytes via a PURE translate_key_event(KeyEvent)->Vec<u8> (copy a known-correct xterm table verbatim, ADR-0001 spirit), forwarded through the SAME rc pump — the harness receives ordinary xterm VT (harness-AGNOSTIC, no win32-input-mode). Press-only (drop Repeat/Release). Detach stays the ctrl-b+'d' PREFIX, event-sourced (doyle Option B): Ctrl+B arms; armed+plain-'d'⇒Detach; armed+Ctrl+B⇒emit literal 0x02; armed+other⇒0x02 then translate(other). Non-tty stdin (piped/tests) → FALL BACK to the byte-read path (keeps e2e byte-injection working). UNIX UNCHANGED (its raw-mode byte stream already delivers proper VT; cfg-split, zero Unix regression). SUPERSEDES the W7 normalize_key_byte swap on Windows — the translator emits 0x7f for Backspace and 0x08 for Ctrl+Backspace natively (REQ-HAZARD-RC-INPUT-KEY-ENCODING folded in). NO int (a live interactive console can't be driven in CI — HITL, REQ-RUN-PICKER/RC-1 precedent); the exhaustive non-vacuous translate_key_event mapping unit + the event-detach unit ARE the surface. (v0.13.0)
2026-07-06T06:24:02.7102243Z - Required stages: doc, impl, unit
2026-07-06T06:24:02.7102272Z 
2026-07-06T06:24:02.7102376Z ### REQ-HAZARD-PTY-INPUT-WRITER-WEDGE
2026-07-06T06:24:02.7108511Z - Title: Pasting into an `spt rc` session WEDGES the broker — after a paste the operator can no longer type AND can no longer attach to NEW or EXISTING sessions (`brain IPC read deadline`). ROOT (doyle /diagnose, code-grounded): the operator-keystroke path rc -> net-stream Input -> serve_attach (attach.rs:197 brain.send_effect) -> KIND_INPUT -> broker dispatch loop (broker.rs:1091) -> dispatch_input (broker.rs:1459) -> session.write_input(&bytes) runs SYNCHRONOUSLY on the broker request-handling thread. W1b (REQ-HAZARD-EFFECT-JOURNAL-PTY-WEDGE) released the journal lock across the effect (fix 1) + made PtyWrite ephemeral/no-fsync (fix 3) but EXPLICITLY DEFERRED fix (2) — bound/fail-fast the PtyWrite itself. A single keystroke never fills the ConPTY input buffer; a PASTE BURST does -> write_input blocks -> the dispatch thread cannot service the next frame (a re-attach subscribe, a become_controller restore-write, an inject-floor flush) -> wedge. Not a bug-2 regression (the byte path funnels to the same write_input; paste just reliably fills the buffer). FIX (doyle design, V0.13.0-P0-PTY-INPUT-WRITER-DESIGN.md, CONTEXT L33 broker-owns-PTY/minimal + L435 SessionSurface + single-writer pattern): one dedicated per-session INPUT-WRITER THREAD = the SOLE caller of the blocking write_input, fed by a BOUNDED FIFO channel; every caller (dispatch_input, serve_attach->send_effect, inject-floor flush) ENQUEUES + returns immediately, never blocks. A blocked/slow harness blocks ONLY its own writer thread, never the broker dispatch. Backpressure (operator ruling): queue full => DROP excess input + stamp the session INPUT_BACKPRESSURE (visible health signal); the daemon NEVER wedges; a merely-slow harness self-heals as the writer drains. Exactly-once preserved (PtyWrite ephemeral: apply_once effect = the non-blocking enqueue => Applied; ack now means accepted+ordered, benign — rc does not gate on landing); order preserved (single FIFO + single writer); inject-floor (W2 Layer C) choreography moves to the lone writer. Completes the W1b-deferred fix (2), cross-platform (cfg(unix) forkpty park folds in). (v0.13.0)
2026-07-06T06:24:02.7108720Z - Required stages: impl, unit, int
2026-07-06T06:24:02.7108749Z 
2026-07-06T06:24:02.7108850Z ### REQ-SESSION-RESUME-TEMPLATE
2026-07-06T06:24:02.7115923Z - Title: Resuming an endpoint session that HAS conversation history brings up a BLANK session. ROOT (doyle, code-grounded + CONTEXT — case-3 spt-core MISSING feature, NOT a perri docs-miss): CONTEXT L127-129 already defines the resume-session seam ('continue-existing: resume an existing harness session under the adapter — its NATIVE resume'), and the manifest already has the resume-variant pattern (Session has BOTH psyche_init AND psyche_resume, manifest.rs:217-219) — but the agent's own session has ONLY self_ (`[session.self]`, no resume sibling). cmd_endpoint_run (cli.rs:1304) re-passes the session_id through `[session.self]` on resume (resume.unwrap_or_else(mint_session_id)), so the adapter's FRESH command (e.g. `claude --session-id ..`) runs again instead of the harness NATIVE resume (`claude -r ..`) -> CC starts a fresh transcript -> blank. spt-core forwards session_id + cwd faithfully; it just has no way to express the native-resume invocation. SECOND GAP: CC resolves a transcript by session_id + cwd, but the session ledger records only {ts, session_id, trigger} (no cwd), so picker Resume-from-history (cross-project rows) can't restore the right cwd. FIX (doyle design, V0.13.0-P2-SESSION-RESUME-DESIGN.md, mirrors psyche_init->psyche_resume exactly): (A) add a `[session.resume]` role (resume: Option<SessionRole> on Session + roles()/is_empty()); cmd_endpoint_run selects it when --resume is set AND it's declared (fill {id}/{session_id}=resumed id/{session_name} + the resume cwd), else FALL BACK to `[session.self]` (full back-compat). (B) record cwd PER ledger row (operator ruling): {ts, session_id, trigger, cwd} additive serde-default; resume cwd = resumed row cwd -> else perch info.cwd -> else current_dir (back-compat for old rows + single-project endpoints); picker threads the selected row's cwd through Outcome::Run -> cmd_endpoint_run. (C) public docs (MANIFEST + harness-contract) teach `[session.resume]` so perri builds the adapter side BLIND. Adapter follow-on (perri, AFTER spt-core ships+docs): declare `[session.resume] command = claude -r {session_id} --remote-control {id} --dangerously-skip-permissions` from the resume cwd. Completes REQ-READY-AGENT-RESUME / REQ-RUN-PICKER resume-from-history. (v0.13.0)
2026-07-06T06:24:02.7116290Z - Required stages: doc, impl, unit, int
2026-07-06T06:24:02.7116324Z 
2026-07-06T06:24:02.7116418Z ### REQ-RC-WIN-PASTE
2026-07-06T06:24:02.7121142Z - Title: In an `spt rc` session neither ctrl+V nor right-click pastes (CC explicitly supports ctrl+V). ROOT (doyle /diagnose): RawGuard does only enable_raw_mode (no bracketed paste / no mouse capture / no clipboard interception); the Windows console delivers a paste as synthetic per-char KEY EVENTs (no crossterm Event::Paste), and ctrl+V translates to bare ^V forwarded to CC — but CC runs DAEMON-SIDE with NO access to the operator's LOCAL clipboard, so remote paste is fundamentally CLIENT-ORIGINATED. A multi-line paste-as-keys also becomes a \r submit-storm. FIX (doyle design, V0.13.0-P1-RC-PASTE-DESIGN.md, cfg(windows), folds into the bug-2 event path): on a paste gesture rc reads the LOCAL clipboard + forwards a BRACKETED PASTE (ESC[200~ + content + ESC[201~); CC has bracketed-paste mode on (its TUI sets ESC[?2004h) so it treats it as a paste — content intact, no submit-storm, harness-AGNOSTIC. ctrl+V: intercept Char('v')+CONTROL in the event loop -> read_clipboard -> bracketed paste. Right-click: RawGuard also EnableMouseCapture (disables console QuickEdit + enables ENABLE_MOUSE_INPUT so right-click surfaces as Event::Mouse on legacy cmd/powershell) -> right-button -> read_clipboard -> bracketed paste; DROP all other mouse (CC has no mouse features, operator-confirmed, so capture costs nothing). read_clipboard = clipboard-win crate (cfg(windows), minimal); empty/failed = clean no-op. Content forwarded VERBATIM (literal pasted text, no per-char translation). Unix UNCHANGED (its terminal pastes natively through the byte pump). DEPENDS ON P0 (a paste chunk must not wedge the broker). (v0.13.0)
2026-07-06T06:24:02.7121251Z - Required stages: doc, impl, unit
2026-07-06T06:24:02.7121289Z 
2026-07-06T06:24:02.7121396Z ### REQ-HAZARD-INPUT-ACK-BACKPRESSURE
2026-07-06T06:24:02.7128591Z - Title: A FLOOD of operator input on one brain↔broker connection deadlocks the broker PERMANENTLY (entire broker — no new/existing attach; the controller stays latched because the per-conn handler can't process the detach). ROOT (doyle /diagnose, code-grounded + HITL capture, the v0.13.0 P1 ctrl+V re-open): `serve_attach` processes a whole `NetStreamData` batch of N operator `Input` records in its inner `for rec in decoder.push()` loop, calling `brain.send_effect(op_id, &bytes)` N times WITHOUT returning to `read_event()` — so the brain writes N `KIND_INPUT` frames back-to-back and drains nothing. The broker's single-threaded per-conn handler answers EACH with `send_frame(applied_envelope)` on the SAME conn (B5 exactly-once ack, KNOWN-HAZARDS 7.2). With the brain not reading, the broker→brain return direction fills (~10 frames = the IPC pipe buffer) → `send_frame` BLOCKS → the handler stops reading → the brain's writes block too → mutual full-duplex DEADLOCK. Capture pinned it: 11 input frames, write_input 11/11 (P0 holds — the PTY write is fine), ack send START=11 / END=10 (frame #11's applied-ack never returns). Same class as the v0.12.1 L0 two-conn split. Windows Terminal's ctrl+V paste accelerator was the trigger (injects the clipboard as a char-by-char key flood) but the deadlock is generic to ANY input flood, NOT ctrl+V-specific and NOT a P0 (PTY-write) or W1 (output-drain) regression. The applied-ack is load-bearing ONLY for `shellchan` (one-at-a-time spool delivery WAITS on `BrokerEvent::Applied`); `serve_attach` DISCARDS it (the operator/rc path is fire-and-forward, op_id for dedup only, never gates on the ack). FIX (doyle-approved): CONDITIONAL ACK — `InputReq` gains `ack: bool` (serde default = true, N-1-safe: an older brain's input still acks = today's behavior). `serve_attach`'s operator path calls `send_effect_no_ack` (ack=false) → `dispatch_input` writes NO applied frame → the per-conn handler never writes back while servicing the flood → it always drains → no deadlock (cures ANY input flood). `shellchan` keeps `send_effect` (ack=true) and its `Applied`-wait. Exactly-once PRESERVED: the broker still dedups by (session, op_id) at the applied-set regardless of the ack. N-1 caveat: an OLD resident broker (self-update window) ignores `ack=false` → still acks → the deadlock persists until a broker restart (inherent KNOWN-HAZARDS 7.9 broker-resident-wire-change class). (v0.13.0)
2026-07-06T06:24:02.7128916Z - Required stages: doc, impl, unit, int
2026-07-06T06:24:02.7129030Z 
2026-07-06T06:24:02.7129140Z ### REQ-RC-MOUSE-FORWARD
2026-07-06T06:24:02.7133441Z - Title: On Windows, `spt rc` must FORWARD scroll-wheel events to the harness when the harness has mouse reporting on. ROOT (operator HITL): P1's RawGuard EnableMouseCapture (added for right-click paste, REQ-RC-WIN-PASTE) makes Windows Terminal forward ALL mouse — including the scroll wheel — to rc instead of scrolling its own buffer, but the rc mouse handler dropped everything except right-button-down → scroll DIED (and WT's native scrollback is stolen by the capture). Operator ruling: keep mouse capture + right-click bracketed paste AND forward scroll to the harness. FIX (doyle design, cfg(windows), folds into the rc mouse handler): TRACK the harness's mouse-reporting mode by scanning its OUTPUT stream for the DECSET set/reset — ESC[?1000h/1002h/1003h (mouse on) + ESC[?1006h (SGR ext) and their ...l (off) — into a shared MouseMode{enabled,sgr} (pump writes from output, stdin reader reads); the scan survives a sequence SPLIT across output chunks (a bounded carry buffer). The mouse handler: right-button-DOWN -> bracketed clipboard paste (unchanged, REQ-RC-WIN-PASTE); ScrollUp/Down -> translate to an xterm SGR mouse report (ESC[<64;col+1;row+1M up / ESC[<65;..M down, 0-based crossterm -> 1-based xterm) and forward ONLY when enabled && sgr (else DROP — a legacy X10 report the harness may not parse is garbage); Moved/drag/left/middle -> DROP (scroll is the operator's need; click-forward risks garbage, no click-to-position). Unix UNCHANGED (no capture; the terminal scrolls natively). (v0.13.0)
2026-07-06T06:24:02.7133566Z - Required stages: doc, impl, unit
2026-07-06T06:24:02.7133599Z 
2026-07-06T06:24:02.7133703Z ### REQ-HAZARD-CONTROLLER-WRITER-REORDER
2026-07-06T06:24:02.7147483Z - Title: Two `controller_writer` threads must never race ONE brain↔broker connection's socket. ROOT (doyle, instrumented RACEDIAG repro on kitsubito): on a brain-restart re-serve the handoff brain registers as controller on the SAME session TWICE over the SAME `Brain::conn` socket — (1) `Brain::handoff` eagerly `subscribe(prior.session_id, prior.next_seq=1)` → `become_controller(from_seq=1)`, initial=[1], spawns writer-A (writes seq 1); (2) `serve_attach` re-handles the replayed `Request{from_seq:0}` → `attach_as(sid,0)` → `become_controller(from_seq=0)`, initial=[0,1], spawns writer-B (writes 0 then 1). `become_controller` (broker.rs) drops the prior `ControllerSink` (its `tx`) but does NOT stop the prior writer thread — writer-A keeps flushing its owned `initial` batch, and both writers hold clones of the same `SharedSend` (`Arc<Mutex<socket>>`) with NO inter-thread ordering. When writer-A's seq 1 wins the socket before writer-B's seq 0, the strict legacy consumer (brain.rs read_event reject-gap path) sees `output gap: got seq 1 want 0` → the test `attach_survives_target_brain_restart_exactly_once` panics at `.expect("re-serve")` OR HANGS in `render_until` (serve thread died on the gap → MARKER_TWO never reaches the wire). `prior.next_seq` is life1's CONSUMPTION cursor, NOT life2's connection state — life2's socket has been sent NOTHING, so a `from_seq=0` full replay on a connection that already streamed seq 1 is contradictory. Snap-above tolerance ALONE can't fix it (it would dedup-drop the late seq 0 → byte loss → the exactly-once byte-identity assert fails). PRE-EXISTING, surfaced by the v0.13.0 green-both-runners release gate; P1b is INNOCENT (its diff touches only input-ack machinery, proven mechanically + the test passes post-P1b in isolation). Sibling flaky cluster: `inject_control_wedge::g2`, `broker::spawn_env_reaches_child`. INVARIANT: on a single brain↔broker connection the controller output-frame stream is monotonic non-decreasing in seq (modulo dedup re-sends); exactly ONE `controller_writer` is ever live per connection; a SUPERSEDED writer writes NO further frames; a re-serve never replays a seq below what the connection already received. FIX (doyle design, corrected at the gate 2026-06-20): fix #1 as designed ('drop handoff's eager subscribe so serve_attach's attach_as is the sole registration') was REVERTED — handoff's `subscribe(prior.next_seq)` IS the standalone-resume mechanism (the brain-only update engine `apply_brain_only` + the `handoff`/`idempotent`/`daemon_e2e` int tests replay output through it with NO `serve_attach`; dropping it hung every resume-via-handoff test). The shipped fix is three parts: (1) CORRECTNESS — `Brain::handoff` seeds `session_cursors` at `prior.next_seq` so the consumer runs the production dedup-below+snap-above path, never the strict reject-gap legacy trap; this is COMPLETE (not merely tolerant) because every `controller_writer` emits an ASCENDING seq stream and the surviving writer (serve_attach's attach_as(sid,0)) offers the complete `[0,end]` range, so a snap-above merge of ascending writers delivers `[K,end]` with no skip/dup (first sighting of any seq>M is preceded by M on that writer). (2) INVARIANT — `controller_writer`'s INITIAL-BATCH replay is epoch-gated: `controller_epoch` is a shared `Arc<AtomicU64>`, the writer re-reads it UNDER `send.lock()` (atomically with `write_frame`) and returns the instant it is superseded — no check-then-block-then-write window, no superseded replay (W1-safe: never blocks the drain under `Mutex<OutputLog>`). The LIVE loop is NOT gated (new output only flows to the current controller; a superseded writer must still deliver its terminal `Displaced` kick — gating it suppressed the loud-take notice; it ends on `tx`-drop). (3) EXPLICIT-RESUME / OPERATOR-STREAM BOUNDARY (the LOAD-BEARING fix — kitsubito RACEDIAG ~33% repro the keystones missed) — `Brain::subscribe_with` (shared by attach/attach_as) resets the resume-mode dedup cursor to `from_seq`. The handoff eager subscribe makes serve_attach's brain receive the replay's seq K BEFORE the operator Request is processed (`attached`=false); that frame is dropped by the if-attached forward gate but the snap-above cursor already advanced past K, and `attach_as(sid,0)`'s re-subscribe used to leave the cursor advanced → the broker's re-send of seq K arrives below it, deduped, never forwarded → operator viewport forward-gap (silent content loss in the real rc consumer). Resetting to from_seq on the attach_as re-subscribe re-delivers from 0 (operator dedups the overlap) so seq K reaches the viewport. The epoch gate (2) is sound (RACEDIAG: zero socket interleaving above K); cold-start brains (empty map — production dispatch serve) keep the legacy next_seq path, so production is unaffected. (v0.13.0)
2026-07-06T06:24:02.7147884Z - Required stages: doc, impl, unit, int
2026-07-06T06:24:02.7147918Z 
2026-07-06T06:24:02.7148027Z ### REQ-HAZARD-CONTROLLER-RETAKE-FLOOR
2026-07-06T06:24:02.7152345Z - Title: `become_controller` should STRUCTURALLY refuse a controller re-take whose `from_seq` falls below the connection's already-delivered contiguous floor — making the P1c reorder invariant un-reintroducible by a future caller, not just removed at the one caller. ROOT/SCOPE (doyle proposed, P1c gate dialogue): P1c fixes REQ-HAZARD-CONTROLLER-WRITER-REORDER three ways (handoff single-take + epoch-gate-under-lock + session_cursors seed), removing the one decreasing-floor double-take and bounding any other to already-committed-only. A self-enforcing broker guard would refuse the bad SHAPE outright. BLOCKER: the obvious predicate (`from_seq >= delivered_through`) is UNSAFE because `delivered_through` is SESSION-WIDE (the `Arc<AtomicU64>` on `OutputLog`, shared by all controllers/viewers, advanced monotonic-MAX; `resume_seq` reads it) — a normal fresh-operator `from_seq=0` attach to a producing session legitimately sits below it (full ring replay + consumer dedup-below/snap-above), and monotonic-MAX can't distinguish the hazard (a `seq1`-without-`seq0` write reads as `2`). The structurally-correct guard needs a NEW per-connection contiguous-sent cursor (the true highest-contiguous seq this socket has received) that does not exist today; the guard then refuses a re-take below THAT. Bigger than P1c; no live gap (P1c fully fixes the actual bug). Mint/refine stages when the per-connection cursor is built. (v0.13.0 follow-up, post-ship)
2026-07-06T06:24:02.7152560Z - Required stages: 
2026-07-06T06:24:02.7152584Z 
2026-07-06T06:24:02.7152728Z ### REQ-ADAPTER-MULTIPLATFORM-SPT
2026-07-06T06:24:02.7155349Z - Title: A `.spt` adapter archive may pack multiple platforms in one signed asset: shared `manifest.toml` + `strings/` at the root, role binaries under per-Rust-target-triple subdirectories (ADR-0016 triple vocabulary, e.g. `x86_64-pc-windows-msvc/`); install/update extracts the shared root plus ONLY `current_platform()`'s triple subdir, flattened into `install_dir` so flat `<install_dir>/<program>` resolution (REQ-INSTALL-11) is unchanged. Name stays `adapter.spt` (plain-tar or gzip, `--asset` optional default); one whole-archive Ed25519 signature over the fat archive (REQ-UPD-9 single-artifact verify). A legacy flat archive (no triple subdirs) extracts as today (free back-compat); a multi-platform archive sets `min_spt_core_version >= 0.13.2` (forward-compat gate, readable before extract); a multi-platform archive missing the recipient's triple -> typed `NoArtifactForPlatform`, never a silent no-op. Large adapters may still split per-platform (single-triple archives via `--asset`, or ADR-0016 update-set machinery). (ADR-0024, v0.13.2)
2026-07-06T06:24:02.7155463Z - Required stages: doc, impl, unit, int
2026-07-06T06:24:02.7155491Z 
2026-07-06T06:24:02.7155592Z ### REQ-ADAPTER-LIVE-UPDATE
2026-07-06T06:24:02.7158377Z - Title: An adapter update is live and daemon-coordinated (the adapter analog of brain self-update, ADR-0004): for an endpoint with a running RESIDENT adapter binary (today the `[message-idle-translation-binary]`), the CLI keeps fetch+verify and hands the APPLY to the daemon over IPC, which per affected endpoint (1) STOPS the resident binary -> releases the OS file lock (fixes the Windows 'Access denied (os error 5)' overwrite failure), (2) swaps on disk ONLY files whose CRC differs from the staged archive (unchanged files + their still-running binaries untouched), (3) RE-CLONES the new on-disk manifest into the running `BrainLifecycle` (the in-memory manifest is cached at bringup and otherwise goes stale -> binaries+manifest back on the same page), (4) RESTARTS the resident binary from the new files. An endpoint NOT running -> CLI swaps directly (no lock, no cache). Only the resident class is cycled; ephemeral adapter binaries (Psyche loop, `[digest]` extractor, `[session.*]` runners, hooks) self-heal on next spawn and are excluded. The daemon keeps a per-endpoint registry of resident adapter children. (ADR-0025, v0.13.2)
2026-07-06T06:24:02.7158601Z - Required stages: doc, impl, unit, int
2026-07-06T06:24:02.7158634Z 
2026-07-06T06:24:02.7158740Z ### REQ-HAZARD-ADAPTER-APPLY-SILENT-NOOP
2026-07-06T06:24:02.7163406Z - Title: A DELEGATED live adapter apply MUST NEVER report success without performing the swap, and the live-update seam MUST use ONE parent-aware adapter matcher across all its comparators. TWO defects made the field repro (BUILD-F015B-APPLYMATCH: `--adapter cc:ccs` live update silently no-ops): (D1, matcher skew) the broker's dispatch_adapter_apply filtered sessions by EXACT `s.adapter == req.adapter`, but a `--adapter <adapter>:<profile>` endpoint stores the COMPOSITE `cc:ccs` while the apply carries the PARENT record name `cc` — so every :profile endpoint fell out to affected=[]; select_endpoints_running_adapter had the same `adp == adapter` skew, while the CLI live-gate (adapter_has_live_endpoint) already parent-matched — divergent rules on ONE seam. (D2, silent success) the affected.is_empty() branch replied KIND_APPLIED and RETURNED WITHOUT SWAPPING; once the CLI delegates the apply there is no CLI-side fallback swap, so success-without-swap = the update never lands (re-register re-reads the OLD manifest, version-of-truth honestly says old). FIX: (1) ONE shared spt_runtime::profile::adapter_parent_matches(session_adapter, parent) used by the live-gate + broker apply-filter + select_endpoints_running_adapter (no exact `==` against a record name at any live-update seam); (2) the daemon owns the whole apply once delegated — the CRC swap runs UNCONDITIONALLY (terminate/restart loops no-op when nothing is resident), KIND_APPLIED reported ONLY after a real swap. (F015B, ADR-0025 amendment)
2026-07-06T06:24:02.7163607Z - Required stages: doc, impl, unit, int
2026-07-06T06:24:02.7163640Z 
2026-07-06T06:24:02.7163764Z ### REQ-HAZARD-STOP-PATH-PSYCHE-ORPHAN-REAP
2026-07-06T06:24:02.7166623Z - Title: Endpoint-stop and brain-death reconcile MUST reap a brain-less perch's orphan detached Psyche via the cmdline-scoped guard (`psyche_orphan_should_reap`) — the handle-reap (`LiveSet::stop_host`, REQ-HAZARD-UNHOST-PSYCHE-REAP) CANNOT, because the owning brain is gone (its `psyche_child` handle died with it), and the brain-start scoped-reap (REQ-HAZARD-BRAIN-RESTART-PSYCHE-DUP) never fires for a perch being STOPPED rather than re-hosted. So the live-host calls the scoped reap after `stop_host` at the reconcile stop-side AND in `confirm_residency_or_unhost`. Preserves fail-safe-decline (pid-alive AND exe-basename==psyche-program AND cmdline contains `<id>-psyche`; any unreadable signal DECLINES — a missed dup is bounded, a wrong-kill is catastrophic). This is the orphan-leak half of the perri F-010xF-015 field bug (the unsupervised install-dir Psyche that locked an update); the other half is the psyche own-copy (ADR-0025 amendment). (v0.13.2 W3 (a))
2026-07-06T06:24:02.7166733Z - Required stages: 
2026-07-06T06:24:02.7166767Z 
2026-07-06T06:24:02.7166868Z ### REQ-ADAPTER-UPDATE-MESSAGE
2026-07-06T06:24:02.7168351Z - Title: An adapter manifest may declare `[update].message` — a plain (multi-line) human notice surfaced to stdout, markdown-rendered (the v0.13.0 helpfmt prose path), ONLY when `spt adapter update` actually APPLIES an update (version changed), not on a no-op. Read from the newly-installed manifest; avenue-agnostic (gh_release/delegated/file_pull). No `{key}` substitution. Use: an adapter telling the operator a post-update action, e.g. spt-claude-code's "run `/reload-plugins` in any ongoing sessions". (v0.13.2)
2026-07-06T06:24:02.7168457Z - Required stages: doc, impl, unit
2026-07-06T06:24:02.7168485Z 
2026-07-06T06:24:02.7168589Z ### REQ-ADAPTER-GH-TRANSPORT
2026-07-06T06:24:02.7169971Z - Title: The `gh_release` avenue (and `spt adapter add --release`) gain a fetch `transport`: `https` (current reqwest direct, public), `gh` (shell the pre-authorized `gh` CLI — the private-repo path; `gh` honors OAuth and `GH_TOKEN`, so spt custodies no token), or `auto` (default: prefer `gh` when installed+authed, else HTTPS). `--gh`/`--https` force it on `add`. Additive over the existing fetch path; verify->extract->register downstream is unchanged. (v0.13.2)
2026-07-06T06:24:02.7170179Z - Required stages: doc, impl, unit
2026-07-06T06:24:02.7170207Z 
2026-07-06T06:24:02.7170308Z ### REQ-ADAPTER-PROOF-DIR-OVERRIDE
2026-07-06T06:24:02.7171709Z - Title: The author-time proof commands (`spt adapter digest-proof`, `spt adapter translate-proof`) gain a `--dir <path>` / `--manifest <file>` override so an author proofs a DEV binary against an on-disk manifest+install dir WITHOUT staging a full extracted GhReleaseManaged install (mirrors digest-proof's `--sample` pointing straight at a file). Fixes perri F-011: a bare-file-added gh_release adapter currently can't be resolved by the *-proof commands ('manifest is not present yet at <dir>'); un-stales the bare-file digest-proof int. (perri F-011, v0.13.x DX)
2026-07-06T06:24:02.7171906Z - Required stages: doc, impl, unit, int
2026-07-06T06:24:02.7171939Z 
2026-07-06T06:24:02.7172048Z ### REQ-ADAPTER-VERSION-CMD
2026-07-06T06:24:02.7173533Z - Title: `spt adapter version <name>` prints a registered adapter's declared version — the EXISTING mandatory `[adapter].version` manifest field (manifest.rs already requires it; NOT a `[strings].version`, NOT `get-string`, no second version source). A new `AdapterCmd::Version{option}` resolves the option's merged view via `registry::resolve_option` like the sibling adapter subcommands and prints `manifest.adapter.version`; an unresolvable option errors (exit 1) the same way. (v0.13.2 W6)
2026-07-06T06:24:02.7177933Z - Required stages: doc, impl, unit
2026-07-06T06:24:02.7177976Z 
2026-07-06T06:24:02.7178091Z ### REQ-DOCS-NO-INTERNAL-CODES
2026-07-06T06:24:02.7179826Z - Title: Public CLI --help (the clap `///` doc-comments) and the generated `docs-site/src/cli/reference.md` MUST NOT contain internal tracker/decision codes — `REQ-*`, `F-###`, `M#-W#`, `ADR-####`. They are meaningless to an end user reading --help and ship to GH-Pages. A CI-gated scan (the `xtask check` docs gate) fails on any such token in the GENERATED reference.md (which by construction contains only clap help, so rustdoc `///` on fns/structs is OUT of scope and keeps its REQ/ADR cross-refs). Substance is kept; codes are rewritten to plain language. (v0.13.2 W6)
2026-07-06T06:24:02.7179937Z - Required stages: doc, impl, unit
2026-07-06T06:24:02.7179971Z 
2026-07-06T06:24:02.7180069Z ### REQ-RUN-MULTISUBNET-HOME
2026-07-06T06:24:02.7182742Z - Title: `spt endpoint run` resolves the home subnet at the skeleton-create step and pre-creates the skeleton perch carrying it, so the harness `bind` inherits home via establish_perch's immutable prior-branch (no hook change, no env injection). Resolution: sole-subnet auto; multi-subnet + no --subnet + NON-interactive terminal -> refuse early with MRU-ordered --subnet guidance (never the silent 25s online-timeout); multi-subnet + no --subnet + INTERACTIVE -> print proposed config (id/project/adapter[:profile]/home=MRU-default) + 'Ok to proceed? Y/n', n -> --subnet guidance; --subnet overrides + validates membership. MRU = ordered move-to-front LISTs at two levels (per-project + always-updated node-global fallback). Home stays IMMUTABLE (ADR-0010). Fixes the LATENT multi-subnet bringup gap (perri, not a regression — HOME_REFUSED established >=0.11.0; exposed by the node crossing 1->2 subnets). (ADR-0026)
2026-07-06T06:24:02.7182857Z - Required stages: doc, impl, unit, int
2026-07-06T06:24:02.7182890Z 
2026-07-06T06:24:02.7183003Z ### REQ-ENDPOINT-UNBOUND-ATTACH
2026-07-06T06:24:02.7185484Z - Title: An spt-hosted endpoint is ATTACHABLE between spawn and bind: gate the attach on the broker SESSION being attachable (session+PTY+OutputLog exist at spawn, before bind), not on perch STATUS_ONLINE (bind). cmd_endpoint_run + `spt rc <id>` attach to a live broker session regardless of perch status (headless bringups too; lets an operator clear a bind-gating prompt) -- replaces await_endpoint_online; preserves REQ-HAZARD-RC-ATTACH-ONLINE-RACE's 'no attach before a session' intent at the earlier session-exists point; source = the broker sessions map (ADR-0025 W3a); local-only. New on-disk status STATUS_UNBOUND (spawn->unbound, bind->online, death->offline); lifecycle reuses the existing exit-waiter/reconcile (session death->offline); unbound is attachable but NOT message-addressable (messaging stays online/bound-gated). EpDisplay gains Unbound = HOLLOW (+ hollow-controlled variant) -- amber=HarnessOnly is taken + means not-controllable (the opposite of attachable). (ADR-0027)
2026-07-06T06:24:02.7185734Z - Required stages: doc, impl, unit, int
2026-07-06T06:24:02.7185762Z 
2026-07-06T06:24:02.7185861Z ### REQ-MANIFEST-SUBST
2026-07-06T06:24:02.7188503Z - Title: Manifest substitution primitives for resolve-not-execute (ADR-0029, supersedes a rejected `spt api run-hook`): (1) two adapter-static substitution keys `{adapter_dir}` (the registry record's precise source_dir — install dir, survives updates, the dir bare-program resolution uses) and `{adapter_name}`, available wherever command/string substitution runs; (2) lazy substitution INSIDE `[strings]` values at `get-string` read time, scoped to those adapter-static keys ONLY (session-scoped {id}/{session_id}/… are NOT available — get-string carries no session; a get-string --session-id is a deferred larger change). Invariant preserved: spt-core never executes a string — it substitutes and returns; the adapter's own wrapper executes the result (e.g. a CC hook dispatcher get-strings its packed binary once per session into an env var, then runs it per-hook, so hook logic rides `spt adapter update`). (v0.16.0)
2026-07-06T06:24:02.7188713Z - Required stages: doc, impl, unit
2026-07-06T06:24:02.7188742Z 
2026-07-06T06:24:02.7188846Z ### REQ-ADAPTER-UPDATE-POST
2026-07-06T06:24:02.7191938Z - Title: Composite adapter update — an avenue-agnostic `[update.post]` sub-table `{ command, self_verifies }` run AFTER the primary avenue (gh_release/file_pull/delegated) resolves, in the same `spt adapter update` (ADR-0029). Runs UNCONDITIONALLY (even on an adapter version no-op — the post-step's own idempotent check decides). PUBLISHED stdin JSON seam: one line `{adapter_applied, adapter_name, profile_name, version, previous_version, adapter_dir}` (additive keys; post-step ignores unknown). stdout decides the notice: custom text SUPERSEDES [update].message; a reserved sentinel fires the static [update].message; empty = no notice. exit code orthogonal (0 ok / nonzero failed). Precedence: dynamic-stdout > sentinel/manifest-message > nothing. NO [update.post] declared ⇒ today's adapter_applied→[update].message unchanged; post-step FAILS ⇒ loud warning + fall back to adapter_applied→message. FAILURE-ISOLATED: a committed gh_release pull is never rolled back if the post-step fails (independent channels). (v0.16.0)
2026-07-06T06:24:02.7192057Z - Required stages: doc, impl, unit, int
2026-07-06T06:24:02.7192086Z 
2026-07-06T06:24:02.7192200Z ### REQ-TRANSLATE-COMMAND
2026-07-06T06:24:02.7195558Z - Title: `[message-idle-translation-binary]` accepts a `command` (opaque; args + ADAPTER-STATIC {adapter_dir}/{adapter_name} substitution ONLY — ratified v0.16.0 W1, NOT session {key}: the translation binary is a persistent process serving all sessions on the endpoint (session/event ctx arrives per-message via the stdin Init/Event protocol, never the spawn argv) and the live-update respawn site has no session ctx (a {id}-bearing command would MissingKey→spool); program token resolved against install_dir like [digest].extractor/[session.psyche_init]) in addition to the bare `path`. `path` is DEPRECATED — keeps parsing (manifest forward/back-compat) but emits a registration warning steering to command. Exactly one of {path, command} (both-set refused at registration; neither = no translation binary). The spawn lifecycle + stdin/stdout JSON-lines protocol (Init/Event/Input → key/text/delay_ms/commit) are UNCHANGED — command alters only how the executable+args are located/launched (read_translation_path → read_translation_command). Unblocks folding `claude-spt translate` into the one consolidated binary (downstream ADR-0006). (v0.16.0)
2026-07-06T06:24:02.7195778Z - Required stages: doc, impl, unit
2026-07-06T06:24:02.7195811Z 
2026-07-06T06:24:02.7195907Z ### REQ-SEND-REPLYTO-REMOVE
2026-07-06T06:24:02.7197246Z - Title: Remove `--reply-to` from `spt send` — a target-fallback + REPLIED-label nicety that confuses agents, with no wire effect (ADR-0020 already made messages structural (from,body), no __REPLY_TO__). Hard-remove (no deprecation shim): the clap flag, the is_reply/REPLIED label branch (always SENT/QUEUED), the `send` how-to --reply-to example, and the reply-to mention in REQ-DOCS-6's send topic. Reply-correlation stays on the structural `from` attribute. (v0.16.0)
2026-07-06T06:24:02.7197341Z - Required stages: impl, unit
2026-07-06T06:24:02.7197374Z 
2026-07-06T06:24:02.7197469Z ### REQ-DIGEST-CURSOR
2026-07-06T06:24:02.7201124Z - Title: `spt endpoint digest` gains incremental turn-end consumption (extends REQ-TERM-4/5): `--last <N>` = the last N TURNS (the digest's natural unit; --last 1 = the latest turn = turn-end output); a per-entry STABLE SOURCE-DERIVED `seq` in the --json output (deterministic from the entry's append position in the source — transcript record index across the session ledger / digest.log index — so a live re-projection yields the same seq for the same committed entry; NOT a window-position index that renumbers on slide); `--after <seq>` = entries newer than seq still in the window (full window + signal if seq predates it, mirroring the version-slide full-refresh). An in-flight (still-growing) entry is flagged `partial: true` with NO stable seq until finalized (consumer reprocesses partial, skips <= seq). Also emit per-entry `ts` where present (seq is the authoritative dedup+cursor key). The digest's agent text is sufficient fidelity (no raw-source mode). BINDING doc-guidance: an adapter's [digest] extractor / api digest-entry MUST classify delivered user-facing messages as turn-opening `input` (equiv to direct PTY user-input), else messaging-driven sessions collapse into a few giant turns and --last/seq lose granularity. (v0.16.0)
2026-07-06T06:24:02.7201363Z - Required stages: doc, impl, unit
2026-07-06T06:24:02.7201396Z 
2026-07-06T06:24:02.7201472Z ### REQ-CLI-JSON
2026-07-06T06:24:02.7203456Z - Title: A global `--json` flag (clap global=true) honored by the READ/STATUS command set: endpoint list/whoami, daemon status, subnet status/show-code, endpoint description/role, adapter list/version, notif list, grant list, access list, shell list, how-to (endpoint digest already has it). Action commands do not honor it. A shared print_json() helper + a coverage TEST asserting every command in the set emits valid JSON (guards against the missing-shared-formatter drift). Output uses explicit per-command output DTOs with committed field names — internal structs are NOT serialized verbatim (their fields would become a public contract; JSON is a consumed wire-parity surface). (v0.16.0)
2026-07-06T06:24:02.7203571Z - Required stages: impl, unit, int
2026-07-06T06:24:02.7203605Z 
2026-07-06T06:24:02.7203686Z ### REQ-RUN-EMPTY-CREATE
2026-07-06T06:24:02.7204970Z - Title: `spt endpoint run` / bare `spt` routes a TOTALLY-EMPTY scope straight to the endpoint-creation flow: when gather_endpoints() is empty (nothing attachable, local OR subnet) PickerModel::new opens on Screen::CreateAdapter instead of PickExisting (today it always opens PickExisting + renders a blank list). A node WITH subnet endpoints but no local ones still has things to pick → stays on the picker. Extends REQ-RUN-PICKER. (v0.16.0)
2026-07-06T06:24:02.7205069Z - Required stages: impl, unit
2026-07-06T06:24:02.7205102Z 
2026-07-06T06:24:02.7205184Z ### REQ-RC-IDENTITY
2026-07-06T06:24:02.7207409Z - Title: `spt rc` overlays a persistent endpoint-identity marker so the operator always groks which endpoint they control: a reserved TOP status row via a DECSTBM scroll-region (shrink the PTY's reported rows by 1, own the row), right-aligned `SUBNET : ENDPOINT_ID @ NODE`, CYAN text. Re-assert the margin + repaint on alt-screen enter / DECSTBM reset / resize (output-scanning, like the existing mouse_scanner). NO window title (the harness, e.g. CC, owns it for busyness — OSC dropped). Resolve subnet/node/id once at attach (perch/registry read) and thread into the pump; subnet = the endpoint's home/primary ("local" if none). The literal floating rounded-rectangle corner box is DEFERRED to the future web-based GUI (not a grid-model rc — that lift is better spent on the GUI). (v0.16.0)
2026-07-06T06:24:02.7207605Z - Required stages: impl, unit, int
2026-07-06T06:24:02.7207638Z 
2026-07-06T06:24:02.7207734Z ### REQ-JOIN-TWO-PHASE
2026-07-06T06:24:02.7211254Z - Title: `spt subnet join` is two-phase (meet-before-code) so the entered code is FRESH at the ceremony regardless of discovery time (ADR-0030). The meet selector is the PUBLIC `(subnet-name, TOTP-epoch)` (rendezvous_token = SHA256(domain ‖ name ‖ totp_step)); the secret TOTP-code is the SPAKE2 password ONLY, never a discovery input — so the code is collected AFTER a member is found. Extend the brain.pair_join event stream (brain.rs:1009): CLI PairMeetReq{subnet} → daemon meets (name, current-epoch) resolving the seed-holder's REAL stable pairing address → MetMember event → CLI prompts the code (cli.rs cmd_subnet_join :6236) → PairCodeSubmit{code} → daemon dials the held real-address on SPT_PAIR_ALPN + SPAKE2 → PairJoined/PairFail. Daemon holds the real-address between phases, bounded by a 5-MINUTE wait-for-code timeout; a wrong-code retry re-runs the CEREMONY ONLY against the held address (no re-search). The non-interactive `--code` path stays one-shot (no prompt; relies on REQ-NET-FAMILY-GATE fast discovery, fails loudly per REQ-JOIN-DIAGNOSTICS on staleness). Security unchanged — the meet is pre-trust/unauthenticated (SPT_PAIR_MEET_ALPN); auth stays in SPAKE2. (next milestone)
2026-07-06T06:24:02.7211479Z - Required stages: doc, impl, unit, int
2026-07-06T06:24:02.7211507Z 
2026-07-06T06:24:02.7211599Z ### REQ-NET-FAMILY-GATE
2026-07-06T06:24:02.7213969Z - Title: spt-core binds only IP families that are actually REACHABLE (ADR-0030), so a half-broken family (e.g. IPv6 whose AAAA resolves but whose path is dead) never silently consumes connection/discovery time. At NetEndpoint::bind (endpoint.rs), probe each family's reachability ONCE and bind only the working ones: dual-stack when both healthy; IPv4-only when IPv6 is dead; IPv6-only when IPv4 is dead (drop the DEAD family — NOT a fixed prefer-IPv4; IPv6-only networks must keep working). Re-evaluated on daemon restart (once-at-bind, no live re-eval in v1). Explicit overrides SPT_DISABLE_IPV6 / SPT_DISABLE_IPV4 force a family off (escape hatch + determinism + testing, mirroring SPT_NTP_SERVER); a forced-off family is never bound regardless of the probe. Reusable beyond join — every spt connection benefits. (next milestone)
2026-07-06T06:24:02.7214078Z - Required stages: doc, impl, unit
2026-07-06T06:24:02.7214122Z 
2026-07-06T06:24:02.7214213Z ### REQ-JOIN-DIAGNOSTICS
2026-07-06T06:24:02.7216979Z - Title: `spt subnet join` never fails SILENTLY (ADR-0030; the field incident showed no output at all). (a) LIVE progress during the meet (replace the one-shot "Searching…" cli.rs:6268 with periodic elapsed/deadline) so silence ≠ hang; (b) DETAILED failure on meet-exhaustion — rendezvous candidates + families attempted (IPv4/IPv6) + relay-vs-direct + the last concrete error — surfaced BEFORE any code prompt (a dead subnet must not make the user fetch a code); connect_seed_holder (pairhost.rs:437) and dial_via_rendezvous (meet.rs:281) currently swallow per-attempt errors — thread the last error up with attempt context; (c) PROPAGATE the terminal event — brain.rs:1024 `_ => continue` must deliver a daemon NoSeedHolder/PairFail to the CLI as a printed error (this is WHY the user saw nothing); (d) `--verbose`/`SPT_LOG` discovery TRACE (per-probe derived id, discovery path mDNS/n0-DNS/relay, per-family timeouts), opt-in — no such knob exists today. (next milestone)
2026-07-06T06:24:02.7217188Z - Required stages: doc, impl, unit
2026-07-06T06:24:02.7217222Z 
2026-07-06T06:24:02.7217323Z ### REQ-PRESENCE-LIVENESS-TRUTH
2026-07-06T06:24:02.7222211Z - Title: A node's gossiped per-endpoint registry Status reflects real liveness, so a remote viewer never paints a DEAD endpoint as ONLINE. ROOT (confirmed + gated vs CONTEXT.md): registryhost.rs:397-405 advertises a NOT-alive perch as Status::Dormant (the `else` of is_perch_alive), re-stamped every gossip round (never ages to Offline). Design intent GATED vs resting.rs + CONTEXT.md: active/dormant is the MULTI-INSTANCE routing differentiator (active = the bare-id routing target; dormant = a WARM non-target sibling — 'driving ling@laptop makes ling@desktop dormant', resting.rs:97; transitions active→dormant on AttentionShift/Detach). suspended = COLD (session closed, resumable-on-wake) while its NODE is UP. offline = NODE DOWN — NEVER self-gossiped (RestState has no Offline; a live node only ever gossips active/dormant/suspended), remote-inferred via epoch-lease eviction. So labeling a NOT-running perch Dormant is the DEFECT (dormant requires warm/running). PRIMARY FIX (registryhost `else`, not-bound-alive): live-but-UNBOUND (has a live broker session; is_perch_alive is bound-gated) → Active/Dormant (still warm); else (cold, no live session, but its node is up because this very daemon is gossiping) → SUSPENDED — NOT Dormant, NOT Offline (the node is UP; Offline is never self-gossiped). This alone removes the false-ONLINE. dormant keeps gossiping (routing/MRA needs it) but RENDERS as its online flavor (no distinct glyph; the dormant→suspended auto-suspend timer disambiguates recency). The DISPLAY of these states (incl Suspended=gray-filled) is REQ-SUBNET-DISPLAY-PARITY. Design: docs/design/subnet-presence-display.md §A. (next milestone)
2026-07-06T06:24:02.7222425Z - Required stages: impl, unit, int
2026-07-06T06:24:02.7222459Z 
2026-07-06T06:24:02.7222564Z ### REQ-SUBNET-DISPLAY-PARITY
2026-07-06T06:24:02.7226810Z - Title: The `spt endpoint run` picker renders endpoint state IDENTICALLY for local and remote (subnet) rows — bound/unbound, controlled (+driver node), and harness-only are all visible across the subnet, not local-only. Today data.rs:293-294 reduces a remote row to plain green-filled/gray-hollow because those facts aren't propagated. (1) GOSSIP additive per-Instance fields: bound/unbound, controlled + driver-node, harness_only (Offline is never gossiped — node-down is remote-inferred). (2) Derive the full EpDisplay for subnet rows from the gossiped fields, same path as local (remove the remote-reduction). (3) PALETTE rework (fill = ACTIONABLE: filled=can act now (rc-control if online, WAKE if suspended-on-live-node) / hollow=cannot (no control seat / node gone)): green-filled=online+bound+free; blue-filled=online+controlled (desc shows `controlled by <node>`); RED-filled=online+UNBOUND (controlled-or-not; controlled-ness shown via available options not glyph) — replaces green-hollow Unbound + absorbs the dropped UnboundControlled; AMBER-HOLLOW=online+harness-only (no broker seat → can't rc) — was amber-FILLED; GRAY-FILLED=Suspended (cold, node up — wakeable) NEW; gray-hollow=Offline (node down) now REMOTE-ONLY. EpDisplay: drop UnboundControlled, Unbound→red-filled, HarnessOnly→amber-hollow, add Suspended(gray-filled). Picker maps Active|Dormant→online flavor, Suspended→gray-filled, Offline→gray-hollow. (next milestone)
2026-07-06T06:24:02.7226933Z - Required stages: impl, unit, int
2026-07-06T06:24:02.7226968Z 
2026-07-06T06:24:02.7227063Z ### REQ-UPDATE-FETCH-CURRENT-UX
2026-07-06T06:24:02.7229942Z - Title: `spt update fetch` reports an already-staged / already-applied latest as an ACTIONABLE human outcome (exit 0), not a Debug-formatted error. ROOT: cmd_update_fetch (cli.rs) sets the rollback floor = staged_version, so when the published candidate == the already-staged version, verify_update_set_metadata returns Err(RejectReason::Rollback{current,candidate}) — printed as {reason:?} (Debug) at exit 1, reading as a FAILURE when the update is merely already downloaded and just needs `spt update apply` (this bit the operator: fetch kept 'failing', apply was the missing step). FIX: a PURE classifier (reason, applied, staged) -> {AlreadyStaged (latest downloaded, not yet installed) / AlreadyApplied (up to date) / GenuineError}; already-staged + already-applied print a friendly message and exit 0; genuine rejects use RejectReason's Display (release.rs, not Debug) + exit 1 — applied at ALL THREE fetch reject sites (metadata + artifact-verify + plan-verify). (v0.18.0)
2026-07-06T06:24:02.7230142Z - Required stages: impl, unit
2026-07-06T06:24:02.7230176Z 
2026-07-06T06:24:02.7230271Z ### REQ-UPDATE-FETCH-APPLY-FLAG
2026-07-06T06:24:02.7232856Z - Title: `spt update fetch --apply` is the one-shot get-to-latest: fetch, then INSTALL the staged update REGARDLESS of whether the fetch itself staged anything new — so the brittle `fetch && apply` chain (which broke when fetch no-oped / exited nonzero on an already-staged latest, skipping the chained apply) is unnecessary. Composes with REQ-UPDATE-FETCH-CURRENT-UX: the end state is 'installed latest', reached idempotently from new-staged -> apply / already-staged (applied<candidate) -> STILL apply / already-applied -> noop+exit0 / genuine error (bad signature, no artifact for platform, true downgrade, network) -> do NOT apply, propagate the error + nonzero. Reuses the existing cmd_update_apply core (its own verify + two-phase + auto-rollback own correctness; no duplicated swap/respawn). Additive clap flag (plain doc-comment, no internal codes); reference.md regenerated. (v0.18.0)
2026-07-06T06:24:02.7233058Z - Required stages: impl, unit
2026-07-06T06:24:02.7233091Z 
2026-07-06T06:24:02.7233189Z ### REQ-UPDATE-RUNNING-IMAGE-SURFACE
2026-07-06T06:24:02.7236384Z - Title: `spt` surfaces the RUNNING broker image version beside the on-disk version so an updated-looking node reveals broker-side dormancy. ROOT (F-025): `spt update apply` restarts the BRAIN only (ADR-0018 D3-3) — the BROKER process survives and keeps running its pre-apply compiled image, so every broker-side surface of a freshly-applied release (the F015B live-apply matcher, dispatch inject legs, etc.) is silently dormant until a full daemon bounce, with nothing in the CLI revealing the split. FIX: the running broker SELF-REPORTS its compiled image version over IPC (a new request KIND answered by the live broker process from its own compiled build constant) — HARD CONSTRAINT: the version comes FROM the running broker process, NEVER inferred from disk bytes, install manifest, or file timestamps, since the disk is exactly the half that is already ahead; a version-surface command (`spt version` and/or `spt daemon status`) prints the running-broker version beside the on-disk/product version and flags a mismatch. Keeps read-side truth independent of write-side claims (the field lesson from F015B). (F-025)
2026-07-06T06:24:02.7236492Z - Required stages: impl, unit, int
2026-07-06T06:24:02.7236530Z 
2026-07-06T06:24:02.7236636Z ### REQ-UPDATE-APPLY-RESTART-NOTICE
2026-07-06T06:24:02.7238558Z - Title: `spt update apply` prints a LOUD restart-required notice whenever the surviving broker will keep running the pre-apply image (which, until broker-restart choreography exists, is ALWAYS on a successful apply). Public wording, no internal CODE:RESULT markers (composes with REQ-ADAPTER-UPDATE-MESSAGE / the update-apply-confident-message rule) — name the user-visible CONSEQUENCE ('daemon-coordinated features run the previous version until the daemon restarts'), not the broker/brain internals. Composes with REQ-UPDATE-RUNNING-IMAGE-SURFACE (the notice tells the user what the version-surface will then show, and how to clear it). (F-025)
2026-07-06T06:24:02.7238651Z - Required stages: impl, unit
2026-07-06T06:24:02.7238685Z 
2026-07-06T06:24:02.7238785Z ### REQ-UPDATE-APPLY-ALREADY-APPLIED
2026-07-06T06:24:02.7241162Z - Title: `spt update apply` classifies an already-staged / already-applied state as a friendly exit-0 no-op instead of dying at the binary-aside rename with 'Access is denied (os error 5)'. ROOT (F-025): a second apply on an already-applied staged version reaches the two-phase binary-aside rename and fails os-error-5, reading as a hard failure when the machine is simply up to date. FIX: apply gains the same pure classifier `fetch` got in v0.18.0 (REQ-UPDATE-FETCH-CURRENT-UX) — already-applied → clear message + exit 0, and the flow MUST short-circuit BEFORE the binary-aside rename in that state; mirror the classifier at ALL apply reject/entry sites the way the fetch fix covered its three. Genuine errors (bad signature, wrong platform, true downgrade, network) still propagate nonzero. (F-025)
2026-07-06T06:24:02.7241366Z - Required stages: impl, unit
2026-07-06T06:24:02.7241395Z 
2026-07-06T06:24:02.7241500Z ### REQ-BROKER-ATTACH-JOURNAL-RESILIENT
2026-07-06T06:24:02.7244180Z - Title: A poisoned EffectJournal mutex or a sick NetHost runtime must NOT permanently brick all future attaches. Bug #16 (URGENT): a live spt-hosted endpoint (eel-a) attach fails with 'brain IPC read deadline elapsed' after a self-update brain-respawn — the broker survives the respawn and one journaled op (dispatch_net_stream_open journal.apply_once + loopback open_stream runtime.block_on nethost.rs:1060) enters a bad state, so every journaled attach silently kills its per-conn reply thread while non-journaled ops keep working. Fix: recover PoisonError via into_inner (effect.rs apply_once, replace the .expect panics) so one panic cannot brick all attaches; bound the loopback open_stream block_on (nethost.rs:1060) like the QUIC bounded_block_on so a sick runtime fails fast with an error frame not an opaque 10s deadline. Reinforces REQ-HAZARD-EFFECT-JOURNAL-PTY-WEDGE. See docs/NEXT-MILESTONE-BUG-TRIAGE.md #16.
2026-07-06T06:24:02.7244419Z - Required stages: impl, unit
2026-07-06T06:24:02.7244452Z 
2026-07-06T06:24:02.7244547Z ### REQ-WAN-SEND-DELIVERY
2026-07-06T06:24:02.7246732Z - Title: Bug #9/#10: cross-node spt send reports SENT(WAN) but does not deliver, even on stable-IP pairs. Real root: spt send resolves the dial with id-only addr_for_node_hex (endpoint.rs:538) which forces a fresh iroh discovery round-trip every send, while the gossip pump uses cached direct addresses (dial_seeded/PeerAddrStore) so gossip stays green but send rides a marginal discovery path that cannot carry the fire-and-forget payload; the handshake completes so SENT(WAN) prints falsely. Fix: (1) route the WAN dial through the pump seeded-direct-address resolution (PeerAddrStore first, id-only fallback); (2) receiver writes its WanOutcome back so the sender confirms delivery under the QUIC deadline and only reports SENT on confirmed delivery, honest failure otherwise. Access-gate/perch/spool all verified correct (ruled out). See docs/NEXT-MILESTONE-BUG-TRIAGE.md #9-10.
2026-07-06T06:24:02.7246833Z - Required stages: impl, unit, int
2026-07-06T06:24:02.7246867Z 
2026-07-06T06:24:02.7246967Z ### REQ-RC-CROSS-NODE-ATTACH
2026-07-06T06:24:02.7249023Z - Title: Bug #4: spt rc to a remote endpoint fails with 'no live session' though endpoint list shows it Active — rc.rs:1063 resolves only the LOCAL broker session table and always dials loopback, never consulting the registry or dialing the owning node (the cross-node attach transport exists in the broker; only the client leg is missing). Fix: on a local resolve miss, resolve the owning node from the registry (reuse resolve_across_visible), net_dial that node, and run a remote session-resolve + serve_attach round-trip (mirror the wansend resolve-dial-round-trip pattern). Shares the resolve-owning-node primitive with REQ-WAN-SEND-DELIVERY. See docs/NEXT-MILESTONE-BUG-TRIAGE.md #4.
2026-07-06T06:24:02.7249137Z - Required stages: doc, impl, unit, int
2026-07-06T06:24:02.7249160Z 
2026-07-06T06:24:02.7249264Z ### REQ-RC-WIN-VT-OUTPUT
2026-07-06T06:24:02.7252680Z - Title: Bug #12: `spt rc` to an endpoint renders ANSI escapes LITERALLY (raw ←[K / color codes) on a Win10 conhost console, garbling the viewport — while `endpoint run --attach` in the SAME env renders fine and Win11 Windows Terminal is unaffected. Root (code-grounded, doyle): rc.rs RawGuard::enable calls only crossterm enable_raw_mode (INPUT raw mode) and NEVER enables ENABLE_VIRTUAL_TERMINAL_PROCESSING on the OUTPUT handle; Win10 conhost defaults VT-output OFF so escapes print literally, whereas the picker/alt-screen setup on the endpoint-run path enters crossterm's VT-enabling console setup first (leaving VT-output on) — so it is the rc-attach CLIENT PATH specifically, and --attach-works-same-env confirms (not refutes) the VT-out theory. Fix: in the rc attach path (RawGuard), on cfg(windows) + interactive console (mirror the windows_mouse_wanted guard so piped stdin/stdout keeps clean bytes for the e2e byte tests), SetConsoleMode STD_OUTPUT_HANDLE |= ENABLE_VIRTUAL_TERMINAL_PROCESSING|ENABLE_PROCESSED_OUTPUT, capture the prior mode, restore on Drop. cfg(windows)-only, client-side, independent of #4/#6. See docs/NEXT-MILESTONE-BUG-TRIAGE.md #12.
2026-07-06T06:24:02.7252875Z - Required stages: impl, unit
2026-07-06T06:24:02.7252980Z 
2026-07-06T06:24:02.7253089Z ### REQ-GOSSIP-CONTROLLED-ANY
2026-07-06T06:24:02.7255079Z - Title: Bug #3: a locally-controlled endpoint gossips controller_node = None so remote viewers show it free to control. Root: driven_by is stamped Some(node) only for a REMOTE WAN attach (attach.rs:337); a local controller is by=None by design (broker.rs:1750, KH 7.15 — a local-only controller must not latch driven_by). Fix: broker stamps a SEPARATE any-controller datum (true/Some(host) for a local OR remote controller) alongside stamp_driven_by, and advertise_local gossips Instance controller_node from it, leaving the remote-only driven_by untouched (do not trip REQ-HAZARD-DRIVEN-BY-SELFHEAL). node-refresh is NOT the fix (data is absent at source). See docs/NEXT-MILESTONE-BUG-TRIAGE.md #3.
2026-07-06T06:24:02.7255170Z - Required stages: impl, unit
2026-07-06T06:24:02.7255204Z 
2026-07-06T06:24:02.7255298Z ### REQ-SUBNET-COUNT-ROUTABLE
2026-07-06T06:24:02.7256999Z - Title: Bug #2: a remote node endpoint count drifts (0/2, 1/3) because node_status_rows (cli.rs:5314) increments the per-node total unconditionally, counting non-routable Offline ghost rows; purge is not a registry eviction (it gossips a one-shot Offline row that is immortal on remote viewers — eviction is per whole-node only). Fix: routable-only denominator (total += status.routable()) keeping a separate raw count for the all-Offline liveness branch; plus per-row Offline-TTL eviction so purged endpoints stop accumulating on remote snapshots. See docs/NEXT-MILESTONE-BUG-TRIAGE.md #2.
2026-07-06T06:24:02.7257095Z - Required stages: impl, unit
2026-07-06T06:24:02.7257128Z 
2026-07-06T06:24:02.7257227Z ### REQ-BROKER-SCREEN-GRID
2026-07-06T06:24:02.7259857Z - Title: Bugs #6 + #12 + #7/#8-artifacts: the broker is a raw-byte pump with no screen model — OutputLog replays the raw ring from seq 0 into a fresh terminal on attach, so an alt-screen TUI (Claude Code) corrupts scrollback (#6) and rc-to-a-pre-running-endpoint garbles (#12 — rc and endpoint run --attach are the SAME client fn, so it is replay content not a client-VT bug). Fix: a server-side VT/grid/screen model (tmux/mosh-style) that maintains authoritative screen + alt/main + cursor and synthesizes a CLEAN current-screen repaint on attach instead of replaying mid-stream ring bytes. Also eliminates residual-cell artifacts on animate/scroll/resize (#7/#8). Operator NON-NEGOTIABLE: accurate PTY representation with zero artifacts. (win32 vterm in the report means this server-side emulator, not ConPTY which is already the backend.) See docs/NEXT-MILESTONE-BUG-TRIAGE.md #6/#12.
2026-07-06T06:24:02.7259967Z - Required stages: doc, impl, unit, int
2026-07-06T06:24:02.7260001Z 
2026-07-06T06:24:02.7260101Z ### REQ-RC-IDMARKER-DISABLE
2026-07-06T06:24:02.7261450Z - Title: Bugs #14 + #7/#8 (marker half): feature-flag the top-right StatusRow endpoint-id marker OFF (rc.rs:198-307). It is a one-shot absolutely-positioned paint that scrolls off-screen and is not re-stickied (#14), and its DECSC/clear/SGR injection splices into the harness in-flight drawing causing residual artifacts (#7/#8). Ship disabled next release (operator: save the concept for a future web SPT GUI); revisit as a proper per-frame sticky overlay only once REQ-BROKER-SCREEN-GRID provides the screen model. See docs/NEXT-MILESTONE-BUG-TRIAGE.md #14.
2026-07-06T06:24:02.7261650Z - Required stages: impl, unit
2026-07-06T06:24:02.7261683Z 
2026-07-06T06:24:02.7261789Z ### REQ-ENDPOINT-LIST-PALETTE
2026-07-06T06:24:02.7264012Z - Title: Bugs #11 + #15 (display): spt endpoint list renders status as plain text while the picker turns the same ResourceRow into the W5 colored EpDisplay palette. Fix: extract one shared ResourceRow-to-EpDisplay builder + make the picker display enums/helpers public, and have endpoint list render the same colored status squares (via helpfmt stdout_color, not ratatui Span). This also fixes #15 — a lone warm detached instance renders as its online flavor (Dormant maps to online) instead of leaking the bare word Dormant through the text-only list (no resting.rs/CONTEXT model change; operator ruling display-only). Couples REQ-PICKER-NODE-GROUPING (both edit subnet_rows — sequence the shared-builder extraction first). See docs/NEXT-MILESTONE-BUG-TRIAGE.md #11/#15.
2026-07-06T06:24:02.7264207Z - Required stages: impl, unit
2026-07-06T06:24:02.7264235Z 
2026-07-06T06:24:02.7264336Z ### REQ-PICKER-NODE-GROUPING
2026-07-06T06:24:02.7265726Z - Title: Bug #13: the endpoint run Subnet tab shows a machine once PER shared subnet (subnet_rows data.rs:253 iterates per-subnet, groups by subnet:node, no cross-subnet dedup). Fix: dedup by (node, endpoint_id) across the subnet loop, collect the set of shared subnet names per endpoint, emit one group per MACHINE (group = node_display) with its shared subnets listed beneath the machine name; reconcile per-endpoint status across subnets (most-alive). Couples REQ-ENDPOINT-LIST-PALETTE (both edit subnet_rows). See docs/NEXT-MILESTONE-BUG-TRIAGE.md #13.
2026-07-06T06:24:02.7265835Z - Required stages: impl, int
2026-07-06T06:24:02.7265868Z 
2026-07-06T06:24:02.7265968Z ### REQ-ENDPOINT-LIST-NODE-GROUPED
2026-07-06T06:24:02.7270441Z - Title: spt endpoint list is node-grouped over unique INSTANCES, not subnet-grouped over duplicated rows: one row per (id,node) instance — subnet duplication collapsed (ADR-0006 §1: subnet is never an identity axis), freshest-epoch wins a cross-subnet status disagreement (the resolve_among twin rule) — grouped under 'This node: <label>' (cyan; local roster is the status truth, advertised-status vocabulary, corrupt = suspended + corrupt annotation) then remote nodes alphabetical (node name orange 38;5;208, the legacy $LIVE orange), each node carrying a light-gray 'Shared subnets:' line (subnets among our memberships where that node gossips any visible row; per-instance subnet detail stays in --json/--detail), instance rows [id, endpoint_type, glyph, status] (endpoint_type threaded from Instance.endpoint_type through ResourceRow — additive, pre-field rows render '-'), per-node 'Total:' lines with NO grand total (the stderr ENDPOINTS:<n> line is REMOVED — it counted subnet rows, so the same instance in N subnets counted N times), SELF pin kept first with a '(self @ <node>)' marker (REQ-WHOAMI-1 alias; self also appears as a This-node row so the node total stays honest), remote nodes with zero visible instances skipped, --subnet narrows the union to that subnet's view, --json DTO structure UNCHANGED (committed surface; gains only an additive endpoint_type field). Grill-with-docs ruling 2026-07-02 (operator + doyle); sibling of REQ-PICKER-NODE-GROUPING (the picker half of the same dedup law).
2026-07-06T06:24:02.7270557Z - Required stages: impl, unit
2026-07-06T06:24:02.7270590Z 
2026-07-06T06:24:02.7270689Z ### REQ-ENDPOINT-LIST-REST-FILTER
2026-07-06T06:24:02.7273094Z - Title: spt endpoint list hides SUSPENDED instances by default; a new --show-all flag reveals them. Status-first row ordering with fixed precedence ONLINE > CONTROLLED > UNBOUND > SUSPENDED (when shown) > corrupt last, alphabetical by id within each band. Two invariants: (1) CORRUPT rows ALWAYS render regardless of filters — corrupt is a record condition demanding operator action (purge/re-mint), not resting clutter; hiding it would re-create counter-39 bug #3 (cross-ref REQ-HAZARD-CORRUPT-PERCH-COHERENCE, CONTEXT.md instance-state _Also avoid_); (2) the per-node Total line DISCLOSES the filter — 'Total: N (+M suspended hidden)' — so nothing silently vanishes. Registry-Offline rows stay excluded by projection law (resource_projection skips unroutable; unchanged). Grill-with-docs ruling 2026-07-02 (operator + doyle).
2026-07-06T06:24:02.7273294Z - Required stages: impl, unit
2026-07-06T06:24:02.7273332Z 
2026-07-06T06:24:02.7273433Z ### REQ-ADAPTER-UPDATE-INPLACE
2026-07-06T06:24:02.7274844Z - Title: Bug #18: spt adapter update fails at re-register with os error 2 because it derives the install dir from the update repo NAME (_github/<safe>) instead of updating in place at the adapter record source_dir; when the adapter repo is intentionally renamed across releases (spt-claude-code to claude-spt, supported), the derived dir is fresh/empty and re-register reads a missing manifest. Fix: adapter update installs and re-registers in place at the registered source_dir and tolerates a changed update repo/URL across a rename. See docs/NEXT-MILESTONE-BUG-TRIAGE.md #18.
2026-07-06T06:24:02.7275031Z - Required stages: impl, unit
2026-07-06T06:24:02.7275064Z 
2026-07-06T06:24:02.7275163Z ### REQ-DIGEST-PROFILE-ENV
2026-07-06T06:24:02.7277463Z - Title: Bug #17: spt endpoint digest returns NO_DIGEST for a ccs-profile endpoint (claude-spt:ccs) though [digest] is wired and the transcript exists — under .ccs (CLAUDE_CONFIG_DIR relocation) not .claude. The on-demand digest runs the extractor in the daemon context WITHOUT the endpoint profile transcript-location env, so the env-aware resolver cannot find the relocated transcript. Fix: propagate/persist the endpoint profile transcript-location env (e.g. the ccs CLAUDE_CONFIG_DIR) to the on-demand digest extractor so a profile-relocated transcript resolves; confirm the exact extractor verdict via spt adapter digest-proof. Ownership spt-core (digest env/profile propagation), possibly with a claude-spt extractor-resolver assist. See docs/NEXT-MILESTONE-BUG-TRIAGE.md #17.
2026-07-06T06:24:02.7277569Z - Required stages: doc, impl, unit
2026-07-06T06:24:02.7277602Z 
2026-07-06T06:24:02.7277701Z ### REQ-DIGEST-FETCHER-STRATEGY
2026-07-06T06:24:02.7281559Z - Title: Bug #17 (W6b, closes eel-a end-to-end): [digest] gains a `fetcher` strategy mirroring [history]'s locate/normalize split (CONTEXT §history: [digest] mirrors history's two strategies — locate ownership). ROOT: the pre-W6b [digest] had only the locate_normalize analog (spt-core resolves ONE `source` template + pre-reads the file), which CANNOT express a PARTITIONED transcript layout — CC's projects/<munge(cwd)>/<session_id>.jsonl or a date-globbed rollout tree — the exact case CONTEXT already assigns to the adapter. spt-core (correctly) provides NO {project}/slug key (harness-specific cwd munging = the charter violation FIX-A was rejected for). Fix: strategy = fetcher makes the ADAPTER's extractor locate + read + emit normalized records; spt-core runs it bounded (no locate, no pre-read, no stdin) and consumes stdout, feeding only the harness-NEUTRAL inputs it owns — {session_id}, the perch-bound {cwd} (info.json.cwd), and the captured [env] direction=read vars (W6/REQ-DIGEST-PROFILE-ENV) — so the extractor globs the unique {session_id} under {read-var-root}/projects/ with no slug. Keeps locate_normalize (default, back-compat) for a trivial single-file harness. Distinct capability from REQ-DIGEST-PROFILE-ENV (which supplies the root env). See docs/NEXT-MILESTONE-BUG-TRIAGE.md #17.
2026-07-06T06:24:02.7281669Z - Required stages: doc, impl, unit, int
2026-07-06T06:24:02.7281703Z 
2026-07-06T06:24:02.7281803Z ### REQ-ADAPTER-ADD-SURFACE-ERRORS
2026-07-06T06:24:02.7283232Z - Title: Bug #1: adapter add runs the install-as-first-update via conduct (cli.rs:6963) which on a non-zero exit prints only the exit code and DISCARDS the subprocess stdout/stderr, so the real error is invisible (the failure itself does propagate). Fix: include out.stderr/stdout in the ADAPTER_INSTALL_FAIL message (mirror run_update_post_step). Operator ruling: ALSO run the [update.post] composite step at install-time (today it runs only on explicit adapter update), so an install both surfaces detail and completes the delegated post-step. See docs/NEXT-MILESTONE-BUG-TRIAGE.md #1.
2026-07-06T06:24:02.7283449Z - Required stages: impl, unit
2026-07-06T06:24:02.7283477Z 
2026-07-06T06:24:02.7283572Z ### REQ-ENDPOINT-LIST-NODE-IDENT
2026-07-06T06:24:02.7284885Z - Title: Bug #5: spt endpoint list local section header is the hardcoded literal LOCAL (this node) (render_local_section cli.rs:4359). Change to 'This node: <node-id>' using the existing node-ident idiom (os_hostname + nodeid public-key prefix, cli.rs:5531 — factor a node_ident_display helper); compute in the impure print_local_section, pass into the pure renderer. Update the two test assertions (cli.rs:10711/10716). See docs/NEXT-MILESTONE-BUG-TRIAGE.md #5.
2026-07-06T06:24:02.7285080Z - Required stages: impl, unit
2026-07-06T06:24:02.7285113Z 
2026-07-06T06:24:02.7285219Z ### REQ-HAZARD-CONTROL-STAMP-LIFETIME
2026-07-06T06:24:02.7287722Z - Title: #2: a control/viewer stamp never outlives its session — every teardown path clears what attach stamped. The broker exit-waiter (broker.rs ~:1844) sends the exit frame + sessions.remove(&id) but does NOT clear the perch's controller/viewer stamps; clear_controller()->stamp_driven_by() (clears driven_by+controlled) runs ONLY on controller-detach/evict/displace. /exit kills the CHILD not the controller conn, so the OutputLog drops with controlled:true, viewer_count, (and driven_by for a remote controller) latched in info.json forever — and hfenduleam keeps gossiping controller_node=self cross-node. Fix: on session reap, clear the perch's controller/viewer stamps (set_driven_by(None)+set_controlled(false)+set_viewer_count(0) via the known endpoint id) — broker stays the single writer. KNOWN-HAZARDS invariant. See docs/NEXT-MILESTONE-PICKER-TRIAGE.md #2.
2026-07-06T06:24:02.7287829Z - Required stages: doc, impl, int
2026-07-06T06:24:02.7287861Z 
2026-07-06T06:24:02.7287956Z ### REQ-PICKER-CONTROLLED-LOCAL
2026-07-06T06:24:02.7290451Z - Title: #3 local half: a LOCALLY-controlled endpoint renders CONTROLLED in its own node's picker. display_status() (crates/spt/src/picker/model.rs:415) derives Controlled ONLY from driven_by.is_some(), but driven_by is REMOTE-only by design (KH 7.15) — a locally-controlled endpoint has driven_by=None + controlled=true, and local_rows (data.rs:220) never threads controlled into EndpointRow, so a locally-RC'd endpoint shows plain ONLINE in its own picker (remote rows are fine — gossip stamps controller_node=self, REQ-GOSSIP-CONTROLLED-ANY; the asymmetry is the bug). Fix: EndpointRow gains controlled:bool (local: rec.controlled; remote: controller_node.is_some()); display_status -> Controlled when driven_by.is_some()||controlled; desc pane says 'controlled locally' when the driver is unnamed. See docs/NEXT-MILESTONE-PICKER-TRIAGE.md #3.
2026-07-06T06:24:02.7290561Z - Required stages: impl, unit
2026-07-06T06:24:02.7290594Z 
2026-07-06T06:24:02.7290696Z ### REQ-PICKER-PROJECT-HISTORY-TRUTH
2026-07-06T06:24:02.7293345Z - Title: #1: picker project history is derived from sessions.log cwds (newest->oldest, deduped by project_id_for_dir) UNION context-store branches, EXCLUDING owlery-internal paths (any cwd under spt_home()/owlery) everywhere a project is displayed or inferred. Fixes three stacked defects (crates/spt/src/picker/data.rs): (1a) project_history_for (data.rs:372) reads ONLY context-store p-* branches, which are empty on this box -> history []; (1b) the fallback origin project (data.rs:207) is derived from info.json.cwd = latest-boot-cwd (rewritten every rebind), not origin; (1c) psyche-host sessions bind owlery-internal cwds that pollute history. Full DIRS stay available in the model (feature #5 needs them). PROJECT REPRESENTATION RULING (operator 2026-07-03): project IDs ONLY, EVERYWHERE incl local display; on ID collision disambiguate minimally via a PURE disambiguate_project_ids(entries)->display-names fn (append one-level-up parent folder and/or root drive letter, e.g. 'spt-core (projects)' vs 'spt-core (D:)'). See docs/NEXT-MILESTONE-PICKER-TRIAGE.md #1.
2026-07-06T06:24:02.7293556Z - Required stages: impl, unit
2026-07-06T06:24:02.7293584Z 
2026-07-06T06:24:02.7293683Z ### REQ-STORE-CONTEXT-BRANCH-FILL
2026-07-06T06:24:02.7295164Z - Title: #1 SI-1 (RCA, operator-promoted 2026-07-03): the context store (tracked/.seed.git) holds ZERO p-* branches on a box with months of live-agent use, while kitsubito/enlyzeam stores carry them. Context commits never land -> picker history has no store source (REQ-PICKER-PROJECT-HISTORY-TRUTH's fallback ships regardless, but the store must ALSO fill). RCA the contextstore write->branch-commit path with evidence (commune-ingest/context-commit regression vs store re-init), contrast the healthy stores, land whatever fix the RCA names. See docs/NEXT-MILESTONE-PICKER-TRIAGE.md #1 SI-1.
2026-07-06T06:24:02.7295367Z - Required stages: doc, impl, unit, int
2026-07-06T06:24:02.7295392Z 
2026-07-06T06:24:02.7295497Z ### REQ-GOSSIP-ADAPTER-PROJECTS
2026-07-06T06:24:02.7297826Z - Title: #4: remote endpoint details (harness + project history) are gossiped, not faked. Today from_resource_row (crates/spt/src/picker/model.rs:340) hardcodes project_history=Vec::new() for every remote row and passes adapter_profile=row.resources (the blurb masquerading as the harness), and Instance/ResourceRow (crates/spt-net/src/net/registry.rs:457) carry no adapter field and no project list. Fix: additive gossip fields N-1-safe exactly like endpoint_type — Instance.adapter (composite <adapter>[:profile]) + Instance.recent_projects (bounded, newest-first, project IDs only) -> thread to ResourceRow -> from_resource_row stops faking. Pre-field remote rows render '-'. Project IDs only + REQ-PICKER-PROJECT-HISTORY-TRUTH's disambiguation. See docs/NEXT-MILESTONE-PICKER-TRIAGE.md #4.
2026-07-06T06:24:02.7297934Z - Required stages: impl, unit, int
2026-07-06T06:24:02.7297968Z 
2026-07-06T06:24:02.7298060Z ### REQ-ENDPOINT-LIST-PROJECT-COL
2026-07-06T06:24:02.7299968Z - Title: #8: spt endpoint list gains a second column <project>/ (the endpoint's LATEST project) -> 4 columns total: id / <project>/ / type / status. Local rows: head of REQ-PICKER-PROJECT-HISTORY-TRUTH (sessions.log-derived, owlery-excluded). Remote rows: head of REQ-GOSSIP-ADAPTER-PROJECTS recent_projects. Project IDs only + #4 disambiguation; '-' when unknown (pre-field remote rows). Extends the v0.21.0 node-grouped renderer (format_instance_rows — additive column, alignment char-width-safe). --json: additive project field on the row DTO (skip-if-none, N-1 safe). Depends on #1 + #4. See docs/NEXT-MILESTONE-PICKER-TRIAGE.md #8.
2026-07-06T06:24:02.7300073Z - Required stages: impl, unit
2026-07-06T06:24:02.7300101Z 
2026-07-06T06:24:02.7300200Z ### REQ-API-ENDPOINT-INFO
2026-07-06T06:24:02.7303153Z - Title: #7: spt api endpoint-info [<id>] (JSON) lets an endpoint learn its ATTACHED (controlling) node — claude-spt surfaces local + attached node names on UserPromptSubmit so the agent knows whether getting a file to the user needs extra steps (user RC'd in from another machine). spt api * is the harness-contract agent-facing surface (JSON-first, rides perch identity/auth so the bare no-<id> form self-resolves like whoami). Payload (committed DTO, additive-forever): { id, endpoint_type, adapter, local_node:{label,key}, attached_node:{label,key}|null, controlled:bool, project:<current project id>, cwd, subnets:[...] } — attached_node from controller stamps (driven_by remote / self-node when controlled with no remote driver), null when uncontrolled. HARD dependency on #2 + #3 (stamps must be honest first). Adapter-side consumable -> perri release-ping on publish. Naming: chose 'spt api endpoint-info' over alt 'spt endpoint get-info' — api is the agent surface (doc rationale). See docs/NEXT-MILESTONE-PICKER-TRIAGE.md #7.
2026-07-06T06:24:02.7303356Z - Required stages: impl, unit
2026-07-06T06:24:02.7303389Z 
2026-07-06T06:24:02.7303486Z ### REQ-PICKER-START-PROJECT-CHOICE
2026-07-06T06:24:02.7305279Z - Title: #5: after 'Start now' in the endpoint picker, swap the bottom Options panel to a 'Choose project' list: (1) the endpoint's most recent project dir, (2) 'Here: <dir>' — the spt endpoint run cwd (only if different), (3) all other project-history dirs newest->oldest. Fire the step ONLY when (A) the run cwd mismatches a singular history entry, or (B) history has >1 entry; otherwise start immediately (today's behavior). Depends on REQ-PICKER-PROJECT-HISTORY-TRUTH (needs full DIRS from sessions.log, owlery-internal exclusion applies). Start-now is local-only (no gossip). See docs/NEXT-MILESTONE-PICKER-TRIAGE.md #5.
2026-07-06T06:24:02.7305381Z - Required stages: impl, unit
2026-07-06T06:24:02.7305414Z 
2026-07-06T06:24:02.7305518Z ### REQ-PICKER-RESUME-CONTEXT-PANEL
2026-07-06T06:24:02.7306725Z - Title: #6: the 'Resume from history' view keeps the endpoint's 'Confirm selection' top panel and swaps ONLY the bottom panel to 'Resume from a prior session' — the user stays contextually informed about what they're picking (today the resume view replaces the whole screen). crates/spt/src/picker/view.rs (resume screen) + model screen state. See docs/NEXT-MILESTONE-PICKER-TRIAGE.md #6.
2026-07-06T06:24:02.7306824Z - Required stages: impl, unit
2026-07-06T06:24:02.7306858Z 
2026-07-06T06:24:02.7306949Z ### REQ-MSG-SELF-DETECT-ANCESTRY
2026-07-06T06:24:02.7310309Z - Title: #9 (F026, operator field bug): a perch-owned `spt send` from an endpoint's OWN session must self-identify, not mis-stamp `cli@<node>` (whose replies bounce NO_PERCH). ROOT: roster::detect_self_id (roster.rs) was ENV-ONLY — OWL_SESSION_ID matched to info.session_id, else SPT_AGENT_ID — but an agent-session Bash child often carries NEITHER (the env export is spawn-path-dependent), so a perch-owned sender was classified bare-CLI and REQ-MSG-CLI-ORIGIN stamped it cli@<node> (the stamp works as designed on a wrong premise; that REQ's evidence stays intact). FIX: detect_self_id gains leg (c) PID-ANCESTRY fallback AFTER the env legs — walk THIS process's ancestry, match a live non-corrupt roster perch's recorded harness pid (info.json.pid Numeric, alive-gated via is_process_alive, corrupt/BUSY skipped), first match = self. from-LABEL / routing default ONLY, NOT authentication — authenticate() is untouched (pid-ancestry-for-AUTH stays parked per F-024 with its Windows pid-spoof caveats; a display/routing stamp has no such bar). Best-effort: a broken ancestry walk degrades to None → cli-stamp, never errors the send.
2026-07-06T06:24:02.7312821Z - Required stages: impl, unit, int
2026-07-06T06:24:02.7312859Z 
2026-07-06T06:24:02.7312963Z ### REQ-CLI-BROKEN-PIPE-TOLERANT
2026-07-06T06:24:02.7314408Z - Title: #10 (F026 micro): `spt <anything> | <pager/Select-First-N>` must not PANIC when stdout closes early. A closed downstream reader mid-print panics with 'failed printing to stdout: The pipe is being closed. (os error 232)' (live repro: `spt daemon status | Select -First N`). Fix: tolerate BrokenPipe process-wide — a write to a closed stdout exits 0 (SIGPIPE-equivalent: a consumer that stops reading is a normal end, not a crash), without leaking a Rust panic + backtrace to the user.
2026-07-06T06:24:02.7314522Z - Required stages: impl, unit
2026-07-06T06:24:02.7314556Z 
2026-07-06T06:24:02.7314657Z ### REQ-XTASK-SPT-BIN-TARGET-DIR
2026-07-06T06:24:02.7316909Z - Title: #13 (F026 micro, tooling): xtask `spt_bin()` (crates/xtask/src/main.rs) BUILDS `spt` via cargo (which honors CARGO_TARGET_DIR) but returns a HARDCODED `<root>/target/debug/spt` path — so under a redirected target dir (CI / isolated-gate rigs that set CARGO_TARGET_DIR to a throwaway) the binary lands in `$CARGO_TARGET_DIR/debug` while xtask looks in `<root>/target/debug` -> NotFound -> `xtask check` (docs-drift gate) spuriously fails. Workaround was running `xtask check` with CARGO_TARGET_DIR unset. FIX: a pure `target_debug_dir(root, CARGO_TARGET_DIR)` seam mirroring cargo's resolution — absolute override as-is, relative resolved against `root` (the dir cargo is invoked in), default `<root>/target` — join `debug`; `spt_bin` returns from it. See docs/NEXT-MILESTONE-PICKER-TRIAGE.md.
2026-07-06T06:24:02.7317175Z - Required stages: impl, unit
2026-07-06T06:24:02.7317205Z 
2026-07-06T06:24:02.7317318Z ### REQ-HAZARD-CONTROL-STAMP-CONVERGENCE
2026-07-06T06:24:02.7322333Z - Title: Control/viewer stamps must CONVERGE to broker session-table truth for every session-backed endpoint, not merely edge-trigger — the UPWARD companion to the DOWNWARD edge-clear REQ-HAZARD-CONTROL-STAMP-LIFETIME (7.27); same 'stamps == broker truth' family. ROOT (F-026 stamp-gap, hall-b/ball-b): a picker-created endpoint's broker spawn become_controller->stamp_driven_by->set_controlled(true) fires BEFORE the adapter binds its perch (a fresh endpoint has no perch until claude boots + binds), so mutate_info returns NotFound and the edge stamp is SWALLOWED (let _); the adapter's bind then writes InfoJson::new with controlled:false DEFAULT and no later edge re-stamps -> the endpoint reads uncontrolled FOREVER while driven (the #3 display fix is correct but datum-starved on this creation path). FIX: the broker (SINGLE WRITER) re-asserts each live session's control/viewer stamps to session-table truth, DIVERGENCE-GATED (read info; compare driven_by/controlled/viewer_count; write ONLY on diff — no per-poll fsync storm), on the KIND_SESSIONS handler (piggyback: the daemon reconcile + picker poll it, so a fresh perch converges within one reconcile-poll window after bind = the BOUNDED window, no new timer). Event-on-input rejected (an idle controlled session like hall-b never converges). Writes run OFF the log lock (snapshot truth under the lock, converge off it) per the lock-across-effect discipline (KH 7.12/5.16).
2026-07-06T06:24:02.7322556Z - Required stages: doc, impl, unit, int
2026-07-06T06:24:02.7322594Z 
2026-07-06T06:24:02.7322691Z ### REQ-PICKER-PROJECT-DISPLAY-NAME
2026-07-06T06:24:02.7325168Z - Title: A1 (F028, operator #1/#4/#6-display): `github-com-*` 'ghost' project entries are NOT phantoms — project_id_for_dir (spt-store/src/project.rs:64) derives ids from the git remote slug BY DESIGN (REQ-STORE-1 cross-machine sync): `github.com/SaberMage/spt-core` -> `github-com-sabermage-spt-core`. The ref is truthful; the BUG is presentation — the raw slug renders as the DISPLAY NAME everywhere (confirm-panel history view.rs:415-419, choose-project labels model.rs:314-337, resume-row titles, endpoint-list project column via latest_project_ref data.rs:417), which no operator recognizes as 'spt-core'. FIX: keep the slug as the KEY, render a friendly display name — the repo tail (spt-core) reusing the disambiguate_project_ids (model.rs:346) suffix mechanism for collisions. One shared display-name seam across all four surfaces. See triage A1.
2026-07-06T06:24:02.7325396Z - Required stages: impl, unit
2026-07-06T06:24:02.7325434Z 
2026-07-06T06:24:02.7325539Z ### REQ-PICKER-CONTROL-LINE-STATUS-GATE
2026-07-06T06:24:02.7326910Z - Title: A2 (F028, operator #2): the picker confirm-panel 'controlled locally' line renders for OFFLINE endpoints. view.rs:425-436 builds control_line from ep.controlled with NO status gate; an offline endpoint with a stale controlled stamp shows 'controlled locally' (operator screenshot: hall-a offline + controlled locally). RENDER HALF (this REQ): control_line MUST be empty when status != Online. The upstream STICKY-stamp half (stamp survives client SIGKILL >=5min) is B3/REQ-PRESENCE-CONTROL-REAP-ON-EXIT. FIX: gate the render. See triage A2(a).
2026-07-06T06:24:02.7327010Z - Required stages: impl, unit
2026-07-06T06:24:02.7327043Z 
2026-07-06T06:24:02.7327140Z ### REQ-PICKER-OFFLINE-NO-VIEW
2026-07-06T06:24:02.7328108Z - Title: A3 (F028, operator #3): 'View now (read-only)' is offered for OFFLINE endpoints. model.rs:1030 offline branch of confirm_options is vec![Start, View] — View is meaningless with no live PTY. FIX: offline set = [Start] (+ the existing Resume/ChangeAdapter/Instantiate/Fork/Shortcut tail). Update the view.rs options tests. See triage A3.
2026-07-06T06:24:02.7328301Z - Required stages: impl, unit
2026-07-06T06:24:02.7328339Z 
2026-07-06T06:24:02.7328440Z ### REQ-PICKER-CHOOSE-DEDUP-ALL
2026-07-06T06:24:02.7329910Z - Title: A4 (F028, operator #5): choose-project duplicate rows. model.rs:314-337 build_project_choices dedups the `Here: <run_cwd>` row only against the HEAD ref's dir (line 324) — an OLDER history ref with the SAME dir still renders, giving `Here: C:\...\projects` + `projects` as two rows for one project (operator screenshot). FIX: dedupe `Here` against ALL history dirs, and skip rest-rows whose dir == run_cwd when Here is present. Extend the model.rs:1847 choose-project test. See triage A4.
2026-07-06T06:24:02.7330017Z - Required stages: impl, unit
2026-07-06T06:24:02.7330045Z 
2026-07-06T06:24:02.7330149Z ### REQ-RESUME-ROW-PER-PROJECT
2026-07-06T06:24:02.7331353Z - Title: A5 (F028, operator #6): resume-from-history labels EVERY session with the endpoint's newest project. data.rs:480-496 resume_rows_for clones project_history.first() onto every ResumeRow (line 481/488), so all sessions read as the head project (the ghost). The per-row e.cwd is already carried for launch-into-dir. FIX: derive per-row project_id_for_dir(e.cwd) (owlery-excluded -> fall back to trigger token), rendered through A1's display-name path. See triage A5.
2026-07-06T06:24:02.7331443Z - Required stages: impl, unit
2026-07-06T06:24:02.7331471Z 
2026-07-06T06:24:02.7331561Z ### REQ-RUN-NO-DUP-SESSION
2026-07-06T06:24:02.7334140Z - Title: B1 (F028, hall-b diagnosis, verified 0.22.0): `endpoint run --id X --create` on an endpoint with a LIVE session mints a silent DUPLICATE session — and attach output can CROSS sessions (second create for diag-hallc minted a new session while the old ran; the new run's attach viewport rendered the OLD session's screen — claude resume-picker UI of pid 84512 while new claude 356020 had no -r). ROOT CLASS of the 0.21.0 attach-stall (zero events in FIRST_EVENT_GRACE rc.rs:1402 = attach bound to dead/wrong same-id slot); also the triplicate `launch --id ball-b` on ENLYZEAM. FIX: (i) run-on-live-session must REFUSE or REATTACH, never silently duplicate; (ii) RCA the attach/output routing that let frames cross same-id sessions (broker session-slot keying, dispatch_adapter vs serve_attach resolution). Int: two sessions one endpoint id -> each attach sees only its own frames. See triage B1.
2026-07-06T06:24:02.7334260Z - Required stages: impl, unit, int
2026-07-06T06:24:02.7334289Z 
2026-07-06T06:24:02.7334398Z ### REQ-RESUME-HARNESS-SESSION-ID
2026-07-06T06:24:02.7336898Z - Title: B2 (F028, hall-b diagnosis, verified 0.22.0): respawn/`--resume` feeds the SPT session id to `claude -r`. After the 02:05 daemon bounce respawn built `claude.exe -r 70b5bfa40901b7d4` — an spt session id in claude's OWN session-id namespace -> claude hangs forever at a 'No sessions match' resume-picker while the endpoint reads online. Hits after EVERY daemon bounce + every picker Resume. The HARNESS session id (claude UUID, stamped in sessions.log/info.json by the hooks) is what {session_id} must mean in the adapter's [session.resume] command; the spt sid must not leak. FIX: substitute the HARNESS session id in the resume template (spt-core substitution-key semantics + LIKELY claude-spt manifest coordination — FLAG perri BEFORE touching the manifest, adapter-boundary rule). Int: resume template receives the ledger UUID, not the spt sid. See triage B2.
2026-07-06T06:24:02.7337080Z - Required stages: impl, unit
2026-07-06T06:24:02.7337108Z 
2026-07-06T06:24:02.7337222Z ### REQ-PRESENCE-CONTROL-REAP-ON-EXIT
2026-07-06T06:24:02.7339990Z - Title: B3 (F028, hall-b diagnosis + deferred #11 seed; BROADENED perri F-b CONFIRMED): dead-pid ONLINE decay window + sticky CONTROLLED stamp. Repro: /exit -> all endpoint processes dead -> `endpoint list` stays ■ ONLINE for a decay window before OFFLINE. Sticky CONTROLLED: perri confirmed controlled=true + attached_node SET while alive=false/OFFLINE, persisting >20min AND ACROSS A DAEMON RESTART (hall-b) — worse than the SIGKILL>=5min original (CAVEAT still: may reflect claude's --remote-control channel not the PTY attach — DISAMBIGUATE first). This is the deferred #11; RCA belongs to this wave. FIX: reap must clear presence AND control stamps promptly across FOUR paths — (i) clean exit, (ii) serve conn-drop, (iii) session-died-without-exit (crash/bounce), (iv) a BOOT-TIME sweep so a restarted daemon does NOT resurrect control stamps for endpoints it can see are dead. Int tests per edge. Closes A2(b). See triage B3 (broadened).
2026-07-06T06:24:02.7340204Z - Required stages: impl, unit, int
2026-07-06T06:24:02.7340237Z 
2026-07-06T06:24:02.7340338Z ### REQ-RESUME-REAP-PRIOR-HARNESS
2026-07-06T06:24:02.7341339Z - Title: B4 (F028, hall-b diagnosis, verified 0.22.0): `--resume` respawns a SECOND harness onto the SAME session without reaping the first. Observed live: resume of b4421cf9 spawned pid 34432 while gen1 (250376) kept running — two claude.exe stacks, one session id. FIX: resume must reap/refuse when the session already has a live harness. See triage B4.
2026-07-06T06:24:02.7341485Z - Required stages: impl, unit, int
2026-07-06T06:24:02.7341519Z 
2026-07-06T06:24:02.7341618Z ### REQ-CRC-SWAP-OLD-DISPLACE
2026-07-06T06:24:02.7344286Z - Title: C1 (F028, infra; memory crc-swap-old-litter-brick, RCA'd ENLYZEAM + confirmed systemic): crc_swap `.old`-litter bricks every subsequent adapter update. apply_crc_swap Phase-3 `let _ = remove_file(.old)` (spt-daemon/src/crc_swap.rs:129-133) silently fails whenever ANY pre-update process still image-maps the old binary (NORMAL on a live box — endpoint launch children survive updates). The NEXT update's first commit-op rename(exe->exe.old) = MoveFileExW(REPLACE_EXISTING) must delete the mapped .old -> win32 err 5 -> whole apply fails + rolls back FOREVER, context-free. FIX: (i) DISPLACE not replace — when <target>.old exists, rename it aside to a unique suffix (rename succeeds on mapped files; spt's own updater already does spt.exe.old-<counter>); GC stale .old.* opportunistically. (ii) Wrap swap io errors with op + path (`rename claude-spt.exe -> claude-spt.exe.old: …`). Unit seam exists (crc_swap tests). See triage C1.
2026-07-06T06:24:02.7344381Z - Required stages: impl, unit
2026-07-06T06:24:02.7344414Z 
2026-07-06T06:24:02.7344530Z ### REQ-SESSIONS-LOG-ENDPOINT-ATTRIBUTION
2026-07-06T06:24:02.7347115Z - Title: C2 (F028, infra; ROOT-CAUSED + severity-upgraded doyle RCA 2026-07-03): cross-endpoint perch contamination — a foreign psyche's SessionStart hook REBINDS a victim perch's IDENTITY, not merely its ledger. Evidence: hall-a's info.json.session_id IS f015b-probe-psyche's session (359d7bd7) + hall-a's ledger holds the foreign psyche session; same class as hall-b's dead-pid stamp (141556). This REQ = the OBSERVABLE (foreign session_id in a perch's ledger/info.json + resume offering foreign sessions) and its belt-braces: (iii) filter owlery-cwd rows OUT of resume_rows; (iv) one-time repair for already-contaminated perches (hall-a on HFENDULEAM) or self-heal on next legitimate session-start. The ROOT (identity pinned at spawn + honest bind + nested self-resolve) is REQ-BIND-HONEST-SELF-STAMP — C2 is UPSTREAM of B3 (presence/CONTROLLED read the very stamps this corrupts). See triage C2.
2026-07-06T06:24:02.7347272Z - Required stages: impl, unit
2026-07-06T06:24:02.7347310Z 
2026-07-06T06:24:02.7347411Z ### REQ-BIND-HONEST-SELF-STAMP
2026-07-06T06:24:02.7351513Z - Title: C2-ROOT (F028, doyle RCA 2026-07-03): the identity-attribution ROOT behind REQ-SESSIONS-LOG-ENDPOINT-ATTRIBUTION — three composing defects let a psyche-hosted SessionStart hook stamp a FOREIGN perch: (1) roster::detect_self_id leg (a) scans the owlery ONE level (roster.rs:107 read_dir(owlery)) so a NESTED psyche perch owlery/<parent>/nested/<id>-psyche can never self-resolve; (2) [session.psyche_init] (claude-spt manifest ~L347) spawns the psyche with NO env_remove + no pinned child identity, so whatever OWL_SESSION_ID/SPT_AGENT_ID reaches the child resolves to a foreign top-level perch; (3) the hook then writes info.json (session_id/pid rebind) + sessions.log on the mis-resolved victim. FIX (spt-core half): (i) identity PINNED at spawn — ManifestRuntime role spawns inject the child's OWN SPT_AGENT_ID=<child perch id> + OWL_SESSION_ID=<child session>, AND detect_self_id enumerates NESTED perches (fix the one-level owlery scan); (ii) BIND HONESTY — a session-start stamp may only write a perch whose resolved id AFFIRMATIVELY matches; never a fallback pick; refuse + loud-skip when unresolved (kin REQ-MSG-CLI-ORIGIN honest-default + #9 ancestry). ADAPTER half = PERRI touchpoint (psyche_init env scrubbing / relies on runtime pinning; hook loses silent fallback-perch behavior) — FLAG doyle BEFORE any manifest move (adapter glue-model rule). See triage C2 fix (i)+(ii).
2026-07-06T06:24:02.7351718Z - Required stages: impl, unit, int
2026-07-06T06:24:02.7351752Z 
2026-07-06T06:24:02.7351922Z ### REQ-PEER-PUMP-CHURN-STALL
2026-07-06T06:24:02.7354094Z - Title: B5 (F028, perri F-a; DEFECT daemon, OBSERVED-ONCE, HIGH): the peer pump STALLS under rapid rc attach/EOF-detach/--take churn. Fresh 0.22.0 daemon ~10min after restart, during rapid rc cycling: `peer pump: STALLED (last tick 122s)`; while stalled `spt rc --view` -> `RC_FAIL: attach request: brain IPC read deadline elapsed` (repeatable) and controlled-clear stopped propagating. Daemon restart recovered + endpoints auto-revived. Prior class: REQ-HAZARD-PUMP-IPC-DEADLINE (reader-thread+channel carrier), REQ-broker-QUIC-deadline (bounded_block_on) — something in the rc-churn path can still wedge the pump tick. perri holds exact timestamps + a repro candidate (rapid attach/detach/take against one endpoint) — REQUEST before RCA. See triage B5.
2026-07-06T06:24:02.7354199Z - Required stages: 
2026-07-06T06:24:02.7354231Z 
2026-07-06T06:24:02.7354338Z ### REQ-TRANSLATE-BINARY-LIVENESS-DECAY
2026-07-06T06:24:02.7356621Z - Title: SUPERSEDED by REQ-TRANSLATE-COMMIT-MISS-TOLERANCE (F029 C-1). B6 (F028, perri F-e) was ROOT-PINNED as the commit-deadline-miss fault: at a checkpoint clear boundary the clear-only inject's {commit} was never observed within INJECT_COMMIT_DEADLINE, so the inject worker FAULTED + TERMINATED a HEALTHY translate binary and (by ADR-0022) never respawned → every subsequent force-native reported delivered=false ('no live translation binary'). NOT a dormancy/liveness-registration decay (that hypothesis is dead) — deterministic at every checkpoint-armed boundary. The fix (miss != fault + N=3 strike budget + bounded respawn + perch-visible fault stamp) lives under REQ-TRANSLATE-COMMIT-MISS-TOLERANCE + REQ-HAZARD-TRANSLATE-FAULT-PERMANENT-DEATH. See triage addendum C-1.
2026-07-06T06:24:02.7356772Z - Required stages: 
2026-07-06T06:24:02.7356805Z 
2026-07-06T06:24:02.7356921Z ### REQ-PSYCHE-CRASHLOOP-BACKOFF-SHUTDOWN
2026-07-06T06:24:02.7358539Z - Title: C3 (F028, perri F-h): psyche wrapper crash-loop has no backoff, and `endpoint shutdown` misses a wedged wrapper. A probe psyche crash-looped ~3 boots/sec for ~30min (CC died instantly on the untrusted owlery cwd; ledger hit ordinal 5358) — SILENTLY; and `spt endpoint shutdown` did NOT tear the looping wrapper down (docs say shutdown tears the Psyche with the perch; manual kill was required). FIX: (i) bounded backoff + loud give-up on a psyche boot loop (the psyche_host_error surface already exists), (ii) shutdown must cover a wedged/looping wrapper. See triage C3.
2026-07-06T06:24:02.7358639Z - Required stages: 
2026-07-06T06:24:02.7358671Z 
2026-07-06T06:24:02.7358762Z ### REQ-DOC-ENDPOINT-DROP-RESOLUTION
2026-07-06T06:24:02.7359996Z - Title: D1 (F028, perri F-c; docs/truth): SI-1's resolution rule — a RELATIVE watched drop dir resolves against the ENDPOINT's cwd, never the daemon's (KH 7.28, shipped v0.22.0) — is documented NOWHERE public. Add it to harness-contract/manifest.md + the manifest schema field descriptions so an adapter author knows a relative commune_dir/signoff_dir is endpoint-resolved. docs-drift gate applies. See triage D1.
2026-07-06T06:24:02.7360190Z - Required stages: 
2026-07-06T06:24:02.7360218Z 
2026-07-06T06:24:02.7360308Z ### REQ-DAEMON-STATUS-JSON-TRUTH
2026-07-06T06:24:02.7361777Z - Title: D2 (F028, perri F-d): `daemon status --json` truth drift. managed_by/managed_active read null in JSON while the HUMAN view says 'managed-by: manual — at-logon task registered' (the two surfaces disagree); and pump staleness (the STALLED diagnosis, B5) is NOT computable from JSON — only a raw pump_heartbeat_ms is emitted, no derived staleness/stalled field. FIX: JSON managed_by/active match the human render, and add a derived pump-staleness/stalled field so B5's condition is machine-observable. See triage D2.
2026-07-06T06:24:02.7361867Z - Required stages: 
2026-07-06T06:24:02.7361896Z 
2026-07-06T06:24:02.7362007Z ### REQ-ENDPOINT-LIST-RENDER-POLISH
2026-07-06T06:24:02.7364205Z - Title: A6 (F028, operator, 4 asks): `spt endpoint list` render polish. (a) the 'Shared subnets' line is NOT dim — LIGHT_GRAY = "37" (cli.rs:3019) is standard-palette WHITE, indistinguishable from row text; use SGR 90 (bright-black/gray) for the dim intent. (b) the `Total:` line takes the same dim color. (c) move the status glyph ADJACENT to the endpoint name (operator: 'right behind the endpoint name'), mirroring the picker's glyph-beside-name presentation (today the glyph sits at the end next to the status word). (d) color the status WORD like the picker TUI (green ONLINE / gray OFFLINE / blue when driven, matching picker glyph semantics). All in render_node_grouped/render_instance_row (cli.rs ~3000s); pure render with an injected color decision — unit-testable off a tty. See triage A6.
2026-07-06T06:24:02.7364354Z - Required stages: impl, unit
2026-07-06T06:24:02.7364391Z 
2026-07-06T06:24:02.7364472Z ### REQ-CLI-WIN-VT-ENABLE
2026-07-06T06:24:02.7366542Z - Title: A7 (F028, operator, Win10 conhost): ANSI emitted without VT enable → garbled console. Evidence (raw PowerShell 7, Win10 conhost): literal `←[36m` in `endpoint list` + `--help`. ROOT: ENABLE_VIRTUAL_TERMINAL_PROCESSING is enabled ONLY on the rc attach path (rc.rs:746, REQ-RC-WIN-VT-OUTPUT) — plain CLI stdout never enables it, and the color decision doesn't fall back when the console can't render VT. FIX: lift the rc.rs VT-enable into a SHARED startup helper for every colored-output path; if SetConsoleMode fails (or stdout isn't a console), STRIP colors (the ansi_wrap/helpfmt color=false path already exists — plumb the decision, not new rendering). Windows Terminal masks this (VT always on) — TEST on raw conhost. See triage A7.
2026-07-06T06:24:02.7366646Z - Required stages: impl, unit
2026-07-06T06:24:02.7366679Z 
2026-07-06T06:24:02.7366784Z ### REQ-GOSSIP-CONTROLLED-CROSS-NODE
2026-07-06T06:24:02.7369136Z - Title: B7 (F028, operator, cross-node): a remote endpoint's CONTROLLED state is not rendered. Evidence: ball-b ONLINE + CONTROLLED on ENLYZEAM (local view), but HFENDULEAM renders remote ball-b as plain ONLINE (both 0.22.0). The F-026 #4 gossiped any-controller datum (REQ-GOSSIP-ADAPTER-PROJECTS controlled bool) either isn't SENT for the locally-controlled case, isn't APPLIED on the receiving row, or DECAYS. Local leg confirmed fine (sibling hall-b renders blue-glyph correctly); the gap is the REMOTE leg. perri's validation had this ENV-BLOCKED — two live nodes now available to RCA. FIX: RCA sender-side (is controlled gossiped when locally-controlled?) / receiver-render (does from_resource_row surface it?) / decay, then lock with a cross-node int. See triage B7.
2026-07-06T06:24:02.7369236Z - Required stages: 
2026-07-06T06:24:02.7369269Z 
2026-07-06T06:24:02.7369366Z ### REQ-HAZARD-INJECT-WORKER-POISON
2026-07-06T06:24:02.7372122Z - Title: The per-session inject-worker floor Mutex is SHARED by the inject worker (open/flush) and the controller-input path (dispatch_input Layer C buffer_if_held); a panic under the lock on EITHER poisons it, and a bare .lock().unwrap() at the next site then panics too — a panic in the inject WORKER kills its thread WITHOUT reaping the translation child, orphaning a live binary while event_tx.send fails, so force-native reports 'worker-gone' delivered=false FOREVER (the F-e generic-miss shape). HARDENING, NOT the F-e incident root (perri's matrix exonerated poison under thrash/dormancy/churn): (i) poison-tolerant floor lock (unwrap_or_else into_inner) at all 3 sites so one panic can't cascade the session's delivery dead; (ii) a panic-resilient inject worker (catch_unwind -> fault+terminate the child on a worker panic) so a dead worker never orphans a live binary + strands delivery. Poison-tolerance class of REQ-HAZARD-EFFECT-JOURNAL-PTY-WEDGE / bug #16.
2026-07-06T06:24:02.7372333Z - Required stages: impl, unit
2026-07-06T06:24:02.7372361Z 
2026-07-06T06:24:02.7372470Z ### REQ-HAZARD-DETACHED-DAEMON-STDIO
2026-07-06T06:24:02.7377554Z - Title: A daemon DETACHED-IN-FACT (no interactive console, or an inherited stderr PIPE nobody drains) that never nulled its std handles will BLOCK on stdio writes when the pipe fills, and/or pop a visible conhost window (REQ-HAZARD-WMI-DAEMON-WINDOW is a covered surface of this hazard). detach_console nulls the 3 handles only under the --detached flag; a rung that omits it (the bare line-82 elevated->deelevated respawn; a STALE installer at-logon task registered as bare `daemon run`, confirmed live field-drift on ENLYZEAM) is exposed. FIX: (load-bearing) inside `daemon run`, null the 3 std handles when stderr GetFileType==FILE_TYPE_PIPE — a pipe is the ONLY std sink that BLOCKS the daemon when it fills; catches every rung whose inherited stderr is an undrained pipe, independent of whether each caller passed --detached, while a FILE (2>run.log AND every int-test Stdio::from(file) brain-log capture), a CONSOLE (scrolls), and a NULL/absent handle (DETACHED_PROCESS rungs, already discard) all SURVIVE. DELIBERATELY NOT gated on GetConsoleWindow==NULL: a CREATE_NO_WINDOW daemon has no console window yet a drained FILE stderr — nulling it would blank the capture for ZERO safety gain (a file never blocks) and mass-red the int-test brain-log assertions. (belt) pass --detached on the bare line-82 respawn; (drift nag) parse the schtasks /Query action argv and LOUDLY nag when the at-logon task is the stale bare `daemon run` form (manual/installer re-registers; the daemon must NOT self-elevate to rewrite it). Defense-in-depth — no current spt Windows spawn path was proven to yield a BLOCKING inherited pipe (all rungs null-discard or scrolling-conhost), so this is hardening, not a confirmed incident root.
2026-07-06T06:24:02.7377717Z - Required stages: impl, unit
2026-07-06T06:24:02.7377750Z 
2026-07-06T06:24:02.7377853Z ### REQ-PICKER-CURRENT-DIR-LABEL
2026-07-06T06:24:02.7380246Z - Title: A-2/A-3 (F029, operator, semantic pair): the Choose-project rows must self-identify the CURRENT DIR. build_project_choices (picker/model.rs:322-352). A-2: when the run cwd IS already a history dir the `Here:` row is (correctly) suppressed by the dedup (REQ-PICKER-CHOOSE-DEDUP-ALL), but the matching history row rendered bare `r.display` with no cwd affordance — mark it `<display> (CURRENT DIR)`. A-3: the not-in-history current-dir row changes from `Here: <run_cwd>` to `CURRENT DIR --> <project>`, deriving the display the SAME way the history refs do (folder tail; honest fallback to the raw path when underivable). `cwd` payload unchanged. Grep-tests rule: 3 `starts_with("Here: ")` asserts (model.rs) + a `Here: /here` render assert (view.rs) are behavior assertions on the OLD label. See triage A-2/A-3.
2026-07-06T06:24:02.7380406Z - Required stages: impl, unit
2026-07-06T06:24:02.7380440Z 
2026-07-06T06:24:02.7380541Z ### REQ-PICKER-FORK-LABEL-CWD
2026-07-06T06:24:02.7381480Z - Title: B-3 (F029, operator): the confirm-panel `Fork endpoint` option label is static and says nothing about WHERE the fork lands. A fork runs in the picker's launch cwd (run_cwd); the label must state that dir honestly: `Fork endpoint here --> <current dir>`. Anchor picker/view.rs confirm_option_label (was `fn(opt)->&'static str`). Make the label model-aware for the dir-relative options. See triage B-3.
2026-07-06T06:24:02.7381677Z - Required stages: impl, unit
2026-07-06T06:24:02.7381705Z 
2026-07-06T06:24:02.7381809Z ### REQ-PICKER-SHORTCUT-LABEL-FILENAME
2026-07-06T06:24:02.7383365Z - Title: B-4 (F029, operator): the confirm-panel shortcut option label is a static `New/Update spt-<id> shortcut (s)` placeholder — it should name the REAL file it writes: `Set shortcut here --> <current dir>/<shortcut-name>` where <shortcut-name> is the EXACT on-disk filename (incl. extension). The name must be produced by the SAME function that names the file in shortcut creation (picker/shortcut.rs shortcut_filename over the manifest-resolved basename) so label and writer can NEVER drift. Anchor picker/view.rs confirm_option_label. See triage B-4.
2026-07-06T06:24:02.7383466Z - Required stages: impl, unit
2026-07-06T06:24:02.7383499Z 
2026-07-06T06:24:02.7383612Z ### REQ-HAZARD-ADAPTER-PROFILE-STAMP-CLOBBER
2026-07-06T06:24:02.7386169Z - Title: A-4 (F029, operator regression): the picker/confirm views drop an endpoint's adapter `:profile` (showed `claude-spt` where `claude-spt:ccs` was created). ROOT: stamp_creation_fields (spt-store/home.rs) gave the incoming BIND-TIME adapter value UNCONDITIONAL precedence (`rec.adapter = adapter.map(...).or_else(prior)`), but a hook bind resolves the adapter ADAPTER-AGNOSTICALLY (ADR-0021: a binary basename → the BARE parent, profile unknowable), so the first hook bind rewrote the richer `claude-spt:ccs` → `claude-spt`. (F-028's establish_perch self-heal widened how often this re-stamps; the precedence is the root.) FIX: profile-preserving precedence — when the incoming adapter is exactly the PARENT of the prior's `parent:profile` composite, KEEP the prior; replace only on a genuinely different adapter (or a different explicit profile). Paid-for field bug → hazard. See triage A-4.
2026-07-06T06:24:02.7386333Z - Required stages: impl, unit, int
2026-07-06T06:24:02.7386362Z 
2026-07-06T06:24:02.7386446Z ### REQ-PICKER-WINDOW-TITLE
2026-07-06T06:24:02.7387880Z - Title: B-5 (F029, operator): `spt endpoint run`'s interactive picker window/tab is untitled — hard to find among many terminals. Set the window/tab title to `SPT Endpoint Picker`. Anchor picker/mod.rs:88 setup_terminal (crossterm SetTitle in the execute! chain). Set-only is acceptable (crossterm can't cheaply read the prior title to restore). Applies ONLY to the interactive picker path — non-interactive/headless `endpoint run` (REQ-HOST-RUN-1) must NOT retitle the operator's terminal. See triage B-5.
2026-07-06T06:24:02.7387977Z - Required stages: impl
2026-07-06T06:24:02.7388000Z 
2026-07-06T06:24:02.7388105Z ### REQ-PICKER-KEY-GATE-LAUNCH-CAPABLE
2026-07-06T06:24:02.7389680Z - Title: B-1 (F029, operator): the `h` (headless start) / `s` (shortcut) keybinds fire from broad picker contexts (mod.rs handle_confirm_key / ChooseProject / Resume) regardless of whether the highlighted row would LAUNCH the endpoint. Restrict both to launch-capable highlights: (a) `Start now` in the immediate-start case (should_offer_project_choice == false), (b) a Choose-project row, (c) a Resume-from-history row. The footer hint line must render `h`/`s` ONLY when actually live (hint truth = availability truth). FIX: gate the key handlers on (screen, highlighted-option), unit the gate as a pure matrix. See triage B-1.
2026-07-06T06:24:02.7389837Z - Required stages: impl, unit
2026-07-06T06:24:02.7389866Z 
2026-07-06T06:24:02.7389970Z ### REQ-PICKER-CHANGE-ADAPTER-FLOW
2026-07-06T06:24:02.7392346Z - Title: B-2 (F029, operator; LARGEST item): `ConfirmOption::ChangeAdapter` wrongly routes into the CREATE flow (Screen::CreateAdapter → CreateId → CreateHome → START, reenter_create(true)) — it re-prompts id + home and then STARTS the endpoint. Required: prompt ONLY the harness-adapter pick, apply the change to the perch record (update info.json.adapter via the existing write seam; an `<adapter>:<profile>` pick stamps the full option, composing with A-4), then RETURN to the endpoint's Confirm menu — NO id prompt, NO home prompt, NO start. FIX: a return-to-Confirm mode on the adapter-pick screen (flag or dedicated Screen::ChangeAdapterPick) skipping CreateId/CreateHome + the launch outcome. Unit the flow-state transitions + the record write. Shared-seam: touches picker flow state — run the full picker cluster. See triage B-2.
2026-07-06T06:24:02.7392566Z - Required stages: impl, unit
2026-07-06T06:24:02.7392594Z 
2026-07-06T06:24:02.7392689Z ### REQ-TRANSLATE-COMMIT-MISS-TOLERANCE
2026-07-06T06:24:02.7395605Z - Title: C-1 (F029, B6 ROOT — rescope of REQ-TRANSLATE-BINARY-LIVENESS-DECAY, now PINNED): at a checkpoint clear boundary the clear-only inject drives `/clear`; its `{commit}` is never observed within INJECT_COMMIT_DEADLINE (5s, broker.rs:158) so the inject worker FAULTS + TERMINATES a HEALTHY translate binary (broker.rs respool_and_fault + return) and by ADR-0022 design NEVER respawns → every subsequent force-native reports delivered=false ('no live translation binary', cli.rs:5046) = B6's exact field signature; the v0.12.0 checkpoint post-clear WAKE dies with the terminated binary + the fire-and-forget FIRE in the dead window. NOT a race — deterministic at every checkpoint-armed boundary (perri captured-stderr proof: TRANSLATION_FAULT on the F-019 unread daemon-stderr channel). FIX (REVISED, supersedes terminate-then-respawn): miss != fault — preserve the binary; the watchdog's job is ANTI-STALL (release the operator floor), not execution-verification. See addendum C-1 + ADR-0022 amendment.
2026-07-06T06:24:02.7395762Z - Required stages: impl, unit, int
2026-07-06T06:24:02.7395795Z 
2026-07-06T06:24:02.7395919Z ### REQ-HAZARD-TRANSLATE-FAULT-PERMANENT-DEATH
2026-07-06T06:24:02.7397772Z - Title: C-1 hazard (F029; paid-for: B6 + three-version checkpoint-wake breakage): a REAL translation fault (binary death — stdin write fail / stdout disconnect — or strike-budget exhaustion) must get a BOUNDED eager respawn (C3(b) give-up budget) instead of permanent death, and must stamp a PERCH-VISIBLE fault surface (mutate_info field, cleared on healthy respawn/commit) — TRANSLATION_FAULT is daemon-stderr-only today (the F-019 unread-channel trap; same honesty rule as F-027 ENDPOINT_SPAWN_FAIL). A real fault legitimately loses in-memory state (the wake is NOT carried across a real fault, unlike a mere commit-miss). See addendum C-1 (3)-(4).
2026-07-06T06:24:02.7397879Z - Required stages: impl, unit, int
2026-07-06T06:24:02.7397907Z 
2026-07-06T06:24:02.7398007Z ### REQ-HAZARD-BOUNDARY-READY-STRAND
2026-07-06T06:24:02.7401589Z - Title: C-2 (F029, SEAM-2 pinned — B6's SECOND HALF, the live-wake blocker; perri wakep9 vs wakep4 gate-state dump + doyle code trace): at a /clear, CC fires SessionEnd(reason=clear) for the DEPARTING session BEFORE SessionStart; the departing sid STILL matches the perch pin at that instant, so the adapter's [hooks.SessionEnd] → `api session-end` AUTHENTICATES and the soft handler REMOVES the ready marker (+ unregister_address, reporting.rs cmd_session_end:206-207). The subsequent `api boundary` rotates the sid but NOTHING re-writes ready → is_online false → try_spt_hosted_inject Nones on the CLI gate BEFORE any broker RPC → every post-clear force-native (incl. the checkpoint FIRE) reports the generic UNDELIVERED, persistent by construction (no path re-stamps ready outside a real bind). The single differing gate field at every UNDELIVERED instant is ready-absent (info online/controllable/rotated-sid all healthy, translate alive). Paid-for hazard. FIX: cmd_boundary re-stamps the ready marker (+ status online, idempotent) ATOMICALLY with the sid rotation — a boundary PROVES a live successor session on the same harness process; a REAL end has no subsequent boundary so genuine teardown is untouched. See triage addendum C-2.
2026-07-06T06:24:02.7401752Z - Required stages: impl, int
2026-07-06T06:24:02.7401785Z 
2026-07-06T06:24:02.7401890Z ### REQ-PSYCHE-EPHEMERAL-DRIVER
2026-07-06T06:24:02.7405030Z - Title: W1 (F030, design §3): each psyche-relevant event runs exactly ONE bounded per-event turn through the existing driver stack (psyche_turn_and_relay for outbound-intent events / resume_psyche for session-custody transitions / run_psyche_turn for pure merges) — no resident psyche process exists between events. host_one (livehost.rs:518) STOPS spawning spawn_psyche_owned; the pulse loop stays as the daemon-side scheduler (thread + stop-flag + drop-dir watch correct) but a fire now invokes one bounded turn, daemon-driving every substitution key from daemon-known context (child never self-resolves home/subnet/perch — direction-(a) multi-subnet churn impossible by construction). Turn failures consume a bounded failure budget (C3(b) shape): N consecutive failures → psyche_host_error stamp + cooldown, reset on success; no respawn storm (nothing resident to respawn). Red-first: fire an event on a hosted live endpoint → assert one turn ran (SIDE-EFFECT PROOF FILE — transcript-jsonl asserts are structurally blind, 2026-07-04 rig lesson) and no {id}-psyche process survives the turn.
2026-07-06T06:24:02.7405235Z - Required stages: doc, impl, unit, int
2026-07-06T06:24:02.7405312Z 
2026-07-06T06:24:02.7405415Z ### REQ-PSYCHE-SID-CUSTODY
2026-07-06T06:24:02.7408275Z - Title: W2 (F030, design §3): the psyche mints and keeps its OWN session id, stored in the nested {id}-psyche perch record — {session_id} in psyche role templates becomes the psyche's sid, never the parent's (today's fill at livehost.rs:518 is the PARENT's — the custody bug). Parent boundary (/clear, /compact) does NOT rotate the psyche sid (the psyche's conversational thread survives parent resets — its job). resume_psyche validates the custody key before spawn (resume.rs:183). Reseed path: psyche session lost/invalid → ResumeMode::FreshWithPreload (download_psyche_context composes role/live/project into {psyche_context}, resume.rs:100) + LOUD PSYCHE_RESEED:{id} marker (custody-loss loop visible; W1 budget bounds it). If the parent sid is still needed by a template it gets its OWN explicit key {parent_session_id} — never aliased. Red-first: parent `api boundary clear` → nested perch sid UNCHANGED (today it is the parent's — guard-revert reproduces).
2026-07-06T06:24:02.7408390Z - Required stages: doc, impl, unit, int
2026-07-06T06:24:02.7408425Z 
2026-07-06T06:24:02.7408529Z ### REQ-PSYCHE-NESTED-RESOLUTION
2026-07-06T06:24:02.7411500Z - Title: W4 (F030, design §3; F-017 sibling, general not psyche-only): nested {parent}/{nested} ids resolve under the PARENT's home — subnet-less resolution for nested perches (the home-ASSIGNMENT seam, not perch-path which is already subnet-less) — so child-side verbs acting on nested perches need no --subnet the child cannot know. ROOT: home::assign_home returns Ambiguous on a multi-subnet node w/o --subnet; a nested id must instead derive home from its parent perch. Additionally expose a SINGLE {subnet} base_keys fill WHEN KNOWN (own_subnet = home-subnet label, 'local' when unhomed; absent → LOUD missing-key fail, the {node} precedent). NO {home} key (doyle W4 Q1: the endpoint home subnet is ONE concept per CONTEXT.md:640, and 'home:' is already the subnet-name qualifier position CONTEXT.md:652 — a {home} template key invites meaning-drift). Red-first = evidence #3's exact repro: 2-subnet home, nested-id verb, must succeed (was: `spt ready <id> --once` → exit 1 READY_FAIL … pass --subnet).
2026-07-06T06:24:02.7411663Z - Required stages: doc, impl, unit, int
2026-07-06T06:24:02.7411692Z 
2026-07-06T06:24:02.7411796Z ### REQ-PSYCHE-CONTEXT-FILE-INDIRECTION
2026-07-06T06:24:02.7415971Z - Title: W4 (F030; doyle Q2 ruling + perri file-always freeze, 2026-07-04): the composed psyche mind ({psyche_context}) rides the SHIM argv today — a real ~20KB doyle psyche-download exceeds the win32 CreateProcess lpCommandLine ~32k cap → the shim spawn BRICKS. FIX (file-always, replaces {psyche_context} outright — no size-branch, no argv cliff, one path): core writes the mind to a file in the psyche's NESTED perch dir BEFORE each turn spawn and fills a single {psyche_context_file} = that PATH (argv-cap-immune). The soft fresh/continue discriminator moves from KEY-presence to FILE-CONTENT: FreshWithPreload writes the composed mind NON-EMPTY (the <fresh-psyche/> never-empty guarantee carries to the file content); ContinueExisting writes it TRULY 0-BYTE (perri BINDING PIN 1 — NO sentinel/placeholder EVER, else her non-empty=fresh discriminator misfires a spurious --session-id adopt). Core owns the file lifecycle: write-before-spawn each turn, overwrite in place, persists between turns in the nested perch (debuggability); never deleted per turn. perri shim delta: --psyche-context-file <path> arg, read-file prefix, TRIM-based emptiness (her tolerance, NOT core's license — core writes exactly 0 bytes on continue, PIN 2), read-failure = generic fail NEVER 95, never writes/deletes the file. Red-first: a ~40KB mind → the old {psyche_context}-on-argv path BRICKS the win32 shim spawn; the file path succeeds (shim reads the full mind from file).
2026-07-06T06:24:02.7416186Z - Required stages: doc, impl, unit, int
2026-07-06T06:24:02.7416220Z 
2026-07-06T06:24:02.7416328Z ### REQ-PSYCHE-LEGACY-RESIDENT-SWEEP
2026-07-06T06:24:02.7422098Z - Title: W5 (F030; doyle+perri 2026-07-04): a dirty daemon upgrade from <=v0.24.0 strands a RESIDENT psyche wrapper the OLD daemon spawned — and F-030 W4's nested-`ready` resolution fix CONVERTED that wrapper's accidental self-reap into a permanent HANG. The pre-W3 wrapper's only spt IPC is `spt ready <parent>-psyche --once` (BLOCKING, no internal timeout); pre-W4 that hit READY_FAIL on a multi-subnet home → the wrapper exit-4'd (accidental reap). Post-W4 the nested id resolves cleanly → the wrapper REGISTERS then BLOCKS FOREVER on its first post-upgrade poll: no exit, no psyche_host_error, no CPU (KH 2.6 invisible-loop class, one level up). Post-W3 core has no residency machinery to reap it. FIX: a ONE-SHOT legacy-resident sweep at BRAIN START (never per-reconcile/periodic — burying residency-era machinery, not resurrecting it). GUARD = adapter-AGNOSTIC (glue-model): resurrect the retired reap_orphan_psyches LOGIC — for each self-perch live-agent id derive `<id>-psyche` and kill iff (a) exe basename == the adapter's MANIFEST-declared psyche program (normalize_basename, never a hardcoded adapter name) AND (b) cmdline contains the id marker `<id>-psyche` AND (c) pid alive; any unreadable signal → DECLINE + loud log (fail-safe-decline, positive-match-only; infra never-kill inside the sweep). FRATRICIDE is closed by TIMING (perri-confirmed from the owning side): the ephemeral shim is daemon-spawned per-event, bounded, exits at turn end — at brain start BEFORE the first reconcile/pulse no current shim is resident, so any `<id>-psyche` psyche-program process alive then is unambiguously stranded-legacy. RESIDUE (doyle PIN 3): the hung wrapper REGISTERED a `<parent>-psyche` ready perch before blocking; killing the pid alone leaves a phantom ready-record with a dead pid (the REMOTE-TRUTH presence-lie class) — the sweep MUST also clear that stale registration or prove the existing stale-perch cleanup reaps it. No field window pre-W6 (nothing releases). (F-030 W5)
2026-07-06T06:24:02.7422285Z - Required stages: impl, unit, int
2026-07-06T06:24:02.7422313Z 
2026-07-06T06:24:02.7422413Z ### REQ-HAZARD-PSYCHE-RESIDENCY-EXPECTATION
2026-07-06T06:24:02.7425261Z - Title: W3 (F030 hazard; paid-for: hall-bf churn ordinal 6491+ + adapter v0.13.2 bad-ship brick 2026-07-04): a psyche failure of ANY shape must NOT remove or alter the parent endpoint's ready/hosted state, and hosting must NOT churn-respawn. The v0.13.2 shim-exit tripped the residency machinery (confirm_residency_or_unhost) which tore down the endpoint's hosted state — ready marker removed, never re-stamped, every force-native gated leg=cli-gate-not-hosted PERMANENTLY (field brick). FIX: residency machinery retires with the resident child; the teardown that touches parent hosted state is DELETED — psyche trouble stamps psyche fields only. REQ-HAZARD-LIVEHOST-NONRESIDENT's spirit transfers to the W1 failure budget (its entry gets a SUPERSEDED pointer here, LIVENESS-DECAY→SUPERSEDED pattern from C-1). Conformance int = the hall-bf shape: multi-subnet home, live endpoint, failing psyche → parent stays deliverable, no rehost churn, error stamped (the wave's heart).
2026-07-06T06:24:02.7425458Z - Required stages: doc, impl, int
2026-07-06T06:24:02.7425486Z 
2026-07-06T06:24:02.7425581Z ### REQ-HAZARD-THRASH-GUARD-BLIND
2026-07-06T06:24:02.7426741Z - Title: W3 (F030 hazard; paid-for: evidence #6, hall-bf ~12/min re-host NEVER tripped the C3(b) thrash guard — boot records were not ledger boundaries to the guard): the failure budget must count REAL attempts (ledger-derived: boot/turn records via the psyche perch ledger), not whatever it counted that let 12/min churn run invisibly. Red-first synthetic loop: a 12/min synthetic failure loop MUST trip the budget.
2026-07-06T06:24:02.7426841Z - Required stages: doc, impl, unit
2026-07-06T06:24:02.7426864Z 
2026-07-06T06:24:02.7426961Z ### REQ-EFFECTIVE-INSTANCE-STATE
2026-07-06T06:24:02.7431073Z - Title: A-1 (REMOTE-TRUTH triage §A + ADR-0033 §Decision): the effective instance state of a perch is DERIVED through ONE shared function — liveness discriminates warm/cold, stored rest intent refines within warm, absent intent NEVER defaults active. ROOT (certain): resting::apply_event derived its `from` off the stored rest_state field ALONE (resting.rs:225, `unwrap_or(RestState::Active)`) — a cold perch (offline) with no intent answered `from=Active`, so a Wake event found it 'already in target state' and returned Ok(None) = the field NO_EDGE-on-a-definitely-suspended-endpoint bug (the banked F-028 rest_state-void seed). advertised_status (registryhost.rs:821) ALREADY derived correctly (is_perch_alive→intent-refined / is_perch_unbound→Dormant / cold→Suspended) — the two readers disagreed. FIX (Q1 shared derivation, hazard-class): a pure `effective_rest_state(alive, unbound, intent) -> RestState` mirroring advertised_status, consumed by BOTH advertised_status (mapped RestState→Status, behavior identical) AND apply_event's `from` (real is_perch_alive/is_perch_unbound reads); void + cold ⇒ Suspended. Bonus: kills the spurious active→suspend echo a cold+void perch used to fire (on_rest_edge on a dead driver). Red-first: perch status=offline + no rest_state → daemon_rest_event(Wake) yields from=Suspended→to=Active EdgeReport, not Ok(None).
2026-07-06T06:24:02.7431262Z - Required stages: doc, impl, unit
2026-07-06T06:24:02.7431295Z 
2026-07-06T06:24:02.7431395Z ### REQ-OPID-MINTER-NAMESPACE
2026-07-06T06:24:02.7438145Z - Title: A-4a (REMOTE-TRUTH triage §A + ADR-0034 Decision 1 + Amendments 1 & 2): the broker effect journal's dedup key gains a minter dimension so ops minted by independent counters can never collide. ROOT (high, ground-truthed vs HEAD): the journaled-op producers key into ONE journal namespace (NET_EFFECT_SESSION|shell_sid, op) at broker.rs (EffectKey=(u64,u64)); a CLI wake op colliding with an already-journaled daemon op reproduces the typed 'already applied … retry with a fresh op_id' with NO broker restart (field-hit: spt endpoint wake id@node WOKE_FAIL). Same latent class: nethost dial_ops/stream_ops HashMap<u64,u64> ('Shares the one net op-id namespace') would re-clobber even after the journal separates them; AND shellchan::deliver_stdin_pending journals (shell_sid, row_id) so an rc operator's ops on the same shell_sid collide with spool row ids (dropped keystroke OR dropped spool row). Amendment 2 corrected the minter set: the REAL journal minters are {cli, pump, rc, shell} + legacy — psyche/epoch are the EpochSource notif/lease counter domain, NEVER submit to apply_once, DROPPED from the journal enum (a tag with no stamp site = doc'd-but-dead knob). FIX (Decision 1 + Amdt 2): ONE canonical Minter enum {Legacy, Cli, Pump, Rc, Shell, Wake} — Legacy reserved for pre-upgrade lines + untagged wire, monotonically shrinks; enum is the single source for the TEXTUAL journal-line token (self-describing during recovery). EffectKey becomes (effect-class, minter, op); recover() DUAL-PARSES (old shorter line → minter=Legacy, new longer line → parsed tag) so old journals need no migration and old-shape keys can never equal new-shape (migration-free). A MintedOp{minter, seq} newtype REPLACES bare op_id:u64 through the brain/daemon THREADING paths so forgot-to-stamp is UNCOMPILABLE (row_id stays the shell seq — never re-minted, the durable spool exactly-once identity). Wire keeps an additive optional minter field (serde default absent ⇒ Legacy materialized at broker decode; serde_json no deny_unknown_fields ⇒ NO wire version bump); the newtype is NOT forced into wire structs. nethost op-maps re-key by (minter, op). Red-first: mint an rc op == a journaled shell/pump/daemon op int on the same session → pre-fix the second dedups/clobbers (WOKE_FAIL class); post-fix both are distinct keys, both Applied.
2026-07-06T06:24:02.7438431Z - Required stages: doc, impl, unit
2026-07-06T06:24:02.7438465Z 
2026-07-06T06:24:02.7438556Z ### REQ-OPID-TRACING-RETRY
2026-07-06T06:24:02.7442948Z - Title: A-4b (REMOTE-TRUTH triage §A + ADR-0034 Decision 2): the tracing-only op families auto-retry ONCE with a fresh op on the typed no-longer-held error, so a broker-restart-dropped conn/stream self-heals instead of surfacing core lingo to the user. ROOT: net/rest.rs declares rest op-ids 'tracing/correlation only … redelivery needs reporting, not dedup', yet the journal enforced exactly-once on them — a rest/attach op whose conn the broker no longer holds (post-restart) returned the typed 'already applied … no longer held … retry with a fresh op_id' (broker.rs:2796 net-dial / 3047 stream-open) straight to the user (WOKE_FAIL / rc attach fail). FIX (Decision 2, scoped): the rest family (request_rest) + rc attach stream-open (request_attach_endpoint) — and ONLY those — catch the typed no-longer-held error INTERNALLY and re-issue ONCE with a FRESH op minted from the SAME minter (A-4a MintedOp; same producer, new seq). sync/update pull families (request_sync/request_update, durable open_op) are NOT wrapped — their exactly-once dedup is load-bearing (negative control). The typed op error becomes internal-only; if the retry ALSO fails, the user-facing line names the observable situation + next action in operator language, ZERO journal/op/brain lingo (F-1 public-error rule applies early — this string is user-facing). Red-first: mint a colliding op → assert the retry succeeds + the user sees NOTHING; NEGATIVE CONTROL — a durable family's no-longer-held stays a hard error, no silent retry.
2026-07-06T06:24:02.7443124Z - Required stages: doc, impl, unit
2026-07-06T06:24:02.7443152Z 
2026-07-06T06:24:02.7443257Z ### REQ-REST-VERB-ROUTING
2026-07-06T06:24:02.7450206Z - Title: A-3 (REMOTE-TRUTH triage §A + Q3 operator-law): a BARE-id rest verb (spt wake/suspend <id>) routes across the subnet like send's fallback instead of failing local-only. ROOT (certain): cmd_rest (cli.rs:3296) gates the remote arm on id.contains('@'|':'); a bare id falls to the local-only arm (cli.rs:3340) → daemon_rest_event → info::read_info miss (resting.rs:248) → 'WOKE_FAIL:{id}: info.json absent or unreadable — not a hosted perch'. cmd_send (cli.rs:5142) DOES fall back on a local miss; cmd_rest's remote arm (cli.rs:3307, wan_rest) already handles every WanRestOutcome — it is simply never reached on a bare-id local miss. Contradicts CONTEXT:286 'a wake must route'. Q3 SUBSTRATE GAP: resolve_across_visible (registry.rs:971) filters only by Status::routable() and its Ambiguity payload is node-hexes-only — it CANNOT express the Q3 status rule; per-candidate (node,status) comes from SubnetRegistry::instances(id). FIX: a NEW pure select_rest_target helper (status-aware, isolated from resolve_across_visible which cmd_send keeps) applying GOAL-SATISFACTION semantics (ADR/triage addendum @188d269, NOT naive verb symmetry — the mixed case breaks symmetry): wake is an ∃-goal (satisfied when ANY instance Active), suspend is a ∀-goal (satisfied when ALL instances Suspended); one helper parameterized by the verb's satisfaction predicate — 0 candidates→NotFound; goal already satisfied→NoOp naming the satisfying node(s); exactly 1 ACTIONABLE (not-at-target) instance→Act(node); >1 actionable→Ambiguous(copy-paste id@node list). Edge rulings: wake with >1 Active = NoOp naming ALL active nodes (NOT Ambiguous — nothing actionable); suspend mixed (X suspended + Y active, NOT ∀-satisfied) = Act(Y) if exactly one active / Ambiguous if several active. Candidate status is ADVERTISED/gossiped (post-A-1 shared-derivation, may be STALE) so a NoOp verdict is ADVISORY and the qualified id@node path is the operator override (noted in the helper doc-comment). cmd_rest's bare-id local miss loads snapshots → instances(id) → select_rest_target → dispatches (Act→wan_rest to the node / NoOp naming node(s) / Ambiguous render_refusal copy-paste id@node list / NotFound NO_ENDPOINT), all F-1 public language from day one. Qualified id@node path unchanged; shutdown leg-2 stays LOCAL_ONLY. Red-first: a bare id present ONLY in a remote registry snapshot routes to that node instead of WOKE_FAIL.
2026-07-06T06:24:02.7450525Z - Required stages: impl, unit
2026-07-06T06:24:02.7450559Z 
2026-07-06T06:24:02.7450650Z ### REQ-SESSION-ADAPTER-RECORDED
2026-07-06T06:24:02.7455273Z - Title: D-2 (REMOTE-TRUTH triage §D-2 + operator Q5 @c248afc): the session ledger records the adapter[:profile] a session ran under, so a later resume can restore the harness the session actually used (not merely the endpoint's CURRENT stamp). ROOT: SessionEntry (spt-store/sessions.rs:58) carries ts/session_id/trigger/cwd/ordinal but NOT the adapter — a resume-from-history row cannot know which harness authored the transcript, so a resume under a since-changed endpoint adapter (B-2 ChangeAdapter, or a fork) launches the wrong harness. FIX: an ADDITIVE `adapter: Option<String>` on SessionEntry, exact cwd/ordinal serde pattern (#[serde(default, skip_serializing_if="Option::is_none")]) — a pre-migration row missing the key deserializes None; None omits the key on serialize (byte-identical to old rows); an unknown key on an old reader is ignored (serde default) — back-compat BOTH directions. Stamped at every PRODUCTION session-boundary append. CENSUS (doyle-confirmed @94f0205, corrects the triage-era 5-site drift to the real 3): startup.rs:317 (live bind boot row, rec.adapter in scope), reporting.rs:94 (boundary rotation row UNDER the mutate_info lock, capture adapter_for_ledger=rec.adapter beside cwd_for_ledger), ready.rs:119 in crates/spt-msg (ready-agent boot row, rec.adapter in scope). NOT digest.rs:601 (cfg(test) fixture) and NOT a livehost psyche-ledger append (none exists — the live /clear|/compact boundary shells `api boundary` → reporting.rs:94, the SAME append). None-stamp is a benign degrade (resume falls back to the endpoint's current adapter).
2026-07-06T06:24:02.7455377Z - Required stages: impl, unit
2026-07-06T06:24:02.7455406Z 
2026-07-06T06:24:02.7455517Z ### REQ-RESUME-ADAPTER-FOLLOWS-SESSION
2026-07-06T06:24:02.7461616Z - Title: D-2 (REMOTE-TRUTH triage §D-2 + operator Q5 @c248afc): a resume-from-history restores the RECORDED session adapter (REQ-SESSION-ADAPTER-RECORDED) — the resumed harness is the one the session ran under, re-stamped onto the endpoint PRE-SPAWN, and an unregistered recorded adapter refuses LOUDLY before launching anything. ROOT: the picker's resume_outcome (model.rs:1285) bakes adapter=ep.adapter_profile from the selected ENDPOINT, ignoring the ledger row — so a resume always uses the endpoint's CURRENT adapter even when the session ran under a different one; and the endpoint's info.adapter is never re-stamped to the row's on the resume path (cli.rs:1962 skeleton writer early-returns for an existing perch — adapter immutable, carried by bind's stamp_creation_fields). FIX (doyle fork ruling): ResumeRow (model.rs:199) gains adapter: Option<String> threaded from SessionEntry.adapter in picker/data.rs; the row title (model.rs:228) renders [{adapter}] when Some ({head} [{adapter}] - {time} (…{id5})); resume_outcome bakes the ROW's adapter with an endpoint fallback (row.adapter.unwrap_or(ep.adapter_profile)) — None → the endpoint's current stamp (benign degrade). The pre-spawn RE-STAMP + refusal ride the picker resume dispatch (mod.rs:360 Run arm, resume.is_some()) reusing the hazard-guarded mutate_info seam (write_adapter_change/mod.rs:336), NEVER the bind path: order = read current info.adapter → if the baked adapter DIFFERS (a real replace; a None-row bakes the endpoint's own → equals current → NO write) → registered-check via resolve_option (Err(NotRegistered) → loud F-1 refusal naming the adapter + `spt adapter add`, NO stamp, NO spawn) → write_adapter_change re-stamp → spawn. ONE adapter write path (the mutate_info seam); REQ-HAZARD-ADAPTER-PROFILE-STAMP-CLOBBER's bind/hook path (stamp_creation_fields, home.rs) UNTOUCHED — both its guard tests stay green as the gate condition. Red-first: a resume row adapter="claude-spt" over an endpoint stamped "claude-spt:ccs" → the baked Outcome.adapter == "claude-spt" (the deliberate replace) and the pre-spawn stamp writes it.
2026-07-06T06:24:02.7461935Z - Required stages: impl, unit
2026-07-06T06:24:02.7461968Z 
2026-07-06T06:24:02.7462049Z ### REQ-WAKE-RESUME-LEG
2026-07-06T06:24:02.7467502Z - Title: A-2 (REMOTE-TRUTH triage §A-2 + ADR-0033): the daemon reconcile gains a WAKE-RESUME LEG — an endpoint whose rest INTENT is Active but whose harness session is COLD (status != online) is resumed by the daemon via the adapter's [session.resume] template using the LAST LEDGER session id, so a bare `spt wake <id>` on a suspended live agent actually brings it back (today: reconcile_once start-arm hosts ONLY status==online (livehost.rs:199), so a woken-but-unbound endpoint is skipped forever — neither status reaches online nor does reconcile re-host). This is the ADR-0033 LIFT: the thin `spt wake` edge writes rest intent, the DAEMON does the work. Mirrors shellwake::resolve_wake (read rest state, live-pid double-launch guard, launch, NEVER flip status — the harness self-binds → online). The leg reads the recorded adapter (D-2, REQ-SESSION-ADAPTER-RECORDED); an UNREGISTERED recorded adapter is the Q5 daemon-variant refuse: do NOT spawn, record a LOUD host_error report (F-1 naming the adapter + `spt adapter add`), never silent, never fallback-spawn on a different adapter. BINDS: (1) status=online is set ONLY by a real bind — the resume leg NEVER stamps it (CONTEXT liveness truth; the A-1 effective-state derivation depends on this staying honest). (2) host_error is a REPORT of the most recent host-level failure, NEVER a liveness input — neither liveness nor advertised_status reads it (host_error + online still derives Active); cleared on a successful host/bind; the existing silent `continue` on a deregistered online adapter (livehost.rs:205) folds into the same field. (3) the resume-pid guard marker is CUSTODY-ONLY (F-030 nested-record discipline) — never a liveness input. cold-with-no-ledger-row degrades benign (loud-logged skip, no crash, today's behavior). Single-node; C-2 picker Wake-now unblocks after. --wait is a SEPARATE rider (REQ-WAKE-WAIT).
2026-07-06T06:24:02.7467660Z - Required stages: impl, unit, int
2026-07-06T06:24:02.7467693Z 
2026-07-06T06:24:02.7467783Z ### REQ-WAKE-WAIT
2026-07-06T06:24:02.7469697Z - Title: A-2 rider (REMOTE-TRUTH triage §A-2): `spt endpoint wake --wait` blocks on the REAL bind (status reaches online) after the daemon wake-resume lift (REQ-WAKE-RESUME-LEG), instead of the DEFAULT accepted-not-bound print (thin edge writes intent, daemon lifts async — ADR-0033). Reuses the F-027 bind-await machinery if/when it lands, else a bounded poll on status==online with a plain-language timeout (no core lingo, F-1). Default wake is UNCHANGED (accepted-not-bound truth). Separate chunk from the core leg (doyle A-2 ruling: C-2 needs the core leg, not --wait); F-027 bind-await stays design-only until this activates.
2026-07-06T06:24:02.7469797Z - Required stages: 
2026-07-06T06:24:02.7469826Z 
2026-07-06T06:24:02.7469926Z ### REQ-PICKER-REMOTE-WAKE
2026-07-06T06:24:02.7476190Z - Title: C-2 (REMOTE-TRUTH triage §C-2 #4 + addendum @3442ce5): a REMOTE suspended picker row offers `Wake now` — waking the endpoint THROUGH its owning node's rest edge (the A-2 daemon resume leg) — instead of a bare `Start now` that silently cold-starts a COLLIDING LOCAL instance of a remote id (node-anchored identity violation, ADR-0003/0023). ROOT (certain): confirm_options collapsed Suspended into the offline action set = [Start,…]; on a REMOTE row `Start` bakes Outcome::Run with NO node → picker dispatch → cmd_endpoint_run creates a fresh LOCAL perch of the remote id (model.rs confirm_terminal / mod.rs dispatch). Remote rows are only Online/Suspended, so remote+offline == remote-suspended. FIX: confirm_options splits the offline arm on is_local — remote → vec![Wake] (a new ConfirmOption::Wake), local → vec![Start] UNCHANGED; confirm_terminal(Wake) → a new Outcome::Wake{id,node} carrying the RAW node hex; dispatch routes crate::cli::cmd_endpoint_wake_remote(id,node) → cmd_rest(id@node, RestEvent::Wake) = the EXISTING WAN rest arm (dispatch_wan_rest → wan_rest), and A-2's resume leg revives the session async (the full loop the operator wanted). `Instantiate locally` stays the separate deliberate-copy verb. ADDENDUM correction (a): EndpointRow.node is the LOSSY DISPLAY string (node_label_display = 'LABEL (prefix…)'), which node_qualifier_matches (full-hex-prefix|exact-label) CANNOT match — a dead Wake; so a NEW EndpointRow.node_key: String carries the raw ResourceRow.node hex (empty for local rows — Wake is remote-only) threaded through from_resource_row + the 4 literal ctors. CO-GATE (b, addendum): ChangeAdapter (was `offline`-gated) is gated `offline && is_local` — write_adapter_change → resolve_perch_path(Infer) → mutate_info rewrites a LOCAL perch record, so offering it on a remote suspended row is the SAME colliding-local-write-for-a-remote-id class (the Start twin); a remote node's adapter is not ours to rewrite from here. Red-first: a remote suspended row → confirm_options has Wake NOT Start NOT ChangeAdapter, and confirm_terminal(Wake) → Outcome::Wake{node==raw hex} (never a local Outcome::Run); a LOCAL offline row is UNCHANGED (Start + ChangeAdapter).
2026-07-06T06:24:02.7476384Z - Required stages: impl, unit
2026-07-06T06:24:02.7476422Z 
2026-07-06T06:24:02.7476531Z ### REQ-HAZARD-BROKER-FLOOR-LOCK-POISON
2026-07-06T06:24:02.7484105Z - Title: B-1 (REMOTE-TRUTH triage §B-1, PIVOTED @e5eb99a): NO bare `.lock().unwrap()` on a broker-resident lock reachable from serve/dispatch — a brain-only self-update keeps the broker + all its Mutexes ALIVE (REQ-UPD-3), so a single panic under one poisons it PERMANENTLY: the next `.lock().unwrap()` panics, kills its per-conn reply thread, and EVERY subsequent attach silently deadlines ('brain IPC read deadline elapsed') while non-locked ops keep working. TRIAGE-DRIFT (sweep-dispatch-site-counts discipline): the triage named 3 sites (broker.rs:1163 flush_inject_floor / :1297 inject-worker-open / :2142 buffer_if_held) as the surviving class, but ALL 3 are the INJECT FLOOR and were ALREADY poison-proofed by REQ-HAZARD-INJECT-WORKER-POISON (lock_floor, shipped post-triage — the FLOOR HALF is SUBSUMED, this seed redirects). The SURVIVING class (matching the triage's own symptom description) is the ATTACH-PATH lock set: self.sessions Mutex<HashMap> ×18 + its sessions_exit alias ×1, the per-session OutputLog RING ×11 (log/h.log/log_drain/log_exit), pair_holds ×4 — 34 production bare .lock().unwrap() (cfg(test) excluded). FIX (doyle B-1 ruling): recover ALL THREE via ONE shared `recover<T>(&Mutex<T>) -> MutexGuard<T>` helper (into_inner idiom, same as lock_floor / the effect journal bug #16 — safe for the short coherent-on-recovery map ops of sessions/pair_holds), plus `recover_log(&Mutex<OutputLog>)` for the ring which adds a COHERENCE CLAMP on the poison-recovery path: a panic mid-append can leave the ring torn (over-cap, a last seq not below next_seq, non-monotonic front/back) and serving those bytes risks garbage, so OutputLog::clamp_or_reset cheap-checks the invariants and RESETS the ring empty (next_seq preserved — cursors never rewind) + loud-logs on violation. Rationale: fail-fast on the log reintroduces the very wedge B-1 kills (poisoned log = every subscriber attach panics forever); blind recover serves torn bytes; clamp-or-reset costs only scrollback that self-heals on the next PTY output + repaint (lost scrollback << permanent wedge, torn-serve eliminated not tolerated). Sessions/pair_holds recover bare (short map ops, coherent-on-recovery). CLASS invariant (KNOWN-HAZARDS 7.33): any new broker-resident lock uses recover/recover_log or a documented fail-fast justification. Red-first: a scripted panic-under-sessions-lock → recover hands back a usable guard, the next attach still opens; a TORN-RING variant → recover_log clamps/resets so the subscriber gets sane bytes.
2026-07-06T06:24:02.7484448Z - Required stages: doc, impl, unit
2026-07-06T06:24:02.7484481Z 
2026-07-06T06:24:02.7484587Z ### REQ-CONTROLLER-LIVENESS-REAP
2026-07-06T06:24:02.7492590Z - Title: B-2 (REMOTE-TRUTH triage §B-2, REDUCED @bdc1242): a stale ONLINE+CONTROLLED stamp on a live-session perch self-heals — the info.json driven_by/controlled RECORD is made to match the broker's SINK-TABLE TRUTH. ROOT (persisted-stale-stamp class, doyle Q1): the livehost control reap gates on !has_session (reconcile_hosted_liveness), and a brain-only update KEEPS the session (REQ-UPD-3), so a controller stamp that went stale WHILE the session lived was never re-derived from broker truth. NOT a transport bug: (a) a persisted conn is the REQ-UPD-3 feature; (b) an idle-severed conn eventually EOFs via QUIC keepalive → handle_conn detach (path 1) — and the reason paths 1-3 previously failed to clean up was the B-1 broker floor-lock POISON WEDGE (cleanup panicked under the poisoned lock), now fixed. REDUCTION (doyle, my ground-truth): the prescription was 80% pre-built — converge_perch_stamps (broker.rs, REQ-HAZARD-CONTROL-STAMP-CONVERGENCE) ALREADY converges info.json driven_by/controlled to the broker's controller_by/has_controller on EVERY KIND_SESSIONS poll, and the livehost reconcile already TRIGGERS that poll per tick (query_live_session_endpoints). So NO new IPC query, NO new livehost arm, NO 5th detach path — the ONLY gap is that a controller whose WRITER THREAD died (severed conn: the writer failed a socket write, or a detach dropped by the prior B-1 wedge) still reports controller_by=Some/has_controller=true, so converge keeps the stale stamp. FIX: a broker-side lazy-reap in the KIND_SESSIONS snapshot closure — OutputLog::reap_dead_controller() drops a controller whose _writer.is_finished() BEFORE controller_by/has_controller are read, so the reply + the off-lock converge both see the honest (cleared) state and the stamp clears. LOCK-SAFE: the reap drops the sink in-memory ONLY (no stamp_driven_by → no info.json I/O under the log lock, the KH 7.12/5.16 lock-across-effect discipline); the OFF-lock converge_perch_stamps writes the honest stamp. KH 7.15 held by construction: the reap only ever CLEARS, never latches driven_by; a LIVE (idle, parked-on-rx.recv) controller is is_finished()==false so it is NEVER false-reaped. RESIDUAL (doyle Q2 accepted): a TRULY IDLE severed controller (writer parked on recv, no output, conn not yet EOF'd) stays is_finished()==false and converges only on output-resume / conn-EOF — that harder active-probe case is the RESERVED REQ-HAZARD-DRIVEN-BY-IDLE-REMOTE-EVICT (SessionInfo.controller_by doc), deliberately NOT built here so the reserved seed keeps its scope. Red-first: a dead-writer sink → reap clears it (controller_by honest None → converge clears the stamp); a live-writer sink → UNTOUCHED (no-false-reap control).
2026-07-06T06:24:02.7492886Z - Required stages: impl, unit
2026-07-06T06:24:02.7492919Z 
2026-07-06T06:24:02.7493014Z ### REQ-ADAPTER-FLOOR-ENFORCE
2026-07-06T06:24:02.7500881Z - Title: F-5 (REMOTE-TRUTH triage §F-5 + doyle rulings 2026-07-05): BOTH adapter acquisition verbs (spt adapter add + spt adapter update) REFUSE when the installed spt-core is BELOW the adapter's declared [adapter].min_spt_core_version floor — with an F-1 operator refusal naming the installed core, the floor, and the next action (update spt-core first). ROOT: the floor was PARSED + required (manifest.rs) but never compared to the running core — dead enforcement; and the [update].version_check knob that gated it was DOC'D-BUT-DEAD (never read by any production path — a contract lie). RULINGS: RETIRE version_check (drop the manifest field + schema + docs + the cfg(test) literals; a pre-existing manifest still setting it deserializes fine — serde ignores the unknown key, no deny_unknown_fields, so retiring is back-compatible); SEMVER-compare NOT string-compare (the 0.9.0 < 0.25.0 lexical trap); enforce on BOTH verbs; nothing installs / registry untouched on refuse (binds both verbs, no residuals). FIX: (1) a pure spt-runtime version_meets_floor(core, floor) -> bool (numeric per-component: split '.', u64, missing→0, non-numeric→0, first-diff decides, equal-when-zero-padded ⇒ satisfied) — mirrors the CLI version_is_newer parse (same numeric model, different question: freshness=strictly-newer vs floor=at-least). (2) ADD: the gate lives INSIDE registry::register (the choke point) via a register_with_core(core_version) seam register() delegates to with env!(CARGO_PKG_VERSION) — the floor check runs right after the manifest parse, BEFORE any registry write, returning the typed RegistryError::CoreFloor{adapter,core,floor} (Display = the ONE F-1 refusal both verbs surface); nothing recorded on refuse. (3) UPDATE: a PRE-SWAP peek (staged_floor_ok) extracts the staged .spt to a THROWAWAY temp, parses its manifest floor, and refuses BEFORE apply_release_crc_swap mutates the live pointer-mode home — so a refusal (or an unverifiable floor: FAIL-CLOSED) leaves the live install BYTE-UNTOUCHED; register@8932 stays as the defense-in-depth backstop for every other entry path. doyle bind: the register-only gate would let the crc-swap replace the live files with a floor-violating version while the record refuses (record and reality disagree — the exact contract-lie shape this milestone kills), so the pre-swap peek is the only correct answer. Red-first: perri negative repro on ADD (fresh home + synthetic low core + high-floor manifest → CoreFloor refuse, registry untouched) + the UPDATE pre-swap refuse (live home byte-untouched) + a floor-met positive control (0.25.0-on-0.25.0 installs); + version_meets_floor table incl. the 0.9<0.25 trap.
2026-07-06T06:24:02.7501076Z - Required stages: doc, impl, unit
2026-07-06T06:24:02.7501110Z 
2026-07-06T06:24:02.7501211Z ### REQ-RUN-ID-REUSES-ADAPTER
2026-07-06T06:24:02.7505273Z - Title: D-1 (REMOTE-TRUTH triage §D-1): `spt endpoint run --id <id>` with NO --adapter, when <id> names an EXISTING perch, REUSES that perch's recorded info.adapter and runs NON-INTERACTIVELY — instead of always falling to the picker as a create-new prefill (an existing endpoint retyping its own adapter, or being sent to a create-new flow, is the operator wart). ROOT (certain, no design tension): the cli `match (adapter,id)` special-cased only (Some,Some)→cmd_endpoint_run; the catch-all routed EVERY lone --id to crate::picker::run as a create-new prefill, never considering an existing endpoint (cli.rs ~1290). FIX: a PURE resolve_run_target(adapter, id, recorded) over the 4 (adapter?,id?) quadrants — (Some,Some)→Direct{a,id}; (None,Some(id))→ recorded adapter present (info.adapter = adapter-chosen-at-creation, spt-store info.rs:167) → Direct{recorded,id}, absent/no-perch → Picker{None,Some(id)} (today's create-new prefill UNCHANGED); (Some,None)/(None,None)→Picker unchanged. The perch lookup (read_info(resolve_perch_path(id,Infer)).adapter) is INJECTED as a closure so the router is pure + testable without a perch on disk; resume threads into BOTH Direct paths. Red-first: (None,Some(id),recorded=Some) → Direct (pre-fix this routed to Picker create-new). int (live run --id on an existing perch reuses its recorded adapter non-interactively) deferred to the rig.
2026-07-06T06:24:02.7505521Z - Required stages: impl, unit
2026-07-06T06:24:02.7505555Z 
2026-07-06T06:24:02.7505654Z ### REQ-PICKER-PURGE-SHORTCUT
2026-07-06T06:24:02.7509290Z - Title: C-3 (REMOTE-TRUTH triage §C-3 #8): the pick-existing list gains an `x` purge shortcut — on an OFFLINE LOCAL highlight, `x` opens a small in-TUI confirm screen (Screen::ConfirmPurge, the B-2 ChangeAdapterPick shape) and Enter purges via the ONE existing purge core `cmd_endpoint_purge(id, yes=true, force=false)` — NEVER the core's stdin [y/N] (it fights the picker's raw mode; the confirm screen IS the confirm). The shortcut INHERITS both purge gates (offline-only + node-local, cli.rs cmd_endpoint_purge / CONTEXT:189): gated-off presses stay on the list and FLASH WHY (online → offline-only, remote → local-only). force=false is deliberate — the model gate is advisory; the core's own offline check is the authority, and a race to online between gate and purge must REFUSE, never stop-then-purge. After a successful purge the picker STAYS (inline outcome, like Shortcut/ChangeAdapter): the row leaves the in-memory list (remove_endpoint, cursor re-clamped) + flash PURGED:{id}. Hint truth (B-1/F029 discipline): the pick legend renders `x purge` ONLY when purge_key_live() — the same predicate the handler gates on. Red-first: purge outcome reachable ONLY from an offline LOCAL highlight (online/remote → no screen change + why-flash).
2026-07-06T06:24:02.7509466Z - Required stages: impl, unit
2026-07-06T06:24:02.7509499Z 
2026-07-06T06:24:02.7509591Z ### REQ-PICKER-BACK-NAV
2026-07-06T06:24:02.7512190Z - Title: C-4 (REMOTE-TRUTH triage §C-4 #9): Backspace is a back() ALIAS across the picker — one keypress backs out one screen along the SAME reverse map Esc walks (model back(), complete for all screens incl. the C-3 ConfirmPurge), and from the kind layer it cancels the picker (Esc parity) — EXCEPT the two text-edit contexts, where Backspace stays CHAR-DELETE: CreateId entry (id_backspace) and the pick-list filter mode (filter_backspace). DELIBERATE: no empty-buffer fallthrough to back() in the text contexts — mixing delete and nav on one key invites miskeys mid-typing; Esc already backs out (the triage's optional extra, declined). Pure key routing in handle_key (picker/mod.rs) ahead of the per-screen arms; zero model change (the reverse map pre-existed). Red-first: Backspace on Confirm → PickExisting (pre-fix: dead key); on CreateId with a buffer → buffer shortens, screen unchanged; empty buffer → STILL no nav.
2026-07-06T06:24:02.7512294Z - Required stages: impl, unit
2026-07-06T06:24:02.7512328Z 
2026-07-06T06:24:02.7512415Z ### REQ-RC-RECONNECT
2026-07-06T06:24:02.7517937Z - Title: B-3 (REMOTE-TRUTH triage §B-3, the operator-asked UX): the rc attach viewport RECONNECTS on a severed transport instead of print-and-exit. Pre-fix rc was one-shot (resolve→dial→attach→pump→parting line); FAULT-MATRIX row 9 over-promised. FIX: the establish sequence (daemon ensure → broker conn → session resolve local-first/cross-node → dial → attach-open w/ A-4b tracing retry → subscribe) is factored into establish_attach and run_attach_inner wraps establish+pump in a loop. RECONNECTABLE class = severed transport ONLY: PumpEnd::BrokerGone (broker-conn EOF class, broker bounce) + the NEW PumpEnd::Severed (serve-side stream EOF AFTER rendered output = remote conn drop — pre-fix MISLABELED as 'detached — still running'; a nothing-rendered EOF stays the honest NoLiveSession refuse). FINAL ends (Exited/Detached/Displaced/Stalled/NoLiveSession) never re-drive — re-attaching a deliberately-ended session is wrong. On sever: full-screen centered 'Reconnecting to {target}…' banner (pure byte-emit like StatusRow; target = owning-node label or 'local daemon'; Q4 UX rule — operator language, internal sever detail never paints), then re-drive establish_attach every RECONNECT_PAUSE (1s) inside RECONNECT_WINDOW (30s, generous for a daemon bounce); a Detach keypress mid-window aborts honestly to [detached]; window expiry → PumpEnd::ReconnectGaveUp with a plain-language give-up line naming the cause, the window, and the retry action (never op/read-err lingo). Per re-establish: fresh OpMinter (ADR-0034 rc tracing per viewport), fresh initial resize (PTY matches the CURRENT terminal), pump-local render cursor resets so the re-serve ring replay REPAINTS the screen the banner cleared. FAULT-MATRIX row 9 made TRUE (F-3), not edited down. Red-first: serve-EOF-after-render → Severed (vs the pre-fix false Detached); only BrokerGone/Severed classify Reconnect.
2026-07-06T06:24:02.7518247Z - Required stages: doc, impl, unit
2026-07-06T06:24:02.7518280Z 
2026-07-06T06:24:02.7518378Z ### REQ-SELF-DETECT-PARENT-PID
2026-07-06T06:24:02.7523004Z - Title: E-1 (REMOTE-TRUTH triage §E-1 #7): self-detect leg (c) — the pid-ancestry fallback — ALSO candidates on `rec.parent_pid` (the harness pid, CONTEXT's 'stable session-binding anchor', stamped at bind), not `rec.pid` alone. ROOT: for an spt-hosted endpoint (broker PTY, headless) `rec.pid` is the ephemeral bind-CLI pid, ALREADY DEAD by send time (the F-026 #11 dead-pid class, field-sighted on hall-bf) — never in any sender's ancestry and alive-gated out — so an spt-hosted sender could NEVER resolve self via leg (c): its messages were from-stamped `cli@NODE` (operator #7) and replies bounced NO_PERCH. FIX: detect_self_by_ancestry pushes a second candidate (id, parent_pid) when `rec.parent_pid` is Some + alive; the pure nearest-first matcher (match_self_by_ancestry) is unchanged. LABEL-ONLY, exactly like the rest of leg (c): from-label/routing default, NEVER authentication — authenticate() untouched, the pid-ancestry-for-auth question stays parked (KH 7.3/7.5 separation holds; a wrong label self-corrects, a wrong grant does not). Env legs (a)/(b) stay first. Red-first int (the triage-specified missing test): rec.pid = dead sibling + rec.parent_pid = genuine live ancestor → self resolves (pre-fix None); ancestry-gate control: live-but-non-ancestor parent_pid must NOT resolve. Rider (same cluster, activated separately once doyle rules the fix shape): F-026 #11 dead-pid itself — rec.pid should hold something that stays true, or liveness readers stop trusting it. Cross-node from-stamp proof (spt-hosted B-side sender arrives at A as `<id>@node`, not `cli@node`) rides the [twohost] rig wave rung.
2026-07-06T06:24:02.7523116Z - Required stages: impl, int
2026-07-06T06:24:02.7523141Z 
2026-07-06T06:24:02.7523232Z ### REQ-HAZARD-DEAD-REC-PID
2026-07-06T06:24:02.7526670Z - Title: E-1 rider (F-026 #11 dead-pid class, doyle-ruled SCOPED 2026-07-05 — KNOWN-HAZARDS 7.34): a dead `rec.pid` on an spt-hosted perch is EXPECTED, not staleness — the recorded pid is the ephemeral bind-CLI pid, which dies immediately after bind (the broker holds the PTY; no resident harness process at that pid). NO reader may alive-gate on `rec.pid` alone: spt-hosted LIVENESS comes from the daemon-managed status field (KH 2.5 — status present ⇒ authoritative, never a per-pid probe); IDENTITY comes from session/ancestry resolution where `rec.parent_pid` (the harness pid, the stable session-binding anchor) is the ancestry candidate (REQ-SELF-DETECT-PARENT-PID). Re-stamping rec.pid with the harness pid (shape (a)) is OVERRULED: ADR-0021 demoted pid to a bind-time seed hint (re-anchoring truth there reverses the design); every pre-existing record keeps the old CLI pid so readers need the scoped discipline anyway (migration hole); blast radius (every rec.pid consumer + KH 2.5 external-perch probe semantics) buys nothing the reader-side fix doesn't. CLASS rule: any newly sighted rec.pid-alive-gating reader gets the same scoped fix and EXTENDS this requirement's evidence — no new REQ per reader.
2026-07-06T06:24:02.7526923Z - Required stages: doc, int
2026-07-06T06:24:02.7526956Z 
2026-07-06T06:24:02.7527041Z ## How to report back
2026-07-06T06:24:02.7527074Z 
2026-07-06T06:24:02.7527238Z For every (requirement, failing criterion) pair, emit one finding:
2026-07-06T06:24:02.7527271Z 
2026-07-06T06:24:02.7527347Z     {
2026-07-06T06:24:02.7527448Z       "code": "requirement_quality",
2026-07-06T06:24:02.7527552Z       "requirementId": "REQ-...",
2026-07-06T06:24:02.7527704Z       "criterion": "singular" | "verifiable" | "atomic" | "active-voice",
2026-07-06T06:24:02.7527806Z       "message": "<short reason>",
2026-07-06T06:24:02.7527919Z       "suggestedRevision": "<optional rewrite>"
2026-07-06T06:24:02.7528005Z     }
2026-07-06T06:24:02.7528033Z 
2026-07-06T06:24:02.7528248Z Wrap your response as { "findings": [ ... ] } listing only your concerns; the
2026-07-06T06:24:02.7528373Z deterministic findings above don't need to be repeated.
